diff --git a/src/dnssec/sign/denial/nsec.rs b/src/dnssec/sign/denial/nsec.rs index f7a2334c..61741b47 100644 --- a/src/dnssec/sign/denial/nsec.rs +++ b/src/dnssec/sign/denial/nsec.rs @@ -98,12 +98,12 @@ where // Skip any glue or other out-of-zone records that sort earlier than // the zone apex. - records.skip_before(&apex_owner); + records.skip_before(apex_owner); for owner_rrs in records { // If the owner is out of zone, we have moved out of our zone and are // done. - if !owner_rrs.is_in_zone(&apex_owner) { + if !owner_rrs.is_in_zone(apex_owner) { debug!( "Stopping at owner {} as it is out of zone and assumed to trail the zone", owner_rrs.owner() @@ -128,7 +128,7 @@ where // If this owner is the parent side of a zone cut, we keep the owner // name for later. This also means below that if `cut.is_some()` we // are at the parent side of a zone. - cut = if owner_rrs.is_zone_cut(&apex_owner) { + cut = if owner_rrs.is_zone_cut(apex_owner) { trace!("Zone cut detected at owner {}", owner_rrs.owner()); Some(name.clone()) } else { diff --git a/src/dnssec/sign/denial/nsec3.rs b/src/dnssec/sign/denial/nsec3.rs index 1ab51877..38c6381a 100644 --- a/src/dnssec/sign/denial/nsec3.rs +++ b/src/dnssec/sign/denial/nsec3.rs @@ -205,7 +205,7 @@ where // If the owner is out of zone, we might have moved out of our zone // and are done. - if !owner_rrs.is_in_zone(&apex_owner) { + if !owner_rrs.is_in_zone(apex_owner) { debug!( "Stopping at owner {} as it is out of zone and assumed to trail the zone", owner_rrs.owner() @@ -232,7 +232,7 @@ where // If this owner is the parent side of a zone cut, we keep the owner // name for later. This also means below that if `cut.is_some()` we // are at the parent side of a zone. - cut = if owner_rrs.is_zone_cut(&apex_owner) { + cut = if owner_rrs.is_zone_cut(apex_owner) { trace!("Zone cut detected at owner {}", owner_rrs.owner()); Some(name.clone()) } else { @@ -478,7 +478,7 @@ where config.params.flags(), config.params.iterations(), config.params.salt(), - &apex_owner, + apex_owner, bitmap, nsec3_ttl.unwrap(), )?; @@ -508,7 +508,7 @@ where config.params.flags(), config.params.iterations(), config.params.salt(), - &apex_owner, + apex_owner, bitmap, nsec3_ttl.unwrap(), )?; @@ -617,10 +617,6 @@ where nsec3.data_mut().set_next_owner(next_hashed_owner_name); } - let Some(nsec3param_ttl) = nsec3param_ttl else { - return Err(SigningError::SoaRecordCouldNotBeDetermined); - }; - // RFC 5155 7.1 step 8: // "Finally, add an NSEC3PARAM RR with the same Hash Algorithm, // Iterations, and Salt fields to the zone apex." diff --git a/src/dnssec/sign/mod.rs b/src/dnssec/sign/mod.rs index 01bb6f15..8d1a10d0 100644 --- a/src/dnssec/sign/mod.rs +++ b/src/dnssec/sign/mod.rs @@ -298,7 +298,7 @@ where /// An implementation of [RFC 4035 section 2 Zone Signing] with optional /// support for NSEC3 ([RFC 5155]), i.e. it will generate `NSEC` or `NSEC3` /// (and if NSEC3 is in use then also `NSEC3PARAM`), and `RRSIG` records. -/// +/// /// This function **CANNOT** be used to generate RRSIG RRs for DNSKEY, CDS and /// CDNSKEY RRs. This function expects those RRs and their RRSIGs to already /// be present in the zone. To sign DNSKEY, CDS and CDNSKEY RRs the lower diff --git a/src/dnssec/sign/signatures/rrsigs.rs b/src/dnssec/sign/signatures/rrsigs.rs index ae66001d..edf6e66a 100644 --- a/src/dnssec/sign/signatures/rrsigs.rs +++ b/src/dnssec/sign/signatures/rrsigs.rs @@ -50,11 +50,11 @@ impl GenerateRrsigConfig { /// /// An implementation of [RFC 4035 section 2.2] for generating RRSIG RRs for a /// zone. -/// +/// /// This function takes DNS records and signing keys and uses the signing keys /// to generate and output RRSIG RRs that sign the input records per [RFC /// 9364]. -/// +/// /// RRSIG RRs will **NOT** be generated for records: /// - With RTYPE RRSIG, because [RFC 4035 section 2.2] states that _"An /// RRSIG RR itself MUST NOT be signed"_. @@ -69,12 +69,12 @@ impl GenerateRrsigConfig { /// - The order of the output records should not be relied upon. /// /// # Design rationale -/// +/// /// The restriction to limit signing to records not involved in the chain of /// trust with the parent zone is imposed because there is considerable /// variation and complexity in the strategies used to protect and roll the /// keys used to sign records in a DNSSEC signed zone. -/// +/// /// It is common operational practice (see [RFC 6871]) to increase security by /// using two separate keys to sign the zone. A Key Signing Key aka KSK is /// used to sign the keys used to establish trust with the parent zone, and a @@ -82,13 +82,13 @@ impl GenerateRrsigConfig { /// zone, with the KSK signing the ZSK. This allows the ZSK to be rolled /// without needing to submit information about the new key to the parent zone /// operator. -/// +/// /// Deciding which key to use to sign which records at a given time, /// especially during key rolls, can be complex. Attempting to cover all /// possible cases in this function would increase the complexity and /// fragility and reduce flexibility. As such it is left to the caller to /// ensure that this is done correctly and doing so also enables the caller to -/// have complete control over the key signing strategy used. +/// have complete control over the key signing strategy used. /// /// [RFC 4035 section 2.2]: https://www.rfc-editor.org/rfc/rfc4035#section-2.2 /// [RFC 6871]: https://www.rfc-editor.org/rfc/rfc6871 @@ -132,7 +132,7 @@ where let mut cut: Option = None; // Skip any glue records that sort earlier than the zone apex. - records.skip_before(&apex_owner); + records.skip_before(apex_owner); // For all records for owner_rrs in records { @@ -658,7 +658,8 @@ mod tests { TEST_INCEPTION.into(), TEST_EXPIRATION.into(), ), - ).unwrap(); + ) + .unwrap(); assert!(rrsigs.is_empty()); } diff --git a/src/dnssec/sign/traits.rs b/src/dnssec/sign/traits.rs index 4a6c2e2f..3d51f419 100644 --- a/src/dnssec/sign/traits.rs +++ b/src/dnssec/sign/traits.rs @@ -141,7 +141,7 @@ where /// Ttl::ZERO, /// Ttl::ZERO, /// Ttl::ZERO)); -/// records.insert(Record::new(root, Class::IN, Ttl::ZERO, soa)).unwrap(); +/// records.insert(Record::new(root.clone(), Class::IN, Ttl::ZERO, soa)).unwrap(); /// /// // Generate or import signing keys (see above). /// @@ -155,6 +155,7 @@ where /// let mut signer_generated_records = SortedRecords::default(); /// /// records.sign_zone( +/// &root, /// &mut signing_config, /// &keys, /// &mut signer_generated_records).unwrap();