]>
Commit | Line | Data |
---|---|---|
89c4ed63 A |
1 | ; config options |
2 | ; The island of trust is at example.com | |
3 | server: | |
4 | trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b" | |
5 | val-override-date: "20070916134226" | |
6 | target-fetch-policy: "0 0 0 0 0" | |
7 | ||
8 | stub-zone: | |
9 | name: "." | |
10 | stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET. | |
11 | CONFIG_END | |
12 | ||
13 | SCENARIO_BEGIN Test validator with NSEC3 with no DS referral with bad signature. | |
14 | ||
15 | ; K.ROOT-SERVERS.NET. | |
16 | RANGE_BEGIN 0 100 | |
17 | ADDRESS 193.0.14.129 | |
18 | ENTRY_BEGIN | |
19 | MATCH opcode qtype qname | |
20 | ADJUST copy_id | |
21 | REPLY QR NOERROR | |
22 | SECTION QUESTION | |
23 | . IN NS | |
24 | SECTION ANSWER | |
25 | . IN NS K.ROOT-SERVERS.NET. | |
26 | SECTION ADDITIONAL | |
27 | K.ROOT-SERVERS.NET. IN A 193.0.14.129 | |
28 | ENTRY_END | |
29 | ||
30 | ENTRY_BEGIN | |
31 | MATCH opcode subdomain | |
32 | ADJUST copy_id copy_query | |
33 | REPLY QR NOERROR | |
34 | SECTION QUESTION | |
35 | com. IN A | |
36 | SECTION AUTHORITY | |
37 | com. IN NS a.gtld-servers.net. | |
38 | SECTION ADDITIONAL | |
39 | a.gtld-servers.net. IN A 192.5.6.30 | |
40 | ENTRY_END | |
41 | RANGE_END | |
42 | ||
43 | ; a.gtld-servers.net. | |
44 | RANGE_BEGIN 0 100 | |
45 | ADDRESS 192.5.6.30 | |
46 | ENTRY_BEGIN | |
47 | MATCH opcode qtype qname | |
48 | ADJUST copy_id | |
49 | REPLY QR NOERROR | |
50 | SECTION QUESTION | |
51 | com. IN NS | |
52 | SECTION ANSWER | |
53 | com. IN NS a.gtld-servers.net. | |
54 | SECTION ADDITIONAL | |
55 | a.gtld-servers.net. IN A 192.5.6.30 | |
56 | ENTRY_END | |
57 | ||
58 | ENTRY_BEGIN | |
59 | MATCH opcode subdomain | |
60 | ADJUST copy_id copy_query | |
61 | REPLY QR NOERROR | |
62 | SECTION QUESTION | |
63 | example.com. IN A | |
64 | SECTION AUTHORITY | |
65 | example.com. IN NS ns.example.com. | |
66 | SECTION ADDITIONAL | |
67 | ns.example.com. IN A 1.2.3.4 | |
68 | ENTRY_END | |
69 | RANGE_END | |
70 | ||
71 | ; ns.example.com. | |
72 | RANGE_BEGIN 0 100 | |
73 | ADDRESS 1.2.3.4 | |
74 | ENTRY_BEGIN | |
75 | MATCH opcode qtype qname | |
76 | ADJUST copy_id | |
77 | REPLY QR AA REFUSED | |
78 | SECTION QUESTION | |
79 | ns.example.com. IN A | |
80 | ENTRY_END | |
81 | ||
82 | ENTRY_BEGIN | |
83 | MATCH opcode qtype qname | |
84 | ADJUST copy_id | |
85 | REPLY QR AA REFUSED | |
86 | SECTION QUESTION | |
87 | ns.example.com. IN AAAA | |
88 | ENTRY_END | |
89 | ||
90 | ENTRY_BEGIN | |
91 | MATCH opcode qtype qname | |
92 | ADJUST copy_id | |
93 | REPLY QR NOERROR | |
94 | SECTION QUESTION | |
95 | example.com. IN NS | |
96 | SECTION ANSWER | |
97 | example.com. IN NS ns.example.com. | |
98 | example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854} | |
99 | SECTION ADDITIONAL | |
100 | ns.example.com. IN A 1.2.3.4 | |
101 | ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854} | |
102 | ENTRY_END | |
103 | ||
104 | ; response to DNSKEY priming query | |
105 | ENTRY_BEGIN | |
106 | MATCH opcode qtype qname | |
107 | ADJUST copy_id | |
108 | REPLY QR NOERROR | |
109 | SECTION QUESTION | |
110 | example.com. IN DNSKEY | |
111 | SECTION ANSWER | |
112 | example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b} | |
113 | example.com. 3600 IN RRSIG DNSKEY 3 2 3600 20070926134802 20070829134802 2854 example.com. MCwCFG1yhRNtTEa3Eno2zhVVuy2EJX3wAhQeLyUp6+UXcpC5qGNu9tkrTEgPUg== ;{id = 2854} | |
114 | SECTION AUTHORITY | |
115 | example.com. IN NS ns.example.com. | |
116 | example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854} | |
117 | SECTION ADDITIONAL | |
118 | ns.example.com. IN A 1.2.3.4 | |
119 | ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854} | |
120 | ENTRY_END | |
121 | ||
122 | ; response to query of interest | |
123 | ENTRY_BEGIN | |
124 | MATCH opcode qtype qname | |
125 | ADJUST copy_id | |
126 | REPLY QR NOERROR | |
127 | SECTION QUESTION | |
128 | www.example.com. IN A | |
129 | SECTION AUTHORITY | |
130 | example.com. IN SOA ns.example.com. hostmaster.example.com. 2007090400 28800 7200 604800 18000 | |
131 | example.com. 3600 IN RRSIG SOA 3 2 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCM6lsu9byZIQ1yYjJmyYfFWM2RWAIUcR5t84r2La824oWCkLjmHXRQlco= ;{id = 2854} | |
132 | ||
133 | ; NODATA response. H(www.example.com.) = s1unhcti19bkdr98fegs0v46mbu3t4m3 | |
134 | s1unhcti19bkdr98fegs0v46mbu3t4m3.example.com. IN NSEC3 1 1 123 aabb00123456bbccdd s1unhcti19bkdr98fegs0v46mbu3t4m4 MX RRSIG | |
135 | s1unhcti19bkdr98fegs0v46mbu3t4m3.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MCwCFE/a24nsY2luhQmZjY/ObAIgNSMkAhQWd4MUOUVK55bD6AbMHWrDA0yvEA== ;{id = 2854} | |
136 | ||
137 | ENTRY_END | |
138 | ||
139 | ; refer to server one down | |
140 | ENTRY_BEGIN | |
141 | MATCH opcode qtype qname | |
142 | ADJUST copy_id | |
143 | REPLY QR NOERROR | |
144 | SECTION QUESTION | |
145 | www.sub.example.com. IN A | |
146 | SECTION AUTHORITY | |
147 | sub.example.com. IN NS ns.sub.example.com. | |
148 | ; proof that there is no DS here. | |
149 | ;sub.example.com. 3600 IN DS 2854 DSA 1 be4d46cd7489cce25a31af0dff2968ce0425dd31 | |
150 | ;sub.example.com. 3600 IN RRSIG DS 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQC1WMTfb25sTgeUEXCFR4+YiJqecwIUc2R/jrO4amyQxovSnld2reg8eyo= ;{id = 2854} | |
151 | ; sub.example.com. -> 8r1f0ieoutlnjc03meng9e3bn2n0o9pd. | |
152 | 8r1f0ieoutlnjc03meng9e3bn2n0o9pd.example.com. IN NSEC3 1 1 123 aabb00123456bbccdd 8r1f0ieoutlnjc03meng9e3bn3n0o9pd NS RRSIG | |
153 | ; bad signature: | |
154 | 8r1f0ieoutlnjc03meng9e3bn2n0o9pd.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20010926135752 20010829135752 2854 example.com. MC0CFEC78oZJjqlV6kVyQb4X0o6tsUpUAhUAk+bgth7eeN+aO8ts2+yLSyzSX9g= ;{id = 2854} | |
155 | ;8r1f0ieoutlnjc03meng9e3bn2n0o9pd.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFEC78oZJjqlV6kVyQb4X0o6tsUpUAhUAk+bgth7eeN+aO8ts2+yLSyzSX9g= ;{id = 2854} | |
156 | SECTION ADDITIONAL | |
157 | ns.sub.example.com. IN A 1.2.3.10 | |
158 | ENTRY_END | |
159 | ||
160 | ENTRY_BEGIN | |
161 | MATCH opcode qtype qname | |
162 | ADJUST copy_id | |
163 | REPLY QR NOERROR | |
164 | SECTION QUESTION | |
165 | sub.example.com. IN DS | |
166 | SECTION AUTHORITY | |
167 | ; proof that there is no DS here. | |
168 | ;sub.example.com. 3600 IN DS 2854 DSA 1 be4d46cd7489cce25a31af0dff2968ce0425dd31 | |
169 | ;sub.example.com. 3600 IN RRSIG DS 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQC1WMTfb25sTgeUEXCFR4+YiJqecwIUc2R/jrO4amyQxovSnld2reg8eyo= ;{id = 2854} | |
170 | ; sub.example.com. -> 8r1f0ieoutlnjc03meng9e3bn2n0o9pd. | |
171 | 8r1f0ieoutlnjc03meng9e3bn2n0o9pd.example.com. IN NSEC3 1 1 123 aabb00123456bbccdd 8r1f0ieoutlnjc03meng9e3bn3n0o9pd NS RRSIG | |
172 | ; bad signature | |
173 | 8r1f0ieoutlnjc03meng9e3bn2n0o9pd.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20010926135752 20010829135752 2854 example.com. MC0CFEC78oZJjqlV6kVyQb4X0o6tsUpUAhUAk+bgth7eeN+aO8ts2+yLSyzSX9g= ;{id = 2854} | |
174 | ;8r1f0ieoutlnjc03meng9e3bn2n0o9pd.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFEC78oZJjqlV6kVyQb4X0o6tsUpUAhUAk+bgth7eeN+aO8ts2+yLSyzSX9g= ;{id = 2854} | |
175 | ENTRY_END | |
176 | RANGE_END | |
177 | ||
178 | ; ns.sub.example.com. | |
179 | RANGE_BEGIN 0 100 | |
180 | ADDRESS 1.2.3.10 | |
181 | ENTRY_BEGIN | |
182 | MATCH opcode qtype qname | |
183 | ADJUST copy_id | |
184 | REPLY QR REFUSED | |
185 | SECTION QUESTION | |
186 | sub.example.com. IN NS | |
187 | SECTION ANSWER | |
188 | ENTRY_END | |
189 | ||
190 | ||
191 | ; response to DNSKEY priming query | |
192 | ENTRY_BEGIN | |
193 | MATCH opcode qtype qname | |
194 | ADJUST copy_id | |
195 | REPLY QR NOERROR | |
196 | SECTION QUESTION | |
197 | sub.example.com. IN DNSKEY | |
198 | SECTION ANSWER | |
199 | sub.example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b} | |
200 | sub.example.com. 3600 IN RRSIG DNSKEY 3 3 3600 20070926135752 20070829135752 2854 sub.example.com. MCwCFBznBTYM/SrdUnjQdBnLtRO79KAaAhQReG5nRuL7Xsdf6D0KKwPa1GpWyQ== ;{id = 2854} | |
201 | ||
202 | ENTRY_END | |
203 | ||
204 | ENTRY_BEGIN | |
205 | MATCH opcode qtype qname | |
206 | ADJUST copy_id | |
207 | REPLY QR NOERROR | |
208 | SECTION QUESTION | |
209 | www.sub.example.com. IN A | |
210 | SECTION ANSWER | |
211 | www.sub.example.com. IN A 1.2.3.123 | |
212 | www.sub.example.com. 3600 IN RRSIG A 3 4 3600 20070926135752 20070829135752 2854 sub.example.com. MC0CFEExteiCsLkRi/md6o5K8BhRJAKFAhUAgg2tkvwaDn8Xbm9q+5xnjvgIB8k= ;{id = 2854} | |
213 | ENTRY_END | |
214 | RANGE_END | |
215 | ||
216 | STEP 1 QUERY | |
217 | ENTRY_BEGIN | |
218 | REPLY RD DO | |
219 | SECTION QUESTION | |
220 | www.sub.example.com. IN A | |
221 | ENTRY_END | |
222 | ||
223 | ; recursion happens here. | |
224 | STEP 10 CHECK_ANSWER | |
225 | ENTRY_BEGIN | |
226 | MATCH all | |
227 | REPLY QR RD RA DO SERVFAIL | |
228 | SECTION QUESTION | |
229 | www.sub.example.com. IN A | |
230 | SECTION ANSWER | |
231 | SECTION AUTHORITY | |
232 | SECTION ADDITIONAL | |
233 | ENTRY_END | |
234 | ||
235 | SCENARIO_END |