From: Matthijs Mekking Date: Thu, 29 Jun 2023 09:28:01 +0000 (+0200) Subject: Update zonechecks system test X-Git-Tag: v9.19.16~32^2~11 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=a4b6ff32e9255180e7357eca6ad299a5020efe45;p=thirdparty%2Fbind9.git Update zonechecks system test Change test configuration to make use of 'dnssec-policy' instead of 'auto-dnssec'. --- diff --git a/bin/tests/system/zonechecks/clean.sh b/bin/tests/system/zonechecks/clean.sh index ed4012a266a..330b242b047 100644 --- a/bin/tests/system/zonechecks/clean.sh +++ b/bin/tests/system/zonechecks/clean.sh @@ -15,7 +15,7 @@ rm -f *.out rm -f */named.memstats rm -f */named.conf rm -f */named.run -rm -f */*.db */*.db.signed */K*.key */K*.private */*.jnl */dsset-* +rm -f */*.db */*.db.signed */K*.key */K*.private */K*.state */*.jnl */dsset-* rm -f */signer.err rm -f rndc.out.* rm -f ns*/named.lock diff --git a/bin/tests/system/zonechecks/ns1/named.conf.in b/bin/tests/system/zonechecks/ns1/named.conf.in index 03bc91838c8..efb11b01d8f 100644 --- a/bin/tests/system/zonechecks/ns1/named.conf.in +++ b/bin/tests/system/zonechecks/ns1/named.conf.in @@ -35,6 +35,13 @@ controls { inet 10.53.0.1 port @CONTROLPORT@ allow { any; } keys { rndc_key; }; }; +dnssec-policy "zonechecks" { + keys { + ksk key-directory lifetime unlimited algorithm @DEFAULT_ALGORITHM@; + zsk key-directory lifetime unlimited algorithm @DEFAULT_ALGORITHM@; + }; +}; + view unused { match-clients { none; }; @@ -52,7 +59,7 @@ view primary { file "primary.db"; allow-update { any; }; allow-transfer { any; }; - auto-dnssec maintain; + dnssec-policy zonechecks; }; zone "bigserial.example" {