| /src/external/bsd/nsd/dist/ |
| packet.c | 123 rrset_type *rrsig; local 156 (rrsig = domain_find_rrset(owner, rrset->zone, TYPE_RRSIG))) 158 for (i = 0; i < rrsig->rr_count; ++i) { 159 if (rr_rrsig_type_covered(rrsig->rrs[i]) 163 rrsig->rrs[i], 164 rrset_rrtype(rrset)==TYPE_SOA?rrset->rrs[0]->ttl:rrsig->rrs[i]->ttl))
|
| /src/external/mpl/bind/dist/lib/dns/ |
| skr.c | 161 dns_rdata_rrsig_t rrsig; local 169 result = dns_rdata_tostruct(&tuple->rdata, &rrsig, NULL); 178 if (rrsig.covered == covering_type && 179 rrsig.keyid == dst_key_id(key))
|
| ncache.c | 638 dns_rdata_rrsig_t rrsig; local 696 (void)dns_rdata_tostruct(&rdata, &rrsig, NULL); 697 if (rrsig.covered == covers) { 738 dns_rdata_rrsig_t rrsig; local 767 * Extract covers from RRSIG. 779 (void)dns_rdata_tostruct(&rdata, &rrsig, NULL); 780 covers = rrsig.covered;
|
| keymgr.c | 997 * least one key with the same algorithm that has its RRSIG 1136 * Check for existence of RRSIG (zsk), or a good RRSIG state. 1137 * See equations what are good RRSIG states. 1245 * in that case allow publishing the RRSIG records before the 1326 * Rule 3: There must be RRSIG records at all times. Again, 1374 * publication of a DNSKEY (plus RRSIG (KSK)) before 1418 * dependent information (RRSIG ZSK) to be purged from 1426 * TTLsig is the maximum TTL of all zone RRSIG 2621 int rrsig, active, retire local [all...] |
| update.c | 564 * Return true if the record is a RRSIG. 683 * Check whether there is an rrset other than a NSEC or RRSIG NSEC, 997 * Add RRSIG records for an RRset, recording the change in "diff". 1140 /* Calculate the signature, creating a RRSIG RDATA. */ 1155 /* Update the database and journal with the RRSIG. */ 1199 dns_rdata_rrsig_t rrsig; local 1224 result = dns_rdata_tostruct(&rdata, &rrsig, NULL); 1228 if (rrsig.keyid == dst_key_id(keys[i])) { 1247 * If there is not a matching DNSKEY then delete the RRSIG. 1345 * Update RRSIG, NSEC and NSEC3 records affected by an update. The origina [all...] |
| resolver.c | 819 * ANY if qtype was SIG or RRSIG) */ 5175 * typemap with just RRSIG(46) and NSEC(47) bits set. 5278 * Returns true if the rdataset is of type 'type', or type RRSIG 5303 * RFC 4034, 3: The RRSIG Resource Record 5305 * digital signature, RRSIG RRs must be present for names containing a 5316 * So types allowed next to CNAME are: KEY, SIG, NXT, RRSIG, and NSEC. 5403 dns_rdata_rrsig_t rrsig; local 5413 result = dns_rdata_tostruct(&rdata, &rrsig, NULL); 5415 dns_name_copy(&rrsig.signer, signer); 5420 result = dns_rdata_tostruct(&rdata, &rrsig, NULL) 6006 dns_rdata_rrsig_t rrsig; local [all...] |
| zone.c | 6712 "DNSKEY RRSIG(s) have expired"); 6719 "DNSKEY RRSIG(s) will expire within 7 days: %s", 6790 * Deleting the SOA RRSIG is always okay. 6838 dns_rdata_rrsig_t rrsig; local 6879 result = dns_rdata_tostruct(&rdata, &rrsig, NULL); 6884 if (delsig_ok(&rrsig, keys, nkeys, kasp != NULL, &warn)) 6897 * At this point, we've got an RRSIG, 6901 * keep the old RRSIG. Marking the key as 6923 dns_secalg_format(rrsig.algorithm, 6932 rrsig.keyid) 7543 dns_rdata_rrsig_t rrsig; local 9319 dns_rdata_rrsig_t rrsig; local 21006 dns_rdata_rrsig_t rrsig; local [all...] |
| /src/external/mpl/bind/dist/tests/dns/ |
| rdataset_test.c | 43 dns_rdata_rrsig_t rrsig; local 56 rrsig.timeexpire = ttltimeexpire; 57 rrsig.originalttl = 1000; 59 dns_rdataset_trimttl(&rdataset, &sigrdataset, &rrsig, ttltimenow, true); 65 rrsig.timeexpire = ttltimenow - 200; 66 rrsig.originalttl = 1000; 68 dns_rdataset_trimttl(&rdataset, &sigrdataset, &rrsig, ttltimenow, true); 74 rrsig.timeexpire = ttltimenow - 200; 75 rrsig.originalttl = 1000; 77 dns_rdataset_trimttl(&rdataset, &sigrdataset, &rrsig, ttltimenow [all...] |
| sigs_test.c | 114 dns_rdata_rrsig_t rrsig; local 165 * Found tuple must be of type RRSIG. 174 result = dns_rdata_tostruct(&found->rdata, &rrsig, NULL); 177 result = dns_rdatatype_totext(rrsig.covered, &typebuf); 179 assert_int_equal(expected_type, rrsig.covered);
|
| /src/external/mpl/dhcp/bind/dist/lib/dns/ |
| ncache.c | 611 dns_rdata_rrsig_t rrsig; local 669 (void)dns_rdata_tostruct(&rdata, &rrsig, NULL); 670 if (rrsig.covered == covers) { 718 dns_rdata_rrsig_t rrsig; local 749 * Extract covers from RRSIG. 761 (void)dns_rdata_tostruct(&rdata, &rrsig, NULL); 762 rdataset->covers = rrsig.covered;
|
| keymgr.c | 888 * least one key with the same algorithm that has its RRSIG 1027 * Check for existence of RRSIG (zsk), or a good RRSIG state. 1028 * See equations what are good RRSIG states. 1136 * in that case allow publishing the RRSIG records before the 1213 * Rule 3: There must be RRSIG records at all times. Again, 1255 * publication of a DNSKEY (plus RRSIG (KSK)) before 1288 * dependent information (RRSIG ZSK) to be purged from 1296 * TTLsig is the maximum TTL of all zone RRSIG 2378 int rrsig, active, retire local [all...] |
| update.c | 677 * Return true if the record is a RRSIG. 797 * Check whether there is an rrset other than a NSEC or RRSIG NSEC, 1089 * Add RRSIG records for an RRset, recording the change in "diff". 1262 /* Calculate the signature, creating a RRSIG RDATA. */ 1266 /* Update the database and journal with the RRSIG. */ 1310 dns_rdata_rrsig_t rrsig; local 1338 result = dns_rdata_tostruct(&rdata, &rrsig, NULL); 1342 if (rrsig.keyid == dst_key_id(keys[i])) { 1361 * If there is not a matching DNSKEY then delete the RRSIG. 1459 * Update RRSIG, NSEC and NSEC3 records affected by an update. The origina [all...] |
| resolver.c | 749 * ANY if qtype was SIG or RRSIG) */ 956 dns_rdata_rrsig_t rrsig; local 966 result = dns_rdata_tostruct(&rdata, &rrsig, NULL); 968 namereln = dns_name_fullcompare(&rrsig.signer, &fctx->domain, 1017 * Also accept answers with RRSIG records from the child zone. 1018 * Direct queries for RRSIG records should not be answered from 1043 * RRsig from child? 6240 dns_rdata_rrsig_t rrsig; local 6281 result = dns_rdata_tostruct(&rdata, &rrsig, NULL); 6283 /* Wildcard has rrsig.labels < labels - 1. * [all...] |
| zone.c | 6734 "DNSKEY RRSIG(s) have expired"); 6741 "DNSKEY RRSIG(s) will expire within 7 days: %s", 6812 * Deleting the SOA RRSIG is always okay. 6860 dns_rdata_rrsig_t rrsig; local 6897 result = dns_rdata_tostruct(&rdata, &rrsig, NULL); 6904 if (delsig_ok(&rrsig, keys, nkeys, kasp, &warn)) { 6916 * At this point, we've got an RRSIG, 6920 * keep the old RRSIG. Marking the key as 6942 dns_secalg_format(rrsig.algorithm, 6951 rrsig.keyid) 7620 dns_rdata_rrsig_t rrsig; local 9391 dns_rdata_rrsig_t rrsig; local 20601 dns_rdata_rrsig_t rrsig; local [all...] |
| /src/external/apache2/mDNSResponder/dist/mDNSShared/dns_objects/utilities/ |
| rdata_parser.c | 364 // MARK: - RRSIG Parser 367 uint16_t type_covered; // Indicates which DNS type RRSIG covers. 369 uint8_t labels; // The number of labels in the RRSIG owner name, is used to check wild matching. 370 uint32_t original_ttl; // The original TTL of the records that are covered by the RRSIG, it is used to 372 uint32_t signature_expiration; // The epoch time when the RRSIG expires. 373 uint32_t signature_inception; // The epoch time when the RRSIG should start to be valid to validate. 374 uint16_t key_tag; // The key tag that identifies which DNSKEY it uses to generate the current RRSIG. 458 const rdata_rrsig_t * const rrsig = (const rdata_rrsig_t *)rdata; local 459 const uint8_t * const signer_name = rrsig->signer_name; 472 // Minimal size of the RRSIG rdata: <all the fields before signer_name> + <1 byte root domain> + <1 byte signature [all...] |
| /src/external/mpl/bind/dist/bin/dnssec/ |
| dnssec-ksr.c | 691 dns_rdata_t *rrsig = NULL; local 715 rrsig = isc_mem_get(mctx, sizeof(*rrsig)); 716 dns_rdata_init(rrsig); 727 dns_rdata_fromregion(rrsig, dns_rdataclass_in, 729 ISC_LIST_APPEND(rrsiglist->rdata, rrsig, link);
|
| dnssec-signzone.c | 357 * Find the key that generated an RRSIG, if it is in the key list. If 363 keythatsigned_unlocked(dns_rdata_rrsig_t *rrsig) { 369 if (rrsig->keyid == dst_key_id(key->key) && 370 rrsig->algorithm == dst_key_alg(key->key) && 371 dns_name_equal(&rrsig->signer, dst_key_name(key->key))) 380 * Finds the key that generated a RRSIG, if possible. First look at the keys 384 keythatsigned(dns_rdata_rrsig_t *rrsig) { 390 key = keythatsigned_unlocked(rrsig); 404 key = keythatsigned_unlocked(rrsig); 410 result = dst_key_fromfile(&rrsig->signer, rrsig->keyid 519 dns_rdata_rrsig_t rrsig; local [all...] |
| /src/external/apache2/mDNSResponder/dist/Clients/ |
| dns-sd.c | 360 else if (!strcasecmp(s, "rrsig" )) return(kDNSServiceType_RRSIG); 417 case kDNSServiceType_RRSIG: return("RRSIG"); 1108 rdataRRSig *rrsig = (rdataRRSig *)rd; local 1117 expClock = (unsigned long)swap32(rrsig->sigExpireTime); 1120 inceptClock = (unsigned long)swap32(rrsig->sigInceptTime); 1124 DNSTypeName(swap16(rrsig->typeCovered)), rrsig->alg, rrsig->labels, swap32(rrsig->origTTL), 1125 expTimeBuf, inceptTimeBuf, swap16(rrsig->keyTag)) [all...] |
| /src/external/apache2/mDNSResponder/dist/mDNSCore/ |
| DNSCommon.c | 284 case kDNSType_RRSIG: return("RRSIG"); 606 // See <https://datatracker.ietf.org/doc/html/rfc4034#section-3.2> for RRSIG RR Presentation Format. 609 dnssec_obj_rr_rrsig_t rrsig = NULL; local 612 rrsig = dnssec_obj_rr_rrsig_create(rr->name->c, rr->rdata->u.data, rr->rdlength, false, &err); 617 rrsig_rdata_description = dnssec_obj_rr_copy_rdata_rfc_description(rrsig, &err); 626 MDNS_DISPOSE_DNSSEC_OBJ(rrsig); 2121 // The type covered of RRSIG should match the non-duplicate DNSSEC question type, because RRSIG will be used by it
|
| mDNS.c | 5488 // If we get a CNAME back while we are validating the response (i.e., CNAME for DS, DNSKEY, RRSIG), 6166 // If the RRSIG covers a CNAME, and this RRSIG covers a wildcard resource record, 9765 // This operation ensures that mDNSResponder will deliver all the records including RRSIG or denial of 10210 // Here we assume that the total number of RRSIG records contained in a response should be no more than 30 (large enough). 10215 // Parse SOA, NSEC/NSEC3, RRSIG records contained in the DNS message to DNSSEC objects. 10249 // All SOA, NSEC/NSEC3, RRSIG records are in the authority section. 10298 // Other than SOA, NSEC/NSEC3/RRSIG can use the rdata parsed by GetLargeResourceRecord() directly because 10331 dnssec_obj_rr_rrsig_t rrsig = dnssec_obj_rr_rrsig_create(rr->name->c, rr->rdata->u.data, rr->rdlength, mDNStrue, &err); local 10337 const mDNSu16 typeCovered = dnssec_obj_rr_rrsig_get_type_covered(rrsig); [all...] |
| /src/external/bsd/unbound/dist/services/ |
| authzone.c | 712 /** find an rrsig index in the rrset. returns true if found */ 743 /** get rrsig type covered from rdata. 944 rrsig_num_that_cover(struct auth_rrset* rrsig, uint16_t rr_type, size_t* sigsz) 946 struct packed_rrset_data* d = rrsig->data; 949 log_assert(d && rrsig->type == LDNS_RR_TYPE_RRSIG); 960 /** See if rrsig set has covered sigs for rrset and move them over */ 963 struct auth_rrset* rrset, struct auth_rrset* rrsig) 966 struct packed_rrset_data* sigold = rrsig->data; 971 log_assert(rrsig->type == LDNS_RR_TYPE_RRSIG); 972 sigs = rrsig_num_that_cover(rrsig, rr_type, &sigsz) 1165 struct auth_rrset* rrsig; local [all...] |
| /src/external/mpl/bind/dist/lib/ns/ |
| query.c | 5313 * If it's an RRSIG or SIG query, we'll iterate the node. 7762 * original type requested) might have been RRSIG or 7895 * here on a search for RRSIG/SIG, so that's okay. 9570 * Determine the correct TTL to use for the SOA and RRSIG 9591 * Add SOA record. Omit the RRSIG if DNSSEC was not requested. 9647 * Add answer RRset. Omit the RRSIG if DNSSEC was not requested. 9742 * SOA record + RRSIG for the negative answer. 9758 * Determine the correct TTL to use for the SOA and RRSIG 9780 * Add SOA record. Omit the RRSIG if DNSSEC was not requested. 9842 dns_rdata_rrsig_t rrsig; local [all...] |