93ca8abdf86dfe69d40c0bc5389151e0672780af |
|
23-Jan-2018 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
92b0a8996988de11fbe721caac44370ebb534330 |
|
22-Jan-2018 |
Evan Hunt <each@isc.org> |
[v9_11] fix test failure by sorting "type" to the top of zone clauses |
40354825af06e1b97b74c0a27e3de30ee37a3899 |
|
22-Jan-2018 |
Evan Hunt <each@isc.org> |
[v9_11] silence warning |
1cf118a656f5fd210787908b845362077fc507f8 |
|
22-Jan-2018 |
Evan Hunt <each@isc.org> |
[v9_11] automatically generate named.conf grammars for the ARM
4873. [doc] Grammars for named.conf included in the ARM are now
automatically generated by the configuration parser
itself. As a side effect of the work needed to
separate zone type grammars from each other, this
also makes checking of zone statements in
named-checkconf more correct and consistent.
[RT #36957]
(cherry picked from commit 129c4414cb6cff8042f1985fe5833aaae6043142)
(cherry picked from commit f662d5484e0cf4cd83da300620b3701fee5a2ca1) |
ad9772c559c6aa42f8930f4acf1a2d833a08040a |
|
17-Oct-2017 |
Michał Kępień <m <michal@isc.org> |
[v9_11] Doxygen fixes and cleanups
4773. [doc] Fixed generating Doxygen documentation for functions
annotated using certain macros. Miscellaneous
Doxygen-related cleanups. [RT #46276]
(cherry picked from commit 2361003a887a09a07c393716d470370126bb5ff9) |
95ed40ff9a47da91cd46c1fed16f60190cac48b3 |
|
31-Aug-2017 |
Mark Andrews <marka@isc.org> |
sort view_clauses |
b5fb3f8722c905526d3867cd117e599daef419b9 |
|
14-Aug-2017 |
Mark Andrews <marka@isc.org> |
request-nsid/request-sit out of order
(cherry picked from commit bf1ab06a48b25989db692a1cff4775f16e27e7fd) |
8026cf576818f02e44585323548f0ad3c97659f5 |
|
14-Aug-2017 |
Mark Andrews <marka@isc.org> |
alphabetize options_clauses
(cherry picked from commit 60fd71ec66811ecc3c12fbec588c26f683d2b7d3) |
afb3bcade3ffa29dbdfd96e9d377cd53d1bd0948 |
|
14-Aug-2017 |
Mark Andrews <marka@isc.org> |
tcp-only and tcp-keepalive where out of alphabetical order
(cherry picked from commit 9697129ae2789fc2e384fbf3c306c9d05039a633) |
76e878e109a5039d2d301e56fbbb4ca326fa5741 |
|
14-Aug-2017 |
Mark Andrews <marka@isc.org> |
sit-secret was out of alphabetical order
(cherry picked from commit fa7bacca7d9b11884ddd5bd3f5b11f7a80ad48b7) |
324b00ad4950b00346f5ba2382a51709bd82afe9 |
|
14-Aug-2017 |
Mark Andrews <marka@isc.org> |
4678. [bug] geoip-use-ecs has the wrong type when geoip support
is disabled at configure time. [RT #45763]
(cherry picked from commit cc88df4f017508a2030abcc84c8197e0c4ce5f7d) |
af0d9b770594ece695cc9a7325ed42abb728a5f7 |
|
27-Apr-2017 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
3b38e4b8344cb3bb28f2b116d2e39f8371ef8e34 |
|
26-Apr-2017 |
Mukund Sivaraman <muks@isc.org> |
Set a LMDB mapsize and also provide a config option to control it (#44954)
(cherry picked from commit 241b49e6119eb37eebe2de98f0e8bde436074cb3) |
6ae22c411920be5f5fd1780ac0cd44cbb21b144a |
|
02-Dec-2016 |
Mukund Sivaraman <muks@isc.org> |
Add doc function for cfg_type_querysource4 and cfg_type_querysource6 (#43768)
(cherry picked from commit 5c843b384d7a22b7b6ff287bd581b18bb1bd5083) |
2a2335a013b5a0a40bacb50c136496b83da1885c |
|
30-Nov-2016 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
0c2d891abeb2b35e290ca9da29e1227110b5be23 |
|
29-Nov-2016 |
Mark Andrews <marka@isc.org> |
4520. [cleanup] Alphabetise more of the grammar when printing it
out. Fix unbalanced indenting. [RT #43755]
(cherry picked from commit 4352551d231346f28984b218775dcba0f5c19d7f) |
744c1db6352c4c3f11c8538e4a2a57c8b0e0d570 |
|
02-Nov-2016 |
Mark Andrews <marka@isc.org> |
4504. [security] Allow the maximum number of records in a zone to
be specified. This provides a control for issues
raised in CVE-2016-6170. [RT #42143]
(cherry picked from commit 5f8412a4cb5ee14a0e8cddd4107854b40ee3291e) |
bd19cef22382906a11fb6f1ffdef11038e432bca |
|
01-Nov-2016 |
Mark Andrews <marka@isc.org> |
4502. [func] Report multiple and experimental options when printing
grammar. [RT #43134]
(cherry picked from commit 89286906dc8bbe058060ee1a51d2a89426d14e2f) |
94694e720a911a38b01ff5036c01d883b3c9cbb1 |
|
11-Oct-2016 |
Evan Hunt <each@isc.org> |
[v9_11] add cfg_parse_buffer3() function with linenum parameter
4482. [cleanup] Change #4455 was incomplete. [RT #43252]
(cherry picked from commit 676ac3cc8234dafcbab053554c657113e811e562) |
7204d08a319cf590ae4280b8cc20999320398574 |
|
18-Aug-2016 |
Mark Andrews <marka@isc.org> |
4447. [tuning] Allow the fstrm_iothr_init() options to be set using
named.conf to control how dnstap manages the data
flow. [RT #42974]
(cherry picked from commit 934837913ff197b1a10ad027705d4497fae21e59) |
4d09627fde8fcdd17dd46b865ef238cf0f87ca8f |
|
15-Aug-2016 |
Mark Andrews <marka@isc.org> |
don't return void
(cherry picked from commit 42a14518ac471f6ab5f6994bc2b315406651755e) |
2fb6d3782b548ba678cfb8ff09e0d1e49fafb84d |
|
12-Aug-2016 |
Mark Andrews <marka@isc.org> |
4437. [func] Minimal-responses now has two additional modes
no-auth and no-auth-recursive which suppress
adding the NS records to the authority section
as well as the associated address records for the
nameservers. [RT #42005]
(cherry picked from commit 78e31dd18798f22828059b0f5cbc1c984c7e142c) |
b7161f9898405faee05ba72a63ad10e4541f1346 |
|
22-Jul-2016 |
Mark Andrews <marka@isc.org> |
4424. [experimental] Named now sends _ta-XXXX.<trust-anchor>/NULL queries
to provide feedback to the trust-anchor administrators
about how key rollovers are progressing as per
draft-ietf-dnsop-edns-key-tag-02. This can be
disabled using 'trust-anchor-telemetry no;'.
[RT #40583]
(cherry picked from commit f20179857a8512441c3be7ad33f1c84e367de041) |
0c27b3fe77ac1d5094ba3521e8142d9e7973133f |
|
27-Jun-2016 |
Mark Andrews <marka@isc.org> |
4401. [misc] Change LICENSE to MPL 2.0. |
3d0b7d5cc3428dedf4486e949fbd536eef494b99 |
|
31-May-2016 |
Evan Hunt <each@isc.org> |
[master] zone-directory option for catalog zones
4380. [experimental] Added a "zone-directory" option to "catalog-zones"
syntax, allowing local masterfiles for slaves
that are provisioned by catalog zones to be stored
in a directory other than the server's working
directory. [RT #42527] |
7a00d69909ace5dc11bcff9c1e07c311f92a7f8e |
|
26-May-2016 |
Witold Krecicki <wpk@isc.org> |
4376. [experimental] Added support for Catalog Zones, a new method for
provisioning secondary servers in which a list of
zones to be served is stored in a DNS zone and can
be propagated to slaves via AXFR/IXFR. [RT #41581]
4375. [func] Add support for automatic reallocation of isc_buffer
to isc_buffer_put* functions. [RT #42394] |
0cbe448914be61d0f92b1e9d3adaeba87d25639d |
|
25-May-2016 |
Evan Hunt <each@isc.org> |
[master] minimal-any
4371. [func] New "minimal-any" option reduces the size of UDP
responses for qtype ANY by returning a single
arbitrarily selected RRset instead of all RRsets.
Thanks to Tony Finch. [RT #41615] |
f89adb2c2a52b505501c3eaa2aec9fd4df6bd60a |
|
06-May-2016 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
08e36aa5a5c7697a839f83831fccf8fb3f792848 |
|
05-May-2016 |
Mark Andrews <marka@isc.org> |
4356. [func] Add the ability to specify whether to wait for
nameserver addresses to be looked up or not to
rpz with a new modifying directive 'nsip-wait-recurse'. [RT #35009] |
fbed5f0f44515f5b3ca499a3466c875507852970 |
|
26-Dec-2015 |
Evan Hunt <each@isc.org> |
[master] fix geoip options
4284. [bug] Some GeoIP options were incorrectly documented
using abbreviated forms which were not accepted by
named. The code has been updated to allow both
long and abbreviated forms. [RT #41381] |
ecc06cbc32c5a2b91a17e65c1820c9c66313d35c |
|
15-Dec-2015 |
Mukund Sivaraman <muks@isc.org> |
Use optimal message sizes to improve compression in AXFRs (#40996) |
dd784c18ef799e9e35c9debe34323c50d4e7f8a5 |
|
16-Nov-2015 |
Francis Dupont <fdupont@isc.org> |
Merged VS 2015 64 bit warnings (#40373) |
58f7af60e79a5aaf58f6a8861c306d4c617fb1d1 |
|
11-Nov-2015 |
Mukund Sivaraman <muks@isc.org> |
Allow non-destructive control channel access using a "read-only" clause (#40498) |
bfd4b9e11aa9e8c2b43022a6b7a896b26bd5d7a0 |
|
05-Nov-2015 |
Witold Krecicki <wpk@isc.org> |
4255. [func] Add 'message-compression' option to disable DNS compression in responses. [RT #40726] |
72ac929f2bfe186ab4fe2d9425685d6ef419f200 |
|
28-Oct-2015 |
Mark Andrews <marka@isc.org> |
4244. [bug] The parser was not reporting that use-ixfr is obsolete.
[RT #41010] |
a625502bdd149be06bd0cc06000c3dc9e4a813b9 |
|
03-Oct-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
b66b333f59cf51ef87f973084a5023acd9317fb2 |
|
02-Oct-2015 |
Evan Hunt <each@isc.org> |
[master] dnstap
4235. [func] Added support in named for "dnstap", a fast method of
capturing and logging DNS traffic, and a new command
"dnstap-read" to read a dnstap log file. Use
"configure --enable-dnstap" to enable this
feature (note that this requires libprotobuf-c
and libfstrm). See the ARM for configuration details.
Thanks to Robert Edmonds of Farsight Security.
[RT #40211] |
a00f9e2f50675bd43cc6a9fe2669709162a2ccb4 |
|
29-Sep-2015 |
Evan Hunt <each@isc.org> |
[master] merge dyndb
4224. [func] Added support for "dyndb", a new interface for loading
zone data from an external database, developed by
Red Hat for the FreeIPA project.
DynDB drivers fully implement the BIND database
API, and are capable of significantly better
performance and functionality than DLZ drivers,
while taking advantage of advanced database
features not available in BIND such as multi-master
replication.
Thanks to Adam Tkac and Petr Spacek of Red Hat.
[RT #35271] |
e6d0a391f5f9b18f5bd497aefff269e474ee560c |
|
28-Sep-2015 |
Witold Krecicki <wpk@isc.org> |
4223. [func] Add support for setting max-cache-size to percentage
of available physical memory, set default to 90%.
[RT #38442] |
98a7f8c7ae44bb98d5469cb3a4240c59abceba7f |
|
28-Sep-2015 |
Mark Andrews <marka@isc.org> |
4222. [func] Bias IPv6 servers when selecting the next server to
query. [RT #40836] |
2592ee16b5f1fe17b59f73433abb7d55b4c241bb |
|
18-Sep-2015 |
Mark Andrews <marka@isc.org> |
document optional class |
03fac9f93189263f44186bc38e9097df6d9adb2f |
|
18-Sep-2015 |
Mark Andrews <marka@isc.org> |
document that the syslog facility is optional |
4ca7391e640bd4f0abb31508019d3bd62819fa8e |
|
09-Sep-2015 |
Mark Andrews <marka@isc.org> |
4196. [doc] Improve how "enum + other" types are documented.
[RT #40608]
4195. [bug] 'max-zone-ttl unlimited;' was broken. [RT #40608] |
fbd9aaa58c32abaeab1bd3ca6943b18ce19ea023 |
|
09-Sep-2015 |
Mark Andrews <marka@isc.org> |
4194. [bug] named-checkconf -p failed to properly print a port
range. [RT #40634] |
c631ff56bfe13f7b47ff01950364f4db423bf21a |
|
13-Aug-2015 |
Mark Andrews <marka@isc.org> |
Updated CHANGES note to include require-server-cookie:
4152. [func] Implement DNS COOKIE option. This replaces the
experimental SIT option of BIND 9.10. The following
named.conf directives are available: send-cookie,
cookie-secret, cookie-algorithm, nocookie-udp-size
and require-server-cookie. The following dig options
are available: +[no]cookie[=value] and +[no]badcookie.
[RT #39928] |
1479200aa05414b2acf33607dbd1682c16f58c51 |
|
09-Jul-2015 |
Evan Hunt <each@isc.org> |
[master] DDoS mitigation features
3938. [func] Added quotas to be used in recursive resolvers
that are under high query load for names in zones
whose authoritative servers are nonresponsive or
are experiencing a denial of service attack.
- "fetches-per-server" limits the number of
simultaneous queries that can be sent to any
single authoritative server. The configured
value is a starting point; it is automatically
adjusted downward if the server is partially or
completely non-responsive. The algorithm used to
adjust the quota can be configured via the
"fetch-quota-params" option.
- "fetches-per-zone" limits the number of
simultaneous queries that can be sent for names
within a single domain. (Note: Unlike
"fetches-per-server", this value is not
self-tuning.)
- New stats counters have been added to count
queries spilled due to these quotas.
See the ARM for details of these options. [RT #37125] |
33ca26968b638b4ff9c657e9574d14d1a04a52dd |
|
06-Jul-2015 |
Mukund Sivaraman <muks@isc.org> |
Allow RPZ rewrite logging to be configured on a per-zone basis (#39754) |
ce67023ae3ad39a77da5361d0187ab6f3f0219cb |
|
06-Jul-2015 |
Mark Andrews <marka@isc.org> |
4152. [func] Implement DNS COOKIE option. This replaces the
experimental SIT option of BIND 9.10. The following
named.conf directives are avaliable: send-cookie,
cookie-secret, cookie-algorithm and nocookie-udp-size.
The following dig options are available:
+[no]cookie[=value] and +[no]badcookie. [RT #39928] |
8aecc50f0d3aa2f91a2b2d2d5e320c52f6f250f1 |
|
23-Jun-2015 |
Mukund Sivaraman <muks@isc.org> |
Remove backwards compatibility grammar (#39845)
This was not done in the previous merge commit, so that it could be
merged cleanly into release branches. |
0439bfedd97fa2e004cbf572773d703b33fda10f |
|
23-Jun-2015 |
Mukund Sivaraman <muks@isc.org> |
Fix parsing of NZFs saved by rndc addzone with view specified (#39845) |
6c0c85563f461b4dd5fea3c4a768d547eaaf0bd6 |
|
05-Jun-2015 |
Mark Andrews <marka@isc.org> |
update comment as per rt39703 |
c82b3781158672e8308b53a8b6289e432ceb48d0 |
|
23-Apr-2015 |
Mark Andrews <marka@isc.org> |
4108. [func] A additional nxdomain redirect (nxdomain-redirect)
method is now supported. [RT #37989] |
f1a261ba2d5e11a106a0a95c46b409a9daf138ef |
|
17-Apr-2015 |
Mark Andrews <marka@isc.org> |
4104. [bug] Address uninitialized elements. [RT #39252] |
7ae96d882326357448f8f440c52f47ac1b1fa455 |
|
03-Mar-2015 |
Evan Hunt <each@isc.org> |
[master] add "lock-file" and fix up singleton code
4080. [func] Completed change #4022, adding a "lock-file" option
to named.conf to override the default lock file,
in addition to the "named -X <filename>" command
line option. Setting the lock file to "none"
using either method disables the check completely.
[RT #37908] |
761d135ed686601f36fe3d0d4aaa6bf41287bb0f |
|
21-Jan-2015 |
Evan Hunt <each@isc.org> |
[master] add TCP pipelining support
4040. [func] Added server-side support for pipelined TCP
queries. TCP connections are no longer closed after
the first query received from a client. (The new
"keep-response-order" option allows clients to be
specified for which the old behavior will still be
used.) [RT #37821] |
b129f72d951663755496670606e5f7303e8f2dc2 |
|
08-Jan-2015 |
Tinderbox User <tbox@isc.org> |
update copyright notice / whitespace |
74eb2f5cbc98d9646bcd13ffcb17688f0db5ab8d |
|
07-Jan-2015 |
Evan Hunt <each@isc.org> |
[master] rndc showzone / rndc delzone of non-added zones
4030. [func] "rndc delzone" is now applicable to zones that were
configured in named.conf, as well as zones that
were added via "rndc addzone". (Note, however, that
if named.conf is not also modified, the deleted zone
will return when named is reloaded.) [RT #37887]
4029. [func] "rndc showzone" displays the current configuration
of a specified zone. [RT #37887] |
5c5c6d289db78e41f714007426a387498e15963c |
|
02-Dec-2014 |
Francis Dupont <fdupont@isc.org> |
Add a TCP only option to server/peer |
c4f54e5bd1cd09f601252627b5b26768ab797742 |
|
19-Nov-2014 |
Evan Hunt <each@isc.org> |
[master] add max-recursion-queries
also fixes and documentation for max-recursion-depth |
3230429e175dcaafe9c59967124d44c02ca0ccad |
|
18-Nov-2014 |
Evan Hunt <each@isc.org> |
[master] limit recursion depth and iterative queries
4006. [security] A flaw in delegation handling could be exploited
to put named into an infinite loop. This has
been addressed by placing limits on the number
of levels of recursion named will allow (default 7),
and the number of iterative queries that it will
send (default 50) before terminating a recursive
query (CVE-2014-8500).
The recursion depth limit is configured via the
"max-recursion-depth" option. [RT #35780] |
00fb0253c9df8a4686115745ae91d501f62c7451 |
|
30-Oct-2014 |
Mark Andrews <marka@isc.org> |
3991. [func] Add the ability to buffer logging output by specifying
"buffered yes;" when defining a channel. [RT #26561] |
10c12aa5493f34920585164c5fb54a7ac9109fbd |
|
29-Sep-2014 |
Mark Andrews <marka@isc.org> |
3956. [func] Notify messages are now rate limited by notify-rate and
startup-notify-rate instead of serial-query-rate.
[RT #24454]
3955. [bug] Notify messages due to changes are no longer queued
behind startup notify messages. [RT #24454] |
947cf282a721b089c1106780f13ae8e6298bddb1 |
|
10-Sep-2014 |
Mark Andrews <marka@isc.org> |
3949. [experimental] Experimental support for draft-andrews-edns1 by sending
EDNS(1) queries (define DRAFT_ANDREWS_EDNS1 when
building). Add support for limiting the EDNS version
advertised to servers: server { edns-version 0; };
Log the EDNS version received in the query log.
[RT #35864] |
a8783019814daa36dd57afe3f527462822834c3b |
|
04-Sep-2014 |
Evan Hunt <each@isc.org> |
[master] servfail cache
3943. [func] SERVFAIL responses can now be cached for a
limited time (configured by "servfail-ttl",
default 10 seconds, limit 30). This can reduce
the frequency of retries when an authoritative
server is known to be failing, e.g., due to
ongoing DNSSEC validation problems. [RT #21347] |
d46855caedd5cb101795707f6f467fa363ef1448 |
|
29-Aug-2014 |
Evan Hunt <each@isc.org> |
[master] ECS authoritative support
3936. [func] Added authoritative support for the EDNS Client
Subnet (ECS) option.
ACLs can now include "ecs" elements which specify
an address or network prefix; if an ECS option is
included in a DNS query, then the address encoded
in the option will be matched against "ecs" ACL
elements.
Also, if an ECS address is included in a query,
then it will be used instead of the client source
address when matching "geoip" ACL elements. This
behavior can be overridden with "geoip-use-ecs no;".
When "ecs" or "geoip" ACL elements are used to
select a view for a query, the response will include
an ECS option to indicate which client network the
answer is valid for.
(Thanks to Vincent Bernat.) [RT #36781] |
11649973111d83027faf08ed4fb36a2b3c29c875 |
|
26-Aug-2014 |
Mark Andrews <marka@isc.org> |
3931. [cleanup] Cleanup how dlz grammer is defined. [RT #36879] |
be5d42f255e6c961233cb81d78e6e20ba6690870 |
|
25-Aug-2014 |
Mark Andrews <marka@isc.org> |
dlz clauses are not inheritable |
15a885dfc6358c674a41e3de12a806b3fb4321c0 |
|
16-Aug-2014 |
Mark Andrews <marka@isc.org> |
remove duplicate request-ixfr rt36878
(cherry picked from commit 0a484c39fc85752925bb3231b1b566420437a1e3) |
b47839a675daea42bdceee6b144abbac498e9772 |
|
06-Aug-2014 |
Mark Andrews <marka@isc.org> |
alphabetize zone_clauses |
43b9737b11f4f14b2d378746d0cd5561b1dc24a0 |
|
06-Aug-2014 |
Mark Andrews <marka@isc.org> |
3911. [func] Implement EDNS EXPIRE option client side. [RT #35925] |
0e50e5020667001585f29ef607e9874a2a1d43a7 |
|
22-Jul-2014 |
Mark Andrews <marka@isc.org> |
alphabetize server_clauses |
b8a9632333a92d73a503afe1aaa7990016c8bee9 |
|
19-Jun-2014 |
Evan Hunt <each@isc.org> |
[master] complete NTA work
3882. [func] By default, negative trust anchors will be tested
periodically to see whether data below them can be
validated, and if so, they will be allowed to
expire early. The "rndc nta -force" option
overrides this behvaior. The default NTA lifetime
and the recheck frequency can be configured by the
"nta-lifetime" and "nta-recheck" options. [RT #36146] |
896f49f8bdee644cd8d10e320ea3084ca3f74e2a |
|
16-May-2014 |
Evan Hunt <each@isc.org> |
[master] increase and allow configuration of lwresd tasks/clients
3852. [func] Increase the default number of clients available
for servicing lightweight resolver queries, and
make them configurable via the "lwres-tasks" and
"lwres-clients" options. (Thanks to Tomas Hozza.)
[RT #35857] |
ec3b216506b715f10e0b653afc20068ce8c5aa79 |
|
18-Apr-2014 |
Evan Hunt <each@isc.org> |
[master] masterfile-style
3814. [func] The "masterfile-style" zone option controls the
formatting of dumped zone files. Options are
"relative" (multiline format) and "full" (one
record per line). The default is "relative".
[RT #20798] |
7318bbc26262a66a0d740ceefed769961ef7e476 |
|
18-Apr-2014 |
Evan Hunt <each@isc.org> |
[master] serial-update-method date;
3811. [func] "serial-update-method date;" sets serial number
on dynamic update to today's date in YYYYMMDDNN
format. (Thanks to Bradley Forschinger.) [RT #24903] |
b0d80023540e70c03b911633735a41284d1d72d6 |
|
26-Feb-2014 |
Mark Andrews <marka@isc.org> |
use cfg_type_sstring rather than cfg_type_qstring for sit-secret |
5e45c8aabfad8f0c7995c4b8cf27690c1395ef8d |
|
20-Feb-2014 |
Mark Andrews <marka@isc.org> |
add CFG_CLAUSEFLAG_NOTCONFIGURED flag |
35f6a21f5f8114542c050bfcb484b39ce513d4bd |
|
19-Feb-2014 |
Evan Hunt <each@isc.org> |
[master] max-zone-ttl
3746. [func] New "max-zone-ttl" option enforces maximum
TTLs for zones. If loading a zone containing a
higher TTL, the load fails. DDNS updates with
higher TTLs are accepted but the TTL is truncated.
(Note: Currently supported for master zones only;
inline-signing slaves will be added.) [RT #38405] |
b5f6271f4daf1e54501af2cb7dd278d7e8003d65 |
|
18-Feb-2014 |
Mark Andrews <marka@isc.org> |
3744. [experimental] SIT: send and process Source Identity Tokens
(which are similar to DNS Cookies by Donald Eastlake)
and are designed to help clients detect off path
spoofed responses and for servers to detect legitimate
clients.
SIT use a experimental EDNS option code (65001).
SIT can be enabled via --enable-developer or
--enable-sit. It is on by default in Windows.
RRL processing as been updated to know about SIT with
legitimate clients not being rate limited. [RT #35389] |
62ec9fd1681ffae7d6b0d54618599ecf650e3100 |
|
07-Feb-2014 |
Mark Andrews <marka@isc.org> |
3733. [func] Improve interface scanning support. Interface
information will be automatically updated if the
OS supports routing sockets. Use
"automatic-interface-scan no;" to disable.
Add "rndc scan" to trigger a scan. [RT #23027] |
166341d55424ca522eb456a1c7d0211e391f1ac8 |
|
07-Feb-2014 |
Evan Hunt <each@isc.org> |
[master] add no-case-compress
3731. [func] Added a "no-case-compress" ACL, which causes
named to use case-insensitive compression
(disabling change #3645) for specified
clients. (This is useful when dealing
with broken client implementations that
use case-sensitive name comparisons,
rejecting responses that fail to match the
capitalization of the query that was sent.)
[RT #35300] |
fb756ba3047770957173ba546257ca43af7ba3e4 |
|
12-Jan-2014 |
Mark Andrews <marka@isc.org> |
3703. [func] Prefetch about to expire records if they are queried
for, see prefetch option for details. [RT #35041] |
ff6de396a93b9b73a37173059a595f3d295b57cb |
|
10-Jan-2014 |
Mark Andrews <marka@isc.org> |
3701. [func] named-checkconf can now suppress the printing of
shared secrets by specifying '-x'. [RT #34465] |
431a83fb29482c5170b3e4026e59bb14849a6707 |
|
10-Jan-2014 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
e851ea826066ac5a5b01c2c23218faa0273a12e8 |
|
09-Jan-2014 |
Evan Hunt <each@isc.org> |
[master] replace memcpy() with memmove().
3698. [cleanup] Replaced all uses of memcpy() with memmove().
[RT #35120] |
434bfc3dfa2003ba0dd4b2392286806131fd6724 |
|
14-Nov-2013 |
Evan Hunt <each@isc.org> |
[master] "in-view" zone option
3673. [func] New "in-view" zone option allows direct sharing
of zones between views. [RT #32968] |
e543b4e5dbf929c4298532b6ce0c8e8c6bfd9b74 |
|
01-Aug-2013 |
Mark Andrews <marka@isc.org> |
remove redundent 'request-ixfr' |
421d4a06479e61fbdc35087f3c4abc9fe65ad72a |
|
12-Jul-2013 |
Evan Hunt <each@isc.org> |
[master] rpz work
3620. [func] Added "rpz-client-ip" policy triggers, enabling
RPZ responses to be configured on the basis of
the client IP address; this can be used, for
example, to blacklist misbehaving recursive
or stub resolvers. [RT #33605]
3619. [bug] Fixed a bug in RPZ with "recursive-only no;"
[RT #33776] |
26bb3b7a67b833f0a18072567de036226890ca1a |
|
30-Apr-2013 |
Mark Andrews <marka@isc.org> |
3559. [func] Check that both forms of Sender Policy Framework
records exist or do not exist. [RT #33355] |
a6d43d18b1f6164fd144b2fa25ea57f5566b3bf9 |
|
25-Apr-2013 |
Evan Hunt <each@isc.org> |
[master] fixed several RRL issues
3554. [bug] RRL failed to correctly rate-limit upward
referrals and failed to count dropped error
responses in the statistics. [RT #33225] |
1e9f7a42bcfdfaa0ad314bed46e6c1297cdd0348 |
|
23-Mar-2013 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
67adc03ef81fb610f8df093b17f55275ee816754 |
|
22-Mar-2013 |
Evan Hunt <each@isc.org> |
[master] add DSCP support
3535. [func] Add support for setting Differentiated Services Code
Point (DSCP) values in named. Most configuration
options which take a "port" option (e.g.,
listen-on, forwarders, also-notify, masters,
notify-source, etc) can now also take a "dscp"
option specifying a code point for use with
outgoing traffic, if supported by the underlying
OS. [RT #27596] |
9cc2e4b4ab78e430bd32402d8ac21e5fb4ae39a6 |
|
28-Feb-2013 |
Evan Hunt <each@isc.org> |
[master] ifdef around geoip syntax in parser |
501941f0b6cce74c2ff75b10aff3f230d5d37e4c |
|
28-Feb-2013 |
Evan Hunt <each@isc.org> |
[master] add geoip support
3504. [func] Add support for ACLs based on geographic location,
using MaxMind GeoIP databases. Based on code
contributed by Ken Brownfield <kb@slide.com>.
[RT #30681] |
40a7e85f3ee3bd66a8f87bf8af674e1e48b05396 |
|
27-Feb-2013 |
Evan Hunt <each@isc.org> |
[master] better zone-statistics syntax
3501. [func] zone-statistics now takes three options: full,
terse, and none. "yes" and "no" are retained as
synonyms for full and terse, respectively. [RT #29165] |
94315060c2b0d9deafabe72d6a0482405fd9d377 |
|
25-Feb-2013 |
Evan Hunt <each@isc.org> |
[master] RPZ speedup (phase 2, multiple RPZ's)
3495. [func] Support multiple response-policy zones, while
improving RPZ performance. [RT #32476] |
55e5c51e661e23e24573db84114a3837817745c9 |
|
25-Feb-2013 |
Evan Hunt <each@isc.org> |
[master] DNS RRL
3494. [func] DNS RRL: Blunt the impact of DNS reflection and
amplification attacks by rate-limiting substantially-
identical responses. [RT #28130] |
17131a9459e5b30f764bc77f4fed288907a5b5e0 |
|
26-Jan-2013 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
c9611b45736af157e2993c6ef852e55e8e24ca83 |
|
24-Jan-2013 |
Evan Hunt <each@isc.org> |
[master] change "fast" to "map"
3475. [cleanup] Changed name of 'map' zone file format (previously
'fast'). [RT #32458] |
2b8bed6681d1541474f022586cbe728dfce36880 |
|
06-Dec-2012 |
Evan Hunt <each@isc.org> |
[master] multiple-dlz/dlz-nxdomain
3432. [func] Multiple DLZ databases can now be configured.
DLZ databases are searched in the order configured,
unless set to "search no", in which case a
zone can be configured to be retrieved from a
particular DLZ database by using a "dlz <name>"
option in the zone statement. DLZ databases can
support type "master" and "redirect" zones.
[RT #27597] |
058e44186b74531402c1f99088eb9dbe4926f8da |
|
02-Oct-2012 |
Mark Andrews <marka@isc.org> |
3387. [func] Support for a DS digest can be disabled at
runtime with disable-ds-digests. [RT #21581] |
7829fad4093f2c1985b1efb7cea00287ff015d2b |
|
20-Jun-2012 |
ckb <ckb@isc.org> |
merging fast format zone files
Conflicts:
.gitignore
bin/named/zoneconf.c
bin/tests/.gitignore
bin/tests/system/autosign/tests.sh
bin/tests/system/masterformat/clean.sh
bin/tests/system/masterformat/ns1/compile.sh
bin/tests/system/masterformat/tests.sh
configure
lib/dns/db.c
lib/dns/include/dns/db.h
lib/dns/include/dns/types.h
lib/dns/master.c
lib/dns/masterdump.c
lib/dns/rbt.c
lib/dns/rbtdb.c
lib/dns/sdb.c
lib/dns/sdlz.c
lib/dns/tests/.cvsignore
lib/dns/tests/Makefile.in
lib/dns/win32/libdns.def
lib/dns/xfrin.c
lib/dns/zone.c
lib/export/dns/Makefile.in
lib/isc/include/isc/file.h
lib/isc/unix/file.c
lib/isc/win32/file.c
lib/isccfg/namedconf.c |
7865ea9545f28f12f046b32d24c989e8441b9812 |
|
14-Jun-2012 |
Mark Andrews <marka@isc.org> |
3339. [func] Allow the maximum supported rsa exponent size to be specified: "max-rsa-exponent-size <value>;" [RT #29228] |
afaa290bb6acc504e93a0adbf20b6dd6c64e6d63 |
|
31-May-2012 |
Vernon Schryver <vjs@isc.org> |
Squashed commit of the following:
commit aea73609ac5d41ed091360e94370798965f28f05
commit eef7f44c57a060b24a426eb8888e16176a0a69b1
commit a88a26d864ad399fa2d40e3b9659b4d26f454ca1
commit 1b90d59568e7e3b65690c6bd075cf4d60b03e454
Merge: 74d8f73 cd02924
commit 74d8f73ed553bb64a305e284905762f7ff0029aa
commit 9a59ef6bbd4befe91e5691e8b85afe1cb7ab0706
commit c63606a53b4f1bb7066b37d3cfe588e9dc21a119
commit 2c392a840c8838455d144ce163bd873bee400c97
commit 0241f53563e6e7bed462a883d98a8931f01e0980
commit 79fe22b5d6f04bdaa3073cf54d41952194e879e1
commit 351b3049625f2edd39729dd85413e961b97d4b3b
commit 7207674fc77c9a10d84c0cb94e36d1c09bb31459
commit 543ad34cf08f901c20b438c9d2f45482cff13d5e
commit fc45b99ce4438627fdcbeb4365695ba0065fa46f
commit c425207f57e0a5157372aa7edbb79b13170563e5
commit ef8c5e23ca284e0ea02f69ce1f356d537c19d93b
commit ba0d4e3aa51efe412cfa1d031651f949442d1802
commit 41c7969c7cb6884b93011f7ace3fd9522efc021e
and more from CVS
for rt26172
Add
- optional "recursive-only yes|no" to the response-policy statement
- optional max-policy-ttl to limit the lies that "recursive-only no"
can introduce into resolvers' caches
- test that queries with RD=0 are not rewritten by default
- performance smoke test
Change encoding of PASSTHRU action to "rpz-passthru".
(The old encoding is still accepted.)
Fix rt26180 assert botch in zone_findrdataset() in this branch
as well.
Fix missing signatures on NOERROR results despite RPZ hits
when there are signatures and the client asks for DNSSEC, |
d878b8d87c3f46a25ccae9f5cfe6e39af67562e0 |
|
14-May-2012 |
Evan Hunt <each@isc.org> |
merged filter-aaaa-on-v6 (ATT SoW)
3327. [func] Added 'filter-aaaa-on-v6' option; this is similar
to 'filter-aaaa-on-v4' but applies to IPv6
connections. (Use "configure --enable-filter-aaaa"
to enable this option.) [RT #27308] |
5fa46bc91672ef5737aee6f99763161511566c24 |
|
11-Mar-2012 |
Tinderbox User <tbox@isc.org> |
update copyright notice |
207845805eb591b77ffbd99735617cab7e2ed804 |
|
07-Mar-2012 |
Evan Hunt <each@isc.org> |
set $Id$ |
28a8f5b0de57d269cf2845c69cb6abe18cbd3b3a |
|
07-Mar-2012 |
Mark Andrews <marka@isc.org> |
set $Id$ |
2d7f41d66caf648e9f178f0cfd78b097be61c92c |
|
06-Mar-2012 |
Evan Hunt <each@isc.org> |
Revert "Re-created rt27597a for ongoing DLZ work"
This reverts commit d731ee9121c3864839c3bdcd3b7ee603ec3999ff. |
d731ee9121c3864839c3bdcd3b7ee603ec3999ff |
|
05-Mar-2012 |
Evan Hunt <each@isc.org> |
Re-created rt27597a for ongoing DLZ work |
632c0f1e91cd1884c6c9c7b51f7189a1e9c6ea17 |
|
05-Mar-2012 |
Evan Hunt <each@isc.org> |
Revert accidental merge of unfinished DLZ work |
954501715d5cfa8f98171161bed80f962d8dede6 |
|
04-Mar-2012 |
Evan Hunt <each@isc.org> |
checkpoint: multiple-DLZ functionality
- multiple DLZ's can be specified, including multiple DLZ's using
the same driver; e.g., two different back-ends both loaded by the
dlopen driver
- new "search" option can be specified in a DLZ indicating whether
this DLZ database should be searched for unknown zones. The
default is "yes". If "no", then the zone can only be found by
named if it's registered in the zone table, which happens if the
zone is configured for dynamic updates, or if "dlz <dlzname>" is
specified in the zone statement. (The latter functionality is
incomplete in this commit). |
ac436908582fe08c85c886b200664816b11fded6 |
|
07-Nov-2011 |
Mark Andrews <marka@isc.org> |
3209. [func] Add "dnssec-lookaside 'off'". [RT #24858] |
9fee08f655527a5dd849b171daeeee1dbbccca76 |
|
13-Oct-2011 |
Vernon Schryver <vjs@isc.org> |
Commit rt25172 changes to HEAD including
- fix precedence among competing rules
- improve ARM text including documenting rule precedence
- try to rewrite CNAME chains until first hit
- new "rpz" logging channel
- same fix for "NS ." as in RT 24985 |
fad5116b3d68e825d29f87a1d3cb41409f42e8f5 |
|
07-Sep-2011 |
Scott Mann <smann@isc.org> |
Remove the ixfr-from-differences side-effect which causes an AXFR and extend
request-ixfr to the zone level. |
9198ab377b1cbf07d6d0c6eec25296c135bd66bd |
|
30-Aug-2011 |
Mark Andrews <marka@isc.org> |
3147. [func] Initial inline signing support. [RT #23657] |
a69070d8fab55dbc63ba9f96c9d3e34f0ea9119a |
|
01-Jul-2011 |
Mark Andrews <marka@isc.org> |
3130. [func] Support alternate methods for managing a dynamic
zone's serial number. Two methods are currently
defined using serial-update-method, "increment"
(default) and "unixtime". [RT #23849] |
bfe32d08c51a606744bd0d6ea518eb95084d2eef |
|
23-May-2011 |
Evan Hunt <each@isc.org> |
3116. [func] New 'dnssec-update-mode' option controls updates
of DNSSEC records in signed dynamic zones. Set to
'no-resign' to disable automatic RRSIG regeneration
while retaining the ability to sign new or changed
data. [RT #24533] |
de7df3e56fe99c33a415674b018aae93eee94750 |
|
07-May-2011 |
Evan Hunt <each@isc.org> |
3111. [bug] Improved consistency checks for dnssec-enable and
dnssec-validation, added test cases to the
checkconf system test. [RT #24398] |
ac21f918f23ce95fd5be807428ee9e2c42319878 |
|
06-May-2011 |
Evan Hunt <each@isc.org> |
3109. [func] The also-notify option now uses the same syntax
as a zone's masters clause. This means it is
now possible to specify a TSIG key to use when
sending notifies to a given server, or to include
an explicit named masters list in an also-notfiy
statement. [RT #23508] |
39f2d1a96a7c7494b1db0ea0f45e063a6a5ef9bb |
|
29-Apr-2011 |
Evan Hunt <each@isc.org> |
3102. [func] New 'dnssec-loadkeys-interval' option configures
how often, in minutes, to check the key repository
for updates when using automatic key maintenance.
Default is every 60 minutes (formerly hard-coded
to 12 hours). [RT #23744]
3101. [bug] Zones using automatic key maintenance could fail
to check the key repository for updates. [RT #23744] |
0874abad14e3e9ecfc3dc1a1a2b9969f2f027724 |
|
11-Mar-2011 |
Mark Andrews <marka@isc.org> |
3069. [cleanup] Silence warnings messages from clang static analysis.
[RT #20256] |
0e507dbb816575e6220fe309e8ada68897ffcdbe |
|
23-Feb-2011 |
Mark Andrews <marka@isc.org> |
2039. [func] Redirect on NXDOMAIN support. [RT #23146] |
000a8970f840a0c27c5cc404826853c4674362ac |
|
03-Feb-2011 |
Mark Andrews <marka@isc.org> |
3011. [func] Change the default query timeout from 30 seconds
to 10. Allow setting this in named.conf using the new
'resolver-query-timeout' option, which specifies a max
time in seconds. 0 means 'default' and anything longer
than 30 will be silently set to 30. [RT #22852] |
87708bde16713bc02ff2598f4a82f98c699a2f2d |
|
13-Jan-2011 |
Mark Andrews <marka@isc.org> |
3008. [func] Response policy zones (RPZ) support. [RT #21726] |
dc4fa197dd1031b3c966e5ee9d69a0f49ae1d9ce |
|
07-Jan-2011 |
Mark Andrews <marka@isc.org> |
3004. [func] DNS64 reverse support. [RT #22769] |
3916872f379457fe344afb02398a009701c5016a |
|
07-Jan-2011 |
Evan Hunt <each@isc.org> |
3003. [experimental] Added update-policy match type "external",
enabliing named to defer the decision of whether to
allow a dynamic update to an external daemon.
(Contributed by Andrew Tridgell.) [RT #22758] |
1da9dbcf48dcfc5c1589def3e785844935d1882c |
|
05-Jan-2011 |
Automatic Updater <source@isc.org> |
update copyright notice |
79bf7c874bb5a01b5b5db44af10b4ae24c89b93e |
|
04-Jan-2011 |
Evan Hunt <each@isc.org> |
3001. [func] Added a default trust anchor for the root zone, which
can be switched on by setting "dnssec-validation auto;"
in the named.conf options. [RT #21727] |
71bd858d8ed62672e7c23999dc7c02fd16a55089 |
|
18-Dec-2010 |
Evan Hunt <each@isc.org> |
2989. [func] Added support for writable DLZ zones. (Contributed
by Andrew Tridgell of the Samba project.) [RT #22629]
2988. [experimental] Added a "dlopen" DLZ driver, allowing the creation
of external DLZ drivers that can be loaded as
shared objects at runtime rather than linked with
named. Currently this is switched on via a
compile-time option, "configure --with-dlz-dlopen".
Note: the syntax for configuring DLZ zones
is likely to be refined in future releases.
(Contributed by Andrew Tridgell of the Samba
project.) [RT #22629]
2987. [func] Improve ease of configuring TKEY/GSS updates by
adding a "tkey-gssapi-keytab" option. If set,
updates will be allowed with any key matching
a principal in the specified keytab file.
"tkey-gssapi-credential" is no longer required
and is expected to be deprecated. (Contributed
by Andrew Tridgell of the Samba project.)
[RT #22629] |
743bbdc18f839499862e4fb28ec32f607b1632dc |
|
16-Dec-2010 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2947. [func] Add new zone type "static-stub". It's like a stub
zone, but the nameserver names and/or their IP
addresses are statically configured. [RT #21474]
(for 9.8.0) |
e334405421979688f2d838805ac67ee47bd62976 |
|
08-Dec-2010 |
Mark Andrews <marka@isc.org> |
2981. [func] Partial DNS64 support (AAAA synthesis). [RT #21991] |
cfd262045c23cadb8415f0111f56995258f17361 |
|
11-Aug-2010 |
Evan Hunt <each@isc.org> |
2936. [func] Improved configuration syntax and multiple-view
support for addzone/delzone feature (see change
#2930). Removed "new-zone-file" option, replaced
with "allow-new-zones (yes|no)". The new-zone-file
for each view is now created automatically, with
a filename generated from a hash of the view name.
It is no longer necessary to "include" the
new-zone-file in named.conf; this happens
automatically. Zones that were not added via
"rndc addzone" can no longer be removed with
"rndc delzone". [RT #19447] |
a90aca78aa7847ba65d27def47f69339987869c8 |
|
12-Jul-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
a207cfc5d18d74f0e29bb946067f3c317d8715bf |
|
11-Jul-2010 |
Evan Hunt <each@isc.org> |
Removed a duplicate entry in namedconf.c. |
86dcc4005887f91d23d970d4574a8f6afa7e28d2 |
|
11-Jul-2010 |
Evan Hunt <each@isc.org> |
2930. [experimental] New "rndc addzone" and "rndc delzone" commads
allow dynamic addition and deletion of zones.
To enable this feature, specify a "new-zone-file"
option at the view or options level in named.conf.
Zone configuration information for the new zones
will be written into that file. To make the new
zones persist after a restart, "include" the file
into named.conf in the appropriate view. (Note:
This feature is not yet documented, and its syntax
is expected to change.) [RT #19447] |
bf13e709db49bb19e0c2e73f0a964fe9d7bea4df |
|
25-Jun-2010 |
Mark Andrews <marka@isc.org> |
2924. [func] 'rndc secroots' dump a combined summary of the
current managed keys combined with trusted keys.
[RT #20904] |
48dfee71508886d86fe8fb12f91961b5daf3141d |
|
22-Jun-2010 |
Mark Andrews <marka@isc.org> |
2920. [func] Allow 'filter-aaaa-on-v4' to be applied selectively
to IPv4 clients. New acl 'filter-aaaa' (default any). |
57b47bca2621b2bade5dadb18984d155346d2b9a |
|
29-May-2010 |
Mark Andrews <marka@isc.org> |
checkpoint |
7d9be933d7f4504cd0355ced1fb7fbd137e455b7 |
|
21-May-2010 |
Mark Andrews <marka@isc.org> |
2903. [bug] managed-keys-directory missing from namedconf.c.
[RT #21370] |
b7bcdb3eaabfb864df0baf28741e07081c665aac |
|
14-May-2010 |
Automatic Updater <source@isc.org> |
update copyright notice |
e12030c433a08b9e9678717ec5e8092c9e4da72c |
|
13-May-2010 |
Mark Andrews <marka@isc.org> |
2889. [bug] Element of the grammar where not properly reported.
[RT #21046] |
3d17a3ba61a303d5c4d9867068d0fbe9f24d2988 |
|
04-Dec-2009 |
Mark Andrews <marka@isc.org> |
2801. [func] Detect and report records that are different according
to DNSSEC but are sematically equal according to plain
DNS. Apply plain DNS comparisons rather than DNSSEC
comparisons when processing UPDATE requests.
dnssec-signzone now removes such semantically duplicate
records prior to signing the RRset.
named-checkzone -r {ignore|warn|fail} (default warn)
named-compilezone -r {ignore|warn|fail} (default warn)
named.conf: check-dup-records {ignore|warn|fail}; |
8e4f3f1cbceef520ba889270c993de0ac376a2a7 |
|
04-Dec-2009 |
Evan Hunt <each@isc.org> |
2799. [cleanup] Changed the "secure-to-insecure" option to
"dnssec-secure-to-insecure", and "dnskey-ksk-only"
to "dnssec-dnskey-kskonly", for clarity. [RT #20586] |
5d9922e86f3d7f58f4c6b1234962ee4567108830 |
|
28-Nov-2009 |
Vernon Schryver <vjs@isc.org> |
Allow the optional filter-aaaa-on-v4 option in view statements to close #20635 |
c8aa7ce70d75d5d8f28f941e3a522c71e948b166 |
|
27-Oct-2009 |
Evan Hunt <each@isc.org> |
2732. [func] Add optional filter-aaaa-on-v4 option, available
if built with './configure --enable-filter-aaaa'.
Filters out AAAA answers to clients connecting
via IPv4. (This is NOT recommended for general
use.) [RT #20339] |
97639003b0992b5f30ce82bdcc2fcd9d621ff09c |
|
13-Oct-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
77b8f88f144928eddcca144c348d6ef53e7d5c43 |
|
12-Oct-2009 |
Evan Hunt <each@isc.org> |
2712. [func] New 'auto-dnssec' zone option allows zone signing
to be fully automated in zones configured for
dynamic DNS. 'auto-dnssec allow;' permits a zone
to be signed by creating keys for it in the
key-directory and using 'rndc sign <zone>'.
'auto-dnssec maintain;' allows that too, plus it
also keeps the zone's DNSSEC keys up to date
according to their timing metadata. [RT #19943] |
3727725bb7d63605b68a644060857013d563b67f |
|
10-Oct-2009 |
Evan Hunt <each@isc.org> |
2710. [func] New 'dnssec-signzone -x' flag and 'dnskey-ksk-only'
zone option cause a zone to be signed with only KSKs
signing the DNSKEY RRset, not ZSKs. This reduces
the size of a DNSKEY answer. [RT #20340] |
28479307225582ad0b2e11441d85fcf5169551d0 |
|
09-Oct-2009 |
Mark Andrews <marka@isc.org> |
2708. [func] Insecure to secure and NSEC3 parameter changes via
update are now fully supported and no longer require
defines to enable. We now no longer overload the
NSEC3PARAM flag field, nor the NSEC OPT bit at the
apex. Secure to insecure changes are controlled by
by the named.conf option 'secure-to-insecure'.
Warning: If you had previously enabled support by
adding defines at compile time to BIND 9.6 you should
ensure that all changes that are in progress have
completed prior to upgrading to BIND 9.7. BIND 9.7
is not backwards compatible. |
3a6b6f5b11a6db4677a5e244a852ec33defffce5 |
|
02-Sep-2009 |
Evan Hunt <each@isc.org> |
remove references to the "ddns-autoconf" option, which no longer exists |
85be60e3c8e47b9fdfeaa0770f445b206c39bca8 |
|
01-Sep-2009 |
Evan Hunt <each@isc.org> |
2665. [func] Clarify syntax for managed-keys {} statement, add
ARM documentation about RFC 5011 support. [RT #19874] |
9069215eac23e32f4ef1c8e44ad7ff2865cfcdac |
|
29-Jul-2009 |
Evan Hunt <each@isc.org> |
2641. [bug] Fixed an error in parsing update-policy syntax,
added a regression test to check it. [RT #20007] |
08f860f800d32007a0c9bf456f6c35fbb2ecbc81 |
|
15-Jul-2009 |
Evan Hunt <each@isc.org> |
2630. [func] Improved syntax for DDNS autoconfiguration: use
"update-policy local;" to switch on local DDNS in a
zone. [RT #19875] |
b655c721b6db0fcdcee99648ceba32a84022dff3 |
|
11-Jul-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
98e8948bd715fbefa8870e6f344183bc67e22340 |
|
10-Jul-2009 |
Mark Andrews <marka@isc.org> |
2622. [bug] Printing of named.conf grammar was broken. [RT #19919] |
cfb1587eb9a6dc6d1d36ea0344e1b20068b81e88 |
|
30-Jun-2009 |
Evan Hunt <each@isc.org> |
2619. [func] Add support for RFC 5011, automatic trust anchor
maintenance. The new "managed-keys" statement can
be used in place of "trusted-keys" for zones which
support this protocol. (Note: this syntax is
expected to change prior to 9.7.0 final.) [RT #19248] |
b6306ef56e6df1d772967887a2c16e2531ae4b27 |
|
11-Jun-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
351b62535d4c4f89883bfdba025999dd32490266 |
|
10-Jun-2009 |
Evan Hunt <each@isc.org> |
2609. [func] Simplify the configuration of dynamic zones:
- add ddns-confgen command to generate
configuration text for named.conf
- add zone option "ddns-autoconf yes;", which
causes named to generate a TSIG session key
and allow updates to the zone using that key
- add '-l' (localhost) option to nsupdate, which
causes nsupdate to connect to a locally-running
named process using the session key generated
by named
[RT #19284] |
40d0f115a64595aa83cfe0b760587d3d1efa0385 |
|
30-May-2009 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2604. [func] Add support for DNS rebinding attack prevention through
new options, deny-answer-addresses and
deny-answer-aliases. Based on contributed code from
JD Nurmi, Google. [RT #18192] |
3a30493983df83a3184dd1ecd39cf31ccdac3bad |
|
04-Mar-2009 |
Evan Hunt <each@isc.org> |
2572. [func] Simplify DLV configuration, with a new option
"dnssec-lookaside auto;" This is the equivalent
of "dnssec-lookaside . trust-anchor dlv.isc.org;"
plus setting a trusted-key for dlv.isc.org.
Note: The trusted key is hard-coded into named,
but is also stored in (and can be overridden
by) $sysconfdir/bind.keys. As the ISC DLV key
rolls over it can be kept up to date by replacing
the bind.keys file with a key downloaded from
https://www.isc.org/solutions/dlv. [RT #18685] |
9e0d0a279b956cc2eae41c00a6846b0ca8c617c6 |
|
10-Jan-2009 |
Automatic Updater <source@isc.org> |
update copyright notice |
7781f25078c491a9650dec555bdc86cb0ed49861 |
|
09-Jan-2009 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2526. [func] New named option "attach-cache" that allows multiple
views to share a single cache to save memory and
improve lookup efficiency. [RT 18905] |
2be6798f93e7ba1f4c4082e7b0837c7668a06dca |
|
28-Sep-2008 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2457. [tuning] max-cache-size is reverted to 0, the previous
default. It should be safe because expired cache
entries are also purged. |
6098d364b690cb9dabf96e9664c4689c8559bd2e |
|
24-Sep-2008 |
Mark Andrews <marka@isc.org> |
2448. [func] Add NSEC3 support. [RT #15452] |
0eeaaaf0ae1ae2856b94886fa80f94c21e6f1bfd |
|
04-Sep-2008 |
Mark Andrews <marka@isc.org> |
2398. [bug] Improve file descriptor management. New,
temporary, named.conf option reserved-sockets,
default 512. [RT #18344] |
2cf81a3d8a8a12e81a762a0bc3d46e0b117733bf |
|
24-Jun-2008 |
Automatic Updater <source@isc.org> |
update copyright notice |
386d3a99c190bad55edf44d076e6bd087e230ab8 |
|
23-Jun-2008 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2375. [security] Fully randomize UDP query ports to improve
forgery resilience. [RT #17949, #18098] |
db30f4bdcb66afb7eb1ab0c6882cc70be9a53d79 |
|
03-Apr-2008 |
Mark Andrews <marka@isc.org> |
2353. [func] Add support for Name Server ID (RFC 5001).
'dig +nsid' requests NSID from server.
'request-nsid yes;' causes recursive server to send
NSID requests to upstream servers. Server responds
to NSID requests with the string configured by
'server-id' option. [RT #17091] |
3f42cf2f3e4dc7e740b4609ba7d7430292348f2b |
|
02-Apr-2008 |
Mark Andrews <marka@isc.org> |
2349. [func] Provide incremental re-signing support for secure
dynamic zones. [RT #1091]
back out incorrect branch rt1091 and apply correct branch rt1091a. |
7e26a2a646877bcd5e03fce6d7347e88f059011e |
|
27-Mar-2008 |
Mark Andrews <marka@isc.org> |
2344. [bug] Improve "logging{ file ...; };" documentation.
[RT #17888] |
95c5f1d17b09e06a09ebdfa331e4ff04f06ffd42 |
|
22-Jan-2008 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
noticed the default max-cache-size [RT #17515] |
2f012d936b5ccdf6520c96a4de23721dc58a2221 |
|
19-Jan-2008 |
Automatic Updater <source@isc.org> |
update copyright notice |
b0b4ba753363812ac8de2353dedf02bf1cc9ffe8 |
|
17-Jan-2008 |
Mark Andrews <marka@isc.org> |
Fix documentation for:
2294. [func] Allow the experimental statistics channels to have
multiple connections and ACL. |
bfcc5ae79a46c5c55e6cf1a9fe4d70a957712d2b |
|
17-Jan-2008 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
2294. [func] Allow the experimental statistics channels to have
multiple connections and ACL.
Note: the stats-server and stats-server-v6 options
available in the previous beta releases are replaced
with the generic statistics-channels statment. |
1da14e066c23245c255dedb311d5a9cf0e5bb667 |
|
03-Jan-2008 |
Automatic Updater <source@isc.org> |
update copyright notice |
92f60809e854ccf5f115883c6347e370da048848 |
|
02-Jan-2008 |
Mark Andrews <marka@isc.org> |
2286. [func] Allow a TCP connection to be used as a weak
authentication method for reverse zones.
New update-policy methods tcp-self and 6to4-self.
[RT #17378] |
a1e2170ad5c5018fbe8f7b8449d8885d5d298e88 |
|
26-Sep-2007 |
Mark Andrews <marka@isc.org> |
2250. [func] New flag 'memstatistics' to state whether the
memory statistics file should be written or not.
Additionally named's -m option will cause the
statistics file to be written. [RT #17113] |
ca84283333d22c64abfbcb87872dd5e6d9172c5a |
|
18-Sep-2007 |
Mark Andrews <marka@isc.org> |
2244. [func] Allow the check of nameserver names against the
SOA MNAME field to be disabled by specifying
'notify-to-soa yes;'. [RT #17073] |
ec5347e2c775f027573ce5648b910361aa926c01 |
|
19-Jun-2007 |
Automatic Updater <source@isc.org> |
update copyright notice |
819b98479eff49ed93f57f4d65eb0ffe72136adc |
|
29-Mar-2007 |
Mark Andrews <marka@isc.org> |
2165. [func] Allow the destination address of a query to determine
if we will answer the query or recurse.
allow-query-on, allow-recursion-on and
allow-query-cache-on. [RT #16291] |
0b174d124377d8cd5de07864af9190d74f9f5755 |
|
06-Feb-2007 |
Mark Andrews <marka@isc.org> |
update copyright notice |
281bab0f36eaedc56f859721fbdf45568b71cd60 |
|
02-Feb-2007 |
Mark Andrews <marka@isc.org> |
2129. [func] Provide a pool of UDP sockets for queries to be
made over. See use-queryport-pool, queryport-pool-ports
and queryport-pool-updateinterval. [RT #16415] |
186e7f37c9fc985a7a7264cc8170e48a25bed434 |
|
21-Dec-2006 |
Mark Andrews <marka@isc.org> |
2122. [func] Experimental http server and statistics support
for named via xml. |
289ae548d52bc8f982d9823af64cafda7bd92232 |
|
04-Dec-2006 |
Mark Andrews <marka@isc.org> |
2105. [func] GSS-TSIG support (RFC 3645). |
a45a6ea2b03448751d7c44931e8ac7666e7cc2ce |
|
05-Jun-2006 |
Mark Andrews <marka@isc.org> |
2035. [func] Make falling back to TCP on UDP refresh failure
optional. Default "try-tcp-refresh yes;" for BIND 8
compatibility. [RT #16123] |
6412902ffc0d255657f54db768f30b6efa819143 |
|
03-May-2006 |
Mark Andrews <marka@isc.org> |
2015. [cleanup] use-additional-cache is now acache-enable for
consistancy. Default acache-enable off in BIND 9.4
as it requires memory usage to be configured.
It may be enabled by default in BIND 9.5 once we
have more experience with it. |
cfe92110ce4eaf19f7f3255d2961710879bdc9dd |
|
10-Mar-2006 |
Mark Andrews <marka@isc.org> |
2007. [func] It is now possible to explicitly enable DNSSEC
validation. default dnssec-validation no; to
be changed to yes in 9.5.0. [RT #15674] |
59d84d1b077678cb77f6cbcc53d8cfa60ff69cb7 |
|
06-Mar-2006 |
Mark Andrews <marka@isc.org> |
2001. [func] Check the KSK flag when updating a secure dynamic zone.
New zone option "update-check-ksk yes;". [RT #15817] |
45e1bd63587102c3bb361eaca42ee7b714fb3542 |
|
28-Feb-2006 |
Mark Andrews <marka@isc.org> |
1991. [cleanup] The configuration data, once read, should be treated
as readonly. Expand the use of const to enforce this
at compile time. [RT #15813] |
7d4a465de03b26bf9f5ef131d03253b8f6afc169 |
|
17-Feb-2006 |
Mark Andrews <marka@isc.org> |
1597. [func] Allow notify-source and query-source to be specified
on a per server basis similar to transfer-source. |
6e373c502584f9292e964378411d296c8259026b |
|
16-Feb-2006 |
Mark Andrews <marka@isc.org> |
1983. [func] Two new update policies. "selfsub" and "selfwild".
[RT #12895] |
dc6da18ccbb808d21f123cc6bda399b44ad11445 |
|
06-Jan-2006 |
Mark Andrews <marka@isc.org> |
1964. [func] Seperate out MX and SRV to CNAME checks. [RT #15723] |
a1bc94109313bf4ebb6e6ff655d71d45582d2e43 |
|
05-Jan-2006 |
Mark Andrews <marka@isc.org> |
1959. [func] Control the zeroing of the negative response TTL to
a soa query. Defaults "zero-no-soa-ttl yes;" and
"zero-no-soa-ttl-cache no;". [RT #15460] |
08c90261660649ca7d92065f6f13a61ec5a9a86d |
|
05-Jan-2006 |
Mark Andrews <marka@isc.org> |
1953. [func] Named now falls back to advertising EDNS with a
512 byte receive buffer if the initial EDNS queries
fail. [RT #14852]
1952. [func] The maximum EDNS UDP response named will send can
now be set in named.conf (max-udp-size). This is
independent of the advertised receive buffer
(edns-udp-size). [RT #14852] |
acb4f5236966c2b680b949c1eda826948b24fc23 |
|
05-Jan-2006 |
Mark Andrews <marka@isc.org> |
update copyright notice |
fabf2ee6b01ee06a0de940b83d53cf57f9f79265 |
|
04-Jan-2006 |
Mark Andrews <marka@isc.org> |
1947. [func] It is now possible to configure named to accept
expired RRSIGs. Default "dnssec-accept-expired no;".
Setting "dnssec-accept-expired yes;" leaves named
vulnerable to replay attacks. [RT #14685] |
1425217e5c3a2cbab7f8344e600e0c16047289ff |
|
26-Oct-2005 |
Mark Andrews <marka@isc.org> |
spelling arguement vs arguments |
03e200df5dc283f24a6a349f0b31d3eab26da893 |
|
05-Sep-2005 |
Mark Andrews <marka@isc.org> |
1913. [func] Integrate contibuted DLZ code into named. [RT #11382] |
2c15fcdeac4c2402258867fbac24d7475ef98259 |
|
25-Aug-2005 |
Mark Andrews <marka@isc.org> |
seperate out sibling glue checks |
6b79e960e6ba2991aeb02a6c39af255ab7f06d99 |
|
18-Aug-2005 |
Mark Andrews <marka@isc.org> |
1913. [func] Automatic empty zone creation for D.F.IP6.ARPA and
friends. Note: RFC 1918 zones are not yet covered by
this but are likely to be in a future release.
New options: empty-server, empty-contact,
empty-zones-enable and disable-empty-zone. |
fb827ed6df9a473770fb69a75a455b4ad0d14f52 |
|
18-Jul-2005 |
Mark Andrews <marka@isc.org> |
9.4/HEAD sync |
fd780f3d47179d68ba2d4661fb9cac9ce1e74928 |
|
27-Jun-2005 |
Mark Andrews <marka@isc.org> |
1891. [func] Limit the number of recursive clients that can be
waiting for a single query (<qname,qtype,qclass>) to
resolve. New options clients-per-query and
max-clients-per-query. |
a903095bf4512dae561c7f6fc7854a51bebf334a |
|
20-Jun-2005 |
Mark Andrews <marka@isc.org> |
1817. [func] add support for additional zone file formats for
improving loading performance. The masterfile-format
option in named.conf can be used to specify a
non-default format. A new separate command
named-compilezone was provided to generate zone files
in a new format. |
1c153afce556ff3c687986fb7c4a0b0a7f5e7cd8 |
|
07-Jun-2005 |
Mark Andrews <marka@isc.org> |
1868. [func] edns-udp-size can now be overridden on a per
server basis. [RT #14851] |
c5223c9cb7c22620d5ee6611228673e95b48a270 |
|
19-May-2005 |
Mark Andrews <marka@isc.org> |
1862. [func] Add additional zone data constancy checks.
named-checkzone has extended checking of NS, MX and
SRV record and the hosts they reference.
named has extended post zone load checks.
New zone options: check-mx and integrity-check.
[RT #4940] |
e5a5c60a5e690ee9858c9e3facba189b8646f0b7 |
|
12-May-2005 |
Mark Andrews <marka@isc.org> |
1858. [bug] The flush-zones-on-shutdown option wasn't being
parsed. [RT #14686] |
ab023a65562e62b85a824509d829b6fad87e00b1 |
|
27-Apr-2005 |
Rob Austein <sra@isc.org> |
1851. [doc] Doxygen comment markup. [RT #11398] |
4423c99613db1399dbb5c51e86ef0d351a1418c2 |
|
23-Feb-2005 |
Mark Andrews <marka@isc.org> |
1814. [func] UNIX domain controls are now supported. |
4844ed026a9b5a91044e76399cee80a6514cbf0d |
|
17-Jan-2005 |
Mark Andrews <marka@isc.org> |
1798. [func] The server syntax has been extended to support a
range of servers. [RT #11132] |
48f929d315bafeeffe0a37082ab4c9661a928c39 |
|
12-Jan-2005 |
Mark Andrews <marka@isc.org> |
1792. [func] New zone option "notify-delay". Specify a minimum
delay between sets of NOTIFY messages. |
2f4ffd7f5594c0464f2a872aee5ef102f6f7b10f |
|
11-Jan-2005 |
Mark Andrews <marka@isc.org> |
update copyrights |
508f61f8d699c46f962b682f388e54b446a7194d |
|
10-Jan-2005 |
Mark Andrews <marka@isc.org> |
1794. [func] Named and named-checkzone can now both check for
non-terminal wildcard records. |
d0eb2cc33c5db3366a16b1cb0abcca6ec7c8ee3c |
|
21-Dec-2004 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
1526. [func] Implemented "additional section caching (or acache)",
an internal cache framework for additional section
content to improve response performance. Several
configuration options were provided to control the
behavior. |
73fb13fe97cf2f1d93d5e2ea56583fdb2f40b6f3 |
|
11-Nov-2004 |
Mark Andrews <marka@isc.org> |
1755. [func] allow-update is now settable at the options / view
level. [RT #6636] |
49210da3fb6a9268725b2a7db864ade531e5d403 |
|
21-Oct-2004 |
Mark Andrews <marka@isc.org> |
1676. [func] New option "allow-query-cache". This lets
allow-query be used to specify the default zone
access level rather than having to have every
zone override the global value. allow-query-cache
can be set at both the options and view levels.
If allow-query-cache is not set allow-query applies. |
4181218570e915959dd203c18f8cf4a03dca5d68 |
|
18-Oct-2004 |
Mark Andrews <marka@isc.org> |
1747. [bug] BIND 8 compatability: named/named-checkconf failed
to parse "host-statistics-max" in named.conf. |
1672cff96d0b02badab6f94524e10285dde851fc |
|
14-Oct-2004 |
Mark Andrews <marka@isc.org> |
1684. [func] ixfr-from-differences now takes master and slave in
addition to yes and no at the options and view levels. |
207f0a15bb486d8dc27cf5ff963fac6068ee2972 |
|
07-Oct-2004 |
Mark Andrews <marka@isc.org> |
1705. [func] Allow the journal's name to be changed via named.conf. |
c4f9e613e12f03795bee18cf2ca8e6a9d39d6468 |
|
23-Jul-2004 |
Mark Andrews <marka@isc.org> |
1680. [func] rndc: the source address can now be specified. |
7389e8330d62a059b8923fb8ca6f933caeb559d9 |
|
18-Jun-2004 |
Mark Andrews <marka@isc.org> |
1666. [bug] The optional port on hostnames in dual-stack-servers
was being ignored.
1665. [func] rndc now allows addresses to be set in the
server clauses. |
c315e5cfead876251ee4ff5600ee67303b2729a4 |
|
04-Jun-2004 |
Mark Andrews <marka@isc.org> |
1648. [func] Update dnssec-lookaside named.conf syntax to support
multiple dnssec-lookaside namespaces (not yet
implemented). |
8d414d155953f89a4eff40f16878438a8c9228f3 |
|
16-Apr-2004 |
Mark Andrews <marka@isc.org> |
1600. [bug] Duplicate zone pre-load checks were not case
insensitive.
1599. [bug] Fix memory leak on error path when checking named.conf.
1598. [func] Specify that certain parts of the namespace must
be secure (dnssec-must-be-secure). |
3b1fce680f1dbe9467cd3b0ab3138ea52d5a976f |
|
30-Mar-2004 |
Mark Andrews <marka@isc.org> |
1595. [func] New notify type 'master-only'. Enable notify for
master zones only. |
0b9af9eb37f624033652f6cc463262474ee13344 |
|
30-Mar-2004 |
Mark Andrews <marka@isc.org> |
1596. [func] Accept 'notify-source' style syntax for query-source. |
50105afc551903541608b11851d73278b23579a3 |
|
10-Mar-2004 |
Mark Andrews <marka@isc.org> |
1589. [func] DNSSEC lookaside validation.
enable-dnssec -> dnssec-enable |
dafcb997e390efa4423883dafd100c975c4095d6 |
|
05-Mar-2004 |
Mark Andrews <marka@isc.org> |
update copyright notice |
7ad4d54f29c315cbcb241ca5fc12ba1e0744358b |
|
02-Mar-2004 |
Mark Andrews <marka@isc.org> |
1537. [func] New option "querylog". If set specify whether query
logging is to be enabled or disabled at startup. |
2047977ce2dfcfe3a0fa2d638c3242841310fad3 |
|
27-Feb-2004 |
Mark Andrews <marka@isc.org> |
1586. [func] "check-names" is now implemented. |
89783da064f4f9bf2e82d2b3941ddeffe2a8c30d |
|
17-Feb-2004 |
Mark Andrews <marka@isc.org> |
1581. [func] Disable DNSSEC support by default. To enable
DNSSEC specify "enable-dnssec yes;" in named.conf. |
35541328a8c18ba1f984300dfe30ec8713c90031 |
|
14-Jan-2004 |
Mark Andrews <marka@isc.org> |
1558. [func] New DNSSEC 'disable-algorithms'. Support entry into
child zones for which we don't have a supported
algorithm. Such child zones are treated as unsigned.
1557. [func] Implement missing DNSSEC tests for
* NOQNAME proof with wildcard answers.
* NOWILDARD proof with NXDOMAIN.
Cache and return NOQNAME with wildcard answers. |
600cbd1fcea3c9cc9706dc1ff8fc0d0034ebdeac |
|
25-Sep-2003 |
Tatuya JINMEI 神明達哉 <ji <jinmei@isc.org> |
1515. [func] Allow transfer source to be set in a server statement.
[RT #6496]
implemented by marka, reviewed and documented by jinmei.
Notes:
lib/dns/zone.c had to be modified manually.
ARM html files were not regenerated (yet). |
0b1da8124c817270f5dfe46cd0211b993c931a91 |
|
19-Sep-2003 |
Mark Andrews <marka@isc.org> |
1510. [func] New view option "root-delegation-only". Apply
delegation-only check to all TLDs and root.
Note there are some TLDs that are NOT delegation
only (e.g. DE and MUSEUM) these can be excluded
from the checks buy using exclude.
root-delegation-only exclude { "DE"; "MUSEUM"; }; |
4607e7a9b8dfb1b41c70e51c2b603daaf22cf302 |
|
17-Sep-2003 |
Mark Andrews <marka@isc.org> |
1504. [func] New zone type "delegation-only". |
603658ea65b34c4b57f154b1e2412b4f01866b6b |
|
17-Apr-2003 |
Mark Andrews <marka@isc.org> |
1462. [bug] parse_sizeval() failed to check the token type.
[RT #5586] |
b500de3be9ba5318da157364bf9fbbda5f88f203 |
|
27-Feb-2003 |
Mark Andrews <marka@isc.org> |
alt-transfer-source-v4 -> alt-transfer-source |
476386968b1f287a695f73c48862e961011af99b |
|
27-Feb-2003 |
Mark Andrews <marka@isc.org> |
1446. [func] Implemented undocumented alternate transfer sources
from BIND 8. See use-alt-transfer-source,
alt-transfer-source-v4 and alt-transfer-source-v6.
SECURITY: use-alt-transfer-source is ENABLED unless
you are using views. This may caues a security risk
resulting in accidental disclosure of wrong zone
content if the master supplying different source
content based on IP address. If you are not certian
ISC recommends setting use-alt-transfer-source no;
developer: marka
reviewer: explorer |
888bb8bf68ba1a2b032a64122efd9125a9155ad7 |
|
26-Feb-2003 |
Mark Andrews <marka@isc.org> |
1443. [func] Masters lists can now be specified and referenced
in zone masters clauses and other masters lists.
developer: marka
reviewer: explorer |
b312748a11d27fe387984973ba79975a9d6863c4 |
|
26-Feb-2003 |
Mark Andrews <marka@isc.org> |
1442. [func] New fuctions for manipulating port lists:
dns_portlist_create(), dns_portlist_add(),
dns_portlist_remove(), dns_portlist_match(),
dns_portlist_attach() and dns_portlist_detach().
1441. [func] It is now possible to tell dig to bind to a specific
source port.
1440. [func] It is now possible to tell named to avoid using
certian source ports (avoid-v4-udp-ports,
avoid-v6-udp-ports).
developer: marka
reviewer: explorer |
e2fb08b85de8158fe6b71008311e3d98104b92a6 |
|
26-Feb-2003 |
Mark Andrews <marka@isc.org> |
1432. [func] The advertised EDNS UDP buffer size can now be set
via named.conf (edns-udp-size).
developer: marka
reviewer: explorer |
a1301ef891a1e89ee9e0494009803bb8968e4a94 |
|
04-Feb-2003 |
Mark Andrews <marka@isc.org> |
undo (wrong branch) |
ab4bec8504b15af606535598a40023725d28886b |
|
04-Feb-2003 |
Mark Andrews <marka@isc.org> |
checkpoint |
9bd478a5e6df956a79bbdb5c182d5b44763786ce |
|
20-Jan-2003 |
Mark Andrews <marka@isc.org> |
1417. [func] ID.SERVER/CHAOS is now a built in zone.
See "server-id" for how to configure. |
0ffaee887ff5674b8c3bb0435ae838f641981706 |
|
16-Jan-2003 |
Mark Andrews <marka@isc.org> |
1412. [func] You can now specify servers to be tried if a nameserver
has IPv6 address and you only support IPv4 or the
reverse. See dual-stack-servers. |
49a940dc68b30d9e4f9e1bd3c0503d8b90bb1726 |
|
27-Nov-2002 |
Mark Andrews <marka@isc.org> |
1402. [cleanup] A6 has been moved to experimental and is no longer
fully supported.
developer: jinmei
reviewer: marka |
43ee20a821c490fa5bb43df924e9970705c22ecf |
|
13-Nov-2002 |
Michael Graff <mgraff@isc.org> |
merge rt4112 |
a9ae9d743c7f85bec44e95b1f62c7a2a114a2fd6 |
|
10-Sep-2002 |
Mark Andrews <marka@isc.org> |
1380. [func] 'rndc recursing' dump recursing queries to
'recursing-file = "named.recursing";'. |
87f4715d6c0a22f3449eb3291c91aa45ba86c955 |
|
29-Jul-2002 |
Mark Andrews <marka@isc.org> |
1344. [func] Log if the serial number on the master has gone backwards.
If you have multiple machines specified in the masters
clause you may want to set 'multi-master yes;' to suppress
this warning. |
981e5046e06a80462c0f14cdef84dcf7fb706402 |
|
13-Jul-2002 |
Mark Andrews <marka@isc.org> |
max-journal-size is a zone option |
c4a9ce445c48a57eed5aa16582b1964cf8cedf87 |
|
26-Apr-2002 |
Mark Andrews <marka@isc.org> |
1274. [func] preferred-glue option from BIND 8.3. |
6f49c3e3159ccc877213f6f5ae441e8c052cd6a5 |
|
07-Mar-2002 |
Mark Andrews <marka@isc.org> |
rrset-order is nolonger not implemented.
rrset-order should be a view level option. |
a7038d1a0513c8e804937ebc95fc9cb3a46c04f5 |
|
20-Feb-2002 |
Mark Andrews <marka@isc.org> |
copyrights |
47af71b5233c8863ee64883458c824df3a396ea7 |
|
22-Jan-2002 |
Andreas Gustafsson <source@isc.org> |
use token.value.as_textregion.base, not token.value.pointer |
a5c077e40c784cf9e25c95a1ab94db2faab04ae9 |
|
21-Jan-2002 |
Brian Wellington <source@isc.org> |
1181. [func] Add the "key-directory" configuration statement,
which allows the server to look for online signing
keys in alternate directories. |
669e9657c731176df235832367f61435f7b83ddf |
|
04-Jan-2002 |
Andreas Gustafsson <source@isc.org> |
Split off the named.conf grammar into a source module separate
from the configuration parser, to facilitate reuse of the latter for
parsing non-BIND configuration files |