Skip to content
Snippets Groups Projects
  1. Oct 28, 2013
  2. Oct 14, 2013
  3. Oct 12, 2013
  4. Oct 11, 2013
  5. Oct 01, 2013
  6. Sep 26, 2013
    • Jan Kadlec's avatar
      SEC: zone resign planning · 81b7bbc7
      Jan Kadlec authored
      - Signing function now store the oldest signature expiration time, this time is
      later used to plan zone resigning.
      - Added new info strings to the 'zonestatus' command - gives information about w
      hen the zone will be resigned
      
      Refs #4
      81b7bbc7
  7. Sep 25, 2013
  8. Sep 24, 2013
  9. Sep 20, 2013
  10. Sep 19, 2013
  11. Sep 12, 2013
  12. Sep 11, 2013
    • Jan Včelák's avatar
      DNSSEC: use only compatible algorithms with NSEC/NSEC3 · ba2cb05a
      Jan Včelák authored
      Key algorithm and used NSEC type must match:
      
      RFC 5155 states, that for compatibility with old resolvers, NSEC3
      must be used only with NSEC3 algorithms.
      
      It makes no sense to sign NSEC with NSEC3 keys, because it will make
      the validation impossible on NSEC3-unaware resolvers. This is stricter
      than what dnssec-signzone from ISC does.
      
      refs #4
      ba2cb05a
  13. Sep 10, 2013
  14. Sep 04, 2013
  15. Sep 01, 2013
  16. Aug 27, 2013
    • Jan Kadlec's avatar
      DNSSEC: bugfixes, debug code · 3cc2223f
      Jan Kadlec authored
      - First store merge changesets, then apply signatures
      - Added pretty print function to dump changesets, HAS TO BE REMOVED!!!
      - some fixes, mainly in signature checking
      - fails to save to journal for same reason
      - deliberate leaks - malformed changesets, needs custom freeing function
      
      Refs #4
      3cc2223f
    • Jan Kadlec's avatar
      DNSSEC: signature checking, forced signing, merged diff's and DNSSEC's changesets · 8ab216e1
      Jan Kadlec authored
      - Zones are now automatically (re)signed when server starts/reloads
      - Signature validity check now calculates the signature as well - this is used to detect changes to RRs themselves
      - 'knotc signzone' issues a force signing of zone - all RRSIGs are dropped and recreated
      - Some leaks and bugs still present, but the code is commitable now
      
      Refs #4
      8ab216e1
  17. Aug 22, 2013
    • Jan Kadlec's avatar
      DNSSEC: Small changes. · 18d9ee1b
      Jan Kadlec authored
      - Refactored node walking a bit (API instead of hard-coded trie walk)
      - Double free fix (wrong merge probably)
      
      Refs #4
      18d9ee1b
  18. Aug 13, 2013
  19. Aug 12, 2013
    • Jan Kadlec's avatar
      DNSSEC: Handling of SOA RRSIGs. · 54e06c83
      Jan Kadlec authored
      - Quite a lot of changes had to be done, because some variables were only accesible locally.
      - Some includes might not be needed, needs a second look.
      
      Refs #4
      54e06c83
  20. Aug 06, 2013
  21. Jul 31, 2013