// NS9 options { query-source address 10.53.0.9; notify-source 10.53.0.9; transfer-source 10.53.0.9; port @PORT@; pid-file "named.pid"; listen-on { 10.53.0.9; }; listen-on-v6 { none; }; allow-transfer { any; }; recursion no; }; key rndc_key { secret "1234abcd8765"; algorithm hmac-sha256; }; controls { inet 10.53.0.9 port @CONTROLPORT@ allow { any; } keys { rndc_key; }; }; parental-agents "ns2" port @PORT@ { 10.53.0.2; }; zone "." { type hint; file "../../common/root.hint"; }; /* * Zone with parental agent configured, due for DS checking. */ zone "dspublished.checkds" { type primary; file "dspublished.checkds.db"; dnssec-policy "default"; parental-agents { 10.53.0.2 port @PORT@; }; }; /* * Zone with parental agent configured, due for DS checking. * Same as above, but now with a reference to parental-agents. */ zone "reference.checkds" { type primary; file "reference.checkds.db"; dnssec-policy "default"; parental-agents { "ns2"; }; }; /* * Zone with parental agent configured, due for DS checking. * The parental agent does not have the DS yet. */ zone "missing-dspublished.checkds" { type primary; file "missing-dspublished.checkds.db"; dnssec-policy "default"; parental-agents { 10.53.0.5 port @PORT@; // missing }; }; /* * Zone with parental agent configured, due for DS checking. * This case, the server is badly configured. */ zone "bad-dspublished.checkds" { type primary; file "bad-dspublished.checkds.db"; dnssec-policy "default"; parental-agents { 10.53.0.6 port @PORT@; // bad }; }; /* * Zone with multiple parental agents configured, due for DS checking. * All need to have the DS before the rollover may continue. */ zone "multiple-dspublished.checkds" { type primary; file "multiple-dspublished.checkds.db"; dnssec-policy "default"; parental-agents { 10.53.0.2 port @PORT@; 10.53.0.4 port @PORT@; }; }; /* * Zone with multiple parental agents configured, due for DS checking. * All need to have the DS before the rollover may continue. * This case, one server is still missing the DS. */ zone "incomplete-dspublished.checkds" { type primary; file "incomplete-dspublished.checkds.db"; dnssec-policy "default"; parental-agents { 10.53.0.2 port @PORT@; 10.53.0.4 port @PORT@; 10.53.0.5 port @PORT@; // missing }; }; /* * Zone with multiple parental agents configured, due for DS checking. * All need to have the DS before the rollover may continue. * This case, one server is badly configured. */ zone "bad2-dspublished.checkds" { type primary; file "bad2-dspublished.checkds.db"; dnssec-policy "default"; parental-agents { 10.53.0.2 port @PORT@; 10.53.0.4 port @PORT@; 10.53.0.6 port @PORT@; // bad }; }; // TODO: Other test cases: // - Test with bogus response // - check with TSIG // - check with TLS /* * Zones that are going insecure (test DS withdrawn polling). */ zone "dswithdrawn.checkds" { type primary; file "dswithdrawn.checkds.db"; dnssec-policy "insecure"; parental-agents { 10.53.0.5 port @PORT@; }; }; zone "missing-dswithdrawn.checkds" { type primary; file "missing-dswithdrawn.checkds.db"; dnssec-policy "insecure"; parental-agents { 10.53.0.2 port @PORT@; // still published }; }; zone "bad-dswithdrawn.checkds" { type primary; file "bad-dswithdrawn.checkds.db"; dnssec-policy "insecure"; parental-agents { 10.53.0.6 port @PORT@; // bad }; }; zone "multiple-dswithdrawn.checkds" { type primary; file "multiple-dswithdrawn.checkds.db"; dnssec-policy "insecure"; parental-agents { 10.53.0.5 port @PORT@; 10.53.0.7 port @PORT@; }; }; zone "incomplete-dswithdrawn.checkds" { type primary; file "incomplete-dswithdrawn.checkds.db"; dnssec-policy "insecure"; parental-agents { 10.53.0.2 port @PORT@; // still published 10.53.0.5 port @PORT@; 10.53.0.7 port @PORT@; }; }; zone "bad2-dswithdrawn.checkds" { type primary; file "bad2-dswithdrawn.checkds.db"; dnssec-policy "insecure"; parental-agents { 10.53.0.5 port @PORT@; 10.53.0.7 port @PORT@; 10.53.0.6 port @PORT@; // bad }; };