Child pages
  • UAPI Functions - DNSSEC::set_nsec3

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Description

Excerpt
This function configures the domain to use Next Secure Record 3 (NSEC3) semantics.

Multiexcerpt include
SpaceWithExcerptcom.atlassian.confluence.content.render.xhtml.model.resource.identifiers.SpaceResourceIdentifier@12665
MultiExcerptNameAPIDisabledDNSRole
PageWithExcerptLIB:_ServerRoleDisabledAPI

Panel
bgColor#F2F2F2
borderStylenone

Examples 


Panel
bgColor#FFFFFF
borderStylenone


Expand
titlecPanel or Webmail Session URL


Code Block
languagetext
https://hostname.example.com:2083/cpsess##########/execute/DNSSEC/set_nsec3?domain=example.com&use_nsec3=1&nsec3_opt_out=0&nsec3_iterations=7&nsec3_narrow=1&nsec3_salt=1A2B3C4D5E6F

Include Page
LIB:_CallUAPIFromBrowserLink
LIB:_CallUAPIFromBrowserLink


Expand
titleLiveAPI PHP Class


Code Block
languagephp
linenumberstrue
$cpanel = new CPANEL(); // Connect to cPanel - only do this once.

// Set NSEC3.
$sa_settings = $cpanel->uapi(
    'DNSSEC', 'set_nsec3',
    array(
        'domain'     		=> 'example.com',
        'use_nsec3'     	=> '1',
        'nsec3_opt_out'     => '0',
        'nsec3_iterations'  => '7',
        'nsec3_narrow'      => '1',
        'nsec3_salt'     	=> '1A2B3C4D5E6F',
    )
);

Include Page
LIB:_LiveAPIPHPLink
LIB:_LiveAPIPHPLink


Expand
titleLiveAPI Perl Module


Code Block
languageperl
linenumberstrue
my $cpliveapi = Cpanel::LiveAPI->new(); # Connect to cPanel - only do this once.

# Set NSEC3.
my $sa_settings = $cpliveapi->uapi(
    'DNSSEC', 'set_nsec3',
    {
        'domain'     		=> 'example.com',
        'use_nsec3'     	=> '1',
        'nsec3_opt_out'     => '0',
        'nsec3_iterations'  => '7',
        'nsec3_narrow'     	=> '1',
        'nsec3_salt'     	=> '1A2B3C4D5E6F',
    }
);

Include Page
LIB:_LiveAPIPerlLink
LIB:_LiveAPIPerlLink


Expand
titlecPanel Template Toolkit


Code Block
languagexml
<!-- Set NSEC3. -->
[% SET sa_settings = execute('DNSSEC', 'set_nsec3' { 'domain' => 'example.com','use_nsec3' => '1','nsec3_opt_out => '0','nsec3_iterations' => '7','nsec3_narrow' => '1','nsec3_salt' => '1A2B3C4D5E6F',} ); %]

Include Page
LIB:_TTLink
LIB:_TTLink


Expand
titleCommand Line


Code Block
uapi --user=username DNSSEC set_nsec3 domain=example.com use_nsec3=1 nsec3_opt_out=0 nsec3_iterations=7 nsec3_narrow=1 nsec3_salt=1A2B3C4D5E6F

Include Page
LIB:_UAPICLINote
LIB:_UAPICLINote


Expand
titleOutput (JSON)


Code Block
languagetext
linenumberstrue
{  
   "data":null,
   "errors":null,
   "messages":null,
   "status":1,
   "metadata":{  
      "DNSSEC":{  
         "enabled":{  
            "example.com":1
         }
      }
   }
}


Include Page
LIB:_cPanelAPIShellNote
LIB:_cPanelAPIShellNote


Parameters

ParameterTypeDescriptionPossible valuesExample
domainstring

Required

The domain on which to enable NSEC3 semantics.

A valid domain.example.com
nsec3_opt_outBoolean

Required

Whether the system will create records for all delegations.

 

  • 1 — Create records for all delegations.
  • 0 — Create records only for secure delegations.

    Note
    titleNote:

    Only select 1 if you must create records for all delegations.


 

0

nsec3_iterationsinteger

Required

The number of times that the system re-executes the first resource record hash operation.

A positive integer less than 501.

7

nsec3_narrowBoolean

Required

Whether NSEC3 will operate in Narrow mode or Inclusive mode.

In Narrow mode, PowerDNS sends out white lies about the next secure record. Rather than query the resource record in the database, PowerDNS sends the hash plus 1 as the next secure record.

  • 1 — Narrow mode.
  • 0 — Inclusive mode.
1
nsec3_saltstring

Required

The salt value that PowerDNS uses in the hashes.

For more information about the salt value, read the RFC 5155 documentation.

A hexidecimal string. 1A2B3C4D5E6F

Returns

This function only returns metadata.