- 11 Aug, 2010 1 commit
-
-
Evan Hunt authored
support for addzone/delzone feature (see change #2930). Removed "new-zone-file" option, replaced with "allow-new-zones (yes|no)". The new-zone-file for each view is now created automatically, with a filename generated from a hash of the view name. It is no longer necessary to "include" the new-zone-file in named.conf; this happens automatically. Zones that were not added via "rndc addzone" can no longer be removed with "rndc delzone". [RT #19447]
-
- 09 Jul, 2010 1 commit
-
-
Evan Hunt authored
- added LRU expiration for generated TSIGs - added the ability to use a non-default realm - added new "realm" keyword in nsupdate - limited lifetime of generated keys to 1 hour or the lifetime of the context (whichever is smaller) [RT #19737]
-
- 25 Jun, 2010 1 commit
-
-
Mark Andrews authored
current managed keys combined with trusted keys. [RT #20904]
-
- 22 Jun, 2010 1 commit
-
-
Mark Andrews authored
to IPv4 clients. New acl 'filter-aaaa' (default any).
-
- 14 May, 2010 1 commit
-
-
Mark Andrews authored
managed-keys-directory. [RT #20924]
-
- 25 Feb, 2010 1 commit
-
-
Mark Andrews authored
-
- 03 Feb, 2010 1 commit
-
-
Evan Hunt authored
README.rfc5011 into the ARM. [RT #20899]
-
- 23 Jan, 2010 1 commit
-
-
Mark Andrews authored
been five (5) seconds.
-
- 07 Jan, 2010 2 commits
-
-
Automatic Updater authored
-
Evan Hunt authored
digest length were used incorrectly, leading to interoperability problems with other DNS implementations. This has been corrected. (Note: If an oversize key is in use, and compatibility is needed with an older release of BIND, the new tool "isc-hmac-fixup" can convert the key secret to a form that will work with all versions.) [RT #20751]
-
- 18 Dec, 2009 1 commit
-
-
Evan Hunt authored
to insecure. [RT #20746]
-
- 04 Dec, 2009 2 commits
-
-
Mark Andrews authored
and genrandom under windows. [RT #20670] 2802. [cleanup] Rename journalprint to named-journalprint. [RT #20670]
-
Mark Andrews authored
to DNSSEC but are sematically equal according to plain DNS. Apply plain DNS comparisons rather than DNSSEC comparisons when processing UPDATE requests. dnssec-signzone now removes such semantically duplicate records prior to signing the RRset. named-checkzone -r {ignore|warn|fail} (default warn) named-compilezone -r {ignore|warn|fail} (default warn) named.conf: check-dup-records {ignore|warn|fail};
-
- 03 Dec, 2009 1 commit
-
-
Evan Hunt authored
"dnssec-secure-to-insecure", and "dnskey-ksk-only" to "dnssec-dnskey-kskonly", for clarity. [RT #20586]
-
- 28 Nov, 2009 1 commit
-
-
Vernon Schryver authored
-
- 26 Nov, 2009 1 commit
-
-
Evan Hunt authored
-
- 10 Nov, 2009 1 commit
-
-
Evan Hunt authored
the ARM. [RT #20303]
-
- 06 Nov, 2009 1 commit
-
-
Evan Hunt authored
-
- 05 Nov, 2009 1 commit
-
-
Evan Hunt authored
also the configure option which enables it was wrong.
-
- 04 Nov, 2009 1 commit
-
-
Evan Hunt authored
-
- 03 Nov, 2009 1 commit
-
-
Mark Andrews authored
-
- 26 Oct, 2009 1 commit
-
-
Evan Hunt authored
if built with './configure --enable-filter-aaaa'. Filters out AAAA answers to clients connecting via IPv4. (This is NOT recommended for general use.) [RT #20339]
-
- 22 Oct, 2009 2 commits
- 16 Oct, 2009 1 commit
-
-
Evan Hunt authored
-
- 14 Oct, 2009 1 commit
-
-
Jeremy Reed authored
No content changed. No CHANGES entry added.
-
- 12 Oct, 2009 3 commits
-
-
Evan Hunt authored
-
Evan Hunt authored
-
Evan Hunt authored
to be fully automated in zones configured for dynamic DNS. 'auto-dnssec allow;' permits a zone to be signed by creating keys for it in the key-directory and using 'rndc sign <zone>'. 'auto-dnssec maintain;' allows that too, plus it also keeps the zone's DNSSEC keys up to date according to their timing metadata. [RT #19943]
-
- 10 Oct, 2009 1 commit
-
-
Evan Hunt authored
zone option cause a zone to be signed with only KSKs signing the DNSKEY RRset, not ZSKs. This reduces the size of a DNSKEY answer. [RT #20340]
-
- 08 Oct, 2009 1 commit
-
-
Mark Andrews authored
update are now fully supported and no longer require defines to enable. We now no longer overload the NSEC3PARAM flag field, nor the NSEC OPT bit at the apex. Secure to insecure changes are controlled by by the named.conf option 'secure-to-insecure'. Warning: If you had previously enabled support by adding defines at compile time to BIND 9.6 you should ensure that all changes that are in progress have completed prior to upgrading to BIND 9.7. BIND 9.7 is not backwards compatible.
-
- 05 Oct, 2009 1 commit
-
-
Evan Hunt authored
supported TSIG key algorithm. [RT #18046]
-
- 03 Oct, 2009 1 commit
-
-
Evan Hunt authored
[RT #12252]
-
- 02 Sep, 2009 2 commits
-
-
Jeremy Reed authored
As discussed in RT #19874.
-
Mark Andrews authored
-
- 01 Sep, 2009 1 commit
-
-
Evan Hunt authored
ARM documentation about RFC 5011 support. [RT #19874]
-
- 25 Aug, 2009 1 commit
-
-
Mark Andrews authored
bind.keys, rndc.key or session.key. [RT #20155]
-
- 27 Jul, 2009 1 commit
-
-
Evan Hunt authored
-
- 19 Jul, 2009 1 commit
-
-
Evan Hunt authored
dnssec-* tools. Major changes: - all dnssec-* tools now take a -K option to specify a directory in which key files will be stored - DNSSEC can now store metadata indicating when they are scheduled to be published, acttivated, revoked or removed; these values can be set by dnssec-keygen or overwritten by the new dnssec-settime command - dnssec-signzone -S (for "smart") option reads key metadata and uses it to determine automatically which keys to publish to the zone, use for signing, revoke, or remove from the zone [RT #19816]
-
- 14 Jul, 2009 1 commit
-
-
Evan Hunt authored
"update-policy local;" to switch on local DDNS in a zone. [RT #19875]
-