]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
Update zonechecks system test
authorMatthijs Mekking <matthijs@isc.org>
Thu, 29 Jun 2023 09:28:01 +0000 (11:28 +0200)
committerMatthijs Mekking <matthijs@isc.org>
Thu, 20 Jul 2023 09:04:23 +0000 (11:04 +0200)
Change test configuration to make use of 'dnssec-policy' instead of
'auto-dnssec'.

bin/tests/system/zonechecks/clean.sh
bin/tests/system/zonechecks/ns1/named.conf.in

index ed4012a266a467c4944bdf09d19340559e930f53..330b242b047c67b63b5d09ecfb05424f7a3d7c9c 100644 (file)
@@ -15,7 +15,7 @@ rm -f *.out
 rm -f */named.memstats
 rm -f */named.conf
 rm -f */named.run
-rm -f */*.db */*.db.signed */K*.key */K*.private */*.jnl */dsset-*
+rm -f */*.db */*.db.signed */K*.key */K*.private */K*.state */*.jnl */dsset-*
 rm -f */signer.err
 rm -f rndc.out.*
 rm -f ns*/named.lock
index 03bc91838c865d2ca604b495189b5a7e0dc98f0e..efb11b01d8fab513fd3dd384f942a6d29b868977 100644 (file)
@@ -35,6 +35,13 @@ controls {
        inet 10.53.0.1 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
 };
 
+dnssec-policy "zonechecks" {
+       keys {
+               ksk key-directory lifetime unlimited algorithm @DEFAULT_ALGORITHM@;
+               zsk key-directory lifetime unlimited algorithm @DEFAULT_ALGORITHM@;
+       };
+};
+
 view unused {
        match-clients { none; };
 
@@ -52,7 +59,7 @@ view primary {
                file "primary.db";
                allow-update { any; };
                allow-transfer { any; };
-               auto-dnssec maintain;
+               dnssec-policy zonechecks;
        };
 
        zone "bigserial.example" {