Extend the "chain" system test with AUTHORITY section checks for signed, secure delegations. This complements the checks for signed, insecure delegations added by commit82b7e6ccef. Extend the existing AUTHORITY section checks for signed, insecure delegations to ensure nonexistence of DS RRsets in such responses. Adjust comments accordingly. Ensure dig failures cause the "chain" system test to fail. (cherry picked from commita14efdf54c)
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
See COPYRIGHT in the source root or https://isc.org/copyright.html for terms.
ns1 is the root server.
ns2 and ns5 are both authoritative servers.
ans3 is a mock authoritative server that can return various broken
responses.
ans4 is a mock authoritative server that can return CNAME or DNAME
responses of arbitrary size in arbitrary order.
ns7 is the resolver under test.