From 9bf471d2082eb5196e894b78da3cf6d1be8c5963 Mon Sep 17 00:00:00 2001 From: Harvie Date: Wed, 4 Aug 2010 08:28:45 +0200 Subject: [PATCH] dnssec-tools: cleaned up verison, still segfaults... dunno why. reported upstream. --- dnssec-tools/PKGBUILD | 10 +++++----- dnssec-tools/dnssec-tools.install | 1 + dnssec-tools/dnsval.conf | 16 +++++++++------- dnssec-tools/resolv.conf | 15 +++++++++++++++ 4 files changed, 30 insertions(+), 12 deletions(-) create mode 100644 dnssec-tools/resolv.conf diff --git a/dnssec-tools/PKGBUILD b/dnssec-tools/PKGBUILD index eac4e7a..28fd6e3 100644 --- a/dnssec-tools/PKGBUILD +++ b/dnssec-tools/PKGBUILD @@ -10,11 +10,12 @@ url="http://www.dnssec-tools.org/" license="Custom" arch=('i686' 'x86_64') depends=(dnssec-root-zone-trust-anchors perl perl-timedate perl-net-dns perl-net-dns-sec) -backup=(etc/dnssec-tools/dnsval.conf.head etc/dnssec-tools/dnsval.conf.tail) +backup=(etc/dnssec-tools/resolv.conf etc/dnssec-tools/root.hints) install="${pkgname}.install" -source=("http://www.dnssec-tools.org/download/${pkgname}-${pkgver}.tar.gz" dnsval.conf) +source=("http://www.dnssec-tools.org/download/${pkgname}-${pkgver}.tar.gz" dnsval.conf resolv.conf) md5sums=('f3dfe18ae50cf65594936e1684d469d0' - '05656944ff9caa959591f547cfe25eba') + 'aaee6f50ab4abbc183f64b5de013f756' + '03ff269fa39d2a7eb6cbe108bcea473a') build() { cd ${srcdir}/${pkgname}-${pkgver}/ || return 1 @@ -44,8 +45,7 @@ build() { msg2 'configuration files' cp -r validator/etc/* "${pkgdir}/etc/${pkgname}/" rm -rf "${pkgdir}/etc/${pkgname}/${pkgname}.conf" #will be generated in post_install - cp -f "${srcdir}/dnsval.conf" "${pkgdir}/etc/dnssec-tools/" - touch "${pkgdir}"/etc/dnssec-tools/dnsval.conf.{head,tail} + cp -f "${srcdir}"/{dnsval,resolv}.conf "${pkgdir}/etc/dnssec-tools/" msg2 'license informations' mkdir -p "${pkgdir}/usr/share/licenses/${pkgname}/" cp COPYING "${pkgdir}/usr/share/licenses/${pkgname}/" diff --git a/dnssec-tools/dnssec-tools.install b/dnssec-tools/dnssec-tools.install index 7cf3b94..34658ce 100644 --- a/dnssec-tools/dnssec-tools.install +++ b/dnssec-tools/dnssec-tools.install @@ -2,6 +2,7 @@ post_install() { echo 'Generating default config file if not exists...' while echo; do true; done 2>/dev/null | dtinitconf >/dev/null + touch /etc/dnssec-tools/dnsval.conf.{head,tail} return 0 } diff --git a/dnssec-tools/dnsval.conf b/dnssec-tools/dnsval.conf index 2b4e984..d6e77e0 100644 --- a/dnssec-tools/dnsval.conf +++ b/dnssec-tools/dnsval.conf @@ -32,13 +32,15 @@ global-options # Default policies ################################## -: trust-anchor - dnssec-tools.org DS 54556 5 2 6B026928292D452A5CC37B3EF327F27F50A29936CB31E664EB066D71A476E282 -; - -: zone-security-expectation - dnssec-tools.org validate -; +#: trust-anchor +# . "974 0 0 MIIDyjCCArKgAwIBAgIBBDANBgkqhkiG9w0BAQsFADBLMQ4wDAYDVQQKEwVJQ0FOTjEYMBYGA1UEAxMPSUNBTk4gRE5TU0VDIENBMR8wHQYJKoZIhvcNAQkBExBkbnNzZWNAaWNhbm4ub3JnMB4XDTEwMDcxNDE3MDEyNVoXDTExMDcxNDE3MDEyNVowgbMxDjAMBgNVBAoTBUlDQU5OMQ0wCwYDVQQLEwRJQU5BMTAwLgYDVQQDEydSb290IFpvbmUgS1NLIDIwMTAtMDYtMTZUMjE6MTk6MjQrMDA6MDAxYDBeBggrBgEEAYdoNRNSLiBJTiBEUyAxOTAzNiA4IDIgNDlBQUMxMUQ3QjZGNjQ0NjcwMkU1NEExNjA3MzcxNjA3QTFBNDE4NTUyMDBGRDJDRTFDRERFMzJGMjRFOEZCNTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKgAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjFFVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoXbfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaDX6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpzW5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relSQageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulqQxA+Uk1ihz0CAwEAAaNQME4wDAYDVR0TAQH/BAIwADAfBgNVHSMEGDAWgBSPskJpw53kPPoTuf/ywKTv2A/oIjAdBgNVHQ4EFgQUQRqS+htWdh5iK3HNGv27Q5lfCckwDQYJKoZIhvcNAQELBQADggEBAI+NnJjL8bGgilX7lb5b6eMimeZeRw6fMgkVQzxt9c4kQ6p8h048II4aP8QUBIzeDZtKuvRsyNjM9oil9OUXCNp3NTY/bsr6oSy9kwdz1G/bg7OfEb+3QXPmXTvCPpwCjIBsz9nfXp+bjzJ0vGi0YkVImML9EClLCOfnHtwrG+fQQSjyCeppHZVe354qwjOv/3Lf7gH0m9FudgA4tFZ7ncsmHn2OKSlJZkkdxZegY83ZigxjMCvL2hG1lcRhast6RJSVaAi81mwQhQk2c3h2HM5DhDR1WikGqBeKID//MoI3v2CK43wpm6I/zciC/Avg1tyOtCFHiAR2lD9b9U/M598=" +# dnssec-tools.org DS 54556 5 2 6B026928292D452A5CC37B3EF327F27F50A29936CB31E664EB066D71A476E282 +#; + +#: zone-security-expectation +# . validate +# dnssec-tools.org validate +#; : provably-insecure-status . trusted diff --git a/dnssec-tools/resolv.conf b/dnssec-tools/resolv.conf new file mode 100644 index 0000000..1deafb5 --- /dev/null +++ b/dnssec-tools/resolv.conf @@ -0,0 +1,15 @@ +#This is list of public DNSSEC validating nameservers +#it should be replaced with symlink to /etc/resolv.conf +#when your nameserver will support DNSSEC. + +#CZ NIC +nameserver 217.31.204.130 +nameserver 2001:1488:800:400::130 +nameserver 217.31.204.131 +nameserver 2001:1488:800:400::131 + +#OARC +nameserver 149.20.64.20 +nameserver 2001:4f8:3:2bc:1::64:20 +nameserver 149.20.64.21 +nameserver 2001:4f8:3:2bc:1::64:21 -- 2.30.2