Bv9ARM.ch09.html revision 5347c0fcb04eaea19d9f39795646239f487c6207
d98c74e2ec5b96bd22aa4ed6d893e8993787493bMichael Graff<!--
d98c74e2ec5b96bd22aa4ed6d893e8993787493bMichael Graff - Copyright (C) 2000-2015 Internet Systems Consortium, Inc. ("ISC")
d98c74e2ec5b96bd22aa4ed6d893e8993787493bMichael Graff -
d98c74e2ec5b96bd22aa4ed6d893e8993787493bMichael Graff - This Source Code Form is subject to the terms of the Mozilla Public
d03d4524993ecf5da72694907cb8581eadbe5c4dBrian Wellington - License, v. 2.0. If a copy of the MPL was not distributed with this
d03d4524993ecf5da72694907cb8581eadbe5c4dBrian Wellington - file, You can obtain one at http://mozilla.org/MPL/2.0/.
d03d4524993ecf5da72694907cb8581eadbe5c4dBrian Wellington-->
75f6c57d9544aa77a3b1a04587b4702c07343c90Brian Wellington<html>
75f6c57d9544aa77a3b1a04587b4702c07343c90Brian Wellington<head>
75f6c57d9544aa77a3b1a04587b4702c07343c90Brian Wellington<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
f34984369fbc87f6cc5c5d1059303377a1724d79James Brister<title>Appendix�A.�Release Notes</title>
f34984369fbc87f6cc5c5d1059303377a1724d79James Brister<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
f34984369fbc87f6cc5c5d1059303377a1724d79James Brister<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
7cd4c3ddd1baf5f2b204562fdba3da37c716cc78Andreas Gustafsson<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
7cd4c3ddd1baf5f2b204562fdba3da37c716cc78Andreas Gustafsson<link rel="prev" href="Bv9ARM.ch08.html" title="Chapter�8.�Troubleshooting">
76a191c4202a4839e4ce598ec91f0c0d12f630aaAndreas Gustafsson<link rel="next" href="Bv9ARM.ch10.html" title="Appendix�B.�A Brief History of the DNS and BIND">
76a191c4202a4839e4ce598ec91f0c0d12f630aaAndreas Gustafsson</head>
76a191c4202a4839e4ce598ec91f0c0d12f630aaAndreas Gustafsson<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
76a191c4202a4839e4ce598ec91f0c0d12f630aaAndreas Gustafsson<div class="navheader">
fef059dcec0f7f83b09b9ce30b91b21a51d9c481Andreas Gustafsson<table width="100%" summary="Navigation header">
fef059dcec0f7f83b09b9ce30b91b21a51d9c481Andreas Gustafsson<tr><th colspan="3" align="center">Appendix�A.�Release Notes</th></tr>
fef059dcec0f7f83b09b9ce30b91b21a51d9c481Andreas Gustafsson<tr>
5f80c1428b9b7235fc9c1c80aa505457c3043504Brian Wellington<td width="20%" align="left">
5f80c1428b9b7235fc9c1c80aa505457c3043504Brian Wellington<a accesskey="p" href="Bv9ARM.ch08.html">Prev</a>�</td>
5f80c1428b9b7235fc9c1c80aa505457c3043504Brian Wellington<th width="60%" align="center">�</th>
af602636644fdfaabc331bd926b0aabb9432e152Brian Wellington<td width="20%" align="right">�<a accesskey="n" href="Bv9ARM.ch10.html">Next</a>
af602636644fdfaabc331bd926b0aabb9432e152Brian Wellington</td>
af602636644fdfaabc331bd926b0aabb9432e152Brian Wellington</tr>
b3aaa872e12e5c8658271bde8e4dd85d015e823fAndreas Gustafsson</table>
b3aaa872e12e5c8658271bde8e4dd85d015e823fAndreas Gustafsson<hr>
b3aaa872e12e5c8658271bde8e4dd85d015e823fAndreas Gustafsson</div>
b3aaa872e12e5c8658271bde8e4dd85d015e823fAndreas Gustafsson<div class="appendix">
b3aaa872e12e5c8658271bde8e4dd85d015e823fAndreas Gustafsson<div class="titlepage"><div><div><h1 class="title">
b3aaa872e12e5c8658271bde8e4dd85d015e823fAndreas Gustafsson<a name="Bv9ARM.ch09"></a>Release Notes</h1></div></div></div>
b3aaa872e12e5c8658271bde8e4dd85d015e823fAndreas Gustafsson<div class="toc">
389f2ccc2f5f00a11a14114d40492f7ac8249fa7Olafur Gudmundsson<p><b>Table of Contents</b></p>
389f2ccc2f5f00a11a14114d40492f7ac8249fa7Olafur Gudmundsson<dl class="toc">
6deb631b20b7e212d9a350759e472fa60f9e92e4David Lawrence<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.0b2</a></span></dt>
6deb631b20b7e212d9a350759e472fa60f9e92e4David Lawrence<dd><dl>
6deb631b20b7e212d9a350759e472fa60f9e92e4David Lawrence<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
b1d234eb75e2804e09d89178a76df39c321db51bBrian Wellington<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
b1d234eb75e2804e09d89178a76df39c321db51bBrian Wellington<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
a9bc95f22ef2dd4a12e79be99412c9f18b814a5dBrian Wellington<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
a9bc95f22ef2dd4a12e79be99412c9f18b814a5dBrian Wellington<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
a9bc95f22ef2dd4a12e79be99412c9f18b814a5dBrian Wellington<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
bcea9925141b1e0076cd7b078f1dae1449a1229bDavid Lawrence<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_port">Porting Changes</a></span></dt>
bcea9925141b1e0076cd7b078f1dae1449a1229bDavid Lawrence<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
bcea9925141b1e0076cd7b078f1dae1449a1229bDavid Lawrence<dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
bcea9925141b1e0076cd7b078f1dae1449a1229bDavid Lawrence<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
bcea9925141b1e0076cd7b078f1dae1449a1229bDavid Lawrence</dl></dd>
bcea9925141b1e0076cd7b078f1dae1449a1229bDavid Lawrence</dl>
3c8e458ed2118828b13f35ca6fcc409da66c2869David Lawrence</div>
3c8e458ed2118828b13f35ca6fcc409da66c2869David Lawrence<div class="section">
7ffc4c63ac8841d127c2d77c8716cc0dc483badcDavid Lawrence<div class="titlepage"><div><div><h2 class="title" style="clear: both">
7ffc4c63ac8841d127c2d77c8716cc0dc483badcDavid Lawrence<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.0b2</h2></div></div></div>
7ffc4c63ac8841d127c2d77c8716cc0dc483badcDavid Lawrence<div class="section">
19d1b1667d073850d4366352aaf8319efc5debeeBrian Wellington<div class="titlepage"><div><div><h3 class="title">
19d1b1667d073850d4366352aaf8319efc5debeeBrian Wellington<a name="relnotes_intro"></a>Introduction</h3></div></div></div>
19d1b1667d073850d4366352aaf8319efc5debeeBrian Wellington<p>
20b20b23948b90cb2f7d7f402da99d09f837efd0David Lawrence BIND 9.11.0 is a new feature release of BIND, still under development.
20b20b23948b90cb2f7d7f402da99d09f837efd0David Lawrence This document summarizes new features and functional changes that
20b20b23948b90cb2f7d7f402da99d09f837efd0David Lawrence have been introduced on this branch. With each development
20b20b23948b90cb2f7d7f402da99d09f837efd0David Lawrence release leading up to the final BIND 9.11.0 release, this document
a89b06a49cc61cdce2ce0ea0f62b514998fa16d9Andreas Gustafsson will be updated with additional features added and bugs fixed.
a89b06a49cc61cdce2ce0ea0f62b514998fa16d9Andreas Gustafsson </p>
a89b06a49cc61cdce2ce0ea0f62b514998fa16d9Andreas Gustafsson</div>
a89b06a49cc61cdce2ce0ea0f62b514998fa16d9Andreas Gustafsson<div class="section">
9c987b20b9246a34f38af8ed3cd22c61040933a7Andreas Gustafsson<div class="titlepage"><div><div><h3 class="title">
9c987b20b9246a34f38af8ed3cd22c61040933a7Andreas Gustafsson<a name="relnotes_download"></a>Download</h3></div></div></div>
7e9bfde7951c4e35bcbd0d3439790cc823a6794cAndreas Gustafsson<p>
7e9bfde7951c4e35bcbd0d3439790cc823a6794cAndreas Gustafsson The latest versions of BIND 9 software can always be found at
7e9bfde7951c4e35bcbd0d3439790cc823a6794cAndreas Gustafsson <a class="link" href="http://www.isc.org/downloads/" target="_top">http://www.isc.org/downloads/</a>.
7e9bfde7951c4e35bcbd0d3439790cc823a6794cAndreas Gustafsson There you will find additional information about each release,
4c9406964425ecc33fac38bb093e236b43b449e6Andreas Gustafsson source code, and pre-compiled versions for Microsoft Windows
4c9406964425ecc33fac38bb093e236b43b449e6Andreas Gustafsson operating systems.
4c9406964425ecc33fac38bb093e236b43b449e6Andreas Gustafsson </p>
4c9406964425ecc33fac38bb093e236b43b449e6Andreas Gustafsson</div>
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff<div class="section">
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff<div class="titlepage"><div><div><h3 class="title">
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff<a name="relnotes_license"></a>License Change</h3></div></div></div>
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff<p>
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff With the release of BIND 9.11.0, ISC is changing the open
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff source license for BIND from the ISC license to the Mozilla
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff Public License (MPL 2.0). This change is effective from BIND
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff 9.11.0b1 onwards.
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff </p>
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff<p>
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff The MPL-2.0 license requires that if you make changes to
533131b93b69c4534b5f1f9138b59211670e6e6dMichael Graff licensed software (e.g. BIND) and distribute them outside
73abbeb5823a9b3e01b05a8878db915eb6beccdaAndreas Gustafsson your organization, that you publish those changes under that
73abbeb5823a9b3e01b05a8878db915eb6beccdaAndreas Gustafsson same license. It does not require that you publish or disclose
73abbeb5823a9b3e01b05a8878db915eb6beccdaAndreas Gustafsson anything other than the changes you made to our software.
73abbeb5823a9b3e01b05a8878db915eb6beccdaAndreas Gustafsson </p>
538971e27d45861c937331f52b0e96d3a5157d8eAndreas Gustafsson<p>
538971e27d45861c937331f52b0e96d3a5157d8eAndreas Gustafsson This new requirement will not affect anyone who is using BIND
538971e27d45861c937331f52b0e96d3a5157d8eAndreas Gustafsson without redistributing it, nor anyone redistributing it without
538971e27d45861c937331f52b0e96d3a5157d8eAndreas Gustafsson changes, therefore this change will be without consequence
7ffc4c63ac8841d127c2d77c8716cc0dc483badcDavid Lawrence for most individuals and organizations who are using BIND.
c50936eb40263b65ebf6afe4e6556e2dc67c10e4Brian Wellington </p>
8977ab7ca0ed63a39a8cd0b915ab9cb1254dcd3fJames Brister<p>
8977ab7ca0ed63a39a8cd0b915ab9cb1254dcd3fJames Brister Those unsure whether or not the license change affects their
8977ab7ca0ed63a39a8cd0b915ab9cb1254dcd3fJames Brister use of BIND, or who wish to discuss how to comply with the
8977ab7ca0ed63a39a8cd0b915ab9cb1254dcd3fJames Brister license may contact ISC at <a class="link" href="https://www.isc.org/mission/contact/" target="_top">
dc97fe4ed08488d314ab5bc8e99ed839542cf411David Lawrence https://www.isc.org/mission/contact/</a>.
dc97fe4ed08488d314ab5bc8e99ed839542cf411David Lawrence </p>
dc97fe4ed08488d314ab5bc8e99ed839542cf411David Lawrence</div>
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson<div class="section">
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson<div class="titlepage"><div><div><h3 class="title">
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson<a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem"><p>
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson getrrsetbyname with a non absolute name could trigger an
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson infinite recursion bug in lwresd and named with lwres
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson configured if when combined with a search list entry the
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson resulting name is too long. This flaw is disclosed in
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson CVE-2016-2775. [RT #42694]
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson </p></li></ul></div>
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson</div>
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson<div class="section">
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson<div class="titlepage"><div><div><h3 class="title">
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson<a name="relnotes_features"></a>New Features</h3></div></div></div>
95be83b467e2384d414693982318a5c06cccf1d7Andreas Gustafsson<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence<li class="listitem">
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence<p>
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence A new method of provisioning secondary servers called
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence "Catalog Zones" has been added. This is an implementation of
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence <a class="link" href="https://datatracker.ietf.org/doc/draft-muks-dnsop-dns-catalog-zones/" target="_top">
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence draft-muks-dnsop-dns-catalog-zones/
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence </a>.
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence </p>
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence<p>
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence A catalog zone is a regular DNS zone which contains a list
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence of "member zones", along with the configuration options for
6fa1cb5754695d550a58c6e8978fda65f5146af7David Lawrence each of those zones. When a server is configured to use a
52b784e2a662038b833e4f9ad7bff881faf52a85Andreas Gustafsson catalog zone, all the zones listed in the catalog zone are
52b784e2a662038b833e4f9ad7bff881faf52a85Andreas Gustafsson added to the local server as slave zones. When the catalog
52b784e2a662038b833e4f9ad7bff881faf52a85Andreas Gustafsson zone is updated (e.g., by adding or removing zones, or
edb8ffbbf3e4b3c16a10fdd45720d97706e6bf50Mark Andrews changing configuration options for existing zones) those
edb8ffbbf3e4b3c16a10fdd45720d97706e6bf50Mark Andrews changes will be put into effect. Since the catalog zone is
edb8ffbbf3e4b3c16a10fdd45720d97706e6bf50Mark Andrews itself a DNS zone, this means configuration changes can be
edb8ffbbf3e4b3c16a10fdd45720d97706e6bf50Mark Andrews propagated to slaves using the standard AXFR/IXFR update
59abb512d344bfa09012cc11b7d814966f035da4Mark Andrews mechanism.
59abb512d344bfa09012cc11b7d814966f035da4Mark Andrews </p>
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence<p>
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence This feature should be considered experimental. It currently
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence supports only basic features; more advanced features such as
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence ACLs and TSIG keys are not yet supported. Example catalog
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence zone configurations can be found in the Chapter 9 of the
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence BIND Administrator Reference Manual.
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence </p>
600cfa2ba4c50017581b6c14e3a688a82ecebbe0David Lawrence<p>
a120694df8156f76eb629e4d686d3729362e3c90David Lawrence Support for master entries with TSIG keys has been added to catalog
a120694df8156f76eb629e4d686d3729362e3c90David Lawrence zones, as well as support for allow-query and allow-transfer.
a120694df8156f76eb629e4d686d3729362e3c90David Lawrence </p>
a120694df8156f76eb629e4d686d3729362e3c90David Lawrence</li>
fcba8f29fedd5a29651579e22c96413b4f37cab9Brian Wellington<li class="listitem"><p>
fcba8f29fedd5a29651579e22c96413b4f37cab9Brian Wellington Added rndc python module.
f6afa4ac95f3a6c86c61c0b122cd0dc6f957649bBrian Wellington </p></li>
f6afa4ac95f3a6c86c61c0b122cd0dc6f957649bBrian Wellington<li class="listitem">
34b394b43e2207e8f8f3703f0402422121455638David Lawrence<p>
34b394b43e2207e8f8f3703f0402422121455638David Lawrence Added support for DynDB, a new interface for loading zone data
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister from an external database, developed by Red Hat for the FreeIPA
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister project. (Thanks in particular to Adam Tkac and Petr
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister Spacek of Red Hat for the contribution.)
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister </p>
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister<p>
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister Unlike the existing DLZ and SDB interfaces, which provide a
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister limited subset of database functionality within BIND &#8212;
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister translating DNS queries into real-time database lookups with
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister relatively poor performance and with no ability to handle
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister DNSSEC-signed data &#8212; DynDB is able to fully implement
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister and extend the database API used natively by BIND.
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister </p>
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister<p>
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister A DynDB module could pre-load data from an external data
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister source, then serve it with the same performance and
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister functionality as conventional BIND zones, and with the
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister ability to take advantage of database features not
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister available in BIND, such as multi-master replication.
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister </p>
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister</li>
cde7793c7fb83adecf1a60bfc76cde6d1d7db0ebJames Brister<li class="listitem">
527ea00c176abc167a6daf978e06f52c7e70aa06Andreas Gustafsson<p>
527ea00c176abc167a6daf978e06f52c7e70aa06Andreas Gustafsson New quotas have been added to limit the queries that are
527ea00c176abc167a6daf978e06f52c7e70aa06Andreas Gustafsson sent by recursive resolvers to authoritative servers
f7d85bae58428b91fde90f87c1e9ef89897acf2eAndreas Gustafsson experiencing denial-of-service attacks. When configured,
f7d85bae58428b91fde90f87c1e9ef89897acf2eAndreas Gustafsson these options can both reduce the harm done to authoritative
f7d85bae58428b91fde90f87c1e9ef89897acf2eAndreas Gustafsson servers and also avoid the resource exhaustion that can be
f7d85bae58428b91fde90f87c1e9ef89897acf2eAndreas Gustafsson experienced by recursive servers when they are being used as a
ec7493d8d1966a3dc5f5306fc0a96519e0de6dceAndreas Gustafsson vehicle for such an attack.
ec7493d8d1966a3dc5f5306fc0a96519e0de6dceAndreas Gustafsson </p>
ec7493d8d1966a3dc5f5306fc0a96519e0de6dceAndreas Gustafsson<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: circle; ">
ec7493d8d1966a3dc5f5306fc0a96519e0de6dceAndreas Gustafsson<li class="listitem"><p>
34b394b43e2207e8f8f3703f0402422121455638David Lawrence <code class="option">fetches-per-server</code> limits the number of
289fd0daf888e3f7b1733bd750f60891ce90e1e6Andreas Gustafsson simultaneous queries that can be sent to any single
289fd0daf888e3f7b1733bd750f60891ce90e1e6Andreas Gustafsson authoritative server. The configured value is a starting
289fd0daf888e3f7b1733bd750f60891ce90e1e6Andreas Gustafsson point; it is automatically adjusted downward if the server is
289fd0daf888e3f7b1733bd750f60891ce90e1e6Andreas Gustafsson partially or completely non-responsive. The algorithm used to
bd36d3014e8a82d217ed1c88cdb4c717a25fee09Andreas Gustafsson adjust the quota can be configured via the
bd36d3014e8a82d217ed1c88cdb4c717a25fee09Andreas Gustafsson <code class="option">fetch-quota-params</code> option.
8adf1b9e749ca303ea8a8ffb29b5101ecbe2ecf6Mark Andrews </p></li>
8adf1b9e749ca303ea8a8ffb29b5101ecbe2ecf6Mark Andrews<li class="listitem"><p>
8adf1b9e749ca303ea8a8ffb29b5101ecbe2ecf6Mark Andrews <code class="option">fetches-per-zone</code> limits the number of
8adf1b9e749ca303ea8a8ffb29b5101ecbe2ecf6Mark Andrews simultaneous queries that can be sent for names within a
8adf1b9e749ca303ea8a8ffb29b5101ecbe2ecf6Mark Andrews single domain. (Note: Unlike "fetches-per-server", this
8adf1b9e749ca303ea8a8ffb29b5101ecbe2ecf6Mark Andrews value is not self-tuning.)
8adf1b9e749ca303ea8a8ffb29b5101ecbe2ecf6Mark Andrews </p></li>
8adf1b9e749ca303ea8a8ffb29b5101ecbe2ecf6Mark Andrews</ul></div>
8adf1b9e749ca303ea8a8ffb29b5101ecbe2ecf6Mark Andrews<p>
c052487cdf42c83bb0fa8e4c0ed135e801ac1e90Mark Andrews Statistics counters have also been added to track the number
c052487cdf42c83bb0fa8e4c0ed135e801ac1e90Mark Andrews of queries affected by these quotas.
dcd66bf9667816cfc3419f2040e03f5621d88555Andreas Gustafsson </p>
dcd66bf9667816cfc3419f2040e03f5621d88555Andreas Gustafsson</li>
dcd66bf9667816cfc3419f2040e03f5621d88555Andreas Gustafsson<li class="listitem">
dcd66bf9667816cfc3419f2040e03f5621d88555Andreas Gustafsson<p>
f4f3f2cf3499cf6c32f6329aca08b5c557f507f1Mark Andrews Added support for <span class="command"><strong>dnstap</strong></span>, a fast,
f4f3f2cf3499cf6c32f6329aca08b5c557f507f1Mark Andrews flexible method for capturing and logging DNS traffic,
f4f3f2cf3499cf6c32f6329aca08b5c557f507f1Mark Andrews developed by Robert Edmonds at Farsight Security, Inc.,
f4f3f2cf3499cf6c32f6329aca08b5c557f507f1Mark Andrews whose assistance is gratefully acknowledged.
f4f3f2cf3499cf6c32f6329aca08b5c557f507f1Mark Andrews </p>
f4f3f2cf3499cf6c32f6329aca08b5c557f507f1Mark Andrews<p>
f4f3f2cf3499cf6c32f6329aca08b5c557f507f1Mark Andrews To enable <span class="command"><strong>dnstap</strong></span> at compile time,
ff8d15be4e6096329fe6ae8217d0adcabd08c94bOlafur Gudmundsson the <span class="command"><strong>fstrm</strong></span> and <span class="command"><strong>protobuf-c</strong></span>
f2fdfe7c42f3b10f3653f851ce5a0a90ee5ac1f9David Lawrence libraries must be available, and BIND must be configured with
f2fdfe7c42f3b10f3653f851ce5a0a90ee5ac1f9David Lawrence <code class="option">--enable-dnstap</code>.
6a13d6f3c687d463a2a88f696a5193a5651612baAndreas Gustafsson </p>
9dff010bd0224c0eb0046e02c51947bf69cbb718David Lawrence<p>
9dff010bd0224c0eb0046e02c51947bf69cbb718David Lawrence A new utility <span class="command"><strong>dnstap-read</strong></span> has been added
9dff010bd0224c0eb0046e02c51947bf69cbb718David Lawrence to allow <span class="command"><strong>dnstap</strong></span> data to be presented in
9dff010bd0224c0eb0046e02c51947bf69cbb718David Lawrence a human-readable format.
996f4a8bc34cb0203ce6a40ff82bca8bf32423ccAndreas Gustafsson </p>
f2fdfe7c42f3b10f3653f851ce5a0a90ee5ac1f9David Lawrence<p>
f2fdfe7c42f3b10f3653f851ce5a0a90ee5ac1f9David Lawrence <span class="command"><strong>rndc dnstap -roll</strong></span> causes <span class="command"><strong>dnstap</strong></span>
6a13d6f3c687d463a2a88f696a5193a5651612baAndreas Gustafsson output files to be rolled like log files -- the most recent output
47b26abe77184f9bedc68e36bdad03332cf67570David Lawrence file is renamed with a <code class="filename">.0</code> suffix, the next
47b26abe77184f9bedc68e36bdad03332cf67570David Lawrence most recent with <code class="filename">.1</code>, etc. (Note that this
c0fcd6b98bc1fe5bbd2bd1a4d729215f65e3d20fJames Brister only works when <span class="command"><strong>dnstap</strong></span> output is being written
c0fcd6b98bc1fe5bbd2bd1a4d729215f65e3d20fJames Brister to a file, not to a UNIX domain socket.) An optional numerical
17d0495c338ca6273cc1e1e3fd9354ab785a9ae9Mark Andrews argument specifies how many backup log files to retain; if not
17d0495c338ca6273cc1e1e3fd9354ab785a9ae9Mark Andrews specified or set to 0, there is no limit.
17d0495c338ca6273cc1e1e3fd9354ab785a9ae9Mark Andrews </p>
4c5651ee049cbace08d5350e3d23a0d6da491fa8James Brister<p>
4c5651ee049cbace08d5350e3d23a0d6da491fa8James Brister <span class="command"><strong>rndc dnstap -reopen</strong></span> simply closes and reopens
4c5651ee049cbace08d5350e3d23a0d6da491fa8James Brister the <span class="command"><strong>dnstap</strong></span> output channel without renaming
e06abf2270cc397e6a1ab8e25055e9c05f256beeJames Brister the output file.
e06abf2270cc397e6a1ab8e25055e9c05f256beeJames Brister </p>
e06abf2270cc397e6a1ab8e25055e9c05f256beeJames Brister<p>
e06abf2270cc397e6a1ab8e25055e9c05f256beeJames Brister For more information on <span class="command"><strong>dnstap</strong></span>, see
e06abf2270cc397e6a1ab8e25055e9c05f256beeJames Brister <a class="link" href="http://dnstap.info" target="_top">http://dnstap.info</a>.
e411a986b94276c28e6a971f9c3b61d45c635456James Brister </p>
e411a986b94276c28e6a971f9c3b61d45c635456James Brister</li>
e411a986b94276c28e6a971f9c3b61d45c635456James Brister<li class="listitem">
e411a986b94276c28e6a971f9c3b61d45c635456James Brister<p>
c6ce77b4dccb15297f78de9e0c00d40f40ce8aa4Mark Andrews New statistics counters have been added to track traffic
c6ce77b4dccb15297f78de9e0c00d40f40ce8aa4Mark Andrews sizes, as specified in RSSAC002. Query and response
76a33ffee5be9a1001c27c103e6d98983443cbfdAndreas Gustafsson message sizes are broken up into ranges of histogram buckets:
76a33ffee5be9a1001c27c103e6d98983443cbfdAndreas Gustafsson TCP and UDP queries of size 0-15, 16-31, ..., 272-288, and 288+,
1d7172079ddd7aaad66a135a814d0013c6503837Andreas Gustafsson and TCP and UDP responses of size 0-15, 16-31, ..., 4080-4095,
1d7172079ddd7aaad66a135a814d0013c6503837Andreas Gustafsson and 4096+. These values can be accessed via the XML and JSON
5159c427839689d5070e2f9c6c9a0168dd9f6583Mark Andrews statistics channels at, for example,
5159c427839689d5070e2f9c6c9a0168dd9f6583Mark Andrews <a class="link" href="http://localhost:8888/xml/v3/traffic" target="_top">http://localhost:8888/xml/v3/traffic</a>
1d7172079ddd7aaad66a135a814d0013c6503837Andreas Gustafsson or
41da7fdc551c50cddebf2c5311e322efd793fd3bDavid Lawrence <a class="link" href="http://localhost:8888/json/v1/traffic" target="_top">http://localhost:8888/json/v1/traffic</a>.
41da7fdc551c50cddebf2c5311e322efd793fd3bDavid Lawrence </p>
5159c427839689d5070e2f9c6c9a0168dd9f6583Mark Andrews<p>
5159c427839689d5070e2f9c6c9a0168dd9f6583Mark Andrews Statistics for RSSAC02v3 traffic-volume, traffic-sizes and
1d7172079ddd7aaad66a135a814d0013c6503837Andreas Gustafsson rcode-volume reporting are now collected.
dd3fc76a33569ee9d5d30effc0d975651a4567f5Andreas Gustafsson </p>
3364cad7e4699aff0b2d5090ab09a6da9733a118Andreas Gustafsson</li>
3364cad7e4699aff0b2d5090ab09a6da9733a118Andreas Gustafsson<li class="listitem">
3364cad7e4699aff0b2d5090ab09a6da9733a118Andreas Gustafsson<p>
dd3fc76a33569ee9d5d30effc0d975651a4567f5Andreas Gustafsson A new DNSSEC key management utility,
e2cf9c2db3fd484d160d3b7850f5e4d9c19945faJames Brister <span class="command"><strong>dnssec-keymgr</strong></span>, has been added. This tool
e2cf9c2db3fd484d160d3b7850f5e4d9c19945faJames Brister is meant to run unattended (e.g., under <span class="command"><strong>cron</strong></span>).
e2cf9c2db3fd484d160d3b7850f5e4d9c19945faJames Brister It reads a policy definition file
dd3fc76a33569ee9d5d30effc0d975651a4567f5Andreas Gustafsson (default: <code class="filename">/etc/dnssec.policy</code>)
e2cf9c2db3fd484d160d3b7850f5e4d9c19945faJames Brister and creates or updates DNSSEC keys as necessary to ensure that a
e2cf9c2db3fd484d160d3b7850f5e4d9c19945faJames Brister zone's keys match the defined policy for that zone. New keys are
e2cf9c2db3fd484d160d3b7850f5e4d9c19945faJames Brister created whenever necessary to ensure rollovers occur correctly.
e2cf9c2db3fd484d160d3b7850f5e4d9c19945faJames Brister Existing keys' timing metadata is adjusted as needed to set the
dd3fc76a33569ee9d5d30effc0d975651a4567f5Andreas Gustafsson correct rollover period, prepublication interval, etc. If
dd3fc76a33569ee9d5d30effc0d975651a4567f5Andreas Gustafsson the configured policy changes, keys are corrected automatically.
e2cf9c2db3fd484d160d3b7850f5e4d9c19945faJames Brister See the <span class="command"><strong>dnssec-keymgr</strong></span> man page for full details.
41da7fdc551c50cddebf2c5311e322efd793fd3bDavid Lawrence </p>
41da7fdc551c50cddebf2c5311e322efd793fd3bDavid Lawrence<p>
e2cf9c2db3fd484d160d3b7850f5e4d9c19945faJames Brister Note: <span class="command"><strong>dnssec-keymgr</strong></span> depends on Python and on
36357e4304862fb47e9fae03c704cb6720310c45James Brister the Python lex/yacc module, PLY. The other Python-based tools,
36357e4304862fb47e9fae03c704cb6720310c45James Brister <span class="command"><strong>dnssec-coverage</strong></span> and
36357e4304862fb47e9fae03c704cb6720310c45James Brister <span class="command"><strong>dnssec-checkds</strong></span>, have been
9bb05852fed91ff3913601b7ed8e43e711aa9094David Lawrence refactored and updated as part of this work.
9bb05852fed91ff3913601b7ed8e43e711aa9094David Lawrence </p>
9bb05852fed91ff3913601b7ed8e43e711aa9094David Lawrence<p>
9bb05852fed91ff3913601b7ed8e43e711aa9094David Lawrence <span class="command"><strong>dnssec-keymgr</strong></span> now takes a -r
9bb05852fed91ff3913601b7ed8e43e711aa9094David Lawrence <em class="replaceable"><code>randomfile</code></em> option.
9bb05852fed91ff3913601b7ed8e43e711aa9094David Lawrence </p>
9bb05852fed91ff3913601b7ed8e43e711aa9094David Lawrence<p>
9bb05852fed91ff3913601b7ed8e43e711aa9094David Lawrence (Many thanks to Sebasti�n
b09983678f5d116d3c8387aaeab4f2dc4deb0454David Lawrence Castro for his assistance in developing this tool at the IETF
b09983678f5d116d3c8387aaeab4f2dc4deb0454David Lawrence 95 Hackathon in Buenos Aires, April 2016.)
b09983678f5d116d3c8387aaeab4f2dc4deb0454David Lawrence </p>
b09983678f5d116d3c8387aaeab4f2dc4deb0454David Lawrence</li>
4be63b1fd8c18dbeca1648d6cf22fa14f057a469David Lawrence<li class="listitem"><p>
4be63b1fd8c18dbeca1648d6cf22fa14f057a469David Lawrence The serial number of a dynamically updatable zone can
4be63b1fd8c18dbeca1648d6cf22fa14f057a469David Lawrence now be set using
4be63b1fd8c18dbeca1648d6cf22fa14f057a469David Lawrence <span class="command"><strong>rndc signing -serial <em class="replaceable"><code>number</code></em> <em class="replaceable"><code>zonename</code></em></strong></span>.
014892d86d30b7eceb0003d51788f9b5cadfc1bfAndreas Gustafsson This is particularly useful with <code class="option">inline-signing</code>
014892d86d30b7eceb0003d51788f9b5cadfc1bfAndreas Gustafsson zones that have been reset. Setting the serial number to a value
b99d080717fdd741961d736581270d37bad8bec0David Lawrence larger than that on the slaves will trigger an AXFR-style
b99d080717fdd741961d736581270d37bad8bec0David Lawrence transfer.
b99d080717fdd741961d736581270d37bad8bec0David Lawrence </p></li>
97f75286ada13a1b06a424607e638bde5ebfb3caAndreas Gustafsson<li class="listitem"><p>
97f75286ada13a1b06a424607e638bde5ebfb3caAndreas Gustafsson When answering recursive queries, SERVFAIL responses can now be
97f75286ada13a1b06a424607e638bde5ebfb3caAndreas Gustafsson cached by the server for a limited time; subsequent queries for
b905ff7cbe3737d3c76115fa71c340a8ce439120David Lawrence the same query name and type will return another SERVFAIL until
b905ff7cbe3737d3c76115fa71c340a8ce439120David Lawrence the cache times out. This reduces the frequency of retries
23a09704774241d2dba059e4d9231cd3d28bb116David Lawrence when a query is persistently failing, which can be a burden
23a09704774241d2dba059e4d9231cd3d28bb116David Lawrence on recursive servers. The SERVFAIL cache timeout is controlled
23a09704774241d2dba059e4d9231cd3d28bb116David Lawrence by <code class="option">servfail-ttl</code>, which defaults to 1 second
358628c8f4804a2db52be0f6d03a66137fab4884David Lawrence and has an upper limit of 30.
358628c8f4804a2db52be0f6d03a66137fab4884David Lawrence </p></li>
358628c8f4804a2db52be0f6d03a66137fab4884David Lawrence<li class="listitem"><p>
358628c8f4804a2db52be0f6d03a66137fab4884David Lawrence The new <span class="command"><strong>rndc nta</strong></span> command can now be used to
54a2e7e8a21ee765f41bd995101995613bff9e8cDavid Lawrence set a "negative trust anchor" (NTA), disabling DNSSEC validation for
54a2e7e8a21ee765f41bd995101995613bff9e8cDavid Lawrence a specific domain; this can be used when responses from a domain
54a2e7e8a21ee765f41bd995101995613bff9e8cDavid Lawrence are known to be failing validation due to administrative error
54a2e7e8a21ee765f41bd995101995613bff9e8cDavid Lawrence rather than because of a spoofing attack. NTAs are strictly
54a2e7e8a21ee765f41bd995101995613bff9e8cDavid Lawrence temporary; by default they expire after one hour, but can be
027212247d59c05452abb7a8b253efe52d14459eDavid Lawrence configured to last up to one week. The default NTA lifetime
027212247d59c05452abb7a8b253efe52d14459eDavid Lawrence can be changed by setting the <code class="option">nta-lifetime</code> in
027212247d59c05452abb7a8b253efe52d14459eDavid Lawrence <code class="filename">named.conf</code>. When added, NTAs are stored in a
027212247d59c05452abb7a8b253efe52d14459eDavid Lawrence file (<code class="filename"><em class="replaceable"><code>viewname</code></em>.nta</code>)
5610876d1b4a851d6d8806d95aff3e571becac5bDavid Lawrence in order to persist across restarts of the <span class="command"><strong>named</strong></span> server.
5610876d1b4a851d6d8806d95aff3e571becac5bDavid Lawrence </p></li>
a2605214c27439a8af2ad4bd9a8630dcfcc8152eDavid Lawrence<li class="listitem"><p>
a2605214c27439a8af2ad4bd9a8630dcfcc8152eDavid Lawrence The EDNS Client Subnet (ECS) option is now supported for
a2605214c27439a8af2ad4bd9a8630dcfcc8152eDavid Lawrence authoritative servers; if a query contains an ECS option then
344e909ce9c59422a70105aba498e68b2d42623bDavid Lawrence ACLs containing <code class="option">geoip</code> or <code class="option">ecs</code>
344e909ce9c59422a70105aba498e68b2d42623bDavid Lawrence elements can match against the address encoded in the option.
738922ba7bb10b206f6f54931aed068e3dcb950dDavid Lawrence This can be used to select a view for a query, so that different
738922ba7bb10b206f6f54931aed068e3dcb950dDavid Lawrence answers can be provided depending on the client network.
eefea43215016bce437ab4a7441b2851fd182960David Lawrence </p></li>
eefea43215016bce437ab4a7441b2851fd182960David Lawrence<li class="listitem"><p>
eefea43215016bce437ab4a7441b2851fd182960David Lawrence The EDNS EXPIRE option has been implemented on the client
9c4f33b6718407e94d50dbfb4977e16d3f83de9dDavid Lawrence side, allowing a slave server to set the expiration timer
9c4f33b6718407e94d50dbfb4977e16d3f83de9dDavid Lawrence correctly when transferring zone data from another slave
9c4f33b6718407e94d50dbfb4977e16d3f83de9dDavid Lawrence server.
c403d3f7d6cb17406e9be03a330ed5cf91619abcDavid Lawrence </p></li>
c403d3f7d6cb17406e9be03a330ed5cf91619abcDavid Lawrence<li class="listitem"><p>
c403d3f7d6cb17406e9be03a330ed5cf91619abcDavid Lawrence A new <code class="option">masterfile-style</code> zone option controls
c403d3f7d6cb17406e9be03a330ed5cf91619abcDavid Lawrence the formatting of text zone files: When set to
a0f6cda5fd9f2fcc4154bb63628f849b639a40caAndreas Gustafsson <code class="literal">full</code>, the zone file will dumped in
a0f6cda5fd9f2fcc4154bb63628f849b639a40caAndreas Gustafsson single-line-per-record format.
a0f6cda5fd9f2fcc4154bb63628f849b639a40caAndreas Gustafsson </p></li>
dc91d010dbd848ab3a11815e5a3d109662a38b0cDavid Lawrence<li class="listitem"><p>
dc91d010dbd848ab3a11815e5a3d109662a38b0cDavid Lawrence <span class="command"><strong>dig +ednsopt</strong></span> can now be used to set
dc91d010dbd848ab3a11815e5a3d109662a38b0cDavid Lawrence arbitrary EDNS options in DNS requests.
e3b3a046bf653d39cb5b92534a6a36fce1702d20Bob Halley </p></li>
e3b3a046bf653d39cb5b92534a6a36fce1702d20Bob Halley<li class="listitem"><p>
e3b3a046bf653d39cb5b92534a6a36fce1702d20Bob Halley <span class="command"><strong>dig +ednsflags</strong></span> can now be used to set
e3b3a046bf653d39cb5b92534a6a36fce1702d20Bob Halley yet-to-be-defined EDNS flags in DNS requests.
e3b3a046bf653d39cb5b92534a6a36fce1702d20Bob Halley </p></li>
e3b3a046bf653d39cb5b92534a6a36fce1702d20Bob Halley<li class="listitem"><p>
904463e94cafd59c8284f472ea8f58f1f311b8cbDavid Lawrence <span class="command"><strong>dig +[no]ednsnegotiation</strong></span> can now be used enable /
904463e94cafd59c8284f472ea8f58f1f311b8cbDavid Lawrence disable EDNS version negotiation.
2d78d06402ef2605ff8f6b3f5008673754d3711eDavid Lawrence </p></li>
2d78d06402ef2605ff8f6b3f5008673754d3711eDavid Lawrence<li class="listitem"><p>
2d78d06402ef2605ff8f6b3f5008673754d3711eDavid Lawrence <span class="command"><strong>dig +header-only</strong></span> can now be used to send
bf6f755a74e24441e96a110b3c8d11cfe2ed0da7David Lawrence queries without a question section.
1a7f6c3898266854db100fb2cb36418d650de8e7Brian Wellington </p></li>
1a7f6c3898266854db100fb2cb36418d650de8e7Brian Wellington<li class="listitem"><p>
1a7f6c3898266854db100fb2cb36418d650de8e7Brian Wellington <span class="command"><strong>dig +ttlunits</strong></span> causes <span class="command"><strong>dig</strong></span>
1a7f6c3898266854db100fb2cb36418d650de8e7Brian Wellington to print TTL values with time-unit suffixes: w, d, h, m, s for
56433595bb938c21fd3b07a0f7c565d942bb8780David Lawrence weeks, days, hours, minutes, and seconds.
56433595bb938c21fd3b07a0f7c565d942bb8780David Lawrence </p></li>
fc9e755ba340607d76c7de897ee2d985d3b24505David Lawrence<li class="listitem"><p>
fc9e755ba340607d76c7de897ee2d985d3b24505David Lawrence <span class="command"><strong>dig +zflag</strong></span> can be used to set the last
fc9e755ba340607d76c7de897ee2d985d3b24505David Lawrence unassigned DNS header flag bit. This bit is normally zero.
7896e45912df15d07eb99f885b9d9c15ad5f3f68David Lawrence </p></li>
7896e45912df15d07eb99f885b9d9c15ad5f3f68David Lawrence<li class="listitem"><p>
7896e45912df15d07eb99f885b9d9c15ad5f3f68David Lawrence <span class="command"><strong>dig +dscp=<em class="replaceable"><code>value</code></em></strong></span>
7896e45912df15d07eb99f885b9d9c15ad5f3f68David Lawrence can now be used to set the DSCP code point in outgoing query
7896e45912df15d07eb99f885b9d9c15ad5f3f68David Lawrence packets.
32eddfc189108fa93e31761e13150594c7a79d2bDavid Lawrence </p></li>
32eddfc189108fa93e31761e13150594c7a79d2bDavid Lawrence<li class="listitem"><p>
32eddfc189108fa93e31761e13150594c7a79d2bDavid Lawrence <span class="command"><strong>dig +mapped</strong></span> can now be used to determine
32eddfc189108fa93e31761e13150594c7a79d2bDavid Lawrence if mapped IPv4 addresses can be used.
b8dd48ecf83142f6ee7238cbd68fec455e527fc8Mark Andrews </p></li>
b8dd48ecf83142f6ee7238cbd68fec455e527fc8Mark Andrews<li class="listitem"><p>
b8dd48ecf83142f6ee7238cbd68fec455e527fc8Mark Andrews <code class="option">serial-update-method</code> can now be set to
68e4926b2262571e004b4be00b905ec776c01d9cMichael Graff <code class="literal">date</code>. On update, the serial number will
68e4926b2262571e004b4be00b905ec776c01d9cMichael Graff be set to the current date in YYYYMMDDNN format.
68e4926b2262571e004b4be00b905ec776c01d9cMichael Graff </p></li>
6c7e680943ccdb75f23b050a7bc5ac0825e5244aMark Andrews<li class="listitem"><p>
6c7e680943ccdb75f23b050a7bc5ac0825e5244aMark Andrews <span class="command"><strong>dnssec-signzone -N date</strong></span> also sets the serial
6c7e680943ccdb75f23b050a7bc5ac0825e5244aMark Andrews number to YYYYMMDDNN.
6c7e680943ccdb75f23b050a7bc5ac0825e5244aMark Andrews </p></li>
6c7e680943ccdb75f23b050a7bc5ac0825e5244aMark Andrews<li class="listitem"><p>
6c7e680943ccdb75f23b050a7bc5ac0825e5244aMark Andrews <span class="command"><strong>named -L <em class="replaceable"><code>filename</code></em></strong></span>
61e9c1cdbe29683bb2db388e4fc6a6fd59315cefDavid Lawrence causes <span class="command"><strong>named</strong></span> to send log messages to the
61e9c1cdbe29683bb2db388e4fc6a6fd59315cefDavid Lawrence specified file by default instead of to the system log.
61e9c1cdbe29683bb2db388e4fc6a6fd59315cefDavid Lawrence </p></li>
8b11f3debd9a9494d5aec60ea228ab393fbdc26eDavid Lawrence<li class="listitem"><p>
8b11f3debd9a9494d5aec60ea228ab393fbdc26eDavid Lawrence The rate limiter configured by the
8b11f3debd9a9494d5aec60ea228ab393fbdc26eDavid Lawrence <code class="option">serial-query-rate</code> option no longer covers
2cc1d2536d5834fbe20281068b8bd34dd1ee5337David Lawrence NOTIFY messages; those are now separately controlled by
2cc1d2536d5834fbe20281068b8bd34dd1ee5337David Lawrence <code class="option">notify-rate</code> and
2cc1d2536d5834fbe20281068b8bd34dd1ee5337David Lawrence <code class="option">startup-notify-rate</code> (the latter of which
140d92622430165001bd91ba2e7d516992faeb2fMichael Sawyer controls the rate of NOTIFY messages sent when the server
140d92622430165001bd91ba2e7d516992faeb2fMichael Sawyer is first started up or reconfigured).
6d208969b3ed736f434bc5120044f8fd2f595f22David Lawrence </p></li>
6d208969b3ed736f434bc5120044f8fd2f595f22David Lawrence<li class="listitem"><p>
145bd6ea3394faf2faa40c99cb6bb7c96027ae16David Lawrence The default number of tasks and client objects available
145bd6ea3394faf2faa40c99cb6bb7c96027ae16David Lawrence for serving lightweight resolver queries have been increased,
145bd6ea3394faf2faa40c99cb6bb7c96027ae16David Lawrence and are now configurable via the new <code class="option">lwres-tasks</code>
0c33e418cb443ade8ed55f5433bc4d409c7af0b8David Lawrence and <code class="option">lwres-clients</code> options in
0c33e418cb443ade8ed55f5433bc4d409c7af0b8David Lawrence <code class="filename">named.conf</code>. [RT #35857]
0c33e418cb443ade8ed55f5433bc4d409c7af0b8David Lawrence </p></li>
8a0ba20b16177d40bd557b491f56003c7d38a4a2David Lawrence<li class="listitem"><p>
8a0ba20b16177d40bd557b491f56003c7d38a4a2David Lawrence Log output to files can now be buffered by specifying
8a0ba20b16177d40bd557b491f56003c7d38a4a2David Lawrence <span class="command"><strong>buffered yes;</strong></span> when creating a channel.
b3e77535185043f089b346166440402d092030c3David Lawrence </p></li>
b3e77535185043f089b346166440402d092030c3David Lawrence<li class="listitem"><p>
b3e77535185043f089b346166440402d092030c3David Lawrence <span class="command"><strong>delv +tcp</strong></span> will exclusively use TCP when
b3e77535185043f089b346166440402d092030c3David Lawrence sending queries.
b3e77535185043f089b346166440402d092030c3David Lawrence </p></li>
03f0e349d81a580a562fd21402ef97d11c15429aBrian Wellington<li class="listitem"><p>
9e842bb2d3802de0f7da5d6d33382a4859bc6876Brian Wellington <span class="command"><strong>named</strong></span> will now check to see whether
9e842bb2d3802de0f7da5d6d33382a4859bc6876Brian Wellington other name server processes are running before starting up.
9e842bb2d3802de0f7da5d6d33382a4859bc6876Brian Wellington This is implemented in two ways: 1) by refusing to start
e1747e09e7cc6771dca1a1702e42e6401dbeebedDavid Lawrence if the configured network interfaces all return "address
e1747e09e7cc6771dca1a1702e42e6401dbeebedDavid Lawrence in use", and 2) by attempting to acquire a lock on a file
e1747e09e7cc6771dca1a1702e42e6401dbeebedDavid Lawrence specified by the <code class="option">lock-file</code> option or
a231769eaae9add23b16124388e1d474fb488873David Lawrence the <span class="command"><strong>-X</strong></span> command line option. The
a231769eaae9add23b16124388e1d474fb488873David Lawrence default lock file is
a231769eaae9add23b16124388e1d474fb488873David Lawrence <code class="filename">/var/run/named/named.lock</code>.
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence Specifying <code class="literal">none</code> will disable the lock
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence file check.
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence </p></li>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence<li class="listitem"><p>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence <span class="command"><strong>rndc delzone</strong></span> can now be applied to zones
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence which were configured in <code class="filename">named.conf</code>;
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence it is no longer restricted to zones which were added by
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence <span class="command"><strong>rndc addzone</strong></span>. (Note, however, that
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence this does not edit <code class="filename">named.conf</code>; the zone
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence must be removed from the configuration or it will return
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence when <span class="command"><strong>named</strong></span> is restarted or reloaded.)
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence </p></li>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence<li class="listitem"><p>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence <span class="command"><strong>rndc modzone</strong></span> can be used to reconfigure
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence a zone, using similar syntax to <span class="command"><strong>rndc addzone</strong></span>.
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence </p></li>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence<li class="listitem"><p>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence <span class="command"><strong>rndc showzone</strong></span> displays the current
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence configuration for a specified zone.
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence </p></li>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence<li class="listitem">
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence<p>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence Added server-side support for pipelined TCP queries. Clients
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence may continue sending queries via TCP while previous queries are
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence processed in parallel. Responses are sent when they are
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence ready, not necessarily in the order in which the queries were
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence received.
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence </p>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence<p>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence To revert to the former behavior for a particular
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence client address or range of addresses, specify the address prefix
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence in the "keep-response-order" option. To revert to the former
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence behavior for all clients, use "keep-response-order { any; };".
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence </p>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence</li>
6e49e91bd08778d7eae45a2229dcf41ed97cc636David Lawrence<li class="listitem"><p>
a59b51eb1d9a80d682efc669414e16dc8da47e95David Lawrence The new <span class="command"><strong>mdig</strong></span> command is a version of
a59b51eb1d9a80d682efc669414e16dc8da47e95David Lawrence <span class="command"><strong>dig</strong></span> that sends multiple pipelined
6b526894f47f6d6ff08f4f49b952b4ec8247ba9eDavid Lawrence queries and then waits for responses, instead of sending one
6b526894f47f6d6ff08f4f49b952b4ec8247ba9eDavid Lawrence query and waiting the response before sending the next. [RT #38261]
f6cdcafa335c3ff1890c20dcaf276546f8523fe3David Lawrence </p></li>
f6cdcafa335c3ff1890c20dcaf276546f8523fe3David Lawrence<li class="listitem"><p>
f6cdcafa335c3ff1890c20dcaf276546f8523fe3David Lawrence To enable better monitoring and troubleshooting of RFC 5011
16a107c904a30a687a08efec86a26a2f9398d2edAndreas Gustafsson trust anchor management, the new <span class="command"><strong>rndc managed-keys</strong></span>
16a107c904a30a687a08efec86a26a2f9398d2edAndreas Gustafsson can be used to check status of trust anchors or to force keys
16a107c904a30a687a08efec86a26a2f9398d2edAndreas Gustafsson to be refreshed. Also, the managed-keys data file now has
16a107c904a30a687a08efec86a26a2f9398d2edAndreas Gustafsson easier-to-read comments. [RT #38458]
33e927bf8622db6d3e5ecfd871f517db47fa722bDavid Lawrence </p></li>
33e927bf8622db6d3e5ecfd871f517db47fa722bDavid Lawrence<li class="listitem"><p>
33e927bf8622db6d3e5ecfd871f517db47fa722bDavid Lawrence An <span class="command"><strong>--enable-querytrace</strong></span> configure switch is
3e6b98586e823544344bcbbcad825d3d4485de59David Lawrence now available to enable very verbose query tracelogging. This
3e6b98586e823544344bcbbcad825d3d4485de59David Lawrence option can only be set at compile time. This option has a
3e6b98586e823544344bcbbcad825d3d4485de59David Lawrence negative performance impact and should be used only for
2d78d06402ef2605ff8f6b3f5008673754d3711eDavid Lawrence debugging. [RT #37520]
947bd6c648bd29bc226971324de1b30230a56a22David Lawrence </p></li>
878363c06b3d42f8fa4acca0c4aec9252b7844d9David Lawrence<li class="listitem"><p>
878363c06b3d42f8fa4acca0c4aec9252b7844d9David Lawrence A new <span class="command"><strong>tcp-only</strong></span> option can be specified
cc5547dbcb04bdc498cf050c6104a1974f68c6eaAndreas Gustafsson in <span class="command"><strong>server</strong></span> statements to force
cc5547dbcb04bdc498cf050c6104a1974f68c6eaAndreas Gustafsson <span class="command"><strong>named</strong></span> to connect to the specified
b8957f3496b6a900df9ca263864a47dbb1cb8978David Lawrence server via TCP. [RT #37800]
b8957f3496b6a900df9ca263864a47dbb1cb8978David Lawrence </p></li>
c7f22f83aac9e61dafee191cad040e9c42652cc8David Lawrence<li class="listitem"><p>
c7f22f83aac9e61dafee191cad040e9c42652cc8David Lawrence The <span class="command"><strong>nxdomain-redirect</strong></span> option specifies
c7f22f83aac9e61dafee191cad040e9c42652cc8David Lawrence a DNS namespace to use for NXDOMAIN redirection. When a
c4717613e45323ed23dc6e9162cba89f1f83830cDavid Lawrence recursive lookup returns NXDOMAIN, a second lookup is
c4717613e45323ed23dc6e9162cba89f1f83830cDavid Lawrence initiated with the specified name appended to the query
c4717613e45323ed23dc6e9162cba89f1f83830cDavid Lawrence name. This allows NXDOMAIN redirection data to be supplied
f6d6835ed5bb14f7d87cb9b736deadf9de2085ddAndreas Gustafsson by multiple zones configured on the server or by recursive
f6d6835ed5bb14f7d87cb9b736deadf9de2085ddAndreas Gustafsson queries to other servers. (The older method, using
f6d6835ed5bb14f7d87cb9b736deadf9de2085ddAndreas Gustafsson a single <span class="command"><strong>type redirect</strong></span> zone, has
d41c9885ecfb4be7382fd32a58ae4a9fb2056b81David Lawrence better average performance but is less flexible.) [RT #37989]
d41c9885ecfb4be7382fd32a58ae4a9fb2056b81David Lawrence </p></li>
38feb01f1b0a3ac65897ae63c22c27c72e8cfda1David Lawrence<li class="listitem"><p>
38feb01f1b0a3ac65897ae63c22c27c72e8cfda1David Lawrence The following types have been implemented: CSYNC, NINFO, RKEY,
38feb01f1b0a3ac65897ae63c22c27c72e8cfda1David Lawrence SINK, TA, TALINK.
38feb01f1b0a3ac65897ae63c22c27c72e8cfda1David Lawrence </p></li>
802aa6f2b70cc0b4e69ef0a1dcab0a8d68a0fdeaDavid Lawrence<li class="listitem"><p>
802aa6f2b70cc0b4e69ef0a1dcab0a8d68a0fdeaDavid Lawrence A new <span class="command"><strong>message-compression</strong></span> option can be
802aa6f2b70cc0b4e69ef0a1dcab0a8d68a0fdeaDavid Lawrence used to specify whether or not to use name compression when
5b27fa26dd1288f61de9ace6f4ec56be63858048David Lawrence answering queries. Setting this to <strong class="userinput"><code>no</code></strong>
5b27fa26dd1288f61de9ace6f4ec56be63858048David Lawrence results in larger responses, but reduces CPU consumption and
5b27fa26dd1288f61de9ace6f4ec56be63858048David Lawrence may improve throughput. The default is <strong class="userinput"><code>yes</code></strong>.
5b27fa26dd1288f61de9ace6f4ec56be63858048David Lawrence </p></li>
5b27fa26dd1288f61de9ace6f4ec56be63858048David Lawrence<li class="listitem"><p>
5b27fa26dd1288f61de9ace6f4ec56be63858048David Lawrence A <span class="command"><strong>read-only</strong></span> option is now available in the
32d7adf5ee52c5a86122ee3d9e35a894fc5ed0a6Bob Halley <span class="command"><strong>controls</strong></span> statement to grant non-destructive
32d7adf5ee52c5a86122ee3d9e35a894fc5ed0a6Bob Halley control channel access. In such cases, a restricted set of
32d7adf5ee52c5a86122ee3d9e35a894fc5ed0a6Bob Halley <span class="command"><strong>rndc</strong></span> commands are allowed, which can
32d7adf5ee52c5a86122ee3d9e35a894fc5ed0a6Bob Halley report information from <span class="command"><strong>named</strong></span>, but cannot
32d7adf5ee52c5a86122ee3d9e35a894fc5ed0a6Bob Halley reconfigure or stop the server. By default, the control channel
32d7adf5ee52c5a86122ee3d9e35a894fc5ed0a6Bob Halley access is <span class="emphasis"><em>not</em></span> restricted to these
32d7adf5ee52c5a86122ee3d9e35a894fc5ed0a6Bob Halley read-only operations. [RT #40498]
32d7adf5ee52c5a86122ee3d9e35a894fc5ed0a6Bob Halley </p></li>
32d7adf5ee52c5a86122ee3d9e35a894fc5ed0a6Bob Halley<li class="listitem"><p>
32d7adf5ee52c5a86122ee3d9e35a894fc5ed0a6Bob Halley When loading a signed zone, <span class="command"><strong>named</strong></span> will
cc43f2461d2b7da80105cf6d1b96bda4e93303cdDavid Lawrence now check whether an RRSIG's inception time is in the future,
cc43f2461d2b7da80105cf6d1b96bda4e93303cdDavid Lawrence and if so, it will regenerate the RRSIG immediately. This helps
58bc93c3ddbdf0b2fde9b7d2b4342f90d83ec633David Lawrence when a system's clock needs to be reset backwards.
58bc93c3ddbdf0b2fde9b7d2b4342f90d83ec633David Lawrence </p></li>
58bc93c3ddbdf0b2fde9b7d2b4342f90d83ec633David Lawrence<li class="listitem"><p>
7ce81e15fa98db5b13fba06d54526e8679ac064cDavid Lawrence The new <span class="command"><strong>minimal-any</strong></span> option reduces the size
7ce81e15fa98db5b13fba06d54526e8679ac064cDavid Lawrence of answers to UDP queries for type ANY by implementing one of
8fedfa7b45989d3c1715e414637bc1a96331fd14David Lawrence the strategies in "draft-ietf-dnsop-refuse-any": returning
8fedfa7b45989d3c1715e414637bc1a96331fd14David Lawrence a single arbitrarily-selected RRset that matches the query
7da5c63dc0eaeec88aaf67b7aeee43ab0b0125baDavid Lawrence name rather than returning all of the matching RRsets.
7da5c63dc0eaeec88aaf67b7aeee43ab0b0125baDavid Lawrence Thanks to Tony Finch for the contribution. [RT #41615]
7da5c63dc0eaeec88aaf67b7aeee43ab0b0125baDavid Lawrence </p></li>
7da5c63dc0eaeec88aaf67b7aeee43ab0b0125baDavid Lawrence</ul></div>
7da5c63dc0eaeec88aaf67b7aeee43ab0b0125baDavid Lawrence</div>
7da5c63dc0eaeec88aaf67b7aeee43ab0b0125baDavid Lawrence<div class="section">
32eeec855957c3dd38f0d6c98ca79b67a71300b6Brian Wellington<div class="titlepage"><div><div><h3 class="title">
32eeec855957c3dd38f0d6c98ca79b67a71300b6Brian Wellington<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
f3f88c6802df4cfee59439b19a1c49637b70342dDavid Lawrence<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
f3f88c6802df4cfee59439b19a1c49637b70342dDavid Lawrence<li class="listitem"><p>
f3f88c6802df4cfee59439b19a1c49637b70342dDavid Lawrence The ISC DNSSEC Lookaside Validation (DLV) service is scheduled
77f372eed39827f5efef476602de7c0505f99b91David Lawrence to be disabled in 2017. A warning is now logged when
77f372eed39827f5efef476602de7c0505f99b91David Lawrence <span class="command"><strong>named</strong></span> is configured to use this service,
77f372eed39827f5efef476602de7c0505f99b91David Lawrence either explicitly or via <code class="option">dnssec-lookaside auto;</code>.
8b7304a34c751e519ede7d00b77f1f962c0a37e4David Lawrence [RT #42207]
8b7304a34c751e519ede7d00b77f1f962c0a37e4David Lawrence </p></li>
8b7304a34c751e519ede7d00b77f1f962c0a37e4David Lawrence<li class="listitem"><p>
8b7304a34c751e519ede7d00b77f1f962c0a37e4David Lawrence The timers returned by the statistics channel (indicating current
8b7304a34c751e519ede7d00b77f1f962c0a37e4David Lawrence time, server boot time, and most recent reconfiguration time) are
8b7304a34c751e519ede7d00b77f1f962c0a37e4David Lawrence now reported with millisecond accuracy. [RT #40082]
cabcfd3e90a647c7bab3c5cc3ef7b36f49830787David Lawrence </p></li>
cabcfd3e90a647c7bab3c5cc3ef7b36f49830787David Lawrence<li class="listitem"><p>
cabcfd3e90a647c7bab3c5cc3ef7b36f49830787David Lawrence Updated the compiled-in addresses for H.ROOT-SERVERS.NET
cabcfd3e90a647c7bab3c5cc3ef7b36f49830787David Lawrence and L.ROOT-SERVERS.NET.
cabcfd3e90a647c7bab3c5cc3ef7b36f49830787David Lawrence </p></li>
585529aaeb95a71cd3d95df2602a4688fc7c3292David Lawrence<li class="listitem"><p>
585529aaeb95a71cd3d95df2602a4688fc7c3292David Lawrence ACLs containing <span class="command"><strong>geoip asnum</strong></span> elements were
585529aaeb95a71cd3d95df2602a4688fc7c3292David Lawrence not correctly matched unless the full organization name was
585529aaeb95a71cd3d95df2602a4688fc7c3292David Lawrence specified in the ACL (as in
585529aaeb95a71cd3d95df2602a4688fc7c3292David Lawrence <span class="command"><strong>geoip asnum "AS1234 Example, Inc.";</strong></span>).
d111a46c88adda33a93839f4934e127b6147d87dBob Halley They can now match against the AS number alone (as in
e4e183af576855f4ccc9fc28084ffe095aaa5b55Andreas Gustafsson <span class="command"><strong>geoip asnum "AS1234";</strong></span>).
e4e183af576855f4ccc9fc28084ffe095aaa5b55Andreas Gustafsson </p></li>
e4e183af576855f4ccc9fc28084ffe095aaa5b55Andreas Gustafsson<li class="listitem"><p>
e49a98d47fea220023c22bcc7204f13f7f0b07feBrian Wellington When using native PKCS#11 cryptography (i.e.,
6f17d90364f01c3e81073a9ffb40b0093878c8e2Brian Wellington <span class="command"><strong>configure --enable-native-pkcs11</strong></span>) HSM PINs
195da2b26542b85d60308b2af35ea9966df9c3bbMichael Graff of up to 256 characters can now be used.
195da2b26542b85d60308b2af35ea9966df9c3bbMichael Graff </p></li>
195da2b26542b85d60308b2af35ea9966df9c3bbMichael Graff<li class="listitem"><p>
e9a9ae4fc627f24cb960a3008f2723ba9a55b274Brian Wellington NXDOMAIN responses to queries of type DS are now cached separately
e9a9ae4fc627f24cb960a3008f2723ba9a55b274Brian Wellington from those for other types. This helps when using "grafted" zones
e9a9ae4fc627f24cb960a3008f2723ba9a55b274Brian Wellington of type forward, for which the parent zone does not contain a
d1bdeae7bb7a0642170d5476c2fd901db3028143Andreas Gustafsson delegation, such as local top-level domains. Previously a query
d1bdeae7bb7a0642170d5476c2fd901db3028143Andreas Gustafsson of type DS for such a zone could cause the zone apex to be cached
d1bdeae7bb7a0642170d5476c2fd901db3028143Andreas Gustafsson as NXDOMAIN, blocking all subsequent queries. (Note: This
d111a46c88adda33a93839f4934e127b6147d87dBob Halley change is only helpful when DNSSEC validation is not enabled.
d111a46c88adda33a93839f4934e127b6147d87dBob Halley "Grafted" zones without a delegation in the parent are not a
d111a46c88adda33a93839f4934e127b6147d87dBob Halley recommended configuration.)
d111a46c88adda33a93839f4934e127b6147d87dBob Halley </p></li>
585529aaeb95a71cd3d95df2602a4688fc7c3292David Lawrence<li class="listitem"><p>
9e53cbca72767d0c91962b7a01650ea07d7398ddMark Andrews Update forwarding performance has been improved by allowing
585529aaeb95a71cd3d95df2602a4688fc7c3292David Lawrence a single TCP connection to be shared between multiple updates.
9e53cbca72767d0c91962b7a01650ea07d7398ddMark Andrews </p></li>
585529aaeb95a71cd3d95df2602a4688fc7c3292David Lawrence<li class="listitem"><p>
2d0c5f1eada2015324cb89c11c7c5c11cccb493fAndreas Gustafsson By default, <span class="command"><strong>nsupdate</strong></span> will now check
3bb3b7ac462a90c2b8b1fb783324d800e2ba748cMichael Graff the correctness of hostnames when adding records of type
3bb3b7ac462a90c2b8b1fb783324d800e2ba748cMichael Graff A, AAAA, MX, SOA, NS, SRV or PTR. This behavior can be
3bb3b7ac462a90c2b8b1fb783324d800e2ba748cMichael Graff disabled with <span class="command"><strong>check-names no</strong></span>.
c6adcd09c8d5c0acd47a8dccb8061bb1105cad95Michael Graff </p></li>
c6adcd09c8d5c0acd47a8dccb8061bb1105cad95Michael Graff<li class="listitem"><p>
b5fff54fe9335b20c02d749831fc0eaeda97198fBrian Wellington Added support for OPENPGPKEY type.
15a0ed30600ea88fe1227233155586f0c3c6cc34Bob Halley </p></li>
15a0ed30600ea88fe1227233155586f0c3c6cc34Bob Halley<li class="listitem"><p>
15a0ed30600ea88fe1227233155586f0c3c6cc34Bob Halley The names of the files used to store managed keys and added
15a0ed30600ea88fe1227233155586f0c3c6cc34Bob Halley zones for each view are no longer based on the SHA256 hash
53c892082e4dd70a12bb5badd81a9e939d7e6efdBrian Wellington of the view name, except when this is necessary because the
53c892082e4dd70a12bb5badd81a9e939d7e6efdBrian Wellington view name contains characters that would be incompatible with use
b5fff54fe9335b20c02d749831fc0eaeda97198fBrian Wellington as a file name. For views whose names do not contain forward
b5fff54fe9335b20c02d749831fc0eaeda97198fBrian Wellington slashes ('/'), backslashes ('\'), or capital letters - which
b5fff54fe9335b20c02d749831fc0eaeda97198fBrian Wellington could potentially cause namespace collision problems on
b5fff54fe9335b20c02d749831fc0eaeda97198fBrian Wellington case-insensitive filesystems - files will now be named
b5fff54fe9335b20c02d749831fc0eaeda97198fBrian Wellington after the view (for example, <code class="filename">internal.mkeys</code>
b5fff54fe9335b20c02d749831fc0eaeda97198fBrian Wellington or <code class="filename">external.nzf</code>). However, to ensure
3ae757933270e8298a6c1c5f9dfd30a4d852972cAndreas Gustafsson consistent behavior when upgrading, if a file using the old
3ae757933270e8298a6c1c5f9dfd30a4d852972cAndreas Gustafsson name format is found to exist, it will continue to be used.
3ae757933270e8298a6c1c5f9dfd30a4d852972cAndreas Gustafsson </p></li>
3ae757933270e8298a6c1c5f9dfd30a4d852972cAndreas Gustafsson<li class="listitem"><p>
3ae757933270e8298a6c1c5f9dfd30a4d852972cAndreas Gustafsson "rndc" can now return text output of arbitrary size to
b61bbad878d0ac563a093525aa826cdba0fd43bfMark Andrews the caller. (Prior to this, certain commands such as
b61bbad878d0ac563a093525aa826cdba0fd43bfMark Andrews "rndc tsig-list" and "rndc zonestatus" could return
b61bbad878d0ac563a093525aa826cdba0fd43bfMark Andrews truncated output.)
4716e94840921878b26e493576f84afe4fe08752Mark Andrews </p></li>
4716e94840921878b26e493576f84afe4fe08752Mark Andrews<li class="listitem"><p>
4716e94840921878b26e493576f84afe4fe08752Mark Andrews Errors reported when running <span class="command"><strong>rndc addzone</strong></span>
622af581bd08a61d12c70f80b1d40d0d9c8a1fa3David Lawrence (e.g., when a zone file cannot be loaded) have been clarified
622af581bd08a61d12c70f80b1d40d0d9c8a1fa3David Lawrence to make it easier to diagnose problems.
622af581bd08a61d12c70f80b1d40d0d9c8a1fa3David Lawrence </p></li>
3db95284356cd54df84ed2425f189ad2b44e4992David Lawrence<li class="listitem"><p>
3db95284356cd54df84ed2425f189ad2b44e4992David Lawrence When encountering an authoritative name server whose name is
b4b032ab5a3d0e96e7c752e232e3050e8806b8cbBob Halley an alias pointing to another name, the resolver treats
0e9c5d24d25cb77a6935abf9247734b576626c9fBob Halley this as an error and skips to the next server. Previously
0e9c5d24d25cb77a6935abf9247734b576626c9fBob Halley this happened silently; now the error will be logged to
3886e748a4086b813e3453232a742903762fedadBob Halley the newly-created "cname" log category.
3886e748a4086b813e3453232a742903762fedadBob Halley </p></li>
3886e748a4086b813e3453232a742903762fedadBob Halley<li class="listitem"><p>
3886e748a4086b813e3453232a742903762fedadBob Halley If <span class="command"><strong>named</strong></span> is not configured to validate
3886e748a4086b813e3453232a742903762fedadBob Halley answers, then allow fallback to plain DNS on timeout even when
3886e748a4086b813e3453232a742903762fedadBob Halley we know the server supports EDNS. This will allow the server to
b4b032ab5a3d0e96e7c752e232e3050e8806b8cbBob Halley potentially resolve signed queries when TCP is being
b4b032ab5a3d0e96e7c752e232e3050e8806b8cbBob Halley blocked.
b4b032ab5a3d0e96e7c752e232e3050e8806b8cbBob Halley </p></li>
b4b032ab5a3d0e96e7c752e232e3050e8806b8cbBob Halley<li class="listitem"><p>
b4b032ab5a3d0e96e7c752e232e3050e8806b8cbBob Halley Large inline-signing changes should be less disruptive.
ce0004744d2c232581af53cbc6201f4ec4cf1f1cBrian Wellington Signature generation is now done incrementally; the number
ce0004744d2c232581af53cbc6201f4ec4cf1f1cBrian Wellington of signatures to be generated in each quantum is controlled
ce0004744d2c232581af53cbc6201f4ec4cf1f1cBrian Wellington by "sig-signing-signatures <em class="replaceable"><code>number</code></em>;".
ce0004744d2c232581af53cbc6201f4ec4cf1f1cBrian Wellington [RT #37927]
ce0004744d2c232581af53cbc6201f4ec4cf1f1cBrian Wellington </p></li>
ce0004744d2c232581af53cbc6201f4ec4cf1f1cBrian Wellington<li class="listitem">
ce0004744d2c232581af53cbc6201f4ec4cf1f1cBrian Wellington<p>
b4b4adc097365bd3f980b30bc7cc30199f4b8456Andreas Gustafsson The experimental SIT option (code point 65001) of BIND
b4b4adc097365bd3f980b30bc7cc30199f4b8456Andreas Gustafsson 9.10.0 through BIND 9.10.2 has been replaced with the COOKIE
b4b4adc097365bd3f980b30bc7cc30199f4b8456Andreas Gustafsson option (code point 10). It is no longer experimental, and
134ba0e08a0ae9a564a8d8628fc633377d3fc239Bob Halley is sent by default, by both <span class="command"><strong>named</strong></span> and
83a39d3f3c9b9966bc060d46e8e419adb004888aAndreas Gustafsson <span class="command"><strong>dig</strong></span>.
134ba0e08a0ae9a564a8d8628fc633377d3fc239Bob Halley </p>
134ba0e08a0ae9a564a8d8628fc633377d3fc239Bob Halley<p>
134ba0e08a0ae9a564a8d8628fc633377d3fc239Bob Halley The SIT-related named.conf options have been marked as
134ba0e08a0ae9a564a8d8628fc633377d3fc239Bob Halley obsolete, and are otherwise ignored.
83a39d3f3c9b9966bc060d46e8e419adb004888aAndreas Gustafsson </p>
8426878e988859184706f36e2229e24e77b80aa4Andreas Gustafsson</li>
8426878e988859184706f36e2229e24e77b80aa4Andreas Gustafsson<li class="listitem"><p>
0f7045b0c437b158c61c195c319d2762882ece83Andreas Gustafsson When <span class="command"><strong>dig</strong></span> receives a truncated (TC=1)
0f7045b0c437b158c61c195c319d2762882ece83Andreas Gustafsson response or a BADCOOKIE response code from a server, it
0f7045b0c437b158c61c195c319d2762882ece83Andreas Gustafsson will automatically retry the query using the server COOKIE
7c0e50b5623a6ffc9e3986e129f8ca6bae9aabfaBrian Wellington that was returned by the server in its initial response.
7c0e50b5623a6ffc9e3986e129f8ca6bae9aabfaBrian Wellington [RT #39047]
a25310fd1dce652cdebba2b3dbc5d38cc3706745Andreas Gustafsson </p></li>
a25310fd1dce652cdebba2b3dbc5d38cc3706745Andreas Gustafsson<li class="listitem"><p>
a25310fd1dce652cdebba2b3dbc5d38cc3706745Andreas Gustafsson A alternative NXDOMAIN redirect method (nxdomain-redirect)
a25310fd1dce652cdebba2b3dbc5d38cc3706745Andreas Gustafsson which allows the redirect information to be looked up from
42712a426dd62518ca7c36982867e5622f7265e7Michael Graff a namespace on the Internet rather than requiring a zone
42712a426dd62518ca7c36982867e5622f7265e7Michael Graff to be configured on the server is now available.
e6a6c0a5d6393d3a7f75b486f16e4ef15c4857bbDavid Lawrence </p></li>
e6a6c0a5d6393d3a7f75b486f16e4ef15c4857bbDavid Lawrence<li class="listitem"><p>
e6a6c0a5d6393d3a7f75b486f16e4ef15c4857bbDavid Lawrence Retrieving the local port range from net.ipv4.ip_local_port_range
e6a6c0a5d6393d3a7f75b486f16e4ef15c4857bbDavid Lawrence on Linux is now supported.
11a898e05092e8477fbfe1a245c1c5871a846638Andreas Gustafsson </p></li>
11a898e05092e8477fbfe1a245c1c5871a846638Andreas Gustafsson<li class="listitem"><p>
5d4f11b265c396d71ec2162a632e620425481a9eDavid Lawrence A new <code class="option">nsip-wait-recurse</code> directive has been
5d4f11b265c396d71ec2162a632e620425481a9eDavid Lawrence added to RPZ, specifying whether to look up unknown name server
b295930144c8782e84528dcd355153ae5a5d66e8David Lawrence IP addresses and wait for a response before applying RPZ-NSIP rules.
b295930144c8782e84528dcd355153ae5a5d66e8David Lawrence The default is <strong class="userinput"><code>yes</code></strong>. If set to
b295930144c8782e84528dcd355153ae5a5d66e8David Lawrence <strong class="userinput"><code>no</code></strong>, <span class="command"><strong>named</strong></span> will only
0bcb1d4d630f8d7547ee62870e1b059827cc1c8aDavid Lawrence apply RPZ-NSIP rules to servers whose addresses are already cached.
0bcb1d4d630f8d7547ee62870e1b059827cc1c8aDavid Lawrence The addresses will be looked up in the background so the rule can
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister be applied on subsequent queries. This improves performance when
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister the cache is cold, at the cost of temporary imprecision in applying
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister policy directives. [RT #35009]
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister </p></li>
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister<li class="listitem"><p>
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister Within the <code class="option">response-policy</code> option, it is now
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister possible to configure RPZ rewrite logging on a per-zone basis
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister using the <code class="option">log</code> clause.
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister </p></li>
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister<li class="listitem"><p>
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister The default preferred glue is now the address type of the
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister transport the query was received over.
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister </p></li>
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister<li class="listitem"><p>
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister On machines with 2 or more processors (CPU), the default value
ce3be21d63d1e06b222ecb66b4eae909b4658d53James Brister for the number of UDP listeners has been changed to the number
7b2db4b8d13e3d8bc81419ffcc8b39de8193ef63David Lawrence of detected processors minus one.
7b2db4b8d13e3d8bc81419ffcc8b39de8193ef63David Lawrence </p></li>
7b2db4b8d13e3d8bc81419ffcc8b39de8193ef63David Lawrence<li class="listitem"><p>
7b2db4b8d13e3d8bc81419ffcc8b39de8193ef63David Lawrence Zone transfers now use smaller message sizes to improve
9e7c9ad159b581714c67148c3c698c12730d7ef7James Brister message compression. This results in reduced network usage.
9e7c9ad159b581714c67148c3c698c12730d7ef7James Brister </p></li>
bf062442eeef2fe404d728891b1317b01fbb7908Andreas Gustafsson<li class="listitem">
bf062442eeef2fe404d728891b1317b01fbb7908Andreas Gustafsson<p>
bf062442eeef2fe404d728891b1317b01fbb7908Andreas Gustafsson Added support for the AVC resource record type (Application
bf062442eeef2fe404d728891b1317b01fbb7908Andreas Gustafsson Visibility and Control).
bf062442eeef2fe404d728891b1317b01fbb7908Andreas Gustafsson </p>
bf062442eeef2fe404d728891b1317b01fbb7908Andreas Gustafsson<p>
bf062442eeef2fe404d728891b1317b01fbb7908Andreas Gustafsson Changed <span class="command"><strong>rndc reconfig</strong></span> behavior so that newly
bf062442eeef2fe404d728891b1317b01fbb7908Andreas Gustafsson added zones are loaded asynchronously and the loading does not
bf062442eeef2fe404d728891b1317b01fbb7908Andreas Gustafsson block the server.
404e3e4738e97d5dff48fab1e76839e963cb16a6Brian Wellington </p>
404e3e4738e97d5dff48fab1e76839e963cb16a6Brian Wellington</li>
404e3e4738e97d5dff48fab1e76839e963cb16a6Brian Wellington</ul></div>
5b84a24a3bf571adae57c1bc006a0bce0f9f2befDavid Lawrence</div>
5b84a24a3bf571adae57c1bc006a0bce0f9f2befDavid Lawrence<div class="section">
5b84a24a3bf571adae57c1bc006a0bce0f9f2befDavid Lawrence<div class="titlepage"><div><div><h3 class="title">
5b84a24a3bf571adae57c1bc006a0bce0f9f2befDavid Lawrence<a name="relnotes_port"></a>Porting Changes</h3></div></div></div>
5b84a24a3bf571adae57c1bc006a0bce0f9f2befDavid Lawrence<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem"><p>
5b84a24a3bf571adae57c1bc006a0bce0f9f2befDavid Lawrence None.
d9cc295339982d8d86075ab4285cc700d354e2eeBob Halley </p></li></ul></div>
7d1d130f4fe1b7485142c4f55a4ef3760b5fa30aBrian Wellington</div>
7d1d130f4fe1b7485142c4f55a4ef3760b5fa30aBrian Wellington<div class="section">
7d1d130f4fe1b7485142c4f55a4ef3760b5fa30aBrian Wellington<div class="titlepage"><div><div><h3 class="title">
d9cc295339982d8d86075ab4285cc700d354e2eeBob Halley<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
d9cc295339982d8d86075ab4285cc700d354e2eeBob Halley<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
d9cc295339982d8d86075ab4285cc700d354e2eeBob Halley<li class="listitem"><p>
9ac79ef3f89b23d80f9649abf71fdc65bb7a8b62David Lawrence Fixed a crash when calling <span class="command"><strong>rndc stats</strong></span> on some
9ac79ef3f89b23d80f9649abf71fdc65bb7a8b62David Lawrence Windows builds: some Visual Studio compilers generate code that
9ac79ef3f89b23d80f9649abf71fdc65bb7a8b62David Lawrence crashes when the "%z" printf() format specifier is used. [RT #42380]
a6a0b5e9b7078887a73ecec8be2935daa287a389James Brister </p></li>
a6a0b5e9b7078887a73ecec8be2935daa287a389James Brister<li class="listitem"><p>
a6a0b5e9b7078887a73ecec8be2935daa287a389James Brister Windows installs were failing due to triggering UAC without
a6a0b5e9b7078887a73ecec8be2935daa287a389James Brister the installation binary being signed.
be768c2e952c34438025999125f984995a2c675fBob Halley </p></li>
da6affdf7dd677a636155e4a41f6de416a2d815bBob Halley<li class="listitem"><p>
da6affdf7dd677a636155e4a41f6de416a2d815bBob Halley A change in the internal binary representation of the RBT database
da6affdf7dd677a636155e4a41f6de416a2d815bBob Halley node structure enabled a race condition to occur (especially when
da6affdf7dd677a636155e4a41f6de416a2d815bBob Halley BIND was built with certain compilers or optimizer settings),
da6affdf7dd677a636155e4a41f6de416a2d815bBob Halley leading to inconsistent database state which caused random
da6affdf7dd677a636155e4a41f6de416a2d815bBob Halley assertion failures. [RT #42380]
be768c2e952c34438025999125f984995a2c675fBob Halley </p></li>
be768c2e952c34438025999125f984995a2c675fBob Halley</ul></div>
be768c2e952c34438025999125f984995a2c675fBob Halley</div>
f00e30e9322fb2170ad3e21c3336c5b81be964c2James Brister<div class="section">
01e320c4fb51c802e9fe86c192fbebf4229ca918Bob Halley<div class="titlepage"><div><div><h3 class="title">
19e0c849f69ad8b655b4d199e16de0a4a94562d6Bob Halley<a name="end_of_life"></a>End of Life</h3></div></div></div>
19e0c849f69ad8b655b4d199e16de0a4a94562d6Bob Halley<p>
19e0c849f69ad8b655b4d199e16de0a4a94562d6Bob Halley The end of life for BIND 9.11 is yet to be determined but
19e0c849f69ad8b655b4d199e16de0a4a94562d6Bob Halley will not be before BIND 9.13.0 has been released for 6 months.
9ac79ef3f89b23d80f9649abf71fdc65bb7a8b62David Lawrence <a class="link" href="https://www.isc.org/downloads/software-support-policy/" target="_top">https://www.isc.org/downloads/software-support-policy/</a>
01e320c4fb51c802e9fe86c192fbebf4229ca918Bob Halley </p>
01e320c4fb51c802e9fe86c192fbebf4229ca918Bob Halley</div>
01e320c4fb51c802e9fe86c192fbebf4229ca918Bob Halley<div class="section">
dd6132005a5c48dea642c2ed0507bf472c8ee9bbJames Brister<div class="titlepage"><div><div><h3 class="title">
dd6132005a5c48dea642c2ed0507bf472c8ee9bbJames Brister<a name="relnotes_thanks"></a>Thank You</h3></div></div></div>
dd6132005a5c48dea642c2ed0507bf472c8ee9bbJames Brister<p>
d6d18435cd47a57f43af2eab835d0f6b7a76f2bdAndreas Gustafsson Thank you to everyone who assisted us in making this release possible.
d6d18435cd47a57f43af2eab835d0f6b7a76f2bdAndreas Gustafsson If you would like to contribute to ISC to assist us in continuing to
d6d18435cd47a57f43af2eab835d0f6b7a76f2bdAndreas Gustafsson make quality open source software, please visit our donations page at
3f46e84f9ff264cac8c07c2136a507827afb2760James Brister <a class="link" href="http://www.isc.org/donate/" target="_top">http://www.isc.org/donate/</a>.
3f46e84f9ff264cac8c07c2136a507827afb2760James Brister </p>
3f46e84f9ff264cac8c07c2136a507827afb2760James Brister</div>
3f46e84f9ff264cac8c07c2136a507827afb2760James Brister</div>
3f46e84f9ff264cac8c07c2136a507827afb2760James Brister</div>
3f46e84f9ff264cac8c07c2136a507827afb2760James Brister<div class="navfooter">
3f46e84f9ff264cac8c07c2136a507827afb2760James Brister<hr>
3f46e84f9ff264cac8c07c2136a507827afb2760James Brister<table width="100%" summary="Navigation footer">
3f46e84f9ff264cac8c07c2136a507827afb2760James Brister<tr>
99b80297d416ebb722b2515023c51b3aacdc1fb9Bob Halley<td width="40%" align="left">
fdb12d38d325efba64581bdee7fac188466fff55Bob Halley<a accesskey="p" href="Bv9ARM.ch08.html">Prev</a>�</td>
fdb12d38d325efba64581bdee7fac188466fff55Bob Halley<td width="20%" align="center">�</td>
fdb12d38d325efba64581bdee7fac188466fff55Bob Halley<td width="40%" align="right">�<a accesskey="n" href="Bv9ARM.ch10.html">Next</a>
fdb12d38d325efba64581bdee7fac188466fff55Bob Halley</td>
fdb12d38d325efba64581bdee7fac188466fff55Bob Halley</tr>
fdb12d38d325efba64581bdee7fac188466fff55Bob Halley<tr>
43a5758df763a04d907a8b406e89a96f5c207a9cBrian Wellington<td width="40%" align="left" valign="top">Chapter�8.�Troubleshooting�</td>
43a5758df763a04d907a8b406e89a96f5c207a9cBrian Wellington<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
43a5758df763a04d907a8b406e89a96f5c207a9cBrian Wellington<td width="40%" align="right" valign="top">�Appendix�B.�A Brief History of the <acronym class="acronym">DNS</acronym> and <acronym class="acronym">BIND</acronym>
c73aafe6016ed1a7a6972681148cedf6a48a21bcBrian Wellington</td>
c73aafe6016ed1a7a6972681148cedf6a48a21bcBrian Wellington</tr>
c73aafe6016ed1a7a6972681148cedf6a48a21bcBrian Wellington</table>
99b80297d416ebb722b2515023c51b3aacdc1fb9Bob Halley</div>
99b80297d416ebb722b2515023c51b3aacdc1fb9Bob Halley<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.0b2</p>
99b80297d416ebb722b2515023c51b3aacdc1fb9Bob Halley</body>
99b80297d416ebb722b2515023c51b3aacdc1fb9Bob Halley</html>
99b80297d416ebb722b2515023c51b3aacdc1fb9Bob Halley