octodns.record.ds
Classes
|
|
|
|
|
Checks DS records against deprecated algorithms and digest types per RFC 8624. |
|
Strict DS rdata validator per RFC 4034 §5.1, RFC 4509, and RFC 6605. |
|
Validates DS rdata. |
- class octodns.record.ds.DsValueValidator(id, sets=None)[source]
Bases:
ValueValidatorValidates DS rdata. Supports both the current field names (
key_tag,algorithm,digest_type,digest) and the deprecated legacy field names (flags,protocol,algorithm,public_key), which will be removed in 2.0.- validate(value_cls, data, _type)[source]
Validate a record’s rdata values.
- Parameters:
value_cls (type) – The concrete value class being validated (e.g.
MxValue,_Ipv4Value). Validators that need access to value class-level attributes (e.g.VALID_ALGORITHMS,_address_type) should read them fromvalue_cls. Per-instance configuration should live onself, not onvalue_cls.data (list | tuple | str | dict) – The rdata to validate. For multi-value record types this is a list/tuple of value dicts or strings; for single-value types it may be a bare value. Most validators iterate
datadirectly — when a validator needs to accept either form it should normalize withif not isinstance(data, (list, tuple)): data = (data,)._type (str) – The record type string (e.g.
'MX','A'). Passed through to helpers like_check_target_formatwhich format it into their reason strings.
- Returns:
A list of human-readable reason strings describing validation failures. Must return an empty list when the values are valid. Reasons from multiple validators are concatenated by the caller, so each reason must stand alone without context from the others.
- Return type:
Notes
Implementations must not raise on invalid input — all failures are reported via the returned list. Reason strings are surfaced verbatim in
ValidationErrormessages, so phrasing and punctuation should be stable across releases.
- class octodns.record.ds.DsValueRfcValidator(id, sets=None)[source]
Bases:
ValueValidatorStrict DS rdata validator per RFC 4034 §5.1, RFC 4509, and RFC 6605.
key_tagmust be in [0, 65535] (uint16).algorithmmust be in [0, 255] (uint8).digest_typemust be in [0, 255] (uint8).digestmust be a valid hexadecimal string.For known digest types, the digest length is enforced: type 1 (SHA-1) = 40 hex chars, type 2 (SHA-256) = 64 hex chars, type 4 (SHA-384) = 96 hex chars.
The deprecated legacy field names (
flags,protocol,public_key) are not accepted in strict mode.Enabled as part of the
strictvalidator set:manager: enabled: - strict
- _hex_re = re.compile('^[0-9a-fA-F]+$')
- _digest_type_lengths = {1: 40, 2: 64, 4: 96}
- validate(value_cls, data, _type)[source]
Validate a record’s rdata values.
- Parameters:
value_cls (type) – The concrete value class being validated (e.g.
MxValue,_Ipv4Value). Validators that need access to value class-level attributes (e.g.VALID_ALGORITHMS,_address_type) should read them fromvalue_cls. Per-instance configuration should live onself, not onvalue_cls.data (list | tuple | str | dict) – The rdata to validate. For multi-value record types this is a list/tuple of value dicts or strings; for single-value types it may be a bare value. Most validators iterate
datadirectly — when a validator needs to accept either form it should normalize withif not isinstance(data, (list, tuple)): data = (data,)._type (str) – The record type string (e.g.
'MX','A'). Passed through to helpers like_check_target_formatwhich format it into their reason strings.
- Returns:
A list of human-readable reason strings describing validation failures. Must return an empty list when the values are valid. Reasons from multiple validators are concatenated by the caller, so each reason must stand alone without context from the others.
- Return type:
Notes
Implementations must not raise on invalid input — all failures are reported via the returned list. Reason strings are surfaced verbatim in
ValidationErrormessages, so phrasing and punctuation should be stable across releases.
- class octodns.record.ds.DsValueBestPracticeValidator(id, sets=None)[source]
Bases:
ValueValidatorChecks DS records against deprecated algorithms and digest types per RFC 8624.
digest_type1 (SHA-1) is NOT RECOMMENDED (§3.3); use digest_type 2 (SHA-256).Signing
algorithmvalues 1 (RSA/MD5), 3 (DSA/SHA1), 5 (RSA/SHA-1), 6 (DSA-NSEC3-SHA1), and 7 (RSASHA1-NSEC3-SHA1) are deprecated (§3.1).
Enabled as part of the
best-practicevalidator set:manager: enabled: - best-practice
- _deprecated_algorithms = {1: 'RSA/MD5', 3: 'DSA/SHA1', 5: 'RSA/SHA-1', 6: 'DSA-NSEC3-SHA1', 7: 'RSASHA1-NSEC3-SHA1'}
- validate(value_cls, data, _type)[source]
Validate a record’s rdata values.
- Parameters:
value_cls (type) – The concrete value class being validated (e.g.
MxValue,_Ipv4Value). Validators that need access to value class-level attributes (e.g.VALID_ALGORITHMS,_address_type) should read them fromvalue_cls. Per-instance configuration should live onself, not onvalue_cls.data (list | tuple | str | dict) – The rdata to validate. For multi-value record types this is a list/tuple of value dicts or strings; for single-value types it may be a bare value. Most validators iterate
datadirectly — when a validator needs to accept either form it should normalize withif not isinstance(data, (list, tuple)): data = (data,)._type (str) – The record type string (e.g.
'MX','A'). Passed through to helpers like_check_target_formatwhich format it into their reason strings.
- Returns:
A list of human-readable reason strings describing validation failures. Must return an empty list when the values are valid. Reasons from multiple validators are concatenated by the caller, so each reason must stand alone without context from the others.
- Return type:
Notes
Implementations must not raise on invalid input — all failures are reported via the returned list. Reason strings are surfaced verbatim in
ValidationErrormessages, so phrasing and punctuation should be stable across releases.
- class octodns.record.ds.DsValue(value)[source]
Bases:
EqualityTupleMixin,dict- log = <Logger DsValue (WARNING)>
- VALIDATORS = [<octodns.record.ds.DsValueValidator object>, <octodns.record.ds.DsValueRfcValidator object>, <octodns.record.ds.DsValueBestPracticeValidator object>]
- property key_tag
- property algorithm
- property digest_type
- property digest
- property data
- property rdata_text
- class octodns.record.ds.DsRecord(zone, name, data, source=None, context=None)[source]
Bases:
ValuesMixin,Record- REFERENCES = ('https://datatracker.ietf.org/doc/html/rfc4034', 'https://datatracker.ietf.org/doc/html/rfc4035', 'https://datatracker.ietf.org/doc/html/rfc4509', 'https://datatracker.ietf.org/doc/html/rfc6605', 'https://datatracker.ietf.org/doc/html/rfc6840', 'https://datatracker.ietf.org/doc/html/rfc8080', 'https://datatracker.ietf.org/doc/html/rfc8624')
- _type = 'DS'