Phase 1.4: UPDATE opcode handler + TSIG verification
Replaces the Phase-1.3 refuseUpdate() stub with a real RFC 2136 handler. Caddy via caddy-dns/rfc2136 can now inject and remove records. UPDATE message handling (update.go): - Zone section validation: must be exactly one SOA-typed record naming a zone we're authoritative for. Returns FORMERR/NOTAUTH otherwise. - Prerequisites (§3.2): name-exists, RRset-exists, name-NOT-exists, RRset-NOT-exists semantics implemented. First failure short-circuits with the spec's rcode (NXDOMAIN/NXRRSET/YXDOMAIN/YXRRSET). - Updates (§3.4.2): add RR, delete RRset (CLASS=ANY+RDLEN=0), delete all RRsets at name (CLASS=ANY+TYPE=ANY), delete specific RR (CLASS= NONE). - Apex SOA/NS protected: synthetic and cannot be added or removed via UPDATE. Apex wipe (TYPE=ANY at apex) also refused. - Default TTL applied to incoming records with TTL=0. TSIG (tsig.go + setup.go): - setup() now populates dnsserver.Config.TsigSecret so the underlying dns.Server auto-verifies signatures via miekg/dns. - checkTSIG() in ServeDNS gates UPDATEs: rejects if no TSIG, unknown key name, algorithm-downgrade attempt, or w.TsigStatus() != nil. - No TSIG keys configured → all UPDATEs refused (safety default). - Algorithm pinning prevents downgrade attacks (e.g. forced HMAC-MD5). Tests (update_test.go): 11 new cases covering happy paths and every error rcode. Total: 35 top-level test passes, 0 failures. ServeDNS dispatch now calls handleUpdate after auth gate. The refuseUpdate() stub is gone. UPDATE end-to-end via nsupdate requires the custom CoreDNS image (Phase 2) to verify TSIG plumbing on the dns.Server side.
This commit is contained in:
parent
1cca9a5aa7
commit
1d2d919728
5 changed files with 537 additions and 16 deletions
23
setup.go
23
setup.go
|
|
@ -1,6 +1,7 @@
|
|||
package rfc2136
|
||||
|
||||
import (
|
||||
"encoding/base64"
|
||||
"strconv"
|
||||
|
||||
"github.com/coredns/caddy"
|
||||
|
|
@ -26,7 +27,27 @@ func setup(c *caddy.Controller) error {
|
|||
return plugin.Error("rfc2136", err)
|
||||
}
|
||||
|
||||
dnsserver.GetConfig(c).AddPlugin(func(next plugin.Handler) plugin.Handler {
|
||||
cfg := dnsserver.GetConfig(c)
|
||||
|
||||
// Register our TSIG keys with the underlying dns.Server so miekg/dns
|
||||
// auto-verifies incoming signatures. We then just inspect the
|
||||
// verification result via dns.ResponseWriter.TsigStatus() in our
|
||||
// UPDATE handler — no need to do MAC arithmetic ourselves.
|
||||
//
|
||||
// dns.Server.TsigSecret expects base64-encoded secrets, so we
|
||||
// re-encode (the parser decoded them at Corefile-load time, and
|
||||
// keeping the raw bytes lets future code do other things with
|
||||
// them).
|
||||
if len(p.TSIGKeys) > 0 {
|
||||
if cfg.TsigSecret == nil {
|
||||
cfg.TsigSecret = make(map[string]string)
|
||||
}
|
||||
for name, key := range p.TSIGKeys {
|
||||
cfg.TsigSecret[name] = base64.StdEncoding.EncodeToString(key.Secret)
|
||||
}
|
||||
}
|
||||
|
||||
cfg.AddPlugin(func(next plugin.Handler) plugin.Handler {
|
||||
p.Next = next
|
||||
return p
|
||||
})
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue