d77cb075aae5595e460e3299bfc1e8ea5d42b560 |
|
15-Feb-2018 |
Evan Hunt <each@isc.org> |
[v9_11] prep 9.11.3rc1 |
2767fc751bdce031fc83fa60b43dee020e1e2dee |
|
07-Feb-2018 |
Mark Andrews <marka@isc.org> |
add note for update-policy rules changes
(cherry picked from commit ff8f2a584d6a809158b1aaf59bde12061c096cc1) |
dc2a85bed7fcfceab0df1867fbc1d35796261ded |
|
05-Jan-2018 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
5599d587e6e2ff088a510c50fe40f1a10b8b6b63 |
|
04-Jan-2018 |
Evan Hunt <each@isc.org> |
[v9_11] typo |
7ff28f5befbee76048a23e504dcd3f9a44ce6209 |
|
04-Jan-2018 |
Evan Hunt <each@isc.org> |
[v9_11] block validator deadlock and prevent use-after-free
4859. [bug] A loop was possible when attempting to validate
unsigned CNAME responses from secure zones;
this caused a delay in returning SERVFAIL and
also increased the chances of encountering
CVE-2017-3145. [RT #46839]
4858. [security] Addresses could be referenced after being freed
in resolver.c, causing an assertion failure.
(CVE-2017-3145) [RT #46839] |
6155978af562d677f9ad554a621c4038d7c877a5 |
|
05-Dec-2017 |
Mark Andrews <marka@isc.org> |
add [RT #46774]
(cherry picked from commit 77f96234391bb393050ad445a9088644cc90235a) |
b722ecd2f881c3bb758aaebe5d8a44843993b107 |
|
05-Dec-2017 |
Evan Hunt <each@isc.org> |
[v9_11] revised release note |
15bc7f54ff32b57c5b03c0813d010df38680402a |
|
04-Dec-2017 |
Mark Andrews <marka@isc.org> |
add note for [RT #46743] and [RT #46754]
(cherry picked from commit 9ff34db455b1d0d2addcdac7092f273acdec4c65) |
f53e0bda467d96dfeeba1b4da30c37b37766bb75 |
|
30-Nov-2017 |
Evan Hunt <each@isc.org> |
[v9_11] fix "allow-transfer" inheritance and clean up ACL configuration
4836. [bug] Zones created using "rndc addzone" could
temporarily fail to inherit an "allow-transfer"
ACL that had been configured in the options
statement. [RT #46603]
(cherry picked from commit e197a2bd150783f53044342cf0d02510dfb744df) |
7382f5160274938d143d82bda1941b32822dac53 |
|
29-Oct-2017 |
Mark Andrews <marka@isc.org> |
Add system tests and remove redundent logging from:
4801. [func] 'dnssec-lookaside auto;' and 'dnssec-lookaside .
trust-anchor dlv.isc.org;' now elicit warnings rather
than being fatal configuration errors. [RT #46410]
(cherry picked from commit f5e1b555c59074e9b8626921c4a068ee6fc1c1e3) |
317330c25ac8f1a5cbab46f85f10280c0b3d34dd |
|
20-Oct-2017 |
Mark Andrews <marka@isc.org> |
use correct tag |
a4ea78aa55fa5e5161ff0ca6eb047f856456fba4 |
|
20-Oct-2017 |
Mark Andrews <marka@isc.org> |
s/made/may/ |
ff08ac42f7fb3a2ac611cbac8df7bc28d93c8de4 |
|
20-Oct-2017 |
Mark Andrews <marka@isc.org> |
note removal of <isc/util.h> from other header files
(cherry picked from commit 9e5439a6d897f90fd12e09dd1cd81b37c1de96bc) |
56e30ebae6fdb0bdf94419caff3a43fb2d16c5df |
|
18-Oct-2017 |
Evan Hunt <each@isc.org> |
[v9_11] require writable managed keys directory
4769. [bug] Enforce the requirement that the managed keys
directory (specified by "managed-keys-directory",
and defaulting to the working directory if not
specified) must be writable. [RT #46077] |
e609b6b32bc8455692e1497a4568c68d7bfb9f36 |
|
17-Oct-2017 |
Evan Hunt <each@isc.org> |
[v9_11] README and relnote fixes
(cherry picked from commit 30419509dd31502bbddcb69a41201eb73f8aeccc) |
f592d2f76cac7115038124c510d2ba3050334b4d |
|
07-Oct-2017 |
Evan Hunt <each@isc.org> |
[v9_11] further restrict update-policy local
4762. [func] "update-policy local" is now restricted to updates
from local addresses. (Previously, other addresses
were allowed so long as updates were signed by the
local session key.) [RT #45492] |
2732d4922c2e72a399204320791acfd2fd3d6c7c |
|
05-Oct-2017 |
Mark Andrews <marka@isc.org> |
4754. [bug] dns_zone_setview needs a two stage commit to properly
handle errors. [RT #45841] |
73b52dd1f0cbcfd87ee8b50a2beaae46aee38a11 |
|
05-Oct-2017 |
Evan Hunt <each@isc.org> |
[v9_11] fix tag |
d5bd8bb71a8970d4ebc4701b3e9ec3efef4954b7 |
|
03-Oct-2017 |
Evan Hunt <each@isc.org> |
[v9_11] de-DLV
4749. [func] The ISC DLV service has been shut down, and all
DLV records have been removed from dlv.isc.org.
- Removed references to ISC DLV in documentation
- Removed DLV key from bind.keys
- No longer use ISC DLV by default in delv
[RT #46155] |
a64daf673deff2358a91bee26bbf2bf874f47c6e |
|
25-Aug-2017 |
Mark Andrews <marka@isc.org> |
4688. [protocol] Check and display EDNS KEY TAG options (RFC 8145) in
messages. [RT #44804]
(cherry picked from commit 07741d43c8da09821b6eedbbe066fad86af72cc8) |
1073e2001caee13cc1fa52de97feddd633d50fd8 |
|
31-Jul-2017 |
Evan Hunt <each@isc.org> |
[v9_11] revise CHANGES note and add release note |
d4098be27be4d6d41c78e693baadaca9295a257c |
|
15-Jul-2017 |
Evan Hunt <each@isc.org> |
[v9_11] update relnotes to mention termination of windows XP support |
3ba9f5804c6ea21d075a5c0f6fa99f4fdadd3d71 |
|
14-Jul-2017 |
Evan Hunt <each@isc.org> |
[v9_11] add a release note for TSIG regression |
e55c767c89e3ee73b85879bcd407a391bb0af1b7 |
|
11-Jul-2017 |
Mark Andrews <marka@isc.org> |
note change in AD setting on some truncated answers
(cherry picked from commit 56d8312a48942422855beb86bb9af955d6e8ef90) |
66afb7c86a52e36a3c052ab9a1fa98e213841b28 |
|
10-Jul-2017 |
Mark Andrews <marka@isc.org> |
add note about .local
(cherry picked from commit 99879922328da2d328f8ab62d59a5ed28de66a56) |
a03f4b1ea4f1a4a70963fbeb606841c217f9e5f3 |
|
27-Jun-2017 |
Evan Hunt <each@isc.org> |
[v9_11] address TSIG bypass/forgery vulnerabilities
4643. [security] An error in TSIG handling could permit unauthorized
zone transfers or zone updates. (CVE-2017-3142)
(CVE-2017-3143) [RT #45383]
(cherry picked from commit 581c1526ab0f74a177980da9ff0514f795ed8669) |
214b53880b6d77359f60feccb91bd2589059300a |
|
13-Jun-2017 |
Evan Hunt <each@isc.org> |
[v9_11] prevent reload failure due to LMDB database perms
4638. [bug] Reloading or reconfiguring named could fail on
some platforms when LMDB was in use. [RT #45203]
(cherry picked from commit bf05e66bb38c44378a7873ff3701e6e596e70bf7) |
c28e44f3f8bc46c6bf1c15cc06af0c42fcd7e924 |
|
30-May-2017 |
Evan Hunt <each@isc.org> |
[v9_11] quote service registry paths
4532. [security] The BIND installer on Windows used an unquoted
service path, which can enable privilege escalation.
(CVE-2017-3141) [RT #45229]
(cherry picked from commit 967a3b9419a3c12b8c0870c86d1ee3840bcbbad7) |
3440cf9c60cd5d35634e7f274fd3eccbba2173a5 |
|
30-May-2017 |
Evan Hunt <each@isc.org> |
[v9_11] fix rpz formerr loop
4531. [security] Some RPZ configurations could go into an infinite
query loop when encountering responses with TTL=0.
(CVE-2017-3140) [RT #45181] |
474577728422b990f94e57988674e7646375491d |
|
17-May-2017 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
403e7b451207fe6514a5d641562713b1af233b9c |
|
16-May-2017 |
Evan Hunt <each@isc.org> |
[v9_11] symbolic option names for dig +ednsopt
4555. [func] dig +ednsopt: EDNS options can now be specified by
name in addition to numeric value. [RT #44461]
(cherry picked from commit 25a9b90369f2de5c9921fae84a27c94c83f156be) |
613cdc91fe79f9c1e16f335522a1a305791d4a9a |
|
11-May-2017 |
Mark Andrews <marka@isc.org> |
add warning about semicolon no longer being escaped
(cherry picked from commit d4d73bca797a70976d627c355907026ca1aee880) |
c83a3061551c86bd661839be935de061f7322f5c |
|
04-May-2017 |
Evan Hunt <each@isc.org> |
[v9_11] fix lmdb delzone
4616. [bug] When using LMDB, zones deleted using "rndc delzone"
were not correctly removed from the new-zone
database. [RT #45185]
(cherry picked from commit 3a554a444caf444b6239a7ae80d6448cad3a363e) |
8b9c4592ed718c4187971f1104381faf538bf4f7 |
|
21-Apr-2017 |
Evan Hunt <each@isc.org> |
[v9_11] give threads unique names to assist debugging
4602. [func] Threads are now set to human-readable
names to assist debugging, when supported by
the OS. [RT #43234]
(cherry picked from commit d26ae7fc0802f67a50f6f01152f356182d47305e) |
c03cca46292d1c11ca1e5dcb6f6c23661fad5bd7 |
|
21-Apr-2017 |
Evan Hunt <each@isc.org> |
[v9_11] clear out relnotes |
869cb92bab5827aa735af34acae125a1d42235a6 |
|
12-Apr-2017 |
Evan Hunt <each@isc.org> |
[v9_11] formatting
(cherry picked from commit 52e398c0afdb220ee2cc5119d10f8c23f924d883) |
33cc2edb8ef072fb2da1064160ecf7c351abe68c |
|
29-Mar-2017 |
Mark Andrews <marka@isc.org> |
add CVE-2017-3138
(cherry picked from commit fe1ad70e510d2327f9decf5096915becbc2c95c0) |
559cbe04e73cf601784a371e09554c20407a6c7b |
|
23-Feb-2017 |
Evan Hunt <each@isc.org> |
[v9_11] remove unnecessary INSIST and prep 9.11.1rc2
4578. [security] Some chaining (CNAME or DNAME) responses to upstream
queries could trigger assertion failures.
(CVE-2017-3137) [RT #44734]
(cherry picked from commit a1365a0042db8c1cd0ee4dbd0c91ce65ae09e098) |
42f4ea63175156f3c5b7576fc21f26de0f8a0f1d |
|
14-Feb-2017 |
Mark Andrews <marka@isc.org> |
add CVE-2017-3136 note
(cherry picked from commit d77eadc26113486f32fea25320ae4c6f1f2e7fb2) |
6043c4453db797e74fed185775a216e47d790b6a |
|
07-Feb-2017 |
Evan Hunt <each@isc.org> |
[v9_11] doc style |
8e69860942eefdf7a21f929a99a9c6f657e806cd |
|
06-Feb-2017 |
Evan Hunt <each@isc.org> |
[v9_11] removed extra note about bind.keys update |
59f34c1fc775bf1817c49f5b4a121285f9608efc |
|
05-Feb-2017 |
Evan Hunt <each@isc.org> |
[v9_11] release note about new root key |
07b7a3eadeda94eddd50977c9582dae2f955b638 |
|
04-Feb-2017 |
Evan Hunt <each@isc.org> |
[v9_11] store local and remote addresses in dnstap
4569. [func] Store both local and remote addresses in dnstap
logging, and modify dnstap-read output format to
print them. [RT #43595]
(cherry picked from commit 650b5e7592be43d6994ba425bc1fa654d538cd7e) |
51b03196964ede418c46c0bfe1946a4edb91135a |
|
02-Feb-2017 |
Mark Andrews <marka@isc.org> |
new root KSK |
781f6daa74867ca6937a4d58afa4abcf96699d34 |
|
30-Jan-2017 |
Evan Hunt <each@isc.org> |
[v9_11] change 4558 was incomplete
(cherry picked from commit cd668ea57fc236e1f7509c3827e4a39a62078a2d) |
2f70ce448a550a3544f30c8ba6f2a30c4697721d |
|
24-Jan-2017 |
Evan Hunt <each@isc.org> |
[v9_11] expand relnote
(cherry picked from commit afa0ff0cbb75f4ce20d082eb3cb30ea6b2840920) |
22e3ffcf2c52114092b2dbdf2bc1872371c96192 |
|
23-Jan-2017 |
Mark Andrews <marka@isc.org> |
4556. [security] Combining dns64 and rpz can result in dereferencing
a NULL pointer (read). (CVE-2017-3135) [RT#44434]
(cherry picked from commit 5abe80ef138340e3d4f551059a3c340b78940933) |
f6b909274159da7aaad8463c90f15018136cf6cb |
|
13-Jan-2017 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
2cee8eadec6545fb0ce10fb8c1d7b60870ec2fb4 |
|
12-Jan-2017 |
Mark Andrews <marka@isc.org> |
4553. [bug] Named could deadlock there were multiple changes to
NSEC/NSEC3 parameters for a zone being processed at
the same time. [RT #42770]
(cherry picked from commit d2e1b47d4fc7f2e12ea91cc59dc5f951a9df5fbc) |
9e4e871392b39cbeff443c58fbd96f1690b618a4 |
|
12-Jan-2017 |
Mark Andrews <marka@isc.org> |
4552. [bug] Named could trigger a assertion when sending notify
messages. [RT #44019]
(cherry picked from commit 42924b40af972acc2f2ca82d6e7211e10b4f4a29) |
ac424b61bbfbf588c9d5d180a63bbefa49175e03 |
|
29-Dec-2016 |
Evan Hunt <each@isc.org> |
[v9_11] release notes |
b243aa40f97cb2f77fbe746977d61f0a8c2e9194 |
|
29-Dec-2016 |
Mark Andrews <marka@isc.org> |
4508. [security] Named incorrectly tried to cache TKEY records which
could trigger a assertion failure when there was
a class mismatch. (CVE-2016-9131) [RT #43522]
(cherry picked from commit 2c1c4b99a127a0f34e10fe27324d552ccbc54e04) |
58f15381f7f69f4e986d7014fda4feb223b8b36c |
|
28-Dec-2016 |
Evan Hunt <each@isc.org> |
[v9_11] expand intro |
544e2b48ece5724f2c4a0d6636048a72335cfd54 |
|
28-Dec-2016 |
Evan Hunt <each@isc.org> |
[v9_11] release notes |
6649db1ca4f3dc2d14f41f77e03867ac013215f9 |
|
28-Dec-2016 |
Evan Hunt <each@isc.org> |
[v9_11] release note |
d438157f7e637d01f1e23eb5099496040444ae94 |
|
27-Dec-2016 |
Evan Hunt <each@isc.org> |
[v9_11] clarify auth ECS is not meant for production use |
83a28ca274521e15086fc39febde507bcc4e145e |
|
07-Dec-2016 |
Mark Andrews <marka@isc.org> |
4527. [doc] Support DocBook XSL Stylesheets v1.79.1. [RT #43831]
(cherry picked from commit 1b8ce3b3302f0afe682d04df8a1f20b4ac346fb2) |
744c1db6352c4c3f11c8538e4a2a57c8b0e0d570 |
|
02-Nov-2016 |
Mark Andrews <marka@isc.org> |
4504. [security] Allow the maximum number of records in a zone to
be specified. This provides a control for issues
raised in CVE-2016-6170. [RT #42143]
(cherry picked from commit 5f8412a4cb5ee14a0e8cddd4107854b40ee3291e) |
fcadf0b3205be950da14c80fedbf088fc8fd2190 |
|
22-Sep-2016 |
Evan Hunt <each@isc.org> |
[v9_11] render querylog format consistent, and add a release note
4471. [cleanup] Render client/query logging format consistent for
ease of log file parsing. (Note that this affects
"querylog" format: there is now an additional field
indicating the client object address.) [RT #43238]
(cherry picked from commit c4b7db49326be650fa95a7ede6e066bbe1268561) |
61349d96c085d63d165b40ad053dfe158fcfdec1 |
|
09-Sep-2016 |
Mark Andrews <marka@isc.org> |
reorder
(cherry picked from commit 9ffbc3f9b35e377aea919cc4285f6456f489e7f2) |
cdf97b41dc727bc42a02ece9c8dee2f9061872c8 |
|
09-Sep-2016 |
Mark Andrews <marka@isc.org> |
add CVE-2016-2776
(cherry picked from commit d4c8a622c0806b332880d7a9db69cf48a5260901) |
99e64ce41f3b6ff98cf57562d4493d6a706bb487 |
|
25-Aug-2016 |
Evan Hunt <each@isc.org> |
[v9_11] fix dnssec-policy.conf in notes
(cherry picked from commit bfb479d5e32c42c6ebf85d13bbb2f9cfa46173be) |
756b54c8ffb2cf3caeb94dfdce661790fef56800 |
|
25-Aug-2016 |
Evan Hunt <each@isc.org> |
[v9_11] add missing release notes and fix other doc nits
(cherry picked from commit 864dc79dce81123d31a30bc7b47ea564dd7a20a3) |
2fb6d3782b548ba678cfb8ff09e0d1e49fafb84d |
|
12-Aug-2016 |
Mark Andrews <marka@isc.org> |
4437. [func] Minimal-responses now has two additional modes
no-auth and no-auth-recursive which suppress
adding the NS records to the authority section
as well as the associated address records for the
nameservers. [RT #42005]
(cherry picked from commit 78e31dd18798f22828059b0f5cbc1c984c7e142c) |
b7161f9898405faee05ba72a63ad10e4541f1346 |
|
22-Jul-2016 |
Mark Andrews <marka@isc.org> |
4424. [experimental] Named now sends _ta-XXXX.<trust-anchor>/NULL queries
to provide feedback to the trust-anchor administrators
about how key rollovers are progressing as per
draft-ietf-dnsop-edns-key-tag-02. This can be
disabled using 'trust-anchor-telemetry no;'.
[RT #40583]
(cherry picked from commit f20179857a8512441c3be7ad33f1c84e367de041) |
adb0ac475d4a58404812eee3a158447decf9e026 |
|
22-Jul-2016 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
2c9f6f236fffed32f50837437d453dfeb17f56f2 |
|
21-Jul-2016 |
Evan Hunt <each@isc.org> |
[v9_11] add release note |
801707fe19600313a0b1f7845a518100f69e58b6 |
|
21-Jul-2016 |
Evan Hunt <each@isc.org> |
[v9_11] store "addzone" zone config in a NZD database
4421. [func] When built with LMDB (Lightning Memory-mapped
Database), named will now use a database to store
the configuration for zones added by "rndc addzone"
instead of using a flat NZF file. This improves
performance of "rndc delzone" and "rndc modzone"
significantly. Existing NZF files will
automatically by converted to NZD databases.
To view the contents of an NZD or to roll back to
NZF format, use "named-nzd2nzf". To disable
this feature, use "configure --without-lmdb".
[RT #39837] |
0ad430bda9a5686f4b4343940bfc90ecc3da94f9 |
|
14-Jul-2016 |
Mark Andrews <marka@isc.org> |
grammar
(cherry picked from commit 8f7881684be27d6d698f78f771d3d16dc57101c9) |
3525200d9fb0e70aec4f6a3c7e0ed5a7dd8398af |
|
13-Jul-2016 |
Evan Hunt <each@isc.org> |
[v9_11] rndc dnstap -roll
4411. [func] "rndc dnstap -roll" automatically rolls the
dnstap output file; the previous version is
saved with ".0" suffix, and earlier versions
with ".1" and so on. An optional numeric argument
indicates how many prior files to save. [RT #42830] |
d23a531fdef10e0b61eeef99e0ee348e1247756e |
|
13-Jul-2016 |
Mark Andrews <marka@isc.org> |
add [RT #42694] |
967c2a93ac2f40b578d65fe096981fceca7ebc5a |
|
13-Jul-2016 |
Mark Andrews <marka@isc.org> |
issue -> flaw
(cherry picked from commit 268f9e6832841a8e9f22562cc1294b4046d39ec3) |
b740318a42e7e9e9511c4a3213a81a51257c1ab9 |
|
11-Jul-2016 |
Mark Andrews <marka@isc.org> |
add CVE-2016-2775
(cherry picked from commit 909d442cc0bed4337760419fa135c98224a79c73) |
da984e8fc5f36cbd7215a0b9d41dd7bbeecc7b10 |
|
07-Jul-2016 |
Mark Andrews <marka@isc.org> |
add note for rt42694
(cherry picked from commit 429701008e672edc50d33c83d983ba096fee5f13) |
d2647cd5fd919c2a3ccd983a0ef9e6cfca68824c |
|
06-Jul-2016 |
Mark Andrews <marka@isc.org> |
license section is no longer a list |
988c13928a921b03c904ca2dc4b1d01fa21ff84d |
|
05-Jul-2016 |
Mark Andrews <marka@isc.org> |
spelling |
f0e7471845e0c9f1509fb91cae4a8e6655132acb |
|
02-Jul-2016 |
Evan Hunt <each@isc.org> |
[v9_11] notes formatting, fix a CHANGES tag |
4ab08a81171c1b6644483e6f4cf4d96ec682912f |
|
27-Jun-2016 |
Witold Krecicki <wpk@isc.org> |
Fix a typo and missing link in notes.xml |
448e23ed619dfa617df5666ad8df28ef2d9772bf |
|
27-Jun-2016 |
Curtis Blackburn <ckb@isc.org> |
cleanup of notes.xml
added better text to describe the license change
added information about the following changes to notes.xml
+4396. [func] dnssec-keymgr now takes a '-r randomfile' option.
+ [RT #42455]
+4392. [func] Collect statistics for RSSAC02v3 traffic-volume,
+ traffic-sizes and rcode-volume reporting. [RT #41475]
+4388. [func] Support for master entries with TSIG keys in catalog
+ zones. [RT #42577]
+4385. [func] Add support for allow-query and allow-transfer ACLs
+ to catalog zones. [RT #42578] |
0c27b3fe77ac1d5094ba3521e8142d9e7973133f |
|
27-Jun-2016 |
Mark Andrews <marka@isc.org> |
4401. [misc] Change LICENSE to MPL 2.0. |
7d262a3647a517a86d6d83058aedd18b7a6b06df |
|
24-Jun-2016 |
Mark Andrews <marka@isc.org> |
4394. [func] Add rndc command "dnstap-reopen" to close and
reopen dnstap output filed. [RT #41803] |
7a00d69909ace5dc11bcff9c1e07c311f92a7f8e |
|
26-May-2016 |
Witold Krecicki <wpk@isc.org> |
4376. [experimental] Added support for Catalog Zones, a new method for
provisioning secondary servers in which a list of
zones to be served is stored in a DNS zone and can
be propagated to slaves via AXFR/IXFR. [RT #41581]
4375. [func] Add support for automatic reallocation of isc_buffer
to isc_buffer_put* functions. [RT #42394] |
5c5dcf34c35bd946cf3d1c563559d020eee0e296 |
|
26-May-2016 |
Evan Hunt <each@isc.org> |
[master] spelling |
8e4d28d018c402fe0b9c3ea393e35b8339ef8d70 |
|
26-May-2016 |
Evan Hunt <each@isc.org> |
[master] extend release notes |
9211688e88c5bc8cd344b9d16497736b62933174 |
|
26-May-2016 |
Evan Hunt <each@isc.org> |
[master] fix tag mismatch |
0cbe448914be61d0f92b1e9d3adaeba87d25639d |
|
25-May-2016 |
Evan Hunt <each@isc.org> |
[master] minimal-any
4371. [func] New "minimal-any" option reduces the size of UDP
responses for qtype ANY by returning a single
arbitrarily selected RRset instead of all RRsets.
Thanks to Tony Finch. [RT #41615] |
47d19078de548016572db6ba7c29030bce9d5796 |
|
24-May-2016 |
Mark Andrews <marka@isc.org> |
note RNDC module |
259107718fb6c0cce23f44a798d31149956160dc |
|
17-May-2016 |
Mark Andrews <marka@isc.org> |
update for 9.11.0a2 |
e846f127d64ea690b789efa6e5b4ff9f64cf3235 |
|
05-May-2016 |
Witold Krecicki <wpk@isc.org> |
4362. [func] Changed rndc reconfig behaviour so that newly added
zones are loaded asynchronously and the loading does
not block the server. [RT #41934] |
370c6e0ac1ad6330e5ded66e5636c5c93d2ce3ff |
|
05-May-2016 |
Evan Hunt <each@isc.org> |
[master] add nsip-wait-recurse release note |
66074f152f2a42218e6d54f50d4fa3717940c299 |
|
04-May-2016 |
Evan Hunt <each@isc.org> |
[master] log message when using ISC DLV
4352. [cleanup] The ISC DNSSEC Lookaside Validation (DLV) service
is scheduled to be disabled in 2017. A warning is
now logged when named is configured to use it,
either explicitly or via "dnssec-lookaside auto;"
[RT #42207] |
1bebd86e9f9f7453f326907ebe01ee3d477e6bba |
|
29-Apr-2016 |
Mark Andrews <marka@isc.org> |
fix tag mis-match |
f6096b958c8b58c4709860d7c4dcdde5deeacb7a |
|
28-Apr-2016 |
Evan Hunt <each@isc.org> |
[master] dnssec-keymgr
4349. [contrib] kasp2policy: A python script to create a DNSSEC
policy file from an OpenDNSSEC KASP XML file.
4348. [func] dnssec-keymgr: A new python-based DNSSEC key
management utility, which reads a policy definition
file and can create or update DNSSEC keys as needed
to ensure that a zone's keys match policy, roll over
correctly on schedule, etc. Thanks to Sebastian
Castro for assistance in development. [RT #39211] |
4d3f9f216a40a9a11e421fae402d022b9fbb367d |
|
25-Mar-2016 |
Evan Hunt <each@isc.org> |
[master] better relnote for read-only controls option |
1831596a792a6433f8cc1fbc2d86054fb9143559 |
|
24-Mar-2016 |
Evan Hunt <each@isc.org> |
[master] fixes for release notes |
936bfae6d59f4ebae1f9bddb9516233268e58000 |
|
24-Mar-2016 |
Evan Hunt <each@isc.org> |
[master] remove pre-9.11.0a1 security fixes from 9.11 release notes |
46472a450e043434d78fa18edc73bca8c47f3981 |
|
23-Mar-2016 |
Tinderbox User <tbox@isc.org> |
regen master |
bee8d5b202f6a8be7ca7165b98caf3b737d9f3d0 |
|
23-Mar-2016 |
Evan Hunt <each@isc.org> |
[master] fix broken tag |
448884248519a8edade1b51aa7d20140b12764a9 |
|
23-Mar-2016 |
Evan Hunt <each@isc.org> |
[master] prep 9.11.0a1 |
98c5690bd930d71afb8a66937989f7ee50086723 |
|
10-Mar-2016 |
Mark Andrews <marka@isc.org> |
note rrsig regeneration |
7a3a30e29681599aa2b090e13cbd5931d994b793 |
|
04-Mar-2016 |
Mark Andrews <marka@isc.org> |
add AVC |
44c86318ed432af96848269250930297eea2bba3 |
|
04-Mar-2016 |
Evan Hunt <each@isc.org> |
[master] recursively clean empty interior nodes when deleting database records
4324. [bug] When deleting records from a zone database, interior
nodes could be left empty but not deleted, damaging
search performance afterward. [RT #40997] |
455c0848f80a8acda27aad1466c72987cafaa029 |
|
27-Feb-2016 |
Mark Andrews <marka@isc.org> |
4322. [security] Duplicate EDNS COOKIE options in a response could
trigger an assertion failure. (CVE-2016-2088)
[RT #41809] |
5995fec51cc8bb7e53804e4936e60aa1537f3673 |
|
21-Feb-2016 |
Mukund Sivaraman <muks@isc.org> |
Fix resolver assertion failure due to improper DNAME handling (CVE-2016-1286) (#41753) |
a2b15b3305acd52179e6f3dc7d073b07fbc40b8e |
|
17-Feb-2016 |
Mark Andrews <marka@isc.org> |
4318. [security] Malformed control messages can trigger assertions
in named and rndc. (CVE-2016-1285) [RT #41666] |
b5c22260e58adfed220bde499880f7e772d7876f |
|
29-Jan-2016 |
Evan Hunt <each@isc.org> |
[master] remove reporter's name per his request |
630b2d0c5a04cfc8b08d4585b7a0d997c00d7341 |
|
22-Jan-2016 |
Evan Hunt <each@isc.org> |
[master] NOSETFC incorrectly applied
4300. [bug] A flag could be set in the wrong field when setting
up nonrecursive queries; this could cause the
SERVFAIL cache to cache responses it shouldn't.
New querytrace logging has been added which
identified this error. [RT #41155] |
bb5d14d7243d71e03d262ff175b355b52873e195 |
|
08-Jan-2016 |
Evan Hunt <each@isc.org> |
[master] millisecond granularity for statschannel timers
4290. [func] The timers returned by the statistics channel
(indicating current time, server boot time, and
most recent reconfiguration time) are now reported
with millisecond accuracy. [RT #40082] |
455b99ed9266bce8a3b73e3462df8092ab0feb95 |
|
05-Jan-2016 |
Evan Hunt <each@isc.org> |
[master] fix ticket number |
c8b968f4144a271213756cc33e8062b9efdd7441 |
|
05-Jan-2016 |
Evan Hunt <each@isc.org> |
[master] fix use after free on xfr timeout
4289. [bug] The server could crash due to memory being used
after it was freed if a zone transfer timed out.
[RT #41297] |
41494939b62d74fb159009f28428df23e5fc70e3 |
|
05-Jan-2016 |
Evan Hunt <each@isc.org> |
[master] fixed bogus server regression
4288. [bug] Fixed a regression in resolver.c:possibly_mark()
which caused known-bogus servers to be queried
anyway. [RT #41321] |
e1836d1fe413cc14430ce89508e79c4c01df830b |
|
05-Jan-2016 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
43176d82c8eb2d8ed49614bbe7b7a3d2d6bbc6a5 |
|
04-Jan-2016 |
Evan Hunt <each@isc.org> |
[master] clean up notes |
292eb9c4e4fc51aec911e72821735a123a8c252a |
|
31-Dec-2015 |
Mark Andrews <marka@isc.org> |
4286. [security] render_ecs errors were mishandled when printing out
a OPT record resulting in a assertion failure.
(CVE-2015-8705) [RT #41397]
(cherry picked from commit 3e0c1603a835c678b07f1147909bf196988ee0d3) |
9c52f43036fb7099c71682b74c1ae1527a949ccc |
|
31-Dec-2015 |
Mark Andrews <marka@isc.org> |
remove period |
1b3d21180244529f0099894fe9d29beb3f11efb3 |
|
31-Dec-2015 |
Mark Andrews <marka@isc.org> |
4285. [security] Specific APL data could trigger a INSIST.
(CVE-2015-8704) [RT #41396] |
fbed5f0f44515f5b3ca499a3466c875507852970 |
|
26-Dec-2015 |
Evan Hunt <each@isc.org> |
[master] fix geoip options
4284. [bug] Some GeoIP options were incorrectly documented
using abbreviated forms which were not accepted by
named. The code has been updated to allow both
long and abbreviated forms. [RT #41381] |
8beb9bf514ad55f5dc3257c2c1848a1d72aad1ab |
|
18-Dec-2015 |
Mark Andrews <marka@isc.org> |
add dig +mapped |
6960e7fd121f866b4cd8d4d7d186f0d802175dcc |
|
15-Dec-2015 |
Mukund Sivaraman <muks@isc.org> |
Update notes.xml for #40996 |
4071efbec0e87b987aaf109f1ae8050aa8ecbcb8 |
|
03-Dec-2015 |
Evan Hunt <each@isc.org> |
[master] disallow map zones in response-policy
4269. [bug] Zones using "map" format master files currently
don't work as policy zones. This limitation has
now been documented; attempting to use such zones
in "response-policy" statements is now a
configuration error. [RT #38321] |
7bde79b32a8eac89ad43006a36c76ce09cb06885 |
|
03-Dec-2015 |
Mark Andrews <marka@isc.org> |
update description |
ff2f98076c29d932132107550317ae7fc4412f3c |
|
03-Dec-2015 |
Mark Andrews <marka@isc.org> |
Add CVE-2015-8461 |
cbc660172de0186af554c26b50056c67da1c1228 |
|
20-Nov-2015 |
Mark Andrews <marka@isc.org> |
spelling |
b57276f89eaa9c685c6b53ce90d21281e45a23b8 |
|
18-Nov-2015 |
Mark Andrews <marka@isc.org> |
note the address changes for H.ROOT-SERVERS.NET |
63042d5b579ae3d43104133007e55c224c698904 |
|
17-Nov-2015 |
Evan Hunt <each@isc.org> |
[master] typo |
c8821d124c532e0a65752b378f924d4259499fd3 |
|
16-Nov-2015 |
Mark Andrews <marka@isc.org> |
4260. [security] Insufficient testing when parsing a message allowed
records with an incorrect class to be be accepted,
triggering a REQUIRE failure when those records
were subsequently cached. (CVE-2015-8000) [RT #4098] |
8012e06abffd31ba0bdd1dbcfd5d2b262a935071 |
|
11-Nov-2015 |
Mukund Sivaraman <muks@isc.org> |
Update notes.xml for #40498 |
bfd4b9e11aa9e8c2b43022a6b7a896b26bd5d7a0 |
|
05-Nov-2015 |
Witold Krecicki <wpk@isc.org> |
4255. [func] Add 'message-compression' option to disable DNS compression in responses. [RT #40726] |
6b8519147a5c24b4a5942042e83fd539d0d445cc |
|
04-Nov-2015 |
Evan Hunt <each@isc.org> |
[master] NTAs did not survive reoad/reconfig
4251. [bug] NTAs were deleted when the server was reconfigured
or reloaded. [RT #41058] |
30eec077db2bdcb6f2a0dc388a3cdde2ede75ec1 |
|
22-Oct-2015 |
Mark Andrews <marka@isc.org> |
cleanup trailing white space in SGML like files |
90174e64f49bb7cba6a83fb665ebcb597aad7b57 |
|
17-Oct-2015 |
Evan Hunt <each@isc.org> |
[master] shorten default servfail-ttl
4239. [func] Changed default servfail-ttl value to 1 second from 10.
Also, the maximum value is now 30 instead of 300. [RT #37556] |
19c7b1a0293498a3e36692c59646ed6e15ffc8d0 |
|
07-Oct-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
14a656f94b1fd0ababd84a772228dfa52276ba15 |
|
06-Oct-2015 |
Evan Hunt <each@isc.org> |
[master] upgrade doc toolchain
4237. [doc] Upgraded documentation toolchain to use DocBook 5
and dblatex. [RT #40766] |
56ebb560a135323cb0a9da33426b229278e642f6 |
|
06-Oct-2015 |
Mukund Sivaraman <muks@isc.org> |
Fix notes and CHANGES for #40761 |
9260c1157d12ef716fe6227fd8af845ec7fd1eed |
|
03-Oct-2015 |
Mukund Sivaraman <muks@isc.org> |
Update CHANGES and notes.xml for #40761 |
930719e8767e0a58ca1b57cfbbb2b07b885afd14 |
|
03-Oct-2015 |
Mukund Sivaraman <muks@isc.org> |
Update the default value for number of UDP listeners (#40761) |
b66b333f59cf51ef87f973084a5023acd9317fb2 |
|
02-Oct-2015 |
Evan Hunt <each@isc.org> |
[master] dnstap
4235. [func] Added support in named for "dnstap", a fast method of
capturing and logging DNS traffic, and a new command
"dnstap-read" to read a dnstap log file. Use
"configure --enable-dnstap" to enable this
feature (note that this requires libprotobuf-c
and libfstrm). See the ARM for configuration details.
Thanks to Robert Edmonds of Farsight Security.
[RT #40211] |
a00f9e2f50675bd43cc6a9fe2669709162a2ccb4 |
|
29-Sep-2015 |
Evan Hunt <each@isc.org> |
[master] merge dyndb
4224. [func] Added support for "dyndb", a new interface for loading
zone data from an external database, developed by
Red Hat for the FreeIPA project.
DynDB drivers fully implement the BIND database
API, and are capable of significantly better
performance and functionality than DLZ drivers,
while taking advantage of advanced database
features not available in BIND such as multi-master
replication.
Thanks to Adam Tkac and Petr Spacek of Red Hat.
[RT #35271] |
f6e45a5c54b7af4b1c303e8d3ff3b7d78622df9e |
|
18-Sep-2015 |
Mark Andrews <marka@isc.org> |
4217. [protocol] Add support for CSYNC. [RT #40532] |
e0a30050c8516a3d54a4f8dcdd88435704a8a3ed |
|
17-Sep-2015 |
Mark Andrews <marka@isc.org> |
4214. [protocol] Add support for TALINK. [RT #40544] |
5a49f61ca968283d59c97e583fd6fb02ecaeb773 |
|
11-Sep-2015 |
Mark Andrews <marka@isc.org> |
4199. [protocol] Add support for NINFO, RKEY, SINK, TA.
[RT #40545] [RT #40547] [RT #40561] [RT #40563] |
a0ef8211d3bb5d4a7e56145e014c3da3466051c8 |
|
11-Sep-2015 |
Mark Andrews <marka@isc.org> |
4201. [func] The default preferred-glue is now the address record
type of the transport the query was received
over. [RT #40468] |
3fa134363f99816b36e30822a098196810ae6f20 |
|
10-Sep-2015 |
Mark Andrews <marka@isc.org> |
4200. [cleanup] win32: update BINDinstall to be BIND release
independent. [RT #38915] |
3dd63ba00f91f4d54ba45ba1831375950758c0a7 |
|
10-Sep-2015 |
Mark Andrews <marka@isc.org> |
4199. [protocol] Add support for NINFO, RKEY, TA.
[RT #40545] [RT #40547] [RT #40563] |
63874956de9673be49d4a75484514836dd27e6ed |
|
10-Sep-2015 |
Mark Andrews <marka@isc.org> |
4199. [protocol] Add support for NINFO, RKEY. [RT #40547] [RT #40563] |
8b29fc0b7a13db404f1a13fcfad42c2e7cfbe25b |
|
10-Sep-2015 |
Mark Andrews <marka@isc.org> |
4199. [protocol] Add support for RKEY. [RT #40563] |
4c9ead8b9f2d58bfff65f466577f37b178f19a1d |
|
27-Aug-2015 |
Evan Hunt <each@isc.org> |
[master] fix incorrect bug ID |
310f88d008f976a278121341f5b16666ff4db902 |
|
15-Aug-2015 |
Tinderbox User <tbox@isc.org> |
[master] fix the o umlaut for HTML and TXT too |
afc3103851e3876db36a9f17193c72b6bddd1b97 |
|
14-Aug-2015 |
Evan Hunt <each@isc.org> |
[master] add CVE number |
a73d9c0b4dbd6ad4cc8c9967d0b5627b3b43c6f7 |
|
13-Aug-2015 |
Tinderbox User <tbox@isc.org> |
support umlaut 'o' |
9716b6a5d61995a2f7d4af6489bd49baea4f8b69 |
|
13-Aug-2015 |
Evan Hunt <each@isc.org> |
[master] xml doesn't define ö |
c631ff56bfe13f7b47ff01950364f4db423bf21a |
|
13-Aug-2015 |
Mark Andrews <marka@isc.org> |
Updated CHANGES note to include require-server-cookie:
4152. [func] Implement DNS COOKIE option. This replaces the
experimental SIT option of BIND 9.10. The following
named.conf directives are available: send-cookie,
cookie-secret, cookie-algorithm, nocookie-udp-size
and require-server-cookie. The following dig options
are available: +[no]cookie[=value] and +[no]badcookie.
[RT #39928] |
c707e2b9861dfa3f86b3520b9c3630db70cb020c |
|
12-Aug-2015 |
Evan Hunt <each@isc.org> |
[master] fix length check in OPENPGPKEY
4170. [security] An incorrect boundary check in the OPENPGPKEY
rdatatype could trigger an assertion failure.
[RT #40286] |
ce9f893e21d2ffc6f6a78bf226c038c396740aeb |
|
07-Aug-2015 |
Evan Hunt <each@isc.org> |
[master] address buffer accounting error
4168. [security] A buffer accounting error could trigger an
assertion failure when parsing certain malformed
DNSSEC keys. (CVE-2015-5722) [RT #40212] |
d2f45d7ffdae0eb110ff2b388bca61ff8c9af361 |
|
05-Aug-2015 |
Evan Hunt <each@isc.org> |
[master] revert incorrect 'correction' |
7ed374872f00b5db110cb4f908e11c672a9426a4 |
|
31-Jul-2015 |
Evan Hunt <each@isc.org> |
[master] corrected relnotes -- assertion in name.c not message.c |
c5eb9add52241aab2e95f31b53bb911438bb38f5 |
|
14-Jul-2015 |
Mark Andrews <marka@isc.org> |
add CVE-2015-5477 |
1479200aa05414b2acf33607dbd1682c16f58c51 |
|
09-Jul-2015 |
Evan Hunt <each@isc.org> |
[master] DDoS mitigation features
3938. [func] Added quotas to be used in recursive resolvers
that are under high query load for names in zones
whose authoritative servers are nonresponsive or
are experiencing a denial of service attack.
- "fetches-per-server" limits the number of
simultaneous queries that can be sent to any
single authoritative server. The configured
value is a starting point; it is automatically
adjusted downward if the server is partially or
completely non-responsive. The algorithm used to
adjust the quota can be configured via the
"fetch-quota-params" option.
- "fetches-per-zone" limits the number of
simultaneous queries that can be sent for names
within a single domain. (Note: Unlike
"fetches-per-server", this value is not
self-tuning.)
- New stats counters have been added to count
queries spilled due to these quotas.
See the ARM for details of these options. [RT #37125] |
70d987def5a58ebeb8243017c0ec2e9b2c326cf4 |
|
07-Jul-2015 |
Evan Hunt <each@isc.org> |
[master] traffic size stats
4156. [func] Added statistics counters to track the sizes
of incoming queries and outgoing responses in
histogram buckets, as specified in RSSAC002.
[RT #39049] |
33ca26968b638b4ff9c657e9574d14d1a04a52dd |
|
06-Jul-2015 |
Mukund Sivaraman <muks@isc.org> |
Allow RPZ rewrite logging to be configured on a per-zone basis (#39754) |
ce67023ae3ad39a77da5361d0187ab6f3f0219cb |
|
06-Jul-2015 |
Mark Andrews <marka@isc.org> |
4152. [func] Implement DNS COOKIE option. This replaces the
experimental SIT option of BIND 9.10. The following
named.conf directives are avaliable: send-cookie,
cookie-secret, cookie-algorithm and nocookie-udp-size.
The following dig options are available:
+[no]cookie[=value] and +[no]badcookie. [RT #39928] |
f4d1c19691330d3494e877b2b04c7985af7dc829 |
|
16-Jun-2015 |
Mukund Sivaraman <muks@isc.org> |
Add comma |
572e95f52a2156ab6147e29dd271f94a6a533537 |
|
17-Jun-2015 |
Mark Andrews <marka@isc.org> |
add release notes for CVE-2015-4620 |
8c9fba44a41e3ea23e7e8405029980aba672f7ce |
|
04-Jun-2015 |
Evan Hunt <each@isc.org> |
[master] further RPZ fixes
4131. [bug] Addressed further problems with reloading RPZ
zones. [RT #39649] |
f5c20627f4660ef25334d4a7103ac2c7a8261bda |
|
21-May-2015 |
Evan Hunt <each@isc.org> |
[master] fix tags |
72a1c3f1a7ad790ebe13ef6be85c269b2c2dcb95 |
|
21-May-2015 |
Mukund Sivaraman <muks@isc.org> |
Update notes.xml and CHANGES for #39567 |
705cea35a8f798340ac947713ab97791be521b52 |
|
21-May-2015 |
Mukund Sivaraman <muks@isc.org> |
Fix RPZ radix tree search() for CLIENT-IP triggers (#39481) |
19365b43e922fcbaf5caff3f92b87b52cbc1b530 |
|
21-May-2015 |
Evan Hunt <each@isc.org> |
[master] ensure rpz summary consistence during AXFR updates
4121. [bug] When updating a response-policy zone via AXFR,
summary data about other policy zones could fall
out of sync. Ultimately this could trigger an
assertion failure in rpz.c. [RT #39567] |
7e6cf6fc6e700061a1cec3bcf67786706d956fc5 |
|
20-May-2015 |
Evan Hunt <each@isc.org> |
[master] address a possible policy update race
4120. [bug] A bug in RPZ could cause the server to crash if
policy zones were updated while recursion was
pending for RPZ processing of an active query.
[RT #39415] |
b947e1a521c6931f787d6d1b3604d5b138170c3d |
|
07-May-2015 |
Mukund Sivaraman <muks@isc.org> |
Fix a bug in RPZ that could cause unwanted recursion (#39229)
Conflicts:
doc/arm/notes.xml |
e77e44954909dd2e0af1ce724e01f4199ae1e9c0 |
|
25-Apr-2015 |
Mark Andrews <marka@isc.org> |
4109. [port] linux: support reading the local port range from
net.ipv4.ip_local_port_range. [RT # 39379] |
ef1aaab9ed44bcc6b58d85de2673e382dc6a7c1d |
|
23-Apr-2015 |
Evan Hunt <each@isc.org> |
[master] more verbose CHANGES note, added release note
4108. [func] An additional NXDOMAIN redirect method (option
"nxdomain-redirect") has been added, allowing
redirection to a specified DNS namespace instead
of a single redirect zone. [RT #37989] |
c82b3781158672e8308b53a8b6289e432ceb48d0 |
|
23-Apr-2015 |
Mark Andrews <marka@isc.org> |
4108. [func] A additional nxdomain redirect (nxdomain-redirect)
method is now supported. [RT #37989] |
fc3ed1dbda48d0e832ffc8ad70394cd475986531 |
|
15-Apr-2015 |
Evan Hunt <each@isc.org> |
[master] fix +split and +rrcomments with dig +short
4101. [bug] dig: the +split and +rrcomments options didn't
work with +short. [RT #39291] |
2637d30fbd235fe98145f4312b10cc41a13bf7dc |
|
13-Apr-2015 |
Jeremy C. Reed <jreed@isc.org> |
docbook <command> tags around named server references |
2b66b8b6fb5d4e34a0c2545c67d6bf831f75decd |
|
13-Apr-2015 |
Jeremy C. Reed <jreed@isc.org> |
fix mismatched docbook tag |
d9b37259f3abcb27e6b1b0bcb312c26cfd229fda |
|
08-Apr-2015 |
Evan Hunt <each@isc.org> |
[master] hold a reference on fetch context during query
4094. [bug] A race during shutdown or reconfiguration could
cause an assertion in mem.c. [RT #38979] |
f28e5058c33bfb99f8717d94c2525a976897dc91 |
|
07-Apr-2015 |
Evan Hunt <each@isc.org> |
[master] dig can now learn the SIT value when retrying
4093. [func] Dig now learns the SIT value from truncated
responses when it retries over TCP. [RT #39047] |
1b05d22789fd9a17aca4f459639bc2b6848c3160 |
|
04-Mar-2015 |
Mark Andrews <marka@isc.org> |
4082. [bug] Incrementally sign large inline zone deltas.
[RT #37927] |
ff295743c2b86e454f4c9ecb05460f8ab9b91ba8 |
|
04-Mar-2015 |
Evan Hunt <each@isc.org> |
[master] release note for change #4013 |
7ae96d882326357448f8f440c52f47ac1b1fa455 |
|
03-Mar-2015 |
Evan Hunt <each@isc.org> |
[master] add "lock-file" and fix up singleton code
4080. [func] Completed change #4022, adding a "lock-file" option
to named.conf to override the default lock file,
in addition to the "named -X <filename>" command
line option. Setting the lock file to "none"
using either method disables the check completely.
[RT #37908] |
84f95ddb2572641022619950a211aff49e331c98 |
|
01-Mar-2015 |
Mukund Sivaraman <muks@isc.org> |
Update win32 configure for --enable-querytrace (#37520)
Also enable querytrace when --enable-developer is specified. |
7acc2f21563b79229d592f09dde17e60d64afc8f |
|
23-Feb-2015 |
Evan Hunt <each@isc.org> |
[master] fix LOADPENDING issues
4063. [bug] Asynchronous zone loads were not handled
correctly when the zone load was already in
progress; this could trigger a crash in zt.c.
[RT #37573] |
591389c7d44e5ca20c357627dd179772cfefaacc |
|
06-Feb-2015 |
Evan Hunt <each@isc.org> |
[master] 5011 tests and fixes
4056. [bug] Expanded automatic testing of trust anchor
management and fixed several small bugs including
a memory leak and a possible loss of key state
information. [RT #38458]
4055. [func] "rndc managed-keys" can be used to check status
of trust anchors or to force keys to be refreshed,
Also, the managed keys data file has easier-to-read
comments. [RT #38458] |
1059bc2e42e8214f8b73d3b4cd181d8394a94a6a |
|
04-Feb-2015 |
Francis Dupont <fdupont@isc.org> |
added mdig tool |
801fb8b894c75fc1e3fa0284e096ade6dcdc1110 |
|
04-Feb-2015 |
Evan Hunt <each@isc.org> |
[master] avoid crash due to managed-key rollover
4053. [security] Revoking a managed trust anchor and supplying
an untrusted replacement could cause named
to crash with an assertion failure.
(CVE-2015-1349) [RT #38344] |
e3e783a0e9cd7b503f8b9b21acf7204e27459c40 |
|
02-Feb-2015 |
Mukund Sivaraman <muks@isc.org> |
Update notes.xml for #38454 |
6089bce129fbc96be0dc697feca3d3fbb6180a77 |
|
21-Jan-2015 |
Francis Dupont <fdupont@isc.org> |
missing '-' in keep-response-order |
2817aa56ca12139849ba1017ff978833174f6294 |
|
21-Jan-2015 |
Evan Hunt <each@isc.org> |
[master] "rndc modzone"
4043. [func] "rndc modzone" can be used to modify the
configuration of an existing zone, using similar
syntax to "rndc addzone". [RT #37895] |
b88b75c2b88618f9c885c61e1ab0bd1cddd4474e |
|
21-Jan-2015 |
Evan Hunt <each@isc.org> |
[master] correct CHANGES note |
761d135ed686601f36fe3d0d4aaa6bf41287bb0f |
|
21-Jan-2015 |
Evan Hunt <each@isc.org> |
[master] add TCP pipelining support
4040. [func] Added server-side support for pipelined TCP
queries. TCP connections are no longer closed after
the first query received from a client. (The new
"keep-response-order" option allows clients to be
specified for which the old behavior will still be
used.) [RT #37821] |
a6f0e9c985220f0e4509777e6528afb64e0ad576 |
|
12-Jan-2015 |
Mukund Sivaraman <muks@isc.org> |
Add NTA persistence (#37087)
4034. [func] When added, negative trust anchors (NTA) are now
saved to files (viewname.nta), in order to
persist across restarts of the named server.
[RT #37087] |
79521569952d5e2475f05e4397dc976f4685056e |
|
10-Jan-2015 |
Mark Andrews <marka@isc.org> |
4032. [bug] Built-in "empty" zones did not correctly inherit the
"allow-transfer" ACL from the options or view.
[RT #38310] |
b129f72d951663755496670606e5f7303e8f2dc2 |
|
08-Jan-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
74eb2f5cbc98d9646bcd13ffcb17688f0db5ab8d |
|
07-Jan-2015 |
Evan Hunt <each@isc.org> |
[master] rndc showzone / rndc delzone of non-added zones
4030. [func] "rndc delzone" is now applicable to zones that were
configured in named.conf, as well as zones that
were added via "rndc addzone". (Note, however, that
if named.conf is not also modified, the deleted zone
will return when named is reloaded.) [RT #37887]
4029. [func] "rndc showzone" displays the current configuration
of a specified zone. [RT #37887] |
47d837a49967a6a1b290024f5efb0669276013b1 |
|
17-Dec-2014 |
Mukund Sivaraman <muks@isc.org> |
Make named a singleton process [RT#37908]
Conflicts:
bin/tests/system/conf.sh.in
lib/dns/win32/libdns.def.in
lib/isc/win32/file.c
The merge also needed to update files in legacy and tcp system tests
(newly introduced in master after branch was created) to introduce use
of lockfile. |
be7fba80190c33b0e50f086509b42bb319bb95b4 |
|
16-Dec-2014 |
Evan Hunt <each@isc.org> |
[master] adjust max-recursion-queries
4021. [bug] Adjust max-recursion-queries to accommodate
the need for more queries when the cache is
empty. [RT #38104] |
03fd9cb81c2a92cf54baab5103db10e8ef9d524a |
|
05-Dec-2014 |
Mark Andrews <marka@isc.org> |
4020. [bug] Change 3736 broke nsupdate's SOA MNAME discovery
resulting in updates being sent to the wrong server.
[RT #37925] |
017aa9aef63aaef6a370c180f6290b8388deda01 |
|
05-Dec-2014 |
Mark Andrews <marka@isc.org> |
4019. [func] If named is not configured to validate the answer
then allow fallback to plain DNS on timeout even
when we know the server supports EDNS. [RT #37978] |
693d70f96fc2b3c1830580edcc29146afd6a9f61 |
|
03-Dec-2014 |
Mark Andrews <marka@isc.org> |
4017. [testing] Add system test to check lookups to legacy servers
with broken DNS behaviour. [RT #37965] |
ea3aa401bc74d34560af190a4009d436054d1bfa |
|
03-Dec-2014 |
Mark Andrews <marka@isc.org> |
4015. [bug] Nameservers that are skipped due to them being
CNAMEs were not being logged. They are now logged
to category 'cname' as per BIND 8. [RT #37935] |
92384667ff3bc059237849b3afd4c715c9164435 |
|
21-Nov-2014 |
Evan Hunt <each@isc.org> |
[master] delv +tcp
4009. [func] delv: added a +tcp option. [RT #37855] |
166a7500be8d4c925d6b4f54ea8981120933ad4e |
|
20-Nov-2014 |
Evan Hunt <each@isc.org> |
[master] add notes |
e32d354f754a5d7847a0862bcd6302827ea225bf |
|
15-Nov-2014 |
Evan Hunt <each@isc.org> |
[master] allow arbitrary-size rndc output
4005. [func] The buffer used for returning text from rndc
commands is now dynamically resizable, allowing
arbitrarily large amounts of text to be sent back
to the client. (Prior to this change, it was
possible for the output of "rndc tsig-list" to be
truncated.) [RT #37731] |
3cc8c7d63040a3eafde2b00e1f60465e7053208a |
|
05-Nov-2014 |
Evan Hunt <each@isc.org> |
[master] fix nxrrset in nxdomain redirection
4000. [bug] NXDOMAIN redirection incorrectly handled NXRRSET
from the redirect zone. [RT #37722] |
ce96d4326c872c8165b5e3a81ac5b49950c782c6 |
|
05-Nov-2014 |
Evan Hunt <each@isc.org> |
[master] new mkeys and nzf naming format
3999. [func] "mkeys" and "nzf" files are now named after
their corresponding views, unless the view name
contains characters that would be incompatible
with use in a filename (i.e., slash, backslash,
or capital letters). If a view name does contain
these characters, the files will still be named
using a cryptographic hash of the view name.
Regardless of this, if a file using the old name
format is found to exist, it will continue to be
used. [RT #37704] |
257d7508c89c0166e8e6f19f65d34e9de7daa390 |
|
03-Nov-2014 |
Mark Andrews <marka@isc.org> |
3997. [protocol] Add OPENGPGKEY record. [RT# 37671] |
d68f8db3eeba7ef77a8921a6682c0a216442e781 |
|
31-Oct-2014 |
Mark Andrews <marka@isc.org> |
add end of life statement |
f0a54842b1a50dac0b020958eb6025ed676f9a34 |
|
31-Oct-2014 |
Mark Andrews <marka@isc.org> |
3994. [func] Dig now supports setting the last unassigned DNS
header flag bit (dig +zflag). [RT #37421] |
0f5144163c44a67d9be986383769852a0dae502a |
|
30-Oct-2014 |
Mark Andrews <marka@isc.org> |
3993. [func] Dig now supports EDNS negotiation by default.
(dig +[no]ednsnegotiation). [RT #37604] |
f274cbeaed0e4c5fdbde9f5c30833d7f1da37cd3 |
|
30-Oct-2014 |
Mark Andrews <marka@isc.org> |
3992. [func] DiG can now send queries without questions
(dig +header-only). [RT #37599] |
00fb0253c9df8a4686115745ae91d501f62c7451 |
|
30-Oct-2014 |
Mark Andrews <marka@isc.org> |
3991. [func] Add the ability to buffer logging output by specifying
"buffered yes;" when defining a channel. [RT #26561] |
de41f327d9e5fff8b7e17dd3e2ee5ddef5f1d1c3 |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] missed a ticket number |
e179fcd4dca04c8b7aee0e6c18386bafc822c0a2 |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] [rt35857] relnote |
512e41f44d36d3c31eb9ad0ed0666450b3555f13 |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] [rt36945] relnote |
c69e3a95f017282f67640b4da9946d5d950dc194 |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] [rt36892] relnote |
a80fc8467d13e4dfabfd5eb470134878041da919 |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] [rt37138] relnote |
8f2a79879ea454ad0091341461ae26f06013c558 |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] [rt37159] relnote |
6e23e76b5d6f89d9d08f61ac57aead212452056f |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] [rt37172] relnote |
9d49dba3b7963cab8e76a4ce9191b51433d85184 |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] [rt37197] relnote |
44f1102bfbc8a9d1438e6c3583d573688aef6bca |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] [rt37410] relnote |
42fa62dd3100465bcd742ff2379b57cd2f14de28 |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] [rt37506] relnote |
7be3c12291467fa7450b2123c161ea8bfe13f1a1 |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] more relnotes backfill |
67c6b5edd034c445ccb6c36097d9fac4de21a542 |
|
22-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] backfill release notes |
4140a96f22b2319a658c17723c976ddff0e2633a |
|
21-Oct-2014 |
Mark Andrews <marka@isc.org> |
3987. [func] Allow the zone serial of a dynamically updatable
zone to be updated via rndc. [RT #37404] |
90e0af6bc6c1bcafad126e1779fc478c0aeaeb8f |
|
20-Oct-2014 |
Evan Hunt <each@isc.org> |
[master] include relnotes in doc
3982. [doc] Include release notes in product documentation.
[RT #37272] |