dnsmasq: add UCI DNSSEC runtime support
authorSteven Barth <cyrus@openwrt.org>
Wed, 18 Jun 2014 10:04:29 +0000 (10:04 +0000)
committerSteven Barth <cyrus@openwrt.org>
Wed, 18 Jun 2014 10:04:29 +0000 (10:04 +0000)
Ship keys for the root zone and add two uci options to enable
DNSSEC checks:

Option 'dnssec': Activate DNSSEC validation
Option 'dnsseccheckunsigned': Ensure answers without DNSSEC are in
unsigned zones.

Signed-off-by: Andre Heider <a.heider@gmail.com>
SVN-Revision: 41245

package/network/services/dnsmasq/files/dnsmasq.init

index f7edb28806b15cace0b32ec03ccf7400c42ecf13..9f16d5f5d45f9543cf8dc8c08b11a15337376eff 100644 (file)
@@ -14,6 +14,7 @@ ADD_LOCAL_HOSTNAME=1
 
 CONFIGFILE="/var/etc/dnsmasq.conf"
 HOSTFILE="/tmp/hosts/dhcp"
+TRUSTANCHORSFILE="/usr/share/dnsmasq/trust-anchors.conf"
 
 xappend() {
        local value="$1"
@@ -186,6 +187,13 @@ dnsmasq() {
                config_list_foreach "$cfg" rebind_domain append_rebind_domain
        }
 
+       config_get dnssec "$cfg" dnssec
+       [ "$dnssec" -gt 0 ] && {
+               xappend "--conf-file=$TRUSTANCHORSFILE"
+               xappend "--dnssec"
+               append_bool "$cfg" dnsseccheckunsigned "--dnssec-check-unsigned"
+       }
+
        dhcp_option_add "$cfg" "" 0
 
        xappend "--dhcp-broadcast=tag:needs-broadcast"