Bv9ARM.ch09.html revision adabefa84c3dcf048566cc23fd457c577f208eea
1c57c3f79db0bf0358bbe6d7b5ad650c0c852f4bTinderbox User<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - Copyright (C) 2000-2016 Internet Systems Consortium, Inc. ("ISC")
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - This Source Code Form is subject to the terms of the Mozilla Public
1c57c3f79db0bf0358bbe6d7b5ad650c0c852f4bTinderbox User - License, v. 2.0. If a copy of the MPL was not distributed with this
1c57c3f79db0bf0358bbe6d7b5ad650c0c852f4bTinderbox User - file, You can obtain one at http://mozilla.org/MPL/2.0/.
1c57c3f79db0bf0358bbe6d7b5ad650c0c852f4bTinderbox User<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
1c57c3f79db0bf0358bbe6d7b5ad650c0c852f4bTinderbox User<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
f9ce6280cec79deb16ff6d9807aa493ff23e10d9Tinderbox User<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
e21a6f5ec65fad1c18f6723f5495e55bcd15a53dTinderbox User<link rel="prev" href="Bv9ARM.ch08.html" title="Chapter�8.�Troubleshooting">
f9ce6280cec79deb16ff6d9807aa493ff23e10d9Tinderbox User<link rel="next" href="Bv9ARM.ch10.html" title="Appendix�B.�A Brief History of the DNS and BIND">
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
46472a450e043434d78fa18edc73bca8c47f3981Tinderbox User<table width="100%" summary="Navigation header">
46472a450e043434d78fa18edc73bca8c47f3981Tinderbox User<tr><th colspan="3" align="center">Appendix�A.�Release Notes</th></tr>
46472a450e043434d78fa18edc73bca8c47f3981Tinderbox User<a accesskey="p" href="Bv9ARM.ch08.html">Prev</a>�</td>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<td width="20%" align="right">�<a accesskey="n" href="Bv9ARM.ch10.html">Next</a>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<div class="titlepage"><div><div><h1 class="title">
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<a name="Bv9ARM.ch09"></a>Release Notes</h1></div></div></div>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.1b1</a></span></dt>
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_maint">Maintenance</a></span></dt>
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_misc">Miscellaneous Notes</a></span></dt>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User<div class="titlepage"><div><div><h2 class="title" style="clear: both">
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.1b1</h2></div></div></div>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<div class="titlepage"><div><div><h3 class="title">
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<a name="relnotes_intro"></a>Introduction</h3></div></div></div>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User This document summarizes changes since the last production
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User release on the BIND 9.11 branch.
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User Please see the <code class="filename">CHANGES</code> file for a further
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User list of bug fixes and other changes.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<div class="titlepage"><div><div><h3 class="title">
63d4f7ac5634f3b20d42cc160c01ac03d013b11cTinderbox User<a name="relnotes_download"></a>Download</h3></div></div></div>
63d4f7ac5634f3b20d42cc160c01ac03d013b11cTinderbox User The latest versions of BIND 9 software can always be found at
63d4f7ac5634f3b20d42cc160c01ac03d013b11cTinderbox User <a class="link" href="http://www.isc.org/downloads/" target="_top">http://www.isc.org/downloads/</a>.
63d4f7ac5634f3b20d42cc160c01ac03d013b11cTinderbox User There you will find additional information about each release,
63d4f7ac5634f3b20d42cc160c01ac03d013b11cTinderbox User source code, and pre-compiled versions for Microsoft Windows
63d4f7ac5634f3b20d42cc160c01ac03d013b11cTinderbox User operating systems.
576bce9d7331498ca5453f8743f94ed8e2e59d9fTinderbox User<div class="titlepage"><div><div><h3 class="title">
63d4f7ac5634f3b20d42cc160c01ac03d013b11cTinderbox User<a name="relnotes_license"></a>License Change</h3></div></div></div>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User With the release of BIND 9.11.0, ISC changed to the open
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User source license for BIND from the ISC license to the Mozilla
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt Public License (MPL 2.0).
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User The MPL-2.0 license requires that if you make changes to
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User licensed software (e.g. BIND) and distribute them outside
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User your organization, that you publish those changes under that
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User same license. It does not require that you publish or disclose
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User anything other than the changes you made to our software.
1ffe3f29e3cd0d8355500e9fd34de918ad9b4a01Tinderbox User This new requirement will not affect anyone who is using BIND
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User without redistributing it, nor anyone redistributing it without
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User changes, therefore this change will be without consequence
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User for most individuals and organizations who are using BIND.
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User Those unsure whether or not the license change affects their
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User use of BIND, or who wish to discuss how to comply with the
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User license may contact ISC at <a class="link" href="https://www.isc.org/mission/contact/" target="_top">
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User<div class="titlepage"><div><div><h3 class="title">
eb2a5f51bd5c100799d93d51c9e22666cbd64d90Tinderbox User<a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
260e8e04b0dc24cb884c789b5d9eb046457f264eTinderbox User If a server is configured with a response policy zone (RPZ)
1ffe3f29e3cd0d8355500e9fd34de918ad9b4a01Tinderbox User that rewrites an answer with local data, and is also configured
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User for DNS64 address mapping, a NULL pointer can be read
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User triggering a server crash. This flaw is disclosed in
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User CVE-2017-3135. [RT #44434]
eb2a5f51bd5c100799d93d51c9e22666cbd64d90Tinderbox User A coding error in the <code class="option">nxdomain-redirect</code>
3ba1f79ade054aa6a0dc5032502bcdcf357cd7bdTinderbox User feature could lead to an assertion failure if the redirection
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt namespace was served from a local authoritative data source
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User such as a local zone or a DLZ instead of via recursive
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt lookup. This flaw is disclosed in CVE-2016-9778. [RT #43837]
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <span class="command"><strong>named</strong></span> could mishandle authority sections
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt with missing RRSIGs, triggering an assertion failure. This
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt flaw is disclosed in CVE-2016-9444. [RT #43632]
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <span class="command"><strong>named</strong></span> mishandled some responses where
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User covering RRSIG records were returned without the requested
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt data, resulting in an assertion failure. This flaw is
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt disclosed in CVE-2016-9147. [RT #43548]
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <span class="command"><strong>named</strong></span> incorrectly tried to cache TKEY
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt records which could trigger an assertion failure when there was
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User a class mismatch. This flaw is disclosed in CVE-2016-9131.
7e71f05d8643aca84914437c900cb716444507e4Tinderbox User It was possible to trigger assertions when processing
7e71f05d8643aca84914437c900cb716444507e4Tinderbox User responses containing answers of type DNAME. This flaw is
7e71f05d8643aca84914437c900cb716444507e4Tinderbox User disclosed in CVE-2016-8864. [RT #43465]
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt Added the ability to specify the maximum number of records
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User permitted in a zone (<code class="option">max-records #;</code>).
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User This provides a mechanism to block overly large zone
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt transfers, which is a potential risk with slave zones from
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt other parties, as described in CVE-2016-6170.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<div class="titlepage"><div><div><h3 class="title">
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt Expanded and improved the YAML output from
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <span class="command"><strong>dnstap-read -y</strong></span>: it now includes packet
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt size and a detailed breakdown of message contents.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt [RT #43622] [RT #43642]
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt If an ACL is specified with an address prefix in which the
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt prefix length is longer than the address portion (for example,
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt 192.0.2.1/8), <span class="command"><strong>named</strong></span> will now log a warning.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt In future releases this will be a fatal configuration error.
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<div class="titlepage"><div><div><h3 class="title">
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
76cf91b5df7a1bc450afcb9ce7585c61bb87de68Tinderbox User Named could deadlock there were multiple changes to
1700442a7751c2bbdafe2d039cebbd8316496957Tinderbox User NSEC/NSEC3 parameters for a zone being processed at the
1700442a7751c2bbdafe2d039cebbd8316496957Tinderbox User same time. [RT #42770]
1700442a7751c2bbdafe2d039cebbd8316496957Tinderbox User Named could trigger a assertion when sending notify
1700442a7751c2bbdafe2d039cebbd8316496957Tinderbox User messages. [RT #44019]
1700442a7751c2bbdafe2d039cebbd8316496957Tinderbox User Referencing a nonexistent zone in a <span class="command"><strong>response-policy</strong></span>
76cf91b5df7a1bc450afcb9ce7585c61bb87de68Tinderbox User statement could cause an assertion failure during configuration.
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User <span class="command"><strong>rndc addzone</strong></span> could cause a crash
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User when attempting to add a zone with a type other than
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <span class="command"><strong>master</strong></span> or <span class="command"><strong>slave</strong></span>.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt Such zones are now rejected. [RT #43665]
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <span class="command"><strong>named</strong></span> could hang when encountering log
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User file names with large apparent gaps in version number (for
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt example, when files exist called "logfile.0", "logfile.1",
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User and "logfile.1482954169"). This is now handled correctly.
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User If a zone was updated while <span class="command"><strong>named</strong></span> was
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User processing a query for nonexistent data, it could return
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User out-of-sync NSEC3 records causing potential DNSSEC validation
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User failure. [RT #43247]
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User<div class="titlepage"><div><div><h3 class="title">
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User<a name="relnotes_maint"></a>Maintenance</h3></div></div></div>
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User The built-in root hints have been updated to include an
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User IPv6 address (2001:500:12::d0d) for G.ROOT-SERVERS.NET.
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User<div class="titlepage"><div><div><h3 class="title">
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User<a name="relnotes_misc"></a>Miscellaneous Notes</h3></div></div></div>
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User Authoritative server support for the EDNS Client Subnet option
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User (ECS), introduced in BIND 9.11.0, was based on an early version
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User of the specification, and is now known to have incompatibilities
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User with other ECS implementations. It is also inefficient, requiring
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User a separate view for each answer, and is unable to correct for
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User overlapping subnets in the configuration. It is intended for
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User testing purposes but is not recommended for for production use.
3241ddcf9354c5ab50f4df5a656e72a5c68e172bTinderbox User This was not made sufficiently clear in the documentation at
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User the time of release.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<div class="titlepage"><div><div><h3 class="title">
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<a name="end_of_life"></a>End of Life</h3></div></div></div>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User The end of life for BIND 9.11 is yet to be determined but
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt will not be before BIND 9.13.0 has been released for 6 months.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <a class="link" href="https://www.isc.org/downloads/software-support-policy/" target="_top">https://www.isc.org/downloads/software-support-policy/</a>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<div class="titlepage"><div><div><h3 class="title">
e2b184f84e846bbcb764b6f0aef5dcd583d3d7a1Tinderbox User<a name="relnotes_thanks"></a>Thank You</h3></div></div></div>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User Thank you to everyone who assisted us in making this release possible.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt If you would like to contribute to ISC to assist us in continuing to
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt make quality open source software, please visit our donations page at
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <a class="link" href="http://www.isc.org/donate/" target="_top">http://www.isc.org/donate/</a>.
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<a accesskey="p" href="Bv9ARM.ch08.html">Prev</a>�</td>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<td width="40%" align="right">�<a accesskey="n" href="Bv9ARM.ch10.html">Next</a>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<td width="40%" align="left" valign="top">Chapter�8.�Troubleshooting�</td>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<td width="40%" align="right" valign="top">�Appendix�B.�A Brief History of the <acronym class="acronym">DNS</acronym> and <acronym class="acronym">BIND</acronym>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.1b1</p>