bind9/bin/tests/system/masterformat
Matthijs Mekking 2f5c670ce9
Add new test cases with DNSSEC signing
kasp-max-types-per-name (named2.conf.in):
An unsigned zone with RR type count on a name right below the
configured limit. Then sign the zone using KASP. Adding a RRSIG would
push it over the RR type limit per name. Signing should fail, but
the server should not crash, nor end up in infinite resign-attempt loop.

kasp-max-records-per-type-dnskey (named1.conf.in):
Test with low max-record-per-rrset limit and a DNSSEC policy requiring
more than the limit. Signing should fail.

kasp-max-types-per-name (named1.conf.in):
Each RRSIG(covered type) is counted as an individual RR type. Test the
corner case where a signed zone, which is just below the limit-1,
adds a new type - doing so would trigger signing for the new type and
thus increase the number of "types" by 2, pushing it over the limit
again.

(cherry picked from commit 14e5230f897a178221b606c242b8fbcb357704aa)
2024-06-10 18:51:27 +02:00
..
ns1 Add new test cases with DNSSEC signing 2024-06-10 18:51:27 +02:00
ns2 Add test cases that use DNSSEC signing 2024-06-10 18:51:27 +02:00
ns3 explicitly set dnssec-validation in system tests 2023-06-26 15:03:06 -07:00
ns4 Add new test cases with DNSSEC signing 2024-06-10 18:51:27 +02:00
clean.sh Update the copyright information in all files in the repository 2022-01-11 09:05:02 +01:00
setup.sh Add new test cases with DNSSEC signing 2024-06-10 18:51:27 +02:00
tests.sh Add new test cases with DNSSEC signing 2024-06-10 18:51:27 +02:00
tests_sh_masterformat.py Add pytest functions for shell system tests 2023-05-23 16:55:26 +02:00