0c27b3fe77ac1d5094ba3521e8142d9e7973133f |
|
27-Jun-2016 |
Mark Andrews <marka@isc.org> |
4401. [misc] Change LICENSE to MPL 2.0. |
3cd204c4a46f21bf2a38f35e79af45ac595be943 |
|
15-Apr-2016 |
Evan Hunt <each@isc.org> |
[master] fixed revoked key regression
4436. [bug] Fixed a regression introduced in change #4337 which
caused signed domains with revoked KSKs to fail
validation. [RT #42147] |
4a7004f3cec6958b8b20bccf07b9f6a44f0fd590 |
|
11-Mar-2016 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
7c525954642f8fb3698b555115edb09fe3bd3354 |
|
10-Mar-2016 |
Mark Andrews <marka@isc.org> |
4331. [func] When loading managed signed zones detect if the
RRSIG's inception time is in the future and regenerate
the RRSIG immediately. [RT #41808] |
a5c7cfbac4e401c41741c123347739ab87c80a52 |
|
30-Oct-2014 |
Mark Andrews <marka@isc.org> |
3990. [testing] Add tests for unknown DNSSEC algorithm handling.
[RT #37541] |
c83b91fb6345464807161cc36c5d9046a15d5866 |
|
30-Sep-2014 |
Mark Andrews <marka@isc.org> |
3960. [bug] 'dig +sigchase' could loop forever. [RT #37220] |
5a31767b0982ba0fd5211d51fd002730c929656a |
|
20-Jun-2014 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
b8a9632333a92d73a503afe1aaa7990016c8bee9 |
|
19-Jun-2014 |
Evan Hunt <each@isc.org> |
[master] complete NTA work
3882. [func] By default, negative trust anchors will be tested
periodically to see whether data below them can be
validated, and if so, they will be allowed to
expire early. The "rndc nta -force" option
overrides this behvaior. The default NTA lifetime
and the recheck frequency can be configured by the
"nta-lifetime" and "nta-recheck" options. [RT #36146] |
2c089bf6d24936de631a57b4958ba6b8b5e3b23d |
|
16-Sep-2013 |
Mark Andrews <marka@isc.org> |
whitspace |
b5f4cc132e91afb1217f4aa79424793c0e11c09a |
|
04-Sep-2013 |
Mark Andrews <marka@isc.org> |
3641. [bug] Handle changes to sig-validity-interval settings
better. [RT #34625] |
7ace3277956c49f7554b7130ef761bde3b35db30 |
|
15-Aug-2013 |
Mark Andrews <marka@isc.org> |
3632. [bug] Signature from newly inactive keys were not being
removed. [RT #32178] |
cfa2326b5c96a3a4c720262e077b2baf9fc27970 |
|
15-Mar-2013 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
4eb998928b9aef0ceda42d7529980d658138698a |
|
14-Mar-2013 |
Evan Hunt <each@isc.org> |
[master] algorithm flexibility for rndc
3525. [func] Support for additional signing algorithms in rndc:
hmac-sha1, -sha224, -sha256, -sha384, and -sha512.
The -A option to rndc-confgen can be used to
select the algorithm for the generated key.
(The default is still hmac-md5; this may
change in a future release.) [RT #20363] |
8f6d6d72e80314bd36c50f1805e424b6f6332cae |
|
14-Aug-2012 |
Evan Hunt <each@isc.org> |
support '-' salt in rndc signing -nsec3param
3361. [bug] "rndc signing -nsec3param" didn't work correctly
when salt was set to '-' (no salt). [RT #30099] |
a847a4bcd665fb1cafc1b2a0a42be7a1ede82a89 |
|
18-May-2012 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
26833735d3d95e731a1cfb2a9b12c9bc10ba208a |
|
17-May-2012 |
Evan Hunt <each@isc.org> |
Handle RRSIG signer case consistently
3329. [bug] Handle RRSIG signer-name case consistently: We
generate RRSIG records with the signer-name in
lower case. We accept them with any case, but if
they fail to validate, we try again in lower case.
[RT #27451] |
9c03f13e18c1b0c32f62391a17300378605bbc7b |
|
28-Oct-2011 |
Evan Hunt <each@isc.org> |
3185. [func] New 'rndc signing' option for auto-dnssec zones:
- 'rndc signing -list' displays the current
state of signing operations
- 'rndc signing -clear' clears the signing state
records for keys that have fully signed the zone
- 'rndc signing -nsec3param' sets the NSEC3
parameters for the zone
The 'rndc keydone' syntax is removed. [RT #23729] |
bfe32d08c51a606744bd0d6ea518eb95084d2eef |
|
23-May-2011 |
Evan Hunt <each@isc.org> |
3116. [func] New 'dnssec-update-mode' option controls updates
of DNSSEC records in signed dynamic zones. Set to
'no-resign' to disable automatic RRSIG regeneration
while retaining the ability to sign new or changed
data. [RT #24533] |
a50ce0f80bd665545389cfd91df31d3f4fe66b04 |
|
19-May-2011 |
Scott Mann <smann@isc.org> |
Fix for RT #23136 task 1. |
5095e72ac3c0f1e16c246b56e8277614571bf132 |
|
21-Mar-2011 |
Mark Andrews <marka@isc.org> |
3083. [bug] NOTIFY messages were not being sent when generating
a NSEC3 chain incrementally. [RT #23702] |
eff7f78bc65f30efd87a398e66084ddab72799d3 |
|
05-Mar-2011 |
Mark Andrews <marka@isc.org> |
3061. [func] New option "dnssec-signzone -D", only write out
generated DNSSEC records. [RT #22896] |
664917bedafa65dee4349c84324a31731aa1e228 |
|
28-Feb-2011 |
Francis Dupont <fdupont@isc.org> |
Use RRSIG original TTL in validated RRset TTL [RT #23332] |
4f07b2b00cf52582b2ee9b55aabe7eb5066e57e7 |
|
23-Feb-2011 |
Mark Andrews <marka@isc.org> |
3040. [bug] Named failed to validate insecure zones where a node
with a CNAME existed between the trust anchor and the
top of the zone. [RT #23338] |
b1b42b03b774d77ddfd38e5e0a5c0a3ed1944b89 |
|
15-Feb-2011 |
Mark Andrews <marka@isc.org> |
3020. [bug] auto-dnssec failed to correctly update the zone when changing the DNSKEY RRset. [RT #23232] |
c5fa3706950224af3f5ae6d22944b1b8298d4edd |
|
15-Feb-2011 |
Mark Andrews <marka@isc.org> |
3019. [func] Test: check apex NSEC3 records after adding DNSKEY
record via UPDATE. [RT #23229] |
56748bc3d1e6b088cd9dcc2aa63ebce4d4539fa2 |
|
09-Feb-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
37b017f2ca736c251b80d2db564ef274317da168 |
|
08-Feb-2011 |
Mark Andrews <marka@isc.org> |
Regression test for:
3018. [bug] Named failed to check for the "none;" acl when deciding
if a zone may need to be re-signed. [RT #23120] |
5312c2ffbedd55046f4d606cf425fa74d0401d2a |
|
11-Jul-2010 |
Evan Hunt <each@isc.org> |
dnssec and dlv tests included master zones whose master files were missing.
this was a bug that hadn't been noticed before, but 19447 added a test for
that condition and it caused test failures. |
6bb1560124ce99fe50b9847ce29fcaed52564900 |
|
19-Jan-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
e11a0c114cdaf8f7e7832e9f1a011138248093a6 |
|
18-Jan-2010 |
Evan Hunt <each@isc.org> |
2841. [func] Added "smartsign" and improved "autosign" and
"dnssec" regression tests. [RT #20865] |
990dca4605f47703dfdadacb594fbafe01760661 |
|
28-Oct-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
e09cdbac087b88524ac40e943d040e2a032c48f2 |
|
27-Oct-2009 |
Mark Andrews <marka@isc.org> |
2738. [func] Add RSASHA256 and RSASHA512 tests to the dnssec system
test. [RT #20453] |
3398334b3acda24b086957286288ca9852662b12 |
|
25-Sep-2008 |
Automatic Updater <source@isc.org> |
update copyright notice |
6098d364b690cb9dabf96e9664c4689c8559bd2e |
|
24-Sep-2008 |
Mark Andrews <marka@isc.org> |
2448. [func] Add NSEC3 support. [RT #15452] |
70e5a7403f0e0a3bd292b8287c5fed5772c15270 |
|
20-Jun-2007 |
Automatic Updater <source@isc.org> |
update copyright notice |
ec5347e2c775f027573ce5648b910361aa926c01 |
|
19-Jun-2007 |
Automatic Updater <source@isc.org> |
update copyright notice |
d6b5e0b0e8a4e3e927f8d47ca82c3e7f42e0f4bb |
|
10-Mar-2006 |
Mark Andrews <marka@isc.org> |
update copyright notice |
cfe92110ce4eaf19f7f3255d2961710879bdc9dd |
|
10-Mar-2006 |
Mark Andrews <marka@isc.org> |
2007. [func] It is now possible to explicitly enable DNSSEC
validation. default dnssec-validation no; to
be changed to yes in 9.5.0. [RT #15674] |
38e8022ace865803bdd609c9763cd7d7ba2818dc |
|
05-May-2004 |
Mark Andrews <marka@isc.org> |
1625. [bug] named failed to load/transfer RFC2535 signed zones
which contained CNAMES. [RT# 11237] |
8d414d155953f89a4eff40f16878438a8c9228f3 |
|
16-Apr-2004 |
Mark Andrews <marka@isc.org> |
1600. [bug] Duplicate zone pre-load checks were not case
insensitive.
1599. [bug] Fix memory leak on error path when checking named.conf.
1598. [func] Specify that certain parts of the namespace must
be secure (dnssec-must-be-secure). |
50105afc551903541608b11851d73278b23579a3 |
|
10-Mar-2004 |
Mark Andrews <marka@isc.org> |
1589. [func] DNSSEC lookaside validation.
enable-dnssec -> dnssec-enable |
dafcb997e390efa4423883dafd100c975c4095d6 |
|
05-Mar-2004 |
Mark Andrews <marka@isc.org> |
update copyright notice |
821644d49b73b49f2abc5463bc53a3132f612478 |
|
02-Mar-2004 |
Mark Andrews <marka@isc.org> |
1574. [bug] Don't attempt to open the controls socket(s) when
running tests. [RT #9091] |
89783da064f4f9bf2e82d2b3941ddeffe2a8c30d |
|
17-Feb-2004 |
Mark Andrews <marka@isc.org> |
1581. [func] Disable DNSSEC support by default. To enable
DNSSEC specify "enable-dnssec yes;" in named.conf. |
a7038d1a0513c8e804937ebc95fc9cb3a46c04f5 |
|
20-Feb-2002 |
Mark Andrews <marka@isc.org> |
copyrights |
473ca0bf8c73e5fc3132df074b2d4e14be5eaa1e |
|
22-Jan-2002 |
Andreas Gustafsson <source@isc.org> |
Added RT #2399 regression test |
e4b5f088ca2dad7c81a9df0172fd534a3a880879 |
|
19-Sep-2001 |
Andreas Gustafsson <source@isc.org> |
Added RT #1763 regression test |
1988fd60faefcc65119896996e0f33d91440b1d2 |
|
11-Jan-2001 |
Andreas Gustafsson <source@isc.org> |
share the root.hint file among most of the system tests instead of having multiple identical copies |
499b34cea04a46823d003d4c0520c8b03e8513cb |
|
09-Jan-2001 |
Brian Wellington <source@isc.org> |
copyright update |
f333ea9bdd3f85b74ae790e6c8ce2684295b3483 |
|
28-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
added notify-source options |
4f37905cc38162128a507e619e38ae535720686b |
|
22-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
added 'transfer-source' directives to all system test named.conf
files, so that tests succeed while transfer-source is still being (ab)used as
the notify source address |
5a77e9620a0b2f7417469c98be374de49d0eccc6 |
|
22-Nov-2000 |
Andreas Gustafsson <source@isc.org> |
make spacing in listen-on-v6 option consistent with other options |
40f53fa8d9c6a4fc38c0014495e7a42b08f52481 |
|
01-Aug-2000 |
David Lawrence <source@isc.org> |
Trailing whitespace trimmed. Perhaps running "perl util/spacewhack.pl in your
own CVS tree will help minimize CVS conflicts. Maybe not.
Blame Graff for getting me to trim all trailing whitespace. |
15a44745412679c30a6d022733925af70a38b715 |
|
27-Jul-2000 |
David Lawrence <source@isc.org> |
word wrap copyright notice at column 70 |
9c3531d72aeaad6c5f01efe6a1c82023e1379e4d |
|
23-Jun-2000 |
David Lawrence <source@isc.org> |
add RCS id string |
d0be1e954bd4674fc27f2616c72adb37cf3525a2 |
|
22-Jun-2000 |
David Lawrence <source@isc.org> |
update_copyrights |
126c8d0c085dedfbd52931a3c0579189f49d6690 |
|
14-Jun-2000 |
Brian Wellington <source@isc.org> |
Add listen-on-v6 {none;}; , since without it, v6 was binding v4 mapped
sockets and causing failures on some platforms |
ee6fe1d1975604af266af6c370fc6193dae80fdd |
|
13-Jun-2000 |
Michael Sawyer <source@isc.org> |
Remove port option from query-sources |
5458e9245c6f5bac6aefd64ad37c595bae49bd7b |
|
13-Jun-2000 |
Michael Sawyer <source@isc.org> |
Add query-source everywhere
Fix out output |
5006de65318890450e5b7008d8805ce48525f58e |
|
10-Jun-2000 |
Brian Wellington <source@isc.org> |
- Added query-source to each server.
- Added an insecure child of a secure parent (insecure.secure.example)
- Added a privately secure child of a secure parent (private.secure.example) |
ca793cbfcf2ec525f9475265c48130d4b7ed78b2 |
|
07-Jun-2000 |
Andreas Gustafsson <source@isc.org> |
run test DNS on port 5300 |
a92428ecb8be7eb85e5296b2c9082c2c9c43a4e7 |
|
19-May-2000 |
Michael Sawyer <source@isc.org> |
Sweeping changes to system test suite |
02fdafbf53f712ee72ef50c4fa537f97082d8114 |
|
18-May-2000 |
Michael Sawyer <source@isc.org> |
Add missing files |
d98372394fd6253336e9c9d580f48bd6ff9710f7 |
|
18-May-2000 |
Michael Sawyer <source@isc.org> |
Addition of test suite. |
0e9dcd548051a8ec34744bfa18b4e09fea742a39 |
|
16-May-2000 |
Andreas Gustafsson <source@isc.org> |
added system tests |