5a0fe4f4834430539ba734f257064742916e3aa4 |
|
12-Apr-2017 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
672c06580e47fed48e3e87977a2362da13dce13a |
|
11-Apr-2017 |
Evan Hunt <each@isc.org> |
[v9_11] correct -M in synopsis
(cherry picked from commit a477a025d57379e64f48854b4c8cdf7442d88e80) |
83a28ca274521e15086fc39febde507bcc4e145e |
|
07-Dec-2016 |
Mark Andrews <marka@isc.org> |
4527. [doc] Support DocBook XSL Stylesheets v1.79.1. [RT #43831]
(cherry picked from commit 1b8ce3b3302f0afe682d04df8a1f20b4ac346fb2) |
704e6c8876907aac0bf7380effca8bca400d4acd |
|
21-Jul-2016 |
Mark Andrews <marka@isc.org> |
copyright
(cherry picked from commit 813e9f7ee291c611828041727c21a9f225fe1bcb) |
0c27b3fe77ac1d5094ba3521e8142d9e7973133f |
|
27-Jun-2016 |
Mark Andrews <marka@isc.org> |
4401. [misc] Change LICENSE to MPL 2.0. |
30eec077db2bdcb6f2a0dc388a3cdde2ede75ec1 |
|
22-Oct-2015 |
Mark Andrews <marka@isc.org> |
cleanup trailing white space in SGML like files |
19c7b1a0293498a3e36692c59646ed6e15ffc8d0 |
|
07-Oct-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
2eeb74d1cf5355dd98f6d507a10086e16bb08c4b |
|
06-Oct-2015 |
Tinderbox User <tbox@isc.org> |
regen master |
14a656f94b1fd0ababd84a772228dfa52276ba15 |
|
06-Oct-2015 |
Evan Hunt <each@isc.org> |
[master] upgrade doc toolchain
4237. [doc] Upgraded documentation toolchain to use DocBook 5
and dblatex. [RT #40766] |
f3150c99d7a3389eba632844c59b8563fc917e3e |
|
22-Aug-2014 |
Jeremy C. Reed <jreed@isc.org> |
add missing -Q from synopsis |
42782931073786f98d3d0a617351db40066949a4 |
|
15-Jun-2014 |
Mukund Sivaraman <muks@isc.org> |
[10686] Add version printing option to various BIND utilites
Squashed commit of the following:
commit 95effe9b2582a7eb878ccb8cb9ef51dfc5bbfde7
Author: Evan Hunt <each@isc.org>
Date: Tue Jun 10 16:52:45 2014 -0700
[rt10686] move version() to dnssectool.c
commit df205b541d1572ea5306a5f671af8b54b9c5c770
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:38:31 2014 +0530
Rearrange order of cases
commit cfd30893f2540bf9d607e1fd37545ea7b441e0d0
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:38:08 2014 +0530
Add version printer to dnssec-verify
commit a625ea338c74ab5e21634033ef87f170ba37fdbe
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:32:19 2014 +0530
Add version printer to dnssec-signzone
commit d91e1c0f0697b3304ffa46fccc66af65591040d9
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:26:01 2014 +0530
Add version printer to dnssec-settime
commit 46fc8775da3e13725c31d13e090b406d69b8694f
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:25:48 2014 +0530
Fix docbook
commit 8123d2efbd84cdfcbc70403aa9bb27b96921bab2
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:20:17 2014 +0530
Add version printer to dnssec-revoke
commit d0916420317d3e8c69cf1b37d2209ea2d072b913
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:17:54 2014 +0530
Add version printer to dnssec-keygen
commit 93b0bd5ebc043298dc7d8f446ea543cb40eaecf8
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:14:11 2014 +0530
Add version printer to dnssec-keyfromlabel
commit 07001bcd9ae2d7b09dd9e243b0ab35307290d05d
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:13:39 2014 +0530
Update usage help output, docbook
commit 85cdd702f41c96fbc767fc689d1ed97fe1f3a926
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:07:18 2014 +0530
Add version printer to dnssec-importkey
commit 9274fc61e38205aad561edf445940b4e73d788dc
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 21:01:53 2014 +0530
Add version printer to dnssec-dsfromkey
commit bf4605ea2d7282e751fd73489627cc8a99f45a90
Author: Mukund Sivaraman <muks@isc.org>
Date: Tue Jun 10 20:49:22 2014 +0530
Add -V to nsupdate usage output |
b4ba66ba1e36a6d8236d20be55273ce663819d69 |
|
30-Apr-2014 |
Evan Hunt <each@isc.org> |
[master] "dnssec-signzone -N date"
3827. [func] "dnssec-signzone -N date" updates serial number
to the current date in YYYYMMDDNN format.
[RT #35800] |
1753d3c4d74241a847794f7e7cfd94cc79be6600 |
|
27-Feb-2014 |
Evan Hunt <each@isc.org> |
[master] correct dates in man pages |
35f6a21f5f8114542c050bfcb484b39ce513d4bd |
|
19-Feb-2014 |
Evan Hunt <each@isc.org> |
[master] max-zone-ttl
3746. [func] New "max-zone-ttl" option enforces maximum
TTLs for zones. If loading a zone containing a
higher TTL, the load fails. DDNS updates with
higher TTLs are accepted but the TTL is truncated.
(Note: Currently supported for master zones only;
inline-signing slaves will be added.) [RT #38405] |
6ea2385360e9e2167e65f9286447da9eea189457 |
|
16-Jan-2014 |
Tinderbox User <tbox@isc.org> |
regen master |
ba751492fcc4f161a18b983d4f018a1a52938cb9 |
|
15-Jan-2014 |
Evan Hunt <each@isc.org> |
[master] native PKCS#11 support
3705. [func] "configure --enable-native-pkcs11" enables BIND
to use the PKCS#11 API for all cryptographic
functions, so that it can drive a hardware service
module directly without the need to use a modified
OpenSSL as intermediary (so long as the HSM's vendor
provides a complete-enough implementation of the
PKCS#11 interface). This has been tested successfully
with the Thales nShield HSM and with SoftHSMv2 from
the OpenDNSSEC project. [RT #29031] |
0bbe3273a224aa07b6af4165a26fd26d6f30c0ad |
|
11-Dec-2013 |
Evan Hunt <each@isc.org> |
[master] dnssec-signzone -Q
3686. [func] "dnssec-signzone -Q" drops signatures from keys
that are still published but no longer active.
[RT #34990] |
cbadc440b92cd01d298181bdbdb422da1b764377 |
|
13-Oct-2013 |
Mark Andrews <marka@isc.org> |
typos |
43b94483957d3168796a816ed86cf097518817dc |
|
25-Jan-2013 |
Tinderbox User <tbox@isc.org> |
regen master |
c9611b45736af157e2993c6ef852e55e8e24ca83 |
|
24-Jan-2013 |
Evan Hunt <each@isc.org> |
[master] change "fast" to "map"
3475. [cleanup] Changed name of 'map' zone file format (previously
'fast'). [RT #32458] |
3b398443f0dca316ba7a6e057ba2d1b8ab4ddf70 |
|
22-Jun-2012 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
6844e3f010440a9f3eb200b3c2123a19e58a64dc |
|
22-Jun-2012 |
Evan Hunt <each@isc.org> |
Add documentation for 'fast' format |
f30785f506a522ed6a5e394af2bb13b6f883927e |
|
22-Dec-2011 |
Evan Hunt <each@isc.org> |
3252. [bug] When master zones using inline-signing were
updated while the server was offline, the source
zone could fall out of sync with the signed
copy. They can now resynchronize. [RT #26676] |
b4d8192d210290112e07b0e22b491c45c50ba696 |
|
08-Dec-2011 |
Evan Hunt <each@isc.org> |
3241. [func] Extended the header of raw-format master files to
include the serial number of the zone from which
they were generated, if different (as in the case
of inline-signing zones). This is to be used in
inline-signing zones, to track changes between the
unsigned and signed versions of the zone, which may
have different serial numbers.
(Note: raw zonefiles generated by this version of
BIND are no longer compatble with prior versions.
To generate a backward-compatible raw zonefile
using dnssec-signzone or named-compilezone, specify
output format "raw=0" instead of simply "raw".)
[RT #26587] |
d9eebc08497af272b2d44c07f4eb85153dec4253 |
|
08-Nov-2011 |
Evan Hunt <each@isc.org> |
3211. [func] dnssec-signzone: "-f -" prints to stdout; "-O full"
option prints in single-line-per-record format.
[RT #20287] |
35f1a4fc935ad0f05a23d5a6cfba17f5913fdcc1 |
|
21-Mar-2011 |
Evan Hunt <each@isc.org> |
3085. [func] New '-R' option in dnssec-signzone forces removal
of signatures which have not yet expired but
were generated by a key that no longer exists.
[RT #22471] |
61bcc232038f0a2cb77ed6269675fdc288f5ec98 |
|
17-Mar-2011 |
Evan Hunt <each@isc.org> |
3076. [func] New '-L' option in dnssec-keygen, dnsset-settime, and
dnssec-keyfromlabel sets the default TTL of the
key. When possible, automatic signing will use that
TTL when the key is published. [RT #23304] |
0e27506ce3135f9bd49e12564ad0e15256135118 |
|
06-Mar-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
eff7f78bc65f30efd87a398e66084ddab72799d3 |
|
05-Mar-2011 |
Mark Andrews <marka@isc.org> |
3061. [func] New option "dnssec-signzone -D", only write out
generated DNSSEC records. [RT #22896] |
61271cdee65f3313e98f382b07e6674861d9020a |
|
04-Mar-2011 |
Evan Hunt <each@isc.org> |
3060. [func] New option "dnssec-signzone -X <date>" allows
specification of a separate expiration date
for DNSKEY RRSIGs and other RRSIGs. [RT #22141] |
8e4f3f1cbceef520ba889270c993de0ac376a2a7 |
|
04-Dec-2009 |
Evan Hunt <each@isc.org> |
2799. [cleanup] Changed the "secure-to-insecure" option to
"dnssec-secure-to-insecure", and "dnskey-ksk-only"
to "dnssec-dnskey-kskonly", for clarity. [RT #20586] |
f80b665135127a12ca503c8830aa465aa1ddd17d |
|
03-Nov-2009 |
Evan Hunt <each@isc.org> |
fix typo: s/pcks11/pkcs11/ |
c00929ed9f5234a0f2d79bd338fa931de85f4bb2 |
|
13-Oct-2009 |
Evan Hunt <each@isc.org> |
additional doc improvement |
77b8f88f144928eddcca144c348d6ef53e7d5c43 |
|
12-Oct-2009 |
Evan Hunt <each@isc.org> |
2712. [func] New 'auto-dnssec' zone option allows zone signing
to be fully automated in zones configured for
dynamic DNS. 'auto-dnssec allow;' permits a zone
to be signed by creating keys for it in the
key-directory and using 'rndc sign <zone>'.
'auto-dnssec maintain;' allows that too, plus it
also keeps the zone's DNSSEC keys up to date
according to their timing metadata. [RT #19943] |
3727725bb7d63605b68a644060857013d563b67f |
|
10-Oct-2009 |
Evan Hunt <each@isc.org> |
2710. [func] New 'dnssec-signzone -x' flag and 'dnskey-ksk-only'
zone option cause a zone to be signed with only KSKs
signing the DNSKEY RRset, not ZSKs. This reduces
the size of a DNSKEY answer. [RT #20340] |
8b78c993cb475cc94e88560941b28c37684789d9 |
|
05-Oct-2009 |
Francis Dupont <fdupont@isc.org> |
explicit engine rt20230a |
a93a66f61872a92ef4a272ca998aaff954ab4fed |
|
30-Sep-2009 |
Evan Hunt <each@isc.org> |
2794. [bug] Reduce default NSEC3 iterations from 100 to 10.
[RT #19970] |
fb596cc9af28ab5bf71c6796ebd1809654307a08 |
|
25-Sep-2009 |
Evan Hunt <each@isc.org> |
2691. [func] dnssec-signzone: retain the existing NSEC or NSEC3
chain when re-signing a previously-signed zone.
Use -u to modify NSEC3 parameters or switch
between NSEC and NSEC3. [RT #20304] |
eab9975bcf5830a73f18ed8f320ae18ea32775ee |
|
02-Sep-2009 |
Evan Hunt <each@isc.org> |
2668. [func] Several improvements to dnssec-* tools, including:
- dnssec-keygen and dnssec-settime can now set key
metadata fields 0 (to unset a value, use "none")
- dnssec-revoke sets the revocation date in
addition to the revoke bit
- dnssec-settime can now print individual metadata
fields instead of always printing all of them,
and can print them in unix epoch time format for
use by scripts
[RT #19942] |
553ead32ff5b00284e574dcabc39115d4d74ec66 |
|
19-Jul-2009 |
Evan Hunt <each@isc.org> |
2636. [func] Simplify zone signing and key maintenance with the
dnssec-* tools. Major changes:
- all dnssec-* tools now take a -K option to
specify a directory in which key files will be
stored
- DNSSEC can now store metadata indicating when
they are scheduled to be published, acttivated,
revoked or removed; these values can be set by
dnssec-keygen or overwritten by the new
dnssec-settime command
- dnssec-signzone -S (for "smart") option reads key
metadata and uses it to determine automatically
which keys to publish to the zone, use for
signing, revoke, or remove from the zone
[RT #19816] |
6a550cb83cc2196f8af0592a258f75985cdcb5eb |
|
05-Jun-2009 |
Jeremy Reed <jreed@isc.org> |
Please bump date on manpage. So we know we aren't using 2000 docs.
For -P: clean up sentence and clarify that the option skips the tests.
(This is for RT19653. No CHANGES entry added for this minor fix.) |
39844d471080b2de4f8bb9d81f7e136ef80f0ae2 |
|
04-Jun-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
2534a73a5914470f7ffe00663b6bbaff5e411e57 |
|
04-Jun-2009 |
Mark Andrews <marka@isc.org> |
2608. [func] Perform post signing verification checks in
dnssec-signzone. These can be disabled with -P.
The post sign verification test ensures that for each
algorithm in use there is at least one non revoked
self signed KSK key. That all revoked KSK keys are
self signed. That all records in the zone are signed
by the algorithm. [RT #19653] |
e1648063291cb3237f91d0e168fb666f73a6994f |
|
14-Oct-2008 |
Jeremy Reed <jreed@isc.org> |
Change the SEE ALSO from obsolete 2535 to 4033. |
3398334b3acda24b086957286288ca9852662b12 |
|
25-Sep-2008 |
Automatic Updater <source@isc.org> |
update copyright notice |
6e2871232f7ede047799480370aff444be1f5a13 |
|
24-Sep-2008 |
Automatic Updater <source@isc.org> |
update copyright notice |
6098d364b690cb9dabf96e9664c4689c8559bd2e |
|
24-Sep-2008 |
Mark Andrews <marka@isc.org> |
2448. [func] Add NSEC3 support. [RT #15452] |
ec5347e2c775f027573ce5648b910361aa926c01 |
|
19-Jun-2007 |
Automatic Updater <source@isc.org> |
update copyright notice |
561a29af8c54a216e7d30b5b4f6e0d21661654ec |
|
09-May-2007 |
Mark Andrews <marka@isc.org> |
minor man page updated from Jeremy [RT #16859] |
c1a883f2e04d94e99c433b1f6cfd0c0338f4ed85 |
|
30-Jan-2007 |
Mark Andrews <marka@isc.org> |
update copyright notice |
5cd4555ad444fd391002ae32450572054369fd42 |
|
29-Jan-2007 |
Rob Austein <sra@isc.org> |
2128. [doc] xsltproc --nonet, update DTD versions. [RT #16635] |
170938fdfc065eb9629b1dc2793f883e2d6cc565 |
|
16-Apr-2006 |
Mark Andrews <marka@isc.org> |
tag mis-match |
4b3f3cc67135e676a9b3b688685fb59e3494b0e6 |
|
15-Apr-2006 |
Mark Andrews <marka@isc.org> |
update copyright notice |
6ed53e5949d9fcd9715b440015b56e5a896d63df |
|
13-Apr-2006 |
David Hankins <dhankins@isc.org> |
2011. [func] dnssec-signzone can now update the SOA record of
the signed zone, either as an increment or as the
system time(). [RT #15633] |
b5ad6dfea4cc3e7d1d322ac99f1e5a31096837c4 |
|
19-Jul-2005 |
Mark Andrews <marka@isc.org> |
1903. [doc] Review ARM for BIND 9.4. |
e174044290953a2499f574e35cc9c22ba126a303 |
|
28-Jun-2005 |
Mark Andrews <marka@isc.org> |
1817. [func] Add support for additional zone file formats for
improving loading performance. The masterfile-format
option in named.conf can be used to specify a
non-default format. A separate command
named-compilezone was provided to generate zone files
in the new format. Additionally, the -I and -O options
for dnssec-signzone specify the input and output
formats. |
74b0c89c0c6bded3200fef99b7a5a838f84f763e |
|
24-Jun-2005 |
Mark Andrews <marka@isc.org> |
remove garbage line |
f5d30e2864e048a42c4dc1134993ae7efdb5d6c3 |
|
13-May-2005 |
Mark Andrews <marka@isc.org> |
update copyright notice |
268a4475065fe6a8cd7cc707820982cf5e98f430 |
|
11-May-2005 |
Rob Austein <sra@isc.org> |
1856. [doc] Switch Docbook toolchain from DSSSL to XSL. |
c651f15b30f1dae5cc2f00878fb5da5b3a35a468 |
|
07-Apr-2005 |
Mark Andrews <marka@isc.org> |
1849. [doc] All forms of the man pages (docbook, man, html) should
have consistant copyright dates. |
fec3621e807f9367a76771ae74ea0ce4133764c4 |
|
24-Mar-2005 |
Mark Andrews <marka@isc.org> |
update copyright notice |
6e8a8077faf96d8da0b6cf738913f5f1f86e4008 |
|
22-Mar-2005 |
Mark Andrews <marka@isc.org> |
1840. [func] dnssec-signzone can now randomize signature endtimes
(dnssec-signzone -j jitter). [RT #13609] |
cc3aafe737334d444781f8a34ffaf459e075bb9a |
|
11-Jun-2004 |
Mark Andrews <marka@isc.org> |
1659. [cleanup] Cleanup some messages that were referring to KEY vs
DNSKEY, NXT vs NSEC and SIG vs RRSIG.
1658. [func] Update dnssec-keygen to default to KEY for HMAC-MD5
and DH. Tighten which options apply to KEY and
DNSKEY records. |
17cb8353e999e3294e6619613f401af3f7b1540c |
|
03-Jun-2004 |
Mark Andrews <marka@isc.org> |
update corpauthor |
50105afc551903541608b11851d73278b23579a3 |
|
10-Mar-2004 |
Mark Andrews <marka@isc.org> |
1589. [func] DNSSEC lookaside validation.
enable-dnssec -> dnssec-enable |
dafcb997e390efa4423883dafd100c975c4095d6 |
|
05-Mar-2004 |
Mark Andrews <marka@isc.org> |
update copyright notice |
0f98d5c83ea5e2de40e1f9bbfd0aa70436f4bd6e |
|
02-Nov-2003 |
Mark Andrews <marka@isc.org> |
repeated words |
93d6dfaf66258337985427c86181f01fc51f0bb4 |
|
30-Sep-2003 |
Mark Andrews <marka@isc.org> |
1516. [func] Roll the DNSSEC types to RRSIG, NSEC and DNSKEY. |
b587e1d83f007ce68a9ae93097c461d8eb7aa373 |
|
07-Feb-2003 |
Mark Andrews <marka@isc.org> |
spelling |
b0c15bd9792112fb47f6d956e580e4369e92f4e7 |
|
18-Jan-2003 |
Mark Andrews <marka@isc.org> |
1415. [func] DS TTL now derived from NS ttl. NXT TTL now derived
from SOA MINIMUM.
1414. [func] Support for KSK flag. |
bf7f253e306d0ced8ae24d7a0598773950da11f4 |
|
18-Jan-2003 |
Mark Andrews <marka@isc.org> |
1413. [func] Explictly request the (re-)generation of DS records from
keysets (dnssec-signzone -g).
developer: marka
reviewer: explorer |
99776003811a413457a2c35a808ad860df877d24 |
|
04-Nov-2002 |
Mark Andrews <marka@isc.org> |
1396. [func] dnssec-signzone: adjust the default signing time by
1 hour to allow for clock skew. |
d4ef65050feac78554addf6e16a06c6e2e0bd331 |
|
10-Apr-2001 |
Brian Wellington <source@isc.org> |
copyright updates
(note - this doesn't touch lib/bind at all. Mark, whenever you're done with
lib/bind, make sure to do the copyright magic) |
0b062f4990db5cc6db2fe3398926f71b92a67407 |
|
31-Mar-2001 |
Brian Wellington <source@isc.org> |
converted man pages to docbook and cleaned them up. |