dnssec-checkds CDS support, and other improvements
* Use `dnssec-dsfromkey -p` to work out what the delegation records should be, based on CDS records. * Better error checking for failures by `dig`. * Add a --every mode for checking all the parent name servers. This is for extra protection against long propagation delays. * Add a --quiet mode to avoid unwanted cronspam. There is still output if something unexpected happens, so --quiet mode is better for cron jobs than just redirecting the output. * Explain how this tool relates to other tools. The current strict consistency logic was introduced when SHA-1 was deprecated, but it wasn't documented. The manual has now been updated. (Users who want checks based on validation semantics should use something like zonemaster or dnsviz instead.)
Name | Stage | Failure | ||
---|---|---|---|---|
failed
|
system:gcc:stretch:amd64 | System | ||
|
||||
failed
|
system:gcc:alpine3.11:amd64 | System | ||
|
||||
failed
|
system:gcc:centos7:amd64 | System | ||
|
||||
failed
|
system:gcc:xenial:amd64 | System | ||
|
||||
failed
|
system:nolibtool:sid:amd64 | System | ||
|
||||
failed
|
system:gcc:tumbleweed:amd64 | System | ||
|
||||
failed
|
system:gcc:bionic:amd64 | System | ||
|
||||
failed
|
system:gcc:fedora31:amd64 | System | ||
|
||||
failed
|
system:pkcs11:sid:amd64 | System | ||
|
||||
failed
|
system:rwlock:sid:amd64 | System | ||
|
||||
failed
|
system:asan:sid:amd64 | System | ||
|
||||
failed
|
system:gcc:sid:amd64 | System | ||
|
||||
failed
|
unit:tsan:buster:amd64 | Unit | ||
|
||||
failed
|
system:gcc:centos6:amd64 | System | ||
|
||||
failed
|
cppcheck:gcc:sid:amd64 | Postcheck | ||
|
||||
failed
|
system:clang:freebsd12.0:amd64 | System | ||
|
||||
failed
|
system:gcc:centos8:amd64 | System | ||
|
||||
failed
|
misc:sid:amd64 | Precheck | ||
|
||||
failed
|
system:gcc:jessie:amd64 | System | ||
|
||||
failed
|
system:gcc:buster:amd64 | System | ||
|
||||
failed
|
system:tsan:buster:amd64 | System | ||
|
||||
failed
|
system:clang:freebsd11.3:amd64 | System | ||
|