Release 1.7.0: complete the secDNS (DNSSEC) extension per RFC 5910 - #61
Merged
Merged
Conversation
Fixes #31. SecDNSCreate and SecDNSUpdate only handled dsData. - keyData: SecDNSKeyData, usable on its own (create KeyData, update KeyDataToAdd/KeyDataToRemove) or inside a dsData (SecDNSData.KeyData). - SecDNSUpdate: RemoveAll (rem/all), MaxSigLife (chg), Urgent. The schema's choices (dsData or keyData, one kind of rem) are enforced with InvalidOperationException. - SecDNSInfData.FromResponse reads secDNS:infData from any domain info response, including the Nominet and IIS subclasses. - SecDNSData.KeyTag is now an int: key tags run to 65535 and a short could not hold half of them. DigestType can be set (default stays SHA1 for compatibility; digestType was hard-coded to 1). - SecDNSAlgorithm names current algorithms (RSASHA256, ECDSAP256SHA256, ED25519 and others). Tests follow the RFC 5910 examples and validate the generated XML against secDNS-1.1.xsd. Bump to 1.7.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #31.
Summary
The secDNS extension only handled
dsData. This adds the rest of RFC 5910:keyData: newSecDNSKeyData. It works on its own (SecDNSCreate.KeyData,SecDNSUpdate.KeyDataToAdd/KeyDataToRemove) or inside a DS record (SecDNSData.KeyData).RemoveAll(<secDNS:rem><secDNS:all>)MaxSigLife(<secDNS:chg>)Urgent(theurgentattribute)InvalidOperationExceptioninstead of producing XML the registry would reject.SecDNSInfData.FromResponse(response)readssecDNS:infDatafrom any domain info response, includingNominetDomainInfoResponseandIisDomainInfoResponse. It returns null when a response has none.maxSigLifeon create, which the issue lists, was already supported.Bugs found along the way
SecDNSData.KeyTagwas ashort, but key tags run from 0 to 65535, so about half of real keys couldn't be sent. It's now anint. Existing code likeKeyTag = 12345still compiles; code that readsKeyTaginto ashortwon't.digestTypewas hard-coded to 1 (SHA-1). The newDigestTypeproperty accepts SHA256 and others. The default stays SHA1 so existing callers send the same XML.SecDNSAlgorithmstopped at algorithm 5. It now names 6–8, 10 and 12–16, including RSASHA256 (8), ECDSAP256SHA256 (13) and ED25519 (15).Version bumped to 1.7.0. The
KeyTagtype change breaks binary compatibility, so callers need to recompile.Testing
dsDatapluskeyDatakeyDataonlymaxSigLifekeyDatamaxSigLifesecDNS-1.1.xsd, which the test project now copies to its output directory.🤖 Generated with Claude Code