bind9/bin/dnssec
Tony Finch d8f2eb249a Deprecate SHA-1 DS digests in dnssec-signzone
This affects two cases:

  * When writing a `dsset` file for this zone, to be used by its
    parent, only write a SHA-256 DS record.

  * When reading a `keyset` file for a child, to generate DS records
    to include in this zone, generate SHA-256 DS records only.

This change does not affect digests used in CDS records.

This is for conformance with the DS/CDS algorithm requirements in
https://tools.ietf.org/html/draft-ietf-dnsop-algorithm-update
2019-05-08 18:17:55 -07:00
..
win32 Convert *.vcxproj.user to CRLF line endings 2019-03-08 18:01:48 +01:00
.gitignore [master] dnssec-cds 2017-10-05 01:04:18 -07:00
dnssec-cds.8 prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-cds.c Deprecate SHA-1 in dnssec-dsfromkey 2019-05-08 18:17:55 -07:00
dnssec-cds.docbook cleanup: revamp the dnssec-dsfromkey man page and help output 2019-02-05 19:02:18 -08:00
dnssec-cds.html prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-dsfromkey.8 prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-dsfromkey.c Deprecate SHA-1 in dnssec-dsfromkey 2019-05-08 18:17:55 -07:00
dnssec-dsfromkey.docbook Deprecate SHA-1 in dnssec-dsfromkey 2019-05-08 18:17:55 -07:00
dnssec-dsfromkey.html prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-importkey.8 prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-importkey.c bin/dnssec: move a little boilerplate into shared code 2019-05-08 18:17:55 -07:00
dnssec-importkey.docbook update copyrights 2019-01-02 10:20:43 +11:00
dnssec-importkey.html prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-keyfromlabel.8 prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-keyfromlabel.c bin/dnssec: move a little boilerplate into shared code 2019-05-08 18:17:55 -07:00
dnssec-keyfromlabel.docbook update copyrights 2019-01-02 10:20:43 +11:00
dnssec-keyfromlabel.html prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-keygen.8 prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-keygen.c bin/dnssec: move a little boilerplate into shared code 2019-05-08 18:17:55 -07:00
dnssec-keygen.docbook A bit more cleanup in the dnssec-keygen manual 2019-03-14 13:22:01 +11:00
dnssec-keygen.html prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-revoke.8 prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-revoke.c bin/dnssec: move a little boilerplate into shared code 2019-05-08 18:17:55 -07:00
dnssec-revoke.docbook update copyrights 2019-01-02 10:20:43 +11:00
dnssec-revoke.html prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-settime.8 prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-settime.c bin/dnssec: move a little boilerplate into shared code 2019-05-08 18:17:55 -07:00
dnssec-settime.docbook update copyrights 2019-01-02 10:20:43 +11:00
dnssec-settime.html prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-signzone.8 prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-signzone.c Deprecate SHA-1 DS digests in dnssec-signzone 2019-05-08 18:17:55 -07:00
dnssec-signzone.docbook update copyrights 2019-01-02 10:20:43 +11:00
dnssec-signzone.html prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-verify.8 prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssec-verify.c bin/dnssec: move a little boilerplate into shared code 2019-05-08 18:17:55 -07:00
dnssec-verify.docbook update copyrights 2019-01-02 10:20:43 +11:00
dnssec-verify.html prep 9.13.6 2019-02-06 22:13:05 +00:00
dnssectool.c Deprecate SHA-1 in dnssec-dsfromkey 2019-05-08 18:17:55 -07:00
dnssectool.h Deprecate SHA-1 in dnssec-dsfromkey 2019-05-08 18:17:55 -07:00
Makefile.in Bail-out early in the for install loops instead of continuing because for masks the error in the middle 2018-09-03 12:05:45 +02:00