]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
Don't verify the zone when setting expire to "now+1s" as it can fail
authorMark Andrews <marka@isc.org>
Wed, 8 Jul 2020 03:18:31 +0000 (13:18 +1000)
committerMark Andrews <marka@isc.org>
Mon, 13 Jul 2020 02:42:46 +0000 (12:42 +1000)
as too much wall clock time may have elapsed.

Also capture signzone output for forensic analysis

(cherry picked from commit a0e8a11cc6f61ec5f16370cfd9888e5758a3f391)

bin/tests/system/statschannel/clean.sh
bin/tests/system/statschannel/ns2/sign.sh

index 4904d91e43dfc5413def331e054295e0d8a6b6ca..bf5d3b397719e1b70aeb688090c3161f691b4866 100644 (file)
@@ -9,21 +9,22 @@
 # See the COPYRIGHT file distributed with this work for additional
 # information regarding copyright ownership.
 
-rm -f traffic traffic.out.* traffic.json.* traffic.xml.*
-rm -f zones zones.out.* zones.json.* zones.xml.* zones.expect.*
+rm -f compressed.headers regular.headers compressed.out regular.out
 rm -f dig.out*
-rm -f ns*/named.memstats
+rm -f ns*/managed-keys.bind*
 rm -f ns*/named.conf
-rm -f ns*/named.run*
 rm -f ns*/named.lock
+rm -f ns*/named.memstats
+rm -f ns*/named.run*
 rm -f ns*/named.stats
-rm -f xml.*stats json.*stats
-rm -f xml.*mem json.*mem
-rm -f compressed.headers regular.headers compressed.out regular.out
-rm -f ns*/managed-keys.bind*
+rm -f ns*/signzone.out.*
+rm -f ns2/*.db.signed* ns2/dsset-*. ns2/*.jbk
 rm -f ns2/Kdnssec* ns2/dnssec.*.id
 rm -f ns2/Kmanykeys* ns2/manykeys.*.id
-rm -f ns2/*.db.signed* ns2/dsset-*. ns2/*.jbk
 rm -f ns2/dnssec.db.signed* ns2/dsset-dnssec.
 rm -f ns3/*.db
+rm -f traffic traffic.out.* traffic.json.* traffic.xml.*
+rm -f xml.*mem json.*mem
+rm -f xml.*stats json.*stats
+rm -f zones zones.out.* zones.json.* zones.xml.* zones.expect.*
 rm -rf ./.cache ./__pycache__
index 669adec3ec0846413e39639052dc11235d4f7ca3..f772c0f2b15d289773bcfe77ad5ab776e60ef468 100644 (file)
@@ -20,7 +20,7 @@ zonefile=dnssec.db.signed
 ksk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" -f KSK "$zone")
 zsk=$("$KEYGEN" -q -a "$DEFAULT_ALGORITHM" -b "$DEFAULT_BITS" "$zone")
 # Sign deliberately with a very short expiration date.
-"$SIGNER" -S -x -O full -e "now"+1s -o "$zone" -f "$zonefile" "$infile" > /dev/null 2>&1
+"$SIGNER" -P -S -x -O full -e "now"+1s -o "$zone" -f "$zonefile" "$infile" > "signzone.out.$zone" 2>&1
 keyfile_to_key_id "$ksk" > dnssec.ksk.id
 keyfile_to_key_id "$zsk" > dnssec.zsk.id
 
@@ -34,7 +34,7 @@ zsk13=$("$KEYGEN" -q -a ECDSAP256SHA256 -b 256 "$zone")
 ksk14=$("$KEYGEN" -q -a ECDSAP384SHA384 -b 384 -f KSK "$zone")
 zsk14=$("$KEYGEN" -q -a ECDSAP384SHA384 -b 384 "$zone")
 # Sign deliberately with a very short expiration date.
-"$SIGNER" -S -x -O full -e "now"+1s -o "$zone" -f "$zonefile" "$infile" > /dev/null 2>&1
+"$SIGNER" -S -x -O full -e "now"+1s -o "$zone" -f "$zonefile" "$infile" > "signzone.out.$zone" 2>&1
 keyfile_to_key_id "$ksk8" > manykeys.ksk8.id
 keyfile_to_key_id "$zsk8" > manykeys.zsk8.id
 keyfile_to_key_id "$ksk13" > manykeys.ksk13.id