0aadc6dd7b719539445e7a0a058b15dd9d982a9b |
|
21-Aug-2017 |
Michał Kępień <m <michal@isc.org> |
[v9_11] Prevent dnssec-settime from printing a bogus warning
4686. [bug] dnssec-settime -p could print a bogus warning about
key deletion scheduled before its inactivation when a
key had an inactivation date set but no deletion date
set. [RT #45807]
(cherry picked from commit 330365566dab00a1b659dd32e90698800f13af0f) |
f20ff8b74d21fa3e3f071544f6fd060d015cf27e |
|
21-Aug-2017 |
Michał Kępień <m <michal@isc.org> |
[v9_11] Fix calculation of dates for a successor key
4685. [bug] dnssec-settime incorrectly calculated publication and
activation dates for a successor key. [RT #45806]
(cherry picked from commit 5201b96d0343697ebcc73e6140db8d3729132c3b) |
3523e19da21545ade45394cb64d7462f20b77347 |
|
10-Aug-2017 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
7dbeb5e7f067585abfb12fac314a0d2a8f0dd040 |
|
09-Aug-2017 |
Evan Hunt <each@isc.org> |
[v9_11] silence gcc 7 warnings
4673. [port] Silence GCC 7 warnings. [RT #45592]
(cherry picked from commit cdacec1dcb93149b8efc7af38ec916adcdd706f3) |
0c27b3fe77ac1d5094ba3521e8142d9e7973133f |
|
27-Jun-2016 |
Mark Andrews <marka@isc.org> |
4401. [misc] Change LICENSE to MPL 2.0. |
f6096b958c8b58c4709860d7c4dcdde5deeacb7a |
|
28-Apr-2016 |
Evan Hunt <each@isc.org> |
[master] dnssec-keymgr
4349. [contrib] kasp2policy: A python script to create a DNSSEC
policy file from an OpenDNSSEC KASP XML file.
4348. [func] dnssec-keymgr: A new python-based DNSSEC key
management utility, which reads a policy definition
file and can create or update DNSSEC keys as needed
to ensure that a zone's keys match policy, roll over
correctly on schedule, etc. Thanks to Sebastian
Castro for assistance in development. [RT #39211] |
4df65ccfeca981cef1bf66706b8b505a8407f9d2 |
|
26-Jan-2016 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
f8432e3f249dbec36394539ca1f3cb25bf33abfe |
|
25-Jan-2016 |
Mark Andrews <marka@isc.org> |
4301. [bug] dnssec-settime -p [DP]sync was not working. [RT #41534] |
5b1c7ef35bb495820360182b5192689f33f1cc7d |
|
20-Nov-2015 |
Mark Andrews <marka@isc.org> |
4264. [bug] Check const of strchr/strrchr assignments match
argument's const status. [RT #41150] |
e939674d53a127ddeeaf4b41fd72933f0b493308 |
|
04-Nov-2015 |
Mark Andrews <marka@isc.org> |
4252. [func] Add support for automating the generation CDS and
CDNSKEY rrsets to named and dnssec-signzone.
[RT #40424] |
bc8f82492dfdfa8b6d58bca850fa328e176cfd91 |
|
14-Apr-2015 |
Mark Andrews <marka@isc.org> |
4098. [bug] Address use-after-free issue when using a
predecessor key with dnssec-settime. [RT #39272] |
af669cb4fd7ecfb67ed145b176e5e764b249573b |
|
27-Feb-2015 |
Mark Andrews <marka@isc.org> |
4074. [cleanup] Cleaned up more warnings from gcc -Wshadow. [RT #38708] |
c110d61b173a68420d19858abb80285be0dc1120 |
|
21-Jan-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
11463c0ac24692e229ec87f307f5e7df3c0a7e10 |
|
20-Jan-2015 |
Evan Hunt <each@isc.org> |
[master] clean up gcc -Wshadow warnings
4039. [cleanup] Cleaned up warnings from gcc -Wshadow. [RT #37381] |
42782931073786f98d3d0a617351db40066949a4 |
|
15-Jun-2014 |
Mukund Sivaraman <muks@isc.org> |
[10686] Add version printing option to various BIND utilites
Squashed commit of the following:
commit 95effe9b2582a7eb878ccb8cb9ef51dfc5bbfde7
Author: Evan Hunt <each@isc.org>
Date: Tue Jun 10 16:52:45 2014 -0700
[rt10686] move version() to dnssectool.c
commit df205b541d1572ea5306a5f671af8b54b9c5c770
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:38:31 2014 +0530
Rearrange order of cases
commit cfd30893f2540bf9d607e1fd37545ea7b441e0d0
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:38:08 2014 +0530
Add version printer to dnssec-verify
commit a625ea338c74ab5e21634033ef87f170ba37fdbe
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:32:19 2014 +0530
Add version printer to dnssec-signzone
commit d91e1c0f0697b3304ffa46fccc66af65591040d9
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:26:01 2014 +0530
Add version printer to dnssec-settime
commit 46fc8775da3e13725c31d13e090b406d69b8694f
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:25:48 2014 +0530
Fix docbook
commit 8123d2efbd84cdfcbc70403aa9bb27b96921bab2
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:20:17 2014 +0530
Add version printer to dnssec-revoke
commit d0916420317d3e8c69cf1b37d2209ea2d072b913
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:17:54 2014 +0530
Add version printer to dnssec-keygen
commit 93b0bd5ebc043298dc7d8f446ea543cb40eaecf8
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:14:11 2014 +0530
Add version printer to dnssec-keyfromlabel
commit 07001bcd9ae2d7b09dd9e243b0ab35307290d05d
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:13:39 2014 +0530
Update usage help output, docbook
commit 85cdd702f41c96fbc767fc689d1ed97fe1f3a926
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:07:18 2014 +0530
Add version printer to dnssec-importkey
commit 9274fc61e38205aad561edf445940b4e73d788dc
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:01:53 2014 +0530
Add version printer to dnssec-dsfromkey
commit bf4605ea2d7282e751fd73489627cc8a99f45a90
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 20:49:22 2014 +0530
Add -V to nsupdate usage output |
acbb301e648b82fcc38b876a44403cf0fe539cc9 |
|
13-Mar-2014 |
Evan Hunt <each@isc.org> |
[master] better error output when initializing pkcs11
3786. [func] Provide more detailed error codes when using
native PKCS#11. "pkcs11-tokens" now fails robustly
rather than asserting when run against an HSM with
an incomplete PCKS#11 API implementation. [RT #35479] |
a165a17a81ff3285f4f4d79785fafb465e626183 |
|
07-Feb-2014 |
Evan Hunt <each@isc.org> |
[master] dnssec-keygen fixes
3730. [cleanup] Added "never" as a synonym for "none" when
configuring key event dates in the dnssec tools.
[RT #35277]
3729. [bug] dnssec-kegeyn could set the publication date
incorrectly when only the activation date was
specified on the command line. [RT #35278] |
e20788e1216ed720aefa84f3295f7899d9f28c22 |
|
16-Jan-2014 |
Mark Andrews <marka@isc.org> |
update copyrights |
ba751492fcc4f161a18b983d4f018a1a52938cb9 |
|
15-Jan-2014 |
Evan Hunt <each@isc.org> |
[master] native PKCS#11 support
3705. [func] "configure --enable-native-pkcs11" enables BIND
to use the PKCS#11 API for all cryptographic
functions, so that it can drive a hardware service
module directly without the need to use a modified
OpenSSL as intermediary (so long as the HSM's vendor
provides a complete-enough implementation of the
PKCS#11 interface). This has been tested successfully
with the Thales nShield HSM and with SoftHSMv2 from
the OpenDNSSEC project. [RT #29031] |
0c91911b4d1e872b87eaf6431ed47fe24d18dd43 |
|
04-Sep-2013 |
Mark Andrews <marka@isc.org> |
3642. [func] Allow externally generated DNSKEY to be imported
into the DNSKEY management framework. A new tool
dnssec-importkey is used to this. [RT #34698] |
5ac5300fdf18c91405d1f83f521bf887ded495a3 |
|
18-Jan-2013 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
c8803902d6e740d1ed85e099835813466fa51391 |
|
17-Jan-2013 |
Curtis Blackburn <ckb@isc.org> |
[bug] Added checks in dnssec-keygen and dnssec-settime to check for
delete date < inactive date. [RT #31719] |
a1dbf90381912261b03e24a22d51923f3b8c1c49 |
|
28-Nov-2012 |
Evan Hunt <each@isc.org> |
[master] remove libgen.h from dnssec tools
we no longer use basename() or dirname() |
291a670d12e88142f36a7561312233d80217d7f4 |
|
06-Jul-2012 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
c514f38c801755da4dbe405139d8512873b332b0 |
|
05-Jul-2012 |
ckb <ckb@isc.org> |
Conflicts:
lib/dns/dst_parse.c
lib/isc/win32/file.c |
6b95b91c617a3e56aff611772744af32b5410e1f |
|
02-Jun-2011 |
Evan Hunt <each@isc.org> |
3122. [cleanup] dnssec-settime: corrected usage message. [RT #24664] |
10a759cee69dcc3ce3a4d65e6e263c66e7f60ee8 |
|
21-Mar-2011 |
Evan Hunt <each@isc.org> |
3086. [bug] Running dnssec-settime -f on an old-style key will
now force an update to the new key format even if no
other change has been specified, using "-P now -A now"
as default values. [RT #22474] |
207cee019eb5cbbe7c905f7c52f7b5d11f8c0305 |
|
18-Mar-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
61bcc232038f0a2cb77ed6269675fdc288f5ec98 |
|
17-Mar-2011 |
Evan Hunt <each@isc.org> |
3076. [func] New '-L' option in dnssec-keygen, dnsset-settime, and
dnssec-keyfromlabel sets the default TTL of the
key. When possible, automatic signing will use that
TTL when the key is published. [RT #23304] |
584ad7dedd0928a59830f82d82ae696bf6f4e705 |
|
19-Dec-2010 |
Evan Hunt <each@isc.org> |
2990. [bug] 'dnssec-settime -S' no longer tests prepublication
interval validity when the interval is set to 0.
[RT #22761] |
f428e385a4f7a42196b53de8e134909e8c488258 |
|
17-Aug-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
c6f4972c745f8903aba6dcca41f17a44c473db66 |
|
17-Aug-2010 |
Mark Andrews <marka@isc.org> |
2943. [func] Add support to load new keys into managed zones
without signing immediately with "rndc loadkeys".
Add support to link keys with "dnssec-keygen -S"
and "dnssec-settime -S". [RT #21351] |
dcfca6f18d5069155ae50025aaeead0cc8c04730 |
|
03-Feb-2010 |
Evan Hunt <each@isc.org> |
2847. [cleanup] Corrected usage message in dnssec-settime. [RT #20921] |
8ebf67b7f0aeea7ef8c6e034c57a1dc57a7b216a |
|
07-Jan-2010 |
Evan Hunt <each@isc.org> |
2833. [cleanup] Fix usage messages in dnssec-keygen and dnssec-settime.
[RT #20851] |
247f299fb05235185bfacb19262b8799cbb3e0e0 |
|
07-Jan-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
b1fbf2a4db3b65b9c624ed627d4b4a8cafc5246a |
|
06-Jan-2010 |
Evan Hunt <each@isc.org> |
fix spacing |
928e12ccdc36220075e01d7fa3b6fa79e9162385 |
|
19-Dec-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
9de98fbbbee124bbb8d609669cfaff17ec7a36e0 |
|
18-Dec-2009 |
Evan Hunt <each@isc.org> |
2809. [cleanup] Restored accidentally-deleted text in usage output
in dnssec-settime and dnssec-revoke [RT #20739] |
e3b59e4af757d4b26ecb96e65f9953488283c216 |
|
27-Oct-2009 |
Evan Hunt <each@isc.org> |
Minor cleanup in dnssec-* tools |
c02149960459e4406d9e50fb1867433e7f0e8f0d |
|
26-Oct-2009 |
Evan Hunt <each@isc.org> |
2731. [func] Additional work on change 2709. The key parser
will now ignore unrecognized fields when the
minor version number of the private key format
has been increased. It will reject any key with
the major version number increased. [RT #20310] |
77b8f88f144928eddcca144c348d6ef53e7d5c43 |
|
12-Oct-2009 |
Evan Hunt <each@isc.org> |
2712. [func] New 'auto-dnssec' zone option allows zone signing
to be fully automated in zones configured for
dynamic DNS. 'auto-dnssec allow;' permits a zone
to be signed by creating keys for it in the
key-directory and using 'rndc sign <zone>'.
'auto-dnssec maintain;' allows that too, plus it
also keeps the zone's DNSSEC keys up to date
according to their timing metadata. [RT #19943] |
315a1514a58dbb1ca563445313d67c1cf664d248 |
|
09-Oct-2009 |
Evan Hunt <each@isc.org> |
2709. [func] Added some data fields, currently unused, to the
private key file format, to allow implementation
of explicit key rollover in a future release
without impairing backward or forward compatibility.
[RT #20310] |
8b78c993cb475cc94e88560941b28c37684789d9 |
|
05-Oct-2009 |
Francis Dupont <fdupont@isc.org> |
explicit engine rt20230a |
debd489a44363870f96f75818e89ec27d3cab736 |
|
29-Sep-2009 |
Francis Dupont <fdupont@isc.org> |
noreturn RT #20257 |
53c22b8e0da67ca756ca309d5f84db9c189cd0a2 |
|
23-Sep-2009 |
Evan Hunt <each@isc.org> |
2685. [bug] Fixed dnssec-signzone -S handling of revoked keys.
Also, added warnings when revoking a ZSK, as this is
not defined by protocol (but is legal). [RT #19943] |
b843f577bbcd6660fbaa506d9e55b156c689a5a8 |
|
14-Sep-2009 |
Evan Hunt <each@isc.org> |
2677. [func] Changes to key metadata behavior:
- Keys without "publish" or "active" dates set will
no longer be used for smart signing. However,
those dates will be set to "now" by default when
a key is created; to generate a key but not use
it yet, use dnssec-keygen -G.
- New "inactive" date (dnssec-keygen/settime -I)
sets the time when a key is no longer used for
signing but is still published.
- The "unpublished" date (-U) is deprecated in
favor of "deleted" (-D).
[rt20247] |
8d0a1ede2fe6d7c101ba59223772780c8b5b201d |
|
04-Sep-2009 |
Evan Hunt <each@isc.org> |
RT #20213:
- correctly use -K option in dnssec-keygen
- fix an improper free() in dnssec-revoke
- fix grammar in dnssec-settime |
d7201de09b85929a86b157f4b2d91667c68c6b52 |
|
03-Sep-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
eab9975bcf5830a73f18ed8f320ae18ea32775ee |
|
02-Sep-2009 |
Evan Hunt <each@isc.org> |
2668. [func] Several improvements to dnssec-* tools, including:
- dnssec-keygen and dnssec-settime can now set key
metadata fields 0 (to unset a value, use "none")
- dnssec-revoke sets the revocation date in
addition to the revoke bit
- dnssec-settime can now print individual metadata
fields instead of always printing all of them,
and can print them in unix epoch time format for
use by scripts
[RT #19942] |
5ac9ef944830b43258a5055e03f78c2dfb57f14e |
|
29-Aug-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
747abb4993e03b8812514e4476bff67f5248c717 |
|
28-Aug-2009 |
Evan Hunt <each@isc.org> |
2658. [bug] dnssec-settime and dnssec-revoke didn't process
key file paths correctly. [RT #20078] |
2847ddeaf1f02535759c02f9b90207397f0daa34 |
|
21-Jul-2009 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
misc. bug fixes including null pointer dereference and memory leak.
[RT #19953]
I don't update CHANGES as this code has never been publicly released. |
f73695f9bde65a7d26ee2ac1d1d9e7101060fdc9 |
|
19-Jul-2009 |
Evan Hunt <each@isc.org> |
fix a merge error from rebasing dnssec-settime (an assignment was left in
place that was supposed to have been removed--this was already reviewed, I
just merged the fix wrong) |
2a3574f8d4cd7a72ccc51f47a55797d2f7fc1053 |
|
19-Jul-2009 |
Evan Hunt <each@isc.org> |
windows portability fix (review by mgraff) |
9edd523c2295757f1e1c5e93ea369cae892f0754 |
|
19-Jul-2009 |
Evan Hunt <each@isc.org> |
more win32 build fixes |
553ead32ff5b00284e574dcabc39115d4d74ec66 |
|
19-Jul-2009 |
Evan Hunt <each@isc.org> |
2636. [func] Simplify zone signing and key maintenance with the
dnssec-* tools. Major changes:
- all dnssec-* tools now take a -K option to
specify a directory in which key files will be
stored
- DNSSEC can now store metadata indicating when
they are scheduled to be published, acttivated,
revoked or removed; these values can be set by
dnssec-keygen or overwritten by the new
dnssec-settime command
- dnssec-signzone -S (for "smart") option reads key
metadata and uses it to determine automatically
which keys to publish to the zone, use for
signing, revoke, or remove from the zone
[RT #19816] |