some housecleaning
authorDavid Blacka <david@blacka.com>
Fri, 18 Sep 2009 23:34:42 +0000 (19:34 -0400)
committerDavid Blacka <david@blacka.com>
Fri, 18 Sep 2009 23:34:42 +0000 (19:34 -0400)
.gitignore [new file with mode: 0644]
arpa.zone [moved from zones/arpa.zone with 98% similarity]
bin/digbind.sh [new file with mode: 0755]
bin/dignsd.sh [new file with mode: 0755]
bin/dnskey_query.sh [moved from bin/query.sh with 70% similarity]
bin/do.sh
bin/sign.sh
named.conf
root-servers.net.zone [moved from zones/root-servers.net with 91% similarity]
root.zone [moved from zones/root.zone with 99% similarity]
run/.gitignore

diff --git a/.gitignore b/.gitignore
new file mode 100644 (file)
index 0000000..67f187a
--- /dev/null
@@ -0,0 +1,4 @@
+arpa.zone.signed
+root-servers.net.signed
+root.zone.signed
+nsd.db
similarity index 98%
rename from zones/arpa.zone
rename to arpa.zone
index 84c1f2b..5f39f15 100644 (file)
+++ b/arpa.zone
@@ -6,7 +6,7 @@
 
 $ORIGIN ARPA.
 @ IN    SOA     A.ROOT-SERVERS.NET. NSTLD.VERISIGN-GRS.COM. (
-                                 2009091801 ;serial
+                                 2009091802 ;serial
                                  1800 ;refresh every 30 min
                                  900 ;retry every 15 min
                                  604800 ;expire after a week
diff --git a/bin/digbind.sh b/bin/digbind.sh
new file mode 100755 (executable)
index 0000000..670ede3
--- /dev/null
@@ -0,0 +1,6 @@
+#! /bin/bash
+
+basedir=$(cd `dirname $0`/..; pwd)
+cd $basedir
+
+./bin/dig -p 4053 @127.0.0.1 +dnssec +ignore +norec $@
diff --git a/bin/dignsd.sh b/bin/dignsd.sh
new file mode 100755 (executable)
index 0000000..972ae1a
--- /dev/null
@@ -0,0 +1,6 @@
+#! /bin/bash
+
+basedir=$(cd `dirname $0`/..; pwd)
+cd $basedir
+
+./bin/dig -p 4153 @127.0.0.1 +dnssec +ignore +norec $@
similarity index 70%
rename from bin/query.sh
rename to bin/dnskey_query.sh
index bedcd1e..74dd340 100755 (executable)
@@ -1,3 +1,7 @@
+#! /bin/bash
+
+basedir=$(cd `dirname $0`/..; pwd)
+cd $basedir
 
 echo "BIND:"
 ./bin/dig -p 4053 @127.0.0.1 . ns +dnssec +ignore +norec $@
index 44c5e65..63e6c29 100755 (executable)
--- a/bin/do.sh
+++ b/bin/do.sh
@@ -1,11 +1,14 @@
 #! /bin/bash
 
+basedir=$(cd `dirname $0`/..; pwd)
+cd $basedir
+
 f=$1
 
-echo "Modify root zone and sign.sh"
-read c
-./sign.sh
+echo "Modify zones and sign.sh"
+getkey
+./bin/sign.sh
 echo "Restart bind and NSD"
-read c
-./query.sh > $f
+getkey
+./bin/dnskey_query.sh > $f
 egrep -e "(BIND|NSD|SIZE)" $f
index eeca588..680b996 100755 (executable)
@@ -1,5 +1,10 @@
 #/bin/bash
+
+basedir=$(cd `dirname $0`/..; pwd)
+cd $basedir
+
 export PATH=$PATH:/home/davidb/src/jdnssec/jdnssec-tools/bin
+
 KSK1=keys/K.+008+06820
 KSK2=keys/K.+008+36326
 KSK3=keys/K.+005+57497
@@ -15,5 +20,8 @@ ARPAKSK1=keys/Karpa.+005+52246
 ARPAZSK1=keys/Karpa.+005+64611
 
 jdnssec-signzone -k $KSK1 -f root.zone.signed root.zone $ZSK1
-jdnssec-signzone -k $RSKSK1 -f root-servers.net.signed root-servers.net $RSZSK1
-jdnssec-signzone -k $ARPAKSK1 -f arpa.zone.signed arpa.zone $ARPAZSK1
\ No newline at end of file
+
+jdnssec-signzone -k $ARPAKSK1 -f arpa.zone.signed arpa.zone $ARPAZSK1
+
+jdnssec-signzone -k $RSKSK1 -f root-servers.net.signed \
+    root-servers.net.zone $RSZSK1
index 4de38d5..4a682e6 100644 (file)
@@ -19,6 +19,6 @@ zone "arpa." {
 
 zone "root-servers.net." {
      type master;
-     file "root-servers.net";
+     file "root-servers.net.zone";
      #file "root-servers.net.signed";
 };
similarity index 91%
rename from zones/root-servers.net
rename to root-servers.net.zone
index 2bc2ec0..976cabb 100644 (file)
@@ -1,8 +1,11 @@
-root-servers.net.      3600000 IN      SOA     a.root-servers.net. nstld.verisign-grs.com. 2008121200 14400 7200 1209600 3600000
+root-servers.net.      3600000 IN      SOA     a.root-servers.net. nstld.verisign-grs.com. 2009091800 14400 7200 1209600 3600000
 root-servers.net.      3600000 IN      NS      k.root-servers.net.
 root-servers.net.      3600000 IN      NS      f.root-servers.net.
 root-servers.net.      3600000 IN      NS      j.root-servers.net.
 root-servers.net.      3600000 IN      NS      a.root-servers.net.
+$TTL 86400
+$INCLUDE keys/rs-ksk1
+$INCLUDE keys/rs-zsk1
 $TTL 3600000
 A.ROOT-SERVERS.NET. A 198.41.0.4
 A.ROOT-SERVERS.NET. AAAA 2001:503:BA3E:0:0:0:2:30
similarity index 99%
rename from zones/root.zone
rename to root.zone
index 219987f..5d6eb26 100644 (file)
+++ b/root.zone
@@ -5,7 +5,7 @@
 ; with Verisign Inc.
 
 . IN    SOA     A.ROOT-SERVERS.NET. NSTLD.VERISIGN-GRS.COM. (
-                                 2009091801 ;serial
+                                 2009091806 ;serial
                                  1800 ;refresh every 30 min
                                  900 ;retry every 15 min
                                  604800 ;expire after a week
@@ -46,16 +46,21 @@ I.ROOT-SERVERS.NET. A 192.36.148.17
 E.ROOT-SERVERS.NET. A 192.203.230.10
 D.ROOT-SERVERS.NET. A 128.8.10.90
 $TTL 86400
+;; DS records (from the iTAR)
+$INCLUDE keys/anchors.mf
+;; Keys
+;; 2048-bit RSA KSKs
 $INCLUDE keys/ksk1
 ;$INCLUDE keys/ksk2
+;; 1024-bit ZSKs
 $INCLUDE keys/zsk1
 ;$INCLUDE keys/zsk2
+;; 1280-bit ZSKs
 ;$INCLUDE keys/zsk3
 ;$INCLUDE keys/zsk4
+;; 2048-bit ZSKs
 ;$INCLUDE keys/zsk5
 ;$INCLUDE keys/zsk6
-;;
-$INCLUDE anchors.mf
 $TTL 172800
 ZM. NS HIPPO.RU.AC.ZA.
 ZM. NS NS1.ZAMNET.ZM.
index 58f1108..01acb08 100644 (file)
@@ -1,3 +1,3 @@
 named.pid
 nsd.pid
-
+nsd.log