Merge branch 'fix-signing-with-early-glue' into add-logging-to-nsec3-and-rrsig-generation

This commit is contained in:
Ximon Eighteen
2025-05-08 16:49:32 +02:00
5 changed files with 19 additions and 21 deletions
+3 -3
View File
@@ -98,12 +98,12 @@ where
// Skip any glue or other out-of-zone records that sort earlier than
// the zone apex.
records.skip_before(&apex_owner);
records.skip_before(apex_owner);
for owner_rrs in records {
// If the owner is out of zone, we have moved out of our zone and are
// done.
if !owner_rrs.is_in_zone(&apex_owner) {
if !owner_rrs.is_in_zone(apex_owner) {
debug!(
"Stopping at owner {} as it is out of zone and assumed to trail the zone",
owner_rrs.owner()
@@ -128,7 +128,7 @@ where
// If this owner is the parent side of a zone cut, we keep the owner
// name for later. This also means below that if `cut.is_some()` we
// are at the parent side of a zone.
cut = if owner_rrs.is_zone_cut(&apex_owner) {
cut = if owner_rrs.is_zone_cut(apex_owner) {
trace!("Zone cut detected at owner {}", owner_rrs.owner());
Some(name.clone())
} else {
+4 -8
View File
@@ -205,7 +205,7 @@ where
// If the owner is out of zone, we might have moved out of our zone
// and are done.
if !owner_rrs.is_in_zone(&apex_owner) {
if !owner_rrs.is_in_zone(apex_owner) {
debug!(
"Stopping at owner {} as it is out of zone and assumed to trail the zone",
owner_rrs.owner()
@@ -232,7 +232,7 @@ where
// If this owner is the parent side of a zone cut, we keep the owner
// name for later. This also means below that if `cut.is_some()` we
// are at the parent side of a zone.
cut = if owner_rrs.is_zone_cut(&apex_owner) {
cut = if owner_rrs.is_zone_cut(apex_owner) {
trace!("Zone cut detected at owner {}", owner_rrs.owner());
Some(name.clone())
} else {
@@ -478,7 +478,7 @@ where
config.params.flags(),
config.params.iterations(),
config.params.salt(),
&apex_owner,
apex_owner,
bitmap,
nsec3_ttl.unwrap(),
)?;
@@ -508,7 +508,7 @@ where
config.params.flags(),
config.params.iterations(),
config.params.salt(),
&apex_owner,
apex_owner,
bitmap,
nsec3_ttl.unwrap(),
)?;
@@ -617,10 +617,6 @@ where
nsec3.data_mut().set_next_owner(next_hashed_owner_name);
}
let Some(nsec3param_ttl) = nsec3param_ttl else {
return Err(SigningError::SoaRecordCouldNotBeDetermined);
};
// RFC 5155 7.1 step 8:
// "Finally, add an NSEC3PARAM RR with the same Hash Algorithm,
// Iterations, and Salt fields to the zone apex."
+1 -1
View File
@@ -298,7 +298,7 @@ where
/// An implementation of [RFC 4035 section 2 Zone Signing] with optional
/// support for NSEC3 ([RFC 5155]), i.e. it will generate `NSEC` or `NSEC3`
/// (and if NSEC3 is in use then also `NSEC3PARAM`), and `RRSIG` records.
///
///
/// This function **CANNOT** be used to generate RRSIG RRs for DNSKEY, CDS and
/// CDNSKEY RRs. This function expects those RRs and their RRSIGs to already
/// be present in the zone. To sign DNSKEY, CDS and CDNSKEY RRs the lower
+9 -8
View File
@@ -50,11 +50,11 @@ impl GenerateRrsigConfig {
///
/// An implementation of [RFC 4035 section 2.2] for generating RRSIG RRs for a
/// zone.
///
///
/// This function takes DNS records and signing keys and uses the signing keys
/// to generate and output RRSIG RRs that sign the input records per [RFC
/// 9364].
///
///
/// RRSIG RRs will **NOT** be generated for records:
/// - With RTYPE RRSIG, because [RFC 4035 section 2.2] states that _"An
/// RRSIG RR itself MUST NOT be signed"_.
@@ -69,12 +69,12 @@ impl GenerateRrsigConfig {
/// - The order of the output records should not be relied upon.
///
/// # Design rationale
///
///
/// The restriction to limit signing to records not involved in the chain of
/// trust with the parent zone is imposed because there is considerable
/// variation and complexity in the strategies used to protect and roll the
/// keys used to sign records in a DNSSEC signed zone.
///
///
/// It is common operational practice (see [RFC 6871]) to increase security by
/// using two separate keys to sign the zone. A Key Signing Key aka KSK is
/// used to sign the keys used to establish trust with the parent zone, and a
@@ -82,13 +82,13 @@ impl GenerateRrsigConfig {
/// zone, with the KSK signing the ZSK. This allows the ZSK to be rolled
/// without needing to submit information about the new key to the parent zone
/// operator.
///
///
/// Deciding which key to use to sign which records at a given time,
/// especially during key rolls, can be complex. Attempting to cover all
/// possible cases in this function would increase the complexity and
/// fragility and reduce flexibility. As such it is left to the caller to
/// ensure that this is done correctly and doing so also enables the caller to
/// have complete control over the key signing strategy used.
/// have complete control over the key signing strategy used.
///
/// [RFC 4035 section 2.2]: https://www.rfc-editor.org/rfc/rfc4035#section-2.2
/// [RFC 6871]: https://www.rfc-editor.org/rfc/rfc6871
@@ -132,7 +132,7 @@ where
let mut cut: Option<N> = None;
// Skip any glue records that sort earlier than the zone apex.
records.skip_before(&apex_owner);
records.skip_before(apex_owner);
// For all records
for owner_rrs in records {
@@ -658,7 +658,8 @@ mod tests {
TEST_INCEPTION.into(),
TEST_EXPIRATION.into(),
),
).unwrap();
)
.unwrap();
assert!(rrsigs.is_empty());
}
+2 -1
View File
@@ -141,7 +141,7 @@ where
/// Ttl::ZERO,
/// Ttl::ZERO,
/// Ttl::ZERO));
/// records.insert(Record::new(root, Class::IN, Ttl::ZERO, soa)).unwrap();
/// records.insert(Record::new(root.clone(), Class::IN, Ttl::ZERO, soa)).unwrap();
///
/// // Generate or import signing keys (see above).
///
@@ -155,6 +155,7 @@ where
/// let mut signer_generated_records = SortedRecords::default();
///
/// records.sign_zone(
/// &root,
/// &mut signing_config,
/// &keys,
/// &mut signer_generated_records).unwrap();