Compare commits
46 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
78b703cc1f | ||
|
|
8b8b3e97d6 | ||
|
|
290a5eb9ab | ||
|
|
4e4f8c8518 | ||
|
|
00db7f45fd | ||
|
|
aca3c550fd | ||
|
|
a815d5ceb5 | ||
|
|
4378f987b4 | ||
|
|
ff25a45a41 | ||
|
|
b40bc8c8c4 | ||
|
|
cf62fe5503 | ||
|
|
ed5314b647 | ||
|
|
af22b4c836 | ||
|
|
30676f9c5f | ||
|
|
e0603a12ee | ||
|
|
cf411e66ff | ||
|
|
76eb755d81 | ||
|
|
aea6801444 | ||
|
|
d032099ab8 | ||
|
|
7729230caf | ||
|
|
6402a7906b | ||
|
|
efad4ae8c3 | ||
|
|
03bc58ac1c | ||
|
|
44a1ea8515 | ||
|
|
b51b7b6266 | ||
|
|
fd11bcc212 | ||
|
|
f6f181d9d5 | ||
|
|
3e06916fb7 | ||
|
|
9b172b6d29 | ||
|
|
65cf5aa6e0 | ||
|
|
c1ece0be9b | ||
|
|
36d37531c9 | ||
|
|
3a9a611c68 | ||
|
|
edb5faaa4f | ||
|
|
d9ce22f975 | ||
|
|
53d26d27a4 | ||
|
|
6a0d9a2e1d | ||
|
|
d494ea8a41 | ||
|
|
66c20407d2 | ||
|
|
2ac739ed73 | ||
|
|
5edcf115f4 | ||
|
|
3533e401fa | ||
|
|
899c629af5 | ||
|
|
e5a4a14d54 | ||
|
|
bb9dac4e90 | ||
|
|
cc43f811ad |
136 changed files with 15105 additions and 13859 deletions
|
|
@ -1 +0,0 @@
|
||||||
1
|
|
||||||
143
.gitignore
vendored
143
.gitignore
vendored
|
|
@ -92,149 +92,6 @@ bind-9.7.2b1.tar.gz
|
||||||
/bind-9.11.5-P4.tar.gz
|
/bind-9.11.5-P4.tar.gz
|
||||||
/bind-9.11.6.tar.gz
|
/bind-9.11.6.tar.gz
|
||||||
/bind-9.11.6-P1.tar.gz
|
/bind-9.11.6-P1.tar.gz
|
||||||
/bind-9.11.7.tar.gz
|
|
||||||
/bind-9.11.8.tar.gz
|
/bind-9.11.8.tar.gz
|
||||||
/bind-9.11.9.tar.gz
|
/bind-9.11.9.tar.gz
|
||||||
/bind-9.11.10.tar.gz
|
/bind-9.11.10.tar.gz
|
||||||
/bind-9.11.11.tar.gz
|
|
||||||
/bind-9.11.12.tar.gz
|
|
||||||
/bind-9.11.13.tar.gz
|
|
||||||
/bind-9.11.13.tar.gz.asc
|
|
||||||
/bind-9.11.14.tar.gz
|
|
||||||
/bind-9.11.14.tar.gz.asc
|
|
||||||
/bind-9.11.17.tar.gz
|
|
||||||
/bind-9.11.17.tar.gz.asc
|
|
||||||
/bind-9.11.18.tar.gz
|
|
||||||
/bind-9.11.18.tar.gz.asc
|
|
||||||
/bind-9.11.19.tar.gz
|
|
||||||
/bind-9.11.19.tar.gz.asc
|
|
||||||
/bind-9.11.20.tar.gz
|
|
||||||
/bind-9.11.20.tar.gz.asc
|
|
||||||
/bind-9.11.21.tar.gz
|
|
||||||
/bind-9.11.21.tar.gz.asc
|
|
||||||
/bind-9.11.22.tar.gz
|
|
||||||
/bind-9.11.22.tar.gz.asc
|
|
||||||
/bind-9.11.23.tar.gz
|
|
||||||
/bind-9.11.23.tar.gz.asc
|
|
||||||
/bind-9.11.24.tar.gz
|
|
||||||
/bind-9.11.24.tar.gz.asc
|
|
||||||
/bind-9.11.25.tar.gz
|
|
||||||
/bind-9.11.25.tar.gz.asc
|
|
||||||
/bind-9.11.26.tar.gz
|
|
||||||
/bind-9.11.26.tar.gz.asc
|
|
||||||
/bind-9.16.1.tar.xz
|
|
||||||
/bind-9.16.1.tar.xz.asc
|
|
||||||
/bind-9.16.2.tar.xz
|
|
||||||
/bind-9.16.2.tar.xz.asc
|
|
||||||
/bind-9.16.4.tar.xz
|
|
||||||
/bind-9.16.4.tar.xz.asc
|
|
||||||
/bind-9.16.5.tar.xz
|
|
||||||
/bind-9.16.5.tar.xz.asc
|
|
||||||
/bind-9.16.6.tar.xz
|
|
||||||
/bind-9.16.6.tar.xz.asc
|
|
||||||
/bind-9.16.7.tar.xz
|
|
||||||
/bind-9.16.7.tar.xz.asc
|
|
||||||
/bind-9.16.8.tar.xz
|
|
||||||
/bind-9.16.8.tar.xz.asc
|
|
||||||
/bind-9.16.9.tar.xz
|
|
||||||
/bind-9.16.9.tar.xz.asc
|
|
||||||
/bind-9.16.10.tar.xz
|
|
||||||
/bind-9.16.10.tar.xz.asc
|
|
||||||
/bind-9.16.11.tar.xz
|
|
||||||
/bind-9.16.11.tar.xz.asc
|
|
||||||
/bind-9.16.13.tar.xz
|
|
||||||
/bind-9.16.13.tar.xz.asc
|
|
||||||
/bind-9.16.15.tar.xz
|
|
||||||
/bind-9.16.15.tar.xz.asc
|
|
||||||
/bind-9.16.16.tar.xz
|
|
||||||
/bind-9.16.16.tar.xz.asc
|
|
||||||
/bind-9.16.17.tar.xz
|
|
||||||
/bind-9.16.17.tar.xz.asc
|
|
||||||
/bind-9.16.18.tar.xz
|
|
||||||
/bind-9.16.18.tar.xz.asc
|
|
||||||
/bind-9.16.19.tar.xz
|
|
||||||
/bind-9.16.19.tar.xz.asc
|
|
||||||
/bind-9.16.20.tar.xz
|
|
||||||
/bind-9.16.20.tar.xz.asc
|
|
||||||
/bind-9.16.21.tar.xz
|
|
||||||
/bind-9.16.21.tar.xz.asc
|
|
||||||
/bind-9.16.22.tar.xz
|
|
||||||
/bind-9.16.22.tar.xz.asc
|
|
||||||
/bind-9.16.23.tar.xz
|
|
||||||
/bind-9.16.23.tar.xz.asc
|
|
||||||
/bind-9.16.24.tar.xz
|
|
||||||
/bind-9.16.24.tar.xz.asc
|
|
||||||
/bind-9.16.25.tar.xz
|
|
||||||
/bind-9.16.25.tar.xz.asc
|
|
||||||
/bind-9.16.26.tar.xz
|
|
||||||
/bind-9.16.26.tar.xz.asc
|
|
||||||
/bind-9.16.27.tar.xz
|
|
||||||
/bind-9.16.27.tar.xz.asc
|
|
||||||
/bind-9.16.28.tar.xz
|
|
||||||
/bind-9.16.28.tar.xz.asc
|
|
||||||
/bind-9.16.29.tar.xz
|
|
||||||
/bind-9.16.29.tar.xz.asc
|
|
||||||
/bind-9.16.30.tar.xz
|
|
||||||
/bind-9.16.30.tar.xz.asc
|
|
||||||
/bind-9.18.0.tar.xz
|
|
||||||
/bind-9.18.0.tar.xz.asc
|
|
||||||
/bind-9.18.1.tar.xz
|
|
||||||
/bind-9.18.1.tar.xz.asc
|
|
||||||
/bind-9.18.2.tar.xz
|
|
||||||
/bind-9.18.2.tar.xz.asc
|
|
||||||
/bind-9.18.3.tar.xz
|
|
||||||
/bind-9.18.3.tar.xz.asc
|
|
||||||
/bind-9.18.4.tar.xz
|
|
||||||
/bind-9.18.4.tar.xz.asc
|
|
||||||
/bind-9.18.5.tar.xz
|
|
||||||
/bind-9.18.5.tar.xz.asc
|
|
||||||
/bind-9.18.6.tar.xz
|
|
||||||
/bind-9.18.6.tar.xz.asc
|
|
||||||
/bind-9.18.7.tar.xz
|
|
||||||
/bind-9.18.7.tar.xz.asc
|
|
||||||
/bind-9.18.8.tar.xz
|
|
||||||
/bind-9.18.8.tar.xz.asc
|
|
||||||
/bind-9.18.9.tar.xz
|
|
||||||
/bind-9.18.9.tar.xz.asc
|
|
||||||
/bind-9.18.10.tar.xz
|
|
||||||
/bind-9.18.10.tar.xz.asc
|
|
||||||
/bind-9.18.11.tar.xz
|
|
||||||
/bind-9.18.11.tar.xz.asc
|
|
||||||
/bind-9.18.12.tar.xz
|
|
||||||
/bind-9.18.12.tar.xz.asc
|
|
||||||
/bind-9.18.13.tar.xz
|
|
||||||
/bind-9.18.13.tar.xz.asc
|
|
||||||
/bind-9.18.14.tar.xz
|
|
||||||
/bind-9.18.14.tar.xz.asc
|
|
||||||
/bind-9.18.15.tar.xz
|
|
||||||
/bind-9.18.15.tar.xz.asc
|
|
||||||
/bind-9.18.16.tar.xz
|
|
||||||
/bind-9.18.16.tar.xz.asc
|
|
||||||
/bind-9.18.17.tar.xz
|
|
||||||
/bind-9.18.17.tar.xz.asc
|
|
||||||
/bind-9.18.18.tar.xz
|
|
||||||
/bind-9.18.18.tar.xz.asc
|
|
||||||
/bind-9.18.19.tar.xz
|
|
||||||
/bind-9.18.19.tar.xz.asc
|
|
||||||
/bind-9.18.20.tar.xz
|
|
||||||
/bind-9.18.20.tar.xz.asc
|
|
||||||
/bind-9.18.21.tar.xz
|
|
||||||
/bind-9.18.21.tar.xz.asc
|
|
||||||
/bind-9.18.24.tar.xz
|
|
||||||
/bind-9.18.24.tar.xz.asc
|
|
||||||
/bind-9.18.26.tar.xz
|
|
||||||
/bind-9.18.26.tar.xz.asc
|
|
||||||
/bind-9.18.28.tar.xz
|
|
||||||
/bind-9.18.28.tar.xz.asc
|
|
||||||
/bind-9.18.29.tar.xz
|
|
||||||
/bind-9.18.29.tar.xz.asc
|
|
||||||
/bind-9.18.30.tar.xz
|
|
||||||
/bind-9.18.30.tar.xz.asc
|
|
||||||
/bind-9.18.31.tar.xz
|
|
||||||
/bind-9.18.31.tar.xz.asc
|
|
||||||
/bind-9.18.32.tar.xz
|
|
||||||
/bind-9.18.32.tar.xz.asc
|
|
||||||
/bind-9.18.33.tar.xz
|
|
||||||
/bind-9.18.33.tar.xz.asc
|
|
||||||
/bind-9.18.*.tar.xz
|
|
||||||
/bind-9.18.*.tar.xz.asc
|
|
||||||
|
|
|
||||||
|
|
@ -1,61 +0,0 @@
|
||||||
From 31bd3a0996a85c0fced0c6ace3da1241b30dc397 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Thu, 30 Apr 2026 17:28:40 +0200
|
|
||||||
Subject: [PATCH] Use variable PROGRAM_SUFFIX in install target
|
|
||||||
|
|
||||||
--program-suffix is handled by configure itself. But some makefile rules
|
|
||||||
need to know it by a special value. Provide that to make multiple
|
|
||||||
versions installable together on a single system.
|
|
||||||
---
|
|
||||||
Makefile.top | 1 +
|
|
||||||
bin/check/Makefile.am | 6 +++---
|
|
||||||
bin/confgen/Makefile.am | 6 +++---
|
|
||||||
3 files changed, 7 insertions(+), 6 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/Makefile.top b/Makefile.top
|
|
||||||
index e186d15..91c076b 100644
|
|
||||||
--- a/Makefile.top
|
|
||||||
+++ b/Makefile.top
|
|
||||||
@@ -14,6 +14,7 @@ AM_CPPFLAGS = \
|
|
||||||
AM_LDFLAGS = \
|
|
||||||
$(STD_LDFLAGS)
|
|
||||||
LDADD =
|
|
||||||
+PROGRAM_SUFFIX =
|
|
||||||
|
|
||||||
if HOST_MACOS
|
|
||||||
AM_LDFLAGS += \
|
|
||||||
diff --git a/bin/check/Makefile.am b/bin/check/Makefile.am
|
|
||||||
index 8f63c35..36f232c 100644
|
|
||||||
--- a/bin/check/Makefile.am
|
|
||||||
+++ b/bin/check/Makefile.am
|
|
||||||
@@ -27,8 +27,8 @@ LDADD += \
|
|
||||||
bin_PROGRAMS = named-checkconf named-checkzone
|
|
||||||
|
|
||||||
install-exec-hook:
|
|
||||||
- ln -f $(DESTDIR)$(bindir)/named-checkzone \
|
|
||||||
- $(DESTDIR)$(bindir)/named-compilezone
|
|
||||||
+ ln -f $(DESTDIR)$(bindir)/named-checkzone$(PROGRAM_SUFFIX) \
|
|
||||||
+ $(DESTDIR)$(bindir)/named-compilezone$(PROGRAM_SUFFIX)
|
|
||||||
|
|
||||||
uninstall-hook:
|
|
||||||
- -rm -f $(DESTDIR)$(bindir)/named-compilezone
|
|
||||||
+ -rm -f $(DESTDIR)$(bindir)/named-compilezone$(PROGRAM_SUFFIX)
|
|
||||||
diff --git a/bin/confgen/Makefile.am b/bin/confgen/Makefile.am
|
|
||||||
index c1dca43..fe86dd7 100644
|
|
||||||
--- a/bin/confgen/Makefile.am
|
|
||||||
+++ b/bin/confgen/Makefile.am
|
|
||||||
@@ -23,8 +23,8 @@ libconfgen_la_SOURCES = \
|
|
||||||
sbin_PROGRAMS = tsig-keygen rndc-confgen
|
|
||||||
|
|
||||||
install-exec-hook:
|
|
||||||
- ln -f $(DESTDIR)$(sbindir)/tsig-keygen \
|
|
||||||
- $(DESTDIR)$(sbindir)/ddns-confgen
|
|
||||||
+ ln -f $(DESTDIR)$(sbindir)/tsig-keygen$(PROGRAM_SUFFIX) \
|
|
||||||
+ $(DESTDIR)$(sbindir)/ddns-confgen$(PROGRAM_SUFFIX)
|
|
||||||
|
|
||||||
uninstall-hook:
|
|
||||||
- -rm -f $(DESTDIR)$(sbindir)/ddns-confgen
|
|
||||||
+ -rm -f $(DESTDIR)$(sbindir)/ddns-confgen$(PROGRAM_SUFFIX)
|
|
||||||
--
|
|
||||||
2.54.0
|
|
||||||
|
|
||||||
43
Changes.md
43
Changes.md
|
|
@ -1,43 +0,0 @@
|
||||||
# Significant Changes in BIND9 package
|
|
||||||
|
|
||||||
## BIND 9.16
|
|
||||||
|
|
||||||
### New features
|
|
||||||
|
|
||||||
- *libuv* is used for network subsystem as a mandatory dependency
|
|
||||||
- *dnssec-policy* support in named.conf is introduced, providing a a key and signing policy
|
|
||||||
([KASP](https://gitlab.isc.org/isc-projects/bind9/-/wikis/DNSSEC-Key-and-Signing-Policy-(KASP)))
|
|
||||||
- *trusted-keys* and *managed-keys* are deprecated, replaced by *trust-anchors*
|
|
||||||
- *trust-anchors* support also anchor in a *DS* format, in addition to *DNSKEY* format
|
|
||||||
- **dig, mdig** and **delv** support **+yaml** parameter to print detailed machine parseable output
|
|
||||||
|
|
||||||
### Feature changes
|
|
||||||
|
|
||||||
- Static trust anchor and *dnssec-validation auto;* are incompatible and cause fatal error, when used together.
|
|
||||||
- *DS* and *CDS* now generates only SHA-256 digest, SHA-1 is no longer generated by default
|
|
||||||
- SipHash 2-4 DNS Cookie ([RFC 7873](https://www.rfc-editor.org/rfc/rfc7873.html) is now default).
|
|
||||||
Only AES alternative algorithm is kept, HMAC-SHA cookie support were removed.
|
|
||||||
- **dnssec-signzone** and **dnssec-verify** commands print output to stdout, *-q* parameter can silence them
|
|
||||||
|
|
||||||
### Features removed
|
|
||||||
|
|
||||||
- *dnssec-enable* option is obsolete, DNSSEC support is always enabled
|
|
||||||
- *dnssec-lookaside* option is deprecated and support for it removed from all tools
|
|
||||||
- *cleaning-interval* option is removed
|
|
||||||
|
|
||||||
### Upstream release notes
|
|
||||||
|
|
||||||
- [9.16.10 notes](https://downloads.isc.org/isc/bind9/9.16.10/doc/arm/html/notes.html#notes-for-bind-9-16-10)
|
|
||||||
- [9.16.0 notes](https://downloads.isc.org/isc/bind9/9.16.0/doc/arm/html/notes.html#notes-for-bind-9-16-0)
|
|
||||||
|
|
||||||
## BIND 9.14
|
|
||||||
|
|
||||||
- single thread support removed. Cannot provide *bind-export-libs* for DHCP
|
|
||||||
- *lwres* support completely removed. Both daemon and library
|
|
||||||
- common parts of daemon moved into *libns* shared library
|
|
||||||
- introduced plugin for filtering aaaa responses
|
|
||||||
- some SDB utilities no longer supported
|
|
||||||
|
|
||||||
### Upstream release notes
|
|
||||||
|
|
||||||
- [9.14.7 notes](https://downloads.isc.org/isc/bind9/9.14.7/RELEASE-NOTES-bind-9.14.7.html)
|
|
||||||
14
README.md
14
README.md
|
|
@ -14,13 +14,6 @@ More details about upstream project can be found on their
|
||||||
only upstream sources and packaging instructions for
|
only upstream sources and packaging instructions for
|
||||||
[Fedora Project](https://fedoraproject.org).
|
[Fedora Project](https://fedoraproject.org).
|
||||||
|
|
||||||
Any rebase requires to be built together with
|
|
||||||
[bind-dyndb-ldap](https://src.fedoraproject.org/rpms/bind-dyndb-ldap/) to prevent conflict
|
|
||||||
at installation of [freeipa-server-dns](https://src.fedoraproject.org/rpms/freeipa).
|
|
||||||
Stable bodhi updates are checked, but rawhide are not checked explicitly.
|
|
||||||
Symbol of libraries in *bind-libs* changes with every minor version change of bind,
|
|
||||||
therefore they break any package dependent on bind-libs.
|
|
||||||
|
|
||||||
## Subpackages
|
## Subpackages
|
||||||
|
|
||||||
The package contains several subpackages, some of them can be disabled on rebuild.
|
The package contains several subpackages, some of them can be disabled on rebuild.
|
||||||
|
|
@ -28,7 +21,11 @@ The package contains several subpackages, some of them can be disabled on rebuil
|
||||||
* **bind** -- *named* daemon providing DNS server
|
* **bind** -- *named* daemon providing DNS server
|
||||||
* **bind-utils** -- set of tools to analyse DNS responses or update entries (dig, host)
|
* **bind-utils** -- set of tools to analyse DNS responses or update entries (dig, host)
|
||||||
* **bind-doc** -- documentation for current bind, *BIND 9 Administrator Reference Manual*.
|
* **bind-doc** -- documentation for current bind, *BIND 9 Administrator Reference Manual*.
|
||||||
* **bind-libs** -- Shared libraries used by some others programs
|
* **bind-license** -- Shared license for all packages but bind-export-libs.
|
||||||
|
* **bind-sdb** -- *named* daemon built with support for [Dynamically Loadable Zones](http://bind-dlz.sourceforge.net/), interface to serve DNS names from external databases like LDAP or SQL. Can be disabled by `--without SDB`.
|
||||||
|
* **bind-pkcs11** -- *named* daemon built with native PKCS#11 support. Can be disabled by `--without PKCS11`.
|
||||||
|
* **bind-libs** and **bind-libs-lite** -- Shared libraries used by some others programs
|
||||||
|
* **bind-export-libs** -- Special subset of libraries without support for threads. Used by *dhcp* package. Can be disabled by `--without EXPORT_LIBS`
|
||||||
* **bind-devel** -- Development headers for libs. Can be disabled by `--without DEVEL`
|
* **bind-devel** -- Development headers for libs. Can be disabled by `--without DEVEL`
|
||||||
|
|
||||||
|
|
||||||
|
|
@ -36,3 +33,4 @@ The package contains several subpackages, some of them can be disabled on rebuil
|
||||||
|
|
||||||
* *GSSTSIG* -- Support for Kerberos authentication in BIND.
|
* *GSSTSIG* -- Support for Kerberos authentication in BIND.
|
||||||
* *LMDB* -- Support for dynamic database for managing runtime added zones. Provides faster removal of added zone with much less overhead. But requires lmdb linked to base libs.
|
* *LMDB* -- Support for dynamic database for managing runtime added zones. Provides faster removal of added zone with much less overhead. But requires lmdb linked to base libs.
|
||||||
|
* *DLZ* -- Support for dynamic loaded modules providing support for features *bind-sdb* provides, but only small module is required.
|
||||||
|
|
|
||||||
79
README.sdb_pgsql
Normal file
79
README.sdb_pgsql
Normal file
|
|
@ -0,0 +1,79 @@
|
||||||
|
PGSQL BIND SDB driver
|
||||||
|
|
||||||
|
The postgresql BIND SDB driver is of experimental status and should not be
|
||||||
|
used for production systems.
|
||||||
|
|
||||||
|
Usage:
|
||||||
|
|
||||||
|
o Use the named_sdb process ( put ENABLE_SDB=yes in /etc/sysconfig/named )
|
||||||
|
|
||||||
|
o Edit your named.conf to contain a database zone, eg. :
|
||||||
|
|
||||||
|
zone "pgdb.net." IN {
|
||||||
|
type master;
|
||||||
|
database "pgsql bind pgdb localhost pguser pgpasswd";
|
||||||
|
# ^- DB name ^-Table ^-host ^-user ^-password
|
||||||
|
};
|
||||||
|
|
||||||
|
o Create the database zone table
|
||||||
|
The table must contain the columns "name", "rdtype", and "rdata", and
|
||||||
|
is expected to contain a properly constructed zone. The program "zonetodb"
|
||||||
|
creates such a table.
|
||||||
|
|
||||||
|
zonetodb usage:
|
||||||
|
|
||||||
|
zonetodb origin file dbname dbtable
|
||||||
|
|
||||||
|
where
|
||||||
|
origin : zone origin, eg "pgdb.net."
|
||||||
|
file : master zone database file, eg. pgdb.net.db
|
||||||
|
dbname : name of postgresql database
|
||||||
|
dbtable: name of table in database
|
||||||
|
|
||||||
|
Eg. to import this zone in the file 'pgdb.net.db' into the 'bind' database
|
||||||
|
'pgdb' table:
|
||||||
|
|
||||||
|
---
|
||||||
|
#pgdb.net.db:
|
||||||
|
$TTL 1H
|
||||||
|
@ SOA localhost. root.localhost. ( 1
|
||||||
|
3H
|
||||||
|
1H
|
||||||
|
1W
|
||||||
|
1H )
|
||||||
|
NS localhost.
|
||||||
|
host1 A 192.168.2.1
|
||||||
|
host2 A 192.168.2.2
|
||||||
|
host3 A 192.168.2.3
|
||||||
|
host4 A 192.168.2.4
|
||||||
|
host5 A 192.168.2.5
|
||||||
|
host6 A 192.168.2.6
|
||||||
|
host7 A 192.168.2.7
|
||||||
|
---
|
||||||
|
|
||||||
|
Issue this command as the pgsql user authorized to update the bind database:
|
||||||
|
|
||||||
|
# zonetodb pgdb.net. pgdb.net.db bind pgdb
|
||||||
|
|
||||||
|
will create / update the pgdb table in the 'bind' db:
|
||||||
|
|
||||||
|
$ psql -dbind -c 'select * from pgdb;'
|
||||||
|
name | ttl | rdtype | rdata
|
||||||
|
----------------+------+--------+-----------------------------------------------------
|
||||||
|
pgdb.net | 3600 | SOA | localhost. root.localhost. 1 10800 3600 604800 3600
|
||||||
|
pgdb.net | 3600 | NS | localhost.
|
||||||
|
host1.pgdb.net | 3600 | A | 192.168.2.1
|
||||||
|
host2.pgdb.net | 3600 | A | 192.168.2.2
|
||||||
|
host3.pgdb.net | 3600 | A | 192.168.2.3
|
||||||
|
host4.pgdb.net | 3600 | A | 192.168.2.4
|
||||||
|
host5.pgdb.net | 3600 | A | 192.168.2.5
|
||||||
|
host6.pgdb.net | 3600 | A | 192.168.2.6
|
||||||
|
host7.pgdb.net | 3600 | A | 192.168.2.7
|
||||||
|
(9 rows)
|
||||||
|
|
||||||
|
I've tested exactly the above configuration with bind-sdb-9.3.1+ and it works OK.
|
||||||
|
|
||||||
|
NOTE: If you use pgsqldb SDB, ensure the postgresql service is started before the named
|
||||||
|
service .
|
||||||
|
|
||||||
|
USE AT YOUR OWN RISK!
|
||||||
620
bind-9.10-dist-native-pkcs11.patch
Normal file
620
bind-9.10-dist-native-pkcs11.patch
Normal file
|
|
@ -0,0 +1,620 @@
|
||||||
|
diff --git a/bin/Makefile.in b/bin/Makefile.in
|
||||||
|
index f0c504a..ce7a2da 100644
|
||||||
|
--- a/bin/Makefile.in
|
||||||
|
+++ b/bin/Makefile.in
|
||||||
|
@@ -11,8 +11,8 @@ srcdir = @srcdir@
|
||||||
|
VPATH = @srcdir@
|
||||||
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
|
-SUBDIRS = named rndc dig delv dnssec tools nsupdate check confgen \
|
||||||
|
- @NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@ tests
|
||||||
|
+SUBDIRS = named named-pkcs11 rndc dig delv dnssec dnssec-pkcs11 tools nsupdate \
|
||||||
|
+ check confgen @NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@ tests
|
||||||
|
TARGETS =
|
||||||
|
|
||||||
|
@BIND9_MAKE_RULES@
|
||||||
|
diff --git a/bin/dnssec-pkcs11/Makefile.in b/bin/dnssec-pkcs11/Makefile.in
|
||||||
|
index 4b8ca13..32f4470 100644
|
||||||
|
--- a/bin/dnssec-pkcs11/Makefile.in
|
||||||
|
+++ b/bin/dnssec-pkcs11/Makefile.in
|
||||||
|
@@ -15,18 +15,18 @@ VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
|
-CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} @DST_OPENSSL_INC@
|
||||||
|
+CINCLUDES = ${DNS_PKCS11_INCLUDES} ${ISC_PKCS11_INCLUDES}
|
||||||
|
|
||||||
|
-CDEFINES = -DVERSION=\"${VERSION}\" @USE_PKCS11@ @PKCS11_ENGINE@ \
|
||||||
|
- @CRYPTO@ -DPK11_LIB_LOCATION=\"@PKCS11_PROVIDER@\"
|
||||||
|
+CDEFINES = -DVERSION=\"${VERSION}\" @PKCS11_ENGINE@ \
|
||||||
|
+ @CRYPTO_PK11@ -DPK11_LIB_LOCATION=\"@PKCS11_PROVIDER@\"
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
-DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
|
-ISCLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
-ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@
|
||||||
|
+DNSLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
|
+ISCLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
||||||
|
+ISCNOSYMLIBS = ../../lib/isc-pkcs11/libisc-pkcs11-nosymtbl.@A@
|
||||||
|
|
||||||
|
-DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||||
|
-ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
+DNSDEPLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@
|
||||||
|
+ISCDEPLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
||||||
|
|
||||||
|
DEPLIBS = ${DNSDEPLIBS} ${ISCDEPLIBS}
|
||||||
|
|
||||||
|
@@ -35,10 +35,10 @@ LIBS = ${DNSLIBS} ${ISCLIBS} @LIBS@
|
||||||
|
NOSYMLIBS = ${DNSLIBS} ${ISCNOSYMLIBS} @LIBS@
|
||||||
|
|
||||||
|
# Alphabetically
|
||||||
|
-TARGETS = dnssec-keygen@EXEEXT@ dnssec-signzone@EXEEXT@ \
|
||||||
|
- dnssec-keyfromlabel@EXEEXT@ dnssec-dsfromkey@EXEEXT@ \
|
||||||
|
- dnssec-revoke@EXEEXT@ dnssec-settime@EXEEXT@ \
|
||||||
|
- dnssec-verify@EXEEXT@ dnssec-importkey@EXEEXT@
|
||||||
|
+TARGETS = dnssec-keygen-pkcs11@EXEEXT@ dnssec-signzone-pkcs11@EXEEXT@ \
|
||||||
|
+ dnssec-keyfromlabel-pkcs11@EXEEXT@ dnssec-dsfromkey-pkcs11@EXEEXT@ \
|
||||||
|
+ dnssec-revoke-pkcs11@EXEEXT@ dnssec-settime-pkcs11@EXEEXT@ \
|
||||||
|
+ dnssec-verify-pkcs11@EXEEXT@ dnssec-importkey-pkcs11@EXEEXT@
|
||||||
|
|
||||||
|
OBJS = dnssectool.@O@
|
||||||
|
|
||||||
|
@@ -59,15 +59,15 @@ MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||||
|
|
||||||
|
@BIND9_MAKE_RULES@
|
||||||
|
|
||||||
|
-dnssec-dsfromkey@EXEEXT@: dnssec-dsfromkey.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
+dnssec-dsfromkey-pkcs11@EXEEXT@: dnssec-dsfromkey.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
export BASEOBJS="dnssec-dsfromkey.@O@ ${OBJS}"; \
|
||||||
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
|
-dnssec-keyfromlabel@EXEEXT@: dnssec-keyfromlabel.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
+dnssec-keyfromlabel-pkcs11@EXEEXT@: dnssec-keyfromlabel.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
export BASEOBJS="dnssec-keyfromlabel.@O@ ${OBJS}"; \
|
||||||
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
|
-dnssec-keygen@EXEEXT@: dnssec-keygen.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
+dnssec-keygen-pkcs11@EXEEXT@: dnssec-keygen.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
export BASEOBJS="dnssec-keygen.@O@ ${OBJS}"; \
|
||||||
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
|
@@ -75,7 +75,7 @@ dnssec-signzone.@O@: dnssec-signzone.c
|
||||||
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -DVERSION=\"${VERSION}\" \
|
||||||
|
-c ${srcdir}/dnssec-signzone.c
|
||||||
|
|
||||||
|
-dnssec-signzone@EXEEXT@: dnssec-signzone.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
+dnssec-signzone-pkcs11@EXEEXT@: dnssec-signzone.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
export BASEOBJS="dnssec-signzone.@O@ ${OBJS}"; \
|
||||||
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
|
@@ -83,19 +83,19 @@ dnssec-verify.@O@: dnssec-verify.c
|
||||||
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -DVERSION=\"${VERSION}\" \
|
||||||
|
-c ${srcdir}/dnssec-verify.c
|
||||||
|
|
||||||
|
-dnssec-verify@EXEEXT@: dnssec-verify.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
+dnssec-verify-pkcs11@EXEEXT@: dnssec-verify.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
export BASEOBJS="dnssec-verify.@O@ ${OBJS}"; \
|
||||||
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
|
-dnssec-revoke@EXEEXT@: dnssec-revoke.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
+dnssec-revoke-pkcs11@EXEEXT@: dnssec-revoke.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||||
|
dnssec-revoke.@O@ ${OBJS} ${LIBS}
|
||||||
|
|
||||||
|
-dnssec-settime@EXEEXT@: dnssec-settime.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
+dnssec-settime-pkcs11@EXEEXT@: dnssec-settime.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||||
|
dnssec-settime.@O@ ${OBJS} ${LIBS}
|
||||||
|
|
||||||
|
-dnssec-importkey@EXEEXT@: dnssec-importkey.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
+dnssec-importkey-pkcs11@EXEEXT@: dnssec-importkey.@O@ ${OBJS} ${DEPLIBS}
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ \
|
||||||
|
dnssec-importkey.@O@ ${OBJS} ${LIBS}
|
||||||
|
|
||||||
|
@@ -106,16 +106,14 @@ docclean manclean maintainer-clean::
|
||||||
|
|
||||||
|
installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||||
|
- $(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
install-man8: ${MANPAGES}
|
||||||
|
${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
-install:: ${TARGETS} installdirs install-man8
|
||||||
|
+install:: ${TARGETS} installdirs
|
||||||
|
for t in ${TARGETS}; do ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} $$t ${DESTDIR}${sbindir} || exit 1; done
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
- for m in ${MANPAGES}; do rm -f ${DESTDIR}${mandir}/man8/$$m || exit 1; done
|
||||||
|
for t in ${TARGETS}; do ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/$$t || exit 1; done
|
||||||
|
|
||||||
|
clean distclean::
|
||||||
|
diff --git a/bin/dnssec/Makefile.in b/bin/dnssec/Makefile.in
|
||||||
|
index 4b8ca13..4175996 100644
|
||||||
|
--- a/bin/dnssec/Makefile.in
|
||||||
|
+++ b/bin/dnssec/Makefile.in
|
||||||
|
@@ -17,7 +17,7 @@ VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
|
CINCLUDES = ${DNS_INCLUDES} ${ISC_INCLUDES} @DST_OPENSSL_INC@
|
||||||
|
|
||||||
|
-CDEFINES = -DVERSION=\"${VERSION}\" @USE_PKCS11@ @PKCS11_ENGINE@ \
|
||||||
|
+CDEFINES = -DVERSION=\"${VERSION}\" \
|
||||||
|
@CRYPTO@ -DPK11_LIB_LOCATION=\"@PKCS11_PROVIDER@\"
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
diff --git a/bin/named-pkcs11/Makefile.in b/bin/named-pkcs11/Makefile.in
|
||||||
|
index df1f7ee..f397ab0 100644
|
||||||
|
--- a/bin/named-pkcs11/Makefile.in
|
||||||
|
+++ b/bin/named-pkcs11/Makefile.in
|
||||||
|
@@ -43,27 +43,28 @@ DLZDRIVER_INCLUDES = @DLZ_DRIVER_INCLUDES@
|
||||||
|
DLZDRIVER_LIBS = @DLZ_DRIVER_LIBS@
|
||||||
|
|
||||||
|
CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include -I. \
|
||||||
|
- ${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
||||||
|
- ${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_INCLUDES} \
|
||||||
|
+ ${LWRES_INCLUDES} ${DNS_PKCS11_INCLUDES} ${BIND9_INCLUDES} \
|
||||||
|
+ ${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_PKCS11_INCLUDES} \
|
||||||
|
${DLZDRIVER_INCLUDES} ${DBDRIVER_INCLUDES} ${MAXMINDDB_CFLAGS} \
|
||||||
|
@DST_OPENSSL_INC@
|
||||||
|
|
||||||
|
-CDEFINES = @CONTRIB_DLZ@ @USE_PKCS11@ @PKCS11_ENGINE@ @CRYPTO@
|
||||||
|
+CDEFINES = @USE_PKCS11@ @PKCS11_ENGINE@ @CRYPTO_PK11@
|
||||||
|
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
DNSLIBS = ../../lib/dns/libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
|
+DNSLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
ISCCCLIBS = ../../lib/isccc/libisccc.@A@
|
||||||
|
-ISCLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
-ISCNOSYMLIBS = ../../lib/isc/libisc-nosymtbl.@A@
|
||||||
|
+ISCLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
||||||
|
+ISCNOSYMLIBS = ../../lib/isc-pkcs11/libisc-pkcs11-nosymtbl.@A@
|
||||||
|
LWRESLIBS = ../../lib/lwres/liblwres.@A@
|
||||||
|
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
||||||
|
|
||||||
|
-DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||||
|
+DNSDEPLIBS = ../../lib/dns-pkcs11/libdns-pkcs11.@A@
|
||||||
|
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
ISCCCDEPLIBS = ../../lib/isccc/libisccc.@A@
|
||||||
|
-ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
+ISCDEPLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
||||||
|
LWRESDEPLIBS = ../../lib/lwres/liblwres.@A@
|
||||||
|
BIND9DEPLIBS = ../../lib/bind9/libbind9.@A@
|
||||||
|
|
||||||
|
@@ -72,15 +73,15 @@ DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
||||||
|
|
||||||
|
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} \
|
||||||
|
- ${DLZDRIVER_LIBS} ${DBDRIVER_LIBS} @LIBS@
|
||||||
|
+ @LIBS@
|
||||||
|
|
||||||
|
NOSYMLIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCNOSYMLIBS} \
|
||||||
|
- ${DLZDRIVER_LIBS} ${DBDRIVER_LIBS} @LIBS@
|
||||||
|
+ @LIBS@
|
||||||
|
|
||||||
|
SUBDIRS = unix
|
||||||
|
|
||||||
|
-TARGETS = named@EXEEXT@ lwresd@EXEEXT@ feature-test@EXEEXT@
|
||||||
|
+TARGETS = named-pkcs11@EXEEXT@ feature-test-pkcs11@EXEEXT@
|
||||||
|
|
||||||
|
GEOIPLINKOBJS = geoip.@O@
|
||||||
|
GEOIP2LINKOBJS = geoip.@O@
|
||||||
|
@@ -94,8 +95,7 @@ OBJS = builtin.@O@ client.@O@ config.@O@ control.@O@ \
|
||||||
|
tkeyconf.@O@ tsigconf.@O@ update.@O@ xfrout.@O@ \
|
||||||
|
zoneconf.@O@ \
|
||||||
|
lwaddr.@O@ lwresd.@O@ lwdclient.@O@ lwderror.@O@ lwdgabn.@O@ \
|
||||||
|
- lwdgnba.@O@ lwdgrbn.@O@ lwdnoop.@O@ lwsearch.@O@ \
|
||||||
|
- ${DLZDRIVER_OBJS} ${DBDRIVER_OBJS}
|
||||||
|
+ lwdgnba.@O@ lwdgrbn.@O@ lwdnoop.@O@ lwsearch.@O@
|
||||||
|
|
||||||
|
UOBJS = unix/os.@O@ unix/dlz_dlopen_driver.@O@
|
||||||
|
|
||||||
|
@@ -113,8 +113,7 @@ SRCS = builtin.c client.c config.c control.c \
|
||||||
|
tkeyconf.c tsigconf.c update.c xfrout.c \
|
||||||
|
zoneconf.c \
|
||||||
|
lwaddr.c lwresd.c lwdclient.c lwderror.c lwdgabn.c \
|
||||||
|
- lwdgnba.c lwdgrbn.c lwdnoop.c lwsearch.c \
|
||||||
|
- ${DLZDRIVER_SRCS} ${DBDRIVER_SRCS}
|
||||||
|
+ lwdgnba.c lwdgrbn.c lwdnoop.c lwsearch.c
|
||||||
|
|
||||||
|
MANPAGES = named.8 lwresd.8 named.conf.5
|
||||||
|
|
||||||
|
@@ -154,21 +153,21 @@ server.@O@: server.c
|
||||||
|
-DPRODUCT=\"${PRODUCT}\" \
|
||||||
|
-DVERSION=\"${VERSION}\" -c ${srcdir}/server.c
|
||||||
|
|
||||||
|
-named@EXEEXT@: ${OBJS} ${DEPLIBS}
|
||||||
|
+named-pkcs11@EXEEXT@: ${OBJS} ${DEPLIBS}
|
||||||
|
export MAKE_SYMTABLE="yes"; \
|
||||||
|
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
||||||
|
${FINALBUILDCMD}
|
||||||
|
|
||||||
|
-lwresd@EXEEXT@: named@EXEEXT@
|
||||||
|
+lwresd@EXEEXT@: named-pkcs11@EXEEXT@
|
||||||
|
rm -f lwresd@EXEEXT@
|
||||||
|
- @LN@ named@EXEEXT@ lwresd@EXEEXT@
|
||||||
|
+ @LN@ named-pkcs11@EXEEXT@ lwresd@EXEEXT@
|
||||||
|
|
||||||
|
# Bit of hack, do not produce intermediate .o object for featuretest
|
||||||
|
feature-test.@O@: ${top_srcdir}/bin/tests/system/feature-test.c
|
||||||
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||||
|
-c ${top_srcdir}/bin/tests/system/feature-test.c
|
||||||
|
|
||||||
|
-feature-test@EXEEXT@: feature-test.@O@
|
||||||
|
+feature-test-pkcs11@EXEEXT@: feature-test.@O@
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} \
|
||||||
|
-o $@ feature-test.@O@ ${ISCLIBS} ${LIBS}
|
||||||
|
|
||||||
|
@@ -201,16 +200,11 @@ install-man8: named.8 lwresd.8
|
||||||
|
|
||||||
|
install-man: install-man5 install-man8
|
||||||
|
|
||||||
|
-install:: named@EXEEXT@ lwresd@EXEEXT@ installdirs install-man
|
||||||
|
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
- (cd ${DESTDIR}${sbindir}; rm -f lwresd@EXEEXT@; @LN@ named@EXEEXT@ lwresd@EXEEXT@)
|
||||||
|
+install:: named-pkcs11@EXEEXT@ installdirs
|
||||||
|
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-pkcs11@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
- rm -f ${DESTDIR}${mandir}/man5/named.conf.5
|
||||||
|
- rm -f ${DESTDIR}${mandir}/man8/lwresd.8
|
||||||
|
- rm -f ${DESTDIR}${mandir}/man8/named.8
|
||||||
|
- rm -f ${DESTDIR}${sbindir}/lwresd@EXEEXT@
|
||||||
|
- ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named@EXEEXT@
|
||||||
|
+ ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named-pkcs11@EXEEXT@
|
||||||
|
|
||||||
|
@DLZ_DRIVER_RULES@
|
||||||
|
|
||||||
|
diff --git a/bin/named/Makefile.in b/bin/named/Makefile.in
|
||||||
|
index df1f7ee..9660965 100644
|
||||||
|
--- a/bin/named/Makefile.in
|
||||||
|
+++ b/bin/named/Makefile.in
|
||||||
|
@@ -48,7 +48,7 @@ CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include -I. \
|
||||||
|
${DLZDRIVER_INCLUDES} ${DBDRIVER_INCLUDES} ${MAXMINDDB_CFLAGS} \
|
||||||
|
@DST_OPENSSL_INC@
|
||||||
|
|
||||||
|
-CDEFINES = @CONTRIB_DLZ@ @USE_PKCS11@ @PKCS11_ENGINE@ @CRYPTO@
|
||||||
|
+CDEFINES = @CONTRIB_DLZ@ @CRYPTO@
|
||||||
|
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
diff --git a/bin/pkcs11/Makefile.in b/bin/pkcs11/Makefile.in
|
||||||
|
index a058c91..d4b689a 100644
|
||||||
|
--- a/bin/pkcs11/Makefile.in
|
||||||
|
+++ b/bin/pkcs11/Makefile.in
|
||||||
|
@@ -15,13 +15,13 @@ top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
|
-CINCLUDES = ${ISC_INCLUDES}
|
||||||
|
+CINCLUDES = ${ISC_PKCS11_INCLUDES}
|
||||||
|
|
||||||
|
CDEFINES =
|
||||||
|
|
||||||
|
-ISCLIBS = ../../lib/isc/libisc.@A@ @ISC_OPENSSL_LIBS@
|
||||||
|
+ISCLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@ @ISC_OPENSSL_LIBS@
|
||||||
|
|
||||||
|
-ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
+ISCDEPLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
||||||
|
|
||||||
|
DEPLIBS = ${ISCDEPLIBS}
|
||||||
|
|
||||||
|
diff --git a/configure.ac b/configure.ac
|
||||||
|
index 3b88105..0532feb 100644
|
||||||
|
--- a/configure.ac
|
||||||
|
+++ b/configure.ac
|
||||||
|
@@ -1139,12 +1139,14 @@ AC_SUBST(USE_GSSAPI)
|
||||||
|
AC_SUBST(DST_GSSAPI_INC)
|
||||||
|
AC_SUBST(DNS_GSSAPI_LIBS)
|
||||||
|
DNS_CRYPTO_LIBS="$DNS_GSSAPI_LIBS $DNS_CRYPTO_LIBS"
|
||||||
|
+DNS_CRYPTO_PK11_LIBS="$DNS_GSSAPI_LIBS $DNS_CRYPTO_PK11_LIBS"
|
||||||
|
|
||||||
|
#
|
||||||
|
# Applications linking with libdns also need to link with these libraries.
|
||||||
|
#
|
||||||
|
|
||||||
|
AC_SUBST(DNS_CRYPTO_LIBS)
|
||||||
|
+AC_SUBST(DNS_CRYPTO_PK11_LIBS)
|
||||||
|
|
||||||
|
#
|
||||||
|
# was --with-randomdev specified?
|
||||||
|
@@ -1529,11 +1531,11 @@ fi
|
||||||
|
AC_MSG_CHECKING(for OpenSSL library)
|
||||||
|
OPENSSL_WARNING=
|
||||||
|
openssldirs="/usr /usr/local /usr/local/ssl /opt/local /usr/pkg /usr/sfw"
|
||||||
|
-if test "yes" = "$want_native_pkcs11"
|
||||||
|
-then
|
||||||
|
- use_openssl="native_pkcs11"
|
||||||
|
- AC_MSG_RESULT(use of native PKCS11 instead)
|
||||||
|
-fi
|
||||||
|
+# if test "yes" = "$want_native_pkcs11"
|
||||||
|
+# then
|
||||||
|
+# use_openssl="native_pkcs11"
|
||||||
|
+# AC_MSG_RESULT(use of native PKCS11 instead)
|
||||||
|
+# fi
|
||||||
|
|
||||||
|
if test "auto" = "$use_openssl"
|
||||||
|
then
|
||||||
|
@@ -1546,6 +1548,7 @@ then
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
+CRYPTO_PK11=""
|
||||||
|
OPENSSL_ECDSA=""
|
||||||
|
OPENSSL_GOST=""
|
||||||
|
OPENSSL_ED25519=""
|
||||||
|
@@ -1567,11 +1570,10 @@ case "$with_gost" in
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
-case "$use_openssl" in
|
||||||
|
- native_pkcs11)
|
||||||
|
- AC_MSG_RESULT(disabled because of native PKCS11)
|
||||||
|
+if test "$want_native_pkcs11" = "yes"
|
||||||
|
+then
|
||||||
|
DST_OPENSSL_INC=""
|
||||||
|
- CRYPTO="-DPKCS11CRYPTO"
|
||||||
|
+ CRYPTO_PK11="-DPKCS11CRYPTO"
|
||||||
|
CRYPTOLIB="pkcs11"
|
||||||
|
OPENSSLECDSALINKOBJS=""
|
||||||
|
OPENSSLECDSALINKSRCS=""
|
||||||
|
@@ -1581,7 +1583,9 @@ case "$use_openssl" in
|
||||||
|
OPENSSLGOSTLINKSRCS=""
|
||||||
|
OPENSSLLINKOBJS=""
|
||||||
|
OPENSSLLINKSRCS=""
|
||||||
|
- ;;
|
||||||
|
+fi
|
||||||
|
+
|
||||||
|
+case "$use_openssl" in
|
||||||
|
no)
|
||||||
|
AC_MSG_RESULT(no)
|
||||||
|
DST_OPENSSL_INC=""
|
||||||
|
@@ -1613,7 +1617,7 @@ case "$use_openssl" in
|
||||||
|
If you do not want OpenSSL, use --without-openssl])
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
- if test "yes" = "$want_native_pkcs11"
|
||||||
|
+ if false # test "yes" = "$want_native_pkcs11"
|
||||||
|
then
|
||||||
|
AC_MSG_RESULT()
|
||||||
|
AC_MSG_ERROR([OpenSSL and native PKCS11 cannot be used together.])
|
||||||
|
@@ -2041,6 +2045,7 @@ AC_SUBST(OPENSSL_ED25519)
|
||||||
|
AC_SUBST(OPENSSL_GOST)
|
||||||
|
|
||||||
|
DNS_CRYPTO_LIBS="$DNS_CRYPTO_LIBS $DST_OPENSSL_LIBS"
|
||||||
|
+DNS_CRYPTO_PK11_LIBS="$DNS_CRYPTO_LIBS"
|
||||||
|
|
||||||
|
ISC_PLATFORM_WANTAES="#undef ISC_PLATFORM_WANTAES"
|
||||||
|
if test "yes" = "$with_aes"
|
||||||
|
@@ -2364,6 +2369,7 @@ esac
|
||||||
|
AC_SUBST(PKCS11LINKOBJS)
|
||||||
|
AC_SUBST(PKCS11LINKSRCS)
|
||||||
|
AC_SUBST(CRYPTO)
|
||||||
|
+AC_SUBST(CRYPTO_PK11)
|
||||||
|
AC_SUBST(PKCS11_ECDSA)
|
||||||
|
AC_SUBST(PKCS11_GOST)
|
||||||
|
AC_SUBST(PKCS11_ED25519)
|
||||||
|
@@ -5491,8 +5497,11 @@ AC_CONFIG_FILES([
|
||||||
|
bin/delv/Makefile
|
||||||
|
bin/dig/Makefile
|
||||||
|
bin/dnssec/Makefile
|
||||||
|
+ bin/dnssec-pkcs11/Makefile
|
||||||
|
bin/named/Makefile
|
||||||
|
bin/named/unix/Makefile
|
||||||
|
+ bin/named-pkcs11/Makefile
|
||||||
|
+ bin/named-pkcs11/unix/Makefile
|
||||||
|
bin/nsupdate/Makefile
|
||||||
|
bin/pkcs11/Makefile
|
||||||
|
bin/python/Makefile
|
||||||
|
@@ -5565,6 +5574,10 @@ AC_CONFIG_FILES([
|
||||||
|
lib/dns/include/dns/Makefile
|
||||||
|
lib/dns/include/dst/Makefile
|
||||||
|
lib/dns/tests/Makefile
|
||||||
|
+ lib/dns-pkcs11/Makefile
|
||||||
|
+ lib/dns-pkcs11/include/Makefile
|
||||||
|
+ lib/dns-pkcs11/include/dns/Makefile
|
||||||
|
+ lib/dns-pkcs11/include/dst/Makefile
|
||||||
|
lib/irs/Makefile
|
||||||
|
lib/irs/include/Makefile
|
||||||
|
lib/irs/include/irs/Makefile
|
||||||
|
@@ -5589,6 +5602,24 @@ AC_CONFIG_FILES([
|
||||||
|
lib/isc/unix/include/Makefile
|
||||||
|
lib/isc/unix/include/isc/Makefile
|
||||||
|
lib/isc/unix/include/pkcs11/Makefile
|
||||||
|
+ lib/isc-pkcs11/$arch/Makefile
|
||||||
|
+ lib/isc-pkcs11/$arch/include/Makefile
|
||||||
|
+ lib/isc-pkcs11/$arch/include/isc/Makefile
|
||||||
|
+ lib/isc-pkcs11/$thread_dir/Makefile
|
||||||
|
+ lib/isc-pkcs11/$thread_dir/include/Makefile
|
||||||
|
+ lib/isc-pkcs11/$thread_dir/include/isc/Makefile
|
||||||
|
+ lib/isc-pkcs11/Makefile
|
||||||
|
+ lib/isc-pkcs11/include/Makefile
|
||||||
|
+ lib/isc-pkcs11/include/isc/Makefile
|
||||||
|
+ lib/isc-pkcs11/include/isc/platform.h
|
||||||
|
+ lib/isc-pkcs11/include/pk11/Makefile
|
||||||
|
+ lib/isc-pkcs11/include/pkcs11/Makefile
|
||||||
|
+ lib/isc-pkcs11/tests/Makefile
|
||||||
|
+ lib/isc-pkcs11/nls/Makefile
|
||||||
|
+ lib/isc-pkcs11/unix/Makefile
|
||||||
|
+ lib/isc-pkcs11/unix/include/Makefile
|
||||||
|
+ lib/isc-pkcs11/unix/include/isc/Makefile
|
||||||
|
+ lib/isc-pkcs11/unix/include/pkcs11/Makefile
|
||||||
|
lib/isccc/Makefile
|
||||||
|
lib/isccc/include/Makefile
|
||||||
|
lib/isccc/include/isccc/Makefile
|
||||||
|
diff --git a/lib/Makefile.in b/lib/Makefile.in
|
||||||
|
index 81270a0..bcb5312 100644
|
||||||
|
--- a/lib/Makefile.in
|
||||||
|
+++ b/lib/Makefile.in
|
||||||
|
@@ -15,7 +15,7 @@ top_srcdir = @top_srcdir@
|
||||||
|
# Attempt to disable parallel processing.
|
||||||
|
.NOTPARALLEL:
|
||||||
|
.NO_PARALLEL:
|
||||||
|
-SUBDIRS = isc isccc dns isccfg bind9 lwres irs samples
|
||||||
|
+SUBDIRS = isc isc-pkcs11 isccc dns dns-pkcs11 isccfg bind9 lwres irs samples
|
||||||
|
TARGETS =
|
||||||
|
|
||||||
|
@BIND9_MAKE_RULES@
|
||||||
|
diff --git a/lib/dns-pkcs11/Makefile.in b/lib/dns-pkcs11/Makefile.in
|
||||||
|
index 7f09bd6..c388d9e 100644
|
||||||
|
--- a/lib/dns-pkcs11/Makefile.in
|
||||||
|
+++ b/lib/dns-pkcs11/Makefile.in
|
||||||
|
@@ -26,17 +26,16 @@ VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
|
USE_ISC_SPNEGO = @USE_ISC_SPNEGO@
|
||||||
|
|
||||||
|
-CINCLUDES = -I. -I${top_srcdir}/lib/dns -Iinclude ${DNS_INCLUDES} \
|
||||||
|
- ${ISC_INCLUDES} ${MAXMINDDB_CFLAGS} \
|
||||||
|
- @DST_OPENSSL_INC@ @DST_GSSAPI_INC@
|
||||||
|
+CINCLUDES = -I. -I${top_srcdir}/lib/dns-pkcs11 -Iinclude ${DNS_PKCS11_INCLUDES} \
|
||||||
|
+ ${ISC_PKCS11_INCLUDES} ${MAXMINDDB_CFLAGS} @DST_OPENSSL_INC@ @DST_GSSAPI_INC@
|
||||||
|
|
||||||
|
-CDEFINES = -DUSE_MD5 @CRYPTO@ @USE_GSSAPI@ ${USE_ISC_SPNEGO}
|
||||||
|
+CDEFINES = -DUSE_MD5 @CRYPTO_PK11@ @USE_GSSAPI@ ${USE_ISC_SPNEGO}
|
||||||
|
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
-ISCLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
+ISCLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
||||||
|
|
||||||
|
-ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
+ISCDEPLIBS = ../../lib/isc-pkcs11/libisc-pkcs11.@A@
|
||||||
|
|
||||||
|
LIBS = ${MAXMINDDB_LIBS} @LIBS@
|
||||||
|
|
||||||
|
@@ -150,15 +149,15 @@ version.@O@: version.c
|
||||||
|
-DLIBAGE=${LIBAGE} \
|
||||||
|
-c ${srcdir}/version.c
|
||||||
|
|
||||||
|
-libdns.@SA@: ${OBJS}
|
||||||
|
+libdns-pkcs11.@SA@: ${OBJS}
|
||||||
|
${AR} ${ARFLAGS} $@ ${OBJS}
|
||||||
|
${RANLIB} $@
|
||||||
|
|
||||||
|
-libdns.la: ${OBJS}
|
||||||
|
+libdns-pkcs11.la: ${OBJS}
|
||||||
|
${LIBTOOL_MODE_LINK} \
|
||||||
|
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libdns.la -rpath ${libdir} \
|
||||||
|
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libdns-pkcs11.la -rpath ${libdir} \
|
||||||
|
-version-info ${LIBINTERFACE}:${LIBREVISION}:${LIBAGE} \
|
||||||
|
- ${OBJS} ${ISCLIBS} @DNS_CRYPTO_LIBS@ ${LIBS}
|
||||||
|
+ ${OBJS} ${ISCLIBS} @DNS_CRYPTO_PK11_LIBS@ ${LIBS}
|
||||||
|
|
||||||
|
include: gen
|
||||||
|
${MAKE} include/dns/enumtype.h
|
||||||
|
@@ -189,22 +188,22 @@ gen: gen.c
|
||||||
|
${BUILD_CPPFLAGS} ${BUILD_LDFLAGS} -o $@ ${srcdir}/gen.c \
|
||||||
|
${BUILD_LIBS} ${LFS_LIBS}
|
||||||
|
|
||||||
|
-timestamp: include libdns.@A@
|
||||||
|
+timestamp: include libdns-pkcs11.@A@
|
||||||
|
touch timestamp
|
||||||
|
|
||||||
|
-testdirs: libdns.@A@
|
||||||
|
+testdirs: libdns-pkcs11.@A@
|
||||||
|
|
||||||
|
installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${libdir}
|
||||||
|
|
||||||
|
install:: timestamp installdirs
|
||||||
|
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_LIBRARY} libdns.@A@ ${DESTDIR}${libdir}
|
||||||
|
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_LIBRARY} libdns-pkcs11.@A@ ${DESTDIR}${libdir}
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
- ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${libdir}/libdns.@A@
|
||||||
|
+ ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${libdir}/libdns-pkcs11.@A@
|
||||||
|
|
||||||
|
clean distclean::
|
||||||
|
- rm -f libdns.@A@ timestamp
|
||||||
|
+ rm -f libdns-pkcs11.@A@ timestamp
|
||||||
|
rm -f gen code.h include/dns/enumtype.h include/dns/enumclass.h
|
||||||
|
rm -f include/dns/rdatastruct.h
|
||||||
|
rm -f dnstap.pb-c.c dnstap.pb-c.h
|
||||||
|
diff --git a/lib/isc-pkcs11/Makefile.in b/lib/isc-pkcs11/Makefile.in
|
||||||
|
index 98acfff..2fd6981 100644
|
||||||
|
--- a/lib/isc-pkcs11/Makefile.in
|
||||||
|
+++ b/lib/isc-pkcs11/Makefile.in
|
||||||
|
@@ -23,8 +23,8 @@ CINCLUDES = -I${srcdir}/unix/include \
|
||||||
|
-I${srcdir}/@ISC_THREAD_DIR@/include \
|
||||||
|
-I${srcdir}/@ISC_ARCH_DIR@/include \
|
||||||
|
-I./include \
|
||||||
|
- -I${srcdir}/include ${DNS_INCLUDES} @ISC_OPENSSL_INC@
|
||||||
|
-CDEFINES = @CRYPTO@ -DPK11_LIB_LOCATION=\"${PROVIDER}\"
|
||||||
|
+ -I${srcdir}/include ${DNS_PKCS11_INCLUDES}
|
||||||
|
+CDEFINES = @CRYPTO_PK11@ -DPK11_LIB_LOCATION=\"${PROVIDER}\"
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
# Alphabetically
|
||||||
|
@@ -103,40 +103,40 @@ version.@O@: version.c
|
||||||
|
-DLIBAGE=${LIBAGE} \
|
||||||
|
-c ${srcdir}/version.c
|
||||||
|
|
||||||
|
-libisc.@SA@: ${OBJS} ${SYMTBLOBJS}
|
||||||
|
+libisc-pkcs11.@SA@: ${OBJS} ${SYMTBLOBJS}
|
||||||
|
${AR} ${ARFLAGS} $@ ${OBJS} ${SYMTBLOBJS}
|
||||||
|
${RANLIB} $@
|
||||||
|
|
||||||
|
-libisc-nosymtbl.@SA@: ${OBJS}
|
||||||
|
+libisc-pkcs11-nosymtbl.@SA@: ${OBJS}
|
||||||
|
${AR} ${ARFLAGS} $@ ${OBJS}
|
||||||
|
${RANLIB} $@
|
||||||
|
|
||||||
|
-libisc.la: ${OBJS} ${SYMTBLOBJS}
|
||||||
|
+libisc-pkcs11.la: ${OBJS} ${SYMTBLOBJS}
|
||||||
|
${LIBTOOL_MODE_LINK} \
|
||||||
|
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisc.la -rpath ${libdir} \
|
||||||
|
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisc-pkcs11.la -rpath ${libdir} \
|
||||||
|
-version-info ${LIBINTERFACE}:${LIBREVISION}:${LIBAGE} \
|
||||||
|
${OBJS} ${SYMTBLOBJS} ${LIBS}
|
||||||
|
|
||||||
|
-libisc-nosymtbl.la: ${OBJS}
|
||||||
|
+libisc-pkcs11-nosymtbl.la: ${OBJS}
|
||||||
|
${LIBTOOL_MODE_LINK} \
|
||||||
|
- ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisc-nosymtbl.la -rpath ${libdir} \
|
||||||
|
+ ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o libisc-pkcs11-nosymtbl.la -rpath ${libdir} \
|
||||||
|
-version-info ${LIBINTERFACE}:${LIBREVISION}:${LIBAGE} \
|
||||||
|
${OBJS} ${LIBS}
|
||||||
|
|
||||||
|
-timestamp: libisc.@A@ libisc-nosymtbl.@A@
|
||||||
|
+timestamp: libisc-pkcs11.@A@ libisc-pkcs11-nosymtbl.@A@
|
||||||
|
touch timestamp
|
||||||
|
|
||||||
|
-testdirs: libisc.@A@ libisc-nosymtbl.@A@
|
||||||
|
+testdirs: libisc-pkcs11.@A@ libisc-pkcs11-nosymtbl.@A@
|
||||||
|
|
||||||
|
installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${libdir}
|
||||||
|
|
||||||
|
install:: timestamp installdirs
|
||||||
|
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_LIBRARY} libisc.@A@ ${DESTDIR}${libdir}
|
||||||
|
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_LIBRARY} libisc-pkcs11.@A@ ${DESTDIR}${libdir}
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
- ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${libdir}/libisc.@A@
|
||||||
|
+ ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${libdir}/libisc-pkcs11.@A@
|
||||||
|
|
||||||
|
clean distclean::
|
||||||
|
- rm -f libisc.@A@ libisc-nosymtbl.@A@ libisc.la \
|
||||||
|
- libisc-nosymtbl.la timestamp
|
||||||
|
+ rm -f libisc-pkcs11.@A@ libisc-pkcs11-nosymtbl.@A@ libisc-pkcs11.la \
|
||||||
|
+ libisc-pkcs11-nosymtbl.la timestamp
|
||||||
|
diff --git a/make/includes.in b/make/includes.in
|
||||||
|
index fa86ad1..3cfbe9f 100644
|
||||||
|
--- a/make/includes.in
|
||||||
|
+++ b/make/includes.in
|
||||||
|
@@ -43,3 +43,13 @@ BIND9_INCLUDES = @BIND9_BIND9_BUILDINCLUDE@ \
|
||||||
|
|
||||||
|
TEST_INCLUDES = \
|
||||||
|
-I${top_srcdir}/lib/tests/include
|
||||||
|
+
|
||||||
|
+ISC_PKCS11_INCLUDES = @BIND9_ISC_BUILDINCLUDE@ \
|
||||||
|
+ -I${top_srcdir}/lib/isc-pkcs11 \
|
||||||
|
+ -I${top_srcdir}/lib/isc-pkcs11/include \
|
||||||
|
+ -I${top_srcdir}/lib/isc-pkcs11/unix/include \
|
||||||
|
+ -I${top_srcdir}/lib/isc-pkcs11/@ISC_THREAD_DIR@/include \
|
||||||
|
+ -I${top_srcdir}/lib/isc-pkcs11/@ISC_ARCH_DIR@/include
|
||||||
|
+
|
||||||
|
+DNS_PKCS11_INCLUDES = @BIND9_DNS_BUILDINCLUDE@ \
|
||||||
|
+ -I${top_srcdir}/lib/dns-pkcs11/include
|
||||||
53
bind-9.10-sdb-sqlite-bld.patch
Normal file
53
bind-9.10-sdb-sqlite-bld.patch
Normal file
|
|
@ -0,0 +1,53 @@
|
||||||
|
diff --git a/bin/named-sdb/Makefile.in b/bin/named-sdb/Makefile.in
|
||||||
|
index 1894830..445182a 100644
|
||||||
|
--- a/bin/named-sdb/Makefile.in
|
||||||
|
+++ b/bin/named-sdb/Makefile.in
|
||||||
|
@@ -34,10 +34,10 @@ top_srcdir = @top_srcdir@
|
||||||
|
#
|
||||||
|
# Add database drivers here.
|
||||||
|
#
|
||||||
|
-DBDRIVER_OBJS = ldapdb.@O@ pgsqldb.@O@ dirdb.@O@
|
||||||
|
-DBDRIVER_SRCS = ldapdb.c pgsqldb.c dirdb.c
|
||||||
|
+DBDRIVER_OBJS = ldapdb.@O@ pgsqldb.@O@ sqlitedb.@O@ dirdb.@O@
|
||||||
|
+DBDRIVER_SRCS = ldapdb.c pgsqldb.c sqlitedb.c dirdb.c
|
||||||
|
DBDRIVER_INCLUDES =
|
||||||
|
-DBDRIVER_LIBS = -lldap -llber -lpq
|
||||||
|
+DBDRIVER_LIBS = -lldap -llber -lsqlite3 -lpq
|
||||||
|
|
||||||
|
DLZ_DRIVER_DIR = ${top_srcdir}/contrib/dlz/drivers
|
||||||
|
|
||||||
|
diff --git a/bin/sdb_tools/Makefile.in b/bin/sdb_tools/Makefile.in
|
||||||
|
index 7f3c5e2..b1bca66 100644
|
||||||
|
--- a/bin/sdb_tools/Makefile.in
|
||||||
|
+++ b/bin/sdb_tools/Makefile.in
|
||||||
|
@@ -32,11 +32,11 @@ DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
||||||
|
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} ${DBDRIVER_LIBS} @LIBS@
|
||||||
|
|
||||||
|
-TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@
|
||||||
|
+TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@ zone2sqlite@EXEEXT@
|
||||||
|
|
||||||
|
-OBJS = zone2ldap.@O@ zonetodb.@O@
|
||||||
|
+OBJS = zone2ldap.@O@ zonetodb.@O@ zone2sqlite.@O@
|
||||||
|
|
||||||
|
-SRCS = zone2ldap.c zonetodb.c
|
||||||
|
+SRCS = zone2ldap.c zonetodb.c zone2sqlite.c
|
||||||
|
|
||||||
|
MANPAGES = zone2ldap.1
|
||||||
|
|
||||||
|
@@ -50,6 +50,9 @@ zone2ldap@EXEEXT@: zone2ldap.@O@ ${DEPLIBS}
|
||||||
|
zonetodb@EXEEXT@: zonetodb.@O@ ${DEPLIBS}
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zonetodb.@O@ -lpq ${LIBS}
|
||||||
|
|
||||||
|
+zone2sqlite@EXEEXT@: zone2sqlite.@O@ ${DEPLIBS}
|
||||||
|
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o $@ zone2sqlite.@O@ -lsqlite3 -lssl ${LIBS}
|
||||||
|
+
|
||||||
|
clean distclean manclean maintainer-clean::
|
||||||
|
rm -f ${TARGETS} ${OBJS}
|
||||||
|
|
||||||
|
@@ -60,4 +63,5 @@ installdirs:
|
||||||
|
install:: ${TARGETS} installdirs
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2ldap@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zonetodb@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2sqlite@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${INSTALL_DATA} ${srcdir}/zone2ldap.1 ${DESTDIR}${mandir}/man1/zone2ldap.1
|
||||||
319
bind-9.10-sdb.patch
Normal file
319
bind-9.10-sdb.patch
Normal file
|
|
@ -0,0 +1,319 @@
|
||||||
|
diff --git a/bin/Makefile.in b/bin/Makefile.in
|
||||||
|
index ce7a2da..4e6a824 100644
|
||||||
|
--- a/bin/Makefile.in
|
||||||
|
+++ b/bin/Makefile.in
|
||||||
|
@@ -11,8 +11,8 @@ srcdir = @srcdir@
|
||||||
|
VPATH = @srcdir@
|
||||||
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
|
-SUBDIRS = named named-pkcs11 rndc dig delv dnssec dnssec-pkcs11 tools nsupdate \
|
||||||
|
- check confgen @NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@ tests
|
||||||
|
+SUBDIRS = named named-sdb named-pkcs11 rndc dig delv dnssec dnssec-pkcs11 tools nsupdate \
|
||||||
|
+ check confgen @NZD_TOOLS@ @PYTHON_TOOLS@ @PKCS11_TOOLS@ sdb_tools tests
|
||||||
|
TARGETS =
|
||||||
|
|
||||||
|
@BIND9_MAKE_RULES@
|
||||||
|
diff --git a/bin/named-sdb/Makefile.in b/bin/named-sdb/Makefile.in
|
||||||
|
index 9660965..184fbb2 100644
|
||||||
|
--- a/bin/named-sdb/Makefile.in
|
||||||
|
+++ b/bin/named-sdb/Makefile.in
|
||||||
|
@@ -30,10 +30,10 @@ VERSION=@BIND9_VERSION@
|
||||||
|
#
|
||||||
|
# Add database drivers here.
|
||||||
|
#
|
||||||
|
-DBDRIVER_OBJS =
|
||||||
|
-DBDRIVER_SRCS =
|
||||||
|
+DBDRIVER_OBJS = ldapdb.@O@ pgsqldb.@O@ sqlitedb.@O@ dirdb.@O@
|
||||||
|
+DBDRIVER_SRCS = ldapdb.c pgsqldb.c sqlitedb.c dirdb.c
|
||||||
|
DBDRIVER_INCLUDES =
|
||||||
|
-DBDRIVER_LIBS =
|
||||||
|
+DBDRIVER_LIBS = -lldap -llber -lsqlite3 -lpq
|
||||||
|
|
||||||
|
DLZ_DRIVER_DIR = ${top_srcdir}/contrib/dlz/drivers
|
||||||
|
|
||||||
|
@@ -80,7 +80,7 @@ NOSYMLIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
|
||||||
|
SUBDIRS = unix
|
||||||
|
|
||||||
|
-TARGETS = named@EXEEXT@ lwresd@EXEEXT@ feature-test@EXEEXT@
|
||||||
|
+TARGETS = named-sdb@EXEEXT@ feature-test-sdb@EXEEXT@
|
||||||
|
|
||||||
|
GEOIPLINKOBJS = geoip.@O@
|
||||||
|
GEOIP2LINKOBJS = geoip.@O@
|
||||||
|
@@ -154,7 +154,7 @@ server.@O@: server.c
|
||||||
|
-DPRODUCT=\"${PRODUCT}\" \
|
||||||
|
-DVERSION=\"${VERSION}\" -c ${srcdir}/server.c
|
||||||
|
|
||||||
|
-named@EXEEXT@: ${OBJS} ${DEPLIBS}
|
||||||
|
+named-sdb@EXEEXT@: ${OBJS} ${DEPLIBS}
|
||||||
|
export MAKE_SYMTABLE="yes"; \
|
||||||
|
export BASEOBJS="${OBJS} ${UOBJS}"; \
|
||||||
|
${FINALBUILDCMD}
|
||||||
|
@@ -168,7 +168,7 @@ feature-test.@O@: ${top_srcdir}/bin/tests/system/feature-test.c
|
||||||
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||||
|
-c ${top_srcdir}/bin/tests/system/feature-test.c
|
||||||
|
|
||||||
|
-feature-test@EXEEXT@: feature-test.@O@
|
||||||
|
+feature-test-sdb@EXEEXT@: feature-test.@O@
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} \
|
||||||
|
-o $@ feature-test.@O@ ${ISCLIBS} ${LIBS}
|
||||||
|
|
||||||
|
@@ -190,8 +190,6 @@ statschannel.@O@: bind9.xsl.h
|
||||||
|
|
||||||
|
installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||||
|
- $(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man5
|
||||||
|
- $(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
install-man5: named.conf.5
|
||||||
|
${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man5
|
||||||
|
@@ -201,16 +199,11 @@ install-man8: named.8 lwresd.8
|
||||||
|
|
||||||
|
install-man: install-man5 install-man8
|
||||||
|
|
||||||
|
-install:: named@EXEEXT@ lwresd@EXEEXT@ installdirs install-man
|
||||||
|
- ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
- (cd ${DESTDIR}${sbindir}; rm -f lwresd@EXEEXT@; @LN@ named@EXEEXT@ lwresd@EXEEXT@)
|
||||||
|
+install:: ${TARGETS} installdirs
|
||||||
|
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-sdb@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
- rm -f ${DESTDIR}${mandir}/man5/named.conf.5
|
||||||
|
- rm -f ${DESTDIR}${mandir}/man8/lwresd.8
|
||||||
|
- rm -f ${DESTDIR}${mandir}/man8/named.8
|
||||||
|
- rm -f ${DESTDIR}${sbindir}/lwresd@EXEEXT@
|
||||||
|
- ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named@EXEEXT@
|
||||||
|
+ ${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named-sdb@EXEEXT@
|
||||||
|
|
||||||
|
@DLZ_DRIVER_RULES@
|
||||||
|
|
||||||
|
diff --git a/bin/named-sdb/main.c b/bin/named-sdb/main.c
|
||||||
|
index 108b8d6..a943421 100644
|
||||||
|
--- a/bin/named-sdb/main.c
|
||||||
|
+++ b/bin/named-sdb/main.c
|
||||||
|
@@ -93,6 +93,10 @@
|
||||||
|
* Include header files for database drivers here.
|
||||||
|
*/
|
||||||
|
/* #include "xxdb.h" */
|
||||||
|
+#include "ldapdb.h"
|
||||||
|
+#include "pgsqldb.h"
|
||||||
|
+#include "sqlitedb.h"
|
||||||
|
+#include "dirdb.h"
|
||||||
|
|
||||||
|
#ifdef CONTRIB_DLZ
|
||||||
|
/*
|
||||||
|
@@ -1069,6 +1073,11 @@ setup(void) {
|
||||||
|
ns_main_earlyfatal("isc_app_start() failed: %s",
|
||||||
|
isc_result_totext(result));
|
||||||
|
|
||||||
|
+ ldapdb_clear();
|
||||||
|
+ pgsqldb_clear();
|
||||||
|
+ dirdb_clear();
|
||||||
|
+ sqlitedb_clear();
|
||||||
|
+
|
||||||
|
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
ISC_LOG_NOTICE, "starting %s %s%s%s <id:%s>",
|
||||||
|
ns_g_product, ns_g_version,
|
||||||
|
@@ -1269,6 +1278,75 @@ setup(void) {
|
||||||
|
isc_result_totext(result));
|
||||||
|
#endif
|
||||||
|
|
||||||
|
+ result = ldapdb_init();
|
||||||
|
+ if (result != ISC_R_SUCCESS)
|
||||||
|
+ {
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_ERROR,
|
||||||
|
+ "SDB ldap module initialisation failed: %s.",
|
||||||
|
+ isc_result_totext(result)
|
||||||
|
+ );
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_ERROR,
|
||||||
|
+ "SDB ldap zone database will be unavailable."
|
||||||
|
+ );
|
||||||
|
+ }else
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_NOTICE, "SDB ldap zone database module loaded."
|
||||||
|
+ );
|
||||||
|
+
|
||||||
|
+ result = pgsqldb_init();
|
||||||
|
+ if (result != ISC_R_SUCCESS)
|
||||||
|
+ {
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_ERROR,
|
||||||
|
+ "SDB pgsql module initialisation failed: %s.",
|
||||||
|
+ isc_result_totext(result)
|
||||||
|
+ );
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_ERROR,
|
||||||
|
+ "SDB pgsql zone database will be unavailable."
|
||||||
|
+ );
|
||||||
|
+ }else
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_NOTICE, "SDB postgreSQL DB zone database module loaded."
|
||||||
|
+ );
|
||||||
|
+
|
||||||
|
+ result = sqlitedb_init();
|
||||||
|
+ if (result != ISC_R_SUCCESS)
|
||||||
|
+ {
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_ERROR,
|
||||||
|
+ "SDB sqlite3 module initialisation failed: %s.",
|
||||||
|
+ isc_result_totext(result)
|
||||||
|
+ );
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_ERROR,
|
||||||
|
+ "SDB sqlite3 zone database will be unavailable."
|
||||||
|
+ );
|
||||||
|
+ }else
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_NOTICE, "SDB sqlite3 DB zone database module loaded."
|
||||||
|
+ );
|
||||||
|
+
|
||||||
|
+ result = dirdb_init();
|
||||||
|
+ if (result != ISC_R_SUCCESS)
|
||||||
|
+ {
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_ERROR,
|
||||||
|
+ "SDB directory DB module initialisation failed: %s.",
|
||||||
|
+ isc_result_totext(result)
|
||||||
|
+ );
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_ERROR,
|
||||||
|
+ "SDB directory DB zone database will be unavailable."
|
||||||
|
+ );
|
||||||
|
+ }else
|
||||||
|
+ isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
+ ISC_LOG_NOTICE, "SDB directory DB zone database module loaded."
|
||||||
|
+ );
|
||||||
|
+
|
||||||
|
+
|
||||||
|
ns_server_create(ns_g_mctx, &ns_g_server);
|
||||||
|
|
||||||
|
#ifdef HAVE_LIBSECCOMP
|
||||||
|
@@ -1311,6 +1389,11 @@ cleanup(void) {
|
||||||
|
|
||||||
|
dns_name_destroy();
|
||||||
|
|
||||||
|
+ ldapdb_clear();
|
||||||
|
+ pgsqldb_clear();
|
||||||
|
+ sqlitedb_clear();
|
||||||
|
+ dirdb_clear();
|
||||||
|
+
|
||||||
|
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
|
||||||
|
ISC_LOG_NOTICE, "exiting");
|
||||||
|
ns_log_shutdown();
|
||||||
|
diff --git a/bin/named/Makefile.in b/bin/named/Makefile.in
|
||||||
|
index 9660965..03f7c05 100644
|
||||||
|
--- a/bin/named/Makefile.in
|
||||||
|
+++ b/bin/named/Makefile.in
|
||||||
|
@@ -45,10 +45,10 @@ DLZDRIVER_LIBS = @DLZ_DRIVER_LIBS@
|
||||||
|
CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include -I. \
|
||||||
|
${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
||||||
|
${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_INCLUDES} \
|
||||||
|
- ${DLZDRIVER_INCLUDES} ${DBDRIVER_INCLUDES} ${MAXMINDDB_CFLAGS} \
|
||||||
|
+ ${MAXMINDDB_CFLAGS} \
|
||||||
|
@DST_OPENSSL_INC@
|
||||||
|
|
||||||
|
-CDEFINES = @CONTRIB_DLZ@ @CRYPTO@
|
||||||
|
+CDEFINES = @CRYPTO@
|
||||||
|
|
||||||
|
CWARNINGS =
|
||||||
|
|
||||||
|
@@ -72,11 +72,11 @@ DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
||||||
|
|
||||||
|
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} \
|
||||||
|
- ${DLZDRIVER_LIBS} ${DBDRIVER_LIBS} @LIBS@
|
||||||
|
+ @LIBS@
|
||||||
|
|
||||||
|
NOSYMLIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCNOSYMLIBS} \
|
||||||
|
- ${DLZDRIVER_LIBS} ${DBDRIVER_LIBS} @LIBS@
|
||||||
|
+ @LIBS@
|
||||||
|
|
||||||
|
SUBDIRS = unix
|
||||||
|
|
||||||
|
@@ -94,8 +94,7 @@ OBJS = builtin.@O@ client.@O@ config.@O@ control.@O@ \
|
||||||
|
tkeyconf.@O@ tsigconf.@O@ update.@O@ xfrout.@O@ \
|
||||||
|
zoneconf.@O@ \
|
||||||
|
lwaddr.@O@ lwresd.@O@ lwdclient.@O@ lwderror.@O@ lwdgabn.@O@ \
|
||||||
|
- lwdgnba.@O@ lwdgrbn.@O@ lwdnoop.@O@ lwsearch.@O@ \
|
||||||
|
- ${DLZDRIVER_OBJS} ${DBDRIVER_OBJS}
|
||||||
|
+ lwdgnba.@O@ lwdgrbn.@O@ lwdnoop.@O@ lwsearch.@O@
|
||||||
|
|
||||||
|
UOBJS = unix/os.@O@ unix/dlz_dlopen_driver.@O@
|
||||||
|
|
||||||
|
@@ -113,8 +112,7 @@ SRCS = builtin.c client.c config.c control.c \
|
||||||
|
tkeyconf.c tsigconf.c update.c xfrout.c \
|
||||||
|
zoneconf.c \
|
||||||
|
lwaddr.c lwresd.c lwdclient.c lwderror.c lwdgabn.c \
|
||||||
|
- lwdgnba.c lwdgrbn.c lwdnoop.c lwsearch.c \
|
||||||
|
- ${DLZDRIVER_SRCS} ${DBDRIVER_SRCS}
|
||||||
|
+ lwdgnba.c lwdgrbn.c lwdnoop.c lwsearch.c
|
||||||
|
|
||||||
|
MANPAGES = named.8 lwresd.8 named.conf.5
|
||||||
|
|
||||||
|
@@ -212,7 +210,5 @@ uninstall::
|
||||||
|
rm -f ${DESTDIR}${sbindir}/lwresd@EXEEXT@
|
||||||
|
${LIBTOOL_MODE_UNINSTALL} rm -f ${DESTDIR}${sbindir}/named@EXEEXT@
|
||||||
|
|
||||||
|
-@DLZ_DRIVER_RULES@
|
||||||
|
-
|
||||||
|
named-symtbl.@O@: named-symtbl.c
|
||||||
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} -c named-symtbl.c
|
||||||
|
diff --git a/bin/sdb_tools/Makefile.in b/bin/sdb_tools/Makefile.in
|
||||||
|
index c7e0868..95ab742 100644
|
||||||
|
--- a/bin/sdb_tools/Makefile.in
|
||||||
|
+++ b/bin/sdb_tools/Makefile.in
|
||||||
|
@@ -32,11 +32,11 @@ DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
||||||
|
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} ${DBDRIVER_LIBS} @LIBS@
|
||||||
|
|
||||||
|
-TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@
|
||||||
|
+TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@ zone2sqlite@EXEEXT@
|
||||||
|
|
||||||
|
-OBJS = zone2ldap.@O@ zonetodb.@O@
|
||||||
|
+OBJS = zone2ldap.@O@ zonetodb.@O@ zone2sqlite.@O@
|
||||||
|
|
||||||
|
-SRCS = zone2ldap.c zonetodb.c
|
||||||
|
+SRCS = zone2ldap.c zonetodb.c zone2sqlite.c
|
||||||
|
|
||||||
|
MANPAGES = zone2ldap.1
|
||||||
|
|
||||||
|
@@ -50,6 +50,9 @@ zone2ldap@EXEEXT@: zone2ldap.@O@ ${DEPLIBS}
|
||||||
|
zonetodb@EXEEXT@: zonetodb.@O@ ${DEPLIBS}
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zonetodb.@O@ -lpq ${LIBS}
|
||||||
|
|
||||||
|
+zone2sqlite@EXEEXT@: zone2sqlite.@O@ ${DEPLIBS}
|
||||||
|
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o $@ zone2sqlite.@O@ -lsqlite3 -lssl ${LIBS}
|
||||||
|
+
|
||||||
|
clean distclean manclean maintainer-clean::
|
||||||
|
rm -f ${TARGETS} ${OBJS}
|
||||||
|
|
||||||
|
@@ -60,4 +63,5 @@ installdirs:
|
||||||
|
install:: ${TARGETS} installdirs
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2ldap@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zonetodb@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2sqlite@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${INSTALL_DATA} ${srcdir}/zone2ldap.1 ${DESTDIR}${mandir}/man1/zone2ldap.1
|
||||||
|
diff --git a/configure.ac b/configure.ac
|
||||||
|
index d8147ae..930cd1c 100644
|
||||||
|
--- a/configure.ac
|
||||||
|
+++ b/configure.ac
|
||||||
|
@@ -5532,6 +5532,8 @@ AC_CONFIG_FILES([
|
||||||
|
bin/named/unix/Makefile
|
||||||
|
bin/named-pkcs11/Makefile
|
||||||
|
bin/named-pkcs11/unix/Makefile
|
||||||
|
+ bin/named-sdb/Makefile
|
||||||
|
+ bin/named-sdb/unix/Makefile
|
||||||
|
bin/nsupdate/Makefile
|
||||||
|
bin/pkcs11/Makefile
|
||||||
|
bin/python/Makefile
|
||||||
|
@@ -5556,6 +5558,7 @@ AC_CONFIG_FILES([
|
||||||
|
bin/python/isc/tests/dnskey_test.py
|
||||||
|
bin/python/isc/tests/policy_test.py
|
||||||
|
bin/rndc/Makefile
|
||||||
|
+ bin/sdb_tools/Makefile
|
||||||
|
bin/tests/Makefile
|
||||||
|
bin/tests/headerdep_test.sh
|
||||||
|
bin/tests/optional/Makefile
|
||||||
18
bind-9.10-use-of-strlcat.patch
Normal file
18
bind-9.10-use-of-strlcat.patch
Normal file
|
|
@ -0,0 +1,18 @@
|
||||||
|
diff --git a/bin/sdb_tools/zone2ldap.c b/bin/sdb_tools/zone2ldap.c
|
||||||
|
index d56bc56..99c3314 100644
|
||||||
|
--- a/bin/sdb_tools/zone2ldap.c
|
||||||
|
+++ b/bin/sdb_tools/zone2ldap.c
|
||||||
|
@@ -817,11 +817,11 @@ build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag, char *zone)
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
- strlcat (dn, tmp, sizeof (dn));
|
||||||
|
+ strncat (dn, tmp, sizeof (dn) - strlen (dn));
|
||||||
|
}
|
||||||
|
|
||||||
|
sprintf (tmp, "dc=%s", dc_list[0]);
|
||||||
|
- strlcat (dn, tmp, sizeof (dn));
|
||||||
|
+ strncat (dn, tmp, sizeof (dn) - strlen (dn));
|
||||||
|
|
||||||
|
fflush(NULL);
|
||||||
|
return dn;
|
||||||
41
bind-9.11-ed448-disable.patch
Normal file
41
bind-9.11-ed448-disable.patch
Normal file
|
|
@ -0,0 +1,41 @@
|
||||||
|
From e6bad0789c731f06de781997e33e864c71510ff2 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Thu, 21 Feb 2019 12:36:17 +0100
|
||||||
|
Subject: [PATCH] Disable autodetected ED448 algorithm support
|
||||||
|
|
||||||
|
Implementation is broken in bind, disabled also in more recent versions.
|
||||||
|
Makes bin/tests/system/dnssec fail.
|
||||||
|
---
|
||||||
|
configure.in | 9 +++++++--
|
||||||
|
1 file changed, 7 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/configure.in b/configure.in
|
||||||
|
index ca84ff3239..da4dd5f249 100644
|
||||||
|
--- a/configure.in
|
||||||
|
+++ b/configure.in
|
||||||
|
@@ -1917,6 +1917,9 @@ int main() {
|
||||||
|
}
|
||||||
|
],
|
||||||
|
[AC_MSG_RESULT(yes)
|
||||||
|
+ # ED448 support is broken in BIND
|
||||||
|
+ # https://gitlab.isc.org/isc-projects/bind9/issues/225
|
||||||
|
+ # disable if autodetected, can be enabled by --with-eddsa=all
|
||||||
|
have_ed448="yes"],
|
||||||
|
[AC_MSG_RESULT(no)
|
||||||
|
have_ed448="no"],
|
||||||
|
@@ -1929,8 +1932,10 @@ int main() {
|
||||||
|
esac
|
||||||
|
case $have_ed448 in
|
||||||
|
yes)
|
||||||
|
- AC_DEFINE(HAVE_OPENSSL_ED448, 1,
|
||||||
|
- [Define if your OpenSSL version supports Ed448.])
|
||||||
|
+ # ED448 support is broken in BIND
|
||||||
|
+ # https://gitlab.isc.org/isc-projects/bind9/issues/225
|
||||||
|
+ # AC_DEFINE(HAVE_OPENSSL_ED448, 1,
|
||||||
|
+ # [Define if your OpenSSL version supports Ed448.])
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
;;
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
27
bind-9.11-engine-pkcs11.patch
Normal file
27
bind-9.11-engine-pkcs11.patch
Normal file
|
|
@ -0,0 +1,27 @@
|
||||||
|
From 37f89ccfc439f8d86c401d9ae10e94e53b924961 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Tue, 27 Aug 2019 20:39:59 +0200
|
||||||
|
Subject: [PATCH] Do not set engine for native PKCS11
|
||||||
|
|
||||||
|
It resets already set lib_path to pkcs11, which is invalid in native
|
||||||
|
pkcs11 crypto. Engine has to be path to PKCS#11 module.
|
||||||
|
---
|
||||||
|
bin/named/include/named/globals.h | 2 +-
|
||||||
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/bin/named/include/named/globals.h b/bin/named/include/named/globals.h
|
||||||
|
index eda2214..2a611d5 100644
|
||||||
|
--- a/bin/named/include/named/globals.h
|
||||||
|
+++ b/bin/named/include/named/globals.h
|
||||||
|
@@ -160,7 +160,7 @@ EXTERN const char * ns_g_defaultdnstap INIT(NULL);
|
||||||
|
|
||||||
|
EXTERN const char * ns_g_username INIT(NULL);
|
||||||
|
|
||||||
|
-#if defined(USE_PKCS11)
|
||||||
|
+#if defined(USE_PKCS11) && !defined(PKCS11CRYPTO)
|
||||||
|
EXTERN const char * ns_g_engine INIT(PKCS11_ENGINE);
|
||||||
|
#else
|
||||||
|
EXTERN const char * ns_g_engine INIT(NULL);
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
39
bind-9.11-export-suffix.patch
Normal file
39
bind-9.11-export-suffix.patch
Normal file
|
|
@ -0,0 +1,39 @@
|
||||||
|
diff --git a/configure.ac b/configure.ac
|
||||||
|
index c1bfd62..7c5ad51 100644
|
||||||
|
--- a/configure.ac
|
||||||
|
+++ b/configure.ac
|
||||||
|
@@ -5333,6 +5333,8 @@ AC_SUBST(BUILD_CPPFLAGS)
|
||||||
|
AC_SUBST(BUILD_LDFLAGS)
|
||||||
|
AC_SUBST(BUILD_LIBS)
|
||||||
|
|
||||||
|
+AC_SUBST(LIBDIR_SUFFIX)
|
||||||
|
+
|
||||||
|
#
|
||||||
|
# Commands to run at the end of config.status.
|
||||||
|
# Don't just put these into configure, it won't work right if somebody
|
||||||
|
diff --git a/isc-config.sh.in b/isc-config.sh.in
|
||||||
|
index b5e94ed..d2857e0 100644
|
||||||
|
--- a/isc-config.sh.in
|
||||||
|
+++ b/isc-config.sh.in
|
||||||
|
@@ -13,16 +13,17 @@ prefix=@prefix@
|
||||||
|
exec_prefix=@exec_prefix@
|
||||||
|
exec_prefix_set=
|
||||||
|
includedir=@includedir@
|
||||||
|
+libdir_suffix=@LIBDIR_SUFFIX@
|
||||||
|
arch=$(uname -m)
|
||||||
|
|
||||||
|
case $arch in
|
||||||
|
x86_64 | amd64 | sparc64 | s390x | ppc64)
|
||||||
|
- libdir=/usr/lib64
|
||||||
|
- sec_libdir=/usr/lib
|
||||||
|
+ libdir=/usr/lib64${libdir_suffix}
|
||||||
|
+ sec_libdir=/usr/lib${libdir_suffix}
|
||||||
|
;;
|
||||||
|
* )
|
||||||
|
- libdir=/usr/lib
|
||||||
|
- sec_libdir=/usr/lib64
|
||||||
|
+ libdir=/usr/lib${libdir_suffix}
|
||||||
|
+ sec_libdir=/usr/lib64${libdir_suffix}
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
58
bind-9.11-feature-test-named.patch
Normal file
58
bind-9.11-feature-test-named.patch
Normal file
|
|
@ -0,0 +1,58 @@
|
||||||
|
From d394129acaa40ec7fc68ab27802f0a01fcd50f3d Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Wed, 30 Jan 2019 14:37:17 +0100
|
||||||
|
Subject: [PATCH] Create feature-test in source directory
|
||||||
|
|
||||||
|
Feature-test tool is used in system tests to test compiled in changes.
|
||||||
|
Because we build more variants of named with different configuration,
|
||||||
|
compile feature-test for each of them this way.
|
||||||
|
---
|
||||||
|
bin/named/Makefile.in | 11 ++++++++++-
|
||||||
|
bin/tests/system/conf.sh.in | 2 +-
|
||||||
|
2 files changed, 11 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/named/Makefile.in b/bin/named/Makefile.in
|
||||||
|
index 3166368..df1f7ee 100644
|
||||||
|
--- a/bin/named/Makefile.in
|
||||||
|
+++ b/bin/named/Makefile.in
|
||||||
|
@@ -80,7 +80,7 @@ NOSYMLIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
|
||||||
|
SUBDIRS = unix
|
||||||
|
|
||||||
|
-TARGETS = named@EXEEXT@ lwresd@EXEEXT@
|
||||||
|
+TARGETS = named@EXEEXT@ lwresd@EXEEXT@ feature-test@EXEEXT@
|
||||||
|
|
||||||
|
GEOIPLINKOBJS = geoip.@O@
|
||||||
|
GEOIP2LINKOBJS = geoip.@O@
|
||||||
|
@@ -163,6 +163,15 @@ lwresd@EXEEXT@: named@EXEEXT@
|
||||||
|
rm -f lwresd@EXEEXT@
|
||||||
|
@LN@ named@EXEEXT@ lwresd@EXEEXT@
|
||||||
|
|
||||||
|
+# Bit of hack, do not produce intermediate .o object for featuretest
|
||||||
|
+feature-test.@O@: ${top_srcdir}/bin/tests/system/feature-test.c
|
||||||
|
+ ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||||
|
+ -c ${top_srcdir}/bin/tests/system/feature-test.c
|
||||||
|
+
|
||||||
|
+feature-test@EXEEXT@: feature-test.@O@
|
||||||
|
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} \
|
||||||
|
+ -o $@ feature-test.@O@ ${ISCLIBS} ${LIBS}
|
||||||
|
+
|
||||||
|
doc man:: ${MANOBJS}
|
||||||
|
|
||||||
|
docclean manclean maintainer-clean::
|
||||||
|
diff --git a/bin/tests/system/conf.sh.in b/bin/tests/system/conf.sh.in
|
||||||
|
index 65c0c5a..117d6ec 100644
|
||||||
|
--- a/bin/tests/system/conf.sh.in
|
||||||
|
+++ b/bin/tests/system/conf.sh.in
|
||||||
|
@@ -71,7 +71,7 @@ DNSTAPREAD=$TOP/bin/tools/dnstap-read
|
||||||
|
MDIG=$TOP/bin/tools/mdig
|
||||||
|
NZD2NZF=$TOP/bin/tools/named-nzd2nzf
|
||||||
|
FSTRM_CAPTURE=@FSTRM_CAPTURE@
|
||||||
|
-FEATURETEST=$TOP/bin/tests/system/feature-test
|
||||||
|
+FEATURETEST=$TOP/bin/named/feature-test
|
||||||
|
|
||||||
|
RANDFILE=$TOP/bin/tests/system/random.data
|
||||||
|
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
1459
bind-9.11-fips-code.patch
Normal file
1459
bind-9.11-fips-code.patch
Normal file
File diff suppressed because it is too large
Load diff
97
bind-9.11-fips-disable.patch
Normal file
97
bind-9.11-fips-disable.patch
Normal file
|
|
@ -0,0 +1,97 @@
|
||||||
|
From df23c869f8973bc9494dcdc86ef46070d8194897 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Mon, 5 Aug 2019 11:54:03 +0200
|
||||||
|
Subject: [PATCH] Allow explicit disabling of autodisabled MD5
|
||||||
|
|
||||||
|
Default security policy might include explicitly disabled RSAMD5
|
||||||
|
algorithm. Current FIPS code automatically disables in FIPS mode. But if
|
||||||
|
RSAMD5 is included in security policy, it fails to start, because that
|
||||||
|
algorithm is not recognized. Allow it disabled, but fail on any
|
||||||
|
other usage.
|
||||||
|
---
|
||||||
|
bin/named/server.c | 2 +-
|
||||||
|
lib/dns/rcode.c | 31 +++++++++++++------------------
|
||||||
|
2 files changed, 14 insertions(+), 19 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/named/server.c b/bin/named/server.c
|
||||||
|
index 3cd49a9..ef82d89 100644
|
||||||
|
--- a/bin/named/server.c
|
||||||
|
+++ b/bin/named/server.c
|
||||||
|
@@ -1551,7 +1551,7 @@ disable_algorithms(const cfg_obj_t *disabled, dns_resolver_t *resolver) {
|
||||||
|
result = isc_parse_uint8(&ui, r.base, 10);
|
||||||
|
alg = ui;
|
||||||
|
}
|
||||||
|
- if (result != ISC_R_SUCCESS) {
|
||||||
|
+ if (result != ISC_R_SUCCESS && result != ISC_R_DISABLED) {
|
||||||
|
cfg_obj_log(cfg_listelt_value(element),
|
||||||
|
ns_g_lctx, ISC_LOG_ERROR,
|
||||||
|
"invalid algorithm");
|
||||||
|
diff --git a/lib/dns/rcode.c b/lib/dns/rcode.c
|
||||||
|
index f51d548..8dbb12d 100644
|
||||||
|
--- a/lib/dns/rcode.c
|
||||||
|
+++ b/lib/dns/rcode.c
|
||||||
|
@@ -126,7 +126,6 @@
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#define SECALGNAMES \
|
||||||
|
- MD5_SECALGNAMES \
|
||||||
|
DH_SECALGNAMES \
|
||||||
|
DSA_SECALGNAMES \
|
||||||
|
{ DNS_KEYALG_ECC, "ECC", 0 }, \
|
||||||
|
@@ -178,6 +177,7 @@ static struct tbl rcodes[] = { RCODENAMES ERCODENAMES };
|
||||||
|
static struct tbl tsigrcodes[] = { RCODENAMES TSIGRCODENAMES };
|
||||||
|
static struct tbl certs[] = { CERTNAMES };
|
||||||
|
static struct tbl secalgs[] = { SECALGNAMES };
|
||||||
|
+static struct tbl md5_secalgs[] = { MD5_SECALGNAMES };
|
||||||
|
static struct tbl secprotos[] = { SECPROTONAMES };
|
||||||
|
static struct tbl hashalgs[] = { HASHALGNAMES };
|
||||||
|
static struct tbl dsdigests[] = { DSDIGESTNAMES };
|
||||||
|
@@ -358,33 +358,28 @@ dns_cert_totext(dns_cert_t cert, isc_buffer_t *target) {
|
||||||
|
return (dns_mnemonic_totext(cert, target, certs));
|
||||||
|
}
|
||||||
|
|
||||||
|
-static inline struct tbl *
|
||||||
|
-secalgs_tbl_start() {
|
||||||
|
- struct tbl *algs = secalgs;
|
||||||
|
-
|
||||||
|
-#ifndef PK11_MD5_DISABLE
|
||||||
|
- if (!isc_md5_available()) {
|
||||||
|
- while (algs->name != NULL &&
|
||||||
|
- algs->value == DNS_KEYALG_RSAMD5)
|
||||||
|
- ++algs;
|
||||||
|
- }
|
||||||
|
-#endif
|
||||||
|
- return algs;
|
||||||
|
-}
|
||||||
|
-
|
||||||
|
isc_result_t
|
||||||
|
dns_secalg_fromtext(dns_secalg_t *secalgp, isc_textregion_t *source) {
|
||||||
|
unsigned int value;
|
||||||
|
+ isc_result_t result;
|
||||||
|
|
||||||
|
- RETERR(dns_mnemonic_fromtext(&value, source,
|
||||||
|
- secalgs_tbl_start(), 0xff));
|
||||||
|
+ result = dns_mnemonic_fromtext(&value, source,
|
||||||
|
+ secalgs, 0xff);
|
||||||
|
+ if (result != ISC_R_SUCCESS) {
|
||||||
|
+ result = dns_mnemonic_fromtext(&value, source,
|
||||||
|
+ md5_secalgs, 0xff);
|
||||||
|
+ if (result != ISC_R_SUCCESS) {
|
||||||
|
+ return (result);
|
||||||
|
+ } else if (!isc_md5_available())
|
||||||
|
+ return (ISC_R_DISABLED);
|
||||||
|
+ }
|
||||||
|
*secalgp = value;
|
||||||
|
return (ISC_R_SUCCESS);
|
||||||
|
}
|
||||||
|
|
||||||
|
isc_result_t
|
||||||
|
dns_secalg_totext(dns_secalg_t secalg, isc_buffer_t *target) {
|
||||||
|
- return (dns_mnemonic_totext(secalg, target, secalgs_tbl_start()));
|
||||||
|
+ return (dns_mnemonic_totext(secalg, target, secalgs));
|
||||||
|
}
|
||||||
|
|
||||||
|
void
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
1408
bind-9.11-fips-tests.patch
Normal file
1408
bind-9.11-fips-tests.patch
Normal file
File diff suppressed because it is too large
Load diff
92
bind-9.11-host-idn-disable.patch
Normal file
92
bind-9.11-host-idn-disable.patch
Normal file
|
|
@ -0,0 +1,92 @@
|
||||||
|
From ec50eff97c259b5bfbfa4e050d69fe7b39b0f15a Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Tue, 25 Sep 2018 18:08:46 +0200
|
||||||
|
Subject: [PATCH] Disable IDN from environment as documented
|
||||||
|
|
||||||
|
Manual page of host contained instructions to disable IDN processing
|
||||||
|
when it was built with libidn2. When refactoring IDN support however,
|
||||||
|
support for disabling IDN in host and nslookup was lost. Use also
|
||||||
|
environment variable and document it for nslookup, host and dig.
|
||||||
|
|
||||||
|
Support variable CHARSET=ASCII to disable IDN, supported in downstream
|
||||||
|
RH patch since RHEL 5.
|
||||||
|
---
|
||||||
|
bin/dig/dig.docbook | 4 +++-
|
||||||
|
bin/dig/dighost.c | 5 +++++
|
||||||
|
bin/dig/host.docbook | 2 +-
|
||||||
|
bin/dig/nslookup.docbook | 15 +++++++++++++++
|
||||||
|
4 files changed, 24 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/dig/dig.docbook b/bin/dig/dig.docbook
|
||||||
|
index 5d19301..933af79 100644
|
||||||
|
--- a/bin/dig/dig.docbook
|
||||||
|
+++ b/bin/dig/dig.docbook
|
||||||
|
@@ -1312,7 +1312,9 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
||||||
|
reply from the server.
|
||||||
|
If you'd like to turn off the IDN support for some reason, use
|
||||||
|
parameters <parameter>+noidnin</parameter> and
|
||||||
|
- <parameter>+noidnout</parameter>.
|
||||||
|
+ <parameter>+noidnout</parameter> or define
|
||||||
|
+ the <envar>IDN_DISABLE</envar> environment variable.
|
||||||
|
+
|
||||||
|
</para>
|
||||||
|
</refsection>
|
||||||
|
|
||||||
|
diff --git a/bin/dig/dighost.c b/bin/dig/dighost.c
|
||||||
|
index 5eabc1f..73aaab8 100644
|
||||||
|
--- a/bin/dig/dighost.c
|
||||||
|
+++ b/bin/dig/dighost.c
|
||||||
|
@@ -826,6 +826,11 @@ make_empty_lookup(void) {
|
||||||
|
looknew->badcookie = true;
|
||||||
|
#ifdef WITH_IDN_SUPPORT
|
||||||
|
looknew->idnin = isatty(1)?(getenv("IDN_DISABLE") == NULL):false;
|
||||||
|
+ if (looknew->idnin) {
|
||||||
|
+ const char *charset = getenv("CHARSET");
|
||||||
|
+ if (charset && !strcmp(charset, "ASCII"))
|
||||||
|
+ looknew->idnin = false;
|
||||||
|
+ }
|
||||||
|
#else
|
||||||
|
looknew->idnin = false;
|
||||||
|
#endif
|
||||||
|
diff --git a/bin/dig/host.docbook b/bin/dig/host.docbook
|
||||||
|
index da0f8fb..9689b5a 100644
|
||||||
|
--- a/bin/dig/host.docbook
|
||||||
|
+++ b/bin/dig/host.docbook
|
||||||
|
@@ -379,7 +379,7 @@
|
||||||
|
<command>host</command> appropriately converts character encoding of
|
||||||
|
domain name before sending a request to DNS server or displaying a
|
||||||
|
reply from the server.
|
||||||
|
- If you'd like to turn off the IDN support for some reason, defines
|
||||||
|
+ If you'd like to turn off the IDN support for some reason, define
|
||||||
|
the <envar>IDN_DISABLE</envar> environment variable.
|
||||||
|
The IDN support is disabled if the variable is set when
|
||||||
|
<command>host</command> runs.
|
||||||
|
diff --git a/bin/dig/nslookup.docbook b/bin/dig/nslookup.docbook
|
||||||
|
index d46fc2d..6d7d181 100644
|
||||||
|
--- a/bin/dig/nslookup.docbook
|
||||||
|
+++ b/bin/dig/nslookup.docbook
|
||||||
|
@@ -495,6 +495,21 @@ nslookup -query=hinfo -timeout=10
|
||||||
|
</para>
|
||||||
|
</refsection>
|
||||||
|
|
||||||
|
+ <refsection><info><title>IDN SUPPORT</title></info>
|
||||||
|
+
|
||||||
|
+ <para>
|
||||||
|
+ If <command>nslookup</command> has been built with IDN (internationalized
|
||||||
|
+ domain name) support, it can accept and display non-ASCII domain names.
|
||||||
|
+ <command>nslookup</command> appropriately converts character encoding of
|
||||||
|
+ domain name before sending a request to DNS server or displaying a
|
||||||
|
+ reply from the server.
|
||||||
|
+ If you'd like to turn off the IDN support for some reason, define
|
||||||
|
+ the <envar>IDN_DISABLE</envar> environment variable.
|
||||||
|
+ The IDN support is disabled if the variable is set when
|
||||||
|
+ <command>nslookup</command> runs.
|
||||||
|
+ </para>
|
||||||
|
+ </refsection>
|
||||||
|
+
|
||||||
|
<refsection><info><title>FILES</title></info>
|
||||||
|
|
||||||
|
<para><filename>/etc/resolv.conf</filename>
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
50
bind-9.11-json-c.patch
Normal file
50
bind-9.11-json-c.patch
Normal file
|
|
@ -0,0 +1,50 @@
|
||||||
|
From cb6d2019766a6c8c5516fd8859cedf0052f03293 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Thu, 25 Jul 2019 11:37:57 +0200
|
||||||
|
Subject: [PATCH] Skip support of jsoncpp
|
||||||
|
|
||||||
|
Bind cannot be compiled when jsoncpp-devel is installed. Remove support
|
||||||
|
for jsoncpp, use only json-c-devel. Bind 9.15 has already support for
|
||||||
|
--with-json-c, do not yet introduce it.
|
||||||
|
---
|
||||||
|
configure.ac | 17 ++---------------
|
||||||
|
1 file changed, 2 insertions(+), 15 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/configure.ac b/configure.ac
|
||||||
|
index 6d05337..5ce83b5 100644
|
||||||
|
--- a/configure.ac
|
||||||
|
+++ b/configure.ac
|
||||||
|
@@ -2594,15 +2594,7 @@ case "$use_libjson" in
|
||||||
|
auto|yes)
|
||||||
|
for d in /usr /usr/local /opt/local
|
||||||
|
do
|
||||||
|
- if test -f "${d}/include/json/json.h"
|
||||||
|
- then
|
||||||
|
- if test ${d} != /usr
|
||||||
|
- then
|
||||||
|
- libjson_cflags="-I ${d}/include"
|
||||||
|
- LIBS="$LIBS -L${d}/lib"
|
||||||
|
- fi
|
||||||
|
- have_libjson="yes"
|
||||||
|
- elif test -f "${d}/include/json-c/json.h"
|
||||||
|
+ if test -f "${d}/include/json-c/json.h"
|
||||||
|
then
|
||||||
|
if test ${d} != /usr
|
||||||
|
then
|
||||||
|
@@ -2615,12 +2607,7 @@ case "$use_libjson" in
|
||||||
|
done
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
- if test -f "${use_libjson}/include/json/json.h"
|
||||||
|
- then
|
||||||
|
- libjson_cflags="-I${use_libjson}/include"
|
||||||
|
- LIBS="$LIBS -L${use_libjson}/lib"
|
||||||
|
- have_libjson="yes"
|
||||||
|
- elif test -f "${use_libjson}/include/json-c/json.h"
|
||||||
|
+ if test -f "${use_libjson}/include/json-c/json.h"
|
||||||
|
then
|
||||||
|
libjson_cflags="-I${use_libjson}/include"
|
||||||
|
LIBS="$LIBS -L${use_libjson}/lib"
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
192
bind-9.11-kyua-pkcs11.patch
Normal file
192
bind-9.11-kyua-pkcs11.patch
Normal file
|
|
@ -0,0 +1,192 @@
|
||||||
|
From eb38d2278937ec3fe45d0af30cd080953bbb5b54 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Tue, 2 Jan 2018 18:13:07 +0100
|
||||||
|
Subject: [PATCH] Fix pkcs11 variants atf tests
|
||||||
|
|
||||||
|
Add dns-pkcs11 tests Makefile to configure
|
||||||
|
|
||||||
|
Add pkcs11 Kyuafile, fix dh_test to pass in pkcs11 mode
|
||||||
|
---
|
||||||
|
configure.ac | 1 +
|
||||||
|
lib/Kyuafile | 2 ++
|
||||||
|
lib/dns-pkcs11/tests/Makefile.in | 10 +++++-----
|
||||||
|
lib/dns-pkcs11/tests/dh_test.c | 3 ++-
|
||||||
|
lib/isc-pkcs11/tests/Makefile.in | 6 +++---
|
||||||
|
lib/isc-pkcs11/tests/hash_test.c | 32 +++++++++++++++++++++++++-------
|
||||||
|
6 files changed, 38 insertions(+), 16 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/configure.ac b/configure.ac
|
||||||
|
index 0532feb..a83ddd5 100644
|
||||||
|
--- a/configure.ac
|
||||||
|
+++ b/configure.ac
|
||||||
|
@@ -5578,6 +5578,7 @@ AC_CONFIG_FILES([
|
||||||
|
lib/dns-pkcs11/include/Makefile
|
||||||
|
lib/dns-pkcs11/include/dns/Makefile
|
||||||
|
lib/dns-pkcs11/include/dst/Makefile
|
||||||
|
+ lib/dns-pkcs11/tests/Makefile
|
||||||
|
lib/irs/Makefile
|
||||||
|
lib/irs/include/Makefile
|
||||||
|
lib/irs/include/irs/Makefile
|
||||||
|
diff --git a/lib/Kyuafile b/lib/Kyuafile
|
||||||
|
index 7c8bab0..eec9564 100644
|
||||||
|
--- a/lib/Kyuafile
|
||||||
|
+++ b/lib/Kyuafile
|
||||||
|
@@ -2,8 +2,10 @@ syntax(2)
|
||||||
|
test_suite('bind9')
|
||||||
|
|
||||||
|
include('dns/Kyuafile')
|
||||||
|
+include('dns-pkcs11/Kyuafile')
|
||||||
|
include('irs/Kyuafile')
|
||||||
|
include('isc/Kyuafile')
|
||||||
|
+include('isc-pkcs11/Kyuafile')
|
||||||
|
include('isccc/Kyuafile')
|
||||||
|
include('isccfg/Kyuafile')
|
||||||
|
include('lwres/Kyuafile')
|
||||||
|
diff --git a/lib/dns-pkcs11/tests/Makefile.in b/lib/dns-pkcs11/tests/Makefile.in
|
||||||
|
index 7671e1d..e237d5c 100644
|
||||||
|
--- a/lib/dns-pkcs11/tests/Makefile.in
|
||||||
|
+++ b/lib/dns-pkcs11/tests/Makefile.in
|
||||||
|
@@ -17,12 +17,12 @@ VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
|
CINCLUDES = -I. -Iinclude ${DNS_INCLUDES} ${ISC_INCLUDES} \
|
||||||
|
@DST_OPENSSL_INC@
|
||||||
|
-CDEFINES = @CRYPTO@ -DTESTS="\"${top_builddir}/lib/dns/tests/\""
|
||||||
|
+CDEFINES = @CRYPTO_PK11@ -DTESTS="\"${top_builddir}/lib/dns-pkcs11/tests/\""
|
||||||
|
|
||||||
|
-ISCLIBS = ../../isc/libisc.@A@
|
||||||
|
-ISCDEPLIBS = ../../isc/libisc.@A@
|
||||||
|
-DNSLIBS = ../libdns.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
|
-DNSDEPLIBS = ../libdns.@A@
|
||||||
|
+ISCLIBS = ../../isc-pkcs11/libisc-pkcs11.@A@
|
||||||
|
+ISCDEPLIBS = ../../isc-pkcs11/libisc-pkcs11.@A@
|
||||||
|
+DNSLIBS = ../libdns-pkcs11.@A@ ${MAXMINDDB_LIBS} @DNS_CRYPTO_LIBS@
|
||||||
|
+DNSDEPLIBS = ../libdns-pkcs11.@A@
|
||||||
|
|
||||||
|
LIBS = @LIBS@ @CMOCKA_LIBS@
|
||||||
|
CFLAGS = @CFLAGS@ @CMOCKA_CFLAGS@
|
||||||
|
diff --git a/lib/dns-pkcs11/tests/dh_test.c b/lib/dns-pkcs11/tests/dh_test.c
|
||||||
|
index 4dbfd82..a383b8e 100644
|
||||||
|
--- a/lib/dns-pkcs11/tests/dh_test.c
|
||||||
|
+++ b/lib/dns-pkcs11/tests/dh_test.c
|
||||||
|
@@ -86,7 +86,8 @@ dh_computesecret(void **state) {
|
||||||
|
result = dst_key_computesecret(key, key, &buf);
|
||||||
|
assert_int_equal(result, DST_R_NOTPRIVATEKEY);
|
||||||
|
result = key->func->computesecret(key, key, &buf);
|
||||||
|
- assert_int_equal(result, DST_R_COMPUTESECRETFAILURE);
|
||||||
|
+ /* PKCS11 variant gives different result, accept both */
|
||||||
|
+ assert_true(result == DST_R_COMPUTESECRETFAILURE || result == DST_R_INVALIDPRIVATEKEY);
|
||||||
|
|
||||||
|
dst_key_free(&key);
|
||||||
|
}
|
||||||
|
diff --git a/lib/isc-pkcs11/tests/Makefile.in b/lib/isc-pkcs11/tests/Makefile.in
|
||||||
|
index 2fdee0b..a263b35 100644
|
||||||
|
--- a/lib/isc-pkcs11/tests/Makefile.in
|
||||||
|
+++ b/lib/isc-pkcs11/tests/Makefile.in
|
||||||
|
@@ -16,10 +16,10 @@ VERSION=@BIND9_VERSION@
|
||||||
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
|
CINCLUDES = -I. -Iinclude ${ISC_INCLUDES} @ISC_OPENSSL_INC@
|
||||||
|
-CDEFINES = @CRYPTO@ -DTESTS="\"${top_builddir}/lib/isc/tests/\""
|
||||||
|
+CDEFINES = @CRYPTO_PK11@ -DTESTS="\"${top_builddir}/lib/isc-pkcs11/tests/\""
|
||||||
|
|
||||||
|
-ISCLIBS = ../libisc.@A@ @ISC_OPENSSL_LIBS@
|
||||||
|
-ISCDEPLIBS = ../libisc.@A@
|
||||||
|
+ISCLIBS = ../libisc-pkcs11.@A@ @ISC_OPENSSL_LIBS@
|
||||||
|
+ISCDEPLIBS = ../libisc-pkcs11.@A@
|
||||||
|
|
||||||
|
LIBS = @LIBS@ @CMOCKA_LIBS@
|
||||||
|
CFLAGS = @CFLAGS@ @CMOCKA_CFLAGS@
|
||||||
|
diff --git a/lib/isc-pkcs11/tests/hash_test.c b/lib/isc-pkcs11/tests/hash_test.c
|
||||||
|
index 9c4d299..d9deba2 100644
|
||||||
|
--- a/lib/isc-pkcs11/tests/hash_test.c
|
||||||
|
+++ b/lib/isc-pkcs11/tests/hash_test.c
|
||||||
|
@@ -85,7 +85,7 @@ typedef struct hash_testcase {
|
||||||
|
|
||||||
|
typedef struct hash_test_key {
|
||||||
|
const char *key;
|
||||||
|
- const int len;
|
||||||
|
+ const unsigned len;
|
||||||
|
} hash_test_key_t;
|
||||||
|
|
||||||
|
/* non-hmac tests */
|
||||||
|
@@ -956,8 +956,11 @@ isc_hmacsha1_test(void **state) {
|
||||||
|
hash_test_key_t *test_key = test_keys;
|
||||||
|
|
||||||
|
while (testcase->input != NULL && testcase->result != NULL) {
|
||||||
|
+ int len = ISC_MAX(test_key->len, ISC_SHA1_DIGESTLENGTH);
|
||||||
|
+
|
||||||
|
+ memset(buffer, 0, ISC_SHA1_DIGESTLENGTH);
|
||||||
|
memmove(buffer, test_key->key, test_key->len);
|
||||||
|
- isc_hmacsha1_init(&hmacsha1, buffer, test_key->len);
|
||||||
|
+ isc_hmacsha1_init(&hmacsha1, buffer, len);
|
||||||
|
isc_hmacsha1_update(&hmacsha1,
|
||||||
|
(const uint8_t *) testcase->input,
|
||||||
|
testcase->input_len);
|
||||||
|
@@ -1116,8 +1119,11 @@ isc_hmacsha224_test(void **state) {
|
||||||
|
hash_test_key_t *test_key = test_keys;
|
||||||
|
|
||||||
|
while (testcase->input != NULL && testcase->result != NULL) {
|
||||||
|
+ int len = ISC_MAX(test_key->len, ISC_SHA224_DIGESTLENGTH);
|
||||||
|
+
|
||||||
|
+ memset(buffer, 0, ISC_SHA224_DIGESTLENGTH);
|
||||||
|
memmove(buffer, test_key->key, test_key->len);
|
||||||
|
- isc_hmacsha224_init(&hmacsha224, buffer, test_key->len);
|
||||||
|
+ isc_hmacsha224_init(&hmacsha224, buffer, len);
|
||||||
|
isc_hmacsha224_update(&hmacsha224,
|
||||||
|
(const uint8_t *) testcase->input,
|
||||||
|
testcase->input_len);
|
||||||
|
@@ -1277,8 +1283,11 @@ isc_hmacsha256_test(void **state) {
|
||||||
|
hash_test_key_t *test_key = test_keys;
|
||||||
|
|
||||||
|
while (testcase->input != NULL && testcase->result != NULL) {
|
||||||
|
+ int len = ISC_MAX(test_key->len, ISC_SHA256_DIGESTLENGTH);
|
||||||
|
+
|
||||||
|
+ memset(buffer, 0, ISC_SHA256_DIGESTLENGTH);
|
||||||
|
memmove(buffer, test_key->key, test_key->len);
|
||||||
|
- isc_hmacsha256_init(&hmacsha256, buffer, test_key->len);
|
||||||
|
+ isc_hmacsha256_init(&hmacsha256, buffer, len);
|
||||||
|
isc_hmacsha256_update(&hmacsha256,
|
||||||
|
(const uint8_t *) testcase->input,
|
||||||
|
testcase->input_len);
|
||||||
|
@@ -1444,8 +1453,11 @@ isc_hmacsha384_test(void **state) {
|
||||||
|
hash_test_key_t *test_key = test_keys;
|
||||||
|
|
||||||
|
while (testcase->input != NULL && testcase->result != NULL) {
|
||||||
|
+ int len = ISC_MAX(test_key->len, ISC_SHA384_DIGESTLENGTH);
|
||||||
|
+
|
||||||
|
+ memset(buffer, 0, ISC_SHA384_DIGESTLENGTH);
|
||||||
|
memmove(buffer, test_key->key, test_key->len);
|
||||||
|
- isc_hmacsha384_init(&hmacsha384, buffer, test_key->len);
|
||||||
|
+ isc_hmacsha384_init(&hmacsha384, buffer, len);
|
||||||
|
isc_hmacsha384_update(&hmacsha384,
|
||||||
|
(const uint8_t *) testcase->input,
|
||||||
|
testcase->input_len);
|
||||||
|
@@ -1611,8 +1623,11 @@ isc_hmacsha512_test(void **state) {
|
||||||
|
hash_test_key_t *test_key = test_keys;
|
||||||
|
|
||||||
|
while (testcase->input != NULL && testcase->result != NULL) {
|
||||||
|
+ int len = ISC_MAX(test_key->len, ISC_SHA512_DIGESTLENGTH);
|
||||||
|
+
|
||||||
|
+ memset(buffer, 0, ISC_SHA512_DIGESTLENGTH);
|
||||||
|
memmove(buffer, test_key->key, test_key->len);
|
||||||
|
- isc_hmacsha512_init(&hmacsha512, buffer, test_key->len);
|
||||||
|
+ isc_hmacsha512_init(&hmacsha512, buffer, len);
|
||||||
|
isc_hmacsha512_update(&hmacsha512,
|
||||||
|
(const uint8_t *) testcase->input,
|
||||||
|
testcase->input_len);
|
||||||
|
@@ -1755,8 +1770,11 @@ isc_hmacmd5_test(void **state) {
|
||||||
|
hash_test_key_t *test_key = test_keys;
|
||||||
|
|
||||||
|
while (testcase->input != NULL && testcase->result != NULL) {
|
||||||
|
+ int len = ISC_MAX(test_key->len, ISC_MD5_DIGESTLENGTH);
|
||||||
|
+
|
||||||
|
+ memset(buffer, 0, ISC_MD5_DIGESTLENGTH);
|
||||||
|
memmove(buffer, test_key->key, test_key->len);
|
||||||
|
- isc_hmacmd5_init(&hmacmd5, buffer, test_key->len);
|
||||||
|
+ isc_hmacmd5_init(&hmacmd5, buffer, len);
|
||||||
|
isc_hmacmd5_update(&hmacmd5,
|
||||||
|
(const uint8_t *) testcase->input,
|
||||||
|
testcase->input_len);
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
256
bind-9.11-oot-manual.patch
Normal file
256
bind-9.11-oot-manual.patch
Normal file
|
|
@ -0,0 +1,256 @@
|
||||||
|
From 8ca95f47231822df2b9c171a4da1e93ca5b748eb Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Wed, 25 Jul 2018 12:24:16 +0200
|
||||||
|
Subject: [PATCH] Use make automatic variables to install updated manuals
|
||||||
|
|
||||||
|
Make will choose modified manual from build directory or original from source
|
||||||
|
directory automagically. Take advantage of install tool feature.
|
||||||
|
Install all files in single command instead of iterating on each of them.
|
||||||
|
---
|
||||||
|
bin/check/Makefile.in | 8 +++++---
|
||||||
|
bin/confgen/Makefile.in | 9 +++++----
|
||||||
|
bin/delv/Makefile.in | 6 ++++--
|
||||||
|
bin/dig/Makefile.in | 8 ++++----
|
||||||
|
bin/dnssec/Makefile.in | 6 ++++--
|
||||||
|
bin/named/Makefile.in | 13 +++++++++----
|
||||||
|
bin/pkcs11/Makefile.in | 9 ++++-----
|
||||||
|
bin/python/Makefile.in | 8 ++++----
|
||||||
|
bin/tools/Makefile.in | 25 +++++++++++++++----------
|
||||||
|
9 files changed, 54 insertions(+), 38 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/check/Makefile.in b/bin/check/Makefile.in
|
||||||
|
index c124e80..1174f8d 100644
|
||||||
|
--- a/bin/check/Makefile.in
|
||||||
|
+++ b/bin/check/Makefile.in
|
||||||
|
@@ -83,12 +83,14 @@ installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
-install:: named-checkconf@EXEEXT@ named-checkzone@EXEEXT@ installdirs
|
||||||
|
+install-man8: ${MANPAGES}
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
||||||
|
+ (cd ${DESTDIR}${mandir}/man8; rm -f named-compilezone.8; ${LINK_PROGRAM} named-checkzone.8 named-compilezone.8)
|
||||||
|
+
|
||||||
|
+install:: named-checkconf@EXEEXT@ named-checkzone@EXEEXT@ installdirs install-man8
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-checkconf@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-checkzone@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
(cd ${DESTDIR}${sbindir}; rm -f named-compilezone@EXEEXT@; ${LINK_PROGRAM} named-checkzone@EXEEXT@ named-compilezone@EXEEXT@)
|
||||||
|
- for m in ${MANPAGES}; do ${INSTALL_DATA} ${srcdir}/$$m ${DESTDIR}${mandir}/man8 || exit 1; done
|
||||||
|
- (cd ${DESTDIR}${mandir}/man8; rm -f named-compilezone.8; ${LINK_PROGRAM} named-checkzone.8 named-compilezone.8)
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
rm -f ${DESTDIR}${mandir}/man8/named-compilezone.8
|
||||||
|
diff --git a/bin/confgen/Makefile.in b/bin/confgen/Makefile.in
|
||||||
|
index 87f13dd..7865c0c 100644
|
||||||
|
--- a/bin/confgen/Makefile.in
|
||||||
|
+++ b/bin/confgen/Makefile.in
|
||||||
|
@@ -95,13 +95,14 @@ installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
-install:: rndc-confgen@EXEEXT@ ddns-confgen@EXEEXT@ installdirs
|
||||||
|
+install-man8: rndc-confgen.8 ddns-confgen.8
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
||||||
|
+ (cd ${DESTDIR}${mandir}/man8; rm -f tsig-keygen.8; ${LINK_PROGRAM} ddns-confgen.8 tsig-keygen.8)
|
||||||
|
+
|
||||||
|
+install:: rndc-confgen@EXEEXT@ ddns-confgen@EXEEXT@ installdirs install-man8
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} rndc-confgen@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} ddns-confgen@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/rndc-confgen.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/ddns-confgen.8 ${DESTDIR}${mandir}/man8
|
||||||
|
(cd ${DESTDIR}${sbindir}; rm -f tsig-keygen@EXEEXT@; ${LINK_PROGRAM} ddns-confgen@EXEEXT@ tsig-keygen@EXEEXT@)
|
||||||
|
- (cd ${DESTDIR}${mandir}/man8; rm -f tsig-keygen.8; ${LINK_PROGRAM} ddns-confgen.8 tsig-keygen.8)
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
rm -f ${DESTDIR}${mandir}/man8/tsig-keygen.8
|
||||||
|
diff --git a/bin/delv/Makefile.in b/bin/delv/Makefile.in
|
||||||
|
index e2d2802..19361a8 100644
|
||||||
|
--- a/bin/delv/Makefile.in
|
||||||
|
+++ b/bin/delv/Makefile.in
|
||||||
|
@@ -63,10 +63,12 @@ installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${bindir}
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
||||||
|
|
||||||
|
-install:: delv@EXEEXT@ installdirs
|
||||||
|
+install-man1: delv.1
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man1
|
||||||
|
+
|
||||||
|
+install:: delv@EXEEXT@ installdirs install-man1
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} \
|
||||||
|
delv@EXEEXT@ ${DESTDIR}${bindir}
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/delv.1 ${DESTDIR}${mandir}/man1
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
rm -f ${DESTDIR}${mandir}/man1/delv.1
|
||||||
|
diff --git a/bin/dig/Makefile.in b/bin/dig/Makefile.in
|
||||||
|
index a9830a9..d7ac0b6 100644
|
||||||
|
--- a/bin/dig/Makefile.in
|
||||||
|
+++ b/bin/dig/Makefile.in
|
||||||
|
@@ -91,16 +91,16 @@ installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${bindir}
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
||||||
|
|
||||||
|
-install:: dig@EXEEXT@ host@EXEEXT@ nslookup@EXEEXT@ installdirs
|
||||||
|
+install-man1: ${MANPAGES}
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man1
|
||||||
|
+
|
||||||
|
+install:: dig@EXEEXT@ host@EXEEXT@ nslookup@EXEEXT@ installdirs install-man1
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} \
|
||||||
|
dig@EXEEXT@ ${DESTDIR}${bindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} \
|
||||||
|
host@EXEEXT@ ${DESTDIR}${bindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} \
|
||||||
|
nslookup@EXEEXT@ ${DESTDIR}${bindir}
|
||||||
|
- for m in ${MANPAGES}; do \
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/$$m ${DESTDIR}${mandir}/man1 || exit 1; \
|
||||||
|
- done
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
for m in ${MANPAGES}; do \
|
||||||
|
diff --git a/bin/dnssec/Makefile.in b/bin/dnssec/Makefile.in
|
||||||
|
index 2239ad1..ce0a177 100644
|
||||||
|
--- a/bin/dnssec/Makefile.in
|
||||||
|
+++ b/bin/dnssec/Makefile.in
|
||||||
|
@@ -110,9 +110,11 @@ installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
-install:: ${TARGETS} installdirs
|
||||||
|
+install-man8: ${MANPAGES}
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
||||||
|
+
|
||||||
|
+install:: ${TARGETS} installdirs install-man8
|
||||||
|
for t in ${TARGETS}; do ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} $$t ${DESTDIR}${sbindir} || exit 1; done
|
||||||
|
- for m in ${MANPAGES}; do ${INSTALL_DATA} ${srcdir}/$$m ${DESTDIR}${mandir}/man8 || exit 1; done
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
for m in ${MANPAGES}; do rm -f ${DESTDIR}${mandir}/man8/$$m || exit 1; done
|
||||||
|
diff --git a/bin/named/Makefile.in b/bin/named/Makefile.in
|
||||||
|
index e1f85a9..d92bc9a 100644
|
||||||
|
--- a/bin/named/Makefile.in
|
||||||
|
+++ b/bin/named/Makefile.in
|
||||||
|
@@ -176,12 +176,17 @@ installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man5
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
-install:: named@EXEEXT@ lwresd@EXEEXT@ installdirs
|
||||||
|
+install-man5: named.conf.5
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man5
|
||||||
|
+
|
||||||
|
+install-man8: named.8 lwresd.8
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
||||||
|
+
|
||||||
|
+install-man: install-man5 install-man8
|
||||||
|
+
|
||||||
|
+install:: named@EXEEXT@ lwresd@EXEEXT@ installdirs install-man
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
(cd ${DESTDIR}${sbindir}; rm -f lwresd@EXEEXT@; @LN@ named@EXEEXT@ lwresd@EXEEXT@)
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/named.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/lwresd.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/named.conf.5 ${DESTDIR}${mandir}/man5
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
rm -f ${DESTDIR}${mandir}/man5/named.conf.5
|
||||||
|
diff --git a/bin/pkcs11/Makefile.in b/bin/pkcs11/Makefile.in
|
||||||
|
index ae90616..a058c91 100644
|
||||||
|
--- a/bin/pkcs11/Makefile.in
|
||||||
|
+++ b/bin/pkcs11/Makefile.in
|
||||||
|
@@ -71,7 +71,10 @@ installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
-install:: ${TARGETS} installdirs
|
||||||
|
+install-man8: ${MANPAGES}
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
||||||
|
+
|
||||||
|
+install:: ${TARGETS} installdirs install-man8
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} pkcs11-list@EXEEXT@ \
|
||||||
|
${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} pkcs11-destroy@EXEEXT@ \
|
||||||
|
@@ -80,10 +83,6 @@ install:: ${TARGETS} installdirs
|
||||||
|
${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} pkcs11-tokens@EXEEXT@ \
|
||||||
|
${DESTDIR}${sbindir}
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/pkcs11-list.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/pkcs11-destroy.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/pkcs11-keygen.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/pkcs11-tokens.8 ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
rm -f ${DESTDIR}${mandir}/man8/pkcs11-tokens.8
|
||||||
|
diff --git a/bin/python/Makefile.in b/bin/python/Makefile.in
|
||||||
|
index aa678d4..064c404 100644
|
||||||
|
--- a/bin/python/Makefile.in
|
||||||
|
+++ b/bin/python/Makefile.in
|
||||||
|
@@ -47,13 +47,13 @@ installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
-install:: ${TARGETS} installdirs
|
||||||
|
+install-man8: ${MANPAGES}
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
||||||
|
+
|
||||||
|
+install:: ${TARGETS} installdirs install-man8
|
||||||
|
${INSTALL_SCRIPT} dnssec-checkds ${DESTDIR}${sbindir}
|
||||||
|
${INSTALL_SCRIPT} dnssec-coverage ${DESTDIR}${sbindir}
|
||||||
|
${INSTALL_SCRIPT} dnssec-keymgr ${DESTDIR}${sbindir}
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/dnssec-checkds.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/dnssec-coverage.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/dnssec-keymgr.8 ${DESTDIR}${mandir}/man8
|
||||||
|
if test -n "${PYTHON}" ; then \
|
||||||
|
if test -n "${DESTDIR}" ; then \
|
||||||
|
${PYTHON} ${srcdir}/setup.py install --root=${DESTDIR} --prefix=${prefix} @PYTHON_INSTALL_LIB@ ; \
|
||||||
|
diff --git a/bin/tools/Makefile.in b/bin/tools/Makefile.in
|
||||||
|
index 7bf2af4..c395bc7 100644
|
||||||
|
--- a/bin/tools/Makefile.in
|
||||||
|
+++ b/bin/tools/Makefile.in
|
||||||
|
@@ -119,17 +119,27 @@ installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
-nzd:
|
||||||
|
+nzd-man: named-nzd2nzf.8
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
||||||
|
+
|
||||||
|
+nzd: nzd-man
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-nzd2nzf@EXEEXT@ \
|
||||||
|
${DESTDIR}${sbindir}
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/named-nzd2nzf.8 ${DESTDIR}${mandir}/man8
|
||||||
|
|
||||||
|
-dnstap:
|
||||||
|
+dnstap-man: dnstap-read.1
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man1
|
||||||
|
+
|
||||||
|
+dnstap: dnstap-man
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} dnstap-read@EXEEXT@ \
|
||||||
|
${DESTDIR}${bindir}
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/dnstap-read.1 ${DESTDIR}${mandir}/man1
|
||||||
|
|
||||||
|
-install:: ${TARGETS} installdirs @DNSTAP@ @NZD_TOOLS@
|
||||||
|
+install-man1: arpaname.1 named-rrchecker.1 mdig.1
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man1
|
||||||
|
+
|
||||||
|
+install-man8: named-journalprint.8 nsec3hash.8
|
||||||
|
+ ${INSTALL_DATA} $^ ${DESTDIR}${mandir}/man8
|
||||||
|
+
|
||||||
|
+install:: ${TARGETS} installdirs @DNSTAP@ @NZD_TOOLS@ install-man1 install-man8
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} arpaname@EXEEXT@ \
|
||||||
|
${DESTDIR}${bindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} named-journalprint@EXEEXT@ \
|
||||||
|
@@ -144,13 +154,8 @@ install:: ${TARGETS} installdirs @DNSTAP@ @NZD_TOOLS@
|
||||||
|
${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} mdig@EXEEXT@ \
|
||||||
|
${DESTDIR}${bindir}
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/arpaname.1 ${DESTDIR}${mandir}/man1
|
||||||
|
${INSTALL_DATA} ${srcdir}/isc-hmac-fixup.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/named-journalprint.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/named-rrchecker.1 ${DESTDIR}${mandir}/man1
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/nsec3hash.8 ${DESTDIR}${mandir}/man8
|
||||||
|
${INSTALL_DATA} ${srcdir}/genrandom.8 ${DESTDIR}${mandir}/man8
|
||||||
|
- ${INSTALL_DATA} ${srcdir}/mdig.1 ${DESTDIR}${mandir}/man1
|
||||||
|
|
||||||
|
uninstall::
|
||||||
|
rm -f ${DESTDIR}${mandir}/man1/mdig.1
|
||||||
|
--
|
||||||
|
2.14.4
|
||||||
|
|
||||||
27
bind-9.11-pk11.patch
Normal file
27
bind-9.11-pk11.patch
Normal file
|
|
@ -0,0 +1,27 @@
|
||||||
|
diff --git a/lib/dns/dst_internal.h b/lib/dns/dst_internal.h
|
||||||
|
index 640519a..fc40472 100644
|
||||||
|
--- a/lib/dns/dst_internal.h
|
||||||
|
+++ b/lib/dns/dst_internal.h
|
||||||
|
@@ -59,6 +59,9 @@
|
||||||
|
#include <openssl/objects.h>
|
||||||
|
#include <openssl/rsa.h>
|
||||||
|
#endif
|
||||||
|
+#if PKCS11CRYPTO
|
||||||
|
+#include <pk11/pk11.h>
|
||||||
|
+#endif
|
||||||
|
|
||||||
|
ISC_LANG_BEGINDECLS
|
||||||
|
|
||||||
|
diff --git a/lib/isc/include/pk11/internal.h b/lib/isc/include/pk11/internal.h
|
||||||
|
index aa8907a..603712a 100644
|
||||||
|
--- a/lib/isc/include/pk11/internal.h
|
||||||
|
+++ b/lib/isc/include/pk11/internal.h
|
||||||
|
@@ -13,6 +13,8 @@
|
||||||
|
#ifndef PK11_INTERNAL_H
|
||||||
|
#define PK11_INTERNAL_H 1
|
||||||
|
|
||||||
|
+#include <pk11/pk11.h>
|
||||||
|
+
|
||||||
|
/*! \file pk11/internal.h */
|
||||||
|
|
||||||
|
ISC_LANG_BEGINDECLS
|
||||||
120
bind-9.11-rh1205168.patch
Normal file
120
bind-9.11-rh1205168.patch
Normal file
|
|
@ -0,0 +1,120 @@
|
||||||
|
From 90416594843a56550e40b11561807786219ce1c4 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Evan Hunt <each@isc.org>
|
||||||
|
Date: Mon, 11 Sep 2017 15:01:36 -0700
|
||||||
|
Subject: [PATCH] remap getaddrinfo() to irs_getgetaddrinfo()
|
||||||
|
|
||||||
|
The libirs version of getaddrinfo() cannot be called from within BIND9.
|
||||||
|
|
||||||
|
fix prototypes
|
||||||
|
---
|
||||||
|
lib/irs/include/irs/netdb.h.in | 94 ++++++++++++++++++++++++++++++++++++++++++
|
||||||
|
1 file changed, 94 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/lib/irs/include/irs/netdb.h.in b/lib/irs/include/irs/netdb.h.in
|
||||||
|
index 23dcd37..f36113d 100644
|
||||||
|
--- a/lib/irs/include/irs/netdb.h.in
|
||||||
|
+++ b/lib/irs/include/irs/netdb.h.in
|
||||||
|
@@ -150,6 +150,100 @@ struct addrinfo {
|
||||||
|
#define NI_DGRAM 0x00000010
|
||||||
|
|
||||||
|
/*
|
||||||
|
+ * Define to map into irs_ namespace.
|
||||||
|
+ */
|
||||||
|
+
|
||||||
|
+#define IRS_NAMESPACE
|
||||||
|
+
|
||||||
|
+#ifdef IRS_NAMESPACE
|
||||||
|
+
|
||||||
|
+/*
|
||||||
|
+ * Use our versions not the ones from the C library.
|
||||||
|
+ */
|
||||||
|
+
|
||||||
|
+#ifdef getnameinfo
|
||||||
|
+#undef getnameinfo
|
||||||
|
+#endif
|
||||||
|
+#define getnameinfo irs_getnameinfo
|
||||||
|
+
|
||||||
|
+#ifdef getaddrinfo
|
||||||
|
+#undef getaddrinfo
|
||||||
|
+#endif
|
||||||
|
+#define getaddrinfo irs_getaddrinfo
|
||||||
|
+
|
||||||
|
+#ifdef freeaddrinfo
|
||||||
|
+#undef freeaddrinfo
|
||||||
|
+#endif
|
||||||
|
+#define freeaddrinfo irs_freeaddrinfo
|
||||||
|
+
|
||||||
|
+#ifdef gai_strerror
|
||||||
|
+#undef gai_strerror
|
||||||
|
+#endif
|
||||||
|
+#define gai_strerror irs_gai_strerror
|
||||||
|
+
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
+extern int getaddrinfo (const char *name,
|
||||||
|
+ const char *service,
|
||||||
|
+ const struct addrinfo *req,
|
||||||
|
+ struct addrinfo **pai);
|
||||||
|
+extern int getnameinfo (const struct sockaddr *sa,
|
||||||
|
+ socklen_t salen, char *host,
|
||||||
|
+ socklen_t hostlen, char *serv,
|
||||||
|
+ socklen_t servlen, int flags);
|
||||||
|
+extern void freeaddrinfo (struct addrinfo *ai);
|
||||||
|
+extern const char *gai_strerror (int ecode);
|
||||||
|
+
|
||||||
|
+/*
|
||||||
|
+ * Define to map into irs_ namespace.
|
||||||
|
+ */
|
||||||
|
+
|
||||||
|
+#define IRS_NAMESPACE
|
||||||
|
+
|
||||||
|
+#ifdef IRS_NAMESPACE
|
||||||
|
+
|
||||||
|
+/*
|
||||||
|
+ * Use our versions not the ones from the C library.
|
||||||
|
+ */
|
||||||
|
+
|
||||||
|
+#ifdef getnameinfo
|
||||||
|
+#undef getnameinfo
|
||||||
|
+#endif
|
||||||
|
+#define getnameinfo irs_getnameinfo
|
||||||
|
+
|
||||||
|
+#ifdef getaddrinfo
|
||||||
|
+#undef getaddrinfo
|
||||||
|
+#endif
|
||||||
|
+#define getaddrinfo irs_getaddrinfo
|
||||||
|
+
|
||||||
|
+#ifdef freeaddrinfo
|
||||||
|
+#undef freeaddrinfo
|
||||||
|
+#endif
|
||||||
|
+#define freeaddrinfo irs_freeaddrinfo
|
||||||
|
+
|
||||||
|
+#ifdef gai_strerror
|
||||||
|
+#undef gai_strerror
|
||||||
|
+#endif
|
||||||
|
+#define gai_strerror irs_gai_strerror
|
||||||
|
+
|
||||||
|
+int
|
||||||
|
+getaddrinfo(const char *hostname, const char *servname,
|
||||||
|
+ const struct addrinfo *hints, struct addrinfo **res);
|
||||||
|
+
|
||||||
|
+int
|
||||||
|
+getnameinfo(const struct sockaddr *sa, IRS_GETNAMEINFO_SOCKLEN_T salen,
|
||||||
|
+ char *host, IRS_GETNAMEINFO_BUFLEN_T hostlen,
|
||||||
|
+ char *serv, IRS_GETNAMEINFO_BUFLEN_T servlen,
|
||||||
|
+ IRS_GETNAMEINFO_FLAGS_T flags);
|
||||||
|
+
|
||||||
|
+void freeaddrinfo (struct addrinfo *ai);
|
||||||
|
+
|
||||||
|
+IRS_GAISTRERROR_RETURN_T
|
||||||
|
+gai_strerror(int ecode);
|
||||||
|
+
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
+/*
|
||||||
|
* Tell Emacs to use C mode on this file.
|
||||||
|
* Local variables:
|
||||||
|
* mode: c
|
||||||
|
--
|
||||||
|
2.9.5
|
||||||
|
|
||||||
16
bind-9.11-rh1410433.patch
Normal file
16
bind-9.11-rh1410433.patch
Normal file
|
|
@ -0,0 +1,16 @@
|
||||||
|
diff --git a/lib/dns/dyndb.c b/lib/dns/dyndb.c
|
||||||
|
index 15561ce..e4449b0 100644
|
||||||
|
--- a/lib/dns/dyndb.c
|
||||||
|
+++ b/lib/dns/dyndb.c
|
||||||
|
@@ -133,8 +133,11 @@ load_library(isc_mem_t *mctx, const char *filename, const char *instname,
|
||||||
|
instname, filename);
|
||||||
|
|
||||||
|
flags = RTLD_NOW|RTLD_LOCAL;
|
||||||
|
+#if 0
|
||||||
|
+ /* Shared global namespace is required for dns-pkcs11 library */
|
||||||
|
#if defined(RTLD_DEEPBIND) && !__SANITIZE_ADDRESS__
|
||||||
|
flags |= RTLD_DEEPBIND;
|
||||||
|
+#endif
|
||||||
|
#endif
|
||||||
|
|
||||||
|
handle = dlopen(filename, flags);
|
||||||
288
bind-9.11-rh1624100.patch
Normal file
288
bind-9.11-rh1624100.patch
Normal file
|
|
@ -0,0 +1,288 @@
|
||||||
|
From 76594cba9a1e910bb36160d96fc3872349341799 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@sury.org>
|
||||||
|
Date: Wed, 25 Apr 2018 14:04:31 +0200
|
||||||
|
Subject: [PATCH] Replace isc_safe routines with their OpenSSL counter parts
|
||||||
|
|
||||||
|
(cherry picked from commit 66ba2fdad583d962a1f4971c85d58381f0849e4d)
|
||||||
|
|
||||||
|
Remove isc_safe_memcompare, it's not needed anywhere and can't be replaced with CRYPTO_memcmp()
|
||||||
|
|
||||||
|
(cherry picked from commit b105ccee68ccc3c18e6ea530063b3c8e5a42571c)
|
||||||
|
|
||||||
|
Fix the isc_safe_memwipe() usage with (NULL, >0)
|
||||||
|
|
||||||
|
(cherry picked from commit 083461d3329ff6f2410745848a926090586a9846)
|
||||||
|
---
|
||||||
|
bin/dnssec/dnssec-signzone.c | 2 +-
|
||||||
|
lib/dns/nsec3.c | 4 +-
|
||||||
|
lib/dns/spnego.c | 4 +-
|
||||||
|
lib/isc/Makefile.in | 8 +---
|
||||||
|
lib/isc/include/isc/safe.h | 18 ++------
|
||||||
|
lib/isc/safe.c | 83 ------------------------------------
|
||||||
|
lib/isc/tests/safe_test.c | 18 --------
|
||||||
|
7 files changed, 11 insertions(+), 126 deletions(-)
|
||||||
|
delete mode 100644 lib/isc/safe.c
|
||||||
|
|
||||||
|
diff --git a/bin/dnssec/dnssec-signzone.c b/bin/dnssec/dnssec-signzone.c
|
||||||
|
index 6ddaebe..d921870 100644
|
||||||
|
--- a/bin/dnssec/dnssec-signzone.c
|
||||||
|
+++ b/bin/dnssec/dnssec-signzone.c
|
||||||
|
@@ -787,7 +787,7 @@ hashlist_add_dns_name(hashlist_t *l, /*const*/ dns_name_t *name,
|
||||||
|
|
||||||
|
static int
|
||||||
|
hashlist_comp(const void *a, const void *b) {
|
||||||
|
- return (isc_safe_memcompare(a, b, hash_length + 1));
|
||||||
|
+ return (memcmp(a, b, hash_length + 1));
|
||||||
|
}
|
||||||
|
|
||||||
|
static void
|
||||||
|
diff --git a/lib/dns/nsec3.c b/lib/dns/nsec3.c
|
||||||
|
index 6ae7ca8..01426d6 100644
|
||||||
|
--- a/lib/dns/nsec3.c
|
||||||
|
+++ b/lib/dns/nsec3.c
|
||||||
|
@@ -1963,7 +1963,7 @@ dns_nsec3_noexistnodata(dns_rdatatype_t type, dns_name_t* name,
|
||||||
|
* Work out what this NSEC3 covers.
|
||||||
|
* Inside (<0) or outside (>=0).
|
||||||
|
*/
|
||||||
|
- scope = isc_safe_memcompare(owner, nsec3.next, nsec3.next_length);
|
||||||
|
+ scope = memcmp(owner, nsec3.next, nsec3.next_length);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Prepare to compute all the hashes.
|
||||||
|
@@ -1987,7 +1987,7 @@ dns_nsec3_noexistnodata(dns_rdatatype_t type, dns_name_t* name,
|
||||||
|
return (ISC_R_IGNORE);
|
||||||
|
}
|
||||||
|
|
||||||
|
- order = isc_safe_memcompare(hash, owner, length);
|
||||||
|
+ order = memcmp(hash, owner, length);
|
||||||
|
if (first && order == 0) {
|
||||||
|
/*
|
||||||
|
* The hashes are the same.
|
||||||
|
diff --git a/lib/dns/spnego.c b/lib/dns/spnego.c
|
||||||
|
index ad77f24..670982a 100644
|
||||||
|
--- a/lib/dns/spnego.c
|
||||||
|
+++ b/lib/dns/spnego.c
|
||||||
|
@@ -371,7 +371,7 @@ gssapi_spnego_decapsulate(OM_uint32 *,
|
||||||
|
|
||||||
|
/* mod_auth_kerb.c */
|
||||||
|
|
||||||
|
-static int
|
||||||
|
+static isc_boolean_t
|
||||||
|
cmp_gss_type(gss_buffer_t token, gss_OID gssoid)
|
||||||
|
{
|
||||||
|
unsigned char *p;
|
||||||
|
@@ -395,7 +395,7 @@ cmp_gss_type(gss_buffer_t token, gss_OID gssoid)
|
||||||
|
if (((OM_uint32) *p++) != gssoid->length)
|
||||||
|
return (GSS_S_DEFECTIVE_TOKEN);
|
||||||
|
|
||||||
|
- return (isc_safe_memcompare(p, gssoid->elements, gssoid->length));
|
||||||
|
+ return (!isc_safe_memequal(p, gssoid->elements, gssoid->length));
|
||||||
|
}
|
||||||
|
|
||||||
|
/* accept_sec_context.c */
|
||||||
|
diff --git a/lib/isc/Makefile.in b/lib/isc/Makefile.in
|
||||||
|
index 0fd0837..8ad54bb 100644
|
||||||
|
--- a/lib/isc/Makefile.in
|
||||||
|
+++ b/lib/isc/Makefile.in
|
||||||
|
@@ -60,7 +60,7 @@ OBJS = @ISC_EXTRA_OBJS@ @ISC_PK11_O@ @ISC_PK11_RESULT_O@ \
|
||||||
|
parseint.@O@ portset.@O@ quota.@O@ radix.@O@ random.@O@ \
|
||||||
|
ratelimiter.@O@ refcount.@O@ region.@O@ regex.@O@ result.@O@ \
|
||||||
|
rwlock.@O@ \
|
||||||
|
- safe.@O@ serial.@O@ siphash.@O@ sha1.@O@ sha2.@O@ sockaddr.@O@ stats.@O@ \
|
||||||
|
+ serial.@O@ siphash.@O@ sha1.@O@ sha2.@O@ sockaddr.@O@ stats.@O@ \
|
||||||
|
string.@O@ strtoul.@O@ symtab.@O@ task.@O@ taskpool.@O@ \
|
||||||
|
tm.@O@ timer.@O@ version.@O@ \
|
||||||
|
${UNIXOBJS} ${NLSOBJS} ${THREADOBJS}
|
||||||
|
@@ -79,7 +79,7 @@ SRCS = @ISC_EXTRA_SRCS@ @ISC_PK11_C@ @ISC_PK11_RESULT_C@ \
|
||||||
|
netaddr.c netscope.c pool.c ondestroy.c \
|
||||||
|
parseint.c portset.c quota.c radix.c random.c ${CHACHASRCS} \
|
||||||
|
ratelimiter.c refcount.c region.c regex.c result.c rwlock.c \
|
||||||
|
- safe.c serial.c siphash.c sha1.c sha2.c sockaddr.c stats.c string.c \
|
||||||
|
+ serial.c siphash.c sha1.c sha2.c sockaddr.c stats.c string.c \
|
||||||
|
strtoul.c symtab.c task.c taskpool.c timer.c \
|
||||||
|
tm.c version.c
|
||||||
|
|
||||||
|
@@ -95,10 +95,6 @@ TESTDIRS = @UNITTESTS@
|
||||||
|
|
||||||
|
@BIND9_MAKE_RULES@
|
||||||
|
|
||||||
|
-safe.@O@: safe.c
|
||||||
|
- ${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} @CCNOOPT@ \
|
||||||
|
- -c ${srcdir}/safe.c
|
||||||
|
-
|
||||||
|
version.@O@: version.c
|
||||||
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||||
|
-DVERSION=\"${VERSION}\" \
|
||||||
|
diff --git a/lib/isc/include/isc/safe.h b/lib/isc/include/isc/safe.h
|
||||||
|
index 66ed08b..88b8f47 100644
|
||||||
|
--- a/lib/isc/include/isc/safe.h
|
||||||
|
+++ b/lib/isc/include/isc/safe.h
|
||||||
|
@@ -15,29 +15,19 @@
|
||||||
|
|
||||||
|
/*! \file isc/safe.h */
|
||||||
|
|
||||||
|
-#include <stdbool.h>
|
||||||
|
-
|
||||||
|
-#include <isc/types.h>
|
||||||
|
-#include <stdlib.h>
|
||||||
|
+#include <isc/lang.h>
|
||||||
|
+#include <openssl/crypto.h>
|
||||||
|
|
||||||
|
ISC_LANG_BEGINDECLS
|
||||||
|
|
||||||
|
-bool
|
||||||
|
-isc_safe_memequal(const void *s1, const void *s2, size_t n);
|
||||||
|
+#define isc_safe_memequal(s1, s2, n) !CRYPTO_memcmp(s1, s2, n)
|
||||||
|
/*%<
|
||||||
|
* Returns true iff. two blocks of memory are equal, otherwise
|
||||||
|
* false.
|
||||||
|
*
|
||||||
|
*/
|
||||||
|
|
||||||
|
-int
|
||||||
|
-isc_safe_memcompare(const void *b1, const void *b2, size_t len);
|
||||||
|
-/*%<
|
||||||
|
- * Clone of libc memcmp() which is safe to differential timing attacks.
|
||||||
|
- */
|
||||||
|
-
|
||||||
|
-void
|
||||||
|
-isc_safe_memwipe(void *ptr, size_t len);
|
||||||
|
+#define isc_safe_memwipe(ptr, len) OPENSSL_cleanse(ptr, len)
|
||||||
|
/*%<
|
||||||
|
* Clear the memory of length `len` pointed to by `ptr`.
|
||||||
|
*
|
||||||
|
diff --git a/lib/isc/safe.c b/lib/isc/safe.c
|
||||||
|
deleted file mode 100644
|
||||||
|
index 7a464b6..0000000
|
||||||
|
--- a/lib/isc/safe.c
|
||||||
|
+++ /dev/null
|
||||||
|
@@ -1,83 +0,0 @@
|
||||||
|
-/*
|
||||||
|
- * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
||||||
|
- *
|
||||||
|
- * This Source Code Form is subject to the terms of the Mozilla Public
|
||||||
|
- * License, v. 2.0. If a copy of the MPL was not distributed with this
|
||||||
|
- * file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
||||||
|
- *
|
||||||
|
- * See the COPYRIGHT file distributed with this work for additional
|
||||||
|
- * information regarding copyright ownership.
|
||||||
|
- */
|
||||||
|
-
|
||||||
|
-/*! \file */
|
||||||
|
-
|
||||||
|
-#include <config.h>
|
||||||
|
-
|
||||||
|
-#include <stdbool.h>
|
||||||
|
-
|
||||||
|
-#include <isc/safe.h>
|
||||||
|
-#include <isc/string.h>
|
||||||
|
-#include <isc/util.h>
|
||||||
|
-
|
||||||
|
-#ifdef WIN32
|
||||||
|
-#include <windows.h>
|
||||||
|
-#endif
|
||||||
|
-
|
||||||
|
-#ifdef _MSC_VER
|
||||||
|
-#pragma optimize("", off)
|
||||||
|
-#endif
|
||||||
|
-
|
||||||
|
-bool
|
||||||
|
-isc_safe_memequal(const void *s1, const void *s2, size_t n) {
|
||||||
|
- uint8_t acc = 0;
|
||||||
|
-
|
||||||
|
- if (n != 0U) {
|
||||||
|
- const uint8_t *p1 = s1, *p2 = s2;
|
||||||
|
-
|
||||||
|
- do {
|
||||||
|
- acc |= *p1++ ^ *p2++;
|
||||||
|
- } while (--n != 0U);
|
||||||
|
- }
|
||||||
|
- return (acc == 0);
|
||||||
|
-}
|
||||||
|
-
|
||||||
|
-
|
||||||
|
-int
|
||||||
|
-isc_safe_memcompare(const void *b1, const void *b2, size_t len) {
|
||||||
|
- const unsigned char *p1 = b1, *p2 = b2;
|
||||||
|
- size_t i;
|
||||||
|
- int res = 0, done = 0;
|
||||||
|
-
|
||||||
|
- for (i = 0; i < len; i++) {
|
||||||
|
- /* lt is -1 if p1[i] < p2[i]; else 0. */
|
||||||
|
- int lt = (p1[i] - p2[i]) >> CHAR_BIT;
|
||||||
|
-
|
||||||
|
- /* gt is -1 if p1[i] > p2[i]; else 0. */
|
||||||
|
- int gt = (p2[i] - p1[i]) >> CHAR_BIT;
|
||||||
|
-
|
||||||
|
- /* cmp is 1 if p1[i] > p2[i]; -1 if p1[i] < p2[i]; else 0. */
|
||||||
|
- int cmp = lt - gt;
|
||||||
|
-
|
||||||
|
- /* set res = cmp if !done. */
|
||||||
|
- res |= cmp & ~done;
|
||||||
|
-
|
||||||
|
- /* set done if p1[i] != p2[i]. */
|
||||||
|
- done |= lt | gt;
|
||||||
|
- }
|
||||||
|
-
|
||||||
|
- return (res);
|
||||||
|
-}
|
||||||
|
-
|
||||||
|
-void
|
||||||
|
-isc_safe_memwipe(void *ptr, size_t len) {
|
||||||
|
- if (ISC_UNLIKELY(ptr == NULL || len == 0))
|
||||||
|
- return;
|
||||||
|
-
|
||||||
|
-#ifdef WIN32
|
||||||
|
- SecureZeroMemory(ptr, len);
|
||||||
|
-#elif HAVE_EXPLICIT_BZERO
|
||||||
|
- explicit_bzero(ptr, len);
|
||||||
|
-#else
|
||||||
|
- memset(ptr, 0, len);
|
||||||
|
-#endif
|
||||||
|
-}
|
||||||
|
diff --git a/lib/isc/tests/safe_test.c b/lib/isc/tests/safe_test.c
|
||||||
|
index 266ac75..60e9181 100644
|
||||||
|
--- a/lib/isc/tests/safe_test.c
|
||||||
|
+++ b/lib/isc/tests/safe_test.c
|
||||||
|
@@ -45,22 +45,6 @@ isc_safe_memequal_test(void **state) {
|
||||||
|
"\x00\x00\x00\x00", 4));
|
||||||
|
}
|
||||||
|
|
||||||
|
-/* test isc_safe_memcompare() */
|
||||||
|
-static void
|
||||||
|
-isc_safe_memcompare_test(void **state) {
|
||||||
|
- UNUSED(state);
|
||||||
|
-
|
||||||
|
- assert_int_equal(isc_safe_memcompare("test", "test", 4), 0);
|
||||||
|
- assert_true(isc_safe_memcompare("test", "tesc", 4) > 0);
|
||||||
|
- assert_true(isc_safe_memcompare("test", "tesy", 4) < 0);
|
||||||
|
- assert_int_equal(isc_safe_memcompare("\x00\x00\x00\x00",
|
||||||
|
- "\x00\x00\x00\x00", 4), 0);
|
||||||
|
- assert_true(isc_safe_memcompare("\x00\x00\x00\x00",
|
||||||
|
- "\x00\x00\x00\x01", 4) < 0);
|
||||||
|
- assert_true(isc_safe_memcompare("\x00\x00\x00\x02",
|
||||||
|
- "\x00\x00\x00\x00", 4) > 0);
|
||||||
|
-}
|
||||||
|
-
|
||||||
|
/* test isc_safe_memwipe() */
|
||||||
|
static void
|
||||||
|
isc_safe_memwipe_test(void **state) {
|
||||||
|
@@ -69,7 +53,6 @@ isc_safe_memwipe_test(void **state) {
|
||||||
|
/* These should pass. */
|
||||||
|
isc_safe_memwipe(NULL, 0);
|
||||||
|
isc_safe_memwipe((void *) -1, 0);
|
||||||
|
- isc_safe_memwipe(NULL, 42);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* isc_safe_memwipe(ptr, size) should function same as
|
||||||
|
@@ -108,7 +91,6 @@ main(void) {
|
||||||
|
const struct CMUnitTest tests[] = {
|
||||||
|
cmocka_unit_test(isc_safe_memequal_test),
|
||||||
|
cmocka_unit_test(isc_safe_memwipe_test),
|
||||||
|
- cmocka_unit_test(isc_safe_memcompare_test),
|
||||||
|
};
|
||||||
|
|
||||||
|
return (cmocka_run_group_tests(tests, NULL, NULL));
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
86
bind-9.11-rh1647829-2.patch
Normal file
86
bind-9.11-rh1647829-2.patch
Normal file
|
|
@ -0,0 +1,86 @@
|
||||||
|
From fdfc8ad6a1069eea6b012972c972798003d58312 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Tue, 29 Jan 2019 18:07:44 +0100
|
||||||
|
Subject: [PATCH] Fallback to ASCII on output IDN conversion error
|
||||||
|
|
||||||
|
It is possible dig used ACE encoded name in locale, which does not
|
||||||
|
support converting it to unicode. Instead of fatal error, fallback to
|
||||||
|
ACE name on output.
|
||||||
|
|
||||||
|
(cherry picked from commit 7f4cb8f9584597fea16de6557124ac8b1bd47440)
|
||||||
|
|
||||||
|
Modify idna test to fallback to ACE
|
||||||
|
|
||||||
|
Test valid A-label on input would be displayed as A-label on output if
|
||||||
|
locale does not allow U-label.
|
||||||
|
|
||||||
|
(cherry picked from commit 4ce232f8605bdbe0594ebe5a71383c9d4e6f263b)
|
||||||
|
|
||||||
|
Emit warning on IDN output failure
|
||||||
|
|
||||||
|
Warning is emitted before any dig headers.
|
||||||
|
|
||||||
|
(cherry picked from commit 4b410038c531fbb902cd5fb83174eed1f06cb7d7)
|
||||||
|
---
|
||||||
|
bin/dig/dighost.c | 15 +++++++++++++--
|
||||||
|
bin/tests/system/idna/tests.sh | 17 +++++++++++++++++
|
||||||
|
2 files changed, 30 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/dig/dighost.c b/bin/dig/dighost.c
|
||||||
|
index 73aaab8..375f99f 100644
|
||||||
|
--- a/bin/dig/dighost.c
|
||||||
|
+++ b/bin/dig/dighost.c
|
||||||
|
@@ -4877,9 +4877,20 @@ idn_ace_to_locale(const char *from, char *to, size_t tolen) {
|
||||||
|
*/
|
||||||
|
res = idn2_to_unicode_8zlz(utf8_src, &tmp_str, 0);
|
||||||
|
if (res != IDN2_OK) {
|
||||||
|
- fatal("Cannot represent '%s' in the current locale (%s), "
|
||||||
|
- "use +noidnout or a different locale",
|
||||||
|
+ static bool warned = false;
|
||||||
|
+
|
||||||
|
+ res = idn2_to_ascii_8z(utf8_src, &tmp_str, 0);
|
||||||
|
+ if (res != IDN2_OK) {
|
||||||
|
+ fatal("Cannot represent '%s' "
|
||||||
|
+ "in the current locale nor ascii (%s), "
|
||||||
|
+ "use +noidnout or a different locale",
|
||||||
|
from, idn2_strerror(res));
|
||||||
|
+ } else if (!warned) {
|
||||||
|
+ fprintf(stderr, ";; Warning: cannot represent '%s' "
|
||||||
|
+ "in the current locale",
|
||||||
|
+ tmp_str);
|
||||||
|
+ warned = true;
|
||||||
|
+ }
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
diff --git a/bin/tests/system/idna/tests.sh b/bin/tests/system/idna/tests.sh
|
||||||
|
index 7acb0fa..0269bcd 100644
|
||||||
|
--- a/bin/tests/system/idna/tests.sh
|
||||||
|
+++ b/bin/tests/system/idna/tests.sh
|
||||||
|
@@ -244,6 +244,23 @@ idna_enabled_test() {
|
||||||
|
idna_test "$text" "+idnin +noidnout" "xn--nxasmq6b.com" "xn--nxasmq6b.com."
|
||||||
|
idna_test "$text" "+idnin +idnout" "xn--nxasmq6b.com" "βόλοσ.com."
|
||||||
|
|
||||||
|
+ # Test of valid A-label in locale that cannot display it
|
||||||
|
+ #
|
||||||
|
+ # +noidnout: The string is sent as-is to the server and the returned qname
|
||||||
|
+ # is displayed in the same form.
|
||||||
|
+ # +idnout: The string is sent as-is to the server and the returned qname
|
||||||
|
+ # is displayed as the corresponding A-label.
|
||||||
|
+ #
|
||||||
|
+ # The "+[no]idnout" flag has no effect in these cases.
|
||||||
|
+ text="Checking valid A-label in C locale"
|
||||||
|
+ label="xn--nxasmq6b.com"
|
||||||
|
+ LC_ALL=C idna_test "$text" "" "$label" "$label."
|
||||||
|
+ LC_ALL=C idna_test "$text" "+noidnin +noidnout" "$label" "$label."
|
||||||
|
+ LC_ALL=C idna_test "$text" "+noidnin +idnout" "$label" "$label."
|
||||||
|
+ LC_ALL=C idna_test "$text" "+idnin +noidnout" "$label" "$label."
|
||||||
|
+ LC_ALL=C idna_test "$text" "+idnin +idnout" "$label" "$label."
|
||||||
|
+ LC_ALL=C idna_test "$text" "+noidnin +idnout" "$label" "$label."
|
||||||
|
+
|
||||||
|
|
||||||
|
|
||||||
|
# Tests of invalid A-labels
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
86
bind-9.11-rh1647829.patch
Normal file
86
bind-9.11-rh1647829.patch
Normal file
|
|
@ -0,0 +1,86 @@
|
||||||
|
From 2eca7f5fa97a24997e4d8f900460ba43ae167e97 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Tue, 29 Jan 2019 18:07:44 +0100
|
||||||
|
Subject: [PATCH] Fallback to ASCII on output IDN conversion error
|
||||||
|
|
||||||
|
It is possible dig used ACE encoded name in locale, which does not
|
||||||
|
support converting it to unicode. Instead of fatal error, fallback to
|
||||||
|
ACE name on output.
|
||||||
|
|
||||||
|
(cherry picked from commit 7f4cb8f9584597fea16de6557124ac8b1bd47440)
|
||||||
|
|
||||||
|
Modify idna test to fallback to ACE
|
||||||
|
|
||||||
|
Test valid A-label on input would be displayed as A-label on output if
|
||||||
|
locale does not allow U-label.
|
||||||
|
|
||||||
|
(cherry picked from commit 4ce232f8605bdbe0594ebe5a71383c9d4e6f263b)
|
||||||
|
|
||||||
|
Emit warning on IDN output failure
|
||||||
|
|
||||||
|
Warning is emitted before any dig headers.
|
||||||
|
|
||||||
|
(cherry picked from commit 4b410038c531fbb902cd5fb83174eed1f06cb7d7)
|
||||||
|
---
|
||||||
|
bin/dig/dighost.c | 15 +++++++++++++--
|
||||||
|
bin/tests/system/idna/tests.sh | 17 +++++++++++++++++
|
||||||
|
2 files changed, 30 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/dig/dighost.c b/bin/dig/dighost.c
|
||||||
|
index bb8702c..d7cfc33 100644
|
||||||
|
--- a/bin/dig/dighost.c
|
||||||
|
+++ b/bin/dig/dighost.c
|
||||||
|
@@ -4860,9 +4860,20 @@ idn_ace_to_locale(const char *from, char *to, size_t tolen) {
|
||||||
|
*/
|
||||||
|
res = idn2_to_unicode_8zlz(utf8_src, &tmp_str, 0);
|
||||||
|
if (res != IDN2_OK) {
|
||||||
|
- fatal("Cannot represent '%s' in the current locale (%s), "
|
||||||
|
- "use +noidnout or a different locale",
|
||||||
|
+ static bool warned = false;
|
||||||
|
+
|
||||||
|
+ res = idn2_to_ascii_8z(utf8_src, &tmp_str, 0);
|
||||||
|
+ if (res != IDN2_OK) {
|
||||||
|
+ fatal("Cannot represent '%s' "
|
||||||
|
+ "in the current locale nor ascii (%s), "
|
||||||
|
+ "use +noidnout or a different locale",
|
||||||
|
from, idn2_strerror(res));
|
||||||
|
+ } else if (!warned) {
|
||||||
|
+ fprintf(stderr, ";; Warning: cannot represent '%s' "
|
||||||
|
+ "in the current locale",
|
||||||
|
+ tmp_str);
|
||||||
|
+ warned = true;
|
||||||
|
+ }
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
diff --git a/bin/tests/system/idna/tests.sh b/bin/tests/system/idna/tests.sh
|
||||||
|
index 6637bf6..215a9d5 100644
|
||||||
|
--- a/bin/tests/system/idna/tests.sh
|
||||||
|
+++ b/bin/tests/system/idna/tests.sh
|
||||||
|
@@ -244,6 +244,23 @@ idna_enabled_test() {
|
||||||
|
idna_test "$text" "+idnin +noidnout" "xn--nxasmq6b.com" "xn--nxasmq6b.com."
|
||||||
|
idna_test "$text" "+idnin +idnout" "xn--nxasmq6b.com" "βόλοσ.com."
|
||||||
|
|
||||||
|
+ # Test of valid A-label in locale that cannot display it
|
||||||
|
+ #
|
||||||
|
+ # +noidnout: The string is sent as-is to the server and the returned qname
|
||||||
|
+ # is displayed in the same form.
|
||||||
|
+ # +idnout: The string is sent as-is to the server and the returned qname
|
||||||
|
+ # is displayed as the corresponding A-label.
|
||||||
|
+ #
|
||||||
|
+ # The "+[no]idnout" flag has no effect in these cases.
|
||||||
|
+ text="Checking valid A-label in C locale"
|
||||||
|
+ label="xn--nxasmq6b.com"
|
||||||
|
+ LC_ALL=C idna_test "$text" "" "$label" "$label."
|
||||||
|
+ LC_ALL=C idna_test "$text" "+noidnin +noidnout" "$label" "$label."
|
||||||
|
+ LC_ALL=C idna_test "$text" "+noidnin +idnout" "$label" "$label."
|
||||||
|
+ LC_ALL=C idna_test "$text" "+idnin +noidnout" "$label" "$label."
|
||||||
|
+ LC_ALL=C idna_test "$text" "+idnin +idnout" "$label" "$label."
|
||||||
|
+ LC_ALL=C idna_test "$text" "+noidnin +idnout" "$label" "$label."
|
||||||
|
+
|
||||||
|
|
||||||
|
|
||||||
|
# Tests of invalid A-labels
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
48
bind-9.11-rh1663318.patch
Normal file
48
bind-9.11-rh1663318.patch
Normal file
|
|
@ -0,0 +1,48 @@
|
||||||
|
From b16a1ff25644bb075f454afe68ee63f6f385ca9c Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Wed, 23 Jan 2019 21:11:07 +0100
|
||||||
|
Subject: [PATCH] Made RAND_status check optional (broke --disable-crypto-rand)
|
||||||
|
MIME-Version: 1.0
|
||||||
|
Content-Type: text/plain; charset=UTF-8
|
||||||
|
Content-Transfer-Encoding: 8bit
|
||||||
|
|
||||||
|
Unlike upstream, skip it also for DHCP.
|
||||||
|
|
||||||
|
Disable RAND_status also in non-threaded builds. DHCP is built without
|
||||||
|
threads and should not check RAND_status on dns library initialization.
|
||||||
|
Lack of entropy is possible state for dhclient, but it must not fail
|
||||||
|
even in this case. Because DHCP itself does not require custom random
|
||||||
|
generator, leave default RAND_OpenSSL configured. It should help TLS
|
||||||
|
connection to LDAP in single DHCP binary, while keeping secure random
|
||||||
|
data if needed.
|
||||||
|
|
||||||
|
(modified upstream commit 8a98277811ea50035ff37b744fa3dc5b75bee099)
|
||||||
|
|
||||||
|
Signed-off-by: Petr Menšík <pemensik@redhat.com>
|
||||||
|
---
|
||||||
|
lib/dns/openssl_link.c | 2 ++
|
||||||
|
1 file changed, 2 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/lib/dns/openssl_link.c b/lib/dns/openssl_link.c
|
||||||
|
index 7a233dd..941eb17 100644
|
||||||
|
--- a/lib/dns/openssl_link.c
|
||||||
|
+++ b/lib/dns/openssl_link.c
|
||||||
|
@@ -289,6 +289,7 @@ dst__openssl_init(const char *engine) {
|
||||||
|
#endif
|
||||||
|
#endif /* !defined(OPENSSL_NO_ENGINE) */
|
||||||
|
|
||||||
|
+#if defined(ISC_PLATFORM_CRYPTORANDOM) && defined(ISC_PLATFORM_USETHREADS)
|
||||||
|
/* Protect ourselves against unseeded PRNG */
|
||||||
|
if (RAND_status() != 1) {
|
||||||
|
FATAL_ERROR(__FILE__, __LINE__,
|
||||||
|
@@ -296,6 +297,7 @@ dst__openssl_init(const char *engine) {
|
||||||
|
"cannot be initialized (see the `PRNG not "
|
||||||
|
"seeded' message in the OpenSSL FAQ)");
|
||||||
|
}
|
||||||
|
+#endif
|
||||||
|
|
||||||
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
37
bind-9.11-rh1666814.patch
Normal file
37
bind-9.11-rh1666814.patch
Normal file
|
|
@ -0,0 +1,37 @@
|
||||||
|
From 3bb29f45604ac6890f4ea5cdcbd1a62e6dad14a7 Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Wed, 16 Jan 2019 16:27:33 +0100
|
||||||
|
Subject: [PATCH 2/2] Fix possible crash when loading corrupted file
|
||||||
|
|
||||||
|
Some values passes internal triggers by coincidence. Fix the check and
|
||||||
|
check also first_node_offset before even passing it further.
|
||||||
|
---
|
||||||
|
lib/dns/rbt.c | 5 +++--
|
||||||
|
1 file changed, 3 insertions(+), 2 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/dns/rbt.c b/lib/dns/rbt.c
|
||||||
|
index 62d0826..b029b7d 100644
|
||||||
|
--- a/lib/dns/rbt.c
|
||||||
|
+++ b/lib/dns/rbt.c
|
||||||
|
@@ -787,7 +787,7 @@ treefix(dns_rbt_t *rbt, void *base, size_t filesize, dns_rbtnode_t *n,
|
||||||
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
|
CONFIRM((void *) n >= base);
|
||||||
|
- CONFIRM((char *) n - (char *) base <= (int) nodemax);
|
||||||
|
+ CONFIRM((size_t)((char *) n - (char *) base) <= nodemax);
|
||||||
|
CONFIRM(DNS_RBTNODE_VALID(n));
|
||||||
|
|
||||||
|
dns_name_init(&nodename, NULL);
|
||||||
|
@@ -939,7 +939,8 @@ dns_rbt_deserialize_tree(void *base_address, size_t filesize,
|
||||||
|
rbt->root = (dns_rbtnode_t *)((char *)base_address +
|
||||||
|
header_offset + header->first_node_offset);
|
||||||
|
|
||||||
|
- if ((header->nodecount * sizeof(dns_rbtnode_t)) > filesize) {
|
||||||
|
+ if ((header->nodecount * sizeof(dns_rbtnode_t)) > filesize
|
||||||
|
+ || header->first_node_offset > filesize) {
|
||||||
|
result = ISC_R_INVALIDFILE;
|
||||||
|
goto cleanup;
|
||||||
|
}
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
196
bind-9.11-rh1732883.patch
Normal file
196
bind-9.11-rh1732883.patch
Normal file
|
|
@ -0,0 +1,196 @@
|
||||||
|
From 348947b3d573e2187db61fb43919d2260dcfc135 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Pavel Zhukov <pzhukov@redhat.com>
|
||||||
|
Date: Wed, 24 Jul 2019 17:15:55 +0200
|
||||||
|
Subject: [PATCH] Detect system time jumps
|
||||||
|
|
||||||
|
In case if system time was changed backward it's possible to have ip
|
||||||
|
address dropped by the kernel due to lifetime expirity. Try to detect
|
||||||
|
this situation using either monotonic time or saved timestamp and execute
|
||||||
|
go_reboot() procedure to request lease extention
|
||||||
|
---
|
||||||
|
lib/isc/include/isc/result.h | 3 ++-
|
||||||
|
lib/isc/include/isc/util.h | 3 +++
|
||||||
|
lib/isc/result.c | 2 ++
|
||||||
|
lib/isc/unix/app.c | 39 +++++++++++++++++++++++++++++----
|
||||||
|
lib/isc/unix/include/isc/time.h | 20 +++++++++++++++++
|
||||||
|
lib/isc/unix/time.c | 22 +++++++++++++++++++
|
||||||
|
6 files changed, 84 insertions(+), 5 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/lib/isc/include/isc/result.h b/lib/isc/include/isc/result.h
|
||||||
|
index 0fd4971..2add549 100644
|
||||||
|
--- a/lib/isc/include/isc/result.h
|
||||||
|
+++ b/lib/isc/include/isc/result.h
|
||||||
|
@@ -87,9 +87,10 @@
|
||||||
|
#define ISC_R_CRYPTOFAILURE 65 /*%< cryptography library failure */
|
||||||
|
#define ISC_R_DISCQUOTA 66 /*%< disc quota */
|
||||||
|
#define ISC_R_DISCFULL 67 /*%< disc full */
|
||||||
|
+#define ISC_R_TIMESHIFTED 68 /*%< system time changed */
|
||||||
|
|
||||||
|
/*% Not a result code: the number of results. */
|
||||||
|
-#define ISC_R_NRESULTS 68
|
||||||
|
+#define ISC_R_NRESULTS 69
|
||||||
|
|
||||||
|
ISC_LANG_BEGINDECLS
|
||||||
|
|
||||||
|
diff --git a/lib/isc/include/isc/util.h b/lib/isc/include/isc/util.h
|
||||||
|
index 973c348..8160dd3 100644
|
||||||
|
--- a/lib/isc/include/isc/util.h
|
||||||
|
+++ b/lib/isc/include/isc/util.h
|
||||||
|
@@ -289,6 +289,9 @@ extern void mock_assert(const int result, const char* const expression,
|
||||||
|
* Time
|
||||||
|
*/
|
||||||
|
#define TIME_NOW(tp) RUNTIME_CHECK(isc_time_now((tp)) == ISC_R_SUCCESS)
|
||||||
|
+#ifdef CLOCK_BOOTTIME
|
||||||
|
+#define TIME_MONOTONIC(tp) RUNTIME_CHECK(isc_time_boottime((tp)) == ISC_R_SUCCESS)
|
||||||
|
+#endif
|
||||||
|
|
||||||
|
/*%
|
||||||
|
* Alignment
|
||||||
|
diff --git a/lib/isc/result.c b/lib/isc/result.c
|
||||||
|
index abb6ed2..8c95a93 100644
|
||||||
|
--- a/lib/isc/result.c
|
||||||
|
+++ b/lib/isc/result.c
|
||||||
|
@@ -103,6 +103,7 @@ static const char *description[ISC_R_NRESULTS] = {
|
||||||
|
"crypto failure", /*%< 65 */
|
||||||
|
"disc quota", /*%< 66 */
|
||||||
|
"disc full", /*%< 67 */
|
||||||
|
+ "time changed", /*%< 68 */
|
||||||
|
};
|
||||||
|
|
||||||
|
static const char *identifier[ISC_R_NRESULTS] = {
|
||||||
|
@@ -174,6 +175,7 @@ static const char *identifier[ISC_R_NRESULTS] = {
|
||||||
|
"ISC_R_CRYPTOFAILURE",
|
||||||
|
"ISC_R_DISCQUOTA",
|
||||||
|
"ISC_R_DISCFULL",
|
||||||
|
+ "ISC_R_TIMESHIFTED",
|
||||||
|
};
|
||||||
|
|
||||||
|
#define ISC_RESULT_RESULTSET 2
|
||||||
|
diff --git a/lib/isc/unix/app.c b/lib/isc/unix/app.c
|
||||||
|
index 7e5a0ee..ceab74e 100644
|
||||||
|
--- a/lib/isc/unix/app.c
|
||||||
|
+++ b/lib/isc/unix/app.c
|
||||||
|
@@ -442,15 +442,48 @@ isc__app_ctxonrun(isc_appctx_t *ctx0, isc_mem_t *mctx, isc_task_t *task,
|
||||||
|
static isc_result_t
|
||||||
|
evloop(isc__appctx_t *ctx) {
|
||||||
|
isc_result_t result;
|
||||||
|
+ isc_time_t now;
|
||||||
|
+#ifdef CLOCK_BOOTTIME
|
||||||
|
+ isc_time_t monotonic;
|
||||||
|
+ uint64_t diff = 0;
|
||||||
|
+#else
|
||||||
|
+ isc_time_t prev;
|
||||||
|
+ TIME_NOW(&prev);
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
+
|
||||||
|
|
||||||
|
while (!ctx->want_shutdown) {
|
||||||
|
int n;
|
||||||
|
- isc_time_t when, now;
|
||||||
|
+ isc_time_t when;
|
||||||
|
struct timeval tv, *tvp;
|
||||||
|
isc_socketwait_t *swait;
|
||||||
|
bool readytasks;
|
||||||
|
bool call_timer_dispatch = false;
|
||||||
|
-
|
||||||
|
+ uint64_t us;
|
||||||
|
+
|
||||||
|
+#ifdef CLOCK_BOOTTIME
|
||||||
|
+ // TBD macros for following three lines
|
||||||
|
+ TIME_NOW(&now);
|
||||||
|
+ TIME_MONOTONIC(&monotonic);
|
||||||
|
+ INSIST(now.seconds > monotonic.seconds)
|
||||||
|
+ us = isc_time_microdiff (&now, &monotonic);
|
||||||
|
+ if (us < diff){
|
||||||
|
+ us = diff - us;
|
||||||
|
+ if (us > 1000000){ // ignoring shifts less than one second
|
||||||
|
+ return ISC_R_TIMESHIFTED;
|
||||||
|
+ };
|
||||||
|
+ diff = isc_time_microdiff (&now, &monotonic);
|
||||||
|
+ } else {
|
||||||
|
+ diff = isc_time_microdiff (&now, &monotonic);
|
||||||
|
+ // not implemented
|
||||||
|
+ }
|
||||||
|
+#else
|
||||||
|
+ TIME_NOW(&now);
|
||||||
|
+ if (isc_time_compare (&now, &prev) < 0)
|
||||||
|
+ return ISC_R_TIMESHIFTED;
|
||||||
|
+ TIME_NOW(&prev);
|
||||||
|
+#endif
|
||||||
|
/*
|
||||||
|
* Check the reload (or suspend) case first for exiting the
|
||||||
|
* loop as fast as possible in case:
|
||||||
|
@@ -475,8 +508,6 @@ evloop(isc__appctx_t *ctx) {
|
||||||
|
if (result != ISC_R_SUCCESS)
|
||||||
|
tvp = NULL;
|
||||||
|
else {
|
||||||
|
- uint64_t us;
|
||||||
|
-
|
||||||
|
TIME_NOW(&now);
|
||||||
|
us = isc_time_microdiff(&when, &now);
|
||||||
|
if (us == 0)
|
||||||
|
diff --git a/lib/isc/unix/include/isc/time.h b/lib/isc/unix/include/isc/time.h
|
||||||
|
index b864c29..5dd43c9 100644
|
||||||
|
--- a/lib/isc/unix/include/isc/time.h
|
||||||
|
+++ b/lib/isc/unix/include/isc/time.h
|
||||||
|
@@ -132,6 +132,26 @@ isc_time_isepoch(const isc_time_t *t);
|
||||||
|
*\li 't' is a valid pointer.
|
||||||
|
*/
|
||||||
|
|
||||||
|
+#ifdef CLOCK_BOOTTIME
|
||||||
|
+isc_result_t
|
||||||
|
+isc_time_boottime(isc_time_t *t);
|
||||||
|
+/*%<
|
||||||
|
+ * Set 't' to monotonic time from previous boot
|
||||||
|
+ * it's not affected by system time change. It also
|
||||||
|
+ * includes the time system was suspended
|
||||||
|
+ *
|
||||||
|
+ * Requires:
|
||||||
|
+ *\li 't' is a valid pointer.
|
||||||
|
+ *
|
||||||
|
+ * Returns:
|
||||||
|
+ *
|
||||||
|
+ *\li Success
|
||||||
|
+ *\li Unexpected error
|
||||||
|
+ * Getting the time from the system failed.
|
||||||
|
+ */
|
||||||
|
+#endif /* CLOCK_BOOTTIME */
|
||||||
|
+
|
||||||
|
+
|
||||||
|
isc_result_t
|
||||||
|
isc_time_now(isc_time_t *t);
|
||||||
|
/*%<
|
||||||
|
diff --git a/lib/isc/unix/time.c b/lib/isc/unix/time.c
|
||||||
|
index 8edc9df..fe0bb91 100644
|
||||||
|
--- a/lib/isc/unix/time.c
|
||||||
|
+++ b/lib/isc/unix/time.c
|
||||||
|
@@ -498,3 +498,25 @@ isc_time_formatISO8601ms(const isc_time_t *t, char *buf, unsigned int len) {
|
||||||
|
t->nanoseconds / NS_PER_MS);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
+
|
||||||
|
+
|
||||||
|
+#ifdef CLOCK_BOOTTIME
|
||||||
|
+isc_result_t
|
||||||
|
+isc_time_boottime(isc_time_t *t) {
|
||||||
|
+ struct timespec ts;
|
||||||
|
+
|
||||||
|
+ char strbuf[ISC_STRERRORSIZE];
|
||||||
|
+
|
||||||
|
+ if (clock_gettime (CLOCK_BOOTTIME, &ts) != 0){
|
||||||
|
+ isc__strerror(errno, strbuf, sizeof(strbuf));
|
||||||
|
+ UNEXPECTED_ERROR(__FILE__, __LINE__, "%s", strbuf);
|
||||||
|
+ return (ISC_R_UNEXPECTED);
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
+ t->seconds = ts.tv_sec;
|
||||||
|
+ t->nanoseconds = ts.tv_nsec;
|
||||||
|
+
|
||||||
|
+ return (ISC_R_SUCCESS);
|
||||||
|
+
|
||||||
|
+};
|
||||||
|
+#endif
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
2123
bind-9.11-rt31459.patch
Normal file
2123
bind-9.11-rt31459.patch
Normal file
File diff suppressed because it is too large
Load diff
778
bind-9.11-rt46047.patch
Normal file
778
bind-9.11-rt46047.patch
Normal file
|
|
@ -0,0 +1,778 @@
|
||||||
|
From ab9ee91f596c14cfc55a67ba3523b42a54e3e244 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Evan Hunt <each@isc.org>
|
||||||
|
Date: Thu, 28 Sep 2017 10:09:22 -0700
|
||||||
|
Subject: [PATCH] completed and corrected the crypto-random change
|
||||||
|
|
||||||
|
4724. [func] By default, BIND now uses the random number
|
||||||
|
functions provided by the crypto library (i.e.,
|
||||||
|
OpenSSL or a PKCS#11 provider) as a source of
|
||||||
|
randomness rather than /dev/random. This is
|
||||||
|
suitable for virtual machine environments
|
||||||
|
which have limited entropy pools and lack
|
||||||
|
hardware random number generators.
|
||||||
|
|
||||||
|
This can be overridden by specifying another
|
||||||
|
entropy source via the "random-device" option
|
||||||
|
in named.conf, or via the -r command line option;
|
||||||
|
however, for functions requiring full cryptographic
|
||||||
|
strength, such as DNSSEC key generation, this
|
||||||
|
cannot be overridden. In particular, the -r
|
||||||
|
command line option no longer has any effect on
|
||||||
|
dnssec-keygen.
|
||||||
|
|
||||||
|
This can be disabled by building with
|
||||||
|
"configure --disable-crypto-rand".
|
||||||
|
[RT #31459] [RT #46047]
|
||||||
|
---
|
||||||
|
bin/confgen/keygen.c | 12 +++---
|
||||||
|
bin/dnssec/dnssec-keygen.docbook | 24 +++++++----
|
||||||
|
bin/dnssec/dnssectool.c | 12 +++---
|
||||||
|
bin/named/client.c | 3 +-
|
||||||
|
bin/named/config.c | 4 +-
|
||||||
|
bin/named/controlconf.c | 19 +++++---
|
||||||
|
bin/named/include/named/server.h | 2 +
|
||||||
|
bin/named/interfacemgr.c | 1 +
|
||||||
|
bin/named/query.c | 1 +
|
||||||
|
bin/named/server.c | 52 ++++++++++++++--------
|
||||||
|
bin/nsupdate/nsupdate.c | 4 +-
|
||||||
|
bin/tests/system/pipelined/pipequeries.c | 4 +-
|
||||||
|
bin/tests/system/tkey/keycreate.c | 4 +-
|
||||||
|
bin/tests/system/tkey/keydelete.c | 5 +--
|
||||||
|
doc/arm/Bv9ARM-book.xml | 55 +++++++++++++++++-------
|
||||||
|
doc/arm/notes.xml | 31 +++++++++++++
|
||||||
|
lib/dns/dst_api.c | 4 +-
|
||||||
|
lib/dns/include/dst/dst.h | 14 +++++-
|
||||||
|
lib/dns/openssl_link.c | 3 +-
|
||||||
|
lib/isc/include/isc/entropy.h | 50 +++++++++++++++------
|
||||||
|
lib/isc/include/isc/random.h | 28 +++++++-----
|
||||||
|
lib/isccfg/namedconf.c | 2 +-
|
||||||
|
22 files changed, 228 insertions(+), 106 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/confgen/keygen.c b/bin/confgen/keygen.c
|
||||||
|
index 295e16f..0f79aa8 100644
|
||||||
|
--- a/bin/confgen/keygen.c
|
||||||
|
+++ b/bin/confgen/keygen.c
|
||||||
|
@@ -161,17 +161,15 @@ generate_key(isc_mem_t *mctx, const char *randomfile, dns_secalg_t alg,
|
||||||
|
|
||||||
|
DO("create entropy context", isc_entropy_create(mctx, &ectx));
|
||||||
|
|
||||||
|
- if (randomfile != NULL && strcmp(randomfile, "keyboard") == 0) {
|
||||||
|
- randomfile = NULL;
|
||||||
|
- open_keyboard = ISC_ENTROPY_KEYBOARDYES;
|
||||||
|
- }
|
||||||
|
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
- if (randomfile != NULL &&
|
||||||
|
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
||||||
|
- randomfile = NULL;
|
||||||
|
+ if (randomfile == NULL) {
|
||||||
|
isc_entropy_usehook(ectx, true);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
+ if (randomfile != NULL && strcmp(randomfile, "keyboard") == 0) {
|
||||||
|
+ randomfile = NULL;
|
||||||
|
+ open_keyboard = ISC_ENTROPY_KEYBOARDYES;
|
||||||
|
+ }
|
||||||
|
DO("start entropy source", isc_entropy_usebestsource(ectx,
|
||||||
|
&entropy_source,
|
||||||
|
randomfile,
|
||||||
|
diff --git a/bin/dnssec/dnssec-keygen.docbook b/bin/dnssec/dnssec-keygen.docbook
|
||||||
|
index 0ae6b41..4562430 100644
|
||||||
|
--- a/bin/dnssec/dnssec-keygen.docbook
|
||||||
|
+++ b/bin/dnssec/dnssec-keygen.docbook
|
||||||
|
@@ -348,15 +348,23 @@
|
||||||
|
<term>-r <replaceable class="parameter">randomdev</replaceable></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
- Specifies the source of randomness. If the operating
|
||||||
|
- system does not provide a <filename>/dev/random</filename>
|
||||||
|
- or equivalent device, the default source of randomness
|
||||||
|
- is keyboard input. <filename>randomdev</filename>
|
||||||
|
- specifies
|
||||||
|
+ Specifies a source of randomness. Normally, when generating
|
||||||
|
+ DNSSEC keys, this option has no effect; the random number
|
||||||
|
+ generation function provided by the cryptographic library will
|
||||||
|
+ be used.
|
||||||
|
+ </para>
|
||||||
|
+ <para>
|
||||||
|
+ If that behavior is disabled at compile time, however,
|
||||||
|
+ the specified file will be used as entropy source
|
||||||
|
+ for key generation. <filename>randomdev</filename> is
|
||||||
|
the name of a character device or file containing random
|
||||||
|
- data to be used instead of the default. The special value
|
||||||
|
- <filename>keyboard</filename> indicates that keyboard
|
||||||
|
- input should be used.
|
||||||
|
+ data to be used. The special value <filename>keyboard</filename>
|
||||||
|
+ indicates that keyboard input should be used.
|
||||||
|
+ </para>
|
||||||
|
+ <para>
|
||||||
|
+ The default is <filename>/dev/random</filename> if the
|
||||||
|
+ operating system provides it or an equivalent device;
|
||||||
|
+ if not, the default source of randomness is keyboard input.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
diff --git a/bin/dnssec/dnssectool.c b/bin/dnssec/dnssectool.c
|
||||||
|
index 31a99e7..38c83ed 100644
|
||||||
|
--- a/bin/dnssec/dnssectool.c
|
||||||
|
+++ b/bin/dnssec/dnssectool.c
|
||||||
|
@@ -241,18 +241,16 @@ setup_entropy(isc_mem_t *mctx, const char *randomfile, isc_entropy_t **ectx) {
|
||||||
|
ISC_LIST_INIT(sources);
|
||||||
|
}
|
||||||
|
|
||||||
|
+#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
+ if (randomfile == NULL) {
|
||||||
|
+ isc_entropy_usehook(*ectx, true);
|
||||||
|
+ }
|
||||||
|
+#endif
|
||||||
|
if (randomfile != NULL && strcmp(randomfile, "keyboard") == 0) {
|
||||||
|
usekeyboard = ISC_ENTROPY_KEYBOARDYES;
|
||||||
|
randomfile = NULL;
|
||||||
|
}
|
||||||
|
|
||||||
|
-#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
- if (randomfile != NULL &&
|
||||||
|
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
||||||
|
- randomfile = NULL;
|
||||||
|
- isc_entropy_usehook(*ectx, true);
|
||||||
|
- }
|
||||||
|
-#endif
|
||||||
|
result = isc_entropy_usebestsource(*ectx, &source, randomfile,
|
||||||
|
usekeyboard);
|
||||||
|
|
||||||
|
diff --git a/bin/named/client.c b/bin/named/client.c
|
||||||
|
index 29fecad..a12623a 100644
|
||||||
|
--- a/bin/named/client.c
|
||||||
|
+++ b/bin/named/client.c
|
||||||
|
@@ -1752,7 +1752,8 @@ ns_client_addopt(ns_client_t *client, dns_message_t *message,
|
||||||
|
|
||||||
|
isc_buffer_init(&buf, cookie, sizeof(cookie));
|
||||||
|
isc_stdtime_get(&now);
|
||||||
|
- isc_random_get(&nonce);
|
||||||
|
+ nonce = ((isc_rng_random(ns_g_server->rngctx) << 16) |
|
||||||
|
+ isc_rng_random(ns_g_server->rngctx));
|
||||||
|
|
||||||
|
compute_cookie(client, now, nonce, ns_g_server->secret, &buf);
|
||||||
|
|
||||||
|
diff --git a/bin/named/config.c b/bin/named/config.c
|
||||||
|
index a153172..8d46bc3 100644
|
||||||
|
--- a/bin/named/config.c
|
||||||
|
+++ b/bin/named/config.c
|
||||||
|
@@ -93,7 +93,9 @@ options {\n\
|
||||||
|
# pid-file \"" NS_LOCALSTATEDIR "/run/named/named.pid\"; /* or /lwresd.pid */\n\
|
||||||
|
port 53;\n\
|
||||||
|
prefetch 2 9;\n"
|
||||||
|
-#ifdef PATH_RANDOMDEV
|
||||||
|
+#if defined(ISC_PLATFORM_CRYPTORANDOM)
|
||||||
|
+" random-device none;\n"
|
||||||
|
+#elif defined(PATH_RANDOMDEV)
|
||||||
|
" random-device \"" PATH_RANDOMDEV "\";\n"
|
||||||
|
#endif
|
||||||
|
" recursing-file \"named.recursing\";\n\
|
||||||
|
diff --git a/bin/named/controlconf.c b/bin/named/controlconf.c
|
||||||
|
index d955c2f..40621f2 100644
|
||||||
|
--- a/bin/named/controlconf.c
|
||||||
|
+++ b/bin/named/controlconf.c
|
||||||
|
@@ -325,9 +325,10 @@ log_invalid(isccc_ccmsg_t *ccmsg, isc_result_t result) {
|
||||||
|
|
||||||
|
static void
|
||||||
|
control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||||
|
- controlconnection_t *conn;
|
||||||
|
- controllistener_t *listener;
|
||||||
|
- controlkey_t *key;
|
||||||
|
+ controlconnection_t *conn = NULL;
|
||||||
|
+ controllistener_t *listener = NULL;
|
||||||
|
+ ns_server_t *server = NULL;
|
||||||
|
+ controlkey_t *key = NULL;
|
||||||
|
isccc_sexpr_t *request = NULL;
|
||||||
|
isccc_sexpr_t *response = NULL;
|
||||||
|
uint32_t algorithm;
|
||||||
|
@@ -338,16 +339,17 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||||
|
isc_buffer_t *text;
|
||||||
|
isc_result_t result;
|
||||||
|
isc_result_t eresult;
|
||||||
|
- isccc_sexpr_t *_ctrl;
|
||||||
|
+ isccc_sexpr_t *_ctrl = NULL;
|
||||||
|
isccc_time_t sent;
|
||||||
|
isccc_time_t exp;
|
||||||
|
uint32_t nonce;
|
||||||
|
- isccc_sexpr_t *data;
|
||||||
|
+ isccc_sexpr_t *data = NULL;
|
||||||
|
|
||||||
|
REQUIRE(event->ev_type == ISCCC_EVENT_CCMSG);
|
||||||
|
|
||||||
|
conn = event->ev_arg;
|
||||||
|
listener = conn->listener;
|
||||||
|
+ server = listener->controls->server;
|
||||||
|
algorithm = DST_ALG_UNKNOWN;
|
||||||
|
secret.rstart = NULL;
|
||||||
|
text = NULL;
|
||||||
|
@@ -458,8 +460,11 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
|
||||||
|
* Establish nonce.
|
||||||
|
*/
|
||||||
|
if (conn->nonce == 0) {
|
||||||
|
- while (conn->nonce == 0)
|
||||||
|
- isc_random_get(&conn->nonce);
|
||||||
|
+ while (conn->nonce == 0) {
|
||||||
|
+ uint16_t r1 = isc_rng_random(server->rngctx);
|
||||||
|
+ uint16_t r2 = isc_rng_random(server->rngctx);
|
||||||
|
+ conn->nonce = (r1 << 16) | r2;
|
||||||
|
+ }
|
||||||
|
eresult = ISC_R_SUCCESS;
|
||||||
|
} else
|
||||||
|
eresult = ns_control_docommand(request, listener->readonly, &text);
|
||||||
|
diff --git a/bin/named/include/named/server.h b/bin/named/include/named/server.h
|
||||||
|
index f5ed2b7..b2c1d05 100644
|
||||||
|
--- a/bin/named/include/named/server.h
|
||||||
|
+++ b/bin/named/include/named/server.h
|
||||||
|
@@ -20,6 +20,7 @@
|
||||||
|
#include <isc/log.h>
|
||||||
|
#include <isc/magic.h>
|
||||||
|
#include <isc/quota.h>
|
||||||
|
+#include <isc/random.h>
|
||||||
|
#include <isc/sockaddr.h>
|
||||||
|
#include <isc/types.h>
|
||||||
|
#include <isc/xml.h>
|
||||||
|
@@ -134,6 +135,7 @@ struct ns_server {
|
||||||
|
char * lockfile;
|
||||||
|
|
||||||
|
uint16_t transfer_tcp_message_size;
|
||||||
|
+ isc_rng_t * rngctx;
|
||||||
|
};
|
||||||
|
|
||||||
|
struct ns_altsecret {
|
||||||
|
diff --git a/bin/named/interfacemgr.c b/bin/named/interfacemgr.c
|
||||||
|
index 135533b..4546831 100644
|
||||||
|
--- a/bin/named/interfacemgr.c
|
||||||
|
+++ b/bin/named/interfacemgr.c
|
||||||
|
@@ -17,6 +17,7 @@
|
||||||
|
|
||||||
|
#include <isc/interfaceiter.h>
|
||||||
|
#include <isc/os.h>
|
||||||
|
+#include <isc/random.h>
|
||||||
|
#include <isc/string.h>
|
||||||
|
#include <isc/task.h>
|
||||||
|
#include <isc/util.h>
|
||||||
|
diff --git a/bin/named/query.c b/bin/named/query.c
|
||||||
|
index f85cc76..43a3661 100644
|
||||||
|
--- a/bin/named/query.c
|
||||||
|
+++ b/bin/named/query.c
|
||||||
|
@@ -19,6 +19,7 @@
|
||||||
|
#include <isc/hex.h>
|
||||||
|
#include <isc/mem.h>
|
||||||
|
#include <isc/print.h>
|
||||||
|
+#include <isc/random.h>
|
||||||
|
#include <isc/rwlock.h>
|
||||||
|
#include <isc/serial.h>
|
||||||
|
#include <isc/stats.h>
|
||||||
|
diff --git a/bin/named/server.c b/bin/named/server.c
|
||||||
|
index 405ff71..700f83d 100644
|
||||||
|
--- a/bin/named/server.c
|
||||||
|
+++ b/bin/named/server.c
|
||||||
|
@@ -8203,21 +8203,32 @@ load_configuration(const char *filename, ns_server_t *server,
|
||||||
|
* Open the source of entropy.
|
||||||
|
*/
|
||||||
|
if (first_time) {
|
||||||
|
+ const char *randomdev = NULL;
|
||||||
|
+ int level = ISC_LOG_ERROR;
|
||||||
|
obj = NULL;
|
||||||
|
result = ns_config_get(maps, "random-device", &obj);
|
||||||
|
- if (result != ISC_R_SUCCESS) {
|
||||||
|
+ if (result == ISC_R_SUCCESS) {
|
||||||
|
+ if (!cfg_obj_isvoid(obj)) {
|
||||||
|
+ level = ISC_LOG_INFO;
|
||||||
|
+ randomdev = cfg_obj_asstring(obj);
|
||||||
|
+ }
|
||||||
|
+ }
|
||||||
|
+ if (randomdev == NULL) {
|
||||||
|
+#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
+ isc_entropy_usehook(ns_g_entropy, true);
|
||||||
|
+#else
|
||||||
|
+ if ((obj != NULL) && !cfg_obj_isvoid(obj))
|
||||||
|
+ level = ISC_LOG_INFO;
|
||||||
|
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
|
||||||
|
- NS_LOGMODULE_SERVER, ISC_LOG_INFO,
|
||||||
|
+ NS_LOGMODULE_SERVER, level,
|
||||||
|
"no source of entropy found");
|
||||||
|
+ if ((obj == NULL) || cfg_obj_isvoid(obj)) {
|
||||||
|
+ CHECK(ISC_R_FAILURE);
|
||||||
|
+ }
|
||||||
|
+#endif
|
||||||
|
} else {
|
||||||
|
- const char *randomdev = cfg_obj_asstring(obj);
|
||||||
|
-#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
- if (strcmp(randomdev, ISC_PLATFORM_CRYPTORANDOM) == 0)
|
||||||
|
- isc_entropy_usehook(ns_g_entropy, true);
|
||||||
|
-#else
|
||||||
|
- int level = ISC_LOG_ERROR;
|
||||||
|
result = isc_entropy_createfilesource(ns_g_entropy,
|
||||||
|
- randomdev);
|
||||||
|
+ randomdev);
|
||||||
|
#ifdef PATH_RANDOMDEV
|
||||||
|
if (ns_g_fallbackentropy != NULL) {
|
||||||
|
level = ISC_LOG_INFO;
|
||||||
|
@@ -8228,8 +8239,8 @@ load_configuration(const char *filename, ns_server_t *server,
|
||||||
|
NS_LOGCATEGORY_GENERAL,
|
||||||
|
NS_LOGMODULE_SERVER,
|
||||||
|
level,
|
||||||
|
- "could not open entropy source "
|
||||||
|
- "%s: %s",
|
||||||
|
+ "could not open "
|
||||||
|
+ "entropy source %s: %s",
|
||||||
|
randomdev,
|
||||||
|
isc_result_totext(result));
|
||||||
|
}
|
||||||
|
@@ -8249,7 +8260,6 @@ load_configuration(const char *filename, ns_server_t *server,
|
||||||
|
}
|
||||||
|
isc_entropy_detach(&ns_g_fallbackentropy);
|
||||||
|
}
|
||||||
|
-#endif
|
||||||
|
#endif
|
||||||
|
}
|
||||||
|
}
|
||||||
|
@@ -9014,6 +9024,7 @@ ns_server_create(isc_mem_t *mctx, ns_server_t **serverp) {
|
||||||
|
server->in_roothints = NULL;
|
||||||
|
server->blackholeacl = NULL;
|
||||||
|
server->keepresporder = NULL;
|
||||||
|
+ server->rngctx = NULL;
|
||||||
|
|
||||||
|
/* Must be first. */
|
||||||
|
CHECKFATAL(dst_lib_init2(ns_g_mctx, ns_g_entropy,
|
||||||
|
@@ -9040,6 +9051,9 @@ ns_server_create(isc_mem_t *mctx, ns_server_t **serverp) {
|
||||||
|
CHECKFATAL(dns_tkeyctx_create(ns_g_mctx, ns_g_entropy,
|
||||||
|
&server->tkeyctx),
|
||||||
|
"creating TKEY context");
|
||||||
|
+ server->rngctx = NULL;
|
||||||
|
+ CHECKFATAL(isc_rng_create(ns_g_mctx, ns_g_entropy, &server->rngctx),
|
||||||
|
+ "creating random numbers context");
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Setup the server task, which is responsible for coordinating
|
||||||
|
@@ -9246,7 +9260,8 @@ ns_server_destroy(ns_server_t **serverp) {
|
||||||
|
|
||||||
|
if (server->zonemgr != NULL)
|
||||||
|
dns_zonemgr_detach(&server->zonemgr);
|
||||||
|
-
|
||||||
|
+ if (server->rngctx != NULL)
|
||||||
|
+ isc_rng_detach(&server->rngctx);
|
||||||
|
if (server->tkeyctx != NULL)
|
||||||
|
dns_tkeyctx_destroy(&server->tkeyctx);
|
||||||
|
|
||||||
|
@@ -13197,10 +13212,10 @@ newzone_cfgctx_destroy(void **cfgp) {
|
||||||
|
|
||||||
|
static isc_result_t
|
||||||
|
generate_salt(unsigned char *salt, size_t saltlen) {
|
||||||
|
- int i, n;
|
||||||
|
+ size_t i, n;
|
||||||
|
union {
|
||||||
|
unsigned char rnd[256];
|
||||||
|
- uint32_t rnd32[64];
|
||||||
|
+ uint16_t rnd16[128];
|
||||||
|
} rnd;
|
||||||
|
unsigned char text[512 + 1];
|
||||||
|
isc_region_t r;
|
||||||
|
@@ -13210,9 +13225,10 @@ generate_salt(unsigned char *salt, size_t saltlen) {
|
||||||
|
if (saltlen > 256U)
|
||||||
|
return (ISC_R_RANGE);
|
||||||
|
|
||||||
|
- n = (int) (saltlen + sizeof(uint32_t) - 1) / sizeof(uint32_t);
|
||||||
|
- for (i = 0; i < n; i++)
|
||||||
|
- isc_random_get(&rnd.rnd32[i]);
|
||||||
|
+ n = (saltlen + sizeof(uint16_t) - 1) / sizeof(uint16_t);
|
||||||
|
+ for (i = 0; i < n; i++) {
|
||||||
|
+ rnd.rnd16[i] = isc_rng_random(ns_g_server->rngctx);
|
||||||
|
+ }
|
||||||
|
|
||||||
|
memmove(salt, rnd.rnd, saltlen);
|
||||||
|
|
||||||
|
diff --git a/bin/nsupdate/nsupdate.c b/bin/nsupdate/nsupdate.c
|
||||||
|
index 0286987..0376377 100644
|
||||||
|
--- a/bin/nsupdate/nsupdate.c
|
||||||
|
+++ b/bin/nsupdate/nsupdate.c
|
||||||
|
@@ -283,9 +283,7 @@ setup_entropy(isc_mem_t *mctx, const char *randomfile, isc_entropy_t **ectx) {
|
||||||
|
}
|
||||||
|
|
||||||
|
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
- if (randomfile != NULL &&
|
||||||
|
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
||||||
|
- randomfile = NULL;
|
||||||
|
+ if (randomfile == NULL) {
|
||||||
|
isc_entropy_usehook(*ectx, true);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
diff --git a/bin/tests/system/pipelined/pipequeries.c b/bin/tests/system/pipelined/pipequeries.c
|
||||||
|
index 7b4f617..507bf0a 100644
|
||||||
|
--- a/bin/tests/system/pipelined/pipequeries.c
|
||||||
|
+++ b/bin/tests/system/pipelined/pipequeries.c
|
||||||
|
@@ -282,9 +282,7 @@ main(int argc, char *argv[]) {
|
||||||
|
ectx = NULL;
|
||||||
|
RUNCHECK(isc_entropy_create(mctx, &ectx));
|
||||||
|
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
- if (randomfile != NULL &&
|
||||||
|
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
||||||
|
- randomfile = NULL;
|
||||||
|
+ if (randomfile == NULL) {
|
||||||
|
isc_entropy_usehook(ectx, true);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
diff --git a/bin/tests/system/tkey/keycreate.c b/bin/tests/system/tkey/keycreate.c
|
||||||
|
index fe8698e..937fcc3 100644
|
||||||
|
--- a/bin/tests/system/tkey/keycreate.c
|
||||||
|
+++ b/bin/tests/system/tkey/keycreate.c
|
||||||
|
@@ -255,9 +255,7 @@ main(int argc, char *argv[]) {
|
||||||
|
ectx = NULL;
|
||||||
|
RUNCHECK(isc_entropy_create(mctx, &ectx));
|
||||||
|
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
- if (randomfile != NULL &&
|
||||||
|
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
||||||
|
- randomfile = NULL;
|
||||||
|
+ if (randomfile == NULL) {
|
||||||
|
isc_entropy_usehook(ectx, true);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
diff --git a/bin/tests/system/tkey/keydelete.c b/bin/tests/system/tkey/keydelete.c
|
||||||
|
index 2146f9b..64b8e74 100644
|
||||||
|
--- a/bin/tests/system/tkey/keydelete.c
|
||||||
|
+++ b/bin/tests/system/tkey/keydelete.c
|
||||||
|
@@ -171,6 +171,7 @@ main(int argc, char **argv) {
|
||||||
|
randomfile = argv[2];
|
||||||
|
argv += 2;
|
||||||
|
argc -= 2;
|
||||||
|
+ POST(argc);
|
||||||
|
}
|
||||||
|
keyname = argv[1];
|
||||||
|
|
||||||
|
@@ -182,9 +183,7 @@ main(int argc, char **argv) {
|
||||||
|
ectx = NULL;
|
||||||
|
RUNCHECK(isc_entropy_create(mctx, &ectx));
|
||||||
|
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
- if (randomfile != NULL &&
|
||||||
|
- strcmp(randomfile, ISC_PLATFORM_CRYPTORANDOM) == 0) {
|
||||||
|
- randomfile = NULL;
|
||||||
|
+ if (randomfile == NULL) {
|
||||||
|
isc_entropy_usehook(ectx, true);
|
||||||
|
}
|
||||||
|
#endif
|
||||||
|
diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml
|
||||||
|
index b40cb05..8a81438 100644
|
||||||
|
--- a/doc/arm/Bv9ARM-book.xml
|
||||||
|
+++ b/doc/arm/Bv9ARM-book.xml
|
||||||
|
@@ -5071,22 +5071,45 @@ badresp:1,adberr:0,findfail:0,valfail:0]
|
||||||
|
<term><command>random-device</command></term>
|
||||||
|
<listitem>
|
||||||
|
<para>
|
||||||
|
- The source of entropy to be used by the server. Entropy is
|
||||||
|
- primarily needed
|
||||||
|
- for DNSSEC operations, such as TKEY transactions and dynamic
|
||||||
|
- update of signed
|
||||||
|
- zones. This options specifies the device (or file) from which
|
||||||
|
- to read
|
||||||
|
- entropy. If this is a file, operations requiring entropy will
|
||||||
|
- fail when the
|
||||||
|
- file has been exhausted. If not specified, the default value
|
||||||
|
- is
|
||||||
|
- <filename>/dev/random</filename>
|
||||||
|
- (or equivalent) when present, and none otherwise. The
|
||||||
|
- <command>random-device</command> option takes
|
||||||
|
- effect during
|
||||||
|
- the initial configuration load at server startup time and
|
||||||
|
- is ignored on subsequent reloads.
|
||||||
|
+ Specifies a source of entropy to be used by the server.
|
||||||
|
+ This is a device or file from which to read entropy.
|
||||||
|
+ If it is a file, operations requiring entropy
|
||||||
|
+ will fail when the file has been exhausted.
|
||||||
|
+ </para>
|
||||||
|
+ <para>
|
||||||
|
+ Entropy is needed for cryptographic operations such as
|
||||||
|
+ TKEY transactions, dynamic update of signed zones, and
|
||||||
|
+ generation of TSIG session keys. It is also used for
|
||||||
|
+ seeding and stirring the pseudo-random number generator,
|
||||||
|
+ which is used for less critical functions requiring
|
||||||
|
+ randomness such as generation of DNS message transaction
|
||||||
|
+ ID's.
|
||||||
|
+ </para>
|
||||||
|
+ <para>
|
||||||
|
+ If <command>random-device</command> is not specified, or
|
||||||
|
+ if it is set to <literal>none</literal>, entropy will be
|
||||||
|
+ read from the random number generation function supplied
|
||||||
|
+ by the cryptographic library with which BIND was linked
|
||||||
|
+ (i.e. OpenSSL or a PKCS#11 provider).
|
||||||
|
+ </para>
|
||||||
|
+ <para>
|
||||||
|
+ The <command>random-device</command> option takes
|
||||||
|
+ effect during the initial configuration load at server
|
||||||
|
+ startup time and is ignored on subsequent reloads.
|
||||||
|
+ </para>
|
||||||
|
+ <para>
|
||||||
|
+ If BIND is built with
|
||||||
|
+ <command>configure --disable-crypto-rand</command>, then
|
||||||
|
+ entropy is <emphasis>not</emphasis> sourced from the
|
||||||
|
+ cryptographic library. In this case, if
|
||||||
|
+ <command>random-device</command> is not specified, the
|
||||||
|
+ default value is the system random device,
|
||||||
|
+ <filename>/dev/random</filename> or the equivalent.
|
||||||
|
+ This default can be overridden with
|
||||||
|
+ <command>configure --with-randomdev</command>.
|
||||||
|
+ If no system random device exists, then no entropy source
|
||||||
|
+ will be configured, and <command>named</command> will only
|
||||||
|
+ be able to use pseudo-random numbers.
|
||||||
|
</para>
|
||||||
|
</listitem>
|
||||||
|
</varlistentry>
|
||||||
|
diff --git a/doc/arm/notes.xml b/doc/arm/notes.xml
|
||||||
|
index 00ce8f1..527135a 100644
|
||||||
|
--- a/doc/arm/notes.xml
|
||||||
|
+++ b/doc/arm/notes.xml
|
||||||
|
@@ -124,6 +124,37 @@
|
||||||
|
</itemizedlist>
|
||||||
|
</section>
|
||||||
|
|
||||||
|
+ <section xml:id="relnotes_rh_changes"><info><title>Red Hat Specific Changes</title></info>
|
||||||
|
+ <itemizedlist>
|
||||||
|
+ <listitem>
|
||||||
|
+ <para>
|
||||||
|
+ By default, BIND now uses the random number generation functions
|
||||||
|
+ in the cryptographic library (i.e., OpenSSL or a PKCS#11
|
||||||
|
+ provider) as a source of high-quality randomness rather than
|
||||||
|
+ <filename>/dev/random</filename>. This is suitable for virtual
|
||||||
|
+ machine environments, which may have limited entropy pools and
|
||||||
|
+ lack hardware random number generators.
|
||||||
|
+ </para>
|
||||||
|
+ <para>
|
||||||
|
+ This can be overridden by specifying another entropy source via
|
||||||
|
+ the <command>random-device</command> option in
|
||||||
|
+ <filename>named.conf</filename>, or via the <command>-r</command>
|
||||||
|
+ command line option. However, for functions requiring full
|
||||||
|
+ cryptographic strength, such as DNSSEC key generation, this
|
||||||
|
+ <emphasis>cannot</emphasis> be overridden. In particular, the
|
||||||
|
+ <command>-r</command> command line option no longer has any
|
||||||
|
+ effect on <command>dnssec-keygen</command>.
|
||||||
|
+ </para>
|
||||||
|
+ <para>
|
||||||
|
+ This can be disabled by building with
|
||||||
|
+ <command>configure --disable-crypto-rand</command>, in which
|
||||||
|
+ case <filename>/dev/random</filename> will be the default
|
||||||
|
+ entropy source. [RT #31459] [RT #46047]
|
||||||
|
+ </para>
|
||||||
|
+ </listitem>
|
||||||
|
+ </itemizedlist>
|
||||||
|
+ </section>
|
||||||
|
+
|
||||||
|
<section xml:id="end_of_life"><info><title>End of Life</title></info>
|
||||||
|
<para>
|
||||||
|
BIND 9.11 (Extended Support Version) will be supported until at
|
||||||
|
diff --git a/lib/dns/dst_api.c b/lib/dns/dst_api.c
|
||||||
|
index b55ebe0..d2b43d3 100644
|
||||||
|
--- a/lib/dns/dst_api.c
|
||||||
|
+++ b/lib/dns/dst_api.c
|
||||||
|
@@ -2016,10 +2016,12 @@ dst__entropy_getdata(void *buf, unsigned int len, bool pseudo) {
|
||||||
|
else
|
||||||
|
flags |= ISC_ENTROPY_BLOCKING;
|
||||||
|
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
+ /* get entropy directly from crypto provider */
|
||||||
|
return (dst_random_getdata(buf, len, NULL, flags));
|
||||||
|
#else
|
||||||
|
+ /* get entropy from entropy source or hook function */
|
||||||
|
return (isc_entropy_getdata(dst_entropy_pool, buf, len, NULL, flags));
|
||||||
|
-#endif
|
||||||
|
+#endif /* ISC_PLATFORM_CRYPTORANDOM */
|
||||||
|
#endif /* PKCS11CRYPTO */
|
||||||
|
}
|
||||||
|
|
||||||
|
diff --git a/lib/dns/include/dst/dst.h b/lib/dns/include/dst/dst.h
|
||||||
|
index 6813c96..665574d 100644
|
||||||
|
--- a/lib/dns/include/dst/dst.h
|
||||||
|
+++ b/lib/dns/include/dst/dst.h
|
||||||
|
@@ -163,8 +163,18 @@ isc_result_t
|
||||||
|
dst_random_getdata(void *data, unsigned int length,
|
||||||
|
unsigned int *returned, unsigned int flags);
|
||||||
|
/*%<
|
||||||
|
- * \brief Return data from the crypto random generator.
|
||||||
|
- * Specialization of isc_entropy_getdata().
|
||||||
|
+ * Gets random data from the random generator provided by the
|
||||||
|
+ * crypto library, if BIND was built with --enable-crypto-rand.
|
||||||
|
+ *
|
||||||
|
+ * See isc_entropy_getdata() for parameter usage. Normally when
|
||||||
|
+ * this function is available, it will be set up as a hook in the
|
||||||
|
+ * entropy context, so that isc_entropy_getdata() is a front-end to
|
||||||
|
+ * this function.
|
||||||
|
+ *
|
||||||
|
+ * Returns:
|
||||||
|
+ * \li ISC_R_SUCCESS on success
|
||||||
|
+ * \li ISC_R_NOTIMPLEMENTED if BIND is built with --disable-crypto-rand
|
||||||
|
+ * \li DST_R_OPENSSLFAILURE, DST_R_CRYPTOFAILURE, or other codes on error
|
||||||
|
*/
|
||||||
|
|
||||||
|
bool
|
||||||
|
diff --git a/lib/dns/openssl_link.c b/lib/dns/openssl_link.c
|
||||||
|
index 6849732..e00a0e4 100644
|
||||||
|
--- a/lib/dns/openssl_link.c
|
||||||
|
+++ b/lib/dns/openssl_link.c
|
||||||
|
@@ -484,7 +484,8 @@ dst__openssl_getengine(const char *engine) {
|
||||||
|
|
||||||
|
isc_result_t
|
||||||
|
dst_random_getdata(void *data, unsigned int length,
|
||||||
|
- unsigned int *returned, unsigned int flags) {
|
||||||
|
+ unsigned int *returned, unsigned int flags)
|
||||||
|
+{
|
||||||
|
#ifdef ISC_PLATFORM_CRYPTORANDOM
|
||||||
|
#ifndef DONT_REQUIRE_DST_LIB_INIT
|
||||||
|
INSIST(dst__memory_pool != NULL);
|
||||||
|
diff --git a/lib/isc/include/isc/entropy.h b/lib/isc/include/isc/entropy.h
|
||||||
|
index 632166a..c7cb17d 100644
|
||||||
|
--- a/lib/isc/include/isc/entropy.h
|
||||||
|
+++ b/lib/isc/include/isc/entropy.h
|
||||||
|
@@ -9,8 +9,6 @@
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
-/* $Id: entropy.h,v 1.35 2009/10/19 02:37:08 marka Exp $ */
|
||||||
|
-
|
||||||
|
#ifndef ISC_ENTROPY_H
|
||||||
|
#define ISC_ENTROPY_H 1
|
||||||
|
|
||||||
|
@@ -191,9 +189,8 @@ isc_entropy_createcallbacksource(isc_entropy_t *ent,
|
||||||
|
/*!<
|
||||||
|
* \brief Create an entropy source that is polled via a callback.
|
||||||
|
*
|
||||||
|
- * This would
|
||||||
|
- * be used when keyboard input is used, or a GUI input method. It can
|
||||||
|
- * also be used to hook in any external entropy source.
|
||||||
|
+ * This would be used when keyboard input is used, or a GUI input method.
|
||||||
|
+ * It can also be used to hook in any external entropy source.
|
||||||
|
*
|
||||||
|
* Samples are added via isc_entropy_addcallbacksample(), below.
|
||||||
|
* _addcallbacksample() is the only function which may be called from
|
||||||
|
@@ -234,15 +231,32 @@ isc_result_t
|
||||||
|
isc_entropy_getdata(isc_entropy_t *ent, void *data, unsigned int length,
|
||||||
|
unsigned int *returned, unsigned int flags);
|
||||||
|
/*!<
|
||||||
|
- * \brief Extract data from the entropy pool. This may load the pool from various
|
||||||
|
- * sources.
|
||||||
|
+ * \brief Get random data from entropy pool 'ent'.
|
||||||
|
+ *
|
||||||
|
+ * If a hook has been set up using isc_entropy_sethook() and
|
||||||
|
+ * isc_entropy_usehook(), then the hook function will be called to get
|
||||||
|
+ * random data.
|
||||||
|
+ *
|
||||||
|
+ * Otherwise, randomness is extracted from the entropy pool set up in BIND.
|
||||||
|
+ * This may cause the pool to be loaded from various sources. Ths is done
|
||||||
|
+ * by stirring the pool and returning a part of hash as randomness.
|
||||||
|
+ * (Note that no secrets are given away here since parts of the hash are
|
||||||
|
+ * XORed together before returning.)
|
||||||
|
+ *
|
||||||
|
+ * 'flags' may contain ISC_ENTROPY_GOODONLY, ISC_ENTROPY_PARTIAL, or
|
||||||
|
+ * ISC_ENTROPY_BLOCKING. These will be honored if the hook function is
|
||||||
|
+ * not in use. If it is, the flags will be passed to the hook function
|
||||||
|
+ * but it may ignore them.
|
||||||
|
*
|
||||||
|
- * Do this by stiring the pool and returning a part of hash as randomness.
|
||||||
|
- * Note that no secrets are given away here since parts of the hash are
|
||||||
|
- * xored together before returned.
|
||||||
|
+ * Up to 'length' bytes of randomness are retrieved and copied into 'data'.
|
||||||
|
+ * (If 'returned' is not NULL, and the number of bytes copied is less than
|
||||||
|
+ * 'length' - which may happen if ISC_ENTROPY_PARTIAL was used - then the
|
||||||
|
+ * number of bytes copied will be stored in *returned.)
|
||||||
|
*
|
||||||
|
- * Honor the request from the caller to only return good data, any data,
|
||||||
|
- * etc.
|
||||||
|
+ * Returns:
|
||||||
|
+ * \li ISC_R_SUCCESS on success
|
||||||
|
+ * \li ISC_R_NOENTROPY if entropy pool is empty
|
||||||
|
+ * \li other error codes are possible when a hook is in use
|
||||||
|
*/
|
||||||
|
|
||||||
|
void
|
||||||
|
@@ -307,13 +321,21 @@ isc_entropy_usebestsource(isc_entropy_t *ectx, isc_entropysource_t **source,
|
||||||
|
void
|
||||||
|
isc_entropy_usehook(isc_entropy_t *ectx, bool onoff);
|
||||||
|
/*!<
|
||||||
|
- * \brief Mark/unmark the given entropy structure as being hooked.
|
||||||
|
+ * \brief Configure entropy context 'ectx' to use the hook function
|
||||||
|
+ *
|
||||||
|
+ * Sets the entropy context to call the hook function for random number
|
||||||
|
+ * generation, if such a function has been configured via
|
||||||
|
+ * isc_entropy_sethook(), whenever isc_entropy_getdata() is called.
|
||||||
|
*/
|
||||||
|
|
||||||
|
void
|
||||||
|
isc_entropy_sethook(isc_entropy_getdata_t myhook);
|
||||||
|
/*!<
|
||||||
|
- * \brief Set the getdata hook (e.g., for a crypto random generator).
|
||||||
|
+ * \brief Set the hook function.
|
||||||
|
+ *
|
||||||
|
+ * The hook function is a global value: only one hook function
|
||||||
|
+ * can be set in the system. Individual entropy contexts may be
|
||||||
|
+ * configured to use it, or not, by calling isc_entropy_usehook().
|
||||||
|
*/
|
||||||
|
|
||||||
|
ISC_LANG_ENDDECLS
|
||||||
|
diff --git a/lib/isc/include/isc/random.h b/lib/isc/include/isc/random.h
|
||||||
|
index f8aed34..17c551b 100644
|
||||||
|
--- a/lib/isc/include/isc/random.h
|
||||||
|
+++ b/lib/isc/include/isc/random.h
|
||||||
|
@@ -9,8 +9,6 @@
|
||||||
|
* information regarding copyright ownership.
|
||||||
|
*/
|
||||||
|
|
||||||
|
-/* $Id: random.h,v 1.20 2009/01/17 23:47:43 tbox Exp $ */
|
||||||
|
-
|
||||||
|
#ifndef ISC_RANDOM_H
|
||||||
|
#define ISC_RANDOM_H 1
|
||||||
|
|
||||||
|
@@ -21,13 +19,23 @@
|
||||||
|
#include <isc/mutex.h>
|
||||||
|
|
||||||
|
/*! \file isc/random.h
|
||||||
|
- * \brief Implements a random state pool which will let the caller return a
|
||||||
|
- * series of possibly non-reproducible random values.
|
||||||
|
+ * \brief Implements pseudo random number generators.
|
||||||
|
+ *
|
||||||
|
+ * Two pseudo-random number generators are implemented, in isc_random_*
|
||||||
|
+ * and isc_rng_*. Neither one is very strong; they should not be used
|
||||||
|
+ * in cryptography functions.
|
||||||
|
+ *
|
||||||
|
+ * isc_random_* is based on arc4random if it is available on the system.
|
||||||
|
+ * Otherwise it is based on the posix srand() and rand() functions.
|
||||||
|
+ * It is useful for jittering values a bit here and there, such as
|
||||||
|
+ * timeouts, etc, but should not be relied upon to generate
|
||||||
|
+ * unpredictable sequences (for example, when choosing transaction IDs).
|
||||||
|
*
|
||||||
|
- * Note that the
|
||||||
|
- * strength of these numbers is not all that high, and should not be
|
||||||
|
- * used in cryptography functions. It is useful for jittering values
|
||||||
|
- * a bit here and there, such as timeouts, etc.
|
||||||
|
+ * isc_rng_* is based on ChaCha20, and is seeded and stirred from the
|
||||||
|
+ * system entropy source. It is stronger than isc_random_* and can
|
||||||
|
+ * be used for generating unpredictable sequences. It is still not as
|
||||||
|
+ * good as using system entropy directly (see entropy.h) and should not
|
||||||
|
+ * be used for cryptographic functions such as key generation.
|
||||||
|
*/
|
||||||
|
|
||||||
|
ISC_LANG_BEGINDECLS
|
||||||
|
@@ -115,8 +123,8 @@ isc_rng_random(isc_rng_t *rngctx);
|
||||||
|
uint16_t
|
||||||
|
isc_rng_uniformrandom(isc_rng_t *rngctx, uint16_t upper_bound);
|
||||||
|
/*%<
|
||||||
|
- * Returns a uniformly distributed pseudo random 16-bit unsigned
|
||||||
|
- * integer.
|
||||||
|
+ * Returns a uniformly distributed pseudo-random 16-bit unsigned integer
|
||||||
|
+ * less than 'upper_bound'.
|
||||||
|
*/
|
||||||
|
|
||||||
|
ISC_LANG_ENDDECLS
|
||||||
|
diff --git a/lib/isccfg/namedconf.c b/lib/isccfg/namedconf.c
|
||||||
|
index fbc62cc..9cad61d 100644
|
||||||
|
--- a/lib/isccfg/namedconf.c
|
||||||
|
+++ b/lib/isccfg/namedconf.c
|
||||||
|
@@ -1109,7 +1109,7 @@ options_clauses[] = {
|
||||||
|
{ "pid-file", &cfg_type_qstringornone, 0 },
|
||||||
|
{ "port", &cfg_type_uint32, 0 },
|
||||||
|
{ "querylog", &cfg_type_boolean, 0 },
|
||||||
|
- { "random-device", &cfg_type_qstring, 0 },
|
||||||
|
+ { "random-device", &cfg_type_qstringornone, 0 },
|
||||||
|
{ "recursing-file", &cfg_type_qstring, 0 },
|
||||||
|
{ "recursive-clients", &cfg_type_uint32, 0 },
|
||||||
|
{ "reserved-sockets", &cfg_type_uint32, 0 },
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
39
bind-9.11-tests-pkcs11.patch
Normal file
39
bind-9.11-tests-pkcs11.patch
Normal file
|
|
@ -0,0 +1,39 @@
|
||||||
|
From 66298a12b09784eab2c052ab22f87bb2b2f1267b Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Fri, 1 Mar 2019 15:55:46 +0100
|
||||||
|
Subject: [PATCH] Detect correctly pkcs11 support
|
||||||
|
|
||||||
|
It fails now always, because oot builds are not supported by
|
||||||
|
cleanpkcs11.sh.
|
||||||
|
---
|
||||||
|
bin/tests/system/cleanpkcs11.sh | 2 +-
|
||||||
|
bin/tests/system/conf.sh.in | 1 +
|
||||||
|
2 files changed, 2 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/bin/tests/system/cleanpkcs11.sh b/bin/tests/system/cleanpkcs11.sh
|
||||||
|
index b974708..3bbef4c 100644
|
||||||
|
--- a/bin/tests/system/cleanpkcs11.sh
|
||||||
|
+++ b/bin/tests/system/cleanpkcs11.sh
|
||||||
|
@@ -12,6 +12,6 @@
|
||||||
|
SYSTEMTESTTOP=.
|
||||||
|
. $SYSTEMTESTTOP/conf.sh
|
||||||
|
|
||||||
|
-if [ ! -x ../../pkcs11/pkcs11-destroy ]; then exit 1; fi
|
||||||
|
+if [ ! -x "$PK11DESTROY" ]; then exit 1; fi
|
||||||
|
|
||||||
|
$PK11DEL -w0 > /dev/null 2>&1
|
||||||
|
diff --git a/bin/tests/system/conf.sh.in b/bin/tests/system/conf.sh.in
|
||||||
|
index a446c18..ede1203 100644
|
||||||
|
--- a/bin/tests/system/conf.sh.in
|
||||||
|
+++ b/bin/tests/system/conf.sh.in
|
||||||
|
@@ -46,6 +46,7 @@ CHECKZONE=$TOP/bin/check/named-checkzone
|
||||||
|
CHECKCONF=$TOP/bin/check/named-checkconf
|
||||||
|
PK11GEN="$TOP/bin/pkcs11/pkcs11-keygen -q -s ${SLOT:-0} -p ${HSMPIN:-1234}"
|
||||||
|
PK11LIST="$TOP/bin/pkcs11/pkcs11-list -s ${SLOT:-0} -p ${HSMPIN:-1234}"
|
||||||
|
+PK11DESTROY=$TOP/bin/pkcs11/pkcs11-destroy
|
||||||
|
PK11DEL="$TOP/bin/pkcs11/pkcs11-destroy -s ${SLOT:-0} -p ${HSMPIN:-1234} -w 0"
|
||||||
|
JOURNALPRINT=$TOP/bin/tools/named-journalprint
|
||||||
|
VERIFY=$TOP/bin/dnssec/dnssec-verify
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
65
bind-9.11-tests-variants.patch
Normal file
65
bind-9.11-tests-variants.patch
Normal file
|
|
@ -0,0 +1,65 @@
|
||||||
|
From 06a22ff20ac3d68fa1f995c91068b43392425e43 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Fri, 1 Mar 2019 15:48:20 +0100
|
||||||
|
Subject: [PATCH] Make alternative named builds testable in system tests
|
||||||
|
|
||||||
|
Red Hat has alternative variant builds of named, which are not ever
|
||||||
|
tested by system tests. New variables make it relatively easy to test
|
||||||
|
alternative variants.
|
||||||
|
|
||||||
|
For sdb variant use:
|
||||||
|
export NAMED_VARIANT=-sdb DNSSEC_VARIANT=
|
||||||
|
|
||||||
|
For pkcs variant use:
|
||||||
|
export NAMED_VARIANT=-pkcs11 DNSSEC_VARIANT=-pkcs11
|
||||||
|
---
|
||||||
|
bin/tests/system/conf.sh.in | 19 ++++++++++---------
|
||||||
|
1 file changed, 10 insertions(+), 9 deletions(-)
|
||||||
|
|
||||||
|
diff --git a/bin/tests/system/conf.sh.in b/bin/tests/system/conf.sh.in
|
||||||
|
index 4b0fe39..f135af6 100644
|
||||||
|
--- a/bin/tests/system/conf.sh.in
|
||||||
|
+++ b/bin/tests/system/conf.sh.in
|
||||||
|
@@ -34,7 +34,7 @@ DISABLED_ALGORITHM=ECDSAP384SHA384
|
||||||
|
DISABLED_ALGORITHM_NUMBER=14
|
||||||
|
DISABLED_BITS=384
|
||||||
|
|
||||||
|
-NAMED=$TOP/bin/named/named
|
||||||
|
+NAMED=$TOP/bin/named${NAMED_VARIANT}/named${NAMED_VARIANT}
|
||||||
|
# We must use "named -l" instead of "lwresd" because argv[0] is lost
|
||||||
|
# if the program is libtoolized.
|
||||||
|
LWRESD="$TOP/bin/named/named -l"
|
||||||
|
@@ -45,13 +45,14 @@ NSUPDATE=$TOP/bin/nsupdate/nsupdate
|
||||||
|
DDNSCONFGEN=$TOP/bin/confgen/ddns-confgen
|
||||||
|
TSIGKEYGEN=$TOP/bin/confgen/tsig-keygen
|
||||||
|
RNDCCONFGEN=$TOP/bin/confgen/rndc-confgen
|
||||||
|
-KEYGEN=$TOP/bin/dnssec/dnssec-keygen
|
||||||
|
-KEYFRLAB=$TOP/bin/dnssec/dnssec-keyfromlabel
|
||||||
|
-SIGNER=$TOP/bin/dnssec/dnssec-signzone
|
||||||
|
-REVOKE=$TOP/bin/dnssec/dnssec-revoke
|
||||||
|
-SETTIME=$TOP/bin/dnssec/dnssec-settime
|
||||||
|
-DSFROMKEY=$TOP/bin/dnssec/dnssec-dsfromkey
|
||||||
|
-IMPORTKEY=$TOP/bin/dnssec/dnssec-importkey
|
||||||
|
+KEYGEN=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-keygen${DNSSEC_VARIANT}
|
||||||
|
+KEYFRLAB=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-keyfromlabel${DNSSEC_VARIANT}
|
||||||
|
+SIGNER=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-signzone${DNSSEC_VARIANT}
|
||||||
|
+REVOKE=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-revoke${DNSSEC_VARIANT}
|
||||||
|
+SETTIME=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-settime${DNSSEC_VARIANT}
|
||||||
|
+DSFROMKEY=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-dsfromkey${DNSSEC_VARIANT}
|
||||||
|
+IMPORTKEY=$TOP/bin/dnssec${DNSSEC_VARIANT}/dnssec-importkey${DNSSEC_VARIANT}
|
||||||
|
+CHECKDS=$TOP/bin/python/dnssec-checkds
|
||||||
|
CHECKDS=$TOP/bin/python/dnssec-checkds
|
||||||
|
COVERAGE=$TOP/bin/python/dnssec-coverage
|
||||||
|
KEYMGR=$TOP/bin/python/dnssec-keymgr
|
||||||
|
@@ -71,7 +72,7 @@ DNSTAPREAD=$TOP/bin/tools/dnstap-read
|
||||||
|
MDIG=$TOP/bin/tools/mdig
|
||||||
|
NZD2NZF=$TOP/bin/tools/named-nzd2nzf
|
||||||
|
FSTRM_CAPTURE=@FSTRM_CAPTURE@
|
||||||
|
-FEATURETEST=$TOP/bin/named/feature-test
|
||||||
|
+FEATURETEST=$TOP/bin/named${NAMED_VARIANT}/feature-test${NAMED_VARIANT}
|
||||||
|
|
||||||
|
RANDFILE=$TOP/bin/tests/system/random.data
|
||||||
|
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
30
bind-9.11-unit-disable-random.patch
Normal file
30
bind-9.11-unit-disable-random.patch
Normal file
|
|
@ -0,0 +1,30 @@
|
||||||
|
From 373f07148217a8e70e33446f5108fb42d1079ba6 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Mensik <pemensik@redhat.com>
|
||||||
|
Date: Thu, 21 Feb 2019 22:42:27 +0100
|
||||||
|
Subject: [PATCH] Disable random_test
|
||||||
|
|
||||||
|
It fails too often on some architecture, failing the whole build along.
|
||||||
|
Because it runs two times for pkcs11 and normal build and any of
|
||||||
|
subtests can occasionally fail, stop it.
|
||||||
|
|
||||||
|
It can be used again by defining 'unstable' variable in Kyuafile.
|
||||||
|
---
|
||||||
|
lib/isc/tests/Kyuafile | 2 +-
|
||||||
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/lib/isc/tests/Kyuafile b/lib/isc/tests/Kyuafile
|
||||||
|
index 4cd2574..9df2340 100644
|
||||||
|
--- a/lib/isc/tests/Kyuafile
|
||||||
|
+++ b/lib/isc/tests/Kyuafile
|
||||||
|
@@ -19,7 +19,7 @@ tap_test_program{name='pool_test'}
|
||||||
|
tap_test_program{name='print_test'}
|
||||||
|
tap_test_program{name='queue_test'}
|
||||||
|
tap_test_program{name='radix_test'}
|
||||||
|
-tap_test_program{name='random_test'}
|
||||||
|
+tap_test_program{name='random_test', required_configs='unstable'}
|
||||||
|
tap_test_program{name='regex_test'}
|
||||||
|
tap_test_program{name='result_test'}
|
||||||
|
tap_test_program{name='safe_test'}
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
16
bind-9.11.10.tar.gz.asc
Normal file
16
bind-9.11.10.tar.gz.asc
Normal file
|
|
@ -0,0 +1,16 @@
|
||||||
|
-----BEGIN PGP SIGNATURE-----
|
||||||
|
|
||||||
|
iQIzBAABAgAdFiEErj+seWcR7Fn8AHqkdLtrmky7PTgFAl1VKuIACgkQdLtrmky7
|
||||||
|
PThvHg/+O+c3U/k/3wYB5XAmT2HSCIqIp8gdu4+0B4rsIJAN+aR1HDIsCTuJqyjw
|
||||||
|
jw9fI61d5skxeJljbNChAMTC2Ps1W7bXHFC8B25WQvQAcL/FDJQrLtgRXCJKB9sd
|
||||||
|
/hss07hGrrZbE5wRePJJtn4R1d6WLoA/hz1da7IcoZJpFPmlkHE9kZUd9mPAHnMv
|
||||||
|
QYCqpl821m53UMENufyrwNMDTaIwqPM4fJ8OVBam/743ZIOP/imwMVnJws6HjRz1
|
||||||
|
n4JPoKsMkLOTV0hDotgTl7V1qm4EXKG5xPM882frpfRkk/V/qOvEzLkgVLDF6xHR
|
||||||
|
iuZsMvKfrc/VyrKRcQNHs2kA0EqbKfskLoSenj7B/WrvVCeQ+MA4MSg/81Rzzs6P
|
||||||
|
gDDCMcWY3X2VlYUA521Z9DagoC49DpfKf+rfeCH/HTNjdWkfClnQoGb9n5Ggy/sM
|
||||||
|
NP/ApLN2TOHqMIMU0RGr2U3OY8TNmpq7xfggnr3qL5Of1ez4HYlyLdmma3HPJjvY
|
||||||
|
uYdJwVRcJ7rq510QBSf8VGK9/qERkhklh4MZvIzS5htnn+94Gk3gT8p3aZGQ5z2d
|
||||||
|
W2RVl+4HQ7aRtQMeQeX79uccVF9vcTBTiAJhILYcp7Q6NBOVMTCabSAnRk3f0GfS
|
||||||
|
1x+Ojt+7yVCB3pym8N+mHM3q8l7VvIw1As7QAGi6mdVAaTN8zxc=
|
||||||
|
=ZIsR
|
||||||
|
-----END PGP SIGNATURE-----
|
||||||
|
|
@ -1,16 +0,0 @@
|
||||||
-----BEGIN PGP SIGNATURE-----
|
|
||||||
|
|
||||||
iQIzBAABAgAdFiEErj+seWcR7Fn8AHqkdLtrmky7PTgFAl2WMooACgkQdLtrmky7
|
|
||||||
PThv2RAAnXNLYTzXtH6ls29tRm5Hc+D6UaeqcWDNQ4BpkRVhrFxtukalGCi9mmB6
|
|
||||||
NPJzFyXmaOW654pypCIuEgqJNFUpDtLzLzT7SUF+mhm+5plsaRSBnh4mq87l5KSp
|
|
||||||
twODAPnfCJV+HBk5RmToLEstAbGQ7xEBTyQtZoFkY+V7zEFwENKiCvWsoSWOkYR3
|
|
||||||
zXo3sKjc83HV9ShbW/mCtbZf5L0qlbrKOAzqJfAFMhNNJi8kMbmr/Zi2sIfN+Rhv
|
|
||||||
g8HQo89Epv6r51yAdeED8idIX4rKjjcEtHrZeDmLdCcdHgSEj2sIlH92Joce6vL0
|
|
||||||
S59A0rItIXm6fW8sz6WNpcj4tVtWYbIYjXZ4SPFNkaUrHv8cUekq+5vbI+v07Gh3
|
|
||||||
2bhtDsDyTY5I1/AsY/EFmwkCAjUS00jZryBnuJpLB3v5JtUog4ek32yLBzPrqRBo
|
|
||||||
1876j4nlXAia8mG0OgJNWZ0gHyUPe/TgfR8fQDLmHxHHlKrJNTEwY6bLW8jzFTX1
|
|
||||||
zk510fI1K7J9tiQgf5wcBQ2h3EBlqzDNIJDovoATzLYIf0HKyVegh/vnQdtdEhUR
|
|
||||||
1DzJAt3bsBfAP1AFfWPD/ACu5Zdm7SxY1wE/pjkwttDU3sRZqOfuwNBGeolu3cVN
|
|
||||||
O9/h1zsyVeVS0ui2vu4+V4EvNitmXsVbG2doDq9L5yBiIKGO2Ew=
|
|
||||||
=GCy6
|
|
||||||
-----END PGP SIGNATURE-----
|
|
||||||
29
bind-9.11.5-P4.tar.gz.asc
Normal file
29
bind-9.11.5-P4.tar.gz.asc
Normal file
|
|
@ -0,0 +1,29 @@
|
||||||
|
-----BEGIN PGP SIGNATURE-----
|
||||||
|
Comment: GPGTools - http://gpgtools.org
|
||||||
|
|
||||||
|
iQIzBAABAgAdFiEEvg6XSLcYJToou4n/8bEb8FzwLlcFAlxks5sACgkQ8bEb8Fzw
|
||||||
|
Lld2iA//SfqtuHZGjTKVk35vLEjpK52Xs/rmawtTI1aMApk8jEXgD7yASa5dkgM1
|
||||||
|
xRcU7H/8omkf16Oi1m1fdamnMYhW6AvbfX4hdRY9EDn3JepXGdO0ft9G2KzmvZBt
|
||||||
|
mU8bcqOfPHzEG0mu/oWMtL9eh9Edh5dFWxHkSGUnadXFTWH0NXRiyQwwmY6VexV4
|
||||||
|
CQ7VkfP1fkuyZpq5tjyg9Z/umOmmwuwjkoaTbHxtfRLWVwMNgw24Pt6hUqjjJmCz
|
||||||
|
auDlBuGXKjBgRqRmAQR3klmcvNCna3+4e1+W9w/pgRxeEr9YD1JLVyhsAvLZ9FUc
|
||||||
|
Dpxz/MKfRkM71Lv3wvxrIODUrmSSecQ520lljxnNammnO0UuS6Og7LCpl6fSWm0c
|
||||||
|
y3A51mq25TJ1AyOlaiSU2TPYc5XJOMjyBqIqAvJei1cV/R2gMTjbYGz3rU+b9LlG
|
||||||
|
iRgdvAmUUhvBYAKXX7SmMUOFpXDiFv+Zbk0Gincok47VHihO4hksPx+RbL8BSOUJ
|
||||||
|
PGsQytwVnSQJTrDGuELyQYSGJzN8l8fMLKckNiRecNWFHCOQFpkdbtlYp+C4yopR
|
||||||
|
lGkx04ZVarlJBOPRkoN6mzZiXR17WaghHHXNq4gOP+HME6YAWJv3oLAAxeD8Tvyd
|
||||||
|
p4M4xCHw3WZt6OiKwgCE02wnthn3aUyRv+oOGYCL3+eTtoUzdNKJAjMEAAECAB0W
|
||||||
|
IQQVaJBoXqDfahNx7yAXzF2x8AiEBwUCXGSznAAKCRAXzF2x8AiEB3qgD/4qc2S3
|
||||||
|
KcshK/BX10j75dmPVmNGdW1SH8V1h+nFKVIkvTzVXybBL3XeF7HP6/aJd460ku4n
|
||||||
|
XZ5FXd78f+g+G2gJaMA+rprS0NfpclhUS64SVTSDY727dnmV49xDdRIpqmUB7B1w
|
||||||
|
Nx9bLRHBxuPigE6S+Nmt78xrFmtS1cwegY2pz3ZD4HDDmtKMRuhZ9el71S7vLJyh
|
||||||
|
60pvFCqQMPJX7r0OXFC4iYwgIHab0iHQu4AASvaXzi03dR2S058aRk6gBMoBlQcL
|
||||||
|
Mcc/RzpHdJAKRx1bmU3h//HUAa5S6cKpRjDsFGj0GtFNY/ksdevTXTM3qB9k5GlR
|
||||||
|
T4mEadsWP3ARL9qQHyW4eStTdkH1qzgJF2tKn2M+dXlfdRXNImZPrEDXOfzmyRfA
|
||||||
|
ZoJLBeaJw5MaWeTtAcuPsppGDUuA9+hk9mpycmFZrxD21X4pr+NMrHa3TCFzAwgF
|
||||||
|
qyc96uX1SiFMRyUmLJY2ZMBR2y8W7TdL+MWjWzsGxQg8Dj3IaAbvRg1XztxDP9XB
|
||||||
|
RPYTniq7VOw4eEk3UgfjnIYfnEBQY+5d79MlSwxE4NBRg/h+ulZSHjP5HQ6BGzqu
|
||||||
|
aPg+p/P+G2GfQ5x0RxchG0B/Ogj2PRIwXptgwOXVoEs1671odj3aEE5E8JKquYlO
|
||||||
|
PRIIubc/EfYopZfyM2ryv2hAT+1z8ngeac1ycQ==
|
||||||
|
=kFOo
|
||||||
|
-----END PGP SIGNATURE-----
|
||||||
16
bind-9.11.6-P1.tar.gz.asc
Normal file
16
bind-9.11.6-P1.tar.gz.asc
Normal file
|
|
@ -0,0 +1,16 @@
|
||||||
|
-----BEGIN PGP SIGNATURE-----
|
||||||
|
|
||||||
|
iQIzBAABAgAdFiEEFWiQaF6g32oTce8gF8xdsfAIhAcFAlysrg0ACgkQF8xdsfAI
|
||||||
|
hAc4qQ/6A2odUTpjuaPQK/ziTD8UpJXyqFr5rZ+Qx3+wAA7XcFF6rviRwQ1dULu/
|
||||||
|
AmQVhAWeXHa15ruFVFJZoovnRoKYUZLOtvTrcfJkHG0MwBivEpJ/rcOLlOWhAHeG
|
||||||
|
N6q5teyOrG1kCXNcS8uGHqzm+QfMA3xCUqCpYHWOtZ60I9T3O+8Y6Xyzb+oc6+CY
|
||||||
|
w1pXeq0doJa9tFnZpVvhCPTol4LPL8KkTLoMmpRA5dRMrVYH3f45fdixABn3HSFx
|
||||||
|
Ea/CiMeGvIfZI0X119Txufw2Yi8/NMicf/iZBEmvvHUG49/tFX2Vmj4sxUkL4gY/
|
||||||
|
qqXEkD7oQsVEUj3X12ITyOqj6CtfiJcOgJIzTVas3vD4QR51nRSY+IGYuH7zQUSf
|
||||||
|
qVSCFKdLY2NlRwK6VSBVOxN5Ye31qwPEok6WgGgBy2+mWY+FvAm4Z4sIBeyX2QT/
|
||||||
|
A0+42GuFErMne7Ppd9Pb+cCKhaIDC4i3vM/lA8kvMvhz+peqKux6MbD9Ab79hSuV
|
||||||
|
HCZzAzFPsuaHxP1m6wRWYgeGUZWA89uTbwGa5iiAmiXXqhHswzxBCgfKXyUjuObn
|
||||||
|
pH+XTeZ59qTgQZT3bdyj0QrmCM0JfvFEt2OkuBIDvAnoVcb0smyLrizYaZLo+0of
|
||||||
|
6OLW76WW2GSjzvfT4RlDP5B3ns3PdjrCKaKji3aIUD7G/oYr7zA=
|
||||||
|
=TsjB
|
||||||
|
-----END PGP SIGNATURE-----
|
||||||
|
|
@ -1,16 +0,0 @@
|
||||||
-----BEGIN PGP SIGNATURE-----
|
|
||||||
|
|
||||||
iQIzBAABAgAdFiEErj+seWcR7Fn8AHqkdLtrmky7PTgFAl2WMpEACgkQdLtrmky7
|
|
||||||
PTh/sg//QbNRAQvADQfwF1PPo+JxB+3WzQ9oJAWeHbOoiubwkUwO9xE+BEnTNd5o
|
|
||||||
oM1lSLqFxNykOTaoeJlqPftPod1cxo7lSzkwflugGyB/59wliCpqCg053YV4x9mO
|
|
||||||
QggvA/E50+0FI/Om/7v4GHGADu/JE83FovOueWAB0LgqfDSD6QFcNFF9sUJJ4P7r
|
|
||||||
FcEXSWj8QbrHMWBKncZUOpD2ECotvtrYmi0DTHl1XfigESDQpWtsnTFuabCCsvkh
|
|
||||||
ch9wQRplAes2Mf/aS5tl1y0QKKBFuEjtGiTdgrDl6o9GLnx6CueX5saZehu2EVkr
|
|
||||||
fq2vEYUC2lRQSjuxSMMJ3L0TGUcl7+ixlAIISS2K9L5Xx7MhBXt/EH5KiKPfsEet
|
|
||||||
3EH+DhxV5uXjDU7MgvREnxT+ssV23e0HWTz4tVVQ9LpvYmWPIgLcSOhHCc57yoQF
|
|
||||||
c46V0f69dMWbMAlQ93EZSG274ZvpIszpK8+3hGI3/TuDFFgiQJeJJBFVtYJMle69
|
|
||||||
3mEEclfzO7fBiXZFec6nVx2309bL64bafN7zszPKXl4XgoefOfD0v0eWqQT4fxfm
|
|
||||||
dnGC0qMqSZs5F+d0fISV5JUUNYzt9PZjvnzqLLGOeTF6l3/n9G1mmNsXcxJ1OEIF
|
|
||||||
6qh1oO7JTPjt0MFhKac4QjNQi/Bnp25O3I/PRyWZCbiwXkyvyQU=
|
|
||||||
=ZT7s
|
|
||||||
-----END PGP SIGNATURE-----
|
|
||||||
|
|
@ -1,854 +0,0 @@
|
||||||
From 2a4786b0edde59274f682c9bd4ae4026c2d08218 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Evan Hunt <each@isc.org>
|
|
||||||
Date: Wed, 1 Jul 2026 22:56:02 -0700
|
|
||||||
Subject: [PATCH] add isctest.mark method for ecdsa_deterinistic
|
|
||||||
|
|
||||||
This checks support for ECDSA deterministic mode in the cryptography
|
|
||||||
library.
|
|
||||||
|
|
||||||
(cherry picked from commit 6e44151466864d3dd783a20da83d01028781d3e2)
|
|
||||||
(cherry picked from commit dc3f52388427f4f94087d984d5a2088b925810e2)
|
|
||||||
|
|
||||||
Reproducer for #5874 NSEC3 impersonation
|
|
||||||
|
|
||||||
LLM generated.
|
|
||||||
|
|
||||||
(cherry picked from commit f3e2eb333be3ac636f745aa13cfb8d9ee8af87d8)
|
|
||||||
(cherry picked from commit 35e3d49d2222c13786a06021c7ed583d2a656e51)
|
|
||||||
|
|
||||||
Update reproducer #5874
|
|
||||||
|
|
||||||
Update the llm generated reproducer:
|
|
||||||
- Move server.py into ans1/ans.py
|
|
||||||
- Remove unnecessary named.conf configuration options
|
|
||||||
- Add comments describing the steps (copied from GL issue)
|
|
||||||
- Rename system test
|
|
||||||
|
|
||||||
(cherry picked from commit c1321fef165a2ef8c2bff971901c58941e8e694c)
|
|
||||||
(cherry picked from commit 833dd3b230b92596074e8da15b12298f46c939f2)
|
|
||||||
---
|
|
||||||
bin/tests/system/chain/ans3/ans.py | 10 +-
|
|
||||||
bin/tests/system/chain/ans4/ans.py | 8 +-
|
|
||||||
bin/tests/system/cookie/ans9/ans.py | 7 +-
|
|
||||||
bin/tests/system/digdelv/ans8/ans.py | 7 +-
|
|
||||||
bin/tests/system/dnssec/ans10/ans.py | 11 +-
|
|
||||||
bin/tests/system/forward/ans11/ans.py | 12 +-
|
|
||||||
bin/tests/system/isctest/mark.py | 12 +
|
|
||||||
.../system/nsec3_impersonation/ans1/ans.py | 280 ++++++++++++++++++
|
|
||||||
.../nsec3_impersonation/ns2/named.conf.j2 | 33 +++
|
|
||||||
.../tests_nsec3_impersonation.py | 152 ++++++++++
|
|
||||||
bin/tests/system/qmin/ans2/ans.py | 11 +-
|
|
||||||
bin/tests/system/qmin/ans3/ans.py | 11 +-
|
|
||||||
bin/tests/system/qmin/ans4/ans.py | 11 +-
|
|
||||||
bin/tests/system/resolver/ans10/ans.py | 12 +-
|
|
||||||
14 files changed, 529 insertions(+), 48 deletions(-)
|
|
||||||
create mode 100644 bin/tests/system/nsec3_impersonation/ans1/ans.py
|
|
||||||
create mode 100644 bin/tests/system/nsec3_impersonation/ns2/named.conf.j2
|
|
||||||
create mode 100644 bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/chain/ans3/ans.py b/bin/tests/system/chain/ans3/ans.py
|
|
||||||
index 0a031c1145..7c54c3c51a 100644
|
|
||||||
--- a/bin/tests/system/chain/ans3/ans.py
|
|
||||||
+++ b/bin/tests/system/chain/ans3/ans.py
|
|
||||||
@@ -19,10 +19,10 @@ import sys
|
|
||||||
import signal
|
|
||||||
import socket
|
|
||||||
import select
|
|
||||||
-from datetime import datetime, timedelta
|
|
||||||
-import functools
|
|
||||||
|
|
||||||
-import dns, dns.message, dns.query
|
|
||||||
+import dns
|
|
||||||
+import dns.message
|
|
||||||
+import dns.query
|
|
||||||
from dns.rdatatype import *
|
|
||||||
from dns.rdataclass import *
|
|
||||||
from dns.rcode import *
|
|
||||||
@@ -173,9 +173,9 @@ else:
|
|
||||||
while running:
|
|
||||||
try:
|
|
||||||
inputready, outputready, exceptready = select.select(input, [], [])
|
|
||||||
- except select.error as e:
|
|
||||||
+ except select.error:
|
|
||||||
break
|
|
||||||
- except socket.error as e:
|
|
||||||
+ except socket.error:
|
|
||||||
break
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
break
|
|
||||||
diff --git a/bin/tests/system/chain/ans4/ans.py b/bin/tests/system/chain/ans4/ans.py
|
|
||||||
index c969117368..de536b25bd 100755
|
|
||||||
--- a/bin/tests/system/chain/ans4/ans.py
|
|
||||||
+++ b/bin/tests/system/chain/ans4/ans.py
|
|
||||||
@@ -22,7 +22,9 @@ import select
|
|
||||||
from datetime import datetime, timedelta
|
|
||||||
import functools
|
|
||||||
|
|
||||||
-import dns, dns.message, dns.query
|
|
||||||
+import dns
|
|
||||||
+import dns.message
|
|
||||||
+import dns.query
|
|
||||||
from dns.rdatatype import *
|
|
||||||
from dns.rdataclass import *
|
|
||||||
from dns.rcode import *
|
|
||||||
@@ -371,9 +373,9 @@ else:
|
|
||||||
while running:
|
|
||||||
try:
|
|
||||||
inputready, outputready, exceptready = select.select(input, [], [])
|
|
||||||
- except select.error as e:
|
|
||||||
+ except select.error:
|
|
||||||
break
|
|
||||||
- except socket.error as e:
|
|
||||||
+ except socket.error:
|
|
||||||
break
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
break
|
|
||||||
diff --git a/bin/tests/system/cookie/ans9/ans.py b/bin/tests/system/cookie/ans9/ans.py
|
|
||||||
index 3b0f82cc1d..2710386d74 100644
|
|
||||||
--- a/bin/tests/system/cookie/ans9/ans.py
|
|
||||||
+++ b/bin/tests/system/cookie/ans9/ans.py
|
|
||||||
@@ -15,9 +15,6 @@ import sys
|
|
||||||
import signal
|
|
||||||
import socket
|
|
||||||
import select
|
|
||||||
-from datetime import datetime, timedelta
|
|
||||||
-import time
|
|
||||||
-import functools
|
|
||||||
|
|
||||||
import dns
|
|
||||||
import dns.edns
|
|
||||||
@@ -257,9 +254,9 @@ else:
|
|
||||||
while running:
|
|
||||||
try:
|
|
||||||
inputready, outputready, exceptready = select.select(input, [], [])
|
|
||||||
- except select.error as e:
|
|
||||||
+ except select.error:
|
|
||||||
break
|
|
||||||
- except socket.error as e:
|
|
||||||
+ except socket.error:
|
|
||||||
break
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
break
|
|
||||||
diff --git a/bin/tests/system/digdelv/ans8/ans.py b/bin/tests/system/digdelv/ans8/ans.py
|
|
||||||
index 3e18edc1cc..1896a2bafc 100644
|
|
||||||
--- a/bin/tests/system/digdelv/ans8/ans.py
|
|
||||||
+++ b/bin/tests/system/digdelv/ans8/ans.py
|
|
||||||
@@ -17,7 +17,8 @@ import socket
|
|
||||||
import select
|
|
||||||
import struct
|
|
||||||
|
|
||||||
-import dns, dns.message
|
|
||||||
+import dns
|
|
||||||
+import dns.message
|
|
||||||
from dns.rcode import *
|
|
||||||
|
|
||||||
modes = [
|
|
||||||
@@ -109,9 +110,9 @@ hung_conns = []
|
|
||||||
while running:
|
|
||||||
try:
|
|
||||||
inputready, outputready, exceptready = select.select(input, [], [])
|
|
||||||
- except select.error as e:
|
|
||||||
+ except select.error:
|
|
||||||
break
|
|
||||||
- except socket.error as e:
|
|
||||||
+ except socket.error:
|
|
||||||
break
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
break
|
|
||||||
diff --git a/bin/tests/system/dnssec/ans10/ans.py b/bin/tests/system/dnssec/ans10/ans.py
|
|
||||||
index 84bf0a2642..46af72a147 100644
|
|
||||||
--- a/bin/tests/system/dnssec/ans10/ans.py
|
|
||||||
+++ b/bin/tests/system/dnssec/ans10/ans.py
|
|
||||||
@@ -16,10 +16,11 @@ import signal
|
|
||||||
import socket
|
|
||||||
import select
|
|
||||||
from datetime import datetime, timedelta
|
|
||||||
-import time
|
|
||||||
-import functools
|
|
||||||
|
|
||||||
-import dns, dns.message, dns.query, dns.flags
|
|
||||||
+import dns
|
|
||||||
+import dns.message
|
|
||||||
+import dns.query
|
|
||||||
+import dns.flags
|
|
||||||
from dns.rdatatype import *
|
|
||||||
from dns.rdataclass import *
|
|
||||||
from dns.rcode import *
|
|
||||||
@@ -140,9 +141,9 @@ else:
|
|
||||||
while running:
|
|
||||||
try:
|
|
||||||
inputready, outputready, exceptready = select.select(input, [], [])
|
|
||||||
- except select.error as e:
|
|
||||||
+ except select.error:
|
|
||||||
break
|
|
||||||
- except socket.error as e:
|
|
||||||
+ except socket.error:
|
|
||||||
break
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
break
|
|
||||||
diff --git a/bin/tests/system/forward/ans11/ans.py b/bin/tests/system/forward/ans11/ans.py
|
|
||||||
index 00b5895f76..d5b8a5b037 100644
|
|
||||||
--- a/bin/tests/system/forward/ans11/ans.py
|
|
||||||
+++ b/bin/tests/system/forward/ans11/ans.py
|
|
||||||
@@ -16,11 +16,11 @@ import signal
|
|
||||||
import socket
|
|
||||||
import select
|
|
||||||
import struct
|
|
||||||
-from datetime import datetime, timedelta
|
|
||||||
-import time
|
|
||||||
-import functools
|
|
||||||
|
|
||||||
-import dns, dns.message, dns.query, dns.flags
|
|
||||||
+import dns
|
|
||||||
+import dns.message
|
|
||||||
+import dns.query
|
|
||||||
+import dns.flags
|
|
||||||
from dns.rdatatype import *
|
|
||||||
from dns.rdataclass import *
|
|
||||||
from dns.rcode import *
|
|
||||||
@@ -192,9 +192,9 @@ hung_conns = []
|
|
||||||
while running:
|
|
||||||
try:
|
|
||||||
inputready, outputready, exceptready = select.select(input, [], [])
|
|
||||||
- except select.error as e:
|
|
||||||
+ except select.error:
|
|
||||||
break
|
|
||||||
- except socket.error as e:
|
|
||||||
+ except socket.error:
|
|
||||||
break
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
break
|
|
||||||
diff --git a/bin/tests/system/isctest/mark.py b/bin/tests/system/isctest/mark.py
|
|
||||||
index 53860a806c..098af5acfc 100644
|
|
||||||
--- a/bin/tests/system/isctest/mark.py
|
|
||||||
+++ b/bin/tests/system/isctest/mark.py
|
|
||||||
@@ -88,3 +88,15 @@ softhsm2_environment = pytest.mark.skipif(
|
|
||||||
),
|
|
||||||
reason="SOFTHSM2_CONF and SOFTHSM2_MODULE environmental variables must be set and pkcs11-tool and softhsm2-util tools present",
|
|
||||||
)
|
|
||||||
+
|
|
||||||
+ecdsa_deterministic = False
|
|
||||||
+try:
|
|
||||||
+ from cryptography.hazmat.backends import default_backend
|
|
||||||
+
|
|
||||||
+ ecdsa_deterministic = default_backend().ecdsa_deterministic_supported()
|
|
||||||
+except Exception: # pylint: disable=broad-except
|
|
||||||
+ pass
|
|
||||||
+
|
|
||||||
+with_ecdsa_deterministic = pytest.mark.skipif(
|
|
||||||
+ not ecdsa_deterministic, reason="ECDSA deterministic signing is not supported"
|
|
||||||
+)
|
|
||||||
diff --git a/bin/tests/system/nsec3_impersonation/ans1/ans.py b/bin/tests/system/nsec3_impersonation/ans1/ans.py
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..177e79c195
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/nsec3_impersonation/ans1/ans.py
|
|
||||||
@@ -0,0 +1,280 @@
|
|
||||||
+#!/usr/bin/python3
|
|
||||||
+
|
|
||||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+#
|
|
||||||
+# SPDX-License-Identifier: MPL-2.0
|
|
||||||
+#
|
|
||||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+#
|
|
||||||
+# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+# information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+from collections.abc import AsyncGenerator
|
|
||||||
+from dataclasses import dataclass
|
|
||||||
+from pathlib import Path
|
|
||||||
+
|
|
||||||
+import json
|
|
||||||
+
|
|
||||||
+from cryptography.hazmat.primitives import serialization
|
|
||||||
+
|
|
||||||
+import dns.dnssec
|
|
||||||
+import dns.flags
|
|
||||||
+import dns.message
|
|
||||||
+import dns.name
|
|
||||||
+import dns.rcode
|
|
||||||
+import dns.rdata
|
|
||||||
+import dns.rdataclass
|
|
||||||
+import dns.rdatatype
|
|
||||||
+import dns.rrset
|
|
||||||
+
|
|
||||||
+from isctest.asyncserver import (
|
|
||||||
+ AsyncDnsServer,
|
|
||||||
+ DnsResponseSend,
|
|
||||||
+ QueryContext,
|
|
||||||
+ ResponseHandler,
|
|
||||||
+)
|
|
||||||
+
|
|
||||||
+TTL = 300
|
|
||||||
+TLD = "tld.test."
|
|
||||||
+APEX_HASH = "1B40241KFORIOG780N4IKSCRLVETPCTQ"
|
|
||||||
+ATTACKER = f"{APEX_HASH.lower()}.{TLD}"
|
|
||||||
+VICTIM = f"victim.{TLD}"
|
|
||||||
+AUTH_IP = "10.53.0.1"
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+@dataclass(frozen=True)
|
|
||||||
+class Key:
|
|
||||||
+ zone: dns.name.Name
|
|
||||||
+ private_key: object
|
|
||||||
+ dnskey: dns.rdata.Rdata
|
|
||||||
+ ds: dns.rdata.Rdata
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def name(text: str) -> dns.name.Name:
|
|
||||||
+ return dns.name.from_text(text)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def load_keys() -> dict[str, Key]:
|
|
||||||
+ path = Path(__file__).resolve().parent / "keys.json"
|
|
||||||
+ with path.open(encoding="utf-8") as keys_file:
|
|
||||||
+ raw_keys = json.load(keys_file)
|
|
||||||
+
|
|
||||||
+ keys = {}
|
|
||||||
+ for zone, raw_key in raw_keys.items():
|
|
||||||
+ private_key = serialization.load_pem_private_key(
|
|
||||||
+ raw_key["private_pem"].encode("ascii"),
|
|
||||||
+ password=None,
|
|
||||||
+ )
|
|
||||||
+ dnskey = dns.rdata.from_text(
|
|
||||||
+ dns.rdataclass.IN, dns.rdatatype.DNSKEY, raw_key["dnskey"]
|
|
||||||
+ )
|
|
||||||
+ ds = dns.rdata.from_text(dns.rdataclass.IN, dns.rdatatype.DS, raw_key["ds"])
|
|
||||||
+ keys[zone] = Key(name(zone), private_key, dnskey, ds)
|
|
||||||
+
|
|
||||||
+ return keys
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def rrset(owner: str, rdtype: dns.rdatatype.RdataType, *rdatas: str) -> dns.rrset.RRset:
|
|
||||||
+ return dns.rrset.from_text(owner, TTL, dns.rdataclass.IN, rdtype, *rdatas)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def rrset_from_rdata(owner: str, rdata: dns.rdata.Rdata) -> dns.rrset.RRset:
|
|
||||||
+ return dns.rrset.from_rdata(name(owner), TTL, rdata)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def rrsig_rrset(covered: dns.rrset.RRset, signer: Key) -> dns.rrset.RRset:
|
|
||||||
+ rrsig = dns.dnssec.sign(
|
|
||||||
+ covered,
|
|
||||||
+ signer.private_key,
|
|
||||||
+ signer.zone,
|
|
||||||
+ signer.dnskey,
|
|
||||||
+ lifetime=86400,
|
|
||||||
+ verify=True,
|
|
||||||
+ )
|
|
||||||
+ return dns.rrset.from_rdata(covered.name, covered.ttl, rrsig)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def add_signed(
|
|
||||||
+ section: list[dns.rrset.RRset], covered: dns.rrset.RRset, signer: Key
|
|
||||||
+) -> None:
|
|
||||||
+ section.append(covered)
|
|
||||||
+ section.append(rrsig_rrset(covered, signer))
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def dnskey_rrset(zone: str, zone_key: Key) -> dns.rrset.RRset:
|
|
||||||
+ return rrset_from_rdata(zone, zone_key.dnskey)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def ds_rrset(zone: str, zone_key: Key) -> dns.rrset.RRset:
|
|
||||||
+ return rrset_from_rdata(zone, zone_key.ds)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def soa_rrset(zone: str) -> dns.rrset.RRset:
|
|
||||||
+ return rrset(
|
|
||||||
+ zone,
|
|
||||||
+ dns.rdatatype.SOA,
|
|
||||||
+ f"ns.{zone} hostmaster.{zone} 1 3600 600 86400 300",
|
|
||||||
+ )
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def ns_rrset(zone: str, ns_target: str) -> dns.rrset.RRset:
|
|
||||||
+ return rrset(zone, dns.rdatatype.NS, ns_target)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def glue_rrset(ns_target: str, address: str) -> dns.rrset.RRset:
|
|
||||||
+ return rrset(ns_target, dns.rdatatype.A, address)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def answer_dnskey(response: dns.message.Message, zone: str, zone_key: Key) -> None:
|
|
||||||
+ add_signed(response.answer, dnskey_rrset(zone, zone_key), zone_key)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def answer_soa(response: dns.message.Message, zone: str, zone_key: Key) -> None:
|
|
||||||
+ add_signed(response.answer, soa_rrset(zone), zone_key)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def answer_ns(
|
|
||||||
+ response: dns.message.Message, zone: str, ns_target: str, zone_key: Key
|
|
||||||
+) -> None:
|
|
||||||
+ add_signed(response.answer, ns_rrset(zone, ns_target), zone_key)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class SignedResponseHandler(ResponseHandler):
|
|
||||||
+ def __init__(self, keys: dict[str, Key]) -> None:
|
|
||||||
+ self.keys = keys
|
|
||||||
+
|
|
||||||
+ async def get_responses(
|
|
||||||
+ self, qctx: QueryContext
|
|
||||||
+ ) -> AsyncGenerator[DnsResponseSend, None]:
|
|
||||||
+ qctx.prepare_new_response(with_zone_data=False)
|
|
||||||
+ qctx.response.flags |= dns.flags.AA
|
|
||||||
+ qctx.response.set_rcode(dns.rcode.NOERROR)
|
|
||||||
+ self.respond(qctx)
|
|
||||||
+ yield DnsResponseSend(qctx.response, authoritative=True)
|
|
||||||
+
|
|
||||||
+ def respond(self, qctx: QueryContext) -> None:
|
|
||||||
+ raise NotImplementedError
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def child_nsec3_rrset() -> dns.rrset.RRset:
|
|
||||||
+ rdata = dns.rdata.from_text(
|
|
||||||
+ dns.rdataclass.IN,
|
|
||||||
+ dns.rdatatype.NSEC3,
|
|
||||||
+ f"1 0 0 - {APEX_HASH} NS SOA RRSIG DNSKEY NSEC3PARAM",
|
|
||||||
+ )
|
|
||||||
+ return dns.rrset.from_rdata(name(f"{APEX_HASH}.{TLD}"), TTL, rdata)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def forged_nxdomain(response: dns.message.Message, keys: dict[str, Key]) -> None:
|
|
||||||
+ response.set_rcode(dns.rcode.NXDOMAIN)
|
|
||||||
+
|
|
||||||
+ add_signed(response.authority, soa_rrset(TLD), keys[TLD])
|
|
||||||
+
|
|
||||||
+ # The owner name derives zone "tld.test.", but the RRSIG signer is the
|
|
||||||
+ # malicious child zone "1b40241kforiog780n4ikscrlvetpctq.tld.test.".
|
|
||||||
+ add_signed(response.authority, child_nsec3_rrset(), keys[ATTACKER])
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class VictimForgedNxdomainHandler(SignedResponseHandler):
|
|
||||||
+ """
|
|
||||||
+ This serves the forged response for the victim's domain.
|
|
||||||
+ """
|
|
||||||
+
|
|
||||||
+ def match(self, qctx: QueryContext) -> bool:
|
|
||||||
+ return qctx.qname == name(VICTIM) and qctx.qtype == dns.rdatatype.A
|
|
||||||
+
|
|
||||||
+ def respond(self, qctx: QueryContext) -> None:
|
|
||||||
+ forged_nxdomain(qctx.response, self.keys)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class ChildDsHandler(SignedResponseHandler):
|
|
||||||
+ """
|
|
||||||
+ This will spoof the response for the malicious zone when qtype is DS.
|
|
||||||
+ It is actually a validly signed DS response.
|
|
||||||
+ """
|
|
||||||
+
|
|
||||||
+ def match(self, qctx: QueryContext) -> bool:
|
|
||||||
+ return qctx.qname == name(ATTACKER) and qctx.qtype == dns.rdatatype.DS
|
|
||||||
+
|
|
||||||
+ def respond(self, qctx: QueryContext) -> None:
|
|
||||||
+ response = qctx.response
|
|
||||||
+ zone = ATTACKER
|
|
||||||
+ child_key = self.keys[ATTACKER]
|
|
||||||
+ parent_key = self.keys[TLD]
|
|
||||||
+
|
|
||||||
+ add_signed(response.answer, ds_rrset(zone, child_key), parent_key)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class AttackerZoneHandler(SignedResponseHandler):
|
|
||||||
+ """
|
|
||||||
+ Acts as the malicious authoritative name server. The zone being served
|
|
||||||
+ is the hashed label of the parent zone (tld.test). This will respond
|
|
||||||
+ for all queries qtype SOA, DNSKEY, NS at the apex. Any names below
|
|
||||||
+ the apex are answered with an NXDOMAIN with no NSEC or NSEC3 present.
|
|
||||||
+ """
|
|
||||||
+
|
|
||||||
+ def match(self, qctx: QueryContext) -> bool:
|
|
||||||
+ return qctx.qname.is_subdomain(name(ATTACKER))
|
|
||||||
+
|
|
||||||
+ def respond(self, qctx: QueryContext) -> None:
|
|
||||||
+ if qctx.qname == name(ATTACKER):
|
|
||||||
+ if qctx.qtype == dns.rdatatype.DNSKEY:
|
|
||||||
+ answer_dnskey(qctx.response, ATTACKER, self.keys[ATTACKER])
|
|
||||||
+ elif qctx.qtype == dns.rdatatype.SOA:
|
|
||||||
+ answer_soa(qctx.response, ATTACKER, self.keys[ATTACKER])
|
|
||||||
+ else:
|
|
||||||
+ answer_ns(
|
|
||||||
+ qctx.response, ATTACKER, f"ns.{ATTACKER}", self.keys[ATTACKER]
|
|
||||||
+ )
|
|
||||||
+ qctx.response.additional.append(glue_rrset(f"ns.{ATTACKER}", AUTH_IP))
|
|
||||||
+ return
|
|
||||||
+
|
|
||||||
+ qctx.response.set_rcode(dns.rcode.NXDOMAIN)
|
|
||||||
+ add_signed(qctx.response.authority, soa_rrset(ATTACKER), self.keys[ATTACKER])
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class TldZoneHandler(SignedResponseHandler):
|
|
||||||
+ """
|
|
||||||
+ Acts as the TLD who is being used in the attack, but is not a standard
|
|
||||||
+ name server. It only responds with validly signed records for DNSKEY, SOA
|
|
||||||
+ and NS on the apex. Any names below the apex are answered with an NXDOMAIN
|
|
||||||
+ with no NSEC or NSEC3 present.
|
|
||||||
+
|
|
||||||
+ If we turn this into a regular name server than the attack won't work.
|
|
||||||
+ The attack assumes that the adversary can inject these responses on-path.
|
|
||||||
+ """
|
|
||||||
+
|
|
||||||
+ def match(self, qctx: QueryContext) -> bool:
|
|
||||||
+ return qctx.qname.is_subdomain(name(TLD))
|
|
||||||
+
|
|
||||||
+ def respond(self, qctx: QueryContext) -> None:
|
|
||||||
+ if qctx.qname == name(TLD):
|
|
||||||
+ if qctx.qtype == dns.rdatatype.DNSKEY:
|
|
||||||
+ answer_dnskey(qctx.response, TLD, self.keys[TLD])
|
|
||||||
+ elif qctx.qtype == dns.rdatatype.SOA:
|
|
||||||
+ answer_soa(qctx.response, TLD, self.keys[TLD])
|
|
||||||
+ else:
|
|
||||||
+ answer_ns(qctx.response, TLD, "ns.tld.test.", self.keys[TLD])
|
|
||||||
+ qctx.response.additional.append(glue_rrset("ns.tld.test.", AUTH_IP))
|
|
||||||
+ return
|
|
||||||
+
|
|
||||||
+ qctx.response.set_rcode(dns.rcode.NXDOMAIN)
|
|
||||||
+ add_signed(qctx.response.authority, soa_rrset(TLD), self.keys[TLD])
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def main() -> None:
|
|
||||||
+ keys = load_keys()
|
|
||||||
+ server = AsyncDnsServer(default_aa=True)
|
|
||||||
+ server.install_response_handlers(
|
|
||||||
+ VictimForgedNxdomainHandler(keys),
|
|
||||||
+ ChildDsHandler(keys),
|
|
||||||
+ AttackerZoneHandler(keys),
|
|
||||||
+ TldZoneHandler(keys),
|
|
||||||
+ )
|
|
||||||
+ server.run()
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+if __name__ == "__main__":
|
|
||||||
+ main()
|
|
||||||
diff --git a/bin/tests/system/nsec3_impersonation/ns2/named.conf.j2 b/bin/tests/system/nsec3_impersonation/ns2/named.conf.j2
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..2c9b0bba9e
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/nsec3_impersonation/ns2/named.conf.j2
|
|
||||||
@@ -0,0 +1,33 @@
|
|
||||||
+// validating resolver
|
|
||||||
+
|
|
||||||
+options {
|
|
||||||
+ query-source address 10.53.0.2;
|
|
||||||
+ notify-source 10.53.0.2;
|
|
||||||
+ transfer-source 10.53.0.2;
|
|
||||||
+ port @PORT@;
|
|
||||||
+ pid-file "named.pid";
|
|
||||||
+ listen-on { 10.53.0.2; };
|
|
||||||
+ listen-on-v6 { none; };
|
|
||||||
+ recursion yes;
|
|
||||||
+ dnssec-validation yes;
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+controls {
|
|
||||||
+ inet 10.53.0.2 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+include "../../_common/rndc.key";
|
|
||||||
+
|
|
||||||
+zone "." {
|
|
||||||
+ type hint;
|
|
||||||
+ file "../../_common/root.hint";
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "tld.test" {
|
|
||||||
+ type static-stub;
|
|
||||||
+ server-addresses { 10.53.0.1; };
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+trust-anchors {
|
|
||||||
+ tld.test. static-key 257 3 13 "@TLD_DNSKEY@";
|
|
||||||
+};
|
|
||||||
diff --git a/bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py b/bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..bd9bd275b6
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/nsec3_impersonation/tests_nsec3_impersonation.py
|
|
||||||
@@ -0,0 +1,152 @@
|
|
||||||
+#!/usr/bin/python3
|
|
||||||
+
|
|
||||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+#
|
|
||||||
+# SPDX-License-Identifier: MPL-2.0
|
|
||||||
+#
|
|
||||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+#
|
|
||||||
+# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+# information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+from pathlib import Path
|
|
||||||
+
|
|
||||||
+import json
|
|
||||||
+
|
|
||||||
+from cryptography.hazmat.primitives import serialization
|
|
||||||
+from cryptography.hazmat.primitives.asymmetric import ec
|
|
||||||
+
|
|
||||||
+import dns.dnssec
|
|
||||||
+import dns.flags
|
|
||||||
+import dns.name
|
|
||||||
+import dns.rdataclass
|
|
||||||
+import dns.rdatatype
|
|
||||||
+import pytest
|
|
||||||
+
|
|
||||||
+import isctest
|
|
||||||
+import isctest.mark
|
|
||||||
+
|
|
||||||
+APEX_HASH = "1B40241KFORIOG780N4IKSCRLVETPCTQ"
|
|
||||||
+ATTACKER = f"{APEX_HASH.lower()}.tld.test."
|
|
||||||
+VICTIM = "victim.tld.test."
|
|
||||||
+AUTH = "10.53.0.1"
|
|
||||||
+RESOLVER = "10.53.0.2"
|
|
||||||
+
|
|
||||||
+pytestmark = [
|
|
||||||
+ isctest.mark.with_ecdsa_deterministic,
|
|
||||||
+ pytest.mark.extra_artifacts(
|
|
||||||
+ [
|
|
||||||
+ "ans*/ans.run",
|
|
||||||
+ "ans*/keys.json",
|
|
||||||
+ ]
|
|
||||||
+ ),
|
|
||||||
+]
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def _make_key(zone):
|
|
||||||
+ private_key = ec.generate_private_key(ec.SECP256R1())
|
|
||||||
+ dnskey = dns.dnssec.make_dnskey(
|
|
||||||
+ private_key.public_key(),
|
|
||||||
+ algorithm="ECDSAP256SHA256",
|
|
||||||
+ flags=257,
|
|
||||||
+ )
|
|
||||||
+ ds = dns.dnssec.make_ds(dns.name.from_text(zone), dnskey, "SHA256")
|
|
||||||
+ private_pem = private_key.private_bytes(
|
|
||||||
+ encoding=serialization.Encoding.PEM,
|
|
||||||
+ format=serialization.PrivateFormat.PKCS8,
|
|
||||||
+ encryption_algorithm=serialization.NoEncryption(),
|
|
||||||
+ ).decode("ascii")
|
|
||||||
+ return {
|
|
||||||
+ "private_pem": private_pem,
|
|
||||||
+ "dnskey": dnskey.to_text(),
|
|
||||||
+ "ds": ds.to_text(),
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def bootstrap():
|
|
||||||
+ zones = ["tld.test.", ATTACKER]
|
|
||||||
+ keys = {zone: _make_key(zone) for zone in zones}
|
|
||||||
+
|
|
||||||
+ Path("ans1/keys.json").write_text(json.dumps(keys, indent=2), encoding="ascii")
|
|
||||||
+
|
|
||||||
+ tld_dnskey = "".join(keys["tld.test."]["dnskey"].split()[3:])
|
|
||||||
+ return {"TLD_DNSKEY": tld_dnskey}
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def check_dnskey_response(zone):
|
|
||||||
+ query = isctest.query.create(zone, "DNSKEY")
|
|
||||||
+ response = isctest.query.tcp(query, AUTH)
|
|
||||||
+
|
|
||||||
+ isctest.check.noerror(response)
|
|
||||||
+ assert response.flags & dns.flags.AA
|
|
||||||
+ assert (
|
|
||||||
+ response.get_rrset(
|
|
||||||
+ response.answer,
|
|
||||||
+ dns.name.from_text(zone),
|
|
||||||
+ dns.rdataclass.IN,
|
|
||||||
+ dns.rdatatype.DNSKEY,
|
|
||||||
+ )
|
|
||||||
+ is not None
|
|
||||||
+ ), response
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def check_ds_response(zone):
|
|
||||||
+ query = isctest.query.create(zone, "DS")
|
|
||||||
+ response = isctest.query.tcp(query, AUTH)
|
|
||||||
+
|
|
||||||
+ isctest.check.noerror(response)
|
|
||||||
+ assert response.flags & dns.flags.AA
|
|
||||||
+ assert (
|
|
||||||
+ response.get_rrset(
|
|
||||||
+ response.answer,
|
|
||||||
+ dns.name.from_text(zone),
|
|
||||||
+ dns.rdataclass.IN,
|
|
||||||
+ dns.rdatatype.DS,
|
|
||||||
+ )
|
|
||||||
+ is not None
|
|
||||||
+ ), response
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def test_attack_responses():
|
|
||||||
+ check_dnskey_response("tld.test.")
|
|
||||||
+ check_dnskey_response(ATTACKER)
|
|
||||||
+ check_ds_response(ATTACKER)
|
|
||||||
+
|
|
||||||
+ query = isctest.query.create(VICTIM, "A")
|
|
||||||
+ response = isctest.query.tcp(query, AUTH)
|
|
||||||
+
|
|
||||||
+ isctest.check.nxdomain(response)
|
|
||||||
+ assert response.flags & dns.flags.AA
|
|
||||||
+
|
|
||||||
+ nsec3_owner = dns.name.from_text(f"{APEX_HASH}.tld.test.")
|
|
||||||
+ nsec3 = response.get_rrset(
|
|
||||||
+ response.authority,
|
|
||||||
+ nsec3_owner,
|
|
||||||
+ dns.rdataclass.IN,
|
|
||||||
+ dns.rdatatype.NSEC3,
|
|
||||||
+ )
|
|
||||||
+ rrsig = response.get_rrset(
|
|
||||||
+ response.authority,
|
|
||||||
+ nsec3_owner,
|
|
||||||
+ dns.rdataclass.IN,
|
|
||||||
+ dns.rdatatype.RRSIG,
|
|
||||||
+ covers=dns.rdatatype.NSEC3,
|
|
||||||
+ )
|
|
||||||
+
|
|
||||||
+ assert nsec3 is not None, response
|
|
||||||
+ assert rrsig is not None, response
|
|
||||||
+ assert rrsig[0].signer == dns.name.from_text(ATTACKER)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def test_nsec3_impersonation():
|
|
||||||
+ """
|
|
||||||
+ Reproducer for #5874:
|
|
||||||
+ F-006 DNSSEC Validation Bypass NSEC3 Apex Hash Label Parent Impersonation
|
|
||||||
+ """
|
|
||||||
+ query = isctest.query.create(VICTIM, "A")
|
|
||||||
+ response = isctest.query.tcp(query, RESOLVER)
|
|
||||||
+
|
|
||||||
+ isctest.check.noadflag(response)
|
|
||||||
+ isctest.check.servfail(response)
|
|
||||||
diff --git a/bin/tests/system/qmin/ans2/ans.py b/bin/tests/system/qmin/ans2/ans.py
|
|
||||||
index d372c2003b..9343fbc8ef 100755
|
|
||||||
--- a/bin/tests/system/qmin/ans2/ans.py
|
|
||||||
+++ b/bin/tests/system/qmin/ans2/ans.py
|
|
||||||
@@ -15,11 +15,12 @@ import sys
|
|
||||||
import signal
|
|
||||||
import socket
|
|
||||||
import select
|
|
||||||
-from datetime import datetime, timedelta
|
|
||||||
import time
|
|
||||||
-import functools
|
|
||||||
|
|
||||||
-import dns, dns.message, dns.query, dns.flags
|
|
||||||
+import dns
|
|
||||||
+import dns.message
|
|
||||||
+import dns.query
|
|
||||||
+import dns.flags
|
|
||||||
from dns.rdatatype import *
|
|
||||||
from dns.rdataclass import *
|
|
||||||
from dns.rcode import *
|
|
||||||
@@ -432,9 +433,9 @@ else:
|
|
||||||
while running:
|
|
||||||
try:
|
|
||||||
inputready, outputready, exceptready = select.select(input, [], [])
|
|
||||||
- except select.error as e:
|
|
||||||
+ except select.error:
|
|
||||||
break
|
|
||||||
- except socket.error as e:
|
|
||||||
+ except socket.error:
|
|
||||||
break
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
break
|
|
||||||
diff --git a/bin/tests/system/qmin/ans3/ans.py b/bin/tests/system/qmin/ans3/ans.py
|
|
||||||
index b5ae73c3fa..4e7250790f 100755
|
|
||||||
--- a/bin/tests/system/qmin/ans3/ans.py
|
|
||||||
+++ b/bin/tests/system/qmin/ans3/ans.py
|
|
||||||
@@ -15,11 +15,12 @@ import sys
|
|
||||||
import signal
|
|
||||||
import socket
|
|
||||||
import select
|
|
||||||
-from datetime import datetime, timedelta
|
|
||||||
import time
|
|
||||||
-import functools
|
|
||||||
|
|
||||||
-import dns, dns.message, dns.query, dns.flags
|
|
||||||
+import dns
|
|
||||||
+import dns.message
|
|
||||||
+import dns.query
|
|
||||||
+import dns.flags
|
|
||||||
from dns.rdatatype import *
|
|
||||||
from dns.rdataclass import *
|
|
||||||
from dns.rcode import *
|
|
||||||
@@ -261,9 +262,9 @@ else:
|
|
||||||
while running:
|
|
||||||
try:
|
|
||||||
inputready, outputready, exceptready = select.select(input, [], [])
|
|
||||||
- except select.error as e:
|
|
||||||
+ except select.error:
|
|
||||||
break
|
|
||||||
- except socket.error as e:
|
|
||||||
+ except socket.error:
|
|
||||||
break
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
break
|
|
||||||
diff --git a/bin/tests/system/qmin/ans4/ans.py b/bin/tests/system/qmin/ans4/ans.py
|
|
||||||
index 517217aec1..2d5556daff 100755
|
|
||||||
--- a/bin/tests/system/qmin/ans4/ans.py
|
|
||||||
+++ b/bin/tests/system/qmin/ans4/ans.py
|
|
||||||
@@ -15,11 +15,12 @@ import sys
|
|
||||||
import signal
|
|
||||||
import socket
|
|
||||||
import select
|
|
||||||
-from datetime import datetime, timedelta
|
|
||||||
import time
|
|
||||||
-import functools
|
|
||||||
|
|
||||||
-import dns, dns.message, dns.query, dns.flags
|
|
||||||
+import dns
|
|
||||||
+import dns.message
|
|
||||||
+import dns.query
|
|
||||||
+import dns.flags
|
|
||||||
from dns.rdatatype import *
|
|
||||||
from dns.rdataclass import *
|
|
||||||
from dns.rcode import *
|
|
||||||
@@ -320,9 +321,9 @@ else:
|
|
||||||
while running:
|
|
||||||
try:
|
|
||||||
inputready, outputready, exceptready = select.select(input, [], [])
|
|
||||||
- except select.error as e:
|
|
||||||
+ except select.error:
|
|
||||||
break
|
|
||||||
- except socket.error as e:
|
|
||||||
+ except socket.error:
|
|
||||||
break
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
break
|
|
||||||
diff --git a/bin/tests/system/resolver/ans10/ans.py b/bin/tests/system/resolver/ans10/ans.py
|
|
||||||
index 6e95dbbfc6..d637c63e5a 100644
|
|
||||||
--- a/bin/tests/system/resolver/ans10/ans.py
|
|
||||||
+++ b/bin/tests/system/resolver/ans10/ans.py
|
|
||||||
@@ -15,11 +15,11 @@ import sys
|
|
||||||
import signal
|
|
||||||
import socket
|
|
||||||
import select
|
|
||||||
-from datetime import datetime, timedelta
|
|
||||||
-import time
|
|
||||||
-import functools
|
|
||||||
|
|
||||||
-import dns, dns.message, dns.query, dns.flags
|
|
||||||
+import dns
|
|
||||||
+import dns.message
|
|
||||||
+import dns.query
|
|
||||||
+import dns.flags
|
|
||||||
from dns.rdatatype import *
|
|
||||||
from dns.rdataclass import *
|
|
||||||
from dns.rcode import *
|
|
||||||
@@ -128,9 +128,9 @@ else:
|
|
||||||
while running:
|
|
||||||
try:
|
|
||||||
inputready, outputready, exceptready = select.select(input, [], [])
|
|
||||||
- except select.error as e:
|
|
||||||
+ except select.error:
|
|
||||||
break
|
|
||||||
- except socket.error as e:
|
|
||||||
+ except socket.error:
|
|
||||||
break
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
break
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,67 +0,0 @@
|
||||||
From 608026780a43abe5b23a9af3af21808369032158 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Evan Hunt <each@isc.org>
|
|
||||||
Date: Thu, 21 May 2026 14:41:55 -0700
|
|
||||||
Subject: [PATCH] Check NSEC3 signer matches the owning zone
|
|
||||||
|
|
||||||
When validating NSEC3 records, reject any signature whose signer field
|
|
||||||
does not match the zone owning the NSEC3.
|
|
||||||
|
|
||||||
This ensures that a child zone cannot impersonate its parent and forge
|
|
||||||
NXDOMAIN responses for sibling domains.
|
|
||||||
|
|
||||||
Fixes: isc-projects/bind9#5874
|
|
||||||
(cherry picked from commit 6e5066bb1f0f12d090e8707adb7d6ccf74f8012b)
|
|
||||||
(cherry picked from commit c9cb6a5e24e43489cf3fd4d4cc2193b6a74499cb)
|
|
||||||
---
|
|
||||||
lib/dns/dnssec.c | 19 +++++++++++++++++--
|
|
||||||
lib/isc/result.c | 2 +-
|
|
||||||
2 files changed, 18 insertions(+), 3 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/dnssec.c b/lib/dns/dnssec.c
|
|
||||||
index b12529b5d5..9b9b1f2bb2 100644
|
|
||||||
--- a/lib/dns/dnssec.c
|
|
||||||
+++ b/lib/dns/dnssec.c
|
|
||||||
@@ -424,10 +424,25 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
- * NS, SOA and DNSKEY records are signed by their owner.
|
|
||||||
- * DS records are signed by the parent.
|
|
||||||
+ * NS, SOA and DNSKEY records are signed by their owners.
|
|
||||||
+ * NSEC3 records are signed by the apex, exactly one level up
|
|
||||||
+ * from their owner names.
|
|
||||||
+ * DS records are signed by the parent zone.
|
|
||||||
*/
|
|
||||||
switch (set->type) {
|
|
||||||
+ case dns_rdatatype_nsec3: {
|
|
||||||
+ dns_name_t apex = DNS_NAME_INITEMPTY;
|
|
||||||
+ labels = dns_name_countlabels(name);
|
|
||||||
+ if (labels <= 1) {
|
|
||||||
+ inc_stat(dns_dnssecstats_fail);
|
|
||||||
+ return DNS_R_INVALIDNSEC3;
|
|
||||||
+ }
|
|
||||||
+ dns_name_split(name, labels - 1, NULL, &apex);
|
|
||||||
+ if (!dns_name_equal(&apex, &sig.signer)) {
|
|
||||||
+ inc_stat(dns_dnssecstats_fail);
|
|
||||||
+ return DNS_R_SIGINVALID;
|
|
||||||
+ }
|
|
||||||
+ } break;
|
|
||||||
case dns_rdatatype_ns:
|
|
||||||
case dns_rdatatype_soa:
|
|
||||||
case dns_rdatatype_dnskey:
|
|
||||||
diff --git a/lib/isc/result.c b/lib/isc/result.c
|
|
||||||
index 83e8cfeed7..b76c3d1f7b 100644
|
|
||||||
--- a/lib/isc/result.c
|
|
||||||
+++ b/lib/isc/result.c
|
|
||||||
@@ -198,7 +198,7 @@ static const char *description[ISC_R_NRESULTS] = {
|
|
||||||
[DNS_R_COVERINGNSEC] = "covering NSEC record returned",
|
|
||||||
[DNS_R_MXISADDRESS] = "MX is an address",
|
|
||||||
[DNS_R_DUPLICATE] = "duplicate query",
|
|
||||||
- [DNS_R_INVALIDNSEC3] = "invalid NSEC3 owner name (wildcard)",
|
|
||||||
+ [DNS_R_INVALIDNSEC3] = "invalid NSEC3 owner name",
|
|
||||||
[DNS_R_NOTPRIMARY] = "not primary",
|
|
||||||
[DNS_R_BROKENCHAIN] = "broken trust chain",
|
|
||||||
[DNS_R_EXPIRED] = "expired",
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,320 +0,0 @@
|
||||||
From a4ce4c0ce5b8d7630417730dc1b98bf554e0801f Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mark Andrews <marka@isc.org>
|
|
||||||
Date: Tue, 19 May 2026 10:44:04 +1000
|
|
||||||
Subject: [PATCH] Check that dns_name_fromwire honours the active region
|
|
||||||
|
|
||||||
When reading DNS records from the wire the active region of the
|
|
||||||
source buffer is set to the end of the current record. dns_name_fromwire
|
|
||||||
should fail if it attempts to read past this setting.
|
|
||||||
|
|
||||||
(cherry picked from commit 3ed821d68b15fe4e6288e3054397d6bce7e65968)
|
|
||||||
(cherry picked from commit d413c9ac2e29a728531354a69c8c8234c01b7d1e)
|
|
||||||
|
|
||||||
Check that a short PRIVATEDNS record is rejected
|
|
||||||
|
|
||||||
A bug in dns_name_fromwire meant that short PRIVATEDNS key
|
|
||||||
records where being accepted. Test that this is no longer
|
|
||||||
the case.
|
|
||||||
|
|
||||||
(cherry picked from commit f48d48027384d8c2210b5ce9e3eac7af101ead3d)
|
|
||||||
(cherry picked from commit 19ac8b8e46aeb0a15e217bc7bdf485b31b87d9b4)
|
|
||||||
|
|
||||||
POC for PRIVATEDNS DNSKEY overrun not being detected
|
|
||||||
|
|
||||||
Construct a DNS message where a PRIVATEDNS DNSKEY identifier
|
|
||||||
overruns the record boundary by 3 byte so that the label ends
|
|
||||||
at the end of the compression pointer for the next record. The
|
|
||||||
next type is less than 256 so the next octet is 00 terminating
|
|
||||||
the identifier name. The transfered zone is then written to
|
|
||||||
disk using master-format text triggering the assertion when the
|
|
||||||
truncated identier is discovered.
|
|
||||||
|
|
||||||
Note this test will produce a false result in versions of
|
|
||||||
BIND that do not check the PRIVATEDNS identifier as it looks
|
|
||||||
for the error message when the transfer is aborted.
|
|
||||||
|
|
||||||
(cherry picked from commit 9ce3bce8bc8b4e9c6a9b1e84b5849c33eb27830e)
|
|
||||||
(cherry picked from commit 8e066d3fc369e3346f22bb5cfb67a7ab08a74034)
|
|
||||||
---
|
|
||||||
bin/tests/system/xfer/ans9/ans.py | 142 ++++++++++++++++++++++++
|
|
||||||
bin/tests/system/xfer/ns6/named.conf.in | 9 ++
|
|
||||||
bin/tests/system/xfer/tests.sh | 16 +++
|
|
||||||
tests/dns/name_test.c | 30 +++++
|
|
||||||
tests/dns/rdata_test.c | 21 ++++
|
|
||||||
5 files changed, 218 insertions(+)
|
|
||||||
create mode 100644 bin/tests/system/xfer/ans9/ans.py
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/xfer/ans9/ans.py b/bin/tests/system/xfer/ans9/ans.py
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..a9e73953ee
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/xfer/ans9/ans.py
|
|
||||||
@@ -0,0 +1,142 @@
|
|
||||||
+"""
|
|
||||||
+Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+
|
|
||||||
+SPDX-License-Identifier: MPL-2.0
|
|
||||||
+
|
|
||||||
+This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+
|
|
||||||
+See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+information regarding copyright ownership.
|
|
||||||
+"""
|
|
||||||
+
|
|
||||||
+from collections.abc import AsyncGenerator
|
|
||||||
+
|
|
||||||
+import dns.name
|
|
||||||
+import dns.rcode
|
|
||||||
+import dns.rdatatype
|
|
||||||
+import dns.rrset
|
|
||||||
+
|
|
||||||
+from isctest.asyncserver import (
|
|
||||||
+ ControllableAsyncDnsServer,
|
|
||||||
+ DnsResponseSend,
|
|
||||||
+ DomainHandler,
|
|
||||||
+ QueryContext,
|
|
||||||
+ ResponseAction,
|
|
||||||
+ ToggleResponsesCommand,
|
|
||||||
+)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class AXFRServer(DomainHandler):
|
|
||||||
+ """
|
|
||||||
+ Yield SOA and AXFR responses. Every new AXFR response increments the SOA
|
|
||||||
+ version.
|
|
||||||
+ """
|
|
||||||
+
|
|
||||||
+ domains = ["xfr-and-reconfig", "private-dns-overrun"]
|
|
||||||
+
|
|
||||||
+ def __init__(self) -> None:
|
|
||||||
+ super().__init__()
|
|
||||||
+ self.soa_version = 0
|
|
||||||
+
|
|
||||||
+ async def get_responses(
|
|
||||||
+ self, qctx: QueryContext
|
|
||||||
+ ) -> AsyncGenerator[ResponseAction, None]:
|
|
||||||
+ # This is oversimplified because I am lazy - we are appending the SOA
|
|
||||||
+ # RRset to the ANSWER section for _every_ QTYPE. named is only
|
|
||||||
+ # expected to send a SOA query over UDP and then an AXFR query over
|
|
||||||
+ # TCP. Responses to both of those start with a SOA RRset in the ANSWER
|
|
||||||
+ # section :-)
|
|
||||||
+ soa_message = qctx.response
|
|
||||||
+ soa_rrset = dns.rrset.from_text(
|
|
||||||
+ qctx.qname,
|
|
||||||
+ 300,
|
|
||||||
+ qctx.qclass,
|
|
||||||
+ dns.rdatatype.SOA,
|
|
||||||
+ f". . {self.soa_version} 0 0 0 0",
|
|
||||||
+ )
|
|
||||||
+ soa_message.answer.append(soa_rrset)
|
|
||||||
+
|
|
||||||
+ yield DnsResponseSend(soa_message)
|
|
||||||
+
|
|
||||||
+ if qctx.qtype == dns.rdatatype.SOA:
|
|
||||||
+ # If QTYPE=SOA, the SOA record is the complete response.
|
|
||||||
+ return
|
|
||||||
+
|
|
||||||
+ if qctx.qtype != dns.rdatatype.AXFR:
|
|
||||||
+ # If QTYPE=AXFR, we will continue cramming RRsets into the ANSWER
|
|
||||||
+ # section of a subsequent DNS message below.
|
|
||||||
+ #
|
|
||||||
+ # If QTYPE was not SOA or AXFR, abort. Yeah, we just sent a broken
|
|
||||||
+ # response by yielding DnsResponseSend() with a SOA RRset in the
|
|
||||||
+ # ANSWER section above. We will have to carry that burden for the
|
|
||||||
+ # rest of our lives.
|
|
||||||
+ return
|
|
||||||
+
|
|
||||||
+ # Send just the obligatory NS RRset at zone apex in the next message.
|
|
||||||
+ # This is stupidly inefficient, but makes looping below simpler as we
|
|
||||||
+ # will already have been done with the mandatory stuff by then.
|
|
||||||
+ ns_message = qctx.prepare_new_response()
|
|
||||||
+ ns_rrset = dns.rrset.from_text(
|
|
||||||
+ qctx.qname, 300, qctx.qclass, dns.rdatatype.NS, "."
|
|
||||||
+ )
|
|
||||||
+ ns_message.answer.append(ns_rrset)
|
|
||||||
+
|
|
||||||
+ yield DnsResponseSend(ns_message)
|
|
||||||
+
|
|
||||||
+ # Generate the AXFR with a txt rrset.
|
|
||||||
+ txt_message = qctx.prepare_new_response()
|
|
||||||
+ txt_rrset = dns.rrset.from_text(
|
|
||||||
+ qctx.qname,
|
|
||||||
+ 300,
|
|
||||||
+ qctx.qclass,
|
|
||||||
+ dns.rdatatype.TXT,
|
|
||||||
+ "foo bar",
|
|
||||||
+ )
|
|
||||||
+ txt_message.answer.append(txt_rrset)
|
|
||||||
+
|
|
||||||
+ yield DnsResponseSend(txt_message)
|
|
||||||
+
|
|
||||||
+ if qctx.qname == dns.name.from_text("private-dns-overrun"):
|
|
||||||
+ # A message where the malformed DNSKEY algorithm identifier
|
|
||||||
+ # finishes on a 00 byte in the next record. Assumes the
|
|
||||||
+ # next record starts with a compression pointer which is
|
|
||||||
+ # followed by the type which starts with 00.
|
|
||||||
+
|
|
||||||
+ # Generate malformed PRIVATE DNS DNSKEY
|
|
||||||
+ dnskey_message = qctx.prepare_new_response()
|
|
||||||
+ dnskey_rrset = dns.rrset.from_text(
|
|
||||||
+ qctx.qname,
|
|
||||||
+ 300,
|
|
||||||
+ qctx.qclass,
|
|
||||||
+ dns.rdatatype.DNSKEY,
|
|
||||||
+ "\\# 12 00 00 00 fd 09 00 00 00 00 00 00 00",
|
|
||||||
+ )
|
|
||||||
+ dnskey_message.answer.append(dnskey_rrset)
|
|
||||||
+ # Generate well formed PRIVATE DNS DNSKEY
|
|
||||||
+ dnskey_rrset = dns.rrset.from_text(
|
|
||||||
+ qctx.qname,
|
|
||||||
+ 300,
|
|
||||||
+ qctx.qclass,
|
|
||||||
+ dns.rdatatype.DNSKEY,
|
|
||||||
+ "\\# 12 00 00 00 fd 06 00 00 00 00 00 00 00",
|
|
||||||
+ )
|
|
||||||
+ dnskey_message.answer.append(dnskey_rrset)
|
|
||||||
+
|
|
||||||
+ yield DnsResponseSend(dnskey_message)
|
|
||||||
+
|
|
||||||
+ # Finish the AXFR transaction by sending the second SOA RRset.
|
|
||||||
+ yield DnsResponseSend(soa_message)
|
|
||||||
+
|
|
||||||
+ # This makes sure that the next SOA request causes a new zone transfer
|
|
||||||
+ self.soa_version += 1
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+if __name__ == "__main__":
|
|
||||||
+ server = ControllableAsyncDnsServer(
|
|
||||||
+ default_aa=True, default_rcode=dns.rcode.NOERROR
|
|
||||||
+ )
|
|
||||||
+ server.install_control_command(ToggleResponsesCommand())
|
|
||||||
+ server.install_response_handler(AXFRServer())
|
|
||||||
+ server.run()
|
|
||||||
diff --git a/bin/tests/system/xfer/ns6/named.conf.in b/bin/tests/system/xfer/ns6/named.conf.in
|
|
||||||
index 142383c89a..63809448f0 100644
|
|
||||||
--- a/bin/tests/system/xfer/ns6/named.conf.in
|
|
||||||
+++ b/bin/tests/system/xfer/ns6/named.conf.in
|
|
||||||
@@ -83,3 +83,12 @@ zone "ixfr-too-big" {
|
|
||||||
primaries { 10.53.0.1; };
|
|
||||||
file "ixfr-too-big.bk";
|
|
||||||
};
|
|
||||||
+
|
|
||||||
+# GL#6004
|
|
||||||
+zone "private-dns-overrun" {
|
|
||||||
+ type secondary;
|
|
||||||
+ primaries { 10.53.0.9; };
|
|
||||||
+ file "private-dns-overrun.bk";
|
|
||||||
+ masterfile-format text; # force bug to be exercised
|
|
||||||
+ request-ixfr no; # ans9 supports only axfr
|
|
||||||
+};
|
|
||||||
diff --git a/bin/tests/system/xfer/tests.sh b/bin/tests/system/xfer/tests.sh
|
|
||||||
index a2c0adbc28..e08be175b7 100755
|
|
||||||
--- a/bin/tests/system/xfer/tests.sh
|
|
||||||
+++ b/bin/tests/system/xfer/tests.sh
|
|
||||||
@@ -622,5 +622,21 @@ if [ $tmp -eq 0 ]; then
|
|
||||||
fi
|
|
||||||
status=$((status + tmp))
|
|
||||||
|
|
||||||
+# def test_malformed_private_dns_identifier_overrun(ns6):
|
|
||||||
+# isctest.log.info(
|
|
||||||
+# "Check that a malformed PRIVATEDNS DNSKEY which overruns the record is rejected"
|
|
||||||
+# )
|
|
||||||
+# with ns6.watch_log_from_start(timeout=60) as watcher_transfer_completed:
|
|
||||||
+# watcher_transfer_completed.wait_for_line(
|
|
||||||
+# "zone private-dns-overrun/IN: zone transfer finished: unexpected end of input"
|
|
||||||
+# )
|
|
||||||
+n=$((n + 1))
|
|
||||||
+echo_i "Check that a malformed PRIVATEDNS DNSKEY which overruns the record is rejected ($n)"
|
|
||||||
+tmp=0
|
|
||||||
+nextpartreset ns6/named.run
|
|
||||||
+retry 60 wait_for_message "zone private-dns-overrun/IN: zone transfer finished: unexpected end of input" || tmp=1
|
|
||||||
+if test $tmp != 0; then echo_i "failed"; fi
|
|
||||||
+status=$((status + tmp))
|
|
||||||
+
|
|
||||||
echo_i "exit status: $status"
|
|
||||||
[ $status -eq 0 ] || exit 1
|
|
||||||
diff --git a/tests/dns/name_test.c b/tests/dns/name_test.c
|
|
||||||
index fb34dcace1..95f6598eb8 100644
|
|
||||||
--- a/tests/dns/name_test.c
|
|
||||||
+++ b/tests/dns/name_test.c
|
|
||||||
@@ -335,6 +335,35 @@ ISC_RUN_TEST_IMPL(fromregion) {
|
|
||||||
assert_false(dns_name_isabsolute(&name));
|
|
||||||
}
|
|
||||||
|
|
||||||
+ISC_RUN_TEST_IMPL(fromwire) {
|
|
||||||
+ dns_decompress_t dctx;
|
|
||||||
+ dns_fixedname_t fixed;
|
|
||||||
+ dns_name_t *name = dns_fixedname_initname(&fixed);
|
|
||||||
+ isc_buffer_t b;
|
|
||||||
+ unsigned char source[] = { 0x03, 'o', 'n', 'e', 0x00, 0x03,
|
|
||||||
+ 't', 'w', 'o', 0x00, 0x05, 't',
|
|
||||||
+ 'h', 'r', 'e', 'e', 0x00 };
|
|
||||||
+ isc_result_t result;
|
|
||||||
+
|
|
||||||
+ isc_buffer_init(&b, source, sizeof(source));
|
|
||||||
+ isc_buffer_add(&b, sizeof(source));
|
|
||||||
+ isc_buffer_setactive(&b, 10); /* names 'one.' and 'two.' */
|
|
||||||
+
|
|
||||||
+ /*
|
|
||||||
+ * We should only be able to read two names from the buffer
|
|
||||||
+ * as the active region has been set to cover only the first
|
|
||||||
+ * two.
|
|
||||||
+ */
|
|
||||||
+ dns_decompress_init(&dctx, -1, DNS_DECOMPRESS_STRICT);
|
|
||||||
+ dns_decompress_setmethods(&dctx, DNS_COMPRESS_NONE);
|
|
||||||
+ result = dns_name_fromwire(name, &b, &dctx, 0, NULL);
|
|
||||||
+ assert_int_equal(result, ISC_R_SUCCESS);
|
|
||||||
+ result = dns_name_fromwire(name, &b, &dctx, 0, NULL);
|
|
||||||
+ assert_int_equal(result, ISC_R_SUCCESS);
|
|
||||||
+ result = dns_name_fromwire(name, &b, &dctx, 0, NULL);
|
|
||||||
+ assert_int_not_equal(result, ISC_R_SUCCESS);
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
/* is trust-anchor-telemetry test */
|
|
||||||
ISC_RUN_TEST_IMPL(istat) {
|
|
||||||
dns_fixedname_t fixed;
|
|
||||||
@@ -778,6 +807,7 @@ ISC_TEST_LIST_START
|
|
||||||
ISC_TEST_ENTRY(fullcompare)
|
|
||||||
ISC_TEST_ENTRY(compression)
|
|
||||||
ISC_TEST_ENTRY(fromregion)
|
|
||||||
+ISC_TEST_ENTRY(fromwire)
|
|
||||||
ISC_TEST_ENTRY(istat)
|
|
||||||
ISC_TEST_ENTRY(init)
|
|
||||||
ISC_TEST_ENTRY(invalidate)
|
|
||||||
diff --git a/tests/dns/rdata_test.c b/tests/dns/rdata_test.c
|
|
||||||
index 6354819d10..7f0df6e046 100644
|
|
||||||
--- a/tests/dns/rdata_test.c
|
|
||||||
+++ b/tests/dns/rdata_test.c
|
|
||||||
@@ -2199,6 +2199,27 @@ ISC_RUN_TEST_IMPL(key) {
|
|
||||||
|
|
||||||
check_rdata(NULL, wire_ok, NULL, false, dns_rdataclass_in,
|
|
||||||
dns_rdatatype_key, sizeof(dns_rdata_key_t));
|
|
||||||
+
|
|
||||||
+ /*
|
|
||||||
+ * A valid PRIVATEDNS record with an active region shorter than the
|
|
||||||
+ * actual record length. A bug in dns_name_fromwire meant that this
|
|
||||||
+ * was previously accepted.
|
|
||||||
+ */
|
|
||||||
+ dns_decompress_t dctx;
|
|
||||||
+ unsigned char key[] = { 0x00, 0x00, 0x00, 253, 0x07, 'e', 'x',
|
|
||||||
+ 'a', 'm', 'p', 'l', 'e', 0x00 };
|
|
||||||
+ unsigned char buf[sizeof(key)];
|
|
||||||
+ isc_buffer_t source, target;
|
|
||||||
+ isc_result_t result;
|
|
||||||
+
|
|
||||||
+ isc_buffer_init(&source, key, sizeof(key));
|
|
||||||
+ isc_buffer_add(&source, sizeof(key));
|
|
||||||
+ isc_buffer_setactive(&source, sizeof(key) - 1);
|
|
||||||
+ isc_buffer_init(&target, buf, sizeof(buf));
|
|
||||||
+ dns_decompress_init(&dctx, -1, DNS_DECOMPRESS_ANY);
|
|
||||||
+ result = dns_rdata_fromwire(NULL, dns_rdataclass_in, dns_rdatatype_key,
|
|
||||||
+ &source, &dctx, 0, &target);
|
|
||||||
+ assert_int_not_equal(result, ISC_R_SUCCESS);
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,54 +0,0 @@
|
||||||
From 7596cbc240b0492461943f7c34d040fb66a7554c Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mark Andrews <marka@isc.org>
|
|
||||||
Date: Tue, 19 May 2026 15:00:17 +1000
|
|
||||||
Subject: [PATCH] Fix the yaml query zone name code in dnstap-read
|
|
||||||
|
|
||||||
When the buffer to read the query zone name was constructed
|
|
||||||
isc_buffer_setactive was not called. This is now needed as
|
|
||||||
dns_name_fromwire is being corrected to check the active region.
|
|
||||||
|
|
||||||
(cherry picked from commit a25522c28c46655a81d2bf1d96374c81d834b157)
|
|
||||||
(cherry picked from commit a5f1a9d0d2ec021618924b14202ac96ead8299c1)
|
|
||||||
|
|
||||||
Fix dns_name_fromwire to honour the active region
|
|
||||||
|
|
||||||
dns_name_fromwire was not honouring the source buffer's active
|
|
||||||
region when reading names from the wire. This allowed malformed
|
|
||||||
records to be accepted when they shouldn't have been. This has
|
|
||||||
been corrected.
|
|
||||||
|
|
||||||
(cherry picked from commit 7c4f07a7ef6b571073327b02209df7f75b9363ff)
|
|
||||||
(cherry picked from commit e73b70a64453e7d97a11cb5f0afe8bb02d34aaf8)
|
|
||||||
---
|
|
||||||
bin/tools/dnstap-read.c | 1 +
|
|
||||||
lib/dns/name.c | 2 +-
|
|
||||||
2 files changed, 2 insertions(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/bin/tools/dnstap-read.c b/bin/tools/dnstap-read.c
|
|
||||||
index a1d0243a1a..bb78ae12b1 100644
|
|
||||||
--- a/bin/tools/dnstap-read.c
|
|
||||||
+++ b/bin/tools/dnstap-read.c
|
|
||||||
@@ -298,6 +298,7 @@ print_yaml(dns_dtdata_t *dt) {
|
|
||||||
|
|
||||||
isc_buffer_init(&b, m->query_zone.data, m->query_zone.len);
|
|
||||||
isc_buffer_add(&b, m->query_zone.len);
|
|
||||||
+ isc_buffer_setactive(&b, m->query_zone.len);
|
|
||||||
|
|
||||||
dns_decompress_init(&dctx, -1, DNS_DECOMPRESS_NONE);
|
|
||||||
result = dns_name_fromwire(name, &b, &dctx, 0, NULL);
|
|
||||||
diff --git a/lib/dns/name.c b/lib/dns/name.c
|
|
||||||
index cc0e30e5b5..2ce868a2ba 100644
|
|
||||||
--- a/lib/dns/name.c
|
|
||||||
+++ b/lib/dns/name.c
|
|
||||||
@@ -1833,7 +1833,7 @@ dns_name_fromwire(dns_name_t *const name, isc_buffer_t *const source,
|
|
||||||
* The amount of the source we consumed is set once.
|
|
||||||
*/
|
|
||||||
const uint8_t *const source_buf = isc_buffer_base(source);
|
|
||||||
- const uint8_t *const source_max = isc_buffer_used(source);
|
|
||||||
+ const uint8_t *const source_max = isc_buffer_active(source);
|
|
||||||
const uint8_t *const start = isc_buffer_current(source);
|
|
||||||
const uint8_t *marker = start;
|
|
||||||
const uint8_t *cursor = start;
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,69 +0,0 @@
|
||||||
From cde8bb21e09205a7bd1f41fd07ed011fc80d8d71 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mark Andrews <marka@isc.org>
|
|
||||||
Date: Fri, 10 Apr 2026 10:24:06 +1000
|
|
||||||
Subject: [PATCH] Fix TTL extraction from A/AAAA record
|
|
||||||
|
|
||||||
(cherry picked from commit 89c86e338db2492b92e6618c586f146c6928dc6d)
|
|
||||||
(cherry picked from commit adc8285d23e2eac6ec463f5dbc5a9596fdd36c60)
|
|
||||||
|
|
||||||
Check rpz name too long wildcard CNAME expansion handling
|
|
||||||
|
|
||||||
(cherry picked from commit 9345394e2097031b55b3ef34ceaadf5a7ebbeef2)
|
|
||||||
(cherry picked from commit 095b11f20f911f5b8059bdc349b256d6c64ece30)
|
|
||||||
---
|
|
||||||
bin/tests/system/rpz/ns2/tld2.db | 2 ++
|
|
||||||
bin/tests/system/rpz/ns4/tld4.db | 2 ++
|
|
||||||
bin/tests/system/rpz/tests.sh | 7 +++++--
|
|
||||||
3 files changed, 9 insertions(+), 2 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/rpz/ns2/tld2.db b/bin/tests/system/rpz/ns2/tld2.db
|
|
||||||
index c6f2556db5..c091ee27b7 100644
|
|
||||||
--- a/bin/tests/system/rpz/ns2/tld2.db
|
|
||||||
+++ b/bin/tests/system/rpz/ns2/tld2.db
|
|
||||||
@@ -123,3 +123,5 @@ a7-1 A 192.168.7.1
|
|
||||||
|
|
||||||
a7-2 A 192.168.7.2
|
|
||||||
TXT "a7-2 tld2 text"
|
|
||||||
+
|
|
||||||
+*.wild A 192.168.9.1
|
|
||||||
diff --git a/bin/tests/system/rpz/ns4/tld4.db b/bin/tests/system/rpz/ns4/tld4.db
|
|
||||||
index fca419c6dd..8accd76baf 100644
|
|
||||||
--- a/bin/tests/system/rpz/ns4/tld4.db
|
|
||||||
+++ b/bin/tests/system/rpz/ns4/tld4.db
|
|
||||||
@@ -59,6 +59,8 @@ a3-6.tld2 A 56.56.56.56
|
|
||||||
|
|
||||||
a3-7.sub1.tld2 A 57.57.57.57
|
|
||||||
|
|
||||||
+*.wild.sub1.tld2 A 57.57.57.57
|
|
||||||
+
|
|
||||||
a3-8.tld2 A 58.58.58.58
|
|
||||||
|
|
||||||
a3-9.sub9.tld2 A 59.59.59.59
|
|
||||||
diff --git a/bin/tests/system/rpz/tests.sh b/bin/tests/system/rpz/tests.sh
|
|
||||||
index 87e4118ca3..5297437694 100644
|
|
||||||
--- a/bin/tests/system/rpz/tests.sh
|
|
||||||
+++ b/bin/tests/system/rpz/tests.sh
|
|
||||||
@@ -391,7 +391,7 @@ addr() {
|
|
||||||
digcmd $2 >$DIGNM
|
|
||||||
#ckalive "$2" "server crashed by 'dig $2'" || return 1
|
|
||||||
ADDR_ESC=$(echo "$ADDR" | sed -e 's/\./\\./g')
|
|
||||||
- ADDR_TTL=$(sed -n -e "s/^[-.a-z0-9]\{1,\}[ ]*\([0-9]*\) IN AA* ${ADDR_ESC}\$/\1/p" $DIGNM)
|
|
||||||
+ ADDR_TTL=$(sed -n -e "s/^[-.a-z0-9]\{1,\}[ ]*\([0-9]*\)[ ]IN[ ]AA*[ ]${ADDR_ESC}\$/\1/p" $DIGNM)
|
|
||||||
if test -z "$ADDR_TTL"; then
|
|
||||||
setret "'dig $2' wrong; no address $ADDR record in $DIGNM"
|
|
||||||
return 0
|
|
||||||
@@ -516,7 +516,10 @@ nochange TCP a3-9.tld2 # 33 tcp-only
|
|
||||||
here x.servfail <<'EOF' # 34 qname-wait-recurse yes
|
|
||||||
;; status: SERVFAIL, x
|
|
||||||
EOF
|
|
||||||
-addr 35.35.35.35 "x.servfail @$ns5" # 35 qname-wait-recurse no
|
|
||||||
+addr 35.35.35.35 "x.servfail @$ns5" # 35 qname-wait-recurse no
|
|
||||||
+here aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.wild.sub1.tld2 <<'EOF' # 36 wildcard CNAME name to long
|
|
||||||
+ ;; status: YXDOMAIN, x
|
|
||||||
+EOF
|
|
||||||
end_group
|
|
||||||
ckstats $ns3 test1 ns3 22
|
|
||||||
ckstats $ns5 test1 ns5 1
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,31 +0,0 @@
|
||||||
From 49f4cc4e93f14f1d5b6a472124e6aa457167fede Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mark Andrews <marka@isc.org>
|
|
||||||
Date: Fri, 10 Apr 2026 10:26:14 +1000
|
|
||||||
Subject: [PATCH] Properly handle rpz name to long wildcard expansion
|
|
||||||
|
|
||||||
Previously a self referential CNAME and the original address
|
|
||||||
record were returned. We now return a YXDOMAIN response.
|
|
||||||
|
|
||||||
(cherry picked from commit cfc4c4f69870ce492deaaa429453563d1621ded3)
|
|
||||||
(cherry picked from commit dc328a199f96222e0c30cc20b7b795bfc2c9b2e4)
|
|
||||||
---
|
|
||||||
lib/ns/query.c | 3 ++-
|
|
||||||
1 file changed, 2 insertions(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
|
||||||
index d3a10be9ba..3bd7daf79c 100644
|
|
||||||
--- a/lib/ns/query.c
|
|
||||||
+++ b/lib/ns/query.c
|
|
||||||
@@ -7591,7 +7591,8 @@ query_rpzcname(query_ctx_t *qctx, dns_name_t *cname) {
|
|
||||||
qctx->fname, NULL);
|
|
||||||
if (result == DNS_R_NAMETOOLONG) {
|
|
||||||
client->message->rcode = dns_rcode_yxdomain;
|
|
||||||
- } else if (result != ISC_R_SUCCESS) {
|
|
||||||
+ }
|
|
||||||
+ if (result != ISC_R_SUCCESS) {
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,280 +0,0 @@
|
||||||
From d7e1f4495d6bac8c29b332e04e9b27140339375b Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Ond=C5=99ej=20Sur=C3=BD?= <ondrej@sury.org>
|
|
||||||
Date: Tue, 23 Jun 2026 10:59:38 +0200
|
|
||||||
Subject: [PATCH] Make the dns_slabheaders in the cache reference counted
|
|
||||||
|
|
||||||
Instead of only reference counting the enclosing qpcnode, add the
|
|
||||||
reference counting directly to the slabheaders. The reference is
|
|
||||||
incremented when an rdataset is bound to the header and decremented when
|
|
||||||
the rdataset is disassociated, so a stale slabheader can be removed from
|
|
||||||
the node's down chain as soon as its own reference count reaches zero,
|
|
||||||
instead of waiting for the whole qpcnode to become unreferenced.
|
|
||||||
|
|
||||||
Building on that, clean up the ancient headers eagerly: mark_ancient()
|
|
||||||
is made idempotent, releases the header's own (container) reference and
|
|
||||||
reaps the stale headers from the node's down chain as soon as their
|
|
||||||
references reach zero. A header evicted over the per-name type limit is
|
|
||||||
expired only after the new rdataset has been bound, so the bind's
|
|
||||||
increment always precedes mark_ancient()'s decrement.
|
|
||||||
|
|
||||||
Because a header can now be reclaimed independently of its node, the
|
|
||||||
rdataset iterators must keep the header they are positioned on alive:
|
|
||||||
each iterator takes a reference on its current header and releases it
|
|
||||||
when it advances or is destroyed. Iteration otherwise stays lazy and
|
|
||||||
re-reads the node on every step, so it still observes records added to
|
|
||||||
the node while the iterator is live, as zone signing requires.
|
|
||||||
|
|
||||||
The slab headers are shared with the zone databases, so the matching
|
|
||||||
increment is added to every bind path. The noqname/closest proofs hand
|
|
||||||
out rdatasets backed by bare slabs that have no header, so they are
|
|
||||||
given a separate dns_rdataproof_rdatasetmethods that leaves the
|
|
||||||
reference count untouched.
|
|
||||||
|
|
||||||
(cherry picked from commit 2dabf117e1264fd13fb33096f87e78a039fd1c6c)
|
|
||||||
(cherry picked from commit 231b1ca3edfb26389e1af39181aa6b4413e87ec4)
|
|
||||||
---
|
|
||||||
bin/tests/system/reclimit/tests.sh | 4 +-
|
|
||||||
lib/dns/include/dns/rdataslab.h | 1 +
|
|
||||||
lib/dns/rbtdb.c | 77 +++++++++++++++++++++++++-----
|
|
||||||
3 files changed, 69 insertions(+), 13 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/reclimit/tests.sh b/bin/tests/system/reclimit/tests.sh
|
|
||||||
index c15225488f..55ccac7759 100644
|
|
||||||
--- a/bin/tests/system/reclimit/tests.sh
|
|
||||||
+++ b/bin/tests/system/reclimit/tests.sh
|
|
||||||
@@ -338,13 +338,13 @@ echo_i "checking that NXDOMAIN names over the max-types-per-name limit don't get
|
|
||||||
|
|
||||||
# Query for 10 NXDOMAIN types
|
|
||||||
for ntype in $(seq 65270 65279); do
|
|
||||||
- check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR big SOA 0 || ret=1
|
|
||||||
+ check_manytypes 1 manytypes.big "TYPE${ntype}" NOERROR big SOA 120 || ret=1
|
|
||||||
done
|
|
||||||
# Wait at least 1 second
|
|
||||||
sleep 1
|
|
||||||
# Query for 10 NXDOMAIN types again - these should not be cached
|
|
||||||
for ntype in $(seq 65270 65279); do
|
|
||||||
- check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR big SOA 0 || ret=1
|
|
||||||
+ check_manytypes 2 manytypes.big "TYPE${ntype}" NOERROR big SOA 120 || ret=1
|
|
||||||
done
|
|
||||||
|
|
||||||
if [ $ret -ne 0 ]; then echo_i "failed"; fi
|
|
||||||
diff --git a/lib/dns/include/dns/rdataslab.h b/lib/dns/include/dns/rdataslab.h
|
|
||||||
index 5729c004ca..6bd3b5997d 100644
|
|
||||||
--- a/lib/dns/include/dns/rdataslab.h
|
|
||||||
+++ b/lib/dns/include/dns/rdataslab.h
|
|
||||||
@@ -44,6 +44,7 @@
|
|
||||||
#include <stdbool.h>
|
|
||||||
|
|
||||||
#include <isc/lang.h>
|
|
||||||
+#include <isc/refcount.h>
|
|
||||||
|
|
||||||
#include <dns/types.h>
|
|
||||||
|
|
||||||
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
|
||||||
index 62bc97d783..0b8547950f 100644
|
|
||||||
--- a/lib/dns/rbtdb.c
|
|
||||||
+++ b/lib/dns/rbtdb.c
|
|
||||||
@@ -158,6 +158,7 @@ struct noqname {
|
|
||||||
};
|
|
||||||
|
|
||||||
typedef struct rdatasetheader {
|
|
||||||
+ isc_refcount_t references;
|
|
||||||
/*%
|
|
||||||
* Locked by the owning node's lock.
|
|
||||||
*/
|
|
||||||
@@ -1447,6 +1448,7 @@ init_rdataset(dns_rbtdb_t *rbtdb, rdatasetheader_t *h) {
|
|
||||||
h->heap_index = 0;
|
|
||||||
atomic_init(&h->attributes, 0);
|
|
||||||
atomic_init(&h->last_refresh_fail_ts, 0);
|
|
||||||
+ isc_refcount_init(&h->references, 1);
|
|
||||||
|
|
||||||
STATIC_ASSERT(sizeof(h->attributes) == 2,
|
|
||||||
"The .attributes field of rdatasetheader_t needs to be "
|
|
||||||
@@ -1559,6 +1561,9 @@ rollback_node(dns_rbtnode_t *node, rbtdb_serial_t serial) {
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
+static void
|
|
||||||
+clean_stale_headers(dns_rbtdb_t *rbtdb, isc_mem_t *mctx, rdatasetheader_t *top);
|
|
||||||
+
|
|
||||||
static void
|
|
||||||
mark_header_ancient(dns_rbtdb_t *rbtdb, rdatasetheader_t *header) {
|
|
||||||
uint_least16_t attributes = atomic_load_acquire(&header->attributes);
|
|
||||||
@@ -1584,8 +1589,12 @@ mark_header_ancient(dns_rbtdb_t *rbtdb, rdatasetheader_t *header) {
|
|
||||||
update_rrsetstats(rbtdb, header->type, attributes, false);
|
|
||||||
header->node->dirty = 1;
|
|
||||||
|
|
||||||
+ isc_refcount_decrement(&header->references);
|
|
||||||
+
|
|
||||||
/* Increment the stats counter for the ancient RRtype. */
|
|
||||||
update_rrsetstats(rbtdb, header->type, newattributes, true);
|
|
||||||
+
|
|
||||||
+ clean_stale_headers(rbtdb, rbtdb->common.mctx, header);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void
|
|
||||||
@@ -1621,12 +1630,19 @@ static void
|
|
||||||
clean_stale_headers(dns_rbtdb_t *rbtdb, isc_mem_t *mctx,
|
|
||||||
rdatasetheader_t *top) {
|
|
||||||
rdatasetheader_t *d, *down_next;
|
|
||||||
+ rdatasetheader_t *down_parent = top;
|
|
||||||
|
|
||||||
for (d = top->down; d != NULL; d = down_next) {
|
|
||||||
down_next = d->down;
|
|
||||||
- free_rdataset(rbtdb, mctx, d);
|
|
||||||
+ d->next = down_parent;
|
|
||||||
+
|
|
||||||
+ if (isc_refcount_current(&d->references) == 0) {
|
|
||||||
+ free_rdataset(rbtdb, mctx, d);
|
|
||||||
+ down_parent->down = down_next;
|
|
||||||
+ } else {
|
|
||||||
+ down_parent = d;
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
- top->down = NULL;
|
|
||||||
}
|
|
||||||
|
|
||||||
static void
|
|
||||||
@@ -1642,6 +1658,7 @@ clean_cache_node(dns_rbtdb_t *rbtdb, dns_rbtnode_t *node) {
|
|
||||||
for (current = node->data; current != NULL; current = top_next) {
|
|
||||||
top_next = current->next;
|
|
||||||
clean_stale_headers(rbtdb, mctx, current);
|
|
||||||
+ INSIST(current->down == NULL);
|
|
||||||
/*
|
|
||||||
* If current is nonexistent, ancient, or stale and
|
|
||||||
* we are not keeping stale, we can clean it up.
|
|
||||||
@@ -3114,6 +3131,8 @@ bind_rdataset(dns_rbtdb_t *rbtdb, dns_rbtnode_t *node, rdatasetheader_t *header,
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
+ isc_refcount_increment(&header->references);
|
|
||||||
+
|
|
||||||
dns__rbtnode_acquire(rbtdb, node, locktype);
|
|
||||||
|
|
||||||
INSIST(rdataset->methods == NULL); /* We must be disassociated. */
|
|
||||||
@@ -6307,6 +6326,7 @@ add32(dns_rbtdb_t *rbtdb, dns_rbtnode_t *rbtnode, const dns_name_t *nodename,
|
|
||||||
bool header_nx;
|
|
||||||
bool newheader_nx;
|
|
||||||
bool merge;
|
|
||||||
+ bool do_expireheader = false;
|
|
||||||
dns_rdatatype_t rdtype, covers;
|
|
||||||
rbtdb_rdatatype_t negtype, sigtype;
|
|
||||||
dns_trust_t trust;
|
|
||||||
@@ -6856,6 +6876,7 @@ find_header:
|
|
||||||
}
|
|
||||||
|
|
||||||
if (IS_CACHE(rbtdb) && overmaxtype(rbtdb, ntypes)) {
|
|
||||||
+ do_expireheader = true;
|
|
||||||
if (expireheader == NULL) {
|
|
||||||
expireheader = newheader;
|
|
||||||
}
|
|
||||||
@@ -6869,15 +6890,6 @@ find_header:
|
|
||||||
*/
|
|
||||||
expireheader = newheader;
|
|
||||||
}
|
|
||||||
-
|
|
||||||
- set_ttl(rbtdb, expireheader, 0);
|
|
||||||
- mark_header_ancient(rbtdb, expireheader);
|
|
||||||
- /*
|
|
||||||
- * FIXME: In theory, we should mark the RRSIG
|
|
||||||
- * and the header at the same time, but there is
|
|
||||||
- * no direct link between those two header, so
|
|
||||||
- * we would have to check the whole list again.
|
|
||||||
- */
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -6901,6 +6913,15 @@ find_header:
|
|
||||||
isc_rwlocktype_write, addedrdataset);
|
|
||||||
}
|
|
||||||
|
|
||||||
+ /*
|
|
||||||
+ * We need to delay the expiration of the header until we are bound to
|
|
||||||
+ * it to prevent decrement-then-increment on the header references.
|
|
||||||
+ */
|
|
||||||
+ if (do_expireheader) {
|
|
||||||
+ set_ttl(rbtdb, expireheader, 0);
|
|
||||||
+ mark_header_ancient(rbtdb, expireheader);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
return ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -8692,6 +8713,12 @@ rdataset_disassociate(dns_rdataset_t *rdataset) {
|
|
||||||
dns_db_t *db = rdataset->private1;
|
|
||||||
dns_dbnode_t *node = rdataset->private2;
|
|
||||||
|
|
||||||
+ if (rdataset->methods == &rdataset_methods) {
|
|
||||||
+ rdatasetheader_t *header = rdataset->private3;
|
|
||||||
+ header--;
|
|
||||||
+ isc_refcount_decrement(&header->references);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
detachnode(db, &node);
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -8806,6 +8833,11 @@ rdataset_clone(dns_rdataset_t *source, dns_rdataset_t *target) {
|
|
||||||
dns_dbnode_t *cloned_node = NULL;
|
|
||||||
|
|
||||||
attachnode(db, node, &cloned_node);
|
|
||||||
+ if (source->methods == &rdataset_methods) {
|
|
||||||
+ rdatasetheader_t *header = source->private3;
|
|
||||||
+ header--;
|
|
||||||
+ isc_refcount_increment(&header->references);
|
|
||||||
+ }
|
|
||||||
INSIST(!ISC_LINK_LINKED(target, link));
|
|
||||||
*target = *source;
|
|
||||||
ISC_LINK_INIT(target, link);
|
|
||||||
@@ -8969,6 +9001,11 @@ rdatasetiter_destroy(dns_rdatasetiter_t **iteratorp) {
|
|
||||||
|
|
||||||
rbtiterator = (rbtdb_rdatasetiter_t *)(*iteratorp);
|
|
||||||
|
|
||||||
+ if (rbtiterator->current != NULL) {
|
|
||||||
+ isc_refcount_decrement(&rbtiterator->current->references);
|
|
||||||
+ rbtiterator->current = NULL;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
if (rbtiterator->common.version != NULL) {
|
|
||||||
closeversion(rbtiterator->common.db,
|
|
||||||
&rbtiterator->common.version, false);
|
|
||||||
@@ -9046,9 +9083,18 @@ rdatasetiter_first(dns_rdatasetiter_t *iterator) {
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
+ if (header != NULL) {
|
|
||||||
+ isc_refcount_increment0(&header->references);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
NODE_UNLOCK(&rbtdb->node_locks[rbtnode->locknum].lock,
|
|
||||||
isc_rwlocktype_read);
|
|
||||||
|
|
||||||
+ if (rbtiterator->current != NULL) {
|
|
||||||
+ isc_refcount_decrement(&rbtiterator->current->references);
|
|
||||||
+ rbtiterator->current = NULL;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
rbtiterator->current = header;
|
|
||||||
|
|
||||||
if (header == NULL) {
|
|
||||||
@@ -9140,9 +9186,18 @@ rdatasetiter_next(dns_rdatasetiter_t *iterator) {
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
+ if (header != NULL) {
|
|
||||||
+ isc_refcount_increment0(&header->references);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
NODE_UNLOCK(&rbtdb->node_locks[rbtnode->locknum].lock,
|
|
||||||
isc_rwlocktype_read);
|
|
||||||
|
|
||||||
+ if (rbtiterator->current != NULL) {
|
|
||||||
+ isc_refcount_decrement(&rbtiterator->current->references);
|
|
||||||
+ rbtiterator->current = NULL;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
rbtiterator->current = header;
|
|
||||||
|
|
||||||
if (header == NULL) {
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,144 +0,0 @@
|
||||||
From b08e0876639ab9f3dae3813202861fd1098f2611 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mark Andrews <marka@isc.org>
|
|
||||||
Date: Tue, 14 Apr 2026 13:46:22 +1000
|
|
||||||
Subject: [PATCH] Test RRSIG record parsing
|
|
||||||
|
|
||||||
In particular test that labels and signer fields are consistent.
|
|
||||||
|
|
||||||
(cherry picked from commit 5a95e64731afe63d348d272cc4d3b2f9847150c2)
|
|
||||||
(cherry picked from commit 19e496ca260b6a756ae1378e8ebcbdb666b7d9ed)
|
|
||||||
---
|
|
||||||
tests/dns/rdata_test.c | 110 +++++++++++++++++++++++++++++++++++++++++
|
|
||||||
1 file changed, 110 insertions(+)
|
|
||||||
|
|
||||||
diff --git a/tests/dns/rdata_test.c b/tests/dns/rdata_test.c
|
|
||||||
index 7f0df6e046..c704d98ed1 100644
|
|
||||||
--- a/tests/dns/rdata_test.c
|
|
||||||
+++ b/tests/dns/rdata_test.c
|
|
||||||
@@ -2504,6 +2504,115 @@ ISC_RUN_TEST_IMPL(rkey) {
|
|
||||||
dns_rdatatype_rkey, sizeof(dns_rdata_rkey_t));
|
|
||||||
}
|
|
||||||
|
|
||||||
+ISC_RUN_TEST_IMPL(rrsig) {
|
|
||||||
+ text_ok_t text_ok[] = {
|
|
||||||
+ TEXT_VALID("SOA 8 0 86400 20260426170000 20260413160000 54393 "
|
|
||||||
+ ". "
|
|
||||||
+ "tFbcoVP8MnpecUquJ/aj+XeNgV7ts9GSHVkXaXRJrJ/"
|
|
||||||
+ "TEkOZApVG0F6E "
|
|
||||||
+ "9sYpxGk2ItweLL43ujioGj0HWwZDRR+vbur+O/"
|
|
||||||
+ "dIdheiig1VvU+9HXLi "
|
|
||||||
+ "QOViY9Kc64ixdyJhYCC5K+bO1qsHxd+"
|
|
||||||
+ "KJXOaxyHbqchYkDFy4PL6qftE "
|
|
||||||
+ "VaLkueRgjXgOsq/"
|
|
||||||
+ "NxvCXDgAa5xy0+3Sl0myxIs8rJ5KeXfJQFe7qxgaw "
|
|
||||||
+ "VjJsJTKw8neOTw2rQfLaigWu2LIWw+"
|
|
||||||
+ "IyVrLjZJdLqGkiLBGd1w4X3U12 "
|
|
||||||
+ "fFxoY3eqzNgBEtduoGKPZ/"
|
|
||||||
+ "NpP9cuKJORJ18283aV8hR4WO91VR0q1zcM jLwqUg=="),
|
|
||||||
+ /* labels too short for signer */
|
|
||||||
+ TEXT_INVALID("SOA 8 0 86400 20260426170000 20260413160000 "
|
|
||||||
+ "54393 example. "
|
|
||||||
+ "tFbcoVP8MnpecUquJ/aj+XeNgV7ts9GSHVkXaXRJrJ/"
|
|
||||||
+ "TEkOZApVG0F6E "
|
|
||||||
+ "9sYpxGk2ItweLL43ujioGj0HWwZDRR+vbur+O/"
|
|
||||||
+ "dIdheiig1VvU+9HXLi "
|
|
||||||
+ "QOViY9Kc64ixdyJhYCC5K+bO1qsHxd+"
|
|
||||||
+ "KJXOaxyHbqchYkDFy4PL6qftE "
|
|
||||||
+ "VaLkueRgjXgOsq/"
|
|
||||||
+ "NxvCXDgAa5xy0+3Sl0myxIs8rJ5KeXfJQFe7qxgaw "
|
|
||||||
+ "VjJsJTKw8neOTw2rQfLaigWu2LIWw+"
|
|
||||||
+ "IyVrLjZJdLqGkiLBGd1w4X3U12 "
|
|
||||||
+ "fFxoY3eqzNgBEtduoGKPZ/"
|
|
||||||
+ "NpP9cuKJORJ18283aV8hR4WO91VR0q1zcM jLwqUg=="),
|
|
||||||
+ /*
|
|
||||||
+ * Sentinel.
|
|
||||||
+ */
|
|
||||||
+ TEXT_SENTINEL()
|
|
||||||
+ };
|
|
||||||
+ wire_ok_t wire_ok[] = {
|
|
||||||
+ WIRE_VALID(0x00, 0x06, 0x08, 0x00, 0x00, 0x01, 0x51, 0x80, 0x69,
|
|
||||||
+ 0xee, 0x44, 0x90, 0x69, 0xdd, 0x13, 0x00, 0xd4, 0x79,
|
|
||||||
+ 0x00, 0xb4, 0x56, 0xdc, 0xa1, 0x53, 0xfc, 0x32, 0x7a,
|
|
||||||
+ 0x5e, 0x71, 0x4a, 0xae, 0x27, 0xf6, 0xa3, 0xf9, 0x77,
|
|
||||||
+ 0x8d, 0x81, 0x5e, 0xed, 0xb3, 0xd1, 0x92, 0x1d, 0x59,
|
|
||||||
+ 0x17, 0x69, 0x74, 0x49, 0xac, 0x9f, 0xd3, 0x12, 0x43,
|
|
||||||
+ 0x99, 0x02, 0x95, 0x46, 0xd0, 0x5e, 0x84, 0xf6, 0xc6,
|
|
||||||
+ 0x29, 0xc4, 0x69, 0x36, 0x22, 0xdc, 0x1e, 0x2c, 0xbe,
|
|
||||||
+ 0x37, 0xba, 0x38, 0xa8, 0x1a, 0x3d, 0x07, 0x5b, 0x06,
|
|
||||||
+ 0x43, 0x45, 0x1f, 0xaf, 0x6e, 0xea, 0xfe, 0x3b, 0xf7,
|
|
||||||
+ 0x48, 0x76, 0x17, 0xa2, 0x8a, 0x0d, 0x55, 0xbd, 0x4f,
|
|
||||||
+ 0xbd, 0x1d, 0x72, 0xe2, 0x40, 0xe5, 0x62, 0x63, 0xd2,
|
|
||||||
+ 0x9c, 0xeb, 0x88, 0xb1, 0x77, 0x22, 0x61, 0x60, 0x20,
|
|
||||||
+ 0xb9, 0x2b, 0xe6, 0xce, 0xd6, 0xab, 0x07, 0xc5, 0xdf,
|
|
||||||
+ 0x8a, 0x25, 0x73, 0x9a, 0xc7, 0x21, 0xdb, 0xa9, 0xc8,
|
|
||||||
+ 0x58, 0x90, 0x31, 0x72, 0xe0, 0xf2, 0xfa, 0xa9, 0xfb,
|
|
||||||
+ 0x44, 0x55, 0xa2, 0xe4, 0xb9, 0xe4, 0x60, 0x8d, 0x78,
|
|
||||||
+ 0x0e, 0xb2, 0xaf, 0xcd, 0xc6, 0xf0, 0x97, 0x0e, 0x00,
|
|
||||||
+ 0x1a, 0xe7, 0x1c, 0xb4, 0xfb, 0x74, 0xa5, 0xd2, 0x6c,
|
|
||||||
+ 0xb1, 0x22, 0xcf, 0x2b, 0x27, 0x92, 0x9e, 0x5d, 0xf2,
|
|
||||||
+ 0x50, 0x15, 0xee, 0xea, 0xc6, 0x06, 0xb0, 0x56, 0x32,
|
|
||||||
+ 0x6c, 0x25, 0x32, 0xb0, 0xf2, 0x77, 0x8e, 0x4f, 0x0d,
|
|
||||||
+ 0xab, 0x41, 0xf2, 0xda, 0x8a, 0x05, 0xae, 0xd8, 0xb2,
|
|
||||||
+ 0x16, 0xc3, 0xe2, 0x32, 0x56, 0xb2, 0xe3, 0x64, 0x97,
|
|
||||||
+ 0x4b, 0xa8, 0x69, 0x22, 0x2c, 0x11, 0x9d, 0xd7, 0x0e,
|
|
||||||
+ 0x17, 0xdd, 0x4d, 0x76, 0x7c, 0x5c, 0x68, 0x63, 0x77,
|
|
||||||
+ 0xaa, 0xcc, 0xd8, 0x01, 0x12, 0xd7, 0x6e, 0xa0, 0x62,
|
|
||||||
+ 0x8f, 0x67, 0xf3, 0x69, 0x3f, 0xd7, 0x2e, 0x28, 0x93,
|
|
||||||
+ 0x91, 0x27, 0x5f, 0x36, 0xf3, 0x76, 0x95, 0xf2, 0x14,
|
|
||||||
+ 0x78, 0x58, 0xef, 0x75, 0x55, 0x1d, 0x2a, 0xd7, 0x37,
|
|
||||||
+ 0x0c, 0x8c, 0xbc, 0x2a, 0x52),
|
|
||||||
+ /* labels too short for signer */
|
|
||||||
+ WIRE_INVALID(
|
|
||||||
+ 0x00, 0x06, 0x08, 0x00, 0x00, 0x01, 0x51, 0x80, 0x69,
|
|
||||||
+ 0xee, 0x44, 0x90, 0x69, 0xdd, 0x13, 0x00, 0xd4, 0x79,
|
|
||||||
+ 0x07, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x00,
|
|
||||||
+ 0xb4, 0x56, 0xdc, 0xa1, 0x53, 0xfc, 0x32, 0x7a, 0x5e,
|
|
||||||
+ 0x71, 0x4a, 0xae, 0x27, 0xf6, 0xa3, 0xf9, 0x77, 0x8d,
|
|
||||||
+ 0x81, 0x5e, 0xed, 0xb3, 0xd1, 0x92, 0x1d, 0x59, 0x17,
|
|
||||||
+ 0x69, 0x74, 0x49, 0xac, 0x9f, 0xd3, 0x12, 0x43, 0x99,
|
|
||||||
+ 0x02, 0x95, 0x46, 0xd0, 0x5e, 0x84, 0xf6, 0xc6, 0x29,
|
|
||||||
+ 0xc4, 0x69, 0x36, 0x22, 0xdc, 0x1e, 0x2c, 0xbe, 0x37,
|
|
||||||
+ 0xba, 0x38, 0xa8, 0x1a, 0x3d, 0x07, 0x5b, 0x06, 0x43,
|
|
||||||
+ 0x45, 0x1f, 0xaf, 0x6e, 0xea, 0xfe, 0x3b, 0xf7, 0x48,
|
|
||||||
+ 0x76, 0x17, 0xa2, 0x8a, 0x0d, 0x55, 0xbd, 0x4f, 0xbd,
|
|
||||||
+ 0x1d, 0x72, 0xe2, 0x40, 0xe5, 0x62, 0x63, 0xd2, 0x9c,
|
|
||||||
+ 0xeb, 0x88, 0xb1, 0x77, 0x22, 0x61, 0x60, 0x20, 0xb9,
|
|
||||||
+ 0x2b, 0xe6, 0xce, 0xd6, 0xab, 0x07, 0xc5, 0xdf, 0x8a,
|
|
||||||
+ 0x25, 0x73, 0x9a, 0xc7, 0x21, 0xdb, 0xa9, 0xc8, 0x58,
|
|
||||||
+ 0x90, 0x31, 0x72, 0xe0, 0xf2, 0xfa, 0xa9, 0xfb, 0x44,
|
|
||||||
+ 0x55, 0xa2, 0xe4, 0xb9, 0xe4, 0x60, 0x8d, 0x78, 0x0e,
|
|
||||||
+ 0xb2, 0xaf, 0xcd, 0xc6, 0xf0, 0x97, 0x0e, 0x00, 0x1a,
|
|
||||||
+ 0xe7, 0x1c, 0xb4, 0xfb, 0x74, 0xa5, 0xd2, 0x6c, 0xb1,
|
|
||||||
+ 0x22, 0xcf, 0x2b, 0x27, 0x92, 0x9e, 0x5d, 0xf2, 0x50,
|
|
||||||
+ 0x15, 0xee, 0xea, 0xc6, 0x06, 0xb0, 0x56, 0x32, 0x6c,
|
|
||||||
+ 0x25, 0x32, 0xb0, 0xf2, 0x77, 0x8e, 0x4f, 0x0d, 0xab,
|
|
||||||
+ 0x41, 0xf2, 0xda, 0x8a, 0x05, 0xae, 0xd8, 0xb2, 0x16,
|
|
||||||
+ 0xc3, 0xe2, 0x32, 0x56, 0xb2, 0xe3, 0x64, 0x97, 0x4b,
|
|
||||||
+ 0xa8, 0x69, 0x22, 0x2c, 0x11, 0x9d, 0xd7, 0x0e, 0x17,
|
|
||||||
+ 0xdd, 0x4d, 0x76, 0x7c, 0x5c, 0x68, 0x63, 0x77, 0xaa,
|
|
||||||
+ 0xcc, 0xd8, 0x01, 0x12, 0xd7, 0x6e, 0xa0, 0x62, 0x8f,
|
|
||||||
+ 0x67, 0xf3, 0x69, 0x3f, 0xd7, 0x2e, 0x28, 0x93, 0x91,
|
|
||||||
+ 0x27, 0x5f, 0x36, 0xf3, 0x76, 0x95, 0xf2, 0x14, 0x78,
|
|
||||||
+ 0x58, 0xef, 0x75, 0x55, 0x1d, 0x2a, 0xd7, 0x37, 0x0c,
|
|
||||||
+ 0x8c, 0xbc, 0x2a, 0x52),
|
|
||||||
+
|
|
||||||
+ WIRE_SENTINEL()
|
|
||||||
+ };
|
|
||||||
+ check_rdata(text_ok, wire_ok, NULL, false, dns_rdataclass_in,
|
|
||||||
+ dns_rdatatype_rrsig, sizeof(dns_rdata_rrsig_t));
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
ISC_RUN_TEST_IMPL(resinfo) {
|
|
||||||
text_ok_t text_ok[] = {
|
|
||||||
TEXT_VALID_CHANGED("qnamemin exterr=15,16,17 "
|
|
||||||
@@ -3357,6 +3466,7 @@ ISC_TEST_ENTRY(nsec3)
|
|
||||||
ISC_TEST_ENTRY(nxt)
|
|
||||||
ISC_TEST_ENTRY(resinfo)
|
|
||||||
ISC_TEST_ENTRY(rkey)
|
|
||||||
+ISC_TEST_ENTRY(rrsig)
|
|
||||||
ISC_TEST_ENTRY(sshfp)
|
|
||||||
ISC_TEST_ENTRY(wallet)
|
|
||||||
ISC_TEST_ENTRY(wks)
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,267 +0,0 @@
|
||||||
From 7a8a1f74c742e98fb5e105b013e7c2bd7af4a76c Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mark Andrews <marka@isc.org>
|
|
||||||
Date: Tue, 14 Apr 2026 15:14:06 +1000
|
|
||||||
Subject: [PATCH] Don't sign out of zone records in dnssec-signzone
|
|
||||||
|
|
||||||
dnssec-signzone was signing extraneous records that were not within
|
|
||||||
the namespace of the zone. This no longer occurs.
|
|
||||||
|
|
||||||
(cherry picked from commit e45c9af7051421fd370f20ba8325199c606223fd)
|
|
||||||
|
|
||||||
Don't sign out of zone records in dnssec-signzone
|
|
||||||
|
|
||||||
dnssec-signzone was signing extraneous records that were not within
|
|
||||||
the namespace of the zone. This no longer occurs.
|
|
||||||
|
|
||||||
(cherry picked from commit e45c9af7051421fd370f20ba8325199c606223fd)
|
|
||||||
(cherry picked from commit 1a4986e2533f87e80eb21da3f06708d335aff1e2)
|
|
||||||
|
|
||||||
Invalid signed wildcard records were being accepted
|
|
||||||
|
|
||||||
An RRSIG whose Labels field indicates fewer labels than its signer
|
|
||||||
name requires was being accepted. When such a record covers a
|
|
||||||
wildcard, the validator reconstructs a wildcard owner name above the
|
|
||||||
signer's zone and caches it as secure. RFC 8198 cache synthesis
|
|
||||||
(synth-from-dnssec) then serves that forged wildcard for unrelated
|
|
||||||
names, poisoning the cache.
|
|
||||||
|
|
||||||
These records are now rejected, both when an RRSIG is parsed and when
|
|
||||||
its signature is verified.
|
|
||||||
|
|
||||||
(cherry picked from commit 084ca5ee10515e461d46b63df9660b8394bc7de9)
|
|
||||||
(cherry picked from commit 15089066b15f826d7487c3d160b5872820f84b83)
|
|
||||||
---
|
|
||||||
bin/dnssec/dnssec-signzone.c | 5 ++++
|
|
||||||
lib/dns/dnssec.c | 43 +++++++++++++++++++++++---------
|
|
||||||
lib/dns/rdata/generic/rrsig_46.c | 37 ++++++++++++++++++++-------
|
|
||||||
3 files changed, 64 insertions(+), 21 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/dnssec/dnssec-signzone.c b/bin/dnssec/dnssec-signzone.c
|
|
||||||
index 73855e6284..9e3a48a592 100644
|
|
||||||
--- a/bin/dnssec/dnssec-signzone.c
|
|
||||||
+++ b/bin/dnssec/dnssec-signzone.c
|
|
||||||
@@ -1643,6 +1643,11 @@ assignwork(isc_task_t *task, isc_task_t *worker) {
|
|
||||||
dns_db_detachnode(gdb, &node);
|
|
||||||
goto next;
|
|
||||||
}
|
|
||||||
+ if (!dns_name_issubdomain(name, gorigin)) {
|
|
||||||
+ dumpnode(name, node);
|
|
||||||
+ dns_db_detachnode(gdb, &node);
|
|
||||||
+ goto next;
|
|
||||||
+ }
|
|
||||||
/*
|
|
||||||
* Sort the zone data from the glue and out-of-zone data.
|
|
||||||
* For NSEC zones nodes with zone data have NSEC records.
|
|
||||||
diff --git a/lib/dns/dnssec.c b/lib/dns/dnssec.c
|
|
||||||
index c7e922437c..b12529b5d5 100644
|
|
||||||
--- a/lib/dns/dnssec.c
|
|
||||||
+++ b/lib/dns/dnssec.c
|
|
||||||
@@ -130,11 +130,11 @@ dns_dnssec_keyfromrdata(const dns_name_t *name, const dns_rdata_t *rdata,
|
|
||||||
isc_buffer_t b;
|
|
||||||
isc_region_t r;
|
|
||||||
|
|
||||||
- INSIST(name != NULL);
|
|
||||||
- INSIST(rdata != NULL);
|
|
||||||
- INSIST(mctx != NULL);
|
|
||||||
- INSIST(key != NULL);
|
|
||||||
- INSIST(*key == NULL);
|
|
||||||
+ REQUIRE(name != NULL);
|
|
||||||
+ REQUIRE(rdata != NULL);
|
|
||||||
+ REQUIRE(mctx != NULL);
|
|
||||||
+ REQUIRE(key != NULL);
|
|
||||||
+ REQUIRE(*key == NULL);
|
|
||||||
REQUIRE(rdata->type == dns_rdatatype_key ||
|
|
||||||
rdata->type == dns_rdatatype_dnskey);
|
|
||||||
|
|
||||||
@@ -187,12 +187,14 @@ dns_dnssec_sign(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
|
||||||
isc_result_t ret;
|
|
||||||
isc_buffer_t *databuf = NULL;
|
|
||||||
char data[256 + 8];
|
|
||||||
+ unsigned int labels;
|
|
||||||
unsigned int sigsize;
|
|
||||||
dns_fixedname_t fnewname;
|
|
||||||
dns_fixedname_t fsigner;
|
|
||||||
|
|
||||||
REQUIRE(name != NULL);
|
|
||||||
- REQUIRE(dns_name_countlabels(name) <= 255);
|
|
||||||
+ labels = dns_name_countlabels(name);
|
|
||||||
+ REQUIRE(labels <= 255 && labels > 0);
|
|
||||||
REQUIRE(set != NULL);
|
|
||||||
REQUIRE(key != NULL);
|
|
||||||
REQUIRE(inception != NULL);
|
|
||||||
@@ -221,7 +223,7 @@ dns_dnssec_sign(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
|
||||||
|
|
||||||
sig.covered = set->type;
|
|
||||||
sig.algorithm = dst_key_alg(key);
|
|
||||||
- sig.labels = dns_name_countlabels(name) - 1;
|
|
||||||
+ sig.labels = labels - 1;
|
|
||||||
if (dns_name_iswildcard(name)) {
|
|
||||||
sig.labels--;
|
|
||||||
}
|
|
||||||
@@ -365,10 +367,13 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
|
||||||
isc_result_t ret;
|
|
||||||
unsigned char data[300];
|
|
||||||
dst_context_t *ctx = NULL;
|
|
||||||
- int labels = 0;
|
|
||||||
+ unsigned int labels;
|
|
||||||
+ unsigned int siglabels;
|
|
||||||
bool downcase = false;
|
|
||||||
|
|
||||||
REQUIRE(name != NULL);
|
|
||||||
+ labels = dns_name_countlabels(name);
|
|
||||||
+ REQUIRE(labels > 0);
|
|
||||||
REQUIRE(set != NULL);
|
|
||||||
REQUIRE(key != NULL);
|
|
||||||
REQUIRE(mctx != NULL);
|
|
||||||
@@ -383,6 +388,21 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
|
||||||
return DNS_R_SIGINVALID;
|
|
||||||
}
|
|
||||||
|
|
||||||
+ /*
|
|
||||||
+ * The RRSIG labels field can't indicate fewer labels than the
|
|
||||||
+ * signer. Also the labels shouldn't be greater than that of
|
|
||||||
+ * the owner name.
|
|
||||||
+ *
|
|
||||||
+ * sig.labels doesn't include the root label, so add 1 to account
|
|
||||||
+ * for it.
|
|
||||||
+ */
|
|
||||||
+ siglabels = sig.labels + 1;
|
|
||||||
+ if (siglabels < dns_name_countlabels(&sig.signer) || siglabels > labels)
|
|
||||||
+ {
|
|
||||||
+ inc_stat(dns_dnssecstats_fail);
|
|
||||||
+ return DNS_R_SIGINVALID;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
if (isc_serial_lt(sig.timeexpire, sig.timesigned)) {
|
|
||||||
inc_stat(dns_dnssecstats_fail);
|
|
||||||
return DNS_R_SIGINVALID;
|
|
||||||
@@ -449,10 +469,9 @@ again:
|
|
||||||
* If the name is an expanded wildcard, use the wildcard name.
|
|
||||||
*/
|
|
||||||
dns_fixedname_init(&fnewname);
|
|
||||||
- labels = dns_name_countlabels(name) - 1;
|
|
||||||
RUNTIME_CHECK(dns_name_downcase(name, dns_fixedname_name(&fnewname),
|
|
||||||
NULL) == ISC_R_SUCCESS);
|
|
||||||
- if (labels - sig.labels > 0) {
|
|
||||||
+ if (labels > siglabels) {
|
|
||||||
dns_name_split(dns_fixedname_name(&fnewname), sig.labels + 1,
|
|
||||||
NULL, dns_fixedname_name(&fnewname));
|
|
||||||
}
|
|
||||||
@@ -463,7 +482,7 @@ again:
|
|
||||||
* Create an envelope for each rdata: <name|type|class|ttl>.
|
|
||||||
*/
|
|
||||||
isc_buffer_init(&envbuf, data, sizeof(data));
|
|
||||||
- if (labels - sig.labels > 0) {
|
|
||||||
+ if (labels > siglabels) {
|
|
||||||
isc_buffer_putuint8(&envbuf, 1);
|
|
||||||
isc_buffer_putuint8(&envbuf, '*');
|
|
||||||
memmove(data + 2, r.base, r.length);
|
|
||||||
@@ -559,7 +578,7 @@ cleanup_struct:
|
|
||||||
inc_stat(dns_dnssecstats_fail);
|
|
||||||
}
|
|
||||||
|
|
||||||
- if (ret == ISC_R_SUCCESS && labels - sig.labels > 0) {
|
|
||||||
+ if (ret == ISC_R_SUCCESS && labels > siglabels) {
|
|
||||||
if (wild != NULL) {
|
|
||||||
RUNTIME_CHECK(dns_name_concatenate(
|
|
||||||
dns_wildcardname,
|
|
||||||
diff --git a/lib/dns/rdata/generic/rrsig_46.c b/lib/dns/rdata/generic/rrsig_46.c
|
|
||||||
index 10bc039e93..4cf4259c2b 100644
|
|
||||||
--- a/lib/dns/rdata/generic/rrsig_46.c
|
|
||||||
+++ b/lib/dns/rdata/generic/rrsig_46.c
|
|
||||||
@@ -23,12 +23,12 @@
|
|
||||||
static isc_result_t
|
|
||||||
fromtext_rrsig(ARGS_FROMTEXT) {
|
|
||||||
isc_token_t token;
|
|
||||||
- unsigned char c;
|
|
||||||
+ unsigned char alg, labels;
|
|
||||||
long i;
|
|
||||||
dns_rdatatype_t covered;
|
|
||||||
- char *e;
|
|
||||||
+ char *e = NULL;
|
|
||||||
isc_result_t result;
|
|
||||||
- dns_name_t name;
|
|
||||||
+ dns_name_t signer;
|
|
||||||
isc_buffer_t buffer;
|
|
||||||
uint32_t time_signed, time_expire;
|
|
||||||
|
|
||||||
@@ -61,8 +61,8 @@ fromtext_rrsig(ARGS_FROMTEXT) {
|
|
||||||
*/
|
|
||||||
RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
|
|
||||||
false));
|
|
||||||
- RETTOK(dns_secalg_fromtext(&c, &token.value.as_textregion));
|
|
||||||
- RETERR(mem_tobuffer(target, &c, 1));
|
|
||||||
+ RETTOK(dns_secalg_fromtext(&alg, &token.value.as_textregion));
|
|
||||||
+ RETERR(mem_tobuffer(target, &alg, 1));
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Labels.
|
|
||||||
@@ -72,8 +72,8 @@ fromtext_rrsig(ARGS_FROMTEXT) {
|
|
||||||
if (token.value.as_ulong > 0xffU) {
|
|
||||||
RETTOK(ISC_R_RANGE);
|
|
||||||
}
|
|
||||||
- c = (unsigned char)token.value.as_ulong;
|
|
||||||
- RETERR(mem_tobuffer(target, &c, 1));
|
|
||||||
+ labels = (unsigned char)token.value.as_ulong;
|
|
||||||
+ RETERR(mem_tobuffer(target, &labels, 1));
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Original ttl.
|
|
||||||
@@ -144,12 +144,20 @@ fromtext_rrsig(ARGS_FROMTEXT) {
|
|
||||||
*/
|
|
||||||
RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
|
|
||||||
false));
|
|
||||||
- dns_name_init(&name, NULL);
|
|
||||||
+ dns_name_init(&signer, NULL);
|
|
||||||
buffer_fromregion(&buffer, &token.value.as_region);
|
|
||||||
if (origin == NULL) {
|
|
||||||
origin = dns_rootname;
|
|
||||||
}
|
|
||||||
- RETTOK(dns_name_fromtext(&name, &buffer, origin, options, target));
|
|
||||||
+ RETTOK(dns_name_fromtext(&signer, &buffer, origin, options, target));
|
|
||||||
+
|
|
||||||
+ /*
|
|
||||||
+ * (RRSIG labels doesn't include the root label, so add one
|
|
||||||
+ * to normalize it before checking against the signer.)
|
|
||||||
+ */
|
|
||||||
+ if ((unsigned int)(labels + 1) < dns_name_countlabels(&signer)) {
|
|
||||||
+ RETTOK(ISC_R_RANGE);
|
|
||||||
+ }
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Sig.
|
|
||||||
@@ -278,6 +286,7 @@ static isc_result_t
|
|
||||||
fromwire_rrsig(ARGS_FROMWIRE) {
|
|
||||||
isc_region_t sr;
|
|
||||||
dns_name_t name;
|
|
||||||
+ unsigned char labels;
|
|
||||||
|
|
||||||
REQUIRE(type == dns_rdatatype_rrsig);
|
|
||||||
|
|
||||||
@@ -300,6 +309,8 @@ fromwire_rrsig(ARGS_FROMWIRE) {
|
|
||||||
return ISC_R_UNEXPECTEDEND;
|
|
||||||
}
|
|
||||||
|
|
||||||
+ labels = sr.base[3];
|
|
||||||
+
|
|
||||||
isc_buffer_forward(source, 18);
|
|
||||||
RETERR(mem_tobuffer(target, sr.base, 18));
|
|
||||||
|
|
||||||
@@ -309,6 +320,14 @@ fromwire_rrsig(ARGS_FROMWIRE) {
|
|
||||||
dns_name_init(&name, NULL);
|
|
||||||
RETERR(dns_name_fromwire(&name, source, dctx, options, target));
|
|
||||||
|
|
||||||
+ /*
|
|
||||||
+ * (RRSIG labels doesn't include the root label, so add one
|
|
||||||
+ * to normalize it before checking against the signer.)
|
|
||||||
+ */
|
|
||||||
+ if ((unsigned int)(labels + 1) < dns_name_countlabels(&name)) {
|
|
||||||
+ RETERR(DNS_R_FORMERR);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
/*
|
|
||||||
* Sig.
|
|
||||||
*/
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,435 +0,0 @@
|
||||||
From a31296b120efc985fb1fc3c932882e965156473b Mon Sep 17 00:00:00 2001
|
|
||||||
From: Colin Vidal <colin@isc.org>
|
|
||||||
Date: Mon, 15 Jun 2026 11:34:08 +0200
|
|
||||||
Subject: [PATCH] Reproducer for #5946 (assertion in some CNAME/DNAME queries)
|
|
||||||
|
|
||||||
Add a system test reproducing the issue reported by #5946, which
|
|
||||||
is also CVE-2026-12617. There are two scenarios:
|
|
||||||
|
|
||||||
- A client send queries for a DNAME and A record to the resolver (ns3),
|
|
||||||
and the authoritative server (ans2) responds positively to the A query
|
|
||||||
but delay the DNAME response and respond later negatively;
|
|
||||||
|
|
||||||
- A client send queries for a CNAME and A record to the resolver (ns3),
|
|
||||||
and the authoritative server (ans2) responds positively to the A query
|
|
||||||
but delay the CNAME response and respond later with a self-referential
|
|
||||||
CNAME.
|
|
||||||
|
|
||||||
The test does not check the results of the queries, however, it expects
|
|
||||||
the resolver to correctly handle those and do not assert.
|
|
||||||
|
|
||||||
(cherry picked from commit e88271f2e584010157b068cc998dd76451273562)
|
|
||||||
(cherry picked from commit bb92832fb6ae899bee7206c2d8966258461c2f71)
|
|
||||||
|
|
||||||
Stabilize timing in the cname_dname_negcache test
|
|
||||||
|
|
||||||
The #5946 reproducer relied on ans2 answering the negative DNAME/CNAME
|
|
||||||
query a fixed second after receiving it, racing that delay against the
|
|
||||||
resolver's per-query timeout. When the timeout fired first -- which
|
|
||||||
happens under load, most notably under ThreadSanitizer, where named is
|
|
||||||
slowed but ans2 (wall-clock) is not -- the resolver dropped the late
|
|
||||||
answer, never processed the negative response, and the watched SOA never
|
|
||||||
appeared, so the test timed out. This made it flaky on the
|
|
||||||
security-bind-9.20 CI. Merely shortening the fixed delay would trade
|
|
||||||
that for the opposite, worse failure: the negative answer arriving
|
|
||||||
before the positive one is cached, silently not exercising the bug.
|
|
||||||
|
|
||||||
Release the negative answer based on the resolver's progress instead of
|
|
||||||
a wall-clock deadline: hold it until ans2 has sent the positive answer
|
|
||||||
(a shared event), then wait a short settle for the resolver to cache it.
|
|
||||||
Both queries traverse the same delegation, so any latency reaching ans2
|
|
||||||
shifts the positive send and the negative fetch's deadline together and
|
|
||||||
cancels out; only the settle, kept well under MINIMUM_QUERY_TIMEOUT
|
|
||||||
(301 ms), has to fit inside the per-query timeout.
|
|
||||||
|
|
||||||
Verified that the stabilized test still triggers the
|
|
||||||
INSIST(namereln == dns_namereln_subdomain) assertion when the resolver
|
|
||||||
fix is reverted.
|
|
||||||
|
|
||||||
Assisted-by: Claude:claude-opus-4-8
|
|
||||||
(cherry picked from commit 738456d91564526e6f15c3858b4c809cd6749e1e)
|
|
||||||
(cherry picked from commit 0c20ee4e8e68999ca617434cde65dd3808f57d8c)
|
|
||||||
|
|
||||||
Split cname_dname_negcache into per-scenario modules
|
|
||||||
|
|
||||||
The DNAME and CNAME scenarios shared a single module, hence a single
|
|
||||||
module-scoped ns3 (the framework sets servers up per module, not per
|
|
||||||
test function). test_dname_negcache cached foo.test. DNAME bar.test.;
|
|
||||||
when test_cname_negcache ran next against the same resolver,
|
|
||||||
cname.foo.test. was DNAME-mapped to cname.bar.test., so the resolver
|
|
||||||
never queried ans2 for the self-referential CNAME and that half of the
|
|
||||||
bug was never exercised. The hardcoded, unanchored "foo.test." watcher
|
|
||||||
still matched test_dname's leftover SOA, so test_cname passed without
|
|
||||||
testing anything -- the CNAME assertion had no coverage.
|
|
||||||
|
|
||||||
Give each scenario its own module so each gets a fresh server set, and
|
|
||||||
anchor the watcher to the queried name so a test cannot pass on an
|
|
||||||
unrelated record.
|
|
||||||
|
|
||||||
With the resolver fix reverted, each module now independently triggers
|
|
||||||
its own assertion:
|
|
||||||
|
|
||||||
DNAME query.c INSIST(namereln == dns_namereln_subdomain)
|
|
||||||
CNAME query.c INSIST(qctx->rdataset == NULL || qctx->qtype == dname)
|
|
||||||
|
|
||||||
Assisted-by: Claude:claude-opus-4-8
|
|
||||||
(cherry picked from commit 3ef0b8d04a1653407cfb9ee88772ae18689b1318)
|
|
||||||
(cherry picked from commit 887124315f03a006c4dc76e48ae3d0d8aac3c407)
|
|
||||||
---
|
|
||||||
.../system/cname_dname_negcache/ans2/ans.py | 148 ++++++++++++++++++
|
|
||||||
.../system/cname_dname_negcache/common.py | 46 ++++++
|
|
||||||
.../cname_dname_negcache/ns1/bar.test.db | 5 +
|
|
||||||
.../cname_dname_negcache/ns1/named.conf.j2 | 24 +++
|
|
||||||
.../system/cname_dname_negcache/ns1/root.db | 6 +
|
|
||||||
.../system/cname_dname_negcache/ns1/test.db | 8 +
|
|
||||||
.../cname_dname_negcache/ns3/named.conf.j2 | 11 ++
|
|
||||||
.../tests_cname_negcache.py | 16 ++
|
|
||||||
.../tests_dname_negcache.py | 16 ++
|
|
||||||
9 files changed, 280 insertions(+)
|
|
||||||
create mode 100644 bin/tests/system/cname_dname_negcache/ans2/ans.py
|
|
||||||
create mode 100644 bin/tests/system/cname_dname_negcache/common.py
|
|
||||||
create mode 100644 bin/tests/system/cname_dname_negcache/ns1/bar.test.db
|
|
||||||
create mode 100644 bin/tests/system/cname_dname_negcache/ns1/named.conf.j2
|
|
||||||
create mode 100644 bin/tests/system/cname_dname_negcache/ns1/root.db
|
|
||||||
create mode 100644 bin/tests/system/cname_dname_negcache/ns1/test.db
|
|
||||||
create mode 100644 bin/tests/system/cname_dname_negcache/ns3/named.conf.j2
|
|
||||||
create mode 100644 bin/tests/system/cname_dname_negcache/tests_cname_negcache.py
|
|
||||||
create mode 100644 bin/tests/system/cname_dname_negcache/tests_dname_negcache.py
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/cname_dname_negcache/ans2/ans.py b/bin/tests/system/cname_dname_negcache/ans2/ans.py
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..392fe1e088
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/cname_dname_negcache/ans2/ans.py
|
|
||||||
@@ -0,0 +1,148 @@
|
|
||||||
+"""
|
|
||||||
+Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+
|
|
||||||
+SPDX-License-Identifier: MPL-2.0
|
|
||||||
+
|
|
||||||
+This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+
|
|
||||||
+See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+information regarding copyright ownership.
|
|
||||||
+"""
|
|
||||||
+
|
|
||||||
+from collections.abc import AsyncGenerator
|
|
||||||
+
|
|
||||||
+import asyncio
|
|
||||||
+
|
|
||||||
+from dns import name, rcode, rdataclass, rdatatype, rrset
|
|
||||||
+
|
|
||||||
+from isctest.asyncserver import (
|
|
||||||
+ AsyncDnsServer,
|
|
||||||
+ DnsResponseSend,
|
|
||||||
+ QnameQtypeHandler,
|
|
||||||
+ QueryContext,
|
|
||||||
+ StaticResponseHandler,
|
|
||||||
+)
|
|
||||||
+
|
|
||||||
+# The attack relies on the resolver caching the positive CNAME/DNAME answer
|
|
||||||
+# *before* it processes the negative answer for the same name. The negative
|
|
||||||
+# answer must therefore be held back until the positive one has been sent, but
|
|
||||||
+# released again while the negative fetch is still waiting for it.
|
|
||||||
+#
|
|
||||||
+# Releasing it at a fixed wall-clock delay (the original approach) is racy: the
|
|
||||||
+# delay must be larger than the time it takes the resolver to cache the
|
|
||||||
+# positive answer, yet smaller than the resolver's per-query timeout. Under
|
|
||||||
+# load -- most notably ThreadSanitizer, which slows down `named` but not this
|
|
||||||
+# (wall-clock) server -- those bounds can be violated in either direction,
|
|
||||||
+# making the test either time out (#5946 CI failures) or, worse, silently stop
|
|
||||||
+# exercising the bug.
|
|
||||||
+#
|
|
||||||
+# Instead, gate the negative answer on an event set right after the positive
|
|
||||||
+# answer is sent. Both queries traverse the same delegation, so any latency in
|
|
||||||
+# reaching this server shifts the positive send and the negative fetch's
|
|
||||||
+# deadline together and cancels out; only the small settle below has to fit
|
|
||||||
+# inside the per-query timeout.
|
|
||||||
+#
|
|
||||||
+# _SETTLE must be longer than the few milliseconds the resolver needs to cache
|
|
||||||
+# the positive answer, and shorter than MINIMUM_QUERY_TIMEOUT (301 ms in
|
|
||||||
+# lib/dns/resolver.c) so the in-flight negative fetch has not given up yet.
|
|
||||||
+_SETTLE = 0.1
|
|
||||||
+
|
|
||||||
+_dname_positive_sent = asyncio.Event()
|
|
||||||
+_cname_positive_sent = asyncio.Event()
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+async def _hold_until_positive_cached(positive_sent: asyncio.Event) -> None:
|
|
||||||
+ await positive_sent.wait()
|
|
||||||
+ await asyncio.sleep(_SETTLE)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def build_rrset(
|
|
||||||
+ qname: name.Name | str,
|
|
||||||
+ rtype: rdatatype.RdataType,
|
|
||||||
+ rdata: str,
|
|
||||||
+ ttl: int = 300,
|
|
||||||
+) -> rrset.RRset:
|
|
||||||
+ return rrset.from_text(qname, ttl, rdataclass.IN, rtype, rdata)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class FooTestNsHandler(QnameQtypeHandler, StaticResponseHandler):
|
|
||||||
+ qnames = ["foo.test."]
|
|
||||||
+ qtypes = [rdatatype.NS]
|
|
||||||
+ answer = [build_rrset("foo.test.", rdatatype.NS, "ns.foo.test.")]
|
|
||||||
+ additional = [build_rrset("ns.foo.test.", rdatatype.A, "10.53.0.2")]
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class DelayedDnameNegHandler(QnameQtypeHandler, StaticResponseHandler):
|
|
||||||
+ qnames = ["foo.test."]
|
|
||||||
+ qtypes = [rdatatype.DNAME]
|
|
||||||
+ authority = [
|
|
||||||
+ build_rrset(
|
|
||||||
+ "foo.test.",
|
|
||||||
+ rdatatype.SOA,
|
|
||||||
+ "ns.test. op.ns.test. 2081509183 86400 3600 3600000 300",
|
|
||||||
+ )
|
|
||||||
+ ]
|
|
||||||
+
|
|
||||||
+ async def get_responses(
|
|
||||||
+ self, qctx: QueryContext
|
|
||||||
+ ) -> AsyncGenerator[DnsResponseSend, None]:
|
|
||||||
+ await _hold_until_positive_cached(_dname_positive_sent)
|
|
||||||
+ async for response in super().get_responses(qctx):
|
|
||||||
+ yield response
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class DnamePosHandler(QnameQtypeHandler, StaticResponseHandler):
|
|
||||||
+ qnames = ["a.foo.test."]
|
|
||||||
+ qtypes = [rdatatype.A]
|
|
||||||
+ answer = [
|
|
||||||
+ build_rrset("foo.test.", rdatatype.DNAME, "bar.test."),
|
|
||||||
+ build_rrset("a.foo.test.", rdatatype.CNAME, "a.bar.test."),
|
|
||||||
+ ]
|
|
||||||
+
|
|
||||||
+ async def get_responses(
|
|
||||||
+ self, qctx: QueryContext
|
|
||||||
+ ) -> AsyncGenerator[DnsResponseSend, None]:
|
|
||||||
+ async for response in super().get_responses(qctx):
|
|
||||||
+ yield response
|
|
||||||
+ _dname_positive_sent.set()
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class CnameHandler(QnameQtypeHandler):
|
|
||||||
+ qnames = ["cname.foo.test."]
|
|
||||||
+ qtypes = [rdatatype.CNAME, rdatatype.A]
|
|
||||||
+ answer = [build_rrset("cname.foo.test.", rdatatype.CNAME, "cname.foo.test.")]
|
|
||||||
+ authority = [
|
|
||||||
+ build_rrset(
|
|
||||||
+ "cname.foo.test.",
|
|
||||||
+ rdatatype.SOA,
|
|
||||||
+ "ns.test. op.ns.test. 2081509183 86400 3600 3600000 300",
|
|
||||||
+ )
|
|
||||||
+ ]
|
|
||||||
+
|
|
||||||
+ async def get_responses(
|
|
||||||
+ self, qctx: QueryContext
|
|
||||||
+ ) -> AsyncGenerator[DnsResponseSend, None]:
|
|
||||||
+ if qctx.qtype == rdatatype.CNAME:
|
|
||||||
+ await _hold_until_positive_cached(_cname_positive_sent)
|
|
||||||
+ qctx.prepare_new_response(with_zone_data=False)
|
|
||||||
+ qctx.response.authority.extend(self.authority)
|
|
||||||
+ yield DnsResponseSend(qctx.response, authoritative=True)
|
|
||||||
+ else:
|
|
||||||
+ qctx.prepare_new_response(with_zone_data=False)
|
|
||||||
+ qctx.response.answer.extend(self.answer)
|
|
||||||
+ yield DnsResponseSend(qctx.response, authoritative=True)
|
|
||||||
+ _cname_positive_sent.set()
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def main() -> None:
|
|
||||||
+ server = AsyncDnsServer(default_aa=True, default_rcode=rcode.NOERROR)
|
|
||||||
+ server.install_response_handlers(
|
|
||||||
+ FooTestNsHandler(), DelayedDnameNegHandler(), DnamePosHandler(), CnameHandler()
|
|
||||||
+ )
|
|
||||||
+ server.run()
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+if __name__ == "__main__":
|
|
||||||
+ main()
|
|
||||||
diff --git a/bin/tests/system/cname_dname_negcache/common.py b/bin/tests/system/cname_dname_negcache/common.py
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..397cfdfa3d
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/cname_dname_negcache/common.py
|
|
||||||
@@ -0,0 +1,46 @@
|
|
||||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+#
|
|
||||||
+# SPDX-License-Identifier: MPL-2.0
|
|
||||||
+#
|
|
||||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+#
|
|
||||||
+# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+# information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+from os import environ
|
|
||||||
+from re import compile as Re
|
|
||||||
+from re import escape
|
|
||||||
+from socket import AF_INET, SOCK_DGRAM, socket
|
|
||||||
+
|
|
||||||
+import isctest
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def run_attack(ns, name1, type1, name2, type2):
|
|
||||||
+ msg1 = isctest.query.create(name1, type1, cd=True)
|
|
||||||
+ msg2 = isctest.query.create(name2, type2, cd=True)
|
|
||||||
+ port = int(environ["PORT"])
|
|
||||||
+
|
|
||||||
+ with socket(AF_INET, SOCK_DGRAM) as sock:
|
|
||||||
+ # The order the requests go out doesn't matter. What is important is
|
|
||||||
+ # that the first query starts recursion before the second query returns
|
|
||||||
+ # the answer, and the second query returns the answer before the first
|
|
||||||
+ # query returns the answer. (So, when the NOERROR/NODATA comes back from
|
|
||||||
+ # the first query, the cache is queried and we get the positive response
|
|
||||||
+ # cached from the second query attached to the fresp rdataset of the
|
|
||||||
+ # response of the first query.)
|
|
||||||
+ # That ordering is enforced by ans2, which holds back the negative
|
|
||||||
+ # answer to the first query until it has answered the second one (see
|
|
||||||
+ # ans2/ans.py); the resolver must not crash while reconciling them.
|
|
||||||
+ sock.sendto(msg1.to_wire(), (ns.ip, port))
|
|
||||||
+ sock.sendto(msg2.to_wire(), (ns.ip, port))
|
|
||||||
+
|
|
||||||
+ # The second query comes back immediately, the resolver caches the DNAME.
|
|
||||||
+ # The first query comes back shortly after, once ans2 has released the
|
|
||||||
+ # negative answer, and should not crash the server. Wait for the negative
|
|
||||||
+ # SOA for this specific name (not just any foo.test. one) so the test cannot
|
|
||||||
+ # pass on an unrelated record.
|
|
||||||
+ soa = Re(rf"(?<![\w.]){escape(name1)}.*IN\s+SOA\s+ns\.test\.\s+op\.ns\.test\.")
|
|
||||||
+ with ns.watch_log_from_start(timeout=15) as watcher:
|
|
||||||
+ watcher.wait_for_sequence([soa])
|
|
||||||
diff --git a/bin/tests/system/cname_dname_negcache/ns1/bar.test.db b/bin/tests/system/cname_dname_negcache/ns1/bar.test.db
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..840b9c3a2c
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/cname_dname_negcache/ns1/bar.test.db
|
|
||||||
@@ -0,0 +1,5 @@
|
|
||||||
+$TTL 300
|
|
||||||
+bar.test. IN SOA ns.bar.test. hostmaster.bar.test. 1 600 600 1200 600
|
|
||||||
+bar.test. NS ns.bar.test.
|
|
||||||
+ns A 10.53.0.1
|
|
||||||
+a A 10.0.0.1
|
|
||||||
diff --git a/bin/tests/system/cname_dname_negcache/ns1/named.conf.j2 b/bin/tests/system/cname_dname_negcache/ns1/named.conf.j2
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..d72dd1181d
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/cname_dname_negcache/ns1/named.conf.j2
|
|
||||||
@@ -0,0 +1,24 @@
|
|
||||||
+options {
|
|
||||||
+ query-source address @ns.ip@;
|
|
||||||
+ port @PORT@;
|
|
||||||
+ pid-file "named.pid";
|
|
||||||
+ listen-on { @ns.ip@; };
|
|
||||||
+ listen-on-v6 { none; };
|
|
||||||
+ recursion no;
|
|
||||||
+ dnssec-validation no;
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "." {
|
|
||||||
+ type primary;
|
|
||||||
+ file "root.db";
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "test." {
|
|
||||||
+ type primary;
|
|
||||||
+ file "test.db";
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "bar.test." {
|
|
||||||
+ type primary;
|
|
||||||
+ file "bar.test.db";
|
|
||||||
+};
|
|
||||||
diff --git a/bin/tests/system/cname_dname_negcache/ns1/root.db b/bin/tests/system/cname_dname_negcache/ns1/root.db
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..c456c45b9d
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/cname_dname_negcache/ns1/root.db
|
|
||||||
@@ -0,0 +1,6 @@
|
|
||||||
+$TTL 300
|
|
||||||
+. IN SOA ns. hostmaster. 1 600 600 1200 600
|
|
||||||
+. NS a.root-servers.nil.
|
|
||||||
+a.root-servers.nil. A 10.53.0.1
|
|
||||||
+test NS ns.test
|
|
||||||
+ns.test A 10.53.0.1
|
|
||||||
diff --git a/bin/tests/system/cname_dname_negcache/ns1/test.db b/bin/tests/system/cname_dname_negcache/ns1/test.db
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..acb68e00f8
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/cname_dname_negcache/ns1/test.db
|
|
||||||
@@ -0,0 +1,8 @@
|
|
||||||
+$TTL 300
|
|
||||||
+test. IN SOA ns.test. hostmaster.test. 1 600 600 1200 600
|
|
||||||
+test. NS ns.test.
|
|
||||||
+ns A 10.53.0.1
|
|
||||||
+bar NS ns.bar
|
|
||||||
+ns.bar A 10.53.0.1
|
|
||||||
+foo NS ns.foo
|
|
||||||
+ns.foo A 10.53.0.2
|
|
||||||
diff --git a/bin/tests/system/cname_dname_negcache/ns3/named.conf.j2 b/bin/tests/system/cname_dname_negcache/ns3/named.conf.j2
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..197d72756b
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/cname_dname_negcache/ns3/named.conf.j2
|
|
||||||
@@ -0,0 +1,11 @@
|
|
||||||
+options {
|
|
||||||
+ query-source address @ns.ip@;
|
|
||||||
+ port @PORT@;
|
|
||||||
+ pid-file "named.pid";
|
|
||||||
+ listen-on { @ns.ip@; };
|
|
||||||
+ listen-on-v6 { none; };
|
|
||||||
+ recursion yes;
|
|
||||||
+ dnssec-validation no;
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+{% include "_common/root.hint.conf" %}
|
|
||||||
diff --git a/bin/tests/system/cname_dname_negcache/tests_cname_negcache.py b/bin/tests/system/cname_dname_negcache/tests_cname_negcache.py
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..a546d29109
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/cname_dname_negcache/tests_cname_negcache.py
|
|
||||||
@@ -0,0 +1,16 @@
|
|
||||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+#
|
|
||||||
+# SPDX-License-Identifier: MPL-2.0
|
|
||||||
+#
|
|
||||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+#
|
|
||||||
+# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+# information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+from cname_dname_negcache.common import run_attack
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def test_cname_negcache(ns3):
|
|
||||||
+ run_attack(ns3, "cname.foo.test.", "CNAME", "cname.foo.test.", "A")
|
|
||||||
diff --git a/bin/tests/system/cname_dname_negcache/tests_dname_negcache.py b/bin/tests/system/cname_dname_negcache/tests_dname_negcache.py
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..41a80b4e05
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/cname_dname_negcache/tests_dname_negcache.py
|
|
||||||
@@ -0,0 +1,16 @@
|
|
||||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+#
|
|
||||||
+# SPDX-License-Identifier: MPL-2.0
|
|
||||||
+#
|
|
||||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+#
|
|
||||||
+# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+# information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+from cname_dname_negcache.common import run_attack
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def test_dname_negcache(ns3):
|
|
||||||
+ run_attack(ns3, "foo.test.", "DNAME", "a.foo.test.", "A")
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,280 +0,0 @@
|
||||||
From 3138886f3767c0a6b933fd147c5465472209bac6 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Colin Vidal <colin@isc.org>
|
|
||||||
Date: Thu, 18 Jun 2026 18:17:05 +0200
|
|
||||||
Subject: [PATCH] Do not assert in some CNAME/DNAME queries
|
|
||||||
|
|
||||||
Fix a `named` crash because of a fail assertion for certains types of
|
|
||||||
CNAME and DNAME queries:
|
|
||||||
|
|
||||||
- If a client queries for a DNAME and A record to the resolver, and the
|
|
||||||
authoritative server responds positively to the A query but delay the
|
|
||||||
DNAME response and respond later negatively;
|
|
||||||
|
|
||||||
- If a client queries for a CNAME and A record to the resolver, and the
|
|
||||||
authoritative server responds positively to the A query but delay the
|
|
||||||
CNAME response and respond later with a self-referential CNAME.
|
|
||||||
|
|
||||||
The first scenario consists of sending two queries: `foo.test./DNAME`
|
|
||||||
and `a.foo.test./A`. The authoritative server delays the answer for
|
|
||||||
`foo.test./DNAME` but immediately answers the DNAME record for the
|
|
||||||
second query: `foo.test. DNAME bar.test.`. The resolver caches it,
|
|
||||||
follows the DNAME, and resolves `a.bar.test./A`. The authoritative
|
|
||||||
server eventually answers negatively for `foo.test./DNAME`
|
|
||||||
(NOERROR/NODATA, with only an SOA in the authority section). The
|
|
||||||
resolver pulls out the previously cached rdataset (because it has a
|
|
||||||
higher trust level than the received negative answer), and wrongly (this
|
|
||||||
is the first bug) sets the result to `DNS_R_DNAME` instead of
|
|
||||||
`ISC_R_SUCCESS`. The code in `ns/query.c` that handles the resolver
|
|
||||||
result interprets this as "this is a non-DNAME query and we got a DNAME
|
|
||||||
rdataset, so follow the chain". It goes into the `query_dname()`
|
|
||||||
function, which asserts that the qname is a subdomain of the owner name
|
|
||||||
in the rdataset. That assertion fails because the qname (`foo.test.`) is
|
|
||||||
exactly equal to the owner name of the DNAME (`foo.test.`), rather than
|
|
||||||
being a subdomain of it. `DNS_R_DNAME` must only be set when the qtype
|
|
||||||
is something other than DNAME and the resolver has obtained a DNAME that
|
|
||||||
needs to be followed.
|
|
||||||
|
|
||||||
The second scenario consists of sending two queries:
|
|
||||||
`cname.foo.test./CNAME` and `cname.foo.test./A`. The authoritative
|
|
||||||
server delays the answer for `cname.foo.test./CNAME` but immediately
|
|
||||||
answers the CNAME record for the second query: `cname.foo.test. CNAME
|
|
||||||
cname.foo.test.`. Note that the CNAME is self-referential. The resolver
|
|
||||||
caches it and sets the result code to `DNS_R_CNAME`. Then `ns/query.c`
|
|
||||||
interprets this as "this is a non-CNAME query and we got a CNAME
|
|
||||||
rdataset, so follow the chain" (which is correct in this case; however,
|
|
||||||
because the CNAME rdataset is self-referential, the resolver responds
|
|
||||||
with SERVFAIL, which is expected). The authoritative server eventually
|
|
||||||
answers negatively for `cname.foo.test./CNAME`. The resolver then pulls
|
|
||||||
out the previously cached CNAME rdataset (obtained from the A answer,
|
|
||||||
even though it was self-referential, the resolver cached it) and wrongly
|
|
||||||
sets the result to `DNS_R_CNAME` (this is the second bug). As noted
|
|
||||||
above, `ns/query.c` interprets this as "this is a non-CNAME query and we
|
|
||||||
got a CNAME rdataset, so follow the chain". The internals here are
|
|
||||||
slightly more subtle: it first goes into `query_cname()` and sets the
|
|
||||||
CNAME rdataset in the message answer section, then restarts the query to
|
|
||||||
follow the CNAME. The restart retrieves the CNAME rdataset from the
|
|
||||||
cache directly (without going to the resolver), and this time the query
|
|
||||||
context result is `ISC_R_SUCCESS` (since it was found) and
|
|
||||||
`qctx->rdataset` points to the same CNAME again (as it is
|
|
||||||
self-referential), so it goes directly into the
|
|
||||||
`query_prepresponse()/query_respond()` flow, which attempts to add the
|
|
||||||
rdataset to the message answer again. However, this fails because the
|
|
||||||
rdataset is already in the message, and the assertion which expects that
|
|
||||||
operation to succeed fails (due to `qctx->rdataset` being set to `NULL`
|
|
||||||
when ownership of the rdataset was transferred). `DNS_R_CNAME` must only
|
|
||||||
be set when the qtype is something other than CNAME and the resolver has
|
|
||||||
obtained a CNAME that needs to be followed.
|
|
||||||
|
|
||||||
In both cases, the correct answer from the resolver should have been
|
|
||||||
`ISC_R_SUCCESS` (instead of respectively `DNS_R_DNAME` and
|
|
||||||
`DNS_R_CNAME`) becuase the rdataset that has been looked up was found.
|
|
||||||
|
|
||||||
(cherry picked from commit 773d46d58c693047a5945c8fe40512edd0ac214e)
|
|
||||||
(cherry picked from commit c740c37689f234e21a9b0ef760471ef2cf1133f5)
|
|
||||||
---
|
|
||||||
lib/dns/resolver.c | 137 ++++++++++++++++++++-------------------------
|
|
||||||
1 file changed, 60 insertions(+), 77 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
|
||||||
index edc9c207e1..1f8b5058d1 100644
|
|
||||||
--- a/lib/dns/resolver.c
|
|
||||||
+++ b/lib/dns/resolver.c
|
|
||||||
@@ -692,10 +692,10 @@ fctx_destroy(fetchctx_t *fctx, bool exiting);
|
|
||||||
static void
|
|
||||||
send_shutdown_events(dns_resolver_t *res);
|
|
||||||
static isc_result_t
|
|
||||||
-ncache_adderesult(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
|
||||||
- dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t minttl,
|
|
||||||
- dns_ttl_t maxttl, bool optout, bool secure,
|
|
||||||
- dns_rdataset_t *ardataset, isc_result_t *eresultp);
|
|
||||||
+ncache_adderesult(fetchctx_t *fctx, dns_message_t *message, dns_dbnode_t *node,
|
|
||||||
+ dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t maxttl,
|
|
||||||
+ bool optout, bool secure, dns_rdataset_t *ardataset,
|
|
||||||
+ isc_result_t *eresultp);
|
|
||||||
static void
|
|
||||||
validated(isc_task_t *task, isc_event_t *event);
|
|
||||||
static void
|
|
||||||
@@ -5563,6 +5563,46 @@ has_000_label(dns_rdataset_t *nsecset) {
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
+/*
|
|
||||||
+ * After a (non-error) negative-cache add, 'rdataset' is bound to whatever
|
|
||||||
+ * rdataset the cache authoritatively holds for the queried name and type.
|
|
||||||
+ * Map that to the result code the fetch should report:
|
|
||||||
+ *
|
|
||||||
+ * - A negative cache entry (the one we just added, or a pre-existing one):
|
|
||||||
+ * DNS_R_NCACHENXDOMAIN or DNS_R_NCACHENXRRSET, depending on NXDOMAIN vs
|
|
||||||
+ * NODATA.
|
|
||||||
+ *
|
|
||||||
+ * - A positive rdataset that was already cached at higher trust, which
|
|
||||||
+ * caused our negative entry to be discarded (e.g. a CNAME or DNAME cached
|
|
||||||
+ * by a concurrent query): ISC_R_SUCCESS, because that cached positive
|
|
||||||
+ * answer is what gets returned. Note the specific case for CNAME and
|
|
||||||
+ * DNAME *if* the query type is not the same as the rdataset type. There
|
|
||||||
+ * is a chain to follow *only* if the query type doesn't ask for the CNAME
|
|
||||||
+ * or the DNAME.
|
|
||||||
+ */
|
|
||||||
+static isc_result_t
|
|
||||||
+fctx_setresult(fetchctx_t *fctx, dns_rdataset_t *rdataset) {
|
|
||||||
+ isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
+
|
|
||||||
+ if (NEGATIVE(rdataset)) {
|
|
||||||
+ result = NXDOMAIN(rdataset) ? DNS_R_NCACHENXDOMAIN
|
|
||||||
+ : DNS_R_NCACHENXRRSET;
|
|
||||||
+ } else if (result == ISC_R_SUCCESS && rdataset->type != fctx->type) {
|
|
||||||
+ switch (rdataset->type) {
|
|
||||||
+ case dns_rdatatype_cname:
|
|
||||||
+ result = DNS_R_CNAME;
|
|
||||||
+ break;
|
|
||||||
+ case dns_rdatatype_dname:
|
|
||||||
+ result = DNS_R_DNAME;
|
|
||||||
+ break;
|
|
||||||
+ default:
|
|
||||||
+ break;
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ return result;
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
/*
|
|
||||||
* The validator has finished.
|
|
||||||
*/
|
|
||||||
@@ -5836,8 +5876,7 @@ validated(isc_task_t *task, isc_event_t *event) {
|
|
||||||
ttl = 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
- result = ncache_adderesult(message, fctx->cache, node, covers,
|
|
||||||
- now, fctx->res->view->minncachettl,
|
|
||||||
+ result = ncache_adderesult(fctx, message, node, covers, now,
|
|
||||||
ttl, vevent->optout, vevent->secure,
|
|
||||||
ardataset, &eresult);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
@@ -6081,23 +6120,7 @@ answer_response:
|
|
||||||
*/
|
|
||||||
INSIST(hevent->rdataset != NULL);
|
|
||||||
if (dns_rdataset_isassociated(hevent->rdataset)) {
|
|
||||||
- if (NEGATIVE(hevent->rdataset)) {
|
|
||||||
- INSIST(eresult == DNS_R_NCACHENXDOMAIN ||
|
|
||||||
- eresult == DNS_R_NCACHENXRRSET);
|
|
||||||
- } else if (eresult == ISC_R_SUCCESS &&
|
|
||||||
- hevent->rdataset->type != fctx->type)
|
|
||||||
- {
|
|
||||||
- switch (hevent->rdataset->type) {
|
|
||||||
- case dns_rdatatype_cname:
|
|
||||||
- eresult = DNS_R_CNAME;
|
|
||||||
- break;
|
|
||||||
- case dns_rdatatype_dname:
|
|
||||||
- eresult = DNS_R_DNAME;
|
|
||||||
- break;
|
|
||||||
- default:
|
|
||||||
- break;
|
|
||||||
- }
|
|
||||||
- }
|
|
||||||
+ eresult = fctx_setresult(fctx, hevent->rdataset);
|
|
||||||
}
|
|
||||||
|
|
||||||
hevent->result = eresult;
|
|
||||||
@@ -6747,24 +6770,7 @@ cache_name(fetchctx_t *fctx, dns_name_t *name, dns_message_t *message,
|
|
||||||
* event->result.
|
|
||||||
*/
|
|
||||||
if (dns_rdataset_isassociated(event->rdataset)) {
|
|
||||||
- if (NEGATIVE(event->rdataset)) {
|
|
||||||
- INSIST(eresult ==
|
|
||||||
- DNS_R_NCACHENXDOMAIN ||
|
|
||||||
- eresult == DNS_R_NCACHENXRRSET);
|
|
||||||
- } else if (eresult == ISC_R_SUCCESS &&
|
|
||||||
- event->rdataset->type != fctx->type)
|
|
||||||
- {
|
|
||||||
- switch (event->rdataset->type) {
|
|
||||||
- case dns_rdatatype_cname:
|
|
||||||
- eresult = DNS_R_CNAME;
|
|
||||||
- break;
|
|
||||||
- case dns_rdatatype_dname:
|
|
||||||
- eresult = DNS_R_DNAME;
|
|
||||||
- break;
|
|
||||||
- default:
|
|
||||||
- break;
|
|
||||||
- }
|
|
||||||
- }
|
|
||||||
+ eresult = fctx_setresult(fctx, event->rdataset);
|
|
||||||
}
|
|
||||||
event->result = eresult;
|
|
||||||
if (adbp != NULL && *adbp != NULL) {
|
|
||||||
@@ -6833,12 +6839,14 @@ cache_message(fetchctx_t *fctx, dns_message_t *message,
|
|
||||||
* eresult.
|
|
||||||
*/
|
|
||||||
static isc_result_t
|
|
||||||
-ncache_adderesult(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
|
||||||
- dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t minttl,
|
|
||||||
- dns_ttl_t maxttl, bool optout, bool secure,
|
|
||||||
- dns_rdataset_t *ardataset, isc_result_t *eresultp) {
|
|
||||||
+ncache_adderesult(fetchctx_t *fctx, dns_message_t *message, dns_dbnode_t *node,
|
|
||||||
+ dns_rdatatype_t covers, isc_stdtime_t now, dns_ttl_t maxttl,
|
|
||||||
+ bool optout, bool secure, dns_rdataset_t *ardataset,
|
|
||||||
+ isc_result_t *eresultp) {
|
|
||||||
isc_result_t result;
|
|
||||||
dns_rdataset_t rdataset;
|
|
||||||
+ dns_db_t *cache = fctx->cache;
|
|
||||||
+ dns_ttl_t minttl = fctx->res->view->minncachettl;
|
|
||||||
|
|
||||||
if (ardataset == NULL) {
|
|
||||||
dns_rdataset_init(&rdataset);
|
|
||||||
@@ -6854,37 +6862,13 @@ ncache_adderesult(dns_message_t *message, dns_db_t *cache, dns_dbnode_t *node,
|
|
||||||
}
|
|
||||||
if (result == DNS_R_UNCHANGED || result == ISC_R_SUCCESS) {
|
|
||||||
/*
|
|
||||||
- * If the cache now contains a negative entry and we
|
|
||||||
- * care about whether it is DNS_R_NCACHENXDOMAIN or
|
|
||||||
- * DNS_R_NCACHENXRRSET then extract it.
|
|
||||||
+ * The cache settled successfully (DNS_R_UNCHANGED means our
|
|
||||||
+ * negative entry was discarded in favour of existing
|
|
||||||
+ * higher-trust data). Either way 'ardataset' is now bound to
|
|
||||||
+ * the rdataset the cache holds for this name and type; derive
|
|
||||||
+ * the result code from it.
|
|
||||||
*/
|
|
||||||
- if (NEGATIVE(ardataset)) {
|
|
||||||
- /*
|
|
||||||
- * The cache data is a negative cache entry.
|
|
||||||
- */
|
|
||||||
- if (NXDOMAIN(ardataset)) {
|
|
||||||
- *eresultp = DNS_R_NCACHENXDOMAIN;
|
|
||||||
- } else {
|
|
||||||
- *eresultp = DNS_R_NCACHENXRRSET;
|
|
||||||
- }
|
|
||||||
- } else {
|
|
||||||
- /*
|
|
||||||
- * The attempt to add a negative cache entry
|
|
||||||
- * was rejected. Set *eresultp to reflect
|
|
||||||
- * the type of the dataset being returned.
|
|
||||||
- */
|
|
||||||
- switch (ardataset->type) {
|
|
||||||
- case dns_rdatatype_cname:
|
|
||||||
- *eresultp = DNS_R_CNAME;
|
|
||||||
- break;
|
|
||||||
- case dns_rdatatype_dname:
|
|
||||||
- *eresultp = DNS_R_DNAME;
|
|
||||||
- break;
|
|
||||||
- default:
|
|
||||||
- *eresultp = ISC_R_SUCCESS;
|
|
||||||
- break;
|
|
||||||
- }
|
|
||||||
- }
|
|
||||||
+ *eresultp = fctx_setresult(fctx, ardataset);
|
|
||||||
result = ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
if (ardataset == &rdataset && dns_rdataset_isassociated(ardataset)) {
|
|
||||||
@@ -7029,8 +7013,7 @@ ncache_message(fetchctx_t *fctx, dns_message_t *message,
|
|
||||||
ttl = 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
- result = ncache_adderesult(message, fctx->cache, node, covers, now,
|
|
||||||
- fctx->res->view->minncachettl, ttl, false,
|
|
||||||
+ result = ncache_adderesult(fctx, message, node, covers, now, ttl, false,
|
|
||||||
false, ardataset, &eresult);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
goto unlock;
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,416 +0,0 @@
|
||||||
From 89e950d215e9922e5af6e3c69b9d6a8750346bb6 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Alessio Podda <alessio@isc.org>
|
|
||||||
Date: Fri, 12 Jun 2026 11:16:01 +0200
|
|
||||||
Subject: [PATCH] Reproducer for #5985 addnoqname mismatch
|
|
||||||
|
|
||||||
LLM generated.
|
|
||||||
|
|
||||||
(cherry picked from commit 5f4de929b3e4749b6e32c51660be11c47c2514e6)
|
|
||||||
(cherry picked from commit 0cf010c153518f1f9831e201891ecba8d8ba65e1)
|
|
||||||
|
|
||||||
Update reproducer #5985
|
|
||||||
|
|
||||||
Update the llm generated reproducer:
|
|
||||||
- Move server.py into ans/ans1.py
|
|
||||||
- Remove unncessary named.conf configuration options
|
|
||||||
- Add comments describing the steps
|
|
||||||
- Rename system test
|
|
||||||
|
|
||||||
(cherry picked from commit fd539807829dd7d2eb76c8b503083f5d84fec6f0)
|
|
||||||
(cherry picked from commit 6c0e599ea85c0c53a4af09742e64e193da089bb4)
|
|
||||||
---
|
|
||||||
.../dnssec_findnoqname_mismatch/ans1/ans.py | 207 ++++++++++++++++++
|
|
||||||
.../ns2/named.conf.j2 | 33 +++
|
|
||||||
.../tests_findnoqname_mismatch.py | 126 +++++++++++
|
|
||||||
3 files changed, 366 insertions(+)
|
|
||||||
create mode 100644 bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py
|
|
||||||
create mode 100644 bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2
|
|
||||||
create mode 100644 bin/tests/system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py b/bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..b36fc831c8
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_findnoqname_mismatch/ans1/ans.py
|
|
||||||
@@ -0,0 +1,207 @@
|
|
||||||
+#!/usr/bin/python3
|
|
||||||
+
|
|
||||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+#
|
|
||||||
+# SPDX-License-Identifier: MPL-2.0
|
|
||||||
+
|
|
||||||
+from collections.abc import AsyncGenerator
|
|
||||||
+from dataclasses import dataclass
|
|
||||||
+from datetime import datetime, timedelta, timezone
|
|
||||||
+from pathlib import Path
|
|
||||||
+
|
|
||||||
+import base64
|
|
||||||
+import json
|
|
||||||
+
|
|
||||||
+from cryptography.hazmat.primitives import serialization
|
|
||||||
+
|
|
||||||
+import dns.dnssec
|
|
||||||
+import dns.flags
|
|
||||||
+import dns.message
|
|
||||||
+import dns.name
|
|
||||||
+import dns.rdata
|
|
||||||
+import dns.rdataclass
|
|
||||||
+import dns.rcode
|
|
||||||
+import dns.rdatatype
|
|
||||||
+import dns.rrset
|
|
||||||
+
|
|
||||||
+from isctest.asyncserver import (
|
|
||||||
+ AsyncDnsServer,
|
|
||||||
+ DnsResponseSend,
|
|
||||||
+ QueryContext,
|
|
||||||
+ ResponseHandler,
|
|
||||||
+)
|
|
||||||
+
|
|
||||||
+TTL = 300
|
|
||||||
+ZONE = "f217.test."
|
|
||||||
+CHILD = f"evil.{ZONE}"
|
|
||||||
+ATTACK = f"www.{CHILD}"
|
|
||||||
+NSEC_OWNER = f"00000000.{CHILD}"
|
|
||||||
+NSEC_NEXT = f"zzz.{CHILD}"
|
|
||||||
+FORGED_A = "192.0.2.217"
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+@dataclass(frozen=True)
|
|
||||||
+class Key:
|
|
||||||
+ zone: dns.name.Name
|
|
||||||
+ private_key: object
|
|
||||||
+ dnskey: dns.rdata.Rdata
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def name(text: str) -> dns.name.Name:
|
|
||||||
+ return dns.name.from_text(text)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def load_key() -> Key:
|
|
||||||
+ path = Path(__file__).resolve().parent / "keys.json"
|
|
||||||
+ with path.open(encoding="utf-8") as keys_file:
|
|
||||||
+ raw_key = json.load(keys_file)[ZONE]
|
|
||||||
+
|
|
||||||
+ private_key = serialization.load_pem_private_key(
|
|
||||||
+ raw_key["private_pem"].encode("ascii"),
|
|
||||||
+ password=None,
|
|
||||||
+ )
|
|
||||||
+ dnskey = dns.rdata.from_text(
|
|
||||||
+ dns.rdataclass.IN, dns.rdatatype.DNSKEY, raw_key["dnskey"]
|
|
||||||
+ )
|
|
||||||
+ return Key(name(ZONE), private_key, dnskey)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def rrset(owner: str, rdtype: dns.rdatatype.RdataType, *rdatas: str) -> dns.rrset.RRset:
|
|
||||||
+ return dns.rrset.from_text(owner, TTL, dns.rdataclass.IN, rdtype, *rdatas)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def rrset_from_rdata(owner: str, rdata: dns.rdata.Rdata) -> dns.rrset.RRset:
|
|
||||||
+ return dns.rrset.from_rdata(name(owner), TTL, rdata)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def add_signed(
|
|
||||||
+ section: list[dns.rrset.RRset], covered: dns.rrset.RRset, signer: Key
|
|
||||||
+) -> None:
|
|
||||||
+ rrsig = dns.dnssec.sign(
|
|
||||||
+ covered,
|
|
||||||
+ signer.private_key,
|
|
||||||
+ signer.zone,
|
|
||||||
+ signer.dnskey,
|
|
||||||
+ lifetime=86400,
|
|
||||||
+ verify=True,
|
|
||||||
+ )
|
|
||||||
+ section.append(covered)
|
|
||||||
+ section.append(dns.rrset.from_rdata(covered.name, covered.ttl, rrsig))
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def soa_rrset(zone: str) -> dns.rrset.RRset:
|
|
||||||
+ return rrset(
|
|
||||||
+ zone,
|
|
||||||
+ dns.rdatatype.SOA,
|
|
||||||
+ f"ns.{ZONE} hostmaster.{ZONE} 1 7200 3600 1209600 300",
|
|
||||||
+ )
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def garbage_rrsig(
|
|
||||||
+ owner: str, covered: dns.rdatatype.RdataType, labels: int, signer: str
|
|
||||||
+) -> dns.rrset.RRset:
|
|
||||||
+ now = datetime.now(timezone.utc)
|
|
||||||
+ inception = (now - timedelta(hours=1)).strftime("%Y%m%d%H%M%S")
|
|
||||||
+ expiration = (now + timedelta(days=1)).strftime("%Y%m%d%H%M%S")
|
|
||||||
+ signature = base64.b64encode(bytes(64)).decode("ascii")
|
|
||||||
+ text = (
|
|
||||||
+ f"{dns.rdatatype.to_text(covered)} 13 {labels} {TTL} "
|
|
||||||
+ f"{expiration} {inception} 12345 {signer} {signature}"
|
|
||||||
+ )
|
|
||||||
+ rdata = dns.rdata.from_text(dns.rdataclass.IN, dns.rdatatype.RRSIG, text)
|
|
||||||
+ return dns.rrset.from_rdata(name(owner), TTL, rdata)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def add_ds_denial(response: dns.message.Message, key: Key) -> None:
|
|
||||||
+ add_signed(response.authority, soa_rrset(ZONE), key)
|
|
||||||
+ nsec = rrset(CHILD, dns.rdatatype.NSEC, f"ns.{ZONE} NS RRSIG NSEC")
|
|
||||||
+ add_signed(response.authority, nsec, key)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def add_attack_answer(response: dns.message.Message) -> None:
|
|
||||||
+ """
|
|
||||||
+ Crafted authoritative response to <q>.evil.f217.hack./A
|
|
||||||
+
|
|
||||||
+ ;; ANSWER
|
|
||||||
+ <q>.evil.f217.hack. 300 IN A 192.0.2.217
|
|
||||||
+ <q>.evil.f217.hack. 300 IN RRSIG A 13 1 300 <exp> <inc> 12345 evil.f217.hack. <base64 of 64×0x00>
|
|
||||||
+ ^^^ Labels = 1, qname has 4 labels, wildcard heuristic fires
|
|
||||||
+
|
|
||||||
+ ;; AUTHORITY (single owner, three rdatasets in this wire order)
|
|
||||||
+ 00000000.evil.f217.hack. 300 IN NSEC zzz.evil.f217.hack. A RRSIG NSEC
|
|
||||||
+ 00000000.evil.f217.hack. 300 IN RRSIG NSEC 13 4 300 <exp> <inc> 12345 evil.f217.hack. <base64 of 64×0x00>
|
|
||||||
+ 00000000.evil.f217.hack. 300 IN NSEC3 1 0 0 - VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV A RRSIG
|
|
||||||
+ """
|
|
||||||
+ # A + RRSIG
|
|
||||||
+ response.answer.append(rrset(ATTACK, dns.rdatatype.A, FORGED_A))
|
|
||||||
+ response.answer.append(garbage_rrsig(ATTACK, dns.rdatatype.A, 1, CHILD))
|
|
||||||
+ # NSEC
|
|
||||||
+ nsec = rrset(
|
|
||||||
+ NSEC_OWNER,
|
|
||||||
+ dns.rdatatype.NSEC,
|
|
||||||
+ f"{NSEC_NEXT} A RRSIG NSEC",
|
|
||||||
+ )
|
|
||||||
+ response.authority.append(nsec)
|
|
||||||
+ # RRSIG(NSEC)
|
|
||||||
+ response.authority.append(
|
|
||||||
+ garbage_rrsig(
|
|
||||||
+ NSEC_OWNER,
|
|
||||||
+ dns.rdatatype.NSEC,
|
|
||||||
+ len(name(NSEC_OWNER).labels) - 1,
|
|
||||||
+ CHILD,
|
|
||||||
+ )
|
|
||||||
+ )
|
|
||||||
+ # NSEC3
|
|
||||||
+ nsec3 = rrset(
|
|
||||||
+ NSEC_OWNER,
|
|
||||||
+ dns.rdatatype.NSEC3,
|
|
||||||
+ "1 0 0 - VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV A RRSIG",
|
|
||||||
+ )
|
|
||||||
+ response.authority.append(nsec3)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+class RuntimeCheckHandler(ResponseHandler):
|
|
||||||
+ def __init__(self, key: Key) -> None:
|
|
||||||
+ self.key = key
|
|
||||||
+ self.zone = name(ZONE)
|
|
||||||
+ self.child = name(CHILD)
|
|
||||||
+ self.attack = name(ATTACK)
|
|
||||||
+
|
|
||||||
+ def match(self, qctx: QueryContext) -> bool:
|
|
||||||
+ return qctx.qname.is_subdomain(self.zone)
|
|
||||||
+
|
|
||||||
+ async def get_responses(
|
|
||||||
+ self, qctx: QueryContext
|
|
||||||
+ ) -> AsyncGenerator[DnsResponseSend, None]:
|
|
||||||
+ qctx.prepare_new_response(with_zone_data=False)
|
|
||||||
+ qctx.response.flags |= dns.flags.AA
|
|
||||||
+ qctx.response.set_rcode(dns.rcode.NOERROR)
|
|
||||||
+
|
|
||||||
+ if qctx.qname == self.zone and qctx.qtype == dns.rdatatype.DNSKEY:
|
|
||||||
+ add_signed(
|
|
||||||
+ qctx.response.answer,
|
|
||||||
+ rrset_from_rdata(ZONE, self.key.dnskey),
|
|
||||||
+ self.key,
|
|
||||||
+ )
|
|
||||||
+ elif qctx.qname == self.zone and qctx.qtype == dns.rdatatype.SOA:
|
|
||||||
+ add_signed(qctx.response.answer, soa_rrset(ZONE), self.key)
|
|
||||||
+ elif qctx.qname == self.child and qctx.qtype == dns.rdatatype.DS:
|
|
||||||
+ add_ds_denial(qctx.response, self.key)
|
|
||||||
+ elif qctx.qname == self.child and qctx.qtype == dns.rdatatype.DNSKEY:
|
|
||||||
+ qctx.response.authority.append(soa_rrset(CHILD))
|
|
||||||
+ elif qctx.qname == self.attack and qctx.qtype == dns.rdatatype.A:
|
|
||||||
+ add_attack_answer(qctx.response)
|
|
||||||
+ else:
|
|
||||||
+ add_signed(qctx.response.authority, soa_rrset(ZONE), self.key)
|
|
||||||
+
|
|
||||||
+ yield DnsResponseSend(qctx.response, authoritative=True)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def main() -> None:
|
|
||||||
+ server = AsyncDnsServer(default_aa=True)
|
|
||||||
+ server.install_response_handlers(RuntimeCheckHandler(load_key()))
|
|
||||||
+ server.run()
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+if __name__ == "__main__":
|
|
||||||
+ main()
|
|
||||||
diff --git a/bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2 b/bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..f4fbd8a617
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_findnoqname_mismatch/ns2/named.conf.j2
|
|
||||||
@@ -0,0 +1,33 @@
|
|
||||||
+// validating resolver
|
|
||||||
+
|
|
||||||
+options {
|
|
||||||
+ query-source address 10.53.0.2;
|
|
||||||
+ notify-source 10.53.0.2;
|
|
||||||
+ transfer-source 10.53.0.2;
|
|
||||||
+ port @PORT@;
|
|
||||||
+ pid-file "named.pid";
|
|
||||||
+ listen-on { 10.53.0.2; };
|
|
||||||
+ listen-on-v6 { none; };
|
|
||||||
+ recursion yes;
|
|
||||||
+ dnssec-validation yes;
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+controls {
|
|
||||||
+ inet 10.53.0.2 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+include "../../_common/rndc.key";
|
|
||||||
+
|
|
||||||
+zone "." {
|
|
||||||
+ type hint;
|
|
||||||
+ file "../../_common/root.hint";
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "f217.test" {
|
|
||||||
+ type static-stub;
|
|
||||||
+ server-addresses { 10.53.0.1; };
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+trust-anchors {
|
|
||||||
+ f217.test. static-key 257 3 13 "@ZONE_DNSKEY@";
|
|
||||||
+};
|
|
||||||
diff --git a/bin/tests/system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py b/bin/tests/system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..f3e332a360
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_findnoqname_mismatch/tests_findnoqname_mismatch.py
|
|
||||||
@@ -0,0 +1,126 @@
|
|
||||||
+#!/usr/bin/python3
|
|
||||||
+
|
|
||||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+#
|
|
||||||
+# SPDX-License-Identifier: MPL-2.0
|
|
||||||
+
|
|
||||||
+from pathlib import Path
|
|
||||||
+
|
|
||||||
+import json
|
|
||||||
+
|
|
||||||
+from cryptography.hazmat.primitives import serialization
|
|
||||||
+from cryptography.hazmat.primitives.asymmetric import ec
|
|
||||||
+
|
|
||||||
+import dns.dnssec
|
|
||||||
+import dns.name
|
|
||||||
+import dns.rdataclass
|
|
||||||
+import dns.rdatatype
|
|
||||||
+import pytest
|
|
||||||
+
|
|
||||||
+import isctest
|
|
||||||
+import isctest.mark
|
|
||||||
+
|
|
||||||
+ZONE = "f217.test."
|
|
||||||
+CHILD = f"evil.{ZONE}"
|
|
||||||
+ATTACK = f"www.{CHILD}"
|
|
||||||
+NSEC_OWNER = f"00000000.{CHILD}"
|
|
||||||
+FORGED_A = "192.0.2.217"
|
|
||||||
+AUTH = "10.53.0.1"
|
|
||||||
+RESOLVER = "10.53.0.2"
|
|
||||||
+
|
|
||||||
+pytestmark = [
|
|
||||||
+ isctest.mark.with_ecdsa_deterministic,
|
|
||||||
+ pytest.mark.extra_artifacts(
|
|
||||||
+ [
|
|
||||||
+ "ans1/ans.run",
|
|
||||||
+ "ans1/keys.json",
|
|
||||||
+ ]
|
|
||||||
+ ),
|
|
||||||
+]
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def _make_key():
|
|
||||||
+ private_key = ec.generate_private_key(ec.SECP256R1())
|
|
||||||
+ dnskey = dns.dnssec.make_dnskey(
|
|
||||||
+ private_key.public_key(),
|
|
||||||
+ algorithm="ECDSAP256SHA256",
|
|
||||||
+ flags=257,
|
|
||||||
+ )
|
|
||||||
+ private_pem = private_key.private_bytes(
|
|
||||||
+ encoding=serialization.Encoding.PEM,
|
|
||||||
+ format=serialization.PrivateFormat.PKCS8,
|
|
||||||
+ encryption_algorithm=serialization.NoEncryption(),
|
|
||||||
+ ).decode("ascii")
|
|
||||||
+ return {
|
|
||||||
+ "private_pem": private_pem,
|
|
||||||
+ "dnskey": dnskey.to_text(),
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def bootstrap():
|
|
||||||
+ keys = {ZONE: _make_key()}
|
|
||||||
+ Path("ans1/keys.json").write_text(json.dumps(keys, indent=2), encoding="ascii")
|
|
||||||
+ zone_dnskey = "".join(keys[ZONE]["dnskey"].split()[3:])
|
|
||||||
+ return {"ZONE_DNSKEY": zone_dnskey}
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def _query(server, qname, qtype):
|
|
||||||
+ query = isctest.query.create(qname, qtype)
|
|
||||||
+ return isctest.query.tcp(query, server, attempts=1, timeout=5)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def _rrset(response, section, owner, rdtype, covers=None):
|
|
||||||
+ if covers is None:
|
|
||||||
+ return response.get_rrset(
|
|
||||||
+ section, dns.name.from_text(owner), dns.rdataclass.IN, rdtype
|
|
||||||
+ )
|
|
||||||
+ return response.get_rrset(
|
|
||||||
+ section,
|
|
||||||
+ dns.name.from_text(owner),
|
|
||||||
+ dns.rdataclass.IN,
|
|
||||||
+ rdtype,
|
|
||||||
+ covers=covers,
|
|
||||||
+ )
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def _has_a(response, section, owner, address):
|
|
||||||
+ rrset = _rrset(response, section, owner, dns.rdatatype.A)
|
|
||||||
+ return rrset is not None and any(rdata.address == address for rdata in rrset)
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def _check_rrsig(response, section, owner, rdtype, signer, labels=None):
|
|
||||||
+ rrsig = _rrset(response, section, owner, dns.rdatatype.RRSIG, covers=rdtype)
|
|
||||||
+ assert rrsig is not None, response.to_text()
|
|
||||||
+ assert rrsig[0].signer == dns.name.from_text(signer), response.to_text()
|
|
||||||
+ if labels is not None:
|
|
||||||
+ assert rrsig[0].labels == labels, response.to_text()
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def test_malicious_findnoqname_addnoqname_mismatch():
|
|
||||||
+ response = _query(AUTH, ATTACK, "A")
|
|
||||||
+ isctest.check.noerror(response)
|
|
||||||
+ assert _has_a(response, response.answer, ATTACK, FORGED_A), response.to_text()
|
|
||||||
+ _check_rrsig(response, response.answer, ATTACK, dns.rdatatype.A, CHILD, labels=1)
|
|
||||||
+
|
|
||||||
+ # Has NSEC
|
|
||||||
+ assert _rrset(response, response.authority, NSEC_OWNER, dns.rdatatype.NSEC)
|
|
||||||
+ _check_rrsig(response, response.authority, NSEC_OWNER, dns.rdatatype.NSEC, CHILD)
|
|
||||||
+ # Has NSEC3
|
|
||||||
+ assert _rrset(response, response.authority, NSEC_OWNER, dns.rdatatype.NSEC3)
|
|
||||||
+ assert (
|
|
||||||
+ _rrset(
|
|
||||||
+ response,
|
|
||||||
+ response.authority,
|
|
||||||
+ NSEC_OWNER,
|
|
||||||
+ dns.rdatatype.RRSIG,
|
|
||||||
+ covers=dns.rdatatype.NSEC3,
|
|
||||||
+ )
|
|
||||||
+ is None
|
|
||||||
+ )
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def test_resolver_findnoqname_addnoqname_mismatch():
|
|
||||||
+ # Send one trigger query
|
|
||||||
+ _query(RESOLVER, ATTACK, "A")
|
|
||||||
+ response = _query(RESOLVER, ZONE, "SOA")
|
|
||||||
+ isctest.check.noerror(response)
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,158 +0,0 @@
|
||||||
From 895cac04332d85489ddf881b28e18e9956f6e348 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Evan Hunt <each@isc.org>
|
|
||||||
Date: Wed, 13 May 2026 20:45:57 -0700
|
|
||||||
Subject: [PATCH] dns_rdataset_addnoqname() could find unsigned NSEC/NSEC3
|
|
||||||
|
|
||||||
The dns_rdatalist addnoqname() implementation searches for the first
|
|
||||||
NSEC or NSEC3 record in a message, then for the first RRSIG covering
|
|
||||||
that type in the same message. Previously, if no RRSIG for the type was
|
|
||||||
found, the function accepted the unsigned record. Now, it will instead
|
|
||||||
continue searching until an NSEC or NSEC3 that does have a matching
|
|
||||||
signature is found.
|
|
||||||
|
|
||||||
When this function is called from validated() in resolver.c, a
|
|
||||||
non-success return code is now treated as an error instead of triggering
|
|
||||||
an assertion failure.
|
|
||||||
|
|
||||||
Fixes: isc-projects/bind9#5985
|
|
||||||
(cherry picked from commit 57cba571ee31311e54d8a11cb38094d439f04e09)
|
|
||||||
(cherry picked from commit 48f5aa5fb3746d6194edcc57e8792a8b3cc3b454)
|
|
||||||
---
|
|
||||||
lib/dns/rbtdb.c | 10 +++++++---
|
|
||||||
lib/dns/rdatalist.c | 33 ++++++++++++++++-----------------
|
|
||||||
lib/dns/resolver.c | 4 +++-
|
|
||||||
lib/ns/query.c | 3 +--
|
|
||||||
4 files changed, 27 insertions(+), 23 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/rbtdb.c b/lib/dns/rbtdb.c
|
|
||||||
index 0b8547950f..c922df557b 100644
|
|
||||||
--- a/lib/dns/rbtdb.c
|
|
||||||
+++ b/lib/dns/rbtdb.c
|
|
||||||
@@ -6946,7 +6946,7 @@ delegating_type(dns_rbtdb_t *rbtdb, dns_rbtnode_t *node,
|
|
||||||
static isc_result_t
|
|
||||||
addnoqname(dns_rbtdb_t *rbtdb, rdatasetheader_t *newheader,
|
|
||||||
uint32_t maxrrperset, dns_rdataset_t *rdataset) {
|
|
||||||
- struct noqname *noqname;
|
|
||||||
+ struct noqname *noqname = NULL;
|
|
||||||
isc_mem_t *mctx = rbtdb->common.mctx;
|
|
||||||
dns_name_t name;
|
|
||||||
dns_rdataset_t neg, negsig;
|
|
||||||
@@ -6958,7 +6958,9 @@ addnoqname(dns_rbtdb_t *rbtdb, rdatasetheader_t *newheader,
|
|
||||||
dns_rdataset_init(&negsig);
|
|
||||||
|
|
||||||
result = dns_rdataset_getnoqname(rdataset, &name, &neg, &negsig);
|
|
||||||
- RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
|
||||||
+ if (result != ISC_R_SUCCESS) {
|
|
||||||
+ goto cleanup;
|
|
||||||
+ }
|
|
||||||
|
|
||||||
noqname = isc_mem_get(mctx, sizeof(*noqname));
|
|
||||||
dns_name_init(&noqname->name, NULL);
|
|
||||||
@@ -6984,7 +6986,9 @@ addnoqname(dns_rbtdb_t *rbtdb, rdatasetheader_t *newheader,
|
|
||||||
cleanup:
|
|
||||||
dns_rdataset_disassociate(&neg);
|
|
||||||
dns_rdataset_disassociate(&negsig);
|
|
||||||
- free_noqname(mctx, &noqname);
|
|
||||||
+ if (noqname != NULL) {
|
|
||||||
+ free_noqname(mctx, &noqname);
|
|
||||||
+ }
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
|
|
||||||
diff --git a/lib/dns/rdatalist.c b/lib/dns/rdatalist.c
|
|
||||||
index 98036f9cb3..2cca8d64be 100644
|
|
||||||
--- a/lib/dns/rdatalist.c
|
|
||||||
+++ b/lib/dns/rdatalist.c
|
|
||||||
@@ -192,6 +192,7 @@ isc__rdatalist_addnoqname(dns_rdataset_t *rdataset, const dns_name_t *name) {
|
|
||||||
dns_rdataset_t *neg = NULL;
|
|
||||||
dns_rdataset_t *negsig = NULL;
|
|
||||||
dns_rdataset_t *rdset;
|
|
||||||
+ dns_rdataset_t *sigset;
|
|
||||||
dns_ttl_t ttl;
|
|
||||||
|
|
||||||
REQUIRE(rdataset != NULL);
|
|
||||||
@@ -199,30 +200,27 @@ isc__rdatalist_addnoqname(dns_rdataset_t *rdataset, const dns_name_t *name) {
|
|
||||||
for (rdset = ISC_LIST_HEAD(name->list); rdset != NULL;
|
|
||||||
rdset = ISC_LIST_NEXT(rdset, link))
|
|
||||||
{
|
|
||||||
- if (rdset->rdclass != rdataset->rdclass) {
|
|
||||||
- continue;
|
|
||||||
- }
|
|
||||||
- if (rdset->type == dns_rdatatype_nsec ||
|
|
||||||
- rdset->type == dns_rdatatype_nsec3)
|
|
||||||
+ if (rdset->rdclass != rdataset->rdclass ||
|
|
||||||
+ (rdset->type != dns_rdatatype_nsec &&
|
|
||||||
+ rdset->type != dns_rdatatype_nsec3))
|
|
||||||
{
|
|
||||||
- neg = rdset;
|
|
||||||
+ continue;
|
|
||||||
}
|
|
||||||
- }
|
|
||||||
- if (neg == NULL) {
|
|
||||||
- return ISC_R_NOTFOUND;
|
|
||||||
- }
|
|
||||||
|
|
||||||
- for (rdset = ISC_LIST_HEAD(name->list); rdset != NULL;
|
|
||||||
- rdset = ISC_LIST_NEXT(rdset, link))
|
|
||||||
- {
|
|
||||||
- if (rdset->type == dns_rdatatype_rrsig &&
|
|
||||||
- rdset->covers == neg->type)
|
|
||||||
+ for (sigset = ISC_LIST_HEAD(name->list); sigset != NULL;
|
|
||||||
+ sigset = ISC_LIST_NEXT(sigset, link))
|
|
||||||
{
|
|
||||||
- negsig = rdset;
|
|
||||||
+ if (sigset->type == dns_rdatatype_rrsig &&
|
|
||||||
+ sigset->covers == rdset->type)
|
|
||||||
+ {
|
|
||||||
+ neg = rdset;
|
|
||||||
+ negsig = sigset;
|
|
||||||
+ break;
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
- if (negsig == NULL) {
|
|
||||||
+ if (neg == NULL || negsig == NULL) {
|
|
||||||
return ISC_R_NOTFOUND;
|
|
||||||
}
|
|
||||||
/*
|
|
||||||
@@ -238,6 +236,7 @@ isc__rdatalist_addnoqname(dns_rdataset_t *rdataset, const dns_name_t *name) {
|
|
||||||
rdataset->ttl = neg->ttl = negsig->ttl = ttl;
|
|
||||||
rdataset->attributes |= DNS_RDATASETATTR_NOQNAME;
|
|
||||||
rdataset->private6 = name;
|
|
||||||
+
|
|
||||||
return ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
|
|
||||||
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
|
||||||
index 1f8b5058d1..059ce53a9e 100644
|
|
||||||
--- a/lib/dns/resolver.c
|
|
||||||
+++ b/lib/dns/resolver.c
|
|
||||||
@@ -5893,7 +5893,9 @@ validated(isc_task_t *task, isc_event_t *event) {
|
|
||||||
result = dns_rdataset_addnoqname(
|
|
||||||
vevent->rdataset,
|
|
||||||
vevent->proofs[DNS_VALIDATOR_NOQNAMEPROOF]);
|
|
||||||
- RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
|
||||||
+ if (result != ISC_R_SUCCESS) {
|
|
||||||
+ goto noanswer_response;
|
|
||||||
+ }
|
|
||||||
INSIST(vevent->sigrdataset != NULL);
|
|
||||||
vevent->sigrdataset->ttl = vevent->rdataset->ttl;
|
|
||||||
if (vevent->proofs[DNS_VALIDATOR_CLOSESTENCLOSER] != NULL) {
|
|
||||||
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
|
||||||
index 3bd7daf79c..2a2ba1daba 100644
|
|
||||||
--- a/lib/ns/query.c
|
|
||||||
+++ b/lib/ns/query.c
|
|
||||||
@@ -7953,8 +7953,7 @@ query_addnoqnameproof(query_ctx_t *qctx) {
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
|
|
||||||
- result = dns_rdataset_getnoqname(qctx->noqname, fname, neg, negsig);
|
|
||||||
- RUNTIME_CHECK(result == ISC_R_SUCCESS);
|
|
||||||
+ CHECK(dns_rdataset_getnoqname(qctx->noqname, fname, neg, negsig));
|
|
||||||
|
|
||||||
query_addrrset(qctx, &fname, &neg, &negsig, dbuf,
|
|
||||||
DNS_SECTION_AUTHORITY);
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,445 +0,0 @@
|
||||||
From eaa35628f4a201049295a8944f4d28e8a1013199 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Ayd=C4=B1n=20Mercan?= <aydin@isc.org>
|
|
||||||
Date: Wed, 6 May 2026 16:54:57 +0300
|
|
||||||
Subject: [PATCH] Add system test for out-of-zone nsec dnssec bypass
|
|
||||||
|
|
||||||
A malicious zone with out-of-zone NSEC entries can get a DNSSEC
|
|
||||||
validating resolver's cache to cover the victim zone for non-existence
|
|
||||||
and prevent nameserver queries without DNSSEC failure.
|
|
||||||
|
|
||||||
Test for this case with an `evil.test` zone that tries to cover the
|
|
||||||
`victim.test` zone.
|
|
||||||
|
|
||||||
(cherry picked from commit 654f9773c0af59965c343bdfeb096b3dffe9dd53)
|
|
||||||
(cherry picked from commit c969ad2c17b43dd999e358bfeb280d3df6fab822)
|
|
||||||
---
|
|
||||||
.../system/dnssec_bypass/ns1/named.conf.j2 | 31 ++++
|
|
||||||
bin/tests/system/dnssec_bypass/ns1/root.db | 19 +++
|
|
||||||
bin/tests/system/dnssec_bypass/ns1/test.db | 23 +++
|
|
||||||
.../system/dnssec_bypass/ns2/named.conf.j2 | 26 +++
|
|
||||||
bin/tests/system/dnssec_bypass/ns2/victim.db | 18 +++
|
|
||||||
bin/tests/system/dnssec_bypass/ns3/evil.db | 23 +++
|
|
||||||
.../system/dnssec_bypass/ns3/named.conf.j2 | 26 +++
|
|
||||||
.../system/dnssec_bypass/ns4/named.conf.j2 | 35 ++++
|
|
||||||
.../system/dnssec_bypass/tests_bypass.py | 152 ++++++++++++++++++
|
|
||||||
9 files changed, 353 insertions(+)
|
|
||||||
create mode 100644 bin/tests/system/dnssec_bypass/ns1/named.conf.j2
|
|
||||||
create mode 100644 bin/tests/system/dnssec_bypass/ns1/root.db
|
|
||||||
create mode 100644 bin/tests/system/dnssec_bypass/ns1/test.db
|
|
||||||
create mode 100644 bin/tests/system/dnssec_bypass/ns2/named.conf.j2
|
|
||||||
create mode 100644 bin/tests/system/dnssec_bypass/ns2/victim.db
|
|
||||||
create mode 100644 bin/tests/system/dnssec_bypass/ns3/evil.db
|
|
||||||
create mode 100644 bin/tests/system/dnssec_bypass/ns3/named.conf.j2
|
|
||||||
create mode 100644 bin/tests/system/dnssec_bypass/ns4/named.conf.j2
|
|
||||||
create mode 100644 bin/tests/system/dnssec_bypass/tests_bypass.py
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/dnssec_bypass/ns1/named.conf.j2 b/bin/tests/system/dnssec_bypass/ns1/named.conf.j2
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..59ced1831a
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_bypass/ns1/named.conf.j2
|
|
||||||
@@ -0,0 +1,31 @@
|
|
||||||
+/*
|
|
||||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+ *
|
|
||||||
+ * SPDX-License-Identifier: MPL-2.0
|
|
||||||
+ *
|
|
||||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+ *
|
|
||||||
+ * See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+ * information regarding copyright ownership.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
+options {
|
|
||||||
+ port @PORT@;
|
|
||||||
+ pid-file "named.pid";
|
|
||||||
+ listen-on { 10.53.0.1; };
|
|
||||||
+ listen-on-v6 { none; };
|
|
||||||
+ recursion no;
|
|
||||||
+ dnssec-validation no;
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "test." {
|
|
||||||
+ type primary;
|
|
||||||
+ file "test.db.signed";
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "." {
|
|
||||||
+ type primary;
|
|
||||||
+ file "root.db.signed";
|
|
||||||
+};
|
|
||||||
diff --git a/bin/tests/system/dnssec_bypass/ns1/root.db b/bin/tests/system/dnssec_bypass/ns1/root.db
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..8d98a0456c
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_bypass/ns1/root.db
|
|
||||||
@@ -0,0 +1,19 @@
|
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+;
|
|
||||||
+; SPDX-License-Identifier: MPL-2.0
|
|
||||||
+;
|
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+;
|
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+; information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+$TTL 3600
|
|
||||||
+. IN SOA a.nil. a.nil. 1 3600 600 86400 300
|
|
||||||
+. IN NS a.root-servers.nil.
|
|
||||||
+
|
|
||||||
+a.root-servers.nil. IN A 10.53.0.1
|
|
||||||
+
|
|
||||||
+test. IN NS ns1.test.
|
|
||||||
+ns1.test. IN A 10.53.0.1
|
|
||||||
diff --git a/bin/tests/system/dnssec_bypass/ns1/test.db b/bin/tests/system/dnssec_bypass/ns1/test.db
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..6efcd95e42
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_bypass/ns1/test.db
|
|
||||||
@@ -0,0 +1,23 @@
|
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+;
|
|
||||||
+; SPDX-License-Identifier: MPL-2.0
|
|
||||||
+;
|
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+;
|
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+; information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+$ORIGIN test.
|
|
||||||
+$TTL 3600
|
|
||||||
+
|
|
||||||
+@ IN SOA a a 1 3600 600 86400 300
|
|
||||||
+ IN NS ns1.test.
|
|
||||||
+ns1 IN A 10.53.0.1
|
|
||||||
+
|
|
||||||
+evil IN NS ns1.evil
|
|
||||||
+ns1.evil IN A 10.53.0.3
|
|
||||||
+
|
|
||||||
+victim IN NS ns1.victim
|
|
||||||
+ns1.victim IN A 10.53.0.2
|
|
||||||
diff --git a/bin/tests/system/dnssec_bypass/ns2/named.conf.j2 b/bin/tests/system/dnssec_bypass/ns2/named.conf.j2
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..e81cee7cac
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_bypass/ns2/named.conf.j2
|
|
||||||
@@ -0,0 +1,26 @@
|
|
||||||
+/*
|
|
||||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+ *
|
|
||||||
+ * SPDX-License-Identifier: MPL-2.0
|
|
||||||
+ *
|
|
||||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+ *
|
|
||||||
+ * See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+ * information regarding copyright ownership.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
+options {
|
|
||||||
+ port @PORT@;
|
|
||||||
+ pid-file "named.pid";
|
|
||||||
+ listen-on { 10.53.0.2; };
|
|
||||||
+ listen-on-v6 { none; };
|
|
||||||
+ recursion no;
|
|
||||||
+ dnssec-validation no;
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "victim.test." {
|
|
||||||
+ type primary;
|
|
||||||
+ file "victim.db.signed";
|
|
||||||
+};
|
|
||||||
diff --git a/bin/tests/system/dnssec_bypass/ns2/victim.db b/bin/tests/system/dnssec_bypass/ns2/victim.db
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..edcc234322
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_bypass/ns2/victim.db
|
|
||||||
@@ -0,0 +1,18 @@
|
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+;
|
|
||||||
+; SPDX-License-Identifier: MPL-2.0
|
|
||||||
+;
|
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+;
|
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+; information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+$ORIGIN victim.test.
|
|
||||||
+$TTL 3600
|
|
||||||
+
|
|
||||||
+@ IN SOA ns1 hostmaster 1 3600 600 86400 2147483647
|
|
||||||
+ IN NS ns1
|
|
||||||
+
|
|
||||||
+ns1 IN A 10.53.0.2
|
|
||||||
diff --git a/bin/tests/system/dnssec_bypass/ns3/evil.db b/bin/tests/system/dnssec_bypass/ns3/evil.db
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..618f9d3e85
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_bypass/ns3/evil.db
|
|
||||||
@@ -0,0 +1,23 @@
|
|
||||||
+; Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+;
|
|
||||||
+; SPDX-License-Identifier: MPL-2.0
|
|
||||||
+;
|
|
||||||
+; This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+; License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+; file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+;
|
|
||||||
+; See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+; information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+$ORIGIN evil.test.
|
|
||||||
+$TTL 300
|
|
||||||
+
|
|
||||||
+@ IN SOA ns1 hostmaster 1 3600 600 86400 300
|
|
||||||
+ IN NS ns1
|
|
||||||
+; Try to poison the victim zone in a resolver cache.
|
|
||||||
+; If admitted, the aggressive NSEC cache will accept a range such as
|
|
||||||
+; [evil.test, b.victim.test) and will cause the victim nameserver to
|
|
||||||
+; be never queried.
|
|
||||||
+ IN NSEC b.victim.test. NS SOA RRSIG NSEC DNSKEY
|
|
||||||
+
|
|
||||||
+ns1 IN A 10.53.0.3
|
|
||||||
diff --git a/bin/tests/system/dnssec_bypass/ns3/named.conf.j2 b/bin/tests/system/dnssec_bypass/ns3/named.conf.j2
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..17d3e18e4e
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_bypass/ns3/named.conf.j2
|
|
||||||
@@ -0,0 +1,26 @@
|
|
||||||
+/*
|
|
||||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+ *
|
|
||||||
+ * SPDX-License-Identifier: MPL-2.0
|
|
||||||
+ *
|
|
||||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+ *
|
|
||||||
+ * See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+ * information regarding copyright ownership.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
+options {
|
|
||||||
+ port @PORT@;
|
|
||||||
+ pid-file "named.pid";
|
|
||||||
+ listen-on { 10.53.0.3; };
|
|
||||||
+ listen-on-v6 { none; };
|
|
||||||
+ recursion no;
|
|
||||||
+ dnssec-validation no;
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "evil.test." {
|
|
||||||
+ type primary;
|
|
||||||
+ file "evil.db.signed";
|
|
||||||
+};
|
|
||||||
diff --git a/bin/tests/system/dnssec_bypass/ns4/named.conf.j2 b/bin/tests/system/dnssec_bypass/ns4/named.conf.j2
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..039695d9b7
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_bypass/ns4/named.conf.j2
|
|
||||||
@@ -0,0 +1,35 @@
|
|
||||||
+/*
|
|
||||||
+ * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+ *
|
|
||||||
+ * SPDX-License-Identifier: MPL-2.0
|
|
||||||
+ *
|
|
||||||
+ * This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+ * License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+ * file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+ *
|
|
||||||
+ * See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+ * information regarding copyright ownership.
|
|
||||||
+ */
|
|
||||||
+
|
|
||||||
+options {
|
|
||||||
+ query-source address 10.53.0.4;
|
|
||||||
+ notify-source 10.53.0.4;
|
|
||||||
+ transfer-source 10.53.0.4;
|
|
||||||
+ port @PORT@;
|
|
||||||
+ pid-file "named.pid";
|
|
||||||
+ listen-on { 10.53.0.4; };
|
|
||||||
+ listen-on-v6 { none; };
|
|
||||||
+ allow-transfer { any; };
|
|
||||||
+ recursion yes;
|
|
||||||
+ dnssec-validation yes;
|
|
||||||
+ synth-from-dnssec yes;
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+trust-anchors {
|
|
||||||
+ @root.domain@ @root.type@ @root.contents@;
|
|
||||||
+};
|
|
||||||
+
|
|
||||||
+zone "." {
|
|
||||||
+ type hint;
|
|
||||||
+ file "../../_common/root.hint";
|
|
||||||
+};
|
|
||||||
diff --git a/bin/tests/system/dnssec_bypass/tests_bypass.py b/bin/tests/system/dnssec_bypass/tests_bypass.py
|
|
||||||
new file mode 100644
|
|
||||||
index 0000000000..c41bb7e016
|
|
||||||
--- /dev/null
|
|
||||||
+++ b/bin/tests/system/dnssec_bypass/tests_bypass.py
|
|
||||||
@@ -0,0 +1,152 @@
|
|
||||||
+# Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
||||||
+#
|
|
||||||
+# SPDX-License-Identifier: MPL-2.0
|
|
||||||
+#
|
|
||||||
+# This Source Code Form is subject to the terms of the Mozilla Public
|
|
||||||
+# License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
||||||
+# file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
|
||||||
+#
|
|
||||||
+# See the COPYRIGHT file distributed with this work for additional
|
|
||||||
+# information regarding copyright ownership.
|
|
||||||
+
|
|
||||||
+from datetime import datetime, timedelta, timezone
|
|
||||||
+
|
|
||||||
+import shutil
|
|
||||||
+
|
|
||||||
+from cryptography.hazmat.primitives.asymmetric import ec
|
|
||||||
+
|
|
||||||
+import dns.dnssec
|
|
||||||
+import dns.name
|
|
||||||
+import dns.rdataclass
|
|
||||||
+import dns.rdataset
|
|
||||||
+import dns.rdatatype
|
|
||||||
+import dns.rrset
|
|
||||||
+import dns.zone
|
|
||||||
+
|
|
||||||
+from isctest.run import EnvCmd
|
|
||||||
+
|
|
||||||
+import isctest
|
|
||||||
+
|
|
||||||
+TTL = 3600
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def bootstrap():
|
|
||||||
+ keygen = EnvCmd("KEYGEN", "-q -a ECDSA256")
|
|
||||||
+ signer = EnvCmd("SIGNER", "-S -g -O full")
|
|
||||||
+
|
|
||||||
+ def sign_regular_zone(ns: str, zone: str, database: str) -> isctest.kasp.Key:
|
|
||||||
+ isctest.log.info(f"{zone}: generate keys")
|
|
||||||
+ keygen(zone, cwd=ns).out.strip()
|
|
||||||
+ ksk = keygen(f"-f KSK {zone}", cwd=ns).out.strip()
|
|
||||||
+
|
|
||||||
+ isctest.log.info(f"{zone}: sign zone")
|
|
||||||
+ signer(f"-o {zone} {database}", cwd=ns)
|
|
||||||
+
|
|
||||||
+ if ns != "ns1":
|
|
||||||
+ shutil.copy(f"{ns}/dsset-{zone}", f"ns1/dsset-{zone}")
|
|
||||||
+ shutil.copy(f"{ns}/{ksk}.key", f"ns1/{ksk}.key")
|
|
||||||
+
|
|
||||||
+ return isctest.kasp.Key(ksk, keydir=ns)
|
|
||||||
+
|
|
||||||
+ # dnssec-signzone and `dns.dnssec.sign_zone` correctly disregard the invalid
|
|
||||||
+ # NSEC entries when signing the zone. However, for this test we actualy *want*
|
|
||||||
+ # to serve invalid yet signed zones. To accomplish this we sign the zone and then
|
|
||||||
+ # replace the correct entries with the faulty ones accompanied by its RRSIG.
|
|
||||||
+ #
|
|
||||||
+ # TODO(aydin): move this to `isctest` to sign broken zones
|
|
||||||
+ def sign_rogue_zone(ns: str, zone: str, database: str) -> None:
|
|
||||||
+ # Read zone.
|
|
||||||
+ origin = dns.name.from_text(zone)
|
|
||||||
+ data = dns.zone.from_file(f"{ns}/{database}", origin=origin, relativize=False)
|
|
||||||
+
|
|
||||||
+ # Get key for signing.
|
|
||||||
+ isctest.log.info(f"{zone}: generate keys")
|
|
||||||
+ private_key = ec.generate_private_key(ec.SECP256R1())
|
|
||||||
+ dnskey = dns.dnssec.make_dnskey(
|
|
||||||
+ public_key=private_key.public_key(),
|
|
||||||
+ algorithm=dns.dnssec.Algorithm.ECDSAP256SHA256,
|
|
||||||
+ flags=257,
|
|
||||||
+ )
|
|
||||||
+
|
|
||||||
+ # Sign zone.
|
|
||||||
+ isctest.log.info(f"{zone}: sign zone")
|
|
||||||
+ now = datetime.now(timezone.utc)
|
|
||||||
+ inception = now - timedelta(hours=1)
|
|
||||||
+ expiration = now + timedelta(days=30)
|
|
||||||
+
|
|
||||||
+ for name, node in data.nodes.items():
|
|
||||||
+ owner = name.derelativize(origin)
|
|
||||||
+ rdatasets = list(node.rdatasets)
|
|
||||||
+
|
|
||||||
+ for rdataset in rdatasets:
|
|
||||||
+ rrset = dns.rrset.RRset(owner, rdataset.rdclass, rdataset.rdtype)
|
|
||||||
+ rrset.update(rdataset)
|
|
||||||
+
|
|
||||||
+ rrsig = dns.dnssec.sign(
|
|
||||||
+ rrset=rrset,
|
|
||||||
+ private_key=private_key,
|
|
||||||
+ signer=origin,
|
|
||||||
+ dnskey=dnskey,
|
|
||||||
+ inception=inception,
|
|
||||||
+ expiration=expiration,
|
|
||||||
+ deterministic=False,
|
|
||||||
+ )
|
|
||||||
+
|
|
||||||
+ rdataset = dns.rdataset.Rdataset(rrset.rdclass, dns.rdatatype.RRSIG)
|
|
||||||
+ rdataset.add(rrsig, rrset.ttl)
|
|
||||||
+ node.replace_rdataset(rdataset)
|
|
||||||
+
|
|
||||||
+ # Sign DNSKEY RRset.
|
|
||||||
+ dnskey_rrset = dns.rrset.RRset(origin, dns.rdataclass.IN, dns.rdatatype.DNSKEY)
|
|
||||||
+ dnskey_rrset.add(dnskey, ttl=TTL)
|
|
||||||
+
|
|
||||||
+ apex_node = data.nodes[origin]
|
|
||||||
+ apex_node.replace_rdataset(dnskey_rrset)
|
|
||||||
+
|
|
||||||
+ rrsig = dns.dnssec.sign(
|
|
||||||
+ rrset=dnskey_rrset,
|
|
||||||
+ private_key=private_key,
|
|
||||||
+ signer=origin,
|
|
||||||
+ dnskey=dnskey,
|
|
||||||
+ inception=inception,
|
|
||||||
+ expiration=expiration,
|
|
||||||
+ deterministic=False,
|
|
||||||
+ )
|
|
||||||
+ rdataset = dns.rdataset.Rdataset(rrset.rdclass, dns.rdatatype.RRSIG)
|
|
||||||
+ rdataset.add(rrsig, dnskey_rrset.ttl)
|
|
||||||
+ apex_node.replace_rdataset(rdataset)
|
|
||||||
+
|
|
||||||
+ # Output zone.
|
|
||||||
+ data.to_file(f"{ns}/{database}.signed", relativize=False)
|
|
||||||
+
|
|
||||||
+ # Output DS.
|
|
||||||
+ ds = dns.dnssec.make_ds(name=origin, key=dnskey, algorithm="SHA256")
|
|
||||||
+ with open(f"ns1/dsset-{zone}", "w", encoding="utf-8") as f:
|
|
||||||
+ f.write(f"{zone} {TTL} IN DS {ds.to_text()}\n")
|
|
||||||
+
|
|
||||||
+ sign_rogue_zone("ns3", "evil.test.", "evil.db")
|
|
||||||
+ sign_regular_zone("ns2", "victim.test.", "victim.db")
|
|
||||||
+ sign_regular_zone("ns1", "test.", "test.db")
|
|
||||||
+ root_ksk = sign_regular_zone("ns1", ".", "root.db")
|
|
||||||
+
|
|
||||||
+ return {
|
|
||||||
+ "root": root_ksk.into_ta("static-key"),
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+def test_out_of_zone_nsec(ns4):
|
|
||||||
+ isctest.log.info("trying to poison aggressive nsec cache")
|
|
||||||
+ msg = isctest.query.create("nx.evil.test", "A")
|
|
||||||
+ res = isctest.query.tcp(msg, ns4.ip)
|
|
||||||
+ isctest.check.noadflag(res)
|
|
||||||
+
|
|
||||||
+ isctest.log.info("query victim from recursive")
|
|
||||||
+ msg = isctest.query.create("victim.test", "SOA")
|
|
||||||
+ res = isctest.query.tcp(msg, ns4.ip, attempts=1)
|
|
||||||
+ isctest.check.noerror(res)
|
|
||||||
+ isctest.check.adflag(res)
|
|
||||||
+ isctest.check.rr_count_eq(res.answer, 2)
|
|
||||||
+
|
|
||||||
+ isctest.log.info("checking for query history on victim nameserver")
|
|
||||||
+ with open("ns2/named.run", "r", encoding="utf-8") as f:
|
|
||||||
+ assert "(victim.test): query 'victim.test/SOA/IN' approved" in f.read()
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,277 +0,0 @@
|
||||||
From 72967445f37a01d28b4ecb0e8f907e22fddd5087 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Ayd=C4=B1n=20Mercan?= <aydin@isc.org>
|
|
||||||
Date: Thu, 7 May 2026 18:59:20 +0300
|
|
||||||
Subject: [PATCH] Reject out-of-zone NSEC next owner names
|
|
||||||
|
|
||||||
When verifying DNSSEC records, make sure that a next owner name of
|
|
||||||
an NSEC record is a subdomain of the signer field.
|
|
||||||
|
|
||||||
This follows the specification RFC 4034, section 4.1.1:
|
|
||||||
|
|
||||||
Owner names of RRsets for which the given zone is not authoritative
|
|
||||||
(such as glue records) MUST NOT be listed in the Next Domain Name
|
|
||||||
unless at least one authoritative RRset exists at the same owner
|
|
||||||
name.
|
|
||||||
|
|
||||||
While the above paragraph is intended for glue records, it also
|
|
||||||
applies to out-of-zone data.
|
|
||||||
|
|
||||||
(cherry picked from commit 4065512d25b71605b9502bb69dfb903776d35aa9)
|
|
||||||
(cherry picked from commit 058023c66f11d78590d4aa8c4f98946c4c965e21)
|
|
||||||
|
|
||||||
change dns_nsec_requiredtypespresent to dns_nsec_is_legal
|
|
||||||
|
|
||||||
Change `dns_nsec_requiredtypespresent` to `dns_nsec_is_legal` as a
|
|
||||||
function for checking multiple NSEC validity rules.
|
|
||||||
|
|
||||||
Currently we now additionally check for out-of-zone NSEC entries.
|
|
||||||
|
|
||||||
(cherry picked from commit be2a6a497312469890b552907d039d2de0b44ccc)
|
|
||||||
(cherry picked from commit f751e19a30d107f04c2f644aff9f8dab8fed03ab)
|
|
||||||
---
|
|
||||||
lib/dns/dnssec.c | 13 ++++++++++
|
|
||||||
lib/dns/include/dns/dnssec.h | 6 +++++
|
|
||||||
lib/dns/include/dns/nsec.h | 18 ++++++++++----
|
|
||||||
lib/dns/nsec.c | 17 ++++++++++---
|
|
||||||
lib/dns/resolver.c | 48 ++++++++++++++++++++++++++++++++++--
|
|
||||||
lib/ns/query.c | 6 ++---
|
|
||||||
6 files changed, 94 insertions(+), 14 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/dnssec.c b/lib/dns/dnssec.c
|
|
||||||
index 9b9b1f2bb2..5acaea9ecb 100644
|
|
||||||
--- a/lib/dns/dnssec.c
|
|
||||||
+++ b/lib/dns/dnssec.c
|
|
||||||
@@ -357,8 +357,10 @@ isc_result_t
|
|
||||||
dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
|
||||||
bool ignoretime, unsigned int maxbits, isc_mem_t *mctx,
|
|
||||||
dns_rdata_t *sigrdata, dns_name_t *wild) {
|
|
||||||
+ dns_rdata_nsec_t nsec;
|
|
||||||
dns_rdata_rrsig_t sig;
|
|
||||||
dns_fixedname_t fnewname;
|
|
||||||
+ dns_rdata_t rdata = DNS_RDATA_INIT;
|
|
||||||
isc_region_t r;
|
|
||||||
isc_buffer_t envbuf;
|
|
||||||
dns_rdata_t *rdatas;
|
|
||||||
@@ -464,6 +466,17 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
|
||||||
}
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
+ /*
|
|
||||||
+ * Check for out of zone NSEC entries.
|
|
||||||
+ */
|
|
||||||
+ if (set->type == dns_rdatatype_nsec) {
|
|
||||||
+ RETERR(dns_rdataset_first(set));
|
|
||||||
+ dns_rdataset_current(set, &rdata);
|
|
||||||
+ RETERR(dns_rdata_tostruct(&rdata, &nsec, NULL));
|
|
||||||
+ if (!dns_name_issubdomain(&nsec.next, &sig.signer)) {
|
|
||||||
+ return DNS_R_NOVALIDNSEC;
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
|
|
||||||
again:
|
|
||||||
ret = dst_context_create(key, mctx, DNS_LOGCATEGORY_DNSSEC, false,
|
|
||||||
diff --git a/lib/dns/include/dns/dnssec.h b/lib/dns/include/dns/dnssec.h
|
|
||||||
index cb8fd9dc20..2be11b9144 100644
|
|
||||||
--- a/lib/dns/include/dns/dnssec.h
|
|
||||||
+++ b/lib/dns/include/dns/dnssec.h
|
|
||||||
@@ -151,6 +151,9 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
|
||||||
* this record, as this requires a resolver or database.
|
|
||||||
* If 'ignoretime' is true, temporal validity will not be checked.
|
|
||||||
*
|
|
||||||
+ * If 'set' is of type NSEC, this function also verifies that the
|
|
||||||
+ * Next Name is a subdomain of the Signer's Name from 'sigrdata'.
|
|
||||||
+ *
|
|
||||||
* 'maxbits' specifies the maximum number of rsa exponent bits accepted.
|
|
||||||
*
|
|
||||||
* Requires:
|
|
||||||
@@ -173,6 +176,9 @@ dns_dnssec_verify(const dns_name_t *name, dns_rdataset_t *set, dst_key_t *key,
|
|
||||||
*\li #DNS_R_KEYUNAUTHORIZED - the key cannot sign this data (either
|
|
||||||
* it is not a zone key or its flags prevent
|
|
||||||
* authentication)
|
|
||||||
+ *
|
|
||||||
+ *\li #DNS_R_NOVALIDNSEC - the NSEC rdata is not valid
|
|
||||||
+ *\li #DNS_R_KEYUNAUTHORIZED - the key cannot sign this data
|
|
||||||
*\li DST_R_*
|
|
||||||
*/
|
|
||||||
|
|
||||||
diff --git a/lib/dns/include/dns/nsec.h b/lib/dns/include/dns/nsec.h
|
|
||||||
index 50df8e45f1..1e71bf14e8 100644
|
|
||||||
--- a/lib/dns/include/dns/nsec.h
|
|
||||||
+++ b/lib/dns/include/dns/nsec.h
|
|
||||||
@@ -119,13 +119,21 @@ dns_nsec_noexistnodata(dns_rdatatype_t type, const dns_name_t *name,
|
|
||||||
*/
|
|
||||||
|
|
||||||
bool
|
|
||||||
-dns_nsec_requiredtypespresent(dns_rdataset_t *rdataset);
|
|
||||||
-/*
|
|
||||||
- * Return true if all the NSEC records in rdataset have both
|
|
||||||
- * NSEC and RRSIG present.
|
|
||||||
+dns_nsec_is_legal(dns_rdataset_t *rdataset, const dns_name_t *name);
|
|
||||||
+/**<
|
|
||||||
+ * \brief
|
|
||||||
+ * Validates a rdataset of type NSEC.
|
|
||||||
*
|
|
||||||
- * Requires:
|
|
||||||
+ * This functions checks for the following in the given rdataset:
|
|
||||||
+ * \li All NSEC records have both NSEC and RRSIG present
|
|
||||||
+ * \li All NSEC entries are under the `name`
|
|
||||||
+ *
|
|
||||||
+ * \par Requires:
|
|
||||||
* \li rdataset to be a NSEC rdataset.
|
|
||||||
+ * \li `name` is a valid dns_name_t
|
|
||||||
+ *
|
|
||||||
+ * \retval true if all the checks pass
|
|
||||||
+ * \retval false otherwise
|
|
||||||
*/
|
|
||||||
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
diff --git a/lib/dns/nsec.c b/lib/dns/nsec.c
|
|
||||||
index 80ee8d7d58..5abcce5f7f 100644
|
|
||||||
--- a/lib/dns/nsec.c
|
|
||||||
+++ b/lib/dns/nsec.c
|
|
||||||
@@ -21,6 +21,7 @@
|
|
||||||
#include <isc/util.h>
|
|
||||||
|
|
||||||
#include <dns/db.h>
|
|
||||||
+#include <dns/name.h>
|
|
||||||
#include <dns/nsec.h>
|
|
||||||
#include <dns/rdata.h>
|
|
||||||
#include <dns/rdatalist.h>
|
|
||||||
@@ -497,8 +498,9 @@ dns_nsec_noexistnodata(dns_rdatatype_t type, const dns_name_t *name,
|
|
||||||
}
|
|
||||||
|
|
||||||
bool
|
|
||||||
-dns_nsec_requiredtypespresent(dns_rdataset_t *nsecset) {
|
|
||||||
- dns_rdataset_t rdataset;
|
|
||||||
+dns_nsec_is_legal(dns_rdataset_t *nsecset, const dns_name_t *name) {
|
|
||||||
+ dns_rdataset_t rdataset = DNS_RDATASET_INIT;
|
|
||||||
+ dns_rdata_nsec_t nsec;
|
|
||||||
isc_result_t result;
|
|
||||||
bool found = false;
|
|
||||||
|
|
||||||
@@ -513,12 +515,19 @@ dns_nsec_requiredtypespresent(dns_rdataset_t *nsecset) {
|
|
||||||
{
|
|
||||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
|
||||||
dns_rdataset_current(&rdataset, &rdata);
|
|
||||||
- if (!dns_nsec_typepresent(&rdata, dns_rdatatype_nsec) ||
|
|
||||||
- !dns_nsec_typepresent(&rdata, dns_rdatatype_rrsig))
|
|
||||||
+
|
|
||||||
+ /* must never fail */
|
|
||||||
+ result = dns_rdata_tostruct(&rdata, &nsec, NULL);
|
|
||||||
+ INSIST(result == ISC_R_SUCCESS);
|
|
||||||
+
|
|
||||||
+ if (!dns_name_issubdomain(&nsec.next, name) ||
|
|
||||||
+ !dns_nsec_typepresent(&rdata, dns_rdatatype_rrsig) ||
|
|
||||||
+ !dns_nsec_typepresent(&rdata, dns_rdatatype_nsec))
|
|
||||||
{
|
|
||||||
dns_rdataset_disassociate(&rdataset);
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
+
|
|
||||||
found = true;
|
|
||||||
}
|
|
||||||
dns_rdataset_disassociate(&rdataset);
|
|
||||||
diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c
|
|
||||||
index 059ce53a9e..eac67f7a19 100644
|
|
||||||
--- a/lib/dns/resolver.c
|
|
||||||
+++ b/lib/dns/resolver.c
|
|
||||||
@@ -65,7 +65,9 @@
|
|
||||||
#include <dns/rootns.h>
|
|
||||||
#include <dns/stats.h>
|
|
||||||
#include <dns/tsig.h>
|
|
||||||
+#include <dns/types.h>
|
|
||||||
#include <dns/validator.h>
|
|
||||||
+#include <dns/view.h>
|
|
||||||
#include <dns/zone.h>
|
|
||||||
|
|
||||||
/* Detailed logging of fctx attach/detach */
|
|
||||||
@@ -5603,6 +5605,36 @@ fctx_setresult(fetchctx_t *fctx, dns_rdataset_t *rdataset) {
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
|
|
||||||
+static bool
|
|
||||||
+get_and_check_signer_name(dns_name_t *signer, dns_rdataset_t *sigrdataset) {
|
|
||||||
+ dns_rdata_rrsig_t rrsig;
|
|
||||||
+ isc_result_t result;
|
|
||||||
+ dns_rdata_t rdata;
|
|
||||||
+
|
|
||||||
+ if (dns_rdataset_first(sigrdataset) != ISC_R_SUCCESS) {
|
|
||||||
+ return false;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ rdata = (dns_rdata_t)DNS_RDATA_INIT;
|
|
||||||
+ dns_rdataset_current(sigrdataset, &rdata);
|
|
||||||
+ result = dns_rdata_tostruct(&rdata, &rrsig, NULL);
|
|
||||||
+ INSIST(result == ISC_R_SUCCESS);
|
|
||||||
+ dns_name_copy(&rrsig.signer, signer);
|
|
||||||
+
|
|
||||||
+ while (dns_rdataset_next(sigrdataset) == ISC_R_SUCCESS) {
|
|
||||||
+ rdata = (dns_rdata_t)DNS_RDATA_INIT;
|
|
||||||
+ dns_rdataset_current(sigrdataset, &rdata);
|
|
||||||
+ result = dns_rdata_tostruct(&rdata, &rrsig, NULL);
|
|
||||||
+ INSIST(result == ISC_R_SUCCESS);
|
|
||||||
+
|
|
||||||
+ if (!dns_name_equal(signer, &rrsig.signer)) {
|
|
||||||
+ return false;
|
|
||||||
+ }
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ return true;
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
/*
|
|
||||||
* The validator has finished.
|
|
||||||
*/
|
|
||||||
@@ -5633,6 +5665,8 @@ validated(isc_task_t *task, isc_event_t *event) {
|
|
||||||
dns_fixedname_t fwild;
|
|
||||||
dns_name_t *wild = NULL;
|
|
||||||
dns_message_t *message = NULL;
|
|
||||||
+ dns_fixedname_t fsigner;
|
|
||||||
+ dns_name_t *signer = NULL;
|
|
||||||
|
|
||||||
UNUSED(task); /* for now */
|
|
||||||
|
|
||||||
@@ -6021,10 +6055,20 @@ answer_response:
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
- * Don't cache NSEC if missing NSEC or RRSIG types.
|
|
||||||
+ * Don't cache if all the RRSIGs don't have the same
|
|
||||||
+ * signer.
|
|
||||||
+ */
|
|
||||||
+ signer = dns_fixedname_initname(&fsigner);
|
|
||||||
+ if (!get_and_check_signer_name(signer, sigrdataset)) {
|
|
||||||
+ continue;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ /*
|
|
||||||
+ * Don't cache NSEC if missing NSEC or RRSIG
|
|
||||||
+ * types.
|
|
||||||
*/
|
|
||||||
if (rdataset->type == dns_rdatatype_nsec &&
|
|
||||||
- !dns_nsec_requiredtypespresent(rdataset))
|
|
||||||
+ !dns_nsec_is_legal(rdataset, signer))
|
|
||||||
{
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
|
||||||
index 2a2ba1daba..8bbcd7ff30 100644
|
|
||||||
--- a/lib/ns/query.c
|
|
||||||
+++ b/lib/ns/query.c
|
|
||||||
@@ -10370,10 +10370,10 @@ query_coveringnsec(query_ctx_t *qctx) {
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
- * If NSEC or RRSIG are missing from the type map
|
|
||||||
- * reject the NSEC RRset.
|
|
||||||
+ * Check that the NSEC entry is legal.
|
|
||||||
+ * (NSEC + RRSIG present and the entry isn't out-of-zone)
|
|
||||||
*/
|
|
||||||
- if (!dns_nsec_requiredtypespresent(qctx->rdataset)) {
|
|
||||||
+ if (!dns_nsec_is_legal(qctx->rdataset, signer)) {
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
|
|
||||||
--
|
|
||||||
2.55.0
|
|
||||||
|
|
||||||
|
|
@ -1,76 +0,0 @@
|
||||||
From 12f50726b6bd8f6b3ed6709695e0f6893bc865c6 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Tue, 16 Sep 2025 11:46:03 +0200
|
|
||||||
Subject: [PATCH] Fix expectations on idna system test
|
|
||||||
|
|
||||||
IDNA tests always redirect output into the file. That means its
|
|
||||||
behaviour has changed and is now processing IDN input by default and
|
|
||||||
just disables IDN output by default.
|
|
||||||
|
|
||||||
New behaviour when redirected is the same as +idnin +noidnout, but does
|
|
||||||
not fail hard on input errors.
|
|
||||||
---
|
|
||||||
bin/tests/system/idna/tests.sh | 12 ++++++------
|
|
||||||
1 file changed, 6 insertions(+), 6 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/tests/system/idna/tests.sh b/bin/tests/system/idna/tests.sh
|
|
||||||
index 398b7e1..37f02b1 100644
|
|
||||||
--- a/bin/tests/system/idna/tests.sh
|
|
||||||
+++ b/bin/tests/system/idna/tests.sh
|
|
||||||
@@ -194,7 +194,7 @@ idna_enabled_test() {
|
|
||||||
# Note that ASCII characters are converted to lower-case.
|
|
||||||
|
|
||||||
text="Checking valid non-ASCII label"
|
|
||||||
- idna_test "$text" "" "München" "M\195\188nchen."
|
|
||||||
+ idna_test "$text" "" "München" "xn--mnchen-3ya."
|
|
||||||
idna_test "$text" "+noidnin +noidnout" "München" "M\195\188nchen."
|
|
||||||
idna_test "$text" "+noidnin +idnout" "München" "M\195\188nchen."
|
|
||||||
idna_test "$text" "+idnin +noidnout" "München" "xn--mnchen-3ya."
|
|
||||||
@@ -218,7 +218,7 @@ idna_enabled_test() {
|
|
||||||
# for the valid U-label.
|
|
||||||
|
|
||||||
text="Checking that non-transitional IDNA processing is used"
|
|
||||||
- idna_test "$text" "" "faß.de" "fa\195\159.de."
|
|
||||||
+ idna_test "$text" "" "faß.de" "xn--fa-hia.de."
|
|
||||||
idna_test "$text" "+noidnin +noidnout" "faß.de" "fa\195\159.de."
|
|
||||||
idna_test "$text" "+noidnin +idnout" "faß.de" "fa\195\159.de."
|
|
||||||
idna_test "$text" "+idnin +noidnout" "faß.de" "xn--fa-hia.de."
|
|
||||||
@@ -228,7 +228,7 @@ idna_enabled_test() {
|
|
||||||
# onto the Greek sigma character ("σ") in IDNA2003.
|
|
||||||
|
|
||||||
text="Second check that non-transitional IDNA processing is used"
|
|
||||||
- idna_test "$text" "" "βόλος.com" "\206\178\207\140\206\187\206\191\207\130.com."
|
|
||||||
+ idna_test "$text" "" "βόλος.com" "xn--nxasmm1c.com."
|
|
||||||
idna_test "$text" "+noidnin +noidnout" "βόλος.com" "\206\178\207\140\206\187\206\191\207\130.com."
|
|
||||||
idna_test "$text" "+noidnin +idnout" "βόλος.com" "\206\178\207\140\206\187\206\191\207\130.com."
|
|
||||||
idna_test "$text" "+idnin +noidnout" "βόλος.com" "xn--nxasmm1c.com."
|
|
||||||
@@ -288,7 +288,7 @@ idna_enabled_test() {
|
|
||||||
idna_test "$text" "" "xn--xx" "xn--xx."
|
|
||||||
idna_test "$text" "+noidnin +noidnout" "xn--xx" "xn--xx."
|
|
||||||
idna_fail "$text" "+noidnin +idnout" "xn--xx"
|
|
||||||
- idna_fail "$text" "+idnin +noidnout" "xn--xx"
|
|
||||||
+ idna_test "$text" "+idnin +noidnout" "xn--xx" "xn--xx."
|
|
||||||
idna_fail "$text" "+idnin +idnout" "xn--xx"
|
|
||||||
|
|
||||||
# Fake A-label - the string does not translate to anything.
|
|
||||||
@@ -297,7 +297,7 @@ idna_enabled_test() {
|
|
||||||
idna_test "$text" "" "xn--ahahah" "xn--ahahah."
|
|
||||||
idna_test "$text" "+noidnin +noidnout" "xn--ahahah" "xn--ahahah."
|
|
||||||
idna_fail "$text" "+noidnin +idnout" "xn--ahahah"
|
|
||||||
- idna_fail "$text" "+idnin +noidnout" "xn--ahahah"
|
|
||||||
+ idna_test "$text" "+idnin +noidnout" "xn--ahahah" "xn--ahahah."
|
|
||||||
idna_fail "$text" "+idnin +idnout" "xn--ahahah"
|
|
||||||
|
|
||||||
# Too long a label. The punycode string is too long (at 64 characters).
|
|
||||||
@@ -324,7 +324,7 @@ idna_enabled_test() {
|
|
||||||
# The +[no]idnout options should not have any effect on the test.
|
|
||||||
|
|
||||||
text="Checking invalid input U-label"
|
|
||||||
- idna_test "$text" "" "√.com" "\226\136\154.com."
|
|
||||||
+ idna_test "$text" "" "√.com" "xn--19g.com."
|
|
||||||
idna_test "$text" "+noidnin +noidnout" "√.com" "\226\136\154.com."
|
|
||||||
idna_test "$text" "+noidnin +idnout" "√.com" "\226\136\154.com."
|
|
||||||
idna_test "$text" "+idnin +noidnout" "√.com" "xn--19g.com."
|
|
||||||
--
|
|
||||||
2.51.0
|
|
||||||
|
|
||||||
|
|
@ -1,98 +0,0 @@
|
||||||
From fcc50604359a05e24003f3ff51c3812d8f307814 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Wed, 6 Nov 2024 21:29:47 +0100
|
|
||||||
Subject: [PATCH] Allow always IDN input in dig
|
|
||||||
MIME-Version: 1.0
|
|
||||||
Content-Type: text/plain; charset=UTF-8
|
|
||||||
Content-Transfer-Encoding: 8bit
|
|
||||||
|
|
||||||
Even when stdout is non-interactive terminal, allow unicode characters
|
|
||||||
to be encoded into ACE form. Still disable IDN output, but unless
|
|
||||||
+noidnin or IDN_DISABLE=1 env is detected, consider input as locale
|
|
||||||
defined name.
|
|
||||||
|
|
||||||
Provides more isolated change, which issue #3527 introduced similar
|
|
||||||
behavior into 9.19 with more changes.
|
|
||||||
|
|
||||||
Ignore input IDN errors when stdout is not terminal
|
|
||||||
|
|
||||||
Attempt to prevent visible regressions when enabling IDN on input
|
|
||||||
always. Instead of new hard failures preventing IDN decoding of input
|
|
||||||
name just use original input.
|
|
||||||
|
|
||||||
Should make the change backward compatible. When on interactive terminal
|
|
||||||
behave the same way as before and emit hard errors. Become more
|
|
||||||
forgiving in scripts where stdout leads to script. Decoding output is
|
|
||||||
not enabled there and if input decoding fails, just use input as it was.
|
|
||||||
|
|
||||||
Change dig manual +idnin
|
|
||||||
|
|
||||||
Note in manual IDN input is always enabled. But it silently ignores
|
|
||||||
errors when stdout is not a terminal to prevent regressions.
|
|
||||||
|
|
||||||
Signed-off-by: Petr Menšík <pemensik@redhat.com>
|
|
||||||
---
|
|
||||||
bin/dig/dig.rst | 5 ++---
|
|
||||||
bin/dig/dighost.c | 16 ++++++++++++----
|
|
||||||
2 files changed, 14 insertions(+), 7 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/dig/dig.rst b/bin/dig/dig.rst
|
|
||||||
index 88b0a40307..e2bf3764d3 100644
|
|
||||||
--- a/bin/dig/dig.rst
|
|
||||||
+++ b/bin/dig/dig.rst
|
|
||||||
@@ -453,9 +453,8 @@ abbreviation is unambiguous; for example, :option:`+cd` is equivalent to
|
|
||||||
This option processes [or does not process] IDN domain names on input. This requires
|
|
||||||
``IDN SUPPORT`` to have been enabled at compile time.
|
|
||||||
|
|
||||||
- The default is to process IDN input when standard output is a tty.
|
|
||||||
- The IDN processing on input is disabled when :program:`dig` output is redirected
|
|
||||||
- to files, pipes, and other non-tty file descriptors.
|
|
||||||
+ The default is to process IDN input. The input IDN processing errors are ignored
|
|
||||||
+ when :program:`dig` output is redirected to files, pipes, and other non-tty file descriptors.
|
|
||||||
|
|
||||||
.. option:: +idnout, +noidnout
|
|
||||||
|
|
||||||
diff --git a/bin/dig/dighost.c b/bin/dig/dighost.c
|
|
||||||
index 0f8ac1335c..1307346192 100644
|
|
||||||
--- a/bin/dig/dighost.c
|
|
||||||
+++ b/bin/dig/dighost.c
|
|
||||||
@@ -604,7 +604,7 @@ dig_lookup_t *
|
|
||||||
make_empty_lookup(void) {
|
|
||||||
dig_lookup_t *looknew;
|
|
||||||
#ifdef HAVE_LIBIDN2
|
|
||||||
- bool idn_allowed = isatty(1) ? (getenv("IDN_DISABLE") == NULL) : false;
|
|
||||||
+ bool idn_allowed = (getenv("IDN_DISABLE") == NULL);
|
|
||||||
#endif /* HAVE_LIBIDN2 */
|
|
||||||
|
|
||||||
debug("make_empty_lookup()");
|
|
||||||
@@ -623,7 +623,7 @@ make_empty_lookup(void) {
|
|
||||||
.badcookie = true,
|
|
||||||
#ifdef HAVE_LIBIDN2
|
|
||||||
.idnin = idn_allowed,
|
|
||||||
- .idnout = idn_allowed,
|
|
||||||
+ .idnout = isatty(1) && idn_allowed,
|
|
||||||
#endif /* HAVE_LIBIDN2 */
|
|
||||||
.udpsize = -1,
|
|
||||||
.edns = -1,
|
|
||||||
@@ -4871,8 +4871,16 @@ idn_locale_to_ace(const char *src, char *dst, size_t dstlen) {
|
|
||||||
res = idn2_to_ascii_lz(src, &ascii_src, IDN2_TRANSITIONAL);
|
|
||||||
}
|
|
||||||
if (res != IDN2_OK) {
|
|
||||||
- fatal("'%s' is not a legal IDNA2008 name (%s), use +noidnin",
|
|
||||||
- src, idn2_strerror(res));
|
|
||||||
+ if (isatty(1)) {
|
|
||||||
+ fatal("'%s' is not a legal IDNA2008 name (%s), use +noidnin",
|
|
||||||
+ src, idn2_strerror(res));
|
|
||||||
+ } else {
|
|
||||||
+ /* In case of non-terminal output silently ignore errors
|
|
||||||
+ * in IDN input decoding. */
|
|
||||||
+ (void)strlcpy(dst, src, dstlen);
|
|
||||||
+ resetlocale(LC_ALL);
|
|
||||||
+ return;
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
|
|
||||||
/*
|
|
||||||
--
|
|
||||||
2.50.1
|
|
||||||
|
|
||||||
|
|
@ -1,54 +0,0 @@
|
||||||
From 3f686891729c7d39d879e8b5bb1aa17d874d265d Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Thu, 19 Jun 2025 19:51:43 +0200
|
|
||||||
Subject: [PATCH] Limit number of additional records fetched
|
|
||||||
|
|
||||||
Limit number of started fetches for additional zone instead of doing
|
|
||||||
none. Keep limit of NS filled with additional records, but present at
|
|
||||||
least some if possible.
|
|
||||||
|
|
||||||
Might help broken implementations relying on receiving addresses in the
|
|
||||||
response for NS query in authoritative zone.
|
|
||||||
---
|
|
||||||
lib/dns/rdataset.c | 11 ++++++-----
|
|
||||||
1 file changed, 6 insertions(+), 5 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/rdataset.c b/lib/dns/rdataset.c
|
|
||||||
index 532e49a..bfa8e37 100644
|
|
||||||
--- a/lib/dns/rdataset.c
|
|
||||||
+++ b/lib/dns/rdataset.c
|
|
||||||
@@ -581,6 +581,7 @@ dns_rdataset_additionaldata(dns_rdataset_t *rdataset,
|
|
||||||
size_t limit) {
|
|
||||||
dns_rdata_t rdata = DNS_RDATA_INIT;
|
|
||||||
isc_result_t result;
|
|
||||||
+ size_t n = 0;
|
|
||||||
|
|
||||||
/*
|
|
||||||
* For each rdata in rdataset, call 'add' for each name and type in the
|
|
||||||
@@ -590,10 +591,6 @@ dns_rdataset_additionaldata(dns_rdataset_t *rdataset,
|
|
||||||
REQUIRE(DNS_RDATASET_VALID(rdataset));
|
|
||||||
REQUIRE((rdataset->attributes & DNS_RDATASETATTR_QUESTION) == 0);
|
|
||||||
|
|
||||||
- if (limit != 0 && dns_rdataset_count(rdataset) > limit) {
|
|
||||||
- return DNS_R_TOOMANYRECORDS;
|
|
||||||
- }
|
|
||||||
-
|
|
||||||
result = dns_rdataset_first(rdataset);
|
|
||||||
if (result != ISC_R_SUCCESS) {
|
|
||||||
return result;
|
|
||||||
@@ -603,7 +600,11 @@ dns_rdataset_additionaldata(dns_rdataset_t *rdataset,
|
|
||||||
dns_rdataset_current(rdataset, &rdata);
|
|
||||||
result = dns_rdata_additionaldata(&rdata, owner_name, add, arg);
|
|
||||||
if (result == ISC_R_SUCCESS) {
|
|
||||||
- result = dns_rdataset_next(rdataset);
|
|
||||||
+ if (limit != 0 && ++n >= limit) {
|
|
||||||
+ result = DNS_R_TOOMANYRECORDS;
|
|
||||||
+ } else {
|
|
||||||
+ result = dns_rdataset_next(rdataset);
|
|
||||||
+ }
|
|
||||||
}
|
|
||||||
dns_rdata_reset(&rdata);
|
|
||||||
} while (result == ISC_R_SUCCESS);
|
|
||||||
--
|
|
||||||
2.50.1
|
|
||||||
|
|
||||||
|
|
@ -1,897 +0,0 @@
|
||||||
From 5bd1369eb7781ad2b349b99f783a7ed07fb7d6ac Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Thu, 13 Feb 2025 13:20:28 +0100
|
|
||||||
Subject: [PATCH] Backport OpenSSL 3 provider support
|
|
||||||
|
|
||||||
Use gist of 451edf324281d30fbbe5669223dcea331670847c and
|
|
||||||
5fd6cfc625aa84005618236f4cd699c07367a3dc upstream commits, but do not do
|
|
||||||
significant rebase together. Move engine loading of EVP_PKEY from label to
|
|
||||||
openssl_link and copy provider variant from newer.
|
|
||||||
|
|
||||||
Remove legacy RSA calls from _fromlabel to separate engine handling
|
|
||||||
code. Make rsa_check accepting EVP_PKEY pair only and use conditional
|
|
||||||
compilation to verify them. Move checking of max exponent bits to
|
|
||||||
rsa_check too, because it is done from all usages anyway.
|
|
||||||
|
|
||||||
Use rsa_check_legacy in places where bit checking is not necessary.
|
|
||||||
|
|
||||||
Fix keyfromlabel to not use engine parameter for provider keys
|
|
||||||
|
|
||||||
- Rework key checks to not require 'engine' tag, private key
|
|
||||||
is valid with 'label' tag alone
|
|
||||||
|
|
||||||
- Fix _fromlabel() functions to work with engine == NULL
|
|
||||||
|
|
||||||
- Update dst__openssl_fromlabel_engine() to do provider lookup
|
|
||||||
only when engine is not set
|
|
||||||
|
|
||||||
(cherry picked from commit de486d0ec5d5642ddb1820a1269f5406a2bb1c64)
|
|
||||||
|
|
||||||
Use dst_key_t label to signal isprivate property as a downstream
|
|
||||||
alternative to upstream commit 74361b0b6e5a6b17ebeea6afe1ca990395d7a6dd.
|
|
||||||
That would require additional heavier changes.
|
|
||||||
|
|
||||||
Downstream change:
|
|
||||||
Move RSA bits check to legacy, let it use rsa_check for newer
|
|
||||||
|
|
||||||
rsabigexponent tests got broken by this change.
|
|
||||||
---
|
|
||||||
lib/dns/dst_openssl.h | 4 +
|
|
||||||
lib/dns/dst_parse.c | 21 ++---
|
|
||||||
lib/dns/openssl_link.c | 161 +++++++++++++++++++++++++++-----
|
|
||||||
lib/dns/openssldh_link.c | 5 +
|
|
||||||
lib/dns/opensslecdsa_link.c | 109 +++++++++++-----------
|
|
||||||
lib/dns/openssleddsa_link.c | 40 +++-----
|
|
||||||
lib/dns/opensslrsa_link.c | 181 ++++++++++++++----------------------
|
|
||||||
7 files changed, 296 insertions(+), 225 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/lib/dns/dst_openssl.h b/lib/dns/dst_openssl.h
|
|
||||||
index 819af0f..cd386c0 100644
|
|
||||||
--- a/lib/dns/dst_openssl.h
|
|
||||||
+++ b/lib/dns/dst_openssl.h
|
|
||||||
@@ -64,4 +64,8 @@ ENGINE *
|
|
||||||
dst__openssl_getengine(const char *engine);
|
|
||||||
#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
|
|
||||||
+isc_result_t
|
|
||||||
+dst__openssl_fromlabel(int key_base_id, const char *engine, const char *label,
|
|
||||||
+ const char *pin, EVP_PKEY **ppub, EVP_PKEY **ppriv);
|
|
||||||
+
|
|
||||||
ISC_LANG_ENDDECLS
|
|
||||||
diff --git a/lib/dns/dst_parse.c b/lib/dns/dst_parse.c
|
|
||||||
index a353b86..7f3fe51 100644
|
|
||||||
--- a/lib/dns/dst_parse.c
|
|
||||||
+++ b/lib/dns/dst_parse.c
|
|
||||||
@@ -195,10 +195,9 @@ check_rsa(const dst_private_t *priv, bool external) {
|
|
||||||
|
|
||||||
mask = (1ULL << TAG_SHIFT) - 1;
|
|
||||||
|
|
||||||
- if (have[TAG_RSA_ENGINE & mask]) {
|
|
||||||
+ if (have[TAG_RSA_LABEL & mask]) {
|
|
||||||
ok = have[TAG_RSA_MODULUS & mask] &&
|
|
||||||
- have[TAG_RSA_PUBLICEXPONENT & mask] &&
|
|
||||||
- have[TAG_RSA_LABEL & mask];
|
|
||||||
+ have[TAG_RSA_PUBLICEXPONENT & mask];
|
|
||||||
} else {
|
|
||||||
ok = have[TAG_RSA_MODULUS & mask] &&
|
|
||||||
have[TAG_RSA_PUBLICEXPONENT & mask] &&
|
|
||||||
@@ -259,11 +258,9 @@ check_ecdsa(const dst_private_t *priv, bool external) {
|
|
||||||
|
|
||||||
mask = (1ULL << TAG_SHIFT) - 1;
|
|
||||||
|
|
||||||
- if (have[TAG_ECDSA_ENGINE & mask]) {
|
|
||||||
- ok = have[TAG_ECDSA_LABEL & mask];
|
|
||||||
- } else {
|
|
||||||
- ok = have[TAG_ECDSA_PRIVATEKEY & mask];
|
|
||||||
- }
|
|
||||||
+ ok = have[TAG_ECDSA_LABEL & mask] ||
|
|
||||||
+ have[TAG_ECDSA_PRIVATEKEY & mask];
|
|
||||||
+
|
|
||||||
return ok ? 0 : -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -295,11 +292,9 @@ check_eddsa(const dst_private_t *priv, bool external) {
|
|
||||||
|
|
||||||
mask = (1ULL << TAG_SHIFT) - 1;
|
|
||||||
|
|
||||||
- if (have[TAG_EDDSA_ENGINE & mask]) {
|
|
||||||
- ok = have[TAG_EDDSA_LABEL & mask];
|
|
||||||
- } else {
|
|
||||||
- ok = have[TAG_EDDSA_PRIVATEKEY & mask];
|
|
||||||
- }
|
|
||||||
+ ok = have[TAG_EDDSA_LABEL & mask] ||
|
|
||||||
+ have[TAG_EDDSA_PRIVATEKEY & mask];
|
|
||||||
+
|
|
||||||
return ok ? 0 : -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
diff --git a/lib/dns/openssl_link.c b/lib/dns/openssl_link.c
|
|
||||||
index e3a89f4..2495be4 100644
|
|
||||||
--- a/lib/dns/openssl_link.c
|
|
||||||
+++ b/lib/dns/openssl_link.c
|
|
||||||
@@ -44,6 +44,9 @@
|
|
||||||
#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
|
||||||
#include <openssl/engine.h>
|
|
||||||
#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
+#include <openssl/store.h>
|
|
||||||
+#endif
|
|
||||||
|
|
||||||
#include "openssl_shim.h"
|
|
||||||
|
|
||||||
@@ -51,6 +54,12 @@
|
|
||||||
static ENGINE *e = NULL;
|
|
||||||
#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
|
|
||||||
+#define DST_RET(a) \
|
|
||||||
+ { \
|
|
||||||
+ result = a; \
|
|
||||||
+ goto cleanup; \
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
static void
|
|
||||||
enable_fips_mode(void) {
|
|
||||||
#ifdef HAVE_FIPS_MODE
|
|
||||||
@@ -70,32 +79,28 @@ enable_fips_mode(void) {
|
|
||||||
|
|
||||||
isc_result_t
|
|
||||||
dst__openssl_init(const char *engine) {
|
|
||||||
- isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
-
|
|
||||||
enable_fips_mode();
|
|
||||||
|
|
||||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
|
||||||
if (engine != NULL && *engine == '\0') {
|
|
||||||
engine = NULL;
|
|
||||||
}
|
|
||||||
|
|
||||||
- if (engine != NULL) {
|
|
||||||
- e = ENGINE_by_id(engine);
|
|
||||||
- if (e == NULL) {
|
|
||||||
- result = DST_R_NOENGINE;
|
|
||||||
- goto cleanup_rm;
|
|
||||||
- }
|
|
||||||
- if (!ENGINE_init(e)) {
|
|
||||||
- result = DST_R_NOENGINE;
|
|
||||||
- goto cleanup_rm;
|
|
||||||
- }
|
|
||||||
- /* This will init the engine. */
|
|
||||||
- if (!ENGINE_set_default(e, ENGINE_METHOD_ALL)) {
|
|
||||||
- result = DST_R_NOENGINE;
|
|
||||||
- goto cleanup_init;
|
|
||||||
- }
|
|
||||||
+ if (engine == NULL) {
|
|
||||||
+ return (ISC_R_SUCCESS);
|
|
||||||
}
|
|
||||||
|
|
||||||
+#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
|
||||||
+ e = ENGINE_by_id(engine);
|
|
||||||
+ if (e == NULL) {
|
|
||||||
+ goto cleanup_rm;
|
|
||||||
+ }
|
|
||||||
+ if (!ENGINE_init(e)) {
|
|
||||||
+ goto cleanup_rm;
|
|
||||||
+ }
|
|
||||||
+ /* This will init the engine. */
|
|
||||||
+ if (!ENGINE_set_default(e, ENGINE_METHOD_ALL)) {
|
|
||||||
+ goto cleanup_init;
|
|
||||||
+ }
|
|
||||||
return ISC_R_SUCCESS;
|
|
||||||
cleanup_init:
|
|
||||||
ENGINE_finish(e);
|
|
||||||
@@ -105,10 +110,8 @@ cleanup_rm:
|
|
||||||
}
|
|
||||||
e = NULL;
|
|
||||||
ERR_clear_error();
|
|
||||||
-#else
|
|
||||||
- UNUSED(engine);
|
|
||||||
#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
- return result;
|
|
||||||
+ return (DST_R_NOENGINE);
|
|
||||||
}
|
|
||||||
|
|
||||||
void
|
|
||||||
@@ -220,4 +223,120 @@ dst__openssl_getengine(const char *engine) {
|
|
||||||
}
|
|
||||||
#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
|
|
||||||
+static isc_result_t
|
|
||||||
+dst__openssl_fromlabel_engine(int key_base_id, const char *engine,
|
|
||||||
+ const char *label,
|
|
||||||
+ EVP_PKEY **ppub, EVP_PKEY **ppriv) {
|
|
||||||
+#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
|
||||||
+ isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
+ ENGINE *e = NULL;
|
|
||||||
+ EVP_PKEY *pkey = NULL, *pubpkey = NULL;
|
|
||||||
+
|
|
||||||
+ UNUSED(key_base_id);
|
|
||||||
+
|
|
||||||
+ e = dst__openssl_getengine(engine);
|
|
||||||
+ if (e == NULL) {
|
|
||||||
+ DST_RET(dst__openssl_toresult(DST_R_NOENGINE));
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ pubpkey = ENGINE_load_public_key(e, label, NULL, NULL);
|
|
||||||
+ if (pubpkey == NULL) {
|
|
||||||
+ DST_RET(dst__openssl_toresult2("ENGINE_load_public_key",
|
|
||||||
+ DST_R_OPENSSLFAILURE));
|
|
||||||
+ }
|
|
||||||
+ if (EVP_PKEY_get_base_id(pubpkey) != key_base_id) {
|
|
||||||
+ DST_RET(DST_R_BADKEYTYPE);
|
|
||||||
+ }
|
|
||||||
+ pkey = ENGINE_load_private_key(e, label, NULL, NULL);
|
|
||||||
+ if (pkey == NULL) {
|
|
||||||
+ DST_RET(dst__openssl_toresult2("ENGINE_load_private_key",
|
|
||||||
+ DST_R_OPENSSLFAILURE));
|
|
||||||
+ }
|
|
||||||
+ if (EVP_PKEY_base_id(pkey) != key_base_id) {
|
|
||||||
+ DST_RET(DST_R_INVALIDPRIVATEKEY);
|
|
||||||
+ }
|
|
||||||
+ *ppub = pubpkey;
|
|
||||||
+ *ppriv = pkey;
|
|
||||||
+cleanup:
|
|
||||||
+ return result;
|
|
||||||
+#else
|
|
||||||
+ UNUSED(key_base_id);
|
|
||||||
+ UNUSED(engine);
|
|
||||||
+ UNUSED(label);
|
|
||||||
+ UNUSED(ppub);
|
|
||||||
+ UNUSED(ppriv);
|
|
||||||
+ return DST_R_NOENGINE;
|
|
||||||
+#endif
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+static isc_result_t
|
|
||||||
+dst__openssl_fromlabel_provider(int key_base_id, const char *label, const char *pin,
|
|
||||||
+ EVP_PKEY **ppub, EVP_PKEY **ppriv) {
|
|
||||||
+ UNUSED(pin);
|
|
||||||
+#if OPENSSL_VERSION_NUMBER >= 0x30000000L
|
|
||||||
+ isc_result_t result = DST_R_OPENSSLFAILURE;
|
|
||||||
+ OSSL_STORE_CTX *ctx = NULL;
|
|
||||||
+
|
|
||||||
+
|
|
||||||
+ ctx = OSSL_STORE_open(label, NULL, NULL, NULL, NULL);
|
|
||||||
+ if (!ctx) {
|
|
||||||
+ DST_RET(dst__openssl_toresult2("OSSL_STORE_open_ex",
|
|
||||||
+ DST_R_OPENSSLFAILURE));
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ while (!OSSL_STORE_eof(ctx)) {
|
|
||||||
+ OSSL_STORE_INFO *info = OSSL_STORE_load(ctx);
|
|
||||||
+ if (info == NULL) {
|
|
||||||
+ continue;
|
|
||||||
+ }
|
|
||||||
+ switch (OSSL_STORE_INFO_get_type(info)) {
|
|
||||||
+ case OSSL_STORE_INFO_PKEY:
|
|
||||||
+ if (*ppriv != NULL) {
|
|
||||||
+ DST_RET(DST_R_INVALIDPRIVATEKEY);
|
|
||||||
+ }
|
|
||||||
+ *ppriv = OSSL_STORE_INFO_get1_PKEY(info);
|
|
||||||
+ if (EVP_PKEY_get_base_id(*ppriv) != key_base_id) {
|
|
||||||
+ DST_RET(DST_R_BADKEYTYPE);
|
|
||||||
+ }
|
|
||||||
+ break;
|
|
||||||
+ case OSSL_STORE_INFO_PUBKEY:
|
|
||||||
+ if (*ppub != NULL) {
|
|
||||||
+ DST_RET(DST_R_INVALIDPUBLICKEY);
|
|
||||||
+ }
|
|
||||||
+ *ppub = OSSL_STORE_INFO_get1_PUBKEY(info);
|
|
||||||
+ if (EVP_PKEY_get_base_id(*ppub) != key_base_id) {
|
|
||||||
+ DST_RET(DST_R_BADKEYTYPE);
|
|
||||||
+ }
|
|
||||||
+ break;
|
|
||||||
+ }
|
|
||||||
+ OSSL_STORE_INFO_free(info);
|
|
||||||
+ }
|
|
||||||
+ if (*ppriv != NULL && *ppub != NULL) {
|
|
||||||
+ result = ISC_R_SUCCESS;
|
|
||||||
+ }
|
|
||||||
+cleanup:
|
|
||||||
+ OSSL_STORE_close(ctx);
|
|
||||||
+ return result;
|
|
||||||
+#else
|
|
||||||
+ UNUSED(key_base_id);
|
|
||||||
+ UNUSED(label);
|
|
||||||
+ UNUSED(ppub);
|
|
||||||
+ UNUSED(ppriv);
|
|
||||||
+ return (DST_R_OPENSSLFAILURE);
|
|
||||||
+#endif
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
+isc_result_t
|
|
||||||
+dst__openssl_fromlabel(int key_base_id, const char *engine, const char *label,
|
|
||||||
+ const char *pin, EVP_PKEY **ppub, EVP_PKEY **ppriv) {
|
|
||||||
+ if (engine == NULL) {
|
|
||||||
+ return (dst__openssl_fromlabel_provider(key_base_id, label,
|
|
||||||
+ pin, ppub, ppriv));
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ return (dst__openssl_fromlabel_engine(key_base_id, engine, label,
|
|
||||||
+ ppub, ppriv));
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
/*! \file */
|
|
||||||
diff --git a/lib/dns/openssldh_link.c b/lib/dns/openssldh_link.c
|
|
||||||
index a4ba0f7..38345e6 100644
|
|
||||||
--- a/lib/dns/openssldh_link.c
|
|
||||||
+++ b/lib/dns/openssldh_link.c
|
|
||||||
@@ -610,6 +610,11 @@ err:
|
|
||||||
|
|
||||||
static bool
|
|
||||||
openssldh_isprivate(const dst_key_t *key) {
|
|
||||||
+ if (key->label != NULL) {
|
|
||||||
+ /* assume that _fromlabel will not pass without loading private key,
|
|
||||||
+ * but for non-exportable key cannot get d value on the object. */
|
|
||||||
+ return true;
|
|
||||||
+ }
|
|
||||||
#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000
|
|
||||||
DH *dh = key->keydata.dh;
|
|
||||||
const BIGNUM *priv_key = NULL;
|
|
||||||
diff --git a/lib/dns/opensslecdsa_link.c b/lib/dns/opensslecdsa_link.c
|
|
||||||
index af45fdc..8b49b5d 100644
|
|
||||||
--- a/lib/dns/opensslecdsa_link.c
|
|
||||||
+++ b/lib/dns/opensslecdsa_link.c
|
|
||||||
@@ -617,6 +617,12 @@ opensslecdsa_isprivate(const dst_key_t *key) {
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
+ if (key->label != NULL) {
|
|
||||||
+ /* assume that _fromlabel will not pass without loading private key,
|
|
||||||
+ * but for non-exportable key cannot get d value on the object. */
|
|
||||||
+ return true;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000
|
|
||||||
eckey = EVP_PKEY_get1_EC_KEY(pkey);
|
|
||||||
|
|
||||||
@@ -916,7 +922,7 @@ cleanup:
|
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000
|
|
||||||
static isc_result_t
|
|
||||||
-ecdsa_check(EC_KEY *eckey, EC_KEY *pubeckey) {
|
|
||||||
+ecdsa_check_legacy(EC_KEY *eckey, EC_KEY *pubeckey) {
|
|
||||||
const EC_POINT *pubkey;
|
|
||||||
|
|
||||||
pubkey = EC_KEY_get0_public_key(eckey);
|
|
||||||
@@ -937,9 +943,42 @@ ecdsa_check(EC_KEY *eckey, EC_KEY *pubeckey) {
|
|
||||||
|
|
||||||
return ISC_R_FAILURE;
|
|
||||||
}
|
|
||||||
+
|
|
||||||
+static isc_result_t
|
|
||||||
+ecdsa_check(EVP_PKEY **pkey, EVP_PKEY *pubpkey, int group_nid) {
|
|
||||||
+ isc_result_t result = ISC_R_FAILURE;
|
|
||||||
+ EC_KEY *eckey;
|
|
||||||
+ EC_KEY *pubeckey;
|
|
||||||
+
|
|
||||||
+ eckey = EVP_PKEY_get1_EC_KEY(*pkey);
|
|
||||||
+ if (eckey == NULL) {
|
|
||||||
+ DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
|
||||||
+ }
|
|
||||||
+ if (EC_GROUP_get_curve_name(EC_KEY_get0_group(eckey)) != group_nid) {
|
|
||||||
+ DST_RET(DST_R_INVALIDPRIVATEKEY);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ pubeckey = EVP_PKEY_get1_EC_KEY(pubpkey);
|
|
||||||
+ if (pubeckey == NULL) {
|
|
||||||
+ DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
|
||||||
+ }
|
|
||||||
+ if (EC_GROUP_get_curve_name(EC_KEY_get0_group(pubeckey)) != group_nid) {
|
|
||||||
+ DST_RET(DST_R_INVALIDPUBLICKEY);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ CHECK(ecdsa_check_legacy(eckey, pubeckey));
|
|
||||||
+cleanup:
|
|
||||||
+ if (pubeckey != NULL) {
|
|
||||||
+ EC_KEY_free(pubeckey);
|
|
||||||
+ }
|
|
||||||
+ if (eckey != NULL) {
|
|
||||||
+ EC_KEY_free(eckey);
|
|
||||||
+ }
|
|
||||||
+ return result;
|
|
||||||
+}
|
|
||||||
#else
|
|
||||||
static isc_result_t
|
|
||||||
-ecdsa_check(EVP_PKEY **pkey, EVP_PKEY *pubpkey) {
|
|
||||||
+ecdsa_check(EVP_PKEY **pkey, EVP_PKEY *pubpkey, int group_nid) {
|
|
||||||
isc_result_t result = ISC_R_FAILURE;
|
|
||||||
int status;
|
|
||||||
size_t pkey_len = 0;
|
|
||||||
@@ -954,6 +993,8 @@ ecdsa_check(EVP_PKEY **pkey, EVP_PKEY *pubpkey) {
|
|
||||||
EVP_PKEY_CTX *ctx = NULL;
|
|
||||||
EVP_PKEY *pkey_new = NULL;
|
|
||||||
|
|
||||||
+ UNUSED(group_nid);
|
|
||||||
+
|
|
||||||
/* Check if `pkey` has a public key. */
|
|
||||||
status = EVP_PKEY_get_octet_string_param(*pkey, OSSL_PKEY_PARAM_PUB_KEY,
|
|
||||||
NULL, 0, &pkey_len);
|
|
||||||
@@ -1267,7 +1308,7 @@ opensslecdsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
|
||||||
pubeckey = EVP_PKEY_get1_EC_KEY(pub->keydata.pkey);
|
|
||||||
}
|
|
||||||
|
|
||||||
- if (ecdsa_check(eckey, pubeckey) != ISC_R_SUCCESS) {
|
|
||||||
+ if (ecdsa_check_legacy(eckey, pubeckey) != ISC_R_SUCCESS) {
|
|
||||||
DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -1276,7 +1317,7 @@ opensslecdsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
|
||||||
}
|
|
||||||
#else
|
|
||||||
if (ecdsa_check(&key->keydata.pkey,
|
|
||||||
- pub == NULL ? NULL : pub->keydata.pkey) !=
|
|
||||||
+ pub == NULL ? NULL : pub->keydata.pkey, NID_undef) !=
|
|
||||||
ISC_R_SUCCESS)
|
|
||||||
{
|
|
||||||
DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
|
||||||
@@ -1309,11 +1350,7 @@ cleanup:
|
|
||||||
static isc_result_t
|
|
||||||
opensslecdsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
|
||||||
const char *pin) {
|
|
||||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
- ENGINE *e;
|
|
||||||
- EC_KEY *eckey = NULL;
|
|
||||||
- EC_KEY *pubeckey = NULL;
|
|
||||||
int group_nid;
|
|
||||||
EVP_PKEY *pkey = NULL;
|
|
||||||
EVP_PKEY *pubpkey = NULL;
|
|
||||||
@@ -1323,13 +1360,9 @@ opensslecdsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
|
||||||
|
|
||||||
UNUSED(pin);
|
|
||||||
|
|
||||||
- if (engine == NULL || label == NULL) {
|
|
||||||
+ if (label == NULL) {
|
|
||||||
return DST_R_NOENGINE;
|
|
||||||
}
|
|
||||||
- e = dst__openssl_getengine(engine);
|
|
||||||
- if (e == NULL) {
|
|
||||||
- DST_RET(DST_R_NOENGINE);
|
|
||||||
- }
|
|
||||||
|
|
||||||
if (key->key_alg == DST_ALG_ECDSA256) {
|
|
||||||
group_nid = NID_X9_62_prime256v1;
|
|
||||||
@@ -1337,48 +1370,27 @@ opensslecdsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
|
||||||
group_nid = NID_secp384r1;
|
|
||||||
}
|
|
||||||
|
|
||||||
- /* Load private key. */
|
|
||||||
- pkey = ENGINE_load_private_key(e, label, NULL, NULL);
|
|
||||||
- if (pkey == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult2("ENGINE_load_private_key",
|
|
||||||
- DST_R_OPENSSLFAILURE));
|
|
||||||
- }
|
|
||||||
+ CHECK(dst__openssl_fromlabel(EVP_PKEY_EC, engine, label, pin,
|
|
||||||
+ &pubpkey, &pkey));
|
|
||||||
+
|
|
||||||
/* Check base id, group nid */
|
|
||||||
if (EVP_PKEY_base_id(pkey) != EVP_PKEY_EC) {
|
|
||||||
DST_RET(DST_R_INVALIDPRIVATEKEY);
|
|
||||||
}
|
|
||||||
- eckey = EVP_PKEY_get1_EC_KEY(pkey);
|
|
||||||
- if (eckey == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
|
||||||
- }
|
|
||||||
- if (EC_GROUP_get_curve_name(EC_KEY_get0_group(eckey)) != group_nid) {
|
|
||||||
- DST_RET(DST_R_INVALIDPRIVATEKEY);
|
|
||||||
- }
|
|
||||||
-
|
|
||||||
- /* Load public key. */
|
|
||||||
- pubpkey = ENGINE_load_public_key(e, label, NULL, NULL);
|
|
||||||
- if (pubpkey == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult2("ENGINE_load_public_key",
|
|
||||||
- DST_R_OPENSSLFAILURE));
|
|
||||||
- }
|
|
||||||
/* Check base id, group nid */
|
|
||||||
if (EVP_PKEY_base_id(pubpkey) != EVP_PKEY_EC) {
|
|
||||||
DST_RET(DST_R_INVALIDPUBLICKEY);
|
|
||||||
}
|
|
||||||
- pubeckey = EVP_PKEY_get1_EC_KEY(pubpkey);
|
|
||||||
- if (pubeckey == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
|
||||||
- }
|
|
||||||
- if (EC_GROUP_get_curve_name(EC_KEY_get0_group(pubeckey)) != group_nid) {
|
|
||||||
- DST_RET(DST_R_INVALIDPUBLICKEY);
|
|
||||||
- }
|
|
||||||
|
|
||||||
- if (ecdsa_check(eckey, pubeckey) != ISC_R_SUCCESS) {
|
|
||||||
+ if (ecdsa_check(&pkey, pubpkey, group_nid) != ISC_R_SUCCESS) {
|
|
||||||
DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
|
||||||
}
|
|
||||||
|
|
||||||
+ if (engine != NULL)
|
|
||||||
+ key->engine = isc_mem_strdup(key->mctx, engine);
|
|
||||||
+ else
|
|
||||||
+ key->engine = NULL;
|
|
||||||
key->label = isc_mem_strdup(key->mctx, label);
|
|
||||||
- key->engine = isc_mem_strdup(key->mctx, engine);
|
|
||||||
key->key_size = EVP_PKEY_bits(pkey);
|
|
||||||
key->keydata.pkey = pkey;
|
|
||||||
pkey = NULL;
|
|
||||||
@@ -1390,21 +1402,8 @@ cleanup:
|
|
||||||
if (pkey != NULL) {
|
|
||||||
EVP_PKEY_free(pkey);
|
|
||||||
}
|
|
||||||
- if (pubeckey != NULL) {
|
|
||||||
- EC_KEY_free(pubeckey);
|
|
||||||
- }
|
|
||||||
- if (eckey != NULL) {
|
|
||||||
- EC_KEY_free(eckey);
|
|
||||||
- }
|
|
||||||
|
|
||||||
return result;
|
|
||||||
-#else
|
|
||||||
- UNUSED(key);
|
|
||||||
- UNUSED(engine);
|
|
||||||
- UNUSED(label);
|
|
||||||
- UNUSED(pin);
|
|
||||||
- return DST_R_NOENGINE;
|
|
||||||
-#endif /* !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
}
|
|
||||||
|
|
||||||
static dst_func_t opensslecdsa_functions = {
|
|
||||||
diff --git a/lib/dns/openssleddsa_link.c b/lib/dns/openssleddsa_link.c
|
|
||||||
index 6301db4..08d505b 100644
|
|
||||||
--- a/lib/dns/openssleddsa_link.c
|
|
||||||
+++ b/lib/dns/openssleddsa_link.c
|
|
||||||
@@ -362,6 +362,12 @@ openssleddsa_isprivate(const dst_key_t *key) {
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
+ if (key->label != NULL) {
|
|
||||||
+ /* assume that _fromlabel will not pass without loading private key,
|
|
||||||
+ * but for non-exportable key cannot get d value on the object. */
|
|
||||||
+ return true;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
/* Must have a buffer to actually check if there is a private key. */
|
|
||||||
if (EVP_PKEY_get_raw_private_key(pkey, buf, &len) == 1) {
|
|
||||||
return true;
|
|
||||||
@@ -591,9 +597,7 @@ cleanup:
|
|
||||||
static isc_result_t
|
|
||||||
openssleddsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
|
||||||
const char *pin) {
|
|
||||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
|
||||||
isc_result_t result;
|
|
||||||
- ENGINE *e;
|
|
||||||
EVP_PKEY *pkey = NULL, *pubpkey = NULL;
|
|
||||||
int baseid = EVP_PKEY_NONE;
|
|
||||||
|
|
||||||
@@ -616,28 +620,17 @@ openssleddsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
|
||||||
return ISC_R_NOTIMPLEMENTED;
|
|
||||||
}
|
|
||||||
|
|
||||||
- if (engine == NULL) {
|
|
||||||
- return DST_R_NOENGINE;
|
|
||||||
- }
|
|
||||||
- e = dst__openssl_getengine(engine);
|
|
||||||
- if (e == NULL) {
|
|
||||||
- return DST_R_NOENGINE;
|
|
||||||
- }
|
|
||||||
- pkey = ENGINE_load_private_key(e, label, NULL, NULL);
|
|
||||||
- if (pkey == NULL) {
|
|
||||||
- return dst__openssl_toresult2("ENGINE_load_private_key",
|
|
||||||
- ISC_R_NOTFOUND);
|
|
||||||
- }
|
|
||||||
- if (EVP_PKEY_base_id(pkey) != baseid) {
|
|
||||||
- DST_RET(DST_R_INVALIDPRIVATEKEY);
|
|
||||||
- }
|
|
||||||
+ DST_RET(dst__openssl_fromlabel(baseid, engine, label, pin,
|
|
||||||
+ &pubpkey, &pkey));
|
|
||||||
|
|
||||||
- pubpkey = ENGINE_load_public_key(e, label, NULL, NULL);
|
|
||||||
- if (eddsa_check(pkey, pubpkey) != ISC_R_SUCCESS) {
|
|
||||||
+ if (EVP_PKEY_base_id(pkey) != baseid) {
|
|
||||||
DST_RET(DST_R_INVALIDPRIVATEKEY);
|
|
||||||
}
|
|
||||||
|
|
||||||
- key->engine = isc_mem_strdup(key->mctx, engine);
|
|
||||||
+ if (engine != NULL)
|
|
||||||
+ key->engine = isc_mem_strdup(key->mctx, engine);
|
|
||||||
+ else
|
|
||||||
+ key->engine = NULL;
|
|
||||||
key->label = isc_mem_strdup(key->mctx, label);
|
|
||||||
key->key_size = EVP_PKEY_bits(pkey);
|
|
||||||
key->keydata.pkey = pkey;
|
|
||||||
@@ -652,13 +645,6 @@ cleanup:
|
|
||||||
EVP_PKEY_free(pkey);
|
|
||||||
}
|
|
||||||
return result;
|
|
||||||
-#else /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
- UNUSED(key);
|
|
||||||
- UNUSED(engine);
|
|
||||||
- UNUSED(label);
|
|
||||||
- UNUSED(pin);
|
|
||||||
- return DST_R_NOENGINE;
|
|
||||||
-#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
}
|
|
||||||
|
|
||||||
static dst_func_t openssleddsa_functions = {
|
|
||||||
diff --git a/lib/dns/opensslrsa_link.c b/lib/dns/opensslrsa_link.c
|
|
||||||
index b92e1bf..12210e8 100644
|
|
||||||
--- a/lib/dns/opensslrsa_link.c
|
|
||||||
+++ b/lib/dns/opensslrsa_link.c
|
|
||||||
@@ -545,6 +545,12 @@ opensslrsa_isprivate(const dst_key_t *key) {
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
|
|
||||||
+ if (key->label != NULL) {
|
|
||||||
+ /* assume that _fromlabel will not pass without loading private key,
|
|
||||||
+ * but for non-exportable key cannot get d value on the object. */
|
|
||||||
+ return true;
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000
|
|
||||||
rsa = EVP_PKEY_get1_RSA(pkey);
|
|
||||||
INSIST(rsa != NULL);
|
|
||||||
@@ -995,7 +1001,7 @@ cleanup:
|
|
||||||
|
|
||||||
#if OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000
|
|
||||||
static isc_result_t
|
|
||||||
-rsa_check(RSA *rsa, RSA *pub) {
|
|
||||||
+rsa_check_legacy(RSA *rsa, RSA *pub) {
|
|
||||||
const BIGNUM *n1 = NULL, *n2 = NULL;
|
|
||||||
const BIGNUM *e1 = NULL, *e2 = NULL;
|
|
||||||
BIGNUM *n = NULL, *e = NULL;
|
|
||||||
@@ -1050,6 +1056,46 @@ rsa_check(RSA *rsa, RSA *pub) {
|
|
||||||
|
|
||||||
return ISC_R_SUCCESS;
|
|
||||||
}
|
|
||||||
+
|
|
||||||
+static isc_result_t
|
|
||||||
+rsa_check(EVP_PKEY *pkey, EVP_PKEY *pubpkey) {
|
|
||||||
+ isc_result_t ret = ISC_R_FAILURE;
|
|
||||||
+ RSA *rsa = NULL, *pubrsa = NULL;
|
|
||||||
+ const BIGNUM *ex = NULL;
|
|
||||||
+
|
|
||||||
+ pubrsa = EVP_PKEY_get1_RSA(pubpkey);
|
|
||||||
+ if (pubrsa == NULL) {
|
|
||||||
+ DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ rsa = EVP_PKEY_get1_RSA(pkey);
|
|
||||||
+ if (rsa == NULL) {
|
|
||||||
+ DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ ret = rsa_check_legacy(rsa, pubrsa);
|
|
||||||
+ if (ret != ISC_R_SUCCESS) {
|
|
||||||
+ DST_RET(ret);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+ RSA_get0_key(rsa, NULL, &ex, NULL);
|
|
||||||
+
|
|
||||||
+ if (ex == NULL) {
|
|
||||||
+ DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
|
||||||
+ }
|
|
||||||
+ if (BN_num_bits(ex) > RSA_MAX_PUBEXP_BITS) {
|
|
||||||
+ DST_RET(ISC_R_RANGE);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
+err:
|
|
||||||
+ if (rsa != NULL) {
|
|
||||||
+ RSA_free(rsa);
|
|
||||||
+ }
|
|
||||||
+ if (pubrsa != NULL) {
|
|
||||||
+ RSA_free(pubrsa);
|
|
||||||
+ }
|
|
||||||
+ return ret;
|
|
||||||
+}
|
|
||||||
#else
|
|
||||||
static isc_result_t
|
|
||||||
rsa_check(EVP_PKEY *pkey, EVP_PKEY *pubpkey) {
|
|
||||||
@@ -1097,6 +1143,10 @@ rsa_check(EVP_PKEY *pkey, EVP_PKEY *pubpkey) {
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
+ if (BN_num_bits(e1) > RSA_MAX_PUBEXP_BITS) {
|
|
||||||
+ DST_RET(ISC_R_RANGE);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
if (EVP_PKEY_eq(pkey, pubpkey) == 1) {
|
|
||||||
DST_RET(ISC_R_SUCCESS);
|
|
||||||
}
|
|
||||||
@@ -1119,6 +1169,10 @@ cleanup:
|
|
||||||
}
|
|
||||||
#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000 */
|
|
||||||
|
|
||||||
+static isc_result_t
|
|
||||||
+opensslrsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
|
||||||
+ const char *pin);
|
|
||||||
+
|
|
||||||
static isc_result_t
|
|
||||||
opensslrsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
|
||||||
dst_private_t priv;
|
|
||||||
@@ -1131,12 +1185,8 @@ opensslrsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
|
||||||
OSSL_PARAM *params = NULL;
|
|
||||||
EVP_PKEY_CTX *ctx = NULL;
|
|
||||||
#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000 */
|
|
||||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
|
||||||
- const BIGNUM *ex = NULL;
|
|
||||||
- ENGINE *ep = NULL;
|
|
||||||
- const char *engine = NULL;
|
|
||||||
-#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
isc_mem_t *mctx = NULL;
|
|
||||||
+ const char *engine = NULL;
|
|
||||||
const char *label = NULL;
|
|
||||||
EVP_PKEY *pkey = NULL;
|
|
||||||
BIGNUM *n = NULL, *e = NULL, *d = NULL;
|
|
||||||
@@ -1190,46 +1240,7 @@ opensslrsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
|
||||||
* See if we can fetch it.
|
|
||||||
*/
|
|
||||||
if (label != NULL) {
|
|
||||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
|
||||||
- if (engine == NULL) {
|
|
||||||
- DST_RET(DST_R_NOENGINE);
|
|
||||||
- }
|
|
||||||
- ep = dst__openssl_getengine(engine);
|
|
||||||
- if (ep == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_NOENGINE));
|
|
||||||
- }
|
|
||||||
- pkey = ENGINE_load_private_key(ep, label, NULL, NULL);
|
|
||||||
- if (pkey == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult2("ENGINE_load_private_"
|
|
||||||
- "key",
|
|
||||||
- ISC_R_NOTFOUND));
|
|
||||||
- }
|
|
||||||
- key->engine = isc_mem_strdup(key->mctx, engine);
|
|
||||||
- key->label = isc_mem_strdup(key->mctx, label);
|
|
||||||
-
|
|
||||||
- rsa = EVP_PKEY_get1_RSA(pkey);
|
|
||||||
- if (rsa == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
|
||||||
- }
|
|
||||||
- if (rsa_check(rsa, pubrsa) != ISC_R_SUCCESS) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
|
||||||
- }
|
|
||||||
- RSA_get0_key(rsa, NULL, &ex, NULL);
|
|
||||||
-
|
|
||||||
- if (ex == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
|
||||||
- }
|
|
||||||
- if (BN_num_bits(ex) > RSA_MAX_PUBEXP_BITS) {
|
|
||||||
- DST_RET(ISC_R_RANGE);
|
|
||||||
- }
|
|
||||||
-
|
|
||||||
- key->key_size = EVP_PKEY_bits(pkey);
|
|
||||||
- key->keydata.pkey = pkey;
|
|
||||||
- pkey = NULL;
|
|
||||||
- DST_RET(ISC_R_SUCCESS);
|
|
||||||
-#else /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
- DST_RET(DST_R_NOENGINE);
|
|
||||||
-#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
+ DST_RET(opensslrsa_fromlabel(key, engine, label, NULL));
|
|
||||||
}
|
|
||||||
|
|
||||||
for (i = 0; i < priv.nelements; i++) {
|
|
||||||
@@ -1318,9 +1329,14 @@ opensslrsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
|
||||||
BN_clear_free(iqmp);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
- if (rsa_check(rsa, pubrsa) != ISC_R_SUCCESS) {
|
|
||||||
+ if (rsa_check_legacy(rsa, pubrsa) != ISC_R_SUCCESS) {
|
|
||||||
DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
|
||||||
}
|
|
||||||
+
|
|
||||||
+ if (BN_num_bits(e) > RSA_MAX_PUBEXP_BITS) {
|
|
||||||
+ DST_RET(ISC_R_RANGE);
|
|
||||||
+ }
|
|
||||||
+
|
|
||||||
#else
|
|
||||||
bld = OSSL_PARAM_BLD_new();
|
|
||||||
if (bld == NULL) {
|
|
||||||
@@ -1387,17 +1403,9 @@ opensslrsa_parse(dst_key_t *key, isc_lex_t *lexer, dst_key_t *pub) {
|
|
||||||
DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
|
||||||
}
|
|
||||||
|
|
||||||
- if (rsa_check(pkey, pub != NULL ? pub->keydata.pkey : NULL) !=
|
|
||||||
- ISC_R_SUCCESS)
|
|
||||||
- {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
|
||||||
- }
|
|
||||||
+ CHECK(rsa_check(pkey, pub != NULL ? pub->keydata.pkey : NULL));
|
|
||||||
#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L || OPENSSL_API_LEVEL < 30000 */
|
|
||||||
|
|
||||||
- if (BN_num_bits(e) > RSA_MAX_PUBEXP_BITS) {
|
|
||||||
- DST_RET(ISC_R_RANGE);
|
|
||||||
- }
|
|
||||||
-
|
|
||||||
key->key_size = BN_num_bits(n);
|
|
||||||
key->keydata.pkey = pkey;
|
|
||||||
pkey = NULL;
|
|
||||||
@@ -1461,69 +1469,31 @@ cleanup:
|
|
||||||
static isc_result_t
|
|
||||||
opensslrsa_fromlabel(dst_key_t *key, const char *engine, const char *label,
|
|
||||||
const char *pin) {
|
|
||||||
-#if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000
|
|
||||||
- ENGINE *e = NULL;
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
EVP_PKEY *pkey = NULL, *pubpkey = NULL;
|
|
||||||
- RSA *rsa = NULL, *pubrsa = NULL;
|
|
||||||
- const BIGNUM *ex = NULL;
|
|
||||||
|
|
||||||
UNUSED(pin);
|
|
||||||
|
|
||||||
- if (engine == NULL) {
|
|
||||||
- DST_RET(DST_R_NOENGINE);
|
|
||||||
- }
|
|
||||||
- e = dst__openssl_getengine(engine);
|
|
||||||
- if (e == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_NOENGINE));
|
|
||||||
- }
|
|
||||||
+ CHECK(dst__openssl_fromlabel(EVP_PKEY_RSA, engine, label, pin,
|
|
||||||
+ &pubpkey, &pkey));
|
|
||||||
+ CHECK(rsa_check(pkey, pubpkey));
|
|
||||||
|
|
||||||
- pubpkey = ENGINE_load_public_key(e, label, NULL, NULL);
|
|
||||||
- if (pubpkey == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult2("ENGINE_load_public_key",
|
|
||||||
- DST_R_OPENSSLFAILURE));
|
|
||||||
- }
|
|
||||||
- pubrsa = EVP_PKEY_get1_RSA(pubpkey);
|
|
||||||
- if (pubrsa == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
|
||||||
- }
|
|
||||||
-
|
|
||||||
- pkey = ENGINE_load_private_key(e, label, NULL, NULL);
|
|
||||||
if (pkey == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult2("ENGINE_load_private_key",
|
|
||||||
+ DST_RET(dst__openssl_toresult2("dst__openssl_fromlabel",
|
|
||||||
DST_R_OPENSSLFAILURE));
|
|
||||||
}
|
|
||||||
|
|
||||||
- key->engine = isc_mem_strdup(key->mctx, engine);
|
|
||||||
+ if (engine != NULL)
|
|
||||||
+ key->engine = isc_mem_strdup(key->mctx, engine);
|
|
||||||
+ else
|
|
||||||
+ key->engine = NULL;
|
|
||||||
key->label = isc_mem_strdup(key->mctx, label);
|
|
||||||
|
|
||||||
- rsa = EVP_PKEY_get1_RSA(pkey);
|
|
||||||
- if (rsa == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_OPENSSLFAILURE));
|
|
||||||
- }
|
|
||||||
- if (rsa_check(rsa, pubrsa) != ISC_R_SUCCESS) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
|
||||||
- }
|
|
||||||
- RSA_get0_key(rsa, NULL, &ex, NULL);
|
|
||||||
-
|
|
||||||
- if (ex == NULL) {
|
|
||||||
- DST_RET(dst__openssl_toresult(DST_R_INVALIDPRIVATEKEY));
|
|
||||||
- }
|
|
||||||
- if (BN_num_bits(ex) > RSA_MAX_PUBEXP_BITS) {
|
|
||||||
- DST_RET(ISC_R_RANGE);
|
|
||||||
- }
|
|
||||||
-
|
|
||||||
key->key_size = EVP_PKEY_bits(pkey);
|
|
||||||
key->keydata.pkey = pkey;
|
|
||||||
pkey = NULL;
|
|
||||||
|
|
||||||
cleanup:
|
|
||||||
- if (rsa != NULL) {
|
|
||||||
- RSA_free(rsa);
|
|
||||||
- }
|
|
||||||
- if (pubrsa != NULL) {
|
|
||||||
- RSA_free(pubrsa);
|
|
||||||
- }
|
|
||||||
if (pkey != NULL) {
|
|
||||||
EVP_PKEY_free(pkey);
|
|
||||||
}
|
|
||||||
@@ -1531,13 +1501,6 @@ cleanup:
|
|
||||||
EVP_PKEY_free(pubpkey);
|
|
||||||
}
|
|
||||||
return result;
|
|
||||||
-#else /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
- UNUSED(key);
|
|
||||||
- UNUSED(engine);
|
|
||||||
- UNUSED(label);
|
|
||||||
- UNUSED(pin);
|
|
||||||
- return DST_R_NOENGINE;
|
|
||||||
-#endif /* if !defined(OPENSSL_NO_ENGINE) && OPENSSL_API_LEVEL < 30000 */
|
|
||||||
}
|
|
||||||
|
|
||||||
static dst_func_t opensslrsa_functions = {
|
|
||||||
--
|
|
||||||
2.52.0
|
|
||||||
|
|
||||||
|
|
@ -1,75 +0,0 @@
|
||||||
From 0f3a398fe813189c5dd56b0367a72c7b3f19504b Mon Sep 17 00:00:00 2001
|
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
|
||||||
Date: Wed, 14 Sep 2022 13:06:24 +0200
|
|
||||||
Subject: [PATCH] Disable some often failing tests
|
|
||||||
|
|
||||||
Make those tests skipped in default build, when CI=true environment is
|
|
||||||
set. It is not clear why they fail mostly on COPR, but they do fail
|
|
||||||
often.
|
|
||||||
---
|
|
||||||
tests/isc/netmgr_test.c | 9 +++++++--
|
|
||||||
1 file changed, 7 insertions(+), 2 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/tests/isc/netmgr_test.c b/tests/isc/netmgr_test.c
|
|
||||||
index 94e4bf7..7f9629c 100644
|
|
||||||
--- a/tests/isc/netmgr_test.c
|
|
||||||
+++ b/tests/isc/netmgr_test.c
|
|
||||||
@@ -1567,13 +1567,13 @@ stream_half_recv_half_send(void **state __attribute__((unused))) {
|
|
||||||
/* TCP */
|
|
||||||
ISC_RUN_TEST_IMPL(tcp_noop) { stream_noop(state); }
|
|
||||||
|
|
||||||
-ISC_RUN_TEST_IMPL(tcp_noresponse) { stream_noresponse(state); }
|
|
||||||
+ISC_RUN_TEST_IMPL(tcp_noresponse) { SKIP_IN_CI; stream_noresponse(state); }
|
|
||||||
|
|
||||||
ISC_RUN_TEST_IMPL(tcp_timeout_recovery) { stream_timeout_recovery(state); }
|
|
||||||
|
|
||||||
ISC_RUN_TEST_IMPL(tcp_recv_one) { stream_recv_one(state); }
|
|
||||||
|
|
||||||
-ISC_RUN_TEST_IMPL(tcp_recv_two) { stream_recv_two(state); }
|
|
||||||
+ISC_RUN_TEST_IMPL(tcp_recv_two) { SKIP_IN_CI; stream_recv_two(state); }
|
|
||||||
|
|
||||||
ISC_RUN_TEST_IMPL(tcp_recv_send) {
|
|
||||||
SKIP_IN_CI;
|
|
||||||
@@ -1623,6 +1623,7 @@ ISC_RUN_TEST_IMPL(tcp_recv_one_quota) {
|
|
||||||
}
|
|
||||||
|
|
||||||
ISC_RUN_TEST_IMPL(tcp_recv_two_quota) {
|
|
||||||
+ SKIP_IN_CI;
|
|
||||||
atomic_store(&check_listener_quota, true);
|
|
||||||
stream_recv_two(state);
|
|
||||||
}
|
|
||||||
@@ -1836,6 +1837,7 @@ ISC_RUN_TEST_IMPL(tcpdns_recv_two) {
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
isc_nmsocket_t *listen_sock = NULL;
|
|
||||||
|
|
||||||
+ SKIP_IN_CI;
|
|
||||||
atomic_store(&nsends, 2);
|
|
||||||
|
|
||||||
result = isc_nm_listentcpdns(listen_nm, &tcp_listen_addr,
|
|
||||||
@@ -2095,6 +2097,7 @@ ISC_RUN_TEST_IMPL(tls_recv_one) {
|
|
||||||
}
|
|
||||||
|
|
||||||
ISC_RUN_TEST_IMPL(tls_recv_two) {
|
|
||||||
+ SKIP_IN_CI;
|
|
||||||
stream_use_TLS = true;
|
|
||||||
stream_recv_two(state);
|
|
||||||
}
|
|
||||||
@@ -2160,6 +2163,7 @@ ISC_RUN_TEST_IMPL(tls_recv_one_quota) {
|
|
||||||
}
|
|
||||||
|
|
||||||
ISC_RUN_TEST_IMPL(tls_recv_two_quota) {
|
|
||||||
+ SKIP_IN_CI;
|
|
||||||
stream_use_TLS = true;
|
|
||||||
atomic_store(&check_listener_quota, true);
|
|
||||||
stream_recv_two(state);
|
|
||||||
@@ -2395,6 +2399,7 @@ ISC_RUN_TEST_IMPL(tlsdns_recv_two) {
|
|
||||||
isc_result_t result = ISC_R_SUCCESS;
|
|
||||||
isc_nmsocket_t *listen_sock = NULL;
|
|
||||||
|
|
||||||
+ SKIP_IN_CI;
|
|
||||||
atomic_store(&nsends, 2);
|
|
||||||
|
|
||||||
result = isc_nm_listentlsdns(listen_nm, &tcp_listen_addr,
|
|
||||||
--
|
|
||||||
2.37.2
|
|
||||||
|
|
||||||
|
|
@ -1,114 +0,0 @@
|
||||||
From c5c756ce2ac4c1563d024428e148ca27c7721f71 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Aram Sargsyan <aram@isc.org>
|
|
||||||
Date: Wed, 21 Sep 2022 15:05:11 +0000
|
|
||||||
Subject: [PATCH 2/3] Document nsupdate options related to DoT
|
|
||||||
|
|
||||||
Add documentation for the newly implemented DoT feature of the
|
|
||||||
nsupdate program.
|
|
||||||
|
|
||||||
(cherry picked from commit bd8299d7b501234263a6aee98049f879b1c700b7)
|
|
||||||
---
|
|
||||||
bin/nsupdate/nsupdate.rst | 48 ++++++++++++++++++++++++++++++++++++++-
|
|
||||||
1 file changed, 47 insertions(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/bin/nsupdate/nsupdate.rst b/bin/nsupdate/nsupdate.rst
|
|
||||||
index 81bb4815cf4..f1ab5c76fa7 100644
|
|
||||||
--- a/bin/nsupdate/nsupdate.rst
|
|
||||||
+++ b/bin/nsupdate/nsupdate.rst
|
|
||||||
@@ -19,7 +19,7 @@ nsupdate - dynamic DNS update utility
|
|
||||||
Synopsis
|
|
||||||
~~~~~~~~
|
|
||||||
|
|
||||||
-:program:`nsupdate` [**-d**] [**-D**] [**-i**] [**-L** level] [ [**-g**] | [**-o**] | [**-l**] | [**-y** [hmac:]keyname:secret] | [**-k** keyfile] ] [**-t** timeout] [**-u** udptimeout] [**-r** udpretries] [**-v**] [**-T**] [**-P**] [**-V**] [ [**-4**] | [**-6**] ] [filename]
|
|
||||||
+:program:`nsupdate` [**-d**] [**-D**] [**-i**] [**-L** level] [ [**-g**] | [**-o**] | [**-l**] | [**-y** [hmac:]keyname:secret] | [**-k** keyfile] ] [ [**-S**] [**-K** tlskeyfile] [**-E** tlscertfile] [**-A** tlscafile] [**-H** tlshostname] [-O] ] [**-t** timeout] [**-u** udptimeout] [**-r** udpretries] [**-v**] [**-T**] [**-P**] [**-V**] [ [**-4**] | [**-6**] ] [filename]
|
|
||||||
|
|
||||||
Description
|
|
||||||
~~~~~~~~~~~
|
|
||||||
@@ -71,6 +71,15 @@ Options
|
|
||||||
|
|
||||||
This option sets use of IPv6 only.
|
|
||||||
|
|
||||||
+.. option:: -A tlscafile
|
|
||||||
+
|
|
||||||
+ This option specifies the file of the certificate authorities (CA) certificates
|
|
||||||
+ (in PEM format) in order to verify the remote server TLS certificate when
|
|
||||||
+ using DNS-over-TLS (DoT), to achieve Strict or Mutual TLS. When used, it will
|
|
||||||
+ override the certificates from the global certificates store, which are
|
|
||||||
+ otherwise used by default when :option:`-S` is enabled. This option can not
|
|
||||||
+ be used in conjuction with :option:`-O`, and it implies :option:`-S`.
|
|
||||||
+
|
|
||||||
.. option:: -C
|
|
||||||
|
|
||||||
Overrides the default `resolv.conf` file. This is only intended for testing.
|
|
||||||
@@ -84,10 +93,23 @@ Options
|
|
||||||
|
|
||||||
This option sets extra debug mode.
|
|
||||||
|
|
||||||
+.. option:: -E tlscertfile
|
|
||||||
+
|
|
||||||
+ This option sets the certificate(s) file for authentication for the
|
|
||||||
+ DNS-over-TLS (DoT) transport to the remote server. The certificate
|
|
||||||
+ chain file is expected to be in PEM format. This option implies :option:`-S`,
|
|
||||||
+ and can only be used with :option:`-K`.
|
|
||||||
+
|
|
||||||
.. option:: -g
|
|
||||||
|
|
||||||
This option enables standard GSS-TSIG mode.
|
|
||||||
|
|
||||||
+.. option:: -H tlshostname
|
|
||||||
+
|
|
||||||
+ This option makes :program:`nsupdate` use the provided hostname during remote
|
|
||||||
+ server TLS certificate verification. Otherwise, the DNS server name
|
|
||||||
+ is used. This option implies :option:`-S`.
|
|
||||||
+
|
|
||||||
.. option:: -i
|
|
||||||
|
|
||||||
This option forces interactive mode, even when standard input is not a terminal.
|
|
||||||
@@ -104,6 +126,13 @@ Options
|
|
||||||
key used to authenticate Dynamic DNS update requests. In this case,
|
|
||||||
the key specified is not an HMAC-MD5 key.
|
|
||||||
|
|
||||||
+.. option:: -K tlskeyfile
|
|
||||||
+
|
|
||||||
+ This option sets the key file for authenticated encryption for the
|
|
||||||
+ DNS-over-TLS (DoT) transport with the remote server. The private key file is
|
|
||||||
+ expected to be in PEM format. This option implies :option:`-S`, and can only
|
|
||||||
+ be used with :option:`-E`.
|
|
||||||
+
|
|
||||||
.. option:: -l
|
|
||||||
|
|
||||||
This option sets local-host only mode, which sets the server address to localhost
|
|
||||||
@@ -123,6 +152,14 @@ Options
|
|
||||||
This option enables a non-standards-compliant variant of GSS-TSIG
|
|
||||||
used by Windows 2000.
|
|
||||||
|
|
||||||
+.. option:: -O
|
|
||||||
+
|
|
||||||
+ This option enables Opportunistic TLS. When used, the remote peer's TLS
|
|
||||||
+ certificate will not be verified. This option should be used for debugging
|
|
||||||
+ purposes only, and it is not recommended to use it in production. This
|
|
||||||
+ option can not be used in conjuction with :option:`-A`, and it implies
|
|
||||||
+ :option:`-S`.
|
|
||||||
+
|
|
||||||
.. option:: -p port
|
|
||||||
|
|
||||||
This option sets the port to use for connections to a name server. The default is
|
|
||||||
@@ -138,6 +175,15 @@ Options
|
|
||||||
This option sets the number of UDP retries. The default is 3. If zero, only one update
|
|
||||||
request is made.
|
|
||||||
|
|
||||||
+.. option:: -S
|
|
||||||
+
|
|
||||||
+ This option indicates whether to use DNS-over-TLS (DoT) when querying
|
|
||||||
+ name servers specified by ``server servername port`` syntax in the input
|
|
||||||
+ file, and the primary server discovered through a SOA request. When the
|
|
||||||
+ :option:`-K` and :option:`-E` options are used, then the specified TLS
|
|
||||||
+ client certificate and private key pair are used for authentication
|
|
||||||
+ (Mutual TLS). This option implies :option:`-v`.
|
|
||||||
+
|
|
||||||
.. option:: -t timeout
|
|
||||||
|
|
||||||
This option sets the maximum time an update request can take before it is aborted. The
|
|
||||||
--
|
|
||||||
2.47.0
|
|
||||||
|
|
||||||
File diff suppressed because it is too large
Load diff
File diff suppressed because it is too large
Load diff
|
|
@ -1,45 +0,0 @@
|
||||||
From 32f203d4e3c711cde5b1546a054be42b16436822 Mon Sep 17 00:00:00 2001
|
|
||||||
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
|
||||||
Date: Fri, 17 Jul 2026 19:42:39 +0200
|
|
||||||
Subject: [PATCH] Support program suffixes of tsig-confgen and ddns-confgen
|
|
||||||
|
|
||||||
Suffixes different than .exe are used on Fedora. But those commands
|
|
||||||
require exact names only. Allow switching between two variants only from
|
|
||||||
prefix. That should work on all platforms. It should support also names
|
|
||||||
like tsig-confgen-9.18 or tsig-confgen-9.20.
|
|
||||||
|
|
||||||
The same case applies to named-checkzone and named-compilezone.
|
|
||||||
---
|
|
||||||
bin/check/named-checkzone.c | 2 +-
|
|
||||||
bin/confgen/tsig-keygen.c | 2 +-
|
|
||||||
2 files changed, 2 insertions(+), 2 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bin/check/named-checkzone.c b/bin/check/named-checkzone.c
|
|
||||||
index ae8feafc8c..5a1f712463 100644
|
|
||||||
--- a/bin/check/named-checkzone.c
|
|
||||||
+++ b/bin/check/named-checkzone.c
|
|
||||||
@@ -137,7 +137,7 @@ main(int argc, char **argv) {
|
|
||||||
}
|
|
||||||
|
|
||||||
#define PROGCMP(X) \
|
|
||||||
- (strcasecmp(prog_name, X) == 0 || strcasecmp(prog_name, X ".exe") == 0)
|
|
||||||
+ (strncasecmp(prog_name, X, strlen(X)) == 0)
|
|
||||||
|
|
||||||
if (PROGCMP("named-checkzone")) {
|
|
||||||
progmode = progmode_check;
|
|
||||||
diff --git a/bin/confgen/tsig-keygen.c b/bin/confgen/tsig-keygen.c
|
|
||||||
index f0d2f9a245..9b13312b5b 100644
|
|
||||||
--- a/bin/confgen/tsig-keygen.c
|
|
||||||
+++ b/bin/confgen/tsig-keygen.c
|
|
||||||
@@ -113,7 +113,7 @@ main(int argc, char **argv) {
|
|
||||||
}
|
|
||||||
|
|
||||||
#define PROGCMP(X) \
|
|
||||||
- (strcasecmp(progname, X) == 0 || strcasecmp(progname, X ".exe") == 0)
|
|
||||||
+ (strncasecmp(progname, X, strlen(X)) == 0)
|
|
||||||
|
|
||||||
if (PROGCMP("tsig-keygen")) {
|
|
||||||
progmode = progmode_keygen;
|
|
||||||
--
|
|
||||||
2.54.0
|
|
||||||
|
|
||||||
63
bind-9.3.1rc1-sdb_tools-Makefile.in
Normal file
63
bind-9.3.1rc1-sdb_tools-Makefile.in
Normal file
|
|
@ -0,0 +1,63 @@
|
||||||
|
srcdir = @srcdir@
|
||||||
|
VPATH = @srcdir@
|
||||||
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
|
VERSION=@BIND9_VERSION@
|
||||||
|
|
||||||
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
|
CINCLUDES = -I${srcdir}/include -I${srcdir}/unix/include \
|
||||||
|
${LWRES_INCLUDES} ${DNS_INCLUDES} ${BIND9_INCLUDES} \
|
||||||
|
${ISCCFG_INCLUDES} ${ISCCC_INCLUDES} ${ISC_INCLUDES}
|
||||||
|
|
||||||
|
CDEFINES = -DBIND9
|
||||||
|
|
||||||
|
DNSLIBS = ../../lib/dns/libdns.@A@ @DNS_CRYPTO_LIBS@
|
||||||
|
ISCCFGLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
ISCCCLIBS = ../../lib/isccc/libisccc.@A@
|
||||||
|
ISCLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
LWRESLIBS = ../../lib/lwres/liblwres.@A@
|
||||||
|
BIND9LIBS = ../../lib/bind9/libbind9.@A@
|
||||||
|
|
||||||
|
DNSDEPLIBS = ../../lib/dns/libdns.@A@
|
||||||
|
ISCCFGDEPLIBS = ../../lib/isccfg/libisccfg.@A@
|
||||||
|
ISCCCDEPLIBS = ../../lib/isccc/libisccc.@A@
|
||||||
|
ISCDEPLIBS = ../../lib/isc/libisc.@A@
|
||||||
|
LWRESDEPLIBS = ../../lib/lwres/liblwres.@A@
|
||||||
|
BIND9DEPLIBS = ../../lib/bind9/libbind9.@A@
|
||||||
|
|
||||||
|
DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
||||||
|
${ISCCFGDEPLIBS} ${ISCCCDEPLIBS} ${ISCDEPLIBS}
|
||||||
|
|
||||||
|
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} ${DBDRIVER_LIBS} @LIBS@
|
||||||
|
|
||||||
|
TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@
|
||||||
|
|
||||||
|
OBJS = zone2ldap.@O@ zonetodb.@O@
|
||||||
|
|
||||||
|
SRCS = zone2ldap.c zonetodb.c
|
||||||
|
|
||||||
|
MANPAGES = zone2ldap.1
|
||||||
|
|
||||||
|
EXT_CFLAGS =
|
||||||
|
|
||||||
|
@BIND9_MAKE_RULES@
|
||||||
|
|
||||||
|
zone2ldap@EXEEXT@: zone2ldap.@O@ ${DEPLIBS}
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zone2ldap.@O@ -lldap -llber ${LIBS}
|
||||||
|
|
||||||
|
zonetodb@EXEEXT@: zonetodb.@O@ ${DEPLIBS}
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${CFLAGS} ${LDFLAGS} -o $@ zonetodb.@O@ -lpq ${LIBS}
|
||||||
|
|
||||||
|
clean distclean manclean maintainer-clean::
|
||||||
|
rm -f ${TARGETS} ${OBJS}
|
||||||
|
|
||||||
|
installdirs:
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||||
|
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man1
|
||||||
|
|
||||||
|
install:: ${TARGETS} installdirs
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2ldap@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zonetodb@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${INSTALL_DATA} ${srcdir}/zone2ldap.1 ${DESTDIR}${mandir}/man1/zone2ldap.1
|
||||||
|
|
@ -1,66 +1,68 @@
|
||||||
From 402403b4bbb4f603693378e86b6c97997ccb0401 Mon Sep 17 00:00:00 2001
|
diff --git a/bin/named/named.8 b/bin/named/named.8
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
index ef10ef4..3150b22 100644
|
||||||
Date: Wed, 17 Jun 2020 23:17:13 +0200
|
--- a/bin/named/named.8
|
||||||
Subject: [PATCH] Update man named with Red Hat specifics
|
+++ b/bin/named/named.8
|
||||||
|
@@ -349,6 +349,63 @@ The default configuration file\&.
|
||||||
This is almost unmodified text and requires revalidation. Some of those
|
/var/run/named/named\&.pid
|
||||||
statements are no longer correct.
|
.RS 4
|
||||||
---
|
The default process\-id file\&.
|
||||||
bin/named/named.rst | 41 +++++++++++++++++++++++++++++++++++++++++
|
+.PP
|
||||||
1 file changed, 41 insertions(+)
|
+.SH "NOTES"
|
||||||
|
+.PP
|
||||||
diff --git a/bin/named/named.rst b/bin/named/named.rst
|
+.TP
|
||||||
index ea440b2..fa51984 100644
|
+\fBRed Hat SELinux BIND Security Profile:\fR
|
||||||
--- a/bin/named/named.rst
|
+.PP
|
||||||
+++ b/bin/named/named.rst
|
|
||||||
@@ -212,6 +212,47 @@ Files
|
|
||||||
|named_pid|
|
|
||||||
The default process-id file.
|
|
||||||
|
|
||||||
+Notes
|
|
||||||
+~~~~~
|
|
||||||
+
|
|
||||||
+**Red Hat SELinux BIND Security Profile:**
|
|
||||||
+
|
|
||||||
+By default, Red Hat ships BIND with the most secure SELinux policy
|
+By default, Red Hat ships BIND with the most secure SELinux policy
|
||||||
+that will not prevent normal BIND operation and will prevent exploitation
|
+that will not prevent normal BIND operation and will prevent exploitation
|
||||||
+of all known BIND security vulnerabilities . See the selinux(8) man page
|
+of all known BIND security vulnerabilities . See the selinux(8) man page
|
||||||
+for information about SElinux.
|
+for information about SElinux.
|
||||||
+
|
+.PP
|
||||||
+It is not necessary to run named in a chroot environment if the Red Hat
|
+It is not necessary to run named in a chroot environment if the Red Hat
|
||||||
+SELinux policy for named is enabled. When enabled, this policy is far
|
+SELinux policy for named is enabled. When enabled, this policy is far
|
||||||
+more secure than a chroot environment. Users are recommended to enable
|
+more secure than a chroot environment. Users are recommended to enable
|
||||||
+SELinux and remove the bind-chroot package.
|
+SELinux and remove the bind-chroot package.
|
||||||
+
|
+.PP
|
||||||
+*With this extra security comes some restrictions:*
|
+With this extra security comes some restrictions:
|
||||||
+
|
+.PP
|
||||||
+By default, the SELinux policy does not allow named to write any master
|
+By default, the SELinux policy does not allow named to write any master
|
||||||
+zone database files. Only the root user may create files in the $ROOTDIR/var/named
|
+zone database files. Only the root user may create files in the $ROOTDIR/var/named
|
||||||
+zone database file directory (the options { "directory" } option), where
|
+zone database file directory (the options { "directory" } option), where
|
||||||
+$ROOTDIR is set in /etc/sysconfig/named.
|
+$ROOTDIR is set in /etc/sysconfig/named.
|
||||||
+
|
+.PP
|
||||||
+The "named" group must be granted read privelege to
|
+The "named" group must be granted read privelege to
|
||||||
+these files in order for named to be enabled to read them.
|
+these files in order for named to be enabled to read them.
|
||||||
+
|
+.PP
|
||||||
+Any file created in the zone database file directory is automatically assigned
|
+Any file created in the zone database file directory is automatically assigned
|
||||||
+the SELinux file context *named_zone_t* .
|
+the SELinux file context named_zone_t .
|
||||||
+
|
+.PP
|
||||||
+By default, SELinux prevents any role from modifying *named_zone_t* files; this
|
+By default, SELinux prevents any role from modifying named_zone_t files; this
|
||||||
+means that files in the zone database directory cannot be modified by dynamic
|
+means that files in the zone database directory cannot be modified by dynamic
|
||||||
+DNS (DDNS) updates or zone transfers.
|
+DNS (DDNS) updates or zone transfers.
|
||||||
+
|
+.PP
|
||||||
+The Red Hat BIND distribution and SELinux policy creates three directories where
|
+The Red Hat BIND distribution and SELinux policy creates three directories where
|
||||||
+named is allowed to create and modify files: */var/named/slaves*, */var/named/dynamic*
|
+named is allowed to create and modify files: /var/named/slaves, /var/named/dynamic
|
||||||
+*/var/named/data*. By placing files you want named to modify, such as
|
+/var/named/data. By placing files you want named to modify, such as
|
||||||
+slave or DDNS updateable zone files and database / statistics dump files in
|
+slave or DDNS updateable zone files and database / statistics dump files in
|
||||||
+these directories, named will work normally and no further operator action is
|
+these directories, named will work normally and no further operator action is
|
||||||
+required. Files in these directories are automatically assigned the '*named_cache_t*'
|
+required. Files in these directories are automatically assigned the 'named_cache_t'
|
||||||
+file context, which SELinux allows named to write.
|
+file context, which SELinux allows named to write.
|
||||||
+
|
+.PP
|
||||||
+
|
+\fBRed Hat BIND SDB support:\fR
|
||||||
See Also
|
+.PP
|
||||||
~~~~~~~~
|
+Red Hat ships named with compiled in Simplified Database Backend modules that ISC
|
||||||
|
+provides in the "contrib/sdb" directory. Install bind-sdb package if you want use them
|
||||||
--
|
+.PP
|
||||||
2.34.1
|
+The SDB modules for LDAP, PostGreSQL, DirDB and SQLite are compiled into named-sdb.
|
||||||
|
+.PP
|
||||||
|
+See the documentation for the various SDB modules in /usr/share/doc/bind-sdb-*/ .
|
||||||
|
+.br
|
||||||
|
+.PP
|
||||||
|
+\fBRed Hat system-config-bind:\fR
|
||||||
|
+.PP
|
||||||
|
+Red Hat provides the system-config-bind GUI to configure named.conf and zone
|
||||||
|
+database files. Run the "system-config-bind" command and access the manual
|
||||||
|
+by selecting the Help menu.
|
||||||
|
+.PP
|
||||||
|
.RE
|
||||||
|
.SH "SEE ALSO"
|
||||||
|
.PP
|
||||||
519
bind-9.3.2b1-fix_sdb_ldap.patch
Normal file
519
bind-9.3.2b1-fix_sdb_ldap.patch
Normal file
|
|
@ -0,0 +1,519 @@
|
||||||
|
diff --git a/bin/sdb_tools/Makefile.in b/bin/sdb_tools/Makefile.in
|
||||||
|
index 95ab742..6069f09 100644
|
||||||
|
--- a/bin/sdb_tools/Makefile.in
|
||||||
|
+++ b/bin/sdb_tools/Makefile.in
|
||||||
|
@@ -32,11 +32,11 @@ DEPLIBS = ${LWRESDEPLIBS} ${DNSDEPLIBS} ${BIND9DEPLIBS} \
|
||||||
|
LIBS = ${LWRESLIBS} ${DNSLIBS} ${BIND9LIBS} \
|
||||||
|
${ISCCFGLIBS} ${ISCCCLIBS} ${ISCLIBS} ${DBDRIVER_LIBS} @LIBS@
|
||||||
|
|
||||||
|
-TARGETS = zone2ldap@EXEEXT@ zonetodb@EXEEXT@ zone2sqlite@EXEEXT@
|
||||||
|
+TARGETS = zone2ldap@EXEEXT@ ldap2zone@EXEEXT@ zonetodb@EXEEXT@ zone2sqlite@EXEEXT@
|
||||||
|
|
||||||
|
-OBJS = zone2ldap.@O@ zonetodb.@O@ zone2sqlite.@O@
|
||||||
|
+OBJS = zone2ldap.@O@ ldap2zone.@O@ zonetodb.@O@ zone2sqlite.@O@
|
||||||
|
|
||||||
|
-SRCS = zone2ldap.c zonetodb.c zone2sqlite.c
|
||||||
|
+SRCS = zone2ldap.c ldap2zone.c zonetodb.c zone2sqlite.c
|
||||||
|
|
||||||
|
MANPAGES = zone2ldap.1
|
||||||
|
|
||||||
|
@@ -53,6 +53,9 @@ zonetodb@EXEEXT@: zonetodb.@O@ ${DEPLIBS}
|
||||||
|
zone2sqlite@EXEEXT@: zone2sqlite.@O@ ${DEPLIBS}
|
||||||
|
${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o $@ zone2sqlite.@O@ -lsqlite3 -lssl ${LIBS}
|
||||||
|
|
||||||
|
+ldap2zone@EXEEXT@: ldap2zone.@O@ ${DEPLIBS}
|
||||||
|
+ ${LIBTOOL_MODE_LINK} ${PURIFY} ${CC} ${ALL_CFLAGS} ${LDFLAGS} -o $@ ldap2zone.@O@ -lldap -llber ${LIBS}
|
||||||
|
+
|
||||||
|
clean distclean manclean maintainer-clean::
|
||||||
|
rm -f ${TARGETS} ${OBJS}
|
||||||
|
|
||||||
|
@@ -62,6 +65,7 @@ installdirs:
|
||||||
|
|
||||||
|
install:: ${TARGETS} installdirs
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2ldap@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
+ ${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} ldap2zone@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zonetodb@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${LIBTOOL_MODE_INSTALL} ${INSTALL_PROGRAM} zone2sqlite@EXEEXT@ ${DESTDIR}${sbindir}
|
||||||
|
${INSTALL_DATA} ${srcdir}/zone2ldap.1 ${DESTDIR}${mandir}/man1/zone2ldap.1
|
||||||
|
diff --git a/bin/sdb_tools/zone2ldap.c b/bin/sdb_tools/zone2ldap.c
|
||||||
|
index aa2c711..76186b5 100644
|
||||||
|
--- a/bin/sdb_tools/zone2ldap.c
|
||||||
|
+++ b/bin/sdb_tools/zone2ldap.c
|
||||||
|
@@ -66,6 +66,9 @@ ldap_info;
|
||||||
|
/* usage Info */
|
||||||
|
void usage (void);
|
||||||
|
|
||||||
|
+/* Check for existence of (and possibly add) containing dNSZone objects */
|
||||||
|
+int lookup_dns_zones( ldap_info *ldinfo);
|
||||||
|
+
|
||||||
|
/* Add to the ldap dit */
|
||||||
|
void add_ldap_values (ldap_info * ldinfo);
|
||||||
|
|
||||||
|
@@ -82,7 +85,7 @@ char **hostname_to_dn_list (char *hostname, char *zone, unsigned int flags);
|
||||||
|
int get_attr_list_size (char **tmp);
|
||||||
|
|
||||||
|
/* Get a DN */
|
||||||
|
-char *build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag);
|
||||||
|
+char *build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag, char *zone);
|
||||||
|
|
||||||
|
/* Add to RR list */
|
||||||
|
void add_to_rr_list (char *dn, char *name, char *type, char *data,
|
||||||
|
@@ -104,11 +107,27 @@ void
|
||||||
|
init_ldap_conn ();
|
||||||
|
void usage();
|
||||||
|
|
||||||
|
-char *argzone, *ldapbase, *binddn, *bindpw = NULL;
|
||||||
|
-const char *ldapsystem = "localhost";
|
||||||
|
-static const char *objectClasses[] =
|
||||||
|
- { "top", "dNSZone", NULL };
|
||||||
|
-static const char *topObjectClasses[] = { "top", NULL };
|
||||||
|
+static char *argzone, *ldapbase, *binddn, *bindpw = NULL;
|
||||||
|
+
|
||||||
|
+/* these are needed to placate gcc4's const-ness const-ernations : */
|
||||||
|
+static char localhost[] = "localhost";
|
||||||
|
+static char *ldapsystem=&(localhost[0]);
|
||||||
|
+/* dnszone schema class names: */
|
||||||
|
+static char topClass [] ="top";
|
||||||
|
+static char dNSZoneClass[] ="dNSZone";
|
||||||
|
+static char objectClass [] ="objectClass";
|
||||||
|
+static char dcObjectClass[]="dcObject";
|
||||||
|
+/* dnszone schema attribute names: */
|
||||||
|
+static char relativeDomainName[]="relativeDomainName";
|
||||||
|
+static char dNSTTL []="dNSTTL";
|
||||||
|
+static char zoneName []="zoneName";
|
||||||
|
+static char dc []="dc";
|
||||||
|
+static char sameZone []="@";
|
||||||
|
+/* LDAPMod mod_values: */
|
||||||
|
+static char *objectClasses []= { &(topClass[0]), &(dNSZoneClass[0]), NULL };
|
||||||
|
+static char *topObjectClasses []= { &(topClass[0]), &(dcObjectClass[0]), &(dNSZoneClass[0]), NULL };
|
||||||
|
+static char *dn_buffer [64]={NULL};
|
||||||
|
+
|
||||||
|
LDAP *conn;
|
||||||
|
unsigned int debug = 0;
|
||||||
|
|
||||||
|
@@ -132,12 +151,12 @@ main (int argc, char **argv)
|
||||||
|
isc_result_t result;
|
||||||
|
char *basedn;
|
||||||
|
ldap_info *tmp;
|
||||||
|
- LDAPMod *base_attrs[2];
|
||||||
|
- LDAPMod base;
|
||||||
|
+ LDAPMod *base_attrs[5];
|
||||||
|
+ LDAPMod base, dcBase, znBase, rdnBase;
|
||||||
|
isc_buffer_t buff;
|
||||||
|
char *zonefile=0L;
|
||||||
|
char fullbasedn[1024];
|
||||||
|
- char *ctmp;
|
||||||
|
+ char *ctmp, *zn, *dcp[2], *znp[2], *rdn[2];
|
||||||
|
dns_fixedname_t fixedzone, fixedname;
|
||||||
|
dns_rdataset_t rdataset;
|
||||||
|
char **dc_list;
|
||||||
|
@@ -150,7 +169,7 @@ main (int argc, char **argv)
|
||||||
|
extern char *optarg;
|
||||||
|
extern int optind, opterr, optopt;
|
||||||
|
int create_base = 0;
|
||||||
|
- int topt;
|
||||||
|
+ int topt, dcn, zdn, znlen;
|
||||||
|
|
||||||
|
if (argc < 2)
|
||||||
|
{
|
||||||
|
@@ -158,7 +177,7 @@ main (int argc, char **argv)
|
||||||
|
exit (-1);
|
||||||
|
}
|
||||||
|
|
||||||
|
- while ((topt = getopt (argc, argv, "D:w:b:z:f:h:?dcv")) != -1)
|
||||||
|
+ while ((topt = getopt (argc, argv, "D:Ww:b:z:f:h:?dcv")) != -1)
|
||||||
|
{
|
||||||
|
switch (topt)
|
||||||
|
{
|
||||||
|
@@ -181,6 +200,9 @@ main (int argc, char **argv)
|
||||||
|
if (bindpw == NULL)
|
||||||
|
fatal("strdup");
|
||||||
|
break;
|
||||||
|
+ case 'W':
|
||||||
|
+ bindpw = getpass("Enter LDAP Password: ");
|
||||||
|
+ break;
|
||||||
|
case 'b':
|
||||||
|
ldapbase = strdup (optarg);
|
||||||
|
if (ldapbase == NULL)
|
||||||
|
@@ -300,27 +322,62 @@ main (int argc, char **argv)
|
||||||
|
{
|
||||||
|
if (debug)
|
||||||
|
printf ("Creating base zone DN %s\n", argzone);
|
||||||
|
-
|
||||||
|
+
|
||||||
|
dc_list = hostname_to_dn_list (argzone, argzone, DNS_TOP);
|
||||||
|
- basedn = build_dn_from_dc_list (dc_list, 0, NO_SPEC);
|
||||||
|
|
||||||
|
- for (ctmp = &basedn[strlen (basedn)]; ctmp >= &basedn[0]; ctmp--)
|
||||||
|
+ basedn = build_dn_from_dc_list (dc_list, 0, NO_SPEC, argzone);
|
||||||
|
+ if (debug)
|
||||||
|
+ printf ("base DN %s\n", basedn);
|
||||||
|
+
|
||||||
|
+ for (ctmp = &basedn[strlen (basedn)], dcn=0; ctmp >= &basedn[0]; ctmp--)
|
||||||
|
{
|
||||||
|
- if ((*ctmp == ',') || (ctmp == &basedn[0]))
|
||||||
|
+ if ((*ctmp == ',') || (ctmp == &basedn[0]))
|
||||||
|
{
|
||||||
|
+
|
||||||
|
base.mod_op = LDAP_MOD_ADD;
|
||||||
|
- base.mod_type = (char*)"objectClass";
|
||||||
|
- base.mod_values = (char**)topObjectClasses;
|
||||||
|
+ base.mod_type = objectClass;
|
||||||
|
+ base.mod_values = topObjectClasses;
|
||||||
|
base_attrs[0] = (void*)&base;
|
||||||
|
- base_attrs[1] = NULL;
|
||||||
|
-
|
||||||
|
+
|
||||||
|
+ dcBase.mod_op = LDAP_MOD_ADD;
|
||||||
|
+ dcBase.mod_type = dc;
|
||||||
|
+ dcp[0]=dc_list[dcn];
|
||||||
|
+ dcp[1]=0L;
|
||||||
|
+ dcBase.mod_values=dcp;
|
||||||
|
+ base_attrs[1] = (void*)&dcBase;
|
||||||
|
+
|
||||||
|
+ znBase.mod_op = LDAP_MOD_ADD;
|
||||||
|
+ znBase.mod_type = zoneName;
|
||||||
|
+ for( zdn = dcn, znlen = 0; zdn >= 0; zdn-- )
|
||||||
|
+ znlen += strlen(dc_list[zdn])+1;
|
||||||
|
+ znp[0] = (char*)malloc(znlen+1);
|
||||||
|
+ znp[1] = 0L;
|
||||||
|
+ for( zdn = dcn, zn=znp[0]; zdn >= 0; zdn-- )
|
||||||
|
+ zn+=sprintf(zn,"%s%s",dc_list[zdn],
|
||||||
|
+ ((zdn > 0) && (*(dc_list[zdn-1])!='.')) ? "." : ""
|
||||||
|
+ );
|
||||||
|
+
|
||||||
|
+ znBase.mod_values = znp;
|
||||||
|
+ base_attrs[2] = (void*)&znBase;
|
||||||
|
+
|
||||||
|
+ rdnBase.mod_op = LDAP_MOD_ADD;
|
||||||
|
+ rdnBase.mod_type = relativeDomainName;
|
||||||
|
+ rdn[0] = strdup(sameZone);
|
||||||
|
+ rdn[1] = 0L;
|
||||||
|
+ rdnBase.mod_values = rdn;
|
||||||
|
+ base_attrs[3] = (void*)&rdnBase;
|
||||||
|
+
|
||||||
|
+ dcn++;
|
||||||
|
+
|
||||||
|
+ base.mod_values = topObjectClasses;
|
||||||
|
+ base_attrs[4] = NULL;
|
||||||
|
+
|
||||||
|
if (ldapbase)
|
||||||
|
{
|
||||||
|
if (ctmp != &basedn[0])
|
||||||
|
sprintf (fullbasedn, "%s,%s", ctmp + 1, ldapbase);
|
||||||
|
else
|
||||||
|
- sprintf (fullbasedn, "%s,%s", ctmp, ldapbase);
|
||||||
|
-
|
||||||
|
+ sprintf (fullbasedn, "%s,%s", ctmp, ldapbase);
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
@@ -329,8 +386,13 @@ main (int argc, char **argv)
|
||||||
|
else
|
||||||
|
sprintf (fullbasedn, "%s", ctmp);
|
||||||
|
}
|
||||||
|
+
|
||||||
|
+ if( debug )
|
||||||
|
+ printf("Full base dn: %s\n", fullbasedn);
|
||||||
|
+
|
||||||
|
result = ldap_add_s (conn, fullbasedn, base_attrs);
|
||||||
|
ldap_result_check ("intial ldap_add_s", fullbasedn, result);
|
||||||
|
+
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
||||||
|
@@ -408,14 +470,14 @@ generate_ldap (dns_name_t * dnsname, dns_rdata_t * rdata, unsigned int ttl)
|
||||||
|
isc_result_check (result, "dns_rdata_totext");
|
||||||
|
data[isc_buffer_usedlength (&buff)] = 0;
|
||||||
|
|
||||||
|
- dc_list = hostname_to_dn_list (name, argzone, DNS_OBJECT);
|
||||||
|
+ dc_list = hostname_to_dn_list ((char*)name, argzone, DNS_OBJECT);
|
||||||
|
len = (get_attr_list_size (dc_list) - 2);
|
||||||
|
- dn = build_dn_from_dc_list (dc_list, ttl, WI_SPEC);
|
||||||
|
+ dn = build_dn_from_dc_list (dc_list, ttl, WI_SPEC, argzone);
|
||||||
|
|
||||||
|
if (debug)
|
||||||
|
printf ("Adding %s (%s %s) to run queue list.\n", dn, type, data);
|
||||||
|
|
||||||
|
- add_to_rr_list (dn, dc_list[len], type, data, ttl, DNS_OBJECT);
|
||||||
|
+ add_to_rr_list (dn, dc_list[len], (char*)type, (char*)data, ttl, DNS_OBJECT);
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
@@ -455,7 +517,8 @@ add_to_rr_list (char *dn, char *name, char *type,
|
||||||
|
int attrlist;
|
||||||
|
char ldap_type_buffer[128];
|
||||||
|
char charttl[64];
|
||||||
|
-
|
||||||
|
+ char *zn;
|
||||||
|
+ int znlen;
|
||||||
|
|
||||||
|
if ((tmp = locate_by_dn (dn)) == NULL)
|
||||||
|
{
|
||||||
|
@@ -482,13 +545,13 @@ add_to_rr_list (char *dn, char *name, char *type,
|
||||||
|
fatal("malloc");
|
||||||
|
}
|
||||||
|
tmp->attrs[0]->mod_op = LDAP_MOD_ADD;
|
||||||
|
- tmp->attrs[0]->mod_type = (char*)"objectClass";
|
||||||
|
+ tmp->attrs[0]->mod_type = objectClass;
|
||||||
|
|
||||||
|
if (flags == DNS_OBJECT)
|
||||||
|
- tmp->attrs[0]->mod_values = (char**)objectClasses;
|
||||||
|
+ tmp->attrs[0]->mod_values = objectClasses;
|
||||||
|
else
|
||||||
|
{
|
||||||
|
- tmp->attrs[0]->mod_values = (char**)topObjectClasses;
|
||||||
|
+ tmp->attrs[0]->mod_values =topObjectClasses;
|
||||||
|
tmp->attrs[1] = NULL;
|
||||||
|
tmp->attrcnt = 2;
|
||||||
|
tmp->next = ldap_info_base;
|
||||||
|
@@ -497,7 +560,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
||||||
|
}
|
||||||
|
|
||||||
|
tmp->attrs[1]->mod_op = LDAP_MOD_ADD;
|
||||||
|
- tmp->attrs[1]->mod_type = (char*)"relativeDomainName";
|
||||||
|
+ tmp->attrs[1]->mod_type = relativeDomainName;
|
||||||
|
tmp->attrs[1]->mod_values = (char **) calloc (sizeof (char *), 2);
|
||||||
|
|
||||||
|
if (tmp->attrs[1]->mod_values == (char **)NULL)
|
||||||
|
@@ -526,7 +589,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
||||||
|
fatal("strdup");
|
||||||
|
|
||||||
|
tmp->attrs[3]->mod_op = LDAP_MOD_ADD;
|
||||||
|
- tmp->attrs[3]->mod_type = (char*)"dNSTTL";
|
||||||
|
+ tmp->attrs[3]->mod_type = dNSTTL;
|
||||||
|
tmp->attrs[3]->mod_values = (char **) calloc (sizeof (char *), 2);
|
||||||
|
|
||||||
|
if (tmp->attrs[3]->mod_values == (char **)NULL)
|
||||||
|
@@ -539,14 +602,25 @@ add_to_rr_list (char *dn, char *name, char *type,
|
||||||
|
if (tmp->attrs[3]->mod_values[0] == NULL)
|
||||||
|
fatal("strdup");
|
||||||
|
|
||||||
|
+ znlen=strlen(gbl_zone);
|
||||||
|
+ if ( *(gbl_zone + (znlen-1)) == '.' )
|
||||||
|
+ { /* ldapdb MUST search by relative zone name */
|
||||||
|
+ zn = (char*)malloc(znlen);
|
||||||
|
+ strncpy(zn,gbl_zone,znlen-1);
|
||||||
|
+ *(zn + (znlen-1))='\0';
|
||||||
|
+ }else
|
||||||
|
+ {
|
||||||
|
+ zn = gbl_zone;
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
tmp->attrs[4]->mod_op = LDAP_MOD_ADD;
|
||||||
|
- tmp->attrs[4]->mod_type = (char*)"zoneName";
|
||||||
|
+ tmp->attrs[4]->mod_type = zoneName;
|
||||||
|
tmp->attrs[4]->mod_values = (char **)calloc(sizeof(char *), 2);
|
||||||
|
|
||||||
|
if (tmp->attrs[4]->mod_values == (char **)NULL)
|
||||||
|
fatal("calloc");
|
||||||
|
|
||||||
|
- tmp->attrs[4]->mod_values[0] = gbl_zone;
|
||||||
|
+ tmp->attrs[4]->mod_values[0] = zn;
|
||||||
|
tmp->attrs[4]->mod_values[1] = NULL;
|
||||||
|
|
||||||
|
tmp->attrs[5] = NULL;
|
||||||
|
@@ -557,7 +631,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
||||||
|
else
|
||||||
|
{
|
||||||
|
|
||||||
|
- for (i = 0; tmp->attrs[i] != NULL; i++)
|
||||||
|
+ for (i = 0; tmp->attrs[i] != NULL; i++)
|
||||||
|
{
|
||||||
|
sprintf (ldap_type_buffer, "%sRecord", type);
|
||||||
|
if (!strncmp
|
||||||
|
@@ -631,44 +705,70 @@ char **
|
||||||
|
hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
||||||
|
{
|
||||||
|
char *tmp;
|
||||||
|
- static char *dn_buffer[64];
|
||||||
|
int i = 0;
|
||||||
|
- char *zname;
|
||||||
|
- char *hnamebuff;
|
||||||
|
-
|
||||||
|
- zname = strdup (hostname);
|
||||||
|
- if (zname == NULL)
|
||||||
|
- fatal("strdup");
|
||||||
|
-
|
||||||
|
- if (flags == DNS_OBJECT)
|
||||||
|
- {
|
||||||
|
-
|
||||||
|
- if (strlen (zname) != strlen (zone))
|
||||||
|
- {
|
||||||
|
- tmp = &zname[strlen (zname) - strlen (zone)];
|
||||||
|
- *--tmp = '\0';
|
||||||
|
- hnamebuff = strdup (zname);
|
||||||
|
- if (hnamebuff == NULL)
|
||||||
|
- fatal("strdup");
|
||||||
|
- zname = ++tmp;
|
||||||
|
- }
|
||||||
|
- else
|
||||||
|
- hnamebuff = (char*)"@";
|
||||||
|
- }
|
||||||
|
- else
|
||||||
|
- {
|
||||||
|
- zname = zone;
|
||||||
|
- hnamebuff = NULL;
|
||||||
|
- }
|
||||||
|
-
|
||||||
|
- for (tmp = strrchr (zname, '.'); tmp != (char *) 0;
|
||||||
|
- tmp = strrchr (zname, '.'))
|
||||||
|
- {
|
||||||
|
- *tmp++ = '\0';
|
||||||
|
- dn_buffer[i++] = tmp;
|
||||||
|
- }
|
||||||
|
- dn_buffer[i++] = zname;
|
||||||
|
- dn_buffer[i++] = hnamebuff;
|
||||||
|
+ char *hname=0L, *last=0L;
|
||||||
|
+ int hlen=strlen(hostname), zlen=(strlen(zone));
|
||||||
|
+
|
||||||
|
+/* printf("hostname: %s zone: %s\n",hostname, zone); */
|
||||||
|
+ hname=0L;
|
||||||
|
+ if(flags == DNS_OBJECT)
|
||||||
|
+ {
|
||||||
|
+ if( (zone[ zlen - 1 ] == '.') && (hostname[hlen - 1] != '.') )
|
||||||
|
+ {
|
||||||
|
+ hname=(char*)malloc(hlen + 1);
|
||||||
|
+ hlen += 1;
|
||||||
|
+ sprintf(hname, "%s.", hostname);
|
||||||
|
+ hostname = hname;
|
||||||
|
+ }
|
||||||
|
+ if(strcmp(hostname, zone) == 0)
|
||||||
|
+ {
|
||||||
|
+ if( hname == 0 )
|
||||||
|
+ hname=strdup(hostname);
|
||||||
|
+ last = strdup(sameZone);
|
||||||
|
+ }else
|
||||||
|
+ {
|
||||||
|
+ if( (hlen < zlen)
|
||||||
|
+ ||( strcmp( hostname + (hlen - zlen), zone ) != 0)
|
||||||
|
+ )
|
||||||
|
+ {
|
||||||
|
+ if( hname != 0 )
|
||||||
|
+ free(hname);
|
||||||
|
+ hname=(char*)malloc( hlen + zlen + 1);
|
||||||
|
+ if( *zone == '.' )
|
||||||
|
+ sprintf(hname, "%s%s", hostname, zone);
|
||||||
|
+ else
|
||||||
|
+ sprintf(hname,"%s",zone);
|
||||||
|
+ }else
|
||||||
|
+ {
|
||||||
|
+ if( hname == 0 )
|
||||||
|
+ hname = strdup(hostname);
|
||||||
|
+ }
|
||||||
|
+ last = hname;
|
||||||
|
+ }
|
||||||
|
+ }else
|
||||||
|
+ { /* flags == DNS_TOP */
|
||||||
|
+ hname = strdup(zone);
|
||||||
|
+ last = hname;
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
+ for (tmp = strrchr (hname, '.'); tmp != (char *) 0;
|
||||||
|
+ tmp = strrchr (hname, '.'))
|
||||||
|
+ {
|
||||||
|
+ if( *( tmp + 1 ) != '\0' )
|
||||||
|
+ {
|
||||||
|
+ *tmp = '\0';
|
||||||
|
+ dn_buffer[i++] = ++tmp;
|
||||||
|
+ }else
|
||||||
|
+ { /* trailing '.' ! */
|
||||||
|
+ dn_buffer[i++] = strdup(".");
|
||||||
|
+ *tmp = '\0';
|
||||||
|
+ if( tmp == hname )
|
||||||
|
+ break;
|
||||||
|
+ }
|
||||||
|
+ }
|
||||||
|
+ if( ( last != hname ) && (tmp != hname) )
|
||||||
|
+ dn_buffer[i++] = hname;
|
||||||
|
+ dn_buffer[i++] = last;
|
||||||
|
dn_buffer[i] = NULL;
|
||||||
|
|
||||||
|
return dn_buffer;
|
||||||
|
@@ -680,24 +780,32 @@ hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
||||||
|
* exception of "@"/SOA. */
|
||||||
|
|
||||||
|
char *
|
||||||
|
-build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag)
|
||||||
|
+build_dn_from_dc_list (char **dc_list, unsigned int ttl, int flag, char *zone)
|
||||||
|
{
|
||||||
|
int size;
|
||||||
|
- int x;
|
||||||
|
+ int x, znlen;
|
||||||
|
static char dn[1024];
|
||||||
|
char tmp[128];
|
||||||
|
+ char zn[DNS_NAME_MAXTEXT+1];
|
||||||
|
|
||||||
|
bzero (tmp, sizeof (tmp));
|
||||||
|
bzero (dn, sizeof (dn));
|
||||||
|
size = get_attr_list_size (dc_list);
|
||||||
|
+ znlen = strlen(zone);
|
||||||
|
+ if ( *(zone + (znlen-1)) == '.' )
|
||||||
|
+ { /* ldapdb MUST search by relative zone name */
|
||||||
|
+ memcpy(&(zn[0]),zone,znlen-1);
|
||||||
|
+ *(zn + (znlen-1))='\0';
|
||||||
|
+ zone = zn;
|
||||||
|
+ }
|
||||||
|
for (x = size - 2; x > 0; x--)
|
||||||
|
{
|
||||||
|
if (flag == WI_SPEC)
|
||||||
|
{
|
||||||
|
if (x == (size - 2) && (strncmp (dc_list[x], "@", 1) == 0) && (ttl))
|
||||||
|
- sprintf (tmp, "relativeDomainName=%s + dNSTTL=%u,", dc_list[x], ttl);
|
||||||
|
+ sprintf (tmp, "zoneName=%s + relativeDomainName=%s,", zone, dc_list[x]);
|
||||||
|
else if (x == (size - 2))
|
||||||
|
- sprintf(tmp, "relativeDomainName=%s,",dc_list[x]);
|
||||||
|
+ sprintf(tmp, "zoneName=%s + relativeDomainName=%s,", zone, dc_list[x]);
|
||||||
|
else
|
||||||
|
sprintf(tmp,"dc=%s,", dc_list[x]);
|
||||||
|
}
|
||||||
|
@@ -723,6 +831,7 @@ void
|
||||||
|
init_ldap_conn ()
|
||||||
|
{
|
||||||
|
int result;
|
||||||
|
+ char ldb_tag[]="LDAP Bind";
|
||||||
|
conn = ldap_open (ldapsystem, LDAP_PORT);
|
||||||
|
if (conn == NULL)
|
||||||
|
{
|
||||||
|
@@ -732,7 +841,7 @@ init_ldap_conn ()
|
||||||
|
}
|
||||||
|
|
||||||
|
result = ldap_simple_bind_s (conn, binddn, bindpw);
|
||||||
|
- ldap_result_check ("ldap_simple_bind_s", (char*)"LDAP Bind", result);
|
||||||
|
+ ldap_result_check ("ldap_simple_bind_s", ldb_tag , result);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Like isc_result_check, only for LDAP */
|
||||||
|
@@ -749,8 +858,6 @@ ldap_result_check (const char *msg, char *dn, int err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
-
|
||||||
|
-
|
||||||
|
/* For running the ldap_info run queue. */
|
||||||
|
void
|
||||||
|
add_ldap_values (ldap_info * ldinfo)
|
||||||
|
@@ -758,14 +865,14 @@ add_ldap_values (ldap_info * ldinfo)
|
||||||
|
int result;
|
||||||
|
char dnbuffer[1024];
|
||||||
|
|
||||||
|
-
|
||||||
|
if (ldapbase != NULL)
|
||||||
|
sprintf (dnbuffer, "%s,%s", ldinfo->dn, ldapbase);
|
||||||
|
else
|
||||||
|
sprintf (dnbuffer, "%s", ldinfo->dn);
|
||||||
|
|
||||||
|
result = ldap_add_s (conn, dnbuffer, ldinfo->attrs);
|
||||||
|
- ldap_result_check ("ldap_add_s", dnbuffer, result);
|
||||||
|
+ ldap_result_check ("ldap_add_s", dnbuffer, result);
|
||||||
|
+
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
@@ -776,5 +883,5 @@ void
|
||||||
|
usage ()
|
||||||
|
{
|
||||||
|
fprintf (stderr,
|
||||||
|
- "zone2ldap -D [BIND DN] -w [BIND PASSWORD] -b [BASE DN] -z [ZONE] -f [ZONE FILE] -h [LDAP HOST] "
|
||||||
|
+ "zone2ldap -D [BIND DN] [-w BIND PASSWORD | -W:prompt] -b [BASE DN] -z [ZONE] -f [ZONE FILE] -h [LDAP HOST] "
|
||||||
|
"[-c Create LDAP Base structure][-d Debug Output (lots !)] \n ");}
|
||||||
230
bind-9.3.2b2-sdbsrc.patch
Normal file
230
bind-9.3.2b2-sdbsrc.patch
Normal file
|
|
@ -0,0 +1,230 @@
|
||||||
|
diff --git a/contrib/sdb/bdb/bdb.c b/contrib/sdb/bdb/bdb.c
|
||||||
|
index 23594bb..b3c6619 100644
|
||||||
|
--- a/contrib/sdb/bdb/bdb.c
|
||||||
|
+++ b/contrib/sdb/bdb/bdb.c
|
||||||
|
@@ -43,7 +43,7 @@
|
||||||
|
#include <dns/lib.h>
|
||||||
|
#include <dns/ttl.h>
|
||||||
|
|
||||||
|
-#include <named/bdb.h>
|
||||||
|
+#include "bdb.h"
|
||||||
|
#include <named/globals.h>
|
||||||
|
#include <named/config.h>
|
||||||
|
|
||||||
|
diff --git a/contrib/sdb/ldap/zone2ldap.c b/contrib/sdb/ldap/zone2ldap.c
|
||||||
|
index 07c89bc..23dd873 100644
|
||||||
|
--- a/contrib/sdb/ldap/zone2ldap.c
|
||||||
|
+++ b/contrib/sdb/ldap/zone2ldap.c
|
||||||
|
@@ -63,16 +63,16 @@ typedef struct LDAP_INFO
|
||||||
|
ldap_info;
|
||||||
|
|
||||||
|
/* usage Info */
|
||||||
|
-void usage ();
|
||||||
|
+void usage (void);
|
||||||
|
|
||||||
|
/* Add to the ldap dit */
|
||||||
|
void add_ldap_values (ldap_info * ldinfo);
|
||||||
|
|
||||||
|
/* Init an ldap connection */
|
||||||
|
-void init_ldap_conn ();
|
||||||
|
+void init_ldap_conn (void);
|
||||||
|
|
||||||
|
/* Ldap error checking */
|
||||||
|
-void ldap_result_check (char *msg, char *dn, int err);
|
||||||
|
+void ldap_result_check (const char *msg, char *dn, int err);
|
||||||
|
|
||||||
|
/* Put a hostname into a char ** array */
|
||||||
|
char **hostname_to_dn_list (char *hostname, char *zone, unsigned int flags);
|
||||||
|
@@ -88,7 +88,7 @@ void add_to_rr_list (char *dn, char *name, char *type, char *data,
|
||||||
|
unsigned int ttl, unsigned int flags);
|
||||||
|
|
||||||
|
/* Error checking */
|
||||||
|
-void isc_result_check (isc_result_t res, char *errorstr);
|
||||||
|
+void isc_result_check (isc_result_t res, const char *errorstr);
|
||||||
|
|
||||||
|
/* Generate LDIF Format files */
|
||||||
|
void generate_ldap (dns_name_t * dnsname, dns_rdata_t * rdata,
|
||||||
|
@@ -97,11 +97,17 @@ void generate_ldap (dns_name_t * dnsname, dns_rdata_t * rdata,
|
||||||
|
/* head pointer to the list */
|
||||||
|
ldap_info *ldap_info_base = NULL;
|
||||||
|
|
||||||
|
+ldap_info *
|
||||||
|
+locate_by_dn (char *dn);
|
||||||
|
+void
|
||||||
|
+init_ldap_conn ();
|
||||||
|
+void usage();
|
||||||
|
+
|
||||||
|
char *argzone, *ldapbase, *binddn, *bindpw = NULL;
|
||||||
|
-char *ldapsystem = "localhost";
|
||||||
|
-static char *objectClasses[] =
|
||||||
|
+const char *ldapsystem = "localhost";
|
||||||
|
+static const char *objectClasses[] =
|
||||||
|
{ "top", "dNSZone", NULL };
|
||||||
|
-static char *topObjectClasses[] = { "top", NULL };
|
||||||
|
+static const char *topObjectClasses[] = { "top", NULL };
|
||||||
|
LDAP *conn;
|
||||||
|
unsigned int debug = 0;
|
||||||
|
|
||||||
|
@@ -128,7 +134,7 @@ main (int argc, char **argv)
|
||||||
|
LDAPMod *base_attrs[2];
|
||||||
|
LDAPMod base;
|
||||||
|
isc_buffer_t buff;
|
||||||
|
- char *zonefile;
|
||||||
|
+ char *zonefile=0L;
|
||||||
|
char fullbasedn[1024];
|
||||||
|
char *ctmp;
|
||||||
|
dns_fixedname_t fixedzone, fixedname;
|
||||||
|
@@ -304,9 +310,9 @@ main (int argc, char **argv)
|
||||||
|
if ((*ctmp == ',') || (ctmp == &basedn[0]))
|
||||||
|
{
|
||||||
|
base.mod_op = LDAP_MOD_ADD;
|
||||||
|
- base.mod_type = "objectClass";
|
||||||
|
- base.mod_values = topObjectClasses;
|
||||||
|
- base_attrs[0] = &base;
|
||||||
|
+ base.mod_type = (char*)"objectClass";
|
||||||
|
+ base.mod_values = (char**)topObjectClasses;
|
||||||
|
+ base_attrs[0] = (void*)&base;
|
||||||
|
base_attrs[1] = NULL;
|
||||||
|
|
||||||
|
if (ldapbase)
|
||||||
|
@@ -363,7 +369,7 @@ main (int argc, char **argv)
|
||||||
|
* I should probably rename this function, as not to cause any
|
||||||
|
* confusion with the isc* routines. Will exit on error. */
|
||||||
|
void
|
||||||
|
-isc_result_check (isc_result_t res, char *errorstr)
|
||||||
|
+isc_result_check (isc_result_t res, const char *errorstr)
|
||||||
|
{
|
||||||
|
if (res != ISC_R_SUCCESS)
|
||||||
|
{
|
||||||
|
@@ -470,20 +476,20 @@ add_to_rr_list (char *dn, char *name, char *type,
|
||||||
|
if (tmp->attrs == (LDAPMod **) NULL)
|
||||||
|
fatal("calloc");
|
||||||
|
|
||||||
|
- for (i = 0; i < flags; i++)
|
||||||
|
+ for (i = 0; i < (int)flags; i++)
|
||||||
|
{
|
||||||
|
tmp->attrs[i] = (LDAPMod *) malloc (sizeof (LDAPMod));
|
||||||
|
if (tmp->attrs[i] == (LDAPMod *) NULL)
|
||||||
|
fatal("malloc");
|
||||||
|
}
|
||||||
|
tmp->attrs[0]->mod_op = LDAP_MOD_ADD;
|
||||||
|
- tmp->attrs[0]->mod_type = "objectClass";
|
||||||
|
+ tmp->attrs[0]->mod_type = (char*)"objectClass";
|
||||||
|
|
||||||
|
if (flags == DNS_OBJECT)
|
||||||
|
- tmp->attrs[0]->mod_values = objectClasses;
|
||||||
|
+ tmp->attrs[0]->mod_values = (char**)objectClasses;
|
||||||
|
else
|
||||||
|
{
|
||||||
|
- tmp->attrs[0]->mod_values = topObjectClasses;
|
||||||
|
+ tmp->attrs[0]->mod_values = (char**)topObjectClasses;
|
||||||
|
tmp->attrs[1] = NULL;
|
||||||
|
tmp->attrcnt = 2;
|
||||||
|
tmp->next = ldap_info_base;
|
||||||
|
@@ -492,7 +498,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
||||||
|
}
|
||||||
|
|
||||||
|
tmp->attrs[1]->mod_op = LDAP_MOD_ADD;
|
||||||
|
- tmp->attrs[1]->mod_type = "relativeDomainName";
|
||||||
|
+ tmp->attrs[1]->mod_type = (char*)"relativeDomainName";
|
||||||
|
tmp->attrs[1]->mod_values = (char **) calloc (sizeof (char *), 2);
|
||||||
|
|
||||||
|
if (tmp->attrs[1]->mod_values == (char **)NULL)
|
||||||
|
@@ -521,7 +527,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
||||||
|
fatal("strdup");
|
||||||
|
|
||||||
|
tmp->attrs[3]->mod_op = LDAP_MOD_ADD;
|
||||||
|
- tmp->attrs[3]->mod_type = "dNSTTL";
|
||||||
|
+ tmp->attrs[3]->mod_type = (char*)"dNSTTL";
|
||||||
|
tmp->attrs[3]->mod_values = (char **) calloc (sizeof (char *), 2);
|
||||||
|
|
||||||
|
if (tmp->attrs[3]->mod_values == (char **)NULL)
|
||||||
|
@@ -535,7 +541,7 @@ add_to_rr_list (char *dn, char *name, char *type,
|
||||||
|
fatal("strdup");
|
||||||
|
|
||||||
|
tmp->attrs[4]->mod_op = LDAP_MOD_ADD;
|
||||||
|
- tmp->attrs[4]->mod_type = "zoneName";
|
||||||
|
+ tmp->attrs[4]->mod_type = (char*)"zoneName";
|
||||||
|
tmp->attrs[4]->mod_values = (char **)calloc(sizeof(char *), 2);
|
||||||
|
|
||||||
|
if (tmp->attrs[4]->mod_values == (char **)NULL)
|
||||||
|
@@ -648,7 +654,7 @@ hostname_to_dn_list (char *hostname, char *zone, unsigned int flags)
|
||||||
|
zname = ++tmp;
|
||||||
|
}
|
||||||
|
else
|
||||||
|
- hnamebuff = "@";
|
||||||
|
+ hnamebuff = (char*)"@";
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
@@ -727,12 +733,12 @@ init_ldap_conn ()
|
||||||
|
}
|
||||||
|
|
||||||
|
result = ldap_simple_bind_s (conn, binddn, bindpw);
|
||||||
|
- ldap_result_check ("ldap_simple_bind_s", "LDAP Bind", result);
|
||||||
|
+ ldap_result_check ("ldap_simple_bind_s", (char*)"LDAP Bind", result);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Like isc_result_check, only for LDAP */
|
||||||
|
void
|
||||||
|
-ldap_result_check (char *msg, char *dn, int err)
|
||||||
|
+ldap_result_check (const char *msg, char *dn, int err)
|
||||||
|
{
|
||||||
|
if ((err != LDAP_SUCCESS) && (err != LDAP_ALREADY_EXISTS))
|
||||||
|
{
|
||||||
|
diff --git a/contrib/sdb/pgsql/pgsqldb.c b/contrib/sdb/pgsql/pgsqldb.c
|
||||||
|
index 50d3cba..516eb9f 100644
|
||||||
|
--- a/contrib/sdb/pgsql/pgsqldb.c
|
||||||
|
+++ b/contrib/sdb/pgsql/pgsqldb.c
|
||||||
|
@@ -23,7 +23,7 @@
|
||||||
|
#include <string.h>
|
||||||
|
#include <stdlib.h>
|
||||||
|
|
||||||
|
-#include <pgsql/libpq-fe.h>
|
||||||
|
+#include <libpq-fe.h>
|
||||||
|
|
||||||
|
#include <isc/mem.h>
|
||||||
|
#include <isc/print.h>
|
||||||
|
diff --git a/contrib/sdb/pgsql/zonetodb.c b/contrib/sdb/pgsql/zonetodb.c
|
||||||
|
index b8f5912..ff2d135 100644
|
||||||
|
--- a/contrib/sdb/pgsql/zonetodb.c
|
||||||
|
+++ b/contrib/sdb/pgsql/zonetodb.c
|
||||||
|
@@ -37,7 +37,7 @@
|
||||||
|
#include <dns/rdatatype.h>
|
||||||
|
#include <dns/result.h>
|
||||||
|
|
||||||
|
-#include <pgsql/libpq-fe.h>
|
||||||
|
+#include <libpq-fe.h>
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Generate a PostgreSQL table from a zone.
|
||||||
|
@@ -54,6 +54,9 @@ char *dbname, *dbtable;
|
||||||
|
char str[10240];
|
||||||
|
|
||||||
|
void
|
||||||
|
+closeandexit(int status);
|
||||||
|
+
|
||||||
|
+void
|
||||||
|
closeandexit(int status) {
|
||||||
|
if (conn != NULL)
|
||||||
|
PQfinish(conn);
|
||||||
|
@@ -61,6 +64,9 @@ closeandexit(int status) {
|
||||||
|
}
|
||||||
|
|
||||||
|
void
|
||||||
|
+check_result(isc_result_t result, const char *message);
|
||||||
|
+
|
||||||
|
+void
|
||||||
|
check_result(isc_result_t result, const char *message) {
|
||||||
|
if (result != ISC_R_SUCCESS) {
|
||||||
|
fprintf(stderr, "%s: %s\n", message,
|
||||||
|
@@ -84,7 +90,8 @@ quotestring(const unsigned char *source, unsigned char *dest) {
|
||||||
|
}
|
||||||
|
*dest++ = 0;
|
||||||
|
}
|
||||||
|
-
|
||||||
|
+void
|
||||||
|
+addrdata(dns_name_t *name, dns_ttl_t ttl, dns_rdata_t *rdata);
|
||||||
|
void
|
||||||
|
addrdata(dns_name_t *name, dns_ttl_t ttl, dns_rdata_t *rdata) {
|
||||||
|
unsigned char namearray[DNS_NAME_MAXTEXT + 1];
|
||||||
|
|
@ -1,28 +1,27 @@
|
||||||
From 13348a5fc64387bf53ef450688e181100d0ceddb Mon Sep 17 00:00:00 2001
|
--- bind-9.5.0b2/bin/named/Makefile.in.pie 2008-02-11 17:21:47.000000000 +0100
|
||||||
From: Petr Mensik <pemensik@redhat.com>
|
+++ bind-9.5.0b2/bin/named/Makefile.in 2008-02-11 17:22:10.000000000 +0100
|
||||||
Date: Thu, 12 Dec 2024 15:56:13 +0100
|
@@ -100,8 +100,12 @@ HTMLPAGES = named.html lwresd.html named
|
||||||
Subject: [PATCH] Harden named service build flags
|
|
||||||
|
|
||||||
---
|
|
||||||
bin/named/Makefile.am | 5 ++++-
|
|
||||||
1 file changed, 4 insertions(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/bin/named/Makefile.am b/bin/named/Makefile.am
|
|
||||||
index 57a023b..b832e9c 100644
|
|
||||||
--- a/bin/named/Makefile.am
|
|
||||||
+++ b/bin/named/Makefile.am
|
|
||||||
@@ -33,7 +33,10 @@ endif HAVE_LIBXML2
|
|
||||||
|
|
||||||
AM_CPPFLAGS += \
|
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||||
-DNAMED_LOCALSTATEDIR=\"${localstatedir}\" \
|
|
||||||
- -DNAMED_SYSCONFDIR=\"${sysconfdir}\"
|
+EXT_CFLAGS = -fpie
|
||||||
+ -DNAMED_SYSCONFDIR=\"${sysconfdir}\" \
|
|
||||||
+ -fpie
|
|
||||||
+
|
+
|
||||||
+AM_LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
@BIND9_MAKE_RULES@
|
||||||
|
|
||||||
sbin_PROGRAMS = named
|
+LDFLAGS += -pie -Wl,-z,relro,-z,now,-z,nodlopen,-z,noexecstack
|
||||||
|
+
|
||||||
|
main.@O@: main.c
|
||||||
|
${LIBTOOL_MODE_COMPILE} ${CC} ${ALL_CFLAGS} \
|
||||||
|
-DVERSION=\"${VERSION}\" \
|
||||||
|
diff -up bind-9.5.0b2/bin/named/unix/Makefile.in.pie bind-9.5.0b2/bin/named/unix/Makefile.in
|
||||||
|
--- bind-9.5.0b2/bin/named/unix/Makefile.in.pie 2008-02-11 17:22:21.000000000 +0100
|
||||||
|
+++ bind-9.5.0b2/bin/named/unix/Makefile.in 2008-02-11 17:23:00.000000000 +0100
|
||||||
|
@@ -19,6 +19,8 @@ srcdir = @srcdir@
|
||||||
|
VPATH = @srcdir@
|
||||||
|
top_srcdir = @top_srcdir@
|
||||||
|
|
||||||
--
|
+EXT_CFLAGS = -fpie
|
||||||
2.47.1
|
+
|
||||||
|
@BIND9_MAKE_INCLUDES@
|
||||||
|
|
||||||
|
CINCLUDES = -I${srcdir}/include -I${srcdir}/../include \
|
||||||
|
|
|
||||||
53
bind-9.5-dlz-64bit.patch
Normal file
53
bind-9.5-dlz-64bit.patch
Normal file
|
|
@ -0,0 +1,53 @@
|
||||||
|
diff --git a/contrib/dlz/config.dlz.in b/contrib/dlz/config.dlz.in
|
||||||
|
index 47525af..eefe3c3 100644
|
||||||
|
--- a/contrib/dlz/config.dlz.in
|
||||||
|
+++ b/contrib/dlz/config.dlz.in
|
||||||
|
@@ -17,6 +17,13 @@
|
||||||
|
#
|
||||||
|
dlzdir='${DLZ_DRIVER_DIR}'
|
||||||
|
|
||||||
|
+AC_MSG_CHECKING([for target libdir])
|
||||||
|
+AC_RUN_IFELSE([int main(void) {exit((sizeof(void *) == 8) ? 0 : 1);}],
|
||||||
|
+ [target_lib=lib64],
|
||||||
|
+ [target_lib=lib],
|
||||||
|
+)
|
||||||
|
+AC_MSG_RESULT(["$target_lib"])
|
||||||
|
+
|
||||||
|
#
|
||||||
|
# Private autoconf macro to simplify configuring drivers:
|
||||||
|
#
|
||||||
|
@@ -292,9 +299,9 @@ case "$use_dlz_bdb" in
|
||||||
|
then
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
- elif test -f "$dd/lib/lib${d}.so"
|
||||||
|
+ elif test -f "$dd/${target_lib}/lib${d}.so"
|
||||||
|
then
|
||||||
|
- dlz_bdb_libs="-L${dd}/lib -l${d}"
|
||||||
|
+ dlz_bdb_libs="-L${dd}/${target_lib} -l${d}"
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
@@ -396,7 +403,7 @@ case "$use_dlz_ldap" in
|
||||||
|
*)
|
||||||
|
DLZ_ADD_DRIVER(LDAP, dlz_ldap_driver,
|
||||||
|
[-I$use_dlz_ldap/include],
|
||||||
|
- [-L$use_dlz_ldap/lib -lldap -llber])
|
||||||
|
+ [-L$use_dlz_ldap/${target_lib} -lldap -llber])
|
||||||
|
|
||||||
|
AC_MSG_RESULT(
|
||||||
|
[using LDAP from $use_dlz_ldap/lib and $use_dlz_ldap/include])
|
||||||
|
@@ -432,11 +439,11 @@ then
|
||||||
|
odbcdirs="/usr /usr/local /usr/pkg"
|
||||||
|
for d in $odbcdirs
|
||||||
|
do
|
||||||
|
- if test -f $d/include/sql.h -a -f $d/lib/libodbc.a
|
||||||
|
+ if test -f $d/include/sql.h -a -f $d/${target_lib}/libodbc.a
|
||||||
|
then
|
||||||
|
use_dlz_odbc=$d
|
||||||
|
dlz_odbc_include="-I$use_dlz_odbc/include"
|
||||||
|
- dlz_odbc_libs="-L$use_dlz_odbc/lib -lodbc"
|
||||||
|
+ dlz_odbc_libs="-L$use_dlz_odbc/${target_lib} -lodbc"
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
done
|
||||||
31
bind-9.9.1-P2-dlz-libdb.patch
Normal file
31
bind-9.9.1-P2-dlz-libdb.patch
Normal file
|
|
@ -0,0 +1,31 @@
|
||||||
|
diff -up bind-9.10.1b1/contrib/dlz/config.dlz.in.libdb bind-9.10.1b1/contrib/dlz/config.dlz.in
|
||||||
|
--- bind-9.10.1b1/contrib/dlz/config.dlz.in.libdb 2014-08-04 12:33:09.320735111 +0200
|
||||||
|
+++ bind-9.10.1b1/contrib/dlz/config.dlz.in 2014-08-04 12:41:46.888241910 +0200
|
||||||
|
@@ -263,7 +263,7 @@ case "$use_dlz_bdb" in
|
||||||
|
# Check other locations for includes.
|
||||||
|
# Order is important (sigh).
|
||||||
|
|
||||||
|
- bdb_incdirs="/db53 /db51 /db48 /db47 /db46 /db45 /db44 /db43 /db42 /db41 /db4 /db"
|
||||||
|
+ bdb_incdirs="/db53 /db51 /db48 /db47 /db46 /db45 /db44 /db43 /db42 /db41 /db4 /libdb /db"
|
||||||
|
# include a blank element first
|
||||||
|
for d in "" $bdb_incdirs
|
||||||
|
do
|
||||||
|
@@ -288,16 +288,9 @@ case "$use_dlz_bdb" in
|
||||||
|
bdb_libnames="db53 db-5.3 db51 db-5.1 db48 db-4.8 db47 db-4.7 db46 db-4.6 db45 db-4.5 db44 db-4.4 db43 db-4.3 db42 db-4.2 db41 db-4.1 db"
|
||||||
|
for d in $bdb_libnames
|
||||||
|
do
|
||||||
|
- if test "$dd" = "/usr"
|
||||||
|
+ if test -f "$dd/${target_lib}/lib${d}.so"
|
||||||
|
then
|
||||||
|
- AC_CHECK_LIB($d, db_create, dlz_bdb_libs="-l${d}")
|
||||||
|
- if test $dlz_bdb_libs != "yes"
|
||||||
|
- then
|
||||||
|
- break
|
||||||
|
- fi
|
||||||
|
- elif test -f "$dd/${target_lib}/lib${d}.so"
|
||||||
|
- then
|
||||||
|
- dlz_bdb_libs="-L${dd}/${target_lib} -l${d}"
|
||||||
|
+ dlz_bdb_libs="-L${dd}/${target_lib}/libdb -l${d}"
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
done
|
||||||
54
bind-9.9.1-P2-multlib-conflict.patch
Normal file
54
bind-9.9.1-P2-multlib-conflict.patch
Normal file
|
|
@ -0,0 +1,54 @@
|
||||||
|
diff --git a/config.h.in b/config.h.in
|
||||||
|
index 4ecaa8f..2f65ccc 100644
|
||||||
|
--- a/config.h.in
|
||||||
|
+++ b/config.h.in
|
||||||
|
@@ -600,7 +600,7 @@ int sigwait(const unsigned int *set, int *sig);
|
||||||
|
#undef PREFER_GOSTASN1
|
||||||
|
|
||||||
|
/* The size of `void *', as computed by sizeof. */
|
||||||
|
-#undef SIZEOF_VOID_P
|
||||||
|
+/* #undef SIZEOF_VOID_P */
|
||||||
|
|
||||||
|
/* Define to 1 if you have the ANSI C header files. */
|
||||||
|
#undef STDC_HEADERS
|
||||||
|
diff --git a/isc-config.sh.in b/isc-config.sh.in
|
||||||
|
index a8a0a89..b5e94ed 100644
|
||||||
|
--- a/isc-config.sh.in
|
||||||
|
+++ b/isc-config.sh.in
|
||||||
|
@@ -13,7 +13,18 @@ prefix=@prefix@
|
||||||
|
exec_prefix=@exec_prefix@
|
||||||
|
exec_prefix_set=
|
||||||
|
includedir=@includedir@
|
||||||
|
-libdir=@libdir@
|
||||||
|
+arch=$(uname -m)
|
||||||
|
+
|
||||||
|
+case $arch in
|
||||||
|
+ x86_64 | amd64 | sparc64 | s390x | ppc64)
|
||||||
|
+ libdir=/usr/lib64
|
||||||
|
+ sec_libdir=/usr/lib
|
||||||
|
+ ;;
|
||||||
|
+ * )
|
||||||
|
+ libdir=/usr/lib
|
||||||
|
+ sec_libdir=/usr/lib64
|
||||||
|
+ ;;
|
||||||
|
+esac
|
||||||
|
|
||||||
|
usage()
|
||||||
|
{
|
||||||
|
@@ -132,6 +143,16 @@ if test x"$echo_libs" = x"true"; then
|
||||||
|
if test x"${exec_prefix_set}" = x"true"; then
|
||||||
|
libs="-L${exec_prefix}/lib"
|
||||||
|
else
|
||||||
|
+ if [ ! -x $libdir/libisc.so ] ; then
|
||||||
|
+ if [ ! -x $sec_libdir/libisc.so ] ; then
|
||||||
|
+ echo "Error: ISC libs not found in $libdir"
|
||||||
|
+ if [ -d $sec_libdir ] ; then
|
||||||
|
+ echo "Error: ISC libs not found in $sec_libdir"
|
||||||
|
+ fi
|
||||||
|
+ exit 1
|
||||||
|
+ fi
|
||||||
|
+ libdir=$sec_libdir
|
||||||
|
+ fi
|
||||||
|
libs="-L${libdir}"
|
||||||
|
fi
|
||||||
|
if test x"$libirs" = x"true" ; then
|
||||||
42
bind-95-rh452060.patch
Normal file
42
bind-95-rh452060.patch
Normal file
|
|
@ -0,0 +1,42 @@
|
||||||
|
diff --git a/bin/dig/dighost.c b/bin/dig/dighost.c
|
||||||
|
index aa5315d..1fa711a 100644
|
||||||
|
--- a/bin/dig/dighost.c
|
||||||
|
+++ b/bin/dig/dighost.c
|
||||||
|
@@ -1814,6 +1814,13 @@ clear_query(dig_query_t *query) {
|
||||||
|
|
||||||
|
if (query->timer != NULL)
|
||||||
|
isc_timer_detach(&query->timer);
|
||||||
|
+
|
||||||
|
+ if (query->waiting_senddone) {
|
||||||
|
+ debug("send_done not yet called");
|
||||||
|
+ query->pending_free = true;
|
||||||
|
+ return;
|
||||||
|
+ }
|
||||||
|
+
|
||||||
|
lookup = query->lookup;
|
||||||
|
|
||||||
|
if (lookup->current_query == query)
|
||||||
|
@@ -1839,10 +1846,7 @@ clear_query(dig_query_t *query) {
|
||||||
|
isc_mempool_put(commctx, query->recvspace);
|
||||||
|
isc_buffer_invalidate(&query->recvbuf);
|
||||||
|
isc_buffer_invalidate(&query->lengthbuf);
|
||||||
|
- if (query->waiting_senddone)
|
||||||
|
- query->pending_free = true;
|
||||||
|
- else
|
||||||
|
- isc_mem_free(mctx, query);
|
||||||
|
+ isc_mem_free(mctx, query);
|
||||||
|
}
|
||||||
|
|
||||||
|
/*%
|
||||||
|
@@ -2892,9 +2896,9 @@ send_done(isc_task_t *_task, isc_event_t *event) {
|
||||||
|
isc_event_free(&event);
|
||||||
|
|
||||||
|
if (query->pending_free)
|
||||||
|
- isc_mem_free(mctx, query);
|
||||||
|
+ clear_query(query);
|
||||||
|
|
||||||
|
- check_if_done();
|
||||||
|
+ check_next_lookup(l);
|
||||||
|
UNLOCK_LOOKUP;
|
||||||
|
}
|
||||||
|
|
||||||
23
bind-96-old-api.patch
Normal file
23
bind-96-old-api.patch
Normal file
|
|
@ -0,0 +1,23 @@
|
||||||
|
diff -up bind-9.6.0b1/contrib/sdb/ldap/ldapdb.c.old-api bind-9.6.0b1/contrib/sdb/ldap/ldapdb.c
|
||||||
|
--- bind-9.6.0b1/contrib/sdb/ldap/ldapdb.c.old-api 2008-11-24 13:28:13.000000000 +0100
|
||||||
|
+++ bind-9.6.0b1/contrib/sdb/ldap/ldapdb.c 2008-11-24 13:28:23.000000000 +0100
|
||||||
|
@@ -25,6 +25,7 @@
|
||||||
|
/* Using LDAPv3 by default, change this if you want v2 */
|
||||||
|
#ifndef LDAPDB_LDAP_VERSION
|
||||||
|
#define LDAPDB_LDAP_VERSION 3
|
||||||
|
+#define LDAP_DEPRECATED 1
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#include <config.h>
|
||||||
|
diff -up bind-9.6.0b1/contrib/sdb/ldap/zone2ldap.c.old-api bind-9.6.0b1/contrib/sdb/ldap/zone2ldap.c
|
||||||
|
--- bind-9.6.0b1/contrib/sdb/ldap/zone2ldap.c.old-api 2008-11-24 13:29:05.000000000 +0100
|
||||||
|
+++ bind-9.6.0b1/contrib/sdb/ldap/zone2ldap.c 2008-11-24 13:29:14.000000000 +0100
|
||||||
|
@@ -13,6 +13,8 @@
|
||||||
|
* ditched dNSDomain2 schema support. Version 0.3-ALPHA
|
||||||
|
*/
|
||||||
|
|
||||||
|
+#define LDAP_DEPRECATED 1
|
||||||
|
+
|
||||||
|
#include <errno.h>
|
||||||
|
#include <string.h>
|
||||||
|
#include <stdlib.h>
|
||||||
|
|
@ -1,38 +0,0 @@
|
||||||
# vim: ft=conf:
|
|
||||||
# TODO: these definitions are in different form in rpm spec %files chroot section
|
|
||||||
# find a way to have it defined only once
|
|
||||||
#defattr(0664,root,named,-)
|
|
||||||
c /var/named/chroot/dev/null 0664 root named - 1:3
|
|
||||||
c /var/named/chroot/dev/random 0664 root named - 1:8
|
|
||||||
c /var/named/chroot/dev/urandom 0664 root named - 1:9
|
|
||||||
c /var/named/chroot/dev/zero 0664 root named - 1:5
|
|
||||||
#defattr(0640,root,named,0750)
|
|
||||||
d /var/named/chroot 0750 root named -
|
|
||||||
d /var/named/chroot/dev 0750 root named -
|
|
||||||
d /var/named/chroot/etc 0750 root named -
|
|
||||||
d /var/named/chroot/etc/named 0750 root named -
|
|
||||||
d /var/named/chroot/etc/pki 0750 root named -
|
|
||||||
d /var/named/chroot/etc/pki/dnssec-keys 0750 root named -
|
|
||||||
d /var/named/chroot/etc/crypto-policies 0750 root named -
|
|
||||||
d /var/named/chroot/etc/crypto-policies/back-ends 0750 root named -
|
|
||||||
d /var/named/chroot/var 0750 root named -
|
|
||||||
d /var/named/chroot/run 0750 root named -
|
|
||||||
#defattr(-,root,root,-)
|
|
||||||
d /var/named/chroot/usr - root root -
|
|
||||||
d /var/named/chroot/usr/lib64 - root root -
|
|
||||||
d /var/named/chroot/usr/lib64/bind - root root -
|
|
||||||
d /var/named/chroot/usr/lib64/named - root root -
|
|
||||||
d /var/named/chroot/usr/share/GeoIP - root root -
|
|
||||||
d /var/named/chroot/usr/share/named - root root -
|
|
||||||
d /var/named/chroot/proc - root root -
|
|
||||||
d /var/named/chroot/proc/sys - root root -
|
|
||||||
d /var/named/chroot/proc/sys/net - root root -
|
|
||||||
d /var/named/chroot/proc/sys/net/ipv4 - root root -
|
|
||||||
#defattr(0660,root,named,01770)
|
|
||||||
d /var/named/chroot/var/named 01770 root named -
|
|
||||||
#defattr(0660,named,named,0770)
|
|
||||||
d /var/named/chroot/var/tmp 0770 named named -
|
|
||||||
d /var/named/chroot/var/log 0770 named named -
|
|
||||||
#defattr(-,named,named,-)
|
|
||||||
d /var/named/chroot/run/named - named named -
|
|
||||||
L /var/named/chroot/var/run - named named - ../run
|
|
||||||
48
bind-rh1663318.patch
Normal file
48
bind-rh1663318.patch
Normal file
|
|
@ -0,0 +1,48 @@
|
||||||
|
From b16a1ff25644bb075f454afe68ee63f6f385ca9c Mon Sep 17 00:00:00 2001
|
||||||
|
From: =?UTF-8?q?Petr=20Men=C5=A1=C3=ADk?= <pemensik@redhat.com>
|
||||||
|
Date: Wed, 23 Jan 2019 21:11:07 +0100
|
||||||
|
Subject: [PATCH] Made RAND_status check optional (broke --disable-crypto-rand)
|
||||||
|
MIME-Version: 1.0
|
||||||
|
Content-Type: text/plain; charset=UTF-8
|
||||||
|
Content-Transfer-Encoding: 8bit
|
||||||
|
|
||||||
|
Unlike upstream, skip it also for DHCP.
|
||||||
|
|
||||||
|
Disable RAND_status also in non-threaded builds. DHCP is built without
|
||||||
|
threads and should not check RAND_status on dns library initialization.
|
||||||
|
Lack of entropy is possible state for dhclient, but it must not fail
|
||||||
|
even in this case. Because DHCP itself does not require custom random
|
||||||
|
generator, leave default RAND_OpenSSL configured. It should help TLS
|
||||||
|
connection to LDAP in single DHCP binary, while keeping secure random
|
||||||
|
data if needed.
|
||||||
|
|
||||||
|
(modified upstream commit 8a98277811ea50035ff37b744fa3dc5b75bee099)
|
||||||
|
|
||||||
|
Signed-off-by: Petr Menšík <pemensik@redhat.com>
|
||||||
|
---
|
||||||
|
lib/dns/openssl_link.c | 2 ++
|
||||||
|
1 file changed, 2 insertions(+)
|
||||||
|
|
||||||
|
diff --git a/lib/dns/openssl_link.c b/lib/dns/openssl_link.c
|
||||||
|
index 7a233dd..941eb17 100644
|
||||||
|
--- a/lib/dns/openssl_link.c
|
||||||
|
+++ b/lib/dns/openssl_link.c
|
||||||
|
@@ -289,6 +289,7 @@ dst__openssl_init(const char *engine) {
|
||||||
|
#endif
|
||||||
|
#endif /* !defined(OPENSSL_NO_ENGINE) */
|
||||||
|
|
||||||
|
+#if defined(ISC_PLATFORM_CRYPTORANDOM) && defined(ISC_PLATFORM_USETHREADS)
|
||||||
|
/* Protect ourselves against unseeded PRNG */
|
||||||
|
if (RAND_status() != 1) {
|
||||||
|
FATAL_ERROR(__FILE__, __LINE__,
|
||||||
|
@@ -296,6 +297,7 @@ dst__openssl_init(const char *engine) {
|
||||||
|
"cannot be initialized (see the `PRNG not "
|
||||||
|
"seeded' message in the OpenSSL FAQ)");
|
||||||
|
}
|
||||||
|
+#endif
|
||||||
|
|
||||||
|
return (ISC_R_SUCCESS);
|
||||||
|
|
||||||
|
--
|
||||||
|
2.20.1
|
||||||
|
|
||||||
|
|
@ -1,10 +1 @@
|
||||||
# vim: ft=conf:
|
|
||||||
d /run/named 0755 named named -
|
d /run/named 0755 named named -
|
||||||
d /var/named 01770 root named -
|
|
||||||
d /var/named/slaves 0770 named named -
|
|
||||||
d /var/named/data 0770 named named -
|
|
||||||
d /var/named/dynamic 0770 named named -
|
|
||||||
L /var/named/named.ca 0640 named named - ../../../etc/named.ca
|
|
||||||
L /var/named/named.localhost 0640 named named - ../../../usr/share/named/named.localhost
|
|
||||||
L /var/named/named.loopback 0640 named named - ../../../usr/share/named/named.loopback
|
|
||||||
L /var/named/named.empty 0640 named named - ../../../usr/share/named/named.empty
|
|
||||||
|
|
|
||||||
81
bind93-rh490837.patch
Normal file
81
bind93-rh490837.patch
Normal file
|
|
@ -0,0 +1,81 @@
|
||||||
|
diff --git a/lib/isc/include/isc/stdio.h b/lib/isc/include/isc/stdio.h
|
||||||
|
index 1f44b5a..a3625f9 100644
|
||||||
|
--- a/lib/isc/include/isc/stdio.h
|
||||||
|
+++ b/lib/isc/include/isc/stdio.h
|
||||||
|
@@ -69,6 +69,9 @@ isc_stdio_sync(FILE *f);
|
||||||
|
* direct counterpart in the stdio library.
|
||||||
|
*/
|
||||||
|
|
||||||
|
+isc_result_t
|
||||||
|
+isc_stdio_fgetc(FILE *f, int *ret);
|
||||||
|
+
|
||||||
|
ISC_LANG_ENDDECLS
|
||||||
|
|
||||||
|
#endif /* ISC_STDIO_H */
|
||||||
|
diff --git a/lib/isc/lex.c b/lib/isc/lex.c
|
||||||
|
index a8955bc..fc6103b 100644
|
||||||
|
--- a/lib/isc/lex.c
|
||||||
|
+++ b/lib/isc/lex.c
|
||||||
|
@@ -434,17 +434,14 @@ isc_lex_gettoken(isc_lex_t *lex, unsigned int options, isc_token_t *tokenp) {
|
||||||
|
if (source->is_file) {
|
||||||
|
stream = source->input;
|
||||||
|
|
||||||
|
-#if defined(HAVE_FLOCKFILE) && defined(HAVE_GETCUNLOCKED)
|
||||||
|
- c = getc_unlocked(stream);
|
||||||
|
-#else
|
||||||
|
- c = getc(stream);
|
||||||
|
-#endif
|
||||||
|
- if (c == EOF) {
|
||||||
|
- if (ferror(stream)) {
|
||||||
|
- source->result = ISC_R_IOERROR;
|
||||||
|
- result = source->result;
|
||||||
|
+ result = isc_stdio_fgetc(stream, &c);
|
||||||
|
+
|
||||||
|
+ if (result != ISC_R_SUCCESS) {
|
||||||
|
+ if (result != ISC_R_EOF) {
|
||||||
|
+ source->result = result;
|
||||||
|
goto done;
|
||||||
|
}
|
||||||
|
+
|
||||||
|
source->at_eof = true;
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
diff --git a/lib/isc/unix/errno2result.c b/lib/isc/unix/errno2result.c
|
||||||
|
index 2f12bcc..5bfd648 100644
|
||||||
|
--- a/lib/isc/unix/errno2result.c
|
||||||
|
+++ b/lib/isc/unix/errno2result.c
|
||||||
|
@@ -40,6 +40,7 @@ isc___errno2result(int posixerrno, bool dolog,
|
||||||
|
case EINVAL: /* XXX sometimes this is not for files */
|
||||||
|
case ENAMETOOLONG:
|
||||||
|
case EBADF:
|
||||||
|
+ case EISDIR:
|
||||||
|
return (ISC_R_INVALIDFILE);
|
||||||
|
case ENOENT:
|
||||||
|
return (ISC_R_FILENOTFOUND);
|
||||||
|
diff --git a/lib/isc/unix/stdio.c b/lib/isc/unix/stdio.c
|
||||||
|
index e60fa65..77f0b13 100644
|
||||||
|
--- a/lib/isc/unix/stdio.c
|
||||||
|
+++ b/lib/isc/unix/stdio.c
|
||||||
|
@@ -149,3 +149,22 @@ isc_stdio_sync(FILE *f) {
|
||||||
|
return (isc__errno2result(errno));
|
||||||
|
}
|
||||||
|
|
||||||
|
+isc_result_t
|
||||||
|
+isc_stdio_fgetc(FILE *f, int *ret) {
|
||||||
|
+ int r;
|
||||||
|
+ isc_result_t result = ISC_R_SUCCESS;
|
||||||
|
+
|
||||||
|
+#if defined(HAVE_FLOCKFILE) && defined(HAVE_GETCUNLOCKED)
|
||||||
|
+ r = fgetc_unlocked(f);
|
||||||
|
+#else
|
||||||
|
+ r = fgets(f);
|
||||||
|
+#endif
|
||||||
|
+
|
||||||
|
+ if (r == EOF)
|
||||||
|
+ result = ferror(f) ? isc__errno2result(errno) : ISC_R_EOF;
|
||||||
|
+
|
||||||
|
+ *ret = r;
|
||||||
|
+
|
||||||
|
+ return result;
|
||||||
|
+}
|
||||||
|
+
|
||||||
51
bind97-rh478718.patch
Normal file
51
bind97-rh478718.patch
Normal file
|
|
@ -0,0 +1,51 @@
|
||||||
|
diff --git a/configure.ac b/configure.ac
|
||||||
|
index 26c509e..c1bfd62 100644
|
||||||
|
--- a/configure.ac
|
||||||
|
+++ b/configure.ac
|
||||||
|
@@ -4152,6 +4152,10 @@ if test "yes" = "$use_atomic"; then
|
||||||
|
AC_MSG_RESULT($arch)
|
||||||
|
fi
|
||||||
|
|
||||||
|
+if test ! "$arch" = "x86_64" -a "$have_xaddq" = "yes"; then
|
||||||
|
+ AC_MSG_ERROR([XADDQ present but disabled by Fedora patch!])
|
||||||
|
+fi
|
||||||
|
+
|
||||||
|
if test "yes" = "$have_atomic"; then
|
||||||
|
AC_MSG_CHECKING([compiler support for inline assembly code])
|
||||||
|
|
||||||
|
diff --git a/lib/isc/include/isc/platform.h.in b/lib/isc/include/isc/platform.h.in
|
||||||
|
index c902d46..9c7c342 100644
|
||||||
|
--- a/lib/isc/include/isc/platform.h.in
|
||||||
|
+++ b/lib/isc/include/isc/platform.h.in
|
||||||
|
@@ -284,19 +284,25 @@
|
||||||
|
* If the "xaddq" operation (64bit xadd) is available on this architecture,
|
||||||
|
* ISC_PLATFORM_HAVEXADDQ will be defined.
|
||||||
|
*/
|
||||||
|
-@ISC_PLATFORM_HAVEXADDQ@
|
||||||
|
|
||||||
|
/*
|
||||||
|
- * If the 32-bit "atomic swap" operation is available on this
|
||||||
|
- * architecture, ISC_PLATFORM_HAVEATOMICSTORE" will be defined.
|
||||||
|
+ * If the 64-bit "atomic swap" operation is available on this
|
||||||
|
+ * architecture, ISC_PLATFORM_HAVEATOMICSTOREQ" will be defined.
|
||||||
|
*/
|
||||||
|
-@ISC_PLATFORM_HAVEATOMICSTORE@
|
||||||
|
+
|
||||||
|
+#ifdef __x86_64__
|
||||||
|
+#define ISC_PLATFORM_HAVEXADDQ 1
|
||||||
|
+#define ISC_PLATFORM_HAVEATOMICSTOREQ 1
|
||||||
|
+#else
|
||||||
|
+#undef ISC_PLATFORM_HAVEXADDQ
|
||||||
|
+#undef ISC_PLATFORM_HAVEATOMICSTOREQ
|
||||||
|
+#endif
|
||||||
|
|
||||||
|
/*
|
||||||
|
- * If the 64-bit "atomic swap" operation is available on this
|
||||||
|
+ * If the 32-bit "atomic swap" operation is available on this
|
||||||
|
* architecture, ISC_PLATFORM_HAVEATOMICSTORE" will be defined.
|
||||||
|
*/
|
||||||
|
-@ISC_PLATFORM_HAVEATOMICSTOREQ@
|
||||||
|
+@ISC_PLATFORM_HAVEATOMICSTORE@
|
||||||
|
|
||||||
|
/*
|
||||||
|
* If the "compare-and-exchange" operation is available on this architecture,
|
||||||
30
bind97-rh645544.patch
Normal file
30
bind97-rh645544.patch
Normal file
|
|
@ -0,0 +1,30 @@
|
||||||
|
diff -up bind-9.9.4rc2/lib/dns/resolver.c.rh645544 bind-9.9.4rc2/lib/dns/resolver.c
|
||||||
|
--- bind-9.9.4rc2/lib/dns/resolver.c.rh645544 2013-08-19 10:30:52.000000000 +0200
|
||||||
|
+++ bind-9.9.4rc2/lib/dns/resolver.c 2013-09-06 17:58:03.864165823 +0200
|
||||||
|
@@ -1138,7 +1138,7 @@ log_edns(fetchctx_t *fctx) {
|
||||||
|
*/
|
||||||
|
dns_name_format(&fctx->domain, domainbuf, sizeof(domainbuf));
|
||||||
|
isc_log_write(dns_lctx, DNS_LOGCATEGORY_EDNS_DISABLED,
|
||||||
|
- DNS_LOGMODULE_RESOLVER, ISC_LOG_INFO,
|
||||||
|
+ DNS_LOGMODULE_RESOLVER, ISC_LOG_DEBUG(1),
|
||||||
|
"success resolving '%s' (in '%s'?) after %s",
|
||||||
|
fctx->info, domainbuf, fctx->reason);
|
||||||
|
|
||||||
|
@@ -3804,7 +3804,7 @@ log_lame(fetchctx_t *fctx, dns_adbaddrin
|
||||||
|
dns_name_format(&fctx->domain, domainbuf, sizeof(domainbuf));
|
||||||
|
isc_sockaddr_format(&addrinfo->sockaddr, addrbuf, sizeof(addrbuf));
|
||||||
|
isc_log_write(dns_lctx, DNS_LOGCATEGORY_LAME_SERVERS,
|
||||||
|
- DNS_LOGMODULE_RESOLVER, ISC_LOG_INFO,
|
||||||
|
+ DNS_LOGMODULE_RESOLVER, ISC_LOG_DEBUG(1),
|
||||||
|
"lame server resolving '%s' (in '%s'?): %s",
|
||||||
|
namebuf, domainbuf, addrbuf);
|
||||||
|
}
|
||||||
|
@@ -3831,7 +3831,7 @@ log_formerr(fetchctx_t *fctx, const char
|
||||||
|
}
|
||||||
|
|
||||||
|
isc_log_write(dns_lctx, DNS_LOGCATEGORY_RESOLVER,
|
||||||
|
- DNS_LOGMODULE_RESOLVER, ISC_LOG_NOTICE,
|
||||||
|
+ DNS_LOGMODULE_RESOLVER, ISC_LOG_DEBUG(1),
|
||||||
|
"DNS format error from %s resolving %s%s%s: %s",
|
||||||
|
nsbuf, fctx->info, clmsg, clbuf, msgbuf);
|
||||||
|
}
|
||||||
14
bind97-rh669163.patch
Normal file
14
bind97-rh669163.patch
Normal file
|
|
@ -0,0 +1,14 @@
|
||||||
|
diff -up bind-9.7.2-P3/lib/lwres/lwconfig.c.rh669163 bind-9.7.2-P3/lib/lwres/lwconfig.c
|
||||||
|
--- bind-9.7.2-P3/lib/lwres/lwconfig.c.rh669163 2011-01-28 14:48:38.934472578 +0100
|
||||||
|
+++ bind-9.7.2-P3/lib/lwres/lwconfig.c 2011-01-28 14:49:50.421326035 +0100
|
||||||
|
@@ -612,6 +612,10 @@ lwres_conf_parse(lwres_context_t *ctx, c
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
+ /* Ignore options with no parameters */
|
||||||
|
+ if (stopchar == '\n')
|
||||||
|
+ continue;
|
||||||
|
+
|
||||||
|
if (strlen(word) == 0U)
|
||||||
|
rval = LWRES_R_SUCCESS;
|
||||||
|
else if (strcmp(word, "nameserver") == 0)
|
||||||
44
bind99-rh640538.patch
Normal file
44
bind99-rh640538.patch
Normal file
|
|
@ -0,0 +1,44 @@
|
||||||
|
diff --git a/bin/dig/dig.docbook b/bin/dig/dig.docbook
|
||||||
|
index 1079421..f11abd1 100644
|
||||||
|
--- a/bin/dig/dig.docbook
|
||||||
|
+++ b/bin/dig/dig.docbook
|
||||||
|
@@ -1177,6 +1177,39 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
|
||||||
|
</para>
|
||||||
|
</refsection>
|
||||||
|
|
||||||
|
+ <refsection><info><title>RETURN CODES</title></info>
|
||||||
|
+ <para>
|
||||||
|
+ <command>Dig</command> return codes are:
|
||||||
|
+ <variablelist>
|
||||||
|
+ <varlistentry>
|
||||||
|
+ <listitem>
|
||||||
|
+ <para>0: Everything went well, including things like NXDOMAIN</para>
|
||||||
|
+ </listitem>
|
||||||
|
+ </varlistentry>
|
||||||
|
+ <varlistentry>
|
||||||
|
+ <listitem>
|
||||||
|
+ <para>1: Usage error</para>
|
||||||
|
+ </listitem>
|
||||||
|
+ </varlistentry>
|
||||||
|
+ <varlistentry>
|
||||||
|
+ <listitem>
|
||||||
|
+ <para>8: Couldn't open batch file</para>
|
||||||
|
+ </listitem>
|
||||||
|
+ </varlistentry>
|
||||||
|
+ <varlistentry>
|
||||||
|
+ <listitem>
|
||||||
|
+ <para>9: No reply from server</para>
|
||||||
|
+ </listitem>
|
||||||
|
+ </varlistentry>
|
||||||
|
+ <varlistentry>
|
||||||
|
+ <listitem>
|
||||||
|
+ <para>10: Internal error</para>
|
||||||
|
+ </listitem>
|
||||||
|
+ </varlistentry>
|
||||||
|
+ </variablelist>
|
||||||
|
+ </para>
|
||||||
|
+ </refsection>
|
||||||
|
+
|
||||||
|
<refsection><info><title>FILES</title></info>
|
||||||
|
|
||||||
|
<para><filename>/etc/resolv.conf</filename>
|
||||||
1
ci.fmf
1
ci.fmf
|
|
@ -1 +0,0 @@
|
||||||
resultsdb-testcase: separate
|
|
||||||
252
codesign2019.txt
252
codesign2019.txt
|
|
@ -1,252 +0,0 @@
|
||||||
-----BEGIN PGP PUBLIC KEY BLOCK-----
|
|
||||||
Comment: GPGTools - http://gpgtools.org
|
|
||||||
|
|
||||||
mQINBFwq9BQBEADHjPDCwsHVtxnMNilgu187W8a9rYTMLgLfQwioSbjsF7dUJu8m
|
|
||||||
r1w2stcsatRs7HBk/j26RNJagY2Jt0QufOQLlTePpTl6UPU8EeiJ8c15DNf45TMk
|
|
||||||
pa/3MdIVpDnBioyD1JNqsI4z+yCYZ7p/TRVCyh5vCcwmt5pdKjKMTcu7aD2PtTtI
|
|
||||||
yhTIetJavy1HQmgOl4/t/nKL7Lll2xtZ56JFUt7epo0h69fiUvPewkhykzoEf4UG
|
|
||||||
ZFHSLZKqdMNPs/Jr9n7zS+iOgEXJnKDkp8SoXpAcgJ5fncROMXpxgY2U+G5rB9n0
|
|
||||||
/hvV1zG+EP6OLIGqekiDUga84LdmR/8Cyc7DimUmaoIZXrAo0Alpt0aZ8GimdKmh
|
|
||||||
qirIguJOSrrsZTeZLilCWu37fRIjCQ3dSMNyhHJaOhRJQpQOEDG7jHxFak7627aF
|
|
||||||
UnVwBAOK3NlFfbomapXQm64lYNoONGrpV0ctueD3VoPipxIyzNHHgcsXDZ6C00sv
|
|
||||||
SbuuS9jlFEDonA6S8tApKgkEJuToBuopM4xqqwHNJ4e6QoXYjERIgIBTco3r/76D
|
|
||||||
o22ZxSK1m2m2i+p0gnWTlFn6RH+r6gfLwZRj8iR4fa0yMn3DztyTO6H8AiaslONt
|
|
||||||
LV2kvkhBar1/6dzlBvMdiRBejrVnw+Jg2bOmYTncFN00szPOXbEalps8wwARAQAB
|
|
||||||
tE1JbnRlcm5ldCBTeXN0ZW1zIENvbnNvcnRpdW0sIEluYy4gKFNpZ25pbmcga2V5
|
|
||||||
LCAyMDE5LTIwMjApIDxjb2Rlc2lnbkBpc2Mub3JnPokCVAQTAQgAPhYhBK4/rHln
|
|
||||||
EexZ/AB6pHS7a5pMuz04BQJcKvQUAhsDBQkD7JcABQsJCAcCBhUKCQgLAgQWAgMB
|
|
||||||
Ah4BAheAAAoJEHS7a5pMuz0476oP/1+UaSHfe4WVHV43QaQ/z1rw7vg2aHEwyWJA
|
|
||||||
1D1tBr9+LvfohswwWBLIjcKRaoXZ4pLBFjuiYHBTsdaAQFeQQvQTXMmBx21ZyUZj
|
|
||||||
tjim8f9T1JhmIrMx6tF14NbqFpjw82Mv0rc8y74pdRvkdnFigqLKUoN2tFQlKeG+
|
|
||||||
5T24zNwrGrlR3S7gnM47nD1JqKwt4GnczLnMBW/0gbLscMUpAeNo/gY4g0GV/zkn
|
|
||||||
Rt91bLpcEyDAv+ZhQZbkJ49dnNzl5cTK5+uQWnlAZAdPecdLkvBNRNgj/FKL41RF
|
|
||||||
JGN6eqq3+jlPbyj9okeJoGQ64Ibv1ZHVTQIx5vT1+PuVX/Nm0GqSUZdLqR33daKI
|
|
||||||
hjpgUdUK/D0AnN5ulVuE1NnZWjVDTXVEeU8DFvi4lxZVHnZixejxFIZ7vRMvyaHa
|
|
||||||
xLwbevwEUuPLzWn3XhC5yQeqCe6zmzzaPhPlg6NTnM5wgzcKORqCXgxzmtnX+Pbd
|
|
||||||
gXTwNKAJId/141vj1OtZQKJexG9QLufMjBg5rg/qdKooozremeM+FovIocbdFnmX
|
|
||||||
pzP8it8r8FKi7FpXRE3fwxwba4Y9AS2/owtuixlJ2+7M2OXwZEtxyXTXw2v5GFOP
|
|
||||||
vN64G/b71l9c3yKVlQ3BXD0jErv9XcieeFDR9PK0XGlsxykPcIXZYVy2KSWptkSf
|
|
||||||
6f2op3tMiQEzBBABCAAdFiEEFcm6uMUTPAcGawLtlumWUDlMmawFAlwuSqAACgkQ
|
|
||||||
lumWUDlMmaz+igf/ZW8OY5aWjRk7QiXp93jkWRIbMi8kB9jW5u6tfYXFjMADpqiQ
|
|
||||||
yYdzEHFayRF92PQwj81UzIWzOWjErFWLDE2xol9sP5LdzeqoyED+XTqKggpVsIs+
|
|
||||||
Lq672qnumQoZKp1YGb8MDocU2DNg/VsMdi7kCnEnPbcSuBxksmxGYomusXNrAF94
|
|
||||||
1OJ2sqd9BuFamLIyn8XUCGGYlsvMoe4kTCg6Cc1sQvx0lDG8urKN57jBKWbP4alV
|
|
||||||
+JBV5KQcf74gzPmE3ypgY1tMEwxyH/WyS9ekDbai0qauX6eUAsM1bduH8fIcknLS
|
|
||||||
Zl5hrJTrzWFF9/DKOth8QOwhJ9zoIF1fcAsx9okBMwQQAQgAHRYhBHpqR7X54SM6
|
|
||||||
0lUrXL2X3GOe6MR7BQJcLktcAAoJEL2X3GOe6MR7jwEH/iaolMeno1oeWAgzN6Mg
|
|
||||||
bx3maweh/9Vqty1fwk7Crq1G78X5i1OCkknEL2p0Bfle4ApwcC4HZVcqCgoYpRV3
|
|
||||||
/EEXtwkMNy3plWdBbLCQSev/E1D39GzgAHiMnv7NUJnkoJbvMrvrAiUTXPTtARMM
|
|
||||||
gjEpvgEs60wuJxS8ESomRhe/KW4myxDoBxF+K+e5bOkOvvWVcAYJHWZ1BIZs4n6b
|
|
||||||
+C2vO8q5aKTkQ/XvNT7utbTOqj1SGhItRaAQKXHBdzkQ1Et3wTA4+uRg4gK12624
|
|
||||||
9LperYs26w9X9UzApl+qVxQhtWUw3tnUXMastDfQrRcvJgq1xpv++OqX5Uc93RTf
|
|
||||||
SNWJAjMEEAEIAB0WIQS+DpdItxglOii7if/xsRvwXPAuVwUCXC5LlQAKCRDxsRvw
|
|
||||||
XPAuV29KEACEwlTVVKe4gnBYHnlAD7csoQ0+gJ6C+Ofzlw+UItRIcFeVCAknSGBs
|
|
||||||
NPxr9JStIvKpmsbSKpCNUEAYnRP2immh94y/C6BuTe1uUUmqBGr1f4OAUwZpmI29
|
|
||||||
ixYeY/uUs9FZO3bS0/WtG46tdcJK41qtM0DYAGT3oeZhJMTW15dfvMGlFukauSOU
|
|
||||||
+BbR+6sZhqdbWl/AOTE/6x5otnAaW0GObY/BW240Xq/KTgBrzVdK5qNoYsMVsiTd
|
|
||||||
0im0JKvFG08ED+ZfcILhlO6G9jRhoTkhtYuf8CKN1dPf2IoB5FrRFf0xqRr9hNlk
|
|
||||||
X7ViNMP9OPb8i3BubWvRi5rNSquCwrFATSiAgaA9Yi1BNzQsmQxOql9lsh7eCH7m
|
|
||||||
+8zzUg9umWI6PkSv8vHBo2kPX73wmtEsF6vxJlk0yDBuQw7y0uuKh406tEEk4cP2
|
|
||||||
8U4baq+ihpioupDhNuEII1h1Eh/RBE408RAOpcr+2F0m/fKOoJyz7u+AxyV81Ia6
|
|
||||||
fyBnUfZnlfKo16w87c1HJRs9dKkRa5yGziBf9TcED3sru58Pftes2Nr80/iOh26i
|
|
||||||
P2pRihcIyrmeAqDWnneErVCmPMDTe6zkMrm/0iZ25/Jfq+M8IHEzFEw3Y1FBOeFg
|
|
||||||
9TyMDwYG2biJPTNTDO0BQ+Rrvs4SjFWEYSxgJSvG1jMfSPt5AR6MJrkCDQRcKvQU
|
|
||||||
ARAAufZX5WzJr0lZAhxaGpHY6JMBr4jVOCP4TrDZhwC2K4CXNM/PLLNisWzquiWa
|
|
||||||
FvUDhB89kCxrEhipwVFYhBr16CDQxrr8yhah3RIxrBMYhRTxgIAkANgkhGWfDJSE
|
|
||||||
zXauA7krYtS3rYwhfXe4cNsTkLPbnMUlyLJcqj2wnZcZIt97aL+NFRPyfIw1KfUb
|
|
||||||
9u3tB9seDYbvTEULeL07aTnHpWM5f3bTwJrJ2OFPzXseCCzPiVNh3Bv+YtJ1pMTr
|
|
||||||
c/UHO5DoJuHLsF0wicPSrpD0twspFdR/0rT6eNycsaCtV4GQzBcMPvY7qai5XrZm
|
|
||||||
Cqgluo1W6l6+F5YrKvRMtyyFkUNGcPywdjSlP44JyRrS2uzvFUViSsJArcmFG2TJ
|
|
||||||
LCohnse8wqjw0dIUVbmDbE4zjaG56zkvu0k+04Wwp3XPgOZrbl6cbhX3yLhu/Gt0
|
|
||||||
dzd9EReoNfKXk32hBzKas/vdeB5DZejbOOOWYftqyZC1LvDvvrYFhFK6VGozfZ6L
|
|
||||||
Fml1hzn+xPahp5tRv93/T9zXeVPm9zilGMqm/gjRgh8ojWxNQoNzJyqTPWIvWmbu
|
|
||||||
EIP3T3cTFq6lJpJsg3+sfzofGWZCGnBZQGqm8rEOoUWiaKe1BvQCX1x8p4/x8/tX
|
|
||||||
TaVDpQCGoqxXt09plkDuGMuiDICxBlaHWUR2jLoHc2cLrB8AEQEAAYkCPAQYAQgA
|
|
||||||
JhYhBK4/rHlnEexZ/AB6pHS7a5pMuz04BQJcKvQUAhsMBQkD7JcAAAoJEHS7a5pM
|
|
||||||
uz04pB8P/Amfg54IFeALiPOrKbjC3bVAQzrsf09IL8sUln/LCZIx9HgGAJj/f35S
|
|
||||||
Q35sK2ucjWiDX6qCxVrWmC6caQXFgXOFSKIlqladmmgj4sIdLM5wj4nbomHChpB5
|
|
||||||
rqV/GgkFwWBQ3kPCatXvc8Bg+zKJ+wXgTuPFXefyE9R+SLuas2grQ9hAjvTGHYbq
|
|
||||||
iYxSlNDFc1aHLAQ3bS76351MHuMHOpLzoB0OkZDCVNW4GNEqrLbINdr50RAK+Loo
|
|
||||||
Z2UBIobEZjXYor9A2FWkSvdjyz6X1QKMdQMath6R91k/O0abBa7ly4/805eAGXM3
|
|
||||||
w1Xf2eMlpiUs69BeYoJBklK8aNMntpDREunJjhiPU4JoDzSxl5Qv7LuXylyo0YJA
|
|
||||||
9YmydKhTTcRdwsKc//nGr/ckg4BRl+VbtJBYvd3xGB7IQ+pT/TOakv9qCospAhr3
|
|
||||||
EQjVP/XpnWJRd+x+dq8UXqwWmTenWDE42cNr7BDFJdOqS5ZWy4sIz4sdjpSxXMB9
|
|
||||||
8iiRtKSpKRCJgXScB7SYebh835EgG2YyQGdhJMO7C6ok9POYQBqL8sBqRzImJKoT
|
|
||||||
VDvOH42WArKwJWTHa4mPdiDHEIZlkONerec3JXtl4Mfv8cwZ5Lb8fSiB/x8AWvqs
|
|
||||||
puc/7hQtkus4TcgutS1fwhAwpnFItpVF6+73CMQrJsblBdTjW0T+uQINBFxbVHwB
|
|
||||||
EADebZOJbhPdhHeBPdlZYE3rRjB8scDpWdjrCupfmeTC9MM6JgCE4DEMBtBXk+h1
|
|
||||||
+7wfpblYYNFwGVFvytG5nvGRDtHWxwd1Z9O8Fx4Zqu0Fx/wAn7ZL3ryE+tdHR7JK
|
|
||||||
7SLxOa2X49T/8LY0U8Q65I4ZRo/b4VMcXApCmncw3QSRqHT/mYdNnf+HHPvi3jza
|
|
||||||
md3iVptCS4Iaisc079DFda+htWXspBc13lmPi2vGQkWjjS3B4yO8JackyQPVhpsg
|
|
||||||
KYbRBzOH0Kii8bXmyA6O5uIJYEddp5Veged4FE/ej3CrgGP1D0Yk1epx8lLbi9RB
|
|
||||||
kwFS7DA5rQ23UnbSy1WyV1ZgPrWqQAWuGpjMTVTWN0ElI3AGxAnE8lZlSXyE+XyV
|
|
||||||
uHjjIVrayBjLKVqDuSLdKZeCvI4QsyHH6F0NKJQkngvXxLZYxO6s0c2EFFLzdVWT
|
|
||||||
1V9GMP8UsDrrb+JsZjUVmPR1tTP4xqEQG6KjfFoQm5XWpGtFwh91OK1lwf/Bx2/C
|
|
||||||
j+PquLLFcj7hEP79VDTUZPQAduTTxIeTzHXH+x1PCHFB10xxH3e82VSdJeBUrJxn
|
|
||||||
riXzK50SKTTmF+uYpHqE8Jg1N2Y1n5ksuxeYUy8PFjhAeBCqZ6ZcldUDf4999e/z
|
|
||||||
PT8bwfCDr8jRdqJHrq7RxTJiP5RsMudWpKeohzJGwQ5uZwARAQABiQRyBBgBCAAm
|
|
||||||
FiEErj+seWcR7Fn8AHqkdLtrmky7PTgFAlxbVHwCGwIFCQO9IQACQAkQdLtrmky7
|
|
||||||
PTjBdCAEGQEIAB0WIQSVztolaxygoV8wL7WVIaftXazpGAUCXFtUfAAKCRCVIaft
|
|
||||||
XazpGPeMEACm9nxA/VKf8RxDo2ZuTgyuSwlR8tCjAE4k3+UoiYUbamkW4pjx9Vgd
|
|
||||||
1zC5bNxSWZ5vlJ4CH8ArKFqNK5LBVDZqhYureAo/1Af2b9vRJw0/QQHhuXz/jqeT
|
|
||||||
wwrLuKpy796Gpt+aFfcmS0ZC4QXfxJERhAP6tu1p6YmAsSb+bjziQVkKrt9mhOrL
|
|
||||||
dtz6WP0Fg1joRj33FgnnLtayHvtgQrNFI3ztCjk/B2FjYZxqbBGfk5gyo0cTE2Fi
|
|
||||||
oLhG/XrxIoZepFMJkGYETnYQXrOt2KuJLvawV70YQmG8EqHYY8drKA0XDZs8TVdT
|
|
||||||
5cvGvtm8ERz5znsssRBxQMI5Ml6O2ahrXp8Eq4htCzlvO8t2MOtzvqAJRiyAd6bA
|
|
||||||
Uo+MGVRpnvePOR1SAgBXCd416rF0iCXc1utZxnqwdq9kJAZ+8mCLx4N4jk6AdGpX
|
|
||||||
zcNkLg7QmUzXn75RxZ6GrIUYZJNMlswXq5XhSW4o8ePlaxWjh9+QTtU964AZhpA1
|
|
||||||
uoHsKGTBxHJs0w6McZm14kb2PuaO2/rpf8s8IZyc93+Y5O/gHZ6/agBjA9qN6wkQ
|
|
||||||
R1d5UhJC4QS/m35rBGBKK9X3fqQxaBCio6Qz+m4A3GchrztJpq+2P+ma5ylsTq5j
|
|
||||||
V4njky26WNtrV7+N0C4Moj3I4Qn6YU/eSManTXzHzoiPZCEH/IOxgXIiD/9Zm3Zz
|
|
||||||
I+h4NCfSGyP11/w1gEzlTHQ4at/FXIIDh0Y2ZNpWPffuFQLtcER2vyKPwhDYpGMy
|
|
||||||
NNHXks4azfrXVCv0wmSNBbeS8pJrYtopZpCEBrAbg/YLv9m5lpDSRHaR3gv/qMZ7
|
|
||||||
QxY+NwqciqTwGq68PuF4mDSvtfuFmbEES9Iybiie+eL/6DU2knfBjgshUe6vElR+
|
|
||||||
LYoPQ45GY2IxRTJ1pMXaZw1+evwH3UvseRGkRygiaBgoU/qR4prynvjMQcacCa+C
|
|
||||||
aRnXZJYp/usVBeY0xut9toc9/OcLGoBr5h9l5YjruO2vu8VHou8N0tarVQn3YbQR
|
|
||||||
Fi+YtNtclWJa8Pq1AsKRTCFwDwP6eODv6mNOrEFydNRcpiQmzp47VWF/YHRfHzCq
|
|
||||||
A1wHLxLUrpQTaVw6J4FqedAQ31aAO4faA7MS+ZMNBqZCZ7lTGC6TvojqqBAN2yX7
|
|
||||||
AnnYpZHM+lGpi2/ukVzLqSkGmdNOgbu+UZvoej3YnHYig4yWP+z2xrlJl8bkhU/d
|
|
||||||
r9IQE5aRCEPB/JWhHJ2/GqYl9qjshlB52+6X2KDarwptOtzT9ooArYhpMwKIYh34
|
|
||||||
c7X8tlAKYk7V5j7txIRFDKKAftC7dM82PntXJxSkWyR70GYnYjiXyrqqerqT7xIC
|
|
||||||
mDEQgFOPpy09zFW62paO9uiZw6qwybwqgGpoX7kCDQRcW1TbARAA3ERo2mPv2VVg
|
|
||||||
ZUFr4MtPDm4UG00YJW/LYa3D3k0e9tdSScACXprk1sAoxUlQx/CSdErPKwXG4rax
|
|
||||||
iN4t5nICUUNYSC0dh09G25jC7nwsWc0AYyZu+h/FzfvpOm3fBwmBlzILlGh0URwH
|
|
||||||
Ffj9fHt6hos4C+3PFZZ/X24aMJF/cov1oYi9rqFwt/l0mgtPE88Iyj2/Vp3Lergg
|
|
||||||
QMzKfEuyluj9fL2cgU0Qa7oAPXmaxhHtua4cvbM5SXGo3FXjIgzH9OfM+2orebeN
|
|
||||||
wH1M3ec6w+nPmRmCJLvPKGOeS7GVXL5/aOyPlDWzSXYnpCKS2ntw4K4nt0IA8n8z
|
|
||||||
1db109l/C2noDrDSJEqOo843ShNGTYOMVUrj3a+Y7o2ATc9pNZalf0PwnKas7NDb
|
|
||||||
IJ152PEQw665iYXcv2awjLF6W0yuSq8kfiaAxIrsie2Dto0zgqOs0Ot9Y74u11Hh
|
|
||||||
wBSHUO3mEZJScAAcI/yDF2PvjvCQSzu4mdXb77t6X2O6YHULz4A7bVQCMazcTDI9
|
|
||||||
/S0W2+ixPnnJVnE3xgjK9zuizji8JDJw1hJCQM+yTLVqq9pfvcRfQ6uwpMRzz/O3
|
|
||||||
S0zDRiA69/GyfNwkpgz5QaGpY02IK5WrQU1doRjIz4BHAYzoIOkMkRqTtjdElQZw
|
|
||||||
/D3wSO2uwsEMNwRzibR/Lz1JF2aGn6EAEQEAAYkEcgQYAQgAJhYhBK4/rHlnEexZ
|
|
||||||
/AB6pHS7a5pMuz04BQJcW1TbAhsCBQkDvSEAAkAJEHS7a5pMuz04wXQgBBkBCAAd
|
|
||||||
FiEE1wyE5ktVjlvM7AchMuIXXx11eioFAlxbVNsACgkQMuIXXx11eiqCfQ//SFDf
|
|
||||||
rOIEoslp6n6vlCuavOg02wvjskKQGP1P1Q4v40Fw1Gl87n9uXAoMpeF4H+pzUxOi
|
|
||||||
BHYCQi+EemwocSThzaWfPzd3JG/0OcRymf+ZOcBb+58VJL7p88QdMFIAi5J+KMuA
|
|
||||||
fEG0zLkc9anEnXoVMmQJX5K+6PyeVDvBbYGjLjQAsWTZTiVuQI0w3WxFtDGWqQII
|
|
||||||
8e/qE0DA7c/auGn7j2hid308+FcdfpmLefW9YesWjE1yYvHoCRdFOJ/7Sft4MQCI
|
|
||||||
Re7UET3TRMBvtisP2DcqyzGPp22s4ZYFCCJJNiB92bXdEl5zXe4Ff7JTfNE/QrR7
|
|
||||||
Wg5R9hZHgHdbp8p8bA3f0y29YCx3puYg7BbmQWiMh3rXWE5b090pSpw0K9BQU3vO
|
|
||||||
irr+5/2TaFOJXHl4VF03GrWsSncShCbdsdRIv4TB0lY2mN4q+e7bjlAzJJeoaS97
|
|
||||||
GIqu3DBlAJyx/ZwWW23DXXwoQ4jNuJhpl2jaCE7rVQB0uLjbp0i9Zdd4SdYZxmO/
|
|
||||||
Y+JfgoJz8eyx8wZi4eDz1ijN0WKsIGjxJH5VUK9STjijDMeG6ZZRLc6b1QCGhe97
|
|
||||||
ZbDkEUTdQGoeu4L5Fiqoma13NEsf8ofBDv+myJm/O67Va9JI3gxhIrhmF7LMzQQp
|
|
||||||
lYx2peZC1CmhEnn83dtt83mhXvX6Dth657BW/Qd+GQ//SVuTPuNkBXfrTi4dbnv+
|
|
||||||
cU6IsoIBodTF/WsQ6h4kbtsPhO5DbrsLNuNumrqVEN8jw+HUsEeNvFNeMrTPdG2V
|
|
||||||
87ShQ4BQGkCf+GFRBj0myxxXOFZYQx6RpY5fCe7yOcTzpkbnPWmm7V8HdOuZ0NnL
|
|
||||||
JNQ5YogOI6UvXVKv35R9qBo+G9jkhhb0eaAu6BERzKVANKfsGN7545ElZ1qlffMh
|
|
||||||
AQhXGb6TsvCeSg2cWGb2cnVL2d58uVukD4PDiq4qqwgClkF3bOO70SIgGrCteHbi
|
|
||||||
4Hseopex5m6GqqjoUYXr7QQBwSaQdc+gKtEjMHCsHbUyHRk0qEHdEe+2RmL0d0ra
|
|
||||||
QMJfKyYQjcCR7tnrgN4WD1h4NKRdC/KRW31MDmH9XVPrkOMQCUCnArXkOwdKWsKf
|
|
||||||
h8af9HqweXOT1FHJN/M3tWaBpv6KoduF2f2pj1VhPZ2EqFUycJ26lrHyOpsynQR6
|
|
||||||
+TD+c1uXotDwKN5RW+YL1cydk6mhib64fdOyPUeTcHehjMAFgM2f5wi35Ujcj8id
|
|
||||||
37cWOqRsggSbMnGO4AUA/YtcVNG8TjZbakson8ENK7e8q4sEiNFUZ7/CtzNokwHQ
|
|
||||||
5uOG1+qB85Y4ImGnIZVeiBpjt73VVawg4Zvm/omtW50P9R+4rVhMJZZFAgrWg8BH
|
|
||||||
H/KNznW0vUuShG8B+2FA/eu5Ag0EXFtVDAEQAL5ftI1GgVJEFgX5VsuFnfBnH95c
|
|
||||||
zqmwEXaTP4s7Xm3O0Wy579EzRUD1eEw/UaD/q2OHScwvMP65cZYQ9w4hnCN6H96P
|
|
||||||
96Teo7LOMCssvSXIO7gqP33LKTqDzsIoAFHwWE3dq1jbyP6T1Je85mr0Edvk8kOC
|
|
||||||
B1hudswAARno/7X9zGulhhwuEHk5Iey7R59yRUQqBctdNcetGyaiFjjX0evuVADi
|
|
||||||
/z/s07XhDLDt7+3Vglh1/7XGC64QhB9QjZ8j0u7+0xfmLLjhi+7EpkDlAHIJXX1H
|
|
||||||
0wAsPOGKlYruQUmIsMNfBINZeulHEBZ4cAd30xsM296DzJ6QL9sAGfYMhRs0YHB/
|
|
||||||
EJ10Zv0iw1pU2jCCUv/9Kf4F4nwgHQWQP7JAbfhOIUOUq/YlxjTLnkd25+7vD3KH
|
|
||||||
NQ6UiRDROR9Jwetpd/zokpf5O5iTBpVL+sCq+NsTZyDOjITve2sY0V8v10M+Z+pL
|
|
||||||
cp/cUZ4JEDS/WJ4/ovBNJP8b+YwN/RBgCjl8UBX/N+e7AA52eYP2H9GK9XPkzSCE
|
|
||||||
VxEf5PyjGrwedpoLkzagrHsDuWo3uBquLyneT/ozihqKQAuInUy5B7rWU4mpKHe5
|
|
||||||
Vto5o6Zuj+6MgHgIQzRK6Da2ziMNEmroxwZibcYCtUPdvcvxGh+byclnzBclKjOw
|
|
||||||
kAalFPx0SxEbHmzPABEBAAGJBHIEGAEIACYWIQSuP6x5ZxHsWfwAeqR0u2uaTLs9
|
|
||||||
OAUCXFtVDAIbAgUJA70hAAJACRB0u2uaTLs9OMF0IAQZAQgAHRYhBK7WIv4CB360
|
|
||||||
tcFGwUKiedJIzcMQBQJcW1UMAAoJEEKiedJIzcMQH+cQAIQYXDnqi4Hl21LtAgky
|
|
||||||
pZxug+x/LECVlwkrIfaQF337+fG+H9J7SdU87Sn1Xe/YUgQnF0XP/fjIVFM0e/Tb
|
|
||||||
xVlmTFqiejLnIwJJDgUaHO3POT2sGEyO3tc0mqSzyRBxtMQ8yvApccBhL5QODv3h
|
|
||||||
hlRWgk5MXU0IPeXw134IWm+o/PRiPBoXPawvVfEVIBlUFaiSZASf4BAiSad4aJQe
|
|
||||||
P8PyP7FPvQB1xiib0iSetn6ZmNeN2OSUJPiPA8aE9JCKuFtomVQEDM0BqQDl5A7h
|
|
||||||
5O2uyf0Li+/ArqBvfBjrH03e5zbID02dO3D2BjsV3jUeVPQ5WDgVg8LH+nfg/rRy
|
|
||||||
wfCsx9zFp1mt3K4xN2v7IKwxGndApgCcx17gsjzMvLz0J7sSGov4MNjzqvGEDKCl
|
|
||||||
uUvNKXqy7je9xcQLpoyvWtoWFXWTbQAcK5Vv+hC67r9bHpjI1KuqA8hYqNKxsv7s
|
|
||||||
wiLZdd4SK9SIuwf0j8/XTZwmoFfGolJil0ZNxyqBF39+CMVpaHdLM1qKZz99TVzS
|
|
||||||
h4obOOjkUjK458xSo0XCbJ4qXYp7PgxyWK6GIbTozbbG/1ldw+LUnqxt8Shf797L
|
|
||||||
J9lbI3ICuR2P5PYlKJf3b6D9GyfqyrP387fKAKhHsYkZ1XD54/8wIgTrdfeNPtL0
|
|
||||||
1mjWDjw5KvO9kuPBjcmzgt+NrtsQAJwKeZsiqLLcY8kJ9xP+/xtTlh2iVuZMfxwq
|
|
||||||
hwlo4MMCzpobLDZ/JKU398m77eboTKJSBfeUYxQd4ATn1L8NLKjLxKAaBkjEk0nN
|
|
||||||
8w9OUQbFlhQ/asLzzF7Z9IGGh9/SEgBZ8V67a0O3Qw9Xdi3ARK3bbZ8RIVJ0+P9G
|
|
||||||
CGrfq9j4ZmGA2L4irLjsvDAv7CSMb4WBKW8j0Jz5LFMwOMJgG1TT5c6lNqFj6y09
|
|
||||||
rZcVLnt8+lUv2Bw3LC0oI1TjFkrrCzIdfg++mPi3K/ZFc50bvnWF4eCOjgZ5U9Vb
|
|
||||||
sxFZq3+vTRcIfI9z2lZ9CNDRA1O5jGvuVtEGLiSLF2aJ6kiNriLuuGTlXfg/Fpgh
|
|
||||||
GTvyppOTzF7PtHzHBQ/ZjnhWojnc/jyJRwLK8cCl6+EOc887v8BDmqgFWtmycsE2
|
|
||||||
5fDJ7UFGP13g/eDL3ZUgMDty5dQaUOTX145t2KT+lMqpY6ZK2EC+eoqrnIGJ+tYy
|
|
||||||
0l4RRxi10mbNhuPIIDdph7X+mUHgCeA9gyF0Y+LqiB6CX+zFg7ovLvnCbMPxdGXq
|
|
||||||
z7AjfwqZBKI+BVuBeDtyW4onmElCu5cXNKsg3W0IlQlZf9PMDU6Ht0XLUs7EPfbQ
|
|
||||||
sH1Vqi1XE1W/tGnkmjcpG/qlt9Gx1uwFGLP6iomqUBc2c0GZ6R1xplXvd3w3yC8d
|
|
||||||
8lAgPGImuQINBFxbVToBEADkuxhQx9gxlzzCc0nUu2v82XsD+GzONp9irt14gslx
|
|
||||||
te96eKaTXTi0t5eya0X5TIY3wbREwjlfAeM9AfcAmWcsM4izrfPtANM6WOxB2Tbz
|
|
||||||
EY2cqv7NBQii7Z5aqPyjcIiT0b0Gs2evlDkn3xEBBqTSrNcnGSA29bZPIkaUb7Qo
|
|
||||||
p/Ani0S3/tgcR21gXsJwkgpfNKwvPT03Lz3/o5rXAyag0M/25adgk9SVKNcXc8h2
|
|
||||||
HSGv5ENjwUKNNnowVbNLw4287mFUM2Vd6unGJ2MBj7aUwTrfBl7gNV96mMdDJWcB
|
|
||||||
hGKYkxUvibuHCa2KH7gTrnV6X7sdrgD5CbJMPq6OZNSP6n6bUVg22eHxoETplFwT
|
|
||||||
4NvV3clRMWIAG1XgXR1l99LAh7PPnPMM1pHQGPwYHQskoBFS4g5knzHpB9h9TfZ3
|
|
||||||
MM4cDZR5NgWmE0fYVnWe5ax+wW0/IOklUoHv3qoL4yiN9wFJq2oLzUNQd9+tsqiy
|
|
||||||
vxSTh8iYmHegyn5KuBPsrMPgvqiKOdalTZKkak9DOx4cGQL2qHspKxiBOb6uox2v
|
|
||||||
fjMQ5bDeUn+4DYMdnZNHeywCUegJmDakUtlfvN+136IDHGwfdGcitqzswzd3+PI2
|
|
||||||
qlwPE19gkrp9NUaD3Qj2ZtDP7sU2cThc6Gra5KRFW8f98bI77j1Wu6pCnYFLqPz4
|
|
||||||
QQARAQABiQRyBBgBCAAmFiEErj+seWcR7Fn8AHqkdLtrmky7PTgFAlxbVToCGwIF
|
|
||||||
CQO9IQACQAkQdLtrmky7PTjBdCAEGQEIAB0WIQR5HX64jryNAThDSqwz3zWa56YK
|
|
||||||
eQUCXFtVOgAKCRAz3zWa56YKeSWOEADK8u03LESGSQlZQqnnCAI8iYs1s+XRMEnG
|
|
||||||
2tAQ1OK7/4eNgr1yZckmaW4FBMgeEgYIBJ7v3SlW7Hf7dE10TYPNGbP6UxVW8HIP
|
|
||||||
rA4CINcGZXWWwpS374JNMS6A5eb6viuEgEMEi00jx0MmLvCMZKypmwXQUl5YJ5nB
|
|
||||||
ytpQ1681mCQxGBMhT1eKQt3B4nAsoEnP+HnqVM/nKxBemSBNXX+C0b/YeQoLC3sD
|
|
||||||
L+Z0NRI8U6PZl9Rokod3uynH0vfBYCEJd6MvsjtnJlVVaseYIA3ESNrFG12tw95I
|
|
||||||
wKNrVCANZ1DBSyK4ovmmWsDrH+uFTHSLNjlxIuVxUfmXcLfgcepVCmd/7Z7UrWYr
|
|
||||||
SXSvP0VG4ZmEPE7tNb8bfyADftO1cVsmcHBQeSrgvpSrTv9L8MocojpR5vJc1f+a
|
|
||||||
sBT7rAeGzZP9riz1GmryXawaZgdLfaaJfzRQkc1uTChb7kMN+UMhVUdCAXmho0XO
|
|
||||||
SfcsW84u/LpjdYh2Ww41xQO6EWvbZDNgD/Fdmp8Uh1MqJ1Dejri6kjNn6wPImXJd
|
|
||||||
Eu6nHqWDRdYsfT4XUB18tB+4aIpFzCyIgpf7p1uaVU7Oqip5sZkc/WXKr77lV23m
|
|
||||||
PQvpGRNCzgU2TJY7ktR3LOvUVN6wNfLMHzeQk18NdmcEGUrJ0YYtl9vE5/Eg9L6x
|
|
||||||
LBH9PKt17IQ8D/9DLwQX8pl3fuTM8ZbzIPLxiXhbgzBBTXKRE2u1888+RIq9xE7c
|
|
||||||
aVFjwq4qpgqZ5SFonTcG4Pi5ck3mFAzyA5zLRF+ckpmBpwSPMpLwCpv10369D1jh
|
|
||||||
AF3JsUwt6DIb2BISMhh2ThSUMSKO75q8GSotsKjJyjD6vl1x4L7WXubTWxEiNuwD
|
|
||||||
3kAjFWS1Z1VWtA9SURWAbsDaCV4VmwCCpSIwRr9OTbyu9XuMdMxGNpl8SwW7MVQb
|
|
||||||
x4aYNvR7Hl/wIR71AHAXoSfrKp3p12anXjYYASHmbm16ugP4H7HLMBfznKet2f76
|
|
||||||
gIxJr1CsAMTSqypcC1UoVb6Gz8djeIR+GU+6efHI4TIUMy5uMIUx8tYbwSEeo/y6
|
|
||||||
NnjpJFYYjJa671iSABInNxs4+X+1zrFa+wl45EnaFxziEet2Qzv/VsusoLvLwnYi
|
|
||||||
BZckclAS5xoVGFW0WJ01OfLUDHxGMt9GSheL8c+GLMaMtaCWunpmmt9zZ9WdpBOu
|
|
||||||
AGluMG1Cee50TrhXaGE8CdNr8nOdSeLNAveBAPmuVa0JDSe20/D/RuYJLKeG9Vsq
|
|
||||||
BZvjuGlOUsfl6UjtiGRbgS9OWpxeez5ugc9yyV+rBGIpmnIb+9quz2HmGxE65eA2
|
|
||||||
cRNsZRIjFLzeAx/0RMaT1nlLFTBbUuZ+tJ+fgFtRGMhifZn1pb2dMQo0N7kCDQRc
|
|
||||||
W1VuARAAv4LYaNq2Zev/v7M5DnxLpgHRcMkG7TOQpycrlK5653llpZzTy3mh5peW
|
|
||||||
vcq3IDmdeUIJxQ+WDh2f0vS+NIKDC/HAddfHrZPbhO7zLxLcMW5KmV05ancaRSP0
|
|
||||||
s0+IyQmvVxUNrgPinZiphlvRGoLXS6pdgfc4jIR9B2umPecfvfu/6EWFPnXZgG8K
|
|
||||||
yY3Z+mwrmEO0FaXHBQuu6nactiPe79N4bLe8hk9RW6yIxLBeJzIoOlIcJmuRHapt
|
|
||||||
nS2lV3mfhZdFnkAp1o6a2TL5BwgMY0wZUKZr78HEMKh6LbPN9rPepf0neUeq/k1l
|
|
||||||
NJU7V6XMS+rezF31vgSJ5KoNGYhxtWZ54uksH2rcw7+ltpSVtqY91G/vibpRCJG3
|
|
||||||
LdX/kxHni1NEWyZlpS/6ntuH6HSoNYsR9IMsbESs3QVCH74ApK88CxYCRB0SEo0M
|
|
||||||
yAElbQ3bfEKCKl/FwC4IzAYAJ2arWKwBHRSJlsrNCtczrjG7j3EyJrn8+Tm5yjO6
|
|
||||||
0THQjvc/nBxrNE09r1Lzz7jrDWC9Rl+BH6wqdniymoYyUAQsX2rZ+Jhah1Zkf+Gu
|
|
||||||
76qtY+EH494dPM+0FazcBlgBd6/J5mh3Wk9JuecXLTEUGtzd1GmI9CENPAklCauX
|
|
||||||
tNOWeTop27djuKWsZxuP1GyV6UYixFVOSWteyAbA32cncVv/2ZUAEQEAAYkEcgQY
|
|
||||||
AQgAJhYhBK4/rHlnEexZ/AB6pHS7a5pMuz04BQJcW1VuAhsCBQkDvSEAAkAJEHS7
|
|
||||||
a5pMuz04wXQgBBkBCAAdFiEEFWiQaF6g32oTce8gF8xdsfAIhAcFAlxbVW4ACgkQ
|
|
||||||
F8xdsfAIhAd4jxAAiO9+VRQQ3eBOsJRgANdgL/l51kq7qE3u8xnSqNkrmdYDdT2H
|
|
||||||
TYH5W4n2AmGo50BDafdjd6tut0qtzA3/hGWCooydxKFOsnIYziUeoHvlICj3RkHO
|
|
||||||
y7utcFhAgRWi+kzFwnnXGf13dMU9iG7yvKrCrCEw44gzoQ1KnY1Xsj18n5JkqxeT
|
|
||||||
94bzcSbz20OpOSIMfSQPrpy18WrZYwHodcIZ3IUUACCpMZdfTa9c/qHRQ/rcwl+B
|
|
||||||
0JlHx0V4AYiSAsiMVgflO1Eqi7apPuwxPPd5nnHkrdDM9CYC3LdBORBXwncG3oZ5
|
|
||||||
eTSXmsvFxHXH41JHsm/1QFcVmFAYhu9qJFCGiD+8UeTFtT+nnHU69BszgtUskqX8
|
|
||||||
k9PqLdK7Vxkp16wc6WOp1NeIQ6Fd4PxTGrPqs9bJk7TlYtTFWpA0X+EMj/San+Ku
|
|
||||||
PxqLEa4Ab12R4vs1pCrn/g1z3C/6ujH4B70HOrRTIeTjULJ6xdwXGtwUA09hio0r
|
|
||||||
pHhtyZhAh5irUJNto4ZOk/Qyd+dfMsNvRJfbVIK2mmeRaBnp902AsQNgYVdi2Aki
|
|
||||||
0h4kz3bVLGw7iD/xV2hV69+JwLSijkkmOpz/EjMwj0hDDYrHH3Y3o0dV3dNdk/5i
|
|
||||||
6lQgcxSVsl9kWlHcoEllKbf0Hb1muKVwoGGYxFYna2jsLFVjG29M7iPSgrHjmg/+
|
|
||||||
I3fmsLZ0VI9kmxniUlZ6gz5NB5PJ3RXmwKO9LkBgE5C1wpuZbNEQ1NsR2bprlJPm
|
|
||||||
++GNSo8HaheuTRJn42kkOgfIJwjuvXih3FE/NtRA/W8H2uF6YLDjBKGZJbxQcmsd
|
|
||||||
CTEuCRCVP8X7C5n3rl1YqzfWfNr8QFxvH7ivG7KOlSxvyTKcYatWb9uDUPrnr74f
|
|
||||||
ZaMljHGsNyKj70MzZcrrsmt61yWGR0h+02rmIKlskl4hkh+qF5ehI+Bkd7eblsBy
|
|
||||||
rxEREHq/ij2Vd7l0Z606YCE8vj8WfcsJj8JjwR3A+nND/oNJTTbQ3b8OvasvqIey
|
|
||||||
WqqmGg73nbHjd/VIAUsfvnsEYatDk4pAA/wQr9c4T4s5Q/QRwDrAsa4J89FrDjWC
|
|
||||||
hQBPL7TaP8Af/3Y3/86jLCN4lnW1qjPXv5rhBFeI0EVi1k1qdV06qr5HOk7CwQTT
|
|
||||||
uc4rCdFcEnw8kVKZa/yFnlJfRa0Z4IwSahdp5fdFEuad6LpOcFFnYxWtIWhcg4GT
|
|
||||||
RcMha/OZnsfqOqiAt6In+1IwuJBz3uMM7xw2AMaxzAejGEL63F81C5iJ6Ld6kQK+
|
|
||||||
XblDW0G643bVbzkBb46MAT+UnLuWQUs3NDtk1FEioJyWUgbO/srMH4MoWM7rG8ZT
|
|
||||||
nQPohNmPBrqL2phmE27HQsQ0rTjH2Z2ol7iy9OFMtT0=
|
|
||||||
=MkGo
|
|
||||||
-----END PGP PUBLIC KEY BLOCK-----
|
|
||||||
148
dnszone.schema
Normal file
148
dnszone.schema
Normal file
|
|
@ -0,0 +1,148 @@
|
||||||
|
# A schema for storing DNS zones in LDAP
|
||||||
|
#
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.0.0 NAME 'dNSTTL'
|
||||||
|
DESC 'An integer denoting time to live'
|
||||||
|
EQUALITY integerMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.0.1 NAME 'dNSClass'
|
||||||
|
DESC 'The class of a resource record'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.0.2 NAME 'zoneName'
|
||||||
|
DESC 'The name of a zone, i.e. the name of the highest node in the zone'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.0.3 NAME 'relativeDomainName'
|
||||||
|
DESC 'The starting labels of a domain name'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.12 NAME 'pTRRecord'
|
||||||
|
DESC 'domain name pointer, RFC 1035'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.13 NAME 'hInfoRecord'
|
||||||
|
DESC 'host information, RFC 1035'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.14 NAME 'mInfoRecord'
|
||||||
|
DESC 'mailbox or mail list information, RFC 1035'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.16 NAME 'tXTRecord'
|
||||||
|
DESC 'text string, RFC 1035'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.18 NAME 'aFSDBRecord'
|
||||||
|
DESC 'for AFS Data Base location, RFC 1183'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.24 NAME 'SigRecord'
|
||||||
|
DESC 'Signature, RFC 2535'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.25 NAME 'KeyRecord'
|
||||||
|
DESC 'Key, RFC 2535'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.28 NAME 'aAAARecord'
|
||||||
|
DESC 'IPv6 address, RFC 1886'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.29 NAME 'LocRecord'
|
||||||
|
DESC 'Location, RFC 1876'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.30 NAME 'nXTRecord'
|
||||||
|
DESC 'non-existant, RFC 2535'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.33 NAME 'sRVRecord'
|
||||||
|
DESC 'service location, RFC 2782'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.35 NAME 'nAPTRRecord'
|
||||||
|
DESC 'Naming Authority Pointer, RFC 2915'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.36 NAME 'kXRecord'
|
||||||
|
DESC 'Key Exchange Delegation, RFC 2230'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.37 NAME 'certRecord'
|
||||||
|
DESC 'certificate, RFC 2538'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.38 NAME 'a6Record'
|
||||||
|
DESC 'A6 Record Type, RFC 2874'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.39 NAME 'dNameRecord'
|
||||||
|
DESC 'Non-Terminal DNS Name Redirection, RFC 2672'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.43 NAME 'dSRecord'
|
||||||
|
DESC 'Delegation Signer, RFC 3658'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.46 NAME 'rRSIGRecord'
|
||||||
|
DESC 'RRSIG, RFC 3755'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
attributetype ( 1.3.6.1.4.1.2428.20.1.47 NAME 'nSECRecord'
|
||||||
|
DESC 'NSEC, RFC 3755'
|
||||||
|
EQUALITY caseIgnoreIA5Match
|
||||||
|
SUBSTR caseIgnoreIA5SubstringsMatch
|
||||||
|
SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )
|
||||||
|
|
||||||
|
objectclass ( 1.3.6.1.4.1.2428.20.3 NAME 'dNSZone'
|
||||||
|
SUP top STRUCTURAL
|
||||||
|
MUST ( zoneName $ relativeDomainName )
|
||||||
|
MAY ( DNSTTL $ DNSClass $
|
||||||
|
ARecord $ MDRecord $ MXRecord $ NSRecord $
|
||||||
|
SOARecord $ CNAMERecord $ PTRRecord $ HINFORecord $
|
||||||
|
MINFORecord $ TXTRecord $ SIGRecord $ KEYRecord $
|
||||||
|
AAAARecord $ LOCRecord $ NXTRecord $ SRVRecord $
|
||||||
|
NAPTRRecord $ KXRecord $ CERTRecord $ A6Record $
|
||||||
|
DNAMERecord ) )
|
||||||
16
gating.yaml
16
gating.yaml
|
|
@ -1,16 +0,0 @@
|
||||||
--- !Policy
|
|
||||||
product_versions:
|
|
||||||
- fedora-*
|
|
||||||
decision_contexts: [bodhi_update_push_testing]
|
|
||||||
subject_type: koji_build
|
|
||||||
rules:
|
|
||||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tier1-public.functional}
|
|
||||||
|
|
||||||
#gating rawhide
|
|
||||||
--- !Policy
|
|
||||||
product_versions:
|
|
||||||
- fedora-*
|
|
||||||
decision_contexts: [bodhi_update_push_stable]
|
|
||||||
subject_type: koji_build
|
|
||||||
rules:
|
|
||||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tier1-public.functional}
|
|
||||||
|
|
@ -1,23 +1,12 @@
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
if [ -r /etc/rc.d/init.d/functions ]; then
|
. /etc/rc.d/init.d/functions
|
||||||
. /etc/rc.d/init.d/functions
|
|
||||||
else
|
|
||||||
success() {
|
|
||||||
echo $" OK "
|
|
||||||
}
|
|
||||||
|
|
||||||
failure() {
|
|
||||||
echo -n " "
|
|
||||||
echo $"FAILED"
|
|
||||||
}
|
|
||||||
fi
|
|
||||||
|
|
||||||
# This script generates /etc/rndc.key if doesn't exist AND if there is no rndc.conf
|
# This script generates /etc/rndc.key if doesn't exist AND if there is no rndc.conf
|
||||||
|
|
||||||
if [ ! -s /etc/rndc.key ] && [ ! -s /etc/rndc.conf ]; then
|
if [ ! -s /etc/rndc.key -a ! -s /etc/rndc.conf ]; then
|
||||||
echo -n $"Generating /etc/rndc.key:"
|
echo -n $"Generating /etc/rndc.key:"
|
||||||
if /usr/sbin/rndc-confgen -a -A hmac-sha256 > /dev/null 2>&1
|
if /usr/sbin/rndc-confgen -a -A hmac-sha256 -r /dev/urandom > /dev/null 2>&1
|
||||||
then
|
then
|
||||||
chmod 640 /etc/rndc.key
|
chmod 640 /etc/rndc.key
|
||||||
chown root:named /etc/rndc.key
|
chown root:named /etc/rndc.key
|
||||||
|
|
@ -25,9 +14,7 @@ if [ ! -s /etc/rndc.key ] && [ ! -s /etc/rndc.conf ]; then
|
||||||
success $"/etc/rndc.key generation"
|
success $"/etc/rndc.key generation"
|
||||||
echo
|
echo
|
||||||
else
|
else
|
||||||
rc=$?
|
|
||||||
failure $"/etc/rndc.key generation"
|
failure $"/etc/rndc.key generation"
|
||||||
echo
|
echo
|
||||||
exit $rc
|
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
|
||||||
175
isc-keyblock.asc
175
isc-keyblock.asc
|
|
@ -1,175 +0,0 @@
|
||||||
-----BEGIN PGP PUBLIC KEY BLOCK-----
|
|
||||||
|
|
||||||
mQINBGNjen4BEADDHiUVNbkFtiKPaMWjKxbKmF1nmv7XKjDhwSww6WFiGPbQyxNM
|
|
||||||
r8EHlEJx5kMT67rx0IYMhTLiXm/9C4dGYyUfFWc35CGetuzstzCNkwJs7vZAhEyk
|
|
||||||
+06CX4GFiHPOmWIupGCxFkNz1Qopz3ZePMlZRslVCHzW4dbg5NKLI0ojXlNaTDU5
|
|
||||||
mgUXpsPi/6l6QE6q3ouvmWPF4u71cZ1+W4UkIRAXOlbVsDzGaMaoHjJd8cOM8DrZ
|
|
||||||
gKHACNPjzqOvEujXDC2vyKw6XpxR+pHz0QcrRtlKnVhPNiKcDfw2mJJ5zxi9uSDc
|
|
||||||
dh5FomMn9sS4gy2Tub2urELnPf9xnURftRGG3VO6nZc81ufQB4s1BNT2ny0Uhx5V
|
|
||||||
mXUJwefMypMBfAvWCWBCeyWYtBeo7LT3NmtLq3oVGPfl7+a0ToFAYeghspK8/nOX
|
|
||||||
6/fqF1MEtzvWjXljz6K7FSDYSY9AoaESLHGwCo6dtff5S7f1+l6PCUNo6aM/B5Ke
|
|
||||||
SIAN9Lm6z2iVuy9Lukw+5IRoRKHHV4rJauPtDeYoWnNiSd7Q4vFtotUIjRpDARpm
|
|
||||||
xWS711Q2T+knHFLEiU8QzxjLhOnTzh4n9dDLHCkOY5WM5krldVeL5EuTyPKinuSn
|
|
||||||
oE01A7I4IGJp753CshibxjNYDiEOVeK93R38Y543edlIrYxnfyMVsiqPkwARAQAB
|
|
||||||
tDRNaWNoYcWCIEvEmXBpZcWEIChDb2RlLVNpZ25pbmcgS2V5KSA8bWljaGFsQGlz
|
|
||||||
Yy5vcmc+iQJOBBMBCgA4FiEEcGtsKGIOdvkdEfffUQpkKgbFLOwFAmNjen4CGwMF
|
|
||||||
CwkIBwMFFQoJCAsFFgIDAQACHgECF4AACgkQUQpkKgbFLOwiLxAAjYuI4JQ8mPq7
|
|
||||||
YrV9m4tu+jOKvoKfpjct2Rh02n/X3ChOgrdcXU898eH56tRk8Mv/E+cBTPN9zQn6
|
|
||||||
rLprbYR2t2R+zgvuUZWA8In7aewoPIJw8OdlG0gTK9m3VHJIOhIX07qcFttSZw4m
|
|
||||||
4rEU5mdxi9FatBWBzqnVm4Pn577aqRXK908j+6TvgWbZ6Cq0tw3syVT4kGj+93+P
|
|
||||||
uIQQQkTYN8UDQPsAKzfzkbQC9I5YXBKUoB9CfhXig8V9N75R0gsWkJ8Vy/8wsPXT
|
|
||||||
9/EPIIzhnhSuUIjvvBPbLGrzDgbhrfUQ/QVuXDVN8xl3rAWM/tiNGOnmzoYORyM5
|
|
||||||
ftrnCDIaO4aVKR6rtEzfdQa5Kid1StfhFien/U8jYErxkEn2HRt2gVEX5nYq31T+
|
|
||||||
0jgVode2Dzkm4+HKHmfOYsQeC07Mu6wZw9raNYqFjTcfh0ajFpLIT3j2YqOJE2jy
|
|
||||||
KbcveJcy2NiOiUl13exIZuBkZm0wEVbvgVX1PlgL3GJqnbU/Q+maRTb8FBoQVsOd
|
|
||||||
GIm7U/phU91qR+00SkOcp2LgHCCNKrmHXgiBNYBbInNIp6ze3bFvfKTRFn8WdY9v
|
|
||||||
Z7vNfKar8rt90mpjYG9qMhmvh4E9icfp3wRUtOwyi7VVtVTTUq0iFTe2C0m0v6KW
|
|
||||||
XcDwwwaTbl79BOqOH3Gp1flS2ECBsyiZAg0EY2N8xQEQAMWcyZbpxEyefX4JTszG
|
|
||||||
ocpz8C8yqvZJQUfoDK5AecQWR7OegPkIqwJcHEH5cz+MduklXNQdra/snn6pxGig
|
|
||||||
At3xCwfzRTH/aYXdjcjnma1elzZSTgk6Maw4zR/W9wea2DcUtMCcsys0gviN/VUe
|
|
||||||
Aqt+5pmhy2PlEWfJG+Mzyrqgz3Q8hRyAJAKONAwNhs1A4ZqQX/6iuCkJbH1CBeoW
|
|
||||||
+c+5qJHYEXsx25qR1yiKOFo5b90QOcwaebUq+xKQRlnESn75FTgDjDfDm9BqrHcn
|
|
||||||
Tv79kOuIN5vhz4BCsuo5QbNu4RGrs/1VSTPvMf5AN7xs9pYNMAEde7pSF1Ps3B5p
|
|
||||||
CE6iUw9L53ytV4iJQKXpzG29LofUu65YQjIXPgK7NbBO7FUHA41YbSfoWiOAjfMh
|
|
||||||
iE025YM2+RPQh/Nrc3PqBj4h21ycT+d8eEXKfc/okbVFFE9dKS1hUwKgSrs7baOG
|
|
||||||
CBZdpiB+t3jWrr8UrteALab7v0rndco3QKOe9U3f+Gm3MdgLK1TGiRgpdyiIXEel
|
|
||||||
J7zhsdoYEvaKMgUOjhf+COdlf8b9ITg93mDKe8h0OcpirCXw4O2ma3sklabzZKZf
|
|
||||||
CPhhja6Ro5gmO5pxaLau+esQWNrjEikynNIs+GRphtcFsVVH+ww26mR0nI65Llgv
|
|
||||||
kb4+DrbDGSPP6R/C2q/LMLM1ABEBAAG0ME1pY2hhbCBOb3dhayAoQ29kZS1TaWdu
|
|
||||||
aW5nIEtleSkgPG1ub3dha0Bpc2Mub3JnPokCTgQTAQoAOBYhBNmczq+Hl0cBTwON
|
|
||||||
YxguI1eUYu+qBQJjY3zFAhsDBQsJCAcDBRUKCQgLBRYCAwEAAh4BAheAAAoJEBgu
|
|
||||||
I1eUYu+q9IAP/j/GGneuvjwbXdATiQAmkiFlOxjs+SsO/hgA/mmWcm+Kpg4cAlbP
|
|
||||||
C2xEDa6biJyZ8TmLZEqPNrRm/umiisC8JnIJpIbInn42n4aDCRDW35lrYGdnP1Ft
|
|
||||||
fexnEOWAJBDRVvh9OnfRfvf+HLFfLFl40b/15YzkTYGIfrMR9y8zalkzXxsVNsyr
|
|
||||||
9Eq2pmYR7BT2z8d/9SAVuh8D3qgUylIgcFcCFJodsrI4zJSpIMfMntwVsZxDlis8
|
|
||||||
JVFN8/pfhuBBe6vjqX/cGJnj6OL3T12jvvniv13W3rar2Ocm6XA9j1t5TZNhKqAy
|
|
||||||
azAKu52NtdJjh25B6C/H+haXAX1eduCCE74uSarqS3F1wf6JI3p8fnWzk4hZNzxp
|
|
||||||
nZjIk3vrHNjE4jXTZosXCf5DoVRfMpNbxj3YEnXV+kNZQRYPPatUPgFYbxz91hbN
|
|
||||||
tHyCiy0GmTyf0QId8LTc0y9mPtP9QureJJ6rL8lt7pvXyrYglqhxDgRhJIGKMKdw
|
|
||||||
0bQtTEF4tyNzC4/sg4/omAGH66clhXlqMmuUjHSUiQyA4LL1mJl63Q+bwqXX4B8t
|
|
||||||
898tSUmb4Jmg3jLZ3Z9Hl7H8Sp3yYPOLzb2YUF6w3xFsUrNNzVxHFo8tAtEhtEfX
|
|
||||||
D+ypkowZq8g41WqMlOBrrzQFuExUSXckH2Cn97lV6lkBoueqxP+Zv0bbmQINBGNj
|
|
||||||
qIkBEADDw/CKszyuFKpVp4Z26rKJ3ooOlp8p9a+fmfuknPtMjJMSX8xK8pOlK739
|
|
||||||
K83yvDRUidT4+R9IAUKM7TqGA0hoPZmZQLiK0YLlAAXufKxO9IsDZI/7DuF2d8fu
|
|
||||||
usKQfS4oJC/IbzOAVwgwodnvKhttLWutT09GxiHrnfVPu6Uf4A+GWtrcTIWhXuxE
|
|
||||||
m7+16ToxBOTLtQ3hh79/RndUuM0ldKRRzJUzASGIPmdQJDLCKgSSeaGjZAdq6gkl
|
|
||||||
qT/K/R8eoLWSOaBRq8lBE1k7Tq4nSwthMHtCQq4+vxFWH3VF9hwy6ixccROPqt9s
|
|
||||||
fNfJK3KF4KGhfejMuVn/Lxp1v+Ne2DsdnVofFakAbBMpMyauzAyXPncYSfFhzLBD
|
|
||||||
kkn7THkfRznmHD8ux89kV534EyqYLjAy8AAD6zNc3tSYgfC0UUw7yz05Sl/eV9Xc
|
|
||||||
pbezu2ipONlXko8jpCQiiHck599cy+StrjjYPwcHF5m8uUlNnzHoUj8qsoK5SA8u
|
|
||||||
RnTW2I4DFbL0+x8eL7gmNQYFdMaA4azogtaTFWgPL2jPJ3B+/bUfHDZflvR0FB5+
|
|
||||||
OD/QHsDv4SB6uX8TOhGbFsHpt7E0scb2U9B8gQeQQJZ3jmcIRp+K18mjYh/ErDFW
|
|
||||||
23ixBe7h3tn2MGUTOhv1ibOYDE3GYBuGLQiom6yhCs8zrneuAQARAQABtDFXbG9k
|
|
||||||
ZWsgV2VuY2VsIChDb2RlLVNpZ25pbmcgS2V5KSA8d2xvZGVrQGlzYy5vcmc+iQJO
|
|
||||||
BBMBCgA4FiEEAlmjO19aOkRmzzRcel4ITKylGIQFAmNjqIkCGwMFCwkIBwMFFQoJ
|
|
||||||
CAsFFgIDAQACHgECF4AACgkQel4ITKylGIRk9g//XrvOYy9zQkpo4Dkol8yLxr99
|
|
||||||
Dq9Ur2v8F5Ba4za4QdUxeYrlq8J827mkUqMtnlyb/+3zSMy2I6HAI8QxlDZL5K0g
|
|
||||||
Gm7iLrwVTM8nAQiNU5vAe4D6PeO5ATBEvRdAUTQGz4xeaTrUXbmNUSC1dZEPvH1z
|
|
||||||
Fa/Z1WZoy9GLeuWDXix6OXTP8FlQWUTL4/ILLtfJDsWCCX7efkyfnvad8Ye2NfU9
|
|
||||||
tBjRX5QQ0Dpvgpr8/7El44XcmaHxPWEiq8X2p/d6j3nU/7LspUXRu3ptu5Q2RqMM
|
|
||||||
iRDZme2c8zieHETpC7m5sshzGxRtT5jWEtZ6V37On5DNTObvXCiaGV95qgiHi5VG
|
|
||||||
s3MFD3QSo1jJI951k68UM8V+OnzbJGN7TezZ3fTn5Pwdd4C4035QMl0E5NXCcXc8
|
|
||||||
9d+3DeFmewRRGCaOKPuO/jFPLWcwMlQqp5tkNx8LpqEZfD7/t6FrSvDUsUDU8Rn0
|
|
||||||
TQILnUZioO68HmeuJbhKaUCMuZGjBIbBqviiufFRiJuEFOVKADQ1u/P5ct/0T/gE
|
|
||||||
JAho3aubzdYMH5DLsaw03W5KfOjeTLW10zSmSK65wnR6fdwlo5l/Sg6Z63QXD+/H
|
|
||||||
/OIFgzviJkyoh6MkH55z2K8BDWbhOmaUBjNAcQEXV1KyHeLDkQ+TJfLjctv4KIpv
|
|
||||||
D7i6kNIp1b6OSdDS9W+ZAg0EY2OzdwEQAMRWPO237ohaXNpKO+dw1qkfOYYisiTQ
|
|
||||||
yfkT7BG0Xvu8jxeOdRuvUzzplgOfwWhOQkyEEXd205/PpwReeeRwhiu0BDSrzYGM
|
|
||||||
KZdw9Bw4enoaOinf5WTqM76mc5WUYfvDJIiHies+ANxj4EqTzvSif9hxvvzrbKYV
|
|
||||||
lHdaGtLm40D6yZSzDEe3X49DmEABM4g/Bs7NfVJcJ3LtLo6qbLy2tKEgNPW+VN/s
|
|
||||||
harufucxnH5HM6BUUOGZx8L04UCNJu+jvZ0zjLc5DqubNO1526kZclAo94DfTkb+
|
|
||||||
ir9nxKn7RkdcseibeYPdeIh3le6aU6M0KhTJs3RCxaQF9At08Vrrkh+wkK2Jr5QW
|
|
||||||
bs8cHpEJ+Q7BwDuAQetFi94eq7Sswh4mjhJ6ZnFCx8v9EbQnvL76afMbhZOezpaQ
|
|
||||||
aAwXVuIio2fsJpHfxWnXb93H1QKiOQdBZZLQGowcFQCqAWg7h2FwWWbKMV1smGHr
|
|
||||||
/28tLZtk/4aSCd9cZ9+nofFPPemPLbYwnBECIZN21QKZ2oBXKxb3hchy4EBTKWtC
|
|
||||||
G/fbTsjSfTCUpMNZ57HO3rGXchjSdIf+tTGJpAqWkTcXuhWXBMWPK6/2REk/DKis
|
|
||||||
XHugHg9R9hqGs2DaMpGh5NrOLly9+0dsjU15iTQucXbCS9895bRtmDjIN8dLSo9H
|
|
||||||
6DDw4yO7SHTlABEBAAG0NE1hcmNpbiBHb2R6aW5hIChDb2RlLVNpZ25pbmcgS2V5
|
|
||||||
KSA8bWdvZHppbmFAaXNjLm9yZz6JAk4EEwEKADgWIQQJCioHkj+SW1dngDpC5d94
|
|
||||||
yDJx2wUCY2OzdwIbAwULCQgHAwUVCgkICwUWAgMBAAIeAQIXgAAKCRBC5d94yDJx
|
|
||||||
29U0D/41C8WaGEphQW1N5lT/1284qiPuz3w3iSciAAoAe8iHUGBcSNpAWQmWvWXI
|
|
||||||
buKb92Gtt8JtSOHwQj8qiHjqRsUu02t/tEgQMQUq6p2jqbxODJfHR8oMFMMB0i0I
|
|
||||||
RgKtEQeq5wRJpVtH+zIFSl9PorsJtHHfhVbqxvE/axcNKa+WaqZdHuKMqADupQEw
|
|
||||||
6rD7yYVX6YPiHxMhba2AAAoHT/3VpHC0JidZ5BWGwkfnGbV1/7O91GHfJx6KN/AK
|
|
||||||
DKb5hFl4TrieDLJzphBWg0y4FJ4K7WSIKvcT2cLel9f9pHV6ysqSZWkCbkjkaVIi
|
|
||||||
LyoA0o7l263WU0D5oG2ihW6Pa2YrWHDDjfTem+kOEFsMjN+Gw74I4KWUBtldfnHK
|
|
||||||
A8TyeviKkVok1lwDAoJ3LJi/bcyCLgBZLInOU31mQ7mIXq1ENCOIvQvaG0Lwdt59
|
|
||||||
sBI8sknHkt+54t/VCaKbWSBOzgGur6EDf9WtPHWvHNCKEleDiHCELdhRYYtENO7T
|
|
||||||
vTv6Fq6Lh26dor26LnARLPvGLAKwONJ0vlTEG8IyoD5AHz9MwdXYgzh8wIvc/HtD
|
|
||||||
/0FlQGLd0WYVI6UjZfPxHOZAzARJKXLJMqiSn8hnO8v6JZaUcOF0yRKTKtzqsjzU
|
|
||||||
v9TubCGdQAaCSCaD2fmA0BEs/FpOnZ8P1fXMpcHGEtMV0qc0wZkCDQRjY7/GARAA
|
|
||||||
ubCCHkdiMblMA9ZlcOVN1Wep7TuYxQouATTb+73iHDQRNIU7DvluHoSq5zJe1Qst
|
|
||||||
zjTmtlkr2dyI5JnBexUEKrw2X7gPXfLaXY01gLLB/Jn8tU9VxPqBybxmjmEdP58B
|
|
||||||
I7BwmCyMYNqDuvPSfTMlogH/pF35Al+c8UbOfDEQqxSO2nKPNa4T5ZoVxvMxV4gn
|
|
||||||
hEJPv8Xte/wiE+CxxbmO2we6rwJjWe7O3T0mNmqvpO8iIsLlQnwTFD5L1huywPc0
|
|
||||||
UDHK0nl8k2lkue2buaOiancLatXt/i+L1DIimCgZwOt3DlVLURH5lz5ALXE/fn+5
|
|
||||||
wKkp+XVyNTAEFhSGifgBDYFw3nZeRTU7unMsRssL8SjuwPWoCcRI/3VE08xCuXc+
|
|
||||||
h6NpGfeJjLRgUSSBF+958djY320TcXaRLrqRhjcJ34dBsDYsRSC15nnq2JU6Vj5t
|
|
||||||
rJL9qOdwVAFwKeAfROUULcy/LHZ3QgKLN5jOfdqYzE2KHk1+VANttRPTG34i6uq6
|
|
||||||
yzCFFYadwST22+QWvxh2ohYj2INvvrzRf3lVxssWyb4USB0JPajgnGeNY/hSYfDa
|
|
||||||
KArqOr9S+3q7h0v4RgoPxDRFIC8v/10W4wPC7R3wj0m/1WHkSm951Wtzq3V84uCF
|
|
||||||
LLhx2ByNpnJFRFqklonAH3WHUIeYcdXAsTeunrGU/XsAEQEAAbQuR3JlZyBDaG91
|
|
||||||
bGVzIChDb2RlLVNpZ25pbmcgS2V5KSA8Z3JlZ0Bpc2Mub3JnPokCTgQTAQoAOBYh
|
|
||||||
BJWA1r8syA8eO7ESUt6rkdVLE8m4BQJjY7/GAhsDBQsJCAcDBRUKCQgLBRYCAwEA
|
|
||||||
Ah4BAheAAAoJEN6rkdVLE8m42PwP/RFmUzgsoM23Z/NQ2AacCFTmHweEllkmf+25
|
|
||||||
3hP80BuSHKsdzlmllFux+xbKZEpQK0nL3fqW8yyv69WmsoKZPpZJxmQ6bwUbtXC7
|
|
||||||
rHkt5gfOXiTaxDBmgO2dcnDsKLb+bEQ7C5hay1P8rOvf13a4UZeTP37gRGmMr38+
|
|
||||||
LvADIspIxBdSvFa7Hb4HKG4VVDai8jaPCF0q8daEWMJxyKSfOQBtSVVAzjLcGrYR
|
|
||||||
bCPDAI1DEASyQOru52WREe4vJCwSaq9dZyGhaWcnyTVQO8bsSLxu7cUVxA3SOheQ
|
|
||||||
izYKkYNbaBDmWlZxLYFsTUf5izEYdW5BwHaowmw22hSspFod+c37BoY/ePfkR5iQ
|
|
||||||
YuEff/unyqvdHMDqIXWZqpAi5o5hW3jdCd7ZL5T0WWjz4CQ8eko1ZYYnYzZlDrge
|
|
||||||
F0veW8+lzHBLx3Ad8HyVGwtRe+VV1V0AZ0lpWMtxo02ZDRtqNDqPqVfLT5P87ZPv
|
|
||||||
r5GhKtedgrjwY2clgmCT0xgAKNxi2SC+c/vI5PRkIoqwbTiryLIYq8tl6T1k6AMY
|
|
||||||
eN1ZNQR7eNEXpIvYRD/BZw7IWKkCRaKwfDVhUHCm0ikylwdLXIfEEEA5mu2LJeZh
|
|
||||||
vCddhks0S8+lRyWR/3okurF6rlloNtM1pslceh2AMDwfs3fORhYJxFsV7O7fyRnD
|
|
||||||
NS93fq56mQINBGNj8P4BEADXK//p0lWEUNUYirsm6BUyUXqPlPrpVTdPB1tJPj1o
|
|
||||||
zgeMKFOpYRPU1IZF1G6pbKD09gL6y19LehQYx1a57PF7kCx2ZvvcFN24EHto1H1p
|
|
||||||
Ti48dZ7KyyEO1rBeLY5Zjgz6YvQZcSH3cd6cTrAo7hPIAjtgSTWp04FjtYJqf+tT
|
|
||||||
gf+9ZWY+i4nQ6/Q5Z5NUd8jsOcOoFDsmY6Fds+lzn0aZSg2yfd8fnX5QFOIwDv66
|
|
||||||
aM25q2kvkrX0wtvSQbulC8x5g6fIB3xEL6MWbXcEBYkBMW5Cnw/Kmyj7lJwVwvEO
|
|
||||||
FFhKaOH/d2LG3rM66gl048aJYLhEJyFSyooBynXs8S/NLDgca94Bvb54FPX8LC3p
|
|
||||||
lqJRLxhdkha5NLcUYiHOq/L7LWdThh5rRAy87Ggog8TVza118K3oiYujlyVEzLhB
|
|
||||||
NVMT8x5kl15YknVgOKJAv9j28bSZihHrS7aga1BtYFD8yA9MuuDaHARV6YmThkdg
|
|
||||||
OEz/PNECjsxCLcT5Bbthzg6Jg1qo3Unyeup0UbyX4zxSphCVmerDmMYddLjJ/ydc
|
|
||||||
1uxyn4IPINBSx2sAPuUIymhVC29MB6N+SnB37/poTvSsIH15Vg264OVdaervIpuC
|
|
||||||
W3eUANr7zrdO85nc1CTWGhugFwccXv9nyxAt8zUF/ci17p1/mLpy9K3LqlStVI9j
|
|
||||||
MwARAQABtDBDYXRoeSBBbG1vbmQgKENvZGUtU2lnbmluZyBLZXkpIDxjYXRoeWFA
|
|
||||||
aXNjLm9yZz6JAk4EEwEKADgWIQT8h0w+P+hncHCscb617/asfhrd+AUCY2Pw/gIb
|
|
||||||
AwULCQgHAwUVCgkICwUWAgMBAAIeAQIXgAAKCRC17/asfhrd+HM6D/9KD/n245Fq
|
|
||||||
jVzew92lJtufAxAFkTA5WO6fXweMlUeqMOub4vpVMLPLoFe5TzWbJMtF0m/P5+aU
|
|
||||||
YbcvZBWFHsrnwTgA55c1VrhggLOxpw4EU0TvBdwrO7PFOYc2WznaMG+mJdqw+uNM
|
|
||||||
yK+G44aIaC6rvi3ILSo5HPnbgQWHs39QIRLLcUjtqvavQQeyYAl0zrvNI9Xrs/Nf
|
|
||||||
eE6PS4hIXg90A9VJRhay18w9hA+STb+xmK+3oSwP1ayLqqQ43OnV/pExSHBsjBQk
|
|
||||||
4p1nIPlRFL30lGp/o2MoBsRvQM1tELpgBTk1LaTHzuKEpOskrWU37xu0QgEtj7YE
|
|
||||||
r0X+GGBxgJuUzqSyLsaDgH1sEDqE+AthFfv2dxDadcXM2cdch9y3OyuSMo89aWGc
|
|
||||||
mEVyesjYoV40tDCG73qLtfehhV/iARDMCfnZGyGYIZdDBL+tZTNeLKVDIUi/R3x9
|
|
||||||
OmpEl8ZuCuYltyEsJnCF/rQBVMgcTOmsMu6CMx+qT3kC8iGtHqkUT2ufpKISahTn
|
|
||||||
e329FQjClEWwBHkr0T4K80Z0REjSo6UBtio73IOCxXe0RqO37L/qgo8xKZbLxy86
|
|
||||||
857PRWJhgbw169FJ2kR5p+M5d/g/MUeYnigvWlORW5LyrFg6RnZ1ZbULZI80QhHN
|
|
||||||
aSFf/w020HBsLCkzWA/XM6MO2ifJTSn8NpkCDQRkSjCrARAApLUMHAbmxUMWLgDQ
|
|
||||||
apRZBwWXriEyIVqA/SIy1PyWPPFXqs3LZ5Kn5Gw1WO8PfzkPZNtccGmNLjujIoRB
|
|
||||||
qR41nV5zxcpS896SujBoYl80A4F4v9Op9i2pFeI9r9acFcUDjbGWBqNro4EfRcJN
|
|
||||||
Ctkd9+pl3TUvFX06QCTxmmHy3M81SW3b4NWI+jia1cKjCd+qBFBgKWdjSMBeVTBC
|
|
||||||
R9eKqsBQ1UJql2bRzc8pReS+TYCeEbhaOCvUCCKCwGtsSUOW726iNB/4zR4OOuQV
|
|
||||||
B9ORufwed+E/RXa8N08/l5O96uXG0krJtOVm0/qQcXOaKxiDo6djnAgCdjFK5zaj
|
|
||||||
7594wqbI7de58alWb/egqIhjBTgk+/cO+epZ05qx5SoJZL7ny2ottrfS2cBqP4g1
|
|
||||||
SIt1sYl9ImHmJkNrNDy0s25nE9Nga6OfRqVbwnwot4ouTGwj0oZsCjw+gWjDdztH
|
|
||||||
1fUWSnlA8jaX9/RZG2wKt9dI+Tp/U4d5dyTb8lIIzzgtAzDmDfPxwwT0rxAAL13A
|
|
||||||
gDkJ0AzXA4WTOxb/JE2yfCz//kt7n8SYM//LixL4VAB7e/wnfZBhTq0OFpaPjFU0
|
|
||||||
h/k0dc40AqcUuK3lSSjQr3KTzRHtjz8qtN4DFSuyZac83QSVtWE1rFKjS8bl3XHC
|
|
||||||
kFFRJ2dMt2WRSkLOYNiTGbYLvmEAEQEAAbQwQW5kcmVpIFBhdmVsIChDb2RlLVNp
|
|
||||||
Z25pbmcgS2V5KSA8YW5kcmVpQGlzYy5vcmc+iQJOBBMBCgA4FiEE2mo1COZypJ3T
|
|
||||||
gq/ZW49NkbiO2QkFAmRKMKsCGwMFCwkIBwMFFQoJCAsFFgIDAQACHgECF4AACgkQ
|
|
||||||
W49NkbiO2QnQZw//XCpeqT0z/sqtu4FYWwYLz1OvWqhe+uA45f9BccnNSVkGFa7w
|
|
||||||
3hlLQC/FLUIx2cVy9AluJBP29iQge/bCcXnzo/QvCbhe/4lCTxhr7nsBe1bWpuNI
|
|
||||||
4Pl+cQxZQBwcz74zZ1jjaaQOqm3XtdZxeKNfCQmNvz389UZEk2m8K6qJD23fy20V
|
|
||||||
n5Y2C502UuP3MitbYKBxBSbs+Auwy1evz/prQ9VeD4Nv3Zr+jWbWFW+dSDC8jkrX
|
|
||||||
cGdwWrUQ51QD8VBB9lPWPGY6yTbRmacr4AlVSo2DAfyjHRrGHigRF/VAD5p1+u2g
|
|
||||||
3UFLJaEyujfzwU1kG4+zQCWZ2W2UBOekklq/yefxEY5vU1/Lad7vQhBmogQNF21T
|
|
||||||
FvLUE6ez7XNsdMZStDPiT8OoTyFZYLRM4yw5rWKw+1mICBv7NV82YD/8hoMoZPyX
|
|
||||||
2tNRTXv2MZ6qD++0dMCIZNEyFTB344srvQSyJ7K7vwxulc7iFWngRA8oe6JkAhH4
|
|
||||||
B0yNq1FJm6jIL41S2FmnDL3DlfAdKWapBqzgqkv+X5DQBaTlG9a4BcSsdMJgU/Yx
|
|
||||||
dD03YsKhDtEWTqBmmEamR1K1CgCC3mOJfsHB5z+Qhdraz2hMr00EQrD5lnpLLpcF
|
|
||||||
rYWoilvVlRy7Y7U5wfhY4074L2ZfB+yElKsvtfGKJX/8g+eJdeRuII+hjEc=
|
|
||||||
=NX7P
|
|
||||||
-----END PGP PUBLIC KEY BLOCK-----
|
|
||||||
41
ldap2zone.1
Normal file
41
ldap2zone.1
Normal file
|
|
@ -0,0 +1,41 @@
|
||||||
|
.\" Copyright (C) 2004, 2005 Stig Venaas <venaas@uninett.no>
|
||||||
|
.\"
|
||||||
|
.\" Permission to use, copy, modify, and distribute this software for any
|
||||||
|
.\" purpose with or without fee is hereby granted, provided that the above
|
||||||
|
.\" copyright notice and this permission notice appear in all copies.
|
||||||
|
.\" Manpage written by Jan Gorig
|
||||||
|
.TH ldap2zone 1 "15 March 2010" "BIND9"
|
||||||
|
.SH NAME
|
||||||
|
ldap2zone - Creates zone file from LDAP dnszone information
|
||||||
|
.SH SYNOPSIS
|
||||||
|
.B ldap2zone zone-name LDAP-URL default-ttl [serial]
|
||||||
|
.SH DESCRIPTION
|
||||||
|
ldap2zone is a tool that reads info for a zone from LDAP and constructs a standard plain ascii zone file that is written to the standard output. The LDAP information has to be stored using the dnszone schema. The schema is used by BIND with LDAP back-end.
|
||||||
|
|
||||||
|
\fBzone-name\fR
|
||||||
|
.RS 4
|
||||||
|
Name of the zone, eg "mydomain.net."
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\fBLDAP-URL\fR
|
||||||
|
.RS 4
|
||||||
|
LDAP URL to dnszone information
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\fBdefault-ttl\fR
|
||||||
|
.RS 4
|
||||||
|
Default TTL value to be used in zone
|
||||||
|
.RE
|
||||||
|
.PP
|
||||||
|
\fBserial\fR
|
||||||
|
.RS 4
|
||||||
|
(optional) Program checks this number to be different than SOA serial number.
|
||||||
|
.RE
|
||||||
|
|
||||||
|
.SH "EXIT STATUS"
|
||||||
|
Exits with 0 on success or 1 on failure.
|
||||||
|
.SH "SEE ALSO"
|
||||||
|
named(8) ldap(3)
|
||||||
|
http://www.venaas.no/dns/ldap2zone/
|
||||||
|
.SH "COPYRIGHT"
|
||||||
|
Copyright (C) 2004, 2005 Stig Venaas
|
||||||
|
|
@ -1,143 +0,0 @@
|
||||||
#!/usr/bin/python3
|
|
||||||
#
|
|
||||||
# Makefile modificator
|
|
||||||
#
|
|
||||||
# Should help in building bin/tests/system tests standalone,
|
|
||||||
# linked to libraries installed into the system.
|
|
||||||
# TODO:
|
|
||||||
# - Fix top_srcdir, because dyndb/driver/Makefile uses $TOPSRC/mkinstalldirs
|
|
||||||
# - Fix conf.sh to contain paths to system tools
|
|
||||||
# - Export $TOP/version somewhere, where it would be used
|
|
||||||
# - system tests needs bin/tests code. Do not include just bin/tests/system
|
|
||||||
#
|
|
||||||
# Possible solution:
|
|
||||||
#
|
|
||||||
# sed -e 's/$TOP\/s\?bin\/\(delv\|confgen\|named\|nsupdate\|pkcs11\|python\|rndc\|check\|dig\|dnssec\|tools\)\/\([[:alnum:]-]\+\)/`type -p \2`/' conf.sh
|
|
||||||
# sed -e 's,../../../../\(isc-config.sh\),\1,' builtin/tests.sh
|
|
||||||
# or use: $NAMED -V | head -1 | cut -d ' ' -f 2
|
|
||||||
|
|
||||||
import re
|
|
||||||
import argparse
|
|
||||||
|
|
||||||
"""
|
|
||||||
Script for replacing Makefile ISC_INCLUDES with runtime flags.
|
|
||||||
|
|
||||||
Should translate part of Makefile to use isc-config.sh instead static linked sources.
|
|
||||||
ISC_INCLUDES = -I/home/pemensik/rhel/bind/bind-9.11.12/build/lib/isc/include \
|
|
||||||
-I${top_srcdir}/lib/isc \
|
|
||||||
-I${top_srcdir}/lib/isc/include \
|
|
||||||
-I${top_srcdir}/lib/isc/unix/include \
|
|
||||||
-I${top_srcdir}/lib/isc/pthreads/include \
|
|
||||||
-I${top_srcdir}/lib/isc/x86_32/include
|
|
||||||
|
|
||||||
Should be translated to:
|
|
||||||
ISC_INCLUDES = $(shell isc-config.sh --cflags isc)
|
|
||||||
"""
|
|
||||||
|
|
||||||
def isc_config(mode, lib):
|
|
||||||
if mode:
|
|
||||||
return '$(shell isc-config.sh {mode} {lib})'.format(mode=mode, lib=lib)
|
|
||||||
else:
|
|
||||||
return ''
|
|
||||||
|
|
||||||
def check_match(match, debug=False):
|
|
||||||
"""
|
|
||||||
Check this definition is handled by internal library
|
|
||||||
"""
|
|
||||||
if not match:
|
|
||||||
return False
|
|
||||||
lib = match.group(2).lower()
|
|
||||||
ok = not lib_filter or lib in lib_filter
|
|
||||||
if debug:
|
|
||||||
print('{status} {lib}: {text}'.format(status=ok, lib=lib, text=match.group(1)))
|
|
||||||
return ok
|
|
||||||
|
|
||||||
def fix_line(match, mode):
|
|
||||||
lib = match.group(2).lower()
|
|
||||||
return match.group(1)+isc_config(mode, lib)+"\n"
|
|
||||||
|
|
||||||
def fix_file_lines(path, debug=False):
|
|
||||||
"""
|
|
||||||
Opens file and scans fixes selected parameters
|
|
||||||
|
|
||||||
Returns list of lines if something should be changed,
|
|
||||||
None if no action is required
|
|
||||||
"""
|
|
||||||
fixed = []
|
|
||||||
changed = False
|
|
||||||
with open(path, 'r') as fin:
|
|
||||||
fout = None
|
|
||||||
|
|
||||||
line = next(fin, None)
|
|
||||||
while line:
|
|
||||||
appended = False
|
|
||||||
while line.endswith("\\\n"):
|
|
||||||
line += next(fin, None)
|
|
||||||
|
|
||||||
inc = re_includes.match(line)
|
|
||||||
deplibs = re_deplibs.match(line)
|
|
||||||
libs = re_libs.match(line)
|
|
||||||
newline = None
|
|
||||||
if check_match(inc, debug=debug):
|
|
||||||
newline = fix_line(inc, '--cflags')
|
|
||||||
elif check_match(deplibs, debug=debug):
|
|
||||||
newline = fix_line(libs, None)
|
|
||||||
elif check_match(libs, debug=debug):
|
|
||||||
newline = fix_line(libs, '--libs')
|
|
||||||
|
|
||||||
if newline and line != newline:
|
|
||||||
changed = True
|
|
||||||
line = newline
|
|
||||||
|
|
||||||
fixed.append(line)
|
|
||||||
line = next(fin, None)
|
|
||||||
|
|
||||||
if not changed:
|
|
||||||
return None
|
|
||||||
else:
|
|
||||||
return fixed
|
|
||||||
|
|
||||||
def write_lines(path, lines):
|
|
||||||
fout = open(path, 'w')
|
|
||||||
for line in lines:
|
|
||||||
fout.write(line)
|
|
||||||
fout.close()
|
|
||||||
|
|
||||||
def print_lines(lines):
|
|
||||||
for line in lines:
|
|
||||||
print(line, end='')
|
|
||||||
|
|
||||||
if __name__ == '__main__':
|
|
||||||
parser = argparse.ArgumentParser(description='Makefile multiline include replacer')
|
|
||||||
parser.add_argument('files', nargs='+')
|
|
||||||
parser.add_argument('--filter', type=str,
|
|
||||||
default='isc isccc isccfg dns lwres bind9 irs',
|
|
||||||
help='List of libraries supported by isc-config.sh')
|
|
||||||
parser.add_argument('--check', action='store_true',
|
|
||||||
help='Test file only')
|
|
||||||
parser.add_argument('--print', action='store_true',
|
|
||||||
help='Print changed file only')
|
|
||||||
parser.add_argument('--debug', action='store_true',
|
|
||||||
help='Enable debug outputs')
|
|
||||||
|
|
||||||
args = parser.parse_args()
|
|
||||||
lib_filter = None
|
|
||||||
|
|
||||||
re_includes = re.compile(r'^\s*((\w+)_INCLUDES\s+=\s*).*')
|
|
||||||
re_deplibs = re.compile(r'^\s*((\w+)DEPLIBS\s*=).*')
|
|
||||||
re_libs = re.compile(r'^\s*((\w+)LIBS\s*=).*')
|
|
||||||
|
|
||||||
if args.filter:
|
|
||||||
lib_filter = set(args.filter.split(' '))
|
|
||||||
pass
|
|
||||||
|
|
||||||
for path in args.files:
|
|
||||||
lines = fix_file_lines(path, debug=args.debug)
|
|
||||||
if lines:
|
|
||||||
if args.print:
|
|
||||||
print_lines(lines)
|
|
||||||
elif not args.check:
|
|
||||||
write_lines(path, lines)
|
|
||||||
print('File {path} was fixed'.format(path=path))
|
|
||||||
else:
|
|
||||||
print('File {path} does not need fixing'.format(path=path))
|
|
||||||
|
|
@ -8,5 +8,5 @@ After=named-setup-rndc.service
|
||||||
[Service]
|
[Service]
|
||||||
Type=oneshot
|
Type=oneshot
|
||||||
RemainAfterExit=yes
|
RemainAfterExit=yes
|
||||||
ExecStart=/usr/libexec/%{name}/setup-named-chroot.sh /var/named/chroot on /etc/named-chroot.files
|
ExecStart=/usr/libexec/setup-named-chroot.sh /var/named/chroot on /etc/named-chroot.files
|
||||||
ExecStop=/usr/libexec/%{name}/setup-named-chroot.sh /var/named/chroot off /etc/named-chroot.files
|
ExecStop=/usr/libexec/setup-named-chroot.sh /var/named/chroot off /etc/named-chroot.files
|
||||||
|
|
@ -3,7 +3,6 @@
|
||||||
# if they are missing or empty in target directory.
|
# if they are missing or empty in target directory.
|
||||||
/etc/localtime
|
/etc/localtime
|
||||||
/etc/named.root.key
|
/etc/named.root.key
|
||||||
/etc/named.ca
|
|
||||||
/etc/named.conf
|
/etc/named.conf
|
||||||
/etc/named.rfc1912.zones
|
/etc/named.rfc1912.zones
|
||||||
/etc/rndc.conf
|
/etc/rndc.conf
|
||||||
|
|
@ -17,10 +16,7 @@
|
||||||
/etc/named
|
/etc/named
|
||||||
/usr/lib64/bind
|
/usr/lib64/bind
|
||||||
/usr/lib/bind
|
/usr/lib/bind
|
||||||
/usr/share/GeoIP
|
|
||||||
/usr/share/named
|
|
||||||
/run/named
|
/run/named
|
||||||
/proc/sys/net/ipv4/ip_local_port_range
|
|
||||||
# Warning: the order is important
|
# Warning: the order is important
|
||||||
# If a directory containing $ROOTDIR is listed here,
|
# If a directory containing $ROOTDIR is listed here,
|
||||||
# it MUST be listed last. (/var/named contains /var/named/chroot)
|
# it MUST be listed last. (/var/named contains /var/named/chroot)
|
||||||
|
|
|
||||||
|
|
@ -12,21 +12,20 @@ After=network.target
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
Type=forking
|
Type=forking
|
||||||
Environment=OPTIONS=
|
|
||||||
Environment=NAMEDCONF=/etc/named.conf
|
Environment=NAMEDCONF=/etc/named.conf
|
||||||
EnvironmentFile=-/etc/sysconfig/named
|
EnvironmentFile=-/etc/sysconfig/named
|
||||||
Environment=KRB5_KTNAME=/etc/named.keytab
|
Environment=KRB5_KTNAME=/etc/named.keytab
|
||||||
PIDFile=/var/named/chroot/run/named/named.pid
|
PIDFile=/var/named/chroot/run/named/named.pid
|
||||||
|
|
||||||
ExecStartPre=/bin/bash -c 'if [ ! "$DISABLE_ZONE_CHECKING" == "yes" ]; then %{_bindir}/named-checkconf%{program_suffix} -t /var/named/chroot -z "$NAMEDCONF"; else echo "Checking of zone files is disabled"; fi'
|
ExecStartPre=/bin/bash -c 'if [ ! "$DISABLE_ZONE_CHECKING" == "yes" ]; then /usr/sbin/named-checkconf -t /var/named/chroot -z "$NAMEDCONF"; else echo "Checking of zone files is disabled"; fi'
|
||||||
ExecStart=%{_sbindir}/named%{program_suffix} -u named -c ${NAMEDCONF} -t /var/named/chroot $OPTIONS
|
ExecStart=/usr/sbin/named -u named -c ${NAMEDCONF} -t /var/named/chroot $OPTIONS
|
||||||
|
|
||||||
ExecReload=/bin/sh -c 'if %{_sbindir}/rndc%{program_suffix} null > /dev/null 2>&1; then %{_sbindir}/rndc%{program_suffix} reload; else %{_bindir}/kill -HUP $MAINPID; fi'
|
; until https://github.com/systemd/systemd/pull/13098 is present, ignore return value
|
||||||
|
ExecReload=-/bin/sh -c 'if /usr/sbin/rndc null > /dev/null 2>&1; then /usr/sbin/rndc reload; else /bin/kill -HUP $MAINPID; fi'
|
||||||
|
|
||||||
ExecStop=/bin/sh -c '%{_sbindir}/rndc%{program_suffix} stop > /dev/null 2>&1 || %{_bindir}/kill -TERM $MAINPID'
|
ExecStop=/bin/sh -c '/usr/sbin/rndc stop > /dev/null 2>&1 || /bin/kill -TERM $MAINPID'
|
||||||
|
|
||||||
PrivateTmp=false
|
PrivateTmp=false
|
||||||
Restart=on-abnormal
|
|
||||||
|
|
||||||
[Install]
|
[Install]
|
||||||
WantedBy=multi-user.target
|
WantedBy=multi-user.target
|
||||||
27
named-pkcs11.service
Normal file
27
named-pkcs11.service
Normal file
|
|
@ -0,0 +1,27 @@
|
||||||
|
[Unit]
|
||||||
|
Description=Berkeley Internet Name Domain (DNS) with native PKCS#11
|
||||||
|
Wants=nss-lookup.target
|
||||||
|
Wants=named-setup-rndc.service
|
||||||
|
Before=nss-lookup.target
|
||||||
|
After=network.target
|
||||||
|
After=named-setup-rndc.service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=forking
|
||||||
|
Environment=NAMEDCONF=/etc/named.conf
|
||||||
|
EnvironmentFile=-/etc/sysconfig/named
|
||||||
|
Environment=KRB5_KTNAME=/etc/named.keytab
|
||||||
|
PIDFile=/run/named/named.pid
|
||||||
|
|
||||||
|
ExecStartPre=/bin/bash -c 'if [ ! "$DISABLE_ZONE_CHECKING" == "yes" ]; then /usr/sbin/named-checkconf -z "$NAMEDCONF"; else echo "Checking of zone files is disabled"; fi'
|
||||||
|
ExecStart=/usr/sbin/named-pkcs11 -u named -c ${NAMEDCONF} $OPTIONS
|
||||||
|
|
||||||
|
; until https://github.com/systemd/systemd/pull/13098 is present, ignore return value
|
||||||
|
ExecReload=-/bin/sh -c 'if /usr/sbin/rndc null > /dev/null 2>&1; then /usr/sbin/rndc reload; else /bin/kill -HUP $MAINPID; fi'
|
||||||
|
|
||||||
|
ExecStop=/bin/sh -c '/usr/sbin/rndc stop > /dev/null 2>&1 || /bin/kill -TERM $MAINPID'
|
||||||
|
|
||||||
|
PrivateTmp=true
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
12
named-sdb-chroot-setup.service
Normal file
12
named-sdb-chroot-setup.service
Normal file
|
|
@ -0,0 +1,12 @@
|
||||||
|
[Unit]
|
||||||
|
Description=Set-up/destroy chroot environment for named-sdb
|
||||||
|
BindsTo=named-sdb-chroot.service
|
||||||
|
Wants=named-setup-rndc.service
|
||||||
|
After=named-setup-rndc.service
|
||||||
|
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
RemainAfterExit=yes
|
||||||
|
ExecStart=/usr/libexec/setup-named-chroot.sh /var/named/chroot_sdb on /etc/named-chroot.files
|
||||||
|
ExecStop=/usr/libexec/setup-named-chroot.sh /var/named/chroot_sdb off /etc/named-chroot.files
|
||||||
31
named-sdb-chroot.service
Normal file
31
named-sdb-chroot.service
Normal file
|
|
@ -0,0 +1,31 @@
|
||||||
|
# Don't forget to add "$AddUnixListenSocket /var/named/chroot_sdb/dev/log"
|
||||||
|
# line to your /etc/rsyslog.conf file. Otherwise your logging becomes
|
||||||
|
# broken when rsyslogd daemon is restarted (due update, for example).
|
||||||
|
|
||||||
|
[Unit]
|
||||||
|
Description=Berkeley Internet Name Domain (DNS)
|
||||||
|
Wants=nss-lookup.target
|
||||||
|
Requires=named-sdb-chroot-setup.service
|
||||||
|
Before=nss-lookup.target
|
||||||
|
After=named-sdb-chroot-setup.service
|
||||||
|
After=network.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=forking
|
||||||
|
Environment=NAMEDCONF=/etc/named.conf
|
||||||
|
EnvironmentFile=-/etc/sysconfig/named
|
||||||
|
Environment=KRB5_KTNAME=/etc/named.keytab
|
||||||
|
PIDFile=/var/named/chroot_sdb/run/named/named.pid
|
||||||
|
|
||||||
|
ExecStartPre=/bin/bash -c 'if [ ! "$DISABLE_ZONE_CHECKING" == "yes" ]; then /usr/sbin/named-checkconf -t /var/named/chroot_sdb -z "$NAMEDCONF"; else echo "Checking of zone files is disabled"; fi'
|
||||||
|
ExecStart=/usr/sbin/named-sdb -u named -c ${NAMEDCONF} -t /var/named/chroot_sdb $OPTIONS
|
||||||
|
|
||||||
|
; until https://github.com/systemd/systemd/pull/13098 is present, ignore return value
|
||||||
|
ExecReload=-/bin/sh -c 'if /usr/sbin/rndc null > /dev/null 2>&1; then /usr/sbin/rndc reload; else /bin/kill -HUP $MAINPID; fi'
|
||||||
|
|
||||||
|
ExecStop=/bin/sh -c '/usr/sbin/rndc stop > /dev/null 2>&1 || /bin/kill -TERM $MAINPID'
|
||||||
|
|
||||||
|
PrivateTmp=false
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
1
named-sdb.8
Normal file
1
named-sdb.8
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
.so man8/named.8.gz
|
||||||
27
named-sdb.service
Normal file
27
named-sdb.service
Normal file
|
|
@ -0,0 +1,27 @@
|
||||||
|
[Unit]
|
||||||
|
Description=Berkeley Internet Name Domain (DNS)
|
||||||
|
Wants=nss-lookup.target
|
||||||
|
Wants=named-setup-rndc.service
|
||||||
|
Before=nss-lookup.target
|
||||||
|
After=named-setup-rndc.service
|
||||||
|
After=network.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=forking
|
||||||
|
Environment=NAMEDCONF=/etc/named.conf
|
||||||
|
EnvironmentFile=-/etc/sysconfig/named
|
||||||
|
Environment=KRB5_KTNAME=/etc/named.keytab
|
||||||
|
PIDFile=/run/named/named.pid
|
||||||
|
|
||||||
|
ExecStartPre=/bin/bash -c 'if [ ! "$DISABLE_ZONE_CHECKING" == "yes" ]; then /usr/sbin/named-checkconf -z "$NAMEDCONF"; else echo "Checking of zone files is disabled"; fi'
|
||||||
|
ExecStart=/usr/sbin/named-sdb -u named -c ${NAMEDCONF} $OPTIONS
|
||||||
|
|
||||||
|
; until https://github.com/systemd/systemd/pull/13098 is present, ignore return value
|
||||||
|
ExecReload=-/bin/sh -c 'if /usr/sbin/rndc null > /dev/null 2>&1; then /usr/sbin/rndc reload; else /bin/kill -HUP $MAINPID; fi'
|
||||||
|
|
||||||
|
ExecStop=/bin/sh -c '/usr/sbin/rndc stop > /dev/null 2>&1 || /bin/kill -TERM $MAINPID'
|
||||||
|
|
||||||
|
PrivateTmp=true
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
Some files were not shown because too many files have changed in this diff Show more
Loading…
Add table
Add a link
Reference in a new issue