1. 11 Dec, 2013 2 commits
    • Evan Hunt's avatar
      typo · 4e1d84a3
      Evan Hunt authored
      4e1d84a3
    • Evan Hunt's avatar
      [master] dnssec-signzone -Q · 0bbe3273
      Evan Hunt authored
      3686.	[func]		"dnssec-signzone -Q" drops signatures from keys
      			that are still published but no longer active.
      			[RT #34990]
      0bbe3273
  2. 18 Sep, 2013 1 commit
  3. 04 Sep, 2013 2 commits
  4. 15 Aug, 2013 1 commit
  5. 12 Aug, 2013 2 commits
  6. 12 Jun, 2013 1 commit
  7. 10 Apr, 2013 1 commit
  8. 04 Apr, 2013 1 commit
  9. 03 Apr, 2013 1 commit
  10. 21 Mar, 2013 1 commit
  11. 20 Mar, 2013 1 commit
    • Evan Hunt's avatar
      [master] add dnssec-coverage tool · 831f59eb
      Evan Hunt authored
      3528.	[func]		New "dnssec-coverage" command scans the timing
      			metadata for a set of DNSSEC keys and reports if a
      			lapse in signing coverage has been scheduled
      			inadvertently. (Note: This tool depends on python;
      			it will not be built or installed on systems that
      			do not have a python interpreter.) [RT #28098]
      831f59eb
  12. 23 Jan, 2013 1 commit
    • Evan Hunt's avatar
      [master] fix incorrect nsec3 check · 9a0dd99a
      Evan Hunt authored
          - check for NSEC3 in empty nodes when not due to optout delegations
          - fixed typo in output ("Bad record NSEC record")
          - incidentally fixed an error in signzone that caused an
            incorrect warning about missing DNSKEYs when using -S
            and -3 together
      
      3473.	[bug]		dnssec-signzone/verify could incorrectly report
      			an error condition due to an empty node above an
      			opt-out delegation lacking an NSEC3. [RT #32072]
      9a0dd99a
  13. 10 Jan, 2013 2 commits
  14. 28 Nov, 2012 1 commit
  15. 27 Nov, 2012 1 commit
    • Mark Andrews's avatar
      3424. [func] dnssec-dsfromkey now emits the hash without spaces. · b13b4520
      Mark Andrews authored
                              [RT #31951]
      
      Squashed commit of the following:
      
      commit 7369da0369e1de1fe6c5b5f84df8848b9a0984eb
      Author: Mark Andrews <marka@isc.org>
      Date:   Fri Nov 23 17:24:04 2012 +1100
      
          dupped/created reversed in log message
      
      commit 0cef5faaf3ac22b00ed0f95b6bb7a146cf4cac15
      Author: Mark Andrews <marka@isc.org>
      Date:   Fri Nov 23 13:40:14 2012 +1100
      
          remove space from DS hash
      b13b4520
  16. 21 Nov, 2012 1 commit
    • Mark Andrews's avatar
      3421. [bug] Named loops when re-signing if all keys are offline. · 20b95f5f
      Mark Andrews authored
                              [RT #31916]
      
      Squashed commit of the following:
      
      commit f47af0ca6793687b9c8d08fd44b0c091ba5a4f9a
      Author: Mark Andrews <marka@isc.org>
      Date:   Wed Nov 21 17:45:21 2012 +1100
      
          dns_dns_zonediff_t -> dns_zonediff_t, clarify comment
      
      commit 344edefc3ee90856a7ff990abe7971925ba843b2
      Author: Mark Andrews <marka@isc.org>
      Date:   Tue Nov 20 13:12:26 2012 +1100
      
          commit the zone changes if a keep was marked as being offline
      
      commit cad2c2446ebfc20b6d8c4f6dd0d6596d7106cc0f
      Author: Mark Andrews <marka@isc.org>
      Date:   Tue Nov 20 13:08:29 2012 +1100
      
          check for looping when re-signing expiring.example
      20b95f5f
  17. 24 Oct, 2012 1 commit
  18. 06 Oct, 2012 1 commit
  19. 14 Aug, 2012 1 commit
  20. 25 Jul, 2012 1 commit
  21. 29 Jun, 2012 2 commits
  22. 17 May, 2012 1 commit
    • Evan Hunt's avatar
      Handle RRSIG signer case consistently · 26833735
      Evan Hunt authored
      3329.	[bug]		Handle RRSIG signer-name case consistently: We
      			generate RRSIG records with the signer-name in
      			lower case.  We accept them with any case, but if
      			they fail to validate, we try again in lower case.
      			[RT #27451]
      26833735
  23. 22 Feb, 2012 2 commits
  24. 22 Dec, 2011 1 commit
  25. 08 Dec, 2011 1 commit
    • Evan Hunt's avatar
      3241. [func] Extended the header of raw-format master files to · b4d8192d
      Evan Hunt authored
      			include the serial number of the zone from which
      			they were generated, if different (as in the case
      			of inline-signing zones).  This is to be used in
      			inline-signing zones, to track changes between the
      			unsigned and signed versions of the zone, which may
      			have different serial numbers.
      
      			(Note: raw zonefiles generated by this version of
      			BIND are no longer compatble with prior versions.
      			To generate a backward-compatible raw zonefile
      			using dnssec-signzone or named-compilezone, specify
      			output format "raw=0" instead of simply "raw".)
      			[RT #26587]
      b4d8192d
  26. 29 Nov, 2011 1 commit
  27. 07 Nov, 2011 1 commit
  28. 04 Nov, 2011 2 commits
  29. 28 Oct, 2011 1 commit
    • Evan Hunt's avatar
      3185. [func] New 'rndc signing' option for auto-dnssec zones: · 9c03f13e
      Evan Hunt authored
      			 - 'rndc signing -list' displays the current
      			   state of signing operations
      			 - 'rndc signing -clear' clears the signing state
      		  	   records for keys that have fully signed the zone
      			 - 'rndc signing -nsec3param' sets the NSEC3
      			   parameters for the zone
      			The 'rndc keydone' syntax is removed. [RT #23729]
      9c03f13e
  30. 26 Oct, 2011 1 commit
  31. 20 Oct, 2011 1 commit
  32. 15 Oct, 2011 1 commit
  33. 11 Oct, 2011 1 commit