Evan Hunt
c707e2b986
[master] fix length check in OPENPGPKEY
...
4170. [security] An incorrect boundary check in the OPENPGPKEY
rdatatype could trigger an assertion failure.
[RT #40286 ]
2015-08-11 20:01:44 -07:00
Tinderbox User
5002bd49e8
regen master
2015-08-08 01:06:01 +00:00
Evan Hunt
ce9f893e21
[master] address buffer accounting error
...
4168. [security] A buffer accounting error could trigger an
assertion failure when parsing certain malformed
DNSSEC keys. (CVE-2015-5722) [RT #40212 ]
2015-08-07 13:16:10 -07:00
Jeremy C. Reed
658b0ec21c
fix spelling typo
2015-08-07 12:31:55 -04:00
Tinderbox User
964783e7e8
regen master
2015-08-07 01:06:05 +00:00
Evan Hunt
d2f45d7ffd
[master] revert incorrect 'correction'
2015-08-05 12:15:25 -07:00
Tinderbox User
233da44607
regen master
2015-08-01 01:05:43 +00:00
Evan Hunt
7ed374872f
[master] corrected relnotes -- assertion in name.c not message.c
2015-07-31 12:03:29 -07:00
Mark Andrews
090ba6ff30
update
2015-07-26 06:45:53 +10:00
Tinderbox User
98e1584b29
update copyright notice / whitespace
2015-07-24 23:45:21 +00:00
Mark Andrews
b2b408e4ed
update
2015-07-24 23:39:58 +10:00
Mark Andrews
364162f4ae
update
2015-07-24 15:05:20 +10:00
Mark Andrews
230f8da57c
update
2015-07-24 14:58:21 +10:00
Tinderbox User
5d564da348
regen master
2015-07-24 01:04:59 +00:00
Mark Andrews
98869e60fa
whitespace
2015-07-23 17:56:03 +10:00
Tinderbox User
bd84b04e4f
regen master
2015-07-21 01:05:05 +00:00
Evan Hunt
8a205b4534
[master] remove accidentally duplicated section on clients-per-query
2015-07-20 15:25:28 -07:00
Tinderbox User
bd9a66d553
regen master
2015-07-15 01:04:58 +00:00
Mark Andrews
84114ec4c7
request-nsid -> request-sit
2015-07-15 08:38:08 +10:00
Mark Andrews
c5eb9add52
add CVE-2015-5477
2015-07-15 07:51:06 +10:00
Tinderbox User
b3338fc248
regen master
2015-07-11 01:05:48 +00:00
Tinderbox User
c0cbdeedb5
regen master
2015-07-10 01:05:03 +00:00
Evan Hunt
1479200aa0
[master] DDoS mitigation features
...
3938. [func] Added quotas to be used in recursive resolvers
that are under high query load for names in zones
whose authoritative servers are nonresponsive or
are experiencing a denial of service attack.
- "fetches-per-server" limits the number of
simultaneous queries that can be sent to any
single authoritative server. The configured
value is a starting point; it is automatically
adjusted downward if the server is partially or
completely non-responsive. The algorithm used to
adjust the quota can be configured via the
"fetch-quota-params" option.
- "fetches-per-zone" limits the number of
simultaneous queries that can be sent for names
within a single domain. (Note: Unlike
"fetches-per-server", this value is not
self-tuning.)
- New stats counters have been added to count
queries spilled due to these quotas.
See the ARM for details of these options. [RT #37125 ]
2015-07-08 22:53:39 -07:00
Tinderbox User
40f508f08b
regen master
2015-07-08 01:04:56 +00:00
Evan Hunt
70d987def5
[master] traffic size stats
...
4156. [func] Added statistics counters to track the sizes
of incoming queries and outgoing responses in
histogram buckets, as specified in RSSAC002.
[RT #39049 ]
2015-07-06 22:29:06 -07:00
Mukund Sivaraman
33ca26968b
Allow RPZ rewrite logging to be configured on a per-zone basis ( #39754 )
2015-07-06 08:57:51 +05:30
Tinderbox User
1879ff4932
regen master
2015-07-06 01:04:49 +00:00
Mark Andrews
ce67023ae3
4152. [func] Implement DNS COOKIE option. This replaces the
...
experimental SIT option of BIND 9.10. The following
named.conf directives are avaliable: send-cookie,
cookie-secret, cookie-algorithm and nocookie-udp-size.
The following dig options are available:
+[no]cookie[=value] and +[no]badcookie. [RT #39928 ]
2015-07-06 09:44:24 +10:00
Mark Andrews
aa3bffca69
whitespace
2015-07-04 12:50:29 +10:00
Tinderbox User
6cd01c0a96
regen master
2015-06-30 01:04:57 +00:00
Tinderbox User
0a4f0f6ab6
regen master
2015-06-26 01:05:04 +00:00
Witold Krecicki
f10a67dad2
Add statistics counters for nxdomain redirections. [RT #39790 ]
2015-06-25 09:21:50 +02:00
Tinderbox User
0da3028ccf
regen master
2015-06-20 01:05:58 +00:00
Witold Krecicki
6a3249533a
fix rpz-client-ip documentation [RT #39783 ]
2015-06-19 10:23:53 +02:00
Tinderbox User
b708ffc480
regen master
2015-06-19 01:05:11 +00:00
Mukund Sivaraman
f4d1c19691
Add comma
2015-06-17 12:23:44 +05:30
Mark Andrews
572e95f52a
add release notes for CVE-2015-4620
2015-06-17 11:19:53 +10:00
Tinderbox User
871ab4edd8
regen master
2015-06-06 01:06:45 +00:00
Mark Andrews
94f7158d44
update rpz doc as per rt39703
2015-06-05 11:13:02 +10:00
Tinderbox User
335c82aebd
regen master
2015-06-05 01:05:03 +00:00
Evan Hunt
8c9fba44a4
[master] further RPZ fixes
...
4131. [bug] Addressed further problems with reloading RPZ
zones. [RT #39649 ]
2015-06-03 18:18:55 -07:00
Tinderbox User
22be030b50
regen master
2015-05-29 01:04:57 +00:00
Tinderbox User
431e5c81db
update copyright notice / whitespace
2015-05-28 23:45:24 +00:00
Tinderbox User
481870b95f
regen master
2015-05-28 01:04:54 +00:00
Mark Andrews
598b502695
4127. [protocol] CDS and CDNSKEY need to be signed by the key signing
...
key as per RFC 7344, Section 4.1. [RT #37215 ]
2015-05-27 15:25:45 +10:00
Tinderbox User
661e7fbf77
regen master
2015-05-22 01:04:47 +00:00
Evan Hunt
f5c20627f4
[master] fix tags
2015-05-21 14:29:22 -07:00
Mukund Sivaraman
72a1c3f1a7
Update notes.xml and CHANGES for #39567
2015-05-21 21:45:47 +05:30
Mukund Sivaraman
705cea35a8
Fix RPZ radix tree search() for CLIENT-IP triggers ( #39481 )
2015-05-21 11:10:49 +05:30
Tinderbox User
b9a0676eec
regen master
2015-05-21 01:04:46 +00:00