Evan Hunt and Ondřej Surý
f5362ed135
CHANGES and release note
2021-01-26 12:38:32 +01:00
Evan Hunt and Ondřej Surý
57aadd6cea
add syntax and setter/getter functions to configure max-ixfr-ratio
2021-01-26 12:38:32 +01:00
Ondřej Surý and Michał Kępień
88c098b467
Add CHANGES and release note for GL #2387
...
(cherry picked from commit b30aaa3748 )
2021-01-25 15:28:09 +01:00
Michał Kępień
0847e40635
Set up release notes for BIND 9.16.12
2021-01-21 09:33:16 +01:00
Michał Kępień
2e8eb485e9
Prepare release notes for BIND 9.16.11
2021-01-21 09:11:54 +01:00
Michał Kępień
19bd23df6a
Add release note for GL #2091
2021-01-21 09:11:54 +01:00
Michał Kępień
db3380e5ee
Reorder release notes
2021-01-21 09:11:54 +01:00
Michał Kępień
9396f3ef13
Tweak and reword release notes
2021-01-21 09:11:54 +01:00
Michał Kępień
d17c8903cf
Restore release note for GL #2245
2021-01-21 09:11:54 +01:00
Matthijs Mekking
87b44b59c8
Update documentation on -E option
...
The -E option does not default to pkcs11 if --with-pkcs11 is set,
but always needs to be set explicitly.
(cherry picked from commit 0536375d4cf61c9b570a32e808dde78a7ef859bf)
2021-01-19 09:06:01 +01:00
Matthijs Mekking
4d48df7f97
Update serve-stale config defaults
...
Change the serve-stale configuration defaults so that they match the
recommendations from RFC 8767.
(cherry picked from commit e15a433b23 )
2021-01-15 10:38:30 +01:00
Michał Kępień
86a326e761
Regenerate doc/misc/options{,.active}
...
Make the "docs" GitLab CI job pass again after backporting documentation
changes.
2021-01-12 16:00:38 +01:00
Suzanne Goldlust and Michał Kępień
016f603419
Add missing named.conf man page
...
(cherry picked from commit 4cd6be18d3 )
2021-01-12 15:45:09 +01:00
Suzanne Goldlust and Michał Kępień
14439e3c96
Final text edits to BIND 9 ARM in this round of updates
...
(cherry picked from commit 056f12eb34 )
2021-01-12 15:45:09 +01:00
Suzanne Goldlust and Michał Kępień
6bee0b80a1
Content and grammar edits to pkcs11.rst
...
(cherry picked from commit 28be579424 )
2021-01-12 15:42:31 +01:00
Ondřej Surý and Michał Kępień
d49a882292
Update the generated files after the source manpages update
...
(cherry picked from commit 9ab86d0da2 )
2021-01-12 15:40:00 +01:00
Suzanne Goldlust and Michał Kępień
4ba472ab21
Updates to .rst files to remove more references to "master" and "slave"
...
(cherry picked from commit 42386f3d9f )
2021-01-12 15:31:44 +01:00
Suzanne Goldlust and Michał Kępień
55636ab510
Various text edits and fixes to the documentation
...
(cherry picked from commit 5aa5ad5abc )
2021-01-12 15:26:59 +01:00
Evan Hunt and Michał Kępień
aa13408757
CHANGES, release note
...
(cherry picked from commit 565f99f9e5 )
2021-01-12 15:21:14 +01:00
Evan Hunt and Michał Kępień
1a32a4d001
prevent "primaries" lists from having duplicate names
...
it is now an error to have two primaries lists with the same
name. this is true regardless of whether the "primaries" or
"masters" keywords were used to define them.
(cherry picked from commit f619708bbf )
2021-01-12 15:21:14 +01:00
Evan Hunt and Michał Kępień
746aa2581c
add "primary-only" as a synonym for "master-only"
...
update the "notify" option to use RFC 8499 terminology as well.
(cherry picked from commit 424a3cf3cc )
2021-01-12 15:21:14 +01:00
Evan Hunt and Michał Kępień
04b9cdb53c
add "primaries" as a synonym for "masters" in named.conf
...
as "type primary" is preferred over "type master" now, it makes
sense to make "primaries" available as a synonym too.
added a correctness check to ensure "primaries" and "masters"
cannot both be used in the same zone.
(cherry picked from commit 16e14353b1 )
2021-01-12 15:21:14 +01:00
Matthijs Mekking
c4520620dc
Fix signatures-validity config option
...
KASP was using 'signatures-validity-dnskey' instead of
'signatures-validity'.
(cherry picked from commit ad63e9e4f8 )
2021-01-12 13:13:05 +01:00
Michal Nowak
883e1cb4df
Update copyright date in man pages
...
(cherry picked from commit 358c133ee2 )
2021-01-11 12:54:46 +01:00
Michał Kępień
22bec45f9c
Add the ISC DNSSEC Guide as a BIND 9 ARM appendix
...
Add the ISC DNSSEC Guide to the BIND 9 ARM in order to include the
former in every BIND release.
(cherry picked from commit f96e6a1e1d )
2021-01-08 13:53:52 +01:00
Mark Andrews
5874c04d13
Add release note
...
(cherry picked from commit 584e589d84 )
2021-01-06 16:33:32 +11:00
Mark Andrews
4222429b28
update for 2021
2021-01-04 15:14:44 +11:00
Matthijs Mekking
7fdd0f7be9
Add notes for [ #2341 ]
...
Mention the bugfix in the release.
(cherry picked from commit 08b6e8c2c9 )
2020-12-23 12:06:35 +01:00
Matthijs Mekking
decdd1d3e1
Add documentation and notes for [ #1750 ]
...
(cherry picked from commit 7825d8f916 )
2020-12-23 12:06:09 +01:00
Mark Andrews
b8c44c8e1f
Add CHANGES and release notes for [GL #2245 ]
...
(cherry picked from commit fc4af548e7 )
2020-12-23 09:26:50 +11:00
Michał Kępień
797974c7c3
Set up release notes for BIND 9.16.11
2020-12-16 22:21:19 +01:00
Michal Nowak
5f0e9c8645
Fix program name reference in dnssec-keymgr(8)
2020-12-14 13:17:27 +01:00
Michal Nowak
c77c96133d
Fix a reference to rndc(8) in named(8) manual page
...
(cherry picked from commit befcbcac28 )
2020-12-14 13:17:27 +01:00
Ondřej Surý and Ondřej Surý
66bb0a1e80
Add CHANGES and release notes for GL #2058
...
(cherry picked from commit ba887a688c )
2020-12-12 08:08:49 +01:00
Mark Andrews and Ondřej Surý
151500b522
Update dnssec-signzone -N soa-serial-format description
...
document the autoincrement when the serial would go backwards.
(cherry picked from commit eb1b29b19e )
2020-12-12 08:07:51 +01:00
Ondřej Surý
099fc1fdf8
Add CHANGES and release notes
2020-12-09 10:46:16 +01:00
Michał Kępień and Ondřej Surý
a01961260d
Prepare release notes for BIND 9.16.10
2020-12-09 10:46:16 +01:00
Michał Kępień and Ondřej Surý
2ef1784b85
Reorder release notes
2020-12-09 10:45:49 +01:00
Michał Kępień and Ondřej Surý
3f6f0b9f66
Tweak and reword release notes
2020-12-09 10:45:49 +01:00
Michał Kępień and Ondřej Surý
d902dc611f
Fix formatting of "dnssec-policy" documentation
2020-12-09 10:45:49 +01:00
Ondřej Surý and Ondřej Surý
9d35c9b96d
Add CHANGES and release not for GL #2250
...
(cherry picked from commit c7d81f12f8 )
2020-12-02 12:02:10 +01:00
Ondřej Surý and Ondřej Surý
5d34daaf78
Change the default value for nocookie-udp-size back to 4096
...
The DNS Flag Day 2020 reduced all the EDNS buffer sizes to 1232. In
this commit, we revert the default value for nocookie-udp-size back to
4096 because the option is too obscure and most people don't realize
that they also need to change this configuration option in addition to
max-udp-size.
(cherry picked from commit 79c196fc77 )
2020-12-02 12:01:50 +01:00
Mark Andrews
5c10b5a4e8
Adjust default value of "max-recursion-queries"
...
Since the queries sent towards root and TLD servers are now included in
the count (as a result of the fix for CVE-2020-8616),
"max-recursion-queries" has a higher chance of being exceeded by
non-attack queries. Increase its default value from 75 to 100.
(cherry picked from commit ab0bf49203 )
2020-12-02 00:53:49 +11:00
Mark Andrews
45719ff249
Add release note for [GL #2315 ]
...
(cherry picked from commit 356243aaec )
2020-12-01 23:29:43 +11:00
Mark Andrews
e98edb871d
Add release note for [GL #2275 ]
...
(cherry picked from commit d0dd71380b )
2020-11-27 08:44:00 +11:00
Matthijs Mekking
6db879160f
Detect NSEC3 salt collisions
...
When generating a new salt, compare it with the previous NSEC3
paremeters to ensure the new parameters are different from the
previous ones.
This moves the salt generation call from 'bin/named/*.s' to
'lib/dns/zone.c'. When setting new NSEC3 parameters, you can set a new
function parameter 'resalt' to enforce a new salt to be generated. A
new salt will also be generated if 'salt' is set to NULL.
Logging salt with zone context can now be done with 'dnssec_log',
removing the need for 'dns_nsec3_log_salt'.
(cherry picked from commit 6b5d7357df )
2020-11-26 14:15:05 +00:00
Matthijs Mekking
52d3bf5f31
Change nsec3param salt config to saltlen
...
Upon request from Mark, change the configuration of salt to salt
length.
Introduce a new function 'dns_zone_checknsec3aram' that can be used
upon reconfiguration to check if the existing NSEC3 parameters are
in sync with the configuration. If a salt is used that matches the
configured salt length, don't change the NSEC3 parameters.
(cherry picked from commit 6f97bb6b1f )
2020-11-26 14:15:04 +00:00
Matthijs Mekking
c993bc19a0
Add changes and notes for kasp NSEC3 support
...
This feature is news worthy.
(cherry picked from commit 9adad77ac3 )
2020-11-26 14:15:03 +00:00
Matthijs Mekking
5dfd3b2d7b
Add kasp nsec3param configuration
...
Add configuration and documentation on how to enable NSEC3 when
using dnssec-policy for signing your zones.
(cherry picked from commit f7ca96c805 )
2020-11-26 14:15:02 +00:00
Michał Kępień
ce18f66336
Set up release notes for BIND 9.16.10
2020-11-26 12:30:25 +01:00