897d49e9292f2fa05cf03768c4fe2429be0ae0ca |
|
08-Dec-2017 |
Mark Andrews <marka@isc.org> |
increment test number
(cherry picked from commit e5c2cfdbf9cfc9811a2df481586331cbff693642) |
0d6328ce5f6b799f8e7c6cbbb3b965cf29bfb7ba |
|
06-Dec-2017 |
Mark Andrews <marka@isc.org> |
4840. [test] Add tests to cover fallback to using ZSK on inactive
KSK. [RT #46787]
(cherry picked from commit 32d09cd7e05f53b227f7a68d7f6e8cc5a3f2b1fb) |
e5f0db473410df1b5508e74984ee5ecf573683e3 |
|
05-Dec-2017 |
Curtis Blackburn <ckb@isc.org> |
clarify "stage 1" and "stage 2" in autosign test |
15057131d5f815e8b6b2b9a58961d6707e317440 |
|
05-Dec-2017 |
Mark Andrews <marka@isc.org> |
set the DNSKEY deletion time to now+5 once we got all the zones into their initial state
(cherry picked from commit ecafa2ae506b8cae3660de29d66c10af656174c5) |
e01ef6f01c7e8f80122cd80a2e011425a0135489 |
|
05-Dec-2017 |
Mark Andrews <marka@isc.org> |
4839. [bug] zone.c:zone_sign was not properly determining
if there were active KSK and ZSK keys for
a algorithm when update-check-ksk is true
(default) leaving records unsigned with one or
more DNSKEY algorithms. [RT #46774]
(cherry picked from commit 00f5ea91cf6d3897f24efb2ba097bda1df24082f) |
95d40c1e9d1438f4636d6501c8d0b7736cb90d70 |
|
05-Dec-2017 |
Evan Hunt <each@isc.org> |
[v9_11] fix test descriptions |
45c5f403619029a363cf089e0a4b1bb44425dd84 |
|
05-Dec-2017 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
677f507de7c546c187c1505c48bc7b440545485c |
|
04-Dec-2017 |
Mark Andrews <marka@isc.org> |
4838. [bug] zone.c:add_sigs was not properly determining
if there were active KSK and ZSK keys for
a algorithm when update-check-ksk is true
(default) leaving records unsigned with one or
more DNSKEY algorithms. [RT #46754]
(cherry picked from commit 6fa2a0691e1d701b361611069ab97471b8cd29bd) |
801707fe19600313a0b1f7845a518100f69e58b6 |
|
21-Jul-2016 |
Evan Hunt <each@isc.org> |
[v9_11] store "addzone" zone config in a NZD database
4421. [func] When built with LMDB (Lightning Memory-mapped
Database), named will now use a database to store
the configuration for zones added by "rndc addzone"
instead of using a flat NZF file. This improves
performance of "rndc delzone" and "rndc modzone"
significantly. Existing NZF files will
automatically by converted to NZD databases.
To view the contents of an NZD or to roll back to
NZF format, use "named-nzd2nzf". To disable
this feature, use "configure --without-lmdb".
[RT #39837] |
0c27b3fe77ac1d5094ba3521e8142d9e7973133f |
|
27-Jun-2016 |
Mark Andrews <marka@isc.org> |
4401. [misc] Change LICENSE to MPL 2.0. |
3635d8f9104e70e141a8f191a0e6c1502ceed2f3 |
|
14-Jun-2016 |
Mark Andrews <marka@isc.org> |
do not overflow exit status. [RT #42643] |
4df65ccfeca981cef1bf66706b8b505a8407f9d2 |
|
26-Jan-2016 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
9478de25bb86e8942e35cf50462cf108154958e9 |
|
25-Jan-2016 |
Mark Andrews <marka@isc.org> |
4301. [bug] dnssec-settime -p [DP]sync was not working. [RT #41534] |
4ba2689c1f4e0c8c670fc47307d7b46d9da3a45b |
|
06-Nov-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
e939674d53a127ddeeaf4b41fd72933f0b493308 |
|
04-Nov-2015 |
Mark Andrews <marka@isc.org> |
4252. [func] Add support for automating the generation CDS and
CDNSKEY rrsets to named and dnssec-signzone.
[RT #40424] |
1c95f672323b7ac176af4225a36d33daa442542c |
|
24-Jun-2014 |
Mark Andrews <marka@isc.org> |
use $PERL |
79d27f505a67ee1fb5cf104cbe7b1ead67d252b4 |
|
04-Jun-2014 |
Mukund Sivaraman <muks@isc.org> |
[35063] Don't publish an activated key automatically before its publish time |
aa7b16ec2a5dacda1d65b64e0f7af434d02cbba4 |
|
22-Jan-2014 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
d58e33bfabfee19a035031dac633d36659738d56 |
|
21-Jan-2014 |
Evan Hunt <each@isc.org> |
[master] testcrypto.sh in system tests
3714. [test] System tests that need to test for cryptography
support before running can now use a common
"testcrypto.sh" script to do so. [RT #35213] |
377b774598f3973c2b231fb88d39acca1ff5ebc4 |
|
16-Aug-2013 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
d1e22676de16e6dee54c58b27cca11c5fb8f1ff5 |
|
15-Aug-2013 |
Mark Andrews <marka@isc.org> |
3635. [bug] Signatures were not being removed from a zone with
only KSK keys for a algorithm. [RT #24439] |
3ff483ed84344e81ad2fc79faf6f036c18fbab05 |
|
02-Dec-2012 |
Mark Andrews <marka@isc.org> |
loop 'I:checking expired signatures were updated' test |
bf8267aa453e5d2a735ed732a043b77a0b355b20 |
|
29-Jun-2012 |
Mark Andrews <marka@isc.org> |
reverse bad copyright update |
247bf378605811d695e968dbe930a7fc45c0038e |
|
29-Jun-2012 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
7829fad4093f2c1985b1efb7cea00287ff015d2b |
|
20-Jun-2012 |
ckb <ckb@isc.org> |
merging fast format zone files
Conflicts:
.gitignore
bin/named/zoneconf.c
bin/tests/.gitignore
bin/tests/system/autosign/tests.sh
bin/tests/system/masterformat/clean.sh
bin/tests/system/masterformat/ns1/compile.sh
bin/tests/system/masterformat/tests.sh
configure
lib/dns/db.c
lib/dns/include/dns/db.h
lib/dns/include/dns/types.h
lib/dns/master.c
lib/dns/masterdump.c
lib/dns/rbt.c
lib/dns/rbtdb.c
lib/dns/sdb.c
lib/dns/sdlz.c
lib/dns/tests/.cvsignore
lib/dns/tests/Makefile.in
lib/dns/win32/libdns.def
lib/dns/xfrin.c
lib/dns/zone.c
lib/export/dns/Makefile.in
lib/isc/include/isc/file.h
lib/isc/unix/file.c
lib/isc/win32/file.c
lib/isccfg/namedconf.c |
6a2ebd69b5dbe29bde5ef71a28ed3ab5ba02a9d1 |
|
12-May-2012 |
Francis Dupont <fdupont@isc.org> |
fix key name variable in autosign |
f4bd753e0bdc7a9dc6c00be8aa04e114625a6402 |
|
07-Feb-2012 |
Evan Hunt <each@isc.org> |
fixed a test error that caused autosign to fail on freebsd |
99f6179191e583d23f3c5567d3c00b57b64eb52d |
|
06-Feb-2012 |
Evan Hunt <each@isc.org> |
3277. [bug] Make sure automatic key maintenance is started
when "auto-dnssec maintain" is turned on during
"rndc reconfig". [RT #26805] |
c2f843fc2bfe31be94433f29c7e839b390736f4f |
|
03-Feb-2012 |
Automatic Updater <source@isc.org> |
update copyright notice |
92a83eeb2dfbc57e7664211105dba513f13b630b |
|
02-Feb-2012 |
Mark Andrews <marka@isc.org> |
portable code, ok'd bu Evan |
9892bae7b760071b37881d4dc888ea4b4320a851 |
|
22-Dec-2011 |
Mark Andrews <marka@isc.org> |
forcing full sign with unreadable keys |
281a31ad37c2cbe20be2d5c2c718a2d40d197221 |
|
22-Dec-2011 |
Mark Andrews <marka@isc.org> |
+/- 500ms was too small a fudge factor (-582ms seen in testing), raise to +/- 1000ms |
91013b0e1955471a02654ff3d0eebca00c77cc4b |
|
12-Dec-2011 |
Mark Andrews <marka@isc.org> |
join line for old awk |
6c1a7787234dd35d804825dbf9277435788a3271 |
|
12-Dec-2011 |
Mark Andrews <marka@isc.org> |
chech that the final time is within 10 seconds but no greater than the expected interval |
374b677c50f2a053bf23d2a5d40b58d78fbd32eb |
|
27-Nov-2011 |
Mark Andrews <marka@isc.org> |
make grep more precise |
9c03f13e18c1b0c32f62391a17300378605bbc7b |
|
28-Oct-2011 |
Evan Hunt <each@isc.org> |
3185. [func] New 'rndc signing' option for auto-dnssec zones:
- 'rndc signing -list' displays the current
state of signing operations
- 'rndc signing -clear' clears the signing state
records for keys that have fully signed the zone
- 'rndc signing -nsec3param' sets the NSEC3
parameters for the zone
The 'rndc keydone' syntax is removed. [RT #23729] |
1946c596b47b0495ce745fe2fff7da799919b0d2 |
|
20-Oct-2011 |
Mark Andrews <marka@isc.org> |
3174. [bug] Always compute to revoked key tag from scratch.
[RT #24711] |
020c4484fe510434c1b3aaac040ab6cfb3340115 |
|
15-Oct-2011 |
Mark Andrews <marka@isc.org> |
3173. [port] Correctly validate root DS responses. [RT #25726] |
f96ba7c74694c34b1a5904bf6708ece1a17a2f05 |
|
26-Jul-2011 |
Mark Andrews <marka@isc.org> |
remove check for oldid as named may have already deleted it |
acf34e66a8e82975a6cd64ef680fbc9d83944023 |
|
26-Jul-2011 |
Mark Andrews <marka@isc.org> |
id was not being properly set |
b47c020d5c635b662ac57e5485d266fd62c796c0 |
|
08-Jul-2011 |
Evan Hunt <each@isc.org> |
3133. [bug] Change #3114 was incomplete. [RT #24577] |
79ce3a9e82384cc31fd6b86be8f3d1474fcfd9f4 |
|
10-Jun-2011 |
Evan Hunt <each@isc.org> |
3128. [func] Inserting an NSEC3PARAM via dynamic update in an
auto-dnssec zone that has not been signed yet
will cause it to be signed with the specified NSEC3
parameters when keys are activated. The
NSEC3PARAM record will not appear in the zone until
it is signed, but the parameters will be stored.
[RT #23684] |
5e3affc6a0b155ee1cadac735c1a71f4d418ad69 |
|
10-Jun-2011 |
Evan Hunt <each@isc.org> |
3127. [bug] 'rndc thaw' will now remove a zone's journal file
if the zone serial number has been changed and
ixfr-from-differences is not in use. [RT #24687] |
ae0691566a4e99ed72cb00ff78fd6418673fbf84 |
|
31-May-2011 |
Mark Andrews <marka@isc.org> |
date +%s is not portable, use perl -e 'print time();', Adjust messages |
fe8572e1165ff5383dab9758b7507dab8d8095f3 |
|
30-May-2011 |
Mark Andrews <marka@isc.org> |
The old active key could be deleted before the "former standby key has now
signed fully" ran causing it to fail. Delay the deletion by 10 seconds. |
0245f7725c40fd29637fbc83ee25bd84be25bfd2 |
|
26-May-2011 |
Evan Hunt <each@isc.org> |
3118. [bug] When rolling to a new DNSSEC key, a private-type
record could be created and never marked complete.
[RT #23253] |
f1d4986b832124b63905e2d5ca401d1d0498c9b8 |
|
03-May-2011 |
Mark Andrews <marka@isc.org> |
treat asb(x) < 500ms as 0 |
65043f48f26fcf8359a6b83250c476fb99eea299 |
|
02-May-2011 |
Mark Andrews <marka@isc.org> |
force numeric comparision |
07907fa31a15480e918df1b93c0bca0e3ad8b5b5 |
|
02-May-2011 |
Mark Andrews <marka@isc.org> |
handle end of day |
bbf46f1aa21fb07e6a0aa0bc2cb1102e022c0ebf |
|
01-May-2011 |
Mark Andrews <marka@isc.org> |
fix expression |
f83682f368a967d5d27e5c2c52896300efed95f8 |
|
01-May-2011 |
Mark Andrews <marka@isc.org> |
awk -v is not portable, add floating point arithmetic effects |
39f2d1a96a7c7494b1db0ea0f45e063a6a5ef9bb |
|
29-Apr-2011 |
Evan Hunt <each@isc.org> |
3102. [func] New 'dnssec-loadkeys-interval' option configures
how often, in minutes, to check the key repository
for updates when using automatic key maintenance.
Default is every 60 minutes (formerly hard-coded
to 12 hours). [RT #23744]
3101. [bug] Zones using automatic key maintenance could fail
to check the key repository for updates. [RT #23744] |
319b8a14881a95996af3a9ba4a20f144eb766b31 |
|
26-Mar-2011 |
Evan Hunt <each@isc.org> |
3092. [bug] Signatures for records at the zone apex could go
stale due to an incorrect timer setting. [RT #23769]
3091. [bug] Fixed a bug in which zone keys that were published
and then subsequently activated could fail to trigger
automatic signing. [RT #22991] |
36b2d5f93c22b096c0417495f27ae0bdebf06ae1 |
|
21-Mar-2011 |
Evan Hunt <each@isc.org> |
use "rndc sync" instead of freeze/thaw cycle to dump zones, now that it's
available. |
61bcc232038f0a2cb77ed6269675fdc288f5ec98 |
|
17-Mar-2011 |
Evan Hunt <each@isc.org> |
3076. [func] New '-L' option in dnssec-keygen, dnsset-settime, and
dnssec-keyfromlabel sets the default TTL of the
key. When possible, automatic signing will use that
TTL when the key is published. [RT #23304] |
624664e50406f63108ddc7bad47dbac87ac74261 |
|
02-Mar-2011 |
Francis Dupont <fdupont@isc.org> |
Fixed last autosign test report [RT #23256] |
be789bc7eb6f683979cd1405a06284ee00cda366 |
|
02-Mar-2011 |
Mark Andrews <marka@isc.org> |
3045. [removed] Replaced by change #3050. |
ba88bcf08b965f65c07735efa2f675b8cbeb735a |
|
02-Mar-2011 |
Mark Andrews <marka@isc.org> |
3050. [bug] The autosign system test was timing dependent.
Wait for the initial autosigning to complete
before running the rest of the test. [RT #23035] |
c8175ece69d986ccd0671bc4d2571b247dfae177 |
|
02-Mar-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
17bc56e321574b43c5837d1741e9157c8f2fcd91 |
|
28-Feb-2011 |
Francis Dupont <fdupont@isc.org> |
ove the testsock.pl sleep to autosign test suite [RT #23400] |
bbedadf76ab670b01887fb9b41097120ea4fdf14 |
|
15-Dec-2010 |
Evan Hunt <each@isc.org> |
2985. [bug] Add a regression test for change #2896. [RT #21324] |
c6f4972c745f8903aba6dcca41f17a44c473db66 |
|
17-Aug-2010 |
Mark Andrews <marka@isc.org> |
2943. [func] Add support to load new keys into managed zones
without signing immediately with "rndc loadkeys".
Add support to link keys with "dnssec-keygen -S"
and "dnssec-settime -S". [RT #21351] |
e24ccb512c110d181e01f977196e518b0e72e451 |
|
07-Jun-2010 |
Mark Andrews <marka@isc.org> |
2914. [bug] Make the "autosign" system test more portable.
[RT #20997] |
5ae2eac4c16bdbbef032544bd9fc86f47e7bdc2c |
|
19-May-2010 |
Mark Andrews <marka@isc.org> |
2902. [func] Add regression test for change 2897. [RT #21040] |
44f175a90a855326725439b2f1178f0dcca8f67d |
|
14-May-2010 |
Mark Andrews <marka@isc.org> |
2892. [bug] Handle REVOKED keys better. [RT #20961] |
6bb1560124ce99fe50b9847ce29fcaed52564900 |
|
19-Jan-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
e11a0c114cdaf8f7e7832e9f1a011138248093a6 |
|
18-Jan-2010 |
Evan Hunt <each@isc.org> |
2841. [func] Added "smartsign" and improved "autosign" and
"dnssec" regression tests. [RT #20865] |
f766024a27c891a107a1f57013d8a460fb172b19 |
|
19-Dec-2009 |
Evan Hunt <each@isc.org> |
change all keys from rsasha1 to nsec3rsasha1 so that the nsec->nsec3
transitions work correctly. (they worked before, but weren't supposed
to; when that bug was fixed, the test broke.) |
095810f8cb710e0211c7db084191c2cad8e3c4c9 |
|
02-Dec-2009 |
Evan Hunt <each@isc.org> |
fixed autosign/metadata brokenness on solaris [rt20685] |
ffd297db793b3efa3854f32f443b9f79e0417f2c |
|
01-Dec-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
75b8de87879ad017c9cd2ffc328e5d2391d16e99 |
|
30-Nov-2009 |
Evan Hunt <each@isc.org> |
Create automatic tests "autosign" and "metadata". [rt19946] |