]>
Commit | Line | Data |
---|---|---|
89c4ed63 A |
1 | ; config options |
2 | ; The island of trust is at example.com | |
3 | server: | |
4 | trust-anchor: "example.com. 3600 IN DS 2854 3 1 46e4ffc6e9a4793b488954bd3f0cc6af0dfb201b" | |
5 | val-override-date: "20070916134226" | |
6 | target-fetch-policy: "0 0 0 0 0" | |
7 | ||
8 | stub-zone: | |
9 | name: "." | |
10 | stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET. | |
11 | CONFIG_END | |
12 | ||
13 | SCENARIO_BEGIN Test validator with unknown algorithm delegation | |
14 | ; DS has unknown algo only. | |
15 | ; so subzone has to be treated as unsigned. | |
16 | ||
17 | ; K.ROOT-SERVERS.NET. | |
18 | RANGE_BEGIN 0 100 | |
19 | ADDRESS 193.0.14.129 | |
20 | ENTRY_BEGIN | |
21 | MATCH opcode qtype qname | |
22 | ADJUST copy_id | |
23 | REPLY QR NOERROR | |
24 | SECTION QUESTION | |
25 | . IN NS | |
26 | SECTION ANSWER | |
27 | . IN NS K.ROOT-SERVERS.NET. | |
28 | SECTION ADDITIONAL | |
29 | K.ROOT-SERVERS.NET. IN A 193.0.14.129 | |
30 | ENTRY_END | |
31 | ||
32 | ENTRY_BEGIN | |
33 | MATCH opcode qtype qname | |
34 | ADJUST copy_id | |
35 | REPLY QR NOERROR | |
36 | SECTION QUESTION | |
37 | www.sub.example.com. IN A | |
38 | SECTION AUTHORITY | |
39 | com. IN NS a.gtld-servers.net. | |
40 | SECTION ADDITIONAL | |
41 | a.gtld-servers.net. IN A 192.5.6.30 | |
42 | ENTRY_END | |
43 | RANGE_END | |
44 | ||
45 | ; a.gtld-servers.net. | |
46 | RANGE_BEGIN 0 100 | |
47 | ADDRESS 192.5.6.30 | |
48 | ENTRY_BEGIN | |
49 | MATCH opcode qtype qname | |
50 | ADJUST copy_id | |
51 | REPLY QR NOERROR | |
52 | SECTION QUESTION | |
53 | com. IN NS | |
54 | SECTION ANSWER | |
55 | com. IN NS a.gtld-servers.net. | |
56 | SECTION ADDITIONAL | |
57 | a.gtld-servers.net. IN A 192.5.6.30 | |
58 | ENTRY_END | |
59 | ||
60 | ENTRY_BEGIN | |
61 | MATCH opcode qtype qname | |
62 | ADJUST copy_id | |
63 | REPLY QR NOERROR | |
64 | SECTION QUESTION | |
65 | www.sub.example.com. IN A | |
66 | SECTION AUTHORITY | |
67 | example.com. IN NS ns.example.com. | |
68 | SECTION ADDITIONAL | |
69 | ns.example.com. IN A 1.2.3.4 | |
70 | ENTRY_END | |
71 | RANGE_END | |
72 | ||
73 | ; ns.example.com. | |
74 | RANGE_BEGIN 0 100 | |
75 | ADDRESS 1.2.3.4 | |
76 | ENTRY_BEGIN | |
77 | MATCH opcode qtype qname | |
78 | ADJUST copy_id | |
79 | REPLY QR NOERROR | |
80 | SECTION QUESTION | |
81 | example.com. IN NS | |
82 | SECTION ANSWER | |
83 | example.com. IN NS ns.example.com. | |
84 | example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854} | |
85 | SECTION ADDITIONAL | |
86 | ns.example.com. IN A 1.2.3.4 | |
87 | ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854} | |
88 | ENTRY_END | |
89 | ||
90 | ; response to DNSKEY priming query | |
91 | ENTRY_BEGIN | |
92 | MATCH opcode qtype qname | |
93 | ADJUST copy_id | |
94 | REPLY QR NOERROR | |
95 | SECTION QUESTION | |
96 | example.com. IN DNSKEY | |
97 | SECTION ANSWER | |
98 | example.com. 3600 IN DNSKEY 256 3 3 ALXLUsWqUrY3JYER3T4TBJII s70j+sDS/UT2QRp61SE7S3E EXopNXoFE73JLRmvpi/UrOO/Vz4Se 6wXv/CYCKjGw06U4WRgR YXcpEhJROyNapmdIKSx hOzfLVE1gqA0PweZR8d tY3aNQSRn3sPpwJr6Mi /PqQKAMMrZ9ckJpf1+b QMOOvxgzz2U1GS18b3y ZKcgTMEaJzd/GZYzi/B N2DzQ0MsrSwYXfsNLFO Bbs8PJMW4LYIxeeOe6rUgkWOF 7CC9Dh/dduQ1QrsJhmZAEFfd6ByYV+ ;{id = 2854 (zsk), size = 1688b} | |
99 | example.com. 3600 IN RRSIG DNSKEY DSA 2 3600 20070926134150 20070829134150 2854 example.com. MCwCFBQRtlR4BEv9ohi+PGFjp+AHsJuHAhRCvz0shggvnvI88DFnBDCczHUcVA== ;{id = 2854} | |
100 | SECTION AUTHORITY | |
101 | example.com. IN NS ns.example.com. | |
102 | example.com. 3600 IN RRSIG NS 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFQCN+qHdJxoI/2tNKwsb08pra/G7aAIUAWA5sDdJTbrXA1/3OaesGBAO3sI= ;{id = 2854} | |
103 | SECTION ADDITIONAL | |
104 | ns.example.com. IN A 1.2.3.4 | |
105 | ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854} | |
106 | ENTRY_END | |
107 | ||
108 | ; response for delegation to sub.example.com. | |
109 | ENTRY_BEGIN | |
110 | MATCH opcode qtype subdomain | |
111 | ADJUST copy_id copy_query | |
112 | REPLY QR NOERROR | |
113 | SECTION QUESTION | |
114 | sub.example.com. IN A | |
115 | SECTION ANSWER | |
116 | SECTION AUTHORITY | |
117 | sub.example.com. IN NS ns.sub.example.com. | |
118 | ; algorithm 208 is unknown. | |
119 | sub.example.com. 3600 IN DS 30899 208 1 f7ed618f24d5e5202927e1d27bc2e84a141cb4b3 | |
120 | sub.example.com. 3600 IN RRSIG DS 3 3 3600 20070926134150 20070829134150 2854 example.com. AEMPMNVJAygL0TyRUU+MVgP4FA7jSIpVj6628IdLe7eY3OwWp3hUTnU= ;{id = 2854} | |
121 | ;sub.example.com. 3600 IN DS 30899 RSASHA1 1 f7ed618f24d5e5202927e1d27bc2e84a141cb4b3 | |
122 | ;sub.example.com. 3600 IN RRSIG DS 3 3 3600 20070926134150 20070829134150 2854 example.com. MCwCFCW3ix0GD4BSvNLWIbROCJt5DAW9AhRt/kg9kBKJ20UBUdumrBUHqnskdA== ;{id = 2854} | |
123 | SECTION ADDITIONAL | |
124 | ns.sub.example.com. IN A 1.2.3.6 | |
125 | ENTRY_END | |
126 | RANGE_END | |
127 | ||
128 | ; ns.sub.example.com. | |
129 | RANGE_BEGIN 0 100 | |
130 | ADDRESS 1.2.3.6 | |
131 | ENTRY_BEGIN | |
132 | MATCH opcode qtype qname | |
133 | ADJUST copy_id | |
134 | REPLY QR NOERROR | |
135 | SECTION QUESTION | |
136 | sub.example.com. IN NS | |
137 | SECTION ANSWER | |
138 | sub.example.com. IN NS ns.sub.example.com. | |
139 | sub.example.com. 3600 IN RRSIG NS 5 3 3600 20070926134150 20070829134150 30899 sub.example.com. wcpHeBILHfo8C9uxMhcW03gcURZeUffiKdSTb50ZjzTHgMNhRyMfpcvSpXEd9548A9UTmWKeLZChfr5Z/glONw== ;{id = 30899} | |
140 | SECTION ADDITIONAL | |
141 | ns.sub.example.com. IN A 1.2.3.6 | |
142 | ns.sub.example.com. 3600 IN RRSIG A 5 4 3600 20070926134150 20070829134150 30899 sub.example.com. UF7shD/gt1FOp2UHgLTNbPzVykklSXFMEtJ1xD+Hholwf/PIzd7zoaIttIYibNa4fUXCqMg22H9P7MRhfmFe6g== ;{id = 30899} | |
143 | ENTRY_END | |
144 | ||
145 | ; response to DNSKEY priming query | |
146 | ; sub.example.com. 3600 IN DS 30899 RSASHA1 1 f7ed618f24d5e5202927e1d27bc2e84a141cb4b3 | |
147 | ENTRY_BEGIN | |
148 | MATCH opcode qtype qname | |
149 | ADJUST copy_id | |
150 | REPLY QR NOERROR | |
151 | SECTION QUESTION | |
152 | sub.example.com. IN DNSKEY | |
153 | SECTION ANSWER | |
154 | sub.example.com. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b} | |
155 | sub.example.com. 3600 IN RRSIG DNSKEY 5 3 3600 20070926134150 20070829134150 30899 sub.example.com. uNGp99iznjD7oOX02XnQbDnbg75UwBHRvZSKYUorTKvPUnCWMHKdRsQ+mf+Fx3GZ+Fz9BVjoCmQqpnfgXLEYqw== ;{id = 30899} | |
156 | SECTION AUTHORITY | |
157 | sub.example.com. IN NS ns.sub.example.com. | |
158 | sub.example.com. 3600 IN RRSIG NS 5 3 3600 20070926134150 20070829134150 30899 sub.example.com. wcpHeBILHfo8C9uxMhcW03gcURZeUffiKdSTb50ZjzTHgMNhRyMfpcvSpXEd9548A9UTmWKeLZChfr5Z/glONw== ;{id = 30899} | |
159 | SECTION ADDITIONAL | |
160 | ns.sub.example.com. IN A 1.2.3.6 | |
161 | ns.sub.example.com. 3600 IN RRSIG A 5 4 3600 20070926134150 20070829134150 30899 sub.example.com. UF7shD/gt1FOp2UHgLTNbPzVykklSXFMEtJ1xD+Hholwf/PIzd7zoaIttIYibNa4fUXCqMg22H9P7MRhfmFe6g== ;{id = 30899} | |
162 | ENTRY_END | |
163 | ||
164 | ; response to query of interest | |
165 | ENTRY_BEGIN | |
166 | MATCH opcode qtype qname | |
167 | ADJUST copy_id | |
168 | REPLY QR NOERROR | |
169 | SECTION QUESTION | |
170 | www.sub.example.com. IN A | |
171 | SECTION ANSWER | |
172 | www.sub.example.com. IN A 11.11.11.11 | |
173 | www.sub.example.com. 3600 IN RRSIG A 5 4 3600 20070926134150 20070829134150 30899 sub.example.com. 0DqqRfRtm7VSEQ4mmBbzrKRqQAay3JAE8DPDGmjtokrrjN9F1G/HxozDV7bjdIh2EChlQea8FPwf/GepJMUVxg== ;{id = 30899} | |
174 | SECTION AUTHORITY | |
175 | SECTION ADDITIONAL | |
176 | ENTRY_END | |
177 | RANGE_END | |
178 | ||
179 | STEP 1 QUERY | |
180 | ENTRY_BEGIN | |
181 | REPLY RD DO | |
182 | SECTION QUESTION | |
183 | www.sub.example.com. IN A | |
184 | ENTRY_END | |
185 | ||
186 | ; recursion happens here. | |
187 | STEP 10 CHECK_ANSWER | |
188 | ENTRY_BEGIN | |
189 | MATCH all | |
190 | REPLY QR RD RA DO NOERROR | |
191 | SECTION QUESTION | |
192 | www.sub.example.com. IN A | |
193 | SECTION ANSWER | |
194 | www.sub.example.com. 3600 IN A 11.11.11.11 | |
195 | www.sub.example.com. 3600 IN RRSIG A 5 4 3600 20070926134150 20070829134150 30899 sub.example.com. 0DqqRfRtm7VSEQ4mmBbzrKRqQAay3JAE8DPDGmjtokrrjN9F1G/HxozDV7bjdIh2EChlQea8FPwf/GepJMUVxg== ;{id = 30899} | |
196 | SECTION AUTHORITY | |
197 | SECTION ADDITIONAL | |
198 | ENTRY_END | |
199 | ||
200 | SCENARIO_END |