]> git.saurik.com Git - apple/network_cmds.git/blob - unbound/testdata/autotrust_addpend_early.rpl
8ff3299e7ffa2a1d514efe23eda6810b9c1dddd9
[apple/network_cmds.git] / unbound / testdata / autotrust_addpend_early.rpl
1 ; config options
2 server:
3 target-fetch-policy: "0 0 0 0 0"
4 log-time-ascii: yes
5 stub-zone:
6 name: "."
7 stub-addr: 193.0.14.129 # K.ROOT-SERVERS.NET.
8 ; initial content (say from dig example.com DNSKEY > example.com.key)
9 AUTOTRUST_FILE example.com
10 example.com. 10800 IN DNSKEY 257 3 5 AwEAAc3Z5DQDJpH4oPdNtC4BUQHk50XMD+dHr4r8psHmivIa83hxR5CRgCtd9sENCW9Ae8OIO19xw9t/RPaEAqQa+OE= ;{id = 55582 (ksk), size = 512b}
11 example.com. 10800 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
12 AUTOTRUST_END
13 CONFIG_END
14
15 SCENARIO_BEGIN Test autotrust with ADDPEND used too early
16 ; this should not work, as the holdown has not expired yet.
17
18 ; K-ROOT
19 RANGE_BEGIN 0 100
20 ADDRESS 193.0.14.129
21 ENTRY_BEGIN
22 MATCH opcode qname qtype
23 ADJUST copy_id copy_query
24 REPLY QR AA
25 SECTION QUESTION
26 . IN NS
27 SECTION ANSWER
28 . IN NS k.root-servers.net.
29 SECTION ADDITIONAL
30 k.root-servers.net IN A 193.0.14.129
31 ENTRY_END
32
33 ENTRY_BEGIN
34 MATCH opcode subdomain
35 ADJUST copy_id copy_query
36 REPLY QR
37 SECTION QUESTION
38 com. IN NS
39 SECTION AUTHORITY
40 com. IN NS a.gtld-servers.net.
41 SECTION ADDITIONAL
42 a.gtld-servers.net. IN A 192.5.6.30
43 ENTRY_END
44 RANGE_END
45
46 ; a.gtld-servers.net.
47 RANGE_BEGIN 0 100
48 ADDRESS 192.5.6.30
49 ENTRY_BEGIN
50 MATCH opcode subdomain
51 ADJUST copy_id copy_query
52 REPLY QR
53 SECTION QUESTION
54 example.com. IN NS
55 SECTION AUTHORITY
56 example.com. IN NS ns.example.com.
57 SECTION ADDITIONAL
58 ns.example.com. IN A 1.2.3.4
59 ENTRY_END
60 RANGE_END
61
62 ; ns.example.com. KSK 55582
63 RANGE_BEGIN 0 10
64 ADDRESS 1.2.3.4
65 ENTRY_BEGIN
66 MATCH opcode qname qtype
67 ADJUST copy_id
68 REPLY QR AA
69 SECTION QUESTION
70 www.example.com. IN A
71 SECTION ANSWER
72 www.example.com. 3600 IN A 10.20.30.40
73 www.example.com. 3600 IN RRSIG A 5 3 3600 20090924111500 20090821111500 30899 example.com. pYGxVLsWUvOp1wSf0iwPap+JnECfC5GAm1lRqy3YEqecNGld7U7x/5Imo3CerbdZrVptUQs2oH0lcjwYJXMnsw== ;{id = 30899}
74 SECTION AUTHORITY
75 example.com. 3600 IN NS ns.example.com.
76 example.com. 3600 IN RRSIG NS 5 2 3600 20090924111500 20090821111500 30899 example.com. J5wxRq0jgwQL6yy530kvo9cHqNAUHV8IF4dvaYZL0bNraO2Oe6dVXqlJl4+cxNHI2TMsstwFPr2Zz8tv6Az2mQ== ;{id = 30899}
77 SECTION ADDITIONAL
78 ns.example.com. 3600 IN A 1.2.3.4
79 ns.example.com. 3600 IN RRSIG A 5 3 3600 20090924111500 20090821111500 30899 example.com. JsXbS18oyc0zkVaOWGSFdIQuOsZKflT0GraT9afDPoWLCgH4ApF7jNgfJV7Pqy1sTBRajME5IUAhpANwGBuW4A== ;{id = 30899}
80 ENTRY_END
81
82 ENTRY_BEGIN
83 MATCH opcode qname qtype
84 ADJUST copy_id
85 REPLY QR AA
86 SECTION QUESTION
87 example.com. IN DNSKEY
88 SECTION ANSWER
89 ; KSK 1
90 example.com. 10800 IN DNSKEY 257 3 5 AwEAAc3Z5DQDJpH4oPdNtC4BUQHk50XMD+dHr4r8psHmivIa83hxR5CRgCtd9sENCW9Ae8OIO19xw9t/RPaEAqQa+OE= ;{id = 55582 (ksk), size = 512b}
91 ; ZSK 1
92 example.com. 10800 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
93 ; signatures
94 example.com. 10800 IN RRSIG DNSKEY 5 2 10800 20090924111500 20090821111500 30899 example.com. b/HK231jIQLX8IhlZfup3r0yhpXaasbPE6LzxoEVVvWaTZWcLmeV8jDIcn0qO7Yvs7bIJN20lwVAV0GcHH3hWQ== ;{id = 30899}
95 example.com. 10800 IN RRSIG DNSKEY 5 2 10800 20090924111500 20090821111500 55582 example.com. PCHme1QLoULxqjhg5tMlpR0qJlBfstEUVq18TtNoKQe9le1YhJ9caheXcTWoK+boLhXxg9u6Yyvq8FboQh0OjA== ;{id = 55582}
96 ENTRY_END
97 RANGE_END
98
99 ; ns.example.com. KSK 55582 and 60946
100 RANGE_BEGIN 11 40
101 ADDRESS 1.2.3.4
102 ENTRY_BEGIN
103 MATCH opcode qname qtype
104 ADJUST copy_id
105 REPLY QR AA
106 SECTION QUESTION
107 example.com. IN DNSKEY
108 SECTION ANSWER
109 ; KSK 1
110 example.com. 10800 IN DNSKEY 257 3 5 AwEAAc3Z5DQDJpH4oPdNtC4BUQHk50XMD+dHr4r8psHmivIa83hxR5CRgCtd9sENCW9Ae8OIO19xw9t/RPaEAqQa+OE= ;{id = 55582 (ksk), size = 512b}
111 ; KSK 2
112 example.com. 10800 IN DNSKEY 257 3 5 AwEAAeiaUiUIpWMfYz5L0sfJTZWnuN9IyBX4em9VjsoqQTsOD1HDQpNb4buvJo7pN2aBCxNS7e0OL8e2mVB6CLZ+8ek= ;{id = 60946 (ksk), size = 512b}
113 ; ZSK 1
114 example.com. 10800 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
115 ; signatures
116 example.com. 10800 IN RRSIG DNSKEY 5 2 10800 20091024111500 20090921111500 30899 example.com. rkaCUpTFPWVu4Om5oMTR+39Mct6ZMs56xrE0rbxMMOokfvIQheIxsAEc5BFJeA/2y5WTewl6diCD6yQXCybrDg== ;{id = 30899}
117 example.com. 10800 IN RRSIG DNSKEY 5 2 10800 20091024111500 20090921111500 55582 example.com. CoMon+lWPAsUvgfpCTDPx8Zn8dQpky3lu2O6T+oJ2Mat9a/u1YwGhSQHGPn7ZNG/4vKM97tx84sSlUGz3geD1w== ;{id = 55582}
118 example.com. 10800 IN RRSIG DNSKEY 5 2 10800 20091024111500 20090921111500 60946 example.com. o+Cbs7DcYPYlSLd4hi3vkSVQpXGnKgKSi9MpHGfu1Uahv5190U2DUOxP1du/HOYbf+IHYL8zLbMZjVEG5wgnTg== ;{id = 60946}
119 ENTRY_END
120 RANGE_END
121
122 ; ns.example.com. KSK 60946
123 RANGE_BEGIN 41 50
124 ADDRESS 1.2.3.4
125 ENTRY_BEGIN
126 MATCH opcode qname qtype
127 ADJUST copy_id
128 REPLY QR AA
129 SECTION QUESTION
130 example.com. IN DNSKEY
131 SECTION ANSWER
132 ; KSK 2
133 example.com. 10800 IN DNSKEY 257 3 5 AwEAAeiaUiUIpWMfYz5L0sfJTZWnuN9IyBX4em9VjsoqQTsOD1HDQpNb4buvJo7pN2aBCxNS7e0OL8e2mVB6CLZ+8ek= ;{id = 60946 (ksk), size = 512b}
134 ; ZSK 1
135 example.com. 10800 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}
136 ; signatures
137 example.com. 10800 IN RRSIG DNSKEY 5 2 10800 20091024111500 20090921111500 30899 example.com. nDlOZCE24pNtuoYkmmy9cVvtCn7ykdmlhJX9hYcI9b3DzqJjOrGz3GD5RQvti3uxD74gFcFho0g76NwOKFx/qQ== ;{id = 30899}
138 example.com. 10800 IN RRSIG DNSKEY 5 2 10800 20091024111500 20090921111500 60946 example.com. qBHDZu0XQmr6kpt51r1DxT5tuyfwSHcoL8qLpwwhyyNFF13OPlvxgmCVl+1v27A9+h8tcuqaNls5f+tcFBwtRg== ;{id = 60946}
139 ENTRY_END
140
141 ENTRY_BEGIN
142 MATCH opcode qname qtype
143 ADJUST copy_id
144 REPLY QR AA REFUSED
145 SECTION QUESTION
146 ns.example.com. IN A
147 ENTRY_END
148
149 ENTRY_BEGIN
150 MATCH opcode qname qtype
151 ADJUST copy_id
152 REPLY QR AA REFUSED
153 SECTION QUESTION
154 ns.example.com. IN AAAA
155 ENTRY_END
156 RANGE_END
157
158
159 ; set date/time to Aug 24 07:46:40 (2009).
160 STEP 5 TIME_PASSES ELAPSE 1251100000
161 STEP 6 TRAFFIC ; the initial probe
162 STEP 7 ASSIGN t0 = ${time}
163 STEP 8 ASSIGN probe0 = ${range 4800 ${timeout} 5400}
164
165 ; the auto probing should have been done now.
166 STEP 10 CHECK_AUTOTRUST example.com
167 FILE_BEGIN
168 ; autotrust trust anchor file
169 ;;id: example.com. 1
170 ;;last_queried: ${$t0} ;;${ctime $t0}
171 ;;last_success: ${$t0} ;;${ctime $t0}
172 ;;next_probe_time: ${$t0 + $probe0} ;;${ctime $t0 + $probe0}
173 ;;query_failed: 0
174 ;;query_interval: 5400
175 ;;retry_time: 3600
176 example.com. 10800 IN DNSKEY 257 3 5 AwEAAc3Z5DQDJpH4oPdNtC4BUQHk50XMD+dHr4r8psHmivIa83hxR5CRgCtd9sENCW9Ae8OIO19xw9t/RPaEAqQa+OE= ;{id = 55582 (ksk), size = 512b} ;;state=2 [ VALID ] ;;count=0 ;;lastchange=${$t0} ;;${ctime $t0}
177 FILE_END
178
179 ; key prepublished. First poll. 30 days later
180 STEP 11 TIME_PASSES EVAL ${30*24*3600}
181 STEP 12 TRAFFIC
182 STEP 13 ASSIGN t1 = ${time}
183 STEP 14 ASSIGN probe1 = ${range 4800 ${timeout} 5400}
184 STEP 15 CHECK_AUTOTRUST example.com
185 FILE_BEGIN
186 ; autotrust trust anchor file
187 ;;id: example.com. 1
188 ;;last_queried: ${$t1} ;;${ctime $t1}
189 ;;last_success: ${$t1} ;;${ctime $t1}
190 ;;next_probe_time: ${$t1 + $probe1} ;;${ctime $t1 + $probe1}
191 ;;query_failed: 0
192 ;;query_interval: 5400
193 ;;retry_time: 3600
194 example.com. 10800 IN DNSKEY 257 3 5 AwEAAeiaUiUIpWMfYz5L0sfJTZWnuN9IyBX4em9VjsoqQTsOD1HDQpNb4buvJo7pN2aBCxNS7e0OL8e2mVB6CLZ+8ek= ;{id = 60946 (ksk), size = 512b} ;;state=1 [ ADDPEND ] ;;count=1 ;;lastchange=${$t1} ;;${ctime $t1}
195 example.com. 10800 IN DNSKEY 257 3 5 AwEAAc3Z5DQDJpH4oPdNtC4BUQHk50XMD+dHr4r8psHmivIa83hxR5CRgCtd9sENCW9Ae8OIO19xw9t/RPaEAqQa+OE= ;{id = 55582 (ksk), size = 512b} ;;state=2 [ VALID ] ;;count=0 ;;lastchange=${$t0} ;;${ctime $t0}
196 FILE_END
197
198 ; Second poll. 10 days later
199 STEP 21 TIME_PASSES EVAL ${10*24*3600}
200 STEP 22 TRAFFIC
201 STEP 23 ASSIGN t2 = ${time}
202 STEP 24 ASSIGN probe2 = ${range 4800 ${timeout} 5400}
203 STEP 25 CHECK_AUTOTRUST example.com
204 FILE_BEGIN
205 ; autotrust trust anchor file
206 ;;id: example.com. 1
207 ;;last_queried: ${$t2} ;;${ctime $t2}
208 ;;last_success: ${$t2} ;;${ctime $t2}
209 ;;next_probe_time: ${$t2 + $probe2} ;;${ctime $t2 + $probe2}
210 ;;query_failed: 0
211 ;;query_interval: 5400
212 ;;retry_time: 3600
213 example.com. 10800 IN DNSKEY 257 3 5 AwEAAeiaUiUIpWMfYz5L0sfJTZWnuN9IyBX4em9VjsoqQTsOD1HDQpNb4buvJo7pN2aBCxNS7e0OL8e2mVB6CLZ+8ek= ;{id = 60946 (ksk), size = 512b} ;;state=1 [ ADDPEND ] ;;count=2 ;;lastchange=${$t1} ;;${ctime $t1}
214 example.com. 10800 IN DNSKEY 257 3 5 AwEAAc3Z5DQDJpH4oPdNtC4BUQHk50XMD+dHr4r8psHmivIa83hxR5CRgCtd9sENCW9Ae8OIO19xw9t/RPaEAqQa+OE= ;{id = 55582 (ksk), size = 512b} ;;state=2 [ VALID ] ;;count=0 ;;lastchange=${$t0} ;;${ctime $t0}
215 FILE_END
216
217 ; t3 is removed third poll time.
218
219 ; only 10 days later: hold down has not lapsed! (need 21 days).
220 STEP 41 TIME_PASSES EVAL ${10*24*3600}
221 STEP 42 TRAFFIC
222 STEP 43 ASSIGN t4 = ${time}
223 ; must fail!
224 STEP 44 ASSIGN probe4 = ${range 3200 ${timeout} 3600}
225 STEP 45 CHECK_AUTOTRUST example.com
226 FILE_BEGIN
227 ; autotrust trust anchor file
228 ;;id: example.com. 1
229 ;;last_queried: ${$t4} ;;${ctime $t4}
230 ;;last_success: ${$t2} ;;${ctime $t2}
231 ;;next_probe_time: ${$t4 + $probe4} ;;${ctime $t4 + $probe4}
232 ;;query_failed: 6
233 ;;query_interval: 5400
234 ;;retry_time: 3600
235 example.com. 10800 IN DNSKEY 257 3 5 AwEAAeiaUiUIpWMfYz5L0sfJTZWnuN9IyBX4em9VjsoqQTsOD1HDQpNb4buvJo7pN2aBCxNS7e0OL8e2mVB6CLZ+8ek= ;{id = 60946 (ksk), size = 512b} ;;state=1 [ ADDPEND ] ;;count=2 ;;lastchange=${$t1} ;;${ctime $t1}
236 example.com. 10800 IN DNSKEY 257 3 5 AwEAAc3Z5DQDJpH4oPdNtC4BUQHk50XMD+dHr4r8psHmivIa83hxR5CRgCtd9sENCW9Ae8OIO19xw9t/RPaEAqQa+OE= ;{id = 55582 (ksk), size = 512b} ;;state=2 [ VALID ] ;;count=0 ;;lastchange=${$t0} ;;${ctime $t0}
237 FILE_END
238
239
240 SCENARIO_END