diff --git a/2001:07b8:616.ip6 b/2001:07b8:616.ip6 index 1cefb9c..f1b9c0b 100644 --- a/2001:07b8:616.ip6 +++ b/2001:07b8:616.ip6 @@ -1,10 +1,10 @@ ; DNS master zone file for reverse IPv6 for cacert.org, under RCS control -; @(#)(CAcert) $Id: 2001:07b8:616.ip6,v 1.9 2015/03/04 10:56:01 root Exp $ +; @(#)(CAcert) $Id: 2001:07b8:616.ip6,v 1.11 2018/02/25 09:27:53 root Exp $ $TTL 12h ; default TTL for zone data @ IN SOA ns1.cacert.org. hostmaster.cacert.org. ( - 2015030401 ; Serial + 2018022501 ; Serial 4h ; refresh time 1h ; retry interval 2d ; expire time @@ -22,7 +22,7 @@ $TTL 12h ; default TTL for zone data ; infra - 2001:07b8:0616:0162:0001::/80 9.0.0.0.0.0.0.0.0.0.0.0.1.0.0.0.2.6.1.0 PTR infra01.cacert.org. -0.1.0.0.0.0.0.0.0.0.0.0.1.0.0.0.2.6.1.0 PTR infra02.cacert.org. +0.1.0.0.0.0.0.0.0.0.0.0.1.0.0.0.2.6.1.0 PTR infrastructure.cacert.org. ; infra - 2001:07b8:0616:0162:0002::/80 0.1.0.0.0.0.0.0.0.0.0.0.2.0.0.0.2.6.1.0 PTR infra02.cacert.org. @@ -46,7 +46,7 @@ $TTL 12h ; default TTL for zone data 2.3.0.0.0.0.0.0.0.0.0.0.2.0.0.0.2.6.1.0 PTR emailout.cacert.org. 4.3.0.0.0.0.0.0.0.0.0.0.2.0.0.0.2.6.1.0 PTR board.cacert.org. 4.3.0.0.0.0.0.0.0.0.0.0.2.0.0.0.2.6.1.0 PTR cod.cacert.org. -1.4.2.0.0.0.0.0.0.0.0.0.2.0.0.0.2.6.1.0 PTR arbitration.cacert.org. +1.0.2.0.0.0.0.0.0.0.0.0.2.0.0.0.2.6.1.0 PTR proxyout.cacert.org. 8.4.2.0.0.0.0.0.0.0.0.0.2.0.0.0.2.6.1.0 PTR test.cacert.org. 9.4.2.0.0.0.0.0.0.0.0.0.2.0.0.0.2.6.1.0 PTR test2.cacert.org. 0.5.2.0.0.0.0.0.0.0.0.0.2.0.0.0.2.6.1.0 PTR git.cacert.org. diff --git a/2001:07b8:616.ip6.log b/2001:07b8:616.ip6.log index eccc2bd..18429d7 100644 --- a/2001:07b8:616.ip6.log +++ b/2001:07b8:616.ip6.log @@ -1,16 +1,25 @@ RCS file: /var/opendnssec/unsigned/RCS/2001:07b8:616.ip6,v Working file: /var/opendnssec/unsigned/2001:07b8:616.ip6 -head: 1.9 +head: 1.11 branch: locks: strict access list: symbolic names: keyword substitution: kv -total revisions: 9; selected revisions: 9 +total revisions: 11; selected revisions: 11 description: 2001:07b8:616.ip6 - zone file for reverse IPv6 of cacert.org ---------------------------- +revision 1.11 +date: 2018/02/25 09:27:53; author: root; state: Exp; lines: +4 -3 +Update infra02 to infrastructure, add reverse IPv6 for proxyout.cacert.org. +---------------------------- +revision 1.10 +date: 2018/02/15 16:15:21; author: root; state: Exp; lines: +2 -3 +Drop all records for arbitrations.cacert.org per e-mail request +from Jan Dittberner on 15.02.2018. +---------------------------- revision 1.9 date: 2015/03/04 10:56:01; author: root; state: Exp; lines: +29 -26 Move infra LXC containers to a separate /80 subnet. diff --git a/213.154.225.224.ip4 b/213.154.225.224.ip4 index e6dc200..318f383 100644 --- a/213.154.225.224.ip4 +++ b/213.154.225.224.ip4 @@ -1,10 +1,10 @@ ; DNS master zone file for reverse IPv4 for CAcert 213.154.225.224/27 -; @(#)(CAcert) $Id: 213.154.225.224.ip4,v 1.3 2014/02/06 13:39:51 root Exp $ +; @(#)(CAcert) $Id: 213.154.225.224.ip4,v 1.5 2018/02/18 14:33:18 root Exp $ $TTL 12h ; default TTL for zone data @ IN SOA ns1.cacert.org. hostmaster.cacert.org. ( - 2014020601 ; Serial + 2018021801 ; Serial 4h ; refresh time 1h ; retry interval 2d ; expire time @@ -30,8 +30,7 @@ $TTL 12h ; default TTL for zone data 238 IN PTR svn.cacert.org. 239 IN PTR emailout.cacert.org. 240 IN PTR translations.cacert.org. -241 IN PTR arbitration.cacert.org. -242 IN PTR cacert.eu. +242 IN PTR web.cacert.org. 243 IN PTR cats.cacert.org. 244 IN PTR issue.cacert.org. 245 IN PTR www.cacert.org. diff --git a/213.154.225.224.ip4.log b/213.154.225.224.ip4.log index 28f0756..01f9b68 100644 --- a/213.154.225.224.ip4.log +++ b/213.154.225.224.ip4.log @@ -1,16 +1,26 @@ RCS file: /var/opendnssec/unsigned/RCS/213.154.225.224.ip4,v Working file: /var/opendnssec/unsigned/213.154.225.224.ip4 -head: 1.3 +head: 1.5 branch: locks: strict access list: symbolic names: keyword substitution: kv -total revisions: 3; selected revisions: 3 +total revisions: 5; selected revisions: 5 description: 213.154.225.224.ip4 - zone file for reverse IPv4 of cacert.org ---------------------------- +revision 1.5 +date: 2018/02/18 14:33:18; author: root; state: Exp; lines: +3 -3 +Update PTR record for 242 from cacert.eu. to web.cacert.org. per e-mail request +from Jan Dittberner on 17.02.2018. +---------------------------- +revision 1.4 +date: 2018/02/15 15:59:08; author: root; state: Exp; lines: +2 -3 +Drop all records for arbitrations.cacert.org per e-mail request +from Jan Dittberner on 15.02.2018. +---------------------------- revision 1.3 date: 2014/02/06 13:39:51; author: root; state: Exp; lines: +3 -3 Name changes per e-mail request from Mario Lipinski on 05.02.2014. diff --git a/cacert.com b/cacert.com index a5b75d3..490719c 100644 --- a/cacert.com +++ b/cacert.com @@ -1,10 +1,10 @@ ; DNS master zone file for cacert.com, under RCS control -; @(#)(CAcert) $Id: cacert.com,v 1.22 2016/10/12 07:18:06 root Exp $ +; @(#)(CAcert) $Id: cacert.com,v 1.23 2017/09/29 13:36:39 root Exp $ $TTL 12h ; default TTL for zone data @ 1h IN SOA ns1.cacert.com. hostmaster.cacert.com. ( - 2016101201 ; Serial + 2017092901 ; Serial 4h ; refresh time 1h ; retry interval 7d ; expire time @@ -18,6 +18,10 @@ $TTL 12h ; default TTL for zone data @ IN A 213.154.225.245 @ IN MX 10 email.cacert.org. +@ IN CAA 0 issue "cacert.org" +@ IN CAA 0 issuewild "cacert.org" +@ IN CAA 0 iodef "critical-admin@cacert.org" + ns1 IN A 213.154.225.251 ; ns.cacert.org ns1 IN AAAA 2001:7b8:616:0163::102 ns3 IN A 46.249.47.169 ; mars.overmeer.net diff --git a/cacert.com.log b/cacert.com.log index a0c06cf..f4a4923 100644 --- a/cacert.com.log +++ b/cacert.com.log @@ -1,16 +1,20 @@ RCS file: /var/opendnssec/unsigned/RCS/cacert.com,v Working file: /var/opendnssec/unsigned/cacert.com -head: 1.22 +head: 1.23 branch: locks: strict access list: symbolic names: keyword substitution: kv -total revisions: 22; selected revisions: 22 +total revisions: 23; selected revisions: 23 description: cacert.com - zone file for cacert.com ---------------------------- +revision 1.23 +date: 2017/09/29 13:36:39; author: root; state: Exp; lines: +6 -2 +Add CAA records. +---------------------------- revision 1.22 date: 2016/10/12 07:18:06; author: root; state: Exp; lines: +4 -4 Set TTL for SOA to 1 hour, and SOA expire time to 7 days, per web recommendations. diff --git a/cacert.net b/cacert.net index dc10cd7..ad44deb 100644 --- a/cacert.net +++ b/cacert.net @@ -1,10 +1,10 @@ ; DNS master zone file for cacert.net, under RCS control -; @(#)(CAcert) $Id: cacert.net,v 1.23 2016/10/12 07:18:06 root Exp $ +; @(#)(CAcert) $Id: cacert.net,v 1.24 2017/09/29 13:36:39 root Exp $ $TTL 12h ; default TTL for zone data @ 1h IN SOA ns1.cacert.net. hostmaster.cacert.net. ( - 2016101201 ; Serial + 2017092901 ; Serial 4h ; refresh time 1h ; retry interval 7d ; expire time @@ -18,6 +18,10 @@ $TTL 12h ; default TTL for zone data @ IN A 213.154.225.245 @ IN MX 10 email.cacert.org. +@ IN CAA 0 issue "cacert.org" +@ IN CAA 0 issuewild "cacert.org" +@ IN CAA 0 iodef "critical-admin@cacert.org" + ns1 IN A 213.154.225.251 ; ns.cacert.org ns1 IN AAAA 2001:7b8:616:0163::102 ns3 IN A 46.249.47.169 ; mars.overmeer.net diff --git a/cacert.net.log b/cacert.net.log index f121f96..208c347 100644 --- a/cacert.net.log +++ b/cacert.net.log @@ -1,16 +1,20 @@ RCS file: /var/opendnssec/unsigned/RCS/cacert.net,v Working file: /var/opendnssec/unsigned/cacert.net -head: 1.23 +head: 1.24 branch: locks: strict access list: symbolic names: keyword substitution: kv -total revisions: 23; selected revisions: 23 +total revisions: 24; selected revisions: 24 description: cacert.net - DNS master zone file for cacert.net, under RCS control ---------------------------- +revision 1.24 +date: 2017/09/29 13:36:39; author: root; state: Exp; lines: +6 -2 +Add CAA records. +---------------------------- revision 1.23 date: 2016/10/12 07:18:06; author: root; state: Exp; lines: +4 -4 Set TTL for SOA to 1 hour, and SOA expire time to 7 days, per web recommendations. diff --git a/cacert.org b/cacert.org index 659866c..6ad3f1c 100644 --- a/cacert.org +++ b/cacert.org @@ -1,10 +1,10 @@ ; DNS master zone file for cacert.org, under RCS control -; @(#)(CAcert) $Id: cacert.org,v 1.104 2016/10/12 07:18:06 root Exp $ +; @(#)(CAcert) $Id: cacert.org,v 1.110 2018/02/25 09:19:36 root Exp $ $TTL 12h ; default TTL for zone data @ 1h IN SOA ns1.cacert.org. hostmaster.cacert.org. ( - 2016101201 ; Serial + 2018022501 ; Serial 4h ; refresh time 1h ; retry interval 7d ; expire time @@ -21,13 +21,19 @@ $TTL 12h ; default TTL for zone data ; TODO: Remove 'ip4:213.154.225.239' after transition @ IN TXT "v=spf1 ip4:213.154.225.245 ip4:213.154.225.246 ip4:213.154.225.247 ip6:2001:7b8:3:9c::245 ip6:2001:7b8:3:9c::246 ip6:2001:7b8:3:9c::247 ip4:213.154.225.228 ip4:213.154.225.230 ip4:213.154.225.239 -all" -arbitration IN A 213.154.225.241 -arbitration IN SSHFP 1 1 40d9c8ebcf8d41a04b990fbc5308675d029bf4ef -arbitration IN SSHFP 2 1 7474bfb01af775511805bf15c45bb9d7591d0ce6 +@ IN CAA 0 issue "cacert.org" +@ IN CAA 0 issuewild "cacert.org" +@ IN CAA 0 iodef "critical-admin@cacert.org" blog IN A 213.154.225.234 blog IN SSHFP 1 1 32ca6e4ba3275aab0d65f0f46969b11a4c4b36e8 +blog IN SSHFP 1 2 3afb452ac3690cf7cd9a3332813bf7b13dbd288c7a4efbd9ab9dd4b4649ff2b6 blog IN SSHFP 2 1 aafba94ebe5c5c45cdf5ef10d0bc31bea4d9ecec +blog IN SSHFP 2 2 4d4384ebd1906125ae26d2fa976596af914b4b3587f2204a0e01368a3640f680 +blog IN SSHFP 3 1 8fa85a31215f10ea78fd0126d1c705c9a3662c86 +blog IN SSHFP 3 2 86d330b900db9bf0a8bc9ec34b126aa8261fec9e02b123ab61c2aee0b56ae047 +blog IN SSHFP 4 1 90903e8f4b35457bf41235f070adf592d7f724dd +blog IN SSHFP 4 2 f24b770c16dcb91afc9461e62e6fe63a63d413efa4794751c039ed6d5213127b board IN A 213.154.225.252 board IN SSHFP 1 1 f5c02a860a1cc07aeefbf802540680c7476bde6e @@ -36,7 +42,13 @@ finance IN CNAME board.cacert.org. bugs IN A 213.154.225.232 bugs IN SSHFP 1 1 4b4bc32c4e655559b43a370b77cad4983e8c24f8 +bugs IN SSHFP 1 2 51f10258849d1194f282deb0da97009016423d5f0b28a0056a551c4f38c2870a bugs IN SSHFP 2 1 7916e317983d8bc85d719bb793e5e46a6b4976b2 +bugs IN SSHFP 2 2 7632a8a40f1534a3afa3c630d062062dd23c7b1fd24fc518334d82cfa4977892 +bugs IN SSHFP 3 1 72737bd1240b446c2b8e0aad0acff889e3b72ec7 +bugs IN SSHFP 3 2 152fc9f8d7d72979846757db7fa433bd3f6340cd0dcebcce5d681e60dc46ca44 +bugs IN SSHFP 4 1 bb6b5f8599c3a93383392b80cc029a0d65ffc7f1 +bugs IN SSHFP 4 2 caa52e4c5ddecc5ee144aa2b6965101961ff7e7518063b43908d133f1cdf6e15 cacert-fw IN A 213.154.225.229 cacert-fw IN AAAA 2001:7b8:3:9c::4 @@ -71,8 +83,6 @@ cats IN SSHFP 2 2 0835241a5b1905097c332b176faec92e05c690169ba125184f3fe2c9612d9 cats IN SSHFP 3 1 cc7f9edc6f2b9ce4a3f3953ff97c951572ba0f8c cats IN SSHFP 3 2 1f54953c96de0e93cd19e66ca25085d6773ceefd3c376be2e77c1a337ccd008d -coaudit IN CNAME infrastructure.cacert.org. - community-vpn IN A 78.47.142.76 critmon IN A 89.106.208.38 @@ -99,24 +109,10 @@ emailout IN SSHFP 2 1 0e8888352604dbd1cc4d201bc1e985d80b9cf752 emailout IN SSHFP 2 2 a7402f014b47b805663c904dabbc9590db7d8d0f350cea6d9f63e12bc27bac0c emailout IN SSHFP 3 1 527004f2091d2cef2c28b5f8241fc0e76307b2ba emailout IN SSHFP 3 2 9094dcf8860523a83542ec4cc46fbcfed396f5525bc202cfecf42d1a7044136d +emailout IN SSHFP 4 1 63f40df8536052d33d2d515eceb111ccb7983619 +emailout IN SSHFP 4 2 4ceb488ad17ea7c8db161fdf3357e273d2ea1fe5be183794aacd7c4bfdfaa8a5 -eu IN A 213.154.225.242 -web IN A 213.154.225.242 -web IN SSHFP 1 1 85f5338d90930200cbbfce1aab56988b4c8f0f22 -web IN SSHFP 1 2 d39cbd51588f322f7b4384274cf0166f25b10f54a6cd153ed7251ff30b5b516e -web IN SSHFP 2 1 906f0c17bb0e233b0f52ce33cfe64038d45ac4f2 -web IN SSHFP 2 2 dbf6221a8a403b4c9f537b676305fdae07ff45a1c18d88b1141031402af0250f -web IN SSHFP 3 1 7b62d8d1e093c28cda0f3d2444846128b41c10de -web IN SSHFP 3 2 0917da677c9e6caf1818c1151ec2a813623a2b2955a1a850f260d64ef041400b - -funding IN A 213.154.225.242 -webstatic IN A 213.154.225.242 -webstatic IN SSHFP 1 1 30897a7a984d8350495946d54c6374e9331237ef -webstatic IN SSHFP 1 2 32bb10c5cf48532d077066e012230058ddf3cce731c561f228e310eb7a546e3f -webstatic IN SSHFP 2 1 868361a51ec60607bfd964d0f8f3e4ee5e803fc6 -webstatic IN SSHFP 2 2 a173bb85ec19f63ecb273bca130ef63501fe1b89fd55b62997195e6816cab547 -webstatic IN SSHFP 3 1 7fc847cec20b9d65296d4a0edafba22a14ee9dc4 -webstatic IN SSHFP 3 2 68879264e0ed5d0914797bf2292436fb32cca24683dcf5d927a53589c1bfb6d7 +funding IN CNAME web.cacert.org. git IN A 213.154.225.250 git IN SSHFP 1 1 23c7622d6db5822c809152c1c0fd9ea7838f76c6 @@ -125,6 +121,8 @@ git IN SSHFP 2 1 8509db491902fe10ab84c8f24b02f10c1adf0e7f git IN SSHFP 2 2 00c20c26b6b9a026bbb11b5c45cbec5d3ab44a039dc0f097cad88374d3567d01 git IN SSHFP 3 1 60de5788bd83abc7f315b667f634bda5da8502ed git IN SSHFP 3 2 132bd98483440124f6b8117148b02a66645477f53c18f974e4decb32a7495644 +git IN SSHFP 4 1 13d611007b43d073cf4d89784510398116623eb7 +git IN SSHFP 4 2 40a61a25488fe01c056eaaff703ef0ff9c6b01bee00580a91b95741dfaa59751 hopper IN A 213.136.19.144 hopper IN AAAA 2001:7b8:616:0162::100 @@ -135,9 +133,10 @@ hopper IN SSHFP 2 2 de43b28a103b0afa685dd4918515f0b8ddbc4422b476a5af3374af63831 hopper IN SSHFP 3 1 f450a0cb1816e519b3f03e9ea9c8a54a94955071 hopper IN SSHFP 3 2 cc1b07f5bc75760dbb98a5bc515bf9cf7f3559bff032d56ba37b32bc38031375 -infradocs IN CNAME webstatic.cacert.org. +infradocs IN CNAME web.cacert.org. infrastructure IN A 213.154.225.230 +infrastructure IN AAAA 2001:7b8:616:162:1::10 infrastructure IN SSHFP 1 1 5a82d3c150af002c05784f73250a067053aeed63 infrastructure IN SSHFP 1 2 63b0d74a3f1ce61865a5eb0497ef05243bc4067ec983c69ab8e62f3cb940cc82 infrastructure IN SSHFP 2 1 af8d8e3386eaa72997709632adf2b457e6fef0dc @@ -160,6 +159,8 @@ jenkins IN SSHFP 2 1 4ce4eef515bdee033d68b92419f71679880b2fd5 jenkins IN SSHFP 2 2 7e76d01b8dc48178535f3f6164c07ef35d3436f352db8c62ffacd5b8e3c106a7 jenkins IN SSHFP 3 1 1ce55a42b27bf42a78e281440f146da17255a97d jenkins IN SSHFP 3 2 20763231fecf9518c2cecab05ac76e4483f563c0853f8b8a53e469316da75381 +jenkins IN SSHFP 4 1 157ca8b4329dd78f2f83a6cdc0fc11009387c47f +jenkins IN SSHFP 4 2 db988ff234a4948bbcb1a61ff21c080efed454825141b0a1d041921f78573562 lists IN A 213.154.225.231 lists IN SSHFP 1 1 87f75b9124326b566ed22dcf65a9740eede8f0ff @@ -174,7 +175,16 @@ lists._domainkey.lists IN TXT "v=DKIM1\;g=*\;k=rsa\;t=y\;p=MIGfMA0GCSqGSIb3DQEBA mail._domainkey IN TXT "v=DKIM1\;g=*\;k=rsa\;t=y\;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDOZV5h3rm18QRiNfNnwXadX8jeSC3zjpU7GFNTfZk1ifjLxrlVrSsfAvlVfFvR2/uQXegwEkiNV5bd57d989T+VVLZZbSv+OAXX4ZwihsLkf3huDszKtJTvsybqUNh97OE00THSyJCrcowFDcLv5IN2ULCOlMjTqbZxZuaNW0S6wIDAQAB" auto._domainkey IN TXT "v=DKIM1\;g=*\;k=rsa\;t=y\;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDDNFxiNr+NHJwih3OPhGr4iwLE+BBDu72YrMSzUnU1FF50CW7iOtuhg796UZ6xrZ5VuhAix6YmmzcvF2UxYzoD/XpfZ4MzBu0ND4/nkt9/YOTyIBzwQqn9uMNve0Y76Zsel89dIJtOI+y+lfnFExV0jKwe53gzmxMVpMSSCcZPGwIDAQAB" ; ----- DKIM auto for cacert.org -monitor IN CNAME infrastructure.cacert.org. +monitor IN A 213.154.225.230 +monitor IN AAAA 2001:7b8:616:162:2::18 +monitor IN SSHFP 1 1 1128972fb54f927477a781718e2f9c114e9ca383 +monitor IN SSHFP 1 2 f223904069aeaa2e0eac5d9092ab7debae70f06ec3c25e94f49f1b15f633ed5d +monitor IN SSHFP 2 1 3a36e5df06304c481f01fc723fd88a086e82d986 +monitor IN SSHFP 2 2 4a1ff7396ae874559cf196d54d5d7f6890dba6de73b46af049258b1024cdace2 +monitor IN SSHFP 3 1 f2178de365fc5539681c4c1a8d4111688a7403d6 +monitor IN SSHFP 3 2 196bd8aa1414b7d20d87fed5455bba67660e468cbf633801c4d0665fe66f32c9 +monitor IN SSHFP 4 1 442f4f28905fc6a58bfe12c3f2eafe2938f25573 +monitor IN SSHFP 4 2 2f9ae80bcebb6efc432747246e12103add80f4d875450055b882455b0acf2c6 ns IN A 213.154.225.251 ; master ns1 IN A 213.154.225.251 ; ns.cacert.org @@ -196,22 +206,30 @@ ocsp1 IN AAAA 2001:7b8:616:0163::103 openppm IN A 194.24.160.131 -pgpkeys IN CNAME infrastructure.cacert.org. +proxyout IN AAAA 2001:7b8:616:162:2::201 +proxyout IN SSHFP 1 1 9666fa7a0850e1ba358bb4a7ff701ba66d81a0d9 +proxyout IN SSHFP 1 2 4dfb03b90dadb969d39692e71482f19596be20ea42f7b426c430251a009ad3f2 +proxyout IN SSHFP 3 1 abc0a160b7b7e1b33e6d5857514e3fbcaf112ef9 +proxyout IN SSHFP 3 2 77bf57015934a6ca4856823b8b87dfa2133b3e3681309761d49e32bfee19e66b +proxyout IN SSHFP 4 1 89d5470cfccd0bacb292a74c824ffa40433ef28a +proxyout IN SSHFP 4 2 dbaca22544f735faa91432e00205d2b112fba6932222936a2a67c388cc6902a7 -policy IN CNAME webstatic.cacert.org. -www.policy IN CNAME webstatic.cacert.org. -preview.policy IN CNAME webstatic.cacert.org. -_443._tcp.policy IN TLSA 3 1 1 b782b34ae598c658604f23c0915c1affeffcaf932c35d3edb7999410d7515405 -_443._tcp.www.policy IN TLSA 3 1 1 b782b34ae598c658604f23c0915c1affeffcaf932c35d3edb7999410d7515405 -_443._tcp.preview.policy IN TLSA 3 1 1 b782b34ae598c658604f23c0915c1affeffcaf932c35d3edb7999410d7515405 +pgpkeys IN CNAME infrastructure.cacert.org. secure IN A 213.154.225.246 secure IN AAAA 2001:7b8:3:9c::246 _443._tcp.secure IN TLSA 2 0 0 3082073d30820525a003020102020100300d06092a864886f70d010104050030793110300e060355040a1307526f6f74204341311e301c060355040b1315687474703a2f2f7777772e6361636572742e6f7267312230200603550403131943412043657274205369676e696e6720417574686f726974793121301f06092a864886f70d0109011612737570706f7274406361636572742e6f7267301e170d3033303333303132323934395a170d3333303332393132323934395a30793110300e060355040a1307526f6f74204341311e301c060355040b1315687474703a2f2f7777772e6361636572742e6f7267312230200603550403131943412043657274205369676e696e6720417574686f726974793121301f06092a864886f70d0109011612737570706f7274406361636572742e6f726730820222300d06092a864886f70d01010105000382020f003082020a0282020100ce22c0e2467dec3628075096f2a033408c4bf13b663f31e56b0236dbd67cf6f1888f4e7736054195f909f012cf46867360b76e7ee8c05864aecdb0ad45170c63fa670ae8d6d2bf3ee798c4f04cfae003bb355d6c21de9e20d9bacd66323772faf708f5c7cd58c98ee70e5eea3efe1ca1140a156c86845b64662a7aa94b5379f588a27bee2f0a612b8db27e4d56a513eceada929eac44411e5860650566f8c044bdcb94f7427e0bf76568985105f0f30591041d1b1782ecc857bbc36b7a88f1b072cc255b2091ec1602128f32e9171848d0c7052e023042b8259c056b3faa3aa7eb5348f7e8d2b60798dc1bc6347f7fc91c827a05582b085bf338a2ab175d66c998d79e108ba2d2dd749af7710c7260dfcd6f98339d9634763e247a92b00e951e6fe6a0453847aad741ed4ab712f6d71b838a0f2ed809b659d7aa04ffd2937d682edd8b4bab58ba2f8dea95a7a0c35489a5fbdb8b51229db2c3be11be2c91868b9678ad20d38a2f1a3fc6d051658721b11901657f451c87f57cd0414c4f299821fd331f750c0451fa1977dbd4141cee81c31df598b769069122dd0050cc8131ac12077b38da685be62bd47ec95fade8eb724cf301e54b20bf9aa657ca9100018ba1752137b5630d673e464f702067cec5d659db02e0f0d2cbcdba62b79041e8dd20e429bc642942c822dc789aff43ec981b09514b5a5ac271f1c4cb73a9e5a10b0203010001a38201ce308201ca301d0603551d0e0416041416b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d13081a30603551d2304819b308198801416b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1a17da47b30793110300e060355040a1307526f6f74204341311e301c060355040b1315687474703a2f2f7777772e6361636572742e6f7267312230200603550403131943412043657274205369676e696e6720417574686f726974793121301f06092a864886f70d0109011612737570706f7274406361636572742e6f7267820100300f0603551d130101ff040530030101ff30320603551d1f042b30293027a025a023862168747470733a2f2f7777772e6361636572742e6f72672f7265766f6b652e63726c303006096086480186f84201040423162168747470733a2f2f7777772e6361636572742e6f72672f7265766f6b652e63726c303406096086480186f842010804271625687474703a2f2f7777772e6361636572742e6f72672f696e6465782e7068703f69643d3130305606096086480186f842010d04491647546f2067657420796f7572206f776e20636572746966696361746520666f7220465245452068656164206f76657220746f20687474703a2f2f7777772e6361636572742e6f7267300d06092a864886f70d0101040500038202010028c7ee9c8202ba5c8012ca350a1d816f896a99ccf2680f7fa7e18d58953ebdf206c3905aacb560f6994301a388709c9d629da487af67580d30363be6ad48d3cb740286713ee22b0368f1346240463b53ea28f4acfb6695538a4d5dfd3bd960d7ca79693bb16592a6c681825c9ccdeb4d018aa5df1155aa15ca1f37c082987061db6a7c96a38e2e543e4f21a990efdc82bfdce845ad4d9073083c9465b00499767fe2bcc26a15aa97043724d81e944e6d0e51bed6c48fca966df743dfe83065273b7bbb434363c443f7b2ec68cce1198e22fb98e17b5a3e01373b8b08b0a2f3954e1acb9bcd9ab1dbb270f02d4adbd8b0e36f45483312fffe3c322a54f7c4f78af08823c247fe647a71c0d11ea663b0077ea42fd3018fdc9f2bb6c608a90f934825fc12fd9f42dcf3c43ef657b0d7dd69d10677340a4bd2caa0ff1cc68cc916bec4cc323768735f08fb51f7495336050a95024cf2791a10f6d83a759cf31df1a20d7067861bb316f52fe5a4eb7986f93d0bc2730ba599ac6ffc67b8e52f0ba618248d7bd14835291840ac9360e1968650b47a59d88f210b9fcf8291c63bbf6bdc0791b9975623aab66c94c648063ce4ce4eaae4f62f09dc536f2efc74eb3a6399c2a6ac89bca7b244a00d8a10e36cf224cbfa9b9f70472ede148bd4b2200996a264f1241cdca1359c15b2d4bc552e7d06f59c0e55f45ad693da76ad25734cc543 svn IN A 213.154.225.238 +svn IN AAAA 2001:7b8:616:162:2::15 svn IN SSHFP 1 1 1128972fb54f927477a781718e2f9c114e9ca383 svn IN SSHFP 2 1 3a36e5df06304c481f01fc723fd88a086e82d986 +svn IN SSHFP 1 2 f223904069aeaa2e0eac5d9092ab7debae70f06ec3c25e94f49f1b15f633ed5d +svn IN SSHFP 2 2 4a1ff7396ae874559cf196d54d5d7f6890dba6de73b46af049258b1024cdace2 +svn IN SSHFP 3 1 ea3eeac6cb50f9bbd2e2bb7d5fc39c13348d4a23 +svn IN SSHFP 3 2 56fb13ba24d88b3dcfd7de0c33d6f0b5e65c2b0c8b8bf44c5877746b74c49986 +svn IN SSHFP 4 1 537d0496fd72a5dfcbc196aac7b02ad7d02896bb +svn IN SSHFP 4 2 3a06b4ea07382dab0dfe54dbe926739587e0e8715e327e518279be1bd847b73c cert.svn IN CNAME svn.cacert.org. nocert.svn IN CNAME svn.cacert.org. @@ -229,12 +247,38 @@ www.test2 IN CNAME test2.cacert.org. translations IN A 213.154.225.240 translations IN SSHFP 1 1 1128972fb54f927477a781718e2f9c114e9ca383 +translations IN SSHFP 1 2 f223904069aeaa2e0eac5d9092ab7debae70f06ec3c25e94f49f1b15f633ed5d translations IN SSHFP 2 1 3a36e5df06304c481f01fc723fd88a086e82d986 +translations IN SSHFP 2 2 4a1ff7396ae874559cf196d54d5d7f6890dba6de73b46af049258b1024cdace2 +translations IN SSHFP 3 1 0f0cbd9c188d619d743859a249238f684d6cca5f +translations IN SSHFP 3 2 441d76eb651022a8c5810c6946cbdec47504e97ad669b073ec9d6e27791a7c4d +translations IN SSHFP 4 1 a4102e1fbf1be1acd53f2e7653dd8898e567c437 +translations IN SSHFP 4 2 6fe3334b51e68f9f650b00d13f504306029b71a76c5aff54873d72b24ed19dd5 l10n IN CNAME translations.cacert.org. tverify IN A 213.154.225.247 tverify IN AAAA 2001:7b8:3:9c::247 +web IN A 213.154.225.242 +web IN SSHFP 1 1 85f5338d90930200cbbfce1aab56988b4c8f0f22 +web IN SSHFP 1 2 d39cbd51588f322f7b4384274cf0166f25b10f54a6cd153ed7251ff30b5b516e +web IN SSHFP 2 1 906f0c17bb0e233b0f52ce33cfe64038d45ac4f2 +web IN SSHFP 2 2 dbf6221a8a403b4c9f537b676305fdae07ff45a1c18d88b1141031402af0250f +web IN SSHFP 3 1 7b62d8d1e093c28cda0f3d2444846128b41c10de +web IN SSHFP 3 2 0917da677c9e6caf1818c1151ec2a813623a2b2955a1a850f260d64ef041400b +web IN SSHFP 4 1 e835735157ee3f75663b9c18adbe12b49b28ca96 +web IN SSHFP 4 2 2079bd1a37f4bbbe770033be58360b16e1f03cadd17807b5d35c46fcd782c189 + +webstatic IN A 213.154.225.242 +webstatic IN SSHFP 1 1 30897a7a984d8350495946d54c6374e9331237ef +webstatic IN SSHFP 1 2 32bb10c5cf48532d077066e012230058ddf3cce731c561f228e310eb7a546e3f +webstatic IN SSHFP 2 1 868361a51ec60607bfd964d0f8f3e4ee5e803fc6 +webstatic IN SSHFP 2 2 a173bb85ec19f63ecb273bca130ef63501fe1b89fd55b62997195e6816cab547 +webstatic IN SSHFP 3 1 7fc847cec20b9d65296d4a0edafba22a14ee9dc4 +webstatic IN SSHFP 3 2 68879264e0ed5d0914797bf2292436fb32cca24683dcf5d927a53589c1bfb6d7 +webstatic IN SSHFP 4 1 A087EF97F4D014B4281A9E462DDC080354231873 +webstatic IN SSHFP 4 2 342DF8975A92B9FAC1763C63264EF9A0E9E686B416D5590B20BB0E84995EEFB0 + wiki IN A 213.154.225.235 wiki IN SSHFP 1 1 5c3e0d3265782405e0141c47bf0e16ec14b12e08 wiki IN SSHFP 2 1 04f7ab767579f004cc3ab2cc42a4ccaa24e51154 diff --git a/cacert.org.log b/cacert.org.log index 2e62a6f..912101d 100644 --- a/cacert.org.log +++ b/cacert.org.log @@ -1,16 +1,45 @@ RCS file: /var/opendnssec/unsigned/RCS/cacert.org,v Working file: /var/opendnssec/unsigned/cacert.org -head: 1.104 +head: 1.110 branch: locks: strict access list: symbolic names: keyword substitution: kv -total revisions: 104; selected revisions: 104 +total revisions: 110; selected revisions: 110 description: cacert.org - zone file for cacert.org ---------------------------- +revision 1.110 +date: 2018/02/25 09:19:36; author: root; state: Exp; lines: +58 -24 +Tons of changes per e-mail request from Jan Dittberner on 24.02.2018. +---------------------------- +revision 1.109 +date: 2018/02/18 14:30:49; author: root; state: Exp; lines: +8 -10 +Various changes for infrastructure hosts per e-mail request from Jan Dittberrer on 17.02.2018. +---------------------------- +revision 1.108 +date: 2018/02/16 08:04:12; author: root; state: Exp; lines: +14 -4 +Add SHA256, ED25519 and ECDSA SSHFP records for blog.cacert.org. +Add SHA256, ED25519 and ECDSA SSHFP records for bugs.cacert.org. +Remove records for coaudit. +(e-mail request from Jan Dittberner on 15.02.2018) +---------------------------- +revision 1.107 +date: 2018/02/15 15:57:21; author: root; state: Exp; lines: +2 -6 +Drop all records for arbitrations.cacert.org per e-mail request +from Jan Dittberner on 15.02.2018. +---------------------------- +revision 1.106 +date: 2018/02/15 10:07:23; author: root; state: Exp; lines: +4 -2 +Add SSHFP records for new ED25519 SSH host key on git.cacert.org +per e-mail request from Jan Dittberner on 14.02.2018. +---------------------------- +revision 1.105 +date: 2017/09/29 13:36:39; author: root; state: Exp; lines: +6 -2 +Add CAA records. +---------------------------- revision 1.104 date: 2016/10/12 07:18:06; author: root; state: Exp; lines: +4 -4 Set TTL for SOA to 1 hour, and SOA expire time to 7 days, per web recommendations.