OpenBSD Handbook

OpenBSD 7.9 release · amd64 · Generated 2026-09-09

walker-3.8

retrieve DNS zone via DNSSEC NXT/NSEC traversal

Back to search · Project homepage

Description

This is a proof-of-concept of a utility to download DNS zone contents even when AXFR is disabled on the server, assuming DNSSEC is used. Optionally it can also verify all digital signature RRs within a zone against the zone key. If you do not know what DNSSEC is, please refer to: RFC 2535, RFC 4033, RFC 4034, RFC 4035, "dnssec.net" (lots of DNSSEC information). The tool supports both the old DNSSEC according to RFC 2535 (i.e., KEY/SIG) and the latest DNSSEC version according to RFC 4033 (i.e., DNSKEY/RRSIG).

Package information

Ports path
net/walker
Package architecture
*
Maintainer
The OpenBSD ports mailing-list <ports@openbsd.org>
Categories
net
Available flavors
None listed

These are ports metadata. Binary availability depends on the release, architecture and mirror. Build and test dependencies are not an installation checklist.

Direct dependencies

Runtime

Installing and updating packages · Package details as JSON