Retire dyndns legacy shared-key fallback entirely
uschi's device should be using its own dedicated login now, and with jens/kack/test's own hostnames already removed, nothing needed the fallback anymore. Removed the update-policy fallback grant, retired the original shared TSIG key (in production since March 2022), and deleted the now-dead legacy code path from nsupdate.php and its ipv4/ ipv6 variants. Per-host auth binding for dyndns is now unconditional with no exceptions. Verified jens can no longer update any host, while uschi/vpn continue to update themselves normally. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -130,6 +130,30 @@ Nothing here is urgent; all are low-risk, no-downtime changes.
|
|||||||
`uschi`'s own current real IP back so nothing actually changed) that
|
`uschi`'s own current real IP back so nothing actually changed) that
|
||||||
the `jens`→`uschi` legacy path still returns `0`. `named-checkconf`/
|
the `jens`→`uschi` legacy path still returns `0`. `named-checkconf`/
|
||||||
`rndc reload` clean throughout.
|
`rndc reload` clean throughout.
|
||||||
|
**Legacy fallback removed entirely 2026-07-26** — confirmed the
|
||||||
|
`jens` fallback wasn't needed for `uschi` anymore (its own dedicated
|
||||||
|
login/key from the original fix is what should be used going
|
||||||
|
forward), and with `jens`'s and `kack`/`test`'s own hostnames already
|
||||||
|
gone, nothing was left depending on it. Removed the
|
||||||
|
`grant "dyndns.jayfield.org" subdomain dyndns.jayfield.org. ANY;`
|
||||||
|
fallback grant and its key `include` from `named.conf.default-zones`;
|
||||||
|
retired the original shared TSIG key itself
|
||||||
|
(`/etc/bind/dyndns.jayfield.org.key`, in production since March 2022)
|
||||||
|
to
|
||||||
|
`/root/removed-configs-backup/dyndns-remove-legacy-fallback-20260726102228/`;
|
||||||
|
removed the now-dead legacy-path branch from
|
||||||
|
`nsupdate.php`/`nsupdate_ipv4.php`/`nsupdate_ipv6.php` — `nsupdate()`
|
||||||
|
now unconditionally rejects (`-1`) any request where the
|
||||||
|
authenticated user doesn't match the requested host, no exceptions.
|
||||||
|
Verified: `jens` attempting to update `uschi` now fails immediately
|
||||||
|
(`ret=-1`, no BIND round-trip at all — rejected in PHP before ever
|
||||||
|
building an `nsupdate` command), while `uschi` and `vpn` updating
|
||||||
|
themselves still succeed (`ret=0`, confirmed via `dig` against their
|
||||||
|
real IPs). Per-user auth binding for dyndns is now unconditional,
|
||||||
|
closing this item out completely — no more grandfathered exceptions
|
||||||
|
of any kind. The `jens` `.htpasswd` account itself was left in place
|
||||||
|
(not asked to remove it, and it's now inert for DNS updates anyway
|
||||||
|
since it has no hostname or grant left to use).
|
||||||
|
|
||||||
- [x] **dyndns/default-vhost access logging is a no-op** — done 2026-07-25
|
- [x] **dyndns/default-vhost access logging is a no-op** — done 2026-07-25
|
||||||
found 2026-07-20 while investigating the command injection below.
|
found 2026-07-20 while investigating the command injection below.
|
||||||
|
|||||||
Reference in New Issue
Block a user