2018-03-15 18:32:45 -07:00
|
|
|
Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
2016-06-27 14:56:38 +10:00
|
|
|
|
2020-09-14 16:20:40 -07:00
|
|
|
See COPYRIGHT in the source root or https://isc.org/copyright.html for terms.
|
2018-02-23 09:53:12 +01:00
|
|
|
|
2012-06-25 13:57:32 +10:00
|
|
|
dnssec-verify a tool to verify a zone is correctly signed.
|
|
|
|
|
|
|
|
* check that every record that should be signed has a valid RRSIG set.
|
|
|
|
* check that every record that shouldn't be signed isn't.
|
|
|
|
* check that each RRSIG set has a valid RRSIG and that all DNSKEY algorithms
|
|
|
|
in use are checked.
|
|
|
|
* provide a mechanism to mark DNSKEY algorithms to be ignored to support
|
2020-02-21 14:12:42 -08:00
|
|
|
verification of zones that are in the process of adding/removing
|
2012-06-25 13:57:32 +10:00
|
|
|
support for a algorithm.
|
|
|
|
* provide a mechanism to check the zone as of a specified date and time.
|
|
|
|
* check that RRSIG won't expire within the TTL interval.
|
|
|
|
* check that original TTL matches.
|
|
|
|
|
|
|
|
NSEC:
|
|
|
|
* check that every node with data within the zone has a NSEC RRset.
|
|
|
|
* check that empty nodes don't have a NSEC record.
|
|
|
|
* check that nodes outside the zone do not have a NSEC record.
|
|
|
|
* check that the NSEC chain is valid.
|
|
|
|
|
|
|
|
NSEC3: for each NSEC3 chain
|
|
|
|
* check that every node with data within the zone has a NSEC3 RRset.
|
|
|
|
* check that empty nodes within the zone have a NSEC3 record.
|
|
|
|
* check that nodes outside the zone do not have a NSEC3 record.
|
|
|
|
* check that each NSEC3 in the NSEC3PARAM record is valid.
|