mirror of
https://github.com/NLnetLabs/unbound.git
synced 2026-08-17 21:25:50 +02:00
Compare commits
175
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6cb2b251c5 | ||
|
|
41e1ffe1c4 | ||
|
|
5a6638fed0 | ||
|
|
fd3293a0ee | ||
|
|
0f7ced491e | ||
|
|
52e48a90ea | ||
|
|
2a5bcffcc2 | ||
|
|
931efbbaa0 | ||
|
|
74468b2edb | ||
|
|
f2ba9e985b | ||
|
|
553ebaf7a9 | ||
|
|
5043992159 | ||
|
|
463bd32b26 | ||
|
|
a81e19a6eb | ||
|
|
db695709e6 | ||
|
|
62e37fe3ee | ||
|
|
c6e92c19b2 | ||
|
|
9865f38f69 | ||
|
|
8959cd47a8 | ||
|
|
c968fc7581 | ||
|
|
cbd9764601 | ||
|
|
9c1f6e2df5 | ||
|
|
e8bcec4529 | ||
|
|
c4392dd54c | ||
|
|
748bfb0b0e | ||
|
|
6510d8f20a | ||
|
|
c7d15770c1 | ||
|
|
48aec18ef7 | ||
|
|
7987b687dc | ||
|
|
b22e1d4273 | ||
|
|
92198b3624 | ||
|
|
facde2ca10 | ||
|
|
d85debfae4 | ||
|
|
db452ffc16 | ||
|
|
26f9ea8942 | ||
|
|
b0b9193603 | ||
|
|
d2bf27acd7 | ||
|
|
149ff1cd5a | ||
|
|
08bf892be6 | ||
|
|
ab316be813 | ||
|
|
5134e8e1ae | ||
|
|
4736eaf80d | ||
|
|
a404373112 | ||
|
|
5f9e30aacb | ||
|
|
7b76e85956 | ||
|
|
cb3044c09d | ||
|
|
009a68a795 | ||
|
|
f52b202747 | ||
|
|
a9ea07cbb3 | ||
|
|
e384cdaf70 | ||
|
|
18a5fb1fc5 | ||
|
|
bf02cdbf5c | ||
|
|
4d473bd618 | ||
|
|
496c91c250 | ||
|
|
91786f4cc6 | ||
|
|
359d9ec426 | ||
|
|
d45774fe03 | ||
|
|
0e11cd160d | ||
|
|
bb67a404fb | ||
|
|
4016aa755e | ||
|
|
b33c39334b | ||
|
|
6fe044de03 | ||
|
|
81fe98956c | ||
|
|
ab143fd1f8 | ||
|
|
eb0deb1301 | ||
|
|
8351afe61a | ||
|
|
edbbacecf9 | ||
|
|
1e5a3fb786 | ||
|
|
7f4a12c652 | ||
|
|
49bb418691 | ||
|
|
2540d6c511 | ||
|
|
fd7af10ff6 | ||
|
|
f304a2a459 | ||
|
|
fceea2bcd5 | ||
|
|
45297772c9 | ||
|
|
a22a3b1669 | ||
|
|
341492391e | ||
|
|
de6d807e3d | ||
|
|
134db23ea8 | ||
|
|
e8a709a315 | ||
|
|
dd9da95c70 | ||
|
|
824ceffedb | ||
|
|
e839035a7a | ||
|
|
3d832f5dca | ||
|
|
459039cf08 | ||
|
|
60470b186e | ||
|
|
c988905aa4 | ||
|
|
af2b300529 | ||
|
|
0e90c03e95 | ||
|
|
f293924be8 | ||
|
|
f9cc9481e2 | ||
|
|
542b812690 | ||
|
|
674fdd5e39 | ||
|
|
c9107bfb1a | ||
|
|
5a62edfc26 | ||
|
|
87fafec48a | ||
|
|
a490e8777f | ||
|
|
3a422ba496 | ||
|
|
6890f55d17 | ||
|
|
b54a0400ab | ||
|
|
a7001366a1 | ||
|
|
a084af819c | ||
|
|
5c9f7c00ba | ||
|
|
cf4ef6fbaf | ||
|
|
9c8fd98719 | ||
|
|
272096d611 | ||
|
|
834a8fc30f | ||
|
|
0f9ae7acd8 | ||
|
|
5605f8d003 | ||
|
|
1b42a51048 | ||
|
|
3f8b0b1cfe | ||
|
|
453df0c66c | ||
|
|
cedeaa8316 | ||
|
|
9ddbb430ef | ||
|
|
568f0699dc | ||
|
|
24aad68487 | ||
|
|
e4aa70b4c5 | ||
|
|
f6371f11a4 | ||
|
|
ce290651d0 | ||
|
|
1d29f79974 | ||
|
|
927af50c81 | ||
|
|
f06b1e8ef3 | ||
|
|
c2b1ad1418 | ||
|
|
9db2d3fa78 | ||
|
|
8a290f6a16 | ||
|
|
016f27739d | ||
|
|
c49a3af953 | ||
|
|
7d07e1b9c3 | ||
|
|
f8719c1aa1 | ||
|
|
448a9f414f | ||
|
|
86723bd032 | ||
|
|
0374d468c8 | ||
|
|
2157540f35 | ||
|
|
749ee526e8 | ||
|
|
b12ae95d1d | ||
|
|
1dd6ef9f24 | ||
|
|
5166d65ea2 | ||
|
|
9ada9f1093 | ||
|
|
d5e4fa21de | ||
|
|
45f95a18af | ||
|
|
8f58908f45 | ||
|
|
bdb519c5c1 | ||
|
|
7726691af9 | ||
|
|
eb5ab1f8e6 | ||
|
|
b2639ba961 | ||
|
|
c3a5bcb8d4 | ||
|
|
ff4f04de2a | ||
|
|
b24aac895f | ||
|
|
188bfacd05 | ||
|
|
4eaa855db9 | ||
|
|
44560e40ea | ||
|
|
1d83bb84ed | ||
|
|
9ebbdbabd3 | ||
|
|
6d8e67e7f9 | ||
|
|
eb1b1e6044 | ||
|
|
d48e17e1dd | ||
|
|
669a20084c | ||
|
|
6b8f7df843 | ||
|
|
37a906991e | ||
|
|
fd3e3ed05b | ||
|
|
ce12d59957 | ||
|
|
c70c747c04 | ||
|
|
6849c1030b | ||
|
|
947bd1ab91 | ||
|
|
c9a1cdec68 | ||
|
|
dba780a00c | ||
|
|
4f8f9f2f74 | ||
|
|
630d9dbc94 | ||
|
|
c3f6bcb89a | ||
|
|
62b02dc911 | ||
|
|
2122b961d3 | ||
|
|
56916e48fb | ||
|
|
ec4878be75 | ||
|
|
ac895c6d35 | ||
|
|
39e8652152 |
+31
-7
@@ -53,11 +53,12 @@ LINTFLAGS+="-DBN_ULONG=unsigned long" -Dkrb5_int32=int "-Dkrb5_ui_4=unsigned int
|
||||
INSTALL=$(srcdir)/install-sh
|
||||
|
||||
COMMON_SRC=$(wildcard services/*.c services/cache/*.c util/*.c \
|
||||
util/data/*.c util/storage/*.c iterator/*.c) util/configparser.c \
|
||||
util/configlexer.c testcode/checklocks.c
|
||||
util/data/*.c util/storage/*.c iterator/*.c validator/*.c) \
|
||||
util/configparser.c util/configlexer.c testcode/checklocks.c
|
||||
COMMON_OBJ=$(addprefix $(BUILD),$(COMMON_SRC:.c=.o))
|
||||
COMPAT_OBJ=$(addprefix $(BUILD)compat/,$(LIBOBJS))
|
||||
UNITTEST_SRC=$(wildcard testcode/unit*.c) testcode/readhex.c $(COMMON_SRC)
|
||||
UNITTEST_SRC=$(wildcard testcode/unit*.c) testcode/readhex.c \
|
||||
testcode/ldns-testpkts.c $(COMMON_SRC)
|
||||
UNITTEST_OBJ=$(addprefix $(BUILD),$(UNITTEST_SRC:.c=.o)) $(COMPAT_OBJ)
|
||||
DAEMON_SRC=$(wildcard daemon/*.c) $(COMMON_SRC)
|
||||
DAEMON_OBJ=$(addprefix $(BUILD),$(DAEMON_SRC:.c=.o)) $(COMPAT_OBJ)
|
||||
@@ -70,13 +71,18 @@ LOCKVERIFY_SRC=testcode/lock_verify.c $(COMMON_SRC)
|
||||
LOCKVERIFY_OBJ=$(addprefix $(BUILD),$(LOCKVERIFY_SRC:.c=.o)) $(COMPAT_OBJ)
|
||||
PKTVIEW_SRC=testcode/pktview.c testcode/readhex.c $(COMMON_SRC)
|
||||
PKTVIEW_OBJ=$(addprefix $(BUILD),$(PKTVIEW_SRC:.c=.o)) $(COMPAT_OBJ)
|
||||
SIGNIT_SRC=testcode/signit.c $(COMMON_SRC)
|
||||
SIGNIT_OBJ=$(addprefix $(BUILD),$(SIGNIT_SRC:.c=.o)) $(COMPAT_OBJ)
|
||||
MEMSTATS_SRC=testcode/memstats.c $(COMMON_SRC)
|
||||
MEMSTATS_OBJ=$(addprefix $(BUILD),$(MEMSTATS_SRC:.c=.o)) $(COMPAT_OBJ)
|
||||
ALL_SRC=$(COMMON_SRC) $(UNITTEST_SRC) $(DAEMON_SRC) \
|
||||
$(TESTBOUND_SRC) $(LOCKVERIFY_SRC)
|
||||
$(TESTBOUND_SRC) $(LOCKVERIFY_SRC) $(PKTVIEW_SRC) $(SIGNIT_SRC) \
|
||||
$(MEMSTATS_SRC)
|
||||
ALL_OBJ=$(addprefix $(BUILD),$(ALL_SRC:.c=.o) \
|
||||
$(addprefix compat/,$(LIBOBJS))) $(COMPAT_OBJ)
|
||||
|
||||
COMPILE=$(LIBTOOL) --tag=CC --mode=compile $(CC) $(CPPFLAGS) $(CFLAGS)
|
||||
LINK=$(LIBTOOL) --tag=CC --mode=link $(CC) $(staticexe) $(CFLAGS) $(LDFLAGS)
|
||||
LINK=$(LIBTOOL) --tag=CC --mode=link $(CC) $(staticexe) $(RUNTIME_PATH) $(CFLAGS) $(LDFLAGS)
|
||||
LINK_LIB=$(LIBTOOL) --tag=CC --mode=link $(CC) $(CFLAGS) $(LDFLAGS) -release $(VERSION)
|
||||
|
||||
$(BUILD)%.o: $(srcdir)/%.c
|
||||
@@ -84,9 +90,14 @@ $(BUILD)%.o: $(srcdir)/%.c
|
||||
@if test ! -d $(dir $@); then $(INSTALL) -d $(patsubst %/,%,$(dir $@)); fi
|
||||
$Q$(COMPILE) -c $< -o $@
|
||||
|
||||
.PHONY: clean realclean doc lint all install uninstall
|
||||
.PHONY: clean realclean doc lint all install uninstall tests test
|
||||
|
||||
all: $(COMMON_OBJ) unbound unittest testbound lock-verify pktview
|
||||
all: $(COMMON_OBJ) unbound
|
||||
|
||||
tests: unittest testbound lock-verify pktview signit memstats
|
||||
|
||||
test: tests
|
||||
bash testcode/do-tests.sh
|
||||
|
||||
unbound: $(DAEMON_OBJ)
|
||||
$(INFO) Link $@
|
||||
@@ -108,6 +119,14 @@ pktview: $(PKTVIEW_OBJ)
|
||||
$(INFO) Link $@
|
||||
$Q$(LINK) -o $@ $^ $(LIBS)
|
||||
|
||||
signit: $(SIGNIT_OBJ)
|
||||
$(INFO) Link $@
|
||||
$Q$(LINK) -o $@ $^ $(LIBS)
|
||||
|
||||
memstats: $(MEMSTATS_OBJ)
|
||||
$(INFO) Link $@
|
||||
$Q$(LINK) -o $@ $^ $(LIBS)
|
||||
|
||||
#testcode/ldns-testpkts.c: $(ldnsdir)/examples/ldns-testpkts.c \
|
||||
# $(ldnsdir)/examples/ldns-testpkts.h
|
||||
# cp $(ldnsdir)/examples/ldns-testpkts.c testcode/ldns-testpkts.c
|
||||
@@ -116,9 +135,14 @@ pktview: $(PKTVIEW_OBJ)
|
||||
util/config_file.c: util/configparser.h
|
||||
util/configlexer.c: $(srcdir)/util/configlexer.lex util/configparser.h
|
||||
$(INFO) Lex $<
|
||||
ifeq "$(strip $(LEX))" ":"
|
||||
$Qecho "Need to rebuild lexer, but no lex program"
|
||||
exit 1
|
||||
else
|
||||
@if test ! -d util; then $(INSTALL) -d util; fi
|
||||
$Qecho "#include \"util/configyyrename.h\"" > $@
|
||||
$Q$(LEX) -t $< >> $@
|
||||
endif
|
||||
|
||||
util/configparser.c util/configparser.h: $(srcdir)/util/configparser.y
|
||||
$(INFO) Yacc $<
|
||||
|
||||
+55
-9
@@ -2,7 +2,7 @@
|
||||
# Process this file with autoconf to produce a configure script.
|
||||
AC_PREREQ(2.57)
|
||||
|
||||
AC_INIT(unbound, 0.4, wouter@nlnetlabs.nl, unbound)
|
||||
AC_INIT(unbound, 0.5, wouter@nlnetlabs.nl, unbound)
|
||||
|
||||
CFLAGS=
|
||||
AC_AIX
|
||||
@@ -359,14 +359,14 @@ CHECK_YYUNPUT
|
||||
# Checks for libraries.
|
||||
AC_ARG_WITH(ssl, AC_HELP_STRING([--with-ssl=pathname],
|
||||
[enable SSL (will check /usr/local/ssl
|
||||
/usr/lib/ssl /usr/ssl /usr/pkg /usr/local /usr/sfw /usr)]),[
|
||||
/usr/lib/ssl /usr/ssl /usr/pkg /usr/local /opt/local /usr/sfw /usr)]),[
|
||||
],[
|
||||
withval="yes"
|
||||
])
|
||||
if test x_$withval != x_no; then
|
||||
AC_MSG_CHECKING(for SSL)
|
||||
if test x_$withval = x_ -o x_$withval = x_yes; then
|
||||
withval="/usr/local/ssl /usr/lib/ssl /usr/ssl /usr/pkg /usr/local /usr/sfw /usr"
|
||||
withval="/usr/local/ssl /usr/lib/ssl /usr/ssl /usr/pkg /usr/local /opt/local /usr/sfw /usr"
|
||||
fi
|
||||
for dir in $withval; do
|
||||
ssldir="$dir"
|
||||
@@ -392,10 +392,11 @@ AC_ARG_WITH(ssl, AC_HELP_STRING([--with-ssl=pathname],
|
||||
AC_SUBST(RUNTIME_PATH)
|
||||
fi
|
||||
AC_CHECK_HEADERS([openssl/ssl.h],,, [AC_INCLUDES_DEFAULT])
|
||||
AC_CHECK_HEADERS([openssl/err.h],,, [AC_INCLUDES_DEFAULT])
|
||||
|
||||
# check for thread library.
|
||||
AC_ARG_WITH(pthreads, AC_HELP_STRING([--with-pthreads],
|
||||
[use pthreads library, or --without--pthreads to disable threading support.]),
|
||||
[use pthreads library, or --without-pthreads to disable threading support.]),
|
||||
[ ],[ withval="yes" ])
|
||||
ub_have_pthreads=no
|
||||
if test x_$withval != x_no; then
|
||||
@@ -406,7 +407,7 @@ if test x_$withval != x_no; then
|
||||
CFLAGS="$CFLAGS $PTHREAD_CFLAGS"
|
||||
CC="$PTHREAD_CC"
|
||||
ub_have_pthreads=yes
|
||||
AC_CHECK_TYPES(pthread_spinlock_t,,,[#include <pthread.h>])
|
||||
AC_CHECK_TYPES([pthread_spinlock_t, pthread_rwlock_t],,,[#include <pthread.h>])
|
||||
])
|
||||
fi
|
||||
|
||||
@@ -429,14 +430,16 @@ if test x_$withval != x_no; then
|
||||
fi
|
||||
fi
|
||||
|
||||
# check for library used by libevent after 1.3c
|
||||
AC_CHECK_LIB(rt, clock_gettime)
|
||||
# check for libevent
|
||||
AC_ARG_WITH(libevent, AC_HELP_STRING([--with-libevent=pathname],
|
||||
[set path to libevent (will check /usr/local /usr/lib /usr/pkg /usr/sfw /usr)]),
|
||||
[set path to libevent (will check /usr/local /opt/local /usr/lib /usr/pkg /usr/sfw /usr)]),
|
||||
[ ],[ withval="yes" ])
|
||||
if test x_$withval != x_no; then
|
||||
AC_MSG_CHECKING(for libevent)
|
||||
if test x_$withval = x_ -o x_$withval = x_yes; then
|
||||
withval="/usr/local /usr/lib /usr/pkg /usr/sfw /usr";
|
||||
withval="/usr/local /opt/local /usr/lib /usr/pkg /usr/sfw /usr";
|
||||
fi
|
||||
for dir in $withval; do
|
||||
thedir="$dir"
|
||||
@@ -453,7 +456,10 @@ if test x_$withval != x_no; then
|
||||
CPPFLAGS="$CPPFLAGS -I$thedir";
|
||||
LDFLAGS="$thedir/.libs/*.o $LDFLAGS";
|
||||
else
|
||||
AC_MSG_ERROR(Cannot find the libevent library in $withval)
|
||||
AC_MSG_ERROR([Cannot find the libevent library in $withval
|
||||
You can restart configure with --with-libevent=no to use a builtin alternative.
|
||||
Please note that this alternative is not as capable as libevent when using
|
||||
many outgoing ports. ])
|
||||
fi
|
||||
else
|
||||
AC_MSG_RESULT(found in $thedir)
|
||||
@@ -479,13 +485,30 @@ if test x_$enable_static_exe = x_yes; then
|
||||
staticexe="-static"
|
||||
fi
|
||||
|
||||
# set lock checking if requested
|
||||
AC_ARG_ENABLE(lock_checks, AC_HELP_STRING([--enable-lock-checks],
|
||||
[ enable to check lock and unlock calls, for debug purposes ]),
|
||||
, )
|
||||
if test x_$enable_lock_checks = x_yes; then
|
||||
AC_DEFINE(ENABLE_LOCK_CHECKS, 1, [Define if you want to use debug lock checking (slow).])
|
||||
fi
|
||||
|
||||
# set memory allocation checking if requested
|
||||
AC_ARG_ENABLE(alloc-checks, AC_HELP_STRING([--enable-alloc-checks],
|
||||
[ enable to check memory allocation, for debug purposes ]),
|
||||
, )
|
||||
if test x_$enable_alloc_checks = x_yes; then
|
||||
AC_DEFINE(UNBOUND_ALLOC_STATS, 1, [use statistics for allocs and frees, for debug use])
|
||||
else
|
||||
AC_FUNC_MALLOC
|
||||
fi
|
||||
|
||||
# check to see if libraries are needed for these functions.
|
||||
AC_CHECK_LIB(socket, socket)
|
||||
AC_CHECK_LIB(nsl, inet_pton)
|
||||
|
||||
AC_FUNC_CHOWN
|
||||
AC_FUNC_FORK
|
||||
AC_FUNC_MALLOC
|
||||
AC_TYPE_SIGNAL
|
||||
AC_FUNC_FSEEKO
|
||||
AC_SYS_LARGEFILE
|
||||
@@ -558,6 +581,10 @@ AH_BOTTOM([
|
||||
#include <getopt.h>
|
||||
#endif
|
||||
|
||||
#ifdef HAVE_OPENSSL_ERR_H
|
||||
#include <openssl/err.h>
|
||||
#endif
|
||||
|
||||
#ifdef HAVE_ATTR_FORMAT
|
||||
# define ATTR_FORMAT(archetype, string_index, first_to_check) \
|
||||
__attribute__ ((format (archetype, string_index, first_to_check)))
|
||||
@@ -629,6 +656,25 @@ struct sockaddr_storage;
|
||||
|
||||
#include "ldns/ldns.h"
|
||||
|
||||
#ifdef UNBOUND_ALLOC_STATS
|
||||
# define malloc(s) unbound_stat_malloc_log(s, __FILE__, __LINE__, __func__)
|
||||
# define calloc(n,s) unbound_stat_calloc_log(n, s, __FILE__, __LINE__, __func__)
|
||||
# define free(p) unbound_stat_free_log(p, __FILE__, __LINE__, __func__)
|
||||
# define realloc(p,s) unbound_stat_realloc_log(p, s, __FILE__, __LINE__, __func__)
|
||||
void *unbound_stat_malloc(size_t size);
|
||||
void *unbound_stat_calloc(size_t nmemb, size_t size);
|
||||
void unbound_stat_free(void *ptr);
|
||||
void *unbound_stat_realloc(void *ptr, size_t size);
|
||||
void *unbound_stat_malloc_log(size_t size, const char* file, int line,
|
||||
const char* func);
|
||||
void *unbound_stat_calloc_log(size_t nmemb, size_t size, const char* file,
|
||||
int line, const char* func);
|
||||
void unbound_stat_free_log(void *ptr, const char* file, int line,
|
||||
const char* func);
|
||||
void *unbound_stat_realloc_log(void *ptr, size_t size, const char* file,
|
||||
int line, const char* func);
|
||||
#endif /* UNBOUND_ALLOC_STATS */
|
||||
|
||||
/** default port for DNS traffic. */
|
||||
#define UNBOUND_DNS_PORT 53
|
||||
])
|
||||
|
||||
+101
-13
@@ -39,9 +39,6 @@
|
||||
* The daemon consists of global settings and a number of workers.
|
||||
*/
|
||||
|
||||
/** buffer size for network connections */
|
||||
#define BUFSZ 65552
|
||||
|
||||
#include "config.h"
|
||||
#include "daemon/daemon.h"
|
||||
#include "daemon/worker.h"
|
||||
@@ -54,6 +51,7 @@
|
||||
#include "services/cache/infra.h"
|
||||
#include "util/module.h"
|
||||
#include "iterator/iterator.h"
|
||||
#include "validator/validator.h"
|
||||
#include <signal.h>
|
||||
|
||||
/** How many quit requests happened. */
|
||||
@@ -124,6 +122,7 @@ daemon_init()
|
||||
return NULL;
|
||||
signal_handling_record();
|
||||
checklock_start();
|
||||
ERR_load_crypto_strings();
|
||||
daemon->need_to_exit = 0;
|
||||
daemon->num_modules = 0;
|
||||
if(!(daemon->env = (struct module_env*)calloc(1,
|
||||
@@ -148,6 +147,93 @@ daemon_open_shared_ports(struct daemon* daemon)
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** count number of modules (words) in the string */
|
||||
static int
|
||||
count_modules(const char* s)
|
||||
{
|
||||
int num = 0;
|
||||
if(!s)
|
||||
return 0;
|
||||
while(*s) {
|
||||
/* skip whitespace */
|
||||
while(*s && isspace((int)*s))
|
||||
s++;
|
||||
if(*s && !isspace((int)*s)) {
|
||||
/* skip identifier */
|
||||
num++;
|
||||
while(*s && !isspace((int)*s))
|
||||
s++;
|
||||
}
|
||||
}
|
||||
return num;
|
||||
}
|
||||
|
||||
/**
|
||||
* Get funcblock for module name
|
||||
* @param str: string with module name. Advanced to next value on success.
|
||||
* @return funcblock or NULL on error.
|
||||
*/
|
||||
static struct module_func_block*
|
||||
daemon_module_factory(const char** str)
|
||||
{
|
||||
/* these are the modules available */
|
||||
int num = 2;
|
||||
const char* names[] = {"iterator", "validator", NULL};
|
||||
struct module_func_block* (*fb[])(void) =
|
||||
{&iter_get_funcblock, &val_get_funcblock, NULL};
|
||||
|
||||
int i;
|
||||
const char* s = *str;
|
||||
while(*s && isspace((int)*s))
|
||||
s++;
|
||||
for(i=0; i<num; i++) {
|
||||
if(strncmp(names[i], s, strlen(names[i])) == 0) {
|
||||
s += strlen(names[i]);
|
||||
*str = s;
|
||||
return (*fb[i])();
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/**
|
||||
* Read config file module settings and set up the modfunc block
|
||||
* @param daemon: the daemon.
|
||||
* @return false on error
|
||||
*/
|
||||
static int
|
||||
daemon_config_modules(struct daemon* daemon)
|
||||
{
|
||||
const char* str = daemon->cfg->module_conf;
|
||||
int i;
|
||||
verbose(VERB_DETAIL, "module config: \"%s\"", str);
|
||||
daemon->num_modules = count_modules(str);
|
||||
if(daemon->num_modules == 0) {
|
||||
log_err("error: no modules specified");
|
||||
return 0;
|
||||
}
|
||||
if(daemon->num_modules > MAX_MODULE) {
|
||||
log_err("error: too many modules (%d max %d)",
|
||||
daemon->num_modules, MAX_MODULE);
|
||||
return 0;
|
||||
}
|
||||
daemon->modfunc = (struct module_func_block**)calloc((size_t)
|
||||
daemon->num_modules, sizeof(struct module_func_block*));
|
||||
if(!daemon->modfunc) {
|
||||
log_err("out of memory");
|
||||
return 0;
|
||||
}
|
||||
for(i=0; i<daemon->num_modules; i++) {
|
||||
daemon->modfunc[i] = daemon_module_factory(&str);
|
||||
if(!daemon->modfunc[i]) {
|
||||
log_err("Unknown value for first module in: '%s'",
|
||||
str);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
/**
|
||||
* Desetup the modules, deinit, delete.
|
||||
* @param daemon: the daemon.
|
||||
@@ -174,18 +260,15 @@ static void daemon_setup_modules(struct daemon* daemon)
|
||||
if(daemon->num_modules != 0)
|
||||
daemon_desetup_modules(daemon);
|
||||
/* fixed setup of the modules */
|
||||
daemon->num_modules = 1;
|
||||
daemon->modfunc = (struct module_func_block**)calloc((size_t)
|
||||
daemon->num_modules, sizeof(struct module_func_block*));
|
||||
if(!daemon->modfunc) {
|
||||
fatal_exit("malloc failure allocating function callbacks");
|
||||
if(!daemon_config_modules(daemon)) {
|
||||
fatal_exit("failed to setup modules");
|
||||
}
|
||||
daemon->modfunc[0] = iter_get_funcblock();
|
||||
daemon->env->cfg = daemon->cfg;
|
||||
daemon->env->alloc = &daemon->superalloc;
|
||||
daemon->env->worker = NULL;
|
||||
daemon->env->send_packet = &worker_send_packet;
|
||||
daemon->env->send_query = &worker_send_query;
|
||||
daemon->env->need_to_validate = 0; /* set by module init below */
|
||||
for(i=0; i<daemon->num_modules; i++) {
|
||||
log_info("init module %d: %s", i, daemon->modfunc[i]->name);
|
||||
if(!(*daemon->modfunc[i]->init)(daemon->env, i)) {
|
||||
@@ -252,8 +335,7 @@ thread_start(void* arg)
|
||||
worker->cmd_send_fd = -1;
|
||||
close_other_pipes(worker->daemon, worker->thread_num);
|
||||
#endif
|
||||
if(!worker_init(worker, worker->daemon->cfg, worker->daemon->ports,
|
||||
BUFSZ, 0))
|
||||
if(!worker_init(worker, worker->daemon->cfg, worker->daemon->ports, 0))
|
||||
fatal_exit("Could not initialize thread");
|
||||
|
||||
worker_work(worker);
|
||||
@@ -328,8 +410,7 @@ daemon_fork(struct daemon* daemon)
|
||||
/* Special handling for the main thread. This is the thread
|
||||
* that handles signals.
|
||||
*/
|
||||
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports,
|
||||
BUFSZ, 1))
|
||||
if(!worker_init(daemon->workers[0], daemon->cfg, daemon->ports, 1))
|
||||
fatal_exit("Could not initialize main thread");
|
||||
signal_handling_playback(daemon->workers[0]);
|
||||
|
||||
@@ -379,5 +460,12 @@ daemon_delete(struct daemon* daemon)
|
||||
free(daemon->pidfile);
|
||||
free(daemon->env);
|
||||
free(daemon);
|
||||
/* libcrypto cleanup */
|
||||
/* CONF_modules_unload(1); */
|
||||
EVP_cleanup();
|
||||
/* ENGINE_cleanup(); */
|
||||
CRYPTO_cleanup_all_ex_data(); /* safe, no more threads right now */
|
||||
ERR_remove_state(0);
|
||||
ERR_free_strings();
|
||||
checklock_stop();
|
||||
}
|
||||
|
||||
+9
-1
@@ -55,6 +55,9 @@
|
||||
#include <pwd.h>
|
||||
#include <sys/resource.h>
|
||||
|
||||
/** global debug value to keep track of heap memory allocation */
|
||||
void* unbound_start_brk = 0;
|
||||
|
||||
/** print usage. */
|
||||
static void usage()
|
||||
{
|
||||
@@ -74,7 +77,8 @@ static void
|
||||
checkrlimits(struct config_file* cfg)
|
||||
{
|
||||
int list = ((cfg->do_ip4?1:0) + (cfg->do_ip6?1:0)) *
|
||||
((cfg->do_udp?1:0) + (cfg->do_tcp?1 + TCP_ACCEPT_COUNT:0));
|
||||
((cfg->do_udp?1:0) + (cfg->do_tcp?1 +
|
||||
(int)cfg->incoming_num_tcp:0));
|
||||
size_t ifs = (size_t)(cfg->num_ifs==0?1:cfg->num_ifs);
|
||||
size_t listen_num = list*ifs;
|
||||
size_t outnum = cfg->outgoing_num_ports*ifs + cfg->outgoing_num_tcp;
|
||||
@@ -359,6 +363,9 @@ main(int argc, char* argv[])
|
||||
int cmdline_verbose = 0;
|
||||
int debug_mode = 0;
|
||||
|
||||
/* take debug snapshot of heap */
|
||||
unbound_start_brk = sbrk(0);
|
||||
|
||||
log_init(NULL);
|
||||
/* parse the options */
|
||||
while( (c=getopt(argc, argv, "c:dhv")) != -1) {
|
||||
@@ -389,5 +396,6 @@ main(int argc, char* argv[])
|
||||
}
|
||||
|
||||
run_daemon(cfgfile, cmdline_verbose, debug_mode);
|
||||
log_init(NULL); /* close logfile */
|
||||
return 0;
|
||||
}
|
||||
|
||||
+288
-40
@@ -55,6 +55,7 @@
|
||||
#include "services/outbound_list.h"
|
||||
#include "services/cache/rrset.h"
|
||||
#include "services/cache/infra.h"
|
||||
#include "services/cache/dns.h"
|
||||
#include "services/mesh.h"
|
||||
#include "util/data/msgparse.h"
|
||||
#include "util/data/msgencode.h"
|
||||
@@ -69,32 +70,94 @@
|
||||
/** Size of an UDP datagram */
|
||||
#define NORMAL_UDP_SIZE 512 /* bytes */
|
||||
|
||||
/** Report on memory usage by this thread and global */
|
||||
#ifdef UNBOUND_ALLOC_STATS
|
||||
/** measure memory leakage */
|
||||
static void
|
||||
worker_mem_report(struct worker* worker)
|
||||
debug_memleak(size_t accounted, size_t heap,
|
||||
size_t total_alloc, size_t total_free)
|
||||
{
|
||||
static int init = 0;
|
||||
static size_t base_heap, base_accounted, base_alloc, base_free;
|
||||
size_t base_af, cur_af, grow_af, grow_acc;
|
||||
if(!init) {
|
||||
init = 1;
|
||||
base_heap = heap;
|
||||
base_accounted = accounted;
|
||||
base_alloc = total_alloc;
|
||||
base_free = total_free;
|
||||
}
|
||||
base_af = base_alloc - base_free;
|
||||
cur_af = total_alloc - total_free;
|
||||
grow_af = cur_af - base_af;
|
||||
grow_acc = accounted - base_accounted;
|
||||
log_info("Leakage: %d leaked. growth: %u use, %u acc, %u heap",
|
||||
(int)(grow_af - grow_acc), (unsigned)grow_af,
|
||||
(unsigned)grow_acc, (unsigned)(heap - base_heap));
|
||||
}
|
||||
|
||||
/** give debug heap size indication */
|
||||
static void
|
||||
debug_total_mem(size_t calctotal)
|
||||
{
|
||||
extern void* unbound_start_brk;
|
||||
extern size_t unbound_mem_alloc, unbound_mem_freed;
|
||||
void* cur = sbrk(0);
|
||||
int total = cur-unbound_start_brk;
|
||||
log_info("Total heap memory estimate: %u total-alloc: %u "
|
||||
"total-free: %u", (unsigned)total,
|
||||
(unsigned)unbound_mem_alloc, (unsigned)unbound_mem_freed);
|
||||
debug_memleak(calctotal, (size_t)total,
|
||||
unbound_mem_alloc, unbound_mem_freed);
|
||||
}
|
||||
#endif /* UNBOUND_ALLOC_STATS */
|
||||
|
||||
/** Report on memory usage by this thread and global */
|
||||
void
|
||||
worker_mem_report(struct worker* ATTR_UNUSED(worker),
|
||||
struct serviced_query* ATTR_UNUSED(cur_serv))
|
||||
{
|
||||
#ifdef UNBOUND_ALLOC_STATS
|
||||
/* debug func in validator module */
|
||||
size_t total, front, back, mesh, msg, rrset, infra, ac, superac;
|
||||
size_t me;
|
||||
size_t me, iter, val;
|
||||
int i;
|
||||
if(verbosity < VERB_ALGO)
|
||||
return;
|
||||
front = listen_get_mem(worker->front);
|
||||
back = outnet_get_mem(worker->back);
|
||||
msg = slabhash_get_mem(worker->env.msg_cache);
|
||||
rrset = slabhash_get_mem(&worker->env.rrset_cache->table);
|
||||
infra = slabhash_get_mem(worker->env.infra_cache->hosts);
|
||||
infra = infra_get_mem(worker->env.infra_cache);
|
||||
mesh = mesh_get_mem(worker->env.mesh);
|
||||
ac = alloc_get_mem(&worker->alloc);
|
||||
superac = alloc_get_mem(&worker->daemon->superalloc);
|
||||
iter = 0;
|
||||
val = 0;
|
||||
for(i=0; i<worker->env.mesh->num_modules; i++) {
|
||||
if(strcmp(worker->env.mesh->modfunc[i]->name, "validator")==0)
|
||||
val += (*worker->env.mesh->modfunc[i]->get_mem)
|
||||
(&worker->env, i);
|
||||
else iter += (*worker->env.mesh->modfunc[i]->get_mem)
|
||||
(&worker->env, i);
|
||||
}
|
||||
me = sizeof(*worker) + sizeof(*worker->base) + sizeof(*worker->comsig)
|
||||
+ comm_point_get_mem(worker->cmd_com) +
|
||||
sizeof(worker->rndstate) + region_get_mem(worker->scratchpad);
|
||||
total = front+back+mesh+msg+rrset+infra+ac+superac+me;
|
||||
sizeof(worker->rndstate) + region_get_mem(worker->scratchpad)+
|
||||
sizeof(*worker->env.scratch_buffer) +
|
||||
ldns_buffer_capacity(worker->env.scratch_buffer);
|
||||
if(cur_serv) {
|
||||
me += serviced_get_mem(cur_serv);
|
||||
}
|
||||
total = front+back+mesh+msg+rrset+infra+iter+val+ac+superac+me;
|
||||
log_info("Memory conditions: %u front=%u back=%u mesh=%u msg=%u "
|
||||
"rrset=%u infra=%u alloccache=%u globalalloccache=%u me=%u",
|
||||
"rrset=%u infra=%u iter=%u val=%u "
|
||||
"alloccache=%u globalalloccache=%u me=%u",
|
||||
(unsigned)total, (unsigned)front, (unsigned)back,
|
||||
(unsigned)mesh, (unsigned)msg, (unsigned)rrset,
|
||||
(unsigned)infra, (unsigned)ac, (unsigned)superac,
|
||||
(unsigned)me);
|
||||
(unsigned)infra, (unsigned)iter, (unsigned)val, (unsigned)ac,
|
||||
(unsigned)superac, (unsigned)me);
|
||||
debug_total_mem(total);
|
||||
#endif /* UNBOUND_ALLOC_STATS */
|
||||
}
|
||||
|
||||
void
|
||||
@@ -124,7 +187,7 @@ worker_handle_reply(struct comm_point* c, void* arg, int error,
|
||||
|
||||
if(error != 0) {
|
||||
mesh_report_reply(worker->env.mesh, &e, 0, reply_info);
|
||||
worker_mem_report(worker);
|
||||
worker_mem_report(worker, NULL);
|
||||
return 0;
|
||||
}
|
||||
/* sanity check. */
|
||||
@@ -135,11 +198,11 @@ worker_handle_reply(struct comm_point* c, void* arg, int error,
|
||||
/* error becomes timeout for the module as if this reply
|
||||
* never arrived. */
|
||||
mesh_report_reply(worker->env.mesh, &e, 0, reply_info);
|
||||
worker_mem_report(worker);
|
||||
worker_mem_report(worker, NULL);
|
||||
return 0;
|
||||
}
|
||||
mesh_report_reply(worker->env.mesh, &e, 1, reply_info);
|
||||
worker_mem_report(worker);
|
||||
worker_mem_report(worker, NULL);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -150,11 +213,12 @@ worker_handle_service_reply(struct comm_point* c, void* arg, int error,
|
||||
{
|
||||
struct outbound_entry* e = (struct outbound_entry*)arg;
|
||||
struct worker* worker = e->qstate->env->worker;
|
||||
struct serviced_query *sq = e->qsent;
|
||||
|
||||
verbose(VERB_ALGO, "worker scvd callback for qstate %p", e->qstate);
|
||||
verbose(VERB_ALGO, "worker svcd callback for qstate %p", e->qstate);
|
||||
if(error != 0) {
|
||||
mesh_report_reply(worker->env.mesh, e, 0, reply_info);
|
||||
worker_mem_report(worker);
|
||||
worker_mem_report(worker, sq);
|
||||
return 0;
|
||||
}
|
||||
/* sanity check. */
|
||||
@@ -166,11 +230,11 @@ worker_handle_service_reply(struct comm_point* c, void* arg, int error,
|
||||
* never arrived. */
|
||||
verbose(VERB_ALGO, "worker: bad reply handled as timeout");
|
||||
mesh_report_reply(worker->env.mesh, e, 0, reply_info);
|
||||
worker_mem_report(worker);
|
||||
worker_mem_report(worker, sq);
|
||||
return 0;
|
||||
}
|
||||
mesh_report_reply(worker->env.mesh, e, 1, reply_info);
|
||||
worker_mem_report(worker);
|
||||
worker_mem_report(worker, sq);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -257,6 +321,130 @@ worker_handle_control_cmd(struct comm_point* c, void* arg, int error,
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** check if a delegation is secure */
|
||||
static enum sec_status
|
||||
check_delegation_secure(struct reply_info *rep)
|
||||
{
|
||||
/* return smallest security status */
|
||||
size_t i;
|
||||
enum sec_status sec = sec_status_secure;
|
||||
enum sec_status s;
|
||||
size_t num = rep->an_numrrsets + rep->ns_numrrsets;
|
||||
/* check if answer and authority are OK */
|
||||
for(i=0; i<num; i++) {
|
||||
s = ((struct packed_rrset_data*)rep->rrsets[i]->entry.data)
|
||||
->security;
|
||||
if(s < sec)
|
||||
sec = s;
|
||||
}
|
||||
/* in additional, only unchecked triggers revalidation */
|
||||
for(i=num; i<rep->rrset_count; i++) {
|
||||
s = ((struct packed_rrset_data*)rep->rrsets[i]->entry.data)
|
||||
->security;
|
||||
if(s == sec_status_unchecked)
|
||||
return s;
|
||||
}
|
||||
return sec;
|
||||
}
|
||||
|
||||
/** remove nonsecure from a delegation referral additional section */
|
||||
static void
|
||||
deleg_remove_nonsecure_additional(struct reply_info* rep)
|
||||
{
|
||||
/* we can simply edit it, since we are working in the scratch region */
|
||||
size_t i;
|
||||
enum sec_status s;
|
||||
|
||||
for(i = rep->an_numrrsets+rep->ns_numrrsets; i<rep->rrset_count; i++) {
|
||||
s = ((struct packed_rrset_data*)rep->rrsets[i]->entry.data)
|
||||
->security;
|
||||
if(s != sec_status_secure) {
|
||||
memmove(rep->rrsets+i, rep->rrsets+i+1,
|
||||
sizeof(struct ub_packed_rrset_key*)*
|
||||
(rep->rrset_count - i - 1));
|
||||
rep->ar_numrrsets--;
|
||||
rep->rrset_count--;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/** answer nonrecursive query from the cache */
|
||||
static int
|
||||
answer_norec_from_cache(struct worker* worker, struct query_info* qinfo,
|
||||
uint16_t id, uint16_t flags, struct comm_reply* repinfo,
|
||||
struct edns_data* edns)
|
||||
{
|
||||
/* for a nonrecursive query return either:
|
||||
* o an error (servfail; we try to avoid this)
|
||||
* o a delegation (closest we have; this routine tries that)
|
||||
* o the answer (checked by answer_from_cache)
|
||||
*
|
||||
* So, grab a delegation from the rrset cache.
|
||||
* Then check if it needs validation, if so, this routine fails,
|
||||
* so that iterator can prime and validator can verify rrsets.
|
||||
*/
|
||||
uint16_t udpsize = edns->udp_size;
|
||||
int secure = 0;
|
||||
uint32_t timenow = (uint32_t)time(0);
|
||||
int must_validate = !(flags&BIT_CD) && worker->env.need_to_validate;
|
||||
struct dns_msg *msg = NULL;
|
||||
struct delegpt *dp;
|
||||
|
||||
dp = dns_cache_find_delegation(&worker->env, qinfo->qname,
|
||||
qinfo->qname_len, qinfo->qtype, qinfo->qclass,
|
||||
worker->scratchpad, &msg, timenow);
|
||||
if(!dp) { /* no delegation, need to reprime */
|
||||
region_free_all(worker->scratchpad);
|
||||
return 0;
|
||||
}
|
||||
if(must_validate) {
|
||||
switch(check_delegation_secure(msg->rep)) {
|
||||
case sec_status_unchecked:
|
||||
/* some rrsets have not been verified yet, go and
|
||||
* let validator do that */
|
||||
region_free_all(worker->scratchpad);
|
||||
return 0;
|
||||
case sec_status_bogus:
|
||||
/* some rrsets are bogus, reply servfail */
|
||||
edns->edns_version = EDNS_ADVERTISED_VERSION;
|
||||
edns->udp_size = EDNS_ADVERTISED_SIZE;
|
||||
edns->ext_rcode = 0;
|
||||
edns->bits &= EDNS_DO;
|
||||
error_encode(repinfo->c->buffer, LDNS_RCODE_SERVFAIL,
|
||||
&msg->qinfo, id, flags, edns);
|
||||
region_free_all(worker->scratchpad);
|
||||
return 1;
|
||||
case sec_status_secure:
|
||||
/* all rrsets are secure */
|
||||
/* remove non-secure rrsets from the add. section*/
|
||||
if(worker->env.cfg->val_clean_additional)
|
||||
deleg_remove_nonsecure_additional(msg->rep);
|
||||
secure = 1;
|
||||
break;
|
||||
case sec_status_indeterminate:
|
||||
case sec_status_insecure:
|
||||
default:
|
||||
/* not secure */
|
||||
secure = 0;
|
||||
break;
|
||||
}
|
||||
}
|
||||
/* return this delegation from the cache */
|
||||
edns->edns_version = EDNS_ADVERTISED_VERSION;
|
||||
edns->udp_size = EDNS_ADVERTISED_SIZE;
|
||||
edns->ext_rcode = 0;
|
||||
edns->bits &= EDNS_DO;
|
||||
msg->rep->flags |= BIT_QR|BIT_RA;
|
||||
if(!reply_info_answer_encode(&msg->qinfo, msg->rep, id, flags,
|
||||
repinfo->c->buffer, 0, 1, worker->scratchpad,
|
||||
udpsize, edns, (int)(edns->bits & EDNS_DO), secure)) {
|
||||
error_encode(repinfo->c->buffer, LDNS_RCODE_SERVFAIL,
|
||||
&msg->qinfo, id, flags, edns);
|
||||
}
|
||||
region_free_all(worker->scratchpad);
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** check cname chain in cache reply */
|
||||
static int
|
||||
check_cache_chain(struct reply_info* rep) {
|
||||
@@ -282,6 +470,18 @@ check_cache_chain(struct reply_info* rep) {
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** check security status in cache reply */
|
||||
static int
|
||||
all_rrsets_secure(struct reply_info* rep) {
|
||||
size_t i;
|
||||
for(i=0; i<rep->rrset_count; i++) {
|
||||
if( ((struct packed_rrset_data*)rep->rrsets[i]->entry.data)
|
||||
->security != sec_status_secure )
|
||||
return 0;
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** answer query from the cache */
|
||||
static int
|
||||
answer_from_cache(struct worker* worker, struct lruhash_entry* e, uint16_t id,
|
||||
@@ -291,6 +491,8 @@ answer_from_cache(struct worker* worker, struct lruhash_entry* e, uint16_t id,
|
||||
struct reply_info* rep = (struct reply_info*)e->data;
|
||||
uint32_t timenow = time(0);
|
||||
uint16_t udpsize = edns->udp_size;
|
||||
int secure;
|
||||
int must_validate = !(flags&BIT_CD) && worker->env.need_to_validate;
|
||||
/* see if it is possible */
|
||||
if(rep->ttl <= timenow) {
|
||||
/* the rrsets may have been updated in the meantime.
|
||||
@@ -299,10 +501,6 @@ answer_from_cache(struct worker* worker, struct lruhash_entry* e, uint16_t id,
|
||||
*/
|
||||
return 0;
|
||||
}
|
||||
edns->edns_version = EDNS_ADVERTISED_VERSION;
|
||||
edns->udp_size = EDNS_ADVERTISED_SIZE;
|
||||
edns->ext_rcode = 0;
|
||||
edns->bits &= EDNS_DO;
|
||||
if(!rrset_array_lock(rep->ref, rep->rrset_count, timenow))
|
||||
return 0;
|
||||
/* locked and ids and ttls are OK. */
|
||||
@@ -311,15 +509,52 @@ answer_from_cache(struct worker* worker, struct lruhash_entry* e, uint16_t id,
|
||||
htons(LDNS_RR_TYPE_CNAME) || rep->rrsets[0]->rk.type ==
|
||||
htons(LDNS_RR_TYPE_DNAME))) {
|
||||
if(!check_cache_chain(rep)) {
|
||||
/* cname chain invalid, redo iterator steps */
|
||||
verbose(VERB_ALGO, "Cache reply: cname chain broken");
|
||||
bail_out:
|
||||
rrset_array_unlock_touch(worker->env.rrset_cache,
|
||||
worker->scratchpad, rep->ref, rep->rrset_count);
|
||||
region_free_all(worker->scratchpad);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
/* check security status of the cached answer */
|
||||
if( rep->security == sec_status_bogus && must_validate) {
|
||||
/* BAD cached */
|
||||
edns->edns_version = EDNS_ADVERTISED_VERSION;
|
||||
edns->udp_size = EDNS_ADVERTISED_SIZE;
|
||||
edns->ext_rcode = 0;
|
||||
edns->bits &= EDNS_DO;
|
||||
error_encode(repinfo->c->buffer, LDNS_RCODE_SERVFAIL,
|
||||
&mrentry->key, id, flags, edns);
|
||||
rrset_array_unlock_touch(worker->env.rrset_cache,
|
||||
worker->scratchpad, rep->ref, rep->rrset_count);
|
||||
region_free_all(worker->scratchpad);
|
||||
return 1;
|
||||
} else if( rep->security == sec_status_unchecked && must_validate) {
|
||||
verbose(VERB_ALGO, "Cache reply: unchecked entry needs "
|
||||
"validation");
|
||||
goto bail_out; /* need to validate cache entry first */
|
||||
} else if(rep->security == sec_status_secure) {
|
||||
if(all_rrsets_secure(rep))
|
||||
secure = 1;
|
||||
else {
|
||||
if(must_validate) {
|
||||
verbose(VERB_ALGO, "Cache reply: secure entry"
|
||||
" changed status");
|
||||
goto bail_out; /* rrset changed, re-verify */
|
||||
}
|
||||
secure = 0;
|
||||
}
|
||||
} else secure = 0;
|
||||
|
||||
edns->edns_version = EDNS_ADVERTISED_VERSION;
|
||||
edns->udp_size = EDNS_ADVERTISED_SIZE;
|
||||
edns->ext_rcode = 0;
|
||||
edns->bits &= EDNS_DO;
|
||||
if(!reply_info_answer_encode(&mrentry->key, rep, id, flags,
|
||||
repinfo->c->buffer, timenow, 1, worker->scratchpad,
|
||||
udpsize, edns, (int)(edns->bits & EDNS_DO) )) {
|
||||
udpsize, edns, (int)(edns->bits & EDNS_DO), secure)) {
|
||||
error_encode(repinfo->c->buffer, LDNS_RCODE_SERVFAIL,
|
||||
&mrentry->key, id, flags, edns);
|
||||
}
|
||||
@@ -501,7 +736,6 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
|
||||
edns.udp_size = 65535; /* max size for TCP replies */
|
||||
if(qinfo.qclass == LDNS_RR_CLASS_CH && answer_chaos(worker, &qinfo,
|
||||
&edns, c->buffer)) {
|
||||
verbose(VERB_ALGO, "class CH reply");
|
||||
return 1;
|
||||
}
|
||||
h = query_info_hash(&qinfo);
|
||||
@@ -514,14 +748,25 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
|
||||
lock_rw_unlock(&e->lock);
|
||||
return 1;
|
||||
}
|
||||
verbose(VERB_DETAIL, "answer from the cache -- data has timed out");
|
||||
verbose(VERB_ALGO, "answer from the cache failed");
|
||||
lock_rw_unlock(&e->lock);
|
||||
}
|
||||
if(!LDNS_RD_WIRE(ldns_buffer_begin(c->buffer))) {
|
||||
if(answer_norec_from_cache(worker, &qinfo,
|
||||
*(uint16_t*)ldns_buffer_begin(c->buffer),
|
||||
ldns_buffer_read_u16_at(c->buffer, 2), repinfo,
|
||||
&edns)) {
|
||||
return 1;
|
||||
}
|
||||
verbose(VERB_ALGO, "answer norec from cache -- "
|
||||
"need to validate or not primed");
|
||||
}
|
||||
ldns_buffer_rewind(c->buffer);
|
||||
server_stats_querymiss(&worker->stats, worker);
|
||||
|
||||
/* grab a work request structure for this new request */
|
||||
if(worker->env.mesh->all.count > worker->request_size) {
|
||||
/* @@@ TODO implement overload mode */
|
||||
if(0 && worker->env.mesh->all.count > worker->request_size) {
|
||||
/* we could get this due to a slow tcp incoming query,
|
||||
that started before we performed listen_pushback */
|
||||
verbose(VERB_DETAIL, "worker: too many incoming requests "
|
||||
@@ -538,11 +783,13 @@ worker_handle_request(struct comm_point* c, void* arg, int error,
|
||||
ldns_buffer_read_u16_at(c->buffer, 2),
|
||||
&edns, repinfo, *(uint16_t*)ldns_buffer_begin(c->buffer));
|
||||
|
||||
if(0) { /* TODO overload mode does not work yet. */
|
||||
if(worker->env.mesh->all.count == worker->request_size) {
|
||||
/* the max request number has been reached, stop accepting */
|
||||
listen_pushback(worker->front);
|
||||
}
|
||||
worker_mem_report(worker);
|
||||
}
|
||||
worker_mem_report(worker, NULL);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -612,7 +859,7 @@ worker_create(struct daemon* daemon, int id)
|
||||
|
||||
int
|
||||
worker_init(struct worker* worker, struct config_file *cfg,
|
||||
struct listen_port* ports, size_t buffer_size, int do_sigs)
|
||||
struct listen_port* ports, int do_sigs)
|
||||
{
|
||||
unsigned int seed;
|
||||
int startport;
|
||||
@@ -659,7 +906,8 @@ worker_init(struct worker* worker, struct config_file *cfg,
|
||||
return 0;
|
||||
}
|
||||
worker->front = listen_create(worker->base, ports,
|
||||
buffer_size, worker_handle_request, worker);
|
||||
cfg->msg_buffer_size, (int)cfg->incoming_num_tcp,
|
||||
worker_handle_request, worker);
|
||||
if(!worker->front) {
|
||||
log_err("could not create listening sockets");
|
||||
worker_delete(worker);
|
||||
@@ -668,8 +916,8 @@ worker_init(struct worker* worker, struct config_file *cfg,
|
||||
startport = cfg->outgoing_base_port +
|
||||
cfg->outgoing_num_ports * worker->thread_num;
|
||||
worker->back = outside_network_create(worker->base,
|
||||
buffer_size, (size_t)cfg->outgoing_num_ports, cfg->ifs,
|
||||
cfg->num_ifs, cfg->do_ip4, cfg->do_ip6, startport,
|
||||
cfg->msg_buffer_size, (size_t)cfg->outgoing_num_ports,
|
||||
cfg->ifs, cfg->num_ifs, cfg->do_ip4, cfg->do_ip6, startport,
|
||||
cfg->do_tcp?cfg->outgoing_num_tcp:0,
|
||||
worker->daemon->env->infra_cache, worker->rndstate);
|
||||
if(!worker->back) {
|
||||
@@ -677,20 +925,20 @@ worker_init(struct worker* worker, struct config_file *cfg,
|
||||
worker_delete(worker);
|
||||
return 0;
|
||||
}
|
||||
outside_network_set_secondary_buffer(worker->back,
|
||||
worker->front->udp_buff);
|
||||
if(worker->thread_num != 0) {
|
||||
/* start listening to commands */
|
||||
if(!(worker->cmd_com=comm_point_create_local(worker->base,
|
||||
worker->cmd_recv_fd, buffer_size,
|
||||
worker->cmd_recv_fd, cfg->msg_buffer_size,
|
||||
worker_handle_control_cmd, worker))) {
|
||||
log_err("could not create control compt.");
|
||||
worker_delete(worker);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
/* we use the msg_buffer_size as a good estimate for what the
|
||||
* user wants for memory usage sizes */
|
||||
worker->scratchpad = region_create_custom(malloc, free,
|
||||
65536, 8192, 32, 1);
|
||||
cfg->msg_buffer_size, cfg->msg_buffer_size/4, 32, 1);
|
||||
if(!worker->scratchpad) {
|
||||
log_err("malloc failure");
|
||||
worker_delete(worker);
|
||||
@@ -711,14 +959,13 @@ worker_init(struct worker* worker, struct config_file *cfg,
|
||||
worker->env.detach_subs = &mesh_detach_subs;
|
||||
worker->env.attach_sub = &mesh_attach_sub;
|
||||
worker->env.kill_sub = &mesh_state_delete;
|
||||
worker->env.query_done = &mesh_query_done;
|
||||
worker->env.walk_supers = &mesh_walk_supers;
|
||||
worker->env.detect_cycle = &mesh_detect_cycle;
|
||||
if(!worker->env.mesh) {
|
||||
worker->env.scratch_buffer = ldns_buffer_new(cfg->msg_buffer_size);
|
||||
if(!worker->env.mesh || !worker->env.scratch_buffer) {
|
||||
worker_delete(worker);
|
||||
return 0;
|
||||
}
|
||||
worker_mem_report(worker);
|
||||
worker_mem_report(worker, NULL);
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -735,8 +982,9 @@ worker_delete(struct worker* worker)
|
||||
return;
|
||||
mesh_stats(worker->env.mesh, "mesh has");
|
||||
server_stats_log(&worker->stats, worker->thread_num);
|
||||
worker_mem_report(worker);
|
||||
worker_mem_report(worker, NULL);
|
||||
mesh_delete(worker->env.mesh);
|
||||
ldns_buffer_free(worker->env.scratch_buffer);
|
||||
listen_delete(worker->front);
|
||||
outside_network_delete(worker->back);
|
||||
comm_signal_delete(worker->comsig);
|
||||
@@ -790,7 +1038,8 @@ worker_send_query(uint8_t* qname, size_t qnamelen, uint16_t qtype,
|
||||
struct module_qstate* q)
|
||||
{
|
||||
struct worker* worker = q->env->worker;
|
||||
struct outbound_entry* e = (struct outbound_entry*)malloc(sizeof(*e));
|
||||
struct outbound_entry* e = (struct outbound_entry*)region_alloc(
|
||||
q->region, sizeof(*e));
|
||||
if(!e)
|
||||
return NULL;
|
||||
e->qstate = q;
|
||||
@@ -799,7 +1048,6 @@ worker_send_query(uint8_t* qname, size_t qnamelen, uint16_t qtype,
|
||||
worker_handle_service_reply, e, worker->back->udp_buff,
|
||||
&outbound_entry_compare);
|
||||
if(!e->qsent) {
|
||||
free(e);
|
||||
return NULL;
|
||||
}
|
||||
return e;
|
||||
|
||||
+1
-2
@@ -127,12 +127,11 @@ struct worker* worker_create(struct daemon* daemon, int id);
|
||||
* @param worker: worker to initialize, created with worker_create.
|
||||
* @param cfg: configuration settings.
|
||||
* @param ports: list of shared query ports.
|
||||
* @param buffer_size: size of datagram buffer.
|
||||
* @param do_sigs: if true, worker installs signal handlers.
|
||||
* @return: false on error.
|
||||
*/
|
||||
int worker_init(struct worker* worker, struct config_file *cfg,
|
||||
struct listen_port* ports, size_t buffer_size, int do_sigs);
|
||||
struct listen_port* ports, int do_sigs);
|
||||
|
||||
/**
|
||||
* Make worker work.
|
||||
|
||||
+329
@@ -1,5 +1,334 @@
|
||||
25 September 2007: Wouter
|
||||
- tests for NSEC3. Fixup bitmap checks for NSEC3.
|
||||
- positive ANY response needs to check if wildcard expansion, and
|
||||
check that original data did not exist.
|
||||
- tests for NSEC3 that wrong use of OPTOUT is bad. For insecure
|
||||
delegation, for abuse of child zone apex nsec3.
|
||||
|
||||
24 September 2007: Wouter
|
||||
- do not make test programs by default.
|
||||
- But 'make test' will perform all of the tests.
|
||||
- Advertise builtin select libevent alternative when no libevent
|
||||
is found.
|
||||
- signit can generate NSEC3 hashes, for generating tests.
|
||||
- multiple nsec3 paramaters in message test.
|
||||
- too high nsec3 iterations becomes insecure test.
|
||||
|
||||
21 September 2007: Wouter
|
||||
- fixup empty_DS_name allocated in wrong region (port DEC Alpha).
|
||||
- fixup testcode lock safety (port FreeBSD).
|
||||
- removes subscript has type char warnings (port Solaris 9).
|
||||
- fixup of field with format type to int (port MacOS/X intel).
|
||||
- added test for infinite loop case in nonRD answer validation.
|
||||
It was a more general problem, but hard to reproduce. When an
|
||||
unsigned rrset is being validated and the key fetched, the DS
|
||||
sequence is followed, but if the final name has no DS, then no
|
||||
proof is possible - the signature has been stripped off.
|
||||
|
||||
20 September 2007: Wouter
|
||||
- fixup and test for NSEC wildcard with empty nonterminals.
|
||||
- makedist.sh fixup for svn info.
|
||||
- acl features request in plan.
|
||||
- improved DS empty nonterminal handling.
|
||||
- compat with ANS nxdomain for empty nonterminals. Attempts the nodata
|
||||
proof anyway, which succeeds in ANS failure case.
|
||||
- striplab protection in case it becomes -1.
|
||||
- plans for static and blacklist config.
|
||||
|
||||
19 September 2007: Wouter
|
||||
- comments about non-packed usage.
|
||||
- plan for overload support in 0.6.
|
||||
- added testbound tests for a failed resolution from the logs
|
||||
and for failed prime when missing glue.
|
||||
- fixup so useless delegation points are not returned from the
|
||||
cache. Also the safety belt is used if priming fails to complete.
|
||||
- fixup NSEC rdata not to be lowercased, bind compat.
|
||||
|
||||
18 September 2007: Wouter
|
||||
- wildcard nsec3 testcases, and fixup to get correct wildcard name.
|
||||
- validator prints subtype classification for debug.
|
||||
|
||||
17 September 2007: Wouter
|
||||
- NSEC3 hash cache unit test.
|
||||
- validator nsec3 nameerror test.
|
||||
|
||||
14 September 2007: Wouter
|
||||
- nsec3 nodata proof, nods proof, wildcard proof.
|
||||
- nsec3 support for cname chain ending in noerror or nodata.
|
||||
- validator calls nsec3 proof routines if no NSECs prove anything.
|
||||
- fixup iterator bug where it stored the answer to a cname under
|
||||
the wrong qname into the cache. When prepending the cnames, the
|
||||
qname has to be reset to the original qname.
|
||||
|
||||
13 September 2007: Wouter
|
||||
- nsec3 find matching and covering, ce proof, prove namerror msg.
|
||||
|
||||
12 September 2007: Wouter
|
||||
- fixup of manual page warnings, like for NSD bugreport.
|
||||
- nsec3 work, config, max iterations, filter, and hash cache.
|
||||
|
||||
6 September 2007: Wouter
|
||||
- fixup to find libevent on mac port install.
|
||||
- fixup size_t vs unsigned portability in validator/sigcrypt.
|
||||
- please compiler on different platforms, for unreachable code.
|
||||
- val_nsec3 file.
|
||||
- pthread_rwlock type is optional, in case of old pthread libs.
|
||||
|
||||
5 September 2007: Wouter
|
||||
- cname, name error validator tests.
|
||||
- logging of qtype ANY works.
|
||||
- ANY type answers get RRSIG in answer section of replies (but not
|
||||
in other sections, unless DO bit is on).
|
||||
- testbound can replay a TCP query (set MATCH TCP in the QUERY).
|
||||
- DS and noDS referral validation test.
|
||||
- if you configure many trust anchors, parent trust anchors can
|
||||
securely deny existance of child trust anchors, if validated.
|
||||
- not all *.name NSECs are present because a wildcard was matched,
|
||||
and *.name NSECs can prove nodata for empty nonterminals.
|
||||
Also, for wildcard name NSECs, check they are not from the parent
|
||||
zone (for wildcarded zone cuts), and check absence of CNAME bit,
|
||||
for a nodata proof.
|
||||
- configure option for memory allocation debugging.
|
||||
- port configure option for memory allocation to solaris10.
|
||||
|
||||
4 September 2007: Wouter
|
||||
- fixup of Leakage warning when serviced queries processed multiple
|
||||
callbacks for the same query from the same server.
|
||||
- testbound removes config file from /tmp on failed exit.
|
||||
- fixup for referral cleanup of the additional section.
|
||||
- tests for cname, referral validation.
|
||||
- neater testbound tpkg output.
|
||||
- DNAMEs no longer match their apex when synthesized from the cache.
|
||||
- find correct signer name for DNAME responses.
|
||||
- wildcarded DNAME test and fixup code to detect.
|
||||
- prepend NSEC and NSEC3 rrsets in the iterator while chasing CNAMEs.
|
||||
So that wildcarded CNAMEs get their NSEC with them to the answer.
|
||||
- test for a CNAME to a DNAME to a CNAME to an answer, all from
|
||||
different domains, for key fetching and signature checking of
|
||||
CNAME'd messages.
|
||||
|
||||
3 September 2007: Wouter
|
||||
- Fixed error in iterator that would cause assertion failure in
|
||||
validator. CNAME to a NXDOMAIN response was collated into a response
|
||||
with both a CNAME and the NXDOMAIN rcode. Added a test that the
|
||||
rcode is changed to NOERROR (because of the CNAME).
|
||||
- timeout on tcp does not lead to spurious leakage detect.
|
||||
- account memory for name of lame zones, so that memory leakages does
|
||||
not show lame cache growth as a leakage growth.
|
||||
- config setting for lameness cache expressed in bytes, instead of
|
||||
number of entries.
|
||||
- tool too summarize allocations per code line.
|
||||
|
||||
31 August 2007: Wouter
|
||||
- can read bind trusted-keys { ... }; files, in a compatibility mode.
|
||||
- iterator should not detach target queries that it still could need.
|
||||
the protection against multiple outstanding queries is moved to a
|
||||
current_query num check.
|
||||
- validator nodata, positive, referral tests.
|
||||
- dname print can print '*' wildcard.
|
||||
|
||||
30 August 2007: Wouter
|
||||
- fixup override date config option.
|
||||
- config options to control memory usage.
|
||||
- caught bad free of un-alloced data in worker_send error case.
|
||||
- memory accounting for key cache (trust anchors and temporary cache).
|
||||
- memory accounting fixup for outside network tcp pending waits.
|
||||
- memory accounting fixup for outside network tcp callbacks.
|
||||
- memory accounting for iterator fixed storage.
|
||||
- key cache size and slabs config options.
|
||||
- lib crypto cleanups at exit.
|
||||
|
||||
29 August 2007: Wouter
|
||||
- test tool to sign rrsets for testing validator with.
|
||||
- added RSA and DSA test keys, public and private pairs, 512 bits.
|
||||
- default configuration is with validation enabled.
|
||||
Only a trust-anchor needs to be configured for DNSSEC to work.
|
||||
- do not convert to DER for DSA signature verification.
|
||||
- validator replay test file, for a DS to DNSKEY DSA key prime and
|
||||
positive response.
|
||||
|
||||
28 August 2007: Wouter
|
||||
- removed double use for udp buffers, that could fail,
|
||||
instead performs a malloc to do the backup.
|
||||
- validator validates referral messages, by validating all the rrsets
|
||||
and stores the rrsets in the cache. Further referral (nonRD queries)
|
||||
replies are made from the rrset cache directly. Unless unchecked
|
||||
rrsets are encountered, there are then validated.
|
||||
- enforce that signing is done by a parent domain (or same domain).
|
||||
- adjust TTL downwards if rrset TTL bigger than signature allows.
|
||||
- permissive mode feature, sets AD bit for secure, but bogus does
|
||||
not give servfail (bogus is changed into indeterminate).
|
||||
- optimization of rrset verification. rr canonical sorting is reused,
|
||||
for the same rrset. canonical rrset image in buffer is reused for
|
||||
the same signature.
|
||||
- if the rrset is too big (64k exactly + large owner name) the
|
||||
canonicalization routine will fail if it does not fit in buffer.
|
||||
- faster verification for large sigsets.
|
||||
- verb_detail mode reports validation failures, but not the entire
|
||||
algorithm for validation. Key prime failures are reported as
|
||||
verb_ops level.
|
||||
|
||||
27 August 2007: Wouter
|
||||
- do not garble the edns if a cache answer fails.
|
||||
- answer norecursive from cache if possible.
|
||||
- honor clean_additional setting when returning secure non-recursive
|
||||
referrals.
|
||||
- do not store referral in msg cache for nonRD queries.
|
||||
- store verification status in the rrset cache to speed up future
|
||||
verification.
|
||||
- mark rrsets indeterminate and insecure if they are found to be so.
|
||||
and store this in the cache.
|
||||
|
||||
24 August 2007: Wouter
|
||||
- message is bogus if unsecure authority rrsets are present.
|
||||
- val-clean-additional option, so you can turn it off.
|
||||
- move rrset verification out of the specific proof types into one
|
||||
routine. This makes the proof routines prettier.
|
||||
- fixup cname handling in validator, cname-to-positive and cname-to-
|
||||
nodata work.
|
||||
- Do not synthesize DNSKEY and DS responses from the rrset cache if
|
||||
the rrset is from the additional section. Signatures may have
|
||||
fallen off the packet, and cause validation failure.
|
||||
- more verbose signature date errors (with the date attached).
|
||||
- increased default infrastructure cache size. It is important for
|
||||
performance, and 1000 entries are only 212k (or a 400 k total cache
|
||||
size). To 10000 entries (for 2M entries, 4M cache size).
|
||||
|
||||
23 August 2007: Wouter
|
||||
- CNAME handling - move needs_validation to before val_new().
|
||||
val_new() setups the chase-reply to be an edited copy of the msg.
|
||||
new classification, and find signer can find for it.
|
||||
removal of unsigned crap from additional, and query restart for
|
||||
cname.
|
||||
- refuse to follow wildcarded DNAMEs when validating.
|
||||
But you can query for qtype ANY, or qtype DNAME and validate that.
|
||||
|
||||
22 August 2007: Wouter
|
||||
- bogus TTL.
|
||||
- review - use val_error().
|
||||
|
||||
21 August 2007: Wouter
|
||||
- ANY response validation.
|
||||
- store security status in cache.
|
||||
- check cache security status and either send the query to be
|
||||
validated, return the query to client, or send servfail to client.
|
||||
Sets AD bit on validated replies.
|
||||
- do not examine security status on an error reply in mesh_done.
|
||||
- construct DS, DNSKEY messages from rrset cache.
|
||||
- manual page entry for override-date.
|
||||
|
||||
20 August 2007: Wouter
|
||||
- validate and positive validation, positive wildcard NSEC validation.
|
||||
- nodata validation, nxdomain validation.
|
||||
|
||||
18 August 2007: Wouter
|
||||
- process DNSKEY response in FINDKEY state.
|
||||
|
||||
17 August 2007: Wouter
|
||||
- work on DS2KE routine.
|
||||
- val_nsec.c for validator NSEC proofs.
|
||||
- unit test for NSEC bitmap reading.
|
||||
- dname iswild and canonical_compare with unit tests.
|
||||
|
||||
16 August 2007: Wouter
|
||||
- DS sig unit test.
|
||||
- latest release libevent 1.3c and 1.3d have threading fixed.
|
||||
- key entry fixup data pointer and ttl absolute.
|
||||
- This makes a key-prime succeed in validator, with DS or DNSKEY as
|
||||
trust-anchor.
|
||||
- fixup canonical compare byfield routine, fix bug and also neater.
|
||||
- fixed iterator response type classification for queries of type
|
||||
ANY and NS.
|
||||
dig ANY gives sometimes NS rrset in AN and NS section, and parser
|
||||
removes the NS section duplicate. dig NS gives sometimes the NS
|
||||
in the answer section, as referral.
|
||||
- validator FINDKEY state.
|
||||
|
||||
15 August 2007: Wouter
|
||||
- crypto calls to verify signatures.
|
||||
- unit test for rrsig verification.
|
||||
|
||||
14 August 2007: Wouter
|
||||
- default outgoing ports changed to avoid port 2049 by default.
|
||||
This port is widely blocked by firewalls.
|
||||
- count infra lameness cache in memory size.
|
||||
- accounting of memory improved
|
||||
- outbound entries are allocated in the query region they are for.
|
||||
- extensive debugging for memory allocations.
|
||||
- --enable-lock-checks can be used to enable lock checking.
|
||||
- protect undefs in config.h from autoheaders ministrations.
|
||||
- print all received udp packets. log hex will print on multiple
|
||||
lines if needed.
|
||||
- fixed error in parser with backwards rrsig references.
|
||||
- mark cycle targets for iterator did not have CD flag so failed
|
||||
its task.
|
||||
|
||||
13 August 2007: Wouter
|
||||
- fixup makefile, if lexer is missing give nice error and do not
|
||||
mess up the dependencies.
|
||||
- canonical compare routine updated.
|
||||
- canonical hinfo compare.
|
||||
- printout list of the queries that the mesh is working on.
|
||||
|
||||
10 August 2007: Wouter
|
||||
- malloc and free overrides that track total allocation and frees.
|
||||
for memory debugging.
|
||||
- work on canonical sort.
|
||||
|
||||
9 August 2007: Wouter
|
||||
- canonicalization, signature checks
|
||||
- dname signature label count and unit test.
|
||||
- added debug heap size print to memory printout.
|
||||
- typo fixup in worker.c
|
||||
- -R needed on solaris.
|
||||
- validator override option for date check testing.
|
||||
|
||||
8 August 2007: Wouter
|
||||
- ldns _raw routines created (in ldns trunk).
|
||||
- sigcrypt DS digest routines
|
||||
- val_utils uses sigcrypt to perform signature cryptography.
|
||||
- sigcrypt keyset processing
|
||||
|
||||
7 August 2007: Wouter
|
||||
- security status type.
|
||||
- security status is copied when rdata is equal for rrsets.
|
||||
- rrset id is updated to invalidate all the message cache entries
|
||||
that refer to NSEC, NSEC3, DNAME rrsets that have changed.
|
||||
- val_util work
|
||||
- val_sigcrypt file for validator signature checks.
|
||||
|
||||
6 August 2007: Wouter
|
||||
- key cache for validator.
|
||||
- moved isroot and dellabel to own dname routines, with unit test.
|
||||
|
||||
3 August 2007: Wouter
|
||||
- replanning.
|
||||
- scrubber check section of lame NS set.
|
||||
- trust anchors can be in config file or read from zone file,
|
||||
DS and DNSKEY entries.
|
||||
- unit test trust anchor storage.
|
||||
- trust anchors converted to packed rrsets.
|
||||
- key entry definition.
|
||||
|
||||
2 August 2007: Wouter
|
||||
- configure change for latest libevent trunk version (needs -lrt).
|
||||
- query_done and walk_supers are moved out of module interface.
|
||||
- fixup delegation point duplicates.
|
||||
- fixup iterator scrubber; lame NS set is let through the scrubber
|
||||
so that the classification is lame.
|
||||
- validator module exists, and does nothing but pass through,
|
||||
with calling of next module and return.
|
||||
- validator work.
|
||||
|
||||
1 August 2007: Wouter
|
||||
- set version to 0.5
|
||||
- module work for module to module interconnections.
|
||||
- config of modules.
|
||||
- detect cycle takes flags.
|
||||
|
||||
31 July 2007: Wouter
|
||||
- updated plan
|
||||
- release 0.4 tag.
|
||||
|
||||
30 July 2007: Wouter
|
||||
- changed random state init, so that sequential process IDs are not
|
||||
|
||||
+13
-2
@@ -14,7 +14,7 @@ This software is under BSD license, see LICENSE for details.
|
||||
* libevent http://www.monkey.org/~provos/libevent/ (BSD license)
|
||||
|
||||
* Create build environment
|
||||
* run libtoolize -c if config.sub is missing.
|
||||
* run libtoolize -c if config.sub is missing, or run glibtoolize.
|
||||
* autoreconf (autoheader && autoconf), if ./configure is missing.
|
||||
|
||||
* Make and install: ./configure; make; make install
|
||||
@@ -28,10 +28,21 @@ This software is under BSD license, see LICENSE for details.
|
||||
* --enable-static-exe
|
||||
This enables a debug option to statically link, against ldns and
|
||||
libevent libraries.
|
||||
* --enable-lock-checks
|
||||
This enables a debug option to check lock and unlock calls. It needs
|
||||
a recent pthreads library to work.
|
||||
* --enable-alloc-checks
|
||||
This enables a debug option to check malloc (calloc, realloc, free).
|
||||
The server periodically checks if the amount of memory used fits with
|
||||
the amount of memory it thinks it should be using, and reports
|
||||
memory usage in detail.
|
||||
|
||||
* 'make test' attempts to run a series of tests, depending on the support
|
||||
programs that are installed.
|
||||
|
||||
Known issues
|
||||
------------
|
||||
o If libevent is older (1.3 and before), unbound will exit instead of reload
|
||||
o If libevent is older (before 1.3c), unbound will exit instead of reload
|
||||
on sighup. On a restart 'did not exit gracefully last time' warning is
|
||||
printed. Perform ./configure --with-libevent=no or update libevent, rerun
|
||||
configure and recompile unbound to make sighup work correctly.
|
||||
|
||||
@@ -28,3 +28,28 @@ o (option) to not send replies to clients after a timeout of (say 5 secs) has
|
||||
passed, but keep task active for later retries by client.
|
||||
o private TTL feature
|
||||
o pretend-dnssec-unaware, and pretend-edns-unaware modes for debug/workshops.
|
||||
o delegpt use rbtree for ns-list, to avoid slowdown for very large NS sets.
|
||||
o be able to have different listen and query-to addresses to bind to,
|
||||
so you can listen to localhost and query-to to the internet.
|
||||
o reprime and refresh oft used data before timeout.
|
||||
o retain prime results in a overlaid roothints file.
|
||||
o store primed key data in a overlaid keyhints file (sort of like drafttimers).
|
||||
o windows version, auto update feature, a query to check for the version.
|
||||
o autoreport of problems
|
||||
o logrotation, syslog
|
||||
o command the server with TSIG inband. get-config, clearcache,
|
||||
get stats, get memstats, get ..., reload, clear one zone from cache
|
||||
o watch for spoof nearmisses.
|
||||
o improve compression of DNS packets by first puttig uncompressible rrs, then
|
||||
compress to their rdata.
|
||||
o if one server is not responsive do not spend 75 secs on that server, but
|
||||
try other servers with lower rtt.
|
||||
o NSID rfc 5001 support.
|
||||
o timers rfc 5011 support.
|
||||
o Treat YXDOMAIN from a DNAME properly, in iterator (not throwaway), validator.
|
||||
o grab ports nonconsequtive and change the set after a while (change within
|
||||
a given range). Could be bad for OS if wrong port. unsure if it helps secure.
|
||||
o workaround for nxdomain responses for ENT DS queries. Not look at rcode and
|
||||
look at valid empty nonterminal proof that is inside the packet.
|
||||
o make timeout backoffs randomized (a couple percent random) to spread traffic.
|
||||
o inspect date on executable, then warn user in log if its more than 1 year.
|
||||
|
||||
+69
-3
@@ -42,6 +42,13 @@ server:
|
||||
# number of outgoing simultaneous tcp buffers to hold per thread.
|
||||
# outgoing-num-tcp: 10
|
||||
|
||||
# number of incoming simultaneous tcp buffers to hold per thread.
|
||||
# incoming-num-tcp: 10
|
||||
|
||||
# buffer size for handling DNS data. No messages larger than this
|
||||
# size can be sent or received, by UDP or TCP. In bytes.
|
||||
# msg-buffer-size: 65552
|
||||
|
||||
# the amount of memory to use for the message cache.
|
||||
# in bytes. default is 4 Mb
|
||||
# msg-cache-size: 4194304
|
||||
@@ -76,10 +83,10 @@ server:
|
||||
# infra-cache-slabs: 4
|
||||
|
||||
# the maximum number of hosts that are cached (roundtrip times, EDNS).
|
||||
# infra-cache-numhosts: 1000
|
||||
# infra-cache-numhosts: 10000
|
||||
|
||||
# the maximum number of lame zones per host that are cached.
|
||||
# infra-cache-numlame: 1000
|
||||
# the maximum size of the lame zones cached per host. in bytes.
|
||||
# infra-cache-lame-size: 10240
|
||||
|
||||
# Enable IPv4, "yes" or "no".
|
||||
# do-ip4: yes
|
||||
@@ -147,6 +154,65 @@ server:
|
||||
# DNS port, use "1.2.3.4@123" to block port 123 for 1.2.3.4.
|
||||
# do-not-query-address: 127.0.0.1
|
||||
# do-not-query-address: ::1
|
||||
|
||||
# module configuration of the server. A string with identifiers
|
||||
# separated by spaces. "iterator" or "validator iterator"
|
||||
# module-config: "validator iterator"
|
||||
|
||||
# File with trusted keys for validation. Specify more than one file
|
||||
# with several entries, one file per entry.
|
||||
# Zone file format, with DS and DNSKEY entries.
|
||||
# trust-anchor-file: ""
|
||||
|
||||
# Trusted key for validation. DS or DNSKEY. specify the RR on a
|
||||
# single line, surrounded by "". TTL is ignored. class is IN default.
|
||||
# (These examples are from August 2007 and may not be valid anymore).
|
||||
# trust-anchor: "nlnetlabs.nl. DNSKEY 257 3 5 AQPzzTWMz8qSWIQlfRnPckx2BiVmkVN6LPupO3mbz7FhLSnm26n6iG9N Lby97Ji453aWZY3M5/xJBSOS2vWtco2t8C0+xeO1bc/d6ZTy32DHchpW 6rDH1vp86Ll+ha0tmwyy9QP7y2bVw5zSbFCrefk8qCUBgfHm9bHzMG1U BYtEIQ=="
|
||||
# trust-anchor: "jelte.nlnetlabs.nl. DS 42860 5 1 14D739EB566D2B1A5E216A0BA4D17FA9B038BE4A"
|
||||
|
||||
# File with trusted keys for validation. Specify more than one file
|
||||
# with several entries, one file per entry. Like trust-anchor-file
|
||||
# but has a different file format. Format is BIND-9 style format,
|
||||
# the trusted-keys { name flag proto algo "key"; }; clauses are read.
|
||||
# trusted-keys-file: ""
|
||||
|
||||
# Override the date for validation with a specific fixed date.
|
||||
# Do not set this unless you are debugging signature inception
|
||||
# and expiration. "" or "0" turns the feature off.
|
||||
# val-override-date: ""
|
||||
|
||||
# The time to live for bogus data, rrsets and messages. This avoids
|
||||
# some of the revalidation, until the time interval expires. in secs.
|
||||
# val-bogus-ttl: 900
|
||||
|
||||
# Should additional section of secure message also be kept clean of
|
||||
# unsecure data. Useful to shield the users of this validator from
|
||||
# potential bogus data in the additional section. All unsigned data
|
||||
# in the additional section is removed from secure messages.
|
||||
# val-clean-additional: yes
|
||||
|
||||
# Turn permissive mode on to permit bogus messages. Thus, messages
|
||||
# for which security checks failed will be returned to clients,
|
||||
# instead of SERVFAIL. It still performs the security checks, which
|
||||
# result in interesting log files and possibly the AD bit in
|
||||
# replies if the message is found secure. The default is off.
|
||||
# val-permissive-mode: no
|
||||
|
||||
# It is possible to configure NSEC3 maximum iteration counts per
|
||||
# keysize. Keep this table very short, as linear search is done.
|
||||
# A message with an NSEC3 with larger count is marked insecure.
|
||||
# List in ascending order the keysize and count values.
|
||||
# val-nsec3-keysize-iterations: "1024 150 2048 500 4096 2500"
|
||||
|
||||
# the amount of memory to use for the key cache.
|
||||
# in bytes. default is 4 Mb
|
||||
# key-cache-size: 4194304
|
||||
|
||||
# the number of slabs to use for the key cache.
|
||||
# the number of slabs must be a power of 2.
|
||||
# more slabs reduce lock contention, but fragment memory usage.
|
||||
# key-cache-slabs: 4
|
||||
|
||||
|
||||
# Stub zones.
|
||||
# Create entries like below, to make all queries for 'example.com' and
|
||||
|
||||
@@ -30,16 +30,19 @@ Roughly the boxes are as follows:
|
||||
Twice as long; one box for module layout, one box for iterator module.
|
||||
0.5 Validator - validator module.
|
||||
0.6 Bigger and better - Operational useful features (config, log, memory)
|
||||
0.7 Local zones feature - localzones stubzones fwdzones, no leak rfc1918.
|
||||
0.7 Put to a limited audience.
|
||||
gamma/alpha core functionality test release, to a small audience.
|
||||
partial functionality. For more extensive use and testing.
|
||||
0.8 Local zones feature - localzones stubzones fwdzones, no leak rfc1918.
|
||||
views support; for selective recursive service.
|
||||
0.8 Library use - resolver validator lib (and test apps)
|
||||
0.9 Corner cases - be able to resolve in the wild. Run fuzzers.
|
||||
0.9 Library use - resolver validator lib (and test apps)
|
||||
0.10 Corner cases - be able to resolve in the wild. Run fuzzers.
|
||||
Run as many tests as we can think of.
|
||||
Go through logs and check for long, unresolved cases
|
||||
Use profiler.
|
||||
0.10 Beta release. Run shadow for a resolver in production for several
|
||||
0.11 Beta release. Run shadow for a resolver in production for several
|
||||
weeks.
|
||||
0.11 Features features
|
||||
0.12 Features features
|
||||
aggressive negative caching for NSEC, NSEC3.
|
||||
multiple queries per question, server exploration, server selection.
|
||||
option to use real entropy for randomness (mix it in once in a while).
|
||||
@@ -142,19 +145,59 @@ Styleguide:
|
||||
* Test resolver.
|
||||
* Speed test.
|
||||
|
||||
*** Put to a limited audience
|
||||
* The alpha/gamma core functionality, svn access to limited audience.
|
||||
* Support features and requests as they arise.
|
||||
* Provide real-world experiences.
|
||||
|
||||
*** Bigger and Better
|
||||
* Config file syntax checker program. Tests on checker.
|
||||
* Logging first class feature with config options.
|
||||
* with logfile turnover to avoid Gbs of logs.
|
||||
* donotqueryaddresses with trie for blocking entire netblocks.
|
||||
* Memory overhaul, special allocators for hashtable caches, and mesh qstates.
|
||||
* keep a preallocated list of region-chunks per worker thread.
|
||||
* allocate region struct and cleanup list in region itself; use
|
||||
linked list cleanup list. unit test on this. do not call region
|
||||
to avoid name-collision with nsd regions, 'regional'.
|
||||
* read root hints from file.
|
||||
* failover to next server in 1 second, instead of 100 seconds on one server.
|
||||
* failure to return answer, w. reason (donotq, noanswer servers, cannot
|
||||
find servers, validationfail w.classification, error),
|
||||
with threadno, starttime and endtime and qname/type/class, prime/qflags,
|
||||
from-clients, from-internal, has-subrequests, a nice error report,
|
||||
so that an excerpt from those times can be made from the logs.
|
||||
logfileparsing tool that makes these excerpts and emails them.
|
||||
* clear cache as a callback from the new-rrset-id routine.
|
||||
* make overload mode work; phase 0 all ok, phase 1 some threads close ports,
|
||||
to let other threads pick up work. phase 2, all threads closed, so all open
|
||||
the ports again and drop all non-cache-reply queries.
|
||||
Keep mutexed num-overloaded-threads counter. thread incs it when it hits
|
||||
max number of user queries serviced in mesh. threads decs it when it
|
||||
falls below 90% of the max. if incs, and not all threads closed, phase 1,
|
||||
else, phase 2 start is broadcast over command pipes. if decs, open ports
|
||||
if phase 1, start servicing, phase is 0 again. Make robust against delays.
|
||||
readme: max about 1 second worth of incoming queries, 10k perhaps,
|
||||
or 1/number of seconds it takes start up of 10k.
|
||||
* should the source include a copy of the ldns lib for ease of building by
|
||||
new users.
|
||||
* no greedy TTL algo (and test).
|
||||
* maximum TTL, cap incoming values, and config option.
|
||||
|
||||
*** Local zones feature.
|
||||
* Build in local zone features. First the total stop for1912.
|
||||
* Then 'local content' for minimal serving of localhost.localdomain,
|
||||
and so on.
|
||||
* Remember jakob's diagram.
|
||||
* views support, selective recursive service
|
||||
* Remember jakob's diagram. views support, selective recursive service:
|
||||
* acl for allowed recursion (RD=1), then drop or refused query.
|
||||
like 10.0.0.0/8 allow, 0.0.0.0/0 refuse, ... in-order.
|
||||
perhaps also, same list to disallow RD=0 access, like;
|
||||
allow_recursion, drop_recursion, refuse_recursion, drop_all
|
||||
* static answers for queries, fixed RRs from cfg, option
|
||||
query for that RR returns answer with that RR.
|
||||
* blacklist (return fixed nxdomain for domain and below), option
|
||||
can be used to block AS112 traffic, option to unblock a zone.
|
||||
* after checking acl, do iter: static, blacklist, forwards, recurse.
|
||||
* Forward-local-zone to NSD.
|
||||
- include in package, autoforkexec on localhost to do so.
|
||||
* forward local zone to remote server.
|
||||
@@ -181,6 +224,9 @@ Styleguide:
|
||||
* read a file with cache contents and settings, provide fake
|
||||
environment for module-handle-state-X functions, then check
|
||||
resulting module state structure to correct answer.
|
||||
* speed test cache responses.
|
||||
* using two servers, compare answer differences between bind and unbound.
|
||||
this gives false differences due to changes in the rest of internet.
|
||||
|
||||
*** Beta release.
|
||||
* Run shadow for a resolver in production for several weeks.
|
||||
@@ -197,7 +243,9 @@ Styleguide:
|
||||
* Be able to prime roots using several queries (like, get only NS first).
|
||||
* Nicer statistics
|
||||
* private TTL, dTLS features.
|
||||
|
||||
* retry-mode, where a bogus result triggers a retry-mode query, where a list
|
||||
of responses over a time interval is collected, and each is validated.
|
||||
* draft-timers, DLV features.
|
||||
|
||||
treeshrew/
|
||||
validator/ *.c *.h
|
||||
|
||||
@@ -79,3 +79,45 @@ o An authoritative name server.
|
||||
o Too many Features.
|
||||
|
||||
|
||||
5. Choices
|
||||
----------
|
||||
o rfc2181 decourages duplicates RRs in RRsets. unbound does not create
|
||||
duplicates, but when presented with duplicates on the wire from the
|
||||
authoritative servers, does not perform duplicate removal.
|
||||
It does do some rrsig duplicate removal, in the msgparser, for dnssec qtype
|
||||
rrsig and any, because of special rrsig processing in the msgparser.
|
||||
o The harden-glue feature, when yes all out of zone glue is deleted, when
|
||||
no out of zone glue is used for further resolving, is more complicated
|
||||
than that, see below.
|
||||
Main points:
|
||||
* rfc2182 trust handling is used.
|
||||
* data is let through only in very specific cases
|
||||
* spoofability remains possible.
|
||||
Not all glue is let through (despite the name of the option). Only glue
|
||||
which is present in a delegation, of type A and AAAA, where the name is
|
||||
present in the NS record in the authority section is let through.
|
||||
The glue that is let through is stored in the cache (marked as 'from the
|
||||
additional section'). And will then be used for sending queries to. It
|
||||
will not be present in the reply to the client (if RD is off).
|
||||
A direct query for that name will attempt to get a msg into the message
|
||||
cache. Since A and AAAA queries are not synthesized by the unbound cache,
|
||||
this query will be (eventually) sent to the authoritative server and its
|
||||
answer will be put in the cache, marked as 'from the answer section' and
|
||||
thus remove the 'from the additional section' data, and this record is
|
||||
returned to the client.
|
||||
The message has a TTL smaller or equal to the TTL of the answer RR.
|
||||
If the cache memory is low; the answer RR may be dropped, and a glue
|
||||
RR may be inserted, within the message TTL time, and thus return the
|
||||
spoofed glue to a client. When the message expires, it is refetched and
|
||||
the cached RR is updated with the correct content.
|
||||
The server can be spoofed by getting it to visit a especially prepared
|
||||
domain. This domain then inserts an address for another authoritative
|
||||
server into the cache, when visiting that other domain, this address may
|
||||
then be used to send queries to. And fake answers may be returned.
|
||||
If the other domain is signed by DNSSEC, the fakes will be detected.
|
||||
|
||||
In summary, the harden glue feature presents a security risk if
|
||||
disabled. Disabling the feature leads to possible better performance
|
||||
as more glue is present for the recursive service to use. The feature
|
||||
is implemented so as to minimise the security risk, while trying to
|
||||
keep this performance gain.
|
||||
|
||||
@@ -17,7 +17,6 @@ unbound
|
||||
.Op Fl d
|
||||
.Op Fl v
|
||||
.Op Fl c Ar cfgfile
|
||||
|
||||
.Sh DESCRIPTION
|
||||
.Ic Unbound
|
||||
is an implementation of a DNS resolver, that does caching and
|
||||
@@ -25,27 +24,21 @@ DNSSEC validation.
|
||||
.Pp
|
||||
The available options are:
|
||||
.Bl -tag -width indent
|
||||
|
||||
.It Fl h
|
||||
Show the version and commandline option help.
|
||||
|
||||
.It Fl c Ar cfgfile
|
||||
Set the config file to read with settings for unbound. The syntax is
|
||||
described in
|
||||
.Xr unbound.conf 5 .
|
||||
|
||||
.It Fl d
|
||||
Debug flag, do not fork into the background, but stay attached to the
|
||||
console.
|
||||
|
||||
.It Fl v
|
||||
Increase verbosity. If given multiple times, more information is logged.
|
||||
This is in addition to the verbosity (if any) from the config file.
|
||||
|
||||
.El
|
||||
.Sh SEE ALSO
|
||||
.Xr unbound.conf 5 .
|
||||
|
||||
.Sh AUTHORS
|
||||
.Ic Unbound
|
||||
developers are mentioned in the CREDITS file in the distribution.
|
||||
|
||||
+107
-17
@@ -20,11 +20,9 @@ is used to configure
|
||||
.Xr unbound 8 .
|
||||
The file format has attributes and values. Some attributes have attributes inside them.
|
||||
The notation is: attribute: value.
|
||||
|
||||
.Pp
|
||||
Comments start with # and last to the end of line. Empty lines are
|
||||
ignored as is whitespace at the beginning of a line.
|
||||
|
||||
.El
|
||||
.Sh EXAMPLE
|
||||
An example config file is shown below. Copy this to /etc/unbound/unbound.conf
|
||||
and start the server with:
|
||||
@@ -37,7 +35,6 @@ Most settings are the defaults. Stop the server with:
|
||||
.fi
|
||||
Below is a minimal config file. The source distribution contains an extensive
|
||||
example.conf file with all the options.
|
||||
|
||||
.nf
|
||||
# unbound.conf(5) config file for unbound(8).
|
||||
server:
|
||||
@@ -48,19 +45,15 @@ server:
|
||||
pidfile: "/etc/unbound/unbound.pid"
|
||||
# verbosity: 1 # uncomment and increase to get more logging.
|
||||
.fi
|
||||
|
||||
.El
|
||||
.Sh FILE FORMAT
|
||||
There must be whitespace between keywords. Attribute keywords end with a colon ':'. An attribute
|
||||
is followed by its containing attributes, or a value.
|
||||
|
||||
.Pp
|
||||
Files can be included using the
|
||||
.Ic include:
|
||||
directive. It can appear anywhere, and takes a single filename as an argument.
|
||||
Processing continues as if the text from the included file was copied into
|
||||
the config file at that point.
|
||||
|
||||
.Ss Server Options
|
||||
There may only be one
|
||||
.Ic server:
|
||||
@@ -91,6 +84,15 @@ extra resources from the operating system.
|
||||
.It \fBoutgoing-num-tcp:\fR <number>
|
||||
Number of outgoing TCP buffers to allocate per thread. Default is 10. If set
|
||||
to 0, or if do_tcp is "no", no TCP queries to authoritative servers are done.
|
||||
.It \fBincoming-num-tcp:\fR <number>
|
||||
Number of incoming TCP buffers to allocate per thread. Default is 10. If set
|
||||
to 0, or if do_tcp is "no", no TCP queries from clients are accepted.
|
||||
.It \fBmsg-buffer-size:\fR <number>
|
||||
Number of bytes size of the message buffers. Default is 65552 bytes, enough
|
||||
for 64 Kb packets, the maximum DNS message size. No message larger than this
|
||||
can be sent or received. Can be reduced to use less memory, but some requests
|
||||
for DNS data, such as for huge resource records, will result in a SERVFAIL
|
||||
reply to the client.
|
||||
.It \fBmsg-cache-size:\fR <number>
|
||||
Number of bytes size of the message cache. Default is 4 megabytes.
|
||||
.It \fBmsg-cache-slabs:\fR <number>
|
||||
@@ -113,9 +115,11 @@ The time to live when a delegation is discovered to be lame. Default is 900.
|
||||
Number of slabs in the infrastructure cache. Slabs reduce lock contention
|
||||
by threads. Must be set to a power of 2.
|
||||
.It \fBinfra-cache-numhosts:\fR <number>
|
||||
Number of hosts for which information is cached. Default is 1000.
|
||||
.It \fBinfra-cache-numlame:\fR <number>
|
||||
Number of zones per host for which lameness is cached. Default is 1000.
|
||||
Number of hosts for which information is cached. Default is 10000.
|
||||
.It \fBinfra-cache-lame-size:\fR <number>
|
||||
Number of bytes that the lameness cache per host is allowed to use. Default
|
||||
is 10 kb, which gives maximum storage for a couple score zones, depending on
|
||||
the lame zone name lengths.
|
||||
.It \fBdo-ip4:\fR <yes or no>
|
||||
Enable or disable whether ip4 queries are answered. Default is yes.
|
||||
.It \fBdo-ip6:\fR <yes or no>
|
||||
@@ -129,7 +133,7 @@ If given a chroot is done to the given directory. The default is none ("").
|
||||
.It \fBusername:\fR <name>
|
||||
If given, after binding the port the user privileges are dropped. Default is
|
||||
not to change user, username: "".
|
||||
|
||||
.Pp
|
||||
If this user is not capable of binding the
|
||||
port, reloads (by signal HUP) will still retain the opened ports.
|
||||
If you change the port number in the config file, and that new port number
|
||||
@@ -158,13 +162,13 @@ version is returned.
|
||||
Set the target fetch policy used by unbound to determine if it should fetch
|
||||
nameserver target addresses opportunistically. The policy is described per
|
||||
dependency depth.
|
||||
|
||||
.Pp
|
||||
The number of values determines the maximum dependency depth
|
||||
that unbound will pursue in answering a query.
|
||||
A value of -1 means to fetch all targets opportunistically for that dependency
|
||||
depth. A value of 0 means to fetch on demand only. A positive value fetches
|
||||
that many targets opportunistically.
|
||||
|
||||
.Pp
|
||||
Enclose the list between quotes ("") and put spaces between numbers.
|
||||
The default is "3 2 1 0 0". Setting all zeroes, "0 0 0 0 0" gives behaviour
|
||||
closer to that of BIND 9, while setting "-1 -1 -1 -1 -1" gives behaviour
|
||||
@@ -183,8 +187,66 @@ Will trust glue only if it is within the servers authority. Default is on.
|
||||
Do not query the given IP address. Can be IP4 or IP6. By default the
|
||||
DNS port is blocked for that address. Appending the character '@' and then
|
||||
the portnumber will block other port numbers.
|
||||
.It \fBmodule-config:\fR <"module names">
|
||||
Module configuration, a list of module names separated by spaces, surround
|
||||
the string with quotes (""). The modules can be validator, iterator.
|
||||
Setting this to "iterator" will result in a non-validating server.
|
||||
Setting this to "validator iterator" will turn on DNSSEC validation.
|
||||
You must also set trust-anchors for validation to be useful.
|
||||
.It \fBtrust-anchor-file:\fR <filename>
|
||||
File with trusted keys for validation. Both DS and DNSKEY entries can appear
|
||||
in the file. The format of the file is the standard DNS Zone file format.
|
||||
Default is "", or no trust anchor file.
|
||||
.It \fBtrust-anchor:\fR <"Resource Record">
|
||||
A DS or DNSKEY RR for a key to use for validation. Multiple entries can be
|
||||
given to specify multiple trusted keys, in addition to the trust-anchor-files.
|
||||
The resource record is entered in the same format as 'dig' or 'drill' prints
|
||||
them, the same format as in the zone file. Has to be on a single line, with
|
||||
"" around it. A TTL can be specified for ease of cut and paste, but is ignored.
|
||||
A class can be specified, but class IN is default.
|
||||
.It \fBtrusted-keys-file:\fR <filename>
|
||||
File with trusted keys for validation. Specify more than one file
|
||||
with several entries, one file per entry. Like \fBtrust-anchor-file\fR
|
||||
but has a different file format. Format is BIND-9 style format,
|
||||
the trusted-keys { name flag proto algo "key"; }; clauses are read.
|
||||
.It \fBval-override-date:\fR <rrsig-style date spec>
|
||||
Default is "" or "0", which disables this debugging feature. If enabled by
|
||||
giving a RRSIG style date, that date is used for verifying RRSIG inception
|
||||
and expiration dates, instead of the current date. Do not set this unless
|
||||
you are debugging signature inception and expiration.
|
||||
.It \fBval-bogus-ttl:\fR <number>
|
||||
The time to live for bogus data. This is data that has failed validation;
|
||||
due to invalid signatures or other checks. The TTL from that data cannot be
|
||||
trusted, and this value is used instead. The value is in seconds, default 900.
|
||||
The time interval prevents repeated revalidation of bogus data.
|
||||
.It \fBval-clean-additional:\fR <yes or no>
|
||||
Instruct the validator to remove data from the additional section of secure
|
||||
messages that are not signed properly. Messages that are insecure, bogus,
|
||||
indeterminate or unchecked are not affected. Default is yes. Use this setting
|
||||
to protect the users that rely on this validator for authentication from
|
||||
protentially bad data in the additional section.
|
||||
.It \fBval-permissive-mode:\fR <yes or no>
|
||||
Instruct the validator to mark bogus messages as indeterminate. The security
|
||||
checks are performed, but if the result is bogus (failed security), the
|
||||
reply is not withheld from the client with SERVFAIL as usual. The client
|
||||
receives the bogus data. For messages that are found to be secure the AD bit
|
||||
is set in replies. Also logging is performed as for full validation.
|
||||
The default value is "no".
|
||||
.It \fBval-nsec3-keysize-iterations:\fR <"list of values">
|
||||
List of keysize and iteration count values, separated by spaces, surrounded
|
||||
by quotes. Default is "1024 150 2048 500 4096 2500". This determines the
|
||||
maximum allowed NSEC3 iteration count before a message is simply marked
|
||||
insecure instead of performing the many hashing iterations. The list must
|
||||
be in ascending order and have at least one entry. If you set it to
|
||||
"1024 65535" there is no restriction to NSEC3 iteration values.
|
||||
This table must be kept short; a very long list could cause slower operation.
|
||||
.It \fBkey-cache-size:\fR <number>
|
||||
Number of bytes size of the key cache. Default is 4 megabytes.
|
||||
.It \fBkey-cache-slabs:\fR <number>
|
||||
Number of slabs in the key cache. Slabs reduce lock contention by threads.
|
||||
Must be set to a power of 2. Setting (close) to the number of cpus is a
|
||||
reasonable guess.
|
||||
.El
|
||||
|
||||
.Ss Stub Zone Options
|
||||
There may be multiple
|
||||
.Ic stub-zone:
|
||||
@@ -199,7 +261,6 @@ Name of stub zone nameserver. Is itself resolved before it is used.
|
||||
IP address of stub zone nameserver. Can be IP 4 or IP 6.
|
||||
To use a nondefault port for DNS communication append '@' with the port number.
|
||||
.El
|
||||
|
||||
.Ss Forward Zone Options
|
||||
There may be multiple
|
||||
.Ic forward-zone:
|
||||
@@ -217,7 +278,36 @@ Name of server to forward to. Is itself resolved before it is used.
|
||||
IP address of server to forward to. Can be IP 4 or IP 6.
|
||||
To use a nondefault port for DNS communication append '@' with the port number.
|
||||
.El
|
||||
|
||||
.Sh MEMORY CONTROL EXAMPLE
|
||||
In the example config settings below memory usage is reduced. Some service
|
||||
levels are lower, notable very large data and a high TCP load are no longer
|
||||
supported. Very large data and high TCP loads are exceptional for the DNS.
|
||||
DNSSEC validation is enabled, just add trust anchors.
|
||||
If you do not have to worry about programs using more than 1 meg of memory,
|
||||
the below example is not for you. Use the defaults to receive full service.
|
||||
.Pp
|
||||
.nf
|
||||
# example settings that reduce memory usage
|
||||
server:
|
||||
num-threads: 1
|
||||
outgoing-num-tcp: 1 # this limits TCP service, uses less buffers.
|
||||
incoming-num-tcp: 1
|
||||
outgoing-range: 1 # uses less memory, but less port randomness.
|
||||
msg-buffer-size: 8192 # note this limits service, 'no huge stuff'.
|
||||
msg-cache-size: 102400 # 100 Kb.
|
||||
msg-cache-slabs: 1
|
||||
rrset-cache-size: 102400 # 100 Kb.
|
||||
rrset-cache-slabs: 1
|
||||
infra-cache-numhosts: 200
|
||||
infra-cache-numlame: 10
|
||||
key-cache-size: 102400 # 100 Kb.
|
||||
key-cache-slabs: 1
|
||||
num-queries-per-thread: 30
|
||||
target-fetch-policy: "2 1 0 0 0 0"
|
||||
harden-large-queries: "yes"
|
||||
harden-short-bufsize: "yes"
|
||||
do-ip6: no # save a bit of memory if not used.
|
||||
.fi
|
||||
.Sh FILES
|
||||
.Bl -tag -width indent
|
||||
.It Pa /etc/unbound
|
||||
|
||||
@@ -90,13 +90,20 @@ delegpt_set_name(struct delegpt* dp, struct region* region, uint8_t* name)
|
||||
int
|
||||
delegpt_add_ns(struct delegpt* dp, struct region* region, uint8_t* name)
|
||||
{
|
||||
struct delegpt_ns* ns = (struct delegpt_ns*)region_alloc(region,
|
||||
struct delegpt_ns* ns;
|
||||
size_t len;
|
||||
(void)dname_count_size_labels(name, &len);
|
||||
/* slow check for duplicates to avoid counting failures when
|
||||
* adding the same server as a dependency twice */
|
||||
if(delegpt_find_ns(dp, name, len))
|
||||
return 1;
|
||||
ns = (struct delegpt_ns*)region_alloc(region,
|
||||
sizeof(struct delegpt_ns));
|
||||
if(!ns)
|
||||
return 0;
|
||||
ns->next = dp->nslist;
|
||||
ns->namelen = len;
|
||||
dp->nslist = ns;
|
||||
(void)dname_count_size_labels(name, &ns->namelen);
|
||||
ns->name = region_alloc_init(region, name, ns->namelen);
|
||||
ns->resolved = 0;
|
||||
return 1;
|
||||
|
||||
@@ -147,3 +147,10 @@ donotq_lookup(struct iter_donotq* donotq, struct sockaddr_storage* addr,
|
||||
return 1;
|
||||
return 0;
|
||||
}
|
||||
|
||||
size_t
|
||||
donotq_get_mem(struct iter_donotq* donotq)
|
||||
{
|
||||
if(!donotq) return 0;
|
||||
return sizeof(*donotq) + region_get_mem(donotq->region);
|
||||
}
|
||||
|
||||
@@ -103,4 +103,12 @@ int donotq_apply_cfg(struct iter_donotq* donotq, struct config_file* cfg);
|
||||
int donotq_lookup(struct iter_donotq* donotq, struct sockaddr_storage* addr,
|
||||
socklen_t addrlen);
|
||||
|
||||
/**
|
||||
* Get memory used by donotqueryaddresses structure.
|
||||
* @param donotq: structure for address storage.
|
||||
* @return bytes in use.
|
||||
*/
|
||||
size_t donotq_get_mem(struct iter_donotq* donotq);
|
||||
|
||||
|
||||
#endif /* ITERATOR_ITER_DONOTQ_H */
|
||||
|
||||
@@ -283,3 +283,11 @@ forwards_lookup(struct iter_forwards* fwd, uint8_t* qname, uint16_t qclass)
|
||||
return result->dp;
|
||||
return NULL;
|
||||
}
|
||||
|
||||
size_t
|
||||
forwards_get_mem(struct iter_forwards* fwd)
|
||||
{
|
||||
if(!fwd)
|
||||
return 0;
|
||||
return sizeof(*fwd) + region_get_mem(fwd->region);
|
||||
}
|
||||
|
||||
@@ -118,4 +118,11 @@ int forwards_apply_cfg(struct iter_forwards* fwd, struct config_file* cfg);
|
||||
struct delegpt* forwards_lookup(struct iter_forwards* fwd,
|
||||
uint8_t* qname, uint16_t qclass);
|
||||
|
||||
/**
|
||||
* Get memory in use by forward storage
|
||||
* @param fwd: forward storage.
|
||||
* @return bytes in use
|
||||
*/
|
||||
size_t forwards_get_mem(struct iter_forwards* fwd);
|
||||
|
||||
#endif /* ITERATOR_ITER_FWD_H */
|
||||
|
||||
@@ -375,3 +375,10 @@ hints_lookup_stub(struct iter_hints* hints, uint8_t* qname,
|
||||
return result->dp; /* need to prime this stub */
|
||||
return NULL;
|
||||
}
|
||||
|
||||
size_t
|
||||
hints_get_mem(struct iter_hints* hints)
|
||||
{
|
||||
if(!hints) return 0;
|
||||
return sizeof(*hints) + region_get_mem(hints->region);
|
||||
}
|
||||
|
||||
@@ -127,4 +127,11 @@ struct delegpt* hints_lookup_root(struct iter_hints* hints, uint16_t qclass);
|
||||
struct delegpt* hints_lookup_stub(struct iter_hints* hints,
|
||||
uint8_t* qname, uint16_t qclass, struct delegpt* dp);
|
||||
|
||||
/**
|
||||
* Get memory in use by hints
|
||||
* @param hints: hint storage.
|
||||
* @return bytes in use
|
||||
*/
|
||||
size_t hints_get_mem(struct iter_hints* hints);
|
||||
|
||||
#endif /* ITERATOR_ITER_HINTS_H */
|
||||
|
||||
@@ -138,6 +138,18 @@ response_type_from_server(struct dns_msg* msg, struct query_info* request,
|
||||
for(i=0; i<msg->rep->an_numrrsets; i++) {
|
||||
struct ub_packed_rrset_key* s = msg->rep->rrsets[i];
|
||||
|
||||
/* if the answer section has NS rrset, and qtype ANY
|
||||
* and the delegation is lower, and no CNAMEs followed,
|
||||
* this is a referral where the NS went to AN section */
|
||||
if((request->qtype == LDNS_RR_TYPE_ANY ||
|
||||
request->qtype == LDNS_RR_TYPE_NS) &&
|
||||
ntohs(s->rk.type) == LDNS_RR_TYPE_NS &&
|
||||
ntohs(s->rk.rrset_class) == request->qclass &&
|
||||
dname_strict_subdomain_c(s->rk.dname,
|
||||
origzone)) {
|
||||
return RESPONSE_TYPE_REFERRAL;
|
||||
}
|
||||
|
||||
/* If we have encountered an answer (before or
|
||||
* after a CNAME), then we are done! Note that
|
||||
* if qtype == CNAME then this will be noted as an
|
||||
|
||||
+13
-3
@@ -515,17 +515,27 @@ scrub_sanitize(ldns_buffer* pkt, struct msg_parse* msg, uint8_t* zonename,
|
||||
* same check can be used */
|
||||
|
||||
if(!pkt_sub(pkt, rrset->dname, zonename)) {
|
||||
if(!env->cfg->harden_glue) {
|
||||
if(msg->an_rrsets == 0 &&
|
||||
rrset->type == LDNS_RR_TYPE_NS &&
|
||||
rrset->section == LDNS_SECTION_AUTHORITY &&
|
||||
FLAGS_GET_RCODE(msg->flags) ==
|
||||
LDNS_RCODE_NOERROR) {
|
||||
/* noerror, nodata and this NS rrset is above
|
||||
* the zone. This is LAME!
|
||||
* Leave in the NS for lame classification. */
|
||||
} else if(!env->cfg->harden_glue) {
|
||||
/* store in cache! Since it is relevant
|
||||
* (from normalize) it will be picked up
|
||||
* from the cache to be used later */
|
||||
store_rrset(pkt, msg, env, rrset);
|
||||
remove_rrset("sanitize: storing potential "
|
||||
"poison RRset:", pkt, msg, prev, &rrset);
|
||||
} else
|
||||
continue;
|
||||
} else {
|
||||
remove_rrset("sanitize: removing potential "
|
||||
"poison RRset:", pkt, msg, prev, &rrset);
|
||||
continue;
|
||||
continue;
|
||||
}
|
||||
}
|
||||
prev = rrset;
|
||||
rrset = rrset->rrset_all_next;
|
||||
|
||||
+31
-74
@@ -55,34 +55,9 @@
|
||||
#include "util/config_file.h"
|
||||
#include "util/region-allocator.h"
|
||||
#include "util/data/msgparse.h"
|
||||
#include "util/data/dname.h"
|
||||
#include "util/random.h"
|
||||
|
||||
/** count number of integers in fetch policy string */
|
||||
static int
|
||||
fetch_count(const char* s)
|
||||
{
|
||||
/* format ::= (sp num)+ sp */
|
||||
/* num ::= [-](0-9)+ */
|
||||
/* sp ::= (space|tab)* */
|
||||
int num = 0;
|
||||
while(*s) {
|
||||
while(*s && isspace(*s))
|
||||
s++;
|
||||
if(!*s) /* end of string */
|
||||
break;
|
||||
if(*s == '-')
|
||||
s++;
|
||||
if(!*s) /* only - not allowed */
|
||||
return 0;
|
||||
if(!isdigit(*s)) /* bad character */
|
||||
return 0;
|
||||
while(*s && isdigit(*s))
|
||||
s++;
|
||||
num++;
|
||||
}
|
||||
return num;
|
||||
}
|
||||
|
||||
/** fillup fetch policy array */
|
||||
static void
|
||||
fetch_fill(struct iter_env* ie, const char* str)
|
||||
@@ -91,7 +66,8 @@ fetch_fill(struct iter_env* ie, const char* str)
|
||||
int i;
|
||||
for(i=0; i<ie->max_dependency_depth+1; i++) {
|
||||
ie->target_fetch_policy[i] = strtol(s, &e, 10);
|
||||
log_assert(s != e); /* parsed syntax already */
|
||||
if(s == e)
|
||||
fatal_exit("cannot parse fetch policy number %s", s);
|
||||
s = e;
|
||||
}
|
||||
}
|
||||
@@ -100,7 +76,7 @@ fetch_fill(struct iter_env* ie, const char* str)
|
||||
static int
|
||||
read_fetch_policy(struct iter_env* ie, const char* str)
|
||||
{
|
||||
int count = fetch_count(str);
|
||||
int count = cfg_count_numbers(str);
|
||||
if(count < 1) {
|
||||
log_err("Cannot parse target fetch policy: \"%s\"", str);
|
||||
return 0;
|
||||
@@ -296,51 +272,7 @@ int
|
||||
iter_dns_store(struct module_env* env, struct query_info* msgqinf,
|
||||
struct reply_info* msgrep, int is_referral)
|
||||
{
|
||||
struct reply_info* rep = NULL;
|
||||
/* alloc, malloc properly (not in region, like msg is) */
|
||||
rep = reply_info_copy(msgrep, env->alloc, NULL);
|
||||
if(!rep)
|
||||
return 0;
|
||||
|
||||
if(is_referral) {
|
||||
/* store rrsets */
|
||||
struct rrset_ref ref;
|
||||
uint32_t now = time(NULL);
|
||||
size_t i;
|
||||
for(i=0; i<rep->rrset_count; i++) {
|
||||
packed_rrset_ttl_add((struct packed_rrset_data*)
|
||||
rep->rrsets[i]->entry.data, now);
|
||||
ref.key = rep->rrsets[i];
|
||||
ref.id = rep->rrsets[i]->id;
|
||||
/*ignore ret: it was in the cache, ref updated */
|
||||
(void)rrset_cache_update(env->rrset_cache, &ref,
|
||||
env->alloc, now);
|
||||
}
|
||||
free(rep);
|
||||
return 1;
|
||||
} else {
|
||||
/* store msg, and rrsets */
|
||||
struct query_info qinf;
|
||||
hashvalue_t h;
|
||||
|
||||
qinf = *msgqinf;
|
||||
qinf.qname = memdup(msgqinf->qname, msgqinf->qname_len);
|
||||
if(!qinf.qname) {
|
||||
reply_info_parsedelete(rep, env->alloc);
|
||||
return 0;
|
||||
}
|
||||
/* fixup flags to be sensible for a reply based on the cache */
|
||||
/* this module means that RA is available. It is an answer QR.
|
||||
* Not AA from cache. Not CD in cache (depends on client bit). */
|
||||
rep->flags |= (BIT_RA | BIT_QR);
|
||||
rep->flags &= ~(BIT_AA | BIT_CD);
|
||||
h = query_info_hash(&qinf);
|
||||
dns_cache_store_msg(env, &qinf, h, rep);
|
||||
/* qname is used inside query_info_entrysetup, and set to
|
||||
* NULL. If it has not been used, free it. free(0) is safe. */
|
||||
free(qinf.qname);
|
||||
}
|
||||
return 1;
|
||||
return dns_cache_store(env, msgqinf, msgrep, is_referral);
|
||||
}
|
||||
|
||||
int
|
||||
@@ -365,7 +297,8 @@ causes_cycle(struct module_qstate* qstate, uint8_t* name, size_t namelen,
|
||||
qinf.qname_len = namelen;
|
||||
qinf.qtype = t;
|
||||
qinf.qclass = c;
|
||||
return (*qstate->env->detect_cycle)(qstate, &qinf);
|
||||
return (*qstate->env->detect_cycle)(qstate, &qinf,
|
||||
(uint16_t)(BIT_RD|BIT_CD), qstate->is_priming);
|
||||
}
|
||||
|
||||
void
|
||||
@@ -388,3 +321,27 @@ iter_mark_cycle_targets(struct module_qstate* qstate, struct delegpt* dp)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
int
|
||||
iter_dp_is_useless(uint16_t flags, struct delegpt* dp)
|
||||
{
|
||||
struct delegpt_ns* ns;
|
||||
/* check:
|
||||
* o all NS items are required glue.
|
||||
* o no addresses are provided.
|
||||
* o RD qflag is on.
|
||||
*/
|
||||
if(!(flags&BIT_RD))
|
||||
return 0;
|
||||
/* either available or unused targets */
|
||||
if(dp->usable_list || dp->result_list)
|
||||
return 0;
|
||||
|
||||
for(ns = dp->nslist; ns; ns = ns->next) {
|
||||
if(ns->resolved) /* skip failed targets */
|
||||
continue;
|
||||
if(!dname_subdomain_c(ns->name, dp->name))
|
||||
return 0; /* one address is not required glue */
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -128,4 +128,12 @@ int iter_ns_probability(struct ub_randstate* rnd, int n, int m);
|
||||
*/
|
||||
void iter_mark_cycle_targets(struct module_qstate* qstate, struct delegpt* dp);
|
||||
|
||||
/**
|
||||
* See if delegation is useful or offers immediately no targets for
|
||||
* further recursion.
|
||||
* @param flags: query flags.
|
||||
* @param dp: delegpt to check.
|
||||
*/
|
||||
int iter_dp_is_useless(uint16_t flags, struct delegpt* dp);
|
||||
|
||||
#endif /* ITERATOR_ITER_UTILS_H */
|
||||
|
||||
+266
-100
@@ -81,15 +81,14 @@ static void
|
||||
iter_deinit(struct module_env* env, int id)
|
||||
{
|
||||
struct iter_env* iter_env;
|
||||
if(!env || !env->modinfo)
|
||||
if(!env || !env->modinfo || !env->modinfo[id])
|
||||
return;
|
||||
iter_env = (struct iter_env*)env->modinfo[id];
|
||||
free(iter_env->target_fetch_policy);
|
||||
hints_delete(iter_env->hints);
|
||||
forwards_delete(iter_env->fwds);
|
||||
donotq_delete(iter_env->donotq);
|
||||
if(iter_env)
|
||||
free(iter_env);
|
||||
free(iter_env);
|
||||
}
|
||||
|
||||
/** new query for iterator */
|
||||
@@ -104,16 +103,17 @@ iter_new(struct module_qstate* qstate, int id)
|
||||
memset(iq, 0, sizeof(*iq));
|
||||
iq->state = INIT_REQUEST_STATE;
|
||||
iq->final_state = FINISHED_STATE;
|
||||
iq->prepend_list = NULL;
|
||||
iq->prepend_last = NULL;
|
||||
iq->an_prepend_list = NULL;
|
||||
iq->an_prepend_last = NULL;
|
||||
iq->ns_prepend_list = NULL;
|
||||
iq->ns_prepend_last = NULL;
|
||||
iq->dp = NULL;
|
||||
iq->depth = 0;
|
||||
iq->num_target_queries = 0;
|
||||
iq->num_current_queries = 0;
|
||||
iq->query_restart_count = 0;
|
||||
iq->referral_count = 0;
|
||||
iq->priming = 0;
|
||||
iq->priming_stub = 0;
|
||||
iq->wait_priming_stub = 0;
|
||||
iq->refetch_glue = 0;
|
||||
iq->chase_flags = qstate->query_flags;
|
||||
/* Start with the (current) qname. */
|
||||
@@ -217,52 +217,69 @@ error_response(struct module_qstate* qstate, int id, int rcode)
|
||||
verbose(VERB_DETAIL, "return error response %s",
|
||||
ldns_lookup_by_id(ldns_rcodes, rcode)?
|
||||
ldns_lookup_by_id(ldns_rcodes, rcode)->name:"??");
|
||||
/* tell clients that we failed */
|
||||
(*qstate->env->query_done)(qstate, rcode, NULL);
|
||||
/* tell our parents that we failed */
|
||||
(*qstate->env->walk_supers)(qstate, id, &error_supers);
|
||||
qstate->return_rcode = rcode;
|
||||
qstate->return_msg = NULL;
|
||||
qstate->ext_state[id] = module_finished;
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** prepend the prepend list in the answer section of dns_msg */
|
||||
/** prepend the prepend list in the answer and authority section of dns_msg */
|
||||
static int
|
||||
iter_prepend(struct iter_qstate* iq, struct dns_msg* msg,
|
||||
struct region* region)
|
||||
{
|
||||
struct iter_prep_list* p;
|
||||
struct ub_packed_rrset_key** sets;
|
||||
size_t num = 0;
|
||||
for(p = iq->prepend_list; p; p = p->next)
|
||||
num++;
|
||||
if(num == 0)
|
||||
size_t num_an = 0, num_ns = 0;;
|
||||
for(p = iq->an_prepend_list; p; p = p->next)
|
||||
num_an++;
|
||||
for(p = iq->ns_prepend_list; p; p = p->next)
|
||||
num_ns++;
|
||||
if(num_an + num_ns == 0)
|
||||
return 1;
|
||||
verbose(VERB_ALGO, "prepending %d rrsets", (int)num);
|
||||
sets = region_alloc(region, (num+msg->rep->rrset_count) *
|
||||
verbose(VERB_ALGO, "prepending %d rrsets", (int)num_an + (int)num_ns);
|
||||
sets = region_alloc(region, (num_an+num_ns+msg->rep->rrset_count) *
|
||||
sizeof(struct ub_packed_rrset_key*));
|
||||
if(!sets)
|
||||
return 0;
|
||||
memcpy(sets+num, msg->rep->rrsets, msg->rep->rrset_count *
|
||||
sizeof(struct ub_packed_rrset_key*));
|
||||
num = 0;
|
||||
for(p = iq->prepend_list; p; p = p->next) {
|
||||
sets[num++] = p->rrset;
|
||||
/* ANSWER section */
|
||||
num_an = 0;
|
||||
for(p = iq->an_prepend_list; p; p = p->next) {
|
||||
sets[num_an++] = p->rrset;
|
||||
}
|
||||
msg->rep->rrset_count += num;
|
||||
msg->rep->an_numrrsets += num;
|
||||
memcpy(sets+num_an, msg->rep->rrsets, msg->rep->an_numrrsets *
|
||||
sizeof(struct ub_packed_rrset_key*));
|
||||
/* AUTH section */
|
||||
num_ns = 0;
|
||||
for(p = iq->ns_prepend_list; p; p = p->next) {
|
||||
sets[msg->rep->an_numrrsets + num_an + num_ns++] = p->rrset;
|
||||
}
|
||||
memcpy(sets + num_an + msg->rep->an_numrrsets + num_ns,
|
||||
msg->rep->rrsets + msg->rep->an_numrrsets,
|
||||
(msg->rep->ns_numrrsets + msg->rep->ar_numrrsets) *
|
||||
sizeof(struct ub_packed_rrset_key*));
|
||||
|
||||
/* if the rcode was NXDOMAIN, and we prepended DNAME/CNAMEs, then
|
||||
* it should now be NOERROR. */
|
||||
if(FLAGS_GET_RCODE(msg->rep->flags) == LDNS_RCODE_NXDOMAIN) {
|
||||
FLAGS_SET_RCODE(msg->rep->flags, LDNS_RCODE_NOERROR);
|
||||
}
|
||||
msg->rep->rrset_count += num_an + num_ns;
|
||||
msg->rep->an_numrrsets += num_an;
|
||||
msg->rep->ns_numrrsets += num_ns;
|
||||
msg->rep->rrsets = sets;
|
||||
return 1;
|
||||
}
|
||||
|
||||
/**
|
||||
* Add rrset to prepend list
|
||||
* Add rrset to ANSWER prepend list
|
||||
* @param qstate: query state.
|
||||
* @param iq: iterator query state.
|
||||
* @param rrset: rrset to add.
|
||||
* @return false on failure (malloc).
|
||||
*/
|
||||
static int
|
||||
iter_add_prepend(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
iter_add_prepend_answer(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
struct ub_packed_rrset_key* rrset)
|
||||
{
|
||||
struct iter_prep_list* p = (struct iter_prep_list*)region_alloc(
|
||||
@@ -272,10 +289,35 @@ iter_add_prepend(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
p->rrset = rrset;
|
||||
p->next = NULL;
|
||||
/* add at end */
|
||||
if(iq->prepend_last)
|
||||
iq->prepend_last->next = p;
|
||||
else iq->prepend_list = p;
|
||||
iq->prepend_last = p;
|
||||
if(iq->an_prepend_last)
|
||||
iq->an_prepend_last->next = p;
|
||||
else iq->an_prepend_list = p;
|
||||
iq->an_prepend_last = p;
|
||||
return 1;
|
||||
}
|
||||
|
||||
/**
|
||||
* Add rrset to AUTHORITY prepend list
|
||||
* @param qstate: query state.
|
||||
* @param iq: iterator query state.
|
||||
* @param rrset: rrset to add.
|
||||
* @return false on failure (malloc).
|
||||
*/
|
||||
static int
|
||||
iter_add_prepend_auth(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
struct ub_packed_rrset_key* rrset)
|
||||
{
|
||||
struct iter_prep_list* p = (struct iter_prep_list*)region_alloc(
|
||||
qstate->region, sizeof(struct iter_prep_list));
|
||||
if(!p)
|
||||
return 0;
|
||||
p->rrset = rrset;
|
||||
p->next = NULL;
|
||||
/* add at end */
|
||||
if(iq->ns_prepend_last)
|
||||
iq->ns_prepend_last->next = p;
|
||||
else iq->ns_prepend_list = p;
|
||||
iq->ns_prepend_last = p;
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -312,7 +354,7 @@ handle_cname_response(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
* directly. */
|
||||
if(ntohs(r->rk.type) == LDNS_RR_TYPE_DNAME &&
|
||||
dname_strict_subdomain_c(*mname, r->rk.dname)) {
|
||||
if(!iter_add_prepend(qstate, iq, r))
|
||||
if(!iter_add_prepend_answer(qstate, iq, r))
|
||||
return 0;
|
||||
continue;
|
||||
}
|
||||
@@ -320,13 +362,24 @@ handle_cname_response(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
if(ntohs(r->rk.type) == LDNS_RR_TYPE_CNAME &&
|
||||
query_dname_compare(*mname, r->rk.dname) == 0) {
|
||||
/* Add this relevant CNAME rrset to the prepend list.*/
|
||||
if(!iter_add_prepend(qstate, iq, r))
|
||||
if(!iter_add_prepend_answer(qstate, iq, r))
|
||||
return 0;
|
||||
get_cname_target(r, mname, mname_len);
|
||||
}
|
||||
|
||||
/* Other rrsets in the section are ignored. */
|
||||
}
|
||||
/* add authority rrsets to authority prepend, for wildcarded CNAMEs */
|
||||
for(i=msg->rep->an_numrrsets; i<msg->rep->an_numrrsets +
|
||||
msg->rep->ns_numrrsets; i++) {
|
||||
struct ub_packed_rrset_key* r = msg->rep->rrsets[i];
|
||||
/* only add NSEC/NSEC3, as they may be needed for validation */
|
||||
if(ntohs(r->rk.type) == LDNS_RR_TYPE_NSEC ||
|
||||
ntohs(r->rk.type) == LDNS_RR_TYPE_NSEC3) {
|
||||
if(!iter_add_prepend_auth(qstate, iq, r))
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -376,9 +429,7 @@ generate_sub_request(uint8_t* qname, size_t qnamelen, uint16_t qtype,
|
||||
* the resolution chain, which might have a validator. We are
|
||||
* uninterested in validating things not on the direct resolution
|
||||
* path. */
|
||||
/* Turned off! CD does not make a difference in query results.
|
||||
qstate->query_flags |= BIT_CD;
|
||||
*/
|
||||
qflags |= BIT_CD;
|
||||
|
||||
/* attach subquery, lookup existing or make a new one */
|
||||
if(!(*qstate->env->attach_sub)(qstate, &qinf, qflags, prime, &subq)) {
|
||||
@@ -433,6 +484,12 @@ prime_root(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
verbose(VERB_ALGO, "Cannot prime due to lack of hints");
|
||||
return 0;
|
||||
}
|
||||
/* copy dp; to avoid messing up available list for other thr/queries */
|
||||
dp = delegpt_copy(dp, qstate->region);
|
||||
if(!dp) {
|
||||
log_err("out of memory priming root, copydp");
|
||||
return 0;
|
||||
}
|
||||
/* Priming requests start at the QUERYTARGETS state, skipping
|
||||
* the normal INIT state logic (which would cause an infloop). */
|
||||
if(!generate_sub_request((uint8_t*)"\000", 1, LDNS_RR_TYPE_NS,
|
||||
@@ -448,7 +505,6 @@ prime_root(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
subiq->dp = dp;
|
||||
/* there should not be any target queries. */
|
||||
subiq->num_target_queries = 0;
|
||||
subiq->priming = 1;
|
||||
}
|
||||
|
||||
/* this module stops, our submodule starts, and does the query. */
|
||||
@@ -500,13 +556,19 @@ prime_stub(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
(struct iter_qstate*)subq->minfo[id];
|
||||
|
||||
/* Set the initial delegation point to the hint. */
|
||||
subiq->dp = stub_dp;
|
||||
/* make copy to avoid use of stub dp by different qs/threads */
|
||||
subiq->dp = delegpt_copy(stub_dp, subq->region);
|
||||
if(!subiq->dp) {
|
||||
log_err("out of memory priming stub, copydp");
|
||||
(*qstate->env->kill_sub)(subq);
|
||||
(void)error_response(qstate, id, LDNS_RCODE_SERVFAIL);
|
||||
return 1; /* return 1 to make module stop, with error */
|
||||
}
|
||||
/* there should not be any target queries -- although there
|
||||
* wouldn't be anyway, since stub hints never have
|
||||
* missing targets. */
|
||||
subiq->num_target_queries = 0;
|
||||
subiq->priming = 1;
|
||||
subiq->priming_stub = 1;
|
||||
subiq->wait_priming_stub = 1;
|
||||
}
|
||||
|
||||
/* this module stops, our submodule starts, and does the query. */
|
||||
@@ -651,32 +713,80 @@ processInitRequest(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
delnamelen = iq->qchase.qname_len;
|
||||
}
|
||||
if((iq->qchase.qtype == LDNS_RR_TYPE_DS || iq->refetch_glue)
|
||||
&& delname[0] != 0) {
|
||||
&& !dname_is_root(delname)) {
|
||||
/* do not adjust root label, remove first label from delname */
|
||||
size_t lablen = delname[0] + 1;
|
||||
delname += lablen;
|
||||
delnamelen -= lablen;
|
||||
dname_remove_label(&delname, &delnamelen);
|
||||
}
|
||||
|
||||
/* Lookup the delegation in the cache. If null, then the cache needs
|
||||
* to be primed for the qclass. */
|
||||
iq->dp = dns_cache_find_delegation(qstate->env, delname, delnamelen,
|
||||
iq->qchase.qtype, iq->qchase.qclass, qstate->region,
|
||||
&iq->deleg_msg);
|
||||
while(1) {
|
||||
|
||||
/* Lookup the delegation in the cache. If null, then the cache needs
|
||||
* to be primed for the qclass. */
|
||||
iq->dp = dns_cache_find_delegation(qstate->env, delname,
|
||||
delnamelen, iq->qchase.qtype, iq->qchase.qclass,
|
||||
qstate->region, &iq->deleg_msg, (uint32_t)time(NULL));
|
||||
|
||||
/* If the cache has returned nothing, then we have a root priming
|
||||
* situation. */
|
||||
if(iq->dp == NULL) {
|
||||
/* Note that the result of this will set a new
|
||||
* DelegationPoint based on the result of priming. */
|
||||
if(!prime_root(qstate, iq, ie, id, iq->qchase.qclass))
|
||||
return error_response(qstate, id, LDNS_RCODE_REFUSED);
|
||||
/* If the cache has returned nothing, then we have a
|
||||
* root priming situation. */
|
||||
if(iq->dp == NULL) {
|
||||
/* Note that the result of this will set a new
|
||||
* DelegationPoint based on the result of priming. */
|
||||
if(!prime_root(qstate, iq, ie, id, iq->qchase.qclass))
|
||||
return error_response(qstate, id,
|
||||
LDNS_RCODE_REFUSED);
|
||||
|
||||
/* priming creates and sends a subordinate query, with
|
||||
* this query as the parent. So further processing for
|
||||
* this event will stop until reactivated by the results
|
||||
* of priming. */
|
||||
return 0;
|
||||
/* priming creates and sends a subordinate query, with
|
||||
* this query as the parent. So further processing for
|
||||
* this event will stop until reactivated by the
|
||||
* results of priming. */
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* see if this dp not useless.
|
||||
* It is useless if:
|
||||
* o all NS items are required glue.
|
||||
* o no addresses are provided.
|
||||
* o RD qflag is on.
|
||||
* Instead, go up one level, and try to get even further
|
||||
* If the root was useless, use safety belt information.
|
||||
* Only check cache returns, because replies for servers
|
||||
* could be useless but lead to loops (bumping into the
|
||||
* same server reply) if useless-checked.
|
||||
*/
|
||||
if(iter_dp_is_useless(qstate->query_flags, iq->dp)) {
|
||||
if(dname_is_root(iq->dp->name)) {
|
||||
/* use safety belt */
|
||||
verbose(VERB_OPS, "Priming problem: NS but "
|
||||
"no addresses. Fallback to the safety belt.");
|
||||
iq->dp = hints_lookup_root(ie->hints,
|
||||
iq->qchase.qclass);
|
||||
/* note deleg_msg is from previous lookup,
|
||||
* but RD is on, so it is not used */
|
||||
if(!iq->dp) {
|
||||
log_err("internal error: no hints dp");
|
||||
return error_response(qstate, id,
|
||||
LDNS_RCODE_REFUSED);
|
||||
}
|
||||
iq->dp = delegpt_copy(iq->dp, qstate->region);
|
||||
if(!iq->dp) {
|
||||
log_err("out of memory in safety belt");
|
||||
return error_response(qstate, id,
|
||||
LDNS_RCODE_SERVFAIL);
|
||||
}
|
||||
break;
|
||||
} else {
|
||||
log_info("cache delegation was useless:");
|
||||
delegpt_log(iq->dp);
|
||||
/* go up */
|
||||
delname = iq->dp->name;
|
||||
delnamelen = iq->dp->namelen;
|
||||
dname_remove_label(&delname, &delnamelen);
|
||||
}
|
||||
} else break;
|
||||
}
|
||||
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
log_info("cache delegation returns delegpt");
|
||||
delegpt_log(iq->dp);
|
||||
}
|
||||
|
||||
/* Reset the RD flag. If this is a query restart, then the RD
|
||||
@@ -921,6 +1031,15 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
verbose(VERB_DETAIL, "Failed to get a delegation, giving up");
|
||||
return error_response(qstate, id, LDNS_RCODE_SERVFAIL);
|
||||
}
|
||||
delegpt_log(iq->dp);
|
||||
|
||||
if(iq->num_current_queries>0) {
|
||||
/* already busy answering a query, this restart is because
|
||||
* more delegpt addrs became available, wait for existing
|
||||
* query. */
|
||||
verbose(VERB_ALGO, "woke up, but wait for outstanding query");
|
||||
return 0;
|
||||
}
|
||||
|
||||
tf_policy = 0;
|
||||
if(iq->depth <= ie->max_dependency_depth) {
|
||||
@@ -1002,11 +1121,6 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
iq->num_current_queries);
|
||||
return 0;
|
||||
}
|
||||
/* move other targets to slumber list */
|
||||
if(iq->num_target_queries>0) {
|
||||
(*qstate->env->detach_subs)(qstate);
|
||||
iq->num_target_queries = 0;
|
||||
}
|
||||
|
||||
/* We have a valid target. */
|
||||
log_query_info(VERB_DETAIL, "sending query:", &iq->qchase);
|
||||
@@ -1015,7 +1129,8 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
outq = (*qstate->env->send_query)(
|
||||
iq->qchase.qname, iq->qchase.qname_len,
|
||||
iq->qchase.qtype, iq->qchase.qclass,
|
||||
iq->chase_flags, 1, &target->addr, target->addrlen, qstate);
|
||||
iq->chase_flags, EDNS_DO|BIT_CD,
|
||||
&target->addr, target->addrlen, qstate);
|
||||
if(!outq) {
|
||||
log_err("error sending query to auth server; skip this address");
|
||||
log_addr("error for address:", &target->addr, target->addrlen);
|
||||
@@ -1184,17 +1299,13 @@ processQueryResponse(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
static void
|
||||
prime_supers(struct module_qstate* qstate, int id, struct module_qstate* forq)
|
||||
{
|
||||
struct iter_qstate* iq = (struct iter_qstate*)qstate->minfo[id];
|
||||
struct iter_qstate* foriq = (struct iter_qstate*)forq->minfo[id];
|
||||
struct delegpt* dp = NULL;
|
||||
enum response_type type = response_type_from_server(iq->response,
|
||||
&iq->qchase, iq->dp);
|
||||
|
||||
log_assert(iq->priming || iq->priming_stub);
|
||||
if(type == RESPONSE_TYPE_ANSWER) {
|
||||
/* Convert our response to a delegation point */
|
||||
dp = delegpt_from_message(iq->response, forq->region);
|
||||
}
|
||||
log_assert(qstate->is_priming || foriq->wait_priming_stub);
|
||||
log_assert(qstate->return_rcode == LDNS_RCODE_NOERROR);
|
||||
/* Convert our response to a delegation point */
|
||||
dp = delegpt_from_message(qstate->return_msg, forq->region);
|
||||
if(!dp) {
|
||||
/* if there is no convertable delegation point, then
|
||||
* the ANSWER type was (presumably) a negative answer. */
|
||||
@@ -1205,10 +1316,10 @@ prime_supers(struct module_qstate* qstate, int id, struct module_qstate* forq)
|
||||
return;
|
||||
}
|
||||
|
||||
log_query_info(VERB_DETAIL, "priming successful for", &iq->qchase);
|
||||
log_query_info(VERB_DETAIL, "priming successful for", &qstate->qinfo);
|
||||
delegpt_log(dp);
|
||||
foriq->dp = dp;
|
||||
foriq->deleg_msg = dns_copy_msg(iq->response, forq->region);
|
||||
foriq->deleg_msg = dns_copy_msg(qstate->return_msg, forq->region);
|
||||
if(!foriq->deleg_msg) {
|
||||
log_err("copy prime response: out of memory");
|
||||
foriq->dp = NULL;
|
||||
@@ -1218,9 +1329,10 @@ prime_supers(struct module_qstate* qstate, int id, struct module_qstate* forq)
|
||||
|
||||
/* root priming responses go to init stage 2, priming stub
|
||||
* responses to to stage 3. */
|
||||
if(iq->priming_stub)
|
||||
if(foriq->wait_priming_stub) {
|
||||
foriq->state = INIT_REQUEST_3_STATE;
|
||||
else foriq->state = INIT_REQUEST_2_STATE;
|
||||
foriq->wait_priming_stub = 0;
|
||||
} else foriq->state = INIT_REQUEST_2_STATE;
|
||||
/* because we are finished, the parent will be reactivated */
|
||||
}
|
||||
|
||||
@@ -1239,14 +1351,19 @@ prime_supers(struct module_qstate* qstate, int id, struct module_qstate* forq)
|
||||
static int
|
||||
processPrimeResponse(struct module_qstate* qstate, int id)
|
||||
{
|
||||
struct iter_qstate* iq = (struct iter_qstate*)qstate->minfo[id];
|
||||
enum response_type type = response_type_from_server(iq->response,
|
||||
&iq->qchase, iq->dp);
|
||||
if(type == RESPONSE_TYPE_ANSWER) {
|
||||
qstate->return_rcode = LDNS_RCODE_NOERROR;
|
||||
qstate->return_msg = iq->response;
|
||||
} else {
|
||||
qstate->return_rcode = LDNS_RCODE_SERVFAIL;
|
||||
qstate->return_msg = NULL;
|
||||
}
|
||||
|
||||
/* This event is finished. */
|
||||
qstate->ext_state[id] = module_finished;
|
||||
|
||||
/* there should be no outside clients subscribed tell them to
|
||||
* bugger off (and retry) */
|
||||
(*qstate->env->query_done)(qstate, LDNS_RCODE_SERVFAIL, NULL);
|
||||
/* tell interested supers that priming is done */
|
||||
(*qstate->env->walk_supers)(qstate, id, &prime_supers);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -1257,7 +1374,7 @@ processPrimeResponse(struct module_qstate* qstate, int id)
|
||||
* to received target responses (caching, updating the current delegation
|
||||
* point, etc).
|
||||
* Callback from walk_supers for every super state that is interested in
|
||||
* the results from thiis query.
|
||||
* the results from this query.
|
||||
*
|
||||
* @param qstate: query state.
|
||||
* @param id: module id.
|
||||
@@ -1271,8 +1388,11 @@ processTargetResponse(struct module_qstate* qstate, int id,
|
||||
struct iter_qstate* foriq = (struct iter_qstate*)forq->minfo[id];
|
||||
struct ub_packed_rrset_key* rrset;
|
||||
struct delegpt_ns* dpns;
|
||||
log_assert(qstate->return_rcode == LDNS_RCODE_NOERROR);
|
||||
|
||||
foriq->state = QUERYTARGETS_STATE;
|
||||
log_query_info(VERB_ALGO, "processTargetResponse", &qstate->qinfo);
|
||||
log_query_info(VERB_ALGO, "processTargetResponse super", &forq->qinfo);
|
||||
|
||||
/* check to see if parent event is still interested (in orig name). */
|
||||
dpns = delegpt_find_ns(foriq->dp, qstate->qinfo.qname,
|
||||
@@ -1297,7 +1417,7 @@ processTargetResponse(struct module_qstate* qstate, int id,
|
||||
* the original event.
|
||||
* NOTE: we could only look for the AnswerRRset if the
|
||||
* response type was ANSWER. */
|
||||
rrset = reply_find_answer_rrset(&iq->qchase, iq->response->rep);
|
||||
rrset = reply_find_answer_rrset(&iq->qchase, qstate->return_msg->rep);
|
||||
if(rrset) {
|
||||
/* if CNAMEs have been followed - add new NS to delegpt. */
|
||||
/* BTW. RFC 1918 says NS should not have got CNAMEs. Robust. */
|
||||
@@ -1309,7 +1429,12 @@ processTargetResponse(struct module_qstate* qstate, int id,
|
||||
}
|
||||
if(!delegpt_add_rrset(foriq->dp, forq->region, rrset))
|
||||
log_err("out of memory adding targets");
|
||||
} else dpns->resolved = 1; /* fail the target */
|
||||
verbose(VERB_ALGO, "added target response");
|
||||
delegpt_log(foriq->dp);
|
||||
} else {
|
||||
verbose(VERB_ALGO, "iterator TargetResponse failed");
|
||||
dpns->resolved = 1; /* fail the target */
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -1352,28 +1477,54 @@ processFinished(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
/* if (mPrivateTTL > 0){IterUtils.setPrivateTTL(resp, mPrivateTTL); } */
|
||||
|
||||
/* prepend any items we have accumulated */
|
||||
if(iq->prepend_list) {
|
||||
if(iq->an_prepend_list || iq->ns_prepend_list) {
|
||||
if(!iter_prepend(iq, iq->response, qstate->region)) {
|
||||
log_err("prepend rrsets: out of memory");
|
||||
return error_response(qstate, id, LDNS_RCODE_SERVFAIL);
|
||||
}
|
||||
/* store message with the finished prepended items */
|
||||
if(!iter_dns_store(qstate->env, &qstate->qinfo,
|
||||
iq->response->rep, 0))
|
||||
return error_response(qstate, id, LDNS_RCODE_SERVFAIL);
|
||||
/* reset the query name back */
|
||||
iq->response->qinfo = qstate->qinfo;
|
||||
/* store message with the finished prepended items,
|
||||
* but only if we did recursion. The nonrecursion referral
|
||||
* from cache does not need to be stored in the msg cache. */
|
||||
if(qstate->query_flags&BIT_RD) {
|
||||
if(!iter_dns_store(qstate->env, &qstate->qinfo,
|
||||
iq->response->rep, 0))
|
||||
return error_response(qstate, id,
|
||||
LDNS_RCODE_SERVFAIL);
|
||||
}
|
||||
}
|
||||
if(query_dname_compare(qstate->qinfo.qname,
|
||||
iq->response->qinfo.qname) == 0) {
|
||||
/* use server supplied upper/lower case */
|
||||
qstate->qinfo.qname = iq->response->qinfo.qname;
|
||||
}
|
||||
(*qstate->env->query_done)(qstate, LDNS_RCODE_NOERROR,
|
||||
iq->response->rep);
|
||||
(*qstate->env->walk_supers)(qstate, id, &processTargetResponse);
|
||||
|
||||
qstate->return_rcode = LDNS_RCODE_NOERROR;
|
||||
qstate->return_msg = iq->response;
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* Return priming query results to interestes super querystates.
|
||||
*
|
||||
* Sets the delegation point and delegation message (not nonRD queries).
|
||||
* This is a callback from walk_supers.
|
||||
*
|
||||
* @param qstate: query state that finished.
|
||||
* @param id: module id.
|
||||
* @param super: the qstate to inform.
|
||||
*/
|
||||
static void
|
||||
iter_inform_super(struct module_qstate* qstate, int id,
|
||||
struct module_qstate* super)
|
||||
{
|
||||
if(qstate->return_rcode != LDNS_RCODE_NOERROR)
|
||||
error_supers(qstate, id, super);
|
||||
else if(qstate->is_priming)
|
||||
prime_supers(qstate, id, super);
|
||||
else processTargetResponse(qstate, id, super);
|
||||
}
|
||||
|
||||
/**
|
||||
* Handle iterator state.
|
||||
* Handle events. This is the real processing loop for events, responsible
|
||||
@@ -1487,6 +1638,8 @@ process_response(struct module_qstate* qstate, struct iter_qstate* iq,
|
||||
/* edns is not examined, but removed from message to help cache */
|
||||
if(parse_extract_edns(prs, &edns) != LDNS_RCODE_NOERROR)
|
||||
goto handle_it;
|
||||
/* remove CD-bit, we asked for in case we handle validation ourself */
|
||||
prs->flags &= ~BIT_CD;
|
||||
|
||||
/* normalize and sanitize: easy to delete items from linked lists */
|
||||
if(!scrub_message(pkt, prs, &iq->qchase, iq->dp->name,
|
||||
@@ -1524,7 +1677,8 @@ iter_operate(struct module_qstate* qstate, enum module_ev event, int id,
|
||||
&iq->qchase);
|
||||
|
||||
/* perform iterator state machine */
|
||||
if(event == module_event_new && iq == NULL) {
|
||||
if((event == module_event_new || event == module_event_pass) &&
|
||||
iq == NULL) {
|
||||
if(!iter_new(qstate, id)) {
|
||||
(void)error_response(qstate, id, LDNS_RCODE_SERVFAIL);
|
||||
return;
|
||||
@@ -1566,12 +1720,24 @@ iter_clear(struct module_qstate* qstate, int id)
|
||||
qstate->minfo[id] = NULL;
|
||||
}
|
||||
|
||||
/** iterator alloc size routine */
|
||||
static size_t iter_get_mem(struct module_env* env, int id)
|
||||
{
|
||||
struct iter_env* ie = (struct iter_env*)env->modinfo[id];
|
||||
if(!ie)
|
||||
return 0;
|
||||
return sizeof(*ie) + sizeof(int)*((size_t)ie->max_dependency_depth+1)
|
||||
+ hints_get_mem(ie->hints) + forwards_get_mem(ie->fwds)
|
||||
+ donotq_get_mem(ie->donotq);
|
||||
}
|
||||
|
||||
/**
|
||||
* The iterator function block
|
||||
*/
|
||||
static struct module_func_block iter_block = {
|
||||
"iterator",
|
||||
&iter_init, &iter_deinit, &iter_operate, &iter_clear
|
||||
&iter_init, &iter_deinit, &iter_operate, &iter_inform_super,
|
||||
&iter_clear, &iter_get_mem
|
||||
};
|
||||
|
||||
struct module_func_block*
|
||||
|
||||
+12
-11
@@ -182,9 +182,17 @@ struct iter_qstate {
|
||||
* This is a list of RRsets that must be prepended to the
|
||||
* ANSWER section of a response before being sent upstream.
|
||||
*/
|
||||
struct iter_prep_list* prepend_list;
|
||||
struct iter_prep_list* an_prepend_list;
|
||||
/** Last element of the prepend list */
|
||||
struct iter_prep_list* prepend_last;
|
||||
struct iter_prep_list* an_prepend_last;
|
||||
|
||||
/**
|
||||
* This is the list of RRsets that must be prepended to the
|
||||
* AUTHORITY section of the response before being sent upstream.
|
||||
*/
|
||||
struct iter_prep_list* ns_prepend_list;
|
||||
/** Last element of the authority prepend list */
|
||||
struct iter_prep_list* ns_prepend_last;
|
||||
|
||||
/** query name used for chasing the results. Initially the same as
|
||||
* the state qinfo, but after CNAMEs this will be different.
|
||||
@@ -215,18 +223,11 @@ struct iter_qstate {
|
||||
/** the number of times this query as followed a referral. */
|
||||
int referral_count;
|
||||
|
||||
/**
|
||||
* This flag, if true, means that this event is a priming query.
|
||||
* In that case priming stub may be set as well.
|
||||
*/
|
||||
int priming;
|
||||
|
||||
/**
|
||||
* This is flag that, if true, means that this event is
|
||||
* representing a stub priming query. It is meaningless unless
|
||||
* the finalState is the PRIMING_RESP_STATE.
|
||||
* waiting for a stub priming query.
|
||||
*/
|
||||
int priming_stub;
|
||||
int wait_priming_stub;
|
||||
|
||||
/**
|
||||
* This is a flag that, if true, means that this query is
|
||||
|
||||
+1
-1
@@ -134,7 +134,7 @@ done
|
||||
# Check if SVNROOT is specified.
|
||||
if [ -z "$SVNROOT" ]; then
|
||||
if test -f .svn/entries; then
|
||||
eval `grep 'url=' .svn/entries | head -1`
|
||||
eval `svn info | grep 'URL:' | sed -e 's/URL: /url=/' | head -1`
|
||||
SVNROOT="$url"
|
||||
fi
|
||||
if test -z "$SVNROOT"; then
|
||||
|
||||
Vendored
+92
-13
@@ -139,11 +139,18 @@ copy_rrset(struct ub_packed_rrset_key* key, struct region* region,
|
||||
/** find closest NS or DNAME and returns the rrset (locked) */
|
||||
static struct ub_packed_rrset_key*
|
||||
find_closest_of_type(struct module_env* env, uint8_t* qname, size_t qnamelen,
|
||||
uint16_t qclass, uint32_t now, uint16_t searchtype)
|
||||
uint16_t qclass, uint32_t now, uint16_t searchtype, int stripfront)
|
||||
{
|
||||
struct ub_packed_rrset_key *rrset;
|
||||
uint8_t lablen;
|
||||
|
||||
if(stripfront) {
|
||||
/* strip off so that DNAMEs have strict subdomain match */
|
||||
lablen = *qname;
|
||||
qname += lablen + 1;
|
||||
qnamelen -= lablen + 1;
|
||||
}
|
||||
|
||||
/* snip off front part of qname until the type is found */
|
||||
while(qnamelen > 0) {
|
||||
if((rrset = rrset_cache_lookup(env->rrset_cache, qname,
|
||||
@@ -316,16 +323,15 @@ create_msg(uint8_t* qname, size_t qnamelen, uint16_t qtype, uint16_t qclass,
|
||||
struct delegpt*
|
||||
dns_cache_find_delegation(struct module_env* env, uint8_t* qname,
|
||||
size_t qnamelen, uint16_t qtype, uint16_t qclass,
|
||||
struct region* region, struct dns_msg** msg)
|
||||
struct region* region, struct dns_msg** msg, uint32_t now)
|
||||
{
|
||||
/* try to find closest NS rrset */
|
||||
struct ub_packed_rrset_key* nskey;
|
||||
struct packed_rrset_data* nsdata;
|
||||
struct delegpt* dp;
|
||||
uint32_t now = (uint32_t)time(NULL);
|
||||
|
||||
nskey = find_closest_of_type(env, qname, qnamelen, qclass, now,
|
||||
LDNS_RR_TYPE_NS);
|
||||
LDNS_RR_TYPE_NS, 0);
|
||||
if(!nskey) /* hope the caller has hints to prime or something */
|
||||
return NULL;
|
||||
nsdata = (struct packed_rrset_data*)nskey->entry.data;
|
||||
@@ -355,8 +361,6 @@ dns_cache_find_delegation(struct module_env* env, uint8_t* qname,
|
||||
/* find and add A entries */
|
||||
if(!find_add_addrs(env, qclass, region, dp, now, msg))
|
||||
log_err("find_delegation: addrs out of memory");
|
||||
log_info("dns_cache_find_delegation returns delegpt");
|
||||
delegpt_log(dp);
|
||||
return dp;
|
||||
}
|
||||
|
||||
@@ -399,6 +403,7 @@ tomsg(struct module_env* env, struct msgreply_entry* e, struct reply_info* r,
|
||||
msg->rep->flags = r->flags;
|
||||
msg->rep->qdcount = r->qdcount;
|
||||
msg->rep->ttl = r->ttl;
|
||||
msg->rep->security = r->security;
|
||||
msg->rep->an_numrrsets = r->an_numrrsets;
|
||||
msg->rep->ns_numrrsets = r->ns_numrrsets;
|
||||
msg->rep->ar_numrrsets = r->ar_numrrsets;
|
||||
@@ -417,9 +422,9 @@ tomsg(struct module_env* env, struct msgreply_entry* e, struct reply_info* r,
|
||||
return msg;
|
||||
}
|
||||
|
||||
/** synthesize CNAME response from cached CNAME item */
|
||||
/** synthesize RRset-only response from cached RRset item */
|
||||
static struct dns_msg*
|
||||
cname_msg(struct ub_packed_rrset_key* rrset, struct region* region,
|
||||
rrset_msg(struct ub_packed_rrset_key* rrset, struct region* region,
|
||||
uint32_t now, struct query_info* q)
|
||||
{
|
||||
struct dns_msg* msg;
|
||||
@@ -427,12 +432,13 @@ cname_msg(struct ub_packed_rrset_key* rrset, struct region* region,
|
||||
rrset->entry.data;
|
||||
if(now > d->ttl)
|
||||
return NULL;
|
||||
msg = gen_dns_msg(region, q, 1); /* only the CNAME RRset */
|
||||
msg = gen_dns_msg(region, q, 1); /* only the CNAME (or other) RRset */
|
||||
if(!msg)
|
||||
return NULL;
|
||||
msg->rep->flags = BIT_QR; /* reply, no AA, no error */
|
||||
msg->rep->qdcount = 1;
|
||||
msg->rep->ttl = d->ttl - now;
|
||||
msg->rep->security = sec_status_unchecked;
|
||||
msg->rep->an_numrrsets = 1;
|
||||
msg->rep->ns_numrrsets = 0;
|
||||
msg->rep->ar_numrrsets = 0;
|
||||
@@ -462,6 +468,7 @@ synth_dname_msg(struct ub_packed_rrset_key* rrset, struct region* region,
|
||||
msg->rep->flags = BIT_QR; /* reply, no AA, no error */
|
||||
msg->rep->qdcount = 1;
|
||||
msg->rep->ttl = d->ttl - now;
|
||||
msg->rep->security = sec_status_unchecked;
|
||||
msg->rep->an_numrrsets = 1;
|
||||
msg->rep->ns_numrrsets = 0;
|
||||
msg->rep->ar_numrrsets = 0;
|
||||
@@ -560,7 +567,7 @@ dns_cache_lookup(struct module_env* env,
|
||||
* are more important, the CNAME is resynthesized and thus
|
||||
* consistent with the DNAME */
|
||||
if( (rrset=find_closest_of_type(env, qname, qnamelen, qclass, now,
|
||||
LDNS_RR_TYPE_DNAME))) {
|
||||
LDNS_RR_TYPE_DNAME, 1))) {
|
||||
/* synthesize a DNAME+CNAME message based on this */
|
||||
struct dns_msg* msg = synth_dname_msg(rrset, region, now, &k);
|
||||
if(msg) {
|
||||
@@ -573,7 +580,7 @@ dns_cache_lookup(struct module_env* env,
|
||||
/* see if we have CNAME for this domain */
|
||||
if( (rrset=rrset_cache_lookup(env->rrset_cache, qname, qnamelen,
|
||||
LDNS_RR_TYPE_CNAME, qclass, 0, now, 0))) {
|
||||
struct dns_msg* msg = cname_msg(rrset, region, now, &k);
|
||||
struct dns_msg* msg = rrset_msg(rrset, region, now, &k);
|
||||
if(msg) {
|
||||
lock_rw_unlock(&rrset->entry.lock);
|
||||
return msg;
|
||||
@@ -581,7 +588,79 @@ dns_cache_lookup(struct module_env* env,
|
||||
lock_rw_unlock(&rrset->entry.lock);
|
||||
}
|
||||
|
||||
/* construct DS, DNSKEY messages from rrset cache. TODO */
|
||||
|
||||
/* construct DS, DNSKEY messages from rrset cache. */
|
||||
if((qtype == LDNS_RR_TYPE_DS || qtype == LDNS_RR_TYPE_DNSKEY) &&
|
||||
(rrset=rrset_cache_lookup(env->rrset_cache, qname, qnamelen,
|
||||
qtype, qclass, 0, now, 0))) {
|
||||
/* if the rrset is from the additional section, and the
|
||||
* signatures have fallen off, then do not synthesize a msg
|
||||
* instead, allow a full query for signed results to happen.
|
||||
* Forego all rrset data from additional section, because
|
||||
* some signatures may not be present and cause validation
|
||||
* failure.
|
||||
*/
|
||||
struct packed_rrset_data *d = (struct packed_rrset_data*)
|
||||
rrset->entry.data;
|
||||
if(d->trust != rrset_trust_add_noAA &&
|
||||
d->trust != rrset_trust_add_AA) {
|
||||
struct dns_msg* msg = rrset_msg(rrset, region, now, &k);
|
||||
if(msg) {
|
||||
lock_rw_unlock(&rrset->entry.lock);
|
||||
return msg;
|
||||
}
|
||||
}
|
||||
lock_rw_unlock(&rrset->entry.lock);
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
|
||||
int
|
||||
dns_cache_store(struct module_env* env, struct query_info* msgqinf,
|
||||
struct reply_info* msgrep, int is_referral)
|
||||
{
|
||||
struct reply_info* rep = NULL;
|
||||
/* alloc, malloc properly (not in region, like msg is) */
|
||||
rep = reply_info_copy(msgrep, env->alloc, NULL);
|
||||
if(!rep)
|
||||
return 0;
|
||||
|
||||
if(is_referral) {
|
||||
/* store rrsets */
|
||||
struct rrset_ref ref;
|
||||
uint32_t now = time(NULL);
|
||||
size_t i;
|
||||
for(i=0; i<rep->rrset_count; i++) {
|
||||
packed_rrset_ttl_add((struct packed_rrset_data*)
|
||||
rep->rrsets[i]->entry.data, now);
|
||||
ref.key = rep->rrsets[i];
|
||||
ref.id = rep->rrsets[i]->id;
|
||||
/*ignore ret: it was in the cache, ref updated */
|
||||
(void)rrset_cache_update(env->rrset_cache, &ref,
|
||||
env->alloc, now);
|
||||
}
|
||||
free(rep);
|
||||
return 1;
|
||||
} else {
|
||||
/* store msg, and rrsets */
|
||||
struct query_info qinf;
|
||||
hashvalue_t h;
|
||||
|
||||
qinf = *msgqinf;
|
||||
qinf.qname = memdup(msgqinf->qname, msgqinf->qname_len);
|
||||
if(!qinf.qname) {
|
||||
reply_info_parsedelete(rep, env->alloc);
|
||||
return 0;
|
||||
}
|
||||
/* fixup flags to be sensible for a reply based on the cache */
|
||||
/* this module means that RA is available. It is an answer QR.
|
||||
* Not AA from cache. Not CD in cache (depends on client bit). */
|
||||
rep->flags |= (BIT_RA | BIT_QR);
|
||||
rep->flags &= ~(BIT_AA | BIT_CD);
|
||||
h = query_info_hash(&qinf);
|
||||
dns_cache_store_msg(env, &qinf, h, rep);
|
||||
/* qname is used inside query_info_entrysetup, and set to
|
||||
* NULL. If it has not been used, free it. free(0) is safe. */
|
||||
free(qinf.qname);
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
Vendored
+20
-1
@@ -59,6 +59,24 @@ struct dns_msg {
|
||||
struct reply_info *rep;
|
||||
};
|
||||
|
||||
/**
|
||||
* Allocate a dns_msg with malloc/alloc structure and store in dns cache.
|
||||
*
|
||||
* @param env: environment, with alloc structure and dns cache.
|
||||
* @param qinf: query info, the query for which answer is stored.
|
||||
* this is allocated in a region, and will be copied to malloc area
|
||||
* before insertion.
|
||||
* @param rep: reply in dns_msg from dns_alloc_msg for example.
|
||||
* this is allocated in a region, and will be copied to malloc area
|
||||
* before insertion.
|
||||
* @param is_referral: If true, then the given message to be stored is a
|
||||
* referral. The cache implementation may use this as a hint.
|
||||
* It will store only the RRsets, not the message.
|
||||
* @return 0 on alloc error (out of memory).
|
||||
*/
|
||||
int dns_cache_store(struct module_env* env, struct query_info* qinf,
|
||||
struct reply_info* rep, int is_referral);
|
||||
|
||||
/**
|
||||
* Store message in the cache. Stores in message cache and rrset cache.
|
||||
* Both qinfo and rep should be malloced and are put in the cache.
|
||||
@@ -84,11 +102,12 @@ void dns_cache_store_msg(struct module_env* env, struct query_info* qinfo,
|
||||
* @param region: where to allocate result delegation.
|
||||
* @param msg: if not NULL, delegation message is returned here, synthesized
|
||||
* from the cache.
|
||||
* @param timenow: the time now, for checking if TTL on cache entries is OK.
|
||||
* @return new delegation or NULL on error or if not found in cache.
|
||||
*/
|
||||
struct delegpt* dns_cache_find_delegation(struct module_env* env,
|
||||
uint8_t* qname, size_t qnamelen, uint16_t qtype, uint16_t qclass,
|
||||
struct region* region, struct dns_msg** msg);
|
||||
struct region* region, struct dns_msg** msg, uint32_t timenow);
|
||||
|
||||
/**
|
||||
* Find cached message
|
||||
|
||||
Vendored
+48
-8
@@ -50,9 +50,11 @@
|
||||
/** calculate size for the hashtable, does not count size of lameness,
|
||||
* so the hashtable is a fixed number of items */
|
||||
static size_t
|
||||
infra_host_sizefunc(void* ATTR_UNUSED(k), void* ATTR_UNUSED(d))
|
||||
infra_host_sizefunc(void* k, void* ATTR_UNUSED(d))
|
||||
{
|
||||
return sizeof(struct infra_host_key) + sizeof(struct infra_host_data);
|
||||
struct infra_host_key* key = (struct infra_host_key*)k;
|
||||
return sizeof(*key) + sizeof(struct infra_host_data)
|
||||
+ lock_get_mem(&key->entry.lock);
|
||||
}
|
||||
|
||||
/** compare two addresses, returns -1, 0, or +1 */
|
||||
@@ -103,7 +105,7 @@ infra_create(struct config_file* cfg)
|
||||
}
|
||||
infra->host_ttl = cfg->host_ttl;
|
||||
infra->lame_ttl = cfg->lame_ttl;
|
||||
infra->max_lame = cfg->infra_cache_numlame;
|
||||
infra->max_lame_size = cfg->infra_cache_lame_size;
|
||||
return infra;
|
||||
}
|
||||
|
||||
@@ -124,7 +126,7 @@ infra_adjust(struct infra_cache* infra, struct config_file* cfg)
|
||||
return infra_create(cfg);
|
||||
infra->host_ttl = cfg->host_ttl;
|
||||
infra->lame_ttl = cfg->lame_ttl;
|
||||
infra->max_lame = cfg->infra_cache_numlame;
|
||||
infra->max_lame_size = cfg->infra_cache_lame_size;
|
||||
maxmem = cfg->infra_cache_numhosts *
|
||||
(sizeof(struct infra_host_key)+sizeof(struct infra_host_data));
|
||||
if(maxmem != slabhash_get_size(infra->hosts) ||
|
||||
@@ -291,9 +293,11 @@ infra_lookup_lame(struct infra_host_data* host,
|
||||
/** calculate size, which is fixed, zonename does not count so that
|
||||
* a fixed number of items is stored */
|
||||
static size_t
|
||||
infra_lame_sizefunc(void* ATTR_UNUSED(k), void* ATTR_UNUSED(d))
|
||||
infra_lame_sizefunc(void* k, void* ATTR_UNUSED(d))
|
||||
{
|
||||
return sizeof(struct infra_lame_key)+sizeof(struct infra_lame_data);
|
||||
struct infra_lame_key* key = (struct infra_lame_key*)k;
|
||||
return sizeof(*key) + sizeof(struct infra_lame_data)
|
||||
+ key->namelen + lock_get_mem(&key->entry.lock);
|
||||
}
|
||||
|
||||
/** compare zone names, returns -1, 0, +1 */
|
||||
@@ -384,8 +388,7 @@ infra_set_lame(struct infra_cache* infra,
|
||||
if(!data->lameness) {
|
||||
/* create hash table if not there already */
|
||||
data->lameness = lruhash_create(INFRA_LAME_STARTSIZE,
|
||||
infra->max_lame*(sizeof(struct infra_lame_key)+
|
||||
sizeof(struct infra_lame_data)), infra_lame_sizefunc,
|
||||
infra->max_lame_size, infra_lame_sizefunc,
|
||||
infra_lame_compfunc, infra_lame_delkeyfunc,
|
||||
infra_lame_deldatafunc, NULL);
|
||||
if(!data->lameness) {
|
||||
@@ -486,3 +489,40 @@ infra_get_lame_rtt(struct infra_cache* infra,
|
||||
lock_rw_unlock(&e->lock);
|
||||
return 1;
|
||||
}
|
||||
|
||||
/** helper memory count for a host lame cache */
|
||||
static size_t
|
||||
count_host_lame(struct lruhash_entry* e)
|
||||
{
|
||||
struct infra_host_data* host_data = (struct infra_host_data*)e->data;
|
||||
if(!host_data->lameness)
|
||||
return 0;
|
||||
return lruhash_get_mem(host_data->lameness);
|
||||
}
|
||||
|
||||
size_t
|
||||
infra_get_mem(struct infra_cache* infra)
|
||||
{
|
||||
size_t i, bin;
|
||||
size_t s = sizeof(*infra) +
|
||||
slabhash_get_mem(infra->hosts);
|
||||
struct lruhash_entry* e;
|
||||
for(i=0; i<infra->hosts->size; i++) {
|
||||
lock_quick_lock(&infra->hosts->array[i]->lock);
|
||||
for(bin=0; bin<infra->hosts->array[i]->size; bin++) {
|
||||
lock_quick_lock(&infra->hosts->array[i]->
|
||||
array[bin].lock);
|
||||
/* count data size in bin items. */
|
||||
for(e = infra->hosts->array[i]->array[bin].
|
||||
overflow_list; e; e = e->overflow_next) {
|
||||
lock_rw_rdlock(&e->lock);
|
||||
s += count_host_lame(e);
|
||||
lock_rw_unlock(&e->lock);
|
||||
}
|
||||
lock_quick_unlock(&infra->hosts->array[i]->
|
||||
array[bin].lock);
|
||||
}
|
||||
lock_quick_unlock(&infra->hosts->array[i]->lock);
|
||||
}
|
||||
return s;
|
||||
}
|
||||
|
||||
Vendored
+9
-2
@@ -103,8 +103,8 @@ struct infra_cache {
|
||||
int host_ttl;
|
||||
/** TTL for Lameness information, in seconds */
|
||||
int lame_ttl;
|
||||
/** infra lame cache max memory per host, for this many entries */
|
||||
size_t max_lame;
|
||||
/** infra lame cache max memory per host, in bytes */
|
||||
size_t max_lame_size;
|
||||
};
|
||||
|
||||
/** infra host cache default hash lookup size */
|
||||
@@ -235,4 +235,11 @@ int infra_get_lame_rtt(struct infra_cache* infra,
|
||||
struct sockaddr_storage* addr, socklen_t addrlen,
|
||||
uint8_t* name, size_t namelen, int* lame, int* rtt, time_t timenow);
|
||||
|
||||
/**
|
||||
* Get memory used by the infra cache.
|
||||
* @param infra: infrastructure cache.
|
||||
* @return memory in use in bytes.
|
||||
*/
|
||||
size_t infra_get_mem(struct infra_cache* infra);
|
||||
|
||||
#endif /* SERVICES_CACHE_INFRA_H */
|
||||
|
||||
Vendored
+114
-9
@@ -45,6 +45,7 @@
|
||||
#include "util/data/packed_rrset.h"
|
||||
#include "util/data/msgreply.h"
|
||||
#include "util/region-allocator.h"
|
||||
#include "util/alloc.h"
|
||||
|
||||
struct rrset_cache* rrset_cache_create(struct config_file* cfg,
|
||||
struct alloc_cache* alloc)
|
||||
@@ -110,33 +111,63 @@ rrset_cache_touch(struct rrset_cache* r, struct ub_packed_rrset_key* key,
|
||||
|
||||
/** see if rrset needs to be updated in the cache */
|
||||
static int
|
||||
need_to_update_rrset(void* nd, void* cd, uint32_t timenow)
|
||||
need_to_update_rrset(void* nd, void* cd, uint32_t timenow, int equal)
|
||||
{
|
||||
struct packed_rrset_data* newd = (struct packed_rrset_data*)nd;
|
||||
struct packed_rrset_data* cached = (struct packed_rrset_data*)cd;
|
||||
/* o store if rrset has been validated */
|
||||
if( newd->security > cached->security) {
|
||||
return 1;
|
||||
}
|
||||
/* o if current RRset is more trustworthy - insert it */
|
||||
if( newd->trust > cached->trust )
|
||||
if( newd->trust > cached->trust ) {
|
||||
/* if the cached rrset is bogus, and this one equal,
|
||||
* do not update the TTL - let it expire. */
|
||||
if(equal && cached->ttl >= timenow &&
|
||||
cached->security == sec_status_bogus)
|
||||
return 0;
|
||||
return 1;
|
||||
}
|
||||
/* o item in cache has expired */
|
||||
if( cached->ttl < timenow )
|
||||
return 1;
|
||||
/* o same trust, but different in data - insert it */
|
||||
if( newd->trust == cached->trust &&
|
||||
!rrsetdata_equal(newd, cached))
|
||||
if( newd->trust == cached->trust && !equal )
|
||||
return 1;
|
||||
/* o see if TTL is better than TTL in cache. */
|
||||
/* if so, see if rrset+rdata is the same */
|
||||
/* if so, update TTL in cache, even if trust is worse. */
|
||||
if( newd->ttl > cached->ttl &&
|
||||
rrsetdata_equal(newd, cached)) {
|
||||
if( newd->ttl > cached->ttl && equal ) {
|
||||
/* if the cached rrset is bogus, and this one equal,
|
||||
* do not update the TTL - let it expire. */
|
||||
if(cached->security == sec_status_bogus)
|
||||
return 0;
|
||||
/* since all else is the same, use the best trust value */
|
||||
if(newd->trust < cached->trust)
|
||||
if(newd->trust < cached->trust) {
|
||||
newd->trust = cached->trust;
|
||||
newd->security = cached->security;
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** Update RRSet special key ID */
|
||||
static void
|
||||
rrset_update_id(struct rrset_ref* ref, struct alloc_cache* alloc)
|
||||
{
|
||||
/* this may clear the cache and invalidate lock below */
|
||||
uint64_t newid = alloc_get_id(alloc);
|
||||
/* obtain writelock */
|
||||
lock_rw_wrlock(&ref->key->entry.lock);
|
||||
/* check if it was deleted in the meantime, if so, skip update */
|
||||
if(ref->key->id == ref->id) {
|
||||
ref->key->id = newid;
|
||||
ref->id = newid;
|
||||
}
|
||||
lock_rw_unlock(&ref->key->entry.lock);
|
||||
}
|
||||
|
||||
int
|
||||
rrset_cache_update(struct rrset_cache* r, struct rrset_ref* ref,
|
||||
struct alloc_cache* alloc, uint32_t timenow)
|
||||
@@ -144,6 +175,8 @@ rrset_cache_update(struct rrset_cache* r, struct rrset_ref* ref,
|
||||
struct lruhash_entry* e;
|
||||
struct ub_packed_rrset_key* k = ref->key;
|
||||
hashvalue_t h = k->entry.hash;
|
||||
uint16_t rrset_type = ntohs(k->rk.type);
|
||||
int equal = 0;
|
||||
/* looks up item with a readlock - no editing! */
|
||||
if((e=slabhash_lookup(&r->table, h, k, 0)) != 0) {
|
||||
/* return id and key as they will be used in the cache
|
||||
@@ -155,7 +188,10 @@ rrset_cache_update(struct rrset_cache* r, struct rrset_ref* ref,
|
||||
*/
|
||||
ref->key = (struct ub_packed_rrset_key*)e->key;
|
||||
ref->id = ref->key->id;
|
||||
if(!need_to_update_rrset(k->entry.data, e->data, timenow)) {
|
||||
equal = rrsetdata_equal((struct packed_rrset_data*)k->entry.
|
||||
data, (struct packed_rrset_data*)e->data);
|
||||
if(!need_to_update_rrset(k->entry.data, e->data, timenow,
|
||||
equal)) {
|
||||
/* cache is superior, return that value */
|
||||
lock_rw_unlock(&e->lock);
|
||||
ub_packed_rrset_parsedelete(k, alloc);
|
||||
@@ -171,8 +207,17 @@ rrset_cache_update(struct rrset_cache* r, struct rrset_ref* ref,
|
||||
* cache size values nicely. */
|
||||
}
|
||||
slabhash_insert(&r->table, h, &k->entry, k->entry.data, alloc);
|
||||
if(e)
|
||||
if(e) {
|
||||
/* For NSEC, NSEC3, DNAME, when rdata is updated, update
|
||||
* the ID number so that proofs in message cache are
|
||||
* invalidated */
|
||||
if((rrset_type == LDNS_RR_TYPE_NSEC
|
||||
|| rrset_type == LDNS_RR_TYPE_NSEC3
|
||||
|| rrset_type == LDNS_RR_TYPE_DNAME) && !equal) {
|
||||
rrset_update_id(ref, alloc);
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -265,3 +310,63 @@ rrset_array_unlock_touch(struct rrset_cache* r, struct region* scratch,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
void
|
||||
rrset_update_sec_status(struct rrset_cache* r,
|
||||
struct ub_packed_rrset_key* rrset)
|
||||
{
|
||||
uint32_t now = (uint32_t)time(0);
|
||||
struct packed_rrset_data* updata =
|
||||
(struct packed_rrset_data*)rrset->entry.data;
|
||||
struct lruhash_entry* e;
|
||||
struct packed_rrset_data* cachedata;
|
||||
|
||||
/* hash it again to make sure it has a hash */
|
||||
rrset->entry.hash = rrset_key_hash(&rrset->rk);
|
||||
|
||||
e = slabhash_lookup(&r->table, rrset->entry.hash, rrset, 1);
|
||||
if(!e)
|
||||
return; /* not in the cache anymore */
|
||||
cachedata = (struct packed_rrset_data*)e->data;
|
||||
if(!rrsetdata_equal(updata, cachedata)) {
|
||||
lock_rw_unlock(&e->lock);
|
||||
return; /* rrset has changed in the meantime */
|
||||
}
|
||||
/* update the cached rrset */
|
||||
if(updata->security > cachedata->security) {
|
||||
cachedata->trust = updata->trust;
|
||||
cachedata->security = updata->security;
|
||||
cachedata->ttl = updata->ttl + now;
|
||||
}
|
||||
lock_rw_unlock(&e->lock);
|
||||
}
|
||||
|
||||
void
|
||||
rrset_check_sec_status(struct rrset_cache* r,
|
||||
struct ub_packed_rrset_key* rrset)
|
||||
{
|
||||
uint32_t now = (uint32_t)time(0);
|
||||
struct packed_rrset_data* updata =
|
||||
(struct packed_rrset_data*)rrset->entry.data;
|
||||
struct lruhash_entry* e;
|
||||
struct packed_rrset_data* cachedata;
|
||||
|
||||
/* hash it again to make sure it has a hash */
|
||||
rrset->entry.hash = rrset_key_hash(&rrset->rk);
|
||||
|
||||
e = slabhash_lookup(&r->table, rrset->entry.hash, rrset, 0);
|
||||
if(!e)
|
||||
return; /* not in the cache anymore */
|
||||
cachedata = (struct packed_rrset_data*)e->data;
|
||||
if(now > cachedata->ttl || !rrsetdata_equal(updata, cachedata)) {
|
||||
lock_rw_unlock(&e->lock);
|
||||
return; /* expired, or rrset has changed in the meantime */
|
||||
}
|
||||
if(cachedata->security > updata->security) {
|
||||
updata->security = cachedata->security;
|
||||
if(cachedata->security == sec_status_bogus)
|
||||
updata->ttl = cachedata->ttl - now;
|
||||
updata->trust = cachedata->trust;
|
||||
}
|
||||
lock_rw_unlock(&e->lock);
|
||||
}
|
||||
|
||||
Vendored
+23
@@ -184,4 +184,27 @@ void rrset_array_unlock(struct rrset_ref* ref, size_t count);
|
||||
void rrset_array_unlock_touch(struct rrset_cache* r, struct region* scratch,
|
||||
struct rrset_ref* ref, size_t count);
|
||||
|
||||
/**
|
||||
* Update security status of an rrset. Looks up the rrset.
|
||||
* If found, checks if rdata is equal.
|
||||
* If so, it will update the security, trust and rrset-ttl values.
|
||||
* The values are only updated if security is increased (towards secure).
|
||||
* @param r: the rrset cache.
|
||||
* @param rrset: which rrset to attempt to update. This rrset is left
|
||||
* untouched. The rrset in the cache is updated in-place.
|
||||
*/
|
||||
void rrset_update_sec_status(struct rrset_cache* r,
|
||||
struct ub_packed_rrset_key* rrset);
|
||||
|
||||
/**
|
||||
* Looks up security status of an rrset. Looks up the rrset.
|
||||
* If found, checks if rdata is equal, and entry did not expire.
|
||||
* If so, it will update the security, trust and rrset-ttl values.
|
||||
* @param r: the rrset cache.
|
||||
* @param rrset: This rrset may change security status due to the cache.
|
||||
* But its status will only improve, towards secure.
|
||||
*/
|
||||
void rrset_check_sec_status(struct rrset_cache* r,
|
||||
struct ub_packed_rrset_key* rrset);
|
||||
|
||||
#endif /* SERVICES_CACHE_RRSET_H */
|
||||
|
||||
@@ -288,7 +288,8 @@ listen_cp_insert(struct comm_point* c, struct listen_dnsport* front)
|
||||
|
||||
struct listen_dnsport*
|
||||
listen_create(struct comm_base* base, struct listen_port* ports,
|
||||
size_t bufsize, comm_point_callback_t* cb, void *cb_arg)
|
||||
size_t bufsize, int tcp_accept_count,
|
||||
comm_point_callback_t* cb, void *cb_arg)
|
||||
{
|
||||
struct listen_dnsport* front = (struct listen_dnsport*)
|
||||
malloc(sizeof(struct listen_dnsport));
|
||||
@@ -308,7 +309,7 @@ listen_create(struct comm_base* base, struct listen_port* ports,
|
||||
cp = comm_point_create_udp(base, ports->fd,
|
||||
front->udp_buff, cb, cb_arg);
|
||||
else cp = comm_point_create_tcp(base, ports->fd,
|
||||
TCP_ACCEPT_COUNT, bufsize, cb, cb_arg);
|
||||
tcp_accept_count, bufsize, cb, cb_arg);
|
||||
if(!cp) {
|
||||
log_err("can't create commpoint");
|
||||
listen_delete(front);
|
||||
@@ -381,10 +382,14 @@ listening_ports_open(struct config_file* cfg)
|
||||
struct listen_port* list = NULL;
|
||||
struct addrinfo hints;
|
||||
int i, do_ip4, do_ip6;
|
||||
int do_tcp;
|
||||
char portbuf[32];
|
||||
snprintf(portbuf, sizeof(portbuf), "%d", cfg->port);
|
||||
do_ip4 = cfg->do_ip4;
|
||||
do_ip6 = cfg->do_ip6;
|
||||
do_tcp = cfg->do_tcp;
|
||||
if(cfg->incoming_num_tcp == 0)
|
||||
do_tcp = 0;
|
||||
|
||||
/* getaddrinfo */
|
||||
memset(&hints, 0, sizeof(hints));
|
||||
@@ -403,7 +408,7 @@ listening_ports_open(struct config_file* cfg)
|
||||
if(cfg->num_ifs == 0) {
|
||||
if(do_ip6) {
|
||||
hints.ai_family = AF_INET6;
|
||||
if(!ports_create_if(NULL, cfg->do_udp, cfg->do_tcp,
|
||||
if(!ports_create_if(NULL, cfg->do_udp, do_tcp,
|
||||
&hints, portbuf, &list)) {
|
||||
listening_ports_free(list);
|
||||
return NULL;
|
||||
@@ -411,7 +416,7 @@ listening_ports_open(struct config_file* cfg)
|
||||
}
|
||||
if(do_ip4) {
|
||||
hints.ai_family = AF_INET;
|
||||
if(!ports_create_if(NULL, cfg->do_udp, cfg->do_tcp,
|
||||
if(!ports_create_if(NULL, cfg->do_udp, do_tcp,
|
||||
&hints, portbuf, &list)) {
|
||||
listening_ports_free(list);
|
||||
return NULL;
|
||||
@@ -423,7 +428,7 @@ listening_ports_open(struct config_file* cfg)
|
||||
continue;
|
||||
hints.ai_family = AF_INET6;
|
||||
if(!ports_create_if(cfg->ifs[i], cfg->do_udp,
|
||||
cfg->do_tcp, &hints, portbuf, &list)) {
|
||||
do_tcp, &hints, portbuf, &list)) {
|
||||
listening_ports_free(list);
|
||||
return NULL;
|
||||
}
|
||||
@@ -432,7 +437,7 @@ listening_ports_open(struct config_file* cfg)
|
||||
continue;
|
||||
hints.ai_family = AF_INET;
|
||||
if(!ports_create_if(cfg->ifs[i], cfg->do_udp,
|
||||
cfg->do_tcp, &hints, portbuf, &list)) {
|
||||
do_tcp, &hints, portbuf, &list)) {
|
||||
listening_ports_free(list);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -48,9 +48,6 @@ struct listen_list;
|
||||
struct addrinfo;
|
||||
struct config_file;
|
||||
|
||||
/** number of simultaneous open TCP connections for queries */
|
||||
#define TCP_ACCEPT_COUNT 10
|
||||
|
||||
/**
|
||||
* Listening for queries structure.
|
||||
* Contains list of query-listen sockets.
|
||||
@@ -111,13 +108,15 @@ void listening_ports_free(struct listen_port* list);
|
||||
* for default all ifs.
|
||||
* @param ports: the list of shared ports.
|
||||
* @param bufsize: size of datagram buffer.
|
||||
* @param tcp_accept_count: max number of simultaneous TCP connections
|
||||
* from clients.
|
||||
* @param cb: callback function when a request arrives. It is passed
|
||||
* the packet and user argument. Return true to send a reply.
|
||||
* @param cb_arg: user data argument for callback function.
|
||||
* @return: the malloced listening structure, ready for use. NULL on error.
|
||||
*/
|
||||
struct listen_dnsport* listen_create(struct comm_base* base,
|
||||
struct listen_port* ports, size_t bufsize,
|
||||
struct listen_port* ports, size_t bufsize, int tcp_accept_count,
|
||||
comm_point_callback_t* cb, void* cb_arg);
|
||||
|
||||
/**
|
||||
|
||||
+112
-32
@@ -45,6 +45,7 @@
|
||||
#include "config.h"
|
||||
#include "services/mesh.h"
|
||||
#include "services/outbound_list.h"
|
||||
#include "services/cache/dns.h"
|
||||
#include "util/log.h"
|
||||
#include "util/net_help.h"
|
||||
#include "util/module.h"
|
||||
@@ -59,9 +60,9 @@ mesh_state_compare(const void* ap, const void* bp)
|
||||
struct mesh_state* a = (struct mesh_state*)ap;
|
||||
struct mesh_state* b = (struct mesh_state*)bp;
|
||||
|
||||
if(a->is_priming && !b->is_priming)
|
||||
if(a->s.is_priming && !b->s.is_priming)
|
||||
return -1;
|
||||
if(!a->is_priming && b->is_priming)
|
||||
if(!a->s.is_priming && b->s.is_priming)
|
||||
return 1;
|
||||
|
||||
if((a->s.query_flags&BIT_RD) && !(b->s.query_flags&BIT_RD))
|
||||
@@ -69,6 +70,11 @@ mesh_state_compare(const void* ap, const void* bp)
|
||||
if(!(a->s.query_flags&BIT_RD) && (b->s.query_flags&BIT_RD))
|
||||
return 1;
|
||||
|
||||
if((a->s.query_flags&BIT_CD) && !(b->s.query_flags&BIT_CD))
|
||||
return -1;
|
||||
if(!(a->s.query_flags&BIT_CD) && (b->s.query_flags&BIT_CD))
|
||||
return 1;
|
||||
|
||||
return query_info_compare(&a->s.qinfo, &b->s.qinfo);
|
||||
}
|
||||
|
||||
@@ -206,8 +212,6 @@ mesh_state_create(struct module_env* env, struct query_info* qinfo,
|
||||
mstate->run_node = *RBTREE_NULL;
|
||||
mstate->node.key = mstate;
|
||||
mstate->run_node.key = mstate;
|
||||
mstate->debug_flags = 0;
|
||||
mstate->is_priming = prime;
|
||||
mstate->reply_list = NULL;
|
||||
rbtree_init(&mstate->super_set, &mesh_state_ref_compare);
|
||||
rbtree_init(&mstate->sub_set, &mesh_state_ref_compare);
|
||||
@@ -222,10 +226,13 @@ mesh_state_create(struct module_env* env, struct query_info* qinfo,
|
||||
return NULL;
|
||||
}
|
||||
/* remove all weird bits from qflags */
|
||||
mstate->s.query_flags = (qflags & BIT_RD);
|
||||
mstate->s.query_flags = (qflags & (BIT_RD|BIT_CD));
|
||||
mstate->s.is_priming = prime;
|
||||
mstate->s.reply = NULL;
|
||||
mstate->s.region = region;
|
||||
mstate->s.curmod = 0;
|
||||
mstate->s.return_msg = 0;
|
||||
mstate->s.return_rcode = LDNS_RCODE_NOERROR;
|
||||
mstate->s.env = env;
|
||||
mstate->s.mesh_info = mstate;
|
||||
/* init modules */
|
||||
@@ -418,6 +425,15 @@ mesh_send_reply(struct mesh_state* m, int rcode, struct reply_info* rep,
|
||||
struct mesh_reply* r)
|
||||
{
|
||||
struct timeval end_time;
|
||||
int secure;
|
||||
/* examine security status */
|
||||
if(m->s.env->need_to_validate && !(r->qflags&BIT_CD) && rep &&
|
||||
rep->security <= sec_status_bogus) {
|
||||
rcode = LDNS_RCODE_SERVFAIL;
|
||||
}
|
||||
if(rep && rep->security == sec_status_secure)
|
||||
secure = 1;
|
||||
else secure = 0;
|
||||
/* send the reply */
|
||||
if(rcode) {
|
||||
error_encode(r->query_reply.c->buffer, rcode, &m->s.qinfo,
|
||||
@@ -432,7 +448,7 @@ mesh_send_reply(struct mesh_state* m, int rcode, struct reply_info* rep,
|
||||
if(!reply_info_answer_encode(&m->s.qinfo, rep, r->qid,
|
||||
r->qflags, r->query_reply.c->buffer, 0, 1,
|
||||
m->s.env->scratch, udp_size, &r->edns,
|
||||
(int)(r->edns.bits & EDNS_DO)))
|
||||
(int)(r->edns.bits & EDNS_DO), secure))
|
||||
{
|
||||
error_encode(r->query_reply.c->buffer,
|
||||
LDNS_RCODE_SERVFAIL, &m->s.qinfo, r->qid,
|
||||
@@ -456,32 +472,26 @@ mesh_send_reply(struct mesh_state* m, int rcode, struct reply_info* rep,
|
||||
}
|
||||
}
|
||||
|
||||
void mesh_query_done(struct module_qstate* qstate, int rcode,
|
||||
struct reply_info* rep)
|
||||
void mesh_query_done(struct mesh_state* mstate)
|
||||
{
|
||||
struct mesh_state* m = qstate->mesh_info;
|
||||
struct mesh_reply* r;
|
||||
log_assert(!(m->debug_flags&1)); /* not twice! */
|
||||
m->debug_flags |= 1;
|
||||
for(r = m->reply_list; r; r = r->next) {
|
||||
mesh_send_reply(m, rcode, rep, r);
|
||||
struct reply_info* rep = (mstate->s.return_msg?
|
||||
mstate->s.return_msg->rep:NULL);
|
||||
for(r = mstate->reply_list; r; r = r->next) {
|
||||
mesh_send_reply(mstate, mstate->s.return_rcode, rep, r);
|
||||
}
|
||||
}
|
||||
|
||||
void mesh_walk_supers(struct module_qstate* qstate, int id,
|
||||
void (*cb)(struct module_qstate*, int, struct module_qstate*))
|
||||
void mesh_walk_supers(struct mesh_area* mesh, struct mesh_state* mstate)
|
||||
{
|
||||
struct mesh_state* m = qstate->mesh_info;
|
||||
struct mesh_area* mesh = m->s.env->mesh;
|
||||
struct mesh_state_ref* ref;
|
||||
log_assert(!(m->debug_flags&2)); /* not twice! */
|
||||
m->debug_flags |= 2;
|
||||
RBTREE_FOR(ref, struct mesh_state_ref*, &qstate->mesh_info->super_set)
|
||||
RBTREE_FOR(ref, struct mesh_state_ref*, &mstate->super_set)
|
||||
{
|
||||
/* make super runnable */
|
||||
(void)rbtree_insert(&mesh->run, &ref->s->run_node);
|
||||
/* callback */
|
||||
(*cb)(qstate, id, &ref->s->s);
|
||||
/* callback the function to inform super of result */
|
||||
(*mesh->modfunc[ref->s->s.curmod]->inform_super)(&mstate->s,
|
||||
ref->s->s.curmod, &ref->s->s);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -492,7 +502,7 @@ struct mesh_state* mesh_area_find(struct mesh_area* mesh,
|
||||
struct mesh_state* result;
|
||||
|
||||
key.node.key = &key;
|
||||
key.is_priming = prime;
|
||||
key.s.is_priming = prime;
|
||||
key.s.qinfo = *qinfo;
|
||||
key.s.query_flags = qflags;
|
||||
|
||||
@@ -521,6 +531,58 @@ int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns,
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* Continue processing the mesh state at another module.
|
||||
* Handles module to modules tranfer of control.
|
||||
* Handles module finished.
|
||||
* @param mesh: the mesh area.
|
||||
* @param mstate: currently active mesh state.
|
||||
* Deleted if finished, calls _done and _supers to
|
||||
* send replies to clients and inform other mesh states.
|
||||
* This in turn may create additional runnable mesh states.
|
||||
* @param s: state at which the current module exited.
|
||||
* @param ev: the event sent to the module.
|
||||
* returned is the event to send to the next module.
|
||||
* @return true if continue processing at the new module.
|
||||
* false if not continued processing is needed.
|
||||
*/
|
||||
static int
|
||||
mesh_continue(struct mesh_area* mesh, struct mesh_state* mstate,
|
||||
enum module_ext_state s, enum module_ev* ev)
|
||||
{
|
||||
if(s == module_wait_module) {
|
||||
/* start next module */
|
||||
mstate->s.curmod++;
|
||||
if(mesh->num_modules == mstate->s.curmod) {
|
||||
log_err("Cannot pass to next module; at last module");
|
||||
log_query_info(VERB_DETAIL, "pass error for qstate",
|
||||
&mstate->s.qinfo);
|
||||
log_assert(0); /* catch this for now */
|
||||
mstate->s.curmod--;
|
||||
return mesh_continue(mesh, mstate, module_error, ev);
|
||||
}
|
||||
*ev = module_event_pass;
|
||||
return 1;
|
||||
}
|
||||
if(s == module_error && mstate->s.return_rcode == LDNS_RCODE_NOERROR) {
|
||||
/* error is bad, handle pass back up below */
|
||||
mstate->s.return_rcode = LDNS_RCODE_SERVFAIL;
|
||||
}
|
||||
if(s == module_error || s == module_finished) {
|
||||
if(mstate->s.curmod == 0) {
|
||||
mesh_query_done(mstate);
|
||||
mesh_walk_supers(mesh, mstate);
|
||||
mesh_state_delete(&mstate->s);
|
||||
return 0;
|
||||
}
|
||||
/* pass along the locus of control */
|
||||
mstate->s.curmod --;
|
||||
*ev = module_event_moddone;
|
||||
return 1;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
void mesh_run(struct mesh_area* mesh, struct mesh_state* mstate,
|
||||
enum module_ev ev, struct outbound_entry* e)
|
||||
{
|
||||
@@ -537,23 +599,40 @@ void mesh_run(struct mesh_area* mesh, struct mesh_state* mstate,
|
||||
s = mstate->s.ext_state[mstate->s.curmod];
|
||||
verbose(VERB_ALGO, "mesh_run: %s module exit state is %s",
|
||||
mesh->modfunc[mstate->s.curmod]->name, strextstate(s));
|
||||
if(s == module_error || s == module_finished) {
|
||||
/* must have called _done and _supers */
|
||||
log_assert(mstate->debug_flags == 3);
|
||||
mesh_state_delete(&mstate->s);
|
||||
}
|
||||
e = NULL;
|
||||
if(mesh_continue(mesh, mstate, s, &ev))
|
||||
continue;
|
||||
|
||||
/* run more modules */
|
||||
ev = module_event_pass;
|
||||
e = NULL;
|
||||
if(mesh->run.count > 0) {
|
||||
/* pop random element off the runnable tree */
|
||||
mstate = (struct mesh_state*)mesh->run.root->key;
|
||||
(void)rbtree_delete(&mesh->run, mstate);
|
||||
} else mstate = NULL;
|
||||
}
|
||||
if(verbosity >= VERB_ALGO)
|
||||
if(verbosity >= VERB_ALGO) {
|
||||
mesh_stats(mesh, "mesh_run: end");
|
||||
mesh_log_list(mesh);
|
||||
}
|
||||
}
|
||||
|
||||
void
|
||||
mesh_log_list(struct mesh_area* mesh)
|
||||
{
|
||||
char buf[30];
|
||||
struct mesh_state* m;
|
||||
int num = 0;
|
||||
RBTREE_FOR(m, struct mesh_state*, &mesh->all) {
|
||||
snprintf(buf, sizeof(buf), "%d%s%s%s%s%s mod%d %s",
|
||||
num++, (m->s.is_priming)?"p":"", /* prime */
|
||||
(m->s.query_flags&BIT_RD)?"RD":"",
|
||||
(m->s.query_flags&BIT_CD)?"CD":"",
|
||||
(m->super_set.count==0)?"d":"", /* detached */
|
||||
(m->sub_set.count!=0)?"c":"", /* children */
|
||||
m->s.curmod, (m->reply_list)?"hr":"nr"); /*hasreply*/
|
||||
log_query_info(VERB_ALGO, buf, &m->s.qinfo);
|
||||
}
|
||||
}
|
||||
|
||||
void
|
||||
@@ -602,11 +681,12 @@ find_in_subsub(struct mesh_state* m, struct mesh_state* tofind)
|
||||
}
|
||||
|
||||
int
|
||||
mesh_detect_cycle(struct module_qstate* qstate, struct query_info* qinfo)
|
||||
mesh_detect_cycle(struct module_qstate* qstate, struct query_info* qinfo,
|
||||
uint16_t flags, int prime)
|
||||
{
|
||||
struct mesh_area* mesh = qstate->env->mesh;
|
||||
struct mesh_state* cyc_m = qstate->mesh_info;
|
||||
struct mesh_state* dep_m = mesh_area_find(mesh, qinfo, BIT_RD, 0);
|
||||
struct mesh_state* dep_m = mesh_area_find(mesh, qinfo, flags, prime);
|
||||
if(!dep_m)
|
||||
return 0;
|
||||
if(dep_m == cyc_m || find_in_subsub(dep_m, cyc_m))
|
||||
|
||||
+26
-24
@@ -95,7 +95,7 @@ struct mesh_area {
|
||||
/**
|
||||
* A mesh query state
|
||||
* Unique per qname, qtype, qclass (from the qstate).
|
||||
* And RD flag; in case a client turns it off.
|
||||
* And RD / CD flag; in case a client turns it off.
|
||||
* And priming queries are different from ordinary queries (because of hints).
|
||||
*
|
||||
* The entire structure is allocated in a region, this region is the qstate
|
||||
@@ -106,15 +106,11 @@ struct mesh_state {
|
||||
rbnode_t node;
|
||||
/** node in mesh_area runnable tree, key is this struct */
|
||||
rbnode_t run_node;
|
||||
/** if this is a (stub or root) priming query (with hints) */
|
||||
int is_priming;
|
||||
/** the query state. Note that the qinfo and query_flags
|
||||
* may not change. */
|
||||
struct module_qstate s;
|
||||
/** the list of replies to clients for the results */
|
||||
struct mesh_reply* reply_list;
|
||||
/** debug flags */
|
||||
int debug_flags;
|
||||
/** set of superstates (that want this state's result)
|
||||
* contains struct mesh_state_ref* */
|
||||
rbtree_t super_set;
|
||||
@@ -226,7 +222,7 @@ void mesh_detach_subs(struct module_qstate* qstate);
|
||||
* @param qstate: the state to find mesh state, and that wants to receive
|
||||
* the results from the new subquery.
|
||||
* @param qinfo: what to query for (copied).
|
||||
* @param qflags: what flags to use (RD flag or not).
|
||||
* @param qflags: what flags to use (RD / CD flag or not).
|
||||
* @param prime: if it is a (stub) priming query.
|
||||
* @param newq: If the new subquery needs initialisation, it is returned,
|
||||
* otherwise NULL is returned.
|
||||
@@ -244,28 +240,25 @@ int mesh_attach_sub(struct module_qstate* qstate, struct query_info* qinfo,
|
||||
* Must be called before a module can module_finished or return module_error.
|
||||
* The module must handle the super query states itself as well.
|
||||
*
|
||||
* @param qstate: used for original query info. And to find mesh info.
|
||||
* @param rcode: if not 0 (NOERROR) an error is sent back (and rep ignored).
|
||||
* @param rep: reply to encode and send back to clients.
|
||||
* @param mstate: mesh state that is done. return_rcode and return_msg
|
||||
* are used for replies.
|
||||
* return_rcode: if not 0 (NOERROR) an error is sent back (and
|
||||
* return_msg is ignored).
|
||||
* return_msg: reply to encode and send back to clients.
|
||||
*/
|
||||
void mesh_query_done(struct module_qstate* qstate, int rcode,
|
||||
struct reply_info* rep);
|
||||
void mesh_query_done(struct mesh_state* mstate);
|
||||
|
||||
/**
|
||||
* Get a callback for the super query states that are interested in the
|
||||
* Call inform_super for the super query states that are interested in the
|
||||
* results from this query state. These can then be changed for error
|
||||
* or results.
|
||||
* Must be called befor a module can module_finished or return module_error.
|
||||
* After finishing or module error, the super query states become runnable
|
||||
* with event module_event_pass.
|
||||
* Called when a module is module_finished or returns module_error.
|
||||
* The super query states become runnable with event module_event_pass.
|
||||
*
|
||||
* @param qstate: the state that has results, used to find mesh state.
|
||||
* @param id: module id.
|
||||
* @param cb: callback function. Called as
|
||||
* cb(qstate, id, super_qstate) for every super query state.
|
||||
* @param mesh: mesh area to add newly runnable modules to.
|
||||
* @param mstate: the state that has results, used to find mesh state.
|
||||
*/
|
||||
void mesh_walk_supers(struct module_qstate* qstate, int id,
|
||||
void (*cb)(struct module_qstate*, int, struct module_qstate*));
|
||||
void mesh_walk_supers(struct mesh_area* mesh, struct mesh_state* mstate);
|
||||
|
||||
/**
|
||||
* Delete mesh state, cleanup and also rbtrees and so on.
|
||||
@@ -281,7 +274,7 @@ void mesh_state_delete(struct module_qstate* qstate);
|
||||
* Does not put the mesh state into rbtrees and so on.
|
||||
* @param env: module environment to set.
|
||||
* @param qinfo: query info that the mesh is for.
|
||||
* @param qflags: flags for query (RD flag).
|
||||
* @param qflags: flags for query (RD / CD flag).
|
||||
* @param prime: if true, it is a priming query, set is_priming on mesh state.
|
||||
* @return: new mesh state or NULL on allocation error.
|
||||
*/
|
||||
@@ -301,7 +294,7 @@ void mesh_state_cleanup(struct mesh_state* mstate);
|
||||
*
|
||||
* @param mesh: the mesh area to look in.
|
||||
* @param qinfo: what query
|
||||
* @param qflags: if RD bit is set or not.
|
||||
* @param qflags: if RD / CD bit is set or not.
|
||||
* @param prime: if it is a priming query.
|
||||
* @return: mesh state or NULL if not found.
|
||||
*/
|
||||
@@ -350,6 +343,12 @@ void mesh_run(struct mesh_area* mesh, struct mesh_state* mstate,
|
||||
*/
|
||||
void mesh_stats(struct mesh_area* mesh, const char* str);
|
||||
|
||||
/**
|
||||
* Print all the states in the mesh to the log.
|
||||
* @param mesh: the mesh to print all states of.
|
||||
*/
|
||||
void mesh_log_list(struct mesh_area* mesh);
|
||||
|
||||
/**
|
||||
* Calculate memory size in use by mesh and all queries inside it.
|
||||
* @param mesh: the mesh to examine.
|
||||
@@ -362,10 +361,13 @@ size_t mesh_get_mem(struct mesh_area* mesh);
|
||||
* trees.
|
||||
* @param qstate: given mesh querystate.
|
||||
* @param qinfo: query info for dependency.
|
||||
* @param flags: query flags of dependency.
|
||||
* @param prime: if dependency is a priming query or not.
|
||||
* @return true if the name,type,class exists and the given qstate mesh exists
|
||||
* as a dependency of that name. Thus if qstate becomes dependent on
|
||||
* name,type,class then a cycle is created.
|
||||
*/
|
||||
int mesh_detect_cycle(struct module_qstate* qstate, struct query_info* qinfo);
|
||||
int mesh_detect_cycle(struct module_qstate* qstate, struct query_info* qinfo,
|
||||
uint16_t flags, int prime);
|
||||
|
||||
#endif /* SERVICES_MESH_H */
|
||||
|
||||
@@ -57,7 +57,7 @@ outbound_list_clear(struct outbound_list* list)
|
||||
while(p) {
|
||||
np = p->next;
|
||||
outnet_serviced_query_stop(p->qsent, p);
|
||||
free(p);
|
||||
/* in region, no free needed */
|
||||
p = np;
|
||||
}
|
||||
outbound_list_init(list);
|
||||
@@ -84,5 +84,5 @@ outbound_list_remove(struct outbound_list* list, struct outbound_entry* e)
|
||||
if(e->prev)
|
||||
e->prev->next = e->next;
|
||||
else list->first = e->next;
|
||||
free(e);
|
||||
/* in region, no free needed */
|
||||
}
|
||||
|
||||
+68
-19
@@ -120,7 +120,7 @@ waiting_tcp_delete(struct waiting_tcp* w)
|
||||
|
||||
/** use next free buffer to service a tcp query */
|
||||
static int
|
||||
outnet_tcp_take_into_use(struct waiting_tcp* w, uint8_t* pkt)
|
||||
outnet_tcp_take_into_use(struct waiting_tcp* w, uint8_t* pkt, size_t pkt_len)
|
||||
{
|
||||
struct pending_tcp* pend = w->outnet->tcp_free;
|
||||
int s;
|
||||
@@ -154,7 +154,7 @@ outnet_tcp_take_into_use(struct waiting_tcp* w, uint8_t* pkt)
|
||||
pend->next_free = NULL;
|
||||
pend->query = w;
|
||||
ldns_buffer_clear(pend->c->buffer);
|
||||
ldns_buffer_write(pend->c->buffer, pkt, w->pkt_len);
|
||||
ldns_buffer_write(pend->c->buffer, pkt, pkt_len);
|
||||
ldns_buffer_flip(pend->c->buffer);
|
||||
pend->c->tcp_is_reading = 0;
|
||||
pend->c->tcp_byte_count = 0;
|
||||
@@ -172,9 +172,11 @@ use_free_buffer(struct outside_network* outnet)
|
||||
outnet->tcp_wait_first = w->next_waiting;
|
||||
if(outnet->tcp_wait_last == w)
|
||||
outnet->tcp_wait_last = NULL;
|
||||
if(!outnet_tcp_take_into_use(w, w->pkt)) {
|
||||
(void)(*w->cb)(NULL, w->cb_arg, NETEVENT_CLOSED, NULL);
|
||||
if(!outnet_tcp_take_into_use(w, w->pkt, w->pkt_len)) {
|
||||
comm_point_callback_t* cb = w->cb;
|
||||
void* cb_arg = w->cb_arg;
|
||||
waiting_tcp_delete(w);
|
||||
(void)(*cb)(NULL, cb_arg, NETEVENT_CLOSED, NULL);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -259,6 +261,9 @@ outnet_udp_cb(struct comm_point* c, void* arg, int error,
|
||||
}
|
||||
|
||||
verbose(VERB_ALGO, "received udp reply.");
|
||||
if(verbosity >= VERB_ALGO)
|
||||
log_hex("udp message", ldns_buffer_begin(c->buffer),
|
||||
ldns_buffer_limit(c->buffer));
|
||||
if(p->c != c) {
|
||||
verbose(VERB_DETAIL, "received reply id,addr on wrong port. "
|
||||
"dropped.");
|
||||
@@ -429,7 +434,7 @@ outside_network_create(struct comm_base *base, size_t bufsize,
|
||||
outnet->num_tcp = num_tcp;
|
||||
outnet->infra = infra;
|
||||
outnet->rnd = rnd;
|
||||
outnet->udp_second = 0;
|
||||
outnet->svcd_overhead = 0;
|
||||
#ifndef INET6
|
||||
do_ip6 = 0;
|
||||
#endif
|
||||
@@ -490,13 +495,6 @@ outside_network_create(struct comm_base *base, size_t bufsize,
|
||||
return outnet;
|
||||
}
|
||||
|
||||
void
|
||||
outside_network_set_secondary_buffer(struct outside_network* outnet,
|
||||
ldns_buffer* buf)
|
||||
{
|
||||
outnet->udp_second = buf;
|
||||
}
|
||||
|
||||
/** helper pending delete */
|
||||
static void
|
||||
pending_node_del(rbnode_t* node, void* arg)
|
||||
@@ -717,6 +715,8 @@ outnet_tcptimer(void* arg)
|
||||
{
|
||||
struct waiting_tcp* w = (struct waiting_tcp*)arg;
|
||||
struct outside_network* outnet = w->outnet;
|
||||
comm_point_callback_t* cb;
|
||||
void* cb_arg;
|
||||
if(w->pkt) {
|
||||
/* it is on the waiting list */
|
||||
struct waiting_tcp* p=outnet->tcp_wait_first, *prev=NULL;
|
||||
@@ -738,8 +738,10 @@ outnet_tcptimer(void* arg)
|
||||
pend->next_free = outnet->tcp_free;
|
||||
outnet->tcp_free = pend;
|
||||
}
|
||||
(void)(*w->cb)(NULL, w->cb_arg, NETEVENT_TIMEOUT, NULL);
|
||||
cb = w->cb;
|
||||
cb_arg = w->cb_arg;
|
||||
waiting_tcp_delete(w);
|
||||
(void)(*cb)(NULL, cb_arg, NETEVENT_TIMEOUT, NULL);
|
||||
use_free_buffer(outnet);
|
||||
}
|
||||
|
||||
@@ -764,7 +766,7 @@ pending_tcp_query(struct outside_network* outnet, ldns_buffer* packet,
|
||||
return NULL;
|
||||
}
|
||||
w->pkt = NULL;
|
||||
w->pkt_len = ldns_buffer_limit(packet);
|
||||
w->pkt_len = 0;
|
||||
/* id uses lousy random() TODO use better and entropy */
|
||||
id = ((unsigned)ub_random(rnd)>>8) & 0xffff;
|
||||
LDNS_ID_SET(ldns_buffer_begin(packet), id);
|
||||
@@ -778,13 +780,15 @@ pending_tcp_query(struct outside_network* outnet, ldns_buffer* packet,
|
||||
comm_timer_set(w->timer, &tv);
|
||||
if(pend) {
|
||||
/* we have a buffer available right now */
|
||||
if(!outnet_tcp_take_into_use(w, ldns_buffer_begin(packet))) {
|
||||
if(!outnet_tcp_take_into_use(w, ldns_buffer_begin(packet),
|
||||
ldns_buffer_limit(packet))) {
|
||||
waiting_tcp_delete(w);
|
||||
return NULL;
|
||||
}
|
||||
} else {
|
||||
/* queue up */
|
||||
w->pkt = (uint8_t*)w + sizeof(struct waiting_tcp);
|
||||
w->pkt_len = ldns_buffer_limit(packet);
|
||||
memmove(w->pkt, ldns_buffer_begin(packet), w->pkt_len);
|
||||
w->next_waiting = NULL;
|
||||
if(outnet->tcp_wait_last)
|
||||
@@ -897,6 +901,7 @@ serviced_delete(struct serviced_query* sq)
|
||||
(struct pending_tcp*)p->next_waiting);
|
||||
} else {
|
||||
waiting_list_remove(sq->outnet, p);
|
||||
waiting_tcp_delete(p);
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -921,8 +926,10 @@ serviced_encode(struct serviced_query* sq, ldns_buffer* buff, int with_edns)
|
||||
edns.edns_version = EDNS_ADVERTISED_VERSION;
|
||||
edns.udp_size = EDNS_ADVERTISED_SIZE;
|
||||
edns.bits = 0;
|
||||
if(sq->dnssec)
|
||||
if(sq->dnssec & EDNS_DO)
|
||||
edns.bits = EDNS_DO;
|
||||
if(sq->dnssec & BIT_CD)
|
||||
LDNS_CD_SET(ldns_buffer_begin(buff));
|
||||
attach_edns_record(buff, &edns);
|
||||
}
|
||||
}
|
||||
@@ -968,6 +975,8 @@ serviced_callbacks(struct serviced_query* sq, int error, struct comm_point* c,
|
||||
{
|
||||
struct service_callback* p = sq->cblist, *n;
|
||||
int dobackup = (sq->cblist && sq->cblist->next); /* >1 cb*/
|
||||
uint8_t *backup_p = NULL;
|
||||
size_t backlen = 0;
|
||||
rbnode_t* rem;
|
||||
/* remove from tree, and schedule for deletion, so that callbacks
|
||||
* can safely deregister themselves and even create new serviced
|
||||
@@ -981,16 +990,29 @@ serviced_callbacks(struct serviced_query* sq, int error, struct comm_point* c,
|
||||
* may send outgoing queries that overwrite the buffer.
|
||||
* use secondary buffer to store the query.
|
||||
* This is a data copy, but faster than packet to server */
|
||||
ldns_buffer_copy(sq->outnet->udp_second, c->buffer);
|
||||
backlen = ldns_buffer_limit(c->buffer);
|
||||
backup_p = memdup(ldns_buffer_begin(c->buffer), backlen);
|
||||
if(!backup_p) {
|
||||
log_err("malloc failure in serviced query callbacks");
|
||||
error = NETEVENT_CLOSED;
|
||||
c = NULL;
|
||||
}
|
||||
sq->outnet->svcd_overhead = backlen;
|
||||
}
|
||||
while(p) {
|
||||
n = p->next;
|
||||
if(dobackup && c) {
|
||||
ldns_buffer_copy(c->buffer, sq->outnet->udp_second);
|
||||
ldns_buffer_clear(c->buffer);
|
||||
ldns_buffer_write(c->buffer, backup_p, backlen);
|
||||
ldns_buffer_flip(c->buffer);
|
||||
}
|
||||
(void)(*p->cb)(c, p->cb_arg, error, rep);
|
||||
p = n;
|
||||
}
|
||||
if(backup_p) {
|
||||
free(backup_p);
|
||||
sq->outnet->svcd_overhead = 0;
|
||||
}
|
||||
verbose(VERB_ALGO, "svcd callbacks end");
|
||||
log_assert(sq->cblist == NULL);
|
||||
serviced_delete(sq);
|
||||
@@ -1239,8 +1261,10 @@ size_t outnet_get_mem(struct outside_network* outnet)
|
||||
for(w=outnet->tcp_wait_first; w; w = w->next_waiting)
|
||||
s += waiting_tcp_get_mem(w);
|
||||
s += sizeof(*outnet->pending);
|
||||
s += sizeof(struct pending) * outnet->pending->count;
|
||||
s += (sizeof(struct pending) + comm_timer_get_mem(NULL)) *
|
||||
outnet->pending->count;
|
||||
s += sizeof(*outnet->serviced);
|
||||
s += outnet->svcd_overhead;
|
||||
RBTREE_FOR(sq, struct serviced_query*, outnet->serviced) {
|
||||
s += sizeof(*sq) + sq->qbuflen;
|
||||
for(sb = sq->cblist; sb; sb = sb->next)
|
||||
@@ -1248,3 +1272,28 @@ size_t outnet_get_mem(struct outside_network* outnet)
|
||||
}
|
||||
return s;
|
||||
}
|
||||
|
||||
size_t
|
||||
serviced_get_mem(struct serviced_query* sq)
|
||||
{
|
||||
struct service_callback* sb;
|
||||
size_t s;
|
||||
s = sizeof(*sq) + sq->qbuflen;
|
||||
for(sb = sq->cblist; sb; sb = sb->next)
|
||||
s += sizeof(*sb);
|
||||
if(sq->status == serviced_query_UDP_EDNS ||
|
||||
sq->status == serviced_query_UDP) {
|
||||
s += sizeof(struct pending);
|
||||
s += comm_timer_get_mem(NULL);
|
||||
} else {
|
||||
/* does not have size of the pkt pointer */
|
||||
/* always has a timer except on malloc failures */
|
||||
|
||||
/* these sizes are part of the main outside network mem */
|
||||
/*
|
||||
s += sizeof(struct waiting_tcp);
|
||||
s += comm_timer_get_mem(NULL);
|
||||
*/
|
||||
}
|
||||
return s;
|
||||
}
|
||||
|
||||
+15
-17
@@ -64,12 +64,9 @@ struct outside_network {
|
||||
/** buffer shared by UDP connections, since there is only one
|
||||
datagram at any time. */
|
||||
ldns_buffer* udp_buff;
|
||||
|
||||
/** buffer for storage. (buffer for incoming connections, since
|
||||
* either an event to outside or incoming happens, but not both
|
||||
* This buffer is used during callbacks, so that the datagram
|
||||
* that just arrived does not collide with new datagrams sent out. */
|
||||
ldns_buffer* udp_second;
|
||||
/** serviced_callbacks malloc overhead when processing multiple
|
||||
* identical serviced queries to the same server. */
|
||||
size_t svcd_overhead;
|
||||
|
||||
/**
|
||||
* Array of udp comm point* that are used to listen to pending events.
|
||||
@@ -210,7 +207,7 @@ struct serviced_query {
|
||||
uint8_t* qbuf;
|
||||
/** length of qbuf. */
|
||||
size_t qbuflen;
|
||||
/** If an EDNS section is included, the DO bit will be turned on. */
|
||||
/** If an EDNS section is included, the DO/CD bit will be turned on. */
|
||||
int dnssec;
|
||||
/** where to send it */
|
||||
struct sockaddr_storage addr;
|
||||
@@ -271,16 +268,6 @@ struct outside_network* outside_network_create(struct comm_base* base,
|
||||
*/
|
||||
void outside_network_delete(struct outside_network* outnet);
|
||||
|
||||
/**
|
||||
* Set secondary UDP buffer. Make sure it is not used during outside network
|
||||
* callbacks. Such as the incoming network UDP buffer. Caller responsible
|
||||
* for deletion.
|
||||
* @param outnet: outside network.
|
||||
* @param buf: buffer to use as secondary buffer.
|
||||
*/
|
||||
void outside_network_set_secondary_buffer(struct outside_network* outnet,
|
||||
ldns_buffer* buf);
|
||||
|
||||
/**
|
||||
* Send UDP query, create pending answer.
|
||||
* Changes the ID for the query to be random and unique for that destination.
|
||||
@@ -337,6 +324,8 @@ void pending_delete(struct outside_network* outnet, struct pending* p);
|
||||
* @param qclass: query class. (host format)
|
||||
* @param flags: flags u16 (host format), includes opcode, CD bit.
|
||||
* @param dnssec: if set, DO bit is set in EDNS queries.
|
||||
* If the value includes BIT_CD, CD bit is set when in EDNS queries.
|
||||
* If the value includes BIT_DO, DO bit is set when in EDNS queries.
|
||||
* @param callback: callback function.
|
||||
* @param callback_arg: user argument to callback function.
|
||||
* @param addr: to which server to send the query.
|
||||
@@ -371,4 +360,13 @@ void outnet_serviced_query_stop(struct serviced_query* sq, void* cb_arg);
|
||||
*/
|
||||
size_t outnet_get_mem(struct outside_network* outnet);
|
||||
|
||||
/**
|
||||
* Get memory size in use by serviced query while it is servicing callbacks.
|
||||
* This takes into account the pre-deleted status of it; it will be deleted
|
||||
* when the callbacks are done.
|
||||
* @param sq: serviced query.
|
||||
* @return size in bytes.
|
||||
*/
|
||||
size_t serviced_get_mem(struct serviced_query* sq);
|
||||
|
||||
#endif /* OUTSIDE_NETWORK_H */
|
||||
|
||||
+18
-1
@@ -205,6 +205,23 @@ prot_store(struct checked_lock* lock)
|
||||
}
|
||||
}
|
||||
|
||||
/** get memory held by lock */
|
||||
size_t
|
||||
lock_get_mem(void* pp)
|
||||
{
|
||||
size_t s;
|
||||
struct checked_lock* lock = *(struct checked_lock**)pp;
|
||||
struct protected_area* p;
|
||||
s = sizeof(struct checked_lock);
|
||||
acquire_locklock(lock, __func__, __FILE__, __LINE__);
|
||||
for(p = lock->prot; p; p = p->next) {
|
||||
s += sizeof(struct protected_area);
|
||||
s += p->size;
|
||||
}
|
||||
LOCKRET(pthread_mutex_unlock(&lock->lock));
|
||||
return s;
|
||||
}
|
||||
|
||||
/** write lock trace info to file, while you hold those locks */
|
||||
static void
|
||||
ordercheck_locklock(struct thr_check* thr, struct checked_lock* lock)
|
||||
@@ -340,7 +357,7 @@ checklock_destroy(enum check_lock_type type, struct checked_lock** lock,
|
||||
e->create_func, e->create_file, e->create_line,
|
||||
(unsigned int)e->contention_count,
|
||||
(unsigned int)e->history_count,
|
||||
100*e->contention_count/e->history_count);
|
||||
(int)(100*e->contention_count/e->history_count));
|
||||
}
|
||||
|
||||
/* delete it */
|
||||
|
||||
@@ -196,6 +196,13 @@ void lock_protect(void* lock, void* area, size_t size);
|
||||
*/
|
||||
void lock_unprotect(void* lock, void* area);
|
||||
|
||||
/**
|
||||
* Get memory associated with a checked lock
|
||||
* @param lock: the checked lock, any type. (struct checked_lock**).
|
||||
* @return: in bytes, including protected areas.
|
||||
*/
|
||||
size_t lock_get_mem(void* lock);
|
||||
|
||||
/**
|
||||
* Initialise checklock. Sets up internal debug structures.
|
||||
*/
|
||||
|
||||
@@ -2,8 +2,10 @@
|
||||
|
||||
NEED_SPLINT='00-lint.tpkg'
|
||||
NEED_DOXYGEN='01-doc.tpkg'
|
||||
NEED_LDNS_TESTNS='fwd_no_edns.tpkg fwd_tcp_tc.tpkg fwd_tcp.tpkg fwd_three_service.tpkg fwd_three.tpkg fwd_ttlexpire.tpkg fwd_udp.tpkg'
|
||||
|
||||
cd testdata;
|
||||
sh ../testcode/mini_tpkg.sh clean
|
||||
for test in `ls *.tpkg`; do
|
||||
SKIP=0
|
||||
if echo $NEED_SPLINT | grep $test >/dev/null; then
|
||||
@@ -16,10 +18,16 @@ for test in `ls *.tpkg`; do
|
||||
SKIP=1;
|
||||
fi
|
||||
fi
|
||||
if echo $NEED_LDNS_TESTNS | grep $test >/dev/null; then
|
||||
if test ! -x "`which ldns-testns`"; then
|
||||
SKIP=1;
|
||||
fi
|
||||
fi
|
||||
if test $SKIP -eq 0; then
|
||||
echo $test
|
||||
tpkg -a ../.. exe $test
|
||||
sh ../testcode/mini_tpkg.sh -a ../.. exe $test
|
||||
else
|
||||
echo "skip $test"
|
||||
fi
|
||||
done
|
||||
sh ../testcode/mini_tpkg.sh report
|
||||
|
||||
+17
-10
@@ -179,6 +179,7 @@ pending_find_match(struct replay_runtime* runtime, struct entry** entry,
|
||||
p->start_step, p->end_step, (*entry)->lineno);
|
||||
if(p->addrlen != 0)
|
||||
log_addr("matched ip", &p->addr, p->addrlen);
|
||||
log_pkt("matched pkt: ", (*entry)->reply_list->reply);
|
||||
return 1;
|
||||
}
|
||||
p = p->next_range;
|
||||
@@ -353,7 +354,9 @@ fake_front_query(struct replay_runtime* runtime, struct replay_moment *todo)
|
||||
repinfo.c->fd = -1;
|
||||
repinfo.c->ev = (struct internal_event*)runtime;
|
||||
repinfo.c->buffer = ldns_buffer_new(runtime->bufsize);
|
||||
repinfo.c->type = comm_udp;
|
||||
if(todo->match->match_transport == transport_tcp)
|
||||
repinfo.c->type = comm_tcp;
|
||||
else repinfo.c->type = comm_udp;
|
||||
fill_buffer_with_reply(repinfo.c->buffer, todo->match, NULL);
|
||||
log_info("testbound: incoming QUERY");
|
||||
/* call the callback for incoming queries */
|
||||
@@ -520,7 +523,8 @@ run_scenario(struct replay_runtime* runtime)
|
||||
|
||||
struct listen_dnsport*
|
||||
listen_create(struct comm_base* base, struct listen_port* ATTR_UNUSED(ports),
|
||||
size_t bufsize, comm_point_callback_t* cb, void* cb_arg)
|
||||
size_t bufsize, int ATTR_UNUSED(tcp_accept_count),
|
||||
comm_point_callback_t* cb, void* cb_arg)
|
||||
{
|
||||
struct replay_runtime* runtime = (struct replay_runtime*)base;
|
||||
struct listen_dnsport* l= calloc(1, sizeof(struct listen_dnsport));
|
||||
@@ -692,13 +696,6 @@ outside_network_delete(struct outside_network* outnet)
|
||||
free(outnet);
|
||||
}
|
||||
|
||||
void
|
||||
outside_network_set_secondary_buffer(struct outside_network*
|
||||
ATTR_UNUSED(outnet), ldns_buffer* ATTR_UNUSED(buf))
|
||||
{
|
||||
/* nothing to do */
|
||||
}
|
||||
|
||||
struct pending*
|
||||
pending_udp_query(struct outside_network* outnet, ldns_buffer* packet,
|
||||
struct sockaddr_storage* addr, socklen_t addrlen, int timeout,
|
||||
@@ -818,6 +815,11 @@ struct serviced_query* outnet_serviced_query(struct outside_network* outnet,
|
||||
ldns_status status;
|
||||
(void)arg_compare;
|
||||
log_assert(pend);
|
||||
log_nametypeclass(VERB_OPS, "pending serviced query",
|
||||
qname, qtype, qclass);
|
||||
verbose(VERB_OPS, "pending serviced query flags%s%s%s%s",
|
||||
(flags&BIT_RD)?" RD":"", (flags&BIT_CD)?" CD":"",
|
||||
(flags&~(BIT_RD|BIT_CD))?" MORE":"", (dnssec)?" DO":"");
|
||||
|
||||
/* create packet with EDNS */
|
||||
pend->buffer = ldns_buffer_new(512);
|
||||
@@ -859,7 +861,7 @@ struct serviced_query* outnet_serviced_query(struct outside_network* outnet,
|
||||
ldns_get_errorstr_by_id(status));
|
||||
fatal_exit("internal error");
|
||||
}
|
||||
log_pkt("pending serviced query: ", pend->pkt);
|
||||
/*log_pkt("pending serviced query: ", pend->pkt);*/
|
||||
|
||||
/* see if it matches the current moment */
|
||||
if(runtime->now && runtime->now->evt_type == repevt_back_query &&
|
||||
@@ -952,4 +954,9 @@ size_t comm_point_get_mem(struct comm_point* ATTR_UNUSED(c))
|
||||
return 0;
|
||||
}
|
||||
|
||||
size_t serviced_get_mem(struct serviced_query* ATTR_UNUSED(c))
|
||||
{
|
||||
return 0;
|
||||
}
|
||||
|
||||
/*********** End of Dummy routines ***********/
|
||||
|
||||
@@ -68,7 +68,7 @@ static bool str_keyword(const char** str, const char* keyword)
|
||||
if(strncmp(*str, keyword, len) != 0)
|
||||
return false;
|
||||
*str += len;
|
||||
while(isspace(**str))
|
||||
while(isspace((int)**str))
|
||||
(*str)++;
|
||||
return true;
|
||||
}
|
||||
@@ -120,7 +120,7 @@ static void matchline(const char* line, struct entry* e)
|
||||
error("expected = or : in MATCH: %s", line);
|
||||
parse++;
|
||||
e->ixfr_soa_serial = (uint32_t)strtol(parse, (char**)&parse, 10);
|
||||
while(isspace(*parse))
|
||||
while(isspace((int)*parse))
|
||||
parse++;
|
||||
} else {
|
||||
error("could not parse MATCH: '%s'", parse);
|
||||
@@ -184,6 +184,8 @@ static void replyline(const char* line, ldns_pkt *reply)
|
||||
ldns_pkt_set_ra(reply, true);
|
||||
} else if(str_keyword(&parse, "AD")) {
|
||||
ldns_pkt_set_ad(reply, true);
|
||||
} else if(str_keyword(&parse, "DO")) {
|
||||
ldns_pkt_set_edns_do(reply, true);
|
||||
} else {
|
||||
error("could not parse REPLY: '%s'", parse);
|
||||
}
|
||||
@@ -200,13 +202,15 @@ static void adjustline(const char* line, struct entry* e,
|
||||
return;
|
||||
if(str_keyword(&parse, "copy_id")) {
|
||||
e->copy_id = true;
|
||||
} else if(str_keyword(&parse, "copy_query")) {
|
||||
e->copy_query = true;
|
||||
} else if(str_keyword(&parse, "sleep=")) {
|
||||
e->sleeptime = (unsigned int) strtol(parse, (char**)&parse, 10);
|
||||
while(isspace(*parse))
|
||||
while(isspace((int)*parse))
|
||||
parse++;
|
||||
} else if(str_keyword(&parse, "packet_sleep=")) {
|
||||
pkt->packet_sleep = (unsigned int) strtol(parse, (char**)&parse, 10);
|
||||
while(isspace(*parse))
|
||||
while(isspace((int)*parse))
|
||||
parse++;
|
||||
} else {
|
||||
error("could not parse ADJUST: '%s'", parse);
|
||||
@@ -230,6 +234,7 @@ static struct entry* new_entry()
|
||||
e->match_transport = transport_any;
|
||||
e->reply_list = NULL;
|
||||
e->copy_id = false;
|
||||
e->copy_query = false;
|
||||
e->sleeptime = 0;
|
||||
e->next = NULL;
|
||||
return e;
|
||||
@@ -385,7 +390,7 @@ get_origin(const char* name, int lineno, ldns_rdf** origin, char* parse)
|
||||
*origin = NULL;
|
||||
|
||||
end=parse;
|
||||
while(!isspace(*end) && !isendline(*end))
|
||||
while(!isspace((int)*end) && !isendline(*end))
|
||||
end++;
|
||||
store = *end;
|
||||
*end = 0;
|
||||
@@ -415,7 +420,7 @@ read_entry(FILE* in, const char* name, int *lineno, uint32_t* default_ttl,
|
||||
parse = line;
|
||||
(*lineno) ++;
|
||||
|
||||
while(isspace(*parse))
|
||||
while(isspace((int)*parse))
|
||||
parse++;
|
||||
/* test for keywords */
|
||||
if(isendline(*parse))
|
||||
@@ -692,6 +697,12 @@ adjust_packet(struct entry* match, ldns_pkt* answer_pkt, ldns_pkt* query_pkt)
|
||||
/* copy & adjust packet */
|
||||
if(match->copy_id)
|
||||
ldns_pkt_set_id(answer_pkt, ldns_pkt_id(query_pkt));
|
||||
if(match->copy_query) {
|
||||
ldns_rr_list* list = ldns_pkt_get_section_clone(query_pkt,
|
||||
LDNS_SECTION_QUESTION);
|
||||
ldns_rr_list_deep_free(ldns_pkt_question(answer_pkt));
|
||||
ldns_pkt_set_question(answer_pkt, list);
|
||||
}
|
||||
if(match->sleeptime > 0) {
|
||||
verbose(3, "sleeping for %d seconds\n", match->sleeptime);
|
||||
sleep(match->sleeptime);
|
||||
|
||||
@@ -54,11 +54,13 @@
|
||||
(opcode) QUERY IQUERY STATUS NOTIFY UPDATE
|
||||
(rcode) NOERROR FORMERR SERVFAIL NXDOMAIN NOTIMPL YXDOMAIN
|
||||
YXRRSET NXRRSET NOTAUTH NOTZONE
|
||||
(flags) QR AA TC RD CD RA AD
|
||||
(flags) QR AA TC RD CD RA AD DO
|
||||
REPLY ...
|
||||
; any additional actions to do.
|
||||
; 'copy_id' copies the ID from the query to the answer.
|
||||
ADJUST copy_id
|
||||
; 'copy_query' copies the query name, type and class to the answer.
|
||||
ADJUST copy_query
|
||||
; 'sleep=10' sleeps for 10 seconds before giving the answer (TCP is open)
|
||||
ADJUST [sleep=<num>] ; sleep before giving any reply
|
||||
ADJUST [packet_sleep=<num>] ; sleep before this packet in sequence
|
||||
@@ -174,6 +176,8 @@ struct entry {
|
||||
/** how to adjust the reply packet */
|
||||
/** copy over the ID from the query into the answer */
|
||||
bool copy_id;
|
||||
/** copy the query nametypeclass from query into the answer */
|
||||
bool copy_query;
|
||||
/** in seconds */
|
||||
unsigned int sleeptime;
|
||||
|
||||
|
||||
@@ -0,0 +1,270 @@
|
||||
/*
|
||||
* testcode/memstats.c - debug tool to show memory allocation statistics.
|
||||
*
|
||||
* Copyright (c) 2007, NLnet Labs. All rights reserved.
|
||||
*
|
||||
* This software is open source.
|
||||
*
|
||||
* Redistribution and use in source and binary forms, with or without
|
||||
* modification, are permitted provided that the following conditions
|
||||
* are met:
|
||||
*
|
||||
* Redistributions of source code must retain the above copyright notice,
|
||||
* this list of conditions and the following disclaimer.
|
||||
*
|
||||
* Redistributions in binary form must reproduce the above copyright notice,
|
||||
* this list of conditions and the following disclaimer in the documentation
|
||||
* and/or other materials provided with the distribution.
|
||||
*
|
||||
* Neither the name of the NLNET LABS nor the names of its contributors may
|
||||
* be used to endorse or promote products derived from this software without
|
||||
* specific prior written permission.
|
||||
*
|
||||
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
|
||||
* TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||
* PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE
|
||||
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
* INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
* CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
* POSSIBILITY OF SUCH DAMAGE.
|
||||
*/
|
||||
|
||||
/**
|
||||
* \file
|
||||
*
|
||||
* This program reads a log file and prints the memory allocation summed
|
||||
* up.
|
||||
*/
|
||||
#include "config.h"
|
||||
#include "util/log.h"
|
||||
#include "util/rbtree.h"
|
||||
#include <sys/stat.h>
|
||||
|
||||
/**
|
||||
* The allocation statistics block
|
||||
*/
|
||||
struct codeline {
|
||||
/** rbtree node */
|
||||
rbnode_t node;
|
||||
/** the name of the file:linenumber */
|
||||
char* codeline;
|
||||
/** the name of the function */
|
||||
char* func;
|
||||
/** number of bytes allocated */
|
||||
uint64_t alloc;
|
||||
/** number of bytes freed */
|
||||
uint64_t free;
|
||||
};
|
||||
|
||||
/**
|
||||
* Other allocation stats
|
||||
*/
|
||||
struct alloc_misc {
|
||||
/** number of region allocs */
|
||||
uint64_t region_alloc;
|
||||
};
|
||||
|
||||
/** print usage and exit */
|
||||
static void
|
||||
usage()
|
||||
{
|
||||
printf("usage: memstats <logfile>\n");
|
||||
printf("statistics are printed on stdout.\n");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/** compare two codeline structs for rbtree */
|
||||
static int
|
||||
codeline_cmp(const void* a, const void* b)
|
||||
{
|
||||
return strcmp((const char*)a, (const char*)b);
|
||||
}
|
||||
|
||||
/** match logfile line to see if it needs accounting processing */
|
||||
static int
|
||||
match(char* line)
|
||||
{
|
||||
/* f.e.:
|
||||
* [1187340064] unbound[24604:0] info: ul/rb.c:81 r_create malloc(12)
|
||||
* 0123456789 123456789 123456789 123456789
|
||||
*/
|
||||
if(strlen(line) < 36) /* up to 'info: ' */
|
||||
return 0;
|
||||
if(strncmp(line+30, "info: ", 6) != 0)
|
||||
return 0;
|
||||
if(strncmp(line+36, "stat ", 5) == 0)
|
||||
return 0; /* skip the hex dumps */
|
||||
if(strstr(line+36, "malloc("))
|
||||
return 1;
|
||||
else if(strstr(line+36, "calloc("))
|
||||
return 1;
|
||||
/* skip reallocs */
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** read up the region stats */
|
||||
static void
|
||||
read_region_stat(char* line, struct alloc_misc* misc)
|
||||
{
|
||||
long num = 0;
|
||||
if(sscanf(line+50, "%ld", &num) != 1) {
|
||||
printf("%s\n%s\n", line, line+50);
|
||||
fatal_exit("unhandled region");
|
||||
}
|
||||
misc->region_alloc += num;
|
||||
}
|
||||
|
||||
/** find or alloc codeline in tree */
|
||||
static struct codeline*
|
||||
get_codeline(rbtree_t* tree, char* key, char* func)
|
||||
{
|
||||
struct codeline* cl = (struct codeline*)rbtree_search(tree, key);
|
||||
if(!cl) {
|
||||
cl = calloc(1, sizeof(*cl));
|
||||
if(!cl) return 0;
|
||||
cl->codeline = strdup(key);
|
||||
if(!cl->codeline) return 0;
|
||||
cl->func = strdup(func);
|
||||
if(!cl->func) return 0;
|
||||
cl->alloc = 0;
|
||||
cl->node.key = cl->codeline;
|
||||
(void)rbtree_insert(tree, &cl->node);
|
||||
}
|
||||
return cl;
|
||||
}
|
||||
|
||||
/** read up the malloc stats */
|
||||
static void
|
||||
read_malloc_stat(char* line, rbtree_t* tree)
|
||||
{
|
||||
char codeline[10240];
|
||||
char name[10240];
|
||||
int skip = 0;
|
||||
long num = 0;
|
||||
struct codeline* cl = 0;
|
||||
if(sscanf(line+36, "%s %s %n", codeline, name, &skip) != 2) {
|
||||
printf("%s\n%s\n", line, line+36);
|
||||
fatal_exit("unhandled malloc");
|
||||
}
|
||||
if(sscanf(line+36+skip+7, "%ld", &num) != 1) {
|
||||
printf("%s\n%s\n", line, line+36+skip+7);
|
||||
fatal_exit("unhandled malloc");
|
||||
}
|
||||
cl = get_codeline(tree, codeline, name);
|
||||
if(!cl)
|
||||
fatal_exit("alloc failure");
|
||||
cl->alloc += num;
|
||||
}
|
||||
|
||||
/** read up the calloc stats */
|
||||
static void
|
||||
read_calloc_stat(char* line, rbtree_t* tree)
|
||||
{
|
||||
char codeline[10240];
|
||||
char name[10240];
|
||||
int skip = 0;
|
||||
long num = 0, sz = 0;
|
||||
struct codeline* cl = 0;
|
||||
if(sscanf(line+36, "%s %s %n", codeline, name, &skip) != 2) {
|
||||
printf("%s\n%s\n", line, line+36);
|
||||
fatal_exit("unhandled calloc");
|
||||
}
|
||||
if(sscanf(line+36+skip+7, "%ld, %ld", &num, &sz) != 2) {
|
||||
printf("%s\n%s\n", line, line+36+skip+7);
|
||||
fatal_exit("unhandled calloc");
|
||||
}
|
||||
|
||||
cl = get_codeline(tree, codeline, name);
|
||||
if(!cl)
|
||||
fatal_exit("alloc failure");
|
||||
cl->alloc += num*sz;
|
||||
}
|
||||
|
||||
/** get size of file */
|
||||
static off_t
|
||||
get_file_size(const char* fname)
|
||||
{
|
||||
struct stat s;
|
||||
if(stat(fname, &s) < 0) {
|
||||
fatal_exit("could not stat %s: %s", fname, strerror(errno));
|
||||
}
|
||||
return s.st_size;
|
||||
}
|
||||
|
||||
/** read the logfile */
|
||||
static void
|
||||
readfile(rbtree_t* tree, const char* fname, struct alloc_misc* misc)
|
||||
{
|
||||
off_t total = get_file_size(fname);
|
||||
off_t done = (off_t)0;
|
||||
int report = 0;
|
||||
FILE* in = fopen(fname, "r");
|
||||
char buf[102400];
|
||||
if(!in)
|
||||
fatal_exit("could not open %s: %s", fname, strerror(errno));
|
||||
printf("Reading %s of size %lld\n", fname, (long long)total);
|
||||
while(fgets(buf, 102400, in)) {
|
||||
buf[102400-1] = 0;
|
||||
done += (off_t)strlen(buf);
|
||||
/* progress count */
|
||||
if((int)(((double)done / (double)total)*100.) > report) {
|
||||
report = (int)(((double)done / (double)total)*100.);
|
||||
fprintf(stderr, " %d%%", report);
|
||||
}
|
||||
|
||||
if(!match(buf))
|
||||
continue;
|
||||
if(strncmp(buf+36, "region ", 7) == 0)
|
||||
read_region_stat(buf, misc);
|
||||
else if(strstr(buf+36, "malloc("))
|
||||
read_malloc_stat(buf, tree);
|
||||
else if(strstr(buf+36, "calloc("))
|
||||
read_calloc_stat(buf, tree);
|
||||
else {
|
||||
printf("%s\n", buf);
|
||||
fatal_exit("unhandled input");
|
||||
}
|
||||
}
|
||||
fprintf(stderr, " done\n");
|
||||
fclose(in);
|
||||
}
|
||||
|
||||
/** print memory stats */
|
||||
static void
|
||||
printstats(rbtree_t* tree, struct alloc_misc* misc)
|
||||
{
|
||||
struct codeline* cl;
|
||||
uint64_t total = 0;
|
||||
printf("%12lld in region alloc\n", (long long)misc->region_alloc);
|
||||
total += misc->region_alloc;
|
||||
RBTREE_FOR(cl, struct codeline*, tree) {
|
||||
printf("%12lld in %s %s\n", (long long)cl->alloc,
|
||||
cl->codeline, cl->func);
|
||||
total += cl->alloc;
|
||||
}
|
||||
printf("------------\n");
|
||||
printf("%12lld total in %ld code lines\n", (long long)total,
|
||||
(long)tree->count);
|
||||
printf("\n");
|
||||
}
|
||||
|
||||
/** main program */
|
||||
int main(int argc, const char* argv[])
|
||||
{
|
||||
rbtree_t* tree = 0;
|
||||
struct alloc_misc misc;
|
||||
if(argc != 2) {
|
||||
usage();
|
||||
}
|
||||
tree = rbtree_create(codeline_cmp);
|
||||
if(!tree)
|
||||
fatal_exit("alloc failure");
|
||||
memset(&misc, 0, sizeof(misc));
|
||||
readfile(tree, argv[1], &misc);
|
||||
printstats(tree, &misc);
|
||||
return 0;
|
||||
}
|
||||
Executable
+111
@@ -0,0 +1,111 @@
|
||||
# tpkg that only exes the files.
|
||||
args="../.."
|
||||
if test "$1" = "-a"; then
|
||||
args=$2
|
||||
shift
|
||||
shift
|
||||
fi
|
||||
|
||||
if test "$1" = "clean"; then
|
||||
echo "rm -f result.* .done* .tpkg.var.master .tpkg.var.test"
|
||||
rm -f result.* .done* .tpkg.var.master .tpkg.var.test
|
||||
exit 0
|
||||
fi
|
||||
if test "$1" = "fake"; then
|
||||
echo "minitpkg fake $2"
|
||||
echo "fake" > .done-`basename $2 .tpkg`
|
||||
exit 0
|
||||
fi
|
||||
if test "$1" = "report" || test "$2" = "report"; then
|
||||
echo "Minitpkg Report"
|
||||
for result in result.*; do
|
||||
name=`echo $result | sed -e 's/result\.//'`
|
||||
if test -f ".done-$name"; then
|
||||
if test "$1" != "-q"; then
|
||||
echo "** PASSED ** : $name"
|
||||
fi
|
||||
else
|
||||
echo "!! FAILED !! : $name"
|
||||
fi
|
||||
done
|
||||
exit 0
|
||||
fi
|
||||
|
||||
if test "$1" != 'exe'; then
|
||||
# usage
|
||||
echo "mini tpkg. Reduced functionality for old shells."
|
||||
echo " tpkg exe <file>"
|
||||
echo " tpkg fake <file>"
|
||||
echo " tpkg clean"
|
||||
echo " tpkg [-q] report"
|
||||
exit 1
|
||||
fi
|
||||
shift
|
||||
|
||||
# do not execute if the disk is too full
|
||||
#DISKLIMIT=100000
|
||||
# This check is not portable (to Solaris 10).
|
||||
#avail=`df . | tail -1 | awk '{print $4}'`
|
||||
#if test "$avail" -lt "$DISKLIMIT"; then
|
||||
#echo "minitpkg: The disk is too full! Only $avail."
|
||||
#exit 1
|
||||
#fi
|
||||
|
||||
name=`basename $1 .tpkg`
|
||||
dir=$name.$$
|
||||
result=result.$name
|
||||
done=.done-$name
|
||||
success="no"
|
||||
shell="bash"
|
||||
|
||||
# check already done
|
||||
if test -f .done-$name; then
|
||||
echo "minitpkg .done-$name exists. skip test."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# Extract
|
||||
echo "minitpkg extract $1 to $dir"
|
||||
mkdir $dir
|
||||
gzip -cd $name.tpkg | (cd $dir; tar xf -)
|
||||
cd $dir
|
||||
mv $name.dir/* .
|
||||
|
||||
# EXE
|
||||
echo "minitpkg exe $name"
|
||||
echo "minitpkg exe $name" > $result
|
||||
if test -f $name.pre; then
|
||||
echo "minitpkg exe $name.pre"
|
||||
echo "minitpkg exe $name.pre" >> $result
|
||||
$shell $name.pre $args >> $result
|
||||
if test $? -ne 0; then
|
||||
echo "Warning: $name.pre did not exit successfully"
|
||||
fi
|
||||
fi
|
||||
if test -f $name.test; then
|
||||
echo "minitpkg exe $name.test"
|
||||
echo "minitpkg exe $name.test" >> $result
|
||||
$shell $name.test $args >>$result 2>&1
|
||||
if test $? -ne 0; then
|
||||
echo "$name: FAILED" >> $result
|
||||
echo "$name: FAILED"
|
||||
success="no"
|
||||
else
|
||||
echo "$name: PASSED" >> $result
|
||||
echo "$name: PASSED" > ../.done-$name
|
||||
echo "$name: PASSED"
|
||||
success="yes"
|
||||
fi
|
||||
fi
|
||||
if test -f $name.post; then
|
||||
echo "minitpkg exe $name.post"
|
||||
echo "minitpkg exe $name.post" >> $result
|
||||
$shell $name.post $args >> $result
|
||||
if test $? -ne 0; then
|
||||
echo "Warning: $name.post did not exit successfully"
|
||||
fi
|
||||
fi
|
||||
|
||||
mv $result ..
|
||||
cd ..
|
||||
rm -rf $dir
|
||||
+21
-13
@@ -111,8 +111,13 @@ void analyze_rdata(ldns_buffer*pkt, const ldns_rr_descriptor* desc,
|
||||
}
|
||||
rdf++;
|
||||
}
|
||||
if(rdlen)
|
||||
if(rdlen) {
|
||||
size_t i;
|
||||
printf(" remain[%d]\n", (int)rdlen);
|
||||
for(i=0; i<rdlen; i++)
|
||||
printf(" %2.2X", (unsigned)ldns_buffer_current(pkt)[i]);
|
||||
printf("\n");
|
||||
}
|
||||
else printf("\n");
|
||||
ldns_buffer_skip(pkt, (ssize_t)rdlen);
|
||||
}
|
||||
@@ -134,9 +139,9 @@ void analyze_rr(ldns_buffer* pkt, int q)
|
||||
printf("\n");
|
||||
} else {
|
||||
ttl = ldns_buffer_read_u32(pkt);
|
||||
printf(" ttl %d (0x%x)", ttl, ttl);
|
||||
printf(" ttl %d (0x%x)", (int)ttl, (unsigned)ttl);
|
||||
len = ldns_buffer_read_u16(pkt);
|
||||
printf(" rdata len %d:\n", len);
|
||||
printf(" rdata len %d:\n", (int)len);
|
||||
if(ldns_rr_descript(type))
|
||||
analyze_rdata(pkt, ldns_rr_descript(type), len);
|
||||
else ldns_buffer_skip(pkt, (ssize_t)len);
|
||||
@@ -152,25 +157,28 @@ void analyze(ldns_buffer* pkt)
|
||||
if(ldns_buffer_limit(pkt) < 12) return;
|
||||
|
||||
i = ldns_buffer_read_u16(pkt);
|
||||
printf("id (hostorder): %d (0x%x)\n", i, i);
|
||||
printf("id (hostorder): %d (0x%x)\n", (int)i, (unsigned)i);
|
||||
f = ldns_buffer_read_u16(pkt);
|
||||
printf("flags: 0x%x\n", f);
|
||||
printf("flags: 0x%x\n", (unsigned)f);
|
||||
qd = ldns_buffer_read_u16(pkt);
|
||||
printf("qdcount: %d\n", qd);
|
||||
printf("qdcount: %d\n", (int)qd);
|
||||
an = ldns_buffer_read_u16(pkt);
|
||||
printf("ancount: %d\n", an);
|
||||
printf("ancount: %d\n", (int)an);
|
||||
ns = ldns_buffer_read_u16(pkt);
|
||||
printf("nscount: %d\n", ns);
|
||||
printf("nscount: %d\n", (int)ns);
|
||||
ar = ldns_buffer_read_u16(pkt);
|
||||
printf("arcount: %d\n", ar);
|
||||
printf("arcount: %d\n", (int)ar);
|
||||
|
||||
printf(";-- query section\n");
|
||||
while(ldns_buffer_remaining(pkt) > 0) {
|
||||
if(rrnum == qd) printf(";-- answer section\n");
|
||||
if(rrnum == qd+an) printf(";-- authority section\n");
|
||||
if(rrnum == qd+an+ns) printf(";-- additional section\n");
|
||||
if(rrnum == (int)qd)
|
||||
printf(";-- answer section\n");
|
||||
if(rrnum == (int)qd+(int)an)
|
||||
printf(";-- authority section\n");
|
||||
if(rrnum == (int)qd+(int)an+(int)ns)
|
||||
printf(";-- additional section\n");
|
||||
printf("rr %d ", rrnum);
|
||||
analyze_rr(pkt, rrnum < qd);
|
||||
analyze_rr(pkt, rrnum < (int)qd);
|
||||
rrnum++;
|
||||
}
|
||||
}
|
||||
|
||||
+3
-3
@@ -46,7 +46,7 @@ static void
|
||||
skip_whites(const char** p)
|
||||
{
|
||||
while(1) {
|
||||
while(isspace(**p))
|
||||
while(isspace((int)**p))
|
||||
(*p)++;
|
||||
if(**p == ';') {
|
||||
/* comment, skip until newline */
|
||||
@@ -68,11 +68,11 @@ void hex_to_buf(ldns_buffer* pkt, const char* hex)
|
||||
skip_whites(&p);
|
||||
if(ldns_buffer_position(pkt) == ldns_buffer_limit(pkt))
|
||||
fatal_exit("hex_to_buf: buffer too small");
|
||||
if(!isalnum(*p))
|
||||
if(!isalnum((int)*p))
|
||||
break;
|
||||
val = ldns_hexdigit_to_int(*p++) << 4;
|
||||
skip_whites(&p);
|
||||
log_assert(*p && isalnum(*p));
|
||||
log_assert(*p && isalnum((int)*p));
|
||||
val |= ldns_hexdigit_to_int(*p++);
|
||||
ldns_buffer_write_u8(pkt, (uint8_t)val);
|
||||
skip_whites(&p);
|
||||
|
||||
+7
-7
@@ -92,7 +92,7 @@ strip_end_white(char* p)
|
||||
{
|
||||
size_t i;
|
||||
for(i = strlen(p); i > 0; i--) {
|
||||
if(isspace(p[i-1]))
|
||||
if(isspace((int)p[i-1]))
|
||||
p[i-1] = 0;
|
||||
else return;
|
||||
}
|
||||
@@ -133,12 +133,12 @@ replay_range_read(char* remain, FILE* in, const char* name, int* lineno,
|
||||
while(fgets(line, MAX_LINE_LEN-1, in)) {
|
||||
(*lineno)++;
|
||||
parse = line;
|
||||
while(isspace(*parse))
|
||||
while(isspace((int)*parse))
|
||||
parse++;
|
||||
if(!*parse || *parse == ';')
|
||||
continue;
|
||||
if(parse_keyword(&parse, "ADDRESS")) {
|
||||
while(isspace(*parse))
|
||||
while(isspace((int)*parse))
|
||||
parse++;
|
||||
strip_end_white(parse);
|
||||
if(!extstrtoaddr(parse, &rng->addr, &rng->addrlen)) {
|
||||
@@ -199,7 +199,7 @@ replay_moment_read(char* remain, FILE* in, const char* name, int* lineno,
|
||||
return NULL;
|
||||
}
|
||||
remain += skip;
|
||||
while(isspace(*remain))
|
||||
while(isspace((int)*remain))
|
||||
remain++;
|
||||
if(parse_keyword(&remain, "NOTHING")) {
|
||||
mom->evt_type = repevt_nothing;
|
||||
@@ -224,7 +224,7 @@ replay_moment_read(char* remain, FILE* in, const char* name, int* lineno,
|
||||
free(mom);
|
||||
return NULL;
|
||||
}
|
||||
while(isspace(*remain))
|
||||
while(isspace((int)*remain))
|
||||
remain++;
|
||||
if(parse_keyword(&remain, "ADDRESS")) {
|
||||
if(!extstrtoaddr(remain, &mom->addr, &mom->addrlen)) {
|
||||
@@ -251,7 +251,7 @@ static struct replay_scenario*
|
||||
make_scenario(char* line)
|
||||
{
|
||||
struct replay_scenario* scen;
|
||||
while(isspace(*line))
|
||||
while(isspace((int)*line))
|
||||
line++;
|
||||
if(!*line) {
|
||||
log_err("scenario: no title given");
|
||||
@@ -283,7 +283,7 @@ replay_scenario_read(FILE* in, const char* name, int* lineno)
|
||||
while(fgets(line, MAX_LINE_LEN-1, in)) {
|
||||
parse=line;
|
||||
(*lineno)++;
|
||||
while(isspace(*parse))
|
||||
while(isspace((int)*parse))
|
||||
parse++;
|
||||
if(!*parse)
|
||||
continue; /* empty line */
|
||||
|
||||
@@ -0,0 +1,249 @@
|
||||
/*
|
||||
* testcode/signit.c - debug tool to sign rrsets with given keys.
|
||||
*
|
||||
* Copyright (c) 2007, NLnet Labs. All rights reserved.
|
||||
*
|
||||
* This software is open source.
|
||||
*
|
||||
* Redistribution and use in source and binary forms, with or without
|
||||
* modification, are permitted provided that the following conditions
|
||||
* are met:
|
||||
*
|
||||
* Redistributions of source code must retain the above copyright notice,
|
||||
* this list of conditions and the following disclaimer.
|
||||
*
|
||||
* Redistributions in binary form must reproduce the above copyright notice,
|
||||
* this list of conditions and the following disclaimer in the documentation
|
||||
* and/or other materials provided with the distribution.
|
||||
*
|
||||
* Neither the name of the NLNET LABS nor the names of its contributors may
|
||||
* be used to endorse or promote products derived from this software without
|
||||
* specific prior written permission.
|
||||
*
|
||||
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
|
||||
* TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||
* PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE
|
||||
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
* INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
* CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
* POSSIBILITY OF SUCH DAMAGE.
|
||||
*/
|
||||
|
||||
/**
|
||||
* \file
|
||||
*
|
||||
* This program signs rrsets with the given keys. It can be used to
|
||||
* construct input to test the validator with.
|
||||
*/
|
||||
#include "config.h"
|
||||
#include "util/log.h"
|
||||
#include "util/config_file.h"
|
||||
#include "util/net_help.h"
|
||||
|
||||
/**
|
||||
* Key settings
|
||||
*/
|
||||
struct keysets {
|
||||
/** signature inception */
|
||||
uint32_t incep;
|
||||
/** signature expiration */
|
||||
uint32_t expi;
|
||||
/** owner name */
|
||||
char* owner;
|
||||
/** keytag */
|
||||
uint16_t keytag;
|
||||
/** DNSKEY flags */
|
||||
uint16_t flags;
|
||||
};
|
||||
|
||||
/** print usage and exit */
|
||||
static void
|
||||
usage()
|
||||
{
|
||||
printf("usage: signit expi ince keytag owner keyfile\n");
|
||||
printf("present rrset data on stdin.\n");
|
||||
printf("signed data is printed to stdout.\n");
|
||||
printf("\n");
|
||||
printf("Or use: signit NSEC3PARAM hash flags iter salt\n");
|
||||
printf("present names on stdin, hashed names are printed to stdout.\n");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
/** read expi ince keytag owner from cmdline */
|
||||
static void
|
||||
parse_cmdline(char *argv[], struct keysets* s)
|
||||
{
|
||||
s->expi = cfg_convert_timeval(argv[1]);
|
||||
s->incep = cfg_convert_timeval(argv[2]);
|
||||
s->keytag = (uint16_t)atoi(argv[3]);
|
||||
s->owner = argv[4];
|
||||
s->flags = DNSKEY_BIT_ZSK; /* to enforce signing */
|
||||
}
|
||||
|
||||
/** read all key files, exit on error */
|
||||
static ldns_key_list*
|
||||
read_keys(int num, char* names[], struct keysets* set)
|
||||
{
|
||||
int i;
|
||||
ldns_key_list* keys = ldns_key_list_new();
|
||||
ldns_key* k;
|
||||
ldns_rdf* rdf;
|
||||
ldns_status s;
|
||||
int b;
|
||||
FILE* in;
|
||||
|
||||
if(!keys) fatal_exit("alloc failure");
|
||||
for(i=0; i<num; i++) {
|
||||
printf("read keyfile %s\n", names[i]);
|
||||
in = fopen(names[i], "r");
|
||||
if(!in) fatal_exit("could not open %s: %s", names[i],
|
||||
strerror(errno));
|
||||
s = ldns_key_new_frm_fp(&k, in);
|
||||
fclose(in);
|
||||
if(s != LDNS_STATUS_OK)
|
||||
fatal_exit("bad keyfile %s: %s", names[i],
|
||||
ldns_get_errorstr_by_id(s));
|
||||
ldns_key_set_expiration(k, set->expi);
|
||||
ldns_key_set_inception(k, set->incep);
|
||||
s = ldns_str2rdf_dname(&rdf, set->owner);
|
||||
if(s != LDNS_STATUS_OK)
|
||||
fatal_exit("bad owner name %s: %s", set->owner,
|
||||
ldns_get_errorstr_by_id(s));
|
||||
ldns_key_set_pubkey_owner(k, rdf);
|
||||
ldns_key_set_flags(k, set->flags);
|
||||
ldns_key_set_keytag(k, set->keytag);
|
||||
b = ldns_key_list_push_key(keys, k);
|
||||
log_assert(b);
|
||||
}
|
||||
return keys;
|
||||
}
|
||||
|
||||
/** read list of rrs from the file */
|
||||
static ldns_rr_list*
|
||||
read_rrs(FILE* in)
|
||||
{
|
||||
uint32_t my_ttl = 3600;
|
||||
ldns_rdf *my_origin = NULL;
|
||||
ldns_rdf *my_prev = NULL;
|
||||
ldns_status s;
|
||||
int line_nr = 1;
|
||||
int b;
|
||||
|
||||
ldns_rr_list* list;
|
||||
ldns_rr *rr;
|
||||
|
||||
list = ldns_rr_list_new();
|
||||
if(!list) fatal_exit("alloc error");
|
||||
|
||||
while(!feof(in)) {
|
||||
s = ldns_rr_new_frm_fp_l(&rr, in, &my_ttl, &my_origin,
|
||||
&my_prev, &line_nr);
|
||||
if(s == LDNS_STATUS_SYNTAX_TTL ||
|
||||
s == LDNS_STATUS_SYNTAX_ORIGIN ||
|
||||
s == LDNS_STATUS_SYNTAX_EMPTY)
|
||||
continue;
|
||||
else if(s != LDNS_STATUS_OK)
|
||||
fatal_exit("parse error in line %d: %s", line_nr,
|
||||
ldns_get_errorstr_by_id(s));
|
||||
b = ldns_rr_list_push_rr(list, rr);
|
||||
log_assert(b);
|
||||
}
|
||||
printf("read %d lines\n", line_nr);
|
||||
|
||||
return list;
|
||||
}
|
||||
|
||||
/** sign the rrs with the keys */
|
||||
static void
|
||||
signit(ldns_rr_list* rrs, ldns_key_list* keys)
|
||||
{
|
||||
ldns_rr_list* rrset;
|
||||
ldns_rr_list* sigs;
|
||||
|
||||
while(ldns_rr_list_rr_count(rrs) > 0) {
|
||||
rrset = ldns_rr_list_pop_rrset(rrs);
|
||||
if(!rrset) fatal_exit("copy alloc failure");
|
||||
sigs = ldns_sign_public(rrset, keys);
|
||||
if(!sigs) fatal_exit("failed to sign");
|
||||
ldns_rr_list_print(stdout, rrset);
|
||||
ldns_rr_list_print(stdout, sigs);
|
||||
printf("\n");
|
||||
ldns_rr_list_free(rrset);
|
||||
ldns_rr_list_free(sigs);
|
||||
}
|
||||
}
|
||||
|
||||
/** process keys and signit */
|
||||
static void
|
||||
process_keys(int argc, char* argv[])
|
||||
{
|
||||
ldns_rr_list* rrs;
|
||||
ldns_key_list* keys;
|
||||
struct keysets settings;
|
||||
log_assert(argc == 6);
|
||||
|
||||
parse_cmdline(argv, &settings);
|
||||
keys = read_keys(1, argv+5, &settings);
|
||||
rrs = read_rrs(stdin);
|
||||
signit(rrs, keys);
|
||||
|
||||
ldns_rr_list_deep_free(rrs);
|
||||
ldns_key_list_free(keys);
|
||||
}
|
||||
|
||||
/** process nsec3 params and perform hashing */
|
||||
static void
|
||||
process_nsec3(int argc, char* argv[])
|
||||
{
|
||||
char line[10240];
|
||||
ldns_rdf* salt;
|
||||
ldns_rdf* in, *out;
|
||||
ldns_status status;
|
||||
status = ldns_str2rdf_nsec3_salt(&salt, argv[5]);
|
||||
if(status != LDNS_STATUS_OK)
|
||||
fatal_exit("Could not parse salt %s: %s", argv[5],
|
||||
ldns_get_errorstr_by_id(status));
|
||||
log_assert(argc == 6);
|
||||
while(fgets(line, (int)sizeof(line), stdin)) {
|
||||
if(strlen(line) > 0)
|
||||
line[strlen(line)-1] = 0; /* remove trailing newline */
|
||||
if(line[0]==0)
|
||||
continue;
|
||||
status = ldns_str2rdf_dname(&in, line);
|
||||
if(status != LDNS_STATUS_OK)
|
||||
fatal_exit("Could not parse name %s: %s", line,
|
||||
ldns_get_errorstr_by_id(status));
|
||||
ldns_rdf_print(stdout, in);
|
||||
printf(" -> ");
|
||||
/* arg 3 is flags, unused */
|
||||
out = ldns_nsec3_hash_name(in, (uint8_t)atoi(argv[2]),
|
||||
(uint16_t)atoi(argv[4]),
|
||||
ldns_rdf_data(salt)[0], ldns_rdf_data(salt)+1);
|
||||
if(!out)
|
||||
fatal_exit("Could not hash %s", line);
|
||||
ldns_rdf_print(stdout, out);
|
||||
printf("\n");
|
||||
ldns_rdf_deep_free(in);
|
||||
ldns_rdf_deep_free(out);
|
||||
}
|
||||
ldns_rdf_deep_free(salt);
|
||||
}
|
||||
|
||||
/** main program */
|
||||
int main(int argc, char* argv[])
|
||||
{
|
||||
log_init(NULL);
|
||||
if(argc != 6) {
|
||||
usage();
|
||||
}
|
||||
if(strcmp(argv[1], "NSEC3PARAM") == 0) {
|
||||
process_nsec3(argc, argv);
|
||||
return 0;
|
||||
}
|
||||
process_keys(argc, argv);
|
||||
return 0;
|
||||
}
|
||||
+2
-3
@@ -77,12 +77,11 @@ EOF
|
||||
# echossh $1 "gtar xzf unbound_ttt.tar.gz && rm unbound_ttt.tar.gz"
|
||||
fi
|
||||
echossh $1 "cd $2; $MAKE_CMD -f makeconf.mak.$$ Makefile"
|
||||
echossh $1 "cd $2; $MAKE_CMD"
|
||||
echossh $1 "cd $2; $MAKE_CMD all tests"
|
||||
echossh $1 "cd $2; $MAKE_CMD doc"
|
||||
if test $RUN_TEST = yes; then
|
||||
echossh $1 "cd $2/testdata; tpkg clean"
|
||||
echossh $1 "cd $2; bash testcode/do-tests.sh"
|
||||
echossh $1 "cd $2/testdata; tpkg -q report" | tee -a $REPORT_FILE
|
||||
echossh $1 "cd $2/testdata; sh ../testcode/mini_tpkg.sh -q report" | tee -a $REPORT_FILE
|
||||
fi
|
||||
echossh $1 "cd $2; rm -f makeconf.mak.$$"
|
||||
rm -f makeconf.mak.$$
|
||||
|
||||
+16
-5
@@ -53,6 +53,8 @@
|
||||
|
||||
/** maximum line length for lines in the replay file. */
|
||||
#define MAX_LINE_LEN 1024
|
||||
/** the config file (removed at exit) */
|
||||
static char cfgfile[MAX_LINE_LEN];
|
||||
|
||||
/** give commandline usage for testbound. */
|
||||
static void
|
||||
@@ -82,7 +84,7 @@ add_opts(char* optarg, int* pass_argc, char* pass_argv[])
|
||||
{
|
||||
char *p = optarg, *np;
|
||||
size_t len;
|
||||
while(p && isspace(*p))
|
||||
while(p && isspace((int)*p))
|
||||
p++;
|
||||
while(p && *p) {
|
||||
/* find location of next string and length of this one */
|
||||
@@ -100,7 +102,7 @@ add_opts(char* optarg, int* pass_argc, char* pass_argv[])
|
||||
(*pass_argc)++;
|
||||
/* go to next option */
|
||||
p = np;
|
||||
while(p && isspace(*p))
|
||||
while(p && isspace((int)*p))
|
||||
p++;
|
||||
}
|
||||
}
|
||||
@@ -136,7 +138,7 @@ setup_config(FILE* in, char* configfile, int* lineno,
|
||||
while(fgets(line, MAX_LINE_LEN-1, in)) {
|
||||
parse = line;
|
||||
(*lineno)++;
|
||||
while(isspace(*parse))
|
||||
while(isspace((int)*parse))
|
||||
parse++;
|
||||
if(!*parse || parse[0] == ';')
|
||||
continue;
|
||||
@@ -179,6 +181,12 @@ setup_playback(const char* filename, char* configfile,
|
||||
log_info("Scenario: %s", scen->title);
|
||||
return scen;
|
||||
}
|
||||
|
||||
/** remove config file at exit */
|
||||
void remove_configfile(void)
|
||||
{
|
||||
unlink(cfgfile);
|
||||
}
|
||||
|
||||
/**
|
||||
* Main fake event test program. Setup, teardown and report errors.
|
||||
@@ -195,11 +203,11 @@ main(int argc, char* argv[])
|
||||
int init_optind = optind;
|
||||
char* init_optarg = optarg;
|
||||
struct replay_scenario* scen = NULL;
|
||||
char cfgfile[MAX_LINE_LEN];
|
||||
|
||||
log_init(NULL);
|
||||
log_info("Start of %s testbound program.", PACKAGE_STRING);
|
||||
/* determine commandline options for the daemon */
|
||||
cfgfile[0] = 0;
|
||||
pass_argc = 1;
|
||||
pass_argv[0] = "unbound";
|
||||
add_opts("-d", &pass_argc, pass_argv);
|
||||
@@ -224,6 +232,8 @@ main(int argc, char* argv[])
|
||||
testbound_usage();
|
||||
return 1;
|
||||
}
|
||||
if(atexit(&remove_configfile) != 0)
|
||||
fatal_exit("atexit() failed: %s", strerror(errno));
|
||||
|
||||
/* setup test environment */
|
||||
scen = setup_playback(playback_file, cfgfile, &pass_argc, pass_argv);
|
||||
@@ -240,9 +250,10 @@ main(int argc, char* argv[])
|
||||
/* run the normal daemon */
|
||||
res = daemon_main(pass_argc, pass_argv);
|
||||
|
||||
unlink(cfgfile);
|
||||
fake_event_cleanup();
|
||||
for(c=1; c<pass_argc; c++)
|
||||
free(pass_argv[c]);
|
||||
if(res == 0)
|
||||
log_info("Testbound Exit Success");
|
||||
return res;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,118 @@
|
||||
/*
|
||||
* testcode/unitanchor.c - unit test for trust anchor storage.
|
||||
*
|
||||
* Copyright (c) 2007, NLnet Labs. All rights reserved.
|
||||
*
|
||||
* This software is open source.
|
||||
*
|
||||
* Redistribution and use in source and binary forms, with or without
|
||||
* modification, are permitted provided that the following conditions
|
||||
* are met:
|
||||
*
|
||||
* Redistributions of source code must retain the above copyright notice,
|
||||
* this list of conditions and the following disclaimer.
|
||||
*
|
||||
* Redistributions in binary form must reproduce the above copyright notice,
|
||||
* this list of conditions and the following disclaimer in the documentation
|
||||
* and/or other materials provided with the distribution.
|
||||
*
|
||||
* Neither the name of the NLNET LABS nor the names of its contributors may
|
||||
* be used to endorse or promote products derived from this software without
|
||||
* specific prior written permission.
|
||||
*
|
||||
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
|
||||
* TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||
* PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE
|
||||
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
* INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
* CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
* POSSIBILITY OF SUCH DAMAGE.
|
||||
*
|
||||
*/
|
||||
/**
|
||||
* \file
|
||||
* Calls trust anchor unit tests. Exits with code 1 on a failure.
|
||||
*/
|
||||
|
||||
#include "config.h"
|
||||
#include "util/log.h"
|
||||
#include "util/data/dname.h"
|
||||
#include "testcode/unitmain.h"
|
||||
#include "validator/val_anchor.h"
|
||||
|
||||
/** test empty set */
|
||||
static void
|
||||
test_anchor_empty(struct val_anchors* a)
|
||||
{
|
||||
uint16_t c = LDNS_RR_CLASS_IN;
|
||||
unit_assert(anchors_lookup(a, (uint8_t*)"\000", 1, c) == NULL);
|
||||
unit_assert(anchors_lookup(a, (uint8_t*)"\003com\000", 5, c) == NULL);
|
||||
unit_assert(anchors_lookup(a,
|
||||
(uint8_t*)"\007example\003com\000", 11, c) == NULL);
|
||||
unit_assert(anchors_lookup(a, (uint8_t*)"\002nl\000", 4, c) == NULL);
|
||||
unit_assert(anchors_lookup(a,
|
||||
(uint8_t*)"\004labs\002nl\000", 9, c) == NULL);
|
||||
unit_assert(anchors_lookup(a,
|
||||
(uint8_t*)"\004fabs\002nl\000", 9, c) == NULL);
|
||||
}
|
||||
|
||||
/** test set of one anchor */
|
||||
static void
|
||||
test_anchor_one(ldns_buffer* buff, struct val_anchors* a)
|
||||
{
|
||||
uint16_t c = LDNS_RR_CLASS_IN;
|
||||
unit_assert(anchor_store_str(a, buff,
|
||||
"nl. DS 42860 5 1 14D739EB566D2B1A5E216A0BA4D17FA9B038BE4A"));
|
||||
unit_assert(anchors_lookup(a, (uint8_t*)"\000", 1, c) == NULL);
|
||||
unit_assert(anchors_lookup(a, (uint8_t*)"\003com\000", 5, c) == NULL);
|
||||
unit_assert(anchors_lookup(a,
|
||||
(uint8_t*)"\007example\003com\000", 11, c) == NULL);
|
||||
unit_assert(anchors_lookup(a, (uint8_t*)"\002nl\000", 4, c) != NULL);
|
||||
unit_assert(anchors_lookup(a,
|
||||
(uint8_t*)"\004labs\002nl\000", 9, c) != NULL);
|
||||
unit_assert(anchors_lookup(a,
|
||||
(uint8_t*)"\004fabs\002nl\000", 9, c) != NULL);
|
||||
unit_assert(anchors_lookup(a, (uint8_t*)"\002oo\000", 4, c) == NULL);
|
||||
}
|
||||
|
||||
/** test with several anchors */
|
||||
static void
|
||||
test_anchors(ldns_buffer* buff, struct val_anchors* a)
|
||||
{
|
||||
struct trust_anchor* ta;
|
||||
uint16_t c = LDNS_RR_CLASS_IN;
|
||||
unit_assert(anchor_store_str(a, buff,
|
||||
"labs.nl. DS 42860 5 1 14D739EB566D2B1A5E216A0BA4D17FA9B038BE4A"));
|
||||
unit_assert(anchors_lookup(a, (uint8_t*)"\000", 1, c) == NULL);
|
||||
unit_assert(anchors_lookup(a, (uint8_t*)"\003com\000", 5, c) == NULL);
|
||||
unit_assert(anchors_lookup(a,
|
||||
(uint8_t*)"\007example\003com\000", 11, c) == NULL);
|
||||
unit_assert(ta = anchors_lookup(a, (uint8_t*)"\002nl\000", 4, c));
|
||||
unit_assert(query_dname_compare(ta->name, (uint8_t*)"\002nl\000")==0);
|
||||
unit_assert(ta = anchors_lookup(a,
|
||||
(uint8_t*)"\004labs\002nl\000", 9, c));
|
||||
unit_assert(query_dname_compare(ta->name,
|
||||
(uint8_t*)"\004labs\002nl\000") == 0);
|
||||
unit_assert(ta = anchors_lookup(a,
|
||||
(uint8_t*)"\004fabs\002nl\000", 9, c));
|
||||
unit_assert(query_dname_compare(ta->name,
|
||||
(uint8_t*)"\002nl\000") == 0);
|
||||
unit_assert(anchors_lookup(a, (uint8_t*)"\002oo\000", 4, c) == NULL);
|
||||
}
|
||||
|
||||
void anchors_test()
|
||||
{
|
||||
ldns_buffer* buff = ldns_buffer_new(65800);
|
||||
struct val_anchors* a;
|
||||
unit_assert(a = anchors_create());
|
||||
ldns_buffer_flip(buff);
|
||||
test_anchor_empty(a);
|
||||
test_anchor_one(buff, a);
|
||||
test_anchors(buff, a);
|
||||
anchors_delete(a);
|
||||
ldns_buffer_free(buff);
|
||||
}
|
||||
+309
-4
@@ -76,21 +76,21 @@ static void
|
||||
dname_test_qdtl(ldns_buffer* buff)
|
||||
{
|
||||
ldns_buffer_write_at(buff, 0, "\012abCDeaBCde\003cOm\000", 16);
|
||||
query_dname_tolower(ldns_buffer_begin(buff), 16);
|
||||
query_dname_tolower(ldns_buffer_begin(buff));
|
||||
unit_assert( memcmp(ldns_buffer_begin(buff),
|
||||
"\012abcdeabcde\003com\000", 16) == 0);
|
||||
|
||||
ldns_buffer_write_at(buff, 0, "\001+\012abC{e-ZYXe\003NET\000", 18);
|
||||
query_dname_tolower(ldns_buffer_begin(buff), 18);
|
||||
query_dname_tolower(ldns_buffer_begin(buff));
|
||||
unit_assert( memcmp(ldns_buffer_begin(buff),
|
||||
"\001+\012abc{e-zyxe\003net\000", 18) == 0);
|
||||
|
||||
ldns_buffer_write_at(buff, 0, "\000", 1);
|
||||
query_dname_tolower(ldns_buffer_begin(buff), 1);
|
||||
query_dname_tolower(ldns_buffer_begin(buff));
|
||||
unit_assert( memcmp(ldns_buffer_begin(buff), "\000", 1) == 0);
|
||||
|
||||
ldns_buffer_write_at(buff, 0, "\002NL\000", 4);
|
||||
query_dname_tolower(ldns_buffer_begin(buff), 4);
|
||||
query_dname_tolower(ldns_buffer_begin(buff));
|
||||
unit_assert( memcmp(ldns_buffer_begin(buff), "\002nl\000", 4) == 0);
|
||||
}
|
||||
|
||||
@@ -433,6 +433,305 @@ dname_test_strict_subdomain()
|
||||
(uint8_t*)"\007example\003org", 3));
|
||||
}
|
||||
|
||||
/** test dname_is_root */
|
||||
static void
|
||||
dname_test_isroot()
|
||||
{
|
||||
unit_assert(dname_is_root((uint8_t*)"\000"));
|
||||
unit_assert(!dname_is_root((uint8_t*)"\001a\000"));
|
||||
unit_assert(!dname_is_root((uint8_t*)"\005abvcd\003com\000"));
|
||||
/* malformed dname in this test, but should work */
|
||||
unit_assert(!dname_is_root((uint8_t*)"\077a\000"));
|
||||
unit_assert(dname_is_root((uint8_t*)"\000"));
|
||||
}
|
||||
|
||||
/** test dname_remove_label */
|
||||
static void
|
||||
dname_test_removelabel()
|
||||
{
|
||||
uint8_t* orig = (uint8_t*)"\007example\003com\000";
|
||||
uint8_t* n = orig;
|
||||
size_t l = 13;
|
||||
dname_remove_label(&n, &l);
|
||||
unit_assert( n == orig+8 );
|
||||
unit_assert( l == 5 );
|
||||
dname_remove_label(&n, &l);
|
||||
unit_assert( n == orig+12 );
|
||||
unit_assert( l == 1 );
|
||||
dname_remove_label(&n, &l);
|
||||
unit_assert( n == orig+12 );
|
||||
unit_assert( l == 1 );
|
||||
}
|
||||
|
||||
/** test dname_signame_label_count */
|
||||
static void
|
||||
dname_test_sigcount()
|
||||
{
|
||||
unit_assert(dname_signame_label_count((uint8_t*)"\000") == 0);
|
||||
unit_assert(dname_signame_label_count((uint8_t*)"\001*\000") == 0);
|
||||
unit_assert(dname_signame_label_count((uint8_t*)"\003xom\000") == 1);
|
||||
unit_assert(dname_signame_label_count(
|
||||
(uint8_t*)"\001*\003xom\000") == 1);
|
||||
unit_assert(dname_signame_label_count(
|
||||
(uint8_t*)"\007example\003xom\000") == 2);
|
||||
unit_assert(dname_signame_label_count(
|
||||
(uint8_t*)"\001*\007example\003xom\000") == 2);
|
||||
unit_assert(dname_signame_label_count(
|
||||
(uint8_t*)"\003www\007example\003xom\000") == 3);
|
||||
unit_assert(dname_signame_label_count(
|
||||
(uint8_t*)"\001*\003www\007example\003xom\000") == 3);
|
||||
}
|
||||
|
||||
/** test dname_is_wild routine */
|
||||
static void
|
||||
dname_test_iswild()
|
||||
{
|
||||
unit_assert( !dname_is_wild((uint8_t*)"\000") );
|
||||
unit_assert( dname_is_wild((uint8_t*)"\001*\000") );
|
||||
unit_assert( !dname_is_wild((uint8_t*)"\003net\000") );
|
||||
unit_assert( dname_is_wild((uint8_t*)"\001*\003net\000") );
|
||||
}
|
||||
|
||||
/** test dname_canonical_compare */
|
||||
static void
|
||||
dname_test_canoncmp()
|
||||
{
|
||||
/* equality */
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\000",
|
||||
(uint8_t*)"\000"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003net\000",
|
||||
(uint8_t*)"\003net\000"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\007example\003net\000",
|
||||
(uint8_t*)"\007example\003net\000"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\004test\007example\003net\000",
|
||||
(uint8_t*)"\004test\007example\003net\000"
|
||||
) == 0);
|
||||
|
||||
/* subdomains */
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003com",
|
||||
(uint8_t*)"\000"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\000",
|
||||
(uint8_t*)"\003com"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\007example\003com",
|
||||
(uint8_t*)"\003com"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003com",
|
||||
(uint8_t*)"\007example\003com"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\007example\003com",
|
||||
(uint8_t*)"\000"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\000",
|
||||
(uint8_t*)"\007example\003com"
|
||||
) == -1);
|
||||
|
||||
/* compare rightmost label */
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003com",
|
||||
(uint8_t*)"\003net"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003net",
|
||||
(uint8_t*)"\003com"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003net",
|
||||
(uint8_t*)"\003org"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\007example\003net",
|
||||
(uint8_t*)"\003org"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003org",
|
||||
(uint8_t*)"\007example\003net"
|
||||
) == 1);
|
||||
|
||||
/* label length makes a difference; but only if rest is equal */
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\004neta",
|
||||
(uint8_t*)"\003net"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\002ne",
|
||||
(uint8_t*)"\004neta"
|
||||
) == -1);
|
||||
|
||||
/* label content */
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003aag\007example\003net",
|
||||
(uint8_t*)"\003bla\007example\003net"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003bla\007example\003net",
|
||||
(uint8_t*)"\003aag\007example\003net"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003bla\003aag\007example\003net",
|
||||
(uint8_t*)"\003aag\003bla\007example\003net"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\02sn\003opt\003aag\007example\003net",
|
||||
(uint8_t*)"\02sn\003opt\003bla\007example\003net"
|
||||
) == -1);
|
||||
|
||||
/* lowercase during compare */
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\003bLa\007examPLe\003net",
|
||||
(uint8_t*)"\003bla\007eXAmple\003nET"
|
||||
) == 0);
|
||||
|
||||
/* example from 4034 */
|
||||
/* example a.example yljkjljk.a.example Z.a.example zABC.a.EXAMPLE
|
||||
z.example \001.z.example *.z.example \200.z.example */
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"",
|
||||
(uint8_t*)"\007example"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\007example",
|
||||
(uint8_t*)"\001a\007example"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001a\007example",
|
||||
(uint8_t*)"\010yljkjljk\001a\007example"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\010yljkjljk\001a\007example",
|
||||
(uint8_t*)"\001Z\001a\007example"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001Z\001a\007example",
|
||||
(uint8_t*)"\004zABC\001a\007EXAMPLE"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\004zABC\001a\007EXAMPLE",
|
||||
(uint8_t*)"\001z\007example"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001z\007example",
|
||||
(uint8_t*)"\001\001\001z\007example"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001\001\001z\007example",
|
||||
(uint8_t*)"\001*\001z\007example"
|
||||
) == -1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001*\001z\007example",
|
||||
(uint8_t*)"\001\200\001z\007example"
|
||||
) == -1);
|
||||
/* same example in reverse */
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\007example",
|
||||
(uint8_t*)""
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001a\007example",
|
||||
(uint8_t*)"\007example"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\010yljkjljk\001a\007example",
|
||||
(uint8_t*)"\001a\007example"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001Z\001a\007example",
|
||||
(uint8_t*)"\010yljkjljk\001a\007example"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\004zABC\001a\007EXAMPLE",
|
||||
(uint8_t*)"\001Z\001a\007example"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001z\007example",
|
||||
(uint8_t*)"\004zABC\001a\007EXAMPLE"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001\001\001z\007example",
|
||||
(uint8_t*)"\001z\007example"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001*\001z\007example",
|
||||
(uint8_t*)"\001\001\001z\007example"
|
||||
) == 1);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001\200\001z\007example",
|
||||
(uint8_t*)"\001*\001z\007example"
|
||||
) == 1);
|
||||
/* same example for equality */
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\007example",
|
||||
(uint8_t*)"\007example"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001a\007example",
|
||||
(uint8_t*)"\001a\007example"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\010yljkjljk\001a\007example",
|
||||
(uint8_t*)"\010yljkjljk\001a\007example"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001Z\001a\007example",
|
||||
(uint8_t*)"\001Z\001a\007example"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\004zABC\001a\007EXAMPLE",
|
||||
(uint8_t*)"\004zABC\001a\007EXAMPLE"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001z\007example",
|
||||
(uint8_t*)"\001z\007example"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001\001\001z\007example",
|
||||
(uint8_t*)"\001\001\001z\007example"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001*\001z\007example",
|
||||
(uint8_t*)"\001*\001z\007example"
|
||||
) == 0);
|
||||
unit_assert( dname_canonical_compare(
|
||||
(uint8_t*)"\001\200\001z\007example",
|
||||
(uint8_t*)"\001\200\001z\007example"
|
||||
) == 0);
|
||||
}
|
||||
|
||||
/** Test dname_get_shared_topdomain */
|
||||
static void
|
||||
dname_test_topdomain()
|
||||
{
|
||||
unit_assert( query_dname_compare(
|
||||
dname_get_shared_topdomain(
|
||||
(uint8_t*)"",
|
||||
(uint8_t*)""),
|
||||
(uint8_t*)"") == 0);
|
||||
unit_assert( query_dname_compare(
|
||||
dname_get_shared_topdomain(
|
||||
(uint8_t*)"\003www\007example\003com",
|
||||
(uint8_t*)"\003www\007example\003com"),
|
||||
(uint8_t*)"\003www\007example\003com") == 0);
|
||||
unit_assert( query_dname_compare(
|
||||
dname_get_shared_topdomain(
|
||||
(uint8_t*)"\003www\007example\003com",
|
||||
(uint8_t*)"\003bla\007example\003com"),
|
||||
(uint8_t*)"\007example\003com") == 0);
|
||||
}
|
||||
|
||||
void dname_test()
|
||||
{
|
||||
ldns_buffer* buff = ldns_buffer_new(65800);
|
||||
@@ -446,5 +745,11 @@ void dname_test()
|
||||
dname_test_pkt_dname_len(buff);
|
||||
dname_test_strict_subdomain();
|
||||
dname_test_subdomain();
|
||||
dname_test_isroot();
|
||||
dname_test_removelabel();
|
||||
dname_test_sigcount();
|
||||
dname_test_iswild();
|
||||
dname_test_canoncmp();
|
||||
dname_test_topdomain();
|
||||
ldns_buffer_free(buff);
|
||||
}
|
||||
|
||||
@@ -213,8 +213,10 @@ main(int argc, char* argv[])
|
||||
}
|
||||
printf("Start of %s unit test.\n", PACKAGE_STRING);
|
||||
checklock_start();
|
||||
verify_test();
|
||||
net_test();
|
||||
dname_test();
|
||||
anchors_test();
|
||||
rtt_test();
|
||||
alloc_test();
|
||||
lruhash_test();
|
||||
|
||||
@@ -55,5 +55,9 @@ void slabhash_test();
|
||||
void msgparse_test();
|
||||
/** unit test dname handling functions */
|
||||
void dname_test();
|
||||
/** unit test trust anchor storage functions */
|
||||
void anchors_test();
|
||||
/** unit test for verification functions */
|
||||
void verify_test();
|
||||
|
||||
#endif /* TESTCODE_UNITMAIN_H */
|
||||
|
||||
+24
-11
@@ -51,6 +51,8 @@
|
||||
|
||||
/** verbose message parse unit test */
|
||||
static int vbmp = 0;
|
||||
/** if matching within a section should disregard the order of RRs. */
|
||||
static int matches_nolocation = 0;
|
||||
|
||||
/** match two rr lists */
|
||||
static int
|
||||
@@ -65,18 +67,25 @@ match_list(ldns_rr_list* q, ldns_rr_list *p)
|
||||
}
|
||||
for(i=0; i<ldns_rr_list_rr_count(q); i++)
|
||||
{
|
||||
if(ldns_rr_compare(ldns_rr_list_rr(q, i),
|
||||
ldns_rr_list_rr(p, i)) != 0) {
|
||||
verbose(3, "rr %u different", (unsigned)i);
|
||||
return 0;
|
||||
if(matches_nolocation) {
|
||||
if(!ldns_rr_list_contains_rr(p, ldns_rr_list_rr(q, i)))
|
||||
{
|
||||
verbose(3, "rr %u not found", (unsigned)i);
|
||||
return 0;
|
||||
}
|
||||
} else {
|
||||
if(ldns_rr_compare(ldns_rr_list_rr(q, i),
|
||||
ldns_rr_list_rr(p, i)) != 0) {
|
||||
verbose(3, "rr %u different", (unsigned)i);
|
||||
return 0;
|
||||
}
|
||||
/* and check the ttl */
|
||||
if(ldns_rr_ttl(ldns_rr_list_rr(q, i)) !=
|
||||
ldns_rr_ttl(ldns_rr_list_rr(p, i))) {
|
||||
verbose(3, "rr %u ttl different", (unsigned)i);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
/* and check the ttl */
|
||||
if(ldns_rr_ttl(ldns_rr_list_rr(q, i)) !=
|
||||
ldns_rr_ttl(ldns_rr_list_rr(p, i))) {
|
||||
verbose(3, "rr %u ttl different", (unsigned)i);
|
||||
return 0;
|
||||
}
|
||||
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
@@ -433,6 +442,10 @@ void msgparse_test()
|
||||
testfromdrillfile(pkt, &alloc, out, "testdata/test_packets.4");
|
||||
testfromdrillfile(pkt, &alloc, out, "testdata/test_packets.5");
|
||||
|
||||
matches_nolocation = 1; /* RR order not important for the next test */
|
||||
testfromdrillfile(pkt, &alloc, out, "testdata/test_packets.6");
|
||||
matches_nolocation = 0;
|
||||
|
||||
/* cleanup */
|
||||
alloc_clear(&alloc);
|
||||
alloc_clear(&super_a);
|
||||
|
||||
@@ -0,0 +1,463 @@
|
||||
/*
|
||||
* testcode/unitverify.c - unit test for signature verification routines.
|
||||
*
|
||||
* Copyright (c) 2007, NLnet Labs. All rights reserved.
|
||||
*
|
||||
* This software is open source.
|
||||
*
|
||||
* Redistribution and use in source and binary forms, with or without
|
||||
* modification, are permitted provided that the following conditions
|
||||
* are met:
|
||||
*
|
||||
* Redistributions of source code must retain the above copyright notice,
|
||||
* this list of conditions and the following disclaimer.
|
||||
*
|
||||
* Redistributions in binary form must reproduce the above copyright notice,
|
||||
* this list of conditions and the following disclaimer in the documentation
|
||||
* and/or other materials provided with the distribution.
|
||||
*
|
||||
* Neither the name of the NLNET LABS nor the names of its contributors may
|
||||
* be used to endorse or promote products derived from this software without
|
||||
* specific prior written permission.
|
||||
*
|
||||
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
|
||||
* TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
|
||||
* PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE
|
||||
* LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
|
||||
* CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
|
||||
* SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
|
||||
* INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
|
||||
* CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
|
||||
* ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
|
||||
* POSSIBILITY OF SUCH DAMAGE.
|
||||
*
|
||||
*/
|
||||
/**
|
||||
* \file
|
||||
* Calls verification unit tests. Exits with code 1 on a failure.
|
||||
*/
|
||||
|
||||
#include "config.h"
|
||||
#include "util/log.h"
|
||||
#include "testcode/unitmain.h"
|
||||
#include "validator/val_sigcrypt.h"
|
||||
#include "validator/val_nsec.h"
|
||||
#include "validator/val_nsec3.h"
|
||||
#include "validator/validator.h"
|
||||
#include "testcode/ldns-testpkts.h"
|
||||
#include "util/data/msgreply.h"
|
||||
#include "util/data/msgparse.h"
|
||||
#include "util/data/dname.h"
|
||||
#include "util/region-allocator.h"
|
||||
#include "util/alloc.h"
|
||||
#include "util/rbtree.h"
|
||||
#include "util/net_help.h"
|
||||
#include "util/module.h"
|
||||
#include "util/config_file.h"
|
||||
|
||||
/** verbose signature test */
|
||||
static int vsig = 0;
|
||||
|
||||
/** entry to packet buffer with wireformat */
|
||||
static void
|
||||
entry_to_buf(struct entry* e, ldns_buffer* pkt)
|
||||
{
|
||||
unit_assert(e->reply_list);
|
||||
if(e->reply_list->reply_from_hex) {
|
||||
ldns_buffer_copy(pkt, e->reply_list->reply_from_hex);
|
||||
} else {
|
||||
ldns_status status;
|
||||
size_t answer_size;
|
||||
uint8_t* ans = NULL;
|
||||
status = ldns_pkt2wire(&ans, e->reply_list->reply,
|
||||
&answer_size);
|
||||
if(status != LDNS_STATUS_OK) {
|
||||
log_err("could not create reply: %s",
|
||||
ldns_get_errorstr_by_id(status));
|
||||
fatal_exit("error in test");
|
||||
}
|
||||
ldns_buffer_clear(pkt);
|
||||
ldns_buffer_write(pkt, ans, answer_size);
|
||||
ldns_buffer_flip(pkt);
|
||||
free(ans);
|
||||
}
|
||||
}
|
||||
|
||||
/** entry to reply info conversion */
|
||||
static void
|
||||
entry_to_repinfo(struct entry* e, struct alloc_cache* alloc, struct region*
|
||||
region, ldns_buffer* pkt, struct query_info* qi,
|
||||
struct reply_info** rep)
|
||||
{
|
||||
int ret;
|
||||
struct edns_data edns;
|
||||
entry_to_buf(e, pkt);
|
||||
/* lock alloc lock to please lock checking software.
|
||||
* alloc_special_obtain assumes it is talking to a ub-alloc,
|
||||
* and does not need to perform locking. Here the alloc is
|
||||
* the only one, so we lock it here */
|
||||
lock_quick_lock(&alloc->lock);
|
||||
ret = reply_info_parse(pkt, alloc, qi, rep, region, &edns);
|
||||
lock_quick_unlock(&alloc->lock);
|
||||
if(ret != 0) {
|
||||
printf("parse code %d: %s\n", ret,
|
||||
ldns_lookup_by_id(ldns_rcodes, ret)->name);
|
||||
unit_assert(ret != 0);
|
||||
}
|
||||
}
|
||||
|
||||
/** extract DNSKEY rrset from answer and convert it */
|
||||
static struct ub_packed_rrset_key*
|
||||
extract_keys(struct entry* e, struct alloc_cache* alloc, struct region*
|
||||
region, ldns_buffer* pkt)
|
||||
{
|
||||
struct ub_packed_rrset_key* dnskey = NULL;
|
||||
struct query_info qinfo;
|
||||
struct reply_info* rep = NULL;
|
||||
size_t i;
|
||||
|
||||
entry_to_repinfo(e, alloc, region, pkt, &qinfo, &rep);
|
||||
for(i=0; i<rep->an_numrrsets; i++) {
|
||||
if(ntohs(rep->rrsets[i]->rk.type) == LDNS_RR_TYPE_DNSKEY) {
|
||||
dnskey = rep->rrsets[i];
|
||||
rep->rrsets[i] = NULL;
|
||||
break;
|
||||
}
|
||||
}
|
||||
unit_assert(dnskey);
|
||||
|
||||
reply_info_parsedelete(rep, alloc);
|
||||
query_info_clear(&qinfo);
|
||||
return dnskey;
|
||||
}
|
||||
|
||||
/** return true if answer should be bogus */
|
||||
static int
|
||||
should_be_bogus(struct ub_packed_rrset_key* rrset)
|
||||
{
|
||||
struct packed_rrset_data* d = (struct packed_rrset_data*)rrset->
|
||||
entry.data;
|
||||
if(d->rrsig_count == 0)
|
||||
return 1;
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** verify and test one rrset against the key rrset */
|
||||
static void
|
||||
verifytest_rrset(struct module_env* env, struct val_env* ve,
|
||||
struct ub_packed_rrset_key* rrset, struct ub_packed_rrset_key* dnskey)
|
||||
{
|
||||
enum sec_status sec;
|
||||
if(vsig) {
|
||||
log_nametypeclass(VERB_DETAIL, "verify of rrset",
|
||||
rrset->rk.dname, ntohs(rrset->rk.type),
|
||||
ntohs(rrset->rk.rrset_class));
|
||||
}
|
||||
sec = dnskeyset_verify_rrset(env, ve, rrset, dnskey);
|
||||
if(vsig) {
|
||||
printf("verify outcome is: %s\n", sec_status_to_string(sec));
|
||||
}
|
||||
if(should_be_bogus(rrset)) {
|
||||
unit_assert(sec == sec_status_bogus);
|
||||
} else {
|
||||
unit_assert(sec == sec_status_secure);
|
||||
}
|
||||
}
|
||||
|
||||
/** verify and test an entry - every rr in the message */
|
||||
static void
|
||||
verifytest_entry(struct entry* e, struct alloc_cache* alloc, struct region*
|
||||
region, ldns_buffer* pkt, struct ub_packed_rrset_key* dnskey,
|
||||
struct module_env* env, struct val_env* ve)
|
||||
{
|
||||
struct query_info qinfo;
|
||||
struct reply_info* rep = NULL;
|
||||
size_t i;
|
||||
|
||||
region_free_all(region);
|
||||
if(vsig) {
|
||||
printf("verifying pkt:\n");
|
||||
ldns_pkt_print(stdout, e->reply_list->reply);
|
||||
printf("\n");
|
||||
}
|
||||
entry_to_repinfo(e, alloc, region, pkt, &qinfo, &rep);
|
||||
|
||||
for(i=0; i<rep->rrset_count; i++) {
|
||||
verifytest_rrset(env, ve, rep->rrsets[i], dnskey);
|
||||
}
|
||||
|
||||
reply_info_parsedelete(rep, alloc);
|
||||
query_info_clear(&qinfo);
|
||||
}
|
||||
|
||||
/** find RRset in reply by type */
|
||||
static struct ub_packed_rrset_key*
|
||||
find_rrset_type(struct reply_info* rep, uint16_t type)
|
||||
{
|
||||
size_t i;
|
||||
for(i=0; i<rep->rrset_count; i++) {
|
||||
if(ntohs(rep->rrsets[i]->rk.type) == type)
|
||||
return rep->rrsets[i];
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/** DS sig test an entry - get DNSKEY and DS in entry and verify */
|
||||
static void
|
||||
dstest_entry(struct entry* e, struct alloc_cache* alloc, struct region*
|
||||
region, ldns_buffer* pkt, struct module_env* env)
|
||||
{
|
||||
struct query_info qinfo;
|
||||
struct reply_info* rep = NULL;
|
||||
struct ub_packed_rrset_key* ds, *dnskey;
|
||||
int ret;
|
||||
|
||||
region_free_all(region);
|
||||
if(vsig) {
|
||||
printf("verifying DS-DNSKEY match:\n");
|
||||
ldns_pkt_print(stdout, e->reply_list->reply);
|
||||
printf("\n");
|
||||
}
|
||||
entry_to_repinfo(e, alloc, region, pkt, &qinfo, &rep);
|
||||
ds = find_rrset_type(rep, LDNS_RR_TYPE_DS);
|
||||
dnskey = find_rrset_type(rep, LDNS_RR_TYPE_DNSKEY);
|
||||
/* check test is OK */
|
||||
unit_assert(ds && dnskey);
|
||||
|
||||
ret = ds_digest_match_dnskey(env, dnskey, 0, ds, 0);
|
||||
if(strncmp((char*)qinfo.qname, "\003yes", 4) == 0) {
|
||||
if(vsig) {
|
||||
printf("result(yes)= %s\n", ret?"yes":"no");
|
||||
}
|
||||
unit_assert(ret);
|
||||
} else if (strncmp((char*)qinfo.qname, "\002no", 3) == 0) {
|
||||
if(vsig) {
|
||||
printf("result(no)= %s\n", ret?"yes":"no");
|
||||
}
|
||||
unit_assert(!ret);
|
||||
verbose(VERB_DETAIL, "DS fail: OK; matched unit test");
|
||||
} else {
|
||||
fatal_exit("Bad qname in DS unit test, yes or no");
|
||||
}
|
||||
|
||||
reply_info_parsedelete(rep, alloc);
|
||||
query_info_clear(&qinfo);
|
||||
}
|
||||
|
||||
/** verify from a file */
|
||||
static void
|
||||
verifytest_file(const char* fname, const char* at_date)
|
||||
{
|
||||
/*
|
||||
* The file contains a list of ldns-testpkts entries.
|
||||
* The first entry must be a query for DNSKEY.
|
||||
* The answer rrset is the keyset that will be used for verification
|
||||
*/
|
||||
struct ub_packed_rrset_key* dnskey;
|
||||
struct region* region = region_create(malloc, free);
|
||||
struct alloc_cache alloc;
|
||||
ldns_buffer* buf = ldns_buffer_new(65535);
|
||||
struct entry* e;
|
||||
struct entry* list = read_datafile(fname);
|
||||
struct module_env env;
|
||||
struct val_env ve;
|
||||
|
||||
if(!list)
|
||||
fatal_exit("could not read %s: %s", fname, strerror(errno));
|
||||
alloc_init(&alloc, NULL, 1);
|
||||
memset(&env, 0, sizeof(env));
|
||||
memset(&ve, 0, sizeof(ve));
|
||||
env.scratch = region;
|
||||
env.scratch_buffer = buf;
|
||||
ve.date_override = cfg_convert_timeval(at_date);
|
||||
unit_assert(region && buf);
|
||||
dnskey = extract_keys(list, &alloc, region, buf);
|
||||
if(vsig) log_nametypeclass(VERB_DETAIL, "test dnskey",
|
||||
dnskey->rk.dname, ntohs(dnskey->rk.type),
|
||||
ntohs(dnskey->rk.rrset_class));
|
||||
/* ready to go! */
|
||||
for(e = list->next; e; e = e->next) {
|
||||
verifytest_entry(e, &alloc, region, buf, dnskey, &env, &ve);
|
||||
}
|
||||
|
||||
delete_entry(list);
|
||||
region_destroy(region);
|
||||
alloc_clear(&alloc);
|
||||
ldns_buffer_free(buf);
|
||||
}
|
||||
|
||||
/** verify DS matches DNSKEY from a file */
|
||||
static void
|
||||
dstest_file(const char* fname)
|
||||
{
|
||||
/*
|
||||
* The file contains a list of ldns-testpkts entries.
|
||||
* The first entry must be a query for DNSKEY.
|
||||
* The answer rrset is the keyset that will be used for verification
|
||||
*/
|
||||
struct region* region = region_create(malloc, free);
|
||||
struct alloc_cache alloc;
|
||||
ldns_buffer* buf = ldns_buffer_new(65535);
|
||||
struct entry* e;
|
||||
struct entry* list = read_datafile(fname);
|
||||
struct module_env env;
|
||||
|
||||
if(!list)
|
||||
fatal_exit("could not read %s: %s", fname, strerror(errno));
|
||||
alloc_init(&alloc, NULL, 1);
|
||||
memset(&env, 0, sizeof(env));
|
||||
env.scratch = region;
|
||||
env.scratch_buffer = buf;
|
||||
unit_assert(region && buf);
|
||||
|
||||
/* ready to go! */
|
||||
for(e = list; e; e = e->next) {
|
||||
dstest_entry(e, &alloc, region, buf, &env);
|
||||
}
|
||||
|
||||
delete_entry(list);
|
||||
region_destroy(region);
|
||||
alloc_clear(&alloc);
|
||||
ldns_buffer_free(buf);
|
||||
}
|
||||
|
||||
/** helper for unittest of NSEC routines */
|
||||
static int
|
||||
unitest_nsec_has_type_rdata(char* bitmap, size_t len, uint16_t type)
|
||||
{
|
||||
return nsecbitmap_has_type_rdata((uint8_t*)bitmap, len, type);
|
||||
}
|
||||
|
||||
/** Test NSEC type bitmap routine */
|
||||
static void
|
||||
nsectest()
|
||||
{
|
||||
/* bitmap starts at type bitmap rdata field */
|
||||
/* from rfc 4034 example */
|
||||
char* bitmap = "\000\006\100\001\000\000\000\003"
|
||||
"\004\033\000\000\000\000\000\000"
|
||||
"\000\000\000\000\000\000\000\000"
|
||||
"\000\000\000\000\000\000\000\000"
|
||||
"\000\000\000\000\040";
|
||||
size_t len = 37;
|
||||
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 0));
|
||||
unit_assert(unitest_nsec_has_type_rdata(bitmap, len, LDNS_RR_TYPE_A));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 2));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 3));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 4));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 5));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 6));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 7));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 8));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 9));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 10));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 11));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 12));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 13));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 14));
|
||||
unit_assert(unitest_nsec_has_type_rdata(bitmap, len, LDNS_RR_TYPE_MX));
|
||||
unit_assert(unitest_nsec_has_type_rdata(bitmap, len, LDNS_RR_TYPE_RRSIG));
|
||||
unit_assert(unitest_nsec_has_type_rdata(bitmap, len, LDNS_RR_TYPE_NSEC));
|
||||
unit_assert(unitest_nsec_has_type_rdata(bitmap, len, 1234));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 1233));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 1235));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 1236));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 1237));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 1238));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 1239));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 1240));
|
||||
unit_assert(!unitest_nsec_has_type_rdata(bitmap, len, 2230));
|
||||
}
|
||||
|
||||
/** Test hash algo - NSEC3 hash it and compare result */
|
||||
static void
|
||||
nsec3_hash_test_entry(struct entry* e, rbtree_t* ct,
|
||||
struct alloc_cache* alloc, struct region* region,
|
||||
ldns_buffer* buf)
|
||||
{
|
||||
struct query_info qinfo;
|
||||
struct reply_info* rep = NULL;
|
||||
struct ub_packed_rrset_key* answer, *nsec3;
|
||||
struct nsec3_cached_hash* hash;
|
||||
int ret;
|
||||
uint8_t* qname;
|
||||
|
||||
if(vsig) {
|
||||
printf("verifying NSEC3 hash:\n");
|
||||
ldns_pkt_print(stdout, e->reply_list->reply);
|
||||
printf("\n");
|
||||
}
|
||||
entry_to_repinfo(e, alloc, region, buf, &qinfo, &rep);
|
||||
nsec3 = find_rrset_type(rep, LDNS_RR_TYPE_NSEC3);
|
||||
answer = find_rrset_type(rep, LDNS_RR_TYPE_AAAA);
|
||||
qname = region_alloc_init(region, qinfo.qname, qinfo.qname_len);
|
||||
/* check test is OK */
|
||||
unit_assert(nsec3 && answer && qname);
|
||||
|
||||
ret = nsec3_hash_name(ct, region, buf, nsec3, 0, qname,
|
||||
qinfo.qname_len, &hash);
|
||||
if(ret != 1) {
|
||||
printf("Bad nsec3_hash_name retcode %d\n", ret);
|
||||
unit_assert(ret == 1);
|
||||
}
|
||||
unit_assert(hash->dname && hash->hash && hash->hash_len &&
|
||||
hash->b32 && hash->b32_len);
|
||||
unit_assert(hash->b32_len == (size_t)answer->rk.dname[0]);
|
||||
/* does not do lowercasing. */
|
||||
unit_assert(memcmp(hash->b32, answer->rk.dname+1, hash->b32_len)
|
||||
== 0);
|
||||
|
||||
reply_info_parsedelete(rep, alloc);
|
||||
query_info_clear(&qinfo);
|
||||
}
|
||||
|
||||
|
||||
/** Read file to test NSEC3 hash algo */
|
||||
static void
|
||||
nsec3_hash_test(const char* fname)
|
||||
{
|
||||
/*
|
||||
* The list contains a list of ldns-testpkts entries.
|
||||
* Every entry is a test.
|
||||
* The qname is hashed.
|
||||
* The answer section AAAA RR name is the required result.
|
||||
* The auth section NSEC3 is used to get hash parameters.
|
||||
* The hash cache is maintained per file.
|
||||
*
|
||||
* The test does not perform canonicalization during the compare.
|
||||
*/
|
||||
rbtree_t ct;
|
||||
struct region* region = region_create(malloc, free);
|
||||
struct alloc_cache alloc;
|
||||
ldns_buffer* buf = ldns_buffer_new(65535);
|
||||
struct entry* e;
|
||||
struct entry* list = read_datafile(fname);
|
||||
|
||||
if(!list)
|
||||
fatal_exit("could not read %s: %s", fname, strerror(errno));
|
||||
rbtree_init(&ct, &nsec3_hash_cmp);
|
||||
alloc_init(&alloc, NULL, 1);
|
||||
unit_assert(region && buf);
|
||||
|
||||
/* ready to go! */
|
||||
for(e = list; e; e = e->next) {
|
||||
nsec3_hash_test_entry(e, &ct, &alloc, region, buf);
|
||||
}
|
||||
|
||||
delete_entry(list);
|
||||
region_destroy(region);
|
||||
alloc_clear(&alloc);
|
||||
ldns_buffer_free(buf);
|
||||
}
|
||||
|
||||
void
|
||||
verify_test()
|
||||
{
|
||||
printf("verify test\n");
|
||||
verifytest_file("testdata/test_signatures.1", "20070818005004");
|
||||
dstest_file("testdata/test_ds_sig.1");
|
||||
nsectest();
|
||||
nsec3_hash_test("testdata/test_nsec3_hash.1");
|
||||
}
|
||||
Vendored
BIN
Binary file not shown.
Vendored
+1
@@ -0,0 +1 @@
|
||||
example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b
|
||||
Vendored
+1
@@ -0,0 +1 @@
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJIIs70j+sDS/UT2QRp61SE7S3EEXopNXoFE73JLRmvpi/UrOO/Vz4Se6wXv/CYCKjGw06U4WRgRYXcpEhJROyNapmdIKSxhOzfLVE1gqA0PweZR8dtY3aNQSRn3sPpwJr6Mi/PqQKAMMrZ9ckJpf1+bQMOOvxgzz2U1GS18b3yZKcgTMEaJzd/GZYzi/BN2DzQ0MsrSwYXfsNLFOBbs8PJMW4LYIxeeOe6rUgkWOF7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
+7
@@ -0,0 +1,7 @@
|
||||
Private-key-format: v1.2
|
||||
Algorithm: 3 (DSA)
|
||||
Prime(p): +sDS/UT2QRp61SE7S3EEXopNXoFE73JLRmvpi/UrOO/Vz4Se6wXv/CYCKjGw06U4WRgRYXcpEhJROyNapmdIKQ==
|
||||
Subprime(q): tctSxapStjclgRHdPhMEkgizvSM=
|
||||
Base(g): LGE7N8tUTWCoDQ/B5lHx21jdo1BJGfew+nAmvoyL8+pAoAwytn1yQml/X5tAw46/GDPPZTUZLXxvfJkpyBMwRg==
|
||||
Private_value(x): XMs4XYi1oNckzTPvGMkgG5IiuzY=
|
||||
Public_value(y): ic3fxmWM4vwTdg80NDLK0sGF37DSxTgW7PDyTFuC2CMXnjnuq1IJFjhewgvQ4f3XbkNUK7CYZmQBBX3egcmFfg==
|
||||
Vendored
+1
@@ -0,0 +1 @@
|
||||
example.com. 3600 IN DS 30899 5 1 d4bf9d2e10f6d76840d42ef5913022abcd0bf512
|
||||
Vendored
+1
@@ -0,0 +1 @@
|
||||
example.com. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
+10
@@ -0,0 +1,10 @@
|
||||
Private-key-format: v1.2
|
||||
Algorithm: 5 (RSASHA1)
|
||||
Modulus: 0ONXIUfQxB7f2iMyBQKmp2w5UX5SaEbOcs9YxbKESE+3Vn9K/j3g7nsHcZLMzR+sJ1OEC/KXyhUYeTyGFQSytw==
|
||||
PublicExponent: Aw==
|
||||
PrivateExponent: i0I6Fi/ggr8/5sIhWKxvGkgmNlQ28C80TIo7LncC2t6ar2Q5rpyiDxEHvFLfphRh108ZOqf2tQdHx7tXTx5Gqw==
|
||||
Prime1: 9WS85Q92ilTAuGiVi+KesKzrFqF98l2Gpu4003hfmbc=
|
||||
Prime2: 2eqsD2jcY4Mgw26A8XFiaLdxx5J4s10Dhd9ur6X3rwE=
|
||||
Exponent1: o5h97gpPBuMrJZsOXUG/IHNHZGupTD5ZxJ7N4lA/u88=
|
||||
Exponent2: kUcdX5s9l6zAgkmrS6DsRc+hL7b7Ij4CWT+fH8P6dKs=
|
||||
Coefficient: PVZrElFmz9tWa4kwu9jArjcocycYu0eBycgguQ03J7w=
|
||||
Vendored
+3
@@ -11,6 +11,7 @@ SCENARIO_BEGIN Old answer is dropped from the cache
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
@@ -47,6 +48,7 @@ ENTRY_END
|
||||
; another query to force the cache to drop the example.com entry.
|
||||
STEP 11 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
ENTRY_END
|
||||
@@ -84,6 +86,7 @@ ENTRY_END
|
||||
; query, same as first, but it fell out of the cache.
|
||||
STEP 21 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
Vendored
BIN
Binary file not shown.
Vendored
BIN
Binary file not shown.
Vendored
BIN
Binary file not shown.
Vendored
BIN
Binary file not shown.
Vendored
BIN
Binary file not shown.
Vendored
BIN
Binary file not shown.
Vendored
BIN
Binary file not shown.
Vendored
+118
@@ -0,0 +1,118 @@
|
||||
; config options
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test cname followed by nxdomain reply rcode.
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.next.com. IN A
|
||||
SECTION AUTHORITY
|
||||
next.com. IN NS ns.next.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.next.com. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.next.com.
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.next.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.5
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NXDOMAIN
|
||||
SECTION QUESTION
|
||||
www.next.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.next.com.
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+159
@@ -0,0 +1,159 @@
|
||||
; config options
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test cname to nodata and if qname is set to orig after prepend
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.next.com. IN A
|
||||
SECTION AUTHORITY
|
||||
next.com. IN NS ns.next.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.next.com. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.next.com.
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.next.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.5
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
www.next.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
next.com. IN SOA next.com. next.com. 2007090400 28800 7200 604800 18000
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD CD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 3 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD CD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.next.com.
|
||||
SECTION AUTHORITY
|
||||
next.com. IN SOA next.com. next.com. 2007090400 28800 7200 604800 18000
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
; query it from cache again
|
||||
STEP 5 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
STEP 7 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.next.com.
|
||||
SECTION AUTHORITY
|
||||
next.com. IN SOA next.com. next.com. 2007090400 28800 7200 604800 18000
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
; query answer to cname from cache again, test if stored under wrong qname.
|
||||
STEP 9 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.next.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
STEP 11 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
www.next.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
next.com. IN SOA next.com. next.com. 2007090400 28800 7200 604800 18000
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+190
@@ -0,0 +1,190 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
val-override-date: "20070916134226"
|
||||
target-fetch-policy: "3 2 1 0 0" # make sure it fetches for test
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test iterator with empty delegation from cache.
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
|
||||
; sneak in some data into the cache to simulate partial data after timeouts
|
||||
example.net. NS ns.example.net.
|
||||
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qname
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
net. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
; com zone
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
; net zone
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qname
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
example.net. NS ns.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
; example.net. zone
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN A
|
||||
SECTION ANSWER
|
||||
ns.example.net. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN AAAA
|
||||
SECTION ANSWER
|
||||
ENTRY_END
|
||||
|
||||
; example.com. zone
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134802 20070829134802 2854 example.com. MCwCFG1yhRNtTEa3Eno2zhVVuy2EJX3wAhQeLyUp6+UXcpC5qGNu9tkrTEgPUg== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN A 10.20.30.40
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCQMyTjn7WWwpwAR1LlVeLpRgZGuQIUCcJDEkwAuzytTDRlYK7nIMwH1CM= ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
www.example.com. 3600 IN RRSIG A 3 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFC99iE9K5y2WNgI0gFvBWaTi9wm6AhUAoUqOpDtG5Zct+Qr9F3mSdnbc6V4= ;{id = 2854}
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN A 10.20.30.40
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
; make sure glue fetch is done.
|
||||
STEP 11 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 12 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+118
@@ -0,0 +1,118 @@
|
||||
; config options
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test lameness detection after scrubber.
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
; This server is Lame!
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR RD NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
com. 155182 IN NS a.gtld-servers.net.
|
||||
com. 155182 IN NS b.gtld-servers.net.
|
||||
com. 155182 IN NS c.gtld-servers.net.
|
||||
com. 155182 IN NS d.gtld-servers.net.
|
||||
com. 155182 IN NS e.gtld-servers.net.
|
||||
com. 155182 IN NS f.gtld-servers.net.
|
||||
com. 155182 IN NS g.gtld-servers.net.
|
||||
com. 155182 IN NS h.gtld-servers.net.
|
||||
com. 155182 IN NS i.gtld-servers.net.
|
||||
com. 155182 IN NS j.gtld-servers.net.
|
||||
com. 155182 IN NS k.gtld-servers.net.
|
||||
com. 155182 IN NS l.gtld-servers.net.
|
||||
com. 155182 IN NS m.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. 155182 IN A 192.5.6.30
|
||||
b.gtld-servers.net. 155182 IN A 192.33.14.30
|
||||
c.gtld-servers.net. 155182 IN A 192.26.92.30
|
||||
d.gtld-servers.net. 155182 IN A 192.31.80.30
|
||||
e.gtld-servers.net. 155182 IN A 192.12.94.30
|
||||
f.gtld-servers.net. 155182 IN A 192.35.51.30
|
||||
g.gtld-servers.net. 155182 IN A 192.42.93.30
|
||||
h.gtld-servers.net. 155182 IN A 192.54.112.30
|
||||
i.gtld-servers.net. 155182 IN A 192.43.172.30
|
||||
j.gtld-servers.net. 155182 IN A 192.48.79.30
|
||||
k.gtld-servers.net. 155182 IN A 192.52.178.30
|
||||
l.gtld-servers.net. 155182 IN A 192.41.162.30
|
||||
m.gtld-servers.net. 155182 IN A 192.55.83.30
|
||||
a.gtld-servers.net. 155182 IN AAAA 2001:503:a83e::2:30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursin happens here
|
||||
|
||||
; check that the answer is a failure (lame server)
|
||||
; and not a nodata-noerror message (false answer classification).
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA SERVFAIL
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+257
@@ -0,0 +1,257 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
val-override-date: "20070916134226"
|
||||
target-fetch-policy: "3 2 1 0 0" # make sure it fetches for test
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test iterator with root prime answer without glue.
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
; glue ommitted!
|
||||
;K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qname
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
K.ROOT-SERVERS.NET. IN A
|
||||
SECTION AUTHORITY
|
||||
net. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
|
||||
; sneak in some data into the cache to simulate partial data after timeouts
|
||||
example.net. NS ns.example.net.
|
||||
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qname
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
net. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
; com zone
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
; net zone
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qname
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
K.ROOT-SERVERS.NET. IN A
|
||||
SECTION AUTHORITY
|
||||
ROOT-SERVERS.NET. IN NS A.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
A.ROOT-SERVERS.NET. IN A 198.41.0.4
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qname
|
||||
ADJUST copy_id copy_query
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
example.net. NS ns.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; A.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 198.41.0.4
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
K.ROOT-SERVERS.NET. IN A
|
||||
SECTION ANSWER
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
K.ROOT-SERVERS.NET. IN AAAA
|
||||
SECTION ANSWER
|
||||
; no ip6 address: we want to use only one address for K. to avoid having
|
||||
; to duplicate the entries in this file for both addresses.
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
; example.net. zone
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN A
|
||||
SECTION ANSWER
|
||||
ns.example.net. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN AAAA
|
||||
SECTION ANSWER
|
||||
ENTRY_END
|
||||
|
||||
; example.com. zone
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134802 20070829134802 2854 example.com. MCwCFG1yhRNtTEa3Eno2zhVVuy2EJX3wAhQeLyUp6+UXcpC5qGNu9tkrTEgPUg== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN A 10.20.30.40
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCQMyTjn7WWwpwAR1LlVeLpRgZGuQIUCcJDEkwAuzytTDRlYK7nIMwH1CM= ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
www.example.com. 3600 IN RRSIG A 3 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFC99iE9K5y2WNgI0gFvBWaTi9wm6AhUAoUqOpDtG5Zct+Qr9F3mSdnbc6V4= ;{id = 2854}
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN A 10.20.30.40
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
|
||||
; make sure glue fetch is done.
|
||||
STEP 11 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 12 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
ns.example.net. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
STEP 13 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
K.ROOT-SERVERS.NET. IN AAAA
|
||||
ENTRY_END
|
||||
|
||||
STEP 14 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NOERROR
|
||||
SECTION QUESTION
|
||||
K.ROOT-SERVERS.NET. IN AAAA
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+33
@@ -0,0 +1,33 @@
|
||||
;
|
||||
; DS match test file.
|
||||
; test matching of DS hash against DNSKEYs.
|
||||
;
|
||||
; enter ENTRYs with a DS and a DNSKEY.
|
||||
; These are matched against another.
|
||||
; If the query name starts with 'yes' then it must match.
|
||||
; If the query name starts with 'no' then it must not match.
|
||||
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
yes. IN A
|
||||
SECTION ANSWER
|
||||
nlnetlabs.nl. 3600 IN DS 43791 RSASHA1 1 81ee88356df3c3077549445ed2fb1c92adc80641
|
||||
nlnetlabs.nl. DNSKEY 257 3 5 AQPzzTWMz8qSWIQlfRnPckx2BiVmkVN6LPupO3mbz7FhLSnm26n6iG9N Lby97Ji453aWZY3M5/xJBSOS2vWtco2t8C0+xeO1bc/d6ZTy32DHchpW 6rDH1vp86Ll+ha0tmwyy9QP7y2bVw5zSbFCrefk8qCUBgfHm9bHzMG1U BYtEIQ==
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
yes. IN A
|
||||
SECTION ANSWER
|
||||
jelte.nlnetlabs.nl. DS 42860 5 1 14D739EB566D2B1A5E216A0BA4D17FA9B038BE4A
|
||||
jelte.nlnetlabs.nl. 3600 IN DNSKEY 256 3 5 AQOraLfzarHAlFskVGwAGnX0LRjlcOiO6y5WM4Kz+QvZ9vX28h4lOvnf d5tkxnZm7ERLTAJoFq+1w/wl7VXs2Isz75BSZ7LQh3OT2xXnS6VT5ZxX ko/UCOdoGiKZZ63jHZ0jNSTCYy8+5rfvwRD8s3gGuErp5KcHg3V8VLUK SDNNEQ==
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
no. IN A
|
||||
SECTION ANSWER
|
||||
nlnetlabs.nl. 3600 IN DS 43791 RSASHA1 1 14D739EB566D2B1A5E216A0BA4D17FA9B038BE4A
|
||||
nlnetlabs.nl. DNSKEY 257 3 5 AQPzzTWMz8qSWIQlfRnPckx2BiVmkVN6LPupO3mbz7FhLSnm26n6iG9N Lby97Ji453aWZY3M5/xJBSOS2vWtco2t8C0+xeO1bc/d6ZTy32DHchpW 6rDH1vp86Ll+ha0tmwyy9QP7y2bVw5zSbFCrefk8qCUBgfHm9bHzMG1U BYtEIQ==
|
||||
ENTRY_END
|
||||
|
||||
Vendored
+180
@@ -0,0 +1,180 @@
|
||||
;
|
||||
; NSEC3 hash algo test file.
|
||||
; The hash cache is maintained for the duration of the file.
|
||||
; Every entry is a hash test.
|
||||
; query name is hashed.
|
||||
; answer AAAA record hash the correct hashed answer name.
|
||||
; auth NSEC3 record has the hash parameters.
|
||||
;
|
||||
|
||||
|
||||
; These are from the nsec3-draft-11 example zone.
|
||||
; H(example) = 0p9mhaveqvm6t7vbl5lop2u3t2rp3tom
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
example. IN AAAA
|
||||
SECTION ANSWER
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(a.example) = 35mthgpgcu1qg68fab165klnsnk3dpvl
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
a.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
35mthgpgcu1qg68fab165klnsnk3dpvl.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(ai.example) = gjeqe526plbf1g8mklp59enfd789njgi
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
ai.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
gjeqe526plbf1g8mklp59enfd789njgi.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(ns1.example) = 2t7b4g4vsa5smi47k61mv5bv1a22bojr
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
ns1.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
2t7b4g4vsa5smi47k61mv5bv1a22bojr.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(ns2.example) = q04jkcevqvmu85r014c7dkba38o0ji5r
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
ns2.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
q04jkcevqvmu85r014c7dkba38o0ji5r.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(w.example) = k8udemvp1j2f7eg6jebps17vp3n8i58h
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
w.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
k8udemvp1j2f7eg6jebps17vp3n8i58h.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(*.w.example) = r53bq7cc2uvmubfu5ocmm6pers9tk9en
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
*.w.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
r53bq7cc2uvmubfu5ocmm6pers9tk9en.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(x.w.example) = b4um86eghhds6nea196smvmlo4ors995
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
x.w.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
b4um86eghhds6nea196smvmlo4ors995.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(y.w.example) = ji6neoaepv8b5o6k4ev33abha8ht9fgc
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
y.w.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
ji6neoaepv8b5o6k4ev33abha8ht9fgc.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(x.y.w.example) = 2vptu5timamqttgl4luu9kg21e0aor3s
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
x.y.w.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
2vptu5timamqttgl4luu9kg21e0aor3s.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(xx.example) = t644ebqk9bibcna874givr6joj62mlhv
|
||||
; capitalization changed.
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
xX.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
t644ebqk9bibcna874givr6joj62mlhv.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
b4um86eghhds6nea196smvmlo4ors995.example. NSEC3 1 1 12 aabbccdd (gjeqe526plbf1g8mklp59enfd789njgi MX RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; H(2t7b4g4vsa5smi47k61mv5bv1a22bojr.example)
|
||||
; = kohar7mbb8dc2ce8a9qvl8hon4k53uhi
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
2t7b4g4vsa5smi47k61mv5bv1a22bojr.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
kohar7mbb8dc2ce8a9qvl8hon4k53uhi.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
b4um86eghhds6nea196smvmlo4ors995.example. NSEC3 1 1 12 aabbccdd (gjeqe526plbf1g8mklp59enfd789njgi MX RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
|
||||
|
||||
; repeat entry to test the cache.
|
||||
; H(example) = 0p9mhaveqvm6t7vbl5lop2u3t2rp3tom
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
example. IN AAAA
|
||||
SECTION ANSWER
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; repeat entry to test the cache.
|
||||
; H(a.example) = 35mthgpgcu1qg68fab165klnsnk3dpvl
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
a.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
35mthgpgcu1qg68fab165klnsnk3dpvl.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; repeat entry to test the cache.
|
||||
; H(ai.example) = gjeqe526plbf1g8mklp59enfd789njgi
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
ai.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
gjeqe526plbf1g8mklp59enfd789njgi.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
; repeat entry to test the cache.
|
||||
; capitalization of qname.
|
||||
; H(ai.example) = gjeqe526plbf1g8mklp59enfd789njgi
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
AI.example. IN AAAA
|
||||
SECTION ANSWER
|
||||
gjeqe526plbf1g8mklp59enfd789njgi.example. AAAA ::1
|
||||
SECTION AUTHORITY
|
||||
0p9mhaveqvm6t7vbl5lop2u3t2rp3tom.example. NSEC3 1 1 12 aabbccdd (2t7b4g4vsa5smi47k61mv5bv1a22bojr MX DNSKEY NS SOA NSEC3PARAM RRSIG )
|
||||
ENTRY_END
|
||||
|
||||
Vendored
+13
@@ -0,0 +1,13 @@
|
||||
; test packets for unit test
|
||||
;-- next packet --
|
||||
; test packet from nlnetlabs.nl ANY +dnssec last SRV has RRSIG first.
|
||||
|
||||
63578490000100190000000D096E6C6E65746C616273026E6C0000FF0001C00C00060001000151800028046F70656EC00C0A686F73746D6173746572C00C77A1A1BB0000708000001C2000093A8000004650C00C002E000100000E1000A00030050200000E1046E6941D46C1AA1D4706096E6C6E65746C616273026E6C00066B3C47EA4915422B5D312C4221165E01BAA2578D947B0485E01336C355EC4ED3A98BBB7BDDEE50F1DD9CB6D0F535AECB7FC1FD2ED465A416245D69652B6A5D85A441618575ACE9E8DF7EB7E8FE887CD5932D5BEB4DA166DDAA6124F7FD4115C4F0A0534E938C7DE9E77E5C37DC43E279F39C6CD893EA788E39958785C53BEDC070002E000100000E1001200030050200000E1046E6941D46C1AA1D9003096E6C6E65746C616273026E6C00B7AEBD8B1306D263E891326B3C92177676BF25E7795B837532591333E214C04096B7E420CC18C797B81F0A3FA577C364A7D4D36A1284723B3DA04CD120F94A4F07EF98FDBA07A44012BDA0C18091F8AE8FA9F2EDB5F6203664DF945FFCA8087B98823FEB0DC87470F9897A40E43D122A3C4717AF728DC7AE08B3A7CC2F56B7F7B0F9261F9DDC61A30DC06D8B73C8CE1EC2DD011034DB5AABA0A738426014BE076BB7015BA269EED5D9A9BCFEF8767A0D7B09644C50476C2EF49C10A138077EC3BDB2D75DB8AE64E766C855D108F374FD22063564A9B6
|
||||
1254931B60E0572F4CC42874387E9063748F0C828A27C85BE31183CF6F97739EAD719415FD8DD506E074C11C002E000100000E1000A00030050200000E1046E6941D46C1AA1DAB0F096E6C6E65746C616273026E6C0065258E476A661AF6EB0C7B3FB6511A9E8D96C0D86B9563DD0BD3A3FE751F25CE324AB06F7FB00584C82CC4CB293B9321A890194B0ECF1953A202FF0A172E5028D1476D0F854E0D6F14E529329ED991E5CCEE57E0D96C6E74D6F4D58823B978FAF56221F0A8DFB295E50CD20CC70A8812D5CABD6D8C02966D3FBF414F0236DE8CC2480030000100000E100086010003050103A96D8AD435A850015E7FC13089F7FC1B48CFDE57E37E8D864032620A9FA405DD9E7B07ABA981C8D51C43B216403761C22DE45CFE5AAA1D0AB0019F8A9285DEAA25847C88FDD2E9F8CDE8F569963323AE1B29FFAC95737D02E9CECFD9BFE6816662E62602E7A9647A00ECD1519F016E479A8B0A8D056860C8CEB4DA3717E30643C2480030000100000E100106010103050103BA4ED88EABBB996BCC07AD0354193DD95EE75A1A39DB76E527C8BC3D5B088311DF15CB5028E0554AEF1A84005A3817980E91D1ABE98ED7CF417E6797B501A425BE10618EE8EF2213D9E4422E34690651B45360B8555F938950731876B5E918F7721BE5754C14E6C49FFE3A651D916893D89EB0E57529498441FA9D2463019FEEEC4F3BF70336
|
||||
9EBB7C82EDC75F9D76E4B7D01ED0CA038AF9FECF78064371D068DAAB32E6B9C1B0FB0B85B129769585B3658F4D5A34206600111DE71BA599A6D8AAF0E6006F52B6D8AF22FA3F3E843C2F3510CC8D679531E6C16576CD406930B06809B08B1AA067D5393DD675E2710EEF46A8E0CCFFF9B06714EF3BB4AD6CE86DC2480030000100000E100086010103050103F3CD358CCFCA925884257D19CF724C7606256691537A2CFBA93B799BCFB1612D29E6DBA9FA886F4D2DBCBDEC98B8E77696658DCCE7FC49052392DAF5AD728DADF02D3EC5E3B56DCFDDE994F2DF60C7721A56EAB0C7D6FA7CE8B97E85AD2D9B0CB2F503FBCB66D5C39CD26C50AB79F93CA8250181F1E6F5B1F3306D54058B4421C248002E00010000025800A0002305020000025846E6941D46C1AA1D4706096E6C6E65746C616273026E6C006F0EFD5F3606CDC8501772579B48A24A3522EB2E05A6908BFC9329A63AE2D31640F05B5D26A5ED591A789A705FC54A8D61AB08399F75DCB51380CE647D078670D8330DB2F58517FC74CEF1F9636759C188B8D6FCDE3844411A1F24DA06E371DF17C70F897D1AC23EEFC1CE720E365EF4F4B852BBD25152FB0AEEAEDE0F622A58C52A00230001000002580027001400000173075349502B44325500045F736970045F756470096E6C6E65746C616273026E6C00C5DD002E00010001518000A0001C05020001518046
|
||||
E6941D46C1AA1D4706096E6C6E65746C616273026E6C00816A6DF6B45D28B9EFEDA508223F84B8EA9FDBC1122D6758E1DC9BF1379B0DE7305AF63A978EF6B4EB6920083B82A30D24A119C233905F24CFC3EB29782C650FE87699D8CAD2AFF98A790A936F11E29F44D9C0F3A5A4986475DC637AC42018A3377313BE8A3A2C59E67A0B390A4AE9647FCA295A0BE6891B616BB274AB3662C4C609001C0001000151800010200107B8020600010000000000000001C609002E00010001518000A0001005020001518046E6941D46C1AA1D4706096E6C6E65746C616273026E6C0084B11D5C675C84EFF41B5E672E297B4B7171FCF14092236ADC7B356ED4A9A67997A4F4B666C36873EDF3A800BEB4274C4277C408917621F8D380C3A3726FCBA82FF8ED46E5F07DE5AE936993640A62A3F2D2C26EB1DE93E56DE1A277128A442D7AFDEFD264856C35AD59A06A8E881B2CB7205E79805A59B2ACE1A15EDF151338C6D10010000100015180001A19537469636874696E67204E4C6E6574204C616273207A6F6E65C6D1002E00010001518000A0000F05020001518046E6941D46C1AA1D4706096E6C6E65746C616273026E6C0032FBD313E442240AD077248B87DB4CA1B8BB8AEC94B2E815293DDC93093E10E29D1920BCBF2F84244DD58FB9707C6380D171DDB1B39239305C6FDA81E0AFA8E59C4596D3774CB4939B80CA9473558D
|
||||
AA3CB31FD2E8D756F425A80CDA9EDB48A9547582F998D363D8D64E45E65EFECA8BD11B3036D2B8B1DFF0FFD0F703CE7BB6C7A3000F00010001518000040032C02AC7A3000F00010001518000110064056F6D76616C067465646E6574C7ADC7A3002E00010001518000A0000605020001518046E6941D46C1AA1D4706096E6C6E65746C616273026E6C0087059806E37D4CFEC617C733F1841B9EB5DBA3F02E7E105E9D23A9998C34F276FE032A83758FA6B4D30A540BCCB0D82AAA1903C8CDF34377712556B08A227613F40FB3A129B6205B16A377227EE682ED9D6F22069BFA24E50FD485C525DE6D1813B056F9AEF2C0CE408BBA7A3E8D9347AA648849B7896275BE6D7EC443B6E1A0C87C002E00010001518000A0000205020001518046E6941D46C1AA1D4706096E6C6E65746C616273026E6C007588829ABDACCB921070102946174422ECB1057BF9B1DF3A6A179FB03E7CA698C967FDD34EF0973142B6471B161981B0BF9EE066608744D8A60EDC873EFC8461E055915D924BC2FEBCF5DC22D1468EAD2C27D167112FEC0F3C079A91F279EC0925CE54F2AD1EA280D973584633DE119D32F16EAAD012A052D6C66690799AD1D4C92800020001000151800002C02AC92800020001000151800016036E73370F646F6D61696E2D7265676973747279C932C92800020001000151800002C84FC928002E00010001518000A0
|
||||
000105020001518046E6941D46C1AA1D4706096E6C6E65746C616273026E6C004A8FDD14D1F4655452A6C5A9321434B9A4FC73C1D63E7D30030D716AC1ABBB37E208319F2A80111D211EE6D8A47FF4084401353FD65B2F50CB6D3EC0C9593CFA53630E75AAEB483C70E9B5B754B5EAD88DDCC2B0EE8D9BA4BAC3F8643BE12A3BD9CE6051BDDE14C46CE9608B935F004C0828ECF0C7958E272F71F67DE8DDDE72CA1200010001000151800004D59AE001CA12002E00010000465000A0002F05020000465046E6941D46C1AA1D4706096E6C6E65746C616273026E6C000E85A6563F289CC81E360B46EC09C30D0B16B3E7C75DB01C6F7544594425237D38D02FCC3C304F904DE3617D195BBA1F0642C2906E1F91C8D4CC7E34903837607AC1FEE5A9F1AA22596EDEC40AAD323EC8F9845F2A17C94F266C0F30E604E1C6A38124EA2A5F87E3522A7E100E4A2B85059FDF9C2716DAC5D735CE111237F395CACE002F0001000046500021045F736970045F756470096E6C6E65746C616273026E6C00000762018008100380066A6F686E6E79CB7200010001000002580004D59AE02CC02A00010001000002580004D59AE001C02A001C0001000002580010200107B8020600010000000000000001C02A001C0001000002580010200107B8020600010000000000000053C84F00010001000070800004D59AE011C84F001C00010000
|
||||
70800010200107B802060001020039FFFE59B187C9D0000100010000FE8B00043E0456E6CB68002E00010000025800A0002105040000025846E6941D46C1AA1D4706096E6C6E65746C616273026E6C0098CEBAD0E8783AE7234B216005CD368086EAE5879C25181A0FF4533F5FE60D5E818D6B10AA5D96D57B9648CD1A530184D128AD1F04BF03316563383A85BF22F8E0E8E2551F419BEFBE849B2C6510A4471D7A285DD071511AF1AEB555A2DDBEDFE535717C1384FA130CEAC5EE86B07A61FAB69C3CEA143FC6AE5006D2152E9CFDCB89002E00010000025800A0000105030000025846E6941C46C1AA1C4706096E6C6E65746C616273026E6C00432C065713ABF3D8C9C40E1A46EF6FE49F2060689C281BACDDC98ECD06F3D354D77B2216E4EE408D080F9DF86F0F1C427B772D32EDCEE989B2AC8D76615E59E6FD11A1A963D5CEEB40F05C04CC4752A7308739B3C6C9C06A92D65522AB674AD2C27DC5DAC91044DE85A5D8126E170E515C52A642F51FB24323DEE893AF9995DCC02A002E00010000025800A0000105030000025846E6941C46C1AA1C4706096E6C6E65746C616273026E6C000EBC0704DD6A076244351A27EE61E35EA294A2E6726C919E8BF33BDF7DC97913FE54C1EAAE26624C3F852C77BA1356AF771C3AC6636A3C23DE82AB03FE9F72515E6289D18779083006FE38152773E0AD6A3E9831006B9EA6
|
||||
490EEAFE1359AC9FF23F1189E303B838C5D4F3BBDE4FDFC531F1B1095E8BB301F5F8F17C2F20B526C02A002E00010000025800A0001C05030000025846E6941C46C1AA1C4706096E6C6E65746C616273026E6C006D9C956476F8A04DE789F4439DFFB289AED649EC80320B0A68AE004FD5B39D5F3A955B18AB2DB535662B624FC36ECCBAEC421C7C3D3C2E67ADE6B284AE424974BF24CFAC9A6C3AF9541E70C4D4B8F196419D34C7686D5D95693C4C75B560E543BAED77EF343C1D14F0C5CC842757ABC86B6EC9A8C41F38AEF12B9E7886B1251ECB680021000100000258001B0000000013C4066A6F686E6E79096E6C6E65746C616273026E6C000000291000000080000000
|
||||
|
||||
Vendored
+605
@@ -0,0 +1,605 @@
|
||||
; Signature test file
|
||||
|
||||
; first entry is a DNSKEY answer, with the DNSKEY rrset used for verification.
|
||||
; later entries are verified with it.
|
||||
|
||||
|
||||
; DNSKEY used for testing, from august 2007.
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
nlnetlabs.nl. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
nlnetlabs.nl. 3600 IN DNSKEY 256 3 5 AQOpbYrUNahQAV5/wTCJ9/wbSM/eV+N+jYZAMmIKn6QF3Z57B6upgcjV HEOyFkA3YcIt5Fz+WqodCrABn4qShd6qJYR8iP3S6fjN6PVpljMjrhsp /6yVc30C6c7P2b/mgWZi5iYC56lkegDs0VGfAW5HmosKjQVoYMjOtNo3 F+MGQw==
|
||||
nlnetlabs.nl. 3600 IN DNSKEY 257 3 5 AQO6TtiOq7uZa8wHrQNUGT3ZXudaGjnbduUnyLw9WwiDEd8Vy1Ao4FVK 7xqEAFo4F5gOkdGr6Y7Xz0F+Z5e1AaQlvhBhjujvIhPZ5EIuNGkGUbRT YLhVX5OJUHMYdrXpGPdyG+V1TBTmxJ/+OmUdkWiT2J6w5XUpSYRB+p0k YwGf7uxPO/cDNp67fILtx1+dduS30B7QygOK+f7PeAZDcdBo2qsy5rnB sPsLhbEpdpWFs2WPTVo0IGYAER3nG6WZptiq8OYAb1K22K8i+j8+hDwv NRDMjWeVMebBZXbNQGkwsGgJsIsaoGfVOT3WdeJxDu9GqODM//mwZxTv O7StbOht
|
||||
nlnetlabs.nl. 3600 IN DNSKEY 257 3 5 AQPzzTWMz8qSWIQlfRnPckx2BiVmkVN6LPupO3mbz7FhLSnm26n6iG9N Lby97Ji453aWZY3M5/xJBSOS2vWtco2t8C0+xeO1bc/d6ZTy32DHchpW 6rDH1vp86Ll+ha0tmwyy9QP7y2bVw5zSbFCrefk8qCUBgfHm9bHzMG1U BYtEIQ==
|
||||
ENTRY_END
|
||||
|
||||
; first entry; the www site
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
www.nlnetlabs.nl. IN A
|
||||
SECTION ANSWER
|
||||
www.nlnetlabs.nl. 600 IN A 213.154.224.1
|
||||
www.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Luav3fjE1VGhran3tnxR93cgoEyH3Kh//240KDCT8k0U4Tfw6xSBMVjj rf3oH13SXCZfYdJYZbZEahBvysMRm40Izl4+rpfUKzwjHXn1una1o4Gt A48v0fwffCXtUPz1TDFq9IKlVe95uLwjheMF8auDXHLwLItj2lF827Dd VI0=
|
||||
SECTION AUTHORITY
|
||||
nlnetlabs.nl. 86400 IN NS ns7.domain-registry.nl.
|
||||
nlnetlabs.nl. 86400 IN NS open.nlnetlabs.nl.
|
||||
nlnetlabs.nl. 86400 IN NS omval.tednet.nl.
|
||||
nlnetlabs.nl. 86400 IN RRSIG NS 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. mXE8tSPoCvD7f6SjQ4skJi8tvbiloN5dlXNHcwufK1rREEVl8oCJ34VV cldL6tv4APj8w0PXmYOiB3xM3TIFpi33n6eqRjudKiq5906PKaj/zLEE cl+dU64+hg9VL0rsT+Fx7TWs/i+gh6oiQm6MsbG415UWUgqtZLflwmMB SC4=
|
||||
SECTION ADDITIONAL
|
||||
ns7.domain-registry.nl. 8380 IN A 62.4.86.230
|
||||
open.nlnetlabs.nl. 600 IN A 213.154.224.1
|
||||
open.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::53
|
||||
open.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::1
|
||||
omval.tednet.nl. 28800 IN A 213.154.224.17
|
||||
omval.tednet.nl. 28800 IN AAAA 2001:7b8:206:1:200:39ff:fe59:b187
|
||||
open.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. ViuIpiw1c6a0roF+XCOSFMQ3BCH/qmy+lRcU0Y8jEeoN7vLu5rJlWUuF yuuU3kAx6RFB/XDPjxNzm2OER/JJSUUeagzXSqnJVL8Orj03RGpS2PAW 5p66uf5uMv34VEednxoGoigVHKIBfpIwYIbcaXAkDaRMMpw+ylRWwWee q84=
|
||||
open.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. bcDWQYXDf6XEyNFeYeDJZTcdUCD4hbfzEIMCL1Fap4Lm6FNSvACQ8c+F F48UfJVdvSZeczDKgsHSm7nte81qYu4+lBQm5TuJcMkjgJakHumKGV0Y 17wIJAsMPiacw+NNICweKO4x4RKwNzWgcn1ymktYsiaPIJpOxQCQVJcU tlg=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
bartok.nlnetlabs.nl. IN MX
|
||||
SECTION ANSWER
|
||||
bartok.nlnetlabs.nl. 600 IN MX 50 bartok.nlnetlabs.nl.
|
||||
bartok.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
bartok.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. kPtROxDJsZMq0XF/sM6tF3MQyaWBPAKGmEdWJ1DAcKwR5GJgBCCPbL4Z poV7NtJwfs0tN+vE5IqdxRu707Px3Omoc9HUJqF7mwu+dr8R4ltMkUGH 4XJpfSty7/4Q4B7Y/BrcJbYduudi4YmwqmO0ffFDJjTjDgJGCGC/DFtE HAo=
|
||||
ENTRY_END
|
||||
|
||||
; big zone apex
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
nlnetlabs.nl. IN ANY
|
||||
SECTION ANSWER
|
||||
nlnetlabs.nl. 18000 IN NSEC _sip._udp.nlnetlabs.nl. A NS SOA MX TXT AAAA NAPTR RRSIG NSEC DNSKEY
|
||||
nlnetlabs.nl. 18000 IN RRSIG NSEC 5 2 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. RMppeajhOKtJXWq2HRFHN7fbbBVrqQwyr8uuiaSft48JpCA4QfM8/sxD ahqGOt2P5BvMqVeHz6oWPYrxpnoe9NGJBYCnQ50aipTEFohct9HTFUFu cnk2NoEizMHPWWbQOhVxXaL+sQHZhLR69DIu6KwH9SNu8Dks9V2n6Yi5 slg=
|
||||
nlnetlabs.nl. 86400 IN A 213.154.224.1
|
||||
nlnetlabs.nl. 86400 IN RRSIG A 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. mpbqSRHxv3TUo+MgzQndhWdZp0CqlOyaIPKFp2trycJ7onH63hCZ7Ixd d4sk/DhIfgzoo8HHootbsYvFCHr5oue8qgkAk9bjco7wWFt9KskturwS RS29p8+jTf4uQ0oXOad0IJo07iccpPyqVapIOHjOFwsFKG1ma7TZQRcW Sz0=
|
||||
nlnetlabs.nl. 86400 IN NS open.nlnetlabs.nl.
|
||||
nlnetlabs.nl. 86400 IN NS omval.tednet.nl.
|
||||
nlnetlabs.nl. 86400 IN NS ns7.domain-registry.nl.
|
||||
nlnetlabs.nl. 86400 IN RRSIG NS 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. mXE8tSPoCvD7f6SjQ4skJi8tvbiloN5dlXNHcwufK1rREEVl8oCJ34VV cldL6tv4APj8w0PXmYOiB3xM3TIFpi33n6eqRjudKiq5906PKaj/zLEE cl+dU64+hg9VL0rsT+Fx7TWs/i+gh6oiQm6MsbG415UWUgqtZLflwmMB SC4=
|
||||
nlnetlabs.nl. 86400 IN RRSIG SOA 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. C54bDHKC2sRbVUrDOeM2kXCHpJIFu0LlZWAFVFLf4l1Grfj+B4WcXqel kSVhi/Gpt70VW+zDEOHrS0kcE5XaBnrQE1AUZ9QjGyfjXlRzGWYbyVLD evIFrs7FdIeGKKWWp1YDLUHHF+txDT9NFu6KyEqPbZEVgIVok3skO5Vu jpA=
|
||||
nlnetlabs.nl. 86400 IN MX 100 omval.tednet.nl.
|
||||
nlnetlabs.nl. 86400 IN MX 50 open.nlnetlabs.nl.
|
||||
nlnetlabs.nl. 86400 IN RRSIG MX 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. o9l0WEH53WBdFd+3PE5UHN8kAJVFDb60DcES9oWlBOVwsBMqeTU7eDQr o+wlq1AlUYC+PlFb/W1vLdWN6eCJ//4iPxFJhKoElUEFR+ICPYIIZcD9 VLJM3i4FVsqUwcfgHdOcafciMpMeCgYutxbQDoOwDPe5o+jbynu3gq9a PQ4=
|
||||
nlnetlabs.nl. 86400 IN TXT "Stichting NLnet Labs zone"
|
||||
nlnetlabs.nl. 86400 IN RRSIG TXT 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. lSeFN/S4BATNoC5DG2fYtdSGkC5yxIwOxMH3rChYurB/bD3M4435ySKS Z+vHjLbXQqPtlXw1Jt5ZcVZujRhBM6kEmYZ2XwvC0rPZF0wMtz9nFhxK oc+seBSuP0R9GkbJZReho+JwAYh4F7EC/RQVbHylE1lPAQUHtxCGjmlV EAg=
|
||||
nlnetlabs.nl. 86400 IN AAAA 2001:7b8:206:1::1
|
||||
nlnetlabs.nl. 86400 IN RRSIG AAAA 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. KGGDcoOAmCby+/xrK7f1b/t/evXfwWgm39VVzE/xButUtPzXv+0htDgO jtUMmouO3GWicIU3fGCffDBCdOmdIrMffjvrR0lKmQAC5JwWPt2FNF/F K7dKh+KrRMp2ruqucpajfvwShWnfesEWaTYWNox1/saLjsw1NXiQ6h+0 2bc=
|
||||
nlnetlabs.nl. 600 IN NAPTR 20 0 "s" "SIP+D2U" "" _sip._udp.nlnetlabs.nl.
|
||||
nlnetlabs.nl. 600 IN RRSIG NAPTR 5 2 600 20070912141341 20070815141341 18182 nlnetlabs.nl. cxgMuZWTVJEagjnERLGjnPNZ7JKuyfe3o1gkkjoS1sg+AQb/8nUEKO/A tIoAwqPHWyALjlbOf25mWEIWviYVVt9TDn6d8k4saWNgTdnnCS+Kc5sM fV/Wz0Np/eQRZElBN0fP4QSBv0rk1VjqK1FHnFpSYz/zRV7FqDSQE1nQ 64w=
|
||||
nlnetlabs.nl. 3600 IN DNSKEY 257 3 5 AQO6TtiOq7uZa8wHrQNUGT3ZXudaGjnbduUnyLw9WwiDEd8Vy1Ao4FVK 7xqEAFo4F5gOkdGr6Y7Xz0F+Z5e1AaQlvhBhjujvIhPZ5EIuNGkGUbRT YLhVX5OJUHMYdrXpGPdyG+V1TBTmxJ/+OmUdkWiT2J6w5XUpSYRB+p0k YwGf7uxPO/cDNp67fILtx1+dduS30B7QygOK+f7PeAZDcdBo2qsy5rnB sPsLhbEpdpWFs2WPTVo0IGYAER3nG6WZptiq8OYAb1K22K8i+j8+hDwv NRDMjWeVMebBZXbNQGkwsGgJsIsaoGfVOT3WdeJxDu9GqODM//mwZxTv O7StbOht
|
||||
nlnetlabs.nl. 3600 IN DNSKEY 257 3 5 AQPzzTWMz8qSWIQlfRnPckx2BiVmkVN6LPupO3mbz7FhLSnm26n6iG9N Lby97Ji453aWZY3M5/xJBSOS2vWtco2t8C0+xeO1bc/d6ZTy32DHchpW 6rDH1vp86Ll+ha0tmwyy9QP7y2bVw5zSbFCrefk8qCUBgfHm9bHzMG1U BYtEIQ==
|
||||
nlnetlabs.nl. 3600 IN DNSKEY 256 3 5 AQOpbYrUNahQAV5/wTCJ9/wbSM/eV+N+jYZAMmIKn6QF3Z57B6upgcjV HEOyFkA3YcIt5Fz+WqodCrABn4qShd6qJYR8iP3S6fjN6PVpljMjrhsp /6yVc30C6c7P2b/mgWZi5iYC56lkegDs0VGfAW5HmosKjQVoYMjOtNo3 F+MGQw==
|
||||
nlnetlabs.nl. 3600 IN RRSIG DNSKEY 5 2 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. foMQGGiev3Lys1fGMfYiHCHnqE9IIzpOFsXECGmT2kPHCRvXWDRcAGMu DWWfCQBPcAlDLZBKCvpUhp/H/VSLS+EA6wonPWN2dS20cDuPWKm3QsHo 6+wQmw7y5t/ejsd+i370dUTjgT40T5bR6nvXZkOLN0DJvaLk7USDRvRg BNU=
|
||||
nlnetlabs.nl. 3600 IN RRSIG DNSKEY 5 2 3600 20070912141341 20070815141341 36867 nlnetlabs.nl. hw0alVZsoFJqe+u4Meg2VMJ9acbLa85V65RvEAB6RDOqXvaYBhok3kNJ HGR4zq+FYC7i4EKczT7HVKdLtxL9QGt0rzVPq++tcE85861kAgHcLpB9 Iml8QkR7dRER/FpQ1t15gTxoGg6ctlNLfDM6j0x5+S144Rg7gAm1YODB VfL5gSML385EVo2nX7Jiv/Rz1Y6shJ5SzmXnkARqhrJDhQE/Tuf2N+HY sCNatrAv3aNwN0P7a+c99qd5esIb/WVt8eR7cx9Z46nO9GV8HOvfeYxh nMnhlQ/Oy+yG2s2FnJMpD9B4m4WS/m/lBR4pyxHvZR2PQ+/drlJ+oRUS Jt4yhw==
|
||||
nlnetlabs.nl. 3600 IN RRSIG DNSKEY 5 2 3600 20070912141341 20070815141341 43791 nlnetlabs.nl. uykSWt5yfpz/IN2jKEO+XPtCj9KBFuNWz7vIk+HvEDd+KhXp7vpjISvC tI/xK6yRCeTBIbX6uxR8VRsWEtoKuWwXWHhNmpPBWTGdDuguHOLiuGBn NBUSiTPhideDW8qx/cir6I1MtqypHjEr2w9dn21xdYZbieNXpdZWDLQl ufw=
|
||||
nlnetlabs.nl. 86400 IN SOA open.nlnetlabs.nl. hostmaster.nlnetlabs.nl. 2007081501 28800 7200 604800 18000
|
||||
SECTION ADDITIONAL
|
||||
ns7.domain-registry.nl. 8295 IN A 62.4.86.230
|
||||
open.nlnetlabs.nl. 600 IN A 213.154.224.1
|
||||
open.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::53
|
||||
open.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::1
|
||||
omval.tednet.nl. 28800 IN A 213.154.224.17
|
||||
omval.tednet.nl. 28800 IN AAAA 2001:7b8:206:1:200:39ff:fe59:b187
|
||||
johnny.nlnetlabs.nl. 600 IN A 213.154.224.44
|
||||
open.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. ViuIpiw1c6a0roF+XCOSFMQ3BCH/qmy+lRcU0Y8jEeoN7vLu5rJlWUuF yuuU3kAx6RFB/XDPjxNzm2OER/JJSUUeagzXSqnJVL8Orj03RGpS2PAW 5p66uf5uMv34VEednxoGoigVHKIBfpIwYIbcaXAkDaRMMpw+ylRWwWee q84=
|
||||
open.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. bcDWQYXDf6XEyNFeYeDJZTcdUCD4hbfzEIMCL1Fap4Lm6FNSvACQ8c+F F48UfJVdvSZeczDKgsHSm7nte81qYu4+lBQm5TuJcMkjgJakHumKGV0Y 17wIJAsMPiacw+NNICweKO4x4RKwNzWgcn1ymktYsiaPIJpOxQCQVJcU tlg=
|
||||
_sip._udp.nlnetlabs.nl. 600 IN RRSIG SRV 5 4 600 20070912141341 20070815141341 18182 nlnetlabs.nl. ON/hEJ3zq5J7QUKEMT7mDY8Jj++cYCpTJoFfR/XjWC+JxQuQ5kA5HHoI kI6kABBVK+/6Npz1wof3ELQxvz3IU1jxVn2gwwofC2BNcf+MKRw6aSwc BKcDWRsrQwtMRABwZ63ixobXIUOr/NWBoRODrKQ+61ntPFmwHHCFmfwR YJ0=
|
||||
johnny.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. EJAy5kI3QxNNABLIw/asxL2LjCMshjnWMNyUeu1pRd7KM3QQUDygnw+c 50MpE1y4X8LkBXDizazoUXPsqEGhq+fzGeFEhdB0DqrxVXtyQ3ikHa+d oVp2jdGiI5zl3yWBlxr4GtLr59jIB0ZU1sL5F0voBIAGv2i6PqArRswr HBI=
|
||||
_sip._udp.nlnetlabs.nl. 600 IN SRV 0 0 5060 johnny.nlnetlabs.nl.
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
nlnetlabs.nl. IN AXFR
|
||||
SECTION ANSWER
|
||||
; <<>> DiG 9.4.1-P1 <<>> @open.nlnetlabs.nl. nlnetlabs.nl. AXFR
|
||||
; (3 servers found)
|
||||
;; global options: printcmd
|
||||
nlnetlabs.nl. 86400 IN SOA open.nlnetlabs.nl. hostmaster.nlnetlabs.nl. 2007081501 28800 7200 604800 18000
|
||||
nlnetlabs.nl. 18000 IN NSEC _sip._udp.nlnetlabs.nl. A NS SOA MX TXT AAAA NAPTR RRSIG NSEC DNSKEY
|
||||
nlnetlabs.nl. 18000 IN RRSIG NSEC 5 2 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. RMppeajhOKtJXWq2HRFHN7fbbBVrqQwyr8uuiaSft48JpCA4QfM8/sxD ahqGOt2P5BvMqVeHz6oWPYrxpnoe9NGJBYCnQ50aipTEFohct9HTFUFu cnk2NoEizMHPWWbQOhVxXaL+sQHZhLR69DIu6KwH9SNu8Dks9V2n6Yi5 slg=
|
||||
nlnetlabs.nl. 86400 IN A 213.154.224.1
|
||||
nlnetlabs.nl. 86400 IN RRSIG A 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. mpbqSRHxv3TUo+MgzQndhWdZp0CqlOyaIPKFp2trycJ7onH63hCZ7Ixd d4sk/DhIfgzoo8HHootbsYvFCHr5oue8qgkAk9bjco7wWFt9KskturwS RS29p8+jTf4uQ0oXOad0IJo07iccpPyqVapIOHjOFwsFKG1ma7TZQRcW Sz0=
|
||||
nlnetlabs.nl. 86400 IN NS ns7.domain-registry.nl.
|
||||
nlnetlabs.nl. 86400 IN NS open.nlnetlabs.nl.
|
||||
nlnetlabs.nl. 86400 IN NS omval.tednet.nl.
|
||||
nlnetlabs.nl. 86400 IN RRSIG NS 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. mXE8tSPoCvD7f6SjQ4skJi8tvbiloN5dlXNHcwufK1rREEVl8oCJ34VV cldL6tv4APj8w0PXmYOiB3xM3TIFpi33n6eqRjudKiq5906PKaj/zLEE cl+dU64+hg9VL0rsT+Fx7TWs/i+gh6oiQm6MsbG415UWUgqtZLflwmMB SC4=
|
||||
nlnetlabs.nl. 86400 IN RRSIG SOA 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. C54bDHKC2sRbVUrDOeM2kXCHpJIFu0LlZWAFVFLf4l1Grfj+B4WcXqel kSVhi/Gpt70VW+zDEOHrS0kcE5XaBnrQE1AUZ9QjGyfjXlRzGWYbyVLD evIFrs7FdIeGKKWWp1YDLUHHF+txDT9NFu6KyEqPbZEVgIVok3skO5Vu jpA=
|
||||
nlnetlabs.nl. 86400 IN MX 50 open.nlnetlabs.nl.
|
||||
nlnetlabs.nl. 86400 IN MX 100 omval.tednet.nl.
|
||||
nlnetlabs.nl. 86400 IN RRSIG MX 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. o9l0WEH53WBdFd+3PE5UHN8kAJVFDb60DcES9oWlBOVwsBMqeTU7eDQr o+wlq1AlUYC+PlFb/W1vLdWN6eCJ//4iPxFJhKoElUEFR+ICPYIIZcD9 VLJM3i4FVsqUwcfgHdOcafciMpMeCgYutxbQDoOwDPe5o+jbynu3gq9a PQ4=
|
||||
nlnetlabs.nl. 86400 IN TXT "Stichting NLnet Labs zone"
|
||||
nlnetlabs.nl. 86400 IN RRSIG TXT 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. lSeFN/S4BATNoC5DG2fYtdSGkC5yxIwOxMH3rChYurB/bD3M4435ySKS Z+vHjLbXQqPtlXw1Jt5ZcVZujRhBM6kEmYZ2XwvC0rPZF0wMtz9nFhxK oc+seBSuP0R9GkbJZReho+JwAYh4F7EC/RQVbHylE1lPAQUHtxCGjmlV EAg=
|
||||
nlnetlabs.nl. 86400 IN AAAA 2001:7b8:206:1::1
|
||||
nlnetlabs.nl. 86400 IN RRSIG AAAA 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. KGGDcoOAmCby+/xrK7f1b/t/evXfwWgm39VVzE/xButUtPzXv+0htDgO jtUMmouO3GWicIU3fGCffDBCdOmdIrMffjvrR0lKmQAC5JwWPt2FNF/F K7dKh+KrRMp2ruqucpajfvwShWnfesEWaTYWNox1/saLjsw1NXiQ6h+0 2bc=
|
||||
nlnetlabs.nl. 600 IN NAPTR 20 0 "s" "SIP+D2U" "" _sip._udp.nlnetlabs.nl.
|
||||
nlnetlabs.nl. 600 IN RRSIG NAPTR 5 2 600 20070912141341 20070815141341 18182 nlnetlabs.nl. cxgMuZWTVJEagjnERLGjnPNZ7JKuyfe3o1gkkjoS1sg+AQb/8nUEKO/A tIoAwqPHWyALjlbOf25mWEIWviYVVt9TDn6d8k4saWNgTdnnCS+Kc5sM fV/Wz0Np/eQRZElBN0fP4QSBv0rk1VjqK1FHnFpSYz/zRV7FqDSQE1nQ 64w=
|
||||
nlnetlabs.nl. 3600 IN DNSKEY 256 3 5 AQOpbYrUNahQAV5/wTCJ9/wbSM/eV+N+jYZAMmIKn6QF3Z57B6upgcjV HEOyFkA3YcIt5Fz+WqodCrABn4qShd6qJYR8iP3S6fjN6PVpljMjrhsp /6yVc30C6c7P2b/mgWZi5iYC56lkegDs0VGfAW5HmosKjQVoYMjOtNo3 F+MGQw==
|
||||
nlnetlabs.nl. 3600 IN DNSKEY 257 3 5 AQO6TtiOq7uZa8wHrQNUGT3ZXudaGjnbduUnyLw9WwiDEd8Vy1Ao4FVK 7xqEAFo4F5gOkdGr6Y7Xz0F+Z5e1AaQlvhBhjujvIhPZ5EIuNGkGUbRT YLhVX5OJUHMYdrXpGPdyG+V1TBTmxJ/+OmUdkWiT2J6w5XUpSYRB+p0k YwGf7uxPO/cDNp67fILtx1+dduS30B7QygOK+f7PeAZDcdBo2qsy5rnB sPsLhbEpdpWFs2WPTVo0IGYAER3nG6WZptiq8OYAb1K22K8i+j8+hDwv NRDMjWeVMebBZXbNQGkwsGgJsIsaoGfVOT3WdeJxDu9GqODM//mwZxTv O7StbOht
|
||||
nlnetlabs.nl. 3600 IN DNSKEY 257 3 5 AQPzzTWMz8qSWIQlfRnPckx2BiVmkVN6LPupO3mbz7FhLSnm26n6iG9N Lby97Ji453aWZY3M5/xJBSOS2vWtco2t8C0+xeO1bc/d6ZTy32DHchpW 6rDH1vp86Ll+ha0tmwyy9QP7y2bVw5zSbFCrefk8qCUBgfHm9bHzMG1U BYtEIQ==
|
||||
nlnetlabs.nl. 3600 IN RRSIG DNSKEY 5 2 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. foMQGGiev3Lys1fGMfYiHCHnqE9IIzpOFsXECGmT2kPHCRvXWDRcAGMu DWWfCQBPcAlDLZBKCvpUhp/H/VSLS+EA6wonPWN2dS20cDuPWKm3QsHo 6+wQmw7y5t/ejsd+i370dUTjgT40T5bR6nvXZkOLN0DJvaLk7USDRvRg BNU=
|
||||
nlnetlabs.nl. 3600 IN RRSIG DNSKEY 5 2 3600 20070912141341 20070815141341 36867 nlnetlabs.nl. hw0alVZsoFJqe+u4Meg2VMJ9acbLa85V65RvEAB6RDOqXvaYBhok3kNJ HGR4zq+FYC7i4EKczT7HVKdLtxL9QGt0rzVPq++tcE85861kAgHcLpB9 Iml8QkR7dRER/FpQ1t15gTxoGg6ctlNLfDM6j0x5+S144Rg7gAm1YODB VfL5gSML385EVo2nX7Jiv/Rz1Y6shJ5SzmXnkARqhrJDhQE/Tuf2N+HY sCNatrAv3aNwN0P7a+c99qd5esIb/WVt8eR7cx9Z46nO9GV8HOvfeYxh nMnhlQ/Oy+yG2s2FnJMpD9B4m4WS/m/lBR4pyxHvZR2PQ+/drlJ+oRUS Jt4yhw==
|
||||
nlnetlabs.nl. 3600 IN RRSIG DNSKEY 5 2 3600 20070912141341 20070815141341 43791 nlnetlabs.nl. uykSWt5yfpz/IN2jKEO+XPtCj9KBFuNWz7vIk+HvEDd+KhXp7vpjISvC tI/xK6yRCeTBIbX6uxR8VRsWEtoKuWwXWHhNmpPBWTGdDuguHOLiuGBn NBUSiTPhideDW8qx/cir6I1MtqypHjEr2w9dn21xdYZbieNXpdZWDLQl ufw=
|
||||
_sip._udp.nlnetlabs.nl. 18000 IN NSEC alpha.nlnetlabs.nl. SRV
|
||||
_sip._udp.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 4 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. R0Mg9z4VQHtZXK3xcv3SOZLlibfhJ4nCXURBzvDSn2C3eI1UHvOdbeZ/ B7L7/1aVlho2kHFwjkPI0wGdTSyPqlc3tSHh9Kr+EuMw2wiqtjKqzROF 9hofI/V/PKYCQGBS31e6Dq2Mi5pfeHfxAaBQ8HoFVyLBvj7Xc33aRXGE DaI=
|
||||
_sip._udp.nlnetlabs.nl. 600 IN SRV 0 0 5060 johnny.nlnetlabs.nl.
|
||||
_sip._udp.nlnetlabs.nl. 600 IN RRSIG SRV 5 4 600 20070912141341 20070815141341 18182 nlnetlabs.nl. ON/hEJ3zq5J7QUKEMT7mDY8Jj++cYCpTJoFfR/XjWC+JxQuQ5kA5HHoI kI6kABBVK+/6Npz1wof3ELQxvz3IU1jxVn2gwwofC2BNcf+MKRw6aSwc BKcDWRsrQwtMRABwZ63ixobXIUOr/NWBoRODrKQ+61ntPFmwHHCFmfwR YJ0=
|
||||
alpha.nlnetlabs.nl. 18000 IN NSEC asus-ap.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
alpha.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. ntDts9XbX6LamoCEkr7nsEBtqC8PMjsbrXmoZUDggDRKIjAjaqRt3tfy 2QdTdVYcPtG1Tj53RqAXGFfIn3+BfpSvkLELO9qIcIFvmaX+wZr458PV okltp9fX8rm2rirspNlHPNCuZBYVWb9gIRJkg64wnDFC31ERqqF+GS8/ iyo=
|
||||
alpha.nlnetlabs.nl. 600 IN A 213.154.224.59
|
||||
alpha.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Hu76XqcNZI3IjJT6DwIisVWXhGFP3MCYUTH2XHGwpGF9mQOHX+Jbk7NO k88mwZ9CM3ZNLrDWGu1Z8qhd1ZfgvpxAXshqGBvKhne7Rvf/CopP4XWx QEKcA3Zy5EYUo8J+UBJVm/l5cURlDyj3skqBb+inFpL+FysLKRcQx2E5 Mg0=
|
||||
alpha.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
alpha.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
alpha.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. YK+H+ugme14+K8H8zdXcB96wI8gNXloKW1IJVBgjzzAwGooqxRM6LEXt jfD9F+ZA8wn0HnB58a/CZ9S/24+grfdTRjUdeTEl8Cbk0ZR5tqVUFLJt MZSXAKczyXWGXZnCn6htGy6diHm+SL0S2Agr/JhsGBBxSX22tTKcoI+i CxA=
|
||||
alpha.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:202:44ff:fe41:b898
|
||||
alpha.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. DtljNKbGwkLs+LtvDeRQEXBUTg/TGFjRdrkxp7HEfx/N6n7fWiRgvzo7 va1py1cc+EMxBO6zC2hegCVS5c1lRjwYuIoA1lSfclkZLQFwwJTfyFVe M/Iq2mE0bbPoJhQ6RAhivD+5Yb9JCqRcKM4B2zlAV2LGKlhwMD/Cq8u3 IB8=
|
||||
asus-ap.nlnetlabs.nl. 18000 IN NSEC bartok.nlnetlabs.nl. A RRSIG NSEC
|
||||
asus-ap.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. bCWeNq/W0loWFRQpKPO2bJT6XsEmjfwdP7X8Iz2aIXmHXmfMyNTpFEJH 26vcJJ8D/hMC8zDAKutHWRdcFPwJp+bCg3HJqemLdvzpdSlcGcC/hmr4 zCVLVNWYK/Q/Vq7/cbVWoJTYwVEarwwwATK+Hu3YZFMPOmxoWoHVPaoN bys=
|
||||
asus-ap.nlnetlabs.nl. 600 IN A 213.154.224.63
|
||||
asus-ap.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. PQFBpiGWor6itylbCSIiowF0iTTGbmS1JyH4Yh2tUsexqlWNSJVvIiL5 EYqdttTSRGGDHkYFas8MN6CWXCvTUAAzAyDHOomHr3qt76n5bPpWXNlQ atz+Q2j+n9sqSrqiFYQ2ubAIyclsMetdRNtZxZvo+0Dqcyn42O6cx+0c L6o=
|
||||
bartok.nlnetlabs.nl. 18000 IN NSEC dhcp-01.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
bartok.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. Q7VfSibMW/aRxye7XKj1mxq9tT3b76H7PNuqNWmvQplA05Ad4mlBGrnN +THcTIv1ymE0pWzDR94LQkmQZabCzFpP5cwRqoVb5TwLgJBwWIxQeVMp zzFQ43+jYhlpiPnmzrtBMmG+js0gDPDa4446mMDFp9BapJEG1TYg2Mzl 7oQ=
|
||||
bartok.nlnetlabs.nl. 600 IN A 213.154.224.50
|
||||
bartok.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. J26AYtIbdOrZdLxKSp65MOdbIcMmx+Cty8l9Z0HlsiamAYovhhWWh39+ HqO6H2sJiGXT8dPBrQvvRNbtbLWi2c02WRAtGZt1GFolLIvkgVPGjd0y 0eLJXikN9L7W4j5nspTRBe6GOWIatCg1NwHM7VWNFEsUSZJVNVxBmIVi Dao=
|
||||
bartok.nlnetlabs.nl. 600 IN MX 50 bartok.nlnetlabs.nl.
|
||||
bartok.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
bartok.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. kPtROxDJsZMq0XF/sM6tF3MQyaWBPAKGmEdWJ1DAcKwR5GJgBCCPbL4Z poV7NtJwfs0tN+vE5IqdxRu707Px3Omoc9HUJqF7mwu+dr8R4ltMkUGH 4XJpfSty7/4Q4B7Y/BrcJbYduudi4YmwqmO0ffFDJjTjDgJGCGC/DFtE HAo=
|
||||
bartok.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:216:76ff:feb8:3c02
|
||||
bartok.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. HKozneYfqXBLk/3VIcSTDGY3jb3fqQfjvl2yKN3rTkYUrewI5EwSMo4p kXfkCZOvhu24UTuPNjJClCa2eDmuCOJ6uRfHprnF5zVEDOXYdibYSF6Q VAHEi7hzKdJVzk+Fg3BYdxkjzx2kq8jCSF7LAMQ7z1I7eJbpRZ/ORafC aHE=
|
||||
dhcp-01.nlnetlabs.nl. 18000 IN NSEC dhcp-02.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-01.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. BhWsjNlZlugg3KMFyaCTK+jX3JXiRsGA7KdKWvP/lvFkBS1nSI4dwwej omkDGiNWa90NGZiBx8A41eqykM9SJNi/+57K6jEKI8X/A1CngK1HxyyS JZyU2sbdSqV7MVERfnd5i7ZbThS5M90G/C2Dr5tJ0pMUJ9mwr1PN7mbj jlw=
|
||||
dhcp-01.nlnetlabs.nl. 3600 IN A 213.154.224.64
|
||||
dhcp-01.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. Q/uN5lccCVcHi/BW3QL7HbQFSjw+9y3kFy00WCxo52ydjo91bPLME3e3 e988ajyZDWDp9BGmIe6lYjXaVpbzB5semGmlpX6ZKw9Ngq8BVVvCIfcN QLEsqzFsnQCa0wrRXqTeBsGa/msU3y09UJOpMBvVndUxjpX7liAMz5Up Iug=
|
||||
dhcp-02.nlnetlabs.nl. 18000 IN NSEC dhcp-03.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-02.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. h0JZ2yT+qAnoZc8C5x/7F063grW9x9nIyY1yHVhLHknwcJ0i7CA662jA FxdsEpj7r9oUrJKZEBC/txzeAb//mOM6Dt7xaQWL2JaqmGjRaIVhUX7g zmGTXqGxNr8+SSLwe8+D6h+FJHXirO495bk6fpa2AQNxlraCROV7IdFW Sik=
|
||||
dhcp-02.nlnetlabs.nl. 3600 IN A 213.154.224.65
|
||||
dhcp-02.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. B08kP1Sw3I2JGN9gZ2WOvmo5Kg0dE/9Hu3zyoiJei2Ed8iNnl7G1snYI bBlWqvsbdqxlcwuV5wcwbkgmXsHQbvuSLjShKTyoJglqdMI3etKsseDT 2kBZsxvarrk4fXVlvTI0ICm35tKEgBKT+Nw87z+ZSd/a4zpIToLVIQv4 rio=
|
||||
dhcp-03.nlnetlabs.nl. 18000 IN NSEC dhcp-04.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-03.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. c4G82wM8U9YX0ESAPFfjosrPTivw/6Mbqq+DtqP76tLG2Ukm5xxth81w HgUDiOVegTQpJbaHXdwJL2gjzTsN3WTdn+5/ivGUSdH7SUiIkcge2MGZ Oz0Q/iCvDs/1ftDYW9SWaizuNay5Uyg15LCasf4UrVam5JcQtidGiBif l3g=
|
||||
dhcp-03.nlnetlabs.nl. 3600 IN A 213.154.224.66
|
||||
dhcp-03.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. bTv4qvtUqco993fs4Oak+BmAU8CyQhk5XUBXoKzXYN4T8Fto5bFUkYi4 tzlzKzNxQpMpKww5uNPBOjxpyi1fBZDt+qZqrGzFiQ6+sq4G1x8qJ7fm h6/wW2QGYNR7A9j9VGmDmlGL9dOwXkNBGuKVPfD8n6GFF1FJ6HNJLqr5 n1U=
|
||||
dhcp-04.nlnetlabs.nl. 18000 IN NSEC dhcp-05.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-04.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. ZquGGtHlQKK+D3CUAsWPPK/pyjtR7QBrrs4OTtEFhzJpkvm6kpYi6Gtf TtMy4M8LFFyslQaMsJM63ByzEf2LjNx3vUjgi80vbl4/dZhBDcegaBcB QBUZ3BUdDihfmjoZk/GvT4ddKoU5l8xGhbeG3qKsfNrA5VWVe51UgwiY dpo=
|
||||
dhcp-04.nlnetlabs.nl. 3600 IN A 213.154.224.67
|
||||
dhcp-04.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. p34f8rWzYb5wQUsk20o+vWv3FfdJ/mbjVoK5zP6WZTIKUMxTAiXihLwB yhgQlOvJKJFT6Q/AZPC55lleZ5h0hE43P6S/9Q9rWRZVUJtrCAqy9xo2 QvRcsM/8VHR8ziehErSGHCSFdsiT6ANNMuO3FC5hBSRLrE8KHO5Aujum 0mg=
|
||||
dhcp-05.nlnetlabs.nl. 18000 IN NSEC dhcp-06.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-05.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. fx9KvvNQgkNrk0cbOJGqUAXIKSKLaS/u3zmdaKKEVJH+Xy2UpX1vGHgF WSgg6Cx8vuYu02yRMBv/PJwI5gg5flAXVfP1+GsT6Zd4c+fapUV6BPFc 7YNANu3eRv1kdjwEVZlKVmmZU9TL6oef+RSXZXiF3Zn8n+Cv+fwRIbGg +0I=
|
||||
dhcp-05.nlnetlabs.nl. 3600 IN A 213.154.224.68
|
||||
dhcp-05.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. GHUlG1mfvwOPXrgY8pUBAtDj+InxjGRUnilnnhdeYnpB9ioNgNAmYMtG peRjGl8I6TgC2pYySkIP4kXHBG+KU/BrwcNyHNTjwCtfkWRD5em3nUMX SAlbh10ArTwtDBPuNLL/JVXQlVnXFqWdzONRH7coi0CQmE9Pd0HIdDe8 L1c=
|
||||
dhcp-06.nlnetlabs.nl. 18000 IN NSEC dhcp-07.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-06.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. DQcSwxeQL1yAZyxeA0JlRRVgy7NPTvwg8Jblv4eSCj/+hC7MWCNnS7uw syCqo06hxK9cDTppyeiBWFig1+Dd+dSJQF4P8NxEgmLLh2TWXEvPPgFy cd/D4C+Dvra0nuu1QWoEJP/oQrHoxGMiRz5b591XB+MOyfNOXTYw7YEg Qus=
|
||||
dhcp-06.nlnetlabs.nl. 3600 IN A 213.154.224.69
|
||||
dhcp-06.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. N7ETvKemqDEOlcFfL21Un+IXT+cYrANIGOwnw9EZC2V/qyRVU0m2WlGB T6VgCOZyBAL5D7tEEqBHlWwTqdzstL4R05xlrgwcXuIehMlKhk5NJd+H t8lFw5jWSPhAeL5/8AM7fKV2gubV2W219ogzuvirIMfOtzf4hyXOsxTb 03Y=
|
||||
dhcp-07.nlnetlabs.nl. 18000 IN NSEC dhcp-08.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-07.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. KNII0C76+CbI1nrRS+TcRYpKfr2jNZ4K1dv9KhGPSV74p4X/HlPD3gn4 B2Gyj7kHGP1t8AkIbhpW1PpT1r3AslXkNoI843/P5XcOIQch4xtgXup5 xMp3gm/WQNOK00zrE8DgL/qnl+zVZBjKYPivuCOse9f5uP+2BAc/F09r fEQ=
|
||||
dhcp-07.nlnetlabs.nl. 3600 IN A 213.154.224.70
|
||||
dhcp-07.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. E4Y9q8xhxzaMHYz9z/2zJm/9GA0mMBIpJENQPOEYTuHA6z17/MZumBym NpuQKmPm89qNIKcSUT3E2Yn/iayPZ7g3B4O6He8FJbv5ZlPXhb+/nZiT POd3gmUGtrGxmmF47u7c+KcMgM8eNS7zLAwHfGYihjbgsW0riTxjzlko 08k=
|
||||
dhcp-08.nlnetlabs.nl. 18000 IN NSEC dhcp-09.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-08.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. DWcPcqjgKVIXnko5DR2uwWDHX2nkp66TY1pcZDKVRCxt1dYO/b28CSHB 7Fnr8J5/fwtV5XKriw4VShk5azAphWke+XA3SCWNUmJ7cK0Rc6XcszwJ 02bHFSHMrfT6uxM6qUSOXJBqoHkhw2clVaeIXJSpmYpFsAF5kgLajOz0 yxM=
|
||||
dhcp-08.nlnetlabs.nl. 3600 IN A 213.154.224.71
|
||||
dhcp-08.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. UTP/kGB7yZyh8aRFgomdLQHVGoRU6rn9HuoH1Tbcvu8++MmicoeYyXrs ei6W6lVHsZLjVAnWqistb8NAsHeS1MMy0cYHDqFe+NQl1osk6c+lmXu5 VxRG79J8CLXHR3Nr23HPWFLjZ0RRyrRykQsjdpgBlcydnfRgZ3JrXyXw GoI=
|
||||
dhcp-09.nlnetlabs.nl. 18000 IN NSEC dhcp-10.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-09.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. luSV2RpmFyjniakKkCo9sY4ZqgAOIo2k3fWmsZeIKEt7C2XD8bKyVO6v iL/55qSbd8p+xs/W6fvWtoDmlgrVk+e1E47UIu7uthbV/nLCyskwM2y4 ZX9VW/yC5WEgG/bzCKH1AY/ucLdYH4b/hD5IDyhM62ZXAqk/umj5zR27 bQA=
|
||||
dhcp-09.nlnetlabs.nl. 3600 IN A 213.154.224.72
|
||||
dhcp-09.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. pjayjQAL8C2DUDJSSLxT2WaVbcRAObAGU7MCEQO+KK6jnbKpXM1lzVuC NFy6z0MqyjjcRv6bsBqLW22XJicJ8uEJxqGKD/w3RUF1mXaGVKj07z/G DpAH/ZuPeVWrlXrszLEuqXKeFd+UMvWc+0Wmfyu+SbAySmEeBhT0UqUM 2L4=
|
||||
dhcp-10.nlnetlabs.nl. 3600 IN A 213.154.224.73
|
||||
dhcp-10.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. A6M/86z7t0FHkSboB/cXkzI4LduR7WYWhMHk/gPOVlWJkVtz6tl/MOaW PIC1Ls7e6qMdNLZpoKxsUUSnjYplurZXOPsi5rR96gWCuR4IRy2Lq+Fu IuVATPhXeKwexSwxDe2A0Ah1RdcTGQRxA763d2tsxenSbmRgSWZRwO/b SnY=
|
||||
dhcp-10.nlnetlabs.nl. 18000 IN NSEC dhcp-11.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-10.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. jKRrUspeXbc+oMTAZxt8C5TLK1PogrPcgIa02XykMJ5r1t/laYI5oXry tWj2S1l41zfNopBmSBGwysDZk67k41lj5Z4Hn9ytLsYzKCaOuOeL8LF0 +R0IlpJKZCZ6EglkyNBnTeXF8XbndoRh8FM6H0OEmftr906k7XQCzIlA WsI=
|
||||
dhcp-11.nlnetlabs.nl. 18000 IN NSEC dhcp-12.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-11.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. BbTDena3H6eEte8SjPGF+B8wQxd2Z024yUVPRs2zWfvLeXShVhJ5PbXJ Z8J4O/8iVxidFPWCr34YdJobtNcDZbMNPdfiLiyWT4LChBEAqWNaBJ7d uVDNxoKiS02aKfrKoOhTWgjf4An0FGmDh30Qxj0Mdq2ck7cNAaVAgCE/ Z5k=
|
||||
dhcp-11.nlnetlabs.nl. 3600 IN A 213.154.224.74
|
||||
dhcp-11.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. ClbgLhqTC1EbKUoYJRJpIaQQKvBEWcxoOChOntxYTFw6vvPSx4C1M8Fr uDX40OEO0NO/l3IwHpBCBKrtKcP0mpdnkwcB3Zu12dlUuZSv8Syx3bjE ehXFcRktbh45M9JfiIuhI6kiN0SjWdK59LJzJ1PMGAOwiKjk7ZxBtngg qUI=
|
||||
dhcp-12.nlnetlabs.nl. 18000 IN NSEC dhcp-13.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-12.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. FAaeKtLXHurb5H8utLHKy7Y75dgQaE+qzcM8NYRjxrVD2qlHRQb+Wj2E 06He2jnOu/XAMC32Auuj0mllc2ixodg1hTCX2z/HyjM1RHR4dj2ZPCOx arKTpiTVd2J2UUabb5aUQjArlzbq1grIvy5fnkRfP5hBprq9Z8S1acVh 7Hs=
|
||||
dhcp-12.nlnetlabs.nl. 3600 IN A 213.154.224.75
|
||||
dhcp-12.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. hejfyrYuoJJ4kJEep/dD/zjIAYa1ouw27xRj0G1CyTZuiyEmZrqgwPzc SbWcVI23ZoqooE5EYPfr/l8QJj0JHpc0QNlxVa/lC9BGFHIVVlOZkvmf qYkxBw0AZPzaW6oa7xA0aYHyksLOwAnaVD1G/P9k3TcNceTbRTJTqvIK 0QI=
|
||||
dhcp-13.nlnetlabs.nl. 18000 IN NSEC dhcp-14.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-13.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. NpHGV/R2Nou9bOLma3xNhFYFTs0iFC4ys/pWuyizz8YmWB32/oJCQ2wK kruitBPuEna3AuYtT5sG07AO5e4ueUYXYG2vLSUn+j6JrneL+k25zH2Z rLE68W+J646iIZZ5ruKraJ2Y28J8GZzArshwFwR9oRi+0iM94jdspIV1 qpI=
|
||||
dhcp-13.nlnetlabs.nl. 3600 IN A 213.154.224.76
|
||||
dhcp-13.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. ZKDNqZ1I/d7KnVUnzakaPHKCj2A1Z8W17c5diDVvrWKeudgeHBM+JD+9 0bfAHH4gbgosKANNTGXA2cpUHlDlJoADhUX5sfd9+l5amxZAqLtC+QnX hea8LuHDIlMQQG66hsX7qvvzVpD1MuK5newEpJfKVUeKHbp+tFRSLGCr u3c=
|
||||
dhcp-14.nlnetlabs.nl. 18000 IN NSEC dhcp-15.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-14.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. c9mU38QvqETEs/v1y0RSeNhP3XELt2dhm4m0cRrYHkqxEERwt9NSDx9n gL9w7xVhVcnfzCXDzIfumqL+ZCjEjavMZ14X6a89CD6lGM+b/dqQoMzw ijeOSTJ6hq0p3lZYS13NXjUaQi8jwCeFNb2q2+TDhF8QPzJrW650Z8IB 5v8=
|
||||
dhcp-14.nlnetlabs.nl. 3600 IN A 213.154.224.77
|
||||
dhcp-14.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. qUR/vpPkDIEQAa9L+a3QilfzvjYWti3btPUdal0gQD1+hmkMlFOI5wGO aaKyDU6GSU8F/i9VmRs3nuggKWVLoG9PJwkfZoDiJNlE81aZ+sKsGE1b AL2Hw2ZYqnUT7LDtzWt/TslpJcpxS0usfMfQtJN8E8iC7kcFEsCcLtyw z0k=
|
||||
dhcp-15.nlnetlabs.nl. 18000 IN NSEC dhcp-16.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-15.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. lAzCYeVTtrmNilOU9SuymQSyziT/qysJLtf92jY1/u9ZfG0wHMP7HE1n c2k1r2yCPKvjnJbNYEgYZJnjUhk8HH797TWkWQXY1dGJ2Vw4fPeXiB8b qH685V5i4fSjWkW6bk32WqdkpkWkLs1P6lzfWq5aQg3csQRWdOfw3HZ3 6NU=
|
||||
dhcp-15.nlnetlabs.nl. 3600 IN A 213.154.224.78
|
||||
dhcp-15.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. k9ji4tuqlojJjFKGL/jlpXZDfEn2OUJYQdu5VJOI9vlGVcdKlL/QMERa vLweoleRNTdu0/Tt27caz7TrG0KtLhM71qRS0rd9X8fmGkO2PpxbvuJW yFjY/ckv22Y/K0sKn1zCf6/o1XxR2Wro6D6+V/u7KLYnRm7aVa//D5ef zfk=
|
||||
dhcp-16.nlnetlabs.nl. 18000 IN NSEC dhcp-80.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-16.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. e1rPfAwWPq9LBn2AXGgw43W8eO7K/VUtKvnGJ/ennRKlfJu5vsqDnhje zbQh2PY33jy2LUuLdGv9H3Ba2Hf4i8skK7YjcXI0yBMmWLiBHGoiF9i1 oD55Fpk+77RLJp6XU6wNDodsNGa83zsAfxdySrwy3USNAkIn3AXee5l7 4OQ=
|
||||
dhcp-16.nlnetlabs.nl. 3600 IN A 213.154.224.79
|
||||
dhcp-16.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. g2qWzNzrbjlZVTGwj0ujmOGZzMmRZ0CNMZbMZVbBrf77aP9Lz1VgDvGL h9MPpBvdk3JanO/xZL+PY2Elkj0iTFGP3uRNteywdcUP2/Xx3nATzJzr eP5mIDZYDKiAmkoqXOLhouWXQ9j1xAJ2uinslw0ZefxaOF6MGpXihdos EYc=
|
||||
dhcp-80.nlnetlabs.nl. 18000 IN NSEC dhcp-81.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-80.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. Q52UtKoSAbaBFrJmT6SH7fHzg2W1HK3ybH/s/sqJSyaqZbf9pZQRopL3 ryiXMX7L4eGXWr4tOuOdVf8j5EboGEJfKDMRBZeQXEgEYw7VlCC0t5dP VALFQP2NKtYa7yZ9rXe7Ua/3duo7ydGpv4/acT0wwNNcW/Risx9pozH0 3OI=
|
||||
dhcp-80.nlnetlabs.nl. 3600 IN A 213.154.224.80
|
||||
dhcp-80.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. HWdpL/uE9hV1FUjMSotBWtTlEJwT3RR36LcTyUa7/VHeL1H5Grq5QkxM 6Mf1Wv4zT9tjqTouDU7vkGlDvh9JN8eW+MIcV42Sugt27F+Oe/MAP4EW heYUF7Ez/7oZ6RWcq2I3n30x+qK3ehfwBNBfMchyPYEIqRIzWwyPVNjF 6c0=
|
||||
dhcp-81.nlnetlabs.nl. 18000 IN NSEC dhcp-82.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-81.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. R04Tz8a9qYlqNg6JPzNlAl+xGn5CGL3qEHJ6AM1C5uwZ9NU6vYdStNbp /gU7LJlMzcsN5wcS9V3dBsAap+P9awL9TUiPphlJA2O/37VL6pr2GmFF ZAKmJW28YN+dbqfeeiKE2mz6J+ZYcumlO5vPr46g6QtRf0pLFVkVlo12 TEE=
|
||||
dhcp-81.nlnetlabs.nl. 3600 IN A 213.154.224.81
|
||||
dhcp-81.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. N6lkHwdgk53nhMoHDT/7cWhuybmHPMDZWPFEdNjnoStic3o8zlAOuXZ+ zucX9S6Pefw2fwTXlfxoAAs5TGU4WCY0I2DQszSDcj8polwDY5SJrJDJ Veu1lXXyd4iBzhZRww/VLoBmf44HLbB0kZ7ZbH+xlmwnbkRZ0xR+gvLb XoI=
|
||||
dhcp-82.nlnetlabs.nl. 18000 IN NSEC dhcp-83.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-82.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. HLiIvzxeEKcJF3NHZgrY1EhnZ+91fdLmvqePzKi7RDJZLxiTsCCdET17 FdQWRX4zT9wMg9WhI0Q2jvacomj1FGaW7jOJl9iEhPNPmy+O9HogWmE5 BxICgAkOJzX1SATH1tQnUTgXMarmmZd1YU/hc2mxM+Xtf5g6xs6VXotK VKE=
|
||||
dhcp-82.nlnetlabs.nl. 3600 IN A 213.154.224.82
|
||||
dhcp-82.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. DhGvag9N4qTDfV2PpZmmDDwSkDx7QTrRAfH4SWU/fM5QYAMSk0P8g/4I dWDRL3BxAvvVNzfm5ATOEe+Kq+xNLDKAMxxRYSbaoeLQtEiRai+QUvrl YU7rgUpszenfwi5c5aVYeI0YvqC8DgLDjqIxcJEqvsi4mbWFYu2u4oJQ B90=
|
||||
dhcp-83.nlnetlabs.nl. 18000 IN NSEC dhcp-84.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-83.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. E2z6O6f4AHqXjlFaOMMyG8Xy9tCD89jgAmpioIqgOB4J/HgZHSzH0xi1 8XjNILyvYDnfjTDEcxUmfPHKBP8u7ngS6dKbKXT4+O4Q3ZeAvYUs3m5v h+U+2oOm5qM21k4CEIQmSSUFVqU44ASry4TbiT+Di9z2iqLDW17ajyr3 3NM=
|
||||
dhcp-83.nlnetlabs.nl. 3600 IN A 213.154.224.83
|
||||
dhcp-83.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. XNPiy0sSgZgQjrq4fcTpxkRiHI8V6N+twVL1Q4A+3oFbAv4CLrvWZBnX 0N2cagdqFhLLtWNYxIw5P7wrZF/UowcxPa2KCr5DyDpo0JfNWR9En38G +XvV/f96DyR8LDnlfoGb7/PeopHnNP0W3sl5jXQPUBfZe6A1gh8Ph0F2 yzg=
|
||||
dhcp-84.nlnetlabs.nl. 18000 IN NSEC dhcp-85.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-84.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. MfJPB+IQxZs2N2x6qjCT3aJ27it8asZedsMrRii/6ZEvGJ0QQU5+x2xl bh3+mxRxbkTguk4Rf6ZPbbCwI3qa3ReP+V0GQTVFIctNmAV7OCreE5y2 svobwBThQp5Ue7U0l4w2u6r2kGXVISipYgll3rp8JdvhD1bs0HC82qL2 WGY=
|
||||
dhcp-84.nlnetlabs.nl. 3600 IN A 213.154.224.84
|
||||
dhcp-84.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. KSgsF31Edr0e7wUJEaUGE1OzRU862UXlSISgmqyjLyqrR6HqyvtVAN7E WWz22LNwZdEKUxqkQ3EFNISGxcl0EgnIuM+1mnKNiWGLZY4gcxv9gyxr dHjtJC/03rCfeN5QDFqxwrZwRcChiyXt8sHDM5t43fWjb0bumjkMt0qb tBM=
|
||||
dhcp-85.nlnetlabs.nl. 18000 IN NSEC dhcp-86.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-85.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. HMipwg278ezTwQ7XW2SLz4rF+QVZRMPwVrxQ3elO/io0juBJLGDiI6UX GNZ8HeoBVLKR+EbXR0uzHj8Bu/nD/+5463CXWFDRVH26cBG8ppkD573v H8kkAsf1NBMSPvmxsnk100vfgInjsdVjbjPViVmq0MF+SUrfCDK3UwGi Vz8=
|
||||
dhcp-85.nlnetlabs.nl. 3600 IN A 213.154.224.85
|
||||
dhcp-85.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. fdbeSnzQ3oDiuT6+h654Z9Q4Ap2G0SNVGzv7fICz5cTW6ofkHHgRGpsl XmZnvHergU4+mesbBsGOq6mQDL5lFVuQpZkoU9U+ZsDTVa4IOHjuxv1Z 7Gq6ipR5Tv/FnJwkxs7IR7G6iikN+cRfWau1b5qfJbjxcxI5IaxxVOjn zGY=
|
||||
dhcp-86.nlnetlabs.nl. 18000 IN NSEC dhcp-87.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-86.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. ZiLXpVFO2a/xUFHr+lCLD/1WxSDBTzyfu+m5KCT63eQMyjetTqhic1xo o4Evww2ePf1/WMoUopJ2ho0gnrsNv6fCRQY1apXwPE/5NW36PZn3h4MV ldlSYx1ut/j1THjNf7QxL/Rd+mcixrYcRAByvn2edfrhU5wuCfybI3MO 3/A=
|
||||
dhcp-86.nlnetlabs.nl. 3600 IN A 213.154.224.86
|
||||
dhcp-86.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. f7O7tH/gA1WhQ/EOEAAsyXpEUH3+XEAC1Kmy1F5zMF6TFB4ynIrqiCbJ Xvdl1AN+WoEClK/bJ+Y9gLjRHzD/fYGSuO1wnPjJRD6WGynVtaYEfSal ly8UHRuywvHlKV4vL6YQ+z/FFegMb47WCvmEd1Gu3QvohyOJrz/aS773 gBo=
|
||||
dhcp-87.nlnetlabs.nl. 18000 IN NSEC dhcp-88.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-87.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. n5zIChy2yTS4ulHqNe2/obbF+JXcKWMs1DnLPRsDm6BaXRjosn32zrj9 P0hoQJNOQxhG8f2xKO+3jYoDXMLKh6qOJrjXjUHeaBBiuj5kxU/EUJRz YspUKC4oEFE3KcA5UNL+siRfdMsnAD+fUVpWs0msrr+aT+rAIeZ44r+B HD0=
|
||||
dhcp-87.nlnetlabs.nl. 3600 IN A 213.154.224.87
|
||||
dhcp-87.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. c2oRlyKG9hDQ+WUdBshyeKrgBNmeZQi/WTMaWMN/F3iICYGOd3NF0JLd ba9LqpY2BHFvA16y1LfVFY/3aRlmFqp/r8GZcdODyC0UMEf1nSY/gILg sLWTdi3H2Fk7+64FfpUu0o5WaDNWQKHz2lAyDU9h403cOQbaDKh5IIMH y0M=
|
||||
dhcp-88.nlnetlabs.nl. 18000 IN NSEC dhcp-89.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-88.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. EeWOJ4JcjbHxB4qu8du2YOa3Xbww9v6kIia88YCJLfRviaUlSqXxkrdl UOj7HoNWMMVyTAAT+Zc5zGS0IZi5JdxyAZyfdC3mwto3asSDNhsT1HZA qpHiOQIXoT/+yPLgYLtpBxafgiPzLP+V4yW+Q1ZmrBj9jZa0+WILjmHz qv8=
|
||||
dhcp-88.nlnetlabs.nl. 3600 IN A 213.154.224.88
|
||||
dhcp-88.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. SSdcAQ+8Dpuc+XfIK9R9vhWTjkOabSrolGYzCvrjSnSyTQQbzNGgLOr3 SEt1XOCEKQ9p/uK+MPvytuJhZEIJThhE7umCJ278+q2EfYHvtc22gMuc /S9b1QpX4iwUNmsJRbSFhfhW7huL92kEhwh2ABUwjD5j/wC8DDLKGJdn bvk=
|
||||
dhcp-89.nlnetlabs.nl. 18000 IN NSEC dhcp-90.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-89.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. nEMoh/PDePEoGN8sqX8+cwzViqGADytqVQgsUjD/dR/rpetLAo+r2NKg mAtRpC0lzF5AMFgqheKvqGTyKFhiiHUCwL2JO6xturvGQ88BiQLku0Dl IsNHRqrqPbRdCsMnnh3dFgnlt2RgY0tFAlb0QvtUFS4JFLeZ4zrE0CAX QYQ=
|
||||
dhcp-89.nlnetlabs.nl. 3600 IN A 213.154.224.89
|
||||
dhcp-89.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. S1QrqU8nF0wHHwkyJDTNz85WGwEZAqK0S3S6U8X5o8j6t6YA5shoqRUg HNNG9i2T2QLAuFDJ6RFKTuC2NjaTtuMlKOJN6eOUBDG7r9JEkTDj79jV EDMjjXOBVhG4DVeughfwSdGX20o/CEcVsD7w/cuG/h86tloLCdAxXf+3 xXQ=
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
SECTION QUESTION
|
||||
nlnetlabs.nl. IN AXFR
|
||||
SECTION ANSWER
|
||||
dhcp-90.nlnetlabs.nl. 18000 IN NSEC dhcp-91.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-90.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. cPEmnWaQJQflV/fR1LTiDn+EfCm9PO7DoIhjvr35dfp9Gx39OJPf5Fnc 4NC2Ay0gnfiJ8RmtWsd5A/rg0HYDAOqI50oHjmgBPjBaCDyclkZdCUdH r4wycksRf8yUWyrOc9EZtF7PekY8Pcd0HtaXG2eWH6h36qPZcuDDZExV ONk=
|
||||
dhcp-90.nlnetlabs.nl. 3600 IN A 213.154.224.90
|
||||
dhcp-90.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. ZLV7Q/fuq/lxC7NuoSL3a8kkXnbvno7cujDLdqjNZWqMBWFe06GKYyFa lDQ6UDhKOOvavGJaY0dA6k+PoSzoL+bch3Ro+56/8+hNOGL33LDSiycZ 5X4bF7ghW+ggvrGCPoomICfoNVOKefHRBzKGBm6C8zJKjggb4FbDFeh9 DVM=
|
||||
dhcp-91.nlnetlabs.nl. 18000 IN NSEC dhcp-92.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-91.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. cJoIQjSfnuf/OIJXr+IQqHC+fl8bXlHrFEQf5PvdUgmYO5lx6HZ9FB9h dLuqDzLdVzPjf7ncBxiQrt1ng7gySAzeBqjezrTm9XqFoTXyK6W5SASC vSmAx/c8yHCcqsNSIWQWyo56VCF+ampF/xqVRO8xmmJP4EWJ49VOMOgt Smw=
|
||||
dhcp-91.nlnetlabs.nl. 3600 IN A 213.154.224.91
|
||||
dhcp-91.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. DlSRwEHWgHWe+epmbdI+bo2fI3K+jJcm6plDXxy4b86Uc0wU25QMMbnV 6ksrJ2SAAXUzcdruJLlpdtdnZk6gX29w9KH9OTyIDDi8+Pkff16F1YQ/ 2WBrCDT/ogQFD7hLpmu5i5MuBSxblCigaQy1DWL8ZQLN1uIg+PIOG5mh j20=
|
||||
dhcp-92.nlnetlabs.nl. 18000 IN NSEC dhcp-93.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-92.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. YqjXuYbOomBjOwFVVCv7tg0ofoHrrvZRGmt2QNTHzuyFyvm1tVlYauF7 xHpTnFsdsKJMkWVNX1U05O1+gXI7mv7CiJmwk4ixap/oGNc/qT5ziOMm mEaW+HbD6Q3bMrb3/n3M3dQdU6aSHjKi6PAeqdu8k7101jb6qwJyKih7 cyg=
|
||||
dhcp-92.nlnetlabs.nl. 3600 IN A 213.154.224.92
|
||||
dhcp-92.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. JGRsNgN+pLLGKqTkPRgGpP7wthjinjxS5aEI/SzyqYJ49jn58gLvUk02 j2rrC4zi14X74qaVg6Rqk5iYEaCnDD8WFF3rrTM2svyrxHtL9WooXVKD meuZUHo/S9em6avaMaJ4ATbrLRnyesDwX9ObKvFPqIB6ngDL7BEbdMcw FXE=
|
||||
dhcp-93.nlnetlabs.nl. 18000 IN NSEC dhcp-94.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-93.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. ghKndVKwVwB3GCCbB05AQ+QHErd5hDH/eThxntJzD+t4XwfE/ba7w+15 R3n/rCMP8GZyOXIu4t9qRDuaqyx0Z2vnSDXVie20qilq+liFuSJc08oI OhD+TTUTfc3JeDFSq8966nE2iDOlga/0PlQv1J2ZWlHy6GW7uG9+erCD OQw=
|
||||
dhcp-93.nlnetlabs.nl. 3600 IN A 213.154.224.93
|
||||
dhcp-93.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. OxOLXxd9IyHhfSZDgH6e3Q4kmu39n/STAFvveQ7lzrzABIiauIHqy2oR mteIYUzy3fV+C+GogeiowA6c9JROKzsU4DQHERP/WGM2TyYGVHrH+vuo FlkNEVUc85hbVySwXgjJDLo3megI0HYatldTNYt5I90mZOgUg7pSpLhG Wo4=
|
||||
dhcp-94.nlnetlabs.nl. 18000 IN NSEC dhcp-95.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-94.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. GiTajmO7Q7P5D9RSjFthAjKb3VFaU3IsEi1WIa9SdDCCgkweHh+a+42V TmbsSUxCEtHtHcutgARIoL1fghxAQUE0d0WPaOHlqsKXcIlOqFGe/uHF phydsYuyba0k5KwP5KQ9vpj55dUHmvE45EGpclooon6/j+dhYjlV15Kh MfI=
|
||||
dhcp-94.nlnetlabs.nl. 3600 IN A 213.154.224.94
|
||||
dhcp-94.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. gMEfCCsC2RBehO29NobegN3YbUmPE6aml7dSEhVS2vzRXkceZ/kCDn4n yXkbBJA6WhZCR3XjIN9/YvGdCWS7TkbzebQC/btbEp1n0t/yDhjzyt8y 2waiIWM4ooehjyKRtr0B6GXv0UolSzK77JzHVtkaNOkNn0WJyLfY/Xyc 494=
|
||||
dhcp-95.nlnetlabs.nl. 18000 IN NSEC dicht.nlnetlabs.nl. A RRSIG NSEC
|
||||
dhcp-95.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. Fv/xwiUB8s25tD6FRSiaSHpO34hpxPZCGSQrkqExl8vqKP3B3dHtIcCX SiA0u22LlkehvpkoHUWzIhjRK2I5MslqHSzN+ZOmf2FNZd/NJruPPwVz lAjRn3pKQkOV1iqQBj0DlxAsTpI5r6a0dkPRcQ+qKs96xUXY6g9fhU/C pjg=
|
||||
dhcp-95.nlnetlabs.nl. 3600 IN A 213.154.224.95
|
||||
dhcp-95.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. g9TfAoDLV1A+FXaLFU1pKxXYIk3Jy9nco8uvX6eR1lnuQkLg0ZD5Kmbk Yen8BuqlUDe7Tn7HFQ9/dq4y6eFXyoVi0ysvRw6E4P0yAwKHmvkqK0Sp surB64dt2MWKMekaXas8MTgCiwe6FkSutEO3/q64yGgFZcfcLTOy+8w6 unY=
|
||||
dicht.nlnetlabs.nl. 18000 IN NSEC fable.nlnetlabs.nl. A RRSIG NSEC
|
||||
dicht.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. V+b6TXHkfPt1DpfJdeQLIqlfyaev6ifluTkgA8rYA1ncehDH4OJtWg/a ChZBy8Y9LMzkQMFgqTBGjPlkrE6uzOlBEfZNAP+YA920KUZ84KdFutfL 0FYYracWonskOMdQvdbZNo0pFz/3OZr/9123okc/dCVEA7tavWiBfsBZ o9Q=
|
||||
dicht.nlnetlabs.nl. 3600 IN A 213.154.224.250
|
||||
dicht.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. enxkeWL8VC9lsXjBnqCZt6BrONS/W6WzNhXJrhDFf/LBZTRdb37MgnGH fCBRqgKn/HozKPKAFtZiqsXrlsQ86P3mzlNm4IUpaj1v+y9syrFOjkyx 4/osLK1CZZdSEMUqROgoE9DQ+UdSJmKto2oUNxjidg8Ewlb7SDPXM/G+ ct0=
|
||||
fable.nlnetlabs.nl. 18000 IN NSEC ferret.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
fable.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. p7JVmo3vVvAmgXLqEAljzKxhacRC6/T5r8SwF+t80zoEDTSTnS7wTmcq K/nXkkxUcQv/9fJAC5pZaj4karJURQ2q38EExwyoJGMgUvw7I8wzGZ/k /NMahGyGJLZf8hbcb0jLyvpnnq38V4DsQfbb9CcifcwmJkvS6cgHU6AE aOg=
|
||||
fable.nlnetlabs.nl. 600 IN A 213.154.224.45
|
||||
fable.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. WWnxLKqS8bZ3WnJfmman1E9Xx+JwXM2/UVF78YjCVqCV8RMT6W2fzPCt ylgCAweIa6aG28hEGzPHCiWlSvQUs+cd2wUWbdDiVwle9FC+Vji9Iszs 19JQy3HEwiuZ4m3eapgYia+DRzJnXg1ZWaFgvhb6IW17DfHPVmcYYHku eQk=
|
||||
fable.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:250:bfff:fe58:4d93
|
||||
fable.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. oOKls8T7L9tx2AqgyClKIcFquXD6aT3NYJb5ZA3gXGp+cPMbvnfixilu pD7XZF2i08AzmlOxHpd1zNw0jp3IMKebQ5eZcIV4kIyyuY6rFovJCmxW ECcLumjIKlyxb8h3Qj7KSZcPH7Pt0yw/czluGD//5LWA+/7gg+itwk20 2dw=
|
||||
ferret.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. CaP8AdmTbja9YXpxnJfYsLWENSChjjG899PVPoluvQYXbfrLcb465uXe mp8MI03nySvo8786wGe++Icj9bXOzeP7zfUSEPW2UFREd3LsjvZB/wdu dfOApQcWBLrQEvD/++EGgJB7idf4cgrkovtW4elRWFpWHY3GQLCvbjGH UYM=
|
||||
ferret.nlnetlabs.nl. 18000 IN NSEC ferret-e.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
ferret.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. FF69Elwu+M4nDJWr+f1UwyaL0UzAoorPOhZ8AZr90uuAeDdhNRZ9fdPj qLb4qqVj+5bDNFS4oxYyf1RZyMsHJPPMwi9j8STFh3uTa56JLSsK8zby CSc90Ik8ipnB/5fe0DThnEHzqGzujuPpX33pTgYd3+OHJCiCsTTJH/ml Tqc=
|
||||
ferret.nlnetlabs.nl. 600 IN A 213.154.224.60
|
||||
ferret.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. QEZ72Z7l0zhUNTn5IqkoasFWSuV/cRasyTw3eFC/B2AT5l+0SQT1AlRd w1WHKJ+EcCeVdtujX4TbWgSfNB9Cwc90tLvWPTm6bq6WXI+LpfHEPw1m Vxi6dZAjncKN6S5GKYmovpiiipQgpA32vjc/52Ptzep1VZuFIXvHYesC 6kc=
|
||||
ferret.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:20d:93ff:fe86:918d
|
||||
ferret-e.nlnetlabs.nl. 18000 IN NSEC floep.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
ferret-e.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. EUhsopQYSHZgNW64CNKUOIgJ3o8NU+EhCXoG0GGyvBQSkUOUAdqzMHJ4 wWXvigqPxpEa24mrMZQKKnHyAq1B/cB8Bt05TCNblOCcUxrDATaUYtOt K16NFIGCmI7gRTt5CTKKjMDrVpH12uDwISk7h2MGCvYVnsA/NN4Y+4BV k8c=
|
||||
ferret-e.nlnetlabs.nl. 600 IN A 213.154.224.61
|
||||
ferret-e.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. GDL06fR5q0+YsaoRcBHzNZHgZ9GRpIGFQyTdwUQLWGIl3XeyZgiMVU3g w1MNDk1TM/UtTOLgUDu+lG2QJEgRFadU43F2ubcSVrL1PahAoN7Gou7N JlagBdgXE99gi2UfPeePBwcL/COv3U8aTSIiEJ7WVODSVtR9l0PCZ1m9 bfU=
|
||||
ferret-e.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:20d:93ff:fe27:ff66
|
||||
ferret-e.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Vt9a8m/XSjOcDurL+0H8vDFRXNsSlTgUVlsxmxQoNnw+2O9iA05i7UUl f2iubmnvgUmBpYa8ILp0FHGD6cyqD/O/wKKNpc4W7RoLBelWAwDVrhx/ yx8j5XXr56ER6XjoPPtCpNVNRvXPZ980VQr7HoPzbJWjOCAUovQ4YONT Ny8=
|
||||
floep.nlnetlabs.nl. 18000 IN NSEC gary.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
floep.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. K5r3od2Qo7nQwgnggvuTpQcB+NX5nlXfFFVH9TRzlx3kSupiEROO3YUd GXtTBl4fw9vDimo2o/VajENF50d0yU6aqfgCHhnjL7rg+pWPbyY6w02M c01/F5RklmwPCiynHebJ/RGXWSKFUi5/hNKr0LCIFae4YydPNUCHyivI 04Y=
|
||||
floep.nlnetlabs.nl. 600 IN A 213.154.224.37
|
||||
floep.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. pmC5tXXZPnc4Sjfmcn4ADpuUbTdKAx9wIm5hflE6xCYnNGNCCY2LZDBh eggJtjMTsY30a7/ziDCwMiG9LzPoUo3cHURV5vVwSfiqMFDSyMrNxYQU aSa9tl+TdP3pxuGG0MG0MykM0CwnkjZOG2kTtd09pNYgg//iuD7UnAp9 6pw=
|
||||
floep.nlnetlabs.nl. 600 IN MX 100 floep.nlnetlabs.nl.
|
||||
floep.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Ix/ol/iR+Tp70/bxUifh4FRu2lK8WDpj6aGyNFyzUrpSQH0cs5ZL+Xns S5fnhmGjkCm+6WCSr6oT1ncKqNmztwKBXFfAjkLQK9iynxDRC+j/ERuv OfxIh+nlvZ5pZXDIOJx4qzHSGZYi3D4bDL0otSjJjXG4316nzeeGIbFG c6g=
|
||||
floep.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:240:f4ff:fe37:7af9
|
||||
floep.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. SekN1WZszjlLSrVN2FFkRGSB0MVcTfsX0GEMn9cknFsA5hItnty+0rlf A++miOFdb6NbxNaoCSBLA95eldnEBkTOy3hp5rMHdQpjUxuzv31z3Kc/ tsMFBajyv79SFWibeUxzwS6kdgabO+yA8EN3S3be2f7/+n3dRBYpxxle cm8=
|
||||
gary.nlnetlabs.nl. 18000 IN NSEC hpr.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
gary.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. k1ylHPSUOzCI+8eOhyJi1RVtc0g6SB+EqDEi0e45fsBh3Hsa5yr7/bua aK3NUI7OHRVjEg0Bs27UmNTrfzmNpFfties+eh5QTbtJ32DqQzzKCPPu CMfGOYVOqUrSVqAuYDLq2hVQwTLtvV6u7Dc5pCDE2RslGoqhL6BExdn5 0wQ=
|
||||
gary.nlnetlabs.nl. 600 IN A 213.154.224.58
|
||||
gary.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. FElqOEtxgXvbJJbXE4e/0i7w/tCCCT03SC3Q4AJZ5wzhjyUBRMUQ5fZ7 Xa2YFUYtWvtZnuP74mIHc1mV4lUpGwT3TbXOVqCX45UaIA9GdEoFDeay S2vJbYRrdJewLGJHb8uIqFi+8MvGQWIm0TcCFd4s3CEMpoPASe+KzO3p ET4=
|
||||
gary.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:216:76ff:feb8:1853
|
||||
gary.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. JiqXQWJj/xzn9NopyM+M0p3EVdg/QuQZbZ+o4bQZ5JWHFvwzXSkjjR6u SDmObQTJCWVmgFvNQav6Y6Xh28Vgw3wO7ut5i3VOs2T7GAF5Ezr2tH2E rPP6NjgmvWgYwNSDCDuyzFIunNocVnUHt1VMk1FpfTxD3IIOY12UBWhL wuA=
|
||||
hpr.nlnetlabs.nl. 18000 IN NSEC iii.nlnetlabs.nl. A TXT RRSIG NSEC
|
||||
hpr.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. aS/em0n3uWpObWr73TyAppJfzVBBqsm3ItqrejZQwvPneUbf/VFTcRCn Rrkr1MkRpGHc1EKe4UOikhc/BLh3/WSlKeAHphVb4FxOHsik1gA9mkWN GgczZiB+iJhoSvXCrB548DcCC3kWRM7llz1GsbVfdJMlMu76G+K8j5DU 4vc=
|
||||
hpr.nlnetlabs.nl. 600 IN A 213.154.224.35
|
||||
hpr.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. MtNG5jmsGvikF2+8VeM6YmtjtdwyaVtlYp2TOnhf9f/DnwGbHF6IyNp7 e3UCGaVSCe25nO3LXC8Bd/B/vXDrKhlvwdeLHnQttVC/1FukNySWLoIl 2TQMo+awluLnvndbSqinZat3IJwy7V3PHTTJByVagg6qf6SahBwPaxjG 7L4=
|
||||
hpr.nlnetlabs.nl. 600 IN TXT "HP LaserJet 2420"
|
||||
hpr.nlnetlabs.nl. 600 IN RRSIG TXT 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. emQOMgaasP6+meaCM7LWQA1euf7K0cKe84pKOJj5wh9ZcX+gIpORsTlt o7wvqbEq6khMRNkjtyqxaJW06LBw/diXtPqpwNbl+DfEXHmtU/QRoJzm tpEBaqZbmBcWXjBZeZJ3EJ4ZLxl1L52JAwOtW6FFtxDzt46pp5mB2DSZ P2E=
|
||||
iii.nlnetlabs.nl. 18000 IN NSEC ipdns.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
iii.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. ASgNY0oaCiUS8DJVzRrPlF33EHjAnYhyTfFjXIUqxXraoNhMba1qqgIS AsBUAbaGfBsxl32lbLMvb1utYrCUtfo+ZMxjpr1EK+KhD0QQoudVI7Yk o60VHl6mrsZXFlJ2DBm/FLYbkMbhJFzI7DLLsRN2vQsCeOTjPHcSw9wi 4Yk=
|
||||
iii.nlnetlabs.nl. 600 IN A 213.154.224.1
|
||||
iii.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. UjvIGM54znUgTcuEJmR/e8u3jnmG1LM/+3JLZmzDdvNMVnW3n+K8qkEz ERWJwW3V+alkN2Rl+udErP8I7H5lB5YmtQDeGnZwiu4k6f/J3gdmNrkx MRpSnEtVYeNkajjPb0xX++7emchkeSydAA/Jt35cEEaMZwvWXkzaUyI2 MYM=
|
||||
iii.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::1
|
||||
iii.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. LzM3IiVN+rCNYAHM0/9Hd2b8q9gO1NeTxdIp4YVnrQqJMYIR+cwmJ7ie 6s7L4tlbbPsuN/rwXTog85dPyRhr7p0p5qFiHePXuzZm9sFwBH+hCrp9 F5/Op0YfjRGDbaQ2Aa2Ujc75Xp92kWVViJWP3efH6/FyGXARXR0OVPNS DM4=
|
||||
ipdns.nlnetlabs.nl. 18000 IN NSEC jelte.nlnetlabs.nl. NS RRSIG NSEC
|
||||
ipdns.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. jFgGPCL0aBhyG+xXjKy0wKlFosRlUtnURPnzSLAgjqU328xZUZK2k4Fe mc5ZxIgUDQdqsXm8B+1zKu8X7fnjeeX/4la8VIP5vRhIETKuDURyrU2S ZO/XYgMyzgXGo91zVxsOEp5otw+w8PuVJX0ErdE60v90KsGuzuy9z1NP aQU=
|
||||
ipdns.nlnetlabs.nl. 3600 IN NS fable.nlnetlabs.nl.
|
||||
jelte.nlnetlabs.nl. 18000 IN NSEC johnny.nlnetlabs.nl. NS DS RRSIG NSEC
|
||||
jelte.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. kKd6XS6j7oXpvhquML+09ef+RdD26UJ/UF7byOsGUGnadu1d+22K6/9a mfvDwwDtLb+ozZb4mHkhsRWgUDkPaLUjwj4GIwUbo0fb/29XsixNt7XZ djqVS0RgoOC6v7MsOluENBN5CB1rL1DPyQYqEGg7coT9onlREL3fy6cA dA8=
|
||||
jelte.nlnetlabs.nl. 600 IN NS talon.fluim.net.
|
||||
jelte.nlnetlabs.nl. 3600 IN DS 31560 5 1 1CFED84787E6E19CCF9372C1187325972FE546CD
|
||||
jelte.nlnetlabs.nl. 3600 IN RRSIG DS 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. MNtlv53uN3bLOFWlpqwZb6gWMJCkrCuUs1qrHiTPpzSyG/2Yn/pvqpRN pvS0OKZgZEv+xPodqFnYbFLc90//FFaMEiiXRh5M2M1wZbxdhf4CF2pQ Ip2E3TecPAZO1OAzxGJwXvYP/INFZsGSedP81+NmGOgXkDQ73hF8Pz7j Dpo=
|
||||
johnny.nlnetlabs.nl. 18000 IN NSEC lappie.nlnetlabs.nl. A MX RRSIG NSEC
|
||||
johnny.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. j3hxzzPIGSGWaaMCmsv5rO0exCMGKG7axgFN+zQ7S72MVBRsssddDa7J 0oFUZvKX3ZxH1oaxwuaBJURo0+2Z4ip4FJaqykY2CAHq19/ki55DDxiK 4hgBUj73gbeMeTWu01grVzdp5SdDCOP87DRmY0fhZ0W82it8bWYV5Nos pFs=
|
||||
johnny.nlnetlabs.nl. 600 IN A 213.154.224.44
|
||||
johnny.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. EJAy5kI3QxNNABLIw/asxL2LjCMshjnWMNyUeu1pRd7KM3QQUDygnw+c 50MpE1y4X8LkBXDizazoUXPsqEGhq+fzGeFEhdB0DqrxVXtyQ3ikHa+d oVp2jdGiI5zl3yWBlxr4GtLr59jIB0ZU1sL5F0voBIAGv2i6PqArRswr HBI=
|
||||
johnny.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
johnny.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
johnny.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. I0qgNxmzI+Y83gLAMRkbqXqaTAwXksmtS0bxyw9ZeZuP6p68ScV5siS1 MsOmqmdcoqLX9BRU0ekL2JZBIiaOCBrZg9Gt4+NMRQdaZGv3cR79X6QB W2cEdQO5dKVuzFWH/oFJEBoThetFNKaEPNH7jlZSUMqSpBEdo6uHGOPP EvQ=
|
||||
lappie.nlnetlabs.nl. 18000 IN NSEC localhost.nlnetlabs.nl. A MX RRSIG NSEC
|
||||
lappie.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. EC+9kJ73MmOyyXzmo9Gf+CoNDEItyKdQB6YderLcv7or9CcWPnZ6hsW1 aZbU4SPYjO8Qtyp5O+vcTY3gFyex0eVmCSI05dNEY9VNCACfb5rUPtGw 6Q+Fc2oll0CAJhFRaRWHHfEoDuDh5MCNjnGM6bDax9JIKzJBi3cNmS1W VEc=
|
||||
lappie.nlnetlabs.nl. 600 IN A 213.154.224.55
|
||||
lappie.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. TXeBHEwmv5bQDnkofdL2No8B7uf2/kQlDMRZh/yeGE86vIppxXZ1I42V SBzM3qEZ+dPWxJZU2yWdFcX45+NVIxQp/ktgaTNHcgPRHalX5B7gbd3N Ga4niMxUSXKQM3aZYqXrxDLvWjYaj9qH23AO65rF/sANAkPiZp4+/GqJ zPc=
|
||||
lappie.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
lappie.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
lappie.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. pD5bMt84XFoNJDcCbkq/+xBLg/yb1nPmfuYOeE4YaSV6lFFmth6HrQiS p86ErhD80R9omATBTEEaHnuYw/HxHUM219NA1kKO9smocB7oNhsb/Has WrdgzlzMm1oGyIJknuVCXFQQo/Z9kUJyLMLPntaOAORsRwuRgOn60JMb szo=
|
||||
localhost.nlnetlabs.nl. 18000 IN NSEC loghost.nlnetlabs.nl. A RRSIG NSEC
|
||||
localhost.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. h7Y5+OptNNj5UMWuDnRARnMbf0IKBYkii20PAHEQ1+tBtfA5bv1aavrk n3i/amzJLk5GV1xAoc459mV0+RcTzOrlrZZ7MwsvYFmdiB+0xmplRTgn 9bF0W43LZ5mMH5pFyBnygc3myoDMxmrgcdhjiW52JRCX19Ui0Dn33lZ3 dYU=
|
||||
localhost.nlnetlabs.nl. 3600 IN A 127.0.0.1
|
||||
localhost.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. T1giRKds7G/HjqKOgDnGXwsRDm/kt6c4cWs10Xd0vaVKmeEFyi52+YoK j6AIRlHMd3aDJO2F0yNTy2MufDZTHVJ6usyGw0+GEi6Vf0AT1lAMtg5i /C4i38KAwJXLCNWQxPTfbAubpnPOtt/078Oq2I/MLNGytcWyRXApyftW J/Q=
|
||||
loghost.nlnetlabs.nl. 18000 IN NSEC lustra.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
loghost.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. VcO1o9JRiqFCkOCgizKfCWslCQObdt7QrvlSDgd7kkcT0UDuDcDMcD42 jDy3hhrJkmU+ICqx1g7CaaMIbsOPZWOsZi/qcNki6oEuLG8gRD55F3X9 TGApgPAd0feU1S2GuEBZSc/4oeizx4xuYrC+RSCQlgl5OUwJf1Iql1v0 Iwc=
|
||||
loghost.nlnetlabs.nl. 600 IN A 213.154.224.1
|
||||
loghost.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Qa7seOsz+RF6J2NIk2Z2WQio+qoxgKHNLdYapzooJxvkghOQCqF2Ogto ykmmTvZTj7fUoZ+gyipkosNi6BIIxIUpI/BaEtEEp/sZK7vQZsGXHoqS Etoduv4dEUX1ZjVtBnuzW8BIg4NzPRXtrHTGox2SNcvEHpB2QrXD33XN BxY=
|
||||
loghost.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
loghost.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
loghost.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. VO0p+Ygk0L1HIwrCRsy/6GAF/HSaWZjDkM19iKhtlA1rmry1DQ4u0Zoz GV4gWLmuqxxC0ablYo3TPP1krRTuVowfEsxOPcInP1NbFXtfaJxNh73a KfyFOHCMbLboBU7pQCdnKjXZOqrOOaipEVAkPviAEhY9Rz3bHeDQKmTX R5M=
|
||||
loghost.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::1
|
||||
loghost.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. G0G/zsG2irSSY/Ym5Sk7e4qyfXU17S3gueNN/3it6AvoT6twshV604GZ 6aFRvpmx5tUhaosSV6uASzeZ65aR+5/kZa+IJtmzDoVliYv3Z1T4Bu85 MFX3ep0OSjXkF8umDzopfgiv89UHU/1lM/R+8WcgIyNBxpkcr0BDk5tL CZY=
|
||||
lustra.nlnetlabs.nl. 18000 IN NSEC markbook.nlnetlabs.nl. A RRSIG NSEC
|
||||
lustra.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. eI6c1Zvg7B4W33c3Hp682BUQFLldh/cuZU9Ynk0Ymga20lyjGRS27SYA 1PNiEge9h6dg+nLPJztgz7lexDfdp2p3ZLq4guNiGkN2YaQDMxoGzeOd zG3hHEyzTYKCBbdAlFmuy+94eIp4GWptlhu2vgAuWjvCQxvqAoTKIfiU 0q4=
|
||||
lustra.nlnetlabs.nl. 600 IN A 213.154.224.52
|
||||
lustra.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. l5CL80Ow8dk/Cv/Yq6U1Fq2RuvkdrU1zvdh8SMIEim1JljsqV1YsyWZC AwBTH6ms35sG8MbiF5X0luwAV/V30jL8CUrB4EhQCA4TDwM+xSYZrEi4 wfb2KpNsX3GNDDa1CV5YEqbJEp69EmMhX92Wg+L2cd+0xXop1Z8PmKKw W5Y=
|
||||
markbook.nlnetlabs.nl. 18000 IN NSEC markbook-wifi.nlnetlabs.nl. A RRSIG NSEC
|
||||
markbook.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. BWuNDPuQ/yQoF6cI26tayhNArrClF9stzilmBnQpewBPuthWEllswZpQ yGKQ1cuBw189DD4rDN+22152lttO7Evwgf3rQTrCCIwpZm4/xERdLVbH 0/vwHVooJHgA4hjX6JeNkT8UrMnyTHt/0j/uZi76YI4jkttGKBQTw1IH V34=
|
||||
markbook.nlnetlabs.nl. 600 IN A 213.154.224.15
|
||||
markbook.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. HDLwWv+UtqQvGPpr1Pb3NHqwt5bUqWOdJRx3a4UN9TAdjH2p54jjd+0Q TkobfBra18VfwThK9J7PP6br0ceEKBLXfI1bpOu93PMTmJJSjReocakw YSkwbjepZH9rWAMnVsUHEenjt6BfyIB36vKe+BXN+nsTT89JVewyd/Up nEk=
|
||||
markbook-wifi.nlnetlabs.nl. 18000 IN NSEC mirre.nlnetlabs.nl. A RRSIG NSEC
|
||||
markbook-wifi.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. Z9ay1VDAu6CFmZwnTBj/zBe/orvWl/KpfqcLe3M+YW0+Xmqr0egZKGtn b6DZjDBUAe0gsu+T5pGa0KL5QxX4SBTs6eIBqNaUmvwQEDFuaxjWiCTJ CtHItcmiWtCYSHMhqXJNehMFUWmW+MCtqQnBzHP/+ETvgwS8PXPrCi2H Exc=
|
||||
markbook-wifi.nlnetlabs.nl. 600 IN A 213.154.224.14
|
||||
markbook-wifi.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. SxAdBN/lM9g4cAVnQbY7T2RyDxtis1DUjQ26N3Vwz9DpjvO6gF1mVZBm E31BIoV0oqx/qPAUZ5acIvelMvnabqeD33eZ8PPSBjLZ1ozGli0hNzD0 2zAL+zSfV6A/Ndl1f0FXH3L8yQnCYk1xamgvrWSwOqB/ikpkK+F0fy4A 0fE=
|
||||
mirre.nlnetlabs.nl. 18000 IN NSEC motel.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
mirre.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. DXlYJ5kmPFQavM16V9QkoHZqHhmyTdFE/iF/k/RL/1NzZ/3G8gL+sXfI r1I1Ziq1/NrrYdAGkZTQqw3TIXMkqsRUFqpGxzPu8mKB2e+IGprzhtyg HanlZQLzQAecIo5iiVpoqK3suYgE43nBDnjbILCUU/uuiKCsqnqwIac4 7Q8=
|
||||
mirre.nlnetlabs.nl. 600 IN A 213.154.224.9
|
||||
mirre.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. IZx+IOx6mC3IZWWjdhAfgp8GGpYpEWGkx+IuIYT15ScE71xcP8Erd1Di s5e6Omtt0roZLOWMAFzC9gxd1n1E6nx9hyP8fYzSDaNsp8mfJhTPl5Of 8NEeGyZ/lBlWbxlBcaV0dSnllP44sjDbmLZqQBWhWWtG+Z5Of0Sqiahs DRU=
|
||||
mirre.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:219:d1ff:fe0b:89f4
|
||||
mirre.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. XEgipNwqEvfrpL2EEwBdGz4gtNMwJb9NQPrro1H85li59ts2yEH7GIGz CrSkI+nwXkNKhwf1NW7EE32DsGmYyWB6Ysg0+ISoeyx2gtlYh4NGVPav MrgWXYfg6p23w94fjfLGze2ADdcDpNmPSuz0q5zdLgEh5kSq09LAn//J txM=
|
||||
motel.nlnetlabs.nl. 18000 IN NSEC nlnetlabs-bit-gw.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
motel.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. n16G/quCXHjHTfhdMdZUf836jZSHkhDbDJZwB0L2UT7OppTMBRwWL2+E /Gfiza5HRYCdOUhx7QBKD/eqXMwbASDuD2wfxoNXHna4aYeuHn47pI+2 cijH4EFslnwzyNvcY0m3L/fws75pmE9iKw4+e92sz2h3Pp4YG7IM+wTg +2A=
|
||||
motel.nlnetlabs.nl. 600 IN A 213.154.224.7
|
||||
motel.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. cIVhYnVXBJoUll4z4y+PisMtJi9HAKQFVLN8yYK/dqkkK0FbMptChIJj Bqnoc3EghwIuGIi1sbAbn/dFb3Bsdio3E6mKsdBJ+Cit4TgqPTcQT05M wWMRKBNVkSVFLxisyAZCl78pNAji2DmpABtDVhHjI2HuhvFEqtUOUH4s GNA=
|
||||
motel.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::7
|
||||
motel.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Ekv3MGcrn16kes3koWHMfw6RwXIot/4kJYQOJus1dICT7Zuhrpbhps2k msSNHQ+/ziuJ0dvmkP4TBZU2rFHsYmJlzEv5qtBF6MMzQFH6M6ZgkDh1 Ovv3Xp5XBGfSm+hJMLtzoWmS8p/22RLogOsiv8RGiKCD+T3UF8TnRleU XXQ=
|
||||
nlnetlabs-bit-gw.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. OxxcW1xKbolFyiydndIfBIYdsb0jLL98VFEUsSaj2qstoLlRAL6YKORV wn/ssblwQsXqfdimVwyoNUvIdIO5rInbcqfBcimXDlvO8ihZENZZv4iw iHPxQ/Bc1pPTYFdHem+xfn/ih5i4oLLn6nd/v/0U1/immMWX16La86s7 Og8=
|
||||
nlnetlabs-bit-gw.nlnetlabs.nl. 3600 IN A 213.136.31.102
|
||||
nlnetlabs-bit-gw.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. aTs3q0dm27hE9RSCUXMxyqVXCH/bo18YzV1N31ywu+0uGAqEkhnwtZpm PNX1C/PJNbmeVpRlOR1oIJ6KV73Q8r9zA2/gWODlr2G7uEwed3Uife0j FRA4D1DRMIituvD3Tjb6UIyqV/qikPe2fn1s9Kcl0IpMJ8uc/HgIARnz DGE=
|
||||
nlnetlabs-bit-gw.nlnetlabs.nl. 3600 IN AAAA 2001:7b8:40:1::3
|
||||
nlnetlabs-bit-gw.nlnetlabs.nl. 3600 IN RRSIG AAAA 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. a4kVuaQbmEs7Ju1slFsv+6aLqkVP1r330aCF1h1c/P+qayNYIpWibQHS ZojJtgVbB2eid0xaYXCFd1TK5BBTu58SSNc9G7vR8U2WTkhmk0bvBeyc bVgMSfiPJsALtj5ID3OAkxtvO1ZusiVbKPXHeSFIXKFHJcRePZ8dox/n /jQ=
|
||||
nlnetlabs-bit-gw.nlnetlabs.nl. 18000 IN NSEC ns-ext.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
ns-ext.nlnetlabs.nl. 18000 IN NSEC ns1.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
ns-ext.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. OY+bcQreb7oTtgveymg0FWRG35NcEu9iBP8SHokm7NH2WtL5jOH7FZMR Jyaaq222Iv9TMcOEn2KEYqui7VaHkoQRS8YKchPHVS85YTDsjk7uULdm bZw6BqskiNKSo90bQDPBobvER41B3DGwvVUP3RDptNrEiMxhuIidGjOl yTU=
|
||||
ns-ext.nlnetlabs.nl. 600 IN A 213.154.224.4
|
||||
ns-ext.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. lj0ArLI85OQ59mhEj9FPnx2UYfTOehnql3nAG8uNmnGbeepyIKDi5QRf ZKp0/eyyBFiMmKHVxvvrm1z0TtOULb7nS5325w9KfS2JQR4/nHAQZrff HGDnqZ8wFWVdnebhAqKzYt8paqlRc4I7tsyYuFxmKGZt4vi+1DQfK0z6 jbw=
|
||||
ns-ext.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::4:53
|
||||
ns-ext.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. gKo21eKXSxeR+8MpSUnGVBt46BLOm39e0Jxolz4dc880hOiWlfNRl+3y vZTILWgTn9iLJ2wz5ZPZwuk9ae/EHqlIvJUx+RLZ+i7tCsMr7Y5P2ris 27Ar0I4aipnN0DIdXio8VQF0GCvQHj+lcFlqBcV0d0saM3ZsMNoZc4jW zo0=
|
||||
ns1.nlnetlabs.nl. 18000 IN NSEC nsd-xfr.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
ns1.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. mRQhMDYQM8/0Dkn9dplPnHqV0+d7wv/rGItfEYNOOu5HwGLmcp0D/fC5 caFMYtlfu6Py7/zNWrs7Ulwg0H0hfJhaQhHmxXRmf4ereFdrEiHEpgyN A1Uw8HsDOjOPEJTSbov2FxYvjihG+qJoiQWF+35qJC5/D0s5M6vXib0f 81A=
|
||||
ns1.nlnetlabs.nl. 600 IN A 213.154.224.1
|
||||
ns1.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. AJpm2iiICAWSAWfcyWSZtlywNWlLgMk3qH2v0OcLawL5GPd9gCOw38iM J0fwYKu34UF08Z7f+ytNA7zPGUFGND4Xhe4lQeYworPXh2SeMfggmWtB y9tjGGsxQJe3+ldRajSIP71fSuWsvcp/YhNA4Q8/pQ51pgrxeOuJDgOj aGw=
|
||||
ns1.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::1
|
||||
ns1.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::53
|
||||
ns1.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. mL6AM8KRQFBtCSy8V10Rjmn0j6PfWB8j8Af79og8DirJkUuIJQq7Oiy/ EaNGHHpThAwEvS/JwCZbFOezx9gLgEW6s/So7E+U1v4iMnjm/HrEQlpk aXcLm6sI3oNP46mlBuBKpbaze6m41wJZHp80xPCqEmbiBxDEdQzjUVcf VBE=
|
||||
nsd-xfr.nlnetlabs.nl. 18000 IN NSEC omega.nlnetlabs.nl. A RRSIG NSEC
|
||||
nsd-xfr.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. p4YKePcT1qhweFhgILxcioJgEgsQprIIpYXSSb1KGcWAizPsTB4VrWAc qBrHWL7ok1XMIUBZEJ1ukwjmWKdG2bIr10PLIRKpFQl/+UtzxRXqldJh 8W9rBrxvZnaQCSFCm/fBMk+TcH82F90EvLIG08Pbr0f8R7Fad1NEwsmG eKg=
|
||||
nsd-xfr.nlnetlabs.nl. 600 IN A 213.154.224.49
|
||||
nsd-xfr.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. HK3CIL/brGoxxuBGd7lvhUUZPt4Xjjs9bxoiiksCxkj7aGz8Kchi98tO sulv4HKGFV9CqzCtwgL09cLJOq4O9qg+WF/ZqbtJhFCLMgOq1hVE42j1 ZQQ78ueVtaBrxztyPHZWha2lgJKj0KKU8B9SJwdY+E6nXqd1lDWIEBtM 5V0=
|
||||
omega.nlnetlabs.nl. 18000 IN NSEC open.nlnetlabs.nl. A MX RRSIG NSEC
|
||||
omega.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. fcIj3rZIOYBdooN8hE/QzUMFm8J1uuwKPTqJpMU0QJWvvGNVZRI0oNVi Lc0rKg35xkW13GC51MPx7fiBOdYJHGVi0azSAtGAn358Q1BkekDXd7CG jMxlZ4z5DxMbdxcUpIIcWu1JGLI8EZ6Oog95CSA1987ya6H2c33Qn1Dr uZw=
|
||||
omega.nlnetlabs.nl. 600 IN A 213.154.224.54
|
||||
omega.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. PPGDFlV4KMJKObKpSIj5EamMQL0xN4jJ1ilmeaZiLyrf5o51sG2YyzZc InUOznjoI74m4I53uvyUuf/DaEDivan+5xHb5ZlUkQu+/JnK2zRXF20b iARFnKdPW8kNe3aWLrolc7XSpKqOXGcsDoa2SS8zSU3oG875IkQOUzwR 76M=
|
||||
omega.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
omega.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
omega.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. UtSt0IyUVg+SiHBNkaz8S7otj2rpqZJQuKJSLb3bQvfXPJ9vnPvJsaCo pVB+CxXqx1GqjKj00Sfq8BZHbDS5OyO1baLRVXTNBZuXcjSDBksWEoel cdxuMG6If2R1rRfZnck3cu4DH2s2eQvk0SKUyfewOjp9QBuuGN/SEJcU X9M=
|
||||
open.nlnetlabs.nl. 18000 IN NSEC pan.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
open.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. mxHCyGC0YrwXJ1EUFB4fEzxV9ZERmCJLkdiCYt3zrub0zzoUAmlRZkrq J+7/HHpozI5mI8NuSNYNHtbD1Nu7Z2a+JaHOgbmKpEXx+BiQjKmUf/fM 63mkv1gtWjluk9wLc2tk01H0JEEX7CrwHfLKX346i6/qDPh4Xa+Mf5p8 2z0=
|
||||
open.nlnetlabs.nl. 600 IN A 213.154.224.1
|
||||
open.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. ViuIpiw1c6a0roF+XCOSFMQ3BCH/qmy+lRcU0Y8jEeoN7vLu5rJlWUuF yuuU3kAx6RFB/XDPjxNzm2OER/JJSUUeagzXSqnJVL8Orj03RGpS2PAW 5p66uf5uMv34VEednxoGoigVHKIBfpIwYIbcaXAkDaRMMpw+ylRWwWee q84=
|
||||
open.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
open.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
open.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. bXZIS3/aa5cdXU2k2vYCbfVj/1FnU8sI/4zAP5HNNVEl5PtNj3Zc97yi 0hj0grLoBqRYpwKB1ZzIVMWbJ0F/Ly39kx7yVWfQ047t27cXUZzGRWKu 3gUITW8qsLVTSr4tj1faWofrWTUZHRjn+5eT7stFTMKFQnXNRnE9aLb8 OhU=
|
||||
open.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::1
|
||||
open.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::53
|
||||
open.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. bcDWQYXDf6XEyNFeYeDJZTcdUCD4hbfzEIMCL1Fap4Lm6FNSvACQ8c+F F48UfJVdvSZeczDKgsHSm7nte81qYu4+lBQm5TuJcMkjgJakHumKGV0Y 17wIJAsMPiacw+NNICweKO4x4RKwNzWgcn1ymktYsiaPIJpOxQCQVJcU tlg=
|
||||
pan.nlnetlabs.nl. 18000 IN NSEC pontdugard.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
pan.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. g126geXJj4BHuWcsmaG+gXMLh6qGya58U2gZ5KGIsLdqjyEdRUrwkwiP vOoXPFhPXYi3PnWO+qmCZF3+VZUYa4WDqGCHfkNtgV0VPmw0sTJvXN8q Y3I4ODvvYXwDSR0lzQvvZh5nXELGs6cMzEhxu9fU9ujBj0nA+3JL6V/t 23o=
|
||||
pan.nlnetlabs.nl. 600 IN A 213.154.224.38
|
||||
pan.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. KJ+uPefKJD2HIqt8EYCsIT24kVRszJ74XwBlvkxuLZZlBu9ld4MBqfaj JJWssWPFGGHVFaK67afa/t8fn+NL7b9uF3OCo6iWSOrFlVzXcT+huQRI yokYnncKdbk4GHWJn7vjfFjfgiNZT5cbdq+e3zp/NjBuvETcyXGgQbDP 7Jw=
|
||||
pan.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:240:f4ff:fe37:8810
|
||||
pan.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Et98q71wUk53WPF3SURj1QmAQLLVXolNVIihwSnZcosB1v4VtrwXIDGp JocHKH3gl5ixOrGFnXLSi0x5icJ/MEFRAEUd5J+CcXhAjMmcwim2mZax d9SWjl0bLjrcXrQNHKqUZJn3QouEkrAiP+FM7eeD4xJ8cWxD3OVj6Foh YYQ=
|
||||
pontdugard.nlnetlabs.nl. 18000 IN NSEC qubit.nlnetlabs.nl. A RRSIG NSEC
|
||||
pontdugard.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. H3nguVxothKIXYwrCGnsklJMK0eDOM9PLY14YZBucyT77GcXbrG8yUKy C6KztNFDWWMDWGF5yZloQVPqaBAvmTKFxPC2q5e/JrCiwmZfStcOgFhg S7IpIZOYwa9QBWmQShfsnb/2GJbE9H1XsvAtGw25BCg4j1CFeBDm+n7s mCg=
|
||||
pontdugard.nlnetlabs.nl. 600 IN A 213.154.224.8
|
||||
pontdugard.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. WfJXmfIWFVRmJxloj73JK/FMwNyBtXiAvDI2eX2BLBu6DCc4VqdE2sjn ObSE7wOx/28Nt5TL3ZktJkW+pOvxDHO0WE9F4GtEskSZdFSV0mV11xC2 dbn3F23+S2MpgNN0ZDEvYeZIcxvpYoDAbwEbKyd22efzcIv+A9dlH11n kPU=
|
||||
qubit.nlnetlabs.nl. 18000 IN NSEC roto.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
qubit.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. JhEWtMOZPbTlq3P7H0VZuGdLXVSxsTbpWe4Ers1zAUEKSZSpQ0UYKX+c IypwIOTgrRJLdPqKYeKWeU+/JVq0ZB2u0oc8fuxVnEfiR9yVILtbLwVv P4pgkzC/lUHU1GPljiqrLo2HngamQuIaznZ72FVrMIgFg3hZElHtturM /G8=
|
||||
qubit.nlnetlabs.nl. 600 IN A 213.154.224.46
|
||||
qubit.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. frtAaueWLxb2/wzKkY4ltLS6yf7NAAMLxj4d6e/VAH7WrhFpak1sqQxn lGXOAJGTlwE36q1EtIOlbxB7ugvd9m8QkMiPkUE8OsdiafGcGR/o7UYH /fTBuqhnU6pkBztENZb1e1+elBZo9+dvkB1NeVkoildpZAUkdy1eYz0Y IaE=
|
||||
qubit.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
qubit.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
qubit.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. HYpo/8yh+GsNZsy2jPGzr5ya/pBYNwXbcpIOboCQt3yRwbieodwn4uDm yftGeL5DSVsaU0GalM7OR98sGG5weXV7WlCccqAZq+SGLALyqJ42hXfi tdNSiq3/snDtx5e+RPKqe97z3jcbthm26SrRLxMdLtt5v0S0ppNGfh4v nX4=
|
||||
qubit.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:202:8aff:fef2:f598
|
||||
qubit.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Pqlh2e0tXkamkSPQuvEQNqbqVWsq0RSqdgYSB1N08M/Jbe+BiqWoml7X EO90ir4ug1gTF/Re0vtEV8cr3lRofhmpHXHMe3dcVoZ538Yq3Eu7MyGV /NsjYGgNj2ek4sZiTt75/auvU6grx04egDJn6gvvsiVt5xnEwipNnP0S WIs=
|
||||
roto.nlnetlabs.nl. 18000 IN NSEC sane.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
roto.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. GYigpeoLV9ax25m4mmF2HKWCbDT/flBZaBo8b8GBJ6RURaBr6ShcMe3J t645fVr6VOIAcNGDddSqqFOWvCIGEZhXSR7e7sjDJBKXVa8j72ANKN5Q zvfx5JDNxclWbsqiADgn6oYC9rp7KxvpqEUL/f/Yp2j7c4OP+xerduvf LWQ=
|
||||
roto.nlnetlabs.nl. 3600 IN A 213.154.224.153
|
||||
roto.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. kBGp41jRARMoXDaLWWUD4i/jrj8n52a75EoFJMOgsy1/8QtWl9UpzGcK P8J32u4rAj8jQTprC9eyLYTXwPp7ACfqmCCSOeec1G3RLDzxm1bs6xzp ez4sZfbcbBlqI/MQccD6O6dTxI3Szxzt9WEM067QwdgU5KcLI7+noaxk 5DY=
|
||||
roto.nlnetlabs.nl. 3600 IN AAAA 2001:7b8:206:1::153
|
||||
roto.nlnetlabs.nl. 3600 IN RRSIG AAAA 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. psSEF/+UXwZpCYqhQbHU89q/DFkA4odxlEcLZZkZmJG1+TFnOuDDh+FV MYFhjlZfHiWoN7tIhTqGtHHh04xrlcx5NVbnphZMqlZd4PBl05iCCrZb FT9AhsHftolVgH8fq29LVO3tQso8pbYw6MpG9flGT45rZzTU/eI8F3Aw luI=
|
||||
sane.nlnetlabs.nl. 18000 IN NSEC sanne.nlnetlabs.nl. A RRSIG NSEC
|
||||
sane.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. ZHA2sgpDy7DLxLZBn+4TWnfYIfFJTZbvr/qqSGKYaMswNUgsq5D0g3sg LS0721YI37qDtZNKA/6wLVO2epnKm0vzLDJSn40YUOMdTyCt/xXpV8p2 oUopbsQhflxP3AWNQ8VnsijhJQLgQhTdr7NEz8EHgHpFjgSjB1h4pDkM nV0=
|
||||
sane.nlnetlabs.nl. 600 IN A 213.154.224.6
|
||||
sane.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. NYHvgCZCpgAVe5roAttvnxc4I3ltRa/P/VHUofQgTRRFIGJY2FzcinYH 8CHRN0BEdgoCzNUGirHvYnbHin8PIqVgfllMWJ7Dtexz+Vl0RRyGqeUo ArVZf3j7C+z/kKpL8CYMk8WvSAVlXlPFqolUiiJJwwNzlsjrKqLs7fwE BzY=
|
||||
sanne.nlnetlabs.nl. 18000 IN NSEC se-dns-probe.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
sanne.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. ewVO7sU70vbby8VL52SZ+M74yy7ClyIH/R9oFbLI3O4OQ2iqN8YXR0Fs uf30tSI6XKYYzIjps1MLlK0zSL23PKwcZIOkK55icSrgV7TnasWkrvFD LigM1smmErxyMeqfrrwu8yGFdhpzHDvYAjqiiVRiXJNRaoLC0GkOYEfQ eQs=
|
||||
sanne.nlnetlabs.nl. 600 IN A 213.154.224.39
|
||||
sanne.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. J0HE1rZbC4cPBVt2gmiFBoyE2s7PyH52BkIalz5J1gBD8xTo6Kq5iPO2 zqk7aijDlbWAvgaftzyKwab5WZHdBJEfZ1wMvlMukPd2tRyiBfW/Hqbi kJf2SzAvUOipAUHHomESV2cO1U5OAbYvFMR5syu9WD/+5xjsnGabSLjK aFw=
|
||||
sanne.nlnetlabs.nl. 600 IN MX 50 sanne.nlnetlabs.nl.
|
||||
sanne.nlnetlabs.nl. 600 IN MX 75 open.nlnetlabs.nl.
|
||||
sanne.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. i3YmK7bxxz37q5NNfU5f0bPoO8xHVOC8xbzngXsieqfKsJEty5PPTDRZ f7opc7Xe/yMfU3IH/ZX2C0NJHxI1GwWGe0mRs5uic/gHJIFMqv/XUvjB MPZKVnIeSSa8fbfOBgHOpjXCXeEGVhHEmRjfrcePTIz5/eNUmPpaQZ15 NvU=
|
||||
sanne.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:200:39ff:fe59:b187
|
||||
sanne.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. mHVDCixUCNsdQoWtenWumJ6jYi5KOYk4WSZBZtm2QOBBVzyY9R6nqIZM HChCivztLR5lLdc7sO4aGekLxko5MVm6nZ+AG2yz2kIRNhxqyYYbWmD2 Ta3QGXz2RKiiwgyE6d5xk55sG9lEHhngwfItBgwYLOvrLVGIdjh8UmGF PLg=
|
||||
se-dns-probe.nlnetlabs.nl. 18000 IN NSEC sixgate.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
se-dns-probe.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. E13fsWV+gXja+Ynt5/fc3ry47LyHBlCuUC74XjWXHGSiCY4KaaWbmv1Y LpjCvVQz7SKXyhL20el1qQVQZkDqfDUvtJKThgJpVdIlPGVpfhg00BMb XaD5UNIzGvsEUPo7cNqPswRvGU/9lc9Tn7z/Fwvikmj+8bL3SbDQPQlk mS8=
|
||||
se-dns-probe.nlnetlabs.nl. 600 IN A 213.154.224.5
|
||||
se-dns-probe.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. jKPpQ5cpUdFh8Dd/VHwN6geBBiPRi4tihr1/FMZO4enHbzmwHhtuh5ql qaZXn1hySLnNOJ70+0e4Ma4DZOsvuapGY44lpuQ49qGbu5AgpxPH2bUZ CjrsVnHfoifhR9c68GhocgjOQ9PS59/Ec2Ej/DF2rMFXFD0aF6bq555f ldE=
|
||||
se-dns-probe.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::5
|
||||
se-dns-probe.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. nh/86UHPGKcVw6nmQT8fYUplqtl5SzzKLYxXk5SsDl1rpGg6iHMvl3nz X/UnDXn7gMa4OQPEg4oVz7ZBjmBSuVjIjM3LoBSF41zZscBfjSue8HUE YIkOhhkJYvzR/xAhjnA+aAjmldtZ7HQYo1XfgOjwx/rh6asIwDtS4TxY 7NM=
|
||||
sixgate.nlnetlabs.nl. 18000 IN NSEC snom0.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
sixgate.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. p9SYrNRZKAcvnrFhk/oJVuVAJMRmlWuyijhz1ueoMrU0zslFqqKOCG1e HcuWVDLjjn8SV8nAak6uEZRWigjttjXLwl1uNenKUtt+pp5vo16a1Eff bGhoN0R4N+Q9yzoI6zfET2y7R+HrYBHOlVkrvUwGFo2Sliupi5b7kumr gdU=
|
||||
sixgate.nlnetlabs.nl. 600 IN A 213.154.224.41
|
||||
sixgate.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. eBLYxx2wU5FyrLCIJqfWpEyUh1omWfqb6d++s3tQJWtbL8jV1E84Erde y7kphOsn8w9ar/ytcVg/k99+664FNTnMEiU8blJnLXUzBB97sy2irmS6 P/2TznKYEIce6kOyD99COJ6D2+u6SHCHEKKBv2G1RIGLyQt13aPiQkjk uXA=
|
||||
sixgate.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
sixgate.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
sixgate.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. KL+o5qDn8O69KadGbacCGLNYRkcVdrY1EqEGCib0AjVcemRyl382cqhP qUQI7Vzlr+dzRz5YON16OK0GOh+j9yBBUeabF2kZoZk/lzS6fojNZrFl Q3aE/sqEygYcKtuVft21Bg0W2v66x+mpYd35jbZbxpgg6K7RW/ceH0u7 rEc=
|
||||
sixgate.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:250:bfff:fe5e:33e0
|
||||
sixgate.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. aG4F9+Vx3wX43Si/iX+J2036Tz8ja0DkJg4+/G+0suCM/OHDFZcfR1Ne zxbwgdhXY74FODdYaz7JuJDUpYoQNy8HA0eHLaXMTPEjzU/C/YuePVrD DJjHEb2TpNapjD4BKCqXDY+OaQclPLdPIoOHkAv7I4DRvn/8qwUHK/Gf 3Fo=
|
||||
snom0.nlnetlabs.nl. 18000 IN NSEC snom1.nlnetlabs.nl. A RRSIG NSEC
|
||||
snom0.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. puhC3IReZ0U31hWvtWLlSrMww4BUf9+ExNAmQY9+rAOh8N61E25qmsSl wOveKfVIW/EK3d7Ld/DDcYEVsoOKcOXrSZ53SVUPFpmdx6FNPvkWkbjT LzwUspdwB/L1Ox7T7yFMvFAaubq0TzbEcZVnZlPxPKwGqw1ABgAT/FzP oo8=
|
||||
snom0.nlnetlabs.nl. 3600 IN A 213.154.224.200
|
||||
snom0.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. kPE4amI57Hk6j+HLuKUzwYgj665mCP7klFnt2Ty1rjbBACXJDrzbgm5k Wq9Ee8OfpTrALro6qFhry5TSFkxA/46KADTRNtYzOHZvHtXJx//ZIJZU 3oBjnMbNFEGKQ7NUa1TmTg0XtKmZkFk45hiVsXEUTkHJ1br55Sk9ZN7P R6E=
|
||||
snom1.nlnetlabs.nl. 18000 IN NSEC snom2.nlnetlabs.nl. A RRSIG NSEC
|
||||
snom1.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. lsp1olju7Z38jPpBQ+TRPttAHLE/QU6tm1iRe8F5DAZVKduUCFtz4qsN jbCD9B5iWuhEBwPZ4+LLQi2Ga27OEioe9k9kFeWuF2GBSxYjSCOeczIr s6gGi7fARK1b4x5HoI5JrbwW8zrQ+y9lu/dwrXhFyPOX5SgQSwqLNUo8 qBM=
|
||||
snom1.nlnetlabs.nl. 3600 IN A 213.154.224.201
|
||||
snom1.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. COot+bPSyihBf9iTeChxvIfMYm9a2LH9eR/kC2bmp64DIo2OhO4W58WJ CcDh/KzW6mtQt2PMU7JW8FwWHrRfgvScWxfcQGl90nlnWrb8I0VaZuyP M65WPwxB+xqCs3tmnN87m2jHCL9eWFXg7yCPPDTRJPDr0OZWbeQZXb2e 9F0=
|
||||
snom2.nlnetlabs.nl. 18000 IN NSEC snom3.nlnetlabs.nl. A RRSIG NSEC
|
||||
snom2.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. SjUDNgnAwaETHAovXMHWVFxcNTFn5+JKqcnk0SYEzIXZiTcfbDGfFE5b hGMVEwKl08KvsHCF9v9ckb+RfL9aQOkRoUEjxnsqU9L0J6WWXYv0CWld 46GFG9Rm0IbiE80IY4KMfXW9/sAbv8anDqhWLm3yHn5Muj2Al+h0OjSB kvE=
|
||||
snom2.nlnetlabs.nl. 3600 IN A 213.154.224.202
|
||||
snom2.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. DQ9hFcmw8bXdW+TX4sTS3y1qPMUOzfzgDRIqCDu8oIiARH102rNpuB8E +JJT2ziaGgKjyfsVxJQldiBMIIvGagLIR0ArsJXThxtlaiFDbQeqZSZL +b8xqQcTDOhaU7xAC0V5cRYfdCYbd5sMtVx7XYQggX/Mot5Zt6oEOg3i msg=
|
||||
snom3.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. PJyBfD+TVk4JjyzUreels+5tWLmOOZg9Of3uklVcX+GK+Q2hCtU7yyUj k2mkeMJ731V7zLQXZGz+1vC91WtIVXP6tlY3rr63nMtj3jb1R8WWqY3/ 4O2hP6d6S2OEyuESuGnIhVXyZlPunzAWgLN53Dnzb+xn8KULe+iy9Sjp uH4=
|
||||
snom3.nlnetlabs.nl. 18000 IN NSEC sol.nlnetlabs.nl. A RRSIG NSEC
|
||||
snom3.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. j/KJY9y9PZIoSnAOzRkUbfq5PoUeSPW/Dy3d7K7HfVlysfJ+I2DloTPs 8CssOp/oCdki5EUnpnn2ym1csJTKZdEl6MSfDGMT4BP1W7FK6RDpLO6z ehQj7yKs+Pbr1nBq0tZWlr/HUTmJY1VJmnj5G81dmazesufO/9wDKer+ TCo=
|
||||
snom3.nlnetlabs.nl. 3600 IN A 213.154.224.203
|
||||
sol.nlnetlabs.nl. 18000 IN NSEC sparc5.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
sol.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. jUXNRrMfRHbf7p4KgbdVI8WsDMC8k/1FOsO3BoIjSyX22Hr5v1RuKHG2 v8ZDlFXMbKcP92xdj3mAJbEmcM2JKvaHiY47VrweO+FbwY3JDgUkTQmH jf3SMOHXrxtKjixQOAJKOWOLDigEBBLkuUjdfG6PybDDG7sBgx8WHFIE Ulc=
|
||||
sol.nlnetlabs.nl. 600 IN A 213.154.224.43
|
||||
sol.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. XEkjh4r+7asDkk98LEV5mlaIFD/nUvfP1eUBKVTfh4a8ba4W5sLo6HgY Y6sJcnaBuK0a4IDv2q2q/BPIokAcg72+P420oRD2vQXUhM+fgxVESJt5 AqWrqRetmctCOIhWuNhOYw1PlCT+lZ9eT5INhXAscepQyyjuAKQ+nQFK qW4=
|
||||
sol.nlnetlabs.nl. 600 IN MX 100 sol.nlnetlabs.nl.
|
||||
sol.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. gEqhZntMOkonkQ6ONN1fwqOPf/kp7XGQMsORg7MPEt8UUxfkx4FlIZSc uQU11EfLr14BE6zkPZj4i8927KmfWK6M2I5F9WWynq41xDPO5giI7nPQ xX1d2ga2Oq/kCHH5Q3DyWmXTrdc9JpbwKIQLdtPEmAN2t2VslSH77M2a IVE=
|
||||
sol.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:7200:ff:fe00:28e3
|
||||
sol.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. ExX2ABe4l4kOkFMeexofV/KE9u+XWvQKpdXtydtawymAz++crBdrYCUj 0tjDH8f9lUJEYPc/M0XUBj0FXrEK/OGrHREcj+U4dA4PfbKdCshp0+Ha jDqNigaFhwtXlRxwaaVX2F4B8y8WTOMpLeLA8GjH14gnC29TY/Fu5EAy rzM=
|
||||
sparc5.nlnetlabs.nl. 18000 IN NSEC stun1.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
sparc5.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. ZGKUwlLbPYCQqGZQzUwaZUU7C89Qnq+7Uyo1VaPmDNMYLLxmi8RaRJKG SzNBDmr+om2MiEV68S4zkwj5aZ+IYB8cvvjdq8ZA4walYg1O8cf0OMFS A03lAnSfWiu9Ok7SryjltHfWZbEmS1bfhJQ7QVznKuIrzUbrx0giGxUl G7A=
|
||||
sparc5.nlnetlabs.nl. 600 IN A 213.154.224.47
|
||||
sparc5.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. PqrRrkXcrTRXWSbrT1JZ9Rvt80SplTqpVgOlmLhe8qIxz+DiYdlBdIv9 bmb6orj1cLYG62/hWuGaW5UHpmslp1rn3LgrZCVbWS7JpULLEYs1l+B7 XYnRRGR4LlQ6cE1fZLbT55k4hMCnv+jYcto+gYDcp58ssZy3MUUyno+P C50=
|
||||
sparc5.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
sparc5.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
sparc5.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. G8cIIEKxLSh+Ql+OxYSCDdaeJ+iLreSS6DWLcgaMSXY+O0qXiy/avUYG IunyJyp95PuIle9OS6s3CpRTH7ZKcC7v80uAeBjGkwliIMaZc3L35x/t epNGGkw2FM2G0ZZCOoH55nw8CT9RHoKtvtXsr2A7er4gj2gLsk6sNSpo jqE=
|
||||
sparc5.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:a00:20ff:fea7:8f78
|
||||
sparc5.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. b9woyIw2bKMA3eJCTurjgBi1/3Er6Edgk6nT0iUBfzhv/qUK0K4ROor+ 9UkenclArkh2lbDHm/ziqn0z35gNn6FZUjo4L2x3jZQggxOuLz9ZhmpP es3eEArPU+c290i6NGGytrOmF5mh7S9h5nVapjDIPqgSBq7TtKBJ89wv ayc=
|
||||
stun1.nlnetlabs.nl. 18000 IN NSEC stun2.nlnetlabs.nl. CNAME RRSIG NSEC
|
||||
stun1.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. HFbzEeDw66ot0Qdm4S8z2YWJT3tD1HlRPhSwV/yN7GnJSQqmD4s6tUkz ZCyZtgcUNUwzm7ntIUMzD/njEiMCPWAR7SMoSHEnfLYlCx43GyiTDf8E J77Do1l8m116gA7sGnj6aPEsKrq/E0ml0yZn8sxRLhWEgxvCiGrQo652 e94=
|
||||
stun1.nlnetlabs.nl. 600 IN CNAME johnny.nlnetlabs.nl.
|
||||
stun1.nlnetlabs.nl. 600 IN RRSIG CNAME 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Vfy6Magu59sn5mCUs1qf/6FghANc01hJ8kpFzmt9Sxhowf+xpuJnyG9a lsYjYHhzvjpCv1ys82aDlN4s28ILOt7sbgeBTfG30VX6F3WZ3A7EtWS4 4ZTEwwDvV+c5x/mm+HAQQCnz9LGuNLF/9rQOprHmEivomWqnp4sXRAHs TyI=
|
||||
stun2.nlnetlabs.nl. 18000 IN NSEC tednet-gw.nlnetlabs.nl. A RRSIG NSEC
|
||||
stun2.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. YQJd0U7xpSZanBGsDMR5o3Sim0aU91L52cDVkdG/mgfkOjJcvXskQbyb 39LQozpAas5PeBvQ6xK07KR0nza4fmg1882Nv5TI38CktrdoBO0m1oDa Zj3rM5MwxAd5jClVIKuQ3Nw0DsTLR5Tlm7IVPZMPrWUJjO5QILfjWXMH Ny0=
|
||||
stun2.nlnetlabs.nl. 600 IN A 213.154.224.154
|
||||
stun2.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. ZxQ4qsRBDOj/BK800jqNncEQoyCWCqkZoT8VUmZOUdnUXv/pOQg3Fe51 a1/zeeUq9D7CPs5O8DV7OcYZSFpJHEA/GIBE+QGMT6wIdtlDl+lyvfOc lQnV+sf5t4jCexh/Mv/fSVgceO6aSqyiWc1jzQ/7kluQ/+Jk3RKJq7PA WUM=
|
||||
tednet-gw.nlnetlabs.nl. 18000 IN NSEC ds10.testlab.nlnetlabs.nl. A RRSIG NSEC
|
||||
tednet-gw.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. KKnPYYlzIMH7atLRWHIQMUim3GnfSQrpkRE49/2NeHcPuEgcSJebOf1l Ew/NEBiDCQtHEK0aiN+sE+nZ3tqdj951Ub9N332nKg98cNIqM5FVTcPS 8C5SrTH83O/xyhLbOYSJd+eOsuGlrmF0dnV6uFwC11DwGEp5fAtHXQ3/ SAQ=
|
||||
tednet-gw.nlnetlabs.nl. 3600 IN A 213.154.224.33
|
||||
tednet-gw.nlnetlabs.nl. 3600 IN RRSIG A 5 3 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. jSPQxVwJ9Mks7+EAAYBrFkEmT8Pxmv1Op6AFldVRzsgNUh8AZYpsTqiO AH49+sbG8ZjHLSSKGdd54PGxPgTvF+h+B7NpSzpnachWIgczbiAejgsD X8EDS3D7JArouSl4/FPns2JKOJXyuA2vipB9Q0hota06O3s3T3VkOJLV Z+8=
|
||||
ds10.testlab.nlnetlabs.nl. 18000 IN NSEC listener.testlab.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
ds10.testlab.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 4 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. CASiMvLsgqAkq6WIOqPIAtjAmi/fcd9mNCxJLgeOuyDrd6r/gbUTHky2 +sU2wYwpM19ThHyb+SLYTqlU/hI1dCpxMGVm5xf8PN3dINSZJFsKaaCx 01fg1j9LaZidOTLu8AtJqGH4TU+E7H7wvv4lvBYwwGejFHpM2r43CxIL DA4=
|
||||
ds10.testlab.nlnetlabs.nl. 3600 IN A 213.154.224.100
|
||||
ds10.testlab.nlnetlabs.nl. 3600 IN RRSIG A 5 4 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. e9iqEEVgfnanV/2O/aNch3vIYbaAG4hvub+/UbbelsXDyADWfcVnunWU kF3WIsxFSqaZIQxAlHyIcK63z/jr+oDaGvPFmZcFE9cIU0rUlRC1GkVA pqNHcXRMcsPVdkX+kF82hbdy/CVqVGfEQfigcQq7E1bvLhs7ir+ckcRR 3gA=
|
||||
ds10.testlab.nlnetlabs.nl. 3600 IN AAAA 2001:7b8:206:1:a00:2bff:fe86:cdb3
|
||||
ds10.testlab.nlnetlabs.nl. 3600 IN RRSIG AAAA 5 4 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. bWxVt+4GHXW2RIv5vxVeGRaDpI5O3wKoUoj71Nm+5Dx8ffzM/ZtcQNKs Xch2H+MowJ4EMqfct8YLufxFp7kv3aTYP7q/bhCk9PoxADSUVnZjs+Zh gSTTpX5InphKFEeT+JIg9RqAyYxMOSfjXU3KRI/xfWtzJ3VgYExVh4i5 UUw=
|
||||
listener.testlab.nlnetlabs.nl. 18000 IN NSEC player.testlab.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
listener.testlab.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 4 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. dDJhcIcG9y/kF2WE/EbDG/5NKtY3cCv6VghKzv3gVnThDg24YwHq1x7s 3cGRzI6l1PpNAEBgim7Z90W5lIlfQfcwknDwh5fSZ7gD74KyG8/2I6SY EMTfW9P+cyM34Ujk8TwSlq0MLQYtElzfEkps0IC5nVRYvyRJYSzPOR51 y7w=
|
||||
listener.testlab.nlnetlabs.nl. 3600 IN A 213.154.224.98
|
||||
listener.testlab.nlnetlabs.nl. 3600 IN RRSIG A 5 4 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. Sj5nJWIyGIuURQTGhIVfxNG8DqKDcTcwSRxWAihplSZ3gXdyL6M0qePn y23qlmj9H3DugndOol/vmmtDOUrAqOUTK3uKXeNuhJ8bxS5AN5f7PaJE CMGDMfvl9XTw6nlKF30ufpbXXlfZ26TFhfXjFmNz/r5H285kF/mNU8bF rX0=
|
||||
listener.testlab.nlnetlabs.nl. 3600 IN AAAA 2001:7b8:206:1:42e0:4cff:fe39:6302
|
||||
listener.testlab.nlnetlabs.nl. 3600 IN RRSIG AAAA 5 4 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. PNZSXJS0xGP65+wQJtG4N8mBxeorUEVv8pRs4FtFqXv4wDvcnTpgCT4d 449V7gjlPk2ngQK5qpy68CvDVs47qrtfpgGQKOfNxeGpQbGsUE9I1114 B+38q4NUQldGGzzBQIxWBIlJnUVABPjAAyNVeSLVREVUp0m8wzsR1HQt syo=
|
||||
player.testlab.nlnetlabs.nl. 18000 IN NSEC rotten.testlab.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
player.testlab.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 4 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. ICq3/OV9Pb9yt+dMASSV6EGiXZulQqsCYoWpUs3a+ZKHVqS1Qepi0vK1 4s/mtv0xn3z/qLDzUjB3UDH4ezo7WZJILQR1W0nVdRj+baCqnR/QfA+4 Y4F37cs8qfrT0neIpSyCzDEdlMaLext+OhyhYP2eQ/17NM/OFJiMavjw OXg=
|
||||
player.testlab.nlnetlabs.nl. 3600 IN A 213.154.224.99
|
||||
player.testlab.nlnetlabs.nl. 3600 IN RRSIG A 5 4 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. F7/bPM5B1Ye9q1urMwT2DVH5u9K3eyDau20o/Zx272aXLkJP3s3fbjhB cUtQz9DFs6MLVthN3s3BN/2+JS5XsxqGeY2ypjhlpWxb4j759gEe79pz 188jzliidXkoTxHotaTfE4z1SR35cS/nfBbMEBLILgkC7TmQpXdh9WdD NQU=
|
||||
player.testlab.nlnetlabs.nl. 3600 IN AAAA 2001:7b8:206:1:22e0:4cff:fe39:5e05
|
||||
player.testlab.nlnetlabs.nl. 3600 IN RRSIG AAAA 5 4 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. DuuL+20G6fAgD5VFMvDHTAm8hKxgvksDvsQRUJ8yT7RpBh/VZQKzpPR/ 0l9FeZZ00dy1x/QSdPTo56t84SUGdvPh219zvs6ksmg4kXfyZquv6m0f 19IoGFX3myQ//aKnE6XDI0jvZekKmY01NXEdC0ujZe06VUyHxUpR3bnQ pek=
|
||||
rotten.testlab.nlnetlabs.nl. 18000 IN NSEC server.testlab.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
rotten.testlab.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 4 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. ZQqczzsqR6ob3f2ldPcxxUFwMoJHygObZkL7XqdkpuHV4WzfA9rw9wUZ FYi5dE3D+2sFPDY8LGjPyd0DqQswDdi80eecv/ZIROiL2ka0buFsFo9L 93RoeaB/f52ilAuvTaJUie8L38p9G9w0g9HljscUEbBhGUSzvB32fAbw SE4=
|
||||
rotten.testlab.nlnetlabs.nl. 3600 IN A 213.154.224.101
|
||||
rotten.testlab.nlnetlabs.nl. 3600 IN RRSIG A 5 4 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. bDraapmxqrCuAcoLuAKxYN646POaFATJa+YJ/ZKSgCJC7efwjVzWAqvL ga3gR+uGu9iRUzQh68OE2IYOgxYtGvG/lkMYBfTcreO6NbgOnFCQ4+J5 BpxucrvgQxz9tVqyl84kG+eZiB+ksVF0FQRYhJxxZUqWTPcMtU2p1RTU dOw=
|
||||
rotten.testlab.nlnetlabs.nl. 3600 IN AAAA 2001:7b8:206:1:206:5bff:fef2:ae8b
|
||||
rotten.testlab.nlnetlabs.nl. 3600 IN RRSIG AAAA 5 4 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. EqVqCWsRTraX6Ykw2L8WOSnV3GG2Ox8T5fh/nHfBX+Nxp8fJJg/CE9+q eVU7GUyqzmobFSDrwc5O9cgtR6hJ/ZP4g2TEWob9TMIguCXByjzq6zqr 8SPn0WXmJV/hja4GnnEM2oe4AZxu1hjWW2YVCJ/LdslPyPqLDPosFcmz 8Fk=
|
||||
server.testlab.nlnetlabs.nl. 18000 IN NSEC tinkerbell.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
server.testlab.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 4 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. TKWHK663II7q0IcML1dy+PsMLYNnrOg9SeXCpgsP8xYsiFHWHPrYViRY NC+tJj3G4ORrhp8qgSi5Zb/loXDNahL2hHsqfs3vmWyONMu5zysBtfC7 BO41fRBkDtDzxQchfpaII0DDNdXzMN6rF0/tA10zOzbetTOrAzdgO0aM h44=
|
||||
server.testlab.nlnetlabs.nl. 3600 IN A 213.154.224.97
|
||||
server.testlab.nlnetlabs.nl. 3600 IN RRSIG A 5 4 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. jYUS4vthWsYDgB1Ks8vOx9qI7mcvLN4YdMb1UnUUMua/jWuZ3j0flmTJ n0oTXWuje5Fnyu+ZgpNAbR2/TgrP9GGwFbnvLcye5lcz0tSK8RQpja7I nVmzs+BSN6YgAmmNpl7hA49ofDPmxb4Uo+ykfh6DR7lPkgec1KuXC47M sFw=
|
||||
server.testlab.nlnetlabs.nl. 3600 IN AAAA 2001:7b8:206:1:22e0:4cff:fe39:5e02
|
||||
server.testlab.nlnetlabs.nl. 3600 IN RRSIG AAAA 5 4 3600 20070912141341 20070815141341 18182 nlnetlabs.nl. a7mvvRN5wAwqObak5JMtWLrMyLCwDhB9eVZCON+nIE478i2WcuPFxWSx XYiOZGiZq7OwIBU7aO7BwaBMKXqNokbJqbwE8KGvLMXgnWQgqlUCHRBy 2YKD9tsFT5xCtaDcSynBlMri/z9Wk+KXxlf58Adj5yCIqTEGueT4n1LG QhQ=
|
||||
tinkerbell.nlnetlabs.nl. 18000 IN NSEC ufo.nlnetlabs.nl. A RRSIG NSEC
|
||||
tinkerbell.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. FX1z7mozbIq/4PufluGQ6ZVirevfKu8nZUHb9Ol4DNAD1nIu0v+teldL Ahx7fHpmzcYrMTA1n9Kktsim8cTd0LizMTd/wwWb+syExqNINZ1L20p1 nvIKzl/Razv27HKsY/kpiBUK7X+TCd/xJnFIO7D2JzoGjyiYpRGiaqef XxY=
|
||||
tinkerbell.nlnetlabs.nl. 600 IN A 213.154.224.13
|
||||
tinkerbell.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Ws7cRR7C2t+njlV/zBhVLfYPJN2l9fWOn97DjcU0sB6hT7r09cYIVV5u 8RTrH5UgwaboSqkImD+0LlbNte9nwcJS9wP3sItg/eO6eZyJ5NGKm/Nk 4KrKV6J1Vx1Ms+EtgzFhxYAiX4ThWBwZxaSNEDVh3ZCA+dAucURt315h xF0=
|
||||
ufo.nlnetlabs.nl. 18000 IN NSEC unbound.nlnetlabs.nl. A MX RRSIG NSEC
|
||||
ufo.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. IgEV6H97KEnxkNdhytWMjmtbXYerO61AqhAhDeD6J8iakPf83SqXOE9R ExwFmiSeqBRe+y/YZ+wVxLeWOU6okBrP4L6FAg57X+WVNNa123KD4r4j CMNR2hxXtFMjvvfRRPdi3i6JtTl2ygHJpvMzvbqJc2BrN7zdaGEG8bDU vQ8=
|
||||
ufo.nlnetlabs.nl. 600 IN A 213.154.224.56
|
||||
ufo.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. mEc9varsLkWC5CCcQJqlSK1Tsk29Qfo6K2WzGQCLHaX+hhy83NbkHSss tYqXgpXNFUcxHRTmPoVofzlHFEkD+/5U8PxFEnSOI5FEfBbcYlHPSr7v l+8AJBPKXlC2ftVr7my7w+UhzvAODEbXxhveeqe/zJfeRImr+lJlANpk /pA=
|
||||
ufo.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
ufo.nlnetlabs.nl. 600 IN MX 100 omval.tednet.nl.
|
||||
ufo.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. K2RffkDkyKmII1DVIgom/MeplVYzo6HLYgm4bbwbGP9y1T41XDwvgnvE EBI7OO+Dcz4m+adtIAD6/adkKYEQnqymok/BK1N1WArMtXXPyotRFOK7 UlrbYIFiIDE7GaVJsvJH0jyCDp8/pAJt7m3WLmhc579avWNvIPNqRAB7 uM0=
|
||||
unbound.nlnetlabs.nl. 18000 IN NSEC viertje.nlnetlabs.nl. A MX AAAA RRSIG NSEC
|
||||
unbound.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. T7VzMgdNSmXjZgw5VI8khY6k71BfeOH59r6vfHQhdlalMpALaDWYN6RD Oloslx7lLucA3ZrQ4X/RPwr84ZrRc0K0sH61MyQtuzyeiIWu8ifK7KHG yuxLYlngZx0jWsf2DgJuUaPaU6tzLLccfRJ0xZbbbv6TKL3sTD+EGSdI Wkc=
|
||||
unbound.nlnetlabs.nl. 600 IN A 213.154.224.1
|
||||
unbound.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. euqJ/pC1YAuQB04coh1qWAptIkgfJDcJcGcKHH+bCGy5NK/IhEH8SKQE D0WlSD1pD+ibmeGQAi2be8eF3v2bHLog/Gm9wPjpxRj7lLkqtVxrXmyO pO6w7S9xfncsqJLkyyDhOgdg4/5LKghb6WAzkPKcMOd9GWLmVPdYhZ7u Pa4=
|
||||
unbound.nlnetlabs.nl. 600 IN MX 10 open.nlnetlabs.nl.
|
||||
unbound.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. YxVXw9KyfAmxJqhIKh6L2X2cs6eUnQNlo3xkenBPZW1UjEne6I4H0nbB hXWc4hWFaADJjLEJlXu0NoYTIsSVafynu4knJfmNiUykmWc2nqUy96R8 1qmQ+TknQ93qW8s/2LA5Maf8UjHqFhbZbX/EpGxlVFEc5WN1nNwIiSH+ hwM=
|
||||
unbound.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::1
|
||||
unbound.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. BwPZseI4zk7Kh4JFKGmeevVKIG4FtLVdajwGWluOk9vhC7Hv7jbEbO+R k/pfkJuibHy+cx0Rv72sRM6vK86G7WD9PsLseHJvCupXOcHB/gfrftfq kSRyt8bNs+XZ2oFVLLj9MkksbuJt7ZrJVhYneBUGvDyzDOitIhg6aIDt oPc=
|
||||
viertje.nlnetlabs.nl. 18000 IN NSEC vrij-2.nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
viertje.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. KDdYp63+Wl7DRcwjA90xwSOqZUGQsZnqweopqsaVhZ3eKz4seGnihRwh oXrNVJlAZpsujIrTZwfh9VbzbATtaUciVCfE4AjGdXxsLKhEQIGjExau XyFgCmaT4/kKc6d9Bdxhw2Lan2cClWQWCtlUEIDyoAybtwkmO5zU0Pil EvE=
|
||||
viertje.nlnetlabs.nl. 600 IN A 213.154.224.62
|
||||
viertje.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. fldcX8mF5FC4YxcoPgOmLhGmW/TTw5MVLOwK35aItqemNfXwFglbuJtv KiW3Qdtcr5g5iE5xkDl9aCJRYlfAyugYgJX+AJ1WkO0nfpSUUbulOnRN MEZImO2EHsyA3JQCEHTZ+J8xfYQJ87rfAD/pRXbmh5TW+wiXckNflf4J rPM=
|
||||
viertje.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1:203:93ff:feea:3086
|
||||
viertje.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. hFGUoyGTYcfURTEKx0qFYaJRBqzGeuctzC/rVQqLGTx0DhzVxNUIJN9V Rqj79FQXQ3S/XxOANmk14Y78HZmykUcARxCDDZGjgGrMTuuoQpYiDCdD FRhWWXr0/uS9yl0exj9Xo7fTIiGHe+d57CIuy8daJuxaBNXvc5+OIiyD U3U=
|
||||
vrij-2.nlnetlabs.nl. 18000 IN NSEC www.nlnetlabs.nl. A MX RRSIG NSEC
|
||||
vrij-2.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. avyjH0dMBtuhwewLd0ZIy/m4dFJCqdD2sWhq7X7s/wHIf4A3sSAZecFf 5Eu0gtyKkX4cIhFjrPzj6NTJPIUZmkaEAXIsmJ6sVw58+Wc6dP0E84d/ WQ8vBkpYzoAWVH5p9FDyax/3jNmn5U5KAqraOy3UaihnbafpmyR801kz 0uQ=
|
||||
vrij-2.nlnetlabs.nl. 600 IN A 213.154.224.53
|
||||
vrij-2.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. ieo0tj2nMObHvje9Zb8KuhHzEE7hAo/d61NovqrGEe3MKFZ1Q/m15bC7 QTXZpuqundT1cIDPQmc9nA7vC7dX3JZameQ1j5QE3GSiNuU5xpFmnpvc KTBQbSDer+dncn/A3F+qY2HjylgkzMrmxRRSxOjexVIYCjFbtUvYsiAd KRk=
|
||||
vrij-2.nlnetlabs.nl. 600 IN MX 50 open.nlnetlabs.nl.
|
||||
vrij-2.nlnetlabs.nl. 600 IN MX 100 sanne.nlnetlabs.nl.
|
||||
vrij-2.nlnetlabs.nl. 600 IN RRSIG MX 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. hwamqP2ZCEhBO5Wn12GsZoKwxkmhn7J0NTbsuYKF2Vk23aPlV9qc7yfR SnK2G4y33dq/omt6LxN+29Sd+9lcu/Krx3rlYd5Y/dmu2ZX/SXX+XVUY Iqla+LwyYe6UWhG1zdvtD5UHuBBYocGcGud9amqFXHo8Q7YVded4AkoC 1BQ=
|
||||
www.nlnetlabs.nl. 18000 IN NSEC nlnetlabs.nl. A AAAA RRSIG NSEC
|
||||
www.nlnetlabs.nl. 18000 IN RRSIG NSEC 5 3 18000 20070912141341 20070815141341 18182 nlnetlabs.nl. L2RzZigsb3UEJTef8PTiDghDDWsRdwEFRUNZTSm79MO6poZOkq/0yzBr mfRMo3ST2wHfcyV+/Ws11imgrZ4EVXZ8bynQ7HFVnsI1xH/SrMHSUnzQ g1OPsiXJbukgfVaM0q4URq6cmBSuX6Ti/6waq39j4Cj3UJXAClG3lloB z+o=
|
||||
www.nlnetlabs.nl. 600 IN A 213.154.224.1
|
||||
www.nlnetlabs.nl. 600 IN RRSIG A 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. Luav3fjE1VGhran3tnxR93cgoEyH3Kh//240KDCT8k0U4Tfw6xSBMVjj rf3oH13SXCZfYdJYZbZEahBvysMRm40Izl4+rpfUKzwjHXn1una1o4Gt A48v0fwffCXtUPz1TDFq9IKlVe95uLwjheMF8auDXHLwLItj2lF827Dd VI0=
|
||||
www.nlnetlabs.nl. 600 IN AAAA 2001:7b8:206:1::1
|
||||
www.nlnetlabs.nl. 600 IN RRSIG AAAA 5 3 600 20070912141341 20070815141341 18182 nlnetlabs.nl. kNBkVXmMFOsKXv6IdhydkSbopCxiW1gHOVHv3G9co1SzRuaubyZ+Z7PL 5xVVMwx9Z7AwvwZ1t4b3IqVnXOXtdbABMSlUyLLRxMGt6pPt6jrcFery 7aNlmtIEStJ4FBLL5T8wdsNWUP4/iV9iTrppB/Emxp0dTz77MF2rpI+V DL0=
|
||||
nlnetlabs.nl. 86400 IN RRSIG SOA 5 2 86400 20070912141341 20070815141341 18182 nlnetlabs.nl. C54bDHKC2sRbVUrDOeM2kXCHpJIFu0LlZWAFVFLf4l1Grfj+B4WcXqel kSVhi/Gpt70VW+zDEOHrS0kcE5XaBnrQE1AUZ9QjGyfjXlRzGWYbyVLD evIFrs7FdIeGKKWWp1YDLUHHF+txDT9NFu6KyEqPbZEVgIVok3skO5Vu jpA=
|
||||
nlnetlabs.nl. 86400 IN SOA open.nlnetlabs.nl. hostmaster.nlnetlabs.nl. 2007081501 28800 7200 604800 18000
|
||||
;; Query time: 20 msec
|
||||
;; SERVER: 2001:7b8:206:1::53#53(2001:7b8:206:1::53)
|
||||
;; WHEN: Thu Aug 16 11:36:35 2007
|
||||
;; XFR size: 493 records (messages 1, bytes 50727)
|
||||
ENTRY_END
|
||||
Vendored
+186
@@ -0,0 +1,186 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
trust-anchor: "sub.example.com. 3600 IN DS 30899 RSASHA1 1 f7ed618f24d5e5202927e1d27bc2e84a141cb4b3"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with secure proof of trust anchor nxdomain
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response for sub.example.com.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NXDOMAIN
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. SOA ns.example.com. h.example.com. 2007090504 1800 1800 2419200 7200
|
||||
example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFC5uwIHSehZtetK2CMNXttSFUB0XAhROFDAgy/FaxR8zFXJzyPdpQG93Sw== ;{id = 2854}
|
||||
blub.example.com. NSEC znub.example.com. A MX RRSIG NSEC
|
||||
blub.example.com. 3600 IN RRSIG NSEC 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFCic/WwyMtdDE/84g8l0S0M8AOtnAhR88hQEp5cD5XQ3EmQ79RUuNTCgdg== ;{id = 2854}
|
||||
example.com. NSEC blub.example.com. SOA NS MX DNSKEY RRSIG NSEC
|
||||
example.com. 3600 IN RRSIG NSEC 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFFYX7iNIlT79gNFFlvnn44Ittm6HAhUAg7u0hZ4to87qyfkonZu2jVLW3xw= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NXDOMAIN
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN DS
|
||||
SECTION AUTHORITY
|
||||
example.com. SOA ns.example.com. h.example.com. 2007090504 1800 1800 2419200 7200
|
||||
example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFC5uwIHSehZtetK2CMNXttSFUB0XAhROFDAgy/FaxR8zFXJzyPdpQG93Sw== ;{id = 2854}
|
||||
blub.example.com. NSEC znub.example.com. A MX RRSIG NSEC
|
||||
blub.example.com. 3600 IN RRSIG NSEC 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFCic/WwyMtdDE/84g8l0S0M8AOtnAhR88hQEp5cD5XQ3EmQ79RUuNTCgdg== ;{id = 2854}
|
||||
example.com. NSEC blub.example.com. SOA NS MX DNSKEY RRSIG NSEC
|
||||
example.com. 3600 IN RRSIG NSEC 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFFYX7iNIlT79gNFFlvnn44Ittm6HAhUAg7u0hZ4to87qyfkonZu2jVLW3xw= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NXDOMAIN
|
||||
SECTION QUESTION
|
||||
sub.example.com. IN DNSKEY
|
||||
SECTION AUTHORITY
|
||||
example.com. SOA ns.example.com. h.example.com. 2007090504 1800 1800 2419200 7200
|
||||
example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFC5uwIHSehZtetK2CMNXttSFUB0XAhROFDAgy/FaxR8zFXJzyPdpQG93Sw== ;{id = 2854}
|
||||
blub.example.com. NSEC znub.example.com. A MX RRSIG NSEC
|
||||
blub.example.com. 3600 IN RRSIG NSEC 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFCic/WwyMtdDE/84g8l0S0M8AOtnAhR88hQEp5cD5XQ3EmQ79RUuNTCgdg== ;{id = 2854}
|
||||
example.com. NSEC blub.example.com. SOA NS MX DNSKEY RRSIG NSEC
|
||||
example.com. 3600 IN RRSIG NSEC 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFFYX7iNIlT79gNFFlvnn44Ittm6HAhUAg7u0hZ4to87qyfkonZu2jVLW3xw= ;{id = 2854}
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.sub.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.6
|
||||
|
||||
; response to DNSKEY priming query
|
||||
; sub.example.com. 3600 IN DS 30899 RSASHA1 1 f7ed618f24d5e5202927e1d27bc2e84a141cb4b3
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
sub.example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
sub.example.com. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
sub.example.com. 3600 IN RRSIG DNSKEY 5 3 3600 20070926134150 20070829134150 30899 sub.example.com. uNGp99iznjD7oOX02XnQbDnbg75UwBHRvZSKYUorTKvPUnCWMHKdRsQ+mf+Fx3GZ+Fz9BVjoCmQqpnfgXLEYqw== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
sub.example.com. IN NS ns.sub.example.com.
|
||||
sub.example.com. 3600 IN RRSIG NS 5 3 3600 20070926134150 20070829134150 30899 sub.example.com. wcpHeBILHfo8C9uxMhcW03gcURZeUffiKdSTb50ZjzTHgMNhRyMfpcvSpXEd9548A9UTmWKeLZChfr5Z/glONw== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ns.sub.example.com. 3600 IN RRSIG A 5 4 3600 20070926134150 20070829134150 30899 sub.example.com. UF7shD/gt1FOp2UHgLTNbPzVykklSXFMEtJ1xD+Hholwf/PIzd7zoaIttIYibNa4fUXCqMg22H9P7MRhfmFe6g== ;{id = 30899}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.sub.example.com. IN A 11.11.11.11
|
||||
www.sub.example.com. 3600 IN RRSIG A 5 4 3600 20070926134150 20070829134150 30899 sub.example.com. 0DqqRfRtm7VSEQ4mmBbzrKRqQAay3JAE8DPDGmjtokrrjN9F1G/HxozDV7bjdIh2EChlQea8FPwf/GepJMUVxg== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NXDOMAIN
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.com. SOA ns.example.com. h.example.com. 2007090504 1800 1800 2419200 7200
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+185
@@ -0,0 +1,185 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "sub.example.com. 3600 IN DS 30899 RSASHA1 1 f7ed618f24d5e5202927e1d27bc2e84a141cb4b3"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with unsigned denial of trust anchor
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response for sub.example.com.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NXDOMAIN
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. SOA ns.example.com. h.example.com. 2007090504 1800 1800 2419200 7200
|
||||
example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFC5uwIHSehZtetK2CMNXttSFUB0XAhROFDAgy/FaxR8zFXJzyPdpQG93Sw== ;{id = 2854}
|
||||
blub.example.com. NSEC znub.example.com. A MX RRSIG NSEC
|
||||
blub.example.com. 3600 IN RRSIG NSEC 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFCic/WwyMtdDE/84g8l0S0M8AOtnAhR88hQEp5cD5XQ3EmQ79RUuNTCgdg== ;{id = 2854}
|
||||
example.com. NSEC blub.example.com. SOA NS MX DNSKEY RRSIG NSEC
|
||||
example.com. 3600 IN RRSIG NSEC 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFFYX7iNIlT79gNFFlvnn44Ittm6HAhUAg7u0hZ4to87qyfkonZu2jVLW3xw= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NXDOMAIN
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN DS
|
||||
SECTION AUTHORITY
|
||||
example.com. SOA ns.example.com. h.example.com. 2007090504 1800 1800 2419200 7200
|
||||
example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFC5uwIHSehZtetK2CMNXttSFUB0XAhROFDAgy/FaxR8zFXJzyPdpQG93Sw== ;{id = 2854}
|
||||
blub.example.com. NSEC znub.example.com. A MX RRSIG NSEC
|
||||
blub.example.com. 3600 IN RRSIG NSEC 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFCic/WwyMtdDE/84g8l0S0M8AOtnAhR88hQEp5cD5XQ3EmQ79RUuNTCgdg== ;{id = 2854}
|
||||
example.com. NSEC blub.example.com. SOA NS MX DNSKEY RRSIG NSEC
|
||||
example.com. 3600 IN RRSIG NSEC 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFFYX7iNIlT79gNFFlvnn44Ittm6HAhUAg7u0hZ4to87qyfkonZu2jVLW3xw= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NXDOMAIN
|
||||
SECTION QUESTION
|
||||
sub.example.com. IN DNSKEY
|
||||
SECTION AUTHORITY
|
||||
example.com. SOA ns.example.com. h.example.com. 2007090504 1800 1800 2419200 7200
|
||||
example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFC5uwIHSehZtetK2CMNXttSFUB0XAhROFDAgy/FaxR8zFXJzyPdpQG93Sw== ;{id = 2854}
|
||||
blub.example.com. NSEC znub.example.com. A MX RRSIG NSEC
|
||||
blub.example.com. 3600 IN RRSIG NSEC 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFCic/WwyMtdDE/84g8l0S0M8AOtnAhR88hQEp5cD5XQ3EmQ79RUuNTCgdg== ;{id = 2854}
|
||||
example.com. NSEC blub.example.com. SOA NS MX DNSKEY RRSIG NSEC
|
||||
example.com. 3600 IN RRSIG NSEC 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFFYX7iNIlT79gNFFlvnn44Ittm6HAhUAg7u0hZ4to87qyfkonZu2jVLW3xw= ;{id = 2854}
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.sub.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.6
|
||||
|
||||
; response to DNSKEY priming query
|
||||
; sub.example.com. 3600 IN DS 30899 RSASHA1 1 f7ed618f24d5e5202927e1d27bc2e84a141cb4b3
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
sub.example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
sub.example.com. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
sub.example.com. 3600 IN RRSIG DNSKEY 5 3 3600 20070926134150 20070829134150 30899 sub.example.com. uNGp99iznjD7oOX02XnQbDnbg75UwBHRvZSKYUorTKvPUnCWMHKdRsQ+mf+Fx3GZ+Fz9BVjoCmQqpnfgXLEYqw== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
sub.example.com. IN NS ns.sub.example.com.
|
||||
sub.example.com. 3600 IN RRSIG NS 5 3 3600 20070926134150 20070829134150 30899 sub.example.com. wcpHeBILHfo8C9uxMhcW03gcURZeUffiKdSTb50ZjzTHgMNhRyMfpcvSpXEd9548A9UTmWKeLZChfr5Z/glONw== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ns.sub.example.com. 3600 IN RRSIG A 5 4 3600 20070926134150 20070829134150 30899 sub.example.com. UF7shD/gt1FOp2UHgLTNbPzVykklSXFMEtJ1xD+Hholwf/PIzd7zoaIttIYibNa4fUXCqMg22H9P7MRhfmFe6g== ;{id = 30899}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.sub.example.com. IN A 11.11.11.11
|
||||
www.sub.example.com. 3600 IN RRSIG A 5 4 3600 20070926134150 20070829134150 30899 sub.example.com. 0DqqRfRtm7VSEQ4mmBbzrKRqQAay3JAE8DPDGmjtokrrjN9F1G/HxozDV7bjdIh2EChlQea8FPwf/GepJMUVxg== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA NXDOMAIN
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.com. SOA ns.example.com. h.example.com. 2007090504 1800 1800 2419200 7200
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+204
@@ -0,0 +1,204 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with empty nonterminals on the trust chain.
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; responses to DS empty nonterminal queries.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
194.example.com. IN DS
|
||||
SECTION AUTHORITY
|
||||
example.com. 3600 IN SOA ns.example.com. host.example.com. 2007091980 3600 7200 1209600 7200
|
||||
example.com. 3600 IN RRSIG SOA 3 2 3600 20070926135752 20070829135752 2854 example.com. MC0CFCOn5qKBIV7bwFMBA+Qqiblx0cylAhUAoFiGtFm2wHhJpq9MooTYdeVw45s= ;{id = 2854}
|
||||
|
||||
; This NSEC proves the NOERROR/NODATA case.
|
||||
194.example.com. IN NSEC 0.0.194.example.com. A RRSIG NSEC
|
||||
194.example.com. 3600 IN RRSIG NSEC 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFDcoKl74U9FjsuYF3Vc0E8GQ2GgzAhUAhlyhO2MMcAWQMxIhEZ4MguokN5g= ;{id = 2854}
|
||||
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
; this should be NOERROR.
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
0.194.example.com. IN DS
|
||||
SECTION AUTHORITY
|
||||
example.com. 3600 IN SOA ns.example.com. host.example.com. 2007091980 3600 7200 1209600 7200
|
||||
example.com. 3600 IN RRSIG SOA 3 2 3600 20070926135752 20070829135752 2854 example.com. MC0CFCOn5qKBIV7bwFMBA+Qqiblx0cylAhUAoFiGtFm2wHhJpq9MooTYdeVw45s= ;{id = 2854}
|
||||
|
||||
; This NSEC proves the NOERROR/NODATA case.
|
||||
194.example.com. IN NSEC 0.0.194.example.com. A RRSIG NSEC
|
||||
194.example.com. 3600 IN RRSIG NSEC 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFDcoKl74U9FjsuYF3Vc0E8GQ2GgzAhUAhlyhO2MMcAWQMxIhEZ4MguokN5g= ;{id = 2854}
|
||||
|
||||
ENTRY_END
|
||||
|
||||
; response for delegation to sub zone.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
0.0.194.example.com. IN NS ns.sub.example.com.
|
||||
0.0.194.example.com. 3600 IN DS 30899 RSASHA1 1 aa46f0717075d9750ac3596c659a2e326b33c28c
|
||||
0.0.194.example.com. 3600 IN RRSIG DS 3 5 3600 20070926135752 20070829135752 2854 example.com. MCwCFC9GIqtp/103hktw6bPpD83gr+0iAhQ8yev2yUaR9l64rYBUYTJqOoTKdw== ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ENTRY_END
|
||||
|
||||
; response for delegation to sub zone
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
0.0.194.example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
0.0.194.example.com. IN NS ns.sub.example.com.
|
||||
0.0.194.example.com. 3600 IN DS 30899 RSASHA1 1 aa46f0717075d9750ac3596c659a2e326b33c28c
|
||||
0.0.194.example.com. 3600 IN RRSIG DS 3 5 3600 20070926135752 20070829135752 2854 example.com. MCwCFC9GIqtp/103hktw6bPpD83gr+0iAhQ8yev2yUaR9l64rYBUYTJqOoTKdw== ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.sub.example.com. for zone 0.0.194.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.6
|
||||
|
||||
; response to DNSKEY priming query
|
||||
; 0.0.194.example.com. 3600 IN DS 30899 RSASHA1 1 aa46f0717075d9750ac3596c659a2e326b33c28c
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
0.0.194.example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
0.0.194.example.com. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
0.0.194.example.com. 3600 IN RRSIG DNSKEY 5 5 3600 20070926135752 20070829135752 30899 0.0.194.example.com. fSmc7ef6NwbDXC0o4wPc/aa8LakW5ZJwEZ4xPYl3tTZKmPNM7hPXskl1tFlvst9Va4u37F62v+16trprHb+SCQ== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
0.0.194.example.com. IN NS ns.sub.example.com.
|
||||
0.0.194.example.com. 3600 IN RRSIG NS 5 5 3600 20070926135752 20070829135752 30899 0.0.194.example.com. KXDA+/PJAE+dXhv6O6Z0ZovDwabSRJcIt+GT5AL6ewlj46hzo/SDKUtEhYCeT1IVQvYtXrESwFZjpp7N0rXXBg== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
SECTION ANSWER
|
||||
328.0.0.194.example.com. IN A 11.11.11.11
|
||||
328.0.0.194.example.com. 3600 IN RRSIG A 5 6 3600 20070926135752 20070829135752 30899 0.0.194.example.com. chZW77mqywhw/4ch6BxXQ4EbFgb9zgh2xF75FLlKq/7ey6CfHSJRpJRjRqtMTn+1i18UL2B4nPS/WnK5DZeqlA== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
SECTION ANSWER
|
||||
328.0.0.194.example.com. 3600 IN A 11.11.11.11
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+207
@@ -0,0 +1,207 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with DS nodata as nxdomain on trust chain
|
||||
; This is a bug in ANS 2.8.1.0 where it gives an NXDOMAIN instead of
|
||||
; NOERROR for an empty nonterminal DS query. The proof for this NXDOMAIN
|
||||
; is the NSEC that proves emptynonterminal.
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; responses to DS empty nonterminal queries.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR AA NOERROR
|
||||
SECTION QUESTION
|
||||
194.example.com. IN DS
|
||||
SECTION AUTHORITY
|
||||
example.com. 3600 IN SOA ns.example.com. host.example.com. 2007091980 3600 7200 1209600 7200
|
||||
example.com. 3600 IN RRSIG SOA 3 2 3600 20070926135752 20070829135752 2854 example.com. MC0CFCOn5qKBIV7bwFMBA+Qqiblx0cylAhUAoFiGtFm2wHhJpq9MooTYdeVw45s= ;{id = 2854}
|
||||
|
||||
; This NSEC proves the NOERROR/NODATA case.
|
||||
194.example.com. IN NSEC 0.0.194.example.com. A RRSIG NSEC
|
||||
194.example.com. 3600 IN RRSIG NSEC 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFDcoKl74U9FjsuYF3Vc0E8GQ2GgzAhUAhlyhO2MMcAWQMxIhEZ4MguokN5g= ;{id = 2854}
|
||||
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
; Bad NXDOMAIN response, this should be NOERROR.
|
||||
REPLY QR AA NXDOMAIN
|
||||
SECTION QUESTION
|
||||
0.194.example.com. IN DS
|
||||
SECTION AUTHORITY
|
||||
example.com. 3600 IN SOA ns.example.com. host.example.com. 2007091980 3600 7200 1209600 7200
|
||||
example.com. 3600 IN RRSIG SOA 3 2 3600 20070926135752 20070829135752 2854 example.com. MC0CFCOn5qKBIV7bwFMBA+Qqiblx0cylAhUAoFiGtFm2wHhJpq9MooTYdeVw45s= ;{id = 2854}
|
||||
|
||||
; This NSEC proves the NOERROR/NODATA case.
|
||||
194.example.com. IN NSEC 0.0.194.example.com. A RRSIG NSEC
|
||||
194.example.com. 3600 IN RRSIG NSEC 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFDcoKl74U9FjsuYF3Vc0E8GQ2GgzAhUAhlyhO2MMcAWQMxIhEZ4MguokN5g= ;{id = 2854}
|
||||
|
||||
ENTRY_END
|
||||
|
||||
; response for delegation to sub zone.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
0.0.194.example.com. IN NS ns.sub.example.com.
|
||||
0.0.194.example.com. 3600 IN DS 30899 RSASHA1 1 aa46f0717075d9750ac3596c659a2e326b33c28c
|
||||
0.0.194.example.com. 3600 IN RRSIG DS 3 5 3600 20070926135752 20070829135752 2854 example.com. MCwCFC9GIqtp/103hktw6bPpD83gr+0iAhQ8yev2yUaR9l64rYBUYTJqOoTKdw== ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ENTRY_END
|
||||
|
||||
; response for delegation to sub zone
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
0.0.194.example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
0.0.194.example.com. IN NS ns.sub.example.com.
|
||||
0.0.194.example.com. 3600 IN DS 30899 RSASHA1 1 aa46f0717075d9750ac3596c659a2e326b33c28c
|
||||
0.0.194.example.com. 3600 IN RRSIG DS 3 5 3600 20070926135752 20070829135752 2854 example.com. MCwCFC9GIqtp/103hktw6bPpD83gr+0iAhQ8yev2yUaR9l64rYBUYTJqOoTKdw== ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.sub.example.com. for zone 0.0.194.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.6
|
||||
|
||||
; response to DNSKEY priming query
|
||||
; 0.0.194.example.com. 3600 IN DS 30899 RSASHA1 1 aa46f0717075d9750ac3596c659a2e326b33c28c
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
0.0.194.example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
0.0.194.example.com. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
0.0.194.example.com. 3600 IN RRSIG DNSKEY 5 5 3600 20070926135752 20070829135752 30899 0.0.194.example.com. fSmc7ef6NwbDXC0o4wPc/aa8LakW5ZJwEZ4xPYl3tTZKmPNM7hPXskl1tFlvst9Va4u37F62v+16trprHb+SCQ== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
0.0.194.example.com. IN NS ns.sub.example.com.
|
||||
0.0.194.example.com. 3600 IN RRSIG NS 5 5 3600 20070926135752 20070829135752 30899 0.0.194.example.com. KXDA+/PJAE+dXhv6O6Z0ZovDwabSRJcIt+GT5AL6ewlj46hzo/SDKUtEhYCeT1IVQvYtXrESwFZjpp7N0rXXBg== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
SECTION ANSWER
|
||||
328.0.0.194.example.com. IN A 11.11.11.11
|
||||
328.0.0.194.example.com. 3600 IN RRSIG A 5 6 3600 20070926135752 20070829135752 30899 0.0.194.example.com. chZW77mqywhw/4ch6BxXQ4EbFgb9zgh2xF75FLlKq/7ey6CfHSJRpJRjRqtMTn+1i18UL2B4nPS/WnK5DZeqlA== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
328.0.0.194.example.com. IN A
|
||||
SECTION ANSWER
|
||||
328.0.0.194.example.com. 3600 IN A 11.11.11.11
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+171
@@ -0,0 +1,171 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with response to qtype ANY
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN ANY
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN ANY
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134802 20070829134802 2854 example.com. MCwCFG1yhRNtTEa3Eno2zhVVuy2EJX3wAhQeLyUp6+UXcpC5qGNu9tkrTEgPUg== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN ANY
|
||||
SECTION ANSWER
|
||||
example.com. 86400 IN SOA open.example.com. hostmaster.example.com. 2007090400 28800 7200 604800 18000
|
||||
example.com. 86400 IN RRSIG SOA 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFQCSs8KJepwaIp5vu++/0hk04lkXvgIUdphJSAE/MYob30WcRei9/nL49tE= ;{id = 2854}
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJIIs70j+sDS/UT2QRp61SE7S3EEXopNXoFE73JLRmvpi/UrOO/Vz4Se6wXv/CYCKjGw06U4WRgRYXcpEhJROyNapmdIKSxhOzfLVE1gqA0PweZR8dtY3aNQSRn3sPpwJr6Mi/PqQKAMMrZ9ckJpf1+bQMOOvxgzz2U1GS18b3yZKcgTMEaJzd/GZYzi/BN2DzQ0MsrSwYXfsNLFOBbs8PJMW4LYIxeeOe6rUgkWOF7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFHq7BNVAeLW+Uw/rkjVS08lrMDk/AhR+bvChHfiE4jLb6uoyE54/irCuqA== ;{id = 2854}
|
||||
example.com. 600 IN NAPTR 20 0 "s" "SIP+D2U" "" _sip._udp.example.com.
|
||||
example.com. 600 IN RRSIG NAPTR 3 2 600 20070926134150 20070829134150 2854 example.com. MC0CFE8qs66bzuOyKmTIacamrmqabMRzAhUAn0MujX1LB0UpTHuLMgdgMgJJlq4= ;{id = 2854}
|
||||
example.com. 86400 IN AAAA 2001:7b8:206:1::1
|
||||
example.com. 86400 IN RRSIG AAAA 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFEqS4WHyqhUkv7t42TsBZJk/Q9paAhUAtTZ8GaXGpot0PmsM0oGzQU+2iw4= ;{id = 2854}
|
||||
example.com. 86400 IN TXT "Stichting NLnet Labs"
|
||||
example.com. 86400 IN RRSIG TXT 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFH3otn2u8zXczBS8L0VKpyAYZGSkAhQLGaQclkzMAzlB5j73opFjdkh8TA== ;{id = 2854}
|
||||
example.com. 86400 IN MX 100 v.net.example.
|
||||
example.com. 86400 IN MX 50 open.example.com.
|
||||
example.com. 86400 IN RRSIG MX 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFEKh3jeqh69zcOqWWv3GNKlMECPyAhR9HJkcPLqlyVWUccWDFJfGGcQfdg== ;{id = 2854}
|
||||
example.com. 86400 IN NS v.net.example.
|
||||
example.com. 86400 IN NS open.example.com.
|
||||
example.com. 86400 IN NS ns7.domain-registry.example.
|
||||
example.com. 86400 IN RRSIG NS 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFQCaRn30X4neKW7KYoTa2kcsoOLgfgIURvKEyDczLypWlx99KpxzMxRYhEc= ;{id = 2854}
|
||||
example.com. 86400 IN A 213.154.224.1
|
||||
example.com. 86400 IN RRSIG A 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFH8kSLxmRTwzlGDxvF1e4y/gM+5dAhQkzyQ2a6Gf+CMaHzVScaUvTt9HhQ== ;{id = 2854}
|
||||
example.com. 18000 IN NSEC _sip._udp.example.com. A NS SOA MX TXT AAAA NAPTR RRSIG NSEC DNSKEY
|
||||
example.com. 18000 IN RRSIG NSEC 3 2 18000 20070926134150 20070829134150 2854 example.com. MCwCFBzOGtpgq4uJ2jeuLPYl2HowIRzDAhQVXNz1haQ1mI7z9lt5gcvWW+lFhA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ns7.domain-registry.example. 80173 IN A 62.4.86.230
|
||||
open.example.com. 600 IN A 213.154.224.1
|
||||
open.example.com. 600 IN AAAA 2001:7b8:206:1::53
|
||||
open.example.com. 600 IN AAAA 2001:7b8:206:1::1
|
||||
v.net.example. 28800 IN A 213.154.224.17
|
||||
v.net.example. 28800 IN AAAA 2001:7b8:206:1:200:39ff:fe59:b187
|
||||
johnny.example.com. 600 IN A 213.154.224.44
|
||||
open.example.com. 600 IN RRSIG A 3 3 600 20070926134150 20070829134150 2854 example.com. MC0CFQCh8bja923UJmg1+sYXMK8WIE4dpgIUQe9sZa0GOcUYSgb2rXoogF8af+Y= ;{id = 2854}
|
||||
open.example.com. 600 IN RRSIG AAAA 3 3 600 20070926134150 20070829134150 2854 example.com. MC0CFQCRGJgIS6kEVG7aJfovuG/q3cgOWwIUYEIFCnfRQlMIYWF7BKMQoMbdkE0= ;{id = 2854}
|
||||
johnny.example.com. 600 IN RRSIG A 3 3 600 20070926134150 20070829134150 2854 example.com. MCwCFAh0/zSpCd/9eMNz7AyfnuGQFD1ZAhQEpNFNw4XByNEcbi/vsVeii9kp7g== ;{id = 2854}
|
||||
_sip._udp.example.com. 600 IN RRSIG SRV 3 4 600 20070926134150 20070829134150 2854 example.com. MCwCFFSRVgOcq1ihVuO6MhCuzWs6SxpVAhRPHHCKy0JxymVkYeFOxTkbVSWMMw== ;{id = 2854}
|
||||
_sip._udp.example.com. 600 IN SRV 0 0 5060 johnny.example.com.
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
MATCH TCP
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
example.com. IN ANY
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN ANY
|
||||
SECTION ANSWER
|
||||
example.com. 86400 IN SOA open.example.com. hostmaster.example.com. 2007090400 28800 7200 604800 18000
|
||||
example.com. 86400 IN RRSIG SOA 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFQCSs8KJepwaIp5vu++/0hk04lkXvgIUdphJSAE/MYob30WcRei9/nL49tE= ;{id = 2854}
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJIIs70j+sDS/UT2QRp61SE7S3EEXopNXoFE73JLRmvpi/UrOO/Vz4Se6wXv/CYCKjGw06U4WRgRYXcpEhJROyNapmdIKSxhOzfLVE1gqA0PweZR8dtY3aNQSRn3sPpwJr6Mi/PqQKAMMrZ9ckJpf1+bQMOOvxgzz2U1GS18b3yZKcgTMEaJzd/GZYzi/BN2DzQ0MsrSwYXfsNLFOBbs8PJMW4LYIxeeOe6rUgkWOF7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFHq7BNVAeLW+Uw/rkjVS08lrMDk/AhR+bvChHfiE4jLb6uoyE54/irCuqA== ;{id = 2854}
|
||||
example.com. 600 IN NAPTR 20 0 "s" "SIP+D2U" "" _sip._udp.example.com.
|
||||
example.com. 600 IN RRSIG NAPTR 3 2 600 20070926134150 20070829134150 2854 example.com. MC0CFE8qs66bzuOyKmTIacamrmqabMRzAhUAn0MujX1LB0UpTHuLMgdgMgJJlq4= ;{id = 2854}
|
||||
example.com. 86400 IN AAAA 2001:7b8:206:1::1
|
||||
example.com. 86400 IN RRSIG AAAA 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFEqS4WHyqhUkv7t42TsBZJk/Q9paAhUAtTZ8GaXGpot0PmsM0oGzQU+2iw4= ;{id = 2854}
|
||||
example.com. 86400 IN TXT "Stichting NLnet Labs"
|
||||
example.com. 86400 IN RRSIG TXT 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFH3otn2u8zXczBS8L0VKpyAYZGSkAhQLGaQclkzMAzlB5j73opFjdkh8TA== ;{id = 2854}
|
||||
example.com. 86400 IN MX 100 v.net.example.
|
||||
example.com. 86400 IN MX 50 open.example.com.
|
||||
example.com. 86400 IN RRSIG MX 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFEKh3jeqh69zcOqWWv3GNKlMECPyAhR9HJkcPLqlyVWUccWDFJfGGcQfdg== ;{id = 2854}
|
||||
example.com. 86400 IN NS v.net.example.
|
||||
example.com. 86400 IN NS open.example.com.
|
||||
example.com. 86400 IN NS ns7.domain-registry.example.
|
||||
example.com. 86400 IN RRSIG NS 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFQCaRn30X4neKW7KYoTa2kcsoOLgfgIURvKEyDczLypWlx99KpxzMxRYhEc= ;{id = 2854}
|
||||
example.com. 86400 IN A 213.154.224.1
|
||||
example.com. 86400 IN RRSIG A 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFH8kSLxmRTwzlGDxvF1e4y/gM+5dAhQkzyQ2a6Gf+CMaHzVScaUvTt9HhQ== ;{id = 2854}
|
||||
example.com. 18000 IN NSEC _sip._udp.example.com. A NS SOA MX TXT AAAA NAPTR RRSIG NSEC DNSKEY
|
||||
example.com. 18000 IN RRSIG NSEC 3 2 18000 20070926134150 20070829134150 2854 example.com. MCwCFBzOGtpgq4uJ2jeuLPYl2HowIRzDAhQVXNz1haQ1mI7z9lt5gcvWW+lFhA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
open.example.com. 600 IN A 213.154.224.1
|
||||
open.example.com. 600 IN AAAA 2001:7b8:206:1::53
|
||||
open.example.com. 600 IN AAAA 2001:7b8:206:1::1
|
||||
_sip._udp.example.com. 600 IN SRV 0 0 5060 johnny.example.com.
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+175
@@ -0,0 +1,175 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with response to qtype ANY that includes DNAME
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN ANY
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN ANY
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134802 20070829134802 2854 example.com. MCwCFG1yhRNtTEa3Eno2zhVVuy2EJX3wAhQeLyUp6+UXcpC5qGNu9tkrTEgPUg== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN ANY
|
||||
SECTION ANSWER
|
||||
example.com. 86400 IN SOA open.example.com. hostmaster.example.com. 2007090400 28800 7200 604800 18000
|
||||
example.com. 86400 IN RRSIG SOA 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFQCSs8KJepwaIp5vu++/0hk04lkXvgIUdphJSAE/MYob30WcRei9/nL49tE= ;{id = 2854}
|
||||
example.com. 3600 IN DNAME example.net.
|
||||
example.com. 3600 IN RRSIG DNAME 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCdje5lZfq9kENX9a8lOOKn79BRlQIUbVCx/fXo0kfvAgC5kB8Dvd5LodQ= ;{id = 2854}
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJIIs70j+sDS/UT2QRp61SE7S3EEXopNXoFE73JLRmvpi/UrOO/Vz4Se6wXv/CYCKjGw06U4WRgRYXcpEhJROyNapmdIKSxhOzfLVE1gqA0PweZR8dtY3aNQSRn3sPpwJr6Mi/PqQKAMMrZ9ckJpf1+bQMOOvxgzz2U1GS18b3yZKcgTMEaJzd/GZYzi/BN2DzQ0MsrSwYXfsNLFOBbs8PJMW4LYIxeeOe6rUgkWOF7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFHq7BNVAeLW+Uw/rkjVS08lrMDk/AhR+bvChHfiE4jLb6uoyE54/irCuqA== ;{id = 2854}
|
||||
example.com. 600 IN NAPTR 20 0 "s" "SIP+D2U" "" _sip._udp.example.com.
|
||||
example.com. 600 IN RRSIG NAPTR 3 2 600 20070926134150 20070829134150 2854 example.com. MC0CFE8qs66bzuOyKmTIacamrmqabMRzAhUAn0MujX1LB0UpTHuLMgdgMgJJlq4= ;{id = 2854}
|
||||
example.com. 86400 IN AAAA 2001:7b8:206:1::1
|
||||
example.com. 86400 IN RRSIG AAAA 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFEqS4WHyqhUkv7t42TsBZJk/Q9paAhUAtTZ8GaXGpot0PmsM0oGzQU+2iw4= ;{id = 2854}
|
||||
example.com. 86400 IN TXT "Stichting NLnet Labs"
|
||||
example.com. 86400 IN RRSIG TXT 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFH3otn2u8zXczBS8L0VKpyAYZGSkAhQLGaQclkzMAzlB5j73opFjdkh8TA== ;{id = 2854}
|
||||
example.com. 86400 IN MX 100 v.net.example.
|
||||
example.com. 86400 IN MX 50 open.example.com.
|
||||
example.com. 86400 IN RRSIG MX 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFEKh3jeqh69zcOqWWv3GNKlMECPyAhR9HJkcPLqlyVWUccWDFJfGGcQfdg== ;{id = 2854}
|
||||
example.com. 86400 IN NS v.net.example.
|
||||
example.com. 86400 IN NS open.example.com.
|
||||
example.com. 86400 IN NS ns7.domain-registry.example.
|
||||
example.com. 86400 IN RRSIG NS 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFQCaRn30X4neKW7KYoTa2kcsoOLgfgIURvKEyDczLypWlx99KpxzMxRYhEc= ;{id = 2854}
|
||||
example.com. 86400 IN A 213.154.224.1
|
||||
example.com. 86400 IN RRSIG A 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFH8kSLxmRTwzlGDxvF1e4y/gM+5dAhQkzyQ2a6Gf+CMaHzVScaUvTt9HhQ== ;{id = 2854}
|
||||
example.com. 18000 IN NSEC _sip._udp.example.com. A NS SOA MX TXT AAAA NAPTR RRSIG NSEC DNSKEY
|
||||
example.com. 18000 IN RRSIG NSEC 3 2 18000 20070926134150 20070829134150 2854 example.com. MCwCFBzOGtpgq4uJ2jeuLPYl2HowIRzDAhQVXNz1haQ1mI7z9lt5gcvWW+lFhA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ns7.domain-registry.example. 80173 IN A 62.4.86.230
|
||||
open.example.com. 600 IN A 213.154.224.1
|
||||
open.example.com. 600 IN AAAA 2001:7b8:206:1::53
|
||||
open.example.com. 600 IN AAAA 2001:7b8:206:1::1
|
||||
v.net.example. 28800 IN A 213.154.224.17
|
||||
v.net.example. 28800 IN AAAA 2001:7b8:206:1:200:39ff:fe59:b187
|
||||
johnny.example.com. 600 IN A 213.154.224.44
|
||||
open.example.com. 600 IN RRSIG A 3 3 600 20070926134150 20070829134150 2854 example.com. MC0CFQCh8bja923UJmg1+sYXMK8WIE4dpgIUQe9sZa0GOcUYSgb2rXoogF8af+Y= ;{id = 2854}
|
||||
open.example.com. 600 IN RRSIG AAAA 3 3 600 20070926134150 20070829134150 2854 example.com. MC0CFQCRGJgIS6kEVG7aJfovuG/q3cgOWwIUYEIFCnfRQlMIYWF7BKMQoMbdkE0= ;{id = 2854}
|
||||
johnny.example.com. 600 IN RRSIG A 3 3 600 20070926134150 20070829134150 2854 example.com. MCwCFAh0/zSpCd/9eMNz7AyfnuGQFD1ZAhQEpNFNw4XByNEcbi/vsVeii9kp7g== ;{id = 2854}
|
||||
_sip._udp.example.com. 600 IN RRSIG SRV 3 4 600 20070926134150 20070829134150 2854 example.com. MCwCFFSRVgOcq1ihVuO6MhCuzWs6SxpVAhRPHHCKy0JxymVkYeFOxTkbVSWMMw== ;{id = 2854}
|
||||
_sip._udp.example.com. 600 IN SRV 0 0 5060 johnny.example.com.
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
MATCH TCP
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
example.com. IN ANY
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN ANY
|
||||
SECTION ANSWER
|
||||
example.com. 86400 IN SOA open.example.com. hostmaster.example.com. 2007090400 28800 7200 604800 18000
|
||||
example.com. 86400 IN RRSIG SOA 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFQCSs8KJepwaIp5vu++/0hk04lkXvgIUdphJSAE/MYob30WcRei9/nL49tE= ;{id = 2854}
|
||||
example.com. 3600 IN DNAME example.net.
|
||||
example.com. 3600 IN RRSIG DNAME 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCdje5lZfq9kENX9a8lOOKn79BRlQIUbVCx/fXo0kfvAgC5kB8Dvd5LodQ= ;{id = 2854}
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJIIs70j+sDS/UT2QRp61SE7S3EEXopNXoFE73JLRmvpi/UrOO/Vz4Se6wXv/CYCKjGw06U4WRgRYXcpEhJROyNapmdIKSxhOzfLVE1gqA0PweZR8dtY3aNQSRn3sPpwJr6Mi/PqQKAMMrZ9ckJpf1+bQMOOvxgzz2U1GS18b3yZKcgTMEaJzd/GZYzi/BN2DzQ0MsrSwYXfsNLFOBbs8PJMW4LYIxeeOe6rUgkWOF7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFHq7BNVAeLW+Uw/rkjVS08lrMDk/AhR+bvChHfiE4jLb6uoyE54/irCuqA== ;{id = 2854}
|
||||
example.com. 600 IN NAPTR 20 0 "s" "SIP+D2U" "" _sip._udp.example.com.
|
||||
example.com. 600 IN RRSIG NAPTR 3 2 600 20070926134150 20070829134150 2854 example.com. MC0CFE8qs66bzuOyKmTIacamrmqabMRzAhUAn0MujX1LB0UpTHuLMgdgMgJJlq4= ;{id = 2854}
|
||||
example.com. 86400 IN AAAA 2001:7b8:206:1::1
|
||||
example.com. 86400 IN RRSIG AAAA 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFEqS4WHyqhUkv7t42TsBZJk/Q9paAhUAtTZ8GaXGpot0PmsM0oGzQU+2iw4= ;{id = 2854}
|
||||
example.com. 86400 IN TXT "Stichting NLnet Labs"
|
||||
example.com. 86400 IN RRSIG TXT 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFH3otn2u8zXczBS8L0VKpyAYZGSkAhQLGaQclkzMAzlB5j73opFjdkh8TA== ;{id = 2854}
|
||||
example.com. 86400 IN MX 100 v.net.example.
|
||||
example.com. 86400 IN MX 50 open.example.com.
|
||||
example.com. 86400 IN RRSIG MX 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFEKh3jeqh69zcOqWWv3GNKlMECPyAhR9HJkcPLqlyVWUccWDFJfGGcQfdg== ;{id = 2854}
|
||||
example.com. 86400 IN NS v.net.example.
|
||||
example.com. 86400 IN NS open.example.com.
|
||||
example.com. 86400 IN NS ns7.domain-registry.example.
|
||||
example.com. 86400 IN RRSIG NS 3 2 86400 20070926134150 20070829134150 2854 example.com. MC0CFQCaRn30X4neKW7KYoTa2kcsoOLgfgIURvKEyDczLypWlx99KpxzMxRYhEc= ;{id = 2854}
|
||||
example.com. 86400 IN A 213.154.224.1
|
||||
example.com. 86400 IN RRSIG A 3 2 86400 20070926134150 20070829134150 2854 example.com. MCwCFH8kSLxmRTwzlGDxvF1e4y/gM+5dAhQkzyQ2a6Gf+CMaHzVScaUvTt9HhQ== ;{id = 2854}
|
||||
example.com. 18000 IN NSEC _sip._udp.example.com. A NS SOA MX TXT AAAA NAPTR RRSIG NSEC DNSKEY
|
||||
example.com. 18000 IN RRSIG NSEC 3 2 18000 20070926134150 20070829134150 2854 example.com. MCwCFBzOGtpgq4uJ2jeuLPYl2HowIRzDAhQVXNz1haQ1mI7z9lt5gcvWW+lFhA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
open.example.com. 600 IN A 213.154.224.1
|
||||
open.example.com. 600 IN AAAA 2001:7b8:206:1::53
|
||||
open.example.com. 600 IN AAAA 2001:7b8:206:1::1
|
||||
_sip._udp.example.com. 600 IN SRV 0 0 5060 johnny.example.com.
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+118
@@ -0,0 +1,118 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with cname loop
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134802 20070829134802 2854 example.com. MCwCFG1yhRNtTEa3Eno2zhVVuy2EJX3wAhQeLyUp6+UXcpC5qGNu9tkrTEgPUg== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.example.com.
|
||||
www.example.com. 3600 IN RRSIG CNAME DSA 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFH0SwLHe7u56TshoVciFRHEl1KqbAhQ3zBOZMlL8bt1DqoDoM5ni8U/1UA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
www.example.com. 3600 IN RRSIG A 3 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFC99iE9K5y2WNgI0gFvBWaTi9wm6AhUAoUqOpDtG5Zct+Qr9F3mSdnbc6V4= ;{id = 2854}
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA SERVFAIL
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+127
@@ -0,0 +1,127 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with cname 2 step loop
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134802 20070829134802 2854 example.com. MCwCFG1yhRNtTEa3Eno2zhVVuy2EJX3wAhQeLyUp6+UXcpC5qGNu9tkrTEgPUg== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME foo.example.com.
|
||||
www.example.com. 3600 IN RRSIG CNAME DSA 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFH0SwLHe7u56TshoVciFRHEl1KqbAhQ3zBOZMlL8bt1DqoDoM5ni8U/1UA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
foo.example.com. IN A
|
||||
SECTION ANSWER
|
||||
foo.example.com. IN CNAME www.example.com.
|
||||
foo.example.com. 3600 IN RRSIG CNAME DSA 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFC7kcWPsMnGbjvzj5UNnxQzM0YvnAhUAgxIKgs1huJHvcAP2Xt3p8Adpy/c= ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA SERVFAIL
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+140
@@ -0,0 +1,140 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with cname 3 step loop
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134802 20070829134802 2854 example.com. MCwCFG1yhRNtTEa3Eno2zhVVuy2EJX3wAhQeLyUp6+UXcpC5qGNu9tkrTEgPUg== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME foo.example.com.
|
||||
www.example.com. 3600 IN RRSIG CNAME DSA 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFH0SwLHe7u56TshoVciFRHEl1KqbAhQ3zBOZMlL8bt1DqoDoM5ni8U/1UA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
foo.example.com. IN A
|
||||
SECTION ANSWER
|
||||
foo.example.com. IN CNAME bar.example.com.
|
||||
foo.example.com. 3600 IN RRSIG CNAME DSA 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFFMlXuWrNL/8aYOl9U9WYjgif8gAAhUAqsC/xOXakHP1SYxMSLANziOik94= ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
bar.example.com. IN A
|
||||
SECTION ANSWER
|
||||
bar.example.com. IN CNAME www.example.com.
|
||||
bar.example.com. 3600 IN RRSIG CNAME DSA 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFAsalUJJSV86uPlfiGS3kKDc0JB7AhQ+qmHqagY/r36Re/J3Q1OfvcA1dA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA SERVFAIL
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+176
@@ -0,0 +1,176 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
trust-anchor: "example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with a query for type cname
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN CNAME
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN CNAME
|
||||
SECTION AUTHORITY
|
||||
net. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN CNAME
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN CNAME
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.example.net.
|
||||
www.example.com. 3600 IN RRSIG CNAME DSA 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFGcJxnNxpWCBzXejiSdl4p1BKRMnAhUApoJrugVBRwFgAoYAhhqlZFac7fE= ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.5
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.net. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
example.net. 3600 IN RRSIG DNSKEY RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. hiFzlQ8VoYgCuvIsfVuxC3mfJDqsTh0yc6abs5xMx5uEcIjb0dndFQx7INOM+imlzveEN73Hqp4OLFpFhsWLlw== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
example.net. 3600 IN RRSIG NS RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. E8JX0l4B+cSR5bkHQwOJy1pBmlLMTYCJ8EwfNMU/eCv0YhKwo26rHhn52FGisgv+Nwp7/NbhHqQ+kJgoZC94XA== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ns.example.net. 3600 IN RRSIG A RSASHA1 3 3600 20070926134150 20070829134150 30899 example.net. x+tQMC9FhzT7Fcy1pM5NrOC7E8nLd7THPI3C6ie4EwL8PrxllqlR3q/DKB0d/m0qCOPcgN6HFOYURV1s4uAcsw== ;{id = 30899}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION ANSWER
|
||||
www.example.net. IN A 11.12.13.14
|
||||
www.example.net. 3600 IN RRSIG A 5 3 3600 20070926134150 20070829134150 30899 example.net. CPxF5hK9Kg5eT7W6LgZwr0ePYEm9HMcSY4vvqCS6gDWB4X9jvXLCfBkCLhsNybPBpGWlsLi5wM6MTdJXuPpsRA== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN CNAME
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN CNAME
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.example.net.
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+177
@@ -0,0 +1,177 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
trust-anchor: "example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with a cname to a dname
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN DNAME
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN DNAME
|
||||
SECTION AUTHORITY
|
||||
net. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN DNAME
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN DNAME
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN DNAME
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.example.net.
|
||||
www.example.com. 3600 IN RRSIG CNAME DSA 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFGcJxnNxpWCBzXejiSdl4p1BKRMnAhUApoJrugVBRwFgAoYAhhqlZFac7fE= ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.5
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.net. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
example.net. 3600 IN RRSIG DNSKEY RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. hiFzlQ8VoYgCuvIsfVuxC3mfJDqsTh0yc6abs5xMx5uEcIjb0dndFQx7INOM+imlzveEN73Hqp4OLFpFhsWLlw== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
example.net. 3600 IN RRSIG NS RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. E8JX0l4B+cSR5bkHQwOJy1pBmlLMTYCJ8EwfNMU/eCv0YhKwo26rHhn52FGisgv+Nwp7/NbhHqQ+kJgoZC94XA== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ns.example.net. 3600 IN RRSIG A RSASHA1 3 3600 20070926134150 20070829134150 30899 example.net. x+tQMC9FhzT7Fcy1pM5NrOC7E8nLd7THPI3C6ie4EwL8PrxllqlR3q/DKB0d/m0qCOPcgN6HFOYURV1s4uAcsw== ;{id = 30899}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN DNAME
|
||||
SECTION ANSWER
|
||||
www.example.net. IN DNAME blarg.com.
|
||||
www.example.net. 3600 IN RRSIG DNAME RSASHA1 3 3600 20070926134150 20070829134150 30899 example.net. ByevtOI1ChCDb8CD8Qvu2pNcooUWN4LkNXQj0vzSLp62rCltiWWTg8iU6DiojeOx2inVqx+PZXyiX1nX80kCgg== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN DNAME
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN DNAME
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.example.net.
|
||||
www.example.net. IN DNAME blarg.com.
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
+325
@@ -0,0 +1,325 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
trust-anchor: "example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}"
|
||||
trust-anchor: "example.org. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJIIs70j+sDS/UT2QRp61SE7S3EEXopNXoFE73JLRmvpi/UrOO/Vz4Se6wXv/CYCKjGw06U4WRgRYXcpEhJROyNapmdIKSxhOzfLVE1gqA0PweZR8dtY3aNQSRn3sPpwJr6Mi/PqQKAMMrZ9ckJpf1+bQMOOvxgzz2U1GS18b3yZKcgTMEaJzd/GZYzi/BN2DzQ0MsrSwYXfsNLFOBbs8PJMW4LYIxeeOe6rUgkWOF7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with cname, dname, cname, positive answer
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
net. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.org. IN A
|
||||
SECTION AUTHORITY
|
||||
org. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.org. IN A
|
||||
SECTION AUTHORITY
|
||||
example.org. IN NS ns.example.org.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.org. IN A 1.2.3.7
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.sub.example.net.
|
||||
www.example.com. 3600 IN RRSIG CNAME 3 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFEv1gOb7KEskzkJNtFKKVBxY+Hb2AhUAqKJDIZJvNl+AdzqAt+JgdvnYAF0= ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
; response for delegation to sub.example.com.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
sub.example.com. IN NS ns.sub.example.com.
|
||||
sub.example.com. 3600 IN DS 30899 RSASHA1 1 f7ed618f24d5e5202927e1d27bc2e84a141cb4b3
|
||||
sub.example.com. 3600 IN RRSIG DS 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFCW3ix0GD4BSvNLWIbROCJt5DAW9AhRt/kg9kBKJ20UBUdumrBUHqnskdA== ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ENTRY_END
|
||||
|
||||
; response for delegation to sub.example.com.
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
sub.example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
sub.example.com. IN NS ns.sub.example.com.
|
||||
sub.example.com. 3600 IN DS 30899 RSASHA1 1 f7ed618f24d5e5202927e1d27bc2e84a141cb4b3
|
||||
sub.example.com. 3600 IN RRSIG DS 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFCW3ix0GD4BSvNLWIbROCJt5DAW9AhRt/kg9kBKJ20UBUdumrBUHqnskdA== ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.5
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.net. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
example.net. 3600 IN RRSIG DNSKEY RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. hiFzlQ8VoYgCuvIsfVuxC3mfJDqsTh0yc6abs5xMx5uEcIjb0dndFQx7INOM+imlzveEN73Hqp4OLFpFhsWLlw== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
example.net. 3600 IN RRSIG NS RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. E8JX0l4B+cSR5bkHQwOJy1pBmlLMTYCJ8EwfNMU/eCv0YhKwo26rHhn52FGisgv+Nwp7/NbhHqQ+kJgoZC94XA== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ns.example.net. 3600 IN RRSIG A RSASHA1 3 3600 20070926134150 20070829134150 30899 example.net. x+tQMC9FhzT7Fcy1pM5NrOC7E8nLd7THPI3C6ie4EwL8PrxllqlR3q/DKB0d/m0qCOPcgN6HFOYURV1s4uAcsw== ;{id = 30899}
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
sub.example.net. IN DS
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
sub.example.net. IN NSEC www.example.net. DNAME RRSIG NSEC
|
||||
sub.example.net. 3600 IN RRSIG NSEC 5 3 3600 20070926134150 20070829134150 30899 example.net. PsKlcOSNElUi3u7Cn6c5+Sv8CRLTqmooMbvloTwUCkM53SuAirXcCA+9Pz5y0unO9+5IxwdkwssnoCOX5FqnCQ== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.net. IN A
|
||||
SECTION ANSWER
|
||||
sub.example.net. IN DNAME sub.example.com.
|
||||
sub.example.net. 3600 IN RRSIG DNAME 5 3 3600 20070926134150 20070829134150 30899 example.net. G/UmcL1VmCF2mjB1O9IeNM2DnvayxEy6vOrvA+Ic/Gqcsgnq/f4VTCV9soQQIAWEir2v5Vt8hqPDP8rCRbMnyA== ;{id = 30899}
|
||||
www.sub.example.net. IN CNAME www.sub.example.com.
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.sub.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.6
|
||||
|
||||
; response to DNSKEY priming query
|
||||
; sub.example.com. 3600 IN DS 30899 RSASHA1 1 f7ed618f24d5e5202927e1d27bc2e84a141cb4b3
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
sub.example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
sub.example.com. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
sub.example.com. 3600 IN RRSIG DNSKEY 5 3 3600 20070926134150 20070829134150 30899 sub.example.com. uNGp99iznjD7oOX02XnQbDnbg75UwBHRvZSKYUorTKvPUnCWMHKdRsQ+mf+Fx3GZ+Fz9BVjoCmQqpnfgXLEYqw== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
sub.example.com. IN NS ns.sub.example.com.
|
||||
sub.example.com. 3600 IN RRSIG NS 5 3 3600 20070926134150 20070829134150 30899 sub.example.com. wcpHeBILHfo8C9uxMhcW03gcURZeUffiKdSTb50ZjzTHgMNhRyMfpcvSpXEd9548A9UTmWKeLZChfr5Z/glONw== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.sub.example.com. IN A 1.2.3.6
|
||||
ns.sub.example.com. 3600 IN RRSIG A 5 4 3600 20070926134150 20070829134150 30899 sub.example.com. UF7shD/gt1FOp2UHgLTNbPzVykklSXFMEtJ1xD+Hholwf/PIzd7zoaIttIYibNa4fUXCqMg22H9P7MRhfmFe6g== ;{id = 30899}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.sub.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.sub.example.com. IN CNAME www.example.org.
|
||||
www.sub.example.com. 3600 IN RRSIG CNAME 5 4 3600 20070926134150 20070829134150 30899 sub.example.com. ZE6A4pkyeUpNCscu2oeBv/3JbbirdwUaAMgmQ/ighzacUJCC6Lh8vAL5aYDEyTk7oktb8uS7gmYan171aM9/tg== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.org.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.7
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.org. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.org. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.org. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134150 20070829134150 2854 example.org. MC0CFBCSESiUl5XEht/LRecGFuX2Xad7AhUAoURP4DsIEbwMjlB955vziIB798E= ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.org. IN NS ns.example.org.
|
||||
example.org. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.org. MCwCFAE1sQemdwqUPt4Qo+mr59a66DlFAhRV1mftIFs2YnkmIWsGtikIOJvh5A== ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.org. IN A 1.2.3.7
|
||||
ns.example.org. 3600 IN RRSIG A 3 3 3600 20070926134150 20070829134150 2854 example.org. MC0CFQC0yXaA8ywsZF+7dHukVIBFD820wQIUONbyI+UX9SDSDFmFnr+ApuTEooY= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.org. IN A
|
||||
SECTION ANSWER
|
||||
www.example.org. IN A 11.11.11.11
|
||||
www.example.org. 3600 IN RRSIG A 3 3 3600 20070926134150 20070829134150 2854 example.org. MC0CFB/erEAxSMqW0I51r6VQMq861B+yAhUAqJ7DPU7xHFpWJGILOQ0WW3aDGi0= ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. 3600 IN CNAME www.sub.example.net.
|
||||
sub.example.net. 3600 IN DNAME sub.example.com.
|
||||
www.sub.example.net. 0 IN CNAME www.sub.example.com.
|
||||
www.sub.example.com. 3600 IN CNAME www.example.org.
|
||||
www.example.org. 3600 IN A 11.11.11.11
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+176
@@ -0,0 +1,176 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
trust-anchor: "example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with cname to nodata
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
net. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. 3600 IN CNAME www.example.net.
|
||||
www.example.com. 3600 IN RRSIG CNAME 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFGtYzScyRnHV8U/jOIPYwrlI9t3oAhRF0PIf+IthUR7uCWIvskWp5CfReQ== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.5
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.net. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
example.net. 3600 IN RRSIG DNSKEY RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. hiFzlQ8VoYgCuvIsfVuxC3mfJDqsTh0yc6abs5xMx5uEcIjb0dndFQx7INOM+imlzveEN73Hqp4OLFpFhsWLlw== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
example.net. 3600 IN RRSIG NS RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. E8JX0l4B+cSR5bkHQwOJy1pBmlLMTYCJ8EwfNMU/eCv0YhKwo26rHhn52FGisgv+Nwp7/NbhHqQ+kJgoZC94XA== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ns.example.net. 3600 IN RRSIG A RSASHA1 3 3600 20070926134150 20070829134150 30899 example.net. x+tQMC9FhzT7Fcy1pM5NrOC7E8nLd7THPI3C6ie4EwL8PrxllqlR3q/DKB0d/m0qCOPcgN6HFOYURV1s4uAcsw== ;{id = 30899}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
www.example.net. IN NSEC example.net. MX NSEC RRSIG
|
||||
www.example.net. 3600 IN RRSIG NSEC 5 3 3600 20070926134150 20070829134150 30899 example.net. Z+3/WKJEqhWoMOQLC7Yb1dTVGaqzmU0bZ2cH9jSfNQZiT0O37yzCNNUmMsW4gsJOh3o61iZ+hxpze3aO3aedqQ== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.example.net.
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+178
@@ -0,0 +1,178 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
trust-anchor: "example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with cname to nxdomain
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
net. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. 3600 IN CNAME www.example.net.
|
||||
www.example.com. 3600 IN RRSIG CNAME 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFGtYzScyRnHV8U/jOIPYwrlI9t3oAhRF0PIf+IthUR7uCWIvskWp5CfReQ== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.5
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.net. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
example.net. 3600 IN RRSIG DNSKEY RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. hiFzlQ8VoYgCuvIsfVuxC3mfJDqsTh0yc6abs5xMx5uEcIjb0dndFQx7INOM+imlzveEN73Hqp4OLFpFhsWLlw== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
example.net. 3600 IN RRSIG NS RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. E8JX0l4B+cSR5bkHQwOJy1pBmlLMTYCJ8EwfNMU/eCv0YhKwo26rHhn52FGisgv+Nwp7/NbhHqQ+kJgoZC94XA== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ns.example.net. 3600 IN RRSIG A RSASHA1 3 3600 20070926134150 20070829134150 30899 example.net. x+tQMC9FhzT7Fcy1pM5NrOC7E8nLd7THPI3C6ie4EwL8PrxllqlR3q/DKB0d/m0qCOPcgN6HFOYURV1s4uAcsw== ;{id = 30899}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NXDOMAIN
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION ANSWER
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NSEC abc.example.net. SOA NS DNSKEY NSEC RRSIG
|
||||
example.net. 3600 IN RRSIG NSEC 5 2 3600 20070926134150 20070829134150 30899 example.net. SEHthmjHyqGlzaOp3Dx6Jn5Fnvvtknw/IF6YSFY8NZLe+YSh1oRJbdEkQ8G92IT08n1jSN6jvKRsFBOUoFOQAw== ;{id = 30899}
|
||||
wab.example.net. IN NSEC wzz.example.net. A NSEC RRSIG
|
||||
wab.example.net. 3600 IN RRSIG NSEC 5 3 3600 20070926134150 20070829134150 30899 example.net. gl8vkI3xfSWx4Pyv5OdOthiewE6u/13kclY7UG9ptuFBddamdJO3RQqyxM6Xcmq+ToO4kMCCyaKijp01gTDoGg== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.example.net.
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Vendored
+177
@@ -0,0 +1,177 @@
|
||||
; config options
|
||||
; The island of trust is at example.com
|
||||
server:
|
||||
trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b"
|
||||
trust-anchor: "example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}"
|
||||
val-override-date: "20070916134226"
|
||||
|
||||
stub-zone:
|
||||
name: "."
|
||||
stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
|
||||
CONFIG_END
|
||||
|
||||
SCENARIO_BEGIN Test validator with a cname to positive
|
||||
|
||||
; K.ROOT-SERVERS.NET.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 193.0.14.129
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
. IN NS
|
||||
SECTION ANSWER
|
||||
. IN NS K.ROOT-SERVERS.NET.
|
||||
SECTION ADDITIONAL
|
||||
K.ROOT-SERVERS.NET. IN A 193.0.14.129
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
com. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
net. IN NS a.gtld-servers.net.
|
||||
SECTION ADDITIONAL
|
||||
a.gtld-servers.net. IN A 192.5.6.30
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; a.gtld-servers.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 192.5.6.30
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ENTRY_END
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.com.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.4
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.com. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b}
|
||||
example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
example.com. IN NS ns.example.com.
|
||||
example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.com. IN A 1.2.3.4
|
||||
ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.example.net.
|
||||
www.example.com. 3600 IN RRSIG CNAME DSA 3 3600 20070926134150 20070829134150 2854 example.com. MC0CFGcJxnNxpWCBzXejiSdl4p1BKRMnAhUApoJrugVBRwFgAoYAhhqlZFac7fE= ;{id = 2854}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
; ns.example.net.
|
||||
RANGE_BEGIN 0 100
|
||||
ADDRESS 1.2.3.5
|
||||
|
||||
; response to DNSKEY priming query
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
example.net. IN DNSKEY
|
||||
SECTION ANSWER
|
||||
example.net. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
|
||||
example.net. 3600 IN RRSIG DNSKEY RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. hiFzlQ8VoYgCuvIsfVuxC3mfJDqsTh0yc6abs5xMx5uEcIjb0dndFQx7INOM+imlzveEN73Hqp4OLFpFhsWLlw== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
example.net. IN NS ns.example.net.
|
||||
example.net. 3600 IN RRSIG NS RSASHA1 2 3600 20070926134150 20070829134150 30899 example.net. E8JX0l4B+cSR5bkHQwOJy1pBmlLMTYCJ8EwfNMU/eCv0YhKwo26rHhn52FGisgv+Nwp7/NbhHqQ+kJgoZC94XA== ;{id = 30899}
|
||||
SECTION ADDITIONAL
|
||||
ns.example.net. IN A 1.2.3.5
|
||||
ns.example.net. 3600 IN RRSIG A RSASHA1 3 3600 20070926134150 20070829134150 30899 example.net. x+tQMC9FhzT7Fcy1pM5NrOC7E8nLd7THPI3C6ie4EwL8PrxllqlR3q/DKB0d/m0qCOPcgN6HFOYURV1s4uAcsw== ;{id = 30899}
|
||||
ENTRY_END
|
||||
|
||||
; response to query of interest
|
||||
ENTRY_BEGIN
|
||||
MATCH opcode qtype qname
|
||||
ADJUST copy_id
|
||||
REPLY QR NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.net. IN A
|
||||
SECTION ANSWER
|
||||
www.example.net. IN A 11.12.13.14
|
||||
www.example.net. 3600 IN RRSIG A 5 3 3600 20070926134150 20070829134150 30899 example.net. CPxF5hK9Kg5eT7W6LgZwr0ePYEm9HMcSY4vvqCS6gDWB4X9jvXLCfBkCLhsNybPBpGWlsLi5wM6MTdJXuPpsRA== ;{id = 30899}
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
RANGE_END
|
||||
|
||||
STEP 1 QUERY
|
||||
ENTRY_BEGIN
|
||||
REPLY RD
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
ENTRY_END
|
||||
|
||||
; recursion happens here.
|
||||
STEP 10 CHECK_ANSWER
|
||||
ENTRY_BEGIN
|
||||
MATCH all
|
||||
REPLY QR RD RA AD NOERROR
|
||||
SECTION QUESTION
|
||||
www.example.com. IN A
|
||||
SECTION ANSWER
|
||||
www.example.com. IN CNAME www.example.net.
|
||||
www.example.net. IN A 11.12.13.14
|
||||
SECTION AUTHORITY
|
||||
SECTION ADDITIONAL
|
||||
ENTRY_END
|
||||
|
||||
SCENARIO_END
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user