Add signzone command. (#8)

Note: Lacks Bubble Babble and OpenSSL Engine support compared to the original `ldns-signzone`.
This commit is contained in:
Ximon Eighteen
2025-06-02 14:32:55 +02:00
committed by GitHub
parent 0dcd6ee03c
commit 7ec5de2bc6
58 changed files with 6717 additions and 589 deletions
+6 -6
View File
@@ -11,12 +11,12 @@ jobs:
os: [ubuntu-latest, windows-latest, macOS-latest]
rust: [1.79.0, stable, beta, nightly]
env:
RUSTFLAGS: "-D warnings"
# We use 'vcpkg' to install OpenSSL on Windows.
VCPKG_ROOT: "${{ github.workspace }}\\vcpkg"
VCPKGRS_TRIPLET: x64-windows-release
# Ensure that OpenSSL is dynamically linked.
VCPKGRS_DYNAMIC: 1
RUSTFLAGS: "-D warnings"
# We use 'vcpkg' to install OpenSSL on Windows.
VCPKG_ROOT: "${{ github.workspace }}\\vcpkg"
VCPKGRS_TRIPLET: x64-windows-release
# Ensure that OpenSSL is dynamically linked.
VCPKGRS_DYNAMIC: 1
steps:
- name: Checkout repository
uses: actions/checkout@v1
Generated
+881 -400
View File
File diff suppressed because it is too large Load Diff
+12 -2
View File
@@ -31,15 +31,23 @@ domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "main", fea
"bytes",
"net",
"resolv",
"tokio-stream",
"tsig",
"unstable-client-transport",
"unstable-sign",
"unstable-validator",
"zonefile",
"unstable-zonetree",
] }
lexopt = "0.3.0"
rayon = "1.10.0"
octseq = "0.5.2"
ring = "0.17.8"
tokio = "1.40.0"
# LDNS-xxx mode specific dependencies.
# TODO: put these behind a feature gate?
jiff = { version = "0.1.15", default-features = false, features = ["alloc", "std"] }
# This is a workaround. lazy_static 1.0.0 fails to compile, but sharded-slab
# still uses it. And sharded-slab is used by tracing-subscriber, which is
# used by domain, which is used by us.
@@ -48,9 +56,11 @@ tracing = "0.1.41"
tracing-subscriber = "0.3.19"
[dev-dependencies]
const_format = " 0.2.33"
test_bin = "0.4.0"
tempfile = "3.14.0"
tempfile = "3.20.0"
regex = "1.11.1"
domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "main", features = [
"unstable-stelline",
] }
pretty_assertions = "1.4.1"
+65 -14
View File
@@ -20,7 +20,8 @@ Arguments
.. option:: <ZONEFILE>
The zonefile to sign.
The zonefile to sign. Any existing NSEC(3) and/or RRSIG resource records
will be skipped when loading the file.
.. option:: <KEY>...
@@ -29,11 +30,6 @@ Arguments
Options
-------
.. option:: -b
Add comments on DNSSEC records. Without this option only DNSKEY RRs
will have their key tag annotated in the comment.
.. option:: -d
Do not add used keys to the resulting zonefile.
@@ -55,8 +51,7 @@ Options
.. option:: -o <DOMAIN>
Set the origin for the zone (only necessary for zonefiles with relative
names and no $ORIGIN).
Set the origin for the zone. Mandatory.
.. option:: -u
@@ -71,9 +66,33 @@ Options
are used: SHA-1, no extra iterations, empty salt. To use different NSEC3
settings see :ref:`dnst-signzone-nsec3-options`.
.. option:: -A
Sign DNSKEYs with all keys instead of the minimal set.
.. option:: -U
Sign with every unique algorithm in the provided keys.
.. option:: -z <[SCHEME:]HASH>
Add a ZONEMD resource record. Accepts both mnemonics and numbers.
This option can be provided more than once to add multiple ZONEMD RRs.
However, only one per scheme-hash tuple will be added.
| HASH supports ``SHA384`` (1) and ``SHA512`` (2).
| SCHEME supports ``SIMPLE`` (1), the default.
.. option:: -Z
Allow adding ZONEMD RRs without signing the zone. With this option, the
<KEY>... argument becomes optional and determines whether to sign the
zone.
.. option:: -H
Hash only, don't sign.
Hash only, don't sign. With this option, the normally mandatory <KEY>...
argument can be omitted.
.. option:: -h, --help
@@ -81,6 +100,36 @@ Options
``--help``).
.. _dnst-signzone-formatting-options:
Output formatting options
--------------------------------
The following options can be used to affect the format of the output.
.. option:: -b
Add comments on DNSSEC records. Without this option only DNSKEY RRs
will have their key tag annotated in the comment.
.. option:: -L
Preceed the zone output by a list that contains the NSEC3 hashes of the
original ownernames.
.. option:: -O
Order NSEC3 RRs by unhashed owner name.
.. option:: -R
Order RRSIG RRs by the record type that they cover.
.. option:: -T
Output YYYYMMDDHHmmSS RRSIG timestamps instead of seconds since epoch.
.. _dnst-signzone-nsec3-options:
NSEC3 options
@@ -93,22 +142,24 @@ settings used.
Specify the hashing algorithm. Defaults to SHA-1.
.. option:: -t <NUMBER>
Set the number of extra hash iterations. Defaults to 0.
.. option:: -s <STRING>
Specify the salt as a hex string. Defaults to ``-``, meaning empty salt.
.. option:: -t <NUMBER>
Set the number of extra hash iterations. Defaults to 0.
.. option:: -p
Set the opt-out flag on all NSEC3 RRs.
.. option:: -A
.. option:: -P
Set the opt-out flag on all NSEC3 RRs and skip unsigned delegations.
.. TODO: document nsec3_opt_out
.. _dnst-signzone-dates:
DATES
+110 -25
View File
@@ -9,11 +9,12 @@ Synopsis
Description
-----------
**ldns-signzone** signs the zone with the given key(s).
``ldns-signzone`` is used to generate a DNSSEC signed zone. When run it will
create a new zonefile that contains RRSIG and NSEC(3) resource records, as
specified in RFC 4033, RFC 4034, RFC 4035 and RFC 5155.
Keys must be specified by their base name (usually ``K<name>+<alg>+<id>``),
i.e. WITHOUT the ``.private`` or ``.key`` extension. Both ``.private`` and
``.key`` files are required.
This is a re-implementation of the original ``ldns-signzone`` which is largely
compatible with the original with some exceptions which are noted below.
Arguments
---------
@@ -22,17 +23,63 @@ Arguments
The zonefile to sign.
Note: Unlike the original LDNS, any existing NSEC(3), NSEC3PARAM and/or
RRSIG resource records will be skipped when loading the zonefile.
Note: Unlike the original LDNS, the origin must be explicitly specified
either via an ``$ORIGIN`` directive in the zonefile or using the ``-o``
command line argument.
.. option:: <KEY>...
The keys to sign the zonefile with.
Keys must be specified by their base file name (usually
``K<name>+<alg>+<id>``), i.e. WITHOUT the ``.private`` or ``.key``
extension, with an optional path prefix. The ``.private`` file is
required to exist. The ``.key`` file will be used if a ``DNSKEY`` record
corresponding to the ``.private`` key cannot be found.
Multiple keys can be specified. Key Signing Keys are used as such when
they are either already present in the zone, or specified in a ``.key``
file, and have the Secure Entry Point flag set.
Note: Unlike the original LDNS:
- Public keys corresponding to ``.private`` key MUST be supplied,
either as DNSKEY RRs in the given zone or as ``.key`` files. This
Implementation is not able to generate missing public keys.
- Supported DNSKEY algorithms are the ones supported by the
domain crate. Supported algorithms include RSASHA256,
ECDSAP256SHA256, and ED25519 but exclude RSHASHA1 and
RSASHA1-NSEC3-SHA1.
Options
-------
.. option:: -a
Sign the DNSKEY records with all keys. By default it is signed with a
minimal number of keys, to keep the response size for the DNSKEY query
small, only the SEP keys that are passed are used. If there are no
SEP keys, the DNSKEY RRset is signed with the non-SEP keys. This option
turns off the default and all keys are used to sign the DNSKEY RRset.
.. option:: -b
Add comments on DNSSEC records. Without this option only DNSKEY RRs
will have their key tag annotated in the comment.
Augments the zone and the RR's with extra comment texts for a more
readable layout, easier to debug. NSEC3 records will have the unhashed
owner names in the comment text.
Without this option, only DNSKEY RR's will have their Key Tag annotated
in the comment text.
Note: This option is ignored if the ``-f -`` is used.
Note: Unlike the original LDNS, DS records are printed without a
bubblebabble version of the data in the comment text, and some ordering
for easier consumption by humans is ONLY done if ``-b`` is in effect,
e.g. ordering RRSIGs after the record they cover, and ordering NSEC3
hashes by unhashed owner name rather than by hashed owner name.
.. option:: -d
@@ -40,57 +87,84 @@ Options
.. option:: -e <DATE>
Set the expiration date of signatures to this date (see
:ref:`ldns-signzone-dates`). Defaults to 4 weeks from now.
Set the expiration timestamp of signatures to the given date (and time,
optionally, see :ref:`ldns-signzone-dates` for details about acceptable
formats for the given ``<DATE>`` value). Defaults to 4 weeks from now.
.. option:: -f <FILE>
Write signed zone to file. Use ``-f -`` to output to stdout. Defaults to
``<ZONEFILE>.signed``.
.. option:: -h
Print the help text.
.. option:: -i <DATE>
Set the inception date of signatures to this date (see
:ref:`ldns-signzone-dates`). Defaults to now.
.. option:: -o <DOMAIN>
Set the origin for the zone (only necessary for zonefiles with
relative names and no $ORIGIN).
.. option:: -u
Set SOA serial to the number of seconds since Jan 1st 1970.
Set the inception timestamp of signatures to the given date (and time,
optionally, see :ref:`ldns-signzone-dates` for details about acceptable
formats for the given ``<DATE>`` value). Defaults to now.
.. option:: -n
Use NSEC3 instead of NSEC. If specified, you can use extra options (see
:ref:`ldns-signzone-nsec3-options`).
.. option:: -h
.. option:: -o <DOMAIN>
Print the help text.
Use this as the origin for the zone (only necessary for zonefiles with
relative names and no $ORIGIN).
.. option:: -u
Set the SOA serial in the resulting zonefile to the given number of
seconds since Jan 1st 1970.
.. option:: -u
Sign with every unique algorithm in the provided keys. The DNSKEY set is
signed with all the SEP keys, plus all the non-SEP keys that have an
algorithm that was not present in the SEP key set.
.. option:: -v
Print the version and exit.
.. option:: -z <[SCHEME:]HASH>
Add a ZONEMD resource record. Accepts both mnemonics and numbers.
This option can be provided more than once to add multiple ZONEMD RRs.
However, only one per scheme-hash tuple will be added.
| HASH supports ``sha384`` (1) and ``sha512`` (2).
| SCHEME supports ``simple`` (1), the default.
.. option:: -Z
Allow adding ZONEMD RRs without signing the zone. With this option, the
<KEY>... argument becomes optional and determines whether to sign the
zone.
.. _ldns-signzone-nsec3-options:
NSEC3 options
--------------------------------
-------------
The following options can be used with ``-n`` to override the default NSEC3
settings used.
.. option:: -a <ALGORITHM>
Specify the hashing algorithm. Defaults to SHA-1.
Specify the hashing algorithm. Only SHA-1 is supported.
.. option:: -t <NUMBER>
Set the number of extra hash iterations. Defaults to 1.
Set the number of extra hash iterations. Defaults to 0.
Note: The default value differs to that of the original LDNS which has a
default of 1. The new default value is in accordance with RFC 9276
"Guidance for NSEC3 Parameter Settings".
.. option:: -s <STRING>
@@ -102,8 +176,19 @@ settings used.
.. _ldns-signzone-dates:
DATES
Engine Options
--------------
Unlike the original LDNS, OpenSSL engines and their associated command line
arguments are not supported by this re-implementation.
Dates
-----
A date can be a UNIX timestamp as seconds since the Epoch (1970-01-01
00:00 UTC), or of the form ``<YYYYMMdd[hhmmss]>``.
Note: RRSIG inception and expiration timestamps in the signed output zone will
be in unsigned decimal integer form (indicating seconds since 1 January 1970
00:00:00 UTC) unlike the original LDNS which produced timestamps in the form
``YYYYMMDDHHmmSS``.
+1 -1
View File
@@ -14,7 +14,7 @@ fn main() -> ExitCode {
let mut args = std::env::args_os();
args.next().unwrap();
let args =
try_ldns_compatibility(args).map(|args| args.expect("ldns commmand is not recognized"));
try_ldns_compatibility(args).map(|args| args.expect("ldns commmand lacks ldns- prefix"));
match args.and_then(|args| args.execute(&env)) {
Ok(()) => ExitCode::SUCCESS,
+7 -4
View File
@@ -4,6 +4,7 @@ pub mod key2ds;
pub mod keygen;
pub mod notify;
pub mod nsec3hash;
pub mod signzone;
pub mod update;
use clap::crate_version;
@@ -57,6 +58,10 @@ pub enum Command {
#[command(name = "nsec3-hash")]
Nsec3Hash(self::nsec3hash::Nsec3Hash),
/// Sign the zone with the given key(s)
#[command(name = "signzone")]
SignZone(self::signzone::SignZone),
/// Send a NOTIFY packet to DNS servers
///
/// This tells them that an updated zone is available at the primaries. It can perform TSIG
@@ -87,6 +92,7 @@ impl Command {
Self::Keygen(keygen) => keygen.execute(env),
Self::Nsec3Hash(nsec3hash) => nsec3hash.execute(env),
Self::Notify(notify) => notify.execute(env),
Self::SignZone(signzone) => signzone.execute(env),
Self::Update(update) => update.execute(env),
Self::Help(help) => help.execute(),
Self::Report(s) => {
@@ -113,10 +119,7 @@ pub trait LdnsCommand {
fn parse_ldns<I: IntoIterator<Item = OsString>>(args: I) -> Result<Args, Error>;
fn parse_ldns_args<I: IntoIterator<Item = OsString>>(args: I) -> Result<Args, Error> {
match Self::parse_ldns(args) {
Ok(c) => Ok(c),
Err(e) => Err(format!("{e}\n\n{}", Self::HELP).into()),
}
Self::parse_ldns(args).map_err(|e| format!("{e}\n\n{}", Self::HELP).into())
}
fn report_help() -> Args {
+4 -3
View File
@@ -176,7 +176,7 @@ mod tests {
use domain::rdata::nsec3::Nsec3Salt;
use crate::commands::nsec3hash::Nsec3Hash;
use crate::env::fake::{FakeCmd, FakeEnv, FakeStream};
use crate::env::fake::{FakeCmd, FakeEnv};
// Note: For the types we use that are provided by the domain crate,
// construction of them from bad inputs should be tested in that
@@ -188,8 +188,9 @@ mod tests {
fn execute() {
let env = FakeEnv {
cmd: FakeCmd::new(["unused"]),
stdout: FakeStream::default(),
stderr: FakeStream::default(),
stdout: Default::default(),
stderr: Default::default(),
seconds_since_epoch: Default::default(),
stelline: None,
};
File diff suppressed because it is too large Load Diff
+25 -3
View File
@@ -17,8 +17,8 @@ use domain::stelline::parse_stelline::{self, Stelline};
use crate::error::Error;
use crate::{parse_args, run, Args};
use super::Env;
use super::Stream;
use super::{Env, RealEnv};
/// A command to run in a [`FakeEnv`]
///
@@ -53,6 +53,9 @@ pub struct FakeEnv {
/// The mocked stderr
pub stderr: FakeStream,
/// The mocked current time, if any
pub seconds_since_epoch: Option<u32>,
pub stelline: Option<(Stelline, Arc<CurrStepValue>)>,
}
@@ -82,6 +85,17 @@ impl Env for FakeEnv {
}
}
fn seconds_since_epoch(&self) -> u32 {
match self.seconds_since_epoch {
Some(seconds) => seconds,
None => RealEnv.seconds_since_epoch(),
}
}
fn set_seconds_since_epoch(&mut self, seconds: u32) {
self.seconds_since_epoch = Some(seconds);
}
fn dgram(
&self,
_src: SocketAddr,
@@ -165,6 +179,7 @@ impl FakeCmd {
cmd: self.clone(),
stdout: Default::default(),
stderr: Default::default(),
seconds_since_epoch: None,
stelline: None,
};
parse_args(env)
@@ -172,17 +187,24 @@ impl FakeCmd {
/// Run the [`FakeCmd`] in a [`FakeEnv`], returning a [`FakeResult`]
pub fn run(&self) -> FakeResult {
let env = FakeEnv {
self.run_with_modified_env(|_| {})
}
pub fn run_with_modified_env<F: Fn(&mut FakeEnv)>(&self, env_modifier: F) -> FakeResult {
let mut env = FakeEnv {
cmd: self.clone(),
stdout: Default::default(),
stderr: Default::default(),
seconds_since_epoch: None,
stelline: self
.stelline
.clone()
.map(|s| (s, Arc::new(CurrStepValue::new()))),
};
let exit_code = run(&env);
env_modifier(&mut env);
let exit_code = run(&mut env);
FakeResult {
exit_code,
+61 -12
View File
@@ -6,15 +6,15 @@ use std::path::Path;
use std::sync::Mutex;
use std::{fmt, io};
mod real;
use domain::net::client::protocol::{AsyncConnect, AsyncDgramRecv, AsyncDgramSend};
use domain::resolv::{stub::conf::ResolvConf, StubResolver};
use tracing_subscriber::fmt::MakeWriter;
#[cfg(test)]
pub mod fake;
use domain::net::client::protocol::{AsyncConnect, AsyncDgramRecv, AsyncDgramSend};
use domain::resolv::{stub::conf::ResolvConf, StubResolver};
mod real;
pub use real::RealEnv;
use tracing_subscriber::fmt::MakeWriter;
pub trait Env {
/// Get an iterator over the command line arguments passed to the program
@@ -38,6 +38,14 @@ pub trait Env {
/// Make relative paths absolute.
fn in_cwd<'a>(&self, path: &'a impl AsRef<Path>) -> Cow<'a, Path>;
/// Get the number of seconds since the UNIX epoch.
fn seconds_since_epoch(&self) -> u32;
/// Set the number of seconds since the UNIX epoch.
///
/// Only for use by FakeEnv, should not do anything in RealEnv.
fn set_seconds_since_epoch(&mut self, seconds: u32);
fn dgram(
&self,
src: SocketAddr,
@@ -107,14 +115,6 @@ impl<T: io::Write> Stream<T> {
}
impl<E: Env> Env for &E {
// fn make_connection(&self) {
// todo!()
// }
// fn make_stub_resolver(&self) {
// todo!()
// }
fn args_os(&self) -> impl Iterator<Item = OsString> {
(**self).args_os()
}
@@ -131,6 +131,55 @@ impl<E: Env> Env for &E {
(**self).in_cwd(path)
}
fn seconds_since_epoch(&self) -> u32 {
(**self).seconds_since_epoch()
}
fn set_seconds_since_epoch(&mut self, _seconds: u32) {
unreachable!()
}
fn dgram(
&self,
socket: SocketAddr,
) -> impl AsyncConnect<Connection: AsyncDgramRecv + AsyncDgramSend + Send + Sync + Unpin + 'static>
+ Clone
+ Send
+ Sync
+ 'static {
(**self).dgram(socket)
}
async fn stub_resolver_from_conf(&self, config: ResolvConf) -> StubResolver {
(**self).stub_resolver_from_conf(config).await
}
}
impl<E: Env> Env for &mut E {
fn args_os(&self) -> impl Iterator<Item = OsString> {
(**self).args_os()
}
fn stdout(&self) -> Stream<impl io::Write> {
(**self).stdout()
}
fn stderr(&self) -> Stream<impl io::Write + Send + Sync + 'static> {
(**self).stderr()
}
fn in_cwd<'a>(&self, path: &'a impl AsRef<Path>) -> Cow<'a, Path> {
(**self).in_cwd(path)
}
fn seconds_since_epoch(&self) -> u32 {
(**self).seconds_since_epoch()
}
fn set_seconds_since_epoch(&mut self, seconds: u32) {
(**self).set_seconds_since_epoch(seconds);
}
fn dgram(
&self,
src: SocketAddr,
+14
View File
@@ -14,6 +14,7 @@ use tokio::net::UdpSocket;
use super::Env;
use super::Stream;
use std::time::{SystemTime, UNIX_EPOCH};
/// Use real I/O
pub struct RealEnv;
@@ -43,6 +44,19 @@ impl Env for RealEnv {
path.as_ref().into()
}
fn seconds_since_epoch(&self) -> u32 {
let now = SystemTime::now();
let value = match now.duration_since(UNIX_EPOCH) {
Ok(value) => value,
Err(_) => UNIX_EPOCH.duration_since(now).unwrap(),
};
value.as_secs() as u32
}
fn set_seconds_since_epoch(&mut self, _seconds: u32) {
// NO OP
}
fn dgram(
&self,
src: SocketAddr,
+9
View File
@@ -42,6 +42,9 @@ impl fmt::Display for PrimaryError {
//--- Interaction
impl Error {
pub const RED: u8 = 31;
pub const YELLOW: u8 = 33;
/// Construct a new error from a string.
pub fn new(error: &str) -> Self {
Self(Box::new(Information {
@@ -108,6 +111,12 @@ impl From<String> for Error {
}
}
impl From<fmt::Error> for Error {
fn from(error: fmt::Error) -> Self {
Self::new(&error.to_string())
}
}
impl From<io::Error> for Error {
fn from(error: io::Error) -> Self {
Self::new(&error.to_string())
+11 -3
View File
@@ -6,12 +6,15 @@ use commands::key2ds::Key2ds;
use commands::keygen::Keygen;
use commands::notify::Notify;
use commands::nsec3hash::Nsec3Hash;
use commands::signzone::SignZone;
use commands::update::Update;
use commands::LdnsCommand;
use env::Env;
use error::Error;
use log::LogFormatter;
use domain::base::zonefile_fmt::DisplayKind;
pub use self::args::Args;
pub mod args;
@@ -22,6 +25,10 @@ pub mod log;
pub mod parse;
pub mod util;
/// Define the way that we output zonefile records once for consistent use
/// everywhere.
pub const DISPLAY_KIND: DisplayKind = DisplayKind::Tabbed;
pub fn try_ldns_compatibility<I: IntoIterator<Item = OsString>>(
args: I,
) -> Result<Option<Args>, Error> {
@@ -41,11 +48,12 @@ pub fn try_ldns_compatibility<I: IntoIterator<Item = OsString>>(
"notify" => Notify::parse_ldns_args(args_iter),
"keygen" => Keygen::parse_ldns_args(args_iter),
"nsec3-hash" => Nsec3Hash::parse_ldns_args(args_iter),
"signzone" => SignZone::parse_ldns_args(args_iter),
"update" => Update::parse_ldns_args(args_iter),
_ => return Err(format!("Unrecognized ldns command 'ldns-{binary_name}'").into()),
};
_ => Err(format!("Unrecognized ldns command 'ldns-{binary_name}'").into()),
}?;
Ok(Some(res?))
Ok(Some(res))
}
/// Get the binary name from a [`Path`].
+1
View File
@@ -0,0 +1 @@
example. IN DNSKEY 257 3 8 AwEAAaYL5iwWI6UgSQVcDZmH7DrhQU/P6cOfi4wXYDzHypsfZ1D8znPwoAqhj54kTBVqgZDHw8QEnMcS3TWxvHBvncRTIXhCLx0BNK5/6mcTSK2IDbxl0j4vkcQrOxc77tyExuFfuXouuKVtE7rggOJiX6ga5LJW2if6Jxe/Rh8+aJv7 ;{id = 31967 (ksk), size = 1024b}
+10
View File
@@ -0,0 +1,10 @@
Private-key-format: v1.2
Algorithm: 8 (RSASHA256)
Modulus: pgvmLBYjpSBJBVwNmYfsOuFBT8/pw5+LjBdgPMfKmx9nUPzOc/CgCqGPniRMFWqBkMfDxAScxxLdNbG8cG+dxFMheEIvHQE0rn/qZxNIrYgNvGXSPi+RxCs7Fzvu3ITG4V+5ei64pW0TuuCA4mJfqBrkslbaJ/onF79GHz5om/s=
PublicExponent: AQAB
PrivateExponent: InZhxVCrAUCcJzKd1/mv++B4j7oVSHa6nc7UOIk28c8owFRX/RQ6AzrY9feOmvtJ/OSZKvvSFjdCFjzXYXapBZqnqrXM0QJ3LA09u2OQNylc1PYj+QtrEhUbKBO9ujgfWw+JAg7eDxuoxfeDmsdQMa2Jx22mk2eJvTIvkLeTtME=
Prime1: 0zxbxvJdeJJn0q7guFpAj6gN8o9JLkDfDEGuY0eWKcCvBTAwT+SZWH3T3e316TS/PCUDvUCmbgJHVFwP8PUCKw==
Prime2: yTv/9Ysj5khXOy7KRhXcPyAwaHp+XtpfCd8msXjmthZI9Z45kvDX6iDOgADoIJQsoUCy8IOKiqd93wYpN091cQ==
Exponent1: aZPde05gEYd7hP4LK5lQc3zXm8iqFwgtc37QnqaFE1FPKRSw0P2891HMtzvckTbf7jvB5rGNfaZ96FgrT4/mCQ==
Exponent2: Q7x6kABh+SXolvdNBwJcvLLtGH4DA5Kl4wDGWX7Eyg3+SQ8VeiyvwROB7vxfJng5/Z11nhfpDnsKl4PPY9rPQQ==
Coefficient: TDG5Jgi0fbqUUkRhugX6VaWGllzt9pew5U3YnlCoNm2lT3s5jiYyaLwHWMmuYRJTAxU6/UheyGg1CL36fUh42w==
+1
View File
@@ -0,0 +1 @@
example. IN DNSKEY 256 3 8 AwEAAbsD4Tcz8hl2Rldov4CrfYpK3ORIh/giSGDlZaDTZR4gpGxGvMBwu2jzQ3m0iX3PvqPoaybC4tznjlJi8g/qsCRHhOkqWmjtmOYOJXEuUTb+4tPBkiboJM5QchxTfKxkYbJ2AD+VAUX1S6h/0DI0ZCGx1H90QTBE2ymRgHBwUfBt ;{id = 38353 (zsk), size = 1024b}
+10
View File
@@ -0,0 +1,10 @@
Private-key-format: v1.2
Algorithm: 8 (RSASHA256)
Modulus: uwPhNzPyGXZGV2i/gKt9ikrc5EiH+CJIYOVloNNlHiCkbEa8wHC7aPNDebSJfc++o+hrJsLi3OeOUmLyD+qwJEeE6SpaaO2Y5g4lcS5RNv7i08GSJugkzlByHFN8rGRhsnYAP5UBRfVLqH/QMjRkIbHUf3RBMETbKZGAcHBR8G0=
PublicExponent: AQAB
PrivateExponent: rUCY4nVDMgd6fvvRfbhhoz5biTkQjfXkq6+ZCPcOVGzVJmIZ9wX4+O90cUmpnl5ZNKvaqJwfY5s5JGX57njzF/FHBK1h8KIRIAFUyuuJFZfKC7IlvE6Jty6BZC3M+IG3NVRtnOKlv4mm2AHcEY6/a6gzkYWE6o05LTBJCd1xhFk=
Prime1: 89TrECdSSWCCIOvdbSfb/fEiYKNQViOqpKtte+DDyhbtLVhuDJ1QpiQIG2ia+Bc69S/u/tdIxGldu+yozCT6Kw==
Prime2: xFkZbpPOZWdt4CrTqq3gAUZHIXXW/89pRqDmfIcphFNKvuYZVH/prJla6xiNBzgWRnMOMJcc+61DjRhHOMrrxw==
Exponent1: rdSDaFbAITO+Ub4Vc/ZQre+09HQ5l8+Bnjfgq8oHixFhMUyz2CZnEqrpZLDkmi3liFsN5XyRkgUUIB+OD0vlVQ==
Exponent2: eJLSeEIR69mA8ri59MUDmyTCB30qwzpmRrYF9BC4YQcZDnOUuHw4TgJ6f4Y7DGTX4PlEjHgvlynGIr329pw9/w==
Coefficient: 5Q/xDoWngb0ahc3wFT42DIM2/E8SLRqkBZ/j0C2BKRi73g7OMXRWpDKf2z45WePP5p/SoTlYYHhRZmNngOoXlA==
+1
View File
@@ -0,0 +1 @@
example. IN DNSKEY 256 3 15 AnxyASt7Bws/Y883BjIsK+Vcl2rlR7fnGqoVHf+wY5o=
+3
View File
@@ -0,0 +1,3 @@
Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: JTalgoa6Cm+aDs0OPQxlrDgxQHFpZSgV5oOeX0kCzsA=
+1
View File
@@ -0,0 +1 @@
example. IN DNSKEY 256 3 15 vARhxM8vGTdL1DuBk8PIRWFZLcYeDAFgHepUiArciRU=
+3
View File
@@ -0,0 +1,3 @@
Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: c2+rvuWuvqOl+816GGJgNsuK0ffAVwt51BgeCXoCDCk=
+1
View File
@@ -0,0 +1 @@
example. IN DS 53470 15 2 1D94021DAF5F14E9C004AB1A699254B284DBF5952FC59D6982D3568047749AC5
+1
View File
@@ -0,0 +1 @@
example. IN DNSKEY 257 3 15 ABfITiMt1O3QAyTkpGVfkAk3mlV8W18/qqHv1BVW5Hs=
+3
View File
@@ -0,0 +1,3 @@
Private-key-format: v1.2
Algorithm: 15 (ED25519)
PrivateKey: ln+C5nOpkcSr1OWT4u3dfG3kdHAZ2nj/Gg1Km5vX8Ts=
+1
View File
@@ -0,0 +1 @@
example.org. IN DNSKEY 256 3 8 AwEAAcCIpalbX67WU8Z+gI/oaeD0EjOt41Py++X1HQauTfSB5gwivbGwIsqA+Qf5+/j3gcuSFRbFzyPfAb5x14jy/TU3MWXGfmJsJX/DeTqiMwfTQTTlWgMdqRi7JuQoDx3ueYOQOLTDPVqlyvF5/g7b9FUd4LO8G3aO2FfqRBjNG8px ;{id = 28954 (zsk), size = 1024b}
+10
View File
@@ -0,0 +1,10 @@
Private-key-format: v1.2
Algorithm: 8 (RSASHA256)
Modulus: wIilqVtfrtZTxn6Aj+hp4PQSM63jU/L75fUdBq5N9IHmDCK9sbAiyoD5B/n7+PeBy5IVFsXPI98BvnHXiPL9NTcxZcZ+Ymwlf8N5OqIzB9NBNOVaAx2pGLsm5CgPHe55g5A4tMM9WqXK8Xn+Dtv0VR3gs7wbdo7YV+pEGM0bynE=
PublicExponent: AQAB
PrivateExponent: twArFfI33CLztfN/l0k9eggDVQOu05hdPZHhaPw8NG9Tja1nyIC2UOyNx7sgeOAoiqnrSZ3y6RGKws3KI+1yJX3vfn5AMdDeiTFGn23ZpyPuTMQSMrgnuITN5ojYmkQTQ9zm7SC+NB3fgBi9jVL9BU+ldDyNo6aAAi0BFAnRPBE=
Prime1: +Lndcd79amU8sQ9h8bjbajAw2Wv2rJx68Du43fg5L3lnl++x2PbSsa8l4BlcIeJWL2fVJ8FymhkgN3UoTfyKww==
Prime2: xioWiN7ILVyJTII0qXhLnvrBQ0iECjtIeT2+Uoap+ZTppnmHtVh6hdbcFpL9QfnUZt/TV/bsDbf/iiiTT2D6uw==
Exponent1: 2AjAEbbIT5BNDdE5ljWkxm/DDiXbJIPpuB13bby7FsQROYOk6rk/ubtSX3pHbtrjVtuN5bD9dGEcfW7SKiKO9w==
Exponent2: ns1Fp8OYeTmJ0aUaXKDJQQrD645mOejOKFLBfVLrTdX28/C6Pyo7bZwEXZbHm6KAgzxlGj4HZusHvojLnDYkVw==
Coefficient: CQkN/JybQvotO32CNMGGRkz1Z0I9pIM4DcTTw8ynKVXUOngrmyVeg9IloFidBTWZS/RJv/gowCRN5oF8/z3i+w==
+1
View File
@@ -0,0 +1 @@
example.org. IN DS 51331 8 2 0745d6d9ba0a53e4e0a8970131600b55cc4918aeb94bd1638b20f84a2eea5ef5
+1
View File
@@ -0,0 +1 @@
example.org. IN DNSKEY 257 3 8 AwEAAckp/oMmocs+pv4KsCkCciazIl2+SohAZ2/bH2viAMg3tHAPjw5YfPNErUBqMGvN4c23iBCnt9TktT5bVoQdpXyCJ+ZwmWrFxlXvXIqG8rpkwHi1xFoXWVZLrG9XYCqLVMq2cB+FgMIaX504XMGk7WQydtV1LAqLgP3B8JA2Fc1j ;{id = 51331 (ksk), size = 1024b}
+10
View File
@@ -0,0 +1,10 @@
Private-key-format: v1.2
Algorithm: 8 (RSASHA256)
Modulus: ySn+gyahyz6m/gqwKQJyJrMiXb5KiEBnb9sfa+IAyDe0cA+PDlh880StQGowa83hzbeIEKe31OS1PltWhB2lfIIn5nCZasXGVe9ciobyumTAeLXEWhdZVkusb1dgKotUyrZwH4WAwhpfnThcwaTtZDJ21XUsCouA/cHwkDYVzWM=
PublicExponent: AQAB
PrivateExponent: VV13vuoO8LPmo5mfhdee32NXKxbMhCNogaQoIlzm3hAdhwxjNcBBTe6P4uztHWJh9y1yFTdHIJXpf8u83BXEml+Q5kYqVH47n5BMoYVLN/+z5NS8RyKgbE79uh5/b7qSmfWYO6cQksmt7eLfl4iip/xbE/mcq5Ov85zWIQCIjek=
Prime1: 8lK2PeLTfJqqVUQz1ok7/2awG1XpPv3By1tOfsJo9y1SxfqnX+atch+wjEXBHmTRZgBjn09wyM3JuQnt5v+BNw==
Prime2: 1ISU5m0Jek5GFK9zDOWjhTXOOxzbsDgFlKs3buHx1MngYJegc+p1xH5DwzCiWztBR3fnvFujEEGjdo/2GIrbNQ==
Exponent1: glCQyP8ulJfoeipPZlQu+86RbmHpKYL1sRLNR8XtBOBO30FIuX4oUHNSUl1A2cOGCMC00nu6P4LLtMLuOYe2SQ==
Exponent2: H69Ar/YzwotnAXCDG7olHhg+jiuoSWag1mCMnDiNoKcUj/IrVvzu4APfQHvAyQ9VlT04TKnw7tyKbYPbMh+JvQ==
Coefficient: JC7PAe7t8H2Cxj5LC7EOQh3K7SX1rq5U4HQmmg/B7vVm+CTqUA5ftkUOGF8KiUGXNGZD5JOOiRpmCG3IwUVb/w==
@@ -0,0 +1 @@
jelte.nlnetlabs.nl. IN DNSKEY 256 3 8 AwEAAbmZNEjurnAH9aav6UEJsoMWoTx/gGRd92xGrrVPC/JzDxL3Ksw8MkReNZGke1ChRnbIQ2f04yj8K5G9OjK/fxBh3J32G7IXdQHWQReBf4oxT1ReQXnZZ3FkiCqgkq5fsAlhO7KQBVSKAVCF17Cso8HAoyQSU6dwKbG27472OhOygEf/knw4nKo+VQpnK90dhs4NikHCI1veo+qd5Q3bFxWIJTWc0LwcWOGYcKZVzkZPCANqFCKANPXGdcqH+bTeAeVHzvM9oaXvseL9TjY5LBg+CMDRSfQv8tpIBk/iBoagDKJ3R8LdUF6SjH3ICVIprbXep98FaB1ZStowgOKPbCc=
@@ -0,0 +1,10 @@
Private-key-format: v1.2
Algorithm: 8 (RSASHA256)
Modulus: uZk0SO6ucAf1pq/pQQmygxahPH+AZF33bEautU8L8nMPEvcqzDwyRF41kaR7UKFGdshDZ/TjKPwrkb06Mr9/EGHcnfYbshd1AdZBF4F/ijFPVF5BedlncWSIKqCSrl+wCWE7spAFVIoBUIXXsKyjwcCjJBJTp3ApsbbvjvY6E7KAR/+SfDicqj5VCmcr3R2Gzg2KQcIjW96j6p3lDdsXFYglNZzQvBxY4ZhwplXORk8IA2oUIoA09cZ1yof5tN4B5UfO8z2hpe+x4v1ONjksGD4IwNFJ9C/y2kgGT+IGhqAMondHwt1QXpKMfcgJUimttd6n3wVoHVlK2jCA4o9sJw==
PublicExponent: AQAB
PrivateExponent: Cr+NQEQCT3PxN/asAsY1qP3LLJ5oUxJWB9aNZkFDpzDJSLHjr/GJ1QfCVm2OGVHzALdW9VLrQi5dtOeefTM11T8K8GLroQQBagUnE94TWBoZnACGuNsW8IF/7pK0q+stXf2xiq+91J2BYfu+TU781Mr70lT1X0Gm8ycYTHvZ9StMZWEcsT1dOJ00axMXyDtwvAleoBbdPWgEp1Q8HWTEPL8ve6bEPUeINvhovuq+bqL1L0wFL7kwSOez6HTrUEv7WqYmC9eE0MIWAVRfLEQHkgTMnnc6yNP7soPLIhXp1+r8B6innOTx2ZRrza+PjZaf7aDfPsBAbNmxg6ru9OCyIQ==
Prime1: +TBbSkr5BDS88V+XI/metoiZca8Y+E4JfoLeNtVgTcFa72Fp/jNvUTi5/eKb9cjf5bYyZvUI6NefkwOLtWx1PnwH2s9d/LcdOM5OSTOlco/um+t7rM9opgp4w5ZpWd8JMA1YjSOod38ngM47B9myjTuDn/h/Xv/+PV35XUx4bO8=
Prime2: vqvjRtHS1UGslBQRzjImqDIQw1nbN6BuhrbJYtXOc23Bz/dNIsC4h9+B4R2D+Tkf6c4l4beJMaAnXuB4ngvAKKKpcgy+o4Utew3HOSEeamLq1bPBAHkV9S50oUEc2wcLYD+5vHN13WyNiEiSuRXW8LSUWbjH1Wrqp38+M6cFZEk=
Exponent1: DqhghlM4qJ2ti4ky68PQKS6J0B0bm+eDOXTbO2B7xLcd8TzKrlA6OQ3cKun8gI2rVejMuC+rsX6VfWFVA3v4vY8wKxfNkIL47hF8m2O1VLLQt003vieJIVM2XVLoqYesE66FSfASBc1t9m6rHEAa96HLkUpdu6nVO6jedTV9U/M=
Exponent2: nWoXVy5/W2S+7/mpwYwR8iZzRHR40XH4Dev2U0ylBxMEQYev/RMSxco21f2iKS2KNWLmT3VRJNFN77xumDynRmUUc34mHaYjqEX1xiqbi8Vij0+59YQCJstVqpOxGPq135583yKLmmS2bF9OEtP/AfZzy6cMBBwi4mnglpA7mVE=
Coefficient: vO61lIEOgDwn5xR/OOrxt3N0fbGPHNB+DcW5p58tgkyeVLKHk12Lzs2pSzJ2hLuw1u9FMkDb/2fahMJY0BHHi6AphEA+CVPDAwEBsnSeQvQlkaSrCyRoimVrxT8Cdie1DOncC3h3jzfvGkY5ppBMNks1FjErIJZCN+g70CiKQw==
@@ -0,0 +1 @@
jelte.nlnetlabs.nl. IN DNSKEY 257 3 8 AwEAAe3iCDazOBQLVjCq6luwnF+r20OHHdrB98vLRxn7Hnc2E5MuB9nHguTEmBQGXNM3wf4cYr6n+56jw/lds3UyoATFA15cWQlTFt//jcoKbUH3gamY3i01cvMCqYN/pcVv651xudiDC1LZ1DgCsxnz2B22Rx1s6jpIUX8omv451E3T ;{id = 31310 (ksk), size = 1024b}
@@ -0,0 +1,10 @@
Private-key-format: v1.2
Algorithm: 8 (RSASHA256)
Modulus: 7eIINrM4FAtWMKrqW7CcX6vbQ4cd2sH3y8tHGfsedzYTky4H2ceC5MSYFAZc0zfB/hxivqf7nqPD+V2zdTKgBMUDXlxZCVMW3/+NygptQfeBqZjeLTVy8wKpg3+lxW/rnXG52IMLUtnUOAKzGfPYHbZHHWzqOkhRfyia/jnUTdM=
PublicExponent: AQAB
PrivateExponent: 3WZ2RpLfKqiye3FX1ia2I8ULufnTq3rEaoSzlFbIsCNAbMd2vxaVmN3wvRJ+6ocGor9AmDo4UhoRl9HB6N5JVtunClmmFg3GB+NP51gk5GYFDfWZUMm1CfJxpCpx7pQNjnwL6srwmXtejcZ//AlK80PR7ur5tn0Szaav0SvT/UE=
Prime1: +02gVgX5jJZ8wpHBNRQfEzzvovzFtWG9XExR72SgZBk+ZamSH/WoLJE9Qim9tgf7pFqz4eMya72ma8M923v2Ow==
Prime2: 8lQyGAz9ZKTcaIRCA1ilrLX+us59srV7QUkJfX5VJvelkRTc6bXFnySOC6N9EsonexyqjyNLqBfFoG5smRTVSQ==
Exponent1: LXk/gTF1lbYJf1/GmWc5tE57gn/A+vBjxpbc4LfRuitDOjwz/+qA8weZESbieFT7eSMcl8x37D0WJzveLqBAzw==
Exponent2: rWfkhONevBNhCYWC+4QG4iVFyAWVWzmUnq4WFXA+nOjf2IbWYoNJjE0LPHbcPILeZ7Gmt1DphbqlF92M5qpKyQ==
Coefficient: 8QvmhoHCpw92nB8L63qLcrANY8PhMGog3ypnvddvcaKMdWF/eJQCFwrP4LhEHTo8BT2FO0ckKGQ3ZJ5jyyX13A==
+1
View File
@@ -0,0 +1 @@
uri.arpa. IN DNSKEY 257 3 8 AwEAAahOTGtQI/HNtJgStghtd8Y4H26mPauZw1UFVSq/X5c3ThjRCd2KieTVokcUhZfWIw9AQmLEO4qJTPXreiXDRZTLm8O0M7jDXggzdnAxhstSaUITjBbvnBf1p2erI2BQK6d7mmsywEgJ8Fy5zhQGMwRpNCe8eDsEPHWdfhO++xxxCqeZQgGi++3M+9/R41qXpJUySlmlxUp0cE5OianyxcJEl5gOnVz9UXpcZeaZdyQuEkZVe1BcXgYB3tKPREujHTiwp+tXZHqfE3pqnDpepzR3tFrHoU3/KkreXP/8Xn0Behe8TByic8Gb60tFl5Q5Kb98poPKzTdeKv0PvhRL+VE=
+10
View File
@@ -0,0 +1,10 @@
Private-key-format: v1.2
Algorithm: 8 (RSASHA256)
Modulus: qE5Ma1Aj8c20mBK2CG13xjgfbqY9q5nDVQVVKr9flzdOGNEJ3YqJ5NWiRxSFl9YjD0BCYsQ7iolM9et6JcNFlMubw7QzuMNeCDN2cDGGy1JpQhOMFu+cF/WnZ6sjYFArp3uaazLASAnwXLnOFAYzBGk0J7x4OwQ8dZ1+E777HHEKp5lCAaL77cz739HjWpeklTJKWaXFSnRwTk6JqfLFwkSXmA6dXP1Relxl5pl3JC4SRlV7UFxeBgHe0o9ES6MdOLCn61dkep8TemqcOl6nNHe0WsehTf8qSt5c//xefQF6F7xMHKJzwZvrS0WXlDkpv3ymg8rNN14q/Q++FEv5UQ==
PublicExponent: AQAB
PrivateExponent: Ljx0WfbGKSNtvWlGgMIx6U55tBgPURkIxE6Wuwuf4xbaaY7juuzYPPlDf2tv1+qH7ySkGCX4hXJ6pgRupfkjIGFfBUB4BQYGyxH4M5Iniau2JuTf01038I0X1C77pPXhSD14ioKCuEeitJaGupGJamjMXy4ziWL8iQMfI6WPrpwdTWWXHHQY/APr53fYGs4RUBFU5uQT7o+v6TA4h1+ZuJ94lUCMgUbnzyM6DVMK7s6vsmhZ3qNowjm2B0h8awxVM3x+P6nTOAZzUH2ZzQZ/eSe0Hs4sqLtO3asgPg7pLy0hvXFX5loo8wXUtncO4DbwH0qb0RDRiNqoZnoC5ozTEQ==
Prime1: 1XhDQbUOmqiyKixhJ9zXb7K5JIckgQnnQUP2rizETn7rJo+R+MQb5oensuhxTQtjuRP6gg5KPUKEyTJbg8/5+durDyd4gqDWhScB8zb+M+4BKXGjdFSOWceHmdFLOcVcF7D/oQndRrWo+3dNtJUwDH7E0mFPpTUU0ctst+icr7M=
Prime2: ydaCz/ttrwSmrdIZqTI+wSsCfXcl04rzeA6bZuYAqjiVM4omDWTnbmNyw0Bm88DzUhJVVsbqYUuAYTM/lh3q/05v/M7nUNjK9ENbUY6bBpb0ZEGNHrbIPTCOPxlRi5Oq1NtKGbOzYjWK+Iaer4iX7P1zlv9SkQkb4u6aME7WkOs=
Exponent1: ku13vV4VczXxiz2IkZtbXTIyZIXwBjD+ztksjK2bYDvTNnNTEVpJqd5s+qMqeNECDn1FywZy6r9CDglvG8amU+dyUbflJmP1wygaG4Eabju+6PuieYtJf1nqZ2C62kSRIm1dRUY421ZlvM9c2JJmw/LtHbCE1T032z6c0eh1ECk=
Exponent2: T45l8WTBTwMeT9VImBBd+/Xf/WRBXKigXuojBuQRzwaOiMojRZRIRJKeYae47MtZHThsus+dAsynxahVn+4a+pcIPTWwp4VMOgtyqyryoB5QJlRQM5MISlYhO23XXpTN+SiWhJr4UfWY2Wz2j2nfuGIOda4d9V0JyOETlYb9vBE=
Coefficient: nCBiMy3WNFryX1dbH3KRBEbjZ70Egmb1R3iJVapfkktFOS8/fl30h2Ae3t/a9NA6LaKXr4xUVAulwk+FjoL2UeBQ4VCuDeYhAfZofKw96cjFORhx6hbPSUR5o99AaGb+WivrI3T5Mnc/JZYPzwCgRljfQT9eAK75/QZdgKsLSzM=
+1
View File
@@ -0,0 +1 @@
uri.arpa. IN DNSKEY 256 3 8 AwEAAbdA7hbl8YtfwjDxI1L06os3xkyehpGROhX8nLCwrwx3+veYbAWIdRahKN2SMSHrRtj8k7bRxJC5fhUweA5L8h4CDVGCOJhkOCni/O0xQ44MVT/bHF4WcCtAbThy8vlPj0xR0r0DkqEbuOsK+uJAJfgli5I5Im3VNB8RPBcfu42GR8ObDOLVxuDJ52A+ZGqH8H9VyGfuxtnjSVenkeQNQidwkfI6IWxrk1/H1G+Az/45yFDZGCWzqBX0yml6dplmxX9LMypPubeDQZniR+9hxut0Ig2Wh3c6yB/619A0P5gbtuO7gqrfkoEuZThEUzzqyKGOQV4UF2hU7BLABuyzch0=
+10
View File
@@ -0,0 +1,10 @@
Private-key-format: v1.2
Algorithm: 8 (RSASHA256)
Modulus: t0DuFuXxi1/CMPEjUvTqizfGTJ6GkZE6FfycsLCvDHf695hsBYh1FqEo3ZIxIetG2PyTttHEkLl+FTB4DkvyHgINUYI4mGQ4KeL87TFDjgxVP9scXhZwK0BtOHLy+U+PTFHSvQOSoRu46wr64kAl+CWLkjkibdU0HxE8Fx+7jYZHw5sM4tXG4MnnYD5kaofwf1XIZ+7G2eNJV6eR5A1CJ3CR8johbGuTX8fUb4DP/jnIUNkYJbOoFfTKaXp2mWbFf0szKk+5t4NBmeJH72HG63QiDZaHdzrIH/rX0DQ/mBu247uCqt+SgS5lOERTPOrIoY5BXhQXaFTsEsAG7LNyHQ==
PublicExponent: AQAB
PrivateExponent: BV4SMqnVUuhhBPWhCKzEg+n7qvWUg8pCmWK7JNjMyE1pWNnMn2FEDX+6/f3h5nYinasmXWO0YYCs2Ag9gMZ/bDR0DGl+ys6NeAvPabXtyPwrSqhJRP0pdZT9Aj9L8XZ3M2T3m5SLLRhDaL429IW9v39uj52hy9PUrAZHxf7RLc+7aEtZUdza+pXo8Xi/MoR/NxI/GteDEaMWyjCOMYwD7rVFvP6YsKPt9LPkPp57dHkdphM0mtG+6rWKCJIMQeM/IDw53P/TnwcujyansSMq2r5Y459ml4PacCULHc9TM3O1A+krTPg4qmUazDg15AKMfoHe6j8RA9z4peNJc/5+dw==
Prime1: +ozZtO7aPodRs8eEUz4pr9kvoACu45mW10HZYf1GqLpX1YacMb0Dg+rCnWl4PiDfIW37eS9KOmVH9PFV3gGkfWKW3bzIGX/mnEJfDgzTvXFydYyRY8b3IxbOq8YZZB2wxRzUoxfqx6KkfullOOCmXmdWml/pjARcNQGHaMfrRRs=
Prime2: uz1ZZxV0pK8KnOur2swBRYnvOWLwjqgZ2lVx4lLaMXLNzmb1OqlhW24R/B62BXKj/W+THjFBAXHu+fg23z1UPwPEdkR2zlTaiFuK8AwO+nMTa49cyK8El52D4aawtkFNMyrHoRMkaEsz5QCZciV57b9VBTmjzb1Dvm8zwN/BcSc=
Exponent1: e5Nk/XyhYB3WClnpxjTu0rDIcJ5lpBRo9Zqg4VfOtgHSuJpAB7g2N6Zefs06ZUpJQ2+/jLHqZor1xrYRqAIfY0hxKMSn3Qvcbk2+HGvvM4z06019mDzWQBRLsyVt+Jc8TLw/lIGDZxutDnuHVVpYNE+7w0BzLIAqCmrKor+YJuk=
Exponent2: ZpHD8Ola/X/6A15CxVft9mcKSlh9yNgjWWxnN4EFkAMA5OmXuuvgrlJMvd0g/zj+xq2hXO/EWYNNU1f6zy3sgZyRuevlXUA0enATW05vwhjZ8ZkWTcU6ccfS4AENWrnJDZeIxh8TWaKgqfk7FcGb2nZun68koWblvmNyaVzpvg8=
Coefficient: vVStdKOcZLLBCnSZ+AgG9E2gDXZRFpNPku+yI4ODehmtBz3WNUupHgSKM/5VZEK/J/6R3VP3XagKdLb/HAA2azpouypbs6qkcWrxUbpE/FGMZ071yfoyJT1X3jaekuzlHsvDZMtPmJ1MgSDgcBs/LAJvxJ+6ZqSBiq4ODwNK/BI=
+1
View File
@@ -0,0 +1 @@
uri.arpa. IN DNSKEY 257 3 8 AwEAAcd4/Jd9UZEHkAtD6IAhkgMqKnhDQR29DRAJBvfymZ2h6hvHRoEk/mLhpmlpdqJ6AWYTGeTu+03Yk4DRyxAbPmWiY3q0+ceezbGEgHzuW53llsu9PFX2zK1yqU6kCJ5V4dNYDwe+G5RoQO0/Qo5IRXzruQIowKZKVdJBi22x6APNul61g22GUk1Et9kO+Wc9g116KBR7eRzmvj/7cprd19sJGDGFCNieyeexIgXstk5u/d+dZ2DXHDn+3hp3QhYQLqbYG7s+9wIzw0Oa1jneujXzI3udkQ6khp1GeIziuI1IWQNNF7/weoHu1LzX/xPCE/aK5eTy1Avu11DTamn163M=
+10
View File
@@ -0,0 +1,10 @@
Private-key-format: v1.2
Algorithm: 8 (RSASHA256)
Modulus: x3j8l31RkQeQC0PogCGSAyoqeENBHb0NEAkG9/KZnaHqG8dGgST+YuGmaWl2onoBZhMZ5O77TdiTgNHLEBs+ZaJjerT5x57NsYSAfO5bneWWy708VfbMrXKpTqQInlXh01gPB74blGhA7T9CjkhFfOu5AijApkpV0kGLbbHoA826XrWDbYZSTUS32Q75Zz2DXXooFHt5HOa+P/tymt3X2wkYMYUI2J7J57EiBey2Tm79351nYNccOf7eGndCFhAuptgbuz73AjPDQ5rWOd66NfMje52RDqSGnUZ4jOK4jUhZA00Xv/B6ge7UvNf/E8IT9orl5PLUC+7XUNNqafXrcw==
PublicExponent: AQAB
PrivateExponent: BIajPJC0XBUO2KKW0OlyFa5MPmRQQut6M2XxCYkwoRn+ZNj1qZJ8TyQNkZC6B1+7TmSajs45V3/VgPPBpsDnfojbtvoKPNRGmIOIIs2JuKBv9nl5t/2ckUbrvoQMSgNq10/FL4jJuWlQJ9Hqoa3UHcx/ayQfkuZW4iloj3mc6REkpVTOpvRApHNuS9uZ9IgtiPzqiuR0dG0MNNpQl70xRoHFZpisubdt8sQVTjqY6+6NKOdyit1StQDy2SyS4Mcan9YzXM3mDWG2vR4euAa4ejXWLCQPbQ1VvwZB/60d2CO8oL4meHnYWfqMWSi5sIgNqpFMHlN1uB1WRrHWVHQIAQ==
Prime1: 8Zp13Hs2QOM3op8pOGNYfPlWS8bFJWsx5pQpT7yQOeoUC5bLmFzlo3W/uCzfHx6Stk1LBHxpUiyo23f2K5q6pCI8kSdhR160ATlOw9W46cxh6tF1GYR6v0NWHfdtZviKm9YAAJOx3w+nIm9FPgS9xBEPhgkxsaM7FW+geVTKHAE=
Prime2: 01vXq87dTsD6iIXWSrgfM/wUGlBLh1y+5BVvwcL3iP1YOoHrp4G43RJjtuvVyQWZo20H79YpsCwKHSBHk+zKMgnjeCfgozHqIZ4InSA91GJIVRMihBaDghTnDaPmVlt8A63xHvv8WxbhjNKjptiosIruxluRnF7hI9Ug3F+nV3M=
Exponent1: 6rh7RObXQJb+2Bj0/PlXYKMEOb40jjPkWPUcZYD2Ra2qJ9AqoC2wU+vzhMTjR+J1+nKBLSyJTfJhYkbbfGVoaklwujyd/658BqxcX1nlug58Gpu/vji839BVe+uD+AQC9X8kpWrX5bPZVlTv2l7U1gUVJc0M4F2K6zp1lyrO6AE=
Exponent2: U+O0KoEk3clCp0VX1LhXyi5XXEpacBOjwKuxe9qCnWDQ0AgZHJckZLqT0Vqxs+QBIxh3ef4q9b3FFeJmBpSJfGroWhyZ0KxTHZy4FoVhhRatVvcNUBgPgmYBfyx6k/QjuOIlPgMOGqluRJKmWebMraW3OAvIM6SE/8/sBwwAQ3k=
Coefficient: zWnobQ285ngZrUp4f1ENagCZNSeCWCXCSCxueHXMiwV+WkHaZL/mHWJ+y+60t3qP1PYn2cvFoDPPEnbTuGrR0gnbyEtElAgxkm2BiDe+zjJxTu7zGMBdnNYWOd4yLMv5sTY1z78WwoJa7UZD87JhjzfnmPXy/ILKL2y/NOWo/uM=
+29
View File
@@ -0,0 +1,29 @@
; modified version ofexample.rfc4035 with CDS and CDNSKEY records.
example. 3600 IN SOA ns1.example. bugs.x.w.example. 1081539377 3600 300 3600000 3600
example. 3600 IN NS ns2.example.
example. 3600 IN NS ns1.example.
example. 3600 IN MX 1 xx.example.
example. 3600 IN DNSKEY 257 3 8 AwEAAaYL5iwWI6UgSQVcDZmH7DrhQU/P6cOfi4wXYDzHypsfZ1D8znPwoAqhj54kTBVqgZDHw8QEnMcS3TWxvHBvncRTIXhCLx0BNK5/6mcTSK2IDbxl0j4vkcQrOxc77tyExuFfuXouuKVtE7rggOJiX6ga5LJW2if6Jxe/Rh8+aJv7 ;{id = 31967 (ksk), size = 1024b}
example. 3600 IN DNSKEY 256 3 8 AwEAAbsD4Tcz8hl2Rldov4CrfYpK3ORIh/giSGDlZaDTZR4gpGxGvMBwu2jzQ3m0iX3PvqPoaybC4tznjlJi8g/qsCRHhOkqWmjtmOYOJXEuUTb+4tPBkiboJM5QchxTfKxkYbJ2AD+VAUX1S6h/0DI0ZCGx1H90QTBE2ymRgHBwUfBt ;{id = 38353 (zsk), size = 1024b}
example. 3600 IN CDS 31967 8 2 2b8562a69323cf45d662976637829ec082c6204d0c83c9e1aedcd655629389aa
example. 3600 IN CDNSKEY 257 3 8 AwEAAaYL5iwWI6UgSQVcDZmH7DrhQU/P6cOfi4wXYDzHypsfZ1D8znPwoAqhj54kTBVqgZDHw8QEnMcS3TWxvHBvncRTIXhCLx0BNK5/6mcTSK2IDbxl0j4vkcQrOxc77tyExuFfuXouuKVtE7rggOJiX6ga5LJW2if6Jxe/Rh8+aJv7 ;{id = 31967 (ksk), size = 1024b}
a.example. 3600 IN NS ns2.a.example.
a.example. 3600 IN NS ns1.a.example.
a.example. 3600 IN DS 57855 5 1 b6dcd485719adca18e5f3d48a2331627fdd3636b
ns1.a.example. 3600 IN A 192.0.2.5
ns2.a.example. 3600 IN A 192.0.2.6
ai.example. 3600 IN A 192.0.2.9
ai.example. 3600 IN HINFO "KLH-10" "ITS"
ai.example. 3600 IN AAAA 2001:db8::f00:baa9
b.example. 3600 IN NS ns1.b.example.
b.example. 3600 IN NS ns2.b.example.
ns1.b.example. 3600 IN A 192.0.2.7
ns2.b.example. 3600 IN A 192.0.2.8
ns1.example. 3600 IN A 192.0.2.1
ns2.example. 3600 IN A 192.0.2.2
*.w.example. 3600 IN MX 1 ai.example.
x.w.example. 3600 IN MX 1 xx.example.
x.y.w.example. 3600 IN MX 1 xx.example.
xx.example. 3600 IN A 192.0.2.10
xx.example. 3600 IN HINFO "KLH-10" "TOPS-20"
xx.example. 3600 IN AAAA 2001:db8::f00:baaa
+20
View File
@@ -0,0 +1,20 @@
; The provenance of this zone is unknown, it is assumed to be hand crafted as
; example.org is an RFC 2606 reserved second level domain.
;
; This example includes various kinds of record that are useful for testing
; DNSSEC corner cases, including occluded and glue RRs, and insecure and secure
; delegations.
example.org. 239 IN SOA example.net. hostmaster.example.net. 1234567890 28800 7200 604800 238
$TTL 1000
example.org. IN NS example.net.
example.org. 240 IN A 128.140.76.106
insecure-deleg.example.org. 240 IN NS example.com.
occluded.insecure-deleg.example.org. 240 IN A 1.2.3.4
secure-deleg.example.org. 240 IN NS example.com.
secure-deleg.example.org. 240 IN DS 3120 15 2 0675d8c4a90ecd25492e4c4c6583afcef7c3b910b7a39162803058e6e7393a19
secure-deleg.example.org. 240 IN NS secure-deleg.example.org.
secure-deleg.example.org. 240 IN A 1.1.1.1
secure-deleg.example.org. 240 IN AAAA ::1
insecure-deleg.example.org. 240 IN NS insecure-deleg.example.org.
insecure-deleg.example.org. 240 IN A 1.1.1.1
insecure-deleg.example.org. 240 IN AAAA ::1
+5
View File
@@ -0,0 +1,5 @@
earlier-sorting.org. 240 IN A 128.140.76.106
example.org. 240 IN SOA example.net. hostmaster.example.net. 1234567890 28800 7200 604800 240
example.org. 240 IN NS earlier-sorting.org.
example.org. 240 IN A 128.140.76.106
some.example.org. 240 IN A 1.1.1.1
@@ -0,0 +1,5 @@
example.org. 240 IN SOA example.net. hostmaster.example.net. 1234567890 28800 7200 604800 240
example.org. 240 IN NS earlier-sorting.org.
example.org. 240 IN A 128.140.76.106
some.example.org. 240 IN A 1.1.1.1
earlier-sorting.org. 240 IN A 128.140.76.106
@@ -0,0 +1,2 @@
example.org. 239 IN SOA example.net. hostmaster.example.net. 1234567890 28800 7200 604800 238
some.example.org. 240 IN A 1.2.3.4
@@ -0,0 +1,2 @@
example.org. 238 IN SOA example.net. hostmaster.example.net. 1234567890 28800 7200 604800 239
some.example.org. 240 IN A 1.2.3.4
+30
View File
@@ -0,0 +1,30 @@
; Extracted using ldns-readzone -s from the signed zone defined at
; https://datatracker.ietf.org/doc/html/rfc4035#appendix-A
; Keys have been replaced by newer algorithm 8 instead of older algorithm 5
; which we do not support, and to match key pairs stored alongside this file.
example. 3600 IN SOA ns1.example. bugs.x.w.example. 1081539377 3600 300 3600000 3600
example. 3600 IN NS ns2.example.
example. 3600 IN NS ns1.example.
example. 3600 IN MX 1 xx.example.
example. 3600 IN DNSKEY 257 3 8 AwEAAaYL5iwWI6UgSQVcDZmH7DrhQU/P6cOfi4wXYDzHypsfZ1D8znPwoAqhj54kTBVqgZDHw8QEnMcS3TWxvHBvncRTIXhCLx0BNK5/6mcTSK2IDbxl0j4vkcQrOxc77tyExuFfuXouuKVtE7rggOJiX6ga5LJW2if6Jxe/Rh8+aJv7 ;{id = 31967 (ksk), size = 1024b}
example. 3600 IN DNSKEY 256 3 8 AwEAAbsD4Tcz8hl2Rldov4CrfYpK3ORIh/giSGDlZaDTZR4gpGxGvMBwu2jzQ3m0iX3PvqPoaybC4tznjlJi8g/qsCRHhOkqWmjtmOYOJXEuUTb+4tPBkiboJM5QchxTfKxkYbJ2AD+VAUX1S6h/0DI0ZCGx1H90QTBE2ymRgHBwUfBt ;{id = 38353 (zsk), size = 1024b}
a.example. 3600 IN NS ns2.a.example.
a.example. 3600 IN NS ns1.a.example.
a.example. 3600 IN DS 57855 5 1 b6dcd485719adca18e5f3d48a2331627fdd3636b
ns1.a.example. 3600 IN A 192.0.2.5
ns2.a.example. 3600 IN A 192.0.2.6
ai.example. 3600 IN A 192.0.2.9
ai.example. 3600 IN HINFO "KLH-10" "ITS"
ai.example. 3600 IN AAAA 2001:db8::f00:baa9
b.example. 3600 IN NS ns1.b.example.
b.example. 3600 IN NS ns2.b.example.
ns1.b.example. 3600 IN A 192.0.2.7
ns2.b.example. 3600 IN A 192.0.2.8
ns1.example. 3600 IN A 192.0.2.1
ns2.example. 3600 IN A 192.0.2.2
*.w.example. 3600 IN MX 1 ai.example.
x.w.example. 3600 IN MX 1 xx.example.
x.y.w.example. 3600 IN MX 1 xx.example.
xx.example. 3600 IN A 192.0.2.10
xx.example. 3600 IN HINFO "KLH-10" "TOPS-20"
xx.example. 3600 IN AAAA 2001:db8::f00:baaa
+32
View File
@@ -0,0 +1,32 @@
; Extracted using ldns-readzone -s from the signed zone defined at
; https://datatracker.ietf.org/doc/html/rfc5155#appendix-A
; Keys have been replaced by newer algorithm 8 instead of older algorithm 5
; which we do not support, and to match key pairs stored alongside this file.
example. 3600 IN SOA ns1.example. bugs.x.w.example. 1 3600 300 3600000 3600
xx.example. 3600 IN AAAA 2001:db8::f00:baaa
xx.example. 3600 IN HINFO "KLH-10" "TOPS-20"
xx.example. 3600 IN A 192.0.2.10
x.y.w.example. 3600 IN MX 1 xx.example.
x.w.example. 3600 IN MX 1 xx.example.
*.w.example. 3600 IN MX 1 ai.example.
ns2.example. 3600 IN A 192.0.2.2
ns1.example. 3600 IN A 192.0.2.1
ns2.c.example. 3600 IN A 192.0.2.8
ns1.c.example. 3600 IN A 192.0.2.7
c.example. 3600 IN NS ns2.c.example.
c.example. 3600 IN NS ns1.c.example.
ai.example. 3600 IN AAAA 2001:db8::f00:baa9
ai.example. 3600 IN HINFO "KLH-10" "ITS"
ai.example. 3600 IN A 192.0.2.9
ns2.a.example. 3600 IN A 192.0.2.6
ns1.a.example. 3600 IN A 192.0.2.5
a.example. 3600 IN DS 58470 5 1 3079f1593ebad6dc121e202a8b766a6a4837206c
a.example. 3600 IN NS ns2.a.example.
a.example. 3600 IN NS ns1.a.example.
2t7b4g4vsa5smi47k61mv5bv1a22bojr.example. 3600 IN A 192.0.2.127
example. 3600 IN NSEC3PARAM 1 0 12 aabbccdd
example. 3600 IN DNSKEY 257 3 8 AwEAAaYL5iwWI6UgSQVcDZmH7DrhQU/P6cOfi4wXYDzHypsfZ1D8znPwoAqhj54kTBVqgZDHw8QEnMcS3TWxvHBvncRTIXhCLx0BNK5/6mcTSK2IDbxl0j4vkcQrOxc77tyExuFfuXouuKVtE7rggOJiX6ga5LJW2if6Jxe/Rh8+aJv7 ;{id = 31967 (ksk), size = 1024b}
example. 3600 IN DNSKEY 256 3 8 AwEAAbsD4Tcz8hl2Rldov4CrfYpK3ORIh/giSGDlZaDTZR4gpGxGvMBwu2jzQ3m0iX3PvqPoaybC4tznjlJi8g/qsCRHhOkqWmjtmOYOJXEuUTb+4tPBkiboJM5QchxTfKxkYbJ2AD+VAUX1S6h/0DI0ZCGx1H90QTBE2ymRgHBwUfBt ;{id = 38353 (zsk), size = 1024b}
example. 3600 IN MX 1 xx.example.
example. 3600 IN NS ns2.example.
example. 3600 IN NS ns1.example.
+35
View File
@@ -0,0 +1,35 @@
; https://www.rfc-editor.org/rfc/rfc8976.html#section-a.2
example. 86400 IN SOA ns1 admin 2018031900 (
1800 900 604800 86400 )
86400 IN NS ns1
86400 IN NS ns2
86400 IN ZONEMD 2018031900 1 1 (
a3b69bad980a3504
e1cffcb0fd6397f9
3848071c93151f55
2ae2f6b1711d4bd2
d8b39808226d7b9d
b71e34b72077f8fe )
ns1 3600 IN A 203.0.113.63
NS2 3600 IN AAAA 2001:db8::63
occluded.sub 7200 IN TXT "I'm occluded but must be digested"
sub 7200 IN NS ns1
duplicate 300 IN TXT "I must be digested just once"
duplicate 300 IN TXT "I must be digested just once"
foo.test. 555 IN TXT "out-of-zone data must be excluded"
UPPERCASE 3600 IN TXT "canonicalize uppercase owner names"
* 777 IN PTR dont-forget-about-wildcards
mail 3600 IN MX 20 MAIL1
mail 3600 IN MX 10 Mail2.Example.
sortme 3600 IN AAAA 2001:db8::5:61
sortme 3600 IN AAAA 2001:db8::3:62
sortme 3600 IN AAAA 2001:db8::4:63
sortme 3600 IN AAAA 2001:db8::1:65
sortme 3600 IN AAAA 2001:db8::2:64
non-apex 900 IN ZONEMD 2018031900 1 1 (
616c6c6f77656420
6275742069676e6f
7265642e20616c6c
6f77656420627574
2069676e6f726564
2e20616c6c6f7765 )
@@ -0,0 +1,31 @@
; Taken from https://www.rfc-editor.org/rfc/rfc8976.html#section-a.3
example. 86400 IN SOA ns1 admin 2018031900 (
1800 900 604800 86400 )
example. 86400 IN NS ns1.example.
example. 86400 IN NS ns2.example.
example. 86400 IN ZONEMD 2018031900 1 1 (
62e6cf51b02e54b9
b5f967d547ce4313
6792901f9f88e637
493daaf401c92c27
9dd10f0edb1c56f8
080211f8480ee306 )
example. 86400 IN ZONEMD 2018031900 1 2 (
08cfa1115c7b948c
4163a901270395ea
226a930cd2cbcf2f
a9a5e6eb85f37c8a
4e114d884e66f176
eab121cb02db7d65
2e0cc4827e7a3204
f166b47e5613fd27 )
example. 86400 IN ZONEMD 2018031900 1 240 (
e2d523f654b9422a
96c5a8f44607bbee )
example. 86400 IN ZONEMD 2018031900 241 1 (
e1846540e33a9e41
89792d18d5d131f6
05fc283e )
ns1.example. 3600 IN A 203.0.113.63
ns2.example. 86400 IN TXT "This example has multiple digests"
NS2.EXAMPLE. 3600 IN AAAA 2001:db8::63
+7
View File
@@ -0,0 +1,7 @@
; Taken from https://www.rfc-editor.org/rfc/rfc8976.html#section-a.1
example. 86400 IN SOA ns1 admin 2018031900 (
1800 900 604800 86400 )
86400 IN NS ns1
86400 IN NS ns2
ns1 3600 IN A 203.0.113.63
ns2 3600 IN AAAA 2001:db8::63
+34
View File
@@ -0,0 +1,34 @@
; loosely based on jelte.nlnetlabs.nl.
jelte.nlnetlabs.nl. 3600 IN SOA ns.jelte.nlnetlabs.nl. jelte.jelte.nlnetlabs.nl. 808 28800 7200 604800 3600
jelte.nlnetlabs.nl. 3600 IN NS ns.jelte.nlnetlabs.nl.
jelte.nlnetlabs.nl. 3600 IN NS ext.ns.whyscream.net.
jelte.nlnetlabs.nl. 3600 IN NS ns-ext.nlnetlabs.nl.
jelte.nlnetlabs.nl. 3600 IN A 178.18.82.80
jelte.nlnetlabs.nl. 60 IN MX 10 smtp.jelte.nlnetlabs.nl.
jelte.nlnetlabs.nl. 3600 IN AAAA 2a02:348:55:5250::80
jelte.nlnetlabs.nl. 0 IN TYPE65534 \# 5 0846480001
dnssec.jelte.nlnetlabs.nl. 3600 IN NS ns2.jelte.nlnetlabs.nl.
dnssec.jelte.nlnetlabs.nl. 3600 IN DS 8340 5 1 5733A59841EA708AE9223822124B07B555E17332
dragon.jelte.nlnetlabs.nl. 1234 IN AAAA 2002:c3a9:dd9d:8:219:d1ff:fe81:5c10
git.jelte.nlnetlabs.nl. 3600 IN AAAA 2a02:348:55:5250::80
git.jelte.nlnetlabs.nl. 3600 IN A 178.18.82.80
imap.jelte.nlnetlabs.nl. 3600 IN A 178.18.82.80
nepmail.jelte.nlnetlabs.nl. 3600 IN MX 10 mirre.nlnetlabs.nl.
ns.jelte.nlnetlabs.nl. 3600 IN A 178.18.82.80
ns.jelte.nlnetlabs.nl. 3600 IN AAAA 2a02:348:55:5250::53
ns-ext.jelte.nlnetlabs.nl. 3600 IN A 178.18.82.80
ns2.jelte.nlnetlabs.nl. 3600 IN A 195.169.221.157
ns2.jelte.nlnetlabs.nl. 3600 IN AAAA 2002:c3a9:dd9d:1::1
nsec3.jelte.nlnetlabs.nl. 3600 IN NS ns2.jelte.nlnetlabs.nl.
nsec3.jelte.nlnetlabs.nl. 3600 IN DS 21665 7 1 8D5E7DEDC1501A38009882DD1508246EB4A2251C
smtp.jelte.nlnetlabs.nl. 3600 IN A 178.18.82.80
svn.jelte.nlnetlabs.nl. 3600 IN A 178.18.82.80
talon.jelte.nlnetlabs.nl. 3600 IN A 195.169.221.157
v6.jelte.nlnetlabs.nl. 3600 IN AAAA 2002:c3a9:dd9d:1::1
vps.jelte.nlnetlabs.nl. 3600 IN A 178.18.82.80
vpsv6.jelte.nlnetlabs.nl. 3600 IN AAAA 2a02:348:55:5250::1
www.jelte.nlnetlabs.nl. 3600 IN A 178.18.82.80
www.jelte.nlnetlabs.nl. 3600 IN AAAA 2a02:348:55:5250::80
wwwv6.jelte.nlnetlabs.nl. 3600 IN AAAA 2a02:348:55:5250::80
+49
View File
@@ -0,0 +1,49 @@
; Taken from https://www.rfc-editor.org/rfc/rfc8976.html#section-a.5
root-servers.net. 3600000 IN SOA a.root-servers.net. (
nstld.verisign-grs.com. 2018091100 14400 7200 1209600 3600000 )
root-servers.net. 3600000 IN NS a.root-servers.net.
root-servers.net. 3600000 IN NS b.root-servers.net.
root-servers.net. 3600000 IN NS c.root-servers.net.
root-servers.net. 3600000 IN NS d.root-servers.net.
root-servers.net. 3600000 IN NS e.root-servers.net.
root-servers.net. 3600000 IN NS f.root-servers.net.
root-servers.net. 3600000 IN NS g.root-servers.net.
root-servers.net. 3600000 IN NS h.root-servers.net.
root-servers.net. 3600000 IN NS i.root-servers.net.
root-servers.net. 3600000 IN NS j.root-servers.net.
root-servers.net. 3600000 IN NS k.root-servers.net.
root-servers.net. 3600000 IN NS l.root-servers.net.
root-servers.net. 3600000 IN NS m.root-servers.net.
a.root-servers.net. 3600000 IN AAAA 2001:503:ba3e::2:30
a.root-servers.net. 3600000 IN A 198.41.0.4
b.root-servers.net. 3600000 IN MX 20 mail.isi.edu.
b.root-servers.net. 3600000 IN AAAA 2001:500:200::b
b.root-servers.net. 3600000 IN A 199.9.14.201
c.root-servers.net. 3600000 IN AAAA 2001:500:2::c
c.root-servers.net. 3600000 IN A 192.33.4.12
d.root-servers.net. 3600000 IN AAAA 2001:500:2d::d
d.root-servers.net. 3600000 IN A 199.7.91.13
e.root-servers.net. 3600000 IN AAAA 2001:500:a8::e
e.root-servers.net. 3600000 IN A 192.203.230.10
f.root-servers.net. 3600000 IN AAAA 2001:500:2f::f
f.root-servers.net. 3600000 IN A 192.5.5.241
g.root-servers.net. 3600000 IN AAAA 2001:500:12::d0d
g.root-servers.net. 3600000 IN A 192.112.36.4
h.root-servers.net. 3600000 IN AAAA 2001:500:1::53
h.root-servers.net. 3600000 IN A 198.97.190.53
i.root-servers.net. 3600000 IN MX 10 mx.i.root-servers.org.
i.root-servers.net. 3600000 IN AAAA 2001:7fe::53
i.root-servers.net. 3600000 IN A 192.36.148.17
j.root-servers.net. 3600000 IN AAAA 2001:503:c27::2:30
j.root-servers.net. 3600000 IN A 192.58.128.30
k.root-servers.net. 3600000 IN AAAA 2001:7fd::1
k.root-servers.net. 3600000 IN A 193.0.14.129
l.root-servers.net. 3600000 IN AAAA 2001:500:9f::42
l.root-servers.net. 3600000 IN A 199.7.83.42
m.root-servers.net. 3600000 IN AAAA 2001:dc3::35
m.root-servers.net. 3600000 IN A 202.12.27.33
root-servers.net. 3600000 IN SOA a.root-servers.net. (
nstld.verisign-grs.com. 2018091100 14400 7200 1209600 3600000 )
root-servers.net. 3600000 IN ZONEMD 2018091100 1 1 (
f1ca0ccd91bd5573d9f431c00ee0101b2545c97602be0a97
8a3b11dbfc1c776d5b3e86ae3d973d6b5349ba7f04340f79 )
+136
View File
@@ -0,0 +1,136 @@
; Extracted using ldns-readzone -s from the signed zone defined at
; https://www.rfc-editor.org/rfc/rfc8976.html#name-the-uriarpa-zone
; Keys have been replaced to match key pairs stored alongside this file.
uri.arpa. 3600 IN SOA sns.dns.icann.org. (
noc.dns.icann.org. 2018100702 10800 3600 1209600 3600 )
uri.arpa. 3600 IN RRSIG SOA 8 2 3600 (
20210217232440 20210120232440 37444 uri.arpa.
GzQw+QzwLDJr13REPGVmpEChjD1D2XlX0ie1DnWHpgaEw1E/dhs3lCN3+B
mHd4Kx3tffTRgiyq65HxR6feQ5v7VmAifjyXUYB1DZur1eP5q0Ms2ygCB3
byoeMgCNsFS1oKZ2LdzNBRpy3oace8xQn1SpmHGfyrsgg+WbHKCT1dY= )
uri.arpa. 86400 IN NS a.iana-servers.net.
uri.arpa. 86400 IN NS b.iana-servers.net.
uri.arpa. 86400 IN NS c.iana-servers.net.
uri.arpa. 86400 IN NS ns2.lacnic.net.
uri.arpa. 86400 IN NS sec3.apnic.net.
uri.arpa. 86400 IN RRSIG NS 8 2 86400 (
20210217232440 20210120232440 37444 uri.arpa.
M+Iei2lcewWGaMtkPlrhM9FpUAHXFkCHTVpeyrjxjEONeNgKtHZor5e4V4
qJBOzNqo8go/qJpWlFBm+T5Hn3asaBZVstFIYky38/C8UeRLPKq1hTTHAR
YUlFrexr5fMtSUAVOgOQPSBfH3xBq/BgSccTdRb9clD+HE7djpqrLS4= )
uri.arpa. 600 IN MX 10 pechora.icann.org.
uri.arpa. 600 IN RRSIG MX 8 2 600 (
20210217232440 20210120232440 37444 uri.arpa.
kQAJQivmv6A5hqYBK8h6Z13ESY69gmosXwKI6WE09I8RFetfrxr24ecdnY
d0lpnDtgNNSoHkYRSOoB+C4+zuJsoyAAzGo9uoWMWj97/2xeGhf3PTC9me
Q9Ohi6hul9By7OR76XYmGhdWX8PBi60RUmZ1guslFBfQ8izwPqzuphs= )
uri.arpa. 3600 IN DNSKEY 256 3 8 (
AwEAAbdA7hbl8YtfwjDxI1L06os3xkyehpGROhX8nLCwrwx3+veYbAWIdR
ahKN2SMSHrRtj8k7bRxJC5fhUweA5L8h4CDVGCOJhkOCni/O0xQ44MVT/b
HF4WcCtAbThy8vlPj0xR0r0DkqEbuOsK+uJAJfgli5I5Im3VNB8RPBcfu4
2GR8ObDOLVxuDJ52A+ZGqH8H9VyGfuxtnjSVenkeQNQidwkfI6IWxrk1/H
1G+Az/45yFDZGCWzqBX0yml6dplmxX9LMypPubeDQZniR+9hxut0Ig2Wh3
c6yB/619A0P5gbtuO7gqrfkoEuZThEUzzqyKGOQV4UF2hU7BLABuyzch0=
)
uri.arpa. 3600 IN DNSKEY 257 3 8 (
AwEAAahOTGtQI/HNtJgStghtd8Y4H26mPauZw1UFVSq/X5c3ThjRCd2Kie
TVokcUhZfWIw9AQmLEO4qJTPXreiXDRZTLm8O0M7jDXggzdnAxhstSaUIT
jBbvnBf1p2erI2BQK6d7mmsywEgJ8Fy5zhQGMwRpNCe8eDsEPHWdfhO++x
xxCqeZQgGi++3M+9/R41qXpJUySlmlxUp0cE5OianyxcJEl5gOnVz9UXpc
ZeaZdyQuEkZVe1BcXgYB3tKPREujHTiwp+tXZHqfE3pqnDpepzR3tFrHoU
3/KkreXP/8Xn0Behe8TByic8Gb60tFl5Q5Kb98poPKzTdeKv0PvhRL+VE=
)
uri.arpa. 3600 IN DNSKEY 257 3 8 (
AwEAAcd4/Jd9UZEHkAtD6IAhkgMqKnhDQR29DRAJBvfymZ2h6hvHRoEk/m
LhpmlpdqJ6AWYTGeTu+03Yk4DRyxAbPmWiY3q0+ceezbGEgHzuW53llsu9
PFX2zK1yqU6kCJ5V4dNYDwe+G5RoQO0/Qo5IRXzruQIowKZKVdJBi22x6A
PNul61g22GUk1Et9kO+Wc9g116KBR7eRzmvj/7cprd19sJGDGFCNieyeex
IgXstk5u/d+dZ2DXHDn+3hp3QhYQLqbYG7s+9wIzw0Oa1jneujXzI3udkQ
6khp1GeIziuI1IWQNNF7/weoHu1LzX/xPCE/aK5eTy1Avu11DTamn163M=
)
uri.arpa. 3600 IN RRSIG DNSKEY 8 2 3600 (
20210217232440 20210120232440 12670 uri.arpa.
DBE2gkKAoxJCfz47KKxzoImN/0AKArhIVHE7TyTwy0DdRPo44V5R+vL6th
UxlQ1CJi2Rw0jwAXymx5Y3Q873pOEllH+4bJoIT4dmoBmPXfYWW7Clvw9U
PKHRP0igKHmCVwIeBYDTU3gfLcMTbR4nEWPDN0GxlL1Mf7ITaC2Ioabo79
Ip3M/MR8I3Vx/xZ4ZKKPHtLn3xUuJluPNanqJrED2gTslL2xWZ1tqjsAjJ
v7JnJo2HJ8XVRB5zBto0IaJ2oBlqcjdcQ/0VlyoM8uOy1pDwHQ2BJl7322
gNMHBP9HSiUPIOaIDNUCwW8eUcW6DIUk+s9u3GN1uTqwWzsYB/rA== )
uri.arpa. 3600 IN RRSIG DNSKEY 8 2 3600 (
20210217232440 20210120232440 30577 uri.arpa.
Kx6HwP4UlkGc1UZ7SERXtQjPajOF4iUvkwDj7MEG1xbQFB1KoJiEb/eiW0
qmSWdIhMDv8myhgauejRLyJxwxz8HDRV4xOeHWnRGfWBk4XGYwkejVzOHz
oIArVdUVRbr2JKigcTOoyFN+uu52cNB7hRYu7dH5y1hlc6UbOnzRpMtGxc
gVyKQ+/ARbIqGG3pegdEOvV49wTPWEiyY65P2urqhvnRg5ok/jzwAdMx4X
Gshiib7Ojq0sRVl2ZIzj4rFgY/qsSO8SEXEhMo2VuSkoJNiofVzYoqpxEe
GnANkIT7Tx2xJL1BWyJxyc7E8Wr2QSgCcc+rYL6IkHDtJGHy7TaQ== )
uri.arpa. 3600 IN ZONEMD 2018100702 1 1 (
0dbc3c4dbfd75777c12ca19c337854b1577799901307c482e9d91d5d15
cd934d16319d98e30c4201cf25a1d5a0254960 )
uri.arpa. 3600 IN RRSIG ZONEMD 8 2 3600 (
20210217232440 20210120232440 37444 uri.arpa.
QDo4XZcL3HMyn8aAHyCUsu/Tqj4Gkth8xY1EqByOb8XOTwVtA4ZNQORE1s
iqNqjtJUbeJPtJSbLNqCL7rCq0CzNNnBscv6IIf4gnqJZjlGtHO30ohXtK
vEc4z7SU3IASsi6bB3nLmEAyERdYSeU6UBfx8vatQDIRhkgEnnWUTh4= )
uri.arpa. 3600 IN NSEC ftp.uri.arpa. (
NS SOA MX RRSIG NSEC DNSKEY ZONEMD )
uri.arpa. 3600 IN RRSIG NSEC 8 2 3600 (
20210217232440 20210120232440 37444 uri.arpa.
dU/rXLM/naWd1+1PiWiYVaNJyCkiuyZJSccr91pJI673T8r3685B4ODMYF
afZRboVgwnl3ZrXddY6xOhZL3n9V9nxXZwjLJ2HJUojFoKcXTlpnUyYUYv
VQ2kj4GHAo6fcGCEp5QFJ2KbCpeJoS+PhKGRRx28icCiNT4/uXQvO2E= )
ftp.uri.arpa. 604800 IN NAPTR 0 0 "" "" (
"!^ftp://([^:/?#]*).*$!\\1!i" . )
ftp.uri.arpa. 604800 IN RRSIG NAPTR 8 3 604800 (
20210217232440 20210120232440 37444 uri.arpa.
EygekDgl+Lyyq4NMSEpPyOrOywYf9Y3FAB4v1DT44J3R5QGidaH8l7ZFjH
oYFI8sY64iYOCV4sBnX/dh6C1L5NgpY+8l5065Xu3vvjyzbtuJ2k6YYwJr
rCbvl5DDn53zAhhO2hL9uLgyLraZGi9i7TFGd0sm3zNyUF/EVL0CcxU= )
ftp.uri.arpa. 3600 IN NSEC http.uri.arpa. (
NAPTR RRSIG NSEC )
ftp.uri.arpa. 3600 IN RRSIG NSEC 8 3 3600 (
20210217232440 20210120232440 37444 uri.arpa.
pbP4KxevPXCu/bDqcvXiuBppXyFEmtHyiy0eAN5gS7mi6mp9Z9bWFjx/Ld
H9+6oFGYa5vGmJ5itu/4EDMe8iQeZbI8yrpM4TquB7RR/MGfBnTd8S+sjy
QtlRYG7yqEu77Vd78Fme22BKPJ+MVqjS0JHMUE/YUGomPkAjLJJwwGw= )
http.uri.arpa. 604800 IN NAPTR 0 0 "" "" (
"!^http://([^:/?#]*).*$!\\1!i" . )
http.uri.arpa. 604800 IN RRSIG NAPTR 8 3 604800 (
20210217232440 20210120232440 37444 uri.arpa.
eTqbWvt1GvTeXozuvm4ebaAfkXFQKrtdu0cEiExto80sHIiCbO0WL8UDa/
J3cDivtQca7LgUbOb6c17NESsrsVkc6zNPx5RK2tG7ZQYmhYmtqtfg1oU5
BRdHZ5TyqIXcHlw9Blo2pir1Y9IQgshhD7UOGkbkEmvB1Lrd0aHhAAg= )
http.uri.arpa. 3600 IN NSEC mailto.uri.arpa. (
NAPTR RRSIG NSEC )
http.uri.arpa. 3600 IN RRSIG NSEC 8 3 3600 (
20210217232440 20210120232440 37444 uri.arpa.
R9rlNzw1CVz2N08q6DhULzcsuUm0UKcPaGAWEU40tr81jEDHsFHNM+khCd
OI8nDstzA42aee4rwCEgijxJpRCcY9hrO1Ysrrr2fdqNz60JikMdarvU5O
0p0VXeaaJDfJQT44+o+YXaBwI7Qod3FTMx7aRib8i7istvPm1Rr7ixA= )
mailto.uri.arpa. 604800 IN NAPTR 0 0 "" "" (
"!^mailto:(.*)@(.*)$!\\2!i" . )
mailto.uri.arpa. 604800 IN RRSIG NAPTR 8 3 604800 (
20210217232440 20210120232440 37444 uri.arpa.
Ch2zTG2F1plEvQPyIH4Yd80XXLjXOPvMbiqDjpJBcnCJsV8QF7kr0wTLnU
T3dB+asQudOjPyzaHGwFlMzmrrAsszN4XAMJ6htDtFJdsgTMP/NkHhYRSm
Vv6rLeAhd+mVfObY12M//b/GGVTjeUI/gJaLW0fLVZxr1Fp5U5CRjyw= )
mailto.uri.arpa. 3600 IN NSEC urn.uri.arpa. (
NAPTR RRSIG NSEC )
mailto.uri.arpa. 3600 IN RRSIG NSEC 8 3 3600 (
20210217232440 20210120232440 37444 uri.arpa.
fQUbSIE6E7JDi2rosah4SpCOTrKufeszFyj5YEavbQuYlQ5cNFvtm8KuE2
xXMRgRI4RGvM2leVqcoDw5hS3m2pOJLxH8l2WE72YjYvWhvnwc5Rofe/8y
B/vaSK9WCnqN8y2q6Vmy73AGP0fuiwmuBra7LlkOiqmyx3amSFizwms= )
urn.uri.arpa. 604800 IN NAPTR 0 0 "" "" (
"/urn:([^:]+)/\\1/i" . )
urn.uri.arpa. 604800 IN RRSIG NAPTR 8 3 604800 (
20210217232440 20210120232440 37444 uri.arpa.
CVt2Tgz0e5ZmaSXqRfNys/8OtVCk9nfP0zhezhN8Bo6MDt6yyKZ2kEEWJP
jkN7PCYHjO8fGjnUn0AHZI2qBNv7PKHcpR42VY03q927q85a65weOO1YE0
vPYMzACpua9TOtfNnynM2Ws0uN9URxUyvYkXBdqOC81N3sx1dVELcwc= )
urn.uri.arpa. 3600 IN NSEC uri.arpa. NAPTR RRSIG NSEC
urn.uri.arpa. 3600 IN RRSIG NSEC 8 3 3600 (
20210217232440 20210120232440 37444 uri.arpa.
JuKkMiC3/j9iM3V8/izcouXWAVGnSZjkOgEgFPhutMqoylQNRcSkbEZQzF
K8B/PIVdzZF0Y5xkO6zaKQjOzz6OkSaNPIo1a7Vyyl3wDY/uLCRRAHRJfp
knuY7O+AUNXvVVIEYJqZggd4kl/Rjh1GTzPYZTRrVi5eQidI1LqCOeg= )
+61
View File
@@ -0,0 +1,61 @@
use std::process::Command;
#[track_caller]
pub fn assert_org_ldns_cmd_eq_new_ldns_cmd(
org_ldns_cmd: &[&str],
new_ldns_cmd: &[&str],
expect_stdout_content: bool,
) {
let org_ldns_cmd_out = Command::new(org_ldns_cmd[0])
.args(&org_ldns_cmd[1..])
.output()
.unwrap();
let new_ldns_cmd_out = test_bin::get_test_bin("ldns")
.args(new_ldns_cmd)
.output()
.unwrap();
assert_eq!(
std::str::from_utf8(&org_ldns_cmd_out.stderr),
Ok(""),
"Unexpected stderr content for original ldns command: {}",
org_ldns_cmd.join(" ")
);
assert_eq!(
std::str::from_utf8(&new_ldns_cmd_out.stderr),
Ok(""),
"Unexpected stderr content for reimplemented ldns command: {}",
new_ldns_cmd.join(" ")
);
if expect_stdout_content {
assert!(
!org_ldns_cmd_out.stdout.is_empty(),
"Expected stdout content for original ldns command: {}: {:?}",
org_ldns_cmd.join(" "),
std::str::from_utf8(&org_ldns_cmd_out.stdout)
);
assert!(
!new_ldns_cmd_out.stdout.is_empty(),
"Expected stdout content for reimplemented ldns command: {}: {:?}",
new_ldns_cmd.join(" "),
std::str::from_utf8(&new_ldns_cmd_out.stdout)
);
}
assert_eq!(
org_ldns_cmd_out.status.code(),
new_ldns_cmd_out.status.code(),
"Exit code mismatch for original ldns command: {}",
org_ldns_cmd.join(" ")
);
// This will only work for LDNS commands whose output we are able to
// replicate exactly.
assert_eq!(
std::str::from_utf8(&org_ldns_cmd_out.stdout),
std::str::from_utf8(&new_ldns_cmd_out.stdout),
"Stdout content mismatch for original ldns command: {}, compared to new ldns emulation command: {}",
org_ldns_cmd.join(" "),
new_ldns_cmd.join(" ")
);
}
+47
View File
@@ -0,0 +1,47 @@
mod common;
use common::assert_org_ldns_cmd_eq_new_ldns_cmd;
const LDNS_CMD: &str = "ldns-nsec3-hash";
const TEST_ZONE_NAME: &str = "nlnetlabs.nl";
#[ignore = "should only be run if ldns command line tools are installed"]
#[test]
fn nsec3_hash() {
// Note: ldns-nsec3-hash defaults NSEC3 iterations to 1, while dnst
// nsec3-hash defaults NSEC3 iterations to 0 even in LDNS compatibility
// mode.
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[LDNS_CMD, TEST_ZONE_NAME],
&[LDNS_CMD, "-t", "1", TEST_ZONE_NAME],
true,
);
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[LDNS_CMD, TEST_ZONE_NAME, "-t", "0"],
&[LDNS_CMD, TEST_ZONE_NAME],
true,
);
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[LDNS_CMD, "-a", "1", TEST_ZONE_NAME],
&[LDNS_CMD, "-t", "1", "-a", "1", TEST_ZONE_NAME],
true,
);
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[LDNS_CMD, "-s", "", TEST_ZONE_NAME],
&[LDNS_CMD, "-t", "1", "-s", "", TEST_ZONE_NAME],
true,
);
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[LDNS_CMD, "-s", "DEADBEEF", TEST_ZONE_NAME],
&[LDNS_CMD, "-t", "1", "-s", "DEADBEEF", TEST_ZONE_NAME],
true,
);
for iterations in 0..10 {
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[LDNS_CMD, "-t", &iterations.to_string(), TEST_ZONE_NAME],
&[LDNS_CMD, "-t", &iterations.to_string(), TEST_ZONE_NAME],
true,
);
}
}
+246
View File
@@ -0,0 +1,246 @@
// Based on: https://github.com/NLnetLabs/ldns/tree/1.8.4/test/20-sign-zone.tpkg
// But uses a newer algorithm as algorithm 5 is not supported by DNST.
mod common;
use common::assert_org_ldns_cmd_eq_new_ldns_cmd;
use const_format::concatcp;
use jiff::{ToSpan, Unit, Zoned};
use std::process::Command;
use tempfile::tempdir;
const LDNS_CMD: &str = "ldns-signzone";
const TEST_DATA_DIR: &str = "test-data/";
const JELTE_ZONE_PATH: &str = concatcp!(TEST_DATA_DIR, "jelte.nlnetlabs.nl");
const JELTE_KSK_PATH: &str = concatcp!(TEST_DATA_DIR, "Kjelte.nlnetlabs.nl.+008+31310");
const JELTE_ZSK_PATH: &str = concatcp!(TEST_DATA_DIR, "Kjelte.nlnetlabs.nl.+008+19779");
const RFC_5155_ZONE_PATH: &str = concatcp!(TEST_DATA_DIR, "example.rfc5155");
const RFC_5155_KSK_PATH: &str = concatcp!(TEST_DATA_DIR, "Kexample.+008+31967");
const RFC_5155_ZSK_PATH: &str = concatcp!(TEST_DATA_DIR, "Kexample.+008+38353");
#[ignore = "should only be run if ldns command line tools are installed"]
#[test]
fn signzone_only_zsk() {
let temp_dir = tempdir().unwrap().keep();
let ldns_out_path = format!("{}/ldns.signed", temp_dir.display());
let dnst_out_path = format!("{}/dnst.signed", temp_dir.display());
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[
LDNS_CMD,
"-b",
"-f",
&ldns_out_path,
JELTE_ZONE_PATH,
JELTE_ZSK_PATH,
],
&[
LDNS_CMD,
"-b",
"-f",
&dnst_out_path,
JELTE_ZONE_PATH,
JELTE_ZSK_PATH,
],
false,
);
verify_signed_zone(dnst_out_path);
}
#[ignore = "should only be run if ldns command line tools are installed"]
#[test]
fn signzone_only_ksk() {
let temp_dir = tempdir().unwrap().keep();
let ldns_out_path = format!("{}/ldns.signed", temp_dir.display());
let dnst_out_path = format!("{}/dnst.signed", temp_dir.display());
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[
LDNS_CMD,
"-b",
"-f",
&ldns_out_path,
JELTE_ZONE_PATH,
JELTE_KSK_PATH,
],
&[
LDNS_CMD,
"-b",
"-f",
&dnst_out_path,
JELTE_ZONE_PATH,
JELTE_KSK_PATH,
],
false,
);
verify_signed_zone(dnst_out_path);
}
#[ignore = "should only be run if ldns command line tools are installed"]
#[test]
fn signzone_with_both_ksk_and_zsk() {
let temp_dir = tempdir().unwrap().keep();
let ldns_out_path = format!("{}/ldns.signed", temp_dir.display());
let dnst_out_path = format!("{}/dnst.signed", temp_dir.display());
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[
LDNS_CMD,
"-b",
"-f",
&ldns_out_path,
JELTE_ZONE_PATH,
JELTE_KSK_PATH,
JELTE_ZSK_PATH,
],
&[
LDNS_CMD,
"-b",
"-f",
&dnst_out_path,
JELTE_ZONE_PATH,
JELTE_KSK_PATH,
JELTE_ZSK_PATH,
],
false,
);
verify_signed_zone(dnst_out_path);
}
#[ignore = "should only be run if ldns command line tools are installed"]
#[test]
fn signzone_nsec_minus_b() {
let temp_dir = tempdir().unwrap().keep();
let ldns_out_path = format!("{}/ldns.signed", temp_dir.display());
let dnst_out_path = format!("{}/dnst.signed", temp_dir.display());
const TS_FMT: &str = "%Y%m%d%H%M%S";
let now = Zoned::now().round(Unit::Second).unwrap();
let inception_ts = now.saturating_sub(1.month()).strftime(TS_FMT).to_string();
let expiration_ts = now.saturating_add(1.month()).strftime(TS_FMT).to_string();
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[
LDNS_CMD,
"-b",
"-n",
"-e",
&expiration_ts,
"-i",
&inception_ts,
"-f",
&ldns_out_path,
JELTE_ZONE_PATH,
JELTE_KSK_PATH,
],
&[
LDNS_CMD,
"-b",
"-n",
"-e",
&expiration_ts,
"-i",
&inception_ts,
"-f",
&dnst_out_path,
JELTE_ZONE_PATH,
JELTE_KSK_PATH,
],
false,
);
verify_signed_zone(dnst_out_path);
}
#[ignore = "should only be run if ldns command line tools are installed"]
#[test]
fn signzone_with_nsec3_no_opt_out() {
let temp_dir = tempdir().unwrap().keep();
let ldns_out_path = format!("{}/ldns.signed", temp_dir.display());
let dnst_out_path = format!("{}/dnst.signed", temp_dir.display());
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[
LDNS_CMD,
"-n",
"-f",
&ldns_out_path,
RFC_5155_ZONE_PATH,
RFC_5155_KSK_PATH,
RFC_5155_ZSK_PATH,
],
&[
LDNS_CMD,
"-n",
"-f",
&dnst_out_path,
RFC_5155_ZONE_PATH,
RFC_5155_KSK_PATH,
RFC_5155_ZSK_PATH,
],
false,
);
verify_signed_zone(dnst_out_path);
}
#[ignore = "should only be run if ldns command line tools are installed"]
#[test]
fn signzone_with_nsec3_opt_out() {
let temp_dir = tempdir().unwrap().keep();
let ldns_out_path = format!("{}/ldns.signed", temp_dir.display());
let dnst_out_path = format!("{}/dnst.signed", temp_dir.display());
assert_org_ldns_cmd_eq_new_ldns_cmd(
&[
LDNS_CMD,
"-n",
"-p",
"-f",
&ldns_out_path,
RFC_5155_ZONE_PATH,
RFC_5155_KSK_PATH,
RFC_5155_ZSK_PATH,
],
&[
LDNS_CMD,
"-n",
"-p",
"-f",
&dnst_out_path,
RFC_5155_ZONE_PATH,
RFC_5155_KSK_PATH,
RFC_5155_ZSK_PATH,
],
false,
);
verify_signed_zone(dnst_out_path);
}
// Note: We don't test for correct handling of early glue due to the original
// LDNS signzone and verify commands not handling this case correctly. See:
// https://github.com/NLnetLabs/ldns/issues/277.
fn verify_signed_zone(dnst_out_path: String) {
let verify_output = Command::new("ldns-verify-zone")
.args([&dnst_out_path])
.output()
.unwrap();
if !verify_output.status.success() {
eprintln!(
"ldns-verify-zone failed with exit code {:?} and stderr output:\n{}",
verify_output.status.code(),
std::str::from_utf8(&verify_output.stderr).unwrap()
);
}
assert!(
verify_output.status.success(),
"Expected zone verification to succeed"
);
}
-116
View File
@@ -1,116 +0,0 @@
use std::process::Command;
const TEST_ZONE_NAME: &str = "nlnetlabs.nl";
const LDNS_NSEC3_CMD: &str = "ldns-nsec3-hash";
const DNST_NSEC3_SUBCMD: &str = "nsec3-hash";
#[ignore = "should only be run if ldns command line tools are installed"]
#[test]
fn nsec3_hash() {
// Note: ldns-nsec3-hash defaults NSEC3 iterations to 1, while dnst
// nsec-hash defaults NSEC3 iterations to 0.
assert_cmds_eq(
&[LDNS_NSEC3_CMD, TEST_ZONE_NAME],
&[DNST_NSEC3_SUBCMD, "--iterations", "1", TEST_ZONE_NAME],
);
assert_cmds_eq(
&[LDNS_NSEC3_CMD, TEST_ZONE_NAME, "-t", "0"],
&[DNST_NSEC3_SUBCMD, TEST_ZONE_NAME],
);
assert_cmds_eq(
&[LDNS_NSEC3_CMD, "-a", "1", TEST_ZONE_NAME],
&[
DNST_NSEC3_SUBCMD,
"--iterations",
"1",
"--algorithm",
"1",
TEST_ZONE_NAME,
],
);
assert_cmds_eq(
&[LDNS_NSEC3_CMD, "-s", "", TEST_ZONE_NAME],
&[
DNST_NSEC3_SUBCMD,
"--iterations",
"1",
"--salt",
"",
TEST_ZONE_NAME,
],
);
assert_cmds_eq(
&[LDNS_NSEC3_CMD, "-s", "DEADBEEF", TEST_ZONE_NAME],
&[
DNST_NSEC3_SUBCMD,
"--iterations",
"1",
"--salt",
"DEADBEEF",
TEST_ZONE_NAME,
],
);
for iterations in 0..10 {
assert_cmds_eq(
&[
LDNS_NSEC3_CMD,
"-t",
&iterations.to_string(),
TEST_ZONE_NAME,
],
&[
DNST_NSEC3_SUBCMD,
"-i",
&iterations.to_string(),
TEST_ZONE_NAME,
],
);
}
}
fn assert_cmds_eq(cmd1: &[&str], cmd2: &[&str]) {
let cmd1_output = Command::new(cmd1[0]).args(&cmd1[1..]).output().unwrap();
let cmd2_output = test_bin::get_test_bin("dnst").args(cmd2).output().unwrap();
assert_eq!(
std::str::from_utf8(&cmd1_output.stderr),
Ok(""),
"Unexpected stderr content for command: {}",
cmd1.join(" ")
);
assert_eq!(
std::str::from_utf8(&cmd2_output.stderr),
Ok(""),
"Unexpected stderr content for command: {}",
cmd2.join(" ")
);
assert!(
!cmd1_output.stdout.is_empty(),
"Expected stdout content for command: {}: {:?}",
cmd1.join(" "),
std::str::from_utf8(&cmd1_output.stdout)
);
assert!(
!cmd2_output.stdout.is_empty(),
"Expected stdout content for command: {}: {:?}",
cmd2.join(" "),
std::str::from_utf8(&cmd2_output.stdout)
);
assert_eq!(
cmd1_output.status.code(),
cmd2_output.status.code(),
"Exit code mismatch for command: {}",
cmd1.join(" ")
);
// This will only work for LDNS commands whose output we are able to
// replicate exactly.
assert_eq!(
std::str::from_utf8(&cmd1_output.stdout),
std::str::from_utf8(&cmd2_output.stdout),
"Stdout content mismatch for command: {}",
cmd1.join(" ")
);
}