2009年12月14日

[installer 2172] BIND 9.7.0rc1, 9.6.2b1

BIND 9.7.0rc1, 9.6.2b1 出ています。

☆ BIND 9.7.0rc1
http://www.isc.org/products/BIND/
ftp://ftp.isc.org/isc/bind/9.7.0rc1/bind-9.7.0rc1.tar.gz

--- 9.7.0rc1 released ---

2806. [bug] "rdnc sign" could delay re-signing the DNSKEY
when it had changed. [RT #20703]

2805. [bug] Fixed namespace problems encountered when building
external programs using non-exported BIND9 libraries
(i.e., built without --enable-exportlib). [RT #20679]

2804. [bug] Send notifies when a zone is signed with "rndc sign"
or as a result of a scheduled key change. [RT #20700]

2803. [port] win32: Install named-journalprint, nsec3hash, arpaname
and genrandom under windows. [RT #20670]

2802. [cleanup] Rename journalprint to named-journalprint. [RT #20670]

2801. [func] Detect and report records that are different according
to DNSSEC but are sematically equal according to plain
DNS. Apply plain DNS comparisons rather than DNSSEC
comparisons when processing UPDATE requests.
dnssec-signzone now removes such semantically duplicate
records prior to signing the RRset.

named-checkzone -r {ignore|warn|fail} (default warn)
named-compilezone -r {ignore|warn|fail} (default warn)

named.conf: check-dup-records {ignore|warn|fail};

2800. [func] Reject zones which have NS records which refer to
CNAMEs, DNAMEs or don't have address record (class IN
only). Reject UPDATEs which would cause the zone
to fail the above checks if committed. [RT #20678]

2799. [cleanup] Changed the "secure-to-insecure" option to
"dnssec-secure-to-insecure", and "dnskey-ksk-only"
to "dnssec-dnskey-kskonly", for clarity. [RT #20586]

2798. [bug] Addressed bugs in managed-keys initialization
and rollover. [RT #20683]

2797. [bug] Don't decrement the dispatch manager's maxbuffers.
[RT #20613]

2796. [bug] Missing dns_rdataset_disassociate() call in
dns_nsec3_delnsec3sx(). [RT #20681]

2795. [cleanup] Add text to differentiate "update with no effect"
log messages. [RT #18889]

2794. [bug] Install <isc/namespace.h>. [RT #20677]

2793. [func] Add "autosign" and "metadata" tests to the
automatic tests. [RT #19946]

2792. [func] "filter-aaaa-on-v4" can now be set in view
options (if compiled in). [RT #20635]

2791. [bug] The installation of isc-config.sh was broken.
[RT #20667]

2790. [bug] Handle DS queries to stub zones. [RT #20440]

2789. [bug] Fixed an INSIST in dispatch.c [RT #20576]

2788. [bug] dnssec-signzone could sign with keys that were
not requested [RT #20625]

2787. [bug] Spurious log message when zone keys were
dynamically reconfigured. [RT #20659]

2786. [bug] Additional could be promoted to answer. [RT #20663]


☆ BIND 9.6.2b1
http://www.isc.org/products/BIND/
ftp://ftp.isc.org/isc/bind/9.6.2b1/bind-9.6.2b1.tar.gz

--- 9.6.2b1 released ---

2797. [bug] Don't decrement the dispatch manager's maxbuffers.
[RT #20613]

2790. [bug] Handle DS queries to stub zones. [RT #20440]

2789. [bug] Fixed an INSIST in dispatch.c [RT #20576]

2786. [bug] Additional could be promoted to answer. [RT #20663]

2784. [bug] TC was not always being set when required glue was
dropped. [RT #20655]

2783. [func] Return minimal responses to EDNS/UDP queries with a UDP
buffer size of 512 or less. [RT #20654]

2782. [port] win32: use getaddrinfo() for hostname lookups.
[RT #20650]

2777. [contrib] DLZ MYSQL auto reconnect support discovery was wrong.

2772. [security] When validating, track whether pending data was from
the additional section or not and only return it if
validates as secure. [RT #20438]

2765. [bug] Skip masters for which the TSIG key cannot be found.
[RT #20595]

2760. [cleanup] Corrected named-compilezone usage summary. [RT #20533]

2759. [doc] Add information about .jbk/.jnw files to
the ARM. [RT #20303]

2758. [bug] win32: Added a workaround for a windows 2008 bug
that could cause the UDP client handler to shut
down. [RT #19176]

2757. [bug] dig: assertion failure could occur in connect
timeout. [RT #20599]

2755. [doc] Clarify documentation of keyset- files in
dnssec-signzone man page. [RT #19810]

2754. [bug] Secure-to-insecure transitions failed when zone
was signed with NSEC3. [RT #20587]

2750. [bug] dig: assertion failure could occur when a server
didn't have an address. [RT #20579]

2749. [bug] ixfr-from-differences generated a non-minimal ixfr
for NSEC3 signed zones. [RT #20452]

2747. [bug] Journal roll forwards failed to set the re-signing
time of RRSIGs correctly. [RT #20541]

2743. [bug] RRSIG could be incorrectly set in the NSEC3 record
for a insecure delegation.

2729. [func] When constructing a CNAME from a DNAME use the DNAME
TTL. [RT #20451]

2723. [bug] isc_base32_totext(), isc_base32hex_totext(), and
isc_base64_totext(), didn't always mark regions of
memory as fully consumed after conversion. [RT #20445]

2722. [bug] Ensure that the memory associated with the name of
a node in a rbt tree is not altered during the life
of the node. [RT #20431]

2721. [port] Have dst__entropy_status() prime the random number
generator. [RT #20369]

2718. [bug] The space calculations in opensslrsa_todns() were
incorrect. [RT #20394]

2716. [bug] nslookup debug mode didn't return the ttl. [RT #20414]

2715. [bug] Require OpenSSL support to be explicitly disabled.
[RT #20288]

2714. [port] aix/powerpc: 'asm("ics");' needs non standard assembler
flags.

2713. [bug] powerpc: atomic operations missing asm("ics") /
__isync() calls.

2706. [bug] Loading a zone with a very large NSEC3 salt could
trigger an assert. [RT #20368]

2705. [bug] Reconcile the XML stats version number with a later
BIND9 release, by adding a "name" attribute to
"cache" elements and increasing the version number
to 2.2. (This is a minor version change, but may
affect XML parsers if they assume the cache element
doesn't take an attribute.)

2704. [bug] Serial of dynamic and stub zones could be inconsistent
with their SOA serial. [RT #19387]

2701. [doc] Correction to ARM: hmac-md5 is no longer the only
supported TSIG key algorithm. [RT #18046]

2700. [doc] The match-mapped-addresses option is discouraged.
[RT #12252]

2699. [bug] Missing lock in rbtdb.c. [RT #20037]

2697. [port] win32: ensure that S_IFMT, S_IFDIR, S_IFCHR and
S_IFREG are defined after including <isc/stat.h>.
[RT #20309]

2696. [bug] named failed to successfully process some valid
acl constructs. [RT #20308]

2692. [port] win32: 32/64 bit cleanups. [RT #20335]

2690. [bug] win32: fix isc_thread_key_getspecific() prototype.
[RT #20315]

2689. [bug] Correctly handle snprintf result. [RT #20306]

2688. [bug] Use INTERFACE_F_POINTTOPOINT, not IFF_POINTOPOINT,
to decide to fetch the destination address. [RT #20305]

2686. [bug] dnssec-signzone should clean the old NSEC chain when
signing with NSEC3 and vice versa. [RT #20301]

2683. [bug] dnssec-signzone should clean out old NSEC3 chains when
the NSEC3 parameters used to sign the zone change.
[RT #20246]

2681. [bug] IPSECKEY RR of gateway type 3 was not correctly
decoded. [RT #20269]

2678. [func] Treat DS queries as if "minimal-response yes;"
was set. [RT #20258]

2672. [bug] Don't enable searching in 'host' when doing reverse
lookups. [RT #20218]

2670. [bug] Unexpected connect failures failed to log enough
information to be useful. [RT #20205]

2663. [func] win32: allow named to run as a service using
"NT AUTHORITY\LocalService" as the account. [RT #19977]

2662. [bug] lwres_getipnodebyname() and lwres_getipnodebyaddr()
returned a misleading error code when lwresd was
down. [RT #20028]

2661. [bug] Check whether socket fd exceeds FD_SETSIZE when
creating lwres context. [RT #20029]

2659. [doc] Clarify dnssec-keygen doc: key name must match zone
name for DNSSEC keys. [RT #19938]

2656. [func] win32: add a "tools only" check box to the installer
which causes it to only install dig, host, nslookup,
nsupdate and relevant DLLs. [RT #19998]

2655. [doc] Document that key-directory does not affect
rndc.key. [RT #20155]

2653. [bug] Treat ENGINE_load_private_key() failures as key
not found rather than out of memory. [RT #18033]

2649. [bug] Set the domain for forward only zones. [RT #19944]

2648. [port] win32: isc_time_seconds() was broken. [RT #19900]

2647. [bug] Remove unnecessary SOA updates when a new KSK is
added. [RT #19913]

2646. [bug] Incorrect cleanup on error in socket.c. [RT #19987]

2645. [port] "gcc -m32" didn't work on amd64 and x86_64 platforms
which default to 64 bits. [RT #19927]

2643. [bug] Stub zones interacted badly with NSEC3 support.
[RT #19777]

2642. [bug] nsupdate could dump core on solaris when reading
improperly formatted key files. [RT #20015]

2640. [security] A specially crafted update packet will cause named
to exit. [RT #20000]

2639. [bug] Silence compiler warnings in gssapi code. [RT #19954]

2637. [func] Rationalize dnssec-signzone's signwithkey() calling.
[RT #19959]

2635. [bug] isc_inet_ntop() incorrectly handled 0.0/16 addresses.
[RT #19716]

2633. [bug] Handle 15 bit rand() functions. [RT #19783]

2632. [func] util/kit.sh: warn if documentation appears to be out of
date. [RT #19922]

2625. [bug] Missing UNLOCK in rbtdb.c. [RT #19865]

2623. [bug] Named started seaches for DS non-optimally. [RT #19915]

2621. [doc] Made copyright boilterplate consistent. [RT #19833]

2920. [bug] Delay thawing the zone until the reload of it has
completed successfully. [RT #19750]

2618. [bug] The sdb and sdlz db_interator_seek() methods could
loop infinitely. [RT #19847]

2617. [bug] ifconfig.sh failed to emit an error message when
run from the wrong location. [RT #19375]

2616. [bug] 'host' used the nameservers from resolv.conf even
when a explicit nameserver was specified. [RT #19852]

2615. [bug] "__attribute__((unused))" was in the wrong place
for ia64 gcc builds. [RT #19854]

2614. [port] win32: 'named -v' should automatically be executed
in the foreground. [RT #19844]

2613. [bug] Option argument validation was missing for
dnssec-dsfromkey. [RT #19828]

2610. [port] sunos: Change #2363 was not complete. [RT #19796]

2608. [func] Perform post signing verification checks in
dnssec-signzone. These can be disabled with -P.

The post sign verification test ensures that for each
algorithm in use there is at least one non revoked
self signed KSK key. That all revoked KSK keys are
self signed. That all records in the zone are signed
by the algorithm. [RT #19653]

2601. [doc] Mention file creation mode mask in the
named manual page.

2593. [bug] Improve a corner source of SERVFAILs [RT #19632]

2589. [bug] dns_db_unregister() failed to clear '*dbimp'.
[RT #19626]

2581. [contrib] dlz/mysql set MYSQL_OPT_RECONNECT option on connection.
Requires MySQL 5.0.19 or later. [RT #19084]

2580. [bug] UpdateRej statistics counter could be incremented twice
for one rejection. [RT #19476]

2533. [doc] ARM: document @ (at-sign). [RT #17144]

2500. [contrib] contrib/sdb/pgsql/zonetodb.c called non-existent
function. [RT #18582]

----
こがよういちろう


投稿者 xml-rpc : 2009年12月14日 19:33
役に立ちました?:
過去のフィードバック 平均:(0) 総合:(0) 投票回数:(0)
本記事へのTrackback: http://hoop.euqset.org/blog/mt-tb2006.cgi/91341
トラックバック
コメント
コメントする




画像の中に見える文字を入力してください。