Compare commits

...

7 Commits

Author SHA1 Message Date
Michał Kępień
5c1f9951b3 Update BIND version for release 2023-08-04 11:17:54 +02:00
Michał Kępień
0a13a5e373 Add a CHANGES marker 2023-08-04 11:17:54 +02:00
Michał Kępień
56aad07a4d Merge branch 'michal/prepare-documentation-for-bind-9.19.16' into 'v9.19.16-release'
Prepare documentation for BIND 9.19.16

See merge request isc-private/bind9!559
2023-08-04 11:17:54 +02:00
Michał Kępień
7d754c2113 Add release note for GL #4215 2023-08-04 11:17:54 +02:00
Michał Kępień
f6a8008e8f Reorder release notes 2023-08-04 11:17:54 +02:00
Michał Kępień
24b45a1e03 Tweak and reword release notes 2023-08-04 11:17:54 +02:00
Michał Kępień
89617cd3d6 Prepare release notes for BIND 9.19.16 2023-08-04 11:17:54 +02:00
5 changed files with 69 additions and 72 deletions

View File

@@ -1,3 +1,5 @@
--- 9.19.16 released ---
6221. [cleanup] Refactor dns_rdataset internals, move rdatasetheader
declarations out of rbtdb.c so they can be used by other
databases in the future, and split the zone and cache

View File

@@ -17,7 +17,7 @@
m4_define([bind_VERSION_MAJOR], 9)dnl
m4_define([bind_VERSION_MINOR], 19)dnl
m4_define([bind_VERSION_PATCH], 16)dnl
m4_define([bind_VERSION_EXTRA], -dev)dnl
m4_define([bind_VERSION_EXTRA], )dnl
m4_define([bind_DESCRIPTION], [(Development Release)])dnl
m4_define([bind_SRCID], [m4_esyscmd_s([git rev-parse --short HEAD | cut -b1-7])])dnl
m4_define([bind_PKG_VERSION], [[bind_VERSION_MAJOR.bind_VERSION_MINOR.bind_VERSION_PATCH]bind_VERSION_EXTRA])dnl

View File

@@ -38,7 +38,7 @@ information about each release, and source code.
.. include:: ../notes/notes-known-issues.rst
.. include:: ../notes/notes-current.rst
.. include:: ../notes/notes-9.19.16.rst
.. include:: ../notes/notes-9.19.15.rst
.. include:: ../notes/notes-9.19.14.rst
.. include:: ../notes/notes-9.19.13.rst

View File

@@ -0,0 +1,65 @@
.. Copyright (C) Internet Systems Consortium, Inc. ("ISC")
..
.. SPDX-License-Identifier: MPL-2.0
..
.. This Source Code Form is subject to the terms of the Mozilla Public
.. License, v. 2.0. If a copy of the MPL was not distributed with this
.. file, you can obtain one at https://mozilla.org/MPL/2.0/.
..
.. See the COPYRIGHT file distributed with this work for additional
.. information regarding copyright ownership.
Notes for BIND 9.19.16
----------------------
Removed Features
~~~~~~~~~~~~~~~~
- The ``auto-dnssec`` configuration statement has been removed. Please
use :any:`dnssec-policy` or manual signing instead. The following
statements have become obsolete: :any:`dnskey-sig-validity`,
:any:`dnssec-dnskey-kskonly`, :any:`dnssec-update-mode`,
:any:`sig-validity-interval`, and :any:`update-check-ksk`. :gl:`#3672`
Feature Changes
~~~~~~~~~~~~~~~
- BIND now returns BADCOOKIE for out-of-date or otherwise bad but
well-formed DNS server cookies. :gl:`#4194`
- When a primary server for a zone responds to an SOA query, but the
subsequent TCP connection required to transfer the zone is refused,
that server is marked as temporarily unreachable. This now also
happens if the TCP connection attempt times out, preventing too many
zones from queuing up on an unreachable server and allowing the
refresh process to move on to the next configured primary more
quickly. :gl:`#4215`
- The :any:`inline-signing` statement can now also be set inside
:any:`dnssec-policy`. The built-in policies ``default`` and
``insecure`` enable the use of :any:`inline-signing`. If
:any:`inline-signing` is set at the ``zone`` level, it overrides the
value set in :any:`dnssec-policy`. :gl:`#3677`
- To improve query-processing latency under load, the uninterrupted time
spent on resolving long chains of cached domain names has been
reduced. :gl:`#4185`
- The :any:`dialup` and :any:`heartbeat-interval` options have been
deprecated and will be removed in a future BIND 9 release. :gl:`#3700`
Bug Fixes
~~~~~~~~~
- Setting :any:`dnssec-policy` to ``insecure`` prevented zones
containing resource records with a TTL value larger than 86400 seconds
(1 day) from being loaded. This has been fixed by ignoring the TTL
values in the zone and using a value of 604800 seconds (1 week) as the
maximum zone TTL in key rollover timing calculations. :gl:`#4032`
Known Issues
~~~~~~~~~~~~
- There are no new known issues with this release. See :ref:`above
<relnotes_known_issues>` for a list of all known issues affecting this
BIND 9 branch.

View File

@@ -1,70 +0,0 @@
.. Copyright (C) Internet Systems Consortium, Inc. ("ISC")
..
.. SPDX-License-Identifier: MPL-2.0
..
.. This Source Code Form is subject to the terms of the Mozilla Public
.. License, v. 2.0. If a copy of the MPL was not distributed with this
.. file, you can obtain one at https://mozilla.org/MPL/2.0/.
..
.. See the COPYRIGHT file distributed with this work for additional
.. information regarding copyright ownership.
Notes for BIND 9.19.16
----------------------
Security Fixes
~~~~~~~~~~~~~~
- None.
New Features
~~~~~~~~~~~~
- None.
Removed Features
~~~~~~~~~~~~~~~~
- The 'auto-dnssec' configuration option has now been removed. Please
use :any:`dnssec-policy` or manual signing instead. The following options
have become obsolete: :any:`dnskey-sig-validity`,
:any:`dnssec-dnskey-kskonly`, :any:`dnssec-update-mode`,
:any:`sig-validity-interval`, and :any:`update-check-ksk`. :gl:`#3672`.
- The :any:`dialup` and :any:`heartbeat-interval` options have been
deprecated and will be removed in a future release. :gl:`#3700`
Feature Changes
~~~~~~~~~~~~~~~
- None.
- Return BADCOOKIE for out-of-date or otherwise bad, well formed
DNS SERVER COOKIES. Previously these were silently treated as
DNS CLIENT COOKIES. :gl:`#4194`
- The option :any:`inline-signing` can now also be set inside
:any:`dnssec-policy`. The built-in policies ``default`` and ``insecure``
enable the use of :any:`inline-signing`. If you set :any:`inline-signing`
at the ``zone`` level, it overrides the value used set in
:any:`dnssec-policy`. :gl:`#3677`.
Bug Fixes
~~~~~~~~~
- None.
- Query-processing latency under load has been improved by reducing the
uninterrupted time spent by resolving long cached chains of domain names.
:gl:`#4185`
- Ignore :any:`max-zone-ttl` for :any:`dnssec-policy` "insecure",
otherwise some zones will not be loaded if they use a TTL value larger
than 86400. :gl:`#4032`.
Known Issues
~~~~~~~~~~~~
- There are no new known issues with this release. See :ref:`above
<relnotes_known_issues>` for a list of all known issues affecting this
BIND 9 branch.