diff --git a/bin/tests/system/autosign/ns1/named.conf.in b/bin/tests/system/autosign/ns1/named.conf.in index 8c2e86c070..426482d3ba 100644 --- a/bin/tests/system/autosign/ns1/named.conf.in +++ b/bin/tests/system/autosign/ns1/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/autosign/ns2/named.conf.in b/bin/tests/system/autosign/ns2/named.conf.in index 9f0c617f76..b56c294d96 100644 --- a/bin/tests/system/autosign/ns2/named.conf.in +++ b/bin/tests/system/autosign/ns2/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; dnssec-loadkeys-interval 30; }; diff --git a/bin/tests/system/autosign/ns3/named.conf.in b/bin/tests/system/autosign/ns3/named.conf.in index dbb7435511..7f491fef9c 100644 --- a/bin/tests/system/autosign/ns3/named.conf.in +++ b/bin/tests/system/autosign/ns3/named.conf.in @@ -24,7 +24,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; dnssec-loadkeys-interval 10; allow-new-zones yes; diff --git a/bin/tests/system/autosign/ns4/named.conf.in b/bin/tests/system/autosign/ns4/named.conf.in index 5c0d8b603f..de98ac28f6 100644 --- a/bin/tests/system/autosign/ns4/named.conf.in +++ b/bin/tests/system/autosign/ns4/named.conf.in @@ -20,7 +20,6 @@ options { listen-on { 10.53.0.4; }; listen-on-v6 { none; }; recursion yes; - dnssec-enable yes; dnssec-validation yes; dnssec-must-be-secure mustbesecure.example yes; }; diff --git a/bin/tests/system/autosign/ns5/named.conf.in b/bin/tests/system/autosign/ns5/named.conf.in index 5684cee7ef..a271401c4e 100644 --- a/bin/tests/system/autosign/ns5/named.conf.in +++ b/bin/tests/system/autosign/ns5/named.conf.in @@ -20,7 +20,6 @@ options { listen-on { 10.53.0.5; }; listen-on-v6 { none; }; recursion yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/checkconf/dnssec.1 b/bin/tests/system/checkconf/dnssec.1 index 176711fc06..82f4414973 100644 --- a/bin/tests/system/checkconf/dnssec.1 +++ b/bin/tests/system/checkconf/dnssec.1 @@ -11,5 +11,4 @@ options { dnssec-enable no; - dnssec-validation yes; }; diff --git a/bin/tests/system/checkconf/dnssec.2 b/bin/tests/system/checkconf/dnssec.2 index 64db848ab1..edef76fde7 100644 --- a/bin/tests/system/checkconf/dnssec.2 +++ b/bin/tests/system/checkconf/dnssec.2 @@ -9,10 +9,6 @@ * information regarding copyright ownership. */ -options { - dnssec-enable no; -}; - view view1 { match-clients { any; }; dnssec-validation yes; diff --git a/bin/tests/system/checkconf/dnssec.3 b/bin/tests/system/checkconf/dnssec.3 index fbb5882deb..a48d9c97a1 100644 --- a/bin/tests/system/checkconf/dnssec.3 +++ b/bin/tests/system/checkconf/dnssec.3 @@ -9,18 +9,12 @@ * information regarding copyright ownership. */ -options { - dnssec-validation no; -}; - view view1 { match-clients { any; }; - dnssec-enable no; }; view view2 { match-clients { none; }; - dnssec-enable yes; }; view view3 { diff --git a/bin/tests/system/checkconf/tests.sh b/bin/tests/system/checkconf/tests.sh index ec3bc04e1b..fa6c4da16b 100644 --- a/bin/tests/system/checkconf/tests.sh +++ b/bin/tests/system/checkconf/tests.sh @@ -111,11 +111,11 @@ status=`expr $status + $ret` n=`expr $n + 1` echo_i "checking named-checkconf dnssec warnings ($n)" ret=0 -$CHECKCONF dnssec.1 2>&1 | grep 'validation yes.*enable no' > /dev/null || ret=1 +# dnssec.1: dnssec-enable is obsolete +$CHECKCONF dnssec.1 2>&1 | grep "'dnssec-enable' is obsolete and should be removed" > /dev/null || ret=1 +# dnssec.2: auto-dnssec warning $CHECKCONF dnssec.2 2>&1 | grep 'auto-dnssec may only be ' > /dev/null || ret=1 -$CHECKCONF dnssec.2 2>&1 | grep 'validation auto.*enable no' > /dev/null || ret=1 -$CHECKCONF dnssec.2 2>&1 | grep 'validation yes.*enable no' > /dev/null || ret=1 -# this one should have no warnings +# dnssec.3: should have no warnings $CHECKCONF dnssec.3 2>&1 | grep '.*' && ret=1 if [ $ret != 0 ]; then echo_i "failed"; fi status=`expr $status + $ret` diff --git a/bin/tests/system/database/ns1/named1.conf.in b/bin/tests/system/database/ns1/named1.conf.in index 8fa82ae050..b6c838ac2d 100644 --- a/bin/tests/system/database/ns1/named1.conf.in +++ b/bin/tests/system/database/ns1/named1.conf.in @@ -30,7 +30,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/database/ns1/named2.conf.in b/bin/tests/system/database/ns1/named2.conf.in index 8238f548b7..8b0c3f1938 100644 --- a/bin/tests/system/database/ns1/named2.conf.in +++ b/bin/tests/system/database/ns1/named2.conf.in @@ -30,7 +30,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/digdelv/ns1/named.conf.in b/bin/tests/system/digdelv/ns1/named.conf.in index 92acac9f4a..066e453d76 100644 --- a/bin/tests/system/digdelv/ns1/named.conf.in +++ b/bin/tests/system/digdelv/ns1/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { fd92:7065:b8e:ffff::1; }; recursion no; notify yes; - dnssec-enable no; dnssec-validation no; }; diff --git a/bin/tests/system/digdelv/ns2/named.conf.in b/bin/tests/system/digdelv/ns2/named.conf.in index 98bc5ac38e..8dafd87b3d 100644 --- a/bin/tests/system/digdelv/ns2/named.conf.in +++ b/bin/tests/system/digdelv/ns2/named.conf.in @@ -18,7 +18,6 @@ options { listen-on { 10.53.0.2; }; listen-on-v6 { fd92:7065:b8e:ffff::2; }; recursion no; - dnssec-enable no; dnssec-validation no; }; diff --git a/bin/tests/system/digdelv/ns3/named.conf.in b/bin/tests/system/digdelv/ns3/named.conf.in index b18b44413b..5017085f70 100644 --- a/bin/tests/system/digdelv/ns3/named.conf.in +++ b/bin/tests/system/digdelv/ns3/named.conf.in @@ -16,7 +16,6 @@ options { listen-on { 10.53.0.3; }; listen-on-v6 { fd92:7065:b8e:ffff::3; }; recursion yes; - dnssec-enable no; dnssec-validation no; server-id "ns3"; }; diff --git a/bin/tests/system/dlv/ns1/named.conf.in b/bin/tests/system/dlv/ns1/named.conf.in index 337558f955..e628dbe36d 100644 --- a/bin/tests/system/dlv/ns1/named.conf.in +++ b/bin/tests/system/dlv/ns1/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; }; zone "." { type master; file "root.signed"; }; diff --git a/bin/tests/system/dlv/ns2/named.conf.in b/bin/tests/system/dlv/ns2/named.conf.in index b08bd13a03..a098365ab5 100644 --- a/bin/tests/system/dlv/ns2/named.conf.in +++ b/bin/tests/system/dlv/ns2/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; }; zone "." { type hint; file "hints"; }; diff --git a/bin/tests/system/dlv/ns3/named.conf.in b/bin/tests/system/dlv/ns3/named.conf.in index 42d712b229..7a9b44d2e9 100644 --- a/bin/tests/system/dlv/ns3/named.conf.in +++ b/bin/tests/system/dlv/ns3/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; }; zone "." { type hint; file "hints"; }; diff --git a/bin/tests/system/dlv/ns4/named.conf.in b/bin/tests/system/dlv/ns4/named.conf.in index 805b5f3335..a98dd6b92b 100644 --- a/bin/tests/system/dlv/ns4/named.conf.in +++ b/bin/tests/system/dlv/ns4/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable no; }; zone "." { type hint; file "hints"; }; diff --git a/bin/tests/system/dlv/ns5/named.conf.in b/bin/tests/system/dlv/ns5/named.conf.in index 11c6041fb9..489306e3c7 100644 --- a/bin/tests/system/dlv/ns5/named.conf.in +++ b/bin/tests/system/dlv/ns5/named.conf.in @@ -22,7 +22,6 @@ options { listen-on-v6 { none; }; recursion yes; notify yes; - dnssec-enable yes; dnssec-validation yes; dnssec-lookaside "." trust-anchor "dlv.utld"; }; diff --git a/bin/tests/system/dlv/ns6/named.conf.in b/bin/tests/system/dlv/ns6/named.conf.in index fe5c68df6d..15583c2a4c 100644 --- a/bin/tests/system/dlv/ns6/named.conf.in +++ b/bin/tests/system/dlv/ns6/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; }; zone "." { type hint; file "hints"; }; diff --git a/bin/tests/system/dns64/ns1/named.conf.in b/bin/tests/system/dns64/ns1/named.conf.in index d8faa1137d..778c0bc9a5 100644 --- a/bin/tests/system/dns64/ns1/named.conf.in +++ b/bin/tests/system/dns64/ns1/named.conf.in @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; allow-recursion { 10.53.0.1; }; notify yes; - dnssec-enable yes; dnssec-validation yes; dns64 2001:bbbb::/96 { diff --git a/bin/tests/system/dns64/ns2/named.conf.in b/bin/tests/system/dns64/ns2/named.conf.in index 070fdecb38..386a9d740b 100644 --- a/bin/tests/system/dns64/ns2/named.conf.in +++ b/bin/tests/system/dns64/ns2/named.conf.in @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; recursion yes; notify yes; - dnssec-enable yes; dnssec-validation yes; dns64 2001:aaaa::/96 { diff --git a/bin/tests/system/dnssec/ns1/named.conf.in b/bin/tests/system/dnssec/ns1/named.conf.in index 4401f59561..68d7993a2b 100644 --- a/bin/tests/system/dnssec/ns1/named.conf.in +++ b/bin/tests/system/dnssec/ns1/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; /* test that we can turn off trust-anchor-telemetry */ trust-anchor-telemetry no; diff --git a/bin/tests/system/dnssec/ns2/named.conf.in b/bin/tests/system/dnssec/ns2/named.conf.in index 4f05632818..558eaecf49 100644 --- a/bin/tests/system/dnssec/ns2/named.conf.in +++ b/bin/tests/system/dnssec/ns2/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; notify-delay 1; minimal-responses no; diff --git a/bin/tests/system/dnssec/ns3/named.conf.in b/bin/tests/system/dnssec/ns3/named.conf.in index fc43832b4e..18268d7975 100644 --- a/bin/tests/system/dnssec/ns3/named.conf.in +++ b/bin/tests/system/dnssec/ns3/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; session-keyfile "session.key"; minimal-responses no; diff --git a/bin/tests/system/dnssec/ns4/named1.conf.in b/bin/tests/system/dnssec/ns4/named1.conf.in index f74a4058ce..9559a00c01 100644 --- a/bin/tests/system/dnssec/ns4/named1.conf.in +++ b/bin/tests/system/dnssec/ns4/named1.conf.in @@ -20,7 +20,6 @@ options { listen-on { 10.53.0.4; }; listen-on-v6 { none; }; recursion yes; - dnssec-enable yes; dnssec-validation yes; dnssec-must-be-secure mustbesecure.example yes; minimal-responses no; diff --git a/bin/tests/system/dnssec/ns4/named2.conf.in b/bin/tests/system/dnssec/ns4/named2.conf.in index 50025ac8cf..f1ec362032 100644 --- a/bin/tests/system/dnssec/ns4/named2.conf.in +++ b/bin/tests/system/dnssec/ns4/named2.conf.in @@ -21,7 +21,6 @@ options { listen-on { 10.53.0.4; }; listen-on-v6 { none; }; recursion yes; - dnssec-enable yes; dnssec-validation auto; bindkeys-file "managed.conf"; minimal-responses no; diff --git a/bin/tests/system/dnssec/ns4/named3.conf.in b/bin/tests/system/dnssec/ns4/named3.conf.in index b0ac3cce76..097ed33de4 100644 --- a/bin/tests/system/dnssec/ns4/named3.conf.in +++ b/bin/tests/system/dnssec/ns4/named3.conf.in @@ -20,7 +20,6 @@ options { listen-on { 10.53.0.4; }; listen-on-v6 { none; }; recursion yes; - dnssec-enable yes; dnssec-validation auto; bindkeys-file "managed.conf"; dnssec-accept-expired yes; diff --git a/bin/tests/system/dnssec/ns4/named5.conf.in b/bin/tests/system/dnssec/ns4/named5.conf.in index 4ec428f07a..7ab0eb6946 100644 --- a/bin/tests/system/dnssec/ns4/named5.conf.in +++ b/bin/tests/system/dnssec/ns4/named5.conf.in @@ -20,7 +20,6 @@ options { listen-on { 10.53.0.4; }; listen-on-v6 { none; }; bindkeys-file "managed.conf"; - dnssec-enable no; }; key rndc_key { diff --git a/bin/tests/system/dnssec/ns5/named1.conf.in b/bin/tests/system/dnssec/ns5/named1.conf.in index 2883d50bad..62d43b5ff7 100644 --- a/bin/tests/system/dnssec/ns5/named1.conf.in +++ b/bin/tests/system/dnssec/ns5/named1.conf.in @@ -20,7 +20,6 @@ options { listen-on { 10.53.0.5; }; listen-on-v6 { none; }; recursion yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/dnssec/ns6/named.conf.in b/bin/tests/system/dnssec/ns6/named.conf.in index 57e6b57fed..61a7cce5a4 100644 --- a/bin/tests/system/dnssec/ns6/named.conf.in +++ b/bin/tests/system/dnssec/ns6/named.conf.in @@ -22,7 +22,6 @@ options { recursion yes; notify yes; disable-algorithms . { @ALTERNATIVE_ALGORITHM@; }; - dnssec-enable yes; dnssec-validation yes; dnssec-lookaside . trust-anchor dlv; }; diff --git a/bin/tests/system/dnssec/ns7/named.conf.in b/bin/tests/system/dnssec/ns7/named.conf.in index 2dc2a9cc90..31e3f85cdc 100644 --- a/bin/tests/system/dnssec/ns7/named.conf.in +++ b/bin/tests/system/dnssec/ns7/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; minimal-responses yes; }; diff --git a/bin/tests/system/dnssec/tests.sh b/bin/tests/system/dnssec/tests.sh index de4d42d948..5fbc31f923 100644 --- a/bin/tests/system/dnssec/tests.sh +++ b/bin/tests/system/dnssec/tests.sh @@ -3648,20 +3648,5 @@ n=$((n+1)) test "$ret" -eq 0 || echo_i "failed" status=$((status+ret)) -# Note: after this check, ns4 will not be validating any more; do not add any -# further validation tests employing ns4 below this check. -echo_i "check that validation defaults to off when dnssec-enable is off ($n)" -ret=0 -# Sanity check - validation should be enabled. -rndccmd 10.53.0.4 validation status | grep "enabled" > /dev/null || ret=1 -# Set "dnssec-enable" to "no" and reconfigure. -copy_setports ns4/named5.conf.in ns4/named.conf -rndccmd 10.53.0.4 reconfig 2>&1 | sed 's/^/ns4 /' | cat_i -# Check validation status again. -rndccmd 10.53.0.4 validation status | grep "disabled" > /dev/null || ret=1 -n=$((n+1)) -test "$ret" -eq 0 || echo_i "failed" -status=$((status+ret)) - echo_i "exit status: $status" [ $status -eq 0 ] || exit 1 diff --git a/bin/tests/system/dsdigest/ns1/named.conf.in b/bin/tests/system/dsdigest/ns1/named.conf.in index 215800cab0..88a2547935 100644 --- a/bin/tests/system/dsdigest/ns1/named.conf.in +++ b/bin/tests/system/dsdigest/ns1/named.conf.in @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/dsdigest/ns2/named.conf.in b/bin/tests/system/dsdigest/ns2/named.conf.in index 73a41ba8d7..6510dd5e92 100644 --- a/bin/tests/system/dsdigest/ns2/named.conf.in +++ b/bin/tests/system/dsdigest/ns2/named.conf.in @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/dsdigest/ns3/named.conf.in b/bin/tests/system/dsdigest/ns3/named.conf.in index 04b4a5e93a..97bfe26687 100644 --- a/bin/tests/system/dsdigest/ns3/named.conf.in +++ b/bin/tests/system/dsdigest/ns3/named.conf.in @@ -22,7 +22,6 @@ options { listen-on { 10.53.0.3; }; listen-on-v6 { none; }; recursion yes; - dnssec-enable yes; dnssec-validation yes; dnssec-must-be-secure . yes; /* only SHA-256 is enabled */ diff --git a/bin/tests/system/dsdigest/ns4/named.conf.in b/bin/tests/system/dsdigest/ns4/named.conf.in index 5047a287d3..91f21a6e01 100644 --- a/bin/tests/system/dsdigest/ns4/named.conf.in +++ b/bin/tests/system/dsdigest/ns4/named.conf.in @@ -22,7 +22,6 @@ options { listen-on { 10.53.0.4; }; listen-on-v6 { none; }; recursion yes; - dnssec-enable yes; dnssec-validation yes; /* only SHA-256 is enabled */ disable-ds-digests . { SHA-1; SHA-384; 5; 6; 7; 8; 9; }; diff --git a/bin/tests/system/ecdsa/ns1/named.conf b/bin/tests/system/ecdsa/ns1/named.conf index 715f7d3f76..50eb048408 100644 --- a/bin/tests/system/ecdsa/ns1/named.conf +++ b/bin/tests/system/ecdsa/ns1/named.conf @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/ecdsa/ns2/named.conf b/bin/tests/system/ecdsa/ns2/named.conf index 50621a53f1..420073fc05 100644 --- a/bin/tests/system/ecdsa/ns2/named.conf +++ b/bin/tests/system/ecdsa/ns2/named.conf @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; recursion yes; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/eddsa/ns1/named.conf b/bin/tests/system/eddsa/ns1/named.conf index 715f7d3f76..50eb048408 100644 --- a/bin/tests/system/eddsa/ns1/named.conf +++ b/bin/tests/system/eddsa/ns1/named.conf @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/eddsa/ns2/named.conf b/bin/tests/system/eddsa/ns2/named.conf index 50621a53f1..420073fc05 100644 --- a/bin/tests/system/eddsa/ns2/named.conf +++ b/bin/tests/system/eddsa/ns2/named.conf @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; recursion yes; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/idna/ns1/named.conf.in b/bin/tests/system/idna/ns1/named.conf.in index 92acac9f4a..066e453d76 100644 --- a/bin/tests/system/idna/ns1/named.conf.in +++ b/bin/tests/system/idna/ns1/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { fd92:7065:b8e:ffff::1; }; recursion no; notify yes; - dnssec-enable no; dnssec-validation no; }; diff --git a/bin/tests/system/inline/ns1/named.conf.in b/bin/tests/system/inline/ns1/named.conf.in index 215800cab0..88a2547935 100644 --- a/bin/tests/system/inline/ns1/named.conf.in +++ b/bin/tests/system/inline/ns1/named.conf.in @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/masterfile/ns2/named.conf.in b/bin/tests/system/masterfile/ns2/named.conf.in index 96e7978c43..33201e4e38 100644 --- a/bin/tests/system/masterfile/ns2/named.conf.in +++ b/bin/tests/system/masterfile/ns2/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/masterformat/ns1/named.conf.in b/bin/tests/system/masterformat/ns1/named.conf.in index e986041d2b..c1d92b7ffb 100644 --- a/bin/tests/system/masterformat/ns1/named.conf.in +++ b/bin/tests/system/masterformat/ns1/named.conf.in @@ -18,7 +18,6 @@ options { listen-on-v6 { none; }; recursion no; notify no; - dnssec-enable yes; session-keyfile "session.key"; servfail-ttl 0; }; diff --git a/bin/tests/system/masterformat/ns2/named.conf.in b/bin/tests/system/masterformat/ns2/named.conf.in index ae28603207..fb519466f4 100644 --- a/bin/tests/system/masterformat/ns2/named.conf.in +++ b/bin/tests/system/masterformat/ns2/named.conf.in @@ -18,7 +18,6 @@ options { port @PORT@; recursion no; notify no; - dnssec-enable yes; servfail-ttl 0; }; diff --git a/bin/tests/system/masterformat/ns3/named.conf.in b/bin/tests/system/masterformat/ns3/named.conf.in index f41dc2e837..032505a300 100644 --- a/bin/tests/system/masterformat/ns3/named.conf.in +++ b/bin/tests/system/masterformat/ns3/named.conf.in @@ -18,7 +18,6 @@ options { listen-on-v6 { none; }; recursion no; notify no; - dnssec-enable yes; }; key rndc_key { diff --git a/bin/tests/system/mkeys/ns1/named1.conf.in b/bin/tests/system/mkeys/ns1/named1.conf.in index 412556b5c8..807cd00e90 100644 --- a/bin/tests/system/mkeys/ns1/named1.conf.in +++ b/bin/tests/system/mkeys/ns1/named1.conf.in @@ -26,7 +26,6 @@ options { listen-on-v6 { none; }; recursion no; notify no; - dnssec-enable yes; dnssec-validation yes; allow-query { allowed; }; }; diff --git a/bin/tests/system/mkeys/ns1/named2.conf.in b/bin/tests/system/mkeys/ns1/named2.conf.in index 5cb096b084..b9aae000e2 100644 --- a/bin/tests/system/mkeys/ns1/named2.conf.in +++ b/bin/tests/system/mkeys/ns1/named2.conf.in @@ -26,7 +26,6 @@ options { listen-on-v6 { none; }; recursion no; notify no; - dnssec-enable yes; dnssec-validation yes; allow-query { allowed; }; }; diff --git a/bin/tests/system/mkeys/ns1/named3.conf.in b/bin/tests/system/mkeys/ns1/named3.conf.in index a0f1dd36c9..9f563ad6a3 100644 --- a/bin/tests/system/mkeys/ns1/named3.conf.in +++ b/bin/tests/system/mkeys/ns1/named3.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify no; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/mkeys/ns2/named.conf.in b/bin/tests/system/mkeys/ns2/named.conf.in index 9076243446..d87bf18c51 100644 --- a/bin/tests/system/mkeys/ns2/named.conf.in +++ b/bin/tests/system/mkeys/ns2/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify no; - dnssec-enable yes; dnssec-validation auto; bindkeys-file "managed.conf"; servfail-ttl 0; diff --git a/bin/tests/system/mkeys/ns3/named.conf.in b/bin/tests/system/mkeys/ns3/named.conf.in index 0227aba024..6720b3a632 100644 --- a/bin/tests/system/mkeys/ns3/named.conf.in +++ b/bin/tests/system/mkeys/ns3/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify no; - dnssec-enable yes; dnssec-validation yes; bindkeys-file "managed.conf"; trust-anchor-telemetry no; diff --git a/bin/tests/system/mkeys/ns4/named.conf.in b/bin/tests/system/mkeys/ns4/named.conf.in index ab3844496a..e0adc97a51 100644 --- a/bin/tests/system/mkeys/ns4/named.conf.in +++ b/bin/tests/system/mkeys/ns4/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify no; - dnssec-enable yes; dnssec-validation auto; bindkeys-file "managed.conf"; managed-keys-directory "nope"; diff --git a/bin/tests/system/mkeys/ns5/named.conf.in b/bin/tests/system/mkeys/ns5/named.conf.in index 6314888979..91f56138e7 100644 --- a/bin/tests/system/mkeys/ns5/named.conf.in +++ b/bin/tests/system/mkeys/ns5/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify no; - dnssec-enable yes; dnssec-validation auto; bindkeys-file "managed.conf"; servfail-ttl 0; diff --git a/bin/tests/system/mkeys/ns6/named.conf.in b/bin/tests/system/mkeys/ns6/named.conf.in index 8d76f7f2e7..23eb115be2 100644 --- a/bin/tests/system/mkeys/ns6/named.conf.in +++ b/bin/tests/system/mkeys/ns6/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify no; - dnssec-enable yes; dnssec-validation yes; trust-anchor-telemetry no; }; diff --git a/bin/tests/system/mkeys/ns7/named.conf.in b/bin/tests/system/mkeys/ns7/named.conf.in index a9aba00733..59959368aa 100644 --- a/bin/tests/system/mkeys/ns7/named.conf.in +++ b/bin/tests/system/mkeys/ns7/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify no; - dnssec-enable yes; dnssec-validation auto; bindkeys-file "managed.conf"; }; diff --git a/bin/tests/system/nsupdate/ns3/named.conf.in b/bin/tests/system/nsupdate/ns3/named.conf.in index e5b414f67c..504d6ebaa3 100644 --- a/bin/tests/system/nsupdate/ns3/named.conf.in +++ b/bin/tests/system/nsupdate/ns3/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/pending/ns2/named.conf.in b/bin/tests/system/pending/ns2/named.conf.in index df2e168272..ef066e3289 100644 --- a/bin/tests/system/pending/ns2/named.conf.in +++ b/bin/tests/system/pending/ns2/named.conf.in @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/pending/ns3/named.conf.in b/bin/tests/system/pending/ns3/named.conf.in index 97129c93dd..a701e8d2e3 100644 --- a/bin/tests/system/pending/ns3/named.conf.in +++ b/bin/tests/system/pending/ns3/named.conf.in @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; recursion no; notify no; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/redirect/ns1/named.conf.in b/bin/tests/system/redirect/ns1/named.conf.in index 47b385a8fc..8a61776b07 100644 --- a/bin/tests/system/redirect/ns1/named.conf.in +++ b/bin/tests/system/redirect/ns1/named.conf.in @@ -23,7 +23,6 @@ options { listen-on-v6 { none; }; allow-recursion { 10.53.0.1; }; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/redirect/ns2/named.conf.in b/bin/tests/system/redirect/ns2/named.conf.in index 3e897900af..0ab3bab559 100644 --- a/bin/tests/system/redirect/ns2/named.conf.in +++ b/bin/tests/system/redirect/ns2/named.conf.in @@ -25,7 +25,6 @@ options { listen-on-v6 { none; }; recursion yes; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/redirect/ns3/named.conf.in b/bin/tests/system/redirect/ns3/named.conf.in index 04a651b065..feab73cb12 100644 --- a/bin/tests/system/redirect/ns3/named.conf.in +++ b/bin/tests/system/redirect/ns3/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; allow-recursion { 10.53.0.3; }; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/redirect/ns4/named.conf.in b/bin/tests/system/redirect/ns4/named.conf.in index 70f0df07f6..8e9a0afd19 100644 --- a/bin/tests/system/redirect/ns4/named.conf.in +++ b/bin/tests/system/redirect/ns4/named.conf.in @@ -25,7 +25,6 @@ options { listen-on-v6 { none; }; recursion yes; notify yes; - dnssec-enable yes; dnssec-validation yes; nxdomain-redirect "redirect"; diff --git a/bin/tests/system/rootkeysentinel/ns1/named.conf.in b/bin/tests/system/rootkeysentinel/ns1/named.conf.in index 6312ca1621..1cdab00a4b 100644 --- a/bin/tests/system/rootkeysentinel/ns1/named.conf.in +++ b/bin/tests/system/rootkeysentinel/ns1/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/rootkeysentinel/ns2/named.conf.in b/bin/tests/system/rootkeysentinel/ns2/named.conf.in index 2da0567cd5..4ab4edaec5 100644 --- a/bin/tests/system/rootkeysentinel/ns2/named.conf.in +++ b/bin/tests/system/rootkeysentinel/ns2/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/rootkeysentinel/ns3/named.conf.in b/bin/tests/system/rootkeysentinel/ns3/named.conf.in index ea118ce4e5..68cb81500f 100644 --- a/bin/tests/system/rootkeysentinel/ns3/named.conf.in +++ b/bin/tests/system/rootkeysentinel/ns3/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { none; }; recursion yes; notify yes; - dnssec-enable yes; dnssec-validation yes; root-key-sentinel yes; }; diff --git a/bin/tests/system/rootkeysentinel/ns4/named.conf.in b/bin/tests/system/rootkeysentinel/ns4/named.conf.in index 3a42b3f448..5c18751e73 100644 --- a/bin/tests/system/rootkeysentinel/ns4/named.conf.in +++ b/bin/tests/system/rootkeysentinel/ns4/named.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { none; }; recursion yes; notify yes; - dnssec-enable yes; dnssec-validation yes; root-key-sentinel no; }; diff --git a/bin/tests/system/rsabigexponent/ns1/named.conf.in b/bin/tests/system/rsabigexponent/ns1/named.conf.in index a43c02bc48..95e7bd6312 100644 --- a/bin/tests/system/rsabigexponent/ns1/named.conf.in +++ b/bin/tests/system/rsabigexponent/ns1/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/rsabigexponent/ns2/named.conf.in b/bin/tests/system/rsabigexponent/ns2/named.conf.in index 2e8eb7aa91..b7963e50a7 100644 --- a/bin/tests/system/rsabigexponent/ns2/named.conf.in +++ b/bin/tests/system/rsabigexponent/ns2/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; }; zone "." { diff --git a/bin/tests/system/rsabigexponent/ns3/named.conf.in b/bin/tests/system/rsabigexponent/ns3/named.conf.in index 99d2a0d3fc..34495937c4 100644 --- a/bin/tests/system/rsabigexponent/ns3/named.conf.in +++ b/bin/tests/system/rsabigexponent/ns3/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify yes; - dnssec-enable yes; dnssec-validation yes; max-rsa-exponent-size 35; }; diff --git a/bin/tests/system/runtime/ns2/named-alt1.conf.in b/bin/tests/system/runtime/ns2/named-alt1.conf.in index aab555fc2d..bc0693e2b6 100644 --- a/bin/tests/system/runtime/ns2/named-alt1.conf.in +++ b/bin/tests/system/runtime/ns2/named-alt1.conf.in @@ -19,6 +19,5 @@ options { listen-on-v6 { fd92:7065:b8e:ffff::2; }; recursion no; notify yes; - dnssec-enable no; dnssec-validation no; }; diff --git a/bin/tests/system/runtime/ns2/named-alt2.conf.in b/bin/tests/system/runtime/ns2/named-alt2.conf.in index a513383616..fb8e40288f 100644 --- a/bin/tests/system/runtime/ns2/named-alt2.conf.in +++ b/bin/tests/system/runtime/ns2/named-alt2.conf.in @@ -19,6 +19,5 @@ options { listen-on-v6 { fd92:7065:b8e:ffff::2; }; recursion no; notify yes; - dnssec-enable no; dnssec-validation no; }; diff --git a/bin/tests/system/runtime/ns2/named-alt3.conf.in b/bin/tests/system/runtime/ns2/named-alt3.conf.in index a1cf6145c1..3cb5c09d6a 100644 --- a/bin/tests/system/runtime/ns2/named-alt3.conf.in +++ b/bin/tests/system/runtime/ns2/named-alt3.conf.in @@ -20,6 +20,5 @@ options { listen-on-v6 { fd92:7065:b8e:ffff::2; }; recursion no; notify yes; - dnssec-enable no; dnssec-validation no; }; diff --git a/bin/tests/system/runtime/ns2/named1.conf.in b/bin/tests/system/runtime/ns2/named1.conf.in index 7eb7f6c615..5df31515f6 100644 --- a/bin/tests/system/runtime/ns2/named1.conf.in +++ b/bin/tests/system/runtime/ns2/named1.conf.in @@ -19,7 +19,6 @@ options { listen-on-v6 { fd92:7065:b8e:ffff::2; }; recursion no; notify yes; - dnssec-enable no; dnssec-validation no; }; diff --git a/bin/tests/system/sfcache/ns1/named.conf.in b/bin/tests/system/sfcache/ns1/named.conf.in index a43c02bc48..95e7bd6312 100644 --- a/bin/tests/system/sfcache/ns1/named.conf.in +++ b/bin/tests/system/sfcache/ns1/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/sfcache/ns2/named.conf.in b/bin/tests/system/sfcache/ns2/named.conf.in index 693ee05f67..12eabe39cf 100644 --- a/bin/tests/system/sfcache/ns2/named.conf.in +++ b/bin/tests/system/sfcache/ns2/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/sfcache/ns5/named.conf.in b/bin/tests/system/sfcache/ns5/named.conf.in index f5f0db76c8..b601a52636 100644 --- a/bin/tests/system/sfcache/ns5/named.conf.in +++ b/bin/tests/system/sfcache/ns5/named.conf.in @@ -20,7 +20,6 @@ options { listen-on { 10.53.0.5; }; listen-on-v6 { none; }; recursion yes; - dnssec-enable yes; dnssec-validation yes; servfail-ttl 30; }; diff --git a/bin/tests/system/synthfromdnssec/ns1/named.conf.in b/bin/tests/system/synthfromdnssec/ns1/named.conf.in index 650cc30f08..cb0c0c372b 100644 --- a/bin/tests/system/synthfromdnssec/ns1/named.conf.in +++ b/bin/tests/system/synthfromdnssec/ns1/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/synthfromdnssec/ns2/named.conf.in b/bin/tests/system/synthfromdnssec/ns2/named.conf.in index 351b40eafd..b130d305d3 100644 --- a/bin/tests/system/synthfromdnssec/ns2/named.conf.in +++ b/bin/tests/system/synthfromdnssec/ns2/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify no; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/synthfromdnssec/ns3/named.conf.in b/bin/tests/system/synthfromdnssec/ns3/named.conf.in index 8d7650628a..5a8fbd6718 100644 --- a/bin/tests/system/synthfromdnssec/ns3/named.conf.in +++ b/bin/tests/system/synthfromdnssec/ns3/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify no; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/synthfromdnssec/ns4/named.conf.in b/bin/tests/system/synthfromdnssec/ns4/named.conf.in index 9189e58493..042c6cf0b6 100644 --- a/bin/tests/system/synthfromdnssec/ns4/named.conf.in +++ b/bin/tests/system/synthfromdnssec/ns4/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify no; - dnssec-enable yes; dnssec-validation yes; synth-from-dnssec no; }; diff --git a/bin/tests/system/synthfromdnssec/ns5/named.conf.in b/bin/tests/system/synthfromdnssec/ns5/named.conf.in index 9cbf91c03f..90b83a6432 100644 --- a/bin/tests/system/synthfromdnssec/ns5/named.conf.in +++ b/bin/tests/system/synthfromdnssec/ns5/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion yes; notify no; - dnssec-enable yes; dnssec-validation yes; synth-from-dnssec yes; }; diff --git a/bin/tests/system/wildcard/ns1/named.conf.in b/bin/tests/system/wildcard/ns1/named.conf.in index 3a54d275cd..092ae79fde 100644 --- a/bin/tests/system/wildcard/ns1/named.conf.in +++ b/bin/tests/system/wildcard/ns1/named.conf.in @@ -20,7 +20,6 @@ options { recursion no; dnssec-validation no; notify yes; - dnssec-enable yes; }; zone "." { type master; file "root.db.signed"; }; diff --git a/bin/tests/system/zonechecks/ns1/named.conf.in b/bin/tests/system/zonechecks/ns1/named.conf.in index cd60ba32f2..719535d786 100644 --- a/bin/tests/system/zonechecks/ns1/named.conf.in +++ b/bin/tests/system/zonechecks/ns1/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; }; diff --git a/bin/tests/system/zonechecks/ns2/named.conf.in b/bin/tests/system/zonechecks/ns2/named.conf.in index be847feaff..cd0f7ec24b 100644 --- a/bin/tests/system/zonechecks/ns2/named.conf.in +++ b/bin/tests/system/zonechecks/ns2/named.conf.in @@ -21,7 +21,6 @@ options { listen-on-v6 { none; }; recursion no; notify yes; - dnssec-enable yes; dnssec-validation yes; };