2001-01-17 21:00:59 -05:00
|
|
|
/*
|
2011-03-17 19:47:30 -04:00
|
|
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
2001-01-17 21:00:59 -05:00
|
|
|
*
|
|
|
|
|
* SPDX-License-Identifier: MPL-2.0
|
2021-06-03 02:37:05 -04:00
|
|
|
*
|
2001-01-17 21:00:59 -05:00
|
|
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
|
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
|
|
|
* file, you can obtain one at https://mozilla.org/MPL/2.0/.
|
2018-02-23 03:53:12 -05:00
|
|
|
*
|
2001-01-17 21:00:59 -05:00
|
|
|
* See the COPYRIGHT file distributed with this work for additional
|
|
|
|
|
* information regarding copyright ownership.
|
|
|
|
|
*/
|
|
|
|
|
|
2018-03-28 08:19:37 -04:00
|
|
|
#include <inttypes.h>
|
2018-04-17 11:29:14 -04:00
|
|
|
#include <stdbool.h>
|
2005-06-07 22:09:18 -04:00
|
|
|
#include <stddef.h>
|
2001-01-16 20:08:08 -05:00
|
|
|
#include <stdlib.h>
|
|
|
|
|
|
2022-03-09 05:33:03 -05:00
|
|
|
#include <isc/mem.h>
|
2001-01-16 20:08:08 -05:00
|
|
|
#include <isc/region.h>
|
|
|
|
|
#include <isc/util.h>
|
|
|
|
|
|
|
|
|
|
#include <dns/keyvalues.h>
|
|
|
|
|
|
|
|
|
|
#include <dst/dst.h>
|
2020-02-12 07:59:18 -05:00
|
|
|
|
2020-03-09 11:17:26 -04:00
|
|
|
#include "dst_internal.h"
|
|
|
|
|
|
2018-03-28 08:19:37 -04:00
|
|
|
uint16_t
|
2018-10-25 04:27:49 -04:00
|
|
|
dst_region_computeid(const isc_region_t *source) {
|
2018-03-28 08:19:37 -04:00
|
|
|
uint32_t ac;
|
2001-01-16 20:08:08 -05:00
|
|
|
const unsigned char *p;
|
|
|
|
|
int size;
|
|
|
|
|
|
|
|
|
|
REQUIRE(source != NULL);
|
2001-04-03 22:02:58 -04:00
|
|
|
REQUIRE(source->length >= 4);
|
2001-01-16 20:08:08 -05:00
|
|
|
|
|
|
|
|
p = source->base;
|
|
|
|
|
size = source->length;
|
|
|
|
|
|
2019-05-29 09:17:04 -04:00
|
|
|
for (ac = 0; size > 1; size -= 2, p += 2) {
|
2001-01-16 20:08:08 -05:00
|
|
|
ac += ((*p) << 8) + *(p + 1);
|
2020-02-13 15:48:23 -05:00
|
|
|
}
|
2001-01-16 20:08:08 -05:00
|
|
|
|
2019-05-29 09:17:04 -04:00
|
|
|
if (size > 0) {
|
2001-01-16 20:08:08 -05:00
|
|
|
ac += ((*p) << 8);
|
2020-02-13 15:48:23 -05:00
|
|
|
}
|
2001-01-16 20:08:08 -05:00
|
|
|
ac += (ac >> 16) & 0xffff;
|
|
|
|
|
|
2018-03-28 08:19:37 -04:00
|
|
|
return (uint16_t)(ac & 0xffff);
|
2001-01-16 20:08:08 -05:00
|
|
|
}
|
|
|
|
|
|
2018-03-28 08:19:37 -04:00
|
|
|
uint16_t
|
2018-10-25 04:27:49 -04:00
|
|
|
dst_region_computerid(const isc_region_t *source) {
|
2018-03-28 08:19:37 -04:00
|
|
|
uint32_t ac;
|
2011-10-20 17:20:02 -04:00
|
|
|
const unsigned char *p;
|
|
|
|
|
int size;
|
|
|
|
|
|
|
|
|
|
REQUIRE(source != NULL);
|
|
|
|
|
REQUIRE(source->length >= 4);
|
|
|
|
|
|
|
|
|
|
p = source->base;
|
|
|
|
|
size = source->length;
|
|
|
|
|
|
|
|
|
|
ac = ((*p) << 8) + *(p + 1);
|
|
|
|
|
ac |= DNS_KEYFLAG_REVOKE;
|
2019-05-29 09:17:04 -04:00
|
|
|
for (size -= 2, p += 2; size > 1; size -= 2, p += 2) {
|
2011-10-20 17:20:02 -04:00
|
|
|
ac += ((*p) << 8) + *(p + 1);
|
2020-02-13 15:48:23 -05:00
|
|
|
}
|
2011-10-20 17:20:02 -04:00
|
|
|
|
2019-05-29 09:17:04 -04:00
|
|
|
if (size > 0) {
|
2011-10-20 17:20:02 -04:00
|
|
|
ac += ((*p) << 8);
|
2020-02-13 15:48:23 -05:00
|
|
|
}
|
2011-10-20 17:20:02 -04:00
|
|
|
ac += (ac >> 16) & 0xffff;
|
|
|
|
|
|
2018-03-28 08:19:37 -04:00
|
|
|
return (uint16_t)(ac & 0xffff);
|
2011-10-20 17:20:02 -04:00
|
|
|
}
|
|
|
|
|
|
2001-01-16 20:08:08 -05:00
|
|
|
dns_name_t *
|
|
|
|
|
dst_key_name(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->key_name;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
unsigned int
|
|
|
|
|
dst_key_size(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->key_size;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
unsigned int
|
|
|
|
|
dst_key_proto(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->key_proto;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
unsigned int
|
|
|
|
|
dst_key_alg(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->key_alg;
|
|
|
|
|
}
|
|
|
|
|
|
2018-03-28 08:19:37 -04:00
|
|
|
uint32_t
|
2001-01-16 20:08:08 -05:00
|
|
|
dst_key_flags(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->key_flags;
|
|
|
|
|
}
|
|
|
|
|
|
2001-01-23 21:23:02 -05:00
|
|
|
dns_keytag_t
|
2001-01-16 20:08:08 -05:00
|
|
|
dst_key_id(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->key_id;
|
|
|
|
|
}
|
|
|
|
|
|
2011-10-20 17:20:02 -04:00
|
|
|
dns_keytag_t
|
|
|
|
|
dst_key_rid(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->key_rid;
|
|
|
|
|
}
|
|
|
|
|
|
2001-01-16 20:08:08 -05:00
|
|
|
dns_rdataclass_t
|
|
|
|
|
dst_key_class(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->key_class;
|
|
|
|
|
}
|
|
|
|
|
|
2022-03-09 05:33:03 -05:00
|
|
|
const char *
|
|
|
|
|
dst_key_directory(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->directory;
|
|
|
|
|
}
|
|
|
|
|
|
2018-04-17 11:29:14 -04:00
|
|
|
bool
|
2001-01-16 20:08:08 -05:00
|
|
|
dst_key_iszonekey(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
|
|
|
|
|
if ((key->key_flags & DNS_KEYFLAG_OWNERMASK) != DNS_KEYOWNER_ZONE) {
|
2018-04-17 11:29:14 -04:00
|
|
|
return false;
|
2020-02-13 15:48:23 -05:00
|
|
|
}
|
2001-01-16 20:08:08 -05:00
|
|
|
if (key->key_proto != DNS_KEYPROTO_DNSSEC &&
|
2022-11-02 14:33:14 -04:00
|
|
|
key->key_proto != DNS_KEYPROTO_ANY)
|
|
|
|
|
{
|
2018-04-17 11:29:14 -04:00
|
|
|
return false;
|
2020-02-13 15:48:23 -05:00
|
|
|
}
|
2018-04-17 11:29:14 -04:00
|
|
|
return true;
|
2001-01-16 20:08:08 -05:00
|
|
|
}
|
|
|
|
|
|
2018-04-17 11:29:14 -04:00
|
|
|
bool
|
2001-01-16 20:08:08 -05:00
|
|
|
dst_key_isnullkey(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
|
|
|
|
|
if ((key->key_flags & DNS_KEYFLAG_TYPEMASK) != DNS_KEYTYPE_NOKEY) {
|
2018-04-17 11:29:14 -04:00
|
|
|
return false;
|
2020-02-13 15:48:23 -05:00
|
|
|
}
|
2001-01-16 20:08:08 -05:00
|
|
|
if ((key->key_flags & DNS_KEYFLAG_OWNERMASK) != DNS_KEYOWNER_ZONE) {
|
2018-04-17 11:29:14 -04:00
|
|
|
return false;
|
2020-02-13 15:48:23 -05:00
|
|
|
}
|
2001-01-16 20:08:08 -05:00
|
|
|
if (key->key_proto != DNS_KEYPROTO_DNSSEC &&
|
2022-11-02 14:33:14 -04:00
|
|
|
key->key_proto != DNS_KEYPROTO_ANY)
|
|
|
|
|
{
|
2018-04-17 11:29:14 -04:00
|
|
|
return false;
|
2020-02-13 15:48:23 -05:00
|
|
|
}
|
2018-04-17 11:29:14 -04:00
|
|
|
return true;
|
2001-01-16 20:08:08 -05:00
|
|
|
}
|
2005-04-27 00:57:32 -04:00
|
|
|
|
2023-07-11 08:01:36 -04:00
|
|
|
#define REVOKE(x) ((dst_key_flags(x) & DNS_KEYFLAG_REVOKE) != 0)
|
|
|
|
|
#define KSK(x) ((dst_key_flags(x) & DNS_KEYFLAG_KSK) != 0)
|
|
|
|
|
#define ID(x) dst_key_id(x)
|
|
|
|
|
#define ALG(x) dst_key_alg(x)
|
|
|
|
|
|
|
|
|
|
bool
|
|
|
|
|
dst_key_have_ksk_and_zsk(dst_key_t **keys, unsigned int nkeys, unsigned int i,
|
|
|
|
|
bool check_offline, bool ksk, bool zsk, bool *have_ksk,
|
|
|
|
|
bool *have_zsk) {
|
|
|
|
|
bool hksk = ksk;
|
|
|
|
|
bool hzsk = zsk;
|
|
|
|
|
isc_result_t result;
|
|
|
|
|
|
|
|
|
|
REQUIRE(keys != NULL);
|
|
|
|
|
|
|
|
|
|
for (unsigned int j = 0; j < nkeys && !(hksk && hzsk); j++) {
|
|
|
|
|
if (j == i || ALG(keys[i]) != ALG(keys[j])) {
|
|
|
|
|
continue;
|
|
|
|
|
}
|
|
|
|
|
/*
|
|
|
|
|
* Don't consider inactive keys.
|
|
|
|
|
*/
|
|
|
|
|
if (dst_key_inactive(keys[j])) {
|
|
|
|
|
continue;
|
|
|
|
|
}
|
|
|
|
|
/*
|
|
|
|
|
* Don't consider offline keys.
|
|
|
|
|
*/
|
|
|
|
|
if (check_offline && !dst_key_isprivate(keys[j])) {
|
|
|
|
|
continue;
|
|
|
|
|
}
|
|
|
|
|
if (REVOKE(keys[j])) {
|
|
|
|
|
continue;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (!hksk) {
|
|
|
|
|
result = dst_key_getbool(keys[j], DST_BOOL_KSK, &hksk);
|
|
|
|
|
if (result != ISC_R_SUCCESS) {
|
|
|
|
|
if (KSK(keys[j])) {
|
|
|
|
|
hksk = true;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
if (!hzsk) {
|
|
|
|
|
result = dst_key_getbool(keys[j], DST_BOOL_ZSK, &hzsk);
|
|
|
|
|
if (result != ISC_R_SUCCESS) {
|
|
|
|
|
if (!KSK(keys[j])) {
|
|
|
|
|
hzsk = dst_key_isprivate(keys[j]);
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2023-04-06 11:32:16 -04:00
|
|
|
SET_IF_NOT_NULL(have_ksk, hksk);
|
|
|
|
|
SET_IF_NOT_NULL(have_zsk, hzsk);
|
2023-07-11 08:01:36 -04:00
|
|
|
return hksk && hzsk;
|
|
|
|
|
}
|
|
|
|
|
|
2006-01-26 21:35:15 -05:00
|
|
|
void
|
2018-03-28 08:19:37 -04:00
|
|
|
dst_key_setbits(dst_key_t *key, uint16_t bits) {
|
2006-01-26 21:35:15 -05:00
|
|
|
unsigned int maxbits;
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
if (bits != 0) {
|
|
|
|
|
RUNTIME_CHECK(dst_key_sigsize(key, &maxbits) == ISC_R_SUCCESS);
|
|
|
|
|
maxbits *= 8;
|
|
|
|
|
REQUIRE(bits <= maxbits);
|
|
|
|
|
}
|
|
|
|
|
key->key_bits = bits;
|
|
|
|
|
}
|
|
|
|
|
|
2018-03-28 08:19:37 -04:00
|
|
|
uint16_t
|
2006-01-26 21:35:15 -05:00
|
|
|
dst_key_getbits(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->key_bits;
|
|
|
|
|
}
|
|
|
|
|
|
2011-03-16 21:40:40 -04:00
|
|
|
void
|
|
|
|
|
dst_key_setttl(dst_key_t *key, dns_ttl_t ttl) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
key->key_ttl = ttl;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
dns_ttl_t
|
|
|
|
|
dst_key_getttl(const dst_key_t *key) {
|
|
|
|
|
REQUIRE(VALID_KEY(key));
|
|
|
|
|
return key->key_ttl;
|
|
|
|
|
}
|
|
|
|
|
|
2022-03-09 05:33:03 -05:00
|
|
|
void
|
|
|
|
|
dst_key_setdirectory(dst_key_t *key, const char *dir) {
|
|
|
|
|
if (key->directory != NULL) {
|
|
|
|
|
isc_mem_free(key->mctx, key->directory);
|
|
|
|
|
}
|
|
|
|
|
key->directory = isc_mem_strdup(key->mctx, dir);
|
|
|
|
|
}
|
|
|
|
|
|
2005-04-27 00:57:32 -04:00
|
|
|
/*! \file */
|