Import NetBSD named(8)
Also known as ISC bind. This import adds utilities such as host(1), dig(1), and nslookup(1), as well as many other tools and libraries. Change-Id: I035ca46e64f1965d57019e773f4ff0ef035e4aa3
This commit is contained in:
61
external/bsd/bind/dist/bin/python/Makefile.in
vendored
Normal file
61
external/bsd/bind/dist/bin/python/Makefile.in
vendored
Normal file
@@ -0,0 +1,61 @@
|
||||
# Copyright (C) 2012-2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
|
||||
# Id
|
||||
|
||||
srcdir = @srcdir@
|
||||
VPATH = @srcdir@
|
||||
top_srcdir = @top_srcdir@
|
||||
|
||||
@BIND9_MAKE_INCLUDES@
|
||||
|
||||
PYTHON = @PYTHON@
|
||||
|
||||
TARGETS = dnssec-checkds dnssec-coverage
|
||||
PYSRCS = dnssec-checkds.py dnssec-coverage.py
|
||||
|
||||
MANPAGES = dnssec-checkds.8 dnssec-coverage.8
|
||||
HTMLPAGES = dnssec-checkds.html dnssec-coverage.html
|
||||
MANOBJS = ${MANPAGES} ${HTMLPAGES}
|
||||
|
||||
@BIND9_MAKE_RULES@
|
||||
|
||||
dnssec-checkds: dnssec-checkds.py
|
||||
cp -f dnssec-checkds.py dnssec-checkds
|
||||
chmod +x dnssec-checkds
|
||||
|
||||
dnssec-coverage: dnssec-coverage.py
|
||||
cp -f dnssec-coverage.py dnssec-coverage
|
||||
chmod +x dnssec-coverage
|
||||
|
||||
doc man:: ${MANOBJS}
|
||||
|
||||
docclean manclean maintainer-clean::
|
||||
rm -f ${MANOBJS}
|
||||
|
||||
installdirs:
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${sbindir}
|
||||
$(SHELL) ${top_srcdir}/mkinstalldirs ${DESTDIR}${mandir}/man8
|
||||
|
||||
install:: ${TARGETS} installdirs
|
||||
${INSTALL_SCRIPT} dnssec-checkds@EXEEXT@ ${DESTDIR}${sbindir}
|
||||
${INSTALL_SCRIPT} dnssec-coverage@EXEEXT@ ${DESTDIR}${sbindir}
|
||||
${INSTALL_DATA} ${srcdir}/dnssec-checkds.8 ${DESTDIR}${mandir}/man8
|
||||
${INSTALL_DATA} ${srcdir}/dnssec-coverage.8 ${DESTDIR}${mandir}/man8
|
||||
|
||||
clean distclean::
|
||||
rm -f ${TARGETS}
|
||||
|
||||
distclean::
|
||||
rm -f dnssec-checkds.py dnssec-coverage.py
|
||||
82
external/bsd/bind/dist/bin/python/dnssec-checkds.8
vendored
Normal file
82
external/bsd/bind/dist/bin/python/dnssec-checkds.8
vendored
Normal file
@@ -0,0 +1,82 @@
|
||||
.\" $NetBSD: dnssec-checkds.8,v 1.5 2014/12/10 04:37:52 christos Exp $
|
||||
.\"
|
||||
.\" Copyright (C) 2012-2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
.\" purpose with or without fee is hereby granted, provided that the above
|
||||
.\" copyright notice and this permission notice appear in all copies.
|
||||
.\"
|
||||
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" Id
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
.\" Title: dnssec\-checkds
|
||||
.\" Author:
|
||||
.\" Generator: DocBook XSL Stylesheets v1.71.1 <http://docbook.sf.net/>
|
||||
.\" Date: January 01, 2013
|
||||
.\" Manual: BIND9
|
||||
.\" Source: BIND9
|
||||
.\"
|
||||
.TH "DNSSEC\-CHECKDS" "8" "January 01, 2013" "BIND9" "BIND9"
|
||||
.\" disable hyphenation
|
||||
.nh
|
||||
.\" disable justification (adjust text to left margin only)
|
||||
.ad l
|
||||
.SH "NAME"
|
||||
dnssec\-checkds \- A DNSSEC delegation consistency checking tool.
|
||||
.SH "SYNOPSIS"
|
||||
.HP 15
|
||||
\fBdnssec\-checkds\fR [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] {zone}
|
||||
.HP 17
|
||||
\fBdnssec\-dsfromkey\fR [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-d\ \fR\fB\fIdig\ path\fR\fR] [\fB\-D\ \fR\fB\fIdsfromkey\ path\fR\fR] {zone}
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBdnssec\-checkds\fR
|
||||
verifies the correctness of Delegation Signer (DS) or DNSSEC Lookaside Validation (DLV) resource records for keys in a specified zone.
|
||||
.SH "OPTIONS"
|
||||
.PP
|
||||
\-f \fIfile\fR
|
||||
.RS 4
|
||||
If a
|
||||
\fBfile\fR
|
||||
is specified, then the zone is read from that file to find the DNSKEY records. If not, then the DNSKEY records for the zone are looked up in the DNS.
|
||||
.RE
|
||||
.PP
|
||||
\-l \fIdomain\fR
|
||||
.RS 4
|
||||
Check for a DLV record in the specified lookaside domain, instead of checking for a DS record in the zone's parent. For example, to check for DLV records for "example.com" in ISC's DLV zone, use:
|
||||
\fBdnssec\-checkds \-l dlv.isc.org example.com\fR
|
||||
.RE
|
||||
.PP
|
||||
\-d \fIdig path\fR
|
||||
.RS 4
|
||||
Specifies a path to a
|
||||
\fBdig\fR
|
||||
binary. Used for testing.
|
||||
.RE
|
||||
.PP
|
||||
\-D \fIdsfromkey path\fR
|
||||
.RS 4
|
||||
Specifies a path to a
|
||||
\fBdnssec\-dsfromkey\fR
|
||||
binary. Used for testing.
|
||||
.RE
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fBdnssec\-dsfromkey\fR(8),
|
||||
\fBdnssec\-keygen\fR(8),
|
||||
\fBdnssec\-signzone\fR(8),
|
||||
.SH "AUTHOR"
|
||||
.PP
|
||||
Internet Systems Consortium
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2012\-2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
147
external/bsd/bind/dist/bin/python/dnssec-checkds.docbook
vendored
Normal file
147
external/bsd/bind/dist/bin/python/dnssec-checkds.docbook
vendored
Normal file
@@ -0,0 +1,147 @@
|
||||
<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2012-2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<refentry id="man.dnssec-checkds">
|
||||
<refentryinfo>
|
||||
<date>January 01, 2013</date>
|
||||
</refentryinfo>
|
||||
|
||||
<refmeta>
|
||||
<refentrytitle><application>dnssec-checkds</application></refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
<refmiscinfo>BIND9</refmiscinfo>
|
||||
</refmeta>
|
||||
|
||||
<refnamediv>
|
||||
<refname><application>dnssec-checkds</application></refname>
|
||||
<refpurpose>A DNSSEC delegation consistency checking tool.</refpurpose>
|
||||
</refnamediv>
|
||||
|
||||
<docinfo>
|
||||
<copyright>
|
||||
<year>2012</year>
|
||||
<year>2013</year>
|
||||
<year>2014</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
|
||||
<refsynopsisdiv>
|
||||
<cmdsynopsis>
|
||||
<command>dnssec-checkds</command>
|
||||
<arg><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
||||
<arg><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
|
||||
<arg><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
|
||||
<arg choice="req">zone</arg>
|
||||
</cmdsynopsis>
|
||||
<cmdsynopsis>
|
||||
<command>dnssec-dsfromkey</command>
|
||||
<arg><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
|
||||
<arg><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
|
||||
<arg><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
|
||||
<arg choice="req">zone</arg>
|
||||
</cmdsynopsis>
|
||||
</refsynopsisdiv>
|
||||
|
||||
<refsect1>
|
||||
<title>DESCRIPTION</title>
|
||||
<para><command>dnssec-checkds</command>
|
||||
verifies the correctness of Delegation Signer (DS) or DNSSEC
|
||||
Lookaside Validation (DLV) resource records for keys in a specified
|
||||
zone.
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>OPTIONS</title>
|
||||
|
||||
<variablelist>
|
||||
<varlistentry>
|
||||
<term>-f <replaceable class="parameter">file</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
If a <option>file</option> is specified, then the zone is
|
||||
read from that file to find the DNSKEY records. If not,
|
||||
then the DNSKEY records for the zone are looked up in the DNS.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-l <replaceable class="parameter">domain</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Check for a DLV record in the specified lookaside domain,
|
||||
instead of checking for a DS record in the zone's parent.
|
||||
For example, to check for DLV records for "example.com"
|
||||
in ISC's DLV zone, use:
|
||||
<command>dnssec-checkds -l dlv.isc.org example.com</command>
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-d <replaceable class="parameter">dig path</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies a path to a <command>dig</command> binary. Used
|
||||
for testing.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-D <replaceable class="parameter">dsfromkey path</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies a path to a <command>dnssec-dsfromkey</command> binary.
|
||||
Used for testing.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
</variablelist>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>SEE ALSO</title>
|
||||
<para><citerefentry>
|
||||
<refentrytitle>dnssec-dsfromkey</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>dnssec-signzone</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>AUTHOR</title>
|
||||
<para><corpauthor>Internet Systems Consortium</corpauthor>
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
</refentry><!--
|
||||
- Local variables:
|
||||
- mode: sgml
|
||||
- End:
|
||||
-->
|
||||
84
external/bsd/bind/dist/bin/python/dnssec-checkds.html
vendored
Normal file
84
external/bsd/bind/dist/bin/python/dnssec-checkds.html
vendored
Normal file
@@ -0,0 +1,84 @@
|
||||
<!--
|
||||
- Copyright (C) 2012-2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
<!-- Id -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
<title>dnssec-checkds</title>
|
||||
<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
|
||||
</head>
|
||||
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
|
||||
<a name="man.dnssec-checkds"></a><div class="titlepage"></div>
|
||||
<div class="refnamediv">
|
||||
<h2>Name</h2>
|
||||
<p><span class="application">dnssec-checkds</span> — A DNSSEC delegation consistency checking tool.</p>
|
||||
</div>
|
||||
<div class="refsynopsisdiv">
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p><code class="command">dnssec-checkds</code> [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>] [<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>] {zone}</p></div>
|
||||
<div class="cmdsynopsis"><p><code class="command">dnssec-dsfromkey</code> [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>] [<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>] {zone}</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543434"></a><h2>DESCRIPTION</h2>
|
||||
<p><span><strong class="command">dnssec-checkds</strong></span>
|
||||
verifies the correctness of Delegation Signer (DS) or DNSSEC
|
||||
Lookaside Validation (DLV) resource records for keys in a specified
|
||||
zone.
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543446"></a><h2>OPTIONS</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term">-f <em class="replaceable"><code>file</code></em></span></dt>
|
||||
<dd><p>
|
||||
If a <code class="option">file</code> is specified, then the zone is
|
||||
read from that file to find the DNSKEY records. If not,
|
||||
then the DNSKEY records for the zone are looked up in the DNS.
|
||||
</p></dd>
|
||||
<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
|
||||
<dd><p>
|
||||
Check for a DLV record in the specified lookaside domain,
|
||||
instead of checking for a DS record in the zone's parent.
|
||||
For example, to check for DLV records for "example.com"
|
||||
in ISC's DLV zone, use:
|
||||
<span><strong class="command">dnssec-checkds -l dlv.isc.org example.com</strong></span>
|
||||
</p></dd>
|
||||
<dt><span class="term">-d <em class="replaceable"><code>dig path</code></em></span></dt>
|
||||
<dd><p>
|
||||
Specifies a path to a <span><strong class="command">dig</strong></span> binary. Used
|
||||
for testing.
|
||||
</p></dd>
|
||||
<dt><span class="term">-D <em class="replaceable"><code>dsfromkey path</code></em></span></dt>
|
||||
<dd><p>
|
||||
Specifies a path to a <span><strong class="command">dnssec-dsfromkey</strong></span> binary.
|
||||
Used for testing.
|
||||
</p></dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543542"></a><h2>SEE ALSO</h2>
|
||||
<p><span class="citerefentry"><span class="refentrytitle">dnssec-dsfromkey</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543576"></a><h2>AUTHOR</h2>
|
||||
<p><span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
</div>
|
||||
</div></body>
|
||||
</html>
|
||||
327
external/bsd/bind/dist/bin/python/dnssec-checkds.py.in
vendored
Normal file
327
external/bsd/bind/dist/bin/python/dnssec-checkds.py.in
vendored
Normal file
@@ -0,0 +1,327 @@
|
||||
#!@PYTHON@
|
||||
############################################################################
|
||||
# Copyright (C) 2012-2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
############################################################################
|
||||
|
||||
import argparse
|
||||
import pprint
|
||||
import os
|
||||
|
||||
prog='dnssec-checkds'
|
||||
|
||||
# These routines permit platform-independent location of BIND 9 tools
|
||||
if os.name == 'nt':
|
||||
import win32con
|
||||
import win32api
|
||||
|
||||
def prefix(bindir = ''):
|
||||
if os.name != 'nt':
|
||||
return os.path.join('@prefix@', bindir)
|
||||
|
||||
bind_subkey = "Software\\ISC\\BIND"
|
||||
hKey = None
|
||||
keyFound = True
|
||||
try:
|
||||
hKey = win32api.RegOpenKeyEx(win32con.HKEY_LOCAL_MACHINE, bind_subkey)
|
||||
except:
|
||||
keyFound = False
|
||||
if keyFound:
|
||||
try:
|
||||
(namedBase, _) = win32api.RegQueryValueEx(hKey, "InstallDir")
|
||||
except:
|
||||
keyFound = False
|
||||
win32api.RegCloseKey(hKey)
|
||||
if keyFound:
|
||||
return os.path.join(namedBase, bindir)
|
||||
return os.path.join(win32api.GetSystemDirectory(), bindir)
|
||||
|
||||
def shellquote(s):
|
||||
if os.name == 'nt':
|
||||
return '"' + s.replace('"', '"\\"') + '"'
|
||||
return "'" + s.replace("'", "'\\''") + "'"
|
||||
|
||||
############################################################################
|
||||
# DSRR class:
|
||||
# Delegation Signer (DS) resource record
|
||||
############################################################################
|
||||
class DSRR:
|
||||
hashalgs = {1: 'SHA-1', 2: 'SHA-256', 3: 'GOST', 4: 'SHA-384' }
|
||||
rrname=''
|
||||
rrclass='IN'
|
||||
rrtype='DS'
|
||||
keyid=None
|
||||
keyalg=None
|
||||
hashalg=None
|
||||
digest=''
|
||||
ttl=0
|
||||
|
||||
def __init__(self, rrtext):
|
||||
if not rrtext:
|
||||
return
|
||||
|
||||
fields = rrtext.split()
|
||||
if len(fields) < 7:
|
||||
return
|
||||
|
||||
self.rrname = fields[0].lower()
|
||||
fields = fields[1:]
|
||||
if fields[0].upper() in ['IN','CH','HS']:
|
||||
self.rrclass = fields[0].upper()
|
||||
fields = fields[1:]
|
||||
else:
|
||||
self.ttl = int(fields[0])
|
||||
self.rrclass = fields[1].upper()
|
||||
fields = fields[2:]
|
||||
|
||||
if fields[0].upper() != 'DS':
|
||||
raise Exception
|
||||
|
||||
self.rrtype = 'DS'
|
||||
self.keyid = int(fields[1])
|
||||
self.keyalg = int(fields[2])
|
||||
self.hashalg = int(fields[3])
|
||||
self.digest = ''.join(fields[4:]).upper()
|
||||
|
||||
def __repr__(self):
|
||||
return('%s %s %s %d %d %d %s' %
|
||||
(self.rrname, self.rrclass, self.rrtype, self.keyid,
|
||||
self.keyalg, self.hashalg, self.digest))
|
||||
|
||||
def __eq__(self, other):
|
||||
return self.__repr__() == other.__repr__()
|
||||
|
||||
############################################################################
|
||||
# DLVRR class:
|
||||
# DNSSEC Lookaside Validation (DLV) resource record
|
||||
############################################################################
|
||||
class DLVRR:
|
||||
hashalgs = {1: 'SHA-1', 2: 'SHA-256', 3: 'GOST', 4: 'SHA-384' }
|
||||
parent=''
|
||||
dlvname=''
|
||||
rrname='IN'
|
||||
rrclass='IN'
|
||||
rrtype='DLV'
|
||||
keyid=None
|
||||
keyalg=None
|
||||
hashalg=None
|
||||
digest=''
|
||||
ttl=0
|
||||
|
||||
def __init__(self, rrtext, dlvname):
|
||||
if not rrtext:
|
||||
return
|
||||
|
||||
fields = rrtext.split()
|
||||
if len(fields) < 7:
|
||||
return
|
||||
|
||||
self.dlvname = dlvname.lower()
|
||||
parent = fields[0].lower().strip('.').split('.')
|
||||
parent.reverse()
|
||||
dlv = dlvname.split('.')
|
||||
dlv.reverse()
|
||||
while len(dlv) != 0 and len(parent) != 0 and parent[0] == dlv[0]:
|
||||
parent = parent[1:]
|
||||
dlv = dlv[1:]
|
||||
if len(dlv) != 0:
|
||||
raise Exception
|
||||
parent.reverse()
|
||||
self.parent = '.'.join(parent)
|
||||
self.rrname = self.parent + '.' + self.dlvname + '.'
|
||||
|
||||
fields = fields[1:]
|
||||
if fields[0].upper() in ['IN','CH','HS']:
|
||||
self.rrclass = fields[0].upper()
|
||||
fields = fields[1:]
|
||||
else:
|
||||
self.ttl = int(fields[0])
|
||||
self.rrclass = fields[1].upper()
|
||||
fields = fields[2:]
|
||||
|
||||
if fields[0].upper() != 'DLV':
|
||||
raise Exception
|
||||
|
||||
self.rrtype = 'DLV'
|
||||
self.keyid = int(fields[1])
|
||||
self.keyalg = int(fields[2])
|
||||
self.hashalg = int(fields[3])
|
||||
self.digest = ''.join(fields[4:]).upper()
|
||||
|
||||
def __repr__(self):
|
||||
return('%s %s %s %d %d %d %s' %
|
||||
(self.rrname, self.rrclass, self.rrtype,
|
||||
self.keyid, self.keyalg, self.hashalg, self.digest))
|
||||
|
||||
def __eq__(self, other):
|
||||
return self.__repr__() == other.__repr__()
|
||||
|
||||
############################################################################
|
||||
# checkds:
|
||||
# Fetch DS RRset for the given zone from the DNS; fetch DNSKEY
|
||||
# RRset from the masterfile if specified, or from DNS if not.
|
||||
# Generate a set of expected DS records from the DNSKEY RRset,
|
||||
# and report on congruency.
|
||||
############################################################################
|
||||
def checkds(zone, masterfile = None):
|
||||
dslist=[]
|
||||
fp=os.popen("%s +noall +answer -t ds -q %s" %
|
||||
(shellquote(args.dig), shellquote(zone)))
|
||||
for line in fp:
|
||||
dslist.append(DSRR(line))
|
||||
dslist = sorted(dslist, key=lambda ds: (ds.keyid, ds.keyalg, ds.hashalg))
|
||||
fp.close()
|
||||
|
||||
dsklist=[]
|
||||
|
||||
if masterfile:
|
||||
fp = os.popen("%s -f %s %s " %
|
||||
(shellquote(args.dsfromkey), shellquote(masterfile),
|
||||
shellquote(zone)))
|
||||
else:
|
||||
fp = os.popen("%s +noall +answer -t dnskey -q %s | %s -f - %s" %
|
||||
(shellquote(args.dig), shellquote(zone),
|
||||
shellquote(args.dsfromkey), shellquote(zone)))
|
||||
|
||||
for line in fp:
|
||||
dsklist.append(DSRR(line))
|
||||
|
||||
fp.close()
|
||||
|
||||
if (len(dsklist) < 1):
|
||||
print ("No DNSKEY records found in zone apex")
|
||||
return False
|
||||
|
||||
found = False
|
||||
for ds in dsklist:
|
||||
if ds in dslist:
|
||||
print ("DS for KSK %s/%03d/%05d (%s) found in parent" %
|
||||
(ds.rrname.strip('.'), ds.keyalg,
|
||||
ds.keyid, DSRR.hashalgs[ds.hashalg]))
|
||||
found = True
|
||||
else:
|
||||
print ("DS for KSK %s/%03d/%05d (%s) missing from parent" %
|
||||
(ds.rrname.strip('.'), ds.keyalg,
|
||||
ds.keyid, DSRR.hashalgs[ds.hashalg]))
|
||||
|
||||
if not found:
|
||||
print ("No DS records were found for any DNSKEY")
|
||||
|
||||
return found
|
||||
|
||||
############################################################################
|
||||
# checkdlv:
|
||||
# Fetch DLV RRset for the given zone from the DNS; fetch DNSKEY
|
||||
# RRset from the masterfile if specified, or from DNS if not.
|
||||
# Generate a set of expected DLV records from the DNSKEY RRset,
|
||||
# and report on congruency.
|
||||
############################################################################
|
||||
def checkdlv(zone, lookaside, masterfile = None):
|
||||
dlvlist=[]
|
||||
fp=os.popen("%s +noall +answer -t dlv -q %s" %
|
||||
(shellquote(args.dig), shellquote(zone + '.' + lookaside)))
|
||||
for line in fp:
|
||||
dlvlist.append(DLVRR(line, lookaside))
|
||||
dlvlist = sorted(dlvlist,
|
||||
key=lambda dlv: (dlv.keyid, dlv.keyalg, dlv.hashalg))
|
||||
fp.close()
|
||||
|
||||
#
|
||||
# Fetch DNSKEY records from DNS and generate DLV records from them
|
||||
#
|
||||
dlvklist=[]
|
||||
if masterfile:
|
||||
fp = os.popen("%s -f %s -l %s %s " %
|
||||
(args.dsfromkey, masterfile, lookaside, zone))
|
||||
else:
|
||||
fp = os.popen("%s +noall +answer -t dnskey %s | %s -f - -l %s %s"
|
||||
% (shellquote(args.dig), shellquote(zone),
|
||||
shellquote(args.dsfromkey), shellquote(lookaside),
|
||||
shellquote(zone)))
|
||||
|
||||
for line in fp:
|
||||
dlvklist.append(DLVRR(line, lookaside))
|
||||
|
||||
fp.close()
|
||||
|
||||
if (len(dlvklist) < 1):
|
||||
print ("No DNSKEY records found in zone apex")
|
||||
return False
|
||||
|
||||
found = False
|
||||
for dlv in dlvklist:
|
||||
if dlv in dlvlist:
|
||||
print ("DLV for KSK %s/%03d/%05d (%s) found in %s" %
|
||||
(dlv.parent, dlv.keyalg, dlv.keyid,
|
||||
DLVRR.hashalgs[dlv.hashalg], dlv.dlvname))
|
||||
found = True
|
||||
else:
|
||||
print ("DLV for KSK %s/%03d/%05d (%s) missing from %s" %
|
||||
(dlv.parent, dlv.keyalg, dlv.keyid,
|
||||
DLVRR.hashalgs[dlv.hashalg], dlv.dlvname))
|
||||
|
||||
if not found:
|
||||
print ("No DLV records were found for any DNSKEY")
|
||||
|
||||
return found
|
||||
|
||||
|
||||
############################################################################
|
||||
# parse_args:
|
||||
# Read command line arguments, set global 'args' structure
|
||||
############################################################################
|
||||
def parse_args():
|
||||
global args
|
||||
parser = argparse.ArgumentParser(description=prog + ': checks DS coverage')
|
||||
|
||||
bindir = 'bin'
|
||||
if os.name == 'nt':
|
||||
sbindir = 'bin'
|
||||
else:
|
||||
sbindir = 'sbin'
|
||||
|
||||
parser.add_argument('zone', type=str, help='zone to check')
|
||||
parser.add_argument('-f', '--file', dest='masterfile', type=str,
|
||||
help='zone master file')
|
||||
parser.add_argument('-l', '--lookaside', dest='lookaside', type=str,
|
||||
help='DLV lookaside zone')
|
||||
parser.add_argument('-d', '--dig', dest='dig',
|
||||
default=os.path.join(prefix(bindir), 'dig'),
|
||||
type=str, help='path to \'dig\'')
|
||||
parser.add_argument('-D', '--dsfromkey', dest='dsfromkey',
|
||||
default=os.path.join(prefix(sbindir),
|
||||
'dnssec-dsfromkey'),
|
||||
type=str, help='path to \'dig\'')
|
||||
parser.add_argument('-v', '--version', action='version', version='9.9.1')
|
||||
args = parser.parse_args()
|
||||
|
||||
args.zone = args.zone.strip('.')
|
||||
if args.lookaside:
|
||||
lookaside = args.lookaside.strip('.')
|
||||
|
||||
############################################################################
|
||||
# Main
|
||||
############################################################################
|
||||
def main():
|
||||
parse_args()
|
||||
|
||||
if args.lookaside:
|
||||
found = checkdlv(args.zone, args.lookaside, args.masterfile)
|
||||
else:
|
||||
found = checkds(args.zone, args.masterfile)
|
||||
|
||||
exit(0 if found else 1)
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
146
external/bsd/bind/dist/bin/python/dnssec-coverage.8
vendored
Normal file
146
external/bsd/bind/dist/bin/python/dnssec-coverage.8
vendored
Normal file
@@ -0,0 +1,146 @@
|
||||
.\" $NetBSD: dnssec-coverage.8,v 1.1.1.6 2014/12/10 03:34:27 christos Exp $
|
||||
.\"
|
||||
.\" Copyright (C) 2013, 2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
.\"
|
||||
.\" Permission to use, copy, modify, and/or distribute this software for any
|
||||
.\" purpose with or without fee is hereby granted, provided that the above
|
||||
.\" copyright notice and this permission notice appear in all copies.
|
||||
.\"
|
||||
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
.\" PERFORMANCE OF THIS SOFTWARE.
|
||||
.\"
|
||||
.\" Id
|
||||
.\"
|
||||
.hy 0
|
||||
.ad l
|
||||
.\" Title: dnssec\-coverage
|
||||
.\" Author:
|
||||
.\" Generator: DocBook XSL Stylesheets v1.71.1 <http://docbook.sf.net/>
|
||||
.\" Date: January 11, 2014
|
||||
.\" Manual: BIND9
|
||||
.\" Source: BIND9
|
||||
.\"
|
||||
.TH "DNSSEC\-COVERAGE" "8" "January 11, 2014" "BIND9" "BIND9"
|
||||
.\" disable hyphenation
|
||||
.nh
|
||||
.\" disable justification (adjust text to left margin only)
|
||||
.ad l
|
||||
.SH "NAME"
|
||||
dnssec\-coverage \- checks future DNSKEY coverage for a zone
|
||||
.SH "SYNOPSIS"
|
||||
.HP 16
|
||||
\fBdnssec\-coverage\fR [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-l\ \fR\fB\fIlength\fR\fR] [\fB\-f\ \fR\fB\fIfile\fR\fR] [\fB\-d\ \fR\fB\fIDNSKEY\ TTL\fR\fR] [\fB\-m\ \fR\fB\fImax\ TTL\fR\fR] [\fB\-r\ \fR\fB\fIinterval\fR\fR] [\fB\-c\ \fR\fB\fIcompilezone\ path\fR\fR] [\fB\-k\fR] [\fB\-z\fR] [zone]
|
||||
.SH "DESCRIPTION"
|
||||
.PP
|
||||
\fBdnssec\-coverage\fR
|
||||
verifies that the DNSSEC keys for a given zone or a set of zones have timing metadata set properly to ensure no future lapses in DNSSEC coverage.
|
||||
.PP
|
||||
If
|
||||
\fBzone\fR
|
||||
is specified, then keys found in the key repository matching that zone are scanned, and an ordered list is generated of the events scheduled for that key (i.e., publication, activation, inactivation, deletion). The list of events is walked in order of occurrence. Warnings are generated if any event is scheduled which could cause the zone to enter a state in which validation failures might occur: for example, if the number of published or active keys for a given algorithm drops to zero, or if a key is deleted from the zone too soon after a new key is rolled, and cached data signed by the prior key has not had time to expire from resolver caches.
|
||||
.PP
|
||||
If
|
||||
\fBzone\fR
|
||||
is not specified, then all keys in the key repository will be scanned, and all zones for which there are keys will be analyzed. (Note: This method of reporting is only accurate if all the zones that have keys in a given repository share the same TTL parameters.)
|
||||
.SH "OPTIONS"
|
||||
.PP
|
||||
\-K \fIdirectory\fR
|
||||
.RS 4
|
||||
Sets the directory in which keys can be found. Defaults to the current working directory.
|
||||
.RE
|
||||
.PP
|
||||
\-f \fIfile\fR
|
||||
.RS 4
|
||||
If a
|
||||
\fBfile\fR
|
||||
is specified, then the zone is read from that file; the largest TTL and the DNSKEY TTL are determined directly from the zone data, and the
|
||||
\fB\-m\fR
|
||||
and
|
||||
\fB\-d\fR
|
||||
options do not need to be specified on the command line.
|
||||
.RE
|
||||
.PP
|
||||
\-l \fIduration\fR
|
||||
.RS 4
|
||||
The length of time to check for DNSSEC coverage. Key events scheduled further into the future than
|
||||
\fBduration\fR
|
||||
will be ignored, and assumed to be correct.
|
||||
.sp
|
||||
The value of
|
||||
\fBduration\fR
|
||||
can be set in seconds, or in larger units of time by adding a suffix: 'mi' for minutes, 'h' for hours, 'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
|
||||
.RE
|
||||
.PP
|
||||
\-m \fImaximum TTL\fR
|
||||
.RS 4
|
||||
Sets the value to be used as the maximum TTL for the zone or zones being analyzed when determining whether there is a possibility of validation failure. When a zone\-signing key is deactivated, there must be enough time for the record in the zone with the longest TTL to have expired from resolver caches before that key can be purged from the DNSKEY RRset. If that condition does not apply, a warning will be generated.
|
||||
.sp
|
||||
The length of the TTL can be set in seconds, or in larger units of time by adding a suffix: 'mi' for minutes, 'h' for hours, 'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
|
||||
.sp
|
||||
This option is mandatory unless the
|
||||
\fB\-f\fR
|
||||
has been used to specify a zone file. (If
|
||||
\fB\-f\fR
|
||||
has been specified, this option may still be used; it will override the value found in the file.)
|
||||
.RE
|
||||
.PP
|
||||
\-d \fIDNSKEY TTL\fR
|
||||
.RS 4
|
||||
Sets the value to be used as the DNSKEY TTL for the zone or zones being analyzed when determining whether there is a possibility of validation failure. When a key is rolled (that is, replaced with a new key), there must be enough time for the old DNSKEY RRset to have expired from resolver caches before the new key is activated and begins generating signatures. If that condition does not apply, a warning will be generated.
|
||||
.sp
|
||||
The length of the TTL can be set in seconds, or in larger units of time by adding a suffix: 'mi' for minutes, 'h' for hours, 'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
|
||||
.sp
|
||||
This option is mandatory unless the
|
||||
\fB\-f\fR
|
||||
has been used to specify a zone file, or a default key TTL was set with the
|
||||
\fB\-L\fR
|
||||
to
|
||||
\fBdnssec\-keygen\fR. (If either of those is true, this option may still be used; it will override the value found in the zone or key file.)
|
||||
.RE
|
||||
.PP
|
||||
\-r \fIresign interval\fR
|
||||
.RS 4
|
||||
Sets the value to be used as the resign interval for the zone or zones being analyzed when determining whether there is a possibility of validation failure. This value defaults to 22.5 days, which is also the default in
|
||||
\fBnamed\fR. However, if it has been changed by the
|
||||
\fBsig\-validity\-interval\fR
|
||||
option in
|
||||
\fInamed.conf\fR, then it should also be changed here.
|
||||
.sp
|
||||
The length of the interval can be set in seconds, or in larger units of time by adding a suffix: 'mi' for minutes, 'h' for hours, 'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
|
||||
.RE
|
||||
.PP
|
||||
\-k
|
||||
.RS 4
|
||||
Only check KSK coverage; ignore ZSK events. Cannot be used with
|
||||
\fB\-z\fR.
|
||||
.RE
|
||||
.PP
|
||||
\-z
|
||||
.RS 4
|
||||
Only check ZSK coverage; ignore KSK events. Cannot be used with
|
||||
\fB\-k\fR.
|
||||
.RE
|
||||
.PP
|
||||
\-c \fIcompilezone path\fR
|
||||
.RS 4
|
||||
Specifies a path to a
|
||||
\fBnamed\-compilezone\fR
|
||||
binary. Used for testing.
|
||||
.RE
|
||||
.SH "SEE ALSO"
|
||||
.PP
|
||||
\fBdnssec\-checkds\fR(8),
|
||||
\fBdnssec\-dsfromkey\fR(8),
|
||||
\fBdnssec\-keygen\fR(8),
|
||||
\fBdnssec\-signzone\fR(8)
|
||||
.SH "AUTHOR"
|
||||
.PP
|
||||
Internet Systems Consortium
|
||||
.SH "COPYRIGHT"
|
||||
Copyright \(co 2013, 2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
.br
|
||||
270
external/bsd/bind/dist/bin/python/dnssec-coverage.docbook
vendored
Normal file
270
external/bsd/bind/dist/bin/python/dnssec-coverage.docbook
vendored
Normal file
@@ -0,0 +1,270 @@
|
||||
<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
|
||||
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
|
||||
[<!ENTITY mdash "—">]>
|
||||
<!--
|
||||
- Copyright (C) 2013, 2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<refentry id="man.dnssec-coverage">
|
||||
<refentryinfo>
|
||||
<date>January 11, 2014</date>
|
||||
</refentryinfo>
|
||||
|
||||
<refmeta>
|
||||
<refentrytitle><application>dnssec-coverage</application></refentrytitle>
|
||||
<manvolnum>8</manvolnum>
|
||||
<refmiscinfo>BIND9</refmiscinfo>
|
||||
</refmeta>
|
||||
|
||||
<refnamediv>
|
||||
<refname><application>dnssec-coverage</application></refname>
|
||||
<refpurpose>checks future DNSKEY coverage for a zone</refpurpose>
|
||||
</refnamediv>
|
||||
|
||||
<docinfo>
|
||||
<copyright>
|
||||
<year>2013</year>
|
||||
<year>2014</year>
|
||||
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
|
||||
</copyright>
|
||||
</docinfo>
|
||||
|
||||
<refsynopsisdiv>
|
||||
<cmdsynopsis>
|
||||
<command>dnssec-coverage</command>
|
||||
<arg><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
|
||||
<arg><option>-l <replaceable class="parameter">length</replaceable></option></arg>
|
||||
<arg><option>-f <replaceable class="parameter">file</replaceable></option></arg>
|
||||
<arg><option>-d <replaceable class="parameter">DNSKEY TTL</replaceable></option></arg>
|
||||
<arg><option>-m <replaceable class="parameter">max TTL</replaceable></option></arg>
|
||||
<arg><option>-r <replaceable class="parameter">interval</replaceable></option></arg>
|
||||
<arg><option>-c <replaceable class="parameter">compilezone path</replaceable></option></arg>
|
||||
<arg><option>-k</option></arg>
|
||||
<arg><option>-z</option></arg>
|
||||
<arg choice="opt">zone</arg>
|
||||
</cmdsynopsis>
|
||||
</refsynopsisdiv>
|
||||
|
||||
<refsect1>
|
||||
<title>DESCRIPTION</title>
|
||||
<para><command>dnssec-coverage</command>
|
||||
verifies that the DNSSEC keys for a given zone or a set of zones
|
||||
have timing metadata set properly to ensure no future lapses in DNSSEC
|
||||
coverage.
|
||||
</para>
|
||||
<para>
|
||||
If <option>zone</option> is specified, then keys found in
|
||||
the key repository matching that zone are scanned, and an ordered
|
||||
list is generated of the events scheduled for that key (i.e.,
|
||||
publication, activation, inactivation, deletion). The list of
|
||||
events is walked in order of occurrence. Warnings are generated
|
||||
if any event is scheduled which could cause the zone to enter a
|
||||
state in which validation failures might occur: for example, if
|
||||
the number of published or active keys for a given algorithm drops
|
||||
to zero, or if a key is deleted from the zone too soon after a new
|
||||
key is rolled, and cached data signed by the prior key has not had
|
||||
time to expire from resolver caches.
|
||||
</para>
|
||||
<para>
|
||||
If <option>zone</option> is not specified, then all keys in the
|
||||
key repository will be scanned, and all zones for which there are
|
||||
keys will be analyzed. (Note: This method of reporting is only
|
||||
accurate if all the zones that have keys in a given repository
|
||||
share the same TTL parameters.)
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>OPTIONS</title>
|
||||
|
||||
<variablelist>
|
||||
<varlistentry>
|
||||
<term>-K <replaceable class="parameter">directory</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the directory in which keys can be found. Defaults to the
|
||||
current working directory.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-f <replaceable class="parameter">file</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
If a <option>file</option> is specified, then the zone is
|
||||
read from that file; the largest TTL and the DNSKEY TTL are
|
||||
determined directly from the zone data, and the
|
||||
<option>-m</option> and <option>-d</option> options do
|
||||
not need to be specified on the command line.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-l <replaceable class="parameter">duration</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
The length of time to check for DNSSEC coverage. Key events
|
||||
scheduled further into the future than <option>duration</option>
|
||||
will be ignored, and assumed to be correct.
|
||||
</para>
|
||||
<para>
|
||||
The value of <option>duration</option> can be set in seconds,
|
||||
or in larger units of time by adding a suffix: 'mi' for minutes,
|
||||
'h' for hours, 'd' for days, 'w' for weeks, 'mo' for months,
|
||||
'y' for years.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-m <replaceable class="parameter">maximum TTL</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the value to be used as the maximum TTL for the zone or
|
||||
zones being analyzed when determining whether there is a
|
||||
possibility of validation failure. When a zone-signing key is
|
||||
deactivated, there must be enough time for the record in the
|
||||
zone with the longest TTL to have expired from resolver caches
|
||||
before that key can be purged from the DNSKEY RRset. If that
|
||||
condition does not apply, a warning will be generated.
|
||||
</para>
|
||||
<para>
|
||||
The length of the TTL can be set in seconds, or in larger units
|
||||
of time by adding a suffix: 'mi' for minutes, 'h' for hours,
|
||||
'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
|
||||
</para>
|
||||
<para>
|
||||
This option is mandatory unless the <option>-f</option> has
|
||||
been used to specify a zone file. (If <option>-f</option> has
|
||||
been specified, this option may still be used; it will override
|
||||
the value found in the file.)
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-d <replaceable class="parameter">DNSKEY TTL</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the value to be used as the DNSKEY TTL for the zone or
|
||||
zones being analyzed when determining whether there is a
|
||||
possibility of validation failure. When a key is rolled (that
|
||||
is, replaced with a new key), there must be enough time
|
||||
for the old DNSKEY RRset to have expired from resolver caches
|
||||
before the new key is activated and begins generating
|
||||
signatures. If that condition does not apply, a warning
|
||||
will be generated.
|
||||
</para>
|
||||
<para>
|
||||
The length of the TTL can be set in seconds, or in larger units
|
||||
of time by adding a suffix: 'mi' for minutes, 'h' for hours,
|
||||
'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
|
||||
</para>
|
||||
<para>
|
||||
This option is mandatory unless the <option>-f</option> has
|
||||
been used to specify a zone file, or a default key TTL was
|
||||
set with the <option>-L</option> to
|
||||
<command>dnssec-keygen</command>. (If either of those is true,
|
||||
this option may still be used; it will override the value found
|
||||
in the zone or key file.)
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-r <replaceable class="parameter">resign interval</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Sets the value to be used as the resign interval for the zone
|
||||
or zones being analyzed when determining whether there is a
|
||||
possibility of validation failure. This value defaults to
|
||||
22.5 days, which is also the default in
|
||||
<command>named</command>. However, if it has been changed
|
||||
by the <option>sig-validity-interval</option> option in
|
||||
<filename>named.conf</filename>, then it should also be
|
||||
changed here.
|
||||
</para>
|
||||
<para>
|
||||
The length of the interval can be set in seconds, or in larger
|
||||
units of time by adding a suffix: 'mi' for minutes, 'h' for hours,
|
||||
'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-k</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Only check KSK coverage; ignore ZSK events. Cannot be
|
||||
used with <option>-z</option>.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
<varlistentry>
|
||||
<term>-z</term>
|
||||
<listitem>
|
||||
<para>
|
||||
Only check ZSK coverage; ignore KSK events. Cannot be
|
||||
used with <option>-k</option>.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
|
||||
|
||||
<varlistentry>
|
||||
<term>-c <replaceable class="parameter">compilezone path</replaceable></term>
|
||||
<listitem>
|
||||
<para>
|
||||
Specifies a path to a <command>named-compilezone</command> binary.
|
||||
Used for testing.
|
||||
</para>
|
||||
</listitem>
|
||||
</varlistentry>
|
||||
</variablelist>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>SEE ALSO</title>
|
||||
<para>
|
||||
<citerefentry>
|
||||
<refentrytitle>dnssec-checkds</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>dnssec-dsfromkey</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>,
|
||||
<citerefentry>
|
||||
<refentrytitle>dnssec-signzone</refentrytitle><manvolnum>8</manvolnum>
|
||||
</citerefentry>
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
<refsect1>
|
||||
<title>AUTHOR</title>
|
||||
<para><corpauthor>Internet Systems Consortium</corpauthor>
|
||||
</para>
|
||||
</refsect1>
|
||||
|
||||
</refentry><!--
|
||||
- Local variables:
|
||||
- mode: sgml
|
||||
- End:
|
||||
-->
|
||||
191
external/bsd/bind/dist/bin/python/dnssec-coverage.html
vendored
Normal file
191
external/bsd/bind/dist/bin/python/dnssec-coverage.html
vendored
Normal file
@@ -0,0 +1,191 @@
|
||||
<!--
|
||||
- Copyright (C) 2013, 2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
-
|
||||
- Permission to use, copy, modify, and/or distribute this software for any
|
||||
- purpose with or without fee is hereby granted, provided that the above
|
||||
- copyright notice and this permission notice appear in all copies.
|
||||
-
|
||||
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
- PERFORMANCE OF THIS SOFTWARE.
|
||||
-->
|
||||
|
||||
<!-- Id -->
|
||||
<html>
|
||||
<head>
|
||||
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
|
||||
<title>dnssec-coverage</title>
|
||||
<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
|
||||
</head>
|
||||
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
|
||||
<a name="man.dnssec-coverage"></a><div class="titlepage"></div>
|
||||
<div class="refnamediv">
|
||||
<h2>Name</h2>
|
||||
<p><span class="application">dnssec-coverage</span> — checks future DNSKEY coverage for a zone</p>
|
||||
</div>
|
||||
<div class="refsynopsisdiv">
|
||||
<h2>Synopsis</h2>
|
||||
<div class="cmdsynopsis"><p><code class="command">dnssec-coverage</code> [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-l <em class="replaceable"><code>length</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>DNSKEY TTL</code></em></code>] [<code class="option">-m <em class="replaceable"><code>max TTL</code></em></code>] [<code class="option">-r <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-c <em class="replaceable"><code>compilezone path</code></em></code>] [<code class="option">-k</code>] [<code class="option">-z</code>] [zone]</p></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543419"></a><h2>DESCRIPTION</h2>
|
||||
<p><span><strong class="command">dnssec-coverage</strong></span>
|
||||
verifies that the DNSSEC keys for a given zone or a set of zones
|
||||
have timing metadata set properly to ensure no future lapses in DNSSEC
|
||||
coverage.
|
||||
</p>
|
||||
<p>
|
||||
If <code class="option">zone</code> is specified, then keys found in
|
||||
the key repository matching that zone are scanned, and an ordered
|
||||
list is generated of the events scheduled for that key (i.e.,
|
||||
publication, activation, inactivation, deletion). The list of
|
||||
events is walked in order of occurrence. Warnings are generated
|
||||
if any event is scheduled which could cause the zone to enter a
|
||||
state in which validation failures might occur: for example, if
|
||||
the number of published or active keys for a given algorithm drops
|
||||
to zero, or if a key is deleted from the zone too soon after a new
|
||||
key is rolled, and cached data signed by the prior key has not had
|
||||
time to expire from resolver caches.
|
||||
</p>
|
||||
<p>
|
||||
If <code class="option">zone</code> is not specified, then all keys in the
|
||||
key repository will be scanned, and all zones for which there are
|
||||
keys will be analyzed. (Note: This method of reporting is only
|
||||
accurate if all the zones that have keys in a given repository
|
||||
share the same TTL parameters.)
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543444"></a><h2>OPTIONS</h2>
|
||||
<div class="variablelist"><dl>
|
||||
<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
|
||||
<dd><p>
|
||||
Sets the directory in which keys can be found. Defaults to the
|
||||
current working directory.
|
||||
</p></dd>
|
||||
<dt><span class="term">-f <em class="replaceable"><code>file</code></em></span></dt>
|
||||
<dd><p>
|
||||
If a <code class="option">file</code> is specified, then the zone is
|
||||
read from that file; the largest TTL and the DNSKEY TTL are
|
||||
determined directly from the zone data, and the
|
||||
<code class="option">-m</code> and <code class="option">-d</code> options do
|
||||
not need to be specified on the command line.
|
||||
</p></dd>
|
||||
<dt><span class="term">-l <em class="replaceable"><code>duration</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
The length of time to check for DNSSEC coverage. Key events
|
||||
scheduled further into the future than <code class="option">duration</code>
|
||||
will be ignored, and assumed to be correct.
|
||||
</p>
|
||||
<p>
|
||||
The value of <code class="option">duration</code> can be set in seconds,
|
||||
or in larger units of time by adding a suffix: 'mi' for minutes,
|
||||
'h' for hours, 'd' for days, 'w' for weeks, 'mo' for months,
|
||||
'y' for years.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-m <em class="replaceable"><code>maximum TTL</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Sets the value to be used as the maximum TTL for the zone or
|
||||
zones being analyzed when determining whether there is a
|
||||
possibility of validation failure. When a zone-signing key is
|
||||
deactivated, there must be enough time for the record in the
|
||||
zone with the longest TTL to have expired from resolver caches
|
||||
before that key can be purged from the DNSKEY RRset. If that
|
||||
condition does not apply, a warning will be generated.
|
||||
</p>
|
||||
<p>
|
||||
The length of the TTL can be set in seconds, or in larger units
|
||||
of time by adding a suffix: 'mi' for minutes, 'h' for hours,
|
||||
'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
|
||||
</p>
|
||||
<p>
|
||||
This option is mandatory unless the <code class="option">-f</code> has
|
||||
been used to specify a zone file. (If <code class="option">-f</code> has
|
||||
been specified, this option may still be used; it will override
|
||||
the value found in the file.)
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-d <em class="replaceable"><code>DNSKEY TTL</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Sets the value to be used as the DNSKEY TTL for the zone or
|
||||
zones being analyzed when determining whether there is a
|
||||
possibility of validation failure. When a key is rolled (that
|
||||
is, replaced with a new key), there must be enough time
|
||||
for the old DNSKEY RRset to have expired from resolver caches
|
||||
before the new key is activated and begins generating
|
||||
signatures. If that condition does not apply, a warning
|
||||
will be generated.
|
||||
</p>
|
||||
<p>
|
||||
The length of the TTL can be set in seconds, or in larger units
|
||||
of time by adding a suffix: 'mi' for minutes, 'h' for hours,
|
||||
'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
|
||||
</p>
|
||||
<p>
|
||||
This option is mandatory unless the <code class="option">-f</code> has
|
||||
been used to specify a zone file, or a default key TTL was
|
||||
set with the <code class="option">-L</code> to
|
||||
<span><strong class="command">dnssec-keygen</strong></span>. (If either of those is true,
|
||||
this option may still be used; it will override the value found
|
||||
in the zone or key file.)
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-r <em class="replaceable"><code>resign interval</code></em></span></dt>
|
||||
<dd>
|
||||
<p>
|
||||
Sets the value to be used as the resign interval for the zone
|
||||
or zones being analyzed when determining whether there is a
|
||||
possibility of validation failure. This value defaults to
|
||||
22.5 days, which is also the default in
|
||||
<span><strong class="command">named</strong></span>. However, if it has been changed
|
||||
by the <code class="option">sig-validity-interval</code> option in
|
||||
<code class="filename">named.conf</code>, then it should also be
|
||||
changed here.
|
||||
</p>
|
||||
<p>
|
||||
The length of the interval can be set in seconds, or in larger
|
||||
units of time by adding a suffix: 'mi' for minutes, 'h' for hours,
|
||||
'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
|
||||
</p>
|
||||
</dd>
|
||||
<dt><span class="term">-k</span></dt>
|
||||
<dd><p>
|
||||
Only check KSK coverage; ignore ZSK events. Cannot be
|
||||
used with <code class="option">-z</code>.
|
||||
</p></dd>
|
||||
<dt><span class="term">-z</span></dt>
|
||||
<dd><p>
|
||||
Only check ZSK coverage; ignore KSK events. Cannot be
|
||||
used with <code class="option">-k</code>.
|
||||
</p></dd>
|
||||
<dt><span class="term">-c <em class="replaceable"><code>compilezone path</code></em></span></dt>
|
||||
<dd><p>
|
||||
Specifies a path to a <span><strong class="command">named-compilezone</strong></span> binary.
|
||||
Used for testing.
|
||||
</p></dd>
|
||||
</dl></div>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543745"></a><h2>SEE ALSO</h2>
|
||||
<p>
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-checkds</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-dsfromkey</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
|
||||
<span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>
|
||||
</p>
|
||||
</div>
|
||||
<div class="refsect1" lang="en">
|
||||
<a name="id2543788"></a><h2>AUTHOR</h2>
|
||||
<p><span class="corpauthor">Internet Systems Consortium</span>
|
||||
</p>
|
||||
</div>
|
||||
</div></body>
|
||||
</html>
|
||||
798
external/bsd/bind/dist/bin/python/dnssec-coverage.py.in
vendored
Executable file
798
external/bsd/bind/dist/bin/python/dnssec-coverage.py.in
vendored
Executable file
@@ -0,0 +1,798 @@
|
||||
#!@PYTHON@
|
||||
############################################################################
|
||||
# Copyright (C) 2013, 2014 Internet Systems Consortium, Inc. ("ISC")
|
||||
#
|
||||
# Permission to use, copy, modify, and/or distribute this software for any
|
||||
# purpose with or without fee is hereby granted, provided that the above
|
||||
# copyright notice and this permission notice appear in all copies.
|
||||
#
|
||||
# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
|
||||
# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
|
||||
# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
|
||||
# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
|
||||
# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
|
||||
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
|
||||
# PERFORMANCE OF THIS SOFTWARE.
|
||||
############################################################################
|
||||
|
||||
import argparse
|
||||
import os
|
||||
import glob
|
||||
import sys
|
||||
import re
|
||||
import time
|
||||
import calendar
|
||||
from collections import defaultdict
|
||||
import pprint
|
||||
|
||||
prog='dnssec-coverage'
|
||||
|
||||
# These routines permit platform-independent location of BIND 9 tools
|
||||
if os.name == 'nt':
|
||||
import win32con
|
||||
import win32api
|
||||
|
||||
def prefix(bindir = ''):
|
||||
if os.name != 'nt':
|
||||
return os.path.join('@prefix@', bindir)
|
||||
|
||||
bind_subkey = "Software\\ISC\\BIND"
|
||||
hKey = None
|
||||
keyFound = True
|
||||
try:
|
||||
hKey = win32api.RegOpenKeyEx(win32con.HKEY_LOCAL_MACHINE, bind_subkey)
|
||||
except:
|
||||
keyFound = False
|
||||
if keyFound:
|
||||
try:
|
||||
(namedBase, _) = win32api.RegQueryValueEx(hKey, "InstallDir")
|
||||
except:
|
||||
keyFound = False
|
||||
win32api.RegCloseKey(hKey)
|
||||
if keyFound:
|
||||
return os.path.join(namedBase, bindir)
|
||||
return os.path.join(win32api.GetSystemDirectory(), bindir)
|
||||
|
||||
########################################################################
|
||||
# Class Event
|
||||
########################################################################
|
||||
class Event:
|
||||
""" A discrete key metadata event, e.g., Publish, Activate, Inactive,
|
||||
Delete. Stores the date of the event, and identifying information about
|
||||
the key to which the event will occur."""
|
||||
|
||||
def __init__(self, _what, _key):
|
||||
now = time.time()
|
||||
self.what = _what
|
||||
self.when = _key.metadata[_what]
|
||||
self.key = _key
|
||||
self.keyid = _key.keyid
|
||||
self.sep = _key.sep
|
||||
self.zone = _key.zone
|
||||
self.alg = _key.alg
|
||||
|
||||
def __repr__(self):
|
||||
return repr((self.when, self.what, self.keyid, self.sep,
|
||||
self.zone, self.alg))
|
||||
|
||||
def showtime(self):
|
||||
return time.strftime("%a %b %d %H:%M:%S UTC %Y", self.when)
|
||||
|
||||
def showkey(self):
|
||||
return self.key.showkey()
|
||||
|
||||
def showkeytype(self):
|
||||
return self.key.showkeytype()
|
||||
|
||||
########################################################################
|
||||
# Class Key
|
||||
########################################################################
|
||||
class Key:
|
||||
"""An individual DNSSEC key. Identified by path, zone, algorithm, keyid.
|
||||
Contains a dictionary of metadata events."""
|
||||
|
||||
def __init__(self, keyname):
|
||||
directory = os.path.dirname(keyname)
|
||||
key = os.path.basename(keyname)
|
||||
(zone, alg, keyid) = key.split('+')
|
||||
keyid = keyid.split('.')[0]
|
||||
key = [zone, alg, keyid]
|
||||
key_file = directory + os.sep + '+'.join(key) + ".key"
|
||||
private_file = directory + os.sep + '+'.join(key) + ".private"
|
||||
|
||||
self.zone = zone[1:-1]
|
||||
self.alg = int(alg)
|
||||
self.keyid = int(keyid)
|
||||
|
||||
kfp = open(key_file, "r")
|
||||
for line in kfp:
|
||||
if line[0] == ';':
|
||||
continue
|
||||
tokens = line.split()
|
||||
if not tokens:
|
||||
continue
|
||||
|
||||
if tokens[1].lower() in ('in', 'ch', 'hs'):
|
||||
septoken = 3
|
||||
self.ttl = args.keyttl
|
||||
if not self.ttl:
|
||||
vspace()
|
||||
print("WARNING: Unable to determine TTL for DNSKEY %s." %
|
||||
self.showkey())
|
||||
print("\t Using 1 day (86400 seconds); re-run with the -d "
|
||||
"option for more\n\t accurate results.")
|
||||
self.ttl = 86400
|
||||
else:
|
||||
septoken = 4
|
||||
self.ttl = int(tokens[1]) if not args.keyttl else args.keyttl
|
||||
|
||||
if (int(tokens[septoken]) & 0x1) == 1:
|
||||
self.sep = True
|
||||
else:
|
||||
self.sep = False
|
||||
kfp.close()
|
||||
|
||||
pfp = open(private_file, "rU")
|
||||
propDict = dict()
|
||||
for propLine in pfp:
|
||||
propDef = propLine.strip()
|
||||
if len(propDef) == 0:
|
||||
continue
|
||||
if propDef[0] in ('!', '#'):
|
||||
continue
|
||||
punctuation = [propDef.find(c) for c in ':= '] + [len(propDef)]
|
||||
found = min([ pos for pos in punctuation if pos != -1 ])
|
||||
name = propDef[:found].rstrip()
|
||||
value = propDef[found:].lstrip(":= ").rstrip()
|
||||
propDict[name] = value
|
||||
|
||||
if("Publish" in propDict):
|
||||
propDict["Publish"] = time.strptime(propDict["Publish"],
|
||||
"%Y%m%d%H%M%S")
|
||||
|
||||
if("Activate" in propDict):
|
||||
propDict["Activate"] = time.strptime(propDict["Activate"],
|
||||
"%Y%m%d%H%M%S")
|
||||
|
||||
if("Inactive" in propDict):
|
||||
propDict["Inactive"] = time.strptime(propDict["Inactive"],
|
||||
"%Y%m%d%H%M%S")
|
||||
|
||||
if("Delete" in propDict):
|
||||
propDict["Delete"] = time.strptime(propDict["Delete"],
|
||||
"%Y%m%d%H%M%S")
|
||||
|
||||
if("Revoke" in propDict):
|
||||
propDict["Revoke"] = time.strptime(propDict["Revoke"],
|
||||
"%Y%m%d%H%M%S")
|
||||
pfp.close()
|
||||
self.metadata = propDict
|
||||
|
||||
def showkey(self):
|
||||
return "%s/%03d/%05d" % (self.zone, self.alg, self.keyid);
|
||||
|
||||
def showkeytype(self):
|
||||
return ("KSK" if self.sep else "ZSK")
|
||||
|
||||
# ensure that the gap between Publish and Activate is big enough
|
||||
def check_prepub(self):
|
||||
now = time.time()
|
||||
|
||||
if (not "Activate" in self.metadata):
|
||||
debug_print("No Activate information in key: %s" % self.showkey())
|
||||
return False
|
||||
a = calendar.timegm(self.metadata["Activate"])
|
||||
|
||||
if (not "Publish" in self.metadata):
|
||||
debug_print("No Publish information in key: %s" % self.showkey())
|
||||
if a > now:
|
||||
vspace()
|
||||
print("WARNING: Key %s (%s) is scheduled for activation but \n"
|
||||
"\t not for publication." %
|
||||
(self.showkey(), self.showkeytype()))
|
||||
return False
|
||||
p = calendar.timegm(self.metadata["Publish"])
|
||||
|
||||
now = time.time()
|
||||
if p < now and a < now:
|
||||
return True
|
||||
|
||||
if p == a:
|
||||
vspace()
|
||||
print ("WARNING: %s (%s) is scheduled to be published and\n"
|
||||
"\t activated at the same time. This could result in a\n"
|
||||
"\t coverage gap if the zone was previously signed." %
|
||||
(self.showkey(), self.showkeytype()))
|
||||
print("\t Activation should be at least %s after publication."
|
||||
% duration(self.ttl))
|
||||
return True
|
||||
|
||||
if a < p:
|
||||
vspace()
|
||||
print("WARNING: Key %s (%s) is active before it is published" %
|
||||
(self.showkey(), self.showkeytype()))
|
||||
return False
|
||||
|
||||
if (a - p < self.ttl):
|
||||
vspace()
|
||||
print("WARNING: Key %s (%s) is activated too soon after\n"
|
||||
"\t publication; this could result in coverage gaps due to\n"
|
||||
"\t resolver caches containing old data."
|
||||
% (self.showkey(), self.showkeytype()))
|
||||
print("\t Activation should be at least %s after publication." %
|
||||
duration(self.ttl))
|
||||
return False
|
||||
|
||||
return True
|
||||
|
||||
# ensure that the gap between Inactive and Delete is big enough
|
||||
def check_postpub(self, timespan = None):
|
||||
if not timespan:
|
||||
timespan = self.ttl
|
||||
|
||||
now = time.time()
|
||||
|
||||
if (not "Delete" in self.metadata):
|
||||
debug_print("No Delete information in key: %s" % self.showkey())
|
||||
return False
|
||||
d = calendar.timegm(self.metadata["Delete"])
|
||||
|
||||
if (not "Inactive" in self.metadata):
|
||||
debug_print("No Inactive information in key: %s" % self.showkey())
|
||||
if d > now:
|
||||
vspace()
|
||||
print("WARNING: Key %s (%s) is scheduled for deletion but\n"
|
||||
"\t not for inactivation." %
|
||||
(self.showkey(), self.showkeytype()))
|
||||
return False
|
||||
i = calendar.timegm(self.metadata["Inactive"])
|
||||
|
||||
if d < now and i < now:
|
||||
return True
|
||||
|
||||
if (d < i):
|
||||
vspace()
|
||||
print("WARNING: Key %s (%s) is scheduled for deletion before\n"
|
||||
"\t inactivation." % (self.showkey(), self.showkeytype()))
|
||||
return False
|
||||
|
||||
if (d - i < timespan):
|
||||
vspace()
|
||||
print("WARNING: Key %s (%s) scheduled for deletion too soon after\n"
|
||||
"\t deactivation; this may result in coverage gaps due to\n"
|
||||
"\t resolver caches containing old data."
|
||||
% (self.showkey(), self.showkeytype()))
|
||||
print("\t Deletion should be at least %s after inactivation." %
|
||||
duration(timespan))
|
||||
return False
|
||||
|
||||
return True
|
||||
|
||||
########################################################################
|
||||
# class Zone
|
||||
########################################################################
|
||||
class Zone:
|
||||
"""Stores data about a specific zone"""
|
||||
|
||||
def __init__(self, _name, _keyttl = None, _maxttl = None):
|
||||
self.name = _name
|
||||
self.keyttl = _keyttl
|
||||
self.maxttl = _maxttl
|
||||
|
||||
def load(self, filename):
|
||||
if not args.compilezone:
|
||||
sys.stderr.write(prog + ': FATAL: "named-compilezone" not found\n')
|
||||
exit(1)
|
||||
|
||||
if not self.name:
|
||||
return
|
||||
|
||||
maxttl = keyttl = None
|
||||
|
||||
fp = os.popen("%s -o - %s %s 2> /dev/null" %
|
||||
(args.compilezone, self.name, filename))
|
||||
for line in fp:
|
||||
fields = line.split()
|
||||
if not maxttl or int(fields[1]) > maxttl:
|
||||
maxttl = int(fields[1])
|
||||
if fields[3] == "DNSKEY":
|
||||
keyttl = int(fields[1])
|
||||
fp.close()
|
||||
|
||||
self.keyttl = keyttl
|
||||
self.maxttl = maxttl
|
||||
|
||||
############################################################################
|
||||
# debug_print:
|
||||
############################################################################
|
||||
def debug_print(debugVar):
|
||||
"""pretty print a variable iff debug mode is enabled"""
|
||||
if not args.debug_mode:
|
||||
return
|
||||
if type(debugVar) == str:
|
||||
print("DEBUG: " + debugVar)
|
||||
else:
|
||||
print("DEBUG: " + pprint.pformat(debugVar))
|
||||
return
|
||||
|
||||
############################################################################
|
||||
# vspace:
|
||||
############################################################################
|
||||
_firstline = True
|
||||
def vspace():
|
||||
"""adds vertical space between two sections of output text if and only
|
||||
if this is *not* the first section being printed"""
|
||||
global _firstline
|
||||
if _firstline:
|
||||
_firstline = False
|
||||
else:
|
||||
print
|
||||
|
||||
############################################################################
|
||||
# vreset:
|
||||
############################################################################
|
||||
def vreset():
|
||||
"""reset vertical spacing"""
|
||||
global _firstline
|
||||
_firstline = True
|
||||
|
||||
############################################################################
|
||||
# getunit
|
||||
############################################################################
|
||||
def getunit(secs, size):
|
||||
"""given a number of seconds, and a number of seconds in a larger unit of
|
||||
time, calculate how many of the larger unit there are and return both
|
||||
that and a remainder value"""
|
||||
bigunit = secs // size
|
||||
if bigunit:
|
||||
secs %= size
|
||||
return (bigunit, secs)
|
||||
|
||||
############################################################################
|
||||
# addtime
|
||||
############################################################################
|
||||
def addtime(output, unit, t):
|
||||
"""add a formatted unit of time to an accumulating string"""
|
||||
if t:
|
||||
output += ("%s%d %s%s" %
|
||||
((", " if output else ""),
|
||||
t, unit, ("s" if t > 1 else "")))
|
||||
|
||||
return output
|
||||
|
||||
############################################################################
|
||||
# duration:
|
||||
############################################################################
|
||||
def duration(secs):
|
||||
"""given a length of time in seconds, print a formatted human duration
|
||||
in larger units of time
|
||||
"""
|
||||
# define units:
|
||||
minute = 60
|
||||
hour = minute * 60
|
||||
day = hour * 24
|
||||
month = day * 30
|
||||
year = day * 365
|
||||
|
||||
# calculate time in units:
|
||||
(years, secs) = getunit(secs, year)
|
||||
(months, secs) = getunit(secs, month)
|
||||
(days, secs) = getunit(secs, day)
|
||||
(hours, secs) = getunit(secs, hour)
|
||||
(minutes, secs) = getunit(secs, minute)
|
||||
|
||||
output = ''
|
||||
output = addtime(output, "year", years)
|
||||
output = addtime(output, "month", months)
|
||||
output = addtime(output, "day", days)
|
||||
output = addtime(output, "hour", hours)
|
||||
output = addtime(output, "minute", minutes)
|
||||
output = addtime(output, "second", secs)
|
||||
return output
|
||||
|
||||
############################################################################
|
||||
# parse_time
|
||||
############################################################################
|
||||
def parse_time(s):
|
||||
"""convert a formatted time (e.g., 1y, 6mo, 15mi, etc) into seconds"""
|
||||
s = s.strip()
|
||||
|
||||
# if s is an integer, we're done already
|
||||
try:
|
||||
n = int(s)
|
||||
return n
|
||||
except:
|
||||
pass
|
||||
|
||||
# try to parse as a number with a suffix indicating unit of time
|
||||
r = re.compile('([0-9][0-9]*)\s*([A-Za-z]*)')
|
||||
m = r.match(s)
|
||||
if not m:
|
||||
raise Exception("Cannot parse %s" % s)
|
||||
(n, unit) = m.groups()
|
||||
n = int(n)
|
||||
unit = unit.lower()
|
||||
if unit[0] == 'y':
|
||||
return n * 31536000
|
||||
elif unit[0] == 'm' and unit[1] == 'o':
|
||||
return n * 2592000
|
||||
elif unit[0] == 'w':
|
||||
return n * 604800
|
||||
elif unit[0] == 'd':
|
||||
return n * 86400
|
||||
elif unit[0] == 'h':
|
||||
return n * 3600
|
||||
elif unit[0] == 'm' and unit[1] == 'i':
|
||||
return n * 60
|
||||
elif unit[0] == 's':
|
||||
return n
|
||||
else:
|
||||
raise Exception("Invalid suffix %s" % unit)
|
||||
|
||||
############################################################################
|
||||
# algname:
|
||||
############################################################################
|
||||
def algname(alg):
|
||||
"""return the mnemonic for a DNSSEC algorithm"""
|
||||
names = (None, 'RSAMD5', 'DH', 'DSA', 'ECC', 'RSASHA1',
|
||||
'NSEC3DSA', 'NSEC3RSASHA1', 'RSASHA256', None,
|
||||
'RSASHA512', None, 'ECCGOST', 'ECDSAP256SHA256',
|
||||
'ECDSAP384SHA384')
|
||||
name = None
|
||||
if alg in range(len(names)):
|
||||
name = names[alg]
|
||||
return (name if name else str(alg))
|
||||
|
||||
############################################################################
|
||||
# list_events:
|
||||
############################################################################
|
||||
def list_events(eventgroup):
|
||||
"""print a list of the events in an eventgroup"""
|
||||
if not eventgroup:
|
||||
return
|
||||
print (" " + eventgroup[0].showtime() + ":")
|
||||
for event in eventgroup:
|
||||
print (" %s: %s (%s)" %
|
||||
(event.what, event.showkey(), event.showkeytype()))
|
||||
|
||||
############################################################################
|
||||
# process_events:
|
||||
############################################################################
|
||||
def process_events(eventgroup, active, published):
|
||||
"""go through the events in an event group in time-order, add to active
|
||||
list upon Activate event, add to published list upon Publish event,
|
||||
remove from active list upon Inactive event, and remove from published
|
||||
upon Delete event. Emit warnings when inconsistant states are reached"""
|
||||
for event in eventgroup:
|
||||
if event.what == "Activate":
|
||||
active.add(event.keyid)
|
||||
elif event.what == "Publish":
|
||||
published.add(event.keyid)
|
||||
elif event.what == "Inactive":
|
||||
if event.keyid not in active:
|
||||
vspace()
|
||||
print ("\tWARNING: %s (%s) scheduled to become inactive "
|
||||
"before it is active" %
|
||||
(event.showkey(), event.showkeytype()))
|
||||
else:
|
||||
active.remove(event.keyid)
|
||||
elif event.what == "Delete":
|
||||
if event.keyid in published:
|
||||
published.remove(event.keyid)
|
||||
else:
|
||||
vspace()
|
||||
print ("WARNING: key %s (%s) is scheduled for deletion before "
|
||||
"it is published, at %s" %
|
||||
(event.showkey(), event.showkeytype()))
|
||||
elif event.what == "Revoke":
|
||||
# We don't need to worry about the logic of this one;
|
||||
# just stop counting this key as either active or published
|
||||
if event.keyid in published:
|
||||
published.remove(event.keyid)
|
||||
if event.keyid in active:
|
||||
active.remove(event.keyid)
|
||||
|
||||
return (active, published)
|
||||
|
||||
############################################################################
|
||||
# check_events:
|
||||
############################################################################
|
||||
def check_events(eventsList, ksk):
|
||||
"""create lists of events happening at the same time, check for
|
||||
inconsistancies"""
|
||||
active = set()
|
||||
published = set()
|
||||
eventgroups = list()
|
||||
eventgroup = list()
|
||||
keytype = ("KSK" if ksk else "ZSK")
|
||||
|
||||
# collect up all events that have the same time
|
||||
eventsfound = False
|
||||
for event in eventsList:
|
||||
# if checking ZSKs, skip KSKs, and vice versa
|
||||
if (ksk and not event.sep) or (event.sep and not ksk):
|
||||
continue
|
||||
|
||||
# we found an appropriate (ZSK or KSK event)
|
||||
eventsfound = True
|
||||
|
||||
# add event to current eventgroup
|
||||
if (not eventgroup or eventgroup[0].when == event.when):
|
||||
eventgroup.append(event)
|
||||
|
||||
# if we're at the end of the list, we're done. if
|
||||
# we've found an event with a later time, start a new
|
||||
# eventgroup
|
||||
if (eventgroup[0].when != event.when):
|
||||
eventgroups.append(eventgroup)
|
||||
eventgroup = list()
|
||||
eventgroup.append(event)
|
||||
|
||||
if eventgroup:
|
||||
eventgroups.append(eventgroup)
|
||||
|
||||
for eventgroup in eventgroups:
|
||||
if (args.checklimit and
|
||||
calendar.timegm(eventgroup[0].when) > args.checklimit):
|
||||
print("Ignoring events after %s" %
|
||||
time.strftime("%a %b %d %H:%M:%S UTC %Y",
|
||||
time.gmtime(args.checklimit)))
|
||||
return True
|
||||
|
||||
(active, published) = \
|
||||
process_events(eventgroup, active, published)
|
||||
|
||||
list_events(eventgroup)
|
||||
|
||||
# and then check for inconsistencies:
|
||||
if len(active) == 0:
|
||||
print ("ERROR: No %s's are active after this event" % keytype)
|
||||
return False
|
||||
elif len(published) == 0:
|
||||
sys.stdout.write("ERROR: ")
|
||||
print ("ERROR: No %s's are published after this event" % keytype)
|
||||
return False
|
||||
elif len(published.intersection(active)) == 0:
|
||||
sys.stdout.write("ERROR: ")
|
||||
print (("ERROR: No %s's are both active and published " +
|
||||
"after this event") % keytype)
|
||||
return False
|
||||
|
||||
if not eventsfound:
|
||||
print ("ERROR: No %s events found in '%s'" %
|
||||
(keytype, args.path))
|
||||
return False
|
||||
|
||||
return True
|
||||
|
||||
############################################################################
|
||||
# check_zones:
|
||||
# ############################################################################
|
||||
def check_zones(eventsList):
|
||||
"""scan events per zone, algorithm, and key type, in order of occurrance,
|
||||
noting inconsistent states when found"""
|
||||
global foundprob
|
||||
|
||||
foundprob = False
|
||||
zonesfound = False
|
||||
for zone in eventsList:
|
||||
if args.zone and zone != args.zone:
|
||||
continue
|
||||
|
||||
zonesfound = True
|
||||
for alg in eventsList[zone]:
|
||||
if not args.no_ksk:
|
||||
vspace()
|
||||
print("Checking scheduled KSK events for zone %s, algorithm %s..." %
|
||||
(zone, algname(alg)))
|
||||
if not check_events(eventsList[zone][alg], True):
|
||||
foundprob = True
|
||||
else:
|
||||
print ("No errors found")
|
||||
|
||||
if not args.no_zsk:
|
||||
vspace()
|
||||
print("Checking scheduled ZSK events for zone %s, algorithm %s..." %
|
||||
(zone, algname(alg)))
|
||||
if not check_events(eventsList[zone][alg], False):
|
||||
foundprob = True
|
||||
else:
|
||||
print ("No errors found")
|
||||
|
||||
if not zonesfound:
|
||||
print("ERROR: No key events found for %s in '%s'" %
|
||||
(args.zone, args.path))
|
||||
exit(1)
|
||||
|
||||
############################################################################
|
||||
# fill_eventsList:
|
||||
############################################################################
|
||||
def fill_eventsList(eventsList):
|
||||
"""populate the list of events"""
|
||||
for zone, algorithms in keyDict.items():
|
||||
for alg, keys in algorithms.items():
|
||||
for keyid, keydata in keys.items():
|
||||
if("Publish" in keydata.metadata):
|
||||
eventsList[zone][alg].append(Event("Publish", keydata))
|
||||
if("Activate" in keydata.metadata):
|
||||
eventsList[zone][alg].append(Event("Activate", keydata))
|
||||
if("Inactive" in keydata.metadata):
|
||||
eventsList[zone][alg].append(Event("Inactive", keydata))
|
||||
if("Delete" in keydata.metadata):
|
||||
eventsList[zone][alg].append(Event("Delete", keydata))
|
||||
|
||||
eventsList[zone][alg] = sorted(eventsList[zone][alg],
|
||||
key=lambda event: event.when)
|
||||
|
||||
foundprob = False
|
||||
if not keyDict:
|
||||
print("ERROR: No key events found in '%s'" % args.path)
|
||||
exit(1)
|
||||
|
||||
############################################################################
|
||||
# set_path:
|
||||
############################################################################
|
||||
def set_path(command, default=None):
|
||||
"""find the location of a specified command. if a default is supplied
|
||||
and it works, we use it; otherwise we search PATH for a match. If
|
||||
not found, error and exit"""
|
||||
fpath = default
|
||||
if not fpath or not os.path.isfile(fpath) or not os.access(fpath, os.X_OK):
|
||||
path = os.environ["PATH"]
|
||||
if not path:
|
||||
path = os.path.defpath
|
||||
for directory in path.split(os.pathsep):
|
||||
fpath = directory + os.sep + command
|
||||
if os.path.isfile(fpath) or os.access(fpath, os.X_OK):
|
||||
break
|
||||
fpath = None
|
||||
|
||||
return fpath
|
||||
|
||||
############################################################################
|
||||
# parse_args:
|
||||
############################################################################
|
||||
def parse_args():
|
||||
"""Read command line arguments, set global 'args' structure"""
|
||||
global args
|
||||
compilezone = set_path('named-compilezone',
|
||||
os.path.join(prefix('bin'), 'named-compilezone'))
|
||||
|
||||
parser = argparse.ArgumentParser(description=prog + ': checks future ' +
|
||||
'DNSKEY coverage for a zone')
|
||||
|
||||
parser.add_argument('zone', type=str, help='zone to check')
|
||||
parser.add_argument('-K', dest='path', default='.', type=str,
|
||||
help='a directory containing keys to process',
|
||||
metavar='dir')
|
||||
parser.add_argument('-f', dest='filename', type=str,
|
||||
help='zone master file', metavar='file')
|
||||
parser.add_argument('-m', dest='maxttl', type=str,
|
||||
help='the longest TTL in the zone(s)',
|
||||
metavar='time')
|
||||
parser.add_argument('-d', dest='keyttl', type=str,
|
||||
help='the DNSKEY TTL', metavar='time')
|
||||
parser.add_argument('-r', dest='resign', default='1944000',
|
||||
type=int, help='the RRSIG refresh interval '
|
||||
'in seconds [default: 22.5 days]',
|
||||
metavar='time')
|
||||
parser.add_argument('-c', dest='compilezone',
|
||||
default=compilezone, type=str,
|
||||
help='path to \'named-compilezone\'',
|
||||
metavar='path')
|
||||
parser.add_argument('-l', dest='checklimit',
|
||||
type=str, default='0',
|
||||
help='Length of time to check for '
|
||||
'DNSSEC coverage [default: 0 (unlimited)]',
|
||||
metavar='time')
|
||||
parser.add_argument('-z', dest='no_ksk',
|
||||
action='store_true', default=False,
|
||||
help='Only check zone-signing keys (ZSKs)')
|
||||
parser.add_argument('-k', dest='no_zsk',
|
||||
action='store_true', default=False,
|
||||
help='Only check key-signing keys (KSKs)')
|
||||
parser.add_argument('-D', '--debug', dest='debug_mode',
|
||||
action='store_true', default=False,
|
||||
help='Turn on debugging output')
|
||||
parser.add_argument('-v', '--version', action='version', version='9.9.1')
|
||||
|
||||
args = parser.parse_args()
|
||||
|
||||
if args.no_zsk and args.no_ksk:
|
||||
print("ERROR: -z and -k cannot be used together.");
|
||||
exit(1)
|
||||
|
||||
# convert from time arguments to seconds
|
||||
try:
|
||||
if args.maxttl:
|
||||
m = parse_time(args.maxttl)
|
||||
args.maxttl = m
|
||||
except:
|
||||
pass
|
||||
|
||||
try:
|
||||
if args.keyttl:
|
||||
k = parse_time(args.keyttl)
|
||||
args.keyttl = k
|
||||
except:
|
||||
pass
|
||||
|
||||
try:
|
||||
if args.resign:
|
||||
r = parse_time(args.resign)
|
||||
args.resign = r
|
||||
except:
|
||||
pass
|
||||
|
||||
try:
|
||||
if args.checklimit:
|
||||
lim = args.checklimit
|
||||
r = parse_time(args.checklimit)
|
||||
if r == 0:
|
||||
args.checklimit = None
|
||||
else:
|
||||
args.checklimit = time.time() + r
|
||||
except:
|
||||
pass
|
||||
|
||||
# if we've got the values we need from the command line, stop now
|
||||
if args.maxttl and args.keyttl:
|
||||
return
|
||||
|
||||
# load keyttl and maxttl data from zonefile
|
||||
if args.zone and args.filename:
|
||||
try:
|
||||
zone = Zone(args.zone)
|
||||
zone.load(args.filename)
|
||||
if not args.maxttl:
|
||||
args.maxttl = zone.maxttl
|
||||
if not args.keyttl:
|
||||
args.keyttl = zone.maxttl
|
||||
except Exception as e:
|
||||
print("Unable to load zone data from %s: " % args.filename, e)
|
||||
|
||||
if not args.maxttl:
|
||||
vspace()
|
||||
print ("WARNING: Maximum TTL value was not specified. Using 1 week\n"
|
||||
"\t (604800 seconds); re-run with the -m option to get more\n"
|
||||
"\t accurate results.")
|
||||
args.maxttl = 604800
|
||||
|
||||
############################################################################
|
||||
# Main
|
||||
############################################################################
|
||||
def main():
|
||||
global keyDict
|
||||
|
||||
parse_args()
|
||||
path=args.path
|
||||
|
||||
print ("PHASE 1--Loading keys to check for internal timing problems")
|
||||
keyDict = defaultdict(lambda : defaultdict(dict))
|
||||
files = glob.glob(os.path.join(path, '*.private'))
|
||||
for infile in files:
|
||||
key = Key(infile)
|
||||
if args.zone and key.zone != args.zone:
|
||||
continue
|
||||
keyDict[key.zone][key.alg][key.keyid] = key
|
||||
key.check_prepub()
|
||||
if key.sep:
|
||||
key.check_postpub()
|
||||
else:
|
||||
key.check_postpub(args.maxttl + args.resign)
|
||||
|
||||
vspace()
|
||||
print ("PHASE 2--Scanning future key events for coverage failures")
|
||||
vreset()
|
||||
|
||||
eventsList = defaultdict(lambda : defaultdict(list))
|
||||
fill_eventsList(eventsList)
|
||||
check_zones(eventsList)
|
||||
|
||||
if foundprob:
|
||||
exit(1)
|
||||
else:
|
||||
exit(0)
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
Reference in New Issue
Block a user