Skip to main content

RIPE NCC CDS scanner

This utility implements support for automated DNSSEC delegation trust maintenance for the reverse DNS zones delegated by RIPE database. It implements scanning for CDS records according to RFC 7344 and RFC 8078.

Only trust anchor update and remove is supported. Bootstrapping from insecure to secure is not supported.

It reads a dump of DOMAIN objects from the RIPE database. Only domain objects containing ds-rdata: attributes are processed.

CDS records are scanned using default resolver of the host, which MUST be DNSSEC-aware and SHOULD perform DNSSEC-validation. The utility outputs RPSL-like file listing objects that should be modified in the RIPE database. Since the scanner works with dummyfied objects, output cannot be directly pushed into the Database. Instead, it has to be used as a diff-file for a GET-modify-PUT operation on the database.

DNSSEC algorithm support

The utility does all the special validations mandated by RFC 7344. These are done using dnspython. Since these validations provide similar level of security to standard DNSSEC validation process, validation in the DNS resolver is not required.

Therefore, the list of supported algorithms is same as the list of supported DNSSEC algorithms of dnspython.

Installation and usage

This package can be installed using pip, preferably into its own virtualenv.

$ python3 -m venv rcdss-venv
$ source rcdss-venv/bin/activate
(rcdss-venv)$ pip install rcdss
(rcdss-venv)$ rcdss --help

Metadata

Release files for rcdss 0.9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rcdss 0.9
File Size Uploaded
rcdss-0.9.tar.gz 9.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for rcdss 0.9
File Interpreter ABI Platform
rcdss-0.9-py3-none-any.whl Python 3 none any Details

Total release size: 19.3 kB

Release files / rcdss-0.9.tar.gz

Download URL rcdss-0.9.tar.gz
Size 9.6 kB
Tags Source
SHA-256 checksum
How to use checksums
f410e573dd8c2f01521d7422b25ade1d1a891293219256ac5b3928460155f727
BLAKE2b-256 checksum
How to use checksums
d52c58478621b9d2770e9d7f618f3e550d6f387551ede1c7fd099443be9ab03b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.11.4

Release files / rcdss-0.9-py3-none-any.whl

Download URL rcdss-0.9-py3-none-any.whl
Size 9.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
9b61080375618756db2b5db76a1acec430b599410d4115fa9049ea229868f947
BLAKE2b-256 checksum
How to use checksums
25081c8f5d9b438cad23a8187239a1f62732b28f96211af29fc330baae7ae061
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.11.4

Release history Release notifications | RSS feed

This release

0.9 This release

2 release files

0.8

2 release files

0.7

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page