xref: /minix3/external/bsd/bind/dist/bin/tests/system/tsiggss/tests.sh (revision 00b67f09dd46474d133c95011a48590a8e8f94c7)
1*00b67f09SDavid van Moolenbroek#!/bin/sh
2*00b67f09SDavid van Moolenbroek#
3*00b67f09SDavid van Moolenbroek# Copyright (C) 2010, 2011, 2014  Internet Systems Consortium, Inc. ("ISC")
4*00b67f09SDavid van Moolenbroek#
5*00b67f09SDavid van Moolenbroek# Permission to use, copy, modify, and/or distribute this software for any
6*00b67f09SDavid van Moolenbroek# purpose with or without fee is hereby granted, provided that the above
7*00b67f09SDavid van Moolenbroek# copyright notice and this permission notice appear in all copies.
8*00b67f09SDavid van Moolenbroek#
9*00b67f09SDavid van Moolenbroek# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
10*00b67f09SDavid van Moolenbroek# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
11*00b67f09SDavid van Moolenbroek# AND FITNESS.  IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
12*00b67f09SDavid van Moolenbroek# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
13*00b67f09SDavid van Moolenbroek# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
14*00b67f09SDavid van Moolenbroek# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
15*00b67f09SDavid van Moolenbroek# PERFORMANCE OF THIS SOFTWARE.
16*00b67f09SDavid van Moolenbroek
17*00b67f09SDavid van Moolenbroek# tests for TSIG-GSS updates
18*00b67f09SDavid van Moolenbroek
19*00b67f09SDavid van MoolenbroekSYSTEMTESTTOP=..
20*00b67f09SDavid van Moolenbroek. $SYSTEMTESTTOP/conf.sh
21*00b67f09SDavid van Moolenbroek
22*00b67f09SDavid van Moolenbroekstatus=0
23*00b67f09SDavid van Moolenbroek
24*00b67f09SDavid van MoolenbroekDIGOPTS="@10.53.0.1 -p 5300"
25*00b67f09SDavid van Moolenbroek
26*00b67f09SDavid van Moolenbroek# we don't want a KRB5_CONFIG setting breaking the tests
27*00b67f09SDavid van MoolenbroekKRB5_CONFIG=/dev/null
28*00b67f09SDavid van Moolenbroekexport KRB5_CONFIG
29*00b67f09SDavid van Moolenbroek
30*00b67f09SDavid van Moolenbroektest_update() {
31*00b67f09SDavid van Moolenbroek    host="$1"
32*00b67f09SDavid van Moolenbroek    type="$2"
33*00b67f09SDavid van Moolenbroek    cmd="$3"
34*00b67f09SDavid van Moolenbroek    digout="$4"
35*00b67f09SDavid van Moolenbroek
36*00b67f09SDavid van Moolenbroek    cat <<EOF > ns1/update.txt
37*00b67f09SDavid van Moolenbroekserver 10.53.0.1 5300
38*00b67f09SDavid van Moolenbroekupdate add $host $cmd
39*00b67f09SDavid van Moolenbroeksend
40*00b67f09SDavid van MoolenbroekEOF
41*00b67f09SDavid van Moolenbroek    echo "I:testing update for $host $type $cmd"
42*00b67f09SDavid van Moolenbroek    $NSUPDATE -g -d ns1/update.txt > nsupdate.out 2>&1 || {
43*00b67f09SDavid van Moolenbroek	echo "I:update failed for $host $type $cmd"
44*00b67f09SDavid van Moolenbroek	sed "s/^/I:/" nsupdate.out
45*00b67f09SDavid van Moolenbroek	return 1
46*00b67f09SDavid van Moolenbroek    }
47*00b67f09SDavid van Moolenbroek
48*00b67f09SDavid van Moolenbroek    out=`$DIG $DIGOPTS -t $type -q $host | egrep "^${host}"`
49*00b67f09SDavid van Moolenbroek    lines=`echo "$out" | grep "$digout" | wc -l`
50*00b67f09SDavid van Moolenbroek    [ $lines -eq 1 ] || {
51*00b67f09SDavid van Moolenbroek	echo "I:dig output incorrect for $host $type $cmd: $out"
52*00b67f09SDavid van Moolenbroek	return 1
53*00b67f09SDavid van Moolenbroek    }
54*00b67f09SDavid van Moolenbroek    return 0
55*00b67f09SDavid van Moolenbroek}
56*00b67f09SDavid van Moolenbroek
57*00b67f09SDavid van Moolenbroekecho "I:testing updates as administrator"
58*00b67f09SDavid van MoolenbroekKRB5CCNAME="FILE:"`pwd`/ns1/administrator.ccache
59*00b67f09SDavid van Moolenbroekexport KRB5CCNAME
60*00b67f09SDavid van Moolenbroek
61*00b67f09SDavid van Moolenbroektest_update testdc1.example.nil. A "86400 A 10.53.0.10" "10.53.0.10" || status=1
62*00b67f09SDavid van Moolenbroektest_update testdc2.example.nil. A "86400 A 10.53.0.11" "10.53.0.11" || status=1
63*00b67f09SDavid van Moolenbroektest_update denied.example.nil. TXT "86400 TXT helloworld" "helloworld" > /dev/null && status=1
64*00b67f09SDavid van Moolenbroek
65*00b67f09SDavid van Moolenbroekecho "I:testing updates as a user"
66*00b67f09SDavid van MoolenbroekKRB5CCNAME="FILE:"`pwd`/ns1/testdenied.ccache
67*00b67f09SDavid van Moolenbroekexport KRB5CCNAME
68*00b67f09SDavid van Moolenbroek
69*00b67f09SDavid van Moolenbroektest_update testdenied.example.nil. A "86400 A 10.53.0.12" "10.53.0.12" > /dev/null && status=1
70*00b67f09SDavid van Moolenbroektest_update testdenied.example.nil. TXT "86400 TXT helloworld" "helloworld" || status=1
71*00b67f09SDavid van Moolenbroek
72*00b67f09SDavid van Moolenbroekecho "I:testing external update policy"
73*00b67f09SDavid van Moolenbroektest_update testcname.example.nil. TXT "86400 CNAME testdenied.example.nil" "testdenied" > /dev/null && status=1
74*00b67f09SDavid van Moolenbroek$PERL ./authsock.pl --type=CNAME --path=ns1/auth.sock --pidfile=authsock.pid --timeout=120 > /dev/null 2>&1 &
75*00b67f09SDavid van Moolenbroeksleep 1
76*00b67f09SDavid van Moolenbroektest_update testcname.example.nil. TXT "86400 CNAME testdenied.example.nil" "testdenied" || status=1
77*00b67f09SDavid van Moolenbroektest_update testcname.example.nil. TXT "86400 A 10.53.0.13" "10.53.0.13" > /dev/null && status=1
78*00b67f09SDavid van Moolenbroek
79*00b67f09SDavid van Moolenbroekecho "I:testing external policy with SIG(0) key"
80*00b67f09SDavid van Moolenbroekret=0
81*00b67f09SDavid van Moolenbroek$NSUPDATE -R $RANDFILE -k ns1/Kkey.example.nil.*.private <<END > /dev/null 2>&1 || ret=1
82*00b67f09SDavid van Moolenbroekserver 10.53.0.1 5300
83*00b67f09SDavid van Moolenbroekzone example.nil
84*00b67f09SDavid van Moolenbroekupdate add fred.example.nil 120 cname foo.bar.
85*00b67f09SDavid van Moolenbroeksend
86*00b67f09SDavid van MoolenbroekEND
87*00b67f09SDavid van Moolenbroekoutput=`$DIG $DIGOPTS +short cname fred.example.nil.`
88*00b67f09SDavid van Moolenbroek[ -n "$output" ] || ret=1
89*00b67f09SDavid van Moolenbroek[ $ret -eq 0 ] || echo "I:failed"
90*00b67f09SDavid van Moolenbroekstatus=`expr $status + $ret`
91*00b67f09SDavid van Moolenbroek
92*00b67f09SDavid van Moolenbroek[ $status -eq 0 ] && echo "I:tsiggss tests all OK"
93*00b67f09SDavid van Moolenbroek
94*00b67f09SDavid van Moolenbroekkill `cat authsock.pid`
95*00b67f09SDavid van Moolenbroekexit $status
96