This file is indexed.

/usr/share/opendnssec/conf.xml is in opendnssec-common 1:1.4.3-3.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
<?xml version="1.0" encoding="UTF-8"?>

<Configuration>

	<RepositoryList>

<!--
		<Repository name="SoftHSM">
			<Module>/usr/lib/softhsm/libsofthsm.so</Module>
			<TokenLabel>OpenDNSSEC</TokenLabel>
			<PIN>1234</PIN>
			<SkipPublicKey/>
		</Repository>
-->

<!--
		<Repository name="sca6000">
			<Module>/usr/lib/libpkcs11.so</Module>
			<TokenLabel>Sun Metaslot</TokenLabel>
			<PIN>test:1234</PIN>
			<Capacity>255</Capacity>
			<RequireBackup/>
			<SkipPublicKey/>
		</Repository>
-->

	</RepositoryList>

	<Common>
		<Logging>
			<!-- Command line verbosity will overwrite configure file -->
			<Verbosity>3</Verbosity>
			<Syslog><Facility>local0</Facility></Syslog>
		</Logging>
		
		<PolicyFile>/etc/opendnssec/kasp.xml</PolicyFile>
		<ZoneListFile>/etc/opendnssec/zonelist.xml</ZoneListFile>
	</Common>

	<Enforcer>
<!--
		<Privileges>
			<User>opendnssec</User>
			<Group>opendnssec</Group>
		</Privileges>
-->
<!-- NOTE: Enforcer worker threads are not used; this option is ignored -->
<!--
		<WorkerThreads>4</WorkerThreads>
-->
		<Datastore><SQLite>/var/lib/opendnssec/kasp.db</SQLite></Datastore>
		<Interval>PT3600S</Interval>
		<!-- <ManualKeyGeneration/> -->
		<!-- <RolloverNotification>P14D</RolloverNotification> -->
		
		<!-- the <DelegationSignerSubmitCommand> will get all current
		     DNSKEYs (as a RRset) on standard input (with optional CKA_ID)
		-->
		<!-- <DelegationSignerSubmitCommand>/usr/sbin/simple-dnskey-mailer.sh</DelegationSignerSubmitCommand> -->
	</Enforcer>

	<Signer>
<!--
		<Privileges>
			<User>opendnssec</User>
			<Group>opendnssec</Group>
		</Privileges>
-->

		<WorkingDirectory>/var/lib/opendnssec/tmp</WorkingDirectory>
		<WorkerThreads>4</WorkerThreads>
<!--
		<SignerThreads>4</SignerThreads>
-->

<!--
		<Listener>
			<Interface><Port>53</Port></Interface>
		</Listener>
-->

		<!-- the <NotifyCommmand> will expand the following variables:

		     %zone      the name of the zone that was signed
		     %zonefile  the filename of the signed zone
		-->
<!--
		<NotifyCommand>/usr/local/bin/my_nameserver_reload_command</NotifyCommand>
-->
<!--
		<NotifyCommand>/usr/sbin/rndc reload %zone</NotifyCommand>
-->
	</Signer>

</Configuration>