Commit b65d19f9 authored by Tinderbox User's avatar Tinderbox User
Browse files

prep 9.13.2

parent fffc6712
Pipeline #2806 passed with stages
in 10 minutes and 6 seconds
--- 9.13.2 released ---
4987. [cleanup] dns_rdataslab_tordataset() and its related
dns_rdatasetmethods_t callbacks were removed as they
were not being used by anything in BIND. [GL #371]
 
4986. [func] When built on Linux, BIND now requires the libcap library
to set process privileges, unless capability support is
explicitly overridden with "configure --disable-linux-caps".
[GL #321]
4986. [func] When built on Linux, BIND now requires the libcap
library to set process privileges, unless capability
support is explicitly overridden with "configure
--disable-linux-caps". [GL #321]
 
4985. [func] Add a new slave zone option, "mirror", to enable
serving a non-authoritative copy of a zone that
......
......@@ -10,12 +10,12 @@
.\" Title: named.conf
.\" Author:
.\" Generator: DocBook XSL Stylesheets v1.78.1 <http://docbook.sf.net/>
.\" Date: 2018-01-22
.\" Date: 2018-05-29
.\" Manual: BIND9
.\" Source: ISC
.\" Language: English
.\"
.TH "NAMED\&.CONF" "5" "2018\-01\-22" "ISC" "BIND9"
.TH "NAMED\&.CONF" "5" "2018\-05\-29" "ISC" "BIND9"
.\" -----------------------------------------------------------------
.\" * Define some portability stuff
.\" -----------------------------------------------------------------
......@@ -212,7 +212,7 @@ options {
\fIinteger\fR ] [ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [
port \fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIinteger\fR ]; \&.\&.\&. };
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIttlval\fR ]; \&.\&.\&. };
check\-dup\-records ( fail | warn | ignore );
check\-integrity \fIboolean\fR;
check\-mx ( fail | warn | ignore );
......@@ -251,6 +251,7 @@ options {
};
dns64\-contact \fIstring\fR;
dns64\-server \fIstring\fR;
dnskey\-sig\-validity \fIinteger\fR;
dnsrps\-enable \fIboolean\fR;
dnsrps\-options { \fIunspecified\-text\fR };
dnssec\-accept\-expired \fIboolean\fR;
......@@ -299,14 +300,13 @@ options {
fstrm\-set\-output\-notify\-threshold \fIinteger\fR;
fstrm\-set\-output\-queue\-model ( mpsc | spsc );
fstrm\-set\-output\-queue\-size \fIinteger\fR;
fstrm\-set\-reopen\-interval \fIinteger\fR;
fstrm\-set\-reopen\-interval \fIttlval\fR;
geoip\-directory ( \fIquoted_string\fR | none );
geoip\-use\-ecs \fIboolean\fR;
glue\-cache \fIboolean\fR;
heartbeat\-interval \fIinteger\fR;
hostname ( \fIquoted_string\fR | none );
inline\-signing \fIboolean\fR;
interface\-interval \fIinteger\fR;
interface\-interval \fIttlval\fR;
ixfr\-from\-differences ( primary | master | secondary | slave |
\fIboolean\fR );
keep\-response\-order { \fIaddress_match_element\fR; \&.\&.\&. };
......@@ -325,10 +325,10 @@ options {
masterfile\-style ( full | relative );
match\-mapped\-addresses \fIboolean\fR;
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
max\-cache\-ttl \fIinteger\fR;
max\-cache\-ttl \fIttlval\fR;
max\-clients\-per\-query \fIinteger\fR;
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
max\-ncache\-ttl \fIinteger\fR;
max\-ncache\-ttl \fIttlval\fR;
max\-records \fIinteger\fR;
max\-recursion\-depth \fIinteger\fR;
max\-recursion\-queries \fIinteger\fR;
......@@ -369,6 +369,7 @@ options {
preferred\-glue \fIstring\fR;
prefetch \fIinteger\fR [ \fIinteger\fR ];
provide\-ixfr \fIboolean\fR;
qname\-minimization ( strict | relaxed | disabled );
query\-source ( ( [ address ] ( \fIipv4_address\fR | * ) [ port (
\fIinteger\fR | * ) ] ) | ( [ [ address ] ( \fIipv4_address\fR | * ) ]
port ( \fIinteger\fR | * ) ) ) [ dscp \fIinteger\fR ];
......@@ -408,18 +409,19 @@ options {
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
\fIinteger\fR;
response\-policy { zone \fIquoted_string\fR [ log \fIboolean\fR ] [
max\-policy\-ttl \fIinteger\fR ] [ min\-update\-interval \fIinteger\fR ] [
max\-policy\-ttl \fIttlval\fR ] [ min\-update\-interval \fIttlval\fR ] [
policy ( cname | disabled | drop | given | no\-op | nodata |
nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ break\-dnssec \fIboolean\fR ] [
max\-policy\-ttl \fIinteger\fR ] [ min\-update\-interval \fIinteger\fR ] [
max\-policy\-ttl \fIttlval\fR ] [ min\-update\-interval \fIttlval\fR ] [
min\-ns\-dots \fIinteger\fR ] [ nsip\-wait\-recurse \fIboolean\fR ] [
qname\-wait\-recurse \fIboolean\fR ] [ recursive\-only \fIboolean\fR ] [
nsip\-enable \fIboolean\fR ] [ nsdname\-enable \fIboolean\fR ] [
dnsrps\-enable \fIboolean\fR ] [ dnsrps\-options { \fIunspecified\-text\fR
} ];
root\-delegation\-only [ exclude { \fIquoted_string\fR; \&.\&.\&. } ];
root\-key\-sentinel \fIboolean\fR;
rrset\-order { [ class \fIstring\fR ] [ type \fIstring\fR ] [ name
\fIquoted_string\fR ] \fIstring\fR \fIstring\fR; \&.\&.\&. };
secroots\-file \fIquoted_string\fR;
......@@ -580,7 +582,7 @@ view \fIstring\fR [ \fIclass\fR ] {
\fIinteger\fR ] [ dscp \fIinteger\fR ] { ( \fImasters\fR | \fIipv4_address\fR [
port \fIinteger\fR ] | \fIipv6_address\fR [ port \fIinteger\fR ] ) [ key
\fIstring\fR ]; \&.\&.\&. } ] [ zone\-directory \fIquoted_string\fR ] [
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIinteger\fR ]; \&.\&.\&. };
in\-memory \fIboolean\fR ] [ min\-update\-interval \fIttlval\fR ]; \&.\&.\&. };
check\-dup\-records ( fail | warn | ignore );
check\-integrity \fIboolean\fR;
check\-mx ( fail | warn | ignore );
......@@ -618,6 +620,7 @@ view \fIstring\fR [ \fIclass\fR ] {
};
dns64\-contact \fIstring\fR;
dns64\-server \fIstring\fR;
dnskey\-sig\-validity \fIinteger\fR;
dnsrps\-enable \fIboolean\fR;
dnsrps\-options { \fIunspecified\-text\fR };
dnssec\-accept\-expired \fIboolean\fR;
......@@ -671,10 +674,10 @@ view \fIstring\fR [ \fIclass\fR ] {
match\-destinations { \fIaddress_match_element\fR; \&.\&.\&. };
match\-recursive\-only \fIboolean\fR;
max\-cache\-size ( default | unlimited | \fIsizeval\fR | \fIpercentage\fR );
max\-cache\-ttl \fIinteger\fR;
max\-cache\-ttl \fIttlval\fR;
max\-clients\-per\-query \fIinteger\fR;
max\-journal\-size ( default | unlimited | \fIsizeval\fR );
max\-ncache\-ttl \fIinteger\fR;
max\-ncache\-ttl \fIttlval\fR;
max\-records \fIinteger\fR;
max\-recursion\-depth \fIinteger\fR;
max\-recursion\-queries \fIinteger\fR;
......@@ -709,6 +712,7 @@ view \fIstring\fR [ \fIclass\fR ] {
preferred\-glue \fIstring\fR;
prefetch \fIinteger\fR [ \fIinteger\fR ];
provide\-ixfr \fIboolean\fR;
qname\-minimization ( strict | relaxed | disabled );
query\-source ( ( [ address ] ( \fIipv4_address\fR | * ) [ port (
\fIinteger\fR | * ) ] ) | ( [ [ address ] ( \fIipv4_address\fR | * ) ]
port ( \fIinteger\fR | * ) ) ) [ dscp \fIinteger\fR ];
......@@ -743,18 +747,19 @@ view \fIstring\fR [ \fIclass\fR ] {
response\-padding { \fIaddress_match_element\fR; \&.\&.\&. } block\-size
\fIinteger\fR;
response\-policy { zone \fIquoted_string\fR [ log \fIboolean\fR ] [
max\-policy\-ttl \fIinteger\fR ] [ min\-update\-interval \fIinteger\fR ] [
max\-policy\-ttl \fIttlval\fR ] [ min\-update\-interval \fIttlval\fR ] [
policy ( cname | disabled | drop | given | no\-op | nodata |
nxdomain | passthru | tcp\-only \fIquoted_string\fR ) ] [
recursive\-only \fIboolean\fR ] [ nsip\-enable \fIboolean\fR ] [
nsdname\-enable \fIboolean\fR ]; \&.\&.\&. } [ break\-dnssec \fIboolean\fR ] [
max\-policy\-ttl \fIinteger\fR ] [ min\-update\-interval \fIinteger\fR ] [
max\-policy\-ttl \fIttlval\fR ] [ min\-update\-interval \fIttlval\fR ] [
min\-ns\-dots \fIinteger\fR ] [ nsip\-wait\-recurse \fIboolean\fR ] [
qname\-wait\-recurse \fIboolean\fR ] [ recursive\-only \fIboolean\fR ] [
nsip\-enable \fIboolean\fR ] [ nsdname\-enable \fIboolean\fR ] [
dnsrps\-enable \fIboolean\fR ] [ dnsrps\-options { \fIunspecified\-text\fR
} ];
root\-delegation\-only [ exclude { \fIquoted_string\fR; \&.\&.\&. } ];
root\-key\-sentinel \fIboolean\fR;
rrset\-order { [ class \fIstring\fR ] [ type \fIstring\fR ] [ name
\fIquoted_string\fR ] \fIstring\fR \fIstring\fR; \&.\&.\&. };
send\-cookie \fIboolean\fR;
......@@ -847,6 +852,7 @@ view \fIstring\fR [ \fIclass\fR ] {
dialup ( notify | notify\-passive | passive | refresh |
\fIboolean\fR );
dlz \fIstring\fR;
dnskey\-sig\-validity \fIinteger\fR;
dnssec\-dnskey\-kskonly \fIboolean\fR;
dnssec\-loadkeys\-interval \fIinteger\fR;
dnssec\-secure\-to\-insecure \fIboolean\fR;
......@@ -878,6 +884,7 @@ view \fIstring\fR [ \fIclass\fR ] {
max\-zone\-ttl ( unlimited | \fIttlval\fR );
min\-refresh\-time \fIinteger\fR;
min\-retry\-time \fIinteger\fR;
mirror \fIboolean\fR;
multi\-master \fIboolean\fR;
notify ( explicit | master\-only | \fIboolean\fR );
notify\-delay \fIinteger\fR;
......@@ -957,6 +964,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
delegation\-only \fIboolean\fR;
dialup ( notify | notify\-passive | passive | refresh | \fIboolean\fR );
dlz \fIstring\fR;
dnskey\-sig\-validity \fIinteger\fR;
dnssec\-dnskey\-kskonly \fIboolean\fR;
dnssec\-loadkeys\-interval \fIinteger\fR;
dnssec\-secure\-to\-insecure \fIboolean\fR;
......@@ -986,6 +994,7 @@ zone \fIstring\fR [ \fIclass\fR ] {
max\-zone\-ttl ( unlimited | \fIttlval\fR );
min\-refresh\-time \fIinteger\fR;
min\-retry\-time \fIinteger\fR;
mirror \fIboolean\fR;
multi\-master \fIboolean\fR;
notify ( explicit | master\-only | \fIboolean\fR );
notify\-delay \fIinteger\fR;
......
......@@ -193,7 +193,7 @@ options
<em class="replaceable"><code>integer</code></em>][dscp<em class="replaceable"><code>integer</code></em>]{(<em class="replaceable"><code>masters</code></em>|<em class="replaceable"><code>ipv4_address</code></em>[<br>
port<em class="replaceable"><code>integer</code></em>]|<em class="replaceable"><code>ipv6_address</code></em>[port<em class="replaceable"><code>integer</code></em>])[key<br>
<em class="replaceable"><code>string</code></em>];...}][zone-directory<em class="replaceable"><code>quoted_string</code></em>][<br>
in-memory<em class="replaceable"><code>boolean</code></em>][min-update-interval<em class="replaceable"><code>integer</code></em>];...};<br>
in-memory<em class="replaceable"><code>boolean</code></em>][min-update-interval<em class="replaceable"><code>ttlval</code></em>];...};<br>
check-dup-records(fail|warn|ignore);<br>
check-integrity<em class="replaceable"><code>boolean</code></em>;<br>
check-mx(fail|warn|ignore);<br>
......@@ -232,6 +232,7 @@ options
};<br>
dns64-contact<em class="replaceable"><code>string</code></em>;<br>
dns64-server<em class="replaceable"><code>string</code></em>;<br>
dnskey-sig-validity<em class="replaceable"><code>integer</code></em>;<br>
dnsrps-enable<em class="replaceable"><code>boolean</code></em>;<br>
dnsrps-options{<em class="replaceable"><code>unspecified-text</code></em>};<br>
dnssec-accept-expired<em class="replaceable"><code>boolean</code></em>;<br>
......@@ -280,14 +281,13 @@ options
fstrm-set-output-notify-threshold<em class="replaceable"><code>integer</code></em>;<br>
fstrm-set-output-queue-model(mpsc|spsc);<br>
fstrm-set-output-queue-size<em class="replaceable"><code>integer</code></em>;<br>
fstrm-set-reopen-interval<em class="replaceable"><code>integer</code></em>;<br>
fstrm-set-reopen-interval<em class="replaceable"><code>ttlval</code></em>;<br>
geoip-directory(<em class="replaceable"><code>quoted_string</code></em>|none);<br>
geoip-use-ecs<em class="replaceable"><code>boolean</code></em>;<br>
glue-cache<em class="replaceable"><code>boolean</code></em>;<br>
heartbeat-interval<em class="replaceable"><code>integer</code></em>;<br>
hostname(<em class="replaceable"><code>quoted_string</code></em>|none);<br>
inline-signing<em class="replaceable"><code>boolean</code></em>;<br>
interface-interval<em class="replaceable"><code>integer</code></em>;<br>
interface-interval<em class="replaceable"><code>ttlval</code></em>;<br>
ixfr-from-differences(primary|master|secondary|slave|<br>
<em class="replaceable"><code>boolean</code></em>);<br>
keep-response-order{<em class="replaceable"><code>address_match_element</code></em>;...};<br>
......@@ -306,10 +306,10 @@ options
masterfile-style(full|relative);<br>
match-mapped-addresses<em class="replaceable"><code>boolean</code></em>;<br>
max-cache-size(default|unlimited|<em class="replaceable"><code>sizeval</code></em>|<em class="replaceable"><code>percentage</code></em>);<br>
max-cache-ttl<em class="replaceable"><code>integer</code></em>;<br>
max-cache-ttl<em class="replaceable"><code>ttlval</code></em>;<br>
max-clients-per-query<em class="replaceable"><code>integer</code></em>;<br>
max-journal-size(default|unlimited|<em class="replaceable"><code>sizeval</code></em>);<br>
max-ncache-ttl<em class="replaceable"><code>integer</code></em>;<br>
max-ncache-ttl<em class="replaceable"><code>ttlval</code></em>;<br>
max-records<em class="replaceable"><code>integer</code></em>;<br>
max-recursion-depth<em class="replaceable"><code>integer</code></em>;<br>
max-recursion-queries<em class="replaceable"><code>integer</code></em>;<br>
......@@ -350,6 +350,7 @@ options
preferred-glue<em class="replaceable"><code>string</code></em>;<br>
prefetch<em class="replaceable"><code>integer</code></em>[<em class="replaceable"><code>integer</code></em>];<br>
provide-ixfr<em class="replaceable"><code>boolean</code></em>;<br>
qname-minimization(strict|relaxed|disabled);<br>
query-source(([address](<em class="replaceable"><code>ipv4_address</code></em>|*)[port(<br>
<em class="replaceable"><code>integer</code></em>|*)])|([[address](<em class="replaceable"><code>ipv4_address</code></em>|*)]<br>
port(<em class="replaceable"><code>integer</code></em>|*)))[dscp<em class="replaceable"><code>integer</code></em>];<br>
......@@ -389,18 +390,19 @@ options
response-padding{<em class="replaceable"><code>address_match_element</code></em>;...}block-size<br>
<em class="replaceable"><code>integer</code></em>;<br>
response-policy{zone<em class="replaceable"><code>quoted_string</code></em>[log<em class="replaceable"><code>boolean</code></em>][<br>
max-policy-ttl<em class="replaceable"><code>integer</code></em>][min-update-interval<em class="replaceable"><code>integer</code></em>][<br>
max-policy-ttl<em class="replaceable"><code>ttlval</code></em>][min-update-interval<em class="replaceable"><code>ttlval</code></em>][<br>
policy(cname|disabled|drop|given|no-op|nodata|<br>
nxdomain|passthru|tcp-only<em class="replaceable"><code>quoted_string</code></em>)][<br>
recursive-only<em class="replaceable"><code>boolean</code></em>][nsip-enable<em class="replaceable"><code>boolean</code></em>][<br>
nsdname-enable<em class="replaceable"><code>boolean</code></em>];...}[break-dnssec<em class="replaceable"><code>boolean</code></em>][<br>
max-policy-ttl<em class="replaceable"><code>integer</code></em>][min-update-interval<em class="replaceable"><code>integer</code></em>][<br>
max-policy-ttl<em class="replaceable"><code>ttlval</code></em>][min-update-interval<em class="replaceable"><code>ttlval</code></em>][<br>
min-ns-dots<em class="replaceable"><code>integer</code></em>][nsip-wait-recurse<em class="replaceable"><code>boolean</code></em>][<br>
qname-wait-recurse<em class="replaceable"><code>boolean</code></em>][recursive-only<em class="replaceable"><code>boolean</code></em>][<br>
nsip-enable<em class="replaceable"><code>boolean</code></em>][nsdname-enable<em class="replaceable"><code>boolean</code></em>][<br>
dnsrps-enable<em class="replaceable"><code>boolean</code></em>][dnsrps-options{<em class="replaceable"><code>unspecified-text</code></em><br>
}];<br>
root-delegation-only[exclude{<em class="replaceable"><code>quoted_string</code></em>;...}];<br>
root-key-sentinel<em class="replaceable"><code>boolean</code></em>;<br>
rrset-order{[class<em class="replaceable"><code>string</code></em>][type<em class="replaceable"><code>string</code></em>][name<br>
<em class="replaceable"><code>quoted_string</code></em>]<em class="replaceable"><code>string</code></em><em class="replaceable"><code>string</code></em>;...};<br>
secroots-file<em class="replaceable"><code>quoted_string</code></em>;<br>
......@@ -549,7 +551,7 @@ view
<em class="replaceable"><code>integer</code></em>][dscp<em class="replaceable"><code>integer</code></em>]{(<em class="replaceable"><code>masters</code></em>|<em class="replaceable"><code>ipv4_address</code></em>[<br>
port<em class="replaceable"><code>integer</code></em>]|<em class="replaceable"><code>ipv6_address</code></em>[port<em class="replaceable"><code>integer</code></em>])[key<br>
<em class="replaceable"><code>string</code></em>];...}][zone-directory<em class="replaceable"><code>quoted_string</code></em>][<br>
in-memory<em class="replaceable"><code>boolean</code></em>][min-update-interval<em class="replaceable"><code>integer</code></em>];...};<br>
in-memory<em class="replaceable"><code>boolean</code></em>][min-update-interval<em class="replaceable"><code>ttlval</code></em>];...};<br>
check-dup-records(fail|warn|ignore);<br>
check-integrity<em class="replaceable"><code>boolean</code></em>;<br>
check-mx(fail|warn|ignore);<br>
......@@ -587,6 +589,7 @@ view
};<br>
dns64-contact<em class="replaceable"><code>string</code></em>;<br>
dns64-server<em class="replaceable"><code>string</code></em>;<br>
dnskey-sig-validity<em class="replaceable"><code>integer</code></em>;<br>
dnsrps-enable<em class="replaceable"><code>boolean</code></em>;<br>
dnsrps-options{<em class="replaceable"><code>unspecified-text</code></em>};<br>
dnssec-accept-expired<em class="replaceable"><code>boolean</code></em>;<br>
......@@ -640,10 +643,10 @@ view
match-destinations{<em class="replaceable"><code>address_match_element</code></em>;...};<br>
match-recursive-only<em class="replaceable"><code>boolean</code></em>;<br>
max-cache-size(default|unlimited|<em class="replaceable"><code>sizeval</code></em>|<em class="replaceable"><code>percentage</code></em>);<br>
max-cache-ttl<em class="replaceable"><code>integer</code></em>;<br>
max-cache-ttl<em class="replaceable"><code>ttlval</code></em>;<br>
max-clients-per-query<em class="replaceable"><code>integer</code></em>;<br>
max-journal-size(default|unlimited|<em class="replaceable"><code>sizeval</code></em>);<br>
max-ncache-ttl<em class="replaceable"><code>integer</code></em>;<br>
max-ncache-ttl<em class="replaceable"><code>ttlval</code></em>;<br>
max-records<em class="replaceable"><code>integer</code></em>;<br>
max-recursion-depth<em class="replaceable"><code>integer</code></em>;<br>
max-recursion-queries<em class="replaceable"><code>integer</code></em>;<br>
......@@ -678,6 +681,7 @@ view
preferred-glue<em class="replaceable"><code>string</code></em>;<br>
prefetch<em class="replaceable"><code>integer</code></em>[<em class="replaceable"><code>integer</code></em>];<br>
provide-ixfr<em class="replaceable"><code>boolean</code></em>;<br>
qname-minimization(strict|relaxed|disabled);<br>
query-source(([address](<em class="replaceable"><code>ipv4_address</code></em>|*)[port(<br>
<em class="replaceable"><code>integer</code></em>|*)])|([[address](<em class="replaceable"><code>ipv4_address</code></em>|*)]<br>
port(<em class="replaceable"><code>integer</code></em>|*)))[dscp<em class="replaceable"><code>integer</code></em>];<br>
......@@ -712,18 +716,19 @@ view
response-padding{<em class="replaceable"><code>address_match_element</code></em>;...}block-size<br>
<em class="replaceable"><code>integer</code></em>;<br>
response-policy{zone<em class="replaceable"><code>quoted_string</code></em>[log<em class="replaceable"><code>boolean</code></em>][<br>
max-policy-ttl<em class="replaceable"><code>integer</code></em>][min-update-interval<em class="replaceable"><code>integer</code></em>][<br>
max-policy-ttl<em class="replaceable"><code>ttlval</code></em>][min-update-interval<em class="replaceable"><code>ttlval</code></em>][<br>
policy(cname|disabled|drop|given|no-op|nodata|<br>
nxdomain|passthru|tcp-only<em class="replaceable"><code>quoted_string</code></em>)][<br>
recursive-only<em class="replaceable"><code>boolean</code></em>][nsip-enable<em class="replaceable"><code>boolean</code></em>][<br>
nsdname-enable<em class="replaceable"><code>boolean</code></em>];...}[break-dnssec<em class="replaceable"><code>boolean</code></em>][<br>
max-policy-ttl<em class="replaceable"><code>integer</code></em>][min-update-interval<em class="replaceable"><code>integer</code></em>][<br>
max-policy-ttl<em class="replaceable"><code>ttlval</code></em>][min-update-interval<em class="replaceable"><code>ttlval</code></em>][<br>
min-ns-dots<em class="replaceable"><code>integer</code></em>][nsip-wait-recurse<em class="replaceable"><code>boolean</code></em>][<br>
qname-wait-recurse<em class="replaceable"><code>boolean</code></em>][recursive-only<em class="replaceable"><code>boolean</code></em>][<br>
nsip-enable<em class="replaceable"><code>boolean</code></em>][nsdname-enable<em class="replaceable"><code>boolean</code></em>][<br>
dnsrps-enable<em class="replaceable"><code>boolean</code></em>][dnsrps-options{<em class="replaceable"><code>unspecified-text</code></em><br>
}];<br>
root-delegation-only[exclude{<em class="replaceable"><code>quoted_string</code></em>;...}];<br>
root-key-sentinel<em class="replaceable"><code>boolean</code></em>;<br>
rrset-order{[class<em class="replaceable"><code>string</code></em>][type<em class="replaceable"><code>string</code></em>][name<br>
<em class="replaceable"><code>quoted_string</code></em>]<em class="replaceable"><code>string</code></em><em class="replaceable"><code>string</code></em>;...};<br>
send-cookie<em class="replaceable"><code>boolean</code></em>;<br>
......@@ -816,6 +821,7 @@ view
dialup(notify|notify-passive|passive|refresh|<br>
<em class="replaceable"><code>boolean</code></em>);<br>
dlz<em class="replaceable"><code>string</code></em>;<br>
dnskey-sig-validity<em class="replaceable"><code>integer</code></em>;<br>
dnssec-dnskey-kskonly<em class="replaceable"><code>boolean</code></em>;<br>
dnssec-loadkeys-interval<em class="replaceable"><code>integer</code></em>;<br>
dnssec-secure-to-insecure<em class="replaceable"><code>boolean</code></em>;<br>
......@@ -847,6 +853,7 @@ view
max-zone-ttl(unlimited|<em class="replaceable"><code>ttlval</code></em>);<br>
min-refresh-time<em class="replaceable"><code>integer</code></em>;<br>
min-retry-time<em class="replaceable"><code>integer</code></em>;<br>
mirror<em class="replaceable"><code>boolean</code></em>;<br>
multi-master<em class="replaceable"><code>boolean</code></em>;<br>
notify(explicit|master-only|<em class="replaceable"><code>boolean</code></em>);<br>
notify-delay<em class="replaceable"><code>integer</code></em>;<br>
......@@ -923,6 +930,7 @@ zone
delegation-only<em class="replaceable"><code>boolean</code></em>;<br>
dialup(notify|notify-passive|passive|refresh|<em class="replaceable"><code>boolean</code></em>);<br>
dlz<em class="replaceable"><code>string</code></em>;<br>
dnskey-sig-validity<em class="replaceable"><code>integer</code></em>;<br>
dnssec-dnskey-kskonly<em class="replaceable"><code>boolean</code></em>;<br>
dnssec-loadkeys-interval<em class="replaceable"><code>integer</code></em>;<br>
dnssec-secure-to-insecure<em class="replaceable"><code>boolean</code></em>;<br>
......@@ -952,6 +960,7 @@ zone
max-zone-ttl(unlimited|<em class="replaceable"><code>ttlval</code></em>);<br>
min-refresh-time<em class="replaceable"><code>integer</code></em>;<br>
min-retry-time<em class="replaceable"><code>integer</code></em>;<br>
mirror<em class="replaceable"><code>boolean</code></em>;<br>
multi-master<em class="replaceable"><code>boolean</code></em>;<br>
notify(explicit|master-only|<em class="replaceable"><code>boolean</code></em>);<br>
notify-delay<em class="replaceable"><code>integer</code></em>;<br>
......
......@@ -614,6 +614,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -146,6 +146,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -759,6 +759,6 @@ controls {
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -2875,6 +2875,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
This diff is collapsed.
......@@ -361,6 +361,6 @@ allow-query { !{ !10/8; any; }; key example; };
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -136,6 +136,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -36,7 +36,7 @@
<div class="toc">
<p><b>Table of Contents</b></p>
<dl class="toc">
<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.13.1</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.13.2</a></span></dt>
<dd><dl>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
......@@ -54,7 +54,7 @@
</div>
<div class="section">
<div class="titlepage"><div><div><h2 class="title" style="clear: both">
<a name="id-1.9.2"></a>Release Notes for BIND Version 9.13.1</h2></div></div></div>
<a name="id-1.9.2"></a>Release Notes for BIND Version 9.13.2</h2></div></div></div>
<div class="section">
<div class="titlepage"><div><div><h3 class="title">
......@@ -122,6 +122,19 @@
<div class="titlepage"><div><div><h3 class="title">
<a name="relnotes_features"></a>New Features</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
<li class="listitem">
<p>
A new secondary zone option, <span class="command"><strong>mirror</strong></span>,
enables <span class="command"><strong>named</strong></span> to serve a transferred copy
of a zone's contents without acting as an authority for the
zone. A zone must be fully validated against an active trust
anchor before it can be used as a mirror zone. DNS responses
from mirror zones do not set the AA bit ("authoritative answer"),
but do set the AD bit ("authenticated data"). This feature is
meant to facilitate deployment of a local copy of the root zone,
as described in RFC 7706. [GL #33]
</p>
</li>
<li class="listitem">
<p>
BIND now can be compiled against the <span class="command"><strong>libidn2</strong></span>
......@@ -148,6 +161,26 @@
signatures covering DNSKEY RRsets. [GL #145]
</p>
</li>
<li class="listitem">
<p>
Support for QNAME minimization was added and enabled by default
in <span class="command"><strong>relaxed</strong></span> mode, in which BIND will fall back
to normal resolution if the remote server returns something
unexpected during the query minimization process. This default
setting might change to <span class="command"><strong>strict</strong></span> in the future.
</p>
</li>
<li class="listitem">
<p>
When built on Linux, BIND now requires the <span class="command"><strong>libcap</strong></span>
library to set process privileges. The adds a new compile-time
dependency, which can be met on most Linux platforms by installing the
<span class="command"><strong>libcap-dev</strong></span> or <span class="command"><strong>libcap-devel</strong></span>
package. BIND can also be built without capability support by using
<span class="command"><strong>configure --disable-linux-caps</strong></span>, at the cost of some
loss of security.
</p>
</li>
</ul></div>
</div>
......@@ -239,6 +272,23 @@
signatures and digest, nor it will validate them.
</p>
</li>
<li class="listitem">
<p>
Add the ability to not return a DNS COOKIE option when one
is present in the request. To prevent a cookie being returned
add 'answer-cookie no;' to named.conf. [GL #173]
</p>
<p>
<span class="command"><strong>answer-cookie</strong></span> is only intended as a temporary
measure, for use when <span class="command"><strong>named</strong></span> shares an IP address
with other servers that do not yet support DNS COOKIE. A mismatch
between servers on the same address is not expected to cause
operational problems, but the option to disable COOKIE responses so
that all servers have the same behavior is provided out of an
abundance of caution. DNS COOKIE is an important security mechanism,
and should not be disabled unless absolutely necessary.
</p>
</li>
</ul></div>
</div>
......@@ -340,7 +390,10 @@
<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
<p>
None.
<span class="command"><strong>named</strong></span> now rejects excessively large
incremental (IXFR) zone transfers in order to prevent
possible corruption of journal files which could cause
<span class="command"><strong>named</strong></span> to abort when loading zones. [GL #339]
</p>
</li></ul></div>
</div>
......@@ -417,6 +470,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -148,6 +148,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -914,6 +914,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -533,6 +533,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -206,6 +206,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -32,7 +32,7 @@
<div>
<div><h1 class="title">
<a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
<div><p class="releaseinfo">BIND Version 9.13.1</p></div>
<div><p class="releaseinfo">BIND Version 9.13.2</p></div>
<div><p class="copyright">Copyright 2000-2018 Internet Systems Consortium, Inc. ("ISC")</p></div>
</div>
<hr>
......@@ -234,7 +234,7 @@
</dl></dd>
<dt><span class="appendix"><a href="Bv9ARM.ch08.html">A. Release Notes</a></span></dt>
<dd><dl>
<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.13.1</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.13.2</a></span></dt>
<dd><dl>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
......@@ -428,6 +428,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
No preview for this file type
......@@ -90,6 +90,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -220,6 +220,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
......@@ -625,6 +625,6 @@
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.2 (Development Release)</p>
</body>
</html>
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment