Querying DNSSEC
Function
This API is used to query DNSSEC for a public zone.
Public zones are global resources. Select the AP-Singapore (ap-southeast-3) region.
Calling Method
For details, see Calling APIs.
Authorization Information
Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.
- If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
- If you are using identity policy-based authorization, the following identity policy-based permissions are required.
URI
GET /v2/zones/{zone_id}/dnssec
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| zone_id | Yes | String | Definition Public zone ID. You can obtain the ID by calling the API (ListPublicZones) for querying public zones. Constraints N/A Range N/A Default Value N/A |
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| X-Auth-Token | Yes | String | Definition User token, which is used for identity authentication. It must be carried in the request header to verify the user identity during API calls. You can obtain it by calling the IAM API for obtaining a user token. The value of X-Subject-Token in the response header is the user token. For details about how to obtain a user token, see Obtaining a User Token. Constraints N/A Range N/A Default Value N/A |
Response Parameters
Status code: 200
| Parameter | Type | Description |
|---|---|---|
| zone_name | String | Definition Public zone to which the DNSSEC configuration belongs. Range N/A |
| key_tag | Integer | Definition Key tag. It identifies the key used for DNSSEC signing. Range N/A |
| flag | Integer | Definition Flag of a DNSKEY record, which identifies the usage and attributes of the key. Range N/A |
| digest_algorithm | String | Definition Digest algorithm. It is used to calculate the digest of the public key in the DS record. Range N/A |
| digest_type | Integer | Definition Digest algorithm type. It is used to identify the algorithm used to calculate the digest in the DS record. Range N/A |
| digest | String | Definition Digest. This is the digest data calculated based on the public key using the digest algorithm. Range N/A |
| signature | String | Definition Signature algorithm. It identifies the algorithm used to generate the DNSSEC signature, for example, ECDSAP256SHA256. Range N/A |
| signature_type | Integer | Definition Signature algorithm type. It identifies the code of the algorithm used to generate the signature. For example, 13 corresponds to ECDSAP256SHA256. Range N/A |
| ksk_public_key | String | Definition The public key of the key signing key (KSK), which is used to sign other keys and participate in the construction of the trust chain. Range N/A |
| ds_record | String | Definition DS record. A delegation signer (DS) record is used to transfer the trust chain between the parent zone and child zone. Range N/A |
| created_at | String | Definition Creation time. The value must be a UTC+0 time in format of yyyy-MM-dd'T'HH:mm:ss.SSS, for example, 2023-01-01T12:00:00.000. Range N/A |
| updated_at | String | Definition Update time. The value must be a UTC+0 time in format of yyyy-MM-dd'T'HH:mm:ss.SSS, for example, 2023-01-01T12:00:00.000. Range N/A |
| status | String | Definition DNSSEC configuration status. Range |
Status code: 400
| Parameter | Type | Description |
|---|---|---|
| code | String | Definition Error code Range N/A |
| message | String | Definition Error description Range N/A |
Status code: 500
| Parameter | Type | Description |
|---|---|---|
| code | String | Definition Error code Range N/A |
| message | String | Definition Error description Range N/A |
Example Requests
None
Example Responses
Status code: 200
-
{ "zone_name" : "example.com.", "key_tag" : 46576, "flag" : 257, "digest" : "2cb6a21bc5ea1622a24d35b94d171dcc06523daf708f6eb08c3358608e84f51c", "digest_algorithm" : "SHA256", "digest_type" : 2, "signature" : "ECDSAP256SHA256", "signature_type" : 13, "ksk_public_key" : "M7/fjwRNXwWsBxjIMZ2KzxEQ+DnhZ8pbPTn8VCcPKdrDhvV750DkFdXhuXRMLFHrXI9xjIVUugtVKgmdPIEf8w==", "ds_record" : "example.com. 300 IN DS 46576 13 2 2cb6a21bc5ea1622a24d35b94d171dcc06523daf708f6eb08c3358608e84f51c", "created_at" : "2023-11-17T12:03:17.827", "updated_at" : "2023-11-17T12:03:17.827", "status" : "ENABLE" } -
{ "status" : "DISABLE" }
SDK Sample Code
The SDK sample code is as follows.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 | package com.huaweicloud.sdk.test; import com.huaweicloud.sdk.core.auth.ICredential; import com.huaweicloud.sdk.core.auth.BasicCredentials; import com.huaweicloud.sdk.core.exception.ConnectionException; import com.huaweicloud.sdk.core.exception.RequestTimeoutException; import com.huaweicloud.sdk.core.exception.ServiceResponseException; import com.huaweicloud.sdk.dns.v2.region.DnsRegion; import com.huaweicloud.sdk.dns.v2.*; import com.huaweicloud.sdk.dns.v2.model.*; public class ShowDnssecConfigSolution { public static void main(String[] args) { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment String ak = System.getenv("CLOUD_SDK_AK"); String sk = System.getenv("CLOUD_SDK_SK"); ICredential auth = new BasicCredentials() .withAk(ak) .withSk(sk); DnsClient client = DnsClient.newBuilder() .withCredential(auth) .withRegion(DnsRegion.valueOf("<YOUR REGION>")) .build(); ShowDnssecConfigRequest request = new ShowDnssecConfigRequest(); request.withZoneId("{zone_id}"); try { ShowDnssecConfigResponse response = client.showDnssecConfig(request); System.out.println(response.toString()); } catch (ConnectionException e) { e.printStackTrace(); } catch (RequestTimeoutException e) { e.printStackTrace(); } catch (ServiceResponseException e) { e.printStackTrace(); System.out.println(e.getHttpStatusCode()); System.out.println(e.getRequestId()); System.out.println(e.getErrorCode()); System.out.println(e.getErrorMsg()); } } } |
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 | # coding: utf-8 import os from huaweicloudsdkcore.auth.credentials import BasicCredentials from huaweicloudsdkdns.v2.region.dns_region import DnsRegion from huaweicloudsdkcore.exceptions import exceptions from huaweicloudsdkdns.v2 import * if __name__ == "__main__": # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak = os.environ["CLOUD_SDK_AK"] sk = os.environ["CLOUD_SDK_SK"] credentials = BasicCredentials(ak, sk) client = DnsClient.new_builder() \ .with_credentials(credentials) \ .with_region(DnsRegion.value_of("<YOUR REGION>")) \ .build() try: request = ShowDnssecConfigRequest() request.zone_id = "{zone_id}" response = client.show_dnssec_config(request) print(response) except exceptions.ClientRequestException as e: print(e.status_code) print(e.request_id) print(e.error_code) print(e.error_msg) |
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 | package main import ( "fmt" "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic" dns "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/dns/v2" "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/dns/v2/model" region "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/dns/v2/region" ) func main() { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak := os.Getenv("CLOUD_SDK_AK") sk := os.Getenv("CLOUD_SDK_SK") auth, err := basic.NewCredentialsBuilder(). WithAk(ak). WithSk(sk). SafeBuild() if err != nil { fmt.Println(err) return } hcClient, err := dns.DnsClientBuilder(). WithRegion(region.ValueOf("<YOUR REGION>")). WithCredential(auth). SafeBuild() if err != nil { fmt.Println(err) return } client := dns.NewDnsClient(hcClient) request := &model.ShowDnssecConfigRequest{} request.ZoneId = "{zone_id}" response, err := client.ShowDnssecConfig(request) if err == nil { fmt.Printf("%+v\n", response) } else { fmt.Println(err) } } |
For SDK sample code of more programming languages, see the Sample Code tab in API Explorer. SDK sample code can be automatically generated.
Status Codes
| Status Code | Description |
|---|---|
| 200 | Successful request |
| 400 | Bad Request |
| 500 | Internal Server Error |
Error Codes
See Error Codes.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot