Bv9ARM.ch09.html revision 51da15c88648a9e47d0cddff4b2b782665e99401
015055b6e23f5c08f6a5b34726f90b62597e9e45Tinderbox User<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
18920d790825d96ca3943aa2dcb6eb80dc611c5fTinderbox User - Copyright (C) 2000-2017 Internet Systems Consortium, Inc. ("ISC")
e9e4257668ff6c4e583b0c0db2508650b0b677b8Tinderbox User - This Source Code Form is subject to the terms of the Mozilla Public
e9e4257668ff6c4e583b0c0db2508650b0b677b8Tinderbox User - License, v. 2.0. If a copy of the MPL was not distributed with this
c57668a2fbbe558c1bd21652813616f2f517c469Tinderbox User - file, You can obtain one at http://mozilla.org/MPL/2.0/.
8de3f14f1c300c3e1ed99084cc03485b42c92bf1Tinderbox User<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
b886b04d8d2b085cbf3e1bf4442dee87f43ba5e4Tinderbox User<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
e676a596869d8a80a644c99a848afb53d1c5975eMark Andrews<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
e676a596869d8a80a644c99a848afb53d1c5975eMark Andrews<link rel="prev" href="Bv9ARM.ch08.html" title="Chapter�8.�Troubleshooting">
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<link rel="next" href="Bv9ARM.ch10.html" title="Appendix�B.�A Brief History of the DNS and BIND">
a7c412f37cc73d0332887a746e81220cbf09dd00Mark Andrews<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<table width="100%" summary="Navigation header">
e676a596869d8a80a644c99a848afb53d1c5975eMark Andrews<tr><th colspan="3" align="center">Appendix�A.�Release Notes</th></tr>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<a accesskey="p" href="Bv9ARM.ch08.html">Prev</a>�</td>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<td width="20%" align="right">�<a accesskey="n" href="Bv9ARM.ch10.html">Next</a>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<div class="titlepage"><div><div><h1 class="title">
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<a name="Bv9ARM.ch09"></a>Release Notes</h1></div></div></div>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.2b1</a></span></dt>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
015055b6e23f5c08f6a5b34726f90b62597e9e45Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<dt><span class="section"><a href="Bv9ARM.ch09.html#root_key">New DNSSEC Root Key</a></span></dt>
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
dc238a06bffa79de141ee7655765e2df91498a8aTinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater<dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
16f6050f29b6b0422cee858e609f65e474e70ef2Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt<div class="titlepage"><div><div><h2 class="title" style="clear: both">
710bce1a85c96e85ca1a90471382055acd29d51fTinderbox User<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.2b1</h2></div></div></div>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater<div class="titlepage"><div><div><h3 class="title">
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<a name="relnotes_intro"></a>Introduction</h3></div></div></div>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews This document summarizes changes since the last production
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews release on the BIND 9.11 branch.
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews Please see the <code class="filename">CHANGES</code> file for a further
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews list of bug fixes and other changes.
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<div class="titlepage"><div><div><h3 class="title">
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater<a name="relnotes_download"></a>Download</h3></div></div></div>
eabc9c3c07cd956d3c436bd7614cb162dabdda76Mark Andrews The latest versions of BIND 9 software can always be found at
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews <a class="link" href="http://www.isc.org/downloads/" target="_top">http://www.isc.org/downloads/</a>.
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews There you will find additional information about each release,
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews source code, and pre-compiled versions for Microsoft Windows
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews operating systems.
95637507c3d47481fbf0a8a8c750a57f944f677fMark Andrews<div class="titlepage"><div><div><h3 class="title">
2ae159b376dac23870d8005563c585acf85a4b5aEvan Hunt<a name="root_key"></a>New DNSSEC Root Key</h3></div></div></div>
2ae159b376dac23870d8005563c585acf85a4b5aEvan Hunt ICANN is in the process of introducing a new Key Signing Key (KSK) for
2ae159b376dac23870d8005563c585acf85a4b5aEvan Hunt the global root zone. BIND has multiple methods for managing DNSSEC
2ae159b376dac23870d8005563c585acf85a4b5aEvan Hunt trust anchors, with somewhat different behaviors. If the root
2ae159b376dac23870d8005563c585acf85a4b5aEvan Hunt key is configured using the <span class="command"><strong>managed-keys</strong></span>
2ae159b376dac23870d8005563c585acf85a4b5aEvan Hunt statement, or if the pre-configured root key is enabled by using
7cc0a5d21ef046bfd630c4769943d896a7d7472cTinderbox User <span class="command"><strong>dnssec-validation auto</strong></span>, then BIND can keep
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews keys up to date automatically. Servers configured in this way
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews will roll seamlessly to the new key when it is published in
950d203b64f512b85fcc093ee1e9e3e531a1aea3Tinderbox User the root zone. However, keys configured using the
27739dd25026283c24645c8a1044b95ef9eb5ac6Tinderbox User <span class="command"><strong>trusted-keys</strong></span> statement are not automatically
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews maintained. If your server is performing DNSSEC validation
18920d790825d96ca3943aa2dcb6eb80dc611c5fTinderbox User and is configured using <span class="command"><strong>trusted-keys</strong></span>, you are
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews advised to change your configuration before the root zone begins
7a6494cfb6cc7d3f67af07359561e05e6bb8c0edTinderbox User signing with the new KSK. This is currently scheduled for
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User October 11, 2017.
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews This release includes an updated version of the
7a6494cfb6cc7d3f67af07359561e05e6bb8c0edTinderbox User <code class="filename">bind.keys</code> file containing the new root
77932ac533c711eca5cd86de4e7eca8d91102b43Tinderbox User key. This file can also be downloaded from
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <a class="link" href="https://www.isc.org/bind-keys" target="_top">
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<div class="titlepage"><div><div><h3 class="title">
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews<a name="relnotes_license"></a>License Change</h3></div></div></div>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User With the release of BIND 9.11.0, ISC changed to the open
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews source license for BIND from the ISC license to the Mozilla
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User Public License (MPL 2.0).
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews The MPL-2.0 license requires that if you make changes to
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User licensed software (e.g. BIND) and distribute them outside
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews your organization, that you publish those changes under that
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User same license. It does not require that you publish or disclose
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson anything other than the changes you made to our software.
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User This new requirement will not affect anyone who is using BIND
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews without redistributing it, nor anyone redistributing it without
28a5dd720187fddb16055a0f64b63a7b66f29f64Mark Andrews changes, therefore this change will be without consequence
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews for most individuals and organizations who are using BIND.
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User Those unsure whether or not the license change affects their
78f3ed4bc2fcd3d270bfd599804f3b27a1db4d91Mark Andrews use of BIND, or who wish to discuss how to comply with the
fd972434c29fc1169d66594e4cc7697d33036c2bTinderbox User license may contact ISC at <a class="link" href="https://www.isc.org/mission/contact/" target="_top">
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<div class="titlepage"><div><div><h3 class="title">
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont<a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews The BIND installer on Windows used an unquoted service path,
78f3ed4bc2fcd3d270bfd599804f3b27a1db4d91Mark Andrews which can enable privilege escalation. This flaw is disclosed
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews in CVE-2017-3141. [RT #45229]
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews With certain RPZ configurations, a response with TTL 0
78f3ed4bc2fcd3d270bfd599804f3b27a1db4d91Mark Andrews could cause <span class="command"><strong>named</strong></span> to go into an infinite
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews query loop. This flaw is disclosed in CVE-2017-3140.
dc238a06bffa79de141ee7655765e2df91498a8aTinderbox User<div class="titlepage"><div><div><h3 class="title">
37d8e0a4455876fe1e4cca511076cc2c5ab9eedeTinderbox User<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User <span class="command"><strong>dig +ednsopt</strong></span> now accepts the names
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews for EDNS options in addition to numeric values. For example,
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User an EDNS Client-Subnet option could be sent using
fe80a4909bf62b602feaf246866e9d29f7654194Automatic Updater <span class="command"><strong>dig +ednsopt=ecs:...</strong></span>. Thanks to
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User John Worley of Secure64 for the contribution. [RT #44461]
fa0326cc2cf428f67575b6ba3b97b528a31b0010Tinderbox User Threads in <span class="command"><strong>named</strong></span> are now set to human-readable
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User names to assist debugging on operating systems that support that.
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews Threads will have names such as "isc-timer", "isc-sockmgr",
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User "isc-worker0001", and so on. This will affect the reporting of
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews subsidiary thread names in <span class="command"><strong>ps</strong></span> and
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User <span class="command"><strong>top</strong></span>, but not the main thread. [RT #43234]
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson<div class="titlepage"><div><div><h3 class="title">
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User Due to some incorrectly deleted code, when BIND was
dd65eb1efb40b1c47d57963192bfc54873b219beAutomatic Updater built with LMDB, zones that were deleted via
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User <span class="command"><strong>rndc delzone</strong></span> were removed from the
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews running server but were not removed from the new zone
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User database, so that deletion did not persist after a
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews server restart. This has been corrected. [RT #45185]
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User Semicolons are no longer escaped when printing CAA and
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews URI records. This may break applications that depend on the
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User presence of the backslash before the semicolon. [RT #45216]
5f7586ddbd3edd11272cdd30ed613d936129328bTinderbox User<div class="titlepage"><div><div><h3 class="title">
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<a name="end_of_life"></a>End of Life</h3></div></div></div>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User The end of life for BIND 9.11 is yet to be determined but
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews will not be before BIND 9.13.0 has been released for 6 months.
015055b6e23f5c08f6a5b34726f90b62597e9e45Tinderbox User <a class="link" href="https://www.isc.org/downloads/software-support-policy/" target="_top">https://www.isc.org/downloads/software-support-policy/</a>
dc238a06bffa79de141ee7655765e2df91498a8aTinderbox User<div class="titlepage"><div><div><h3 class="title">
37d8e0a4455876fe1e4cca511076cc2c5ab9eedeTinderbox User<a name="relnotes_thanks"></a>Thank You</h3></div></div></div>
dc238a06bffa79de141ee7655765e2df91498a8aTinderbox User Thank you to everyone who assisted us in making this release possible.
a7c412f37cc73d0332887a746e81220cbf09dd00Mark Andrews If you would like to contribute to ISC to assist us in continuing to
7ca715ad1587a68a531ea1cdea07515d7232567eTinderbox User make quality open source software, please visit our donations page at
015055b6e23f5c08f6a5b34726f90b62597e9e45Tinderbox User <a class="link" href="http://www.isc.org/donate/" target="_top">http://www.isc.org/donate/</a>.
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<table width="100%" summary="Navigation footer">
bc0a53583d92309bebcf93c408e2f3247ebd3d3cAutomatic Updater<a accesskey="p" href="Bv9ARM.ch08.html">Prev</a>�</td>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<td width="40%" align="right">�<a accesskey="n" href="Bv9ARM.ch10.html">Next</a>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<td width="40%" align="left" valign="top">Chapter�8.�Troubleshooting�</td>
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<td width="40%" align="right" valign="top">�Appendix�B.�A Brief History of the <acronym class="acronym">DNS</acronym> and <acronym class="acronym">BIND</acronym>
19b3dc94bce93fa76bd7e066f9298630dbc9dcb4Automatic Updater<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.2b1</p>