Files
ExploreDNS/vendor/github.com/miekg/dns/tlsa.go
db806835aa
CI / test (pull_request) Failing after 3h2m8s
CI / docker (pull_request) Has been cancelled
fix: vendor deps and fix CI go-version, timeout, GOTOOLCHAIN (HAN-414)
- Run go mod vendor to eliminate proxy.golang.org network dependency
- Set GOFLAGS=-mod=vendor at job env level so all go commands use vendor/
- Fix go-version from 1.23 to 1.24.0 to match go.mod
- Move GOTOOLCHAIN=local to job-level env (not per-step inline)
- Set cache: false on setup-go (cache is irrelevant with vendoring)
- Add timeout-minutes: 15 so failures are caught quickly instead of 3h

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: multica-agent <github@multica.ai>
2026-06-11 09:08:51 +10:00

45 lines
1.1 KiB
Go

package dns
import (
"crypto/x509"
"net"
"strconv"
)
// Sign creates a TLSA record from an SSL certificate.
func (r *TLSA) Sign(usage, selector, matchingType int, cert *x509.Certificate) (err error) {
r.Hdr.Rrtype = TypeTLSA
r.Usage = uint8(usage)
r.Selector = uint8(selector)
r.MatchingType = uint8(matchingType)
r.Certificate, err = CertificateToDANE(r.Selector, r.MatchingType, cert)
return err
}
// Verify verifies a TLSA record against an SSL certificate. If it is OK
// a nil error is returned.
func (r *TLSA) Verify(cert *x509.Certificate) error {
c, err := CertificateToDANE(r.Selector, r.MatchingType, cert)
if err != nil {
return err // Not also ErrSig?
}
if r.Certificate == c {
return nil
}
return ErrSig // ErrSig, really?
}
// TLSAName returns the ownername of a TLSA resource record as per the
// rules specified in RFC 6698, Section 3.
func TLSAName(name, service, network string) (string, error) {
if !IsFqdn(name) {
return "", ErrFqdn
}
p, err := net.LookupPort(network, service)
if err != nil {
return "", err
}
return "_" + strconv.Itoa(p) + "._" + network + "." + name, nil
}