Auth feature: authenticated DNSSEC bootstrapping #14074
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Short description
Implements draft-ietf-dnsop-dnssec-bootstrapping. We'd like to replace our LUA-based implementation at desec.io with this for about 50k zones.
Protocol draft status: in IETF Last Call. -- Other implementations on child-side include Knot DNS and Cloudflare, and on parent-side .ch/.li.
Implementation:
SIGNALING-ZONE
metadata. Zones with this setting will synthesize bootstrapping records.Questions / tasks:
pdnsutil set-signaling-zone
which would run the last 4 commands above? That way users wouldn't have to worry about NSEC3 mode etc. TheSIGNALING-ZONE
metadata makes sense only with this specific config, so no flexibility would be lost.skip.*
files to the test so that it only runs in the proper context(s). Not sure if I did this right.Checklist
I have: