Compare commits
652
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
92eb269a7d | ||
|
|
9a4e4fde31 | ||
|
|
b6c25c0f00 | ||
|
|
3f19388210 | ||
|
|
30bdd05727 | ||
|
|
b7aac20168 | ||
|
|
b1db9d5325 | ||
|
|
7f4a8bf853 | ||
|
|
2f9e77b2ee | ||
|
|
9fb6709515 | ||
|
|
a628172de2 | ||
|
|
650900f2e9 | ||
|
|
3fc5214464 | ||
|
|
b2d93928af | ||
|
|
e610325783 | ||
|
|
fe24b48e9f | ||
|
|
ded06dc3c5 | ||
|
|
1d802a23a1 | ||
|
|
39645122da | ||
|
|
3d9763b968 | ||
|
|
b6d9add750 | ||
|
|
f71e673751 | ||
|
|
2873ad7f46 | ||
|
|
41cec3a619 | ||
|
|
8a7bfc8850 | ||
|
|
ecb619b71c | ||
|
|
c0bf9b9e26 | ||
|
|
7fae1ef12b | ||
|
|
2f694f0b77 | ||
|
|
67d245d965 | ||
|
|
e6c5ecd698 | ||
|
|
aea824f16e | ||
|
|
a9a9aa7fd8 | ||
|
|
b378d0371f | ||
|
|
a787bc0b14 | ||
|
|
be3a11029a | ||
|
|
5214f24d7b | ||
|
|
7f0fcb8a3e | ||
|
|
dd6598f391 | ||
|
|
891f24fa57 | ||
|
|
fccf65a585 | ||
|
|
bf7a99a3c1 | ||
|
|
7ba1af0280 | ||
|
|
714594d468 | ||
|
|
44b08521ef | ||
|
|
0312e73e16 | ||
|
|
d64921848d | ||
|
|
2e189bb053 | ||
|
|
1b1a94ea6d | ||
|
|
8456b5627d | ||
|
|
e4d08c0232 | ||
|
|
b6c3a2f172 | ||
|
|
1efc7550a3 | ||
|
|
5fc9efba30 | ||
|
|
aa101260d9 | ||
|
|
0be2dc9f22 | ||
|
|
331b74d6bf | ||
|
|
a038f77d92 | ||
|
|
d162bbcceb | ||
|
|
a9bd6f6ea6 | ||
|
|
9943c5dce5 | ||
|
|
2c0c333d16 | ||
|
|
830d40b36e | ||
|
|
7135ef78ee | ||
|
|
37b41ff693 | ||
|
|
3079956ff7 | ||
|
|
59a1e5564d | ||
|
|
99ed3a0e13 | ||
|
|
a9c1fffba0 | ||
|
|
b8be29fee6 | ||
|
|
2868eafc46 | ||
|
|
c00def343f | ||
|
|
05ae2e48ab | ||
|
|
478e4ac201 | ||
|
|
bb65e57297 | ||
|
|
d6de520bd1 | ||
|
|
704b9ee9d0 | ||
|
|
c65c06301c | ||
|
|
f17b9b8dd1 | ||
|
|
7b948c7335 | ||
|
|
6c2e138d7a | ||
|
|
668a972d1e | ||
|
|
dfd96e1aa5 | ||
|
|
7a002c7ece | ||
|
|
fc4e44bd37 | ||
|
|
8745043a86 | ||
|
|
dba0163dac | ||
|
|
9f6e0dc945 | ||
|
|
c73e5866c4 | ||
|
|
d5f682a00b | ||
|
|
4459745ff2 | ||
|
|
9286548c7e | ||
|
|
5eb3f71a3e | ||
|
|
33328871a7 | ||
|
|
de123a67d6 | ||
|
|
1248f05ae8 | ||
|
|
8ceaf28442 | ||
|
|
2ec5b852df | ||
|
|
02c2fc5ad3 | ||
|
|
7c0d9dac9f | ||
|
|
d159fdf25d | ||
|
|
68a360772f | ||
|
|
379949cce4 | ||
|
|
272a31f758 | ||
|
|
279f6b01de | ||
|
|
a09c464a20 | ||
|
|
f91b3a69ce | ||
|
|
0adb4b25d3 | ||
|
|
77332eb2c8 | ||
|
|
a8836b381f | ||
|
|
4f9bfe1460 | ||
|
|
7b0ba6eb10 | ||
|
|
6adcd739ca | ||
|
|
0147acd7b6 | ||
|
|
e48b2424aa | ||
|
|
784e64f238 | ||
|
|
ed52ffba38 | ||
|
|
9b6df37303 | ||
|
|
4a992c7a18 | ||
|
|
a1a5559a8a | ||
|
|
f3f7b7df5d | ||
|
|
7443bd5cc7 | ||
|
|
c6ba51cfc4 | ||
|
|
82c418abfa | ||
|
|
b3f06729e5 | ||
|
|
a2254f01c4 | ||
|
|
42e1fb8322 | ||
|
|
7417b79c7a | ||
|
|
85555f29d7 | ||
|
|
754f7588c6 | ||
|
|
20b446cdc3 | ||
|
|
1f3502f564 | ||
|
|
b5cfc1c056 | ||
|
|
43279de8e6 | ||
|
|
7a605b4d05 | ||
|
|
5b448996e5 | ||
|
|
9643a62dd5 | ||
|
|
7c3f419d66 | ||
|
|
8b159c33ac | ||
|
|
9e6f6156f7 | ||
|
|
8648b7cdb2 | ||
|
|
796b38fe0c | ||
|
|
78a6b2689b | ||
|
|
741bc11bdb | ||
|
|
4a26f7d149 | ||
|
|
27a9be3034 | ||
|
|
bb061abbb9 | ||
|
|
63b702d0d0 | ||
|
|
1beba0fa59 | ||
|
|
e1c4a69197 | ||
|
|
684a44b469 | ||
|
|
0cd10c7763 | ||
|
|
4227b7969b | ||
|
|
ccf7bbab5d | ||
|
|
3b1bd3f48b | ||
|
|
aafb804eb8 | ||
|
|
05c6a29c87 | ||
|
|
6d8d06e82e | ||
|
|
fd8788eb94 | ||
|
|
42f0e25a4c | ||
|
|
8d6dc8613a | ||
|
|
dcc0835a3a | ||
|
|
f75a9e32be | ||
|
|
16908ec3d9 | ||
|
|
402f067fc0 | ||
|
|
938fc81493 | ||
|
|
df709dcf8a | ||
|
|
05f2ba973f | ||
|
|
9c5547b118 | ||
|
|
451484b870 | ||
|
|
aac8736998 | ||
|
|
05f2241fcb | ||
|
|
48989e9426 | ||
|
|
1af6de6b62 | ||
|
|
95c76e537f | ||
|
|
e19819457b | ||
|
|
8b9a3314b1 | ||
|
|
fa04c87578 | ||
|
|
6a1c41143f | ||
|
|
4c1adf96de | ||
|
|
eda4300bbb | ||
|
|
0d637b5985 | ||
|
|
1bee87a364 | ||
|
|
525c583145 | ||
|
|
0cf47ed363 | ||
|
|
ea7cc30f7c | ||
|
|
493b6a9f33 | ||
|
|
1639dc8dca | ||
|
|
fc36798a81 | ||
|
|
72b3b458d3 | ||
|
|
6799a222d1 | ||
|
|
2d249ebeae | ||
|
|
678e2d3cfa | ||
|
|
b984a4b647 | ||
|
|
7fdf40770f | ||
|
|
21d3f66f1c | ||
|
|
8f902a72ff | ||
|
|
fc9c7025bc | ||
|
|
4f74e75632 | ||
|
|
3000f14eba | ||
|
|
4d1e3b1e10 | ||
|
|
ede2208d96 | ||
|
|
c4aec79079 | ||
|
|
49976947ab | ||
|
|
a910b0a839 | ||
|
|
64e2331843 | ||
|
|
6afa99362a | ||
|
|
e711b0304f | ||
|
|
7c3e342935 | ||
|
|
9ce3254a1b | ||
|
|
7dfc092f06 | ||
|
|
5208505f03 | ||
|
|
fbf9856f43 | ||
|
|
4643ee04bd | ||
|
|
b665ce2a96 | ||
|
|
6ee1461cc3 | ||
|
|
0d4d65e7f2 | ||
|
|
b3c1b2a869 | ||
|
|
649a34d628 | ||
|
|
5e74550740 | ||
|
|
6ad0133156 | ||
|
|
c3ed086cf0 | ||
|
|
5234a8e00a | ||
|
|
90a1dabe74 | ||
|
|
80a5c9f5c8 | ||
|
|
a4ec0ccb91 | ||
|
|
7a7b09fee6 | ||
|
|
20c077afc5 | ||
|
|
e38004457c | ||
|
|
67c1ca9a79 | ||
|
|
c6c0a9fdba | ||
|
|
ab1adcca98 | ||
|
|
3526c73062 | ||
|
|
7787de80ca | ||
|
|
aa96ec25c8 | ||
|
|
ec8334fb74 | ||
|
|
8797d8ad08 | ||
|
|
72f0e01f5d | ||
|
|
423a627946 | ||
|
|
42384f367a | ||
|
|
6056efc3ce | ||
|
|
2eaab4042b | ||
|
|
c17783b99e | ||
|
|
343c6d357c | ||
|
|
933df7b31c | ||
|
|
136dcfd692 | ||
|
|
98136164aa | ||
|
|
afc4867e99 | ||
|
|
4f7d1298a8 | ||
|
|
84b557e7cb | ||
|
|
5b600c2cd8 | ||
|
|
b1b1bae9c1 | ||
|
|
bebf353eb5 | ||
|
|
6acbd31bd4 | ||
|
|
ea7bddb4ca | ||
|
|
423eee834a | ||
|
|
640dd566e9 | ||
|
|
fb2f98a9a1 | ||
|
|
17deac8b8e | ||
|
|
91e1981988 | ||
|
|
255134166c | ||
|
|
3bce0c2c20 | ||
|
|
2dc4d72fa9 | ||
|
|
cd17b773b1 | ||
|
|
13fa80ede8 | ||
|
|
e3d8732548 | ||
|
|
05aa45c602 | ||
|
|
9bd6720f58 | ||
|
|
46982b414b | ||
|
|
2c38dd5474 | ||
|
|
935a2ae33f | ||
|
|
db9ad43294 | ||
|
|
6a94e6ba73 | ||
|
|
fc0fe4c5a7 | ||
|
|
56f388cae1 | ||
|
|
b2f3eaf188 | ||
|
|
2d00143ab1 | ||
|
|
996c1d3727 | ||
|
|
2df13f79ef | ||
|
|
993633ad96 | ||
|
|
848c1c8b8b | ||
|
|
7278f2529a | ||
|
|
39780ae54f | ||
|
|
d26e125438 | ||
|
|
bff83b9480 | ||
|
|
6012479419 | ||
|
|
9d8f9cc8f2 | ||
|
|
dafb1eb8bb | ||
|
|
41d827893e | ||
|
|
3352a38da4 | ||
|
|
b218bf5227 | ||
|
|
f8ec2140be | ||
|
|
2f2bc03b2d | ||
|
|
85f3476894 | ||
|
|
e6d7384c0d | ||
|
|
0b7339ac6e | ||
|
|
17d25dbf47 | ||
|
|
c2421a1ec3 | ||
|
|
5746172da3 | ||
|
|
de42a7aa9f | ||
|
|
67bac2bcd9 | ||
|
|
e088272172 | ||
|
|
a3dc02103a | ||
|
|
8c48c4f738 | ||
|
|
114520425c | ||
|
|
ed9853e739 | ||
|
|
ead7b3dc53 | ||
|
|
74082abba0 | ||
|
|
d5b6db3b09 | ||
|
|
d35739d516 | ||
|
|
6f3fdf36b4 | ||
|
|
62abb6aa82 | ||
|
|
a6f2d6191e | ||
|
|
ad12c2f3b0 | ||
|
|
80c476721c | ||
|
|
cf48e8eb32 | ||
|
|
8536d740f1 | ||
|
|
c428479d6d | ||
|
|
448ada561d | ||
|
|
b6960da6c8 | ||
|
|
7ee4ff6182 | ||
|
|
7aa77038bd | ||
|
|
94bddd2ce3 | ||
|
|
e792d01e00 | ||
|
|
53858d4afd | ||
|
|
88497a59cc | ||
|
|
b0f7351820 | ||
|
|
922a2ae44a | ||
|
|
5a4a6b5e91 | ||
|
|
2b1c8c54d1 | ||
|
|
12564928a7 | ||
|
|
8d56749046 | ||
|
|
c0be772ebc | ||
|
|
925ecb0aae | ||
|
|
eee162257c | ||
|
|
075613aea4 | ||
|
|
48ece3bb9d | ||
|
|
0ee0580fc9 | ||
|
|
37fe7c5269 | ||
|
|
13aaeaa06f | ||
|
|
5589748eca | ||
|
|
03ed64c251 | ||
|
|
1fa0deb4ea | ||
|
|
71fe7d3c25 | ||
|
|
3248de7785 | ||
|
|
977f334648 | ||
|
|
fd52417f71 | ||
|
|
ac564683cf | ||
|
|
2ee7ff23ce | ||
|
|
dbbfcdc1f7 | ||
|
|
52773e226a | ||
|
|
ec80c7b576 | ||
|
|
ccd44b69e5 | ||
|
|
01481dee1c | ||
|
|
83e54f906d | ||
|
|
31b3980ef0 | ||
|
|
8c0792723d | ||
|
|
35679aef9b | ||
|
|
a34ced776e | ||
|
|
86a847314a | ||
|
|
b804d3a395 | ||
|
|
b0779cc429 | ||
|
|
ef2dff5c7a | ||
|
|
c7b86d1cac | ||
|
|
3e66b7ba1c | ||
|
|
23ab349bbd | ||
|
|
0bf74ac792 | ||
|
|
b05194160b | ||
|
|
8c5aaacbef | ||
|
|
5a65ec0aff | ||
|
|
bc5aae1579 | ||
|
|
09c2dbffb5 | ||
|
|
c6efc0e50f | ||
|
|
176b23b6cd | ||
|
|
23e29b17db | ||
|
|
eb8007a5ba | ||
|
|
2a65a47f39 | ||
|
|
fb03edacd8 | ||
|
|
0e15cbb092 | ||
|
|
10f4cd066f | ||
|
|
64df488e1e | ||
|
|
12578b9e96 | ||
|
|
8885fd6966 | ||
|
|
9e8cd3ccc5 | ||
|
|
6ff780db5b | ||
|
|
2e7cb4978f | ||
|
|
910a7a56bc | ||
|
|
bd4035900a | ||
|
|
2e4273b55a | ||
|
|
cfaa631f65 | ||
|
|
6b4a17ef7c | ||
|
|
edd6a084f0 | ||
|
|
4b66c0ebf4 | ||
|
|
0f9d45a5b8 | ||
|
|
a339a6df48 | ||
|
|
6f096f5245 | ||
|
|
8120088ec7 | ||
|
|
fe31fedc31 | ||
|
|
4dd9ec8919 | ||
|
|
1334daaec0 | ||
|
|
dd6f9391c3 | ||
|
|
34fb70b17c | ||
|
|
d8905b7a9c | ||
|
|
3c3085be3c | ||
|
|
bf3eeac067 | ||
|
|
b4d37878f6 | ||
|
|
b0916bba41 | ||
|
|
26ee43da1b | ||
|
|
9dfa33050b | ||
|
|
60fa5fc760 | ||
|
|
8fd8404e16 | ||
|
|
4597ebc91b | ||
|
|
eddac8575d | ||
|
|
564707023c | ||
|
|
e4b1d0b686 | ||
|
|
3fb215c952 | ||
|
|
c35a4e05fa | ||
|
|
a07f9b71e9 | ||
|
|
b0ad689e16 | ||
|
|
3b63c51a64 | ||
|
|
4ff25c06c1 | ||
|
|
f239d67c1a | ||
|
|
ec80d61ab0 | ||
|
|
8c37d3d320 | ||
|
|
e2129fb103 | ||
|
|
994fc2e822 | ||
|
|
a711d6f8c0 | ||
|
|
dd524cc893 | ||
|
|
da94ed13b8 | ||
|
|
04e901a86c | ||
|
|
c62748c9e3 | ||
|
|
b1a7ec7481 | ||
|
|
5d43b7126c | ||
|
|
a4ffb64073 | ||
|
|
4a3d589403 | ||
|
|
1a66aabd22 | ||
|
|
01731d4b1b | ||
|
|
96475e7eb4 | ||
|
|
eed2aabc40 | ||
|
|
8cd3cf90b2 | ||
|
|
d8fc544569 | ||
|
|
e4fcbba86e | ||
|
|
cd2469d3cd | ||
|
|
e121c3e179 | ||
|
|
912ce87479 | ||
|
|
29c83f5922 | ||
|
|
6ee04f8458 | ||
|
|
b425b5d56e | ||
|
|
3f96af1ae6 | ||
|
|
628b1837d2 | ||
|
|
670afbe84a | ||
|
|
289f143d8a | ||
|
|
9ca6ad6311 | ||
|
|
cf8e034b75 | ||
|
|
7a69ac32c9 | ||
|
|
edd97cddc1 | ||
|
|
21902d0ac7 | ||
|
|
a35b19f80e | ||
|
|
b1413ccf8d | ||
|
|
009df30f3a | ||
|
|
c6811ed052 | ||
|
|
58121f5f6d | ||
|
|
b6c96f05f3 | ||
|
|
36ce99d8a4 | ||
|
|
1e7e0d2465 | ||
|
|
7489e6e6f9 | ||
|
|
ef2825f1b8 | ||
|
|
68693f8279 | ||
|
|
637b2c4e51 | ||
|
|
6be1e9b565 | ||
|
|
caa5cd947d | ||
|
|
8ad67f8b9f | ||
|
|
f01d739968 | ||
|
|
1ca1dda266 | ||
|
|
4d021be52e | ||
|
|
c5b18d3dcb | ||
|
|
9e8feec7d3 | ||
|
|
1a575d0f90 | ||
|
|
51b05189f7 | ||
|
|
9b43e65c01 | ||
|
|
e25611457d | ||
|
|
07f727ba01 | ||
|
|
f29dfb45d6 | ||
|
|
e00d650328 | ||
|
|
e41b2999be | ||
|
|
cd804158b4 | ||
|
|
7a8269207d | ||
|
|
f020199925 | ||
|
|
d9b3909a21 | ||
|
|
340b1d2b6b | ||
|
|
8f539a8886 | ||
|
|
c48d8e0d42 | ||
|
|
b5a18ac439 | ||
|
|
00114e07ef | ||
|
|
ce86721bc3 | ||
|
|
e9fa7b831b | ||
|
|
2c0710d5e6 | ||
|
|
8f6aaa7230 | ||
|
|
7cad3b2e91 | ||
|
|
d744a6fc23 | ||
|
|
715afa9c57 | ||
|
|
0d7b3b9d73 | ||
|
|
bf2cc19b04 | ||
|
|
d0bc45be17 | ||
|
|
f269585de3 | ||
|
|
9936462f31 | ||
|
|
caf18da7f6 | ||
|
|
21eab267df | ||
|
|
bad5a523c2 | ||
|
|
b9f4ba19a6 | ||
|
|
70e9068432 | ||
|
|
d4163e2e97 | ||
|
|
ac1f0d9d61 | ||
|
|
952d7fde63 | ||
|
|
bfc041def1 | ||
|
|
38277ddb0b | ||
|
|
eb524d27d9 | ||
|
|
4b2911a45a | ||
|
|
76eac9a691 | ||
|
|
519b047362 | ||
|
|
ffb7ae8beb | ||
|
|
434c4e99f3 | ||
|
|
31264a7e00 | ||
|
|
3e912d9aa7 | ||
|
|
26a93d77aa | ||
|
|
011af4de71 | ||
|
|
afc7389ce8 | ||
|
|
545e1391fa | ||
|
|
8bbafeb5ef | ||
|
|
50e1bf3800 | ||
|
|
909dc1a1ab | ||
|
|
fa70fc8731 | ||
|
|
3b2850f4d9 | ||
|
|
3ce6708be2 | ||
|
|
6eed126051 | ||
|
|
6ce39f64d9 | ||
|
|
b8bb1e02ad | ||
|
|
2515825a2b | ||
|
|
8bdb5f586a | ||
|
|
d484b66ae1 | ||
|
|
00333a5c97 | ||
|
|
d6c5052f7e | ||
|
|
37354ee225 | ||
|
|
c4ad0466d6 | ||
|
|
0260d31d26 | ||
|
|
199bd6b623 | ||
|
|
b7a72b1667 | ||
|
|
751ad12dea | ||
|
|
3075445ed6 | ||
|
|
caf073dbe7 | ||
|
|
ab71b29098 | ||
|
|
444d742a94 | ||
|
|
eb21ecf55c | ||
|
|
e98157b7fe | ||
|
|
fdcd58d404 | ||
|
|
78685ed173 | ||
|
|
9113ed840c | ||
|
|
6030cadef0 | ||
|
|
58db2d1d18 | ||
|
|
cadbc158f0 | ||
|
|
7bd3205c61 | ||
|
|
cd3e34de8f | ||
|
|
d0a0c22433 | ||
|
|
512dadc8d1 | ||
|
|
081326929f | ||
|
|
b00360537e | ||
|
|
584c1da066 | ||
|
|
c727c59663 | ||
|
|
097328db7a | ||
|
|
4534fb5ec1 | ||
|
|
7d4d64340e | ||
|
|
0cda448248 | ||
|
|
7e6d76e7db | ||
|
|
b50ced528d | ||
|
|
304c1b6439 | ||
|
|
9b6e023f84 | ||
|
|
bcfc07e3d3 | ||
|
|
ca83a66618 | ||
|
|
6fe28d92c4 | ||
|
|
419aa15cd1 | ||
|
|
fcb6dbcdd7 | ||
|
|
eba576dddf | ||
|
|
a5189eefa5 | ||
|
|
55d82ced78 | ||
|
|
0946db13de | ||
|
|
c17bc7387c | ||
|
|
7d93371581 | ||
|
|
fa2f16db89 | ||
|
|
a48814906f | ||
|
|
767a2aef43 | ||
|
|
7c54199fe1 | ||
|
|
73cafd9d57 | ||
|
|
70f80a3ec7 | ||
|
|
62a8405fa2 | ||
|
|
6718a4ef8b | ||
|
|
123ee350dc | ||
|
|
20bb812148 | ||
|
|
0f9d8eb7b5 | ||
|
|
c5b6f21515 | ||
|
|
e95af30b23 | ||
|
|
dad10c0fd0 | ||
|
|
7b9084d45d | ||
|
|
6858ef9adc | ||
|
|
23964dbbbc | ||
|
|
76d1e95f4e | ||
|
|
00605058b4 | ||
|
|
c7b20f3c40 | ||
|
|
b88faee181 | ||
|
|
ac65f56774 | ||
|
|
d97e628f81 | ||
|
|
c29ccae2a6 | ||
|
|
54a682ea50 | ||
|
|
342cc9b168 | ||
|
|
edafbf1c0f | ||
|
|
8aaee26548 | ||
|
|
4d3ed3f4ea | ||
|
|
a8f89e9a9f | ||
|
|
854af5a353 | ||
|
|
1a8348e2b4 | ||
|
|
feba480527 | ||
|
|
3fede8a7e9 | ||
|
|
ac0d3c21c6 | ||
|
|
f75328b178 | ||
|
|
11cd9d86e4 | ||
|
|
692c879e3c | ||
|
|
3a4334636b | ||
|
|
9119dc25fe | ||
|
|
22aa668b7d | ||
|
|
9150688efd | ||
|
|
edc9c79c9c | ||
|
|
d0f8c50618 | ||
|
|
ea1d4d11fc | ||
|
|
3659cca624 | ||
|
|
54710873a7 | ||
|
|
6dc5343d6d | ||
|
|
61456d886e | ||
|
|
34d7776f14 | ||
|
|
32d1cc1562 | ||
|
|
95817d8bbb | ||
|
|
d50322ed95 | ||
|
|
abe8fa5253 | ||
|
|
72ca05c966 | ||
|
|
7101eae6f4 | ||
|
|
bd9f5c3c19 | ||
|
|
aca0f88750 | ||
|
|
2c3589e22a | ||
|
|
b9cb4c94fa | ||
|
|
8de64964a3 | ||
|
|
229b7d85e8 | ||
|
|
5ce4b04b50 | ||
|
|
3d92f5e95a | ||
|
|
c830a9116d |
@@ -1,2 +1,10 @@
|
|||||||
*.sln.in eol=crlf
|
*.sln.in eol=crlf
|
||||||
*.vcxproj.* eol=crlf
|
*.vcxproj.* eol=crlf
|
||||||
|
|
||||||
|
.gitignore export-ignore
|
||||||
|
/conftools export-ignore
|
||||||
|
/doc/design export-ignore
|
||||||
|
/doc/dev export-ignore
|
||||||
|
/util/** export-ignore
|
||||||
|
/util/bindkeys.pl -export-ignore
|
||||||
|
/util/mksymtbl.pl -export-ignore
|
||||||
|
|||||||
@@ -60,3 +60,4 @@ timestamp
|
|||||||
/compile_commands.json
|
/compile_commands.json
|
||||||
/cppcheck_html/
|
/cppcheck_html/
|
||||||
/cppcheck.results
|
/cppcheck.results
|
||||||
|
/tsan
|
||||||
|
|||||||
+362
-113
@@ -18,6 +18,16 @@ variables:
|
|||||||
MAKE: make
|
MAKE: make
|
||||||
CONFIGURE: ./configure
|
CONFIGURE: ./configure
|
||||||
SCAN_BUILD: scan-build-9
|
SCAN_BUILD: scan-build-9
|
||||||
|
SYMBOLIZER: /usr/lib/llvm-9/bin/llvm-symbolizer
|
||||||
|
ASAN_SYMBOLIZER_PATH: "$SYMBOLIZER"
|
||||||
|
|
||||||
|
CFLAGS_COMMON: -fno-omit-frame-pointer -fno-optimize-sibling-calls -O1 -g -Wall -Wextra
|
||||||
|
|
||||||
|
# Pass run-time flags to AddressSanitizer to get core dumps on error.
|
||||||
|
ASAN_OPTIONS_COMMON: abort_on_error=1:disable_coredump=0:unmap_shadow_on_exit=1
|
||||||
|
|
||||||
|
TARBALL_COMPRESSOR: xz
|
||||||
|
TARBALL_EXTENSION: xz
|
||||||
|
|
||||||
stages:
|
stages:
|
||||||
- precheck
|
- precheck
|
||||||
@@ -27,6 +37,7 @@ stages:
|
|||||||
- docs
|
- docs
|
||||||
- push
|
- push
|
||||||
- postcheck
|
- postcheck
|
||||||
|
- release
|
||||||
|
|
||||||
### Runner Tag Templates
|
### Runner Tag Templates
|
||||||
|
|
||||||
@@ -49,15 +60,15 @@ stages:
|
|||||||
|
|
||||||
.openbsd-amd64: &openbsd_amd64
|
.openbsd-amd64: &openbsd_amd64
|
||||||
tags:
|
tags:
|
||||||
- openbsd
|
- libvirt
|
||||||
- amd64
|
- amd64
|
||||||
|
|
||||||
### Docker Image Templates
|
### Docker Image Templates
|
||||||
|
|
||||||
# Alpine Linux
|
# Alpine Linux
|
||||||
|
|
||||||
.alpine-3.10-amd64: &alpine_3_10_amd64_image
|
.alpine-3.11-amd64: &alpine_3_11_amd64_image
|
||||||
image: "$CI_REGISTRY_IMAGE:alpine-3.10-amd64"
|
image: "$CI_REGISTRY_IMAGE:alpine-3.11-amd64"
|
||||||
<<: *linux_amd64
|
<<: *linux_amd64
|
||||||
|
|
||||||
# CentOS
|
# CentOS
|
||||||
@@ -100,10 +111,16 @@ stages:
|
|||||||
image: "$CI_REGISTRY_IMAGE:debian-sid-i386"
|
image: "$CI_REGISTRY_IMAGE:debian-sid-i386"
|
||||||
<<: *linux_i386
|
<<: *linux_i386
|
||||||
|
|
||||||
|
# openSUSE Tumbleweed
|
||||||
|
|
||||||
|
.tumbleweed-latest-amd64: &tumbleweed_latest_amd64_image
|
||||||
|
image: "$CI_REGISTRY_IMAGE:tumbleweed-latest-amd64"
|
||||||
|
<<: *linux_amd64
|
||||||
|
|
||||||
# Fedora
|
# Fedora
|
||||||
|
|
||||||
.fedora-30-amd64: &fedora_30_amd64_image
|
.fedora-31-amd64: &fedora_31_amd64_image
|
||||||
image: "$CI_REGISTRY_IMAGE:fedora-30-amd64"
|
image: "$CI_REGISTRY_IMAGE:fedora-31-amd64"
|
||||||
<<: *linux_amd64
|
<<: *linux_amd64
|
||||||
|
|
||||||
# Ubuntu
|
# Ubuntu
|
||||||
@@ -131,12 +148,14 @@ stages:
|
|||||||
- merge_requests
|
- merge_requests
|
||||||
- tags
|
- tags
|
||||||
- web
|
- web
|
||||||
|
- schedules
|
||||||
|
|
||||||
.release-branch-triggering-rules: &release_branch_triggering_rules
|
.release-branch-triggering-rules: &release_branch_triggering_rules
|
||||||
only:
|
only:
|
||||||
- merge_requests
|
- merge_requests
|
||||||
- tags
|
- tags
|
||||||
- web
|
- web
|
||||||
|
- schedules
|
||||||
- master@isc-projects/bind9
|
- master@isc-projects/bind9
|
||||||
- /^v9_[1-9][0-9]$/@isc-projects/bind9
|
- /^v9_[1-9][0-9]$/@isc-projects/bind9
|
||||||
|
|
||||||
@@ -157,7 +176,7 @@ stages:
|
|||||||
- configure
|
- configure
|
||||||
- ltmain.sh
|
- ltmain.sh
|
||||||
- m4/libtool.m4
|
- m4/libtool.m4
|
||||||
expire_in: "1 week"
|
expire_in: "1 day"
|
||||||
|
|
||||||
.configure: &configure |
|
.configure: &configure |
|
||||||
${CONFIGURE} \
|
${CONFIGURE} \
|
||||||
@@ -172,12 +191,13 @@ stages:
|
|||||||
--without-make-clean \
|
--without-make-clean \
|
||||||
$EXTRA_CONFIGURE \
|
$EXTRA_CONFIGURE \
|
||||||
|| cat config.log
|
|| cat config.log
|
||||||
|
|
||||||
.build: &build_job
|
.build: &build_job
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
stage: build
|
stage: build
|
||||||
before_script:
|
before_script:
|
||||||
- test -w "${CCACHE_DIR}" && export PATH="/usr/lib/ccache:${PATH}"
|
- test -w "${CCACHE_DIR}" && export PATH="/usr/lib/ccache:${PATH}"
|
||||||
|
- test -n "${OOT_BUILD_WORKSPACE}" && mkdir "${OOT_BUILD_WORKSPACE}" && cd "${OOT_BUILD_WORKSPACE}"
|
||||||
script:
|
script:
|
||||||
- *configure
|
- *configure
|
||||||
- ${MAKE} -j${BUILD_PARALLEL_JOBS:-1} -k all V=1
|
- ${MAKE} -j${BUILD_PARALLEL_JOBS:-1} -k all V=1
|
||||||
@@ -188,7 +208,37 @@ stages:
|
|||||||
- autoreconf:sid:amd64
|
- autoreconf:sid:amd64
|
||||||
artifacts:
|
artifacts:
|
||||||
untracked: true
|
untracked: true
|
||||||
expire_in: "1 week"
|
expire_in: "1 day"
|
||||||
|
|
||||||
|
.windows_build: &windows_build_job
|
||||||
|
stage: build
|
||||||
|
tags:
|
||||||
|
- windows
|
||||||
|
- amd64
|
||||||
|
script:
|
||||||
|
- 'Push-Location "C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Auxiliary/Build"'
|
||||||
|
- '& cmd.exe /C "vcvarsall.bat x64 & set" | Foreach-Object { if ($_ -match "(.*?)=(.*)") { Set-Item -force -path "Env:\$($matches[1])" -value "$($matches[2])" } }'
|
||||||
|
- 'Pop-Location'
|
||||||
|
- 'Set-Location win32utils'
|
||||||
|
- '& "C:/Strawberry/perl/bin/perl.exe" Configure
|
||||||
|
"with-tools-version=15.0"
|
||||||
|
"with-platform-toolset=v141"
|
||||||
|
"with-platform-version=10.0.17763.0"
|
||||||
|
"with-vcredist=C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Redist/MSVC/14.16.27012/vcredist_x64.exe"
|
||||||
|
"with-openssl=C:/OpenSSL"
|
||||||
|
"with-libxml2=C:/libxml2"
|
||||||
|
"with-libuv=C:/libuv"
|
||||||
|
"without-python"
|
||||||
|
"with-system-tests"
|
||||||
|
x64'
|
||||||
|
- 'Set-Item -path "Env:CL" -value "/MP$([Math]::Truncate($BUILD_PARALLEL_JOBS/2))"'
|
||||||
|
- '& msbuild.exe /maxCpuCount:2 /t:Build /p:Configuration=$VSCONF bind9.sln'
|
||||||
|
dependencies: []
|
||||||
|
needs:
|
||||||
|
- autoreconf:sid:amd64
|
||||||
|
artifacts:
|
||||||
|
untracked: true
|
||||||
|
expire_in: "1 day"
|
||||||
|
|
||||||
.setup_interfaces: &setup_interfaces |
|
.setup_interfaces: &setup_interfaces |
|
||||||
if [ "$(id -u)" -eq "0" ]; then
|
if [ "$(id -u)" -eq "0" ]; then
|
||||||
@@ -198,12 +248,11 @@ stages:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
.setup_softhsm: &setup_softhsm |
|
.setup_softhsm: &setup_softhsm |
|
||||||
sh -x util/prepare-softhsm2.sh
|
sh -x bin/tests/prepare-softhsm2.sh
|
||||||
|
|
||||||
.system_test: &system_test_job
|
.system_test: &system_test_job
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
stage: system
|
stage: system
|
||||||
retry: 2
|
|
||||||
before_script:
|
before_script:
|
||||||
- *setup_interfaces
|
- *setup_interfaces
|
||||||
- *setup_softhsm
|
- *setup_softhsm
|
||||||
@@ -212,7 +261,7 @@ stages:
|
|||||||
- test -s bin/tests/system/systests.output
|
- test -s bin/tests/system/systests.output
|
||||||
artifacts:
|
artifacts:
|
||||||
untracked: true
|
untracked: true
|
||||||
expire_in: "1 week"
|
expire_in: "1 day"
|
||||||
when: on_failure
|
when: on_failure
|
||||||
|
|
||||||
.kyua_report: &kyua_report_html |
|
.kyua_report: &kyua_report_html |
|
||||||
@@ -222,6 +271,30 @@ stages:
|
|||||||
--results-filter "" \
|
--results-filter "" \
|
||||||
--output kyua_html
|
--output kyua_html
|
||||||
|
|
||||||
|
.windows_system_test: &windows_system_test_job
|
||||||
|
stage: system
|
||||||
|
tags:
|
||||||
|
- windows
|
||||||
|
- amd64
|
||||||
|
script:
|
||||||
|
- 'Push-Location bin/tests/system'
|
||||||
|
- '$ifIndex = Get-NetIPInterface -AddressFamily IPv4 -InterfaceMetric 75 | Select-Object -ExpandProperty ifIndex'
|
||||||
|
- '& C:/tools/cygwin/bin/sed.exe -i "s/^exit.*/netsh interface ipv4 set dnsservers $ifIndex dhcp/; s/\(name\|interface\)=Loopback/$ifIndex/;" ifconfig.bat'
|
||||||
|
- '& C:/tools/cygwin/bin/sed.exe -i "s/kill -f/kill -W/;" conf.sh stop.pl'
|
||||||
|
- '& cmd.exe /C ifconfig.bat up; ""'
|
||||||
|
- 'Start-Sleep 2'
|
||||||
|
- '$Env:Path = "C:/tools/cygwin/bin;$Env:Path"'
|
||||||
|
- '& sh.exe runall.sh $TEST_PARALLEL_JOBS'
|
||||||
|
- 'If (Test-Path C:/CrashDumps/*) { dir C:/CrashDumps; Throw }'
|
||||||
|
artifacts:
|
||||||
|
untracked: true
|
||||||
|
expire_in: "1 day"
|
||||||
|
when: on_failure
|
||||||
|
only:
|
||||||
|
- schedules
|
||||||
|
- tags
|
||||||
|
- web
|
||||||
|
|
||||||
.unit_test: &unit_test_job
|
.unit_test: &unit_test_job
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
stage: unit
|
stage: unit
|
||||||
@@ -236,7 +309,7 @@ stages:
|
|||||||
- kyua.log
|
- kyua.log
|
||||||
- kyua.results
|
- kyua.results
|
||||||
- kyua_html/
|
- kyua_html/
|
||||||
expire_in: "1 week"
|
expire_in: "1 day"
|
||||||
when: on_failure
|
when: on_failure
|
||||||
|
|
||||||
.cppcheck_args: &run_cppcheck |
|
.cppcheck_args: &run_cppcheck |
|
||||||
@@ -274,7 +347,7 @@ stages:
|
|||||||
- compile_commands.json
|
- compile_commands.json
|
||||||
- cppcheck.results
|
- cppcheck.results
|
||||||
- cppcheck_html/
|
- cppcheck_html/
|
||||||
expire_in: "1 week"
|
expire_in: "1 day"
|
||||||
when: on_failure
|
when: on_failure
|
||||||
|
|
||||||
### Job Definitions
|
### Job Definitions
|
||||||
@@ -291,8 +364,11 @@ misc:sid:amd64:
|
|||||||
- sh util/checklibs.sh > checklibs.out
|
- sh util/checklibs.sh > checklibs.out
|
||||||
- sh util/tabify-changes < CHANGES > CHANGES.tmp
|
- sh util/tabify-changes < CHANGES > CHANGES.tmp
|
||||||
- diff -urNap CHANGES CHANGES.tmp
|
- diff -urNap CHANGES CHANGES.tmp
|
||||||
- rm CHANGES.tmp
|
|
||||||
- perl util/check-changes CHANGES
|
- perl util/check-changes CHANGES
|
||||||
|
- test ! -f CHANGES.SE || sh util/tabify-changes < CHANGES.SE > CHANGES.tmp
|
||||||
|
- test ! -f CHANGES.SE || diff -urNap CHANGES.SE CHANGES.tmp
|
||||||
|
- test ! -f CHANGES.SE || perl util/check-changes master=0 CHANGES.SE
|
||||||
|
- rm CHANGES.tmp
|
||||||
- perl -w util/merge_copyrights
|
- perl -w util/merge_copyrights
|
||||||
- diff -urNap util/copyrights util/newcopyrights
|
- diff -urNap util/copyrights util/newcopyrights
|
||||||
- rm util/newcopyrights
|
- rm util/newcopyrights
|
||||||
@@ -305,15 +381,33 @@ misc:sid:amd64:
|
|||||||
paths:
|
paths:
|
||||||
- util/newcopyrights
|
- util/newcopyrights
|
||||||
- checklibs.out
|
- checklibs.out
|
||||||
expire_in: "1 week"
|
expire_in: "1 day"
|
||||||
when: on_failure
|
when: on_failure
|
||||||
|
|
||||||
🐞:sid:amd64:
|
🐞:sid:amd64:
|
||||||
<<: *precheck_job
|
<<: *precheck_job
|
||||||
|
<<: *debian_buster_amd64_image
|
||||||
script:
|
script:
|
||||||
- util/check-cocci
|
- util/check-cocci
|
||||||
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
- if test "$(git status --porcelain | grep -Ev '\?\?' | wc -l)" -gt "0"; then git status --short; exit 1; fi
|
||||||
|
|
||||||
|
tarball-create:sid:amd64:
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
stage: precheck
|
||||||
|
script:
|
||||||
|
- source version
|
||||||
|
- export BIND_DIRECTORY="bind-${MAJORVER}.${MINORVER}.${PATCHVER}${RELEASETYPE}${RELEASEVER}"
|
||||||
|
- git archive --prefix="${BIND_DIRECTORY}/" --output="${BIND_DIRECTORY}.tar" HEAD
|
||||||
|
- mkdir "${BIND_DIRECTORY}"
|
||||||
|
- echo "SRCID=$(git rev-list --max-count=1 HEAD | cut -b1-7)" > "${BIND_DIRECTORY}/srcid"
|
||||||
|
- tar --append --file="${BIND_DIRECTORY}.tar" "${BIND_DIRECTORY}/srcid"
|
||||||
|
- ${TARBALL_COMPRESSOR} "${BIND_DIRECTORY}.tar"
|
||||||
|
artifacts:
|
||||||
|
paths:
|
||||||
|
- bind-*.tar.${TARBALL_EXTENSION}
|
||||||
|
only:
|
||||||
|
- tags
|
||||||
|
|
||||||
# Jobs for doc builds on Debian Sid (amd64)
|
# Jobs for doc builds on Debian Sid (amd64)
|
||||||
|
|
||||||
docs:sid:amd64:
|
docs:sid:amd64:
|
||||||
@@ -331,7 +425,7 @@ docs:sid:amd64:
|
|||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
- doc/arm/
|
- doc/arm/
|
||||||
expire_in: "1 month"
|
expire_in: "1 day"
|
||||||
|
|
||||||
push:docs:sid:amd64:
|
push:docs:sid:amd64:
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
@@ -343,36 +437,36 @@ push:docs:sid:amd64:
|
|||||||
- master@isc-projects/bind9
|
- master@isc-projects/bind9
|
||||||
- /^v9_[1-9][0-9]$/@isc-projects/bind9
|
- /^v9_[1-9][0-9]$/@isc-projects/bind9
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Alpine Linux 3.10 (amd64)
|
# Jobs for regular GCC builds on Alpine Linux 3.11 (amd64)
|
||||||
|
|
||||||
gcc:alpine3.10:amd64:
|
gcc:alpine3.11:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap"
|
EXTRA_CONFIGURE: "--enable-dnstap"
|
||||||
<<: *alpine_3_10_amd64_image
|
<<: *alpine_3_11_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
system:gcc:alpine3.10:amd64:
|
system:gcc:alpine3.11:amd64:
|
||||||
<<: *alpine_3_10_amd64_image
|
<<: *alpine_3_11_amd64_image
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:alpine3.10:amd64
|
- gcc:alpine3.11:amd64
|
||||||
needs: ["gcc:alpine3.10:amd64"]
|
needs: ["gcc:alpine3.11:amd64"]
|
||||||
|
|
||||||
unit:gcc:alpine3.10:amd64:
|
unit:gcc:alpine3.11:amd64:
|
||||||
<<: *alpine_3_10_amd64_image
|
<<: *alpine_3_11_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:alpine3.10:amd64
|
- gcc:alpine3.11:amd64
|
||||||
needs: ["gcc:alpine3.10:amd64"]
|
needs: ["gcc:alpine3.11:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on CentOS 6 (amd64)
|
# Jobs for regular GCC builds on CentOS 6 (amd64)
|
||||||
|
|
||||||
gcc:centos6:amd64:
|
gcc:centos6:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --disable-warn-error"
|
EXTRA_CONFIGURE: "--with-libidn2 --disable-warn-error"
|
||||||
<<: *centos_centos6_amd64_image
|
<<: *centos_centos6_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -396,7 +490,7 @@ unit:gcc:centos6:amd64:
|
|||||||
gcc:centos7:amd64:
|
gcc:centos7:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||||
<<: *centos_centos7_amd64_image
|
<<: *centos_centos7_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -420,7 +514,7 @@ unit:gcc:centos7:amd64:
|
|||||||
gcc:centos8:amd64:
|
gcc:centos8:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2"
|
EXTRA_CONFIGURE: "--with-libidn2"
|
||||||
<<: *centos_centos8_amd64_image
|
<<: *centos_centos8_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -444,7 +538,7 @@ unit:gcc:centos8:amd64:
|
|||||||
gcc:jessie:amd64:
|
gcc:jessie:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -O2"
|
||||||
EXTRA_CONFIGURE: "--without-cmocka --with-python --disable-geoip"
|
EXTRA_CONFIGURE: "--without-cmocka --with-python --disable-geoip"
|
||||||
<<: *debian_jessie_amd64_image
|
<<: *debian_jessie_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -468,7 +562,7 @@ unit:gcc:jessie:amd64:
|
|||||||
gcc:stretch:amd64:
|
gcc:stretch:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -O2"
|
||||||
<<: *debian_stretch_amd64_image
|
<<: *debian_stretch_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -491,7 +585,7 @@ unit:gcc:stretch:amd64:
|
|||||||
gcc:buster:amd64:
|
gcc:buster:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
<<: *debian_buster_amd64_image
|
<<: *debian_buster_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -525,7 +619,7 @@ scan-build:buster:amd64:
|
|||||||
stage: postcheck
|
stage: postcheck
|
||||||
variables:
|
variables:
|
||||||
CC: clang-9
|
CC: clang-9
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
CONFIGURE: "${SCAN_BUILD} ./configure"
|
CONFIGURE: "${SCAN_BUILD} ./configure"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||||
script:
|
script:
|
||||||
@@ -538,7 +632,7 @@ scan-build:buster:amd64:
|
|||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
- scan-build.reports/
|
- scan-build.reports/
|
||||||
expire_in: "1 week"
|
expire_in: "1 day"
|
||||||
when: on_failure
|
when: on_failure
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Debian Sid (amd64)
|
# Jobs for regular GCC builds on Debian Sid (amd64)
|
||||||
@@ -546,7 +640,7 @@ scan-build:buster:amd64:
|
|||||||
gcc:sid:amd64:
|
gcc:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O3 -g"
|
CFLAGS: "${CFLAGS_COMMON} -O3"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||||
RUN_MAKE_INSTALL: 1
|
RUN_MAKE_INSTALL: 1
|
||||||
MAKE: bear make
|
MAKE: bear make
|
||||||
@@ -574,12 +668,67 @@ cppcheck:gcc:sid:amd64:
|
|||||||
- gcc:sid:amd64
|
- gcc:sid:amd64
|
||||||
needs: ["gcc:sid:amd64"]
|
needs: ["gcc:sid:amd64"]
|
||||||
|
|
||||||
|
# Job for out-of-tree GCC build on Debian Sid (amd64)
|
||||||
|
|
||||||
|
oot:sid:amd64:
|
||||||
|
variables:
|
||||||
|
CC: gcc
|
||||||
|
CFLAGS: "${CFLAGS_COMMON} -O3"
|
||||||
|
CONFIGURE: ../configure
|
||||||
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||||
|
RUN_MAKE_INSTALL: 1
|
||||||
|
OOT_BUILD_WORKSPACE: workspace
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *build_job
|
||||||
|
|
||||||
|
# Jobs for tarball GCC builds on Debian Sid (amd64)
|
||||||
|
|
||||||
|
tarball:sid:amd64:
|
||||||
|
variables:
|
||||||
|
CC: gcc
|
||||||
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2"
|
||||||
|
RUN_MAKE_INSTALL: 1
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *build_job
|
||||||
|
before_script:
|
||||||
|
- tar --extract --file bind-*.tar.${TARBALL_EXTENSION}
|
||||||
|
- rm -f bind-*.tar.${TARBALL_EXTENSION}
|
||||||
|
- cd bind-*
|
||||||
|
dependencies:
|
||||||
|
- tarball-create:sid:amd64
|
||||||
|
needs: ["tarball-create:sid:amd64"]
|
||||||
|
only:
|
||||||
|
- tags
|
||||||
|
|
||||||
|
system:tarball:sid:amd64:
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *system_test_job
|
||||||
|
before_script:
|
||||||
|
- cd bind-*
|
||||||
|
- *setup_interfaces
|
||||||
|
dependencies:
|
||||||
|
- tarball:sid:amd64
|
||||||
|
needs: ["tarball:sid:amd64"]
|
||||||
|
only:
|
||||||
|
- tags
|
||||||
|
|
||||||
|
unit:tarball:sid:amd64:
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
<<: *unit_test_job
|
||||||
|
before_script:
|
||||||
|
- cd bind-*
|
||||||
|
dependencies:
|
||||||
|
- tarball:sid:amd64
|
||||||
|
needs: ["tarball:sid:amd64"]
|
||||||
|
only:
|
||||||
|
- tags
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Debian Sid (i386)
|
# Jobs for regular GCC builds on Debian Sid (i386)
|
||||||
|
|
||||||
gcc:sid:i386:
|
gcc:sid:i386:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O3 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2 --without-python"
|
EXTRA_CONFIGURE: "--enable-dnstap --with-libidn2 --without-python"
|
||||||
<<: *debian_sid_i386_image
|
<<: *debian_sid_i386_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -598,36 +747,60 @@ unit:gcc:sid:i386:
|
|||||||
- gcc:sid:i386
|
- gcc:sid:i386
|
||||||
needs: ["gcc:sid:i386"]
|
needs: ["gcc:sid:i386"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Fedora 30 (amd64)
|
# Jobs for regular GCC builds on openSUSE Tumbleweed (amd64)
|
||||||
|
|
||||||
gcc:fedora30:amd64:
|
gcc:tumbleweed:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2"
|
EXTRA_CONFIGURE: "--with-libidn2"
|
||||||
<<: *fedora_30_amd64_image
|
<<: *tumbleweed_latest_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
system:gcc:fedora30:amd64:
|
system:gcc:tumbleweed:amd64:
|
||||||
<<: *fedora_30_amd64_image
|
<<: *tumbleweed_latest_amd64_image
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:fedora30:amd64
|
- gcc:tumbleweed:amd64
|
||||||
needs: ["gcc:fedora30:amd64"]
|
needs: ["gcc:tumbleweed:amd64"]
|
||||||
|
|
||||||
unit:gcc:fedora30:amd64:
|
unit:gcc:tumbleweed:amd64:
|
||||||
<<: *fedora_30_amd64_image
|
<<: *tumbleweed_latest_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- gcc:fedora30:amd64
|
- gcc:tumbleweed:amd64
|
||||||
needs: ["gcc:fedora30:amd64"]
|
needs: ["gcc:tumbleweed:amd64"]
|
||||||
|
|
||||||
|
# Jobs for regular GCC builds on Fedora 31 (amd64)
|
||||||
|
|
||||||
|
gcc:fedora31:amd64:
|
||||||
|
variables:
|
||||||
|
CC: gcc
|
||||||
|
CFLAGS: "${CFLAGS_COMMON} -O1"
|
||||||
|
EXTRA_CONFIGURE: "--with-libidn2"
|
||||||
|
<<: *fedora_31_amd64_image
|
||||||
|
<<: *build_job
|
||||||
|
|
||||||
|
system:gcc:fedora31:amd64:
|
||||||
|
<<: *fedora_31_amd64_image
|
||||||
|
<<: *system_test_job
|
||||||
|
dependencies:
|
||||||
|
- gcc:fedora31:amd64
|
||||||
|
needs: ["gcc:fedora31:amd64"]
|
||||||
|
|
||||||
|
unit:gcc:fedora31:amd64:
|
||||||
|
<<: *fedora_31_amd64_image
|
||||||
|
<<: *unit_test_job
|
||||||
|
dependencies:
|
||||||
|
- gcc:fedora31:amd64
|
||||||
|
needs: ["gcc:fedora31:amd64"]
|
||||||
|
|
||||||
# Jobs for regular GCC builds on Ubuntu 16.04 Xenial Xerus (amd64)
|
# Jobs for regular GCC builds on Ubuntu 16.04 Xenial Xerus (amd64)
|
||||||
|
|
||||||
gcc:xenial:amd64:
|
gcc:xenial:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -O2"
|
||||||
EXTRA_CONFIGURE: "--disable-geoip"
|
EXTRA_CONFIGURE: "--disable-geoip"
|
||||||
<<: *ubuntu_xenial_amd64_image
|
<<: *ubuntu_xenial_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -651,7 +824,7 @@ unit:gcc:xenial:amd64:
|
|||||||
gcc:bionic:amd64:
|
gcc:bionic:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -Og"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2"
|
EXTRA_CONFIGURE: "--with-libidn2"
|
||||||
<<: *ubuntu_bionic_amd64_image
|
<<: *ubuntu_bionic_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -675,14 +848,15 @@ unit:gcc:bionic:amd64:
|
|||||||
asan:sid:amd64:
|
asan:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
ASAN_OPTIONS: "detect_leaks=0"
|
CFLAGS: "${CFLAGS_COMMON} -fsanitize=address,undefined -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g -fsanitize=address,undefined -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
|
||||||
LDFLAGS: "-fsanitize=address,undefined"
|
LDFLAGS: "-fsanitize=address,undefined"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2"
|
EXTRA_CONFIGURE: "--with-libidn2"
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
system:asan:sid:amd64:
|
system:asan:sid:amd64:
|
||||||
|
variables:
|
||||||
|
ASAN_OPTIONS: ${ASAN_OPTIONS_COMMON}
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
@@ -690,16 +864,75 @@ system:asan:sid:amd64:
|
|||||||
needs: ["asan:sid:amd64"]
|
needs: ["asan:sid:amd64"]
|
||||||
|
|
||||||
unit:asan:sid:amd64:
|
unit:asan:sid:amd64:
|
||||||
|
variables:
|
||||||
|
ASAN_OPTIONS: ${ASAN_OPTIONS_COMMON}
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *unit_test_job
|
<<: *unit_test_job
|
||||||
dependencies:
|
dependencies:
|
||||||
- asan:sid:amd64
|
- asan:sid:amd64
|
||||||
needs: ["asan:sid:amd64"]
|
needs: ["asan:sid:amd64"]
|
||||||
|
|
||||||
|
# Jobs for GCC builds with TSAN enabled on Debian Sid (amd64)
|
||||||
|
|
||||||
|
tsan:buster:amd64:
|
||||||
|
<<: *debian_buster_amd64_image
|
||||||
|
<<: *build_job
|
||||||
|
variables:
|
||||||
|
CC: clang-9
|
||||||
|
CFLAGS: "${CFLAGS_COMMON} -fsanitize=thread -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||||
|
LDFLAGS: "-fsanitize=thread"
|
||||||
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock"
|
||||||
|
|
||||||
|
system:tsan:buster:amd64:
|
||||||
|
variables:
|
||||||
|
TSAN_OPTIONS: "second_deadlock_stack=1 history_size=7 log_exe_name=true log_path=tsan external_symbolizer_path=$SYMBOLIZER exitcode=0"
|
||||||
|
before_script:
|
||||||
|
- *setup_interfaces
|
||||||
|
- echo $TSAN_OPTIONS
|
||||||
|
<<: *debian_buster_amd64_image
|
||||||
|
<<: *system_test_job
|
||||||
|
dependencies:
|
||||||
|
- tsan:buster:amd64
|
||||||
|
needs: ["tsan:buster:amd64"]
|
||||||
|
allow_failure: true
|
||||||
|
after_script:
|
||||||
|
- find bin -name 'tsan.*' -exec python3 util/parse_tsan.py {} \;
|
||||||
|
artifacts:
|
||||||
|
expire_in: "1 day"
|
||||||
|
paths:
|
||||||
|
- bin/tests/system/*/tsan.*
|
||||||
|
- bin/tests/system/*/*/tsan.*
|
||||||
|
- tsan/
|
||||||
|
when: on_failure
|
||||||
|
|
||||||
|
unit:tsan:buster:amd64:
|
||||||
|
variables:
|
||||||
|
TSAN_OPTIONS: "second_deadlock_stack=1 history_size=7 log_exe_name=true log_path=tsan external_symbolizer_path=$SYMBOLIZER"
|
||||||
|
before_script:
|
||||||
|
- echo $TSAN_OPTIONS
|
||||||
|
- lib/isc/tests/result_test
|
||||||
|
<<: *debian_buster_amd64_image
|
||||||
|
<<: *unit_test_job
|
||||||
|
dependencies:
|
||||||
|
- tsan:buster:amd64
|
||||||
|
needs: ["tsan:buster:amd64"]
|
||||||
|
allow_failure: true
|
||||||
|
after_script:
|
||||||
|
- find lib -name 'tsan.*' -exec python3 util/parse_tsan.py {} \;
|
||||||
|
artifacts:
|
||||||
|
expire_in: "1 day"
|
||||||
|
paths:
|
||||||
|
- lib/*/tests/tsan.*
|
||||||
|
- tsan/
|
||||||
|
- kyua.log
|
||||||
|
- kyua.results
|
||||||
|
- kyua_html/
|
||||||
|
when: on_failure
|
||||||
|
|
||||||
rwlock:sid:amd64:
|
rwlock:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
CFLAGS: "${CFLAGS_COMMON} -Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock"
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-pthread-rwlock"
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -722,7 +955,7 @@ unit:rwlock:sid:amd64:
|
|||||||
mutexatomics:sid:amd64:
|
mutexatomics:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
CFLAGS: "${CFLAGS_COMMON} -DISC_MEM_USE_INTERNAL_MALLOC=0"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --enable-mutex-atomics"
|
EXTRA_CONFIGURE: "--with-libidn2 --enable-mutex-atomics"
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -747,7 +980,7 @@ mutexatomics:sid:amd64:
|
|||||||
clang:stretch:amd64:
|
clang:stretch:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: clang
|
CC: clang
|
||||||
CFLAGS: "-Wall -Wextra -Wenum-conversion -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -Wenum-conversion"
|
||||||
EXTRA_CONFIGURE: "--with-python=python3"
|
EXTRA_CONFIGURE: "--with-python=python3"
|
||||||
<<: *debian_stretch_amd64_image
|
<<: *debian_stretch_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -764,7 +997,7 @@ unit:clang:stretch:amd64:
|
|||||||
clang:stretch:i386:
|
clang:stretch:i386:
|
||||||
variables:
|
variables:
|
||||||
CC: clang
|
CC: clang
|
||||||
CFLAGS: "-Wall -Wextra -Wenum-conversion -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON} -Wenum-conversion"
|
||||||
EXTRA_CONFIGURE: "--with-python=python2"
|
EXTRA_CONFIGURE: "--with-python=python2"
|
||||||
<<: *debian_stretch_i386_image
|
<<: *debian_stretch_i386_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -774,7 +1007,7 @@ clang:stretch:i386:
|
|||||||
pkcs11:sid:amd64:
|
pkcs11:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--enable-native-pkcs11 --with-pkcs11=/usr/lib/softhsm/libsofthsm2.so"
|
EXTRA_CONFIGURE: "--enable-native-pkcs11 --with-pkcs11=/usr/lib/softhsm/libsofthsm2.so"
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -797,7 +1030,7 @@ unit:pkcs11:sid:amd64:
|
|||||||
|
|
||||||
clang:freebsd11.3:amd64:
|
clang:freebsd11.3:amd64:
|
||||||
variables:
|
variables:
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
<<: *freebsd_amd64
|
<<: *freebsd_amd64
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
@@ -819,7 +1052,7 @@ unit:clang:freebsd11.3:amd64:
|
|||||||
|
|
||||||
clang:freebsd12.0:amd64:
|
clang:freebsd12.0:amd64:
|
||||||
variables:
|
variables:
|
||||||
CFLAGS: "-Wall -Wextra -O2 -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--enable-dnstap"
|
EXTRA_CONFIGURE: "--enable-dnstap"
|
||||||
<<: *freebsd_amd64
|
<<: *freebsd_amd64
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -838,21 +1071,25 @@ unit:clang:freebsd12.0:amd64:
|
|||||||
- clang:freebsd12.0:amd64
|
- clang:freebsd12.0:amd64
|
||||||
needs: ["clang:freebsd12.0:amd64"]
|
needs: ["clang:freebsd12.0:amd64"]
|
||||||
|
|
||||||
# Jobs for Clang builds on OpenBSD 6.5 (amd64)
|
# Jobs for Clang builds on OpenBSD 6.6 (amd64)
|
||||||
|
|
||||||
clang:openbsd6.5:amd64:
|
clang:openbsd6.6:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: clang
|
CC: clang
|
||||||
|
USER: gitlab-runner
|
||||||
<<: *openbsd_amd64
|
<<: *openbsd_amd64
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
|
|
||||||
system:clang:openbsd6.5:amd64:
|
system:clang:openbsd6.6:amd64:
|
||||||
<<: *openbsd_amd64
|
<<: *openbsd_amd64
|
||||||
<<: *system_test_job
|
<<: *system_test_job
|
||||||
|
variables:
|
||||||
|
USER: gitlab-runner
|
||||||
dependencies:
|
dependencies:
|
||||||
- clang:openbsd6.5:amd64
|
- clang:openbsd6.6:amd64
|
||||||
needs: ["clang:openbsd6.5:amd64"]
|
needs: ["clang:openbsd6.6:amd64"]
|
||||||
only:
|
only:
|
||||||
|
- schedules
|
||||||
- tags
|
- tags
|
||||||
- web
|
- web
|
||||||
|
|
||||||
@@ -861,7 +1098,7 @@ system:clang:openbsd6.5:amd64:
|
|||||||
nolibtool:sid:amd64:
|
nolibtool:sid:amd64:
|
||||||
variables:
|
variables:
|
||||||
CC: gcc
|
CC: gcc
|
||||||
CFLAGS: "-Wall -Wextra -Og -g"
|
CFLAGS: "${CFLAGS_COMMON}"
|
||||||
EXTRA_CONFIGURE: "--with-libidn2 --without-libtool --with-dlopen"
|
EXTRA_CONFIGURE: "--with-libidn2 --without-libtool --with-dlopen"
|
||||||
<<: *debian_sid_amd64_image
|
<<: *debian_sid_amd64_image
|
||||||
<<: *build_job
|
<<: *build_job
|
||||||
@@ -883,62 +1120,74 @@ unit:nolibtool:sid:amd64:
|
|||||||
# Jobs for Visual Studio 2017 builds on Windows (amd64)
|
# Jobs for Visual Studio 2017 builds on Windows (amd64)
|
||||||
|
|
||||||
msvc:windows:amd64:
|
msvc:windows:amd64:
|
||||||
|
<<: *windows_build_job
|
||||||
<<: *default_triggering_rules
|
<<: *default_triggering_rules
|
||||||
stage: build
|
|
||||||
tags:
|
|
||||||
- windows
|
|
||||||
- amd64
|
|
||||||
variables:
|
variables:
|
||||||
VSCONF: Release
|
VSCONF: Release
|
||||||
script:
|
|
||||||
- 'Push-Location "C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Auxiliary/Build"'
|
|
||||||
- '& cmd.exe /C "vcvarsall.bat x64 & set" | Foreach-Object { if ($_ -match "(.*?)=(.*)") { Set-Item -force -path "Env:\$($matches[1])" -value "$($matches[2])" } }'
|
|
||||||
- 'Pop-Location'
|
|
||||||
- 'Set-Location win32utils'
|
|
||||||
- '& "C:/Strawberry/perl/bin/perl.exe" Configure
|
|
||||||
"with-tools-version=15.0"
|
|
||||||
"with-platform-toolset=v141"
|
|
||||||
"with-platform-version=10.0.17763.0"
|
|
||||||
"with-vcredist=C:/Program Files (x86)/Microsoft Visual Studio/2017/BuildTools/VC/Redist/MSVC/14.16.27012/vcredist_x64.exe"
|
|
||||||
"with-openssl=C:/OpenSSL"
|
|
||||||
"with-libxml2=C:/libxml2"
|
|
||||||
"with-libuv=C:/libuv"
|
|
||||||
"without-python"
|
|
||||||
"with-system-tests"
|
|
||||||
x64'
|
|
||||||
- 'Set-Item -path "Env:CL" -value "/MP$([Math]::Truncate($BUILD_PARALLEL_JOBS/2))"'
|
|
||||||
- '& msbuild.exe /maxCpuCount:2 /t:Build /p:Configuration=$VSCONF bind9.sln'
|
|
||||||
dependencies: []
|
|
||||||
needs:
|
|
||||||
- autoreconf:sid:amd64
|
|
||||||
artifacts:
|
|
||||||
untracked: true
|
|
||||||
expire_in: "1 week"
|
|
||||||
|
|
||||||
system:msvc:windows:amd64:
|
system:msvc:windows:amd64:
|
||||||
stage: system
|
<<: *windows_system_test_job
|
||||||
tags:
|
|
||||||
- windows
|
|
||||||
- amd64
|
|
||||||
variables:
|
variables:
|
||||||
VSCONF: Release
|
VSCONF: Release
|
||||||
script:
|
|
||||||
- 'Push-Location bin/tests/system'
|
|
||||||
- '$ifIndex = Get-NetIPInterface -AddressFamily IPv4 -InterfaceMetric 75 | Select-Object -ExpandProperty ifIndex'
|
|
||||||
- '& C:/tools/cygwin/bin/sed.exe -i "s/^exit.*/netsh interface ipv4 set dnsservers $ifIndex dhcp/; s/\(name\|interface\)=Loopback/$ifIndex/;" ifconfig.bat'
|
|
||||||
- '& C:/tools/cygwin/bin/sed.exe -i "s/kill -f/kill -W/;" conf.sh stop.pl'
|
|
||||||
- '& cmd.exe /C ifconfig.bat up; ""'
|
|
||||||
- 'Start-Sleep 2'
|
|
||||||
- '$Env:Path = "C:/tools/cygwin/bin;$Env:Path"'
|
|
||||||
- '& sh.exe runall.sh $TEST_PARALLEL_JOBS'
|
|
||||||
- 'If (Test-Path C:/CrashDumps/*) { dir C:/CrashDumps; Throw }'
|
|
||||||
dependencies:
|
dependencies:
|
||||||
- msvc:windows:amd64
|
- msvc:windows:amd64
|
||||||
needs: ["msvc:windows:amd64"]
|
needs: ["msvc:windows:amd64"]
|
||||||
artifacts:
|
|
||||||
untracked: true
|
msvc-debug:windows:amd64:
|
||||||
expire_in: "1 week"
|
<<: *windows_build_job
|
||||||
when: on_failure
|
variables:
|
||||||
|
VSCONF: Debug
|
||||||
only:
|
only:
|
||||||
|
- schedules
|
||||||
- tags
|
- tags
|
||||||
- web
|
- web
|
||||||
|
|
||||||
|
system:msvc-debug:windows:amd64:
|
||||||
|
<<: *windows_system_test_job
|
||||||
|
variables:
|
||||||
|
VSCONF: Debug
|
||||||
|
dependencies:
|
||||||
|
- msvc-debug:windows:amd64
|
||||||
|
needs: ["msvc-debug:windows:amd64"]
|
||||||
|
|
||||||
|
# Job producing a release tarball
|
||||||
|
|
||||||
|
release:sid:amd64:
|
||||||
|
<<: *debian_sid_amd64_image
|
||||||
|
stage: release
|
||||||
|
script:
|
||||||
|
# Determine BIND version
|
||||||
|
- source version
|
||||||
|
- export BIND_DIRECTORY="bind-${MAJORVER}.${MINORVER}.${PATCHVER}${RELEASETYPE}${RELEASEVER}"
|
||||||
|
# Remove redundant files and system test utilities from Windows build artifacts
|
||||||
|
- find Build/Release/ -name "*.pdb" -print -delete
|
||||||
|
- find Build/Debug/ \( -name "*.bsc" -o -name "*.idb" \) -print -delete
|
||||||
|
- find Build/ -regextype posix-extended -regex "Build/.*/($(find bin/tests/ -type f | sed -nE "s|^bin/tests(/system)?/win32/(.*)\.vcxproj$|\2|p" | paste -d"|" -s))\..*" -print -delete
|
||||||
|
# Create Windows zips
|
||||||
|
- openssl dgst -sha256 "${BIND_DIRECTORY}.tar.${TARBALL_EXTENSION}" | tee Build/Release/SHA256 Build/Debug/SHA256
|
||||||
|
- ( cd Build/Release; zip "../../BIND${BIND_DIRECTORY#bind-}.x64.zip" * )
|
||||||
|
- ( cd Build/Debug; zip "../../BIND${BIND_DIRECTORY#bind-}.debug.x64.zip" * )
|
||||||
|
# Prepare release tarball contents (tarballs + zips + documentation)
|
||||||
|
- mkdir -p release/doc/arm
|
||||||
|
- pushd release
|
||||||
|
- mv "../${BIND_DIRECTORY}.tar.${TARBALL_EXTENSION}" ../BIND*.zip .
|
||||||
|
- tar --extract --file="${BIND_DIRECTORY}.tar.${TARBALL_EXTENSION}"
|
||||||
|
- mv "${BIND_DIRECTORY}"/{CHANGES*,COPYRIGHT,LICENSE,README,srcid} .
|
||||||
|
- mv "${BIND_DIRECTORY}"/doc/arm/{Bv9ARM{*.html,.pdf},man.*,notes.{html,pdf,txt}} doc/arm/
|
||||||
|
- rm -rf "${BIND_DIRECTORY}"
|
||||||
|
- cp doc/arm/notes.html "RELEASE-NOTES-${BIND_DIRECTORY}.html"
|
||||||
|
- cp doc/arm/notes.pdf "RELEASE-NOTES-${BIND_DIRECTORY}.pdf"
|
||||||
|
- cp doc/arm/notes.txt "RELEASE-NOTES-${BIND_DIRECTORY}.txt"
|
||||||
|
- popd
|
||||||
|
# Create release tarball
|
||||||
|
- tar --create --file="${CI_COMMIT_TAG}.tar.gz" --gzip release/
|
||||||
|
dependencies:
|
||||||
|
- tarball-create:sid:amd64
|
||||||
|
- msvc:windows:amd64
|
||||||
|
- msvc-debug:windows:amd64
|
||||||
|
only:
|
||||||
|
- tags
|
||||||
|
artifacts:
|
||||||
|
paths:
|
||||||
|
- "*.tar.gz"
|
||||||
|
expire_in: "1 day"
|
||||||
|
|||||||
@@ -2,8 +2,6 @@
|
|||||||
|
|
||||||
**Tagging Deadline:**
|
**Tagging Deadline:**
|
||||||
|
|
||||||
**ASN Deadline:**
|
|
||||||
|
|
||||||
**Public Release:**
|
**Public Release:**
|
||||||
|
|
||||||
## Release Checklist
|
## Release Checklist
|
||||||
@@ -12,6 +10,7 @@
|
|||||||
|
|
||||||
- [ ] ***(QA)*** Check whether all issues assigned to the release milestone are resolved[^1].
|
- [ ] ***(QA)*** Check whether all issues assigned to the release milestone are resolved[^1].
|
||||||
- [ ] ***(QA)*** Ensure that there are no outstanding merge requests in the private repository[^1] (Subscription Edition only).
|
- [ ] ***(QA)*** Ensure that there are no outstanding merge requests in the private repository[^1] (Subscription Edition only).
|
||||||
|
- [ ] ***(QA)*** Ensure all merge requests marked for backporting have been indeed backported.
|
||||||
|
|
||||||
## Before the Tagging Deadline
|
## Before the Tagging Deadline
|
||||||
|
|
||||||
@@ -33,21 +32,22 @@
|
|||||||
|
|
||||||
## Before the ASN Deadline (for ASN Releases) or the Public Release Date (for Regular Releases)
|
## Before the ASN Deadline (for ASN Releases) or the Public Release Date (for Regular Releases)
|
||||||
|
|
||||||
- [ ] ***(QA)*** Run the `make release` Jenkins jobs to produce the tarballs and zips.
|
- [ ] ***(QA)*** Verify GitLab CI results for the tags created and prepare a QA report for the releases to be published.
|
||||||
- [ ] ***(QA)*** Verify the results of `make release` Jenkins jobs and prepare a QA report for the releases to be published.
|
- [ ] ***(QA)*** Request signatures for the tarballs, providing their location and checksums.
|
||||||
- [ ] ***(QA)*** Request signatures for the tarballs.
|
- [ ] ***(Signers)*** Validate tarball checksums, sign tarballs, and upload signatures.
|
||||||
- [ ] ***(Signers)*** Sign the tarballs.
|
- [ ] ***(QA)*** Verify tarball signatures and check tarball checksums again.
|
||||||
- [ ] ***(QA)*** Check tarball signatures.
|
|
||||||
- [ ] ***(QA)*** Notify Support that the releases are ready for publication.
|
|
||||||
- [ ] ***(Support)*** Pre-publish ASN and/or Subscription Edition tarballs so that packages can be built.
|
- [ ] ***(Support)*** Pre-publish ASN and/or Subscription Edition tarballs so that packages can be built.
|
||||||
- [ ] ***(QA)*** Build and test ASN and/or Subscription Edition packages.
|
- [ ] ***(QA)*** Build and test ASN and/or Subscription Edition packages.
|
||||||
|
- [ ] ***(QA)*** Notify Support that the releases have been prepared.
|
||||||
- [ ] ***(Support)*** Send out ASNs (if applicable).
|
- [ ] ***(Support)*** Send out ASNs (if applicable).
|
||||||
|
|
||||||
## On the Day of Public Release
|
## On the Day of Public Release
|
||||||
|
|
||||||
- [ ] ***(Support)*** Publish the releases according to the release schedule.
|
- [ ] ***(Support)*** Wait for clearance from Security Officer to proceed with the public release (if applicable).
|
||||||
- [ ] ***(Support)*** Write release email to *bind9-announce*.
|
- [ ] ***(Support)*** Place tarballs in public location on FTP site.
|
||||||
- [ ] ***(Support)*** Write email to *bind9-users* (if a major release).
|
- [ ] ***(Support)*** Publish links to downloads on ISC website.
|
||||||
|
- [ ] ***(Support)*** Write release email to *bind-announce*.
|
||||||
|
- [ ] ***(Support)*** Write email to *bind-users* (if a major release).
|
||||||
- [ ] ***(Support)*** Update tickets in case of waiting support customers.
|
- [ ] ***(Support)*** Update tickets in case of waiting support customers.
|
||||||
- [ ] ***(QA)*** Build and test any outstanding private packages.
|
- [ ] ***(QA)*** Build and test any outstanding private packages.
|
||||||
- [ ] ***(QA)*** Build public packages (`*.deb`, RPMs).
|
- [ ] ***(QA)*** Build public packages (`*.deb`, RPMs).
|
||||||
|
|||||||
@@ -1,3 +1,136 @@
|
|||||||
|
5354. [bug] dnssec-policy created new KSK keys when zone is in
|
||||||
|
initial stage of signing (the DS is not yet in
|
||||||
|
rumoured or omnipresent state). Fix by checking
|
||||||
|
key goals rather than active state when determining
|
||||||
|
new keys are needed. [GL #1593]
|
||||||
|
|
||||||
|
5353. [doc] Document port and dscp parameters in forwarders
|
||||||
|
configuration option. [GL !914]
|
||||||
|
|
||||||
|
5352. [bug] Correctly handle catalog zone entries containing
|
||||||
|
characters that aren't legal in filenames. [GL #1592]
|
||||||
|
|
||||||
|
5351. [bug] CDS / CDNSKEY consistency checks failed to handle
|
||||||
|
removal records. [GL #1554]
|
||||||
|
|
||||||
|
5350. [bug] When a view was configured with class CHAOS, the
|
||||||
|
server could crash while processing a query for a
|
||||||
|
non-existent record. [GL #1540]
|
||||||
|
|
||||||
|
5349. [bug] Fix a race in task_pause/unpause. [GL #1571]
|
||||||
|
|
||||||
|
5348. [bug] dnssec-settime -Psync was not being honoured.
|
||||||
|
[GL !2893]
|
||||||
|
|
||||||
|
--- 9.15.8 released ---
|
||||||
|
|
||||||
|
5347. [bug] Fixed a bug that could cause an intermittent crash
|
||||||
|
in validator.c when validating a negative cache
|
||||||
|
entry. [GL #1561]
|
||||||
|
|
||||||
|
5346. [bug] Make hazard pointer array allocations dynamic, fixing
|
||||||
|
a bug that caused named to crash on machines with more
|
||||||
|
than 40 cores. [GL #1493]
|
||||||
|
|
||||||
|
5345. [func] Key-style trust anchors and DS-style trust anchors
|
||||||
|
can now both be used for the same name. [GL #1237]
|
||||||
|
|
||||||
|
5344. [bug] Handle accept() errors properly in netmgr. [GL !2880]
|
||||||
|
|
||||||
|
5343. [func] Add statistics counters to the netmgr. [GL #1311]
|
||||||
|
|
||||||
|
5342. [bug] Disable pktinfo for IPv6 and bind to each interface
|
||||||
|
explicitly instead, because libuv doesn't support
|
||||||
|
pktinfo control messages. [GL #1558]
|
||||||
|
|
||||||
|
5341. [func] Simplify passing the bound TCP socket to child
|
||||||
|
threads by using isc_uv_export/import functions.
|
||||||
|
[GL !2825]
|
||||||
|
|
||||||
|
5340. [bug] Don't deadlock when binding to a TCP socket fails.
|
||||||
|
[GL #1499]
|
||||||
|
|
||||||
|
5339. [bug] With some libmaxminddb versions, named could erroneously
|
||||||
|
match an IP address not belonging to any subnet defined
|
||||||
|
in a given GeoIP2 database to one of the existing
|
||||||
|
entries in that database. [GL #1552]
|
||||||
|
|
||||||
|
5338. [bug] Fix line spacing in `rndc secroots`.
|
||||||
|
Thanks to Tony Finch. [GL !2478]
|
||||||
|
|
||||||
|
5337. [func] 'named -V' now reports maxminddb and protobuf-c
|
||||||
|
versions. [GL !2686]
|
||||||
|
|
||||||
|
--- 9.15.7 released ---
|
||||||
|
|
||||||
|
5336. [bug] The TCP high-water statistic could report an
|
||||||
|
incorrect value on startup. [GL #1392]
|
||||||
|
|
||||||
|
5335. [func] Make TCP listening code multithreaded. [GL !2659]
|
||||||
|
|
||||||
|
5334. [doc] Update documentation with dnssec-policy clarifications.
|
||||||
|
Also change some defaults. [GL !2711]
|
||||||
|
|
||||||
|
5333. [bug] Fix duration printing on Solaris when value is not
|
||||||
|
an ISO 8601 duration. [GL #1460]
|
||||||
|
|
||||||
|
5332. [func] Renamed "dnssec-keys" configuration statement
|
||||||
|
to the more descriptive "trust-anchors". [GL !2702]
|
||||||
|
|
||||||
|
5331. [func] Use compiler-provided mechanisms for thread local
|
||||||
|
storage, and make the requirement for such mechanisms
|
||||||
|
explicit in configure. [GL #1444]
|
||||||
|
|
||||||
|
5330. [bug] 'configure --without-python' was ineffective if
|
||||||
|
PYTHON was set in the environment. [GL #1434]
|
||||||
|
|
||||||
|
5329. [bug] Reconfiguring named caused memory to be leaked when any
|
||||||
|
GeoIP2 database was in use. [GL #1445]
|
||||||
|
|
||||||
|
5328. [bug] rbtdb.c:rdataset_{get,set}ownercase failed to obtain
|
||||||
|
a node lock. [GL #1417]
|
||||||
|
|
||||||
|
5327. [func] Added a statistics counter to track queries
|
||||||
|
dropped because the recursive-clients quota was
|
||||||
|
exceeded. [GL #1399]
|
||||||
|
|
||||||
|
5326. [bug] Add Python dependency on 'distutils.core' to configure.
|
||||||
|
'distutils.core' is required for installation.
|
||||||
|
[GL #1397]
|
||||||
|
|
||||||
|
5325. [bug] Addressed several issues with TCP connections in
|
||||||
|
the netmgr: restored support for TCP connection
|
||||||
|
timeouts, restored TCP backlog support, actively
|
||||||
|
close all open sockets during shutdown. [GL #1312]
|
||||||
|
|
||||||
|
5324. [bug] Change the category of some log messages from general
|
||||||
|
to the more appopriate catergory of xfer-in. [GL #1394]
|
||||||
|
|
||||||
|
5323. [bug] Fix a bug in DNSSEC trust anchor verification.
|
||||||
|
[GL !2609]
|
||||||
|
|
||||||
|
5322. [placeholder]
|
||||||
|
|
||||||
|
5321. [bug] Obtain write lock before updating version->records
|
||||||
|
and version->bytes. [GL #1341]
|
||||||
|
|
||||||
|
5320. [cleanup] Silence TSAN on header->count. [GL #1344]
|
||||||
|
|
||||||
|
--- 9.15.6 released ---
|
||||||
|
|
||||||
|
5319. [func] Trust anchors can now be configured using DS
|
||||||
|
format to represent a key digest, by using the
|
||||||
|
new "initial-ds" or "static-ds" keywords in
|
||||||
|
the "dnssec-keys" statement.
|
||||||
|
|
||||||
|
Note: DNSKEY-format and DS-format trust anchors
|
||||||
|
cannot both be used for the same domain name.
|
||||||
|
[GL #622]
|
||||||
|
|
||||||
|
5318. [cleanup] The DNSSEC validation code has been refactored
|
||||||
|
for clarity and to reduce code duplication.
|
||||||
|
[GL #622]
|
||||||
|
|
||||||
5317. [func] A new asynchronous network communications system
|
5317. [func] A new asynchronous network communications system
|
||||||
based on libuv is now used for listening for
|
based on libuv is now used for listening for
|
||||||
incoming requests and responding to them. (The
|
incoming requests and responding to them. (The
|
||||||
@@ -49,7 +182,8 @@
|
|||||||
5307. [bug] Fix hang when named-compilezone output is sent to pipe.
|
5307. [bug] Fix hang when named-compilezone output is sent to pipe.
|
||||||
Thanks to Tony Finch. [GL !2481]
|
Thanks to Tony Finch. [GL !2481]
|
||||||
|
|
||||||
5306. [placeholder]
|
5306. [security] Set a limit on number of simultaneous pipelined TCP
|
||||||
|
queries. (CVE-2019-6477) [GL #1264]
|
||||||
|
|
||||||
5305. [bug] NSEC Aggressive Cache ("synth-from-dnssec") has been
|
5305. [bug] NSEC Aggressive Cache ("synth-from-dnssec") has been
|
||||||
disabled by default because it was found to have
|
disabled by default because it was found to have
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
Copyright (C) 1996-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright (C) 1996-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
|
||||||
This Source Code Form is subject to the terms of the Mozilla Public
|
This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
License, v. 2.0. If a copy of the MPL was not distributed with this
|
License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
+1
-1
@@ -150,7 +150,7 @@ releases. New features include:
|
|||||||
- "rndc modzone" reconfigures a single zone, without requiring the entire
|
- "rndc modzone" reconfigures a single zone, without requiring the entire
|
||||||
server to be reconfigured.
|
server to be reconfigured.
|
||||||
- "rndc showzone" displays the current configuration of a zone.
|
- "rndc showzone" displays the current configuration of a zone.
|
||||||
- "rndc managed-keys" can be used to check the status of RFC 5001 managed
|
- "rndc managed-keys" can be used to check the status of RFC 5011 managed
|
||||||
trust anchors, or to force trust anchors to be refreshed.
|
trust anchors, or to force trust anchors to be refreshed.
|
||||||
- "max-cache-size" can now be set to a percentage of available memory. The
|
- "max-cache-size" can now be set to a percentage of available memory. The
|
||||||
default is 90%.
|
default is 90%.
|
||||||
|
|||||||
@@ -4,16 +4,29 @@ Supported platforms
|
|||||||
|
|
||||||
In general, this version of BIND will build and run on any POSIX-compliant
|
In general, this version of BIND will build and run on any POSIX-compliant
|
||||||
system with a C11-compliant C compiler, BSD-style sockets with
|
system with a C11-compliant C compiler, BSD-style sockets with
|
||||||
RFC-compliant IPv6 support, POSIX-compliant threads, and the OpenSSL
|
RFC-compliant IPv6 support, POSIX-compliant threads, the libuv
|
||||||
cryptography library. Atomic operations support from the compiler is
|
asynchronous I/O library, and the OpenSSL cryptography library.
|
||||||
needed, either in the form of builtin operations, C11 atomics or the
|
|
||||||
Interlocked family of functions on Windows.
|
|
||||||
|
|
||||||
BIND 9.15 requires fairly recent version of libuv library to run (>= 1.x).
|
The following C11 features are used in BIND 9:
|
||||||
For some of the older systems listed below, you will have to install
|
|
||||||
updated libuv package from sources such as EPEL, PPA and other native
|
* Atomic operations support from the compiler is needed, either in the
|
||||||
sources for updated packages. The other option is to install libuv from
|
form of builtin operations, C11 atomics, or the Interlocked family of
|
||||||
sources.
|
functions on Windows.
|
||||||
|
|
||||||
|
* Thread Local Storage support from the compiler is needed, either in
|
||||||
|
the form of C11 _Thread_local/thread_local, the __thread GCC
|
||||||
|
extension, or the __declspec(thread) MSVC extension on Windows.
|
||||||
|
|
||||||
|
BIND 9.15 requires a fairly recent version of libuv (at least 1.x). For
|
||||||
|
some of the older systems listed below, you will have to install an
|
||||||
|
updated libuv package from sources such as EPEL, PPA, or other native
|
||||||
|
sources for updated packages. The other option is to build and install
|
||||||
|
libuv from source.
|
||||||
|
|
||||||
|
Certain optional BIND features have additional library dependencies. These
|
||||||
|
include libxml2 and libjson-c for statistics, libmaxminddb for
|
||||||
|
geolocation, libfstrm and libprotobuf-c for DNSTAP, and libidn2 for
|
||||||
|
internationalized domain name conversion.
|
||||||
|
|
||||||
ISC regularly tests BIND on many operating systems and architectures, but
|
ISC regularly tests BIND on many operating systems and architectures, but
|
||||||
lacks the resources to test all of them. Consequently, ISC is only able to
|
lacks the resources to test all of them. Consequently, ISC is only able to
|
||||||
@@ -21,15 +34,15 @@ offer support on a "best effort" basis for some.
|
|||||||
|
|
||||||
Regularly tested platforms
|
Regularly tested platforms
|
||||||
|
|
||||||
As of Dec 2019, BIND 9.15 is fully supported and regularly tested on the
|
As of Feb 2020, BIND 9.15 is fully supported and regularly tested on the
|
||||||
following systems:
|
following systems:
|
||||||
|
|
||||||
* Debian 9, 10
|
* Debian 9, 10
|
||||||
* Ubuntu LTS 16.04, 18.04
|
* Ubuntu LTS 16.04, 18.04
|
||||||
* Fedora 30
|
* Fedora 31
|
||||||
* Red Hat Enterprise Linux / CentOS 7, 8
|
* Red Hat Enterprise Linux / CentOS 7, 8
|
||||||
* FreeBSD 11.3, 12.0
|
* FreeBSD 11.3, 12.0
|
||||||
* OpenBSD 6.5
|
* OpenBSD 6.6
|
||||||
* Alpine Linux
|
* Alpine Linux
|
||||||
|
|
||||||
The amd64, i386, armhf and arm64 CPU architectures are all fully
|
The amd64, i386, armhf and arm64 CPU architectures are all fully
|
||||||
@@ -57,10 +70,10 @@ Server 2012 R2, none of these are tested regularly by ISC.
|
|||||||
|
|
||||||
Community maintained
|
Community maintained
|
||||||
|
|
||||||
These systems may not all have easily available the required dependencies
|
These systems may not all have the required dependencies for building BIND
|
||||||
for building BIND although it will be possible in many cases to compile
|
easily available, although it will be possible in many cases to compile
|
||||||
those directly from source. The community and interested parties may wish
|
those directly from source. The community and interested parties may wish
|
||||||
to help with maintenance and we welcome patch contributions, although we
|
to help with maintenance, and we welcome patch contributions, although we
|
||||||
cannot guarantee that we will accept them. All contributions will be
|
cannot guarantee that we will accept them. All contributions will be
|
||||||
assessed against the risk of adverse effect on officially supported
|
assessed against the risk of adverse effect on officially supported
|
||||||
platforms.
|
platforms.
|
||||||
@@ -83,6 +96,4 @@ These are platforms on which BIND 9.15 is known not to build or run:
|
|||||||
* Platforms that don't support atomic operations (via compiler or
|
* Platforms that don't support atomic operations (via compiler or
|
||||||
library)
|
library)
|
||||||
* Linux without NPTL (Native POSIX Thread Library)
|
* Linux without NPTL (Native POSIX Thread Library)
|
||||||
* Platforms where libuv cannot be compiled
|
* Platforms on which libuv cannot be compiled
|
||||||
|
|
||||||
Platform quirks
|
|
||||||
|
|||||||
+33
-20
@@ -12,15 +12,29 @@
|
|||||||
|
|
||||||
In general, this version of BIND will build and run on any POSIX-compliant
|
In general, this version of BIND will build and run on any POSIX-compliant
|
||||||
system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant
|
system with a C11-compliant C compiler, BSD-style sockets with RFC-compliant
|
||||||
IPv6 support, POSIX-compliant threads, and the OpenSSL cryptography library.
|
IPv6 support, POSIX-compliant threads, the `libuv` asynchronous I/O library,
|
||||||
Atomic operations support from the compiler is needed, either in the form of
|
and the OpenSSL cryptography library.
|
||||||
builtin operations, C11 atomics or the Interlocked family of functions on
|
|
||||||
Windows.
|
|
||||||
|
|
||||||
BIND 9.15 requires fairly recent version of libuv library to run (>= 1.x). For
|
The following C11 features are used in BIND 9:
|
||||||
some of the older systems listed below, you will have to install updated libuv
|
|
||||||
package from sources such as EPEL, PPA and other native sources for updated
|
* Atomic operations support from the compiler is needed, either in the form of
|
||||||
packages. The other option is to install libuv from sources.
|
builtin operations, C11 atomics, or the `Interlocked` family of functions on
|
||||||
|
Windows.
|
||||||
|
|
||||||
|
* Thread Local Storage support from the compiler is needed, either in the form
|
||||||
|
of C11 `_Thread_local`/`thread_local`, the `__thread` GCC extension, or
|
||||||
|
the `__declspec(thread)` MSVC extension on Windows.
|
||||||
|
|
||||||
|
BIND 9.15 requires a fairly recent version of `libuv` (at least 1.x). For
|
||||||
|
some of the older systems listed below, you will have to install an updated
|
||||||
|
`libuv` package from sources such as EPEL, PPA, or other native sources for
|
||||||
|
updated packages. The other option is to build and install `libuv` from
|
||||||
|
source.
|
||||||
|
|
||||||
|
Certain optional BIND features have additional library dependencies.
|
||||||
|
These include `libxml2` and `libjson-c` for statistics, `libmaxminddb` for
|
||||||
|
geolocation, `libfstrm` and `libprotobuf-c` for DNSTAP, and `libidn2` for
|
||||||
|
internationalized domain name conversion.
|
||||||
|
|
||||||
ISC regularly tests BIND on many operating systems and architectures, but
|
ISC regularly tests BIND on many operating systems and architectures, but
|
||||||
lacks the resources to test all of them. Consequently, ISC is only able to
|
lacks the resources to test all of them. Consequently, ISC is only able to
|
||||||
@@ -28,15 +42,15 @@ offer support on a "best effort" basis for some.
|
|||||||
|
|
||||||
### Regularly tested platforms
|
### Regularly tested platforms
|
||||||
|
|
||||||
As of Dec 2019, BIND 9.15 is fully supported and regularly tested on the
|
As of Feb 2020, BIND 9.15 is fully supported and regularly tested on the
|
||||||
following systems:
|
following systems:
|
||||||
|
|
||||||
* Debian 9, 10
|
* Debian 9, 10
|
||||||
* Ubuntu LTS 16.04, 18.04
|
* Ubuntu LTS 16.04, 18.04
|
||||||
* Fedora 30
|
* Fedora 31
|
||||||
* Red Hat Enterprise Linux / CentOS 7, 8
|
* Red Hat Enterprise Linux / CentOS 7, 8
|
||||||
* FreeBSD 11.3, 12.0
|
* FreeBSD 11.3, 12.0
|
||||||
* OpenBSD 6.5
|
* OpenBSD 6.6
|
||||||
* Alpine Linux
|
* Alpine Linux
|
||||||
|
|
||||||
The amd64, i386, armhf and arm64 CPU architectures are all fully supported.
|
The amd64, i386, armhf and arm64 CPU architectures are all fully supported.
|
||||||
@@ -63,12 +77,13 @@ Server 2012 R2, none of these are tested regularly by ISC.
|
|||||||
|
|
||||||
### Community maintained
|
### Community maintained
|
||||||
|
|
||||||
These systems may not all have easily available the required dependencies for
|
These systems may not all have the required dependencies for building BIND
|
||||||
building BIND although it will be possible in many cases to compile those
|
easily available, although it will be possible in many cases to compile
|
||||||
directly from source. The community and interested parties may wish to help with
|
those directly from source. The community and interested parties may wish
|
||||||
maintenance and we welcome patch contributions, although we cannot guarantee
|
to help with maintenance, and we welcome patch contributions, although we
|
||||||
that we will accept them. All contributions will be assessed against the risk
|
cannot guarantee that we will accept them. All contributions will be
|
||||||
of adverse effect on officially supported platforms.
|
assessed against the risk of adverse effect on officially supported
|
||||||
|
platforms.
|
||||||
|
|
||||||
* Platforms past or close to their respective EOL dates, such as:
|
* Platforms past or close to their respective EOL dates, such as:
|
||||||
* Ubuntu 14.04, 18.10
|
* Ubuntu 14.04, 18.10
|
||||||
@@ -87,6 +102,4 @@ These are platforms on which BIND 9.15 is known *not* to build or run:
|
|||||||
* Platforms that don't support IPv6 Advanced Socket API (RFC 3542)
|
* Platforms that don't support IPv6 Advanced Socket API (RFC 3542)
|
||||||
* Platforms that don't support atomic operations (via compiler or library)
|
* Platforms that don't support atomic operations (via compiler or library)
|
||||||
* Linux without NPTL (Native POSIX Thread Library)
|
* Linux without NPTL (Native POSIX Thread Library)
|
||||||
* Platforms where libuv cannot be compiled
|
* Platforms on which `libuv` cannot be compiled
|
||||||
|
|
||||||
## Platform quirks
|
|
||||||
|
|||||||
@@ -48,8 +48,8 @@ the file HISTORY.
|
|||||||
For a detailed list of changes made throughout the history of BIND 9, see
|
For a detailed list of changes made throughout the history of BIND 9, see
|
||||||
the file CHANGES. See below for details on the CHANGES file format.
|
the file CHANGES. See below for details on the CHANGES file format.
|
||||||
|
|
||||||
For up-to-date release notes and errata, see http://www.isc.org/software/
|
For up-to-date versions and release notes, see https://www.isc.org/
|
||||||
bind9/releasenotes
|
download/.
|
||||||
|
|
||||||
For information about supported platforms, see PLATFORMS.
|
For information about supported platforms, see PLATFORMS.
|
||||||
|
|
||||||
@@ -111,28 +111,33 @@ BIND 9.15 features
|
|||||||
BIND 9.15 is the newest development branch of BIND 9. It includes a number
|
BIND 9.15 is the newest development branch of BIND 9. It includes a number
|
||||||
of changes from BIND 9.14 and earlier releases. New features include:
|
of changes from BIND 9.14 and earlier releases. New features include:
|
||||||
|
|
||||||
* Support for the new GeoIP2 geolocation API
|
* New dnssec-policy statement to configure a key and signing policy for
|
||||||
* Improved DNSSEC key configuration using dnssec-keys
|
zones, enabling automatic key regeneration and rollover.
|
||||||
|
* New network manager based on libuv.
|
||||||
|
* Added support for the new GeoIP2 geolocation API, libmaxminddb.
|
||||||
|
* Improved DNSSEC trust anchor configuration using the trust-anchors
|
||||||
|
statement, permitting configuration of trust anchors in DS as well as
|
||||||
|
DNSKEY format.
|
||||||
* YAML output for dig, mdig, and delv.
|
* YAML output for dig, mdig, and delv.
|
||||||
|
|
||||||
Building BIND
|
Building BIND
|
||||||
|
|
||||||
Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
||||||
basic POSIX support, and a 64-bit integer type. Successful builds have
|
basic POSIX support, and a 64-bit integer type. BIND also requires the
|
||||||
been observed on many versions of Linux and UNIX, including RHEL/CentOS,
|
libuv asynchronous I/O library, and a cryptography provider library such
|
||||||
Fedora, Debian, Ubuntu, SLES, openSUSE, Slackware, Alpine, FreeBSD,
|
as OpenSSL or a hardware service module supporting PKCS#11. On Linux, BIND
|
||||||
NetBSD, OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE, HP-UX, and
|
requires the libcap library to set process privileges, though this
|
||||||
OpenWRT.
|
requirement can be overridden by disabling capability support at compile
|
||||||
|
time. See Compile-time options below for details on other libraries that
|
||||||
|
may be required to support optional features.
|
||||||
|
|
||||||
BIND requires a cryptography provider library such as OpenSSL or a
|
Successful builds have been observed on many versions of Linux and UNIX,
|
||||||
hardware service module supporting PKCS#11. On Linux, BIND requires the
|
including RHEL/CentOS, Fedora, Debian, Ubuntu, SLES, openSUSE, Slackware,
|
||||||
libcap library to set process privileges, though this requirement can be
|
Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE,
|
||||||
overridden by disabling capability support at compile time. See
|
HP-UX, and OpenWRT.
|
||||||
Compile-time options below for details on other libraries that may be
|
|
||||||
required to support optional features.
|
|
||||||
|
|
||||||
BIND is also available for Windows Server 2008 and higher. See win32utils/
|
BIND is also available for Windows Server 2012 R2 and higher. See
|
||||||
build.txt for details on building for Windows systems.
|
win32utils/build.txt for details on building for Windows systems.
|
||||||
|
|
||||||
To build on a UNIX or Linux system, use:
|
To build on a UNIX or Linux system, use:
|
||||||
|
|
||||||
@@ -175,9 +180,10 @@ Dependencies
|
|||||||
|
|
||||||
Portions of BIND that are written in Python, including dnssec-keymgr,
|
Portions of BIND that are written in Python, including dnssec-keymgr,
|
||||||
dnssec-coverage, dnssec-checkds, and some of the system tests, require the
|
dnssec-coverage, dnssec-checkds, and some of the system tests, require the
|
||||||
argparse and ply modules to be available. argparse is a standard module as
|
argparse, ply and distutils.core modules to be available. argparse is a
|
||||||
of Python 2.7 and Python 3.2. ply is available from https://
|
standard module as of Python 2.7 and Python 3.2. ply is available from
|
||||||
pypi.python.org/pypi/ply.
|
https://pypi.python.org/pypi/ply. distutils.core is required for
|
||||||
|
installation.
|
||||||
|
|
||||||
Compile-time options
|
Compile-time options
|
||||||
|
|
||||||
|
|||||||
@@ -57,8 +57,8 @@ For a detailed list of changes made throughout the history of BIND 9, see
|
|||||||
the file [CHANGES](CHANGES). See [below](#changes) for details on the
|
the file [CHANGES](CHANGES). See [below](#changes) for details on the
|
||||||
CHANGES file format.
|
CHANGES file format.
|
||||||
|
|
||||||
For up-to-date release notes and errata, see
|
For up-to-date versions and release notes, see
|
||||||
[http://www.isc.org/software/bind9/releasenotes](http://www.isc.org/software/bind9/releasenotes)
|
[https://www.isc.org/download/](https://www.isc.org/download/).
|
||||||
|
|
||||||
For information about supported platforms, see [PLATFORMS](PLATFORMS.md).
|
For information about supported platforms, see [PLATFORMS](PLATFORMS.md).
|
||||||
|
|
||||||
@@ -127,29 +127,33 @@ BIND 9.15 is the newest development branch of BIND 9. It includes a
|
|||||||
number of changes from BIND 9.14 and earlier releases. New features
|
number of changes from BIND 9.14 and earlier releases. New features
|
||||||
include:
|
include:
|
||||||
|
|
||||||
* New "dnssec-policy" statement to configure a key and signing policy
|
* New `dnssec-policy` statement to configure a key and signing policy
|
||||||
for zones, enabling automatic key regeneration and rollover.
|
for zones, enabling automatic key regeneration and rollover.
|
||||||
* A new network manager based on libuv.
|
* New network manager based on libuv.
|
||||||
* Support for the new GeoIP2 geolocation API
|
* Added support for the new GeoIP2 geolocation API, `libmaxminddb`.
|
||||||
* Improved DNSSEC trust anchor configuration using `dnssec-keys`
|
* Improved DNSSEC trust anchor configuration using the `trust-anchors`
|
||||||
|
statement, permitting configuration of trust anchors in DS as well as
|
||||||
|
DNSKEY format.
|
||||||
* YAML output for `dig`, `mdig`, and `delv`.
|
* YAML output for `dig`, `mdig`, and `delv`.
|
||||||
|
|
||||||
### <a name="build"/> Building BIND
|
### <a name="build"/> Building BIND
|
||||||
|
|
||||||
Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
Minimally, BIND requires a UNIX or Linux system with an ANSI C compiler,
|
||||||
basic POSIX support, and a 64-bit integer type. Successful builds have been
|
basic POSIX support, and a 64-bit integer type. BIND also requires the
|
||||||
observed on many versions of Linux and UNIX, including RHEL/CentOS, Fedora,
|
`libuv` asynchronous I/O library, and a cryptography provider library
|
||||||
Debian, Ubuntu, SLES, openSUSE, Slackware, Alpine, FreeBSD, NetBSD,
|
such as OpenSSL or a hardware service module supporting PKCS#11. On
|
||||||
OpenBSD, macOS, Solaris, OpenIndiana, OmniOS CE, HP-UX, and OpenWRT.
|
Linux, BIND requires the `libcap` library to set process privileges,
|
||||||
|
though this requirement can be overridden by disabling capability
|
||||||
|
support at compile time. See [Compile-time options](#opts) below
|
||||||
|
for details on other libraries that may be required to support
|
||||||
|
optional features.
|
||||||
|
|
||||||
BIND requires a cryptography provider library such as OpenSSL or a
|
Successful builds have been observed on many versions of Linux and
|
||||||
hardware service module supporting PKCS#11. On Linux, BIND requires
|
UNIX, including RHEL/CentOS, Fedora, Debian, Ubuntu, SLES, openSUSE,
|
||||||
the `libcap` library to set process privileges, though this requirement
|
Slackware, Alpine, FreeBSD, NetBSD, OpenBSD, macOS, Solaris,
|
||||||
can be overridden by disabling capability support at compile time.
|
OpenIndiana, OmniOS CE, HP-UX, and OpenWRT.
|
||||||
See [Compile-time options](#opts) below for details on other libraries
|
|
||||||
that may be required to support optional features.
|
|
||||||
|
|
||||||
BIND is also available for Windows Server 2008 and higher. See
|
BIND is also available for Windows Server 2012 R2 and higher. See
|
||||||
`win32utils/build.txt` for details on building for Windows
|
`win32utils/build.txt` for details on building for Windows
|
||||||
systems.
|
systems.
|
||||||
|
|
||||||
@@ -187,9 +191,11 @@ or if you have Xcode already installed you can run `xcode-select --install`.
|
|||||||
|
|
||||||
Portions of BIND that are written in Python, including
|
Portions of BIND that are written in Python, including
|
||||||
`dnssec-keymgr`, `dnssec-coverage`, `dnssec-checkds`, and some of the
|
`dnssec-keymgr`, `dnssec-coverage`, `dnssec-checkds`, and some of the
|
||||||
system tests, require the `argparse` and `ply` modules to be available.
|
system tests, require the `argparse`, `ply` and `distutils.core` modules
|
||||||
|
to be available.
|
||||||
`argparse` is a standard module as of Python 2.7 and Python 3.2.
|
`argparse` is a standard module as of Python 2.7 and Python 3.2.
|
||||||
`ply` is available from [https://pypi.python.org/pypi/ply](https://pypi.python.org/pypi/ply).
|
`ply` is available from [https://pypi.python.org/pypi/ply](https://pypi.python.org/pypi/ply).
|
||||||
|
`distutils.core` is required for installation.
|
||||||
|
|
||||||
#### <a name="opts"/> Compile-time options
|
#### <a name="opts"/> Compile-time options
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -148,5 +148,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -709,8 +709,6 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
cfg_parser_destroy(&parser);
|
cfg_parser_destroy(&parser);
|
||||||
|
|
||||||
dns_name_destroy();
|
|
||||||
|
|
||||||
isc_log_destroy(&logc);
|
isc_log_destroy(&logc);
|
||||||
|
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|||||||
@@ -41,6 +41,7 @@
|
|||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2002, 2004, 2005, 2007, 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2002, 2004-2007, 2009-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2002, 2004-2007, 2009-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -325,5 +325,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2002, 2004-2007, 2009-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2002, 2004-2007, 2009-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -85,9 +85,9 @@ usage(void) {
|
|||||||
|
|
||||||
static void
|
static void
|
||||||
destroy(void) {
|
destroy(void) {
|
||||||
if (zone != NULL)
|
if (zone != NULL) {
|
||||||
dns_zone_detach(&zone);
|
dns_zone_detach(&zone);
|
||||||
dns_name_destroy();
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/*% main processing routine */
|
/*% main processing routine */
|
||||||
|
|||||||
@@ -44,6 +44,7 @@
|
|||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2002, 2004-2007, 2009-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2002, 2004-2007, 2009-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -144,5 +144,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -38,6 +38,7 @@
|
|||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -206,5 +206,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2001, 2003-2005, 2007, 2009, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -45,6 +45,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2001, 2003-2005, 2007, 2009, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
+3
-3
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -144,7 +144,7 @@ options\&.
|
|||||||
Note: When reading the trust anchor file,
|
Note: When reading the trust anchor file,
|
||||||
\fBdelv\fR
|
\fBdelv\fR
|
||||||
treats
|
treats
|
||||||
\fBdnssec\-keys\fR\fBinitial\-key\fR
|
\fBtrust\-anchors\fR\fBinitial\-key\fR
|
||||||
and
|
and
|
||||||
\fBstatic\-key\fR
|
\fBstatic\-key\fR
|
||||||
entries identically\&. That is, even if a key is configured with
|
entries identically\&. That is, even if a key is configured with
|
||||||
@@ -433,5 +433,5 @@ RFC5155\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+147
-63
@@ -33,8 +33,10 @@
|
|||||||
#include <isc/app.h>
|
#include <isc/app.h>
|
||||||
#include <isc/base64.h>
|
#include <isc/base64.h>
|
||||||
#include <isc/buffer.h>
|
#include <isc/buffer.h>
|
||||||
|
#include <isc/hex.h>
|
||||||
#include <isc/lib.h>
|
#include <isc/lib.h>
|
||||||
#include <isc/log.h>
|
#include <isc/log.h>
|
||||||
|
#include <isc/md.h>
|
||||||
#include <isc/mem.h>
|
#include <isc/mem.h>
|
||||||
#ifdef WIN32
|
#ifdef WIN32
|
||||||
#include <isc/ntpaths.h>
|
#include <isc/ntpaths.h>
|
||||||
@@ -138,7 +140,7 @@ static dns_fixedname_t afn;
|
|||||||
static dns_name_t *anchor_name = NULL;
|
static dns_name_t *anchor_name = NULL;
|
||||||
|
|
||||||
/* Default bind.keys contents */
|
/* Default bind.keys contents */
|
||||||
static char anchortext[] = DNSSEC_KEYS;
|
static char anchortext[] = TRUST_ANCHORS;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Static function prototypes
|
* Static function prototypes
|
||||||
@@ -158,43 +160,44 @@ usage(void) {
|
|||||||
" q-class is one of (in,hs,ch,...) [default: in]\n"
|
" q-class is one of (in,hs,ch,...) [default: in]\n"
|
||||||
" q-type is one of (a,any,mx,ns,soa,hinfo,axfr,txt,...) [default:a]\n"
|
" q-type is one of (a,any,mx,ns,soa,hinfo,axfr,txt,...) [default:a]\n"
|
||||||
" q-opt is one of:\n"
|
" q-opt is one of:\n"
|
||||||
" -x dot-notation (shortcut for reverse lookups)\n"
|
" -4 (use IPv4 query transport only)\n"
|
||||||
" -d level (set debugging level)\n"
|
" -6 (use IPv6 query transport only)\n"
|
||||||
" -a anchor-file (specify root trust anchor)\n"
|
" -a anchor-file (specify root trust anchor)\n"
|
||||||
" -b address[#port] (bind to source address/port)\n"
|
" -b address[#port] (bind to source address/port)\n"
|
||||||
|
" -c class (option included for compatibility;\n"
|
||||||
|
" -d level (set debugging level)\n"
|
||||||
|
" -h (print help and exit)\n"
|
||||||
|
" -i (disable DNSSEC validation)\n"
|
||||||
|
" -m (enable memory usage debugging)\n"
|
||||||
" -p port (specify port number)\n"
|
" -p port (specify port number)\n"
|
||||||
" -q name (specify query name)\n"
|
" -q name (specify query name)\n"
|
||||||
" -t type (specify query type)\n"
|
" -t type (specify query type)\n"
|
||||||
" -c class (option included for compatibility;\n"
|
|
||||||
" only IN is supported)\n"
|
" only IN is supported)\n"
|
||||||
" -4 (use IPv4 query transport only)\n"
|
" -v (print version and exit)\n"
|
||||||
" -6 (use IPv6 query transport only)\n"
|
" -x dot-notation (shortcut for reverse lookups)\n"
|
||||||
" -i (disable DNSSEC validation)\n"
|
|
||||||
" -m (enable memory usage debugging)\n"
|
|
||||||
" d-opt is of the form +keyword[=value], where keyword is:\n"
|
" d-opt is of the form +keyword[=value], where keyword is:\n"
|
||||||
" +[no]all (Set or clear all display flags)\n"
|
" +[no]all (Set or clear all display flags)\n"
|
||||||
" +[no]class (Control display of class)\n"
|
" +[no]class (Control display of class)\n"
|
||||||
|
" +[no]comments (Control display of comment lines)\n"
|
||||||
" +[no]crypto (Control display of cryptographic\n"
|
" +[no]crypto (Control display of cryptographic\n"
|
||||||
" fields in records)\n"
|
" fields in records)\n"
|
||||||
|
" +[no]dlv (Obsolete)\n"
|
||||||
|
" +[no]dnssec (Display DNSSEC records)\n"
|
||||||
|
" +[no]mtrace (Trace messages received)\n"
|
||||||
" +[no]multiline (Print records in an expanded format)\n"
|
" +[no]multiline (Print records in an expanded format)\n"
|
||||||
" +[no]comments (Control display of comment lines)\n"
|
" +[no]root (DNSSEC validation trust anchor)\n"
|
||||||
" +[no]rrcomments (Control display of per-record "
|
" +[no]rrcomments (Control display of per-record "
|
||||||
"comments)\n"
|
"comments)\n"
|
||||||
" +[no]unknownformat (Print RDATA in RFC 3597 "
|
" +[no]rtrace (Trace resolver fetches)\n"
|
||||||
"\"unknown\" format)\n"
|
|
||||||
" +[no]short (Short form answer)\n"
|
" +[no]short (Short form answer)\n"
|
||||||
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
" +[no]split=## (Split hex/base64 fields into chunks)\n"
|
||||||
" +[no]tcp (TCP mode)\n"
|
" +[no]tcp (TCP mode)\n"
|
||||||
" +[no]ttl (Control display of ttls in records)\n"
|
" +[no]ttl (Control display of ttls in records)\n"
|
||||||
" +[no]trust (Control display of trust level)\n"
|
" +[no]trust (Control display of trust level)\n"
|
||||||
" +[no]rtrace (Trace resolver fetches)\n"
|
" +[no]unknownformat (Print RDATA in RFC 3597 "
|
||||||
" +[no]mtrace (Trace messages received)\n"
|
"\"unknown\" format)\n"
|
||||||
" +[no]vtrace (Trace validation process)\n"
|
" +[no]vtrace (Trace validation process)\n"
|
||||||
" +[no]dlv (Obsolete)\n"
|
" +[no]yaml (Present the results as YAML)\n",
|
||||||
" +[no]root (DNSSEC validation trust anchor)\n"
|
|
||||||
" +[no]dnssec (Display DNSSEC records)\n"
|
|
||||||
" -h (print help and exit)\n"
|
|
||||||
" -v (print version and exit)\n",
|
|
||||||
stderr);
|
stderr);
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
@@ -495,14 +498,17 @@ printdata(dns_rdataset_t *rdataset, dns_name_t *owner,
|
|||||||
dns_rdata_reset(&rdata);
|
dns_rdata_reset(&rdata);
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
|
dns_indent_t indent = { " ", 2 };
|
||||||
if (!yaml && (rdataset->attributes &
|
if (!yaml && (rdataset->attributes &
|
||||||
DNS_RDATASETATTR_NEGATIVE) != 0)
|
DNS_RDATASETATTR_NEGATIVE) != 0)
|
||||||
{
|
{
|
||||||
isc_buffer_putstr(&target, "; ");
|
isc_buffer_putstr(&target, "; ");
|
||||||
}
|
}
|
||||||
|
|
||||||
result = dns_master_rdatasettotext(owner, rdataset,
|
result = dns_master_rdatasettotext(owner, rdataset,
|
||||||
style, &target);
|
style,
|
||||||
|
yaml ? &indent :
|
||||||
|
NULL,
|
||||||
|
&target);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (result == ISC_R_NOSPACE) {
|
if (result == ISC_R_NOSPACE) {
|
||||||
@@ -534,8 +540,6 @@ setup_style(dns_master_style_t **stylep) {
|
|||||||
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
||||||
if (yaml) {
|
if (yaml) {
|
||||||
styleflags |= DNS_STYLEFLAG_YAML;
|
styleflags |= DNS_STYLEFLAG_YAML;
|
||||||
dns_master_indentstr = " ";
|
|
||||||
dns_master_indent = 2;
|
|
||||||
} else {
|
} else {
|
||||||
if (showcomments) {
|
if (showcomments) {
|
||||||
styleflags |= DNS_STYLEFLAG_COMMENT;
|
styleflags |= DNS_STYLEFLAG_COMMENT;
|
||||||
@@ -608,11 +612,12 @@ convert_name(dns_fixedname_t *fn, dns_name_t **name, const char *text) {
|
|||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
||||||
dns_rdata_dnskey_t keystruct;
|
dns_rdata_dnskey_t dnskey;
|
||||||
uint32_t flags, proto, alg;
|
dns_rdata_ds_t ds;
|
||||||
const char *keystr, *keynamestr;
|
uint32_t rdata1, rdata2, rdata3;
|
||||||
unsigned char keydata[4096];
|
const char *datastr = NULL, *keynamestr = NULL, *atstr = NULL;
|
||||||
isc_buffer_t keydatabuf;
|
unsigned char data[4096];
|
||||||
|
isc_buffer_t databuf;
|
||||||
unsigned char rrdata[4096];
|
unsigned char rrdata[4096];
|
||||||
isc_buffer_t rrdatabuf;
|
isc_buffer_t rrdatabuf;
|
||||||
isc_region_t r;
|
isc_region_t r;
|
||||||
@@ -620,6 +625,13 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
|||||||
dns_name_t *keyname;
|
dns_name_t *keyname;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
bool match_root = false;
|
bool match_root = false;
|
||||||
|
enum {
|
||||||
|
INITIAL_KEY,
|
||||||
|
STATIC_KEY,
|
||||||
|
INITIAL_DS,
|
||||||
|
STATIC_DS,
|
||||||
|
TRUSTED
|
||||||
|
} anchortype;
|
||||||
|
|
||||||
keynamestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
keynamestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
||||||
CHECK(convert_name(&fkeyname, &keyname, keynamestr));
|
CHECK(convert_name(&fkeyname, &keyname, keynamestr));
|
||||||
@@ -642,46 +654,118 @@ key_fromconfig(const cfg_obj_t *key, dns_client_t *client) {
|
|||||||
|
|
||||||
delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s", trust_anchor);
|
delv_log(ISC_LOG_DEBUG(3), "adding trust anchor %s", trust_anchor);
|
||||||
|
|
||||||
flags = cfg_obj_asuint32(cfg_tuple_get(key, "flags"));
|
/* if DNSKEY, flags; if DS, key tag */
|
||||||
proto = cfg_obj_asuint32(cfg_tuple_get(key, "protocol"));
|
rdata1 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata1"));
|
||||||
alg = cfg_obj_asuint32(cfg_tuple_get(key, "algorithm"));
|
|
||||||
|
|
||||||
keystruct.common.rdclass = dns_rdataclass_in;
|
/* if DNSKEY, protocol; if DS, algorithm */
|
||||||
keystruct.common.rdtype = dns_rdatatype_dnskey;
|
rdata2 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata2"));
|
||||||
/*
|
|
||||||
* The key data in keystruct is not dynamically allocated.
|
|
||||||
*/
|
|
||||||
keystruct.mctx = NULL;
|
|
||||||
|
|
||||||
ISC_LINK_INIT(&keystruct.common, link);
|
/* if DNSKEY, algorithm; if DS, digest type */
|
||||||
|
rdata3 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata3"));
|
||||||
|
|
||||||
if (flags > 0xffff)
|
/* What type of trust anchor is this? */
|
||||||
CHECK(ISC_R_RANGE);
|
atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype"));
|
||||||
if (proto > 0xff)
|
if (strcasecmp(atstr, "static-key") == 0) {
|
||||||
CHECK(ISC_R_RANGE);
|
anchortype = STATIC_KEY;
|
||||||
if (alg > 0xff)
|
} else if (strcasecmp(atstr, "static-ds") == 0) {
|
||||||
CHECK(ISC_R_RANGE);
|
anchortype = STATIC_DS;
|
||||||
|
} else if (strcasecmp(atstr, "initial-key") == 0) {
|
||||||
|
anchortype = INITIAL_KEY;
|
||||||
|
} else if (strcasecmp(atstr, "initial-ds") == 0) {
|
||||||
|
anchortype = INITIAL_DS;
|
||||||
|
} else {
|
||||||
|
delv_log(ISC_LOG_ERROR,
|
||||||
|
"key '%s': invalid initialization method '%s'",
|
||||||
|
keynamestr, atstr);
|
||||||
|
result = ISC_R_FAILURE;
|
||||||
|
goto cleanup;
|
||||||
|
}
|
||||||
|
|
||||||
keystruct.flags = (uint16_t)flags;
|
isc_buffer_init(&databuf, data, sizeof(data));
|
||||||
keystruct.protocol = (uint8_t)proto;
|
|
||||||
keystruct.algorithm = (uint8_t)alg;
|
|
||||||
|
|
||||||
isc_buffer_init(&keydatabuf, keydata, sizeof(keydata));
|
|
||||||
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
|
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
|
||||||
|
|
||||||
keystr = cfg_obj_asstring(cfg_tuple_get(key, "key"));
|
if (rdata1 > 0xffff) {
|
||||||
CHECK(isc_base64_decodestring(keystr, &keydatabuf));
|
CHECK(ISC_R_RANGE);
|
||||||
isc_buffer_usedregion(&keydatabuf, &r);
|
}
|
||||||
keystruct.datalen = r.length;
|
if (rdata2 > 0xff) {
|
||||||
keystruct.data = r.base;
|
CHECK(ISC_R_RANGE);
|
||||||
|
}
|
||||||
|
if (rdata3 > 0xff) {
|
||||||
|
CHECK(ISC_R_RANGE);
|
||||||
|
}
|
||||||
|
|
||||||
CHECK(dns_rdata_fromstruct(NULL,
|
switch (anchortype) {
|
||||||
keystruct.common.rdclass,
|
case STATIC_KEY:
|
||||||
keystruct.common.rdtype,
|
case INITIAL_KEY:
|
||||||
&keystruct, &rrdatabuf));
|
case TRUSTED:
|
||||||
|
dnskey.common.rdclass = dns_rdataclass_in;
|
||||||
|
dnskey.common.rdtype = dns_rdatatype_dnskey;
|
||||||
|
dnskey.mctx = NULL;
|
||||||
|
|
||||||
|
ISC_LINK_INIT(&dnskey.common, link);
|
||||||
|
|
||||||
|
dnskey.flags = (uint16_t)rdata1;
|
||||||
|
dnskey.protocol = (uint8_t)rdata2;
|
||||||
|
dnskey.algorithm = (uint8_t)rdata3;
|
||||||
|
|
||||||
|
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
|
||||||
|
CHECK(isc_base64_decodestring(datastr, &databuf));
|
||||||
|
isc_buffer_usedregion(&databuf, &r);
|
||||||
|
dnskey.datalen = r.length;
|
||||||
|
dnskey.data = r.base;
|
||||||
|
|
||||||
|
CHECK(dns_rdata_fromstruct(NULL, dnskey.common.rdclass,
|
||||||
|
dnskey.common.rdtype,
|
||||||
|
&dnskey, &rrdatabuf));
|
||||||
|
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
||||||
|
dns_rdatatype_dnskey,
|
||||||
|
keyname, &rrdatabuf));
|
||||||
|
break;
|
||||||
|
case INITIAL_DS:
|
||||||
|
case STATIC_DS:
|
||||||
|
ds.common.rdclass = dns_rdataclass_in;
|
||||||
|
ds.common.rdtype = dns_rdatatype_ds;
|
||||||
|
ds.mctx = NULL;
|
||||||
|
|
||||||
|
ISC_LINK_INIT(&ds.common, link);
|
||||||
|
|
||||||
|
ds.key_tag = (uint16_t)rdata1;
|
||||||
|
ds.algorithm = (uint8_t)rdata2;
|
||||||
|
ds.digest_type = (uint8_t)rdata3;
|
||||||
|
|
||||||
|
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
|
||||||
|
CHECK(isc_hex_decodestring(datastr, &databuf));
|
||||||
|
isc_buffer_usedregion(&databuf, &r);
|
||||||
|
|
||||||
|
switch (ds.digest_type) {
|
||||||
|
case DNS_DSDIGEST_SHA1:
|
||||||
|
if (r.length != ISC_SHA1_DIGESTLENGTH) {
|
||||||
|
CHECK(ISC_R_UNEXPECTEDEND);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
case DNS_DSDIGEST_SHA256:
|
||||||
|
if (r.length != ISC_SHA256_DIGESTLENGTH) {
|
||||||
|
CHECK(ISC_R_UNEXPECTEDEND);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
case DNS_DSDIGEST_SHA384:
|
||||||
|
if (r.length != ISC_SHA384_DIGESTLENGTH) {
|
||||||
|
CHECK(ISC_R_UNEXPECTEDEND);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
ds.length = r.length;
|
||||||
|
ds.digest = r.base;
|
||||||
|
|
||||||
|
CHECK(dns_rdata_fromstruct(NULL, ds.common.rdclass,
|
||||||
|
ds.common.rdtype,
|
||||||
|
&ds, &rrdatabuf));
|
||||||
|
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
||||||
|
dns_rdatatype_ds,
|
||||||
|
keyname, &rrdatabuf));
|
||||||
|
};
|
||||||
|
|
||||||
CHECK(dns_client_addtrustedkey(client, dns_rdataclass_in,
|
|
||||||
keyname, &rrdatabuf));
|
|
||||||
num_keys++;
|
num_keys++;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
@@ -735,7 +819,7 @@ setup_dnsseckeys(dns_client_t *client) {
|
|||||||
cfg_parser_t *parser = NULL;
|
cfg_parser_t *parser = NULL;
|
||||||
const cfg_obj_t *trusted_keys = NULL;
|
const cfg_obj_t *trusted_keys = NULL;
|
||||||
const cfg_obj_t *managed_keys = NULL;
|
const cfg_obj_t *managed_keys = NULL;
|
||||||
const cfg_obj_t *dnssec_keys = NULL;
|
const cfg_obj_t *trust_anchors = NULL;
|
||||||
cfg_obj_t *bindkeys = NULL;
|
cfg_obj_t *bindkeys = NULL;
|
||||||
const char *filename = anchorfile;
|
const char *filename = anchorfile;
|
||||||
|
|
||||||
@@ -794,7 +878,7 @@ setup_dnsseckeys(dns_client_t *client) {
|
|||||||
INSIST(bindkeys != NULL);
|
INSIST(bindkeys != NULL);
|
||||||
cfg_map_get(bindkeys, "trusted-keys", &trusted_keys);
|
cfg_map_get(bindkeys, "trusted-keys", &trusted_keys);
|
||||||
cfg_map_get(bindkeys, "managed-keys", &managed_keys);
|
cfg_map_get(bindkeys, "managed-keys", &managed_keys);
|
||||||
cfg_map_get(bindkeys, "dnssec-keys", &dnssec_keys);
|
cfg_map_get(bindkeys, "trust-anchors", &trust_anchors);
|
||||||
|
|
||||||
if (trusted_keys != NULL) {
|
if (trusted_keys != NULL) {
|
||||||
CHECK(load_keys(trusted_keys, client));
|
CHECK(load_keys(trusted_keys, client));
|
||||||
@@ -802,8 +886,8 @@ setup_dnsseckeys(dns_client_t *client) {
|
|||||||
if (managed_keys != NULL) {
|
if (managed_keys != NULL) {
|
||||||
CHECK(load_keys(managed_keys, client));
|
CHECK(load_keys(managed_keys, client));
|
||||||
}
|
}
|
||||||
if (dnssec_keys != NULL) {
|
if (trust_anchors != NULL) {
|
||||||
CHECK(load_keys(dnssec_keys, client));
|
CHECK(load_keys(trust_anchors, client));
|
||||||
}
|
}
|
||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
|
|
||||||
|
|||||||
@@ -40,6 +40,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
@@ -215,7 +216,7 @@
|
|||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
Note: When reading the trust anchor file,
|
Note: When reading the trust anchor file,
|
||||||
<command>delv</command> treats <option>dnssec-keys</option>
|
<command>delv</command> treats <option>trust-anchors</option>
|
||||||
<option>initial-key</option> and <option>static-key</option>
|
<option>initial-key</option> and <option>static-key</option>
|
||||||
entries identically. That is, even if a key is configured
|
entries identically. That is, even if a key is configured
|
||||||
with <command>initial-key</command>, indicating that it is
|
with <command>initial-key</command>, indicating that it is
|
||||||
|
|||||||
+2
-2
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -197,7 +197,7 @@
|
|||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
Note: When reading the trust anchor file,
|
Note: When reading the trust anchor file,
|
||||||
<span class="command"><strong>delv</strong></span> treats <code class="option">dnssec-keys</code>
|
<span class="command"><strong>delv</strong></span> treats <code class="option">trust-anchors</code>
|
||||||
<code class="option">initial-key</code> and <code class="option">static-key</code>
|
<code class="option">initial-key</code> and <code class="option">static-key</code>
|
||||||
entries identically. That is, even if a key is configured
|
entries identically. That is, even if a key is configured
|
||||||
with <span class="command"><strong>initial-key</strong></span>, indicating that it is
|
with <span class="command"><strong>initial-key</strong></span>, indicating that it is
|
||||||
|
|||||||
+2
-2
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -849,5 +849,5 @@ There are probably too many query options\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+22
-23
@@ -54,7 +54,7 @@
|
|||||||
|
|
||||||
dig_lookup_t *default_lookup = NULL;
|
dig_lookup_t *default_lookup = NULL;
|
||||||
|
|
||||||
static char *batchname = NULL;
|
static atomic_uintptr_t batchname = ATOMIC_VAR_INIT(0);
|
||||||
static FILE *batchfp = NULL;
|
static FILE *batchfp = NULL;
|
||||||
static char *argv0;
|
static char *argv0;
|
||||||
static int addresscount = 0;
|
static int addresscount = 0;
|
||||||
@@ -239,6 +239,7 @@ help(void) {
|
|||||||
" +[no]unknownformat (Print RDATA in RFC 3597 \"unknown\" "
|
" +[no]unknownformat (Print RDATA in RFC 3597 \"unknown\" "
|
||||||
"format)\n"
|
"format)\n"
|
||||||
" +[no]vc (TCP mode (+[no]tcp))\n"
|
" +[no]vc (TCP mode (+[no]tcp))\n"
|
||||||
|
" +[no]yaml (Present the results as YAML)\n"
|
||||||
" +[no]zflag (Set Z flag in query)\n"
|
" +[no]zflag (Set Z flag in query)\n"
|
||||||
" global d-opts and servers (before host name) affect all queries.\n"
|
" global d-opts and servers (before host name) affect all queries.\n"
|
||||||
" local d-opts and servers (after host name) affect only that lookup.\n"
|
" local d-opts and servers (after host name) affect only that lookup.\n"
|
||||||
@@ -486,8 +487,8 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf,
|
|||||||
|
|
||||||
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
styleflags |= DNS_STYLEFLAG_REL_OWNER;
|
||||||
if (yaml) {
|
if (yaml) {
|
||||||
dns_master_indentstr = " ";
|
msg->indent.string = " ";
|
||||||
dns_master_indent = 3;
|
msg->indent.count = 3;
|
||||||
styleflags |= DNS_STYLEFLAG_YAML;
|
styleflags |= DNS_STYLEFLAG_YAML;
|
||||||
} else {
|
} else {
|
||||||
if (query->lookup->comments) {
|
if (query->lookup->comments) {
|
||||||
@@ -567,8 +568,7 @@ printmessage(dig_query_t *query, const isc_buffer_t *msgbuf,
|
|||||||
if (!query->lookup->comments)
|
if (!query->lookup->comments)
|
||||||
flags |= DNS_MESSAGETEXTFLAG_NOCOMMENTS;
|
flags |= DNS_MESSAGETEXTFLAG_NOCOMMENTS;
|
||||||
|
|
||||||
result = isc_buffer_allocate(mctx, &buf, len);
|
isc_buffer_allocate(mctx, &buf, len);
|
||||||
check_result(result, "isc_buffer_allocate");
|
|
||||||
|
|
||||||
if (yaml) {
|
if (yaml) {
|
||||||
enum { Q = 0x1, R = 0x2 }; /* Q:query; R:ecursive */
|
enum { Q = 0x1, R = 0x2 }; /* Q:query; R:ecursive */
|
||||||
@@ -741,11 +741,8 @@ repopulate_buffer:
|
|||||||
buftoosmall:
|
buftoosmall:
|
||||||
len += OUTPUTBUF;
|
len += OUTPUTBUF;
|
||||||
isc_buffer_free(&buf);
|
isc_buffer_free(&buf);
|
||||||
result = isc_buffer_allocate(mctx, &buf, len);
|
isc_buffer_allocate(mctx, &buf, len);
|
||||||
if (result == ISC_R_SUCCESS)
|
goto repopulate_buffer;
|
||||||
goto repopulate_buffer;
|
|
||||||
else
|
|
||||||
goto cleanup;
|
|
||||||
}
|
}
|
||||||
check_result(result,
|
check_result(result,
|
||||||
"dns_message_pseudosectiontotext");
|
"dns_message_pseudosectiontotext");
|
||||||
@@ -826,7 +823,6 @@ buftoosmall:
|
|||||||
(char *)isc_buffer_base(buf));
|
(char *)isc_buffer_base(buf));
|
||||||
isc_buffer_free(&buf);
|
isc_buffer_free(&buf);
|
||||||
|
|
||||||
cleanup:
|
|
||||||
if (style != NULL)
|
if (style != NULL)
|
||||||
dns_master_styledestroy(&style, mctx);
|
dns_master_styledestroy(&style, mctx);
|
||||||
return (result);
|
return (result);
|
||||||
@@ -1873,7 +1869,7 @@ dash_option(char *option, char *next, dig_lookup_t **lookup,
|
|||||||
value);
|
value);
|
||||||
return (value_from_next);
|
return (value_from_next);
|
||||||
case 'f':
|
case 'f':
|
||||||
batchname = value;
|
atomic_store(&batchname, (uintptr_t)value);
|
||||||
return (value_from_next);
|
return (value_from_next);
|
||||||
case 'k':
|
case 'k':
|
||||||
strlcpy(keyfile, value, sizeof(keyfile));
|
strlcpy(keyfile, value, sizeof(keyfile));
|
||||||
@@ -2326,13 +2322,15 @@ parse_args(bool is_batchfile, bool config_only,
|
|||||||
* first entry, then trust the callback in dighost_shutdown
|
* first entry, then trust the callback in dighost_shutdown
|
||||||
* to get the rest
|
* to get the rest
|
||||||
*/
|
*/
|
||||||
if ((batchname != NULL) && !(is_batchfile)) {
|
char *filename = (char *)atomic_load(&batchname);
|
||||||
if (strcmp(batchname, "-") == 0)
|
if ((filename != NULL) && !(is_batchfile)) {
|
||||||
|
if (strcmp(filename, "-") == 0) {
|
||||||
batchfp = stdin;
|
batchfp = stdin;
|
||||||
else
|
} else {
|
||||||
batchfp = fopen(batchname, "r");
|
batchfp = fopen(filename, "r");
|
||||||
|
}
|
||||||
if (batchfp == NULL) {
|
if (batchfp == NULL) {
|
||||||
perror(batchname);
|
perror(filename);
|
||||||
if (exitcode < 8)
|
if (exitcode < 8)
|
||||||
exitcode = 8;
|
exitcode = 8;
|
||||||
fatal("couldn't open specified batch file");
|
fatal("couldn't open specified batch file");
|
||||||
@@ -2387,14 +2385,14 @@ query_finished(void) {
|
|||||||
int bargc;
|
int bargc;
|
||||||
char *bargv[16];
|
char *bargv[16];
|
||||||
|
|
||||||
if (batchname == NULL) {
|
if (atomic_load(&batchname) == 0) {
|
||||||
isc_app_shutdown();
|
isc_app_shutdown();
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
if (feof(batchfp)) {
|
if (feof(batchfp)) {
|
||||||
batchname = NULL;
|
atomic_store(&batchname, 0);
|
||||||
isc_app_shutdown();
|
isc_app_shutdown();
|
||||||
if (batchfp != stdin)
|
if (batchfp != stdin)
|
||||||
fclose(batchfp);
|
fclose(batchfp);
|
||||||
@@ -2408,7 +2406,7 @@ query_finished(void) {
|
|||||||
parse_args(true, false, bargc, (char **)bargv);
|
parse_args(true, false, bargc, (char **)bargv);
|
||||||
start_lookup();
|
start_lookup();
|
||||||
} else {
|
} else {
|
||||||
batchname = NULL;
|
atomic_store(&batchname, 0);
|
||||||
if (batchfp != stdin)
|
if (batchfp != stdin)
|
||||||
fclose(batchfp);
|
fclose(batchfp);
|
||||||
isc_app_shutdown();
|
isc_app_shutdown();
|
||||||
@@ -2538,10 +2536,11 @@ void dig_query_start()
|
|||||||
void
|
void
|
||||||
dig_shutdown() {
|
dig_shutdown() {
|
||||||
destroy_lookup(default_lookup);
|
destroy_lookup(default_lookup);
|
||||||
if (batchname != NULL) {
|
if (atomic_load(&batchname) != 0) {
|
||||||
if (batchfp != stdin)
|
if (batchfp != stdin) {
|
||||||
fclose(batchfp);
|
fclose(batchfp);
|
||||||
batchname = NULL;
|
}
|
||||||
|
atomic_store(&batchname, 0);
|
||||||
}
|
}
|
||||||
cancel_all();
|
cancel_all();
|
||||||
destroy_libs();
|
destroy_libs();
|
||||||
|
|||||||
@@ -53,6 +53,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
+2
-6
@@ -883,10 +883,8 @@ setup_text_key(void) {
|
|||||||
unsigned char *secretstore;
|
unsigned char *secretstore;
|
||||||
|
|
||||||
debug("setup_text_key()");
|
debug("setup_text_key()");
|
||||||
result = isc_buffer_allocate(mctx, &namebuf, MXNAME);
|
isc_buffer_allocate(mctx, &namebuf, MXNAME);
|
||||||
check_result(result, "isc_buffer_allocate");
|
|
||||||
dns_name_init(&keyname, NULL);
|
dns_name_init(&keyname, NULL);
|
||||||
check_result(result, "dns_name_init");
|
|
||||||
isc_buffer_putstr(namebuf, keynametext);
|
isc_buffer_putstr(namebuf, keynametext);
|
||||||
secretsize = (unsigned int) strlen(keysecret) * 3 / 4;
|
secretsize = (unsigned int) strlen(keysecret) * 3 / 4;
|
||||||
secretstore = isc_mem_allocate(mctx, secretsize);
|
secretstore = isc_mem_allocate(mctx, secretsize);
|
||||||
@@ -1396,8 +1394,7 @@ setup_libs(void) {
|
|||||||
check_result(result, "dst_lib_init");
|
check_result(result, "dst_lib_init");
|
||||||
is_dst_up = true;
|
is_dst_up = true;
|
||||||
|
|
||||||
result = isc_mempool_create(mctx, COMMSIZE, &commctx);
|
isc_mempool_create(mctx, COMMSIZE, &commctx);
|
||||||
check_result(result, "isc_mempool_create");
|
|
||||||
isc_mempool_setname(commctx, "COMMPOOL");
|
isc_mempool_setname(commctx, "COMMPOOL");
|
||||||
/*
|
/*
|
||||||
* 6 and 2 set as reasonable parameters for 3 or 4 nameserver
|
* 6 and 2 set as reasonable parameters for 3 or 4 nameserver
|
||||||
@@ -4252,7 +4249,6 @@ destroy_libs(void) {
|
|||||||
result = dns_name_settotextfilter(NULL);
|
result = dns_name_settotextfilter(NULL);
|
||||||
check_result(result, "dns_name_settotextfilter");
|
check_result(result, "dns_name_settotextfilter");
|
||||||
#endif /* HAVE_LIBIDN2 */
|
#endif /* HAVE_LIBIDN2 */
|
||||||
dns_name_destroy();
|
|
||||||
|
|
||||||
if (commctx != NULL) {
|
if (commctx != NULL) {
|
||||||
debug("freeing commctx");
|
debug("freeing commctx");
|
||||||
|
|||||||
+2
-2
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -269,5 +269,5 @@ runs\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2002, 2004, 2005, 2007-2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2002, 2004, 2005, 2007-2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+1
-2
@@ -199,8 +199,7 @@ say_message(dns_name_t *name, const char *msg, dns_rdata_t *rdata,
|
|||||||
|
|
||||||
dns_name_format(name, namestr, sizeof(namestr));
|
dns_name_format(name, namestr, sizeof(namestr));
|
||||||
retry:
|
retry:
|
||||||
result = isc_buffer_allocate(mctx, &b, bufsize);
|
isc_buffer_allocate(mctx, &b, bufsize);
|
||||||
check_result(result, "isc_buffer_allocate");
|
|
||||||
result = dns_rdata_totext(rdata, NULL, b);
|
result = dns_rdata_totext(rdata, NULL, b);
|
||||||
if (result == ISC_R_NOSPACE) {
|
if (result == ISC_R_NOSPACE) {
|
||||||
isc_buffer_free(&b);
|
isc_buffer_free(&b);
|
||||||
|
|||||||
@@ -48,6 +48,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2002, 2004, 2005, 2007-2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
+2
-2
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2004-2007, 2010, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2004-2007, 2010, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -301,5 +301,5 @@ runs or when the standard output is not a tty\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2004-2007, 2010, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2004-2007, 2010, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+1
-3
@@ -221,9 +221,7 @@ printrdata(dns_rdata_t *rdata) {
|
|||||||
printf("rdata_%d = ", rdata->type);
|
printf("rdata_%d = ", rdata->type);
|
||||||
|
|
||||||
while (!done) {
|
while (!done) {
|
||||||
result = isc_buffer_allocate(mctx, &b, size);
|
isc_buffer_allocate(mctx, &b, size);
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
check_result(result, "isc_buffer_allocate");
|
|
||||||
result = dns_rdata_totext(rdata, NULL, b);
|
result = dns_rdata_totext(rdata, NULL, b);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
printf("%.*s\n", (int)isc_buffer_usedlength(b),
|
printf("%.*s\n", (int)isc_buffer_usedlength(b),
|
||||||
|
|||||||
+29
-22
@@ -72,6 +72,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
@@ -307,7 +308,7 @@ nslookup -query=hinfo -timeout=10
|
|||||||
The class specifies the protocol group of the information.
|
The class specifies the protocol group of the information.
|
||||||
|
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
(Default = IN; abbreviation = cl)
|
(Default = IN; abbreviation = cl)
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
@@ -317,10 +318,10 @@ nslookup -query=hinfo -timeout=10
|
|||||||
<term><constant><replaceable><optional>no</optional></replaceable>debug</constant></term>
|
<term><constant><replaceable><optional>no</optional></replaceable>debug</constant></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Turn on or off the display of the full response packet and
|
Turn on or off the display of the full response packet and
|
||||||
any intermediate response packets when searching.
|
any intermediate response packets when searching.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
(Default = nodebug; abbreviation = <optional>no</optional>deb)
|
(Default = nodebug; abbreviation = <optional>no</optional>deb)
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
@@ -331,9 +332,9 @@ nslookup -query=hinfo -timeout=10
|
|||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Turn debugging mode on or off. This displays more about
|
Turn debugging mode on or off. This displays more about
|
||||||
what nslookup is doing.
|
what nslookup is doing.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
(Default = nod2)
|
(Default = nod2)
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
@@ -357,7 +358,7 @@ nslookup -query=hinfo -timeout=10
|
|||||||
names in the domain search list to the request until an
|
names in the domain search list to the request until an
|
||||||
answer is received.
|
answer is received.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
(Default = search)
|
(Default = search)
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
@@ -369,7 +370,7 @@ nslookup -query=hinfo -timeout=10
|
|||||||
<para>
|
<para>
|
||||||
Change the default TCP/UDP name server port to <replaceable>value</replaceable>.
|
Change the default TCP/UDP name server port to <replaceable>value</replaceable>.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
(Default = 53; abbreviation = po)
|
(Default = 53; abbreviation = po)
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
@@ -388,9 +389,15 @@ nslookup -query=hinfo -timeout=10
|
|||||||
<para>
|
<para>
|
||||||
Change the type of the information query.
|
Change the type of the information query.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
(Default = A; abbreviations = q, ty)
|
(Default = A and then AAAA; abbreviations = q, ty)
|
||||||
</para>
|
</para>
|
||||||
|
<para>
|
||||||
|
<emphasis role="bold">Note:</emphasis> It is
|
||||||
|
only possible to specify one query type, only
|
||||||
|
the default behavior looks up both when an
|
||||||
|
alternative is not specified.
|
||||||
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
@@ -402,7 +409,7 @@ nslookup -query=hinfo -timeout=10
|
|||||||
have the
|
have the
|
||||||
information.
|
information.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
(Default = recurse; abbreviation = [no]rec)
|
(Default = recurse; abbreviation = [no]rec)
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
@@ -412,9 +419,9 @@ nslookup -query=hinfo -timeout=10
|
|||||||
<term><constant>ndots=</constant><replaceable>number</replaceable></term>
|
<term><constant>ndots=</constant><replaceable>number</replaceable></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Set the number of dots (label separators) in a domain
|
Set the number of dots (label separators) in a domain
|
||||||
that will disable searching. Absolute names always
|
that will disable searching. Absolute names always
|
||||||
stop searching.
|
stop searching.
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
@@ -445,7 +452,7 @@ nslookup -query=hinfo -timeout=10
|
|||||||
Always use a virtual circuit when sending requests to the
|
Always use a virtual circuit when sending requests to the
|
||||||
server.
|
server.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
(Default = novc)
|
(Default = novc)
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
@@ -455,15 +462,15 @@ nslookup -query=hinfo -timeout=10
|
|||||||
<term><constant><replaceable><optional>no</optional></replaceable>fail</constant></term>
|
<term><constant><replaceable><optional>no</optional></replaceable>fail</constant></term>
|
||||||
<listitem>
|
<listitem>
|
||||||
<para>
|
<para>
|
||||||
Try the next nameserver if a nameserver responds with
|
Try the next nameserver if a nameserver responds with
|
||||||
SERVFAIL or a referral (nofail) or terminate query
|
SERVFAIL or a referral (nofail) or terminate query
|
||||||
(fail) on such a response.
|
(fail) on such a response.
|
||||||
</para>
|
</para>
|
||||||
<para>
|
<para>
|
||||||
(Default = nofail)
|
(Default = nofail)
|
||||||
</para>
|
</para>
|
||||||
</listitem>
|
</listitem>
|
||||||
</varlistentry>
|
</varlistentry>
|
||||||
|
|
||||||
</variablelist>
|
</variablelist>
|
||||||
</para>
|
</para>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2004-2007, 2010, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2004-2007, 2010, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2017-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2017-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -293,5 +293,5 @@ RFC 7344\&.
|
|||||||
.RE
|
.RE
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2017-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2017-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -370,9 +370,8 @@ formatset(dns_rdataset_t *rdataset) {
|
|||||||
mctx);
|
mctx);
|
||||||
check_result(result, "dns_master_stylecreate2 failed");
|
check_result(result, "dns_master_stylecreate2 failed");
|
||||||
|
|
||||||
result = isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE);
|
isc_buffer_allocate(mctx, &buf, MAX_CDS_RDATA_TEXT_SIZE);
|
||||||
check_result(result, "printing DS records");
|
result = dns_master_rdatasettotext(name, rdataset, style, NULL, buf);
|
||||||
result = dns_master_rdatasettotext(name, rdataset, style, buf);
|
|
||||||
|
|
||||||
if ((result == ISC_R_SUCCESS) && isc_buffer_availablelength(buf) < 1) {
|
if ((result == ISC_R_SUCCESS) && isc_buffer_availablelength(buf) < 1) {
|
||||||
result = ISC_R_NOSPACE;
|
result = ISC_R_NOSPACE;
|
||||||
@@ -834,8 +833,7 @@ make_new_ds_set(ds_maker_func_t *ds_from_rdata,
|
|||||||
result = dns_rdatalist_tordataset(dslist, &new_ds_set);
|
result = dns_rdatalist_tordataset(dslist, &new_ds_set);
|
||||||
check_result(result, "dns_rdatalist_tordataset(dslist)");
|
check_result(result, "dns_rdatalist_tordataset(dslist)");
|
||||||
|
|
||||||
result = isc_buffer_allocate(mctx, &new_ds_buf, size);
|
isc_buffer_allocate(mctx, &new_ds_buf, size);
|
||||||
check_result(result, "building new DS records");
|
|
||||||
|
|
||||||
for (result = dns_rdataset_first(rdset);
|
for (result = dns_rdataset_first(rdset);
|
||||||
result == ISC_R_SUCCESS;
|
result == ISC_R_SUCCESS;
|
||||||
|
|||||||
@@ -41,6 +41,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2017-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2017-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2008-2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2008-2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -222,5 +222,5 @@ RFC 7344
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2008-2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2008-2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -517,7 +517,6 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
dns_name_destroy();
|
|
||||||
if (verbose > 10) {
|
if (verbose > 10) {
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -42,6 +42,7 @@
|
|||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2008-2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2008-2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2013-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2013-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -134,5 +134,5 @@ RFC 5011\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2013-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2013-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -439,7 +439,6 @@ main(int argc, char **argv) {
|
|||||||
dns_rdataset_disassociate(&rdataset);
|
dns_rdataset_disassociate(&rdataset);
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
dns_name_destroy();
|
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|||||||
@@ -39,6 +39,7 @@
|
|||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2013-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2013-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2008-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2008-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -307,5 +307,5 @@ The PKCS#11 URI Scheme (draft\-pechanec\-pkcs11uri\-13)\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2008-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2008-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -694,7 +694,6 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
dns_name_destroy();
|
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
isc_mem_free(mctx, label);
|
isc_mem_free(mctx, label);
|
||||||
|
|||||||
@@ -44,6 +44,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2008-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2008-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2005, 2007-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2005, 2007-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -39,7 +39,7 @@
|
|||||||
dnssec-keygen \- DNSSEC key generation tool
|
dnssec-keygen \- DNSSEC key generation tool
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBdnssec\-keygen\fR\ 'u
|
.HP \w'\fBdnssec\-keygen\fR\ 'u
|
||||||
\fBdnssec\-keygen\fR [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] {name}
|
\fBdnssec\-keygen\fR [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-d\ \fR\fB\fIbits\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\ \fR\fB\fIpolicy\fR\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-l\ \fR\fB\fIfile\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-T\ \fR\fB\fIrrtype\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] {name}
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-keygen\fR
|
\fBdnssec\-keygen\fR
|
||||||
@@ -109,6 +109,11 @@ option suppresses them\&.
|
|||||||
Indicates that the DNS record containing the key should have the specified class\&. If not specified, class IN is used\&.
|
Indicates that the DNS record containing the key should have the specified class\&. If not specified, class IN is used\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-d \fIbits\fR
|
||||||
|
.RS 4
|
||||||
|
Key size in bits\&. For the algorithms RSASHA1, NSEC3RSASA1, RSASHA256 and RSASHA512 the key size must be in range 1024\-4096\&. DH size is between 128 and 4096\&. This option is ignored for algorithms ECDSAP256SHA256, ECDSAP384SHA384, ED25519 and ED448\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-E \fIengine\fR
|
\-E \fIengine\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Specifies the cryptographic hardware to use, when applicable\&.
|
Specifies the cryptographic hardware to use, when applicable\&.
|
||||||
@@ -142,6 +147,17 @@ Prints a short summary of the options and arguments to
|
|||||||
Sets the directory in which the key files are to be written\&.
|
Sets the directory in which the key files are to be written\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-k \fIpolicy\fR
|
||||||
|
.RS 4
|
||||||
|
Create keys for a specific dnssec\-policy\&. If a policy uses multiple keys,
|
||||||
|
\fBdnssec\-keygen\fR
|
||||||
|
will generate multiple keys\&. This will also create a "\&.state" file to keep track of the key state\&.
|
||||||
|
.sp
|
||||||
|
This option creates keys according to the dnssec\-policy configuration, hence it cannot be used together with many of the other options that
|
||||||
|
\fBdnssec\-keygen\fR
|
||||||
|
provides\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-L \fIttl\fR
|
\-L \fIttl\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Sets the default TTL to use for this key when it is converted into a DNSKEY RR\&. If the key is imported into a zone, this is the TTL that will be used for it, unless there was already a DNSKEY RRset in place, in which case the existing TTL would take precedence\&. If this value is not set and there is no existing DNSKEY RRset, the TTL will default to the SOA TTL\&. Setting the default TTL to
|
Sets the default TTL to use for this key when it is converted into a DNSKEY RR\&. If the key is imported into a zone, this is the TTL that will be used for it, unless there was already a DNSKEY RRset in place, in which case the existing TTL would take precedence\&. If this value is not set and there is no existing DNSKEY RRset, the TTL will default to the SOA TTL\&. Setting the default TTL to
|
||||||
@@ -151,6 +167,12 @@ none
|
|||||||
is the same as leaving it unset\&.
|
is the same as leaving it unset\&.
|
||||||
.RE
|
.RE
|
||||||
.PP
|
.PP
|
||||||
|
\-l \fIfile\fR
|
||||||
|
.RS 4
|
||||||
|
Provide a configuration file that contains a dnssec\-policy statement (matching the policy set with
|
||||||
|
\fB\-k\fR)\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
\-n \fInametype\fR
|
\-n \fInametype\fR
|
||||||
.RS 4
|
.RS 4
|
||||||
Specifies the owner type of the key\&. The value of
|
Specifies the owner type of the key\&. The value of
|
||||||
@@ -352,5 +374,5 @@ RFC 4034\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2005, 2007-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2005, 2007-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -1222,7 +1222,6 @@ main(int argc, char **argv) {
|
|||||||
|
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
dns_name_destroy();
|
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|||||||
@@ -51,6 +51,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2005, 2007-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2005, 2007-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -41,6 +41,7 @@
|
|||||||
[<code class="option">-c <em class="replaceable"><code>class</code></em></code>]
|
[<code class="option">-c <em class="replaceable"><code>class</code></em></code>]
|
||||||
[<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
[<code class="option">-D sync <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-D sync <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
|
[<code class="option">-d <em class="replaceable"><code>bits</code></em></code>]
|
||||||
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
||||||
[<code class="option">-f <em class="replaceable"><code>flag</code></em></code>]
|
[<code class="option">-f <em class="replaceable"><code>flag</code></em></code>]
|
||||||
[<code class="option">-G</code>]
|
[<code class="option">-G</code>]
|
||||||
@@ -49,8 +50,9 @@
|
|||||||
[<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
[<code class="option">-i <em class="replaceable"><code>interval</code></em></code>]
|
[<code class="option">-i <em class="replaceable"><code>interval</code></em></code>]
|
||||||
[<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
|
[<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
|
||||||
[<code class="option">-k</code>]
|
[<code class="option">-k <em class="replaceable"><code>policy</code></em></code>]
|
||||||
[<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>]
|
[<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>]
|
||||||
|
[<code class="option">-l <em class="replaceable"><code>file</code></em></code>]
|
||||||
[<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
|
[<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
|
||||||
[<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
[<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
@@ -59,6 +61,7 @@
|
|||||||
[<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>]
|
[<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
[<code class="option">-S <em class="replaceable"><code>key</code></em></code>]
|
[<code class="option">-S <em class="replaceable"><code>key</code></em></code>]
|
||||||
[<code class="option">-s <em class="replaceable"><code>strength</code></em></code>]
|
[<code class="option">-s <em class="replaceable"><code>strength</code></em></code>]
|
||||||
|
[<code class="option">-T <em class="replaceable"><code>rrtype</code></em></code>]
|
||||||
[<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
|
[<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
|
||||||
[<code class="option">-V</code>]
|
[<code class="option">-V</code>]
|
||||||
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
||||||
@@ -168,6 +171,15 @@
|
|||||||
the specified class. If not specified, class IN is used.
|
the specified class. If not specified, class IN is used.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-d <em class="replaceable"><code>bits</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Key size in bits. For the algorithms RSASHA1, NSEC3RSASA1,
|
||||||
|
RSASHA256 and RSASHA512 the key size must be in range 1024-4096.
|
||||||
|
DH size is between 128 and 4096. This option is ignored for
|
||||||
|
algorithms ECDSAP256SHA256, ECDSAP384SHA384, ED25519 and ED448.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
|
<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -218,6 +230,21 @@
|
|||||||
Sets the directory in which the key files are to be written.
|
Sets the directory in which the key files are to be written.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-k <em class="replaceable"><code>policy</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Create keys for a specific dnssec-policy. If a policy uses
|
||||||
|
multiple keys, <span class="command"><strong>dnssec-keygen</strong></span> will generate
|
||||||
|
multiple keys. This will also create a ".state" file to keep
|
||||||
|
track of the key state.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
This option creates keys according to the dnssec-policy
|
||||||
|
configuration, hence it cannot be used together with many of
|
||||||
|
the other options that <span class="command"><strong>dnssec-keygen</strong></span>
|
||||||
|
provides.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
|
<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
@@ -231,6 +258,13 @@
|
|||||||
or <code class="literal">none</code> is the same as leaving it unset.
|
or <code class="literal">none</code> is the same as leaving it unset.
|
||||||
</p>
|
</p>
|
||||||
</dd>
|
</dd>
|
||||||
|
<dt><span class="term">-l <em class="replaceable"><code>file</code></em></span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Provide a configuration file that contains a dnssec-policy
|
||||||
|
statement (matching the policy set with <span class="command"><strong>-k</strong></span>).
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
|
<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
|
||||||
<dd>
|
<dd>
|
||||||
<p>
|
<p>
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2009, 2011, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2009, 2011, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -99,5 +99,5 @@ RFC 5011\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2009, 2011, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2009, 2011, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -39,6 +39,7 @@
|
|||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2009, 2011, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2009, 2011, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2009-2011, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2009-2011, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -39,7 +39,7 @@
|
|||||||
dnssec-settime \- set the key timing metadata for a DNSSEC key
|
dnssec-settime \- set the key timing metadata for a DNSSEC key
|
||||||
.SH "SYNOPSIS"
|
.SH "SYNOPSIS"
|
||||||
.HP \w'\fBdnssec\-settime\fR\ 'u
|
.HP \w'\fBdnssec\-settime\fR\ 'u
|
||||||
\fBdnssec\-settime\fR [\fB\-f\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-h\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] {keyfile}
|
\fBdnssec\-settime\fR [\fB\-f\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-h\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-s\fR] [\fB\-g\ \fR\fB\fIstate\fR\fR] [\fB\-d\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] [\fB\-k\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] [\fB\-r\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] [\fB\-z\ \fR\fB\fIstate\fR\fR\fB\ \fR\fB\fIdate/offset\fR\fR] {keyfile}
|
||||||
.SH "DESCRIPTION"
|
.SH "DESCRIPTION"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-settime\fR
|
\fBdnssec\-settime\fR
|
||||||
@@ -59,7 +59,25 @@ simply prints the key timing metadata already stored in the key\&.
|
|||||||
.PP
|
.PP
|
||||||
When key metadata fields are changed, both files of a key pair (Knnnn\&.+aaa+iiiii\&.key
|
When key metadata fields are changed, both files of a key pair (Knnnn\&.+aaa+iiiii\&.key
|
||||||
and
|
and
|
||||||
Knnnn\&.+aaa+iiiii\&.private) are regenerated\&. Metadata fields are stored in the private file\&. A human\-readable description of the metadata is also placed in comments in the key file\&. The private file\*(Aqs permissions are always set to be inaccessible to anyone other than the owner (mode 0600)\&.
|
Knnnn\&.+aaa+iiiii\&.private) are regenerated\&.
|
||||||
|
.PP
|
||||||
|
Metadata fields are stored in the private file\&. A human\-readable description of the metadata is also placed in comments in the key file\&. The private file\*(Aqs permissions are always set to be inaccessible to anyone other than the owner (mode 0600)\&.
|
||||||
|
.PP
|
||||||
|
When working with state files, it is possible to update the timing metadata in those files as well with
|
||||||
|
\fB\-s\fR\&. If this option is used you can also update key states with
|
||||||
|
\fB\-d\fR
|
||||||
|
(DS),
|
||||||
|
\fB\-k\fR
|
||||||
|
(DNSKEY),
|
||||||
|
\fB\-r\fR
|
||||||
|
(RRSIG of KSK), or
|
||||||
|
\fB\-z\fR
|
||||||
|
(RRSIG of ZSK)\&. Allowed states are HIDDEN, RUMOURED, OMNIPRESENT, and UNRETENTIVE\&.
|
||||||
|
.PP
|
||||||
|
You can also set the goal state of the key with
|
||||||
|
\fB\-g\fR\&. This should be either HIDDEN or OMNIPRESENT (representing whether the key should be removed from the zone, or published)\&.
|
||||||
|
.PP
|
||||||
|
It is NOT RECOMMENDED to manipulate state files manually except for testing purposes\&.
|
||||||
.SH "OPTIONS"
|
.SH "OPTIONS"
|
||||||
.PP
|
.PP
|
||||||
\-f
|
\-f
|
||||||
@@ -156,6 +174,39 @@ If the key is being set to be an explicit successor to another key, then the def
|
|||||||
.sp
|
.sp
|
||||||
As with date offsets, if the argument is followed by one of the suffixes \*(Aqy\*(Aq, \*(Aqmo\*(Aq, \*(Aqw\*(Aq, \*(Aqd\*(Aq, \*(Aqh\*(Aq, or \*(Aqmi\*(Aq, then the interval is measured in years, months, weeks, days, hours, or minutes, respectively\&. Without a suffix, the interval is measured in seconds\&.
|
As with date offsets, if the argument is followed by one of the suffixes \*(Aqy\*(Aq, \*(Aqmo\*(Aq, \*(Aqw\*(Aq, \*(Aqd\*(Aq, \*(Aqh\*(Aq, or \*(Aqmi\*(Aq, then the interval is measured in years, months, weeks, days, hours, or minutes, respectively\&. Without a suffix, the interval is measured in seconds\&.
|
||||||
.RE
|
.RE
|
||||||
|
.SH "KEY STATE OPTIONS"
|
||||||
|
.PP
|
||||||
|
Known key states are HIDDEN, RUMOURED, OMNIPRESENT and UNRETENTIVE\&. These should not be set manually except for testing purposes\&.
|
||||||
|
.PP
|
||||||
|
\-s
|
||||||
|
.RS 4
|
||||||
|
When setting key timing data, also update the state file\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-g
|
||||||
|
.RS 4
|
||||||
|
Set the goal state for this key\&. Must be HIDDEN or OMNIPRESENT\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-d
|
||||||
|
.RS 4
|
||||||
|
Set the DS state for this key, and when it was last changed\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-k
|
||||||
|
.RS 4
|
||||||
|
Set the DNSKEY state for this key, and when it was last changed\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-r
|
||||||
|
.RS 4
|
||||||
|
Set the RRSIG (KSK) state for this key, and when it was last changed\&.
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\-z
|
||||||
|
.RS 4
|
||||||
|
Set the RRSIG (ZSK) state for this key, and when it was last changed\&.
|
||||||
|
.RE
|
||||||
.SH "PRINTING OPTIONS"
|
.SH "PRINTING OPTIONS"
|
||||||
.PP
|
.PP
|
||||||
\fBdnssec\-settime\fR
|
\fBdnssec\-settime\fR
|
||||||
@@ -200,5 +251,5 @@ RFC 5011\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2009-2011, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2009-2011, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+145
-146
@@ -253,106 +253,6 @@ main(int argc, char **argv) {
|
|||||||
#define CMDLINE_FLAGS "A:D:d:E:fg:hI:i:K:k:L:P:p:R:r:S:suv:Vz:"
|
#define CMDLINE_FLAGS "A:D:d:E:fg:hI:i:K:k:L:P:p:R:r:S:suv:Vz:"
|
||||||
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
|
||||||
switch (ch) {
|
switch (ch) {
|
||||||
case 'E':
|
|
||||||
engine = isc_commandline_argument;
|
|
||||||
break;
|
|
||||||
case 'f':
|
|
||||||
force = true;
|
|
||||||
break;
|
|
||||||
case 'p':
|
|
||||||
p = isc_commandline_argument;
|
|
||||||
if (!strcasecmp(p, "all")) {
|
|
||||||
printcreate = true;
|
|
||||||
printpub = true;
|
|
||||||
printact = true;
|
|
||||||
printrev = true;
|
|
||||||
printinact = true;
|
|
||||||
printdel = true;
|
|
||||||
printsyncadd = true;
|
|
||||||
printsyncdel = true;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
|
|
||||||
do {
|
|
||||||
switch (*p++) {
|
|
||||||
case 'C':
|
|
||||||
printcreate = true;
|
|
||||||
break;
|
|
||||||
case 'P':
|
|
||||||
if (!strncmp(p, "sync", 4)) {
|
|
||||||
p += 4;
|
|
||||||
printsyncadd = true;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
printpub = true;
|
|
||||||
break;
|
|
||||||
case 'A':
|
|
||||||
printact = true;
|
|
||||||
break;
|
|
||||||
case 'R':
|
|
||||||
printrev = true;
|
|
||||||
break;
|
|
||||||
case 'I':
|
|
||||||
printinact = true;
|
|
||||||
break;
|
|
||||||
case 'D':
|
|
||||||
if (!strncmp(p, "sync", 4)) {
|
|
||||||
p += 4;
|
|
||||||
printsyncdel = true;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
printdel = true;
|
|
||||||
break;
|
|
||||||
case ' ':
|
|
||||||
break;
|
|
||||||
default:
|
|
||||||
usage();
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
} while (*p != '\0');
|
|
||||||
break;
|
|
||||||
case 'u':
|
|
||||||
epoch = true;
|
|
||||||
break;
|
|
||||||
case 'K':
|
|
||||||
/*
|
|
||||||
* We don't have to copy it here, but do it to
|
|
||||||
* simplify cleanup later
|
|
||||||
*/
|
|
||||||
directory = isc_mem_strdup(mctx,
|
|
||||||
isc_commandline_argument);
|
|
||||||
break;
|
|
||||||
case 'L':
|
|
||||||
ttl = strtottl(isc_commandline_argument);
|
|
||||||
setttl = true;
|
|
||||||
break;
|
|
||||||
case 'v':
|
|
||||||
verbose = strtol(isc_commandline_argument, &endp, 0);
|
|
||||||
if (*endp != '\0')
|
|
||||||
fatal("-v must be followed by a number");
|
|
||||||
break;
|
|
||||||
case 'P':
|
|
||||||
/* -Psync ? */
|
|
||||||
if (isoptarg("sync", argv, usage)) {
|
|
||||||
if (unsetsyncadd || setsyncadd)
|
|
||||||
fatal("-P sync specified more than "
|
|
||||||
"once");
|
|
||||||
|
|
||||||
changed = true;
|
|
||||||
syncadd = strtotime(isc_commandline_argument,
|
|
||||||
now, now, &setsyncadd);
|
|
||||||
unsetsyncadd = !setsyncadd;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
(void)isoptarg("dnskey", argv, usage);
|
|
||||||
if (setpub || unsetpub)
|
|
||||||
fatal("-P specified more than once");
|
|
||||||
|
|
||||||
changed = true;
|
|
||||||
pub = strtotime(isc_commandline_argument,
|
|
||||||
now, now, &setpub);
|
|
||||||
unsetpub = !setpub;
|
|
||||||
break;
|
|
||||||
case 'A':
|
case 'A':
|
||||||
if (setact || unsetact)
|
if (setact || unsetact)
|
||||||
fatal("-A specified more than once");
|
fatal("-A specified more than once");
|
||||||
@@ -362,24 +262,6 @@ main(int argc, char **argv) {
|
|||||||
now, now, &setact);
|
now, now, &setact);
|
||||||
unsetact = !setact;
|
unsetact = !setact;
|
||||||
break;
|
break;
|
||||||
case 'R':
|
|
||||||
if (setrev || unsetrev)
|
|
||||||
fatal("-R specified more than once");
|
|
||||||
|
|
||||||
changed = true;
|
|
||||||
rev = strtotime(isc_commandline_argument,
|
|
||||||
now, now, &setrev);
|
|
||||||
unsetrev = !setrev;
|
|
||||||
break;
|
|
||||||
case 'I':
|
|
||||||
if (setinact || unsetinact)
|
|
||||||
fatal("-I specified more than once");
|
|
||||||
|
|
||||||
changed = true;
|
|
||||||
inact = strtotime(isc_commandline_argument,
|
|
||||||
now, now, &setinact);
|
|
||||||
unsetinact = !setinact;
|
|
||||||
break;
|
|
||||||
case 'D':
|
case 'D':
|
||||||
/* -Dsync ? */
|
/* -Dsync ? */
|
||||||
if (isoptarg("sync", argv, usage)) {
|
if (isoptarg("sync", argv, usage)) {
|
||||||
@@ -403,14 +285,23 @@ main(int argc, char **argv) {
|
|||||||
now, now, &setdel);
|
now, now, &setdel);
|
||||||
unsetdel = !setdel;
|
unsetdel = !setdel;
|
||||||
break;
|
break;
|
||||||
case 'S':
|
case 'd':
|
||||||
predecessor = isc_commandline_argument;
|
if (setds) {
|
||||||
|
fatal("-d specified more than once");
|
||||||
|
}
|
||||||
|
|
||||||
|
ds = strtokeystate(isc_commandline_argument);
|
||||||
|
setds = true;
|
||||||
|
/* time */
|
||||||
|
(void)isoptarg(isc_commandline_argument, argv, usage);
|
||||||
|
dstime = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setdstime);
|
||||||
break;
|
break;
|
||||||
case 'i':
|
case 'E':
|
||||||
prepub = strtottl(isc_commandline_argument);
|
engine = isc_commandline_argument;
|
||||||
break;
|
break;
|
||||||
case 's':
|
case 'f':
|
||||||
write_state = true;
|
force = true;
|
||||||
break;
|
break;
|
||||||
case 'g':
|
case 'g':
|
||||||
if (setgoal) {
|
if (setgoal) {
|
||||||
@@ -426,17 +317,33 @@ main(int argc, char **argv) {
|
|||||||
}
|
}
|
||||||
setgoal = true;
|
setgoal = true;
|
||||||
break;
|
break;
|
||||||
case 'd':
|
case '?':
|
||||||
if (setds) {
|
if (isc_commandline_option != '?')
|
||||||
fatal("-d specified more than once");
|
fprintf(stderr, "%s: invalid argument -%c\n",
|
||||||
}
|
program, isc_commandline_option);
|
||||||
|
/* FALLTHROUGH */
|
||||||
|
case 'h':
|
||||||
|
/* Does not return. */
|
||||||
|
usage();
|
||||||
|
case 'I':
|
||||||
|
if (setinact || unsetinact)
|
||||||
|
fatal("-I specified more than once");
|
||||||
|
|
||||||
ds = strtokeystate(isc_commandline_argument);
|
changed = true;
|
||||||
setds = true;
|
inact = strtotime(isc_commandline_argument,
|
||||||
/* time */
|
now, now, &setinact);
|
||||||
(void)isoptarg(isc_commandline_argument, argv, usage);
|
unsetinact = !setinact;
|
||||||
dstime = strtotime(isc_commandline_argument,
|
break;
|
||||||
now, now, &setdstime);
|
case 'i':
|
||||||
|
prepub = strtottl(isc_commandline_argument);
|
||||||
|
break;
|
||||||
|
case 'K':
|
||||||
|
/*
|
||||||
|
* We don't have to copy it here, but do it to
|
||||||
|
* simplify cleanup later
|
||||||
|
*/
|
||||||
|
directory = isc_mem_strdup(mctx,
|
||||||
|
isc_commandline_argument);
|
||||||
break;
|
break;
|
||||||
case 'k':
|
case 'k':
|
||||||
if (setdnskey) {
|
if (setdnskey) {
|
||||||
@@ -450,6 +357,93 @@ main(int argc, char **argv) {
|
|||||||
dnskeytime = strtotime(isc_commandline_argument,
|
dnskeytime = strtotime(isc_commandline_argument,
|
||||||
now, now, &setdnskeytime);
|
now, now, &setdnskeytime);
|
||||||
break;
|
break;
|
||||||
|
case 'L':
|
||||||
|
ttl = strtottl(isc_commandline_argument);
|
||||||
|
setttl = true;
|
||||||
|
break;
|
||||||
|
case 'P':
|
||||||
|
/* -Psync ? */
|
||||||
|
if (isoptarg("sync", argv, usage)) {
|
||||||
|
if (unsetsyncadd || setsyncadd)
|
||||||
|
fatal("-P sync specified more than "
|
||||||
|
"once");
|
||||||
|
|
||||||
|
changed = true;
|
||||||
|
syncadd = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setsyncadd);
|
||||||
|
unsetsyncadd = !setsyncadd;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
(void)isoptarg("dnskey", argv, usage);
|
||||||
|
if (setpub || unsetpub)
|
||||||
|
fatal("-P specified more than once");
|
||||||
|
|
||||||
|
changed = true;
|
||||||
|
pub = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setpub);
|
||||||
|
unsetpub = !setpub;
|
||||||
|
break;
|
||||||
|
case 'p':
|
||||||
|
p = isc_commandline_argument;
|
||||||
|
if (!strcasecmp(p, "all")) {
|
||||||
|
printcreate = true;
|
||||||
|
printpub = true;
|
||||||
|
printact = true;
|
||||||
|
printrev = true;
|
||||||
|
printinact = true;
|
||||||
|
printdel = true;
|
||||||
|
printsyncadd = true;
|
||||||
|
printsyncdel = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
do {
|
||||||
|
switch (*p++) {
|
||||||
|
case 'A':
|
||||||
|
printact = true;
|
||||||
|
break;
|
||||||
|
case 'C':
|
||||||
|
printcreate = true;
|
||||||
|
break;
|
||||||
|
case 'D':
|
||||||
|
if (!strncmp(p, "sync", 4)) {
|
||||||
|
p += 4;
|
||||||
|
printsyncdel = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
printdel = true;
|
||||||
|
break;
|
||||||
|
case 'I':
|
||||||
|
printinact = true;
|
||||||
|
break;
|
||||||
|
case 'P':
|
||||||
|
if (!strncmp(p, "sync", 4)) {
|
||||||
|
p += 4;
|
||||||
|
printsyncadd = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
printpub = true;
|
||||||
|
break;
|
||||||
|
case 'R':
|
||||||
|
printrev = true;
|
||||||
|
break;
|
||||||
|
case ' ':
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
usage();
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
} while (*p != '\0');
|
||||||
|
break;
|
||||||
|
case 'R':
|
||||||
|
if (setrev || unsetrev)
|
||||||
|
fatal("-R specified more than once");
|
||||||
|
|
||||||
|
changed = true;
|
||||||
|
rev = strtotime(isc_commandline_argument,
|
||||||
|
now, now, &setrev);
|
||||||
|
unsetrev = !setrev;
|
||||||
|
break;
|
||||||
case 'r':
|
case 'r':
|
||||||
if (setkrrsig) {
|
if (setkrrsig) {
|
||||||
fatal("-r specified more than once");
|
fatal("-r specified more than once");
|
||||||
@@ -462,6 +456,23 @@ main(int argc, char **argv) {
|
|||||||
krrsigtime = strtotime(isc_commandline_argument,
|
krrsigtime = strtotime(isc_commandline_argument,
|
||||||
now, now, &setkrrsigtime);
|
now, now, &setkrrsigtime);
|
||||||
break;
|
break;
|
||||||
|
case 'S':
|
||||||
|
predecessor = isc_commandline_argument;
|
||||||
|
break;
|
||||||
|
case 's':
|
||||||
|
write_state = true;
|
||||||
|
break;
|
||||||
|
case 'u':
|
||||||
|
epoch = true;
|
||||||
|
break;
|
||||||
|
case 'V':
|
||||||
|
/* Does not return. */
|
||||||
|
version(program);
|
||||||
|
case 'v':
|
||||||
|
verbose = strtol(isc_commandline_argument, &endp, 0);
|
||||||
|
if (*endp != '\0')
|
||||||
|
fatal("-v must be followed by a number");
|
||||||
|
break;
|
||||||
case 'z':
|
case 'z':
|
||||||
if (setzrrsig) {
|
if (setzrrsig) {
|
||||||
fatal("-z specified more than once");
|
fatal("-z specified more than once");
|
||||||
@@ -473,18 +484,6 @@ main(int argc, char **argv) {
|
|||||||
zrrsigtime = strtotime(isc_commandline_argument,
|
zrrsigtime = strtotime(isc_commandline_argument,
|
||||||
now, now, &setzrrsigtime);
|
now, now, &setzrrsigtime);
|
||||||
break;
|
break;
|
||||||
case '?':
|
|
||||||
if (isc_commandline_option != '?')
|
|
||||||
fprintf(stderr, "%s: invalid argument -%c\n",
|
|
||||||
program, isc_commandline_option);
|
|
||||||
/* FALLTHROUGH */
|
|
||||||
case 'h':
|
|
||||||
/* Does not return. */
|
|
||||||
usage();
|
|
||||||
|
|
||||||
case 'V':
|
|
||||||
/* Does not return. */
|
|
||||||
version(program);
|
|
||||||
|
|
||||||
default:
|
default:
|
||||||
fprintf(stderr, "%s: unhandled option -%c\n",
|
fprintf(stderr, "%s: unhandled option -%c\n",
|
||||||
|
|||||||
@@ -41,6 +41,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2009-2011, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2009-2011, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -49,6 +49,12 @@
|
|||||||
[<code class="option">-V</code>]
|
[<code class="option">-V</code>]
|
||||||
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
[<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
|
||||||
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
[<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
|
||||||
|
[<code class="option">-s</code>]
|
||||||
|
[<code class="option">-g <em class="replaceable"><code>state</code></em></code>]
|
||||||
|
[<code class="option">-d <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
|
[<code class="option">-k <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
|
[<code class="option">-r <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
|
[<code class="option">-z <em class="replaceable"><code>state</code></em> <em class="replaceable"><code>date/offset</code></em></code>]
|
||||||
{keyfile}
|
{keyfile}
|
||||||
</p></div>
|
</p></div>
|
||||||
</div>
|
</div>
|
||||||
@@ -74,11 +80,30 @@
|
|||||||
When key metadata fields are changed, both files of a key
|
When key metadata fields are changed, both files of a key
|
||||||
pair (<code class="filename">Knnnn.+aaa+iiiii.key</code> and
|
pair (<code class="filename">Knnnn.+aaa+iiiii.key</code> and
|
||||||
<code class="filename">Knnnn.+aaa+iiiii.private</code>) are regenerated.
|
<code class="filename">Knnnn.+aaa+iiiii.private</code>) are regenerated.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
Metadata fields are stored in the private file. A human-readable
|
Metadata fields are stored in the private file. A human-readable
|
||||||
description of the metadata is also placed in comments in the key
|
description of the metadata is also placed in comments in the key
|
||||||
file. The private file's permissions are always set to be
|
file. The private file's permissions are always set to be
|
||||||
inaccessible to anyone other than the owner (mode 0600).
|
inaccessible to anyone other than the owner (mode 0600).
|
||||||
</p>
|
</p>
|
||||||
|
<p>
|
||||||
|
When working with state files, it is possible to update the timing
|
||||||
|
metadata in those files as well with <code class="option">-s</code>. If this
|
||||||
|
option is used you can also update key states with <code class="option">-d</code>
|
||||||
|
(DS), <code class="option">-k</code> (DNSKEY), <code class="option">-r</code> (RRSIG of KSK),
|
||||||
|
or <code class="option">-z</code> (RRSIG of ZSK). Allowed states are HIDDEN,
|
||||||
|
RUMOURED, OMNIPRESENT, and UNRETENTIVE.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
You can also set the goal state of the key with <code class="option">-g</code>.
|
||||||
|
This should be either HIDDEN or OMNIPRESENT (representing whether the
|
||||||
|
key should be removed from the zone, or published).
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
It is NOT RECOMMENDED to manipulate state files manually except for
|
||||||
|
testing purposes.
|
||||||
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
@@ -262,7 +287,57 @@
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.10"></a><h2>PRINTING OPTIONS</h2>
|
<a name="id-1.10"></a><h2>KEY STATE OPTIONS</h2>
|
||||||
|
|
||||||
|
<p>
|
||||||
|
Known key states are HIDDEN, RUMOURED, OMNIPRESENT and UNRETENTIVE.
|
||||||
|
These should not be set manually except for testing purposes.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<div class="variablelist"><dl class="variablelist">
|
||||||
|
<dt><span class="term">-s</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
When setting key timing data, also update the state file.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-g</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Set the goal state for this key. Must be HIDDEN or OMNIPRESENT.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-d</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Set the DS state for this key, and when it was last changed.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-k</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Set the DNSKEY state for this key, and when it was last changed.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-r</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Set the RRSIG (KSK) state for this key, and when it was last
|
||||||
|
changed.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
<dt><span class="term">-z</span></dt>
|
||||||
|
<dd>
|
||||||
|
<p>
|
||||||
|
Set the RRSIG (ZSK) state for this key, and when it was last
|
||||||
|
changed.
|
||||||
|
</p>
|
||||||
|
</dd>
|
||||||
|
</dl></div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="refsection">
|
||||||
|
<a name="id-1.11"></a><h2>PRINTING OPTIONS</h2>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
<span class="command"><strong>dnssec-settime</strong></span> can also be used to print the
|
<span class="command"><strong>dnssec-settime</strong></span> can also be used to print the
|
||||||
@@ -298,7 +373,7 @@
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.11"></a><h2>SEE ALSO</h2>
|
<a name="id-1.12"></a><h2>SEE ALSO</h2>
|
||||||
|
|
||||||
<p><span class="citerefentry">
|
<p><span class="citerefentry">
|
||||||
<span class="refentrytitle">dnssec-keygen</span>(8)
|
<span class="refentrytitle">dnssec-keygen</span>(8)
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2009, 2011-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2009, 2011-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -470,5 +470,5 @@ RFC 4641\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2009, 2011-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2009, 2011-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -226,8 +226,7 @@ dumpnode(dns_name_t *name, dns_dbnode_t *node) {
|
|||||||
|
|
||||||
dns_rdataset_init(&rds);
|
dns_rdataset_init(&rds);
|
||||||
|
|
||||||
result = isc_buffer_allocate(mctx, &buffer, bufsize);
|
isc_buffer_allocate(mctx, &buffer, bufsize);
|
||||||
check_result(result, "isc_buffer_allocate");
|
|
||||||
|
|
||||||
for (result = dns_rdatasetiter_first(iter);
|
for (result = dns_rdatasetiter_first(iter);
|
||||||
result == ISC_R_SUCCESS;
|
result == ISC_R_SUCCESS;
|
||||||
@@ -246,14 +245,14 @@ dumpnode(dns_name_t *name, dns_dbnode_t *node) {
|
|||||||
|
|
||||||
for (;;) {
|
for (;;) {
|
||||||
result = dns_master_rdatasettotext(name, &rds,
|
result = dns_master_rdatasettotext(name, &rds,
|
||||||
masterstyle, buffer);
|
masterstyle, NULL,
|
||||||
|
buffer);
|
||||||
if (result != ISC_R_NOSPACE)
|
if (result != ISC_R_NOSPACE)
|
||||||
break;
|
break;
|
||||||
|
|
||||||
bufsize <<= 1;
|
bufsize <<= 1;
|
||||||
isc_buffer_free(&buffer);
|
isc_buffer_free(&buffer);
|
||||||
result = isc_buffer_allocate(mctx, &buffer, bufsize);
|
isc_buffer_allocate(mctx, &buffer, bufsize);
|
||||||
check_result(result, "isc_buffer_allocate");
|
|
||||||
}
|
}
|
||||||
check_result(result, "dns_master_rdatasettotext");
|
check_result(result, "dns_master_rdatasettotext");
|
||||||
|
|
||||||
@@ -3921,7 +3920,6 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
dns_name_destroy();
|
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|||||||
@@ -51,6 +51,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2009, 2011-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2009, 2011-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -120,5 +120,5 @@ RFC 4033\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -335,7 +335,6 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
cleanup_logging(&log);
|
cleanup_logging(&log);
|
||||||
dst_lib_destroy();
|
dst_lib_destroy();
|
||||||
dns_name_destroy();
|
|
||||||
if (verbose > 10)
|
if (verbose > 10)
|
||||||
isc_mem_stats(mctx, stdout);
|
isc_mem_stats(mctx, stdout);
|
||||||
isc_mem_destroy(&mctx);
|
isc_mem_destroy(&mctx);
|
||||||
|
|||||||
@@ -38,6 +38,7 @@
|
|||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2012, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2012, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
+2
-5
@@ -296,7 +296,7 @@ view \"_bind\" chaos {\n\
|
|||||||
# BEGIN DNSSEC KEYS\n"
|
# BEGIN DNSSEC KEYS\n"
|
||||||
|
|
||||||
/* Imported from bind.keys.h: */
|
/* Imported from bind.keys.h: */
|
||||||
DNSSEC_KEYS
|
TRUST_ANCHORS
|
||||||
|
|
||||||
"# END MANAGED KEYS\n\
|
"# END MANAGED KEYS\n\
|
||||||
\n\
|
\n\
|
||||||
@@ -800,10 +800,7 @@ named_config_getipandkeylist(const cfg_obj_t *config, const cfg_obj_t *list,
|
|||||||
dns_rootname, 0, NULL);
|
dns_rootname, 0, NULL);
|
||||||
if (result != ISC_R_SUCCESS)
|
if (result != ISC_R_SUCCESS)
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
result = dns_name_dup(dns_fixedname_name(&fname), mctx,
|
dns_name_dup(dns_fixedname_name(&fname), mctx, keys[i - 1]);
|
||||||
keys[i - 1]);
|
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
goto cleanup;
|
|
||||||
}
|
}
|
||||||
if (pushed != 0) {
|
if (pushed != 0) {
|
||||||
pushed--;
|
pushed--;
|
||||||
|
|||||||
@@ -445,9 +445,7 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
|||||||
goto cleanup_request;
|
goto cleanup_request;
|
||||||
}
|
}
|
||||||
|
|
||||||
result = isc_buffer_allocate(listener->mctx, &text, 2 * 2048);
|
isc_buffer_allocate(listener->mctx, &text, 2 * 2048);
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
goto cleanup_request;
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Establish nonce.
|
* Establish nonce.
|
||||||
@@ -493,10 +491,7 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
|||||||
goto cleanup_response;
|
goto cleanup_response;
|
||||||
|
|
||||||
if (conn->buffer == NULL) {
|
if (conn->buffer == NULL) {
|
||||||
result = isc_buffer_allocate(listener->mctx,
|
isc_buffer_allocate(listener->mctx, &conn->buffer, 2 * 2048);
|
||||||
&conn->buffer, 2 * 2048);
|
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
goto cleanup_response;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_buffer_clear(conn->buffer);
|
isc_buffer_clear(conn->buffer);
|
||||||
|
|||||||
+8
-4
@@ -113,8 +113,7 @@ named_geoip_load(char *dir) {
|
|||||||
#endif
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
void
|
void named_geoip_unload(void) {
|
||||||
named_geoip_shutdown(void) {
|
|
||||||
#ifdef HAVE_GEOIP2
|
#ifdef HAVE_GEOIP2
|
||||||
if (named_g_geoip->country != NULL) {
|
if (named_g_geoip->country != NULL) {
|
||||||
MMDB_close(named_g_geoip->country);
|
MMDB_close(named_g_geoip->country);
|
||||||
@@ -136,7 +135,12 @@ named_geoip_shutdown(void) {
|
|||||||
MMDB_close(named_g_geoip->domain);
|
MMDB_close(named_g_geoip->domain);
|
||||||
named_g_geoip->domain = NULL;
|
named_g_geoip->domain = NULL;
|
||||||
}
|
}
|
||||||
|
#endif
|
||||||
|
}
|
||||||
|
|
||||||
|
void
|
||||||
|
named_geoip_shutdown(void) {
|
||||||
|
#ifdef HAVE_GEOIP2
|
||||||
|
named_geoip_unload();
|
||||||
#endif /* HAVE_GEOIP2 */
|
#endif /* HAVE_GEOIP2 */
|
||||||
|
|
||||||
dns_geoip_shutdown();
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -19,5 +19,8 @@ named_geoip_init(void);
|
|||||||
void
|
void
|
||||||
named_geoip_load(char *dir);
|
named_geoip_load(char *dir);
|
||||||
|
|
||||||
|
void
|
||||||
|
named_geoip_unload(void);
|
||||||
|
|
||||||
void
|
void
|
||||||
named_geoip_shutdown(void);
|
named_geoip_shutdown(void);
|
||||||
|
|||||||
+45
-12
@@ -23,6 +23,7 @@
|
|||||||
#include <isc/dir.h>
|
#include <isc/dir.h>
|
||||||
#include <isc/file.h>
|
#include <isc/file.h>
|
||||||
#include <isc/hash.h>
|
#include <isc/hash.h>
|
||||||
|
#include <isc/hp.h>
|
||||||
#include <isc/httpd.h>
|
#include <isc/httpd.h>
|
||||||
#include <isc/netmgr.h>
|
#include <isc/netmgr.h>
|
||||||
#include <isc/os.h>
|
#include <isc/os.h>
|
||||||
@@ -59,6 +60,10 @@
|
|||||||
#include <json_c_version.h>
|
#include <json_c_version.h>
|
||||||
#endif /* HAVE_JSON_C */
|
#endif /* HAVE_JSON_C */
|
||||||
|
|
||||||
|
#ifdef HAVE_GEOIP2
|
||||||
|
#include <maxminddb.h>
|
||||||
|
#endif
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Defining NAMED_MAIN provides storage declarations (rather than extern)
|
* Defining NAMED_MAIN provides storage declarations (rather than extern)
|
||||||
* for variables in named/globals.h.
|
* for variables in named/globals.h.
|
||||||
@@ -116,7 +121,7 @@ LIBDNS_EXTERNAL_DATA extern unsigned int dns_zone_mkey_month;
|
|||||||
static bool want_stats = false;
|
static bool want_stats = false;
|
||||||
static char program_name[NAME_MAX] = "named";
|
static char program_name[NAME_MAX] = "named";
|
||||||
static char absolute_conffile[PATH_MAX];
|
static char absolute_conffile[PATH_MAX];
|
||||||
static char saved_command_line[8192] = { 0 };
|
static char saved_command_line[4096] = { 0 };
|
||||||
static char ellipsis[5] = { 0 };
|
static char ellipsis[5] = { 0 };
|
||||||
static char version[512];
|
static char version[512];
|
||||||
static unsigned int maxsocks = 0;
|
static unsigned int maxsocks = 0;
|
||||||
@@ -136,7 +141,6 @@ static bool nonearest = false;
|
|||||||
static bool nosoa = false;
|
static bool nosoa = false;
|
||||||
static bool notcp = false;
|
static bool notcp = false;
|
||||||
static bool sigvalinsecs = false;
|
static bool sigvalinsecs = false;
|
||||||
static unsigned int delay = 0;
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* -4 and -6
|
* -4 and -6
|
||||||
@@ -548,6 +552,17 @@ OPENSSL_VERSION_NUMBER >= 0x10100000L /* 1.1.0 or higher */
|
|||||||
ZLIB_VERSION);
|
ZLIB_VERSION);
|
||||||
printf("linked to zlib version: %s\n",
|
printf("linked to zlib version: %s\n",
|
||||||
zlibVersion());
|
zlibVersion());
|
||||||
|
#endif
|
||||||
|
#if defined(HAVE_GEOIP2)
|
||||||
|
/* Unfortunately, no version define on link time */
|
||||||
|
printf("linked to maxminddb version: %s\n",
|
||||||
|
MMDB_lib_version());
|
||||||
|
#endif
|
||||||
|
#if defined(HAVE_DNSTAP)
|
||||||
|
printf("compiled with protobuf-c version: %s\n",
|
||||||
|
PROTOBUF_C_VERSION);
|
||||||
|
printf("linked to protobuf-c version: %s\n",
|
||||||
|
protobuf_c_version());
|
||||||
#endif
|
#endif
|
||||||
printf("threads support is enabled\n\n");
|
printf("threads support is enabled\n\n");
|
||||||
|
|
||||||
@@ -622,14 +637,10 @@ parse_T_opt(char *option) {
|
|||||||
/*
|
/*
|
||||||
* force the server to behave (or misbehave) in
|
* force the server to behave (or misbehave) in
|
||||||
* specified ways for testing purposes.
|
* specified ways for testing purposes.
|
||||||
* delay=xxxx: delay client responses by xxxx ms to
|
|
||||||
* simulate remote servers.
|
|
||||||
* dscp=x: check that dscp values are as
|
* dscp=x: check that dscp values are as
|
||||||
* expected and assert otherwise.
|
* expected and assert otherwise.
|
||||||
*/
|
*/
|
||||||
if (!strncmp(option, "delay=", 6)) {
|
if (!strcmp(option, "dropedns")) {
|
||||||
delay = atoi(option + 6);
|
|
||||||
} else if (!strcmp(option, "dropedns")) {
|
|
||||||
dropedns = true;
|
dropedns = true;
|
||||||
} else if (!strncmp(option, "dscp=", 5)) {
|
} else if (!strncmp(option, "dscp=", 5)) {
|
||||||
isc_dscp_check_value = atoi(option + 5);
|
isc_dscp_check_value = atoi(option + 5);
|
||||||
@@ -892,6 +903,12 @@ create_managers(void) {
|
|||||||
"using %u UDP listener%s per interface",
|
"using %u UDP listener%s per interface",
|
||||||
named_g_udpdisp, named_g_udpdisp == 1 ? "" : "s");
|
named_g_udpdisp, named_g_udpdisp == 1 ? "" : "s");
|
||||||
|
|
||||||
|
/*
|
||||||
|
* We have ncpus network threads, ncpus worker threads, ncpus
|
||||||
|
* old network threads - make it 4x just to be safe. The memory
|
||||||
|
* impact is neglible.
|
||||||
|
*/
|
||||||
|
isc_hp_init(4*named_g_cpus);
|
||||||
named_g_nm = isc_nm_start(named_g_mctx, named_g_cpus);
|
named_g_nm = isc_nm_start(named_g_mctx, named_g_cpus);
|
||||||
if (named_g_nm == NULL) {
|
if (named_g_nm == NULL) {
|
||||||
UNEXPECTED_ERROR(__FILE__, __LINE__,
|
UNEXPECTED_ERROR(__FILE__, __LINE__,
|
||||||
@@ -939,11 +956,23 @@ create_managers(void) {
|
|||||||
static void
|
static void
|
||||||
destroy_managers(void) {
|
destroy_managers(void) {
|
||||||
/*
|
/*
|
||||||
* isc_taskmgr_destroy() will block until all tasks have exited,
|
* isc_nm_closedown() closes all active connections, freeing
|
||||||
|
* attached clients and other resources and preventing new
|
||||||
|
* connections from being established, but it not does not
|
||||||
|
* stop all processing or destroy the netmgr yet.
|
||||||
|
*/
|
||||||
|
isc_nm_closedown(named_g_nm);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* isc_taskmgr_destroy() will block until all tasks have exited.
|
||||||
*/
|
*/
|
||||||
isc_taskmgr_destroy(&named_g_taskmgr);
|
isc_taskmgr_destroy(&named_g_taskmgr);
|
||||||
isc_timermgr_destroy(&named_g_timermgr);
|
isc_timermgr_destroy(&named_g_timermgr);
|
||||||
isc_socketmgr_destroy(&named_g_socketmgr);
|
isc_socketmgr_destroy(&named_g_socketmgr);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* At this point is safe to destroy the netmgr.
|
||||||
|
*/
|
||||||
isc_nm_destroy(&named_g_nm);
|
isc_nm_destroy(&named_g_nm);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1284,8 +1313,6 @@ setup(void) {
|
|||||||
ns_server_setoption(sctx, NS_SERVER_NOTCP, true);
|
ns_server_setoption(sctx, NS_SERVER_NOTCP, true);
|
||||||
if (sigvalinsecs)
|
if (sigvalinsecs)
|
||||||
ns_server_setoption(sctx, NS_SERVER_SIGVALINSECS, true);
|
ns_server_setoption(sctx, NS_SERVER_SIGVALINSECS, true);
|
||||||
|
|
||||||
named_g_server->sctx->delay = delay;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
@@ -1317,8 +1344,6 @@ cleanup(void) {
|
|||||||
dlz_dlopen_clear();
|
dlz_dlopen_clear();
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
dns_name_destroy();
|
|
||||||
|
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_MAIN,
|
NAMED_LOGMODULE_MAIN,
|
||||||
ISC_LOG_NOTICE, "exiting");
|
ISC_LOG_NOTICE, "exiting");
|
||||||
@@ -1431,6 +1456,10 @@ main(int argc, char *argv[]) {
|
|||||||
setvbuf(stderr, NULL, _IOFBF, BUFSIZ);
|
setvbuf(stderr, NULL, _IOFBF, BUFSIZ);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
#ifdef HAVE_LIBXML2
|
||||||
|
xmlInitThreads();
|
||||||
|
#endif /* HAVE_LIBXML2 */
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Record version in core image.
|
* Record version in core image.
|
||||||
* strings named.core | grep "named version:"
|
* strings named.core | grep "named version:"
|
||||||
@@ -1563,6 +1592,10 @@ main(int argc, char *argv[]) {
|
|||||||
|
|
||||||
named_os_shutdown();
|
named_os_shutdown();
|
||||||
|
|
||||||
|
#ifdef HAVE_LIBXML2
|
||||||
|
xmlCleanupThreads();
|
||||||
|
#endif /* HAVE_LIBXML2 */
|
||||||
|
|
||||||
#ifdef HAVE_GPERFTOOLS_PROFILER
|
#ifdef HAVE_GPERFTOOLS_PROFILER
|
||||||
ProfilerStop();
|
ProfilerStop();
|
||||||
#endif
|
#endif
|
||||||
|
|||||||
+2
-2
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000, 2001, 2003-2009, 2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000, 2001, 2003-2009, 2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -378,5 +378,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000, 2001, 2003-2009, 2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000, 2001, 2003-2009, 2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+90
-61
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2004-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2004-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -10,12 +10,12 @@
|
|||||||
.\" Title: named.conf
|
.\" Title: named.conf
|
||||||
.\" Author:
|
.\" Author:
|
||||||
.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
|
.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
|
||||||
.\" Date: 2019-08-07
|
.\" Date: 2019-08-12
|
||||||
.\" Manual: BIND9
|
.\" Manual: BIND9
|
||||||
.\" Source: ISC
|
.\" Source: ISC
|
||||||
.\" Language: English
|
.\" Language: English
|
||||||
.\"
|
.\"
|
||||||
.TH "NAMED\&.CONF" "5" "2019\-08\-07" "ISC" "BIND9"
|
.TH "NAMED\&.CONF" "5" "2019\-08\-12" "ISC" "BIND9"
|
||||||
.\" -----------------------------------------------------------------
|
.\" -----------------------------------------------------------------
|
||||||
.\" * Define some portability stuff
|
.\" * Define some portability stuff
|
||||||
.\" -----------------------------------------------------------------
|
.\" -----------------------------------------------------------------
|
||||||
@@ -97,19 +97,6 @@ dlz \fIstring\fR {
|
|||||||
.if n \{\
|
.if n \{\
|
||||||
.RE
|
.RE
|
||||||
.\}
|
.\}
|
||||||
.SH "DNSSEC-KEYS"
|
|
||||||
.sp
|
|
||||||
.if n \{\
|
|
||||||
.RS 4
|
|
||||||
.\}
|
|
||||||
.nf
|
|
||||||
dnssec\-keys { \fIstring\fR ( static\-key |
|
|
||||||
initial\-key ) \fIinteger\fR \fIinteger\fR \fIinteger\fR
|
|
||||||
\fIquoted_string\fR; \&.\&.\&. };
|
|
||||||
.fi
|
|
||||||
.if n \{\
|
|
||||||
.RE
|
|
||||||
.\}
|
|
||||||
.SH "DYNDB"
|
.SH "DYNDB"
|
||||||
.sp
|
.sp
|
||||||
.if n \{\
|
.if n \{\
|
||||||
@@ -163,16 +150,16 @@ logging {
|
|||||||
.\}
|
.\}
|
||||||
.SH "MANAGED-KEYS"
|
.SH "MANAGED-KEYS"
|
||||||
.PP
|
.PP
|
||||||
Deprecated \- see DNSSEC\-KEYS\&.
|
Deprecated \- see TRUST\-ANCHORS\&.
|
||||||
.sp
|
.sp
|
||||||
.if n \{\
|
.if n \{\
|
||||||
.RS 4
|
.RS 4
|
||||||
.\}
|
.\}
|
||||||
.nf
|
.nf
|
||||||
managed\-keys { \fIstring\fR ( static\-key
|
managed\-keys { \fIstring\fR ( static\-key
|
||||||
| initial\-key ) \fIinteger\fR
|
| initial\-key | static\-ds |
|
||||||
\fIinteger\fR \fIinteger\fR
|
initial\-ds ) \fIinteger\fR \fIinteger\fR
|
||||||
\fIquoted_string\fR; \&.\&.\&. }; deprecated
|
\fIinteger\fR \fIquoted_string\fR; \&.\&.\&. }; deprecated
|
||||||
.fi
|
.fi
|
||||||
.if n \{\
|
.if n \{\
|
||||||
.RE
|
.RE
|
||||||
@@ -230,7 +217,7 @@ options {
|
|||||||
[ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [ port
|
[ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [ port
|
||||||
\fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
|
\fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
|
||||||
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
|
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
|
||||||
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIttlval\fR ]; \&.\&.\&. };
|
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIduration\fR ]; \&.\&.\&. };
|
||||||
check\-dup\-records ( fail | warn | ignore );
|
check\-dup\-records ( fail | warn | ignore );
|
||||||
check\-integrity \fIboolean\fR;
|
check\-integrity \fIboolean\fR;
|
||||||
check\-mx ( fail | warn | ignore );
|
check\-mx ( fail | warn | ignore );
|
||||||
@@ -312,18 +299,18 @@ options {
|
|||||||
fstrm\-set\-output\-notify\-threshold \fIinteger\fR;
|
fstrm\-set\-output\-notify\-threshold \fIinteger\fR;
|
||||||
fstrm\-set\-output\-queue\-model ( mpsc | spsc );
|
fstrm\-set\-output\-queue\-model ( mpsc | spsc );
|
||||||
fstrm\-set\-output\-queue\-size \fIinteger\fR;
|
fstrm\-set\-output\-queue\-size \fIinteger\fR;
|
||||||
fstrm\-set\-reopen\-interval \fIttlval\fR;
|
fstrm\-set\-reopen\-interval \fIduration\fR;
|
||||||
geoip\-directory ( \fIquoted_string\fR | none );
|
geoip\-directory ( \fIquoted_string\fR | none );
|
||||||
glue\-cache \fIboolean\fR;
|
glue\-cache \fIboolean\fR;
|
||||||
heartbeat\-interval \fIinteger\fR;
|
heartbeat\-interval \fIinteger\fR;
|
||||||
hostname ( \fIquoted_string\fR | none );
|
hostname ( \fIquoted_string\fR | none );
|
||||||
inline\-signing \fIboolean\fR;
|
inline\-signing \fIboolean\fR;
|
||||||
interface\-interval \fIttlval\fR;
|
interface\-interval \fIduration\fR;
|
||||||
ixfr\-from\-differences ( primary | master | secondary | slave |
|
ixfr\-from\-differences ( primary | master | secondary | slave |
|
||||||
\fIboolean\fR );
|
\fIboolean\fR );
|
||||||
keep\-response\-order { \fIaddress_match_element\fR; \&.\&.\&. };
|
keep\-response\-order { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||||
key\-directory \fIquoted_string\fR;
|
key\-directory \fIquoted_string\fR;
|
||||||
lame\-ttl \fIttlval\fR;
|
lame\-ttl \fIduration\fR;
|
||||||
listen\-on [ port \fIinteger\fR ] [ dscp
|
listen\-on [ port \fIinteger\fR ] [ dscp
|
||||||
\fIinteger\fR ] {
|
\fIinteger\fR ] {
|
||||||
\fIaddress_match_element\fR; \&.\&.\&. };
|
\fIaddress_match_element\fR; \&.\&.\&. };
|
||||||
@@ -337,28 +324,28 @@ options {
|
|||||||
masterfile\-style ( full | relative );
|
masterfile\-style ( full | relative );
|
||||||
match\-mapped\-addresses \fIboolean\fR;
|
match\-mapped\-addresses \fIboolean\fR;
|
||||||
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
|
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
|
||||||
max\-cache\-ttl \fIttlval\fR;
|
max\-cache\-ttl \fIduration\fR;
|
||||||
max\-clients\-per\-query \fIinteger\fR;
|
max\-clients\-per\-query \fIinteger\fR;
|
||||||
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
|
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
|
||||||
max\-ncache\-ttl \fIttlval\fR;
|
max\-ncache\-ttl \fIduration\fR;
|
||||||
max\-records \fIinteger\fR;
|
max\-records \fIinteger\fR;
|
||||||
max\-recursion\-depth \fIinteger\fR;
|
max\-recursion\-depth \fIinteger\fR;
|
||||||
max\-recursion\-queries \fIinteger\fR;
|
max\-recursion\-queries \fIinteger\fR;
|
||||||
max\-refresh\-time \fIinteger\fR;
|
max\-refresh\-time \fIinteger\fR;
|
||||||
max\-retry\-time \fIinteger\fR;
|
max\-retry\-time \fIinteger\fR;
|
||||||
max\-rsa\-exponent\-size \fIinteger\fR;
|
max\-rsa\-exponent\-size \fIinteger\fR;
|
||||||
max\-stale\-ttl \fIttlval\fR;
|
max\-stale\-ttl \fIduration\fR;
|
||||||
max\-transfer\-idle\-in \fIinteger\fR;
|
max\-transfer\-idle\-in \fIinteger\fR;
|
||||||
max\-transfer\-idle\-out \fIinteger\fR;
|
max\-transfer\-idle\-out \fIinteger\fR;
|
||||||
max\-transfer\-time\-in \fIinteger\fR;
|
max\-transfer\-time\-in \fIinteger\fR;
|
||||||
max\-transfer\-time\-out \fIinteger\fR;
|
max\-transfer\-time\-out \fIinteger\fR;
|
||||||
max\-udp\-size \fIinteger\fR;
|
max\-udp\-size \fIinteger\fR;
|
||||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||||
memstatistics \fIboolean\fR;
|
memstatistics \fIboolean\fR;
|
||||||
memstatistics\-file \fIquoted_string\fR;
|
memstatistics\-file \fIquoted_string\fR;
|
||||||
message\-compression \fIboolean\fR;
|
message\-compression \fIboolean\fR;
|
||||||
min\-cache\-ttl \fIttlval\fR;
|
min\-cache\-ttl \fIduration\fR;
|
||||||
min\-ncache\-ttl \fIttlval\fR;
|
min\-ncache\-ttl \fIduration\fR;
|
||||||
min\-refresh\-time \fIinteger\fR;
|
min\-refresh\-time \fIinteger\fR;
|
||||||
min\-retry\-time \fIinteger\fR;
|
min\-retry\-time \fIinteger\fR;
|
||||||
minimal\-any \fIboolean\fR;
|
minimal\-any \fIboolean\fR;
|
||||||
@@ -375,8 +362,8 @@ options {
|
|||||||
notify\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) ]
|
notify\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) ]
|
||||||
[ dscp \fIinteger\fR ];
|
[ dscp \fIinteger\fR ];
|
||||||
notify\-to\-soa \fIboolean\fR;
|
notify\-to\-soa \fIboolean\fR;
|
||||||
nta\-lifetime \fIttlval\fR;
|
nta\-lifetime \fIduration\fR;
|
||||||
nta\-recheck \fIttlval\fR;
|
nta\-recheck \fIduration\fR;
|
||||||
nxdomain\-redirect \fIstring\fR;
|
nxdomain\-redirect \fIstring\fR;
|
||||||
pid\-file ( \fIquoted_string\fR | none );
|
pid\-file ( \fIquoted_string\fR | none );
|
||||||
port \fIinteger\fR;
|
port \fIinteger\fR;
|
||||||
@@ -423,13 +410,13 @@ options {
|
|||||||
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
|
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
|
||||||
\fIinteger\fR;
|
\fIinteger\fR;
|
||||||
response\-policy { zone \fIstring\fR [ add\-soa \fIboolean\fR ] [ log
|
response\-policy { zone \fIstring\fR [ add\-soa \fIboolean\fR ] [ log
|
||||||
\fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [ min\-update\-interval
|
\fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [ min\-update\-interval
|
||||||
\fIttlval\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
\fIduration\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
||||||
nodata | nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
|
nodata | nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
|
||||||
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||||
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ add\-soa \fIboolean\fR ] [
|
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ add\-soa \fIboolean\fR ] [
|
||||||
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [
|
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [
|
||||||
min\-update\-interval \fIttlval\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
min\-update\-interval \fIduration\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
||||||
nsip\-wait\-recurse \fIboolean\fR ] [ qname\-wait\-recurse \fIboolean\fR ]
|
nsip\-wait\-recurse \fIboolean\fR ] [ qname\-wait\-recurse \fIboolean\fR ]
|
||||||
[ recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
[ recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||||
nsdname\-enable \fIboolean\fR ] [ dnsrps\-enable \fIboolean\fR ] [
|
nsdname\-enable \fIboolean\fR ] [ dnsrps\-enable \fIboolean\fR ] [
|
||||||
@@ -443,7 +430,7 @@ options {
|
|||||||
serial\-query\-rate \fIinteger\fR;
|
serial\-query\-rate \fIinteger\fR;
|
||||||
serial\-update\-method ( date | increment | unixtime );
|
serial\-update\-method ( date | increment | unixtime );
|
||||||
server\-id ( \fIquoted_string\fR | none | hostname );
|
server\-id ( \fIquoted_string\fR | none | hostname );
|
||||||
servfail\-ttl \fIttlval\fR;
|
servfail\-ttl \fIduration\fR;
|
||||||
session\-keyalg \fIstring\fR;
|
session\-keyalg \fIstring\fR;
|
||||||
session\-keyfile ( \fIquoted_string\fR | none );
|
session\-keyfile ( \fIquoted_string\fR | none );
|
||||||
session\-keyname \fIstring\fR;
|
session\-keyname \fIstring\fR;
|
||||||
@@ -454,7 +441,7 @@ options {
|
|||||||
sortlist { \fIaddress_match_element\fR; \&.\&.\&. };
|
sortlist { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||||
stacksize ( default | unlimited | \fIsizeval\fR );
|
stacksize ( default | unlimited | \fIsizeval\fR );
|
||||||
stale\-answer\-enable \fIboolean\fR;
|
stale\-answer\-enable \fIboolean\fR;
|
||||||
stale\-answer\-ttl \fIttlval\fR;
|
stale\-answer\-ttl \fIduration\fR;
|
||||||
startup\-notify\-rate \fIinteger\fR;
|
startup\-notify\-rate \fIinteger\fR;
|
||||||
statistics\-file \fIquoted_string\fR;
|
statistics\-file \fIquoted_string\fR;
|
||||||
synth\-from\-dnssec \fIboolean\fR;
|
synth\-from\-dnssec \fIboolean\fR;
|
||||||
@@ -564,9 +551,23 @@ statistics\-channels {
|
|||||||
.if n \{\
|
.if n \{\
|
||||||
.RE
|
.RE
|
||||||
.\}
|
.\}
|
||||||
|
.SH "TRUST-ANCHORS"
|
||||||
|
.sp
|
||||||
|
.if n \{\
|
||||||
|
.RS 4
|
||||||
|
.\}
|
||||||
|
.nf
|
||||||
|
trust\-anchors { \fIstring\fR ( static\-key |
|
||||||
|
initial\-key | static\-ds | initial\-ds )
|
||||||
|
\fIinteger\fR \fIinteger\fR \fIinteger\fR
|
||||||
|
\fIquoted_string\fR; \&.\&.\&. };
|
||||||
|
.fi
|
||||||
|
.if n \{\
|
||||||
|
.RE
|
||||||
|
.\}
|
||||||
.SH "TRUSTED-KEYS"
|
.SH "TRUSTED-KEYS"
|
||||||
.PP
|
.PP
|
||||||
Deprecated \- see DNSSEC\-KEYS\&.
|
Deprecated \- see TRUST\-ANCHORS\&.
|
||||||
.sp
|
.sp
|
||||||
.if n \{\
|
.if n \{\
|
||||||
.RS 4
|
.RS 4
|
||||||
@@ -612,7 +613,7 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
[ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [ port
|
[ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [ port
|
||||||
\fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
|
\fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
|
||||||
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
|
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
|
||||||
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIttlval\fR ]; \&.\&.\&. };
|
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIduration\fR ]; \&.\&.\&. };
|
||||||
check\-dup\-records ( fail | warn | ignore );
|
check\-dup\-records ( fail | warn | ignore );
|
||||||
check\-integrity \fIboolean\fR;
|
check\-integrity \fIboolean\fR;
|
||||||
check\-mx ( fail | warn | ignore );
|
check\-mx ( fail | warn | ignore );
|
||||||
@@ -654,9 +655,6 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
dnsrps\-options { \fIunspecified\-text\fR };
|
dnsrps\-options { \fIunspecified\-text\fR };
|
||||||
dnssec\-accept\-expired \fIboolean\fR;
|
dnssec\-accept\-expired \fIboolean\fR;
|
||||||
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
||||||
dnssec\-keys { \fIstring\fR ( static\-key |
|
|
||||||
initial\-key ) \fIinteger\fR \fIinteger\fR
|
|
||||||
\fIinteger\fR \fIquoted_string\fR; \&.\&.\&. };
|
|
||||||
dnssec\-loadkeys\-interval \fIinteger\fR;
|
dnssec\-loadkeys\-interval \fIinteger\fR;
|
||||||
dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR;
|
dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR;
|
||||||
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
||||||
@@ -690,10 +688,11 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
secret \fIstring\fR;
|
secret \fIstring\fR;
|
||||||
};
|
};
|
||||||
key\-directory \fIquoted_string\fR;
|
key\-directory \fIquoted_string\fR;
|
||||||
lame\-ttl \fIttlval\fR;
|
lame\-ttl \fIduration\fR;
|
||||||
lmdb\-mapsize \fIsizeval\fR;
|
lmdb\-mapsize \fIsizeval\fR;
|
||||||
managed\-keys { \fIstring\fR (
|
managed\-keys { \fIstring\fR (
|
||||||
static\-key | initial\-key
|
static\-key | initial\-key
|
||||||
|
| static\-ds | initial\-ds
|
||||||
) \fIinteger\fR \fIinteger\fR
|
) \fIinteger\fR \fIinteger\fR
|
||||||
\fIinteger\fR
|
\fIinteger\fR
|
||||||
\fIquoted_string\fR; \&.\&.\&. }; deprecated
|
\fIquoted_string\fR; \&.\&.\&. }; deprecated
|
||||||
@@ -703,25 +702,25 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
match\-destinations { \fIaddress_match_element\fR; \&.\&.\&. };
|
match\-destinations { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||||
match\-recursive\-only \fIboolean\fR;
|
match\-recursive\-only \fIboolean\fR;
|
||||||
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
|
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
|
||||||
max\-cache\-ttl \fIttlval\fR;
|
max\-cache\-ttl \fIduration\fR;
|
||||||
max\-clients\-per\-query \fIinteger\fR;
|
max\-clients\-per\-query \fIinteger\fR;
|
||||||
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
|
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
|
||||||
max\-ncache\-ttl \fIttlval\fR;
|
max\-ncache\-ttl \fIduration\fR;
|
||||||
max\-records \fIinteger\fR;
|
max\-records \fIinteger\fR;
|
||||||
max\-recursion\-depth \fIinteger\fR;
|
max\-recursion\-depth \fIinteger\fR;
|
||||||
max\-recursion\-queries \fIinteger\fR;
|
max\-recursion\-queries \fIinteger\fR;
|
||||||
max\-refresh\-time \fIinteger\fR;
|
max\-refresh\-time \fIinteger\fR;
|
||||||
max\-retry\-time \fIinteger\fR;
|
max\-retry\-time \fIinteger\fR;
|
||||||
max\-stale\-ttl \fIttlval\fR;
|
max\-stale\-ttl \fIduration\fR;
|
||||||
max\-transfer\-idle\-in \fIinteger\fR;
|
max\-transfer\-idle\-in \fIinteger\fR;
|
||||||
max\-transfer\-idle\-out \fIinteger\fR;
|
max\-transfer\-idle\-out \fIinteger\fR;
|
||||||
max\-transfer\-time\-in \fIinteger\fR;
|
max\-transfer\-time\-in \fIinteger\fR;
|
||||||
max\-transfer\-time\-out \fIinteger\fR;
|
max\-transfer\-time\-out \fIinteger\fR;
|
||||||
max\-udp\-size \fIinteger\fR;
|
max\-udp\-size \fIinteger\fR;
|
||||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||||
message\-compression \fIboolean\fR;
|
message\-compression \fIboolean\fR;
|
||||||
min\-cache\-ttl \fIttlval\fR;
|
min\-cache\-ttl \fIduration\fR;
|
||||||
min\-ncache\-ttl \fIttlval\fR;
|
min\-ncache\-ttl \fIduration\fR;
|
||||||
min\-refresh\-time \fIinteger\fR;
|
min\-refresh\-time \fIinteger\fR;
|
||||||
min\-retry\-time \fIinteger\fR;
|
min\-retry\-time \fIinteger\fR;
|
||||||
minimal\-any \fIboolean\fR;
|
minimal\-any \fIboolean\fR;
|
||||||
@@ -737,8 +736,8 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
notify\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) ]
|
notify\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * ) ]
|
||||||
[ dscp \fIinteger\fR ];
|
[ dscp \fIinteger\fR ];
|
||||||
notify\-to\-soa \fIboolean\fR;
|
notify\-to\-soa \fIboolean\fR;
|
||||||
nta\-lifetime \fIttlval\fR;
|
nta\-lifetime \fIduration\fR;
|
||||||
nta\-recheck \fIttlval\fR;
|
nta\-recheck \fIduration\fR;
|
||||||
nxdomain\-redirect \fIstring\fR;
|
nxdomain\-redirect \fIstring\fR;
|
||||||
plugin ( query ) \fIstring\fR [ {
|
plugin ( query ) \fIstring\fR [ {
|
||||||
\fIunspecified\-text\fR } ];
|
\fIunspecified\-text\fR } ];
|
||||||
@@ -780,13 +779,13 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
|
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
|
||||||
\fIinteger\fR;
|
\fIinteger\fR;
|
||||||
response\-policy { zone \fIstring\fR [ add\-soa \fIboolean\fR ] [ log
|
response\-policy { zone \fIstring\fR [ add\-soa \fIboolean\fR ] [ log
|
||||||
\fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [ min\-update\-interval
|
\fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [ min\-update\-interval
|
||||||
\fIttlval\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
\fIduration\fR ] [ policy ( cname | disabled | drop | given | no\-op |
|
||||||
nodata | nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
|
nodata | nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
|
||||||
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||||
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ add\-soa \fIboolean\fR ] [
|
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ add\-soa \fIboolean\fR ] [
|
||||||
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIttlval\fR ] [
|
break\-dnssec \fIboolean\fR ] [ max\-policy\-ttl \fIduration\fR ] [
|
||||||
min\-update\-interval \fIttlval\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
min\-update\-interval \fIduration\fR ] [ min\-ns\-dots \fIinteger\fR ] [
|
||||||
nsip\-wait\-recurse \fIboolean\fR ] [ qname\-wait\-recurse \fIboolean\fR ]
|
nsip\-wait\-recurse \fIboolean\fR ] [ qname\-wait\-recurse \fIboolean\fR ]
|
||||||
[ recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
[ recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
|
||||||
nsdname\-enable \fIboolean\fR ] [ dnsrps\-enable \fIboolean\fR ] [
|
nsdname\-enable \fIboolean\fR ] [ dnsrps\-enable \fIboolean\fR ] [
|
||||||
@@ -831,14 +830,14 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
\fIinteger\fR | * ) ] [ dscp \fIinteger\fR ];
|
\fIinteger\fR | * ) ] [ dscp \fIinteger\fR ];
|
||||||
transfers \fIinteger\fR;
|
transfers \fIinteger\fR;
|
||||||
};
|
};
|
||||||
servfail\-ttl \fIttlval\fR;
|
servfail\-ttl \fIduration\fR;
|
||||||
sig\-signing\-nodes \fIinteger\fR;
|
sig\-signing\-nodes \fIinteger\fR;
|
||||||
sig\-signing\-signatures \fIinteger\fR;
|
sig\-signing\-signatures \fIinteger\fR;
|
||||||
sig\-signing\-type \fIinteger\fR;
|
sig\-signing\-type \fIinteger\fR;
|
||||||
sig\-validity\-interval \fIinteger\fR [ \fIinteger\fR ];
|
sig\-validity\-interval \fIinteger\fR [ \fIinteger\fR ];
|
||||||
sortlist { \fIaddress_match_element\fR; \&.\&.\&. };
|
sortlist { \fIaddress_match_element\fR; \&.\&.\&. };
|
||||||
stale\-answer\-enable \fIboolean\fR;
|
stale\-answer\-enable \fIboolean\fR;
|
||||||
stale\-answer\-ttl \fIttlval\fR;
|
stale\-answer\-ttl \fIduration\fR;
|
||||||
synth\-from\-dnssec \fIboolean\fR;
|
synth\-from\-dnssec \fIboolean\fR;
|
||||||
transfer\-format ( many\-answers | one\-answer );
|
transfer\-format ( many\-answers | one\-answer );
|
||||||
transfer\-source ( \fIipv4_address\fR | * ) [ port ( \fIinteger\fR | * ) ] [
|
transfer\-source ( \fIipv4_address\fR | * ) [ port ( \fIinteger\fR | * ) ] [
|
||||||
@@ -846,6 +845,10 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
transfer\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * )
|
transfer\-source\-v6 ( \fIipv6_address\fR | * ) [ port ( \fIinteger\fR | * )
|
||||||
] [ dscp \fIinteger\fR ];
|
] [ dscp \fIinteger\fR ];
|
||||||
trust\-anchor\-telemetry \fIboolean\fR; // experimental
|
trust\-anchor\-telemetry \fIboolean\fR; // experimental
|
||||||
|
trust\-anchors { \fIstring\fR ( static\-key |
|
||||||
|
initial\-key | static\-ds | initial\-ds
|
||||||
|
) \fIinteger\fR \fIinteger\fR \fIinteger\fR
|
||||||
|
\fIquoted_string\fR; \&.\&.\&. };
|
||||||
trusted\-keys { \fIstring\fR
|
trusted\-keys { \fIstring\fR
|
||||||
\fIinteger\fR \fIinteger\fR
|
\fIinteger\fR \fIinteger\fR
|
||||||
\fIinteger\fR
|
\fIinteger\fR
|
||||||
@@ -890,6 +893,7 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
dnskey\-sig\-validity \fIinteger\fR;
|
dnskey\-sig\-validity \fIinteger\fR;
|
||||||
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
||||||
dnssec\-loadkeys\-interval \fIinteger\fR;
|
dnssec\-loadkeys\-interval \fIinteger\fR;
|
||||||
|
dnssec\-policy \fIstring\fR;
|
||||||
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
||||||
dnssec\-update\-mode ( maintain | no\-resign );
|
dnssec\-update\-mode ( maintain | no\-resign );
|
||||||
file \fIquoted_string\fR;
|
file \fIquoted_string\fR;
|
||||||
@@ -915,7 +919,7 @@ view \fIstring\fR [ \fIclass\fR ] {
|
|||||||
max\-transfer\-idle\-out \fIinteger\fR;
|
max\-transfer\-idle\-out \fIinteger\fR;
|
||||||
max\-transfer\-time\-in \fIinteger\fR;
|
max\-transfer\-time\-in \fIinteger\fR;
|
||||||
max\-transfer\-time\-out \fIinteger\fR;
|
max\-transfer\-time\-out \fIinteger\fR;
|
||||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||||
min\-refresh\-time \fIinteger\fR;
|
min\-refresh\-time \fIinteger\fR;
|
||||||
min\-retry\-time \fIinteger\fR;
|
min\-retry\-time \fIinteger\fR;
|
||||||
multi\-master \fIboolean\fR;
|
multi\-master \fIboolean\fR;
|
||||||
@@ -996,6 +1000,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
|
|||||||
dnskey\-sig\-validity \fIinteger\fR;
|
dnskey\-sig\-validity \fIinteger\fR;
|
||||||
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
dnssec\-dnskey\-kskonly \fIboolean\fR;
|
||||||
dnssec\-loadkeys\-interval \fIinteger\fR;
|
dnssec\-loadkeys\-interval \fIinteger\fR;
|
||||||
|
dnssec\-policy \fIstring\fR;
|
||||||
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
dnssec\-secure\-to\-insecure \fIboolean\fR;
|
||||||
dnssec\-update\-mode ( maintain | no\-resign );
|
dnssec\-update\-mode ( maintain | no\-resign );
|
||||||
file \fIquoted_string\fR;
|
file \fIquoted_string\fR;
|
||||||
@@ -1020,7 +1025,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
|
|||||||
max\-transfer\-idle\-out \fIinteger\fR;
|
max\-transfer\-idle\-out \fIinteger\fR;
|
||||||
max\-transfer\-time\-in \fIinteger\fR;
|
max\-transfer\-time\-in \fIinteger\fR;
|
||||||
max\-transfer\-time\-out \fIinteger\fR;
|
max\-transfer\-time\-out \fIinteger\fR;
|
||||||
max\-zone\-ttl ( unlimited | \fIttlval\fR );
|
max\-zone\-ttl ( unlimited | \fIduration\fR );
|
||||||
min\-refresh\-time \fIinteger\fR;
|
min\-refresh\-time \fIinteger\fR;
|
||||||
min\-retry\-time \fIinteger\fR;
|
min\-retry\-time \fIinteger\fR;
|
||||||
multi\-master \fIboolean\fR;
|
multi\-master \fIboolean\fR;
|
||||||
@@ -1062,6 +1067,30 @@ zone \fIstring\fR [ \fIclass\fR ] {
|
|||||||
.if n \{\
|
.if n \{\
|
||||||
.RE
|
.RE
|
||||||
.\}
|
.\}
|
||||||
|
.SH "DNSSEC-POLICY"
|
||||||
|
.sp
|
||||||
|
.if n \{\
|
||||||
|
.RS 4
|
||||||
|
.\}
|
||||||
|
.nf
|
||||||
|
dnssec\-policy \fIstring\fR {
|
||||||
|
dnskey\-ttl \fIduration\fR;
|
||||||
|
keys { ( csk | ksk | zsk ) key\-directory lifetime \fIduration\fR algorithm \fIinteger\fR [ \fIinteger\fR ] ; \&.\&.\&. };
|
||||||
|
parent\-ds\-ttl \fIduration\fR;
|
||||||
|
parent\-propagation\-delay \fIduration\fR;
|
||||||
|
parent\-registration\-delay \fIduration\fR;
|
||||||
|
publish\-safety \fIduration\fR;
|
||||||
|
retire\-safety \fIduration\fR;
|
||||||
|
signatures\-refresh \fIduration\fR;
|
||||||
|
signatures\-validity \fIduration\fR;
|
||||||
|
signatures\-validity\-dnskey \fIduration\fR;
|
||||||
|
zone\-max\-ttl \fIduration\fR;
|
||||||
|
zone\-propagation\-delay \fIduration\fR;
|
||||||
|
};
|
||||||
|
.fi
|
||||||
|
.if n \{\
|
||||||
|
.RE
|
||||||
|
.\}
|
||||||
.SH "FILES"
|
.SH "FILES"
|
||||||
.PP
|
.PP
|
||||||
/etc/named\&.conf
|
/etc/named\&.conf
|
||||||
@@ -1078,5 +1107,5 @@ BIND 9 Administrator Reference Manual\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2004-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2004-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -13,7 +13,7 @@
|
|||||||
|
|
||||||
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.named.conf">
|
<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.named.conf">
|
||||||
<info>
|
<info>
|
||||||
<date>2019-08-07</date>
|
<date>2019-08-12</date>
|
||||||
</info>
|
</info>
|
||||||
<refentryinfo>
|
<refentryinfo>
|
||||||
<corpname>ISC</corpname>
|
<corpname>ISC</corpname>
|
||||||
@@ -49,6 +49,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
@@ -110,14 +111,6 @@ dlz <replaceable>string</replaceable> {
|
|||||||
</literallayout>
|
</literallayout>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
<refsection><info><title>DNSSEC-KEYS</title></info>
|
|
||||||
<literallayout class="normal">
|
|
||||||
dnssec-keys { <replaceable>string</replaceable> ( static-key |
|
|
||||||
initial-key ) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
|
||||||
<replaceable>quoted_string</replaceable>; ... };
|
|
||||||
</literallayout>
|
|
||||||
</refsection>
|
|
||||||
|
|
||||||
<refsection><info><title>DYNDB</title></info>
|
<refsection><info><title>DYNDB</title></info>
|
||||||
<literallayout class="normal">
|
<literallayout class="normal">
|
||||||
dyndb <replaceable>string</replaceable> <replaceable>quoted_string</replaceable> {
|
dyndb <replaceable>string</replaceable> <replaceable>quoted_string</replaceable> {
|
||||||
@@ -155,12 +148,12 @@ logging {
|
|||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
<refsection><info><title>MANAGED-KEYS</title></info>
|
<refsection><info><title>MANAGED-KEYS</title></info>
|
||||||
<para>Deprecated - see DNSSEC-KEYS.</para>
|
<para>Deprecated - see TRUST-ANCHORS.</para>
|
||||||
<literallayout class="normal">
|
<literallayout class="normal">
|
||||||
managed-keys { <replaceable>string</replaceable> ( static-key
|
managed-keys { <replaceable>string</replaceable> ( static-key
|
||||||
| initial-key ) <replaceable>integer</replaceable>
|
| initial-key | static-ds |
|
||||||
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
initial-ds ) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||||
<replaceable>quoted_string</replaceable>; ... }; deprecated
|
<replaceable>integer</replaceable> <replaceable>quoted_string</replaceable>; ... }; deprecated
|
||||||
</literallayout>
|
</literallayout>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
@@ -526,8 +519,17 @@ statistics-channels {
|
|||||||
</literallayout>
|
</literallayout>
|
||||||
</refsection>
|
</refsection>
|
||||||
|
|
||||||
|
<refsection><info><title>TRUST-ANCHORS</title></info>
|
||||||
|
<literallayout class="normal">
|
||||||
|
trust-anchors { <replaceable>string</replaceable> ( static-key |
|
||||||
|
initial-key | static-ds | initial-ds )
|
||||||
|
<replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||||
|
<replaceable>quoted_string</replaceable>; ... };
|
||||||
|
</literallayout>
|
||||||
|
</refsection>
|
||||||
|
|
||||||
<refsection><info><title>TRUSTED-KEYS</title></info>
|
<refsection><info><title>TRUSTED-KEYS</title></info>
|
||||||
<para>Deprecated - see DNSSEC-KEYS.</para>
|
<para>Deprecated - see TRUST-ANCHORS.</para>
|
||||||
<literallayout class="normal">
|
<literallayout class="normal">
|
||||||
trusted-keys { <replaceable>string</replaceable> <replaceable>integer</replaceable>
|
trusted-keys { <replaceable>string</replaceable> <replaceable>integer</replaceable>
|
||||||
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||||
@@ -606,9 +608,6 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
dnsrps-options { <replaceable>unspecified-text</replaceable> };
|
dnsrps-options { <replaceable>unspecified-text</replaceable> };
|
||||||
dnssec-accept-expired <replaceable>boolean</replaceable>;
|
dnssec-accept-expired <replaceable>boolean</replaceable>;
|
||||||
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
|
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
|
||||||
dnssec-keys { <replaceable>string</replaceable> ( static-key |
|
|
||||||
initial-key ) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
|
||||||
<replaceable>integer</replaceable> <replaceable>quoted_string</replaceable>; ... };
|
|
||||||
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
|
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
|
||||||
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
|
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
|
||||||
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
|
||||||
@@ -646,6 +645,7 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
lmdb-mapsize <replaceable>sizeval</replaceable>;
|
lmdb-mapsize <replaceable>sizeval</replaceable>;
|
||||||
managed-keys { <replaceable>string</replaceable> (
|
managed-keys { <replaceable>string</replaceable> (
|
||||||
static-key | initial-key
|
static-key | initial-key
|
||||||
|
| static-ds | initial-ds
|
||||||
) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||||
<replaceable>integer</replaceable>
|
<replaceable>integer</replaceable>
|
||||||
<replaceable>quoted_string</replaceable>; ... }; deprecated
|
<replaceable>quoted_string</replaceable>; ... }; deprecated
|
||||||
@@ -798,6 +798,10 @@ view <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
transfer-source-v6 ( <replaceable>ipv6_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * )
|
transfer-source-v6 ( <replaceable>ipv6_address</replaceable> | * ) [ port ( <replaceable>integer</replaceable> | * )
|
||||||
] [ dscp <replaceable>integer</replaceable> ];
|
] [ dscp <replaceable>integer</replaceable> ];
|
||||||
trust-anchor-telemetry <replaceable>boolean</replaceable>; // experimental
|
trust-anchor-telemetry <replaceable>boolean</replaceable>; // experimental
|
||||||
|
trust-anchors { <replaceable>string</replaceable> ( static-key |
|
||||||
|
initial-key | static-ds | initial-ds
|
||||||
|
) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||||
|
<replaceable>quoted_string</replaceable>; ... };
|
||||||
trusted-keys { <replaceable>string</replaceable>
|
trusted-keys { <replaceable>string</replaceable>
|
||||||
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
|
||||||
<replaceable>integer</replaceable>
|
<replaceable>integer</replaceable>
|
||||||
@@ -1014,7 +1018,7 @@ zone <replaceable>string</replaceable> [ <replaceable>class</replaceable> ] {
|
|||||||
|
|
||||||
<literallayout class="normal">
|
<literallayout class="normal">
|
||||||
dnssec-policy <replaceable>string</replaceable> {
|
dnssec-policy <replaceable>string</replaceable> {
|
||||||
dnskey-ttl <replaceable>ttlval</replaceable>;
|
dnskey-ttl <replaceable>duration</replaceable>;
|
||||||
keys { ( csk | ksk | zsk ) key-directory lifetime <replaceable>duration</replaceable> algorithm <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ] ; ... };
|
keys { ( csk | ksk | zsk ) key-directory lifetime <replaceable>duration</replaceable> algorithm <replaceable>integer</replaceable> [ <replaceable>integer</replaceable> ] ; ... };
|
||||||
parent-ds-ttl <replaceable>duration</replaceable>;
|
parent-ds-ttl <replaceable>duration</replaceable>;
|
||||||
parent-propagation-delay <replaceable>duration</replaceable>;
|
parent-propagation-delay <replaceable>duration</replaceable>;
|
||||||
|
|||||||
+91
-65
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2004-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2004-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -92,16 +92,7 @@ dlz
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.11"></a><h2>DNSSEC-KEYS</h2>
|
<a name="id-1.11"></a><h2>DYNDB</h2>
|
||||||
<div class="literallayout"><p><br>
|
|
||||||
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
|
|
||||||
initial-key ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
|
||||||
<em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
|
||||||
</p></div>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<div class="refsection">
|
|
||||||
<a name="id-1.12"></a><h2>DYNDB</h2>
|
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
dyndb <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>quoted_string</code></em> {<br>
|
dyndb <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>quoted_string</code></em> {<br>
|
||||||
<em class="replaceable"><code>unspecified-text</code></em> };<br>
|
<em class="replaceable"><code>unspecified-text</code></em> };<br>
|
||||||
@@ -109,7 +100,7 @@ dyndb
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.13"></a><h2>KEY</h2>
|
<a name="id-1.12"></a><h2>KEY</h2>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
key <em class="replaceable"><code>string</code></em> {<br>
|
key <em class="replaceable"><code>string</code></em> {<br>
|
||||||
algorithm <em class="replaceable"><code>string</code></em>;<br>
|
algorithm <em class="replaceable"><code>string</code></em>;<br>
|
||||||
@@ -119,7 +110,7 @@ key
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.14"></a><h2>LOGGING</h2>
|
<a name="id-1.13"></a><h2>LOGGING</h2>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
logging {<br>
|
logging {<br>
|
||||||
category <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br>
|
category <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br>
|
||||||
@@ -140,18 +131,18 @@ logging
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.15"></a><h2>MANAGED-KEYS</h2>
|
<a name="id-1.14"></a><h2>MANAGED-KEYS</h2>
|
||||||
<p>Deprecated - see DNSSEC-KEYS.</p>
|
<p>Deprecated - see TRUST-ANCHORS.</p>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br>
|
managed-keys { <em class="replaceable"><code>string</code></em> ( static-key<br>
|
||||||
| initial-key ) <em class="replaceable"><code>integer</code></em><br>
|
| initial-key | static-ds |<br>
|
||||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
initial-ds ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
<em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
||||||
</p></div>
|
</p></div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.16"></a><h2>MASTERS</h2>
|
<a name="id-1.15"></a><h2>MASTERS</h2>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
masters <em class="replaceable"><code>string</code></em> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
|
masters <em class="replaceable"><code>string</code></em> [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
|
||||||
<em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<br>
|
<em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<br>
|
||||||
@@ -161,7 +152,7 @@ masters
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.17"></a><h2>OPTIONS</h2>
|
<a name="id-1.16"></a><h2>OPTIONS</h2>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
options {<br>
|
options {<br>
|
||||||
allow-new-zones <em class="replaceable"><code>boolean</code></em>;<br>
|
allow-new-zones <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -196,7 +187,7 @@ options
|
|||||||
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port<br>
|
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port<br>
|
||||||
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key<br>
|
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key<br>
|
||||||
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [<br>
|
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [<br>
|
||||||
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>ttlval</code></em> ]; ... };<br>
|
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>duration</code></em> ]; ... };<br>
|
||||||
check-dup-records ( fail | warn | ignore );<br>
|
check-dup-records ( fail | warn | ignore );<br>
|
||||||
check-integrity <em class="replaceable"><code>boolean</code></em>;<br>
|
check-integrity <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
check-mx ( fail | warn | ignore );<br>
|
check-mx ( fail | warn | ignore );<br>
|
||||||
@@ -278,18 +269,18 @@ options
|
|||||||
fstrm-set-output-notify-threshold <em class="replaceable"><code>integer</code></em>;<br>
|
fstrm-set-output-notify-threshold <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
fstrm-set-output-queue-model ( mpsc | spsc );<br>
|
fstrm-set-output-queue-model ( mpsc | spsc );<br>
|
||||||
fstrm-set-output-queue-size <em class="replaceable"><code>integer</code></em>;<br>
|
fstrm-set-output-queue-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
fstrm-set-reopen-interval <em class="replaceable"><code>ttlval</code></em>;<br>
|
fstrm-set-reopen-interval <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
geoip-directory ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
geoip-directory ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||||
glue-cache <em class="replaceable"><code>boolean</code></em>;<br>
|
glue-cache <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
heartbeat-interval <em class="replaceable"><code>integer</code></em>;<br>
|
heartbeat-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
hostname ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
hostname ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||||
inline-signing <em class="replaceable"><code>boolean</code></em>;<br>
|
inline-signing <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
interface-interval <em class="replaceable"><code>ttlval</code></em>;<br>
|
interface-interval <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
ixfr-from-differences ( primary | master | secondary | slave |<br>
|
ixfr-from-differences ( primary | master | secondary | slave |<br>
|
||||||
<em class="replaceable"><code>boolean</code></em> );<br>
|
<em class="replaceable"><code>boolean</code></em> );<br>
|
||||||
keep-response-order { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
keep-response-order { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||||
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
lame-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
lame-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
listen-on [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
|
listen-on [ port <em class="replaceable"><code>integer</code></em> ] [ dscp<br>
|
||||||
<em class="replaceable"><code>integer</code></em> ] {<br>
|
<em class="replaceable"><code>integer</code></em> ] {<br>
|
||||||
<em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
<em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||||
@@ -303,28 +294,28 @@ options
|
|||||||
masterfile-style ( full | relative );<br>
|
masterfile-style ( full | relative );<br>
|
||||||
match-mapped-addresses <em class="replaceable"><code>boolean</code></em>;<br>
|
match-mapped-addresses <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
max-cache-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );<br>
|
max-cache-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );<br>
|
||||||
max-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-clients-per-query <em class="replaceable"><code>integer</code></em>;<br>
|
max-clients-per-query <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-journal-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
max-journal-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
||||||
max-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-records <em class="replaceable"><code>integer</code></em>;<br>
|
max-records <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-recursion-depth <em class="replaceable"><code>integer</code></em>;<br>
|
max-recursion-depth <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-recursion-queries <em class="replaceable"><code>integer</code></em>;<br>
|
max-recursion-queries <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
max-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-rsa-exponent-size <em class="replaceable"><code>integer</code></em>;<br>
|
max-rsa-exponent-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-stale-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-stale-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-transfer-idle-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-udp-size <em class="replaceable"><code>integer</code></em>;<br>
|
max-udp-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||||
memstatistics <em class="replaceable"><code>boolean</code></em>;<br>
|
memstatistics <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
memstatistics-file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
memstatistics-file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
message-compression <em class="replaceable"><code>boolean</code></em>;<br>
|
message-compression <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
min-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
min-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
min-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
min-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
minimal-any <em class="replaceable"><code>boolean</code></em>;<br>
|
minimal-any <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -341,8 +332,8 @@ options
|
|||||||
notify-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]<br>
|
notify-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]<br>
|
||||||
[ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
[ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
||||||
notify-to-soa <em class="replaceable"><code>boolean</code></em>;<br>
|
notify-to-soa <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
nta-lifetime <em class="replaceable"><code>ttlval</code></em>;<br>
|
nta-lifetime <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
nta-recheck <em class="replaceable"><code>ttlval</code></em>;<br>
|
nta-recheck <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
nxdomain-redirect <em class="replaceable"><code>string</code></em>;<br>
|
nxdomain-redirect <em class="replaceable"><code>string</code></em>;<br>
|
||||||
pid-file ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
pid-file ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||||
port <em class="replaceable"><code>integer</code></em>;<br>
|
port <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
@@ -389,13 +380,13 @@ options
|
|||||||
response-padding { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size<br>
|
response-padding { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size<br>
|
||||||
<em class="replaceable"><code>integer</code></em>;<br>
|
<em class="replaceable"><code>integer</code></em>;<br>
|
||||||
response-policy { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log<br>
|
response-policy { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log<br>
|
||||||
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [ min-update-interval<br>
|
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [ min-update-interval<br>
|
||||||
<em class="replaceable"><code>ttlval</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
<em class="replaceable"><code>duration</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
||||||
nodata | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [<br>
|
nodata | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [<br>
|
||||||
recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [<br>
|
nsdname-enable <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [<br>
|
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [<br>
|
||||||
min-update-interval <em class="replaceable"><code>ttlval</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
min-update-interval <em class="replaceable"><code>duration</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
||||||
nsip-wait-recurse <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]<br>
|
nsip-wait-recurse <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]<br>
|
||||||
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
nsdname-enable <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
@@ -409,7 +400,7 @@ options
|
|||||||
serial-query-rate <em class="replaceable"><code>integer</code></em>;<br>
|
serial-query-rate <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
serial-update-method ( date | increment | unixtime );<br>
|
serial-update-method ( date | increment | unixtime );<br>
|
||||||
server-id ( <em class="replaceable"><code>quoted_string</code></em> | none | hostname );<br>
|
server-id ( <em class="replaceable"><code>quoted_string</code></em> | none | hostname );<br>
|
||||||
servfail-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
servfail-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
session-keyalg <em class="replaceable"><code>string</code></em>;<br>
|
session-keyalg <em class="replaceable"><code>string</code></em>;<br>
|
||||||
session-keyfile ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
session-keyfile ( <em class="replaceable"><code>quoted_string</code></em> | none );<br>
|
||||||
session-keyname <em class="replaceable"><code>string</code></em>;<br>
|
session-keyname <em class="replaceable"><code>string</code></em>;<br>
|
||||||
@@ -420,7 +411,7 @@ options
|
|||||||
sortlist { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
sortlist { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||||
stacksize ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
stacksize ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
||||||
stale-answer-enable <em class="replaceable"><code>boolean</code></em>;<br>
|
stale-answer-enable <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
stale-answer-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
stale-answer-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
startup-notify-rate <em class="replaceable"><code>integer</code></em>;<br>
|
startup-notify-rate <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
statistics-file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
statistics-file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
synth-from-dnssec <em class="replaceable"><code>boolean</code></em>;<br>
|
synth-from-dnssec <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -460,7 +451,7 @@ options
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.18"></a><h2>PLUGIN</h2>
|
<a name="id-1.17"></a><h2>PLUGIN</h2>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
plugin ( query ) <em class="replaceable"><code>string</code></em> [ { <em class="replaceable"><code>unspecified-text</code></em><br>
|
plugin ( query ) <em class="replaceable"><code>string</code></em> [ { <em class="replaceable"><code>unspecified-text</code></em><br>
|
||||||
} ];<br>
|
} ];<br>
|
||||||
@@ -468,7 +459,7 @@ plugin
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.19"></a><h2>SERVER</h2>
|
<a name="id-1.18"></a><h2>SERVER</h2>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
server <em class="replaceable"><code>netprefix</code></em> {<br>
|
server <em class="replaceable"><code>netprefix</code></em> {<br>
|
||||||
bogus <em class="replaceable"><code>boolean</code></em>;<br>
|
bogus <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -506,7 +497,7 @@ server
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.20"></a><h2>STATISTICS-CHANNELS</h2>
|
<a name="id-1.19"></a><h2>STATISTICS-CHANNELS</h2>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
statistics-channels {<br>
|
statistics-channels {<br>
|
||||||
inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> |<br>
|
inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> |<br>
|
||||||
@@ -517,9 +508,19 @@ statistics-channels
|
|||||||
</p></div>
|
</p></div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<div class="refsection">
|
||||||
|
<a name="id-1.20"></a><h2>TRUST-ANCHORS</h2>
|
||||||
|
<div class="literallayout"><p><br>
|
||||||
|
trust-anchors { <em class="replaceable"><code>string</code></em> ( static-key |<br>
|
||||||
|
initial-key | static-ds | initial-ds )<br>
|
||||||
|
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
|
<em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
||||||
|
</p></div>
|
||||||
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.21"></a><h2>TRUSTED-KEYS</h2>
|
<a name="id-1.21"></a><h2>TRUSTED-KEYS</h2>
|
||||||
<p>Deprecated - see DNSSEC-KEYS.</p>
|
<p>Deprecated - see TRUST-ANCHORS.</p>
|
||||||
<div class="literallayout"><p><br>
|
<div class="literallayout"><p><br>
|
||||||
trusted-keys { <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>integer</code></em><br>
|
trusted-keys { <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
@@ -557,7 +558,7 @@ view
|
|||||||
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port<br>
|
[ dscp <em class="replaceable"><code>integer</code></em> ] { ( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [ port<br>
|
||||||
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key<br>
|
<em class="replaceable"><code>integer</code></em> ] | <em class="replaceable"><code>ipv6_address</code></em> [ port <em class="replaceable"><code>integer</code></em> ] ) [ key<br>
|
||||||
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [<br>
|
<em class="replaceable"><code>string</code></em> ]; ... } ] [ zone-directory <em class="replaceable"><code>quoted_string</code></em> ] [<br>
|
||||||
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>ttlval</code></em> ]; ... };<br>
|
in-memory <em class="replaceable"><code>boolean</code></em> ] [ min-update-interval <em class="replaceable"><code>duration</code></em> ]; ... };<br>
|
||||||
check-dup-records ( fail | warn | ignore );<br>
|
check-dup-records ( fail | warn | ignore );<br>
|
||||||
check-integrity <em class="replaceable"><code>boolean</code></em>;<br>
|
check-integrity <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
check-mx ( fail | warn | ignore );<br>
|
check-mx ( fail | warn | ignore );<br>
|
||||||
@@ -599,9 +600,6 @@ view
|
|||||||
dnsrps-options { <em class="replaceable"><code>unspecified-text</code></em> };<br>
|
dnsrps-options { <em class="replaceable"><code>unspecified-text</code></em> };<br>
|
||||||
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-keys { <em class="replaceable"><code>string</code></em> ( static-key |<br>
|
|
||||||
initial-key ) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
|
||||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
|
||||||
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -635,10 +633,11 @@ view
|
|||||||
secret <em class="replaceable"><code>string</code></em>;<br>
|
secret <em class="replaceable"><code>string</code></em>;<br>
|
||||||
};<br>
|
};<br>
|
||||||
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
lame-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
lame-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
lmdb-mapsize <em class="replaceable"><code>sizeval</code></em>;<br>
|
lmdb-mapsize <em class="replaceable"><code>sizeval</code></em>;<br>
|
||||||
managed-keys { <em class="replaceable"><code>string</code></em> (<br>
|
managed-keys { <em class="replaceable"><code>string</code></em> (<br>
|
||||||
static-key | initial-key<br>
|
static-key | initial-key<br>
|
||||||
|
| static-ds | initial-ds<br>
|
||||||
) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
<em class="replaceable"><code>integer</code></em><br>
|
<em class="replaceable"><code>integer</code></em><br>
|
||||||
<em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
<em class="replaceable"><code>quoted_string</code></em>; ... }; deprecated<br>
|
||||||
@@ -648,25 +647,25 @@ view
|
|||||||
match-destinations { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
match-destinations { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||||
match-recursive-only <em class="replaceable"><code>boolean</code></em>;<br>
|
match-recursive-only <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
max-cache-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );<br>
|
max-cache-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> | <em class="replaceable"><code>percentage</code></em> );<br>
|
||||||
max-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-clients-per-query <em class="replaceable"><code>integer</code></em>;<br>
|
max-clients-per-query <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-journal-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
max-journal-size ( default | unlimited | <em class="replaceable"><code>sizeval</code></em> );<br>
|
||||||
max-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-records <em class="replaceable"><code>integer</code></em>;<br>
|
max-records <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-recursion-depth <em class="replaceable"><code>integer</code></em>;<br>
|
max-recursion-depth <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-recursion-queries <em class="replaceable"><code>integer</code></em>;<br>
|
max-recursion-queries <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
max-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
max-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-stale-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
max-stale-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
max-transfer-idle-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-udp-size <em class="replaceable"><code>integer</code></em>;<br>
|
max-udp-size <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||||
message-compression <em class="replaceable"><code>boolean</code></em>;<br>
|
message-compression <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
min-cache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
min-cache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
min-ncache-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
min-ncache-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
minimal-any <em class="replaceable"><code>boolean</code></em>;<br>
|
minimal-any <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -682,8 +681,8 @@ view
|
|||||||
notify-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]<br>
|
notify-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ]<br>
|
||||||
[ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
[ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
||||||
notify-to-soa <em class="replaceable"><code>boolean</code></em>;<br>
|
notify-to-soa <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
nta-lifetime <em class="replaceable"><code>ttlval</code></em>;<br>
|
nta-lifetime <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
nta-recheck <em class="replaceable"><code>ttlval</code></em>;<br>
|
nta-recheck <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
nxdomain-redirect <em class="replaceable"><code>string</code></em>;<br>
|
nxdomain-redirect <em class="replaceable"><code>string</code></em>;<br>
|
||||||
plugin ( query ) <em class="replaceable"><code>string</code></em> [ {<br>
|
plugin ( query ) <em class="replaceable"><code>string</code></em> [ {<br>
|
||||||
<em class="replaceable"><code>unspecified-text</code></em> } ];<br>
|
<em class="replaceable"><code>unspecified-text</code></em> } ];<br>
|
||||||
@@ -725,13 +724,13 @@ view
|
|||||||
response-padding { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size<br>
|
response-padding { <em class="replaceable"><code>address_match_element</code></em>; ... } block-size<br>
|
||||||
<em class="replaceable"><code>integer</code></em>;<br>
|
<em class="replaceable"><code>integer</code></em>;<br>
|
||||||
response-policy { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log<br>
|
response-policy { zone <em class="replaceable"><code>string</code></em> [ add-soa <em class="replaceable"><code>boolean</code></em> ] [ log<br>
|
||||||
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [ min-update-interval<br>
|
<em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [ min-update-interval<br>
|
||||||
<em class="replaceable"><code>ttlval</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
<em class="replaceable"><code>duration</code></em> ] [ policy ( cname | disabled | drop | given | no-op |<br>
|
||||||
nodata | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [<br>
|
nodata | nxdomain | passthru | tcp-only <em class="replaceable"><code>quoted_string</code></em> ) ] [<br>
|
||||||
recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [<br>
|
nsdname-enable <em class="replaceable"><code>boolean</code></em> ]; ... } [ add-soa <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>ttlval</code></em> ] [<br>
|
break-dnssec <em class="replaceable"><code>boolean</code></em> ] [ max-policy-ttl <em class="replaceable"><code>duration</code></em> ] [<br>
|
||||||
min-update-interval <em class="replaceable"><code>ttlval</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
min-update-interval <em class="replaceable"><code>duration</code></em> ] [ min-ns-dots <em class="replaceable"><code>integer</code></em> ] [<br>
|
||||||
nsip-wait-recurse <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]<br>
|
nsip-wait-recurse <em class="replaceable"><code>boolean</code></em> ] [ qname-wait-recurse <em class="replaceable"><code>boolean</code></em> ]<br>
|
||||||
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
[ recursive-only <em class="replaceable"><code>boolean</code></em> ] [ nsip-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
nsdname-enable <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
nsdname-enable <em class="replaceable"><code>boolean</code></em> ] [ dnsrps-enable <em class="replaceable"><code>boolean</code></em> ] [<br>
|
||||||
@@ -776,14 +775,14 @@ view
|
|||||||
<em class="replaceable"><code>integer</code></em> | * ) ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
<em class="replaceable"><code>integer</code></em> | * ) ] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
||||||
transfers <em class="replaceable"><code>integer</code></em>;<br>
|
transfers <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
};<br>
|
};<br>
|
||||||
servfail-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
servfail-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
sig-signing-nodes <em class="replaceable"><code>integer</code></em>;<br>
|
sig-signing-nodes <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
sig-signing-signatures <em class="replaceable"><code>integer</code></em>;<br>
|
sig-signing-signatures <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
sig-signing-type <em class="replaceable"><code>integer</code></em>;<br>
|
sig-signing-type <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
sig-validity-interval <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ];<br>
|
sig-validity-interval <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ];<br>
|
||||||
sortlist { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
sortlist { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
|
||||||
stale-answer-enable <em class="replaceable"><code>boolean</code></em>;<br>
|
stale-answer-enable <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
stale-answer-ttl <em class="replaceable"><code>ttlval</code></em>;<br>
|
stale-answer-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
synth-from-dnssec <em class="replaceable"><code>boolean</code></em>;<br>
|
synth-from-dnssec <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
transfer-format ( many-answers | one-answer );<br>
|
transfer-format ( many-answers | one-answer );<br>
|
||||||
transfer-source ( <em class="replaceable"><code>ipv4_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ] [<br>
|
transfer-source ( <em class="replaceable"><code>ipv4_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * ) ] [<br>
|
||||||
@@ -791,6 +790,10 @@ view
|
|||||||
transfer-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * )<br>
|
transfer-source-v6 ( <em class="replaceable"><code>ipv6_address</code></em> | * ) [ port ( <em class="replaceable"><code>integer</code></em> | * )<br>
|
||||||
] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
] [ dscp <em class="replaceable"><code>integer</code></em> ];<br>
|
||||||
trust-anchor-telemetry <em class="replaceable"><code>boolean</code></em>; // experimental<br>
|
trust-anchor-telemetry <em class="replaceable"><code>boolean</code></em>; // experimental<br>
|
||||||
|
trust-anchors { <em class="replaceable"><code>string</code></em> ( static-key |<br>
|
||||||
|
initial-key | static-ds | initial-ds<br>
|
||||||
|
) <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
|
<em class="replaceable"><code>quoted_string</code></em>; ... };<br>
|
||||||
trusted-keys { <em class="replaceable"><code>string</code></em><br>
|
trusted-keys { <em class="replaceable"><code>string</code></em><br>
|
||||||
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
<em class="replaceable"><code>integer</code></em> <em class="replaceable"><code>integer</code></em><br>
|
||||||
<em class="replaceable"><code>integer</code></em><br>
|
<em class="replaceable"><code>integer</code></em><br>
|
||||||
@@ -835,6 +838,7 @@ view
|
|||||||
dnskey-sig-validity <em class="replaceable"><code>integer</code></em>;<br>
|
dnskey-sig-validity <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
|
dnssec-policy <em class="replaceable"><code>string</code></em>;<br>
|
||||||
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-update-mode ( maintain | no-resign );<br>
|
dnssec-update-mode ( maintain | no-resign );<br>
|
||||||
file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
@@ -860,7 +864,7 @@ view
|
|||||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -937,6 +941,7 @@ zone
|
|||||||
dnskey-sig-validity <em class="replaceable"><code>integer</code></em>;<br>
|
dnskey-sig-validity <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-dnskey-kskonly <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
dnssec-loadkeys-interval <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
|
dnssec-policy <em class="replaceable"><code>string</code></em>;<br>
|
||||||
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
dnssec-secure-to-insecure <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
dnssec-update-mode ( maintain | no-resign );<br>
|
dnssec-update-mode ( maintain | no-resign );<br>
|
||||||
file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
file <em class="replaceable"><code>quoted_string</code></em>;<br>
|
||||||
@@ -961,7 +966,7 @@ zone
|
|||||||
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-idle-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-in <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
max-transfer-time-out <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
max-zone-ttl ( unlimited | <em class="replaceable"><code>ttlval</code></em> );<br>
|
max-zone-ttl ( unlimited | <em class="replaceable"><code>duration</code></em> );<br>
|
||||||
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-refresh-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
min-retry-time <em class="replaceable"><code>integer</code></em>;<br>
|
||||||
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
multi-master <em class="replaceable"><code>boolean</code></em>;<br>
|
||||||
@@ -1003,14 +1008,35 @@ zone
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.24"></a><h2>FILES</h2>
|
<a name="id-1.24"></a><h2>DNSSEC-POLICY</h2>
|
||||||
|
|
||||||
|
<div class="literallayout"><p><br>
|
||||||
|
dnssec-policy <em class="replaceable"><code>string</code></em> {<br>
|
||||||
|
dnskey-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
keys { ( csk | ksk | zsk ) key-directory lifetime <em class="replaceable"><code>duration</code></em> algorithm <em class="replaceable"><code>integer</code></em> [ <em class="replaceable"><code>integer</code></em> ] ; ... };<br>
|
||||||
|
parent-ds-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
parent-propagation-delay <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
parent-registration-delay <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
publish-safety <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
retire-safety <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
signatures-refresh <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
signatures-validity <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
signatures-validity-dnskey <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
zone-max-ttl <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
zone-propagation-delay <em class="replaceable"><code>duration</code></em>;<br>
|
||||||
|
};<br>
|
||||||
|
</p></div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<div class="refsection">
|
||||||
|
<a name="id-1.25"></a><h2>FILES</h2>
|
||||||
|
|
||||||
<p><code class="filename">/etc/named.conf</code>
|
<p><code class="filename">/etc/named.conf</code>
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="refsection">
|
<div class="refsection">
|
||||||
<a name="id-1.25"></a><h2>SEE ALSO</h2>
|
<a name="id-1.26"></a><h2>SEE ALSO</h2>
|
||||||
|
|
||||||
<p><span class="citerefentry">
|
<p><span class="citerefentry">
|
||||||
<span class="refentrytitle">ddns-confgen</span>(8)
|
<span class="refentrytitle">ddns-confgen</span>(8)
|
||||||
|
|||||||
@@ -49,6 +49,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000, 2001, 2003-2009, 2011, 2013-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000, 2001, 2003-2009, 2011, 2013-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
+313
-218
@@ -68,6 +68,7 @@
|
|||||||
#include <dns/events.h>
|
#include <dns/events.h>
|
||||||
#include <dns/forward.h>
|
#include <dns/forward.h>
|
||||||
#include <dns/fixedname.h>
|
#include <dns/fixedname.h>
|
||||||
|
#include <dns/geoip.h>
|
||||||
#include <dns/journal.h>
|
#include <dns/journal.h>
|
||||||
#include <dns/kasp.h>
|
#include <dns/kasp.h>
|
||||||
#include <dns/keytable.h>
|
#include <dns/keytable.h>
|
||||||
@@ -201,8 +202,8 @@
|
|||||||
|
|
||||||
#define CHECKFATAL(op, msg) \
|
#define CHECKFATAL(op, msg) \
|
||||||
do { result = (op); \
|
do { result = (op); \
|
||||||
if (result != ISC_R_SUCCESS) \
|
if (result != ISC_R_SUCCESS) \
|
||||||
fatal(msg, result); \
|
fatal(server, msg, result); \
|
||||||
} while (0) \
|
} while (0) \
|
||||||
|
|
||||||
/*%
|
/*%
|
||||||
@@ -431,7 +432,8 @@ const char *empty_zones[] = {
|
|||||||
};
|
};
|
||||||
|
|
||||||
ISC_PLATFORM_NORETURN_PRE static void
|
ISC_PLATFORM_NORETURN_PRE static void
|
||||||
fatal(const char *msg, isc_result_t result) ISC_PLATFORM_NORETURN_POST;
|
fatal(named_server_t *server,const char *msg, isc_result_t result)
|
||||||
|
ISC_PLATFORM_NORETURN_POST;
|
||||||
|
|
||||||
static void
|
static void
|
||||||
named_server_reload(isc_task_t *task, isc_event_t *event);
|
named_server_reload(isc_task_t *task, isc_event_t *event);
|
||||||
@@ -698,111 +700,198 @@ configure_view_nametable(const cfg_obj_t *vconfig, const cfg_obj_t *config,
|
|||||||
}
|
}
|
||||||
|
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
dstkey_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **target,
|
ta_fromconfig(const cfg_obj_t *key, bool *initialp, const char **namestrp,
|
||||||
const char **keynamestrp, isc_mem_t *mctx)
|
unsigned char *digest, dns_rdata_ds_t *ds)
|
||||||
{
|
{
|
||||||
|
isc_result_t result;
|
||||||
dns_rdata_dnskey_t keystruct;
|
dns_rdata_dnskey_t keystruct;
|
||||||
uint32_t flags, proto, alg;
|
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||||
const char *keystr, *keynamestr;
|
uint32_t rdata1, rdata2, rdata3;
|
||||||
unsigned char keydata[4096];
|
const char *datastr = NULL, *namestr = NULL;
|
||||||
isc_buffer_t keydatabuf;
|
unsigned char data[4096];
|
||||||
|
isc_buffer_t databuf;
|
||||||
unsigned char rrdata[4096];
|
unsigned char rrdata[4096];
|
||||||
isc_buffer_t rrdatabuf;
|
isc_buffer_t rrdatabuf;
|
||||||
isc_region_t r;
|
isc_region_t r;
|
||||||
dns_fixedname_t fkeyname;
|
dns_fixedname_t fname;
|
||||||
dns_name_t *keyname;
|
dns_name_t *name = NULL;
|
||||||
isc_buffer_t namebuf;
|
isc_buffer_t namebuf;
|
||||||
isc_result_t result;
|
const char *atstr = NULL;
|
||||||
dst_key_t *dstkey = NULL;
|
enum {
|
||||||
|
INIT_DNSKEY,
|
||||||
|
STATIC_DNSKEY,
|
||||||
|
INIT_DS,
|
||||||
|
STATIC_DS,
|
||||||
|
TRUSTED
|
||||||
|
} anchortype;
|
||||||
|
|
||||||
INSIST(target != NULL && *target == NULL);
|
REQUIRE(namestrp != NULL && *namestrp == NULL);
|
||||||
INSIST(keynamestrp != NULL && *keynamestrp == NULL);
|
REQUIRE(ds != NULL);
|
||||||
|
|
||||||
flags = cfg_obj_asuint32(cfg_tuple_get(key, "flags"));
|
/* if DNSKEY, flags; if DS, key tag */
|
||||||
proto = cfg_obj_asuint32(cfg_tuple_get(key, "protocol"));
|
rdata1 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata1"));
|
||||||
alg = cfg_obj_asuint32(cfg_tuple_get(key, "algorithm"));
|
|
||||||
keyname = dns_fixedname_name(&fkeyname);
|
/* if DNSKEY, protocol; if DS, algorithm */
|
||||||
keynamestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
rdata2 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata2"));
|
||||||
*keynamestrp = keynamestr;
|
|
||||||
|
/* if DNSKEY, algorithm; if DS, digest type */
|
||||||
|
rdata3 = cfg_obj_asuint32(cfg_tuple_get(key, "rdata3"));
|
||||||
|
|
||||||
|
namestr = cfg_obj_asstring(cfg_tuple_get(key, "name"));
|
||||||
|
*namestrp = namestr;
|
||||||
|
|
||||||
|
name = dns_fixedname_initname(&fname);
|
||||||
|
isc_buffer_constinit(&namebuf, namestr, strlen(namestr));
|
||||||
|
isc_buffer_add(&namebuf, strlen(namestr));
|
||||||
|
CHECK(dns_name_fromtext(name, &namebuf, dns_rootname, 0, NULL));
|
||||||
|
|
||||||
if (*initialp) {
|
if (*initialp) {
|
||||||
const char *initmethod;
|
atstr = cfg_obj_asstring(cfg_tuple_get(key, "anchortype"));
|
||||||
initmethod = cfg_obj_asstring(cfg_tuple_get(key, "init"));
|
|
||||||
|
|
||||||
if (strcasecmp(initmethod, "static-key") == 0) {
|
if (strcasecmp(atstr, "static-key") == 0) {
|
||||||
*initialp = false;
|
*initialp = false;
|
||||||
} else if (strcasecmp(initmethod, "initial-key") != 0) {
|
anchortype = STATIC_DNSKEY;
|
||||||
|
} else if (strcasecmp(atstr, "static-ds") == 0) {
|
||||||
|
*initialp = false;
|
||||||
|
anchortype = STATIC_DS;
|
||||||
|
} else if (strcasecmp(atstr, "initial-key") == 0) {
|
||||||
|
anchortype = INIT_DNSKEY;
|
||||||
|
} else if (strcasecmp(atstr, "initial-ds") == 0) {
|
||||||
|
anchortype = INIT_DS;
|
||||||
|
} else {
|
||||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
||||||
"key '%s': "
|
"key '%s': "
|
||||||
"invalid initialization method '%s'",
|
"invalid initialization method '%s'",
|
||||||
keynamestr, initmethod);
|
namestr, atstr);
|
||||||
result = ISC_R_FAILURE;
|
result = ISC_R_FAILURE;
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
|
} else {
|
||||||
|
anchortype = TRUSTED;
|
||||||
}
|
}
|
||||||
|
|
||||||
/*
|
isc_buffer_init(&databuf, data, sizeof(data));
|
||||||
* This function should never be reached for non-IN classes.
|
|
||||||
*/
|
|
||||||
keystruct.common.rdclass = dns_rdataclass_in;
|
|
||||||
keystruct.common.rdtype = dns_rdatatype_dnskey;
|
|
||||||
|
|
||||||
/*
|
|
||||||
* The key data in keystruct is not dynamically allocated.
|
|
||||||
*/
|
|
||||||
keystruct.mctx = NULL;
|
|
||||||
|
|
||||||
ISC_LINK_INIT(&keystruct.common, link);
|
|
||||||
|
|
||||||
if (flags > 0xffff)
|
|
||||||
CHECKM(ISC_R_RANGE, "key flags");
|
|
||||||
if (flags & DNS_KEYFLAG_REVOKE)
|
|
||||||
CHECKM(DST_R_BADKEYTYPE, "key flags revoke bit set");
|
|
||||||
if (proto > 0xff)
|
|
||||||
CHECKM(ISC_R_RANGE, "key protocol");
|
|
||||||
if (alg > 0xff)
|
|
||||||
CHECKM(ISC_R_RANGE, "key algorithm");
|
|
||||||
keystruct.flags = (uint16_t)flags;
|
|
||||||
keystruct.protocol = (uint8_t)proto;
|
|
||||||
keystruct.algorithm = (uint8_t)alg;
|
|
||||||
|
|
||||||
isc_buffer_init(&keydatabuf, keydata, sizeof(keydata));
|
|
||||||
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
|
isc_buffer_init(&rrdatabuf, rrdata, sizeof(rrdata));
|
||||||
|
|
||||||
keystr = cfg_obj_asstring(cfg_tuple_get(key, "key"));
|
*ds = (dns_rdata_ds_t){
|
||||||
CHECK(isc_base64_decodestring(keystr, &keydatabuf));
|
.common.rdclass = dns_rdataclass_in,
|
||||||
isc_buffer_usedregion(&keydatabuf, &r);
|
.common.rdtype = dns_rdatatype_ds
|
||||||
keystruct.datalen = r.length;
|
};
|
||||||
keystruct.data = r.base;
|
|
||||||
|
|
||||||
if ((keystruct.algorithm == DST_ALG_RSASHA1) &&
|
ISC_LINK_INIT(&ds->common, link);
|
||||||
r.length > 1 && r.base[0] == 1 && r.base[1] == 3)
|
|
||||||
{
|
switch(anchortype) {
|
||||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
|
case INIT_DNSKEY:
|
||||||
"%s '%s' has a weak exponent",
|
case STATIC_DNSKEY:
|
||||||
*initialp ? "initial-key" : "static-key",
|
case TRUSTED:
|
||||||
keynamestr);
|
/*
|
||||||
|
* This function should never be reached for view
|
||||||
|
* class other than IN
|
||||||
|
*/
|
||||||
|
keystruct.common.rdclass = dns_rdataclass_in;
|
||||||
|
keystruct.common.rdtype = dns_rdatatype_dnskey;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* The key data in keystruct is not dynamically allocated.
|
||||||
|
*/
|
||||||
|
keystruct.mctx = NULL;
|
||||||
|
|
||||||
|
ISC_LINK_INIT(&keystruct.common, link);
|
||||||
|
|
||||||
|
if (rdata1 > 0xffff) {
|
||||||
|
CHECKM(ISC_R_RANGE, "key flags");
|
||||||
|
}
|
||||||
|
if (rdata1 & DNS_KEYFLAG_REVOKE) {
|
||||||
|
CHECKM(DST_R_BADKEYTYPE, "key flags revoke bit set");
|
||||||
|
}
|
||||||
|
if (rdata2 > 0xff) {
|
||||||
|
CHECKM(ISC_R_RANGE, "key protocol");
|
||||||
|
}
|
||||||
|
if (rdata3 > 0xff) {
|
||||||
|
CHECKM(ISC_R_RANGE, "key algorithm");
|
||||||
|
}
|
||||||
|
|
||||||
|
keystruct.flags = (uint16_t)rdata1;
|
||||||
|
keystruct.protocol = (uint8_t)rdata2;
|
||||||
|
keystruct.algorithm = (uint8_t)rdata3;
|
||||||
|
|
||||||
|
if (!dst_algorithm_supported(keystruct.algorithm)) {
|
||||||
|
CHECK(DST_R_UNSUPPORTEDALG);
|
||||||
|
}
|
||||||
|
|
||||||
|
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
|
||||||
|
CHECK(isc_base64_decodestring(datastr, &databuf));
|
||||||
|
isc_buffer_usedregion(&databuf, &r);
|
||||||
|
keystruct.datalen = r.length;
|
||||||
|
keystruct.data = r.base;
|
||||||
|
|
||||||
|
CHECK(dns_rdata_fromstruct(&rdata, keystruct.common.rdclass,
|
||||||
|
keystruct.common.rdtype,
|
||||||
|
&keystruct, &rrdatabuf));
|
||||||
|
CHECK(dns_ds_fromkeyrdata(name, &rdata, DNS_DSDIGEST_SHA256,
|
||||||
|
digest, ds));
|
||||||
|
break;
|
||||||
|
|
||||||
|
case INIT_DS:
|
||||||
|
case STATIC_DS:
|
||||||
|
if (rdata1 > 0xffff) {
|
||||||
|
CHECKM(ISC_R_RANGE, "key tag");
|
||||||
|
}
|
||||||
|
if (rdata2 > 0xff) {
|
||||||
|
CHECKM(ISC_R_RANGE, "key algorithm");
|
||||||
|
}
|
||||||
|
if (rdata3 > 0xff) {
|
||||||
|
CHECKM(ISC_R_RANGE, "digest type");
|
||||||
|
}
|
||||||
|
|
||||||
|
ds->key_tag = (uint16_t)rdata1;
|
||||||
|
ds->algorithm = (uint8_t)rdata2;
|
||||||
|
ds->digest_type = (uint8_t)rdata3;
|
||||||
|
|
||||||
|
datastr = cfg_obj_asstring(cfg_tuple_get(key, "data"));
|
||||||
|
CHECK(isc_hex_decodestring(datastr, &databuf));
|
||||||
|
isc_buffer_usedregion(&databuf, &r);
|
||||||
|
|
||||||
|
switch (ds->digest_type) {
|
||||||
|
case DNS_DSDIGEST_SHA1:
|
||||||
|
if (r.length != ISC_SHA1_DIGESTLENGTH) {
|
||||||
|
CHECK(ISC_R_UNEXPECTEDEND);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
case DNS_DSDIGEST_SHA256:
|
||||||
|
if (r.length != ISC_SHA256_DIGESTLENGTH) {
|
||||||
|
CHECK(ISC_R_UNEXPECTEDEND);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
case DNS_DSDIGEST_SHA384:
|
||||||
|
if (r.length != ISC_SHA384_DIGESTLENGTH) {
|
||||||
|
CHECK(ISC_R_UNEXPECTEDEND);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
||||||
|
"key '%s': "
|
||||||
|
"unknown ds digest type %u",
|
||||||
|
namestr, ds->digest_type);
|
||||||
|
result = ISC_R_FAILURE;
|
||||||
|
goto cleanup;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
ds->length = r.length;
|
||||||
|
ds->digest = digest;
|
||||||
|
memmove(ds->digest, r.base, r.length);
|
||||||
|
|
||||||
|
break;
|
||||||
|
|
||||||
|
default:
|
||||||
|
INSIST(0);
|
||||||
|
ISC_UNREACHABLE();
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(dns_rdata_fromstruct(NULL,
|
|
||||||
keystruct.common.rdclass,
|
|
||||||
keystruct.common.rdtype,
|
|
||||||
&keystruct, &rrdatabuf));
|
|
||||||
dns_fixedname_init(&fkeyname);
|
|
||||||
isc_buffer_constinit(&namebuf, keynamestr, strlen(keynamestr));
|
|
||||||
isc_buffer_add(&namebuf, strlen(keynamestr));
|
|
||||||
CHECK(dns_name_fromtext(keyname, &namebuf, dns_rootname, 0, NULL));
|
|
||||||
CHECK(dst_key_fromdns(keyname, dns_rdataclass_in, &rrdatabuf,
|
|
||||||
mctx, &dstkey));
|
|
||||||
|
|
||||||
*target = dstkey;
|
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (dstkey != NULL) {
|
|
||||||
dst_key_free(&dstkey);
|
|
||||||
}
|
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -820,26 +909,31 @@ dstkey_fromconfig(const cfg_obj_t *key, bool *initialp, dst_key_t **target,
|
|||||||
static isc_result_t
|
static isc_result_t
|
||||||
process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
||||||
const dns_name_t *keyname_match, dns_resolver_t *resolver,
|
const dns_name_t *keyname_match, dns_resolver_t *resolver,
|
||||||
bool managed, isc_mem_t *mctx)
|
bool managed)
|
||||||
{
|
{
|
||||||
const dns_name_t *keyname = NULL;
|
dns_fixedname_t fkeyname;
|
||||||
const char *keynamestr = NULL;
|
dns_name_t *keyname = NULL;
|
||||||
dst_key_t *dstkey = NULL;
|
const char *namestr = NULL;
|
||||||
unsigned int keyalg;
|
dns_rdata_ds_t ds;
|
||||||
isc_result_t result;
|
isc_result_t result;
|
||||||
bool initializing = managed;
|
bool initializing = managed;
|
||||||
|
unsigned char digest[ISC_MAX_MD_SIZE];
|
||||||
|
isc_buffer_t b;
|
||||||
|
|
||||||
result = dstkey_fromconfig(key, &initializing,
|
result = ta_fromconfig(key, &initializing, &namestr, digest, &ds);
|
||||||
&dstkey, &keynamestr, mctx);
|
|
||||||
|
|
||||||
switch (result) {
|
switch (result) {
|
||||||
case ISC_R_SUCCESS:
|
case ISC_R_SUCCESS:
|
||||||
/*
|
/*
|
||||||
* Key was parsed correctly, its algorithm is supported by the
|
* Trust anchor was parsed correctly.
|
||||||
* crypto library, and it is not revoked.
|
|
||||||
*/
|
*/
|
||||||
keyname = dst_key_name(dstkey);
|
isc_buffer_constinit(&b, namestr, strlen(namestr));
|
||||||
keyalg = dst_key_alg(dstkey);
|
isc_buffer_add(&b, strlen(namestr));
|
||||||
|
keyname = dns_fixedname_initname(&fkeyname);
|
||||||
|
result = dns_name_fromtext(keyname, &b, dns_rootname, 0, NULL);
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
return (result);
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
case DST_R_UNSUPPORTEDALG:
|
case DST_R_UNSUPPORTEDALG:
|
||||||
case DST_R_BADKEYTYPE:
|
case DST_R_BADKEYTYPE:
|
||||||
@@ -851,7 +945,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
|||||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
|
||||||
"ignoring %s for '%s': %s",
|
"ignoring %s for '%s': %s",
|
||||||
initializing ? "initial-key" : "static-key",
|
initializing ? "initial-key" : "static-key",
|
||||||
keynamestr, isc_result_totext(result));
|
namestr, isc_result_totext(result));
|
||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
case DST_R_NOCRYPTO:
|
case DST_R_NOCRYPTO:
|
||||||
/*
|
/*
|
||||||
@@ -860,7 +954,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
|||||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
||||||
"ignoring %s for '%s': no crypto support",
|
"ignoring %s for '%s': no crypto support",
|
||||||
initializing ? "initial-key" : "static-key",
|
initializing ? "initial-key" : "static-key",
|
||||||
keynamestr);
|
namestr);
|
||||||
return (result);
|
return (result);
|
||||||
default:
|
default:
|
||||||
/*
|
/*
|
||||||
@@ -871,7 +965,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
|||||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
cfg_obj_log(key, named_g_lctx, ISC_LOG_ERROR,
|
||||||
"configuring %s for '%s': %s",
|
"configuring %s for '%s': %s",
|
||||||
initializing ? "initial-key" : "static-key",
|
initializing ? "initial-key" : "static-key",
|
||||||
keynamestr, isc_result_totext(result));
|
namestr, isc_result_totext(result));
|
||||||
return (ISC_R_FAILURE);
|
return (ISC_R_FAILURE);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -889,34 +983,26 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
|||||||
* its owner name. If it does not, do not load the key and log a
|
* its owner name. If it does not, do not load the key and log a
|
||||||
* warning, but do not prevent further keys from being processed.
|
* warning, but do not prevent further keys from being processed.
|
||||||
*/
|
*/
|
||||||
if (!dns_resolver_algorithm_supported(resolver, keyname, keyalg)) {
|
if (!dns_resolver_algorithm_supported(resolver, keyname, ds.algorithm))
|
||||||
|
{
|
||||||
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
|
cfg_obj_log(key, named_g_lctx, ISC_LOG_WARNING,
|
||||||
"ignoring %s for '%s': algorithm is disabled",
|
"ignoring %s for '%s': algorithm is disabled",
|
||||||
initializing ? "initial-key" : "static-key",
|
initializing ? "initial-key" : "static-key",
|
||||||
keynamestr);
|
namestr);
|
||||||
goto done;
|
goto done;
|
||||||
}
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Add the key to 'secroots'. Keys from a "dnssec-keys" or
|
* Add the key to 'secroots'. Keys from a "trust-anchors" or
|
||||||
* "managed-keys" statement may be either static or initializing
|
* "managed-keys" statement may be either static or initializing
|
||||||
* keys. If it's not initializing, we don't want to treat it as
|
* keys. If it's not initializing, we don't want to treat it as
|
||||||
* managed, so we use 'initializing' twice here, for both the
|
* managed, so we use 'initializing' twice here, for both the
|
||||||
* 'managed' and 'initializing' arguments to dns_keytable_add().
|
* 'managed' and 'initializing' arguments to dns_keytable_add().
|
||||||
*/
|
*/
|
||||||
result = dns_keytable_add(secroots, initializing,
|
result = dns_keytable_add(secroots, initializing, initializing,
|
||||||
initializing, &dstkey);
|
keyname, &ds);
|
||||||
|
|
||||||
done:
|
done:
|
||||||
/*
|
|
||||||
* Ensure 'dstkey' does not leak. Note that if dns_keytable_add()
|
|
||||||
* succeeds, ownership of the key structure is transferred to the key
|
|
||||||
* table, i.e. 'dstkey' is set to NULL.
|
|
||||||
*/
|
|
||||||
if (dstkey != NULL) {
|
|
||||||
dst_key_free(&dstkey);
|
|
||||||
}
|
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -927,7 +1013,7 @@ process_key(const cfg_obj_t *key, dns_keytable_t *secroots,
|
|||||||
*/
|
*/
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
load_view_keys(const cfg_obj_t *keys, dns_view_t *view, bool managed,
|
load_view_keys(const cfg_obj_t *keys, dns_view_t *view, bool managed,
|
||||||
const dns_name_t *keyname, isc_mem_t *mctx)
|
const dns_name_t *keyname)
|
||||||
{
|
{
|
||||||
const cfg_listelt_t *elt, *elt2;
|
const cfg_listelt_t *elt, *elt2;
|
||||||
const cfg_obj_t *keylist;
|
const cfg_obj_t *keylist;
|
||||||
@@ -946,9 +1032,8 @@ load_view_keys(const cfg_obj_t *keys, dns_view_t *view, bool managed,
|
|||||||
elt2 != NULL;
|
elt2 != NULL;
|
||||||
elt2 = cfg_list_next(elt2))
|
elt2 = cfg_list_next(elt2))
|
||||||
{
|
{
|
||||||
CHECK(process_key(cfg_listelt_value(elt2),
|
CHECK(process_key(cfg_listelt_value(elt2), secroots,
|
||||||
secroots, keyname, view->resolver,
|
keyname, view->resolver, managed));
|
||||||
managed, mctx));
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1000,9 +1085,9 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
|||||||
const cfg_obj_t *view_keys = NULL;
|
const cfg_obj_t *view_keys = NULL;
|
||||||
const cfg_obj_t *global_keys = NULL;
|
const cfg_obj_t *global_keys = NULL;
|
||||||
const cfg_obj_t *view_managed_keys = NULL;
|
const cfg_obj_t *view_managed_keys = NULL;
|
||||||
const cfg_obj_t *view_dnssec_keys = NULL;
|
const cfg_obj_t *view_trust_anchors = NULL;
|
||||||
const cfg_obj_t *global_managed_keys = NULL;
|
const cfg_obj_t *global_managed_keys = NULL;
|
||||||
const cfg_obj_t *global_dnssec_keys = NULL;
|
const cfg_obj_t *global_trust_anchors = NULL;
|
||||||
const cfg_obj_t *maps[4];
|
const cfg_obj_t *maps[4];
|
||||||
const cfg_obj_t *voptions = NULL;
|
const cfg_obj_t *voptions = NULL;
|
||||||
const cfg_obj_t *options = NULL;
|
const cfg_obj_t *options = NULL;
|
||||||
@@ -1023,11 +1108,11 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
|||||||
(void) cfg_map_get(voptions, "trusted-keys",
|
(void) cfg_map_get(voptions, "trusted-keys",
|
||||||
&view_keys);
|
&view_keys);
|
||||||
|
|
||||||
/* managed-keys and dnssec-keys are synonyms. */
|
/* managed-keys and trust-anchors are synonyms. */
|
||||||
(void) cfg_map_get(voptions, "managed-keys",
|
(void) cfg_map_get(voptions, "managed-keys",
|
||||||
&view_managed_keys);
|
&view_managed_keys);
|
||||||
(void) cfg_map_get(voptions, "dnssec-keys",
|
(void) cfg_map_get(voptions, "trust-anchors",
|
||||||
&view_dnssec_keys);
|
&view_trust_anchors);
|
||||||
|
|
||||||
maps[i++] = voptions;
|
maps[i++] = voptions;
|
||||||
}
|
}
|
||||||
@@ -1036,9 +1121,10 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
|||||||
if (config != NULL) {
|
if (config != NULL) {
|
||||||
(void)cfg_map_get(config, "trusted-keys", &global_keys);
|
(void)cfg_map_get(config, "trusted-keys", &global_keys);
|
||||||
|
|
||||||
/* managed-keys and dnssec-keys are synonyms. */
|
/* managed-keys and trust-anchors are synonyms. */
|
||||||
(void)cfg_map_get(config, "managed-keys", &global_managed_keys);
|
(void)cfg_map_get(config, "managed-keys", &global_managed_keys);
|
||||||
(void)cfg_map_get(config, "dnssec-keys", &global_dnssec_keys);
|
(void)cfg_map_get(config, "trust-anchors",
|
||||||
|
&global_trust_anchors);
|
||||||
|
|
||||||
(void)cfg_map_get(config, "options", &options);
|
(void)cfg_map_get(config, "options", &options);
|
||||||
if (options != NULL) {
|
if (options != NULL) {
|
||||||
@@ -1070,7 +1156,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
|||||||
|
|
||||||
/*
|
/*
|
||||||
* If bind.keys exists and is populated, it overrides
|
* If bind.keys exists and is populated, it overrides
|
||||||
* the dnssec-keys clause hard-coded in named_g_config.
|
* the trust-anchors clause hard-coded in named_g_config.
|
||||||
*/
|
*/
|
||||||
if (bindkeys != NULL) {
|
if (bindkeys != NULL) {
|
||||||
isc_log_write(named_g_lctx, DNS_LOGCATEGORY_SECURITY,
|
isc_log_write(named_g_lctx, DNS_LOGCATEGORY_SECURITY,
|
||||||
@@ -1079,7 +1165,7 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
|||||||
"from '%s'",
|
"from '%s'",
|
||||||
view->name, named_g_server->bindkeysfile);
|
view->name, named_g_server->bindkeysfile);
|
||||||
|
|
||||||
(void)cfg_map_get(bindkeys, "dnssec-keys",
|
(void)cfg_map_get(bindkeys, "trust-anchors",
|
||||||
&builtin_keys);
|
&builtin_keys);
|
||||||
|
|
||||||
if (builtin_keys == NULL) {
|
if (builtin_keys == NULL) {
|
||||||
@@ -1099,13 +1185,13 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
|||||||
"using built-in root key for view %s",
|
"using built-in root key for view %s",
|
||||||
view->name);
|
view->name);
|
||||||
|
|
||||||
(void)cfg_map_get(named_g_config, "dnssec-keys",
|
(void)cfg_map_get(named_g_config, "trust-anchors",
|
||||||
&builtin_keys);
|
&builtin_keys);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (builtin_keys != NULL) {
|
if (builtin_keys != NULL) {
|
||||||
CHECK(load_view_keys(builtin_keys, view, true,
|
CHECK(load_view_keys(builtin_keys, view, true,
|
||||||
dns_rootname, mctx));
|
dns_rootname));
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!keyloaded(view, dns_rootname)) {
|
if (!keyloaded(view, dns_rootname)) {
|
||||||
@@ -1117,16 +1203,14 @@ configure_view_dnsseckeys(dns_view_t *view, const cfg_obj_t *vconfig,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
CHECK(load_view_keys(view_keys, view, false, NULL, mctx));
|
|
||||||
CHECK(load_view_keys(view_managed_keys, view, true, NULL, mctx));
|
|
||||||
CHECK(load_view_keys(view_dnssec_keys, view, true, NULL, mctx));
|
|
||||||
|
|
||||||
if (view->rdclass == dns_rdataclass_in) {
|
if (view->rdclass == dns_rdataclass_in) {
|
||||||
CHECK(load_view_keys(global_keys, view, false, NULL, mctx));
|
CHECK(load_view_keys(view_keys, view, false, NULL));
|
||||||
CHECK(load_view_keys(global_managed_keys, view, true,
|
CHECK(load_view_keys(view_trust_anchors, view, true, NULL));
|
||||||
NULL, mctx));
|
CHECK(load_view_keys(view_managed_keys, view, true, NULL));
|
||||||
CHECK(load_view_keys(global_dnssec_keys, view, true,
|
|
||||||
NULL, mctx));
|
CHECK(load_view_keys(global_keys, view, false, NULL));
|
||||||
|
CHECK(load_view_keys(global_trust_anchors, view, true, NULL));
|
||||||
|
CHECK(load_view_keys(global_managed_keys, view, true, NULL));
|
||||||
}
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -1260,7 +1344,7 @@ get_view_querysource_dispatch(const cfg_obj_t **maps, int af,
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
if (isc_sockaddr_getport(&sa) == 0) {
|
if (isc_sockaddr_getport(&sa) == 0) {
|
||||||
attrs |= DNS_DISPATCHATTR_EXCLUSIVE;
|
// attrs |= DNS_DISPATCHATTR_EXCLUSIVE;
|
||||||
maxdispatchbuffers = EXCLBUFFERS;
|
maxdispatchbuffers = EXCLBUFFERS;
|
||||||
} else {
|
} else {
|
||||||
INSIST(obj != NULL);
|
INSIST(obj != NULL);
|
||||||
@@ -6700,35 +6784,34 @@ struct dotat_arg {
|
|||||||
* reported in the TAT query.
|
* reported in the TAT query.
|
||||||
*/
|
*/
|
||||||
static isc_result_t
|
static isc_result_t
|
||||||
get_tat_qname(dns_name_t *dst, const dns_name_t **origin,
|
get_tat_qname(dns_name_t *target, dns_name_t *keyname, dns_keynode_t *keynode) {
|
||||||
dns_keytable_t *keytable, dns_keynode_t *keynode)
|
dns_rdataset_t *dsset = NULL;
|
||||||
{
|
|
||||||
dns_keynode_t *firstnode = keynode;
|
|
||||||
dns_keynode_t *nextnode;
|
|
||||||
unsigned int i, n = 0;
|
unsigned int i, n = 0;
|
||||||
uint16_t ids[12];
|
uint16_t ids[12];
|
||||||
isc_textregion_t r;
|
isc_textregion_t r;
|
||||||
char label[64];
|
char label[64];
|
||||||
int m;
|
int m;
|
||||||
|
|
||||||
REQUIRE(origin != NULL && *origin == NULL);
|
if ((dsset = dns_keynode_dsset(keynode)) != NULL) {
|
||||||
|
isc_result_t result;
|
||||||
|
|
||||||
do {
|
for (result = dns_rdataset_first(dsset);
|
||||||
dst_key_t *key = dns_keynode_key(keynode);
|
result == ISC_R_SUCCESS;
|
||||||
if (key != NULL) {
|
result = dns_rdataset_next(dsset))
|
||||||
*origin = dst_key_name(key);
|
{
|
||||||
|
dns_rdata_t rdata = DNS_RDATA_INIT;
|
||||||
|
dns_rdata_ds_t ds;
|
||||||
|
|
||||||
|
dns_rdata_reset(&rdata);
|
||||||
|
dns_rdataset_current(dsset, &rdata);
|
||||||
|
result = dns_rdata_tostruct(&rdata, &ds, NULL);
|
||||||
|
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||||
if (n < (sizeof(ids)/sizeof(ids[0]))) {
|
if (n < (sizeof(ids)/sizeof(ids[0]))) {
|
||||||
ids[n] = dst_key_id(key);
|
ids[n] = ds.key_tag;
|
||||||
n++;
|
n++;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
nextnode = NULL;
|
}
|
||||||
(void)dns_keytable_nextkeynode(keytable, keynode, &nextnode);
|
|
||||||
if (keynode != firstnode) {
|
|
||||||
dns_keytable_detachkeynode(keytable, &keynode);
|
|
||||||
}
|
|
||||||
keynode = nextnode;
|
|
||||||
} while (keynode != NULL);
|
|
||||||
|
|
||||||
if (n == 0) {
|
if (n == 0) {
|
||||||
return (DNS_R_EMPTYNAME);
|
return (DNS_R_EMPTYNAME);
|
||||||
@@ -6758,14 +6841,15 @@ get_tat_qname(dns_name_t *dst, const dns_name_t **origin,
|
|||||||
isc_textregion_consume(&r, m);
|
isc_textregion_consume(&r, m);
|
||||||
}
|
}
|
||||||
|
|
||||||
return (dns_name_fromstring2(dst, label, *origin, 0, NULL));
|
return (dns_name_fromstring2(target, label, keyname, 0, NULL));
|
||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
dotat(dns_keytable_t *keytable, dns_keynode_t *keynode,
|
||||||
|
dns_name_t *keyname, void *arg)
|
||||||
|
{
|
||||||
struct dotat_arg *dotat_arg = arg;
|
struct dotat_arg *dotat_arg = arg;
|
||||||
char namebuf[DNS_NAME_FORMATSIZE];
|
char namebuf[DNS_NAME_FORMATSIZE];
|
||||||
const dns_name_t *origin = NULL;
|
|
||||||
dns_fixedname_t fixed, fdomain;
|
dns_fixedname_t fixed, fdomain;
|
||||||
dns_name_t *tatname, *domain;
|
dns_name_t *tatname, *domain;
|
||||||
dns_rdataset_t nameservers;
|
dns_rdataset_t nameservers;
|
||||||
@@ -6782,7 +6866,7 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
|||||||
task = dotat_arg->task;
|
task = dotat_arg->task;
|
||||||
|
|
||||||
tatname = dns_fixedname_initname(&fixed);
|
tatname = dns_fixedname_initname(&fixed);
|
||||||
result = get_tat_qname(tatname, &origin, keytable, keynode);
|
result = get_tat_qname(tatname, keyname, keynode);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -6820,17 +6904,13 @@ dotat(dns_keytable_t *keytable, dns_keynode_t *keynode, void *arg) {
|
|||||||
* order to eventually find the destination host to send the TAT query
|
* order to eventually find the destination host to send the TAT query
|
||||||
* to.
|
* to.
|
||||||
*
|
*
|
||||||
* 'origin' holds the domain name at 'keynode', i.e. the domain name
|
|
||||||
* for which the trust anchors to be reported by this TAT query are
|
|
||||||
* defined.
|
|
||||||
*
|
|
||||||
* After the dns_view_findzonecut() call, 'domain' will hold the
|
* After the dns_view_findzonecut() call, 'domain' will hold the
|
||||||
* deepest zone cut we can find for 'origin' while 'nameservers' will
|
* deepest zone cut we can find for 'keyname' while 'nameservers' will
|
||||||
* hold the NS RRset at that zone cut.
|
* hold the NS RRset at that zone cut.
|
||||||
*/
|
*/
|
||||||
domain = dns_fixedname_initname(&fdomain);
|
domain = dns_fixedname_initname(&fdomain);
|
||||||
dns_rdataset_init(&nameservers);
|
dns_rdataset_init(&nameservers);
|
||||||
result = dns_view_findzonecut(view, origin, domain, NULL, 0, 0,
|
result = dns_view_findzonecut(view, keyname, domain, NULL, 0, 0,
|
||||||
true, true, &nameservers, NULL);
|
true, true, &nameservers, NULL);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
result = dns_resolver_createfetch(view->resolver, tatname,
|
result = dns_resolver_createfetch(view->resolver, tatname,
|
||||||
@@ -6899,7 +6979,7 @@ tat_timer_tick(isc_task_t *task, isc_event_t *event) {
|
|||||||
static void
|
static void
|
||||||
pps_timer_tick(isc_task_t *task, isc_event_t *event) {
|
pps_timer_tick(isc_task_t *task, isc_event_t *event) {
|
||||||
static unsigned int oldrequests = 0;
|
static unsigned int oldrequests = 0;
|
||||||
unsigned int requests = ns_client_requests;
|
unsigned int requests = atomic_load_relaxed(&ns_client_requests);
|
||||||
|
|
||||||
UNUSED(task);
|
UNUSED(task);
|
||||||
isc_event_free(&event);
|
isc_event_free(&event);
|
||||||
@@ -7261,7 +7341,7 @@ configure_session_key(const cfg_obj_t **maps, named_server_t *server,
|
|||||||
server->session_keyname = isc_mem_get(mctx,
|
server->session_keyname = isc_mem_get(mctx,
|
||||||
sizeof(dns_name_t));
|
sizeof(dns_name_t));
|
||||||
dns_name_init(server->session_keyname, NULL);
|
dns_name_init(server->session_keyname, NULL);
|
||||||
CHECK(dns_name_dup(keyname, mctx, server->session_keyname));
|
dns_name_dup(keyname, mctx, server->session_keyname);
|
||||||
|
|
||||||
server->session_keyfile = isc_mem_strdup(mctx, keyfile);
|
server->session_keyfile = isc_mem_strdup(mctx, keyfile);
|
||||||
|
|
||||||
@@ -7614,9 +7694,7 @@ data_to_cfg(dns_view_t *view, MDB_val *key, MDB_val *data,
|
|||||||
REQUIRE(zoneconfig != NULL && *zoneconfig == NULL);
|
REQUIRE(zoneconfig != NULL && *zoneconfig == NULL);
|
||||||
|
|
||||||
if (*text == NULL) {
|
if (*text == NULL) {
|
||||||
result = isc_buffer_allocate(view->mctx, text, 256);
|
isc_buffer_allocate(view->mctx, text, 256);
|
||||||
if (result != ISC_R_SUCCESS)
|
|
||||||
goto cleanup;
|
|
||||||
} else {
|
} else {
|
||||||
isc_buffer_clear(*text);
|
isc_buffer_clear(*text);
|
||||||
}
|
}
|
||||||
@@ -8196,6 +8274,11 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
isc_socketmgr_setreserved(named_g_socketmgr, reserved);
|
isc_socketmgr_setreserved(named_g_socketmgr, reserved);
|
||||||
|
|
||||||
#if defined(HAVE_GEOIP2)
|
#if defined(HAVE_GEOIP2)
|
||||||
|
/*
|
||||||
|
* Release any previously opened GeoIP2 databases.
|
||||||
|
*/
|
||||||
|
named_geoip_unload();
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Initialize GeoIP databases from the configured location.
|
* Initialize GeoIP databases from the configured location.
|
||||||
* This should happen before configuring any ACLs, so that we
|
* This should happen before configuring any ACLs, so that we
|
||||||
@@ -8329,8 +8412,8 @@ load_configuration(const char *filename, named_server_t *server,
|
|||||||
advertised = MAX_TCP_TIMEOUT;
|
advertised = MAX_TCP_TIMEOUT;
|
||||||
}
|
}
|
||||||
|
|
||||||
ns_server_settimeouts(named_g_server->sctx,
|
isc_nm_tcp_settimeouts(named_g_nm, initial, idle,
|
||||||
initial, idle, keepalive, advertised);
|
keepalive, advertised);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Configure sets of UDP query source ports.
|
* Configure sets of UDP query source ports.
|
||||||
@@ -9461,7 +9544,7 @@ run_server(isc_task_t *task, isc_event_t *event) {
|
|||||||
named_g_nm,
|
named_g_nm,
|
||||||
named_g_dispatchmgr,
|
named_g_dispatchmgr,
|
||||||
server->task, named_g_udpdisp, geoip,
|
server->task, named_g_udpdisp, geoip,
|
||||||
&server->interfacemgr),
|
named_g_cpus, &server->interfacemgr),
|
||||||
"creating interface manager");
|
"creating interface manager");
|
||||||
|
|
||||||
CHECKFATAL(isc_timer_create(named_g_timermgr, isc_timertype_inactive,
|
CHECKFATAL(isc_timer_create(named_g_timermgr, isc_timertype_inactive,
|
||||||
@@ -9595,9 +9678,6 @@ shutdown_server(isc_task_t *task, isc_event_t *event) {
|
|||||||
dns_tsigkey_detach(&named_g_sessionkey);
|
dns_tsigkey_detach(&named_g_sessionkey);
|
||||||
dns_name_free(&named_g_sessionkeyname, server->mctx);
|
dns_name_free(&named_g_sessionkeyname, server->mctx);
|
||||||
}
|
}
|
||||||
#ifdef HAVE_DNSTAP
|
|
||||||
dns_dt_shutdown();
|
|
||||||
#endif
|
|
||||||
#if defined(HAVE_GEOIP2)
|
#if defined(HAVE_GEOIP2)
|
||||||
named_geoip_shutdown();
|
named_geoip_shutdown();
|
||||||
#endif /* HAVE_GEOIP2 */
|
#endif /* HAVE_GEOIP2 */
|
||||||
@@ -9664,7 +9744,7 @@ named_server_create(isc_mem_t *mctx, named_server_t **serverp) {
|
|||||||
named_server_t *server = isc_mem_get(mctx, sizeof(*server));
|
named_server_t *server = isc_mem_get(mctx, sizeof(*server));
|
||||||
|
|
||||||
if (server == NULL)
|
if (server == NULL)
|
||||||
fatal("allocating server object", ISC_R_NOMEMORY);
|
fatal(server, "allocating server object", ISC_R_NOMEMORY);
|
||||||
|
|
||||||
server->mctx = mctx;
|
server->mctx = mctx;
|
||||||
server->task = NULL;
|
server->task = NULL;
|
||||||
@@ -9721,7 +9801,7 @@ named_server_create(isc_mem_t *mctx, named_server_t **serverp) {
|
|||||||
/*
|
/*
|
||||||
* GeoIP must be initialized before the interface
|
* GeoIP must be initialized before the interface
|
||||||
* manager (which includes the ACL environment)
|
* manager (which includes the ACL environment)
|
||||||
* is created
|
* is created.
|
||||||
*/
|
*/
|
||||||
named_geoip_init();
|
named_geoip_init();
|
||||||
#endif /* HAVE_GEOIP2 */
|
#endif /* HAVE_GEOIP2 */
|
||||||
@@ -9787,6 +9867,7 @@ named_server_create(isc_mem_t *mctx, named_server_t **serverp) {
|
|||||||
isc_sockstatscounter_max),
|
isc_sockstatscounter_max),
|
||||||
"isc_stats_create");
|
"isc_stats_create");
|
||||||
isc_socketmgr_setstats(named_g_socketmgr, server->sockstats);
|
isc_socketmgr_setstats(named_g_socketmgr, server->sockstats);
|
||||||
|
isc_nm_setstats(named_g_nm, server->sockstats);
|
||||||
|
|
||||||
CHECKFATAL(isc_stats_create(named_g_mctx, &server->zonestats,
|
CHECKFATAL(isc_stats_create(named_g_mctx, &server->zonestats,
|
||||||
dns_zonestatscounter_max),
|
dns_zonestatscounter_max),
|
||||||
@@ -9875,7 +9956,15 @@ named_server_destroy(named_server_t **serverp) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
static void
|
static void
|
||||||
fatal(const char *msg, isc_result_t result) {
|
fatal(named_server_t *server, const char *msg, isc_result_t result) {
|
||||||
|
if (server != NULL) {
|
||||||
|
/*
|
||||||
|
* Prevent races between the OpenSSL on_exit registered
|
||||||
|
* function and any other OpenSSL calls from other tasks
|
||||||
|
* by requesting exclusive access to the task manager.
|
||||||
|
*/
|
||||||
|
(void)isc_task_beginexclusive(server->task);
|
||||||
|
}
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_CRITICAL,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_CRITICAL,
|
||||||
"%s: %s", msg, isc_result_totext(result));
|
"%s: %s", msg, isc_result_totext(result));
|
||||||
@@ -9976,8 +10065,7 @@ named_add_reserved_dispatch(named_server_t *server,
|
|||||||
return;
|
return;
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (dispatch != NULL)
|
isc_mem_put(server->mctx, dispatch, sizeof(*dispatch));
|
||||||
isc_mem_put(server->mctx, dispatch, sizeof(*dispatch));
|
|
||||||
isc_sockaddr_format(addr, addrbuf, sizeof(addrbuf));
|
isc_sockaddr_format(addr, addrbuf, sizeof(addrbuf));
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_WARNING,
|
||||||
@@ -10939,8 +11027,7 @@ named_server_dumpdb(named_server_t *server, isc_lex_t *lex,
|
|||||||
return (ISC_R_SUCCESS);
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (dctx != NULL)
|
dumpcontext_destroy(dctx);
|
||||||
dumpcontext_destroy(dctx);
|
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -10956,17 +11043,20 @@ named_server_dumpsecroots(named_server_t *server, isc_lex_t *lex,
|
|||||||
FILE *fp = NULL;
|
FILE *fp = NULL;
|
||||||
isc_time_t now;
|
isc_time_t now;
|
||||||
char tbuf[64];
|
char tbuf[64];
|
||||||
|
unsigned int used = isc_buffer_usedlength(*text);
|
||||||
|
bool first = true;
|
||||||
|
|
||||||
/* Skip the command name. */
|
/* Skip the command name. */
|
||||||
ptr = next_token(lex, text);
|
ptr = next_token(lex, text);
|
||||||
if (ptr == NULL)
|
if (ptr == NULL) {
|
||||||
return (ISC_R_UNEXPECTEDEND);
|
return (ISC_R_UNEXPECTEDEND);
|
||||||
|
}
|
||||||
|
|
||||||
/* "-" here means print the output instead of dumping to file */
|
/* "-" here means print the output instead of dumping to file */
|
||||||
ptr = next_token(lex, text);
|
ptr = next_token(lex, text);
|
||||||
if (ptr != NULL && strcmp(ptr, "-") == 0)
|
if (ptr != NULL && strcmp(ptr, "-") == 0) {
|
||||||
ptr = next_token(lex, text);
|
ptr = next_token(lex, text);
|
||||||
else {
|
} else {
|
||||||
result = isc_stdio_open(server->secrootsfile, "w", &fp);
|
result = isc_stdio_open(server->secrootsfile, "w", &fp);
|
||||||
if (result != ISC_R_SUCCESS) {
|
if (result != ISC_R_SUCCESS) {
|
||||||
(void) putstr(text, "could not open ");
|
(void) putstr(text, "could not open ");
|
||||||
@@ -10981,66 +11071,85 @@ named_server_dumpsecroots(named_server_t *server, isc_lex_t *lex,
|
|||||||
CHECK(putstr(text, "secure roots as of "));
|
CHECK(putstr(text, "secure roots as of "));
|
||||||
CHECK(putstr(text, tbuf));
|
CHECK(putstr(text, tbuf));
|
||||||
CHECK(putstr(text, ":\n"));
|
CHECK(putstr(text, ":\n"));
|
||||||
|
used = isc_buffer_usedlength(*text);
|
||||||
|
|
||||||
do {
|
do {
|
||||||
for (view = ISC_LIST_HEAD(server->viewlist);
|
for (view = ISC_LIST_HEAD(server->viewlist);
|
||||||
view != NULL;
|
view != NULL;
|
||||||
view = ISC_LIST_NEXT(view, link))
|
view = ISC_LIST_NEXT(view, link))
|
||||||
{
|
{
|
||||||
if (ptr != NULL && strcmp(view->name, ptr) != 0)
|
if (ptr != NULL && strcmp(view->name, ptr) != 0) {
|
||||||
continue;
|
continue;
|
||||||
if (secroots != NULL)
|
}
|
||||||
|
if (secroots != NULL) {
|
||||||
dns_keytable_detach(&secroots);
|
dns_keytable_detach(&secroots);
|
||||||
|
}
|
||||||
result = dns_view_getsecroots(view, &secroots);
|
result = dns_view_getsecroots(view, &secroots);
|
||||||
if (result == ISC_R_NOTFOUND) {
|
if (result == ISC_R_NOTFOUND) {
|
||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
CHECK(putstr(text, "\n Start view "));
|
if (first || used != isc_buffer_usedlength(*text)) {
|
||||||
|
CHECK(putstr(text, "\n"));
|
||||||
|
first = false;
|
||||||
|
}
|
||||||
|
CHECK(putstr(text, " Start view "));
|
||||||
CHECK(putstr(text, view->name));
|
CHECK(putstr(text, view->name));
|
||||||
CHECK(putstr(text, "\n Secure roots:\n\n"));
|
CHECK(putstr(text, "\n Secure roots:\n\n"));
|
||||||
|
used = isc_buffer_usedlength(*text);
|
||||||
CHECK(dns_keytable_totext(secroots, text));
|
CHECK(dns_keytable_totext(secroots, text));
|
||||||
|
|
||||||
if (ntatable != NULL)
|
if (ntatable != NULL) {
|
||||||
dns_ntatable_detach(&ntatable);
|
dns_ntatable_detach(&ntatable);
|
||||||
|
}
|
||||||
result = dns_view_getntatable(view, &ntatable);
|
result = dns_view_getntatable(view, &ntatable);
|
||||||
if (result == ISC_R_NOTFOUND) {
|
if (result == ISC_R_NOTFOUND) {
|
||||||
result = ISC_R_SUCCESS;
|
result = ISC_R_SUCCESS;
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
CHECK(putstr(text, "\n Negative trust anchors:\n\n"));
|
if (used != isc_buffer_usedlength(*text)) {
|
||||||
|
CHECK(putstr(text, "\n"));
|
||||||
|
}
|
||||||
|
CHECK(putstr(text, " Negative trust anchors:\n\n"));
|
||||||
|
used = isc_buffer_usedlength(*text);
|
||||||
CHECK(dns_ntatable_totext(ntatable, NULL, text));
|
CHECK(dns_ntatable_totext(ntatable, NULL, text));
|
||||||
}
|
}
|
||||||
if (ptr != NULL)
|
|
||||||
|
if (ptr != NULL) {
|
||||||
ptr = next_token(lex, text);
|
ptr = next_token(lex, text);
|
||||||
|
}
|
||||||
} while (ptr != NULL);
|
} while (ptr != NULL);
|
||||||
|
|
||||||
cleanup:
|
cleanup:
|
||||||
if (isc_buffer_usedlength(*text) > 0) {
|
if (secroots != NULL) {
|
||||||
if (fp != NULL)
|
|
||||||
(void)putstr(text, "\n");
|
|
||||||
else
|
|
||||||
(void)putnull(text);
|
|
||||||
}
|
|
||||||
if (secroots != NULL)
|
|
||||||
dns_keytable_detach(&secroots);
|
dns_keytable_detach(&secroots);
|
||||||
if (ntatable != NULL)
|
}
|
||||||
|
if (ntatable != NULL) {
|
||||||
dns_ntatable_detach(&ntatable);
|
dns_ntatable_detach(&ntatable);
|
||||||
|
}
|
||||||
|
|
||||||
if (fp != NULL) {
|
if (fp != NULL) {
|
||||||
|
if (used != isc_buffer_usedlength(*text)) {
|
||||||
|
(void)putstr(text, "\n");
|
||||||
|
}
|
||||||
fprintf(fp, "%.*s", (int) isc_buffer_usedlength(*text),
|
fprintf(fp, "%.*s", (int) isc_buffer_usedlength(*text),
|
||||||
(char *) isc_buffer_base(*text));
|
(char *) isc_buffer_base(*text));
|
||||||
isc_buffer_clear(*text);
|
isc_buffer_clear(*text);
|
||||||
(void)isc_stdio_close(fp);
|
(void)isc_stdio_close(fp);
|
||||||
|
} else if (isc_buffer_usedlength(*text) > 0) {
|
||||||
|
(void)putnull(text);
|
||||||
}
|
}
|
||||||
if (result == ISC_R_SUCCESS)
|
|
||||||
|
if (result == ISC_R_SUCCESS) {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||||
"dumpsecroots complete");
|
"dumpsecroots complete");
|
||||||
else
|
} else {
|
||||||
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
isc_log_write(named_g_lctx, NAMED_LOGCATEGORY_GENERAL,
|
||||||
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
NAMED_LOGMODULE_SERVER, ISC_LOG_ERROR,
|
||||||
"dumpsecroots failed: %s",
|
"dumpsecroots failed: %s",
|
||||||
dns_result_totext(result));
|
dns_result_totext(result));
|
||||||
|
}
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -12281,17 +12390,7 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
|||||||
/* We're creating or overwriting the zone */
|
/* We're creating or overwriting the zone */
|
||||||
const cfg_obj_t *zoptions;
|
const cfg_obj_t *zoptions;
|
||||||
|
|
||||||
result = isc_buffer_allocate(view->mctx, &text, 256);
|
isc_buffer_allocate(view->mctx, &text, 256);
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
isc_log_write(named_g_lctx,
|
|
||||||
NAMED_LOGCATEGORY_GENERAL,
|
|
||||||
NAMED_LOGMODULE_SERVER,
|
|
||||||
ISC_LOG_ERROR,
|
|
||||||
"Unable to allocate buffer in "
|
|
||||||
"nzd_save(): %s",
|
|
||||||
isc_result_totext(result));
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
|
|
||||||
zoptions = cfg_tuple_get(zconfig, "options");
|
zoptions = cfg_tuple_get(zconfig, "options");
|
||||||
if (zoptions == NULL) {
|
if (zoptions == NULL) {
|
||||||
@@ -12316,7 +12415,7 @@ nzd_save(MDB_txn **txnp, MDB_dbi dbi, dns_zone_t *zone,
|
|||||||
ISC_LOG_ERROR,
|
ISC_LOG_ERROR,
|
||||||
"Error writing zone config to "
|
"Error writing zone config to "
|
||||||
"buffer in nzd_save(): %s",
|
"buffer in nzd_save(): %s",
|
||||||
isc_result_totext(result));
|
isc_result_totext(dzarg.result));
|
||||||
result = dzarg.result;
|
result = dzarg.result;
|
||||||
goto cleanup;
|
goto cleanup;
|
||||||
}
|
}
|
||||||
@@ -12648,7 +12747,7 @@ migrate_nzf(dns_view_t *view) {
|
|||||||
|
|
||||||
CHECK(nzd_open(view, 0, &txn, &dbi));
|
CHECK(nzd_open(view, 0, &txn, &dbi));
|
||||||
|
|
||||||
CHECK(isc_buffer_allocate(view->mctx, &text, 256));
|
isc_buffer_allocate(view->mctx, &text, 256);
|
||||||
|
|
||||||
for (element = cfg_list_first(zonelist);
|
for (element = cfg_list_first(zonelist);
|
||||||
element != NULL;
|
element != NULL;
|
||||||
@@ -13734,10 +13833,6 @@ named_server_delzone(named_server_t *server, isc_lex_t *lex,
|
|||||||
dns_zone_detach(&raw);
|
dns_zone_detach(&raw);
|
||||||
if (zone != NULL)
|
if (zone != NULL)
|
||||||
dns_zone_detach(&zone);
|
dns_zone_detach(&zone);
|
||||||
if (dz != NULL) {
|
|
||||||
dns_zone_detach(&dz->zone);
|
|
||||||
isc_mem_put(named_g_mctx, dz, sizeof(*dz));
|
|
||||||
}
|
|
||||||
|
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
@@ -15264,8 +15359,8 @@ named_server_tcptimeouts(isc_lex_t *lex, isc_buffer_t **text) {
|
|||||||
if (ptr == NULL)
|
if (ptr == NULL)
|
||||||
return (ISC_R_UNEXPECTEDEND);
|
return (ISC_R_UNEXPECTEDEND);
|
||||||
|
|
||||||
ns_server_gettimeouts(named_g_server->sctx,
|
isc_nm_tcp_gettimeouts(named_g_nm, &initial, &idle,
|
||||||
&initial, &idle, &keepalive, &advertised);
|
&keepalive, &advertised);
|
||||||
|
|
||||||
/* Look for optional arguments. */
|
/* Look for optional arguments. */
|
||||||
ptr = next_token(lex, NULL);
|
ptr = next_token(lex, NULL);
|
||||||
@@ -15304,7 +15399,7 @@ named_server_tcptimeouts(isc_lex_t *lex, isc_buffer_t **text) {
|
|||||||
result = isc_task_beginexclusive(named_g_server->task);
|
result = isc_task_beginexclusive(named_g_server->task);
|
||||||
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
||||||
|
|
||||||
ns_server_settimeouts(named_g_server->sctx, initial, idle,
|
isc_nm_tcp_settimeouts(named_g_nm, initial, idle,
|
||||||
keepalive, advertised);
|
keepalive, advertised);
|
||||||
|
|
||||||
isc_task_endexclusive(named_g_server->task);
|
isc_task_endexclusive(named_g_server->task);
|
||||||
|
|||||||
@@ -324,6 +324,9 @@ init_desc(void) {
|
|||||||
"QryUsedStale");
|
"QryUsedStale");
|
||||||
SET_NSSTATDESC(prefetch, "queries triggered prefetch", "Prefetch");
|
SET_NSSTATDESC(prefetch, "queries triggered prefetch", "Prefetch");
|
||||||
SET_NSSTATDESC(keytagopt, "Keytag option received", "KeyTagOpt");
|
SET_NSSTATDESC(keytagopt, "Keytag option received", "KeyTagOpt");
|
||||||
|
SET_NSSTATDESC(reclimitdropped,
|
||||||
|
"queries dropped due to recursive client limit",
|
||||||
|
"RecLimitDropped");
|
||||||
|
|
||||||
INSIST(i == ns_statscounter_max);
|
INSIST(i == ns_statscounter_max);
|
||||||
|
|
||||||
@@ -3590,10 +3593,6 @@ named_statschannels_configure(named_server_t *server, const cfg_obj_t *config,
|
|||||||
|
|
||||||
ISC_LIST_INIT(new_listeners);
|
ISC_LIST_INIT(new_listeners);
|
||||||
|
|
||||||
#ifdef HAVE_LIBXML2
|
|
||||||
xmlInitThreads();
|
|
||||||
#endif /* HAVE_LIBXML2 */
|
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Get the list of named.conf 'statistics-channels' statements.
|
* Get the list of named.conf 'statistics-channels' statements.
|
||||||
*/
|
*/
|
||||||
@@ -3726,10 +3725,6 @@ named_statschannels_shutdown(named_server_t *server) {
|
|||||||
ISC_LIST_UNLINK(server->statschannels, listener, link);
|
ISC_LIST_UNLINK(server->statschannels, listener, link);
|
||||||
shutdown_listener(listener);
|
shutdown_listener(listener);
|
||||||
}
|
}
|
||||||
|
|
||||||
#ifdef HAVE_LIBXML2
|
|
||||||
xmlCleanupThreads();
|
|
||||||
#endif /* HAVE_LIBXML2 */
|
|
||||||
}
|
}
|
||||||
|
|
||||||
isc_result_t
|
isc_result_t
|
||||||
|
|||||||
@@ -85,7 +85,7 @@ named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
|||||||
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
RETERR(dns_name_fromtext(name, &b, dns_rootname, 0, NULL));
|
||||||
tctx->domain = isc_mem_get(mctx, sizeof(dns_name_t));
|
tctx->domain = isc_mem_get(mctx, sizeof(dns_name_t));
|
||||||
dns_name_init(tctx->domain, NULL);
|
dns_name_init(tctx->domain, NULL);
|
||||||
RETERR(dns_name_dup(name, mctx, tctx->domain));
|
dns_name_dup(name, mctx, tctx->domain);
|
||||||
}
|
}
|
||||||
|
|
||||||
obj = NULL;
|
obj = NULL;
|
||||||
@@ -114,4 +114,3 @@ named_tkeyctx_fromconfig(const cfg_obj_t *options, isc_mem_t *mctx,
|
|||||||
dns_tkeyctx_destroy(&tctx);
|
dns_tkeyctx_destroy(&tctx);
|
||||||
return (result);
|
return (result);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2000-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2000-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -519,5 +519,5 @@ The TSIG key is redundantly stored in two separate files\&. This is a consequenc
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2000-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2000-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
+4
-11
@@ -1238,8 +1238,7 @@ parse_name(char **cmdlinep, dns_message_t *msg, dns_name_t **namep) {
|
|||||||
|
|
||||||
result = dns_message_gettempname(msg, namep);
|
result = dns_message_gettempname(msg, namep);
|
||||||
check_result(result, "dns_message_gettempname");
|
check_result(result, "dns_message_gettempname");
|
||||||
result = isc_buffer_allocate(gmctx, &namebuf, DNS_NAME_MAXWIRE);
|
isc_buffer_allocate(gmctx, &namebuf, DNS_NAME_MAXWIRE);
|
||||||
check_result(result, "isc_buffer_allocate");
|
|
||||||
dns_name_init(*namep, NULL);
|
dns_name_init(*namep, NULL);
|
||||||
dns_name_setbuffer(*namep, namebuf);
|
dns_name_setbuffer(*namep, namebuf);
|
||||||
dns_message_takebuffer(msg, &namebuf);
|
dns_message_takebuffer(msg, &namebuf);
|
||||||
@@ -1284,16 +1283,14 @@ parse_rdata(char **cmdlinep, dns_rdataclass_t rdataclass,
|
|||||||
isc_buffer_add(&source, strlen(cmdline));
|
isc_buffer_add(&source, strlen(cmdline));
|
||||||
result = isc_lex_openbuffer(lex, &source);
|
result = isc_lex_openbuffer(lex, &source);
|
||||||
check_result(result, "isc_lex_openbuffer");
|
check_result(result, "isc_lex_openbuffer");
|
||||||
result = isc_buffer_allocate(gmctx, &buf, MAXWIRE);
|
isc_buffer_allocate(gmctx, &buf, MAXWIRE);
|
||||||
check_result(result, "isc_buffer_allocate");
|
|
||||||
result = dns_rdata_fromtext(NULL, rdataclass, rdatatype, lex,
|
result = dns_rdata_fromtext(NULL, rdataclass, rdatatype, lex,
|
||||||
dns_rootname, 0, gmctx, buf,
|
dns_rootname, 0, gmctx, buf,
|
||||||
&callbacks);
|
&callbacks);
|
||||||
isc_lex_destroy(&lex);
|
isc_lex_destroy(&lex);
|
||||||
if (result == ISC_R_SUCCESS) {
|
if (result == ISC_R_SUCCESS) {
|
||||||
isc_buffer_usedregion(buf, &r);
|
isc_buffer_usedregion(buf, &r);
|
||||||
result = isc_buffer_allocate(gmctx, &newbuf, r.length);
|
isc_buffer_allocate(gmctx, &newbuf, r.length);
|
||||||
check_result(result, "isc_buffer_allocate");
|
|
||||||
isc_buffer_putmem(newbuf, r.base, r.length);
|
isc_buffer_putmem(newbuf, r.base, r.length);
|
||||||
isc_buffer_usedregion(newbuf, &r);
|
isc_buffer_usedregion(newbuf, &r);
|
||||||
dns_rdata_fromregion(rdata, rdataclass, rdatatype, &r);
|
dns_rdata_fromregion(rdata, rdataclass, rdatatype, &r);
|
||||||
@@ -2041,8 +2038,7 @@ show_message(FILE *stream, dns_message_t *msg, const char *description) {
|
|||||||
}
|
}
|
||||||
if (buf != NULL)
|
if (buf != NULL)
|
||||||
isc_buffer_free(&buf);
|
isc_buffer_free(&buf);
|
||||||
result = isc_buffer_allocate(gmctx, &buf, bufsz);
|
isc_buffer_allocate(gmctx, &buf, bufsz);
|
||||||
check_result(result, "isc_buffer_allocate");
|
|
||||||
result = dns_message_totext(msg, style, 0, buf);
|
result = dns_message_totext(msg, style, 0, buf);
|
||||||
bufsz *= 2;
|
bufsz *= 2;
|
||||||
} while (result == ISC_R_NOSPACE);
|
} while (result == ISC_R_NOSPACE);
|
||||||
@@ -3210,9 +3206,6 @@ cleanup(void) {
|
|||||||
ddebug("Shutting down timer manager");
|
ddebug("Shutting down timer manager");
|
||||||
isc_timermgr_destroy(&timermgr);
|
isc_timermgr_destroy(&timermgr);
|
||||||
|
|
||||||
ddebug("Destroying name state");
|
|
||||||
dns_name_destroy();
|
|
||||||
|
|
||||||
ddebug("Removing log context");
|
ddebug("Removing log context");
|
||||||
isc_log_destroy(&glctx);
|
isc_log_destroy(&glctx);
|
||||||
|
|
||||||
|
|||||||
@@ -50,6 +50,7 @@
|
|||||||
<year>2017</year>
|
<year>2017</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2000-2012, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2000-2012, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -93,5 +93,5 @@ Specify how long to pause before carrying out key destruction\&. The default is
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
@@ -124,7 +124,7 @@ main(int argc, char *argv[]) {
|
|||||||
if (errflg || (id && (label != NULL))) {
|
if (errflg || (id && (label != NULL))) {
|
||||||
fprintf(stderr, "Usage:\n");
|
fprintf(stderr, "Usage:\n");
|
||||||
fprintf(stderr, "\tpkcs11-destroy [-m module] [-s slot] "
|
fprintf(stderr, "\tpkcs11-destroy [-m module] [-s slot] "
|
||||||
"[-i id | -l label] [-p pin] [-w waittime]\n");
|
"{-i id | -l label} [-p pin] [-w waittime]\n");
|
||||||
exit(1);
|
exit(1);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -38,6 +38,7 @@
|
|||||||
<year>2016</year>
|
<year>2016</year>
|
||||||
<year>2018</year>
|
<year>2018</year>
|
||||||
<year>2019</year>
|
<year>2019</year>
|
||||||
|
<year>2020</year>
|
||||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||||
</copyright>
|
</copyright>
|
||||||
</docinfo>
|
</docinfo>
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
||||||
<!--
|
<!--
|
||||||
- Copyright (C) 2009, 2014-2016, 2018, 2019 Internet Systems Consortium, Inc. ("ISC")
|
- Copyright (C) 2009, 2014-2016, 2018-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
-
|
-
|
||||||
- This Source Code Form is subject to the terms of the Mozilla Public
|
- This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
- License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
.\" Copyright (C) 2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
.\" Copyright (C) 2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.\"
|
.\"
|
||||||
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
.\" This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
.\" License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
@@ -116,5 +116,5 @@ Open the session with the given PKCS#11 slot\&. The default is slot 0\&.
|
|||||||
\fBInternet Systems Consortium, Inc\&.\fR
|
\fBInternet Systems Consortium, Inc\&.\fR
|
||||||
.SH "COPYRIGHT"
|
.SH "COPYRIGHT"
|
||||||
.br
|
.br
|
||||||
Copyright \(co 2009, 2014-2019 Internet Systems Consortium, Inc. ("ISC")
|
Copyright \(co 2009, 2014-2020 Internet Systems Consortium, Inc. ("ISC")
|
||||||
.br
|
.br
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user