dnssec-signzone.c revision cdde861f12093487c09122ca740d44a4c570c683
135bcc2e42a94543f11af2a4196b13552ab46d89Automatic Updater/*
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * Portions Copyright (C) 1999, 2000 Internet Software Consortium.
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence * Portions Copyright (C) 1995-2000 by Network Associates, Inc.
ec5347e2c775f027573ce5648b910361aa926c01Automatic Updater *
7c74e180c206e6ed99e8beb820da5f399d845c3eDavid Lawrence * Permission to use, copy, modify, and distribute this software for any
7c74e180c206e6ed99e8beb820da5f399d845c3eDavid Lawrence * purpose with or without fee is hereby granted, provided that the above
40f53fa8d9c6a4fc38c0014495e7a42b08f52481David Lawrence * copyright notice and this permission notice appear in all copies.
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews *
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM AND
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * NETWORK ASSOCIATES DISCLAIM ALL WARRANTIES WITH REGARD TO THIS
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * FITNESS. IN NO EVENT SHALL INTERNET SOFTWARE CONSORTIUM OR NETWORK
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * ASSOCIATES BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews * CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF
9c3531d72aeaad6c5f01efe6a1c82023e1379e4dDavid Lawrence * USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR
866d106459313499d0ca7bfccb4b2d23d5e4377cDavid Lawrence * OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
74cb99072c4b0ebd2ccafcfa284288fa760f7a1aMark Andrews * PERFORMANCE OF THIS SOFTWARE.
866d106459313499d0ca7bfccb4b2d23d5e4377cDavid Lawrence */
866d106459313499d0ca7bfccb4b2d23d5e4377cDavid Lawrence
7c74e180c206e6ed99e8beb820da5f399d845c3eDavid Lawrence/* $Id: dnssec-signzone.c,v 1.90 2000/08/10 22:08:23 bwelling Exp $ */
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt
ea31416b4fcdf23732355a8002f93f29e3b3d2dbAndreas Gustafsson#include <config.h>
866d106459313499d0ca7bfccb4b2d23d5e4377cDavid Lawrence
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews#include <stdlib.h>
a5d43b72413db3edd6b36a58f9bdf2cf6ff692f2Bob Halley
a5d43b72413db3edd6b36a58f9bdf2cf6ff692f2Bob Halley#include <isc/commandline.h>
a5d43b72413db3edd6b36a58f9bdf2cf6ff692f2Bob Halley#include <isc/entropy.h>
a5d43b72413db3edd6b36a58f9bdf2cf6ff692f2Bob Halley#include <isc/mem.h>
a5d43b72413db3edd6b36a58f9bdf2cf6ff692f2Bob Halley#include <isc/stdio.h>
ccdac53c027e8964753b36c4d8c7b0e98af501c2Michael Graff#include <isc/string.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <isc/util.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/db.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/dbiterator.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/dnssec.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/fixedname.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/keyvalues.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/log.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/master.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/masterdump.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/nxt.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/rdata.h>
f4ea363e3acc321b24ffe95a64a583e8041d6fd5Mark Andrews#include <dns/rdatalist.h>
914eeb33149a0008e26741d9e7d89dcd6f8b6d0bMark Andrews#include <dns/rdataset.h>
ccdac53c027e8964753b36c4d8c7b0e98af501c2Michael Graff#include <dns/rdatasetiter.h>
a903095bf4512dae561c7f6fc7854a51bebf334aMark Andrews#include <dns/rdatastruct.h>
ccdac53c027e8964753b36c4d8c7b0e98af501c2Michael Graff#include <dns/rdatatype.h>
ccdac53c027e8964753b36c4d8c7b0e98af501c2Michael Graff#include <dns/result.h>
ccdac53c027e8964753b36c4d8c7b0e98af501c2Michael Graff#include <dns/secalg.h>
ccdac53c027e8964753b36c4d8c7b0e98af501c2Michael Graff#include <dns/time.h>
3d776d762914d1b675b4fd49728ce353ccf6f77eBrian Wellington
ccdac53c027e8964753b36c4d8c7b0e98af501c2Michael Graff#include <dst/dst.h>
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrews#include <dst/result.h>
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrews
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrews#include "dnssectool.h"
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrews
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrewsconst char *program = "dnssec-signzone";
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrewsint verbose;
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrews
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrews/*#define USE_ZONESTATUS*/
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrews
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrews#define BUFSIZE 2048
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrews
11dbf2fc38eea8c5d3fe7123718bf197a8bb2e6bMark Andrewstypedef struct signer_key_struct signer_key_t;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewstypedef struct signer_array_struct signer_array_t;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrewsstruct signer_key_struct {
323a9f3430abf186f8f84d795549391a8ed7f274Francis Dupont dst_key_t *key;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews isc_boolean_t isdefault;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews ISC_LINK(signer_key_t) link;
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews};
75a4dd0d377dca2f85cea44e28bf110314c1fe8cDavid Lawrence
75a4dd0d377dca2f85cea44e28bf110314c1fe8cDavid Lawrencestruct signer_array_struct {
75a4dd0d377dca2f85cea44e28bf110314c1fe8cDavid Lawrence unsigned char array[BUFSIZE];
75a4dd0d377dca2f85cea44e28bf110314c1fe8cDavid Lawrence ISC_LINK(signer_array_t) link;
75a4dd0d377dca2f85cea44e28bf110314c1fe8cDavid Lawrence};
91306d962f9d147d94b82fb14edb28f8d907cae7Andreas Gustafsson
91306d962f9d147d94b82fb14edb28f8d907cae7Andreas Gustafssonstatic ISC_LIST(signer_key_t) keylist;
91306d962f9d147d94b82fb14edb28f8d907cae7Andreas Gustafssonstatic isc_stdtime_t starttime = 0, endtime = 0, now;
91306d962f9d147d94b82fb14edb28f8d907cae7Andreas Gustafssonstatic int cycle = -1;
91306d962f9d147d94b82fb14edb28f8d907cae7Andreas Gustafssonstatic isc_boolean_t tryverify = ISC_FALSE;
e893dce91279d7313a579f72caae3941f6dc5a27David Lawrencestatic isc_mem_t *mctx = NULL;
e893dce91279d7313a579f72caae3941f6dc5a27David Lawrencestatic isc_entropy_t *ectx = NULL;
e893dce91279d7313a579f72caae3941f6dc5a27David Lawrencestatic dns_ttl_t zonettl;
e893dce91279d7313a579f72caae3941f6dc5a27David Lawrencestatic FILE *fp;
e893dce91279d7313a579f72caae3941f6dc5a27David Lawrencestatic const dns_master_style_t *masterstyle = &dns_master_style_explicitttl;
e893dce91279d7313a579f72caae3941f6dc5a27David Lawrence
e893dce91279d7313a579f72caae3941f6dc5a27David Lawrencestatic inline void
e893dce91279d7313a579f72caae3941f6dc5a27David Lawrenceset_bit(unsigned char *array, unsigned int index, unsigned int bit) {
e893dce91279d7313a579f72caae3941f6dc5a27David Lawrence unsigned int shift, mask;
e893dce91279d7313a579f72caae3941f6dc5a27David Lawrence
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley shift = 7 - (index % 8);
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley mask = 1 << shift;
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley
8e06cea14c857429ab7e7299af2dce5eeeaa5ff0Michael Graff if (bit != 0)
ce8c568e0d6106bb87069453505e09bc66754b40Andreas Gustafsson array[index / 8] |= mask;
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley else
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley array[index / 8] &= (~mask & 0xFF);
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley}
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halleystatic void
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halleysignwithkey(dns_name_t *name, dns_rdataset_t *rdataset, dns_rdata_t *rdata,
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley dst_key_t *key, isc_buffer_t *b)
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley{
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley isc_result_t result;
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley dns_rdata_init(rdata);
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley result = dns_dnssec_sign(name, rdataset, key, &starttime, &endtime,
3b77946b751f39bd4db5a7d1fe48a81e6b1e7a28Bob Halley mctx, b, rdata);
8e06cea14c857429ab7e7299af2dce5eeeaa5ff0Michael Graff isc_entropy_stopcallbacksources(ectx);
8e06cea14c857429ab7e7299af2dce5eeeaa5ff0Michael Graff if (result != ISC_R_SUCCESS)
3ecf3394e37dc2848a09ffc643565d454e9e6974Andreas Gustafsson fatal("key '%s/%s/%d' failed to sign data: %s",
3ecf3394e37dc2848a09ffc643565d454e9e6974Andreas Gustafsson nametostr(dst_key_name(key)), algtostr(dst_key_alg(key)),
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 dst_key_id(key), isc_result_totext(result));
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉
3ecf3394e37dc2848a09ffc643565d454e9e6974Andreas Gustafsson if (tryverify) {
3ecf3394e37dc2848a09ffc643565d454e9e6974Andreas Gustafsson result = dns_dnssec_verify(name, rdataset, key,
3ecf3394e37dc2848a09ffc643565d454e9e6974Andreas Gustafsson ISC_TRUE, mctx, rdata);
3ecf3394e37dc2848a09ffc643565d454e9e6974Andreas Gustafsson if (result == ISC_R_SUCCESS)
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence vbprintf(3, "\tsignature verified\n");
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence else
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence vbprintf(3, "\tsignature failed to verify\n");
b587e1d83f007ce68a9ae93097c461d8eb7aa373Mark Andrews }
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence}
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrencestatic inline isc_boolean_t
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrenceissigningkey(signer_key_t *key) {
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence return (key->isdefault);
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence}
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrencestatic inline isc_boolean_t
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrenceiszonekey(signer_key_t *key, dns_db_t *db) {
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence return (ISC_TF(dns_name_equal(dst_key_name(key->key),
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence dns_db_origin(db)) &&
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence dst_key_iszonekey(key->key)));
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence}
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence/*
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence * Finds the key that generated a SIG, if possible. First look at the keys
ae4cbb69eef32ced103fe4561e8d2031ee4c3497David Lawrence * that we've loaded already, and then see if there's a key on disk.
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews */
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewsstatic signer_key_t *
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewskeythatsigned(dns_rdata_sig_t *sig) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews isc_result_t result;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dst_key_t *pubkey = NULL, *privkey = NULL;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews signer_key_t *key;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews key = ISC_LIST_HEAD(keylist);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews while (key != NULL) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (sig->keyid == dst_key_id(key->key) &&
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews sig->algorithm == dst_key_alg(key->key) &&
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_name_equal(&sig->signer, dst_key_name(key->key)))
ae4cbb69eef32ced103fe4561e8d2031ee4c3497David Lawrence return key;
ae4cbb69eef32ced103fe4561e8d2031ee4c3497David Lawrence key = ISC_LIST_NEXT(key, link);
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence }
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence result = dst_key_fromfile(&sig->signer, sig->keyid, sig->algorithm,
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence DST_TYPE_PUBLIC, NULL, mctx, &pubkey);
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence if (result != ISC_R_SUCCESS)
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence return (NULL);
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence key = isc_mem_get(mctx, sizeof(signer_key_t));
0293ad13207aa29bd5844cdc87d085ffc009d749David Lawrence if (key == NULL)
0293ad13207aa29bd5844cdc87d085ffc009d749David Lawrence fatal("out of memory");
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = dst_key_fromfile(&sig->signer, sig->keyid, sig->algorithm,
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews DST_TYPE_PRIVATE, NULL, mctx, &privkey);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (result == ISC_R_SUCCESS) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews key->key = privkey;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dst_key_free(&pubkey);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews }
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews else
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews key->key = pubkey;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews key->isdefault = ISC_FALSE;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews ISC_LIST_APPEND(keylist, key, link);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews return key;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews}
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
0293ad13207aa29bd5844cdc87d085ffc009d749David Lawrence/*
0293ad13207aa29bd5844cdc87d085ffc009d749David Lawrence * Check to see if we expect to find a key at this name. If we see a SIG
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence * and can't find the signing key that we expect to find, we drop the sig.
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence * I'm not sure if this is completely correct, but it seems to work.
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence */
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrencestatic isc_boolean_t
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrenceexpecttofindkey(dns_name_t *name, dns_db_t *db, dns_dbversion_t *version) {
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence unsigned int options = DNS_DBFIND_NOWILD;
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence dns_fixedname_t fname;
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence isc_result_t result;
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff dns_fixedname_init(&fname);
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff result = dns_db_find(db, name, version, dns_rdatatype_key, options,
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff 0, NULL, dns_fixedname_name(&fname), NULL, NULL);
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff switch (result) {
1ce985ab3c6670662d555c108b35fed84a6a1001David Lawrence case ISC_R_SUCCESS:
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews case DNS_R_NXDOMAIN:
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews case DNS_R_NXRRSET:
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews return ISC_TRUE;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews case DNS_R_DELEGATION:
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews case DNS_R_CNAME:
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews case DNS_R_DNAME:
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence return ISC_FALSE;
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence default:
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence fatal("failure looking for '%s KEY' in database: %s",
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence nametostr(name), isc_result_totext(result));
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence return ISC_FALSE; /* removes a warning */
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence }
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence}
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrencestatic inline isc_boolean_t
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrencesetverifies(dns_name_t *name, dns_rdataset_t *set, signer_key_t *key,
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence dns_rdata_t *sig)
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence{
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence isc_result_t result;
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence result = dns_dnssec_verify(name, set, key->key, ISC_FALSE, mctx, sig);
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence return (ISC_TF(result == ISC_R_SUCCESS));
4bcaefbcd3ced942139fdc830e007c6ea2b8d2feDavid Lawrence}
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff#define allocbufferandrdata \
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff isc_buffer_t b; \
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff trdata = isc_mem_get(mctx, sizeof(dns_rdata_t)); \
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff tdata = isc_mem_get(mctx, sizeof(signer_array_t)); \
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff ISC_LIST_APPEND(arraylist, tdata, link); \
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff if (trdata == NULL || tdata == NULL) \
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff fatal("out of memory"); \
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff isc_buffer_init(&b, tdata->array, sizeof(tdata->array));
657ce0b9d84fbd66514df53d61a087e8f1161187Michael Graff
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson/*
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson * Signs a set. Goes through contortions to decide if each SIG should
641da3ca1184d9951d5cf91538524a345bf5f271Mark Andrews * be dropped or retained, and then determines if any new SIGs need to
641da3ca1184d9951d5cf91538524a345bf5f271Mark Andrews * be generated.
641da3ca1184d9951d5cf91538524a345bf5f271Mark Andrews */
641da3ca1184d9951d5cf91538524a345bf5f271Mark Andrewsstatic void
641da3ca1184d9951d5cf91538524a345bf5f271Mark Andrewssignset(dns_db_t *db, dns_dbversion_t *version, dns_dbnode_t *node,
80badf38c74c326a694e24281ee258aa26984171Mark Andrews dns_name_t *name, dns_rdataset_t *set)
641da3ca1184d9951d5cf91538524a345bf5f271Mark Andrews{
641da3ca1184d9951d5cf91538524a345bf5f271Mark Andrews dns_rdatalist_t siglist;
641da3ca1184d9951d5cf91538524a345bf5f271Mark Andrews dns_rdataset_t sigset, oldsigset;
641da3ca1184d9951d5cf91538524a345bf5f271Mark Andrews dns_rdata_t oldsigrdata;
641da3ca1184d9951d5cf91538524a345bf5f271Mark Andrews dns_rdata_t *trdata;
9fe28a624c659e380d47dbf45527637dab03b998Mark Andrews dns_rdata_sig_t sig;
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews signer_key_t *key;
9fe28a624c659e380d47dbf45527637dab03b998Mark Andrews isc_result_t result;
9fe28a624c659e380d47dbf45527637dab03b998Mark Andrews isc_boolean_t notsigned = ISC_TRUE, nosigs = ISC_FALSE;
323a9f3430abf186f8f84d795549391a8ed7f274Francis Dupont isc_boolean_t wassignedby[256], nowsignedby[256];
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews signer_array_t *tdata;
9fe28a624c659e380d47dbf45527637dab03b998Mark Andrews ISC_LIST(signer_array_t) arraylist;
9fe28a624c659e380d47dbf45527637dab03b998Mark Andrews int i;
9fe28a624c659e380d47dbf45527637dab03b998Mark Andrews
9fe28a624c659e380d47dbf45527637dab03b998Mark Andrews ISC_LIST_INIT(siglist.rdata);
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews ISC_LIST_INIT(arraylist);
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews for (i = 0; i < 256; i++)
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews wassignedby[i] = nowsignedby[i] = ISC_FALSE;
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews dns_rdataset_init(&oldsigset);
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews result = dns_db_findrdataset(db, node, version, dns_rdatatype_sig,
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews set->type, 0, &oldsigset, NULL);
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews if (result == ISC_R_NOTFOUND) {
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews result = ISC_R_SUCCESS;
774c3a62d9adca187b44fe90919bb409a43a2f2aMark Andrews nosigs = ISC_TRUE;
d7896edb4e93c4785a9281ea86afba86b758e813Mark Andrews }
d7896edb4e93c4785a9281ea86afba86b758e813Mark Andrews if (result != ISC_R_SUCCESS)
d7896edb4e93c4785a9281ea86afba86b758e813Mark Andrews fatal("failed while looking for '%s SIG %s': %s",
d7896edb4e93c4785a9281ea86afba86b758e813Mark Andrews nametostr(name), typetostr(set->type),
d7896edb4e93c4785a9281ea86afba86b758e813Mark Andrews isc_result_totext(result));
d7896edb4e93c4785a9281ea86afba86b758e813Mark Andrews
d7896edb4e93c4785a9281ea86afba86b758e813Mark Andrews vbprintf(1, "%s/%s:\n", nametostr(name), typetostr(set->type));
d7896edb4e93c4785a9281ea86afba86b758e813Mark Andrews
d7896edb4e93c4785a9281ea86afba86b758e813Mark Andrews if (!nosigs) {
9fe28a624c659e380d47dbf45527637dab03b998Mark Andrews result = dns_rdataset_first(&oldsigset);
9fe28a624c659e380d47dbf45527637dab03b998Mark Andrews while (result == ISC_R_SUCCESS) {
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson isc_boolean_t expired, future;
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson isc_boolean_t keep = ISC_FALSE, resign = ISC_FALSE;
31b7a2fed64e388db772a74742a4adc95d1a21e6Mark Andrews
6342df69b05f2f62d060fd4affdf536e51504084Mark Andrews dns_rdataset_current(&oldsigset, &oldsigrdata);
6342df69b05f2f62d060fd4affdf536e51504084Mark Andrews
6342df69b05f2f62d060fd4affdf536e51504084Mark Andrews result = dns_rdata_tostruct(&oldsigrdata, &sig, mctx);
6342df69b05f2f62d060fd4affdf536e51504084Mark Andrews check_result(result, "dns_rdata_tostruct");
6342df69b05f2f62d060fd4affdf536e51504084Mark Andrews
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson expired = ISC_TF(now + cycle > sig.timeexpire);
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson future = ISC_TF(now < sig.timesigned);
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson
8486ce1efa5deded85415d21d5696e5a51c63357Mark Andrews key = keythatsigned(&sig);
c654449ccf403ccd2b81be2038b1013d6fbb06ccMark Andrews
5b02fc32d693bb811199308a40143df0adf818c1Mark Andrews if (sig.timesigned > sig.timeexpire) {
6fcb2f0faad67a6d2cb2e30ec57157d75fbfe58fAndreas Gustafsson /* sig is dropped and not replaced */
38cd4d14cc341c2663e574035074788bb6f0fce2Evan Hunt vbprintf(2, "\tsig by %s/%s/%d dropped - "
38cd4d14cc341c2663e574035074788bb6f0fce2Evan Hunt "invalid validity period\n",
38cd4d14cc341c2663e574035074788bb6f0fce2Evan Hunt nametostr(&sig.signer),
38cd4d14cc341c2663e574035074788bb6f0fce2Evan Hunt algtostr(sig.algorithm),
38cd4d14cc341c2663e574035074788bb6f0fce2Evan Hunt sig.keyid);
38cd4d14cc341c2663e574035074788bb6f0fce2Evan Hunt }
6fcb2f0faad67a6d2cb2e30ec57157d75fbfe58fAndreas Gustafsson else if (key == NULL && !future &&
6fcb2f0faad67a6d2cb2e30ec57157d75fbfe58fAndreas Gustafsson expecttofindkey(&sig.signer, db, version))
6fcb2f0faad67a6d2cb2e30ec57157d75fbfe58fAndreas Gustafsson {
6fcb2f0faad67a6d2cb2e30ec57157d75fbfe58fAndreas Gustafsson /* sig is dropped and not replaced */
6fcb2f0faad67a6d2cb2e30ec57157d75fbfe58fAndreas Gustafsson vbprintf(2, "\tsig by %s/%s/%d dropped - "
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington "private key not found\n",
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington nametostr(&sig.signer),
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington algtostr(sig.algorithm),
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington sig.keyid);
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington }
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington else if (key == NULL || future) {
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington vbprintf(2, "\tsig by %s/%s/%d %s - "
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington "key not found\n",
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington expired ? "retained" : "dropped",
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington nametostr(&sig.signer),
47fd46791da765e3dbedd987e9b263b3bee25986Brian Wellington algtostr(sig.algorithm),
6fcb2f0faad67a6d2cb2e30ec57157d75fbfe58fAndreas Gustafsson sig.keyid);
6fcb2f0faad67a6d2cb2e30ec57157d75fbfe58fAndreas Gustafsson if (!expired)
87708bde16713bc02ff2598f4a82f98c699a2f2dMark Andrews keep = ISC_TRUE;
6fcb2f0faad67a6d2cb2e30ec57157d75fbfe58fAndreas Gustafsson }
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson else if (issigningkey(key)) {
8f3dd8f8e73e4465221a5297819db70e6b383138Mark Andrews if (!expired &&
6e9efadbea9febb0494e713e54dfea6f7ef70383Mark Andrews setverifies(name, set, key, &oldsigrdata))
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews {
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews vbprintf(2,
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews "\tsig by %s/%s/%d retained\n",
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews nametostr(&sig.signer),
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews algtostr(sig.algorithm),
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews sig.keyid);
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews keep = ISC_TRUE;
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews wassignedby[sig.algorithm] = ISC_TRUE;
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews }
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews else {
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews vbprintf(2,
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews "\tsig by %s/%s/%d dropped - "
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews "%s\n",
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews nametostr(&sig.signer),
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews algtostr(sig.algorithm),
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews sig.keyid,
43fe2897fc80bbec2115310ca79d432a252f3ea4Mark Andrews expired ? "expired" :
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson "failed to verify");
754cca729dd82ae8363917dc00ad44f9d900635bMark Andrews wassignedby[sig.algorithm] = ISC_TRUE;
754cca729dd82ae8363917dc00ad44f9d900635bMark Andrews resign = ISC_TRUE;
754cca729dd82ae8363917dc00ad44f9d900635bMark Andrews }
754cca729dd82ae8363917dc00ad44f9d900635bMark Andrews }
754cca729dd82ae8363917dc00ad44f9d900635bMark Andrews else if (iszonekey(key, db)) {
754cca729dd82ae8363917dc00ad44f9d900635bMark Andrews if (!expired &&
754cca729dd82ae8363917dc00ad44f9d900635bMark Andrews setverifies(name, set, key, &oldsigrdata))
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson {
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont vbprintf(2,
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont "\tsig by %s/%s/%d retained\n",
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont nametostr(&sig.signer),
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont algtostr(sig.algorithm),
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont sig.keyid);
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont keep = ISC_TRUE;
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont wassignedby[sig.algorithm] = ISC_TRUE;
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont nowsignedby[sig.algorithm] = ISC_TRUE;
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont }
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont else {
339c130823ff00cdfa70d1f0a8922199aa37f33cMark Andrews vbprintf(2,
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont "\tsig by %s/%s/%d "
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont "dropped - %s\n",
debd489a44363870f96f75818e89ec27d3cab736Francis Dupont nametostr(&sig.signer),
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews algtostr(sig.algorithm),
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews sig.keyid,
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews expired ? "expired" :
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews "failed to verify");
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews wassignedby[sig.algorithm] = ISC_TRUE;
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews if (dst_key_isprivate(key->key))
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews resign = ISC_TRUE;
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews }
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews }
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews else if (!expired) {
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews vbprintf(2, "\tsig by %s/%s/%d retained\n",
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews nametostr(&sig.signer),
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews algtostr(sig.algorithm),
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews sig.keyid);
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews keep = ISC_TRUE;
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews }
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews else {
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews vbprintf(2, "\tsig by %s/%s/%d expired\n",
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews nametostr(&sig.signer),
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews algtostr(sig.algorithm),
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 sig.keyid);
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 }
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews if (keep) {
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews allocbufferandrdata;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews result = dns_rdata_fromstruct(trdata,
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews set->rdclass,
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 dns_rdatatype_sig,
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews &sig, &b);
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews nowsignedby[sig.algorithm] = ISC_TRUE;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews ISC_LIST_APPEND(siglist.rdata, trdata, link);
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews }
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews else if (resign) {
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews allocbufferandrdata;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews vbprintf(1, "\tresigning with key %s/%s/%d\n",
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews nametostr(dst_key_name(key->key)),
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews algtostr(dst_key_alg(key->key)),
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 dst_key_id(key->key));
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 signwithkey(name, set, trdata, key->key, &b);
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 nowsignedby[sig.algorithm] = ISC_TRUE;
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 ISC_LIST_APPEND(siglist.rdata, trdata, link);
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 }
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 dns_rdata_freestruct(&sig);
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 result = dns_rdataset_next(&oldsigset);
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews }
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews if (result == ISC_R_NOMORE)
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 result = ISC_R_SUCCESS;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews check_result(result, "dns_db_dns_rdataset_first()/next()");
ddb35cf2f301ae1c3fa601792034f6d349efc8c5Mark Andrews dns_rdataset_disassociate(&oldsigset);
ddb35cf2f301ae1c3fa601792034f6d349efc8c5Mark Andrews }
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews
ddb35cf2f301ae1c3fa601792034f6d349efc8c5Mark Andrews for (i = 0; i < 256; i++)
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews if (wassignedby[i] != 0) {
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews notsigned = ISC_FALSE;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews break;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews }
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews key = ISC_LIST_HEAD(keylist);
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews while (key != NULL) {
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews unsigned int alg = dst_key_alg(key->key);
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews if (key->isdefault &&
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews (notsigned || (wassignedby[alg] && !nowsignedby[alg])))
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews {
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews allocbufferandrdata;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews vbprintf(1, "\tsigning with key %s/%s/%d\n",
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 nametostr(dst_key_name(key->key)),
ddb35cf2f301ae1c3fa601792034f6d349efc8c5Mark Andrews algtostr(dst_key_alg(key->key)),
ddb35cf2f301ae1c3fa601792034f6d349efc8c5Mark Andrews dst_key_id(key->key));
ddb35cf2f301ae1c3fa601792034f6d349efc8c5Mark Andrews signwithkey(name, set, trdata, key->key, &b);
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 ISC_LIST_APPEND(siglist.rdata, trdata, link);
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 }
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 key = ISC_LIST_NEXT(key, link);
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 }
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 if (!ISC_LIST_EMPTY(siglist.rdata)) {
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 siglist.rdclass = set->rdclass;
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 siglist.type = dns_rdatatype_sig;
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉 siglist.covers = set->type;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews if (endtime - starttime < set->ttl)
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews siglist.ttl = endtime - starttime;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews else
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews siglist.ttl = set->ttl;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews dns_rdataset_init(&sigset);
c0a76b3c0b42a110e14eb56103973944900400c4Mark Andrews result = dns_rdatalist_tordataset(&siglist, &sigset);
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews check_result(result, "dns_rdatalist_tordataset");
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews result = dns_db_addrdataset(db, node, version, 0, &sigset,
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews 0, NULL);
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews if (result == DNS_R_UNCHANGED)
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews result = ISC_R_SUCCESS;
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews check_result(result, "dns_db_addrdataset");
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews dns_rdataset_disassociate(&sigset);
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews }
3dfa202e4fea6b985bcf8761e2d11c176baa40d1Mark Andrews else if (!nosigs) {
386d3a99c190bad55edf44d076e6bd087e230ab8Tatuya JINMEI 神明達哉#if 0
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews /*
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson * If this is compiled in, running a signed set through the
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson * signer with no private keys causes DNS_R_BADDB to occur
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson * later. This is bad.
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson */
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson result = dns_db_deleterdataset(db, node, version,
963c48ba4d06a112c70d50328e827749e95f58dbMark Andrews dns_rdatatype_sig, set->type);
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson if (result == ISC_R_NOTFOUND)
963c48ba4d06a112c70d50328e827749e95f58dbMark Andrews result = ISC_R_SUCCESS;
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson check_result(result, "dns_db_deleterdataset");
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson#endif
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson fatal("File is currently signed but no private keys were "
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson "found. This won't work.");
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson }
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson
a1898260ad19d02e88ab76c1855d33c67add9defMark Andrews trdata = ISC_LIST_HEAD(siglist.rdata);
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson while (trdata != NULL) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdata_t *next = ISC_LIST_NEXT(trdata, link);
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson isc_mem_put(mctx, trdata, sizeof(dns_rdata_t));
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson trdata = next;
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson }
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson tdata = ISC_LIST_HEAD(arraylist);
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson while (tdata != NULL) {
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson signer_array_t *next = ISC_LIST_NEXT(tdata, link);
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson isc_mem_put(mctx, tdata, sizeof(signer_array_t));
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson tdata = next;
a1898260ad19d02e88ab76c1855d33c67add9defMark Andrews }
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson}
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson#ifndef USE_ZONESTATUS
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson/* Determine if a KEY set contains a null key */
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafssonstatic isc_boolean_t
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafssonhasnullkey(dns_rdataset_t *rdataset) {
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson isc_result_t result;
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson dns_rdata_t rdata;
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson isc_boolean_t found = ISC_FALSE;
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson result = dns_rdataset_first(rdataset);
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson while (result == ISC_R_SUCCESS) {
5ff133b82082d82f0ba89b7c999c6b62b6298e46Andreas Gustafsson dst_key_t *key = NULL;
90407942d3afe50f04ccea361de3b164a5a1702dMichael Graff
90407942d3afe50f04ccea361de3b164a5a1702dMichael Graff dns_rdataset_current(rdataset, &rdata);
90407942d3afe50f04ccea361de3b164a5a1702dMichael Graff result = dns_dnssec_keyfromrdata(dns_rootname,
90407942d3afe50f04ccea361de3b164a5a1702dMichael Graff &rdata, mctx, &key);
90407942d3afe50f04ccea361de3b164a5a1702dMichael Graff if (result != ISC_R_SUCCESS)
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews fatal("could not convert KEY into internal format");
13faa8b6a2d0d45e0659049983928366252ab3faMichael Graff if (dst_key_isnullkey(key))
13faa8b6a2d0d45e0659049983928366252ab3faMichael Graff found = ISC_TRUE;
13faa8b6a2d0d45e0659049983928366252ab3faMichael Graff dst_key_free(&key);
3ca0e71a863fe3fbb4f439e5d0bebfd7bd38fb16Mark Andrews if (found == ISC_TRUE)
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson return (ISC_TRUE);
13faa8b6a2d0d45e0659049983928366252ab3faMichael Graff result = dns_rdataset_next(rdataset);
90c1e763d577da656b5eeb02462b5236dca5f266Mark Andrews }
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (result != ISC_R_NOMORE)
3d8dfd44a3be708f00380064411c16b2fa28303aMark Andrews fatal("failure looking for null keys");
13faa8b6a2d0d45e0659049983928366252ab3faMichael Graff return (ISC_FALSE);
4cf228853d658a742a826393f341e2486c629f7bMark Andrews}
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews#endif
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews/*
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews * Looks for signatures of the zone keys by the parent, and imports them
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews * if found.
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews */
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrewsstatic void
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrewsimportparentsig(dns_db_t *db, dns_dbversion_t *version, dns_dbnode_t *node,
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews dns_name_t *name, dns_rdataset_t *set)
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews{
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews unsigned char filename[256];
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews isc_buffer_t b;
5f9e583552f53de12062bfff12e47250abce378fBrian Wellington dns_db_t *newdb = NULL;
5f9e583552f53de12062bfff12e47250abce378fBrian Wellington dns_dbnode_t *newnode = NULL;
3fcf6b956f47405750724bd84e1b2290b61c9186Brian Wellington dns_rdataset_t newset, sigset;
3fcf6b956f47405750724bd84e1b2290b61c9186Brian Wellington dns_rdata_t rdata, newrdata;
3fcf6b956f47405750724bd84e1b2290b61c9186Brian Wellington isc_result_t result;
76117ff568dc788ed24937cfea916a18db285960Mark Andrews
76117ff568dc788ed24937cfea916a18db285960Mark Andrews dns_rdataset_init(&newset);
5f9e583552f53de12062bfff12e47250abce378fBrian Wellington dns_rdataset_init(&sigset);
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews isc_buffer_init(&b, filename, sizeof(filename));
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews isc_buffer_putstr(&b, "signedkey-");
76117ff568dc788ed24937cfea916a18db285960Mark Andrews result = dns_name_totext(name, ISC_FALSE, &b);
76117ff568dc788ed24937cfea916a18db285960Mark Andrews check_result(result, "dns_name_totext()");
45eea1bda65a66106bb7d85eae5997deb013bf0cMark Andrews if (isc_buffer_availablelength(&b) == 0)
45eea1bda65a66106bb7d85eae5997deb013bf0cMark Andrews fatal("name '%s' is too long", nametostr(name));
45eea1bda65a66106bb7d85eae5997deb013bf0cMark Andrews isc_buffer_putuint8(&b, 0);
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews result = dns_db_create(mctx, "rbt", name, dns_dbtype_zone,
5f9e583552f53de12062bfff12e47250abce378fBrian Wellington dns_db_class(db), 0, NULL, &newdb);
a53259c4cc558f86dd008eccc60cc89b6734a03cMark Andrews check_result(result, "dns_db_create()");
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson result = dns_db_load(newdb, (char *)filename);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (result != ISC_R_SUCCESS)
68f72235f8f41fa949823551d8e6476057ec5bd6Andreas Gustafsson goto failure;
68f72235f8f41fa949823551d8e6476057ec5bd6Andreas Gustafsson result = dns_db_findnode(newdb, name, ISC_FALSE, &newnode);
68f72235f8f41fa949823551d8e6476057ec5bd6Andreas Gustafsson if (result != ISC_R_SUCCESS)
68f72235f8f41fa949823551d8e6476057ec5bd6Andreas Gustafsson goto failure;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = dns_db_findrdataset(newdb, newnode, NULL, dns_rdatatype_key,
68f72235f8f41fa949823551d8e6476057ec5bd6Andreas Gustafsson 0, 0, &newset, &sigset);
68f72235f8f41fa949823551d8e6476057ec5bd6Andreas Gustafsson if (result != ISC_R_SUCCESS)
68f72235f8f41fa949823551d8e6476057ec5bd6Andreas Gustafsson goto failure;
68f72235f8f41fa949823551d8e6476057ec5bd6Andreas Gustafsson
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson if (dns_rdataset_count(set) != dns_rdataset_count(&newset))
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews goto failure;
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson
80f323528ac699026a609a5e3b765dc6e88fe37cAndreas Gustafsson dns_rdata_init(&rdata);
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson dns_rdata_init(&newrdata);
0807f596b58e22dd123539d0a351ef061c5eaae4Mark Andrews
0807f596b58e22dd123539d0a351ef061c5eaae4Mark Andrews result = dns_rdataset_first(set);
0807f596b58e22dd123539d0a351ef061c5eaae4Mark Andrews check_result(result, "dns_rdataset_first()");
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson for (; result == ISC_R_SUCCESS; result = dns_rdataset_next(set)) {
3fcf6b956f47405750724bd84e1b2290b61c9186Brian Wellington dns_rdataset_current(set, &rdata);
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews result = dns_rdataset_first(&newset);
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews check_result(result, "dns_rdataset_first()");
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews for (;
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews result == ISC_R_SUCCESS;
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews result = dns_rdataset_next(&newset))
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews {
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews dns_rdataset_current(&newset, &newrdata);
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews if (dns_rdata_compare(&rdata, &newrdata) == 0)
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews break;
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews }
f8f65e2de40b1e9874b88f392f3abeb057ce6172Mark Andrews if (result != ISC_R_SUCCESS)
f8f65e2de40b1e9874b88f392f3abeb057ce6172Mark Andrews break;
f8f65e2de40b1e9874b88f392f3abeb057ce6172Mark Andrews }
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews if (result != ISC_R_NOMORE)
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews goto failure;
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews vbprintf(2, "found the parent's signature of our zone key\n");
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews result = dns_db_addrdataset(db, node, version, 0, &sigset, 0, NULL);
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews check_result(result, "dns_db_addrdataset");
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews failure:
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews if (dns_rdataset_isassociated(&newset))
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews dns_rdataset_disassociate(&newset);
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews if (dns_rdataset_isassociated(&sigset))
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews dns_rdataset_disassociate(&sigset);
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews if (newnode != NULL)
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews dns_db_detachnode(newdb, &newnode);
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews if (newdb != NULL)
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews dns_db_detach(&newdb);
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews}
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews
c5826852e6c789f59b301f8197e65a1dd4e09a44Mark Andrews/*
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews * Looks for our signatures of child keys. If present, inform the caller,
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson * who will set the zone status (KEY) bit in the NXT record.
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson */
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafssonstatic isc_boolean_t
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafssonhaschildkey(dns_db_t *db, dns_name_t *name) {
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson unsigned char filename[256];
bc53aacc6e9302b1f8d01467fc39585584652782Andreas Gustafsson isc_buffer_t b;
bc53aacc6e9302b1f8d01467fc39585584652782Andreas Gustafsson dns_db_t *newdb = NULL;
bc53aacc6e9302b1f8d01467fc39585584652782Andreas Gustafsson dns_dbnode_t *newnode = NULL;
bc53aacc6e9302b1f8d01467fc39585584652782Andreas Gustafsson dns_rdataset_t set, sigset;
bc53aacc6e9302b1f8d01467fc39585584652782Andreas Gustafsson dns_rdata_t sigrdata;
d906600f7d1e86a4315e65a500f806ca1e4caa9bAndreas Gustafsson isc_result_t result;
bc53aacc6e9302b1f8d01467fc39585584652782Andreas Gustafsson isc_boolean_t found = ISC_FALSE;
bc53aacc6e9302b1f8d01467fc39585584652782Andreas Gustafsson dns_rdata_sig_t sig;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews signer_key_t *key;
bc53aacc6e9302b1f8d01467fc39585584652782Andreas Gustafsson
2995f8205eaa0d4bc3a57900a413b5cfdb83564fAndreas Gustafsson dns_rdataset_init(&set);
2995f8205eaa0d4bc3a57900a413b5cfdb83564fAndreas Gustafsson dns_rdataset_init(&sigset);
2995f8205eaa0d4bc3a57900a413b5cfdb83564fAndreas Gustafsson
2995f8205eaa0d4bc3a57900a413b5cfdb83564fAndreas Gustafsson isc_buffer_init(&b, filename, sizeof(filename));
bc53aacc6e9302b1f8d01467fc39585584652782Andreas Gustafsson isc_buffer_putstr(&b, "signedkey-");
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews result = dns_name_totext(name, ISC_FALSE, &b);
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews check_result(result, "dns_name_totext()");
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews if (isc_buffer_availablelength(&b) == 0)
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews fatal("name '%s' is too long", nametostr(name));
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews isc_buffer_putuint8(&b, 0); /* Add a NUL. */
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews result = dns_db_create(mctx, "rbt", name, dns_dbtype_zone,
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews dns_db_class(db), 0, NULL, &newdb);
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews check_result(result, "dns_db_create()");
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews result = dns_db_load(newdb, (char *)filename);
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews if (result != ISC_R_SUCCESS)
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews goto failure;
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews result = dns_db_findnode(newdb, name, ISC_FALSE, &newnode);
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews if (result != ISC_R_SUCCESS)
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews goto failure;
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews result = dns_db_findrdataset(newdb, newnode, NULL, dns_rdatatype_key,
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews 0, 0, &set, &sigset);
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews if (result != ISC_R_SUCCESS)
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews goto failure;
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews if (!dns_rdataset_isassociated(&set) ||
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews !dns_rdataset_isassociated(&sigset))
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews goto failure;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews result = dns_rdataset_first(&sigset);
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews check_result(result, "dns_rdataset_first()");
bc53aacc6e9302b1f8d01467fc39585584652782Andreas Gustafsson dns_rdata_init(&sigrdata);
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson for (; result == ISC_R_SUCCESS; result = dns_rdataset_next(&sigset)) {
919caa020b8f9b856d77b3a72e0c9301dfa495c7Andreas Gustafsson dns_rdataset_current(&sigset, &sigrdata);
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson result = dns_rdata_tostruct(&sigrdata, &sig, mctx);
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson if (result != ISC_R_SUCCESS)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews goto failure;
6805e4e2c46ad3c5a4aa941b5e9a29d34579641eMark Andrews key = keythatsigned(&sig);
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews dns_rdata_freestruct(&sig);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (key == NULL)
bd1db480f30e025bba719799f910b34848a9a997Mark Andrews goto failure;
bd1db480f30e025bba719799f910b34848a9a997Mark Andrews result = dns_dnssec_verify(name, &set, key->key,
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews ISC_FALSE, mctx, &sigrdata);
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews if (result == ISC_R_SUCCESS) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews found = ISC_TRUE;
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson break;
3ca0e71a863fe3fbb4f439e5d0bebfd7bd38fb16Mark Andrews }
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews }
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews failure:
3ca0e71a863fe3fbb4f439e5d0bebfd7bd38fb16Mark Andrews if (dns_rdataset_isassociated(&set))
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews dns_rdataset_disassociate(&set);
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews if (dns_rdataset_isassociated(&sigset))
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews dns_rdataset_disassociate(&sigset);
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews if (newnode != NULL)
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews dns_db_detachnode(newdb, &newnode);
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews if (newdb != NULL)
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews dns_db_detach(&newdb);
c0707105f60934d59321c2fccbc254f9e31ff28aMark Andrews
c0707105f60934d59321c2fccbc254f9e31ff28aMark Andrews return (found);
c0707105f60934d59321c2fccbc254f9e31ff28aMark Andrews}
c0707105f60934d59321c2fccbc254f9e31ff28aMark Andrews
c0707105f60934d59321c2fccbc254f9e31ff28aMark Andrews/*
c0707105f60934d59321c2fccbc254f9e31ff28aMark Andrews * Signs all records at a name. This mostly just signs each set individually,
c0707105f60934d59321c2fccbc254f9e31ff28aMark Andrews * but also adds the SIG bit to any NXTs generated earlier, deals with
c0707105f60934d59321c2fccbc254f9e31ff28aMark Andrews * parent/child KEY signatures, and handles other exceptional cases.
e09cdbac087b88524ac40e943d040e2a032c48f2Mark Andrews */
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewsstatic void
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewssignname(dns_db_t *db, dns_dbversion_t *version, dns_dbnode_t *node,
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews dns_name_t *name)
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews{
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews isc_result_t result;
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews dns_rdata_t rdata;
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews dns_rdataset_t rdataset;
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews dns_rdatasetiter_t *rdsiter;
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews isc_boolean_t isdelegation = ISC_FALSE;
8d326446399c0604686189edde681bd1e2778452Francis Dupont isc_boolean_t childkey = ISC_FALSE;
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews static int warnwild = 0;
8d326446399c0604686189edde681bd1e2778452Francis Dupont isc_boolean_t atorigin;
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews if (dns_name_iswildcard(name)) {
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews if (warnwild++ == 0) {
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews fprintf(stderr, "%s: warning: BIND 9 doesn't properly "
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews "handle wildcards in secure zones:\n",
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews program);
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews fprintf(stderr, "\t- wildcard nonexistence proof is "
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews "not generated by the server\n");
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews fprintf(stderr, "\t- wildcard nonexistence proof is "
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews "not required by the resolver\n");
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews }
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews fprintf(stderr, "%s: warning: wildcard name seen: %s\n",
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews program, nametostr(name));
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews }
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews atorigin = dns_name_equal(name, dns_db_origin(db));
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews if (!atorigin) {
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt dns_rdataset_t nsset;
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt dns_rdataset_init(&nsset);
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt result = dns_db_findrdataset(db, node, version,
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt dns_rdatatype_ns, 0, 0, &nsset,
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt NULL);
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt /* Is this a delegation point? */
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt if (result == ISC_R_SUCCESS) {
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt isdelegation = ISC_TRUE;
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt dns_rdataset_disassociate(&nsset);
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt }
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt }
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt dns_rdataset_init(&rdataset);
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt rdsiter = NULL;
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt result = dns_db_allrdatasets(db, node, version, 0, &rdsiter);
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt check_result(result, "dns_db_allrdatasets()");
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt result = dns_rdatasetiter_first(rdsiter);
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt while (result == ISC_R_SUCCESS) {
85a79fa7eb17767d9ae9030e0289ed3e95aab7c8Evan Hunt dns_rdatasetiter_current(rdsiter, &rdataset);
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews /* If this is a SIG set, skip it. */
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews if (rdataset.type == dns_rdatatype_sig)
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews goto skip;
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews /*
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews * If this is a KEY set at the apex, look for a signedkey file.
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews */
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews if (rdataset.type == dns_rdatatype_key && atorigin) {
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson importparentsig(db, version, node, name, &rdataset);
5989aea4bbe79e09290792f04aeb557e2b2da02eAndreas Gustafsson goto skip;
76117ff568dc788ed24937cfea916a18db285960Mark Andrews }
76117ff568dc788ed24937cfea916a18db285960Mark Andrews
e09cdbac087b88524ac40e943d040e2a032c48f2Mark Andrews /*
5f9e583552f53de12062bfff12e47250abce378fBrian Wellington * If this name is a delegation point, skip all records
5f9e583552f53de12062bfff12e47250abce378fBrian Wellington * except an NXT set, unless we're using null keys, in
08a768e82ad64ede97f640c88e02984b59122753Michael Graff * which case we need to check for a null key and add one
08a768e82ad64ede97f640c88e02984b59122753Michael Graff * if it's not present.
08a768e82ad64ede97f640c88e02984b59122753Michael Graff */
08a768e82ad64ede97f640c88e02984b59122753Michael Graff if (isdelegation) {
08a768e82ad64ede97f640c88e02984b59122753Michael Graff switch (rdataset.type) {
08a768e82ad64ede97f640c88e02984b59122753Michael Graff case dns_rdatatype_nxt:
3fcf6b956f47405750724bd84e1b2290b61c9186Brian Wellington childkey = haschildkey(db, name);
0e40083fdd5445703bd30e46e5bfe7d047bced12Brian Wellington break;
76117ff568dc788ed24937cfea916a18db285960Mark Andrews#ifndef USE_ZONESTATUS
76117ff568dc788ed24937cfea916a18db285960Mark Andrews case dns_rdatatype_key:
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews if (hasnullkey(&rdataset))
0e40083fdd5445703bd30e46e5bfe7d047bced12Brian Wellington break;
08a768e82ad64ede97f640c88e02984b59122753Michael Graff goto skip;
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont#endif
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont default:
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont goto skip;
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont }
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont }
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont /*
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont * There probably should be a dns_nxtsetbit, but it can get
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont * complicated if we need to extend the length of the
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont * bit set. In this case, since the NXT bit is set and
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont * SIG < NXT and KEY < NXT, the easy way works.
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont */
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont if (rdataset.type == dns_rdatatype_nxt) {
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont unsigned char *nxt_bits;
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont dns_name_t nxtname;
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont isc_region_t r, r2;
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont unsigned char keydata[4];
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont dst_key_t *dstkey;
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont isc_buffer_t b;
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont result = dns_rdataset_first(&rdataset);
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont check_result(result, "dns_rdataset_first()");
c1d7e0562f6a72ecc07ab5140cf2b88183adbd08Francis Dupont dns_rdataset_current(&rdataset, &rdata);
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont dns_rdata_toregion(&rdata, &r);
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont dns_name_init(&nxtname, NULL);
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont dns_name_fromregion(&nxtname, &r);
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont dns_name_toregion(&nxtname, &r2);
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont nxt_bits = r.base + r2.length;
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont set_bit(nxt_bits, dns_rdatatype_sig, 1);
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont#ifdef USE_ZONESTATUS
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont if (isdelegation && childkey) {
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont set_bit(nxt_bits, dns_rdatatype_key, 1);
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont vbprintf(2, "found a child key for %s, "
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont "setting KEY bit in NXT\n",
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont nametostr(name));
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont }
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont#else
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont if (isdelegation && !childkey) {
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont dns_rdataset_t keyset;
95b41985f7dfac76f2dccd90f5ef4d820d409e60Evan Hunt dns_rdatalist_t keyrdatalist;
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont dns_rdata_t keyrdata;
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont dns_rdataset_init(&keyset);
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont result = dns_db_findrdataset(db, node, version,
95b41985f7dfac76f2dccd90f5ef4d820d409e60Evan Hunt dns_rdatatype_key,
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont 0, 0, &keyset,
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont NULL);
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont if (result == ISC_R_SUCCESS &&
95b41985f7dfac76f2dccd90f5ef4d820d409e60Evan Hunt hasnullkey(&keyset))
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont goto alreadyhavenullkey;
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont if (result == ISC_R_NOTFOUND)
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont result = ISC_R_SUCCESS;
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont if (result != ISC_R_SUCCESS)
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont fatal("failure looking for null key "
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont "at '%s': %s", nametostr(name),
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont isc_result_totext(result));
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont if (dns_rdataset_isassociated(&keyset))
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont dns_rdataset_disassociate(&keyset);
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont vbprintf(2, "no child key for %s, "
a631b30b1ddd8b2ea780371d0d99ba1c05bc7e42Francis Dupont "adding null key\n",
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews nametostr(name));
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdatalist_init(&keyrdatalist);
4fc55db699529ce60f7f1e12aae40e315831c67fScott Mann dstkey = NULL;
4fc55db699529ce60f7f1e12aae40e315831c67fScott Mann
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = dst_key_generate(name, DNS_KEYALG_DSA,
30f888cbd416f3bcc60b508c3957ef724af592d6Scott Mann 0, 0,
30f888cbd416f3bcc60b508c3957ef724af592d6Scott Mann DNS_KEYTYPE_NOKEY |
30f888cbd416f3bcc60b508c3957ef724af592d6Scott Mann DNS_KEYOWNER_ZONE,
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann DNS_KEYPROTO_DNSSEC,
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann mctx, &dstkey);
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann if (result != ISC_R_SUCCESS)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews fatal("failed to generate null key");
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews isc_buffer_init(&b, keydata, sizeof keydata);
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann result = dst_key_todns(dstkey, &b);
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann dst_key_free(&dstkey);
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann isc_buffer_usedregion(&b, &r);
c7e1812d02d183337db991c19b4214546cf2ebb3Scott Mann dns_rdata_fromregion(&keyrdata,
fbcc480b6c9c2b5b9d40f31ba8238b3f2e7bd29dScott Mann rdataset.rdclass,
c7e1812d02d183337db991c19b4214546cf2ebb3Scott Mann dns_rdatatype_key, &r);
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann ISC_LIST_APPEND(keyrdatalist.rdata, &keyrdata,
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann link);
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann keyrdatalist.rdclass = rdataset.rdclass;
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann keyrdatalist.type = dns_rdatatype_key;
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann keyrdatalist.covers = 0;
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann keyrdatalist.ttl = rdataset.ttl;
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann result = dns_rdatalist_tordataset(&keyrdatalist,
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews &keyset);
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann check_result(result,
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann "dns_rdatalist_tordataset");
30f888cbd416f3bcc60b508c3957ef724af592d6Scott Mann dns_db_addrdataset(db, node, version, 0,
30f888cbd416f3bcc60b508c3957ef724af592d6Scott Mann &keyset, DNS_DBADD_MERGE,
30f888cbd416f3bcc60b508c3957ef724af592d6Scott Mann NULL);
30f888cbd416f3bcc60b508c3957ef724af592d6Scott Mann set_bit(nxt_bits, dns_rdatatype_key, 1);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews signset(db, version, node, name, &keyset);
4fc55db699529ce60f7f1e12aae40e315831c67fScott Mann alreadyhavenullkey:
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann dns_rdataset_disassociate(&keyset);
761fa7d7709bdf2380a02b92f695ecdee929188aScott Mann } else if (isdelegation) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews vbprintf(2, "child key for %s found\n",
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews nametostr(name));
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews }
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews#endif
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews }
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews signset(db, version, node, name, &rdataset);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews skip:
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdataset_disassociate(&rdataset);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = dns_rdatasetiter_next(rdsiter);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews }
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (result != ISC_R_NOMORE)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews fatal("rdataset iteration for name '%s' failed: %s",
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews nametostr(name), isc_result_totext(result));
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdatasetiter_destroy(&rdsiter);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews}
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewsstatic inline isc_boolean_t
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewsactive_node(dns_db_t *db, dns_dbversion_t *version, dns_dbnode_t *node) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdatasetiter_t *rdsiter;
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt isc_boolean_t active = ISC_FALSE;
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt isc_result_t result;
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt dns_rdataset_t rdataset;
3a7b1fb32a27df5326f7fea318f68703c0de7e2eMark Andrews
a20996ab6ff2be473b85470fddd2380a3e180e7bMark Andrews dns_rdataset_init(&rdataset);
a20996ab6ff2be473b85470fddd2380a3e180e7bMark Andrews rdsiter = NULL;
a20996ab6ff2be473b85470fddd2380a3e180e7bMark Andrews result = dns_db_allrdatasets(db, node, version, 0, &rdsiter);
3a7b1fb32a27df5326f7fea318f68703c0de7e2eMark Andrews check_result(result, "dns_db_allrdatasets()");
a20996ab6ff2be473b85470fddd2380a3e180e7bMark Andrews result = dns_rdatasetiter_first(rdsiter);
a20996ab6ff2be473b85470fddd2380a3e180e7bMark Andrews while (result == ISC_R_SUCCESS) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdatasetiter_current(rdsiter, &rdataset);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (rdataset.type != dns_rdatatype_nxt)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews active = ISC_TRUE;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdataset_disassociate(&rdataset);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (!active)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = dns_rdatasetiter_next(rdsiter);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews else
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = ISC_R_NOMORE;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews }
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (result != ISC_R_NOMORE)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews fatal("rdataset iteration failed: %s",
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews isc_result_totext(result));
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdatasetiter_destroy(&rdsiter);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (!active) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews /*
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews * Make sure there is no NXT record for this node.
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews */
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = dns_db_deleterdataset(db, node, version,
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdatatype_nxt, 0);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (result == DNS_R_UNCHANGED)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = ISC_R_SUCCESS;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews check_result(result, "dns_db_deleterdataset");
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews }
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews return (active);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews}
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewsstatic inline isc_result_t
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewsnext_active(dns_db_t *db, dns_dbversion_t *version, dns_dbiterator_t *dbiter,
a7f02c9c6b1df09037baed4e68e4bb31fe4c23e0Mark Andrews dns_name_t *name, dns_dbnode_t **nodep)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews{
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews isc_result_t result;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews isc_boolean_t active;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews do {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews active = ISC_FALSE;
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews result = dns_dbiterator_current(dbiter, nodep, name);
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews if (result == ISC_R_SUCCESS) {
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews active = active_node(db, version, *nodep);
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews if (!active) {
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews dns_db_detachnode(db, nodep);
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews result = dns_dbiterator_next(dbiter);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews }
a7f02c9c6b1df09037baed4e68e4bb31fe4c23e0Mark Andrews }
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews } while (result == ISC_R_SUCCESS && !active);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews return (result);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews}
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewsstatic inline isc_result_t
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewsnext_nonglue(dns_db_t *db, dns_dbversion_t *version, dns_dbiterator_t *dbiter,
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_name_t *name, dns_dbnode_t **nodep, dns_name_t *origin,
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_name_t *lastcut)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews{
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews isc_result_t result, dresult;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews do {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = next_active(db, version, dbiter, name, nodep);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (result == ISC_R_SUCCESS) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (dns_name_issubdomain(name, origin) &&
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews (lastcut == NULL ||
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews !dns_name_issubdomain(name, lastcut)))
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews return (ISC_R_SUCCESS);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dresult = dns_master_dumpnodetostream(mctx, db,
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews version,
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews *nodep, name,
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews masterstyle, fp);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews check_result(dresult, "dns_master_dumpnodetostream");
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_db_detachnode(db, nodep);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = dns_dbiterator_next(dbiter);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews }
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews } while (result == ISC_R_SUCCESS);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews return (result);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews}
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews/*
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews * Extracts the zone minimum TTL from the SOA.
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews */
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewsstatic dns_ttl_t
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewsminimumttl(dns_db_t *db, dns_dbversion_t *version) {
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdataset_t soaset;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_name_t *origin;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_fixedname_t fname;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_name_t *name;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdata_t soarr;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdata_soa_t soa;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews isc_result_t result;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_ttl_t ttl;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews origin = dns_db_origin(db);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_fixedname_init(&fname);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews name = dns_fixedname_name(&fname);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdataset_init(&soaset);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = dns_db_find(db, origin, version, dns_rdatatype_soa,
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews 0, 0, NULL, name, &soaset, NULL);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews if (result != ISC_R_SUCCESS)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews fatal("failed to find '%s SOA' in the zone: %s",
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews nametostr(name), isc_result_totext(result));
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = dns_rdataset_first(&soaset);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews check_result(result, "dns_rdataset_first()");
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews dns_rdataset_current(&soaset, &soarr);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews result = dns_rdata_tostruct(&soarr, &soa, mctx);
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews check_result(result, "dns_rdataset_tostruct()");
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews ttl = soa.minimum;
71bd858d8ed62672e7c23999dc7c02fd16a55089Evan Hunt dns_rdata_freestruct(&soa);
a20996ab6ff2be473b85470fddd2380a3e180e7bMark Andrews dns_rdataset_disassociate(&soaset);
3ec6b563d7b6cb11a047f23faa2a0f206ccd93e7Brian Wellington
3ec6b563d7b6cb11a047f23faa2a0f206ccd93e7Brian Wellington return (ttl);
3ec6b563d7b6cb11a047f23faa2a0f206ccd93e7Brian Wellington}
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrewsstatic void
0e40083fdd5445703bd30e46e5bfe7d047bced12Brian Wellingtoncleannode(dns_db_t *db, dns_dbversion_t *version, dns_dbnode_t *node) {
0e40083fdd5445703bd30e46e5bfe7d047bced12Brian Wellington dns_rdatasetiter_t *rdsiter = NULL;
0e40083fdd5445703bd30e46e5bfe7d047bced12Brian Wellington dns_rdataset_t set;
0e40083fdd5445703bd30e46e5bfe7d047bced12Brian Wellington isc_result_t result, dresult;
0e40083fdd5445703bd30e46e5bfe7d047bced12Brian Wellington
0e40083fdd5445703bd30e46e5bfe7d047bced12Brian Wellington dns_rdataset_init(&set);
3ec6b563d7b6cb11a047f23faa2a0f206ccd93e7Brian Wellington result = dns_db_allrdatasets(db, node, version, 0, &rdsiter);
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington check_result(result, "dns_db_allrdatasets");
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington result = dns_rdatasetiter_first(rdsiter);
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington while (result == ISC_R_SUCCESS) {
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington isc_boolean_t destroy = ISC_FALSE;
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington dns_rdatatype_t covers = 0;
90c1e763d577da656b5eeb02462b5236dca5f266Mark Andrews dns_rdatasetiter_current(rdsiter, &set);
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington if (set.type == dns_rdatatype_sig) {
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington covers = set.covers;
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington destroy = ISC_TRUE;
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington }
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington dns_rdataset_disassociate(&set);
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington result = dns_rdatasetiter_next(rdsiter);
d0fbcfeee1c1dbdb079231545de3a0c58248202fMark Andrews if (destroy) {
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington dresult = dns_db_deleterdataset(db, node, version,
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington dns_rdatatype_sig,
af5ad488cbf17988fbd36a25c908737412ccd382Brian Wellington covers);
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington check_result(dresult, "dns_db_allrdatasets");
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington }
b495fd2992c63472b3ad2d9517ffe9b50118840aAndreas Gustafsson }
af5ad488cbf17988fbd36a25c908737412ccd382Brian Wellington if (result != ISC_R_NOMORE)
f317c00e0d5978f29285ea062b34ec73dc419095Brian Wellington fatal("rdataset iteration failed: %s",
f317c00e0d5978f29285ea062b34ec73dc419095Brian Wellington isc_result_totext(result));
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington dns_rdatasetiter_destroy(&rdsiter);
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington}
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington/*
dee520f1be8c59e10a55b6995844395e811c310fBrian Wellington * Generates NXTs and SIGs for each non-glue name in the zone.
dee520f1be8c59e10a55b6995844395e811c310fBrian Wellington */
dee520f1be8c59e10a55b6995844395e811c310fBrian Wellingtonstatic void
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellingtonsignzone(dns_db_t *db, dns_dbversion_t *version) {
529ff4b4959fb157194f985394951108ff5286e4Brian Wellington isc_result_t result, nxtresult, dresult;
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington dns_dbnode_t *node, *nextnode;
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington dns_fixedname_t fname, fnextname;
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington dns_name_t *name, *nextname, *target, *lastcut;
a14613fce99dee3cad5bf842fd6be78f8e463582Brian Wellington dns_dbiterator_t *dbiter;
5b76a09697bfc76f5acefd65d5b37b1214d271a8Mark Andrews dns_name_t *origin;
5b76a09697bfc76f5acefd65d5b37b1214d271a8Mark Andrews
5b76a09697bfc76f5acefd65d5b37b1214d271a8Mark Andrews zonettl = minimumttl(db, version);
5b76a09697bfc76f5acefd65d5b37b1214d271a8Mark Andrews
5b76a09697bfc76f5acefd65d5b37b1214d271a8Mark Andrews dns_fixedname_init(&fname);
9738408dcbd4c1f7eb2b105c83388608fafd7808Mark Andrews name = dns_fixedname_name(&fname);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson dns_fixedname_init(&fnextname);
489b76292622f5bc18bf1a18845f8166a73bd797Brian Wellington nextname = dns_fixedname_name(&fnextname);
489b76292622f5bc18bf1a18845f8166a73bd797Brian Wellington
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews origin = dns_db_origin(db);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews lastcut = NULL;
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews dbiter = NULL;
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews result = dns_db_createiterator(db, ISC_FALSE, &dbiter);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews check_result(result, "dns_db_createiterator()");
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews result = dns_dbiterator_first(dbiter);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews node = NULL;
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews dns_name_concatenate(origin, NULL, name, NULL);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews result = next_nonglue(db, version, dbiter, name, &node, origin,
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews lastcut);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews while (result == ISC_R_SUCCESS) {
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews nextnode = NULL;
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews if (!dns_name_equal(name, dns_db_origin(db))) {
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews dns_rdatasetiter_t *rdsiter = NULL;
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews dns_rdataset_t set;
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews dns_rdataset_init(&set);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews result = dns_db_allrdatasets(db, node, version,
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews 0, &rdsiter);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews check_result(result, "dns_db_allrdatasets");
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews result = dns_rdatasetiter_first(rdsiter);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews while (result == ISC_R_SUCCESS) {
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews dns_rdatasetiter_current(rdsiter, &set);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews if (set.type == dns_rdatatype_ns) {
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews dns_rdataset_disassociate(&set);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews break;
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews }
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews dns_rdataset_disassociate(&set);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews result = dns_rdatasetiter_next(rdsiter);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews }
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews if (result != ISC_R_SUCCESS && result != ISC_R_NOMORE)
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews fatal("rdataset iteration failed: %s",
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews isc_result_totext(result));
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews if (result == ISC_R_SUCCESS) {
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews if (lastcut != NULL)
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews dns_name_free(lastcut, mctx);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews else {
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews lastcut = isc_mem_get(mctx,
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews sizeof(dns_name_t));
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews if (lastcut == NULL)
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews fatal("out of memory");
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews }
76117ff568dc788ed24937cfea916a18db285960Mark Andrews dns_name_init(lastcut, NULL);
76117ff568dc788ed24937cfea916a18db285960Mark Andrews result = dns_name_dup(name, mctx, lastcut);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews check_result(result, "dns_name_dup()");
2271edc0b4ba96e69a283eced420b94ffb678beeBrian Wellington }
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson dns_rdatasetiter_destroy(&rdsiter);
2271edc0b4ba96e69a283eced420b94ffb678beeBrian Wellington }
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews result = dns_dbiterator_next(dbiter);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews if (result == ISC_R_SUCCESS)
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews result = next_nonglue(db, version, dbiter, nextname,
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews &nextnode, origin, lastcut);
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews if (result == ISC_R_SUCCESS)
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews target = nextname;
be515937febf025ec2a4c381bee58131ab0f32f4Mark Andrews else if (result == ISC_R_NOMORE)
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews target = origin;
7005cfed8cd3296d356883dcb414979f22e06b13Brian Wellington else {
489b76292622f5bc18bf1a18845f8166a73bd797Brian Wellington target = NULL; /* Make compiler happy. */
489b76292622f5bc18bf1a18845f8166a73bd797Brian Wellington fatal("iterating through the database failed: %s",
489b76292622f5bc18bf1a18845f8166a73bd797Brian Wellington isc_result_totext(result));
3184ff5e45c8f821e5165ea60d674bfb87faf5b8Mark Andrews }
3184ff5e45c8f821e5165ea60d674bfb87faf5b8Mark Andrews nxtresult = dns_buildnxt(db, version, node, target, zonettl);
3184ff5e45c8f821e5165ea60d674bfb87faf5b8Mark Andrews check_result(nxtresult, "dns_buildnxt()");
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson signname(db, version, node, name);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson dresult = dns_master_dumpnodetostream(mctx, db, version,
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson node, name,
9ceaa92a8ca8a0270ba296d44599e94d95033759Andreas Gustafsson masterstyle, fp);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson check_result(dresult, "dns_master_dumpnodetostream");
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson cleannode(db, version, node);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson dns_db_detachnode(db, &node);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson node = nextnode;
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson dns_name_concatenate(nextname, NULL, name, NULL);
70e854766f5304f43e94212dc38ebaefe214148cMark Andrews }
16ee4fe11bad616a76c79e9f626a7e04a88ef4abMark Andrews if (result != ISC_R_NOMORE)
16ee4fe11bad616a76c79e9f626a7e04a88ef4abMark Andrews fatal("iterating through the database failed: %s",
16ee4fe11bad616a76c79e9f626a7e04a88ef4abMark Andrews isc_result_totext(result));
16ee4fe11bad616a76c79e9f626a7e04a88ef4abMark Andrews if (lastcut != NULL) {
16ee4fe11bad616a76c79e9f626a7e04a88ef4abMark Andrews dns_name_free(lastcut, mctx);
70e854766f5304f43e94212dc38ebaefe214148cMark Andrews isc_mem_put(mctx, lastcut, sizeof(dns_name_t));
70e854766f5304f43e94212dc38ebaefe214148cMark Andrews }
70e854766f5304f43e94212dc38ebaefe214148cMark Andrews dns_dbiterator_destroy(&dbiter);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson}
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson
fa280ff02ad0c29616a0c3a22ef02cbb3f6db7efDavid Lawrence/*
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson * Load the zone file from disk
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson */
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafssonstatic void
fa280ff02ad0c29616a0c3a22ef02cbb3f6db7efDavid Lawrenceloadzone(char *file, char *origin, dns_db_t **db) {
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson isc_buffer_t b, b2;
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson unsigned char namedata[1024];
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson int len;
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson dns_name_t name;
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson isc_result_t result;
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson len = strlen(origin);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson isc_buffer_init(&b, origin, len);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson isc_buffer_add(&b, len);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson isc_buffer_init(&b2, namedata, sizeof(namedata));
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson dns_name_init(&name, NULL);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson result = dns_name_fromtext(&name, &b, dns_rootname, ISC_FALSE, &b2);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson if (result != ISC_R_SUCCESS)
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson fatal("failed converting name '%s' to dns format: %s",
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson origin, isc_result_totext(result));
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson result = dns_db_create(mctx, "rbt", &name, dns_dbtype_zone,
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson dns_rdataclass_in, 0, NULL, db);
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson check_result(result, "dns_db_create()");
3fafd7c0c42134ff2964b74a31500465a96dee90Andreas Gustafsson
aa30ee42c4b6da9bab4fb84d6cbbda6036a4d426Mark Andrews result = dns_db_load(*db, file);
aa30ee42c4b6da9bab4fb84d6cbbda6036a4d426Mark Andrews if (result != ISC_R_SUCCESS)
9ceaa92a8ca8a0270ba296d44599e94d95033759Andreas Gustafsson fatal("failed loading zone from '%s': %s",
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson file, isc_result_totext(result));
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson}
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson/*
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson * Finds all public zone keys in the zone, and attempts to load the
a1884b96ef53efc8b4e14be173aaee552ca0213aAndreas Gustafsson * private keys from disk.
fafb62400d2f1b1da4f3908447e1f3935fc5155bBrian Wellington */
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrencestatic void
fafb62400d2f1b1da4f3908447e1f3935fc5155bBrian Wellingtonloadzonekeys(dns_db_t *db) {
76117ff568dc788ed24937cfea916a18db285960Mark Andrews dns_name_t *origin;
76117ff568dc788ed24937cfea916a18db285960Mark Andrews dns_dbnode_t *node;
620de5a4b1f23dc9b4ec30d30c0607ff389be0daBob Halley dns_dbversion_t *currentversion;
9ceaa92a8ca8a0270ba296d44599e94d95033759Andreas Gustafsson isc_result_t result;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence dst_key_t *keys[20];
620de5a4b1f23dc9b4ec30d30c0607ff389be0daBob Halley unsigned int nkeys, i;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
76117ff568dc788ed24937cfea916a18db285960Mark Andrews origin = dns_db_origin(db);
76117ff568dc788ed24937cfea916a18db285960Mark Andrews currentversion = NULL;
fafb62400d2f1b1da4f3908447e1f3935fc5155bBrian Wellington dns_db_currentversion(db, &currentversion);
fafb62400d2f1b1da4f3908447e1f3935fc5155bBrian Wellington
fafb62400d2f1b1da4f3908447e1f3935fc5155bBrian Wellington node = NULL;
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews result = dns_db_findnode(db, origin, ISC_FALSE, &node);
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews if (result != ISC_R_SUCCESS)
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews fatal("failed to find the zone's origin: %s",
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews isc_result_totext(result));
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews
90c1e763d577da656b5eeb02462b5236dca5f266Mark Andrews result = dns_dnssec_findzonekeys(db, currentversion, node, origin, mctx,
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews 20, keys, &nkeys);
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews if (result == ISC_R_NOTFOUND)
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews result = ISC_R_SUCCESS;
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews if (result != ISC_R_SUCCESS)
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews fatal("failed to find the zone keys: %s",
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews isc_result_totext(result));
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews
b7945d73bc42499d50d5c4af6a525fe56e4dfacaMark Andrews for (i = 0; i < nkeys; i++) {
a2fa49cebc52195c17ba9ccc28857b0933934291Francis Dupont signer_key_t *key;
b7945d73bc42499d50d5c4af6a525fe56e4dfacaMark Andrews
b7945d73bc42499d50d5c4af6a525fe56e4dfacaMark Andrews key = isc_mem_get(mctx, sizeof(signer_key_t));
b7945d73bc42499d50d5c4af6a525fe56e4dfacaMark Andrews if (key == NULL)
b7945d73bc42499d50d5c4af6a525fe56e4dfacaMark Andrews fatal("out of memory");
b7945d73bc42499d50d5c4af6a525fe56e4dfacaMark Andrews key->key = keys[i];
b7945d73bc42499d50d5c4af6a525fe56e4dfacaMark Andrews key->isdefault = ISC_FALSE;
b7945d73bc42499d50d5c4af6a525fe56e4dfacaMark Andrews
b7945d73bc42499d50d5c4af6a525fe56e4dfacaMark Andrews ISC_LIST_APPEND(keylist, key, link);
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews }
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews dns_db_detachnode(db, &node);
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews dns_db_closeversion(db, &currentversion, ISC_FALSE);
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews}
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrewsstatic isc_stdtime_t
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrewsstrtotime(char *str, isc_int64_t now, isc_int64_t base) {
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews isc_int64_t val, offset;
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews isc_result_t result;
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews char *endp;
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews if (str[0] == '+') {
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews offset = strtol(str + 1, &endp, 0);
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews if (*endp != '\0')
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews fatal("time value %s is invalid", str);
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews val = base + offset;
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews } else if (strncmp(str, "now+", 4) == 0) {
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews offset = strtol(str + 4, &endp, 0);
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews if (*endp != '\0')
23ac30603a7639bea1d331537634b079b046b122Mark Andrews fatal("time value %s is invalid", str);
23ac30603a7639bea1d331537634b079b046b122Mark Andrews val = now + offset;
23ac30603a7639bea1d331537634b079b046b122Mark Andrews } else {
23ac30603a7639bea1d331537634b079b046b122Mark Andrews result = dns_time64_fromtext(str, &val);
23ac30603a7639bea1d331537634b079b046b122Mark Andrews if (result != ISC_R_SUCCESS)
3f123dcc2fe5d2cd08ca91b732741d86a4036906Brian Wellington fatal("time %s must be numeric", str);
3f123dcc2fe5d2cd08ca91b732741d86a4036906Brian Wellington }
64b92523f9333ba053f4b2860335583be455b0b3Brian Wellington
64b92523f9333ba053f4b2860335583be455b0b3Brian Wellington return ((isc_stdtime_t) val);
3f123dcc2fe5d2cd08ca91b732741d86a4036906Brian Wellington}
3f123dcc2fe5d2cd08ca91b732741d86a4036906Brian Wellington
64b92523f9333ba053f4b2860335583be455b0b3Brian Wellingtonstatic void
3f123dcc2fe5d2cd08ca91b732741d86a4036906Brian Wellingtonusage(void) {
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "Usage:\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "\t%s [options] zonefile [keys]\n", program);
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "Options: (default value in parenthesis) \n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "\t-s YYYYMMDDHHMMSS|+offset:\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "\t\tSIG start time - absolute|offset (now)\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "\t-e YYYYMMDDHHMMSS|+offset|\"now\"+offset]:\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "\t\tSIG end time - absolute|from start|from now "
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence "(now + 30 days)\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "\t-c ttl:\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "\t\tcycle period - regenerate "
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence "if < cycle from end ( (end-start)/4 )\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t-v level:\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t\tverbose level (0)\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t-o origin:\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t\tzone origin (name of zonefile)\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t-f outfile:\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t\tfile the signed zone is written in "
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley "(zonefile + .signed)\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t-a\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t\tverify generated signatures\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t-p\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t\tuse pseudorandom data (faster but less secure)\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t-r randomdev:\n");
03f4c76f95f75e2b0d1206e784e35bed6041305cBob Halley fprintf(stderr, "\t\ta file containing random data\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "Signing Keys: ");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "(default: all zone keys that have private keys)\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fprintf(stderr, "\tkeyfile (Kname+alg+tag)\n");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence exit(0);
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence}
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrewsint
8b7d3aeda264513ca83961fb752703cc3c85451dMark Andrewsmain(int argc, char *argv[]) {
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews int i, ch;
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews char *startstr = NULL, *endstr = NULL;
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews char *origin = NULL, *file = NULL, *output = NULL;
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews char *randomfile = NULL;
15bda409010cbf2d3e43baf10f28bae5f7b1abefMark Andrews char *endp;
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews dns_db_t *db;
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews dns_dbversion_t *version;
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews signer_key_t *key;
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews isc_result_t result;
3ea6d4dc33482a752553c59ed94bcecd23d254b0Mark Andrews isc_log_t *log = NULL;
3ea6d4dc33482a752553c59ed94bcecd23d254b0Mark Andrews isc_boolean_t pseudorandom = ISC_FALSE;
8af4e7aa4e2a6fe84bf4ebe09ca1d4ef1d8ab593Mark Andrews unsigned int eflags;
3ea6d4dc33482a752553c59ed94bcecd23d254b0Mark Andrews isc_boolean_t free_output = ISC_FALSE;
3ea6d4dc33482a752553c59ed94bcecd23d254b0Mark Andrews
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence result = isc_mem_create(0, 0, &mctx);
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence if (result != ISC_R_SUCCESS)
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fatal("out of memory");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence dns_result_register();
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence while ((ch = isc_commandline_parse(argc, argv, "s:e:c:v:o:f:ahpr:"))
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence != -1) {
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence switch (ch) {
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence case 's':
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews startstr = isc_commandline_argument;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews break;
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence case 'e':
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence endstr = isc_commandline_argument;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence break;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence case 'c':
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence endp = NULL;
16ee4fe11bad616a76c79e9f626a7e04a88ef4abMark Andrews cycle = strtol(isc_commandline_argument, &endp, 0);
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence if (*endp != '\0' || cycle < 0)
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fatal("cycle period must be numeric and "
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence "positive");
8af4e7aa4e2a6fe84bf4ebe09ca1d4ef1d8ab593Mark Andrews break;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence case 'p':
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence pseudorandom = ISC_TRUE;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence break;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence case 'r':
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence randomfile = isc_commandline_argument;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence break;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence case 'v':
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence endp = NULL;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence verbose = strtol(isc_commandline_argument, &endp, 0);
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence if (*endp != '\0')
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence fatal("verbose level must be numeric");
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence break;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
3fafd7c0c42134ff2964b74a31500465a96dee90Andreas Gustafsson case 'o':
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews origin = isc_commandline_argument;
aa30ee42c4b6da9bab4fb84d6cbbda6036a4d426Mark Andrews break;
aa30ee42c4b6da9bab4fb84d6cbbda6036a4d426Mark Andrews
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence case 'f':
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence output = isc_commandline_argument;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence break;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence case 'a':
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence tryverify = ISC_TRUE;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence break;
9a2574531e3d2ced31072200b416467fdee0c29cDavid Lawrence
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence case 'h':
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence default:
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence usage();
d8dcd6ad4617cc8d7df979bd62101fa9c4bac1bcBob Halley
d8dcd6ad4617cc8d7df979bd62101fa9c4bac1bcBob Halley }
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence }
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence setup_entropy(mctx, randomfile, &ectx);
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence eflags = ISC_ENTROPY_BLOCKING;
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence if (!pseudorandom)
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence eflags |= ISC_ENTROPY_GOODONLY;
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence result = dst_lib_init(mctx, ectx, eflags);
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence if (result != ISC_R_SUCCESS)
df3c4c7988b9bae7d121a8ac9ed17a23366a948dDavid Lawrence fatal("could not initialize dst");
882350d11c90de9de6fc1cead25690c8114b0b95Michael Graff
882350d11c90de9de6fc1cead25690c8114b0b95Michael Graff isc_stdtime_get(&now);
882350d11c90de9de6fc1cead25690c8114b0b95Michael Graff
d5518bf5bc1830f89f411288f39c5c9e6eb7511cMark Andrews if (startstr != NULL)
d5518bf5bc1830f89f411288f39c5c9e6eb7511cMark Andrews starttime = strtotime(startstr, now, now);
882350d11c90de9de6fc1cead25690c8114b0b95Michael Graff else
882350d11c90de9de6fc1cead25690c8114b0b95Michael Graff starttime = now;
d5518bf5bc1830f89f411288f39c5c9e6eb7511cMark Andrews
882350d11c90de9de6fc1cead25690c8114b0b95Michael Graff if (endstr != NULL)
882350d11c90de9de6fc1cead25690c8114b0b95Michael Graff endtime = strtotime(endstr, now, starttime);
64ba6e4cc3a0ccf8c8c6349fa75b937ca9bad9a6Michael Graff else
4e9775118dbf128dd296f01638733ba221f76c34Mark Andrews endtime = starttime + (30 * 24 * 60 * 60);
4e9775118dbf128dd296f01638733ba221f76c34Mark Andrews
4e9775118dbf128dd296f01638733ba221f76c34Mark Andrews if (cycle == -1)
4e9775118dbf128dd296f01638733ba221f76c34Mark Andrews cycle = (endtime - starttime) / 4;
4e9775118dbf128dd296f01638733ba221f76c34Mark Andrews
4e9775118dbf128dd296f01638733ba221f76c34Mark Andrews setup_logging(verbose, mctx, &log);
4e9775118dbf128dd296f01638733ba221f76c34Mark Andrews
4e9775118dbf128dd296f01638733ba221f76c34Mark Andrews argc -= isc_commandline_index;
4e9775118dbf128dd296f01638733ba221f76c34Mark Andrews argv += isc_commandline_index;
4e9775118dbf128dd296f01638733ba221f76c34Mark Andrews
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob if (argc < 1)
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob usage();
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob file = argv[0];
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob
90c1e763d577da656b5eeb02462b5236dca5f266Mark Andrews argc -= 1;
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob argv += 1;
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob if (output == NULL) {
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob free_output = ISC_TRUE;
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob output = isc_mem_allocate(mctx,
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob strlen(file) + strlen(".signed") + 1);
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob if (output == NULL)
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob fatal("out of memory");
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob sprintf(output, "%s.signed", file);
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob }
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob if (origin == NULL)
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob origin = file;
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob db = NULL;
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob loadzone(file, origin, &db);
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob ISC_LIST_INIT(keylist);
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob loadzonekeys(db);
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob if (argc == 0) {
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob signer_key_t *key;
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob key = ISC_LIST_HEAD(keylist);
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob while (key != NULL) {
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob key->isdefault = ISC_TRUE;
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob key = ISC_LIST_NEXT(key, link);
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob }
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob }
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob else {
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob for (i = 0; i < argc; i++) {
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob dst_key_t *newkey = NULL;
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob result = dst_key_fromnamedfile(argv[i],
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob DST_TYPE_PRIVATE,
d901b2252d664a5b96bae117416f8ee822dc6691Stephen Jacob mctx, &newkey);
8b56b8956fc1e6c70efacb4f71db28d0d1f0c577Mark Andrews if (result != ISC_R_SUCCESS)
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley usage();
90c1e763d577da656b5eeb02462b5236dca5f266Mark Andrews
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley key = ISC_LIST_HEAD(keylist);
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley while (key != NULL) {
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley dst_key_t *dkey = key->key;
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley if (dst_key_id(dkey) == dst_key_id(newkey) &&
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley dst_key_alg(dkey) == dst_key_alg(newkey) &&
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley dns_name_equal(dst_key_name(dkey),
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley dst_key_name(newkey)))
c64aeaf419a7ef156b4aabfa2a913831e773157eBob Halley {
74cb99072c4b0ebd2ccafcfa284288fa760f7a1aMark Andrews key->isdefault = ISC_TRUE;
74cb99072c4b0ebd2ccafcfa284288fa760f7a1aMark Andrews if (!dst_key_isprivate(dkey))
74cb99072c4b0ebd2ccafcfa284288fa760f7a1aMark Andrews fatal("cannot sign zone with "
aceae69c7f3e76e8842de178851928619c65b61cMark Andrews "non-private key %s",
aceae69c7f3e76e8842de178851928619c65b61cMark Andrews argv[i]);
aceae69c7f3e76e8842de178851928619c65b61cMark Andrews break;
6e1141e6e83b3907b8b187d97932f30fa82470efMark Andrews }
6e1141e6e83b3907b8b187d97932f30fa82470efMark Andrews key = ISC_LIST_NEXT(key, link);
6e1141e6e83b3907b8b187d97932f30fa82470efMark Andrews }
6e1141e6e83b3907b8b187d97932f30fa82470efMark Andrews if (key == NULL) {
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley key = isc_mem_get(mctx, sizeof(signer_key_t));
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley if (key == NULL)
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley fatal("out of memory");
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley key->key = newkey;
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley key->isdefault = ISC_TRUE;
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley ISC_LIST_APPEND(keylist, key, link);
c64aeaf419a7ef156b4aabfa2a913831e773157eBob Halley }
74cb99072c4b0ebd2ccafcfa284288fa760f7a1aMark Andrews else
74cb99072c4b0ebd2ccafcfa284288fa760f7a1aMark Andrews dst_key_free(&newkey);
74cb99072c4b0ebd2ccafcfa284288fa760f7a1aMark Andrews }
aceae69c7f3e76e8842de178851928619c65b61cMark Andrews }
6e1141e6e83b3907b8b187d97932f30fa82470efMark Andrews
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley version = NULL;
64e41159a919b0711321fe688ca5da4f4d1b7d80Bob Halley result = dns_db_newversion(db, &version);
193738b819e3c699f9edd18864a6810fcfcec855Andreas Gustafsson check_result(result, "dns_db_newversion()");
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 fp = NULL;
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 result = isc_stdio_open(output, "w", &fp);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 if (result != ISC_R_SUCCESS)
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 fatal("failed to open output file %s: %s", output,
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 isc_result_totext(result));
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 signzone(db, version);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 result = isc_stdio_close(fp);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 check_result(result, "isc_stdio_close");
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 dns_db_closeversion(db, &version, ISC_FALSE);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 dns_db_detach(&db);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 while (!ISC_LIST_EMPTY(keylist)) {
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 key = ISC_LIST_HEAD(keylist);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 ISC_LIST_UNLINK(keylist, key, link);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 dst_key_free(&key->key);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 isc_mem_put(mctx, key, sizeof(signer_key_t));
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 }
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 if (free_output)
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 isc_mem_free(mctx, output);
2c016c64f533171e1342c1914754b017026c8ad5Tatuya JINMEI 神明達哉
730e25bf1121ada7e5ee3f33812dc25faa182294Mark Andrews if (log != NULL)
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 isc_log_destroy(&log);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 dst_lib_destroy();
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 cleanup_entropy(&ectx);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 if (verbose > 10)
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉 isc_mem_stats(mctx, stdout);
866a531c59f4005b6857b633a0db6ef00e7741efTatuya JINMEI 神明達哉 isc_mem_destroy(&mctx);
a27fe4c990f96bd792f2a07ca4d38c78d5b9df2cTatuya JINMEI 神明達哉
2c016c64f533171e1342c1914754b017026c8ad5Tatuya JINMEI 神明達哉 return (0);
2c016c64f533171e1342c1914754b017026c8ad5Tatuya JINMEI 神明達哉}
2c016c64f533171e1342c1914754b017026c8ad5Tatuya JINMEI 神明達哉