bind9/bin/tests/system/dnssec
Michał Kępień c6bf43a821 Make NTAs work with validating forwarders
If named is configured to perform DNSSEC validation and also forwards
all queries ("forward only;") to validating resolvers, negative trust
anchors do not work properly because the CD bit is not set in queries
sent to the forwarders.  As a result, instead of retrieving bogus DNSSEC
material and making validation decisions based on its configuration,
named is only receiving SERVFAIL responses to queries for bogus data.
Fix by ensuring the CD bit is always set in queries sent to forwarders
if the query name is covered by an NTA.

(cherry picked from commit 5e80488270)
2019-05-09 20:37:37 -07:00
..
ns1 Make NTAs work with validating forwarders 2019-05-09 20:37:37 -07:00
ns2 Simplify trailing period handling in system tests 2019-04-26 20:38:29 +02:00
ns3 Simplify trailing period handling in system tests 2019-04-26 20:38:29 +02:00
ns4 add a test case 2018-10-04 23:33:18 -07:00
ns5 Ignore trust anchors using disabled algorithm 2019-04-17 10:33:25 +02:00
ns6 Ignore trust anchors using disabled algorithm 2019-04-17 10:33:25 +02:00
ns7 Ignore trust anchors using disabled algorithm 2019-04-17 10:33:25 +02:00
ns8 Ignore trust anchors using disabled algorithm 2019-04-17 10:33:25 +02:00
ns9 Make NTAs work with validating forwarders 2019-05-09 20:37:37 -07:00
signer Remove $Id markers, Principal Author and Reviewed tags from the full source tree 2018-05-11 13:17:46 +02:00
clean.sh Ignore trust anchors using disabled algorithm 2019-04-17 10:33:25 +02:00
dnssec_update_test.pl Update license headers to not include years in copyright in all applicable files 2018-02-23 10:12:02 +01:00
ntadiff.pl Update license headers to not include years in copyright in all applicable files 2018-02-23 10:12:02 +01:00
prereq.sh Run the dnssec system tests with set -e enabled 2018-12-10 19:47:32 +01:00
README Ignore trust anchors using disabled algorithm 2019-04-17 10:33:25 +02:00
setup.sh Make NTAs work with validating forwarders 2019-05-09 20:37:37 -07:00
tests.sh Make NTAs work with validating forwarders 2019-05-09 20:37:37 -07:00

Copyright (C) Internet Systems Consortium, Inc. ("ISC")

See COPYRIGHT in the source root or http://isc.org/copyright.html for terms.

The test setup for the DNSSEC tests has a secure root.

ns1 is the root server.

ns2 and ns3 are authoritative servers for the various test domains.

ns4 is a caching-only server, configured with the correct trusted key
for the root.

ns5 is a caching-only server, configured with the an incorrect trusted
key for the root.  It is used for testing failure cases.

ns6 is a caching-only server configured to use DLV.

ns7 is used for checking non-cacheable answers.

ns8 is a caching-only server, configured with unsupported and disabled
algorithms.  It is used for testing failure cases.