DNSSEC: signature checking, forced signing, merged diff's and DNSSEC's changesets
- Zones are now automatically (re)signed when server starts/reloads - Signature validity check now calculates the signature as well - this is used to detect changes to RRs themselves - 'knotc signzone' issues a force signing of zone - all RRSIGs are dropped and recreated - Some leaks and bugs still present, but the code is commitable now Refs #4
Showing
- src/knot/conf/conf.c 8 additions, 5 deletionssrc/knot/conf/conf.c
- src/knot/server/zones.c 191 additions, 148 deletionssrc/knot/server/zones.c
- src/knot/server/zones.h 4 additions, 3 deletionssrc/knot/server/zones.h
- src/libknot/dnssec/policy.h 4 additions, 1 deletionsrc/libknot/dnssec/policy.h
- src/libknot/dnssec/zone-events.c 78 additions, 61 deletionssrc/libknot/dnssec/zone-events.c
- src/libknot/dnssec/zone-events.h 3 additions, 1 deletionsrc/libknot/dnssec/zone-events.h
- src/libknot/dnssec/zone-sign.c 124 additions, 52 deletionssrc/libknot/dnssec/zone-sign.c
- src/libknot/dnssec/zone-sign.h 1 addition, 1 deletionsrc/libknot/dnssec/zone-sign.h
- src/libknot/rrset.c 4 additions, 5 deletionssrc/libknot/rrset.c
- src/libknot/rrset.h 4 additions, 0 deletionssrc/libknot/rrset.h
- src/libknot/updates/changesets.c 24 additions, 13 deletionssrc/libknot/updates/changesets.c
- src/libknot/updates/changesets.h 15 additions, 3 deletionssrc/libknot/updates/changesets.h
- src/libknot/updates/xfr-in.c 3 additions, 0 deletionssrc/libknot/updates/xfr-in.c
- src/libknot/updates/xfr-in.h 1 addition, 1 deletionsrc/libknot/updates/xfr-in.h
- src/libknot/zone/zone-diff.c 3 additions, 18 deletionssrc/libknot/zone/zone-diff.c
- src/libknot/zone/zone-diff.h 1 addition, 2 deletionssrc/libknot/zone/zone-diff.h
Loading
Please register or sign in to comment