2021-04-08 23:32:50 +02:00
|
|
|
#! /bin/env python3
|
|
|
|
import argparse
|
|
|
|
import collections
|
|
|
|
import configparser
|
|
|
|
import logging
|
|
|
|
|
|
|
|
import dns.name
|
|
|
|
import dns.rdataset
|
|
|
|
import dns.rdatatype
|
|
|
|
from dns.rdtypes.ANY import CNAME, DNAME, MX, NS, SOA, SSHFP, TXT
|
|
|
|
from dns.rdtypes.IN import AAAA, SRV, A
|
2021-04-14 19:13:09 +02:00
|
|
|
import dns.resolver
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
# dns name object '@'
|
|
|
|
AT = dns.name.Name(())
|
|
|
|
|
|
|
|
def format_rname(mail: str):
|
|
|
|
"""
|
|
|
|
Format a email given by re2o API to a rname dnspython object.
|
|
|
|
|
|
|
|
Given an email address in the standard string format `mail@example.tld`
|
|
|
|
return an email address in the format required by RFC 1035
|
|
|
|
`mail.example.tld.`
|
|
|
|
|
|
|
|
Be careful when using this function. It is a very simple email parsing
|
|
|
|
function and does support the wide range of possible emails format. It also
|
|
|
|
does not check is email is valid and does not escape caracters.
|
|
|
|
|
|
|
|
Return a `dns.name.Name` object.
|
|
|
|
"""
|
|
|
|
|
|
|
|
local, domain = mail.split("@")
|
|
|
|
rname = dns.name.Name((local, *dns.name.from_text(domain)))
|
|
|
|
|
|
|
|
return rname
|
|
|
|
|
|
|
|
|
2021-04-14 15:34:06 +02:00
|
|
|
def format_re2o_domain(name: str):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""
|
|
|
|
Format a zone name given by the re2o API to a mname dnspython object.
|
|
|
|
|
|
|
|
Given a a name of the format `.zone.domain.tld` output the
|
|
|
|
`zone.domain.tld.`, formatted accordingly to the RFC 1035.
|
|
|
|
|
|
|
|
Return a `dns.name.name` object.
|
|
|
|
"""
|
|
|
|
|
|
|
|
if name[0] == ".":
|
|
|
|
name = name[1:]
|
|
|
|
|
|
|
|
mname = dns.name.from_text(name)
|
|
|
|
|
|
|
|
return mname
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def add_to_zone(zone, name, rdata):
|
|
|
|
"""Add a rdata object to a zone object."""
|
|
|
|
|
2021-04-14 15:34:06 +02:00
|
|
|
node = zone.find_node(name, create=True)
|
|
|
|
rdataset = node.find_rdataset(
|
|
|
|
rdata.rdclass,
|
2021-04-09 05:02:56 +02:00
|
|
|
rdata.rdtype,
|
|
|
|
create=True
|
|
|
|
)
|
|
|
|
rdataset.add(rdata)
|
|
|
|
|
2021-04-14 19:13:09 +02:00
|
|
|
|
|
|
|
def get_serial(dns_zone):
|
|
|
|
"""
|
|
|
|
Query the serial number from the NS
|
|
|
|
|
2021-04-14 19:21:40 +02:00
|
|
|
The parameter `dns_zone` can either be a `str` or a `dns.zone.Zone` object.
|
|
|
|
Error handling is added to return 0 if the query is unsucessful.
|
2021-04-14 19:13:09 +02:00
|
|
|
"""
|
|
|
|
|
|
|
|
try:
|
|
|
|
answer = dns.resolver.query(dns_zone, 'soa')
|
|
|
|
soa = answer.rrset.items[0]
|
|
|
|
serial = soa.serial
|
|
|
|
except:
|
|
|
|
logging.warning(f"[GET SERIAL] failed to query serial for this zone."
|
|
|
|
"Fallback to default value 0")
|
|
|
|
serial = 0
|
|
|
|
|
|
|
|
return serial
|
|
|
|
|
2021-04-14 19:16:06 +02:00
|
|
|
def update_serial(serial, serial_bits=32):
|
|
|
|
"""Update serial number
|
|
|
|
|
|
|
|
According to RFC 1982 and Knot implementation.
|
|
|
|
SERIAL_BITS = 32 by default.
|
|
|
|
"""
|
|
|
|
|
|
|
|
serial = serial + 1 % 2**32
|
|
|
|
|
|
|
|
return serial
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def soa_handler(re2o_zone, dns_zone):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""Handler for SOA record"""
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
soa = re2o_zone["soa"]
|
2021-04-08 23:32:50 +02:00
|
|
|
logging.debug(f"SOA = {soa}")
|
2021-04-09 05:02:56 +02:00
|
|
|
|
|
|
|
ns = re2o_zone["ns_records"][0]["target"]
|
|
|
|
ns_obj = dns.name.from_text(ns)
|
2021-04-14 19:13:09 +02:00
|
|
|
|
|
|
|
origin = dns_zone.origin
|
|
|
|
serial = get_serial(origin)
|
2021-04-14 19:16:06 +02:00
|
|
|
serial = update_serial(serial)
|
2021-04-14 19:13:09 +02:00
|
|
|
logging.debug(f"[SOA] zone_origin={origin} serial={serial}")
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
soa_obj = SOA.SOA(
|
2021-04-09 05:02:56 +02:00
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.SOA,
|
|
|
|
ns_obj,
|
|
|
|
format_rname(soa["mail"]),
|
2021-04-14 19:13:09 +02:00
|
|
|
serial,
|
2021-04-09 05:02:56 +02:00
|
|
|
soa["refresh"],
|
|
|
|
soa["retry"],
|
|
|
|
soa["expire"],
|
|
|
|
soa["ttl"],
|
2021-04-08 23:32:50 +02:00
|
|
|
)
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
add_to_zone(dns_zone, AT, soa_obj)
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def originv4_handler(re2o_zone, dns_zone):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""Handler for the IPv4 origin"""
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
ipv4_addr = re2o_zone["originv4"]["ipv4"]
|
|
|
|
logging.debug(f"originv4 = {re2o_zone['originv4']}")
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
originv4_obj = A.A(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.A,
|
|
|
|
ipv4_addr
|
|
|
|
)
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
add_to_zone(dns_zone, AT, originv4_obj)
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def originv6_handler(re2o_zone, dns_zone):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""Handler for the IPv6 origin"""
|
|
|
|
|
|
|
|
ipv6_addr = zone["originv6"] # Yes, re2o is this weird and inconsistent
|
|
|
|
logging.debug(f"originv6 = {zone['originv6']}")
|
|
|
|
|
|
|
|
originv6_obj = AAAA.AAAA(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.AAAA,
|
|
|
|
ipv6_addr
|
|
|
|
)
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
add_to_zone(dns_zone, AT, originv6_obj)
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def ns_records_handler(re2o_zone, dns_zone):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""Handler for the NS record"""
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
for record in re2o_zone["ns_records"]:
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
logging.debug(f"NS target = {record}")
|
|
|
|
|
|
|
|
target = record["target"]
|
|
|
|
target_obj = dns.name.from_text(target)
|
|
|
|
|
|
|
|
NS_obj = NS.NS(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.NS,
|
|
|
|
target_obj
|
|
|
|
)
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
add_to_zone(dns_zone, AT, NS_obj)
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def sshfp_record_handler(re2o_zone, dns_zone):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""Handler for the SSHFP record"""
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
for record in re2o_zone["sshfp"]:
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
# DNS Name object for Hostname
|
|
|
|
hostname = record["hostname"]
|
|
|
|
key_name = dns.name.Name(hostname)
|
|
|
|
|
|
|
|
for fp in record["sshfp"]:
|
|
|
|
logging.debug(f"SSHFP = {fp}")
|
|
|
|
|
|
|
|
algorithm = fp["algo_id"]
|
|
|
|
|
|
|
|
for fp_type in fp["hash"]:
|
|
|
|
|
|
|
|
fingerprint = fp["hash"][fp_type]
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
SSHFP_obj = SSHFP.SSHFP(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.SSHFP,
|
|
|
|
algorithm,
|
|
|
|
fp_type,
|
|
|
|
fingerprint,
|
2021-04-08 23:32:50 +02:00
|
|
|
)
|
2021-04-09 05:02:56 +02:00
|
|
|
|
|
|
|
add_to_zone(dns_zone, key_name, SSHFP_obj)
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def mx_records_handler(re2o_zone, dns_zone):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""Handler for the MX record"""
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
for record in re2o_zone["mx_records"]:
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
logging.debug(f"MX = {record}")
|
|
|
|
|
|
|
|
preference = record["priority"]
|
|
|
|
exchange = record["target"]
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
exchange_obj = dns.name.from_text(exchange)
|
|
|
|
|
|
|
|
MX_obj = MX.MX(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.MX,
|
|
|
|
preference,
|
|
|
|
exchange_obj
|
2021-04-08 23:32:50 +02:00
|
|
|
)
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
add_to_zone(dns_zone, AT, MX_obj)
|
|
|
|
|
2021-04-08 23:32:50 +02:00
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def txt_records_handler(re2o_zone, dns_zone):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""Handler for TXT record"""
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
for record in re2o_zone["txt_records"]:
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
logging.debug(f"TXT = {record}")
|
|
|
|
|
|
|
|
# DNS Name object for field1
|
|
|
|
name = record["field1"]
|
|
|
|
key_name = dns.name.Name((name,))
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
TXT_obj = TXT.TXT(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.TXT,
|
|
|
|
record["field2"]
|
2021-04-08 23:32:50 +02:00
|
|
|
)
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
add_to_zone(dns_zone, key_name, TXT_obj)
|
|
|
|
|
2021-04-08 23:32:50 +02:00
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def srv_records_handler(re2o_zone, dns_zone):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""Handler for SRV record"""
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
for record in re2o_zone["srv_records"]:
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
logging.debug(f"SRV = {record}")
|
|
|
|
|
|
|
|
# DNS Name obj for SRV
|
|
|
|
key_name = dns.name.from_text(f"{record['service']}_{record['protocol']}")
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
SRV_obj = SRV.SRV(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.SRV,
|
|
|
|
record["priority"],
|
|
|
|
record["weight"],
|
|
|
|
record["port"],
|
|
|
|
record["target"]
|
2021-04-08 23:32:50 +02:00
|
|
|
)
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
add_to_zone(dns_zone, key_name, SRV_obj)
|
2021-04-08 23:32:50 +02:00
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def a_records_handler(re2o_zone, dns_zone):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""Handler for A Record"""
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
for record in re2o_zone["a_records"]:
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
logging.debug(f"A = {record}")
|
|
|
|
|
|
|
|
# DNS Name object for Hostname
|
|
|
|
hostname = record["hostname"]
|
|
|
|
key_name = dns.name.Name((hostname,))
|
|
|
|
|
|
|
|
ipv4_addr = record["ipv4"]
|
|
|
|
|
|
|
|
A_obj = A.A(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.A,
|
|
|
|
ipv4_addr
|
|
|
|
)
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
add_to_zone(dns_zone, key_name, A_obj)
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
def aaaa_records_handler(re2o_zone, dns_zone):
|
2021-04-08 23:32:50 +02:00
|
|
|
"""Handler for AAAA Record"""
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
for record in re2o_zone["aaaa_records"]:
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
logging.debug(f"AAAA = {record}")
|
|
|
|
|
|
|
|
if record["ipv6"] == []:
|
|
|
|
logging.debug("AAAA record does not have an IPv6. Skipping.")
|
|
|
|
return
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
# DNS Name object for Hostname
|
|
|
|
hostname = record["hostname"]
|
|
|
|
key_name = dns.name.Name((hostname,))
|
|
|
|
|
2021-04-08 23:32:50 +02:00
|
|
|
ipv6_addr = record["ipv6"][0]["ipv6"] # thanks re2o
|
|
|
|
|
|
|
|
AAAA_obj = AAAA.AAAA(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.AAAA,
|
|
|
|
ipv6_addr
|
|
|
|
)
|
|
|
|
|
|
|
|
|
2021-04-09 05:02:56 +02:00
|
|
|
add_to_zone(dns_zone, key_name, AAAA_obj)
|
2021-04-08 23:32:50 +02:00
|
|
|
|
|
|
|
|
2021-04-09 06:23:14 +02:00
|
|
|
def cname_records_handler(re2o_zone, dns_zone):
|
|
|
|
"""Handler fo CNAME records"""
|
|
|
|
|
|
|
|
for record in re2o_zone["cname_records"]:
|
|
|
|
|
|
|
|
logging.debug(f"CNAME = {record}")
|
|
|
|
|
|
|
|
target = dns.name.from_text(record["alias"])
|
|
|
|
name = dns.name.from_text(record["hostname"], origin=None)
|
|
|
|
|
|
|
|
CNAME_obj = CNAME.CNAME(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.CNAME,
|
|
|
|
target
|
|
|
|
)
|
|
|
|
|
|
|
|
add_to_zone(dns_zone, name, CNAME_obj)
|
|
|
|
|
2021-04-14 15:34:06 +02:00
|
|
|
def dname_records_handler(re2o_zone, dns_zone):
|
|
|
|
"""Handler for DNAME records"""
|
|
|
|
|
|
|
|
for record in re2o_zone["dname_records"]:
|
|
|
|
|
|
|
|
logging.debug(f"DNAME = {record}")
|
|
|
|
|
|
|
|
alias = format_re2o_domain(record["alias"])
|
|
|
|
zone = format_re2o_domain(record["zone"])
|
|
|
|
|
|
|
|
DNAME_obj = DNAME.DNAME(
|
|
|
|
dns.rdataclass.IN,
|
|
|
|
dns.rdatatype.DNAME,
|
2021-04-14 15:56:57 +02:00
|
|
|
zone
|
2021-04-14 15:34:06 +02:00
|
|
|
)
|
|
|
|
|
2021-04-14 15:56:57 +02:00
|
|
|
add_to_zone(dns_zone, alias, DNAME_obj)
|
2021-04-14 15:34:06 +02:00
|
|
|
|
2021-04-09 06:23:14 +02:00
|
|
|
|
2021-04-08 23:32:50 +02:00
|
|
|
def pass_handler(zone, records):
|
2021-04-14 19:19:27 +02:00
|
|
|
"""
|
|
|
|
Do nothing (pass)
|
|
|
|
|
|
|
|
Handler which does nothing, used for edge cases like the pseudo-record
|
|
|
|
`name` returned by Re2oAPI or to disable some other handlers in the
|
|
|
|
`HANDLERS` variable.
|
|
|
|
"""
|
2021-04-08 23:32:50 +02:00
|
|
|
pass
|
|
|
|
|
|
|
|
|
|
|
|
HANDLERS = {
|
|
|
|
"soa": soa_handler,
|
|
|
|
"originv4": originv4_handler,
|
|
|
|
"originv6": originv6_handler,
|
|
|
|
"ns_records": ns_records_handler,
|
|
|
|
"sshfp": sshfp_record_handler,
|
|
|
|
"mx_records": mx_records_handler,
|
|
|
|
"txt_records": txt_records_handler,
|
|
|
|
"srv_records": srv_records_handler,
|
|
|
|
"a_records": a_records_handler,
|
|
|
|
"aaaa_records": aaaa_records_handler,
|
2021-04-09 06:23:14 +02:00
|
|
|
"cname_records": cname_records_handler,
|
2021-04-14 15:56:57 +02:00
|
|
|
"dname_records": dname_records_handler,
|
2021-04-14 15:34:06 +02:00
|
|
|
"name": pass_handler,
|
2021-04-08 23:32:50 +02:00
|
|
|
}
|