Home | History | Annotate | only in /src/external/mpl/bind/dist/bin/tests/system/rsabigexponent
Up to higher level directory
NameDateSize
bigkey.c29-Jan-20264.2K
ns1/17-Sep-2026
ns2/17-Sep-2026
ns3/17-Sep-2026
options.conf.j2.manual26-Jan-2025491
README.md25-Jan-20231.6K
setup.sh29-Jan-2026466
tests_rsabigexponent.py17-Jul-20251.8K

README.md

      1 Copyright (C) Internet Systems Consortium, Inc. ("ISC")
      2 
      3 SPDX-License-Identifier: MPL-2.0
      4 
      5 This Source Code Form is subject to the terms of the Mozilla Public
      6 License, v. 2.0.  If a copy of the MPL was not distributed with this
      7 file, you can obtain one at https://mozilla.org/MPL/2.0/.
      8 
      9 See the COPYRIGHT file distributed with this work for additional
     10 information regarding copyright ownership.
     11 
     12 The `rsabigexponent` test is used to `check max-rsa-exponent-size`.
     13 
     14 We only run this test on builds without PKCS#11, as we have control over
     15 the RSA exponent size with plain OpenSSL. We have not explored how to do
     16 this with PKCS#11, which would require generating such a key and then
     17 signing a zone with it. Additionally, even with control of the exponent
     18 size with PKCS#11, generating a DNSKEY with this property and signing
     19 such a zone would be slow and undesirable for each test run; instead, we
     20 use a pregenerated DNSKEY and a saved signed zone.  These are located in
     21 `rsabigexponent/ns2` and currently use RSASHA1 for the `DNSKEY`
     22 algorithm; however, that may need to be changed in the future.
     23 
     24 To generate the `DNSKEY` used in this test, we used `bigkey.c`, as
     25 dnssec-keygen is not capable of generating such keys.
     26 
     27 Do **not** remove `bigkey.c` as it may be needed to generate a new
     28 `DNSKEY` for testing purposes.
     29 
     30 `bigkey` is used to both test that we are not running under PKCS#11 and
     31 generate a `DNSKEY` key with a large RSA exponent.
     32 
     33 To regenerate `ns2/example.db.bad` comment out the range test in
     34 opensslrsa_parse before signing the zone with a ZSK key generated
     35 by `bigkey`.
     36 
     37         if (BN_num_bits(e) > RSA_MAX_PUBEXP_BITS) {
     38                 DST_RET(ISC_R_RANGE);
     39         }
     40