Skip to content

Add DNS delegation integrity fixtures#2076

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/dns-delegation-fixtures-1627
Open

Add DNS delegation integrity fixtures#2076
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/dns-delegation-fixtures-1627

Conversation

@DENGXUELIN

Copy link
Copy Markdown

/claim #1627

Summary

  • Adds an authoritative delegation integrity review step to dns-security with gates for parent/child NS drift, in-bailiwick glue, lame nameservers, SOA drift, delegated NS control, IPv4/IPv6 parity, AXFR/IXFR restriction, and exception governance.
  • Adds an Authoritative Delegation Integrity output table so delegation status is reported separately from DNSSEC status.
  • Adds vulnerable and benign calibration fixtures for stale glue/lame delegation versus validated dual-stack delegation evidence.

Why this improves the existing skill

The current skill can treat DNSSEC-focused evidence as sufficient even when the authoritative delegation is unsafe. This patch makes reviewers verify delegation health directly and includes fixtures that distinguish a signed but unsafe zone from a signed zone with complete delegation evidence.

Validation

  • git diff --cached --check
  • git diff --check origin/main...HEAD
  • git merge-tree --write-tree origin/main HEAD
  • Markdown fence balance check
  • Added-line ASCII check
  • Marker check for DNS-DELEG-01 through DNS-DELEG-08, Authoritative Delegation Integrity, and version: "1.0.1"
  • Added-line sensitive/public-contact pattern scan

Bounty request: Improver Moderate ($100) if accepted/merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant