Linux vps-61133.fhnet.fr 4.9.0-19-amd64 #1 SMP Debian 4.9.320-2 (2022-06-30) x86_64
Apache/2.4.25 (Debian)
Server IP : 93.113.207.21 & Your IP : 216.73.216.35
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
sbin /
Delete
Unzip
Name
Size
Permission
Date
Action
a2disconf
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2dismod
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2dissite
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2enconf
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2enmod
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2ensite
15.89
KB
-rwxr-xr-x
2019-06-16 11:49
a2query
9.64
KB
-rwxr-xr-x
2022-03-18 13:54
accessdb
10.23
KB
-rwxrwxrwx
2016-12-13 14:10
add-shell
860
B
-rwxrwxrwx
2017-04-02 19:10
addgnupghome
3.01
KB
-rwxrwxrwx
2019-02-07 21:57
addgroup
33.7
KB
-rwxrwxrwx
2016-06-27 00:55
adduser
33.7
KB
-rwxrwxrwx
2016-06-27 00:55
anacron
34.02
KB
-rwxr-xr-x
2017-05-29 18:36
apache2
651.16
KB
-rwxr-xr-x
2022-03-18 13:54
apache2ctl
7.05
KB
-rwxr-xr-x
2019-10-13 17:39
apachectl
7.05
KB
-rwxr-xr-x
2019-10-13 17:39
applygnupgdefaults
2.17
KB
-rwxrwxrwx
2019-02-07 21:57
arp
62.03
KB
-rwxrwxrwx
2016-12-26 06:58
arpaname
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
arpd
46.84
KB
-rwxrwxrwx
2017-11-24 10:22
aspell-autobuildhash
13.22
KB
-rwxrwxrwx
2016-10-10 11:58
backup-manager
6.94
KB
-rwxrwxrwx
2016-08-23 12:51
bacula-console
44.77
KB
-rwxr-xr-x
2020-08-26 20:03
bacula-fd
239.47
KB
-rwxr-xr-x
2020-08-26 20:03
bconsole
44.77
KB
-rwxr-xr-x
2020-08-26 20:03
biosdecode
18.82
KB
-rwxrwxrwx
2016-09-01 04:59
bsmtp
18.52
KB
-rwxr-xr-x
2020-08-26 20:03
btraceback
2.27
KB
-rwxr-xr-x
2020-08-26 20:03
check_forensic
952
B
-rwxr-xr-x
2011-04-26 17:10
chgpasswd
57.8
KB
-rwxr-xr-x
2021-03-17 10:27
chpasswd
49.9
KB
-rwxr-xr-x
2021-03-17 10:27
chroot
38.88
KB
-rwxrwxrwx
2017-02-22 13:23
clamd
202.1
KB
-rwxr-xr-x
2022-05-27 11:18
clamonacc
190.09
KB
-rwxr-xr-x
2022-05-27 11:18
convertquota
71.74
KB
-rwxrwxrwx
2018-02-24 07:55
cpgr
52
KB
-rwxr-xr-x
2021-03-17 10:27
cppw
52
KB
-rwxr-xr-x
2021-03-17 10:27
cron
47.48
KB
-rwxr-xr-x
2021-10-29 22:04
dbconfig-generate-include
12.37
KB
-rwxrwxrwx
2017-01-05 20:23
dbconfig-load-include
5.57
KB
-rwxrwxrwx
2017-01-05 20:23
ddns-confgen
17.99
KB
-rwxr-xr-x
2022-03-19 14:43
delgroup
15.43
KB
-rwxrwxrwx
2016-06-27 00:55
deluser
15.43
KB
-rwxrwxrwx
2016-06-27 00:55
dmidecode
102.49
KB
-rwxrwxrwx
2016-09-01 04:59
dnssec-checkds
10.66
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-coverage
28.07
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-dsfromkey
50
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-dsfromkey-pkcs11
50
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-importkey
50
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-importkey-pkcs11
50
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-keyfromlabel
54
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-keyfromlabel-pkcs11
54
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-keygen
62
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-keygen-pkcs11
62
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-revoke
46
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-revoke-pkcs11
46
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-settime
54
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-settime-pkcs11
54
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-signzone
102.03
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-signzone-pkcs11
102.03
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-verify
46.01
KB
-rwxr-xr-x
2022-03-19 14:43
dnssec-verify-pkcs11
46.01
KB
-rwxr-xr-x
2022-03-19 14:43
dovecot
86.09
KB
-rwxr-xr-x
2021-01-05 13:19
dpkg-preconfigure
3.52
KB
-rwxrwxrwx
2017-05-21 19:08
dpkg-reconfigure
4.23
KB
-rwxrwxrwx
2017-05-21 19:08
e2freefrag
10.07
KB
-rwxrwxrwx
2020-07-25 11:03
e4crypt
22.07
KB
-rwxrwxrwx
2020-07-25 11:03
e4defrag
25.99
KB
-rwxrwxrwx
2020-07-25 11:03
edquota
80.11
KB
-rwxrwxrwx
2018-02-24 07:55
fdformat
30.66
KB
-rwxrwxrwx
2018-03-07 19:29
filefrag
14.02
KB
-rwxrwxrwx
2020-07-25 11:03
genccode
10.59
KB
-rwxr-xr-x
2021-10-12 12:29
gencmn
10.64
KB
-rwxr-xr-x
2021-10-12 12:29
genl
50.79
KB
-rwxrwxrwx
2017-11-24 10:22
gennorm2
43.38
KB
-rwxr-xr-x
2021-10-12 12:29
genrandom
10
KB
-rwxr-xr-x
2022-03-19 14:43
gensprep
18.98
KB
-rwxr-xr-x
2021-10-12 12:29
groupadd
57.86
KB
-rwxr-xr-x
2021-03-17 10:27
groupdel
53.65
KB
-rwxr-xr-x
2021-03-17 10:27
groupmems
53.84
KB
-rwxr-xr-x
2021-03-17 10:27
groupmod
68.22
KB
-rwxr-xr-x
2021-03-17 10:27
grpck
53.77
KB
-rwxr-xr-x
2021-03-17 10:27
grpconv
49.65
KB
-rwxr-xr-x
2021-03-17 10:27
grpunconv
49.65
KB
-rwxr-xr-x
2021-03-17 10:27
grub-bios-setup
790.19
KB
-rwxrwxrwx
2019-06-12 13:20
grub-install
996.58
KB
-rwxrwxrwx
2019-06-12 13:20
grub-macbless
777.88
KB
-rwxrwxrwx
2019-06-12 13:20
grub-mkconfig
7.82
KB
-rwxrwxrwx
2019-06-12 13:20
grub-mkdevicemap
204.47
KB
-rwxrwxrwx
2019-06-12 13:20
grub-probe
790.19
KB
-rwxrwxrwx
2019-06-12 13:20
grub-reboot
4.01
KB
-rwxrwxrwx
2019-06-12 13:20
grub-set-default
3.48
KB
-rwxrwxrwx
2019-06-12 13:20
httxt2dbm
9.99
KB
-rwxr-xr-x
2022-03-18 13:54
iconvconfig
22.66
KB
-rwxrwxrwx
2019-02-06 22:17
icupkg
19.18
KB
-rwxr-xr-x
2021-10-12 12:29
inetd
34.38
KB
-rwxrwxrwx
2017-01-02 11:49
install-sgmlcatalog
4.44
KB
-rwxrwxrwx
2016-11-07 08:06
invoke-rc.d
17.69
KB
-rwxrwxrwx
2017-05-02 12:20
ip6tables-apply
6.85
KB
-rwxrwxrwx
2017-04-12 11:41
iptables-apply
6.85
KB
-rwxrwxrwx
2017-04-12 11:41
irqbalance
55.38
KB
-rwxrwxrwx
2017-03-10 19:56
isc-hmac-fixup
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
ispell-autobuildhash
15.39
KB
-rwxrwxrwx
2016-10-10 11:58
ldattach
30.71
KB
-rwxrwxrwx
2018-03-07 19:29
locale-gen
1.5
KB
-rwxrwxrwx
2017-07-31 16:32
logrotate
75.27
KB
-rwxrwxrwx
2017-01-07 19:54
logwatch
58
KB
-rwxr-xr-x
2017-01-21 17:44
make-ssl-cert
3.78
KB
-rwxrwxrwx
2017-04-28 21:58
mkinitramfs
10.01
KB
-rwxrwxrwx
2017-04-26 03:00
mklost+found
9.99
KB
-rwxrwxrwx
2020-07-25 11:03
mysqld
17.05
MB
-rwxr-xr-x
2021-03-22 19:49
named
622.24
KB
-rwxr-xr-x
2022-03-19 14:43
named-checkconf
34.19
KB
-rwxr-xr-x
2022-03-19 14:43
named-checkzone
30.19
KB
-rwxr-xr-x
2022-03-19 14:43
named-compilezone
30.19
KB
-rwxr-xr-x
2022-03-19 14:43
named-journalprint
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
named-pkcs11
622.24
KB
-rwxr-xr-x
2022-03-19 14:43
named-rrchecker
13.99
KB
-rwxr-xr-x
2022-03-19 14:43
netfilter-persistent
1.05
KB
-rwxr-xr-x
2020-05-02 21:33
newusers
78.43
KB
-rwxr-xr-x
2021-03-17 10:27
nfnl_osf
13.99
KB
-rwxrwxrwx
2017-04-12 11:41
nginx
1.01
MB
-rwxr-xr-x
2021-06-07 21:02
nologin
5.99
KB
-rwxr-xr-x
2021-03-17 10:27
nsec3hash
10
KB
-rwxr-xr-x
2022-03-19 14:43
ntp-keygen
73.77
KB
-rwxrwxrwx
2018-02-15 12:45
ntp-wait
3.13
KB
-rwxrwxrwx
2018-02-15 12:45
ntpd
713.22
KB
-rwxrwxrwx
2018-02-15 12:45
ntpdate
75.17
KB
-rwxrwxrwx
2018-02-15 12:45
ntpdate-debian
534
B
-rwxrwxrwx
2018-02-15 12:45
ntptime
18.12
KB
-rwxrwxrwx
2018-02-15 12:45
ownership
10.13
KB
-rwxrwxrwx
2016-09-01 04:59
pam-auth-update
19.03
KB
-rwxrwxrwx
2017-05-27 17:44
pam_getenv
2.82
KB
-rwxrwxrwx
2017-05-27 17:44
pam_timestamp_check
10.37
KB
-rwxrwxrwx
2017-05-27 17:44
paperconfig
4.07
KB
-rwxrwxrwx
2016-11-11 12:28
passenger-memory-stats
5.65
KB
-rwxrwxrwx
2019-03-17 19:40
passenger-status
10.68
KB
-rwxrwxrwx
2019-03-17 19:40
phpdismod
7.11
KB
-rwxrwxrwx
2017-01-01 20:43
phpenmod
7.11
KB
-rwxrwxrwx
2017-01-01 20:43
phpquery
6.26
KB
-rwxrwxrwx
2017-01-01 20:43
pkcs11-destroy
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
pkcs11-keygen
15.58
KB
-rwxr-xr-x
2022-03-19 14:43
pkcs11-list
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
pkcs11-tokens
9.99
KB
-rwxr-xr-x
2022-03-19 14:43
pma-configure
299
B
-rwxr-xr-x
2020-10-23 11:41
pma-secure
157
B
-rwxr-xr-x
2020-10-23 11:41
postalias
17.99
KB
-rwxr-xr-x
2020-02-16 20:59
postcat
14.06
KB
-rwxr-xr-x
2020-02-16 20:59
postconf
175.28
KB
-rwxr-xr-x
2020-02-16 20:59
postdrop
14.12
KB
-rwxr-sr-x
2020-02-16 20:59
postfix
14.07
KB
-rwxr-xr-x
2020-02-16 20:59
postfix-add-filter
4.9
KB
-rwxrwxrwx
2020-02-16 20:59
postfix-add-policy
3.83
KB
-rwxrwxrwx
2020-02-16 20:59
postkick
9.99
KB
-rwxr-xr-x
2020-02-16 20:59
postlock
9.99
KB
-rwxr-xr-x
2020-02-16 20:59
postlog
10.15
KB
-rwxr-xr-x
2020-02-16 20:59
postmap
17.99
KB
-rwxr-xr-x
2020-02-16 20:59
postmulti
26.38
KB
-rwxr-xr-x
2020-02-16 20:59
postqueue
22.07
KB
-rwxr-sr-x
2020-02-16 20:59
postsuper
22.32
KB
-rwxr-xr-x
2020-02-16 20:59
posttls-finger
34.09
KB
-rwxrwxrwx
2020-02-16 20:59
pure-authd
18.41
KB
-rwxrwxrwx
2016-12-08 13:28
pure-ftpd
161.4
KB
-rwxrwxrwx
2016-12-08 13:28
pure-ftpd-control
1.68
KB
-rwxrwxrwx
2016-12-08 13:28
pure-ftpd-virtualchroot
165.4
KB
-rwxrwxrwx
2016-12-08 13:28
pure-ftpd-wrapper
12.16
KB
-rwxrwxrwx
2016-12-08 13:28
pure-ftpwho
22.02
KB
-rwxrwxrwx
2016-12-08 13:28
pure-mrtginfo
9.99
KB
-rwxrwxrwx
2016-12-08 13:28
pure-quotacheck
14.01
KB
-rwxrwxrwx
2016-12-08 13:28
pure-uploadscript
14.26
KB
-rwxrwxrwx
2016-12-08 13:28
pwck
49.84
KB
-rwxr-xr-x
2021-03-17 10:27
pwconv
45.74
KB
-rwxr-xr-x
2021-03-17 10:27
pwunconv
41.72
KB
-rwxr-xr-x
2021-03-17 10:27
qmqp-sink
13.99
KB
-rwxrwxrwx
2020-02-16 20:59
qmqp-source
18.01
KB
-rwxrwxrwx
2020-02-16 20:59
qshape
12.55
KB
-rwxrwxrwx
2020-02-16 20:59
quot
67.48
KB
-rwxrwxrwx
2018-02-24 07:55
quota_nld
75.8
KB
-rwxrwxrwx
2018-02-24 07:55
quotastats
14.38
KB
-rwxrwxrwx
2018-02-24 07:55
quotatool
26.45
KB
-rwxrwxrwx
2014-12-21 21:54
readprofile
18.59
KB
-rwxrwxrwx
2018-03-07 19:29
remove-default-ispell
2.86
KB
-rwxrwxrwx
2016-10-10 11:58
remove-default-wordlist
2.86
KB
-rwxrwxrwx
2016-10-10 11:58
remove-shell
904
B
-rwxrwxrwx
2017-04-02 19:10
repquota
72.05
KB
-rwxrwxrwx
2018-02-24 07:55
rmail
13.99
KB
-rwxrwxrwx
2020-02-16 20:59
rmt
55.03
KB
-rwxr-xr-x
2021-11-27 22:50
rmt-tar
55.03
KB
-rwxr-xr-x
2021-11-27 22:50
rndc
29.99
KB
-rwxr-xr-x
2022-03-19 14:43
rndc-confgen
17.99
KB
-rwxr-xr-x
2022-03-19 14:43
rpc.rquotad
75.96
KB
-rwxrwxrwx
2018-02-24 07:55
rsyslogd
636.3
KB
-rwxr-xr-x
2022-05-20 21:25
rtcwake
42.81
KB
-rwxrwxrwx
2018-03-07 19:29
safe_finger
10.08
KB
-rwxrwxrwx
2016-12-26 00:08
select-default-ispell
3.23
KB
-rwxrwxrwx
2016-10-10 11:58
select-default-wordlist
3.21
KB
-rwxrwxrwx
2016-10-10 11:58
sendmail
26.15
KB
-rwxr-xr-x
2020-02-16 20:59
service
9.83
KB
-rwxrwxrwx
2017-05-02 12:20
setquota
84.11
KB
-rwxrwxrwx
2018-02-24 07:55
smartctl
663.63
KB
-rwxrwxrwx
2016-07-30 19:10
smartd
591.07
KB
-rwxrwxrwx
2016-07-30 19:10
smtp-sink
30.93
KB
-rwxrwxrwx
2020-02-16 20:59
smtp-source
22.02
KB
-rwxrwxrwx
2020-02-16 20:59
snmpd
30.01
KB
-rwxr-xr-x
2020-08-04 17:15
split-logfile
2.36
KB
-rwxr-xr-x
2022-03-18 13:54
sshd
772.48
KB
-rwxrwxrwx
2019-07-15 15:32
tarcat
936
B
-rwxr-xr-x
2021-11-27 22:50
tcpd
10
KB
-rwxrwxrwx
2016-12-26 00:08
tcpdchk
22.13
KB
-rwxrwxrwx
2016-12-26 00:08
tcpdmatch
18.04
KB
-rwxrwxrwx
2016-12-26 00:08
tcpdump
1007.6
KB
-rwxr-xr-x
2020-11-10 15:22
tcptraceroute
1.56
KB
-rwxrwxrwx
2016-08-29 17:45
tcptraceroute.db
1.56
KB
-rwxrwxrwx
2016-08-29 17:45
traceroute
67.16
KB
-rwxrwxrwx
2016-08-29 17:45
try-from
10
KB
-rwxrwxrwx
2016-12-26 00:08
tsig-keygen
17.99
KB
-rwxr-xr-x
2022-03-19 14:43
tunelp
26.61
KB
-rwxrwxrwx
2018-03-07 19:29
tzconfig
106
B
-rwxr-xr-x
2019-10-11 09:23
ufw
4.4
KB
-rwx------
2017-01-10 22:16
unhide
38.26
KB
-rwxrwxrwx
2019-12-17 18:08
unhide-linux
38.26
KB
-rwxrwxrwx
2019-12-17 18:08
unhide-posix
10
KB
-rwxrwxrwx
2019-12-17 18:08
unhide-tcp
18.85
KB
-rwxrwxrwx
2019-12-17 18:08
unhide.rb
13.97
KB
-rwxrwxrwx
2015-11-09 01:23
unhide_rb
14.09
KB
-rwxrwxrwx
2019-12-17 18:08
update-ca-certificates
4.85
KB
-rwxr-xr-x
2021-03-13 18:38
update-catalog
9.15
KB
-rwxrwxrwx
2016-11-07 08:06
update-default-aspell
1
KB
-rwxrwxrwx
2016-10-10 11:58
update-default-ispell
9.68
KB
-rwxrwxrwx
2016-10-10 11:58
update-default-wordlist
7.5
KB
-rwxrwxrwx
2016-10-10 11:58
update-dictcommon-aspell
1
KB
-rwxrwxrwx
2016-10-10 11:58
update-dictcommon-hunspell
782
B
-rwxrwxrwx
2016-10-10 11:58
update-grub
64
B
-rwxrwxrwx
2019-06-12 13:20
update-grub2
64
B
-rwxrwxrwx
2019-06-12 13:20
update-gsfontmap
450
B
-rwxr-xr-x
2022-05-01 17:15
update-inetd
6.05
KB
-rwxrwxrwx
2017-01-15 12:37
update-initramfs
8.02
KB
-rwxrwxrwx
2017-03-06 23:42
update-locale
2.99
KB
-rwxrwxrwx
2016-03-21 00:45
update-mime
8.84
KB
-rwxrwxrwx
2016-05-01 13:20
update-passwd
30.41
KB
-rwxrwxrwx
2017-01-16 16:52
update-rc.d
15.69
KB
-rwxrwxrwx
2017-05-02 12:20
update-xmlcatalog
16.88
KB
-rwxrwxrwx
2016-11-07 15:53
upgrade-from-grub-legacy
1.49
KB
-rwxrwxrwx
2019-06-12 13:20
useradd
119.29
KB
-rwxr-xr-x
2021-03-17 10:27
userdel
82.49
KB
-rwxr-xr-x
2021-03-17 10:27
usermod
119.1
KB
-rwxr-xr-x
2021-03-17 10:27
validlocale
1.73
KB
-rwxrwxrwx
2016-03-21 00:45
vigr
60.22
KB
-rwxr-xr-x
2021-03-17 10:27
vipw
60.22
KB
-rwxr-xr-x
2021-03-17 10:27
visudo
200.34
KB
-rwxr-xr-x
2021-01-23 10:10
vpddecode
14.27
KB
-rwxrwxrwx
2016-09-01 04:59
warnquota
84.11
KB
-rwxrwxrwx
2018-02-24 07:55
xqmstats
14.36
KB
-rwxrwxrwx
2018-02-24 07:55
zic
42.54
KB
-rwxrwxrwx
2019-02-06 22:17
Save
Rename
#!/usr/bin/python3 ############################################################################ # Copyright (C) 2013-2015 Internet Systems Consortium, Inc. ("ISC") # # Permission to use, copy, modify, and/or distribute this software for any # purpose with or without fee is hereby granted, provided that the above # copyright notice and this permission notice appear in all copies. # # THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH # REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY # AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT, # INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM # LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE # OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR # PERFORMANCE OF THIS SOFTWARE. ############################################################################ import argparse import os import glob import sys import re import time import calendar from collections import defaultdict import pprint prog='dnssec-coverage' # These routines permit platform-independent location of BIND 9 tools if os.name == 'nt': import win32con import win32api def prefix(bindir = ''): if os.name != 'nt': return os.path.join('/usr', bindir) bind_subkey = "Software\\ISC\\BIND" hKey = None keyFound = True try: hKey = win32api.RegOpenKeyEx(win32con.HKEY_LOCAL_MACHINE, bind_subkey) except: keyFound = False if keyFound: try: (namedBase, _) = win32api.RegQueryValueEx(hKey, "InstallDir") except: keyFound = False win32api.RegCloseKey(hKey) if keyFound: return os.path.join(namedBase, bindir) return os.path.join(win32api.GetSystemDirectory(), bindir) ######################################################################## # Class Event ######################################################################## class Event: """ A discrete key metadata event, e.g., Publish, Activate, Inactive, Delete. Stores the date of the event, and identifying information about the key to which the event will occur.""" def __init__(self, _what, _key): now = time.time() self.what = _what self.when = _key.metadata[_what] self.key = _key self.keyid = _key.keyid self.sep = _key.sep self.zone = _key.zone self.alg = _key.alg def __repr__(self): return repr((self.when, self.what, self.keyid, self.sep, self.zone, self.alg)) def showtime(self): return time.strftime("%a %b %d %H:%M:%S UTC %Y", self.when) def showkey(self): return self.key.showkey() def showkeytype(self): return self.key.showkeytype() ######################################################################## # Class Key ######################################################################## class Key: """An individual DNSSEC key. Identified by path, zone, algorithm, keyid. Contains a dictionary of metadata events.""" def __init__(self, keyname): directory = os.path.dirname(keyname) key = os.path.basename(keyname) (zone, alg, keyid) = key.split('+') keyid = keyid.split('.')[0] key = [zone, alg, keyid] key_file = directory + os.sep + '+'.join(key) + ".key" private_file = directory + os.sep + '+'.join(key) + ".private" self.zone = zone[1:-1] self.alg = int(alg) self.keyid = int(keyid) kfp = open(key_file, "r") for line in kfp: if line[0] == ';': continue tokens = line.split() if not tokens: continue if tokens[1].lower() in ('in', 'ch', 'hs'): septoken = 3 self.ttl = args.keyttl if not self.ttl: vspace() print("WARNING: Unable to determine TTL for DNSKEY %s." % self.showkey()) print("\t Using 1 day (86400 seconds); re-run with the -d " "option for more\n\t accurate results.") self.ttl = 86400 else: septoken = 4 self.ttl = int(tokens[1]) if not args.keyttl else args.keyttl if (int(tokens[septoken]) & 0x1) == 1: self.sep = True else: self.sep = False kfp.close() pfp = open(private_file, "rU") propDict = dict() for propLine in pfp: propDef = propLine.strip() if len(propDef) == 0: continue if propDef[0] in ('!', '#'): continue punctuation = [propDef.find(c) for c in ':= '] + [len(propDef)] found = min([ pos for pos in punctuation if pos != -1 ]) name = propDef[:found].rstrip() value = propDef[found:].lstrip(":= ").rstrip() propDict[name] = value if("Publish" in propDict): propDict["Publish"] = time.strptime(propDict["Publish"], "%Y%m%d%H%M%S") if("Activate" in propDict): propDict["Activate"] = time.strptime(propDict["Activate"], "%Y%m%d%H%M%S") if("Inactive" in propDict): propDict["Inactive"] = time.strptime(propDict["Inactive"], "%Y%m%d%H%M%S") if("Delete" in propDict): propDict["Delete"] = time.strptime(propDict["Delete"], "%Y%m%d%H%M%S") if("Revoke" in propDict): propDict["Revoke"] = time.strptime(propDict["Revoke"], "%Y%m%d%H%M%S") pfp.close() self.metadata = propDict def showkey(self): return "%s/%03d/%05d" % (self.zone, self.alg, self.keyid); def showkeytype(self): return ("KSK" if self.sep else "ZSK") # ensure that the gap between Publish and Activate is big enough def check_prepub(self): now = time.time() if (not "Activate" in self.metadata): debug_print("No Activate information in key: %s" % self.showkey()) return False a = calendar.timegm(self.metadata["Activate"]) if (not "Publish" in self.metadata): debug_print("No Publish information in key: %s" % self.showkey()) if a > now: vspace() print("WARNING: Key %s (%s) is scheduled for activation but \n" "\t not for publication." % (self.showkey(), self.showkeytype())) return False p = calendar.timegm(self.metadata["Publish"]) now = time.time() if p < now and a < now: return True if p == a: vspace() print ("WARNING: %s (%s) is scheduled to be published and\n" "\t activated at the same time. This could result in a\n" "\t coverage gap if the zone was previously signed." % (self.showkey(), self.showkeytype())) print("\t Activation should be at least %s after publication." % duration(self.ttl)) return True if a < p: vspace() print("WARNING: Key %s (%s) is active before it is published" % (self.showkey(), self.showkeytype())) return False if (a - p < self.ttl): vspace() print("WARNING: Key %s (%s) is activated too soon after\n" "\t publication; this could result in coverage gaps due to\n" "\t resolver caches containing old data." % (self.showkey(), self.showkeytype())) print("\t Activation should be at least %s after publication." % duration(self.ttl)) return False return True # ensure that the gap between Inactive and Delete is big enough def check_postpub(self, timespan = None): if not timespan: timespan = self.ttl now = time.time() if (not "Delete" in self.metadata): debug_print("No Delete information in key: %s" % self.showkey()) return False d = calendar.timegm(self.metadata["Delete"]) if (not "Inactive" in self.metadata): debug_print("No Inactive information in key: %s" % self.showkey()) if d > now: vspace() print("WARNING: Key %s (%s) is scheduled for deletion but\n" "\t not for inactivation." % (self.showkey(), self.showkeytype())) return False i = calendar.timegm(self.metadata["Inactive"]) if d < now and i < now: return True if (d < i): vspace() print("WARNING: Key %s (%s) is scheduled for deletion before\n" "\t inactivation." % (self.showkey(), self.showkeytype())) return False if (d - i < timespan): vspace() print("WARNING: Key %s (%s) scheduled for deletion too soon after\n" "\t deactivation; this may result in coverage gaps due to\n" "\t resolver caches containing old data." % (self.showkey(), self.showkeytype())) print("\t Deletion should be at least %s after inactivation." % duration(timespan)) return False return True ######################################################################## # class Zone ######################################################################## class Zone: """Stores data about a specific zone""" def __init__(self, _name, _keyttl = None, _maxttl = None): self.name = _name self.keyttl = _keyttl self.maxttl = _maxttl def load(self, filename): if not args.compilezone: sys.stderr.write(prog + ': FATAL: "named-compilezone" not found\n') exit(1) if not self.name: return maxttl = keyttl = None fp = os.popen("%s -o - %s %s 2> /dev/null" % (args.compilezone, self.name, filename)) for line in fp: fields = line.split() if not maxttl or int(fields[1]) > maxttl: maxttl = int(fields[1]) if fields[3] == "DNSKEY": keyttl = int(fields[1]) fp.close() self.keyttl = keyttl self.maxttl = maxttl ############################################################################ # debug_print: ############################################################################ def debug_print(debugVar): """pretty print a variable iff debug mode is enabled""" if not args.debug_mode: return if type(debugVar) == str: print("DEBUG: " + debugVar) else: print("DEBUG: " + pprint.pformat(debugVar)) return ############################################################################ # vspace: ############################################################################ _firstline = True def vspace(): """adds vertical space between two sections of output text if and only if this is *not* the first section being printed""" global _firstline if _firstline: _firstline = False else: print('') ############################################################################ # vreset: ############################################################################ def vreset(): """reset vertical spacing""" global _firstline _firstline = True ############################################################################ # getunit ############################################################################ def getunit(secs, size): """given a number of seconds, and a number of seconds in a larger unit of time, calculate how many of the larger unit there are and return both that and a remainder value""" bigunit = secs // size if bigunit: secs %= size return (bigunit, secs) ############################################################################ # addtime ############################################################################ def addtime(output, unit, t): """add a formatted unit of time to an accumulating string""" if t: output += ("%s%d %s%s" % ((", " if output else ""), t, unit, ("s" if t > 1 else ""))) return output ############################################################################ # duration: ############################################################################ def duration(secs): """given a length of time in seconds, print a formatted human duration in larger units of time """ # define units: minute = 60 hour = minute * 60 day = hour * 24 month = day * 30 year = day * 365 # calculate time in units: (years, secs) = getunit(secs, year) (months, secs) = getunit(secs, month) (days, secs) = getunit(secs, day) (hours, secs) = getunit(secs, hour) (minutes, secs) = getunit(secs, minute) output = '' output = addtime(output, "year", years) output = addtime(output, "month", months) output = addtime(output, "day", days) output = addtime(output, "hour", hours) output = addtime(output, "minute", minutes) output = addtime(output, "second", secs) return output ############################################################################ # parse_time ############################################################################ def parse_time(s): """convert a formatted time (e.g., 1y, 6mo, 15mi, etc) into seconds""" s = s.strip() # if s is an integer, we're done already try: n = int(s) return n except: pass # try to parse as a number with a suffix indicating unit of time r = re.compile('([0-9][0-9]*)\s*([A-Za-z]*)') m = r.match(s) if not m: raise Exception("Cannot parse %s" % s) (n, unit) = m.groups() n = int(n) unit = unit.lower() if unit[0] == 'y': return n * 31536000 elif unit[0] == 'm' and unit[1] == 'o': return n * 2592000 elif unit[0] == 'w': return n * 604800 elif unit[0] == 'd': return n * 86400 elif unit[0] == 'h': return n * 3600 elif unit[0] == 'm' and unit[1] == 'i': return n * 60 elif unit[0] == 's': return n else: raise Exception("Invalid suffix %s" % unit) ############################################################################ # algname: ############################################################################ def algname(alg): """return the mnemonic for a DNSSEC algorithm""" names = (None, 'RSAMD5', 'DH', 'DSA', 'ECC', 'RSASHA1', 'NSEC3DSA', 'NSEC3RSASHA1', 'RSASHA256', None, 'RSASHA512', None, 'ECCGOST', 'ECDSAP256SHA256', 'ECDSAP384SHA384') name = None if alg in range(len(names)): name = names[alg] return (name if name else str(alg)) ############################################################################ # list_events: ############################################################################ def list_events(eventgroup): """print a list of the events in an eventgroup""" if not eventgroup: return print (" " + eventgroup[0].showtime() + ":") for event in eventgroup: print (" %s: %s (%s)" % (event.what, event.showkey(), event.showkeytype())) ############################################################################ # process_events: ############################################################################ def process_events(eventgroup, active, published): """go through the events in an event group in time-order, add to active list upon Activate event, add to published list upon Publish event, remove from active list upon Inactive event, and remove from published upon Delete event. Emit warnings when inconsistant states are reached""" for event in eventgroup: if event.what == "Activate": active.add(event.keyid) elif event.what == "Publish": published.add(event.keyid) elif event.what == "Inactive": if event.keyid not in active: vspace() print ("\tWARNING: %s (%s) scheduled to become inactive " "before it is active" % (event.showkey(), event.showkeytype())) else: active.remove(event.keyid) elif event.what == "Delete": if event.keyid in published: published.remove(event.keyid) else: vspace() print ("WARNING: key %s (%s) is scheduled for deletion before " "it is published, at %s" % (event.showkey(), event.showkeytype())) elif event.what == "Revoke": # We don't need to worry about the logic of this one; # just stop counting this key as either active or published if event.keyid in published: published.remove(event.keyid) if event.keyid in active: active.remove(event.keyid) return (active, published) ############################################################################ # check_events: ############################################################################ def check_events(eventsList, ksk): """create lists of events happening at the same time, check for inconsistancies""" active = set() published = set() eventgroups = list() eventgroup = list() keytype = ("KSK" if ksk else "ZSK") # collect up all events that have the same time eventsfound = False for event in eventsList: # if checking ZSKs, skip KSKs, and vice versa if (ksk and not event.sep) or (event.sep and not ksk): continue # we found an appropriate (ZSK or KSK event) eventsfound = True # add event to current eventgroup if (not eventgroup or eventgroup[0].when == event.when): eventgroup.append(event) # if we're at the end of the list, we're done. if # we've found an event with a later time, start a new # eventgroup if (eventgroup[0].when != event.when): eventgroups.append(eventgroup) eventgroup = list() eventgroup.append(event) if eventgroup: eventgroups.append(eventgroup) for eventgroup in eventgroups: if (args.checklimit and calendar.timegm(eventgroup[0].when) > args.checklimit): print("Ignoring events after %s" % time.strftime("%a %b %d %H:%M:%S UTC %Y", time.gmtime(args.checklimit))) return True (active, published) = \ process_events(eventgroup, active, published) list_events(eventgroup) # and then check for inconsistencies: if len(active) == 0: print ("ERROR: No %s's are active after this event" % keytype) return False elif len(published) == 0: sys.stdout.write("ERROR: ") print ("ERROR: No %s's are published after this event" % keytype) return False elif len(published.intersection(active)) == 0: sys.stdout.write("ERROR: ") print (("ERROR: No %s's are both active and published " + "after this event") % keytype) return False if not eventsfound: print ("ERROR: No %s events found in '%s'" % (keytype, args.path)) return False return True ############################################################################ # check_zones: # ############################################################################ def check_zones(eventsList): """scan events per zone, algorithm, and key type, in order of occurrance, noting inconsistent states when found""" global foundprob foundprob = False zonesfound = False for zone in eventsList: if args.zone and zone != args.zone: continue zonesfound = True for alg in eventsList[zone]: if not args.no_ksk: vspace() print("Checking scheduled KSK events for zone %s, algorithm %s..." % (zone, algname(alg))) if not check_events(eventsList[zone][alg], True): foundprob = True else: print ("No errors found") if not args.no_zsk: vspace() print("Checking scheduled ZSK events for zone %s, algorithm %s..." % (zone, algname(alg))) if not check_events(eventsList[zone][alg], False): foundprob = True else: print ("No errors found") if not zonesfound: print("ERROR: No key events found for %s in '%s'" % (args.zone, args.path)) exit(1) ############################################################################ # fill_eventsList: ############################################################################ def fill_eventsList(eventsList): """populate the list of events""" for zone, algorithms in keyDict.items(): for alg, keys in algorithms.items(): for keyid, keydata in keys.items(): if("Publish" in keydata.metadata): eventsList[zone][alg].append(Event("Publish", keydata)) if("Activate" in keydata.metadata): eventsList[zone][alg].append(Event("Activate", keydata)) if("Inactive" in keydata.metadata): eventsList[zone][alg].append(Event("Inactive", keydata)) if("Delete" in keydata.metadata): eventsList[zone][alg].append(Event("Delete", keydata)) eventsList[zone][alg] = sorted(eventsList[zone][alg], key=lambda event: event.when) foundprob = False if not keyDict: print("ERROR: No key events found in '%s'" % args.path) exit(1) ############################################################################ # set_path: ############################################################################ def set_path(command, default=None): """find the location of a specified command. if a default is supplied and it works, we use it; otherwise we search PATH for a match. If not found, error and exit""" fpath = default if not fpath or not os.path.isfile(fpath) or not os.access(fpath, os.X_OK): path = os.environ["PATH"] if not path: path = os.path.defpath for directory in path.split(os.pathsep): fpath = directory + os.sep + command if os.path.isfile(fpath) or os.access(fpath, os.X_OK): break fpath = None return fpath ############################################################################ # parse_args: ############################################################################ def parse_args(): """Read command line arguments, set global 'args' structure""" global args compilezone = set_path('named-compilezone', os.path.join(prefix('bin'), 'named-compilezone')) parser = argparse.ArgumentParser(description=prog + ': checks future ' + 'DNSKEY coverage for a zone') parser.add_argument('zone', type=str, help='zone to check') parser.add_argument('-K', dest='path', default='.', type=str, help='a directory containing keys to process', metavar='dir') parser.add_argument('-f', dest='filename', type=str, help='zone master file', metavar='file') parser.add_argument('-m', dest='maxttl', type=str, help='the longest TTL in the zone(s)', metavar='time') parser.add_argument('-d', dest='keyttl', type=str, help='the DNSKEY TTL', metavar='time') parser.add_argument('-r', dest='resign', default='1944000', type=str, help='the RRSIG refresh interval ' 'in seconds [default: 22.5 days]', metavar='time') parser.add_argument('-c', dest='compilezone', default=compilezone, type=str, help='path to \'named-compilezone\'', metavar='path') parser.add_argument('-l', dest='checklimit', type=str, default='0', help='Length of time to check for ' 'DNSSEC coverage [default: 0 (unlimited)]', metavar='time') parser.add_argument('-z', dest='no_ksk', action='store_true', default=False, help='Only check zone-signing keys (ZSKs)') parser.add_argument('-k', dest='no_zsk', action='store_true', default=False, help='Only check key-signing keys (KSKs)') parser.add_argument('-D', '--debug', dest='debug_mode', action='store_true', default=False, help='Turn on debugging output') parser.add_argument('-v', '--version', action='version', version='9.9.1') args = parser.parse_args() if args.no_zsk and args.no_ksk: print("ERROR: -z and -k cannot be used together."); exit(1) # convert from time arguments to seconds try: if args.maxttl: m = parse_time(args.maxttl) args.maxttl = m except: pass try: if args.keyttl: k = parse_time(args.keyttl) args.keyttl = k except: pass try: if args.resign: r = parse_time(args.resign) args.resign = r except: pass try: if args.checklimit: lim = args.checklimit r = parse_time(args.checklimit) if r == 0: args.checklimit = None else: args.checklimit = time.time() + r except: pass # if we've got the values we need from the command line, stop now if args.maxttl and args.keyttl: return # load keyttl and maxttl data from zonefile if args.zone and args.filename: try: zone = Zone(args.zone) zone.load(args.filename) if not args.maxttl: args.maxttl = zone.maxttl if not args.keyttl: args.keyttl = zone.maxttl except Exception as e: print("Unable to load zone data from %s: " % args.filename, e) if not args.maxttl: vspace() print ("WARNING: Maximum TTL value was not specified. Using 1 week\n" "\t (604800 seconds); re-run with the -m option to get more\n" "\t accurate results.") args.maxttl = 604800 ############################################################################ # Main ############################################################################ def main(): global keyDict parse_args() path=args.path print ("PHASE 1--Loading keys to check for internal timing problems") keyDict = defaultdict(lambda : defaultdict(dict)) files = glob.glob(os.path.join(path, '*.private')) for infile in files: key = Key(infile) if args.zone and key.zone != args.zone: continue keyDict[key.zone][key.alg][key.keyid] = key key.check_prepub() if key.sep: key.check_postpub() else: key.check_postpub(args.maxttl + args.resign) vspace() print ("PHASE 2--Scanning future key events for coverage failures") vreset() eventsList = defaultdict(lambda : defaultdict(list)) fill_eventsList(eventsList) check_zones(eventsList) if foundprob: exit(1) else: exit(0) if __name__ == "__main__": main()