bind9/bin/tests/system/dnssec
Matthijs Mekking 35efbc270f Add test for dnssec-signzone smooth ZSK roll
Add a test case to the dnssec system test to check that:
- a zone with a prepublished key is only signed with the active key.
- a zone with an inactive key but valid signatures retains those
  signatures and does not add signatures from successor key.
- signatures are swapped in a zone when signatures of predecessor
  inactive key are within the refresh interval.
2021-08-11 15:15:25 +02:00
..
ans10 Check that a zone in the process of being signed resolves 2020-10-30 00:17:24 +11:00
ns1 Check that excessive iterations in logged by named when 2021-04-29 17:18:26 +10:00
ns2 Check that excessive iterations in logged by named when 2021-04-29 17:18:26 +10:00
ns3 Check that excessive iterations in logged by named when 2021-04-29 17:18:26 +10:00
ns4 Check that excessive iterations in logged by named when 2021-04-29 17:18:26 +10:00
ns5 update all copyright headers to eliminate the typo 2020-09-14 16:20:40 -07:00
ns6 Remove ISC_MEM_DEBUGSIZE and ISC_MEM_DEBUGRECORD 2021-07-09 15:58:02 +02:00
ns7 Test handling of non-apex RRSIG(SOA) RRsets 2021-04-23 14:26:48 +02:00
ns8 add "static-ds" and "initial-ds" keywords to config parser 2019-11-15 15:47:17 -08:00
ns9 add "static-ds" and "initial-ds" keywords to config parser 2019-11-15 15:47:17 -08:00
signer dnssec-signzone ZSK smooth rollover 2021-08-11 15:15:25 +02:00
clean.sh Check that excessive iterations in logged by named when 2021-04-29 17:18:26 +10:00
dnssec_update_test.pl update all copyright headers to eliminate the typo 2020-09-14 16:20:40 -07:00
ntadiff.pl update all copyright headers to eliminate the typo 2020-09-14 16:20:40 -07:00
README update all copyright headers to eliminate the typo 2020-09-14 16:20:40 -07:00
setup.sh update all copyright headers to eliminate the typo 2020-09-14 16:20:40 -07:00
tests.sh Add test for dnssec-signzone smooth ZSK roll 2021-08-11 15:15:25 +02:00

Copyright (C) Internet Systems Consortium, Inc. ("ISC")

See COPYRIGHT in the source root or https://isc.org/copyright.html for terms.

The test setup for the DNSSEC tests has a secure root.

ns1 is the root server.

ns2 and ns3 are authoritative servers for the various test domains.

ns4 is a caching-only server, configured with the correct trusted key
for the root.

ns5 is a caching-only server, configured with the an incorrect trusted
key for the root.  It is used for testing failure cases.

ns6 is an caching and authoritative server used for testing unusual
server behaviors such as disabled DNSSEC algorithms.

ns7 is used for checking non-cacheable answers.

ns8 is a caching-only server, configured with unsupported and disabled
algorithms.  It is used for testing failure cases.

ns9 is a forwarding-only server.