Libor Peltan
f884b63c9e
tests: added max TTL test with signing and incremental realod
2024-12-19 09:57:08 +01:00
David Vašek
5238477dcb
tests-extra: zone/expire -- fix a typo
2024-12-18 09:35:12 +01:00
Libor Peltan
1c8518a337
tests: compatibility with new Bind9
2024-11-25 10:15:45 +01:00
Daniel Salzman
1ffe8d5db9
zone: don't purge times.catalog_member if still a member zone
2024-11-22 13:02:13 +01:00
Jan Hák
556a19cf07
knotd: expiration aborts transaction in progress
2024-11-18 15:55:49 +01:00
Libor Peltan
d6c68c9d41
nameserver: add check for \0 bytes in QNAME labels and respond it as NXDOMAIN ...
...
if it doens't exactly match a node owner.
2024-11-15 08:07:25 +01:00
Daniel Salzman
edcb6b09f7
conf: change default salt length to 0
2024-11-05 15:12:49 +01:00
Daniel Salzman
3808bf265d
nameserver: add explicit check for root's DS queries
2024-10-29 14:36:43 +01:00
Jan Hák
1483e4414e
mod-cookies: secondary cookie secret
2024-10-26 15:57:22 +02:00
Libor Peltan
e4aa69fe67
tests: add XoT (XFR over TLS) interop with Bind9
2024-10-23 13:42:43 +02:00
Libor Peltan
474eb83d82
log/dnssec: warn upon every incremental if full had failed
2024-10-18 08:18:21 +02:00
Daniel Salzman
a0ad3de5e6
tests-extra: stabilize dnssec/expire
2024-10-10 10:36:49 +02:00
Daniel Salzman
4d6d4f8ece
dnssec: fix zone expiration based on EXPIRE if zone signing results in up-to-date
2024-10-07 13:19:17 +02:00
Daniel Salzman
40e188ab62
tests-extra: add test for ACL configuration
2024-09-27 12:44:40 +02:00
Libor Peltan
42f3d8522f
tests: flush before random_ddns() to ensure clean zonefile format
2024-09-12 15:04:15 +02:00
David Vašek
977851111d
tests-extra: zone/backup_lock -- check '+keysonly' backup/restore
2024-09-12 11:40:37 +02:00
Daniel Salzman
c55625adf8
Merge branch 'tests_ddns_unify' into 'master'
...
tests: all DDNS: randomize, unify and fix protocols and knsupdate usage...
See merge request knot/knot-dns!1708
2024-09-06 09:52:05 +02:00
Libor Peltan
ce059162d7
ctl/zone-status: print since when event is running/pending/frozen
2024-09-04 15:52:38 +02:00
Libor Peltan
65d2b862b3
tests: all DDNS: randomize, unify and fix protocols and knsupdate usage...
...
...also in interference with XDP
2024-09-04 15:50:32 +02:00
David Vašek
e9c162bc34
tests-extra: modules/dnsproxy -- avoid possible random-zone name collisions as subzones
2024-09-03 21:45:02 +02:00
Libor Peltan
4468af58dd
ctl: implemented multi-threaded (mutexted) CTL handling
2024-09-01 18:35:17 +02:00
Daniel Salzman
ed4dc0c905
dnsproxy: fix TSIG handling
2024-08-24 15:39:30 +02:00
Libor Peltan
611130e3e8
tests: duplicit overlapping pregenerate doesnt leave excess ZSKs
2024-08-22 11:14:27 +02:00
Daniel Salzman
0df70dbdf9
tests-extra: enable logging in module/rrl
2024-08-11 21:19:40 +02:00
Libor Peltan
b0a5665ee2
tests/ddns: disable XDP if QUIC as it's the same port and DDNS won't work
2024-08-06 18:20:51 +02:00
Libor Peltan
60c906ca78
test/validate_bind: avoid updating NSs as Bind handles delegations wrong...
...
...see https://gitlab.isc.org/isc-projects/bind9/-/issues/3431
2024-08-06 11:57:56 +02:00
David Vašek
42ccc9e333
tests-extra: modules/dnsproxy -- avoid possible random-zone name collisions
2024-08-06 09:54:07 +02:00
Libor Peltan
46b621895a
test: ensure distinct random labels
2024-07-31 10:50:17 +02:00
Libor Peltan
60c5ed71b5
test: Bind9 now decreases ksk-lifetime by TWICE dnskey-ttl
2024-07-25 12:42:37 +02:00
Libor Peltan
e53e5ab39c
tests: skip Bind9 dnssec-verify for non-apex DNSKEY...
...
...as it doesnt tolerate
2024-07-25 12:06:00 +02:00
Libor Peltan
121ce227f2
test/ddns: fixed escaping of backslash
2024-07-22 11:23:36 +02:00
Daniel Salzman
14a7ba8ab3
conf: add 'zone.default-ttl` configuration option
2024-07-19 16:53:55 +02:00
Libor Peltan
6d5e8a6c72
tests: added DDNSoT by DNSKEY sync
2024-07-15 22:12:04 +02:00
Libor Peltan
f2558d243a
tests: quic/ddns hardened
2024-07-15 22:12:04 +02:00
Jan Hák
94447d17eb
tests-extra: add random knsupdate and protocol selection to some DDNS tests
2024-07-15 22:12:04 +02:00
Daniel Salzman
af767a6d24
libzscanner: add WALLET rrtype
2024-07-11 12:01:35 +02:00
Daniel Salzman
2e52cfd3b3
libzscanner: add support for 'dohpath' and 'ohttp' SVCB parameters
2024-07-11 09:21:46 +02:00
Daniel Salzman
f14e0f355e
dnssec/NSEC: remove another omitted NSEC for existing nonauthoritative node
2024-07-06 10:40:25 +02:00
Libor Peltan
a2beb2b2ff
load: dont skip dnssec+zonemd even when nothing to load
2024-07-05 10:54:01 +02:00
Libor Peltan
1492c4a9b4
tests: improved blocking_txn not to fail and test better
2024-07-04 11:21:32 +02:00
Libor Peltan
2d39009ad8
tests: fix forwarded DDNS with possible master's XDP
2024-07-02 16:31:20 +02:00
Libor Peltan
e73c2d4fd7
dnssec/NSEC: remove empty node's NSEC even when nonauth
2024-06-28 07:34:39 +02:00
Libor Peltan
7958d7ff35
journal: fix corruption when SOA serial matches some metadata name
2024-06-21 10:35:49 +02:00
David Vašek
f0db8f99d4
backup: check that the system CPU architecture and the backup data are compatible
...
Notes about the tests: many tests still relies on 64LE architecture.
This currently applies also to:
zone/backup_lock
dnssec/keytag_conflict
dnssec/no_resign
modules/geoip.
The 64BE-architecture backup is simulated by a modified 64LE backup in the test zone/backup_lock.
Test of restore of QUIC keys from incompatible architecture should be added to zone/backup_lock too.
2024-06-19 13:20:21 +02:00
David Vašek
1cdc3adf07
tests-extra: zone/backup -- fix the recently added testing
2024-06-14 19:31:27 +02:00
David Vašek
a675f90dff
backup: use the force option to overwrite an already existing backupdir
2024-06-14 17:18:30 +02:00
Libor Peltan
d90840a268
knotd: remove assert that doesnt hold in specific circmstances
2024-06-14 10:41:24 +02:00
Libor Peltan
3c9509fdd8
rcu: protect also zonefile flush and XFRout against simultaneous zone CTL update
2024-06-13 21:00:43 +02:00
Libor Peltan
8ae5d29037
purge: after purging timers, set them to sensible values
2024-06-12 11:08:03 +02:00
Daniel Salzman
1d16c453db
nameserver: add TSIG key name to event and nameserver logs
2024-06-06 09:47:53 +02:00