1. 25 Oct, 2017 1 commit
  2. 19 Sep, 2017 2 commits
  3. 11 Sep, 2017 1 commit
    • Evan Hunt's avatar
      [master] DNS Response Policy Service API · 3363f314
      Evan Hunt authored
      4713.	[func]		Added support for the DNS Response Policy Service
      			(DNSRPS) API, which allows named to use an external
      			response policy daemon when built with
      			"configure --enable-dnsrps".  Thanks to Vernon
      			Schryver and Farsight Security. [RT #43376]
      3363f314
  4. 31 Jul, 2017 1 commit
  5. 21 Apr, 2017 1 commit
  6. 16 Mar, 2017 1 commit
  7. 18 Nov, 2016 2 commits
  8. 01 Nov, 2016 1 commit
  9. 27 Oct, 2016 1 commit
  10. 21 Jul, 2016 2 commits
    • Evan Hunt's avatar
      [master] store "addzone" zone config in a NZD database · eca74c52
      Evan Hunt authored
      4421.	[func]		When built with LMDB (Lightning Memory-mapped
      			Database), named will now use a database to store
      			the configuration for zones added by "rndc addzone"
      			instead of using a flat NZF file. This improves
      			performance of "rndc delzone" and "rndc modzone"
      			significantly. Existing NZF files will
      			automatically by converted to NZD databases.
      			To view the contents of an NZD or to roll back to
      			NZF format, use "named-nzd2nzf". To disable
                              this feature, use "configure --without-lmdb".
                              [RT #39837]
      eca74c52
    • Mark Andrews's avatar
      regen · 2d857690
      Mark Andrews authored
      2d857690
  11. 10 Jul, 2016 1 commit
  12. 05 May, 2016 1 commit
  13. 01 Feb, 2016 1 commit
  14. 30 Jan, 2016 1 commit
  15. 02 Oct, 2015 2 commits
    • Evan Hunt's avatar
      [master] dnstap · b66b333f
      Evan Hunt authored
      4235.	[func]		Added support in named for "dnstap", a fast method of
      			capturing and logging DNS traffic, and a new command
      			"dnstap-read" to read a dnstap log file.  Use
      			"configure --enable-dnstap" to enable this
      			feature (note that this requires libprotobuf-c
      			and libfstrm). See the ARM for configuration details.
      
      			Thanks to Robert Edmonds of Farsight Security.
      			[RT #40211]
      b66b333f
    • Witold Krecicki's avatar
      4234. [func] Add deflate compression in statistics channel HTTP · a2390443
      Witold Krecicki authored
                              server. [RT #40861]
      a2390443
  16. 05 Jul, 2015 1 commit
    • Mark Andrews's avatar
      4152. [func] Implement DNS COOKIE option. This replaces the · ce67023a
      Mark Andrews authored
                              experimental SIT option of BIND 9.10.  The following
                              named.conf directives are avaliable: send-cookie,
                              cookie-secret, cookie-algorithm and nocookie-udp-size.
                              The following dig options are available:
                              +[no]cookie[=value] and +[no]badcookie.  [RT #39928]
      ce67023a
  17. 05 Jun, 2015 1 commit
  18. 26 Feb, 2015 1 commit
  19. 19 Dec, 2014 1 commit
  20. 02 Dec, 2014 1 commit
  21. 08 Oct, 2014 1 commit
  22. 30 Jul, 2014 1 commit
    • Mark Andrews's avatar
      [rt36039] · 70be3889
      Mark Andrews authored
      3902.   bug]            liblwres wasn't handling link-local addresses in
                              nameserver clauses in resolv.conf. [RT #36039]
      70be3889
  23. 16 May, 2014 1 commit
  24. 07 May, 2014 1 commit
  25. 10 Mar, 2014 1 commit
    • Evan Hunt's avatar
      [master] use adaptive locks when available · 8cbf3b6f
      Evan Hunt authored
      3781.	[tuning]	Use adaptive mutex locks when available; this
      			has been found to improve performance under load
      			on many systems. "configure --with-locktype=standard"
      			restores conventional mutex locks. [RT #32576]
      8cbf3b6f
  26. 27 Feb, 2014 1 commit
    • Evan Hunt's avatar
      [master] merge several interdependent fixes · 98922b2b
      Evan Hunt authored
      3760.   [bug]           Improve SIT with native PKCS#11 and on Windows.
      			[RT #35433]
      
      3759.   [port]          Enable delve on Windows. [RT #35441]
      
      3758.   [port]          Enable export library APIs on windows. [RT #35382]
      98922b2b
  27. 24 Feb, 2014 1 commit
  28. 20 Feb, 2014 1 commit
  29. 19 Feb, 2014 2 commits
    • Evan Hunt's avatar
      [master] add "--with-tuning=large" option · 6a3fa181
      Evan Hunt authored
      3745.	[func]		"configure --with-tuning=large" adjusts various
      			compiled-in constants and default settings to
      			values suited to large servers with abundant
      			memory. [RT #29538]
      6a3fa181
    • Mark Andrews's avatar
      3744. [experimental] SIT: send and process Source Identity Tokens · b5f6271f
      Mark Andrews authored
                              (which are similar to DNS Cookies by Donald Eastlake)
                              and are designed to help clients detect off path
                              spoofed responses and for servers to detect legitimate
                              clients.
      
                              SIT use a experimental EDNS option code (65001).
      
                              SIT can be enabled via --enable-developer or
                              --enable-sit.  It is on by default in Windows.
      
                              RRL processing as been updated to know about SIT with
                              legitimate clients not being rate limited. [RT #35389]
      b5f6271f
  30. 09 Feb, 2014 1 commit
    • Mark Andrews's avatar
      Add Linux support to: · 850b5e80
      Mark Andrews authored
      3733.   [func]          Improve interface scanning support.  Interface
                              information will be automatically updated if the
                              OS supports routing sockets (MacOS, *BSD, Linux).
                              Use "automatic-interface-scan no;" to disable.
      
                              Add "rndc scan" to trigger a scan. [RT #23027]
      850b5e80
  31. 07 Feb, 2014 1 commit
  32. 18 Jan, 2014 1 commit
  33. 14 Jan, 2014 1 commit
    • Evan Hunt's avatar
      [master] native PKCS#11 support · ba751492
      Evan Hunt authored
      3705.	[func]		"configure --enable-native-pkcs11" enables BIND
      			to use the PKCS#11 API for all cryptographic
      			functions, so that it can drive a hardware service
      			module directly without the need to use a modified
      			OpenSSL as intermediary (so long as the HSM's vendor
      			provides a complete-enough implementation of the
      			PKCS#11 interface). This has been tested successfully
      			with the Thales nShield HSM and with SoftHSMv2 from
      			the OpenDNSSEC project. [RT #29031]
      ba751492
  34. 08 Oct, 2013 1 commit
  35. 11 Jul, 2013 1 commit