]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
Add check calls to kasp zsk-retired test
authorMatthijs Mekking <matthijs@isc.org>
Mon, 9 Mar 2020 09:38:58 +0000 (10:38 +0100)
committerMatthijs Mekking <matthijs@isc.org>
Mon, 9 Mar 2020 12:02:23 +0000 (13:02 +0100)
The test case for zsk-retired was missing the actual checks.  Add
them and fix the set_policy call to expect three keys.

bin/tests/system/kasp/tests.sh

index 0b5c8d0dfe96df9f11af0b29b1c2a798eb73dcdc..30b82679a3bf6859f390d477cb83842b4ad78e53 100644 (file)
@@ -1597,7 +1597,7 @@ set_server "ns3" "10.53.0.3"
 # Zone: zsk-retired.autosign.
 #
 set_zone "zsk-retired.autosign"
-set_policy "autosign" "2" "300"
+set_policy "autosign" "3" "300"
 set_server "ns3" "10.53.0.3"
 # The third key is not yet expected to be signing.
 set_keyrole      "KEY3" "zsk"
@@ -1620,6 +1620,12 @@ set_keystate "KEY3" "GOAL"         "omnipresent"
 set_keystate "KEY3" "STATE_DNSKEY" "rumoured"
 set_keystate "KEY3" "STATE_ZRRSIG" "hidden"
 
+check_keys
+check_apex
+check_subdomain
+dnssec_verify
+check_rrsig_refresh
+
 #
 # Test dnssec-policy inheritance.
 #