1; config options 2server: 3 trust-anchor: "example.com. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}" 4 trust-anchor: "example.org. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b}" 5 val-override-date: "20091011000000" 6 fake-sha1: yes 7 trust-anchor-signaling: no 8 9forward-zone: 10 name: "." 11 forward-addr: 192.0.2.1 12CONFIG_END 13 14SCENARIO_BEGIN Test validator with CNAME to insecure NSEC or NSEC3. 15 16RANGE_BEGIN 0 100 17 ADDRESS 192.0.2.1 18 19ENTRY_BEGIN 20MATCH opcode qtype qname 21ADJUST copy_id 22REPLY QR NOERROR 23SECTION QUESTION 24example.com. IN DNSKEY 25SECTION ANSWER 26example.com. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b} 27example.com. 3600 IN RRSIG DNSKEY 5 2 3600 20091012000000 20091010000000 30899 example.com. BeCk6+D0ysmO1+X0CjvXH55AO78C7Vxrq58C3YgO0wt2eTG/deZCiWI3bz+3OC64cICbJr5fvCfqUuJDABU/fw== ;{id = 30899} 28ENTRY_END 29 30ENTRY_BEGIN 31MATCH opcode qtype qname 32ADJUST copy_id 33REPLY QR NOERROR 34SECTION QUESTION 35www.example.com. IN AAAA 36SECTION ANSWER 37www.example.com. 3600 IN CNAME unsafe.example.com. 38www.example.com. 3600 IN RRSIG CNAME 5 3 3600 20091012000000 20091010000000 30899 example.com. FJN0bZitZfxNQNTD1V2vcDBQ9cb4y4YGa35Ilr+VnrBiisAB9ZyrO8umvdtwzV1VPIlfFDQTJrKh5aZparLHPw== ;{id = 30899} 39SECTION AUTHORITY 40; really an insecure delegation, but co-hosted on the server. 41unsafe.example.com. 3600 IN NSEC v.example.com. NS RRSIG NSEC 42unsafe.example.com. 3600 IN RRSIG NSEC 5 3 3600 20091012000000 20091010000000 30899 example.com. Le9EsRd2MxkOGRCvGtQkXRDAob5ZJOFQlZbDvcWAh5OXVpmcwZmCHctxw/Zyi4LkNYoYCSCc8PiVRrJM3IsGrQ== ;{id = 30899} 43ENTRY_END 44 45ENTRY_BEGIN 46MATCH opcode qtype qname 47ADJUST copy_id 48REPLY QR NOERROR 49SECTION QUESTION 50unsafe.example.com. IN AAAA 51SECTION ANSWER 52; empty response 53ENTRY_END 54 55 56ENTRY_BEGIN 57MATCH opcode qtype qname 58ADJUST copy_id 59REPLY QR NOERROR 60SECTION QUESTION 61example.org. IN DNSKEY 62SECTION ANSWER 63example.org. 3600 IN DNSKEY 256 3 5 AQPQ41chR9DEHt/aIzIFAqanbDlRflJoRs5yz1jFsoRIT7dWf0r+PeDuewdxkszNH6wnU4QL8pfKFRh5PIYVBLK3 ;{id = 30899 (zsk), size = 512b} 64example.org. 3600 IN RRSIG DNSKEY 5 2 3600 20091012000000 20091010000000 30899 example.org. rd9aoXbeaE0zyT96Z0sjN3Mz5Nz/wuRsIH1lwcjwUFmAAT7F+SjwVWeo8nGaTBd8JDSUdiL+VwotEE0I22RrnA== ;{id = 30899} 65ENTRY_END 66 67ENTRY_BEGIN 68MATCH opcode qtype qname 69ADJUST copy_id 70REPLY QR NOERROR 71SECTION QUESTION 72www.example.org. IN AAAA 73SECTION ANSWER 74www.example.org. 3600 IN CNAME unsafe.example.org. 75www.example.org. 3600 IN RRSIG CNAME 5 3 3600 20091012000000 20091010000000 30899 example.org. ZgRbMnunAqa1K46GINIihekkI73/1PkGFSAJRn7bSTxBpLM+qiHJDU1+QgS2SjaSKHqNqbXy/eeG3qX9r9y87g== ;{id = 30899} 76SECTION AUTHORITY 77; really an insecure delegation, but co-hosted on the server. 78; h(unsafe.example.org.) = ltchu0548v0cof8f25u2pj4mjf4shcms. 79ltchu0548v0cof8f25u2pj4mjf4shcms.example.org. IN NSEC3 1 0 1 - ltchu0548v0cof8f25u2pj4mjf4shcmt NS 80ltchu0548v0cof8f25u2pj4mjf4shcms.example.org. 3600 IN RRSIG NSEC3 5 3 3600 20091012000000 20091010000000 30899 example.org. yxuYgfkg8QTdB5yBMN9Up9GyKu7xjKDScqq95/tsy3lx22tLsdLD9Fojdrq7eB+K7Tr72AejmVJs44v6TmWkZw== ;{id = 30899} 81ENTRY_END 82 83ENTRY_BEGIN 84MATCH opcode qtype qname 85ADJUST copy_id 86REPLY QR NOERROR 87SECTION QUESTION 88unsafe.example.org. IN AAAA 89SECTION ANSWER 90; empty response 91ENTRY_END 92 93RANGE_END 94 95; NSEC 96STEP 1 QUERY 97ENTRY_BEGIN 98REPLY RD DO 99SECTION QUESTION 100www.example.com. IN AAAA 101ENTRY_END 102; recursion happens here. 103STEP 10 CHECK_ANSWER 104ENTRY_BEGIN 105MATCH all 106REPLY QR RD RA DO NOERROR 107SECTION QUESTION 108www.example.com. IN AAAA 109SECTION ANSWER 110www.example.com. 3600 IN CNAME unsafe.example.com. 111www.example.com. 3600 IN RRSIG CNAME 5 3 3600 20091012000000 20091010000000 30899 example.com. FJN0bZitZfxNQNTD1V2vcDBQ9cb4y4YGa35Ilr+VnrBiisAB9ZyrO8umvdtwzV1VPIlfFDQTJrKh5aZparLHPw== ;{id = 30899} 112SECTION AUTHORITY 113unsafe.example.com. 3600 IN NSEC v.example.com. NS RRSIG NSEC 114unsafe.example.com. 3600 IN RRSIG NSEC 5 3 3600 20091012000000 20091010000000 30899 example.com. Le9EsRd2MxkOGRCvGtQkXRDAob5ZJOFQlZbDvcWAh5OXVpmcwZmCHctxw/Zyi4LkNYoYCSCc8PiVRrJM3IsGrQ== ;{id = 30899} 115ENTRY_END 116 117; NSEC3 118STEP 20 QUERY 119ENTRY_BEGIN 120REPLY RD DO 121SECTION QUESTION 122www.example.org. IN AAAA 123ENTRY_END 124; recursion happens here. 125STEP 30 CHECK_ANSWER 126ENTRY_BEGIN 127MATCH all 128REPLY QR RD RA DO NOERROR 129SECTION QUESTION 130www.example.org. IN AAAA 131SECTION ANSWER 132www.example.org. 3600 IN CNAME unsafe.example.org. 133www.example.org. 3600 IN RRSIG CNAME 5 3 3600 20091012000000 20091010000000 30899 example.org. ZgRbMnunAqa1K46GINIihekkI73/1PkGFSAJRn7bSTxBpLM+qiHJDU1+QgS2SjaSKHqNqbXy/eeG3qX9r9y87g== ;{id = 30899} 134SECTION AUTHORITY 135ltchu0548v0cof8f25u2pj4mjf4shcms.example.org. 3600 IN NSEC3 1 0 1 - ltchu0548v0cof8f25u2pj4mjf4shcmt NS 136ltchu0548v0cof8f25u2pj4mjf4shcms.example.org. 3600 IN RRSIG NSEC3 5 3 3600 20091012000000 20091010000000 30899 example.org. yxuYgfkg8QTdB5yBMN9Up9GyKu7xjKDScqq95/tsy3lx22tLsdLD9Fojdrq7eB+K7Tr72AejmVJs44v6TmWkZw== ;{id = 30899} 137ENTRY_END 138 139SCENARIO_END 140