When sending, a TSIG signature using the specified key should be added. *keyring*, a ``dict``, ``callable`` or ``dns.tsig.Key``, is either the TSIG keyring or key to use. The format of a keyring dict is a mapping from TSIG key name, as ``dns.name.Name`` to `
(
self,
keyring: Any,
keyname: dns.name.Name | str | None = None,
fudge: int = 300,
original_id: int | None = None,
tsig_error: int = 0,
other_data: bytes = b"",
algorithm: dns.name.Name | str = dns.tsig.default_algorithm,
)
| 678 | return dns.rrset.from_rdata(keyname, 0, tsig) |
| 679 | |
| 680 | def use_tsig( |
| 681 | self, |
| 682 | keyring: Any, |
| 683 | keyname: dns.name.Name | str | None = None, |
| 684 | fudge: int = 300, |
| 685 | original_id: int | None = None, |
| 686 | tsig_error: int = 0, |
| 687 | other_data: bytes = b"", |
| 688 | algorithm: dns.name.Name | str = dns.tsig.default_algorithm, |
| 689 | ) -> None: |
| 690 | """When sending, a TSIG signature using the specified key |
| 691 | should be added. |
| 692 | |
| 693 | *keyring*, a ``dict``, ``callable`` or ``dns.tsig.Key``, is either |
| 694 | the TSIG keyring or key to use. |
| 695 | |
| 696 | The format of a keyring dict is a mapping from TSIG key name, as |
| 697 | ``dns.name.Name`` to ``dns.tsig.Key`` or a TSIG secret, a ``bytes``. |
| 698 | If a ``dict`` *keyring* is specified but a *keyname* is not, the key |
| 699 | used will be the first key in the *keyring*. Note that the order of |
| 700 | keys in a dictionary is not defined, so applications should supply a |
| 701 | keyname when a ``dict`` keyring is used, unless they know the keyring |
| 702 | contains only one key. If a ``callable`` keyring is specified, the |
| 703 | callable will be called with the message and the keyname, and is |
| 704 | expected to return a key. |
| 705 | |
| 706 | *keyname*, a ``dns.name.Name``, ``str`` or ``None``, the name of |
| 707 | this TSIG key to use; defaults to ``None``. If *keyring* is a |
| 708 | ``dict``, the key must be defined in it. If *keyring* is a |
| 709 | ``dns.tsig.Key``, this is ignored. |
| 710 | |
| 711 | *fudge*, an ``int``, the TSIG time fudge. |
| 712 | |
| 713 | *original_id*, an ``int``, the TSIG original id. If ``None``, |
| 714 | the message's id is used. |
| 715 | |
| 716 | *tsig_error*, an ``int``, the TSIG error code. |
| 717 | |
| 718 | *other_data*, a ``bytes``, the TSIG other data. |
| 719 | |
| 720 | *algorithm*, a ``dns.name.Name`` or ``str``, the TSIG algorithm to use. This is |
| 721 | only used if *keyring* is a ``dict``, and the key entry is a ``bytes``. |
| 722 | """ |
| 723 | |
| 724 | if isinstance(keyring, dns.tsig.Key): |
| 725 | key = keyring |
| 726 | keyname = key.name |
| 727 | elif callable(keyring): |
| 728 | key = keyring(self, keyname) |
| 729 | else: |
| 730 | if isinstance(keyname, str): |
| 731 | keyname = dns.name.from_text(keyname) |
| 732 | if keyname is None: |
| 733 | keyname = next(iter(keyring)) |
| 734 | key = keyring[keyname] |
| 735 | if isinstance(key, bytes): |
| 736 | key = dns.tsig.Key(keyname, key, algorithm) |
| 737 | self.keyring = key |