1#!/bin/sh -e 2# 3# Copyright (C) 2009, 2010, 2012, 2014 Internet Systems Consortium, Inc. ("ISC") 4# 5# Permission to use, copy, modify, and/or distribute this software for any 6# purpose with or without fee is hereby granted, provided that the above 7# copyright notice and this permission notice appear in all copies. 8# 9# THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH 10# REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY 11# AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT, 12# INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM 13# LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE 14# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR 15# PERFORMANCE OF THIS SOFTWARE. 16 17# Id: sign.sh,v 1.7 2010/01/18 19:19:31 each Exp 18 19SYSTEMTESTTOP=../.. 20. $SYSTEMTESTTOP/conf.sh 21 22for domain in example example.com; do 23 zone=${domain}. 24 infile=${domain}.db.in 25 zonefile=${domain}.db 26 27 keyname1=`$KEYGEN -q -r $RANDFILE -a NSEC3RSASHA1 -b 768 -n zone $zone` 28 keyname2=`$KEYGEN -q -r $RANDFILE -a NSEC3RSASHA1 -b 1024 -f KSK -n zone $zone` 29 30 cat $infile $keyname1.key $keyname2.key > $zonefile 31 32 $SIGNER -3 bebe -r $RANDFILE -o $zone $zonefile > /dev/null 2>&1 33done 34 35# remove "removed" record from example.com, causing the server to 36# send an apparently-invalid NXDOMAIN 37sed '/^removed/d' example.com.db.signed > example.com.db.new 38rm -f example.com.db.signed 39mv example.com.db.new example.com.db.signed 40