forked from critical/dns-zones
Merge pull request 'add-secondary-ns-support' (#5) from add-secondary-ns-support into main
Reviewed-on: critical/dns-zones#5 Reviewed-by: Dirk Astrath <dirk@cacert.org>add-secure1-alias-for-www1
commit
1d6b970a6a
@ -0,0 +1,72 @@
|
|||||||
|
# CAcert DNS zones
|
||||||
|
|
||||||
|
CAcert runs its own public DNS nameservers on ns1 and ns2 in its BIT datacenter
|
||||||
|
rack in Ede.
|
||||||
|
|
||||||
|
We use [PowerDNS](https://doc.powerdns.com/authoritative/index.html) installed
|
||||||
|
on Debian systems.
|
||||||
|
|
||||||
|
This repository contains a Python script `update-zones.py` that is used for
|
||||||
|
updating DNS information from this Git repository.
|
||||||
|
|
||||||
|
The canonical URL for this repository is
|
||||||
|
[https://code.cacert.org/critical/dns-zones.git](https://code.cacert.org/critical/dns-zones.git).
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
The server certificate for https://code.cacert.org/ needs to be trusted.
|
||||||
|
Therefore the CAcert root CA certificate needs to be put into
|
||||||
|
`/usr/local/share/ca-certificates` and hast to be registered as trusted by
|
||||||
|
running
|
||||||
|
|
||||||
|
```shell
|
||||||
|
update-ca-certificates
|
||||||
|
```
|
||||||
|
|
||||||
|
The `update-zones.py` script needs `git`, `pdnsutil` and `python3`. We only use
|
||||||
|
the Python 3 standard library and no external dependencies. The script uses
|
||||||
|
`/usr/lib/sendmail` to send change mails. Mail sending has been tested with
|
||||||
|
ssmtp and exim4.
|
||||||
|
|
||||||
|
To make sure that all these prerequisites are met, you may run
|
||||||
|
|
||||||
|
```shell
|
||||||
|
apt install python3 ca-certificates pdns-server git mail-transport-agent
|
||||||
|
```
|
||||||
|
|
||||||
|
## Cloning the repository
|
||||||
|
|
||||||
|
The git configuration on ns1 and ns2 has been adapted to allow remembering the
|
||||||
|
credentials to clone the repository. A separate user pdnssync has been setup to
|
||||||
|
allow cloning the repository.
|
||||||
|
|
||||||
|
This repository is meant to be cloned on the CAcert DNS servers ns1 and ns2.
|
||||||
|
|
||||||
|
```shell
|
||||||
|
cd ~
|
||||||
|
git config --global credential.helper store
|
||||||
|
git config --global pull.ff only
|
||||||
|
git clone https://code.cacert.org/critical/dns-zones.git
|
||||||
|
```
|
||||||
|
|
||||||
|
Credentials will only be asked for the initial clone. The credential helper
|
||||||
|
records them in in `~/.git-credentials`.
|
||||||
|
|
||||||
|
## Updating zones
|
||||||
|
|
||||||
|
The user running the update needs read access to the configuration in
|
||||||
|
`/etc/powerdns` (either member of the pdns group or root).
|
||||||
|
|
||||||
|
```
|
||||||
|
$ cd ~/dns-zones
|
||||||
|
$ git pull
|
||||||
|
$ ./update-zones.py
|
||||||
|
```
|
||||||
|
|
||||||
|
The `update-zones.py` tracks the local status in a branch (default
|
||||||
|
'provisioned') that is updated when
|
||||||
|
|
||||||
|
* a) zone changes have been applied
|
||||||
|
* b) the running PowerDNS is responsible as secondary nameserver
|
||||||
|
|
||||||
|
The `update-zones.py` script should be run on both nameservers.
|
@ -1,21 +0,0 @@
|
|||||||
set -x
|
|
||||||
domain=$1
|
|
||||||
now=$(date +"%Y%m%d_%H%M%S")
|
|
||||||
pdnsutil list-zone $1 > $1.$now
|
|
||||||
grep -v SOA $1 >$1.new
|
|
||||||
grep SOA $1.$now >> $1.new
|
|
||||||
pdnsutil load-zone $1 $1.new
|
|
||||||
pdnsutil increase-serial $1
|
|
||||||
mysqldump powerdns > powerdns.dump.$now
|
|
||||||
|
|
||||||
echo "From: Nameserver NS2 <root@ns2.cacert.org>" > mail.txt
|
|
||||||
echo "To: critical-admin@cacert.org" >> mail.txt
|
|
||||||
echo "Subject: Update of zone $1" >> mail.txt
|
|
||||||
#echo "$1 has now the following zonefile-data:" >>mail.txt
|
|
||||||
pdnsutil list-zone $1 > $1.now
|
|
||||||
echo >>mail.txt
|
|
||||||
diff -u0 -b $1.$now $1.now >>mail.txt
|
|
||||||
echo " ------------------------- " >> mail.txt
|
|
||||||
pdnsutil list-zone $1 >> mail.txt
|
|
||||||
|
|
||||||
cat mail.txt | ssmtp -6 critical-admin@cacert.org
|
|
Loading…
Reference in New Issue