Compare commits
152
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4d9a557190 | ||
|
|
4cc36f925c | ||
|
|
65ad25bb86 | ||
|
|
d0bc45be17 | ||
|
|
f269585de3 | ||
|
|
9936462f31 | ||
|
|
caf18da7f6 | ||
|
|
21eab267df | ||
|
|
bad5a523c2 | ||
|
|
b9f4ba19a6 | ||
|
|
70e9068432 | ||
|
|
d4163e2e97 | ||
|
|
ac1f0d9d61 | ||
|
|
952d7fde63 | ||
|
|
bfc041def1 | ||
|
|
38277ddb0b | ||
|
|
eb524d27d9 | ||
|
|
4b2911a45a | ||
|
|
76eac9a691 | ||
|
|
519b047362 | ||
|
|
ffb7ae8beb | ||
|
|
434c4e99f3 | ||
|
|
31264a7e00 | ||
|
|
3e912d9aa7 | ||
|
|
26a93d77aa | ||
|
|
011af4de71 | ||
|
|
afc7389ce8 | ||
|
|
545e1391fa | ||
|
|
8bbafeb5ef | ||
|
|
50e1bf3800 | ||
|
|
909dc1a1ab | ||
|
|
fa70fc8731 | ||
|
|
3b2850f4d9 | ||
|
|
3ce6708be2 | ||
|
|
6eed126051 | ||
|
|
6ce39f64d9 | ||
|
|
b8bb1e02ad | ||
|
|
2515825a2b | ||
|
|
8bdb5f586a | ||
|
|
d484b66ae1 | ||
|
|
00333a5c97 | ||
|
|
d6c5052f7e | ||
|
|
37354ee225 | ||
|
|
c4ad0466d6 | ||
|
|
0260d31d26 | ||
|
|
199bd6b623 | ||
|
|
b7a72b1667 | ||
|
|
751ad12dea | ||
|
|
3075445ed6 | ||
|
|
caf073dbe7 | ||
|
|
ab71b29098 | ||
|
|
444d742a94 | ||
|
|
eb21ecf55c | ||
|
|
e98157b7fe | ||
|
|
fdcd58d404 | ||
|
|
78685ed173 | ||
|
|
9113ed840c | ||
|
|
6030cadef0 | ||
|
|
58db2d1d18 | ||
|
|
cadbc158f0 | ||
|
|
7bd3205c61 | ||
|
|
cd3e34de8f | ||
|
|
d0a0c22433 | ||
|
|
512dadc8d1 | ||
|
|
081326929f | ||
|
|
b00360537e | ||
|
|
584c1da066 | ||
|
|
c727c59663 | ||
|
|
097328db7a | ||
|
|
4534fb5ec1 | ||
|
|
7d4d64340e | ||
|
|
0cda448248 | ||
|
|
7e6d76e7db | ||
|
|
b50ced528d | ||
|
|
304c1b6439 | ||
|
|
9b6e023f84 | ||
|
|
bcfc07e3d3 | ||
|
|
ca83a66618 | ||
|
|
6fe28d92c4 | ||
|
|
419aa15cd1 | ||
|
|
fcb6dbcdd7 | ||
|
|
eba576dddf | ||
|
|
a5189eefa5 | ||
|
|
55d82ced78 | ||
|
|
0946db13de | ||
|
|
c17bc7387c | ||
|
|
7d93371581 | ||
|
|
fa2f16db89 | ||
|
|
a48814906f | ||
|
|
767a2aef43 | ||
|
|
7c54199fe1 | ||
|
|
73cafd9d57 | ||
|
|
70f80a3ec7 | ||
|
|
62a8405fa2 | ||
|
|
6718a4ef8b | ||
|
|
123ee350dc | ||
|
|
20bb812148 | ||
|
|
0f9d8eb7b5 | ||
|
|
c5b6f21515 | ||
|
|
e95af30b23 | ||
|
|
dad10c0fd0 | ||
|
|
7b9084d45d | ||
|
|
6858ef9adc | ||
|
|
23964dbbbc | ||
|
|
76d1e95f4e | ||
|
|
00605058b4 | ||
|
|
c7b20f3c40 | ||
|
|
b88faee181 | ||
|
|
ac65f56774 | ||
|
|
d97e628f81 | ||
|
|
c29ccae2a6 | ||
|
|
54a682ea50 | ||
|
|
342cc9b168 | ||
|
|
edafbf1c0f | ||
|
|
8aaee26548 | ||
|
|
4d3ed3f4ea | ||
|
|
a8f89e9a9f | ||
|
|
854af5a353 | ||
|
|
1a8348e2b4 | ||
|
|
feba480527 | ||
|
|
3fede8a7e9 | ||
|
|
ac0d3c21c6 | ||
|
|
f75328b178 | ||
|
|
11cd9d86e4 | ||
|
|
692c879e3c | ||
|
|
3a4334636b | ||
|
|
9119dc25fe | ||
|
|
22aa668b7d | ||
|
|
9150688efd | ||
|
|
edc9c79c9c | ||
|
|
d0f8c50618 | ||
|
|
ea1d4d11fc | ||
|
|
3659cca624 | ||
|
|
54710873a7 | ||
|
|
6dc5343d6d | ||
|
|
61456d886e | ||
|
|
34d7776f14 | ||
|
|
32d1cc1562 | ||
|
|
95817d8bbb | ||
|
|
d50322ed95 | ||
|
|
abe8fa5253 | ||
|
|
72ca05c966 | ||
|
|
7101eae6f4 | ||
|
|
bd9f5c3c19 | ||
|
|
aca0f88750 | ||
|
|
2c3589e22a | ||
|
|
b9cb4c94fa | ||
|
|
8de64964a3 | ||
|
|
229b7d85e8 | ||
|
|
5ce4b04b50 | ||
|
|
3d92f5e95a | ||
|
|
c830a9116d |
+25
-22
@@ -19,6 +19,8 @@ variables:
|
||||
CONFIGURE: ./configure
|
||||
SCAN_BUILD: scan-build-9
|
||||
|
||||
CFLAGS_COMMON: -fno-omit-frame-pointer -fno-optimize-sibling-calls -O1 -g -Wall -Wextra
|
||||
|
||||
stages:
|
||||
- precheck
|
||||
- build
|
||||
@@ -310,6 +312,7 @@ misc:sid:amd64:
|
||||
|
||||
🐞:sid:amd64:
|
||||
<<: *precheck_job
|
||||
<<: *debian_buster_amd64_image
|
||||
script:
|
||||
- util/check-cocci
|
||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
||||
@@ -348,7 +351,7 @@ push:docs:sid:amd64:
|
||||
gcc:alpine3.10:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--enable-dnstap"
|
||||
<<: *alpine_3_10_amd64_image
|
||||
<<: *build_job
|
||||
@@ -372,7 +375,7 @@ unit:gcc:alpine3.10:amd64:
|
||||
gcc:centos6:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --disable-warn-error"
|
||||
<<: *centos_centos6_amd64_image
|
||||
<<: *build_job
|
||||
@@ -396,7 +399,7 @@ unit:gcc:centos6:amd64:
|
||||
gcc:centos7:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||
<<: *centos_centos7_amd64_image
|
||||
<<: *build_job
|
||||
@@ -420,7 +423,7 @@ unit:gcc:centos7:amd64:
|
||||
gcc:centos8:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--with-libidn2"
|
||||
<<: *centos_centos8_amd64_image
|
||||
<<: *build_job
|
||||
@@ -444,7 +447,7 @@ unit:gcc:centos8:amd64:
|
||||
gcc:jessie:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON} -O2"
|
||||
EXTRA_CONFIGURE: "--without-cmocka --with-python --disable-geoip"
|
||||
<<: *debian_jessie_amd64_image
|
||||
<<: *build_job
|
||||
@@ -468,7 +471,7 @@ unit:gcc:jessie:amd64:
|
||||
gcc:stretch:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON} -O2"
|
||||
<<: *debian_stretch_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
@@ -491,7 +494,7 @@ unit:gcc:stretch:amd64:
|
||||
gcc:buster:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
<<: *debian_buster_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
@@ -525,7 +528,7 @@ scan-build:buster:amd64:
|
||||
stage: postcheck
|
||||
variables:
|
||||
CC: clang-9
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
CONFIGURE: "${SCAN_BUILD} ./configure"
|
||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||
script:
|
||||
@@ -546,7 +549,7 @@ scan-build:buster:amd64:
|
||||
gcc:sid:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O3 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON} -O3"
|
||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||
RUN_MAKE_INSTALL: 1
|
||||
MAKE: bear make
|
||||
@@ -579,7 +582,7 @@ cppcheck:gcc:sid:amd64:
|
||||
gcc:sid:i386:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O3 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2 --without-python"
|
||||
<<: *debian_sid_i386_image
|
||||
<<: *build_job
|
||||
@@ -603,7 +606,7 @@ unit:gcc:sid:i386:
|
||||
gcc:fedora30:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON} -O1"
|
||||
EXTRA_CONFIGURE: "--with-libidn2"
|
||||
<<: *fedora_30_amd64_image
|
||||
<<: *build_job
|
||||
@@ -627,7 +630,7 @@ unit:gcc:fedora30:amd64:
|
||||
gcc:xenial:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON} -O2"
|
||||
EXTRA_CONFIGURE: "--disable-geoip"
|
||||
<<: *ubuntu_xenial_amd64_image
|
||||
<<: *build_job
|
||||
@@ -651,7 +654,7 @@ unit:gcc:xenial:amd64:
|
||||
gcc:bionic:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON} -Og"
|
||||
EXTRA_CONFIGURE: "--with-libidn2"
|
||||
<<: *ubuntu_bionic_amd64_image
|
||||
<<: *build_job
|
||||
@@ -676,7 +679,7 @@ asan:sid:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
ASAN_OPTIONS: "detect_leaks=0"
|
||||
CFLAGS: "-Wall -Wextra -O2 -g -fsanitize=address,undefined -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||
CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||
LDFLAGS: "-fsanitize=address,undefined"
|
||||
EXTRA_CONFIGURE: "--with-libidn2"
|
||||
<<: *debian_sid_amd64_image
|
||||
@@ -699,7 +702,7 @@ unit:asan:sid:amd64:
|
||||
rwlock:sid:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||
CFLAGS: "${CFLAGS_COMMON} -Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock"
|
||||
<<: *debian_sid_amd64_image
|
||||
<<: *build_job
|
||||
@@ -722,7 +725,7 @@ unit:rwlock:sid:amd64:
|
||||
mutexatomics:sid:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||
CFLAGS: "${CFLAGS_COMMON} -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-mutex-atomics"
|
||||
<<: *debian_sid_amd64_image
|
||||
<<: *build_job
|
||||
@@ -747,7 +750,7 @@ mutexatomics:sid:amd64:
|
||||
clang:stretch:amd64:
|
||||
variables:
|
||||
CC: clang
|
||||
CFLAGS: "-Wall -Wextra -Wenum-conversion -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON} -Wenum-conversion"
|
||||
EXTRA_CONFIGURE: "--with-python=python3"
|
||||
<<: *debian_stretch_amd64_image
|
||||
<<: *build_job
|
||||
@@ -764,7 +767,7 @@ unit:clang:stretch:amd64:
|
||||
clang:stretch:i386:
|
||||
variables:
|
||||
CC: clang
|
||||
CFLAGS: "-Wall -Wextra -Wenum-conversion -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON} -Wenum-conversion"
|
||||
EXTRA_CONFIGURE: "--with-python=python2"
|
||||
<<: *debian_stretch_i386_image
|
||||
<<: *build_job
|
||||
@@ -774,7 +777,7 @@ clang:stretch:i386:
|
||||
pkcs11:sid:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--enable-native-pkcs11 --with-pkcs11=/usr/lib/softhsm/libsofthsm2.so"
|
||||
<<: *debian_sid_amd64_image
|
||||
<<: *build_job
|
||||
@@ -797,7 +800,7 @@ unit:pkcs11:sid:amd64:
|
||||
|
||||
clang:freebsd11.3:amd64:
|
||||
variables:
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
<<: *freebsd_amd64
|
||||
<<: *build_job
|
||||
|
||||
@@ -819,7 +822,7 @@ unit:clang:freebsd11.3:amd64:
|
||||
|
||||
clang:freebsd12.0:amd64:
|
||||
variables:
|
||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--enable-dnstap"
|
||||
<<: *freebsd_amd64
|
||||
<<: *build_job
|
||||
@@ -861,7 +864,7 @@ system:clang:openbsd6.5:amd64:
|
||||
nolibtool:sid:amd64:
|
||||
variables:
|
||||
CC: gcc
|
||||
CFLAGS: "-Wall -Wextra -Og -g"
|
||||
CFLAGS: "${CFLAGS_COMMON}"
|
||||
EXTRA_CONFIGURE: "--with-libidn2 --without-libtool --with-dlopen"
|
||||
<<: *debian_sid_amd64_image
|
||||
<<: *build_job
|
||||
|
||||
@@ -1,3 +1,40 @@
|
||||
5326. [bug] Add python dependancy on 'distutils.core' to configure.
|
||||
'distutils.core' is required for installation.
|
||||
[GL #1397]
|
||||
|
||||
5325. [bug] Addressed several issues with TCP connections in
|
||||
the netmgr: restored support for TCP connection
|
||||
timeouts, restored TCP backlog support, actively
|
||||
close all open sockets during shutdown. [GL #1312]
|
||||
|
||||
5324. [bug] Change the category of some log messages from general
|
||||
to the more appopriate catergory of xfer-in. [GL #1394]
|
||||
|
||||
5323. [bug] Fix a bug in DNSSEC trust anchor verification.
|
||||
[GL !2609]
|
||||
|
||||
5322. [placeholder]
|
||||
|
||||
5321. [bug] Obtain write lock before updating version->records
|
||||
and version->bytes. [GL #1341]
|
||||
|
||||
5320. [cleanup] Silence TSAN on header->count. [GL #1344]
|
||||
|
||||
--- 9.15.6 released ---
|
||||
|
||||
5319. [func] Trust anchors can now be configured using DS
|
||||
format to represent a key digest, by using the
|
||||
new "initial-ds" or "static-ds" keywords in
|
||||
the "dnssec-keys" statement.
|
||||
|
||||
Note: DNSKEY-format and DS-format trust anchors
|
||||
cannot both be used for the same domain name.
|
||||
[GL #622]
|
||||
|
||||
5318. [cleanup] The DNSSEC validation code has been refactored
|
||||
for clarity and to reduce code duplication.
|
||||
[GL #622]
|
||||
|
||||
5317. [func] A new asynchronous network communications system
|
||||
based on libuv is now used for listening for
|
||||
incoming requests and responding to them. (The
|
||||
@@ -49,7 +86,8 @@
|
||||
5307. [bug] Fix hang when named-compilezone output is sent to pipe.
|
||||
Thanks to Tony Finch. [GL !2481]
|
||||
|
||||
5306. [placeholder]
|
||||
5306. [security] Set a limit on number of simultaneous pipelined TCP
|
||||
queries. (CVE-2019-6477) [GL #1264]
|
||||
|
||||
5305. [bug] NSEC Aggressive Cache ("synth-from-dnssec") has been
|
||||
disabled by default because it was found to have
|
||||
|
||||
@@ -4,10 +4,11 @@ Supported platforms
|
||||
|
||||
In general, this version of BIND will build and run on any POSIX-compliant
|
||||
system with a C11-compliant C compiler, BSD-style sockets with
|
||||
RFC-compliant IPv6 support, POSIX-compliant threads, and the OpenSSL
|
||||
cryptography library. Atomic operations support from the compiler is
|
||||
needed, either in the form of builtin operations, C11 atomics or the
|
||||
Interlocked family of functions on Windows.
|
||||
RFC-compliant IPv6 support, POSIX-compliant threads, the libuv
|
||||
asynchronous I/O library, and the OpenSSL cryptography library. Atomic
|
||||
operations support from the compiler is needed, either in the form of
|
||||
builtin operations, C11 atomics, or the Interlocked family of functions on
|
||||
Windows.
|
||||
|
||||
BIND 9.15 requires fairly recent version of libuv library to run (>= 1.x).
|
||||
For some of the older systems listed below, you will have to install
|
||||
|
||||
+4
-4
@@ -12,10 +12,10 @@
|
||||
|
||||
In general, this version of BIND will build and run on any POSIX-compliant
|
||||
system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant
|
||||
IPv6 support, POSIX-compliant threads, and the OpenSSL cryptography library.
|
||||
Atomic operations support from the compiler is needed, either in the form of
|
||||
builtin operations, C11 atomics or the Interlocked family of functions on
|
||||
Windows.
|
||||
IPv6 support, POSIX-compliant threads, the `libuv` asynchronous I/O library,
|
||||
and the OpenSSL cryptography library. Atomic operations support from the
|
||||
compiler is needed, either in the form of builtin operations, C11 atomics,
|
||||
or the `Interlocked` family of functions on Windows.
|
||||
|
||||
BIND 9.15 requires fairly recent version of libuv library to run (>= 1.x). For
|
||||
some of the older systems listed below, you will have to install updated libuv
|
||||
|
||||
@@ -48,8 +48,8 @@ the file HISTORY.
|
||||
For a detailed list of changes made throughout the history of BIND 9, see
|
||||
the file CHANGES. See below for details on the CHANGES file format.
|
||||
|
||||
For up-to-date release notes and errata, see http://www.isc.org/software/
|
||||
bind9/releasenotes
|
||||
For up-to-date versions and release notes, see https://www.isc.org/
|
||||
download/.
|
||||
|
||||
For information about supported platforms, see PLATFORMS.
|
||||
|
||||
@@ -111,25 +111,30 @@ BIND 9.15 features
|
||||
BIND 9.15 is the newest development branch of BIND 9. It includes a number
|
||||
of changes from BIND 9.14 and earlier releases. New features include:
|
||||
|
||||
* New "dnssec-policy" statement to configure a key and signing policy
|
||||
for zones, enabling automatic key regeneration and rollover.
|
||||
* New new network manager based on libuv.
|
||||
* Support for the new GeoIP2 geolocation API
|
||||
* Improved DNSSEC key configuration using dnssec-keys
|
||||
* Improved DNSSEC trust anchor configuration using dnssec-keys,
|
||||
permitting configuration of trust anchors in DS as well as DNSKEY
|
||||
format.
|
||||
* YAML output for dig, mdig, and delv.
|
||||
|
||||
Building BIND
|
||||
|
||||
Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
||||
basic POSIX support, and a 64-bit integer type. Successful builds have
|
||||
been observed on many versions of Linux and UNIX, including RHEL/CentOS,
|
||||
Fedora, Debian, Ubuntu, SLES, openSUSE, Slackware, Alpine, FreeBSD,
|
||||
NetBSD, OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE, HP-UX, and
|
||||
OpenWRT.
|
||||
basic POSIX support, and a 64-bit integer type. BIND also requires the
|
||||
libuv asynchronous I/O library, and a cryptography provider library such
|
||||
as OpenSSL or a hardware service module supporting PKCS#11. On Linux, BIND
|
||||
requires the libcap library to set process privileges, though this
|
||||
requirement can be overridden by disabling capability support at compile
|
||||
time. See Compile-time options below for details on other libraries that
|
||||
may be required to support optional features.
|
||||
|
||||
BIND requires a cryptography provider library such as OpenSSL or a
|
||||
hardware service module supporting PKCS#11. On Linux, BIND requires the
|
||||
libcap library to set process privileges, though this requirement can be
|
||||
overridden by disabling capability support at compile time. See
|
||||
Compile-time options below for details on other libraries that may be
|
||||
required to support optional features.
|
||||
Successful builds have been observed on many versions of Linux and UNIX,
|
||||
including RHEL/CentOS, Fedora, Debian, Ubuntu, SLES, openSUSE, Slackware,
|
||||
Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE,
|
||||
HP-UX, and OpenWRT.
|
||||
|
||||
BIND is also available for Windows Server 2008 and higher. See win32utils/
|
||||
build.txt for details on building for Windows systems.
|
||||
|
||||
@@ -57,8 +57,8 @@ For a detailed list of changes made throughout the history of BIND 9, see
|
||||
the file [CHANGES](CHANGES). See [below](#changes) for details on the
|
||||
CHANGES file format.
|
||||
|
||||
For up-to-date release notes and errata, see
|
||||
[http://www.isc.org/software/bind9/releasenotes](http://www.isc.org/software/bind9/releasenotes)
|
||||
For up-to-date versions and release notes, see
|
||||
[https://www.isc.org/download/](https://www.isc.org/download/).
|
||||
|
||||
For information about supported platforms, see [PLATFORMS](PLATFORMS.md).
|
||||
|
||||
@@ -129,25 +129,29 @@ include:
|
||||
|
||||
* New "dnssec-policy" statement to configure a key and signing policy
|
||||
for zones, enabling automatic key regeneration and rollover.
|
||||
* A new network manager based on libuv.
|
||||
* New new network manager based on libuv.
|
||||
* Support for the new GeoIP2 geolocation API
|
||||
* Improved DNSSEC trust anchor configuration using `dnssec-keys`
|
||||
* Improved DNSSEC trust anchor configuration using `dnssec-keys`,
|
||||
permitting configuration of trust anchors in DS as well as
|
||||
DNSKEY format.
|
||||
* YAML output for `dig`, `mdig`, and `delv`.
|
||||
|
||||
### <a name="build"/> Building BIND
|
||||
|
||||
Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
||||
basic POSIX support, and a 64-bit integer type. Successful builds have been
|
||||
observed on many versions of Linux and UNIX, including RHEL/CentOS, Fedora,
|
||||
Debian, Ubuntu, SLES, openSUSE, Slackware, Alpine, FreeBSD, NetBSD,
|
||||
OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE, HP-UX, and OpenWRT.
|
||||
basic POSIX support, and a 64-bit integer type. BIND also requires the
|
||||
`libuv` asynchronous I/O library, and a cryptography provider library
|
||||
such as OpenSSL or a hardware service module supporting PKCS#11. On
|
||||
Linux, BIND requires the `libcap` library to set process privileges,
|
||||
though this requirement can be overridden by disabling capability
|
||||
support at compile time. See [Compile-time options](#opts) below
|
||||
for details on other libraries that may be required to support
|
||||
optional features.
|
||||
|
||||
BIND requires a cryptography provider library such as OpenSSL or a
|
||||
hardware service module supporting PKCS#11. On Linux, BIND requires
|
||||
the `libcap` library to set process privileges, though this requirement
|
||||
can be overridden by disabling capability support at compile time.
|
||||
See [Compile-time options](#opts) below for details on other libraries
|
||||
that may be required to support optional features.
|
||||
Successful builds have been observed on many versions of Linux and
|
||||
UNIX, including RHEL/CentOS, Fedora, Debian, Ubuntu, SLES, openSUSE,
|
||||
Slackware, Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris,
|
||||
OpenIndiana, OmniOS CE, HP-UX, and OpenWRT.
|
||||
|
||||
BIND is also available for Windows Server 2008 and higher. See
|
||||
`win32utils/build.txt` for details on building for Windows
|
||||
@@ -187,9 +191,11 @@ or if you have Xcode already installed you can run `xcode-select --install`.
|
||||
|
||||
Portions of BIND that are written in Python, including
|
||||
`dnssec-keymgr`, `dnssec-coverage`, `dnssec-checkds`, and some of the
|
||||
system tests, require the `argparse` and `ply` modules to be available.
|
||||
system tests, require the `argparse`, `ply` and `distutils.core` modules
|
||||
to be available.
|
||||
`argparse` is a standard module as of Python 2.7 and Python 3.2.
|
||||
`ply` is available from [https://pypi.python.org/pypi/ply](https://pypi.python.org/pypi/ply).
|
||||
`distutils.core` is required for installation.
|
||||
|
||||
#### <a name="opts"/> Compile-time options
|
||||
|
||||
|
||||
+142
-58
@@ -33,8 +33,10 @@
|
||||
#include <isc/app.h>
|
||||
#include <isc/base64.h>
|
||||
#include <isc/buffer.h>
|
||||
#include <isc/hex.h>
|
||||
#include <isc/lib.h>
|
||||
#include <isc/log.h>
|
||||
#include <isc/md.h>
|
||||
#include <isc/mem.h>
|
||||
#ifdef WIN32
|
||||
#include <isc/ntpaths.h>
|
||||
@@ -158,43 +160,44 @@ usage(void) {
|
||||
" q-class is one of (in,hs,ch,...) [default: in]\n"
|
||||
" q-type is one of (a,any,mx,ns,soa,hinfo,axfr,txt,...) [default:a]\n"
|
||||
" q-opt is one of:\n"
|
||||
" -x dot-notation (shortcut for reverse lookups)\n"
|
||||
" -d level (set debugging level)\n"
|
||||
" -4 (use IPv4 query transport only)\n"
|
||||
" -6 (use IPv6 query transport only)\n"
|
||||
" -a anchor-file (specify root trust anchor)\n"
|
||||
" -b address[#port] (bind to source address/port)\n"
|
||||
" -c class (option included for compatibility;\n"
|
||||
" -d level (set debugging level)\n"
|
||||
" -h (print help and exit)\n"
|
||||
" -i (disable DNSSEC validation)\n"
|
||||
" -m (enable memory usage debugging)\n"
|
||||
" -p port (specify port number)\n"
|
||||
" -q name (specify query name)\n"
|
||||
" -t type (specify query type)\n"
|
||||
" -c class (option included for compatibility;\n"
|
||||
" only IN is supported)\n"
|
||||
" -4 (use IPv4 query transport only)\n"
|
||||
" -6 (use IPv6 query transport only)\n"
|
||||
" -i (disable DNSSEC validation)\n"
|
||||
" -m (enable memory usage debugging)\n"
|
||||
" -v (print version and exit)\n"
|
||||
" -x dot-notation (shortcut for reverse lookups)\n"
|
||||
" d-opt is of the form +keyword[=value], where keyword is:\n"
|
||||
" +[no]all (Set or clear all display flags)\n"
|
||||
" +[no]class (Control display of class)\n"
|
||||
" +[no]comments (Control display of comment lines)\n"
|
||||
" +[no]crypto (Control display of cryptographic\n"
|
||||
" fields in records)\n"
|
||||
" +[no]dlv (Obsolete)\n"
|
||||
" +[no]dnssec (Display DNSSEC records)\n"
|
||||
" +[no]mtrace (Trace messages received)\n"
|
||||
" +[no]multiline (Print records in an expanded format)\n"
|
||||
" +[no]comments (Control display of comment lines)\n"
|
||||
" +[no]root (DNSSEC validation trust anchor)\n"
|
||||
" +[no]rrcomments (Control display of per-record "
|
||||
"comments)\n"
|
||||
" +[no]unknownformat (Print RDATA in RFC 3597 "
|
||||
"\"unknown\" format)\n"
|
||||
" +[no]rtrace (Trace resolver fetches)\n"
|
||||
" +[no]short (Short form answer)\n"
|
||||
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
||||
" +[no]tcp (TCP mode)\n"
|
||||
" +[no]ttl (Control display of ttls in records)\n"
|
||||
" +[no]trust (Control display of trust level)\n"
|
||||
" +[no]rtrace (Trace resolver fetches)\n"
|
||||
" +[no]mtrace (Trace messages received)\n"
|
||||
" +[no]unknownformat (Print RDATA in RFC 3597 "
|
||||
"\"unknown\" format)\n"
|
||||
" +[no]vtrace (Trace validation process)\n"
|
||||
" +[no]dlv (Obsolete)\n"
|
||||
" +[no]root (DNSSEC validation trust anchor)\n"
|
||||
" +[no]dnssec (Display DNSSEC records)\n"
|
||||
" -h (print help and exit)\n"
|
||||
" -v (print version and exit)\n",
|
||||
" +[no]yaml (Present the results as YAML)\n",
|
||||
stderr);
|
||||
exit(1);
|
||||
}
|
||||
@@ -495,14 +498,17 @@ printdata(dns_rdataset_t *rdataset, dns_name_t *owner,
|
||||
dns_rdata_reset(&rdata);
|
||||
}
|
||||
} else {
|
||||
dns_indent_t indent = { " ", 2 };
|
||||
if (!yaml && (rdataset->attributes &
|
||||
DNS_RDATASETATTR_NEGATIVE) != 0)
|
||||
{
|
||||
isc_buffer_putstr(&target, "; ");
|
||||
}
|
||||
|
||||
result = dns_master_rdatasettotext(owner, rdataset,
|
||||
style, &target);
|
||||
style,
|
||||
yaml ? &indent :
|
||||
NULL,
|
||||
&target);
|
||||
}
|
||||
|
||||
if (result == ISC_R_NOSPACE) {
|
||||
@@ -534,8 +540,6 @@ setup_style(dns_master_style_t **stylep) {
|
||||
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
||||
if (yaml) {
|
||||
styleflags |= DNS_STYLEFLAG_YAML;
|
||||
dns_master_indentstr = " ";
|
||||
dns_master_indent = 2;
|
||||
} else {
|
||||
if (showcomments) {
|
||||
styleflags |= DNS_STYLEFLAG_COMMENT;
|
||||
@@ -608,11 +612,12 @@ convert_name(dns_fixedname_t *fn, dns_name_t **name, const char *text) {
|
||||
|
||||
static isc_result_t
|
||||
key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
||||
dns_rdata_dnskey_t keystruct;
|
||||
uint32_t flags, proto, alg;
|
||||
const char *keystr, *keynamestr;
|
||||
unsigned char keydata[4096];
|
||||
isc_buffer_t keydatabuf;
|
||||
dns_rdata_dnskey_t dnskey;
|
||||
dns_rdata_ds_t ds;
|
||||
uint32_t n1, n2, n3;
|
||||
const char *datastr = NULL, *keynamestr = NULL, *atstr = NULL;
|
||||
unsigned char data[4096];
|
||||
isc_buffer_t databuf;
|
||||
unsigned char rrdata[4096];
|
||||
isc_buffer_t rrdatabuf;
|
||||
isc_region_t r;
|
||||
@@ -620,6 +625,13 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
||||
dns_name_t *keyname;
|
||||
isc_result_t result;
|
||||
bool match_root = false;
|
||||
enum {
|
||||
INITIAL_KEY,
|
||||
STATIC_KEY,
|
||||
INITIAL_DS,
|
||||
STATIC_DS,
|
||||
TRUSTED
|
||||
} anchortype;
|
||||
|
||||
keynamestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
||||
CHECK(convert_name(&fkeyname, &keyname, keynamestr));
|
||||
@@ -642,46 +654,118 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
||||
|
||||
delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s", trust_anchor);
|
||||
|
||||
flags = cfg_obj_asuint32(cfg_tuple_get(key, "flags"));
|
||||
proto = cfg_obj_asuint32(cfg_tuple_get(key, "protocol"));
|
||||
alg = cfg_obj_asuint32(cfg_tuple_get(key, "algorithm"));
|
||||
/* if DNSKEY, flags; if DS, key tag */
|
||||
n1 = cfg_obj_asuint32(cfg_tuple_get(key, "n1"));
|
||||
|
||||
keystruct.common.rdclass = dns_rdataclass_in;
|
||||
keystruct.common.rdtype = dns_rdatatype_dnskey;
|
||||
/*
|
||||
* The key data in keystruct is not dynamically allocated.
|
||||
*/
|
||||
keystruct.mctx = NULL;
|
||||
/* if DNSKEY, protocol; if DS, algorithm */
|
||||
n2 = cfg_obj_asuint32(cfg_tuple_get(key, "n2"));
|
||||
|
||||
ISC_LINK_INIT(&keystruct.common, link);
|
||||
/* if DNSKEY, algorithm; if DS, digest type */
|
||||
n3 = cfg_obj_asuint32(cfg_tuple_get(key, "n3"));
|
||||
|
||||
if (flags > 0xffff)
|
||||
CHECK(ISC_R_RANGE);
|
||||
if (proto > 0xff)
|
||||
CHECK(ISC_R_RANGE);
|
||||
if (alg > 0xff)
|
||||
CHECK(ISC_R_RANGE);
|
||||
/* What type of trust anchor is this? */
|
||||
atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype"));
|
||||
if (strcasecmp(atstr, "static-key") == 0) {
|
||||
anchortype = STATIC_KEY;
|
||||
} else if (strcasecmp(atstr, "static-ds") == 0) {
|
||||
anchortype = STATIC_DS;
|
||||
} else if (strcasecmp(atstr, "initial-key") == 0) {
|
||||
anchortype = INITIAL_KEY;
|
||||
} else if (strcasecmp(atstr, "initial-ds") == 0) {
|
||||
anchortype = INITIAL_DS;
|
||||
} else {
|
||||
delv_log(ISC_LOG_ERROR,
|
||||
"key '%s': invalid initialization method '%s'",
|
||||
keynamestr, atstr);
|
||||
result = ISC_R_FAILURE;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
keystruct.flags = (uint16_t)flags;
|
||||
keystruct.protocol = (uint8_t)proto;
|
||||
keystruct.algorithm = (uint8_t)alg;
|
||||
|
||||
isc_buffer_init(&keydatabuf, keydata, sizeof(keydata));
|
||||
isc_buffer_init(&databuf, data, sizeof(data));
|
||||
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
|
||||
|
||||
keystr = cfg_obj_asstring(cfg_tuple_get(key, "key"));
|
||||
CHECK(isc_base64_decodestring(keystr, &keydatabuf));
|
||||
isc_buffer_usedregion(&keydatabuf, &r);
|
||||
keystruct.datalen = r.length;
|
||||
keystruct.data = r.base;
|
||||
if (n1 > 0xffff) {
|
||||
CHECK(ISC_R_RANGE);
|
||||
}
|
||||
if (n2 > 0xff) {
|
||||
CHECK(ISC_R_RANGE);
|
||||
}
|
||||
if (n3 > 0xff) {
|
||||
CHECK(ISC_R_RANGE);
|
||||
}
|
||||
|
||||
CHECK(dns_rdata_fromstruct(NULL,
|
||||
keystruct.common.rdclass,
|
||||
keystruct.common.rdtype,
|
||||
&keystruct, &rrdatabuf));
|
||||
switch (anchortype) {
|
||||
case STATIC_KEY:
|
||||
case INITIAL_KEY:
|
||||
case TRUSTED:
|
||||
dnskey.common.rdclass = dns_rdataclass_in;
|
||||
dnskey.common.rdtype = dns_rdatatype_dnskey;
|
||||
dnskey.mctx = NULL;
|
||||
|
||||
ISC_LINK_INIT(&dnskey.common, link);
|
||||
|
||||
dnskey.flags = (uint16_t)n1;
|
||||
dnskey.protocol = (uint8_t)n2;
|
||||
dnskey.algorithm = (uint8_t)n3;
|
||||
|
||||
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
|
||||
CHECK(isc_base64_decodestring(datastr, &databuf));
|
||||
isc_buffer_usedregion(&databuf, &r);
|
||||
dnskey.datalen = r.length;
|
||||
dnskey.data = r.base;
|
||||
|
||||
CHECK(dns_rdata_fromstruct(NULL, dnskey.common.rdclass,
|
||||
dnskey.common.rdtype,
|
||||
&dnskey, &rrdatabuf));
|
||||
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
||||
dns_rdatatype_dnskey,
|
||||
keyname, &rrdatabuf));
|
||||
break;
|
||||
case INITIAL_DS:
|
||||
case STATIC_DS:
|
||||
ds.common.rdclass = dns_rdataclass_in;
|
||||
ds.common.rdtype = dns_rdatatype_ds;
|
||||
ds.mctx = NULL;
|
||||
|
||||
ISC_LINK_INIT(&ds.common, link);
|
||||
|
||||
ds.key_tag = (uint16_t)n1;
|
||||
ds.algorithm = (uint8_t)n2;
|
||||
ds.digest_type = (uint8_t)n3;
|
||||
|
||||
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
|
||||
CHECK(isc_hex_decodestring(datastr, &databuf));
|
||||
isc_buffer_usedregion(&databuf, &r);
|
||||
|
||||
switch (ds.digest_type) {
|
||||
case DNS_DSDIGEST_SHA1:
|
||||
if (r.length != ISC_SHA1_DIGESTLENGTH) {
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
break;
|
||||
case DNS_DSDIGEST_SHA256:
|
||||
if (r.length != ISC_SHA256_DIGESTLENGTH) {
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
break;
|
||||
case DNS_DSDIGEST_SHA384:
|
||||
if (r.length != ISC_SHA384_DIGESTLENGTH) {
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
break;
|
||||
}
|
||||
|
||||
ds.length = r.length;
|
||||
ds.digest = r.base;
|
||||
|
||||
CHECK(dns_rdata_fromstruct(NULL, ds.common.rdclass,
|
||||
ds.common.rdtype,
|
||||
&ds, &rrdatabuf));
|
||||
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
||||
dns_rdatatype_ds,
|
||||
keyname, &rrdatabuf));
|
||||
};
|
||||
|
||||
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
||||
keyname, &rrdatabuf));
|
||||
num_keys++;
|
||||
|
||||
cleanup:
|
||||
|
||||
+3
-2
@@ -239,6 +239,7 @@ help(void) {
|
||||
" +[no]unknownformat (Print RDATA in RFC 3597 \"unknown\" "
|
||||
"format)\n"
|
||||
" +[no]vc (TCP mode (+[no]tcp))\n"
|
||||
" +[no]yaml (Present the results as YAML)\n"
|
||||
" +[no]zflag (Set Z flag in query)\n"
|
||||
" global d-opts and servers (before host name) affect all queries.\n"
|
||||
" local d-opts and servers (after host name) affect only that lookup.\n"
|
||||
@@ -486,8 +487,8 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf,
|
||||
|
||||
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
||||
if (yaml) {
|
||||
dns_master_indentstr = " ";
|
||||
dns_master_indent = 3;
|
||||
msg->indent.string = " ";
|
||||
msg->indent.count = 3;
|
||||
styleflags |= DNS_STYLEFLAG_YAML;
|
||||
} else {
|
||||
if (query->lookup->comments) {
|
||||
|
||||
@@ -372,7 +372,7 @@ formatset(dns_rdataset_t *rdataset) {
|
||||
|
||||
result = isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE);
|
||||
check_result(result, "printing DS records");
|
||||
result = dns_master_rdatasettotext(name, rdataset, style, buf);
|
||||
result = dns_master_rdatasettotext(name, rdataset, style, NULL, buf);
|
||||
|
||||
if ((result == ISC_R_SUCCESS) && isc_buffer_availablelength(buf) < 1) {
|
||||
result = ISC_R_NOSPACE;
|
||||
|
||||
@@ -39,7 +39,7 @@
|
||||
dnssec-keygen \- DNSSEC key generation tool
|
||||
.SH "SYNOPSIS"
|
||||
.HP \w'\fBdnssec\-keygen\fR\ 'u
|
||||
\fBdnssec\-keygen\fR [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] {name}
|
||||
\fBdnssec\-keygen\fR [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-d\ \fR\fB\fIbits\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\ \fR\fB\fIpolicy\fR\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-l\ \fR\fB\fIfile\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-T\ \fR\fB\fIrrtype\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] {name}
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBdnssec\-keygen\fR
|
||||
@@ -109,6 +109,11 @@ option suppresses them\&.
|
||||
Indicates that the DNS record containing the key should have the specified class\&. If not specified, class IN is used\&.
|
||||
.RE
|
||||
.PP
|
||||
\-d \fIbits\fR
|
||||
.RS 4
|
||||
Key size in bits\&. For the algorithms RSASHA1, NSEC3RSASA1, RSASHA256 and RSASHA512 the key size must be in range 1024\-4096\&. DH size is between 128 and 4096\&. This option is ignored for algorithms ECDSAP256SHA256, ECDSAP384SHA384, ED25519 and ED448\&.
|
||||
.RE
|
||||
.PP
|
||||
\-E \fIengine\fR
|
||||
.RS 4
|
||||
Specifies the cryptographic hardware to use, when applicable\&.
|
||||
@@ -142,6 +147,17 @@ Prints a short summary of the options and arguments to
|
||||
Sets the directory in which the key files are to be written\&.
|
||||
.RE
|
||||
.PP
|
||||
\-k \fIpolicy\fR
|
||||
.RS 4
|
||||
Create keys for a specific dnssec\-policy\&. If a policy uses multiple keys,
|
||||
\fBdnssec\-keygen\fR
|
||||
will generate multiple keys\&. This will also create a "\&.state" file to keep track of the key state\&.
|
||||
.sp
|
||||
This option creates keys according to the dnssec\-policy configuration, hence it cannot be used together with many of the other options that
|
||||
\fBdnssec\-keygen\fR
|
||||
provides\&.
|
||||
.RE
|
||||
.PP
|
||||
\-L \fIttl\fR
|
||||
.RS 4
|
||||
Sets the default TTL to use for this key when it is converted into a DNSKEY RR\&. If the key is imported into a zone, this is the TTL that will be used for it, unless there was already a DNSKEY RRset in place, in which case the existing TTL would take precedence\&. If this value is not set and there is no existing DNSKEY RRset, the TTL will default to the SOA TTL\&. Setting the default TTL to
|
||||
@@ -151,6 +167,12 @@ none
|
||||
is the same as leaving it unset\&.
|
||||
.RE
|
||||
.PP
|
||||
\-l \fIfile\fR
|
||||
.RS 4
|
||||
Provide a configuration file that contains a dnssec\-policy statement (matching the policy set with
|
||||
\fB\-k\fR)\&.
|
||||
.RE
|
||||
.PP
|
||||
\-n \fInametype\fR
|
||||
.RS 4
|
||||
Specifies the owner type of the key\&. The value of
|
||||
|
||||
@@ -41,6 +41,7 @@
|
||||
[<code class="option">-c <em class="replaceable"><code>class</code></em></code>]
|
||||
[<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>]
|
||||
[<code class="option">-D sync <em class="replaceable"><code>date/offset</code></em></code>]
|
||||
[<code class="option">-d <em class="replaceable"><code>bits</code></em></code>]
|
||||
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
||||
[<code class="option">-f <em class="replaceable"><code>flag</code></em></code>]
|
||||
[<code class="option">-G</code>]
|
||||
@@ -49,8 +50,9 @@
|
||||
[<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>]
|
||||
[<code class="option">-i <em class="replaceable"><code>interval</code></em></code>]
|
||||
[<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
|
||||
[<code class="option">-k</code>]
|
||||
[<code class="option">-k <em class="replaceable"><code>policy</code></em></code>]
|
||||
[<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>]
|
||||
[<code class="option">-l <em class="replaceable"><code>file</code></em></code>]
|
||||
[<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
|
||||
[<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>]
|
||||
[<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>]
|
||||
@@ -59,6 +61,7 @@
|
||||
[<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>]
|
||||
[<code class="option">-S <em class="replaceable"><code>key</code></em></code>]
|
||||
[<code class="option">-s <em class="replaceable"><code>strength</code></em></code>]
|
||||
[<code class="option">-T <em class="replaceable"><code>rrtype</code></em></code>]
|
||||
[<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
|
||||
[<code class="option">-V</code>]
|
||||
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
||||
@@ -168,6 +171,15 @@
|
||||
the specified class. If not specified, class IN is used.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-d <em class="replaceable"><code>bits</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Key size in bits. For the algorithms RSASHA1, NSEC3RSASA1,
|
||||
RSASHA256 and RSASHA512 the key size must be in range 1024-4096.
|
||||
DH size is between 128 and 4096. This option is ignored for
|
||||
algorithms ECDSAP256SHA256, ECDSAP384SHA384, ED25519 and ED448.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
@@ -218,6 +230,21 @@
|
||||
Sets the directory in which the key files are to be written.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-k <em class="replaceable"><code>policy</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Create keys for a specific dnssec-policy. If a policy uses
|
||||
multiple keys, <span class="command"><strong>dnssec-keygen</strong></span> will generate
|
||||
multiple keys. This will also create a ".state" file to keep
|
||||
track of the key state.
|
||||
</p>
|
||||
<p>
|
||||
This option creates keys according to the dnssec-policy
|
||||
configuration, hence it cannot be used together with many of
|
||||
the other options that <span class="command"><strong>dnssec-keygen</strong></span>
|
||||
provides.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
@@ -231,6 +258,13 @@
|
||||
or <code class="literal">none</code> is the same as leaving it unset.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-l <em class="replaceable"><code>file</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Provide a configuration file that contains a dnssec-policy
|
||||
statement (matching the policy set with <span class="command"><strong>-k</strong></span>).
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
|
||||
@@ -39,7 +39,7 @@
|
||||
dnssec-settime \- set the key timing metadata for a DNSSEC key
|
||||
.SH "SYNOPSIS"
|
||||
.HP \w'\fBdnssec\-settime\fR\ 'u
|
||||
\fBdnssec\-settime\fR [\fB\-f\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-h\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] {keyfile}
|
||||
\fBdnssec\-settime\fR [\fB\-f\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-h\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-s\fR] [\fB\-g\ \fR\fB\fIstate\fR\fR] [\fB\-d\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] [\fB\-k\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] [\fB\-r\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] [\fB\-z\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] {keyfile}
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBdnssec\-settime\fR
|
||||
@@ -59,7 +59,25 @@ simply prints the key timing metadata already stored in the key\&.
|
||||
.PP
|
||||
When key metadata fields are changed, both files of a key pair (Knnnn\&.+aaa+iiiii\&.key
|
||||
and
|
||||
Knnnn\&.+aaa+iiiii\&.private) are regenerated\&. Metadata fields are stored in the private file\&. A human\-readable description of the metadata is also placed in comments in the key file\&. The private file\*(Aqs permissions are always set to be inaccessible to anyone other than the owner (mode 0600)\&.
|
||||
Knnnn\&.+aaa+iiiii\&.private) are regenerated\&.
|
||||
.PP
|
||||
Metadata fields are stored in the private file\&. A human\-readable description of the metadata is also placed in comments in the key file\&. The private file\*(Aqs permissions are always set to be inaccessible to anyone other than the owner (mode 0600)\&.
|
||||
.PP
|
||||
When working with state files, it is possible to update the timing metadata in those files as well with
|
||||
\fB\-s\fR\&. If this option is used you can also update key states with
|
||||
\fB\-d\fR
|
||||
(DS),
|
||||
\fB\-k\fR
|
||||
(DNSKEY),
|
||||
\fB\-r\fR
|
||||
(RRSIG of KSK), or
|
||||
\fB\-z\fR
|
||||
(RRSIG of ZSK)\&. Allowed states are HIDDEN, RUMOURED, OMNIPRESENT, and UNRETENTIVE\&.
|
||||
.PP
|
||||
You can also set the goal state of the key with
|
||||
\fB\-g\fR\&. This should be either HIDDEN or OMNIPRESENT (representing whether the key should be removed from the zone, or published)\&.
|
||||
.PP
|
||||
It is NOT RECOMMENDED to manipulate state files manually except for testing purposes\&.
|
||||
.SH "OPTIONS"
|
||||
.PP
|
||||
\-f
|
||||
@@ -156,6 +174,39 @@ If the key is being set to be an explicit successor to another key, then the def
|
||||
.sp
|
||||
As with date offsets, if the argument is followed by one of the suffixes \*(Aqy\*(Aq, \*(Aqmo\*(Aq, \*(Aqw\*(Aq, \*(Aqd\*(Aq, \*(Aqh\*(Aq, or \*(Aqmi\*(Aq, then the interval is measured in years, months, weeks, days, hours, or minutes, respectively\&. Without a suffix, the interval is measured in seconds\&.
|
||||
.RE
|
||||
.SH "KEY STATE OPTIONS"
|
||||
.PP
|
||||
Known key states are HIDDEN, RUMOURED, OMNIPRESENT and UNRETENTIVE\&. These should not be set manually except for testing purposes\&.
|
||||
.PP
|
||||
\-s
|
||||
.RS 4
|
||||
When setting key timing data, also update the state file\&.
|
||||
.RE
|
||||
.PP
|
||||
\-g
|
||||
.RS 4
|
||||
Set the goal state for this key\&. Must be HIDDEN or OMNIPRESENT\&.
|
||||
.RE
|
||||
.PP
|
||||
\-d
|
||||
.RS 4
|
||||
Set the DS state for this key, and when it was last changed\&.
|
||||
.RE
|
||||
.PP
|
||||
\-k
|
||||
.RS 4
|
||||
Set the DNSKEY state for this key, and when it was last changed\&.
|
||||
.RE
|
||||
.PP
|
||||
\-r
|
||||
.RS 4
|
||||
Set the RRSIG (KSK) state for this key, and when it was last changed\&.
|
||||
.RE
|
||||
.PP
|
||||
\-z
|
||||
.RS 4
|
||||
Set the RRSIG (ZSK) state for this key, and when it was last changed\&.
|
||||
.RE
|
||||
.SH "PRINTING OPTIONS"
|
||||
.PP
|
||||
\fBdnssec\-settime\fR
|
||||
|
||||
+145
-146
@@ -253,106 +253,6 @@ main(int argc, char **argv) {
|
||||
#define CMDLINE_FLAGS "A:D:d:E:fg:hI:i:K:k:L:P:p:R:r:S:suv:Vz:"
|
||||
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
||||
switch (ch) {
|
||||
case 'E':
|
||||
engine = isc_commandline_argument;
|
||||
break;
|
||||
case 'f':
|
||||
force = true;
|
||||
break;
|
||||
case 'p':
|
||||
p = isc_commandline_argument;
|
||||
if (!strcasecmp(p, "all")) {
|
||||
printcreate = true;
|
||||
printpub = true;
|
||||
printact = true;
|
||||
printrev = true;
|
||||
printinact = true;
|
||||
printdel = true;
|
||||
printsyncadd = true;
|
||||
printsyncdel = true;
|
||||
break;
|
||||
}
|
||||
|
||||
do {
|
||||
switch (*p++) {
|
||||
case 'C':
|
||||
printcreate = true;
|
||||
break;
|
||||
case 'P':
|
||||
if (!strncmp(p, "sync", 4)) {
|
||||
p += 4;
|
||||
printsyncadd = true;
|
||||
break;
|
||||
}
|
||||
printpub = true;
|
||||
break;
|
||||
case 'A':
|
||||
printact = true;
|
||||
break;
|
||||
case 'R':
|
||||
printrev = true;
|
||||
break;
|
||||
case 'I':
|
||||
printinact = true;
|
||||
break;
|
||||
case 'D':
|
||||
if (!strncmp(p, "sync", 4)) {
|
||||
p += 4;
|
||||
printsyncdel = true;
|
||||
break;
|
||||
}
|
||||
printdel = true;
|
||||
break;
|
||||
case ' ':
|
||||
break;
|
||||
default:
|
||||
usage();
|
||||
break;
|
||||
}
|
||||
} while (*p != '\0');
|
||||
break;
|
||||
case 'u':
|
||||
epoch = true;
|
||||
break;
|
||||
case 'K':
|
||||
/*
|
||||
* We don't have to copy it here, but do it to
|
||||
* simplify cleanup later
|
||||
*/
|
||||
directory = isc_mem_strdup(mctx,
|
||||
isc_commandline_argument);
|
||||
break;
|
||||
case 'L':
|
||||
ttl = strtottl(isc_commandline_argument);
|
||||
setttl = true;
|
||||
break;
|
||||
case 'v':
|
||||
verbose = strtol(isc_commandline_argument, &endp, 0);
|
||||
if (*endp != '\0')
|
||||
fatal("-v must be followed by a number");
|
||||
break;
|
||||
case 'P':
|
||||
/* -Psync ? */
|
||||
if (isoptarg("sync", argv, usage)) {
|
||||
if (unsetsyncadd || setsyncadd)
|
||||
fatal("-P sync specified more than "
|
||||
"once");
|
||||
|
||||
changed = true;
|
||||
syncadd = strtotime(isc_commandline_argument,
|
||||
now, now, &setsyncadd);
|
||||
unsetsyncadd = !setsyncadd;
|
||||
break;
|
||||
}
|
||||
(void)isoptarg("dnskey", argv, usage);
|
||||
if (setpub || unsetpub)
|
||||
fatal("-P specified more than once");
|
||||
|
||||
changed = true;
|
||||
pub = strtotime(isc_commandline_argument,
|
||||
now, now, &setpub);
|
||||
unsetpub = !setpub;
|
||||
break;
|
||||
case 'A':
|
||||
if (setact || unsetact)
|
||||
fatal("-A specified more than once");
|
||||
@@ -362,24 +262,6 @@ main(int argc, char **argv) {
|
||||
now, now, &setact);
|
||||
unsetact = !setact;
|
||||
break;
|
||||
case 'R':
|
||||
if (setrev || unsetrev)
|
||||
fatal("-R specified more than once");
|
||||
|
||||
changed = true;
|
||||
rev = strtotime(isc_commandline_argument,
|
||||
now, now, &setrev);
|
||||
unsetrev = !setrev;
|
||||
break;
|
||||
case 'I':
|
||||
if (setinact || unsetinact)
|
||||
fatal("-I specified more than once");
|
||||
|
||||
changed = true;
|
||||
inact = strtotime(isc_commandline_argument,
|
||||
now, now, &setinact);
|
||||
unsetinact = !setinact;
|
||||
break;
|
||||
case 'D':
|
||||
/* -Dsync ? */
|
||||
if (isoptarg("sync", argv, usage)) {
|
||||
@@ -403,14 +285,23 @@ main(int argc, char **argv) {
|
||||
now, now, &setdel);
|
||||
unsetdel = !setdel;
|
||||
break;
|
||||
case 'S':
|
||||
predecessor = isc_commandline_argument;
|
||||
case 'd':
|
||||
if (setds) {
|
||||
fatal("-d specified more than once");
|
||||
}
|
||||
|
||||
ds = strtokeystate(isc_commandline_argument);
|
||||
setds = true;
|
||||
/* time */
|
||||
(void)isoptarg(isc_commandline_argument, argv, usage);
|
||||
dstime = strtotime(isc_commandline_argument,
|
||||
now, now, &setdstime);
|
||||
break;
|
||||
case 'i':
|
||||
prepub = strtottl(isc_commandline_argument);
|
||||
case 'E':
|
||||
engine = isc_commandline_argument;
|
||||
break;
|
||||
case 's':
|
||||
write_state = true;
|
||||
case 'f':
|
||||
force = true;
|
||||
break;
|
||||
case 'g':
|
||||
if (setgoal) {
|
||||
@@ -426,17 +317,33 @@ main(int argc, char **argv) {
|
||||
}
|
||||
setgoal = true;
|
||||
break;
|
||||
case 'd':
|
||||
if (setds) {
|
||||
fatal("-d specified more than once");
|
||||
}
|
||||
case '?':
|
||||
if (isc_commandline_option != '?')
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
/* FALLTHROUGH */
|
||||
case 'h':
|
||||
/* Does not return. */
|
||||
usage();
|
||||
case 'I':
|
||||
if (setinact || unsetinact)
|
||||
fatal("-I specified more than once");
|
||||
|
||||
ds = strtokeystate(isc_commandline_argument);
|
||||
setds = true;
|
||||
/* time */
|
||||
(void)isoptarg(isc_commandline_argument, argv, usage);
|
||||
dstime = strtotime(isc_commandline_argument,
|
||||
now, now, &setdstime);
|
||||
changed = true;
|
||||
inact = strtotime(isc_commandline_argument,
|
||||
now, now, &setinact);
|
||||
unsetinact = !setinact;
|
||||
break;
|
||||
case 'i':
|
||||
prepub = strtottl(isc_commandline_argument);
|
||||
break;
|
||||
case 'K':
|
||||
/*
|
||||
* We don't have to copy it here, but do it to
|
||||
* simplify cleanup later
|
||||
*/
|
||||
directory = isc_mem_strdup(mctx,
|
||||
isc_commandline_argument);
|
||||
break;
|
||||
case 'k':
|
||||
if (setdnskey) {
|
||||
@@ -450,6 +357,93 @@ main(int argc, char **argv) {
|
||||
dnskeytime = strtotime(isc_commandline_argument,
|
||||
now, now, &setdnskeytime);
|
||||
break;
|
||||
case 'L':
|
||||
ttl = strtottl(isc_commandline_argument);
|
||||
setttl = true;
|
||||
break;
|
||||
case 'P':
|
||||
/* -Psync ? */
|
||||
if (isoptarg("sync", argv, usage)) {
|
||||
if (unsetsyncadd || setsyncadd)
|
||||
fatal("-P sync specified more than "
|
||||
"once");
|
||||
|
||||
changed = true;
|
||||
syncadd = strtotime(isc_commandline_argument,
|
||||
now, now, &setsyncadd);
|
||||
unsetsyncadd = !setsyncadd;
|
||||
break;
|
||||
}
|
||||
(void)isoptarg("dnskey", argv, usage);
|
||||
if (setpub || unsetpub)
|
||||
fatal("-P specified more than once");
|
||||
|
||||
changed = true;
|
||||
pub = strtotime(isc_commandline_argument,
|
||||
now, now, &setpub);
|
||||
unsetpub = !setpub;
|
||||
break;
|
||||
case 'p':
|
||||
p = isc_commandline_argument;
|
||||
if (!strcasecmp(p, "all")) {
|
||||
printcreate = true;
|
||||
printpub = true;
|
||||
printact = true;
|
||||
printrev = true;
|
||||
printinact = true;
|
||||
printdel = true;
|
||||
printsyncadd = true;
|
||||
printsyncdel = true;
|
||||
break;
|
||||
}
|
||||
|
||||
do {
|
||||
switch (*p++) {
|
||||
case 'A':
|
||||
printact = true;
|
||||
break;
|
||||
case 'C':
|
||||
printcreate = true;
|
||||
break;
|
||||
case 'D':
|
||||
if (!strncmp(p, "sync", 4)) {
|
||||
p += 4;
|
||||
printsyncdel = true;
|
||||
break;
|
||||
}
|
||||
printdel = true;
|
||||
break;
|
||||
case 'I':
|
||||
printinact = true;
|
||||
break;
|
||||
case 'P':
|
||||
if (!strncmp(p, "sync", 4)) {
|
||||
p += 4;
|
||||
printsyncadd = true;
|
||||
break;
|
||||
}
|
||||
printpub = true;
|
||||
break;
|
||||
case 'R':
|
||||
printrev = true;
|
||||
break;
|
||||
case ' ':
|
||||
break;
|
||||
default:
|
||||
usage();
|
||||
break;
|
||||
}
|
||||
} while (*p != '\0');
|
||||
break;
|
||||
case 'R':
|
||||
if (setrev || unsetrev)
|
||||
fatal("-R specified more than once");
|
||||
|
||||
changed = true;
|
||||
rev = strtotime(isc_commandline_argument,
|
||||
now, now, &setrev);
|
||||
unsetrev = !setrev;
|
||||
break;
|
||||
case 'r':
|
||||
if (setkrrsig) {
|
||||
fatal("-r specified more than once");
|
||||
@@ -462,6 +456,23 @@ main(int argc, char **argv) {
|
||||
krrsigtime = strtotime(isc_commandline_argument,
|
||||
now, now, &setkrrsigtime);
|
||||
break;
|
||||
case 'S':
|
||||
predecessor = isc_commandline_argument;
|
||||
break;
|
||||
case 's':
|
||||
write_state = true;
|
||||
break;
|
||||
case 'u':
|
||||
epoch = true;
|
||||
break;
|
||||
case 'V':
|
||||
/* Does not return. */
|
||||
version(program);
|
||||
case 'v':
|
||||
verbose = strtol(isc_commandline_argument, &endp, 0);
|
||||
if (*endp != '\0')
|
||||
fatal("-v must be followed by a number");
|
||||
break;
|
||||
case 'z':
|
||||
if (setzrrsig) {
|
||||
fatal("-z specified more than once");
|
||||
@@ -473,18 +484,6 @@ main(int argc, char **argv) {
|
||||
zrrsigtime = strtotime(isc_commandline_argument,
|
||||
now, now, &setzrrsigtime);
|
||||
break;
|
||||
case '?':
|
||||
if (isc_commandline_option != '?')
|
||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||
program, isc_commandline_option);
|
||||
/* FALLTHROUGH */
|
||||
case 'h':
|
||||
/* Does not return. */
|
||||
usage();
|
||||
|
||||
case 'V':
|
||||
/* Does not return. */
|
||||
version(program);
|
||||
|
||||
default:
|
||||
fprintf(stderr, "%s: unhandled option -%c\n",
|
||||
|
||||
@@ -49,6 +49,12 @@
|
||||
[<code class="option">-V</code>]
|
||||
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
||||
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
||||
[<code class="option">-s</code>]
|
||||
[<code class="option">-g <em class="replaceable"><code>state</code></em></code>]
|
||||
[<code class="option">-d <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||
[<code class="option">-k <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||
[<code class="option">-r <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||
[<code class="option">-z <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||
{keyfile}
|
||||
</p></div>
|
||||
</div>
|
||||
@@ -74,11 +80,30 @@
|
||||
When key metadata fields are changed, both files of a key
|
||||
pair (<code class="filename">Knnnn.+aaa+iiiii.key</code> and
|
||||
<code class="filename">Knnnn.+aaa+iiiii.private</code>) are regenerated.
|
||||
</p>
|
||||
<p>
|
||||
Metadata fields are stored in the private file. A human-readable
|
||||
description of the metadata is also placed in comments in the key
|
||||
file. The private file's permissions are always set to be
|
||||
inaccessible to anyone other than the owner (mode 0600).
|
||||
</p>
|
||||
<p>
|
||||
When working with state files, it is possible to update the timing
|
||||
metadata in those files as well with <code class="option">-s</code>. If this
|
||||
option is used you can also update key states with <code class="option">-d</code>
|
||||
(DS), <code class="option">-k</code> (DNSKEY), <code class="option">-r</code> (RRSIG of KSK),
|
||||
or <code class="option">-z</code> (RRSIG of ZSK). Allowed states are HIDDEN,
|
||||
RUMOURED, OMNIPRESENT, and UNRETENTIVE.
|
||||
</p>
|
||||
<p>
|
||||
You can also set the goal state of the key with <code class="option">-g</code>.
|
||||
This should be either HIDDEN or OMNIPRESENT (representing whether the
|
||||
key should be removed from the zone, or published).
|
||||
</p>
|
||||
<p>
|
||||
It is NOT RECOMMENDED to manipulate state files manually except for
|
||||
testing purposes.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
@@ -262,7 +287,57 @@
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.10"></a><h2>PRINTING OPTIONS</h2>
|
||||
<a name="id-1.10"></a><h2>KEY STATE OPTIONS</h2>
|
||||
|
||||
<p>
|
||||
Known key states are HIDDEN, RUMOURED, OMNIPRESENT and UNRETENTIVE.
|
||||
These should not be set manually except for testing purposes.
|
||||
</p>
|
||||
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term">-s</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
When setting key timing data, also update the state file.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-g</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Set the goal state for this key. Must be HIDDEN or OMNIPRESENT.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-d</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Set the DS state for this key, and when it was last changed.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-k</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Set the DNSKEY state for this key, and when it was last changed.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-r</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Set the RRSIG (KSK) state for this key, and when it was last
|
||||
changed.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-z</span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Set the RRSIG (ZSK) state for this key, and when it was last
|
||||
changed.
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.11"></a><h2>PRINTING OPTIONS</h2>
|
||||
|
||||
<p>
|
||||
<span class="command"><strong>dnssec-settime</strong></span> can also be used to print the
|
||||
@@ -298,7 +373,7 @@
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.11"></a><h2>SEE ALSO</h2>
|
||||
<a name="id-1.12"></a><h2>SEE ALSO</h2>
|
||||
|
||||
<p><span class="citerefentry">
|
||||
<span class="refentrytitle">dnssec-keygen</span>(8)
|
||||
|
||||
@@ -246,7 +246,8 @@ dumpnode(dns_name_t *name, dns_dbnode_t *node) {
|
||||
|
||||
for (;;) {
|
||||
result = dns_master_rdatasettotext(name, &rds,
|
||||
masterstyle, buffer);
|
||||
masterstyle, NULL,
|
||||
buffer);
|
||||
if (result != ISC_R_NOSPACE)
|
||||
break;
|
||||
|
||||
|
||||
+13
-1
@@ -939,11 +939,23 @@ create_managers(void) {
|
||||
static void
|
||||
destroy_managers(void) {
|
||||
/*
|
||||
* isc_taskmgr_destroy() will block until all tasks have exited,
|
||||
* isc_nm_closedown() closes all active connections, freeing
|
||||
* attached clients and other resources and preventing new
|
||||
* connections from being established, but it not does not
|
||||
* stop all processing or destroy the netmgr yet.
|
||||
*/
|
||||
isc_nm_closedown(named_g_nm);
|
||||
|
||||
/*
|
||||
* isc_taskmgr_destroy() will block until all tasks have exited.
|
||||
*/
|
||||
isc_taskmgr_destroy(&named_g_taskmgr);
|
||||
isc_timermgr_destroy(&named_g_timermgr);
|
||||
isc_socketmgr_destroy(&named_g_socketmgr);
|
||||
|
||||
/*
|
||||
* At this point is safe to destroy the netmgr.
|
||||
*/
|
||||
isc_nm_destroy(&named_g_nm);
|
||||
}
|
||||
|
||||
|
||||
+73
-44
@@ -10,12 +10,12 @@
|
||||
.\" Title: named.conf
|
||||
.\" Author:
|
||||
.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
|
||||
.\" Date: 2019-08-07
|
||||
.\" Date: 2019-08-12
|
||||
.\" Manual: BIND9
|
||||
.\" Source: ISC
|
||||
.\" Language: English
|
||||
.\"
|
||||
.TH "NAMED\&.CONF" "5" "2019\-08\-07" "ISC" "BIND9"
|
||||
.TH "NAMED\&.CONF" "5" "2019\-08\-12" "ISC" "BIND9"
|
||||
.\" -----------------------------------------------------------------
|
||||
.\" * Define some portability stuff
|
||||
.\" -----------------------------------------------------------------
|
||||
@@ -104,7 +104,8 @@ dlz \fIstring\fR {
|
||||
.\}
|
||||
.nf
|
||||
dnssec\-keys { \fIstring\fR ( static\-key |
|
||||
initial\-key ) \fIinteger\fR \fIinteger\fR \fIinteger\fR
|
||||
initial\-key | static\-ds | initial\-ds )
|
||||
\fIinteger\fR \fIinteger\fR \fIinteger\fR
|
||||
\fIquoted_string\fR; \&.\&.\&. };
|
||||
.fi
|
||||
.if n \{\
|
||||
@@ -170,9 +171,9 @@ Deprecated \- see DNSSEC\-KEYS\&.
|
||||
.\}
|
||||
.nf
|
||||
managed\-keys { \fIstring\fR ( static\-key
|
||||
| initial\-key ) \fIinteger\fR
|
||||
\fIinteger\fR \fIinteger\fR
|
||||
\fIquoted_string\fR; \&.\&.\&. }; deprecated
|
||||
| initial\-key | static\-ds |
|
||||
initial\-ds ) \fIinteger\fR \fIinteger\fR
|
||||
\fIinteger\fR \fIquoted_string\fR; \&.\&.\&. }; deprecated
|
||||
.fi
|
||||
.if n \{\
|
||||
.RE
|
||||
@@ -230,7 +231,7 @@ options {
|
||||
[ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [ port
|
||||
\fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
|
||||
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
|
||||
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIttlval\fR ]; \&.\&.\&. };
|
||||
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIduration\fR ]; \&.\&.\&. };
|
||||
check\-dup\-records ( fail | warn | ignore );
|
||||
check\-integrity \fIboolean\fR;
|
||||
check\-mx ( fail | warn | ignore );
|
||||
@@ -312,18 +313,18 @@ options {
|
||||
fstrm\-set\-output\-notify\-threshold \fIinteger\fR;
|
||||
fstrm\-set\-output\-queue\-model ( mpsc | spsc );
|
||||
fstrm\-set\-output\-queue\-size \fIinteger\fR;
|
||||
fstrm\-set\-reopen\-interval \fIttlval\fR;
|
||||
fstrm\-set\-reopen\-interval \fIduration\fR;
|
||||
geoip\-directory ( \fIquoted_string\fR | none );
|
||||
glue\-cache \fIboolean\fR;
|
||||
heartbeat\-interval \fIinteger\fR;
|
||||
hostname ( \fIquoted_string\fR | none );
|
||||
inline\-signing \fIboolean\fR;
|
||||
interface\-interval \fIttlval\fR;
|
||||
interface\-interval \fIduration\fR;
|
||||
ixfr\-from\-differences ( primary | master | secondary | slave |
|
||||
\fIboolean\fR );
|
||||
keep\-response\-order { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||
key\-directory \fIquoted_string\fR;
|
||||
lame\-ttl \fIttlval\fR;
|
||||
lame\-ttl \fIduration\fR;
|
||||
listen\-on [ port \fIinteger\fR ] [ dscp
|
||||
\fIinteger\fR ] {
|
||||
\fIaddress_match_element\fR; \&.\&.\&. };
|
||||
@@ -337,28 +338,28 @@ options {
|
||||
masterfile\-style ( full | relative );
|
||||
match\-mapped\-addresses \fIboolean\fR;
|
||||
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
|
||||
max\-cache\-ttl \fIttlval\fR;
|
||||
max\-cache\-ttl \fIduration\fR;
|
||||
max\-clients\-per\-query \fIinteger\fR;
|
||||
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
|
||||
max\-ncache\-ttl \fIttlval\fR;
|
||||
max\-ncache\-ttl \fIduration\fR;
|
||||
max\-records \fIinteger\fR;
|
||||
max\-recursion\-depth \fIinteger\fR;
|
||||
max\-recursion\-queries \fIinteger\fR;
|
||||
max\-refresh\-time \fIinteger\fR;
|
||||
max\-retry\-time \fIinteger\fR;
|
||||
max\-rsa\-exponent\-size \fIinteger\fR;
|
||||
max\-stale\-ttl \fIttlval\fR;
|
||||
max\-stale\-ttl \fIduration\fR;
|
||||
max\-transfer\-idle\-in \fIinteger\fR;
|
||||
max\-transfer\-idle\-out \fIinteger\fR;
|
||||
max\-transfer\-time\-in \fIinteger\fR;
|
||||
max\-transfer\-time\-out \fIinteger\fR;
|
||||
max\-udp\-size \fIinteger\fR;
|
||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
||||
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||
memstatistics \fIboolean\fR;
|
||||
memstatistics\-file \fIquoted_string\fR;
|
||||
message\-compression \fIboolean\fR;
|
||||
min\-cache\-ttl \fIttlval\fR;
|
||||
min\-ncache\-ttl \fIttlval\fR;
|
||||
min\-cache\-ttl \fIduration\fR;
|
||||
min\-ncache\-ttl \fIduration\fR;
|
||||
min\-refresh\-time \fIinteger\fR;
|
||||
min\-retry\-time \fIinteger\fR;
|
||||
minimal\-any \fIboolean\fR;
|
||||
@@ -375,8 +376,8 @@ options {
|
||||
notify\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) ]
|
||||
[ dscp \fIinteger\fR ];
|
||||
notify\-to\-soa \fIboolean\fR;
|
||||
nta\-lifetime \fIttlval\fR;
|
||||
nta\-recheck \fIttlval\fR;
|
||||
nta\-lifetime \fIduration\fR;
|
||||
nta\-recheck \fIduration\fR;
|
||||
nxdomain\-redirect \fIstring\fR;
|
||||
pid\-file ( \fIquoted_string\fR | none );
|
||||
port \fIinteger\fR;
|
||||
@@ -423,13 +424,13 @@ options {
|
||||
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
|
||||
\fIinteger\fR;
|
||||
response\-policy { zone \fIstring\fR [ add\-soa \fIboolean\fR ] [ log
|
||||
\fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [ min\-update\-interval
|
||||
\fIttlval\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
||||
\fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [ min\-update\-interval
|
||||
\fIduration\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
||||
nodata | nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
|
||||
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ add\-soa \fIboolean\fR ] [
|
||||
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [
|
||||
min\-update\-interval \fIttlval\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
||||
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [
|
||||
min\-update\-interval \fIduration\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
||||
nsip\-wait\-recurse \fIboolean\fR ] [ qname\-wait\-recurse \fIboolean\fR ]
|
||||
[ recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||
nsdname\-enable \fIboolean\fR ] [ dnsrps\-enable \fIboolean\fR ] [
|
||||
@@ -443,7 +444,7 @@ options {
|
||||
serial\-query\-rate \fIinteger\fR;
|
||||
serial\-update\-method ( date | increment | unixtime );
|
||||
server\-id ( \fIquoted_string\fR | none | hostname );
|
||||
servfail\-ttl \fIttlval\fR;
|
||||
servfail\-ttl \fIduration\fR;
|
||||
session\-keyalg \fIstring\fR;
|
||||
session\-keyfile ( \fIquoted_string\fR | none );
|
||||
session\-keyname \fIstring\fR;
|
||||
@@ -454,7 +455,7 @@ options {
|
||||
sortlist { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||
stacksize ( default | unlimited | \fIsizeval\fR );
|
||||
stale\-answer\-enable \fIboolean\fR;
|
||||
stale\-answer\-ttl \fIttlval\fR;
|
||||
stale\-answer\-ttl \fIduration\fR;
|
||||
startup\-notify\-rate \fIinteger\fR;
|
||||
statistics\-file \fIquoted_string\fR;
|
||||
synth\-from\-dnssec \fIboolean\fR;
|
||||
@@ -612,7 +613,7 @@ view \fIstring\fR [ \fIclass\fR ] {
|
||||
[ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [ port
|
||||
\fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
|
||||
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
|
||||
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIttlval\fR ]; \&.\&.\&. };
|
||||
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIduration\fR ]; \&.\&.\&. };
|
||||
check\-dup\-records ( fail | warn | ignore );
|
||||
check\-integrity \fIboolean\fR;
|
||||
check\-mx ( fail | warn | ignore );
|
||||
@@ -655,8 +656,9 @@ view \fIstring\fR [ \fIclass\fR ] {
|
||||
dnssec\-accept\-expired \fIboolean\fR;
|
||||
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
||||
dnssec\-keys { \fIstring\fR ( static\-key |
|
||||
initial\-key ) \fIinteger\fR \fIinteger\fR
|
||||
\fIinteger\fR \fIquoted_string\fR; \&.\&.\&. };
|
||||
initial\-key | static\-ds | initial\-ds
|
||||
) \fIinteger\fR \fIinteger\fR \fIinteger\fR
|
||||
\fIquoted_string\fR; \&.\&.\&. };
|
||||
dnssec\-loadkeys\-interval \fIinteger\fR;
|
||||
dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR;
|
||||
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
||||
@@ -690,10 +692,11 @@ view \fIstring\fR [ \fIclass\fR ] {
|
||||
secret \fIstring\fR;
|
||||
};
|
||||
key\-directory \fIquoted_string\fR;
|
||||
lame\-ttl \fIttlval\fR;
|
||||
lame\-ttl \fIduration\fR;
|
||||
lmdb\-mapsize \fIsizeval\fR;
|
||||
managed\-keys { \fIstring\fR (
|
||||
static\-key | initial\-key
|
||||
| static\-ds | initial\-ds
|
||||
) \fIinteger\fR \fIinteger\fR
|
||||
\fIinteger\fR
|
||||
\fIquoted_string\fR; \&.\&.\&. }; deprecated
|
||||
@@ -703,25 +706,25 @@ view \fIstring\fR [ \fIclass\fR ] {
|
||||
match\-destinations { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||
match\-recursive\-only \fIboolean\fR;
|
||||
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
|
||||
max\-cache\-ttl \fIttlval\fR;
|
||||
max\-cache\-ttl \fIduration\fR;
|
||||
max\-clients\-per\-query \fIinteger\fR;
|
||||
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
|
||||
max\-ncache\-ttl \fIttlval\fR;
|
||||
max\-ncache\-ttl \fIduration\fR;
|
||||
max\-records \fIinteger\fR;
|
||||
max\-recursion\-depth \fIinteger\fR;
|
||||
max\-recursion\-queries \fIinteger\fR;
|
||||
max\-refresh\-time \fIinteger\fR;
|
||||
max\-retry\-time \fIinteger\fR;
|
||||
max\-stale\-ttl \fIttlval\fR;
|
||||
max\-stale\-ttl \fIduration\fR;
|
||||
max\-transfer\-idle\-in \fIinteger\fR;
|
||||
max\-transfer\-idle\-out \fIinteger\fR;
|
||||
max\-transfer\-time\-in \fIinteger\fR;
|
||||
max\-transfer\-time\-out \fIinteger\fR;
|
||||
max\-udp\-size \fIinteger\fR;
|
||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
||||
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||
message\-compression \fIboolean\fR;
|
||||
min\-cache\-ttl \fIttlval\fR;
|
||||
min\-ncache\-ttl \fIttlval\fR;
|
||||
min\-cache\-ttl \fIduration\fR;
|
||||
min\-ncache\-ttl \fIduration\fR;
|
||||
min\-refresh\-time \fIinteger\fR;
|
||||
min\-retry\-time \fIinteger\fR;
|
||||
minimal\-any \fIboolean\fR;
|
||||
@@ -737,8 +740,8 @@ view \fIstring\fR [ \fIclass\fR ] {
|
||||
notify\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) ]
|
||||
[ dscp \fIinteger\fR ];
|
||||
notify\-to\-soa \fIboolean\fR;
|
||||
nta\-lifetime \fIttlval\fR;
|
||||
nta\-recheck \fIttlval\fR;
|
||||
nta\-lifetime \fIduration\fR;
|
||||
nta\-recheck \fIduration\fR;
|
||||
nxdomain\-redirect \fIstring\fR;
|
||||
plugin ( query ) \fIstring\fR [ {
|
||||
\fIunspecified\-text\fR } ];
|
||||
@@ -780,13 +783,13 @@ view \fIstring\fR [ \fIclass\fR ] {
|
||||
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
|
||||
\fIinteger\fR;
|
||||
response\-policy { zone \fIstring\fR [ add\-soa \fIboolean\fR ] [ log
|
||||
\fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [ min\-update\-interval
|
||||
\fIttlval\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
||||
\fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [ min\-update\-interval
|
||||
\fIduration\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
||||
nodata | nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
|
||||
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ add\-soa \fIboolean\fR ] [
|
||||
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [
|
||||
min\-update\-interval \fIttlval\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
||||
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [
|
||||
min\-update\-interval \fIduration\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
||||
nsip\-wait\-recurse \fIboolean\fR ] [ qname\-wait\-recurse \fIboolean\fR ]
|
||||
[ recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||
nsdname\-enable \fIboolean\fR ] [ dnsrps\-enable \fIboolean\fR ] [
|
||||
@@ -831,14 +834,14 @@ view \fIstring\fR [ \fIclass\fR ] {
|
||||
\fIinteger\fR | * ) ] [ dscp \fIinteger\fR ];
|
||||
transfers \fIinteger\fR;
|
||||
};
|
||||
servfail\-ttl \fIttlval\fR;
|
||||
servfail\-ttl \fIduration\fR;
|
||||
sig\-signing\-nodes \fIinteger\fR;
|
||||
sig\-signing\-signatures \fIinteger\fR;
|
||||
sig\-signing\-type \fIinteger\fR;
|
||||
sig\-validity\-interval \fIinteger\fR [ \fIinteger\fR ];
|
||||
sortlist { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||
stale\-answer\-enable \fIboolean\fR;
|
||||
stale\-answer\-ttl \fIttlval\fR;
|
||||
stale\-answer\-ttl \fIduration\fR;
|
||||
synth\-from\-dnssec \fIboolean\fR;
|
||||
transfer\-format ( many\-answers | one\-answer );
|
||||
transfer\-source ( \fIipv4_address\fR | * ) [ port ( \fIinteger\fR | * ) ] [
|
||||
@@ -890,6 +893,7 @@ view \fIstring\fR [ \fIclass\fR ] {
|
||||
dnskey\-sig\-validity \fIinteger\fR;
|
||||
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
||||
dnssec\-loadkeys\-interval \fIinteger\fR;
|
||||
dnssec\-policy \fIstring\fR;
|
||||
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
||||
dnssec\-update\-mode ( maintain | no\-resign );
|
||||
file \fIquoted_string\fR;
|
||||
@@ -915,7 +919,7 @@ view \fIstring\fR [ \fIclass\fR ] {
|
||||
max\-transfer\-idle\-out \fIinteger\fR;
|
||||
max\-transfer\-time\-in \fIinteger\fR;
|
||||
max\-transfer\-time\-out \fIinteger\fR;
|
||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
||||
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||
min\-refresh\-time \fIinteger\fR;
|
||||
min\-retry\-time \fIinteger\fR;
|
||||
multi\-master \fIboolean\fR;
|
||||
@@ -996,6 +1000,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
|
||||
dnskey\-sig\-validity \fIinteger\fR;
|
||||
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
||||
dnssec\-loadkeys\-interval \fIinteger\fR;
|
||||
dnssec\-policy \fIstring\fR;
|
||||
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
||||
dnssec\-update\-mode ( maintain | no\-resign );
|
||||
file \fIquoted_string\fR;
|
||||
@@ -1020,7 +1025,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
|
||||
max\-transfer\-idle\-out \fIinteger\fR;
|
||||
max\-transfer\-time\-in \fIinteger\fR;
|
||||
max\-transfer\-time\-out \fIinteger\fR;
|
||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
||||
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||
min\-refresh\-time \fIinteger\fR;
|
||||
min\-retry\-time \fIinteger\fR;
|
||||
multi\-master \fIboolean\fR;
|
||||
@@ -1062,6 +1067,30 @@ zone \fIstring\fR [ \fIclass\fR ] {
|
||||
.if n \{\
|
||||
.RE
|
||||
.\}
|
||||
.SH "DNSSEC-POLICY"
|
||||
.sp
|
||||
.if n \{\
|
||||
.RS 4
|
||||
.\}
|
||||
.nf
|
||||
dnssec\-policy \fIstring\fR {
|
||||
dnskey\-ttl \fIttlval\fR;
|
||||
keys { ( csk | ksk | zsk ) key\-directory lifetime \fIduration\fR algorithm \fIinteger\fR [ \fIinteger\fR ] ; \&.\&.\&. };
|
||||
parent\-ds\-ttl \fIduration\fR;
|
||||
parent\-propagation\-delay \fIduration\fR;
|
||||
parent\-registration\-delay \fIduration\fR;
|
||||
publish\-safety \fIduration\fR;
|
||||
retire\-safety \fIduration\fR;
|
||||
signatures\-refresh \fIduration\fR;
|
||||
signatures\-validity \fIduration\fR;
|
||||
signatures\-validity\-dnskey \fIduration\fR;
|
||||
zone\-max\-ttl \fIduration\fR;
|
||||
zone\-propagation\-delay \fIduration\fR;
|
||||
};
|
||||
.fi
|
||||
.if n \{\
|
||||
.RE
|
||||
.\}
|
||||
.SH "FILES"
|
||||
.PP
|
||||
/etc/named\&.conf
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
|
||||
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.named.conf">
|
||||
<info>
|
||||
<date>2019-08-07</date>
|
||||
<date>2019-08-12</date>
|
||||
</info>
|
||||
<refentryinfo>
|
||||
<corpname>ISC</corpname>
|
||||
@@ -113,7 +113,8 @@ dlz <replaceable>string</replaceable> {
|
||||
<refsection><info><title>DNSSEC-KEYS</title></info>
|
||||
<literallayout class="normal">
|
||||
dnssec-keys { <replaceable>string</replaceable> ( static-key |
|
||||
initial-key ) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||
initial-key | static-ds | initial-ds )
|
||||
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||
<replaceable>quoted_string</replaceable>; ... };
|
||||
</literallayout>
|
||||
</refsection>
|
||||
@@ -158,9 +159,9 @@ logging {
|
||||
<para>Deprecated - see DNSSEC-KEYS.</para>
|
||||
<literallayout class="normal">
|
||||
managed-keys { <replaceable>string</replaceable> ( static-key
|
||||
| initial-key ) <replaceable>integer</replaceable>
|
||||
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||
<replaceable>quoted_string</replaceable>; ... }; deprecated
|
||||
| initial-key | static-ds |
|
||||
initial-ds ) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||
<replaceable>integer</replaceable> <replaceable>quoted_string</replaceable>; ... }; deprecated
|
||||
</literallayout>
|
||||
</refsection>
|
||||
|
||||
@@ -607,8 +608,9 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
||||
dnssec-accept-expired <replaceable>boolean</replaceable>;
|
||||
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
|
||||
dnssec-keys { <replaceable>string</replaceable> ( static-key |
|
||||
initial-key ) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||
<replaceable>integer</replaceable> <replaceable>quoted_string</replaceable>; ... };
|
||||
initial-key | static-ds | initial-ds
|
||||
) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||
<replaceable>quoted_string</replaceable>; ... };
|
||||
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
|
||||
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
|
||||
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
||||
@@ -646,6 +648,7 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
||||
lmdb-mapsize <replaceable>sizeval</replaceable>;
|
||||
managed-keys { <replaceable>string</replaceable> (
|
||||
static-key | initial-key
|
||||
| static-ds | initial-ds
|
||||
) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||
<replaceable>integer</replaceable>
|
||||
<replaceable>quoted_string</replaceable>; ... }; deprecated
|
||||
|
||||
+70
-44
@@ -95,7 +95,8 @@ dlz
|
||||
<a name="id-1.11"></a><h2>DNSSEC-KEYS</h2>
|
||||
<div class="literallayout"><p><br>
|
||||
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
|
||||
initial-key ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||
initial-key | static-ds | initial-ds )<br>
|
||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||
<em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
||||
</p></div>
|
||||
</div>
|
||||
@@ -144,9 +145,9 @@ logging
|
||||
<p>Deprecated - see DNSSEC-KEYS.</p>
|
||||
<div class="literallayout"><p><br>
|
||||
managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br>
|
||||
| initial-key ) <em class="replaceable"><code>integer</code></em><br>
|
||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||
<em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
||||
| initial-key | static-ds |<br>
|
||||
initial-ds ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
||||
</p></div>
|
||||
</div>
|
||||
|
||||
@@ -196,7 +197,7 @@ options
|
||||
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port<br>
|
||||
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key<br>
|
||||
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [<br>
|
||||
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>ttlval</code></em> ]; ... };<br>
|
||||
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>duration</code></em> ]; ... };<br>
|
||||
check-dup-records ( fail | warn | ignore );<br>
|
||||
check-integrity <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
check-mx ( fail | warn | ignore );<br>
|
||||
@@ -278,18 +279,18 @@ options
|
||||
fstrm-set-output-notify-threshold <em class="replaceable"><code>integer</code></em>;<br>
|
||||
fstrm-set-output-queue-model ( mpsc | spsc );<br>
|
||||
fstrm-set-output-queue-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||
fstrm-set-reopen-interval <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
fstrm-set-reopen-interval <em class="replaceable"><code>duration</code></em>;<br>
|
||||
geoip-directory ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||
glue-cache <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
heartbeat-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||
hostname ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||
inline-signing <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
interface-interval <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
interface-interval <em class="replaceable"><code>duration</code></em>;<br>
|
||||
ixfr-from-differences ( primary | master | secondary | slave |<br>
|
||||
<em class="replaceable"><code>boolean</code></em> );<br>
|
||||
keep-response-order { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||
lame-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
lame-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
listen-on [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
|
||||
<em class="replaceable"><code>integer</code></em> ] {<br>
|
||||
<em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||
@@ -303,28 +304,28 @@ options
|
||||
masterfile-style ( full | relative );<br>
|
||||
match-mapped-addresses <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
max-cache-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );<br>
|
||||
max-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
max-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
max-clients-per-query <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-journal-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
||||
max-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
max-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
max-records <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-recursion-depth <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-recursion-queries <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-rsa-exponent-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-stale-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
max-stale-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
max-transfer-idle-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-udp-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||
memstatistics <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
memstatistics-file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||
message-compression <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
min-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
min-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
min-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
min-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
minimal-any <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
@@ -341,8 +342,8 @@ options
|
||||
notify-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]<br>
|
||||
[ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
||||
notify-to-soa <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
nta-lifetime <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
nta-recheck <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
nta-lifetime <em class="replaceable"><code>duration</code></em>;<br>
|
||||
nta-recheck <em class="replaceable"><code>duration</code></em>;<br>
|
||||
nxdomain-redirect <em class="replaceable"><code>string</code></em>;<br>
|
||||
pid-file ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||
port <em class="replaceable"><code>integer</code></em>;<br>
|
||||
@@ -389,13 +390,13 @@ options
|
||||
response-padding { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size<br>
|
||||
<em class="replaceable"><code>integer</code></em>;<br>
|
||||
response-policy { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log<br>
|
||||
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [ min-update-interval<br>
|
||||
<em class="replaceable"><code>ttlval</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
||||
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [ min-update-interval<br>
|
||||
<em class="replaceable"><code>duration</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
||||
nodata | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [<br>
|
||||
recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [<br>
|
||||
min-update-interval <em class="replaceable"><code>ttlval</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
||||
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [<br>
|
||||
min-update-interval <em class="replaceable"><code>duration</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
||||
nsip-wait-recurse <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]<br>
|
||||
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||
@@ -409,7 +410,7 @@ options
|
||||
serial-query-rate <em class="replaceable"><code>integer</code></em>;<br>
|
||||
serial-update-method ( date | increment | unixtime );<br>
|
||||
server-id ( <em class="replaceable"><code>quoted_string</code></em> | none | hostname );<br>
|
||||
servfail-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
servfail-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
session-keyalg <em class="replaceable"><code>string</code></em>;<br>
|
||||
session-keyfile ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||
session-keyname <em class="replaceable"><code>string</code></em>;<br>
|
||||
@@ -420,7 +421,7 @@ options
|
||||
sortlist { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||
stacksize ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
||||
stale-answer-enable <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
stale-answer-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
stale-answer-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
startup-notify-rate <em class="replaceable"><code>integer</code></em>;<br>
|
||||
statistics-file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||
synth-from-dnssec <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
@@ -557,7 +558,7 @@ view
|
||||
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port<br>
|
||||
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key<br>
|
||||
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [<br>
|
||||
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>ttlval</code></em> ]; ... };<br>
|
||||
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>duration</code></em> ]; ... };<br>
|
||||
check-dup-records ( fail | warn | ignore );<br>
|
||||
check-integrity <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
check-mx ( fail | warn | ignore );<br>
|
||||
@@ -600,8 +601,9 @@ view
|
||||
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
|
||||
initial-key ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
||||
initial-key | static-ds | initial-ds<br>
|
||||
) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||
<em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
||||
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
@@ -635,10 +637,11 @@ view
|
||||
secret <em class="replaceable"><code>string</code></em>;<br>
|
||||
};<br>
|
||||
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||
lame-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
lame-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
lmdb-mapsize <em class="replaceable"><code>sizeval</code></em>;<br>
|
||||
managed-keys { <em class="replaceable"><code>string</code></em> (<br>
|
||||
static-key | initial-key<br>
|
||||
| static-ds | initial-ds<br>
|
||||
) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||
<em class="replaceable"><code>integer</code></em><br>
|
||||
<em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
||||
@@ -648,25 +651,25 @@ view
|
||||
match-destinations { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||
match-recursive-only <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
max-cache-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );<br>
|
||||
max-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
max-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
max-clients-per-query <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-journal-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
||||
max-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
max-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
max-records <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-recursion-depth <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-recursion-queries <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-stale-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
max-stale-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
max-transfer-idle-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-udp-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||
message-compression <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
min-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
min-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
min-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
min-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
minimal-any <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
@@ -682,8 +685,8 @@ view
|
||||
notify-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]<br>
|
||||
[ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
||||
notify-to-soa <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
nta-lifetime <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
nta-recheck <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
nta-lifetime <em class="replaceable"><code>duration</code></em>;<br>
|
||||
nta-recheck <em class="replaceable"><code>duration</code></em>;<br>
|
||||
nxdomain-redirect <em class="replaceable"><code>string</code></em>;<br>
|
||||
plugin ( query ) <em class="replaceable"><code>string</code></em> [ {<br>
|
||||
<em class="replaceable"><code>unspecified-text</code></em> } ];<br>
|
||||
@@ -725,13 +728,13 @@ view
|
||||
response-padding { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size<br>
|
||||
<em class="replaceable"><code>integer</code></em>;<br>
|
||||
response-policy { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log<br>
|
||||
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [ min-update-interval<br>
|
||||
<em class="replaceable"><code>ttlval</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
||||
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [ min-update-interval<br>
|
||||
<em class="replaceable"><code>duration</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
||||
nodata | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [<br>
|
||||
recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [<br>
|
||||
min-update-interval <em class="replaceable"><code>ttlval</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
||||
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [<br>
|
||||
min-update-interval <em class="replaceable"><code>duration</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
||||
nsip-wait-recurse <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]<br>
|
||||
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||
@@ -776,14 +779,14 @@ view
|
||||
<em class="replaceable"><code>integer</code></em> | * ) ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
||||
transfers <em class="replaceable"><code>integer</code></em>;<br>
|
||||
};<br>
|
||||
servfail-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
servfail-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
sig-signing-nodes <em class="replaceable"><code>integer</code></em>;<br>
|
||||
sig-signing-signatures <em class="replaceable"><code>integer</code></em>;<br>
|
||||
sig-signing-type <em class="replaceable"><code>integer</code></em>;<br>
|
||||
sig-validity-interval <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ];<br>
|
||||
sortlist { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||
stale-answer-enable <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
stale-answer-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
stale-answer-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
synth-from-dnssec <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
transfer-format ( many-answers | one-answer );<br>
|
||||
transfer-source ( <em class="replaceable"><code>ipv4_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ] [<br>
|
||||
@@ -835,6 +838,7 @@ view
|
||||
dnskey-sig-validity <em class="replaceable"><code>integer</code></em>;<br>
|
||||
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||
dnssec-policy <em class="replaceable"><code>string</code></em>;<br>
|
||||
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
dnssec-update-mode ( maintain | no-resign );<br>
|
||||
file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||
@@ -860,7 +864,7 @@ view
|
||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
@@ -937,6 +941,7 @@ zone
|
||||
dnskey-sig-validity <em class="replaceable"><code>integer</code></em>;<br>
|
||||
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||
dnssec-policy <em class="replaceable"><code>string</code></em>;<br>
|
||||
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
dnssec-update-mode ( maintain | no-resign );<br>
|
||||
file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||
@@ -961,7 +966,7 @@ zone
|
||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
||||
@@ -1003,14 +1008,35 @@ zone
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.24"></a><h2>FILES</h2>
|
||||
<a name="id-1.24"></a><h2>DNSSEC-POLICY</h2>
|
||||
|
||||
<div class="literallayout"><p><br>
|
||||
dnssec-policy <em class="replaceable"><code>string</code></em> {<br>
|
||||
dnskey-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
||||
keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br>
|
||||
parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br>
|
||||
parent-registration-delay <em class="replaceable"><code>duration</code></em>;<br>
|
||||
publish-safety <em class="replaceable"><code>duration</code></em>;<br>
|
||||
retire-safety <em class="replaceable"><code>duration</code></em>;<br>
|
||||
signatures-refresh <em class="replaceable"><code>duration</code></em>;<br>
|
||||
signatures-validity <em class="replaceable"><code>duration</code></em>;<br>
|
||||
signatures-validity-dnskey <em class="replaceable"><code>duration</code></em>;<br>
|
||||
zone-max-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||
zone-propagation-delay <em class="replaceable"><code>duration</code></em>;<br>
|
||||
};<br>
|
||||
</p></div>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.25"></a><h2>FILES</h2>
|
||||
|
||||
<p><code class="filename">/etc/named.conf</code>
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="refsection">
|
||||
<a name="id-1.25"></a><h2>SEE ALSO</h2>
|
||||
<a name="id-1.26"></a><h2>SEE ALSO</h2>
|
||||
|
||||
<p><span class="citerefentry">
|
||||
<span class="refentrytitle">ddns-confgen</span>(8)
|
||||
|
||||
+276
-126
@@ -201,8 +201,8 @@
|
||||
|
||||
#define CHECKFATAL(op, msg) \
|
||||
do { result = (op); \
|
||||
if (result != ISC_R_SUCCESS) \
|
||||
fatal(msg, result); \
|
||||
if (result != ISC_R_SUCCESS) \
|
||||
fatal(server, msg, result); \
|
||||
} while (0) \
|
||||
|
||||
/*%
|
||||
@@ -431,7 +431,8 @@ const char *empty_zones[] = {
|
||||
};
|
||||
|
||||
ISC_PLATFORM_NORETURN_PRE static void
|
||||
fatal(const char *msg, isc_result_t result) ISC_PLATFORM_NORETURN_POST;
|
||||
fatal(named_server_t *server,const char *msg, isc_result_t result)
|
||||
ISC_PLATFORM_NORETURN_POST;
|
||||
|
||||
static void
|
||||
named_server_reload(isc_task_t *task, isc_event_t *event);
|
||||
@@ -698,104 +699,190 @@ configure_view_nametable(const cfg_obj_t *vconfig, const cfg_obj_t *config,
|
||||
}
|
||||
|
||||
static isc_result_t
|
||||
dstkey_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **target,
|
||||
const char **keynamestrp, isc_mem_t *mctx)
|
||||
ta_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **keyp,
|
||||
dns_rdata_ds_t **dsp, const char **namestrp, isc_mem_t *mctx)
|
||||
{
|
||||
dns_rdata_dnskey_t keystruct;
|
||||
uint32_t flags, proto, alg;
|
||||
const char *keystr, *keynamestr;
|
||||
unsigned char keydata[4096];
|
||||
isc_buffer_t keydatabuf;
|
||||
dns_rdata_ds_t *ds = NULL;
|
||||
uint32_t n1, n2, n3;
|
||||
const char *datastr = NULL, *namestr = NULL;
|
||||
unsigned char data[4096];
|
||||
isc_buffer_t databuf;
|
||||
unsigned char rrdata[4096];
|
||||
isc_buffer_t rrdatabuf;
|
||||
isc_region_t r;
|
||||
dns_fixedname_t fkeyname;
|
||||
dns_name_t *keyname;
|
||||
dns_fixedname_t fname;
|
||||
dns_name_t *name = NULL;
|
||||
isc_buffer_t namebuf;
|
||||
isc_result_t result;
|
||||
dst_key_t *dstkey = NULL;
|
||||
const char *atstr = NULL;
|
||||
enum {
|
||||
INIT_DNSKEY,
|
||||
STATIC_DNSKEY,
|
||||
INIT_DS,
|
||||
STATIC_DS,
|
||||
TRUSTED
|
||||
} anchortype;
|
||||
|
||||
INSIST(target != NULL && *target == NULL);
|
||||
INSIST(keynamestrp != NULL && *keynamestrp == NULL);
|
||||
REQUIRE(keyp != NULL && *keyp == NULL);
|
||||
REQUIRE(dsp != NULL && *dsp == NULL);
|
||||
REQUIRE(namestrp != NULL && *namestrp == NULL);
|
||||
|
||||
flags = cfg_obj_asuint32(cfg_tuple_get(key, "flags"));
|
||||
proto = cfg_obj_asuint32(cfg_tuple_get(key, "protocol"));
|
||||
alg = cfg_obj_asuint32(cfg_tuple_get(key, "algorithm"));
|
||||
keyname = dns_fixedname_name(&fkeyname);
|
||||
keynamestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
||||
*keynamestrp = keynamestr;
|
||||
/* if DNSKEY, flags; if DS, key tag */
|
||||
n1 = cfg_obj_asuint32(cfg_tuple_get(key, "n1"));
|
||||
|
||||
/* if DNSKEY, protocol; if DS, algorithm */
|
||||
n2 = cfg_obj_asuint32(cfg_tuple_get(key, "n2"));
|
||||
|
||||
/* if DNSKEY, algorithm; if DS, digest type */
|
||||
n3 = cfg_obj_asuint32(cfg_tuple_get(key, "n3"));
|
||||
|
||||
namestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
||||
*namestrp = namestr;
|
||||
|
||||
name = dns_fixedname_initname(&fname);
|
||||
isc_buffer_constinit(&namebuf, namestr, strlen(namestr));
|
||||
isc_buffer_add(&namebuf, strlen(namestr));
|
||||
CHECK(dns_name_fromtext(name, &namebuf, dns_rootname, 0, NULL));
|
||||
|
||||
if (*initialp) {
|
||||
const char *initmethod;
|
||||
initmethod = cfg_obj_asstring(cfg_tuple_get(key, "init"));
|
||||
atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype"));
|
||||
|
||||
if (strcasecmp(initmethod, "static-key") == 0) {
|
||||
if (strcasecmp(atstr, "static-key") == 0) {
|
||||
*initialp = false;
|
||||
} else if (strcasecmp(initmethod, "initial-key") != 0) {
|
||||
anchortype = STATIC_DNSKEY;
|
||||
} else if (strcasecmp(atstr, "static-ds") == 0) {
|
||||
*initialp = false;
|
||||
anchortype = STATIC_DS;
|
||||
} else if (strcasecmp(atstr, "initial-key") == 0) {
|
||||
anchortype = INIT_DNSKEY;
|
||||
} else if (strcasecmp(atstr, "initial-ds") == 0) {
|
||||
anchortype = INIT_DS;
|
||||
} else {
|
||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
||||
"key '%s': "
|
||||
"invalid initialization method '%s'",
|
||||
keynamestr, initmethod);
|
||||
namestr, atstr);
|
||||
result = ISC_R_FAILURE;
|
||||
goto cleanup;
|
||||
}
|
||||
} else {
|
||||
anchortype = TRUSTED;
|
||||
}
|
||||
|
||||
/*
|
||||
* This function should never be reached for non-IN classes.
|
||||
*/
|
||||
keystruct.common.rdclass = dns_rdataclass_in;
|
||||
keystruct.common.rdtype = dns_rdatatype_dnskey;
|
||||
|
||||
/*
|
||||
* The key data in keystruct is not dynamically allocated.
|
||||
*/
|
||||
keystruct.mctx = NULL;
|
||||
|
||||
ISC_LINK_INIT(&keystruct.common, link);
|
||||
|
||||
if (flags > 0xffff)
|
||||
CHECKM(ISC_R_RANGE, "key flags");
|
||||
if (flags & DNS_KEYFLAG_REVOKE)
|
||||
CHECKM(DST_R_BADKEYTYPE, "key flags revoke bit set");
|
||||
if (proto > 0xff)
|
||||
CHECKM(ISC_R_RANGE, "key protocol");
|
||||
if (alg > 0xff)
|
||||
CHECKM(ISC_R_RANGE, "key algorithm");
|
||||
keystruct.flags = (uint16_t)flags;
|
||||
keystruct.protocol = (uint8_t)proto;
|
||||
keystruct.algorithm = (uint8_t)alg;
|
||||
|
||||
isc_buffer_init(&keydatabuf, keydata, sizeof(keydata));
|
||||
isc_buffer_init(&databuf, data, sizeof(data));
|
||||
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
|
||||
|
||||
keystr = cfg_obj_asstring(cfg_tuple_get(key, "key"));
|
||||
CHECK(isc_base64_decodestring(keystr, &keydatabuf));
|
||||
isc_buffer_usedregion(&keydatabuf, &r);
|
||||
keystruct.datalen = r.length;
|
||||
keystruct.data = r.base;
|
||||
switch(anchortype) {
|
||||
case INIT_DNSKEY:
|
||||
case STATIC_DNSKEY:
|
||||
case TRUSTED:
|
||||
/*
|
||||
* This function should never be reached for view
|
||||
* class other than IN
|
||||
*/
|
||||
keystruct.common.rdclass = dns_rdataclass_in;
|
||||
keystruct.common.rdtype = dns_rdatatype_dnskey;
|
||||
|
||||
if ((keystruct.algorithm == DST_ALG_RSASHA1) &&
|
||||
r.length > 1 && r.base[0] == 1 && r.base[1] == 3)
|
||||
{
|
||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
|
||||
"%s '%s' has a weak exponent",
|
||||
*initialp ? "initial-key" : "static-key",
|
||||
keynamestr);
|
||||
/*
|
||||
* The key data in keystruct is not dynamically allocated.
|
||||
*/
|
||||
keystruct.mctx = NULL;
|
||||
|
||||
ISC_LINK_INIT(&keystruct.common, link);
|
||||
|
||||
if (n1 > 0xffff) {
|
||||
CHECKM(ISC_R_RANGE, "key flags");
|
||||
}
|
||||
if (n1 & DNS_KEYFLAG_REVOKE) {
|
||||
CHECKM(DST_R_BADKEYTYPE, "key flags revoke bit set");
|
||||
}
|
||||
if (n2 > 0xff) {
|
||||
CHECKM(ISC_R_RANGE, "key protocol");
|
||||
}
|
||||
if (n3> 0xff) {
|
||||
CHECKM(ISC_R_RANGE, "key algorithm");
|
||||
}
|
||||
|
||||
keystruct.flags = (uint16_t)n1;
|
||||
keystruct.protocol = (uint8_t)n2;
|
||||
keystruct.algorithm = (uint8_t)n3;
|
||||
|
||||
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
|
||||
CHECK(isc_base64_decodestring(datastr, &databuf));
|
||||
isc_buffer_usedregion(&databuf, &r);
|
||||
keystruct.datalen = r.length;
|
||||
keystruct.data = r.base;
|
||||
|
||||
CHECK(dns_rdata_fromstruct(NULL, keystruct.common.rdclass,
|
||||
keystruct.common.rdtype,
|
||||
&keystruct, &rrdatabuf));
|
||||
CHECK(dst_key_fromdns(name, dns_rdataclass_in,
|
||||
&rrdatabuf, mctx, &dstkey));
|
||||
|
||||
*keyp = dstkey;
|
||||
break;
|
||||
|
||||
case INIT_DS:
|
||||
case STATIC_DS:
|
||||
ds = isc_mem_get(mctx, sizeof(*ds));
|
||||
ds->common.rdclass = dns_rdataclass_in;
|
||||
ds->common.rdtype = dns_rdatatype_ds;
|
||||
ds->mctx = NULL;
|
||||
|
||||
ISC_LINK_INIT(&ds->common, link);
|
||||
|
||||
if (n1 > 0xffff) {
|
||||
CHECKM(ISC_R_RANGE, "key tag");
|
||||
}
|
||||
if (n2 > 0xff) {
|
||||
CHECKM(ISC_R_RANGE, "key algorithm");
|
||||
}
|
||||
if (n3 > 0xff) {
|
||||
CHECKM(ISC_R_RANGE, "digest type");
|
||||
}
|
||||
|
||||
ds->key_tag = (uint16_t)n1;
|
||||
ds->algorithm = (uint8_t)n2;
|
||||
ds->digest_type = (uint8_t)n3;
|
||||
|
||||
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
|
||||
CHECK(isc_hex_decodestring(datastr, &databuf));
|
||||
isc_buffer_usedregion(&databuf, &r);
|
||||
|
||||
switch (ds->digest_type) {
|
||||
case DNS_DSDIGEST_SHA1:
|
||||
if (r.length != ISC_SHA1_DIGESTLENGTH) {
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
break;
|
||||
case DNS_DSDIGEST_SHA256:
|
||||
if (r.length != ISC_SHA256_DIGESTLENGTH) {
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
break;
|
||||
case DNS_DSDIGEST_SHA384:
|
||||
if (r.length != ISC_SHA384_DIGESTLENGTH) {
|
||||
CHECK(ISC_R_UNEXPECTEDEND);
|
||||
}
|
||||
break;
|
||||
}
|
||||
|
||||
ds->mctx = mctx;
|
||||
ds->length = r.length;
|
||||
ds->digest = isc_mem_allocate(mctx, r.length);
|
||||
memmove(ds->digest, r.base, r.length);
|
||||
|
||||
*dsp = ds;
|
||||
ds = NULL;
|
||||
break;
|
||||
|
||||
default:
|
||||
INSIST(0);
|
||||
ISC_UNREACHABLE();
|
||||
}
|
||||
|
||||
CHECK(dns_rdata_fromstruct(NULL,
|
||||
keystruct.common.rdclass,
|
||||
keystruct.common.rdtype,
|
||||
&keystruct, &rrdatabuf));
|
||||
dns_fixedname_init(&fkeyname);
|
||||
isc_buffer_constinit(&namebuf, keynamestr, strlen(keynamestr));
|
||||
isc_buffer_add(&namebuf, strlen(keynamestr));
|
||||
CHECK(dns_name_fromtext(keyname, &namebuf, dns_rootname, 0, NULL));
|
||||
CHECK(dst_key_fromdns(keyname, dns_rdataclass_in, &rrdatabuf,
|
||||
mctx, &dstkey));
|
||||
|
||||
*target = dstkey;
|
||||
return (ISC_R_SUCCESS);
|
||||
|
||||
cleanup:
|
||||
@@ -803,6 +890,11 @@ dstkey_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **target,
|
||||
dst_key_free(&dstkey);
|
||||
}
|
||||
|
||||
if (ds != NULL) {
|
||||
dns_rdata_freestruct(ds);
|
||||
isc_mem_put(mctx, ds, sizeof(*ds));
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -822,24 +914,45 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
||||
const dns_name_t *keyname_match, dns_resolver_t *resolver,
|
||||
bool managed, isc_mem_t *mctx)
|
||||
{
|
||||
const dns_name_t *keyname = NULL;
|
||||
const char *keynamestr = NULL;
|
||||
dns_fixedname_t fkeyname;
|
||||
dns_name_t *keyname = NULL;
|
||||
const char *namestr = NULL;
|
||||
dst_key_t *dstkey = NULL;
|
||||
dns_rdata_ds_t *ds = NULL;
|
||||
unsigned int keyalg;
|
||||
isc_result_t result;
|
||||
bool initializing = managed;
|
||||
|
||||
result = dstkey_fromconfig(key, &initializing,
|
||||
&dstkey, &keynamestr, mctx);
|
||||
result = ta_fromconfig(key, &initializing, &dstkey, &ds,
|
||||
&namestr, mctx);
|
||||
|
||||
switch (result) {
|
||||
case ISC_R_SUCCESS:
|
||||
/*
|
||||
* Key was parsed correctly, its algorithm is supported by the
|
||||
* crypto library, and it is not revoked.
|
||||
* Trust anchor was parsed correctly. If dstkey is
|
||||
* not NULL, then it was a key anchor, its algorithm
|
||||
* is supported by the crypto library, and it is not
|
||||
* revoked. If dstkey is NULL, then it was a DS
|
||||
* trust anchor instead.
|
||||
*/
|
||||
keyname = dst_key_name(dstkey);
|
||||
keyalg = dst_key_alg(dstkey);
|
||||
if (dstkey != NULL) {
|
||||
keyname = dst_key_name(dstkey);
|
||||
keyalg = dst_key_alg(dstkey);
|
||||
} else {
|
||||
isc_buffer_t b;
|
||||
|
||||
INSIST(ds != NULL);
|
||||
|
||||
isc_buffer_constinit(&b, namestr, strlen(namestr));
|
||||
isc_buffer_add(&b, strlen(namestr));
|
||||
keyname = dns_fixedname_initname(&fkeyname);
|
||||
result = dns_name_fromtext(keyname, &b,
|
||||
dns_rootname, 0, NULL);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
return (result);
|
||||
}
|
||||
keyalg = ds->algorithm;
|
||||
}
|
||||
break;
|
||||
case DST_R_UNSUPPORTEDALG:
|
||||
case DST_R_BADKEYTYPE:
|
||||
@@ -851,7 +964,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
|
||||
"ignoring %s for '%s': %s",
|
||||
initializing ? "initial-key" : "static-key",
|
||||
keynamestr, isc_result_totext(result));
|
||||
namestr, isc_result_totext(result));
|
||||
return (ISC_R_SUCCESS);
|
||||
case DST_R_NOCRYPTO:
|
||||
/*
|
||||
@@ -860,7 +973,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
||||
"ignoring %s for '%s': no crypto support",
|
||||
initializing ? "initial-key" : "static-key",
|
||||
keynamestr);
|
||||
namestr);
|
||||
return (result);
|
||||
default:
|
||||
/*
|
||||
@@ -871,7 +984,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
||||
"configuring %s for '%s': %s",
|
||||
initializing ? "initial-key" : "static-key",
|
||||
keynamestr, isc_result_totext(result));
|
||||
namestr, isc_result_totext(result));
|
||||
return (ISC_R_FAILURE);
|
||||
}
|
||||
|
||||
@@ -893,7 +1006,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
|
||||
"ignoring %s for '%s': algorithm is disabled",
|
||||
initializing ? "initial-key" : "static-key",
|
||||
keynamestr);
|
||||
namestr);
|
||||
goto done;
|
||||
}
|
||||
|
||||
@@ -905,7 +1018,9 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
||||
* 'managed' and 'initializing' arguments to dns_keytable_add().
|
||||
*/
|
||||
result = dns_keytable_add(secroots, initializing,
|
||||
initializing, &dstkey);
|
||||
initializing, keyname,
|
||||
dstkey != NULL ? &dstkey : NULL,
|
||||
ds);
|
||||
|
||||
done:
|
||||
/*
|
||||
@@ -917,6 +1032,14 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
||||
dst_key_free(&dstkey);
|
||||
}
|
||||
|
||||
/*
|
||||
* Free 'ds'.
|
||||
*/
|
||||
if (ds != NULL) {
|
||||
dns_rdata_freestruct(ds);
|
||||
isc_mem_put(mctx, ds, sizeof(*ds));
|
||||
}
|
||||
|
||||
return (result);
|
||||
}
|
||||
|
||||
@@ -1117,16 +1240,18 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
||||
}
|
||||
}
|
||||
|
||||
CHECK(load_view_keys(view_keys, view, false, NULL, mctx));
|
||||
CHECK(load_view_keys(view_managed_keys, view, true, NULL, mctx));
|
||||
CHECK(load_view_keys(view_dnssec_keys, view, true, NULL, mctx));
|
||||
|
||||
if (view->rdclass == dns_rdataclass_in) {
|
||||
CHECK(load_view_keys(view_keys, view, false, NULL, mctx));
|
||||
CHECK(load_view_keys(view_dnssec_keys, view, true, NULL,
|
||||
mctx));
|
||||
CHECK(load_view_keys(view_managed_keys, view, true, NULL,
|
||||
mctx));
|
||||
|
||||
CHECK(load_view_keys(global_keys, view, false, NULL, mctx));
|
||||
CHECK(load_view_keys(global_managed_keys, view, true,
|
||||
NULL, mctx));
|
||||
CHECK(load_view_keys(global_dnssec_keys, view, true,
|
||||
NULL, mctx));
|
||||
CHECK(load_view_keys(global_managed_keys, view, true,
|
||||
NULL, mctx));
|
||||
}
|
||||
|
||||
/*
|
||||
@@ -6700,35 +6825,55 @@ struct dotat_arg {
|
||||
* reported in the TAT query.
|
||||
*/
|
||||
static isc_result_t
|
||||
get_tat_qname(dns_name_t *dst, const dns_name_t **origin,
|
||||
get_tat_qname(dns_name_t *target, dns_name_t *keyname,
|
||||
dns_keytable_t *keytable, dns_keynode_t *keynode)
|
||||
{
|
||||
dns_keynode_t *firstnode = keynode;
|
||||
dns_keynode_t *nextnode;
|
||||
dns_keynode_t *nextnode = NULL;
|
||||
dns_rdataset_t *dsset = NULL;
|
||||
unsigned int i, n = 0;
|
||||
uint16_t ids[12];
|
||||
isc_textregion_t r;
|
||||
char label[64];
|
||||
int m;
|
||||
|
||||
REQUIRE(origin != NULL && *origin == NULL);
|
||||
if ((dsset = dns_keynode_dsset(keynode)) != NULL) {
|
||||
isc_result_t result;
|
||||
|
||||
do {
|
||||
dst_key_t *key = dns_keynode_key(keynode);
|
||||
if (key != NULL) {
|
||||
*origin = dst_key_name(key);
|
||||
for (result = dns_rdataset_first(dsset);
|
||||
result == ISC_R_SUCCESS;
|
||||
result = dns_rdataset_next(dsset))
|
||||
{
|
||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||
dns_rdata_ds_t ds;
|
||||
|
||||
dns_rdata_reset(&rdata);
|
||||
dns_rdataset_current(dsset, &rdata);
|
||||
result = dns_rdata_tostruct(&rdata, &ds, NULL);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
if (n < (sizeof(ids)/sizeof(ids[0]))) {
|
||||
ids[n] = dst_key_id(key);
|
||||
ids[n] = ds.key_tag;
|
||||
n++;
|
||||
}
|
||||
}
|
||||
nextnode = NULL;
|
||||
(void)dns_keytable_nextkeynode(keytable, keynode, &nextnode);
|
||||
if (keynode != firstnode) {
|
||||
dns_keytable_detachkeynode(keytable, &keynode);
|
||||
}
|
||||
keynode = nextnode;
|
||||
} while (keynode != NULL);
|
||||
} else {
|
||||
do {
|
||||
dst_key_t *key = dns_keynode_key(keynode);
|
||||
if (key != NULL) {
|
||||
if (n < (sizeof(ids)/sizeof(ids[0]))) {
|
||||
ids[n] = dst_key_id(key);
|
||||
n++;
|
||||
}
|
||||
}
|
||||
nextnode = NULL;
|
||||
(void)dns_keytable_nextkeynode(keytable, keynode,
|
||||
&nextnode);
|
||||
if (keynode != firstnode) {
|
||||
dns_keytable_detachkeynode(keytable, &keynode);
|
||||
}
|
||||
keynode = nextnode;
|
||||
} while (keynode != NULL);
|
||||
}
|
||||
|
||||
if (n == 0) {
|
||||
return (DNS_R_EMPTYNAME);
|
||||
@@ -6758,14 +6903,15 @@ get_tat_qname(dns_name_t *dst, const dns_name_t **origin,
|
||||
isc_textregion_consume(&r, m);
|
||||
}
|
||||
|
||||
return (dns_name_fromstring2(dst, label, *origin, 0, NULL));
|
||||
return (dns_name_fromstring2(target, label, keyname, 0, NULL));
|
||||
}
|
||||
|
||||
static void
|
||||
dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
||||
dotat(dns_keytable_t *keytable, dns_keynode_t *keynode,
|
||||
dns_name_t *keyname, void *arg)
|
||||
{
|
||||
struct dotat_arg *dotat_arg = arg;
|
||||
char namebuf[DNS_NAME_FORMATSIZE];
|
||||
const dns_name_t *origin = NULL;
|
||||
dns_fixedname_t fixed, fdomain;
|
||||
dns_name_t *tatname, *domain;
|
||||
dns_rdataset_t nameservers;
|
||||
@@ -6782,7 +6928,7 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
||||
task = dotat_arg->task;
|
||||
|
||||
tatname = dns_fixedname_initname(&fixed);
|
||||
result = get_tat_qname(tatname, &origin, keytable, keynode);
|
||||
result = get_tat_qname(tatname, keyname, keytable, keynode);
|
||||
if (result != ISC_R_SUCCESS) {
|
||||
return;
|
||||
}
|
||||
@@ -6820,17 +6966,13 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
||||
* order to eventually find the destination host to send the TAT query
|
||||
* to.
|
||||
*
|
||||
* 'origin' holds the domain name at 'keynode', i.e. the domain name
|
||||
* for which the trust anchors to be reported by this TAT query are
|
||||
* defined.
|
||||
*
|
||||
* After the dns_view_findzonecut() call, 'domain' will hold the
|
||||
* deepest zone cut we can find for 'origin' while 'nameservers' will
|
||||
* deepest zone cut we can find for 'keyname' while 'nameservers' will
|
||||
* hold the NS RRset at that zone cut.
|
||||
*/
|
||||
domain = dns_fixedname_initname(&fdomain);
|
||||
dns_rdataset_init(&nameservers);
|
||||
result = dns_view_findzonecut(view, origin, domain, NULL, 0, 0,
|
||||
result = dns_view_findzonecut(view, keyname, domain, NULL, 0, 0,
|
||||
true, true, &nameservers, NULL);
|
||||
if (result == ISC_R_SUCCESS) {
|
||||
result = dns_resolver_createfetch(view->resolver, tatname,
|
||||
@@ -6899,7 +7041,7 @@ tat_timer_tick(isc_task_t *task, isc_event_t *event) {
|
||||
static void
|
||||
pps_timer_tick(isc_task_t *task, isc_event_t *event) {
|
||||
static unsigned int oldrequests = 0;
|
||||
unsigned int requests = ns_client_requests;
|
||||
unsigned int requests = atomic_load_relaxed(&ns_client_requests);
|
||||
|
||||
UNUSED(task);
|
||||
isc_event_free(&event);
|
||||
@@ -8329,8 +8471,8 @@ load_configuration(const char *filename, named_server_t *server,
|
||||
advertised = MAX_TCP_TIMEOUT;
|
||||
}
|
||||
|
||||
ns_server_settimeouts(named_g_server->sctx,
|
||||
initial, idle, keepalive, advertised);
|
||||
isc_nm_tcp_settimeouts(named_g_nm, initial, idle,
|
||||
keepalive, advertised);
|
||||
|
||||
/*
|
||||
* Configure sets of UDP query source ports.
|
||||
@@ -9664,7 +9806,7 @@ named_server_create(isc_mem_t *mctx, named_server_t **serverp) {
|
||||
named_server_t *server = isc_mem_get(mctx, sizeof(*server));
|
||||
|
||||
if (server == NULL)
|
||||
fatal("allocating server object", ISC_R_NOMEMORY);
|
||||
fatal(server, "allocating server object", ISC_R_NOMEMORY);
|
||||
|
||||
server->mctx = mctx;
|
||||
server->task = NULL;
|
||||
@@ -9875,7 +10017,15 @@ named_server_destroy(named_server_t **serverp) {
|
||||
}
|
||||
|
||||
static void
|
||||
fatal(const char *msg, isc_result_t result) {
|
||||
fatal(named_server_t *server, const char *msg, isc_result_t result) {
|
||||
if (server != NULL) {
|
||||
/*
|
||||
* Prevent races between the OpenSSL on_exit registered
|
||||
* function and any other OpenSSL calls from other tasks
|
||||
* by requesting exclusive access to the task manager.
|
||||
*/
|
||||
(void)isc_task_beginexclusive(server->task);
|
||||
}
|
||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||
NAMED_LOGMODULE_SERVER, ISC_LOG_CRITICAL,
|
||||
"%s: %s", msg, isc_result_totext(result));
|
||||
@@ -15264,8 +15414,8 @@ named_server_tcptimeouts(isc_lex_t *lex, isc_buffer_t **text) {
|
||||
if (ptr == NULL)
|
||||
return (ISC_R_UNEXPECTEDEND);
|
||||
|
||||
ns_server_gettimeouts(named_g_server->sctx,
|
||||
&initial, &idle, &keepalive, &advertised);
|
||||
isc_nm_tcp_gettimeouts(named_g_nm, &initial, &idle,
|
||||
&keepalive, &advertised);
|
||||
|
||||
/* Look for optional arguments. */
|
||||
ptr = next_token(lex, NULL);
|
||||
@@ -15304,7 +15454,7 @@ named_server_tcptimeouts(isc_lex_t *lex, isc_buffer_t **text) {
|
||||
result = isc_task_beginexclusive(named_g_server->task);
|
||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||
|
||||
ns_server_settimeouts(named_g_server->sctx, initial, idle,
|
||||
isc_nm_tcp_settimeouts(named_g_nm, initial, idle,
|
||||
keepalive, advertised);
|
||||
|
||||
isc_task_endexclusive(named_g_server->task);
|
||||
|
||||
+5
-3
@@ -276,7 +276,8 @@ See also
|
||||
Fetch all DNSSEC keys for the given zone from the key directory\&. If they are within their publication period, merge them into the zone\*(Aqs DNSKEY RRset\&. Unlike
|
||||
\fBrndc sign\fR, however, the zone is not immediately re\-signed by the new keys, but is allowed to incrementally re\-sign over time\&.
|
||||
.sp
|
||||
This command requires that the
|
||||
This command requires that the zone is configured with a
|
||||
\fBdnssec\-policy\fR, or that the
|
||||
\fBauto\-dnssec\fR
|
||||
zone option be set to
|
||||
maintain, and also requires the zone to be configured to allow dynamic DNS\&. (See "Dynamic Update Policies" in the Administrator Reference Manual for more details\&.)
|
||||
@@ -566,7 +567,8 @@ Fetch all DNSSEC keys for the given zone from the key directory (see the
|
||||
\fBkey\-directory\fR
|
||||
option in the BIND 9 Administrator Reference Manual)\&. If they are within their publication period, merge them into the zone\*(Aqs DNSKEY RRset\&. If the DNSKEY RRset is changed, then the zone is automatically re\-signed with the new key set\&.
|
||||
.sp
|
||||
This command requires that the
|
||||
This command requires that the zone is configured with a
|
||||
\fBdnssec\-policy\fR, or that the
|
||||
\fBauto\-dnssec\fR
|
||||
zone option be set to
|
||||
allow
|
||||
@@ -702,7 +704,7 @@ in each view\&. The list includes both statically configured keys and dynamic TK
|
||||
.PP
|
||||
\fBvalidation ( on | off | status ) \fR\fB[\fIview \&.\&.\&.\fR]\fR\fB \fR
|
||||
.RS 4
|
||||
Enable, disable, or check the current status of DNSSEC validation\&. By default, validation is enabled\&.
|
||||
Enable, disable, or check the current status of DNSSEC validation\&. By default, validation is enabled\&. The cache is flushed when validation is turned on or off to avoid using data that might differ between states\&.
|
||||
.RE
|
||||
.PP
|
||||
\fBzonestatus \fR\fB\fIzone\fR\fR\fB \fR\fB[\fIclass\fR [\fIview\fR]]\fR
|
||||
|
||||
+6
-2
@@ -366,7 +366,8 @@
|
||||
allowed to incrementally re-sign over time.
|
||||
</p>
|
||||
<p>
|
||||
This command requires that the
|
||||
This command requires that the zone is configured with a
|
||||
<span class="command"><strong>dnssec-policy</strong></span>, or that the
|
||||
<span class="command"><strong>auto-dnssec</strong></span> zone option
|
||||
be set to <code class="literal">maintain</code>,
|
||||
and also requires the zone to be configured to
|
||||
@@ -721,7 +722,8 @@
|
||||
re-signed with the new key set.
|
||||
</p>
|
||||
<p>
|
||||
This command requires that the
|
||||
This command requires that the zone is configured with a
|
||||
<span class="command"><strong>dnssec-policy</strong></span>, or that the
|
||||
<span class="command"><strong>auto-dnssec</strong></span> zone option be set
|
||||
to <code class="literal">allow</code> or
|
||||
<code class="literal">maintain</code>,
|
||||
@@ -914,6 +916,8 @@
|
||||
<p>
|
||||
Enable, disable, or check the current status of
|
||||
DNSSEC validation. By default, validation is enabled.
|
||||
The cache is flushed when validation is turned on or off
|
||||
to avoid using data that might differ between states.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><strong class="userinput"><code>zonestatus <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
|
||||
|
||||
@@ -33,12 +33,12 @@ rm $zsknopriv.private
|
||||
ksksby=`$KEYGEN -3 -a RSASHA1 -q -P now -A now+15s -fk $zone`
|
||||
kskrev=`$KEYGEN -3 -a RSASHA1 -q -R now+15s -fk $zone`
|
||||
|
||||
keyfile_to_static_keys $ksksby > trusted.conf
|
||||
keyfile_to_static_ds $ksksby > trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
cp trusted.conf ../ns3/trusted.conf
|
||||
cp trusted.conf ../ns4/trusted.conf
|
||||
|
||||
keyfile_to_static_keys $kskrev > trusted.conf
|
||||
keyfile_to_static_ds $kskrev > trusted.conf
|
||||
cp trusted.conf ../ns5/trusted.conf
|
||||
|
||||
echo $zskact > ../active.key
|
||||
|
||||
@@ -37,7 +37,7 @@ zonefile="${zone}.db"
|
||||
infile="${zonefile}.in"
|
||||
ksk=`$KEYGEN -a RSASHA1 -3 -q -fk $zone`
|
||||
$KEYGEN -a RSASHA1 -3 -q $zone > /dev/null
|
||||
keyfile_to_static_keys $ksk > private.conf
|
||||
keyfile_to_static_ds $ksk > private.conf
|
||||
cp private.conf ../ns4/private.conf
|
||||
$SIGNER -S -3 beef -A -o $zone -f $zonefile $infile > /dev/null
|
||||
|
||||
|
||||
@@ -101,6 +101,8 @@ zone "jitter.nsec3.example" {
|
||||
allow-update { any; };
|
||||
auto-dnssec maintain;
|
||||
sig-validity-interval 10 2;
|
||||
sig-signing-nodes 1000;
|
||||
sig-signing-signatures 100;
|
||||
};
|
||||
|
||||
zone "secure.nsec3.example" {
|
||||
@@ -187,6 +189,8 @@ zone "oldsigs.example" {
|
||||
allow-update { any; };
|
||||
auto-dnssec maintain;
|
||||
sig-validity-interval 10 2;
|
||||
sig-signing-nodes 1000;
|
||||
sig-signing-signatures 100;
|
||||
};
|
||||
|
||||
zone "prepub.example" {
|
||||
|
||||
@@ -72,12 +72,16 @@ checkjitter () {
|
||||
_expiretimes=$(freq "$_file" | awk '{print $1}')
|
||||
|
||||
_count=0
|
||||
# Check if we have at least 8 days
|
||||
# Check if we have at least 5 days
|
||||
# This number has been tuned for `sig-validity-interval 10 2`, as
|
||||
# 1. 1. signature expiration dates should be spread out across at most 8 (10-2) days
|
||||
# 2. we remove first and last day to remove frequency outlier, we are left with 6 (8-2) days
|
||||
# 3. we substract one more day to allow test pass on day boundaries, etc. leaving us with 5 (6-1) days
|
||||
for _num in $_expiretimes
|
||||
do
|
||||
_count=$((_count+1))
|
||||
done
|
||||
if [ "$_count" -lt 8 ]; then
|
||||
if [ "$_count" -lt 5 ]; then
|
||||
echo_i "error: not enough categories"
|
||||
return 1
|
||||
fi
|
||||
@@ -103,7 +107,7 @@ checkjitter () {
|
||||
_low=$((_mean-_limit))
|
||||
_high=$((_mean+_limit))
|
||||
# Find outliers.
|
||||
echo_i "checking whether all frequencies falls into <$_low;$_high> interval"
|
||||
echo_i "checking whether all frequencies fall into <$_low;$_high> range"
|
||||
for _num in $_expiretimes
|
||||
do
|
||||
if [ $_num -gt $_high ] || [ $_num -lt $_low ]; then
|
||||
@@ -387,20 +391,26 @@ $RNDCCMD 10.53.0.1 sync 2>&1 | sed 's/^/ns1 /' | cat_i
|
||||
$RNDCCMD 10.53.0.2 sync 2>&1 | sed 's/^/ns2 /' | cat_i
|
||||
$RNDCCMD 10.53.0.3 sync 2>&1 | sed 's/^/ns3 /' | cat_i
|
||||
|
||||
now="$(TZ=UTC date +%Y%m%d%H%M%S)"
|
||||
check_expiry() (
|
||||
$DIG $DIGOPTS AXFR oldsigs.example @10.53.0.3 > dig.out.test$n
|
||||
nearest_expiration="$(awk '$4 == "RRSIG" { print $9 }' < dig.out.test$n | sort -n | head -1)"
|
||||
if [ "$nearest_expiration" -le "$now" ]; then
|
||||
echo_i "failed: $nearest_expiration <= $now"
|
||||
return 1
|
||||
fi
|
||||
)
|
||||
|
||||
echo_i "checking expired signatures were updated ($n)"
|
||||
for i in 1 2 3 4 5 6 7 8 9
|
||||
do
|
||||
ret=0
|
||||
$DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.3 a > dig.out.ns3.test$n || ret=1
|
||||
$DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.4 a > dig.out.ns4.test$n || ret=1
|
||||
digcomp dig.out.ns3.test$n dig.out.ns4.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n > /dev/null || ret=1
|
||||
[ $ret = 0 ] && break
|
||||
sleep 1
|
||||
done
|
||||
retry 10 check_expiry || ret=1
|
||||
$DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.3 a > dig.out.ns3.test$n || ret=1
|
||||
$DIG $DIGOPTS +noauth a.oldsigs.example. @10.53.0.4 a > dig.out.ns4.test$n || ret=1
|
||||
digcomp dig.out.ns3.test$n dig.out.ns4.test$n || ret=1
|
||||
grep "flags:.*ad.*QUERY" dig.out.ns4.test$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
# Check jitter distribution.
|
||||
echo_i "checking expired signatures were jittered correctly ($n)"
|
||||
ret=0
|
||||
@@ -1027,19 +1037,14 @@ $KEYGEN -a rsasha1 -3 -q -K ns3 jitter.nsec3.example > /dev/null
|
||||
# Trigger zone signing.
|
||||
$RNDCCMD 10.53.0.3 sign jitter.nsec3.example. 2>&1 | sed 's/^/ns3 /' | cat_i
|
||||
# Wait until zone has been signed.
|
||||
i=0
|
||||
while [ "$i" -lt 20 ]; do
|
||||
failed=0
|
||||
$DIG $DIGOPTS axfr jitter.nsec3.example @10.53.0.3 > dig.out.ns3.test$n || failed=1
|
||||
grep "NSEC3PARAM" dig.out.ns3.test$n > /dev/null || failed=1
|
||||
[ $failed -eq 0 ] && break
|
||||
echo_i "waiting ... ($i)"
|
||||
sleep $((i/5))
|
||||
i=$((i+1))
|
||||
done
|
||||
[ $failed != 0 ] && echo_i "error: no NSEC3PARAM found in AXFR" && ret=1
|
||||
check_if_nsec3param_exists() {
|
||||
$DIG $DIGOPTS NSEC3PARAM jitter.nsec3.example @10.53.0.3 > dig.out.ns3.1.test$n || return 1
|
||||
grep -q "^jitter\.nsec3\.example\..*NSEC3PARAM" dig.out.ns3.1.test$n || return 1
|
||||
}
|
||||
retry_quiet 20 check_if_nsec3param_exists || ret=1
|
||||
$DIG $DIGOPTS AXFR jitter.nsec3.example @10.53.0.3 > dig.out.ns3.2.test$n || ret=1
|
||||
# Check jitter distribution.
|
||||
checkjitter dig.out.ns3.test$n || ret=1
|
||||
checkjitter dig.out.ns3.2.test$n || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
@@ -1354,7 +1359,6 @@ $DIG $DIGOPTS @10.53.0.3 sync.example cdnskey > dig.out.ns3.cdnskeytest$n
|
||||
grep -i "sync.example.*in.cds.*[1-9][0-9]* " dig.out.ns3.cdstest$n > /dev/null || ret=1
|
||||
grep -i "sync.example.*in.cdnskey.*257 " dig.out.ns3.cdnskeytest$n > /dev/null || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ "$lret" != 0 ]; then ret=$lret; fi
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
@@ -1389,19 +1393,19 @@ if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
echo_i "setting CDS and CDNSKEY deletion times and calling 'rndc loadkeys'"
|
||||
$SETTIME -D sync now+2 `cat sync.key` > /dev/null
|
||||
$SETTIME -D sync now `cat sync.key` > /dev/null
|
||||
$RNDCCMD 10.53.0.3 loadkeys sync.example | sed 's/^/ns3 /' | cat_i
|
||||
echo_i "waiting for deletion to occur"
|
||||
sleep 3
|
||||
|
||||
echo_i "checking that the CDS and CDNSKEY are deleted ($n)"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.3 sync.example cds > dig.out.ns3.cdstest$n
|
||||
$DIG $DIGOPTS @10.53.0.3 sync.example cdnskey > dig.out.ns3.cdnskeytest$n
|
||||
grep -i "sync.example.*in.cds.*[1-9][0-9]* " dig.out.ns3.cdstest$n > /dev/null && ret=1
|
||||
grep -i "sync.example.*in.cdnskey.*257 " dig.out.ns3.cdnskeytest$n > /dev/null && ret=1
|
||||
ensure_cds_and_cdnskey_are_deleted() {
|
||||
$DIG $DIGOPTS @10.53.0.3 sync.example. CDS > dig.out.ns3.cdstest$n || return 1
|
||||
awk '$1 == "sync.example." && $4 == "CDS" { exit 1; }' dig.out.ns3.cdstest$n || return 1
|
||||
$DIG $DIGOPTS @10.53.0.3 sync.example. CDNSKEY > dig.out.ns3.cdnskeytest$n || return 1
|
||||
awk '$1 == "sync.example." && $4 == "CDNSKEY" { exit 1; }' dig.out.ns3.cdnskeytest$n || return 1
|
||||
}
|
||||
retry 10 ensure_cds_and_cdnskey_are_deleted || ret=1
|
||||
n=`expr $n + 1`
|
||||
if [ "$lret" != 0 ]; then ret=$lret; fi
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
@@ -1410,7 +1414,6 @@ ret=0
|
||||
$SETTIME -p Dsync `cat sync.key` > settime.out.$n|| ret=0
|
||||
grep "SYNC Delete:" settime.out.$n >/dev/null || ret=0
|
||||
n=`expr $n + 1`
|
||||
if [ "$lret" != 0 ]; then ret=$lret; fi
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
@@ -1419,7 +1422,6 @@ ret=0
|
||||
$SETTIME -p Psync `cat sync.key` > settime.out.$n|| ret=0
|
||||
grep "SYNC Publish:" settime.out.$n >/dev/null || ret=0
|
||||
n=`expr $n + 1`
|
||||
if [ "$lret" != 0 ]; then ret=$lret; fi
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-keys {
|
||||
example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
|
||||
example. initial-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
|
||||
};
|
||||
@@ -0,0 +1,15 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-keys {
|
||||
example. static-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
|
||||
example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
|
||||
};
|
||||
@@ -0,0 +1,15 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-keys {
|
||||
example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
|
||||
example. static-ds 60724 5 2 "29E79B9064EE1A11DF3BFF19581DDFED7952C22CC204ACE17B6007EB1437E9E6";
|
||||
};
|
||||
@@ -0,0 +1,15 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-keys {
|
||||
example. initial-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
|
||||
example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
|
||||
};
|
||||
@@ -0,0 +1,15 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-keys {
|
||||
example. static-ds 60724 5 1 "D74CF845955A0DFE604AF215E948E67D2EA94FF3";
|
||||
example. initial-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
|
||||
};
|
||||
@@ -0,0 +1,15 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-keys {
|
||||
example. initial-key 257 3 5 "AwEAAawvFp8GlBx8Qt6yaIqXkDe+nMkSk2HkTAG7qlVBo++AQwZ1j3Xl25IN4jsw0VTMbKUbafw9DYsVzztIwx1sNkKRLo6qP9SSkBL8RicQaafGtURtsYI3oqte5qqLve1CUpRD8J06Pg1xkOxsDlz9sQAyiQrOyvMbykJYkYrFYGLzYAgl/JtMyVVYlBl9pqxQuAPKYPOuO1axaad/wLN3+wTy/hcJfpvJpqzXlDF9bI5RmpoX/7geZ06vpcYJEoT0xkkmPlEl0ZjEDrm/WIaSWG0/CEDpHcOXFz4OEczMVpY+lnuFfKybwF1WHFn2BwVEOS6cMM6ukIjINQyrszHhWUU=";
|
||||
example. static-key 257 3 5 "AwEAAZtP9+RAA+W33A97e+HnnH8WTXzCWiEICyWj1B6rvZ9hd50ysbody0NLx7b3vZ1bzMLxLSRAr/n3Wi0TDZ1fvCKZhennfW8Wlc7ulCvHntSQYfKHUP0YWEo84sQAqIi850N1aiddj6CidwFo9JNW/HQ+8yarfrnGMFhX2STtkE0hNJ/R6JYKmD2EH7k1nyqJd08ibrEt55DuV4BiUjyyERdVbsuwE60jVqAwCKyVBYXb2sI+zv1yPNDBIANd6KTgnq6YWzx5ZodQP3W4K7Z/Bk3EKmVCvrTKZK/ADLAKaL0/6DD07+1jXA4BiNyoZTLTapkudkGad+Rn6zqCkwuMmrU=";
|
||||
};
|
||||
@@ -0,0 +1,14 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-keys {
|
||||
. static-ds 20326 8 2 "E06D44B80B8F1D39A95C0B0D7C65D08458E880409BBC683457104237C7F8EC8D";
|
||||
};
|
||||
@@ -0,0 +1,14 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-keys {
|
||||
example. initial-ds 60724 5 2 "29E79B9064EE1A11DF3BFF19581DDFED7952C22CC204ACE17B6007EB1437E9E6";
|
||||
};
|
||||
@@ -0,0 +1,14 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
dnssec-keys {
|
||||
example. static-ds 60724 5 2 "29E79B9064EE1A11DF3BFF19581DDFED7952C22CC204ACE17B6007EB1437E9E6";
|
||||
};
|
||||
@@ -437,7 +437,15 @@ n=`expr $n + 1`
|
||||
echo_i "check that a static root key generates a warning ($n)"
|
||||
ret=0
|
||||
$CHECKCONF check-root-static-key.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||
grep "static-key entry for the root zone WILL FAIL" checkconf.out$n > /dev/null || ret=1
|
||||
grep "static entry for the root zone WILL FAIL" checkconf.out$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; ret=1; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo_i "check that a static root DS trust anchor generates a warning ($n)"
|
||||
ret=0
|
||||
$CHECKCONF check-root-static-ds.conf > checkconf.out$n 2>/dev/null || ret=1
|
||||
grep "static entry for the root zone WILL FAIL" checkconf.out$n > /dev/null || ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; ret=1; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
|
||||
@@ -221,9 +221,9 @@ assert_int_equal() {
|
||||
}
|
||||
|
||||
# keyfile_to_keys_section: helper function for keyfile_to_*_keys() which
|
||||
# converts keyfile data into a configuration section using the supplied
|
||||
# parameters
|
||||
keyfile_to_keys_section() {
|
||||
# converts keyfile data into a key-style trust anchor configuration
|
||||
# section using the supplied parameters
|
||||
keyfile_to_keys() {
|
||||
section_name=$1
|
||||
key_prefix=$2
|
||||
shift
|
||||
@@ -241,18 +241,54 @@ keyfile_to_keys_section() {
|
||||
echo "};"
|
||||
}
|
||||
|
||||
# keyfile_to_dskeys_section: helper function for keyfile_to_*_dskeys()
|
||||
# converts keyfile data into a DS-style trust anchor configuration
|
||||
# section using the supplied parameters
|
||||
keyfile_to_dskeys() {
|
||||
section_name=$1
|
||||
key_prefix=$2
|
||||
shift
|
||||
shift
|
||||
echo "$section_name {"
|
||||
for keyname in $*; do
|
||||
$DSFROMKEY $keyname.key | \
|
||||
awk '!/^; /{
|
||||
printf "\t\""$1"\" "
|
||||
printf "'"$key_prefix "'"
|
||||
printf $4 " " $5 " " $6 " \""
|
||||
for (i=7; i<=NF; i++) printf $i
|
||||
printf "\";\n"
|
||||
}'
|
||||
done
|
||||
echo "};"
|
||||
}
|
||||
|
||||
# keyfile_to_static_keys: convert key data contained in the keyfile(s)
|
||||
# provided to a *static* "dnssec-keys" section suitable for including in a
|
||||
# provided to a *static-key* "dnssec-keys" section suitable for including in a
|
||||
# resolver's configuration file
|
||||
keyfile_to_static_keys() {
|
||||
keyfile_to_keys_section "dnssec-keys" "static-key" $*
|
||||
keyfile_to_keys "dnssec-keys" "static-key" $*
|
||||
}
|
||||
|
||||
# keyfile_to_initial_keys: convert key data contained in the keyfile(s)
|
||||
# provided to an *initialzing* "dnssec-keys" section suitable for including
|
||||
# provided to an *initial-key* "dnssec-keys" section suitable for including
|
||||
# in a resolver's configuration file
|
||||
keyfile_to_initial_keys() {
|
||||
keyfile_to_keys_section "dnssec-keys" "initial-key" $*
|
||||
keyfile_to_keys "dnssec-keys" "initial-key" $*
|
||||
}
|
||||
|
||||
# keyfile_to_static_ds_keys: convert key data contained in the keyfile(s)
|
||||
# provided to a *static-ds* "dnssec-keys" section suitable for including in a
|
||||
# resolver's configuration file
|
||||
keyfile_to_static_ds() {
|
||||
keyfile_to_dskeys "dnssec-keys" "static-ds" $*
|
||||
}
|
||||
|
||||
# keyfile_to_initial_ds_keys: convert key data contained in the keyfile(s)
|
||||
# provided to an *initial-ds* "dnssec-keys" section suitable for including
|
||||
# in a resolver's configuration file
|
||||
keyfile_to_initial_ds() {
|
||||
keyfile_to_dskeys "dnssec-keys" "initial-ds" $*
|
||||
}
|
||||
|
||||
# keyfile_to_key_id: convert a key file name to a key ID
|
||||
@@ -338,9 +374,9 @@ nextpartpeek() {
|
||||
nextpartread $1 2> /dev/null
|
||||
}
|
||||
|
||||
# retry: keep running a command until it succeeds, up to $1 times, with
|
||||
# one-second intervals
|
||||
retry() {
|
||||
# _retry: keep running a command until it succeeds, up to $1 times, with
|
||||
# one-second intervals, optionally printing a message upon every attempt
|
||||
_retry() {
|
||||
__retries="${1}"
|
||||
shift
|
||||
|
||||
@@ -350,7 +386,9 @@ retry() {
|
||||
fi
|
||||
__retries=$((__retries-1))
|
||||
if [ "${__retries}" -gt 0 ]; then
|
||||
echo_i "retrying"
|
||||
if [ "${__retry_quiet}" -ne 1 ]; then
|
||||
echo_i "retrying"
|
||||
fi
|
||||
sleep 1
|
||||
else
|
||||
return 1
|
||||
@@ -358,6 +396,18 @@ retry() {
|
||||
done
|
||||
}
|
||||
|
||||
# retry: call _retry() in verbose mode
|
||||
retry() {
|
||||
__retry_quiet=0
|
||||
_retry "$@"
|
||||
}
|
||||
|
||||
# retry_quiet: call _retry() in silent mode
|
||||
retry_quiet() {
|
||||
__retry_quiet=1
|
||||
_retry "$@"
|
||||
}
|
||||
|
||||
rndc_reload() {
|
||||
echo_i "`$RNDC -c ../common/rndc.conf -s $2 -p ${CONTROLPORT} reload $3 2>&1 | sed 's/^/'$1' /'`"
|
||||
# reloading single zone is synchronous, if we're reloading whole server
|
||||
@@ -526,5 +576,6 @@ export RRCHECKER
|
||||
export SAMPLEUPDATE
|
||||
export SIGNER
|
||||
export SUBDIRS
|
||||
export TMPDIR
|
||||
export TSIGKEYGEN
|
||||
export WIRETEST
|
||||
|
||||
@@ -17,6 +17,9 @@
|
||||
# Find the top of the BIND9 tree.
|
||||
TOP=@abs_top_builddir@
|
||||
|
||||
# Provide TMPDIR variable for tests that need it.
|
||||
TMPDIR=${TMPDIR:-/tmp}
|
||||
|
||||
# This is not the windows build.
|
||||
CYGWIN=""
|
||||
|
||||
|
||||
@@ -752,6 +752,7 @@ if [ -x "$DIG" ] ; then
|
||||
status=$((status+ret))
|
||||
fi
|
||||
|
||||
n=$((n+1))
|
||||
echo_i "check that dig +unexpected works ($n)"
|
||||
ret=0
|
||||
dig_with_opts @10.53.0.6 +unexpected a a.example > dig.out.test$n || ret=1
|
||||
|
||||
@@ -30,14 +30,15 @@ cp "../ns2/dsset-in-addr.arpa$TP" .
|
||||
grep "$DEFAULT_ALGORITHM_NUMBER [12] " "../ns2/dsset-algroll$TP" > "dsset-algroll$TP"
|
||||
cp "../ns6/dsset-optout-tld$TP" .
|
||||
|
||||
keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone")
|
||||
ksk=$("$KEYGEN" -q -fk -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone")
|
||||
zsk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone "$zone")
|
||||
|
||||
cat "$infile" "$keyname.key" > "$zonefile"
|
||||
cat "$infile" "$ksk.key" "$zsk.key" > "$zonefile"
|
||||
|
||||
"$SIGNER" -P -g -o "$zone" "$zonefile" > /dev/null 2>&1
|
||||
|
||||
# Configure the resolving server with a staitc key.
|
||||
keyfile_to_static_keys "$keyname" > trusted.conf
|
||||
keyfile_to_static_ds "$ksk" > trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
cp trusted.conf ../ns3/trusted.conf
|
||||
cp trusted.conf ../ns4/trusted.conf
|
||||
@@ -46,11 +47,11 @@ cp trusted.conf ../ns7/trusted.conf
|
||||
cp trusted.conf ../ns9/trusted.conf
|
||||
|
||||
# ...or with an initializing key.
|
||||
keyfile_to_initial_keys "$keyname" > managed.conf
|
||||
keyfile_to_initial_ds "$ksk" > managed.conf
|
||||
cp managed.conf ../ns4/managed.conf
|
||||
|
||||
#
|
||||
# Save keyid for managed key id test.
|
||||
#
|
||||
|
||||
keyfile_to_key_id "$keyname" > managed.key.id
|
||||
keyfile_to_key_id "$ksk" > managed.key.id
|
||||
|
||||
@@ -23,7 +23,7 @@ zonefile=root.db.signed
|
||||
keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -f KSK "$zone")
|
||||
|
||||
# copy the KSK out first, then revoke it
|
||||
keyfile_to_initial_keys "$keyname" > revoked.conf
|
||||
keyfile_to_initial_ds "$keyname" > revoked.conf
|
||||
|
||||
"$SETTIME" -R now "${keyname}.key" > /dev/null
|
||||
|
||||
@@ -34,4 +34,4 @@ keyfile_to_initial_keys "$keyname" > revoked.conf
|
||||
|
||||
keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone ".")
|
||||
|
||||
keyfile_to_static_keys "$keyname" > trusted.conf
|
||||
keyfile_to_static_ds "$keyname" > trusted.conf
|
||||
|
||||
@@ -20,7 +20,6 @@ options {
|
||||
listen-on { 10.53.0.8; };
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
minimal-responses no;
|
||||
disable-algorithms "disabled.managed." { @DISABLED_ALGORITHM@; };
|
||||
|
||||
@@ -20,7 +20,6 @@ options {
|
||||
listen-on { 10.53.0.9; };
|
||||
listen-on-v6 { none; };
|
||||
recursion yes;
|
||||
dnssec-enable yes;
|
||||
dnssec-validation yes;
|
||||
forward only;
|
||||
forwarders { 10.53.0.4; };
|
||||
|
||||
@@ -29,7 +29,7 @@ cat $infile $key1.key $key2.key > $zonefile
|
||||
$SIGNER -P -g -o $zone $zonefile > /dev/null
|
||||
|
||||
# Configure the resolving server with a static key.
|
||||
keyfile_to_static_keys $key2 > trusted.conf
|
||||
keyfile_to_static_ds $key2 > trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
cp trusted.conf ../ns3/trusted.conf
|
||||
cp trusted.conf ../ns4/trusted.conf
|
||||
|
||||
@@ -25,5 +25,5 @@ cat $infile $key1.key $key2.key > $zonefile
|
||||
$SIGNER -P -g -o $zone $zonefile > /dev/null 2> signer.err || cat signer.err
|
||||
|
||||
# Configure the resolving server with a static key.
|
||||
keyfile_to_static_keys $key1 > trusted.conf
|
||||
keyfile_to_static_ds $key1 > trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
|
||||
@@ -26,7 +26,7 @@ cat $infile $key1.key $key2.key > $zonefile
|
||||
$SIGNER -P -g -o $zone $zonefile > /dev/null 2> signer.err || cat signer.err
|
||||
|
||||
# Configure the resolving server with a static key.
|
||||
keyfile_to_static_keys $key1 > trusted.conf
|
||||
keyfile_to_static_ds $key1 > trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
|
||||
cd ../ns2 && $SHELL sign.sh
|
||||
|
||||
@@ -24,7 +24,7 @@ $KEYGEN -f KSK -a $DEFAULT_ALGORITHM $zone 2>&1 > keygen.out | cat_i
|
||||
keyname=`cat keygen.out`
|
||||
rm -f keygen.out
|
||||
|
||||
keyfile_to_static_keys $keyname > trusted.conf
|
||||
keyfile_to_static_ds $keyname > trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
cp trusted.conf ../ns3/trusted.conf
|
||||
cp trusted.conf ../ns5/trusted.conf
|
||||
|
||||
@@ -20,5 +20,5 @@ keyname=`$KEYGEN -q -a RSASHA1 -b 1024 -n zone -f KSK $zone`
|
||||
$SIGNER -S -x -T 1200 -o ${zone} root.db > signer.out
|
||||
[ $? = 0 ] || cat signer.out
|
||||
|
||||
keyfile_to_static_keys $keyname > trusted.conf
|
||||
keyfile_to_static_ds $keyname > trusted.conf
|
||||
cp trusted.conf ../ns6/trusted.conf
|
||||
|
||||
@@ -852,6 +852,19 @@ check_signatures() {
|
||||
fi
|
||||
}
|
||||
|
||||
response_has_cds_for_key() (
|
||||
awk -v zone="${ZONE%%.}." \
|
||||
-v ttl="${DNSKEY_TTL}" \
|
||||
-v qtype="${_qtype}" \
|
||||
-v keyid="$(key_get "${1}" ID)" \
|
||||
-v keyalg="${_key_algnum}" \
|
||||
-v hashalg="2" \
|
||||
'BEGIN { ret=1; }
|
||||
$1 == zone && $2 == ttl && $4 == qtype && $5 == keyid && $6 == keyalg && $7 == hashalg { ret=0; exit; }
|
||||
END { exit ret; }' \
|
||||
"$2"
|
||||
)
|
||||
|
||||
# Test CDS and CDNSKEY publication.
|
||||
check_cds() {
|
||||
|
||||
@@ -865,24 +878,24 @@ check_cds() {
|
||||
grep "status: NOERROR" "dig.out.$DIR.test$n" > /dev/null || log_error "mismatch status in DNS response"
|
||||
|
||||
if [ "$(key_get KEY1 STATE_DS)" = "rumoured" ] || [ "$(key_get KEY1 STATE_DS)" = "omnipresent" ]; then
|
||||
grep "${ZONE}\..*${DNSKEY_TTL}.*IN.*${_qtype}.*$(key_get KEY1 ID).*${_key_algnum}.*2" "dig.out.$DIR.test$n" > /dev/null || log_error "missing ${_qtype} record in response for key $(key_get KEY1 ID)"
|
||||
response_has_cds_for_key KEY1 "dig.out.$DIR.test$n" || log_error "missing ${_qtype} record in response for key $(key_get KEY1 ID)"
|
||||
check_signatures $_qtype "dig.out.$DIR.test$n" "KSK"
|
||||
elif [ "$(key_get KEY1 EXPECT)" = "yes" ]; then
|
||||
grep "${ZONE}\..*${DNSKEY_TTL}.*IN.*${_qtype}.*$(key_get KEY1 ID).*${_key_algnum}.*2" "dig.out.$DIR.test$n" > /dev/null && log_error "unexpected ${_qtype} record in response for key $(key_get KEY1 ID)"
|
||||
response_has_cds_for_key KEY1 "dig.out.$DIR.test$n" && log_error "unexpected ${_qtype} record in response for key $(key_get KEY1 ID)"
|
||||
fi
|
||||
|
||||
if [ "$(key_get KEY2 STATE_DS)" = "rumoured" ] || [ "$(key_get KEY2 STATE_DS)" = "omnipresent" ]; then
|
||||
grep "${ZONE}\..*${DNSKEY_TTL}.*IN.*${_qtype}.*$(key_get KEY2 ID).*${_key_algnum}.*2" "dig.out.$DIR.test$n" > /dev/null || log_error "missing ${_qtype} record in response for key $(key_get KEY2 ID)"
|
||||
response_has_cds_for_key KEY2 "dig.out.$DIR.test$n" || log_error "missing ${_qtype} record in response for key $(key_get KEY2 ID)"
|
||||
check_signatures $_qtype "dig.out.$DIR.test$n" "KSK"
|
||||
elif [ "$(key_get KEY2 EXPECT)" = "yes" ]; then
|
||||
grep "${ZONE}\..*${DNSKEY_TTL}.*IN.*${_qtype}.*$(key_get KEY2 ID).*${_key_algnum}.*2" "dig.out.$DIR.test$n" > /dev/null && log_error "unexpected ${_qtype} record in response for key $(key_get KEY2 ID)"
|
||||
response_has_cds_for_key KEY2 "dig.out.$DIR.test$n" && log_error "unexpected ${_qtype} record in response for key $(key_get KEY2 ID)"
|
||||
fi
|
||||
|
||||
if [ "$(key_get KEY3 STATE_DS)" = "rumoured" ] || [ "$(key_get KEY3 STATE_DS)" = "omnipresent" ]; then
|
||||
grep "${ZONE}\..*${DNSKEY_TTL}.*IN.*${_qtype}.*$(key_get KEY3 ID).*${_key_algnum}.*2" "dig.out.$DIR.test$n" > /dev/null || log_error "missing ${_qtype} record in response for key $(key_get KEY3 ID)"
|
||||
response_has_cds_for_key KEY3 "dig.out.$DIR.test$n" || log_error "missing ${_qtype} record in response for key $(key_get KEY3 ID)"
|
||||
check_signatures $_qtype "dig.out.$DIR.test$n" "KSK"
|
||||
elif [ "$(key_get KEY3 EXPECT)" = "yes" ]; then
|
||||
grep "${ZONE}\..*${DNSKEY_TTL}.*IN.*${_qtype}.*$(key_get KEY3 ID).*${_key_algnum}.*2" "dig.out.$DIR.test$n" > /dev/null && log_error "unexpected ${_qtype} record in response for key $(key_get KEY3 ID)"
|
||||
response_has_cds_for_key KEY3 "dig.out.$DIR.test$n" && log_error "unexpected ${_qtype} record in response for key $(key_get KEY3 ID)"
|
||||
fi
|
||||
|
||||
test "$ret" -eq 0 || echo_i "failed"
|
||||
|
||||
@@ -28,5 +28,5 @@ cat $infile $keyname1.key $keyname2.key >$zonefile
|
||||
|
||||
$SIGNER -g -o $zone -f $outfile -e +30y $zonefile > /dev/null 2> signer.err || cat signer.err
|
||||
|
||||
keyfile_to_static_keys $keyname2 > trusted.conf
|
||||
keyfile_to_static_ds $keyname2 > trusted.conf
|
||||
cp trusted.conf ../ns1
|
||||
|
||||
@@ -33,4 +33,4 @@ $SIGNER -P -g -o $zone $zonefile > /dev/null
|
||||
# irrelevant here, so just reuse the root zone key generated above.
|
||||
sed "s/^\./nonexistent./;" $keyname1.key > $keyname1.modified.key
|
||||
|
||||
keyfile_to_static_keys $keyname1 $keyname1.modified > trusted.conf
|
||||
keyfile_to_static_ds $keyname1 $keyname1.modified > trusted.conf
|
||||
|
||||
@@ -75,4 +75,4 @@ for variant in addzone axfr ixfr load reconfig untrusted; do
|
||||
fi
|
||||
done
|
||||
|
||||
keyfile_to_static_keys $keys_to_trust > trusted-mirror.conf
|
||||
keyfile_to_static_ds $keys_to_trust > trusted-mirror.conf
|
||||
|
||||
@@ -21,13 +21,13 @@ zskkeyname=`$KEYGEN -a rsasha256 -q $zone`
|
||||
$SIGNER -Sg -o $zone $zonefile > /dev/null 2>/dev/null
|
||||
|
||||
# Configure the resolving server with an initializing key.
|
||||
keyfile_to_initial_keys $keyname > managed.conf
|
||||
keyfile_to_initial_ds $keyname > managed.conf
|
||||
cp managed.conf ../ns2/managed.conf
|
||||
cp managed.conf ../ns4/managed.conf
|
||||
cp managed.conf ../ns5/managed.conf
|
||||
|
||||
# Configure a static key to be used by delv.
|
||||
keyfile_to_static_keys $keyname > trusted.conf
|
||||
keyfile_to_static_ds $keyname > trusted.conf
|
||||
|
||||
# Prepare an unsupported algorithm key.
|
||||
unsupportedkey=Kunknown.+255+00000
|
||||
|
||||
@@ -27,4 +27,6 @@ rootkey=`cat ../ns1/managed.key`
|
||||
cp "../ns1/${rootkey}.key" .
|
||||
|
||||
# Configure the resolving server with an initializing key.
|
||||
# (We use key-format trust anchors here because otherwise the
|
||||
# unsupported algorithm test won't work.)
|
||||
keyfile_to_initial_keys $unsupportedkey $rsakey $rootkey > managed.conf
|
||||
|
||||
@@ -301,7 +301,7 @@ status=`expr $status + $ret`
|
||||
echo_i "reinitialize trust anchors, add second key to bind.keys"
|
||||
$PERL $SYSTEMTESTTOP/stop.pl --use-rndc --port ${CONTROLPORT} mkeys ns2
|
||||
rm -f ns2/managed-keys.bind*
|
||||
keyfile_to_initial_keys ns1/$original ns1/$standby1 > ns2/managed.conf
|
||||
keyfile_to_initial_ds ns1/$original ns1/$standby1 > ns2/managed.conf
|
||||
nextpart ns2/named.run > /dev/null
|
||||
$PERL $SYSTEMTESTTOP/start.pl --noclean --restart --port ${PORT} mkeys ns2
|
||||
|
||||
|
||||
@@ -28,7 +28,7 @@ cat $infile $keyname1.key $keyname2.key > $zonefile
|
||||
$SIGNER -g -o $zone $zonefile > /dev/null
|
||||
|
||||
# Configure the resolving server with a static key.
|
||||
keyfile_to_static_keys $keyname2 > trusted.conf
|
||||
keyfile_to_static_ds $keyname2 > trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
cp trusted.conf ../ns3/trusted.conf
|
||||
cp trusted.conf ../ns4/trusted.conf
|
||||
|
||||
@@ -22,6 +22,7 @@ options {
|
||||
recursion yes;
|
||||
dnssec-validation yes;
|
||||
querylog yes;
|
||||
prefetch 3 9;
|
||||
};
|
||||
|
||||
server 10.53.0.7 {
|
||||
|
||||
@@ -31,4 +31,4 @@ cat $ksk.key $zsk.key dsset-ds.example.net$TP >> $zonefile
|
||||
$SIGNER -P -o $zone $zonefile > /dev/null
|
||||
|
||||
# Configure a static key to be used by delv
|
||||
keyfile_to_static_keys $ksk > ../ns5/trusted.conf
|
||||
keyfile_to_static_ds $ksk > ../ns5/trusted.conf
|
||||
|
||||
@@ -452,7 +452,7 @@ n=`expr $n + 1`
|
||||
echo_i "check prefetch (${n})"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.5 fetch.tld txt > dig.out.1.${n} || ret=1
|
||||
ttl1=`awk '/"A" "short" "ttl"/ { print $2 - 2 }' dig.out.1.${n}`
|
||||
ttl1=`awk '/"A" "short" "ttl"/ { print $2 - 3 }' dig.out.1.${n}`
|
||||
# sleep so we are in prefetch range
|
||||
sleep ${ttl1:-0}
|
||||
# trigger prefetch
|
||||
@@ -470,7 +470,7 @@ n=`expr $n + 1`
|
||||
echo_i "check prefetch of validated DS's RRSIG TTL is updated (${n})"
|
||||
ret=0
|
||||
$DIG $DIGOPTS +dnssec @10.53.0.5 ds.example.net ds > dig.out.1.${n} || ret=1
|
||||
dsttl1=`awk '$4 == "DS" && $7 == "2" { print $2 - 2 }' dig.out.1.${n}`
|
||||
dsttl1=`awk '$4 == "DS" && $7 == "2" { print $2 - 3 }' dig.out.1.${n}`
|
||||
# sleep so we are in prefetch range
|
||||
sleep ${dsttl1:-0}
|
||||
# trigger prefetch
|
||||
@@ -517,7 +517,7 @@ n=`expr $n + 1`
|
||||
echo_i "check prefetch qtype * (${n})"
|
||||
ret=0
|
||||
$DIG $DIGOPTS @10.53.0.5 fetchall.tld any > dig.out.1.${n} || ret=1
|
||||
ttl1=`awk '/"A" "short" "ttl"/ { print $2 - 2 }' dig.out.1.${n}`
|
||||
ttl1=`awk '/"A" "short" "ttl"/ { print $2 - 3 }' dig.out.1.${n}`
|
||||
# sleep so we are in prefetch range
|
||||
sleep ${ttl1:-0}
|
||||
# trigger prefetch
|
||||
|
||||
@@ -28,7 +28,7 @@ cat $infile $keyname.key > $zonefile
|
||||
$SIGNER -P -g -o $zone $zonefile > /dev/null
|
||||
|
||||
# Configure the resolving server with a static key.
|
||||
keyfile_to_static_keys $keyname > trusted.conf
|
||||
keyfile_to_static_ds $keyname > trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
cp trusted.conf ../ns3/trusted.conf
|
||||
cp trusted.conf ../ns4/trusted.conf
|
||||
|
||||
@@ -25,7 +25,7 @@ cat $infile $keyname.key > $zonefile
|
||||
$SIGNER -P -g -o $zone $zonefile > /dev/null
|
||||
|
||||
# Configure the resolving server with a static key.
|
||||
keyfile_to_static_keys $keyname > trusted.conf
|
||||
keyfile_to_static_ds $keyname > trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
cp trusted.conf ../ns3/trusted.conf
|
||||
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
thread apply all bt full
|
||||
+13
-1
@@ -189,12 +189,24 @@ if [ $status != 0 ]; then
|
||||
echofail "R:$systest:FAIL"
|
||||
# Do not clean up - we need the evidence.
|
||||
else
|
||||
core_dumps="$(find $systest/ -name 'core*' | sort | tr '\n' ' ')"
|
||||
core_dumps="$(find $systest/ -name 'core*' -or -name '*.core' | sort | tr '\n' ' ')"
|
||||
assertion_failures=$(find $systest/ -name named.run | xargs grep "assertion failure" | wc -l)
|
||||
if [ -n "$core_dumps" ]; then
|
||||
echoinfo "I:$systest:Test claims success despite crashes: $core_dumps"
|
||||
echofail "R:$systest:FAIL"
|
||||
# Do not clean up - we need the evidence.
|
||||
find "$systest/" -name 'core*' -or -name '*.core' | while read -r coredump; do
|
||||
SYSTESTDIR="$systest"
|
||||
echoinfo "D:$systest:backtrace from $coredump start"
|
||||
binary=$(gdb --batch --core="$coredump" | sed -ne "s/Core was generated by \`//;s/ .*'.$//p;")
|
||||
"$TOP/libtool" --mode=execute gdb \
|
||||
--batch \
|
||||
--command=run.gdb \
|
||||
--core="$coredump" \
|
||||
-- \
|
||||
"$binary"
|
||||
echoinfo "D:$systest:backtrace from $coredump end"
|
||||
done
|
||||
elif [ $assertion_failures -ne 0 ]; then
|
||||
echoinfo "I:$systest:Test claims success despite $assertion_failures assertion failure(s)"
|
||||
echofail "R:$systest:FAIL"
|
||||
|
||||
@@ -17,6 +17,7 @@ rm -f *.pid
|
||||
rm -f rndc.out*
|
||||
[ -d ns2/nope ] && chmod 755 ns2/nope
|
||||
rm -rf ns2/nope
|
||||
rm -rf ns2/tmp.*
|
||||
rm -f ns*/managed-keys.bind*
|
||||
rm -rf "ns2/`cat ctrl-char-dir-name`"
|
||||
rm -rf "ns2/$;"
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
/*
|
||||
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
*
|
||||
* This Source Code Form is subject to the terms of the Mozilla Public
|
||||
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||
*
|
||||
* See the COPYRIGHT file distributed with this work for additional
|
||||
* information regarding copyright ownership.
|
||||
*/
|
||||
|
||||
options {
|
||||
port @PORT@;
|
||||
pid-file "named9.pid";
|
||||
listen-on { 127.0.0.1; };
|
||||
listen-on-v6 { none; };
|
||||
recursion no;
|
||||
};
|
||||
@@ -1,3 +1,5 @@
|
||||
#!/bin/sh
|
||||
#
|
||||
# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# This Source Code Form is subject to the terms of the Mozilla Public
|
||||
@@ -159,5 +161,31 @@ cd ..
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
|
||||
n=`expr $n + 1`
|
||||
echo_i "verifying that named switches UID ($n)"
|
||||
if [ "`id -u`" = 0 ] && [ ! "$CYGWIN" ]; then
|
||||
ret=0
|
||||
TEMP_NAMED_DIR=`mktemp -d`
|
||||
if [ -d "${TEMP_NAMED_DIR}" ]; then
|
||||
copy_setports ns2/named-alt9.conf.in "${TEMP_NAMED_DIR}/named-alt9.conf"
|
||||
chown -R nobody "${TEMP_NAMED_DIR}"
|
||||
chmod 0700 "${TEMP_NAMED_DIR}"
|
||||
( cd "${TEMP_NAMED_DIR}" && $NAMED -u nobody -c named-alt9.conf -d 99 -g -U 4 >> named9.run 2>&1 & )
|
||||
sleep 2
|
||||
[ -s "${TEMP_NAMED_DIR}/named9.pid" ] || ret=1
|
||||
grep "loading configuration: permission denied" "${TEMP_NAMED_DIR}/named9.run" > /dev/null && ret=1
|
||||
pid=`cat "${TEMP_NAMED_DIR}/named9.pid" 2>/dev/null`
|
||||
test "${pid:+set}" = set && $KILL -15 "${pid}" >/dev/null 2>&1
|
||||
mv "${TEMP_NAMED_DIR}" ns2/
|
||||
else
|
||||
echo_i "mktemp failed"
|
||||
ret=1
|
||||
fi
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=`expr $status + $ret`
|
||||
else
|
||||
echo_i "skipped, not running as root or running on Windows"
|
||||
fi
|
||||
|
||||
echo_i "exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -29,8 +29,8 @@ cat "$infile" "$keyname.key" > "$zonefile"
|
||||
$SIGNER -P -g -o $zone $zonefile > /dev/null
|
||||
|
||||
# Configure the resolving server with a static key.
|
||||
keyfile_to_static_keys "$keyname" > trusted.conf
|
||||
keyfile_to_static_ds "$keyname" > trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
|
||||
# ...or with an initializing key.
|
||||
keyfile_to_initial_keys "$keyname" > managed.conf
|
||||
keyfile_to_initial_ds "$keyname" > managed.conf
|
||||
|
||||
@@ -16,4 +16,4 @@ set -e
|
||||
|
||||
keyname=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -n zone ".")
|
||||
|
||||
keyfile_to_static_keys "$keyname" > trusted.conf
|
||||
keyfile_to_static_ds "$keyname" > trusted.conf
|
||||
|
||||
@@ -27,7 +27,7 @@ cat $infile $keyname1.key $keyname2.key > $zonefile
|
||||
$SIGNER -g -o $zone $zonefile > /dev/null
|
||||
|
||||
# Configure the resolving server with a trusted key.
|
||||
keyfile_to_static_keys $keyname2 > trusted.conf
|
||||
keyfile_to_static_ds $keyname2 > trusted.conf
|
||||
|
||||
zone=undelegated
|
||||
infile=undelegated.db.in
|
||||
@@ -38,5 +38,5 @@ cat $infile $keyname1.key $keyname2.key > $zonefile
|
||||
|
||||
$SIGNER -g -o $zone $zonefile > /dev/null
|
||||
|
||||
keyfile_to_static_keys $keyname2 >> trusted.conf
|
||||
keyfile_to_static_ds $keyname2 >> trusted.conf
|
||||
cp trusted.conf ../ns2/trusted.conf
|
||||
|
||||
@@ -109,7 +109,7 @@ foreach my $name(@ans) {
|
||||
stop_signal($name, "TERM", 1);
|
||||
}
|
||||
|
||||
@ans = wait_for_servers(60, @ans);
|
||||
@ans = wait_for_servers(1200, @ans);
|
||||
|
||||
# Pass 3: SIGABRT
|
||||
foreach my $name (@ns) {
|
||||
|
||||
@@ -40,4 +40,4 @@ cat "$infile" "$keyname.key" > "$zonefile"
|
||||
$SIGNER -P -g -o $zone $zonefile > /dev/null
|
||||
|
||||
# Configure the resolving server with a static key.
|
||||
keyfile_to_static_keys "$keyname" > trusted.conf
|
||||
keyfile_to_static_ds "$keyname" > trusted.conf
|
||||
|
||||
@@ -82,7 +82,7 @@ wait_for_log() {
|
||||
msg=$1
|
||||
file=$2
|
||||
for _ in 1 2 3 4 5 6 7 8 9 10; do
|
||||
nextpart "$file" | grep "$msg" > /dev/null && return
|
||||
nextpartpeek "$file" | grep "$msg" > /dev/null && return
|
||||
sleep 1
|
||||
done
|
||||
echo_i "exceeded time limit waiting for '$msg' in $file"
|
||||
@@ -94,16 +94,19 @@ send_command() {
|
||||
nextpart ans6/ans.run > /dev/null
|
||||
echo "$*" | "${PERL}" "${SYSTEMTESTTOP}/send.pl" 10.53.0.6 "${CONTROLPORT}"
|
||||
wait_for_log "result=" ans6/ans.run
|
||||
if ! nextpartpeek ans6/ans.run | grep -qF "result=OK"; then
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
# Instructs ans6 to open $1 TCP connections to 10.53.0.5.
|
||||
open_connections() {
|
||||
send_command "open" "${1}" 10.53.0.5 "${PORT}"
|
||||
send_command "open" "${1}" 10.53.0.5 "${PORT}" || return 1
|
||||
}
|
||||
|
||||
# Instructs ans6 to close $1 TCP connections to 10.53.0.5.
|
||||
close_connections() {
|
||||
send_command "close" "${1}"
|
||||
send_command "close" "${1}" || return 1
|
||||
}
|
||||
|
||||
# Check TCP statistics after server startup before using them as a baseline for
|
||||
@@ -112,7 +115,7 @@ n=$((n + 1))
|
||||
echo_i "TCP high-water: check initial statistics ($n)"
|
||||
ret=0
|
||||
refresh_tcp_stats
|
||||
assert_int_equal "${TCP_CUR}" 1 "current TCP clients count" || ret=1
|
||||
assert_int_equal "${TCP_CUR}" 0 "current TCP clients count" || ret=1
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=$((status + ret))
|
||||
|
||||
@@ -123,7 +126,7 @@ echo_i "TCP high-water: check value after some TCP connections are established (
|
||||
ret=0
|
||||
OLD_TCP_CUR="${TCP_CUR}"
|
||||
TCP_ADDED=9
|
||||
open_connections "${TCP_ADDED}"
|
||||
open_connections "${TCP_ADDED}" || ret=1
|
||||
check_stats_added() {
|
||||
refresh_tcp_stats
|
||||
assert_int_equal "${TCP_CUR}" $((OLD_TCP_CUR + TCP_ADDED)) "current TCP clients count" || return 1
|
||||
@@ -141,7 +144,7 @@ ret=0
|
||||
OLD_TCP_CUR="${TCP_CUR}"
|
||||
OLD_TCP_HIGH="${TCP_HIGH}"
|
||||
TCP_REMOVED=5
|
||||
close_connections "${TCP_REMOVED}"
|
||||
close_connections "${TCP_REMOVED}" || ret=1
|
||||
check_stats_removed() {
|
||||
refresh_tcp_stats
|
||||
assert_int_equal "${TCP_CUR}" $((OLD_TCP_CUR - TCP_REMOVED)) "current TCP clients count" || return 1
|
||||
@@ -156,19 +159,15 @@ status=$((status + ret))
|
||||
n=$((n + 1))
|
||||
echo_i "TCP high-water: ensure tcp-clients is an upper bound ($n)"
|
||||
ret=0
|
||||
open_connections $((TCP_LIMIT + 1))
|
||||
open_connections $((TCP_LIMIT + 1)) || ret=1
|
||||
check_stats_limit() {
|
||||
refresh_tcp_stats
|
||||
assert_int_equal "${TCP_CUR}" "${TCP_LIMIT}" "current TCP clients count" || return 1
|
||||
assert_int_equal "${TCP_HIGH}" "${TCP_LIMIT}" "TCP high-water value" || return 1
|
||||
}
|
||||
retry 2 check_stats_limit || ret=1
|
||||
close_connections $((TCP_LIMIT + 1))
|
||||
if [ $ret != 0 ]; then echo_i "failed"; fi
|
||||
status=$((status + ret))
|
||||
|
||||
# wait for connections to close
|
||||
sleep 5
|
||||
|
||||
echo_i "exit status: $status"
|
||||
[ $status -eq 0 ] || exit 1
|
||||
|
||||
@@ -43,7 +43,7 @@ cat $infile $keyname1.key $keyname2.key > $zonefile
|
||||
$SIGNER -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
|
||||
echo_i "signed $zone"
|
||||
|
||||
keyfile_to_static_keys $keyname2 > private.nsec.conf
|
||||
keyfile_to_static_ds $keyname2 > private.nsec.conf
|
||||
|
||||
zone=nsec3
|
||||
infile=nsec3.db.in
|
||||
@@ -72,7 +72,7 @@ cat $infile $keyname1.key $keyname2.key > $zonefile
|
||||
$SIGNER -3 - -H 10 -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
|
||||
echo_i "signed $zone"
|
||||
|
||||
keyfile_to_static_keys $keyname2 > private.nsec3.conf
|
||||
keyfile_to_static_ds $keyname2 > private.nsec3.conf
|
||||
|
||||
zone=.
|
||||
infile=root.db.in
|
||||
@@ -87,4 +87,4 @@ cat $infile $keyname1.key $keyname2.key $dssets >$zonefile
|
||||
$SIGNER -o $zone -f $outfile $zonefile > /dev/null 2> signer.err || cat signer.err
|
||||
echo_i "signed $zone"
|
||||
|
||||
keyfile_to_static_keys $keyname2 > trusted.conf
|
||||
keyfile_to_static_ds $keyname2 > trusted.conf
|
||||
|
||||
@@ -291,6 +291,8 @@ print_yaml(dns_dtdata_t *dt) {
|
||||
}
|
||||
|
||||
if (dt->msg != NULL) {
|
||||
dt->msg->indent.count = 2;
|
||||
dt->msg->indent.string = " ";
|
||||
printf(" %s:\n", ((dt->type & DNS_DTTYPE_QUERY) != 0)
|
||||
? "query_message_data"
|
||||
: "response_message_data");
|
||||
@@ -327,8 +329,6 @@ main(int argc, char *argv[]) {
|
||||
break;
|
||||
case 'y':
|
||||
yaml = true;
|
||||
dns_master_indentstr = " ";
|
||||
dns_master_indent = 2;
|
||||
break;
|
||||
default:
|
||||
usage();
|
||||
|
||||
+2
-2
@@ -248,9 +248,9 @@ recvresponse(isc_task_t *task, isc_event_t *event) {
|
||||
|
||||
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
||||
if (yaml) {
|
||||
dns_master_indentstr = " ";
|
||||
dns_master_indent = 3;
|
||||
styleflags |= DNS_STYLEFLAG_YAML;
|
||||
response->indent.string = " ";
|
||||
response->indent.count = 3;
|
||||
} else {
|
||||
if (display_comments) {
|
||||
styleflags |= DNS_STYLEFLAG_COMMENT;
|
||||
|
||||
@@ -669,6 +669,8 @@ BIND9_ISCCFG_BUILDINCLUDE
|
||||
BIND9_ISCCC_BUILDINCLUDE
|
||||
BIND9_ISC_BUILDINCLUDE
|
||||
BIND9_TOP_BUILDDIR
|
||||
WRAP_NAME
|
||||
WRAP_INTERPOSE
|
||||
LD_WRAP_TESTS
|
||||
KYUA
|
||||
UNITTESTS
|
||||
@@ -850,7 +852,6 @@ infodir
|
||||
docdir
|
||||
oldincludedir
|
||||
includedir
|
||||
runstatedir
|
||||
localstatedir
|
||||
sharedstatedir
|
||||
sysconfdir
|
||||
@@ -1023,7 +1024,6 @@ datadir='${datarootdir}'
|
||||
sysconfdir='${prefix}/etc'
|
||||
sharedstatedir='${prefix}/com'
|
||||
localstatedir='${prefix}/var'
|
||||
runstatedir='${localstatedir}/run'
|
||||
includedir='${prefix}/include'
|
||||
oldincludedir='/usr/include'
|
||||
docdir='${datarootdir}/doc/${PACKAGE_TARNAME}'
|
||||
@@ -1276,15 +1276,6 @@ do
|
||||
| -silent | --silent | --silen | --sile | --sil)
|
||||
silent=yes ;;
|
||||
|
||||
-runstatedir | --runstatedir | --runstatedi | --runstated \
|
||||
| --runstate | --runstat | --runsta | --runst | --runs \
|
||||
| --run | --ru | --r)
|
||||
ac_prev=runstatedir ;;
|
||||
-runstatedir=* | --runstatedir=* | --runstatedi=* | --runstated=* \
|
||||
| --runstate=* | --runstat=* | --runsta=* | --runst=* | --runs=* \
|
||||
| --run=* | --ru=* | --r=*)
|
||||
runstatedir=$ac_optarg ;;
|
||||
|
||||
-sbindir | --sbindir | --sbindi | --sbind | --sbin | --sbi | --sb)
|
||||
ac_prev=sbindir ;;
|
||||
-sbindir=* | --sbindir=* | --sbindi=* | --sbind=* | --sbin=* \
|
||||
@@ -1422,7 +1413,7 @@ fi
|
||||
for ac_var in exec_prefix prefix bindir sbindir libexecdir datarootdir \
|
||||
datadir sysconfdir sharedstatedir localstatedir includedir \
|
||||
oldincludedir docdir infodir htmldir dvidir pdfdir psdir \
|
||||
libdir localedir mandir runstatedir
|
||||
libdir localedir mandir
|
||||
do
|
||||
eval ac_val=\$$ac_var
|
||||
# Remove trailing slashes.
|
||||
@@ -1575,7 +1566,6 @@ Fine tuning of the installation directories:
|
||||
--sysconfdir=DIR read-only single-machine data [PREFIX/etc]
|
||||
--sharedstatedir=DIR modifiable architecture-independent data [PREFIX/com]
|
||||
--localstatedir=DIR modifiable single-machine data [PREFIX/var]
|
||||
--runstatedir=DIR modifiable per-process data [LOCALSTATEDIR/run]
|
||||
--libdir=DIR object code libraries [EPREFIX/lib]
|
||||
--includedir=DIR C header files [PREFIX/include]
|
||||
--oldincludedir=DIR C header files for non-gcc [/usr/include]
|
||||
@@ -4019,7 +4009,7 @@ else
|
||||
We can't simply define LARGE_OFF_T to be 9223372036854775807,
|
||||
since some C++ compilers masquerading as C compilers
|
||||
incorrectly reject 9223372036854775807. */
|
||||
#define LARGE_OFF_T ((((off_t) 1 << 31) << 31) - 1 + (((off_t) 1 << 31) << 31))
|
||||
#define LARGE_OFF_T (((off_t) 1 << 62) - 1 + ((off_t) 1 << 62))
|
||||
int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721
|
||||
&& LARGE_OFF_T % 2147483647 == 1)
|
||||
? 1 : -1];
|
||||
@@ -4065,7 +4055,7 @@ else
|
||||
We can't simply define LARGE_OFF_T to be 9223372036854775807,
|
||||
since some C++ compilers masquerading as C compilers
|
||||
incorrectly reject 9223372036854775807. */
|
||||
#define LARGE_OFF_T ((((off_t) 1 << 31) << 31) - 1 + (((off_t) 1 << 31) << 31))
|
||||
#define LARGE_OFF_T (((off_t) 1 << 62) - 1 + ((off_t) 1 << 62))
|
||||
int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721
|
||||
&& LARGE_OFF_T % 2147483647 == 1)
|
||||
? 1 : -1];
|
||||
@@ -4089,7 +4079,7 @@ rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
|
||||
We can't simply define LARGE_OFF_T to be 9223372036854775807,
|
||||
since some C++ compilers masquerading as C compilers
|
||||
incorrectly reject 9223372036854775807. */
|
||||
#define LARGE_OFF_T ((((off_t) 1 << 31) << 31) - 1 + (((off_t) 1 << 31) << 31))
|
||||
#define LARGE_OFF_T (((off_t) 1 << 62) - 1 + ((off_t) 1 << 62))
|
||||
int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721
|
||||
&& LARGE_OFF_T % 2147483647 == 1)
|
||||
? 1 : -1];
|
||||
@@ -4134,7 +4124,7 @@ else
|
||||
We can't simply define LARGE_OFF_T to be 9223372036854775807,
|
||||
since some C++ compilers masquerading as C compilers
|
||||
incorrectly reject 9223372036854775807. */
|
||||
#define LARGE_OFF_T ((((off_t) 1 << 31) << 31) - 1 + (((off_t) 1 << 31) << 31))
|
||||
#define LARGE_OFF_T (((off_t) 1 << 62) - 1 + ((off_t) 1 << 62))
|
||||
int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721
|
||||
&& LARGE_OFF_T % 2147483647 == 1)
|
||||
? 1 : -1];
|
||||
@@ -4158,7 +4148,7 @@ rm -f core conftest.err conftest.$ac_objext conftest.$ac_ext
|
||||
We can't simply define LARGE_OFF_T to be 9223372036854775807,
|
||||
since some C++ compilers masquerading as C compilers
|
||||
incorrectly reject 9223372036854775807. */
|
||||
#define LARGE_OFF_T ((((off_t) 1 << 31) << 31) - 1 + (((off_t) 1 << 31) << 31))
|
||||
#define LARGE_OFF_T (((off_t) 1 << 62) - 1 + ((off_t) 1 << 62))
|
||||
int off_t_is_large[(LARGE_OFF_T % 2147483629 == 721
|
||||
&& LARGE_OFF_T % 2147483647 == 1)
|
||||
? 1 : -1];
|
||||
@@ -12495,6 +12485,9 @@ except: exit(1)'
|
||||
testply='try: import ply
|
||||
except: exit(1)'
|
||||
|
||||
testsetup='try: from distutils.core import setup
|
||||
except: exit(1)'
|
||||
|
||||
default_with_python="python python3 python3.7 python3.6 python3.5 python3.4 python3.3 python3.2 python2 python2.7"
|
||||
|
||||
|
||||
@@ -12613,6 +12606,18 @@ $as_echo_n "checking Python module 'ply'... " >&6; }
|
||||
if "$PYTHON" -c "$testply" 2>/dev/null; then :
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
$as_echo "yes" >&6; }
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
$as_echo "no" >&6; }
|
||||
unset PYTHON
|
||||
continue
|
||||
fi
|
||||
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking Python module 'distutils.core setup'" >&5
|
||||
$as_echo_n "checking Python module 'distutils.core setup'... " >&6; }
|
||||
if "$PYTHON" -c "$testsetup" 2>/dev/null; then :
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
$as_echo "yes" >&6; }
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
$as_echo "no" >&6; }
|
||||
@@ -21814,6 +21819,166 @@ rm -f core conftest.err conftest.$ac_objext \
|
||||
|
||||
|
||||
|
||||
WRAP_INTERPOSE=
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: checking for linker support for '-z interpose' option" >&5
|
||||
$as_echo_n "checking for linker support for '-z interpose' option... " >&6; }
|
||||
|
||||
|
||||
CCASFLAGS_interpose_ax_save_flags=$CCASFLAGS
|
||||
|
||||
|
||||
|
||||
CFLAGS_interpose_ax_save_flags=$CFLAGS
|
||||
|
||||
|
||||
|
||||
CPPFLAGS_interpose_ax_save_flags=$CPPFLAGS
|
||||
|
||||
|
||||
|
||||
CXXFLAGS_interpose_ax_save_flags=$CXXFLAGS
|
||||
|
||||
|
||||
|
||||
ERLCFLAGS_interpose_ax_save_flags=$ERLCFLAGS
|
||||
|
||||
|
||||
|
||||
FCFLAGS_interpose_ax_save_flags=$FCFLAGS
|
||||
|
||||
|
||||
|
||||
FCLIBS_interpose_ax_save_flags=$FCLIBS
|
||||
|
||||
|
||||
|
||||
FFLAGS_interpose_ax_save_flags=$FFLAGS
|
||||
|
||||
|
||||
|
||||
FLIBS_interpose_ax_save_flags=$FLIBS
|
||||
|
||||
|
||||
|
||||
GCJFLAGS_interpose_ax_save_flags=$GCJFLAGS
|
||||
|
||||
|
||||
|
||||
JAVACFLAGS_interpose_ax_save_flags=$JAVACFLAGS
|
||||
|
||||
|
||||
|
||||
LDFLAGS_interpose_ax_save_flags=$LDFLAGS
|
||||
|
||||
|
||||
|
||||
LIBS_interpose_ax_save_flags=$LIBS
|
||||
|
||||
|
||||
|
||||
OBJCFLAGS_interpose_ax_save_flags=$OBJCFLAGS
|
||||
|
||||
|
||||
|
||||
OBJCXXFLAGS_interpose_ax_save_flags=$OBJCXXFLAGS
|
||||
|
||||
|
||||
|
||||
UPCFLAGS_interpose_ax_save_flags=$UPCFLAGS
|
||||
|
||||
|
||||
|
||||
VALAFLAGS_interpose_ax_save_flags=$VALAFLAGS
|
||||
|
||||
|
||||
|
||||
LDFLAGS="-Wl,-z,interpose"
|
||||
cat confdefs.h - <<_ACEOF >conftest.$ac_ext
|
||||
/* end confdefs.h. */
|
||||
|
||||
int
|
||||
main ()
|
||||
{
|
||||
|
||||
;
|
||||
return 0;
|
||||
}
|
||||
_ACEOF
|
||||
if ac_fn_c_try_link "$LINENO"; then :
|
||||
WRAP_INTERPOSE="-Wl,-z,interpose"
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
|
||||
$as_echo "yes" >&6; }
|
||||
else
|
||||
{ $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
|
||||
$as_echo "no" >&6; }
|
||||
fi
|
||||
rm -f core conftest.err conftest.$ac_objext \
|
||||
conftest$ac_exeext conftest.$ac_ext
|
||||
|
||||
CCASFLAGS=$CCASFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
CFLAGS=$CFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
CPPFLAGS=$CPPFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
CXXFLAGS=$CXXFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
ERLCFLAGS=$ERLCFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
FCFLAGS=$FCFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
FCLIBS=$FCLIBS_interpose_ax_save_flags
|
||||
|
||||
|
||||
FFLAGS=$FFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
FLIBS=$FLIBS_interpose_ax_save_flags
|
||||
|
||||
|
||||
GCJFLAGS=$GCJFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
JAVACFLAGS=$JAVACFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
LDFLAGS=$LDFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
LIBS=$LIBS_interpose_ax_save_flags
|
||||
|
||||
|
||||
OBJCFLAGS=$OBJCFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
OBJCXXFLAGS=$OBJCXXFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
UPCFLAGS=$UPCFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
VALAFLAGS=$VALAFLAGS_interpose_ax_save_flags
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
WRAP_NAME=''
|
||||
case $host in #(
|
||||
*-darwin*) :
|
||||
WRAP_NAME='${WRAP_NAME}' ;; #(
|
||||
*) :
|
||||
;;
|
||||
esac
|
||||
|
||||
|
||||
#
|
||||
# Check for i18n
|
||||
#
|
||||
|
||||
@@ -202,6 +202,9 @@ except: exit(1)'
|
||||
testply='try: import ply
|
||||
except: exit(1)'
|
||||
|
||||
testsetup='try: from distutils.core import setup
|
||||
except: exit(1)'
|
||||
|
||||
default_with_python="python python3 python3.7 python3.6 python3.5 python3.4 python3.3 python3.2 python2 python2.7"
|
||||
|
||||
AC_ARG_WITH([python],
|
||||
@@ -255,6 +258,13 @@ AS_IF([test "$with_python" = "no"],
|
||||
unset PYTHON
|
||||
continue])
|
||||
|
||||
AC_MSG_CHECKING([Python module 'distutils.core setup'])
|
||||
AS_IF(["$PYTHON" -c "$testsetup" 2>/dev/null],
|
||||
[AC_MSG_RESULT([yes])],
|
||||
[AC_MSG_RESULT([no])
|
||||
unset PYTHON
|
||||
continue])
|
||||
|
||||
# Stop looking any further once we find a Python interpreter
|
||||
# satisfying all requirements.
|
||||
break
|
||||
@@ -2191,6 +2201,23 @@ AX_RESTORE_FLAGS([wrap])
|
||||
|
||||
AC_SUBST([LD_WRAP_TESTS])
|
||||
|
||||
WRAP_INTERPOSE=
|
||||
AC_MSG_CHECKING([for linker support for '-z interpose' option])
|
||||
AX_SAVE_FLAGS([interpose])
|
||||
LDFLAGS="-Wl,-z,interpose"
|
||||
AC_LINK_IFELSE(
|
||||
[AC_LANG_PROGRAM([],[])],
|
||||
[WRAP_INTERPOSE="-Wl,-z,interpose"
|
||||
AC_MSG_RESULT([yes])],
|
||||
[AC_MSG_RESULT([no])])
|
||||
AX_RESTORE_FLAGS([interpose])
|
||||
|
||||
AC_SUBST([WRAP_INTERPOSE])
|
||||
|
||||
WRAP_NAME=''
|
||||
AS_CASE([$host],[*-darwin*],[WRAP_NAME='${WRAP_NAME}'])
|
||||
AC_SUBST([WRAP_NAME])
|
||||
|
||||
#
|
||||
# Check for i18n
|
||||
#
|
||||
|
||||
+92
-75
@@ -2230,13 +2230,14 @@ allow-update { !{ !localnets; any; }; key host1-host2. ;};
|
||||
The keys specified in <command>dnssec-keys</command>
|
||||
copies of DNSKEY RRs for zones that are used to form the
|
||||
first link in the cryptographic chain of trust. Keys configured
|
||||
with the keyword <command>static-key</command> are loaded directly
|
||||
with the keyword <command>static-key</command> or
|
||||
<command>static-ds</command> are loaded directly
|
||||
into the table of trust anchors, and can only be changed by
|
||||
altering the configuration. Keys configured with
|
||||
<command>initial-key</command> are used to initialize
|
||||
RFC 5011 trust anchor maintenance, and will be kept up to
|
||||
date automatically after the first time <command>named</command>
|
||||
runs.
|
||||
<command>initial-key</command> or <command>initial-ds</command>
|
||||
are used to initialize RFC 5011 trust anchor maintenance, and
|
||||
will be kept up to date automatically after the first time
|
||||
<command>named</command> runs.
|
||||
</para>
|
||||
|
||||
<para>
|
||||
@@ -2276,17 +2277,7 @@ dnssec-keys {
|
||||
97S+LKUTpQcq27R7AT3/V5hRQxScINqwcz4jYqZD2fQ
|
||||
dgxbcDTClU0CRBdiieyLMNzXG3";
|
||||
/* Key for our organization's forward zone */
|
||||
example.com. static-key 257 3 5 "AwEAAaxPMcR2x0HbQV4WeZB6oEDX+r0QM6
|
||||
5KbhTjrW1ZaARmPhEZZe3Y9ifgEuq7vZ/z
|
||||
GZUdEGNWy+JZzus0lUptwgjGwhUS1558Hb
|
||||
4JKUbbOTcM8pwXlj0EiX3oDFVmjHO444gL
|
||||
kBOUKUf/mC7HvfwYH/Be22GnClrinKJp1O
|
||||
g4ywzO9WglMk7jbfW33gUKvirTHr25GL7S
|
||||
TQUzBb5Usxt8lgnyTUHs1t3JwCY5hKZ6Cq
|
||||
FxmAVZP20igTixin/1LcrgX/KMEGd/biuv
|
||||
F4qJCyduieHukuY3H4XMAcR+xia2nIUPvm
|
||||
/oyWR8BW/hWdzOvnSCThlHf3xiYleDbt/o
|
||||
1OTQ09A0=";
|
||||
example.com. static-ds 54135 5 2 "8EF922C97F1D07B23134440F19682E7519ADDAE180E20B1B1EC52E7F58B2831D"
|
||||
|
||||
/* Key for our reverse zone. */
|
||||
2.0.192.IN-ADDRPA.NET. static-key 257 3 5 "AQOnS4xn/IgOUpBPJ3bogzwc
|
||||
@@ -3215,11 +3206,14 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
|
||||
</entry>
|
||||
<entry colname="2">
|
||||
<para>
|
||||
defines DNSSEC keys: if used with the
|
||||
<command>initial-key</command> keyword,
|
||||
keys are kept up to date using RFC 5011
|
||||
trust anchor maintenance, and if used with
|
||||
<command>static-key</command>, keys are permanent.
|
||||
defines DNSSEC trust anchors: if used with
|
||||
the <command>initial-key</command> or
|
||||
<command>initial-ds</command> keyword,
|
||||
trust anchors are kept up to date using RFC
|
||||
5011 trust anchor maintenance, and if used with
|
||||
<command>static-key</command> or
|
||||
<command>static-ds</command>, trust anchors
|
||||
are permanent.
|
||||
</para>
|
||||
</entry>
|
||||
</row>
|
||||
@@ -4628,7 +4622,8 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
<para>
|
||||
Specifies the directory in which to store the files that
|
||||
track managed DNSSEC keys (i.e., those configured using
|
||||
the <command>initial-key</command> keyword in a
|
||||
the <command>initial-key</command> or
|
||||
<command>initial-ds</command> keywords in a
|
||||
<command>dnssec-keys</command> statement). By default,
|
||||
this is the working directory. The directory
|
||||
<emphasis>must</emphasis> be writable by the effective
|
||||
@@ -10864,12 +10859,12 @@ example.com CNAME rpz-tcp-only.
|
||||
trust anchors. DNSSEC is described in <xref linkend="DNSSEC"/>.
|
||||
</para>
|
||||
<para>
|
||||
A trust anchor is defined when the public key for
|
||||
a non-authoritative zone is known, but cannot be securely
|
||||
obtained through DNS, either because it is the DNS root zone
|
||||
or because its parent zone is unsigned. Once a key has been
|
||||
configured as a trust anchor, it is treated as if it had
|
||||
been validated and proven secure.
|
||||
A trust anchor is defined when the public key or public key
|
||||
digest for a non-authoritative zone is known, but cannot be
|
||||
securely obtained through DNS, either because it is the DNS
|
||||
root zone or because its parent zone is unsigned. Once a key
|
||||
or digest has been configured as a trust anchor, it is treated
|
||||
as if it had been validated and proven secure.
|
||||
</para>
|
||||
<para>
|
||||
The resolver attempts DNSSEC validation on all DNS data
|
||||
@@ -10881,19 +10876,9 @@ example.com CNAME rpz-tcp-only.
|
||||
<para>
|
||||
All keys listed in <command>dnssec-keys</command>, and
|
||||
their corresponding zones, are deemed to exist regardless
|
||||
of what parent zones say. Only keys configured as trust anchors
|
||||
of what parent zones say. Only keys configured as trust anchors
|
||||
are used to validate the DNSKEY RRset for the corresponding
|
||||
name. The parent's DS RRset will not be used.
|
||||
</para>
|
||||
<para>
|
||||
The <command>dnssec-keys</command> statement can contain
|
||||
multiple key entries, each consisting of the key's
|
||||
domain name, followed by the <command>static-key</command> or
|
||||
<command>initial-key</command> keyword, then the key's flags,
|
||||
protocol, algorithm, and the Base64 representation of the key
|
||||
data. Spaces, tabs, newlines and carriage returns are ignored
|
||||
in the key data, so the configuration may be split up into
|
||||
multiple lines.
|
||||
name. The parent's DS RRset will not be used.
|
||||
</para>
|
||||
<para>
|
||||
<command>dnssec-keys</command> may be set at the top level
|
||||
@@ -10903,11 +10888,33 @@ example.com CNAME rpz-tcp-only.
|
||||
defined in a view are only used within that view.
|
||||
</para>
|
||||
<para>
|
||||
<command>dnssec-keys</command> entries can be configured with
|
||||
two keywords: <command>static-key</command> or
|
||||
<command>initial-key</command>. Keys configured with
|
||||
<command>static-key</command> are immutable,
|
||||
while keys configured with <command>initial-key</command>
|
||||
The <command>dnssec-keys</command> statement can contain
|
||||
multiple trust anchor entries, each consisting of a
|
||||
domain name, followed by an "anchor type" keyword indicating
|
||||
the trust anchor's format, followed by the key or digest data.
|
||||
</para>
|
||||
<para>
|
||||
If the anchor type is <command>static-key</command> or
|
||||
<command>initial-key</command>, then it is followed with the
|
||||
key's flags, protocol, algorithm, and the Base64 representation
|
||||
of the public key data. This is identical to the text
|
||||
representation of a DNSKEY record. Spaces, tabs, newlines and
|
||||
carriage returns are ignored in the key data, so the
|
||||
configuration may be split up into multiple lines.
|
||||
</para>
|
||||
<para>
|
||||
If the anchor type is <command>static-ds</command> or
|
||||
<command>initial-ds</command>, then it is followed with the
|
||||
key tag, algorithm, digest type, and the hexidecimal
|
||||
representation of the key digest. This is identical to the
|
||||
text representation of a DS record. Spaces, tabs, newlines
|
||||
and carriage returns are ignored.
|
||||
</para>
|
||||
<para>
|
||||
Trust anchors configured with the
|
||||
<command>static-key</command> or <command>static-ds</command>
|
||||
anchor types are immutable, while keys configured with
|
||||
<command>initial-key</command> or <command>initial-ds</command>
|
||||
can be kept up to date automatically, without intervention
|
||||
from the resolver operator. (<command>static-key</command>
|
||||
keys are identical to keys configured using the deprecated
|
||||
@@ -10917,45 +10924,55 @@ example.com CNAME rpz-tcp-only.
|
||||
Suppose, for example, that a zone's key-signing
|
||||
key was compromised, and the zone owner had to revoke and
|
||||
replace the key. A resolver which had the original key
|
||||
configured as a <command>static-key</command> would be
|
||||
unable to validate this zone any longer; it would
|
||||
reply with a SERVFAIL response code. This would
|
||||
continue until the resolver operator had updated the
|
||||
<command>dnssec-keys</command> statement with the new key.
|
||||
configured using <command>static-key</command> or
|
||||
<command>static-ds</command> would be unable to validate
|
||||
this zone any longer; it would reply with a SERVFAIL response
|
||||
code. This would continue until the resolver operator had
|
||||
updated the <command>dnssec-keys</command> statement with
|
||||
the new key.
|
||||
</para>
|
||||
<para>
|
||||
If, however, the trust anchor had been configured with
|
||||
<command>initial-key</command> instead, then the
|
||||
zone owner could add a "stand-by" key to their zone in advance.
|
||||
<command>named</command> would store the stand-by key, and
|
||||
when the original key was revoked, <command>named</command>
|
||||
would be able to transition smoothly to the new key. It would
|
||||
also recognize that the old key had been revoked, and cease
|
||||
using that key to validate answers, minimizing the damage that
|
||||
the compromised key could do. This is the process used to
|
||||
keep the ICANN root DNSSEC key up to date.
|
||||
<command>initial-key</command> or <command>initial-ds</command>
|
||||
instead, then the zone owner could add a "stand-by" key to
|
||||
their zone in advance. <command>named</command> would store
|
||||
the stand-by key, and when the original key was revoked,
|
||||
<command>named</command> would be able to transition smoothly
|
||||
to the new key. It would also recognize that the old key had
|
||||
been revoked, and cease using that key to validate answers,
|
||||
minimizing the damage that the compromised key could do.
|
||||
This is the process used to keep the ICANN root DNSSEC key
|
||||
up to date.
|
||||
</para>
|
||||
<para>
|
||||
Whereas <command>static-key</command>
|
||||
keys continue to be trusted until they are removed from
|
||||
Whereas <command>static-key</command> and
|
||||
<command>static-ds</command> trust anchors continue
|
||||
to be trusted until they are removed from
|
||||
<filename>named.conf</filename>, an
|
||||
<command>initial-key</command> is only trusted
|
||||
<emphasis>once</emphasis>: for as long as it
|
||||
<command>initial-key</command> or <command>initial-ds</command>
|
||||
is only trusted <emphasis>once</emphasis>: for as long as it
|
||||
takes to load the managed key database and start the RFC 5011
|
||||
key maintenance process.
|
||||
</para>
|
||||
<para>
|
||||
It is not possible to mix static with initial trust anchors
|
||||
for the same domain name. It is also not possible to mix
|
||||
<command>key</command> with <command>ds</command> trust anchors.
|
||||
</para>
|
||||
<para>
|
||||
The first time <command>named</command> runs with an
|
||||
<command>initial-key</command> configured in
|
||||
<filename>named.conf</filename>, it fetches the
|
||||
<command>initial-key</command> or <command>initial-ds</command>
|
||||
configured in <filename>named.conf</filename>, it fetches the
|
||||
DNSKEY RRset directly from the zone apex, and validates it
|
||||
using the key specified in <command>dnssec-keys</command>.
|
||||
If the DNSKEY RRset is validly signed, then it is
|
||||
used as the basis for a new managed keys database.
|
||||
using the trust anchor specified in <command>dnssec-keys</command>.
|
||||
If the DNSKEY RRset is validly signed by a key matching
|
||||
the trust anchor, then it is used as the basis for a new
|
||||
managed keys database.
|
||||
</para>
|
||||
<para>
|
||||
From that point on, whenever <command>named</command> runs, it
|
||||
sees the <command>initial-key</command> listed in
|
||||
sees the <command>initial-key</command> or
|
||||
<command>initial-ds</command> listed in
|
||||
<command>dnssec-keys</command>, checks to
|
||||
make sure RFC 5011 key maintenance has already been initialized
|
||||
for the specified domain, and if so, it simply moves on. The
|
||||
@@ -10966,13 +10983,13 @@ example.com CNAME rpz-tcp-only.
|
||||
</para>
|
||||
<para>
|
||||
The next time <command>named</command> runs after an
|
||||
<command>initial-key</command> has been
|
||||
<emphasis>removed</emphasis> from the
|
||||
<command>initial-key</command> or <command>initial-ds</command>
|
||||
trust anchor has been <emphasis>removed</emphasis> from the
|
||||
<command>dnssec-keys</command> statement (or changed to
|
||||
a <command>static-key</command>), the corresponding
|
||||
zone will be removed from the managed keys database,
|
||||
and RFC 5011 key maintenance will no longer be used for that
|
||||
domain.
|
||||
a <command>static-key</command> or <command>static-ds</command>),
|
||||
the corresponding keys will be removed from the managed keys
|
||||
database, and RFC 5011 key maintenance will no longer be used
|
||||
for that domain.
|
||||
</para>
|
||||
<para>
|
||||
In the current implementation, the managed keys database
|
||||
|
||||
@@ -614,6 +614,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -146,6 +146,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -856,6 +856,6 @@ controls {
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+331
-256
@@ -61,18 +61,18 @@
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#dnssec.dynamic.zones">DNSSEC, Dynamic Zones, and Automatic Signing</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.2">Converting from insecure to secure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.7">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.15">Fully automatic zone signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.24">Private-type records</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.31">DNSKEY rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.33">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.38">Automatic key rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.40">NSEC3PARAM rollovers via UPDATE</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.42">Converting from NSEC to NSEC3</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.44">Converting from NSEC3 to NSEC</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.46">Converting from secure to insecure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.50">Periodic re-signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.52">NSEC3 and OPTOUT</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.9">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.17">Fully automatic zone signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.27">Private-type records</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.34">DNSKEY rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.36">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.41">Automatic key rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.43">NSEC3PARAM rollovers via UPDATE</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.45">Converting from NSEC to NSEC3</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.48">Converting from NSEC3 to NSEC</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.50">Converting from secure to insecure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.54">Periodic re-signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.56">NSEC3 and OPTOUT</a></span></dt>
|
||||
</dl></dd>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#rfc5011.support">Dynamic Trust Anchor Management</a></span></dt>
|
||||
<dd><dl>
|
||||
@@ -1060,13 +1060,14 @@ allow-update { !{ !localnets; any; }; key host1-host2. ;};
|
||||
The keys specified in <span class="command"><strong>dnssec-keys</strong></span>
|
||||
copies of DNSKEY RRs for zones that are used to form the
|
||||
first link in the cryptographic chain of trust. Keys configured
|
||||
with the keyword <span class="command"><strong>static-key</strong></span> are loaded directly
|
||||
with the keyword <span class="command"><strong>static-key</strong></span> or
|
||||
<span class="command"><strong>static-ds</strong></span> are loaded directly
|
||||
into the table of trust anchors, and can only be changed by
|
||||
altering the configuration. Keys configured with
|
||||
<span class="command"><strong>initial-key</strong></span> are used to initialize
|
||||
RFC 5011 trust anchor maintenance, and will be kept up to
|
||||
date automatically after the first time <span class="command"><strong>named</strong></span>
|
||||
runs.
|
||||
<span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span>
|
||||
are used to initialize RFC 5011 trust anchor maintenance, and
|
||||
will be kept up to date automatically after the first time
|
||||
<span class="command"><strong>named</strong></span> runs.
|
||||
</p>
|
||||
|
||||
<p>
|
||||
@@ -1106,17 +1107,7 @@ dnssec-keys {
|
||||
97S+LKUTpQcq27R7AT3/V5hRQxScINqwcz4jYqZD2fQ
|
||||
dgxbcDTClU0CRBdiieyLMNzXG3";
|
||||
/* Key for our organization's forward zone */
|
||||
example.com. static-key 257 3 5 "AwEAAaxPMcR2x0HbQV4WeZB6oEDX+r0QM6
|
||||
5KbhTjrW1ZaARmPhEZZe3Y9ifgEuq7vZ/z
|
||||
GZUdEGNWy+JZzus0lUptwgjGwhUS1558Hb
|
||||
4JKUbbOTcM8pwXlj0EiX3oDFVmjHO444gL
|
||||
kBOUKUf/mC7HvfwYH/Be22GnClrinKJp1O
|
||||
g4ywzO9WglMk7jbfW33gUKvirTHr25GL7S
|
||||
TQUzBb5Usxt8lgnyTUHs1t3JwCY5hKZ6Cq
|
||||
FxmAVZP20igTixin/1LcrgX/KMEGd/biuv
|
||||
F4qJCyduieHukuY3H4XMAcR+xia2nIUPvm
|
||||
/oyWR8BW/hWdzOvnSCThlHf3xiYleDbt/o
|
||||
1OTQ09A0=";
|
||||
example.com. static-ds 54135 5 2 "8EF922C97F1D07B23134440F19682E7519ADDAE180E20B1B1EC52E7F58B2831D"
|
||||
|
||||
/* Key for our reverse zone. */
|
||||
2.0.192.IN-ADDRPA.NET. static-key 257 3 5 "AQOnS4xn/IgOUpBPJ3bogzwc
|
||||
@@ -1195,33 +1186,53 @@ options {
|
||||
<a name="id-1.5.10.2"></a>Converting from insecure to secure</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>Changing a zone from insecure to secure can be done in two
|
||||
ways: using a dynamic DNS update, or the
|
||||
<span class="command"><strong>auto-dnssec</strong></span> zone option.</p>
|
||||
<p>For either method, you need to configure
|
||||
<span class="command"><strong>named</strong></span> so that it can see the
|
||||
<code class="filename">K*</code> files which contain the public and private
|
||||
parts of the keys that will be used to sign the zone. These files
|
||||
will have been generated by
|
||||
<span class="command"><strong>dnssec-keygen</strong></span>. You can do this by placing them
|
||||
in the key-directory, as specified in
|
||||
<code class="filename">named.conf</code>:</p>
|
||||
<pre class="programlisting">
|
||||
<p>
|
||||
Changing a zone from insecure to secure can be done in three
|
||||
ways: using a dynamic DNS update, use the
|
||||
<span class="command"><strong>auto-dnssec</strong></span> zone option, or set a DNSSEC
|
||||
policy for the zone with <span class="command"><strong>dnssec-policy</strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
For either method, you need to configure
|
||||
<span class="command"><strong>named</strong></span> so that it can see the
|
||||
<code class="filename">K*</code> files which contain the public and private
|
||||
parts of the keys that will be used to sign the zone. These files
|
||||
will have been generated by
|
||||
<span class="command"><strong>dnssec-keygen</strong></span> (or created when needed by
|
||||
<span class="command"><strong>named</strong></span> if <span class="command"><strong>dnssec-policy</strong></span> is
|
||||
used). Keys should be placed in the key-directory, as specified in
|
||||
<code class="filename">named.conf</code>:</p>
|
||||
<pre class="programlisting">
|
||||
zone example.net {
|
||||
type master;
|
||||
update-policy local;
|
||||
file "dynamic/example.net/example.net";
|
||||
key-directory "dynamic/example.net";
|
||||
};
|
||||
</pre>
|
||||
<p>If one KSK and one ZSK DNSKEY key have been generated, this
|
||||
configuration will cause all records in the zone to be signed
|
||||
with the ZSK, and the DNSKEY RRset to be signed with the KSK as
|
||||
well. An NSEC chain will be generated as part of the initial
|
||||
signing process.</p>
|
||||
</pre>
|
||||
<p>
|
||||
If one KSK and one ZSK DNSKEY key have been generated, this
|
||||
configuration will cause all records in the zone to be signed
|
||||
with the ZSK, and the DNSKEY RRset to be signed with the KSK as
|
||||
well. An NSEC chain will be generated as part of the initial
|
||||
signing process.
|
||||
</p>
|
||||
<p>
|
||||
With <span class="command"><strong>dnssec-policy</strong></span> you specify what keys should
|
||||
be KSK and/or ZSK. If you want a key to sign all records with a key
|
||||
you will need to specify a CSK:
|
||||
</p>
|
||||
<pre class="programlisting">
|
||||
dnssec-policy csk {
|
||||
keys {
|
||||
csk key-directory lifetime P5Y algorithm 13;
|
||||
};
|
||||
};
|
||||
</pre>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.7"></a>Dynamic DNS update method</h3></div></div></div>
|
||||
<a name="id-1.5.10.9"></a>Dynamic DNS update method</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>To insert the keys via dynamic update:</p>
|
||||
@@ -1232,16 +1243,20 @@ options {
|
||||
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
|
||||
> send
|
||||
</pre>
|
||||
<p>While the update request will complete almost immediately,
|
||||
the zone will not be completely signed until
|
||||
<span class="command"><strong>named</strong></span> has had time to walk the zone and
|
||||
generate the NSEC and RRSIG records. The NSEC record at the apex
|
||||
will be added last, to signal that there is a complete NSEC
|
||||
chain.</p>
|
||||
<p>If you wish to sign using NSEC3 instead of NSEC, you should
|
||||
add an NSEC3PARAM record to the initial update request. If you
|
||||
wish the NSEC3 chain to have the OPTOUT bit set, set it in the
|
||||
flags field of the NSEC3PARAM record.</p>
|
||||
<p>
|
||||
While the update request will complete almost immediately,
|
||||
the zone will not be completely signed until
|
||||
<span class="command"><strong>named</strong></span> has had time to walk the zone and
|
||||
generate the NSEC and RRSIG records. The NSEC record at the apex
|
||||
will be added last, to signal that there is a complete NSEC
|
||||
chain.
|
||||
</p>
|
||||
<p>
|
||||
If you wish to sign using NSEC3 instead of NSEC, you should
|
||||
add an NSEC3PARAM record to the initial update request. If you
|
||||
wish the NSEC3 chain to have the OPTOUT bit set, set it in the
|
||||
flags field of the NSEC3PARAM record.
|
||||
</p>
|
||||
<pre class="screen">
|
||||
% nsupdate
|
||||
> ttl 3600
|
||||
@@ -1250,94 +1265,117 @@ options {
|
||||
> update add example.net NSEC3PARAM 1 1 100 1234567890
|
||||
> send
|
||||
</pre>
|
||||
<p>Again, this update request will complete almost
|
||||
immediately; however, the record won't show up until
|
||||
<span class="command"><strong>named</strong></span> has had a chance to build/remove the
|
||||
relevant chain. A private type record will be created to record
|
||||
the state of the operation (see below for more details), and will
|
||||
be removed once the operation completes.</p>
|
||||
<p>While the initial signing and NSEC/NSEC3 chain generation
|
||||
is happening, other updates are possible as well.</p>
|
||||
<p>
|
||||
Again, this update request will complete almost
|
||||
immediately; however, the record won't show up until
|
||||
<span class="command"><strong>named</strong></span> has had a chance to build/remove the
|
||||
relevant chain. A private type record will be created to record
|
||||
the state of the operation (see below for more details), and will
|
||||
be removed once the operation completes.
|
||||
</p>
|
||||
<p>
|
||||
While the initial signing and NSEC/NSEC3 chain generation
|
||||
is happening, other updates are possible as well.
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.15"></a>Fully automatic zone signing</h3></div></div></div>
|
||||
<a name="id-1.5.10.17"></a>Fully automatic zone signing</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>To enable automatic signing, add the
|
||||
<span class="command"><strong>auto-dnssec</strong></span> option to the zone statement in
|
||||
<code class="filename">named.conf</code>.
|
||||
<span class="command"><strong>auto-dnssec</strong></span> has two possible arguments:
|
||||
<code class="constant">allow</code> or
|
||||
<code class="constant">maintain</code>.</p>
|
||||
<p>With
|
||||
<span class="command"><strong>auto-dnssec allow</strong></span>,
|
||||
<span class="command"><strong>named</strong></span> can search the key directory for keys
|
||||
matching the zone, insert them into the zone, and use them to
|
||||
sign the zone. It will do so only when it receives an
|
||||
<span class="command"><strong>rndc sign <zonename></strong></span>.</p>
|
||||
<p>
|
||||
|
||||
<span class="command"><strong>auto-dnssec maintain</strong></span> includes the above
|
||||
functionality, but will also automatically adjust the zone's
|
||||
DNSKEY records on schedule according to the keys' timing metadata.
|
||||
(See <a class="xref" href="man.dnssec-keygen.html" title="dnssec-keygen"><span class="refentrytitle"><span class="application">dnssec-keygen</span></span>(8)</a> and
|
||||
<a class="xref" href="man.dnssec-settime.html" title="dnssec-settime"><span class="refentrytitle"><span class="application">dnssec-settime</span></span>(8)</a> for more information.)
|
||||
To enable automatic signing, you can set a
|
||||
<span class="command"><strong>dnssec-policy</strong></span>, or add the
|
||||
<span class="command"><strong>auto-dnssec</strong></span> option to the zone statement in
|
||||
<code class="filename">named.conf</code>.
|
||||
<span class="command"><strong>auto-dnssec</strong></span> has two possible arguments:
|
||||
<code class="constant">allow</code> or
|
||||
<code class="constant">maintain</code>.
|
||||
</p>
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> will periodically search the key directory
|
||||
for keys matching the zone, and if the keys' metadata indicates
|
||||
that any change should be made the zone, such as adding, removing,
|
||||
or revoking a key, then that action will be carried out. By default,
|
||||
the key directory is checked for changes every 60 minutes; this period
|
||||
can be adjusted with the <code class="option">dnssec-loadkeys-interval</code>, up
|
||||
to a maximum of 24 hours. The <span class="command"><strong>rndc loadkeys</strong></span> forces
|
||||
<span class="command"><strong>named</strong></span> to check for key updates immediately.
|
||||
With <span class="command"><strong>auto-dnssec allow</strong></span>,
|
||||
<span class="command"><strong>named</strong></span> can search the key directory for keys
|
||||
matching the zone, insert them into the zone, and use them to
|
||||
sign the zone. It will do so only when it receives an
|
||||
<span class="command"><strong>rndc sign <zonename></strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
If keys are present in the key directory the first time the zone
|
||||
is loaded, the zone will be signed immediately, without waiting for an
|
||||
<span class="command"><strong>rndc sign</strong></span> or <span class="command"><strong>rndc loadkeys</strong></span>
|
||||
command. (Those commands can still be used when there are unscheduled
|
||||
key changes, however.)
|
||||
|
||||
<span class="command"><strong>auto-dnssec maintain</strong></span> includes the above
|
||||
functionality, but will also automatically adjust the zone's
|
||||
DNSKEY records on schedule according to the keys' timing metadata.
|
||||
(See <a class="xref" href="man.dnssec-keygen.html" title="dnssec-keygen"><span class="refentrytitle"><span class="application">dnssec-keygen</span></span>(8)</a> and
|
||||
<a class="xref" href="man.dnssec-settime.html" title="dnssec-settime"><span class="refentrytitle"><span class="application">dnssec-settime</span></span>(8)</a> for more information.)
|
||||
</p>
|
||||
<p>
|
||||
When new keys are added to a zone, the TTL is set to match that
|
||||
of any existing DNSKEY RRset. If there is no existing DNSKEY RRset,
|
||||
then the TTL will be set to the TTL specified when the key was
|
||||
created (using the <span class="command"><strong>dnssec-keygen -L</strong></span> option), if
|
||||
any, or to the SOA TTL.
|
||||
<span class="command"><strong>dnssec-policy</strong></span> is like
|
||||
<span class="command"><strong>auto-dnssec maintain</strong></span>, but will also automatically
|
||||
create new keys when necessary. Also any configuration related
|
||||
to DNSSEC signing is retrieved from the policy (ignoring existing
|
||||
DNSSEC named.conf options).
|
||||
</p>
|
||||
<p>
|
||||
If you wish the zone to be signed using NSEC3 instead of NSEC,
|
||||
submit an NSEC3PARAM record via dynamic update prior to the
|
||||
scheduled publication and activation of the keys. If you wish the
|
||||
NSEC3 chain to have the OPTOUT bit set, set it in the flags field
|
||||
of the NSEC3PARAM record. The NSEC3PARAM record will not appear in
|
||||
the zone immediately, but it will be stored for later reference. When
|
||||
the zone is signed and the NSEC3 chain is completed, the NSEC3PARAM
|
||||
record will appear in the zone.
|
||||
<span class="command"><strong>named</strong></span> will periodically search the key directory
|
||||
for keys matching the zone, and if the keys' metadata indicates
|
||||
that any change should be made the zone, such as adding, removing,
|
||||
or revoking a key, then that action will be carried out. By default,
|
||||
the key directory is checked for changes every 60 minutes; this period
|
||||
can be adjusted with the <code class="option">dnssec-loadkeys-interval</code>, up
|
||||
to a maximum of 24 hours. The <span class="command"><strong>rndc loadkeys</strong></span> forces
|
||||
<span class="command"><strong>named</strong></span> to check for key updates immediately.
|
||||
</p>
|
||||
<p>Using the
|
||||
<span class="command"><strong>auto-dnssec</strong></span> option requires the zone to be
|
||||
configured to allow dynamic updates, by adding an
|
||||
<span class="command"><strong>allow-update</strong></span> or
|
||||
<span class="command"><strong>update-policy</strong></span> statement to the zone
|
||||
configuration. If this has not been done, the configuration will
|
||||
fail.</p>
|
||||
<p>
|
||||
If keys are present in the key directory the first time the zone
|
||||
is loaded, the zone will be signed immediately, without waiting for an
|
||||
<span class="command"><strong>rndc sign</strong></span> or <span class="command"><strong>rndc loadkeys</strong></span>
|
||||
command. (Those commands can still be used when there are unscheduled
|
||||
key changes, however.)
|
||||
</p>
|
||||
<p>
|
||||
When new keys are added to a zone, the TTL is set to match that
|
||||
of any existing DNSKEY RRset. If there is no existing DNSKEY RRset,
|
||||
then the TTL will be set to the TTL specified when the key was
|
||||
created (using the <span class="command"><strong>dnssec-keygen -L</strong></span> option), if
|
||||
any, or to the SOA TTL.
|
||||
</p>
|
||||
<p>
|
||||
If you wish the zone to be signed using NSEC3 instead of NSEC,
|
||||
submit an NSEC3PARAM record via dynamic update prior to the
|
||||
scheduled publication and activation of the keys. If you wish the
|
||||
NSEC3 chain to have the OPTOUT bit set, set it in the flags field
|
||||
of the NSEC3PARAM record. The NSEC3PARAM record will not appear in
|
||||
the zone immediately, but it will be stored for later reference. When
|
||||
the zone is signed and the NSEC3 chain is completed, the NSEC3PARAM
|
||||
record will appear in the zone.
|
||||
</p>
|
||||
<p>
|
||||
Using the
|
||||
<span class="command"><strong>auto-dnssec</strong></span> option requires the zone to be
|
||||
configured to allow dynamic updates, by adding an
|
||||
<span class="command"><strong>allow-update</strong></span> or
|
||||
<span class="command"><strong>update-policy</strong></span> statement to the zone
|
||||
configuration. If this has not been done, the configuration will
|
||||
fail.
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.24"></a>Private-type records</h3></div></div></div>
|
||||
<a name="id-1.5.10.27"></a>Private-type records</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>The state of the signing process is signaled by
|
||||
private-type records (with a default type value of 65534). When
|
||||
signing is complete, these records will have a nonzero value for
|
||||
the final octet (for those records which have a nonzero initial
|
||||
octet).</p>
|
||||
<p>The private type record format: If the first octet is
|
||||
non-zero then the record indicates that the zone needs to be
|
||||
signed with the key matching the record, or that all signatures
|
||||
that match the record should be removed.</p>
|
||||
<p>
|
||||
The state of the signing process is signaled by
|
||||
private-type records (with a default type value of 65534). When
|
||||
signing is complete, these records will have a nonzero value for
|
||||
the final octet (for those records which have a nonzero initial
|
||||
octet).
|
||||
</p>
|
||||
<p>
|
||||
The private type record format: If the first octet is
|
||||
non-zero then the record indicates that the zone needs to be
|
||||
signed with the key matching the record, or that all signatures
|
||||
that match the record should be removed.
|
||||
</p>
|
||||
<p>
|
||||
</p>
|
||||
<div class="literallayout"><p><br>
|
||||
@@ -1349,14 +1387,18 @@ options {
|
||||
</p></div>
|
||||
<p>
|
||||
</p>
|
||||
<p>Only records flagged as "complete" can be removed via
|
||||
dynamic update. Attempts to remove other private type records
|
||||
will be silently ignored.</p>
|
||||
<p>If the first octet is zero (this is a reserved algorithm
|
||||
number that should never appear in a DNSKEY record) then the
|
||||
record indicates changes to the NSEC3 chains are in progress. The
|
||||
rest of the record contains an NSEC3PARAM record. The flag field
|
||||
tells what operation to perform based on the flag bits.</p>
|
||||
<p>
|
||||
Only records flagged as "complete" can be removed via
|
||||
dynamic update. Attempts to remove other private type records
|
||||
will be silently ignored.
|
||||
</p>
|
||||
<p>
|
||||
If the first octet is zero (this is a reserved algorithm
|
||||
number that should never appear in a DNSKEY record) then the
|
||||
record indicates changes to the NSEC3 chains are in progress. The
|
||||
rest of the record contains an NSEC3PARAM record. The flag field
|
||||
tells what operation to perform based on the flag bits.
|
||||
</p>
|
||||
<p>
|
||||
</p>
|
||||
<div class="literallayout"><p><br>
|
||||
@@ -1370,127 +1412,160 @@ options {
|
||||
</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.31"></a>DNSKEY rollovers</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>As with insecure-to-secure conversions, rolling DNSSEC
|
||||
keys can be done in two ways: using a dynamic DNS update, or the
|
||||
<span class="command"><strong>auto-dnssec</strong></span> zone option.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.33"></a>Dynamic DNS update method</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p> To perform key rollovers via dynamic update, you need to add
|
||||
the <code class="filename">K*</code> files for the new keys so that
|
||||
<span class="command"><strong>named</strong></span> can find them. You can then add the new
|
||||
DNSKEY RRs via dynamic update.
|
||||
<span class="command"><strong>named</strong></span> will then cause the zone to be signed
|
||||
with the new keys. When the signing is complete the private type
|
||||
records will be updated so that the last octet is non
|
||||
zero.</p>
|
||||
<p>If this is for a KSK you need to inform the parent and any
|
||||
trust anchor repositories of the new KSK.</p>
|
||||
<p>You should then wait for the maximum TTL in the zone before
|
||||
removing the old DNSKEY. If it is a KSK that is being updated,
|
||||
you also need to wait for the DS RRset in the parent to be
|
||||
updated and its TTL to expire. This ensures that all clients will
|
||||
be able to verify at least one signature when you remove the old
|
||||
DNSKEY.</p>
|
||||
<p>The old DNSKEY can be removed via UPDATE. Take care to
|
||||
specify the correct key.
|
||||
<span class="command"><strong>named</strong></span> will clean out any signatures generated
|
||||
by the old key after the update completes.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.38"></a>Automatic key rollovers</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>When a new key reaches its activation date (as set by
|
||||
<span class="command"><strong>dnssec-keygen</strong></span> or <span class="command"><strong>dnssec-settime</strong></span>),
|
||||
if the <span class="command"><strong>auto-dnssec</strong></span> zone option is set to
|
||||
<code class="constant">maintain</code>, <span class="command"><strong>named</strong></span> will
|
||||
automatically carry out the key rollover. If the key's algorithm
|
||||
has not previously been used to sign the zone, then the zone will
|
||||
be fully signed as quickly as possible. However, if the new key
|
||||
is replacing an existing key of the same algorithm, then the
|
||||
zone will be re-signed incrementally, with signatures from the
|
||||
old key being replaced with signatures from the new key as their
|
||||
signature validity periods expire. By default, this rollover
|
||||
completes in 30 days, after which it will be safe to remove the
|
||||
old key from the DNSKEY RRset.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.40"></a>NSEC3PARAM rollovers via UPDATE</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>Add the new NSEC3PARAM record via dynamic update. When the
|
||||
new NSEC3 chain has been generated, the NSEC3PARAM flag field
|
||||
will be zero. At this point you can remove the old NSEC3PARAM
|
||||
record. The old chain will be removed after the update request
|
||||
completes.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.42"></a>Converting from NSEC to NSEC3</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>To do this, you just need to add an NSEC3PARAM record. When
|
||||
the conversion is complete, the NSEC chain will have been removed
|
||||
and the NSEC3PARAM record will have a zero flag field. The NSEC3
|
||||
chain will be generated before the NSEC chain is
|
||||
destroyed.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.44"></a>Converting from NSEC3 to NSEC</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>To do this, use <span class="command"><strong>nsupdate</strong></span> to
|
||||
remove all NSEC3PARAM records with a zero flag
|
||||
field. The NSEC chain will be generated before the NSEC3 chain is
|
||||
removed.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.46"></a>Converting from secure to insecure</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>To convert a signed zone to unsigned using dynamic DNS,
|
||||
delete all the DNSKEY records from the zone apex using
|
||||
<span class="command"><strong>nsupdate</strong></span>. All signatures, NSEC or NSEC3 chains,
|
||||
and associated NSEC3PARAM records will be removed automatically.
|
||||
This will take place after the update request completes.</p>
|
||||
<p> This requires the
|
||||
<span class="command"><strong>dnssec-secure-to-insecure</strong></span> option to be set to
|
||||
<strong class="userinput"><code>yes</code></strong> in
|
||||
<code class="filename">named.conf</code>.</p>
|
||||
<p>In addition, if the <span class="command"><strong>auto-dnssec maintain</strong></span>
|
||||
zone statement is used, it should be removed or changed to
|
||||
<span class="command"><strong>allow</strong></span> instead (or it will re-sign).
|
||||
</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.50"></a>Periodic re-signing</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>In any secure zone which supports dynamic updates, <span class="command"><strong>named</strong></span>
|
||||
will periodically re-sign RRsets which have not been re-signed as
|
||||
a result of some update action. The signature lifetimes will be
|
||||
adjusted so as to spread the re-sign load over time rather than
|
||||
all at once.</p>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.52"></a>NSEC3 and OPTOUT</h3></div></div></div>
|
||||
<a name="id-1.5.10.34"></a>DNSKEY rollovers</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> only supports creating new NSEC3 chains
|
||||
where all the NSEC3 records in the zone have the same OPTOUT
|
||||
state.
|
||||
<span class="command"><strong>named</strong></span> supports UPDATES to zones where the NSEC3
|
||||
records in the chain have mixed OPTOUT state.
|
||||
<span class="command"><strong>named</strong></span> does not support changing the OPTOUT
|
||||
state of an individual NSEC3 record, the entire chain needs to be
|
||||
changed if the OPTOUT state of an individual NSEC3 needs to be
|
||||
changed.</p>
|
||||
As with insecure-to-secure conversions, rolling DNSSEC
|
||||
keys can be done in two ways: using a dynamic DNS update, or the
|
||||
<span class="command"><strong>auto-dnssec</strong></span> zone option.
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.36"></a>Dynamic DNS update method</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>
|
||||
To perform key rollovers via dynamic update, you need to add
|
||||
the <code class="filename">K*</code> files for the new keys so that
|
||||
<span class="command"><strong>named</strong></span> can find them. You can then add the new
|
||||
DNSKEY RRs via dynamic update.
|
||||
<span class="command"><strong>named</strong></span> will then cause the zone to be signed
|
||||
with the new keys. When the signing is complete the private type
|
||||
records will be updated so that the last octet is non
|
||||
zero.
|
||||
</p>
|
||||
<p>
|
||||
If this is for a KSK you need to inform the parent and any
|
||||
trust anchor repositories of the new KSK.
|
||||
</p>
|
||||
<p>
|
||||
You should then wait for the maximum TTL in the zone before
|
||||
removing the old DNSKEY. If it is a KSK that is being updated,
|
||||
you also need to wait for the DS RRset in the parent to be
|
||||
updated and its TTL to expire. This ensures that all clients will
|
||||
be able to verify at least one signature when you remove the old
|
||||
DNSKEY.
|
||||
</p>
|
||||
<p>
|
||||
The old DNSKEY can be removed via UPDATE. Take care to
|
||||
specify the correct key.
|
||||
<span class="command"><strong>named</strong></span> will clean out any signatures generated
|
||||
by the old key after the update completes.
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.41"></a>Automatic key rollovers</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>
|
||||
When a new key reaches its activation date (as set by
|
||||
<span class="command"><strong>dnssec-keygen</strong></span> or <span class="command"><strong>dnssec-settime</strong></span>),
|
||||
if the <span class="command"><strong>auto-dnssec</strong></span> zone option is set to
|
||||
<code class="constant">maintain</code>, <span class="command"><strong>named</strong></span> will
|
||||
automatically carry out the key rollover. If the key's algorithm
|
||||
has not previously been used to sign the zone, then the zone will
|
||||
be fully signed as quickly as possible. However, if the new key
|
||||
is replacing an existing key of the same algorithm, then the
|
||||
zone will be re-signed incrementally, with signatures from the
|
||||
old key being replaced with signatures from the new key as their
|
||||
signature validity periods expire. By default, this rollover
|
||||
completes in 30 days, after which it will be safe to remove the
|
||||
old key from the DNSKEY RRset.
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.43"></a>NSEC3PARAM rollovers via UPDATE</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>
|
||||
Add the new NSEC3PARAM record via dynamic update. When the
|
||||
new NSEC3 chain has been generated, the NSEC3PARAM flag field
|
||||
will be zero. At this point you can remove the old NSEC3PARAM
|
||||
record. The old chain will be removed after the update request
|
||||
completes.
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.45"></a>Converting from NSEC to NSEC3</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>
|
||||
To do this, you just need to add an NSEC3PARAM record. When
|
||||
the conversion is complete, the NSEC chain will have been removed
|
||||
and the NSEC3PARAM record will have a zero flag field. The NSEC3
|
||||
chain will be generated before the NSEC chain is
|
||||
destroyed.
|
||||
</p>
|
||||
<p>
|
||||
NSEC3 is not supported yet with <span class="command"><strong>dnssec-policy</strong></span>.
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.48"></a>Converting from NSEC3 to NSEC</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>
|
||||
To do this, use <span class="command"><strong>nsupdate</strong></span> to
|
||||
remove all NSEC3PARAM records with a zero flag
|
||||
field. The NSEC chain will be generated before the NSEC3 chain is
|
||||
removed.
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.50"></a>Converting from secure to insecure</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>
|
||||
To convert a signed zone to unsigned using dynamic DNS,
|
||||
delete all the DNSKEY records from the zone apex using
|
||||
<span class="command"><strong>nsupdate</strong></span>. All signatures, NSEC or NSEC3 chains,
|
||||
and associated NSEC3PARAM records will be removed automatically.
|
||||
This will take place after the update request completes.</p>
|
||||
<p> This requires the
|
||||
<span class="command"><strong>dnssec-secure-to-insecure</strong></span> option to be set to
|
||||
<strong class="userinput"><code>yes</code></strong> in
|
||||
<code class="filename">named.conf</code>.</p>
|
||||
<p>In addition, if the <span class="command"><strong>auto-dnssec maintain</strong></span>
|
||||
zone statement is used, it should be removed or changed to
|
||||
<span class="command"><strong>allow</strong></span> instead (or it will re-sign).
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.54"></a>Periodic re-signing</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>
|
||||
In any secure zone which supports dynamic updates, <span class="command"><strong>named</strong></span>
|
||||
will periodically re-sign RRsets which have not been re-signed as
|
||||
a result of some update action. The signature lifetimes will be
|
||||
adjusted so as to spread the re-sign load over time rather than
|
||||
all at once.
|
||||
</p>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="id-1.5.10.56"></a>NSEC3 and OPTOUT</h3></div></div></div>
|
||||
|
||||
</div>
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> only supports creating new NSEC3 chains
|
||||
where all the NSEC3 records in the zone have the same OPTOUT
|
||||
state.
|
||||
<span class="command"><strong>named</strong></span> supports UPDATES to zones where the NSEC3
|
||||
records in the chain have mixed OPTOUT state.
|
||||
<span class="command"><strong>named</strong></span> does not support changing the OPTOUT
|
||||
state of an individual NSEC3 record, the entire chain needs to be
|
||||
changed if the OPTOUT state of an individual NSEC3 needs to be
|
||||
changed.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
@@ -1512,8 +1587,8 @@ options {
|
||||
<p>To configure a validating resolver to use RFC 5011 to
|
||||
maintain a trust anchor, configure the trust anchor using a
|
||||
<span class="command"><strong>dnssec-keys</strong></span> statement and the
|
||||
<span class="command"><strong>initial-key</strong></span> keyword. Information about
|
||||
this can be found in
|
||||
<span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span>
|
||||
keyword. Information about this can be found in
|
||||
<a class="xref" href="Bv9ARM.ch05.html#dnssec-keys" title="dnssec-keys Statement Definition and Usage">the section called “<span class="command"><strong>dnssec-keys</strong></span> Statement Definition
|
||||
and Usage”</a>.</p>
|
||||
</div>
|
||||
@@ -2840,6 +2915,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+389
-98
@@ -70,6 +70,9 @@
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_keys"><span class="command"><strong>dnssec-keys</strong></span> Statement Grammar</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec-keys"><span class="command"><strong>dnssec-keys</strong></span> Statement Definition
|
||||
and Usage</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy_grammar"><span class="command"><strong>dnssec-policy</strong></span> Statement Grammar</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy"><span class="command"><strong>dnssec-policy</strong></span> Statement Definition
|
||||
and Usage</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#managed-keys"><span class="command"><strong>managed-keys</strong></span> Statement Grammar</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#managed_keys"><span class="command"><strong>managed-keys</strong></span> Statement Definition
|
||||
and Usage</a></span></dt>
|
||||
@@ -806,6 +809,17 @@
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>
|
||||
<p><span class="command"><strong>dnssec-policy</strong></span></p>
|
||||
</td>
|
||||
<td>
|
||||
<p>
|
||||
describes a DNSSEC key and signing policy for zones.
|
||||
See <a class="xref" href="Bv9ARM.ch05.html#dnssec_policy_grammar" title="dnssec-policy Statement Grammar">the section called “<span class="command"><strong>dnssec-policy</strong></span> Statement Grammar”</a> for details.
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>
|
||||
<p><span class="command"><strong>include</strong></span></p>
|
||||
</td>
|
||||
@@ -889,11 +903,14 @@
|
||||
</td>
|
||||
<td>
|
||||
<p>
|
||||
defines DNSSEC keys: if used with the
|
||||
<span class="command"><strong>initial-key</strong></span> keyword,
|
||||
keys are kept up to date using RFC 5011
|
||||
trust anchor maintenance, and if used with
|
||||
<span class="command"><strong>static-key</strong></span>, keys are permanent.
|
||||
defines DNSSEC trust anchors: if used with
|
||||
the <span class="command"><strong>initial-key</strong></span> or
|
||||
<span class="command"><strong>initial-ds</strong></span> keyword,
|
||||
trust anchors are kept up to date using RFC
|
||||
5011 trust anchor maintenance, and if used with
|
||||
<span class="command"><strong>static-key</strong></span> or
|
||||
<span class="command"><strong>static-ds</strong></span>, trust anchors
|
||||
are permanent.
|
||||
</p>
|
||||
</td>
|
||||
</tr>
|
||||
@@ -2418,7 +2435,7 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port
|
||||
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key
|
||||
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [
|
||||
<span class="command"><strong>in-memory</strong></span> <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>ttlval</code></em> ]; ... };
|
||||
<span class="command"><strong>in-memory</strong></span> <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>duration</code></em> ]; ... };
|
||||
<span class="command"><strong>check-dup-records</strong></span> ( fail | warn | ignore );
|
||||
<span class="command"><strong>check-integrity</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>check-mx</strong></span> ( fail | warn | ignore );
|
||||
@@ -2500,18 +2517,18 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
<span class="command"><strong>fstrm-set-output-notify-threshold</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>fstrm-set-output-queue-model</strong></span> ( mpsc | spsc );
|
||||
<span class="command"><strong>fstrm-set-output-queue-size</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>fstrm-set-reopen-interval</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>fstrm-set-reopen-interval</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>geoip-directory</strong></span> ( <em class="replaceable"><code>quoted_string</code></em> | none );
|
||||
<span class="command"><strong>glue-cache</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>heartbeat-interval</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>hostname</strong></span> ( <em class="replaceable"><code>quoted_string</code></em> | none );
|
||||
<span class="command"><strong>inline-signing</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>interface-interval</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>interface-interval</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>ixfr-from-differences</strong></span> ( primary | master | secondary | slave |
|
||||
<em class="replaceable"><code>boolean</code></em> );
|
||||
<span class="command"><strong>keep-response-order</strong></span> { <em class="replaceable"><code>address_match_element</code></em>; ... };
|
||||
<span class="command"><strong>key-directory</strong></span> <em class="replaceable"><code>quoted_string</code></em>;
|
||||
<span class="command"><strong>lame-ttl</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>lame-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>listen-on</strong></span> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp
|
||||
<em class="replaceable"><code>integer</code></em> ] {
|
||||
<em class="replaceable"><code>address_match_element</code></em>; ... };
|
||||
@@ -2525,28 +2542,28 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
<span class="command"><strong>masterfile-style</strong></span> ( full | relative );
|
||||
<span class="command"><strong>match-mapped-addresses</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>max-cache-size</strong></span> ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );
|
||||
<span class="command"><strong>max-cache-ttl</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>max-cache-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>max-clients-per-query</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-journal-size</strong></span> ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );
|
||||
<span class="command"><strong>max-ncache-ttl</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>max-ncache-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>max-records</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-recursion-depth</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-recursion-queries</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-refresh-time</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-retry-time</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-rsa-exponent-size</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-stale-ttl</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>max-stale-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>max-transfer-idle-in</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-transfer-idle-out</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-transfer-time-in</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-transfer-time-out</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-udp-size</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-zone-ttl</strong></span> ( unlimited | <em class="replaceable"><code>ttlval</code></em> );
|
||||
<span class="command"><strong>max-zone-ttl</strong></span> ( unlimited | <em class="replaceable"><code>duration</code></em> );
|
||||
<span class="command"><strong>memstatistics</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>memstatistics-file</strong></span> <em class="replaceable"><code>quoted_string</code></em>;
|
||||
<span class="command"><strong>message-compression</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>min-cache-ttl</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>min-ncache-ttl</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>min-cache-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>min-ncache-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>min-refresh-time</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>min-retry-time</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>minimal-any</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
@@ -2563,8 +2580,8 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
<span class="command"><strong>notify-source-v6</strong></span> ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]
|
||||
[ dscp <em class="replaceable"><code>integer</code></em> ];
|
||||
<span class="command"><strong>notify-to-soa</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>nta-lifetime</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>nta-recheck</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>nta-lifetime</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>nta-recheck</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>nxdomain-redirect</strong></span> <em class="replaceable"><code>string</code></em>;
|
||||
<span class="command"><strong>pid-file</strong></span> ( <em class="replaceable"><code>quoted_string</code></em> | none );
|
||||
<span class="command"><strong>port</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
@@ -2611,13 +2628,13 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
<span class="command"><strong>response-padding</strong></span> { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size
|
||||
<em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>response-policy</strong></span> { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log
|
||||
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [ min-update-interval
|
||||
<em class="replaceable"><code>ttlval</code></em> ] [ policy ( cname | disabled | drop | given | no-op |
|
||||
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [ min-update-interval
|
||||
<em class="replaceable"><code>duration</code></em> ] [ policy ( cname | disabled | drop | given | no-op |
|
||||
<span class="command"><strong>nodata</strong></span> | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [
|
||||
<span class="command"><strong>recursive-only</strong></span> <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [
|
||||
<span class="command"><strong>nsdname-enable</strong></span> <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [
|
||||
<span class="command"><strong>break-dnssec</strong></span> <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [
|
||||
<span class="command"><strong>min-update-interval</strong></span> <em class="replaceable"><code>ttlval</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [
|
||||
<span class="command"><strong>break-dnssec</strong></span> <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [
|
||||
<span class="command"><strong>min-update-interval</strong></span> <em class="replaceable"><code>duration</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [
|
||||
<span class="command"><strong>nsip-wait-recurse</strong></span> <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]
|
||||
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [
|
||||
<span class="command"><strong>nsdname-enable</strong></span> <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [
|
||||
@@ -2631,7 +2648,7 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
<span class="command"><strong>serial-query-rate</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>serial-update-method</strong></span> ( date | increment | unixtime );
|
||||
<span class="command"><strong>server-id</strong></span> ( <em class="replaceable"><code>quoted_string</code></em> | none | hostname );
|
||||
<span class="command"><strong>servfail-ttl</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>servfail-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>session-keyalg</strong></span> <em class="replaceable"><code>string</code></em>;
|
||||
<span class="command"><strong>session-keyfile</strong></span> ( <em class="replaceable"><code>quoted_string</code></em> | none );
|
||||
<span class="command"><strong>session-keyname</strong></span> <em class="replaceable"><code>string</code></em>;
|
||||
@@ -2642,7 +2659,7 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
<span class="command"><strong>sortlist</strong></span> { <em class="replaceable"><code>address_match_element</code></em>; ... };
|
||||
<span class="command"><strong>stacksize</strong></span> ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );
|
||||
<span class="command"><strong>stale-answer-enable</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>stale-answer-ttl</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>stale-answer-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>startup-notify-rate</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>statistics-file</strong></span> <em class="replaceable"><code>quoted_string</code></em>;
|
||||
<span class="command"><strong>synth-from-dnssec</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
@@ -3068,7 +3085,8 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
<p>
|
||||
Specifies the directory in which to store the files that
|
||||
track managed DNSSEC keys (i.e., those configured using
|
||||
the <span class="command"><strong>initial-key</strong></span> keyword in a
|
||||
the <span class="command"><strong>initial-key</strong></span> or
|
||||
<span class="command"><strong>initial-ds</strong></span> keywords in a
|
||||
<span class="command"><strong>dnssec-keys</strong></span> statement). By default,
|
||||
this is the working directory. The directory
|
||||
<span class="emphasis"><em>must</em></span> be writable by the effective
|
||||
@@ -3211,7 +3229,7 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||
the first time; if unsuccessful, the server will
|
||||
will terminate, under the assumption that another
|
||||
server is already running. If not specified, the default is
|
||||
<code class="filename">/var/run/named/named.lock</code>.
|
||||
<code class="filename">none</code>.
|
||||
</p>
|
||||
<p>
|
||||
Specifying <span class="command"><strong>lock-file none</strong></span> disables the
|
||||
@@ -3788,15 +3806,21 @@ options {
|
||||
<dt><span class="term"><span class="command"><strong>automatic-interface-scan</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
If <strong class="userinput"><code>yes</code></strong> and supported by the OS,
|
||||
automatically rescan network interfaces when the interface
|
||||
addresses are added or removed. The default is
|
||||
<strong class="userinput"><code>yes</code></strong>.
|
||||
If <strong class="userinput"><code>yes</code></strong> and supported by the operating
|
||||
system, automatically rescan network interfaces when the
|
||||
interface addresses are added or removed. The default is
|
||||
<strong class="userinput"><code>yes</code></strong>. This configuration option does
|
||||
not affect time based <span class="command"><strong>interface-interval</strong></span>
|
||||
option, and it is recommended to set the time based
|
||||
<span class="command"><strong>interface-interval</strong></span> to 0 when the operator
|
||||
confirms that automatic interface scanning is supported by the
|
||||
operating system.
|
||||
</p>
|
||||
<p>
|
||||
Currently the OS needs to support routing sockets for
|
||||
<span class="command"><strong>automatic-interface-scan</strong></span> to be
|
||||
supported.
|
||||
The <span class="command"><strong>automatic-interface-scan</strong></span> implementation
|
||||
uses routing sockets for the network interface discovery,
|
||||
and therefore the operating system has to support the routing
|
||||
sockets for this feature to work.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>allow-new-zones</strong></span></span></dt>
|
||||
@@ -4305,6 +4329,17 @@ options {
|
||||
response to a UDP request from a cookie aware client.
|
||||
BADCOOKIE is sent if there is a bad or no existent
|
||||
server cookie.
|
||||
The default is <strong class="userinput"><code>no</code></strong>.
|
||||
</p>
|
||||
<p>
|
||||
Set this to <strong class="userinput"><code>yes</code></strong> to test that DNS
|
||||
COOKIE clients correctly handle BADCOOKIE or if you are
|
||||
getting a lot of forged DNS requests with DNS COOKIES
|
||||
present. Setting this to <strong class="userinput"><code>yes</code></strong> will
|
||||
result in reduced amplification effect in a reflection
|
||||
attack, as the BADCOOKIE response will be smaller than
|
||||
a full response, while also requiring a legitimate client
|
||||
to follow up with a second query with the new, valid, cookie.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>answer-cookie</strong></span></span></dt>
|
||||
@@ -4347,6 +4382,7 @@ options {
|
||||
do not send a correct COOKIE option may be limited
|
||||
to receiving smaller responses via the
|
||||
<span class="command"><strong>nocookie-udp-size</strong></span> option.
|
||||
The default is <strong class="userinput"><code>yes</code></strong>.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>stale-answer-enable</strong></span></span></dt>
|
||||
@@ -4959,7 +4995,9 @@ options {
|
||||
<p>
|
||||
Synthesize answers from cached NSEC, NSEC3 and
|
||||
other RRsets that have been proved to be correct
|
||||
using DNSSEC. The default is <span class="command"><strong>yes</strong></span>.
|
||||
using DNSSEC. The default is <span class="command"><strong>no</strong></span>,
|
||||
but it will become <span class="command"><strong>yes</strong></span> again
|
||||
in the future releases.
|
||||
</p>
|
||||
<p>
|
||||
Note:
|
||||
@@ -6469,10 +6507,11 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
||||
minutes. The default
|
||||
is 60 minutes. The maximum value is 28 days (40320 minutes).
|
||||
If set to 0, interface scanning will only occur when
|
||||
the configuration file is loaded. After the scan, the
|
||||
server will
|
||||
begin listening for queries on any newly discovered
|
||||
interfaces (provided they are allowed by the
|
||||
the configuration file is loaded, or when
|
||||
<span class="command"><strong>automatic-interface-scan</strong></span> is enabled
|
||||
and supported by the operating system. After the scan, the
|
||||
server will begin listening for queries on any newly
|
||||
discovered interfaces (provided they are allowed by the
|
||||
<span class="command"><strong>listen-on</strong></span> configuration), and
|
||||
will stop listening on interfaces that have gone away.
|
||||
For convenience, TTL-style time unit suffixes may be
|
||||
@@ -6511,7 +6550,8 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
||||
The first element (which may be an IP address, an IP prefix, an
|
||||
ACL name or a nested <span class="command"><strong>address_match_list</strong></span>) of
|
||||
each top level list is checked against the source address of
|
||||
the query until a match is found.
|
||||
the query until a match is found. When the addresses in the
|
||||
first element overlap, the first rule to match gets selected.
|
||||
</p>
|
||||
<p>
|
||||
Once the source address of the query has been matched, if the
|
||||
@@ -6823,6 +6863,20 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
|
||||
<span class="command"><strong>rndc serve-stale on</strong></span>.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>resolver-nonbackoff-tries</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Specifies how many retries occur before exponential
|
||||
backoff kicks in. The default is <strong class="userinput"><code>3</code></strong>.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>resolver-retry-interval</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The base retry interval in milliseconds.
|
||||
The default is <strong class="userinput"><code>800</code></strong>.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>sig-validity-interval</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
@@ -8798,7 +8852,8 @@ example.com CNAME rpz-tcp-only.
|
||||
<a name="dnssec_keys"></a><span class="command"><strong>dnssec-keys</strong></span> Statement Grammar</h3></div></div></div>
|
||||
<pre class="programlisting">
|
||||
<span class="command"><strong>dnssec-keys</strong></span> { <em class="replaceable"><code>string</code></em> ( static-key |
|
||||
<span class="command"><strong>initial-key</strong></span> ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em>
|
||||
<span class="command"><strong>initial-key</strong></span> | static-ds | initial-ds )
|
||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em>
|
||||
<em class="replaceable"><code>quoted_string</code></em>; ... };
|
||||
</pre>
|
||||
</div>
|
||||
@@ -8812,12 +8867,12 @@ example.com CNAME rpz-tcp-only.
|
||||
trust anchors. DNSSEC is described in <a class="xref" href="Bv9ARM.ch04.html#DNSSEC" title="DNSSEC">the section called “DNSSEC”</a>.
|
||||
</p>
|
||||
<p>
|
||||
A trust anchor is defined when the public key for
|
||||
a non-authoritative zone is known, but cannot be securely
|
||||
obtained through DNS, either because it is the DNS root zone
|
||||
or because its parent zone is unsigned. Once a key has been
|
||||
configured as a trust anchor, it is treated as if it had
|
||||
been validated and proven secure.
|
||||
A trust anchor is defined when the public key or public key
|
||||
digest for a non-authoritative zone is known, but cannot be
|
||||
securely obtained through DNS, either because it is the DNS
|
||||
root zone or because its parent zone is unsigned. Once a key
|
||||
or digest has been configured as a trust anchor, it is treated
|
||||
as if it had been validated and proven secure.
|
||||
</p>
|
||||
<p>
|
||||
The resolver attempts DNSSEC validation on all DNS data
|
||||
@@ -8829,19 +8884,9 @@ example.com CNAME rpz-tcp-only.
|
||||
<p>
|
||||
All keys listed in <span class="command"><strong>dnssec-keys</strong></span>, and
|
||||
their corresponding zones, are deemed to exist regardless
|
||||
of what parent zones say. Only keys configured as trust anchors
|
||||
of what parent zones say. Only keys configured as trust anchors
|
||||
are used to validate the DNSKEY RRset for the corresponding
|
||||
name. The parent's DS RRset will not be used.
|
||||
</p>
|
||||
<p>
|
||||
The <span class="command"><strong>dnssec-keys</strong></span> statement can contain
|
||||
multiple key entries, each consisting of the key's
|
||||
domain name, followed by the <span class="command"><strong>static-key</strong></span> or
|
||||
<span class="command"><strong>initial-key</strong></span> keyword, then the key's flags,
|
||||
protocol, algorithm, and the Base64 representation of the key
|
||||
data. Spaces, tabs, newlines and carriage returns are ignored
|
||||
in the key data, so the configuration may be split up into
|
||||
multiple lines.
|
||||
name. The parent's DS RRset will not be used.
|
||||
</p>
|
||||
<p>
|
||||
<span class="command"><strong>dnssec-keys</strong></span> may be set at the top level
|
||||
@@ -8851,11 +8896,33 @@ example.com CNAME rpz-tcp-only.
|
||||
defined in a view are only used within that view.
|
||||
</p>
|
||||
<p>
|
||||
<span class="command"><strong>dnssec-keys</strong></span> entries can be configured with
|
||||
two keywords: <span class="command"><strong>static-key</strong></span> or
|
||||
<span class="command"><strong>initial-key</strong></span>. Keys configured with
|
||||
<span class="command"><strong>static-key</strong></span> are immutable,
|
||||
while keys configured with <span class="command"><strong>initial-key</strong></span>
|
||||
The <span class="command"><strong>dnssec-keys</strong></span> statement can contain
|
||||
multiple trust anchor entries, each consisting of a
|
||||
domain name, followed by an "anchor type" keyword indicating
|
||||
the trust anchor's format, followed by the key or digest data.
|
||||
</p>
|
||||
<p>
|
||||
If the anchor type is <span class="command"><strong>static-key</strong></span> or
|
||||
<span class="command"><strong>initial-key</strong></span>, then it is followed with the
|
||||
key's flags, protocol, algorithm, and the Base64 representation
|
||||
of the public key data. This is identical to the text
|
||||
representation of a DNSKEY record. Spaces, tabs, newlines and
|
||||
carriage returns are ignored in the key data, so the
|
||||
configuration may be split up into multiple lines.
|
||||
</p>
|
||||
<p>
|
||||
If the anchor type is <span class="command"><strong>static-ds</strong></span> or
|
||||
<span class="command"><strong>initial-ds</strong></span>, then it is followed with the
|
||||
key tag, algorithm, digest type, and the hexidecimal
|
||||
representation of the key digest. This is identical to the
|
||||
text representation of a DS record. Spaces, tabs, newlines
|
||||
and carriage returns are ignored.
|
||||
</p>
|
||||
<p>
|
||||
Trust anchors configured with the
|
||||
<span class="command"><strong>static-key</strong></span> or <span class="command"><strong>static-ds</strong></span>
|
||||
anchor types are immutable, while keys configured with
|
||||
<span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span>
|
||||
can be kept up to date automatically, without intervention
|
||||
from the resolver operator. (<span class="command"><strong>static-key</strong></span>
|
||||
keys are identical to keys configured using the deprecated
|
||||
@@ -8865,45 +8932,55 @@ example.com CNAME rpz-tcp-only.
|
||||
Suppose, for example, that a zone's key-signing
|
||||
key was compromised, and the zone owner had to revoke and
|
||||
replace the key. A resolver which had the original key
|
||||
configured as a <span class="command"><strong>static-key</strong></span> would be
|
||||
unable to validate this zone any longer; it would
|
||||
reply with a SERVFAIL response code. This would
|
||||
continue until the resolver operator had updated the
|
||||
<span class="command"><strong>dnssec-keys</strong></span> statement with the new key.
|
||||
configured using <span class="command"><strong>static-key</strong></span> or
|
||||
<span class="command"><strong>static-ds</strong></span> would be unable to validate
|
||||
this zone any longer; it would reply with a SERVFAIL response
|
||||
code. This would continue until the resolver operator had
|
||||
updated the <span class="command"><strong>dnssec-keys</strong></span> statement with
|
||||
the new key.
|
||||
</p>
|
||||
<p>
|
||||
If, however, the trust anchor had been configured with
|
||||
<span class="command"><strong>initial-key</strong></span> instead, then the
|
||||
zone owner could add a "stand-by" key to their zone in advance.
|
||||
<span class="command"><strong>named</strong></span> would store the stand-by key, and
|
||||
when the original key was revoked, <span class="command"><strong>named</strong></span>
|
||||
would be able to transition smoothly to the new key. It would
|
||||
also recognize that the old key had been revoked, and cease
|
||||
using that key to validate answers, minimizing the damage that
|
||||
the compromised key could do. This is the process used to
|
||||
keep the ICANN root DNSSEC key up to date.
|
||||
<span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span>
|
||||
instead, then the zone owner could add a "stand-by" key to
|
||||
their zone in advance. <span class="command"><strong>named</strong></span> would store
|
||||
the stand-by key, and when the original key was revoked,
|
||||
<span class="command"><strong>named</strong></span> would be able to transition smoothly
|
||||
to the new key. It would also recognize that the old key had
|
||||
been revoked, and cease using that key to validate answers,
|
||||
minimizing the damage that the compromised key could do.
|
||||
This is the process used to keep the ICANN root DNSSEC key
|
||||
up to date.
|
||||
</p>
|
||||
<p>
|
||||
Whereas <span class="command"><strong>static-key</strong></span>
|
||||
keys continue to be trusted until they are removed from
|
||||
Whereas <span class="command"><strong>static-key</strong></span> and
|
||||
<span class="command"><strong>static-ds</strong></span> trust anchors continue
|
||||
to be trusted until they are removed from
|
||||
<code class="filename">named.conf</code>, an
|
||||
<span class="command"><strong>initial-key</strong></span> is only trusted
|
||||
<span class="emphasis"><em>once</em></span>: for as long as it
|
||||
<span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span>
|
||||
is only trusted <span class="emphasis"><em>once</em></span>: for as long as it
|
||||
takes to load the managed key database and start the RFC 5011
|
||||
key maintenance process.
|
||||
</p>
|
||||
<p>
|
||||
It is not possible to mix static with initial trust anchors
|
||||
for the same domain name. It is also not possible to mix
|
||||
<span class="command"><strong>key</strong></span> with <span class="command"><strong>ds</strong></span> trust anchors.
|
||||
</p>
|
||||
<p>
|
||||
The first time <span class="command"><strong>named</strong></span> runs with an
|
||||
<span class="command"><strong>initial-key</strong></span> configured in
|
||||
<code class="filename">named.conf</code>, it fetches the
|
||||
<span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span>
|
||||
configured in <code class="filename">named.conf</code>, it fetches the
|
||||
DNSKEY RRset directly from the zone apex, and validates it
|
||||
using the key specified in <span class="command"><strong>dnssec-keys</strong></span>.
|
||||
If the DNSKEY RRset is validly signed, then it is
|
||||
used as the basis for a new managed keys database.
|
||||
using the trust anchor specified in <span class="command"><strong>dnssec-keys</strong></span>.
|
||||
If the DNSKEY RRset is validly signed by a key matching
|
||||
the trust anchor, then it is used as the basis for a new
|
||||
managed keys database.
|
||||
</p>
|
||||
<p>
|
||||
From that point on, whenever <span class="command"><strong>named</strong></span> runs, it
|
||||
sees the <span class="command"><strong>initial-key</strong></span> listed in
|
||||
sees the <span class="command"><strong>initial-key</strong></span> or
|
||||
<span class="command"><strong>initial-ds</strong></span> listed in
|
||||
<span class="command"><strong>dnssec-keys</strong></span>, checks to
|
||||
make sure RFC 5011 key maintenance has already been initialized
|
||||
for the specified domain, and if so, it simply moves on. The
|
||||
@@ -8914,13 +8991,13 @@ example.com CNAME rpz-tcp-only.
|
||||
</p>
|
||||
<p>
|
||||
The next time <span class="command"><strong>named</strong></span> runs after an
|
||||
<span class="command"><strong>initial-key</strong></span> has been
|
||||
<span class="emphasis"><em>removed</em></span> from the
|
||||
<span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>initial-ds</strong></span>
|
||||
trust anchor has been <span class="emphasis"><em>removed</em></span> from the
|
||||
<span class="command"><strong>dnssec-keys</strong></span> statement (or changed to
|
||||
a <span class="command"><strong>static-key</strong></span>), the corresponding
|
||||
zone will be removed from the managed keys database,
|
||||
and RFC 5011 key maintenance will no longer be used for that
|
||||
domain.
|
||||
a <span class="command"><strong>static-key</strong></span> or <span class="command"><strong>static-ds</strong></span>),
|
||||
the corresponding keys will be removed from the managed keys
|
||||
database, and RFC 5011 key maintenance will no longer be used
|
||||
for that domain.
|
||||
</p>
|
||||
<p>
|
||||
In the current implementation, the managed keys database
|
||||
@@ -8965,12 +9042,216 @@ example.com CNAME rpz-tcp-only.
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="dnssec_policy_grammar"></a><span class="command"><strong>dnssec-policy</strong></span> Statement Grammar</h3></div></div></div>
|
||||
<pre class="programlisting">
|
||||
<span class="command"><strong>dnssec-policy</strong></span> <em class="replaceable"><code>string</code></em> {
|
||||
<span class="command"><strong>dnskey-ttl</strong></span> <em class="replaceable"><code>ttlval</code></em>;
|
||||
<span class="command"><strong>keys</strong></span> { ( csk | ksk | zsk ) key-directory <em class="replaceable"><code>duration</code></em> <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };
|
||||
<span class="command"><strong>parent-ds-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>parent-propagation-delay</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>parent-registration-delay</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>publish-safety</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>retire-safety</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>signatures-refresh</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>signatures-validity</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>signatures-validity-dnskey</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>zone-max-ttl</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
<span class="command"><strong>zone-propagation-delay</strong></span> <em class="replaceable"><code>duration</code></em>;
|
||||
};
|
||||
</pre>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="dnssec_policy"></a><span class="command"><strong>dnssec-policy</strong></span> Statement Definition
|
||||
and Usage</h3></div></div></div>
|
||||
|
||||
<p>
|
||||
The <span class="command"><strong>dnssec-policy</strong></span> statement defines a key and
|
||||
signing policy (KASP) for zones.
|
||||
</p>
|
||||
<p>
|
||||
KASP is used to determine how one or more zones need to be signed
|
||||
with DNSSEC. For example, how often RRSIG records need to be
|
||||
refreshed, or what cryptographic algorithms to use.
|
||||
</p>
|
||||
<p>
|
||||
You can configure multiple policies. To attach a policy to a zone
|
||||
simply add <strong class="userinput"><code>dnssec-policy "policy_name"</code></strong>
|
||||
option to the <span class="command"><strong>zone</strong></span> statement with a matching
|
||||
policy name.
|
||||
</p>
|
||||
|
||||
<div class="variablelist"><dl class="variablelist">
|
||||
<dt><span class="term"><span class="command"><strong>dnskey-ttl</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The TTL of the DNSKEY resource records.
|
||||
Default is <code class="constant">3600</code> seconds.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>keys</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
A list of keys to use. Each line represents one key. Here is
|
||||
an example (for illustration purposes only) of some possible
|
||||
keys in a <span class="command"><strong>dnssec-policy</strong></span>:
|
||||
</p>
|
||||
|
||||
<pre class="programlisting">keys {
|
||||
ksk key-directory lifetime P5Y algorithm 8 2048;
|
||||
zsk key-directory lifetime P30D algorithm 8;
|
||||
csk key-directory lifetime P6MT12H3M15S algorithm 13;
|
||||
};
|
||||
</pre>
|
||||
|
||||
<p>
|
||||
This example lists three keys. The first token determines
|
||||
what RRsets the key will sign. If set to
|
||||
<strong class="userinput"><code>ksk</code></strong> the key will sign the DNSKEY, CDS,
|
||||
and CDNSKEY RRsets, if set to <strong class="userinput"><code>zsk</code></strong> the
|
||||
key will sign the other RRsets, and if set to
|
||||
<strong class="userinput"><code>csk</code></strong> the key will sign all RRsets.
|
||||
</p>
|
||||
<p>
|
||||
The following part determines where the key will be stored.
|
||||
Currently keys can only be stored in the configured
|
||||
<span class="command"><strong>key-directory</strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
The third token tells how long the key may be used. In the
|
||||
example the first key has a lifetime of 5 years, the second
|
||||
key may be used for 30 days and the third key has a rather
|
||||
peculiar lifetime of 6 months, 12 hours, 3 minutes and 15
|
||||
seconds.
|
||||
</p>
|
||||
<p>
|
||||
The last token(s) are the key's algorithm and algorithm
|
||||
length. The length may be omitted as shown in the
|
||||
example for the second and third key.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>publish-safety</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
A margin that is added to the publish interval in key
|
||||
timing equations to give some extra time to cover
|
||||
unforeseen events. Default is <code class="constant">PT5M</code>
|
||||
(5 minutes).
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>retire-safety</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
A margin that is added to the retire interval in key
|
||||
timing equations to give some extra time to cover
|
||||
unforeseen events. Default is <code class="constant">PT5M</code>
|
||||
(5 minutes).
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>signatures-refresh</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
This determines when a RRSIG record needs to be
|
||||
refreshed. The signatures is renewed when the time until
|
||||
the expiration time is closer than
|
||||
<span class="command"><strong>signatures-refresh</strong></span>.
|
||||
<span class="command"><strong>signatures-resign</strong></span> interval. Default
|
||||
is <code class="constant">P5D</code> (5 days), meaning a signature
|
||||
that will expire in 5 days or sooner will be refreshed.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>signatures-validity</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The validity period of an RRSIG record (minus the
|
||||
inception offset and jitter). Default is
|
||||
<code class="constant">P2W</code> (2 weeks).
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>signatures-validity-dnskey</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Like <span class="command"><strong>signatures-validity</strong></span> but for
|
||||
DNSKEY records. Default is <code class="constant">P2W</code> (2
|
||||
weeks).
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>zone-max-ttl</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Like <span class="command"><strong>max-zone-ttl</strong></span>, specifies the
|
||||
maximum permissible TTL value in seconds. When loading a
|
||||
zone file using a <code class="option">masterfile-format</code> or
|
||||
<code class="constant">text</code> or <code class="constant">raw</code>,
|
||||
any record encountered with a TTL higher than
|
||||
<code class="option">zone-max-ttl</code> will be capped to the
|
||||
maximum permissible TTL value.
|
||||
</p>
|
||||
<p>
|
||||
This is needed in DNSSEC-maintained zones because when
|
||||
rolling to a new DNSKEY, the old key needs to remain
|
||||
available until RRSIG records have expired from caches.
|
||||
The <code class="option">zone-max-ttl</code> option guarantees that
|
||||
the largest TTL in the zone will be no higher than the
|
||||
set value.
|
||||
</p>
|
||||
<p>
|
||||
(NOTE: Because <code class="constant">map</code>-format files
|
||||
load directly into memory, this option cannot be
|
||||
used with them.)
|
||||
</p>
|
||||
<p>
|
||||
The default value is <code class="constant">PT24H</code> (24 hours).
|
||||
A <code class="option">zone-max-ttl</code> of zero is treated as if
|
||||
the default value is in use.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>zone-propagation-delay</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The expected propagation delay from when a zone is
|
||||
updated and when the new version of the zone is served by
|
||||
all its name servers. Default is
|
||||
<code class="constant">PT5M</code> (5 minutes).
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>parent-ds-ttl</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The TTL of the DS RRset that the parent uses. Default is
|
||||
<code class="constant">PT1H</code> (1 hour).
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>parent-propagation-delay</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The expected propagation delay from when the parent zone
|
||||
is updated and when the new version of the parent zone is
|
||||
served by all its name servers. Default is
|
||||
<code class="constant">PT1H</code> (1 hour).
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>parent-registration-delay</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The expected registration delay from when a DS RRset
|
||||
change is requested and when the DS RRset has been
|
||||
updated in the parent zone. Default is
|
||||
<code class="constant">P1D</code> (1 day).
|
||||
</p>
|
||||
</dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="managed-keys"></a><span class="command"><strong>managed-keys</strong></span> Statement Grammar</h3></div></div></div>
|
||||
<pre class="programlisting">
|
||||
<span class="command"><strong>managed-keys</strong></span> { <em class="replaceable"><code>string</code></em> ( static-key
|
||||
| initial-key ) <em class="replaceable"><code>integer</code></em>
|
||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em>
|
||||
<em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated
|
||||
| initial-key | static-ds |
|
||||
<span class="command"><strong>initial-ds</strong></span> ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em>
|
||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated
|
||||
</pre>
|
||||
</div>
|
||||
<div class="section">
|
||||
@@ -9180,6 +9461,7 @@ view "external" {
|
||||
<span class="command"><strong>dnskey-sig-validity</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>dnssec-dnskey-kskonly</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>dnssec-loadkeys-interval</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>dnssec-policy</strong></span> <em class="replaceable"><code>string</code></em>;
|
||||
<span class="command"><strong>dnssec-secure-to-insecure</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>dnssec-update-mode</strong></span> ( maintain | no-resign );
|
||||
<span class="command"><strong>file</strong></span> <em class="replaceable"><code>quoted_string</code></em>;
|
||||
@@ -9195,7 +9477,7 @@ view "external" {
|
||||
<span class="command"><strong>max-records</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-transfer-idle-out</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-transfer-time-out</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-zone-ttl</strong></span> ( unlimited | <em class="replaceable"><code>ttlval</code></em> );
|
||||
<span class="command"><strong>max-zone-ttl</strong></span> ( unlimited | <em class="replaceable"><code>duration</code></em> );
|
||||
<span class="command"><strong>notify</strong></span> ( explicit | master-only | <em class="replaceable"><code>boolean</code></em> );
|
||||
<span class="command"><strong>notify-delay</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>notify-source</strong></span> ( <em class="replaceable"><code>ipv4_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ] [ dscp <em class="replaceable"><code>integer</code></em> ];
|
||||
@@ -9231,6 +9513,7 @@ view "external" {
|
||||
<span class="command"><strong>dnskey-sig-validity</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>dnssec-dnskey-kskonly</strong></span> <em class="replaceable"><code>boolean</code></em>;
|
||||
<span class="command"><strong>dnssec-loadkeys-interval</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>dnssec-policy</strong></span> <em class="replaceable"><code>string</code></em>;
|
||||
<span class="command"><strong>dnssec-update-mode</strong></span> ( maintain | no-resign );
|
||||
<span class="command"><strong>file</strong></span> <em class="replaceable"><code>quoted_string</code></em>;
|
||||
<span class="command"><strong>forward</strong></span> ( first | only );
|
||||
@@ -9386,7 +9669,7 @@ view "external" {
|
||||
<span class="command"><strong>masterfile-style</strong></span> ( full | relative );
|
||||
<span class="command"><strong>masters</strong></span> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key <em class="replaceable"><code>string</code></em> ]; ... };
|
||||
<span class="command"><strong>max-records</strong></span> <em class="replaceable"><code>integer</code></em>;
|
||||
<span class="command"><strong>max-zone-ttl</strong></span> ( unlimited | <em class="replaceable"><code>ttlval</code></em> );
|
||||
<span class="command"><strong>max-zone-ttl</strong></span> ( unlimited | <em class="replaceable"><code>duration</code></em> );
|
||||
<span class="command"><strong>zone-statistics</strong></span> ( full | terse | none | <em class="replaceable"><code>boolean</code></em> );
|
||||
};
|
||||
</pre>
|
||||
@@ -10052,6 +10335,14 @@ view "external" {
|
||||
Usage”</a>.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>dnssec-policy</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The key and signing policy for this zone. Set to
|
||||
<strong class="userinput"><code>"default"</code></strong> if you want to make use
|
||||
of the default policy.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term"><span class="command"><strong>dnssec-update-mode</strong></span></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
@@ -14897,6 +15188,6 @@ HOST-127.EXAMPLE. MX 0 .
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -360,6 +360,6 @@ allow-query { !{ !10/8; any; }; key example; };
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -191,6 +191,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+536
-340
@@ -9,22 +9,22 @@
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
<title>Appendix A. Release Notes</title>
|
||||
<title>Appendix A. Release Notes</title>
|
||||
<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
|
||||
<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
|
||||
<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
|
||||
<link rel="prev" href="Bv9ARM.ch07.html" title="Chapter 7. Troubleshooting">
|
||||
<link rel="next" href="Bv9ARM.ch09.html" title="Appendix B. A Brief History of the DNS and BIND">
|
||||
<link rel="prev" href="Bv9ARM.ch07.html" title="Chapter 7. Troubleshooting">
|
||||
<link rel="next" href="Bv9ARM.ch09.html" title="Appendix B. A Brief History of the DNS and BIND">
|
||||
</head>
|
||||
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
|
||||
<div class="navheader">
|
||||
<table width="100%" summary="Navigation header">
|
||||
<tr><th colspan="3" align="center">Appendix A. Release Notes</th></tr>
|
||||
<tr><th colspan="3" align="center">Appendix A. Release Notes</th></tr>
|
||||
<tr>
|
||||
<td width="20%" align="left">
|
||||
<a accesskey="p" href="Bv9ARM.ch07.html">Prev</a> </td>
|
||||
<th width="60%" align="center"> </th>
|
||||
<td width="20%" align="right"> <a accesskey="n" href="Bv9ARM.ch09.html">Next</a>
|
||||
<a accesskey="p" href="Bv9ARM.ch07.html">Prev</a> </td>
|
||||
<th width="60%" align="center"> </th>
|
||||
<td width="20%" align="right"> <a accesskey="n" href="Bv9ARM.ch09.html">Next</a>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
@@ -36,17 +36,19 @@
|
||||
<div class="toc">
|
||||
<p><b>Table of Contents</b></p>
|
||||
<dl class="toc">
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.5</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.6</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_platforms">Supported Platforms</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_download">Download</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_security">Security Fixes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_features">New Features</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_removed">Removed Features</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_changes">Feature Changes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_bugs">Bug Fixes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.6">Notes for BIND 9.15.6</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.5">Notes for BIND 9.15.5</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.4">Notes for BIND 9.15.4</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.3">Notes for BIND 9.15.3</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.2">Notes for BIND 9.15.2</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.1">Notes for BIND 9.15.1</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.0">Notes for BIND 9.15.0</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_license">License</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#end_of_life">End of Life</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_thanks">Thank You</a></span></dt>
|
||||
@@ -55,7 +57,7 @@
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h2 class="title" style="clear: both">
|
||||
<a name="id-1.9.2"></a>Release Notes for BIND Version 9.15.5</h2></div></div></div>
|
||||
<a name="id-1.9.2"></a>Release Notes for BIND Version 9.15.6</h2></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
@@ -119,362 +121,559 @@
|
||||
<a name="relnotes_download"></a>Download</h3></div></div></div>
|
||||
<p>
|
||||
The latest versions of BIND 9 software can always be found at
|
||||
<a class="link" href="http://www.isc.org/downloads/" target="_top">http://www.isc.org/downloads/</a>.
|
||||
<a class="link" href="https://www.isc.org/download/" target="_top">https://www.isc.org/download/</a>.
|
||||
There you will find additional information about each release,
|
||||
source code, and pre-compiled versions for Microsoft Windows
|
||||
operating systems.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<a name="relnotes-9.15.6"></a>Notes for BIND 9.15.6</h3></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.6-new"></a>New Features</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The TCP client quota set using the <span class="command"><strong>tcp-clients</strong></span>
|
||||
option could be exceeded in some cases. This could lead to
|
||||
exhaustion of file descriptors. This flaw is disclosed in
|
||||
CVE-2018-5743. [GL #615]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
A new asynchronous network communications system based on
|
||||
<span class="command"><strong>libuv</strong></span> is now used by <span class="command"><strong>named</strong></span>
|
||||
for listening for incoming requests and responding to them.
|
||||
This change will make it easier to improve performance and
|
||||
implement new protocol layers (for example, DNS over TLS) in
|
||||
the future. [GL #29]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
In certain configurations, <span class="command"><strong>named</strong></span> could crash
|
||||
with an assertion failure if <span class="command"><strong>nxdomain-redirect</strong></span>
|
||||
was in use and a redirected query resulted in an NXDOMAIN from the
|
||||
cache. This flaw is disclosed in CVE-2019-6467. [GL #880]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
The new <span class="command"><strong>dnssec-policy</strong></span> option allows the
|
||||
configuration key and signing policy (KASP) for zones. This
|
||||
option enables <span class="command"><strong>named</strong></span> to generate new keys
|
||||
as needed and automatically roll both ZSK and KSK keys.
|
||||
(Note that the syntax for this statement differs from the DNSSEC
|
||||
policy used by <span class="command"><strong>dnssec-keymgr</strong></span>.) [GL #1134]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
A race condition could trigger an assertion failure when
|
||||
a large number of incoming packets were being rejected.
|
||||
This flaw is disclosed in CVE-2019-6471. [GL #942]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could crash with an assertion failure
|
||||
if a forwarder returned a referral, rather than resolving the
|
||||
query, when QNAME minimization was enabled. This flaw is
|
||||
disclosed in CVE-2019-6476. [GL #1051]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
A flaw in DNSSEC verification when transferring mirror zones
|
||||
could allow data to be incorrectly marked valid. This flaw
|
||||
is disclosed in CVE-2019-6475. [GL #1252]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
Two new keywords have been added to the
|
||||
<span class="command"><strong>dnssec-keys</strong></span> statement:
|
||||
<span class="command"><strong>initial-ds</strong></span> and <span class="command"><strong>static-ds</strong></span>.
|
||||
These allow the use of trust anchors in DS format instead of
|
||||
DNSKEY format. DS format allows trust anchors to be configured
|
||||
for keys that have not yet been published; this is the format
|
||||
used by IANA when announcing future root keys.
|
||||
</p>
|
||||
<p>
|
||||
As with the <span class="command"><strong>initial-key</strong></span> and
|
||||
<span class="command"><strong>static-key</strong></span> keywords, <span class="command"><strong>initial-ds</strong></span>
|
||||
configures a dynamic trust anchor to be maintained via RFC 5011, and
|
||||
<span class="command"><strong>static-ds</strong></span> configures a permanent trust anchor.
|
||||
</p>
|
||||
<p>
|
||||
(Note: Currently, DNSKEY-format and DS-format trust anchors
|
||||
cannot both be used for the same domain name.) [GL #6] [GL #622]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.6-changes"></a>Feature Changes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
NSEC Aggressive Cache (synth-from-dnssec) has been disabled by default
|
||||
because it was found to have a significant performance impact on the
|
||||
recursive service. The NSEC Aggressive Cache will be enable by default
|
||||
in the future releases. [GL #1265]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The DNSSEC validation code has been refactored for clarity and to
|
||||
reduce code duplication. [GL #622]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.6-security"></a>Security Fixes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
Too many simultaneous pipelined TCP queries could cause
|
||||
resource overuse. We now prevent this by enforcing a limit
|
||||
on the number of simultaneous requests per active connection.
|
||||
This flaw`is disclosed in CVE-2019-6477. [GL #1264]
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_features"></a>New Features</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<a name="relnotes-9.15.5"></a>Notes for BIND 9.15.5</h3></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.5-security"></a>Security Fixes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Added a new command line option to <span class="command"><strong>dig</strong></span>:
|
||||
<span class="command"><strong>+[no]unexpected</strong></span>. By default, <span class="command"><strong>dig</strong></span>
|
||||
won't accept a reply from a source other than the one to which
|
||||
it sent the query. Add the <span class="command"><strong>+unexpected</strong></span> argument
|
||||
to enable it to process replies from unexpected sources.
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> could crash with an assertion failure
|
||||
if a forwarder returned a referral, rather than resolving the
|
||||
query, when QNAME minimization was enabled. This flaw is
|
||||
disclosed in CVE-2019-6476. [GL #1051]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The GeoIP2 API from MaxMind is now supported. Geolocation support
|
||||
will be compiled in by default if the <span class="command"><strong>libmaxminddb</strong></span>
|
||||
library is found at compile time, but can be turned off by using
|
||||
<span class="command"><strong>configure --disable-geoip</strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
The default path to the GeoIP2 databases will be set based
|
||||
on the location of the <span class="command"><strong>libmaxminddb</strong></span> library;
|
||||
for example, if it is in <code class="filename">/usr/local/lib</code>,
|
||||
then the default path will be
|
||||
<code class="filename">/usr/local/share/GeoIP</code>.
|
||||
This value can be overridden in <code class="filename">named.conf</code>
|
||||
using the <span class="command"><strong>geoip-directory</strong></span> option.
|
||||
</p>
|
||||
<p>
|
||||
Some <span class="command"><strong>geoip</strong></span> ACL settings that were available with
|
||||
legacy GeoIP, including searches for <span class="command"><strong>netspeed</strong></span>,
|
||||
<span class="command"><strong>org</strong></span>, and three-letter ISO country codes, will
|
||||
no longer work when using GeoIP2. Supported GeoIP2 database
|
||||
types are <span class="command"><strong>country</strong></span>, <span class="command"><strong>city</strong></span>,
|
||||
<span class="command"><strong>domain</strong></span>, <span class="command"><strong>isp</strong></span>, and
|
||||
<span class="command"><strong>as</strong></span>. All of these databases support both IPv4
|
||||
and IPv6 lookups. [GL #182] [GL #1112]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
A flaw in DNSSEC verification when transferring mirror zones
|
||||
could allow data to be incorrectly marked valid. This flaw
|
||||
is disclosed in CVE-2019-6475. [GL #1252]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes-9.15.4"></a>Notes for BIND 9.15.4</h3></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.4-new"></a>New Features</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
In order to clarify the configuration of DNSSEC keys,
|
||||
the <span class="command"><strong>trusted-keys</strong></span> and
|
||||
<span class="command"><strong>managed-keys</strong></span> statements have been
|
||||
deprecated, and the new <span class="command"><strong>dnssec-keys</strong></span>
|
||||
statement should now be used for both types of key.
|
||||
</p>
|
||||
<p>
|
||||
When used with the keyword <span class="command"><strong>initial-key</strong></span>,
|
||||
<span class="command"><strong>dnssec-keys</strong></span> has the same behavior as
|
||||
<span class="command"><strong>managed-keys</strong></span>, i.e., it configures
|
||||
a trust anchor that is to be maintained via RFC 5011.
|
||||
</p>
|
||||
<p>
|
||||
When used with the new keyword <span class="command"><strong>static-key</strong></span>, it
|
||||
has the same behavior as <span class="command"><strong>trusted-keys</strong></span>,
|
||||
configuring a permanent trust anchor that will not automatically
|
||||
be updated. (This usage is not recommended for the root key.)
|
||||
[GL #6]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
Added a new command line option to <span class="command"><strong>dig</strong></span>:
|
||||
<span class="command"><strong>+[no]unexpected</strong></span>. By default, <span class="command"><strong>dig</strong></span>
|
||||
won't accept a reply from a source other than the one to which
|
||||
it sent the query. Add the <span class="command"><strong>+unexpected</strong></span> argument
|
||||
to enable it to process replies from unexpected sources.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The new <span class="command"><strong>add-soa</strong></span> option specifies whether
|
||||
or not the <span class="command"><strong>response-policy</strong></span> zone's SOA record
|
||||
should be included in the additional section of RPZ responses.
|
||||
[GL #865]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Two new metrics have been added to the
|
||||
<span class="command"><strong>statistics-channel</strong></span> to report DNSSEC
|
||||
signing operations. For each key in each zone, the
|
||||
<span class="command"><strong>dnssec-sign</strong></span> counter indicates the total
|
||||
number of signatures <span class="command"><strong>named</strong></span> has generated
|
||||
using that key since server startup, and the
|
||||
<span class="command"><strong>dnssec-refresh</strong></span> counter indicates how
|
||||
many of those signatures were refreshed during zone
|
||||
maintenance, as opposed to having been generated
|
||||
as a result of a zone update. [GL #513]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<p>
|
||||
<span class="command"><strong>dig</strong></span>, <span class="command"><strong>mdig</strong></span> and
|
||||
<span class="command"><strong>delv</strong></span> can all now take a <span class="command"><strong>+yaml</strong></span>
|
||||
option to print output in a a detailed YAML format. [RT #1145]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.4-bugs"></a>Bug Fixes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
When a <span class="command"><strong>response-policy</strong></span> zone expires, ensure
|
||||
that its policies are removed from the RPZ summary database.
|
||||
[GL #1146]
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes-9.15.3"></a>Notes for BIND 9.15.3</h3></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.3-new"></a>New Features</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
Statistics channel groups are now toggleable. [GL #1030]
|
||||
</p>
|
||||
</li>
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.3-removed"></a>Removed Features</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
DNSSEC Lookaside Validation (DLV) is now obsolete.
|
||||
The <span class="command"><strong>dnssec-lookaside</strong></span> option has been
|
||||
marked as deprecated; when used in <code class="filename">named.conf</code>,
|
||||
it will generate a warning but will otherwise be ignored.
|
||||
All code enabling the use of lookaside validation has been removed
|
||||
from the validator, <span class="command"><strong>delv</strong></span>, and the DNSSEC tools.
|
||||
[GL #7]
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.3-changes"></a>Feature Changes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>dig</strong></span>, <span class="command"><strong>mdig</strong></span> and
|
||||
<span class="command"><strong>delv</strong></span> can all now take a <span class="command"><strong>+yaml</strong></span>
|
||||
option to print output in a a detailed YAML format. [RT #1145]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added and
|
||||
made default. Old non-default HMAC-SHA based DNS Cookie algorithms
|
||||
have been removed, and only the default AES algorithm is being kept
|
||||
for legacy reasons. This change doesn't have any operational impact
|
||||
in most common scenarios. [GL #605]
|
||||
</p>
|
||||
<p>
|
||||
If you are running multiple DNS Servers (different versions of BIND 9
|
||||
or DNS server from multiple vendors) responding from the same IP
|
||||
address (anycast or load-balancing scenarios), you'll have to make
|
||||
sure that all the servers are configured with the same DNS Cookie
|
||||
algorithm and same Server Secret for the best performance.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The information from the <span class="command"><strong>dnssec-signzone</strong></span> and
|
||||
<span class="command"><strong>dnssec-verify</strong></span> commands is now printed to standard
|
||||
output. The standard error output is only used to print warnings and
|
||||
errors, and in case the user requests the signed zone to be printed to
|
||||
standard output with <span class="command"><strong>-f -</strong></span> option. A new
|
||||
configuration option <span class="command"><strong>-q</strong></span> has been added to silence
|
||||
all output on standard output except for the name of the signed zone.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
DS records included in DNS referral messages can now be validated
|
||||
and cached immediately, reducing the number of queries needed for
|
||||
a DNSSEC validation. [GL #964]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.3-bugs"></a>Bug Fixes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Cache database statistics counters could report invalid values
|
||||
when stale answers were enabled, because of a bug in counter
|
||||
maintenance when cache data becomes stale. The statistics counters
|
||||
have been corrected to report the number of RRsets for each
|
||||
RR type that are active, stale but still potentially served,
|
||||
or stale and marked for deletion. [GL #602]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Interaction between DNS64 and RPZ No Data rule (CNAME *.) could
|
||||
cause unexpected results; this has been fixed. [GL #1106]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named-checkconf</strong></span> now checks DNS64 prefixes
|
||||
to ensure bits 64-71 are zero. [GL #1159]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named-checkconf</strong></span> now correctly reports a missing
|
||||
<span class="command"><strong>dnstap-output</strong></span> option when
|
||||
<span class="command"><strong>dnstap</strong></span> is set. [GL #1136]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Handle ETIMEDOUT error on connect() with a non-blocking
|
||||
socket. [GL #1133]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>dig</strong></span> now correctly expands the IPv6 address
|
||||
when run with <span class="command"><strong>+expandaaaa +short</strong></span>. [GL #1152]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_removed"></a>Removed Features</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<a name="relnotes-9.15.2"></a>Notes for BIND 9.15.2</h3></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.2-new"></a>New Features</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>dnssec-enable</strong></span> option has been obsoleted and
|
||||
no longer has any effect. DNSSEC responses are always enabled
|
||||
if signatures and other DNSSEC data are present. [GL #866]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
The GeoIP2 API from MaxMind is now supported. Geolocation support
|
||||
will be compiled in by default if the <span class="command"><strong>libmaxminddb</strong></span>
|
||||
library is found at compile time, but can be turned off by using
|
||||
<span class="command"><strong>configure --disable-geoip</strong></span>.
|
||||
</p>
|
||||
<p>
|
||||
The default path to the GeoIP2 databases will be set based
|
||||
on the location of the <span class="command"><strong>libmaxminddb</strong></span> library;
|
||||
for example, if it is in <code class="filename">/usr/local/lib</code>,
|
||||
then the default path will be
|
||||
<code class="filename">/usr/local/share/GeoIP</code>.
|
||||
This value can be overridden in <code class="filename">named.conf</code>
|
||||
using the <span class="command"><strong>geoip-directory</strong></span> option.
|
||||
</p>
|
||||
<p>
|
||||
Some <span class="command"><strong>geoip</strong></span> ACL settings that were available with
|
||||
legacy GeoIP, including searches for <span class="command"><strong>netspeed</strong></span>,
|
||||
<span class="command"><strong>org</strong></span>, and three-letter ISO country codes, will
|
||||
no longer work when using GeoIP2. Supported GeoIP2 database
|
||||
types are <span class="command"><strong>country</strong></span>, <span class="command"><strong>city</strong></span>,
|
||||
<span class="command"><strong>domain</strong></span>, <span class="command"><strong>isp</strong></span>, and
|
||||
<span class="command"><strong>as</strong></span>. All of these databases support both IPv4
|
||||
and IPv6 lookups. [GL #182] [GL #1112]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>cleaning-interval</strong></span> option has been
|
||||
removed. [GL !1731]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
DNSSEC Lookaside Validation (DLV) is now obsolete.
|
||||
The <span class="command"><strong>dnssec-lookaside</strong></span> option has been
|
||||
marked as deprecated; when used in <code class="filename">named.conf</code>,
|
||||
it will generate a warning but will otherwise be ignored.
|
||||
All code enabling the use of lookaside validation has been removed
|
||||
from the validator, <span class="command"><strong>delv</strong></span>, and the DNSSEC tools.
|
||||
[GL #7]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
Two new metrics have been added to the
|
||||
<span class="command"><strong>statistics-channel</strong></span> to report DNSSEC
|
||||
signing operations. For each key in each zone, the
|
||||
<span class="command"><strong>dnssec-sign</strong></span> counter indicates the total
|
||||
number of signatures <span class="command"><strong>named</strong></span> has generated
|
||||
using that key since server startup, and the
|
||||
<span class="command"><strong>dnssec-refresh</strong></span> counter indicates how
|
||||
many of those signatures were refreshed during zone
|
||||
maintenance, as opposed to having been generated
|
||||
as a result of a zone update. [GL #513]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.2-bugs"></a>Bug Fixes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When <span class="command"><strong>qname-minimization</strong></span> was set to
|
||||
<span class="command"><strong>relaxed</strong></span>, some improperly configured domains
|
||||
would fail to resolve, but would have succeeded when minimization
|
||||
was disabled. <span class="command"><strong>named</strong></span> will now fall back to normal
|
||||
resolution in such cases, and also uses type A rather than NS for
|
||||
minimal queries in order to reduce the likelihood of encountering
|
||||
the problem. [GL #1055]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>./configure</strong></span> no longer sets
|
||||
<span class="command"><strong>--sysconfdir</strong></span> to <span class="command"><strong>/etc</strong></span> or
|
||||
<span class="command"><strong>--localstatedir</strong></span> to <span class="command"><strong>/var</strong></span>
|
||||
when <span class="command"><strong>--prefix</strong></span> is not specified and the
|
||||
aforementioned options are not specified explicitly. Instead,
|
||||
Autoconf's defaults of <span class="command"><strong>$prefix/etc</strong></span> and
|
||||
<span class="command"><strong>$prefix/var</strong></span> are respected.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Glue address records were not being returned in responses
|
||||
to root priming queries; this has been corrected. [GL #1092]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<a name="relnotes-9.15.1"></a>Notes for BIND 9.15.1</h3></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.1-security"></a>Security Fixes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
A race condition could trigger an assertion failure when
|
||||
a large number of incoming packets were being rejected.
|
||||
This flaw is disclosed in CVE-2019-6471. [GL #942]
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.1-new"></a>New Features</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
In order to clarify the configuration of DNSSEC keys,
|
||||
the <span class="command"><strong>trusted-keys</strong></span> and
|
||||
<span class="command"><strong>managed-keys</strong></span> statements have been
|
||||
deprecated, and the new <span class="command"><strong>dnssec-keys</strong></span>
|
||||
statement should now be used for both types of key.
|
||||
</p>
|
||||
<p>
|
||||
When used with the keyword <span class="command"><strong>initial-key</strong></span>,
|
||||
<span class="command"><strong>dnssec-keys</strong></span> has the same behavior as
|
||||
<span class="command"><strong>managed-keys</strong></span>, i.e., it configures
|
||||
a trust anchor that is to be maintained via RFC 5011.
|
||||
</p>
|
||||
<p>
|
||||
When used with the new keyword <span class="command"><strong>static-key</strong></span>, it
|
||||
has the same behavior as <span class="command"><strong>trusted-keys</strong></span>,
|
||||
configuring a permanent trust anchor that will not automatically
|
||||
be updated. (This usage is not recommended for the root key.)
|
||||
[GL #6]
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.1-removed"></a>Removed Features</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>cleaning-interval</strong></span> option has been
|
||||
removed. [GL !1731]
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.1-changes"></a>Feature Changes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> will now log a warning if
|
||||
a static key is configured for the root zone. [GL #6]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
<span class="command"><strong>named</strong></span> will now log a warning if
|
||||
a static key is configured for the root zone. [GL #6]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When static and managed DNSSEC keys were both configured for the
|
||||
same name, or when a static key was used to
|
||||
configure a trust anchor for the root zone and
|
||||
<span class="command"><strong>dnssec-validation</strong></span> was set to the default
|
||||
value of <code class="literal">auto</code>, automatic RFC 5011 key
|
||||
rollovers would be disabled. This combination of settings was
|
||||
never intended to work, but there was no check for it in the
|
||||
parser. This has been corrected, and it is now a fatal
|
||||
configuration error. [GL #868]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
DS and CDS records are now generated with SHA-256 digests
|
||||
only, instead of both SHA-1 and SHA-256. This affects the
|
||||
default output of <span class="command"><strong>dnssec-dsfromkey</strong></span>, the
|
||||
<code class="filename">dsset</code> files generated by
|
||||
<span class="command"><strong>dnssec-signzone</strong></span>, the DS records added to
|
||||
a zone by <span class="command"><strong>dnssec-signzone</strong></span> based on
|
||||
<code class="filename">keyset</code> files, the CDS records added to
|
||||
a zone by <span class="command"><strong>named</strong></span> and
|
||||
<span class="command"><strong>dnssec-signzone</strong></span> based on "sync" timing
|
||||
parameters in key files, and the checks performed by
|
||||
<span class="command"><strong>dnssec-checkds</strong></span>.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
JSON-C is now the only supported library for enabling JSON
|
||||
support for BIND statistics. The <span class="command"><strong>configure</strong></span>
|
||||
option has been renamed from <span class="command"><strong>--with-libjson</strong></span>
|
||||
to <span class="command"><strong>--with-json-c</strong></span>. Use
|
||||
<span class="command"><strong>PKG_CONFIG_PATH</strong></span> to specify a custom path to
|
||||
the <span class="command"><strong>json-c</strong></span> library as the new
|
||||
<span class="command"><strong>configure</strong></span> option does not take the library
|
||||
installation path as an optional argument.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added and
|
||||
made default. Old non-default HMAC-SHA based DNS Cookie algorithms
|
||||
have been removed, and only the default AES algorithm is being kept
|
||||
for legacy reasons. This change doesn't have any operational impact
|
||||
in most common scenarios. [GL #605]
|
||||
</p>
|
||||
<p>
|
||||
If you are running multiple DNS Servers (different versions of BIND 9
|
||||
or DNS server from multiple vendors) responding from the same IP
|
||||
address (anycast or load-balancing scenarios), you'll have to make
|
||||
sure that all the servers are configured with the same DNS Cookie
|
||||
algorithm and same Server Secret for the best performance.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The information from the <span class="command"><strong>dnssec-signzone</strong></span> and
|
||||
<span class="command"><strong>dnssec-verify</strong></span> commands is now printed to standard
|
||||
output. The standard error output is only used to print warnings and
|
||||
errors, and in case the user requests the signed zone to be printed to
|
||||
standard output with <span class="command"><strong>-f -</strong></span> option. A new
|
||||
configuration option <span class="command"><strong>-q</strong></span> has been added to silence
|
||||
all output on standard output except for the name of the signed zone.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
DS records included in DNS referral messages can now be validated
|
||||
and cached immediately, reducing the number of queries needed for
|
||||
a DNSSEC validation. [GL #964]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
JSON-C is now the only supported library for enabling JSON
|
||||
support for BIND statistics. The <span class="command"><strong>configure</strong></span>
|
||||
option has been renamed from <span class="command"><strong>--with-libjson</strong></span>
|
||||
to <span class="command"><strong>--with-json-c</strong></span>. Use
|
||||
<span class="command"><strong>PKG_CONFIG_PATH</strong></span> to specify a custom path to
|
||||
the <span class="command"><strong>json-c</strong></span> library as the new
|
||||
<span class="command"><strong>configure</strong></span> option does not take the library
|
||||
installation path as an optional argument.
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<a name="relnotes-9.15.0"></a>Notes for BIND 9.15.0</h3></div></div></div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.0-security"></a>Security Fixes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>allow-update</strong></span> and
|
||||
<span class="command"><strong>allow-update-forwarding</strong></span> options were
|
||||
inadvertently treated as configuration errors when used at the
|
||||
<span class="command"><strong>options</strong></span> or <span class="command"><strong>view</strong></span> level.
|
||||
This has now been corrected.
|
||||
[GL #913]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
In certain configurations, <span class="command"><strong>named</strong></span> could crash
|
||||
with an assertion failure if <span class="command"><strong>nxdomain-redirect</strong></span>
|
||||
was in use and a redirected query resulted in an NXDOMAIN from the
|
||||
cache. This flaw is disclosed in CVE-2019-6467. [GL #880]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When <span class="command"><strong>qname-minimization</strong></span> was set to
|
||||
<span class="command"><strong>relaxed</strong></span>, some improperly configured domains
|
||||
would fail to resolve, but would have succeeded when minimization
|
||||
was disabled. <span class="command"><strong>named</strong></span> will now fall back to normal
|
||||
resolution in such cases, and also uses type A rather than NS for
|
||||
minimal queries in order to reduce the likelihood of encountering
|
||||
the problem. [GL #1055]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>./configure</strong></span> no longer sets
|
||||
<span class="command"><strong>--sysconfdir</strong></span> to <span class="command"><strong>/etc</strong></span> or
|
||||
<span class="command"><strong>--localstatedir</strong></span> to <span class="command"><strong>/var</strong></span>
|
||||
when <span class="command"><strong>--prefix</strong></span> is not specified and the
|
||||
aforementioned options are not specified explicitly. Instead,
|
||||
Autoconf's defaults of <span class="command"><strong>$prefix/etc</strong></span> and
|
||||
<span class="command"><strong>$prefix/var</strong></span> are respected.
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Glue address records were not being returned in responses
|
||||
to root priming queries; this has been corrected. [GL #1092]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Interaction between DNS64 and RPZ No Data rule (CNAME *.) could
|
||||
cause unexpected results; this has been fixed. [GL #1106]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named-checkconf</strong></span> now checks DNS64 prefixes
|
||||
to ensure bits 64-71 are zero. [GL #1159]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>named-checkconf</strong></span> now correctly reports a missing
|
||||
<span class="command"><strong>dnstap-output</strong></span> option when
|
||||
<span class="command"><strong>dnstap</strong></span> is set. [GL #1136]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Handle ETIMEDOUT error on connect() with a non-blocking
|
||||
socket. [GL #1133]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
Cache database statistics counters could report invalid values
|
||||
when stale answers were enabled, because of a bug in counter
|
||||
maintenance when cache data becomes stale. The statistics counters
|
||||
have been corrected to report the number of RRsets for each
|
||||
RR type that are active, stale but still potentially served,
|
||||
or stale and marked for deletion. [GL #602]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
<span class="command"><strong>dig</strong></span> now correctly expands the IPv6 address
|
||||
when run with <span class="command"><strong>+expandaaaa +short</strong></span>. [GL #1152]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When a <span class="command"><strong>response-policy</strong></span> zone expires, ensure
|
||||
that its policies are removed from the RPZ summary database.
|
||||
[GL #1146]
|
||||
</p>
|
||||
</li>
|
||||
<p>
|
||||
The TCP client quota set using the <span class="command"><strong>tcp-clients</strong></span>
|
||||
option could be exceeded in some cases. This could lead to
|
||||
exhaustion of file descriptors. This flaw is disclosed in
|
||||
CVE-2018-5743. [GL #615]
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.0-new"></a>New Features</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
The new <span class="command"><strong>add-soa</strong></span> option specifies whether
|
||||
or not the <span class="command"><strong>response-policy</strong></span> zone's SOA record
|
||||
should be included in the additional section of RPZ responses.
|
||||
[GL #865]
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.0-removed"></a>Removed Features</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>dnssec-enable</strong></span> option has been obsoleted and
|
||||
no longer has any effect. DNSSEC responses are always enabled
|
||||
if signatures and other DNSSEC data are present. [GL #866]
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.0-changes"></a>Feature Changes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
|
||||
<li class="listitem">
|
||||
<p>
|
||||
When static and managed DNSSEC keys were both configured for the
|
||||
same name, or when a static key was used to
|
||||
configure a trust anchor for the root zone and
|
||||
<span class="command"><strong>dnssec-validation</strong></span> was set to the default
|
||||
value of <code class="literal">auto</code>, automatic RFC 5011 key
|
||||
rollovers would be disabled. This combination of settings was
|
||||
never intended to work, but there was no check for it in the
|
||||
parser. This has been corrected, and it is now a fatal
|
||||
configuration error. [GL #868]
|
||||
</p>
|
||||
</li>
|
||||
<li class="listitem">
|
||||
<p>
|
||||
DS and CDS records are now generated with SHA-256 digests
|
||||
only, instead of both SHA-1 and SHA-256. This affects the
|
||||
default output of <span class="command"><strong>dnssec-dsfromkey</strong></span>, the
|
||||
<code class="filename">dsset</code> files generated by
|
||||
<span class="command"><strong>dnssec-signzone</strong></span>, the DS records added to
|
||||
a zone by <span class="command"><strong>dnssec-signzone</strong></span> based on
|
||||
<code class="filename">keyset</code> files, the CDS records added to
|
||||
a zone by <span class="command"><strong>named</strong></span> and
|
||||
<span class="command"><strong>dnssec-signzone</strong></span> based on "sync" timing
|
||||
parameters in key files, and the checks performed by
|
||||
<span class="command"><strong>dnssec-checkds</strong></span>.
|
||||
</p>
|
||||
</li>
|
||||
</ul></div>
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h4 class="title">
|
||||
<a name="relnotes-9.15.0-bugs"></a>Bug Fixes</h4></div></div></div>
|
||||
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
|
||||
<p>
|
||||
The <span class="command"><strong>allow-update</strong></span> and
|
||||
<span class="command"><strong>allow-update-forwarding</strong></span> options were
|
||||
inadvertently treated as configuration errors when used at the
|
||||
<span class="command"><strong>options</strong></span> or <span class="command"><strong>view</strong></span> level.
|
||||
This has now been corrected.
|
||||
[GL #913]
|
||||
</p>
|
||||
</li></ul></div>
|
||||
</div>
|
||||
|
||||
</div>
|
||||
|
||||
<div class="section">
|
||||
<div class="titlepage"><div><div><h3 class="title">
|
||||
<a name="relnotes_license"></a>License</h3></div></div></div>
|
||||
@@ -511,7 +710,7 @@
|
||||
For those needing long term support, the current Extended Support
|
||||
Version (ESV) is BIND 9.11, which will be supported until at
|
||||
least December 2021. See
|
||||
<a class="link" href="https://www.isc.org/downloads/software-support-policy/" target="_top">https://www.isc.org/downloads/software-support-policy/</a>
|
||||
<a class="link" href="https://kb.isc.org/docs/aa-00896" target="_top">https://kb.isc.org/docs/aa-00896</a>
|
||||
for details of ISC's software support policy.
|
||||
</p>
|
||||
</div>
|
||||
@@ -520,9 +719,6 @@
|
||||
<a name="relnotes_thanks"></a>Thank You</h3></div></div></div>
|
||||
<p>
|
||||
Thank you to everyone who assisted us in making this release possible.
|
||||
If you would like to contribute to ISC to assist us in continuing to
|
||||
make quality open source software, please visit our donations page at
|
||||
<a class="link" href="http://www.isc.org/donate/" target="_top">http://www.isc.org/donate/</a>.
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
@@ -532,19 +728,19 @@
|
||||
<table width="100%" summary="Navigation footer">
|
||||
<tr>
|
||||
<td width="40%" align="left">
|
||||
<a accesskey="p" href="Bv9ARM.ch07.html">Prev</a> </td>
|
||||
<td width="20%" align="center"> </td>
|
||||
<td width="40%" align="right"> <a accesskey="n" href="Bv9ARM.ch09.html">Next</a>
|
||||
<a accesskey="p" href="Bv9ARM.ch07.html">Prev</a> </td>
|
||||
<td width="20%" align="center"> </td>
|
||||
<td width="40%" align="right"> <a accesskey="n" href="Bv9ARM.ch09.html">Next</a>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td width="40%" align="left" valign="top">Chapter 7. Troubleshooting </td>
|
||||
<td width="40%" align="left" valign="top">Chapter 7. Troubleshooting </td>
|
||||
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
|
||||
<td width="40%" align="right" valign="top"> Appendix B. A Brief History of the <acronym class="acronym">DNS</acronym> and <acronym class="acronym">BIND</acronym>
|
||||
<td width="40%" align="right" valign="top"> Appendix B. A Brief History of the <acronym class="acronym">DNS</acronym> and <acronym class="acronym">BIND</acronym>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -148,6 +148,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -914,6 +914,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -176,7 +176,8 @@ $ <strong class="userinput"><code>make</code></strong>
|
||||
<code class="filename">named.conf</code>, except that all
|
||||
<span class="command"><strong>managed-keys</strong></span> entries will be treated as
|
||||
if they were configured with the <span class="command"><strong>static-key</strong></span>
|
||||
keyword, even if they are configured with <span class="command"><strong>initial-key</strong></span>.
|
||||
or <span class="command"><strong>static-ds</strong></span> keywords, even if they are configured
|
||||
with <span class="command"><strong>initial-key</strong></span> or <span class="command"><strong>iniital-ds</strong></span>.
|
||||
(See <a class="xref" href="Bv9ARM.ch05.html#managed-keys" title="managed-keys Statement Grammar">the section called “<span class="command"><strong>managed-keys</strong></span> Statement Grammar”</a> for syntax details.)
|
||||
</p>
|
||||
</div>
|
||||
@@ -537,6 +538,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -210,6 +210,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+25
-20
@@ -32,7 +32,7 @@
|
||||
<div>
|
||||
<div><h1 class="title">
|
||||
<a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
|
||||
<div><p class="releaseinfo">BIND Version 9.15.5</p></div>
|
||||
<div><p class="releaseinfo">BIND Version 9.15.6</p></div>
|
||||
<div><p class="copyright">Copyright © 2000-2019 Internet Systems Consortium, Inc. ("ISC")</p></div>
|
||||
</div>
|
||||
<hr>
|
||||
@@ -109,18 +109,18 @@
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#dnssec.dynamic.zones">DNSSEC, Dynamic Zones, and Automatic Signing</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.2">Converting from insecure to secure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.7">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.15">Fully automatic zone signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.24">Private-type records</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.31">DNSKEY rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.33">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.38">Automatic key rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.40">NSEC3PARAM rollovers via UPDATE</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.42">Converting from NSEC to NSEC3</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.44">Converting from NSEC3 to NSEC</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.46">Converting from secure to insecure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.50">Periodic re-signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.52">NSEC3 and OPTOUT</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.9">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.17">Fully automatic zone signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.27">Private-type records</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.34">DNSKEY rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.36">Dynamic DNS update method</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.41">Automatic key rollovers</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.43">NSEC3PARAM rollovers via UPDATE</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.45">Converting from NSEC to NSEC3</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.48">Converting from NSEC3 to NSEC</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.50">Converting from secure to insecure</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.54">Periodic re-signing</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.56">NSEC3 and OPTOUT</a></span></dt>
|
||||
</dl></dd>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch04.html#rfc5011.support">Dynamic Trust Anchor Management</a></span></dt>
|
||||
<dd><dl>
|
||||
@@ -195,6 +195,9 @@
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_keys"><span class="command"><strong>dnssec-keys</strong></span> Statement Grammar</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec-keys"><span class="command"><strong>dnssec-keys</strong></span> Statement Definition
|
||||
and Usage</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy_grammar"><span class="command"><strong>dnssec-policy</strong></span> Statement Grammar</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#dnssec_policy"><span class="command"><strong>dnssec-policy</strong></span> Statement Definition
|
||||
and Usage</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#managed-keys"><span class="command"><strong>managed-keys</strong></span> Statement Grammar</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch05.html#managed_keys"><span class="command"><strong>managed-keys</strong></span> Statement Definition
|
||||
and Usage</a></span></dt>
|
||||
@@ -245,17 +248,19 @@
|
||||
</dl></dd>
|
||||
<dt><span class="appendix"><a href="Bv9ARM.ch08.html">A. Release Notes</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.5</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.6</a></span></dt>
|
||||
<dd><dl>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_platforms">Supported Platforms</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_download">Download</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_security">Security Fixes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_features">New Features</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_removed">Removed Features</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_changes">Feature Changes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_bugs">Bug Fixes</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.6">Notes for BIND 9.15.6</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.5">Notes for BIND 9.15.5</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.4">Notes for BIND 9.15.4</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.3">Notes for BIND 9.15.3</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.2">Notes for BIND 9.15.2</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.1">Notes for BIND 9.15.1</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.15.0">Notes for BIND 9.15.0</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_license">License</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#end_of_life">End of Life</a></span></dt>
|
||||
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_thanks">Thank You</a></span></dt>
|
||||
@@ -443,6 +448,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
Binary file not shown.
@@ -13,6 +13,7 @@
|
||||
|
||||
<programlisting>
|
||||
<command>dnssec-keys</command> { <replaceable>string</replaceable> ( static-key |
|
||||
<command>initial-key</command> ) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||
<command>initial-key</command> | static-ds | initial-ds )
|
||||
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||
<replaceable>quoted_string</replaceable>; ... };
|
||||
</programlisting>
|
||||
|
||||
+2
-1
@@ -138,7 +138,8 @@ $ <userinput>make</userinput>
|
||||
<filename>named.conf</filename>, except that all
|
||||
<command>managed-keys</command> entries will be treated as
|
||||
if they were configured with the <command>static-key</command>
|
||||
keyword, even if they are configured with <command>initial-key</command>.
|
||||
or <command>static-ds</command> keywords, even if they are configured
|
||||
with <command>initial-key</command> or <command>iniital-ds</command>.
|
||||
(See <xref linkend="managed-keys"/> for syntax details.)
|
||||
</para>
|
||||
</section>
|
||||
|
||||
@@ -90,6 +90,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -220,6 +220,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -621,6 +621,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -1188,6 +1188,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -376,6 +376,6 @@ nsupdate -l
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
@@ -156,6 +156,6 @@
|
||||
</tr>
|
||||
</table>
|
||||
</div>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
|
||||
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.6 (Development Release)</p>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user