bc6f4c1c4c1b739fd06d2de05b77b9d08c4d8a5a |
|
02-Aug-2017 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
78608b0a454246d0e1e0169f1d671b8427e48199 |
|
31-Jul-2017 |
Francis Dupont <fdupont@isc.org> |
Added Ed25519 support (#44696) |
83a28ca274521e15086fc39febde507bcc4e145e |
|
07-Dec-2016 |
Mark Andrews <marka@isc.org> |
4527. [doc] Support DocBook XSL Stylesheets v1.79.1. [RT #43831]
(cherry picked from commit 1b8ce3b3302f0afe682d04df8a1f20b4ac346fb2) |
704e6c8876907aac0bf7380effca8bca400d4acd |
|
21-Jul-2016 |
Mark Andrews <marka@isc.org> |
copyright
(cherry picked from commit 813e9f7ee291c611828041727c21a9f225fe1bcb) |
0c27b3fe77ac1d5094ba3521e8142d9e7973133f |
|
27-Jun-2016 |
Mark Andrews <marka@isc.org> |
4401. [misc] Change LICENSE to MPL 2.0. |
1c6d1ca3356928847d4ad068c4d346254c35337c |
|
02-Jun-2016 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
2a8aa1049204bc9829b25b9ccaa99d25e3ced8d2 |
|
01-Jun-2016 |
Francis Dupont <fdupont@isc.org> |
Merged rt42505 (misc DNSSEC bugs) |
e939674d53a127ddeeaf4b41fd72933f0b493308 |
|
04-Nov-2015 |
Mark Andrews <marka@isc.org> |
4252. [func] Add support for automating the generation CDS and
CDNSKEY rrsets to named and dnssec-signzone.
[RT #40424] |
30eec077db2bdcb6f2a0dc388a3cdde2ede75ec1 |
|
22-Oct-2015 |
Mark Andrews <marka@isc.org> |
cleanup trailing white space in SGML like files |
2eeb74d1cf5355dd98f6d507a10086e16bb08c4b |
|
06-Oct-2015 |
Tinderbox User <tbox@isc.org> |
regen master |
14a656f94b1fd0ababd84a772228dfa52276ba15 |
|
06-Oct-2015 |
Evan Hunt <each@isc.org> |
[master] upgrade doc toolchain
4237. [doc] Upgraded documentation toolchain to use DocBook 5
and dblatex. [RT #40766] |
a6ca100924894cdd8e2b791d75a8cef32b1fba1f |
|
14-Jan-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
03f979494f5c80e05a72f876914d9d44085fbd6a |
|
13-Jan-2015 |
Evan Hunt <each@isc.org> |
[master] document default DNSKEY TTL
- see RT #38268 |
edad003e630cf9a25db88d95247d10eb96117d66 |
|
16-Oct-2014 |
Jeremy C. Reed <jreed@isc.org> |
Remove the apostrophe 's from plural acronyms
This is to be consistent with our common usage of just using a
plural "s" without apostrophe.
This was brought up via discussion in ticket 37505.
I didn't have this reviewed. |
42782931073786f98d3d0a617351db40066949a4 |
|
15-Jun-2014 |
Mukund Sivaraman <muks@isc.org> |
[10686] Add version printing option to various BIND utilites
Squashed commit of the following:
commit 95effe9b2582a7eb878ccb8cb9ef51dfc5bbfde7
Author: Evan Hunt <each@isc.org>
Date: Tue Jun 10 16:52:45 2014 -0700
[rt10686] move version() to dnssectool.c
commit df205b541d1572ea5306a5f671af8b54b9c5c770
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:38:31 2014 +0530
Rearrange order of cases
commit cfd30893f2540bf9d607e1fd37545ea7b441e0d0
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:38:08 2014 +0530
Add version printer to dnssec-verify
commit a625ea338c74ab5e21634033ef87f170ba37fdbe
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:32:19 2014 +0530
Add version printer to dnssec-signzone
commit d91e1c0f0697b3304ffa46fccc66af65591040d9
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:26:01 2014 +0530
Add version printer to dnssec-settime
commit 46fc8775da3e13725c31d13e090b406d69b8694f
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:25:48 2014 +0530
Fix docbook
commit 8123d2efbd84cdfcbc70403aa9bb27b96921bab2
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:20:17 2014 +0530
Add version printer to dnssec-revoke
commit d0916420317d3e8c69cf1b37d2209ea2d072b913
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:17:54 2014 +0530
Add version printer to dnssec-keygen
commit 93b0bd5ebc043298dc7d8f446ea543cb40eaecf8
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:14:11 2014 +0530
Add version printer to dnssec-keyfromlabel
commit 07001bcd9ae2d7b09dd9e243b0ab35307290d05d
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:13:39 2014 +0530
Update usage help output, docbook
commit 85cdd702f41c96fbc767fc689d1ed97fe1f3a926
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:07:18 2014 +0530
Add version printer to dnssec-importkey
commit 9274fc61e38205aad561edf445940b4e73d788dc
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:01:53 2014 +0530
Add version printer to dnssec-dsfromkey
commit bf4605ea2d7282e751fd73489627cc8a99f45a90
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 20:49:22 2014 +0530
Add -V to nsupdate usage output |
1753d3c4d74241a847794f7e7cfd94cc79be6600 |
|
27-Feb-2014 |
Evan Hunt <each@isc.org> |
[master] correct dates in man pages |
a165a17a81ff3285f4f4d79785fafb465e626183 |
|
07-Feb-2014 |
Evan Hunt <each@isc.org> |
[master] dnssec-keygen fixes
3730. [cleanup] Added "never" as a synonym for "none" when
configuring key event dates in the dnssec tools.
[RT #35277]
3729. [bug] dnssec-kegeyn could set the publication date
incorrectly when only the activation date was
specified on the command line. [RT #35278] |
6ea2385360e9e2167e65f9286447da9eea189457 |
|
16-Jan-2014 |
Tinderbox User <tbox@isc.org> |
regen master |
ba751492fcc4f161a18b983d4f018a1a52938cb9 |
|
15-Jan-2014 |
Evan Hunt <each@isc.org> |
[master] native PKCS#11 support
3705. [func] "configure --enable-native-pkcs11" enables BIND
to use the PKCS#11 API for all cryptographic
functions, so that it can drive a hardware service
module directly without the need to use a modified
OpenSSL as intermediary (so long as the HSM's vendor
provides a complete-enough implementation of the
PKCS#11 interface). This has been tested successfully
with the Thales nShield HSM and with SoftHSMv2 from
the OpenDNSSEC project. [RT #29031] |
7865ea9545f28f12f046b32d24c989e8441b9812 |
|
14-Jun-2012 |
Mark Andrews <marka@isc.org> |
3339. [func] Allow the maximum supported rsa exponent size to be specified: "max-rsa-exponent-size <value>;" [RT #29228] |
99d8f5a70440ee8b63ab1745d713b96dde890546 |
|
03-May-2012 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
aaaf8d4f4873d21e55c3ffb4f656203d08339865 |
|
02-May-2012 |
Mark Andrews <marka@isc.org> |
3317. [func] Add ECDSA support (RFC 6605). [RT #21918] |
207cee019eb5cbbe7c905f7c52f7b5d11f8c0305 |
|
18-Mar-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
61bcc232038f0a2cb77ed6269675fdc288f5ec98 |
|
17-Mar-2011 |
Evan Hunt <each@isc.org> |
3076. [func] New '-L' option in dnssec-keygen, dnsset-settime, and
dnssec-keyfromlabel sets the default TTL of the
key. When possible, automatic signing will use that
TTL when the key is published. [RT #23304] |
37dee1ff94960a61243f611c0f87f8c316815c53 |
|
23-Dec-2010 |
Mark Andrews <marka@isc.org> |
2999. [func] Add GOST support (RFC 5933). [RT #20639] |
f428e385a4f7a42196b53de8e134909e8c488258 |
|
17-Aug-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
c6f4972c745f8903aba6dcca41f17a44c473db66 |
|
17-Aug-2010 |
Mark Andrews <marka@isc.org> |
2943. [func] Add support to load new keys into managed zones
without signing immediately with "rndc loadkeys".
Add support to link keys with "dnssec-keygen -S"
and "dnssec-settime -S". [RT #21351] |
f80b665135127a12ca503c8830aa465aa1ddd17d |
|
03-Nov-2009 |
Evan Hunt <each@isc.org> |
fix typo: s/pcks11/pkcs11/ |
c6d2578fd67bc1a427d13fd0699b25a187feec8a |
|
28-Oct-2009 |
Mark Andrews <marka@isc.org> |
2741. [func] Allow the dnssec-keygen progress messages to be
suppressed (dnssec-keygen -q). Automatically
suppress the progress messages when stdin is not
a tty. [RT #20474] |
cc6cddfd94e8f0c58c290317b0853dac30b1b895 |
|
22-Oct-2009 |
Evan Hunt <each@isc.org> |
2726. [func] Added support for SHA-2 DNSSEC algorithms,
RSASHA256 and RSASHA512. [RT #20023] |
eec29cfd40361662b25bad50e1b94f7738a8fea0 |
|
16-Oct-2009 |
Jeremy Reed <jreed@isc.org> |
Fix typo as reported by SUN Guonian <sun@cnnic.cn>.
This was seen in 9.7.0a3.
No CHANGES entry as is too minor. |
8b78c993cb475cc94e88560941b28c37684789d9 |
|
05-Oct-2009 |
Francis Dupont <fdupont@isc.org> |
explicit engine rt20230a |
b843f577bbcd6660fbaa506d9e55b156c689a5a8 |
|
14-Sep-2009 |
Evan Hunt <each@isc.org> |
2677. [func] Changes to key metadata behavior:
- Keys without "publish" or "active" dates set will
no longer be used for smart signing. However,
those dates will be set to "now" by default when
a key is created; to generate a key but not use
it yet, use dnssec-keygen -G.
- New "inactive" date (dnssec-keygen/settime -I)
sets the time when a key is no longer used for
signing but is still published.
- The "unpublished" date (-U) is deprecated in
favor of "deleted" (-D).
[rt20247] |
eab9975bcf5830a73f18ed8f320ae18ea32775ee |
|
02-Sep-2009 |
Evan Hunt <each@isc.org> |
2668. [func] Several improvements to dnssec-* tools, including:
- dnssec-keygen and dnssec-settime can now set key
metadata fields 0 (to unset a value, use "none")
- dnssec-revoke sets the revocation date in
addition to the revoke bit
- dnssec-settime can now print individual metadata
fields instead of always printing all of them,
and can print them in unix epoch time format for
use by scripts
[RT #19942] |
41eeb37b516d1bac073781b6ec50a39a669987df |
|
28-Aug-2009 |
Evan Hunt <each@isc.org> |
2659. [doc] Clarify dnssec-keygen doc: key name must match zone
name for DNSSEC keys. [RT #19938] |
553ead32ff5b00284e574dcabc39115d4d74ec66 |
|
19-Jul-2009 |
Evan Hunt <each@isc.org> |
2636. [func] Simplify zone signing and key maintenance with the
dnssec-* tools. Major changes:
- all dnssec-* tools now take a -K option to
specify a directory in which key files will be
stored
- DNSSEC can now store metadata indicating when
they are scheduled to be published, acttivated,
revoked or removed; these values can be set by
dnssec-keygen or overwritten by the new
dnssec-settime command
- dnssec-signzone -S (for "smart") option reads key
metadata and uses it to determine automatically
which keys to publish to the zone, use for
signing, revoke, or remove from the zone
[RT #19816] |
dde8659175c5798267fb0fdefd7576e4efe271b3 |
|
18-Jun-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
b272d38cc5d24f64c0647a9afb340c21c4b9aaf7 |
|
17-Jun-2009 |
Evan Hunt <each@isc.org> |
2612. [func] Add default values for the arguments to
dnssec-keygen. Without arguments, it will now
generate a 1024-bit RSASHA1 zone-signing key,
or with the -f KSK option, a 2048-bit RSASHA1
key-signing key. [RT #19300]
2611. [func] Add -l option to dnssec-dsfromkey to generate
DLV records instead of DS records. [RT #19300] |
733531b6d5c705dad87e85a2bcc557f68f902bb3 |
|
14-Oct-2008 |
Jeremy Reed <jreed@isc.org> |
Change SEE ALSO reference from obsolete 2535 to 4033.
(Also order these numerically.) |
3398334b3acda24b086957286288ca9852662b12 |
|
25-Sep-2008 |
Automatic Updater <source@isc.org> |
update copyright notice |
6098d364b690cb9dabf96e9664c4689c8559bd2e |
|
24-Sep-2008 |
Mark Andrews <marka@isc.org> |
2448. [func] Add NSEC3 support. [RT #15452] |
ec5347e2c775f027573ce5648b910361aa926c01 |
|
19-Jun-2007 |
Automatic Updater <source@isc.org> |
update copyright notice |
bf45f72ed319628eebce60c368177320943d001f |
|
18-Jun-2007 |
Mark Andrews <marka@isc.org> |
2195. [func] dnssec-keygen now defaults to nametype "ZONE"
when generating DNSKEYs. [RT #16954] |
561a29af8c54a216e7d30b5b4f6e0d21661654ec |
|
09-May-2007 |
Mark Andrews <marka@isc.org> |
minor man page updated from Jeremy [RT #16859] |
c1a883f2e04d94e99c433b1f6cfd0c0338f4ed85 |
|
30-Jan-2007 |
Mark Andrews <marka@isc.org> |
update copyright notice |
5cd4555ad444fd391002ae32450572054369fd42 |
|
29-Jan-2007 |
Rob Austein <sra@isc.org> |
2128. [doc] xsltproc --nonet, update DTD versions. [RT #16635] |
79399226b7bd15afb3e97fa9a5ea678359968997 |
|
30-Aug-2005 |
Mark Andrews <marka@isc.org> |
remove make-keyset reference |
b5ad6dfea4cc3e7d1d322ac99f1e5a31096837c4 |
|
19-Jul-2005 |
Mark Andrews <marka@isc.org> |
1903. [doc] Review ARM for BIND 9.4. |
f5d30e2864e048a42c4dc1134993ae7efdb5d6c3 |
|
13-May-2005 |
Mark Andrews <marka@isc.org> |
update copyright notice |
268a4475065fe6a8cd7cc707820982cf5e98f430 |
|
11-May-2005 |
Rob Austein <sra@isc.org> |
1856. [doc] Switch Docbook toolchain from DSSSL to XSL. |
c651f15b30f1dae5cc2f00878fb5da5b3a35a468 |
|
07-Apr-2005 |
Mark Andrews <marka@isc.org> |
1849. [doc] All forms of the man pages (docbook, man, html) should
have consistant copyright dates. |
cc3aafe737334d444781f8a34ffaf459e075bb9a |
|
11-Jun-2004 |
Mark Andrews <marka@isc.org> |
1659. [cleanup] Cleanup some messages that were referring to KEY vs
DNSKEY, NXT vs NSEC and SIG vs RRSIG.
1658. [func] Update dnssec-keygen to default to KEY for HMAC-MD5
and DH. Tighten which options apply to KEY and
DNSKEY records. |
17cb8353e999e3294e6619613f401af3f7b1540c |
|
03-Jun-2004 |
Mark Andrews <marka@isc.org> |
update corpauthor |
dafcb997e390efa4423883dafd100c975c4095d6 |
|
05-Mar-2004 |
Mark Andrews <marka@isc.org> |
update copyright notice |
b0c15bd9792112fb47f6d956e580e4369e92f4e7 |
|
18-Jan-2003 |
Mark Andrews <marka@isc.org> |
1415. [func] DS TTL now derived from NS ttl. NXT TTL now derived
from SOA MINIMUM.
1414. [func] Support for KSK flag. |
a7038d1a0513c8e804937ebc95fc9cb3a46c04f5 |
|
20-Feb-2002 |
Mark Andrews <marka@isc.org> |
copyrights |
2ca556300b09a94f0937b303386d29b95ef057dd |
|
21-Jan-2002 |
Brian Wellington <source@isc.org> |
1180. [func] dnssec-keygen should always generate keys with
protocol 3 (DNSSEC), since it's less confusing
that way. |
d4ef65050feac78554addf6e16a06c6e2e0bd331 |
|
10-Apr-2001 |
Brian Wellington <source@isc.org> |
copyright updates
(note - this doesn't touch lib/bind at all. Mark, whenever you're done with
lib/bind, make sure to do the copyright magic) |
8ffa8320abcc17ae593af566cb946a58fe293860 |
|
31-Mar-2001 |
Brian Wellington <source@isc.org> |
minor changes |
0b062f4990db5cc6db2fe3398926f71b92a67407 |
|
31-Mar-2001 |
Brian Wellington <source@isc.org> |
converted man pages to docbook and cleaned them up. |