diff --git a/bin/tests/system/isctest/vars/basic.py b/bin/tests/system/isctest/vars/basic.py index 07709d4ebb..683bb600b7 100644 --- a/bin/tests/system/isctest/vars/basic.py +++ b/bin/tests/system/isctest/vars/basic.py @@ -54,7 +54,6 @@ BASIC_VARS = { "PIPEQUERIES": f"{BUILD_VARS['TOP_BUILDDIR']}/pipequeries", "TMPDIR": os.getenv("TMPDIR", "/tmp"), "KRB5_CONFIG": "/dev/null", # we don't want a KRB5_CONFIG setting breaking the tests - "KRB5_KTNAME": "dns.keytab", # use local keytab instead of default /etc/krb5.keytab "LC_ALL": "C", "ANS_LOG_LEVEL": "debug", "DYLIB": ("dylib" if os.uname().sysname == "Darwin" else "so"), diff --git a/bin/tests/system/nsupdate/ns10/named.conf.in b/bin/tests/system/nsupdate/ns10/named.conf.in index 51a0b4f587..1ba82fa3d9 100644 --- a/bin/tests/system/nsupdate/ns10/named.conf.in +++ b/bin/tests/system/nsupdate/ns10/named.conf.in @@ -26,7 +26,7 @@ options { notify yes; minimal-responses no; dnssec-validation no; - @TKEY_CONFIGURATION@ + tkey-gssapi-keytab "dns.keytab"; }; key rndc_key { diff --git a/bin/tests/system/nsupdate/ns9/named.conf.in b/bin/tests/system/nsupdate/ns9/named.conf.in index 07e38d2d41..7c3141ed4b 100644 --- a/bin/tests/system/nsupdate/ns9/named.conf.in +++ b/bin/tests/system/nsupdate/ns9/named.conf.in @@ -24,7 +24,7 @@ options { notify yes; minimal-responses no; dnssec-validation no; - @TKEY_CONFIGURATION@ + tkey-gssapi-keytab "dns.keytab"; }; key rndc_key { diff --git a/bin/tests/system/nsupdate/setup.sh b/bin/tests/system/nsupdate/setup.sh index 38942ba297..d42af7f1e3 100644 --- a/bin/tests/system/nsupdate/setup.sh +++ b/bin/tests/system/nsupdate/setup.sh @@ -27,23 +27,8 @@ copy_setports ns5/named.conf.in ns5/named.conf copy_setports ns6/named.conf.in ns6/named.conf copy_setports ns7/named1.conf.in ns7/named.conf copy_setports ns8/named.conf.in ns8/named.conf - -# If "tkey-gssapi-credential" is set in the configuration and GSSAPI support is -# not available, named will refuse to start. As the test system framework does -# not support starting named instances conditionally, ensure that -# "tkey-gssapi-credential" is only present in named.conf if GSSAPI support is -# available. -copy_setports ns9/named.conf.in ns9/named.conf.in.tkey -copy_setports ns10/named.conf.in ns10/named.conf.in.tkey -if $FEATURETEST --gssapi; then - sed 's|@TKEY_CONFIGURATION@|tkey-gssapi-credential "DNS/ns9.example.com@EXAMPLE.COM";|' ns9/named.conf.in.tkey >ns9/named.conf - sed 's|@TKEY_CONFIGURATION@|tkey-gssapi-credential "DNS/ns10.example.com@EXAMPLE.COM";|' ns10/named.conf.in.tkey >ns10/named.conf -else - sed 's|@TKEY_CONFIGURATION@||' ns9/named.conf.in.tkey >ns9/named.conf - sed 's|@TKEY_CONFIGURATION@||' ns10/named.conf.in.tkey >ns10/named.conf -fi -rm -f ns9/named.conf.in.tkey -rm -f ns10/named.conf.in.tkey +copy_setports ns9/named.conf.in ns9/named.conf +copy_setports ns10/named.conf.in ns10/named.conf copy_setports verylarge.in verylarge