]>
Commit | Line | Data |
---|---|---|
89c4ed63 A |
1 | ; config options |
2 | ; The island of trust is at example.com | |
3 | server: | |
4 | trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b" | |
5 | val-override-date: "20070916134226" | |
6 | target-fetch-policy: "0 0 0 0 0" | |
7 | ||
8 | stub-zone: | |
9 | name: "." | |
10 | stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET. | |
11 | CONFIG_END | |
12 | ||
13 | SCENARIO_BEGIN Test validator with GOST DS digest downgrade attack | |
14 | ||
15 | ; K.ROOT-SERVERS.NET. | |
16 | RANGE_BEGIN 0 100 | |
17 | ADDRESS 193.0.14.129 | |
18 | ENTRY_BEGIN | |
19 | MATCH opcode qtype qname | |
20 | ADJUST copy_id | |
21 | REPLY QR NOERROR | |
22 | SECTION QUESTION | |
23 | . IN NS | |
24 | SECTION ANSWER | |
25 | . IN NS K.ROOT-SERVERS.NET. | |
26 | SECTION ADDITIONAL | |
27 | K.ROOT-SERVERS.NET. IN A 193.0.14.129 | |
28 | ENTRY_END | |
29 | ||
30 | ENTRY_BEGIN | |
31 | MATCH opcode qtype qname | |
32 | ADJUST copy_id | |
33 | REPLY QR NOERROR | |
34 | SECTION QUESTION | |
35 | www.sub.example.com. IN A | |
36 | SECTION AUTHORITY | |
37 | com. IN NS a.gtld-servers.net. | |
38 | SECTION ADDITIONAL | |
39 | a.gtld-servers.net. IN A 192.5.6.30 | |
40 | ENTRY_END | |
41 | RANGE_END | |
42 | ||
43 | ; a.gtld-servers.net. | |
44 | RANGE_BEGIN 0 100 | |
45 | ADDRESS 192.5.6.30 | |
46 | ENTRY_BEGIN | |
47 | MATCH opcode qtype qname | |
48 | ADJUST copy_id | |
49 | REPLY QR NOERROR | |
50 | SECTION QUESTION | |
51 | com. IN NS | |
52 | SECTION ANSWER | |
53 | com. IN NS a.gtld-servers.net. | |
54 | SECTION ADDITIONAL | |
55 | a.gtld-servers.net. IN A 192.5.6.30 | |
56 | ENTRY_END | |
57 | ||
58 | ENTRY_BEGIN | |
59 | MATCH opcode subdomain | |
60 | ADJUST copy_id copy_query | |
61 | REPLY QR NOERROR | |
62 | SECTION QUESTION | |
63 | example.com. IN A | |
64 | SECTION AUTHORITY | |
65 | example.com. IN NS ns.example.com. | |
66 | SECTION ADDITIONAL | |
67 | ns.example.com. IN A 1.2.3.4 | |
68 | ENTRY_END | |
69 | RANGE_END | |
70 | ||
71 | ; ns.example.com. | |
72 | RANGE_BEGIN 0 100 | |
73 | ADDRESS 1.2.3.4 | |
74 | ENTRY_BEGIN | |
75 | MATCH opcode qtype qname | |
76 | ADJUST copy_id | |
77 | REPLY QR AA REFUSED | |
78 | SECTION QUESTION | |
79 | ns.example.com. IN AAAA | |
80 | ENTRY_END | |
81 | ||
82 | ENTRY_BEGIN | |
83 | MATCH opcode qtype qname | |
84 | ADJUST copy_id | |
85 | REPLY QR NOERROR | |
86 | SECTION QUESTION | |
87 | example.com. IN NS | |
88 | SECTION ANSWER | |
89 | example.com. IN NS ns.example.com. | |
90 | example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854} | |
91 | SECTION ADDITIONAL | |
92 | ns.example.com. IN A 1.2.3.4 | |
93 | ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854} | |
94 | ENTRY_END | |
95 | ||
96 | ; response to DNSKEY priming query | |
97 | ENTRY_BEGIN | |
98 | MATCH opcode qtype qname | |
99 | ADJUST copy_id | |
100 | REPLY QR NOERROR | |
101 | SECTION QUESTION | |
102 | example.com. IN DNSKEY | |
103 | SECTION ANSWER | |
104 | example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b} | |
105 | example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854} | |
106 | SECTION AUTHORITY | |
107 | example.com. IN NS ns.example.com. | |
108 | example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854} | |
109 | SECTION ADDITIONAL | |
110 | ns.example.com. IN A 1.2.3.4 | |
111 | ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854} | |
112 | ENTRY_END | |
113 | ||
114 | ; response for delegation to sub.example.com. | |
115 | ENTRY_BEGIN | |
116 | MATCH opcode subdomain | |
117 | ADJUST copy_id copy_query | |
118 | REPLY QR NOERROR | |
119 | SECTION QUESTION | |
120 | sub.example.com. IN A | |
121 | SECTION ANSWER | |
122 | SECTION AUTHORITY | |
123 | sub.example.com. IN NS ns.sub.example.com. | |
124 | ||
125 | ; downgrade: false GOST, correct SHA | |
126 | ||
127 | ||
128 | sub.example.com. 3600 IN DS 60385 12 3 2be04f63b3d069fd65f81a3b810b661a00d39be3ff00d1c7481a150b93b0d028 | |
129 | ||
130 | ; correct GOST DS for sub.example.com. | |
131 | ; sub.example.com. 3600 IN DS 60385 12 3 2be04f63b3d069fd65f81a3b810b661a00d39be3ff00d1c7481a150b93b0d027 ; xepov-bofek-fuset-bipiz-tunoz-mukyf-rybyb-ranic-pobet-fakov-fozob-bagus-ludac-pyheb-rygor-bygyd-lyxyx | |
132 | ||
133 | ; SHA1 DS for sub.example.com. | |
134 | sub.example.com. 3600 IN DS 60385 12 1 0a66f7923318bb1e208bfd975ffa2e30cfcdf962 ; xedik-katin-dasec-myvic-vumum-rizan-luluz-paraf-befas-tovek-dyxax | |
135 | ; SHA256 DS for sub.example.com. | |
136 | sub.example.com. 3600 IN DS 60385 12 2 cd3290b84b457d02ca29846a005a5eba61640256ced8deca0ef8345d2cd34a58 ; xufef-dugir-modog-hyzyb-dadod-nicuk-pubyh-polor-pomuk-gobuh-kufet-mulus-pofyz-metoh-tarit-fudih-moxex | |
137 | ||
138 | ; signs SHA1, SHA2 and GOST DSes | |
139 | sub.example.com. 3600 IN RRSIG DS 3 3 3600 20070926135752 20070829135752 2854 example.com. ADB1PPtGoPKRrhNtRtkqeqpgnZdbPOdJMgjdZVxPfgGCoMTu3JFQVbo= ;{id = 2854} | |
140 | ||
141 | SECTION ADDITIONAL | |
142 | ns.sub.example.com. IN A 1.2.3.6 | |
143 | ENTRY_END | |
144 | ||
145 | RANGE_END | |
146 | ||
147 | ; ns.sub.example.com. | |
148 | RANGE_BEGIN 0 100 | |
149 | ADDRESS 1.2.3.6 | |
150 | ENTRY_BEGIN | |
151 | MATCH opcode qtype qname | |
152 | ADJUST copy_id | |
153 | REPLY QR NOERROR | |
154 | SECTION QUESTION | |
155 | sub.example.com. IN NS | |
156 | SECTION ANSWER | |
157 | sub.example.com. IN NS ns.sub.example.com. | |
158 | sub.example.com. 3600 IN RRSIG NS 12 3 3600 20070926134150 20070829134150 60385 sub.example.com. 6mNrX32/DC2RU1A+yWCccn5H6wnsbNYTlf8e/LyF1fsuNfw6tH12sKGBCtk1mp4HpDIgH02HDHplJskSFOvzTw== ;{id = 60385} | |
159 | ||
160 | SECTION ADDITIONAL | |
161 | ns.sub.example.com. IN A 1.2.3.6 | |
162 | ns.sub.example.com. 3600 IN RRSIG A 12 4 3600 20070926134150 20070829134150 60385 sub.example.com. kJEyinL7BkpiPW2HxmFHRLAi68EdrLXToJiK83a5cedDe5ABL7c/k+nFHd3WjATUtVoueY3pSnCDVCJaFmd+/A== ;{id = 60385} | |
163 | ENTRY_END | |
164 | ||
165 | ENTRY_BEGIN | |
166 | MATCH opcode qtype qname | |
167 | ADJUST copy_id | |
168 | REPLY QR AA NOERROR | |
169 | SECTION QUESTION | |
170 | ns.sub.example.com. IN A | |
171 | SECTION ANSWER | |
172 | ns.sub.example.com. IN A 1.2.3.6 | |
173 | ns.sub.example.com. 3600 IN RRSIG A 12 4 3600 20070926134150 20070829134150 60385 sub.example.com. kJEyinL7BkpiPW2HxmFHRLAi68EdrLXToJiK83a5cedDe5ABL7c/k+nFHd3WjATUtVoueY3pSnCDVCJaFmd+/A== ;{id = 60385} | |
174 | SECTION AUTHORITY | |
175 | sub.example.com. IN NS ns.sub.example.com. | |
176 | sub.example.com. 3600 IN RRSIG NS 12 3 3600 20070926134150 20070829134150 60385 sub.example.com. 6mNrX32/DC2RU1A+yWCccn5H6wnsbNYTlf8e/LyF1fsuNfw6tH12sKGBCtk1mp4HpDIgH02HDHplJskSFOvzTw== ;{id = 60385} | |
177 | ENTRY_END | |
178 | ||
179 | ; response to DNSKEY priming query | |
180 | ENTRY_BEGIN | |
181 | MATCH opcode qtype qname | |
182 | ADJUST copy_id | |
183 | REPLY QR NOERROR | |
184 | SECTION QUESTION | |
185 | sub.example.com. IN DNSKEY | |
186 | SECTION ANSWER | |
187 | sub.example.com. 3600 IN DNSKEY 256 3 12 9SZY+xB3wKtrLoRHzkBs9L3fjcvazjnk5HF3gMaD1PVp4pthrwgHIm0TUaLrd3YCa2VCl5wj+MzbhZi8NEJ/Cg== ;{id = 60385 (zsk), size = 512b} | |
188 | sub.example.com. 3600 IN RRSIG DNSKEY 12 3 3600 20070926134150 20070829134150 60385 sub.example.com. zyZCppfMjlMS9xs3pJfbWkdA6EgV5MqI11AdVRV8pBsyI7diYLWm8RAHlhEI5MT59A6IT6Di9YjOCvWJjzZ9tA== ;{id = 60385} | |
189 | SECTION AUTHORITY | |
190 | sub.example.com. IN NS ns.sub.example.com. | |
191 | sub.example.com. 3600 IN RRSIG NS 12 3 3600 20070926134150 20070829134150 60385 sub.example.com. 6mNrX32/DC2RU1A+yWCccn5H6wnsbNYTlf8e/LyF1fsuNfw6tH12sKGBCtk1mp4HpDIgH02HDHplJskSFOvzTw== ;{id = 60385} | |
192 | SECTION ADDITIONAL | |
193 | ns.sub.example.com. IN A 1.2.3.6 | |
194 | ns.sub.example.com. 3600 IN RRSIG A 12 4 3600 20070926134150 20070829134150 60385 sub.example.com. kJEyinL7BkpiPW2HxmFHRLAi68EdrLXToJiK83a5cedDe5ABL7c/k+nFHd3WjATUtVoueY3pSnCDVCJaFmd+/A== ;{id = 60385} | |
195 | ENTRY_END | |
196 | ||
197 | ; response to query of interest | |
198 | ENTRY_BEGIN | |
199 | MATCH opcode qtype qname | |
200 | ADJUST copy_id | |
201 | REPLY QR NOERROR | |
202 | SECTION QUESTION | |
203 | www.sub.example.com. IN A | |
204 | SECTION ANSWER | |
205 | www.sub.example.com. IN A 11.11.11.11 | |
206 | www.sub.example.com. 3600 IN RRSIG A 12 4 3600 20070926134150 20070829134150 60385 sub.example.com. KVDpNBH83UM8l1e9yAdXA1fV+wFJSJF4NtOnDLTtbpfyVbndNW3tvPc2YfLBxTEZeUCns2QrqcmIMdZ086frOQ== ;{id = 60385} | |
207 | ||
208 | SECTION AUTHORITY | |
209 | SECTION ADDITIONAL | |
210 | ENTRY_END | |
211 | ||
212 | ENTRY_BEGIN | |
213 | MATCH opcode qtype qname | |
214 | ADJUST copy_id | |
215 | REPLY QR AA REFUSED | |
216 | SECTION QUESTION | |
217 | ns.sub.example.com. IN AAAA | |
218 | ENTRY_END | |
219 | ||
220 | RANGE_END | |
221 | ||
222 | STEP 1 QUERY | |
223 | ENTRY_BEGIN | |
224 | REPLY RD DO | |
225 | SECTION QUESTION | |
226 | www.sub.example.com. IN A | |
227 | ENTRY_END | |
228 | ||
229 | ; recursion happens here. | |
230 | ; must servfail bogus | |
231 | STEP 10 CHECK_ANSWER | |
232 | ENTRY_BEGIN | |
233 | MATCH all | |
234 | REPLY QR RD RA DO SERVFAIL | |
235 | SECTION QUESTION | |
236 | www.sub.example.com. IN A | |
237 | SECTION ANSWER | |
238 | ;www.sub.example.com. 3600 IN A 11.11.11.11 | |
239 | ;www.sub.example.com. 3600 IN RRSIG A 12 4 3600 20070926134150 20070829134150 60385 sub.example.com. KVDpNBH83UM8l1e9yAdXA1fV+wFJSJF4NtOnDLTtbpfyVbndNW3tvPc2YfLBxTEZeUCns2QrqcmIMdZ086frOQ== ;{id = 60385} | |
240 | SECTION AUTHORITY | |
241 | SECTION ADDITIONAL | |
242 | ENTRY_END | |
243 | ||
244 | SCENARIO_END |