Skip to content

Include DNSSEC status in --whois output - #58

Merged
robtme merged 3 commits into
openrdap:mainfrom
bessone:master
Sep 23, 2026
Merged

robtme merged 3 commits into
openrdap:mainfrom
bessone:master

Conversation

@bessone

@bessone bessone commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Problem

The -w/--whois output format goes through Response.ToWhoisStyleResponse()
in response.go, which builds the WHOIS-style key/value list field by field.
Unlike the default text Printer (print.go), which does print SecureDNS
via printSecureDNS, ToWhoisStyleResponse() never reads d.SecureDNS at
all, so DNSSEC status is silently dropped when using --whois.

Fix

Add a DNSSEC field to the WHOIS-style output, derived from
SecureDNS.DelegationSigned, matching the convention used by
ICANN/Verisign-style WHOIS output (signedDelegation / unsigned).

DelegationSigned (rather than ZoneSigned) was chosen because it reflects
whether the parent zone has published the DS record(s) needed to complete
the DNSSEC chain of trust — i.e. whether DNSSEC validation is actually
operative for the domain, which is what WHOIS consumers expect from this
field. ZoneSigned only indicates the domain's own zone is internally
signed, independent of delegation, and isn't shown in standard WHOIS output.

DS record data (key tag, algorithm, digest, etc.) is intentionally left out
of --whois output, consistent with the terse style of real-world WHOIS
responses; it remains available via the default --text and --json
formats.

Change

Added a DNSSEC field in ToWhoisStyleResponse(), populated right after
Name Server, using the same ordering position it typically has in
production TLD WHOIS output.

Testing

  • Ran rdap --whois example.com against a signed domain and confirmed
    DNSSEC: signedDelegation now appears.
  • Ran against an unsigned domain and confirmed DNSSEC: unsigned appears.
  • Ran against a domain with no SecureDNS object at all and confirmed no
    DNSSEC line is emitted (unchanged behavior — field is simply omitted,
    same as the other w.add() calls when data isn't present).

Summary by CodeRabbit

  • New Features
    • WHOIS-style responses now include a DNSSEC status after the name-server entries when delegation signing information or DS records are available. The status indicates a signed or unsigned delegation; key data alone does not add a DNSSEC status.

Add DNSSEC status handling to response output in whois style
@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5ce892ce-3eca-4960-98d7-bd65f432f546

📥 Commits

Reviewing files that changed from the base of the PR and between bc63f20 and fb41f50.

📒 Files selected for processing (2)
  • response.go
  • response_test.go
🚧 Files skipped from review as they are similar to previous changes (2)
  • response.go
  • response_test.go

Included review availability: Your plan provides up to 2 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

ToWhoisStyleResponse adds DNSSEC after the name-server fields. A non-nil DelegationSigned value sets “signedDelegation” or “unsigned.” If DelegationSigned is nil, non-empty DS records set “signedDelegation.” Keys alone do not add a DNSSEC field. Tests cover these cases and confirm field order.

Merge Risk: ⚪ Minimal · up to fb41f

No actionable merge-blocking risk is established from the supplied evidence.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed Title clearly and concisely describes the main change: adding DNSSEC status to --whois output.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: dae5cd06-423c-46c1-ab0f-00735b99d9eb

📥 Commits

Reviewing files that changed from the base of the PR and between b4d5927 and a93ed82.

📒 Files selected for processing (1)
  • response.go

Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review.

Comment thread response.go Outdated
Match ICANN WHOIS field order, fall back to dsData/keyData presence
when delegationSigned is omitted, and add tests.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5aaeaf3a-bd80-49e9-92d7-8b304fa85dad

📥 Commits

Reviewing files that changed from the base of the PR and between a93ed82 and bc63f20.

📒 Files selected for processing (2)
  • response.go
  • response_test.go

Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review.

Comment thread response.go Outdated
keyData is child DNSKEY data; only DS records prove the parent delegation
is signed (RFC 9083).
@robtme
robtme merged commit 7743122 into openrdap:main Sep 23, 2026
4 checks passed
@robtme

robtme commented Sep 23, 2026

Copy link
Copy Markdown
Member

Great stuff, thanks @bessone!

@robtme robtme mentioned this pull request Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants