From 5686da0cff47087e71f364eac326e513fb033891 Mon Sep 17 00:00:00 2001 From: Ximon Eighteen <3304436+ximon18@users.noreply.github.com> Date: Thu, 8 May 2025 16:43:30 +0200 Subject: [PATCH 1/4] Fix compilation failures caused by git hunk staging and unstaging. --- src/dnssec/sign/denial/nsec3.rs | 4 ---- src/dnssec/sign/signatures/rrsigs.rs | 1 - 2 files changed, 5 deletions(-) diff --git a/src/dnssec/sign/denial/nsec3.rs b/src/dnssec/sign/denial/nsec3.rs index 29bd65b5..78880155 100644 --- a/src/dnssec/sign/denial/nsec3.rs +++ b/src/dnssec/sign/denial/nsec3.rs @@ -611,10 +611,6 @@ where nsec3.data_mut().set_next_owner(next_hashed_owner_name); } - let Some(nsec3param_ttl) = nsec3param_ttl else { - return Err(SigningError::SoaRecordCouldNotBeDetermined); - }; - // RFC 5155 7.1 step 8: // "Finally, add an NSEC3PARAM RR with the same Hash Algorithm, // Iterations, and Salt fields to the zone apex." diff --git a/src/dnssec/sign/signatures/rrsigs.rs b/src/dnssec/sign/signatures/rrsigs.rs index de1d5245..71316fbd 100644 --- a/src/dnssec/sign/signatures/rrsigs.rs +++ b/src/dnssec/sign/signatures/rrsigs.rs @@ -139,7 +139,6 @@ where // If the owner is out of zone, we have moved out of our zone and are // done. if !owner_rrs.is_in_zone(apex_owner) { - if !owner_rrs.is_in_zone(zone_apex) { break; } From 2b0453b09b772dd7487920c9c714c9b16efa231c Mon Sep 17 00:00:00 2001 From: Ximon Eighteen <3304436+ximon18@users.noreply.github.com> Date: Thu, 8 May 2025 16:44:09 +0200 Subject: [PATCH 2/4] Fix outdated doc test. --- src/dnssec/sign/traits.rs | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/dnssec/sign/traits.rs b/src/dnssec/sign/traits.rs index 4a6c2e2f..3d51f419 100644 --- a/src/dnssec/sign/traits.rs +++ b/src/dnssec/sign/traits.rs @@ -141,7 +141,7 @@ where /// Ttl::ZERO, /// Ttl::ZERO, /// Ttl::ZERO)); -/// records.insert(Record::new(root, Class::IN, Ttl::ZERO, soa)).unwrap(); +/// records.insert(Record::new(root.clone(), Class::IN, Ttl::ZERO, soa)).unwrap(); /// /// // Generate or import signing keys (see above). /// @@ -155,6 +155,7 @@ where /// let mut signer_generated_records = SortedRecords::default(); /// /// records.sign_zone( +/// &root, /// &mut signing_config, /// &keys, /// &mut signer_generated_records).unwrap(); From c60bf013cb84d5855fb57aa44566d5a4fb239467 Mon Sep 17 00:00:00 2001 From: Ximon Eighteen <3304436+ximon18@users.noreply.github.com> Date: Thu, 8 May 2025 16:44:21 +0200 Subject: [PATCH 3/4] Cargo fmt. --- src/dnssec/sign/mod.rs | 2 +- src/dnssec/sign/signatures/rrsigs.rs | 15 ++++++++------- 2 files changed, 9 insertions(+), 8 deletions(-) diff --git a/src/dnssec/sign/mod.rs b/src/dnssec/sign/mod.rs index 01bb6f15..8d1a10d0 100644 --- a/src/dnssec/sign/mod.rs +++ b/src/dnssec/sign/mod.rs @@ -298,7 +298,7 @@ where /// An implementation of [RFC 4035 section 2 Zone Signing] with optional /// support for NSEC3 ([RFC 5155]), i.e. it will generate `NSEC` or `NSEC3` /// (and if NSEC3 is in use then also `NSEC3PARAM`), and `RRSIG` records. -/// +/// /// This function **CANNOT** be used to generate RRSIG RRs for DNSKEY, CDS and /// CDNSKEY RRs. This function expects those RRs and their RRSIGs to already /// be present in the zone. To sign DNSKEY, CDS and CDNSKEY RRs the lower diff --git a/src/dnssec/sign/signatures/rrsigs.rs b/src/dnssec/sign/signatures/rrsigs.rs index 71316fbd..e15f2c8a 100644 --- a/src/dnssec/sign/signatures/rrsigs.rs +++ b/src/dnssec/sign/signatures/rrsigs.rs @@ -50,11 +50,11 @@ impl GenerateRrsigConfig { /// /// An implementation of [RFC 4035 section 2.2] for generating RRSIG RRs for a /// zone. -/// +/// /// This function takes DNS records and signing keys and uses the signing keys /// to generate and output RRSIG RRs that sign the input records per [RFC /// 9364]. -/// +/// /// RRSIG RRs will **NOT** be generated for records: /// - With RTYPE RRSIG, because [RFC 4035 section 2.2] states that _"An /// RRSIG RR itself MUST NOT be signed"_. @@ -69,12 +69,12 @@ impl GenerateRrsigConfig { /// - The order of the output records should not be relied upon. /// /// # Design rationale -/// +/// /// The restriction to limit signing to records not involved in the chain of /// trust with the parent zone is imposed because there is considerable /// variation and complexity in the strategies used to protect and roll the /// keys used to sign records in a DNSSEC signed zone. -/// +/// /// It is common operational practice (see [RFC 6871]) to increase security by /// using two separate keys to sign the zone. A Key Signing Key aka KSK is /// used to sign the keys used to establish trust with the parent zone, and a @@ -82,13 +82,13 @@ impl GenerateRrsigConfig { /// zone, with the KSK signing the ZSK. This allows the ZSK to be rolled /// without needing to submit information about the new key to the parent zone /// operator. -/// +/// /// Deciding which key to use to sign which records at a given time, /// especially during key rolls, can be complex. Attempting to cover all /// possible cases in this function would increase the complexity and /// fragility and reduce flexibility. As such it is left to the caller to /// ensure that this is done correctly and doing so also enables the caller to -/// have complete control over the key signing strategy used. +/// have complete control over the key signing strategy used. /// /// [RFC 4035 section 2.2]: https://www.rfc-editor.org/rfc/rfc4035#section-2.2 /// [RFC 6871]: https://www.rfc-editor.org/rfc/rfc6871 @@ -639,7 +639,8 @@ mod tests { TEST_INCEPTION.into(), TEST_EXPIRATION.into(), ), - ).unwrap(); + ) + .unwrap(); assert!(rrsigs.is_empty()); } From b3866970d90ee282d1b460a4e3035c6ebcfe9fb3 Mon Sep 17 00:00:00 2001 From: Ximon Eighteen <3304436+ximon18@users.noreply.github.com> Date: Thu, 8 May 2025 16:45:32 +0200 Subject: [PATCH 4/4] Clippy. --- src/dnssec/sign/denial/nsec.rs | 6 +++--- src/dnssec/sign/denial/nsec3.rs | 8 ++++---- src/dnssec/sign/signatures/rrsigs.rs | 2 +- 3 files changed, 8 insertions(+), 8 deletions(-) diff --git a/src/dnssec/sign/denial/nsec.rs b/src/dnssec/sign/denial/nsec.rs index 4e3bf9e2..977c1549 100644 --- a/src/dnssec/sign/denial/nsec.rs +++ b/src/dnssec/sign/denial/nsec.rs @@ -97,12 +97,12 @@ where // Skip any glue or other out-of-zone records that sort earlier than // the zone apex. - records.skip_before(&apex_owner); + records.skip_before(apex_owner); for owner_rrs in records { // If the owner is out of zone, we have moved out of our zone and are // done. - if !owner_rrs.is_in_zone(&apex_owner) { + if !owner_rrs.is_in_zone(apex_owner) { break; } @@ -119,7 +119,7 @@ where // If this owner is the parent side of a zone cut, we keep the owner // name for later. This also means below that if `cut.is_some()` we // are at the parent side of a zone. - cut = if owner_rrs.is_zone_cut(&apex_owner) { + cut = if owner_rrs.is_zone_cut(apex_owner) { Some(name.clone()) } else { None diff --git a/src/dnssec/sign/denial/nsec3.rs b/src/dnssec/sign/denial/nsec3.rs index 78880155..68c518b9 100644 --- a/src/dnssec/sign/denial/nsec3.rs +++ b/src/dnssec/sign/denial/nsec3.rs @@ -205,7 +205,7 @@ where // If the owner is out of zone, we might have moved out of our zone // and are done. - if !owner_rrs.is_in_zone(&apex_owner) { + if !owner_rrs.is_in_zone(apex_owner) { debug!( "Stopping at owner {} as it is out of zone and assumed to trail the zone", owner_rrs.owner() @@ -232,7 +232,7 @@ where // If this owner is the parent side of a zone cut, we keep the owner // name for later. This also means below that if `cut.is_some()` we // are at the parent side of a zone. - cut = if owner_rrs.is_zone_cut(&apex_owner) { + cut = if owner_rrs.is_zone_cut(apex_owner) { trace!("Zone cut detected at owner {}", owner_rrs.owner()); Some(name.clone()) } else { @@ -472,7 +472,7 @@ where config.params.flags(), config.params.iterations(), config.params.salt(), - &apex_owner, + apex_owner, bitmap, nsec3_ttl.unwrap(), )?; @@ -502,7 +502,7 @@ where config.params.flags(), config.params.iterations(), config.params.salt(), - &apex_owner, + apex_owner, bitmap, nsec3_ttl.unwrap(), )?; diff --git a/src/dnssec/sign/signatures/rrsigs.rs b/src/dnssec/sign/signatures/rrsigs.rs index e15f2c8a..90e6cdd1 100644 --- a/src/dnssec/sign/signatures/rrsigs.rs +++ b/src/dnssec/sign/signatures/rrsigs.rs @@ -132,7 +132,7 @@ where let mut cut: Option = None; // Skip any glue records that sort earlier than the zone apex. - records.skip_before(&apex_owner); + records.skip_before(apex_owner); // For all records for owner_rrs in records {