Commit Graph
4919 Commits
Author SHA1 Message Date
Tinderbox User 5002bd49e8 regen master 2015-08-08 01:06:01 +00:00
Evan Hunt ce9f893e21 [master] address buffer accounting error
4168.	[security]	A buffer accounting error could trigger an
			assertion failure when parsing certain malformed
			DNSSEC keys. (CVE-2015-5722) [RT #40212]
2015-08-07 13:16:10 -07:00
Jeremy C. Reed 658b0ec21c fix spelling typo 2015-08-07 12:31:55 -04:00
Tinderbox User 964783e7e8 regen master 2015-08-07 01:06:05 +00:00
Evan Hunt d2f45d7ffd [master] revert incorrect 'correction' 2015-08-05 12:15:25 -07:00
Tinderbox User 233da44607 regen master 2015-08-01 01:05:43 +00:00
Evan Hunt 7ed374872f [master] corrected relnotes -- assertion in name.c not message.c 2015-07-31 12:03:29 -07:00
Mark Andrews 090ba6ff30 update 2015-07-26 06:45:53 +10:00
Tinderbox User 98e1584b29 update copyright notice / whitespace 2015-07-24 23:45:21 +00:00
Mark Andrews b2b408e4ed update 2015-07-24 23:39:58 +10:00
Mark Andrews 364162f4ae update 2015-07-24 15:05:20 +10:00
Mark Andrews 230f8da57c update 2015-07-24 14:58:21 +10:00
Tinderbox User 5d564da348 regen master 2015-07-24 01:04:59 +00:00
Mark Andrews 98869e60fa whitespace 2015-07-23 17:56:03 +10:00
Tinderbox User bd84b04e4f regen master 2015-07-21 01:05:05 +00:00
Evan Hunt 8a205b4534 [master] remove accidentally duplicated section on clients-per-query 2015-07-20 15:25:28 -07:00
Tinderbox User bd9a66d553 regen master 2015-07-15 01:04:58 +00:00
Mark Andrews 84114ec4c7 request-nsid -> request-sit 2015-07-15 08:38:08 +10:00
Mark Andrews c5eb9add52 add CVE-2015-5477 2015-07-15 07:51:06 +10:00
Tinderbox User b3338fc248 regen master 2015-07-11 01:05:48 +00:00
Tinderbox User c0cbdeedb5 regen master 2015-07-10 01:05:03 +00:00
Evan Hunt 1479200aa0 [master] DDoS mitigation features
3938.	[func]		Added quotas to be used in recursive resolvers
			that are under high query load for names in zones
			whose authoritative servers are nonresponsive or
			are experiencing a denial of service attack.

			- "fetches-per-server" limits the number of
			  simultaneous queries that can be sent to any
			  single authoritative server.  The configured
			  value is a starting point; it is automatically
			  adjusted downward if the server is partially or
			  completely non-responsive. The algorithm used to
			  adjust the quota can be configured via the
			  "fetch-quota-params" option.
			- "fetches-per-zone" limits the number of
			  simultaneous queries that can be sent for names
			  within a single domain.  (Note: Unlike
			  "fetches-per-server", this value is not
			  self-tuning.)
			- New stats counters have been added to count
			  queries spilled due to these quotas.

			See the ARM for details of these options. [RT #37125]
2015-07-08 22:53:39 -07:00
Tinderbox User 40f508f08b regen master 2015-07-08 01:04:56 +00:00
Evan Hunt 70d987def5 [master] traffic size stats
4156.	[func]		Added statistics counters to track the sizes
			of incoming queries and outgoing responses in
			histogram buckets, as specified in RSSAC002.
			[RT #39049]
2015-07-06 22:29:06 -07:00
Mukund Sivaraman 33ca26968b Allow RPZ rewrite logging to be configured on a per-zone basis (#39754) 2015-07-06 08:57:51 +05:30
Tinderbox User 1879ff4932 regen master 2015-07-06 01:04:49 +00:00
Mark Andrews ce67023ae3 4152. [func] Implement DNS COOKIE option. This replaces the
experimental SIT option of BIND 9.10.  The following
                        named.conf directives are avaliable: send-cookie,
                        cookie-secret, cookie-algorithm and nocookie-udp-size.
                        The following dig options are available:
                        +[no]cookie[=value] and +[no]badcookie.  [RT #39928]
2015-07-06 09:44:24 +10:00
Mark Andrews aa3bffca69 whitespace 2015-07-04 12:50:29 +10:00
Tinderbox User 6cd01c0a96 regen master 2015-06-30 01:04:57 +00:00
Tinderbox User 0a4f0f6ab6 regen master 2015-06-26 01:05:04 +00:00
Witold Krecicki f10a67dad2 Add statistics counters for nxdomain redirections. [RT #39790] 2015-06-25 09:21:50 +02:00
Tinderbox User 0da3028ccf regen master 2015-06-20 01:05:58 +00:00
Witold Krecicki 6a3249533a fix rpz-client-ip documentation [RT #39783] 2015-06-19 10:23:53 +02:00
Tinderbox User b708ffc480 regen master 2015-06-19 01:05:11 +00:00
Mukund Sivaraman f4d1c19691 Add comma 2015-06-17 12:23:44 +05:30
Mark Andrews 572e95f52a add release notes for CVE-2015-4620 2015-06-17 11:19:53 +10:00
Tinderbox User 871ab4edd8 regen master 2015-06-06 01:06:45 +00:00
Mark Andrews 94f7158d44 update rpz doc as per rt39703 2015-06-05 11:13:02 +10:00
Tinderbox User 335c82aebd regen master 2015-06-05 01:05:03 +00:00
Evan Hunt 8c9fba44a4 [master] further RPZ fixes
4131.	[bug]		Addressed further problems with reloading RPZ
			zones. [RT #39649]
2015-06-03 18:18:55 -07:00
Tinderbox User 22be030b50 regen master 2015-05-29 01:04:57 +00:00
Tinderbox User 431e5c81db update copyright notice / whitespace 2015-05-28 23:45:24 +00:00
Tinderbox User 481870b95f regen master 2015-05-28 01:04:54 +00:00
Mark Andrews 598b502695 4127. [protocol] CDS and CDNSKEY need to be signed by the key signing
key as per RFC 7344, Section 4.1. [RT #37215]
2015-05-27 15:25:45 +10:00
Tinderbox User 661e7fbf77 regen master 2015-05-22 01:04:47 +00:00
Evan Hunt f5c20627f4 [master] fix tags 2015-05-21 14:29:22 -07:00
Mukund Sivaraman 72a1c3f1a7 Update notes.xml and CHANGES for #39567 2015-05-21 21:45:47 +05:30
Mukund Sivaraman 705cea35a8 Fix RPZ radix tree search() for CLIENT-IP triggers (#39481) 2015-05-21 11:10:49 +05:30
Tinderbox User b9a0676eec regen master 2015-05-21 01:04:46 +00:00
Evan Hunt 19365b43e9 [master] ensure rpz summary consistence during AXFR updates
4121.	[bug]		When updating a response-policy zone via AXFR,
			summary data about other policy zones could fall
			out of sync. Ultimately this could trigger an
			assertion failure in rpz.c. [RT #39567]
2015-05-20 15:00:50 -07:00