37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews#!/bin/sh -e
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews#
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews# Copyright (C) 2010, 2012, 2014, 2016 Internet Systems Consortium, Inc. ("ISC")
bf8267aa453e5d2a735ed732a043b77a0b355b20Mark Andrews#
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews# This Source Code Form is subject to the terms of the Mozilla Public
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews# License, v. 2.0. If a copy of the MPL was not distributed with this
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews# file, You can obtain one at http://mozilla.org/MPL/2.0/.
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews
37dee1ff94960a61243f611c0f87f8c316815c53Mark AndrewsSYSTEMTESTTOP=../..
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews. $SYSTEMTESTTOP/conf.sh
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewszone=.
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewsinfile=root.db.in
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewszonefile=root.db
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewskey1=`$KEYGEN -q -r $RANDFILE -a ECCGOST -n zone $zone`
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewskey2=`$KEYGEN -q -r $RANDFILE -a ECCGOST -n zone -f KSK $zone`
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews$DSFROMKEY -a gost $key2.key > dsset-gost
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewscat $infile $key1.key $key2.key > $zonefile
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews
aaaf8d4f4873d21e55c3ffb4f656203d08339865Mark Andrews$SIGNER -P -g -r $RANDFILE -o $zone $zonefile > /dev/null 2> signer.err || cat signer.err
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews# Configure the resolving server with a trusted key.
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewscat $key1.key | grep -v '^; ' | $PERL -n -e '
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewslocal ($dn, $class, $type, $flags, $proto, $alg, @rest) = split;
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewslocal $key = join("", @rest);
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewsprint <<EOF
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewstrusted-keys {
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews "$dn" $flags $proto $alg "$key";
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews};
37dee1ff94960a61243f611c0f87f8c316815c53Mark AndrewsEOF
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrews' > trusted.conf
37dee1ff94960a61243f611c0f87f8c316815c53Mark Andrewscp trusted.conf ../ns2/trusted.conf