- 05 Sep, 2014 4 commits
-
-
Mark Andrews authored
-
Tinderbox User authored
-
Evan Hunt authored
- possible use before assignment in query.c - missing <varlistentry> in ARM
-
Evan Hunt authored
3944. [test] Added a regression test for "server-id". [RT #37057]
-
- 04 Sep, 2014 6 commits
-
-
Tinderbox User authored
-
Evan Hunt authored
3943. [func] SERVFAIL responses can now be cached for a limited time (configured by "servfail-ttl", default 10 seconds, limit 30). This can reduce the frequency of retries when an authoritative server is known to be failing, e.g., due to ongoing DNSSEC validation problems. [RT #21347]
-
Mark Andrews authored
marked as insecure. [RT #37072]
-
Evan Hunt authored
-
Evan Hunt authored
3940. [func] "rndc nta" now allows negative trust anchors to be set for up to one week. [RT #37069]
-
Mark Andrews authored
connections to be shared. [RT #37039]
-
- 30 Aug, 2014 3 commits
-
-
Mark Andrews authored
-
Mark Andrews authored
-
Mark Andrews authored
-
- 29 Aug, 2014 6 commits
-
-
Tinderbox User authored
-
Mark Andrews authored
-
Evan Hunt authored
3937. [func] Added some debug logging to better indicate the conditions causing SERVFAILs when resolving. [RT #35538]
-
Evan Hunt authored
3936. [func] Added authoritative support for the EDNS Client Subnet (ECS) option. ACLs can now include "ecs" elements which specify an address or network prefix; if an ECS option is included in a DNS query, then the address encoded in the option will be matched against "ecs" ACL elements. Also, if an ECS address is included in a query, then it will be used instead of the client source address when matching "geoip" ACL elements. This behavior can be overridden with "geoip-use-ecs no;". When "ecs" or "geoip" ACL elements are used to select a view for a query, the response will include an ECS option to indicate which client network the answer is valid for. (Thanks to Vincent Bernat.) [RT #36781]
-
Evan Hunt authored
3935. [bug] "geoip asnum" ACL elements would not match unless the full organization name was specified. They can now match against the AS number alone (e.g., AS1234). [RT #36945]
-
Mark Andrews authored
sit-secrets documentation. [RT #36980]
-
- 28 Aug, 2014 1 commit
-
-
Evan Hunt authored
3933. [bug] Corrected the implementation of dns_rdata_casecompare() for the HIP rdata type. [RT #36911] 3932. [test] Improved named-checkconf tests. [RT #36911]
-
- 26 Aug, 2014 2 commits
-
-
Mark Andrews authored
-
Evan Hunt authored
3930. [bug] "rndc nta -r" could cause a server hang if the NTA was not found. [RT #36909]
-
- 25 Aug, 2014 1 commit
-
-
Mark Andrews authored
-
- 23 Aug, 2014 2 commits
-
-
Evan Hunt authored
-
Tinderbox User authored
-
- 22 Aug, 2014 9 commits
-
-
Tinderbox User authored
-
Evan Hunt authored
3928. [test] Improve rndc system test. [RT #36898]
-
Evan Hunt authored
3927. [bug] dig: report PKCS#11 error codes correctly when compiled with --enable-native-pkcs11. [RT #36956]
-
Jeremy C. Reed authored
-
Mark Andrews authored
-
Mark Andrews authored
-
Evan Hunt authored
3922. [bug] When resigning, dnssec-signzone was removing all signatures from delegation nodes. It now retains DS and (if applicable) NSEC signatures. [RT #36946]
-
Mark Andrews authored
-
Mark Andrews authored
in batch mode. [RT #36755]
-
- 21 Aug, 2014 2 commits
-
-
Tinderbox User authored
-
Mark Andrews authored
too long after applying a search list elements. [RT #36892]
-
- 18 Aug, 2014 3 commits
-
-
Tinderbox User authored
-
Mark Andrews authored
-
Mark Andrews authored
shutting down. [RT #36887]
-
- 16 Aug, 2014 1 commit
-
-
Tinderbox User authored
-