Bug 205689 - SSHFP Resource Record addition with system-config-bind
SSHFP Resource Record addition with system-config-bind
Product: Fedora
Classification: Fedora
Component: system-config-bind (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Ondrej Dvoracek
Depends On:
  Show dependency treegraph
Reported: 2006-09-07 19:15 EDT by Eric Moret
Modified: 2007-11-30 17:11 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2007-04-03 07:09:51 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Eric Moret 2006-09-07 19:15:31 EDT
Description of problem:
I could not find out how to add an SSHFP RR with the system-config-bind tool.
SSHFP RR are used by ssh to verify host key fingerprints. Described in rfc4255.

You can use the following command on the ssh server to generate a valid SSHFP RR:

$ ssh-keygen -r simca-1000 -f /etc/ssh/ssh_host_rsa_key.pub
simca-1000 IN SSHFP 1 1 3e21f08cf22a039de93203ee7726bfcf02287756
$ ssh-keygen -r simca-1000 -f /etc/ssh/ssh_host_dsa_key.pub
simca-1000 IN SSHFP 2 1 a6c2f2f5662c0a98f448c32dea880330d6d7950d

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. Create a new zone
2. Right click the new zone name and select Add...
3. The list misses an entry for SSHFP
Expected results:
It should be possible to add SSHFB records to bond configuration using
Comment 1 Martin Stransky 2006-09-08 05:04:11 EDT
Unfortunately it's after test3 freeze....
Comment 2 Juliano F. Ravasi 2006-11-19 17:35:44 EST
Please update Version -> fc6.

system-config-bind really needs a SSHFP record type.
Comment 3 Eric Moret 2007-01-26 17:35:55 EST
ping, we are now back to pre test1 :)
Comment 4 Ondrej Dvoracek 2007-03-13 12:03:35 EDT
I made patch that allows adding SSHFP records with system-config-bind. But now
the bind package maintainter is testing whether this type of DNS record is
supported by bind. 
Comment 5 Eric Moret 2007-03-13 12:40:17 EDT
Hi Thank you for your patch. I confirm that SSHFP RR are working in my setup. I 
have added them manually to my DNS maps and I can query them without a problem. 
My confirmed working version of bind is 9.3.3-0.2.rc2.fc5
Comment 6 Ondrej Dvoracek 2007-03-13 12:44:26 EDT
yeah, the bind maintainer also said that it works. So I'll public the patch as
soon as possible. I have to solve some details.

Note You need to log in before you can comment on or make changes to this bug.