bind9/bin/tests/system/kasp
Matthijs Mekking 68f0fc6309 Force set DS state after 'rndc dnssec -checkds'
Set the DS state after issuing 'rndc dnssec -checkds'. If the DS
was published, it should go in RUMOURED state, regardless whether it
is already safe to do so according to the state machine.

Leaving it in HIDDEN (or if it was magically already in OMNIPRESENT or
UNRETENTIVE) would allow for easy shoot in the foot situations.

Similar, if the DS was withdrawn, the state should be set to
UNRETENTIVE. Leaving it in OMNIPRESENT (or RUMOURED/HIDDEN)
would also allow for easy shoot in the foot situations.

(cherry picked from commit ee42f66fbe)
2023-01-30 09:27:38 +01:00
..
ns2 Update system tests 2022-09-06 09:55:06 +02:00
ns3 Update kasp system test to work with .signed files 2022-11-03 11:42:44 +01:00
ns4 Update system tests 2022-09-06 09:55:06 +02:00
ns5 Update system tests 2022-09-06 09:55:06 +02:00
ns6 Update kasp system test to work with .signed files 2022-11-03 11:42:44 +01:00
clean.sh Update kasp system test to work with .signed files 2022-11-03 11:42:44 +01:00
kasp.conf kasp: stop using RSASHA1 unless necessary for the test 2022-08-10 17:26:29 +10:00
README Update the copyright information in all files in the repository 2022-01-11 09:05:02 +01:00
setup.sh kasp: stop using RSASHA1 unless necessary for the test 2022-08-10 17:26:29 +10:00
tests.sh Force set DS state after 'rndc dnssec -checkds' 2023-01-30 09:27:38 +01:00

Copyright (C) Internet Systems Consortium, Inc. ("ISC")

SPDX-License-Identifier: MPL-2.0

This Source Code Form is subject to the terms of the Mozilla Public
License, v. 2.0.  If a copy of the MPL was not distributed with this
file, you can obtain one at https://mozilla.org/MPL/2.0/.

See the COPYRIGHT file distributed with this work for additional
information regarding copyright ownership.

The test setup for the KASP tests.

ns1 is reserved for the root server.

ns2 is running primary service for ns3.

ns3 is an authoritative server for the various test domains.

ns4 and ns5 are authoritative servers for various test domains related to views.

ns6 is an authoritative server that tests changes in dnssec-policy (algorithm
rollover).