diff options
author | Internet Software Consortium, Inc <@isc.org> | 2010-10-08 08:23:38 -0600 |
---|---|---|
committer | Internet Software Consortium, Inc <@isc.org> | 2010-10-08 08:24:41 -0600 |
commit | 274f3a9719ec6152a42ab768cbec525395b61a93 (patch) | |
tree | 8fd52a0aa04ffb14aff08ada57c1d966aec7a43c /CHANGES | |
parent | 15e215d7ab303000218156146c6d2e39f1b57b35 (diff) | |
download | bind9-274f3a9719ec6152a42ab768cbec525395b61a93.tar.gz |
v9.7.2b1
Diffstat (limited to 'CHANGES')
-rw-r--r-- | CHANGES | 66 |
1 files changed, 62 insertions, 4 deletions
@@ -1,18 +1,76 @@ - --- 9.7.1-P2 released --- + --- 9.7.2b1 released --- -2931. [security] Temporarily and partially disable change 2864 +2931. [bug] Temporarily and partially disable change 2864 because it would cause inifinite attempts of RRSIG queries. This is an urgent care fix; we'll revisit the issue and complete the fix later. [RT #21710] - --- 9.7.1-P1 released --- -2926. [rollback] Temporarially rollback change 2748. [RT #21594] +2930. [experimental] New "rndc addzone" and "rndc delzone" commads + allow dynamic addition and deletion of zones. + To enable this feature, specify a "new-zone-file" + option at the view or options level in named.conf. + Zone configuration information for the new zones + will be written into that file. To make the new + zones persist after a restart, "include" the file + into named.conf in the appropriate view. (Note: + This feature is not yet documented, and its syntax + is expected to change.) [RT #19447] + +2929. [bug] Improved handling of GSS security contexts: + - added LRU expiration for generated TSIGs + - added the ability to use a non-default realm + - added new "realm" keyword in nsupdate + - limited lifetime of generated keys to 1 hour + or the lifetime of the context (whichever is + smaller) + [RT #19737] 2925. [bug] Named failed to accept uncachable negative responses from insecure zones. [RT# 21555] +2924. [func] 'rndc secroots' dump a combined summary of the + current managed keys combined with trusted keys. + [RT #20904] + +2923. [bug] 'dig +trace' could drop core after "connection + timeout". [RT #21514] + +2922. [contrib] Update zkt to version 1.0. + +2921. [bug] The resolver could attempt to destroy a fetch context + too soon. [RT #19878] + +2920. [func] Allow 'filter-aaaa-on-v4' to be applied selectively + to IPv4 clients. New acl 'filter-aaaa' (default any). + +2919. [func] Add autosign-ksk and autosign-zsk virtual time tests. + [RT #20840] + +2918. [maint] Add AAAA address for I.ROOT-SERVERS.NET. + +2917. [func] Virtual time test framework. [RT #20801] + +2916. [func] Add framework to use IPv6 in tests. + fd92:7065:b8e:ffff::1 ... fd92:7065:b8e:ffff::7 + +2915. [cleanup] Be smarter about which objects we attempt to compile + based on configure options. [RT #21444] + +2914. [bug] Make the "autosign" system test more portable. + [RT #20997] + +2913. [func] Add pkcs#11 system tests. [RT #20784] + +2912. [func] Windows clients don't like UPDATE responses that clear + the zone section. [RT #20986] + +2911. [bug] dnssec-signzone didn't handle out of zone records well. + [RT #21367] + +2910. [func] Sanity check Kerberos credentials. [RT #20986] + --- 9.7.1 released --- --- 9.7.1rc1 released --- |