mirror of
https://github.com/NLnetLabs/domain.git
synced 2026-10-01 22:24:56 +02:00
Merge branch 'fix-signing-with-early-glue' into add-logging-to-nsec3-and-rrsig-generation
This commit is contained in:
@@ -98,12 +98,12 @@ where
|
||||
|
||||
// Skip any glue or other out-of-zone records that sort earlier than
|
||||
// the zone apex.
|
||||
records.skip_before(&apex_owner);
|
||||
records.skip_before(apex_owner);
|
||||
|
||||
for owner_rrs in records {
|
||||
// If the owner is out of zone, we have moved out of our zone and are
|
||||
// done.
|
||||
if !owner_rrs.is_in_zone(&apex_owner) {
|
||||
if !owner_rrs.is_in_zone(apex_owner) {
|
||||
debug!(
|
||||
"Stopping at owner {} as it is out of zone and assumed to trail the zone",
|
||||
owner_rrs.owner()
|
||||
@@ -128,7 +128,7 @@ where
|
||||
// If this owner is the parent side of a zone cut, we keep the owner
|
||||
// name for later. This also means below that if `cut.is_some()` we
|
||||
// are at the parent side of a zone.
|
||||
cut = if owner_rrs.is_zone_cut(&apex_owner) {
|
||||
cut = if owner_rrs.is_zone_cut(apex_owner) {
|
||||
trace!("Zone cut detected at owner {}", owner_rrs.owner());
|
||||
Some(name.clone())
|
||||
} else {
|
||||
|
||||
@@ -205,7 +205,7 @@ where
|
||||
|
||||
// If the owner is out of zone, we might have moved out of our zone
|
||||
// and are done.
|
||||
if !owner_rrs.is_in_zone(&apex_owner) {
|
||||
if !owner_rrs.is_in_zone(apex_owner) {
|
||||
debug!(
|
||||
"Stopping at owner {} as it is out of zone and assumed to trail the zone",
|
||||
owner_rrs.owner()
|
||||
@@ -232,7 +232,7 @@ where
|
||||
// If this owner is the parent side of a zone cut, we keep the owner
|
||||
// name for later. This also means below that if `cut.is_some()` we
|
||||
// are at the parent side of a zone.
|
||||
cut = if owner_rrs.is_zone_cut(&apex_owner) {
|
||||
cut = if owner_rrs.is_zone_cut(apex_owner) {
|
||||
trace!("Zone cut detected at owner {}", owner_rrs.owner());
|
||||
Some(name.clone())
|
||||
} else {
|
||||
@@ -478,7 +478,7 @@ where
|
||||
config.params.flags(),
|
||||
config.params.iterations(),
|
||||
config.params.salt(),
|
||||
&apex_owner,
|
||||
apex_owner,
|
||||
bitmap,
|
||||
nsec3_ttl.unwrap(),
|
||||
)?;
|
||||
@@ -508,7 +508,7 @@ where
|
||||
config.params.flags(),
|
||||
config.params.iterations(),
|
||||
config.params.salt(),
|
||||
&apex_owner,
|
||||
apex_owner,
|
||||
bitmap,
|
||||
nsec3_ttl.unwrap(),
|
||||
)?;
|
||||
@@ -617,10 +617,6 @@ where
|
||||
nsec3.data_mut().set_next_owner(next_hashed_owner_name);
|
||||
}
|
||||
|
||||
let Some(nsec3param_ttl) = nsec3param_ttl else {
|
||||
return Err(SigningError::SoaRecordCouldNotBeDetermined);
|
||||
};
|
||||
|
||||
// RFC 5155 7.1 step 8:
|
||||
// "Finally, add an NSEC3PARAM RR with the same Hash Algorithm,
|
||||
// Iterations, and Salt fields to the zone apex."
|
||||
|
||||
@@ -298,7 +298,7 @@ where
|
||||
/// An implementation of [RFC 4035 section 2 Zone Signing] with optional
|
||||
/// support for NSEC3 ([RFC 5155]), i.e. it will generate `NSEC` or `NSEC3`
|
||||
/// (and if NSEC3 is in use then also `NSEC3PARAM`), and `RRSIG` records.
|
||||
///
|
||||
///
|
||||
/// This function **CANNOT** be used to generate RRSIG RRs for DNSKEY, CDS and
|
||||
/// CDNSKEY RRs. This function expects those RRs and their RRSIGs to already
|
||||
/// be present in the zone. To sign DNSKEY, CDS and CDNSKEY RRs the lower
|
||||
|
||||
@@ -50,11 +50,11 @@ impl GenerateRrsigConfig {
|
||||
///
|
||||
/// An implementation of [RFC 4035 section 2.2] for generating RRSIG RRs for a
|
||||
/// zone.
|
||||
///
|
||||
///
|
||||
/// This function takes DNS records and signing keys and uses the signing keys
|
||||
/// to generate and output RRSIG RRs that sign the input records per [RFC
|
||||
/// 9364].
|
||||
///
|
||||
///
|
||||
/// RRSIG RRs will **NOT** be generated for records:
|
||||
/// - With RTYPE RRSIG, because [RFC 4035 section 2.2] states that _"An
|
||||
/// RRSIG RR itself MUST NOT be signed"_.
|
||||
@@ -69,12 +69,12 @@ impl GenerateRrsigConfig {
|
||||
/// - The order of the output records should not be relied upon.
|
||||
///
|
||||
/// # Design rationale
|
||||
///
|
||||
///
|
||||
/// The restriction to limit signing to records not involved in the chain of
|
||||
/// trust with the parent zone is imposed because there is considerable
|
||||
/// variation and complexity in the strategies used to protect and roll the
|
||||
/// keys used to sign records in a DNSSEC signed zone.
|
||||
///
|
||||
///
|
||||
/// It is common operational practice (see [RFC 6871]) to increase security by
|
||||
/// using two separate keys to sign the zone. A Key Signing Key aka KSK is
|
||||
/// used to sign the keys used to establish trust with the parent zone, and a
|
||||
@@ -82,13 +82,13 @@ impl GenerateRrsigConfig {
|
||||
/// zone, with the KSK signing the ZSK. This allows the ZSK to be rolled
|
||||
/// without needing to submit information about the new key to the parent zone
|
||||
/// operator.
|
||||
///
|
||||
///
|
||||
/// Deciding which key to use to sign which records at a given time,
|
||||
/// especially during key rolls, can be complex. Attempting to cover all
|
||||
/// possible cases in this function would increase the complexity and
|
||||
/// fragility and reduce flexibility. As such it is left to the caller to
|
||||
/// ensure that this is done correctly and doing so also enables the caller to
|
||||
/// have complete control over the key signing strategy used.
|
||||
/// have complete control over the key signing strategy used.
|
||||
///
|
||||
/// [RFC 4035 section 2.2]: https://www.rfc-editor.org/rfc/rfc4035#section-2.2
|
||||
/// [RFC 6871]: https://www.rfc-editor.org/rfc/rfc6871
|
||||
@@ -132,7 +132,7 @@ where
|
||||
let mut cut: Option<N> = None;
|
||||
|
||||
// Skip any glue records that sort earlier than the zone apex.
|
||||
records.skip_before(&apex_owner);
|
||||
records.skip_before(apex_owner);
|
||||
|
||||
// For all records
|
||||
for owner_rrs in records {
|
||||
@@ -658,7 +658,8 @@ mod tests {
|
||||
TEST_INCEPTION.into(),
|
||||
TEST_EXPIRATION.into(),
|
||||
),
|
||||
).unwrap();
|
||||
)
|
||||
.unwrap();
|
||||
|
||||
assert!(rrsigs.is_empty());
|
||||
}
|
||||
|
||||
@@ -141,7 +141,7 @@ where
|
||||
/// Ttl::ZERO,
|
||||
/// Ttl::ZERO,
|
||||
/// Ttl::ZERO));
|
||||
/// records.insert(Record::new(root, Class::IN, Ttl::ZERO, soa)).unwrap();
|
||||
/// records.insert(Record::new(root.clone(), Class::IN, Ttl::ZERO, soa)).unwrap();
|
||||
///
|
||||
/// // Generate or import signing keys (see above).
|
||||
///
|
||||
@@ -155,6 +155,7 @@ where
|
||||
/// let mut signer_generated_records = SortedRecords::default();
|
||||
///
|
||||
/// records.sign_zone(
|
||||
/// &root,
|
||||
/// &mut signing_config,
|
||||
/// &keys,
|
||||
/// &mut signer_generated_records).unwrap();
|
||||
|
||||
Reference in New Issue
Block a user