bind9/bin/tests/system/dnssec
Matthijs Mekking 0040947ae7 Test secure chain that includes inactive KSK
Add a regression test case for the scenario where a secure chain of
trust includes an inactive KSK, that is a KSK that is not signing the
DNSKEY RRset.

(cherry picked from commit f0bfd276e0)
2024-03-12 11:50:08 +01:00
..
ans10 Adapt to Python scripts to black 23.1.0 2023-02-17 16:55:47 +01:00
ns1 Test secure chain that includes inactive KSK 2024-03-12 11:50:08 +01:00
ns2 Test secure chain that includes inactive KSK 2024-03-12 11:50:08 +01:00
ns3 Add a system test for mixed-case data for the same owner 2024-02-11 11:57:58 +01:00
ns4 Test managed-keys placeholder 2022-11-01 10:55:19 +00:00
ns5 Reformat shell scripts with shfmt 2023-10-26 13:24:51 +02:00
ns6 Reformat shell scripts with shfmt 2023-10-26 13:24:51 +02:00
ns7 Reformat shell scripts with shfmt 2023-10-26 13:24:51 +02:00
ns8 Update the copyright information in all files in the repository 2022-01-11 12:22:09 +01:00
ns9 Update the copyright information in all files in the repository 2022-01-11 12:22:09 +01:00
signer dnssec/signer/general: Replace RSASHA1 keys with RSASHA512 keys 2022-10-03 13:28:25 +02:00
clean.sh Test secure chain that includes inactive KSK 2024-03-12 11:50:08 +01:00
dnssec_update_test.pl Update the copyright information in all files in the repository 2022-01-11 12:22:09 +01:00
ntadiff.pl Update the copyright information in all files in the repository 2022-01-11 12:22:09 +01:00
prereq.sh Reformat shell scripts with shfmt 2023-10-26 13:24:51 +02:00
README Update the copyright information in all files in the repository 2022-01-11 12:22:09 +01:00
setup.sh Reformat shell scripts with shfmt 2023-10-26 13:24:51 +02:00
tests.sh Test secure chain that includes inactive KSK 2024-03-12 11:50:08 +01:00

Copyright (C) Internet Systems Consortium, Inc. ("ISC")

SPDX-License-Identifier: MPL-2.0

This Source Code Form is subject to the terms of the Mozilla Public
License, v. 2.0.  If a copy of the MPL was not distributed with this
file, you can obtain one at https://mozilla.org/MPL/2.0/.

See the COPYRIGHT file distributed with this work for additional
information regarding copyright ownership.

The test setup for the DNSSEC tests has a secure root.

ns1 is the root server.

ns2 and ns3 are authoritative servers for the various test domains.

ns4 is a caching-only server, configured with the correct trusted key
for the root.

ns5 is a caching-only server, configured with the an incorrect trusted
key for the root.  It is used for testing failure cases.

ns6 is an caching and authoritative server used for testing unusual
server behaviors such as disabled DNSSEC algorithms.

ns7 is used for checking non-cacheable answers.

ns8 is a caching-only server, configured with unsupported and disabled
algorithms.  It is used for testing failure cases.

ns9 is a forwarding-only server.