nameser.h revision 158787
11539Srgrimes/* 21539Srgrimes * Copyright (c) 1983, 1989, 1993 336888Speter * The Regents of the University of California. All rights reserved. 436888Speter * 51539Srgrimes * Redistribution and use in source and binary forms, with or without 61539Srgrimes * modification, are permitted provided that the following conditions 71539Srgrimes * are met: 81539Srgrimes * 1. Redistributions of source code must retain the above copyright 91539Srgrimes * notice, this list of conditions and the following disclaimer. 101539Srgrimes * 2. Redistributions in binary form must reproduce the above copyright 111539Srgrimes * notice, this list of conditions and the following disclaimer in the 121539Srgrimes * documentation and/or other materials provided with the distribution. 131539Srgrimes * 3. All advertising materials mentioning features or use of this software 141539Srgrimes * must display the following acknowledgement: 1536888Speter * This product includes software developed by the University of 1636888Speter * California, Berkeley and its contributors. 171539Srgrimes * 4. Neither the name of the University nor the names of its contributors 181539Srgrimes * may be used to endorse or promote products derived from this software 191539Srgrimes * without specific prior written permission. 2036888Speter * 211539Srgrimes * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 221539Srgrimes * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 231539Srgrimes * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 241539Srgrimes * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 251539Srgrimes * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 261539Srgrimes * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 271539Srgrimes * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 281539Srgrimes * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 291539Srgrimes * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 301539Srgrimes * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 311539Srgrimes * SUCH DAMAGE. 3236888Speter */ 3336888Speter 3436888Speter/* 35156960Sume * Copyright (c) 2004 by Internet Systems Consortium, Inc. ("ISC") 36156960Sume * Copyright (c) 1996-1999 by Internet Software Consortium. 371539Srgrimes * 381539Srgrimes * Permission to use, copy, modify, and distribute this software for any 391539Srgrimes * purpose with or without fee is hereby granted, provided that the above 4036888Speter * copyright notice and this permission notice appear in all copies. 418858Srgrimes * 42156960Sume * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES 43156960Sume * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 44156960Sume * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR 45156960Sume * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 46156960Sume * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 47156960Sume * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT 48156960Sume * OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 4936888Speter */ 5036888Speter 5136888Speter/* 52156960Sume * $Id: nameser.h,v 1.2.2.4.4.1 2004/03/09 08:33:30 marka Exp $ 5350473Speter * $FreeBSD: head/include/arpa/nameser.h 158787 2006-05-21 11:19:36Z ume $ 541539Srgrimes */ 551539Srgrimes 5610132Speter#ifndef _ARPA_NAMESER_H_ 5736888Speter#define _ARPA_NAMESER_H_ 581539Srgrimes 5936888Speter#define BIND_4_COMPAT 6036888Speter 61156960Sume#include <sys/param.h> 621539Srgrimes#include <sys/types.h> 633070Spst#include <sys/cdefs.h> 641539Srgrimes 651539Srgrimes/* 66156960Sume * Revision information. This is the release date in YYYYMMDD format. 67156960Sume * It can change every day so the right thing to do with it is use it 68156960Sume * in preprocessor commands such as "#if (__NAMESER > 19931104)". Do not 69156960Sume * compare for equality; rather, use it to determine whether your libbind.a 70156960Sume * contains a new enough lib/nameser/ to support the feature you need. 713070Spst */ 723070Spst 73156960Sume#define __NAMESER 19991006 /* New interface version stamp. */ 743070Spst 753070Spst/* 7636888Speter * Define constants based on RFC 883, RFC 1034, RFC 1035 771539Srgrimes */ 78156960Sume#define NS_PACKETSZ 512 /* default UDP packet size */ 7936888Speter#define NS_MAXDNAME 1025 /* maximum domain name */ 80156960Sume#define NS_MAXMSG 65535 /* maximum message size */ 8136888Speter#define NS_MAXCDNAME 255 /* maximum compressed domain name */ 8236888Speter#define NS_MAXLABEL 63 /* maximum length of domain label */ 8336888Speter#define NS_HFIXEDSZ 12 /* #/bytes of fixed data in header */ 8436888Speter#define NS_QFIXEDSZ 4 /* #/bytes of fixed data in query */ 8536888Speter#define NS_RRFIXEDSZ 10 /* #/bytes of fixed data in r record */ 8636888Speter#define NS_INT32SZ 4 /* #/bytes of data in a u_int32_t */ 8736888Speter#define NS_INT16SZ 2 /* #/bytes of data in a u_int16_t */ 8836888Speter#define NS_INT8SZ 1 /* #/bytes of data in a u_int8_t */ 8936888Speter#define NS_INADDRSZ 4 /* IPv4 T_A */ 9036888Speter#define NS_IN6ADDRSZ 16 /* IPv6 T_AAAA */ 9136888Speter#define NS_CMPRSFLGS 0xc0 /* Flag bits indicating name compression. */ 9236888Speter#define NS_DEFAULTPORT 53 /* For both TCP and UDP. */ 931539Srgrimes 941539Srgrimes/* 9536888Speter * These can be expanded with synonyms, just keep ns_parse.c:ns_parserecord() 9636888Speter * in synch with it. 971539Srgrimes */ 9836888Spetertypedef enum __ns_sect { 9936888Speter ns_s_qd = 0, /* Query: Question. */ 10036888Speter ns_s_zn = 0, /* Update: Zone. */ 10136888Speter ns_s_an = 1, /* Query: Answer. */ 10236888Speter ns_s_pr = 1, /* Update: Prerequisites. */ 10336888Speter ns_s_ns = 2, /* Query: Name servers. */ 10436888Speter ns_s_ud = 2, /* Update: Update. */ 10536888Speter ns_s_ar = 3, /* Query|Update: Additional records. */ 10636888Speter ns_s_max = 4 10736888Speter} ns_sect; 1081539Srgrimes 1091539Srgrimes/* 11036888Speter * This is a message handle. It is caller allocated and has no dynamic data. 11136888Speter * This structure is intended to be opaque to all but ns_parse.c, thus the 11236888Speter * leading _'s on the member names. Use the accessor functions, not the _'s. 1131539Srgrimes */ 11436888Spetertypedef struct __ns_msg { 11536888Speter const u_char *_msg, *_eom; 11636888Speter u_int16_t _id, _flags, _counts[ns_s_max]; 11736888Speter const u_char *_sections[ns_s_max]; 11836888Speter ns_sect _sect; 11936888Speter int _rrnum; 120156960Sume const u_char *_msg_ptr; 12136888Speter} ns_msg; 12236888Speter 12336888Speter/* Private data structure - do not use from outside library. */ 12436888Speterstruct _ns_flagdata { int mask, shift; }; 12536888Speterextern struct _ns_flagdata _ns_flagdata[]; 12636888Speter 12736888Speter/* Accessor macros - this is part of the public interface. */ 128156960Sume 12936888Speter#define ns_msg_id(handle) ((handle)._id + 0) 13036888Speter#define ns_msg_base(handle) ((handle)._msg + 0) 13136888Speter#define ns_msg_end(handle) ((handle)._eom + 0) 13236888Speter#define ns_msg_size(handle) ((handle)._eom - (handle)._msg) 13336888Speter#define ns_msg_count(handle, section) ((handle)._counts[section] + 0) 13436888Speter 1351539Srgrimes/* 13636888Speter * This is a parsed record. It is caller allocated and has no dynamic data. 1371539Srgrimes */ 13836888Spetertypedef struct __ns_rr { 139156960Sume char name[NS_MAXDNAME]; 14036888Speter u_int16_t type; 14147742Speter u_int16_t rr_class; 14236888Speter u_int32_t ttl; 14336888Speter u_int16_t rdlength; 144156960Sume const u_char * rdata; 14536888Speter} ns_rr; 1461539Srgrimes 14736888Speter/* Accessor macros - this is part of the public interface. */ 14836888Speter#define ns_rr_name(rr) (((rr).name[0] != '\0') ? (rr).name : ".") 149156960Sume#define ns_rr_type(rr) ((ns_type)((rr).type + 0)) 150156960Sume#define ns_rr_class(rr) ((ns_class)((rr).rr_class + 0)) 15136888Speter#define ns_rr_ttl(rr) ((rr).ttl + 0) 15236888Speter#define ns_rr_rdlen(rr) ((rr).rdlength + 0) 15336888Speter#define ns_rr_rdata(rr) ((rr).rdata + 0) 15436888Speter 1551539Srgrimes/* 15636888Speter * These don't have to be in the same order as in the packet flags word, 15736888Speter * and they can even overlap in some cases, but they will need to be kept 15836888Speter * in synch with ns_parse.c:ns_flagdata[]. 1591539Srgrimes */ 16036888Spetertypedef enum __ns_flag { 16136888Speter ns_f_qr, /* Question/Response. */ 16236888Speter ns_f_opcode, /* Operation code. */ 16336888Speter ns_f_aa, /* Authoritative Answer. */ 16436888Speter ns_f_tc, /* Truncation occurred. */ 16536888Speter ns_f_rd, /* Recursion Desired. */ 16636888Speter ns_f_ra, /* Recursion Available. */ 16736888Speter ns_f_z, /* MBZ. */ 16836888Speter ns_f_ad, /* Authentic Data (DNSSEC). */ 16936888Speter ns_f_cd, /* Checking Disabled (DNSSEC). */ 17036888Speter ns_f_rcode, /* Response code. */ 17136888Speter ns_f_max 17236888Speter} ns_flag; 1731539Srgrimes 1741539Srgrimes/* 17536888Speter * Currently defined opcodes. 17636888Speter */ 17736888Spetertypedef enum __ns_opcode { 17836888Speter ns_o_query = 0, /* Standard query. */ 17936888Speter ns_o_iquery = 1, /* Inverse query (deprecated/unsupported). */ 18036888Speter ns_o_status = 2, /* Name server status query (unsupported). */ 18136888Speter /* Opcode 3 is undefined/reserved. */ 18236888Speter ns_o_notify = 4, /* Zone change notification. */ 18336888Speter ns_o_update = 5, /* Zone update message. */ 18436888Speter ns_o_max = 6 18536888Speter} ns_opcode; 18636888Speter 18736888Speter/* 18836888Speter * Currently defined response codes. 18936888Speter */ 19036888Spetertypedef enum __ns_rcode { 19136888Speter ns_r_noerror = 0, /* No error occurred. */ 19236888Speter ns_r_formerr = 1, /* Format error. */ 19336888Speter ns_r_servfail = 2, /* Server failure. */ 19436888Speter ns_r_nxdomain = 3, /* Name error. */ 19536888Speter ns_r_notimpl = 4, /* Unimplemented. */ 19636888Speter ns_r_refused = 5, /* Operation refused. */ 19736888Speter /* these are for BIND_UPDATE */ 19836888Speter ns_r_yxdomain = 6, /* Name exists */ 19936888Speter ns_r_yxrrset = 7, /* RRset exists */ 20036888Speter ns_r_nxrrset = 8, /* RRset does not exist */ 20136888Speter ns_r_notauth = 9, /* Not authoritative for zone */ 20236888Speter ns_r_notzone = 10, /* Zone of record different from zone section */ 203156960Sume ns_r_max = 11, 204156960Sume /* The following are EDNS extended rcodes */ 205156960Sume ns_r_badvers = 16, 206156960Sume /* The following are TSIG errors */ 207156960Sume ns_r_badsig = 16, 208156960Sume ns_r_badkey = 17, 209156960Sume ns_r_badtime = 18 21036888Speter} ns_rcode; 21136888Speter 21236888Speter/* BIND_UPDATE */ 21336888Spetertypedef enum __ns_update_operation { 21436888Speter ns_uop_delete = 0, 21536888Speter ns_uop_add = 1, 21636888Speter ns_uop_max = 2 21736888Speter} ns_update_operation; 21836888Speter 21936888Speter/* 220156960Sume * This structure is used for TSIG authenticated messages 22136888Speter */ 222156960Sumestruct ns_tsig_key { 223156960Sume char name[NS_MAXDNAME], alg[NS_MAXDNAME]; 224156960Sume unsigned char *data; 225156960Sume int len; 22636888Speter}; 227156960Sumetypedef struct ns_tsig_key ns_tsig_key; 22836888Speter 22936888Speter/* 230156960Sume * This structure is used for TSIG authenticated TCP messages 231156960Sume */ 232156960Sumestruct ns_tcp_tsig_state { 233156960Sume int counter; 234156960Sume struct dst_key *key; 235156960Sume void *ctx; 236156960Sume unsigned char sig[NS_PACKETSZ]; 237156960Sume int siglen; 238156960Sume}; 239156960Sumetypedef struct ns_tcp_tsig_state ns_tcp_tsig_state; 240156960Sume 241156960Sume#define NS_TSIG_FUDGE 300 242156960Sume#define NS_TSIG_TCP_COUNT 100 243156960Sume#define NS_TSIG_ALG_HMAC_MD5 "HMAC-MD5.SIG-ALG.REG.INT" 244156960Sume 245156960Sume#define NS_TSIG_ERROR_NO_TSIG -10 246156960Sume#define NS_TSIG_ERROR_NO_SPACE -11 247156960Sume#define NS_TSIG_ERROR_FORMERR -12 248156960Sume 249156960Sume/* 25036888Speter * Currently defined type values for resources and queries. 25136888Speter */ 25236888Spetertypedef enum __ns_type { 253156960Sume ns_t_invalid = 0, /* Cookie. */ 25436888Speter ns_t_a = 1, /* Host address. */ 25536888Speter ns_t_ns = 2, /* Authoritative server. */ 25636888Speter ns_t_md = 3, /* Mail destination. */ 25736888Speter ns_t_mf = 4, /* Mail forwarder. */ 25836888Speter ns_t_cname = 5, /* Canonical name. */ 25936888Speter ns_t_soa = 6, /* Start of authority zone. */ 26036888Speter ns_t_mb = 7, /* Mailbox domain name. */ 26136888Speter ns_t_mg = 8, /* Mail group member. */ 26236888Speter ns_t_mr = 9, /* Mail rename name. */ 26336888Speter ns_t_null = 10, /* Null resource record. */ 26436888Speter ns_t_wks = 11, /* Well known service. */ 26536888Speter ns_t_ptr = 12, /* Domain name pointer. */ 26636888Speter ns_t_hinfo = 13, /* Host information. */ 26736888Speter ns_t_minfo = 14, /* Mailbox information. */ 26836888Speter ns_t_mx = 15, /* Mail routing information. */ 26936888Speter ns_t_txt = 16, /* Text strings. */ 27036888Speter ns_t_rp = 17, /* Responsible person. */ 27136888Speter ns_t_afsdb = 18, /* AFS cell database. */ 27236888Speter ns_t_x25 = 19, /* X_25 calling address. */ 27336888Speter ns_t_isdn = 20, /* ISDN calling address. */ 27436888Speter ns_t_rt = 21, /* Router. */ 27536888Speter ns_t_nsap = 22, /* NSAP address. */ 27636888Speter ns_t_nsap_ptr = 23, /* Reverse NSAP lookup (deprecated). */ 27736888Speter ns_t_sig = 24, /* Security signature. */ 27836888Speter ns_t_key = 25, /* Security key. */ 27936888Speter ns_t_px = 26, /* X.400 mail mapping. */ 28036888Speter ns_t_gpos = 27, /* Geographical position (withdrawn). */ 28136888Speter ns_t_aaaa = 28, /* Ip6 Address. */ 28236888Speter ns_t_loc = 29, /* Location Information. */ 28336888Speter ns_t_nxt = 30, /* Next domain (security). */ 28436888Speter ns_t_eid = 31, /* Endpoint identifier. */ 28536888Speter ns_t_nimloc = 32, /* Nimrod Locator. */ 28636888Speter ns_t_srv = 33, /* Server Selection. */ 28736888Speter ns_t_atma = 34, /* ATM Address */ 28836888Speter ns_t_naptr = 35, /* Naming Authority PoinTeR */ 289156960Sume ns_t_kx = 36, /* Key Exchange */ 290156960Sume ns_t_cert = 37, /* Certification record */ 291156960Sume ns_t_a6 = 38, /* IPv6 address (deprecates AAAA) */ 292156960Sume ns_t_dname = 39, /* Non-terminal DNAME (for IPv6) */ 293156960Sume ns_t_sink = 40, /* Kitchen sink (experimentatl) */ 294156960Sume ns_t_opt = 41, /* EDNS0 option (meta-RR) */ 295156960Sume ns_t_apl = 42, /* Address prefix list (RFC 3123) */ 296156960Sume ns_t_tkey = 249, /* Transaction key */ 297156960Sume ns_t_tsig = 250, /* Transaction signature. */ 29836888Speter ns_t_ixfr = 251, /* Incremental zone transfer. */ 29936888Speter ns_t_axfr = 252, /* Transfer zone of authority. */ 30036888Speter ns_t_mailb = 253, /* Transfer mailbox records. */ 30136888Speter ns_t_maila = 254, /* Transfer mail agent records. */ 30236888Speter ns_t_any = 255, /* Wildcard match. */ 303156960Sume ns_t_zxfr = 256, /* BIND-specific, nonstandard. */ 30436888Speter ns_t_max = 65536 30536888Speter} ns_type; 30636888Speter 307156960Sume/* Exclusively a QTYPE? (not also an RTYPE) */ 308156960Sume#define ns_t_qt_p(t) (ns_t_xfr_p(t) || (t) == ns_t_any || \ 309156960Sume (t) == ns_t_mailb || (t) == ns_t_maila) 310156960Sume/* Some kind of meta-RR? (not a QTYPE, but also not an RTYPE) */ 311156960Sume#define ns_t_mrr_p(t) ((t) == ns_t_tsig || (t) == ns_t_opt) 312156960Sume/* Exclusively an RTYPE? (not also a QTYPE or a meta-RR) */ 313156960Sume#define ns_t_rr_p(t) (!ns_t_qt_p(t) && !ns_t_mrr_p(t)) 314156960Sume#define ns_t_udp_p(t) ((t) != ns_t_axfr && (t) != ns_t_zxfr) 315156960Sume#define ns_t_xfr_p(t) ((t) == ns_t_axfr || (t) == ns_t_ixfr || \ 316156960Sume (t) == ns_t_zxfr) 317156960Sume 31836888Speter/* 3191539Srgrimes * Values for class field 3201539Srgrimes */ 32136888Spetertypedef enum __ns_class { 322156960Sume ns_c_invalid = 0, /* Cookie. */ 32336888Speter ns_c_in = 1, /* Internet. */ 324156960Sume ns_c_2 = 2, /* unallocated/unsupported. */ 32536888Speter ns_c_chaos = 3, /* MIT Chaos-net. */ 32636888Speter ns_c_hs = 4, /* MIT Hesiod. */ 3271539Srgrimes /* Query class values which do not appear in resource records */ 32836888Speter ns_c_none = 254, /* for prereq. sections in update requests */ 32936888Speter ns_c_any = 255, /* Wildcard match. */ 33036888Speter ns_c_max = 65536 33136888Speter} ns_class; 3321539Srgrimes 333156960Sume/* DNSSEC constants. */ 334156960Sume 335156960Sumetypedef enum __ns_key_types { 336156960Sume ns_kt_rsa = 1, /* key type RSA/MD5 */ 337156960Sume ns_kt_dh = 2, /* Diffie Hellman */ 338156960Sume ns_kt_dsa = 3, /* Digital Signature Standard (MANDATORY) */ 339156960Sume ns_kt_private = 254 /* Private key type starts with OID */ 340156960Sume} ns_key_types; 341156960Sume 342156960Sumetypedef enum __ns_cert_types { 343156960Sume cert_t_pkix = 1, /* PKIX (X.509v3) */ 344156960Sume cert_t_spki = 2, /* SPKI */ 345156960Sume cert_t_pgp = 3, /* PGP */ 346156960Sume cert_t_url = 253, /* URL private type */ 347156960Sume cert_t_oid = 254 /* OID private type */ 348156960Sume} ns_cert_types; 349156960Sume 350156960Sume/* Flags field of the KEY RR rdata. */ 35136888Speter#define NS_KEY_TYPEMASK 0xC000 /* Mask for "type" bits */ 35236888Speter#define NS_KEY_TYPE_AUTH_CONF 0x0000 /* Key usable for both */ 35336888Speter#define NS_KEY_TYPE_CONF_ONLY 0x8000 /* Key usable for confidentiality */ 35436888Speter#define NS_KEY_TYPE_AUTH_ONLY 0x4000 /* Key usable for authentication */ 35536888Speter#define NS_KEY_TYPE_NO_KEY 0xC000 /* No key usable for either; no key */ 35621056Speter/* The type bits can also be interpreted independently, as single bits: */ 35736888Speter#define NS_KEY_NO_AUTH 0x8000 /* Key unusable for authentication */ 35836888Speter#define NS_KEY_NO_CONF 0x4000 /* Key unusable for confidentiality */ 359156960Sume#define NS_KEY_RESERVED2 0x2000 /* Security is *mandatory* if bit=0 */ 360156960Sume#define NS_KEY_EXTENDED_FLAGS 0x1000 /* reserved - must be zero */ 36136888Speter#define NS_KEY_RESERVED4 0x0800 /* reserved - must be zero */ 362156960Sume#define NS_KEY_RESERVED5 0x0400 /* reserved - must be zero */ 363156960Sume#define NS_KEY_NAME_TYPE 0x0300 /* these bits determine the type */ 364156960Sume#define NS_KEY_NAME_USER 0x0000 /* key is assoc. with user */ 365156960Sume#define NS_KEY_NAME_ENTITY 0x0200 /* key is assoc. with entity eg host */ 366156960Sume#define NS_KEY_NAME_ZONE 0x0100 /* key is zone key */ 367156960Sume#define NS_KEY_NAME_RESERVED 0x0300 /* reserved meaning */ 368156960Sume#define NS_KEY_RESERVED8 0x0080 /* reserved - must be zero */ 369156960Sume#define NS_KEY_RESERVED9 0x0040 /* reserved - must be zero */ 37036888Speter#define NS_KEY_RESERVED10 0x0020 /* reserved - must be zero */ 37136888Speter#define NS_KEY_RESERVED11 0x0010 /* reserved - must be zero */ 37236888Speter#define NS_KEY_SIGNATORYMASK 0x000F /* key can sign RR's of same name */ 373156960Sume#define NS_KEY_RESERVED_BITMASK ( NS_KEY_RESERVED2 | \ 37436888Speter NS_KEY_RESERVED4 | \ 375156960Sume NS_KEY_RESERVED5 | \ 376156960Sume NS_KEY_RESERVED8 | \ 377156960Sume NS_KEY_RESERVED9 | \ 37836888Speter NS_KEY_RESERVED10 | \ 37936888Speter NS_KEY_RESERVED11 ) 380156960Sume#define NS_KEY_RESERVED_BITMASK2 0xFFFF /* no bits defined here */ 38121056Speter 38221056Speter/* The Algorithm field of the KEY and SIG RR's is an integer, {1..254} */ 38336888Speter#define NS_ALG_MD5RSA 1 /* MD5 with RSA */ 384156960Sume#define NS_ALG_DH 2 /* Diffie Hellman KEY */ 385156960Sume#define NS_ALG_DSA 3 /* DSA KEY */ 386156960Sume#define NS_ALG_DSS NS_ALG_DSA 38736888Speter#define NS_ALG_EXPIRE_ONLY 253 /* No alg, no security */ 38836888Speter#define NS_ALG_PRIVATE_OID 254 /* Key begins with OID giving alg */ 38921056Speter 390156960Sume/* Protocol values */ 391156960Sume/* value 0 is reserved */ 392156960Sume#define NS_KEY_PROT_TLS 1 393156960Sume#define NS_KEY_PROT_EMAIL 2 394156960Sume#define NS_KEY_PROT_DNSSEC 3 395156960Sume#define NS_KEY_PROT_IPSEC 4 396156960Sume#define NS_KEY_PROT_ANY 255 397156960Sume 39821056Speter/* Signatures */ 39936888Speter#define NS_MD5RSA_MIN_BITS 512 /* Size of a mod or exp in bits */ 400156960Sume#define NS_MD5RSA_MAX_BITS 4096 40136888Speter /* Total of binary mod and exp */ 40236888Speter#define NS_MD5RSA_MAX_BYTES ((NS_MD5RSA_MAX_BITS+7/8)*2+3) 40336888Speter /* Max length of text sig block */ 40436888Speter#define NS_MD5RSA_MAX_BASE64 (((NS_MD5RSA_MAX_BYTES+2)/3)*4) 405156960Sume#define NS_MD5RSA_MIN_SIZE ((NS_MD5RSA_MIN_BITS+7)/8) 406156960Sume#define NS_MD5RSA_MAX_SIZE ((NS_MD5RSA_MAX_BITS+7)/8) 40721056Speter 408156960Sume#define NS_DSA_SIG_SIZE 41 409156960Sume#define NS_DSA_MIN_SIZE 213 410156960Sume#define NS_DSA_MAX_BYTES 405 411156960Sume 41236888Speter/* Offsets into SIG record rdata to find various values */ 41336888Speter#define NS_SIG_TYPE 0 /* Type flags */ 41436888Speter#define NS_SIG_ALG 2 /* Algorithm */ 41536888Speter#define NS_SIG_LABELS 3 /* How many labels in name */ 41636888Speter#define NS_SIG_OTTL 4 /* Original TTL */ 41736888Speter#define NS_SIG_EXPIR 8 /* Expiration time */ 41836888Speter#define NS_SIG_SIGNED 12 /* Signature time */ 41936888Speter#define NS_SIG_FOOT 16 /* Key footprint */ 42036888Speter#define NS_SIG_SIGNER 18 /* Domain name of who signed it */ 4211539Srgrimes 42236888Speter/* How RR types are represented as bit-flags in NXT records */ 42336888Speter#define NS_NXT_BITS 8 42436888Speter#define NS_NXT_BIT_SET( n,p) (p[(n)/NS_NXT_BITS] |= (0x80>>((n)%NS_NXT_BITS))) 42536888Speter#define NS_NXT_BIT_CLEAR(n,p) (p[(n)/NS_NXT_BITS] &= ~(0x80>>((n)%NS_NXT_BITS))) 42636888Speter#define NS_NXT_BIT_ISSET(n,p) (p[(n)/NS_NXT_BITS] & (0x80>>((n)%NS_NXT_BITS))) 427156960Sume#define NS_NXT_MAX 127 42821056Speter 429156960Sume/* 430156960Sume * EDNS0 extended flags, host order. 431156960Sume */ 432156960Sume#define NS_OPT_DNSSEC_OK 0x8000U 4331539Srgrimes 4341539Srgrimes/* 4351539Srgrimes * Inline versions of get/put short/long. Pointer is advanced. 4361539Srgrimes */ 437156960Sume#define NS_GET16(s, cp) do { \ 438156960Sume register const u_char *t_cp = (const u_char *)(cp); \ 4393070Spst (s) = ((u_int16_t)t_cp[0] << 8) \ 4403070Spst | ((u_int16_t)t_cp[1]) \ 4413070Spst ; \ 44236888Speter (cp) += NS_INT16SZ; \ 443156960Sume} while (0) 4441539Srgrimes 445156960Sume#define NS_GET32(l, cp) do { \ 446156960Sume register const u_char *t_cp = (const u_char *)(cp); \ 4473070Spst (l) = ((u_int32_t)t_cp[0] << 24) \ 4483070Spst | ((u_int32_t)t_cp[1] << 16) \ 4493070Spst | ((u_int32_t)t_cp[2] << 8) \ 4503070Spst | ((u_int32_t)t_cp[3]) \ 4513070Spst ; \ 45236888Speter (cp) += NS_INT32SZ; \ 453156960Sume} while (0) 4541539Srgrimes 455156960Sume#define NS_PUT16(s, cp) do { \ 4561539Srgrimes register u_int16_t t_s = (u_int16_t)(s); \ 4571539Srgrimes register u_char *t_cp = (u_char *)(cp); \ 4581539Srgrimes *t_cp++ = t_s >> 8; \ 4591539Srgrimes *t_cp = t_s; \ 46036888Speter (cp) += NS_INT16SZ; \ 461156960Sume} while (0) 4621539Srgrimes 463156960Sume#define NS_PUT32(l, cp) do { \ 4641539Srgrimes register u_int32_t t_l = (u_int32_t)(l); \ 4651539Srgrimes register u_char *t_cp = (u_char *)(cp); \ 4661539Srgrimes *t_cp++ = t_l >> 24; \ 4671539Srgrimes *t_cp++ = t_l >> 16; \ 4681539Srgrimes *t_cp++ = t_l >> 8; \ 4691539Srgrimes *t_cp = t_l; \ 47036888Speter (cp) += NS_INT32SZ; \ 471156960Sume} while (0) 4721539Srgrimes 47336888Speter/* 474156960Sume * ANSI C identifier hiding for bind's lib/nameser. 47536888Speter */ 476156960Sume#define ns_msg_getflag __ns_msg_getflag 47736888Speter#define ns_get16 __ns_get16 47836888Speter#define ns_get32 __ns_get32 47936888Speter#define ns_put16 __ns_put16 48036888Speter#define ns_put32 __ns_put32 48136888Speter#define ns_initparse __ns_initparse 482156960Sume#define ns_skiprr __ns_skiprr 48336888Speter#define ns_parserr __ns_parserr 48436888Speter#define ns_sprintrr __ns_sprintrr 48536888Speter#define ns_sprintrrf __ns_sprintrrf 48636888Speter#define ns_format_ttl __ns_format_ttl 48736888Speter#define ns_parse_ttl __ns_parse_ttl 488156960Sume#if 0 489156960Sume#define ns_datetosecs __ns_datetosecs 490156960Sume#endif 491156960Sume#define ns_name_ntol __ns_name_ntol 49236888Speter#define ns_name_ntop __ns_name_ntop 49336888Speter#define ns_name_pton __ns_name_pton 49436888Speter#define ns_name_unpack __ns_name_unpack 49536888Speter#define ns_name_pack __ns_name_pack 49636888Speter#define ns_name_compress __ns_name_compress 49736888Speter#define ns_name_uncompress __ns_name_uncompress 498156467Sume#define ns_name_skip __ns_name_skip 499156960Sume#define ns_name_rollback __ns_name_rollback 500156960Sume#if 0 501156960Sume#define ns_sign __ns_sign 502156960Sume#define ns_sign2 __ns_sign2 503156960Sume#define ns_sign_tcp __ns_sign_tcp 504156960Sume#define ns_sign_tcp2 __ns_sign_tcp2 505156960Sume#define ns_sign_tcp_init __ns_sign_tcp_init 506156960Sume#define ns_find_tsig __ns_find_tsig 507156960Sume#define ns_verify __ns_verify 508156960Sume#define ns_verify_tcp __ns_verify_tcp 509156960Sume#define ns_verify_tcp_init __ns_verify_tcp_init 510158787Sume#endif 511156960Sume#define ns_samedomain __ns_samedomain 512158787Sume#if 0 513156960Sume#define ns_subdomain __ns_subdomain 514156960Sume#endif 515156960Sume#define ns_makecanon __ns_makecanon 516156960Sume#define ns_samename __ns_samename 51736888Speter 51836888Speter__BEGIN_DECLS 519156960Sumeint ns_msg_getflag(ns_msg, int); 52093032Simpu_int ns_get16(const u_char *); 52193032Simpu_long ns_get32(const u_char *); 52293032Simpvoid ns_put16(u_int, u_char *); 52393032Simpvoid ns_put32(u_long, u_char *); 52493032Simpint ns_initparse(const u_char *, int, ns_msg *); 525156960Sumeint ns_skiprr(const u_char *, const u_char *, ns_sect, int); 52693032Simpint ns_parserr(ns_msg *, ns_sect, int, ns_rr *); 52793032Simpint ns_sprintrr(const ns_msg *, const ns_rr *, 52893032Simp const char *, const char *, char *, size_t); 52993032Simpint ns_sprintrrf(const u_char *, size_t, const char *, 53093032Simp ns_class, ns_type, u_long, const u_char *, 53193032Simp size_t, const char *, const char *, 53293032Simp char *, size_t); 53393032Simpint ns_format_ttl(u_long, char *, size_t); 53493032Simpint ns_parse_ttl(const char *, u_long *); 535156960Sume#if 0 536156960Sumeu_int32_t ns_datetosecs(const char *cp, int *errp); 537156960Sume#endif 538156960Sumeint ns_name_ntol(const u_char *, u_char *, size_t); 53993032Simpint ns_name_ntop(const u_char *, char *, size_t); 54093032Simpint ns_name_pton(const char *, u_char *, size_t); 54193032Simpint ns_name_unpack(const u_char *, const u_char *, 54293032Simp const u_char *, u_char *, size_t); 54393032Simpint ns_name_pack(const u_char *, u_char *, int, 54493032Simp const u_char **, const u_char **); 54593032Simpint ns_name_uncompress(const u_char *, const u_char *, 54693032Simp const u_char *, char *, size_t); 54793032Simpint ns_name_compress(const char *, u_char *, size_t, 54893032Simp const u_char **, const u_char **); 54993032Simpint ns_name_skip(const u_char **, const u_char *); 550156960Sumevoid ns_name_rollback(const u_char *, const u_char **, 551156960Sume const u_char **); 552156960Sume#if 0 553156960Sumeint ns_sign(u_char *, int *, int, int, void *, 554156960Sume const u_char *, int, u_char *, int *, time_t); 555156960Sumeint ns_sign2(u_char *, int *, int, int, void *, 556156960Sume const u_char *, int, u_char *, int *, time_t, 557156960Sume u_char **, u_char **); 558156960Sumeint ns_sign_tcp(u_char *, int *, int, int, 559156960Sume ns_tcp_tsig_state *, int); 560156960Sumeint ns_sign_tcp2(u_char *, int *, int, int, 561156960Sume ns_tcp_tsig_state *, int, 562156960Sume u_char **, u_char **); 563156960Sumeint ns_sign_tcp_init(void *, const u_char *, int, 564156960Sume ns_tcp_tsig_state *); 565156960Sumeu_char *ns_find_tsig(u_char *, u_char *); 566156960Sumeint ns_verify(u_char *, int *, void *, 567156960Sume const u_char *, int, u_char *, int *, 568156960Sume time_t *, int); 569156960Sumeint ns_verify_tcp(u_char *, int *, ns_tcp_tsig_state *, int); 570156960Sumeint ns_verify_tcp_init(void *, const u_char *, int, 571156960Sume ns_tcp_tsig_state *); 572158787Sume#endif 573156960Sumeint ns_samedomain(const char *, const char *); 574158787Sume#if 0 575156960Sumeint ns_subdomain(const char *, const char *); 576156960Sume#endif 577156960Sumeint ns_makecanon(const char *, char *, size_t); 578156960Sumeint ns_samename(const char *, const char *); 57936888Speter__END_DECLS 58036888Speter 58136888Speter#ifdef BIND_4_COMPAT 58236888Speter#include <arpa/nameser_compat.h> 58336888Speter#endif 58436888Speter 58510132Speter#endif /* !_ARPA_NAMESER_H_ */ 586