Compare commits

...
2638 Commits
Author SHA1 Message Date
Tinderbox User 6af32d4dbd update SRCID 2012-07-24 07:15:46 +00:00
Evan Hunt 88c28974d4 update api 2012-07-23 23:35:00 -07:00
Tinderbox User c74e3b798e update SRCID 2012-07-24 03:16:19 +00:00
Mark Andrews 0c7c87d863 cast mode to unsigned int for fprintf 2012-07-24 13:03:05 +10:00
Mark Andrews f656c66f6b cleanup unused variables 2012-07-24 12:24:04 +10:00
Tinderbox User 8a9a87cc6f update SRCID 2012-07-24 00:15:52 +00:00
Tinderbox User 5598a19cfd update copyright notice 2012-07-23 23:45:26 +00:00
Tinderbox User 386c7fdcb7 newcopyrights 2012-07-23 23:30:05 +00:00
Tinderbox User 397a8687dc update SRCID 2012-07-23 21:15:43 +00:00
Evan Hunt a55edf69ec update 2012-07-23 13:36:20 -07:00
Tinderbox User 8c76e3e793 update SRCID 2012-07-23 20:15:41 +00:00
Evan Hunt f78b5ea128 fix change note 3348, bug not security 2012-07-23 13:00:27 -07:00
Evan Hunt 0b36ba206e prep 9.7.7b1 2012-07-23 12:56:58 -07:00
Tinderbox User bb3240f943 update SRCID 2012-07-23 07:15:56 +00:00
Mark Andrews b34a14edc6 3354. [func] Improve OpenSSL error logging. [RT #29932] 2012-07-23 15:40:53 +10:00
Tinderbox User 51519d9e40 update SRCID 2012-07-21 00:15:38 +00:00
Tinderbox User 15e9ffe1da newcopyrights 2012-07-20 23:30:04 +00:00
Tinderbox User 918f79d1df update SRCID 2012-07-20 08:15:41 +00:00
Mark Andrews 32d2ce0e3f windows fixes 2012-07-20 18:12:14 +10:00
Tinderbox User d349f2ace4 update SRCID 2012-07-20 05:17:04 +00:00
Tinderbox User e981a3f3aa regen v9_7 2012-07-20 04:40:19 +00:00
Tinderbox User 25e14da142 sync 2012-07-20 04:37:30 +00:00
Tinderbox User d1dfff5a10 update SRCID 2012-07-18 05:17:20 +00:00
Mark Andrews 571e22543a 3352. [bug] Ensure that learned server attributes timeout of the
adb cache. [RT #29856]
2012-07-18 14:19:13 +10:00
Tinderbox User ab92476e5b update SRCID 2012-07-18 00:15:51 +00:00
Mark Andrews 45a82933fa 3351. [bug] isc_mem_put and isc_mem_putanddetach didn't report
caller if either ISC_MEM_DEBUGSIZE or ISC_MEM_DEBUGCTX
                        memory debugging flags are set. [RT #30243]
2012-07-18 10:04:16 +10:00
Mark Andrews 71032bebe7 3350. [bug] Memory read overrun in isc___mem_reallocate if
ISC_MEM_DEBUGCTX memory debugging flag is set.
                        [RT #30240]
2012-07-18 09:53:50 +10:00
Tinderbox User 9caadde54a update SRCID 2012-07-09 19:15:46 +00:00
ckb 540a7fd3ae 3348. [security] prevent RRSIG data from being cached if a negative
record matching the covering type exists at a higher
			trust level. Such data already can't be retrieved from
			the cache since change 3218 -- this prevents it
			being inserted into the cache as well. [RT #26809]
2012-07-09 13:26:24 -05:00
Tinderbox User 019498b927 update SRCID 2012-07-07 00:15:46 +00:00
Tinderbox User 3f1219875c newcopyrights 2012-07-06 23:30:05 +00:00
Tinderbox User 2500fe2623 update SRCID 2012-07-06 19:15:34 +00:00
ckb 1ddbd81785 added cleanup of test files 2012-07-06 13:09:45 -05:00
Tinderbox User 9e08c6c01a update SRCID 2012-07-06 01:15:39 +00:00
Evan Hunt 364ecf0e5d warn when changing mode on .private files
3347.	[bug]		dnssec-settime: Issue a warning when writing a new
			private key file would cause a change in the
			permissions of the existing file. [RT #27724]
2012-07-05 18:05:12 -07:00
Tinderbox User 204ef887fc update SRCID 2012-07-02 17:15:42 +00:00
Evan Hunt 4e33277893 fix bad-cache assert
3346.	[security]	Bad-cache data could be used before it was
			initialized, causing an assert. [RT #30025]
2012-07-02 10:04:31 -07:00
Tinderbox User 7eb3f4ff63 update SRCID 2012-06-30 00:15:54 +00:00
Tinderbox User 45ce811e27 update copyright notice 2012-06-29 23:45:21 +00:00
Tinderbox User c651aebe6d newcopyrights 2012-06-29 23:30:06 +00:00
Tinderbox User 57cb8b4b1a update SRCID 2012-06-29 02:15:54 +00:00
Mark Andrews 32ff30bdf2 reverse bad copyright update 2012-06-29 11:44:33 +10:00
Mark Andrews 61523c6ccf lost line 2012-06-29 11:44:14 +10:00
Tinderbox User 8537f44d0b update copyright notice 2012-06-29 01:21:43 +00:00
Tinderbox User 198a3725ac update SRCID 2012-06-29 01:15:29 +00:00
Mark Andrews adf53c11c1 add support for python 2012-06-29 11:04:58 +10:00
Tinderbox User 657fd642e7 update SRCID 2012-06-27 00:15:36 +00:00
Tinderbox User 5940594202 update copyright notice 2012-06-26 23:45:21 +00:00
Mark Andrews ace3dd051b 3342. [bug] Change #3314 broke saving of stub zones to disk
resulting in excessive cpu usage in some cases.
                        [RT #29952]
2012-06-27 09:33:33 +10:00
Tinderbox User 3250763f2c update SRCID 2012-06-26 00:15:32 +00:00
Tinderbox User a4c1f732af update copyright notice 2012-06-25 23:45:23 +00:00
Tinderbox User 950750b351 newcopyrights 2012-06-25 23:30:03 +00:00
Tinderbox User fae3caaf6f update SRCID 2012-06-25 02:15:39 +00:00
Mark Andrews 16ab9b2264 silence compiler warning by using offsetof to get structure element offsets 2012-06-25 12:04:34 +10:00
Tinderbox User 2a093995dc update SRCID 2012-06-22 00:16:11 +00:00
Tinderbox User 7053dc8ca6 update copyright notice 2012-06-21 23:45:21 +00:00
Tinderbox User b788890749 update SRCID 2012-06-21 06:15:55 +00:00
Evan Hunt b4d196ed98 fix secondkey test, properly 2012-06-20 22:47:08 -07:00
Tinderbox User af574a9b39 update SRCID 2012-06-21 05:15:37 +00:00
Mark Andrews 209ddebc12 Merge branch 'v9_7' of repo.isc.org:/proj/git/prod/bind9 into v9_7 2012-06-21 14:31:40 +10:00
Mark Andrews 3d2bd4f6de remove rundundent call 'result = isc_parse_uint8(&ui, r.base, 10);' 2012-06-21 14:31:10 +10:00
Tinderbox User a799359c80 update SRCID 2012-06-20 22:16:18 +00:00
Evan Hunt ff45852f7f fixed second-key test to use correct rndc.conf 2012-06-20 15:09:43 -07:00
Tinderbox User e3645e4036 update SRCID 2012-06-15 00:16:12 +00:00
Tinderbox User d43de520e4 update copyright notice 2012-06-14 23:45:18 +00:00
Tinderbox User 76bd8ea3a8 update SRCID 2012-06-14 01:15:38 +00:00
Mark Andrews b4697b6ab1 update 2012-06-14 09:46:29 +10:00
Tinderbox User 54f7502add update SRCID 2012-06-13 07:15:36 +00:00
Mark Andrews 4cd6dee154 3337. [bug] Change #3294 broke support for the multiple keys
in controls. [RT #29694]
2012-06-13 16:55:37 +10:00
Tinderbox User 689f866a90 update SRCID 2012-06-09 00:15:34 +00:00
Tinderbox User b703dba08c update copyright notice 2012-06-08 23:45:21 +00:00
Tinderbox User 3fc4b6dd1b newcopyrights 2012-06-08 23:30:06 +00:00
Tinderbox User 876b708618 update SRCID 2012-06-08 05:17:00 +00:00
Evan Hunt ab58a069b3 nslookup exit with error if unsuccessful
3335.	[func]		nslookup: return a nonzero exit code when unable
			to get an answer. [RT #29492]
2012-06-07 22:09:24 -07:00
Tinderbox User 8824ef7cfa update SRCID 2012-06-08 04:16:04 +00:00
Mark Andrews ebaac2c8a9 add # 2012-06-08 13:58:26 +10:00
Tinderbox User bdd14b654e update SRCID 2012-06-07 03:16:22 +00:00
Mark Andrews f792aba03b 3332. [bug] Re-use cached DS rrsets if possible. [RT 29446] 2012-06-07 12:59:03 +10:00
Tinderbox User 5664b2197e update SRCID 2012-06-02 00:15:59 +00:00
Tinderbox User 77ab5a2f2f update copyright notice 2012-06-01 23:45:23 +00:00
Tinderbox User 49c32327eb newcopyrights 2012-06-01 23:42:48 +00:00
Mark Andrews b30a42ef87 add ./bin/tests/system/unknown/large.out 2012-06-02 09:39:35 +10:00
Tinderbox User cc0157667f update SRCID 2012-06-01 17:15:30 +00:00
Evan Hunt a93d8a7764 security fix
3331.	[security]	dns_rdataslab_fromrdataset could produce bad
			rdataslabs. [RT #29644]
2012-06-01 09:56:56 -07:00
Tinderbox User 7e9d377011 update SRCID 2012-06-01 01:15:51 +00:00
Tinderbox User 8eb453b890 regen v9_7 2012-06-01 01:09:55 +00:00
Tinderbox User 23024252f2 sync 2012-06-01 01:07:09 +00:00
Tinderbox User c51467315e update SRCID 2012-05-31 01:15:46 +00:00
Tinderbox User 37d9a05a87 regen v9_7 2012-05-31 01:10:44 +00:00
Tinderbox User 0879e883b3 update SRCID 2012-05-30 16:15:45 +00:00
Evan Hunt 7c884ecbde fixed ARM typo: s/replacable/replaceable/ 2012-05-30 08:17:01 -07:00
Tinderbox User d81a1b7915 update SRCID 2012-05-21 05:41:26 +00:00
Mark Andrews b629b52294 portability awk add space between -v and it's argument, if anything has changed add ./COPYRIGHT 2012-05-21 15:18:40 +10:00
Tinderbox User 5096ee1241 update SRCID 2012-05-21 01:15:49 +00:00
Mark Andrews 8d5ae2f842 awk and toupper is not portable, use sed instead 2012-05-21 10:18:16 +10:00
Tinderbox User 015ae1eb11 update SRCID 2012-05-21 00:15:41 +00:00
Tinderbox User bc0652a6cb update SRCID 2012-05-20 00:15:31 +00:00
Tinderbox User d4d7137ecb update SRCID 2012-05-19 00:15:52 +00:00
Tinderbox User b5e5077d49 update SRCID 2012-05-18 00:15:59 +00:00
Tinderbox User e632029acf update copyright notice 2012-05-17 23:45:23 +00:00
Tinderbox User 5520c45e9b newcopyrights 2012-05-17 23:30:16 +00:00
Evan Hunt fdfd260c4e fix check_data() usage
3328.   [bug]           Fixed inconsistent data checking in dst_parse.c.
                        [RT #29401]
2012-05-17 16:24:55 -07:00
Tinderbox User 6a23051978 update SRCID 2012-05-17 22:15:30 +00:00
Evan Hunt 0f86ac46ae some files were not cleaned up 2012-05-17 14:55:45 -07:00
Tinderbox User 5bd6be8ab7 update SRCID 2012-05-17 19:15:43 +00:00
Evan Hunt 78269d150c Handle RRSIG signer case consistently
3329.	[bug]	Handle RRSIG signer-name case consistently: We
		generate RRSIG records with the signer-name in
		lower case.  We accept them with any case, but if
		they fail to validate, we try again in lower case.
		[RT #27451]
2012-05-17 11:21:33 -07:00
Tinderbox User 48e12b656f update SRCID 2012-05-17 00:15:29 +00:00
Tinderbox User 607926d9bc update SRCID 2012-05-16 00:16:00 +00:00
Tinderbox User 09949f91a3 update SRCID 2012-05-15 00:15:51 +00:00
Tinderbox User 50b57d6ce7 update SRCID 2012-05-14 00:15:52 +00:00
Tinderbox User c9fc66db89 update SRCID 2012-05-13 00:15:30 +00:00
Tinderbox User f1e4967452 update SRCID 2012-05-12 00:15:46 +00:00
Tinderbox User 7ae60699fe update SRCID 2012-05-11 00:15:50 +00:00
Tinderbox User 3cb6fd179f update SRCID 2012-05-10 00:15:55 +00:00
Tinderbox User 353b500254 update SRCID 2012-05-09 23:15:37 +00:00
Mark Andrews 6451a2bd14 3318. [tuning] Reduce the amount of work performed while holding a
bucket lock when finshed with a fetch context.
                        [RT #29239]
2012-05-10 08:45:15 +10:00
Tinderbox User 9c103e049f update SRCID 2012-05-09 00:15:46 +00:00
Tinderbox User 9bea888217 update SRCID 2012-05-08 00:15:38 +00:00
Tinderbox User 53dda396ac update SRCID 2012-05-07 00:15:32 +00:00
Tinderbox User 3b9b39fa01 update SRCID 2012-05-06 00:15:36 +00:00
Tinderbox User cbbcb9014f update SRCID 2012-05-05 00:15:41 +00:00
Tinderbox User cd58d9797d update SRCID 2012-05-04 00:15:43 +00:00
Tinderbox User 7b54fc89fc update SRCID 2012-05-03 01:15:28 +00:00
Tinderbox User 0b4920b006 regen v9_7 2012-05-03 01:10:13 +00:00
Tinderbox User b1b5fb4fb1 sync 2012-05-03 01:07:28 +00:00
Tinderbox User 085e87e610 sync 2012-05-03 01:07:28 +00:00
Tinderbox User d02e34a045 update SRCID 2012-05-03 00:15:52 +00:00
Tinderbox User 004c0dd6b5 update SRCID 2012-05-02 00:15:40 +00:00
Tinderbox User 6e9e81453d update SRCID 2012-05-01 00:15:37 +00:00
Tinderbox User e957d3c530 update SRCID 2012-04-30 00:15:48 +00:00
Tinderbox User 257d5b037f update SRCID 2012-04-29 00:15:39 +00:00
Tinderbox User 87ce2b1060 update SRCID 2012-04-28 00:15:29 +00:00
Tinderbox User 04962afb5b update SRCID 2012-04-27 13:15:35 +00:00
Tinderbox User 7b0791f572 update SRCID 2012-04-27 08:15:47 +00:00
Mark Andrews 50a07c343c 9.7.6 2012-04-27 17:50:32 +10:00
Mark Andrews 5eecfba890 Merge branch 'v9_7' of repo.isc.org:/proj/git/prod/bind9 into v9_7 2012-04-27 17:32:29 +10:00
Mark Andrews f981c07ba7 9.7.6 2012-04-27 17:32:18 +10:00
Mark Andrews 8030fbee3f 3197. [bug] Don't try to log the filename and line number when
the config parser can't open a file. [RT #22263]
2012-04-27 17:30:51 +10:00
Tinderbox User eb808158ad update SRCID 2012-04-27 07:15:51 +00:00
Mark Andrews 4719e6364f 3232. [bug] Zero zone->curmaster before return in
dns_zone_setmasterswithkeys(). [RT #26732]
2012-04-27 17:01:49 +10:00
Mark Andrews 1c642c6c67 only report different text if not in EXCLUDED 2012-04-27 16:31:13 +10:00
Tinderbox User 8ca68065c4 update SRCID 2012-04-27 04:15:52 +00:00
Tinderbox User 9f3756cecb update copyright notice 2012-04-27 04:02:49 +00:00
Tinderbox User 40958c0b73 newcopyrights 2012-04-27 04:01:24 +00:00
Tinderbox User f4631471a2 update SRCID 2012-04-27 03:16:01 +00:00
Mark Andrews 8eb07cce40 check if the pdf version of the ARM needs to be committed 2012-04-27 12:29:01 +10:00
Tinderbox User 20e8335651 update SRCID 2012-04-27 01:15:37 +00:00
Mark Andrews 7307ca6554 sync with master 2012-04-27 10:47:42 +10:00
Tinderbox User 533616d860 update SRCID 2012-04-27 00:15:35 +00:00
Tinderbox User 42bbb73b03 newcopyrights 2012-04-26 23:30:11 +00:00
Tinderbox User d9a2c650d9 update SRCID 2012-04-26 04:15:41 +00:00
Mark Andrews 8e94cc841f 3314. [bug] The masters list could be updated while refesh_callback
and stub_callback were using it. [RT #26732]
2012-04-26 14:03:54 +10:00
Tinderbox User 547a22e6f8 update SRCID 2012-04-26 03:16:03 +00:00
Mark Andrews 5c7898c148 Merge branch 'v9_7' of repo.isc.org:/proj/git/prod/bind9 into v9_7 2012-04-26 12:39:41 +10:00
Mark Andrews c22f2e4093 3313. [protocol] Add TLSA record type. [RT #28989] 2012-04-26 12:39:14 +10:00
Tinderbox User 67c6ea848a update SRCID 2012-04-26 02:15:30 +00:00
Mark Andrews f11f15ecee 3312. [bug] named-checkconf didn't detect a bad dns64 clients acl.
[RT #27631]
2012-04-26 11:48:15 +10:00
Mark Andrews dc570048ad 3311. [bug] Abort the zone dump if zone->db is NULL in
zone.c:zone_gotwritehandle. [RT #29028]
2012-04-26 11:30:31 +10:00
Tinderbox User 589e86f99f update SRCID 2012-04-26 00:15:45 +00:00
Tinderbox User 69819d676a update SRCID 2012-04-25 00:15:41 +00:00
Evan Hunt 6c6d0c3ef7 increase table size for mutex profiling 2012-04-24 16:53:12 -07:00
Tinderbox User d8a403a8be update SRCID 2012-04-24 22:15:41 +00:00
Evan Hunt ed89ac0465 fctx_finddone: call fctx_destroy within the bucket lock 2012-04-24 15:03:11 -07:00
Tinderbox User f6911c31f9 update SRCID 2012-04-24 00:15:39 +00:00
Tinderbox User 948776dde0 newcopyrights 2012-04-23 23:30:11 +00:00
Tinderbox User 3a03cd5d4e update SRCID 2012-04-23 16:15:33 +00:00
Evan Hunt 0d0e1a21ec removed some files merged by mistake 2012-04-23 09:11:45 -07:00
Evan Hunt 09e21676fa gost not supported in 9.7, removing spurious test 2012-04-23 09:04:07 -07:00
Evan Hunt a8b49a7815 fix .gitignore files 2012-04-23 09:02:31 -07:00
Tinderbox User 867247f863 update SRCID 2012-04-23 00:15:44 +00:00
Tinderbox User df9c39975e update SRCID 2012-04-22 00:15:48 +00:00
Tinderbox User 1314ae3759 update SRCID 2012-04-21 00:15:41 +00:00
Tinderbox User d63246add2 update SRCID 2012-04-20 00:15:39 +00:00
Tinderbox User a4bd85a009 update SRCID 2012-04-19 14:16:49 +00:00
Scott Mann fd1fe00183 remove rfc5011.txt from contrib in tarball 2012-04-19 08:02:19 -06:00
Tinderbox User f64c09ba65 update SRCID 2012-04-19 00:15:46 +00:00
Tinderbox User 33c841f9fc update SRCID 2012-04-18 00:16:04 +00:00
Tinderbox User 7970ae49a6 update SRCID 2012-04-17 00:15:38 +00:00
Tinderbox User 0ff6113261 update SRCID 2012-04-16 00:15:48 +00:00
Tinderbox User cce57cf062 update SRCID 2012-04-15 00:15:53 +00:00
Tinderbox User 77142dfe71 update SRCID 2012-04-14 00:15:44 +00:00
Tinderbox User d0caa3dc46 update SRCID 2012-04-13 00:15:50 +00:00
Tinderbox User 71308f34bf update copyright notice 2012-04-12 23:45:21 +00:00
Tinderbox User 0798c610fa newcopyrights 2012-04-12 23:30:09 +00:00
Tinderbox User 2de11cf2a1 update SRCID 2012-04-12 23:15:43 +00:00
Mark Andrews c4cdad183b 3307. [bug] Add missing ISC_LANG_BEGINDECLS and ISC_LANG_ENDDECLS.
[RT #28956]
2012-04-13 08:41:58 +10:00
Tinderbox User 9d3faf1448 update SRCID 2012-04-12 10:15:28 +00:00
Mark Andrews 5ce3bf669f 3307. [bug] Add missing ISC_LANG_ENDDECLS to <dns/tsec.h>. [RT #28956] 2012-04-12 19:22:17 +10:00
Tinderbox User f2b12cb713 update SRCID 2012-04-12 00:15:49 +00:00
Tinderbox User 6b720b9fb1 update SRCID 2012-04-11 03:15:44 +00:00
Mark Andrews 872c6c261d rt28563 2012-04-11 12:35:07 +10:00
Tinderbox User 9b1685861b update SRCID 2012-04-11 02:15:14 +00:00
Mark Andrews 03c6cf9998 add the ability to override --remote 2012-04-11 11:32:36 +10:00
Tinderbox User 11354ff372 update SRCID 2012-04-11 01:15:40 +00:00
Mark Andrews 2d713a2aa0 3304. [bug] Use hmctx, not mctx when freeing rbtdb->heaps. [RT #28571] 2012-04-11 10:50:48 +10:00
Tinderbox User 15e252ef94 update SRCID 2012-04-11 00:15:33 +00:00
Tinderbox User c6fca95cd0 update SRCID 2012-04-10 07:16:56 +00:00
Mark Andrews e0ddc1b3e9 use --remote=cvs.isc.org:/proj/git/prod/bind9.git 2012-04-10 16:20:43 +10:00
Tinderbox User bd6f1082ec update SRCID 2012-04-10 00:16:12 +00:00
Tinderbox User b6da642566 update SRCID 2012-04-09 00:16:56 +00:00
Tinderbox User 5dafbe5013 update SRCID 2012-04-08 00:16:54 +00:00
Tinderbox User 101eba57a3 update SRCID 2012-04-07 00:16:51 +00:00
Tinderbox User 360510a440 update SRCID 2012-04-06 00:15:16 +00:00
Tinderbox User b9cb28effc update SRCID 2012-04-05 00:16:30 +00:00
Tinderbox User f0aead1abf update SRCID 2012-04-04 00:16:38 +00:00
Tinderbox User 034a483d14 update SRCID 2012-04-03 00:16:23 +00:00
Tinderbox User 24610e18df update SRCID 2012-04-02 00:16:59 +00:00
Tinderbox User 925f84ce92 update SRCID 2012-04-01 00:16:33 +00:00
Tinderbox User c43d080209 update SRCID 2012-03-31 00:16:55 +00:00
Tinderbox User ada21070d2 update SRCID 2012-03-30 01:16:56 +00:00
Mark Andrews a6be3a184f 3302. [bug] dns_dnssec_findmatchingkeys could fail to find
keys if the zone name contained character that
                        required special mappings. [RT #28600]
2012-03-30 12:08:41 +11:00
Tinderbox User 40652dd244 update SRCID 2012-03-30 00:16:32 +00:00
Tinderbox User 763362074e newcopyrights 2012-03-29 23:30:08 +00:00
Tinderbox User 27e1e9ff4b update SRCID 2012-03-29 00:16:55 +00:00
Mark Andrews 14bfdd5145 3301. [contrib] Update queryperf to build on darwin. Add -R flag
for non-recursive queries. [RT #28565]
2012-03-29 10:33:52 +11:00
Tinderbox User fcaa745a42 update SRCID 2012-03-28 23:15:54 +00:00
Mark Andrews 7e96cc4696 3300. [bug] Named could die if gssapi was enabled in named.conf
but was not compiled in. [RT #28338]
2012-03-29 09:55:42 +11:00
Tinderbox User ca7cb7b53f update SRCID 2012-03-28 00:16:26 +00:00
Mark Andrews 9e16bfe80e 3299. [bug] Make SDB handle errors from database drivers better.
[RT #28534]
2012-03-28 10:35:42 +11:00
Tinderbox User c8f644fe92 update SRCID 2012-03-27 00:15:53 +00:00
Tinderbox User 09a1be1f01 update SRCID 2012-03-26 00:16:25 +00:00
Tinderbox User 7a5f5ec2af update SRCID 2012-03-25 00:16:33 +00:00
Tinderbox User b9693520fe update SRCID 2012-03-24 00:16:54 +00:00
Tinderbox User 4b5175c834 update SRCID 2012-03-23 00:16:56 +00:00
Tinderbox User 3981c0af39 update SRCID 2012-03-22 19:16:39 +00:00
Evan Hunt 9bf892ead1 prep for 9.7.5 release 2012-03-22 12:14:04 -07:00
Tinderbox User 1cff9801d1 update SRCID 2012-03-22 18:15:59 +00:00
Tinderbox User 2c67878d34 Merge branch 'v9_7' of ssh://repo.isc.org/proj/git/prod/bind9 into v9_7 2012-03-22 17:39:59 +00:00
Tinderbox User 32934cecb0 regen PDF 2012-03-22 17:38:30 +00:00
Tinderbox User 75e452a4d0 update SRCID 2012-03-22 17:15:38 +00:00
Tinderbox User 45c11d8755 regen v9_7 2012-03-22 17:14:19 +00:00
Tinderbox User 4e41c936d3 update SRCID 2012-03-22 02:16:32 +00:00
Mark Andrews ea48b4f38b 3298. [bug] Named could dereference a NULL pointer in
zmgr_start_xfrin_ifquota if the zone was being removed.
                        [RT #28419]
2012-03-22 12:44:29 +11:00
Tinderbox User b6a74ff1b1 update SRCID 2012-03-22 00:16:47 +00:00
Tinderbox User 46c442835d update SRCID 2012-03-21 00:16:51 +00:00
Tinderbox User a8a972cc64 update SRCID 2012-03-20 00:16:52 +00:00
Tinderbox User 37235e8ffd update SRCID 2012-03-19 00:15:54 +00:00
Tinderbox User 64cf48df53 update SRCID 2012-03-18 00:16:55 +00:00
Tinderbox User d0cdabd43d update SRCID 2012-03-17 00:15:51 +00:00
Tinderbox User fd13b03113 update SRCID 2012-03-16 00:16:53 +00:00
Tinderbox User f11290cbd7 update SRCID 2012-03-15 01:16:43 +00:00
Mark Andrews 79a3ae39cc Merge branch 'v9_7' of repo.isc.org:/proj/git/prod/bind9 into v9_7 2012-03-15 12:12:59 +11:00
Mark Andrews cb02609903 3297. [bug] Named could die on a malformed master file. [RT #28467] 2012-03-15 12:12:38 +11:00
Tinderbox User 1e9273edba update SRCID 2012-03-15 00:15:55 +00:00
Tinderbox User d3f7f61cf9 update SRCID 2012-03-14 00:16:47 +00:00
Tinderbox User 86c4f0e78e update SRCID 2012-03-13 00:16:53 +00:00
Tinderbox User 9526a1e08d update copyright notice 2012-03-12 23:45:19 +00:00
Tinderbox User 631c3fc123 update SRCID 2012-03-12 01:16:30 +00:00
Tinderbox User 348a297124 regen v9_7 2012-03-12 01:10:00 +00:00
Mark Andrews 45ca673a76 copyright cleanup 2012-03-12 11:49:27 +11:00
Mark Andrews 3e3cd90fe3 copyright cleanup 2012-03-12 11:39:49 +11:00
Tinderbox User e256523bd6 update SRCID 2012-03-12 00:16:01 +00:00
Tinderbox User 5adce2b966 update SRCID 2012-03-11 00:16:22 +00:00
Tinderbox User cc31c8e443 update copyright notice 2012-03-10 23:45:19 +00:00
Tinderbox User 4f101fd179 newcopyrights 2012-03-10 23:30:10 +00:00
Tinderbox User a490cb1c51 update SRCID 2012-03-10 04:29:37 +00:00
Tinderbox User c2bb6225a9 update SRCID 2012-03-10 00:17:23 +00:00
Evan Hunt 6ec3dfd2af Merged 'rt28345': new git-based merge_copyrights 2012-03-09 15:59:49 -08:00
Mark Andrews f30154be76 remove lib/dns/tests/testdata/master/.gitignore 2012-03-10 10:49:39 +11:00
Tinderbox User c586565250 regen 2012-03-09 23:30:10 +00:00
Tinderbox User d5a9b459de regen 2012-03-09 23:30:10 +00:00
Tinderbox User 7eca2b230a update SRCID 2012-03-09 22:16:48 +00:00
Mark Andrews b62558ef4f empty directory 2012-03-10 08:48:56 +11:00
Tinderbox User f2ee0f85cb update SRCID 2012-03-09 21:16:38 +00:00
Tinderbox User 16be45a7f4 update SRCID 2012-03-09 21:01:16 +00:00
Evan Hunt 70f565b977 s/cvsignore/gitignore/ 2012-03-08 13:44:29 -08:00
Mark Andrews eba040d9c6 3295. [bug] Adjust isc_time_secondsastimet range check to be more
portable. [RT # 26542]
2012-03-08 15:35:39 +11:00
Mark Andrews 558d81f11d update/add .gitignore 2012-03-08 15:01:58 +11:00
Mark Andrews eaeaf4f46f 3294. [bug] isccc/cc.c:table_fromwire failed to free alist on
error. [RT #28265]
2012-03-08 14:44:47 +11:00
Evan Hunt 9eee9c6409 update copyrights 2012-03-07 15:41:02 -08:00
Evan Hunt 974dd2e224 Revert "add .gitattributes (turn on ident)"
This reverts commit 43d8ee6dc4.
2012-03-07 08:45:07 -08:00
Tinderbox User b1b38b22bc regen v9_7 2012-03-07 02:14:40 +00:00
Tinderbox User e7c7209af8 regen v9_7 2012-03-07 01:49:52 +00:00
Evan Hunt 43d8ee6dc4 add .gitattributes (turn on ident) 2012-03-06 17:29:43 -08:00
Evan Hunt 17befb55bd kit.sh now uses git 2012-03-04 10:51:26 -08:00
Evan Hunt 534a885953 added gitignore, removed cvsignore 2012-03-04 09:00:44 -08:00
Automatic Updater edf805b185 update 2012-03-01 00:15:41 +00:00
Automatic Updater 2b0333407e update copyright notice 2012-02-29 23:45:44 +00:00
Automatic Updater abbde5e2fe newcopyrights 2012-02-29 23:30:14 +00:00
Automatic Updater 23e61654ac update 2012-02-29 22:15:43 +00:00
Evan Hunt 36b36dc9e5 3291. [port] Fixed a build error on systems without ENOTSUP.
[RT #28200]
2012-02-29 21:27:21 +00:00
Automatic Updater 47588cbdf1 update 2012-02-29 00:15:45 +00:00
Automatic Updater 3f26cd737a update copyright notice 2012-02-28 23:45:38 +00:00
Automatic Updater b9b70d4a4d newcopyrights 2012-02-28 23:30:12 +00:00
Automatic Updater 327500822e update 2012-02-28 22:15:56 +00:00
Mark Andrews fbeaef0fb0 3290. [bug] <isc/hmacsha.h> was not being installed. [RT #28169] 2012-02-28 21:37:23 +00:00
Automatic Updater 858187ff3b update 2012-02-24 04:15:36 +00:00
Mark Andrews 75e772b59d dns_zone_synckeyzone 2012-02-24 03:58:45 +00:00
Automatic Updater 7b42babfea update 2012-02-23 21:15:52 +00:00
Evan Hunt 0b21f45431 corrected change #3277 to #3278 to match 9.9 and HEAD. 2012-02-23 20:53:09 +00:00
Automatic Updater 2ad64370fd update 2012-02-23 04:16:19 +00:00
Evan Hunt 2e9d59dd15 nicer release notes URL 2012-02-23 03:53:11 +00:00
Automatic Updater beb6f16a99 update 2012-02-23 00:15:39 +00:00
Automatic Updater 6e6f86392f update copyright notice 2012-02-22 23:45:53 +00:00
Automatic Updater 149bd39bf0 newcopyrights 2012-02-22 23:30:09 +00:00
Automatic Updater 95bef6b2cf update 2012-02-22 15:15:45 +00:00
Mark Andrews 6dd3684961 3287. [port] Update ans.pl to work with Net::DNS 0.68. [RT #28028] 2012-02-22 14:31:56 +00:00
Automatic Updater 1f85102b2a update 2012-02-22 01:15:33 +00:00
Evan Hunt d665ddbf70 add pointer to release notes (ugly URL; should be updated to a pretty one) 2012-02-22 00:55:07 +00:00
Evan Hunt 7dd768823b 3286. [bug] Managed key maintenance timer could fail to start
after 'rndc reconfig'. [RT #26786]
2012-02-22 00:31:58 +00:00
Automatic Updater 8795fecbbe update 2012-02-15 21:15:42 +00:00
Automatic Updater c072541ca0 update copyright notice 2012-02-15 21:14:53 +00:00
Automatic Updater a54a5fd60e newcopyrights 2012-02-15 21:13:38 +00:00
Mark Andrews 246a5586f1 3285. [bug] val-frdataset was incorrectly disassociated in
proveunsecure after calling startfinddlvsep.
                        [RT #27928]
2012-02-15 21:04:21 +00:00
Automatic Updater b1f59e4606 update 2012-02-15 13:15:50 +00:00
Mark Andrews 4a462bd067 2x POST(locktype); 2012-02-15 12:33:33 +00:00
Automatic Updater ec541505fa update 2012-02-15 11:15:31 +00:00
Mark Andrews d51b7acff3 9.7.5rc2 2012-02-15 10:24:15 +00:00
Automatic Updater be93322111 update 2012-02-15 02:15:41 +00:00
Mark Andrews 9811bf1c7d 3284. [bug] Address race conditions with the handling of
rbtnode.deadlink. [RT #27738]
2012-02-15 02:03:39 +00:00
Mark Andrews f5d894d721 Loop 'I:checking that large rdatasets loaded' in case the zone transfer has not yet completed 2012-02-15 01:23:57 +00:00
Automatic Updater 36bee53b91 update 2012-02-15 00:15:37 +00:00
Automatic Updater 68761692d6 update copyright notice 2012-02-14 23:46:06 +00:00
Automatic Updater bdc16544b1 newcopyrights 2012-02-14 23:30:08 +00:00
Automatic Updater 39d9d41200 update 2012-02-14 01:15:31 +00:00
Mark Andrews 968368a0b5 extend:
3282.   [bug]           Restrict the TTL of NS RRset to no more than that
                        of the old NS RRset when replacing it.
                        [RT #27792] [RT #27884]
2012-02-14 00:26:41 +00:00
Automatic Updater c58246a801 update 2012-02-14 00:15:44 +00:00
Mark Andrews 72d20be848 3283. [bug] Raw zones with with more than 512 records in a RRset
failed to load. [RT #27863]
2012-02-14 00:14:28 +00:00
Automatic Updater 1632c5931b update 2012-02-10 00:15:57 +00:00
Automatic Updater 31f782b605 update copyright notice 2012-02-09 23:45:56 +00:00
Automatic Updater 6af78d13a0 newcopyrights 2012-02-09 23:30:13 +00:00
Automatic Updater 59259b9f38 update 2012-02-09 22:16:02 +00:00
Mark Andrews 5b7b4fa54b move keygeneration out of the timing critical section 2012-02-09 21:56:42 +00:00
Automatic Updater 70e0923710 update 2012-02-09 21:15:41 +00:00
Mark Andrews fb843dc96a 3282. [bug] Restrict the TTL of NS RRset to no more than that
of the old NS RRset when replacing it. [RT #27792]
2012-02-09 21:02:47 +00:00
Automatic Updater 53ae43cea1 update 2012-02-08 00:15:39 +00:00
Automatic Updater b6768c488c update copyright notice 2012-02-07 23:46:13 +00:00
Automatic Updater 1c5c9f592a newcopyrights 2012-02-07 23:30:09 +00:00
Automatic Updater ba411bf0c9 update 2012-02-07 20:16:28 +00:00
Mark Andrews a0bde96546 3281. [bug] SOA refresh queries could be treated as cancelled
despite succeeding over the loopback interface.
                        [RT #27782]
2012-02-07 19:53:53 +00:00
Automatic Updater d84309ef74 update 2012-02-07 01:15:30 +00:00
Evan Hunt 64e10ec5f6 fixed a test error that caused autosign to fail on freebsd 2012-02-07 00:34:28 +00:00
Automatic Updater bf6690596b update 2012-02-07 00:20:56 +00:00
Automatic Updater 4583255b24 update copyright notice 2012-02-06 23:45:34 +00:00
Automatic Updater 2082485a73 newcopyrights 2012-02-06 23:30:12 +00:00
Mark Andrews 2beec845b4 verify server is answering before starting next server 2012-02-06 23:24:19 +00:00
Automatic Updater 269318dff9 update 2012-02-06 22:15:30 +00:00
Evan Hunt 9ab048a866 3277. [bug] Make sure automatic key maintenance is started
when "auto-dnssec maintain" is turned on during
			"rndc reconfig". [RT #26805]
2012-02-06 21:27:17 +00:00
Automatic Updater e2de4e760c update 2012-02-06 06:15:54 +00:00
Mark Andrews 6d0a5841ce 3276. [bug] win32: ns_os_openfile failed to return NULL on
safe_open failure. [RT #27696]
2012-02-06 05:18:15 +00:00
Automatic Updater 599775372a update 2012-02-04 00:15:40 +00:00
Automatic Updater 5de3c05b17 update copyright notice 2012-02-03 23:45:55 +00:00
Automatic Updater 4c887ecd0e newcopyrights 2012-02-03 23:30:20 +00:00
Automatic Updater a3dbde27f4 update 2012-02-03 05:17:12 +00:00
Mark Andrews ac2ac81731 I:waiting for nameserver to load, ok'd by Evan 2012-02-03 04:47:01 +00:00
Automatic Updater ce8cc06b6f update 2012-02-03 00:15:37 +00:00
Automatic Updater 321e7ff4b8 update copyright notice 2012-02-02 23:46:09 +00:00
Automatic Updater 41a085f283 newcopyrights 2012-02-02 23:30:10 +00:00
Automatic Updater 2c9698f360 update 2012-02-02 04:15:38 +00:00
Mark Andrews 1a3632db69 portable code, ok'd by Evan 2012-02-02 03:50:43 +00:00
Automatic Updater 5372026f4e update 2012-02-01 00:15:31 +00:00
Automatic Updater 0dad651086 update copyright notice 2012-01-31 23:46:16 +00:00
Automatic Updater 0398af52fa newcopyrights 2012-01-31 23:30:11 +00:00
Automatic Updater a01a37def3 update 2012-01-31 23:15:32 +00:00
Mark Andrews b8c4aca1b7 type mismatch 2012-01-31 22:40:37 +00:00
Mark Andrews 03a93e269f 3374. [bug] Log when a zone is not reusable. Only set loadtime
on successful loads.  [RT #27650]
2012-01-31 22:33:27 +00:00
Automatic Updater f8e2c32d29 update 2012-01-31 18:15:32 +00:00
Evan Hunt 1ec2d7e807 3273. [bug] AAAA responses could be returned in the additional
section even when filter-aaaa-on-v4 was in use.
                        [RT #27292]
2012-01-31 18:03:13 +00:00
Automatic Updater 65fb9b21f5 update 2012-01-31 04:15:32 +00:00
Mark Andrews f310b3dce5 3271. [port] darwin: mksymtbl is not always stable, loop several
times before giving up.  mksymtbl was using non
                        portable perl to covert 64 bit hex strings. [RT #27653]
2012-01-31 04:13:29 +00:00
Automatic Updater cb27330e5c update 2012-01-31 00:15:39 +00:00
Automatic Updater f49ff4a82c update copyright notice 2012-01-30 23:46:16 +00:00
Automatic Updater 7deeb1a9d2 newcopyrights 2012-01-30 23:30:13 +00:00
Automatic Updater ff15771dee update 2012-01-30 22:15:45 +00:00
Automatic Updater 665cfabe88 9.7.5 2012-01-30 22:07:34 +00:00
Automatic Updater 2171488708 update 2012-01-30 01:15:27 +00:00
Mark Andrews b8072cb4bc remove doc/draft, doc/rfc 2012-01-30 00:53:35 +00:00
Mark Andrews 7f4214fd1a make 'when' isc_stdtime_t in set_key_expiry_warning 2012-01-30 00:16:19 +00:00
Automatic Updater 42150579ae update 2012-01-28 00:15:38 +00:00
Automatic Updater 291f63ced1 update copyright notice 2012-01-27 23:46:06 +00:00
Automatic Updater e8c02bdafc newcopyrights 2012-01-27 23:30:26 +00:00
Automatic Updater 58a2d0aa43 update 2012-01-27 14:15:56 +00:00
Mark Andrews 08c44d5e4d in dns_name_fromstring check for bindable target with buffer 2012-01-27 13:37:26 +00:00
Automatic Updater b6f29c6d01 update 2012-01-27 08:15:27 +00:00
Mark Andrews 79650d87c6 9.7.5 2012-01-27 07:35:41 +00:00
Automatic Updater 8968554786 update 2012-01-27 07:16:21 +00:00
Mark Andrews 683a27fd16 9.7.5 2012-01-27 06:58:28 +00:00
Automatic Updater 9de47c3e20 update 2012-01-27 02:15:29 +00:00
Mark Andrews 0d26ffb398 back port dns_test_loaddb from 9.9.0 2012-01-27 02:10:20 +00:00
Mark Andrews 581cbb04c8 3268. [bug] Convert RRSIG expiry times to 64 timestamps to work
out the earliest expiry time. [RT #23311]
2012-01-27 01:48:14 +00:00
Mark Andrews 0b62ea07dd 3267. [bug] Memory allocation failures could be mis-reported as
unexpected error.  New ISC_R_UNSET result code.
                        [RT #27336]
2012-01-27 01:27:30 +00:00
Automatic Updater a10d82634c update 2012-01-27 01:15:35 +00:00
Mark Andrews 32ff3f4b78 3266. [bug] The maximum number of NSEC3 iterations for a
DNSKEY RRset was not being properly computed.
                        [RT #26543]
2012-01-27 01:08:22 +00:00
Automatic Updater 10de7852bd update 2012-01-24 00:15:28 +00:00
Automatic Updater 398aa77a34 update copyright notice 2012-01-23 23:45:55 +00:00
Automatic Updater 24d8da4f0f newcopyrights 2012-01-23 23:30:09 +00:00
Automatic Updater 2e28ce5da6 update 2012-01-23 12:15:57 +00:00
Mark Andrews 9df9ea7daa test for Net::DNS 2012-01-23 11:57:07 +00:00
Automatic Updater a955cdf5b5 update 2012-01-21 01:15:31 +00:00
Automatic Updater c9aab81abd sync 2012-01-21 01:07:39 +00:00
Automatic Updater 3ac569ccdb update 2012-01-20 02:15:35 +00:00
Mark Andrews 8e3192c38d remove more bashisms 2012-01-20 01:35:36 +00:00
Automatic Updater 77d4febaa9 update 2012-01-20 00:15:39 +00:00
Automatic Updater 41c2a7b1e7 newcopyrights 2012-01-19 23:30:08 +00:00
Automatic Updater 9788b328d0 update 2012-01-19 09:16:16 +00:00
Mark Andrews c23d30fe02 don't use bash syntax 2012-01-19 08:45:21 +00:00
Automatic Updater 33f72fe9f7 update 2012-01-18 00:15:34 +00:00
Automatic Updater 01e5800d6b newcopyrights 2012-01-17 23:30:08 +00:00
Automatic Updater 6365b4eaae update 2012-01-17 02:15:34 +00:00
Automatic Updater 61877a80eb regen v9_7 2012-01-17 01:39:33 +00:00
Automatic Updater f47f684fb1 update 2012-01-17 00:15:31 +00:00
Automatic Updater 3dfa0a6ee8 newcopyrights 2012-01-16 23:30:07 +00:00
Automatic Updater 9d3085883b update 2012-01-16 23:15:39 +00:00
Evan Hunt 2cd401dfb6 add section explaining how to build with SoftHSM 2012-01-16 22:50:34 +00:00
Automatic Updater c22f3a66c7 update 2012-01-16 19:15:33 +00:00
Evan Hunt c845e4a307 updated pkcs11 documentation 2012-01-16 19:08:30 +00:00
Evan Hunt 7ac2b23c54 - add openssl-1.0.0f-patch
- update openssl-0.9.8s-patch to francis's version
2012-01-16 19:02:19 +00:00
Automatic Updater a0853471cd update 2012-01-14 02:15:38 +00:00
Automatic Updater 78ffe3652b sync 2012-01-14 01:26:33 +00:00
Automatic Updater 970215fe11 update 2012-01-13 00:15:37 +00:00
Automatic Updater df786cc25c update copyright notice 2012-01-12 23:46:17 +00:00
Automatic Updater 4c1eb76521 newcopyrights 2012-01-12 23:30:09 +00:00
Automatic Updater 42fa16c074 update 2012-01-12 02:15:33 +00:00
Automatic Updater f076be3f00 regen v9_7 2012-01-12 01:39:35 +00:00
Automatic Updater 652b1e8834 update 2012-01-12 00:15:34 +00:00
Evan Hunt f8c31fd158 update doc to reflect rebased pkcs11 patch 2012-01-11 23:48:28 +00:00
Evan Hunt f6a185d135 rebase pkcs11 patch to openssl 0.9.8s 2012-01-11 23:46:43 +00:00
Automatic Updater 2bf0663118 update 2012-01-11 21:15:37 +00:00
Curtis Blackburn a777002cad added myself to the list of authors. 2012-01-11 20:19:07 +00:00
Automatic Updater bb148d6903 update 2012-01-11 00:15:28 +00:00
Automatic Updater 25ec2a4109 update copyright notice 2012-01-10 23:46:00 +00:00
Automatic Updater 081231b5eb newcopyrights 2012-01-10 23:30:07 +00:00
Automatic Updater ca65205b3f update 2012-01-10 01:15:38 +00:00
Scott Mann 682db59b71 added scott mann to bind authors 2012-01-10 00:27:47 +00:00
Automatic Updater 90ee0e12bd update 2012-01-06 00:15:42 +00:00
Automatic Updater 3a3671332d newcopyrights 2012-01-05 23:30:26 +00:00
Automatic Updater 0e1e93c385 update 2012-01-05 05:15:36 +00:00
Mark Andrews 8c1109d5bf rrset-order cyclic fix cleanupt 2012-01-05 04:56:12 +00:00
Automatic Updater d94602779b update 2012-01-05 00:15:36 +00:00
Automatic Updater cc8baeb284 update copyright notice 2012-01-04 23:45:53 +00:00
Automatic Updater c682238906 newcopyrights 2012-01-04 23:30:09 +00:00
Automatic Updater 7f06b20a83 update 2012-01-04 03:16:19 +00:00
Evan Hunt 52ca8590dc 3260. [bug] "rrset-order cyclic" could appear not to rotate
for some query patterns.  [RT #27170/27185]
2012-01-04 03:09:33 +00:00
Automatic Updater 04c34ec06b update 2011-12-26 08:16:15 +00:00
Mark Andrews 4bbc08f9a8 cleanup RELEASE-NOTES-BIND-9.7.4.* 2011-12-26 07:56:24 +00:00
Automatic Updater 93c19f7621 update 2011-12-24 00:15:36 +00:00
Automatic Updater 74a0f19645 update copyright notice 2011-12-23 23:46:23 +00:00
Automatic Updater 701606a1d0 update 2011-12-23 07:21:23 +00:00
Automatic Updater df9b583547 regenerate 2011-12-23 07:12:40 +00:00
Evan Hunt 8c7ba5a7f8 update for 9.7.5rc1 2011-12-23 07:11:33 +00:00
Automatic Updater 5ffb0573bd update 2011-12-23 03:16:22 +00:00
Evan Hunt fc91c2c300 prep for rc1 2011-12-23 02:30:02 +00:00
Automatic Updater 601cdb5f7d update 2011-12-23 02:15:44 +00:00
Automatic Updater f02f4b6a6f update 2011-12-23 01:40:18 +00:00
Automatic Updater 3984718a9e update 2011-12-23 01:15:42 +00:00
Mark Andrews edc78a0f1b --enable-fixed-rrset uses reversed order for cyclic 2011-12-23 01:07:21 +00:00
Mark Andrews b04446fa5f 3260. [bug] "rrset-order cyclic" could appears to not rotate
for some query patterns.  [RT #27170]
2011-12-23 00:41:43 +00:00
Automatic Updater 2342724b72 update 2011-12-23 00:15:32 +00:00
Mark Andrews f36d5f257f 3260. [bug] "rrset-order cyclic" could appear to not rotate
for some query patterns.  [RT #27170]
2011-12-22 23:57:43 +00:00
Automatic Updater ac255047aa update copyright notice 2011-12-22 23:45:33 +00:00
Automatic Updater eb2a2f2770 newcopyrights 2011-12-22 23:30:08 +00:00
Automatic Updater 6a2bfeed4a update 2011-12-22 18:15:29 +00:00
Evan Hunt e8d0069146 removed the 9.7.4 release notes 2011-12-22 17:37:16 +00:00
Evan Hunt 2d46c5fd9c 3259. [bug] named-compilezone: Suppress "dump zone to <file>"
message when writing to stdout. [RT #27109]
2011-12-22 17:28:32 +00:00
Automatic Updater 754ddedcfd update 2011-12-22 13:16:15 +00:00
Mark Andrews 8eb14452d6 3258. [test] Add "forcing full sign with unreadable keys" test.
[RT #27153]
2011-12-22 12:25:37 +00:00
Automatic Updater 836e227e8e update 2011-12-22 12:15:36 +00:00
Mark Andrews 17820c59a5 forcing full sign with unreadable keys 2011-12-22 12:08:49 +00:00
Automatic Updater 95b0663467 update 2011-12-22 09:16:07 +00:00
Mark Andrews 2b92da1288 3257. [bug] Do not generate a error message when calling fsync()
in a pipe or socket. [RT #27109]
2011-12-22 08:52:24 +00:00
Mark Andrews a937e32c70 3256. [bug] Disable empty zones for lwresd -C. [RT #27139] 2011-12-22 08:28:18 +00:00
Automatic Updater 0f5d05610e update 2011-12-22 08:16:13 +00:00
Mark Andrews 673cc90d4b 3254. [bug] Set isc_socket_ipv6only() on the IPv6 control channels.
[RT #22249]
2011-12-22 08:11:09 +00:00
Mark Andrews c6897c35e4 3253. [bug] Return DNS_R_SYNTAX when the input to a text field is
too long. [RT #26956]
2011-12-22 07:44:56 +00:00
Mark Andrews b5b8e9569a 3251. [bug] Enforce a upper bound (65535 bytes) on the amount of
memory dns_sdlz_putrr() can allocate per record to
                        prevent run away memory consumption on ISC_R_NOSPACE.
                        [RT #26956]
2011-12-22 07:17:37 +00:00
Automatic Updater c285df25e0 update 2011-12-22 03:16:17 +00:00
Mark Andrews ab507a4e06 +/- 500ms was too small a fudge factor (-582ms seen in testing), raise to +/- 1000ms 2011-12-22 02:21:34 +00:00
Automatic Updater fcb7624340 update 2011-12-21 00:16:14 +00:00
Automatic Updater 4c8de525fa update copyright notice 2011-12-20 23:45:39 +00:00
Automatic Updater 977b7ac162 newcopyrights 2011-12-20 23:30:09 +00:00
Automatic Updater b1bb8a9e51 update 2011-12-20 06:16:11 +00:00
Mark Andrews dd9e257800 configure strips out VPATH. Use ${srcdir} instead so 'make depend' works
in lib/export.
2011-12-20 05:26:37 +00:00
Automatic Updater 62f14d5826 update 2011-12-20 05:16:23 +00:00
Mark Andrews 76e0ae847a @srdir@ -> @srcdir@ 2011-12-20 05:06:16 +00:00
Automatic Updater 81269541d2 update 2011-12-20 01:15:57 +00:00
Mark Andrews 573eb75e0f update slabbed data layout description 2011-12-20 00:56:32 +00:00
Mark Andrews 229892a099 regen 2011-12-20 00:47:53 +00:00
Mark Andrews 962c241c43 3250. [func] 'configure --enable-developer'; turn on various
configure options, normally off by default, that
                        we want developers to build and test with. [RT #27103]
2011-12-20 00:41:32 +00:00
Mark Andrews 17271f13a6 add missing s 2011-12-20 00:30:16 +00:00
Automatic Updater 8fc65d1f05 update 2011-12-20 00:16:10 +00:00
Mark Andrews 3628f04492 3249. [bug] Update log message when saving slave zones files for
analysis after load failures. [RT #27087]

3248.   [bug]           Configure options --enable-fixed-rrset and
                        --enable-exportlib were incompatible with each
                        other. [RT #27087]

3247.   [bug]           'raw' format zones failed to preserve load order
                        breaking 'fixed' sort order. [RT #27087]
2011-12-20 00:14:16 +00:00
Automatic Updater 51ae34b0c8 update 2011-12-19 23:16:03 +00:00
Mark Andrews 89af8f9be3 set status to 1 on R:FAIL 2011-12-19 23:12:35 +00:00
Automatic Updater 3a0ff7fca7 update 2011-12-17 00:16:00 +00:00
Automatic Updater 0d374582db newcopyrights 2011-12-16 23:30:31 +00:00
Automatic Updater 6453c5315b update 2011-12-16 00:15:39 +00:00
Mark Andrews 2592dc5de7 regen 2011-12-16 00:12:56 +00:00
Mark Andrews 66b64c3fce 3243. [port] netbsd,bsdi: the thread defaults were not being
properly set.
2011-12-16 00:07:00 +00:00
Automatic Updater 1b5d6c5450 update 2011-12-12 12:15:53 +00:00
Mark Andrews e8da1d8078 join line for old awk 2011-12-12 12:09:23 +00:00
Automatic Updater 5231c6a26c update 2011-12-12 07:16:20 +00:00
Mark Andrews c4d6a78f38 chech that the final time is within 10 seconds but no greater than the expected interval 2011-12-12 06:49:10 +00:00
Automatic Updater ea660b0770 update 2011-12-07 23:15:37 +00:00
Mark Andrews 4afeb31498 3241. [bug] Address race conditions in the resolver code.
[RT #26889]
2011-12-07 23:11:34 +00:00
Mark Andrews cc4569d518 3240. [bug] DNSKEY state change events could be missed. [RT #26874] 2011-12-07 22:50:31 +00:00
Mark Andrews 8ab3b4e7c7 3239. [bug] dns_dnssec_findmatchingkeys needs to use a consistent
timestamp. [RT #26883]
2011-12-07 22:39:48 +00:00
Mark Andrews 32f6a22e89 3238. [bug] keyrdata was not being reinitialized in
lib/dns/rbtdb.c:iszonesecure. [RT#26913]
2011-12-07 22:25:57 +00:00
Automatic Updater 257b8a080c update 2011-12-07 18:15:26 +00:00
Evan Hunt 531e809a1d 3237. [bug] dig -6 didn't work with +trace. [RT #26906] 2011-12-07 17:24:25 +00:00
Automatic Updater b192d13a5a update 2011-12-05 18:15:32 +00:00
Evan Hunt db2cb7eaae missed a line 2011-12-05 17:27:27 +00:00
Evan Hunt 6a8119e46d missed a file 2011-12-05 17:24:16 +00:00
Automatic Updater 6751efae8d update 2011-12-05 17:15:58 +00:00
Evan Hunt 40f6436384 Back out change #3182 and respin. 2011-12-05 16:57:27 +00:00
Automatic Updater f06f816ec9 update 2011-12-03 00:15:48 +00:00
Automatic Updater f33395b687 update copyright notice 2011-12-02 23:45:51 +00:00
Automatic Updater b5ff9e5b3d newcopyrights 2011-12-02 23:30:10 +00:00
Automatic Updater 581d77363d update 2011-12-02 08:16:14 +00:00
Mark Andrews 3335f10b81 errno2result now reports caller when unable to convert errno 2011-12-02 07:16:30 +00:00
Automatic Updater 929e50bfe0 update 2011-12-02 07:15:37 +00:00
Mark Andrews 93b52e00f9 3234. [bug] 'make depend' produced invalid makefiles. [RT #26830] 2011-12-02 07:06:31 +00:00
Automatic Updater a790c8d8a6 update 2011-12-02 00:15:46 +00:00
Automatic Updater 39b1eee8cf update copyright notice 2011-12-01 23:46:06 +00:00
Automatic Updater dedff3528e newcopyrights 2011-12-01 23:30:11 +00:00
Automatic Updater fe5f32b812 update 2011-12-01 02:15:45 +00:00
Mark Andrews 67c71db8b3 silence Division by zero warning 2011-12-01 01:31:35 +00:00
Automatic Updater db9126fe69 update 2011-12-01 01:15:31 +00:00
Mark Andrews 2871055d09 3231. [bug] named could fail to send a uncompressable zone.
[RT #26796]

3230.   [bug]           'dig axfr' failed to properly handle a multi-message
                        axfr with a serial of 0. [RT #26796]
2011-12-01 01:03:08 +00:00
Scott Mann 61c8049230 Fix problem identified by CLANG: assign local var back to struct. 2011-12-01 00:20:32 +00:00
Automatic Updater 0d7aa181e1 update 2011-12-01 00:15:36 +00:00
Automatic Updater 1a02cf771e update copyright notice 2011-11-30 23:45:37 +00:00
Automatic Updater 71ad25ba17 newcopyrights 2011-11-30 23:30:08 +00:00
Automatic Updater fd1a0b559b update 2011-11-30 06:15:28 +00:00
Mark Andrews dd13cbb093 #include <isc/print.h> 2011-11-30 06:11:20 +00:00
Evan Hunt c89e5fd4c8 add print.h 2011-11-30 06:10:23 +00:00
Mark Andrews 9530453877 move declaration to start of block 2011-11-30 06:07:52 +00:00
Automatic Updater 08620bad8a update 2011-11-30 05:16:21 +00:00
Evan Hunt 039f179f7e 3228. [tuning] Dynamically grow symbol table to improve zone
loading performance. [RT #26523]
2011-11-30 04:26:23 +00:00
Automatic Updater 6f3d8d9dbb update 2011-11-30 02:15:30 +00:00
Mark Andrews dda6a063a2 3227. [bug] Interim fix to make WKS's use of getprotobyname()
and getservbyname() self thread safe. [RT #26232]
2011-11-30 01:22:37 +00:00
Automatic Updater 95a62b6747 update 2011-11-30 01:15:33 +00:00
Mark Andrews 3edc4dba34 3226. [bug] Address minor resource leakages. [RT #26624] 2011-11-30 00:53:35 +00:00
Automatic Updater 7a14a22434 update 2011-11-27 12:15:35 +00:00
Mark Andrews 49f4392f32 make grep more precise 2011-11-27 12:10:10 +00:00
Automatic Updater 4ed74e6600 update 2011-11-24 02:15:32 +00:00
Evan Hunt 8feff2ab3c respin 9.7.5b1 2011-11-24 02:11:27 +00:00
Automatic Updater 134088b1e9 update 2011-11-23 23:15:32 +00:00
Evan Hunt ad4090df9e 3221. [bug] Fixed a potential coredump on shutdown due to
referencing fetch context after it's been freed.
			[RT #26720]
2011-11-23 22:52:46 +00:00
Automatic Updater d5a4201f36 update 2011-11-22 04:15:28 +00:00
Mark Andrews 61201a7a3e 9.7.5b1 2011-11-22 04:06:08 +00:00
Automatic Updater a371376de9 update 2011-11-16 10:15:33 +00:00
Mark Andrews a22db1268c 3218. [security] Cache lookup could return RRSIG data associated with
nonexistent records, leading to an assertion
                        failure. [RT #26590]
2011-11-16 09:53:21 +00:00
Automatic Updater a6aff319f0 update 2011-11-15 22:15:36 +00:00
Evan Hunt fcd518304a 3216. [bug] resolver.c:validated() was not thread-safe. [RT #26478] 2011-11-15 21:46:07 +00:00
Evan Hunt cf8f0db28b file symtab_test.c was added on branch v9_7 on 2011-11-30 04:26:22 +0000 2011-11-15 21:03:11 +00:00
Automatic Updater cb3ccbe4da update 2011-11-10 03:16:12 +00:00
Evan Hunt 6fcfecea15 update libisccfg.def 2011-11-10 02:48:20 +00:00
Automatic Updater 74cfe49e38 regenerate v9_7 2011-11-10 02:20:53 +00:00
Automatic Updater 29a9728c08 update 2011-11-10 02:15:46 +00:00
Evan Hunt a416e52fb7 update api for 9.7.5b1 2011-11-10 01:55:40 +00:00
Automatic Updater f0f91dfa7f update 2011-11-10 00:15:44 +00:00
Automatic Updater ef1cc6ebd7 update for 9.7.5b1 2011-11-09 23:46:46 +00:00
Evan Hunt ce4ea46dd3 Prepare 9.7.5b1 release. 2011-11-09 23:39:07 +00:00
Automatic Updater 546c311c66 update 2011-11-09 06:16:07 +00:00
Evan Hunt 069fa1eb10 3213. [doc] Clarify ixfr-from-differences behavior. [RT #25188] 2011-11-09 05:54:17 +00:00
Automatic Updater 465e37a68c update 2011-11-08 21:15:38 +00:00
Mark Andrews 71bebb88b6 3212. [bug] rbtdb.c: failed to remove a node from the deadnodes
list prior to adding a reference to it leading a
                        possible assertion failure. [RT #23219]
2011-11-08 21:09:09 +00:00
Automatic Updater b4daf94423 update 2011-11-08 02:15:30 +00:00
Automatic Updater ea582b291f regen v9_7 2011-11-08 01:39:35 +00:00
Automatic Updater e02ba543db update 2011-11-08 00:15:36 +00:00
Automatic Updater bd9aa58852 update copyright notice 2011-11-07 23:46:02 +00:00
Automatic Updater 3992adce1d newcopyrights 2011-11-07 23:30:10 +00:00
Automatic Updater a4a309f65b update 2011-11-07 02:15:39 +00:00
Automatic Updater 83cac3fd35 regen v9_7 2011-11-07 01:39:40 +00:00
Mark Andrews ca7b9f18da 3209. [func] Add "dnssec-lookaside 'no'". [RT #24858] 2011-11-07 01:20:51 +00:00
Automatic Updater 1692740692 update 2011-11-07 00:15:42 +00:00
Automatic Updater 5e62f59109 update copyright notice 2011-11-06 23:45:51 +00:00
Automatic Updater 67d3024936 newcopyrights 2011-11-06 23:30:12 +00:00
Mark Andrews 29cadafdb8 3208. [bug] 'dig -y' handle unknown tsig alorithm better.
[RT #25522]
2011-11-06 23:25:29 +00:00
Automatic Updater 4a8ee6dc04 update 2011-11-05 06:15:49 +00:00
Automatic Updater 1c6a9c6bd8 regen 2011-11-05 05:18:46 +00:00
Evan Hunt 9253108001 3207. [contrib] Fixed build error in Berkeley DB DLZ module. [RT #26444] 2011-11-05 05:15:12 +00:00
Automatic Updater 70c9938c8b update 2011-11-05 01:15:32 +00:00
Evan Hunt ce9a9ac5d5 3206. [cleanup] Add ISC information to log at start time. [RT #25484] 2011-11-05 00:46:11 +00:00
Automatic Updater 8a6f58e42b update 2011-11-05 00:15:34 +00:00
Automatic Updater 4ee39d50ef newcopyrights 2011-11-04 23:30:51 +00:00
Automatic Updater ef96028e7c update 2011-11-04 23:15:32 +00:00
Evan Hunt 9781ffef82 added documentation of change categories 2011-11-04 22:28:18 +00:00
Automatic Updater c580f18a41 update 2011-11-04 17:15:30 +00:00
Evan Hunt fd20faa237 fixed RT reference for change #3174 2011-11-04 17:13:39 +00:00
Automatic Updater 52ca456df6 update 2011-11-04 09:15:57 +00:00
Mark Andrews 441bd60bb8 delay activation 10 seconds to allow slower systems to succeed 2011-11-04 09:04:38 +00:00
Automatic Updater 4ca55f0eb6 update 2011-11-04 08:16:04 +00:00
Mark Andrews 6e91d9a41b sync with HEAD 2011-11-04 07:33:47 +00:00
Automatic Updater b4f150ede2 update 2011-11-04 06:15:40 +00:00
Evan Hunt b0843937e8 typo 2011-11-04 05:55:11 +00:00
Evan Hunt 65fdd59d4c 3204. [bug] When a master server that has been marked as
unreachable but sends a NOTIFY, mark it reachable
			again. [RT #25960]
2011-11-04 05:52:21 +00:00
Evan Hunt 82b95385ef 3203. [bug] Increase log level to 'info' for validation failures
from expired or not-yet-valid RRSIGs. [RT #21796]
2011-11-04 05:34:16 +00:00
Automatic Updater 4503f9e859 update 2011-11-04 02:16:09 +00:00
Automatic Updater 4c63c71cbb regen v9_7 2011-11-04 01:37:29 +00:00
Automatic Updater a99c7533ee update 2011-11-04 00:16:00 +00:00
Automatic Updater 8558d6300e update copyright notice 2011-11-03 23:45:34 +00:00
Automatic Updater b29b68213c newcopyrights 2011-11-03 23:30:09 +00:00
Automatic Updater c84b3cfb02 update 2011-11-03 22:15:57 +00:00
Evan Hunt dc102ed192 3200. [doc] Some rndc functions were undocumented or were
missing from 'rndc -h' output. [RT #25555]
2011-11-03 22:06:43 +00:00
Automatic Updater b7955c9c28 update 2011-11-03 21:15:39 +00:00
Evan Hunt afc268ebb8 3198. [doc] Clarified that dnssec-settime can alter keyfile
permissions. [RT #24866]
2011-11-03 20:21:24 +00:00
Automatic Updater 3f23634f0e update 2011-11-03 05:16:09 +00:00
Evan Hunt e2603103fe remove 1/8 and 2/8 from bogusnets example 2011-11-03 04:55:16 +00:00
Evan Hunt 7613e9e7cb 3196. [bug] nsupdate: return nonzero exit code when target zone
doesn't exist. [RT #25783]
2011-11-03 04:30:37 +00:00
Automatic Updater cf781cc854 update 2011-11-03 04:15:32 +00:00
Evan Hunt 9a36ef794e 3195. [cleanup] Silence "file not found" warnings when loading
managed-keys zone. [RT #26340]
2011-11-03 03:27:20 +00:00
Automatic Updater b51999faf8 update 2011-11-03 03:16:07 +00:00
Evan Hunt fd5449f4f8 3194. [doc] Updated RFC references in the 'empty-zones-enable'
documentation. [RT #25203]
2011-11-03 03:10:05 +00:00
Evan Hunt 691d1d2c86 3193. [cleanup] Changed MAXZONEKEYS to DNS_MAXZONEKEYS, moved to
dnssec.h. [RT #26415]
2011-11-03 02:56:18 +00:00
Automatic Updater a8533305a2 update 2011-11-03 00:15:29 +00:00
Mark Andrews 8c6d81740b 3192. [bug] A query structure could be used after being freed.
[RT #22208]
2011-11-02 23:46:17 +00:00
Automatic Updater 11a3eab225 update copyright notice 2011-11-02 23:45:34 +00:00
Automatic Updater 6595f581bf newcopyrights 2011-11-02 23:30:19 +00:00
Automatic Updater a2b4901925 update 2011-11-02 20:15:48 +00:00
Evan Hunt e8cc0e173c edited a comment for clarity. 2011-11-02 19:40:44 +00:00
Automatic Updater 82b4a7b73e update 2011-11-02 15:16:04 +00:00
Mark Andrews 32bd2f5d3c improve error diagnostics 2011-11-02 14:41:33 +00:00
Automatic Updater 05e2dd6a15 update 2011-11-02 09:16:06 +00:00
Mark Andrews 1a3fb98614 loop waiting for stub zone to transfer 2011-11-02 08:20:21 +00:00
Automatic Updater 37e0b1bcbd update 2011-11-02 06:15:33 +00:00
Evan Hunt 918555fc4a fix usage message 2011-11-02 06:00:15 +00:00
Automatic Updater 81a53300ee update 2011-11-02 03:16:10 +00:00
Evan Hunt f240cd7599 grammar fix 2011-11-02 02:22:47 +00:00
Automatic Updater 783468308e update 2011-11-02 01:15:26 +00:00
Mark Andrews 3ec4216b58 3191. [bug] Print NULL records using unknown format. [RT #26392] 2011-11-02 01:11:58 +00:00
Automatic Updater a55a9cf494 update 2011-11-02 00:15:38 +00:00
Automatic Updater c282d8a75b update copyright notice 2011-11-01 23:46:12 +00:00
Automatic Updater acbd22483c newcopyrights 2011-11-01 23:30:12 +00:00
Automatic Updater d148bf327f update 2011-11-01 22:15:39 +00:00
Mark Andrews d0cf4c7802 3190. [bug] Underflow in error handling in isc_mutexblock_init.
[RT #26397]
2011-11-01 22:04:18 +00:00
Automatic Updater a2b9c707aa update 2011-11-01 19:15:34 +00:00
Evan Hunt d3c395f4db 3189. [test] Added a summary report after system tests. [RT #25517] 2011-11-01 18:34:11 +00:00
Automatic Updater 70a9f173bb update 2011-11-01 04:15:26 +00:00
Evan Hunt 23dd98b032 3188. [bug] zone.c:zone_refreshkeys() could fail to detach
references correctly when errors occurred, causing
			a hang on shutdown. [RT #26372]
2011-11-01 03:59:35 +00:00
Automatic Updater 31ef8a7413 update 2011-11-01 00:15:38 +00:00
Automatic Updater f0cc58ba10 update copyright notice 2011-10-31 23:46:12 +00:00
Automatic Updater 612e5be76a newcopyrights 2011-10-31 23:30:09 +00:00
Automatic Updater b33c04170d update 2011-10-31 00:16:01 +00:00
Mark Andrews c94694bfd7 3187. [port] win32: support for Visual Studio 2008. [RT #26356] 2011-10-30 23:43:48 +00:00
Automatic Updater 7a6f43b11e update 2011-10-29 23:15:42 +00:00
Mark Andrews fbdb4098b0 remove unused parameter from next_origin 2011-10-29 22:31:29 +00:00
Automatic Updater 4739c6bad9 update 2011-10-28 12:15:34 +00:00
Automatic Updater eb788c2447 update copyright notice 2011-10-28 12:07:18 +00:00
Automatic Updater 572d70e02e newcopyrights 2011-10-28 12:06:30 +00:00
Automatic Updater 65fec4fa4b update 2011-10-28 05:16:03 +00:00
Mark Andrews 687bb8ca0e style, remove redudant assignment 2011-10-28 05:00:03 +00:00
Automatic Updater 5781c9f608 update 2011-10-28 04:15:26 +00:00
Mark Andrews a4eea6b1ca exit 255 for SKIPPED 2011-10-28 03:16:07 +00:00
Automatic Updater e86f92fc9f update 2011-10-28 03:15:59 +00:00
Scott Mann 38c6b289f9 add test for recent Net::DNS module. 2011-10-28 02:20:36 +00:00
Automatic Updater 11ab9abc93 update 2011-10-28 00:15:56 +00:00
Automatic Updater 871e091d33 update copyright notice 2011-10-27 23:45:36 +00:00
Automatic Updater d8674d3810 newcopyrights 2011-10-27 23:30:08 +00:00
Automatic Updater 9ba8f65e98 update 2011-10-27 22:25:48 +00:00
Mark Andrews 5717db8dad move declarations to start of block 2011-10-27 22:21:36 +00:00
Automatic Updater d38338fd85 update 2011-10-27 21:16:00 +00:00
Scott Mann 07a0a4dedb fix edns0 retry issues (rt #23393/24964). 2011-10-27 20:29:42 +00:00
Automatic Updater 8398bf3d13 update 2011-10-26 06:16:11 +00:00
Mark Andrews 2632325ab1 spin waiting for zone transfer to complete 2011-10-26 05:34:55 +00:00
Automatic Updater 40eaf6ebae update 2011-10-26 00:15:36 +00:00
Automatic Updater 1e112f85f6 update copyright notice 2011-10-25 23:46:16 +00:00
Automatic Updater 9713618f1d newcopyrights 2011-10-25 23:30:09 +00:00
Automatic Updater 7ac24b68f7 update 2011-10-25 22:15:41 +00:00
Mark Andrews 688cf68c1f 3179. [port] kfreebsd: build issues. [RT #26273] 2011-10-25 21:25:30 +00:00
Automatic Updater 29cc00edb7 update 2011-10-25 04:15:52 +00:00
Mark Andrews 455fff78cf improve failure reports 2011-10-25 04:06:48 +00:00
Automatic Updater 28b603e094 update 2011-10-25 03:15:37 +00:00
Mark Andrews 62ccc1a14c Correctly invalidate the sha2/hmac2 contexts. This was already done in practice, but this makes it zero out the whole structure rather than just the first 4 bytes + the key. sha2.c did not always zero out the full sha2 state in invalidate, but will now. 2011-10-25 03:13:54 +00:00
Automatic Updater 0fda82b42b update 2011-10-21 04:15:27 +00:00
Mark Andrews f5965ba439 remove redundant assignment and variable 2011-10-21 03:56:55 +00:00
Automatic Updater 48819570a4 update 2011-10-21 02:15:39 +00:00
Automatic Updater e90c12aa1a regen v9_7 2011-10-21 01:39:11 +00:00
Automatic Updater e1389d0fc0 update 2011-10-21 00:15:33 +00:00
Automatic Updater 7ac50d49b3 update copyright notice 2011-10-20 23:46:05 +00:00
Automatic Updater 78b2b685f5 newcopyrights 2011-10-20 23:30:08 +00:00
Automatic Updater 8b9ce3a945 update 2011-10-20 22:15:29 +00:00
Mark Andrews d2f6d12a22 3175. [bug] Fix how DNSSEC positive wildcard responses from a
NSEC3 signed zone are validated.  Stop sending a
                        unnecessary NSEC3 record when generating such
                        responses. [RT #26200]
2011-10-20 21:46:17 +00:00
Mark Andrews 45ed7563d3 3174. [bug] Always compute to revoked key tag from scratch.
[RT #24711]
2011-10-20 21:26:17 +00:00
Automatic Updater bb989de483 update 2011-10-18 00:15:53 +00:00
Automatic Updater 12cc8e4b55 update copyright notice 2011-10-17 23:45:49 +00:00
Automatic Updater 494956367e newcopyrights 2011-10-17 23:30:11 +00:00
Automatic Updater 3c35c14f4a update 2011-10-17 06:16:07 +00:00
Mark Andrews 22e3009f38 sleep 1 # allow lwresd to finish starting. 2011-10-17 05:43:43 +00:00
Automatic Updater 2b3faeab85 update 2011-10-17 03:16:03 +00:00
Mark Andrews 97f56425ad sync with head 2011-10-17 02:38:48 +00:00
Mark Andrews a793e659f5 add --restart arg 2011-10-17 02:37:41 +00:00
Automatic Updater c6825bef82 update 2011-10-15 05:15:33 +00:00
Mark Andrews 6a24616ccf 3173. [port] Correctly validate root DS responses. [RT #25726] 2011-10-15 05:12:04 +00:00
Automatic Updater d2262312eb update 2011-10-14 08:16:00 +00:00
Mark Andrews d6bc7dc77c properly compute the revoked key's id 2011-10-14 07:26:42 +00:00
Automatic Updater db68945438 update 2011-10-14 06:15:51 +00:00
Mark Andrews dc9823fb8a 3171. [bug] Exclusively lock the task when adding a zone using
'rndc addzone'.  [RT #25600]
2011-10-14 05:47:25 +00:00
Automatic Updater 14e26c0959 update 2011-10-13 23:16:07 +00:00
Automatic Updater 7e2c785e5e update copyright notice 2011-10-13 22:47:23 +00:00
Automatic Updater 7f687c254f newcopyrights 2011-10-13 22:46:28 +00:00
Automatic Updater 1d445ba9c6 update 2011-10-13 14:15:32 +00:00
Mark Andrews d7ae34d839 handle unchecked assignment 2011-10-13 13:15:45 +00:00
Automatic Updater fd4c85061a update 2011-10-13 08:16:08 +00:00
Mark Andrews 85119d84b9 #include <stdlib.h> 2011-10-13 07:42:31 +00:00
Automatic Updater 7467b14c0c update 2011-10-13 05:16:07 +00:00
Mark Andrews 62b55f2813 'grep' -> 'grep -w' when checking for keyids 2011-10-13 04:42:02 +00:00
Automatic Updater 2dccf11e3a update 2011-10-13 01:15:27 +00:00
Mark Andrews 4c697150a3 3169. [func] Catch db/version mis-matches when call dns_db_*().
[RT #26017]
2011-10-13 00:51:59 +00:00
Automatic Updater 847cdc2372 update 2011-10-13 00:15:28 +00:00
Mark Andrews d34e308213 3169. [func] Catch db/version mis-matches when call dns_db_*().
[RT #26017]
2011-10-13 00:06:02 +00:00
Automatic Updater 45d403032d update copyright notice 2011-10-12 23:45:33 +00:00
Automatic Updater 3f4ba1fa54 newcopyrights 2011-10-12 23:30:08 +00:00
Automatic Updater 3169fab89f update 2011-10-12 01:15:30 +00:00
Mark Andrews 605095f7e0 3167. [bug] Negative answers from forwarders were not being
correctly tagged making them appear to not be cached.
			[RT #25380]
2011-10-12 00:28:13 +00:00
Automatic Updater b1fdb5273a update 2011-10-11 01:15:27 +00:00
Mark Andrews c29205c329 handle named.args 2011-10-11 00:50:01 +00:00
Automatic Updater 15a75bf608 update 2011-10-11 00:15:53 +00:00
Scott Mann e9dfa90049 Change s/\R//g to chomp(). 2011-10-10 23:22:38 +00:00
Automatic Updater 6fd741539a update 2011-10-10 20:15:31 +00:00
Scott Mann 48a46376cc fix subdirectory path in start.pl 2011-10-10 19:29:40 +00:00
Automatic Updater 3f91210cb6 update 2011-10-10 19:15:25 +00:00
Scott Mann a7af4a545b allow options to named via start.pl (RT 26044). 2011-10-10 18:53:48 +00:00
Automatic Updater 41d335872e update 2011-10-07 05:15:32 +00:00
Evan Hunt 4dd839d8e2 3157. [tuning] Reduce the time spent in "rndc reconfig" by parsing
the config file before pausing the server. [RT #21373]
2011-10-07 04:43:36 +00:00
Automatic Updater 1b5c297c2d update 2011-10-07 03:16:02 +00:00
Mark Andrews b6e1726eac 3161. [bug] zone.c:del_sigs failed to always reset rdata leading
assertion failures. [RT #25880]
2011-10-07 03:01:35 +00:00
Automatic Updater f5611188f2 update 2011-10-07 02:15:28 +00:00
Automatic Updater f25f2b207c regen v9_7 2011-10-07 01:39:18 +00:00
Automatic Updater bf4134c520 update 2011-10-06 12:15:24 +00:00
Mark Andrews bd6d1e72b3 fix default for sig-signing-type 2011-10-06 11:52:29 +00:00
Mark Andrews 0fa710047e rt21764 session-* fixes 2011-10-06 11:36:08 +00:00
Automatic Updater 5c17396f5c update 2011-09-30 06:15:53 +00:00
Mark Andrews 809adc90e9 3129. [bug] Named could crash on 'rndc reconfig' when
allow-new-zones was set to yes and named ACLs
                        were used, [RT #22739]
2011-09-30 05:25:28 +00:00
Automatic Updater 9ecd6ad01d update 2011-09-08 16:15:26 +00:00
Evan Hunt 063e8ae6cd update cvsignore 2011-09-08 15:28:03 +00:00
Automatic Updater 85855bd04a update 2011-09-07 19:15:27 +00:00
Evan Hunt f6ce33c392 3154. [bug] Attempting to print an empty rdataset could trigger
an assert. [RT #25452]
2011-09-07 19:11:45 +00:00
Automatic Updater fdcf4e9a88 update 2011-09-06 06:15:41 +00:00
Mark Andrews 73f6bc3ebb add depend target 2011-09-06 05:54:38 +00:00
Automatic Updater 915155738e update 2011-09-06 04:15:30 +00:00
Mark Andrews 2cb9555c26 $ -> 18739 2011-09-06 04:05:37 +00:00
Mark Andrews ebd1cb38cb run unit tests even if system tests fail. Report if either set of tests fail 2011-09-06 04:03:07 +00:00
Automatic Updater 5046eb9e1a update 2011-09-06 00:15:30 +00:00
Automatic Updater 35973584f3 update copyright notice 2011-09-05 23:45:33 +00:00
Automatic Updater 20737d23f6 newcopyrights 2011-09-05 23:30:08 +00:00
Automatic Updater 674e2cd3c8 update 2011-09-05 18:15:29 +00:00
Evan Hunt cad1ee5fde 3152. [cleanup] Some versions of gcc and clang failed due to
incorrect use of __builtin_expect. [RT #25183]
2011-09-05 18:01:30 +00:00
Evan Hunt c5d451695e removed Makefile that shouldn't have been committed 2011-09-05 17:41:19 +00:00
Evan Hunt 22fe67981e add time.h to silence compiler warning 2011-09-05 17:39:23 +00:00
Automatic Updater 5b5b2e5e6c update 2011-09-05 00:15:33 +00:00
Mark Andrews e4b4f2ed77 manual adds 2011-09-05 00:08:47 +00:00
Automatic Updater 340265ed8a update 2011-09-04 13:15:28 +00:00
Mark Andrews da45cf7d9f add 2011-09-04 13:02:11 +00:00
Automatic Updater 265454279b update 2011-09-04 12:15:25 +00:00
Mark Andrews 8a57d5e942 report R:PASS/FAIL 2011-09-04 12:11:00 +00:00
Automatic Updater 1b35f8454b update 2011-09-03 16:15:23 +00:00
Evan Hunt ded997a823 removed unused variable to silence a compiler warning 2011-09-03 16:05:32 +00:00
Automatic Updater 9af7e3b726 update 2011-09-03 06:15:26 +00:00
Evan Hunt bf99944cd3 fix whitespace 2011-09-03 05:52:55 +00:00
Automatic Updater bf157cf5f4 update 2011-09-03 00:15:43 +00:00
Automatic Updater 69a1852134 update copyright notice 2011-09-02 23:45:31 +00:00
Automatic Updater 9634848023 update 2011-09-02 23:15:32 +00:00
Evan Hunt 3365971166 3139. [test] Added tests from RFC 6234, RFC 2202, and RFC 1321
for the hashing algorithms (md5, sha1 - sha512, and
			their hmac counterparts).  [RT #25067]
2011-09-02 22:23:08 +00:00
Automatic Updater cb896a6507 update 2011-09-02 22:15:28 +00:00
Evan Hunt 83f4f1c61b 3151. [bug] Queries for type RRSIG or SIG could be handled
incorrectly.  [RT #21050]
2011-09-02 21:54:22 +00:00
Automatic Updater 7558285577 update 2011-09-02 21:15:24 +00:00
Evan Hunt 2533514b8b 3149. [tuning] Improve scalability by allocating one zone
task per 100 zones at startup time.  (The
			BIND9_ZONE_TASKS_HINT environment variable
			which was established as a temporary measure
			in change #3132 is no longer needed or
			used.) [rt25541]
2011-09-02 20:22:27 +00:00
Automatic Updater ee34af0d10 update 2011-09-02 15:15:26 +00:00
Scott Mann c935b96e9c fix comment 2011-09-02 14:42:34 +00:00
Automatic Updater 5b1d5028da update 2011-09-02 02:45:41 +00:00
Mark Andrews 82b403ea73 don't use a expired slave zone 2011-09-02 02:23:33 +00:00
Automatic Updater 6a7faae8cc update 2011-09-01 00:15:54 +00:00
Automatic Updater 0dbb98778e update copyright notice 2011-08-31 23:45:32 +00:00
Automatic Updater 2d3535112d newcopyrights 2011-08-31 23:30:08 +00:00
Automatic Updater b99ebe6c92 update 2011-08-31 08:15:26 +00:00
Mark Andrews d800ae7802 3148. [bug] Processing of normal queries could be stalled when
forwarding a UPDATE message. [RT #24711]
2011-08-31 07:20:44 +00:00
Automatic Updater 31ed5789d1 update 2011-08-31 01:15:28 +00:00
Mark Andrews 0cd7b779d3 silence clang warnings 2011-08-31 00:47:57 +00:00
Automatic Updater 3a41396c3b update 2011-08-31 00:15:48 +00:00
Automatic Updater bbd11f9c74 update copyright notice 2011-08-30 23:45:34 +00:00
Automatic Updater c069179cab newcopyrights 2011-08-30 23:30:10 +00:00
Automatic Updater 3b444759a8 update 2011-08-30 23:15:31 +00:00
Mark Andrews 172f4853b7 silence clang warnings 2011-08-30 22:28:18 +00:00
Automatic Updater 77c23033c8 update 2011-08-30 22:15:28 +00:00
Mark Andrews 43d6b173bc report the result of dns_adb_createfind 2011-08-30 21:53:08 +00:00
Mark Andrews 6e3f51505e dns_view_issecuredomain: check that view->secroots_priv is non NULL before calling dns_keytable_issecuredomaiani otherwise return ISC_R_NOTFOUND 2011-08-30 21:47:20 +00:00
Automatic Updater d261593e81 update 2011-08-30 14:15:30 +00:00
Mark Andrews 9533ace890 silence clang warnings 2011-08-30 14:04:21 +00:00
Automatic Updater 555d3a5f64 update 2011-08-30 01:15:27 +00:00
Mark Andrews 785944ebd1 POST(port); POST(addr); 2011-08-30 00:20:18 +00:00
Automatic Updater b9576c1a55 update 2011-08-30 00:15:44 +00:00
Automatic Updater 110fd066b2 update copyright notice 2011-08-29 23:45:34 +00:00
Automatic Updater 9455840478 newcopyrights 2011-08-29 23:30:09 +00:00
Mark Andrews 33412a6755 query could be tested uninitialised, check the result of dns_message_create 2011-08-29 23:26:19 +00:00
Automatic Updater 100ceaf76e update 2011-08-29 07:15:29 +00:00
Mark Andrews 5be5c9dd6c check the results of dns_name_toprincipal calls, only use gnamebuf.value when valid 2011-08-29 06:38:35 +00:00
Automatic Updater c3b1a39f38 update 2011-08-29 06:15:52 +00:00
Mark Andrews cbf8f049ea *++tp = 0; -> tp++; *tp = 0; 2011-08-29 06:00:29 +00:00
Automatic Updater 48d17ac717 update 2011-08-29 05:16:00 +00:00
Mark Andrews 4733ef3db6 POST(p); POST(len); 2011-08-29 04:22:06 +00:00
Automatic Updater 3b9a2e08f8 update 2011-08-29 04:15:29 +00:00
Mark Andrews fa79b32d9e INSIST(response); 2011-08-29 04:04:42 +00:00
Automatic Updater 1a4be1e7c3 update 2011-08-29 00:15:34 +00:00
Mark Andrews bddfc920b0 add POST, len is not needed 2011-08-28 23:56:42 +00:00
Mark Andrews 0ff5d479be add POST 2011-08-28 23:48:54 +00:00
Automatic Updater 82ed23194e update copyright notice 2011-08-28 23:45:28 +00:00
Mark Andrews 9ad02d655e add missing check_result 2011-08-28 23:37:40 +00:00
Automatic Updater 2b0bbc0f21 newcopyrights 2011-08-28 23:30:08 +00:00
Automatic Updater a9341a82f1 update 2011-08-28 10:15:26 +00:00
Mark Andrews d0d0200ad6 silence 'never read' warning 2011-08-28 09:28:32 +00:00
Mark Andrews 3bb6385d0e report if dns_rdata{class,type}_totext failed 2011-08-28 09:15:08 +00:00
Automatic Updater 621d2e0204 update 2011-08-28 08:15:26 +00:00
Mark Andrews 15cc67ef12 t3 is not used 2011-08-28 08:13:42 +00:00
Automatic Updater fd15b7aae4 update 2011-08-27 00:15:53 +00:00
Automatic Updater e29f472f80 update copyright notice 2011-08-26 23:45:30 +00:00
Automatic Updater 99162dd8fa update 2011-08-26 05:16:04 +00:00
Mark Andrews c49683433b silence 'is never read' warnings 2011-08-26 04:45:38 +00:00
Automatic Updater 669aed2158 update 2011-08-26 04:15:31 +00:00
Mark Andrews f47f63e541 3134. [bug] Improve the accuracy of dnssec-signzone's signing
statistics. [RT #16030]
2011-08-26 03:55:14 +00:00
Automatic Updater 1698f6c929 update 2011-08-26 00:15:49 +00:00
Automatic Updater 65232ec5fa update copyright notice 2011-08-25 23:45:28 +00:00
Automatic Updater b396825615 newcopyrights 2011-08-25 23:30:13 +00:00
Automatic Updater 154d3adcbc update 2011-08-25 14:15:25 +00:00
Mark Andrews e734a20ff0 simplify flag printing, protect first with #ifdef USEINITALWS 2011-08-25 13:30:18 +00:00
Automatic Updater 1addc7c818 update 2011-08-25 11:15:26 +00:00
Mark Andrews a60c4bb0c8 remove isc_os_minprivs call accidently committed 2011-08-25 10:26:17 +00:00
Automatic Updater 3b5fbbf5fe update 2011-08-25 08:15:30 +00:00
Mark Andrews ef7186adef cltfd is only needed when select is being used 2011-08-25 08:11:31 +00:00
Automatic Updater 7387ca7a82 update 2011-08-25 07:15:43 +00:00
Mark Andrews ca31f9bf14 silence 'Dereference of undefined pointer value' by assigning to 'sorted' sequentially from zero 2011-08-25 06:30:00 +00:00
Mark Andrews dc6ecfde62 save the result of is_response(msg) so it can be treated as a invariant by clang 2011-08-25 06:23:06 +00:00
Automatic Updater adbb626636 update 2011-08-25 06:15:33 +00:00
Mark Andrews d865e14494 silence null pointer dereference warning by adding INSIST(sibling != NULL); 2011-08-25 06:11:04 +00:00
Automatic Updater d003a234cf update 2011-08-25 00:15:30 +00:00
Mark Andrews 991aecda47 lib/dns/tests/testdata/dbiterator/zone2.data 2011-08-24 23:54:43 +00:00
Automatic Updater 11fc4e9d94 update 2011-08-24 20:15:26 +00:00
Scott Mann e45d820cf6 Fixes compilation errors in ATF under gcc4.6.0 (RT #25598). 2011-08-24 19:59:03 +00:00
Automatic Updater 77351922c5 update 2011-08-24 00:15:32 +00:00
Automatic Updater 6b1cb71807 update copyright notice 2011-08-23 23:53:26 +00:00
Mark Andrews e4bcbf4a4e manual add 2011-08-23 23:45:22 +00:00
Automatic Updater 4120ec8591 update 2011-08-23 04:15:27 +00:00
Mark Andrews 789547be22 #include <stdlib.h> 2011-08-23 03:52:41 +00:00
Automatic Updater 1090746b55 update 2011-08-23 03:15:47 +00:00
Evan Hunt e15400ccec Fix backport issue 2011-08-23 02:54:41 +00:00
Automatic Updater acfc813fe3 update 2011-08-23 02:15:25 +00:00
Evan Hunt c0f1383f02 3145. [test] Capture output of ATF unit tests in "./atf.out" if
there were any errors while running them. [RT #25527]
2011-08-23 01:29:14 +00:00
Automatic Updater 2233651298 update 2011-08-23 01:15:26 +00:00
Evan Hunt 77d878b630 3144. [bug] dns_dbiterator_seek() could trigger an assert when
used with a nonexistent database node. [RT #25358]
2011-08-23 00:57:46 +00:00
Evan Hunt b7be8695c2 file Makefile was added on branch v9_7 on 2011-09-02 20:22:26 +0000 2011-08-19 00:46:41 +00:00
Automatic Updater 62f4976ba2 update 2011-08-19 00:17:22 +00:00
Automatic Updater d78521d0f1 update copyright notice 2011-08-18 23:45:29 +00:00
Automatic Updater 7060c33697 newcopyrights 2011-08-18 23:30:08 +00:00
Automatic Updater 895e90d967 update 2011-08-18 18:15:26 +00:00
Mark Andrews 016b20872a cast to unsigned 2011-08-18 17:37:14 +00:00
Automatic Updater 6185a29b3e update 2011-08-18 07:15:32 +00:00
Mark Andrews 87ec3cc5e0 sync with head 2011-08-18 06:50:01 +00:00
Mark Andrews 7e67387531 3143. [bug] Silence clang compiler warnings. [RT #25174] 2011-08-18 06:41:59 +00:00
Automatic Updater 473461077d update 2011-08-18 05:16:01 +00:00
Mark Andrews d7ffccecc0 3143. [bug] Silence clang compiler warnings. [RT #25174] 2011-08-18 05:04:37 +00:00
Automatic Updater 78b5fca661 update 2011-08-17 00:15:49 +00:00
Automatic Updater 8cf8ec5c40 update copyright notice 2011-08-16 23:45:29 +00:00
Automatic Updater a8b440c1a1 newcopyrights 2011-08-16 23:30:11 +00:00
Automatic Updater d762a9808d update 2011-08-16 03:15:59 +00:00
Mark Andrews 38aa6b80f4 3142. [bug] NAPTR is class agnostic. [RT #25429] 2011-08-16 02:59:33 +00:00
Automatic Updater 0f20ac1514 update 2011-08-16 00:15:24 +00:00
Mark Andrews 59a1d41ca9 3142. [bug] NAPTR is class agnostic. [RT #25429] 2011-08-16 00:10:31 +00:00
Evan Hunt 7bcd1bf151 file zone2.data was added on branch v9_7 on 2011-08-23 00:57:46 +0000 2011-08-15 23:58:41 +00:00
Evan Hunt be69f7e809 file zone1.data was added on branch v9_7 on 2011-08-23 00:57:46 +0000 2011-08-09 18:17:33 +00:00
Evan Hunt d814fa446b file dbiterator_test.c was added on branch v9_7 on 2011-08-23 00:57:46 +0000 2011-08-09 18:17:31 +00:00
Automatic Updater cd8571aa95 update 2011-08-09 04:15:28 +00:00
Automatic Updater c1d6d061c1 update copyright notice 2011-08-09 04:11:29 +00:00
Automatic Updater aceb10d783 newcopyrights 2011-08-09 04:10:40 +00:00
Automatic Updater d6b2dca644 update 2011-08-09 03:15:58 +00:00
Mark Andrews c8ba3fc75d 3141. [bug] Silence spurious "zone serial (0) unchanged" messages
associated with empty zones. [RT #25079]
2011-08-09 03:14:31 +00:00
Automatic Updater 8116f2b24d update 2011-08-09 02:15:25 +00:00
Automatic Updater 7b4713a02e regen v9_7 2011-08-09 01:39:19 +00:00
Automatic Updater e8f1b1213d update 2011-08-09 00:15:47 +00:00
Automatic Updater 379e2ac37f update copyright notice 2011-08-08 23:45:28 +00:00
Automatic Updater ed9e1d0fa6 newcopyrights 2011-08-08 23:30:08 +00:00
Automatic Updater bf094b5cca update 2011-08-08 04:15:31 +00:00
Mark Andrews c313719d03 rt25400 s/domain/filename/ 2011-08-08 03:28:44 +00:00
Automatic Updater f246dfbfdf update 2011-08-03 02:16:33 +00:00
Automatic Updater dde140cb6f regen v9_7 2011-08-03 02:08:34 +00:00
Automatic Updater b737488df5 update 2011-08-02 05:16:16 +00:00
Evan Hunt 1999760f5d 3136. [func] Add RFC 1918 reverse zones to the list of built-in
empty zones switched on by the 'empty-zones-enable'
			option. [RT #24990]
2011-08-02 04:57:54 +00:00
Automatic Updater 2f809da8bc update 2011-07-30 02:16:25 +00:00
Automatic Updater 064a2bea35 sync 2011-07-30 01:58:08 +00:00
Automatic Updater 84644c3f38 update 2011-07-29 03:16:50 +00:00
Mark Andrews cafd42ef9d missing isc__strerror on error paths 2011-07-29 02:19:49 +00:00
Automatic Updater d96dfb6b2a update 2011-07-29 00:16:31 +00:00
Automatic Updater dfefcdbc5d update copyright notice 2011-07-28 23:46:45 +00:00
Automatic Updater 1ad60cdae7 newcopyrights 2011-07-28 23:30:24 +00:00
Automatic Updater 54b07e13d5 update 2011-07-28 05:16:17 +00:00
Mark Andrews 2bc71862f6 3138. [bug] Address memory leaks and out-of-order operations when
shutting named down. [RT #25210]
2011-07-28 04:37:35 +00:00
Automatic Updater e965f61466 update 2011-07-28 03:26:45 +00:00
Mark Andrews 4c74c25bf5 add ${ISC_INCLUDES} 2011-07-28 03:17:29 +00:00
Automatic Updater 15641b74aa update 2011-07-28 02:16:36 +00:00
Mark Andrews 85f91f6416 use UNUSED() 2011-07-28 01:25:04 +00:00
Automatic Updater f4064f6488 update 2011-07-27 08:16:53 +00:00
Mark Andrews 025933687a silence 'expression result unused' from clang 2011-07-27 07:43:16 +00:00
Automatic Updater d575c37a64 update 2011-07-27 07:16:29 +00:00
Mark Andrews 51b7bdb802 use UNUSED(x) not 'x = x' 2011-07-27 07:08:13 +00:00
Automatic Updater 13ec66ef56 update 2011-07-26 22:16:20 +00:00
Michael Graff 8cd861021b regenerate 2011-07-26 22:09:48 +00:00
Michael Graff 6d511577b0 fix for compiling on OSX Lion. Verified it compiles on Snow Leopard using older XCode as well. 2011-07-26 22:00:36 +00:00
Automatic Updater fc966bc8b7 update 2011-07-26 05:16:10 +00:00
Mark Andrews 83da3b502c remove check for oldid as named may have already deleted it 2011-07-26 04:41:06 +00:00
Mark Andrews d14f0bc8dd id was not being properly set 2011-07-26 04:30:01 +00:00
Automatic Updater f463c3611b update 2011-07-24 00:16:42 +00:00
Automatic Updater 417a6e5ce9 update copyright notice 2011-07-23 23:46:45 +00:00
Automatic Updater 8b1aabd2a7 update 2011-07-23 09:16:11 +00:00
Mark Andrews 06de2249b5 9.7.4 2011-07-23 08:32:06 +00:00
Automatic Updater 7c56a5fa65 update 2011-07-22 00:16:30 +00:00
Automatic Updater 60383f3479 update copyright notice 2011-07-21 23:46:46 +00:00
Automatic Updater 0d16ffbb38 update 2011-07-21 07:16:19 +00:00
Mark Andrews 376b338da4 s/fallbackas/fallback as/ 2011-07-21 06:24:27 +00:00
Automatic Updater 0b619c6751 update 2011-07-21 03:16:21 +00:00
Mark Andrews fba67c8aef Missing changes note:
3114.   [bug]           Retain expired RRSIGs in dynamic zones if key is
                        inactive and there is no replacement key. [RT #23136]
2011-07-21 03:03:58 +00:00
Mark Andrews f79d8d3e0a 9.7.4 2011-07-21 02:43:44 +00:00
Mark Andrews b7ae61a21b update changes note 2011-07-21 02:40:05 +00:00
Automatic Updater 66040ff693 update 2011-07-21 02:16:40 +00:00
Mark Andrews bf31eeeee8 3135. [port] FreeBSD: workaround broken IPV6_USE_MIN_MTU processing.
See http://www.freebsd.org/cgi/query-pr.cgi?pr=158307
                        [RT #24950]
2011-07-21 01:46:17 +00:00
Automatic Updater 19286de949 update 2011-07-21 00:16:30 +00:00
Automatic Updater 159b4147ae update copyright notice 2011-07-20 23:46:50 +00:00
Automatic Updater 2adf1074e4 update 2011-07-20 00:16:33 +00:00
Curtis Blackburn f6ad003ecf 3132.[bug]Workaround for excessive startup time with
large number of zones;
 allow setting of an environment variable to tune
 the number of tasks. default is 8, reccommend
 200 zones per task. If you have 200000 zones:
 csh: setenv BIND9_ZONE_TASKS_HINT 1000
 sh:  BIND9_ZONE_TASKS_HINT=1000;
      export BIND9_ZONE_TASKS_HINT
 Applicable to 9.7, 9.6, auto-tuned in 9.8 and up.
2011-07-20 00:00:24 +00:00
Automatic Updater ff8dbeaea2 update 2011-07-09 00:16:21 +00:00
Automatic Updater 414b674e7c update copyright notice 2011-07-08 23:46:44 +00:00
Automatic Updater c5548964bf newcopyrights 2011-07-08 23:30:18 +00:00
Automatic Updater e946c1762a update 2011-07-08 02:16:14 +00:00
Evan Hunt 4d1b079ac6 3133. [bug] Change #3114 was incomplete. [RT #24577] 2011-07-08 01:46:42 +00:00
Automatic Updater fe3ce1da2b update 2011-06-21 22:16:17 +00:00
Evan Hunt 41ca3ff801 Add the newly discovered PoD to the nsupdate test. (No CHANGES note.) 2011-06-21 22:14:42 +00:00
Automatic Updater 77f4a19e4e update 2011-06-17 00:16:33 +00:00
Automatic Updater 89645a2265 update copyright notice 2011-06-16 23:46:34 +00:00
Automatic Updater 851bccc5a1 update 2011-06-16 02:16:14 +00:00
Mark Andrews 2b24897c64 update for re-tag of 9.7.4rc1 2011-06-16 01:28:42 +00:00
Automatic Updater 011f157473 update 2011-06-15 04:16:49 +00:00
Mark Andrews b3efdb08bd move 9.7.4rc1 release marker 2011-06-15 03:40:52 +00:00
Automatic Updater 38dfbc0462 update 2011-06-09 01:16:31 +00:00
Automatic Updater 96936dcdab update 2011-06-09 00:16:23 +00:00
Evan Hunt d61efe262b Fixed an nsupdate test error. 2011-06-09 00:15:38 +00:00
Evan Hunt b55dbfdc1e 3124. [bug] Use an rdataset attribute flag to indicate
negative-cache records rather than using rrtype 0;
			this will prevent problems when that rrtype is
			used in actual DNS packets. [RT #24777]

3123.	[security]	Change #2912 exposed a latent flaw in
			dns_rdataset_totext() that could cause named to
			crash with an assertion failure. [RT #24777]
2011-06-08 23:15:44 +00:00
Automatic Updater 2327cb8332 update 2011-06-06 02:16:58 +00:00
Automatic Updater 2c50f32188 cleanup removed files 2011-06-06 01:22:07 +00:00
Automatic Updater bc6393b238 update 2011-06-02 21:16:07 +00:00
Evan Hunt 015872cba9 3122. [cleanup] dnssec-settime: corrected usage message. [RT #24664] 2011-06-02 20:23:49 +00:00
Automatic Updater 40fa732370 update 2011-05-31 01:17:48 +00:00
Automatic Updater 37b7f9ed76 update copyright notice 2011-05-31 01:04:36 +00:00
Mark Andrews 5773bce67f update for 9.7.4rc1 re-tag 2011-05-31 00:27:49 +00:00
Automatic Updater 4c0de19d1b update 2011-05-30 23:16:42 +00:00
Mark Andrews 2358a7881c date +%s is not portable, use perl -e 'print time();', Adjust messages 2011-05-30 22:17:25 +00:00
Automatic Updater 593f1e35d7 update 2011-05-30 08:17:02 +00:00
Mark Andrews 863a0dbd20 The old active key could be deleted before the "former standby key has now
signed fully" ran causing it to fail.  Delay the deletion by 10 seconds.
2011-05-30 07:28:13 +00:00
Automatic Updater 0a3856d2c4 update 2011-05-28 01:17:53 +00:00
Automatic Updater 64a1132d74 update 2011-05-28 00:18:49 +00:00
Automatic Updater 7a0ca2b0c7 update copyright notice 2011-05-28 00:15:26 +00:00
Automatic Updater c057a9b862 newcopyrights 2011-05-27 23:33:30 +00:00
Automatic Updater 6fc5dc883e update 2011-05-27 04:51:50 +00:00
Mark Andrews d44cb7d304 move dns_trust_totext from masterdump.c to rdataset.c so that exportlib will build 2011-05-27 04:41:18 +00:00
Automatic Updater e51b6ade48 update 2011-05-27 02:16:25 +00:00
Mark Andrews babe8e1954 move 9.7.4rc1 release point 2011-05-27 01:57:48 +00:00
Automatic Updater b6d8f4bcf7 update 2011-05-27 00:16:32 +00:00
Automatic Updater 4a2abf6faa update copyright notice 2011-05-26 23:46:25 +00:00
Automatic Updater 419ef16980 newcopyrights 2011-05-26 23:36:49 +00:00
Automatic Updater 8f9cf97d96 update 2011-05-26 23:16:34 +00:00
Evan Hunt 6dd373ebab 3121. [security] An authoritative name server sending a negative
response containing a very large RRset could
                        trigger an off-by-one error in the ncache code
                        and crash named. [RT #24650]

3120.	[bug]		Named could fail to validate zones listed in a DLV
			that validated insecure without using DLV and had
			DS records in the parent zone. [RT #24631]

3119.	[bug]		When rolling to a new DNSSEC key, a private-type
			record could be created and never marked complete.
			[RT #23253]
2011-05-26 23:10:13 +00:00
Automatic Updater fc5f2e310e update 2011-05-25 00:16:59 +00:00
Automatic Updater 7000688bfc update copyright notice 2011-05-24 23:46:37 +00:00
Automatic Updater 35e6e7bfe9 update 2011-05-24 02:16:46 +00:00
Automatic Updater 5d900d5216 regen v9_7 2011-05-24 02:10:39 +00:00
Automatic Updater 0f862dd540 update 2011-05-24 01:16:40 +00:00
Automatic Updater 5dd7596365 v9_7_4rc1 2011-05-24 00:48:09 +00:00
Mark Andrews 1bf261f075 9.7.4rc1 2011-05-24 00:41:44 +00:00
Mark Andrews 63aaf0dba0 9.7.4rc1 2011-05-24 00:35:23 +00:00
Mark Andrews 53f747143d v9_7_4rc1 2011-05-24 00:26:44 +00:00
Automatic Updater ea155b7f8b update 2011-05-23 23:16:32 +00:00
Evan Hunt 8a2c86ea10 3118. [bug] nsupdate could dump core on shutdown when using
SIG(0) keys. [RT #24604]
2011-05-23 22:23:05 +00:00
Automatic Updater c02a729605 update 2011-05-23 21:16:16 +00:00
Evan Hunt 0b53de22db 3117. [cleanup] Remove doc and parser references to the
never-implemented 'auto-dnssec create' option.
			[RT #24533]
2011-05-23 20:55:24 +00:00
Automatic Updater 86039977b2 update 2011-05-20 00:16:56 +00:00
Automatic Updater 62bffa3ef0 update copyright notice 2011-05-19 23:46:30 +00:00
Automatic Updater 5f01b84397 newcopyrights 2011-05-19 23:31:12 +00:00
Automatic Updater 12f0fa2a6a update 2011-05-19 22:16:19 +00:00
Evan Hunt 905b16ef04 another post-commit fix for change 3114: call dns_db_resigned()/
dns_db_setsigningtime() only when incrementally resigning, not other
times.
2011-05-19 21:28:01 +00:00
Automatic Updater 3267c08327 update 2011-05-19 05:16:23 +00:00
Evan Hunt 4b7c993dc2 3114. [bug] Retain expired RRSIGs in dynamic zones if key is
inactive and there is no replacement key. [RT #23136]
2011-05-19 04:42:18 +00:00
Automatic Updater 7a9bb15a3c update 2011-05-18 02:16:31 +00:00
Automatic Updater 68e2731590 regen v9_7 2011-05-18 02:11:50 +00:00
Automatic Updater 3602d7ba6a update 2011-05-17 06:16:31 +00:00
Mark Andrews 203987b1f6 3113. [doc] Document the relationship between serial-query-rate
and NOTIFY messages.
2011-05-17 05:30:22 +00:00
Automatic Updater ea2b2d9b49 update 2011-05-17 02:16:21 +00:00
Automatic Updater 28d84645bb regen v9_7 2011-05-17 02:10:42 +00:00
Evan Hunt 94a0e96ade add dns_dnssec_signs 2011-05-17 01:46:41 +00:00
Automatic Updater 480c85c467 update 2011-05-17 00:17:02 +00:00
Automatic Updater d9e9d845a5 update copyright notice 2011-05-16 23:46:51 +00:00
Automatic Updater f0903fa41f newcopyrights 2011-05-16 23:30:56 +00:00
Automatic Updater f12b694d74 update 2011-05-16 23:16:24 +00:00
Evan Hunt 1a035f7c01 "make install" was failing when building with both exportlibs and libtool.
(trivial makefile fix, no CHANGES note.) [RT #24425]
2011-05-16 22:53:56 +00:00
Automatic Updater b8be986508 update 2011-05-16 05:16:27 +00:00
Mark Andrews 3967e289ce 3112. [doc] Add missing descriptions of the update policy name
types "ms-self", "ms-subdomain", "krb5-self" and
                        "krb5-subdomain", which allow machines to update
                        their own records, to the BIND 9 ARM.
2011-05-16 04:16:03 +00:00
Automatic Updater 1f6eacb5f2 update 2011-05-14 02:16:43 +00:00
Automatic Updater fd10c6096f regen v9_7 2011-05-14 02:10:30 +00:00
Evan Hunt a7ff07d136 file expiring.example.db.in was added on branch v9_7 on 2011-05-19 04:42:17 +0000 2011-05-13 21:34:04 +00:00
Automatic Updater efb73dcab3 update 2011-05-13 15:16:20 +00:00
Mark Andrews 4621e0afc1 remove duplicate 2011-05-13 14:15:57 +00:00
Automatic Updater 4d05c5e4c3 update 2011-05-09 00:16:51 +00:00
Automatic Updater b3059b496a newcopyrights 2011-05-08 23:31:16 +00:00
Automatic Updater c5dc89ae15 update 2011-05-08 07:16:15 +00:00
Mark Andrews e080b58ad2 named.conf copyrights 2011-05-08 07:05:12 +00:00
Automatic Updater 063f6cb1f6 update 2011-05-08 02:16:18 +00:00
Automatic Updater 368f38ff7e regen v9_7 2011-05-08 02:08:14 +00:00
Automatic Updater 30e201af17 update 2011-05-08 00:16:57 +00:00
Automatic Updater 7fbd853c14 update copyright notice 2011-05-07 23:46:36 +00:00
Automatic Updater e496dc109f newcopyrights 2011-05-07 23:30:58 +00:00
Automatic Updater 47b7602b32 update 2011-05-07 06:16:47 +00:00
Evan Hunt 52d14ab8a0 3111. [bug] Improved consistency checks for dnssec-enable and
dnssec-validation, added test cases to the
                        checkconf system test. [RT #24398]
2011-05-07 05:52:58 +00:00
Automatic Updater 88cc2316d2 update 2011-05-07 01:17:05 +00:00
Evan Hunt 932d1ded69 3110. [bug] dnssec-signzone: Wrong error message could appear
when attempting to sign with no KSK. [RT #24369]
2011-05-07 00:24:13 +00:00
Automatic Updater dae8f07882 update 2011-05-07 00:17:01 +00:00
Automatic Updater d2d4121e41 update copyright notice 2011-05-06 23:46:35 +00:00
Automatic Updater 1ba011353f newcopyrights 2011-05-06 23:31:17 +00:00
Automatic Updater d6ed4b9543 update 2011-05-06 21:16:17 +00:00
Evan Hunt 77e391dcf0 3107. [bug] dnssec-signzone: Report the correct number of ZSKs
when using -x. [RT #20852]
2011-05-06 21:07:23 +00:00
Automatic Updater 7361f7b44e update 2011-05-06 00:16:57 +00:00
Mark Andrews a1b85f0dc5 set/reset client->signer. 2011-05-05 23:55:19 +00:00
Automatic Updater d2ec48155a update 2011-05-05 20:16:26 +00:00
Automatic Updater 032b797c12 regen 2011-05-05 19:22:38 +00:00
Evan Hunt 030c95db8b 3104. [bug] Better support for cross-compiling. [RT #24367] 2011-05-05 19:19:23 +00:00
Evan Hunt d396fa4d7b file dnssec.3 was added on branch v9_7 on 2011-05-07 05:52:58 +0000 2011-05-05 19:11:54 +00:00
Evan Hunt 23a90cc905 file dnssec.2 was added on branch v9_7 on 2011-05-07 05:52:58 +0000 2011-05-05 19:11:52 +00:00
Evan Hunt 2a15134ad8 file dnssec.1 was added on branch v9_7 on 2011-05-07 05:52:58 +0000 2011-05-05 19:11:50 +00:00
Evan Hunt 49c2c7f047 file clean.sh was added on branch v9_7 on 2011-05-07 05:52:58 +0000 2011-05-05 19:11:48 +00:00
Automatic Updater 70098b1589 update 2011-05-05 05:16:29 +00:00
Mark Andrews 4f0ae1f09f explictly kill the process if the server fails to start, check for a non zero length pid file 2011-05-05 04:56:02 +00:00
Automatic Updater 5bfdeeb223 update 2011-05-04 00:17:01 +00:00
Automatic Updater c828da6fd2 update copyright notice 2011-05-03 23:46:59 +00:00
Automatic Updater 47181231d7 newcopyrights 2011-05-03 23:30:46 +00:00
Automatic Updater f4bf81792a update 2011-05-03 16:16:19 +00:00
Mark Andrews 9f0648fcdb grep was not precise enough leading to test failure 2011-05-03 16:09:48 +00:00
Automatic Updater 836542c79d update 2011-05-03 01:16:57 +00:00
Mark Andrews a6213e6566 treat abs(x) < 500ms as 0 2011-05-03 00:37:24 +00:00
Automatic Updater 5b14ab9dc9 update 2011-05-03 00:16:55 +00:00
Automatic Updater 50e99b5431 update copyright notice 2011-05-02 23:46:49 +00:00
Automatic Updater a6c4c2e290 newcopyrights 2011-05-02 23:30:57 +00:00
Automatic Updater 524fb791e1 update 2011-05-02 05:16:20 +00:00
Mark Andrews a680251f6b force numeric comparision 2011-05-02 05:00:50 +00:00
Automatic Updater 1216351b41 update 2011-05-02 02:16:17 +00:00
Mark Andrews c4135d6b8e handle end of day 2011-05-02 01:41:26 +00:00
Automatic Updater 391b853668 update 2011-05-02 00:16:55 +00:00
Mark Andrews 881c1a4e65 treat exit code 255 as skipped 2011-05-01 23:32:43 +00:00
Automatic Updater eddebea2b4 update 2011-05-01 21:46:31 +00:00
Mark Andrews d1e2909418 fix expression 2011-05-01 21:37:03 +00:00
Automatic Updater 7db4c7b5b5 update 2011-05-01 12:16:18 +00:00
Mark Andrews d8c4983127 awk -v is not portable, add floating point arithmetic effects 2011-05-01 11:33:08 +00:00
Automatic Updater 2b6899f41f update 2011-04-30 02:16:19 +00:00
Automatic Updater 232eb5b99c regen v9_7 2011-04-30 02:11:01 +00:00
Automatic Updater f034123382 update 2011-04-29 22:16:19 +00:00
Evan Hunt bbc2f43f5f 3101. [bug] Zones using automatic key maintenance could fail
to check the key repository for updates. [RT #23744]
2011-04-29 21:43:37 +00:00
Automatic Updater ed6abf57cb update 2011-04-20 00:16:59 +00:00
Automatic Updater 2f19fa2364 update copyright notice 2011-04-19 23:47:01 +00:00
Automatic Updater 745452dd8d newcopyrights 2011-04-19 23:30:40 +00:00
Automatic Updater 751e78699c update 2011-04-19 23:16:27 +00:00
Automatic Updater 6fac8250fe regen 2011-04-19 22:36:19 +00:00
Evan Hunt 882ab80d57 3099. [test] "dlz" system test now runs but gives R:SKIPPED if
not compiled with --with-dlz-filesystem.  [RT #24146]
2011-04-19 22:32:24 +00:00
Automatic Updater e89954332f update 2011-04-16 00:16:56 +00:00
Automatic Updater c6b94cea88 newcopyrights 2011-04-15 23:31:01 +00:00
Automatic Updater bd3d28a0e1 update 2011-04-15 01:16:30 +00:00
Evan Hunt 19ad23141e 3097. [test] Add a tool to test handling of malformed packets.
[RT #24096]
2011-04-15 01:01:13 +00:00
Evan Hunt 4db1370d72 file packet.pl was added on branch v9_7 on 2011-04-15 01:01:13 +0000 2011-04-15 01:00:09 +00:00
edmonds 4ebf39bfb0 update 2011-04-13 23:22:28 +00:00
Automatic Updater 0ac301ced6 update 2011-04-08 07:16:44 +00:00
Automatic Updater 88633933a0 newcopyrights 2011-04-08 06:19:20 +00:00
Automatic Updater 9032c19495 update 2011-04-08 06:16:18 +00:00
Mark Andrews c802ba3785 isc_file_isplainfile 2011-04-08 05:30:55 +00:00
Automatic Updater 89beaff53c update 2011-04-08 05:16:21 +00:00
Mark Andrews 0fa725f3bf dns_cache_create3 2011-04-08 04:46:13 +00:00
Automatic Updater 4d555ab24a update 2011-04-08 03:16:54 +00:00
Automatic Updater 91a4d82324 9.7.4b1 2011-04-08 03:01:10 +00:00
Automatic Updater 1ddd383a5c newcopyrights 2011-04-08 02:49:44 +00:00
Automatic Updater 8d21fb1375 update 2011-04-08 01:16:57 +00:00
Mark Andrews 1dfe15d60e 9.7.4b1 2011-04-08 00:38:52 +00:00
Mark Andrews 05fccbb44f white space 2011-04-08 00:38:43 +00:00
Mark Andrews 452a20766e white space 2011-04-08 00:32:02 +00:00
Mark Andrews bb4175dc30 9.7.4b1 2011-04-08 00:22:19 +00:00
Automatic Updater 513eac3fa9 update 2011-04-08 00:16:57 +00:00
Mark Andrews a7580c035f 9.7.4b1 2011-04-07 23:28:09 +00:00
Automatic Updater d9d1c24e08 update 2011-04-07 23:16:31 +00:00
Mark Andrews ebd1736e8f 3096. [bug] Set KRB5_KTNAME before calling log_cred() in
dst_gssapi_acceptctx(). [RT #24004]
2011-04-07 23:06:06 +00:00
Automatic Updater 0ffe6373a5 update 2011-04-06 11:16:28 +00:00
Mark Andrews 05bec7caf8 3095. [bug] Handle isolated reserved ports in the port range.
[RT #23957]
2011-04-06 10:31:57 +00:00
Automatic Updater 2fbf06bcc8 update 2011-04-06 00:16:54 +00:00
Evan Hunt 07fc520149 add in "dlvauto" system test 2011-04-05 23:15:20 +00:00
Automatic Updater f3b8d1f983 update 2011-04-05 14:16:18 +00:00
Mark Andrews a407a2a647 9.7 doesn't have autodlv 2011-04-05 13:35:10 +00:00
Automatic Updater ffec7b548a update 2011-04-05 07:16:20 +00:00
Mark Andrews 2a55bd28af format portability: cast socklen_t -> long and use %ld 2011-04-05 06:35:37 +00:00
Automatic Updater 7d27e29272 update 2011-04-04 11:16:24 +00:00
Mark Andrews 0f4fb51b1f 1 -> 1U 2011-04-04 11:11:41 +00:00
Automatic Updater 29c4e473a5 update 2011-03-31 16:16:16 +00:00
Evan Hunt 659792d80a Corrected a bug in the dnssec test introduced in change #3046. 2011-03-31 15:56:09 +00:00
Automatic Updater 0910a0b9fb update 2011-03-29 21:16:17 +00:00
Paul Ebersman 46da8e1665 corrected RT bug number for changes 3091 to 22911 2011-03-29 20:24:18 +00:00
Automatic Updater 7cda99b512 update 2011-03-29 00:16:55 +00:00
Automatic Updater 793c8a025a update copyright notice 2011-03-28 23:46:39 +00:00
Automatic Updater 5564fe84c5 newcopyrights 2011-03-28 23:31:01 +00:00
Automatic Updater 0b693c3cc3 update 2011-03-28 06:16:23 +00:00
Mark Andrews da97d91bbf unsigned constants 2011-03-28 05:37:06 +00:00
Mark Andrews 2ac13a1d85 unsigned constants 2011-03-28 05:23:19 +00:00
Automatic Updater aeac83f581 update 2011-03-28 05:16:22 +00:00
Mark Andrews c0f4d881ad while (1) -> for (;;), style 2011-03-28 05:16:01 +00:00
Mark Andrews c5f5e28dcd portability fixes backported from change 2987 2011-03-28 05:09:29 +00:00
Automatic Updater 00b2212e0d update 2011-03-28 04:16:39 +00:00
Mark Andrews 08ac7f3da1 unsigned constants 2011-03-28 03:46:00 +00:00
Automatic Updater 0a58ce1677 update 2011-03-27 00:16:53 +00:00
Automatic Updater 874d107342 update copyright notice 2011-03-26 23:46:44 +00:00
Automatic Updater 9548421f81 newcopyrights 2011-03-26 23:30:48 +00:00
Automatic Updater d96510b789 update 2011-03-26 01:16:28 +00:00
Evan Hunt 33e22751d5 Forgot to add a data file for the autosign test. 2011-03-26 01:09:22 +00:00
Automatic Updater 1c0426be14 update 2011-03-26 00:16:50 +00:00
Evan Hunt de9953980e 3092. [bug] Signatures for records at the zone apex could go
stale due to an incorrect timer setting. [RT #23769]

3091.	[bug]		Fixed a bug in which zone keys that were published
			and then subsequently activated could fail to trigger
			automatic signing. [RT #22991]
2011-03-25 23:54:34 +00:00
Automatic Updater a1daec7a10 regen 2011-03-25 23:30:52 +00:00
Automatic Updater 199727a752 update 2011-03-25 18:16:22 +00:00
Evan Hunt a5607f268d Corrected comment in bind.keys: "dnssec-validation auto" doesn't work in 9.7. 2011-03-25 17:46:40 +00:00
Evan Hunt 84ddf924f1 file delay.example.db was added on branch v9_7 on 2011-03-26 01:09:22 +0000 2011-03-25 03:39:41 +00:00
Automatic Updater f9cc7d28c5 update 2011-03-23 00:16:53 +00:00
Automatic Updater 6b658869ba update copyright notice 2011-03-22 23:46:38 +00:00
Automatic Updater 0a2a4750b3 update 2011-03-22 20:16:45 +00:00
Scott Mann a9fb68beb3 fixup for RT #23687 2011-03-22 19:37:55 +00:00
Automatic Updater a9eff2fe00 update 2011-03-22 19:16:22 +00:00
Scott Mann fd4f29edf2 Remove bin/tests/system/logfileconfig/ns1/named.conf and add setup.sh
in order to resolve changing named.conf issue.  [RT #23687]
2011-03-22 18:44:46 +00:00
Automatic Updater 22e77ee039 update 2011-03-22 04:16:41 +00:00
Evan Hunt 2ca671d4d2 Corrected a mistake that was exposed by change #3085 in 9.9 (though it
has no deleterious effect in 9.8 and earlier).
2011-03-22 03:30:33 +00:00
Automatic Updater e3d0f21f53 update 2011-03-22 02:16:19 +00:00
Automatic Updater 1e98c82a59 regen v9_7 2011-03-22 02:10:56 +00:00
Automatic Updater b0e27f785a update 2011-03-22 00:16:39 +00:00
Automatic Updater 8850c3eb35 update copyright notice 2011-03-21 23:46:29 +00:00
Automatic Updater 04b5e1489a newcopyrights 2011-03-21 23:31:37 +00:00
Automatic Updater a75a475780 update 2011-03-21 21:16:21 +00:00
Mark Andrews 160d5cb860 adjust rt23702 test to take less time 2011-03-21 20:32:39 +00:00
Automatic Updater ad385e3aaa update 2011-03-21 16:16:21 +00:00
Evan Hunt 585530bce3 3086. [bug] Running dnssec-settime -f on an old-style key will
now force an update to the new key format even if no
			other change has been specified, using "-P now -A now"
			as default values.  [RT #22474]
2011-03-21 15:55:48 +00:00
Automatic Updater 975203a88d update 2011-03-21 04:16:31 +00:00
Mark Andrews 9f3efdacd0 wait longer for the nsec3chain generation to complete 2011-03-21 03:31:28 +00:00
Automatic Updater 7a6c7b4622 update 2011-03-21 01:16:53 +00:00
Mark Andrews 53d275bcf7 3083. [bug] NOTIFY messages were not being sent when generating
a NSEC3 chain incrementally. [RT #23702]
2011-03-21 01:08:12 +00:00
Automatic Updater 41810688a1 update 2011-03-19 10:16:21 +00:00
Mark Andrews 8c6e8dd6c1 3081. [bug] Failure of DNAME substitution did not return
YXDOMAIN. [RT #23591]
2011-03-19 10:06:40 +00:00
Automatic Updater 1151904454 update 2011-03-19 00:17:00 +00:00
Automatic Updater abcb1ed6e5 update copyright notice 2011-03-18 23:46:46 +00:00
Automatic Updater ed677aad5b newcopyrights 2011-03-18 23:30:53 +00:00
Automatic Updater 44eb0b53da update 2011-03-18 22:16:22 +00:00
Francis Dupont b61ea69aa3 add 23591 no-regression 2011-03-18 21:37:09 +00:00
Francis Dupont b8f0ed1a12 add new dname test files 2011-03-18 21:33:05 +00:00
Francis Dupont 18103754d2 3081. [bug] Failure of DNAME substitution did not return
YXDOMAIN. [RT #23591]
2011-03-18 21:31:18 +00:00
Automatic Updater 44da510c99 update 2011-03-18 09:16:23 +00:00
Francis Dupont 3a403b358a 3080. [cleanup] Replaced compile time constant by STDTIME_ON_32BITS.
[RT #23587]
2011-03-18 09:07:38 +00:00
Francis Dupont 89a68a7d46 introduce STDTIME_ON_32BITS 2011-03-18 09:07:02 +00:00
Automatic Updater 9a9a197636 update 2011-03-18 08:16:22 +00:00
Mark Andrews 19c5764f41 3079. [bug] Handle isc_event_allocate failures in t_tasks.
[RT #23572]
2011-03-18 07:48:01 +00:00
Automatic Updater f0c059899e update 2011-03-18 05:16:23 +00:00
Evan Hunt 6605a0132b ignore SIGPIPE in ans.pl; this is needed for debian. 2011-03-18 04:40:19 +00:00
Automatic Updater ce1eb06d2a update 2011-03-18 02:16:23 +00:00
Evan Hunt aa9637307b fixed a missing / in /dev/null 2011-03-18 02:06:58 +00:00
Automatic Updater 13f7fc506f update 2011-03-17 06:16:44 +00:00
Mark Andrews f48478f001 3077. [bug] zone.c:zone_refreshkeys() incorrectly called
dns_zone_attach(), use zone->irefs instead. [RT #23303]
2011-03-17 05:30:21 +00:00
Automatic Updater 5a4f843d3e update 2011-03-17 02:16:23 +00:00
Mark Andrews 8a5052e802 3075. [bug] dns_dnssec_findzonekeys{2} used a inconsistant
timestamp when determining which keys are active.
                        [RT #23642]
2011-03-17 01:22:27 +00:00
Automatic Updater ed04eeab8a update 2011-03-14 00:17:29 +00:00
Automatic Updater 9a5a8bc9dd update copyright notice 2011-03-13 23:46:43 +00:00
Automatic Updater db1c68a9c1 newcopyrights 2011-03-13 23:31:02 +00:00
Automatic Updater 2faa53af39 update 2011-03-13 04:17:09 +00:00
Mark Andrews 9a350f520a 3074. [bug] Make the adb cache read through for zone data and
glue learn for zone named is authoritative for.
                        [RT #22842]
2011-03-13 03:38:49 +00:00
Automatic Updater c1b270ae40 update 2011-03-13 00:17:35 +00:00
Automatic Updater d6b5a7bd1b update copyright notice 2011-03-12 23:46:53 +00:00
Automatic Updater f54fe6f19c newcopyrights 2011-03-12 23:30:53 +00:00
Automatic Updater f5933d79ca update 2011-03-12 22:16:58 +00:00
Mark Andrews b134097b24 test for Net::DNS 2011-03-12 21:26:27 +00:00
Automatic Updater 0e54a77925 update 2011-03-12 05:17:13 +00:00
Automatic Updater 88a65863a5 update copyright notice 2011-03-12 04:58:33 +00:00
Automatic Updater 5675d2de03 newcopyrights 2011-03-12 04:56:06 +00:00
Automatic Updater c071a6581e update 2011-03-12 03:17:45 +00:00
Mark Andrews b89e028c05 bin/tests/system/common/rndc.key 2011-03-12 03:08:12 +00:00
Automatic Updater 5c15917576 update 2011-03-11 18:23:56 +00:00
Evan Hunt 3c3d03e138 Forgot to initialize a fixedname 2011-03-11 17:21:30 +00:00
Automatic Updater b08b711e2a update 2011-03-11 14:16:52 +00:00
Mark Andrews ec9d326340 3073. [bug] managed-keys changes were not properly being recorded.
[RT #20256]
2011-03-11 13:24:36 +00:00
Automatic Updater 7a178c0287 update 2011-03-11 13:16:59 +00:00
Mark Andrews a49c3566a7 3071. [bug] has_nsec could be used unintialised in
update.c:next_active. [RT #20256]
2011-03-11 12:55:27 +00:00
Mark Andrews 5b8794da73 3070. [bug] dnssec-signzone potential NULL pointer dereference.
[RT #20256]
2011-03-11 12:42:47 +00:00
Automatic Updater d29938ee0d update 2011-03-11 07:16:52 +00:00
Mark Andrews 526b51ec93 3069. [cleanup] Silence warnings messages from clang static analysis.
[RT #20256]
2011-03-11 07:12:03 +00:00
Automatic Updater bbc6cb37ae update 2011-03-11 03:17:35 +00:00
Mark Andrews b44a3cb109 pkey is only used if USE_ENGINE is defined or USE_EVP is 1 2011-03-11 02:54:07 +00:00
Automatic Updater 8e4c7e687f update 2011-03-11 02:18:34 +00:00
Automatic Updater 0d4ec7d9ac sync 2011-03-11 01:55:50 +00:00
Evan Hunt d7112a033e Reversing prior change, turns out not to be legal on all compilers. 2011-03-11 01:28:29 +00:00
Evan Hunt aa691f6fb4 Silence a compiler warning by using #if comparison instead of if. No
CHANGES note because it's trivial. [RT #23587]
2011-03-11 01:21:57 +00:00
Automatic Updater c653b35f51 update 2011-03-11 01:17:10 +00:00
Mark Andrews c4f131dce9 3068. [bug] Named failed to build with a OpenSSL without engine
support. [RT #23473]
2011-03-11 01:17:09 +00:00
Mark Andrews 11941bb7c6 3067. [bug] ixfr-from-differences {master|slave}; failed to
select the master/slave zones.  [RT #23580]
2011-03-11 00:50:43 +00:00
Automatic Updater 857a10c5ac update 2011-03-10 00:17:32 +00:00
Automatic Updater 7c8c5acdcf update copyright notice 2011-03-09 23:46:26 +00:00
Automatic Updater 496d013619 newcopyrights 2011-03-09 23:31:18 +00:00
Automatic Updater c4c7fdf98e update 2011-03-09 08:16:59 +00:00
Mark Andrews 7a3e203b2d 3065. [bug] RRSIG could have time stamps too far in the future.
[RT #23356]
2011-03-09 07:29:39 +00:00
Automatic Updater c81992af09 update 2011-03-09 02:17:07 +00:00
Automatic Updater 9285be523f regen v9_7 2011-03-09 02:11:34 +00:00
Automatic Updater 1d276ca824 update 2011-03-09 01:17:36 +00:00
Paul Ebersman 9996a31fcb corrected edns-udp-size min to 512 2011-03-09 00:51:40 +00:00
Automatic Updater 20d459121d update 2011-03-08 02:16:59 +00:00
Automatic Updater b7601f1e78 sync 2011-03-08 01:59:52 +00:00
Automatic Updater 258b3ae519 update 2011-03-08 01:17:34 +00:00
Mark Andrews 0b80655d1b add 'sync' to ISC_PLATFORM_USEMACASM build as well 2011-03-08 00:52:04 +00:00
Mark Andrews 438e0483b7 DNAME not DS 2011-03-08 00:38:21 +00:00
Automatic Updater 5d72579040 update 2011-03-08 00:17:37 +00:00
Automatic Updater 9a99e3c47e update copyright notice 2011-03-07 23:46:46 +00:00
Automatic Updater db11e9d7be newcopyrights 2011-03-07 23:30:58 +00:00
Automatic Updater 73027787e1 update 2011-03-07 22:17:00 +00:00
Evan Hunt 3d0d33a56e Style cleanup in DLZ LDAP driver. No functional change, no CHANGES note. 2011-03-07 22:02:41 +00:00
Automatic Updater 652333b000 update 2011-03-07 01:17:33 +00:00
Mark Andrews 29baaada1d 3064. [bug] powerpc: add sync instructions to the end of atomic
operations. [RT #23469]
2011-03-07 00:23:54 +00:00
Automatic Updater 7c704b42da update 2011-03-06 00:17:23 +00:00
Automatic Updater 871a3ebc69 update copyright notice 2011-03-05 23:51:39 +00:00
Automatic Updater 20a5f2b794 newcopyrights 2011-03-05 23:31:04 +00:00
Automatic Updater d41be7b849 update 2011-03-05 23:17:09 +00:00
Evan Hunt 1d6b2871c2 3063. [contrib] More verbose error reporting from DLZ LDAP. [RT #23402] 2011-03-05 23:09:26 +00:00
Automatic Updater bcea85a562 update 2011-03-05 03:17:09 +00:00
Mark Andrews 83032e39d7 add #include <isc/file.h> 2011-03-05 03:02:56 +00:00
Mark Andrews 1105a4fcfc cleanup removed files 2011-03-05 02:51:57 +00:00
Automatic Updater ff349e3d68 update 2011-03-05 02:38:38 +00:00
Automatic Updater 1e9a6f3e14 update 2011-03-04 22:17:00 +00:00
Evan Hunt 47e040c48e 3059. [test] Added a regression test for change #3023. 2011-03-04 22:07:37 +00:00
Automatic Updater 4c80eea432 update 2011-03-04 15:16:56 +00:00
Scott Mann 607c35a5c1 Adding missing test files for RT22771. 2011-03-04 15:09:38 +00:00
Scott Mann 71986a4364 Ensure that log files are plain files. (RT #22771) 2011-03-04 14:17:50 +00:00
Automatic Updater f324e5035a update 2011-03-04 02:17:34 +00:00
Automatic Updater b5906d8cf0 sync 2011-03-04 01:58:34 +00:00
Automatic Updater 17d466904b update 2011-03-04 00:17:31 +00:00
Automatic Updater 2e19f9ff58 update copyright notice 2011-03-03 23:46:43 +00:00
Automatic Updater 445adcb95d newcopyrights 2011-03-03 23:31:03 +00:00
Automatic Updater e28efdcf09 update 2011-03-03 17:16:51 +00:00
Evan Hunt 69c1260911 3057. [bug] "rndc secroots" would abort after the first error
and so could miss some views. [RT #23488]
2011-03-03 16:19:29 +00:00
Automatic Updater d50a91b4b5 update 2011-03-03 14:16:55 +00:00
Francis Dupont 3db330edf8 3055. [bug] Load only the desired keys in the
"dnssec-lookaside auto" mode. [RT #23372]

(back port from 9.8)
2011-03-03 14:06:15 +00:00
Francis Dupont 6c0d104d75 backport load_view_keys() from 9.8 2011-03-03 14:02:53 +00:00
Automatic Updater 538e4f74bf update 2011-03-03 12:16:52 +00:00
Mark Andrews d1288b14be cat the output as atf-report truncates stdout 2011-03-03 11:24:00 +00:00
Automatic Updater 2d032cd20f update 2011-03-03 08:16:56 +00:00
Mark Andrews 31474958ea use csv output format. ticker not suitable for robie 2011-03-03 08:01:16 +00:00
Automatic Updater c05a5e1d73 update 2011-03-03 05:17:02 +00:00
Evan Hunt 031da3eb0c 3053. [bug] Under a sustained high query load with a finite
max-cache-size, it was possible for cache memory
			to be exhausted and not recovered. [RT #23371]
2011-03-03 04:43:36 +00:00
Automatic Updater a45a2e965c update 2011-03-03 00:17:32 +00:00
Automatic Updater f00527a575 update copyright notice 2011-03-02 23:46:59 +00:00
Automatic Updater a9a775cdda newcopyrights 2011-03-02 23:30:49 +00:00
Automatic Updater 377cb850d2 update 2011-03-02 16:16:55 +00:00
Automatic Updater b6effcfad3 regen 2011-03-02 15:24:08 +00:00
Automatic Updater 932edca56d update 2011-03-02 09:17:01 +00:00
Francis Dupont 2fb9f87ccc Fixed last autosign test report [RT #23256] 2011-03-02 09:06:30 +00:00
Automatic Updater af8a702ffa update 2011-03-02 07:16:56 +00:00
Evan Hunt bed2bf2ec7 add MISSING=: to ATF configure arguments to suppress checks for
missing autotools files
2011-03-02 06:40:25 +00:00
Evan Hunt e385b3f9b9 Makefile shouldn't have been committed 2011-03-02 06:18:57 +00:00
Automatic Updater e77ffda2f2 update 2011-03-02 05:17:01 +00:00
Mark Andrews 453e098b25 3051. [bug] NS records obsure DS records at the bottom of the
zone if both are present. [RT #23035]
2011-03-02 04:45:07 +00:00
Mark Andrews b05158a67d 3051. [bug] NS records obsure DS records at the bottom of the
zone if both are present. [RT #23035]
2011-03-02 04:30:53 +00:00
Automatic Updater f3214d80cc update 2011-03-02 04:17:10 +00:00
Mark Andrews 5b4db46db2 3050. [bug] The autosign system test was timing dependent.
Wait for the initial autosigning to complete
                        before running the rest of the test. [RT #23035]
2011-03-02 04:13:02 +00:00
Automatic Updater 676ee9185a update 2011-03-02 03:17:04 +00:00
Mark Andrews cbf9f32246 s/3039/3049/ 2011-03-02 03:05:58 +00:00
Automatic Updater 69dfa864d5 update 2011-03-02 00:17:02 +00:00
Mark Andrews 6a33380ecf 3039. [bug] Save and restore the gid when creating creating
named.pid at startup. [RT #23290]
2011-03-02 00:05:11 +00:00
Automatic Updater 98ec74d568 update copyright notice 2011-03-01 23:47:05 +00:00
Automatic Updater 3abc7a1f90 newcopyrights 2011-03-01 23:30:39 +00:00
Mark Andrews fc7e537b45 3048. [bug] Fully seperate view key mangement. [RT #23419] 2011-03-01 23:22:42 +00:00
Automatic Updater ca6dd4b475 update 2011-03-01 17:16:56 +00:00
Scott Mann a8ab505429 Fixed DNSKEY NODATA responses not cached and added tests [RT #22908]. 2011-03-01 16:47:13 +00:00
Automatic Updater ef1fd9eb5e update 2011-03-01 00:17:17 +00:00
Automatic Updater cf5edf83ec update copyright notice 2011-02-28 23:46:34 +00:00
Automatic Updater c1bf2a2775 newcopyrights 2011-02-28 23:30:51 +00:00
Automatic Updater 448e2663ac regen 2011-02-28 23:30:50 +00:00
Automatic Updater 83e6c42cdd update 2011-02-28 17:17:08 +00:00
Automatic Updater c177dec7c5 autoreconf in hopes of silencing robie warnings 2011-02-28 16:45:56 +00:00
Automatic Updater cc80af09cd update 2011-02-28 15:16:54 +00:00
Francis Dupont fcf1934be8 Use RRSIG original TTL in validated RRset TTL [RT #23332] 2011-02-28 14:28:01 +00:00
Automatic Updater bfdef2abaf update 2011-02-28 13:17:04 +00:00
Mark Andrews ecb10f595d 3044. [bug] Hold the socket manager lock while freeing the socket.
[RT #23333]
2011-02-28 12:52:38 +00:00
Automatic Updater fb2888c3a5 update 2011-02-28 04:57:11 +00:00
Automatic Updater 081a9dc448 update 2011-02-28 02:16:17 +00:00
Automatic Updater 0f1c24fec6 update copyright notice 2011-02-28 01:19:28 +00:00
Automatic Updater 3ba7bb9664 update 2011-02-28 01:16:26 +00:00
Mark Andrews 92fd5d1b25 elseif -> elsif 2011-02-28 01:08:37 +00:00
Mark Andrews ada7ae72c3 atf source maintains it's own copyright 2011-02-28 01:04:35 +00:00
Automatic Updater cf1ddc33ee update 2011-02-28 00:16:38 +00:00
Automatic Updater 33cd4d9181 update 2011-02-27 14:15:38 +00:00
Mark Andrews 743770f874 only run test if ATFBIN defined 2011-02-27 14:14:41 +00:00
Mark Andrews 33ae0e092b regen 2011-02-27 13:30:33 +00:00
Mark Andrews d89c1b9466 remove space between -L path 2011-02-27 13:27:52 +00:00
Automatic Updater 64bbd43587 update 2011-02-27 10:46:05 +00:00
Automatic Updater f560610eff update 2011-02-27 10:32:26 +00:00
Mark Andrews e0c92f8713 regen 2011-02-27 06:25:03 +00:00
Evan Hunt d7372aa85b one more file needed removing. 2011-02-26 06:15:28 +00:00
Evan Hunt 078cef089c Oops, added and committed files in atf-src after running configure.
Removing all the files that are generated from that.
2011-02-26 06:14:35 +00:00
Evan Hunt de3940d1ea 3043. [test] Merged in the NetBSD ATF test framework (currently
version 0.12) for development of future unit tests.
                        Use configure --with-atf to build ATF internally
                        or configure --with-atf=prefix to use an external
                        copy.  [RT #23209]
2011-02-26 02:48:58 +00:00
Evan Hunt d63b8ea4d0 9.7.3 has shipped; removing the release notes from the cvs tree. 2011-02-25 23:16:10 +00:00
Evan Hunt 4e272d5a1c minor typo 2011-02-25 23:13:30 +00:00
Evan Hunt 720b0c0d51 3042. [bug] dig +trace could fail attempting to use IPv6
addresses on systems with only IPv4 connectivity.
			[RT# 23797]
2011-02-25 23:01:56 +00:00
Mark Andrews 4e3697a06e 3041. [bug] dnssec-signzone failed to generate new signatures on
ttl changes. [RT #23330]
2011-02-24 03:14:37 +00:00
Mark Andrews d1828d831e 3040. [bug] Named failed to validate insecure zones where a node
with a CNAME existed between the trust anchor and the
                        top of the zone. [RT #23338]
2011-02-23 12:08:40 +00:00
Mark Andrews 35949f9ac8 change numbers 2011-02-23 03:56:50 +00:00
Automatic Updater e9755e2570 update 2011-02-22 07:15:38 +00:00
Mark Andrews bd27d0df2b 2037. [doc] Update COPYRIGHT to contain all the individual
copyright notices that cover various parts.
2011-02-22 06:36:35 +00:00
Automatic Updater 4ef5f38576 update 2011-02-22 05:15:27 +00:00
Mark Andrews e009a9de75 2036. [bug] Check built-in zone arguments to see if the zone
is re-usable or not. [RT #21914]
2011-02-22 04:30:46 +00:00
Automatic Updater d967b49681 update 2011-02-22 00:15:52 +00:00
Automatic Updater e0c03c4a8c update copyright notice 2011-02-21 23:46:39 +00:00
Automatic Updater 95194a972c newcopyrights 2011-02-21 23:30:37 +00:00
Automatic Updater 3617d02264 update 2011-02-21 08:15:37 +00:00
Mark Andrews 7c290f0115 3035. [cleanup] Simplify by using strlcpy. [RT #22521] 2011-02-21 07:37:48 +00:00
Mark Andrews 70e4b82cd9 3034. [cleanup] nslookup: use strlcpy instead of safecopy. [RT #22521] 2011-02-21 07:26:53 +00:00
Mark Andrews d1bd7d654f check for snprintf failure. [RT #22521] 2011-02-21 07:17:03 +00:00
Automatic Updater 253ed9c697 update 2011-02-21 07:15:34 +00:00
Mark Andrews 5ce02fb8f5 3033. [cleanup] Add two INSIST(bucket != DNS_ADB_INVALIDBUCKET).
[RT #22521]
2011-02-21 07:11:49 +00:00
Mark Andrews e4cf833007 3032. [bug] rdatalist.c: add missing REQUIREs. [RT #22521] 2011-02-21 07:03:55 +00:00
Mark Andrews 2c352f5b03 3031. [bug] dns_rdataclass_format() handle a zero sized buffer.
[RT #22521]
2011-02-21 06:53:54 +00:00
Mark Andrews 3184f5e1a8 3030. [bug] dns_rdatatype_format() handle a zero sized buffer.
[RT #22521]
2011-02-21 06:44:46 +00:00
Mark Andrews 02bf1aae84 3029. [bug] isc_netaddr_format() handle a zero sized buffer.
[RT #22521]
2011-02-21 06:33:37 +00:00
Mark Andrews cbc7936c23 3028. [bug] isc_sockaddr_format() handle a zero sized buffer.
[RT #22521]
2011-02-21 06:22:34 +00:00
Automatic Updater 5651d4d917 update 2011-02-21 06:15:36 +00:00
Mark Andrews 65e40464b9 3027. [bug] Add documented REQUIREs to cfg_obj_asnetprefix() to
catch NULL pointer dereferences before they happen.
                        [RT #22521]
2011-02-21 06:12:39 +00:00
Mark Andrews f2e926483f 3026. [bug] lib/isc/httpd.c: check that we have enough space
after calling grow_headerspace() and if not
                        re-call grow_headerspace() until we do. [RT #22521]
2011-02-21 05:58:33 +00:00
Automatic Updater 0d50d3b07f update 2011-02-21 00:16:15 +00:00
Mark Andrews d05f92796b spelling 2011-02-21 00:06:20 +00:00
Automatic Updater 2cc17e1b1c update 2011-02-20 01:15:29 +00:00
Mark Andrews 7e1e879d56 spelling 2011-02-20 00:59:30 +00:00
Automatic Updater 1fd69a8213 update 2011-02-20 00:15:59 +00:00
Automatic Updater 7a18159352 update copyright notice 2011-02-19 23:46:55 +00:00
Automatic Updater a364df15a9 newcopyrights 2011-02-19 23:30:35 +00:00
Automatic Updater a9c551e555 update 2011-02-19 02:15:52 +00:00
Evan Hunt 8572954ead Fixed incorrect library link order in libisccc and libisccfg 2011-02-19 01:29:45 +00:00
Evan Hunt 9cf990271f Fixed an error in change 3023, ensuring that journal file isn't
removed after IXFR.  No CHANGES note.
2011-02-19 01:25:30 +00:00
Automatic Updater 346b91444e update 2011-02-19 01:15:28 +00:00
Evan Hunt 87519dfd8f 3025. [bug] Fixed a possible deadlock due to zone resigning.
[RT #22964]
2011-02-19 00:46:45 +00:00
Automatic Updater 0cae8f10b7 update 2011-02-19 00:15:58 +00:00
Automatic Updater 5936aeafed update copyright notice 2011-02-18 23:46:44 +00:00
Automatic Updater e49d73b94b newcopyrights 2011-02-18 23:30:30 +00:00
Automatic Updater 10684df873 regen 2011-02-18 23:30:29 +00:00
Automatic Updater 378dbacd83 update 2011-02-18 22:15:26 +00:00
Evan Hunt 7b4467366d 3023. [bug] Named could be left in an inconsistent state when
receiving multiple AXFR response messages that were
			not all TSIG-signed. [RT #23254]
2011-02-18 21:29:19 +00:00
Automatic Updater 631758bd3a update 2011-02-18 00:16:02 +00:00
Automatic Updater 2ec8ca31c0 update copyright notice 2011-02-17 23:46:21 +00:00
Automatic Updater c3b2b710be update 2011-02-17 05:15:20 +00:00
Mark Andrews 5468d7a070 simplify zone_signwithkey call 2011-02-17 04:58:20 +00:00
Automatic Updater 4d1a4aadbb update 2011-02-17 03:16:18 +00:00
Mark Andrews e754375df7 ensure that the DNSKEY rrset get re-signed even if it hasn't been
updated in sign_apex.
2011-02-17 03:01:19 +00:00
Automatic Updater e4dcfc0e1e update 2011-02-16 20:15:25 +00:00
Evan Hunt a0e5d39d03 3021. [bug] Change #3010 was incomplete. [RT #22296] 2011-02-16 19:44:17 +00:00
Automatic Updater 6b57edb1ab update 2011-02-16 00:16:25 +00:00
Automatic Updater 1b2692a5b9 update copyright notice 2011-02-15 23:46:54 +00:00
Automatic Updater 8c97518725 newcopyrights 2011-02-15 23:30:36 +00:00
Automatic Updater bf79880554 update 2011-02-15 22:15:25 +00:00
Mark Andrews 9e1b196510 3020. [bug] auto-dnssec failed to correctly update the zone when
changing the DNSKEY RRset. [RT #23232]
2011-02-15 22:09:36 +00:00
Automatic Updater d006ab34d2 update 2011-02-15 06:15:26 +00:00
Mark Andrews f02cc38da0 undo commits to wrong branch 2011-02-15 05:40:16 +00:00
Automatic Updater 21996d3904 update 2011-02-15 05:15:21 +00:00
Mark Andrews dace425c59 add NSEC/NSEC3 chains 2011-02-15 04:32:53 +00:00
Automatic Updater aae4d811bc update 2011-02-15 04:15:46 +00:00
Mark Andrews d5e086f492 sign all changed rrsets 2011-02-15 03:55:55 +00:00
Automatic Updater b456d81fba update 2011-02-15 00:15:45 +00:00
Mark Andrews 7734aca6a1 3019. [func] Test: check apex NSEC3 records after adding DNSKEY
record via UPDATE. [RT #23229]
2011-02-15 00:03:03 +00:00
Evan Hunt 92442341b6 file unittest.sh was added on branch v9_7 on 2011-02-26 02:47:55 +0000 2011-02-11 04:19:17 +00:00
Automatic Updater 44f8595983 update 2011-02-08 23:17:04 +00:00
Automatic Updater 0321a1fd00 update copyright notice 2011-02-08 23:09:24 +00:00
Automatic Updater 17db42659c newcopyrights 2011-02-08 23:07:04 +00:00
Automatic Updater 6af1573bdb update 2011-02-08 04:15:41 +00:00
Mark Andrews 5bf955196b Regression test for:
3018.   [bug]           Named failed to check for the "none;" acl when deciding
                        if a zone may need to be re-signed. [RT #23120]
2011-02-08 04:06:54 +00:00
Automatic Updater 3cc252d992 update 2011-02-08 03:16:19 +00:00
Automatic Updater ca193080b8 9.7.3 2011-02-08 02:45:30 +00:00
Automatic Updater 8bc362cc47 update 2011-02-08 02:16:05 +00:00
Mark Andrews db23bb6075 9.7.3 2011-02-08 01:25:04 +00:00
Automatic Updater 3e277745be update 2011-02-07 13:16:02 +00:00
Mark Andrews 8e76a261e4 missing [ 2011-02-07 12:25:17 +00:00
Mark Andrews efbab336ac re-tag 9.7.3 2011-02-07 12:18:47 +00:00
Automatic Updater fa253950d9 update 2011-02-07 01:15:27 +00:00
Mark Andrews bc7aed2a6b 3018. [bug] Named failed to check for the "none;" acl when deciding
if a zone may need to be re-signed. RT #23120]
2011-02-07 00:16:48 +00:00
Automatic Updater 0b034daf8e update 2011-02-04 02:16:06 +00:00
Automatic Updater eb19518256 regen v9_7 2011-02-04 02:10:43 +00:00
Automatic Updater efdac14a77 update 2011-02-03 17:15:22 +00:00
Evan Hunt af17ccb8e5 Updated release notes. 2011-02-03 16:23:59 +00:00
Automatic Updater 8b9d13a3c1 update 2011-02-03 13:16:06 +00:00
Automatic Updater 8ce32752e6 update copyright notice 2011-02-03 12:17:23 +00:00
Automatic Updater 7c644b7bf5 newcopyrights 2011-02-03 12:15:18 +00:00
Mark Andrews f2af5e6496 3017. [doc] dnssec-keyfromlabel -I was not properly documented.
[RT #22887]
2011-02-03 12:03:09 +00:00
Mark Andrews 5c64e82dd6 3016. [bug] rndc usage missing '-b'. [RT #22937] 2011-02-03 11:49:00 +00:00
Automatic Updater 7644620ee7 update 2011-02-03 09:15:32 +00:00
Mark Andrews 7c051497fa 3015. [port] win32: fix IN6_IS_ADDR_LINKLOCAL and
IN6_IS_ADDR_SITELOCAL macros. [RT #22724]
2011-02-03 08:18:01 +00:00
Automatic Updater c58e05413c update 2011-02-03 07:15:26 +00:00
Mark Andrews 94d633f808 3012. [bug] Remove DNSKEY TTL change pairs before generating
signing records for any remaining DNSKEY changes.
                        [RT #22590]
2011-02-03 06:25:58 +00:00
Automatic Updater 3524472293 update 2011-02-03 05:39:54 +00:00
Automatic Updater 2dec8208b9 update copyright notice 2011-02-03 05:38:10 +00:00
Mark Andrews e0cb2d799b retag 9.7.3 2011-02-03 05:33:21 +00:00
Automatic Updater 2e977649df update 2011-02-03 05:16:35 +00:00
Automatic Updater e33315f886 newcopyrights 2011-02-03 05:14:00 +00:00
Automatic Updater b628c1221e update 2011-02-03 01:15:20 +00:00
Evan Hunt 24a73837dd 3010. [bug] Fixed a bug where "rndc reconfig" stopped the timer
for refreshing managed-keys. [RT #22296]
2011-02-03 00:28:08 +00:00
Automatic Updater d165d9ba2d update 2011-01-31 03:23:34 +00:00
Automatic Updater 7e10c4f8c5 newcopyrights 2011-01-31 03:19:27 +00:00
Automatic Updater 70725073a9 update 2011-01-31 03:16:43 +00:00
Automatic Updater 690d5cd519 9.7.3 2011-01-31 03:15:11 +00:00
Automatic Updater f7bf1751e5 newcopyrights 2011-01-31 02:43:48 +00:00
Automatic Updater e638dbf10c update 2011-01-31 02:15:50 +00:00
Automatic Updater b0c5373e6c regen v9_7 2011-01-31 02:10:42 +00:00
Automatic Updater e3201af06f update copyright notice 2011-01-31 01:35:20 +00:00
Automatic Updater b4fa6115f0 update 2011-01-31 00:16:07 +00:00
Automatic Updater 3d2f774d23 update 2011-01-31 00:01:00 +00:00
Automatic Updater dbc8f28aa4 update 2011-01-30 09:15:22 +00:00
Mark Andrews 9937ce8e73 spelling 2011-01-30 08:19:46 +00:00
Automatic Updater 50f29e14b4 update 2011-01-30 08:15:25 +00:00
Mark Andrews b5251afe9b 9.7.3 2011-01-30 08:11:25 +00:00
Mark Andrews 7726fff532 9.7.3 2011-01-30 08:01:01 +00:00
Automatic Updater 955ee4992d update 2011-01-28 00:15:53 +00:00
Automatic Updater 1fd0d83a38 update copyright notice 2011-01-27 23:46:37 +00:00
Automatic Updater 1ac91b4140 newcopyrights 2011-01-27 23:30:36 +00:00
Automatic Updater f5199566db update 2011-01-27 03:16:26 +00:00
Mark Andrews a244965075 3009. [bug] clients-per-query code didn't work as expected with
particular query patterns. [RT #22972]
2011-01-27 02:28:54 +00:00
Automatic Updater 7bc44cccc1 update 2011-01-14 01:15:54 +00:00
Automatic Updater bdea0ea015 update copyright notice 2011-01-14 00:51:07 +00:00
Automatic Updater 2109456871 newcopyrights 2011-01-14 00:49:30 +00:00
Mark Andrews 03fbf41ea8 silence: warning: format not a string literal and no format arguments 2011-01-14 00:43:43 +00:00
Automatic Updater f76bf38ff6 update 2011-01-14 00:15:38 +00:00
Automatic Updater 8f89bb0c54 newcopyrights 2011-01-14 00:12:06 +00:00
Mark Andrews 0fc328e58e 9.7.3rc1 2011-01-14 00:09:38 +00:00
Automatic Updater d97a30ec77 update 2011-01-13 23:16:17 +00:00
Automatic Updater f0cd6e4f2c update copyright notice 2011-01-13 22:30:17 +00:00
Automatic Updater ba91cab8d2 newcopyrights 2011-01-13 22:28:39 +00:00
Mark Andrews a14975ce0c update for 9.7.3rc1 2011-01-13 22:24:41 +00:00
Mark Andrews 54a51ed666 9.7.3rc1 2011-01-13 22:21:21 +00:00
Automatic Updater 1e6579f325 update 2011-01-13 22:15:26 +00:00
Mark Andrews c74524f856 remove /I "../..../lib/dns/sec/openssl/include" 2011-01-13 22:12:52 +00:00
Mark Andrews db90edaeaa -V support 2011-01-13 22:00:35 +00:00
Automatic Updater 1eacb4b9e4 update 2011-01-13 05:16:13 +00:00
Automatic Updater 3c2e0ad5b3 update copyright notice 2011-01-13 04:48:58 +00:00
Automatic Updater 00e2b9d750 newcopyrights 2011-01-13 04:47:01 +00:00
Automatic Updater 032bed7f96 update 2011-01-13 03:15:54 +00:00
Mark Andrews 9c2f4c2fdc spelling 2011-01-13 02:39:33 +00:00
Automatic Updater 6d12a64fe5 update 2011-01-13 02:16:02 +00:00
Mark Andrews 76be4e69ee 3007. [bug] Named failed to preserve the case of domain names in
rdata which is no compressable when writing master
                        files.  [RT #22863]
2011-01-13 01:34:41 +00:00
Automatic Updater 3f4f076701 update 2011-01-08 00:15:55 +00:00
Automatic Updater 74d29b18ad update copyright notice 2011-01-07 23:46:36 +00:00
Automatic Updater 303fd2fb85 newcopyrights 2011-01-07 23:30:26 +00:00
Automatic Updater b656ab5ead update 2011-01-07 01:15:17 +00:00
Evan Hunt 3207a16d0d Initialize a pointer to NULL in order to silence a compiler warning.
Committing without review because the change is trivial.
2011-01-07 00:53:18 +00:00
Automatic Updater c097e59568 update 2011-01-06 00:16:07 +00:00
Automatic Updater 29e5061922 newcopyrights 2011-01-05 23:30:37 +00:00
Automatic Updater 71155af8fc update 2011-01-05 00:15:53 +00:00
Automatic Updater a0ad3116d2 update copyright notice 2011-01-04 23:46:31 +00:00
Automatic Updater 60774ae636 newcopyrights 2011-01-04 23:30:33 +00:00
Automatic Updater 7ee7aa860b regen 2011-01-04 23:30:32 +00:00
Automatic Updater a94f717d71 update 2011-01-04 19:15:21 +00:00
Evan Hunt 2bf23735a3 Updated comments, added root key (for informational purposes, not for
direct use by named). [rt21727]
2011-01-04 19:14:48 +00:00
Automatic Updater b11c4861bb update 2011-01-04 05:15:25 +00:00
Mark Andrews 3918f862a0 3002. [bug] isc_mutex_init_errcheck() failed to destroy attr.
[RT #22766]
2011-01-04 04:34:43 +00:00
Automatic Updater ecc25fbd15 update 2010-12-22 04:16:15 +00:00
Mark Andrews 28f47481cc 2996. [security] Temporarily disable SO_ACCEPTFILTER support.
[RT #22589]
2010-12-22 03:27:22 +00:00
Automatic Updater ecb78c1a40 update 2010-12-22 03:15:55 +00:00
Mark Andrews 7d2b1dfede 2995. [bug] The Kerberos realm was not being correctly extracted
from the signer's identity. [RT #22770]
2010-12-22 02:36:17 +00:00
Automatic Updater 310390c8b8 update 2010-12-22 00:16:13 +00:00
Automatic Updater 54b0110b75 newcopyrights 2010-12-21 23:30:23 +00:00
Automatic Updater 6de9bf2601 update 2010-12-21 05:15:30 +00:00
Mark Andrews 0f8ca600f1 regen 2010-12-21 04:33:28 +00:00
Mark Andrews c151a9588b 2994. [port] NetBSD: use pthreads by default on NetBSD >= 5.0, and
do not use threads on earlier versions.  Also kill
                        the unproven-pthreads, mit-pthreads, and ptl2 support.
2010-12-21 04:30:15 +00:00
Automatic Updater 4a83846ddd update 2010-12-19 08:15:18 +00:00
Evan Hunt 83c70e073b 2990. [bug] 'dnssec-settime -S' no longer tests prepublication
interval validity when the interval is set to 0.
			[RT #22761]
2010-12-19 07:27:50 +00:00
Evan Hunt 92f198ef9d When prepublication interval is set to 0 (-i 0), don't check 2010-12-19 07:27:23 +00:00
Automatic Updater 07b49d7453 update 2010-12-18 03:16:18 +00:00
Evan Hunt a8c55a41d5 Added files to clean.sh scripts that have been left around after tests run.
Skipping the ticket/review steps because the change is trivial.
2010-12-18 02:15:17 +00:00
Automatic Updater 38c6c10ac9 update 2010-12-15 19:15:18 +00:00
Evan Hunt 23ae36911c 2985. [bug] Add a regression test for change #2896. [RT #21324] 2010-12-15 18:44:16 +00:00
Automatic Updater b7055d7988 update 2010-12-14 01:15:21 +00:00
Mark Andrews 48e7dcf0d2 2984. [bug] Don't run MX checks when the target of the MX record
is ".".  [RT #22645]
2010-12-14 00:46:41 +00:00
Automatic Updater f4a29a0750 update 2010-12-10 20:15:22 +00:00
johnd 6d6a3a820a Include "loadkeys" in rndc help output. [RT #22493] 2010-12-10 20:08:07 +00:00
Automatic Updater 5c82ca42b3 update 2010-12-10 05:15:54 +00:00
Mark Andrews 465d41bd1c remove semi-colon 2010-12-10 04:47:48 +00:00
Automatic Updater 7ea5188c2d newcopyrights 2010-12-10 04:17:16 +00:00
Automatic Updater 8ab0fa49c7 update 2010-12-10 02:15:24 +00:00
Mark Andrews 59dbcb0b0a 9.7.3b1 2010-12-10 01:49:33 +00:00
Mark Andrews 774cbd433a 9.7.3b1 2010-12-10 01:40:23 +00:00
Mark Andrews 5addd0b6cd 9.7.3b1 2010-12-10 01:23:06 +00:00
Automatic Updater 87ebc102ad update 2010-12-09 12:15:20 +00:00
Mark Andrews 093dc899d3 9.7.3b1 2010-12-09 11:48:55 +00:00
Mark Andrews b5b9469b27 CHANGES 2010-12-09 11:48:17 +00:00
Mark Andrews 390213c7e4 s/dev/adev/ 2010-12-09 11:41:11 +00:00
Automatic Updater 23f81e6d93 update 2010-12-09 08:15:45 +00:00
Mark Andrews 7035aa0ee2 dst_key_attach 2010-12-09 07:56:12 +00:00
Automatic Updater b27e8b331c update 2010-12-09 05:16:07 +00:00
Automatic Updater 9164ae2297 update copyright notice 2010-12-09 04:31:30 +00:00
Automatic Updater b972f8e3a2 newcopyrights 2010-12-09 04:29:46 +00:00
Automatic Updater 388eb181d6 update 2010-12-09 01:15:22 +00:00
Mark Andrews 93b433d299 2982. [bug] Reference count dst keys. dst_key_attach() can be used
increment the reference count.

                        Note: dns_tsigkey_createfromkey() callers should now
                        always call dst_key_free() rather than setting it
                        to NULL on success. [RT #22672]
2010-12-09 01:05:29 +00:00
Automatic Updater 8f541851f4 update 2010-12-08 00:15:51 +00:00
Automatic Updater 39ba8c7737 update copyright notice 2010-12-07 23:46:26 +00:00
Automatic Updater 3892831333 newcopyrights 2010-12-07 23:30:28 +00:00
Automatic Updater 4409333f34 update 2010-12-07 03:15:56 +00:00
Mark Andrews e69bed0b94 2980. [bug] named didn't properly handle UPDATES that changed the
TTL of the NSEC3PARAM RRset. [RT #22363]
2010-12-07 03:01:40 +00:00
Automatic Updater a1c04a4f16 update 2010-12-05 21:15:23 +00:00
Mark Andrews 4dc228da3d isc__task_exiting -> isc_task_exiting 2010-12-05 20:29:24 +00:00
Automatic Updater f3e8fd8e4a update 2010-12-04 14:15:21 +00:00
Mark Andrews 4bcdedcf07 temporally make isc__task_exiting become isc_task_exiting so that the
export version of libisc has all the symbols to link.
2010-12-04 13:27:10 +00:00
Automatic Updater 8a5c01f19e update 2010-12-04 00:16:12 +00:00
Automatic Updater e6aee23f88 update copyright notice 2010-12-03 23:46:20 +00:00
Automatic Updater ac84e86dd8 newcopyrights 2010-12-03 23:30:48 +00:00
Automatic Updater e652cd7642 update 2010-12-03 22:15:26 +00:00
Evan Hunt b1627aebb8 2979. [bug] named could deadlock during shutdown if two
"rndc stop" commands were issued at the same
			time. [RT #22108]
2010-12-03 22:04:49 +00:00
Mark Andrews c35cd8f3a0 pass the address of dstkey 2010-12-03 21:48:11 +00:00
Automatic Updater 2cb64871bb update 2010-12-03 12:15:18 +00:00
Mark Andrews d41b478b81 s/dns_key_free/dst_key_free/ 2010-12-03 12:04:24 +00:00
Automatic Updater 00eb58ff9c update 2010-12-03 01:15:28 +00:00
Mark Andrews a783af3e86 2978. [port] hpux: look for <devpoll.h> [RT #21919] 2010-12-03 00:59:20 +00:00
Mark Andrews a4aef00d65 2977. [bug] 'nsupdate -l' report if the session key is missing.
[RT #21670]
2010-12-03 00:39:46 +00:00
Mark Andrews 6db4de888e remove CVSS scores 2010-12-03 00:30:53 +00:00
Automatic Updater 5480ae18d3 update 2010-12-03 00:15:58 +00:00
Mark Andrews 853a83725f update RT number 2010-12-03 00:11:17 +00:00
Automatic Updater 1517558cd3 update copyright notice 2010-12-02 23:46:30 +00:00
Mark Andrews d6b3b3507f update 2976 description 2010-12-02 23:43:25 +00:00
Automatic Updater ffb4d9e0ba newcopyrights 2010-12-02 23:30:36 +00:00
Mark Andrews e7ca8c91ec 2976. [bug] named die on exit after negotiating a GSS-TSIG key.
[RT #3415]
2010-12-02 23:26:58 +00:00
Automatic Updater da92bed4d5 update 2010-12-02 05:16:11 +00:00
Mark Andrews 7f2d8ae5da 2975. [bug] rbtdb.c:cleanup_dead_nodes_callback() aquired the
wrong lock which could lead to server deadlock.
                        [RT #22614]
2010-12-02 05:07:03 +00:00
Automatic Updater 13a08d776f update 2010-12-01 00:15:49 +00:00
Automatic Updater 14f8d8220c update copyright notice 2010-11-30 23:46:15 +00:00
Automatic Updater 3aa81ceb1c newcopyrights 2010-11-30 23:30:29 +00:00
Automatic Updater 7a86f936b8 update 2010-11-30 03:16:07 +00:00
Evan Hunt f72883c6ae 2974. [bug] Some vaild UPDATE requests could fail due to a
consistency check examining the existing version
			of the zone rather than the new version resulting
			from the UPDATE. [RT #22413]
2010-11-30 02:27:38 +00:00
Mark Andrews e9c45e3dbf file release-notes.css was added on branch v9_7 on 2011-05-24 00:26:44 +0000 2010-11-29 00:41:05 +00:00
Automatic Updater 0c97e821ee update 2010-11-25 05:15:39 +00:00
Mark Andrews d27cd59a97 CVE-2010-3613 Reduce complexity from M to L raising score from 7.1 to 7.8.
Just have the base CVSS vectors.
2010-11-25 04:48:54 +00:00
Automatic Updater 9eea2d2964 update 2010-11-19 00:16:13 +00:00
Mark Andrews 1f897c49f1 2973. [bug] bind.keys.h was being removed by the "make clean"
at the end of configure resulting in build failures
                        where there is very old version of perl installed.
                        Move it to "make maintainer-clean". [RT #22230]
2010-11-18 23:22:45 +00:00
Automatic Updater 0676d1377a update 2010-11-18 03:16:16 +00:00
Mark Andrews c1a94681f2 add CVE, VU and CVSS 2010-11-18 02:50:46 +00:00
Automatic Updater 6539c8dd1b update 2010-11-18 01:16:18 +00:00
Automatic Updater 2dbcb34643 update copyright notice 2010-11-18 00:59:15 +00:00
Mark Andrews e013e99c1c 2972. [bug] win32: address windows socket errors. [RT #21906] 2010-11-18 00:29:02 +00:00
Automatic Updater 46f6e09b51 update 2010-11-18 00:15:54 +00:00
Automatic Updater 97c708294d update copyright notice 2010-11-17 23:46:32 +00:00
Automatic Updater d77da4225c newcopyrights 2010-11-17 23:30:25 +00:00
Automatic Updater 3e612906f4 update 2010-11-17 04:16:03 +00:00
Mark Andrews 636785e7eb handle namedxx.conf 2010-11-17 03:17:24 +00:00
Automatic Updater 7afdd95114 update 2010-11-17 01:15:29 +00:00
Evan Hunt a53c04f050 2971. [bug] Fixed a bug that caused journal files not to be
compacted on Windows systems as a result of
			non-POSIX-compliant rename() semantics. [RT #22434]
2010-11-17 00:29:31 +00:00
Automatic Updater 5165085bfb update 2010-11-17 00:15:53 +00:00
Automatic Updater 2d77ffe6bb update 2010-11-16 08:15:31 +00:00
Mark Andrews 8f110ca521 2970. [security] Adding a NO DATA negative cache entry failed to clear
any matching RRSIG records.  A subsequent lookup of
                        of NO DATA cache entry could trigger a INSIST when the
                        unexpected RRSIG was also returned with the NO DATA
                        cache entry.  [RT #22288]
2010-11-16 07:28:37 +00:00
Automatic Updater 944f9271ac update 2010-11-16 02:16:10 +00:00
Shawn Routhier 75636f9b01 Fix acl type processing so that allow-query works in options and view
statements.  Also add a new set of tests to verify proper functioning.
[RT #22418]
2010-11-16 02:11:53 +00:00
Mark Andrews 8bdc865433 2968. [security] Named could fail to prove a data set was insecure
before marking it as insecure.  One set of conditions
                        that can trigger this occurs naturally when rolling
                        DNSKEY algorithms.  [RT #22309]
2010-11-16 01:21:49 +00:00
Automatic Updater 383ca63dee update 2010-11-11 03:16:11 +00:00
Automatic Updater 5465641352 sync 2010-11-11 02:27:46 +00:00
Automatic Updater 2464e106df update 2010-10-20 00:15:53 +00:00
Automatic Updater e8bff09ffb update copyright notice 2010-10-19 23:46:47 +00:00
Automatic Updater ae1a01ff3d newcopyrights 2010-10-19 23:30:29 +00:00
Automatic Updater bc2014dbbe update 2010-10-19 03:15:50 +00:00
Mark Andrews feb6270d6f 2967. [bug] 'host -D' now turns on debugging messages earlier.
[RT #22361]
2010-10-19 02:54:48 +00:00
Automatic Updater c209a20108 update 2010-10-19 00:16:22 +00:00
Automatic Updater 913562f0d3 update copyright notice 2010-10-18 23:46:48 +00:00
Automatic Updater ebfeba4f78 newcopyrights 2010-10-18 23:30:26 +00:00
Automatic Updater a9a62db641 update 2010-10-18 04:16:19 +00:00
Mark Andrews 4161a9a0e5 2966. [bug] isc_print_vsnprintf() failed to check if there was
space available in the buffer when adding a left
                        justified character with a non zero width,
                        (e.g. "%-1c"). [RT #22270]
2010-10-18 04:01:06 +00:00
Automatic Updater 795b23217b update 2010-10-04 23:15:21 +00:00
Mark Andrews 49f7dba060 silence 'Null terminator in string initializer ignored.' warning 2010-10-04 22:25:25 +00:00
Automatic Updater 93f3b0ddba update 2010-10-03 03:16:09 +00:00
Automatic Updater 9822caa29b sync 2010-10-03 02:27:38 +00:00
Automatic Updater 47edbd3c53 update 2010-09-30 00:15:52 +00:00
Automatic Updater fd56caffe6 update copyright notice 2010-09-29 23:46:44 +00:00
Automatic Updater 76365d5f86 newcopyrights 2010-09-29 23:30:29 +00:00
Automatic Updater 409886d852 update 2010-09-29 05:16:05 +00:00
Mark Andrews f225d11b53 #include <isc/print.h> 2010-09-29 04:29:16 +00:00
Automatic Updater 553a2acba8 update 2010-09-29 04:17:35 +00:00
Mark Andrews affc5a912e 2965. [func] Test HMAC functions using test data from RFC 2104 and
RFC 4634. [RT #21702]
2010-09-29 04:07:10 +00:00
Automatic Updater 309173748f update 2010-09-24 09:15:50 +00:00
Automatic Updater a78ef43fe3 update copyright notice 2010-09-24 08:30:58 +00:00
Automatic Updater dc856c0bcf newcopyrights 2010-09-24 08:27:59 +00:00
Automatic Updater b74a3907a5 update 2010-09-24 06:15:23 +00:00
Mark Andrews 0a2897853b 2963. [security] The allow-query acl was being applied instead of the
allow-query-cache acl to cache lookups. [RT #22114]
2010-09-24 05:54:06 +00:00
Automatic Updater 444d3d9f97 update 2010-09-17 05:15:23 +00:00
Mark Andrews 177931360d spelling 2010-09-17 04:55:50 +00:00
Automatic Updater d356572dda update 2010-09-16 06:15:22 +00:00
Mark Andrews ce5fc01c92 2962. [port] win32: add more dependancies to BINDBuild.dsw.
[RT #22062]
2010-09-16 06:11:43 +00:00
Automatic Updater daf3551b86 update 2010-09-15 23:30:14 +00:00
Mark Andrews 9960be0a54 simplify grep 2010-09-15 23:23:22 +00:00
Automatic Updater 5a16eacf6f update 2010-09-15 16:15:25 +00:00
Evan Hunt b1a6907e81 The "resolver" test was failing on systems with old versions of "grep". 2010-09-15 15:45:16 +00:00
Automatic Updater 9f5cecf887 update 2010-09-15 12:50:12 +00:00
Automatic Updater 6d7a4c30a2 update copyright notice 2010-09-15 12:38:04 +00:00
Automatic Updater fdf81716b4 newcopyrights 2010-09-15 12:33:53 +00:00
Mark Andrews e69b2928cf ./bin/tests/system/resolver/ns4/named.noaa 2010-09-15 12:31:40 +00:00
Mark Andrews 1872751420 2961. [bug] Be still more selective about the non-authoritative
answers we apply change 2748 to. [RT #22074]
2010-09-15 12:23:17 +00:00
Automatic Updater 355ac59256 update 2010-09-15 12:15:22 +00:00
Mark Andrews 3f9371b30c 2960. [func] Check that named accepts non-authoritative answers.
[RT #21594]
2010-09-15 12:10:54 +00:00
Automatic Updater 5557ac8a6f update 2010-09-15 04:16:06 +00:00
Mark Andrews 311f97e2d4 2959. [func] Check that named starts with a missing masterfile.
[RT #22076]

2958.   [bug]           named failed to start with a missing master file.
                        [RT #22076]
2010-09-15 03:36:41 +00:00
Mark Andrews fea199b0ce 2957. [bug] entropy_get() and entropy_getpseudo() failed to match
the API for RAND_bytes() and RAND_pseudo_bytes()
                        respectively. [RT #21962]
2010-09-15 03:20:37 +00:00
Automatic Updater 623d40c98e update 2010-09-14 00:15:43 +00:00
Automatic Updater d3b9504e44 newcopyrights 2010-09-13 23:30:24 +00:00
Mark Andrews 910ceb6004 2928. [bug] Be more selective about the non-authoritative
answer we apply change 2748 to. [RT #21594]
2010-09-13 23:25:22 +00:00
Automatic Updater e5052c8526 update 2010-09-13 07:15:20 +00:00
Mark Andrews 81537dce5b 2956. [port] Enable atomic operations on the PowerPC64. [RT #21899] 2010-09-13 07:09:52 +00:00
Mark Andrews 933b976829 2956. [port] Enable atomic operations on the PowerPC64. [RT #21899] 2010-09-13 07:09:21 +00:00
Automatic Updater d46865e1e9 update 2010-09-13 04:15:49 +00:00
Mark Andrews 91f92550dc 2954. [bug] contrib: dlz_mysql_driver.c bad error handling on
build_sqldbinstance failure. [RT #21623]
2010-09-13 03:30:30 +00:00
Automatic Updater da68f57b1c update 2010-09-08 00:16:10 +00:00
Automatic Updater 68d2587454 update copyright notice 2010-09-07 23:46:37 +00:00
Automatic Updater 738c82a017 newcopyrights 2010-09-07 23:30:29 +00:00
Automatic Updater ff1a145792 update 2010-09-07 03:16:07 +00:00
Mark Andrews ad8fd9b034 2953. [bug] Silence spurious "expected covering NSEC3, got an
exact match" message when returning a wildcard
                        no data response. [RT #21744]
2010-09-07 02:52:10 +00:00
Automatic Updater 76d886a4e3 update 2010-09-07 02:15:48 +00:00
Mark Andrews 26c738828f 2952. [port] win32: named-checkzone and named-checkconf failed
to initialise winsock. [RT #21932]
2010-09-07 01:52:22 +00:00
Automatic Updater 6f15e1a200 update 2010-09-07 01:15:21 +00:00
Mark Andrews 1cbe92ed8c 2951. [bug] named failed to generate a correct signed response
in a optout, delegation only zone with no secure
                        delegations. [RT #22007]
2010-09-07 01:05:59 +00:00
Automatic Updater 430cc35151 update 2010-09-06 05:15:38 +00:00
Mark Andrews 6ee56d59da 2950. [bug] named failed to perform a SOA up to date check when
falling back to TCP on UDP timeouts when
                        ixfr-from-differences was set. [RT #21595]
2010-09-06 04:43:08 +00:00
Mark Andrews ed09ec058a 2949. [bug] dns_view_setnewzones() contained a memory leak if
it was called multiple times. [RT #21942]
2010-09-06 04:34:03 +00:00
Automatic Updater 6b524e41e5 update 2010-09-02 04:15:35 +00:00
Automatic Updater dc797e5833 9.7.2 2010-09-02 03:39:12 +00:00
Mark Andrews dafa96c13e 9.7.2 2010-09-02 03:36:10 +00:00
Automatic Updater 448b6882f6 update 2010-08-26 02:15:16 +00:00
Mark Andrews 14d41c9db7 update 2010-08-26 02:14:45 +00:00
Automatic Updater 2ba7551844 update 2010-08-25 02:15:14 +00:00
Mark Andrews 36e7d4808c cleanup 2010-08-25 01:23:23 +00:00
Automatic Updater 4ebc7953b1 update 2010-08-25 01:15:15 +00:00
Mark Andrews 5a51c60f58 update 2010-08-25 01:11:44 +00:00
Automatic Updater 0cdec93645 update 2010-08-24 01:15:14 +00:00
Mark Andrews 14dfb38385 silence signed/unsigned warning hpux 2010-08-24 01:01:45 +00:00
Automatic Updater 06201ee79d update 2010-08-20 03:15:49 +00:00
Automatic Updater 67a781e65c regen v9_7 2010-08-20 02:40:26 +00:00
Automatic Updater 696be5b2ee update 2010-08-20 02:15:19 +00:00
Mark Andrews 2ca6b13626 2946. [doc] Document the default values for the minimum and maximum
zone refresh and retry values in the ARM. [RT #21886]
2010-08-20 01:36:45 +00:00
Automatic Updater 845eb1f0ed update 2010-08-20 01:15:26 +00:00
Mark Andrews 8c19a64364 2945. [doc] Update empty-zones list in ARM. [RT #21772]
2944.   [maint]         Remove ORCHID prefix from built in empty zones.
                        [RT #21772]
2010-08-20 00:17:40 +00:00
Automatic Updater a2f7b8a534 update 2010-08-18 00:15:58 +00:00
Automatic Updater 63b93f0682 update copyright notice 2010-08-17 23:46:28 +00:00
Automatic Updater cd7d1b6d68 newcopyrights 2010-08-17 23:30:39 +00:00
Automatic Updater bea9285506 update 2010-08-17 04:16:00 +00:00
Mark Andrews 82580033db update default id range to match that used (1..7) 2010-08-17 04:08:07 +00:00
Automatic Updater 20990845d8 update 2010-08-17 02:15:16 +00:00
Mark Andrews 704e4daff8 dns_view_setnewzones 2010-08-17 01:21:07 +00:00
Automatic Updater 98a3748577 update 2010-08-17 01:15:15 +00:00
Mark Andrews 4e5d7e4fff 9.7.2rc1 2010-08-17 00:58:57 +00:00
Automatic Updater 5db09e69de 9.7.2rc1 2010-08-17 00:53:41 +00:00
Mark Andrews b45ded3b33 9.7.2rc1 2010-08-17 00:51:33 +00:00
Automatic Updater 93472ba538 update 2010-08-17 00:15:38 +00:00
Automatic Updater 0a583f82eb regen v9_7 2010-08-17 00:08:26 +00:00
Automatic Updater 5d98af56f2 update copyright notice 2010-08-16 23:46:31 +00:00
Automatic Updater 65f2bd61ae newcopyrights 2010-08-16 23:30:36 +00:00
Automatic Updater 91a8c60f0e update 2010-08-16 23:15:19 +00:00
Mark Andrews 4facc02671 2940. [port] Remove connection aborted error message on
Windows. [RT #21549]
2010-08-16 22:55:17 +00:00
Mark Andrews 05ceebcb1b silence redefinition warnings MacOS 2010-08-16 22:39:36 +00:00
Mark Andrews 30579c29be 2943. [func] Add support to load new keys into managed zones
without signing immediately with "rndc loadkeys".
                        Add support to link keys with "dnssec-keygen -S"
                        and "dnssec-settime -S".  [RT #21351]
2010-08-16 22:27:18 +00:00
Automatic Updater d7c212118e update 2010-08-16 06:15:19 +00:00
Mark Andrews 4d5ef757af 2942. [contrib] zone2sqlite failed to setup the entropy sources.
[RT #21610]
2010-08-16 05:36:08 +00:00
Automatic Updater 42783352fc update 2010-08-16 05:15:16 +00:00
Mark Andrews ff2047b685 2941. [bug] sdb and sdlz (dlz's zone database) failed to support
DNAME at the zone apex.  [RT #21610]
2010-08-16 05:14:58 +00:00
Automatic Updater b16a1e6c07 update 2010-08-14 00:15:33 +00:00
Automatic Updater 770279e013 update copyright notice 2010-08-13 23:46:29 +00:00
Automatic Updater 1ab0c02604 newcopyrights 2010-08-13 23:30:50 +00:00
Automatic Updater 61ed35e09c update 2010-08-13 08:15:17 +00:00
Mark Andrews fe359f7a21 2939. [func] Check that named successfully skips NSEC3 records
that fail to match the NSEC3PARAM record currently
                        in use. [RT# 21868]
2010-08-13 07:35:04 +00:00
Automatic Updater f2080c6915 update 2010-08-13 07:15:15 +00:00
Mark Andrews 71e5c19636 2938. [bug] When generating signed responses, from a signed zone
that uses NSEC3, named would use a uninitialised
                        pointer if it needed to skip a NSEC3 record because
                        it didn't match the selected NSEC3PARAM record for
                        zone. [RT# 21868]
2010-08-13 07:00:40 +00:00
Automatic Updater 188bd721a5 update 2010-08-13 04:15:20 +00:00
Mark Andrews 50874e9ec7 ./bin/tests/system/addzone/ns2/default.nzf.in 2010-08-13 03:34:59 +00:00
Automatic Updater 4eef79de8a update 2010-08-13 03:15:44 +00:00
Automatic Updater 38113dbdb1 sync 2010-08-13 02:28:42 +00:00
Automatic Updater db77363f8c update 2010-08-13 00:15:47 +00:00
Automatic Updater 085c5a5d9b update 2010-08-12 22:15:14 +00:00
Tatuya JINMEI 神明達哉 97e69e38a6 define the wrapper function for mem_isovermem().
(a regression in rt21818)
2010-08-12 21:31:33 +00:00
Automatic Updater 95787a5532 update 2010-08-12 04:15:27 +00:00
Evan Hunt 289fd68776 Removed a leftover UNUSED statement referencing a parameter that doesn't
exist anymore.
2010-08-12 04:04:34 +00:00
Automatic Updater b1b6267a8a update 2010-08-12 03:15:33 +00:00
Automatic Updater 50b789e229 regen v9_7 2010-08-12 02:41:36 +00:00
Automatic Updater c0c9f5afd6 update 2010-08-12 02:15:14 +00:00
Mark Andrews ed4eee1e51 .orig -> .in as .orig is used by patch 2010-08-12 01:32:46 +00:00
Automatic Updater 1f802e5618 update 2010-08-12 00:15:50 +00:00
Automatic Updater a64888719c update copyright notice 2010-08-11 23:46:20 +00:00
Automatic Updater 971a043b47 update 2010-08-11 23:15:22 +00:00
Tatuya JINMEI 神明達哉 8c3613e29f required ctx is valid in mem_isovermem(). 2010-08-11 23:10:24 +00:00
Tatuya JINMEI 神明達哉 879dcb926c 2937. [bug] Worked around an apparent race condition in over
memory conditions.  Without this fix a DNS cache DB or
			ADB could incorrectly stay in an over memory state,
			effectively refusing further caching, which
			subsequently made a BIND 9 caching server unworkable.
			This fix prevents this problem from happening by
			polling the state of the memory context, rather than
			making a copy of the state, which appeared to cause
			a race.  This is a "workaround" in that it doesn't
			solve the possible race per se, but several experiments
			proved this change solves the symptom.  Also, the
			polling overhead hasn't been reported to be an issue.
			This bug should only affect a caching server that
			specifies a finite max-cache-size.  It's also quite
			likely that the bug happens only when enabling threads,
			but it's not confirmed yet. [RT #21818]
2010-08-11 22:56:59 +00:00
Automatic Updater 797af0ae2d update 2010-08-11 19:15:15 +00:00
Evan Hunt 0658d99891 2936. [func] Improved configuration syntax and multiple-view
support for addzone/delzone feature (see change
			#2930).  Removed "new-zone-file" option, replaced
			with "allow-new-zones (yes|no)".  The new-zone-file
			for each view is now created automatically, with
			a filename generated from a hash of the view name.
			It is no longer necessary to "include" the
			new-zone-file in named.conf; this happens
			automatically.  Zones that were not added via
			"rndc addzone" can no longer be removed with
			"rndc delzone". [RT #19447]
2010-08-11 18:19:59 +00:00
Automatic Updater 31d7f00538 update 2010-08-11 03:15:49 +00:00
Automatic Updater 444deec2a0 sync 2010-08-11 02:28:58 +00:00
Automatic Updater 36345eaba4 update 2010-08-11 00:15:51 +00:00
Automatic Updater 867b6769fe update copyright notice 2010-08-10 23:47:45 +00:00
Automatic Updater c4cd50192d newcopyrights 2010-08-10 23:30:29 +00:00
Automatic Updater 7a6894cb7f update 2010-08-10 10:15:21 +00:00
Mark Andrews a3fb29404e 2935. [bug] nsupdate: improve 'file not found' error message.
[RT #21871]
2010-08-10 09:54:11 +00:00
Mark Andrews e05fe79dd3 2934. [bug] Use ANSI C compliant shift range in lib/isc/entropy.c.
[RT #21871]
2010-08-10 09:36:56 +00:00
Automatic Updater a10c0cd87c update 2010-08-10 09:15:19 +00:00
Mark Andrews 76e6cf505e 2933. [bug] 'dig +nsid' used stack memory after it went out of
scope.  This could potentially result in a unknown,
                        potentially malformed, EDNS option being sent instead
                        of the desired NSID option. [RT #21781]
2010-08-10 08:43:40 +00:00
Automatic Updater 5ac5be4ca9 update 2010-08-09 23:15:19 +00:00
Evan Hunt ead09b5724 2932. [cleanup] Corrected a numbering error in the "dnssec" test.
[RT #21597]
2010-08-09 22:35:06 +00:00
Automatic Updater 58ec718890 update 2010-08-04 00:15:47 +00:00
Automatic Updater 0154c3b77b update copyright notice 2010-08-03 23:46:17 +00:00
Automatic Updater 6fbb344271 newcopyrights 2010-08-03 23:30:40 +00:00
Automatic Updater 22076c62a1 update 2010-08-03 17:15:22 +00:00
Tatuya JINMEI 神明達哉 fdc65eb9ec added me to authors. approved by Evan. 2010-08-03 16:44:52 +00:00
Automatic Updater 03db30d50e update 2010-07-20 05:15:14 +00:00
Mark Andrews 74373ce898 while (1) -> for (;;) to silence compiler warning 2010-07-20 04:51:38 +00:00
Mark Andrews 11f8ef90da format/arg mismatch solaris 2010-07-20 04:48:01 +00:00
Automatic Updater dfcaadf673 update 2010-07-20 01:15:16 +00:00
Mark Andrews 01d404c4ad retag 9.7.2b1 2010-07-20 00:37:24 +00:00
Automatic Updater 9b681678ee update 2010-07-19 06:15:13 +00:00
Mark Andrews e5c3961bf6 0 -> 0U 2010-07-19 06:14:11 +00:00
Automatic Updater 494617bce2 update 2010-07-19 05:15:16 +00:00
Mark Andrews d647b53008 silence compiler warnings about (char) as index to array 2010-07-19 05:14:47 +00:00
Automatic Updater ae61729064 update 2010-07-15 02:15:17 +00:00
Tatuya JINMEI 神明達哉 9891a60571 2931. [bug] Temporarily and partially disable change 2864
because it would cause inifinite attempts of RRSIG
			queries.  This is an urgent care fix; we'll
			revisit the issue and complete the fix later.
			[RT #21710]
2010-07-15 01:26:10 +00:00
Automatic Updater 589cf29b85 update 2010-07-13 03:15:43 +00:00
Automatic Updater 832c2e6b68 sync 2010-07-13 02:28:37 +00:00
Automatic Updater 569a2c2b5f update 2010-07-12 19:15:14 +00:00
Evan Hunt 4b186490dd Added function definitions and moved a variable declaration for win32 build. 2010-07-12 18:52:23 +00:00
Automatic Updater d0c7cc3abe update 2010-07-12 18:16:16 +00:00
Evan Hunt ae7644fbdc updated api files for 9.7.2b1 release 2010-07-12 18:11:12 +00:00
Automatic Updater 8756f35d48 update 2010-07-12 17:15:13 +00:00
Evan Hunt 6a009a5e2c update for 9.7.2b1 release 2010-07-12 17:00:00 +00:00
Automatic Updater cb39d9525b updated for 9.7.2b1 release 2010-07-12 16:57:40 +00:00
Automatic Updater 7c80f7895f update 2010-07-12 03:15:40 +00:00
Automatic Updater cc738d9655 regen v9_7 2010-07-12 02:41:01 +00:00
Automatic Updater 8bc0b080dc update 2010-07-12 00:15:47 +00:00
Automatic Updater d4fb9a4b93 update copyright notice 2010-07-11 23:46:36 +00:00
Automatic Updater b7e31c54f2 newcopyrights 2010-07-11 23:30:22 +00:00
Automatic Updater bb11721d68 update 2010-07-11 06:15:14 +00:00
Evan Hunt 2b19800425 Removed a duplicate entry in namedconf.c. 2010-07-11 05:44:05 +00:00
Automatic Updater 046bc782ab update 2010-07-11 03:15:44 +00:00
Automatic Updater 99b2fa2479 regen v9_7 2010-07-11 02:41:30 +00:00
Automatic Updater f5a2086f1f update 2010-07-11 02:15:18 +00:00
Evan Hunt 542d079eb1 dnssec and dlv tests included master zones whose master files were missing.
this was a bug that hadn't been noticed before, but 19447 added a test for
that condition and it caused test failures.
2010-07-11 01:18:17 +00:00
Automatic Updater 31eb153edb update 2010-07-11 00:15:32 +00:00
Evan Hunt 92f39ccb5b 2930. [experimental] New "rndc addzone" and "rndc delzone" commads
allow dynamic addition and deletion of zones.
			To enable this feature, specify a "new-zone-file"
			option at the view or options level in named.conf.
			Zone configuration information for the new zones
			will be written into that file.  To make the new
			zones persist after a restart, "include" the file
			into named.conf in the appropriate view.  (Note:
			This feature is not yet documented, and its syntax
			is expected to change.) [RT #19447]
2010-07-11 00:12:19 +00:00
Automatic Updater e2f3912e14 update 2010-07-10 03:15:44 +00:00
Automatic Updater 523d1871dc regen v9_7 2010-07-10 02:41:31 +00:00
Automatic Updater 29ef7aeb04 update 2010-07-10 00:15:46 +00:00
Automatic Updater 98afc1a6dd update copyright notice 2010-07-09 23:46:27 +00:00
Automatic Updater 1bb3dd1911 newcopyrights 2010-07-09 23:33:24 +00:00
Automatic Updater a7f6945b12 update 2010-07-09 05:15:48 +00:00
Evan Hunt 59c9c71f36 2929. [bug] Improved handling of GSS security contexts:
- added LRU expiration for generated TSIGs
			 - added the ability to use a non-default realm
                         - added new "realm" keyword in nsupdate
			 - limited lifetime of generated keys to 1 hour
			   or the lifetime of the context (whichever is
			   smaller)
			[RT #19737]
2010-07-09 05:14:08 +00:00
Automatic Updater c41e161d06 update 2010-07-08 03:15:43 +00:00
Automatic Updater 0b04e719ae sync 2010-07-08 02:28:35 +00:00
Automatic Updater 7bcbe0f387 update 2010-07-05 03:15:44 +00:00
Automatic Updater de6d4c73d2 sync 2010-07-05 02:28:31 +00:00
Automatic Updater f562d83ce6 update 2010-06-30 03:15:45 +00:00
Automatic Updater 3f56f26766 sync 2010-06-30 02:28:25 +00:00
Automatic Updater 139c403ce5 update 2010-06-29 03:15:41 +00:00
Automatic Updater 956206dda4 sync 2010-06-29 02:28:38 +00:00
Automatic Updater ece11c796a update 2010-06-29 00:15:46 +00:00
Automatic Updater 8bce19c1ea update copyright notice 2010-06-28 23:46:24 +00:00
Automatic Updater bc8f6178e7 newcopyrights 2010-06-28 23:30:30 +00:00
Automatic Updater 356005f612 update 2010-06-28 02:15:19 +00:00
Mark Andrews 5a21c108fe check that we have non-cachable answers to test against
match the dig.out.ns#.$n to the nameserver
2010-06-28 01:37:20 +00:00
Automatic Updater ca5b25ad68 update 2010-06-28 00:15:51 +00:00
Mark Andrews 88b6cb8b8b handle very short source files 2010-06-27 23:33:39 +00:00
Automatic Updater 63118d1444 update 2010-06-27 00:15:42 +00:00
Automatic Updater 4fe6e5b494 update copyright notice 2010-06-26 23:46:27 +00:00
Automatic Updater d49cd04515 newcopyrights 2010-06-26 23:30:25 +00:00
Automatic Updater 0128b3dcd6 update 2010-06-26 06:15:16 +00:00
Mark Andrews f0eda70e86 isc_boolean_t -> dns_v4_aaaa_t 2010-06-26 05:31:17 +00:00
Automatic Updater b07c1edbba update 2010-06-26 03:15:47 +00:00
Automatic Updater 677b20a94c regen v9_7 2010-06-26 02:41:21 +00:00
Mark Andrews f7540a5483 bin/tests/system/dnssec/ns7/named.nosoa 2010-06-26 02:20:23 +00:00
Automatic Updater 2c38bd4799 update 2010-06-26 01:15:13 +00:00
Mark Andrews a386cb22a0 add /* NOT DOCUMENTED */ 2010-06-26 00:20:04 +00:00
Automatic Updater 80ba794a42 update 2010-06-26 00:15:46 +00:00
Mark Andrews 5a7f05ee3c 2925. [bug] Named failed to accept uncachable negative responses
from insecure zones. [RT# 21555]
2010-06-25 23:52:09 +00:00
Automatic Updater c65ab74d31 update copyright notice 2010-06-25 23:46:33 +00:00
Automatic Updater c2dde474aa newcopyrights 2010-06-25 23:30:28 +00:00
Automatic Updater 1cca07d601 update 2010-06-25 07:30:44 +00:00
Mark Andrews 653b008950 remove leading zeros on keyid
account for trusted keys not applying to _bind anymore
2010-06-25 07:27:20 +00:00
Automatic Updater 1386155331 update 2010-06-25 04:15:20 +00:00
Mark Andrews 9777316c64 2924. [func] 'rndc secroots' dump a combined summary of the
current managed keys combined with trusted keys.
                        [RT #20904]
2010-06-25 03:51:07 +00:00
Automatic Updater 5f57c9f71c update 2010-06-24 08:15:25 +00:00
Mark Andrews 9b8836481d changes number 2010-06-24 07:33:05 +00:00
Mark Andrews fe012b4db4 cvs rdiff -r1.3417 -r1.3418 bind9/CHANGES
cvs rdiff -r1.330 -r1.331 bind9/bin/dig/dighost.c
2010-06-24 07:29:07 +00:00
Automatic Updater 12eb4bc93c update 2010-06-24 00:15:44 +00:00
Automatic Updater 5b17e46285 update copyright notice 2010-06-23 23:46:36 +00:00
Automatic Updater f8d7bb61a8 newcopyrights 2010-06-23 23:30:27 +00:00
Automatic Updater 65cc2ab6a5 update 2010-06-23 04:15:39 +00:00
Mark Andrews 728ee05d45 s/to soon/too soon/ 2010-06-23 03:31:31 +00:00
Mark Andrews b9e3320bf4 add period 2010-06-23 03:28:58 +00:00
Automatic Updater 3ebd394165 update 2010-06-23 03:15:34 +00:00
Mark Andrews 128b7183fd 2922 [contrib] Update zkt to version 1.0.: 2010-06-23 02:47:48 +00:00
Automatic Updater aaa0b7a55e regen v9_7 2010-06-23 02:41:06 +00:00
Automatic Updater 0ab62f7ab9 update 2010-06-23 02:15:28 +00:00
Mark Andrews 773efb00d2 2921. [bug] The resolver could attempt to destroy a fetch context
to soon.  [RT #19878]
2010-06-23 01:50:55 +00:00
Automatic Updater f4440dd30a update 2010-06-23 00:15:36 +00:00
Automatic Updater 275c562ce7 update copyright notice 2010-06-22 23:46:34 +00:00
Mark Andrews d845cb6745 update 2010-06-22 23:37:37 +00:00
Automatic Updater 28b4db7239 update 2010-06-22 07:15:16 +00:00
Mark Andrews a86f1249ee 2920. [func] Allow 'filter-aaaa-on-v4' to be applied selectively
to IPv4 clients.  New acl 'filter-aaaa' (default any).
2010-06-22 06:18:07 +00:00
Mark Andrews 6a51d9b6de reverse accidental commit 2010-06-22 06:15:11 +00:00
Automatic Updater a797df31d7 update 2010-06-22 04:15:25 +00:00
Mark Andrews 13ce1be5d3 2920. [func] Allow 'filter-aaaa-on-v4' to be applied selectively
to IPv4 clients.  New acl 'filter-aaaa' (default any).
2010-06-22 04:04:22 +00:00
Automatic Updater d5400f7e7d update 2010-06-22 00:15:48 +00:00
Automatic Updater 2eb5511c39 update copyright notice 2010-06-21 23:46:27 +00:00
Automatic Updater 2ce9908f2d newcopyrights 2010-06-21 23:30:25 +00:00
Automatic Updater 5a74ff52c2 regen 2010-06-21 23:30:24 +00:00
Automatic Updater 3022504c0b update 2010-06-21 03:15:41 +00:00
Mark Andrews 262ed7420f 2919. [func] Add autosign-ksk and autosign-zsk virtual time tests.
[RT #20840]
2010-06-21 02:36:44 +00:00
Automatic Updater fc77335828 update 2010-06-21 00:15:50 +00:00
Automatic Updater c0e2300901 update copyright notice 2010-06-20 23:46:24 +00:00
Automatic Updater 19dd51b6ab newcopyrights 2010-06-20 23:30:24 +00:00
Automatic Updater 92a43c0ead regen 2010-06-20 23:30:23 +00:00
Automatic Updater b7ba53e732 update 2010-06-20 08:15:46 +00:00
Mark Andrews a7b7c601a5 report bind.keys and bindkeys.pl versions in output 2010-06-20 07:36:02 +00:00
Mark Andrews 6cac6ea83b add bind.keys.h dependancy on ${srcdir}/bindkeys.pl 2010-06-20 07:34:54 +00:00
Mark Andrews 9c6a6f9134 add cvs id 2010-06-20 07:32:24 +00:00
Automatic Updater 37cb6b93fd update 2010-06-19 03:15:42 +00:00
Automatic Updater 72b349b75c sync 2010-06-19 02:28:25 +00:00
Automatic Updater f276cf10c8 update 2010-06-19 00:15:40 +00:00
Automatic Updater 5040108c31 update copyright notice 2010-06-18 23:46:26 +00:00
Automatic Updater 55d21ef131 newcopyrights 2010-06-18 23:30:33 +00:00
Automatic Updater e035fcc62a update 2010-06-18 05:39:19 +00:00
Mark Andrews 21879ffd57 AAAA not A 2010-06-18 05:37:15 +00:00
Automatic Updater bf1eb3b85d update 2010-06-18 03:16:17 +00:00
Mark Andrews b2cc42052f /bin/tests/virtual-time/common/controls.conf 2010-06-18 02:49:04 +00:00
Mark Andrews aa4d04e680 ./bin/tests/virtual-time/README 2010-06-18 02:46:31 +00:00
Automatic Updater 2b48d4ec91 update 2010-06-18 02:15:20 +00:00
Mark Andrews e2edd40cb4 2918. [maint] Add AAAA address for I.ROOT-SERVERS.NET. 2010-06-18 02:13:01 +00:00
Mark Andrews b5fb6892fe add 9.7.1 release marker 2010-06-18 02:02:04 +00:00
Automatic Updater 1365b51c71 update 2010-06-18 00:15:45 +00:00
Automatic Updater 399e2fd233 update 2010-06-17 06:15:13 +00:00
Mark Andrews 17560312bb 2917. [func] Virtual time test framework. [RT #20801] 2010-06-17 05:44:42 +00:00
Mark Andrews b7b65b35b6 2917. [func] Virtual time test framework. [RT #20801 2010-06-17 05:43:52 +00:00
Automatic Updater 86bdb760d7 update 2010-06-16 03:15:40 +00:00
Automatic Updater f3a548988c sync 2010-06-16 02:28:07 +00:00
Automatic Updater ec5fcd0136 update 2010-06-12 00:15:45 +00:00
Automatic Updater a6cde7c0f6 update copyright notice 2010-06-11 23:46:18 +00:00
Automatic Updater fe3bf8f43e newcopyrights 2010-06-11 23:30:34 +00:00
Automatic Updater 5f8a100d65 update 2010-06-11 02:15:37 +00:00
Mark Andrews a3d418e155 restore export of PERL PK11GEN PK11LIST PK11DEL 2010-06-11 01:59:22 +00:00
Automatic Updater 08d50931b6 update 2010-06-11 00:49:38 +00:00
Automatic Updater d12037b665 update 2010-06-10 07:17:14 +00:00
Mark Andrews 24b4cd45a2 2916. [func] Add framework to use IPv6 in tests.
fd92:7065:b8e:ffff::1 ... fd92:7065:b8e:ffff::7
2010-06-10 06:20:47 +00:00
cvs2git 7c5699736b This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-06-10 06:19:55 +00:00
Mark Andrews 9a56f03c4c 2916. [func] Add framework to use IPv6 in tests.
fd92:7065:b8e:ffff::1 ... fd92:7065:b8e:ffff::7
2010-06-10 06:19:52 +00:00
Automatic Updater 60f146a7d0 update 2010-06-10 00:21:11 +00:00
Automatic Updater 3fa4e557e0 update 2010-06-10 00:20:42 +00:00
Automatic Updater e40d5d6b71 update copyright notice 2010-06-09 23:50:58 +00:00
Automatic Updater 5c24ec251e update copyright notice 2010-06-09 23:49:43 +00:00
Automatic Updater 8a507eb203 newcopyrights 2010-06-09 23:32:16 +00:00
Automatic Updater 3999dda5a5 newcopyrights 2010-06-09 23:31:44 +00:00
Automatic Updater 3514d179dd auto update 2010-06-09 23:19:22 +00:00
Automatic Updater 387182e77e update 2010-06-09 13:35:23 +00:00
Automatic Updater 1c75aa99a1 update 2010-06-09 13:35:03 +00:00
Automatic Updater 02bd4cd4b4 missing @ 2010-06-09 13:24:41 +00:00
Automatic Updater 36961e2937 missing @ 2010-06-09 13:23:47 +00:00
Automatic Updater 17184891e7 update 2010-06-09 09:17:21 +00:00
Automatic Updater 07510d963a update 2010-06-09 09:16:52 +00:00
Mark Andrews cf56ac2b41 missing @ 2010-06-09 09:04:39 +00:00
Mark Andrews 8b99611ece missing @ 2010-06-09 09:02:31 +00:00
Tatuya JINMEI 神明達哉 09e3a00249 file serveraddress.conf was initially added on branch rt21474. 2010-06-09 07:25:34 +00:00
Tatuya JINMEI 神明達哉 b7e4d6e217 file named.conf.in was initially added on branch rt21474. 2010-06-09 07:25:33 +00:00
Tatuya JINMEI 神明達哉 cdb49c3672 file setup.sh was initially added on branch rt21474. 2010-06-09 07:25:32 +00:00
Tatuya JINMEI 神明達哉 036cffcc86 file example.com4.zone was initially added on branch rt21474. 2010-06-09 06:08:44 +00:00
Tatuya JINMEI 神明達哉 7f7bce08e3 file example.com5.zone was initially added on branch rt21474. 2010-06-09 06:08:43 +00:00
Tatuya JINMEI 神明達哉 902c59120a file example.com3.zone was initially added on branch rt21474. 2010-06-09 06:08:42 +00:00
Tatuya JINMEI 神明達哉 e2b48e4a4b file example.com2.zone was initially added on branch rt21474. 2010-06-09 06:08:41 +00:00
Automatic Updater 9239151bf5 update 2010-06-09 02:21:34 +00:00
Automatic Updater 3703129570 update 2010-06-09 02:21:02 +00:00
Tatuya JINMEI 神明達哉 550e575a3e file good5.conf was initially added on branch rt21474. 2010-06-09 01:57:44 +00:00
Tatuya JINMEI 神明達哉 02f120a9f7 file good4.conf was initially added on branch rt21474. 2010-06-09 01:57:43 +00:00
Tatuya JINMEI 神明達哉 80a84bb8cb file bad6.conf was initially added on branch rt21474. 2010-06-09 01:57:42 +00:00
Mark Andrews a5840f0a32 2915. [cleanup] Be smarter about which objects we attempt to compile
based on configure options. [RT #21444]
2010-06-09 01:51:39 +00:00
Tatuya JINMEI 神明達哉 9cfdae0afd file controls1.conf was initially added on branch rt21474. 2010-06-09 01:51:36 +00:00
Tatuya JINMEI 神明達哉 ecc9331cdb file controlkey.conf was initially added on branch rt21474. 2010-06-09 01:51:35 +00:00
Mark Andrews 02181a6c74 2915. [cleanup] Be smarter about which objects we attempt to compile
based on configure options. [RT #21444]
2010-06-09 01:47:54 +00:00
Mark Andrews 76117ff568 CHANGES 2010-06-09 01:43:09 +00:00
Automatic Updater f45c817901 update 2010-06-09 00:20:55 +00:00
Automatic Updater 3ca4e5d7e1 update 2010-06-09 00:20:19 +00:00
Automatic Updater ad0471f93b update copyright notice 2010-06-08 23:50:24 +00:00
Automatic Updater 4cff55249c update copyright notice 2010-06-08 23:49:12 +00:00
Automatic Updater 45c349c278 newcopyrights 2010-06-08 23:32:05 +00:00
Automatic Updater e23b840d9e newcopyrights 2010-06-08 23:31:45 +00:00
Tatuya JINMEI 神明達哉 0832af2661 file good3.conf was initially added on branch rt21474. 2010-06-08 01:21:02 +00:00
Automatic Updater 605f3a5ef6 update 2010-06-08 00:20:35 +00:00
Automatic Updater c733ede7c7 update 2010-06-08 00:19:54 +00:00
Mark Andrews d80c2f805e update 2010-06-07 23:55:19 +00:00
Mark Andrews bf8c3776f1 update 2010-06-07 23:52:58 +00:00
Automatic Updater 6dc9dcbea2 auto update 2010-06-07 23:19:30 +00:00
Tatuya JINMEI 神明達哉 74a7310253 file good2.conf was initially added on branch rt21474. 2010-06-07 23:03:08 +00:00
Tatuya JINMEI 神明達哉 d6b258b138 file good1.conf was initially added on branch rt21474. 2010-06-07 23:03:07 +00:00
Tatuya JINMEI 神明達哉 75e3a3db1a file bad4.conf was initially added on branch rt21474. 2010-06-07 23:03:06 +00:00
Tatuya JINMEI 神明達哉 f83f6e989c file bad3.conf was initially added on branch rt21474. 2010-06-07 23:03:05 +00:00
Tatuya JINMEI 神明達哉 5b5e98e2c4 file bad2.conf was initially added on branch rt21474. 2010-06-07 23:03:04 +00:00
Tatuya JINMEI 神明達哉 22d9b3c470 file bad1.conf was initially added on branch rt21474. 2010-06-07 23:03:03 +00:00
Tatuya JINMEI 神明達哉 8596334ced file example.org.zone was initially added on branch rt21474. 2010-06-07 22:45:42 +00:00
Tatuya JINMEI 神明達哉 f0585f5ffe file example.net.zone was initially added on branch rt21474. 2010-06-07 22:45:41 +00:00
Tatuya JINMEI 神明達哉 34a49b9046 file example.info.zone was initially added on branch rt21474. 2010-06-07 22:45:40 +00:00
Tatuya JINMEI 神明達哉 d13a0a65c3 file example.edu.zone was initially added on branch rt21474. 2010-06-07 22:45:39 +00:00
Tatuya JINMEI 神明達哉 ae27fcf6ad file example.com.zone was initially added on branch rt21474. 2010-06-07 22:45:38 +00:00
Tatuya JINMEI 神明達哉 a150f937e0 file root.zone was initially added on branch rt21474. 2010-06-07 22:45:37 +00:00
Tatuya JINMEI 神明達哉 56eae9923e file named.conf was initially added on branch rt21474. 2010-06-07 22:45:36 +00:00
Tatuya JINMEI 神明達哉 002eb7e1bc file hints was initially added on branch rt21474. 2010-06-07 22:45:35 +00:00
Tatuya JINMEI 神明達哉 4827ffd3b5 file tests.sh was initially added on branch rt21474. 2010-06-07 22:45:34 +00:00
Tatuya JINMEI 神明達哉 f88543fba8 file clean.sh was initially added on branch rt21474. 2010-06-07 22:45:33 +00:00
Automatic Updater b8451d4055 update 2010-06-07 05:20:24 +00:00
Automatic Updater 0036997ea6 update 2010-06-07 05:19:18 +00:00
Mark Andrews 55fe737bf7 2914. [bug] Make the "autosign" system test more portable.
[RT #20997]
2010-06-07 04:47:26 +00:00
cvs2git 11d477b0ce This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-06-07 04:45:44 +00:00
Mark Andrews e24ccb512c 2914. [bug] Make the "autosign" system test more portable.
[RT #20997]
2010-06-07 04:45:43 +00:00
Automatic Updater cb1aaddd19 update 2010-06-07 04:24:40 +00:00
Automatic Updater 94e718f9cb update 2010-06-07 04:23:03 +00:00
Mark Andrews 1cc4291e10 2913. [func] Add pkcs#11 system tests. [RT #20784] 2010-06-07 03:45:36 +00:00
cvs2git 98886b12f1 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-06-07 03:42:38 +00:00
Mark Andrews 63af1a646a 2913. [func] Add pkcs#11 system tests. [RT #20784] 2010-06-07 03:42:37 +00:00
Automatic Updater e0cc71935a update 2010-06-05 00:20:59 +00:00
Automatic Updater 5b13795dbe update 2010-06-05 00:19:27 +00:00
Automatic Updater 3f2280d2fc update copyright notice 2010-06-04 23:51:14 +00:00
Automatic Updater db8dce00b0 update copyright notice 2010-06-04 23:50:01 +00:00
Automatic Updater 478d64f58f newcopyrights 2010-06-04 23:31:43 +00:00
Automatic Updater 23df967ec2 newcopyrights 2010-06-04 23:31:24 +00:00
Automatic Updater a694635ee9 update 2010-06-04 00:20:50 +00:00
Automatic Updater eb19109585 update 2010-06-04 00:19:49 +00:00
Mark Andrews 2b631b5d6f remove trailing comma 2010-06-04 00:14:53 +00:00
Mark Andrews ec58c4ca54 remove trailing comma 2010-06-04 00:12:54 +00:00
Mark Andrews 5ee4d3f2ee iterations is -H 2010-06-04 00:04:39 +00:00
Mark Andrews 784332dee8 iterations is -H 2010-06-04 00:04:09 +00:00
Automatic Updater 6e13ffa218 update copyright notice 2010-06-03 23:51:05 +00:00
Automatic Updater 4a885f26a0 update copyright notice 2010-06-03 23:49:23 +00:00
Automatic Updater 9d80d23172 newcopyrights 2010-06-03 23:31:51 +00:00
Automatic Updater 3056f9d0d5 newcopyrights 2010-06-03 23:31:32 +00:00
Automatic Updater bbc312f167 auto update 2010-06-03 23:20:22 +00:00
Automatic Updater 49d8f90140 update 2010-06-03 22:18:48 +00:00
Automatic Updater 2ef4d30f72 update 2010-06-03 22:18:00 +00:00
Mark Andrews e74c3a0f59 specify NSEC3 iterations 2010-06-03 21:44:49 +00:00
Mark Andrews 6894f7e981 specify NSEC3 iterations 2010-06-03 21:42:38 +00:00
Automatic Updater 21bade5e85 update 2010-06-03 14:01:15 +00:00
Automatic Updater d018916728 update 2010-06-03 14:00:53 +00:00
Mark Andrews 02d7775718 add -lkrb5 2010-06-03 13:28:35 +00:00
Mark Andrews a7f02c9c6b add -lkrb5 2010-06-03 13:27:46 +00:00
Automatic Updater 40b038c826 update 2010-06-03 06:35:45 +00:00
Automatic Updater be0f31ad9f update 2010-06-03 06:35:12 +00:00
Mark Andrews 61ccf5b46b 2911. [bug] dnssec-signzone didn't handle out of zone records well.
[RT #21367]
2010-06-03 06:31:42 +00:00
cvs2git 44cab72e7e This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-06-03 06:29:06 +00:00
Mark Andrews 10acc63770 2911. [bug] dnssec-signzone didn't handle out of zone records well.
[RT #21367]
2010-06-03 06:29:03 +00:00
Automatic Updater b48dc1327b update 2010-06-03 06:18:01 +00:00
Automatic Updater 07b05ade91 update 2010-06-03 06:17:36 +00:00
Mark Andrews 3b239c7b3b 2912. [func] Windows clients don't like UPDATE responses that clear
the zone section. [RT #20986]
2010-06-03 05:27:59 +00:00
Mark Andrews b7bc86a4d3 2912. [func] Windows clients don't like UPDATE responses that clear
the zone section. [RT #20986]
2010-06-03 05:23:27 +00:00
Automatic Updater 9f9ba278d7 update 2010-06-03 04:23:42 +00:00
Automatic Updater 0c1a5f0a1a update 2010-06-03 04:22:37 +00:00
Mark Andrews bd2b0c9ae5 add kerberosv5/krb5.h to search list 2010-06-03 03:57:24 +00:00
Mark Andrews 3a7b1fb32a add kerberosv5/krb5.h to search list 2010-06-03 03:55:07 +00:00
Mark Andrews b42093b971 2911. [bug] dnssec-signzone didn't handle out of zone records well.
[RT #21367]
2010-06-03 03:32:25 +00:00
Automatic Updater 01f93d7ceb update 2010-06-03 03:21:50 +00:00
Automatic Updater 6146308cc3 update 2010-06-03 03:21:11 +00:00
Mark Andrews 675cc80975 2911. [bug] dnssec-signzone didn't handle out of zone records well.
[RT #21367]
2010-06-03 03:13:32 +00:00
Mark Andrews 838ae5b351 2910. [func] Sanity check Kerberos credentials. [RT #20986] 2010-06-03 02:33:48 +00:00
Mark Andrews a20996ab6f 2910. [func] Sanity check Kerberos credentials. [RT #20986] 2010-06-03 02:29:58 +00:00
Automatic Updater fcf0d7cce2 update 2010-06-02 02:23:20 +00:00
Automatic Updater 6404ecd08d update 2010-06-02 02:22:00 +00:00
Automatic Updater a2d2fc17b0 update copyright notice 2010-06-02 01:28:40 +00:00
Automatic Updater 82404f5aef update copyright notice 2010-06-02 01:27:20 +00:00
Automatic Updater e2fe51aab4 update 2010-06-02 01:25:45 +00:00
Automatic Updater cf6c9f9005 update 2010-06-02 01:22:22 +00:00
Mark Andrews 8302431386 9.7.1rc1 re-tag 2010-06-02 01:19:10 +00:00
Mark Andrews a4003c3c4b named-checkzone -> named-checkconf 2010-06-02 01:14:58 +00:00
Mark Andrews 80852eb5a8 named-checkzone -> named-checkconf 2010-06-02 01:14:02 +00:00
Automatic Updater 0fde13e46f newcopyrights 2010-06-02 01:13:18 +00:00
Automatic Updater a2cb929b48 newcopyrights 2010-06-02 01:12:53 +00:00
Mark Andrews a2c8607929 2909. [bug] named-checkzone -p could die if "update-policy local;"
was specified in named.conf. [RT #21416]
2010-06-02 01:10:06 +00:00
Mark Andrews a27bbd21cf 2909. [bug] named-checkzone -p could die if "update-policy local;"
was specified in named.conf. [RT #21416]
2010-06-02 01:07:47 +00:00
Mark Andrews 8e187acb28 2908. [bug] It was possible for re-signing to stop after removing
a DNSKEY. [RT #21384]
2010-06-02 01:00:28 +00:00
Mark Andrews 29f0da7fb8 2908. [bug] It was possible for re-signing to stop after removing
a DNSKEY. [RT #21384]
2010-06-02 00:58:54 +00:00
Mark Andrews db3ae6b658 2907. [bug] The export version of libdns had undefined references.
[RT #21444]
2010-06-02 00:41:34 +00:00
Mark Andrews b00de53de2 2907. [bug] The export version of libdns had undefined references.
[RT #21444]
2010-06-02 00:38:29 +00:00
Automatic Updater 43998395c9 auto update 2010-06-01 23:17:03 +00:00
Automatic Updater 9db86b94c3 update 2010-06-01 03:28:46 +00:00
Automatic Updater 789515c1d0 9.7.1rc1 2010-06-01 03:14:30 +00:00
Automatic Updater 7a01ff0136 update 2010-06-01 01:16:32 +00:00
Mark Andrews 5b02faec3c 9.7.1rc1 2010-06-01 01:02:33 +00:00
Automatic Updater dbf3418d74 auto update 2010-05-29 23:19:15 +00:00
Automatic Updater 636718021d update 2010-05-29 11:16:53 +00:00
Mark Andrews 57b47bca26 checkpoint 2010-05-29 10:36:22 +00:00
Automatic Updater 0eca13810e update 2010-05-28 04:23:51 +00:00
Automatic Updater 68d79f2a0f update 2010-05-28 04:22:38 +00:00
Mark Andrews e68aa47d4c 2906. [bug] Address RFC 5011 implementation issues. [RT #20903] 2010-05-28 03:18:52 +00:00
Mark Andrews 249dcf3932 Add -> Address 2010-05-28 03:16:57 +00:00
Mark Andrews ead77b9ad4 2906. [bug] Add RFC 5011 implementation issues. [RT #20903] 2010-05-28 03:15:48 +00:00
Automatic Updater bdc5b20680 update 2010-05-28 00:21:05 +00:00
Automatic Updater 269a35ff01 update 2010-05-28 00:19:59 +00:00
Automatic Updater 248b9ab0b0 update copyright notice 2010-05-27 23:51:08 +00:00
Automatic Updater 0329504246 update copyright notice 2010-05-27 23:49:55 +00:00
Mark Andrews 2c35fdceff file named.run was initially added on branch rt21394. 2010-05-27 23:49:35 +00:00
Automatic Updater 48b36fa08b newcopyrights 2010-05-27 23:31:38 +00:00
Automatic Updater 0f82d123cf newcopyrights 2010-05-27 23:31:09 +00:00
Automatic Updater ff4b3adaa4 auto update 2010-05-27 23:19:21 +00:00
Automatic Updater 3718c6396e update 2010-05-27 04:23:37 +00:00
Automatic Updater 6875da69bb update 2010-05-27 04:22:37 +00:00
Mark Andrews 5cb766e596 line length 2010-05-27 03:27:35 +00:00
Mark Andrews 2f34efede1 line length 2010-05-27 03:23:56 +00:00
Automatic Updater 529f589a83 update 2010-05-27 00:20:41 +00:00
Automatic Updater e5d6b3ba09 update 2010-05-27 00:19:45 +00:00
Automatic Updater 051dec6fb7 update copyright notice 2010-05-26 23:50:47 +00:00
Automatic Updater b8612502e2 update copyright notice 2010-05-26 23:49:35 +00:00
Mark Andrews 6420e53c12 2905. [port] aix: set use_atomic=yes with native compiler.
[RT #21402]
2010-05-26 23:47:44 +00:00
Mark Andrews 8e22c73f3e 2905. [port] aix: set use_atomic=yes with native compiler.
[RT #21402]
2010-05-26 23:44:27 +00:00
Mark Andrews 810048c754 ./bin/tests/system/dlv/ns6/hints 2010-05-26 23:36:59 +00:00
Mark Andrews 9fa39c73fc ./bin/tests/system/dlv/ns6/hints 2010-05-26 23:36:11 +00:00
Automatic Updater c177980194 auto update 2010-05-26 23:19:29 +00:00
Automatic Updater 00f1c3f453 update 2010-05-26 07:17:19 +00:00
Automatic Updater 57cb4281fa update 2010-05-26 07:16:47 +00:00
Mark Andrews b4c6ce22d0 call sign.sh robustly 2010-05-26 07:00:37 +00:00
Mark Andrews 491d1d3463 call sign.sh robustly 2010-05-26 07:00:01 +00:00
Mark Andrews d544482827 2904. [bug] When using DLV, sub-zones of the zones in the DLV,
could be incorrectly marked as insecure instead of
                        secure leading to negative proofs failing.  This was
                        a unintended outcome from change 2890. [RT# 21392]
2010-05-26 06:30:43 +00:00
cvs2git 00f7383ab0 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-05-26 06:28:02 +00:00
Mark Andrews e27d55e3ee 2904. [bug] When using DLV, sub-zones of the zones in the DLV,
could be incorrectly marked as insecure instead of
                        secure leading to negative proofs failing.  This was
                        a unintended outcome from change 2890. [RT# 21392]
2010-05-26 06:28:00 +00:00
Automatic Updater 74040af06f auto update 2010-05-25 23:18:57 +00:00
Automatic Updater 2d0accdb56 update 2010-05-22 03:20:34 +00:00
Automatic Updater 637427aed9 regen v9_7 2010-05-22 02:42:20 +00:00
Automatic Updater 0a960506d0 update 2010-05-22 01:16:26 +00:00
Automatic Updater 36025dc74f regen HEAD 2010-05-22 01:13:58 +00:00
Automatic Updater 2cde638aa9 auto update 2010-05-21 23:19:16 +00:00
Automatic Updater 973c0609a2 update 2010-05-21 14:17:20 +00:00
Automatic Updater 3fea8ab161 update 2010-05-21 14:16:44 +00:00
Mark Andrews 43641877ac 2903. [bug] managed-keys-directory missing from namedconf.c.
[RT #21370]
2010-05-21 14:13:48 +00:00
Mark Andrews 7d9be933d7 2903. [bug] managed-keys-directory missing from namedconf.c.
[RT #21370]
2010-05-21 14:10:32 +00:00
Automatic Updater 0d013d4f2e update 2010-05-21 02:20:05 +00:00
Mark Andrews d2761fe281 new logos 2010-05-21 02:13:37 +00:00
Automatic Updater 9ba7b9cd1f auto update 2010-05-19 23:19:23 +00:00
Automatic Updater 02e8b3e120 update 2010-05-19 10:20:58 +00:00
Automatic Updater 3cbd3a3f36 update 2010-05-19 10:20:07 +00:00
Mark Andrews abb239e7fc silence compiler, explict coversion 2010-05-19 09:52:42 +00:00
Mark Andrews c4700949e7 silence compiler, explict coversion 2010-05-19 09:51:31 +00:00
Automatic Updater 15c961a1dd update copyright notice 2010-05-19 09:33:50 +00:00
Automatic Updater 8b96e18c96 update copyright notice 2010-05-19 09:32:36 +00:00
Automatic Updater 19dbf2e20d newcopyrights 2010-05-19 09:27:32 +00:00
Automatic Updater 0dc9c323d2 newcopyrights 2010-05-19 09:27:10 +00:00
Automatic Updater 1969b8c679 update 2010-05-19 08:20:21 +00:00
Automatic Updater 2aec4cb735 update 2010-05-19 08:19:36 +00:00
Mark Andrews 2e023d9a29 2902. [func] Add regression test for change 2897. [RT #21040] 2010-05-19 07:47:11 +00:00
cvs2git 63fe01ab22 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-05-19 07:45:39 +00:00
Mark Andrews 5ae2eac4c1 2902. [func] Add regression test for change 2897. [RT #21040] 2010-05-19 07:45:38 +00:00
Automatic Updater 0b610fdb6e update 2010-05-19 07:17:28 +00:00
Automatic Updater 37eeb883b6 update 2010-05-19 07:17:13 +00:00
Mark Andrews 40be22dada 2901. [port] Use AC_C_FLEXIBLE_ARRAY_MEMBER. [RT #21316] 2010-05-19 07:13:53 +00:00
Mark Andrews 5b02fc32d6 2901. [port] Use AC_C_FLEXIBLE_ARRAY_MEMBER. [RT #21316] 2010-05-19 07:13:15 +00:00
Mark Andrews 756f9eb63a 2900. [bug] The placeholder negative caching element was not
properly constructed triggering a INSIST in
                        dns_ncache_towire(). [RT #21346]
2010-05-19 06:41:05 +00:00
Mark Andrews b667946fa5 2900. [bug] The placeholder negative caching element was not
properly constructed triggering a INSIST in
                        dns_ncache_towire(). [RT #21346]
2010-05-19 06:39:50 +00:00
Automatic Updater 492cae1877 update 2010-05-19 01:16:46 +00:00
Automatic Updater bef75d63d7 regen HEAD 2010-05-19 01:14:14 +00:00
Automatic Updater c3e2e3b317 update 2010-05-18 07:20:31 +00:00
Automatic Updater 3bb935c499 update 2010-05-18 07:19:06 +00:00
Automatic Updater 59d000d7ec update copyright notice 2010-05-18 06:47:46 +00:00
Automatic Updater 3b56f0f090 update copyright notice 2010-05-18 06:47:00 +00:00
Automatic Updater 3ab6f6505b newcopyrights 2010-05-18 06:42:52 +00:00
Automatic Updater da00b95e55 newcopyrights 2010-05-18 06:42:19 +00:00
Mark Andrews bf80fd4841 silence compile warnings, explict conversion 2010-05-18 06:29:32 +00:00
Mark Andrews 32f985bcf4 silence compile warnings, explict conversio 2010-05-18 06:28:29 +00:00
Mark Andrews facf31bace wrong rdataset disassociated. reviewed by each 2010-05-18 06:24:27 +00:00
Automatic Updater 5928877cd0 update 2010-05-18 06:20:07 +00:00
Automatic Updater e9d613fa9d update 2010-05-18 06:19:46 +00:00
Mark Andrews 6ffc3748d9 wrong rdataset disassociated. reviewed by each 2010-05-18 06:18:23 +00:00
Mark Andrews 8438d8e0b4 9.7.1b1 2010-05-18 06:16:05 +00:00
Mark Andrews ed30e0358b 9.7.1b1 2010-05-18 06:14:32 +00:00
Mark Andrews eaf0bd1fd7 2899. [port] win32: Support linking against OpenSSL 1.0.0 2010-05-18 06:11:58 +00:00
Mark Andrews d8624c1f19 2899. [port] win32: Support linking against OpenSSL 1.0.0. 2010-05-18 06:10:36 +00:00
Automatic Updater 1d32fae40d update 2010-05-18 05:20:15 +00:00
Automatic Updater 3f12adb3f0 9.7.1b1 2010-05-18 04:43:02 +00:00
Automatic Updater cebadbc797 update 2010-05-18 04:20:23 +00:00
Automatic Updater 400b8856c9 update 2010-05-18 04:19:17 +00:00
Automatic Updater 7fad6b61d2 regen v9_7 2010-05-18 04:04:36 +00:00
Mark Andrews 78f3ed4bc2 mark docbook inheritance 2010-05-18 03:29:39 +00:00
Mark Andrews a64f7707cc mark docbook inheritance 2010-05-18 03:27:35 +00:00
Automatic Updater e5d4f0c9e2 update 2010-05-18 03:25:42 +00:00
Automatic Updater 1edd0adfcc update 2010-05-18 03:24:27 +00:00
Automatic Updater 37db859ba3 newcopyrights 2010-05-18 03:14:14 +00:00
Automatic Updater 1bf082f6da 9.7.1b1 2010-05-18 03:10:40 +00:00
Automatic Updater 1af8f0c951 regen v9_7 2010-05-18 02:41:37 +00:00
Automatic Updater 4dd3ec797d update copyright notice 2010-05-18 02:38:10 +00:00
Automatic Updater e08a20aa98 update copyright notice 2010-05-18 02:35:12 +00:00
Mark Andrews 0f51e50b08 9.7.1b1 2010-05-18 02:29:00 +00:00
Automatic Updater d7a77415c1 newcopyrights 2010-05-18 02:24:47 +00:00
Automatic Updater 6be22e19ef newcopyrights 2010-05-18 02:24:10 +00:00
Automatic Updater a35d309d39 update 2010-05-18 02:21:40 +00:00
Automatic Updater 11bbddd195 update 2010-05-18 02:20:29 +00:00
Mark Andrews c687d21e23 9.7.1b1 2010-05-18 02:12:30 +00:00
Mark Andrews 721c4a65f3 2898. [bug] nslookup leaked memory when -domain=value was
specified. [RT #21301]
2010-05-18 01:49:55 +00:00
Mark Andrews 98744b5111 2898. [bug] nslookup leaked memory when -domain=value was
specified. [RT #21301]
2010-05-18 01:48:13 +00:00
Mark Andrews 0517d21ebd 2897. [bug] NSEC3 chains could be left behind when transitioning
to insecure. [RT #21040]
2010-05-18 01:40:35 +00:00
Mark Andrews 8d31dd9ab6 2897. [bug] NSEC3 chains could be left behind when transitioning
to insecure. [RT #21040]
2010-05-18 01:39:41 +00:00
Automatic Updater 4201914311 update 2010-05-18 01:17:24 +00:00
Automatic Updater 507aef0c77 update 2010-05-18 01:16:39 +00:00
Automatic Updater e1263b4b9c regen HEAD 2010-05-18 01:14:20 +00:00
Mark Andrews 78f9a0a2b8 2896. [bug] "rndc sign" failed to properly update the zone
when adding a DNSKEY for publication only. [RT #21045]
2010-05-18 01:04:26 +00:00
Mark Andrews 6d58400178 2896. [bug] "rndc sign" failed to properly update the zone
when adding a DNSKEY for publication only. [RT #21045]
2010-05-18 01:03:26 +00:00
Mark Andrews 777d3c3963 silence compiler warning 2010-05-18 00:29:31 +00:00
Mark Andrews 7ac162ea7e silence compiler warning 2010-05-18 00:28:40 +00:00
Automatic Updater d0f5f4f46e update 2010-05-18 00:20:47 +00:00
Automatic Updater 9abc3592ad update 2010-05-18 00:18:46 +00:00
Automatic Updater bd5842db3d update copyright notice 2010-05-17 23:51:05 +00:00
Automatic Updater ee980f5002 update copyright notice 2010-05-17 23:49:51 +00:00
Automatic Updater 4d95e549ed newcopyrights 2010-05-17 23:31:16 +00:00
Automatic Updater 53835b8fd8 newcopyrights 2010-05-17 23:31:03 +00:00
Automatic Updater 112f416309 update 2010-05-17 06:22:49 +00:00
Automatic Updater 6285ade4fb update 2010-05-17 06:21:40 +00:00
Mark Andrews c9c7fc6a01 #include <isc/print.h> 2010-05-17 05:31:43 +00:00
Mark Andrews c385687ce6 #include <isc/print.h> 2010-05-17 05:31:08 +00:00
Automatic Updater cbf3cd3bc2 update 2010-05-17 05:17:46 +00:00
Automatic Updater 6e3cd11729 update 2010-05-17 05:17:06 +00:00
Mark Andrews e6bc9ed3b0 2895. [func] genrandom: add support for the generation of multiple
files.  [RT #20917]
2010-05-17 04:40:10 +00:00
Mark Andrews 3ec79bbc03 2895. [func] genrandom: add support for the generation of multiple
files.  [RT #20917]
2010-05-17 04:38:45 +00:00
Automatic Updater a1bfc38679 update 2010-05-15 03:34:04 +00:00
Automatic Updater fa3174b8f1 regen v9_7 2010-05-15 02:42:00 +00:00
Automatic Updater 7e621e1c51 update 2010-05-15 01:16:43 +00:00
Automatic Updater 0284e57b9b regen HEAD 2010-05-15 01:14:25 +00:00
Automatic Updater d7d098e901 update 2010-05-15 00:21:02 +00:00
Automatic Updater b4159c080b update 2010-05-15 00:20:05 +00:00
Automatic Updater 515c7f3c43 update copyright notice 2010-05-14 23:50:40 +00:00
Automatic Updater 71324ae046 update copyright notice 2010-05-14 23:49:21 +00:00
Automatic Updater c453a50776 newcopyrights 2010-05-14 23:31:50 +00:00
Automatic Updater 4d4be2e895 newcopyrights 2010-05-14 23:31:31 +00:00
Automatic Updater cb5e85be18 auto update 2010-05-14 23:18:40 +00:00
Automatic Updater 9ba22e3716 update 2010-05-14 07:18:44 +00:00
Automatic Updater 9f91506fed update 2010-05-14 07:18:10 +00:00
Mark Andrews 61215a0d76 2894. [contrib] DLZ LDAP support now use '$' not '%'. [RT #21294] 2010-05-14 06:31:35 +00:00
Mark Andrews dc64df4479 2894. [contrib] DLZ LDAP support now use '$' not '%'. [RT #21294] 2010-05-14 06:29:37 +00:00
Automatic Updater 462d82f8e5 update 2010-05-14 05:17:19 +00:00
Automatic Updater 8fe68ee01c update 2010-05-14 05:17:02 +00:00
Mark Andrews 812b6d8d11 2893. [bug] Improve managed keys support. New named.conf option
managed-keys-directory. [RT #20924]
2010-05-14 04:49:40 +00:00
Mark Andrews 778a01b1aa 2893. [bug] Improve managed keys support. New named.conf option
managed-keys-directory. [RT #20924]
2010-05-14 04:48:28 +00:00
Mark Andrews d133eb632a 2892. [bug] Handle REVOKED keys better. [RT #20961] 2010-05-14 04:41:12 +00:00
Mark Andrews 44f175a90a 2892. [bug] Handle REVOKED keys better. [RT #20961] 2010-05-14 04:38:52 +00:00
Automatic Updater d2dd525033 update 2010-05-14 04:22:15 +00:00
Automatic Updater 286bbb3ca4 update 2010-05-14 04:21:28 +00:00
Mark Andrews b756b7d22f 2891. [maint] Update empty-zones list to match
draft-ietf-dnsop-default-local-zones-13. [RT# 21099]
2010-05-14 03:32:11 +00:00
Mark Andrews 21991bd14e 2891. [maint] Update empty-zones list to match
draft-ietf-dnsop-default-local-zones-13. [RT# 21099]
2010-05-14 03:24:24 +00:00
Automatic Updater db2113fd6b update 2010-05-14 03:20:46 +00:00
Automatic Updater e6e37613eb regen v9_7 2010-05-14 02:41:23 +00:00
Automatic Updater e2350edd17 update 2010-05-14 01:16:58 +00:00
Automatic Updater 78f8d31dc6 update 2010-05-14 01:16:31 +00:00
Automatic Updater 1e6032fe39 regen HEAD 2010-05-14 01:14:18 +00:00
Automatic Updater 73120f904b update 2010-05-14 00:21:10 +00:00
Automatic Updater 4deef8a463 update 2010-05-14 00:20:40 +00:00
Mark Andrews 0463ffd804 2890. [bug] Handle the introduction of new trusted-keys and
DS, DLV RRsets better. [RT #21097]
2010-05-14 00:16:32 +00:00
Mark Andrews b335299322 2890. [bug] Handle the introduction of new trusted-keys and
DS, DLV RRsets better. [RT #21097]
2010-05-14 00:13:43 +00:00
Automatic Updater b7bcdb3eaa update copyright notice 2010-05-13 23:50:27 +00:00
Automatic Updater 5a77c5e18e update copyright notice 2010-05-13 23:49:11 +00:00
Automatic Updater 04161382a2 newcopyrights 2010-05-13 23:32:14 +00:00
Automatic Updater 928ec8b49a newcopyrights 2010-05-13 23:31:49 +00:00
Automatic Updater 4d781d52a7 update 2010-05-13 04:32:21 +00:00
Automatic Updater 06da8b9b9a update 2010-05-13 04:30:21 +00:00
Mark Andrews ff5c52617e element -> elements 2010-05-13 03:26:30 +00:00
Automatic Updater a7094451a0 update 2010-05-13 03:22:45 +00:00
Automatic Updater 84108b14a2 update 2010-05-13 03:21:33 +00:00
Mark Andrews bd72d2c9fc 2889. [bug] Elements of the grammar where not properly reported.
[RT #21046]
2010-05-13 03:18:55 +00:00
Mark Andrews e12030c433 2889. [bug] Element of the grammar where not properly reported.
[RT #21046]
2010-05-13 03:16:55 +00:00
Mark Andrews 8d5279c34e typo in threaded build, silence compiler warning 2010-05-13 03:09:56 +00:00
Mark Andrews 49560ac770 typo in threaded build, silence compiler warning 2010-05-13 03:08:30 +00:00
Automatic Updater 448d93c5e8 update 2010-05-13 01:17:18 +00:00
Automatic Updater 2dbcecfaaa update 2010-05-13 01:16:45 +00:00
Mark Andrews f93222ee85 2888. [bug] Only the first EDNS option was displayed. [RT #21273] 2010-05-13 00:42:26 +00:00
Mark Andrews e18c62b1da 2888. [bug] Only the first EDNS option was displayed. [RT #21273] 2010-05-13 00:40:46 +00:00
Automatic Updater 7a1448aa57 update 2010-05-13 00:21:26 +00:00
Automatic Updater 064dac4abe update 2010-05-13 00:19:48 +00:00
Mark Andrews 92a7fc7c7c 2887. [bug] Report the keytag times in UTC in the .key file,
local time is presented as a comment within the
                        comment.  [RT #21223]

2886.   [bug]           ctime() is not thread safe. [RT #21223]
2010-05-12 23:53:33 +00:00
Automatic Updater 21d9ee0d73 update copyright notice 2010-05-12 23:51:13 +00:00
Automatic Updater 7625198d01 update copyright notice 2010-05-12 23:50:01 +00:00
Mark Andrews 5c40acf215 2887. [bug] Report the keytag times in UTC in the .key file,
local time is presented as a comment within the
                        comment.  [RT #21223]

2886.   [bug]           ctime() is not thread safe. [RT #21223]
2010-05-12 23:49:40 +00:00
Automatic Updater 5666e005bd newcopyrights 2010-05-12 23:31:31 +00:00
Automatic Updater c466590f32 newcopyrights 2010-05-12 23:31:14 +00:00
Automatic Updater 70e41f6536 update 2010-05-12 09:45:07 +00:00
Automatic Updater 3fc5a9f930 update 2010-05-12 09:42:06 +00:00
Mark Andrews 711d4218c4 2885. [bug] Improve -fno-strict-aliasing support probing in
configure. [RT #21080]
2010-05-12 08:25:52 +00:00
Mark Andrews 8b7d3aeda2 2885. [bug] Improve -fno-strict-aliasing support probing in
configure. [RT #21080]
2010-05-12 08:25:21 +00:00
Automatic Updater 7f87e0c4c7 update 2010-05-12 06:20:42 +00:00
Automatic Updater 6c0e2269be update 2010-05-12 06:20:10 +00:00
Mark Andrews fe3db97ee9 2884. [bug] Insufficient valadation in dns_name_getlabelsequence().
[RT #21283]
2010-05-12 05:44:01 +00:00
Mark Andrews f083a44415 2884. [bug] Insufficient valadation in dns_name_getlabelsequence().
[RT #21283]
2010-05-12 05:40:32 +00:00
Automatic Updater 30165893f7 update 2010-05-12 03:20:59 +00:00
Mark Andrews 8f295da232 logo updates 2010-05-12 03:03:45 +00:00
Automatic Updater b72434ce64 update 2010-05-12 02:34:05 +00:00
Automatic Updater d9025d3f48 update 2010-05-12 02:32:27 +00:00
Mark Andrews a6d76b4886 2883. [bug] 'dig +short' failed to handle really large datasets.
[RT #21113]
2010-05-12 01:34:45 +00:00
Mark Andrews 108300f7f1 2883. [bug] 'dig +short' failed to handle really large datasets.
[RT #21113]
2010-05-12 01:31:37 +00:00
Automatic Updater 74cfabb955 update 2010-05-12 01:17:18 +00:00
Automatic Updater 0391c5c44f update 2010-05-12 01:16:39 +00:00
Mark Andrews bb828e2c51 2882. [bug] Remove memory context from list of active contexts
before clearing 'magic'. [RT #21274]
2010-05-12 00:49:31 +00:00
Mark Andrews 2fca4a3321 2882. [bug] Remove memory context from list of active contexts
before clearing 'magic'. [RT #21274]
2010-05-12 00:46:55 +00:00
Automatic Updater 43a0c58e70 update 2010-05-11 00:21:26 +00:00
Automatic Updater 2cb4e94838 update 2010-05-11 00:20:46 +00:00
Automatic Updater a955420bed update copyright notice 2010-05-10 23:50:55 +00:00
Automatic Updater efc6a99370 update copyright notice 2010-05-10 23:49:42 +00:00
Automatic Updater 6ffd34dcf0 newcopyrights 2010-05-10 23:31:53 +00:00
Automatic Updater d3d4428652 newcopyrights 2010-05-10 23:31:12 +00:00
Automatic Updater f52d9bc6f9 update 2010-05-10 02:18:57 +00:00
Automatic Updater 056f9c917a update 2010-05-10 02:18:20 +00:00
Mark Andrews d779f5e15d 2881. [bug] Reduce the amount of time the rbtdb write lock
is held when closing a version. [RT #21198]
2010-05-10 01:41:11 +00:00
Mark Andrews 121f783b66 2881. [bug] Reduce the amount of time the rbtdb write lock
is held when closing a version. [RT #21198]
2010-05-10 01:39:03 +00:00
Automatic Updater 36b08488a1 update 2010-05-07 00:20:51 +00:00
Automatic Updater 8ba4364153 update 2010-05-07 00:19:47 +00:00
Automatic Updater d3798f2bff update copyright notice 2010-05-06 23:50:56 +00:00
Automatic Updater 435add4fdd update copyright notice 2010-05-06 23:49:37 +00:00
Automatic Updater 08e3b67977 newcopyrights 2010-05-06 23:31:27 +00:00
Automatic Updater 6b2090a39f newcopyrights 2010-05-06 23:31:06 +00:00
Automatic Updater 4526d04e04 update 2010-05-06 12:16:55 +00:00
Automatic Updater 5faf500982 update 2010-05-06 12:16:27 +00:00
Mark Andrews f2ae969065 handle revoke changes 2010-05-06 11:28:20 +00:00
Mark Andrews a3eae83762 handle revoke changes 2010-05-06 11:27:38 +00:00
Automatic Updater 9d9805c096 update 2010-05-06 06:21:02 +00:00
Automatic Updater 3fd5ddfd6a update 2010-05-06 06:19:59 +00:00
Mark Andrews 1c21efedfe 2880. [cleanup] Make the output of dnssec-keygen and dnssec-revoke
consistent. [RT #21078]
2010-05-06 05:32:56 +00:00
Mark Andrews 707d9fbd86 2880. [cleanup] Make the output of dnssec-keygen and dnssec-revoke
consistent. [RT #21078]
2010-05-06 05:31:19 +00:00
Automatic Updater abe0aa7baa update 2010-05-06 00:21:02 +00:00
Automatic Updater 09eff142e8 update 2010-05-06 00:19:48 +00:00
Automatic Updater fbfdea68e4 newcopyrights 2010-05-05 23:31:49 +00:00
Automatic Updater ea069464d5 newcopyrights 2010-05-05 23:31:30 +00:00
Automatic Updater b1dff14a06 auto update 2010-05-05 23:19:27 +00:00
Automatic Updater 1acd60951d update 2010-05-05 13:17:34 +00:00
Automatic Updater 2b76d22baf update 2010-05-05 13:17:05 +00:00
Mark Andrews a5796bf961 2879. [contrib] DLZ bdbhpt driver fails to close correct cursor.
[RT #21106]
2010-05-05 12:41:23 +00:00
Mark Andrews bb9298e008 2879. [contrib] DLZ bdbhpt driver fails to close correct cursor.
[RT #21106]
2010-05-05 12:39:41 +00:00
Automatic Updater a6e12d97a4 auto update 2010-05-04 23:18:54 +00:00
Automatic Updater db28b5db67 auto update 2010-05-03 23:19:42 +00:00
Automatic Updater 8fc1064130 update 2010-04-29 00:21:06 +00:00
Automatic Updater b780afe5f7 update 2010-04-29 00:19:33 +00:00
Automatic Updater b98844704e update copyright notice 2010-04-28 23:50:51 +00:00
Automatic Updater 70e94a99a6 update copyright notice 2010-04-28 23:49:34 +00:00
Automatic Updater 7b9099f4f2 auto update 2010-04-28 23:19:18 +00:00
Automatic Updater 72d4d83e2a update 2010-04-28 11:17:02 +00:00
Automatic Updater 5d43557478 update 2010-04-28 11:16:33 +00:00
Mark Andrews 01206bd597 2878. [func] Incrementally write the master file after performing
a AXFR.  [RT #21010]
(part 2)
2010-04-28 11:03:45 +00:00
Mark Andrews 6ab18ae52c 2878. [func] Incrementally write the master file after performing
a AXFR.  [RT #21010]
(part 2)
2010-04-28 11:03:07 +00:00
Automatic Updater 97137e17ff update 2010-04-27 04:21:54 +00:00
Automatic Updater 0958becf7e update 2010-04-27 04:20:43 +00:00
Mark Andrews ed840b1045 2878. [func] Incrementally write the master file after performing
a AXFR.  [RT #21010]
2010-04-27 03:26:34 +00:00
Mark Andrews 1df2b7edfe 2878. [func] Incrementally write the master file after performing
a AXFR.  [RT #21010]
2010-04-27 03:24:52 +00:00
Automatic Updater 0932d830f0 update 2010-04-22 00:20:17 +00:00
Automatic Updater 9100c2db3b update 2010-04-22 00:19:18 +00:00
Automatic Updater ed2fa6ce1b update copyright notice 2010-04-21 23:51:22 +00:00
Automatic Updater 63412b419b update copyright notice 2010-04-21 23:50:05 +00:00
Automatic Updater 0098207a9a newcopyrights 2010-04-21 23:31:32 +00:00
Automatic Updater 3f95fa336e newcopyrights 2010-04-21 23:31:14 +00:00
Automatic Updater 21c0dce246 update 2010-04-21 06:17:53 +00:00
Automatic Updater ebc813c9cf update 2010-04-21 06:17:32 +00:00
Mark Andrews 05addc4e62 2877. [bug] The validator failed to skip obviously mismatching
RRSIGs. [RT #21138]
2010-04-21 05:47:29 +00:00
Mark Andrews fd95cc0da9 2877. [bug] The validator failed to skip obviously mismatching
RRSIGs. [RT #21138]
2010-04-21 05:45:47 +00:00
Automatic Updater ac897ce3b9 update 2010-04-21 05:18:01 +00:00
Automatic Updater cf4f3cbdaa update 2010-04-21 05:17:46 +00:00
Mark Andrews 7005c5aa84 2876. [bug] Named could return SERVFAIL for negative responses
from unsigned zones. [RT #21131]
2010-04-21 04:20:22 +00:00
Mark Andrews bb6d33103e 2876. [bug] Named could return SERVFAIL for negative responses
from unsigned zones. [RT #21131]
2010-04-21 04:16:49 +00:00
Automatic Updater 426848b63c update 2010-04-21 03:22:36 +00:00
Automatic Updater 70c8087f2d update 2010-04-21 03:21:47 +00:00
Automatic Updater 428539b1c9 sync 2010-04-21 02:28:38 +00:00
Mark Andrews 7b63825d03 2875. [bug] dns_time64_fromtext() could accept non digits.
[RT #21033]
2010-04-21 02:22:46 +00:00
Mark Andrews cc6d67469c 2875. [bug] dns_time64_fromtext() could accept non digits.
[RT #21033]
2010-04-21 02:21:31 +00:00
Automatic Updater 592a269a64 update 2010-04-21 01:17:14 +00:00
cvs2git 414302b95c This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-04-21 00:43:03 +00:00
Mark Andrews 7fb2b51201 new draft 2010-04-21 00:42:57 +00:00
Automatic Updater f6034c5012 update 2010-04-21 00:21:17 +00:00
Automatic Updater 421abc0d01 update 2010-04-21 00:20:37 +00:00
Automatic Updater 0a199807e7 update copyright notice 2010-04-20 23:51:12 +00:00
Automatic Updater 03d50bfec1 update copyright notice 2010-04-20 23:49:58 +00:00
Automatic Updater 644973f327 newcopyrights 2010-04-20 23:31:42 +00:00
Automatic Updater fe28c38a24 update 2010-04-20 20:16:49 +00:00
Rob Austein 0c23dd6c9c Add contact information to copyright page, fix page style and
numbering for copyright page and table of contents.
2010-04-20 19:16:48 +00:00
Automatic Updater 804754e626 update 2010-04-20 08:20:07 +00:00
Automatic Updater 3b1372a22b update 2010-04-20 08:19:19 +00:00
Mark Andrews e104ca4071 2874. [bug] Cache lack of EDNS support only after the server
successfully responds to the query using plain DNS.
                        [RT #20930]
2010-04-20 07:32:51 +00:00
Mark Andrews 1e9848fb2b 2874. [bug] Cache lack of EDNS support only after the server
successfully responds to the query using plain DNS.
                        [RT #20930]
2010-04-20 07:28:52 +00:00
Automatic Updater 7ac3315851 update 2010-04-20 03:21:43 +00:00
Rob Austein b008ad3de2 Update logo 2010-04-20 02:30:06 +00:00
Automatic Updater f603422ae3 auto update 2010-04-15 23:19:43 +00:00
Automatic Updater 71dc0e9e72 update 2010-04-14 22:16:42 +00:00
Automatic Updater 58394f5b6f update 2010-04-14 22:16:17 +00:00
Tatuya JINMEI 神明達哉 bc4ffe7eaf 2873. [bug] Canceling a dynamic update via the dns/client module
could trigger an assertion failure. [RT #21133]

9.8.0 and 9.7.1
2010-04-14 22:10:04 +00:00
Tatuya JINMEI 神明達哉 c45d848e2a 2873. [bug] Canceling a dynamic update via the dns/client module
could trigger an assertion failure. [RT #21133]
2010-04-14 22:08:47 +00:00
Automatic Updater bf766b1599 update 2010-04-14 00:20:45 +00:00
Automatic Updater 16fb327e1b update 2010-04-14 00:18:54 +00:00
Automatic Updater 0abd3cca60 update copyright notice 2010-04-13 23:50:58 +00:00
Automatic Updater 4bb846d522 update copyright notice 2010-04-13 23:49:44 +00:00
Automatic Updater e77e6219d3 newcopyrights 2010-04-13 23:31:32 +00:00
Automatic Updater 253087fcaa newcopyrights 2010-04-13 23:31:13 +00:00
Automatic Updater ee0be9c2a0 auto update 2010-04-13 23:19:30 +00:00
Automatic Updater 247488ff07 update 2010-04-13 20:16:30 +00:00
Automatic Updater 73b2849f2a update 2010-04-13 19:17:27 +00:00
Shawn Routhier ef4f584745 Modify dns/client.c:dns_clinet_createx() to only require one of IPv4 or
IPv6 rather than both.  [RT #21122]
2010-04-13 19:15:56 +00:00
Shawn Routhier 7dc38ccd52 Modify dns/client.c:dns_client_createx() to only require one of IPv6 or
IPv6 rather than both.  [RT #21122]
2010-04-13 19:06:48 +00:00
Automatic Updater 80ef7645ff update 2010-04-10 03:20:13 +00:00
Automatic Updater fadff54087 sync 2010-04-10 02:37:15 +00:00
Automatic Updater 95a5f28754 update 2010-04-10 00:20:55 +00:00
Automatic Updater aff1c988a4 update 2010-04-10 00:19:13 +00:00
Automatic Updater 127e1bde3a update copyright notice 2010-04-09 23:51:01 +00:00
Automatic Updater 6d30079412 update copyright notice 2010-04-09 23:49:48 +00:00
Automatic Updater 8f1b19fb7e newcopyrights 2010-04-09 23:31:25 +00:00
Automatic Updater c6704835aa newcopyrights 2010-04-09 23:31:04 +00:00
Automatic Updater 55b4b92b8f update 2010-04-09 07:27:39 +00:00
Automatic Updater 93afb677c0 update 2010-04-09 06:20:53 +00:00
Tatuya JINMEI 神明達哉 1b4ca70d35 2871. [bug] Type mismatch in mem_api.c between the definition and
the header file, causing build failure with
			--enable-exportlib. [RT #21138]

9.8.0 and 9.7.1.
2010-04-09 06:20:35 +00:00
Tatuya JINMEI 神明達哉 ce164dbd9c 2871. [bug] Type mismatch in mem_api.c between the definition and
the header file, causing build failure with
			--enable-exportlib. [RT #21138]

9.8.0 and 9.7.1.
2010-04-09 06:09:35 +00:00
Automatic Updater a821347c7f update 2010-04-09 02:18:23 +00:00
cvs2git 4a9cce26cd This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-04-09 02:07:36 +00:00
Mark Andrews c854efc784 new draft 2010-04-09 02:07:30 +00:00
Automatic Updater fdb544b336 auto update 2010-04-08 23:18:57 +00:00
Automatic Updater 33497e72d0 update 2010-04-08 00:21:15 +00:00
Automatic Updater 3e0c546e3b update 2010-04-08 00:20:26 +00:00
Automatic Updater f15cde2b63 update copyright notice 2010-04-07 23:51:06 +00:00
Automatic Updater 85465e7616 update copyright notice 2010-04-07 23:49:51 +00:00
Automatic Updater 2178b22c8f newcopyrights 2010-04-07 23:31:42 +00:00
Automatic Updater 1b47e4478f newcopyrights 2010-04-07 23:31:19 +00:00
Automatic Updater c2020d90fb update 2010-04-07 07:28:53 +00:00
Automatic Updater 8b0294d5fe update 2010-04-07 07:27:21 +00:00
Mark Andrews c6217b2899 s/addresses/address/ 2010-04-07 07:13:09 +00:00
Mark Andrews c449fbf343 s/addresses/address/ 2010-04-07 07:12:29 +00:00
Mark Andrews c89c2619cb 2870. [maint] Add AAAA addresses for L.ROOT-SERVERS.NET. 2010-04-07 07:08:52 +00:00
Mark Andrews 86077a2e87 2870. [maint] Add AAAA addresses for L.ROOT-SERVERS.NET. 2010-04-07 07:05:38 +00:00
Automatic Updater f952eb45cc update 2010-04-02 03:20:29 +00:00
Automatic Updater ee034830da sync 2010-04-02 02:28:41 +00:00
Automatic Updater b254e67fd1 update 2010-04-01 14:16:45 +00:00
cvs2git 91bcd9e3a0 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-04-01 13:32:36 +00:00
Mark Andrews 2c6198111f new draft 2010-04-01 13:32:30 +00:00
Automatic Updater 1b9ebde1c3 update 2010-04-01 03:20:56 +00:00
Automatic Updater e9e30a8196 sync 2010-04-01 02:29:00 +00:00
Automatic Updater 35baf2aace update 2010-03-31 04:20:53 +00:00
cvs2git 666abd5c09 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-03-31 04:12:26 +00:00
Mark Andrews c94f40fc0a new draft 2010-03-31 04:12:20 +00:00
Automatic Updater cf582b8729 update 2010-03-27 03:20:30 +00:00
Automatic Updater 54d78b4325 sync 2010-03-27 02:29:10 +00:00
Automatic Updater 2e790f9762 update 2010-03-26 18:17:05 +00:00
Mark Andrews 314b6614cb 2869. [bug] Fix arguments to dns_keytable_findnextkeynode() call.
[RT #20877]
2010-03-26 17:18:05 +00:00
Automatic Updater 8391ea7dd9 update 2010-03-26 17:16:49 +00:00
Mark Andrews b8d036c434 2869. [bug] Fix arguments to dns_keytable_findnextkeynode() call.
[RT #20877]
2010-03-26 17:12:48 +00:00
cvs2git 54bfb51dd8 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-03-26 16:35:13 +00:00
Mark Andrews b1fa56e8da new draft 2010-03-26 16:35:07 +00:00
Automatic Updater 51ed1b13d3 update 2010-03-26 03:20:21 +00:00
Automatic Updater efc9a1d6db sync 2010-03-26 02:29:10 +00:00
Automatic Updater ce7c7cb24d update 2010-03-25 22:16:44 +00:00
cvs2git d5c454aff6 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-03-25 21:48:17 +00:00
Mark Andrews 26351a2c19 new draft 2010-03-25 21:48:11 +00:00
Automatic Updater c2014ab592 update 2010-03-24 03:20:25 +00:00
Automatic Updater bde4e0e663 sync 2010-03-24 02:33:05 +00:00
Automatic Updater 0e38f474fc update 2010-03-23 08:21:16 +00:00
cvs2git 62e9bef633 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-03-23 08:13:48 +00:00
Mark Andrews 8d02d21009 new draft 2010-03-23 08:13:42 +00:00
Mark Andrews b24330955a new draft 2010-03-23 07:58:26 +00:00
Automatic Updater e2c5a3e25b update 2010-03-19 00:20:56 +00:00
Automatic Updater 2e908bf62a update 2010-03-19 00:20:08 +00:00
Automatic Updater 7da0a5ddc6 update copyright notice 2010-03-18 23:50:57 +00:00
Automatic Updater b0f519e7a8 update copyright notice 2010-03-18 23:49:49 +00:00
Automatic Updater bb43709356 newcopyrights 2010-03-18 23:31:45 +00:00
Automatic Updater 106ff8cce0 newcopyrights 2010-03-18 23:31:28 +00:00
Automatic Updater 8997cd5560 update 2010-03-18 14:17:17 +00:00
Automatic Updater 80db127967 update 2010-03-18 14:16:54 +00:00
Mark Andrews f666841997 regen 2010-03-18 13:32:35 +00:00
Mark Andrews 533d473b7d 2868. [cleanup] Run "make clean" at the end of configure to ensure
any changes made by configure are integrated.
                        Use --with-make-clean=no to disable.  [RT #20994]
2010-03-18 13:32:16 +00:00
Mark Andrews c4e59874fb regen 2010-03-18 13:30:36 +00:00
Mark Andrews 003fd2f720 2868. [cleanup] Run "make clean" at the end of configure to ensure
any changes made by configure are integrated.
                        Use --with-make-clean=no to disable.  [RT #20994]
2010-03-18 13:28:32 +00:00
Automatic Updater 0e52c6229b update 2010-03-17 03:20:19 +00:00
Automatic Updater 2ec7565474 sync 2010-03-17 02:28:21 +00:00
Automatic Updater e63dcf7530 auto update 2010-03-16 23:18:38 +00:00
Automatic Updater daa021383a update 2010-03-16 01:16:29 +00:00
cvs2git 5f17ed0d9b This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-03-16 01:09:26 +00:00
Mark Andrews 49eadb2f98 new draft 2010-03-16 01:09:20 +00:00
Automatic Updater 873dc64585 auto update 2010-03-15 23:19:51 +00:00
Automatic Updater 8f3a7f332a update 2010-03-13 00:21:01 +00:00
Automatic Updater b2f0fad78f update 2010-03-13 00:19:22 +00:00
Automatic Updater 230987e819 update copyright notice 2010-03-12 23:51:11 +00:00
Automatic Updater 3fe2c091cc update copyright notice 2010-03-12 23:49:56 +00:00
Automatic Updater 957a8884fb newcopyrights 2010-03-12 23:31:28 +00:00
Automatic Updater acdcd2b694 newcopyrights 2010-03-12 23:31:08 +00:00
Automatic Updater bf685734ec auto update 2010-03-12 23:19:25 +00:00
Automatic Updater d32a806351 update 2010-03-12 04:20:46 +00:00
Automatic Updater 3e48ba0dbc update 2010-03-12 04:20:04 +00:00
Mark Andrews 7f3d57dda8 2867. [bug] Don't set GSS_C_SEQUENCE_FLAG as Windows DNS servers
don't like it.  [RT #20986]
2010-03-12 03:49:19 +00:00
Mark Andrews a80d26914a 2867. [bug] Don't set GSS_C_SEQUENCE_FLAG as Windows DNS servers
don't like it.  [RT #20986]
2010-03-12 03:47:08 +00:00
Mark Andrews c08a0ebc07 2866. [bug] Windows does not like the TSIG name being compressed.
[RT #20986]
2010-03-12 03:37:20 +00:00
Mark Andrews c19f322914 2866. [bug] Windows does not like the TSIG name being compressed.
[RT #20986]
2010-03-12 03:34:56 +00:00
Mark Andrews 0ee3a9dadd 2865. [bug] memset to zero event.data. [RT #20986] 2010-03-12 03:25:20 +00:00
Mark Andrews ff9301990d 2865. [bug] memset to zero event.data. [RT #20986] 2010-03-12 03:22:57 +00:00
Automatic Updater f3c46d66e3 update 2010-03-12 02:19:48 +00:00
Automatic Updater 4be2f76938 update 2010-03-12 02:18:53 +00:00
Mark Andrews 02d3754d1e 2864. [bug] Direct SIG/RRSIG queries were not handled correctly.
[RT #21050]
2010-03-12 02:00:58 +00:00
Mark Andrews fa2cb8d61d 2864. [bug] Direct SIG/RRSIG queries were not handled correctly.
[RT #21050]
2010-03-12 01:48:35 +00:00
Automatic Updater d24d074ee4 update 2010-03-11 05:17:45 +00:00
Automatic Updater 659826ba3e update 2010-03-11 05:17:27 +00:00
Mark Andrews e6ab0dd2ca 2863. [port] linux: disable IPv6 PMTUD and use network minimum MTU.
[RT #21056]
2010-03-11 04:45:10 +00:00
Mark Andrews 08fb52ec8c 2863. [port] linux: disable IPv6 PMTUD and use network minimum MTU.
[RT #21056]
2010-03-11 04:43:57 +00:00
Automatic Updater b9df4728f1 auto update 2010-03-10 23:19:27 +00:00
Automatic Updater 8da33254f4 update 2010-03-10 03:22:17 +00:00
Automatic Updater f6e4558074 update 2010-03-10 03:20:54 +00:00
Automatic Updater 7b2366db70 regen v9_7 2010-03-10 02:41:46 +00:00
Mark Andrews 9c511a0dc7 cast isc_buffer_usedlength() to (int) 2010-03-10 02:19:08 +00:00
Mark Andrews 9537e40e79 cast isc_buffer_usedlength() to (int) 2010-03-10 02:17:52 +00:00
Automatic Updater 58416c69a3 update 2010-03-10 01:16:34 +00:00
Automatic Updater 83f43b00a5 regen HEAD 2010-03-10 01:14:18 +00:00
Automatic Updater 7354bb18cf update 2010-03-10 00:21:03 +00:00
Automatic Updater f383f03df7 update 2010-03-10 00:19:11 +00:00
Automatic Updater 3767befe3a update copyright notice 2010-03-09 23:51:06 +00:00
Automatic Updater 239618e700 update copyright notice 2010-03-09 23:49:56 +00:00
Automatic Updater 58be84825d newcopyrights 2010-03-09 23:31:36 +00:00
Automatic Updater 2f884b27c2 newcopyrights 2010-03-09 23:31:16 +00:00
Automatic Updater 27eb2ffd3b update 2010-03-09 04:21:01 +00:00
Automatic Updater 247daab1a7 update 2010-03-09 04:20:01 +00:00
Mark Andrews d938014328 2862. [bug] nsupdate didn't default to the parent zone when
updating DS records. [RT #20896]
2010-03-09 03:47:21 +00:00
Mark Andrews 64c43af4f4 2862. [bug] nsupdate didn't default to the parent zone when
updating DS records. [RT #20896]
2010-03-09 03:46:12 +00:00
Mark Andrews 261995c57e 2861. [doc] dnssec-settime man pages didn't correctly document the
inactivation time. [RT #21039]

2860.   [bug]           named-checkconf's usage was out of date. [RT #21039]
2010-03-09 03:40:01 +00:00
Mark Andrews c5259c013b 2861. [doc] dnssec-settime man pages didn't correctly document the
inactivation time. [RT #21039]

2860.   [bug]           named-checkconf's usage was out of date. [RT #21039]
2010-03-09 03:38:18 +00:00
Automatic Updater 7bf3739b88 update 2010-03-09 03:33:08 +00:00
Automatic Updater f4d60f891f sync 2010-03-09 02:29:19 +00:00
Automatic Updater 3f42eeb121 update 2010-03-08 23:16:45 +00:00
cvs2git b0e6be3355 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-03-08 22:17:09 +00:00
Mark Andrews 39158a4c93 new draft 2010-03-08 22:17:03 +00:00
Automatic Updater 2c244f981f update 2010-03-08 01:16:27 +00:00
Mark Andrews 0a1d6361d8 new draft 2010-03-08 01:04:29 +00:00
Automatic Updater b12035d190 auto update 2010-03-06 23:19:03 +00:00
Automatic Updater 44c5f7fe76 update 2010-03-06 06:27:34 +00:00
Automatic Updater 99da34a4bf update 2010-03-06 06:26:53 +00:00
Mark Andrews ce0a4906ad spelling 2010-03-06 05:35:50 +00:00
Mark Andrews ba4f254aa9 spelling 2010-03-06 05:34:02 +00:00
Mark Andrews cec94b0eeb change numbers 2010-03-06 05:28:10 +00:00
Mark Andrews 637a4234fa change numbers 2010-03-06 05:25:36 +00:00
Automatic Updater a5c06c85fa update 2010-03-05 04:21:39 +00:00
Automatic Updater da32ac49ce update 2010-03-05 04:20:19 +00:00
Mark Andrews 3942243c5d change numbers 2010-03-05 03:40:06 +00:00
Mark Andrews 5e95cf76e4 change numbers 2010-03-05 03:36:42 +00:00
Automatic Updater 690a5f9158 update 2010-03-05 01:16:46 +00:00
Automatic Updater 6c8a888822 regen HEAD 2010-03-05 01:14:15 +00:00
Automatic Updater 5488182a69 update 2010-03-05 00:20:54 +00:00
Automatic Updater 44012dd60d update 2010-03-05 00:20:23 +00:00
Automatic Updater 4d42b714be update copyright notice 2010-03-04 23:50:34 +00:00
Automatic Updater f51de9fb15 update copyright notice 2010-03-04 23:49:20 +00:00
Automatic Updater 129090f0f6 newcopyrights 2010-03-04 23:32:07 +00:00
Automatic Updater 2351787aa6 newcopyrights 2010-03-04 23:31:36 +00:00
Automatic Updater 4db00f967f update 2010-03-04 23:17:30 +00:00
Automatic Updater 8d90748586 update 2010-03-04 23:17:17 +00:00
Mark Andrews 40b08512c4 2958. [bug] When canceling validation it was possible to leak
memory. [RT #20800]
2010-03-04 22:28:40 +00:00
Mark Andrews 22c4126ba5 2958. [bug] When canceling validation it was possible to leak
memory. [RT #20800]
2010-03-04 22:25:31 +00:00
Automatic Updater 017032bb4b update 2010-03-04 21:17:24 +00:00
Automatic Updater 71d4ae3fd0 update 2010-03-04 21:17:07 +00:00
Mark Andrews 56c2c3835f 10.53.0.1 through 10.53.0.5 -> 10.53.0.1 through 10.53.0.7 2010-03-04 20:34:16 +00:00
Mark Andrews bc12bc0a1f 10.53.0.1 through 10.53.0.5 -> 10.53.0.1 through 10.53.0.7 2010-03-04 20:32:54 +00:00
Automatic Updater fa291c34fb update 2010-03-04 07:17:29 +00:00
Automatic Updater 850e3057ed update 2010-03-04 07:17:10 +00:00
Mark Andrews a3c95f281a 2957. [bug] RTT estimates were not being adjusted on ICMP errors.
[RT #20772]
2010-03-04 06:48:31 +00:00
Mark Andrews b1003ace6f 2957. [bug] RTT estimates were not being adjusted on ICMP errors.
[RT #20772]
2010-03-04 06:43:21 +00:00
Automatic Updater d8c9997a13 update 2010-03-04 06:22:28 +00:00
Automatic Updater bf54a8b514 update 2010-03-04 06:20:36 +00:00
Mark Andrews 2473968416 2956. [bug] named-checkconf did not fail on a bad trusted key.
[RT #20705]
2010-03-04 06:19:33 +00:00
Mark Andrews 92348098eb 2956. [bug] named-checkconf did not fail on a bad trusted key.
[RT #20705]
2010-03-04 06:17:01 +00:00
Mark Andrews f7033a3346 2955. [bug] The size of a memory allocation was not always properly
recorded. [RT #20927]
2010-03-04 05:48:50 +00:00
Mark Andrews 5388178e8a 2955. [bug] The size of a memory allocation was not always properly
recorded. [RT #20927]
2010-03-04 05:45:51 +00:00
Mark Andrews 41094cee0b 2955. [bug] The size of a memory allocation was not always properly
recorded. [RT #20927]
2010-03-04 05:31:22 +00:00
Mark Andrews d1a5fdc34a 2955. [bug] The size of a memory allocation was not always properly
recorded. [RT #20927]
2010-03-04 05:29:15 +00:00
Mark Andrews 2e20dea9fc 2854. [func] nsupdate will now preserve the entered case of domain
names in update requests it sends. [RT #20928]
2010-03-04 05:24:56 +00:00
Mark Andrews 13396661f4 2854. [func] dig: allow the final soa record in a axfr response to
be suppressed, dig +onesoa. [RT #20929]
2010-03-04 05:18:04 +00:00
Automatic Updater ddab8bd093 auto update 2010-03-03 23:18:09 +00:00
Automatic Updater f16199c056 update 2010-03-03 22:24:05 +00:00
Automatic Updater 0f2d3b866b update 2010-03-03 22:22:09 +00:00
Automatic Updater b8cfef5271 newcopyrights 2010-03-03 22:14:27 +00:00
Automatic Updater 2b7197054f newcopyrights 2010-03-03 22:14:05 +00:00
Automatic Updater ad0a222ec0 update 2010-03-03 07:17:00 +00:00
Mark Andrews 6e08e9d982 dns_rdataset_expire/dns_rdataset_settrust 2010-03-03 06:57:06 +00:00
Automatic Updater 3083bd21de update 2010-03-03 05:17:54 +00:00
Automatic Updater 02e9bb7bf8 update 2010-03-03 05:17:37 +00:00
Mark Andrews 6f8edd57ae dns_resolver_*badcache 2010-03-03 05:13:53 +00:00
Mark Andrews c76ae1723f dns_rdataset_expire/dns_rdataset_settrust 2010-03-03 05:11:45 +00:00
Mark Andrews 69c3b7fd9d dns_resolver_*badcache 2010-03-03 04:56:20 +00:00
Automatic Updater d7f6bf262e update 2010-03-01 02:18:59 +00:00
Automatic Updater bea427cebd sync 2010-03-01 02:18:08 +00:00
Automatic Updater ae905b0ae1 update 2010-03-01 00:20:37 +00:00
cvs2git 9e057920ce This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-02-28 23:44:04 +00:00
Mark Andrews ac0680e9eb new draft 2010-02-28 23:43:58 +00:00
Automatic Updater 7a671773f2 update 2010-02-27 03:20:46 +00:00
Automatic Updater 87d4ee6113 update 2010-02-27 02:19:15 +00:00
Automatic Updater e474b9e989 sync 2010-02-27 02:18:13 +00:00
Automatic Updater 2b5eae2b09 update 2010-02-27 00:20:34 +00:00
Automatic Updater 01ded85842 update 2010-02-27 00:19:25 +00:00
Automatic Updater cc9ed75dd9 update copyright notice 2010-02-26 23:50:59 +00:00
Automatic Updater b1416abab6 update copyright notice 2010-02-26 23:49:47 +00:00
Automatic Updater bf9b61c790 newcopyrights 2010-02-26 23:31:31 +00:00
Automatic Updater a179df7937 newcopyrights 2010-02-26 23:31:06 +00:00
Automatic Updater 13c1b482dd update 2010-02-26 03:35:27 +00:00
cvs2git 71b0add384 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-02-26 02:36:49 +00:00
Mark Andrews ac89fac641 new draft 2010-02-26 02:36:44 +00:00
Automatic Updater 96769258cb update 2010-02-26 02:21:21 +00:00
Automatic Updater db8b916444 update 2010-02-26 02:20:33 +00:00
Mark Andrews 46ef4ef03a 2853. [bug] add_sigs() could run out of scratch space. [RT #21015] 2010-02-26 01:50:39 +00:00
Mark Andrews 64f8608ed6 2853. [bug] add_sigs() could run out of scratch space. [RT #21015] 2010-02-26 01:39:49 +00:00
Automatic Updater f4b095c42e update 2010-02-26 01:16:58 +00:00
Automatic Updater d1f2b629d4 update 2010-02-26 01:16:38 +00:00
Mark Andrews 330d764d3b grab a write lock before updating header->trust 2010-02-26 00:23:12 +00:00
Mark Andrews 8b026a66fd grab a write lock before updating header->trust 2010-02-26 00:18:06 +00:00
Automatic Updater 7788acb1ab auto update 2010-02-25 23:19:28 +00:00
Automatic Updater 2cd05e5976 update 2010-02-25 13:16:12 +00:00
Automatic Updater 3cea95052a regen v9_7 2010-02-25 12:30:09 +00:00
Automatic Updater 20c68c9993 update 2010-02-25 11:20:40 +00:00
Automatic Updater 49853562e2 regen HEAD 2010-02-25 11:13:38 +00:00
Automatic Updater ac7ef3ec32 update 2010-02-25 06:18:37 +00:00
Automatic Updater e1bd9f2ed3 update copyright notice 2010-02-25 05:25:53 +00:00
Automatic Updater f5d0b9895b update 2010-02-25 05:21:13 +00:00
Automatic Updater 2fad51aae1 update 2010-02-25 05:18:40 +00:00
Automatic Updater 9745e31cb8 newcopyrights 2010-02-25 05:13:55 +00:00
Automatic Updater bd2b08d5a3 update copyright notice 2010-02-25 05:08:01 +00:00
Automatic Updater 8ce46dbe07 update copyright notice 2010-02-25 05:06:35 +00:00
Mark Andrews 8a98023414 2852. [bug] Handle broken DNSSEC trust chains better. [RT #15619] 2010-02-25 05:05:09 +00:00
Automatic Updater 233f603cc1 newcopyrights 2010-02-25 05:02:02 +00:00
Mark Andrews 0cae66577c 2852. [bug] Handle broken DNSSEC trust chains better. [RT #15619] 2010-02-25 04:39:13 +00:00
Automatic Updater 507806f969 update 2010-02-25 02:18:57 +00:00
Automatic Updater 8f79637669 sync 2010-02-25 01:56:13 +00:00
Automatic Updater dea0471d46 update 2010-02-25 00:19:29 +00:00
Automatic Updater 026483186a update 2010-02-25 00:18:24 +00:00
Automatic Updater 906effb54f newcopyrights 2010-02-24 23:30:34 +00:00
cvs2git 9544bc192d This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-02-24 23:21:08 +00:00
Mark Andrews efa22d3d71 new draft 2010-02-24 23:21:03 +00:00
Automatic Updater 23beef88a9 update 2010-02-24 02:17:29 +00:00
Automatic Updater 1c5db966aa sync 2010-02-24 01:55:49 +00:00
Mark Andrews 6ad40b3a85 2850. [bug] If isc_heap_insert() failed due to memory shortage
the heap would have corrupted entries. [RT #20951]
2010-02-24 01:46:55 +00:00
Automatic Updater 6b5ba346d0 update 2010-02-23 02:17:39 +00:00
Automatic Updater b469d5cc62 update 2010-02-23 02:17:01 +00:00
Automatic Updater aef8f792fb regen v9_7 2010-02-23 02:09:20 +00:00
cvs2git e8474de3ea This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-02-23 01:32:47 +00:00
Mark Andrews 3ab7336ea7 new draft 2010-02-23 01:32:42 +00:00
Automatic Updater 43048c7f74 update 2010-02-23 01:16:44 +00:00
Automatic Updater 680033ce4d regen HEAD 2010-02-23 01:14:31 +00:00
Automatic Updater 397feff56e update 2010-02-23 00:19:59 +00:00
Automatic Updater 53ff7d91a8 update 2010-02-23 00:19:09 +00:00
Automatic Updater 8077efca7d update copyright notice 2010-02-22 23:49:11 +00:00
Automatic Updater 77c3728447 update copyright notice 2010-02-22 23:48:29 +00:00
Automatic Updater 693c4232df newcopyrights 2010-02-22 23:30:43 +00:00
Automatic Updater aa356e53b8 newcopyrights 2010-02-22 23:30:36 +00:00
Automatic Updater d956434b59 update 2010-02-22 22:17:15 +00:00
Mark Andrews 9a27cf1e9d 2851. [doc] nslookup.1, removed <informalexample> from the docbook
source as it produced bad nroff.  [RT #21007]
2010-02-22 21:28:07 +00:00
Automatic Updater aa38b0b73b update 2010-02-22 21:17:01 +00:00
Mark Andrews d3cbd6b05c 2851. [doc] nslookup.1, removed <informalexample> from the docbook
source as it produced bad nroff.  [RT #21007]
2010-02-22 20:48:56 +00:00
Automatic Updater 312a3b089d update 2010-02-22 02:17:41 +00:00
Automatic Updater b846bbd819 update 2010-02-22 02:17:16 +00:00
Mark Andrews f7eb6b70fb .NOTPARALLEL/.NO_PARALLEL 2010-02-22 02:08:42 +00:00
Mark Andrews f56be26f60 .NOTPARALLEL/.NO_PARALLEL 2010-02-22 02:00:07 +00:00
Automatic Updater 4c54be504c update 2010-02-20 02:19:19 +00:00
Automatic Updater b1f36f06ca sync 2010-02-20 01:56:26 +00:00
Automatic Updater d3bf64ad4b update 2010-02-19 10:17:01 +00:00
cvs2git e49bcccfb1 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-02-19 10:12:48 +00:00
Mark Andrews 62ab12711f new draft 2010-02-19 10:12:43 +00:00
Automatic Updater d7097d666b update 2010-02-16 20:16:31 +00:00
Evan Hunt 975f01067b update README to include packet-storm known issue 2010-02-16 19:38:42 +00:00
Automatic Updater 92d0305964 update 2010-02-16 02:17:20 +00:00
Automatic Updater 7da62bfb79 sync 2010-02-16 01:56:22 +00:00
Automatic Updater 4129583cb6 update 2010-02-15 23:16:54 +00:00
cvs2git e5bc7669fd This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-02-15 22:48:33 +00:00
Mark Andrews 79464adea1 new draft 2010-02-15 22:48:28 +00:00
Automatic Updater 4722228b86 auto update 2010-02-11 23:18:07 +00:00
Automatic Updater df7774663c update 2010-02-07 02:17:13 +00:00
Automatic Updater e83e8d39d7 regen v9_7 2010-02-07 02:08:26 +00:00
Automatic Updater 6b92b96bb2 update 2010-02-07 01:16:42 +00:00
Automatic Updater 21a5f882a1 regen HEAD 2010-02-07 01:14:12 +00:00
Automatic Updater 0eec014e5d update 2010-02-07 00:20:03 +00:00
Automatic Updater ea5cfc962a update 2010-02-07 00:18:47 +00:00
Automatic Updater 46da311781 newcopyrights 2010-02-06 23:30:44 +00:00
Automatic Updater e4d9adbd71 newcopyrights 2010-02-06 23:30:32 +00:00
Automatic Updater 36c043703a update 2010-02-06 08:20:43 +00:00
Automatic Updater 72f771ef45 update 2010-02-06 08:19:32 +00:00
Mark Andrews a4b427d4c3 copyright notice 2010-02-06 07:42:44 +00:00
Mark Andrews 52bf33a5bc copyright notice 2010-02-06 07:42:02 +00:00
Mark Andrews 627987d8ff HISTORY 2010-02-06 07:30:20 +00:00
Mark Andrews 3541946aed HISTORY 2010-02-06 07:29:18 +00:00
Automatic Updater 44feb9a567 update 2010-02-06 00:19:53 +00:00
Automatic Updater 08d64f0387 update 2010-02-06 00:18:34 +00:00
Automatic Updater 00a673b03c update 2010-02-05 00:19:45 +00:00
Automatic Updater 13e2c6d8e1 update 2010-02-05 00:19:01 +00:00
Automatic Updater 6f1b350c3a update copyright notice 2010-02-04 23:49:13 +00:00
Automatic Updater 55690c7b8d update copyright notice 2010-02-04 23:48:30 +00:00
Automatic Updater 9a83aa49de update 2010-02-04 23:41:13 +00:00
Automatic Updater d90a737187 update 2010-02-04 23:40:51 +00:00
Evan Hunt 73aa4c1671 copy HISTORY into the windows zip 2010-02-04 23:38:36 +00:00
Evan Hunt 701f97890a copy HISTORY into the windows zip 2010-02-04 23:38:13 +00:00
Evan Hunt 89600e8dd6 Added HISTORY, added pointer to it from README. (Text changes reviewed
by Larissa.)
2010-02-04 23:34:33 +00:00
cvs2git e690855bc3 This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-02-04 23:34:06 +00:00
Evan Hunt b497531c76 Added HISTORY, put a pointer to it in README. (text changes reviewed by
Larissa.)
2010-02-04 23:34:04 +00:00
Automatic Updater 995eaa289b newcopyrights 2010-02-04 23:30:49 +00:00
Automatic Updater fecec879a7 newcopyrights 2010-02-04 23:30:37 +00:00
Tatuya JINMEI 神明達哉 3a28f0dc73 (forgot to add RT#) 2010-02-04 23:23:46 +00:00
Tatuya JINMEI 神明達哉 139cedabf9 2850. [bug] If isc_heap_insert() failed due to memory shortage
the heap would have corrupted entries.

9.8.0, 9.7.1(?), 9.6.2, 9.5.3
(what about 9.4-ESV?)
2010-02-04 23:22:05 +00:00
Automatic Updater 8a29ed59df update 2010-02-04 06:35:19 +00:00
Evan Hunt da45568ba3 Updated for 9.7.0 release. Removed references to README.* files, now
included in ARM.  Added "known issues" section.  Removed historical feature
lists for 9.2.0 through 9.6.0, in the interests of making the overall file
shorter and more directly useful.
2010-02-04 06:32:34 +00:00
Automatic Updater fc819d0bd9 update 2010-02-04 06:20:29 +00:00
Evan Hunt 63f9161f72 prepare for 9.7.0 release 2010-02-04 05:19:29 +00:00
Automatic Updater 734033a05f regen v9_7 2010-02-04 05:15:18 +00:00
Automatic Updater 157ef67688 update 2010-02-04 02:18:36 +00:00
Automatic Updater 6a2827695a regen 2010-02-04 02:08:20 +00:00
Automatic Updater e047f16684 update 2010-02-04 01:16:52 +00:00
Automatic Updater 9ade382800 update 2010-02-04 01:16:27 +00:00
Automatic Updater 44d0f0256f regen 2010-02-04 01:14:17 +00:00
Mark Andrews 7d47e3d387 2849. [bug] Don't treat errors from the xml2 library as fatal.
[RT #20945]
2010-02-04 01:07:32 +00:00
Mark Andrews 8ac908b38a 2849. [bug] Don't treat errors from the xml2 library as fatal.
[RT #20945]
2010-02-04 00:57:25 +00:00
Automatic Updater db95cc18d8 update 2010-02-04 00:20:02 +00:00
Automatic Updater 8b061d7ed2 update 2010-02-04 00:18:23 +00:00
Automatic Updater f1c89cb4f5 update copyright notice 2010-02-03 23:49:07 +00:00
Automatic Updater 91bb55c45d update copyright notice 2010-02-03 23:48:29 +00:00
Automatic Updater 418cc93231 newcopyrights 2010-02-03 23:30:44 +00:00
Automatic Updater aa52ab8208 newcopyrights 2010-02-03 23:30:34 +00:00
Automatic Updater c696c12cff auto update 2010-02-03 23:18:54 +00:00
Automatic Updater e83e226e08 update 2010-02-03 02:17:50 +00:00
Automatic Updater f4e0a6b968 update 2010-02-03 02:17:17 +00:00
Automatic Updater 85166e0140 regen 2010-02-03 02:08:11 +00:00
Evan Hunt 02973df5f2 2848. [doc] Moved README.dnssec, README.libdns, README.pkcs11 and
README.rfc5011 into the ARM. [RT #20899]
2010-02-03 01:32:44 +00:00
cvs2git 17b58ef7ea This commit was manufactured by cvs2git to create branch 'v9_7'. 2010-02-03 01:31:50 +00:00
Evan Hunt 0b24b2d3c4 2848. [doc] Moved README.dnssec, README.libdns, README.pkcs11 and
README.rfc5011 into the ARM. [RT #20899]
2010-02-03 01:31:49 +00:00
Automatic Updater c060401781 update 2010-02-03 01:17:30 +00:00
Automatic Updater d0fd036e37 update 2010-02-03 01:16:40 +00:00
Evan Hunt dcfca6f18d 2847. [cleanup] Corrected usage message in dnssec-settime. [RT #20921] 2010-02-03 01:02:37 +00:00
Evan Hunt 46b40010ae 2847. [cleanup] Corrected usage message in dnssec-settime. [RT #20921] 2010-02-03 01:02:17 +00:00
Automatic Updater 06d38550f3 update 2010-02-01 00:19:46 +00:00
Automatic Updater 63328d4091 update 2010-02-01 00:18:56 +00:00
Automatic Updater aad3d15976 update copyright notice 2010-01-31 23:49:09 +00:00
Automatic Updater 36f7ffd0c9 update copyright notice 2010-01-31 23:48:29 +00:00
Automatic Updater c2e3270948 newcopyrights 2010-01-31 23:30:43 +00:00
Automatic Updater 36b044f81e newcopyrights 2010-01-31 23:30:37 +00:00
Mark Andrews 5968779f4b 2846. [bug] EOF on unix domain sockets was not being handled
correctly. [RT #20731]
2010-01-31 23:23:10 +00:00
Mark Andrews ebaf977ecf 2846. [bug] EOF on unix domain sockets was not being handled
correctly. [RT #20731]
2010-01-31 23:18:03 +00:00
Automatic Updater 834a31a021 auto update 2010-01-29 23:19:07 +00:00
Automatic Updater b43febe8c3 auto update 2010-01-27 23:18:51 +00:00
Automatic Updater 8a7f5ae9a9 update 2010-01-27 20:16:52 +00:00
Automatic Updater 41866eed87 update 2010-01-27 20:16:34 +00:00
Evan Hunt 140cf92b3b sync 2010-01-27 19:19:51 +00:00
Evan Hunt 63171ebb07 clarified message 2010-01-27 19:19:38 +00:00
Evan Hunt 68ea797082 clarified 2010-01-27 19:18:46 +00:00
Automatic Updater 78d46b371f update 2010-01-27 00:20:51 +00:00
Automatic Updater a56df93f31 update 2010-01-27 00:19:04 +00:00
Francis Dupont 875be659a1 RFC 5011 client can crash. [RT #20903] 2010-01-26 23:35:22 +00:00
Francis Dupont 19a62c240d RFC 5011 client can crash. [RT #20903] 2010-01-26 23:33:10 +00:00
Automatic Updater e8f796f8a6 auto update 2010-01-26 23:19:08 +00:00
Automatic Updater 6c2b739c53 update 2010-01-23 02:18:41 +00:00
Automatic Updater 5201210bae regen 2010-01-23 02:07:50 +00:00
Automatic Updater 36f9773b90 update 2010-01-23 01:17:07 +00:00
Automatic Updater 6467699ca4 update 2010-01-23 01:16:46 +00:00
Automatic Updater 4a5d8786ed regen 2010-01-23 01:13:56 +00:00
Mark Andrews 6fb11c619a restore release marker 2010-01-23 00:43:09 +00:00
Mark Andrews 133d92da58 2844. [doc] notify-delay default in ARM was wrong. It should have
been five (5) seconds.
2010-01-23 00:41:51 +00:00
Mark Andrews fd3a378353 2844. [doc] notify-delay default in ARM was wrong. It should have
been five (5) seconds.
2010-01-23 00:33:21 +00:00
Automatic Updater 3ae6ec7ef6 auto update 2010-01-22 23:19:15 +00:00
Automatic Updater 327c37def7 update 2010-01-22 13:17:12 +00:00
Francis Dupont 0185a9358c sync 2010-01-22 12:56:43 +00:00
Automatic Updater a9a7e2f270 update 2010-01-22 02:31:10 +00:00
Evan Hunt c46b6864af fix typo 2010-01-22 01:46:20 +00:00
Evan Hunt da4a8c89a8 remove reference to isc_time member "seconds", which doesn't exist in win32 2010-01-22 01:34:47 +00:00
Automatic Updater e87e7b378a update 2010-01-22 01:00:56 +00:00
Evan Hunt 56334ccb2d update 2010-01-22 00:56:48 +00:00
Evan Hunt 6bb16fca28 rename "ischmacfix" files to "ischmacfixup" so win32 build will work 2010-01-22 00:55:46 +00:00
1929 changed files with 217692 additions and 60718 deletions
-9
View File
@@ -1,9 +0,0 @@
Makefile
config.log
config.h
config.cache
config.status
libtool
isc-config.sh
configure.lineno
autom4te.cache
+50
View File
@@ -0,0 +1,50 @@
Makefile
config.log
config.h
config.cache
config.status
libtool
isc-config.sh
configure.lineno
autom4te.cache
*.o
*.lo
*.so
*.a
*.la
*_test
timestamp
named.run
gen.dSYM/
.libs/
.deps/
.dirstamp
unit/atf-src/atf-c++/atf-c++.pc
unit/atf-src/atf-c/atf-c.pc
unit/atf-src/atf-c/defs.h
unit/atf-src/atf-c/detail/process_helpers
unit/atf-src/atf-config/atf-config
unit/atf-src/atf-report/atf-report
unit/atf-src/atf-report/fail_helper
unit/atf-src/atf-report/misc_helpers
unit/atf-src/atf-report/pass_helper
unit/atf-src/atf-run/atf-run
unit/atf-src/atf-run/bad_metadata_helper
unit/atf-src/atf-run/expect_helpers
unit/atf-src/atf-run/misc_helpers
unit/atf-src/atf-run/pass_helper
unit/atf-src/atf-run/several_tcs_helper
unit/atf-src/atf-run/zero_tcs_helper
unit/atf-src/atf-sh/atf-check
unit/atf-src/atf-sh/atf-sh
unit/atf-src/atf-sh/misc_helpers
unit/atf-src/atf-version/atf-version
unit/atf-src/atf-version/revision.h
unit/atf-src/atf-version/revision.h.stamp
unit/atf-src/bconfig.h
unit/atf-src/bootstrap/atconfig
unit/atf-src/doc/atf.7
unit/atf-src/stamp-h1
unit/atf-src/test-programs/c_helpers
unit/atf-src/test-programs/cpp_helpers
unit/atf-src/test-programs/sh_helpers
+5
View File
@@ -0,0 +1,5 @@
Content-Type: application/X-atf-atffile; version="1"
prop: test-suite = bind9
tp: lib
+1225 -43
View File
File diff suppressed because it is too large Load Diff
+491 -3
View File
@@ -1,4 +1,4 @@
Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
Copyright (C) 2004-2012 Internet Systems Consortium, Inc. ("ISC")
Copyright (C) 1996-2003 Internet Software Consortium.
Permission to use, copy, modify, and/or distribute this software for any
@@ -13,9 +13,15 @@ LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
PERFORMANCE OF THIS SOFTWARE.
$Id: COPYRIGHT,v 1.15.188.1 2010/01/04 23:48:10 tbox Exp $
$Id: COPYRIGHT,v 1.15.188.4 2012/01/04 23:45:52 tbox Exp $
Portions Copyright (C) 1996-2001 Nominum, Inc.
Portions of this code release fall under one or more of the
following Copyright notices. Please see individual source
files for details.
For binary releases also see: OpenSSL-LICENSE.
Copyright (C) 1996-2001 Nominum, Inc.
Permission to use, copy, modify, and distribute this software for any
purpose with or without fee is hereby granted, provided that the above
@@ -28,3 +34,485 @@ ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT
OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
-----------------------------------------------------------------------------
Copyright (C) 1995-2000 by Network Associates, Inc.
Permission to use, copy, modify, and/or distribute this software for any
purpose with or without fee is hereby granted, provided that the above
copyright notice and this permission notice appear in all copies.
THE SOFTWARE IS PROVIDED "AS IS" AND ISC AND NETWORK ASSOCIATES DISCLAIMS
ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED
WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE
FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR
IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
-----------------------------------------------------------------------------
Copyright (C) 2002 Stichting NLnet, Netherlands, stichting@nlnet.nl.
Permission to use, copy, modify, and distribute this software for any
purpose with or without fee is hereby granted, provided that the
above copyright notice and this permission notice appear in all
copies.
THE SOFTWARE IS PROVIDED "AS IS" AND STICHTING NLNET
DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
STICHTING NLNET BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR
CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS
OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE
USE OR PERFORMANCE OF THIS SOFTWARE.
The development of Dynamically Loadable Zones (DLZ) for Bind 9 was
conceived and contributed by Rob Butler.
Permission to use, copy, modify, and distribute this software for any
purpose with or without fee is hereby granted, provided that the
above copyright notice and this permission notice appear in all
copies.
THE SOFTWARE IS PROVIDED "AS IS" AND ROB BUTLER
DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
ROB BUTLER BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR
CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS
OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE
USE OR PERFORMANCE OF THIS SOFTWARE.
-----------------------------------------------------------------------------
Copyright (c) 1987, 1990, 1993, 1994
The Regents of the University of California. All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions
are met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.
3. All advertising materials mentioning features or use of this software
must display the following acknowledgement:
This product includes software developed by the University of
California, Berkeley and its contributors.
4. Neither the name of the University nor the names of its contributors
may be used to endorse or promote products derived from this software
without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
SUCH DAMAGE.
-----------------------------------------------------------------------------
Copyright (C) The Internet Society 2005. This version of
this module is part of RFC 4178; see the RFC itself for
full legal notices.
(The above copyright notice is per RFC 3978 5.6 (a), q.v.)
-----------------------------------------------------------------------------
Copyright (c) 2004 Masarykova universita
(Masaryk University, Brno, Czech Republic)
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are met:
1. Redistributions of source code must retain the above copyright notice,
this list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.
3. Neither the name of the University nor the names of its contributors may
be used to endorse or promote products derived from this software
without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
POSSIBILITY OF SUCH DAMAGE.
-----------------------------------------------------------------------------
Copyright (c) 1997 - 2003 Kungliga Tekniska Högskolan
(Royal Institute of Technology, Stockholm, Sweden).
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions
are met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.
3. Neither the name of the Institute nor the names of its contributors
may be used to endorse or promote products derived from this software
without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
SUCH DAMAGE.
-----------------------------------------------------------------------------
Copyright (c) 1998 Doug Rabson
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions
are met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.
THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
SUCH DAMAGE.
-----------------------------------------------------------------------------
Copyright ((c)) 2002, Rice University
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are
met:
* Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
* Redistributions in binary form must reproduce the above
copyright notice, this list of conditions and the following
disclaimer in the documentation and/or other materials provided
with the distribution.
* Neither the name of Rice University (RICE) nor the names of its
contributors may be used to endorse or promote products derived
from this software without specific prior written permission.
This software is provided by RICE and the contributors on an "as is"
basis, without any representations or warranties of any kind, express
or implied including, but not limited to, representations or
warranties of non-infringement, merchantability or fitness for a
particular purpose. In no event shall RICE or contributors be liable
for any direct, indirect, incidental, special, exemplary, or
consequential damages (including, but not limited to, procurement of
substitute goods or services; loss of use, data, or profits; or
business interruption) however caused and on any theory of liability,
whether in contract, strict liability, or tort (including negligence
or otherwise) arising in any way out of the use of this software, even
if advised of the possibility of such damage.
-----------------------------------------------------------------------------
Copyright (c) 1993 by Digital Equipment Corporation.
Permission to use, copy, modify, and distribute this software for any
purpose with or without fee is hereby granted, provided that the above
copyright notice and this permission notice appear in all copies, and that
the name of Digital Equipment Corporation not be used in advertising or
publicity pertaining to distribution of the document or software without
specific, written prior permission.
THE SOFTWARE IS PROVIDED "AS IS" AND DIGITAL EQUIPMENT CORP. DISCLAIMS ALL
WARRANTIES WITH REGARD TO THIS SOFTWARE, INCLUDING ALL IMPLIED WARRANTIES
OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL DIGITAL EQUIPMENT
CORPORATION BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL
DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR
PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS
ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
SOFTWARE.
-----------------------------------------------------------------------------
Copyright 2000 Aaron D. Gifford. All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions
are met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.
3. Neither the name of the copyright holder nor the names of contributors
may be used to endorse or promote products derived from this software
without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) AND CONTRIBUTOR(S) ``AS IS'' AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR(S) OR CONTRIBUTOR(S) BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
SUCH DAMAGE.
-----------------------------------------------------------------------------
Copyright (c) 1998 Doug Rabson.
Copyright (c) 2001 Jake Burkholder.
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions
are met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.
THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
SUCH DAMAGE.
-----------------------------------------------------------------------------
Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions
are met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.
3. Neither the name of the project nor the names of its contributors
may be used to endorse or promote products derived from this software
without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
SUCH DAMAGE.
-----------------------------------------------------------------------------
Copyright (c) 1999-2000 by Nortel Networks Corporation
Permission to use, copy, modify, and distribute this software for any
purpose with or without fee is hereby granted, provided that the above
copyright notice and this permission notice appear in all copies.
THE SOFTWARE IS PROVIDED "AS IS" AND NORTEL NETWORKS DISCLAIMS
ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES
OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL NORTEL NETWORKS
BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES
OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,
WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION,
ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
SOFTWARE.
-----------------------------------------------------------------------------
Copyright (c) 2000-2002 Japan Network Information Center. All rights reserved.
By using this file, you agree to the terms and conditions set forth bellow.
LICENSE TERMS AND CONDITIONS
The following License Terms and Conditions apply, unless a different
license is obtained from Japan Network Information Center ("JPNIC"),
a Japanese association, Kokusai-Kougyou-Kanda Bldg 6F, 2-3-4 Uchi-Kanda,
Chiyoda-ku, Tokyo 101-0047, Japan.
1. Use, Modification and Redistribution (including distribution of any
modified or derived work) in source and/or binary forms is permitted
under this License Terms and Conditions.
2. Redistribution of source code must retain the copyright notices as they
appear in each source code file, this License Terms and Conditions.
3. Redistribution in binary form must reproduce the Copyright Notice,
this License Terms and Conditions, in the documentation and/or other
materials provided with the distribution. For the purposes of binary
distribution the "Copyright Notice" refers to the following language:
"Copyright (c) 2000-2002 Japan Network Information Center. All rights
reserved."
4. The name of JPNIC may not be used to endorse or promote products
derived from this Software without specific prior written approval of
JPNIC.
5. Disclaimer/Limitation of Liability: THIS SOFTWARE IS PROVIDED BY JPNIC
"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL JPNIC BE LIABLE
FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
-----------------------------------------------------------------------------
Copyright (C) 2004 Nominet, Ltd.
Permission to use, copy, modify, and distribute this software for any
purpose with or without fee is hereby granted, provided that the above
copyright notice and this permission notice appear in all copies.
THE SOFTWARE IS PROVIDED "AS IS" AND NOMINET DISCLAIMS ALL WARRANTIES WITH
REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
PERFORMANCE OF THIS SOFTWARE.
-----------------------------------------------------------------------------
Portions Copyright RSA Security Inc.
License to copy and use this software is granted provided that it is
identified as "RSA Security Inc. PKCS #11 Cryptographic Token Interface
(Cryptoki)" in all material mentioning or referencing this software.
License is also granted to make and use derivative works provided that
such works are identified as "derived from the RSA Security Inc. PKCS #11
Cryptographic Token Interface (Cryptoki)" in all material mentioning or
referencing the derived work.
RSA Security Inc. makes no representations concerning either the
merchantability of this software or the suitability of this software for
any particular purpose. It is provided "as is" without express or implied
warranty of any kind.
-----------------------------------------------------------------------------
Copyright (c) 1996, David Mazieres <dm@uun.org>
Copyright (c) 2008, Damien Miller <djm@openbsd.org>
Permission to use, copy, modify, and distribute this software for any
purpose with or without fee is hereby granted, provided that the above
copyright notice and this permission notice appear in all copies.
THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
-----------------------------------------------------------------------------
Copyright (c) 2000-2001 The OpenSSL Project. All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions
are met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in
the documentation and/or other materials provided with the
distribution.
3. All advertising materials mentioning features or use of this
software must display the following acknowledgment:
"This product includes software developed by the OpenSSL Project
for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
endorse or promote products derived from this software without
prior written permission. For written permission, please contact
licensing@OpenSSL.org.
5. Products derived from this software may not be called "OpenSSL"
nor may "OpenSSL" appear in their names without prior written
permission of the OpenSSL Project.
6. Redistributions of any form whatsoever must retain the following
acknowledgment:
"This product includes software developed by the OpenSSL Project
for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
OF THE POSSIBILITY OF SUCH DAMAGE.
+255
View File
@@ -0,0 +1,255 @@
3312. [bug] named-checkconf didn't detect a bad dns64 clients acl.
[RT #27631]
3306. [bug] Improve DNS64 reverse zone performance. [RT #28563]
3305. [func] Add wire format lookup method to sdb. [RT #28563]
3303. [bug] named could die when reloading. [RT #28606]
3296. [bug] Named could die with a INSIST failure in
client.c:exit_check. [RT #28346]
3289. [bug] 'rndc retransfer' failed for inline zones. [RT #28036]
3288. [bug] dlz_destroy() function wasn't correctly registered
by the DLZ dlopen driver. [RT #28056]
3280. [bug] Potential double free of a rdataset on out of memory
with DNS64. [RT #27762]
3279. [bug] Hold a internal reference to the zone while performing
a asynchronous load. Address potential memory leak
if the asynchronous is cancelled. [RT #27750]
3277. [bug] win32: isc_socket_dup is not implemented. [RT #27696]
3275. [bug] Corrected rndc -h output; the 'rndc sync -clean'
option had been misspelled as '-clear'. (To avoid
future confusion, both options now work.) [RT #27173]
3270. [bug] "rndc reload" didn't reuse existing zones correctly
when inline-signing was in use. [RT #27650]
3269. [port] darwin 11 and later now built threaded by default.
3265. [bug] Address lock order reversal with inline-signing
support. [27557]
3265. [bug] Address lock order reversal with inline-signing
support. [27557]
3264. [bug] Automatic regeneration of signatures in an
inline-signing zone could stall when the server
was restarted. [RT #27344]
3263. [bug] "rndc sync" did not affect the unsigned side of an
inline-signing zone. [RT #27337]
3262. [bug] Signed responses were handled incorrectly by RPZ.
[RT #27316]
3252. [bug] When master zones using inline-signing were
updated while the server was offline, the source
zone could fall out of sync with the signed
copy. They can now resynchronize. [RT #26676]
3246. [bug] Named failed to start with a empty also-notify list.
[RT #27087]
3245. [bug] Don't report a error unchanged serials unless there
were other changes when thawing a zone with
ixfr-fromdifferences. [RT #26845]
3243. [port] freebsd,netbsd,bsdi: the thread defaults were not
being properly set.
3236. [bug] Backed out changes #3182 and #3202, related to
EDNS(0) fallback behavior. [RT #26416]
3233. [bug] 'rndc freeze/thaw' didn't work for inline zones.
[RT #26632]
3225. [bug] Silence spurious "setsockopt(517, IPV6_V6ONLY) failed"
messages. [RT #26507]
3224. [bug] 'rndc signing' argument parsing was broken. [RT #26684]
3223. [bug] 'task_test privilege_drop' generated false positives.
[RT #26766]
3222. [cleanup] Replace dns_journal_{get,set}_bitws with
dns_journal_{get,set}_sourceserial. [RT #26634]
3220. [bug] Change #3186 was incomplete; dns_db_rpz_findips()
could fail to set the database version correctly,
causing an assertion failure. [RT #26180]
3219. [bug] Disable NOEDNS caching following a timeout.
3217. [cleanup] Fix build problem with --disable-static. [RT #26476]
3215. [bug] 'rndc recursing' could cause a core dump. [RT #26495]
3210. [bug] Canceling the oldest query due to recursive-client
overload could trigger an assertion failure. [RT #26463]
3202. [bug] NOEDNS caching on timeout was too agressive.
[RT #26416]
3186. [bug] Version/db mis-match in rpz code. [RT #26180]
3184. [bug] named had excessive cpu usage when a redirect zone was
configured. [RT #26013]
3183. [bug] Added RTLD_GLOBAL flag to dlopen call. [RT #26301]
3182. [bug] Auth servers behind firewalls which block packets
greater than 512 bytes may cause other servers to
perform poorly. Now, adb retains edns information
and caches noedns servers. [RT #23392/24964]
3178. [bug] A race condition introduced by change #3163 could
cause an assertion failure on shutdown. [RT #26271]
3176. [doc] Corrected example code and added a README to the
sample external DLZ module in contrib/dlz/example.
[RT #26215]
3172. [port] darwin 10.* and freebsd [89] are now built threaded by
default.
3168. [bug] Nxdomain redirection could trigger an assert with
a ANY query. [RT #26017]
3166. [bug] Upgrading a zone to support inline-signing failed.
[RT #26014]
3165. [bug] dnssec-signzone could generate new signatures when
resigning, even when valid signatures were already
present. [RT #26025]
3163. [bug] Use finer-grained locking in client.c to address
concurrency problems with large numbers of threads.
[RT #26044]
3160. [bug] When printing out a NSEC3 record in multiline form
the newline was not being printed causing type codes
to be run together. [RT #25873]
3159. [bug] On some platforms, named could assert on startup
when running in a chrooted environment without
/proc. [RT #25863]
3158. [bug] Recursive servers would prefer a particular UDP
socket instead of using all available sockets.
[RT #26038]
3155. [bug] Fixed a build failure when using contrib DLZ
drivers (e.g., mysql, postgresql, etc). [RT #25710]
3142. [bug] NAPTR is class agnostic. [RT #25429]
3131. [tuning] Improve scalability by allocating one zone task
per 100 zones at startup time, rather than using a
fixed-size task table. [RT #24406]
3127. [bug] 'rndc thaw' will now remove a zone's journal file
if the zone serial number has been changed and
ixfr-from-differences is not in use. [RT #24687]
3126. [security] Using DNAME record to generate replacements caused
RPZ to exit with a assertion failure. [RT #24766]
3125. [security] Using wildcard CNAME records as a replacement with
RPZ caused named to exit with a assertion failure.
[RT #24715]
3115. [bug] Named could fail to return requested data when
following a CNAME that points into the same zone.
[RT #24455]
3108. [cleanup] dnssec-signzone: Clarified some error and
warning messages; removed #ifdef ALLOW_KSKLESS_ZONES
code (use -P instead). [RT #20852]
3105. [bug] GOST support can be suppressed by "configure
--without-gost" [RT #24367]
3103. [bug] Configuring 'dnssec-validation auto' in a view
instead of in the options statement could trigger
an assertion failure in named-checkconf. [RT #24382]
3100. [security] Certain response policy zone configurations could
trigger an INSIST when receiving a query of type
RRSIG. [RT #24280]
3098. [bug] DLZ zones were answering without setting the AA bit.
[RT #24146]
3096. [bug] Set KRB5_KTNAME before calling log_cred() in
dst_gssapi_acceptctx(). [RT #24004]
3094. [doc] Expand dns64 documentation.
3093. [bug] Fix gssapi/kerberos dependencies [RT #23836]
3087. [bug] DDNS updates using SIG(0) with update-policy match
type "external" could cause a crash. [RT #23735]
3082. [port] strtok_r is threads only. [RT #23747]
3072. [bug] dns_dns64_aaaaok() potential NULL pointer dereference.
[RT #20256]
3054. [bug] Added elliptic curve support check in
GOST OpenSSL engine detection. [RT #23485]
3045. [removed] Replaced by change #3050.
3038. [bug] Install <dns/rpz.h>. [RT #23342]
3022. [bug] Fixed rpz SERVFAILs after failed zone transfers
[RT #23246]
3013. [bug] The DNS64 ttl was not always being set as expected.
[RT #23034]
3005. [port] Solaris: Work around the lack of
gsskrb5_register_acceptor_identity() by setting
the KRB5_KTNAME environment variable to the
contents of tkey-gssapi-keytab. Also fixed
test errors on MacOSX. [RT #22853]
3003. [experimental] Added update-policy match type "external",
enabling named to defer the decision of whether to
allow a dynamic update to an external daemon.
(Contributed by Andrew Tridgell.) [RT #22758]
3000. [bug] More TKEY/GSS fixes:
- nsupdate can now get the default realm from
the user's Kerberos principal
- corrected gsstest compilation flags
- improved documentation
- fixed some NULL dereferences
[RT #22795]
2992. [contrib] contrib/check-secure-delegation.pl: A simple tool
for looking at a secure delegation. [RT #22059]
2991. [contrib] contrib/zone-edit.sh: A simple zone editing tool for
dynamic zones. [RT #22365]
2988. [experimental] Added a "dlopen" DLZ driver, allowing the creation
of external DLZ drivers that can be loaded as
shared objects at runtime rather than linked with
named. Currently this is switched on via a
compile-time option, "configure --with-dlz-dlopen".
Note: the syntax for configuring DLZ zones
is likely to be refined in future releases.
(Contributed by Andrew Tridgell of the Samba
project.) [RT #22629]
2948. [port] MacOS: provide a mechanism to configure the test
interfaces at reboot. See bin/tests/system/README
for details.
+3 -2
View File
@@ -1,7 +1,7 @@
<!DOCTYPE article PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd" []>
<!--
- Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2004-2010, 2012 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2000-2003 Internet Software Consortium.
-
- Permission to use, copy, modify, and/or distribute this software for any
@@ -17,7 +17,7 @@
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: FAQ.xml,v 1.52.24.2 2010/01/20 23:48:18 tbox Exp $ -->
<!-- $Id: FAQ.xml,v 1.54 2010/01/19 23:48:55 tbox Exp $ -->
<article class="faq">
<title>Frequently Asked Questions about BIND 9</title>
@@ -30,6 +30,7 @@
<year>2008</year>
<year>2009</year>
<year>2010</year>
<year>2012</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright>
<copyright>
+313
View File
@@ -0,0 +1,313 @@
Summary of functional enhancements from prior major releases of BIND 9:
BIND 9.6.0
Full NSEC3 support
Automatic zone re-signing
New update-policy methods tcp-self and 6to4-self
The BIND 8 resolver library, libbind, has been removed from the
BIND 9 distribution and is now available as a separate download.
Change the default pid file location from /var/run to
/var/run/{named,lwresd} for improved chroot/setuid support.
BIND 9.5.0
GSS-TSIG support (RFC 3645).
DHCID support.
Experimental http server and statistics support for named via xml.
More detailed statistics counters including those supported in BIND 8.
Faster ACL processing.
Use Doxygen to generate internal documentation.
Efficient LRU cache-cleaning mechanism.
NSID support.
BIND 9.4.0
Implemented "additional section caching (or acache)", an
internal cache framework for additional section content to
improve response performance. Several configuration options
were provided to control the behavior.
New notify type 'master-only'. Enable notify for master
zones only.
Accept 'notify-source' style syntax for query-source.
rndc now allows addresses to be set in the server clauses.
New option "allow-query-cache". This lets "allow-query"
be used to specify the default zone access level rather
than having to have every zone override the global value.
"allow-query-cache" can be set at both the options and view
levels. If "allow-query-cache" is not set then "allow-recursion"
is used if set, otherwise "allow-query" is used if set
unless "recursion no;" is set in which case "none;" is used,
otherwise the default (localhost; localnets;) is used.
rndc: the source address can now be specified.
ixfr-from-differences now takes master and slave in addition
to yes and no at the options and view levels.
Allow the journal's name to be changed via named.conf.
'rndc notify zone [class [view]]' resend the NOTIFY messages
for the specified zone.
'dig +trace' now randomly selects the next servers to try.
Report if there is a bad delegation.
Improve check-names error messages.
Make public the function to read a key file, dst_key_read_public().
dig now returns the byte count for axfr/ixfr.
allow-update is now settable at the options / view level.
named-checkconf now checks the logging configuration.
host now can turn on memory debugging flags with '-m'.
Don't send notify messages to self.
Perform sanity checks on NS records which refer to 'in zone' names.
New zone option "notify-delay". Specify a minimum delay
between sets of NOTIFY messages.
Extend adjusting TTL warning messages.
Named and named-checkzone can now both check for non-terminal
wildcard records.
"rndc freeze/thaw" now freezes/thaws all zones.
named-checkconf now check acls to verify that they only
refer to existing acls.
The server syntax has been extended to support a range of
servers.
Report differences between hints and real NS rrset and
associated address records.
Preserve the case of domain names in rdata during zone
transfers.
Restructured the data locking framework using architecture
dependent atomic operations (when available), improving
response performance on multi-processor machines significantly.
x86, x86_64, alpha, powerpc, and mips are currently supported.
UNIX domain controls are now supported.
Add support for additional zone file formats for improving
loading performance. The masterfile-format option in
named.conf can be used to specify a non-default format. A
separate command named-compilezone was provided to generate
zone files in the new format. Additionally, the -I and -O
options for dnssec-signzone specify the input and output
formats.
dnssec-signzone can now randomize signature end times
(dnssec-signzone -j jitter).
Add support for CH A record.
Add additional zone data constancy checks. named-checkzone
has extended checking of NS, MX and SRV record and the hosts
they reference. named has extended post zone load checks.
New zone options: check-mx and integrity-check.
edns-udp-size can now be overridden on a per server basis.
dig can now specify the EDNS version when making a query.
Added framework for handling multiple EDNS versions.
Additional memory debugging support to track size and mctx
arguments.
Detect duplicates of UDP queries we are recursing on and
drop them. New stats category "duplicates".
"USE INTERNAL MALLOC" is now runtime selectable.
The lame cache is now done on a <qname,qclass,qtype> basis
as some servers only appear to be lame for certain query
types.
Limit the number of recursive clients that can be waiting
for a single query (<qname,qtype,qclass>) to resolve. New
options clients-per-query and max-clients-per-query.
dig: report the number of extra bytes still left in the
packet after processing all the records.
Support for IPSECKEY rdata type.
Raise the UDP recieve buffer size to 32k if it is less than 32k.
x86 and x86_64 now have seperate atomic locking implementations.
named-checkconf now validates update-policy entries.
Attempt to make the amount of work performed in a iteration
self tuning. The covers nodes clean from the cache per
iteration, nodes written to disk when rewriting a master
file and nodes destroyed per iteration when destroying a
zone or a cache.
ISC string copy API.
Automatic empty zone creation for D.F.IP6.ARPA and friends.
Note: RFC 1918 zones are not yet covered by this but are
likely to be in a future release.
New options: empty-server, empty-contact, empty-zones-enable
and disable-empty-zone.
dig now has a '-q queryname' and '+showsearch' options.
host/nslookup now continue (default)/fail on SERVFAIL.
dig now warns if 'RA' is not set in the answer when 'RD'
was set in the query. host/nslookup skip servers that fail
to set 'RA' when 'RD' is set unless a server is explicitly
set.
Integrate contibuted DLZ code into named.
Integrate contibuted IDN code from JPNIC.
libbind: corresponds to that from BIND 8.4.7.
BIND 9.3.0
DNSSEC is now DS based (RFC 3658).
See also RFC 3845, doc/draft/draft-ietf-dnsext-dnssec-*.
DNSSEC lookaside validation.
check-names is now implemented.
rrset-order in more complete.
IPv4/IPv6 transition support, dual-stack-servers.
IXFR deltas can now be generated when loading master files,
ixfr-from-differences.
It is now possible to specify the size of a journal, max-journal-size.
It is now possible to define a named set of master servers to be
used in masters clause, masters.
The advertised EDNS UDP size can now be set, edns-udp-size.
allow-v6-synthesis has been obsoleted.
NOTE:
* Zones containing MD and MF will now be rejected.
* dig, nslookup name. now report "Not Implemented" as
NOTIMP rather than NOTIMPL. This will have impact on scripts
that are looking for NOTIMPL.
libbind: corresponds to that from BIND 8.4.5.
BIND 9.2.0
The size of the cache can now be limited using the
"max-cache-size" option.
The server can now automatically convert RFC1886-style recursive
lookup requests into RFC2874-style lookups, when enabled using the
new option "allow-v6-synthesis". This allows stub resolvers that
support AAAA records but not A6 record chains or binary labels to
perform lookups in domains that make use of these IPv6 DNS
features.
Performance has been improved.
The man pages now use the more portable "man" macros rather than
the "mandoc" macros, and are installed by "make install".
The named.conf parser has been completely rewritten. It now
supports "include" directives in more places such as inside "view"
statements, and it no longer has any reserved words.
The "rndc status" command is now implemented.
rndc can now be configured automatically.
A BIND 8 compatible stub resolver library is now included in
lib/bind.
OpenSSL has been removed from the distribution. This means that to
use DNSSEC, OpenSSL must be installed and the --with-openssl option
must be supplied to configure. This does not apply to the use of
TSIG, which does not require OpenSSL.
The source distribution now builds on Windows. See
win32utils/readme1.txt and win32utils/win32-build.txt for details.
This distribution also includes a new lightweight stub
resolver library and associated resolver daemon that fully
support forward and reverse lookups of both IPv4 and IPv6
addresses. This library is considered experimental and
is not a complete replacement for the BIND 8 resolver library.
Applications that use the BIND 8 res_* functions to perform
DNS lookups or dynamic updates still need to be linked against
the BIND 8 libraries. For DNS lookups, they can also use the
new "getrrsetbyname()" API.
BIND 9.2 is capable of acting as an authoritative server
for DNSSEC secured zones. This functionality is believed to
be stable and complete except for lacking support for
verifications involving wildcard records in secure zones.
When acting as a caching server, BIND 9.2 can be configured
to perform DNSSEC secure resolution on behalf of its clients.
This part of the DNSSEC implementation is still considered
experimental. For detailed information about the state of the
DNSSEC implementation, see the file doc/misc/dnssec.
There are a few known bugs:
On some systems, IPv6 and IPv4 sockets interact in
unexpected ways. For details, see doc/misc/ipv6.
To reduce the impact of these problems, the server
no longer listens for requests on IPv6 addresses
by default. If you need to accept DNS queries over
IPv6, you must specify "listen-on-v6 { any; };"
in the named.conf options statement.
FreeBSD prior to 4.2 (and 4.2 if running as non-root)
and OpenBSD prior to 2.8 log messages like
"fcntl(8, F_SETFL, 4): Inappropriate ioctl for device".
This is due to a bug in "/dev/random" and impacts the
server's DNSSEC support.
OS X 10.1.4 (Darwin 5.4), OS X 10.1.5 (Darwin 5.5) and
OS X 10.2 (Darwin 6.0) reports errors like
"fcntl(3, F_SETFL, 4): Operation not supported by device".
This is due to a bug in "/dev/random" and impacts the
server's DNSSEC support.
--with-libtool does not work on AIX.
A bug in some versions of the Microsoft DNS server can cause zone
transfers from a BIND 9 server to a W2K server to fail. For details,
see the "Zone Transfers" section in doc/misc/migration.
+7 -4
View File
@@ -1,4 +1,4 @@
# Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2004-2009, 2011, 2012 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 1998-2002 Internet Software Consortium.
#
# Permission to use, copy, modify, and/or distribute this software for any
@@ -13,7 +13,7 @@
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
# $Id: Makefile.in,v 1.58 2009/11/26 20:52:44 marka Exp $
# $Id: Makefile.in,v 1.58.8.4 2011/09/06 04:05:37 marka Exp $
srcdir = @srcdir@
VPATH = @srcdir@
@@ -21,7 +21,7 @@ top_srcdir = @top_srcdir@
@BIND9_VERSION@
SUBDIRS = make lib bin doc @LIBEXPORT@
SUBDIRS = make unit lib bin doc @LIBEXPORT@
TARGETS =
MANPAGES = isc-config.sh.1
@@ -64,7 +64,10 @@ tags:
check: test
test:
(cd bin/tests && ${MAKE} ${MAKEDEFS} test)
status=0; \
(cd bin/tests && ${MAKE} ${MAKEDEFS} test) || status=1; \
(test -f unit/unittest.sh && $(SHELL) unit/unittest.sh) || status=1; \
exit $$status
FAQ: FAQ.xml
${XSLTPROC} doc/xsl/isc-docbook-text.xsl FAQ.xml | \
+164 -383
View File
@@ -42,6 +42,64 @@ BIND 9
Stichting NLnet - NLnet Foundation
Nominum, Inc.
For a summary of functional enhancements in previous
releases, see the HISTORY file.
For a detailed list of user-visible changes from
previous releases, see the CHANGES file.
For up-to-date release notes and errata, see
http://www.isc.org/software/bind9/releasenotes
BIND 9.7.7
BIND 9.7.7 includes several bug fixes and patches security
flaws described in CVE-2012-1667 and CVE-2012-3817.
BIND 9.7.6
BIND 9.7.6 is a maintenance release, fixing bugs in 9.7.5.
BIND 9.7.5
BIND 9.7.5 includes a number of bug fixes and prevents a security
problem described in CVE-2011-4313
BIND 9.7.4
BIND 9.7.4 is a maintenance release, fixing bugs in 9.7.3.
BIND 9.7.3
BIND 9.7.3 is a maintenance release, fixing bugs in 9.7.2.
BIND 9.7.2
BIND 9.7.2 will address bugs in 9.7.1, and also introduces
some new functionality:
- "rndc loadkeys" to allow new keys to be added to a managed
zone without having them sign the content immediately.
- "rndc addzone" and "rndc delzone" allow adding and deleting
zones at runtime. This requires the view to have the
"new-zone-file" option set to a filename. Zone configuration
information for new zones is specified in the 'rndc addzone'
command line, and is stored in that file. To make new
zones persist after a restart, "include" the file
into named.conf in the appropriate view. (Note:
This feature is not yet documented, and its syntax
is expected to change.)
- "rndc secroots" dumps a list of the current trusted and
managed DNSSEC keys for each view.
- "filter-aaaa-on-v4" can now be applied selectively to
some IPv4 clients but not others, using the "filter-aaaa"
ACL. (This feature requires BIND 9 to be built with
the --enable-filter-aaaa configure option.)
BIND 9.7.1
BIND 9.7.1 is a maintenance release, fixing bugs in 9.7.0.
BIND 9.7.0
BIND 9.7.0 includes a number of changes from BIND 9.6 and earlier
@@ -60,383 +118,64 @@ BIND 9.7.0
- DNS rebinding attack prevention.
- New default values for dnssec-keygen parameters.
- Support for RFC 5011 automated trust anchor maintenance
(see README.rfc5011 for additional details).
- Smart signing: simplified tools for zone signing and key
maintenance.
- The "statistics-channels" option is now available on Windows.
- A new DNSSEC-aware libdns API for use by non-BIND9 applications
(see README.libdns for details).
- On some platforms, named and other binaries can now print out
a stack backtrace on assertion failure, to aid in debugging.
- A "tools only" installation mode on Windows, which only installs
dig, host, nslookup and nsupdate.
- Improved PKCS#11 support, including Keyper support and explicit
OpenSSL engine selection (see README.pkcs11 for additional details).
COMPATIBILITY NOTES:
- If you had built BIND 9.6 with any of ALLOW_NSEC3PARAM_UPDATE,
ALLOW_SECURE_TO_INSECURE or ALLOW_INSECURE_TO_SECURE defined, then
you should ensure that all changes that are in progress have
completed prior to upgrading to BIND 9.7. BIND 9.7 implements
those features in a way which is not backwards compatible.
- Prior releases had a bug which caused HMAC-SHA* keys with long
secrets to be used incorrectly. Fixing this bug means that older
versions of BIND 9 may fail to interoperate with this version
when using TSIG keys. If this occurs, the new "isc-hmac-fixup"
tool will convert a key with a long secret into a form that works
correctly with all versions of BIND 9. See the "isc-hmac-fixup"
man page for additional details.
- Revoking a DNSSEC key with "dnssec-revoke" changes its key ID.
It is possible for the new key ID to collide with that of a
different key. Newly generated keys will not have this problem,
as "dnssec-keygen" looks for potential collisions before
generating keys, but exercise caution if using key revokation
with keys that were generated by older versions of BIND 9.
See README.rfc5011 for more details.
- A bug was fixed in which a key's scheduled inactivity date was
stored incorectly. Users who participated in the 9.7.0 BETA
test and had DNSSEC keys with scheduled inactivity dates will
need to reset those keys' dates using "dnssec-settime -I".
BIND 9.6.0
BIND 9.6.0 includes a number of changes from BIND 9.5 and earlier
releases, including:
Full NSEC3 support
Automatic zone re-signing
New update-policy methods tcp-self and 6to4-self
The BIND 8 resolver library, libbind, has been removed from the
BIND 9 distribution and is now available as a separate download.
Change the default pid file location from /var/run to
/var/run/{named,lwresd} for improved chroot/setuid support.
BIND 9.5.0
BIND 9.5.0 has a number of new features over 9.4,
including:
GSS-TSIG support (RFC 3645).
DHCID support.
Experimental http server and statistics support for named via xml.
More detailed statistics counters including those supported in BIND 8.
Faster ACL processing.
Use Doxygen to generate internal documentation.
Efficient LRU cache-cleaning mechanism.
NSID support.
BIND 9.4.0
BIND 9.4.0 has a number of new features over 9.3,
including:
Implemented "additional section caching (or acache)", an
internal cache framework for additional section content to
improve response performance. Several configuration options
were provided to control the behavior.
New notify type 'master-only'. Enable notify for master
zones only.
Accept 'notify-source' style syntax for query-source.
rndc now allows addresses to be set in the server clauses.
New option "allow-query-cache". This lets "allow-query"
be used to specify the default zone access level rather
than having to have every zone override the global value.
"allow-query-cache" can be set at both the options and view
levels. If "allow-query-cache" is not set then "allow-recursion"
is used if set, otherwise "allow-query" is used if set
unless "recursion no;" is set in which case "none;" is used,
otherwise the default (localhost; localnets;) is used.
rndc: the source address can now be specified.
ixfr-from-differences now takes master and slave in addition
to yes and no at the options and view levels.
Allow the journal's name to be changed via named.conf.
'rndc notify zone [class [view]]' resend the NOTIFY messages
for the specified zone.
'dig +trace' now randomly selects the next servers to try.
Report if there is a bad delegation.
Improve check-names error messages.
Make public the function to read a key file, dst_key_read_public().
dig now returns the byte count for axfr/ixfr.
allow-update is now settable at the options / view level.
named-checkconf now checks the logging configuration.
host now can turn on memory debugging flags with '-m'.
Don't send notify messages to self.
Perform sanity checks on NS records which refer to 'in zone' names.
New zone option "notify-delay". Specify a minimum delay
between sets of NOTIFY messages.
Extend adjusting TTL warning messages.
Named and named-checkzone can now both check for non-terminal
wildcard records.
"rndc freeze/thaw" now freezes/thaws all zones.
named-checkconf now check acls to verify that they only
refer to existing acls.
The server syntax has been extended to support a range of
servers.
Report differences between hints and real NS rrset and
associated address records.
Preserve the case of domain names in rdata during zone
transfers.
Restructured the data locking framework using architecture
dependent atomic operations (when available), improving
response performance on multi-processor machines significantly.
x86, x86_64, alpha, powerpc, and mips are currently supported.
UNIX domain controls are now supported.
Add support for additional zone file formats for improving
loading performance. The masterfile-format option in
named.conf can be used to specify a non-default format. A
separate command named-compilezone was provided to generate
zone files in the new format. Additionally, the -I and -O
options for dnssec-signzone specify the input and output
formats.
dnssec-signzone can now randomize signature end times
(dnssec-signzone -j jitter).
Add support for CH A record.
Add additional zone data constancy checks. named-checkzone
has extended checking of NS, MX and SRV record and the hosts
they reference. named has extended post zone load checks.
New zone options: check-mx and integrity-check.
edns-udp-size can now be overridden on a per server basis.
dig can now specify the EDNS version when making a query.
Added framework for handling multiple EDNS versions.
Additional memory debugging support to track size and mctx
arguments.
Detect duplicates of UDP queries we are recursing on and
drop them. New stats category "duplicates".
"USE INTERNAL MALLOC" is now runtime selectable.
The lame cache is now done on a <qname,qclass,qtype> basis
as some servers only appear to be lame for certain query
types.
Limit the number of recursive clients that can be waiting
for a single query (<qname,qtype,qclass>) to resolve. New
options clients-per-query and max-clients-per-query.
dig: report the number of extra bytes still left in the
packet after processing all the records.
Support for IPSECKEY rdata type.
Raise the UDP recieve buffer size to 32k if it is less than 32k.
x86 and x86_64 now have seperate atomic locking implementations.
named-checkconf now validates update-policy entries.
Attempt to make the amount of work performed in a iteration
self tuning. The covers nodes clean from the cache per
iteration, nodes written to disk when rewriting a master
file and nodes destroyed per iteration when destroying a
zone or a cache.
ISC string copy API.
Automatic empty zone creation for D.F.IP6.ARPA and friends.
Note: RFC 1918 zones are not yet covered by this but are
likely to be in a future release.
New options: empty-server, empty-contact, empty-zones-enable
and disable-empty-zone.
dig now has a '-q queryname' and '+showsearch' options.
host/nslookup now continue (default)/fail on SERVFAIL.
dig now warns if 'RA' is not set in the answer when 'RD'
was set in the query. host/nslookup skip servers that fail
to set 'RA' when 'RD' is set unless a server is explicitly
set.
Integrate contibuted DLZ code into named.
Integrate contibuted IDN code from JPNIC.
libbind: corresponds to that from BIND 8.4.7.
BIND 9.3.0
BIND 9.3.0 has a number of new features over 9.2,
including:
DNSSEC is now DS based (RFC 3658).
See also RFC 3845, doc/draft/draft-ietf-dnsext-dnssec-*.
DNSSEC lookaside validation.
check-names is now implemented.
rrset-order in more complete.
IPv4/IPv6 transition support, dual-stack-servers.
IXFR deltas can now be generated when loading master files,
ixfr-from-differences.
It is now possible to specify the size of a journal, max-journal-size.
It is now possible to define a named set of master servers to be
used in masters clause, masters.
The advertised EDNS UDP size can now be set, edns-udp-size.
allow-v6-synthesis has been obsoleted.
NOTE:
* Zones containing MD and MF will now be rejected.
* dig, nslookup name. now report "Not Implemented" as
NOTIMP rather than NOTIMPL. This will have impact on scripts
that are looking for NOTIMPL.
libbind: corresponds to that from BIND 8.4.5.
BIND 9.2.0
BIND 9.2.0 has a number of new features over 9.1,
including:
- The size of the cache can now be limited using the
"max-cache-size" option.
- The server can now automatically convert RFC1886-style
recursive lookup requests into RFC2874-style lookups,
when enabled using the new option "allow-v6-synthesis".
This allows stub resolvers that support AAAA records
but not A6 record chains or binary labels to perform
lookups in domains that make use of these IPv6 DNS
features.
- Performance has been improved.
- The man pages now use the more portable "man" macros
rather than the "mandoc" macros, and are installed
by "make install".
- The named.conf parser has been completely rewritten.
It now supports "include" directives in more
places such as inside "view" statements, and it no
longer has any reserved words.
- The "rndc status" command is now implemented.
- rndc can now be configured automatically.
- A BIND 8 compatible stub resolver library is now
included in lib/bind.
- OpenSSL has been removed from the distribution. This
means that to use DNSSEC, OpenSSL must be installed and
the --with-openssl option must be supplied to configure.
This does not apply to the use of TSIG, which does not
require OpenSSL.
- The source distribution now builds on Windows.
See win32utils/readme1.txt and win32utils/win32-build.txt
for details.
This distribution also includes a new lightweight stub
resolver library and associated resolver daemon that fully
support forward and reverse lookups of both IPv4 and IPv6
addresses. This library is considered experimental and
is not a complete replacement for the BIND 8 resolver library.
Applications that use the BIND 8 res_* functions to perform
DNS lookups or dynamic updates still need to be linked against
the BIND 8 libraries. For DNS lookups, they can also use the
new "getrrsetbyname()" API.
BIND 9.2 is capable of acting as an authoritative server
for DNSSEC secured zones. This functionality is believed to
be stable and complete except for lacking support for
verifications involving wildcard records in secure zones.
When acting as a caching server, BIND 9.2 can be configured
to perform DNSSEC secure resolution on behalf of its clients.
This part of the DNSSEC implementation is still considered
experimental. For detailed information about the state of the
DNSSEC implementation, see the file doc/misc/dnssec.
There are a few known bugs:
On some systems, IPv6 and IPv4 sockets interact in
unexpected ways. For details, see doc/misc/ipv6.
To reduce the impact of these problems, the server
no longer listens for requests on IPv6 addresses
by default. If you need to accept DNS queries over
IPv6, you must specify "listen-on-v6 { any; };"
in the named.conf options statement.
FreeBSD prior to 4.2 (and 4.2 if running as non-root)
and OpenBSD prior to 2.8 log messages like
"fcntl(8, F_SETFL, 4): Inappropriate ioctl for device".
This is due to a bug in "/dev/random" and impacts the
server's DNSSEC support.
OS X 10.1.4 (Darwin 5.4), OS X 10.1.5 (Darwin 5.5) and
OS X 10.2 (Darwin 6.0) reports errors like
"fcntl(3, F_SETFL, 4): Operation not supported by device".
This is due to a bug in "/dev/random" and impacts the
server's DNSSEC support.
--with-libtool does not work on AIX.
A bug in some versions of the Microsoft DNS server can cause zone
transfers from a BIND 9 server to a W2K server to fail. For details,
see the "Zone Transfers" section in doc/misc/migration.
For a detailed list of user-visible changes from
previous releases, see the CHANGES file.
- A new DNSSEC-aware libdns API for use by non-BIND9 applications
- On some platforms, named and other binaries can now print out
a stack backtrace on assertion failure, to aid in debugging.
- A "tools only" installation mode on Windows, which only installs
dig, host, nslookup and nsupdate.
- Improved PKCS#11 support, including Keyper support and explicit
OpenSSL engine selection.
Known issues in this release:
- A validating resolver that has been incorrectly configured with
an invalid trust anchor will be unable to resolve names covered
by that trust anchor. In all current versions of BIND 9, such a
resolver will also generate significant unnecessary DNS traffic
while trying to validate. The latter problem will be addressed
in future BIND 9 releases. In the meantime, to avoid these
problems, exercise caution when configuring "trusted-keys":
make sure all keys are correct and current when you add them,
and update your configuration in a timely manner when keys
roll over.
- In rare cases, DNSSEC validation can leak memory. When this
happens, it will cause an assertion failure when named exits,
but is otherwise harmless. A fix exists, but was too late for
this release; it will be included in BIND 9.7.1.
Compatibility notes:
- If you had built BIND 9.6 with any of ALLOW_NSEC3PARAM_UPDATE,
ALLOW_SECURE_TO_INSECURE or ALLOW_INSECURE_TO_SECURE defined, then
you should ensure that all changes that are in progress have
completed prior to upgrading to BIND 9.7. BIND 9.7 implements
those features in a way which is not backwards compatible.
- Prior releases had a bug which caused HMAC-SHA* keys with long
secrets to be used incorrectly. Fixing this bug means that older
versions of BIND 9 may fail to interoperate with this version
when using TSIG keys. If this occurs, the new "isc-hmac-fixup"
tool will convert a key with a long secret into a form that works
correctly with all versions of BIND 9. See the "isc-hmac-fixup"
man page for additional details.
- Revoking a DNSSEC key with "dnssec-revoke" changes its key ID.
It is possible for the new key ID to collide with that of a
different key. Newly generated keys will not have this problem,
as "dnssec-keygen" looks for potential collisions before
generating keys, but exercise caution if using key revokation
with keys that were generated by older versions of BIND 9. See
the Administrator's Reference Manual, section 4.10 ("Dynamic
Trust Anchor Management") for more details.
- A bug was fixed in which a key's scheduled inactivity date was
stored incorectly. Users who participated in the 9.7.0 BETA test
and had DNSSEC keys with scheduled inactivity dates will need to
reset those keys' dates using "dnssec-settime -I".
Building
@@ -456,9 +195,9 @@ Building
Ubuntu 7.04, 7.10
Windows XP/2003/2008
NOTE: As of BIND 9.5.1, 9.4.3, and 9.3.6, older versions of
Windows, including Windows NT and Windows 2000, are no longer
supported.
NOTE: As of BIND 9.5.1, 9.4.3, and 9.3.6, older versions of
Windows, including Windows NT and Windows 2000, are no longer
supported.
We have recent reports from the user community that a supported
version of BIND will build and run on the following systems:
@@ -558,10 +297,10 @@ Building
on the configure command line. The default is operating
system dependent.
Support for the "fixed" rrset-order option can be enabled
or disabled by specifying "--enable-fixed-rrset" or
"--disable-fixed-rrset" on the configure command line.
The default is "disabled", to reduce memory footprint.
Support for the "fixed" rrset-order option can be enabled
or disabled by specifying "--enable-fixed-rrset" or
"--disable-fixed-rrset" on the configure command line.
The default is "disabled", to reduce memory footprint.
If your operating system has integrated support for IPv6, it
will be used automatically. If you have installed KAME IPv6
@@ -627,8 +366,50 @@ Documentation
Frequently asked questions and their answers can be found in
FAQ.
Additional information on various subjects can be found
in the other README files.
Additional information on various subjects can be found
in the other README files.
Change Log
A detailed list of all changes to BIND 9 is included in the
file CHANGES, with the most recent changes listed first.
Change notes include tags indicating the category of the
change that was made; these categories are:
[func] New feature
[bug] General bug fix
[security] Fix for a significant security flaw
[experimental] Used for new features when the syntax
or other aspects of the design are still
in flux and may change
[port] Portability enhancement
[maint] Updates to built-in data such as root
server addresses and keys
[tuning] Changes to built-in configuration defaults
and constants to improve performanceo
[protocol] Updates to the DNS protocol such as new
RR types
[test] Changes to the automatic tests, not
affecting server functionality
[cleanup] Minor corrections and refactoring
[doc] Documentation
In general, [func] and [experimental] tags will only appear
in new-feature releases (i.e., those with version numbers
ending in zero). Some new functionality may be backported to
older releases on a case-by-case basis. All other change
types may be applied to all currently-supported releases.
Bug Reports and Mailing Lists
-186
View File
@@ -1,186 +0,0 @@
DNSSEC and Dynamic Zones
As of BIND 9.7.0 it is possible to change a dynamic zone from
insecure to secure and back again. A secure zone can use either
NSEC or NSEC3 chains.
Converting from insecure to secure
Changing a zone from insecure to secure can be done in two ways:
using a dynamic DNS update, or the "auto-dnssec" zone option.
For either method, you need to configure named so that it can see
the K* files which contain the public and private parts of the keys
that will be used to sign the zone. These files will have been
generated by dnssec-keygen. You can do this by placing them in
the key-directory, as specified in named.conf:
zone example.net {
type master;
update-policy local;
file "dynamic/example.net/example.net";
key-directory "dynamic/example.net";
};
If one KSK and one ZSK DNSKEY key have been generated, this configuration
will cause all records in the zone to be signed with the ZSK, and the
DNSKEY RRset to be signed with the KSK as well. An NSEC chain will be
generated as part of the initial signing process.
Dynamic DNS update method
To insert the keys via dynamic update:
% nsupdate
> ttl 3600
> update add example.net DNSKEY 256 3 7 AwEAAZn17pUF0KpbPA2c7Gz76Vb18v0teKT3EyAGfBfL8eQ8al35zz3Y I1m/SAQBxIqMfLtIwqWPdgthsu36azGQAX8=
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
> send
While the update request will complete almost immediately, the zone
will not be completely signed until named has had time to walk the
zone and generate the NSEC and RRSIG records. The NSEC record at the
apex will be added last, to signal that there is a complete NSEC chain.
If you wish to sign using NSEC3 instead of NSEC, you should add an
NSEC3PARAM record to the initial update request. If you wish the
NSEC3 chain to have the OPTOUT bit set, set it in the flags field
of the NSEC3PARAM record.
% nsupdate
> ttl 3600
> update add example.net DNSKEY 256 3 7 AwEAAZn17pUF0KpbPA2c7Gz76Vb18v0teKT3EyAGfBfL8eQ8al35zz3Y I1m/SAQBxIqMfLtIwqWPdgthsu36azGQAX8=
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
> update add example.net NSEC3PARAM 1 1 100 1234567890
> send
Again, this update request will complete almost immediately; however,
the record won't show up until named has had a chance to build/remove
the relevant chain. A private type record will be created to record
the state of the operation (see below for more details), and will be
removed once the operation completes.
While the initial signing and NSEC/NSEC3 chain generation is happening,
other updates are possible as well.
Fully automatic zone signing
To enable automatic signing, add the "auto-dnssec" option to the zone
statement in named.conf. "auto-dnssec" has two possible arguments:
"allow" or "maintain".
With "auto-dnssec allow", named can search the key directory for keys
matching the zone, insert them into the zone, and use them to sign the
zone. It will do so only when it receives an "rndc sign <zonename>"
command.
"auto-dnssec maintain" includes the above functionality, but will also
automatically adjust the zone's DNSKEY records on schedule according to the
keys' timing metadata (see the man pages for dnssec-keygen and
dnssec-settime for more information). If keys are present in the key
directory the first time the zone is loaded, it will be signed
immediately, without waiting for an "rndc sign" command. (This
command can still be used for unscheduled key changes, however.)
Using the "auto-dnssec" option requires the zone to be configured to
allow dynamic updates, by adding an "allow-update" or "update-policy"
statement to the zone configuration. If this has not been done, the
configuration will fail.
Private-type records
The state of the signing process is signaled by private-type records
(with a default type value of 65534). When signing is complete, these
records will have a nonzero value for the final octet (for those records
which have a nonzero initial octet).
The private type record format:
If the first octet is non-zero then the record indicates that the zone needs
to be signed with the key matching the record, or that all signatures that
match the record should be removed.
algorithm (octet 1)
key id in network order (octet 2 and 3)
removal flag (octet 4)
complete flag (octet 5)
Only records flagged as "complete" can be removed via dynamic update.
Attempts to remove other private type records will be silently ignored.
If the first octet is zero (this is a reserved algorithm number
that should never appear in a DNSKEY record) then the record indicates
changes to the NSEC3 chains are in progress. The rest of the record
contains an NSEC3PARAM record. The flag field tells what operation
to perform based on the flag bits.
0x01 OPTOUT
0x80 CREATE
0x40 REMOVE
0x20 NONSEC
DNSKEY rollovers via UPDATE
It is possible to perform key rollovers via dynamic update. You need
to add the K* files for the new keys so that named can find them. You
can then add the new DNSKEY RRs via dynamic update. Named will then cause
the zone to be signed with the new keys. When the signing is
complete the private type records will be updated so that the last
octet is non zero.
If this is for a KSK you need to inform the parent and any trust
anchor repositories of the new KSK.
You should then wait for the maximum TTL in the zone before removing the
old DNSKEY. If it is a KSK that is being updated, you also need to wait
for the DS RRset in the parent to be updated and its TTL to expire.
This ensures that all clients will be able to verify at least one
signature when you remove the old DNSKEY.
The old DNSKEY can be removed via UPDATE. Take care to specify
the correct key. Named will clean out any signatures generated by
the old key after the update completes.
NSEC3PARAM rollovers via UPDATE
Add the new NSEC3PARAM record via dynamic update. When the new NSEC3 chain
has been generated, the NSEC3PARAM flag field will be zero. At this
point you can remove the old NSEC3PARAM record. The old chain will
be removed after the update request completes.
Converting from NSEC to NSEC3
To do this, you just need to add an NSEC3PARAM record. When the
conversion is complete, the NSEC chain will have been removed and
the NSEC3PARAM record will have a zero flag field. The NSEC3 chain
will be generated before the NSEC chain is destroyed.
Converting from NSEC3 to NSEC
To do this, remove all NSEC3PARAM records with a zero flag field. The
NSEC chain will be generated before the NSEC3 chain is removed.
Converting from secure to insecure
To do this, remove all the DNSKEY records. Any NSEC or NSEC3 chains
will be removed as well, along with associated NSEC3PARAM records.
This will take place after the update request completes. This
requires the "dnssec-secure-to-insecure" option to be set to "yes"
in named.conf.
Periodic re-signing
In any secure zone which supports dynamic updates, named will
periodically re-sign RRsets which have not been re-signed as
a result of some update action. The signature lifetimes will
be adjusted so as to spread the re-sign load over time rather than
all at once.
NSEC3 and OPTOUT
Named only supports creating new NSEC3 chains where all the NSEC3
records in the zone have the same OPTOUT state. Named supports
UPDATES to zones where the NSEC3 records in the chain have mixed
OPTOUT state. Named does not support changing the OPTOUT state of
an individual NSEC3 record, the entire chain needs to be changed if
the OPTOUT state of an individual NSEC3 needs to be changed.
-275
View File
@@ -1,275 +0,0 @@
BIND-9 DNS Library Support
This version of BIND9 "exports" its internal libraries so that they
can be used by third-party applications more easily (we call them
"export" libraries in this document). In addition to all major
DNS-related APIs BIND9 is currently using, the export libraries
provide the following features:
- The newly created "DNS client" module. This is a higher level API
that provides an interface to name resolution, single DNS
transaction with a particular server, and dynamic update. Regarding
name resolution, it supports advanced features such as DNSSEC
validation and caching. This module supports both synchronous and
asynchronous mode.
- The new "IRS" (Information Retrieval System) library. It provides
an interface to parse the traditional resolv.conf file and more
advanced, DNS-specific configuration file for the rest of this
package (see the description for the dns.conf file below).
- As part of the IRS library, newly implemented standard address-name
mapping functions, getaddrinfo() and getnameinfo(), are provided.
They use the DNSSEC-aware validating resolver backend, and could use
other advanced features of the BIND9 libraries such as caching. The
getaddrinfo() function resolves both A and AAAA RRs concurrently
(when the address family is unspecified).
- An experimental framework to support other event libraries than
BIND9's internal event task system.
* Prerequisite
GNU make is required to build the export libraries (other part of
BIND9 can still be built with other types of make). In the reminder
of this document, "make" means GNU make. Note that in some platforms
you may need to invoke a different command name than "make"
(e.g. "gmake") to indicate it's GNU make.
* Compilation
1. ./configure --enable-exportlib [other flags]
2. make
This will create (in addition to usual BIND9 programs) and a separate
set of libraries under the lib/export directory. For example,
lib/export/dns/libdns.a is the archive file of the export version of
the BIND9 DNS library.
Sample application programs using the libraries will also be built
under the lib/export/samples directory (see below).
* Installation
1. cd lib/export
2. make install (root privilege is normally required)
(make install at the top directory will do the same)
This will install library object files under the directory specified
by the --with-export-libdir configure option (default:
EPREFIX/lib/bind9), and header files under the directory specified by
the --with-export-includedir configure option (default:
PREFIX/include/bind9).
To see how to build your own application after the installation, see
lib/export/samples/Makefile-postinstall.in
* Known Defects/Restrictions
- Currently, win32 is not supported for the export library. (Normal
BIND9 application can be built as before).
- The "fixed" RRset order is not (currently) supported in the export
library. If you want to use "fixed" RRset order for, e.g. named
while still building the export library even without the fixed
order support, build them separately:
% ./configure --enable-fixed-rrset [other flags, but not --enable-exportlib]
% make (this doesn't have to be make)
% ./configure --enable-exportlib [other flags, but not --enable-fixed-rrset]
% cd lib/export
% make
- The client module and the IRS library currently do not support
DNSSEC validation using DLV (the underlying modules can handle it,
but there is no tunable interface to enable the feature).
- RFC5011 is not supported in the validating stub resolver of the
export library. In fact, it is not clear whether it should: trust
anchors would be a system-wide configuration which would be managed
by an administrator, while the stub resolver will be used by
ordinary applications run by a normal user.
- Not all common /etc/resolv.conf options are supported in the IRS library.
The only available options in this version are "debug" and "ndots".
* The dns.conf File
The IRS library supports an "advanced" configuration file related to
the DNS library for configuration parameters that would be beyond the
capability of the resolv.conf file. Specifically, it is intended to
provide DNSSEC related configuration parameters.
By default the path to this configuration file is /etc/dns.conf.
This module is very experimental and the configuration syntax or
library interfaces may change in future versions. Currently, only the
'trusted-keys' statement is supported, whose syntax is the same as the
same name of statement for named.conf.
* Sample Applications
Some sample application programs using this API are provided for
reference. The following is a brief description of these
applications.
- sample: a simple stub resolver utility.
It sends a query of a given name (of a given optional RR type)
to a specified recursive server, and prints the result as a list of
RRs. It can also act as a validating stub resolver if a trust
anchor is given via a set of command line options.
Usage: sample [options] server_address hostname
Options and Arguments:
-t RRtype
specify the RR type of the query. The default is the A RR.
[-a algorithm] [-e] -k keyname -K keystring
specify a command-line DNS key to validate the answer. For
example, to specify the following DNSKEY of example.com:
example.com. 3600 IN DNSKEY 257 3 5 xxx
specify the options as follows:
-e -k example.com -K "xxx"
-e means that this key is a zone's "key signing key" (as known
as "secure Entry point").
when -a is omitted rsasha1 will be used by default.
-s domain:alt_server_address
specify a separate recursive server address for the specific
"domain". Example: -s example.com:2001:db8::1234
server_address
an IP(v4/v6) address of the recursive server to which queries
are sent.
hostname
the domain name for the query
- sample-async: a simple stub resolver, working asynchronously.
Similar to "sample", but accepts a list of (query) domain names as a
separate file and resolves the names asynchronously.
Usage: sample-async [-s server_address] [-t RR_type] input_file
Options and Arguments:
-s server_address
an IPv4 address of the recursive server to which queries are
sent. (IPv6 addresses are not supported in this implementation)
-t RR_type
specify the RR type of the queries. The default is the A RR.
input_file
a list of domain names to be resolved. each line consists of a
single domain name. Example:
www.example.com
mx.examle.net
ns.xxx.example
- sample-request: a simple DNS transaction client.
It sends a query to a specified server, and prints the response with
minimal processing. It doesn't act as a "stub resolver": it stops
the processing once it gets any response from the server, whether
it's a referral or an alias (CNAME or DNAME) that would require
further queries to get the ultimate answer. In other words, this
utility acts as a very simplified dig.
Usage: sample-request [-t RRtype] server_address hostname
Options and Arguments:
-t RRtype
specify the RR type of the queries. The default is the A RR.
server_address
an IP(v4/v6) address of the recursive server to which the query is
sent.
hostname
the domain name for the query
- sample-gai: getaddrinfo() and getnameinfo() test code.
This is a test program to check getaddrinfo() and getnameinfo()
behavior. It takes a host name as an argument, calls getaddrinfo()
with the given host name, and calls getnameinfo() with the resulting
IP addresses returned by getaddrinfo(). If the dns.conf file exists
and defines a trust anchor, the underlying resolver will act as a
validating resolver, and getaddrinfo()/getnameinfo() will fail with
an EAI_INSECUREDATA error when DNSSEC validation fails.
Usage: sample-gai hostname
- sample-update: a simple dynamic update client program
It accepts a single update command as a command-line argument, sends
an update request message to the authoritative server, and shows the
response from the server. In other words, this is a simplified
nsupdate.
Usage: sample-update [options] (add|delete) "update data"
Options and Arguments:
-a auth_server
An IP address of the authoritative server that has authority
for the zone containing the update name. This should normally
be the primary authoritative server that accepts dynamic
updates. It can also be a secondary server that is configured
to forward update requests to the primary server.
-k keyfile
A TSIG key file to secure the update transaction. The keyfile
format is the same as that for the nsupdate utility.
-p prerequisite
A prerequisite for the update (only one prerequisite can be
specified). The prerequisite format is the same as that is
accepted by the nsupdate utility.
-r recursive_server
An IP address of a recursive server that this utility will
use. A recursive server may be necessary to identify the
authoritative server address to which the update request is
sent.
-z zonename
The domain name of the zone that contains
(add|delete)
Specify the type of update operation. Either "add" or "delete"
must be specified.
"update data"
Specify the data to be updated. A typical example of the data
would look like "name TTL RRtype RDATA".
Note: in practice, either -a or -r must be specified. Others can
be optional; the underlying library routine tries to identify the
appropriate server and the zone name for the update.
Examples: assuming the primary authoritative server of the
dynamic.example.com zone has an IPv6 address 2001:db8::1234,
+ sample-update -a sample-update -k Kxxx.+nnn+mmmm.key add "foo.dynamic.example.com 30 IN A 192.168.2.1"
adds an A RR for foo.dynamic.example.com using the given key.
+ sample-update -a sample-update -k Kxxx.+nnn+mmmm.key delete "foo.dynamic.example.com 30 IN A"
removes all A RRs for foo.dynamic.example.com using the given key.
+ sample-update -a sample-update -k Kxxx.+nnn+mmmm.key delete "foo.dynamic.example.com"
removes all RRs for foo.dynamic.example.com using the given key.
- nsprobe: domain/name server checker in terms of RFC4074.
It checks a set of domains to see the name servers of the domains
behave correctly in terms of RFC4074. This is included in the set
of sample programs to show how the export library can be used in a
DNS-related application.
Usage: nsprobe [-d] [-v [-v...]] [-c cache_address] [input_file]
Options
-d
run in the "debug" mode. with this option nsprobe will dump
every RRs it receives.
-v
increase verbosity of other normal log messages. This can be
specified multiple times
-c cache_address
specify an IP address of a recursive (caching) name server.
nsprobe uses this server to get the NS RRset of each domain and
the A and/or AAAA RRsets for the name servers. The default
value is 127.0.0.1.
input_file
a file name containing a list of domain (zone) names to be
probed. when omitted the standard input will be used. Each
line of the input file specifies a single domain name such as
"example.com". In general this domain name must be the apex
name of some DNS zone (unlike normal "host names" such as
"www.example.com"). nsprobe first identifies the NS RRsets for
the given domain name, and sends A and AAAA queries to these
servers for some "widely used" names under the zone;
specifically, adding "www" and "ftp" to the zone name.
* Library References
As of this writing, there is no formal "manual" of the libraries,
except this document, header files (some of them provide pretty
detailed explanations), and sample application programs.
; $Id: README.libdns,v 1.3 2009/09/15 19:12:03 jinmei Exp $
-309
View File
@@ -1,309 +0,0 @@
BIND 9 PKCS #11 (Cryptoki) support
INTRODUCTION
PKCS #11 (Public Key Cryptography Standard #11) defines a platform-
independent API for the control of hardware security modules (HSMs)
and other cryptographic support devices.
BIND 9 is known to work with two HSMs: The Sun SCA 6000 cryptographic
acceleration board, tested under Solaris x86, and the AEP Keyper
network-attached key storage device, tested with Debian Linux,
Solaris x86 and Windows Server 2003.
PREREQUISITES
See the HSM vendor documentation for information about installing,
initializing, testing and troubleshooting the HSM.
BIND 9 uses OpenSSL for cryptography, but stock OpenSSL does not
yet fully support PKCS #11. However, a PKCS #11 engine for OpenSSL
is available from the OpenSolaris project. It has been modified by
ISC to work with with BIND 9, and to provide new features such as
PIN management and key by reference.
The patched OpenSSL depends on a "PKCS #11 provider". This is a shared
library object, providing a low-level PKCS #11 interface to the HSM
hardware. It is dynamically loaded by OpenSSL at runtime. The PKCS #11
provider comes from the HSM vendor, and and is specific to the HSM to be
controlled.
There are two "flavors" of PKCS #11 support provided by the patched
OpenSSL, one of which must be chosen at configuration time. The correct
choice depends on the HSM hardware:
- Use 'crypto-accelerator' with HSMs that have hardware cryptographic
acceleration features, such as the SCA 6000 board. This causes OpenSSL
to run all supported cryptographic operations in the HSM.
- Use 'sign-only' with HSMs that are designed to function primarily as
secure key storage devices, but lack hardware acceleration. These
devices are highly secure, but are not necessarily any faster at
cryptography than the system CPU--often, they are slower. It is
therefore most efficient to use them only for those cryptographic
functions that require access to the secured private key, such as
zone signing, and to use the system CPU for all other computationally-
intensive operations. The AEP Keyper is an example of such a device.
The modified OpenSSL code is included in the BIND 9.7.0b1 release, in the
form of a context diff against OpenSSL 0.9.8l. Before building BIND 9
with PKCS #11 support, it will be necessary to build OpenSSL with this
patch in place and inform it of the path to the HSM-specific PKCS #11
provider library.
Obtain OpenSSL 0.9.8l:
wget http://www.openssl.org/source/openssl-0.9.8l.tar.gz
Extract the tarball:
tar zxf openssl-0.9.8l.tar.gz
Apply the patch from the BIND 9 release:
patch -p1 -d openssl-0.9.8l \
< bind-9.7.0b1/bin/pkcs11/openssl-0.9.8l-patch
(Note that the patch file may not be compatible with the "patch"
utility on all operating systems. You may need to install GNU patch.)
When building OpenSSL, place it in a non-standard location so that it
does not interfere with OpenSSL libraries elsewhere on the system.
In the following examples, we choose to install into "/opt/pkcs11/usr".
We will use this location when we configure BIND 9.
EXAMPLE 1--BUILDING OPENSSL FOR THE AEP KEYPER ON LINUX:
The AEP Keyper is a highly secure key storage device, but does
not provide hardware cryptographic acceleration. It can carry out
cryptographic operations, but it is probably slower than your
system's CPU. Therefore, we choose the 'sign-only' flavor when
building OpenSSL.
The Keyper-specific PKCS #11 provider library is delivered with the
Keyper software. In this example, we place it /opt/pkcs11/usr/lib:
cp pkcs11.GCC4.0.2.so.4.05 /opt/pkcs11/usr/lib/libpkcs11.so
This library is only available for Linux as a 32-bit binary. If we are
compiling on a 64-bit Linux system, it is necessary to force a 32-bit
build, by specifying -m32 in the build options.
Finally, the Keyper library requires threads, so we must specify -pthread.
cd openssl-0.9.8l
./Configure linux-generic32 -m32 -pthread \
--pk11-libname=/opt/pkcs11/usr/lib/libpkcs11.so \
--pk11-flavor=sign-only \
--prefix=/opt/pkcs11/usr
After configuring, run "make" and "make test". If "make test" fails
with "pthread_atfork() not found", you forgot to add the -pthread
above.
EXAMPLE 2--BUILDING OPENSSL FOR THE SCA 6000 ON SOLARIS:
The SCA-6000 PKCS #11 provider is installed as a system library,
libpkcs11. It is a true crypto accelerator, up to 4 times faster
than any CPU, so the flavor shall be 'crypto-accelerator'.
In this example, we are building on Solaris x86 on an AMD64 system.
cd openssl-0.9.8l
./Configure solaris64-x86_64-cc \
--pk11-libname=/usr/lib/64/libpkcs11.so \
--pk11-flavor=crypto-accelerator \
--prefix=/opt/pkcs11/usr
(For a 32-bit build, use "solaris-x86-cc" and /usr/lib/libpkcs11.so.)
After configuring, run "make" and "make test".
Once you have built OpenSSL, run "apps/openssl engine pkcs11" to confirm
that PKCS #11 support was compiled in correctly. The output should be
one of the following lines, depending on the flavor selected:
(pkcs11) PKCS #11 engine support (sign only)
Or:
(pkcs11) PKCS #11 engine support (crypto accelerator)
Next, run "apps/openssl engine pkcs11 -t". This will attempt to initialize
the PKCS #11 engine. If it is able to do so successfully, it will report
"[ available ]".
If the output is correct, run "make install".
BUILDING BIND 9
When building BIND 9, the location of the custom-built OpenSSL
library must be specified via configure.
EXAMPLE 3--CONFIGURING BIND 9 FOR LINUX
To link with the PKCS #11 provider, threads must be enabled in the
BIND 9 build.
The PKCS #11 library for the AEP Keyper is currently only available as
a 32-bit binary. If we are building on a 64-bit host, we must force a
32-bit build by adding "-m32" to the CC options on the "configure"
command line.
cd ../bind-9.7.0b1
./configure CC="gcc -m32" --enable-threads \
--with-openssl=/opt/pkcs11/usr \
--with-pkcs11=/opt/pkcs11/usr/lib/libpkcs11.so
EXAMPLE 4--CONFIGURING BIND 9 FOR SOLARIS
To link with the PKCS #11 provider, threads must be enabled in the
BIND 9 build.
cd ../bind-9.7.0b1
./configure CC="cc -xarch=amd64" --enable-threads \
--with-openssl=/opt/pkcs11/usr \
--with-pkcs11=/usr/lib/64/libpkcs11.so
(For a 32-bit build, omit CC="cc -xarch=amd64".)
If configure complains about OpenSSL not working, you may have a 32/64-bit
architecture mismatch. Or, you may have incorrectly specified the path to
OpenSSL (it should be the same as the --prefix argument to the OpenSSL
Configure).
After configuring, run "make", "make test" and "make install".
PKCS #11 TOOLS
BIND 9 includes a minimal set of tools to operate the HSM, including
"pkcs11-keygen" to generate a new key pair within the HSM, "pkcs11-list"
to list objects currently available, and "pkcs11-destroy" to remove
objects.
In UNIX/Linux builds, these tools are built only if BIND 9 is configured
with the --with-pkcs11 option. (NOTE: If --with-pkcs11 is set to "yes",
rather than to the path of the PKCS #11 provider, then the tools will be
built but the provider will be left undefined. Use the -m option or the
PKCS11_PROVIDER environment variable to specify the path to the provider.)
USING THE HSM
First, we must set up the runtime environment so the OpenSSL and PKCS #11
libraries can be loaded:
export LD_LIBRARY_PATH=/opt/pkcs11/usr/lib:${LD_LIBRARY_PATH}
When operating an AEP Keyper, it is also necessary to specify the
location of the "machine" file, which stores information about the Keyper
for use by PKCS #11 provider library. If the machine file is in
/opt/Keyper/PKCS11Provider/machine, use:
export KEYPER_LIBRARY_PATH=/opt/Keyper/PKCS11Provider
These environment variables must be set whenever running any tool
that uses the HSM, including pkcs11-keygen, pkcs11-list, pkcs11-destroy,
dnssec-keyfromlabel, dnssec-signzone, dnssec-keygen (which will use
the HSM for random number generation), and named.
We can now create and use keys in the HSM. In this case, we will
create a 2048 bit key and give it the label "sample-ksk":
pkcs11-keygen -b 2048 -l sample-ksk
To confirm that the key exists:
pkcs11-list
Enter PIN:
object[0]: handle 2147483658 class 3 label[8] 'sample-ksk' id[0]
object[1]: handle 2147483657 class 2 label[8] 'sample-ksk' id[0]
Before using this key to sign a zone, we must create a pair of BIND 9
key files. The "dnssec-keyfromlabel" utility does this. In this case,
we will be using the HSM key "sample-ksk" as the key-signing key for
"example.net":
dnssec-keyfromlabel -l sample-ksk -f KSK example.net
The resulting K*.key and K*.private files can now be used to sign the
zone. Unlike normal K* files, which contain both public and private
key data, these files will contain only the public key data, plus an
identifier for the private key which remains stored within the HSM.
The HSM handles signing with the private key.
If you wish to generate a second key in the HSM for use as a zone-signing
key, follow the same procedure above, using a different keylabel, a
smaller key size, and omitting "-f KSK" from the dnssec-keyfromlabel
arguments:
pkcs11-keygen -b 1024 -l sample-zsk
dnssec-keyfromlabel -l sample-zsk example.net
Alternatively, you may prefer to generate a conventional on-disk key,
using dnssec-keygen:
dnssec-keygen example.net
This provides less security than an HSM key, but since HSMs can be
slow or cumbersome to use for security reasons, it may be more
efficient to reserve HSM keys for use in the less frequent
key-signing operation. The zone-signing key can be rolled more
frequently, if you wish, to compensate for a reduction in key
security.
Now you can sign the zone. (Note: If not using the -S option to
dnssec-signzone, it will be necessary to add the contents of both
K*.key files to the zone master file before signing it.)
dnssec-signzone -S example.net
Enter PIN:
Verifying the zone using the following algorithms: NSEC3RSASHA1.
Zone signing complete:
Algorithm: NSEC3RSASHA1: ZSKs: 1, KSKs: 1 active, 0 revoked, 0 stand-by
example.net.signed
SPECIFYING THE ENGINE ON THE COMMAND LINE
The OpenSSL engine can be specified in named and all of the dnssec-*
tools by using the "-E <engine>" command line option. If BIND 9 is built
with the --with-pkcs11 option, this option defaults to "pkcs11".
Specifying the engine will generally not be necessary unless for
some reason you wish to use a different OpenSSL engine.
If you wish to disable use of the "pkcs11" engine--for troubleshooting
purposes, or because the HSM is unavailable--set the engine to the empty
string. For example:
dnssec-signzone -E '' -S example.net
This causes dnssec-signzone to run as if it were compiled without the
--with-pkcs11 option.
RUNNING NAMED WITH AUTOMATIC ZONE RE-SIGNING
If you want named to dynamically re-sign zones using HSM keys, and/or to
to sign new records inserted via nsupdate, then named must have access
to the HSM PIN. This can be accomplished by placing the PIN into the
openssl.cnf file (in the above examples, /opt/pkcs11/usr/ssl/openssl.cnf).
The location of the openssl.cnf file can be overridden by setting the
OPENSSL_CONF environment variable before running named.
Sample openssl.cnf:
openssl_conf = openssl_def
[ openssl_def ]
engines = engine_section
[ engine_section ]
pkcs11 = pkcs11_section
[ pkcs11_section ]
PIN = <PLACE PIN HERE>
This will also allow the dnssec-* tools to access the HSM without
PIN entry. (The pkcs11-* tools access the HSM directly, not via
OpenSSL, so a PIN will still be required to use them.)
PLEASE NOTE: Placing the HSM's PIN in a text file in this manner
may reduce the security advantage of using an HSM. Be sure this
is what you want to do before configuring BIND 9 in this way.
-74
View File
@@ -1,74 +0,0 @@
BIND 9 RFC 5011 support
BIND 9.7.0 introduces support for RFC 5011, dynamic trust anchor
management. Using this feature allows named to keep track of changes to
critical DNSSEC keys without any need for the operator to make changes to
configuration files.
VALIDATING RESOLVER
-------------------
To configure a validating resolver to use RFC5011 to maintain a trust
anchor, configure the trust anchor using a "managed-keys" statement.
Information about this can be found in the ARM, in the section titled
"managed-keys Statement Definition".
AUTHORITATIVE SERVER
--------------------
To set up an authoritative zone for RFC5011 trust anchor maintenance,
generate two (or more) key signing keys (KSKs) for the zone. Sign the zone
with one of them; this is the "active" KSK. All KSK's which do not sign
the zone are "stand-by" keys.
Any validating resolver which is configured to use the active KSK as an
RFC5011-managed trust anchor will take note of the stand-by KSKs in the
zone's DNSKEY RRset, and store them for future reference. The resolver
will recheck the zone periodically, and after 30 days, if the new key is
still there, then the key will be accepted by the resolver as a valid
trust anchor for the zone. Any time after this 30-day acceptance timer
has completed, the active KSK can be revoked, and the zone can be "rolled
over" to the newly accepted key.
The easiest way to place a stand-by key in a zone is to use the "smart
signing" features of dnssec-keygen and dnssec-signzone. If a key with a
publication date in the past, but an activation date which is unset or in
the future, "dnssec-signzone -S" will include the DNSKEY record in the
zone, but will not sign with it:
$ dnssec-keygen -K keys -f KSK -P now -A now+2y example.net
$ dnssec-signzone -S -K keys example.net
To revoke a key, the new command "dnssec-revoke" has been added. This adds
the REVOKED bit to the key flags and re-generates the K*.key and K*.private
files.
After revoking the active key, the zone must be signed with both the
revoked KSK and the new active KSK. (Smart signing takes care of this
automatically.)
Once a key has been revoked and used to sign the DNSKEY RRset in which it
appears, that key will never again be accepted as a valid trust anchor by
the resolver. However, validation can proceed using the new active key
(which had been accepted by the resolver when it was a stand-by key).
See RFC 5011 for more details on key rollover scenarios.
When a key has been revoked, its key ID changes, increasing by
128, and wrapping around at 65535. So, for example, the key
"Kexample.com.+005+10000" becomes "Kexample.com.+005+10128".
If two keys have ID's exactly 128 apart, and one is revoked, then the
two key ID's will collide, causing several problems. To prevent this,
dnssec-keygen will not generate a new key if another key is present which
may collide. This checking will only occur if the new keys are written
to the same directory which holds all other keys in use for that zone.
Older versions of BIND 9 did not have this precaution. Exercise caution if
using key revocation on keys that were generated by previous releases, or
if using keys stored in multiple directories or on multiple machines.
It is expected that a future release of BIND 9 will address this problem
in a different way, by storing revoked keys with their original unrevoked
key ID's.
-1
View File
@@ -1 +0,0 @@
Makefile
+1 -1
View File
@@ -1,4 +1,4 @@
# Copyright (C) 2004, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2004, 2007, 2009, 2012 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 1998-2001 Internet Software Consortium.
#
# Permission to use, copy, modify, and/or distribute this software for any
@@ -1,6 +1,3 @@
Makefile
.libs
*.la
*.lo
named-checkconf
named-checkzone
+1 -1
View File
@@ -1,4 +1,4 @@
# Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2004-2007, 2009, 2012 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2000-2003 Internet Software Consortium.
#
# Permission to use, copy, modify, and/or distribute this software for any
+29 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2000-2002 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: check-tool.c,v 1.39 2009/09/01 00:22:24 jinmei Exp $ */
/* $Id: check-tool.c,v 1.39.104.2 2010/09/07 23:46:37 tbox Exp $ */
/*! \file */
@@ -23,6 +23,10 @@
#include <stdio.h>
#ifdef _WIN32
#include <Winsock2.h>
#endif
#include "check-tool.h"
#include <isc/buffer.h>
#include <isc/log.h>
@@ -661,3 +665,26 @@ dump_zone(const char *zonename, dns_zone_t *zone, const char *filename,
return (result);
}
#ifdef _WIN32
void
InitSockets(void) {
WORD wVersionRequested;
WSADATA wsaData;
int err;
wVersionRequested = MAKEWORD(2, 0);
err = WSAStartup( wVersionRequested, &wsaData );
if (err != 0) {
fprintf(stderr, "WSAStartup() failed: %d\n", err);
exit(1);
}
}
void
DestroySockets(void) {
WSACleanup();
}
#endif
+7 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2005, 2007, 2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2000-2002 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: check-tool.h,v 1.14 2007/06/18 23:47:17 tbox Exp $ */
/* $Id: check-tool.h,v 1.14.560.2 2010/09/07 23:46:37 tbox Exp $ */
#ifndef CHECK_TOOL_H
#define CHECK_TOOL_H
@@ -43,6 +43,11 @@ isc_result_t
dump_zone(const char *zonename, dns_zone_t *zone, const char *filename,
dns_masterformat_t fileformat, const dns_master_style_t *style);
#ifdef _WIN32
void InitSockets(void);
void DestroySockets(void);
#endif
extern int debug;
extern isc_boolean_t nomerge;
extern isc_boolean_t docheckmx;
+1 -1
View File
@@ -13,7 +13,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: named-checkconf.8,v 1.32.126.1 2009/12/29 02:09:32 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
+12 -4
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2007, 2009-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2002 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: named-checkconf.c,v 1.51 2009/12/04 21:09:32 marka Exp $ */
/* $Id: named-checkconf.c,v 1.51.4.5 2011/03/12 04:58:23 tbox Exp $ */
/*! \file */
@@ -64,7 +64,7 @@ usage(void) ISC_PLATFORM_NORETURN_POST;
static void
usage(void) {
fprintf(stderr, "usage: %s [-h] [-j] [-v] [-z] [-t directory] "
fprintf(stderr, "usage: %s [-h] [-j] [-p] [-v] [-z] [-t directory] "
"[named.conf]\n", program);
exit(1);
}
@@ -190,7 +190,7 @@ configure_zone(const char *vclass, const char *view,
if (obj != NULL)
maps[i++] = obj;
}
maps[i++] = NULL;
maps[i] = NULL;
cfg_map_get(zoptions, "type", &typeobj);
if (typeobj == NULL)
@@ -488,6 +488,10 @@ main(int argc, char **argv) {
if (conffile == NULL || conffile[0] == '\0')
conffile = NAMED_CONFFILE;
#ifdef _WIN32
InitSockets();
#endif
RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
RUNTIME_CHECK(setup_logging(mctx, stdout, &logc) == ISC_R_SUCCESS);
@@ -531,5 +535,9 @@ main(int argc, char **argv) {
isc_mem_destroy(&mctx);
#ifdef _WIN32
DestroySockets();
#endif
return (exit_status);
}
+6 -6
View File
@@ -14,7 +14,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: named-checkconf.html,v 1.32.126.1 2009/12/29 02:09:33 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -32,7 +32,7 @@
<div class="cmdsynopsis"><p><code class="command">named-checkconf</code> [<code class="option">-h</code>] [<code class="option">-v</code>] [<code class="option">-j</code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] {filename} [<code class="option">-p</code>] [<code class="option">-z</code>]</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543395"></a><h2>DESCRIPTION</h2>
<a name="id2543396"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">named-checkconf</strong></span>
checks the syntax, but not the semantics, of a
<span><strong class="command">named</strong></span> configuration file. The file is parsed
@@ -52,7 +52,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543444"></a><h2>OPTIONS</h2>
<a name="id2543445"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-h</span></dt>
<dd><p>
@@ -91,21 +91,21 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543568"></a><h2>RETURN VALUES</h2>
<a name="id2543569"></a><h2>RETURN VALUES</h2>
<p><span><strong class="command">named-checkconf</strong></span>
returns an exit status of 1 if
errors were detected and 0 otherwise.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543579"></a><h2>SEE ALSO</h2>
<a name="id2543580"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">named-checkzone</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543609"></a><h2>AUTHOR</h2>
<a name="id2543610"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
+1 -1
View File
@@ -13,7 +13,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: named-checkzone.8,v 1.46 2009/12/04 22:22:25 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
+16 -5
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: named-checkzone.c,v 1.59 2009/12/04 22:06:37 tbox Exp $ */
/* $Id: named-checkzone.c,v 1.59.4.4 2011/12/22 23:45:33 tbox Exp $ */
/*! \file */
@@ -112,6 +112,7 @@ main(int argc, char **argv) {
const char *outputformatstr = NULL;
dns_masterformat_t inputformat = dns_masterformat_text;
dns_masterformat_t outputformat = dns_masterformat_text;
isc_boolean_t logdump = ISC_FALSE;
FILE *errout = stdout;
outputstyle = &dns_master_style_full;
@@ -418,6 +419,7 @@ main(int argc, char **argv) {
if (progmode == progmode_compile) {
dumpzone = 1; /* always dump */
logdump = !quiet;
if (output_filename == NULL) {
fprintf(stderr,
"output file required, but not specified\n");
@@ -436,12 +438,18 @@ main(int argc, char **argv) {
(output_filename == NULL ||
strcmp(output_filename, "-") == 0 ||
strcmp(output_filename, "/dev/fd/1") == 0 ||
strcmp(output_filename, "/dev/stdout") == 0))
strcmp(output_filename, "/dev/stdout") == 0)) {
errout = stderr;
logdump = ISC_FALSE;
}
if (isc_commandline_index + 2 != argc)
usage();
#ifdef _WIN32
InitSockets();
#endif
RUNTIME_CHECK(isc_mem_create(0, 0, &mctx) == ISC_R_SUCCESS);
if (!quiet)
RUNTIME_CHECK(setup_logging(mctx, errout, &lctx)
@@ -458,13 +466,13 @@ main(int argc, char **argv) {
&zone);
if (result == ISC_R_SUCCESS && dumpzone) {
if (!quiet && progmode == progmode_compile) {
if (logdump) {
fprintf(errout, "dump zone to %s...", output_filename);
fflush(errout);
}
result = dump_zone(origin, zone, output_filename,
outputformat, outputstyle);
if (!quiet && progmode == progmode_compile)
if (logdump)
fprintf(errout, "done\n");
}
@@ -476,5 +484,8 @@ main(int argc, char **argv) {
isc_hash_destroy();
isc_entropy_detach(&ectx);
isc_mem_destroy(&mctx);
#ifdef _WIN32
DestroySockets();
#endif
return ((result == ISC_R_SUCCESS) ? 0 : 1);
}
+6 -6
View File
@@ -14,7 +14,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: named-checkzone.html,v 1.46 2009/12/04 22:22:25 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -33,7 +33,7 @@
<div class="cmdsynopsis"><p><code class="command">named-compilezone</code> [<code class="option">-d</code>] [<code class="option">-j</code>] [<code class="option">-q</code>] [<code class="option">-v</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-C <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-f <em class="replaceable"><code>format</code></em></code>] [<code class="option">-F <em class="replaceable"><code>format</code></em></code>] [<code class="option">-i <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-k <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-m <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-n <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-o <em class="replaceable"><code>filename</code></em></code>] [<code class="option">-r <em class="replaceable"><code>mode</code></em></code>] [<code class="option">-s <em class="replaceable"><code>style</code></em></code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-w <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-D</code>] [<code class="option">-W <em class="replaceable"><code>mode</code></em></code>] {<code class="option">-o <em class="replaceable"><code>filename</code></em></code>} {zonename} {filename}</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543691"></a><h2>DESCRIPTION</h2>
<a name="id2543692"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">named-checkzone</strong></span>
checks the syntax and integrity of a zone file. It performs the
same checks as <span><strong class="command">named</strong></span> does when loading a
@@ -53,7 +53,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543726"></a><h2>OPTIONS</h2>
<a name="id2543728"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-d</span></dt>
<dd><p>
@@ -247,14 +247,14 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2544374"></a><h2>RETURN VALUES</h2>
<a name="id2544443"></a><h2>RETURN VALUES</h2>
<p><span><strong class="command">named-checkzone</strong></span>
returns an exit status of 1 if
errors were detected and 0 otherwise.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544386"></a><h2>SEE ALSO</h2>
<a name="id2544455"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">named-checkconf</span>(8)</span>,
<em class="citetitle">RFC 1035</em>,
@@ -262,7 +262,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544419"></a><h2>AUTHOR</h2>
<a name="id2544488"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
@@ -1,3 +1,2 @@
Makefile
ddns-confgen
rndc-confgen
+1 -1
View File
@@ -1,4 +1,4 @@
# Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2009, 2012 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
+1 -1
View File
@@ -12,7 +12,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: ddns-confgen.8,v 1.10 2009/09/19 01:14:52 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
+3 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: ddns-confgen.c,v 1.9 2009/09/29 15:06:05 fdupont Exp $ */
/* $Id: ddns-confgen.c,v 1.9.66.2 2011/03/12 04:58:23 tbox Exp $ */
/*! \file */
@@ -160,6 +160,7 @@ main(int argc, char **argv) {
argc -= isc_commandline_index;
argv += isc_commandline_index;
POST(argv);
if (self_domain != NULL && zone != NULL)
usage(1); /* -s and -z cannot coexist */
+5 -5
View File
@@ -13,7 +13,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: ddns-confgen.html,v 1.10 2009/09/19 01:14:52 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -31,7 +31,7 @@
<div class="cmdsynopsis"><p><code class="command">ddns-confgen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-h</code>] [<code class="option">-k <em class="replaceable"><code>keyname</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomfile</code></em></code>] [ -s <em class="replaceable"><code>name</code></em> | -z <em class="replaceable"><code>zone</code></em> ] [<code class="option">-q</code>] [name]</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543395"></a><h2>DESCRIPTION</h2>
<a name="id2543396"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">ddns-confgen</strong></span>
generates a key for use by <span><strong class="command">nsupdate</strong></span>
and <span><strong class="command">named</strong></span>. It simplifies configuration
@@ -58,7 +58,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543454"></a><h2>OPTIONS</h2>
<a name="id2543456"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
<dd><p>
@@ -125,7 +125,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543642"></a><h2>SEE ALSO</h2>
<a name="id2543643"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">nsupdate</span>(1)</span>,
<span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>,
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
@@ -133,7 +133,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543681"></a><h2>AUTHOR</h2>
<a name="id2543682"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
+1 -1
View File
@@ -13,7 +13,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: rndc-confgen.8,v 1.7 2009/07/11 01:12:45 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
+3 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2005, 2007-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2005, 2007-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2001, 2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: rndc-confgen.c,v 1.5 2009/09/29 15:06:05 fdupont Exp $ */
/* $Id: rndc-confgen.c,v 1.5.66.2 2011/03/12 04:58:23 tbox Exp $ */
/*! \file */
@@ -200,6 +200,7 @@ main(int argc, char **argv) {
argc -= isc_commandline_index;
argv += isc_commandline_index;
POST(argv);
if (argc > 0)
usage(1);
+6 -6
View File
@@ -14,7 +14,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: rndc-confgen.html,v 1.7 2009/07/11 01:12:45 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -32,7 +32,7 @@
<div class="cmdsynopsis"><p><code class="command">rndc-confgen</code> [<code class="option">-a</code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-c <em class="replaceable"><code>keyfile</code></em></code>] [<code class="option">-h</code>] [<code class="option">-k <em class="replaceable"><code>keyname</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomfile</code></em></code>] [<code class="option">-s <em class="replaceable"><code>address</code></em></code>] [<code class="option">-t <em class="replaceable"><code>chrootdir</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>]</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543432"></a><h2>DESCRIPTION</h2>
<a name="id2543433"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">rndc-confgen</strong></span>
generates configuration files
for <span><strong class="command">rndc</strong></span>. It can be used as a
@@ -48,7 +48,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543477"></a><h2>OPTIONS</h2>
<a name="id2543478"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-a</span></dt>
<dd>
@@ -155,7 +155,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543790"></a><h2>EXAMPLES</h2>
<a name="id2543792"></a><h2>EXAMPLES</h2>
<p>
To allow <span><strong class="command">rndc</strong></span> to be used with
no manual configuration, run
@@ -172,7 +172,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543832"></a><h2>SEE ALSO</h2>
<a name="id2543833"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">rndc</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">rndc.conf</span>(5)</span>,
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
@@ -180,7 +180,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543870"></a><h2>AUTHOR</h2>
<a name="id2543872"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
+1 -1
View File
@@ -1,4 +1,4 @@
# Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2009, 2012 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
@@ -1,6 +1,4 @@
Makefile
dig
host
nslookup
*.lo
.libs
+1 -1
View File
@@ -1,4 +1,4 @@
# Copyright (C) 2004, 2005, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2004, 2005, 2007, 2009, 2012 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2000-2002 Internet Software Consortium.
#
# Permission to use, copy, modify, and/or distribute this software for any
+1 -1
View File
@@ -13,7 +13,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: dig.1,v 1.53 2009/07/11 01:12:45 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
+9 -36
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2000-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dig.c,v 1.233 2009/10/03 18:03:53 each Exp $ */
/* $Id: dig.c,v 1.233.62.7 2011/12/07 17:24:25 each Exp $ */
/*! \file */
@@ -44,8 +44,6 @@
#include <dns/result.h>
#include <dns/tsig.h>
#include <bind9/getaddresses.h>
#include <dig/dig.h>
#define ADD_STRING(b, s) { \
@@ -309,6 +307,8 @@ say_message(dns_rdata_t *rdata, dig_query_t *query, isc_buffer_t *buf) {
ADD_STRING(buf, " ");
}
result = dns_rdata_totext(rdata, NULL, buf);
if (result == ISC_R_NOSPACE)
return (result);
check_result(result, "dns_rdata_totext");
if (query->lookup->identify) {
TIME_NOW(&now);
@@ -331,10 +331,8 @@ short_answer(dns_message_t *msg, dns_messagetextflag_t flags,
{
dns_name_t *name;
dns_rdataset_t *rdataset;
isc_buffer_t target;
isc_result_t result, loopresult;
dns_name_t empty_name;
char t[4096];
dns_rdata_t rdata = DNS_RDATA_INIT;
UNUSED(flags);
@@ -350,8 +348,6 @@ short_answer(dns_message_t *msg, dns_messagetextflag_t flags,
name = NULL;
dns_message_currentname(msg, DNS_SECTION_ANSWER, &name);
isc_buffer_init(&target, t, sizeof(t));
for (rdataset = ISC_LIST_HEAD(name->list);
rdataset != NULL;
rdataset = ISC_LIST_NEXT(rdataset, link)) {
@@ -360,6 +356,8 @@ short_answer(dns_message_t *msg, dns_messagetextflag_t flags,
dns_rdataset_current(rdataset, &rdata);
result = say_message(&rdata, query,
buf);
if (result == ISC_R_NOSPACE)
return (result);
check_result(result, "say_message");
loopresult = dns_rdataset_next(rdataset);
dns_rdata_reset(&rdata);
@@ -474,8 +472,6 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
if (!query->lookup->comments)
flags |= DNS_MESSAGETEXTFLAG_NOCOMMENTS;
result = ISC_R_SUCCESS;
result = isc_buffer_allocate(mctx, &buf, len);
check_result(result, "isc_buffer_allocate");
@@ -508,6 +504,8 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
printf(" ad");
if ((msg->flags & DNS_MESSAGEFLAG_CD) != 0)
printf(" cd");
if ((msg->flags & 0x0040U) != 0)
printf("; MBZ: 0x4");
printf("; QUERY: %u, ANSWER: %u, "
"AUTHORITY: %u, ADDITIONAL: %u\n",
@@ -1426,30 +1424,6 @@ preparse_args(int argc, char **argv) {
}
}
static void
getaddresses(dig_lookup_t *lookup, const char *host) {
isc_result_t result;
isc_sockaddr_t sockaddrs[DIG_MAX_ADDRESSES];
isc_netaddr_t netaddr;
int count, i;
dig_server_t *srv;
char tmp[ISC_NETADDR_FORMATSIZE];
result = bind9_getaddresses(host, 0, sockaddrs,
DIG_MAX_ADDRESSES, &count);
if (result != ISC_R_SUCCESS)
fatal("couldn't get address for '%s': %s",
host, isc_result_totext(result));
for (i = 0; i < count; i++) {
isc_netaddr_fromsockaddr(&netaddr, &sockaddrs[i]);
isc_netaddr_format(&netaddr, tmp, sizeof(tmp));
srv = make_server(tmp, host);
ISC_LIST_APPEND(lookup->my_server_list, srv, link);
}
addresscount = count;
}
static void
parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
int argc, char **argv) {
@@ -1544,7 +1518,7 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
if (strncmp(rv[0], "%", 1) == 0)
break;
if (strncmp(rv[0], "@", 1) == 0) {
getaddresses(lookup, &rv[0][1]);
addresscount = getaddresses(lookup, &rv[0][1], NULL);
} else if (rv[0][0] == '+') {
plus_option(&rv[0][1], is_batchfile,
lookup);
@@ -1581,7 +1555,6 @@ parse_args(isc_boolean_t is_batchfile, isc_boolean_t config_only,
(isc_textregion_t *)&tr);
if (result == ISC_R_SUCCESS &&
rdtype == dns_rdatatype_ixfr) {
result = DNS_R_UNKNOWN;
fprintf(stderr, ";; Warning, "
"ixfr requires a "
"serial number\n");
+10 -10
View File
@@ -14,7 +14,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dig.html,v 1.48 2009/07/11 01:12:45 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -34,7 +34,7 @@
<div class="cmdsynopsis"><p><code class="command">dig</code> [global-queryopt...] [query...]</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543518"></a><h2>DESCRIPTION</h2>
<a name="id2543521"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">dig</strong></span>
(domain information groper) is a flexible tool
for interrogating DNS name servers. It performs DNS lookups and
@@ -80,7 +80,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543592"></a><h2>SIMPLE USAGE</h2>
<a name="id2543594"></a><h2>SIMPLE USAGE</h2>
<p>
A typical invocation of <span><strong class="command">dig</strong></span> looks like:
</p>
@@ -126,7 +126,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543683"></a><h2>OPTIONS</h2>
<a name="id2543685"></a><h2>OPTIONS</h2>
<p>
The <code class="option">-b</code> option sets the source IP address of the query
to <em class="parameter"><code>address</code></em>. This must be a valid
@@ -230,7 +230,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544032"></a><h2>QUERY OPTIONS</h2>
<a name="id2544034"></a><h2>QUERY OPTIONS</h2>
<p><span><strong class="command">dig</strong></span>
provides a number of query options which affect
the way in which lookups are made and the results displayed. Some of
@@ -555,7 +555,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2545166"></a><h2>MULTIPLE QUERIES</h2>
<a name="id2545169"></a><h2>MULTIPLE QUERIES</h2>
<p>
The BIND 9 implementation of <span><strong class="command">dig </strong></span>
supports
@@ -601,7 +601,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2545228"></a><h2>IDN SUPPORT</h2>
<a name="id2545230"></a><h2>IDN SUPPORT</h2>
<p>
If <span><strong class="command">dig</strong></span> has been built with IDN (internationalized
domain name) support, it can accept and display non-ASCII domain names.
@@ -615,14 +615,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2545251"></a><h2>FILES</h2>
<a name="id2545253"></a><h2>FILES</h2>
<p><code class="filename">/etc/resolv.conf</code>
</p>
<p><code class="filename">${HOME}/.digrc</code>
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2545336"></a><h2>SEE ALSO</h2>
<a name="id2545338"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">host</span>(1)</span>,
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
@@ -630,7 +630,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2545373"></a><h2>BUGS</h2>
<a name="id2545376"></a><h2>BUGS</h2>
<p>
There are probably too many query options.
</p>
+132 -68
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2000-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dighost.c,v 1.328 2009/11/10 17:27:40 each Exp $ */
/* $Id: dighost.c,v 1.328.22.15 2011/12/07 17:24:25 each Exp $ */
/*! \file
* \note
@@ -66,6 +66,7 @@
#include <dns/tsig.h>
#include <dst/dst.h>
#include <dst/result.h>
#include <isc/app.h>
#include <isc/base64.h>
@@ -81,6 +82,7 @@
#include <isc/print.h>
#include <isc/random.h>
#include <isc/result.h>
#include <isc/serial.h>
#include <isc/string.h>
#include <isc/task.h>
#include <isc/timer.h>
@@ -252,7 +254,7 @@ isc_result_t opentmpkey(isc_mem_t *mctx, const char *file,
char **tempp, FILE **fp);
isc_result_t removetmpkey(isc_mem_t *mctx, const char *file);
void clean_trustedkey(void);
void insert_trustedkey(dst_key_t * key);
void insert_trustedkey(dst_key_t **key);
#if DIG_SIGCHASE_BU
isc_result_t getneededrr(dns_message_t *msg);
void sigchase_bottom_up(dns_message_t *msg);
@@ -566,10 +568,8 @@ make_server(const char *servname, const char *userarg) {
if (srv == NULL)
fatal("memory allocation failure in %s:%d",
__FILE__, __LINE__);
strncpy(srv->servername, servname, MXNAME);
strncpy(srv->userarg, userarg, MXNAME);
srv->servername[MXNAME-1] = 0;
srv->userarg[MXNAME-1] = 0;
strlcpy(srv->servername, servname, MXNAME);
strlcpy(srv->userarg, userarg, MXNAME);
ISC_LINK_INIT(srv, link);
return (srv);
}
@@ -744,7 +744,7 @@ make_empty_lookup(void) {
looknew->xfr_q = NULL;
looknew->current_query = NULL;
looknew->doing_xfr = ISC_FALSE;
looknew->ixfr_serial = ISC_FALSE;
looknew->ixfr_serial = 0;
looknew->trace = ISC_FALSE;
looknew->trace_root = ISC_FALSE;
looknew->identify = ISC_FALSE;
@@ -927,6 +927,11 @@ setup_text_key(void) {
secretsize = isc_buffer_usedlength(&secretbuf);
if (hmacname == NULL) {
result = DST_R_UNSUPPORTEDALG;
goto failure;
}
result = dns_name_fromtext(&keyname, namebuf, dns_rootname, 0, namebuf);
if (result != ISC_R_SUCCESS)
goto failure;
@@ -1142,7 +1147,6 @@ setup_file_key(void) {
keynametext, isc_result_totext(result));
goto failure;
}
dstkey = NULL;
failure:
if (dstkey != NULL)
dst_key_free(&dstkey);
@@ -1161,13 +1165,22 @@ make_searchlist_entry(char *domain) {
return (search);
}
static void
clear_searchlist(void) {
dig_searchlist_t *search;
while ((search = ISC_LIST_HEAD(search_list)) != NULL) {
ISC_LIST_UNLINK(search_list, search, link);
isc_mem_free(mctx, search);
}
}
static void
create_search_list(lwres_conf_t *confdata) {
int i;
dig_searchlist_t *search;
debug("create_search_list()");
ISC_LIST_INIT(search_list);
clear_searchlist();
for (i = 0; i < confdata->searchnxt; i++) {
search = make_searchlist_entry(confdata->search[i]);
@@ -1210,7 +1223,7 @@ setup_system(void) {
else { /* No search list. Use the domain name if any */
if (lwconf->domainname != NULL) {
domain = make_searchlist_entry(lwconf->domainname);
ISC_LIST_INITANDAPPEND(search_list, domain, link);
ISC_LIST_APPEND(search_list, domain, link);
domain = NULL;
}
}
@@ -1265,15 +1278,6 @@ setup_system(void) {
}
static void
clear_searchlist(void) {
dig_searchlist_t *search;
while ((search = ISC_LIST_HEAD(search_list)) != NULL) {
ISC_LIST_UNLINK(search_list, search, link);
isc_mem_free(mctx, search);
}
}
/*%
* Override the search list derived from resolv.conf by 'domain'.
*/
@@ -1386,14 +1390,15 @@ add_opt(dns_message_t *msg, isc_uint16_t udpsize, isc_uint16_t edns,
if (dnssec)
rdatalist->ttl |= DNS_MESSAGEEXTFLAG_DO;
if (nsid) {
unsigned char data[4];
isc_buffer_t buf;
isc_buffer_t *b = NULL;
isc_buffer_init(&buf, data, sizeof(data));
isc_buffer_putuint16(&buf, DNS_OPT_NSID);
isc_buffer_putuint16(&buf, 0);
rdata->data = data;
rdata->length = sizeof(data);
result = isc_buffer_allocate(mctx, &b, 4);
check_result(result, "isc_buffer_allocate");
isc_buffer_putuint16(b, DNS_OPT_NSID);
isc_buffer_putuint16(b, 0);
rdata->data = isc_buffer_base(b);
rdata->length = isc_buffer_usedlength(b);
dns_message_takebuffer(msg, &b);
} else {
rdata->data = NULL;
rdata->length = 0;
@@ -1700,6 +1705,9 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
isc_result_t result;
isc_boolean_t success = ISC_FALSE;
int numLookups = 0;
int num;
isc_result_t lresult, addresses_result;
char bad_namestr[DNS_NAME_FORMATSIZE];
dns_name_t *domain;
isc_boolean_t horizontal = ISC_FALSE, bad = ISC_FALSE;
@@ -1707,6 +1715,8 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
debug("following up %s", query->lookup->textname);
addresses_result = ISC_R_SUCCESS;
bad_namestr[0] = '\0';
for (result = dns_message_firstname(msg, section);
result == ISC_R_SUCCESS;
result = dns_message_nextname(msg, section)) {
@@ -1767,8 +1777,7 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
dns_rdata_freestruct(&ns);
/* Initialize lookup if we've not yet */
debug("found NS %d %s", numLookups, namestr);
numLookups++;
debug("found NS %s", namestr);
if (!success) {
success = ISC_TRUE;
lookup_counter++;
@@ -1790,12 +1799,24 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
domain = dns_fixedname_name(&lookup->fdomain);
dns_name_copy(name, domain, NULL);
}
srv = make_server(namestr, namestr);
debug("adding server %s", srv->servername);
ISC_LIST_APPEND(lookup->my_server_list, srv, link);
debug("adding server %s", namestr);
num = getaddresses(lookup, namestr, &lresult);
if (lresult != ISC_R_SUCCESS) {
debug("couldn't get address for '%s': %s",
namestr, isc_result_totext(lresult));
if (addresses_result == ISC_R_SUCCESS) {
addresses_result = lresult;
strcpy(bad_namestr, namestr);
}
}
numLookups += num;
dns_rdata_reset(&rdata);
}
}
if (numLookups == 0 && addresses_result != ISC_R_SUCCESS) {
fatal("couldn't get address for '%s': %s",
bad_namestr, isc_result_totext(result));
}
if (lookup == NULL &&
section == DNS_SECTION_ANSWER &&
@@ -1808,17 +1829,25 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
if (numLookups > 1) {
isc_uint32_t i, j;
dig_serverlist_t my_server_list;
dig_server_t *next;
ISC_LIST_INIT(my_server_list);
for (i = numLookups; i > 0; i--) {
i = numLookups;
for (srv = ISC_LIST_HEAD(lookup->my_server_list);
srv != NULL;
srv = ISC_LIST_HEAD(lookup->my_server_list)) {
INSIST(i > 0);
isc_random_get(&j);
j %= i;
srv = ISC_LIST_HEAD(lookup->my_server_list);
while (j-- > 0)
srv = ISC_LIST_NEXT(srv, link);
next = ISC_LIST_NEXT(srv, link);
while (j-- > 0 && next != NULL) {
srv = next;
next = ISC_LIST_NEXT(srv, link);
}
ISC_LIST_DEQUEUE(lookup->my_server_list, srv, link);
ISC_LIST_APPEND(my_server_list, srv, link);
i--;
}
ISC_LIST_APPENDLIST(lookup->my_server_list,
my_server_list, link);
@@ -1834,12 +1863,10 @@ followup_lookup(dns_message_t *msg, dig_query_t *query, dns_section_t section)
* Return ISC_TRUE iff there was another searchlist entry.
*/
static isc_boolean_t
next_origin(dns_message_t *msg, dig_query_t *query) {
next_origin(dig_query_t *query) {
dig_lookup_t *lookup;
dig_searchlist_t *search;
UNUSED(msg);
INSIST(!free_now);
debug("next_origin()");
@@ -2401,6 +2428,15 @@ force_timeout(dig_lookup_t *l, dig_query_t *query) {
isc_result_totext(ISC_R_NOMEMORY));
}
isc_task_send(global_task, &event);
/*
* The timer may have expired if, for example, get_address() takes
* long time and the timer was running on a different thread.
* We need to cancel the possible timeout event not to confuse
* ourselves due to the duplicate events.
*/
if (l->timer != NULL)
isc_timer_detach(&l->timer);
}
@@ -2424,7 +2460,7 @@ send_tcp_connect(dig_query_t *query) {
query->waiting_connect = ISC_TRUE;
query->lookup->current_query = query;
result = get_address(query->servname, port, &query->sockaddr);
if (result == ISC_R_NOTFOUND) {
if (result != ISC_R_SUCCESS) {
/*
* This servname doesn't have an address. Try the next server
* by triggering an immediate 'timeout' (we lie, but the effect
@@ -2506,7 +2542,7 @@ send_udp(dig_query_t *query) {
/* XXX Check the sense of this, need assertion? */
query->waiting_connect = ISC_FALSE;
result = get_address(query->servname, port, &query->sockaddr);
if (result == ISC_R_NOTFOUND) {
if (result != ISC_R_SUCCESS) {
/* This servname doesn't have an address. */
force_timeout(l, query);
return;
@@ -2852,8 +2888,10 @@ check_for_more_data(dig_query_t *query, dns_message_t *msg,
dns_rdataset_t *rdataset = NULL;
dns_rdata_t rdata = DNS_RDATA_INIT;
dns_rdata_soa_t soa;
isc_uint32_t serial;
isc_uint32_t ixfr_serial = query->lookup->ixfr_serial, serial;
isc_result_t result;
isc_boolean_t ixfr = query->lookup->rdtype == dns_rdatatype_ixfr;
isc_boolean_t axfr = query->lookup->rdtype == dns_rdatatype_axfr;
debug("check_for_more_data()");
@@ -2903,6 +2941,7 @@ check_for_more_data(dig_query_t *query, dns_message_t *msg,
query->second_rr_rcvd = ISC_TRUE;
query->second_rr_serial = 0;
debug("got the second rr as nonsoa");
axfr = ISC_TRUE;
goto next_rdata;
}
@@ -2912,6 +2951,7 @@ check_for_more_data(dig_query_t *query, dns_message_t *msg,
*/
if (rdata.type != dns_rdatatype_soa)
goto next_rdata;
/* Now we have an SOA. Work with it. */
debug("got an SOA");
result = dns_rdata_tostruct(&rdata, &soa, NULL);
@@ -2921,15 +2961,17 @@ check_for_more_data(dig_query_t *query, dns_message_t *msg,
if (!query->first_soa_rcvd) {
query->first_soa_rcvd = ISC_TRUE;
query->first_rr_serial = serial;
debug("this is the first %d",
query->lookup->ixfr_serial);
if (query->lookup->ixfr_serial >=
serial)
debug("this is the first serial %u",
serial);
if (ixfr && isc_serial_ge(ixfr_serial,
serial)) {
debug("got up to date "
"response");
goto doexit;
}
goto next_rdata;
}
if (query->lookup->rdtype ==
dns_rdatatype_axfr) {
if (axfr) {
debug("doing axfr, got second SOA");
goto doexit;
}
@@ -2939,22 +2981,12 @@ check_for_more_data(dig_query_t *query, dns_message_t *msg,
"empty zone");
goto doexit;
}
debug("this is the second %d",
query->lookup->ixfr_serial);
debug("this is the second serial %u",
serial);
query->second_rr_rcvd = ISC_TRUE;
query->second_rr_serial = serial;
goto next_rdata;
}
if (query->second_rr_serial == 0) {
/*
* If the second RR was a non-SOA
* record, and we're getting any
* other SOA, then this is an
* AXFR, and we're done.
*/
debug("done, since axfr");
goto doexit;
}
/*
* If we get to this point, we're doing an
* IXFR and have to start really looking
@@ -2970,7 +3002,7 @@ check_for_more_data(dig_query_t *query, dns_message_t *msg,
debug("done with ixfr");
goto doexit;
}
debug("meaningless soa %d", serial);
debug("meaningless soa %u", serial);
next_rdata:
result = dns_rdataset_next(rdataset);
} while (result == ISC_R_SUCCESS);
@@ -3347,7 +3379,7 @@ recv_done(isc_task_t *task, isc_event_t *event) {
if (!l->doing_xfr || l->xfr_q == query) {
if (msg->rcode != dns_rcode_noerror &&
(l->origin != NULL || l->need_search)) {
if (!next_origin(msg, query) || showsearch) {
if (!next_origin(query) || showsearch) {
printmessage(query, msg, ISC_TRUE);
received(b->used, &sevent->address, query);
}
@@ -3532,6 +3564,36 @@ get_address(char *host, in_port_t port, isc_sockaddr_t *sockaddr) {
return (ISC_R_SUCCESS);
}
int
getaddresses(dig_lookup_t *lookup, const char *host, isc_result_t *resultp) {
isc_result_t result;
isc_sockaddr_t sockaddrs[DIG_MAX_ADDRESSES];
isc_netaddr_t netaddr;
int count, i;
dig_server_t *srv;
char tmp[ISC_NETADDR_FORMATSIZE];
result = bind9_getaddresses(host, 0, sockaddrs,
DIG_MAX_ADDRESSES, &count);
if (resultp != NULL)
*resultp = result;
if (result != ISC_R_SUCCESS) {
if (resultp == NULL)
fatal("couldn't get address for '%s': %s",
host, isc_result_totext(result));
return 0;
}
for (i = 0; i < count; i++) {
isc_netaddr_fromsockaddr(&netaddr, &sockaddrs[i]);
isc_netaddr_format(&netaddr, tmp, sizeof(tmp));
srv = make_server(tmp, host);
ISC_LIST_APPEND(lookup->my_server_list, srv, link);
}
return count;
}
/*%
* Initiate either a TCP or UDP lookup
*/
@@ -4043,14 +4105,15 @@ sigchase_scanname(dns_rdatatype_t type, dns_rdatatype_t covers,
}
void
insert_trustedkey(dst_key_t * key)
insert_trustedkey(dst_key_t **keyp)
{
if (key == NULL)
if (*keyp == NULL)
return;
if (tk_list.nb_tk >= MAX_TRUSTED_KEY)
return;
tk_list.key[tk_list.nb_tk++] = key;
tk_list.key[tk_list.nb_tk++] = *keyp;
*keyp = NULL;
return;
}
@@ -4169,7 +4232,6 @@ opentmpkey(isc_mem_t *mctx, const char *file, char **tempp, FILE **fp) {
return (result);
}
isc_result_t
get_trusted_key(isc_mem_t *mctx)
{
@@ -4224,12 +4286,14 @@ get_trusted_key(isc_mem_t *mctx)
fclose(fp);
return (ISC_R_FAILURE);
}
insert_trustedkey(key);
#if 0
dst_key_tofile(key, DST_TYPE_PUBLIC,"/tmp");
#endif
key = NULL;
insert_trustedkey(&key);
if (key != NULL)
dst_key_free(&key);
}
fclose(fp);
return (ISC_R_SUCCESS);
}
+1 -1
View File
@@ -13,7 +13,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: host.1,v 1.31 2009/07/11 01:12:45 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
+9 -6
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2007, 2009-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2000-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: host.c,v 1.120 2009/09/29 15:06:05 fdupont Exp $ */
/* $Id: host.c,v 1.120.66.5 2011/03/11 07:11:51 marka Exp $ */
/*! \file */
@@ -521,6 +521,7 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
if ((msg->flags & DNS_MESSAGEFLAG_CD) != 0) {
printf("%scd", did_flag ? " " : "");
did_flag = ISC_TRUE;
POST(did_flag);
}
printf("; QUERY: %u, ANSWER: %u, "
"AUTHORITY: %u, ADDITIONAL: %u\n",
@@ -628,7 +629,9 @@ pre_parse_args(int argc, char **argv) {
case 'v': break;
case 'w': break;
case 'C': break;
case 'D': break;
case 'D':
debugging = ISC_TRUE;
break;
case 'N': break;
case 'R': break;
case 'T': break;
@@ -795,7 +798,7 @@ parse_args(isc_boolean_t is_batchfile, int argc, char **argv) {
ndots = atoi(isc_commandline_argument);
break;
case 'D':
debugging = ISC_TRUE;
/* Handled by pre_parse_args(). */
break;
case '4':
if (have_ipv4) {
@@ -822,8 +825,8 @@ parse_args(isc_boolean_t is_batchfile, int argc, char **argv) {
if (isc_commandline_index >= argc)
show_usage();
strncpy(hostname, argv[isc_commandline_index], sizeof(hostname));
hostname[sizeof(hostname)-1]=0;
strlcpy(hostname, argv[isc_commandline_index], sizeof(hostname));
if (argc > isc_commandline_index + 1) {
set_nameserver(argv[isc_commandline_index+1]);
debug("server is %s", argv[isc_commandline_index+1]);
+5 -5
View File
@@ -14,7 +14,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: host.html,v 1.30 2009/07/11 01:12:45 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -32,7 +32,7 @@
<div class="cmdsynopsis"><p><code class="command">host</code> [<code class="option">-aCdlnrsTwv</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-N <em class="replaceable"><code>ndots</code></em></code>] [<code class="option">-R <em class="replaceable"><code>number</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-W <em class="replaceable"><code>wait</code></em></code>] [<code class="option">-m <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-4</code>] [<code class="option">-6</code>] {name} [server]</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543434"></a><h2>DESCRIPTION</h2>
<a name="id2543436"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">host</strong></span>
is a simple utility for performing DNS lookups.
It is normally used to convert names to IP addresses and vice versa.
@@ -184,7 +184,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543800"></a><h2>IDN SUPPORT</h2>
<a name="id2543802"></a><h2>IDN SUPPORT</h2>
<p>
If <span><strong class="command">host</strong></span> has been built with IDN (internationalized
domain name) support, it can accept and display non-ASCII domain names.
@@ -198,12 +198,12 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543822"></a><h2>FILES</h2>
<a name="id2543825"></a><h2>FILES</h2>
<p><code class="filename">/etc/resolv.conf</code>
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543834"></a><h2>SEE ALSO</h2>
<a name="id2543836"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dig</span>(1)</span>,
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>.
</p>
+5 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2000-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dig.h,v 1.111 2009/09/29 15:06:06 fdupont Exp $ */
/* $Id: dig.h,v 1.111.66.3 2011/12/07 17:24:25 each Exp $ */
#ifndef DIG_H
#define DIG_H
@@ -288,6 +288,9 @@ extern int idnoptions;
isc_result_t
get_address(char *host, in_port_t port, isc_sockaddr_t *sockaddr);
int
getaddresses(dig_lookup_t *lookup, const char *host, isc_result_t *resultp);
isc_result_t
get_reverse(char *reverse, size_t len, char *value, isc_boolean_t ip6_int,
isc_boolean_t strict);
+10 -4
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
.\" Copyright (C) 2004-2007, 2010 Internet Systems Consortium, Inc. ("ISC")
.\"
.\" Permission to use, copy, modify, and/or distribute this software for any
.\" purpose with or without fee is hereby granted, provided that the above
@@ -12,7 +12,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: nslookup.1,v 1.15 2009/07/11 01:12:45 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
@@ -54,7 +54,13 @@ when the first argument is a hyphen (\-) and the second argument is the host nam
Non\-interactive mode is used when the name or Internet address of the host to be looked up is given as the first argument. The optional second argument specifies the host name or address of a name server.
.PP
Options can also be specified on the command line if they precede the arguments and are prefixed with a hyphen. For example, to change the default query type to host information, and the initial timeout to 10 seconds, type:
.sp .RS 4 .nf nslookup \-query=hinfo \-timeout=10 .fi .RE
.sp
.RS 4
.nf
nslookup \-query=hinfo \-timeout=10
.fi
.RE
.sp
.SH "INTERACTIVE COMMANDS"
.PP
\fBhost\fR [server]
@@ -248,5 +254,5 @@ Try the next nameserver if a nameserver responds with SERVFAIL or a referral (no
.PP
Andrew Cherenson
.SH "COPYRIGHT"
Copyright \(co 2004\-2007 Internet Systems Consortium, Inc. ("ISC")
Copyright \(co 2004\-2007, 2010 Internet Systems Consortium, Inc. ("ISC")
.br
+22 -21
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2009, 2011, 2012 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2000-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: nslookup.c,v 1.124 2009/10/20 01:04:03 marka Exp $ */
/* $Id: nslookup.c,v 1.124.40.2 2011/02/21 23:46:37 tbox Exp $ */
#include <config.h>
@@ -57,6 +57,7 @@ static isc_boolean_t in_use = ISC_FALSE;
static char defclass[MXRD] = "IN";
static char deftype[MXRD] = "A";
static isc_event_t *global_event = NULL;
static int query_error = 1, print_error = 0;
static char domainopt[DNS_NAME_MAXTEXT];
@@ -406,6 +407,9 @@ isc_result_t
printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
char servtext[ISC_SOCKADDR_FORMATSIZE];
/* I've we've gotten this far, we've reached a server. */
query_error = 0;
debug("printmessage()");
isc_sockaddr_format(&query->sockaddr, servtext, sizeof(servtext));
@@ -433,6 +437,9 @@ printmessage(dig_query_t *query, dns_message_t *msg, isc_boolean_t headers) {
(msg->rcode != dns_rcode_nxdomain) ? nametext :
query->lookup->textname, rcode_totext(msg->rcode));
debug("returning with rcode == 0");
/* the lookup failed */
print_error |= 1;
return (ISC_R_SUCCESS);
}
@@ -535,12 +542,6 @@ testclass(char *typetext) {
}
}
static void
safecpy(char *dest, char *src, int size) {
strncpy(dest, src, size);
dest[size-1] = 0;
}
static void
set_port(const char *value) {
isc_uint32_t n;
@@ -571,34 +572,34 @@ setoption(char *opt) {
show_settings(ISC_TRUE, ISC_FALSE);
} else if (strncasecmp(opt, "class=", 6) == 0) {
if (testclass(&opt[6]))
safecpy(defclass, &opt[6], sizeof(defclass));
strlcpy(defclass, &opt[6], sizeof(defclass));
} else if (strncasecmp(opt, "cl=", 3) == 0) {
if (testclass(&opt[3]))
safecpy(defclass, &opt[3], sizeof(defclass));
strlcpy(defclass, &opt[3], sizeof(defclass));
} else if (strncasecmp(opt, "type=", 5) == 0) {
if (testtype(&opt[5]))
safecpy(deftype, &opt[5], sizeof(deftype));
strlcpy(deftype, &opt[5], sizeof(deftype));
} else if (strncasecmp(opt, "ty=", 3) == 0) {
if (testtype(&opt[3]))
safecpy(deftype, &opt[3], sizeof(deftype));
strlcpy(deftype, &opt[3], sizeof(deftype));
} else if (strncasecmp(opt, "querytype=", 10) == 0) {
if (testtype(&opt[10]))
safecpy(deftype, &opt[10], sizeof(deftype));
strlcpy(deftype, &opt[10], sizeof(deftype));
} else if (strncasecmp(opt, "query=", 6) == 0) {
if (testtype(&opt[6]))
safecpy(deftype, &opt[6], sizeof(deftype));
strlcpy(deftype, &opt[6], sizeof(deftype));
} else if (strncasecmp(opt, "qu=", 3) == 0) {
if (testtype(&opt[3]))
safecpy(deftype, &opt[3], sizeof(deftype));
strlcpy(deftype, &opt[3], sizeof(deftype));
} else if (strncasecmp(opt, "q=", 2) == 0) {
if (testtype(&opt[2]))
safecpy(deftype, &opt[2], sizeof(deftype));
strlcpy(deftype, &opt[2], sizeof(deftype));
} else if (strncasecmp(opt, "domain=", 7) == 0) {
safecpy(domainopt, &opt[7], sizeof(domainopt));
strlcpy(domainopt, &opt[7], sizeof(domainopt));
set_search_domain(domainopt);
usesearch = ISC_TRUE;
} else if (strncasecmp(opt, "do=", 3) == 0) {
safecpy(domainopt, &opt[3], sizeof(domainopt));
strlcpy(domainopt, &opt[3], sizeof(domainopt));
set_search_domain(domainopt);
usesearch = ISC_TRUE;
} else if (strncasecmp(opt, "port=", 5) == 0) {
@@ -677,11 +678,11 @@ addlookup(char *opt) {
lookup = make_empty_lookup();
if (get_reverse(store, sizeof(store), opt, lookup->ip6_int, ISC_TRUE)
== ISC_R_SUCCESS) {
safecpy(lookup->textname, store, sizeof(lookup->textname));
strlcpy(lookup->textname, store, sizeof(lookup->textname));
lookup->rdtype = dns_rdatatype_ptr;
lookup->rdtypeset = ISC_TRUE;
} else {
safecpy(lookup->textname, opt, sizeof(lookup->textname));
strlcpy(lookup->textname, opt, sizeof(lookup->textname));
lookup->rdtype = rdtype;
lookup->rdtypeset = ISC_TRUE;
}
@@ -893,5 +894,5 @@ main(int argc, char **argv) {
destroy_libs();
isc_app_finish();
return (0);
return (query_error | print_error);
}
+5 -4
View File
@@ -2,7 +2,7 @@
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
[<!ENTITY mdash "&#8212;">]>
<!--
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2004-2007, 2010 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
@@ -17,7 +17,7 @@
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: nslookup.docbook,v 1.16 2007/06/18 23:47:17 tbox Exp $ -->
<!-- $Id: nslookup.docbook,v 1.16.560.2 2010/02/22 23:48:29 tbox Exp $ -->
<!--
- Copyright (c) 1985, 1989
- The Regents of the University of California. All rights reserved.
@@ -73,6 +73,7 @@
<year>2005</year>
<year>2006</year>
<year>2007</year>
<year>2010</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright>
</docinfo>
@@ -129,11 +130,11 @@
arguments and are prefixed with a hyphen. For example, to
change the default query type to host information, and the initial
timeout to 10 seconds, type:
<informalexample>
<!-- <informalexample> produces bad nroff. -->
<programlisting>
nslookup -query=hinfo -timeout=10
</programlisting>
</informalexample>
<!-- </informalexample> -->
</para>
</refsect1>
+13 -11
View File
@@ -1,5 +1,5 @@
<!--
- Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2004-2007, 2010 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
@@ -13,7 +13,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: nslookup.html,v 1.22 2009/07/11 01:12:45 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -31,7 +31,7 @@
<div class="cmdsynopsis"><p><code class="command">nslookup</code> [<code class="option">-option</code>] [name | -] [server]</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543355"></a><h2>DESCRIPTION</h2>
<a name="id2543360"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">Nslookup</strong></span>
is a program to query Internet domain name servers. <span><strong class="command">Nslookup</strong></span>
has two modes: interactive and non-interactive. Interactive mode allows
@@ -43,7 +43,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543371"></a><h2>ARGUMENTS</h2>
<a name="id2543376"></a><h2>ARGUMENTS</h2>
<p>
Interactive mode is entered in the following cases:
</p>
@@ -68,15 +68,17 @@
arguments and are prefixed with a hyphen. For example, to
change the default query type to host information, and the initial
timeout to 10 seconds, type:
</p>
<div class="informalexample"><pre class="programlisting">
</p>
<pre class="programlisting">
nslookup -query=hinfo -timeout=10
</pre></div>
</pre>
<p>
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543413"></a><h2>INTERACTIVE COMMANDS</h2>
<a name="id2543419"></a><h2>INTERACTIVE COMMANDS</h2>
<div class="variablelist"><dl>
<dt><span class="term"><code class="constant">host</code> [<span class="optional">server</span>]</span></dt>
<dd>
@@ -286,19 +288,19 @@ nslookup -query=hinfo -timeout=10
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2546279"></a><h2>FILES</h2>
<a name="id2546354"></a><h2>FILES</h2>
<p><code class="filename">/etc/resolv.conf</code>
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2546291"></a><h2>SEE ALSO</h2>
<a name="id2546365"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dig</span>(1)</span>,
<span class="citerefentry"><span class="refentrytitle">host</span>(1)</span>,
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2546325"></a><h2>Author</h2>
<a name="id2546400"></a><h2>Author</h2>
<p>
Andrew Cherenson
</p>
@@ -1,4 +1,3 @@
Makefile
dnssec-dsfromkey
dnssec-keyfromlabel
dnssec-keygen
@@ -7,5 +6,4 @@ dnssec-revoke
dnssec-settime
dnssec-signkey
dnssec-signzone
*.lo
.libs
+1 -1
View File
@@ -1,4 +1,4 @@
# Copyright (C) 2004, 2005, 2007-2009 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2004, 2005, 2007-2009, 2012 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2000-2002 Internet Software Consortium.
#
# Permission to use, copy, modify, and/or distribute this software for any
+5 -5
View File
@@ -1,18 +1,18 @@
.\" Copyright (C) 2008, 2009 Internet Systems Consortium, Inc. ("ISC")
.\"
.\" Copyright (C) 2008, 2009 Internet Systems Consortium, Inc. ("ISC")
.\"
.\" Permission to use, copy, modify, and/or distribute this software for any
.\" purpose with or without fee is hereby granted, provided that the above
.\" copyright notice and this permission notice appear in all copies.
.\"
.\"
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: dnssec-dsfromkey.8,v 1.11 2009/08/27 01:14:39 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
+5 -8
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2008-2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2008-2011 Internet Systems Consortium, Inc. ("ISC")
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dnssec-dsfromkey.c,v 1.16.50.1 2010/01/13 19:31:51 each Exp $ */
/* $Id: dnssec-dsfromkey.c,v 1.16.50.4 2011/09/03 05:52:55 each Exp $ */
/*! \file */
@@ -265,12 +265,10 @@ emit(unsigned int dtype, isc_boolean_t showall, char *lookaside,
fatal("can't print class");
isc_buffer_usedregion(&nameb, &r);
isc_util_fwrite(r.base, 1, r.length, stdout);
putchar(' ');
printf("%.*s ", (int)r.length, r.base);
isc_buffer_usedregion(&classb, &r);
isc_util_fwrite(r.base, 1, r.length, stdout);
printf("%.*s", (int)r.length, r.base);
if (lookaside == NULL)
printf(" DS ");
@@ -278,8 +276,7 @@ emit(unsigned int dtype, isc_boolean_t showall, char *lookaside,
printf(" DLV ");
isc_buffer_usedregion(&textb, &r);
isc_util_fwrite(r.base, 1, r.length, stdout);
putchar('\n');
printf("%.*s\n", (int)r.length, r.base);
}
ISC_PLATFORM_NORETURN_PRE static void
+12 -13
View File
@@ -1,20 +1,19 @@
<!--
- Copyright (C) 2008, 2009 Internet Systems Consortium, Inc. ("ISC")
-
- Copyright (C) 2008, 2009 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
- copyright notice and this permission notice appear in all copies.
-
-
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dnssec-dsfromkey.html,v 1.11 2009/08/27 01:14:39 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -33,14 +32,14 @@
<div class="cmdsynopsis"><p><code class="command">dnssec-dsfromkey</code> {-s} [<code class="option">-1</code>] [<code class="option">-2</code>] [<code class="option">-a <em class="replaceable"><code>alg</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-s</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-A</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] {dnsname}</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543461"></a><h2>DESCRIPTION</h2>
<a name="id2543462"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">dnssec-dsfromkey</strong></span>
outputs the Delegation Signer (DS) resource record (RR), as defined in
RFC 3658 and RFC 4509, for the given key(s).
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543473"></a><h2>OPTIONS</h2>
<a name="id2543474"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-1</span></dt>
<dd><p>
@@ -101,7 +100,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543659"></a><h2>EXAMPLE</h2>
<a name="id2543660"></a><h2>EXAMPLE</h2>
<p>
To build the SHA-256 DS RR from the
<strong class="userinput"><code>Kexample.com.+003+26160</code></strong>
@@ -116,7 +115,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543689"></a><h2>FILES</h2>
<a name="id2543690"></a><h2>FILES</h2>
<p>
The keyfile can be designed by the key identification
<code class="filename">Knnnn.+aaa+iiiii</code> or the full file name
@@ -130,13 +129,13 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543724"></a><h2>CAVEAT</h2>
<a name="id2543725"></a><h2>CAVEAT</h2>
<p>
A keyfile error can give a "file not found" even if the file exists.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543734"></a><h2>SEE ALSO</h2>
<a name="id2543735"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
@@ -146,7 +145,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543773"></a><h2>AUTHOR</h2>
<a name="id2543774"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
+4 -4
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2008-2010 Internet Systems Consortium, Inc. ("ISC")
.\" Copyright (C) 2008-2011 Internet Systems Consortium, Inc. ("ISC")
.\"
.\" Permission to use, copy, modify, and/or distribute this software for any
.\" purpose with or without fee is hereby granted, provided that the above
@@ -12,7 +12,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: dnssec-keyfromlabel.8,v 1.16.24.1 2010/01/20 02:08:51 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
@@ -162,7 +162,7 @@ Sets the date on which the key is to be activated. After that date, the key will
Sets the date on which the key is to be revoked. After that date, the key will be flagged as revoked. It will be included in the zone and will be used to sign it.
.RE
.PP
\-U \fIdate/offset\fR
\-I \fIdate/offset\fR
.RS 4
Sets the date on which the key is to be retired. After that date, the key will still be included in the zone, but it will not be used to sign it.
.RE
@@ -215,5 +215,5 @@ RFC 4034.
.PP
Internet Systems Consortium
.SH "COPYRIGHT"
Copyright \(co 2008\-2010 Internet Systems Consortium, Inc. ("ISC")
Copyright \(co 2008\-2011 Internet Systems Consortium, Inc. ("ISC")
.br
+17 -5
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2007-2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2007-2011 Internet Systems Consortium, Inc. ("ISC")
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dnssec-keyfromlabel.c,v 1.29.8.2 2010/01/19 23:48:12 tbox Exp $ */
/* $Id: dnssec-keyfromlabel.c,v 1.29.8.6 2011/11/30 00:53:34 marka Exp $ */
/*! \file */
@@ -110,7 +110,8 @@ usage(void) {
int
main(int argc, char **argv) {
char *algname = NULL, *nametype = NULL, *type = NULL;
char *algname = NULL, *freeit = NULL;
char *nametype = NULL, *type = NULL;
const char *directory = NULL;
#ifdef USE_PKCS11
const char *engine = "pkcs11";
@@ -342,6 +343,9 @@ main(int argc, char **argv) {
algname = strdup(DEFAULT_NSEC3_ALGORITHM);
else
algname = strdup(DEFAULT_ALGORITHM);
if (algname == NULL)
fatal("strdup failed");
freeit = algname;
if (verbose > 0)
fprintf(stderr, "no algorithm specified; "
"defaulting to %s\n", algname);
@@ -513,10 +517,12 @@ main(int argc, char **argv) {
* is a risk of ID collision due to this key or another key
* being revoked.
*/
if (key_collision(dst_key_id(key), name, directory, alg, mctx, &exact))
{
if (key_collision(key, name, directory, mctx, &exact)) {
isc_buffer_clear(&buf);
ret = dst_key_buildfilename(key, 0, directory, &buf);
if (ret != ISC_R_SUCCESS)
fatal("dst_key_buildfilename returned: %s\n",
isc_result_totext(ret));
if (exact)
fatal("%s: %s already exists\n", program, filename);
@@ -541,6 +547,9 @@ main(int argc, char **argv) {
isc_buffer_clear(&buf);
ret = dst_key_buildfilename(key, 0, NULL, &buf);
if (ret != ISC_R_SUCCESS)
fatal("dst_key_buildfilename returned: %s\n",
isc_result_totext(ret));
printf("%s\n", filename);
dst_key_free(&key);
@@ -553,5 +562,8 @@ main(int argc, char **argv) {
isc_mem_free(mctx, label);
isc_mem_destroy(&mctx);
if (freeit != NULL)
free(freeit);
return (0);
}
+4 -3
View File
@@ -2,7 +2,7 @@
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
[<!ENTITY mdash "&#8212;">]>
<!--
- Copyright (C) 2008-2010 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2008-2011 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
@@ -17,7 +17,7 @@
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dnssec-keyfromlabel.docbook,v 1.15.24.2 2010/01/19 23:48:12 tbox Exp $ -->
<!-- $Id: dnssec-keyfromlabel.docbook,v 1.15.24.4 2011/02/03 12:17:22 tbox Exp $ -->
<refentry id="man.dnssec-keyfromlabel">
<refentryinfo>
<date>February 8, 2008</date>
@@ -39,6 +39,7 @@
<year>2008</year>
<year>2009</year>
<year>2010</year>
<year>2011</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright>
</docinfo>
@@ -333,7 +334,7 @@
</varlistentry>
<varlistentry>
<term>-U <replaceable class="parameter">date/offset</replaceable></term>
<term>-I <replaceable class="parameter">date/offset</replaceable></term>
<listitem>
<para>
Sets the date on which the key is to be retired. After that
+9 -9
View File
@@ -1,5 +1,5 @@
<!--
- Copyright (C) 2008-2010 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2008-2011 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
@@ -13,7 +13,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dnssec-keyfromlabel.html,v 1.15.24.1 2010/01/20 02:08:51 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -31,7 +31,7 @@
<div class="cmdsynopsis"><p><code class="command">dnssec-keyfromlabel</code> {-l <em class="replaceable"><code>label</code></em>} [<code class="option">-3</code>] [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-k</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-y</code>] {name}</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543491"></a><h2>DESCRIPTION</h2>
<a name="id2543495"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">dnssec-keyfromlabel</strong></span>
gets keys with the given label from a crypto hardware and builds
key files for DNSSEC (Secure DNS), as defined in RFC 2535
@@ -44,7 +44,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543509"></a><h2>OPTIONS</h2>
<a name="id2543513"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
<dd>
@@ -163,7 +163,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543873"></a><h2>TIMING OPTIONS</h2>
<a name="id2543877"></a><h2>TIMING OPTIONS</h2>
<p>
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
If the argument begins with a '+' or '-', it is interpreted as
@@ -195,7 +195,7 @@
date, the key will be flagged as revoked. It will be included
in the zone and will be used to sign it.
</p></dd>
<dt><span class="term">-U <em class="replaceable"><code>date/offset</code></em></span></dt>
<dt><span class="term">-I <em class="replaceable"><code>date/offset</code></em></span></dt>
<dd><p>
Sets the date on which the key is to be retired. After that
date, the key will still be included in the zone, but it
@@ -210,7 +210,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2544039"></a><h2>GENERATED KEY FILES</h2>
<a name="id2544043"></a><h2>GENERATED KEY FILES</h2>
<p>
When <span><strong class="command">dnssec-keyfromlabel</strong></span> completes
successfully,
@@ -249,7 +249,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544112"></a><h2>SEE ALSO</h2>
<a name="id2544116"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
@@ -257,7 +257,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544145"></a><h2>AUTHOR</h2>
<a name="id2544149"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
+18 -4
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2004, 2005, 2007-2009 Internet Systems Consortium, Inc. ("ISC")
.\" Copyright (C) 2004, 2005, 2007-2010 Internet Systems Consortium, Inc. ("ISC")
.\" Copyright (C) 2000-2003 Internet Software Consortium.
.\"
.\" Permission to use, copy, modify, and/or distribute this software for any
@@ -13,7 +13,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: dnssec-keygen.8,v 1.53 2009/11/03 21:58:30 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
@@ -33,7 +33,7 @@
dnssec\-keygen \- DNSSEC key generation tool
.SH "SYNOPSIS"
.HP 14
\fBdnssec\-keygen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-e\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-z\fR] {name}
\fBdnssec\-keygen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-e\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-z\fR] {name}
.SH "DESCRIPTION"
.PP
\fBdnssec\-keygen\fR
@@ -164,6 +164,11 @@ specifies the name of a character device or file containing random data to be us
indicates that keyboard input should be used.
.RE
.PP
\-S \fIkey\fR
.RS 4
Create a new key which is an explicit successor to an existing key. The name, algorithm, size, and type of the key will be set to match the existing key. The activation date of the new key will be set to the inactivation date of the existing one. The publication date will be set to the activation date minus the prepublication interval, which defaults to 30 days.
.RE
.PP
\-s \fIstrength\fR
.RS 4
Specifies the strength value of the key. The strength is a number between 0 and 15, and currently has no defined purpose in DNSSEC.
@@ -216,6 +221,15 @@ Sets the date on which the key is to be retired. After that date, the key will s
.RS 4
Sets the date on which the key is to be deleted. After that date, the key will no longer be included in the zone. (It may remain in the key repository, however.)
.RE
.PP
\-i \fIinterval\fR
.RS 4
Sets the prepublication interval for a key. If set, then the publication and activation dates must be separated by at least this much time. If the activation date is specified but the publication date isn't, then the publication date will default to this much time before the activation date; conversely, if the publication date is specified but activation date isn't, then activation will be set to this much time after publication.
.sp
If the key is being created as an explicit successor to another key, then the default prepublication interval is 30 days; otherwise it is zero.
.sp
As with date offsets, if the argument is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the interval is measured in years, months, weeks, days, hours, or minutes, respectively. Without a suffix, the interval is measured in seconds.
.RE
.SH "GENERATED KEYS"
.PP
When
@@ -284,7 +298,7 @@ RFC 4034.
.PP
Internet Systems Consortium
.SH "COPYRIGHT"
Copyright \(co 2004, 2005, 2007\-2009 Internet Systems Consortium, Inc. ("ISC")
Copyright \(co 2004, 2005, 2007\-2010 Internet Systems Consortium, Inc. ("ISC")
.br
Copyright \(co 2000\-2003 Internet Software Consortium.
.br
+267 -116
View File
@@ -1,5 +1,5 @@
/*
* Portions Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
* Portions Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Portions Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -29,7 +29,7 @@
* IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dnssec-keygen.c,v 1.108.8.4 2010/01/19 23:48:12 tbox Exp $ */
/* $Id: dnssec-keygen.c,v 1.108.8.10 2011/11/30 00:53:34 marka Exp $ */
/*! \file */
@@ -92,27 +92,27 @@ usage(void) {
"NSEC3RSASHA1 if using -3)\n");
fprintf(stderr, " -3: use NSEC3-capable algorithm\n");
fprintf(stderr, " -b <key size in bits>:\n");
fprintf(stderr, " RSAMD5:\t[512..%d]\n", MAX_RSA);
fprintf(stderr, " RSASHA1:\t[512..%d]\n", MAX_RSA);
fprintf(stderr, " NSEC3RSASHA1:\t[512..%d]\n", MAX_RSA);
fprintf(stderr, " RSASHA256:\t[512..%d]\n", MAX_RSA);
fprintf(stderr, " RSASHA512:\t[1024..%d]\n", MAX_RSA);
fprintf(stderr, " DH:\t\t[128..4096]\n");
fprintf(stderr, " DSA:\t\t[512..1024] and divisible by 64\n");
fprintf(stderr, " NSEC3DSA:\t[512..1024] and divisible "
fprintf(stderr, " RSAMD5:\t[512..%d]\n", MAX_RSA);
fprintf(stderr, " RSASHA1:\t[512..%d]\n", MAX_RSA);
fprintf(stderr, " NSEC3RSASHA1:\t[512..%d]\n", MAX_RSA);
fprintf(stderr, " RSASHA256:\t[512..%d]\n", MAX_RSA);
fprintf(stderr, " RSASHA512:\t[1024..%d]\n", MAX_RSA);
fprintf(stderr, " DH:\t\t[128..4096]\n");
fprintf(stderr, " DSA:\t\t[512..1024] and divisible by 64\n");
fprintf(stderr, " NSEC3DSA:\t[512..1024] and divisible "
"by 64\n");
fprintf(stderr, " HMAC-MD5:\t[1..512]\n");
fprintf(stderr, " HMAC-SHA1:\t[1..160]\n");
fprintf(stderr, " HMAC-SHA224:\t[1..224]\n");
fprintf(stderr, " HMAC-SHA256:\t[1..256]\n");
fprintf(stderr, " HMAC-SHA384:\t[1..384]\n");
fprintf(stderr, " HMAC-SHA512:\t[1..512]\n");
fprintf(stderr, " HMAC-MD5:\t[1..512]\n");
fprintf(stderr, " HMAC-SHA1:\t[1..160]\n");
fprintf(stderr, " HMAC-SHA224:\t[1..224]\n");
fprintf(stderr, " HMAC-SHA256:\t[1..256]\n");
fprintf(stderr, " HMAC-SHA384:\t[1..384]\n");
fprintf(stderr, " HMAC-SHA512:\t[1..512]\n");
fprintf(stderr, " (if using the default algorithm, key size\n"
" defaults to 2048 for KSK, or 1024 for all "
"others)\n");
fprintf(stderr, " -n <nametype>: ZONE | HOST | ENTITY | "
"USER | OTHER\n");
fprintf(stderr, " (DNSKEY generation defaults to ZONE)\n");
fprintf(stderr, " (DNSKEY generation defaults to ZONE)\n");
fprintf(stderr, " -c <class>: (default: IN)\n");
fprintf(stderr, " -d <digest bits> (0 => max, default)\n");
#ifdef USE_PKCS11
@@ -136,7 +136,7 @@ usage(void) {
fprintf(stderr, " -h: print usage and exit\n");
fprintf(stderr, " -m <memory debugging mode>:\n");
fprintf(stderr, " usage | trace | record | size | mctx\n");
fprintf(stderr, " usage | trace | record | size | mctx\n");
fprintf(stderr, " -v <level>: set verbosity level (0 - 10)\n");
fprintf(stderr, "Timing options:\n");
fprintf(stderr, " -P date/[+-]offset/none: set key publication date "
@@ -151,6 +151,11 @@ usage(void) {
fprintf(stderr, " -G: generate key only; do not set -P or -A\n");
fprintf(stderr, " -C: generate a backward-compatible key, omitting "
"all dates\n");
fprintf(stderr, " -S <key>: generate a successor to an existing "
"key\n");
fprintf(stderr, " -i <interval>: prepublication interval for "
"successor key "
"(default: 30 days)\n");
fprintf(stderr, "Output:\n");
fprintf(stderr, " K<name>+<alg>+<id>.key, "
"K<name>+<alg>+<id>.private\n");
@@ -190,7 +195,8 @@ progress(int p)
int
main(int argc, char **argv) {
char *algname = NULL, *nametype = NULL, *type = NULL;
char *algname = NULL, *freeit = NULL;
char *nametype = NULL, *type = NULL;
char *classname = NULL;
char *endp;
dst_key_t *key = NULL;
@@ -207,6 +213,8 @@ main(int argc, char **argv) {
isc_textregion_t r;
char filename[255];
const char *directory = NULL;
const char *predecessor = NULL;
dst_key_t *prevkey = NULL;
isc_buffer_t buf;
isc_log_t *log = NULL;
isc_entropy_t *ectx = NULL;
@@ -222,6 +230,7 @@ main(int argc, char **argv) {
isc_stdtime_t publish = 0, activate = 0, revoke = 0;
isc_stdtime_t inactive = 0, delete = 0;
isc_stdtime_t now;
int prepub = -1;
isc_boolean_t setpub = ISC_FALSE, setact = ISC_FALSE;
isc_boolean_t setrev = ISC_FALSE, setinact = ISC_FALSE;
isc_boolean_t setdel = ISC_FALSE;
@@ -243,7 +252,7 @@ main(int argc, char **argv) {
/*
* Process memory debugging argument first.
*/
#define CMDLINE_FLAGS "3a:b:Cc:d:E:eFf:g:K:km:n:p:qr:s:T:t:v:hGP:A:R:I:D:"
#define CMDLINE_FLAGS "3A:a:b:Cc:D:d:E:eFf:Gg:hI:i:K:km:n:P:p:qR:r:S:s:T:t:v:"
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
switch (ch) {
case 'm':
@@ -436,6 +445,12 @@ main(int argc, char **argv) {
unsetdel = ISC_TRUE;
}
break;
case 'S':
predecessor = isc_commandline_argument;
break;
case 'i':
prepub = strtottl(isc_commandline_argument);
break;
case 'F':
/* Reserved for FIPS mode */
/* FALLTHROUGH */
@@ -467,87 +482,208 @@ main(int argc, char **argv) {
setup_logging(verbose, mctx, &log);
if (argc < isc_commandline_index + 1)
fatal("the key name was not specified");
if (argc > isc_commandline_index + 1)
fatal("extraneous arguments");
if (predecessor == NULL) {
if (prepub == -1)
prepub = 0;
if (algname == NULL) {
use_default = ISC_TRUE;
if (use_nsec3)
algname = strdup(DEFAULT_NSEC3_ALGORITHM);
else
algname = strdup(DEFAULT_ALGORITHM);
if (verbose > 0)
fprintf(stderr, "no algorithm specified; "
"defaulting to %s\n", algname);
}
if (argc < isc_commandline_index + 1)
fatal("the key name was not specified");
if (argc > isc_commandline_index + 1)
fatal("extraneous arguments");
if (strcasecmp(algname, "RSA") == 0) {
fprintf(stderr, "The use of RSA (RSAMD5) is not recommended.\n"
"If you still wish to use RSA (RSAMD5) please "
"specify \"-a RSAMD5\"\n");
return (1);
} else if (strcasecmp(algname, "HMAC-MD5") == 0) {
options |= DST_TYPE_KEY;
alg = DST_ALG_HMACMD5;
} else if (strcasecmp(algname, "HMAC-SHA1") == 0) {
options |= DST_TYPE_KEY;
alg = DST_ALG_HMACSHA1;
} else if (strcasecmp(algname, "HMAC-SHA224") == 0) {
options |= DST_TYPE_KEY;
alg = DST_ALG_HMACSHA224;
} else if (strcasecmp(algname, "HMAC-SHA256") == 0) {
options |= DST_TYPE_KEY;
alg = DST_ALG_HMACSHA256;
} else if (strcasecmp(algname, "HMAC-SHA384") == 0) {
options |= DST_TYPE_KEY;
alg = DST_ALG_HMACSHA384;
} else if (strcasecmp(algname, "HMAC-SHA512") == 0) {
options |= DST_TYPE_KEY;
alg = DST_ALG_HMACSHA512;
} else {
r.base = algname;
r.length = strlen(algname);
ret = dns_secalg_fromtext(&alg, &r);
dns_fixedname_init(&fname);
name = dns_fixedname_name(&fname);
isc_buffer_init(&buf, argv[isc_commandline_index],
strlen(argv[isc_commandline_index]));
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
ret = dns_name_fromtext(name, &buf, dns_rootname, 0, NULL);
if (ret != ISC_R_SUCCESS)
fatal("unknown algorithm %s", algname);
if (alg == DST_ALG_DH)
options |= DST_TYPE_KEY;
}
fatal("invalid key name %s: %s",
argv[isc_commandline_index],
isc_result_totext(ret));
if (use_nsec3 &&
alg != DST_ALG_NSEC3DSA && alg != DST_ALG_NSEC3RSASHA1 &&
alg != DST_ALG_RSASHA256 && alg!= DST_ALG_RSASHA512) {
fatal("%s is incompatible with NSEC3; "
"do not use the -3 option", algname);
}
if (type != NULL && (options & DST_TYPE_KEY) != 0) {
if (strcasecmp(type, "NOAUTH") == 0)
flags |= DNS_KEYTYPE_NOAUTH;
else if (strcasecmp(type, "NOCONF") == 0)
flags |= DNS_KEYTYPE_NOCONF;
else if (strcasecmp(type, "NOAUTHCONF") == 0) {
flags |= (DNS_KEYTYPE_NOAUTH | DNS_KEYTYPE_NOCONF);
if (size < 0)
size = 0;
}
else if (strcasecmp(type, "AUTHCONF") == 0)
/* nothing */;
else
fatal("invalid type %s", type);
}
if (size < 0) {
if (use_default) {
size = ((kskflag & DNS_KEYFLAG_KSK) != 0) ? 2048 : 1024;
if (algname == NULL) {
use_default = ISC_TRUE;
if (use_nsec3)
algname = strdup(DEFAULT_NSEC3_ALGORITHM);
else
algname = strdup(DEFAULT_ALGORITHM);
if (algname == NULL)
fatal("strdup failed");
freeit = algname;
if (verbose > 0)
fprintf(stderr, "key size not specified; "
"defaulting to %d\n", size);
} else {
fatal("key size not specified (-b option)");
fprintf(stderr, "no algorithm specified; "
"defaulting to %s\n", algname);
}
if (strcasecmp(algname, "RSA") == 0) {
fprintf(stderr, "The use of RSA (RSAMD5) is not "
"recommended.\nIf you still wish to "
"use RSA (RSAMD5) please specify "
"\"-a RSAMD5\"\n");
return (1);
} else if (strcasecmp(algname, "HMAC-MD5") == 0)
alg = DST_ALG_HMACMD5;
else if (strcasecmp(algname, "HMAC-SHA1") == 0)
alg = DST_ALG_HMACSHA1;
else if (strcasecmp(algname, "HMAC-SHA224") == 0)
alg = DST_ALG_HMACSHA224;
else if (strcasecmp(algname, "HMAC-SHA256") == 0)
alg = DST_ALG_HMACSHA256;
else if (strcasecmp(algname, "HMAC-SHA384") == 0)
alg = DST_ALG_HMACSHA384;
else if (strcasecmp(algname, "HMAC-SHA512") == 0)
alg = DST_ALG_HMACSHA512;
else {
r.base = algname;
r.length = strlen(algname);
ret = dns_secalg_fromtext(&alg, &r);
if (ret != ISC_R_SUCCESS)
fatal("unknown algorithm %s", algname);
if (alg == DST_ALG_DH)
options |= DST_TYPE_KEY;
}
if (use_nsec3 &&
alg != DST_ALG_NSEC3DSA && alg != DST_ALG_NSEC3RSASHA1 &&
alg != DST_ALG_RSASHA256 && alg!= DST_ALG_RSASHA512) {
fatal("%s is incompatible with NSEC3; "
"do not use the -3 option", algname);
}
if (type != NULL && (options & DST_TYPE_KEY) != 0) {
if (strcasecmp(type, "NOAUTH") == 0)
flags |= DNS_KEYTYPE_NOAUTH;
else if (strcasecmp(type, "NOCONF") == 0)
flags |= DNS_KEYTYPE_NOCONF;
else if (strcasecmp(type, "NOAUTHCONF") == 0) {
flags |= (DNS_KEYTYPE_NOAUTH |
DNS_KEYTYPE_NOCONF);
if (size < 0)
size = 0;
}
else if (strcasecmp(type, "AUTHCONF") == 0)
/* nothing */;
else
fatal("invalid type %s", type);
}
if (size < 0) {
if (use_default) {
if ((kskflag & DNS_KEYFLAG_KSK) != 0)
size = 2048;
else
size = 1024;
if (verbose > 0)
fprintf(stderr, "key size not "
"specified; defaulting "
"to %d\n", size);
} else {
fatal("key size not specified (-b option)");
}
}
if (!oldstyle && prepub > 0) {
if (setpub && setact && (activate - prepub) < publish)
fatal("Activation and publication dates "
"are closer together than the\n\t"
"prepublication interval.");
if (!setpub && !setact) {
setpub = setact = ISC_TRUE;
publish = now;
activate = now + prepub;
} else if (setpub && !setact) {
setact = ISC_TRUE;
activate = publish + prepub;
} else if (setact && !setpub) {
setpub = ISC_TRUE;
publish = activate - prepub;
}
if ((activate - prepub) < now)
fatal("Time until activation is shorter "
"than the\n\tprepublication interval.");
}
} else {
char keystr[DST_KEY_FORMATSIZE];
isc_stdtime_t when;
int major, minor;
if (prepub == -1)
prepub = (30 * 86400);
if (algname != NULL)
fatal("-S and -a cannot be used together");
if (size >= 0)
fatal("-S and -b cannot be used together");
if (nametype != NULL)
fatal("-S and -n cannot be used together");
if (type != NULL)
fatal("-S and -t cannot be used together");
if (setpub || unsetpub)
fatal("-S and -P cannot be used together");
if (setact || unsetact)
fatal("-S and -A cannot be used together");
if (use_nsec3)
fatal("-S and -3 cannot be used together");
if (oldstyle)
fatal("-S and -C cannot be used together");
if (genonly)
fatal("-S and -G cannot be used together");
ret = dst_key_fromnamedfile(predecessor, directory,
DST_TYPE_PUBLIC | DST_TYPE_PRIVATE,
mctx, &prevkey);
if (ret != ISC_R_SUCCESS)
fatal("Invalid keyfile %s: %s",
filename, isc_result_totext(ret));
if (!dst_key_isprivate(prevkey))
fatal("%s is not a private key", filename);
name = dst_key_name(prevkey);
alg = dst_key_alg(prevkey);
size = dst_key_size(prevkey);
flags = dst_key_flags(prevkey);
dst_key_format(prevkey, keystr, sizeof(keystr));
dst_key_getprivateformat(prevkey, &major, &minor);
if (major != DST_MAJOR_VERSION || minor < DST_MINOR_VERSION)
fatal("Key %s has incompatible format version %d.%d\n\t"
"It is not possible to generate a successor key.",
keystr, major, minor);
ret = dst_key_gettime(prevkey, DST_TIME_ACTIVATE, &when);
if (ret != ISC_R_SUCCESS)
fatal("Key %s has no activation date.\n\t"
"You must use dnssec-settime -A to set one "
"before generating a successor.", keystr);
ret = dst_key_gettime(prevkey, DST_TIME_INACTIVE, &activate);
if (ret != ISC_R_SUCCESS)
fatal("Key %s has no inactivation date.\n\t"
"You must use dnssec-settime -I to set one "
"before generating a successor.", keystr);
publish = activate - prepub;
if (publish < now)
fatal("Key %s becomes inactive\n\t"
"sooner than the prepublication period "
"for the new key ends.\n\t"
"Either change the inactivation date with "
"dnssec-settime -I,\n\t"
"or use the -i option to set a shorter "
"prepublication interval.", keystr);
ret = dst_key_gettime(prevkey, DST_TIME_DELETE, &when);
if (ret != ISC_R_SUCCESS)
fprintf(stderr, "%s: WARNING: Key %s has no removal "
"date;\n\t it will remain in the zone "
"indefinitely after rollover.\n\t "
"You can use dnssec-settime -D to "
"change this.\n", program, keystr);
setpub = setact = ISC_TRUE;
}
switch (alg) {
@@ -572,6 +708,7 @@ main(int argc, char **argv) {
fatal("invalid DSS key size: %d", size);
break;
case DST_ALG_HMACMD5:
options |= DST_TYPE_KEY;
if (size < 1 || size > 512)
fatal("HMAC-MD5 key size %d out of range", size);
if (dbits != 0 && (dbits < 80 || dbits > 128))
@@ -581,6 +718,7 @@ main(int argc, char **argv) {
dbits);
break;
case DST_ALG_HMACSHA1:
options |= DST_TYPE_KEY;
if (size < 1 || size > 160)
fatal("HMAC-SHA1 key size %d out of range", size);
if (dbits != 0 && (dbits < 80 || dbits > 160))
@@ -590,6 +728,7 @@ main(int argc, char **argv) {
dbits);
break;
case DST_ALG_HMACSHA224:
options |= DST_TYPE_KEY;
if (size < 1 || size > 224)
fatal("HMAC-SHA224 key size %d out of range", size);
if (dbits != 0 && (dbits < 112 || dbits > 224))
@@ -599,6 +738,7 @@ main(int argc, char **argv) {
dbits);
break;
case DST_ALG_HMACSHA256:
options |= DST_TYPE_KEY;
if (size < 1 || size > 256)
fatal("HMAC-SHA256 key size %d out of range", size);
if (dbits != 0 && (dbits < 128 || dbits > 256))
@@ -608,6 +748,7 @@ main(int argc, char **argv) {
dbits);
break;
case DST_ALG_HMACSHA384:
options |= DST_TYPE_KEY;
if (size < 1 || size > 384)
fatal("HMAC-384 key size %d out of range", size);
if (dbits != 0 && (dbits < 192 || dbits > 384))
@@ -617,6 +758,7 @@ main(int argc, char **argv) {
dbits);
break;
case DST_ALG_HMACSHA512:
options |= DST_TYPE_KEY;
if (size < 1 || size > 512)
fatal("HMAC-SHA512 key size %d out of range", size);
if (dbits != 0 && (dbits < 256 || dbits > 512))
@@ -685,16 +827,6 @@ main(int argc, char **argv) {
fatal("a key with algorithm '%s' cannot be a zone key",
algname);
dns_fixedname_init(&fname);
name = dns_fixedname_name(&fname);
isc_buffer_init(&buf, argv[isc_commandline_index],
strlen(argv[isc_commandline_index]));
isc_buffer_add(&buf, strlen(argv[isc_commandline_index]));
ret = dns_name_fromtext(name, &buf, dns_rootname, 0, NULL);
if (ret != ISC_R_SUCCESS)
fatal("invalid key name %s: %s", argv[isc_commandline_index],
isc_result_totext(ret));
switch(alg) {
case DNS_KEYALG_RSAMD5:
case DNS_KEYALG_RSASHA1:
@@ -763,9 +895,18 @@ main(int argc, char **argv) {
/*
* Set key timing metadata (unless using -C)
*
* Publish and activation dates are set to "now" by default,
* but can be overridden. Creation date is always set to
* "now".
* Creation date is always set to "now".
*
* For a new key without an explicit predecessor, publish
* and activation dates are set to "now" by default, but
* can both be overridden.
*
* For a successor key, activation is set to match the
* predecessor's inactivation date. Publish is set to 30
* days earlier than that (XXX: this should be configurable).
* If either of the resulting dates are in the past, that's
* an error; the inactivation date of the predecessor key
* must be updated before a successor key can be created.
*/
if (!oldstyle) {
dst_key_settime(key, DST_TIME_CREATED, now);
@@ -822,8 +963,7 @@ main(int argc, char **argv) {
* if there is a risk of ID collision due to this key
* or another key being revoked.
*/
if (key_collision(dst_key_id(key), name, directory,
alg, mctx, NULL)) {
if (key_collision(key, name, directory, mctx, NULL)) {
conflict = ISC_TRUE;
if (null_key) {
dst_key_free(&key);
@@ -832,12 +972,15 @@ main(int argc, char **argv) {
if (verbose > 0) {
isc_buffer_clear(&buf);
dst_key_buildfilename(key, 0, directory, &buf);
fprintf(stderr,
"%s: %s already exists, or might "
"collide with another key upon "
"revokation. Generating a new key\n",
program, filename);
ret = dst_key_buildfilename(key, 0,
directory, &buf);
if (ret == ISC_R_SUCCESS)
fprintf(stderr,
"%s: %s already exists, or "
"might collide with another "
"key upon revokation. "
"Generating a new key\n",
program, filename);
}
dst_key_free(&key);
@@ -858,8 +1001,13 @@ main(int argc, char **argv) {
isc_buffer_clear(&buf);
ret = dst_key_buildfilename(key, 0, NULL, &buf);
if (ret != ISC_R_SUCCESS)
fatal("dst_key_buildfilename returned: %s\n",
isc_result_totext(ret));
printf("%s\n", filename);
dst_key_free(&key);
if (prevkey != NULL)
dst_key_free(&prevkey);
cleanup_logging(&log);
cleanup_entropy(&ectx);
@@ -869,5 +1017,8 @@ main(int argc, char **argv) {
isc_mem_stats(mctx, stdout);
isc_mem_destroy(&mctx);
if (freeit != NULL)
free(freeit);
return (0);
}
+48 -2
View File
@@ -2,7 +2,7 @@
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
[<!ENTITY mdash "&#8212;">]>
<!--
- Copyright (C) 2004, 2005, 2007-2009 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2004, 2005, 2007-2010 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2000-2003 Internet Software Consortium.
-
- Permission to use, copy, modify, and/or distribute this software for any
@@ -18,7 +18,7 @@
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dnssec-keygen.docbook,v 1.33 2009/11/03 21:44:46 each Exp $ -->
<!-- $Id: dnssec-keygen.docbook,v 1.33.24.2 2010/08/16 23:46:30 tbox Exp $ -->
<refentry id="man.dnssec-keygen">
<refentryinfo>
<date>June 30, 2000</date>
@@ -42,6 +42,7 @@
<year>2007</year>
<year>2008</year>
<year>2009</year>
<year>2010</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright>
<copyright>
@@ -71,6 +72,7 @@
<arg><option>-g <replaceable class="parameter">generator</replaceable></option></arg>
<arg><option>-h</option></arg>
<arg><option>-I <replaceable class="parameter">date/offset</replaceable></option></arg>
<arg><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
<arg><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
<arg><option>-k</option></arg>
<arg><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
@@ -78,6 +80,7 @@
<arg><option>-q</option></arg>
<arg><option>-R <replaceable class="parameter">date/offset</replaceable></option></arg>
<arg><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
<arg><option>-S <replaceable class="parameter">key</replaceable></option></arg>
<arg><option>-s <replaceable class="parameter">strength</replaceable></option></arg>
<arg><option>-t <replaceable class="parameter">type</replaceable></option></arg>
<arg><option>-v <replaceable class="parameter">level</replaceable></option></arg>
@@ -341,6 +344,21 @@
</listitem>
</varlistentry>
<varlistentry>
<term>-S <replaceable class="parameter">key</replaceable></term>
<listitem>
<para>
Create a new key which is an explicit successor to an
existing key. The name, algorithm, size, and type of the
key will be set to match the existing key. The activation
date of the new key will be set to the inactivation date of
the existing one. The publication date will be set to the
activation date minus the prepublication interval, which
defaults to 30 days.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-s <replaceable class="parameter">strength</replaceable></term>
<listitem>
@@ -463,6 +481,34 @@
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-i <replaceable class="parameter">interval</replaceable></term>
<listitem>
<para>
Sets the prepublication interval for a key. If set, then
the publication and activation dates must be separated by at least
this much time. If the activation date is specified but the
publication date isn't, then the publication date will default
to this much time before the activation date; conversely, if
the publication date is specified but activation date isn't,
then activation will be set to this much time after publication.
</para>
<para>
If the key is being created as an explicit successor to another
key, then the default prepublication interval is 30 days;
otherwise it is zero.
</para>
<para>
As with date offsets, if the argument is followed by one of
the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
interval is measured in years, months, weeks, days, hours,
or minutes, respectively. Without a suffix, the interval is
measured in seconds.
</para>
</listitem>
</varlistentry>
</variablelist>
</refsect1>
+44 -10
View File
@@ -1,5 +1,5 @@
<!--
- Copyright (C) 2004, 2005, 2007-2009 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2004, 2005, 2007-2010 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2000-2003 Internet Software Consortium.
-
- Permission to use, copy, modify, and/or distribute this software for any
@@ -14,7 +14,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dnssec-keygen.html,v 1.45 2009/11/03 21:58:30 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -29,10 +29,10 @@
</div>
<div class="refsynopsisdiv">
<h2>Synopsis</h2>
<div class="cmdsynopsis"><p><code class="command">dnssec-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-3</code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-C</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e</code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-g <em class="replaceable"><code>generator</code></em></code>] [<code class="option">-h</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k</code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-q</code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-s <em class="replaceable"><code>strength</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-z</code>] {name}</p></div>
<div class="cmdsynopsis"><p><code class="command">dnssec-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-3</code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-C</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e</code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-g <em class="replaceable"><code>generator</code></em></code>] [<code class="option">-h</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k</code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-q</code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S <em class="replaceable"><code>key</code></em></code>] [<code class="option">-s <em class="replaceable"><code>strength</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-z</code>] {name}</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543558"></a><h2>DESCRIPTION</h2>
<a name="id2543579"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">dnssec-keygen</strong></span>
generates keys for DNSSEC (Secure DNS), as defined in RFC 2535
and RFC 4034. It can also generate keys for use with
@@ -46,7 +46,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543576"></a><h2>OPTIONS</h2>
<a name="id2543597"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
<dd>
@@ -203,6 +203,16 @@
<code class="filename">keyboard</code> indicates that keyboard
input should be used.
</p></dd>
<dt><span class="term">-S <em class="replaceable"><code>key</code></em></span></dt>
<dd><p>
Create a new key which is an explicit successor to an
existing key. The name, algorithm, size, and type of the
key will be set to match the existing key. The activation
date of the new key will be set to the inactivation date of
the existing one. The publication date will be set to the
activation date minus the prepublication interval, which
defaults to 30 days.
</p></dd>
<dt><span class="term">-s <em class="replaceable"><code>strength</code></em></span></dt>
<dd><p>
Specifies the strength value of the key. The strength is
@@ -238,7 +248,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2544128"></a><h2>TIMING OPTIONS</h2>
<a name="id2544166"></a><h2>TIMING OPTIONS</h2>
<p>
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
If the argument begins with a '+' or '-', it is interpreted as
@@ -282,10 +292,34 @@
date, the key will no longer be included in the zone. (It
may remain in the key repository, however.)
</p></dd>
<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
<dd>
<p>
Sets the prepublication interval for a key. If set, then
the publication and activation dates must be separated by at least
this much time. If the activation date is specified but the
publication date isn't, then the publication date will default
to this much time before the activation date; conversely, if
the publication date is specified but activation date isn't,
then activation will be set to this much time after publication.
</p>
<p>
If the key is being created as an explicit successor to another
key, then the default prepublication interval is 30 days;
otherwise it is zero.
</p>
<p>
As with date offsets, if the argument is followed by one of
the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
interval is measured in years, months, weeks, days, hours,
or minutes, respectively. Without a suffix, the interval is
measured in seconds.
</p>
</dd>
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2544226"></a><h2>GENERATED KEYS</h2>
<a name="id2544356"></a><h2>GENERATED KEYS</h2>
<p>
When <span><strong class="command">dnssec-keygen</strong></span> completes
successfully,
@@ -331,7 +365,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544308"></a><h2>EXAMPLE</h2>
<a name="id2544506"></a><h2>EXAMPLE</h2>
<p>
To generate a 768-bit DSA key for the domain
<strong class="userinput"><code>example.com</code></strong>, the following command would be
@@ -352,7 +386,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544352"></a><h2>SEE ALSO</h2>
<a name="id2544550"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
<em class="citetitle">RFC 2539</em>,
@@ -361,7 +395,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544451"></a><h2>AUTHOR</h2>
<a name="id2544581"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
+12 -7
View File
@@ -1,18 +1,18 @@
.\" Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
.\"
.\" Copyright (C) 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
.\"
.\" Permission to use, copy, modify, and/or distribute this software for any
.\" purpose with or without fee is hereby granted, provided that the above
.\" copyright notice and this permission notice appear in all copies.
.\"
.\"
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: dnssec-revoke.8,v 1.8 2009/11/03 21:58:30 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
@@ -32,7 +32,7 @@
dnssec\-revoke \- Set the REVOKED bit on a DNSSEC key
.SH "SYNOPSIS"
.HP 14
\fBdnssec\-revoke\fR [\fB\-hr\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\fR] {keyfile}
\fBdnssec\-revoke\fR [\fB\-hr\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\fR] [\fB\-R\fR] {keyfile}
.SH "DESCRIPTION"
.PP
\fBdnssec\-revoke\fR
@@ -70,6 +70,11 @@ Force overwrite: Causes
\fBdnssec\-revoke\fR
to write the new key pair even if a file already exists matching the algorithm and key ID of the revoked key.
.RE
.PP
\-R
.RS 4
Print the key tag of the key with the REVOKE bit set but do not revoke the key.
.RE
.SH "SEE ALSO"
.PP
\fBdnssec\-keygen\fR(8),
@@ -79,5 +84,5 @@ RFC 5011.
.PP
Internet Systems Consortium
.SH "COPYRIGHT"
Copyright \(co 2009 Internet Systems Consortium, Inc. ("ISC")
Copyright \(co 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
.br
+18 -7
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2009-2011 Internet Systems Consortium, Inc. ("ISC")
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dnssec-revoke.c,v 1.18.34.2 2009/12/18 23:48:18 tbox Exp $ */
/* $Id: dnssec-revoke.c,v 1.18.34.6 2011/10/20 23:46:03 tbox Exp $ */
/*! \file */
@@ -92,6 +92,7 @@ main(int argc, char **argv) {
isc_buffer_t buf;
isc_boolean_t force = ISC_FALSE;
isc_boolean_t remove = ISC_FALSE;
isc_boolean_t id = ISC_FALSE;
if (argc == 1)
usage();
@@ -104,7 +105,7 @@ main(int argc, char **argv) {
isc_commandline_errprint = ISC_FALSE;
while ((ch = isc_commandline_parse(argc, argv, "E:fK:rhv:")) != -1) {
while ((ch = isc_commandline_parse(argc, argv, "E:fK:rRhv:")) != -1) {
switch (ch) {
case 'E':
engine = isc_commandline_argument;
@@ -126,6 +127,9 @@ main(int argc, char **argv) {
case 'r':
remove = ISC_TRUE;
break;
case 'R':
id = ISC_TRUE;
break;
case 'v':
verbose = strtol(isc_commandline_argument, &endp, 0);
if (*endp != '\0')
@@ -161,6 +165,10 @@ main(int argc, char **argv) {
fatal("cannot process filename %s: %s",
argv[isc_commandline_index],
isc_result_totext(result));
if (strcmp(dir, ".") == 0) {
isc_mem_free(mctx, dir);
dir = NULL;
}
}
if (ectx == NULL)
@@ -182,6 +190,10 @@ main(int argc, char **argv) {
fatal("Invalid keyfile name %s: %s",
filename, isc_result_totext(result));
if (id) {
fprintf(stdout, "%u\n", dst_key_rid(key));
goto cleanup;
}
dst_key_format(key, keystr, sizeof(keystr));
if (verbose > 2)
@@ -224,10 +236,8 @@ main(int argc, char **argv) {
isc_result_totext(result));
}
printf("%s\n", newname);
isc_buffer_clear(&buf);
dst_key_buildfilename(key, DST_TYPE_PRIVATE, dir, &buf);
dst_key_buildfilename(key, 0, dir, &buf);
printf("%s\n", newname);
/*
@@ -259,7 +269,8 @@ cleanup:
cleanup_entropy(&ectx);
if (verbose > 10)
isc_mem_stats(mctx, stdout);
isc_mem_free(mctx, dir);
if (dir != NULL)
isc_mem_free(mctx, dir);
isc_mem_destroy(&mctx);
return (0);
+14 -2
View File
@@ -2,7 +2,7 @@
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
[<!ENTITY mdash "&#8212;">]>
<!--
- Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
@@ -17,7 +17,7 @@
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dnssec-revoke.docbook,v 1.7 2009/11/03 21:44:46 each Exp $ -->
<!-- $Id: dnssec-revoke.docbook,v 1.7.24.2 2011/10/20 23:46:04 tbox Exp $ -->
<refentry id="man.dnssec-revoke">
<refentryinfo>
<date>June 1, 2009</date>
@@ -37,6 +37,7 @@
<docinfo>
<copyright>
<year>2009</year>
<year>2011</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright>
</docinfo>
@@ -49,6 +50,7 @@
<arg><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
<arg><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
<arg><option>-f</option></arg>
<arg><option>-R</option></arg>
<arg choice="req">keyfile</arg>
</cmdsynopsis>
</refsynopsisdiv>
@@ -123,6 +125,16 @@
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-R</term>
<listitem>
<para>
Print the key tag of the key with the REVOKE bit set but do
not revoke the key.
</para>
</listitem>
</varlistentry>
</variablelist>
</refsect1>
+15 -11
View File
@@ -1,20 +1,19 @@
<!--
- Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
-
- Copyright (C) 2009, 2011 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
- copyright notice and this permission notice appear in all copies.
-
-
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dnssec-revoke.html,v 1.8 2009/11/03 21:58:30 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -29,10 +28,10 @@
</div>
<div class="refsynopsisdiv">
<h2>Synopsis</h2>
<div class="cmdsynopsis"><p><code class="command">dnssec-revoke</code> [<code class="option">-hr</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f</code>] {keyfile}</p></div>
<div class="cmdsynopsis"><p><code class="command">dnssec-revoke</code> [<code class="option">-hr</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f</code>] [<code class="option">-R</code>] {keyfile}</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543373"></a><h2>DESCRIPTION</h2>
<a name="id2543382"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">dnssec-revoke</strong></span>
reads a DNSSEC key file, sets the REVOKED bit on the key as defined
in RFC 5011, and creates a new pair of key files containing the
@@ -40,7 +39,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543385"></a><h2>OPTIONS</h2>
<a name="id2543394"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-h</span></dt>
<dd><p>
@@ -70,17 +69,22 @@
write the new key pair even if a file already exists matching
the algorithm and key ID of the revoked key.
</p></dd>
<dt><span class="term">-R</span></dt>
<dd><p>
Print the key tag of the key with the REVOKE bit set but do
not revoke the key.
</p></dd>
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543491"></a><h2>SEE ALSO</h2>
<a name="id2543512"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
<em class="citetitle">RFC 5011</em>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543515"></a><h2>AUTHOR</h2>
<a name="id2543537"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
+26 -12
View File
@@ -1,18 +1,18 @@
.\" Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
.\"
.\" Copyright (C) 2009-2011 Internet Systems Consortium, Inc. ("ISC")
.\"
.\" Permission to use, copy, modify, and/or distribute this software for any
.\" purpose with or without fee is hereby granted, provided that the above
.\" copyright notice and this permission notice appear in all copies.
.\"
.\"
.\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: dnssec-settime.8,v 1.9 2009/11/03 21:58:30 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
@@ -52,14 +52,14 @@ simply prints the key timing metadata already stored in the key.
.PP
When key metadata fields are changed, both files of a key pair (\fIKnnnn.+aaa+iiiii.key\fR
and
\fIKnnnn.+aaa+iiiii.private\fR) are regenerated. Metadata fields are stored in the private file. A human\-readable description of the metadata is also placed in comments in the key file.
\fIKnnnn.+aaa+iiiii.private\fR) are regenerated. Metadata fields are stored in the private file. A human\-readable description of the metadata is also placed in comments in the key file. The private file's permissions are always set to be inaccessible to anyone other than the owner (mode 0600).
.SH "OPTIONS"
.PP
\-f
.RS 4
Force an update of an old\-format key with no metadata fields. Without this option,
\fBdnssec\-settime\fR
will fail when attempting to update a legacy key. With this option, the key will be recreated in the new format, but with the original key data retained. The key's creation date will be set to the present time.
will fail when attempting to update a legacy key. With this option, the key will be recreated in the new format, but with the original key data retained. The key's creation date will be set to the present time. If no other values are specified, then the key's publication and activation dates will also be set to the present time.
.RE
.PP
\-K \fIdirectory\fR
@@ -109,6 +109,20 @@ Sets the date on which the key is to be retired. After that date, the key will s
.RS 4
Sets the date on which the key is to be deleted. After that date, the key will no longer be included in the zone. (It may remain in the key repository, however.)
.RE
.PP
\-S \fIpredecessor key\fR
.RS 4
Select a key for which the key being modified will be an explicit successor. The name, algorithm, size, and type of the predecessor key must exactly match those of the key being modified. The activation date of the successor key will be set to the inactivation date of the predecessor. The publication date will be set to the activation date minus the prepublication interval, which defaults to 30 days.
.RE
.PP
\-i \fIinterval\fR
.RS 4
Sets the prepublication interval for a key. If set, then the publication and activation dates must be separated by at least this much time. If the activation date is specified but the publication date isn't, then the publication date will default to this much time before the activation date; conversely, if the publication date is specified but activation date isn't, then activation will be set to this much time after publication.
.sp
If the key is being set to be an explicit successor to another key, then the default prepublication interval is 30 days; otherwise it is zero.
.sp
As with date offsets, if the argument is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the interval is measured in years, months, weeks, days, hours, or minutes, respectively. Without a suffix, the interval is measured in seconds.
.RE
.SH "PRINTING OPTIONS"
.PP
\fBdnssec\-settime\fR
@@ -119,7 +133,7 @@ can also be used to print the timing metadata associated with a key.
Print times in UNIX epoch format.
.RE
.PP
\-p \fIC/P/A/R/U/D/all\fR
\-p \fIC/P/A/R/I/D/all\fR
.RS 4
Print a specific metadata value or set of metadata values. The
\fB\-p\fR
@@ -131,9 +145,9 @@ for the publication date,
\fBA\fR
for the activation date,
\fBR\fR
for the revokation date,
\fBU\fR
for the unpublication date, or
for the revocation date,
\fBI\fR
for the inactivation date, or
\fBD\fR
for the deletion date. To print all of the metadata, use
\fB\-p all\fR.
@@ -148,5 +162,5 @@ RFC 5011.
.PP
Internet Systems Consortium
.SH "COPYRIGHT"
Copyright \(co 2009 Internet Systems Consortium, Inc. ("ISC")
Copyright \(co 2009\-2011 Internet Systems Consortium, Inc. ("ISC")
.br
+155 -29
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2009-2012 Internet Systems Consortium, Inc. ("ISC")
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -14,7 +14,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dnssec-settime.c,v 1.19.34.5 2010/01/07 19:16:30 each Exp $ */
/* $Id: dnssec-settime.c,v 1.19.34.12 2011/06/02 20:23:48 each Exp $ */
/*! \file */
@@ -38,6 +38,7 @@
#include <dns/keyvalues.h>
#include <dns/result.h>
#include <dns/log.h>
#include <dst/dst.h>
@@ -80,9 +81,8 @@ usage(void) {
fprintf(stderr, " -D date/[+-]offset/none: set/unset key "
"deletion date\n");
fprintf(stderr, "Printing options:\n");
fprintf(stderr, " -p C/P/A/R/U/D/all: print a particular time "
"value or values "
"[default: all]\n");
fprintf(stderr, " -p C/P/A/R/I/D/all: print a particular time "
"value or values\n");
fprintf(stderr, " -u: print times in unix epoch "
"format\n");
fprintf(stderr, "Output:\n");
@@ -117,20 +117,27 @@ printtime(dst_key_t *key, int type, const char *tag, isc_boolean_t epoch,
int
main(int argc, char **argv) {
isc_result_t result;
isc_result_t result;
#ifdef USE_PKCS11
const char *engine = "pkcs11";
const char *engine = "pkcs11";
#else
const char *engine = NULL;
const char *engine = NULL;
#endif
char *filename = NULL, *directory = NULL;
char newname[1024];
char keystr[DST_KEY_FORMATSIZE];
char *endp, *p;
int ch;
isc_entropy_t *ectx = NULL;
dst_key_t *key = NULL;
isc_buffer_t buf;
char *filename = NULL, *directory = NULL;
char newname[1024];
char keystr[DST_KEY_FORMATSIZE];
char *endp, *p;
int ch;
isc_entropy_t *ectx = NULL;
const char *predecessor = NULL;
dst_key_t *prevkey = NULL;
dst_key_t *key = NULL;
isc_buffer_t buf;
dns_name_t *name = NULL;
dns_secalg_t alg = 0;
unsigned int size = 0;
isc_uint16_t flags = 0;
int prepub = -1;
isc_stdtime_t now;
isc_stdtime_t pub = 0, act = 0, rev = 0, inact = 0, del = 0;
isc_boolean_t setpub = ISC_FALSE, setact = ISC_FALSE;
@@ -145,6 +152,7 @@ main(int argc, char **argv) {
isc_boolean_t force = ISC_FALSE;
isc_boolean_t epoch = ISC_FALSE;
isc_boolean_t changed = ISC_FALSE;
isc_log_t *log = NULL;
if (argc == 1)
usage();
@@ -153,14 +161,16 @@ main(int argc, char **argv) {
if (result != ISC_R_SUCCESS)
fatal("Out of memory");
setup_logging(verbose, mctx, &log);
dns_result_register();
isc_commandline_errprint = ISC_FALSE;
isc_stdtime_get(&now);
while ((ch = isc_commandline_parse(argc, argv,
"E:fK:uhp:v:P:A:R:I:D:")) != -1) {
#define CMDLINE_FLAGS "A:D:E:fhI:i:K:P:p:R:S:uv:"
while ((ch = isc_commandline_parse(argc, argv, CMDLINE_FLAGS)) != -1) {
switch (ch) {
case 'E':
engine = isc_commandline_argument;
@@ -293,6 +303,12 @@ main(int argc, char **argv) {
now, now);
}
break;
case 'S':
predecessor = isc_commandline_argument;
break;
case 'i':
prepub = strtottl(isc_commandline_argument);
break;
case '?':
if (isc_commandline_option != '?')
fprintf(stderr, "%s: invalid argument -%c\n",
@@ -314,17 +330,6 @@ main(int argc, char **argv) {
if (argc > isc_commandline_index + 1)
fatal("Extraneous arguments");
if (directory != NULL) {
filename = argv[isc_commandline_index];
} else {
result = isc_file_splitpath(mctx, argv[isc_commandline_index],
&directory, &filename);
if (result != ISC_R_SUCCESS)
fatal("cannot process filename %s: %s",
argv[isc_commandline_index],
isc_result_totext(result));
}
if (ectx == NULL)
setup_entropy(mctx, NULL, &ectx);
result = isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE);
@@ -337,6 +342,105 @@ main(int argc, char **argv) {
isc_result_totext(result));
isc_entropy_stopcallbacksources(ectx);
if (predecessor != NULL) {
char keystr[DST_KEY_FORMATSIZE];
isc_stdtime_t when;
int major, minor;
if (prepub == -1)
prepub = (30 * 86400);
if (setpub || unsetpub)
fatal("-S and -P cannot be used together");
if (setact || unsetact)
fatal("-S and -A cannot be used together");
result = dst_key_fromnamedfile(predecessor, directory,
DST_TYPE_PUBLIC |
DST_TYPE_PRIVATE,
mctx, &prevkey);
if (result != ISC_R_SUCCESS)
fatal("Invalid keyfile %s: %s",
filename, isc_result_totext(result));
if (!dst_key_isprivate(prevkey))
fatal("%s is not a private key", filename);
name = dst_key_name(prevkey);
alg = dst_key_alg(prevkey);
size = dst_key_size(prevkey);
flags = dst_key_flags(prevkey);
dst_key_format(prevkey, keystr, sizeof(keystr));
dst_key_getprivateformat(prevkey, &major, &minor);
if (major != DST_MAJOR_VERSION || minor < DST_MINOR_VERSION)
fatal("Predecessor has incompatible format "
"version %d.%d\n\t", major, minor);
result = dst_key_gettime(prevkey, DST_TIME_ACTIVATE, &when);
if (result != ISC_R_SUCCESS)
fatal("Predecessor has no activation date. "
"You must set one before\n\t"
"generating a successor.");
result = dst_key_gettime(prevkey, DST_TIME_INACTIVE, &act);
if (result != ISC_R_SUCCESS)
fatal("Predecessor has no inactivation date. "
"You must set one before\n\t"
"generating a successor.");
pub = act - prepub;
if (pub < now && prepub != 0)
fatal("Predecessor will become inactive before the\n\t"
"prepublication period ends. Either change "
"its inactivation date,\n\t"
"or use the -i option to set a shorter "
"prepublication interval.");
result = dst_key_gettime(prevkey, DST_TIME_DELETE, &when);
if (result != ISC_R_SUCCESS)
fprintf(stderr, "%s: WARNING: Predecessor has no "
"removal date;\n\t"
"it will remain in the zone "
"indefinitely after rollover.\n",
program);
changed = setpub = setact = ISC_TRUE;
dst_key_free(&prevkey);
} else {
if (prepub < 0)
prepub = 0;
if (prepub > 0) {
if (setpub && setact && (act - prepub) < pub)
fatal("Activation and publication dates "
"are closer together than the\n\t"
"prepublication interval.");
if (setpub && !setact) {
setact = ISC_TRUE;
act = pub + prepub;
} else if (setact && !setpub) {
setpub = ISC_TRUE;
pub = act - prepub;
}
if ((act - prepub) < now)
fatal("Time until activation is shorter "
"than the\n\tprepublication interval.");
}
}
if (directory != NULL) {
filename = argv[isc_commandline_index];
} else {
result = isc_file_splitpath(mctx, argv[isc_commandline_index],
&directory, &filename);
if (result != ISC_R_SUCCESS)
fatal("cannot process filename %s: %s",
argv[isc_commandline_index],
isc_result_totext(result));
}
result = dst_key_fromnamedfile(filename, directory,
DST_TYPE_PUBLIC | DST_TYPE_PRIVATE,
mctx, &key);
@@ -349,6 +453,17 @@ main(int argc, char **argv) {
dst_key_format(key, keystr, sizeof(keystr));
if (predecessor != NULL) {
if (!dns_name_equal(name, dst_key_name(key)))
fatal("Key name mismatch");
if (alg != dst_key_alg(key))
fatal("Key algorithm mismatch");
if (size != dst_key_size(key))
fatal("Key size mismatch");
if (flags != dst_key_flags(key))
fatal("Key flags mismatch");
}
if (force)
set_keyversion(key);
else
@@ -401,6 +516,16 @@ main(int argc, char **argv) {
else if (unsetdel)
dst_key_unsettime(key, DST_TIME_DELETE);
/*
* No metadata changes were made but we're forcing an upgrade
* to the new format anyway: use "-P now -A now" as the default
*/
if (force && !changed) {
dst_key_settime(key, DST_TIME_PUBLISH, now);
dst_key_settime(key, DST_TIME_ACTIVATE, now);
changed = ISC_TRUE;
}
/*
* Print out time values, if -p was used.
*/
@@ -457,6 +582,7 @@ main(int argc, char **argv) {
cleanup_entropy(&ectx);
if (verbose > 10)
isc_mem_stats(mctx, stdout);
cleanup_logging(&log);
isc_mem_free(mctx, directory);
isc_mem_destroy(&mctx);
+53 -7
View File
@@ -2,7 +2,7 @@
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
[<!ENTITY mdash "&#8212;">]>
<!--
- Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2009-2011 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
@@ -17,7 +17,7 @@
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dnssec-settime.docbook,v 1.7 2009/11/03 21:44:46 each Exp $ -->
<!-- $Id: dnssec-settime.docbook,v 1.7.24.7 2011/11/03 20:21:24 each Exp $ -->
<refentry id="man.dnssec-settime">
<refentryinfo>
<date>July 15, 2009</date>
@@ -37,6 +37,8 @@
<docinfo>
<copyright>
<year>2009</year>
<year>2010</year>
<year>2011</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright>
</docinfo>
@@ -80,7 +82,8 @@
<filename>Knnnn.+aaa+iiiii.private</filename>) are regenerated.
Metadata fields are stored in the private file. A human-readable
description of the metadata is also placed in comments in the key
file.
file. The private file's permissions are always set to be
inaccessible to anyone other than the owner (mode 0600).
</para>
</refsect1>
@@ -97,7 +100,9 @@
fail when attempting to update a legacy key. With this option,
the key will be recreated in the new format, but with the
original key data retained. The key's creation date will be
set to the present time.
set to the present time. If no other values are specified,
then the key's publication and activation dates will also
be set to the present time.
</para>
</listitem>
</varlistentry>
@@ -210,6 +215,47 @@
</listitem>
</varlistentry>
<varlistentry>
<term>-S <replaceable class="parameter">predecessor key</replaceable></term>
<listitem>
<para>
Select a key for which the key being modified will be an
explicit successor. The name, algorithm, size, and type of the
predecessor key must exactly match those of the key being
modified. The activation date of the successor key will be set
to the inactivation date of the predecessor. The publication
date will be set to the activation date minus the prepublication
interval, which defaults to 30 days.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-i <replaceable class="parameter">interval</replaceable></term>
<listitem>
<para>
Sets the prepublication interval for a key. If set, then
the publication and activation dates must be separated by at least
this much time. If the activation date is specified but the
publication date isn't, then the publication date will default
to this much time before the activation date; conversely, if
the publication date is specified but activation date isn't,
then activation will be set to this much time after publication.
</para>
<para>
If the key is being set to be an explicit successor to another
key, then the default prepublication interval is 30 days;
otherwise it is zero.
</para>
<para>
As with date offsets, if the argument is followed by one of
the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
interval is measured in years, months, weeks, days, hours,
or minutes, respectively. Without a suffix, the interval is
measured in seconds.
</para>
</listitem>
</varlistentry>
</variablelist>
</refsect1>
@@ -231,7 +277,7 @@
</varlistentry>
<varlistentry>
<term>-p <replaceable class="parameter">C/P/A/R/U/D/all</replaceable></term>
<term>-p <replaceable class="parameter">C/P/A/R/I/D/all</replaceable></term>
<listitem>
<para>
Print a specific metadata value or set of metadata values.
@@ -240,8 +286,8 @@
<option>C</option> for the creation date,
<option>P</option> for the publication date,
<option>A</option> for the activation date,
<option>R</option> for the revokation date,
<option>U</option> for the unpublication date, or
<option>R</option> for the revocation date,
<option>I</option> for the inactivation date, or
<option>D</option> for the deletion date.
To print all of the metadata, use <option>-p all</option>.
</para>
+53 -17
View File
@@ -1,20 +1,19 @@
<!--
- Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
-
- Copyright (C) 2009-2011 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
- copyright notice and this permission notice appear in all copies.
-
-
- THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
- REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
- AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
- INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
- LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dnssec-settime.html,v 1.9 2009/11/03 21:58:30 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -32,7 +31,7 @@
<div class="cmdsynopsis"><p><code class="command">dnssec-settime</code> [<code class="option">-f</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-h</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] {keyfile}</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543416"></a><h2>DESCRIPTION</h2>
<a name="id2543424"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">dnssec-settime</strong></span>
reads a DNSSEC private key file and sets the key timing metadata
as specified by the <code class="option">-P</code>, <code class="option">-A</code>,
@@ -53,11 +52,12 @@
<code class="filename">Knnnn.+aaa+iiiii.private</code>) are regenerated.
Metadata fields are stored in the private file. A human-readable
description of the metadata is also placed in comments in the key
file.
file. The private file's permissions are always set to be
inaccessible to anyone other than the owner (mode 0600).
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543464"></a><h2>OPTIONS</h2>
<a name="id2543472"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-f</span></dt>
<dd><p>
@@ -66,7 +66,9 @@
fail when attempting to update a legacy key. With this option,
the key will be recreated in the new format, but with the
original key data retained. The key's creation date will be
set to the present time.
set to the present time. If no other values are specified,
then the key's publication and activation dates will also
be set to the present time.
</p></dd>
<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
<dd><p>
@@ -88,7 +90,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543556"></a><h2>TIMING OPTIONS</h2>
<a name="id2543563"></a><h2>TIMING OPTIONS</h2>
<p>
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
If the argument begins with a '+' or '-', it is interpreted as
@@ -130,10 +132,44 @@
date, the key will no longer be included in the zone. (It
may remain in the key repository, however.)
</p></dd>
<dt><span class="term">-S <em class="replaceable"><code>predecessor key</code></em></span></dt>
<dd><p>
Select a key for which the key being modified will be an
explicit successor. The name, algorithm, size, and type of the
predecessor key must exactly match those of the key being
modified. The activation date of the successor key will be set
to the inactivation date of the predecessor. The publication
date will be set to the activation date minus the prepublication
interval, which defaults to 30 days.
</p></dd>
<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
<dd>
<p>
Sets the prepublication interval for a key. If set, then
the publication and activation dates must be separated by at least
this much time. If the activation date is specified but the
publication date isn't, then the publication date will default
to this much time before the activation date; conversely, if
the publication date is specified but activation date isn't,
then activation will be set to this much time after publication.
</p>
<p>
If the key is being set to be an explicit successor to another
key, then the default prepublication interval is 30 days;
otherwise it is zero.
</p>
<p>
As with date offsets, if the argument is followed by one of
the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
interval is measured in years, months, weeks, days, hours,
or minutes, respectively. Without a suffix, the interval is
measured in seconds.
</p>
</dd>
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543654"></a><h2>PRINTING OPTIONS</h2>
<a name="id2543770"></a><h2>PRINTING OPTIONS</h2>
<p>
<span><strong class="command">dnssec-settime</strong></span> can also be used to print the
timing metadata associated with a key.
@@ -143,7 +179,7 @@
<dd><p>
Print times in UNIX epoch format.
</p></dd>
<dt><span class="term">-p <em class="replaceable"><code>C/P/A/R/U/D/all</code></em></span></dt>
<dt><span class="term">-p <em class="replaceable"><code>C/P/A/R/I/D/all</code></em></span></dt>
<dd><p>
Print a specific metadata value or set of metadata values.
The <code class="option">-p</code> option may be followed by one or more
@@ -151,15 +187,15 @@
<code class="option">C</code> for the creation date,
<code class="option">P</code> for the publication date,
<code class="option">A</code> for the activation date,
<code class="option">R</code> for the revokation date,
<code class="option">U</code> for the unpublication date, or
<code class="option">R</code> for the revocation date,
<code class="option">I</code> for the inactivation date, or
<code class="option">D</code> for the deletion date.
To print all of the metadata, use <code class="option">-p all</code>.
</p></dd>
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543732"></a><h2>SEE ALSO</h2>
<a name="id2543848"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
@@ -167,7 +203,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543765"></a><h2>AUTHOR</h2>
<a name="id2543881"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
+1 -1
View File
@@ -13,7 +13,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: dnssec-signzone.8,v 1.59 2009/12/04 01:13:44 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
+186 -116
View File
@@ -1,5 +1,5 @@
/*
* Portions Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
* Portions Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Portions Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -29,7 +29,7 @@
* IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dnssec-signzone.c,v 1.258.4.2 2010/01/05 23:47:58 tbox Exp $ */
/* $Id: dnssec-signzone.c,v 1.258.4.13 2011/08/26 23:45:30 tbox Exp $ */
/*! \file */
@@ -338,7 +338,7 @@ keythatsigned(dns_rdata_rrsig_t *rrsig) {
} else {
dns_dnsseckey_create(mctx, &pubkey, &key);
}
key->force_publish = ISC_TRUE;
key->force_publish = ISC_FALSE;
key->force_sign = ISC_FALSE;
ISC_LIST_APPEND(keylist, key, link);
@@ -486,32 +486,32 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
if (!expired)
keep = ISC_TRUE;
} else if (issigningkey(key)) {
if (!expired && setverifies(name, set, key->key,
&sigrdata)) {
if (!expired && rrsig.originalttl == set->ttl &&
setverifies(name, set, key->key, &sigrdata)) {
vbprintf(2, "\trrsig by %s retained\n", sigstr);
keep = ISC_TRUE;
wassignedby[key->index] = ISC_TRUE;
nowsignedby[key->index] = ISC_TRUE;
} else {
vbprintf(2, "\trrsig by %s dropped - %s\n",
sigstr,
expired ? "expired" :
"failed to verify");
sigstr, expired ? "expired" :
rrsig.originalttl != set->ttl ?
"ttl change" : "failed to verify");
wassignedby[key->index] = ISC_TRUE;
resign = ISC_TRUE;
}
} else if (iszonekey(key)) {
if (!expired && setverifies(name, set, key->key,
&sigrdata)) {
if (!expired && rrsig.originalttl == set->ttl &&
setverifies(name, set, key->key, &sigrdata)) {
vbprintf(2, "\trrsig by %s retained\n", sigstr);
keep = ISC_TRUE;
wassignedby[key->index] = ISC_TRUE;
nowsignedby[key->index] = ISC_TRUE;
} else {
vbprintf(2, "\trrsig by %s dropped - %s\n",
sigstr,
expired ? "expired" :
"failed to verify");
sigstr, expired ? "expired" :
rrsig.originalttl != set->ttl ?
"ttl change" : "failed to verify");
wassignedby[key->index] = ISC_TRUE;
}
} else if (!expired) {
@@ -522,7 +522,8 @@ signset(dns_diff_t *del, dns_diff_t *add, dns_dbnode_t *node, dns_name_t *name,
}
if (keep) {
nowsignedby[key->index] = ISC_TRUE;
if (key != NULL)
nowsignedby[key->index] = ISC_TRUE;
INCSTAT(nretained);
if (sigset.ttl != ttl) {
vbprintf(2, "\tfixing ttl %s\n", sigstr);
@@ -1387,6 +1388,13 @@ verifyset(dns_rdataset_t *rdataset, dns_name_t *name, dns_dbnode_t *node,
dns_rdataset_current(&sigrdataset, &rdata);
dns_rdata_tostruct(&rdata, &sig, NULL);
if (rdataset->ttl != sig.originalttl) {
dns_name_format(name, namebuf, sizeof(namebuf));
type_format(rdataset->type, typebuf, sizeof(typebuf));
fprintf(stderr, "TTL mismatch for %s %s keytag %u\n",
namebuf, typebuf, sig.keyid);
continue;
}
if ((set_algorithms[sig.algorithm] != 0) ||
(ksk_algorithms[sig.algorithm] == 0))
continue;
@@ -1443,14 +1451,14 @@ verifynode(dns_name_t *name, dns_dbnode_t *node, isc_boolean_t delegation,
/*%
* Verify that certain things are sane:
*
* The apex has a DNSKEY record with at least one KSK, and at least
* The apex has a DNSKEY RRset with at least one KSK, and at least
* one ZSK if the -x flag was not used.
*
* The DNSKEY record was signed with at least one of the KSKs in this
* set.
* The DNSKEY record was signed with at least one of the KSKs in
* the DNSKEY RRset.
*
* The rest of the zone was signed with at least one of the ZSKs
* present in the DNSKEY RRSET.
* present in the DNSKEY RRset.
*/
static void
verifyzone(void) {
@@ -1461,13 +1469,12 @@ verifyzone(void) {
dns_name_t *name, *nextname, *zonecut;
dns_rdata_dnskey_t dnskey;
dns_rdata_t rdata = DNS_RDATA_INIT;
dns_rdataset_t rdataset;
dns_rdataset_t sigrdataset;
dns_rdataset_t keyset, soaset;
dns_rdataset_t keysigs, soasigs;
int i;
isc_boolean_t done = ISC_FALSE;
isc_boolean_t first = ISC_TRUE;
isc_boolean_t goodksk = ISC_FALSE;
isc_boolean_t goodzsk = ISC_FALSE;
isc_result_t result;
unsigned char revoked_ksk[256];
unsigned char revoked_zsk[256];
@@ -1489,18 +1496,30 @@ verifyzone(void) {
fatal("failed to find the zone's origin: %s",
isc_result_totext(result));
dns_rdataset_init(&rdataset);
dns_rdataset_init(&sigrdataset);
dns_rdataset_init(&keyset);
dns_rdataset_init(&keysigs);
dns_rdataset_init(&soaset);
dns_rdataset_init(&soasigs);
result = dns_db_findrdataset(gdb, node, gversion,
dns_rdatatype_dnskey,
0, 0, &rdataset, &sigrdataset);
dns_db_detachnode(gdb, &node);
0, 0, &keyset, &keysigs);
if (result != ISC_R_SUCCESS)
fatal("cannot find DNSKEY rrset\n");
if (!dns_rdataset_isassociated(&sigrdataset))
result = dns_db_findrdataset(gdb, node, gversion,
dns_rdatatype_soa,
0, 0, &soaset, &soasigs);
dns_db_detachnode(gdb, &node);
if (result != ISC_R_SUCCESS)
fatal("cannot find SOA rrset\n");
if (!dns_rdataset_isassociated(&keysigs))
fatal("cannot find DNSKEY RRSIGs\n");
if (!dns_rdataset_isassociated(&soasigs))
fatal("cannot find SOA RRSIGs\n");
memset(revoked_ksk, 0, sizeof(revoked_ksk));
memset(revoked_zsk, 0, sizeof(revoked_zsk));
memset(standby_ksk, 0, sizeof(standby_ksk));
@@ -1517,10 +1536,10 @@ verifyzone(void) {
* and one ZSK per algorithm in it (or, if -x was used, one
* self-signing KSK).
*/
for (result = dns_rdataset_first(&rdataset);
for (result = dns_rdataset_first(&keyset);
result == ISC_R_SUCCESS;
result = dns_rdataset_next(&rdataset)) {
dns_rdataset_current(&rdataset, &rdata);
result = dns_rdataset_next(&keyset)) {
dns_rdataset_current(&keyset, &rdata);
result = dns_rdata_tostruct(&rdata, &dnskey, NULL);
check_result(result, "dns_rdata_tostruct");
@@ -1528,8 +1547,8 @@ verifyzone(void) {
;
else if ((dnskey.flags & DNS_KEYFLAG_REVOKE) != 0) {
if ((dnskey.flags & DNS_KEYFLAG_KSK) != 0 &&
!dns_dnssec_selfsigns(&rdata, gorigin, &rdataset,
&sigrdataset, ISC_FALSE,
!dns_dnssec_selfsigns(&rdata, gorigin, &keyset,
&keysigs, ISC_FALSE,
mctx)) {
char namebuf[DNS_NAME_FORMATSIZE];
char buffer[1024];
@@ -1551,8 +1570,8 @@ verifyzone(void) {
revoked_zsk[dnskey.algorithm] != 255)
revoked_zsk[dnskey.algorithm]++;
} else if ((dnskey.flags & DNS_KEYFLAG_KSK) != 0) {
if (dns_dnssec_selfsigns(&rdata, gorigin, &rdataset,
&sigrdataset, ISC_FALSE, mctx)) {
if (dns_dnssec_selfsigns(&rdata, gorigin, &keyset,
&keysigs, ISC_FALSE, mctx)) {
if (ksk_algorithms[dnskey.algorithm] != 255)
ksk_algorithms[dnskey.algorithm]++;
goodksk = ISC_TRUE;
@@ -1560,8 +1579,8 @@ verifyzone(void) {
if (standby_ksk[dnskey.algorithm] != 255)
standby_ksk[dnskey.algorithm]++;
}
} else if (dns_dnssec_selfsigns(&rdata, gorigin, &rdataset,
&sigrdataset, ISC_FALSE,
} else if (dns_dnssec_selfsigns(&rdata, gorigin, &keyset,
&keysigs, ISC_FALSE,
mctx)) {
#ifdef ALLOW_KSKLESS_ZONES
if (self_algorithms[dnskey.algorithm] != 255)
@@ -1569,7 +1588,10 @@ verifyzone(void) {
#endif
if (zsk_algorithms[dnskey.algorithm] != 255)
zsk_algorithms[dnskey.algorithm]++;
goodzsk = ISC_TRUE;
} else if (dns_dnssec_signs(&rdata, gorigin, &soaset,
&soasigs, ISC_FALSE, mctx)) {
if (zsk_algorithms[dnskey.algorithm] != 255)
zsk_algorithms[dnskey.algorithm]++;
} else {
if (standby_zsk[dnskey.algorithm] != 255)
standby_zsk[dnskey.algorithm]++;
@@ -1580,7 +1602,9 @@ verifyzone(void) {
dns_rdata_freestruct(&dnskey);
dns_rdata_reset(&rdata);
}
dns_rdataset_disassociate(&sigrdataset);
dns_rdataset_disassociate(&keysigs);
dns_rdataset_disassociate(&soaset);
dns_rdataset_disassociate(&soasigs);
#ifdef ALLOW_KSKLESS_ZONES
if (!goodksk) {
@@ -1595,7 +1619,7 @@ verifyzone(void) {
}
#else
if (!goodksk) {
fatal("no self signed KSK's found");
fatal("No self signed KSK's found");
}
#endif
@@ -1655,12 +1679,21 @@ verifyzone(void) {
result = dns_dbiterator_current(dbiter, &node, name);
check_dns_dbiterator_current(result);
if (!dns_name_issubdomain(name, gorigin)) {
dns_db_detachnode(gdb, &node);
result = dns_dbiterator_next(dbiter);
if (result == ISC_R_NOMORE)
done = ISC_TRUE;
else
check_result(result, "dns_dbiterator_next()");
continue;
}
if (delegation(name, node, NULL)) {
zonecut = dns_fixedname_name(&fzonecut);
dns_name_copy(name, zonecut, NULL);
isdelegation = ISC_TRUE;
}
verifynode(name, node, isdelegation, &rdataset,
verifynode(name, node, isdelegation, &keyset,
ksk_algorithms, bad_algorithms);
result = dns_dbiterator_next(dbiter);
nextnode = NULL;
@@ -1697,13 +1730,13 @@ verifyzone(void) {
result = dns_dbiterator_next(dbiter) ) {
result = dns_dbiterator_current(dbiter, &node, name);
check_dns_dbiterator_current(result);
verifynode(name, node, ISC_FALSE, &rdataset,
verifynode(name, node, ISC_FALSE, &keyset,
ksk_algorithms, bad_algorithms);
dns_db_detachnode(gdb, &node);
}
dns_dbiterator_destroy(&dbiter);
dns_rdataset_disassociate(&rdataset);
dns_rdataset_disassociate(&keyset);
/*
* If we made it this far, we have what we consider a properly signed
@@ -1990,6 +2023,46 @@ add_ds(dns_name_t *name, dns_dbnode_t *node, isc_uint32_t nsttl) {
}
}
/*
* Remove records of the given type and their signatures.
*/
static void
remove_records(dns_dbnode_t *node, dns_rdatatype_t which) {
isc_result_t result;
dns_rdatatype_t type, covers;
dns_rdatasetiter_t *rdsiter = NULL;
dns_rdataset_t rdataset;
dns_rdataset_init(&rdataset);
/*
* Delete any records of the given type at the apex.
*/
result = dns_db_allrdatasets(gdb, node, gversion, 0, &rdsiter);
check_result(result, "dns_db_allrdatasets()");
for (result = dns_rdatasetiter_first(rdsiter);
result == ISC_R_SUCCESS;
result = dns_rdatasetiter_next(rdsiter)) {
dns_rdatasetiter_current(rdsiter, &rdataset);
type = rdataset.type;
covers = rdataset.covers;
dns_rdataset_disassociate(&rdataset);
if (type == which || covers == which) {
if (which == dns_rdatatype_nsec && !update_chain)
fatal("Zone contains NSEC records. Use -u "
"to update to NSEC3.");
if (which == dns_rdatatype_nsec3param && !update_chain)
fatal("Zone contains NSEC3 chains. Use -u "
"to update to NSEC.");
result = dns_db_deleterdataset(gdb, node, gversion,
type, covers);
check_result(result, "dns_db_deleterdataset()");
continue;
}
}
dns_rdatasetiter_destroy(&rdsiter);
}
/*%
* Generate NSEC records for the zone and remove NSEC3/NSEC3PARAM records.
*/
@@ -2049,36 +2122,25 @@ nsecify(void) {
result = dns_dbiterator_first(dbiter);
check_result(result, "dns_dbiterator_first()");
result = dns_dbiterator_current(dbiter, &node, name);
check_dns_dbiterator_current(result);
/*
* Delete any NSEC3PARAM records at the apex.
*/
result = dns_db_allrdatasets(gdb, node, gversion, 0, &rdsiter);
check_result(result, "dns_db_allrdatasets()");
for (result = dns_rdatasetiter_first(rdsiter);
result == ISC_R_SUCCESS;
result = dns_rdatasetiter_next(rdsiter)) {
dns_rdatasetiter_current(rdsiter, &rdataset);
type = rdataset.type;
covers = rdataset.covers;
dns_rdataset_disassociate(&rdataset);
if (type == dns_rdatatype_nsec3param ||
covers == dns_rdatatype_nsec3param) {
result = dns_db_deleterdataset(gdb, node, gversion,
type, covers);
check_result(result,
"dns_db_deleterdataset(nsec3param/rrsig)");
continue;
}
}
dns_rdatasetiter_destroy(&rdsiter);
dns_db_detachnode(gdb, &node);
while (!done) {
result = dns_dbiterator_current(dbiter, &node, name);
check_dns_dbiterator_current(result);
/*
* Skip out-of-zone records.
*/
if (!dns_name_issubdomain(name, gorigin)) {
result = dns_dbiterator_next(dbiter);
if (result == ISC_R_NOMORE)
done = ISC_TRUE;
else
check_result(result, "dns_dbiterator_next()");
dns_db_detachnode(gdb, &node);
continue;
}
if (dns_name_equal(name, gorigin))
remove_records(node, dns_rdatatype_nsec3param);
if (delegation(name, node, &nsttl)) {
zonecut = dns_fixedname_name(&fzonecut);
dns_name_copy(name, zonecut, NULL);
@@ -2154,6 +2216,7 @@ addnsec3param(const unsigned char *salt, size_t salt_length,
result = dns_rdata_fromstruct(&rdata, gclass,
dns_rdatatype_nsec3param,
&nsec3param, &b);
check_result(result, "dns_rdata_fromstruct()");
rdatalist.rdclass = rdata.rdclass;
rdatalist.type = rdata.type;
rdatalist.covers = 0;
@@ -2451,8 +2514,6 @@ nsec3ify(unsigned int hashalg, unsigned int iterations,
dns_fixedname_t fname, fnextname, fzonecut;
dns_name_t *name, *nextname, *zonecut;
dns_rdataset_t rdataset;
dns_rdatasetiter_t *rdsiter = NULL;
dns_rdatatype_t type, covers;
int order;
isc_boolean_t active;
isc_boolean_t done = ISC_FALSE;
@@ -2477,40 +2538,25 @@ nsec3ify(unsigned int hashalg, unsigned int iterations,
result = dns_dbiterator_first(dbiter);
check_result(result, "dns_dbiterator_first()");
result = dns_dbiterator_current(dbiter, &node, name);
check_dns_dbiterator_current(result);
/*
* Delete any NSEC records at the apex.
*/
result = dns_db_allrdatasets(gdb, node, gversion, 0, &rdsiter);
check_result(result, "dns_db_allrdatasets()");
for (result = dns_rdatasetiter_first(rdsiter);
result == ISC_R_SUCCESS;
result = dns_rdatasetiter_next(rdsiter)) {
dns_rdatasetiter_current(rdsiter, &rdataset);
type = rdataset.type;
covers = rdataset.covers;
dns_rdataset_disassociate(&rdataset);
if (type == dns_rdatatype_nsec ||
covers == dns_rdatatype_nsec) {
if (!update_chain)
fatal("Zone contains NSEC records. Use -u "
"to update to NSEC3.");
result = dns_db_deleterdataset(gdb, node, gversion,
type, covers);
check_result(result,
"dns_db_deleterdataset(nsec3param/rrsig)");
continue;
}
}
dns_rdatasetiter_destroy(&rdsiter);
dns_db_detachnode(gdb, &node);
while (!done) {
result = dns_dbiterator_current(dbiter, &node, name);
check_dns_dbiterator_current(result);
/*
* Skip out-of-zone records.
*/
if (!dns_name_issubdomain(name, gorigin)) {
result = dns_dbiterator_next(dbiter);
if (result == ISC_R_NOMORE)
done = ISC_TRUE;
else
check_result(result, "dns_dbiterator_next()");
dns_db_detachnode(gdb, &node);
continue;
}
if (dns_name_equal(name, gorigin))
remove_records(node, dns_rdatatype_nsec);
result = dns_dbiterator_next(dbiter);
nextnode = NULL;
while (result == ISC_R_SUCCESS) {
@@ -2627,6 +2673,18 @@ nsec3ify(unsigned int hashalg, unsigned int iterations,
while (!done) {
result = dns_dbiterator_current(dbiter, &node, name);
check_dns_dbiterator_current(result);
/*
* Skip out-of-zone records.
*/
if (!dns_name_issubdomain(name, gorigin)) {
result = dns_dbiterator_next(dbiter);
if (result == ISC_R_NOMORE)
done = ISC_TRUE;
else
check_result(result, "dns_dbiterator_next()");
dns_db_detachnode(gdb, &node);
continue;
}
result = dns_dbiterator_next(dbiter);
nextnode = NULL;
while (result == ISC_R_SUCCESS) {
@@ -2768,7 +2826,7 @@ loadzonekeys(isc_boolean_t preserve_keys, isc_boolean_t load_public) {
}
keyttl = rdataset.ttl;
/* Load keys corresponding to the existing DNSKEY RRset */
/* Load keys corresponding to the existing DNSKEY RRset. */
result = dns_dnssec_keylistfromrdataset(gorigin, directory, mctx,
&rdataset, &keysigs, &soasigs,
preserve_keys, load_public,
@@ -3287,28 +3345,36 @@ removetempfile(void) {
}
static void
print_stats(isc_time_t *timer_start, isc_time_t *timer_finish) {
isc_uint64_t runtime_us; /* Runtime in microseconds */
isc_uint64_t runtime_ms; /* Runtime in milliseconds */
print_stats(isc_time_t *timer_start, isc_time_t *timer_finish,
isc_time_t *sign_start, isc_time_t *sign_finish)
{
isc_uint64_t time_us; /* Time in microseconds */
isc_uint64_t time_ms; /* Time in milliseconds */
isc_uint64_t sig_ms; /* Signatures per millisecond */
runtime_us = isc_time_microdiff(timer_finish, timer_start);
printf("Signatures generated: %10d\n", nsigned);
printf("Signatures retained: %10d\n", nretained);
printf("Signatures dropped: %10d\n", ndropped);
printf("Signatures successfully verified: %10d\n", nverified);
printf("Signatures unsuccessfully verified: %10d\n", nverifyfailed);
runtime_ms = runtime_us / 1000;
printf("Runtime in seconds: %7u.%03u\n",
(unsigned int) (runtime_ms / 1000),
(unsigned int) (runtime_ms % 1000));
if (runtime_us > 0) {
sig_ms = ((isc_uint64_t)nsigned * 1000000000) / runtime_us;
time_us = isc_time_microdiff(sign_finish, sign_start);
time_ms = time_us / 1000;
printf("Signing time in seconds: %7u.%03u\n",
(unsigned int) (time_ms / 1000),
(unsigned int) (time_ms % 1000));
if (time_us > 0) {
sig_ms = ((isc_uint64_t)nsigned * 1000000000) / time_us;
printf("Signatures per second: %7u.%03u\n",
(unsigned int) sig_ms / 1000,
(unsigned int) sig_ms % 1000);
}
time_us = isc_time_microdiff(timer_finish, timer_start);
time_ms = time_us / 1000;
printf("Runtime in seconds: %7u.%03u\n",
(unsigned int) (time_ms / 1000),
(unsigned int) (time_ms % 1000));
}
int
@@ -3322,6 +3388,7 @@ main(int argc, char *argv[]) {
int ndskeys = 0;
char *endp;
isc_time_t timer_start, timer_finish;
isc_time_t sign_start, sign_finish;
dns_dnsseckey_t *key;
isc_result_t result;
isc_log_t *log = NULL;
@@ -3772,6 +3839,8 @@ main(int argc, char *argv[]) {
nokeys = ISC_TRUE;
}
warnifallksk(gdb);
if (IS_NSEC3) {
unsigned int max;
result = dns_nsec3_maxiterations(gdb, NULL, mctx, &max);
@@ -3781,8 +3850,6 @@ main(int argc, char *argv[]) {
"strength. Maximum iterations allowed %u.", max);
}
warnifallksk(gdb);
gversion = NULL;
result = dns_db_newversion(gdb, &gversion);
check_result(result, "dns_db_newversion()");
@@ -3862,6 +3929,7 @@ main(int argc, char *argv[]) {
RUNTIME_CHECK(isc_mutex_init(&statslock) == ISC_R_SUCCESS);
presign();
TIME_NOW(&sign_start);
signapex();
if (!finished) {
/*
@@ -3886,6 +3954,7 @@ main(int argc, char *argv[]) {
isc_taskmgr_destroy(&taskmgr);
isc_mem_put(mctx, tasks, ntasks * sizeof(isc_task_t *));
postsign();
TIME_NOW(&sign_finish);
verifyzone();
if (outputformat != dns_masterformat_text) {
@@ -3939,7 +4008,8 @@ main(int argc, char *argv[]) {
if (printstats) {
TIME_NOW(&timer_finish);
print_stats(&timer_start, &timer_finish);
print_stats(&timer_start, &timer_finish,
&sign_start, &sign_finish);
}
return (0);
+6 -6
View File
@@ -14,7 +14,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: dnssec-signzone.html,v 1.45 2009/12/04 01:13:44 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -32,7 +32,7 @@
<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-p</code>] [<code class="option">-P</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S</code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-t</code>] [<code class="option">-u</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-x</code>] [<code class="option">-z</code>] [<code class="option">-3 <em class="replaceable"><code>salt</code></em></code>] [<code class="option">-H <em class="replaceable"><code>iterations</code></em></code>] [<code class="option">-A</code>] {zonefile} [key...]</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543596"></a><h2>DESCRIPTION</h2>
<a name="id2543597"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">dnssec-signzone</strong></span>
signs a zone. It generates
NSEC and RRSIG records and produces a signed version of the
@@ -43,7 +43,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543611"></a><h2>OPTIONS</h2>
<a name="id2543612"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-a</span></dt>
<dd><p>
@@ -379,7 +379,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2544896"></a><h2>EXAMPLE</h2>
<a name="id2544965"></a><h2>EXAMPLE</h2>
<p>
The following command signs the <strong class="userinput"><code>example.com</code></strong>
zone with the DSA key generated by <span><strong class="command">dnssec-keygen</strong></span>
@@ -409,14 +409,14 @@ db.example.com.signed
%</pre>
</div>
<div class="refsect1" lang="en">
<a name="id2545019"></a><h2>SEE ALSO</h2>
<a name="id2545020"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
<em class="citetitle">RFC 4033</em>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2545044"></a><h2>AUTHOR</h2>
<a name="id2545045"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
+15 -10
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2005, 2007, 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2005, 2007, 2009-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2000, 2001, 2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dnssectool.c,v 1.58.36.2 2010/01/19 23:48:13 tbox Exp $ */
/* $Id: dnssectool.c,v 1.58.36.5 2011/10/21 03:56:55 marka Exp $ */
/*! \file */
@@ -406,19 +406,24 @@ set_keyversion(dst_key_t *key) {
}
isc_boolean_t
key_collision(isc_uint16_t id, dns_name_t *name, const char *dir,
dns_secalg_t alg, isc_mem_t *mctx, isc_boolean_t *exact)
key_collision(dst_key_t *dstkey, dns_name_t *name, const char *dir,
isc_mem_t *mctx, isc_boolean_t *exact)
{
isc_result_t result;
isc_boolean_t conflict = ISC_FALSE;
dns_dnsseckeylist_t matchkeys;
dns_dnsseckey_t *key = NULL;
isc_uint16_t oldid, diff;
isc_uint16_t bits = DNS_KEYFLAG_REVOKE; /* flag bits to look for */
isc_uint16_t id, oldid;
isc_uint32_t rid, roldid;
dns_secalg_t alg;
if (exact != NULL)
*exact = ISC_FALSE;
id = dst_key_id(dstkey);
rid = dst_key_rid(dstkey);
alg = dst_key_alg(dstkey);
ISC_LIST_INIT(matchkeys);
result = dns_dnssec_findmatchingkeys(name, dir, mctx, &matchkeys);
if (result == ISC_R_NOTFOUND)
@@ -430,10 +435,11 @@ key_collision(isc_uint16_t id, dns_name_t *name, const char *dir,
goto next;
oldid = dst_key_id(key->key);
diff = (oldid > id) ? (oldid - id) : (id - oldid);
if ((diff & ~bits) == 0) {
roldid = dst_key_rid(key->key);
if (oldid == rid || roldid == id || id == oldid) {
conflict = ISC_TRUE;
if (diff != 0) {
if (id != oldid) {
if (verbose > 1)
fprintf(stderr, "Key ID %d could "
"collide with %d\n",
@@ -461,4 +467,3 @@ key_collision(isc_uint16_t id, dns_name_t *name, const char *dir,
return (conflict);
}
+5 -4
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2007-2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2007-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2000, 2001, 2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: dnssectool.h,v 1.29.36.2 2010/01/19 23:48:13 tbox Exp $ */
/* $Id: dnssectool.h,v 1.29.36.4 2011/10/20 23:46:04 tbox Exp $ */
#ifndef DNSSECTOOL_H
#define DNSSECTOOL_H 1
@@ -78,6 +78,7 @@ void
set_keyversion(dst_key_t *key);
isc_boolean_t
key_collision(isc_uint16_t id, dns_name_t *name, const char *dir,
dns_secalg_t alg, isc_mem_t *mctx, isc_boolean_t *exact);
key_collision(dst_key_t *key, dns_name_t *name, const char *dir,
isc_mem_t *mctx, isc_boolean_t *exact);
#endif /* DNSSEC_DNSSECTOOL_H */
@@ -1,7 +1,4 @@
Makefile
.libs
*.la
*.lo
named
named-symtbl.c
lwresd
+7 -4
View File
@@ -1,4 +1,4 @@
# Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2004-2010, 2012 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 1998-2002 Internet Software Consortium.
#
# Permission to use, copy, modify, and/or distribute this software for any
@@ -13,7 +13,7 @@
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
# $Id: Makefile.in,v 1.109 2009/12/05 23:31:40 each Exp $
# $Id: Makefile.in,v 1.109.2.3 2010/11/18 23:22:45 marka Exp $
srcdir = @srcdir@
VPATH = @srcdir@
@@ -118,7 +118,7 @@ main.@O@: main.c
-DNS_LOCALSTATEDIR=\"${localstatedir}\" \
-DNS_SYSCONFDIR=\"${sysconfdir}\" -c ${srcdir}/main.c
bind.keys.h: ${top_srcdir}/bind.keys
bind.keys.h: ${top_srcdir}/bind.keys ${top_srcdir}/bind.keys
${PERL} ${srcdir}/bindkeys.pl < ${top_srcdir}/bind.keys > $@
config.@O@: config.c bind.keys.h
@@ -143,7 +143,10 @@ docclean manclean maintainer-clean::
rm -f ${MANOBJS}
clean distclean maintainer-clean::
rm -f ${TARGETS} ${OBJS} bind.keys.h
rm -f ${TARGETS} ${OBJS}
maintainer-clean::
rm -f bind.keys.h
bind9.xsl.h: bind9.xsl ${srcdir}/convertxsl.pl
${PERL} ${srcdir}/convertxsl.pl < ${srcdir}/bind9.xsl > bind9.xsl.h
+98 -8
View File
@@ -1,17 +1,107 @@
/*
* Generated by bindkeys.pl 1.3.104.2 2010/06/20 23:46:24 tbox Exp
* From
*/
#define TRUSTED_KEYS "\
/* $Id$ */\n\
# The bind.keys file is used to override built-in DNSSEC trust anchors\n\
# which are included as part of BIND 9. As of the current release (BIND\n\
# 9.7), the only trust anchor it sets is the one for the ISC DNSSEC\n\
# Lookaside Validation zone (\"dlv.isc.org\"). Trust anchors for any other\n\
# zones MUST be configured elsewhere; if they are configured here, they\n\
# will not be recognized or used by named.\n\
#\n\
# This file also contains a copy of the trust anchor for the DNS root zone\n\
# (\".\"). However, named does not use it; it is provided here for\n\
# informational purposes only. To switch on DNSSEC validation at the\n\
# root, the root key below can be copied into named.conf.\n\
#\n\
# The built-in DLV trust anchor in this file is used directly by named.\n\
# However, it is not activated unless specifically switched on. To use\n\
# the DLV key, set \"dnssec-lookaside auto;\" in the named.conf options.\n\
# Without this option being set, the key in this file is ignored.\n\
#\n\
# This file is NOT expected to be user-configured.\n\
#\n\
# These keys are current as of January 2011. If any key fails to\n\
# initialize correctly, it may have expired. In that event you should\n\
# replace this file with a current version. The latest version of\n\
# bind.keys can always be obtained from ISC at https://www.isc.org/bind-keys.\n\
\n\
trusted-keys {\n\
# NOTE: This key is current as of October 2009.\n\
# If it fails to initialize correctly, it may have expired;\n\
# see https://www.isc.org/solutions/dlv for a replacement.\n\
dlv.isc.org. 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2 brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+ 1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5 ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt TDN0YUuWrBNh\";\n\
# ISC DLV: See https://www.isc.org/solutions/dlv for details.\n\
# NOTE: This key is activated by setting \"dnssec-lookaside auto;\"\n\
# in named.conf.\n\
dlv.isc.org. 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2\n\
brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+\n\
1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5\n\
ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk\n\
Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM\n\
QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt\n\
TDN0YUuWrBNh\";\n\
\n\
# ROOT KEY: See https://data.iana.org/root-anchors/root-anchors.xml\n\
# for current trust anchor information.\n\
# NOTE: This key not active; to use it, copy it into a managed-keys\n\
# statement in named.conf\n\
. initial-key 257 3 8 \"AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF\n\
FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX\n\
bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD\n\
X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz\n\
W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS\n\
Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq\n\
QxA+Uk1ihz0=\";\n\
};\n\
"
#define MANAGED_KEYS "\
/* $Id$ */\n\
# The bind.keys file is used to override built-in DNSSEC trust anchors\n\
# which are included as part of BIND 9. As of the current release (BIND\n\
# 9.7), the only trust anchor it sets is the one for the ISC DNSSEC\n\
# Lookaside Validation zone (\"dlv.isc.org\"). Trust anchors for any other\n\
# zones MUST be configured elsewhere; if they are configured here, they\n\
# will not be recognized or used by named.\n\
#\n\
# This file also contains a copy of the trust anchor for the DNS root zone\n\
# (\".\"). However, named does not use it; it is provided here for\n\
# informational purposes only. To switch on DNSSEC validation at the\n\
# root, the root key below can be copied into named.conf.\n\
#\n\
# The built-in DLV trust anchor in this file is used directly by named.\n\
# However, it is not activated unless specifically switched on. To use\n\
# the DLV key, set \"dnssec-lookaside auto;\" in the named.conf options.\n\
# Without this option being set, the key in this file is ignored.\n\
#\n\
# This file is NOT expected to be user-configured.\n\
#\n\
# These keys are current as of January 2011. If any key fails to\n\
# initialize correctly, it may have expired. In that event you should\n\
# replace this file with a current version. The latest version of\n\
# bind.keys can always be obtained from ISC at https://www.isc.org/bind-keys.\n\
\n\
managed-keys {\n\
# NOTE: This key is current as of October 2009.\n\
# If it fails to initialize correctly, it may have expired;\n\
# see https://www.isc.org/solutions/dlv for a replacement.\n\
dlv.isc.org. initial-key 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2 brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+ 1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5 ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt TDN0YUuWrBNh\";\n\
# ISC DLV: See https://www.isc.org/solutions/dlv for details.\n\
# NOTE: This key is activated by setting \"dnssec-lookaside auto;\"\n\
# in named.conf.\n\
dlv.isc.org. initial-key 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2\n\
brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+\n\
1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5\n\
ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk\n\
Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM\n\
QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt\n\
TDN0YUuWrBNh\";\n\
\n\
# ROOT KEY: See https://data.iana.org/root-anchors/root-anchors.xml\n\
# for current trust anchor information.\n\
# NOTE: This key not active; to use it, copy it into a managed-keys\n\
# statement in named.conf\n\
. initial-key 257 3 8 \"AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF\n\
FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX\n\
bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD\n\
X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz\n\
W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS\n\
Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq\n\
QxA+Uk1ihz0=\";\n\
};\n\
"
+20 -2
View File
@@ -1,6 +1,6 @@
#!/usr/bin/env perl
#
# Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2009, 2010, 2012 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
@@ -14,19 +14,37 @@
# OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
# PERFORMANCE OF THIS SOFTWARE.
# $Id: bindkeys.pl,v 1.3 2009/09/01 07:14:25 each Exp $
# $Id: bindkeys.pl,v 1.3.104.2 2010/06/20 23:46:24 tbox Exp $
use strict;
use warnings;
my $rev = '$Id: bindkeys.pl,v 1.3.104.2 2010/06/20 23:46:24 tbox Exp $';
$rev =~ s/\$//g;
$rev =~ s/,v//g;
$rev =~ s/Id: //;
my $keys = "";
my $lines;
while (<>) {
chomp;
if (/\/\* .Id:.* \*\//) {
$keys = $_;
next;
}
s/\"/\\\"/g;
s/$/\\n\\/;
$lines .= $_ . "\n";
}
$keys =~ s/\$//g;
$keys =~ s/\/\* Id: //;
$keys =~ s/\*\/.*//;
$keys =~ s/,v//;
print "/*\n * Generated by $rev \n * From $keys\n */\n";
my $mkey = '#define MANAGED_KEYS "\\' . "\n" . $lines . "\"\n";
$lines =~ s/managed-keys/trusted-keys/;
+5 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2005, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2005, 2007, 2009, 2010, 2012 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2001-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: builtin.c,v 1.15 2009/03/01 02:45:38 each Exp $ */
/* $Id: builtin.c,v 1.15.154.5 2012/01/11 20:19:07 ckb Exp $ */
/*! \file
* \brief
@@ -127,13 +127,16 @@ do_authors_lookup(dns_sdblookup_t *lookup) {
const char **p;
static const char *authors[] = {
"Mark Andrews",
"Curtis Blackburn",
"James Brister",
"Ben Cottrell",
"Michael Graff",
"Andreas Gustafsson",
"Bob Halley",
"Evan Hunt",
"JINMEI Tatuya",
"David Lawrence",
"Scott Mann",
"Danny Mayer",
"Damien Neil",
"Matt Nelson",
+29 -11
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2012 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: client.c,v 1.266 2009/10/26 23:14:53 each Exp $ */
/* $Id: client.c,v 1.266.36.7 2012/01/31 23:46:14 tbox Exp $ */
#include <config.h>
@@ -633,6 +633,7 @@ ns_client_endrequest(ns_client_t *client) {
dns_message_puttemprdataset(client->message, &client->opt);
}
client->signer = NULL;
client->udpsize = 512;
client->extflags = 0;
client->ednsversion = -1;
@@ -933,6 +934,15 @@ ns_client_send(ns_client_t *client) {
render_opts = 0;
else
render_opts = DNS_MESSAGERENDER_OMITDNSSEC;
preferred_glue = 0;
if (client->view != NULL) {
if (client->view->preferred_glue == dns_rdatatype_a)
preferred_glue = DNS_MESSAGERENDER_PREFER_A;
else if (client->view->preferred_glue == dns_rdatatype_aaaa)
preferred_glue = DNS_MESSAGERENDER_PREFER_AAAA;
}
#ifdef ALLOW_FILTER_AAAA_ON_V4
/*
* filter-aaaa-on-v4 yes or break-dnssec option to suppress
@@ -941,17 +951,15 @@ ns_client_send(ns_client_t *client) {
* that we have both AAAA and A records,
* and that we either have no signatures that the client wants
* or we are supposed to break DNSSEC.
*
* Override preferred glue if necessary.
*/
if ((client->attributes & NS_CLIENTATTR_FILTER_AAAA) != 0)
if ((client->attributes & NS_CLIENTATTR_FILTER_AAAA) != 0) {
render_opts |= DNS_MESSAGERENDER_FILTER_AAAA;
#endif
preferred_glue = 0;
if (client->view != NULL) {
if (client->view->preferred_glue == dns_rdatatype_a)
if (preferred_glue == DNS_MESSAGERENDER_PREFER_AAAA)
preferred_glue = DNS_MESSAGERENDER_PREFER_A;
else if (client->view->preferred_glue == dns_rdatatype_aaaa)
preferred_glue = DNS_MESSAGERENDER_PREFER_AAAA;
}
#endif
/*
* XXXRTH The following doesn't deal with TCP buffer resizing.
@@ -1312,6 +1320,12 @@ ns_client_isself(dns_view_t *myview, dns_tsigkey_t *mykey,
UNUSED(arg);
/*
* ns_g_server->interfacemgr is task exclusive locked.
*/
if (ns_g_server->interfacemgr == NULL)
return (ISC_TRUE);
if (!ns_interfacemgr_listeningon(ns_g_server->interfacemgr, dstaddr))
return (ISC_FALSE);
@@ -1865,13 +1879,13 @@ client_request(isc_task_t *task, isc_event_t *event) {
client->view->recursionacl,
ISC_TRUE) == ISC_R_SUCCESS &&
ns_client_checkaclsilent(client, NULL,
client->view->queryacl,
client->view->cacheacl,
ISC_TRUE) == ISC_R_SUCCESS &&
ns_client_checkaclsilent(client, &client->destaddr,
client->view->recursiononacl,
ISC_TRUE) == ISC_R_SUCCESS &&
ns_client_checkaclsilent(client, &client->destaddr,
client->view->queryonacl,
client->view->cacheonacl,
ISC_TRUE) == ISC_R_SUCCESS)
ra = ISC_TRUE;
@@ -2093,12 +2107,16 @@ client_create(ns_clientmgr_t *manager, ns_client_t **clientp) {
client->next = NULL;
client->shutdown = NULL;
client->shutdown_arg = NULL;
client->signer = NULL;
dns_name_init(&client->signername, NULL);
client->mortal = ISC_FALSE;
client->tcpquota = NULL;
client->recursionquota = NULL;
client->interface = NULL;
client->peeraddr_valid = ISC_FALSE;
#ifdef ALLOW_FILTER_AAAA_ON_V4
client->filter_aaaa = dns_v4_aaaa_ok;
#endif
ISC_EVENT_INIT(&client->ctlevent, sizeof(client->ctlevent), 0, NULL,
NS_EVENT_CLIENTCONTROL, client_start, client, client,
NULL, NULL);
+6 -14
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2001-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: config.c,v 1.106 2009/12/04 21:09:32 marka Exp $ */
/* $Id: config.c,v 1.106.4.6 2010/08/11 18:19:54 each Exp $ */
/*! \file */
@@ -80,6 +80,7 @@ options {\n\
bindkeys-file \"" NS_SYSCONFDIR "/bind.keys\";\n\
port 53;\n\
recursing-file \"named.recursing\";\n\
secroots-file \"named.secroots\";\n\
"
#ifdef PATH_RANDOMDEV
"\
@@ -158,9 +159,11 @@ options {\n\
max-clients-per-query 100;\n\
zero-no-soa-ttl-cache no;\n\
nsec3-test-zone no;\n\
allow-new-zones no;\n\
"
#ifdef ALLOW_FILTER_AAAA_ON_V4
" filter-aaaa-on-v4 no;\n\
filter-aaaa { any; };\n\
"
#endif
@@ -216,6 +219,7 @@ options {\n\
view \"_bind\" chaos {\n\
recursion no;\n\
notify no;\n\
allow-new-zones no;\n\
\n\
zone \"version.bind\" chaos {\n\
type master;\n\
@@ -238,18 +242,6 @@ view \"_bind\" chaos {\n\
};\n\
};\n\
"
"#\n\
# The \"_meta\" view is for zones that are used to store internal\n\
# information for named, such as managed keys. The zones are defined\n\
# elsewhere.\n\
#\n\
view \"_meta\" in {\n\
recursion no;\n\
notify no;\n\
};\n\
"
"#\n\
# Default trusted key(s) for builtin DLV support\n\
# (used if \"dnssec-lookaside auto;\" is set and\n\
+16 -4
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2007, 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2001-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: control.c,v 1.36 2009/10/12 20:48:11 each Exp $ */
/* $Id: control.c,v 1.36.50.5 2010/12/03 22:04:49 each Exp $ */
/*! \file */
@@ -129,11 +129,16 @@ ns_control_docommand(isccc_sexpr_t *message, isc_buffer_t *text) {
* isc_app_shutdown below.
*/
#endif
/* Do not flush master files */
ns_server_flushonshutdown(ns_g_server, ISC_FALSE);
ns_os_shutdownmsg(command, text);
isc_app_shutdown();
result = ISC_R_SUCCESS;
} else if (command_compare(command, NS_COMMAND_STOP)) {
/*
* "stop" is the same as "halt" except it does
* flush master files.
*/
#ifdef HAVE_LIBSCF
if (ns_smf_got_instance == 1 && ns_smf_chroot == 1) {
result = ns_smf_add_message(text);
@@ -153,6 +158,8 @@ ns_control_docommand(isccc_sexpr_t *message, isc_buffer_t *text) {
} else if (command_compare(command, NS_COMMAND_DUMPDB)) {
ns_server_dumpdb(ns_g_server, command);
result = ISC_R_SUCCESS;
} else if (command_compare(command, NS_COMMAND_SECROOTS)) {
result = ns_server_dumpsecroots(ns_g_server, command);
} else if (command_compare(command, NS_COMMAND_TRACE)) {
result = ns_server_setdebuglevel(ns_g_server, command);
} else if (command_compare(command, NS_COMMAND_NOTRACE)) {
@@ -187,8 +194,13 @@ ns_control_docommand(isccc_sexpr_t *message, isc_buffer_t *text) {
result = ns_server_notifycommand(ns_g_server, command, text);
} else if (command_compare(command, NS_COMMAND_VALIDATION)) {
result = ns_server_validation(ns_g_server, command);
} else if (command_compare(command, NS_COMMAND_SIGN)) {
result = ns_server_sign(ns_g_server, command);
} else if (command_compare(command, NS_COMMAND_SIGN) ||
command_compare(command, NS_COMMAND_LOADKEYS)) {
result = ns_server_rekey(ns_g_server, command);
} else if (command_compare(command, NS_COMMAND_ADDZONE)) {
result = ns_server_add_zone(ns_g_server, command);
} else if (command_compare(command, NS_COMMAND_DELZONE)) {
result = ns_server_del_zone(ns_g_server, command);
} else {
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL,
NS_LOGMODULE_CONTROL, ISC_LOG_WARNING,
+9 -11
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2008, 2011, 2012 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2001-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: controlconf.c,v 1.60 2008/07/23 23:27:54 marka Exp $ */
/* $Id: controlconf.c,v 1.60.290.3 2011/12/22 08:11:09 marka Exp $ */
/*! \file */
@@ -373,14 +373,7 @@ control_recvmessage(isc_task_t *task, isc_event_t *event) {
if (result == ISC_R_SUCCESS)
break;
isc_mem_put(listener->mctx, secret.rstart, REGION_SIZE(secret));
if (result == ISCCC_R_BADAUTH) {
/*
* For some reason, request is non-NULL when
* isccc_cc_fromwire returns ISCCC_R_BADAUTH.
*/
if (request != NULL)
isccc_sexpr_free(&request);
} else {
if (result != ISCCC_R_BADAUTH) {
log_invalid(&conn->ccmsg, result);
goto cleanup;
}
@@ -859,7 +852,7 @@ get_rndckey(isc_mem_t *mctx, controlkeylist_t *keyids) {
cfg_obj_log(key, ns_g_lctx, ISC_LOG_WARNING,
"secret for key '%s' on command channel: %s",
keyid->keyname, isc_result_totext(result));
CHECK(result);
goto cleanup;
}
keyid->secret.length = isc_buffer_usedlength(&b);
@@ -1148,6 +1141,11 @@ add_listener(ns_controls_t *cp, controllistener_t **listenerp,
if (result == ISC_R_SUCCESS)
isc_socket_setname(listener->sock, "control", NULL);
#ifndef ISC_ALLOW_MAPPED
if (result == ISC_R_SUCCESS)
isc_socket_ipv6only(listener->sock, ISC_TRUE);
#endif
if (result == ISC_R_SUCCESS)
result = isc_socket_bind(listener->sock, &listener->address,
ISC_SOCKET_REUSEADDRESS);
+1 -1
View File
@@ -1,6 +1,6 @@
#!/usr/bin/env perl
#
# Copyright (C) 2006-2008 Internet Systems Consortium, Inc. ("ISC")
# Copyright (C) 2006-2008, 2012 Internet Systems Consortium, Inc. ("ISC")
#
# Permission to use, copy, modify, and/or distribute this software for any
# purpose with or without fee is hereby granted, provided that the above
+5 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2009, 2012 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: client.h,v 1.91 2009/10/26 23:14:53 each Exp $ */
/* $Id: client.h,v 1.91.36.2 2012/01/31 23:46:15 tbox Exp $ */
#ifndef NAMED_CLIENT_H
#define NAMED_CLIENT_H 1
@@ -141,6 +141,9 @@ struct ns_client {
isc_netaddr_t destaddr;
struct in6_pktinfo pktinfo;
isc_event_t ctlevent;
#ifdef ALLOW_FILTER_AAAA_ON_V4
dns_v4_aaaa_t filter_aaaa;
#endif
/*%
* Information about recent FORMERR response(s), for
* FORMERR loop avoidance. This is separate for each
+6 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2007, 2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2007, 2009, 2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2001-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: control.h,v 1.27 2009/10/12 23:48:01 tbox Exp $ */
/* $Id: control.h,v 1.27.50.4 2010/08/16 22:27:16 marka Exp $ */
#ifndef NAMED_CONTROL_H
#define NAMED_CONTROL_H 1
@@ -42,6 +42,7 @@
#define NS_COMMAND_DUMPSTATS "stats"
#define NS_COMMAND_QUERYLOG "querylog"
#define NS_COMMAND_DUMPDB "dumpdb"
#define NS_COMMAND_SECROOTS "secroots"
#define NS_COMMAND_TRACE "trace"
#define NS_COMMAND_NOTRACE "notrace"
#define NS_COMMAND_FLUSH "flush"
@@ -58,6 +59,9 @@
#define NS_COMMAND_NOTIFY "notify"
#define NS_COMMAND_VALIDATION "validation"
#define NS_COMMAND_SIGN "sign"
#define NS_COMMAND_LOADKEYS "loadkeys"
#define NS_COMMAND_ADDZONE "addzone"
#define NS_COMMAND_DELZONE "delzone"
isc_result_t
ns_controls_create(ns_server_t *server, ns_controls_t **ctrlsp);
+6 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: globals.h,v 1.86 2009/10/05 17:30:49 fdupont Exp $ */
/* $Id: globals.h,v 1.86.60.5 2011/09/05 23:45:31 tbox Exp $ */
#ifndef NAMED_GLOBALS_H
#define NAMED_GLOBALS_H 1
@@ -26,6 +26,7 @@
#include <isc/log.h>
#include <isc/net.h>
#include <isccfg/aclconf.h>
#include <isccfg/cfg.h>
#include <dns/zone.h>
@@ -102,6 +103,7 @@ EXTERN const char * lwresd_g_resolvconffile INIT("/etc"
EXTERN isc_boolean_t ns_g_conffileset INIT(ISC_FALSE);
EXTERN isc_boolean_t lwresd_g_useresolvconf INIT(ISC_FALSE);
EXTERN isc_uint16_t ns_g_udpsize INIT(4096);
EXTERN cfg_aclconfctx_t * ns_g_aclconfctx INIT(NULL);
/*
* Initial resource limits.
@@ -149,6 +151,8 @@ EXTERN int ns_g_listen INIT(3);
EXTERN isc_time_t ns_g_boottime;
EXTERN isc_boolean_t ns_g_memstatistics INIT(ISC_FALSE);
EXTERN isc_boolean_t ns_g_clienttest INIT(ISC_FALSE);
EXTERN isc_boolean_t ns_g_nosoa INIT(ISC_FALSE);
EXTERN isc_boolean_t ns_g_noaa INIT(ISC_FALSE);
#undef EXTERN
#undef INIT
+4 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004, 2005, 2007 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004, 2005, 2007, 2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2002 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: query.h,v 1.40 2007/06/19 23:46:59 tbox Exp $ */
/* $Id: query.h,v 1.40.558.2 2010/09/24 08:30:58 tbox Exp $ */
#ifndef NAMED_QUERY_H
#define NAMED_QUERY_H 1
@@ -71,6 +71,8 @@ struct ns_query {
#define NS_QUERYATTR_SECURE 0x0200
#define NS_QUERYATTR_NOAUTHORITY 0x0400
#define NS_QUERYATTR_NOADDITIONAL 0x0800
#define NS_QUERYATTR_CACHEACLOKVALID 0x1000
#define NS_QUERYATTR_CACHEACLOK 0x2000
isc_result_t
ns_query_init(ns_client_t *client);
+27 -7
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: server.h,v 1.104 2009/11/28 15:57:37 vjs Exp $ */
/* $Id: server.h,v 1.104.8.6 2010/08/16 23:46:30 tbox Exp $ */
#ifndef NAMED_SERVER_H
#define NAMED_SERVER_H 1
@@ -54,9 +54,8 @@ struct ns_server {
dns_acl_t *blackholeacl;
char * statsfile; /*%< Statistics file name */
char * dumpfile; /*%< Dump file name */
char * secrootsfile; /*%< Secroots file name */
char * bindkeysfile; /*%< bind.keys file name */
isc_boolean_t managedkeys; /*%< A managed-keys
statement exists */
char * recfile; /*%< Recursive file name */
isc_boolean_t version_set; /*%< User has set version */
char * version; /*%< User-specified version */
@@ -246,6 +245,12 @@ ns_server_dumpstats(ns_server_t *server);
isc_result_t
ns_server_dumpdb(ns_server_t *server, char *args);
/*%
* Dump the current security roots to the secroots file.
*/
isc_result_t
ns_server_dumpsecroots(ns_server_t *server, char *args);
/*%
* Change or increment the server debug level.
*/
@@ -290,11 +295,14 @@ ns_server_freeze(ns_server_t *server, isc_boolean_t freeze, char *args,
isc_buffer_t *text);
/*%
* Update a zone's DNSKEY set from the key repository, and re-sign the
* zone if there were any changes.
* Update a zone's DNSKEY set from the key repository. If
* the command that triggered the call to this function was "sign",
* then force a full signing of the zone. If it was "loadkeys",
* then don't sign the zone; any needed changes to signatures can
* take place incrementally.
*/
isc_result_t
ns_server_sign(ns_server_t *server, char *args);
ns_server_rekey(ns_server_t *server, char *args);
/*%
* Dump the current recursive queries.
@@ -314,4 +322,16 @@ ns_add_reserved_dispatch(ns_server_t *server, const isc_sockaddr_t *addr);
isc_result_t
ns_server_validation(ns_server_t *server, char *args);
/*%
* Add a zone to a running process
*/
isc_result_t
ns_server_add_zone(ns_server_t *server, char *args);
/*%
* Deletes a zone from a running process
*/
isc_result_t
ns_server_del_zone(ns_server_t *server, char *args);
#endif /* NAMED_SERVER_H */
+3 -4
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2009, 2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2002 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: interfacemgr.c,v 1.95 2009/01/17 23:47:42 tbox Exp $ */
/* $Id: interfacemgr.c,v 1.95.186.2 2011/03/12 04:58:24 tbox Exp $ */
/*! \file */
@@ -379,7 +379,7 @@ ns_interface_setup(ns_interfacemgr_t *mgr, isc_sockaddr_t *addr,
}
}
*ifpret = ifp;
return (ISC_R_SUCCESS);
return (result);
cleanup_interface:
ISC_LIST_UNLINK(ifp->mgr->interfaces, ifp, link);
@@ -964,7 +964,6 @@ isc_boolean_t
ns_interfacemgr_listeningon(ns_interfacemgr_t *mgr, isc_sockaddr_t *addr) {
isc_sockaddr_t *old;
old = ISC_LIST_HEAD(mgr->listenon);
for (old = ISC_LIST_HEAD(mgr->listenon);
old != NULL;
old = ISC_LIST_NEXT(old, link))
+35 -22
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2007, 2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2001 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,12 +15,13 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: logconf.c,v 1.42 2007/06/19 23:46:59 tbox Exp $ */
/* $Id: logconf.c,v 1.42.560.3 2011/03/05 23:51:37 tbox Exp $ */
/*! \file */
#include <config.h>
#include <isc/file.h>
#include <isc/offset.h>
#include <isc/result.h>
#include <isc/stdio.h>
@@ -130,7 +131,7 @@ channel_fromconf(const cfg_obj_t *channel, isc_logconfig_t *lctx) {
}
type = ISC_LOG_TONULL;
if (fileobj != NULL) {
const cfg_obj_t *pathobj = cfg_tuple_get(fileobj, "file");
const cfg_obj_t *sizeobj = cfg_tuple_get(fileobj, "size");
@@ -140,7 +141,7 @@ channel_fromconf(const cfg_obj_t *channel, isc_logconfig_t *lctx) {
isc_offset_t size = 0;
type = ISC_LOG_TOFILE;
if (versionsobj != NULL && cfg_obj_isuint32(versionsobj))
versions = cfg_obj_asuint32(versionsobj);
if (versionsobj != NULL && cfg_obj_isstring(versionsobj) &&
@@ -219,26 +220,38 @@ channel_fromconf(const cfg_obj_t *channel, isc_logconfig_t *lctx) {
if (result == ISC_R_SUCCESS && type == ISC_LOG_TOFILE) {
FILE *fp;
/*
* Test that the file can be opened, since isc_log_open()
* can't effectively report failures when called in
* isc_log_doit().
*/
result = isc_stdio_open(dest.file.name, "a", &fp);
if (result != ISC_R_SUCCESS)
isc_log_write(ns_g_lctx, CFG_LOGCATEGORY_CONFIG,
NS_LOGMODULE_SERVER, ISC_LOG_ERROR,
"logging channel '%s' file '%s': %s",
channelname, dest.file.name,
isc_result_totext(result));
else
(void)isc_stdio_close(fp);
/*
* Allow named to continue by returning success.
*/
result = ISC_R_SUCCESS;
* Test to make sure that file is a plain file.
* Fix defect #22771
*/
result = isc_file_isplainfile(dest.file.name);
if (result == ISC_R_SUCCESS ||
result == ISC_R_FILENOTFOUND) {
/*
* Test that the file can be opened, since
* isc_log_open() can't effectively report
* failures when called in
* isc_log_doit().
*/
result = isc_stdio_open(dest.file.name, "a", &fp);
if (result != ISC_R_SUCCESS) {
syslog(LOG_ERR,
"isc_stdio_open '%s' failed: %s",
dest.file.name,
isc_result_totext(result));
fprintf(stderr,
"isc_stdio_open '%s' failed: %s",
dest.file.name,
isc_result_totext(result));
} else
(void)isc_stdio_close(fp);
} else {
syslog(LOG_ERR, "isc_file_isplainfile '%s' failed: %s",
dest.file.name, isc_result_totext(result));
fprintf(stderr, "isc_file_isplainfile '%s' failed: %s",
dest.file.name, isc_result_totext(result));
}
}
return (result);
+1 -1
View File
@@ -13,7 +13,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: lwresd.8,v 1.31 2009/07/11 01:12:45 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
+7 -7
View File
@@ -14,7 +14,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: lwresd.html,v 1.27 2009/07/11 01:12:45 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -22,7 +22,7 @@
<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
</head>
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
<a name="id2476275"></a><div class="titlepage"></div>
<a name="id2476274"></a><div class="titlepage"></div>
<div class="refnamediv">
<h2>Name</h2>
<p><span class="application">lwresd</span> &#8212; lightweight resolver daemon</p>
@@ -32,7 +32,7 @@
<div class="cmdsynopsis"><p><code class="command">lwresd</code> [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-C <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>debug-level</code></em></code>] [<code class="option">-f</code>] [<code class="option">-g</code>] [<code class="option">-i <em class="replaceable"><code>pid-file</code></em></code>] [<code class="option">-m <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-n <em class="replaceable"><code>#cpus</code></em></code>] [<code class="option">-P <em class="replaceable"><code>port</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-s</code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>] [<code class="option">-v</code>] [<code class="option">-4</code>] [<code class="option">-6</code>]</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543467"></a><h2>DESCRIPTION</h2>
<a name="id2543469"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">lwresd</strong></span>
is the daemon providing name lookup
services to clients that use the BIND 9 lightweight resolver
@@ -67,7 +67,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543514"></a><h2>OPTIONS</h2>
<a name="id2543516"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-4</span></dt>
<dd><p>
@@ -197,7 +197,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543931"></a><h2>FILES</h2>
<a name="id2543933"></a><h2>FILES</h2>
<div class="variablelist"><dl>
<dt><span class="term"><code class="filename">/etc/resolv.conf</code></span></dt>
<dd><p>
@@ -210,14 +210,14 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543971"></a><h2>SEE ALSO</h2>
<a name="id2543973"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">lwres</span>(3)</span>,
<span class="citerefentry"><span class="refentrytitle">resolver</span>(5)</span>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544005"></a><h2>AUTHOR</h2>
<a name="id2544007"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
+27 -3
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
* Copyright (C) 1999-2003 Internet Software Consortium.
*
* Permission to use, copy, modify, and/or distribute this software for any
@@ -15,7 +15,7 @@
* PERFORMANCE OF THIS SOFTWARE.
*/
/* $Id: main.c,v 1.175 2009/10/05 17:30:49 fdupont Exp $ */
/* $Id: main.c,v 1.175.60.7 2011/11/05 00:46:11 each Exp $ */
/*! \file */
@@ -500,13 +500,17 @@ parse_command_line(int argc, char *argv[]) {
/* XXXJAB should we make a copy? */
ns_g_chrootdir = isc_commandline_argument;
break;
case 'T':
case 'T': /* NOT DOCUMENTED */
/*
* clienttest: make clients single shot with their
* own memory context.
*/
if (!strcmp(isc_commandline_argument, "clienttest"))
ns_g_clienttest = ISC_TRUE;
else if (!strcmp(isc_commandline_argument, "nosoa"))
ns_g_nosoa = ISC_TRUE;
else if (!strcmp(isc_commandline_argument, "noaa"))
ns_g_noaa = ISC_TRUE;
else if (!strcmp(isc_commandline_argument, "maxudp512"))
maxudp = 512;
else if (!strcmp(isc_commandline_argument, "maxudp1460"))
@@ -542,6 +546,7 @@ parse_command_line(int argc, char *argv[]) {
argc -= isc_commandline_index;
argv += isc_commandline_index;
POST(argv);
if (argc > 0) {
usage();
@@ -772,6 +777,25 @@ setup(void) {
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
ISC_LOG_NOTICE, "built with %s", ns_g_configargs);
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
ISC_LOG_NOTICE,
"----------------------------------------------------");
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
ISC_LOG_NOTICE,
"BIND 9 is maintained by Internet Systems Consortium,");
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
ISC_LOG_NOTICE,
"Inc. (ISC), a non-profit 501(c)(3) public-benefit ");
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
ISC_LOG_NOTICE,
"corporation. Support and training for BIND 9 are ");
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
ISC_LOG_NOTICE,
"available at https://www.isc.org/support");
isc_log_write(ns_g_lctx, NS_LOGCATEGORY_GENERAL, NS_LOGMODULE_MAIN,
ISC_LOG_NOTICE,
"----------------------------------------------------");
dump_symboltable();
/*
+1 -1
View File
@@ -13,7 +13,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: named.8,v 1.41 2009/10/06 01:14:41 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
+6 -6
View File
@@ -1,4 +1,4 @@
.\" Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
.\" Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
.\"
.\" Permission to use, copy, modify, and/or distribute this software for any
.\" purpose with or without fee is hereby granted, provided that the above
@@ -12,7 +12,7 @@
.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: named.conf.5,v 1.41 2009/12/04 01:13:44 tbox Exp $
.\" $Id$
.\"
.hy 0
.ad l
@@ -252,8 +252,7 @@ options {
disable\-algorithms \fIstring\fR { \fIstring\fR; ... };
dnssec\-enable \fIboolean\fR;
dnssec\-validation \fIboolean\fR;
dnssec\-lookaside \fIstring\fR trust\-anchor \fIstring\fR;
dnssec\-lookaside ( \fIauto\fR | \fIdomain\fR trust\-anchor \fIdomain\fR );
dnssec\-lookaside ( \fIauto\fR | \fIno\fR | \fIdomain\fR trust\-anchor \fIdomain\fR );
dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR;
dnssec\-accept\-expired \fIboolean\fR;
empty\-server \fIstring\fR;
@@ -310,6 +309,7 @@ options {
use\-alt\-transfer\-source \fIboolean\fR;
zone\-statistics \fIboolean\fR;
key\-directory \fIquoted_string\fR;
managed\-keys\-directory \fIquoted_string\fR;
auto\-dnssec \fBallow\fR|\fBmaintain\fR|\fBcreate\fR|\fBoff\fR;
try\-tcp\-refresh \fIboolean\fR;
zero\-no\-soa\-ttl \fIboolean\fR;
@@ -410,7 +410,7 @@ view \fIstring\fR \fIoptional_class\fR {
disable\-algorithms \fIstring\fR { \fIstring\fR; ... };
dnssec\-enable \fIboolean\fR;
dnssec\-validation \fIboolean\fR;
dnssec\-lookaside \fIstring\fR trust\-anchor \fIstring\fR;
dnssec\-lookaside ( \fIauto\fR | \fIno\fR | \fIdomain\fR trust\-anchor \fIdomain\fR );
dnssec\-must\-be\-secure \fIstring\fR \fIboolean\fR;
dnssec\-accept\-expired \fIboolean\fR;
empty\-server \fIstring\fR;
@@ -569,5 +569,5 @@ zone \fIstring\fR \fIoptional_class\fR {
\fBrndc\fR(8),
BIND 9 Administrator Reference Manual.
.SH "COPYRIGHT"
Copyright \(co 2004\-2009 Internet Systems Consortium, Inc. ("ISC")
Copyright \(co 2004\-2011 Internet Systems Consortium, Inc. ("ISC")
.br
+7 -5
View File
@@ -2,7 +2,7 @@
"http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
[<!ENTITY mdash "&#8212;">]>
<!--
- Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
@@ -17,7 +17,7 @@
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: named.conf.docbook,v 1.44 2009/12/03 23:18:16 each Exp $ -->
<!-- $Id: named.conf.docbook,v 1.44.4.4 2011/11/07 23:46:02 tbox Exp $ -->
<refentry>
<refentryinfo>
<date>Aug 13, 2004</date>
@@ -42,6 +42,8 @@
<year>2007</year>
<year>2008</year>
<year>2009</year>
<year>2010</year>
<year>2011</year>
<holder>Internet Systems Consortium, Inc. ("ISC")</holder>
</copyright>
</docinfo>
@@ -281,8 +283,7 @@ options {
disable-algorithms <replaceable>string</replaceable> { <replaceable>string</replaceable>; ... };
dnssec-enable <replaceable>boolean</replaceable>;
dnssec-validation <replaceable>boolean</replaceable>;
dnssec-lookaside <replaceable>string</replaceable> trust-anchor <replaceable>string</replaceable>;
dnssec-lookaside ( <replaceable>auto</replaceable> | <replaceable>domain</replaceable> trust-anchor <replaceable>domain</replaceable> );
dnssec-lookaside ( <replaceable>auto</replaceable> | <replaceable>no</replaceable> | <replaceable>domain</replaceable> trust-anchor <replaceable>domain</replaceable> );
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
dnssec-accept-expired <replaceable>boolean</replaceable>;
@@ -349,6 +350,7 @@ options {
zone-statistics <replaceable>boolean</replaceable>;
key-directory <replaceable>quoted_string</replaceable>;
managed-keys-directory <replaceable>quoted_string</replaceable>;
auto-dnssec <constant>allow</constant>|<constant>maintain</constant>|<constant>create</constant>|<constant>off</constant>;
try-tcp-refresh <replaceable>boolean</replaceable>;
zero-no-soa-ttl <replaceable>boolean</replaceable>;
@@ -456,7 +458,7 @@ view <replaceable>string</replaceable> <replaceable>optional_class</replaceable>
disable-algorithms <replaceable>string</replaceable> { <replaceable>string</replaceable>; ... };
dnssec-enable <replaceable>boolean</replaceable>;
dnssec-validation <replaceable>boolean</replaceable>;
dnssec-lookaside <replaceable>string</replaceable> trust-anchor <replaceable>string</replaceable>;
dnssec-lookaside ( <replaceable>auto</replaceable> | <replaceable>no</replaceable> | <replaceable>domain</replaceable> trust-anchor <replaceable>domain</replaceable> );
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
dnssec-accept-expired <replaceable>boolean</replaceable>;
+20 -20
View File
@@ -1,5 +1,5 @@
<!--
- Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
- Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
-
- Permission to use, copy, modify, and/or distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
@@ -13,7 +13,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: named.conf.html,v 1.50 2009/12/04 01:13:44 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -31,7 +31,7 @@
<div class="cmdsynopsis"><p><code class="command">named.conf</code> </p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543346"></a><h2>DESCRIPTION</h2>
<a name="id2543353"></a><h2>DESCRIPTION</h2>
<p><code class="filename">named.conf</code> is the configuration file
for
<span><strong class="command">named</strong></span>. Statements are enclosed
@@ -50,14 +50,14 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543373"></a><h2>ACL</h2>
<a name="id2543381"></a><h2>ACL</h2>
<div class="literallayout"><p><br>
acl <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
<br>
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543389"></a><h2>KEY</h2>
<a name="id2543397"></a><h2>KEY</h2>
<div class="literallayout"><p><br>
key <em class="replaceable"><code>domain_name</code></em> {<br>
algorithm <em class="replaceable"><code>string</code></em>;<br>
@@ -66,7 +66,7 @@ key
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543409"></a><h2>MASTERS</h2>
<a name="id2543416"></a><h2>MASTERS</h2>
<div class="literallayout"><p><br>
masters <em class="replaceable"><code>string</code></em> [<span class="optional"> port <em class="replaceable"><code>integer</code></em> </span>] {<br>
( <em class="replaceable"><code>masters</code></em> | <em class="replaceable"><code>ipv4_address</code></em> [<span class="optional">port <em class="replaceable"><code>integer</code></em></span>] |<br>
@@ -75,7 +75,7 @@ masters
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543454"></a><h2>SERVER</h2>
<a name="id2543462"></a><h2>SERVER</h2>
<div class="literallayout"><p><br>
server ( <em class="replaceable"><code>ipv4_address[<span class="optional">/prefixlen</span>]</code></em> | <em class="replaceable"><code>ipv6_address[<span class="optional">/prefixlen</span>]</code></em> ) {<br>
bogus <em class="replaceable"><code>boolean</code></em>;<br>
@@ -97,7 +97,7 @@ server
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543523"></a><h2>TRUSTED-KEYS</h2>
<a name="id2543530"></a><h2>TRUSTED-KEYS</h2>
<div class="literallayout"><p><br>
trusted-keys {<br>
<em class="replaceable"><code>domain_name</code></em> <em class="replaceable"><code>flags</code></em> <em class="replaceable"><code>protocol</code></em> <em class="replaceable"><code>algorithm</code></em> <em class="replaceable"><code>key</code></em>; ... <br>
@@ -105,7 +105,7 @@ trusted-keys
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543548"></a><h2>MANAGED-KEYS</h2>
<a name="id2543556"></a><h2>MANAGED-KEYS</h2>
<div class="literallayout"><p><br>
managed-keys {<br>
<em class="replaceable"><code>domain_name</code></em> <code class="constant">initial-key</code> <em class="replaceable"><code>flags</code></em> <em class="replaceable"><code>protocol</code></em> <em class="replaceable"><code>algorithm</code></em> <em class="replaceable"><code>key</code></em>; ... <br>
@@ -113,7 +113,7 @@ managed-keys
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543577"></a><h2>CONTROLS</h2>
<a name="id2543585"></a><h2>CONTROLS</h2>
<div class="literallayout"><p><br>
controls {<br>
inet ( <em class="replaceable"><code>ipv4_address</code></em> | <em class="replaceable"><code>ipv6_address</code></em> | * )<br>
@@ -125,7 +125,7 @@ controls
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543612"></a><h2>LOGGING</h2>
<a name="id2543620"></a><h2>LOGGING</h2>
<div class="literallayout"><p><br>
logging {<br>
channel <em class="replaceable"><code>string</code></em> {<br>
@@ -143,7 +143,7 @@ logging
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543651"></a><h2>LWRES</h2>
<a name="id2543658"></a><h2>LWRES</h2>
<div class="literallayout"><p><br>
lwres {<br>
listen-on [<span class="optional"> port <em class="replaceable"><code>integer</code></em> </span>] {<br>
@@ -156,7 +156,7 @@ lwres
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543692"></a><h2>OPTIONS</h2>
<a name="id2543700"></a><h2>OPTIONS</h2>
<div class="literallayout"><p><br>
options {<br>
avoid-v4-udp-ports { <em class="replaceable"><code>port</code></em>; ... };<br>
@@ -249,8 +249,7 @@ options
disable-algorithms <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br>
dnssec-enable <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-validation <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-lookaside <em class="replaceable"><code>string</code></em> trust-anchor <em class="replaceable"><code>string</code></em>;<br>
dnssec-lookaside ( <em class="replaceable"><code>auto</code></em> | <em class="replaceable"><code>domain</code></em> trust-anchor <em class="replaceable"><code>domain</code></em> );<br>
dnssec-lookaside ( <em class="replaceable"><code>auto</code></em> | <em class="replaceable"><code>no</code></em> | <em class="replaceable"><code>domain</code></em> trust-anchor <em class="replaceable"><code>domain</code></em> );<br>
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
<br>
@@ -317,6 +316,7 @@ options
<br>
zone-statistics <em class="replaceable"><code>boolean</code></em>;<br>
key-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
managed-keys-directory <em class="replaceable"><code>quoted_string</code></em>;<br>
auto-dnssec <code class="constant">allow</code>|<code class="constant">maintain</code>|<code class="constant">create</code>|<code class="constant">off</code>;<br>
try-tcp-refresh <em class="replaceable"><code>boolean</code></em>;<br>
zero-no-soa-ttl <em class="replaceable"><code>boolean</code></em>;<br>
@@ -347,7 +347,7 @@ options
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2544532"></a><h2>VIEW</h2>
<a name="id2544539"></a><h2>VIEW</h2>
<div class="literallayout"><p><br>
view <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>optional_class</code></em> {<br>
match-clients { <em class="replaceable"><code>address_match_element</code></em>; ... };<br>
@@ -423,7 +423,7 @@ view
disable-algorithms <em class="replaceable"><code>string</code></em> { <em class="replaceable"><code>string</code></em>; ... };<br>
dnssec-enable <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-validation <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-lookaside <em class="replaceable"><code>string</code></em> trust-anchor <em class="replaceable"><code>string</code></em>;<br>
dnssec-lookaside ( <em class="replaceable"><code>auto</code></em> | <em class="replaceable"><code>no</code></em> | <em class="replaceable"><code>domain</code></em> trust-anchor <em class="replaceable"><code>domain</code></em> );<br>
dnssec-must-be-secure <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>boolean</code></em>;<br>
dnssec-accept-expired <em class="replaceable"><code>boolean</code></em>;<br>
<br>
@@ -498,7 +498,7 @@ view
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2545203"></a><h2>ZONE</h2>
<a name="id2545217"></a><h2>ZONE</h2>
<div class="literallayout"><p><br>
zone <em class="replaceable"><code>string</code></em> <em class="replaceable"><code>optional_class</code></em> {<br>
type ( master | slave | stub | hint |<br>
@@ -593,12 +593,12 @@ zone
</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2545514"></a><h2>FILES</h2>
<a name="id2545596"></a><h2>FILES</h2>
<p><code class="filename">/etc/named.conf</code>
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2545526"></a><h2>SEE ALSO</h2>
<a name="id2545608"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">named-checkconf</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">rndc</span>(8)</span>,
+8 -8
View File
@@ -14,7 +14,7 @@
- OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
- PERFORMANCE OF THIS SOFTWARE.
-->
<!-- $Id: named.html,v 1.33 2009/10/06 01:14:41 tbox Exp $ -->
<!-- $Id$ -->
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
@@ -32,7 +32,7 @@
<div class="cmdsynopsis"><p><code class="command">named</code> [<code class="option">-4</code>] [<code class="option">-6</code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>debug-level</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine-name</code></em></code>] [<code class="option">-f</code>] [<code class="option">-g</code>] [<code class="option">-m <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-n <em class="replaceable"><code>#cpus</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-s</code>] [<code class="option">-S <em class="replaceable"><code>#max-socks</code></em></code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>] [<code class="option">-v</code>] [<code class="option">-V</code>] [<code class="option">-x <em class="replaceable"><code>cache-file</code></em></code>]</p></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543480"></a><h2>DESCRIPTION</h2>
<a name="id2543482"></a><h2>DESCRIPTION</h2>
<p><span><strong class="command">named</strong></span>
is a Domain Name System (DNS) server,
part of the BIND 9 distribution from ISC. For more
@@ -47,7 +47,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2543505"></a><h2>OPTIONS</h2>
<a name="id2543507"></a><h2>OPTIONS</h2>
<div class="variablelist"><dl>
<dt><span class="term">-4</span></dt>
<dd><p>
@@ -228,7 +228,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2543962"></a><h2>SIGNALS</h2>
<a name="id2543964"></a><h2>SIGNALS</h2>
<p>
In routine operation, signals should not be used to control
the nameserver; <span><strong class="command">rndc</strong></span> should be used
@@ -249,7 +249,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544010"></a><h2>CONFIGURATION</h2>
<a name="id2544012"></a><h2>CONFIGURATION</h2>
<p>
The <span><strong class="command">named</strong></span> configuration file is too complex
to describe in detail here. A complete description is provided
@@ -266,7 +266,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544046"></a><h2>FILES</h2>
<a name="id2544049"></a><h2>FILES</h2>
<div class="variablelist"><dl>
<dt><span class="term"><code class="filename">/etc/named.conf</code></span></dt>
<dd><p>
@@ -279,7 +279,7 @@
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2544086"></a><h2>SEE ALSO</h2>
<a name="id2544088"></a><h2>SEE ALSO</h2>
<p><em class="citetitle">RFC 1033</em>,
<em class="citetitle">RFC 1034</em>,
<em class="citetitle">RFC 1035</em>,
@@ -292,7 +292,7 @@
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2544293"></a><h2>AUTHOR</h2>
<a name="id2544295"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>

Some files were not shown because too many files have changed in this diff Show More