]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
Fix kasp system test
authorMatthijs Mekking <matthijs@isc.org>
Tue, 30 Jul 2024 12:32:31 +0000 (14:32 +0200)
committerMatthijs Mekking <matthijs@isc.org>
Tue, 30 Jul 2024 13:57:28 +0000 (15:57 +0200)
In 9.18, 'inline-signing yes;' must also be configured explicitly for
zones using dnssec-policy without a configured 'allow-update' or
'update-policy'.

bin/tests/system/kasp/ns6/named.conf.in
bin/tests/system/kasp/ns6/named2.conf.in

index f30445ba27463801a840af41715541d9739bbaa3..019893c96e4fc642d50d066ab7f758e00829eedf 100644 (file)
@@ -99,23 +99,27 @@ zone example {
 zone longer-lifetime {
        type primary;
        file "longer-lifetime.db";
+       inline-signing yes;
        dnssec-policy short-lifetime;
 };
 
 zone shorter-lifetime {
        type primary;
        file "shorter-lifetime.db";
+       inline-signing yes;
        dnssec-policy long-lifetime;
 };
 
 zone limit-lifetime {
        type primary;
        file "limit-lifetime.db";
+       inline-signing yes;
        dnssec-policy unlimited-lifetime;
 };
 
 zone unlimit-lifetime {
        type primary;
        file "unlimit-lifetime.db";
+       inline-signing yes;
        dnssec-policy short-lifetime;
 };
index fac2524e04bd921dea392f4157a833ac1977163f..3762688bddce746c4831cdce9db4bcbc62314fab 100644 (file)
@@ -187,23 +187,27 @@ zone example {
 zone longer-lifetime {
        type primary;
        file "longer-lifetime.db";
+       inline-signing yes;
        dnssec-policy long-lifetime;
 };
 
 zone shorter-lifetime {
        type primary;
        file "shorter-lifetime.db";
+       inline-signing yes;
        dnssec-policy short-lifetime;
 };
 
 zone limit-lifetime {
        type primary;
        file "limit-lifetime.db";
+       inline-signing yes;
        dnssec-policy short-lifetime;
 };
 
 zone unlimit-lifetime {
        type primary;
        file "unlimit-lifetime.db";
+       inline-signing yes;
        dnssec-policy unlimited-lifetime;
 };