Bv9ARM.ch09.html revision 659d063f23a35d77ad5826e6556d3137672bb937
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - Copyright (C) 2000-2003 Internet Software Consortium.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - Permission to use, copy, modify, and/or distribute this software for any
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - purpose with or without fee is hereby granted, provided that the above
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - copyright notice and this permission notice appear in all copies.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh - PERFORMANCE OF THIS SOFTWARE.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<!-- $Id$ -->
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
73a3eccd27d9673a6407274ea0de350699562fd9David Hollister<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<link rel="prev" href="Bv9ARM.ch08.html" title="Chapter�8.�Troubleshooting">
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<link rel="next" href="Bv9ARM.ch10.html" title="Appendix�B.�A Brief History of the DNS and BIND">
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<tr><th colspan="3" align="center">Appendix�A.�Release Notes</th></tr>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<td width="20%" align="right">�<a accesskey="n" href="Bv9ARM.ch10.html">Next</a>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<a name="Bv9ARM.ch09"></a>Appendix�A.�Release Notes</h2></div></div></div>
96c4a178a18cd52ee5001195f1552d9cef0c38f0Chris Horne<dt><span class="sect1"><a href="Bv9ARM.ch09.html#id2585697">Release Notes for BIND Version 9.11.0pre-alpha</a></span></dt>
96c4a178a18cd52ee5001195f1552d9cef0c38f0Chris Horne<dt><span class="sect2"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<dt><span class="sect2"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<dt><span class="sect2"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
4b4564630e2553df86b078f1fce1624dade2b2cbDavid Hollister<dt><span class="sect2"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<dt><span class="sect2"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<dt><span class="sect2"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<dt><span class="sect2"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<dt><span class="sect2"><a href="Bv9ARM.ch09.html#relnotes_thanks">Thank You</a></span></dt>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<div class="titlepage"><div><div><h2 class="title" style="clear: both">
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<a name="id2585697"></a>Release Notes for BIND Version 9.11.0pre-alpha</h2></div></div></div>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<a name="relnotes_intro"></a>Introduction</h3></div></div></div>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh This document summarizes changes since the last production release
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh of BIND on the corresponding major release branch.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<a name="relnotes_download"></a>Download</h3></div></div></div>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The latest versions of BIND 9 software can always be found at
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <a href="http://www.isc.org/downloads/" target="_top">http://www.isc.org/downloads/</a>.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh There you will find additional information about each release,
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh source code, and pre-compiled versions for Microsoft Windows
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh operating systems.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh On servers configured to perform DNSSEC validation using
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh managed trust anchors (i.e., keys configured explicitly
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh via <span><strong class="command">managed-keys</strong></span>, or implicitly
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh via <span><strong class="command">dnssec-validation auto;</strong></span> or
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dnssec-lookaside auto;</strong></span>), revoking
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh a trust anchor and sending a new untrusted replacement
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh could cause <span><strong class="command">named</strong></span> to crash with an
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh assertion failure. This could occur in the event of a
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh botched key rollover, or potentially as a result of a
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh deliberate attack if the attacker was in position to
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh monitor the victim's DNS traffic.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh This flaw was discovered by Jan-Piet Mens, and is
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh disclosed in CVE-2015-1349. [RT #38344]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh A flaw in delegation handling could be exploited to put
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">named</strong></span> into an infinite loop, in which
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh each lookup of a name server triggered additional lookups
601c90f161ff0319c1b4a2c3362b466043a65d8dSrikanth, Ramana of more name servers. This has been addressed by placing
601c90f161ff0319c1b4a2c3362b466043a65d8dSrikanth, Ramana limits on the number of levels of recursion
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">named</strong></span> will allow (default 7), and
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh on the number of queries that it will send before
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh terminating a recursive query (default 50).
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The recursion depth limit is configured via the
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="option">max-recursion-depth</code> option, and the query limit
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh via the <code class="option">max-recursion-queries</code> option.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The flaw was discovered by Florian Maury of ANSSI, and is
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh disclosed in CVE-2014-8500. [RT #37580]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh Two separate problems were identified in BIND's GeoIP code that
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh could lead to an assertion failure. One was triggered by use of
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh both IPv4 and IPv6 address families, the other by referencing
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh a GeoIP database in <code class="filename">named.conf</code> which was
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh not installed. Both are covered by CVE-2014-8680. [RT #37672]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh A less serious security flaw was also found in GeoIP: changes
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh to the <span><strong class="command">geoip-directory</strong></span> option in
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="filename">named.conf</code> were ignored when running
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">rndc reconfig</strong></span>. In theory, this could allow
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">named</strong></span> to allow access to unintended clients.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<a name="relnotes_features"></a>New Features</h3></div></div></div>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The serial number of a dynamically updatable zone can
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh now be set using
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">rndc signing -serial <em class="replaceable"><code>number</code></em> <em class="replaceable"><code>zonename</code></em></strong></span>.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh This is particularly useful with <code class="option">inline-signing</code>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh zones that have been reset. Setting the serial number to a value
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh larger than that on the slaves will trigger an AXFR-style
73a3eccd27d9673a6407274ea0de350699562fd9David Hollister When answering recursive queries, SERVFAIL responses can now be
73a3eccd27d9673a6407274ea0de350699562fd9David Hollister cached by the server for a limited time; subsequent queries for
73a3eccd27d9673a6407274ea0de350699562fd9David Hollister the same query name and type will return another SERVFAIL until
73a3eccd27d9673a6407274ea0de350699562fd9David Hollister the cache times out. This reduces the frequency of retries
73a3eccd27d9673a6407274ea0de350699562fd9David Hollister when a query is persistently failing, which can be a burden
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh on recursive serviers. The SERVFAIL cache timeout is controlled
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh by <code class="option">servfail-ttl</code>, which defaults to 10 seconds
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh and has an upper limit of 30.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The new <span><strong class="command">rndc nta</strong></span> command can now be used to
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh set a "negative trust anchor" (NTA), disabling DNSSEC validation for
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh a specific domain; this can be used when responses from a domain
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh are known to be failing validation due to administrative error
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh rather than because of a spoofing attack. NTAs are strictly
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh temporary; by default they expire after one hour, but can be
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh configured to last up to one week. The default NTA lifetime
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh can be changed by setting the <code class="option">nta-lifetime</code> in
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="filename">named.conf</code>. When added, NTAs are stored in a
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh file (<code class="filename"><em class="replaceable"><code>viewname</code></em>.nta</code>)
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh in order to persist across restarts of the named server.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The EDNS Client Subnet (ECS) option is now supported for
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh authoritative servers; if a query contains an ECS option then
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh ACLs containing <code class="option">geoip</code> or <code class="option">ecs</code>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh elements can match against the the address encoded in the option.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh This can be used to select a view for a query, so that different
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh answers can be provided depending on the client network.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The EDNS EXPIRE option has been implemented on the client
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh side, allowing a slave server to set the expiration timer
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh correctly when transferring zone data from another slave
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh A new <code class="option">masterfile-style</code> zone option controls
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh the formatting of text zone files: When set to
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="literal">full</code>, the zone file will dumped in
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh single-line-per-record format.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dig +ednsopt</strong></span> can now be used to set
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh arbitrary EDNS options in DNS requests.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dig +ednsflags</strong></span> can now be used to set
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh yet-to-be-defined EDNS flags in DNS requests.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dig +[no]ednsnegotiation</strong></span> can now be used enable /
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh disable EDNS version negotiation.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dig +header-only</strong></span> can now be used to send
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh queries without a question section.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dig +ttlunits</strong></span> causes <span><strong class="command">dig</strong></span>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh to print TTL values with time-unit suffixes: w, d, h, m, s for
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh weeks, days, hours, minutes, and seconds.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dig +zflag</strong></span> can be used to set the last
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh unassigned DNS header flag bit. This bit in normally zero.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dig +dscp=<em class="replaceable"><code>value</code></em></strong></span>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh can now be used to set the DSCP code point in outgoing query
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="option">serial-update-method</code> can now be set to
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="literal">date</code>. On update, the serial number will
601c90f161ff0319c1b4a2c3362b466043a65d8dSrikanth, Ramana be set to the current date in YYYYMMDDNN format.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dnssec-signzone -N date</strong></span> also sets the serial
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh number to YYYYMMDDNN.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">named -L <em class="replaceable"><code>filename</code></em></strong></span>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh causes named to send log messages to the specified file by
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh default instead of to the system log.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The rate limiter configured by the
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="option">serial-query-rate</code> option no longer covers
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh NOTIFY messages; those are now separately controlled by
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="option">startup-notify-rate</code> (the latter of which
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh controls the rate of NOTIFY messages sent when the server
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh is first started up or reconfigured).
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The default number of tasks and client objects available
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh for serving lightweight resolver queries have been increased,
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh and are now configurable via the new <code class="option">lwres-tasks</code>
6745c559e4b531cf336a91f4653445c32ee46693Jesse Butler and <code class="option">lwres-clients</code> options in
6745c559e4b531cf336a91f4653445c32ee46693Jesse Butler <code class="filename">named.conf</code>. [RT #35857]
6745c559e4b531cf336a91f4653445c32ee46693Jesse Butler Log output to files can now be buffered by specifying
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">buffered yes;</strong></span> when creating a channel.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">delv +tcp</strong></span> will exclusively use TCP when
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh sending queries.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">named</strong></span> will now check to see whether
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh other name server processes are running before starting up.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh This is implemented in two ways: 1) by refusing to start
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh if the configured network interfaces all return "address
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh in use", and 2) by acquiring a file lock on
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="filename">/var/run/named/named.lock</code>, or on a different
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh file specified via the <span><strong class="command">named -X</strong></span> command
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh line option.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">rndc delzone</strong></span> can now be applied to zones
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh which were configured in <code class="filename">named.conf</code>;
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh it is no longer restricted to zones which were added by
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">rndc addzone</strong></span>. (Note, however, that
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh this does not edit <code class="filename">named.conf</code>; the zone
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh must be removed from the configuration or it will return
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh when <span><strong class="command">named</strong></span> is restarted or reloaded.)
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">rndc modzone</strong></span> can be used to reconfigure
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh a zone, using similar syntax to <span><strong class="command">rndc addzone</strong></span>.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">rndc showzone</strong></span> displays the current
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh configuration for a specified zone.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh Added server-side support for pipelined TCP queries. Clients
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler may continue sending queries via TCP while previous queries are
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler processed in parallel. Responses are sent when they are
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler ready, not necessarily in the order in which the queries were
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler To revert to the former behavior for a particular
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler client address or range of addresses, specify the address prefix
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler in the "keep-response-order" option. To revert to the former
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler behavior for all clients, use "keep-response-order { any; };".
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The new <span><strong class="command">mdig</strong></span> command is a version of
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dig</strong></span> that sends multiple pipelined
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh queries and then waits for responses, instead of sending one
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh query and waiting the response before sending the next. [RT #38261]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh To enable better monitoring and troubleshooting of RFC 5011
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh trust anchor management, the new <span><strong class="command">rndc managed-keys</strong></span>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh can be used to check status of trust anchors or to force keys
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh to be refreshed. Also, the managed-keys data file now has
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh easier-to-read comments. [RT #38458]
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler<a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh ACLs containing <span><strong class="command">geoip asnum</strong></span> elements were
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh not correctly matched unless the full organization name was
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh specified in the ACL (as in
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">geoip asnum "AS1234 Example, Inc.";</strong></span>).
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh They can now match against the AS number alone (as in
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">geoip asnum "AS1234";</strong></span>).
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh When using native PKCS#11 cryptography (i.e.,
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">configure --enable-native-pkcs11</strong></span>) HSM PINs
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh of up to 256 characters can now be used.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh NXDOMAIN responses to queries of type DS are now cached separately
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh from those for other types. This helps when using "grafted" zones
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh of type forward, for which the parent zone does not contain a
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh delegation, such as local top-level domains. Previously a query
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh of type DS for such a zone could cause the zone apex to be cached
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh as NXDOMAIN, blocking all subsequent queries. (Note: This
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh change is only helpful when DNSSEC validation is not enabled.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh "Grafted" zones without a delegation in the parent are not a
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh recommended configuration.)
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh Update forwarding performance has been improved by allowing
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh a single TCP connection to be shared between multiple updates.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh By default, <span><strong class="command">nsupdate</strong></span> will now check
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh the correctness of hostnames when adding records of type
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh A, AAAA, MX, SOA, NS, SRV or PTR. This behavior can be
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh disabled with <span><strong class="command">check-names no</strong></span>.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh Added support for OPENPGPKEY type.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The names of the files used to store managed keys and added
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh zones for each view are no longer based on the SHA256 hash
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh of the view name, except when this is necessary because the
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh view name contains characters that would be incompatible with use
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh as a file name. For views whose names do not contain forward
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh slashes ('/'), backslashes ('\'), or capital letters - which
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh could potentially cause namespace collision problems on
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh case-insensitive filesystems - files will now be named
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh after the view (for example, <code class="filename">internal.mkeys</code>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh or <code class="filename">external.nzf</code>). However, to ensure
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh consistent behavior when upgrading, if a file using the old
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh name format is found to exist, it will continue to be used.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh "rndc" can now return text output of arbitrary size to
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh the caller. (Prior to this, certain commands such as
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh "rndc tsig-list" and "rndc zonestatus" could return
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh truncated output.)
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh Errors reported when running <span><strong class="command">rndc addzone</strong></span>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh (e.g., when a zone file cannot be loaded) have been clarified
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh to make it easier to diagnose problems.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh When encountering an authoritative name server whose name is
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh an alias pointing to another name, the resolver treats
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh this as an error and skips to the next server. Previously
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh this happened silently; now the error will be logged to
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh the newly-created "cname" log category.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh If named is not configured to validate the answer then
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh allow fallback to plain DNS on timeout even when we know
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh the server supports EDNS. This will allow the server to
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh potentially resolve signed queries when TCP is being
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">dig</strong></span>, <span><strong class="command">host</strong></span> and
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">nslookup</strong></span> aborted when encountering
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh a name which, after appending search list elements,
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh exceeded 255 bytes. Such names are now skipped, but
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh processing of other names will continue. [RT #36892]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh The error message generated when
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">named-checkzone</strong></span> or
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <span><strong class="command">named-checkconf -z</strong></span> encounters a
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="option">$TTL</code> directive without a value has
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh been clarified. [RT #37138]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh Semicolon characters (;) included in TXT records were
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh incorrectly escaped with a backslash when the record was
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh displayed as text. This is actually only necessary when there
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh are no quotation marks. [RT #37159]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh When files opened for writing by <span><strong class="command">named</strong></span>,
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh such as zone journal files, were referenced more than once
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh in <code class="filename">named.conf</code>, it could lead to file
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh corruption as multiple threads wrote to the same file. This
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh is now detected when loading <code class="filename">named.conf</code>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh and reported as an error. [RT #37172]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh When checking for updates to trust anchors listed in
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <code class="option">managed-keys</code>, <span><strong class="command">named</strong></span>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh now revalidates keys based on the current set of
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh active trust anchors, without relying on any cached
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh record of previous validation. [RT #37506]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh Large-system tuning
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh (<span><strong class="command">configure --with-tuning=large</strong></span>) caused
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh problems on some platforms by setting a socket receive
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh buffer size that was too large. This is now detected and
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh corrected at run time. [RT #37187]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh When NXDOMAIN redirection is in use, queries for a name
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh that is present in the redirection zone but a type that
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh is not present will now return NOERROR instead of NXDOMAIN.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh Due to an inadvertent removal of code in the previous
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh release, when <span><strong class="command">named</strong></span> encountered an
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh authoritative name server which dropped all EDNS queries,
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh it did not always try plain DNS. This has been corrected.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh [RT #37965]
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh A regression caused nsupdate to use the default recursive servers
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister rather than the SOA MNAME server when sending the UPDATE.
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister Adjusted max-recursion-queries to accommodate the smaller
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister initial packet sizes used in BIND 9.10 and higher when
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister contacting authoritative servers for the first time.
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister Built-in "empty" zones did not correctly inherit the
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister "allow-transfer" ACL from the options or view. [RT #38310]
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister Two leaks were fixed that could cause <span><strong class="command">named</strong></span>
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister processes to grow to very large sizes. [RT #38454]
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister Fixed some bugs in RFC 5011 trust anchor management,
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister including a memory leak and a possible loss of state
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister information.[RT #38458]
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister<a name="end_of_life"></a>End of Life</h3></div></div></div>
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister The end of life for BIND 9.11 is yet to be determined but
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister will not be before BIND 9.13.0 has been released for 6 months.
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister <a href="https://www.isc.org/downloads/software-support-policy/" target="_top">https://www.isc.org/downloads/software-support-policy/</a>
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister<div class="titlepage"><div><div><h3 class="title">
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister<a name="relnotes_thanks"></a>Thank You</h3></div></div></div>
9719310a57482091af0a7f0ee31b5e2eec35f154David Hollister Thank you to everyone who assisted us in making this release possible.
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh If you would like to contribute to ISC to assist us in continuing to
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh make quality open source software, please visit our donations page at
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh <a href="http://www.isc.org/donate/" target="_top">http://www.isc.org/donate/</a>.
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler<table width="100%" summary="Navigation footer">
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler<a accesskey="p" href="Bv9ARM.ch08.html">Prev</a>�</td>
5c45adf04db8ffdcb5dd969bb5203ff9b17677dbJesse Butler<td width="40%" align="right">�<a accesskey="n" href="Bv9ARM.ch10.html">Next</a>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<td width="40%" align="left" valign="top">Chapter�8.�Troubleshooting�</td>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
4c06356b0f0fffb4fc1b6eccc8e5d8e2254a84d6dh<td width="40%" align="right" valign="top">�Appendix�B.�A Brief History of the <acronym class="acronym">DNS</acronym> and <acronym class="acronym">BIND</acronym>