1. 09 Sep, 2018 1 commit
  2. 02 Aug, 2018 2 commits
  3. 19 Jul, 2018 1 commit
  4. 11 Jul, 2018 1 commit
  5. 31 May, 2018 1 commit
    • Evan Hunt's avatar
      update system tests so validation won't fail when using IANA key · a7a2fa29
      Evan Hunt authored
      - all tests with "recursion yes" now also specify "dnssec-validation yes",
        and all tests with "recursion no" also specify "dnssec-validation no".
        this must be maintained in all new tests, or else validation will fail
        when we use local root zones for testing.
      - clean.sh has been modified where necessary to remove managed-keys.bind
        and viewname.mkeys files.
      a7a2fa29
  6. 16 May, 2018 1 commit
  7. 11 May, 2018 1 commit
  8. 27 Feb, 2018 1 commit
    • Evan Hunt's avatar
      clean up test output · 0e52fbd0
      Evan Hunt authored
      - removed a few remaing places where output wasn't being passed
        through echo_i or cat_i
      - added a "digcomp" function to conf.sh.in to send digcomp.pl output
        through cat_i and return the correct exit value
      - set SYSTESTDIR when calling echo_i from nsX directories, so that
        the test name will always be printed correctly
      - fixed a test name typo in conf.sh.in
      0e52fbd0
  9. 26 Feb, 2018 1 commit
    • Michał Kępień's avatar
      Fix MX checks for dynamic updates · 857a40c8
      Michał Kępień authored
      The check_mx() function in lib/ns/update.c incorrectly tests whether the
      DNS_RDATA_CHECKMX/DNS_RDATA_CHECKMXFAIL flags are set for each applied
      MX record update as these flags are never set in code paths related to
      dynamic updates; they can only be set when loading a zone from a master
      file (DNS_ZONEOPT_CHECKMX -> DNS_MASTER_CHECKMX -> DNS_RDATA_CHECKMX).
      This flaw allows MX records containing IP addresses to be added to a
      zone even when "check-mx fail;" is used.
      
      Ensure correct behavior by modifying the relevant tests in check_mx() so
      that they use DNS_ZONEOPT_CHECKMX/DNS_ZONEOPT_CHECKMXFAIL instead.
      857a40c8
  10. 23 Feb, 2018 2 commits
  11. 22 Feb, 2018 1 commit
  12. 22 Jan, 2018 2 commits
  13. 27 Nov, 2017 1 commit
  14. 10 Nov, 2017 2 commits
  15. 25 Oct, 2017 1 commit
  16. 07 Oct, 2017 1 commit
  17. 06 Oct, 2017 1 commit
    • Evan Hunt's avatar
      [master] further restrict update-policy local · 995c41e8
      Evan Hunt authored
      4762.	[func]		"update-policy local" is now restricted to updates
      			from local addresses. (Previously, other addresses
      			were allowed so long as updates were signed by the
      			local session key.) [RT #45492]
      995c41e8
  18. 11 Sep, 2017 1 commit
  19. 08 Sep, 2017 1 commit
    • Evan Hunt's avatar
      [master] add libns and remove liblwres · 8eb88aaf
      Evan Hunt authored
      4708.   [cleanup]       Legacy Windows builds (i.e. for XP and earlier)
                              are no longer supported. [RT #45186]
      
      4707.	[func]		The lightweight resolver daemon and library (lwresd
      			and liblwres) have been removed. [RT #45186]
      
      4706.	[func]		Code implementing name server query processing has
      			been moved from bin/named to a new library "libns".
      			Functions remaining in bin/named are now prefixed
      			with "named_" rather than "ns_".  This will make it
      			easier to write unit tests for name server code, or
      			link name server functionality into new tools.
      			[RT #45186]
      8eb88aaf
  20. 01 Sep, 2017 1 commit
  21. 31 Aug, 2017 1 commit
    • Evan Hunt's avatar
      [master] remove default algorithm in dnssec-keygen · 45afdb26
      Evan Hunt authored
      4594.	[func]		dnssec-keygen no longer uses RSASHA1 by default;
      			the signing algorithm must be specified on
      			the command line with the "-a" option.  Signing
      			scripts that rely on the existing default behavior
      			will break; use "dnssec-keygen -a RSASHA1" to
      			repair them. (The goal of this change is to make
      			it easier to find scripts using RSASHA1 so they
      			can be changed in the event of that algorithm
      			being deprecated in the future.) [RT #44755]
      45afdb26
  22. 29 Aug, 2017 1 commit
  23. 17 Aug, 2017 1 commit
  24. 19 Jul, 2017 3 commits
  25. 29 May, 2017 1 commit
  26. 02 May, 2017 2 commits
  27. 24 Apr, 2017 1 commit
  28. 22 Apr, 2017 2 commits
  29. 21 Apr, 2017 1 commit
  30. 13 Dec, 2016 2 commits
  31. 03 Nov, 2016 1 commit