The dnssec-must-be-secure feature was added in the early days of BIND 9 and DNSSEC and it makes sense only as a debugging feature. There are no reasons to keep this feature in the production code anymore. Remove the feature to simplify the code.
85 lines
1.8 KiB
Plaintext
85 lines
1.8 KiB
Plaintext
; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
;
|
|
; SPDX-License-Identifier: MPL-2.0
|
|
;
|
|
; This Source Code Form is subject to the terms of the Mozilla Public
|
|
; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
;
|
|
; See the COPYRIGHT file distributed with this work for additional
|
|
; information regarding copyright ownership.
|
|
|
|
$TTL 300 ; 5 minutes
|
|
@ IN SOA mname1. . (
|
|
2000042407 ; serial
|
|
20 ; refresh (20 seconds)
|
|
20 ; retry (20 seconds)
|
|
1814400 ; expire (3 weeks)
|
|
3600 ; minimum (1 hour)
|
|
)
|
|
NS ns2
|
|
NS ns3
|
|
ns2 A 10.53.0.2
|
|
ns3 A 10.53.0.3
|
|
|
|
a A 10.0.0.1
|
|
b A 10.0.0.2
|
|
d A 10.0.0.4
|
|
|
|
; Used for testing ANY queries
|
|
foo TXT "testing"
|
|
foo A 10.0.1.0
|
|
|
|
; Used for testing CNAME queries
|
|
cname1 CNAME cname1-target
|
|
cname1-target TXT "testing cname"
|
|
|
|
cname2 CNAME cname2-target
|
|
cname2-target TXT "testing cname"
|
|
|
|
; Used for testing DNAME queries
|
|
dname1 DNAME dname1-target
|
|
foo.dname1-target TXT "testing dname"
|
|
|
|
dname2 DNAME dname2-target
|
|
foo.dname2-target TXT "testing dname"
|
|
|
|
; A secure subdomain
|
|
secure NS ns.secure
|
|
ns.secure A 10.53.0.3
|
|
|
|
; An insecure subdomain
|
|
insecure NS ns.insecure
|
|
ns.insecure A 10.53.0.3
|
|
|
|
z A 10.0.0.26
|
|
|
|
nsec3 NS ns.nsec3
|
|
ns.nsec3 A 10.53.0.3
|
|
|
|
optout NS ns.optout
|
|
ns.optout A 10.53.0.3
|
|
|
|
nsec3-unknown NS ns.nsec3-unknown
|
|
ns.nsec3-unknown A 10.53.0.3
|
|
|
|
optout-unknown NS ns.optout-unknown
|
|
ns.optout-unknown A 10.53.0.3
|
|
|
|
multiple NS ns.multiple
|
|
ns.multiple A 10.53.0.3
|
|
|
|
rsasha256 NS ns.rsasha256
|
|
ns.rsasha256 A 10.53.0.3
|
|
|
|
rsasha512 NS ns.rsasha512
|
|
ns.rsasha512 A 10.53.0.3
|
|
|
|
nsec3-to-nsec NS ns.nsec3-to-nsec
|
|
ns.nsec3-to-nsec A 10.53.0.3
|
|
|
|
oldsigs NS ns.oldsigs
|
|
ns.oldsigs A 10.53.0.3
|
|
|
|
dname-at-apex-nsec3 NS ns3
|