1#!/bin/sh -e 2# 3# Copyright (C) 2009, 2010 Internet Systems Consortium, Inc. ("ISC") 4# 5# Permission to use, copy, modify, and/or distribute this software for any 6# purpose with or without fee is hereby granted, provided that the above 7# copyright notice and this permission notice appear in all copies. 8# 9# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH 10# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY 11# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT, 12# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM 13# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE 14# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR 15# PERFORMANCE OF THIS SOFTWARE. 16 17# $Id: sign.sh,v 1.7 2010/01/18 19:19:31 each Exp $ 18 19SYSTEMTESTTOP=../.. 20. $SYSTEMTESTTOP/conf.sh 21 22RANDFILE=../random.data 23 24for domain in example example.com; do 25 zone=${domain}. 26 infile=${domain}.db.in 27 zonefile=${domain}.db 28 29 keyname1=`$KEYGEN -q -r $RANDFILE -a NSEC3RSASHA1 -b 768 -n zone $zone` 30 keyname2=`$KEYGEN -q -r $RANDFILE -a NSEC3RSASHA1 -b 1024 -f KSK -n zone $zone` 31 32 cat $infile $keyname1.key $keyname2.key > $zonefile 33 34 $SIGNER -3 bebe -r $RANDFILE -o $zone $zonefile > /dev/null 2>&1 35done 36 37# remove "removed" record from example.com, causing the server to 38# send an apparently-invalid NXDOMAIN 39sed '/^removed/d' example.com.db.signed > example.com.db.new 40rm -f example.com.db.signed 41mv example.com.db.new example.com.db.signed 42