1. 21 Feb, 2019 6 commits
  2. 20 Feb, 2019 3 commits
    • Evan Hunt's avatar
      Merge branch '428-remove-contrib-sdb' into 'master' · f4ade46f
      Evan Hunt authored
      remove contrib/sdb
      
      Closes #428
      
      See merge request !1501
      f4ade46f
    • Evan Hunt's avatar
      CHANGES · bcc2fd67
      Evan Hunt authored
      bcc2fd67
    • Evan Hunt's avatar
      remove contrib/sdb · c79e2f12
      Evan Hunt authored
      removed the SDB databases in contrib/sdb as they hadn't been
      maintained in some time, and were no longer able to link to named
      without modification.  also:
      
      - cleaned up contrib/README, which still referred to contrib
        subdirectores that were removed already, and linked to an obsolete URL.
      - removed references to sdb in doc/misc/roadmap and doc/misc/sdb.
      c79e2f12
  3. 19 Feb, 2019 6 commits
  4. 18 Feb, 2019 18 commits
  5. 14 Feb, 2019 7 commits
    • Evan Hunt's avatar
      Merge branch '879-dnssec-checkds-help' into 'master' · 4d4233f6
      Evan Hunt authored
      Correct path in dnssec-checkds help
      
      Closes #879
      
      See merge request !1515
      4d4233f6
    • Petr Menšík's avatar
      Correct path in dnssec-checkds help · 7bd544e7
      Petr Menšík authored
      7bd544e7
    • Michał Kępień's avatar
      Merge branch '873-do-not-check-sep-bit-for-mirror-zone-trust-anchors' into 'master' · ef9b9035
      Michał Kępień authored
      Do not check SEP bit for mirror zone trust anchors
      
      Closes #873
      
      See merge request !1506
      ef9b9035
    • Michał Kępień's avatar
      Add CHANGES entry · 2b19b851
      Michał Kępień authored
      5161.	[bug]		Do not require the SEP bit to be set for mirror zone
      			trust anchors. [GL #873]
      2b19b851
    • Michał Kępień's avatar
      Do not check SEP bit for mirror zone trust anchors · 72c20173
      Michał Kępień authored
      When a mirror zone is verified, the 'ignore_kskflag' argument passed to
      dns_zoneverify_dnssec() is set to false.  This means that in order for
      its verification to succeed, a mirror zone needs to have at least one
      key with the SEP bit set configured as a trust anchor.  This brings no
      security benefit and prevents zones signed only using keys without the
      SEP bit set from being mirrored, so change the value of the
      'ignore_kskflag' argument passed to dns_zoneverify_dnssec() to true.
      72c20173
    • Michał Kępień's avatar
      Merge branch 'michal/improve-stability-of-mirror-zone-tests' into 'master' · 724663c1
      Michał Kępień authored
      Improve stability of mirror zone system tests
      
      See merge request !1505
      724663c1
    • Michał Kępień's avatar
      Prevent races when waiting for log messages · 9c611dd9
      Michał Kępień authored
      The "mirror" system test checks whether log messages announcing a mirror
      zone coming into effect are emitted properly.  However, the helper
      functions responsible for waiting for zone transfers and zone loading to
      complete do not wait for these exact log messages, but rather for other
      ones preceding them, which introduces a possibility of false positives.
      
      This problem cannot be addressed by just changing the log message to
      look for because the test still needs to discern between transferring a
      zone and loading a zone.
      
      Add two new log messages at debug level 99 (which is what named
      instances used in system tests are configured with) that are to be
      emitted after the log messages announcing a mirror zone coming into
      effect.  Tweak the aforementioned helper functions to only return once
      the log messages they originally looked for are followed by the newly
      added log messages.  This reliably prevents races when looking for
      "mirror zone is now in use" log messages and also enables a workaround
      previously put into place in the "mirror" system test to be reverted.
      9c611dd9