mirror of
https://github.com/NLnetLabs/unbound.git
synced 2026-08-17 21:25:50 +02:00
Compare commits
84
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8687d69131 | ||
|
|
c622a71a28 | ||
|
|
ecfc6a70ce | ||
|
|
a23c5347a7 | ||
|
|
1ae8be6847 | ||
|
|
f0268d3e83 | ||
|
|
c904a3d375 | ||
|
|
b451cc4af7 | ||
|
|
f9713f9fe5 | ||
|
|
dfac72edfc | ||
|
|
64e102aacb | ||
|
|
bebd6c0f96 | ||
|
|
63aa70ab32 | ||
|
|
7b59014ba3 | ||
|
|
156846e6c4 | ||
|
|
aea2a821b9 | ||
|
|
cacdfee755 | ||
|
|
e3c1981a6a | ||
|
|
e2efd17007 | ||
|
|
4a2dc1df48 | ||
|
|
5c79fd9a0b | ||
|
|
4a3a4f474f | ||
|
|
708581579c | ||
|
|
af1d430759 | ||
|
|
da72734240 | ||
|
|
54175a4180 | ||
|
|
888d5ce9f9 | ||
|
|
b1bb4a4592 | ||
|
|
3b88577dd1 | ||
|
|
6634b8bcc5 | ||
|
|
3d7dfe2f36 | ||
|
|
baee7885bd | ||
|
|
e55b3a2a4c | ||
|
|
e4069e5619 | ||
|
|
a3ec9a974f | ||
|
|
479b954118 | ||
|
|
0955238cd3 | ||
|
|
57dd6a971d | ||
|
|
6a831e3063 | ||
|
|
3807bf00da | ||
|
|
9022381be4 | ||
|
|
ca147a147d | ||
|
|
5147e5aee9 | ||
|
|
6466513cc5 | ||
|
|
7a1a615fd3 | ||
|
|
81d774fb11 | ||
|
|
0254317e0d | ||
|
|
dc37849546 | ||
|
|
766666139b | ||
|
|
86e78fcacc | ||
|
|
47a2d71fd3 | ||
|
|
0719ef21fa | ||
|
|
6d5f22b56d | ||
|
|
b5beb800c8 | ||
|
|
fe63b25441 | ||
|
|
0afbb68b40 | ||
|
|
4562cd372c | ||
|
|
418ef3765d | ||
|
|
29c8b3edba | ||
|
|
5214912555 | ||
|
|
f2c609b9a5 | ||
|
|
aa22fd936e | ||
|
|
4bbb74da39 | ||
|
|
dd4ee42eb6 | ||
|
|
8b95785b8c | ||
|
|
bb4ddab77a | ||
|
|
69354298fc | ||
|
|
bbcf5d122a | ||
|
|
497161f72f | ||
|
|
31e8118b76 | ||
|
|
8811bd4844 | ||
|
|
0f02479dea | ||
|
|
364edccebc | ||
|
|
3d9242b3d3 | ||
|
|
3f378c962f | ||
|
|
4ca37bcadf | ||
|
|
19492da154 | ||
|
|
182e580fe2 | ||
|
|
eefb417c09 | ||
|
|
4fd0d84e66 | ||
|
|
ea0973002f | ||
|
|
8fcc4c98b6 | ||
|
|
7edc1e0fc4 | ||
|
|
e6573fc337 |
+34
-18
@@ -130,7 +130,7 @@ util/fptr_wlist.c util/locks.c util/log.c util/mini_event.c util/module.c \
|
||||
util/netevent.c util/net_help.c util/random.c util/rbtree.c util/regional.c \
|
||||
util/rtt.c util/siphash.c util/edns.c util/storage/dnstree.c util/storage/lookup3.c \
|
||||
util/storage/lruhash.c util/storage/slabhash.c util/tcp_conn_limit.c \
|
||||
util/timehist.c util/tube.c util/proxy_protocol.c util/timeval_func.c \
|
||||
util/timehist.c util/tsig.c util/tube.c util/proxy_protocol.c util/timeval_func.c \
|
||||
util/ub_event.c util/ub_event_pluggable.c util/winsock_event.c \
|
||||
validator/autotrust.c validator/val_anchor.c validator/validator.c \
|
||||
validator/val_kcache.c validator/val_kentry.c validator/val_neg.c \
|
||||
@@ -147,7 +147,7 @@ iter_scrub.lo iter_utils.lo localzone.lo mesh.lo modstack.lo view.lo \
|
||||
outbound_list.lo alloc.lo config_file.lo configlexer.lo configparser.lo \
|
||||
fptr_wlist.lo siphash.lo edns.lo locks.lo log.lo mini_event.lo module.lo net_help.lo \
|
||||
random.lo rbtree.lo regional.lo rtt.lo dnstree.lo lookup3.lo lruhash.lo \
|
||||
slabhash.lo tcp_conn_limit.lo timehist.lo tube.lo winsock_event.lo \
|
||||
slabhash.lo tcp_conn_limit.lo timehist.lo tsig.lo tube.lo winsock_event.lo \
|
||||
autotrust.lo val_anchor.lo rpz.lo rfc_1982.lo proxy_protocol.lo \
|
||||
validator.lo val_kcache.lo val_kentry.lo val_neg.lo val_nsec3.lo val_nsec.lo \
|
||||
val_secalgo.lo val_sigcrypt.lo val_utils.lo dns64.lo $(CACHEDB_OBJ) authzone.lo \
|
||||
@@ -179,11 +179,12 @@ testcode/unitlruhash.c testcode/unitmain.c testcode/unitmsgparse.c \
|
||||
testcode/unitneg.c testcode/unitregional.c testcode/unitslabhash.c \
|
||||
testcode/unitverify.c testcode/readhex.c testcode/testpkts.c testcode/unitldns.c \
|
||||
testcode/unitecs.c testcode/unitauth.c testcode/unitzonemd.c \
|
||||
testcode/unittcpreuse.c testcode/unitdoq.c testcode/unitinfra.c
|
||||
testcode/unittcpreuse.c testcode/unitdoq.c testcode/unitinfra.c \
|
||||
testcode/unittsig.c
|
||||
UNITTEST_OBJ=unitanchor.lo unitdname.lo unitlruhash.lo unitmain.lo \
|
||||
unitmsgparse.lo unitneg.lo unitregional.lo unitslabhash.lo unitverify.lo \
|
||||
readhex.lo testpkts.lo unitldns.lo unitecs.lo unitauth.lo unitzonemd.lo \
|
||||
unittcpreuse.lo unitdoq.lo unitinfra.lo
|
||||
unittcpreuse.lo unitdoq.lo unitinfra.lo unittsig.lo
|
||||
UNITTEST_OBJ_LINK=$(UNITTEST_OBJ) worker_cb.lo $(COMMON_OBJ) $(SLDNS_OBJ) \
|
||||
$(COMPAT_OBJ)
|
||||
DAEMON_SRC=daemon/acl_list.c daemon/cachedump.c daemon/daemon.c \
|
||||
@@ -719,6 +720,7 @@ depend:
|
||||
|
||||
# build rules
|
||||
ipset.lo ipset.o: $(srcdir)/ipset/ipset.c
|
||||
tsig.lo tsig.o: $(srcdir)/util/tsig.c config.h $(srcdir)/util/tsig.h
|
||||
doqclient.lo doqclient.o: $(srcdir)/testcode/doqclient.c
|
||||
unitdoq.lo unitdoq.o: $(srcdir)/testcode/unitdoq.c
|
||||
|
||||
@@ -971,7 +973,8 @@ configlexer.lo configlexer.o: util/configlexer.c config.h $(srcdir)/util/configy
|
||||
$(srcdir)/util/config_file.h $(srcdir)/sldns/rrdef.h util/configparser.h
|
||||
configparser.lo configparser.o: util/configparser.c config.h $(srcdir)/util/configyyrename.h \
|
||||
$(srcdir)/util/config_file.h $(srcdir)/sldns/rrdef.h $(srcdir)/util/net_help.h $(srcdir)/util/log.h \
|
||||
$(srcdir)/util/random.h $(srcdir)/sldns/str2wire.h util/configparser.h
|
||||
$(srcdir)/util/random.h $(srcdir)/util/tsig.h $(srcdir)/util/locks.h $(srcdir)/util/rbtree.h $(srcdir)/sldns/str2wire.h \
|
||||
$(srcdir)/sldns/parseutil.h util/configparser.h
|
||||
shm_main.lo shm_main.o: $(srcdir)/util/shm_side/shm_main.c config.h $(srcdir)/util/shm_side/shm_main.h \
|
||||
$(srcdir)/libunbound/unbound.h $(srcdir)/daemon/daemon.h $(srcdir)/util/locks.h $(srcdir)/util/log.h \
|
||||
$(srcdir)/util/alloc.h $(srcdir)/services/modstack.h \
|
||||
@@ -995,7 +998,7 @@ authzone.lo authzone.o: $(srcdir)/services/authzone.c config.h $(srcdir)/service
|
||||
$(srcdir)/util/storage/dnstree.h $(srcdir)/services/view.h $(srcdir)/sldns/sbuffer.h \
|
||||
$(srcdir)/util/config_file.h $(srcdir)/daemon/stats.h $(srcdir)/util/timehist.h $(srcdir)/libunbound/unbound.h \
|
||||
$(srcdir)/respip/respip.h $(srcdir)/util/data/dname.h $(srcdir)/util/data/msgencode.h $(srcdir)/util/regional.h \
|
||||
$(srcdir)/util/net_help.h $(srcdir)/util/random.h $(srcdir)/services/cache/dns.h \
|
||||
$(srcdir)/util/net_help.h $(srcdir)/util/random.h $(srcdir)/util/tsig.h $(srcdir)/services/cache/dns.h \
|
||||
$(srcdir)/services/outside_network.h $(srcdir)/util/alloc.h \
|
||||
$(srcdir)/services/listen_dnsport.h $(srcdir)/daemon/acl_list.h \
|
||||
$(srcdir)/sldns/str2wire.h $(srcdir)/sldns/wire2str.h $(srcdir)/sldns/parseutil.h $(srcdir)/sldns/keyraw.h \
|
||||
@@ -1019,7 +1022,8 @@ fptr_wlist.lo fptr_wlist.o: $(srcdir)/util/fptr_wlist.c config.h $(srcdir)/util/
|
||||
$(srcdir)/validator/val_utils.h $(srcdir)/validator/val_nsec3.h $(srcdir)/validator/val_anchor.h \
|
||||
$(srcdir)/validator/val_sigcrypt.h $(srcdir)/validator/val_kentry.h $(srcdir)/validator/val_neg.h \
|
||||
$(srcdir)/validator/autotrust.h $(srcdir)/libunbound/libworker.h $(srcdir)/libunbound/context.h \
|
||||
$(srcdir)/libunbound/unbound-event.h $(srcdir)/libunbound/worker.h $(srcdir)/daemon/remote.h \
|
||||
$(srcdir)/libunbound/unbound-event.h $(srcdir)/libunbound/worker.h $(srcdir)/util/tsig.h \
|
||||
$(srcdir)/daemon/remote.h \
|
||||
$(PYTHONMOD_HEADER) $(DYNLIBMOD_HEADER) $(srcdir)/cachedb/cachedb.h \
|
||||
$(srcdir)/ipsecmod/ipsecmod.h $(srcdir)/edns-subnet/subnetmod.h $(srcdir)/util/net_help.h \
|
||||
$(srcdir)/util/random.h $(srcdir)/util/data/dname.h $(srcdir)/edns-subnet/addrtree.h \
|
||||
@@ -1099,6 +1103,12 @@ tcp_conn_limit.lo tcp_conn_limit.o: $(srcdir)/util/tcp_conn_limit.c config.h $(s
|
||||
$(srcdir)/sldns/pkthdr.h $(srcdir)/services/view.h $(srcdir)/sldns/sbuffer.h $(srcdir)/sldns/str2wire.h
|
||||
timehist.lo timehist.o: $(srcdir)/util/timehist.c config.h $(srcdir)/util/timehist.h $(srcdir)/util/log.h \
|
||||
$(srcdir)/util/timeval_func.h
|
||||
tsig.lo tsig.o: $(srcdir)/util/tsig.c config.h $(srcdir)/util/tsig.h $(srcdir)/util/locks.h $(srcdir)/util/log.h \
|
||||
$(srcdir)/util/rbtree.h $(srcdir)/util/config_file.h $(srcdir)/sldns/rrdef.h $(srcdir)/util/net_help.h \
|
||||
$(srcdir)/util/random.h $(srcdir)/util/regional.h $(srcdir)/sldns/parseutil.h $(srcdir)/sldns/pkthdr.h \
|
||||
$(srcdir)/sldns/sbuffer.h $(srcdir)/sldns/str2wire.h $(srcdir)/util/data/msgparse.h \
|
||||
$(srcdir)/util/storage/lruhash.h $(srcdir)/util/data/dname.h \
|
||||
|
||||
tube.lo tube.o: $(srcdir)/util/tube.c config.h $(srcdir)/util/tube.h $(srcdir)/util/log.h $(srcdir)/util/net_help.h \
|
||||
$(srcdir)/util/random.h $(srcdir)/util/netevent.h $(srcdir)/dnscrypt/dnscrypt.h \
|
||||
$(srcdir)/dnscrypt/cert.h $(srcdir)/util/locks.h \
|
||||
@@ -1431,6 +1441,10 @@ unitinfra.lo unitinfra.o: $(srcdir)/testcode/unitinfra.c config.h $(srcdir)/test
|
||||
$(srcdir)/util/netevent.h $(srcdir)/dnscrypt/dnscrypt.h \
|
||||
$(srcdir)/dnscrypt/cert.h \
|
||||
$(srcdir)/util/config_file.h $(srcdir)/util/net_help.h $(srcdir)/util/random.h
|
||||
unittsig.lo unittsig.o: $(srcdir)/testcode/unittsig.c config.h $(srcdir)/util/tsig.h $(srcdir)/util/locks.h \
|
||||
$(srcdir)/util/log.h $(srcdir)/util/rbtree.h $(srcdir)/util/config_file.h $(srcdir)/sldns/rrdef.h \
|
||||
$(srcdir)/util/net_help.h $(srcdir)/util/random.h $(srcdir)/testcode/unitmain.h $(srcdir)/sldns/parseutil.h \
|
||||
$(srcdir)/sldns/pkthdr.h $(srcdir)/sldns/sbuffer.h $(srcdir)/sldns/str2wire.h $(srcdir)/sldns/wire2str.h
|
||||
acl_list.lo acl_list.o: $(srcdir)/daemon/acl_list.c config.h $(srcdir)/daemon/acl_list.h \
|
||||
$(srcdir)/util/storage/dnstree.h $(srcdir)/util/rbtree.h $(srcdir)/services/view.h $(srcdir)/util/locks.h \
|
||||
$(srcdir)/util/log.h $(srcdir)/util/regional.h $(srcdir)/util/config_file.h $(srcdir)/sldns/rrdef.h \
|
||||
@@ -1470,8 +1484,9 @@ daemon.lo daemon.o: $(srcdir)/daemon/daemon.c config.h \
|
||||
$(srcdir)/services/listen_dnsport.h \
|
||||
$(srcdir)/services/cache/rrset.h $(srcdir)/services/cache/infra.h $(srcdir)/util/rtt.h \
|
||||
$(srcdir)/services/localzone.h $(srcdir)/services/authzone.h $(srcdir)/services/mesh.h $(srcdir)/services/rpz.h \
|
||||
$(srcdir)/respip/respip.h $(srcdir)/util/random.h $(srcdir)/util/tube.h $(srcdir)/util/net_help.h $(srcdir)/sldns/keyraw.h \
|
||||
$(srcdir)/iterator/iter_fwd.h $(srcdir)/iterator/iter_hints.h $(srcdir)/cachedb/cachedb.h
|
||||
$(srcdir)/respip/respip.h $(srcdir)/util/random.h $(srcdir)/util/tube.h $(srcdir)/util/net_help.h $(srcdir)/util/tsig.h \
|
||||
$(srcdir)/sldns/keyraw.h $(srcdir)/iterator/iter_fwd.h $(srcdir)/iterator/iter_hints.h \
|
||||
$(srcdir)/cachedb/cachedb.h
|
||||
remote.lo remote.o: $(srcdir)/daemon/remote.c config.h \
|
||||
$(srcdir)/daemon/remote.h \
|
||||
$(srcdir)/util/locks.h $(srcdir)/util/log.h $(srcdir)/daemon/worker.h $(srcdir)/libunbound/worker.h \
|
||||
@@ -1494,7 +1509,7 @@ remote.lo remote.o: $(srcdir)/daemon/remote.c config.h \
|
||||
$(srcdir)/iterator/iter_delegpt.h $(srcdir)/iterator/iter_utils.h $(srcdir)/iterator/iter_resptype.h \
|
||||
$(srcdir)/iterator/iter_donotq.h $(srcdir)/iterator/iter_priv.h $(srcdir)/services/outside_network.h \
|
||||
$(srcdir)/util/regional.h $(srcdir)/sldns/str2wire.h $(srcdir)/sldns/parseutil.h $(srcdir)/sldns/wire2str.h \
|
||||
$(srcdir)/util/timeval_func.h $(srcdir)/util/tcp_conn_limit.h $(srcdir)/util/edns.h $(srcdir)/cachedb/cachedb.h \
|
||||
$(srcdir)/util/timeval_func.h $(srcdir)/util/tcp_conn_limit.h $(srcdir)/util/edns.h $(srcdir)/util/tsig.h $(srcdir)/cachedb/cachedb.h \
|
||||
$(srcdir)/edns-subnet/subnetmod.h $(srcdir)/edns-subnet/addrtree.h $(srcdir)/edns-subnet/edns-subnet.h
|
||||
stats.lo stats.o: $(srcdir)/daemon/stats.c config.h $(srcdir)/daemon/stats.h $(srcdir)/util/timehist.h \
|
||||
$(srcdir)/libunbound/unbound.h $(srcdir)/daemon/worker.h $(srcdir)/libunbound/worker.h $(srcdir)/sldns/sbuffer.h \
|
||||
@@ -1545,7 +1560,7 @@ worker.lo worker.o: $(srcdir)/daemon/worker.c config.h $(srcdir)/util/log.h $(sr
|
||||
$(srcdir)/services/cache/dns.h $(srcdir)/services/authzone.h $(srcdir)/services/mesh.h $(srcdir)/services/rpz.h \
|
||||
$(srcdir)/services/localzone.h $(srcdir)/respip/respip.h $(srcdir)/util/data/msgencode.h \
|
||||
$(srcdir)/util/data/dname.h $(srcdir)/util/fptr_wlist.h $(srcdir)/util/tube.h $(srcdir)/util/proxy_protocol.h \
|
||||
$(srcdir)/util/edns.h $(srcdir)/util/timeval_func.h $(srcdir)/iterator/iter_fwd.h \
|
||||
$(srcdir)/util/tsig.h $(srcdir)/util/edns.h $(srcdir)/util/timeval_func.h $(srcdir)/iterator/iter_fwd.h \
|
||||
$(srcdir)/iterator/iter_hints.h $(srcdir)/iterator/iter_utils.h $(srcdir)/iterator/iter_resptype.h \
|
||||
$(srcdir)/validator/autotrust.h $(srcdir)/validator/val_anchor.h $(srcdir)/libunbound/context.h \
|
||||
$(srcdir)/libunbound/unbound-event.h $(srcdir)/libunbound/libworker.h $(srcdir)/sldns/wire2str.h \
|
||||
@@ -1586,7 +1601,7 @@ worker.lo worker.o: $(srcdir)/daemon/worker.c config.h $(srcdir)/util/log.h $(sr
|
||||
$(srcdir)/services/cache/dns.h $(srcdir)/services/authzone.h $(srcdir)/services/mesh.h $(srcdir)/services/rpz.h \
|
||||
$(srcdir)/services/localzone.h $(srcdir)/respip/respip.h $(srcdir)/util/data/msgencode.h \
|
||||
$(srcdir)/util/data/dname.h $(srcdir)/util/fptr_wlist.h $(srcdir)/util/tube.h $(srcdir)/util/proxy_protocol.h \
|
||||
$(srcdir)/util/edns.h $(srcdir)/util/timeval_func.h $(srcdir)/iterator/iter_fwd.h \
|
||||
$(srcdir)/util/tsig.h $(srcdir)/util/edns.h $(srcdir)/util/timeval_func.h $(srcdir)/iterator/iter_fwd.h \
|
||||
$(srcdir)/iterator/iter_hints.h $(srcdir)/iterator/iter_utils.h $(srcdir)/iterator/iter_resptype.h \
|
||||
$(srcdir)/validator/autotrust.h $(srcdir)/validator/val_anchor.h $(srcdir)/libunbound/context.h \
|
||||
$(srcdir)/libunbound/unbound-event.h $(srcdir)/libunbound/libworker.h $(srcdir)/sldns/wire2str.h \
|
||||
@@ -1615,8 +1630,9 @@ daemon.lo daemon.o: $(srcdir)/daemon/daemon.c config.h \
|
||||
$(srcdir)/services/listen_dnsport.h \
|
||||
$(srcdir)/services/cache/rrset.h $(srcdir)/services/cache/infra.h $(srcdir)/util/rtt.h \
|
||||
$(srcdir)/services/localzone.h $(srcdir)/services/authzone.h $(srcdir)/services/mesh.h $(srcdir)/services/rpz.h \
|
||||
$(srcdir)/respip/respip.h $(srcdir)/util/random.h $(srcdir)/util/tube.h $(srcdir)/util/net_help.h $(srcdir)/sldns/keyraw.h \
|
||||
$(srcdir)/iterator/iter_fwd.h $(srcdir)/iterator/iter_hints.h $(srcdir)/cachedb/cachedb.h
|
||||
$(srcdir)/respip/respip.h $(srcdir)/util/random.h $(srcdir)/util/tube.h $(srcdir)/util/net_help.h $(srcdir)/util/tsig.h \
|
||||
$(srcdir)/sldns/keyraw.h $(srcdir)/iterator/iter_fwd.h $(srcdir)/iterator/iter_hints.h \
|
||||
$(srcdir)/cachedb/cachedb.h
|
||||
stats.lo stats.o: $(srcdir)/daemon/stats.c config.h $(srcdir)/daemon/stats.h $(srcdir)/util/timehist.h \
|
||||
$(srcdir)/libunbound/unbound.h $(srcdir)/daemon/worker.h $(srcdir)/libunbound/worker.h $(srcdir)/sldns/sbuffer.h \
|
||||
$(srcdir)/util/data/packed_rrset.h $(srcdir)/util/storage/lruhash.h $(srcdir)/util/locks.h $(srcdir)/util/log.h \
|
||||
@@ -1687,8 +1703,8 @@ unbound-checkconf.lo unbound-checkconf.o: $(srcdir)/smallapp/unbound-checkconf.c
|
||||
$(srcdir)/util/config_file.h $(srcdir)/sldns/rrdef.h $(srcdir)/util/module.h $(srcdir)/util/storage/lruhash.h \
|
||||
$(srcdir)/util/locks.h $(srcdir)/util/data/msgreply.h $(srcdir)/util/data/packed_rrset.h \
|
||||
$(srcdir)/util/data/msgparse.h $(srcdir)/sldns/pkthdr.h $(srcdir)/util/net_help.h $(srcdir)/util/random.h \
|
||||
$(srcdir)/util/regional.h $(srcdir)/iterator/iterator.h $(srcdir)/services/outbound_list.h \
|
||||
$(srcdir)/iterator/iter_fwd.h $(srcdir)/util/rbtree.h $(srcdir)/iterator/iter_hints.h \
|
||||
$(srcdir)/util/regional.h $(srcdir)/util/tsig.h $(srcdir)/util/rbtree.h $(srcdir)/iterator/iterator.h \
|
||||
$(srcdir)/services/outbound_list.h $(srcdir)/iterator/iter_fwd.h $(srcdir)/iterator/iter_hints.h \
|
||||
$(srcdir)/util/storage/dnstree.h $(srcdir)/validator/validator.h $(srcdir)/validator/val_utils.h \
|
||||
$(srcdir)/validator/val_nsec3.h $(srcdir)/services/localzone.h $(srcdir)/services/view.h \
|
||||
$(srcdir)/sldns/sbuffer.h $(srcdir)/services/listen_dnsport.h $(srcdir)/util/netevent.h \
|
||||
@@ -1721,7 +1737,7 @@ context.lo context.o: $(srcdir)/libunbound/context.c config.h $(srcdir)/libunbou
|
||||
$(srcdir)/services/authzone.h $(srcdir)/services/mesh.h $(srcdir)/services/rpz.h $(srcdir)/daemon/stats.h \
|
||||
$(srcdir)/util/timehist.h $(srcdir)/respip/respip.h $(srcdir)/services/listen_dnsport.h \
|
||||
$(srcdir)/daemon/acl_list.h \
|
||||
$(srcdir)/util/edns.h $(srcdir)/iterator/iter_fwd.h $(srcdir)/iterator/iter_hints.h
|
||||
$(srcdir)/util/edns.h $(srcdir)/util/tsig.h $(srcdir)/iterator/iter_fwd.h $(srcdir)/iterator/iter_hints.h
|
||||
libunbound.lo libunbound.o: $(srcdir)/libunbound/libunbound.c $(srcdir)/libunbound/unbound.h \
|
||||
$(srcdir)/libunbound/unbound-event.h config.h $(srcdir)/libunbound/context.h $(srcdir)/util/locks.h \
|
||||
$(srcdir)/util/log.h $(srcdir)/util/alloc.h $(srcdir)/util/rbtree.h $(srcdir)/services/modstack.h \
|
||||
@@ -1729,7 +1745,7 @@ libunbound.lo libunbound.o: $(srcdir)/libunbound/libunbound.c $(srcdir)/libunbou
|
||||
$(srcdir)/util/config_file.h $(srcdir)/sldns/rrdef.h $(srcdir)/util/module.h $(srcdir)/util/data/msgreply.h \
|
||||
$(srcdir)/util/data/msgparse.h $(srcdir)/sldns/pkthdr.h $(srcdir)/util/regional.h $(srcdir)/util/random.h \
|
||||
$(srcdir)/util/net_help.h $(srcdir)/util/tube.h $(srcdir)/util/ub_event.h $(srcdir)/util/edns.h \
|
||||
$(srcdir)/util/storage/dnstree.h $(srcdir)/services/localzone.h $(srcdir)/services/view.h \
|
||||
$(srcdir)/util/storage/dnstree.h $(srcdir)/util/tsig.h $(srcdir)/services/localzone.h $(srcdir)/services/view.h \
|
||||
$(srcdir)/sldns/sbuffer.h $(srcdir)/services/cache/infra.h $(srcdir)/util/rtt.h $(srcdir)/util/netevent.h \
|
||||
$(srcdir)/dnscrypt/dnscrypt.h $(srcdir)/dnscrypt/cert.h \
|
||||
$(srcdir)/services/cache/rrset.h $(srcdir)/util/storage/slabhash.h $(srcdir)/services/authzone.h \
|
||||
|
||||
@@ -256,6 +256,9 @@
|
||||
/* Define to 1 if you have the `EVP_EncryptInit_ex' function. */
|
||||
#undef HAVE_EVP_ENCRYPTINIT_EX
|
||||
|
||||
/* Define to 1 if you have the `EVP_MAC_CTX_new' function. */
|
||||
#undef HAVE_EVP_MAC_CTX_NEW
|
||||
|
||||
/* Define to 1 if you have the `EVP_MAC_CTX_set_params' function. */
|
||||
#undef HAVE_EVP_MAC_CTX_SET_PARAMS
|
||||
|
||||
@@ -337,6 +340,9 @@
|
||||
/* Define to 1 if you have the <hiredis/hiredis.h> header file. */
|
||||
#undef HAVE_HIREDIS_HIREDIS_H
|
||||
|
||||
/* Define to 1 if you have the `HMAC_CTX_new' function. */
|
||||
#undef HAVE_HMAC_CTX_NEW
|
||||
|
||||
/* Define to 1 if you have the `HMAC_Init_ex' function. */
|
||||
#undef HAVE_HMAC_INIT_EX
|
||||
|
||||
@@ -658,6 +664,9 @@
|
||||
function. */
|
||||
#undef HAVE_SSL_CTX_SET_TLSEXT_TICKET_KEY_EVP_CB
|
||||
|
||||
/* Define to 1 if you have the `SSL_CTX_set_tmp_ecdh' function. */
|
||||
#undef HAVE_SSL_CTX_SET_TMP_ECDH
|
||||
|
||||
/* Define to 1 if you have the `SSL_get0_alpn_selected' function. */
|
||||
#undef HAVE_SSL_GET0_ALPN_SELECTED
|
||||
|
||||
|
||||
@@ -20881,6 +20881,24 @@ then :
|
||||
printf "%s\n" "#define HAVE_BIO_SET_CALLBACK_EX 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_func "$LINENO" "SSL_CTX_set_tmp_ecdh" "ac_cv_func_SSL_CTX_set_tmp_ecdh"
|
||||
if test "x$ac_cv_func_SSL_CTX_set_tmp_ecdh" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_SSL_CTX_SET_TMP_ECDH 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_func "$LINENO" "HMAC_CTX_new" "ac_cv_func_HMAC_CTX_new"
|
||||
if test "x$ac_cv_func_HMAC_CTX_new" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_HMAC_CTX_NEW 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
ac_fn_c_check_func "$LINENO" "EVP_MAC_CTX_new" "ac_cv_func_EVP_MAC_CTX_new"
|
||||
if test "x$ac_cv_func_EVP_MAC_CTX_new" = xyes
|
||||
then :
|
||||
printf "%s\n" "#define HAVE_EVP_MAC_CTX_NEW 1" >>confdefs.h
|
||||
|
||||
fi
|
||||
|
||||
|
||||
# these check_funcs need -lssl
|
||||
|
||||
+1
-1
@@ -999,7 +999,7 @@ else
|
||||
AC_MSG_RESULT([no])
|
||||
fi
|
||||
AC_CHECK_HEADERS([openssl/conf.h openssl/engine.h openssl/bn.h openssl/dh.h openssl/dsa.h openssl/rsa.h openssl/core_names.h openssl/param_build.h],,, [AC_INCLUDES_DEFAULT])
|
||||
AC_CHECK_FUNCS([OPENSSL_config EVP_sha1 EVP_sha256 EVP_sha512 FIPS_mode EVP_default_properties_is_fips_enabled EVP_MD_CTX_new OpenSSL_add_all_digests OPENSSL_init_crypto EVP_cleanup ENGINE_cleanup ERR_load_crypto_strings CRYPTO_cleanup_all_ex_data ERR_free_strings RAND_cleanup DSA_SIG_set0 EVP_dss1 EVP_DigestVerify EVP_aes_256_cbc EVP_EncryptInit_ex HMAC_Init_ex CRYPTO_THREADID_set_callback EVP_MAC_CTX_set_params OSSL_PARAM_BLD_new BIO_set_callback_ex])
|
||||
AC_CHECK_FUNCS([OPENSSL_config EVP_sha1 EVP_sha256 EVP_sha512 FIPS_mode EVP_default_properties_is_fips_enabled EVP_MD_CTX_new OpenSSL_add_all_digests OPENSSL_init_crypto EVP_cleanup ENGINE_cleanup ERR_load_crypto_strings CRYPTO_cleanup_all_ex_data ERR_free_strings RAND_cleanup DSA_SIG_set0 EVP_dss1 EVP_DigestVerify EVP_aes_256_cbc EVP_EncryptInit_ex HMAC_Init_ex CRYPTO_THREADID_set_callback EVP_MAC_CTX_set_params OSSL_PARAM_BLD_new BIO_set_callback_ex SSL_CTX_set_tmp_ecdh HMAC_CTX_new EVP_MAC_CTX_new])
|
||||
|
||||
# these check_funcs need -lssl
|
||||
BAKLIBS="$LIBS"
|
||||
|
||||
+19
-1
@@ -89,6 +89,7 @@
|
||||
#include "util/random.h"
|
||||
#include "util/tube.h"
|
||||
#include "util/net_help.h"
|
||||
#include "util/tsig.h"
|
||||
#include "sldns/keyraw.h"
|
||||
#include "respip/respip.h"
|
||||
#include "iterator/iter_fwd.h"
|
||||
@@ -320,6 +321,17 @@ daemon_init(void)
|
||||
free(daemon);
|
||||
return NULL;
|
||||
}
|
||||
if(!(daemon->env->tsig_key_table = tsig_key_table_create())) {
|
||||
auth_zones_delete(daemon->env->auth_zones);
|
||||
acl_list_delete(daemon->acl_interface);
|
||||
acl_list_delete(daemon->acl);
|
||||
tcl_list_delete(daemon->tcl);
|
||||
edns_known_options_delete(daemon->env);
|
||||
edns_strings_delete(daemon->env->edns_strings);
|
||||
free(daemon->env);
|
||||
free(daemon);
|
||||
return NULL;
|
||||
}
|
||||
return daemon;
|
||||
}
|
||||
|
||||
@@ -771,12 +783,17 @@ daemon_fork(struct daemon* daemon)
|
||||
daemon->use_response_ip = !respip_set_is_empty(
|
||||
daemon->env->respip_set) || have_view_respip_cfg;
|
||||
|
||||
/* setup tsig keys */
|
||||
if(!tsig_key_table_apply_cfg(daemon->env->tsig_key_table, daemon->cfg))
|
||||
fatal_exit("Could not set up TSIG keys");
|
||||
|
||||
/* setup modules */
|
||||
daemon_setup_modules(daemon);
|
||||
|
||||
/* read auth zonefiles */
|
||||
if(!auth_zones_apply_cfg(daemon->env->auth_zones, daemon->cfg, 1,
|
||||
&daemon->use_rpz, daemon->env, &daemon->mods))
|
||||
&daemon->use_rpz, daemon->env, &daemon->mods,
|
||||
daemon->env->tsig_key_table))
|
||||
fatal_exit("auth_zones could not be setup");
|
||||
|
||||
/* Set-up EDNS strings */
|
||||
@@ -944,6 +961,7 @@ daemon_delete(struct daemon* daemon)
|
||||
edns_known_options_delete(daemon->env);
|
||||
edns_strings_delete(daemon->env->edns_strings);
|
||||
auth_zones_delete(daemon->env->auth_zones);
|
||||
tsig_key_table_delete(daemon->env->tsig_key_table);
|
||||
}
|
||||
ub_randfree(daemon->rand);
|
||||
alloc_clear(&daemon->superalloc);
|
||||
|
||||
+31
-1
@@ -98,6 +98,7 @@
|
||||
#include "util/timeval_func.h"
|
||||
#include "util/tcp_conn_limit.h"
|
||||
#include "util/edns.h"
|
||||
#include "util/tsig.h"
|
||||
#ifdef USE_CACHEDB
|
||||
#include "cachedb/cachedb.h"
|
||||
#endif
|
||||
@@ -4645,6 +4646,8 @@ struct fast_reload_construct {
|
||||
struct acl_list* acl_interface;
|
||||
/** construct for tcp connection limit */
|
||||
struct tcl_list* tcl;
|
||||
/** tsig key table */
|
||||
struct tsig_key_table* tsig_key_table;
|
||||
/** construct for local zones */
|
||||
struct local_zones* local_zones;
|
||||
/** if there is response ip configuration in use */
|
||||
@@ -5031,6 +5034,7 @@ fr_construct_clear(struct fast_reload_construct* ct)
|
||||
acl_list_delete(ct->acl);
|
||||
acl_list_delete(ct->acl_interface);
|
||||
tcl_list_delete(ct->tcl);
|
||||
tsig_key_table_delete(ct->tsig_key_table);
|
||||
edns_strings_delete(ct->edns_strings);
|
||||
anchors_delete(ct->anchors);
|
||||
views_delete(ct->views);
|
||||
@@ -5133,6 +5137,8 @@ getmem_config_auth(struct config_auth* p)
|
||||
+ getmem_config_strlist(s->masters)
|
||||
+ getmem_config_strlist(s->urls)
|
||||
+ getmem_config_strlist(s->allow_notify)
|
||||
+ getmem_config_str2list(s->masters_tsig)
|
||||
+ getmem_config_str2list(s->allow_notify_tsig)
|
||||
+ getmem_str(s->zonefile)
|
||||
+ s->rpz_taglistlen
|
||||
+ getmem_str(s->rpz_action_override)
|
||||
@@ -5296,6 +5302,7 @@ fr_printmem(struct fast_reload_thread* fr,
|
||||
mem += auth_zones_get_mem(ct->auth_zones);
|
||||
mem += forwards_get_mem(ct->fwds);
|
||||
mem += hints_get_mem(ct->hints);
|
||||
mem += tsig_key_table_get_mem(ct->tsig_key_table);
|
||||
mem += local_zones_get_mem(ct->local_zones);
|
||||
mem += acl_list_get_mem(ct->acl);
|
||||
mem += acl_list_get_mem(ct->acl_interface);
|
||||
@@ -5384,6 +5391,12 @@ xfr_auth_master_equal(struct auth_master* m1, struct auth_master* m2)
|
||||
return 0;
|
||||
if(m1->port != m2->port)
|
||||
return 0;
|
||||
|
||||
if((m1->tsig_key_name && !m2->tsig_key_name) || (!m1->tsig_key_name && m2->tsig_key_name))
|
||||
return 0;
|
||||
if(m1->tsig_key_name && m2->tsig_key_name && strcmp(m1->tsig_key_name, m2->tsig_key_name) != 0)
|
||||
return 0;
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -5583,12 +5596,24 @@ fr_construct_from_config(struct fast_reload_thread* fr,
|
||||
if(fr_poll_for_quit(fr))
|
||||
return 1;
|
||||
|
||||
if(!(ct->tsig_key_table = tsig_key_table_create())) {
|
||||
fr_construct_clear(ct);
|
||||
return 0;
|
||||
}
|
||||
if(!tsig_key_table_apply_cfg(ct->tsig_key_table, newcfg)) {
|
||||
fr_construct_clear(ct);
|
||||
return 0;
|
||||
}
|
||||
if(fr_poll_for_quit(fr))
|
||||
return 1;
|
||||
|
||||
if(!(ct->auth_zones = auth_zones_create())) {
|
||||
fr_construct_clear(ct);
|
||||
return 0;
|
||||
}
|
||||
if(!auth_zones_apply_cfg(ct->auth_zones, newcfg, 1, &ct->use_rpz,
|
||||
fr->worker->daemon->env, &fr->worker->daemon->mods)) {
|
||||
fr->worker->daemon->env, &fr->worker->daemon->mods,
|
||||
ct->tsig_key_table)) {
|
||||
fr_construct_clear(ct);
|
||||
return 0;
|
||||
}
|
||||
@@ -5918,6 +5943,7 @@ fr_atomic_copy_cfg(struct config_file* oldcfg, struct config_file* cfg,
|
||||
COPY_VAR_ptr(forwards);
|
||||
COPY_VAR_ptr(auths);
|
||||
COPY_VAR_ptr(views);
|
||||
COPY_VAR_ptr(tsig_keys);
|
||||
COPY_VAR_ptr(donotqueryaddrs);
|
||||
#ifdef CLIENT_SUBNET
|
||||
COPY_VAR_ptr(client_subnet);
|
||||
@@ -6355,6 +6381,7 @@ fr_reload_config(struct fast_reload_thread* fr, struct config_file* newcfg,
|
||||
lock_basic_lock(&ct->anchors->lock);
|
||||
lock_basic_lock(&env->anchors->lock);
|
||||
}
|
||||
lock_rw_wrlock(&env->tsig_key_table->lock);
|
||||
|
||||
#if defined(ATOMIC_POINTER_LOCK_FREE) && defined(HAVE_LINK_ATOMIC_STORE)
|
||||
if(fr->fr_nopause) {
|
||||
@@ -6391,6 +6418,8 @@ fr_reload_config(struct fast_reload_thread* fr, struct config_file* newcfg,
|
||||
acl_list_swap_tree(daemon->acl, ct->acl);
|
||||
acl_list_swap_tree(daemon->acl_interface, ct->acl_interface);
|
||||
tcl_list_swap_tree(daemon->tcl, ct->tcl);
|
||||
tsig_key_table_swap_tree(daemon->env->tsig_key_table,
|
||||
ct->tsig_key_table);
|
||||
local_zones_swap_tree(daemon->local_zones, ct->local_zones);
|
||||
respip_set_swap_tree(env->respip_set, ct->respip_set);
|
||||
daemon->use_response_ip = ct->use_response_ip;
|
||||
@@ -6437,6 +6466,7 @@ fr_reload_config(struct fast_reload_thread* fr, struct config_file* newcfg,
|
||||
lock_basic_unlock(&ct->anchors->lock);
|
||||
lock_basic_unlock(&env->anchors->lock);
|
||||
}
|
||||
lock_rw_unlock(&env->tsig_key_table->lock);
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
+51
-13
@@ -67,6 +67,7 @@
|
||||
#include "util/data/dname.h"
|
||||
#include "util/fptr_wlist.h"
|
||||
#include "util/proxy_protocol.h"
|
||||
#include "util/tsig.h"
|
||||
#include "util/tube.h"
|
||||
#include "util/edns.h"
|
||||
#include "util/timeval_func.h"
|
||||
@@ -1157,35 +1158,54 @@ answer_notify(struct worker* w, struct query_info* qinfo,
|
||||
int rcode = LDNS_RCODE_NOERROR;
|
||||
uint32_t serial = 0;
|
||||
int has_serial;
|
||||
struct tsig_data* tsig = NULL;
|
||||
int tsig_rcode = 0;
|
||||
if(!w->env.auth_zones) return;
|
||||
has_serial = auth_zone_parse_notify_serial(pkt, &serial);
|
||||
if(auth_zones_notify(w->env.auth_zones, &w->env, qinfo->qname,
|
||||
qinfo->qname_len, qinfo->qclass, addr,
|
||||
addrlen, has_serial, serial, &refused)) {
|
||||
qinfo->qname_len, qinfo->qclass, addr, addrlen, has_serial,
|
||||
serial, &refused, pkt, &tsig, &tsig_rcode, w->scratchpad)) {
|
||||
rcode = LDNS_RCODE_NOERROR;
|
||||
} else {
|
||||
if(refused)
|
||||
if(tsig_rcode != 0) {
|
||||
rcode = tsig_rcode;
|
||||
} else if(refused) {
|
||||
rcode = LDNS_RCODE_REFUSED;
|
||||
else rcode = LDNS_RCODE_SERVFAIL;
|
||||
} else {
|
||||
rcode = LDNS_RCODE_SERVFAIL;
|
||||
}
|
||||
}
|
||||
|
||||
if(verbosity >= VERB_DETAIL) {
|
||||
char buf[380];
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
char sr[25];
|
||||
char buf[380+LDNS_MAX_DOMAINLEN];
|
||||
char zname[LDNS_MAX_DOMAINLEN], tsigkey[LDNS_MAX_DOMAINLEN];
|
||||
char sr[25], rcode_str[32], tsigtxt[16];;
|
||||
dname_str(qinfo->qname, zname);
|
||||
tsigkey[0]=0;
|
||||
tsigtxt[0]=0;
|
||||
if(tsig && tsig->key_name) {
|
||||
snprintf(tsigtxt, sizeof(tsigtxt), " with TSIG ");
|
||||
dname_str(tsig->key_name, tsigkey);
|
||||
}
|
||||
sr[0]=0;
|
||||
if(has_serial)
|
||||
snprintf(sr, sizeof(sr), "serial %u ",
|
||||
(unsigned)serial);
|
||||
if(rcode == LDNS_RCODE_REFUSED)
|
||||
if(rcode == LDNS_RCODE_REFUSED) {
|
||||
snprintf(buf, sizeof(buf),
|
||||
"refused NOTIFY %sfor %s from", sr, zname);
|
||||
else if(rcode == LDNS_RCODE_SERVFAIL)
|
||||
"refused NOTIFY %sfor %s%s%s from", sr, zname,
|
||||
tsigtxt, tsigkey);
|
||||
} else if(rcode != LDNS_RCODE_NOERROR) {
|
||||
sldns_wire2str_rcode_buf(rcode, rcode_str,
|
||||
sizeof(rcode_str));
|
||||
snprintf(buf, sizeof(buf),
|
||||
"servfail for NOTIFY %sfor %s from", sr, zname);
|
||||
else snprintf(buf, sizeof(buf),
|
||||
"received NOTIFY %sfor %s from", sr, zname);
|
||||
"%s for NOTIFY %sfor %s%s%s from",
|
||||
rcode_str, sr, zname, tsigtxt, tsigkey);
|
||||
} else {
|
||||
snprintf(buf, sizeof(buf),
|
||||
"received NOTIFY %sfor %s%s%s from", sr, zname,
|
||||
tsigtxt, tsigkey);
|
||||
}
|
||||
log_addr(VERB_DETAIL, buf, addr, addrlen);
|
||||
}
|
||||
edns->edns_version = EDNS_ADVERTISED_VERSION;
|
||||
@@ -1196,6 +1216,24 @@ answer_notify(struct worker* w, struct query_info* qinfo,
|
||||
*(uint16_t*)(void *)sldns_buffer_begin(pkt),
|
||||
sldns_buffer_read_u16_at(pkt, 2), edns);
|
||||
LDNS_OPCODE_SET(sldns_buffer_begin(pkt), LDNS_PACKET_NOTIFY);
|
||||
if(tsig) {
|
||||
size_t pos = sldns_buffer_limit(pkt);
|
||||
sldns_buffer_clear(pkt);
|
||||
sldns_buffer_set_position(pkt, pos);
|
||||
if(!tsig_sign_reply(tsig, pkt, w->env.tsig_key_table,
|
||||
(uint64_t)*w->env.now)) {
|
||||
/* Failed to TSIG sign the reply */
|
||||
verbose(VERB_ALGO, "Failed to TSIG sign notify reply");
|
||||
error_encode(pkt, LDNS_RCODE_SERVFAIL, qinfo,
|
||||
*(uint16_t*)(void *)sldns_buffer_begin(pkt),
|
||||
sldns_buffer_read_u16_at(pkt, 2), edns);
|
||||
LDNS_OPCODE_SET(sldns_buffer_begin(pkt), LDNS_PACKET_NOTIFY);
|
||||
} else {
|
||||
/* Flip to delimit buffer after tsig_sign_reply. */
|
||||
sldns_buffer_flip(pkt);
|
||||
}
|
||||
/* The tsig veriable is allocated in the scratch region. */
|
||||
}
|
||||
}
|
||||
|
||||
static int
|
||||
|
||||
+14
-1
@@ -1235,7 +1235,8 @@ remote-control:
|
||||
# authoritatively. zonefile: reads from file (and writes to it if you also
|
||||
# download it), primary: fetches with AXFR and IXFR, or url to zonefile.
|
||||
# With allow-notify: you can give additional (apart from primaries and urls)
|
||||
# sources of notifies.
|
||||
# sources of notifies. primary-tsig: and allow-notify-tsig: use addr keyname,
|
||||
# with the name of the TSIG key to use, declared as a tsig-key:.
|
||||
# auth-zone:
|
||||
# name: "."
|
||||
# primary: 170.247.170.2 # b.root-servers.net
|
||||
@@ -1414,6 +1415,7 @@ remote-control:
|
||||
# and drop. Policies can be loaded from a file, or using zone
|
||||
# transfer, or using HTTP. The respip module needs to be added
|
||||
# to the module-config, e.g.: module-config: "respip validator iterator".
|
||||
# Can also use primary-tsig: and allow-notify-tsig:
|
||||
# rpz:
|
||||
# name: "rpz.example.com"
|
||||
# zonefile: "rpz.example.com"
|
||||
@@ -1427,3 +1429,14 @@ remote-control:
|
||||
# rpz-signal-nxdomain-ra: no
|
||||
# for-downstream: no
|
||||
# tags: "example"
|
||||
|
||||
# TSIG keys
|
||||
# tsig-key:
|
||||
# # The key name is sent to the other party, it must be the same
|
||||
# name: "keyname"
|
||||
# # algorithm hmac-md5, or sha1, sha256, sha224, sha384, sha512
|
||||
# algorithm: sha256
|
||||
# # secret material, must be the same as the other party uses.
|
||||
# # base64 encoded random number.
|
||||
# # e.g. from dd if=/dev/random of=/dev/stdout count=1 bs=32 | base64
|
||||
# secret: "K2tf3TRjvQkVCmJF3/Z9vA=="
|
||||
|
||||
@@ -150,6 +150,7 @@ There are several commands that the server understands.
|
||||
:ref:`trusted-keys-file<unbound.conf.trusted-keys-file>`,
|
||||
:ref:`auto-trust-anchor-file<unbound.conf.auto-trust-anchor-file>`,
|
||||
:ref:`edns-client-string<unbound.conf.edns-client-string>`,
|
||||
:ref:`tsig-key<unbound.conf.tsig-key>`,
|
||||
ipset,
|
||||
:ref:`log-identity<unbound.conf.log-identity>`,
|
||||
:ref:`infra-cache-numhosts<unbound.conf.infra-cache-numhosts>`,
|
||||
|
||||
@@ -3713,6 +3713,12 @@ fallback activates to fetch from the upstream instead of the SERVFAIL.
|
||||
Alternate syntax for :ref:`primary<unbound.conf.auth.primary>`.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.auth@primary-tsig@@: *<IP address or host name>* *<tsig key>*
|
||||
Similar to :ref:`primary<unbound.conf.auth.primary>` and the tsig key
|
||||
is used for TSIG.
|
||||
The key name is from a :ref:`tsig-key<unbound.conf.tsig-key>` entry.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.auth@url@@: *<URL to zone file>*
|
||||
Where to download a zonefile for the zone.
|
||||
With HTTP or HTTPS.
|
||||
@@ -3759,6 +3765,12 @@ fallback activates to fetch from the upstream instead of the SERVFAIL.
|
||||
default.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.auth@allow-notify-tsig@@: *<IP address or host name or netblockIP/prefix>* *<tsig key>*
|
||||
Similar to :ref:`allow-notify<unbound.conf.auth.allow-notify>` and the
|
||||
tsig key is used for TSIG.
|
||||
The key name is from a :ref:`tsig-key<unbound.conf.tsig-key>` entry.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.auth@fallback-enabled@@: *<yes or no>*
|
||||
If enabled, Unbound falls back to querying the internet as a resolver for
|
||||
this zone when lookups fail.
|
||||
@@ -4862,6 +4874,12 @@ The RPZ zones can be configured in the config file with these settings in the
|
||||
Alternate syntax for :ref:`primary<unbound.conf.rpz.primary>`.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.rpz@primary-tsig@@: *<IP address or host name>* *<tsig key>*
|
||||
Similar to :ref:`primary<unbound.conf.rpz.primary>` and the tsig key
|
||||
is used for TSIG.
|
||||
The key name is from a :ref:`tsig-key<unbound.conf.tsig-key>` entry.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.rpz@url@@: *<url to zonefile>*
|
||||
Where to download a zonefile for the zone.
|
||||
With HTTP or HTTPS.
|
||||
@@ -4899,6 +4917,12 @@ The RPZ zones can be configured in the config file with these settings in the
|
||||
default.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.rpz@allow-notify-tsig@@: *<IP address or host name or netblockIP/prefix>* *<tsig key>*
|
||||
Similar to :ref:`allow-notify<unbound.conf.rpz.allow-notify>` and the
|
||||
tsig key is used for TSIG.
|
||||
The key name is from a :ref:`tsig-key<unbound.conf.tsig-key>` entry.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.rpz@zonefile@@: *<filename>*
|
||||
The filename where the zone is stored.
|
||||
If not given then no zonefile is used.
|
||||
@@ -4957,6 +4981,42 @@ The RPZ zones can be configured in the config file with these settings in the
|
||||
If no tags are specified the policies from this clause will be applied for
|
||||
all clients.
|
||||
|
||||
.. _unbound.conf.tsig-key:
|
||||
|
||||
TSIG Key Options
|
||||
^^^^^^^^^^^^^^^^^
|
||||
|
||||
The **tsig-key:** clauses specify the TSIG keys that are used.
|
||||
There can be multiple **tsig-key:** clauses, with each specifying a
|
||||
different key.
|
||||
Each key has a name, algorithm and secret key material.
|
||||
|
||||
TSIG keys are shared secrets.
|
||||
Both sides of the connection share the secret information.
|
||||
Also they must both use the same name for the key, and same algorithm.
|
||||
|
||||
With ``include: "key.conf"`` it is possible to put the declaration of the key
|
||||
or some lines of it in an external file from the main configuration file.
|
||||
It can also be used without such an include, with it the config statements
|
||||
and key material can be put in separate files.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.tsig-key@name@@: *"<key name>"*
|
||||
Name of the TSIG key.
|
||||
The key name is transferred in DNS wireformat in the TSIG record, and
|
||||
is used to reference the TSIG key from where it is configured to be used.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.tsig-key@algorithm@@: *<algorithm name>*
|
||||
Name of the algorithm to use with this TSIG key.
|
||||
This can be md5, sha1, sha224, sha256, sha384 or sha512.
|
||||
|
||||
|
||||
@@UAHL@unbound.conf.tsig-key@secret@@: *"<base64 blob>"*
|
||||
The secret contents is a base64 string.
|
||||
A way to get random base64 bytes is e.g.
|
||||
from ``dd if=/dev/random of=/dev/stdout count=1 bs=32 | base64``
|
||||
|
||||
Memory Control Example
|
||||
----------------------
|
||||
|
||||
|
||||
@@ -52,6 +52,7 @@
|
||||
#include "util/data/msgreply.h"
|
||||
#include "util/storage/slabhash.h"
|
||||
#include "util/edns.h"
|
||||
#include "util/tsig.h"
|
||||
#include "sldns/sbuffer.h"
|
||||
#include "iterator/iter_fwd.h"
|
||||
#include "iterator/iter_hints.h"
|
||||
@@ -81,13 +82,15 @@ context_finalize(struct ub_ctx* ctx)
|
||||
return UB_INITFAIL;
|
||||
listen_setup_locks();
|
||||
log_edns_known_options(VERB_ALGO, ctx->env);
|
||||
if(!tsig_key_table_apply_cfg(ctx->env->tsig_key_table, cfg))
|
||||
return UB_INITFAIL;
|
||||
ctx->local_zones = local_zones_create();
|
||||
if(!ctx->local_zones)
|
||||
return UB_NOMEM;
|
||||
if(!local_zones_apply_cfg(ctx->local_zones, cfg))
|
||||
return UB_INITFAIL;
|
||||
if(!auth_zones_apply_cfg(ctx->env->auth_zones, cfg, 1, &is_rpz,
|
||||
ctx->env, &ctx->mods))
|
||||
ctx->env, &ctx->mods, ctx->env->tsig_key_table))
|
||||
return UB_INITFAIL;
|
||||
if(!(ctx->env->fwds = forwards_create()) ||
|
||||
!forwards_apply_cfg(ctx->env->fwds, cfg))
|
||||
|
||||
@@ -59,6 +59,7 @@
|
||||
#include "util/tube.h"
|
||||
#include "util/ub_event.h"
|
||||
#include "util/edns.h"
|
||||
#include "util/tsig.h"
|
||||
#include "services/modstack.h"
|
||||
#include "services/localzone.h"
|
||||
#include "services/cache/infra.h"
|
||||
@@ -168,6 +169,18 @@ static struct ub_ctx* ub_ctx_create_nopipe(void)
|
||||
errno = ENOMEM;
|
||||
return NULL;
|
||||
}
|
||||
ctx->env->tsig_key_table = tsig_key_table_create();
|
||||
if(!ctx->env->tsig_key_table) {
|
||||
auth_zones_delete(ctx->env->auth_zones);
|
||||
edns_known_options_delete(ctx->env);
|
||||
edns_strings_delete(ctx->env->edns_strings);
|
||||
config_delete(ctx->env->cfg);
|
||||
free(ctx->env);
|
||||
ub_randfree(ctx->seed_rnd);
|
||||
free(ctx);
|
||||
errno = ENOMEM;
|
||||
return NULL;
|
||||
}
|
||||
|
||||
ctx->env->alloc = &ctx->superalloc;
|
||||
ctx->env->worker = NULL;
|
||||
@@ -388,6 +401,7 @@ ub_ctx_delete(struct ub_ctx* ctx)
|
||||
config_delete(ctx->env->cfg);
|
||||
edns_known_options_delete(ctx->env);
|
||||
edns_strings_delete(ctx->env->edns_strings);
|
||||
tsig_key_table_delete(ctx->env->tsig_key_table);
|
||||
forwards_delete(ctx->env->fwds);
|
||||
hints_delete(ctx->env->hints);
|
||||
auth_zones_delete(ctx->env->auth_zones);
|
||||
|
||||
+285
-29
@@ -55,6 +55,7 @@
|
||||
#include "util/log.h"
|
||||
#include "util/module.h"
|
||||
#include "util/random.h"
|
||||
#include "util/tsig.h"
|
||||
#include "services/cache/dns.h"
|
||||
#include "services/outside_network.h"
|
||||
#include "services/listen_dnsport.h"
|
||||
@@ -2091,7 +2092,8 @@ auth_zones_setup_zones(struct auth_zones* az)
|
||||
|
||||
/** set config items and create zones */
|
||||
static int
|
||||
auth_zones_cfg(struct auth_zones* az, struct config_auth* c)
|
||||
auth_zones_cfg(struct auth_zones* az, struct config_auth* c,
|
||||
struct tsig_key_table* tsig_key_table)
|
||||
{
|
||||
struct auth_zone* z;
|
||||
struct auth_xfer* x = NULL;
|
||||
@@ -2110,7 +2112,7 @@ auth_zones_cfg(struct auth_zones* az, struct config_auth* c)
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
if(c->masters || c->urls) {
|
||||
if(c->masters || c->masters_tsig || c->urls) {
|
||||
if(!(x=auth_zones_find_or_add_xfer(az, z))) {
|
||||
lock_rw_unlock(&az->lock);
|
||||
lock_rw_unlock(&z->lock);
|
||||
@@ -2171,12 +2173,14 @@ auth_zones_cfg(struct auth_zones* az, struct config_auth* c)
|
||||
if(x) {
|
||||
z->zone_is_slave = 1;
|
||||
/* set options on xfer zone */
|
||||
if(!xfer_set_masters(&x->task_probe->masters, c, 0)) {
|
||||
if(!xfer_set_masters(&x->task_probe->masters, c, 0,
|
||||
tsig_key_table)) {
|
||||
lock_basic_unlock(&x->lock);
|
||||
lock_rw_unlock(&z->lock);
|
||||
return 0;
|
||||
}
|
||||
if(!xfer_set_masters(&x->task_transfer->masters, c, 1)) {
|
||||
if(!xfer_set_masters(&x->task_transfer->masters, c, 1,
|
||||
tsig_key_table)) {
|
||||
lock_basic_unlock(&x->lock);
|
||||
lock_rw_unlock(&z->lock);
|
||||
return 0;
|
||||
@@ -2244,7 +2248,7 @@ az_delete_deleted_zones(struct auth_zones* az)
|
||||
|
||||
int auth_zones_apply_cfg(struct auth_zones* az, struct config_file* cfg,
|
||||
int setup, int* is_rpz, struct module_env* env,
|
||||
struct module_stack* mods)
|
||||
struct module_stack* mods, struct tsig_key_table* tsig_key_table)
|
||||
{
|
||||
struct config_auth* p;
|
||||
az_setall_deleted(az);
|
||||
@@ -2254,7 +2258,7 @@ int auth_zones_apply_cfg(struct auth_zones* az, struct config_file* cfg,
|
||||
continue;
|
||||
}
|
||||
*is_rpz = (*is_rpz || p->isrpz);
|
||||
if(!auth_zones_cfg(az, p)) {
|
||||
if(!auth_zones_cfg(az, p, tsig_key_table)) {
|
||||
log_err("cannot config auth zone %s", p->name);
|
||||
return 0;
|
||||
}
|
||||
@@ -2312,6 +2316,7 @@ auth_free_masters(struct auth_master* list)
|
||||
auth_free_master_addrs(list->list);
|
||||
free(list->host);
|
||||
free(list->file);
|
||||
free(list->tsig_key_name);
|
||||
free(list);
|
||||
list = n;
|
||||
}
|
||||
@@ -2331,12 +2336,14 @@ auth_xfer_delete(struct auth_xfer* xfr)
|
||||
auth_free_masters(xfr->task_probe->masters);
|
||||
comm_point_delete(xfr->task_probe->cp);
|
||||
comm_timer_delete(xfr->task_probe->timer);
|
||||
tsig_delete(xfr->task_probe->tsig);
|
||||
free(xfr->task_probe);
|
||||
}
|
||||
if(xfr->task_transfer) {
|
||||
auth_free_masters(xfr->task_transfer->masters);
|
||||
comm_point_delete(xfr->task_transfer->cp);
|
||||
comm_timer_delete(xfr->task_transfer->timer);
|
||||
tsig_delete(xfr->task_transfer->tsig);
|
||||
if(xfr->task_transfer->chunks_first) {
|
||||
auth_chunks_delete(xfr->task_transfer);
|
||||
}
|
||||
@@ -3718,11 +3725,30 @@ addr_in_list(struct auth_addr* list, struct sockaddr_storage* addr,
|
||||
* addresses in the addr list) */
|
||||
static int
|
||||
addr_matches_master(struct auth_master* master, struct sockaddr_storage* addr,
|
||||
socklen_t addrlen, struct auth_master** fromhost)
|
||||
socklen_t addrlen, struct auth_master** fromhost,
|
||||
struct tsig_data* tsig)
|
||||
{
|
||||
struct sockaddr_storage a;
|
||||
socklen_t alen = 0;
|
||||
int net = 0;
|
||||
if(master->tsig_key_name && master->tsig_key_name[0]) {
|
||||
uint8_t keyname[LDNS_MAX_DOMAINLEN+1];
|
||||
size_t keynamelen = sizeof(keyname);
|
||||
if(!tsig) {
|
||||
/* This needs a TSIG key, but no TSIG present. */
|
||||
return 0;
|
||||
}
|
||||
if(sldns_str2wire_dname_buf(master->tsig_key_name, keyname,
|
||||
&keynamelen) != 0) {
|
||||
verbose(VERB_ALGO, "could not parse allow-notify-tsig '%s'",
|
||||
master->tsig_key_name);
|
||||
return 0;
|
||||
}
|
||||
if(query_dname_compare(keyname, tsig->key_name) != 0) {
|
||||
/* The TSIG is a different key name, not matched. */
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
if(addr_in_list(master->list, addr, addrlen)) {
|
||||
*fromhost = master;
|
||||
return 1;
|
||||
@@ -3755,11 +3781,12 @@ addr_matches_master(struct auth_master* master, struct sockaddr_storage* addr,
|
||||
/** check access list for notifies */
|
||||
static int
|
||||
az_xfr_allowed_notify(struct auth_xfer* xfr, struct sockaddr_storage* addr,
|
||||
socklen_t addrlen, struct auth_master** fromhost)
|
||||
socklen_t addrlen, struct auth_master** fromhost,
|
||||
struct tsig_data* tsig)
|
||||
{
|
||||
struct auth_master* p;
|
||||
for(p=xfr->allow_notify_list; p; p=p->next) {
|
||||
if(addr_matches_master(p, addr, addrlen, fromhost)) {
|
||||
if(addr_matches_master(p, addr, addrlen, fromhost, tsig)) {
|
||||
return 1;
|
||||
}
|
||||
}
|
||||
@@ -3829,7 +3856,8 @@ xfr_process_notify(struct auth_xfer* xfr, struct module_env* env,
|
||||
int auth_zones_notify(struct auth_zones* az, struct module_env* env,
|
||||
uint8_t* nm, size_t nmlen, uint16_t dclass,
|
||||
struct sockaddr_storage* addr, socklen_t addrlen, int has_serial,
|
||||
uint32_t serial, int* refused)
|
||||
uint32_t serial, int* refused, struct sldns_buffer* pkt,
|
||||
struct tsig_data** tsig, int* tsig_rcode, struct regional* scratchpad)
|
||||
{
|
||||
struct auth_xfer* xfr;
|
||||
struct auth_master* fromhost = NULL;
|
||||
@@ -3844,9 +3872,20 @@ int auth_zones_notify(struct auth_zones* az, struct module_env* env,
|
||||
}
|
||||
lock_basic_lock(&xfr->lock);
|
||||
lock_rw_unlock(&az->lock);
|
||||
|
||||
|
||||
/* check tsig */
|
||||
if(tsig_in_packet(pkt)) {
|
||||
*tsig_rcode = tsig_parse_verify_query(env->tsig_key_table,
|
||||
pkt, tsig, scratchpad, (uint64_t)*env->now);
|
||||
if(*tsig_rcode != 0) {
|
||||
/* The tsig failed to verify. */
|
||||
lock_basic_unlock(&xfr->lock);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
|
||||
/* check access list for notifies */
|
||||
if(!az_xfr_allowed_notify(xfr, addr, addrlen, &fromhost)) {
|
||||
if(!az_xfr_allowed_notify(xfr, addr, addrlen, &fromhost, *tsig)) {
|
||||
lock_basic_unlock(&xfr->lock);
|
||||
/* notify not allowed, refuse the notify */
|
||||
*refused = 1;
|
||||
@@ -3978,9 +4017,20 @@ auth_master_copy(struct auth_master* o)
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
if(m->tsig_key_name) {
|
||||
m->tsig_key_name = strdup(m->tsig_key_name);
|
||||
if(!m->tsig_key_name) {
|
||||
free(m->file);
|
||||
free(m->host);
|
||||
free(m);
|
||||
log_err("malloc failure");
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
if(m->list) {
|
||||
m->list = auth_addr_list_copy(m->list);
|
||||
if(!m->list) {
|
||||
free(m->tsig_key_name);
|
||||
free(m->file);
|
||||
free(m->host);
|
||||
free(m);
|
||||
@@ -4240,6 +4290,37 @@ xfr_create_soa_probe_packet(struct auth_xfer* xfr, sldns_buffer* buf,
|
||||
sldns_buffer_write_u16_at(buf, 0, id);
|
||||
}
|
||||
|
||||
/** sign a query for xfr. */
|
||||
static int
|
||||
xfr_sign_query(struct tsig_data** tsig, sldns_buffer* pkt,
|
||||
struct module_env* env, char* tsig_key_name)
|
||||
{
|
||||
size_t pos;
|
||||
if(*tsig) {
|
||||
tsig_delete(*tsig);
|
||||
*tsig = NULL;
|
||||
}
|
||||
*tsig = tsig_create_fromstr(env->tsig_key_table, tsig_key_name);
|
||||
if(!*tsig) {
|
||||
log_err("tsig key '%s' not found or out of memory",
|
||||
tsig_key_name);
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Position the buffer after the packet contents. */
|
||||
pos = sldns_buffer_limit(pkt);
|
||||
sldns_buffer_clear(pkt);
|
||||
sldns_buffer_set_position(pkt, pos);
|
||||
if(!tsig_sign_query(*tsig, pkt, env->tsig_key_table,
|
||||
(uint64_t)*env->now)) {
|
||||
sldns_buffer_flip(pkt);
|
||||
log_err("tsig key '%s': could not sign query", tsig_key_name);
|
||||
return 0;
|
||||
}
|
||||
sldns_buffer_flip(pkt);
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** create IXFR/AXFR packet for xfr */
|
||||
static void
|
||||
xfr_create_ixfr_packet(struct auth_xfer* xfr, sldns_buffer* buf, uint16_t id,
|
||||
@@ -4298,7 +4379,7 @@ xfr_create_ixfr_packet(struct auth_xfer* xfr, sldns_buffer* buf, uint16_t id,
|
||||
/** check if returned packet is OK */
|
||||
static int
|
||||
check_packet_ok(sldns_buffer* pkt, uint16_t qtype, struct auth_xfer* xfr,
|
||||
uint32_t* serial)
|
||||
uint32_t* serial, struct module_env* env)
|
||||
{
|
||||
/* parse to see if packet worked, valid reply */
|
||||
|
||||
@@ -4372,6 +4453,20 @@ check_packet_ok(sldns_buffer* pkt, uint16_t qtype, struct auth_xfer* xfr,
|
||||
return 0;
|
||||
*serial = sldns_buffer_read_u32(pkt);
|
||||
}
|
||||
|
||||
if(xfr->task_probe->tsig) {
|
||||
/* There could be authority or additional RRs in the reply for the
|
||||
* SOA query, if so skip them by tsig_find_rr. */
|
||||
if(!tsig_find_rr(pkt)) {
|
||||
verbose(VERB_ALGO, "TSIG expected, but not found in reply");
|
||||
return 0;
|
||||
}
|
||||
if(!tsig_parse_verify_reply(xfr->task_probe->tsig, pkt,
|
||||
env->tsig_key_table, (uint64_t)*env->now)) {
|
||||
verbose(VERB_ALGO, "valid TSIG expected in SOA probe reply, but it was not valid");
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -5379,10 +5474,18 @@ xfr_process_chunk_list(struct auth_xfer* xfr, struct module_env* env,
|
||||
lock_rw_unlock(&z->lock);
|
||||
|
||||
if(verbosity >= VERB_QUERY && xfr->have_zone) {
|
||||
char zname[LDNS_MAX_DOMAINLEN];
|
||||
char zname[LDNS_MAX_DOMAINLEN], tsigtxt[16],
|
||||
tsigkey[LDNS_MAX_DOMAINLEN];
|
||||
tsigkey[0]=0;
|
||||
tsigtxt[0]=0;
|
||||
if(xfr->task_transfer->tsig &&
|
||||
xfr->task_transfer->tsig->key_name) {
|
||||
snprintf(tsigtxt, sizeof(tsigtxt), " with TSIG ");
|
||||
dname_str(xfr->task_transfer->tsig->key_name, tsigkey);
|
||||
}
|
||||
dname_str(xfr->name, zname);
|
||||
verbose(VERB_QUERY, "auth zone %s updated to serial %u", zname,
|
||||
(unsigned)xfr->serial);
|
||||
verbose(VERB_QUERY, "auth zone %s updated%s%s to serial %u",
|
||||
zname, tsigtxt, tsigkey, (unsigned)xfr->serial);
|
||||
}
|
||||
/* see if we need to write to a zonefile */
|
||||
xfr_write_after_update(xfr, env);
|
||||
@@ -5399,6 +5502,9 @@ xfr_transfer_disown(struct auth_xfer* xfr)
|
||||
/* remove the commpoint */
|
||||
comm_point_delete(xfr->task_transfer->cp);
|
||||
xfr->task_transfer->cp = NULL;
|
||||
/* remove the tsig data */
|
||||
tsig_delete(xfr->task_transfer->tsig);
|
||||
xfr->task_transfer->tsig = NULL;
|
||||
/* we don't own this item anymore */
|
||||
xfr->task_transfer->worker = NULL;
|
||||
xfr->task_transfer->env = NULL;
|
||||
@@ -5487,6 +5593,10 @@ xfr_transfer_init_fetch(struct auth_xfer* xfr, struct module_env* env)
|
||||
int timeout;
|
||||
if(!master) return 0;
|
||||
if(master->allow_notify) return 0; /* only for notify */
|
||||
if(xfr->task_transfer->tsig) {
|
||||
tsig_delete(xfr->task_transfer->tsig);
|
||||
xfr->task_transfer->tsig = NULL;
|
||||
}
|
||||
|
||||
/* get master addr */
|
||||
if(xfr->task_transfer->scan_addr) {
|
||||
@@ -5561,6 +5671,17 @@ xfr_transfer_init_fetch(struct auth_xfer* xfr, struct module_env* env)
|
||||
xfr->task_transfer->id = GET_RANDOM_ID(env->rnd);
|
||||
xfr_create_ixfr_packet(xfr, env->scratch_buffer,
|
||||
xfr->task_transfer->id, master);
|
||||
if(master->tsig_key_name) {
|
||||
if(!xfr_sign_query(&xfr->task_transfer->tsig,
|
||||
env->scratch_buffer, env, master->tsig_key_name)) {
|
||||
char zname[LDNS_MAX_DOMAINLEN], as[256];
|
||||
dname_str(xfr->name, zname);
|
||||
addr_port_to_str(&addr, addrlen, as, sizeof(as));
|
||||
verbose(VERB_ALGO, "failed to TSIG sign xfr "
|
||||
"for %s to %s", zname, as);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
|
||||
/* connect on fd */
|
||||
xfr->task_transfer->cp = outnet_comm_point_for_tcp(env->outnet,
|
||||
@@ -5577,11 +5698,20 @@ xfr_transfer_init_fetch(struct auth_xfer* xfr, struct module_env* env)
|
||||
}
|
||||
comm_timer_set(xfr->task_transfer->timer, &t);
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char zname[LDNS_MAX_DOMAINLEN], as[256];
|
||||
char zname[LDNS_MAX_DOMAINLEN], as[256], tsigtxt[16],
|
||||
tsigkey[LDNS_MAX_DOMAINLEN];
|
||||
tsigkey[0]=0;
|
||||
tsigtxt[0]=0;
|
||||
if(xfr->task_transfer->tsig &&
|
||||
xfr->task_transfer->tsig->key_name) {
|
||||
snprintf(tsigtxt, sizeof(tsigtxt), " with TSIG ");
|
||||
dname_str(xfr->task_transfer->tsig->key_name, tsigkey);
|
||||
}
|
||||
dname_str(xfr->name, zname);
|
||||
addr_port_to_str(&addr, addrlen, as, sizeof(as));
|
||||
verbose(VERB_ALGO, "auth zone %s transfer next %s fetch from %s started", zname,
|
||||
(xfr->task_transfer->on_ixfr?"IXFR":"AXFR"), as);
|
||||
verbose(VERB_ALGO, "auth zone %s transfer next %s fetch%s%s from %s started",
|
||||
zname, (xfr->task_transfer->on_ixfr?"IXFR":"AXFR"),
|
||||
tsigtxt, tsigkey, as);
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
@@ -5766,9 +5896,10 @@ void auth_xfer_transfer_lookup_callback(void* arg, int rcode, sldns_buffer* buf,
|
||||
*/
|
||||
static int
|
||||
check_xfer_packet(sldns_buffer* pkt, struct auth_xfer* xfr,
|
||||
int* gonextonfail, int* transferdone)
|
||||
struct module_env* env, int* gonextonfail, int* transferdone)
|
||||
{
|
||||
uint8_t* wire = sldns_buffer_begin(pkt);
|
||||
size_t initial_rr_scan_num = xfr->task_transfer->rr_scan_num;
|
||||
int i;
|
||||
if(sldns_buffer_limit(pkt) < LDNS_HEADER_SIZE) {
|
||||
verbose(VERB_ALGO, "xfr to %s failed, packet too small",
|
||||
@@ -6052,6 +6183,28 @@ check_xfer_packet(sldns_buffer* pkt, struct auth_xfer* xfr,
|
||||
sldns_buffer_skip(pkt, (ssize_t)rdlen);
|
||||
}
|
||||
|
||||
/* check tsig */
|
||||
if(xfr->task_transfer->tsig) {
|
||||
sldns_buffer_rewind(pkt);
|
||||
if(!tsig_find_rr(pkt)) {
|
||||
/* Check TSIG reply on first packet. */
|
||||
if(initial_rr_scan_num == 0) {
|
||||
verbose(VERB_ALGO, "TSIG expected, but not found in reply for xfr to %s",
|
||||
xfr->task_transfer->master->host);
|
||||
return 0;
|
||||
}
|
||||
/* No TSIG could be for sign every NTH packet. */
|
||||
sldns_buffer_set_position(pkt, sldns_buffer_limit(pkt));
|
||||
}
|
||||
if(!tsig_parse_verify_reply_xfr(xfr->task_transfer->tsig,
|
||||
pkt, env->tsig_key_table, (uint64_t)*env->now,
|
||||
*transferdone)) {
|
||||
verbose(VERB_ALGO, "valid TSIG expected in xfr reply to %s, but it was not valid",
|
||||
xfr->task_transfer->master->host);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -6228,7 +6381,8 @@ auth_xfer_transfer_tcp_callback(struct comm_point* c, void* arg, int err,
|
||||
/* handle returned packet */
|
||||
/* if it fails, cleanup and end this transfer */
|
||||
/* if it needs to fallback from IXFR to AXFR, do that */
|
||||
if(!check_xfer_packet(c->buffer, xfr, &gonextonfail, &transferdone)) {
|
||||
if(!check_xfer_packet(c->buffer, xfr, env, &gonextonfail,
|
||||
&transferdone)) {
|
||||
goto failed;
|
||||
}
|
||||
/* if it is good, link it into the list of data */
|
||||
@@ -6354,6 +6508,9 @@ xfr_probe_disown(struct auth_xfer* xfr)
|
||||
/* remove the commpoint */
|
||||
comm_point_delete(xfr->task_probe->cp);
|
||||
xfr->task_probe->cp = NULL;
|
||||
/* remove the tsig data */
|
||||
tsig_delete(xfr->task_probe->tsig);
|
||||
xfr->task_probe->tsig = NULL;
|
||||
/* we don't own this item anymore */
|
||||
xfr->task_probe->worker = NULL;
|
||||
xfr->task_probe->env = NULL;
|
||||
@@ -6374,6 +6531,10 @@ xfr_probe_send_probe(struct auth_xfer* xfr, struct module_env* env,
|
||||
if(master->allow_notify) return 0; /* only for notify */
|
||||
if(master->http) return 0; /* only masters get SOA UDP probe,
|
||||
not urls, if those are in this list */
|
||||
if(xfr->task_probe->tsig) {
|
||||
tsig_delete(xfr->task_probe->tsig);
|
||||
xfr->task_probe->tsig = NULL;
|
||||
}
|
||||
|
||||
/* get master addr */
|
||||
if(xfr->task_probe->scan_addr) {
|
||||
@@ -6411,6 +6572,17 @@ xfr_probe_send_probe(struct auth_xfer* xfr, struct module_env* env,
|
||||
xfr->task_probe->id = GET_RANDOM_ID(env->rnd);
|
||||
xfr_create_soa_probe_packet(xfr, env->scratch_buffer,
|
||||
xfr->task_probe->id);
|
||||
if(master->tsig_key_name) {
|
||||
if(!xfr_sign_query(&xfr->task_probe->tsig, env->scratch_buffer,
|
||||
env, master->tsig_key_name)) {
|
||||
char zname[LDNS_MAX_DOMAINLEN], as[256];
|
||||
dname_str(xfr->name, zname);
|
||||
addr_port_to_str(&addr, addrlen, as, sizeof(as));
|
||||
verbose(VERB_ALGO, "failed to TSIG sign soa probe "
|
||||
"for %s to %s", zname, as);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
/* we need to remove the cp if we have a different ip4/ip6 type now */
|
||||
if(xfr->task_probe->cp &&
|
||||
((xfr->task_probe->cp_is_ip6 && !addr_is_ip6(&addr, addrlen)) ||
|
||||
@@ -6454,11 +6626,19 @@ xfr_probe_send_probe(struct auth_xfer* xfr, struct module_env* env,
|
||||
return 0;
|
||||
}
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char zname[LDNS_MAX_DOMAINLEN], as[256];
|
||||
char zname[LDNS_MAX_DOMAINLEN], as[256], tsigtxt[16],
|
||||
tsigkey[LDNS_MAX_DOMAINLEN];
|
||||
tsigkey[0]=0;
|
||||
tsigtxt[0]=0;
|
||||
if(xfr->task_probe->tsig &&
|
||||
xfr->task_probe->tsig->key_name) {
|
||||
snprintf(tsigtxt, sizeof(tsigtxt), " with TSIG ");
|
||||
dname_str(xfr->task_probe->tsig->key_name, tsigkey);
|
||||
}
|
||||
dname_str(xfr->name, zname);
|
||||
addr_port_to_str(&addr, addrlen, as, sizeof(as));
|
||||
verbose(VERB_ALGO, "auth zone %s soa probe sent to %s", zname,
|
||||
as);
|
||||
verbose(VERB_ALGO, "auth zone %s soa probe%s%s sent to %s",
|
||||
zname, tsigtxt, tsigkey, as);
|
||||
}
|
||||
xfr->task_probe->timeout = timeout;
|
||||
#ifndef S_SPLINT_S
|
||||
@@ -6530,13 +6710,24 @@ auth_xfer_probe_udp_callback(struct comm_point* c, void* arg, int err,
|
||||
if(err == NETEVENT_NOERROR) {
|
||||
uint32_t serial = 0;
|
||||
if(check_packet_ok(c->buffer, LDNS_RR_TYPE_SOA, xfr,
|
||||
&serial)) {
|
||||
&serial, env)) {
|
||||
/* successful lookup */
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
char buf[LDNS_MAX_DOMAINLEN];
|
||||
char buf[LDNS_MAX_DOMAINLEN], tsigtxt[16],
|
||||
tsigkey[LDNS_MAX_DOMAINLEN];
|
||||
tsigkey[0]=0;
|
||||
tsigtxt[0]=0;
|
||||
if(xfr->task_probe->tsig &&
|
||||
xfr->task_probe->tsig->key_name) {
|
||||
snprintf(tsigtxt, sizeof(tsigtxt),
|
||||
" with TSIG ");
|
||||
dname_str(xfr->task_probe->tsig->
|
||||
key_name, tsigkey);
|
||||
}
|
||||
dname_str(xfr->name, buf);
|
||||
verbose(VERB_ALGO, "auth zone %s: soa probe "
|
||||
"serial is %u", buf, (unsigned)serial);
|
||||
verbose(VERB_ALGO, "auth zone %s: soa probe"
|
||||
"%s%s serial is %u", buf, tsigtxt,
|
||||
tsigkey, (unsigned)serial);
|
||||
}
|
||||
/* see if this serial indicates that the zone has
|
||||
* to be updated */
|
||||
@@ -6589,6 +6780,9 @@ auth_xfer_probe_udp_callback(struct comm_point* c, void* arg, int err,
|
||||
/* delete commpoint so a new one is created, with a fresh port nr */
|
||||
comm_point_delete(xfr->task_probe->cp);
|
||||
xfr->task_probe->cp = NULL;
|
||||
/* remove the tsig data */
|
||||
tsig_delete(xfr->task_probe->tsig);
|
||||
xfr->task_probe->tsig = NULL;
|
||||
|
||||
/* if the result was not a successful probe, we need
|
||||
* to send the next one */
|
||||
@@ -7294,12 +7488,34 @@ parse_url(char* url, char** host, char** file, int* port, int* ssl)
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** Check the tsig key exists */
|
||||
static int
|
||||
check_tsig_key_exists(struct tsig_key_table* tsig_key_table,
|
||||
const char* optname, char* str, char* str2)
|
||||
{
|
||||
struct tsig_key* key;
|
||||
if(!tsig_key_table)
|
||||
return 1;
|
||||
|
||||
lock_rw_rdlock(&tsig_key_table->lock);
|
||||
key = tsig_key_table_search_fromstr(tsig_key_table, str2);
|
||||
lock_rw_unlock(&tsig_key_table->lock);
|
||||
|
||||
if(!key) {
|
||||
log_err("could not find tsig-key for %s: %s %s",
|
||||
optname, str, str2);
|
||||
return 0;
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
int
|
||||
xfer_set_masters(struct auth_master** list, struct config_auth* c,
|
||||
int with_http)
|
||||
int with_http, struct tsig_key_table* tsig_key_table)
|
||||
{
|
||||
struct auth_master* m;
|
||||
struct config_strlist* p;
|
||||
struct config_str2list* p2;
|
||||
/* list points to the first, or next pointer for the new element */
|
||||
while(*list) {
|
||||
list = &( (*list)->next );
|
||||
@@ -7322,6 +7538,24 @@ xfer_set_masters(struct auth_master** list, struct config_auth* c,
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
for(p2 = c->masters_tsig; p2; p2 = p2->next) {
|
||||
m = auth_master_new(&list);
|
||||
if(!m) return 0;
|
||||
m->ixfr = 1; /* this flag is not configurable */
|
||||
m->host = strdup(p2->str);
|
||||
if(!m->host) {
|
||||
log_err("malloc failure");
|
||||
return 0;
|
||||
}
|
||||
if(!check_tsig_key_exists(tsig_key_table, "primary-tsig",
|
||||
p2->str, p2->str2))
|
||||
return 0;
|
||||
m->tsig_key_name = strdup(p2->str2);
|
||||
if(!m->tsig_key_name) {
|
||||
log_err("malloc failure");
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
for(p = c->allow_notify; p; p = p->next) {
|
||||
m = auth_master_new(&list);
|
||||
if(!m) return 0;
|
||||
@@ -7332,6 +7566,24 @@ xfer_set_masters(struct auth_master** list, struct config_auth* c,
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
for(p2 = c->allow_notify_tsig; p2; p2 = p2->next) {
|
||||
m = auth_master_new(&list);
|
||||
if(!m) return 0;
|
||||
m->allow_notify = 1;
|
||||
m->host = strdup(p2->str);
|
||||
if(!m->host) {
|
||||
log_err("malloc failure");
|
||||
return 0;
|
||||
}
|
||||
if(!check_tsig_key_exists(tsig_key_table, "allow-notify-tsig",
|
||||
p2->str, p2->str2))
|
||||
return 0;
|
||||
m->tsig_key_name = strdup(p2->str2);
|
||||
if(!m->tsig_key_name) {
|
||||
log_err("malloc failure");
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -8667,6 +8919,8 @@ auth_primaries_get_mem(struct auth_master* list)
|
||||
m += strlen(n->host)+1;
|
||||
if(n->file)
|
||||
m += strlen(n->file)+1;
|
||||
if(n->tsig_key_name)
|
||||
m += strlen(n->tsig_key_name)+1;
|
||||
}
|
||||
return m;
|
||||
}
|
||||
@@ -8696,12 +8950,14 @@ auth_xfer_get_mem(struct auth_xfer* xfr)
|
||||
m += auth_primaries_get_mem(xfr->task_probe->masters);
|
||||
m += comm_point_get_mem(xfr->task_probe->cp);
|
||||
m += comm_timer_get_mem(xfr->task_probe->timer);
|
||||
m += tsig_get_mem(xfr->task_probe->tsig);
|
||||
|
||||
/* auth_transfer */
|
||||
m += auth_chunks_get_mem(xfr->task_transfer->chunks_first);
|
||||
m += auth_primaries_get_mem(xfr->task_transfer->masters);
|
||||
m += comm_point_get_mem(xfr->task_transfer->cp);
|
||||
m += comm_timer_get_mem(xfr->task_transfer->timer);
|
||||
m += tsig_get_mem(xfr->task_transfer->tsig);
|
||||
|
||||
/* allow_notify_list */
|
||||
m += auth_primaries_get_mem(xfr->allow_notify_list);
|
||||
|
||||
+21
-3
@@ -55,6 +55,8 @@ struct query_info;
|
||||
struct dns_msg;
|
||||
struct edns_data;
|
||||
struct module_env;
|
||||
struct tsig_data;
|
||||
struct tsig_key_table;
|
||||
struct worker;
|
||||
struct comm_point;
|
||||
struct comm_timer;
|
||||
@@ -361,6 +363,8 @@ struct auth_probe {
|
||||
struct comm_timer* timer;
|
||||
/** timeout in msec */
|
||||
int timeout;
|
||||
/** the tsig data for the packet */
|
||||
struct tsig_data* tsig;
|
||||
};
|
||||
|
||||
/**
|
||||
@@ -430,6 +434,8 @@ struct auth_transfer {
|
||||
/** timeout for the transfer.
|
||||
* on the workers event base. */
|
||||
struct comm_timer* timer;
|
||||
/** the tsig data for the transfer */
|
||||
struct tsig_data* tsig;
|
||||
};
|
||||
|
||||
/** list of addresses */
|
||||
@@ -461,6 +467,8 @@ struct auth_master {
|
||||
int ssl;
|
||||
/** the port number (for urls) */
|
||||
int port;
|
||||
/** the tsig key name (if any, or NULL) */
|
||||
char* tsig_key_name;
|
||||
/** if the host is a hostname, the list of resolved addrs, if any*/
|
||||
struct auth_addr* list;
|
||||
};
|
||||
@@ -490,11 +498,13 @@ struct auth_zones* auth_zones_create(void);
|
||||
* @param is_rpz: set to 1 if at least one RPZ zone is configured.
|
||||
* @param env: environment for offline verification.
|
||||
* @param mods: modules in environment.
|
||||
* @param tsig_key_table: tsig key table to check if tsig keys exist.
|
||||
* If NULL, no check is performed.
|
||||
* @return false on failure.
|
||||
*/
|
||||
int auth_zones_apply_cfg(struct auth_zones* az, struct config_file* cfg,
|
||||
int setup, int* is_rpz, struct module_env* env,
|
||||
struct module_stack* mods);
|
||||
struct module_stack* mods, struct tsig_key_table* tsig_key_table);
|
||||
|
||||
/** initial pick up of worker timeouts, ties events to worker event loop
|
||||
* @param az: auth zones structure
|
||||
@@ -619,13 +629,19 @@ int auth_zones_can_fallback(struct auth_zones* az, uint8_t* nm, size_t nmlen,
|
||||
* @param has_serial: if true, the notify has a serial attached.
|
||||
* @param serial: the serial number, if has_serial is true.
|
||||
* @param refused: is set to true on failure to note refused access.
|
||||
* @param pkt: the packet for TSIG verify.
|
||||
* @param tsig: if TSIG, the structure is returned here, allocated in
|
||||
* the worker scratch region.
|
||||
* @param tsig_rcode: if not NOERROR it is the TSIG error code, TSIG failed.
|
||||
* @param scratchpad: region to allocate tsig in.
|
||||
* @return fail on failures (refused is false) and when access is
|
||||
* denied (refused is true). True when processed.
|
||||
*/
|
||||
int auth_zones_notify(struct auth_zones* az, struct module_env* env,
|
||||
uint8_t* nm, size_t nmlen, uint16_t dclass,
|
||||
struct sockaddr_storage* addr, socklen_t addrlen, int has_serial,
|
||||
uint32_t serial, int* refused);
|
||||
uint32_t serial, int* refused, struct sldns_buffer* pkt,
|
||||
struct tsig_data** tsig, int* tsig_rcode, struct regional* scratchpad);
|
||||
|
||||
/** process notify packet and read serial number from SOA.
|
||||
* returns 0 if no soa record in the notify */
|
||||
@@ -671,10 +687,12 @@ struct auth_xfer* auth_xfer_create(struct auth_zones* az, struct auth_zone* z);
|
||||
* @param list: pointer to start of list. The malloced list is returned here.
|
||||
* @param c: the config items to copy over.
|
||||
* @param with_http: if true, http urls are also included, before the masters.
|
||||
* @param tsig_key_table: if nonNULL, used to check that tsig keys exist in
|
||||
* the key table.
|
||||
* @return false on failure.
|
||||
*/
|
||||
int xfer_set_masters(struct auth_master** list, struct config_auth* c,
|
||||
int with_http);
|
||||
int with_http, struct tsig_key_table* tsig_key_table);
|
||||
|
||||
/** xfer nextprobe timeout callback, this is part of task_nextprobe */
|
||||
void auth_xfer_timer(void* arg);
|
||||
|
||||
@@ -494,6 +494,7 @@ typedef enum sldns_enum_ede_code sldns_ede_code;
|
||||
#define LDNS_TSIG_ERROR_BADMODE 19
|
||||
#define LDNS_TSIG_ERROR_BADNAME 20
|
||||
#define LDNS_TSIG_ERROR_BADALG 21
|
||||
#define LDNS_TSIG_ERROR_BADTRUNC 22
|
||||
|
||||
/** DNS Cookie extended rcode */
|
||||
#define LDNS_EXT_RCODE_BADCOOKIE 23
|
||||
|
||||
@@ -56,6 +56,18 @@ sldns_read_uint32(const void *src)
|
||||
#endif
|
||||
}
|
||||
|
||||
INLINE uint64_t
|
||||
sldns_read_uint48(const void *src)
|
||||
{
|
||||
const uint8_t *p = (const uint8_t *) src;
|
||||
return ( ((uint64_t) p[0] << 40)
|
||||
| ((uint64_t) p[1] << 32)
|
||||
| ((uint64_t) p[2] << 24)
|
||||
| ((uint64_t) p[3] << 16)
|
||||
| ((uint64_t) p[4] << 8)
|
||||
| (uint64_t) p[5]);
|
||||
}
|
||||
|
||||
/*
|
||||
* Copy data allowing for unaligned accesses in network byte order
|
||||
* (big endian).
|
||||
@@ -693,6 +705,32 @@ sldns_buffer_read_u32(sldns_buffer *buffer)
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* returns the 6-byte integer value at the given position in the buffer
|
||||
* \param[in] buffer the buffer
|
||||
* \param[in] at position in the buffer
|
||||
* \return 6 byte integer
|
||||
*/
|
||||
INLINE uint64_t
|
||||
sldns_buffer_read_u48_at(sldns_buffer *buffer, size_t at)
|
||||
{
|
||||
assert(sldns_buffer_available_at(buffer, at, 6));
|
||||
return sldns_read_uint48(buffer->_data + at);
|
||||
}
|
||||
|
||||
/**
|
||||
* returns the 6-byte integer value at the current position in the buffer
|
||||
* \param[in] buffer the buffer
|
||||
* \return 6 byte integer
|
||||
*/
|
||||
INLINE uint64_t
|
||||
sldns_buffer_read_u48(sldns_buffer *buffer)
|
||||
{
|
||||
uint64_t result = sldns_buffer_read_u48_at(buffer, buffer->_position);
|
||||
buffer->_position += 6;
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* returns the status of the buffer
|
||||
* \param[in] buffer
|
||||
|
||||
@@ -255,6 +255,7 @@ static sldns_lookup_table sldns_tsig_errors_data[] = {
|
||||
{ LDNS_TSIG_ERROR_BADMODE, "BADMODE" },
|
||||
{ LDNS_TSIG_ERROR_BADNAME, "BADNAME" },
|
||||
{ LDNS_TSIG_ERROR_BADALG, "BADALG" },
|
||||
{ LDNS_TSIG_ERROR_BADTRUNC, "BADTRUNC" },
|
||||
{ 0, NULL }
|
||||
};
|
||||
sldns_lookup_table* sldns_tsig_errors = sldns_tsig_errors_data;
|
||||
|
||||
@@ -49,6 +49,7 @@
|
||||
#include "util/module.h"
|
||||
#include "util/net_help.h"
|
||||
#include "util/regional.h"
|
||||
#include "util/tsig.h"
|
||||
#include "iterator/iterator.h"
|
||||
#include "iterator/iter_fwd.h"
|
||||
#include "iterator/iter_hints.h"
|
||||
@@ -1003,13 +1004,23 @@ static void
|
||||
check_auth(struct config_file* cfg)
|
||||
{
|
||||
int is_rpz = 0;
|
||||
struct tsig_key_table* tsig_key_table;
|
||||
struct auth_zones* az = auth_zones_create();
|
||||
if(!az || !auth_zones_apply_cfg(az, cfg, 0, &is_rpz, NULL, NULL)) {
|
||||
|
||||
/* construct tsig key table for tsig key name checks, and it
|
||||
* also checks the TSIG key name and algorithm and base64 syntax. */
|
||||
tsig_key_table = tsig_key_table_create();
|
||||
if(!tsig_key_table || !tsig_key_table_apply_cfg(tsig_key_table, cfg))
|
||||
fatal_exit("Could not set up TSIG keys");
|
||||
|
||||
if(!az || !auth_zones_apply_cfg(az, cfg, 0, &is_rpz, NULL, NULL,
|
||||
tsig_key_table)) {
|
||||
fatal_exit("Could not setup authority zones");
|
||||
}
|
||||
if(is_rpz && !strstr(cfg->module_conf, "respip"))
|
||||
fatal_exit("RPZ requires the respip module");
|
||||
auth_zones_delete(az);
|
||||
tsig_key_table_delete(tsig_key_table);
|
||||
}
|
||||
|
||||
/** check config file */
|
||||
|
||||
@@ -1362,6 +1362,7 @@ main(int argc, char* argv[])
|
||||
#ifdef HAVE_NGTCP2
|
||||
doq_test();
|
||||
#endif /* HAVE_NGTCP2 */
|
||||
tsig_test();
|
||||
if(log_get_lock()) {
|
||||
lock_basic_destroy((lock_basic_type*)log_get_lock());
|
||||
}
|
||||
|
||||
@@ -88,5 +88,7 @@ void tcpreuse_test(void);
|
||||
void doq_test(void);
|
||||
/** unit test for infra cache functions */
|
||||
void infra_test(void);
|
||||
/** unit test for tsig functions */
|
||||
void tsig_test(void);
|
||||
|
||||
#endif /* TESTCODE_UNITMAIN_H */
|
||||
|
||||
+1437
File diff suppressed because it is too large
Load Diff
+16
@@ -0,0 +1,16 @@
|
||||
BaseName: auth_tsig
|
||||
Version: 1.0
|
||||
Description: Perform AXFR with TSIG for authority zone.
|
||||
CreationDate: Fri 12 Sep 09:35:40 CEST 2025
|
||||
Maintainer: dr. W.C.A. Wijngaards
|
||||
Category:
|
||||
Component:
|
||||
CmdDepends:
|
||||
Depends:
|
||||
Help:
|
||||
Pre: auth_tsig.pre
|
||||
Post: auth_tsig.post
|
||||
Test: auth_tsig.test
|
||||
AuxFiles:
|
||||
Passed:
|
||||
Failure:
|
||||
+23
@@ -0,0 +1,23 @@
|
||||
server:
|
||||
logfile: "/dev/stderr"
|
||||
xfrdfile: xfrd.state
|
||||
username: ""
|
||||
chroot: ""
|
||||
zonesdir: ""
|
||||
pidfile: "nsd.pid"
|
||||
zonelistfile: "zone.list"
|
||||
verbosity: 5
|
||||
port: @NSD_PORT@
|
||||
interface: 127.0.0.1@@NSD_PORT@
|
||||
|
||||
key:
|
||||
name: "test.key"
|
||||
algorithm: sha256
|
||||
secret: "K2tf3TRjvQkVCmJF3/Z9vA=="
|
||||
|
||||
zone:
|
||||
name: "example.com"
|
||||
zonefile: "example.com.zone"
|
||||
provide-xfr: 0.0.0.0/0 test.key
|
||||
provide-xfr: ::0/0 test.key
|
||||
notify: 127.0.0.1@@UNBOUND_PORT@ test.key
|
||||
+14
@@ -0,0 +1,14 @@
|
||||
# #-- auth_tsig.post --#
|
||||
# source the master var file when it's there
|
||||
[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
|
||||
# source the test var file when it's there
|
||||
[ -f .tpkg.var.test ] && source .tpkg.var.test
|
||||
#
|
||||
# do your teardown here
|
||||
. ../common.sh
|
||||
kill_pid $NSD_PID
|
||||
kill_pid $UNBOUND_PID
|
||||
echo "nsd.log"
|
||||
cat nsd.log
|
||||
echo "unbound.log"
|
||||
cat unbound.log
|
||||
+59
@@ -0,0 +1,59 @@
|
||||
# #-- auth_tsig.pre--#
|
||||
# source the master var file when it's there
|
||||
[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
|
||||
# use .tpkg.var.test for in test variable passing
|
||||
[ -f .tpkg.var.test ] && source .tpkg.var.test
|
||||
|
||||
. ../common.sh
|
||||
#skip_test "Skip test due to no UDP service for SOA query"
|
||||
PRE="../.."
|
||||
if test -n "$NSD"; then
|
||||
:
|
||||
else
|
||||
if `which nsd >/dev/null 2>&1`; then
|
||||
NSD="nsd"
|
||||
else
|
||||
if test -f $PRE/../nsd/nsd; then
|
||||
NSD="$PRE/../nsd/nsd"
|
||||
else
|
||||
skip_test "need nsd"
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
echo "NSD=$NSD"
|
||||
|
||||
if test -f $PRE/unbound_do_valgrind_in_test; then
|
||||
do_valgrind=yes
|
||||
else
|
||||
do_valgrind=no
|
||||
fi
|
||||
VALGRIND_FLAGS="--leak-check=full --show-leak-kinds=all"
|
||||
|
||||
get_random_port 2
|
||||
UNBOUND_PORT=$RND_PORT
|
||||
NSD_PORT=$(($RND_PORT + 1))
|
||||
echo "UNBOUND_PORT=$UNBOUND_PORT" >> .tpkg.var.test
|
||||
echo "NSD_PORT=$NSD_PORT" >> .tpkg.var.test
|
||||
|
||||
# make config file
|
||||
sed -e 's/@UNBOUND_PORT\@/'$UNBOUND_PORT'/' -e 's/@NSD_PORT\@/'$NSD_PORT'/' < auth_tsig.ub.conf > ub.conf
|
||||
sed -e 's/@UNBOUND_PORT\@/'$UNBOUND_PORT'/' -e 's/@NSD_PORT\@/'$NSD_PORT'/' < auth_tsig.nsd.conf > nsd.conf
|
||||
|
||||
# start nsd
|
||||
$NSD -d -c nsd.conf >nsd.log 2>&1 &
|
||||
NSD_PID=$!
|
||||
echo "NSD_PID=$NSD_PID" >> .tpkg.var.test
|
||||
|
||||
# start unbound in the background
|
||||
if test $do_valgrind = "yes"; then
|
||||
valgrind $VALGRIND_FLAGS $PRE/unbound -d -c ub.conf >unbound.log 2>&1 &
|
||||
UNBOUND_PID=$!
|
||||
else
|
||||
$PRE/unbound -d -c ub.conf >unbound.log 2>&1 &
|
||||
UNBOUND_PID=$!
|
||||
fi
|
||||
echo "UNBOUND_PID=$UNBOUND_PID" >> .tpkg.var.test
|
||||
|
||||
cat .tpkg.var.test
|
||||
wait_nsd_up nsd.log
|
||||
wait_unbound_up unbound.log
|
||||
+108
@@ -0,0 +1,108 @@
|
||||
# #-- auth_tsig.test --#
|
||||
# source the master var file when it's there
|
||||
[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
|
||||
# use .tpkg.var.test for in test variable passing
|
||||
[ -f .tpkg.var.test ] && source .tpkg.var.test
|
||||
|
||||
PRE="../.."
|
||||
# do the test
|
||||
echo "> dig www.example.com."
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www.example.com. | tee outfile
|
||||
if grep SERVFAIL outfile; then
|
||||
echo "> try again"
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www.example.com. | tee outfile
|
||||
fi
|
||||
if grep SERVFAIL outfile; then
|
||||
echo "> try again"
|
||||
sleep 1
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www.example.com. | tee outfile
|
||||
fi
|
||||
if grep SERVFAIL outfile; then
|
||||
echo "> try again"
|
||||
sleep 1
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www.example.com. | tee outfile
|
||||
fi
|
||||
if grep SERVFAIL outfile; then
|
||||
echo "> try again"
|
||||
sleep 1
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www.example.com. | tee outfile
|
||||
fi
|
||||
if grep SERVFAIL outfile; then
|
||||
echo "> try again"
|
||||
sleep 10
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www.example.com. | tee outfile
|
||||
fi
|
||||
if grep SERVFAIL outfile; then
|
||||
echo "> try again"
|
||||
sleep 10
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www.example.com. | tee outfile
|
||||
fi
|
||||
echo "> check answer"
|
||||
if grep "1.2.3.4" outfile; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "Not OK"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# update the zonefile.
|
||||
echo "www2.example.com. IN A 1.2.3.5" >> example.com.zone
|
||||
mv example.com.zone tmp.zone
|
||||
sed -e 's/2024082400/2024082401/' <tmp.zone >example.com.zone
|
||||
echo ""
|
||||
echo "new example.com.zone:"
|
||||
cat example.com.zone
|
||||
echo ""
|
||||
|
||||
# NSD reloads the zone file,
|
||||
# sends notify to unbound, with TSIG.
|
||||
# unbound replies to the notify, with TSIG.
|
||||
# unbound fetches SOA record, with TSIG.
|
||||
# unbound fetches zone transfer, with TSIG.
|
||||
kill -1 `cat nsd.pid`
|
||||
|
||||
# test if the zone has updated.
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www2.example.com. | tee outfile
|
||||
if grep NXDOMAIN outfile; then
|
||||
echo "> try again"
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www2.example.com. | tee outfile
|
||||
fi
|
||||
if grep NXDOMAIN outfile; then
|
||||
echo "> try again"
|
||||
sleep 1
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www2.example.com. | tee outfile
|
||||
fi
|
||||
if grep NXDOMAIN outfile; then
|
||||
echo "> try again"
|
||||
sleep 1
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www2.example.com. | tee outfile
|
||||
fi
|
||||
if grep NXDOMAIN outfile; then
|
||||
echo "> try again"
|
||||
sleep 1
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www2.example.com. | tee outfile
|
||||
fi
|
||||
if grep NXDOMAIN outfile; then
|
||||
echo "> try again"
|
||||
sleep 10
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www2.example.com. | tee outfile
|
||||
fi
|
||||
if grep NXDOMAIN outfile; then
|
||||
echo "> try again"
|
||||
sleep 10
|
||||
dig @127.0.0.1 -p $UNBOUND_PORT www2.example.com. | tee outfile
|
||||
fi
|
||||
echo "> check answer"
|
||||
if grep "1.2.3.5" outfile; then
|
||||
echo "OK"
|
||||
else
|
||||
echo "Not OK"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo ""
|
||||
echo "zonefile: unbound-example.com.zone"
|
||||
cat unbound-example.com.zone
|
||||
echo ""
|
||||
|
||||
exit 0
|
||||
+26
@@ -0,0 +1,26 @@
|
||||
server:
|
||||
verbosity: 7
|
||||
num-threads: 1
|
||||
interface: 127.0.0.1
|
||||
port: @UNBOUND_PORT@
|
||||
use-syslog: no
|
||||
directory: ""
|
||||
pidfile: "unbound.pid"
|
||||
chroot: ""
|
||||
username: ""
|
||||
do-not-query-localhost: no
|
||||
log-queries: yes
|
||||
|
||||
# This tsig key is used for testing.
|
||||
tsig-key:
|
||||
name: "test.key"
|
||||
algorithm: sha256
|
||||
secret: "K2tf3TRjvQkVCmJF3/Z9vA=="
|
||||
|
||||
auth-zone:
|
||||
name: "example.com"
|
||||
zonefile: "unbound-example.com.zone"
|
||||
for-upstream: yes
|
||||
for-downstream: yes
|
||||
primary-tsig: "127.0.0.1@@NSD_PORT@" test.key
|
||||
allow-notify-tsig: "127.0.0.2@@NSD_PORT@" test.key
|
||||
+4
@@ -0,0 +1,4 @@
|
||||
example.com. 240 IN SOA ns.nlnetlabs.nl. hostmaster.nlnetlabs.nl. 2024082400 28800 7200 604800 240
|
||||
example.com. NS ns.example.com.
|
||||
ns.example.com. IN A 192.0.2.1
|
||||
www.example.com. A 1.2.3.4
|
||||
Vendored
+176
@@ -0,0 +1,176 @@
|
||||
# Test with algorithm MD5
|
||||
file-algorithm md5
|
||||
|
||||
tsig-key:
|
||||
name: "test.key"
|
||||
algorithm: md5
|
||||
secret: "K2tf3TRjvQkVCmJF3/Z9vA=="
|
||||
|
||||
packet
|
||||
# www.example.net. IN TXT
|
||||
3a03010000010000000000000377777707657861
|
||||
6d706c65036e65740000100001
|
||||
endpacket
|
||||
|
||||
# check with the same contents
|
||||
check-packet
|
||||
3a03010000010000000000000377777707657861
|
||||
6d706c65036e65740000100001
|
||||
endpacket
|
||||
|
||||
# sign the query with <key> <timepoint> <expected function ret>
|
||||
tsig-sign-query test.key 1750411954 1
|
||||
|
||||
check-packet
|
||||
3a03010000010000000000010377777707657861
|
||||
6d706c65036e657400001000010474657374036b
|
||||
65790000fa00ff00000000003a08686d61632d6d
|
||||
6435077369672d616c670372656703696e740000
|
||||
0068552ab2012c0010d4a4778ce91160dc5dfd85
|
||||
7e66f57bda3a0300000000
|
||||
endpacket
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
e707002000010000000000010377777707657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
00000000
|
||||
endpacket
|
||||
|
||||
tsig-sign-query test.key 1750419725 1
|
||||
|
||||
check-packet
|
||||
e707002000010000000000020377777707657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
000000000474657374036b65790000fa00ff0000
|
||||
0000003a08686d61632d6d6435077369672d616c
|
||||
670372656703696e740000006855490d012c0010
|
||||
c00e00f1bafa240f41ee9cbe507b9802e7070000
|
||||
0000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query test.key 1750419725 NOERROR NOERROR 0
|
||||
|
||||
# add some fudge to the time
|
||||
packet
|
||||
e707002000010000000000020377777707657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
000000000474657374036b65790000fa00ff0000
|
||||
0000003a08686d61632d6d6435077369672d616c
|
||||
670372656703696e740000006855490d012c0010
|
||||
c00e00f1bafa240f41ee9cbe507b9802e7070000
|
||||
0000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query test.key 1750419730 NOERROR NOERROR 0
|
||||
|
||||
# purposely make a bad digest
|
||||
# changed 'www' (0x777777) to 'aaa' (0x616161)
|
||||
packet
|
||||
e707002000010000000000020361616107657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
000000000474657374036b65790000fa00ff0000
|
||||
0000003a08686d61632d6d6435077369672d616c
|
||||
670372656703696e740000006855490d012c0010
|
||||
c00e00f1bafa240f41ee9cbe507b9802e7070000
|
||||
0000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query test.key 1750419725 NOTAUTH BADSIG 0
|
||||
|
||||
# the wrong time is used, outside of the fudge region
|
||||
packet
|
||||
e707002000010000000000020377777707657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
000000000474657374036b65790000fa00ff0000
|
||||
0000003a08686d61632d6d6435077369672d616c
|
||||
670372656703696e740000006855490d012c0010
|
||||
c00e00f1bafa240f41ee9cbe507b9802e7070000
|
||||
0000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query test.key 1750819725 NOTAUTH BADTIME 1750819725
|
||||
|
||||
# An unknown key is used, 2222.key
|
||||
packet
|
||||
e707002000010000000000020377777707657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
000000000432323232036b65790000fa00ff0000
|
||||
0000003a08686d61632d6d6435077369672d616c
|
||||
670372656703696e740000006855490d012c0010
|
||||
c00e00f1bafa240f41ee9cbe507b9802e7070000
|
||||
0000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query 2222.key 1750419725 NOTAUTH BADKEY 0
|
||||
|
||||
# An unknown algorithm is used, hmac-UNK, 554e4b
|
||||
packet
|
||||
e707002000010000000000020377777707657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
000000000474657374036b65790000fa00ff0000
|
||||
0000003a08686d61632d554e4b077369672d616c
|
||||
670372656703696e740000006855490d012c0010
|
||||
c00e00f1bafa240f41ee9cbe507b9802e7070000
|
||||
0000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query test.key 1750419725 NOTAUTH BADKEY 0
|
||||
|
||||
# truncated hash
|
||||
packet
|
||||
e707002000010000000000020377777707657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
000000000474657374036b65790000fa00ff0000
|
||||
0000003408686d61632d6d6435077369672d616c
|
||||
670372656703696e740000006855490d012c000a
|
||||
c00e00f1bafa240f41eee7070000
|
||||
0000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query test.key 1750419725 NOTAUTH BADTRUNC 0
|
||||
|
||||
# TSIG does not parse, removed bytes from the end.
|
||||
packet
|
||||
e707002000010000000000020377777707657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
000000000474657374036b65790000fa00ff0000
|
||||
0000003a08686d61632d6d6435077369672d616c
|
||||
670372656703696e740000006855490d012c0010
|
||||
c00e00f1bafa240f41ee9cbe507b9802
|
||||
endpacket
|
||||
|
||||
tsig-verify-query . 1750419725 FORMERR NOERROR 0
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
e707002000010000000000020377777707657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
000000000474657374036b65790000fa00ff0000
|
||||
0000003a08686d61632d6d6435077369672d616c
|
||||
670372656703696e740000006855490d012c0010
|
||||
c00e00f1bafa240f41ee9cbe507b9802e7070000
|
||||
0000
|
||||
endpacket
|
||||
|
||||
tsig-sign-reply 1750419725 NOERROR 1
|
||||
e707840000010001000000010377777707657861
|
||||
6d706c65036e65740000010001c00c0001000100
|
||||
000e1000040a141e2800002904d0000000000000
|
||||
endpacket
|
||||
|
||||
# reply for www.example.net A
|
||||
check-packet
|
||||
e7078400000100010000000203777777076578616d706c65036e65740000010001c00c0001000100000e1000040a141e2800002904d00000000000000474657374036b65790000fa00ff00000000003a08686d61632d6d6435077369672d616c670372656703696e740000006855490d012c0010dc3c138476fcb04cc138aa5c59647b86e70700000000
|
||||
endpacket
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
e707002000010000000000010377777707657861
|
||||
6d706c65036e6574000001000100002910000000
|
||||
00000000
|
||||
endpacket
|
||||
|
||||
tsig-verify-reply test.key 1750419725 1 1
|
||||
e7078400000100010000000203777777076578616d706c65036e65740000010001c00c0001000100000e1000040a141e2800002904d00000000000000474657374036b65790000fa00ff00000000003a08686d61632d6d6435077369672d616c670372656703696e740000006855490d012c0010dc3c138476fcb04cc138aa5c59647b86e70700000000
|
||||
endpacket
|
||||
Vendored
+57
@@ -0,0 +1,57 @@
|
||||
# Test with algorithm
|
||||
file-algorithm sha1
|
||||
|
||||
tsig-key:
|
||||
name: "test.key"
|
||||
algorithm: sha1
|
||||
secret: "K2tf3TRjvQkVCmJF3/Z9vA=="
|
||||
|
||||
packet
|
||||
# www.example.net. IN TXT
|
||||
3a03010000010000000000000377777707657861
|
||||
6d706c65036e65740000100001
|
||||
endpacket
|
||||
|
||||
# sign the query with <key> <timepoint> <expected function ret>
|
||||
tsig-sign-query test.key 1750411954 1
|
||||
|
||||
check-packet
|
||||
3a030100000100000000000103777777076578616d706c65036e657400001000010474657374036b65790000fa00ff00000000002f09686d61632d7368613100000068552ab2012c0014ddea549c7a82a0c4309c0894f884adf9dcf7cd2c3a0300000000
|
||||
endpacket
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
092d0000000100000000000103777777076578616d706c65036e657400000100010000291000000000000000
|
||||
endpacket
|
||||
|
||||
tsig-sign-query test.key 1750420740 1
|
||||
|
||||
check-packet
|
||||
092d0000000100000000000203777777076578616d706c65036e6574000001000100002910000000000000000474657374036b65790000fa00ff00000000002f09686d61632d7368613100000068554d04012c0014f493f53a80f43dbd81df4f2feb7064de8247ba0b092d00000000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query test.key 1750420740 NOERROR NOERROR 0
|
||||
|
||||
packet
|
||||
092d0000000100000000000203777777076578616d706c65036e6574000001000100002910000000000000000474657374036b65790000fa00ff00000000002f09686d61632d7368613100000068554d04012c0014f493f53a80f43dbd81df4f2feb7064de8247ba0b092d00000000
|
||||
endpacket
|
||||
|
||||
tsig-sign-reply 1750420740 NOERROR 1
|
||||
092d840000010001000000010377777707657861
|
||||
6d706c65036e65740000010001c00c0001000100
|
||||
000e1000040a141e2800002904d0000000000000
|
||||
endpacket
|
||||
|
||||
# reply for www.example.net A
|
||||
check-packet
|
||||
092d8400000100010000000203777777076578616d706c65036e65740000010001c00c0001000100000e1000040a141e2800002904d00000000000000474657374036b65790000fa00ff00000000002f09686d61632d7368613100000068554d04012c001475eace537fd51a9fbf192a10b20bfe824dd20318092d00000000
|
||||
endpacket
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
092d0000000100000000000103777777076578616d706c65036e657400000100010000291000000000000000
|
||||
endpacket
|
||||
|
||||
tsig-verify-reply test.key 1750420740 1 1
|
||||
092d8400000100010000000203777777076578616d706c65036e65740000010001c00c0001000100000e1000040a141e2800002904d00000000000000474657374036b65790000fa00ff00000000002f09686d61632d7368613100000068554d04012c001475eace537fd51a9fbf192a10b20bfe824dd20318092d00000000
|
||||
endpacket
|
||||
Vendored
+57
@@ -0,0 +1,57 @@
|
||||
# Test with algorithm
|
||||
file-algorithm sha224
|
||||
|
||||
tsig-key:
|
||||
name: "test.key"
|
||||
algorithm: sha224
|
||||
secret: "K2tf3TRjvQkVCmJF3/Z9vA=="
|
||||
|
||||
packet
|
||||
# www.example.net. IN TXT
|
||||
3a03010000010000000000000377777707657861
|
||||
6d706c65036e65740000100001
|
||||
endpacket
|
||||
|
||||
# sign the query with <key> <timepoint> <expected function ret>
|
||||
tsig-sign-query test.key 1750411954 1
|
||||
|
||||
check-packet
|
||||
3a030100000100000000000103777777076578616d706c65036e657400001000010474657374036b65790000fa00ff0000000000390b686d61632d73686132323400000068552ab2012c001c104d12e4ccab950cb7690233661549b027567ea0c8beb868a7c1c4f33a0300000000
|
||||
endpacket
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
7e7e0000000100000000000103777777076578616d706c65036e657400000100010000291000000000000000
|
||||
endpacket
|
||||
|
||||
tsig-sign-query test.key 1750421692 1
|
||||
|
||||
check-packet
|
||||
7e7e0000000100000000000203777777076578616d706c65036e6574000001000100002910000000000000000474657374036b65790000fa00ff0000000000390b686d61632d736861323234000000685550bc012c001c03431f500872691d8780dafe326cdbe56ceaaca1d0ea3e3a262848e77e7e00000000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query test.key 1750421692 NOERROR NOERROR 0
|
||||
|
||||
packet
|
||||
7e7e0000000100000000000203777777076578616d706c65036e6574000001000100002910000000000000000474657374036b65790000fa00ff0000000000390b686d61632d736861323234000000685550bc012c001c03431f500872691d8780dafe326cdbe56ceaaca1d0ea3e3a262848e77e7e00000000
|
||||
endpacket
|
||||
|
||||
tsig-sign-reply 1750421692 NOERROR 1
|
||||
7e7e840000010001000000010377777707657861
|
||||
6d706c65036e65740000010001c00c0001000100
|
||||
000e1000040a141e2800002904d0000000000000
|
||||
endpacket
|
||||
|
||||
# reply for www.example.net A
|
||||
check-packet
|
||||
7e7e8400000100010000000203777777076578616d706c65036e65740000010001c00c0001000100000e1000040a141e2800002904d00000000000000474657374036b65790000fa00ff0000000000390b686d61632d736861323234000000685550bc012c001c0fa7ddec264122b5e0c3d1a64ed043c3d68582f0ae2ba2d5b3e186127e7e00000000
|
||||
endpacket
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
7e7e0000000100000000000103777777076578616d706c65036e657400000100010000291000000000000000
|
||||
endpacket
|
||||
|
||||
tsig-verify-reply test.key 1750421692 1 1
|
||||
7e7e8400000100010000000203777777076578616d706c65036e65740000010001c00c0001000100000e1000040a141e2800002904d00000000000000474657374036b65790000fa00ff0000000000390b686d61632d736861323234000000685550bc012c001c0fa7ddec264122b5e0c3d1a64ed043c3d68582f0ae2ba2d5b3e186127e7e00000000
|
||||
endpacket
|
||||
Vendored
+1228
File diff suppressed because it is too large
Load Diff
Vendored
+57
@@ -0,0 +1,57 @@
|
||||
# Test with algorithm
|
||||
file-algorithm sha384
|
||||
|
||||
tsig-key:
|
||||
name: "test.key"
|
||||
algorithm: sha384
|
||||
secret: "K2tf3TRjvQkVCmJF3/Z9vA=="
|
||||
|
||||
packet
|
||||
# www.example.net. IN TXT
|
||||
3a03010000010000000000000377777707657861
|
||||
6d706c65036e65740000100001
|
||||
endpacket
|
||||
|
||||
# sign the query with <key> <timepoint> <expected function ret>
|
||||
tsig-sign-query test.key 1750411954 1
|
||||
|
||||
check-packet
|
||||
3a030100000100000000000103777777076578616d706c65036e657400001000010474657374036b65790000fa00ff00000000004d0b686d61632d73686133383400000068552ab2012c00302416b7442f06e5ab2f9814d391c48b73384ab59cccc7de20ecad999a38de62aaa1b61ac0cd3df299bab30776c92322f03a0300000000
|
||||
endpacket
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
aafc0000000100000000000103777777076578616d706c65036e657400000100010000291000000000000000
|
||||
endpacket
|
||||
|
||||
tsig-sign-query test.key 1750421817 1
|
||||
|
||||
check-packet
|
||||
aafc0000000100000000000203777777076578616d706c65036e6574000001000100002910000000000000000474657374036b65790000fa00ff00000000004d0b686d61632d73686133383400000068555139012c00300953f74bcc78dae61e9d93aad74e128dbc240a671de017efd3707235be7890cbf2a51255f5843438fbaa26d04caca506aafc00000000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query test.key 1750421817 NOERROR NOERROR 0
|
||||
|
||||
packet
|
||||
aafc0000000100000000000203777777076578616d706c65036e6574000001000100002910000000000000000474657374036b65790000fa00ff00000000004d0b686d61632d73686133383400000068555139012c00300953f74bcc78dae61e9d93aad74e128dbc240a671de017efd3707235be7890cbf2a51255f5843438fbaa26d04caca506aafc00000000
|
||||
endpacket
|
||||
|
||||
tsig-sign-reply 1750421817 NOERROR 1
|
||||
aafc840000010001000000010377777707657861
|
||||
6d706c65036e65740000010001c00c0001000100
|
||||
000e1000040a141e2800002904d0000000000000
|
||||
endpacket
|
||||
|
||||
# reply for www.example.net A
|
||||
check-packet
|
||||
aafc8400000100010000000203777777076578616d706c65036e65740000010001c00c0001000100000e1000040a141e2800002904d00000000000000474657374036b65790000fa00ff00000000004d0b686d61632d73686133383400000068555139012c00301e895712f5633d84e82afd7b1dcdd792c5d51532c7a5f52701c9bd464f0d8f6cc735530d16417e8bf3cf104808554642aafc00000000
|
||||
endpacket
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
aafc0000000100000000000103777777076578616d706c65036e657400000100010000291000000000000000
|
||||
endpacket
|
||||
|
||||
tsig-verify-reply test.key 1750421817 1 1
|
||||
aafc8400000100010000000203777777076578616d706c65036e65740000010001c00c0001000100000e1000040a141e2800002904d00000000000000474657374036b65790000fa00ff00000000004d0b686d61632d73686133383400000068555139012c00301e895712f5633d84e82afd7b1dcdd792c5d51532c7a5f52701c9bd464f0d8f6cc735530d16417e8bf3cf104808554642aafc00000000
|
||||
endpacket
|
||||
Vendored
+57
@@ -0,0 +1,57 @@
|
||||
# Test with algorithm
|
||||
file-algorithm sha512
|
||||
|
||||
tsig-key:
|
||||
name: "test.key"
|
||||
algorithm: sha512
|
||||
secret: "K2tf3TRjvQkVCmJF3/Z9vA=="
|
||||
|
||||
packet
|
||||
# www.example.net. IN TXT
|
||||
3a03010000010000000000000377777707657861
|
||||
6d706c65036e65740000100001
|
||||
endpacket
|
||||
|
||||
# sign the query with <key> <timepoint> <expected function ret>
|
||||
tsig-sign-query test.key 1750411954 1
|
||||
|
||||
check-packet
|
||||
3a030100000100000000000103777777076578616d706c65036e657400001000010474657374036b65790000fa00ff00000000005d0b686d61632d73686135313200000068552ab2012c00403cd816538bec85fea4ae45a6fb2e961622a4dfad2afa69da999c53133d02e9f2ba789a14b489678b83ab319662d2388fcc7286bfa11d88e71614c845e77584c43a0300000000
|
||||
endpacket
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
e74d0000000100000000000103777777076578616d706c65036e657400000100010000291000000000000000
|
||||
endpacket
|
||||
|
||||
tsig-sign-query test.key 1750421867 1
|
||||
|
||||
check-packet
|
||||
e74d0000000100000000000203777777076578616d706c65036e6574000001000100002910000000000000000474657374036b65790000fa00ff00000000005d0b686d61632d7368613531320000006855516b012c0040bbc78c7a8019119b79f89f3ed66d874acb3a29bfcd3ac75fce3779d60d41080fe536c03de404a9143314eabce88a0c5eff6204d94d3225cf42327322c8a48acae74d00000000
|
||||
endpacket
|
||||
|
||||
tsig-verify-query test.key 1750421867 NOERROR NOERROR 0
|
||||
|
||||
packet
|
||||
e74d0000000100000000000203777777076578616d706c65036e6574000001000100002910000000000000000474657374036b65790000fa00ff00000000005d0b686d61632d7368613531320000006855516b012c0040bbc78c7a8019119b79f89f3ed66d874acb3a29bfcd3ac75fce3779d60d41080fe536c03de404a9143314eabce88a0c5eff6204d94d3225cf42327322c8a48acae74d00000000
|
||||
endpacket
|
||||
|
||||
tsig-sign-reply 1750421867 NOERROR 1
|
||||
e74d840000010001000000010377777707657861
|
||||
6d706c65036e65740000010001c00c0001000100
|
||||
000e1000040a141e2800002904d0000000000000
|
||||
endpacket
|
||||
|
||||
# reply for www.example.net A
|
||||
check-packet
|
||||
e74d8400000100010000000203777777076578616d706c65036e65740000010001c00c0001000100000e1000040a141e2800002904d00000000000000474657374036b65790000fa00ff00000000005d0b686d61632d7368613531320000006855516b012c0040690c00d5e01a382b7a4c07739e0faab1a3c98f5bae1b49213032b7da070c4b985056894e1ebc88468d5d070d0589ea8032fb88f3a1902fa91211d2b4989bbb93e74d00000000
|
||||
endpacket
|
||||
|
||||
# www.example.net A
|
||||
packet
|
||||
e74d0000000100000000000103777777076578616d706c65036e657400000100010000291000000000000000
|
||||
endpacket
|
||||
|
||||
tsig-verify-reply test.key 1750421867 1 1
|
||||
e74d8400000100010000000203777777076578616d706c65036e65740000010001c00c0001000100000e1000040a141e2800002904d00000000000000474657374036b65790000fa00ff00000000005d0b686d61632d7368613531320000006855516b012c0040690c00d5e01a382b7a4c07739e0faab1a3c98f5bae1b49213032b7da070c4b985056894e1ebc88468d5d070d0589ea8032fb88f3a1902fa91211d2b4989bbb93e74d00000000
|
||||
endpacket
|
||||
+27
-1
@@ -223,6 +223,7 @@ config_create(void)
|
||||
cfg->stubs = NULL;
|
||||
cfg->forwards = NULL;
|
||||
cfg->auths = NULL;
|
||||
cfg->tsig_keys = NULL;
|
||||
#ifdef CLIENT_SUBNET
|
||||
cfg->client_subnet = NULL;
|
||||
cfg->client_subnet_zone = NULL;
|
||||
@@ -930,7 +931,7 @@ int config_set_option(struct config_file* cfg, const char* opt,
|
||||
* max-client-subnet-ipv4, max-client-subnet-ipv6,
|
||||
* min-client-subnet-ipv4, min-client-subnet-ipv6,
|
||||
* max-ecs-tree-size-ipv4, max-ecs-tree-size-ipv6, ipsecmod_hook,
|
||||
* ipsecmod_whitelist. */
|
||||
* ipsecmod_whitelist, tsig-key. */
|
||||
return 0;
|
||||
}
|
||||
return 1;
|
||||
@@ -1436,6 +1437,7 @@ config_get_option(struct config_file* cfg, const char* opt,
|
||||
* local-data-ptr - converted to local-data entries
|
||||
* stub-zone, name, stub-addr, stub-host, stub-prime
|
||||
* forward-zone, name, forward-addr, forward-host
|
||||
* tsig-key
|
||||
*/
|
||||
else return 0;
|
||||
return 1;
|
||||
@@ -1642,6 +1644,8 @@ config_delauth(struct config_auth* p)
|
||||
config_delstrlist(p->masters);
|
||||
config_delstrlist(p->urls);
|
||||
config_delstrlist(p->allow_notify);
|
||||
config_deldblstrlist(p->masters_tsig);
|
||||
config_deldblstrlist(p->allow_notify_tsig);
|
||||
free(p->zonefile);
|
||||
free(p->rpz_taglist);
|
||||
free(p->rpz_action_override);
|
||||
@@ -1707,6 +1711,27 @@ config_delviews(struct config_view* p)
|
||||
}
|
||||
}
|
||||
|
||||
void
|
||||
config_deltsig_key(struct config_tsig_key* p)
|
||||
{
|
||||
if(!p) return;
|
||||
free(p->name);
|
||||
free(p->algorithm);
|
||||
free(p->secret);
|
||||
free(p);
|
||||
}
|
||||
|
||||
void
|
||||
config_deltsig_keys(struct config_tsig_key* p)
|
||||
{
|
||||
struct config_tsig_key* np;
|
||||
while(p) {
|
||||
np = p->next;
|
||||
config_deltsig_key(p);
|
||||
p = np;
|
||||
}
|
||||
}
|
||||
|
||||
void
|
||||
config_del_strarray(char** array, int num)
|
||||
{
|
||||
@@ -1761,6 +1786,7 @@ config_delete(struct config_file* cfg)
|
||||
config_delstubs(cfg->forwards);
|
||||
config_delauths(cfg->auths);
|
||||
config_delviews(cfg->views);
|
||||
config_deltsig_keys(cfg->tsig_keys);
|
||||
config_delstrlist(cfg->donotqueryaddrs);
|
||||
config_delstrlist(cfg->root_hints);
|
||||
#ifdef CLIENT_SUBNET
|
||||
|
||||
@@ -45,6 +45,7 @@
|
||||
struct config_stub;
|
||||
struct config_auth;
|
||||
struct config_view;
|
||||
struct config_tsig_key;
|
||||
struct config_strlist;
|
||||
struct config_str2list;
|
||||
struct config_str3list;
|
||||
@@ -262,6 +263,8 @@ struct config_file {
|
||||
struct config_auth* auths;
|
||||
/** the views definitions, linked list */
|
||||
struct config_view* views;
|
||||
/** the tsig-key definitions, linked list */
|
||||
struct config_tsig_key* tsig_keys;
|
||||
/** list of donotquery addresses, linked list */
|
||||
struct config_strlist* donotqueryaddrs;
|
||||
#ifdef CLIENT_SUBNET
|
||||
@@ -847,6 +850,10 @@ struct config_auth {
|
||||
struct config_strlist* urls;
|
||||
/** list of allow-notify */
|
||||
struct config_strlist* allow_notify;
|
||||
/** list of masters with tsig key */
|
||||
struct config_str2list* masters_tsig;
|
||||
/** list of allow-notify with tsig key */
|
||||
struct config_str2list* allow_notify_tsig;
|
||||
/** zonefile (or NULL) */
|
||||
char* zonefile;
|
||||
/** provide downstream answers */
|
||||
@@ -906,6 +913,20 @@ struct config_view {
|
||||
struct config_str2list* respip_data;
|
||||
};
|
||||
|
||||
/**
|
||||
* Tsig-key config options
|
||||
*/
|
||||
struct config_tsig_key {
|
||||
/** next in list */
|
||||
struct config_tsig_key* next;
|
||||
/** name of the tsig key */
|
||||
char* name;
|
||||
/** algorithm */
|
||||
char* algorithm;
|
||||
/** secret date, in base64 */
|
||||
char* secret;
|
||||
};
|
||||
|
||||
/**
|
||||
* List of strings for config options
|
||||
*/
|
||||
@@ -1218,6 +1239,18 @@ void config_delview(struct config_view* p);
|
||||
*/
|
||||
void config_delviews(struct config_view* list);
|
||||
|
||||
/**
|
||||
* Delete a tsig_key item
|
||||
* @param p: tsig_key item
|
||||
*/
|
||||
void config_deltsig_key(struct config_tsig_key* p);
|
||||
|
||||
/**
|
||||
* Delete items in config tsig_key list.
|
||||
* @param list: list.
|
||||
*/
|
||||
void config_deltsig_keys(struct config_tsig_key* list);
|
||||
|
||||
/** check if config for remote control turns on IP-address interface
|
||||
* with certificates or a named pipe without certificates. */
|
||||
int options_remote_is_address(struct config_file* cfg);
|
||||
|
||||
@@ -362,8 +362,11 @@ rpz-signal-nxdomain-ra{COLON} { YDVAR(1, VAR_RPZ_SIGNAL_NXDOMAIN_RA) }
|
||||
zonefile{COLON} { YDVAR(1, VAR_ZONEFILE) }
|
||||
master{COLON} { YDVAR(1, VAR_MASTER) }
|
||||
primary{COLON} { YDVAR(1, VAR_MASTER) }
|
||||
master-tsig{COLON} { YDVAR(2, VAR_MASTER_TSIG) }
|
||||
primary-tsig{COLON} { YDVAR(2, VAR_MASTER_TSIG) }
|
||||
url{COLON} { YDVAR(1, VAR_URL) }
|
||||
allow-notify{COLON} { YDVAR(1, VAR_ALLOW_NOTIFY) }
|
||||
allow-notify-tsig{COLON} { YDVAR(2, VAR_ALLOW_NOTIFY_TSIG) }
|
||||
for-downstream{COLON} { YDVAR(1, VAR_FOR_DOWNSTREAM) }
|
||||
for-upstream{COLON} { YDVAR(1, VAR_FOR_UPSTREAM) }
|
||||
fallback-enabled{COLON} { YDVAR(1, VAR_FALLBACK_ENABLED) }
|
||||
@@ -607,6 +610,9 @@ proxy-protocol-port{COLON} { YDVAR(1, VAR_PROXY_PROTOCOL_PORT) }
|
||||
iter-scrub-ns{COLON} { YDVAR(1, VAR_ITER_SCRUB_NS) }
|
||||
iter-scrub-cname{COLON} { YDVAR(1, VAR_ITER_SCRUB_CNAME) }
|
||||
max-global-quota{COLON} { YDVAR(1, VAR_MAX_GLOBAL_QUOTA) }
|
||||
tsig-key{COLON} { YDVAR(0, VAR_TSIG_KEY) }
|
||||
algorithm{COLON} { YDVAR(1, VAR_ALGORITHM) }
|
||||
secret{COLON} { YDVAR(1, VAR_SECRET) }
|
||||
<INITIAL,val>{NEWLINE} { LEXOUT(("NL\n")); cfg_parser->line++; }
|
||||
|
||||
/* Quoted strings. Strip leading and ending quotes */
|
||||
|
||||
+105
-7
@@ -47,7 +47,9 @@
|
||||
#include "util/configyyrename.h"
|
||||
#include "util/config_file.h"
|
||||
#include "util/net_help.h"
|
||||
#include "util/tsig.h"
|
||||
#include "sldns/str2wire.h"
|
||||
#include "sldns/parseutil.h"
|
||||
|
||||
int ub_c_lex(void);
|
||||
void ub_c_error(const char *message);
|
||||
@@ -190,6 +192,7 @@ extern struct config_parser_state* cfg_parser;
|
||||
%token VAR_CACHEDB_REDISCONNECTTIMEOUT VAR_CACHEDB_REDISREPLICACONNECTTIMEOUT
|
||||
%token VAR_UDP_UPSTREAM_WITHOUT_DOWNSTREAM VAR_FOR_UPSTREAM
|
||||
%token VAR_AUTH_ZONE VAR_ZONEFILE VAR_MASTER VAR_URL VAR_FOR_DOWNSTREAM
|
||||
%token VAR_MASTER_TSIG VAR_ALLOW_NOTIFY_TSIG
|
||||
%token VAR_FALLBACK_ENABLED VAR_TLS_ADDITIONAL_PORT VAR_LOW_RTT VAR_LOW_RTT_PERMIL
|
||||
%token VAR_FAST_SERVER_PERMIL VAR_FAST_SERVER_NUM
|
||||
%token VAR_ALLOW_NOTIFY VAR_TLS_WIN_CERT VAR_TCP_CONNECTION_LIMIT
|
||||
@@ -216,6 +219,7 @@ extern struct config_parser_state* cfg_parser;
|
||||
%token VAR_LOG_DESTADDR VAR_CACHEDB_CHECK_WHEN_SERVE_EXPIRED
|
||||
%token VAR_COOKIE_SECRET_FILE VAR_ITER_SCRUB_NS VAR_ITER_SCRUB_CNAME
|
||||
%token VAR_MAX_GLOBAL_QUOTA VAR_HARDEN_UNVERIFIED_GLUE VAR_LOG_TIME_ISO
|
||||
%token VAR_TSIG_KEY VAR_ALGORITHM VAR_SECRET
|
||||
|
||||
%%
|
||||
toplevelvars: /* empty */ | toplevelvars toplevelvar ;
|
||||
@@ -224,7 +228,7 @@ toplevelvar: serverstart contents_server | stub_clause |
|
||||
rcstart contents_rc | dtstart contents_dt | view_clause |
|
||||
dnscstart contents_dnsc | cachedbstart contents_cachedb |
|
||||
ipsetstart contents_ipset | authstart contents_auth |
|
||||
rpzstart contents_rpz | dynlibstart contents_dl |
|
||||
rpzstart contents_rpz | dynlibstart contents_dl | tsig_key_clause |
|
||||
force_toplevel
|
||||
;
|
||||
force_toplevel: VAR_FORCE_TOPLEVEL
|
||||
@@ -464,9 +468,10 @@ authstart: VAR_AUTH_ZONE
|
||||
;
|
||||
contents_auth: contents_auth content_auth
|
||||
| ;
|
||||
content_auth: auth_name | auth_zonefile | auth_master | auth_url |
|
||||
auth_for_downstream | auth_for_upstream | auth_fallback_enabled |
|
||||
auth_allow_notify | auth_zonemd_check | auth_zonemd_reject_absence
|
||||
content_auth: auth_name | auth_zonefile | auth_master | auth_master_tsig |
|
||||
auth_url | auth_for_downstream | auth_for_upstream |
|
||||
auth_fallback_enabled | auth_allow_notify | auth_allow_notify_tsig |
|
||||
auth_zonemd_check | auth_zonemd_reject_absence
|
||||
;
|
||||
|
||||
rpz_tag: VAR_TAGS STRING_ARG
|
||||
@@ -561,9 +566,10 @@ rpzstart: VAR_RPZ
|
||||
;
|
||||
contents_rpz: contents_rpz content_rpz
|
||||
| ;
|
||||
content_rpz: auth_name | auth_zonefile | rpz_tag | auth_master | auth_url |
|
||||
auth_allow_notify | rpz_action_override | rpz_cname_override |
|
||||
rpz_log | rpz_log_name | rpz_signal_nxdomain_ra | auth_for_downstream
|
||||
content_rpz: auth_name | auth_zonefile | rpz_tag | auth_master |
|
||||
auth_master_tsig | auth_url | auth_allow_notify |
|
||||
auth_allow_notify_tsig | rpz_action_override | rpz_cname_override |
|
||||
rpz_log | rpz_log_name | rpz_signal_nxdomain_ra | auth_for_downstream
|
||||
;
|
||||
server_num_threads: VAR_NUM_THREADS STRING_ARG
|
||||
{
|
||||
@@ -3262,6 +3268,14 @@ auth_master: VAR_MASTER STRING_ARG
|
||||
yyerror("out of memory");
|
||||
}
|
||||
;
|
||||
auth_master_tsig: VAR_MASTER_TSIG STRING_ARG STRING_ARG
|
||||
{
|
||||
OUTYY(("P(master-tsig:%s)\n", $2));
|
||||
if(!cfg_str2list_insert(&cfg_parser->cfg->auths->masters_tsig,
|
||||
$2, $3))
|
||||
yyerror("out of memory");
|
||||
}
|
||||
;
|
||||
auth_url: VAR_URL STRING_ARG
|
||||
{
|
||||
OUTYY(("P(url:%s)\n", $2));
|
||||
@@ -3277,6 +3291,14 @@ auth_allow_notify: VAR_ALLOW_NOTIFY STRING_ARG
|
||||
yyerror("out of memory");
|
||||
}
|
||||
;
|
||||
auth_allow_notify_tsig: VAR_ALLOW_NOTIFY_TSIG STRING_ARG STRING_ARG
|
||||
{
|
||||
OUTYY(("P(allow-notify-tsig:%s)\n", $2));
|
||||
if(!cfg_str2list_insert(
|
||||
&cfg_parser->cfg->auths->allow_notify_tsig, $2, $3))
|
||||
yyerror("out of memory");
|
||||
}
|
||||
;
|
||||
auth_zonemd_check: VAR_ZONEMD_CHECK STRING_ARG
|
||||
{
|
||||
OUTYY(("P(zonemd-check:%s)\n", $2));
|
||||
@@ -3745,6 +3767,82 @@ dl_file: VAR_DYNLIB_FILE STRING_ARG
|
||||
yyerror("out of memory");
|
||||
}
|
||||
;
|
||||
tsig_key_clause: tsig_key_start contents_tsig_key
|
||||
{
|
||||
/* tsig-key end */
|
||||
if(cfg_parser->cfg->tsig_keys) {
|
||||
if(!cfg_parser->cfg->tsig_keys->name)
|
||||
yyerror("tsig-key without name");
|
||||
else if(!cfg_parser->cfg->tsig_keys->algorithm)
|
||||
ub_c_error_msg("tsig-key %s has no algorithm",
|
||||
cfg_parser->cfg->tsig_keys->name);
|
||||
else if(!cfg_parser->cfg->tsig_keys->secret)
|
||||
ub_c_error_msg("tsig-key %s has no secret blob",
|
||||
cfg_parser->cfg->tsig_keys->name);
|
||||
}
|
||||
}
|
||||
;
|
||||
tsig_key_start: VAR_TSIG_KEY
|
||||
{
|
||||
struct config_tsig_key* s;
|
||||
OUTYY(("\nP(tsig-key:)\n"));
|
||||
cfg_parser->started_toplevel = 1;
|
||||
s = (struct config_tsig_key*)calloc(1,
|
||||
sizeof(struct config_tsig_key));
|
||||
if(s) {
|
||||
s->next = cfg_parser->cfg->tsig_keys;
|
||||
cfg_parser->cfg->tsig_keys = s;
|
||||
} else {
|
||||
yyerror("out of memory");
|
||||
}
|
||||
}
|
||||
;
|
||||
contents_tsig_key: contents_tsig_key content_tsig_key
|
||||
| ;
|
||||
content_tsig_key: tsig_key_name | tsig_key_algorithm | tsig_key_secret
|
||||
;
|
||||
tsig_key_name: VAR_NAME STRING_ARG
|
||||
{
|
||||
uint8_t buf[LDNS_MAX_DOMAINLEN+1];
|
||||
size_t len = sizeof(buf);
|
||||
int r;
|
||||
|
||||
OUTYY(("P(name:%s)\n", $2));
|
||||
free(cfg_parser->cfg->tsig_keys->name);
|
||||
cfg_parser->cfg->tsig_keys->name = $2;
|
||||
|
||||
if((r=sldns_str2wire_dname_buf($2, buf, &len))!=0)
|
||||
ub_c_error_msg("could not parse tsig key name"
|
||||
" '%s':%d: %s", $2, LDNS_WIREPARSE_OFFSET(r),
|
||||
sldns_get_errorstr_parse(r));
|
||||
}
|
||||
tsig_key_algorithm: VAR_ALGORITHM STRING_ARG
|
||||
{
|
||||
OUTYY(("P(algorithm:%s)\n", $2));
|
||||
free(cfg_parser->cfg->tsig_keys->algorithm);
|
||||
cfg_parser->cfg->tsig_keys->algorithm = $2;
|
||||
if(!tsig_algo_check_name($2))
|
||||
ub_c_error_msg("could not parse tsig key algorithm '%s'",
|
||||
$2);
|
||||
}
|
||||
tsig_key_secret: VAR_SECRET STRING_ARG
|
||||
{
|
||||
uint8_t data[16384];
|
||||
int size;
|
||||
|
||||
OUTYY(("P(secret:%s)\n", $2));
|
||||
free(cfg_parser->cfg->tsig_keys->secret);
|
||||
cfg_parser->cfg->tsig_keys->secret = $2;
|
||||
|
||||
size = sldns_b64_pton($2, data, sizeof(data));
|
||||
if(size == -1) {
|
||||
ub_c_error_msg("cannot base64 decode tsig secret %s",
|
||||
cfg_parser->cfg->tsig_keys->name?
|
||||
cfg_parser->cfg->tsig_keys->name:"");
|
||||
} else if(size != 0) {
|
||||
explicit_bzero(data, size);
|
||||
}
|
||||
}
|
||||
server_disable_dnssec_lame_check: VAR_DISABLE_DNSSEC_LAME_CHECK STRING_ARG
|
||||
{
|
||||
OUTYY(("P(disable_dnssec_lame_check:%s)\n", $2));
|
||||
|
||||
+1
-1
@@ -97,7 +97,7 @@ dname_valid(uint8_t* dname, size_t maxlen)
|
||||
|
||||
/** compare uncompressed, noncanonical, registers are hints for speed */
|
||||
int
|
||||
query_dname_compare(register uint8_t* d1, register uint8_t* d2)
|
||||
query_dname_compare(register const uint8_t* d1, register const uint8_t* d2)
|
||||
{
|
||||
register uint8_t lab1, lab2;
|
||||
log_assert(d1 && d2);
|
||||
|
||||
+1
-1
@@ -96,7 +96,7 @@ void pkt_dname_tolower(struct sldns_buffer* pkt, uint8_t* dname);
|
||||
* @return: -1, 0, or +1 depending on comparison results.
|
||||
* Sort order is first difference found. not the canonical ordering.
|
||||
*/
|
||||
int query_dname_compare(uint8_t* d1, uint8_t* d2);
|
||||
int query_dname_compare(const uint8_t* d1, const uint8_t* d2);
|
||||
|
||||
/**
|
||||
* Determine correct, compressed, dname present in packet.
|
||||
|
||||
+26
-4
@@ -1282,10 +1282,32 @@ parse_edns_from_query_pkt(sldns_buffer* pkt, struct edns_data* edns,
|
||||
return LDNS_RCODE_FORMERR;
|
||||
}
|
||||
/* check edns section is present */
|
||||
if(LDNS_ARCOUNT(sldns_buffer_begin(pkt)) > 1) {
|
||||
return LDNS_RCODE_FORMERR;
|
||||
}
|
||||
if(LDNS_ARCOUNT(sldns_buffer_begin(pkt)) == 0) {
|
||||
if(LDNS_ARCOUNT(sldns_buffer_begin(pkt)) > 0) {
|
||||
int i, edns_found = 0;
|
||||
for(i=0; i<(int)LDNS_ARCOUNT(sldns_buffer_begin(pkt)); i++) {
|
||||
if(sldns_buffer_remaining(pkt) < 1)
|
||||
return LDNS_RCODE_FORMERR;
|
||||
if(sldns_buffer_current(pkt)[0] == 0) {
|
||||
/* The domain name is the root of length 1. */
|
||||
/* See if the RR Type is OPT. */
|
||||
if(sldns_buffer_remaining(pkt) < 3)
|
||||
return LDNS_RCODE_FORMERR;
|
||||
if(sldns_buffer_read_u16_at(pkt,
|
||||
sldns_buffer_position(pkt)+1) ==
|
||||
LDNS_RR_TYPE_OPT) {
|
||||
/* This is the EDNS OPT record */
|
||||
edns_found = 1;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if(!skip_pkt_rrs(pkt, 1))
|
||||
return LDNS_RCODE_FORMERR;
|
||||
}
|
||||
if(!edns_found) {
|
||||
edns->udp_size = 512;
|
||||
return 0;
|
||||
}
|
||||
} else if(LDNS_ARCOUNT(sldns_buffer_begin(pkt)) == 0) {
|
||||
edns->udp_size = 512;
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -72,6 +72,7 @@
|
||||
#include "libunbound/libworker.h"
|
||||
#include "libunbound/context.h"
|
||||
#include "libunbound/worker.h"
|
||||
#include "util/tsig.h"
|
||||
#include "util/tube.h"
|
||||
#include "util/config_file.h"
|
||||
#include "daemon/remote.h"
|
||||
@@ -262,6 +263,7 @@ fptr_whitelist_rbtree_cmp(int (*fptr) (const void *, const void *))
|
||||
else if(fptr == &auth_zone_cmp) return 1;
|
||||
else if(fptr == &auth_data_cmp) return 1;
|
||||
else if(fptr == &auth_xfer_cmp) return 1;
|
||||
else if(fptr == &tsig_key_compare) return 1;
|
||||
#ifdef HAVE_NGTCP2
|
||||
else if(fptr == &doq_conn_cmp) return 1;
|
||||
else if(fptr == &doq_conid_cmp) return 1;
|
||||
|
||||
@@ -181,6 +181,7 @@ struct views;
|
||||
struct respip_set;
|
||||
struct respip_client_info;
|
||||
struct respip_addr_info;
|
||||
struct tsig_key_table;
|
||||
struct module_stack;
|
||||
|
||||
/** Maximum number of modules in operation */
|
||||
@@ -534,6 +535,8 @@ struct module_env {
|
||||
struct views* views;
|
||||
/** response-ip set with associated actions and tags. */
|
||||
struct respip_set* respip_set;
|
||||
/** the TSIG keys */
|
||||
struct tsig_key_table* tsig_key_table;
|
||||
/** module specific data. indexed by module id. */
|
||||
void* modinfo[MAX_MODULE];
|
||||
|
||||
|
||||
+2463
File diff suppressed because it is too large
Load Diff
+517
@@ -0,0 +1,517 @@
|
||||
/*
|
||||
* util/tsig.h - handle TSIG signatures.
|
||||
*
|
||||
* Copyright (c) 2023, NLnet Labs. All rights reserved.
|
||||
*
|
||||
* This software is open source.
|
||||
*
|
||||
* Redistribution and use in source and binary forms, with or without
|
||||
* modification, are permitted provided that the following conditions
|
||||
* are met:
|
||||
*
|
||||
* Redistributions of source code must retain the above copyright notice,
|
||||
* this list of conditions and the following disclaimer.
|
||||
*
|
||||
* Redistributions in binary form must reproduce the above copyright notice,
|
||||
* this list of conditions and the following disclaimer in the documentation
|
||||
* and/or other materials provided with the distribution.
|
||||
*
|
||||
* Neither the name of the NLNET LABS nor the names of its contributors may
|
||||
* be used to endorse or promote products derived from this software without
|
||||
* specific prior written permission.
|
||||
*
|
||||
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
|
||||
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
||||
* HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
||||
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED
|
||||
* TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
|
||||
* PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
|
||||
* LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
|
||||
* NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
|
||||
* SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
*/
|
||||
|
||||
/**
|
||||
* \file
|
||||
*
|
||||
* This file provides functions to create and verify TSIG RRs.
|
||||
*/
|
||||
|
||||
#ifndef UTIL_TSIG_H
|
||||
#define UTIL_TSIG_H
|
||||
#include "util/locks.h"
|
||||
#include "util/rbtree.h"
|
||||
struct sldns_buffer;
|
||||
struct config_file;
|
||||
struct config_tsig_key;
|
||||
struct regional;
|
||||
struct tsig_calc_state_crypto;
|
||||
|
||||
/**
|
||||
* TSIG record, the RR that is in the packet.
|
||||
* The RR Type is TSIG and the RR class is CLASS_ANY. The TTL is 0.
|
||||
*/
|
||||
struct tsig_record {
|
||||
/** domain name of the RR, the key name. */
|
||||
uint8_t* key_name;
|
||||
/** length of the key_name */
|
||||
size_t key_name_len;
|
||||
/** the position of the TSIG RR in the packet, it is before the owner
|
||||
* name. */
|
||||
size_t tsig_pos;
|
||||
/** the algorithm name, as a domain name. */
|
||||
uint8_t* algorithm_name;
|
||||
/** length of the algorithm_name */
|
||||
size_t algorithm_name_len;
|
||||
/** the signed time, 48bits on the wire */
|
||||
uint64_t signed_time;
|
||||
/** the fudge time */
|
||||
uint16_t fudge_time;
|
||||
/** the mac size, uint16_t on the wire */
|
||||
size_t mac_size;
|
||||
/** the mac data */
|
||||
uint8_t* mac_data;
|
||||
/** the original query id */
|
||||
uint16_t original_query_id;
|
||||
/** the tsig error code */
|
||||
uint16_t error_code;
|
||||
/** length of the other data, uint16_t on the wire */
|
||||
size_t other_size;
|
||||
/** the other data */
|
||||
uint8_t* other_data;
|
||||
/** if the other size is 48bit, the timestamp in it. */
|
||||
uint64_t other_time;
|
||||
};
|
||||
|
||||
/**
|
||||
* TSIG data. This keeps track of the information between packets,
|
||||
* for the TSIG signature, and state, errors, key.
|
||||
*/
|
||||
struct tsig_data {
|
||||
/** The key name, in wireformat */
|
||||
uint8_t* key_name;
|
||||
/** length of the key name */
|
||||
size_t key_name_len;
|
||||
/** The algo name, if the key could not be found. If NULL, it can
|
||||
* be found in the tsig_key algo. */
|
||||
uint8_t* algo_name;
|
||||
/** length of the algo name */
|
||||
size_t algo_name_len;
|
||||
/** mac size */
|
||||
size_t mac_size;
|
||||
/** digest buffer */
|
||||
uint8_t* mac;
|
||||
/** original query ID */
|
||||
uint16_t original_query_id;
|
||||
/** the TSIG class */
|
||||
uint16_t klass;
|
||||
/** the TSIG TTL */
|
||||
uint16_t ttl;
|
||||
/** the time signed, 48bit */
|
||||
uint64_t time_signed;
|
||||
/** fudge amount of time_signed */
|
||||
uint16_t fudge;
|
||||
/** the TSIG error code */
|
||||
uint16_t error;
|
||||
/** other data length, 6 for other_time as failed time. */
|
||||
uint16_t other_len;
|
||||
/** if other len 6, this is 48bit time of error. */
|
||||
uint64_t other_time;
|
||||
/** For zone transfers, there are several packets and TSIGs,
|
||||
* this keeps track of the tsig calculation state. It is malloced,
|
||||
* and the tsig has to be deleted to free it. */
|
||||
struct tsig_calc_state_crypto* calc_state;
|
||||
/** For the first packet it is 0, for later packets 1. */
|
||||
int later_packet;
|
||||
/** The number of update only packets without a tsig. */
|
||||
int num_updates;
|
||||
/** The number of packets after which to sign with TSIG, 1 is every
|
||||
* time. */
|
||||
int every_nth;
|
||||
};
|
||||
|
||||
/**
|
||||
* TSIG algorithm. This is the HMAC algorithm used for the TSIG mac.
|
||||
*/
|
||||
struct tsig_algorithm {
|
||||
/** Short name of the algorithm, like "hmac-md5" */
|
||||
char* short_name;
|
||||
/**
|
||||
* Full wireformat name of the algorith, such as
|
||||
* "hmac-md5.sig-alg.reg.int."
|
||||
* In canonical format, that is in lowercase.
|
||||
*/
|
||||
uint8_t* wireformat_name;
|
||||
/** length of the wireformat_name */
|
||||
size_t wireformat_name_len;
|
||||
/** digest name, like "md5" */
|
||||
const char* digest;
|
||||
/** the maximum size of the digest from the algorithm, in bytes,
|
||||
* like 16 for MD5, and 20 for SHA1. */
|
||||
size_t max_digest_size;
|
||||
};
|
||||
|
||||
/**
|
||||
* TSIG key. This is used to sign and verify packets.
|
||||
*/
|
||||
struct tsig_key {
|
||||
/** the rbtree node */
|
||||
rbnode_type node;
|
||||
/** name of the key as string */
|
||||
char* name_str;
|
||||
/** the algorithm structure */
|
||||
struct tsig_algorithm* algo;
|
||||
/**
|
||||
* Name of the key, in wireformat.
|
||||
* The key name has to be transferred as a domain name, of the TSIG
|
||||
* RR and thus the key name has to be a wireformat domain name.
|
||||
*/
|
||||
uint8_t* name;
|
||||
/** length of name */
|
||||
size_t name_len;
|
||||
/** the data, with the secret portion of the key. decoded from the
|
||||
* base64 string with the secret. */
|
||||
uint8_t* data;
|
||||
/** the size of the data */
|
||||
size_t data_len;
|
||||
};
|
||||
|
||||
/**
|
||||
* The TSIG key storage. Keys are stored by name.
|
||||
* They are read from config.
|
||||
*/
|
||||
struct tsig_key_table {
|
||||
/* Lock on the tsig key table and all keys.
|
||||
* This lock is after the forwards, hints and anchor locks. */
|
||||
lock_rw_type lock;
|
||||
/* Tree of tsig keys, by wireformat name. */
|
||||
struct rbtree_type* tree;
|
||||
};
|
||||
|
||||
/**
|
||||
* Create TSIG key table.
|
||||
* @return NULL on alloc failure.
|
||||
*/
|
||||
struct tsig_key_table* tsig_key_table_create(void);
|
||||
|
||||
/**
|
||||
* Delete TSIG key table. And the keys in it.
|
||||
* @param key_table: to delete.
|
||||
*/
|
||||
void tsig_key_table_delete(struct tsig_key_table* key_table);
|
||||
|
||||
/** Add a key to the TSIG key table. */
|
||||
int tsig_key_table_add_key(struct tsig_key_table* key_table,
|
||||
struct config_tsig_key* s);
|
||||
|
||||
/** Delete a key from the TSIG key table. */
|
||||
void tsig_key_table_del_key_fromstr(struct tsig_key_table* key_table,
|
||||
char* name);
|
||||
|
||||
/**
|
||||
* Apply config to the tsig key table.
|
||||
* @param key_table: the tsig key table.
|
||||
* @param cfg: the config to read.
|
||||
* @return false on failure.
|
||||
*/
|
||||
int tsig_key_table_apply_cfg(struct tsig_key_table* key_table,
|
||||
struct config_file* cfg);
|
||||
|
||||
/**
|
||||
* Find key in key table. Caller must hold lock on the table.
|
||||
* @param key_table: the tsig key table.
|
||||
* @param name: name to look for in wireformat.
|
||||
* @param namelen: length of name.
|
||||
* @return the found key or NULL if not found. The item is locked
|
||||
* by the key_table lock.
|
||||
*/
|
||||
struct tsig_key* tsig_key_table_search(struct tsig_key_table* key_table,
|
||||
uint8_t* name, size_t namelen);
|
||||
|
||||
/**
|
||||
* Find key in key table. Caller must hold lock on the table.
|
||||
* @param key_table: the tsig key table.
|
||||
* @param name: the name in string format, it is parsed to wireformat.
|
||||
* @return the found key or NULL if not found or NULL on parse error of the
|
||||
* key name as a domain name. The item is locked by the key_table lock.
|
||||
*/
|
||||
struct tsig_key* tsig_key_table_search_fromstr(
|
||||
struct tsig_key_table* key_table, char* name);
|
||||
|
||||
/**
|
||||
* Get memory usage of tsig key table.
|
||||
* @param tsig_key_table: the tsig key table.
|
||||
* @return memory use.
|
||||
*/
|
||||
size_t tsig_key_table_get_mem(struct tsig_key_table* tsig_key_table);
|
||||
|
||||
/**
|
||||
* Swap internal tree with preallocated entries. Caller should manage
|
||||
* the locks.
|
||||
* @param tsig_key_table: the tsig_key_table data structure.
|
||||
* @param data: the data structure used to take elements from. This contains
|
||||
* the old elements on return.
|
||||
*/
|
||||
void tsig_key_table_swap_tree(struct tsig_key_table* tsig_key_table,
|
||||
struct tsig_key_table* data);
|
||||
|
||||
/**
|
||||
* Delete TSIG key.
|
||||
* @param key: to delete
|
||||
*/
|
||||
void tsig_key_delete(struct tsig_key* key);
|
||||
|
||||
/**
|
||||
* See if an algorithm name is in the list of accepted algorithm names.
|
||||
* @param algo_name: string to check
|
||||
* @return 0 on failure.
|
||||
*/
|
||||
int tsig_algo_check_name(const char* algo_name);
|
||||
|
||||
/**
|
||||
* Get the TSIG algorithm for the algorithm name.
|
||||
* @param algo_name: string to find.
|
||||
* @return NULL on failure, tsig algorithm structure.
|
||||
*/
|
||||
struct tsig_algorithm* tsig_algo_find_name(const char* algo_name);
|
||||
|
||||
/**
|
||||
* Get the TSIG algorithm for the algorithm wireformat name.
|
||||
* @param algo: wireformat algorithm name to find.
|
||||
* @return NULL on failure, tsig algorithm structure.
|
||||
*/
|
||||
struct tsig_algorithm* tsig_algo_find_wire(uint8_t* algo);
|
||||
|
||||
/**
|
||||
* Sign pkt with the name (domain name), algorithm and key in Base64.
|
||||
* out 0 on success, -1 on failure.
|
||||
* For a shared packet with contents. This signs a reply packet without
|
||||
* the prior hash, since there is no prior packet.
|
||||
*/
|
||||
int tsig_sign_shared(struct sldns_buffer* pkt, const uint8_t* name,
|
||||
const uint8_t* alg, const uint8_t* secret, size_t secret_len,
|
||||
uint64_t now);
|
||||
|
||||
/**
|
||||
* Verify pkt with the name (domain name), algorithm and key in Base64.
|
||||
* out 0 on success, an error code otherwise.
|
||||
* For a shared packet with contents. This verifies a reply packet without
|
||||
* the prior hash, since there is no prior packet.
|
||||
* out 0 on success, on failure:
|
||||
* -1 for malformed, no tsig RR, or too large for buffer.
|
||||
* >0 rcode with a TSIG error code otherwise.
|
||||
*/
|
||||
int tsig_verify_shared(struct sldns_buffer* pkt, const uint8_t* name,
|
||||
const uint8_t* alg, const uint8_t* secret, size_t secret_len,
|
||||
uint64_t now);
|
||||
|
||||
/** Compare function for the key table keys. */
|
||||
int tsig_key_compare(const void* v1, const void* v2);
|
||||
|
||||
/**
|
||||
* Find tsig key and create new tsig data.
|
||||
* @param key_table: the tsig key table.
|
||||
* @param name: key name in wireformat.
|
||||
* @param namelen: length of name.
|
||||
* @return NULL if not found, or alloc failure.
|
||||
*/
|
||||
struct tsig_data* tsig_create(struct tsig_key_table* key_table,
|
||||
uint8_t* name, size_t namelen);
|
||||
|
||||
/**
|
||||
* Find tsig key and create new tsig data.
|
||||
* @param key_table: the tsig key table.
|
||||
* @param name: key name string.
|
||||
* @return NULL if not found, or alloc failure, or could not parse string.
|
||||
*/
|
||||
struct tsig_data* tsig_create_fromstr(struct tsig_key_table* key_table,
|
||||
char* name);
|
||||
|
||||
/**
|
||||
* Delete tsig data.
|
||||
* @param tsig: the tsig data to delete.
|
||||
*/
|
||||
void tsig_delete(struct tsig_data* tsig);
|
||||
|
||||
/**
|
||||
* Get memory usage of tsig data.
|
||||
* @param rsig: the tsig data.
|
||||
* @return memory use.
|
||||
*/
|
||||
size_t tsig_get_mem(struct tsig_data* tsig);
|
||||
|
||||
/**
|
||||
* Sign a query with TSIG. Appends the TSIG record.
|
||||
* @param tsig: the tsig data, keeps state to verify reply.
|
||||
* @param pkt: query packet. position must be at end of packet.
|
||||
* @param key_table: the tsig key table is used to fetch the key details.
|
||||
* @param now: time to sign the query, the current time.
|
||||
* @return false on failure.
|
||||
*/
|
||||
int tsig_sign_query(struct tsig_data* tsig, struct sldns_buffer* pkt,
|
||||
struct tsig_key_table* key_table, uint64_t now);
|
||||
|
||||
/**
|
||||
* Verify a query with TSIG.
|
||||
* @param tsig: the tsig data, keep state to sign reply.
|
||||
* @param pkt: the query packet.
|
||||
* @param key: the key with algorithm, caller must hold lock.
|
||||
* @param rr: the tsig record parsed from the query.
|
||||
* @param now: time that is used, the current time.
|
||||
* @return rcode with failure for alloc failure or malformed wireformat.
|
||||
* 0 NOERROR is success, if tsig is nonNULL it has either verified
|
||||
* or contains a TSIG error.
|
||||
*/
|
||||
int tsig_verify_query(struct tsig_data* tsig, struct sldns_buffer* pkt,
|
||||
struct tsig_key* key, struct tsig_record* rr, uint64_t now);
|
||||
|
||||
/**
|
||||
* Look up key from TSIG in packet.
|
||||
* @param key_table: the tsig key table.
|
||||
* @param pkt: the packet to look at TSIG.
|
||||
* @param rr: the TSIG record parsed.
|
||||
* @param tsig_ret: the tsig key is returned here. Or it can be NULL, no TSIG.
|
||||
* @param region: if nonNULL used to allocate.
|
||||
* @param key: if the key is in the key_table the key is returned.
|
||||
* On success the key table is locked for the key.
|
||||
* @return fail for alloc failure servfail or wireformat malformed formerr,
|
||||
* success has 0 NOERROR, for no TSIG in packet with tsig returned NULL,
|
||||
* and for key not found with tsig returned with a tsig error in it,
|
||||
* and for key found with tsig returned with tsig in it.
|
||||
* After this call, the return value is the rcode for failure. Then the
|
||||
* tsig, is NULL for no TSIG, or nonNULL, with a TSIG error or content that
|
||||
* can be verified with tsig_verify_query.
|
||||
*/
|
||||
int tsig_lookup_key(struct tsig_key_table* key_table,
|
||||
struct sldns_buffer* pkt, struct tsig_record* rr,
|
||||
struct tsig_data** tsig_ret, struct regional* region,
|
||||
struct tsig_key** key);
|
||||
|
||||
/**
|
||||
* Parse a TSIG from the packet. Current position is just before it.
|
||||
* @param pkt: the packet.
|
||||
* @param rr: data filled in, with pointers to the packet buffer.
|
||||
* The key name can be compressed.
|
||||
* @return 0 if OK, otherwise an RCODE.
|
||||
*/
|
||||
int tsig_parse(struct sldns_buffer* pkt, struct tsig_record* rr);
|
||||
|
||||
/**
|
||||
* Parse and verify the TSIG in query packet.
|
||||
* @param key_table: the tsig key table.
|
||||
* @param pkt: the packet
|
||||
* @param tsig: the tsig key is returned. Or it can be NULL.
|
||||
* @param region: if nonNULL used to allocate.
|
||||
* @param now: time that is used, the current time.
|
||||
* @return rcode with failure for alloc failure or malformed wireformat.
|
||||
* 0 NOERROR is success, if tsig is nonNULL it has either verified
|
||||
* or contains a TSIG error.
|
||||
*/
|
||||
int tsig_parse_verify_query(struct tsig_key_table* key_table,
|
||||
struct sldns_buffer* pkt, struct tsig_data** tsig,
|
||||
struct regional* region, uint64_t now);
|
||||
|
||||
/**
|
||||
* Sign a reply with TSIG. Appends the TSIG record.
|
||||
* @param tsig: the tsig data.
|
||||
* @param pkt: the packet to sign.
|
||||
* @param key_table: the tsig key table is used to fetch the key details.
|
||||
* @param now: time to sign the query, the current time.
|
||||
* @return false on failure.
|
||||
*/
|
||||
int tsig_sign_reply(struct tsig_data* tsig, struct sldns_buffer* pkt,
|
||||
struct tsig_key_table* key_table, uint64_t now);
|
||||
|
||||
/**
|
||||
* Verify a reply with TSIG.
|
||||
* @param tsig: the tsig data.
|
||||
* @param pkt: the reply to verify.
|
||||
* @param key: the key with algorithm, caller must hold lock.
|
||||
* @param rr: the tsig record parsed from the reply.
|
||||
* @param now: time to sign the query, the current time.
|
||||
* @return false on failure, like
|
||||
* alloc failure, wireformat malformed, did not verify.
|
||||
*/
|
||||
int tsig_verify_reply(struct tsig_data* tsig, struct sldns_buffer* pkt,
|
||||
struct tsig_key* key, struct tsig_record* rr, uint64_t now);
|
||||
|
||||
/**
|
||||
* Verify a reply with TSIG.
|
||||
* @param tsig: the tsig data.
|
||||
* @param pkt: the reply to verify.
|
||||
* @param key_table: the tsig key table is used to fetch the key details.
|
||||
* @param now: time to sign the query, the current time.
|
||||
* @return false on failure, like
|
||||
* alloc failure, wireformat malformed, did not verify.
|
||||
*/
|
||||
int tsig_parse_verify_reply(struct tsig_data* tsig, struct sldns_buffer* pkt,
|
||||
struct tsig_key_table* key_table, uint64_t now);
|
||||
|
||||
/**
|
||||
* Calculate reserved space for TSIG.
|
||||
* @param tsig: the tsig data
|
||||
* @return number of bytes to keep reserved for the TSIG added.
|
||||
*/
|
||||
size_t tsig_reserved_space(struct tsig_data* tsig);
|
||||
|
||||
/**
|
||||
* See if the packet has a TSIG record, or not.
|
||||
* @param pkt: the packet.
|
||||
* @return false if malformed or no tsig. If found, the position is
|
||||
* just before the TSIG record. So it can be parsed.
|
||||
*/
|
||||
int tsig_find_rr(struct sldns_buffer* pkt);
|
||||
|
||||
/**
|
||||
* See if the packet as a TSIG, or not. Like tsig_find_rr, but it logs
|
||||
* no error for absence of a TSIG.
|
||||
* @param pkt: the packet
|
||||
* @return false if malformed, and false if no tsig. true if tsig,
|
||||
* and the position is just before the TSIG record. So it can be parsed.
|
||||
*/
|
||||
int tsig_in_packet(struct sldns_buffer* pkt);
|
||||
|
||||
/**
|
||||
* Sign XFR reply with TSIG. Appends the TSIG record. Call for later
|
||||
* packets too.
|
||||
* @param tsig: the tsig data. It must be malloced for the crypto state.
|
||||
* @param pkt: the packet to sign.
|
||||
* @param key_table: the tsig key table is used to fetch the key details.
|
||||
* @param now: time to sign the query, the current time.
|
||||
* @param last_packet: set to true for the last packet, that needs to be
|
||||
* TSIG signed.
|
||||
* @return false on failure.
|
||||
*/
|
||||
int tsig_sign_reply_xfr(struct tsig_data* tsig, struct sldns_buffer* pkt,
|
||||
struct tsig_key_table* key_table, uint64_t now, int last_packet);
|
||||
|
||||
/**
|
||||
* Verify XFR reply with TSIG.
|
||||
* @param tsig: the tsig data.
|
||||
* @param pkt: the reply to verify.
|
||||
* @param rr: the tsig record parsed from the reply.
|
||||
* @param now: time to sign the query, the current time.
|
||||
* @return false on failure, like
|
||||
* alloc failure, wireformat malformed, did not verify.
|
||||
*/
|
||||
int tsig_verify_reply_xfr(struct tsig_data* tsig, struct sldns_buffer* pkt,
|
||||
struct tsig_record* rr, uint64_t now);
|
||||
|
||||
/**
|
||||
* Parse and verify XFR reply with TSIG. Position at the TSIG record, or
|
||||
* at end of packet if no TSIG record.
|
||||
* @param tsig: the tsig data.
|
||||
* @param pkt: the reply to verify.
|
||||
* @param key_table: the tsig key table is used to fetch the key details.
|
||||
* @param now: time to sign the query, the current time.
|
||||
* @param last_packet: set true for the last packet, it must have a TSIG.
|
||||
* @return false on failure, like
|
||||
* alloc failure, wireformat malformed, did not verify.
|
||||
*/
|
||||
int tsig_parse_verify_reply_xfr(struct tsig_data* tsig,
|
||||
struct sldns_buffer* pkt, struct tsig_key_table* key_table,
|
||||
uint64_t now, int last_packet);
|
||||
|
||||
#endif /* UTIL_TSIG_H */
|
||||
Reference in New Issue
Block a user