]> mj.ucw.cz Git - nsc-5.git/commit
DNSSEC: Complete support for key delegations to sub-domains
authorMartin Mares <mj@ucw.cz>
Wed, 30 Jan 2019 10:51:15 +0000 (11:51 +0100)
committerMartin Mares <mj@ucw.cz>
Wed, 30 Jan 2019 10:53:05 +0000 (11:53 +0100)
commit57e60f9a9bd96a6cd81651dfd8b833ea82c509c6
tree7353030368fd5aa2dd2ba33b635e8c1f2127acc2
parent8027861ea0c775a47af4ae6ae116b42b25a089ce
DNSSEC: Complete support for key delegations to sub-domains

- key-delegate script for constructing DS record sets in dss/*
- DS macro for importing DS record sets to zones
- DSFOR macro for adding dependencies on DS record sets to Makefile
- key-update does not choke on empty directories
- resign-stamp moved back to keys, so that it is not deleted by key
  hash cleanups
- dnssec-signzone cannot be told to skip creation of dsset files,
  so redirect them from current directory to tmp/
- terminology: domain vs. zone
12 files changed:
TODO
bin/genzone
bin/key-delegate [new file with mode: 0755]
bin/key-gen
bin/key-update
bin/nsconfig
cf.dist/domains
cf.dist/example.com
m4/dnslib.m4
m4/mkmf.m4
m4/mkshell-env.m4
m4/nsc.m4