Commit graph

109 commits

Author SHA1 Message Date
Petr Menšík
d049194f6a Initial attempt to test resolution in iterative mode
Requires unrestricted DNS servers access.
2024-04-03 17:06:20 +02:00
Petr Menšík
c391126fc9 Additional improvements to caching dnssec forwarder
Try multiple starts of named. Trust anchor management might not properly
initialize keys. Ensure they work also after restarts.
2024-03-26 12:24:51 +01:00
Petr Menšík
ef374282fe Use next resolv.conf if first is is security-unaware
Check servers in the most preferred resolv.conf file. If it does not
contain security-aware servers, try next file. Only use fallback
addresses if none of detected servers works with DNSSEC.
2024-03-20 16:54:10 +01:00
Petr Menšík
34be987e9e Fix delv check 2024-03-20 14:28:49 +01:00
Petr Menšík
db71acdb1a Handle better case when no provided server works 2024-03-20 14:25:49 +01:00
Petr Menšík
34632deacc Workarounds for completely DNSSEC-unaware architecture
Instead of hard failures, try to use custom servers.
2024-03-20 13:39:26 +01:00
Petr Menšík
b37c1f3153 Ensure keyId is non-empty and non-zero 2024-03-20 11:28:51 +01:00
Petr Menšík
aea5744967 Rename more functions to move them into bind-utils library 2024-03-19 20:59:51 +01:00
Petr Menšík
dabbd04134 Change to support also alternative packages
Print also used version of dig and named.
2024-03-19 13:20:39 +01:00
Petr Menšík
fc54993c93 Forwarder with DNSSEC enabled test
Basic sanity test configuring forwarder, with enabled dnssec. Check that
known signed domains are indeed signed and marked as such. Check that
few unsigned zones are also marked as unsigned.

Checks also trust anchor is trusted and automatically installed.
2024-03-19 13:02:59 +01:00
Petr Menšík
c51ba65c14 Install python3-dns and pytest
BIND 9.16 still provides python3 modules and can test them using pytest.
cds test can use python3-dns, if it is installed.
2024-02-19 22:46:19 +01:00
Petr Menšík
76a41d1775 Disable upstream test suite when checking rhel 2023-10-17 12:28:20 +02:00
Petr Menšík
2ddad6ff92 Workarounds to DNSSEC failing infrastructure
Be it systemd-resolved activation or some servers not providing working
dnssec, it needs workarounds to resolv.conf.
2023-08-25 16:11:06 +02:00
Petr Menšík
87e2d28453 Convert remaining tests to work with alternative components
Expand adjusting based on components to more alternatives
2023-08-25 15:14:41 +02:00
Petr Menšík
e82b8c0c33 Make more components conditionally run
Expand component adjusts and ability to test multiple components.
2023-08-25 13:31:36 +02:00
Petr Menšík
b39f2d88cd Extend delv tests to include more details 2023-08-25 12:47:53 +02:00
Petr Menšík
acbc9195fe Add unset component and bind9.16 rhel8 component support 2023-08-25 12:47:53 +02:00
Petr Menšík
928e44fe35 First attempt to support multiple components 2023-08-25 12:43:02 +02:00
Petr Menšík
d9f5b1efa6 fixup! Try conditionalizing tests 2023-01-30 20:21:50 +01:00
Petr Menšík
c9d17c4eb0 Correct reproducer to pass
Skip inclusion of TCP control port, which makes the test failing. It is
not wanted in the test anyway.
2023-01-30 19:00:01 +01:00
Petr Menšík
4e305a97d5 Adjust also geoip test
Only this test is enabled at the moment.
2023-01-30 18:37:34 +01:00
Petr Menšík
ecafc60535 Try conditionalizing tests
Accept both component bind or bind9-next. Expects component is set from
CI plan specified per component, but from shared tests/bind repository.
2023-01-30 17:48:52 +01:00
Petr Menšík
2da9e653c8 Adapt test to run even for different than bind pkg
We already have multiple packages with different versions of bind. They
can be in RHEL or Fedora. Attempt to support even alternative packages
run by overriding PACKAGE environment variable to different base SRPM
name.
2023-01-29 14:02:50 +01:00
Petr Menšík
85d8ed4279 Update to RHEL test variant 2022-09-09 17:30:26 +02:00
Petr Menšík
556e3d028c Get Back internal test suite
Imported back from commit 45a1f718bf
2022-09-09 15:33:22 +02:00
Petr Menšík
8092bee1d3 Remove dnssec-enabled yes statement
It is not supported since 9.16+ and is always enabled. It is also
enabled by default on earlier 9.11. There is no reason it has to be
present, except maybe for very old 9.8 or 9.9 versions.
2022-08-04 12:40:23 +02:00
Petr Sklenar
73f9f200e5 Merge #7 Update Smoke/IpaInstallAndStart/main.fmf 2022-04-21 06:42:11 +00:00
Petr Sklenar
63eedc2dc1 bind should work now. 2022-04-20 09:33:25 +02:00
Petr Sklenar
5884358117 pkgs version 2022-02-01 13:26:47 +01:00
Petr Sklenar
40c4349cbb bind version 2022-02-01 12:24:57 +01:00
Petr Sklenar
a22c89f577 bind version 2022-02-01 12:05:13 +01:00
ead5877218 Update Smoke/IpaInstallAndStart/main.fmf 2022-02-01 10:59:50 +00:00
Petr Sklenar
52aed22757 test debug 2022-02-01 11:54:19 +01:00
Petr Sklenar
c8ecdd51bc contact 2022-02-01 11:32:48 +01:00
Petr Sklenar
eb1fc037c0 more time 2022-02-01 11:19:21 +01:00
Petr Sklenar
bf030a963e debug 2022-02-01 11:11:52 +01:00
Petr Sklenar
b272549544 time adjust 2022-02-01 10:58:07 +01:00
Petr Sklenar
57d80fe8c1 x 2022-02-01 10:00:30 +01:00
Petr Sklenar
97338774c9 not needed 2022-02-01 09:45:15 +01:00
Petr Sklenar
4d1ef0e170 not needed 2022-02-01 09:44:54 +01:00
Petr Sklenar
6b45cd8619 init 2022-02-01 09:36:40 +01:00
Petr Sklenar
3388031dae pause tests CoreOS-bind-Regression-bz1769876-BIND-stops-DNSKEY-lookup-in-get-dst-key-1_0-1 2022-01-24 15:38:51 +01:00
a4f9b2e8e6 Merge #1 Adding plans/ci.fmf 2022-01-05 11:37:37 +00:00
Petr Sklenar
a5f5fa480b test needs libs, pausing for now 2022-01-05 08:34:38 +01:00
Petr Sklenar
03795605c7 Adding test 2022-01-04 20:02:32 +01:00
Petr Sklenar
3bf810abc7 Adding test 2022-01-04 20:01:53 +01:00
Petr Sklenar
609e63fec6 Adding test 2022-01-04 20:01:12 +01:00
Petr Sklenar
1d4563e817 Adding test 2022-01-04 19:55:24 +01:00
Petr Sklenar
f664f37374 Adding test 2022-01-04 19:52:20 +01:00
Petr Sklenar
eaea7ebe19 adding dir 2022-01-04 19:46:11 +01:00