]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
prep 9.15.5
authorTinderbox User <tbox@isc.org>
Wed, 2 Oct 2019 05:59:18 +0000 (05:59 +0000)
committerTinderbox User <tbox@isc.org>
Wed, 2 Oct 2019 06:08:59 +0000 (06:08 +0000)
62 files changed:
CHANGES
README
doc/arm/Bv9ARM.ch01.html
doc/arm/Bv9ARM.ch02.html
doc/arm/Bv9ARM.ch03.html
doc/arm/Bv9ARM.ch04.html
doc/arm/Bv9ARM.ch05.html
doc/arm/Bv9ARM.ch06.html
doc/arm/Bv9ARM.ch07.html
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.ch09.html
doc/arm/Bv9ARM.ch10.html
doc/arm/Bv9ARM.ch11.html
doc/arm/Bv9ARM.ch12.html
doc/arm/Bv9ARM.html
doc/arm/Bv9ARM.pdf
doc/arm/man.arpaname.html
doc/arm/man.ddns-confgen.html
doc/arm/man.delv.html
doc/arm/man.dig.html
doc/arm/man.dnssec-cds.html
doc/arm/man.dnssec-checkds.html
doc/arm/man.dnssec-coverage.html
doc/arm/man.dnssec-dsfromkey.html
doc/arm/man.dnssec-importkey.html
doc/arm/man.dnssec-keyfromlabel.html
doc/arm/man.dnssec-keygen.html
doc/arm/man.dnssec-keymgr.html
doc/arm/man.dnssec-revoke.html
doc/arm/man.dnssec-settime.html
doc/arm/man.dnssec-signzone.html
doc/arm/man.dnssec-verify.html
doc/arm/man.dnstap-read.html
doc/arm/man.filter-aaaa.html
doc/arm/man.host.html
doc/arm/man.mdig.html
doc/arm/man.named-checkconf.html
doc/arm/man.named-checkzone.html
doc/arm/man.named-journalprint.html
doc/arm/man.named-nzd2nzf.html
doc/arm/man.named-rrchecker.html
doc/arm/man.named.conf.html
doc/arm/man.named.html
doc/arm/man.nsec3hash.html
doc/arm/man.nslookup.html
doc/arm/man.nsupdate.html
doc/arm/man.pkcs11-destroy.html
doc/arm/man.pkcs11-keygen.html
doc/arm/man.pkcs11-list.html
doc/arm/man.pkcs11-tokens.html
doc/arm/man.rndc-confgen.html
doc/arm/man.rndc.conf.html
doc/arm/man.rndc.html
doc/arm/notes.html
doc/arm/notes.pdf
doc/arm/notes.txt
lib/dns/api
lib/irs/api
lib/isc/api
lib/isccfg/api
lib/ns/api
version

diff --git a/CHANGES b/CHANGES
index 0e582e6c511e6490370345bf662aa3dbd43b1ada..78529403083efa82bed8ec872920e3617a391187 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -1,3 +1,5 @@
+       --- 9.15.5 released ---
+
 5299.  [security]      A flaw in DNSSEC verification when transferring
                        mirror zones could allow data to be incorrectly
                        marked valid. (CVE-2019-6475) [GL #16P]
diff --git a/README b/README
index acca352806d2d0842cd456b743848f4fa77d24d8..3f530296aa4d9d3a1ae1e8617ccb89102ba61a7e 100644 (file)
--- a/README
+++ b/README
@@ -361,7 +361,9 @@ Acknowledgments
 
   * This product includes software developed by the OpenSSL Project for
     use in the OpenSSL Toolkit. http://www.OpenSSL.org/
+
   * This product includes cryptographic software written by Eric Young
     (eay@cryptsoft.com)
+
   * This product includes software written by Tim Hudson
     (tjh@cryptsoft.com)
index 4319abf766c64f0d703d24d33cb8fc6a11abad9e..4e0cfcb2e24cecc3107eb6edc8011626345b5177 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 9d6a6fee5de7128f7936d0817fe0ff0aba09f95c..dcfea3d629e076d6dbb356bbd19a4b6220638154 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 801bc447ca12204733f7d230a2c34634f7a8ac57..c7e0e55f416d814f4bd89ef18e4d259ba186a0b4 100644 (file)
@@ -856,6 +856,6 @@ controls {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 21e2b020cfdf18d6e1653ad3a2455bfc2e9e381f..7454502d31ebcbe6d397dc05475eb1057d8735f6 100644 (file)
@@ -2840,6 +2840,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index ee0dc40f28269cb87c070e0eafbc0222303ff904..8b41f1cbafdb4af7200d41a02a58023b78712976 100644 (file)
@@ -14897,6 +14897,6 @@ HOST-127.EXAMPLE. MX 0 .
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 4ef63d93ac2562280ecad6d0da8dce50c3328b89..18673c4048f97cff5a25fa6e8fbc3e3b62a82b65 100644 (file)
@@ -360,6 +360,6 @@ allow-query { !{ !10/8; any; }; key example; };
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 38fcd9c5c29d875e7b5fb81681a007e5e6f95a65..50d1cf31f36e9c4ca0ab0721d452654831b84284 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 098f23cf248b662841ee5728f88102dbc267c8b9..50135dec4d75a3bb19f85c0c3605833d653a38c2 100644 (file)
@@ -36,7 +36,7 @@
 <div class="toc">
 <p><b>Table of Contents</b></p>
 <dl class="toc">
-<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.4</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.5</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
 </div>
       <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.9.2"></a>Release Notes for BIND Version 9.15.4</h2></div></div></div>
+<a name="id-1.9.2"></a>Release Notes for BIND Version 9.15.5</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
-    <p>
-      BIND 9.15 is an unstable development release of BIND.
-      This document summarizes new features and functional changes that
-      have been introduced on this branch.  With each development release
-      leading up to the stable BIND 9.16 release, this document will be
-      updated with additional features added and bugs fixed.
-    </p>
-  </div>
-
+  <p>
+    BIND 9.15 is an unstable development release of BIND.
+    This document summarizes new features and functional changes that
+    have been introduced on this branch.  With each development release
+    leading up to the stable BIND 9.16 release, this document will be
+    updated with additional features added and bugs fixed.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_versions"></a>Note on Version Numbering</h3></div></div></div>
-    <p>
-      Until BIND 9.12, new feature development releases were tagged
-      as "alpha" and "beta", leading up to the first stable release
-      for a given development branch, which always ended in ".0".
-      More recently, BIND adopted the "odd-unstable/even-stable"
-      release numbering convention. There will be no "alpha" or "beta"
-      releases in the 9.15 branch, only increasing version numbers.
-      So, for example, what would previously have been called 9.15.0a1,
-      9.15.0a2, 9.15.0b1, and so on, will instead be called 9.15.0,
-      9.15.1, 9.15.2, etc.
-    </p>
-    <p>
-      The first stable release from this development branch will be
-      renamed as 9.16.0. Thereafter, maintenance releases will continue
-      on the 9.16 branch, while unstable feature development proceeds in
-      9.17.
-    </p>
-  </div>
-
+  <p>
+    Until BIND 9.12, new feature development releases were tagged
+    as "alpha" and "beta", leading up to the first stable release
+    for a given development branch, which always ended in ".0".
+    More recently, BIND adopted the "odd-unstable/even-stable"
+    release numbering convention. There will be no "alpha" or "beta"
+    releases in the 9.15 branch, only increasing version numbers.
+    So, for example, what would previously have been called 9.15.0a1,
+    9.15.0a2, 9.15.0b1, and so on, will instead be called 9.15.0,
+    9.15.1, 9.15.2, etc.
+  </p>
+  <p>
+    The first stable release from this development branch will be
+    renamed as 9.16.0. Thereafter, maintenance releases will continue
+    on the 9.16 branch, while unstable feature development proceeds in
+    9.17.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_platforms"></a>Supported Platforms</h3></div></div></div>
-    <p>
-      To build on UNIX-like systems, BIND requires support for POSIX.1c
-      threads (IEEE Std 1003.1c-1995), the Advanced Sockets API for
-      IPv6 (RFC 3542), and standard atomic operations provided by the
-      C compiler.
-    </p>
-    <p>
-      The OpenSSL cryptography library must be available for the target
-      platform.  A PKCS#11 provider can be used instead for Public Key
-      cryptography (i.e., DNSSEC signing and validation), but OpenSSL is
-      still required for general cryptography operations such as hashing
-      and random number generation.
-    </p>
-    <p>
-      More information can be found in the <code class="filename">PLATFORMS.md</code>
-      file that is included in the source distribution of BIND 9.  If your
-      compiler and system libraries provide the above features, BIND 9
-      should compile and run. If that isn't the case, the BIND
-      development team will generally accept patches that add support
-      for systems that are still supported by their respective vendors.
-    </p>
-  </div>
-
+  <p>
+    To build on UNIX-like systems, BIND requires support for POSIX.1c
+    threads (IEEE Std 1003.1c-1995), the Advanced Sockets API for
+    IPv6 (RFC 3542), and standard atomic operations provided by the
+    C compiler.
+  </p>
+  <p>
+    The OpenSSL cryptography library must be available for the target
+    platform.  A PKCS#11 provider can be used instead for Public Key
+    cryptography (i.e., DNSSEC signing and validation), but OpenSSL is
+    still required for general cryptography operations such as hashing
+    and random number generation.
+  </p>
+  <p>
+    More information can be found in the <code class="filename">PLATFORMS.md</code>
+    file that is included in the source distribution of BIND 9.  If your
+    compiler and system libraries provide the above features, BIND 9
+    should compile and run. If that isn't the case, the BIND
+    development team will generally accept patches that add support
+    for systems that are still supported by their respective vendors.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_download"></a>Download</h3></div></div></div>
-    <p>
-      The latest versions of BIND 9 software can always be found at
-      <a class="link" href="http://www.isc.org/downloads/" target="_top">http://www.isc.org/downloads/</a>.
-      There you will find additional information about each release,
-      source code, and pre-compiled versions for Microsoft Windows
-      operating systems.
-    </p>
-  </div>
-
+  <p>
+    The latest versions of BIND 9 software can always be found at
+    <a class="link" href="http://www.isc.org/downloads/" target="_top">http://www.isc.org/downloads/</a>.
+    There you will find additional information about each release,
+    source code, and pre-compiled versions for Microsoft Windows
+    operating systems.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-        <p>
-         In certain configurations, <span class="command"><strong>named</strong></span> could crash
-         with an assertion failure if <span class="command"><strong>nxdomain-redirect</strong></span>
-         was in use and a redirected query resulted in an NXDOMAIN from the
-         cache. This flaw is disclosed in CVE-2019-6467. [GL #880]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The TCP client quota set using the <span class="command"><strong>tcp-clients</strong></span>
-         option could be exceeded in some cases. This could lead to
-         exhaustion of file descriptors. This flaw is disclosed in
-         CVE-2018-5743. [GL #615]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         A race condition could trigger an assertion failure when
-         a large number of incoming packets were being rejected.
-         This flaw is disclosed in CVE-2019-6471. [GL #942]
-       </p>
-      </li>
+  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+      <p>
+        The TCP client quota set using the <span class="command"><strong>tcp-clients</strong></span>
+        option could be exceeded in some cases. This could lead to
+        exhaustion of file descriptors. This flaw is disclosed in
+        CVE-2018-5743. [GL #615]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        In certain configurations, <span class="command"><strong>named</strong></span> could crash
+        with an assertion failure if <span class="command"><strong>nxdomain-redirect</strong></span>
+        was in use and a redirected query resulted in an NXDOMAIN from the
+        cache. This flaw is disclosed in CVE-2019-6467. [GL #880]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        A race condition could trigger an assertion failure when
+        a large number of incoming packets were being rejected.
+        This flaw is disclosed in CVE-2019-6471. [GL #942]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+       <span class="command"><strong>named</strong></span> could crash with an assertion failure
+       if a forwarder returned a referral, rather than resolving the
+       query, when QNAME minimization was enabled.  This flaw is
+       disclosed in CVE-2019-6476. [GL #1501]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+       A flaw in DNSSEC verification when transferring mirror zones
+       could allow data to be incorrectly marked valid. This flaw
+       is disclosed in CVE-2019-6475. [GL #16P]
+      </p>
+    </li>
 </ul></div>
-  </div>
-
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_features"></a>New Features</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-          Added a new command line option to <span class="command"><strong>dig</strong></span>:
-         <span style="color: red">&lt;comand&gt;+[no]unexpected&lt;/comand&gt;</span>. By default, <span class="command"><strong>dig</strong></span>
-         won't accept a reply from a source other than the one to which
-         it sent the query.  Add the <span class="command"><strong>+unexpected</strong></span> argument
-         to enable it to process replies from unexpected sources.
-        </p>
-      </li>
-<li class="listitem">
-       <p>
-         The GeoIP2 API from MaxMind is now supported. Geolocation support
-         will be compiled in by default if the <span class="command"><strong>libmaxminddb</strong></span>
-         library is found at compile time, but can be turned off by using
-         <span class="command"><strong>configure --disable-geoip</strong></span>.
-       </p>
-       <p>
-         The default path to the GeoIP2 databases will be set based
-         on the location of the <span class="command"><strong>libmaxminddb</strong></span> library;
-         for example, if it is in <code class="filename">/usr/local/lib</code>,
-         then the default path will be
-         <code class="filename">/usr/local/share/GeoIP</code>.
-         This value can be overridden in <code class="filename">named.conf</code>
-         using the <span class="command"><strong>geoip-directory</strong></span> option.
-       </p>
-       <p>
-         Some <span class="command"><strong>geoip</strong></span> ACL settings that were available with
-         legacy GeoIP, including searches for <span class="command"><strong>netspeed</strong></span>,
-         <span class="command"><strong>org</strong></span>, and three-letter ISO country codes, will
-         no longer work when using GeoIP2. Supported GeoIP2 database
-         types are <span class="command"><strong>country</strong></span>, <span class="command"><strong>city</strong></span>,
-         <span class="command"><strong>domain</strong></span>, <span class="command"><strong>isp</strong></span>, and
-         <span class="command"><strong>as</strong></span>. All of these databases support both IPv4
-         and IPv6 lookups. [GL #182] [GL #1112]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         In order to clarify the configuration of DNSSEC keys,
-         the <span class="command"><strong>trusted-keys</strong></span> and
-         <span class="command"><strong>managed-keys</strong></span> statements have been
-         deprecated, and the new <span class="command"><strong>dnssec-keys</strong></span>
-         statement should now be used for both types of key.
-       </p>
-       <p>
-         When used with the keyword <span class="command"><strong>initial-key</strong></span>,
-         <span class="command"><strong>dnssec-keys</strong></span> has the same behavior as
-         <span class="command"><strong>managed-keys</strong></span>, i.e., it configures
-         a trust anchor that is to be maintained via RFC 5011.
-       </p>
-       <p>
-         When used with the new keyword <span class="command"><strong>static-key</strong></span>, it
-         has the same behavior as <span class="command"><strong>trusted-keys</strong></span>,
-         configuring a permanent trust anchor that will not automatically
-         be updated.  (This usage is not recommended for the root key.)
-         [GL #6]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The new <span class="command"><strong>add-soa</strong></span> option specifies whether
-         or not the <span class="command"><strong>response-policy</strong></span> zone's SOA record
-         should be included in the additional section of RPZ responses.
-         [GL #865]
-        </p>
-      </li>
-<li class="listitem">
-       <p>
-         Two new metrics have been added to the
-         <span class="command"><strong>statistics-channel</strong></span> to report DNSSEC
-         signing operations.  For each key in each zone, the
-         <span class="command"><strong>dnssec-sign</strong></span> counter indicates the total
-         number of signatures <span class="command"><strong>named</strong></span> has generated
-         using that key since server startup, and the
-         <span class="command"><strong>dnssec-refresh</strong></span> counter indicates how
-         many of those signatures were refreshed during zone
-         maintenance, as opposed to having been generated
-         as a result of a zone update.  [GL #513]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Statistics channel groups are now toggleable. [GL #1030]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>dig</strong></span>, <span class="command"><strong>mdig</strong></span> and
-         <span class="command"><strong>delv</strong></span> can all now take a <span class="command"><strong>+yaml</strong></span>
-         option to print output in a a detailed YAML format. [RT #1145]
-        </p>
-      </li>
+  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+      <p>
+        Added a new command line option to <span class="command"><strong>dig</strong></span>:
+        <span class="command"><strong>+[no]unexpected</strong></span>. By default, <span class="command"><strong>dig</strong></span>
+        won't accept a reply from a source other than the one to which
+        it sent the query.  Add the <span class="command"><strong>+unexpected</strong></span> argument
+        to enable it to process replies from unexpected sources.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        The GeoIP2 API from MaxMind is now supported. Geolocation support
+        will be compiled in by default if the <span class="command"><strong>libmaxminddb</strong></span>
+        library is found at compile time, but can be turned off by using
+        <span class="command"><strong>configure --disable-geoip</strong></span>.
+      </p>
+      <p>
+        The default path to the GeoIP2 databases will be set based
+        on the location of the <span class="command"><strong>libmaxminddb</strong></span> library;
+        for example, if it is in <code class="filename">/usr/local/lib</code>,
+        then the default path will be
+        <code class="filename">/usr/local/share/GeoIP</code>.
+        This value can be overridden in <code class="filename">named.conf</code>
+        using the <span class="command"><strong>geoip-directory</strong></span> option.
+      </p>
+      <p>
+        Some <span class="command"><strong>geoip</strong></span> ACL settings that were available with
+        legacy GeoIP, including searches for <span class="command"><strong>netspeed</strong></span>,
+        <span class="command"><strong>org</strong></span>, and three-letter ISO country codes, will
+        no longer work when using GeoIP2. Supported GeoIP2 database
+        types are <span class="command"><strong>country</strong></span>, <span class="command"><strong>city</strong></span>,
+        <span class="command"><strong>domain</strong></span>, <span class="command"><strong>isp</strong></span>, and
+        <span class="command"><strong>as</strong></span>. All of these databases support both IPv4
+        and IPv6 lookups. [GL #182] [GL #1112]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        In order to clarify the configuration of DNSSEC keys,
+        the <span class="command"><strong>trusted-keys</strong></span> and
+        <span class="command"><strong>managed-keys</strong></span> statements have been
+        deprecated, and the new <span class="command"><strong>dnssec-keys</strong></span>
+        statement should now be used for both types of key.
+      </p>
+      <p>
+        When used with the keyword <span class="command"><strong>initial-key</strong></span>,
+        <span class="command"><strong>dnssec-keys</strong></span> has the same behavior as
+        <span class="command"><strong>managed-keys</strong></span>, i.e., it configures
+        a trust anchor that is to be maintained via RFC 5011.
+      </p>
+      <p>
+        When used with the new keyword <span class="command"><strong>static-key</strong></span>, it
+        has the same behavior as <span class="command"><strong>trusted-keys</strong></span>,
+        configuring a permanent trust anchor that will not automatically
+        be updated.  (This usage is not recommended for the root key.)
+        [GL #6]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        The new <span class="command"><strong>add-soa</strong></span> option specifies whether
+        or not the <span class="command"><strong>response-policy</strong></span> zone's SOA record
+        should be included in the additional section of RPZ responses.
+        [GL #865]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Two new metrics have been added to the
+        <span class="command"><strong>statistics-channel</strong></span> to report DNSSEC
+        signing operations.  For each key in each zone, the
+        <span class="command"><strong>dnssec-sign</strong></span> counter indicates the total
+        number of signatures <span class="command"><strong>named</strong></span> has generated
+        using that key since server startup, and the
+        <span class="command"><strong>dnssec-refresh</strong></span> counter indicates how
+        many of those signatures were refreshed during zone
+        maintenance, as opposed to having been generated
+        as a result of a zone update.  [GL #513]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Statistics channel groups are now toggleable. [GL #1030]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        <span class="command"><strong>dig</strong></span>, <span class="command"><strong>mdig</strong></span> and
+        <span class="command"><strong>delv</strong></span> can all now take a <span class="command"><strong>+yaml</strong></span>
+        option to print output in a a detailed YAML format. [RT #1145]
+      </p>
+    </li>
 </ul></div>
-  </div>
-
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_removed"></a>Removed Features</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         The <span class="command"><strong>dnssec-enable</strong></span> option has been obsoleted and
-         no longer has any effect. DNSSEC responses are always enabled
-         if signatures and other DNSSEC data are present. [GL #866]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The <span class="command"><strong>cleaning-interval</strong></span> option has been
-         removed.  [GL !1731]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         DNSSEC Lookaside Validation (DLV) is now obsolete.
-         The <span class="command"><strong>dnssec-lookaside</strong></span> option has been
-         marked as deprecated; when used in <code class="filename">named.conf</code>,
-         it will generate a warning but will otherwise be ignored.
-         All code enabling the use of lookaside validation has been removed
-         from the validator, <span class="command"><strong>delv</strong></span>, and the DNSSEC tools.
-         [GL #7]
-       </p>
-      </li>
+  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+      <p>
+        The <span class="command"><strong>dnssec-enable</strong></span> option has been obsoleted and
+        no longer has any effect. DNSSEC responses are always enabled
+        if signatures and other DNSSEC data are present. [GL #866]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        The <span class="command"><strong>cleaning-interval</strong></span> option has been
+        removed.  [GL !1731]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        DNSSEC Lookaside Validation (DLV) is now obsolete.
+        The <span class="command"><strong>dnssec-lookaside</strong></span> option has been
+        marked as deprecated; when used in <code class="filename">named.conf</code>,
+        it will generate a warning but will otherwise be ignored.
+        All code enabling the use of lookaside validation has been removed
+        from the validator, <span class="command"><strong>delv</strong></span>, and the DNSSEC tools.
+        [GL #7]
+      </p>
+    </li>
 </ul></div>
-  </div>
-
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> will now log a warning if
-         a static key is configured for the root zone. [GL #6]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When static and managed DNSSEC keys were both configured for the
-         same name, or when a static key was used to
-         configure a trust anchor for the root zone and
-         <span class="command"><strong>dnssec-validation</strong></span> was set to the default
-         value of <code class="literal">auto</code>, automatic RFC 5011 key
-         rollovers would be disabled. This combination of settings was
-         never intended to work, but there was no check for it in the
-         parser. This has been corrected, and it is now a fatal
-         configuration error. [GL #868]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         DS and CDS records are now generated with SHA-256 digests
-         only, instead of both SHA-1 and SHA-256. This affects the
-         default output of <span class="command"><strong>dnssec-dsfromkey</strong></span>, the
-         <code class="filename">dsset</code> files generated by
-         <span class="command"><strong>dnssec-signzone</strong></span>, the DS records added to
-         a zone by <span class="command"><strong>dnssec-signzone</strong></span> based on
-         <code class="filename">keyset</code> files, the CDS records added to
-         a zone by <span class="command"><strong>named</strong></span> and
-         <span class="command"><strong>dnssec-signzone</strong></span> based on "sync" timing
-         parameters in key files, and the checks performed by
-         <span class="command"><strong>dnssec-checkds</strong></span>.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         JSON-C is now the only supported library for enabling JSON
-         support for BIND statistics. The <span class="command"><strong>configure</strong></span>
-         option has been renamed from <span class="command"><strong>--with-libjson</strong></span>
-         to <span class="command"><strong>--with-json-c</strong></span>.  Use
-         <span class="command"><strong>PKG_CONFIG_PATH</strong></span> to specify a custom path to
-         the <span class="command"><strong>json-c</strong></span> library as the new
-         <span class="command"><strong>configure</strong></span> option does not take the library
-         installation path as an optional argument.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added and
-         made default.  Old non-default HMAC-SHA based DNS Cookie algorithms
-         have been removed, and only the default AES algorithm is being kept
-         for legacy reasons.  This change doesn't have any operational impact
-         in most common scenarios. [GL #605]
-       </p>
-       <p>
-         If you are running multiple DNS Servers (different versions of BIND 9
-         or DNS server from multiple vendors) responding from the same IP
-         address (anycast or load-balancing scenarios), you'll have to make
-         sure that all the servers are configured with the same DNS Cookie
-         algorithm and same Server Secret for the best performance.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The information from the <span class="command"><strong>dnssec-signzone</strong></span> and
-         <span class="command"><strong>dnssec-verify</strong></span> commands is now printed to standard
-         output.  The standard error output is only used to print warnings and
-         errors, and in case the user requests the signed zone to be printed to
-         standard output with <span class="command"><strong>-f -</strong></span> option.  A new
-         configuration option <span class="command"><strong>-q</strong></span> has been added to silence
-         all output on standard output except for the name of the signed zone.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         DS records included in DNS referral messages can now be validated
-         and cached immediately, reducing the number of queries needed for
-         a DNSSEC validation. [GL #964]
-       </p>
-      </li>
+  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+      <p>
+        <span class="command"><strong>named</strong></span> will now log a warning if
+        a static key is configured for the root zone. [GL #6]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        When static and managed DNSSEC keys were both configured for the
+        same name, or when a static key was used to
+        configure a trust anchor for the root zone and
+        <span class="command"><strong>dnssec-validation</strong></span> was set to the default
+        value of <code class="literal">auto</code>, automatic RFC 5011 key
+        rollovers would be disabled. This combination of settings was
+        never intended to work, but there was no check for it in the
+        parser. This has been corrected, and it is now a fatal
+        configuration error. [GL #868]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        DS and CDS records are now generated with SHA-256 digests
+        only, instead of both SHA-1 and SHA-256. This affects the
+        default output of <span class="command"><strong>dnssec-dsfromkey</strong></span>, the
+        <code class="filename">dsset</code> files generated by
+        <span class="command"><strong>dnssec-signzone</strong></span>, the DS records added to
+        a zone by <span class="command"><strong>dnssec-signzone</strong></span> based on
+        <code class="filename">keyset</code> files, the CDS records added to
+        a zone by <span class="command"><strong>named</strong></span> and
+        <span class="command"><strong>dnssec-signzone</strong></span> based on "sync" timing
+        parameters in key files, and the checks performed by
+        <span class="command"><strong>dnssec-checkds</strong></span>.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        JSON-C is now the only supported library for enabling JSON
+        support for BIND statistics. The <span class="command"><strong>configure</strong></span>
+        option has been renamed from <span class="command"><strong>--with-libjson</strong></span>
+        to <span class="command"><strong>--with-json-c</strong></span>.  Use
+        <span class="command"><strong>PKG_CONFIG_PATH</strong></span> to specify a custom path to
+        the <span class="command"><strong>json-c</strong></span> library as the new
+        <span class="command"><strong>configure</strong></span> option does not take the library
+        installation path as an optional argument.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added and
+        made default.  Old non-default HMAC-SHA based DNS Cookie algorithms
+        have been removed, and only the default AES algorithm is being kept
+        for legacy reasons.  This change doesn't have any operational impact
+        in most common scenarios. [GL #605]
+      </p>
+      <p>
+        If you are running multiple DNS Servers (different versions of BIND 9
+        or DNS server from multiple vendors) responding from the same IP
+        address (anycast or load-balancing scenarios), you'll have to make
+        sure that all the servers are configured with the same DNS Cookie
+        algorithm and same Server Secret for the best performance.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        The information from the <span class="command"><strong>dnssec-signzone</strong></span> and
+        <span class="command"><strong>dnssec-verify</strong></span> commands is now printed to standard
+        output.  The standard error output is only used to print warnings and
+        errors, and in case the user requests the signed zone to be printed to
+        standard output with <span class="command"><strong>-f -</strong></span> option.  A new
+        configuration option <span class="command"><strong>-q</strong></span> has been added to silence
+        all output on standard output except for the name of the signed zone.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        DS records included in DNS referral messages can now be validated
+        and cached immediately, reducing the number of queries needed for
+        a DNSSEC validation. [GL #964]
+      </p>
+    </li>
 </ul></div>
-  </div>
-
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-        <p>
-         The <span class="command"><strong>allow-update</strong></span> and
-         <span class="command"><strong>allow-update-forwarding</strong></span> options were
-         inadvertently treated as configuration errors when used at the
-         <span class="command"><strong>options</strong></span> or <span class="command"><strong>view</strong></span> level.
-         This has now been corrected.
-         [GL #913]
-       </p>
-      </li>
-<li class="listitem">
-        <p>
-         When <span class="command"><strong>qname-minimization</strong></span> was set to
-          <span class="command"><strong>relaxed</strong></span>, some improperly configured domains
-          would fail to resolve, but would have succeeded when minimization
-          was disabled. <span class="command"><strong>named</strong></span> will now fall back to normal
-          resolution in such cases, and also uses type A rather than NS for
-          minimal queries in order to reduce the likelihood of encountering
-          the problem. [GL #1055]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>./configure</strong></span> no longer sets
-         <span class="command"><strong>--sysconfdir</strong></span> to <span class="command"><strong>/etc</strong></span> or
-         <span class="command"><strong>--localstatedir</strong></span> to <span class="command"><strong>/var</strong></span>
-         when <span class="command"><strong>--prefix</strong></span> is not specified and the
-         aforementioned options are not specified explicitly. Instead,
-         Autoconf's defaults of <span class="command"><strong>$prefix/etc</strong></span> and
-         <span class="command"><strong>$prefix/var</strong></span> are respected.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Glue address records were not being returned in responses
-         to root priming queries; this has been corrected. [GL #1092]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Cache database statistics counters could report invalid values
-         when stale answers were enabled, because of a bug in counter
-         maintenance when cache data becomes stale. The statistics counters
-         have been corrected to report the number of RRsets for each
-         RR type that are active, stale but still potentially served,
-         or stale and marked for deletion. [GL #602]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Interaction between DNS64 and RPZ No Data rule (CNAME *.) could
-         cause unexpected results; this has been fixed. [GL #1106]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named-checkconf</strong></span> now checks DNS64 prefixes
-          to ensure bits 64-71 are zero. [GL #1159]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named-checkconf</strong></span> now correctly reports
-         a missing <span class="command"><strong>dnstap-output</strong></span> option when
-         <span class="command"><strong>dnstap</strong></span> is set. [GL #1136]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Handle ETIMEDOUT error on connect() with a non-blocking
-         socket. [GL #1133]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>dig</strong></span> now correctly expands the IPv6 address
-         when run with <span class="command"><strong>+expandaaaa +short</strong></span>. [GL #1152]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When a <span class="command"><strong>response-policy</strong></span> zone expires, ensure
-         that its policies are removed from the RPZ summary database.
-         [GL #1146]
-       </p>
-      </li>
+  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+      <p>
+        The <span class="command"><strong>allow-update</strong></span> and
+        <span class="command"><strong>allow-update-forwarding</strong></span> options were
+        inadvertently treated as configuration errors when used at the
+        <span class="command"><strong>options</strong></span> or <span class="command"><strong>view</strong></span> level.
+        This has now been corrected.
+        [GL #913]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        When <span class="command"><strong>qname-minimization</strong></span> was set to
+        <span class="command"><strong>relaxed</strong></span>, some improperly configured domains
+        would fail to resolve, but would have succeeded when minimization
+        was disabled. <span class="command"><strong>named</strong></span> will now fall back to normal
+        resolution in such cases, and also uses type A rather than NS for
+        minimal queries in order to reduce the likelihood of encountering
+        the problem. [GL #1055]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        <span class="command"><strong>./configure</strong></span> no longer sets
+        <span class="command"><strong>--sysconfdir</strong></span> to <span class="command"><strong>/etc</strong></span> or
+        <span class="command"><strong>--localstatedir</strong></span> to <span class="command"><strong>/var</strong></span>
+        when <span class="command"><strong>--prefix</strong></span> is not specified and the
+        aforementioned options are not specified explicitly. Instead,
+        Autoconf's defaults of <span class="command"><strong>$prefix/etc</strong></span> and
+        <span class="command"><strong>$prefix/var</strong></span> are respected.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Glue address records were not being returned in responses
+        to root priming queries; this has been corrected. [GL #1092]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Interaction between DNS64 and RPZ No Data rule (CNAME *.) could
+        cause unexpected results; this has been fixed. [GL #1106]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        <span class="command"><strong>named-checkconf</strong></span> now checks DNS64 prefixes
+        to ensure bits 64-71 are zero. [GL #1159]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        <span class="command"><strong>named-checkconf</strong></span> now correctly reports a missing
+        <span class="command"><strong>dnstap-output</strong></span> option when
+        <span class="command"><strong>dnstap</strong></span> is set. [GL #1136]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Handle ETIMEDOUT error on connect() with a non-blocking
+        socket. [GL #1133]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Cache database statistics counters could report invalid values
+        when stale answers were enabled, because of a bug in counter
+        maintenance when cache data becomes stale. The statistics counters
+        have been corrected to report the number of RRsets for each
+        RR type that are active, stale but still potentially served,
+        or stale and marked for deletion. [GL #602]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        <span class="command"><strong>dig</strong></span> now correctly expands the IPv6 address
+        when run with <span class="command"><strong>+expandaaaa +short</strong></span>. [GL #1152]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        When a <span class="command"><strong>response-policy</strong></span> zone expires, ensure
+        that its policies are removed from the RPZ summary database.
+        [GL #1146]
+      </p>
+    </li>
 </ul></div>
-  </div>
-
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_license"></a>License</h3></div></div></div>
-    <p>
-      BIND is open source software licensed under the terms of the Mozilla
-      Public License, version 2.0 (see the <code class="filename">LICENSE</code>
-      file for the full text).
-    </p>
-    <p>
-      The license requires that if you make changes to BIND and distribute
-      them outside your organization, those changes must be published under
-      the same license. It does not require that you publish or disclose
-      anything other than the changes you have made to our software.  This
-      requirement does not affect anyone who is using BIND, with or without
-      modifications, without redistributing it, nor anyone redistributing
-      BIND without changes.
-    </p>
-    <p>
-      Those wishing to discuss license compliance may contact ISC at
-      <a class="link" href="https://www.isc.org/mission/contact/" target="_top">
-       https://www.isc.org/mission/contact/</a>.
-    </p>
-  </div>
-
+  <p>
+    BIND is open source software licensed under the terms of the Mozilla
+    Public License, version 2.0 (see the <code class="filename">LICENSE</code>
+    file for the full text).
+  </p>
+  <p>
+    The license requires that if you make changes to BIND and distribute
+    them outside your organization, those changes must be published under
+    the same license. It does not require that you publish or disclose
+    anything other than the changes you have made to our software.  This
+    requirement does not affect anyone who is using BIND, with or without
+    modifications, without redistributing it, nor anyone redistributing
+    BIND without changes.
+  </p>
+  <p>
+    Those wishing to discuss license compliance may contact ISC at
+    <a class="link" href="https://www.isc.org/mission/contact/" target="_top">
+      https://www.isc.org/mission/contact/</a>.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="end_of_life"></a>End of Life</h3></div></div></div>
-    <p>
-      BIND 9.15 is an unstable development branch. When its development
-      is complete, it will be renamed to BIND 9.16, which will be a
-      stable branch.
-    </p>
-    <p>
-      The end of life date for BIND 9.16 has not yet been determined.
-      For those needing long term support, the current Extended Support
-      Version (ESV) is BIND 9.11, which will be supported until at
-      least December 2021. See
-      <a class="link" href="https://www.isc.org/downloads/software-support-policy/" target="_top">https://www.isc.org/downloads/software-support-policy/</a>
-      for details of ISC's software support policy.
-    </p>
-  </div>
-
+  <p>
+    BIND 9.15 is an unstable development branch. When its development
+    is complete, it will be renamed to BIND 9.16, which will be a
+    stable branch.
+  </p>
+  <p>
+    The end of life date for BIND 9.16 has not yet been determined.
+    For those needing long term support, the current Extended Support
+    Version (ESV) is BIND 9.11, which will be supported until at
+    least December 2021. See
+    <a class="link" href="https://www.isc.org/downloads/software-support-policy/" target="_top">https://www.isc.org/downloads/software-support-policy/</a>
+    for details of ISC's software support policy.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_thanks"></a>Thank You</h3></div></div></div>
-    <p>
-      Thank you to everyone who assisted us in making this release possible.
-      If you would like to contribute to ISC to assist us in continuing to
-      make quality open source software, please visit our donations page at
-      <a class="link" href="http://www.isc.org/donate/" target="_top">http://www.isc.org/donate/</a>.
-    </p>
-  </div>
+  <p>
+    Thank you to everyone who assisted us in making this release possible.
+    If you would like to contribute to ISC to assist us in continuing to
+    make quality open source software, please visit our donations page at
+    <a class="link" href="http://www.isc.org/donate/" target="_top">http://www.isc.org/donate/</a>.
+  </p>
+</div>
 </div>
     </div>
 <div class="navfooter">
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index a3537cef766e794c5ac4461d584e37a3fd390b23..251aae8d6fd642fecc301835ba1f060dc22585c8 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index a49ccc53bbb28f0d6df7accaf946866d5bb4f357..392fc0ac866b020bc2858f268cf2fd458f06dfc8 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 1f99f9d5d02ecd349b24f28eae2c074f0b6b0e28..d8fbfe3a295808b51f952f12e1e0b03b4656c997 100644 (file)
@@ -537,6 +537,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index af5147d95ce4ad1c3d49e875d48bc82e94c48c72..a48773dc954b740188fdd68df7ebf9e2c8f5cec3 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index f51222702c450c2468d2e8d0021b6f04d4618fb7..44dbe57b0fdd8f6e70a732b1e86fced063a5a261 100644 (file)
@@ -32,7 +32,7 @@
 <div>
 <div><h1 class="title">
 <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
-<div><p class="releaseinfo">BIND Version 9.15.4</p></div>
+<div><p class="releaseinfo">BIND Version 9.15.5</p></div>
 <div><p class="copyright">Copyright Â© 2000-2019 Internet Systems Consortium, Inc. ("ISC")</p></div>
 </div>
 <hr>
 </dl></dd>
 <dt><span class="appendix"><a href="Bv9ARM.ch08.html">A. Release Notes</a></span></dt>
 <dd><dl>
-<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.4</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.15.5</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 66c3639350f5d84fd1f953d0716d2df0120bff30..cbca0a56bd23d942fbff8732f0dfe5f630a26779 100644 (file)
Binary files a/doc/arm/Bv9ARM.pdf and b/doc/arm/Bv9ARM.pdf differ
index f4c3c81de1727316046e9775cbe17b90969f499d..b338b4c02781696119a0d7f4f8165a0fff514c34 100644 (file)
@@ -90,6 +90,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 2604e653035dae5525a884115fe5c7eda20b7a0d..1566d0a24d4fa26e15f27ba54f3fc234b2c8cc21 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 405341cb91935ab4fd70b81bf3233a9d62c04cd0..14bb9db815dd44857ee21728897b4450fd409fb2 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 5f2bb2956bd1904e59b24ec4838b507bd2e48b63..7dd4d0853e8edf6b0c429e9572e05aa177f019f4 100644 (file)
@@ -1188,6 +1188,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index ab289866ab5aed4a6f4a67c367e16b51a6d8f281..13576db90d17481b7fe9232b124e6c8c03f74c49 100644 (file)
@@ -376,6 +376,6 @@ nsupdate -l
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 2cdd6eda6ecb7ad15cbd2033c0c14dacca53e9e1..7b918884077e2d4696771fe409617ffd21ab8b86 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 45f3a3e45a5a7f76f5506dd5b3a3b3164646b30f..718c2c6bd59e8209b900ee06a2f67179feee5435 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index ad45a53e2f856d772fe7c9aeb311190d9e005abf..183cc7259180853a7e8064faa0fc5fe30b2aea9b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index e153cd5e9a86346b45176c4066d45f18118e3e09..a1651b4a428ecac69c9e9e302e15998a6576cd4a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index c5290dcdf5c5f3d467b2256443e1af0fec3655db..4071867a8ed9f9b3e9c9693aab3f1bfc01dc1a7b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index d9e0fdb89ebb50b2cfd0947fa21a6686d7454144..88124727e8af8c8f4cd238e2cd366d5afe8f8244 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 4d377c1c2c34ab3b9a73aef0a798eb5efd410e19..391ef72af0f2f49098bc565e439c2b75b3928aa8 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 9ad5e9b2bb145acaf7a890f28b7cbb5605af2ed1..8174fd8903e6cd2d626972d7634648f6c19a29b0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 38d0a42c00d22fc9dcbd631db1b29b3fc6682b42..66979faeeac4d6b3d1cd22c745b663d393142971 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index f19fa309300620bbd956996d96aa2c6b14ce2486..baedb13a3673e292b3759989ebd97fe2b49c0698 100644 (file)
@@ -707,6 +707,6 @@ db.example.com.signed
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index e74dab17920c7781659aaf266784758d118280d6..8cbd293f1bc6e96613eecbe9697eb82307eef2d4 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 21a01348d888df51d147fc4044603fba59fbcbee..a8496e25b380fe99a71c80c3d88cdc539dd24d65 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 497c62ea351f17f2bd28c0fe2bc97db36b108b07..62e7c6c37c7b92dec56832156b2912cb569c1130 100644 (file)
@@ -168,6 +168,6 @@ plugin query "/usr/local/lib/filter-aaaa.so" {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index bd72dc29f572baa7de079d3677069f4cc19a4a98..c7d071016959db6ffab67ca180d7fc2a8e069e9c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 670846731b11e95b9c27a24bd9c6845d5698c2dd..15af64a9a1d55ccbc721fc079aab1acf7f11bfad 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index b70d7efdd4f0da7844f77148ad403f162037ee7e..6b1dbe4f47e992ca141b42f524cc55a189ff43e6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 0a50816134fc7678a9d890e1fa36be944ead9b73..2b1dfc82fee5462a682d5b973a460954cb4a38a3 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index db62c9a61e6de65c614069700b1f6d017e0cbe84..088a9fbda24f63dd867e20a746e9928490a9ad86 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 3f03ef211a7e0defb716535e2888e632c5f47847..977b700f29c37c0edf950d599df5d3eac269c3a5 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 36a0da2fe3f04cb269b29d608e55113664b0350b..0abbbc6d6ffa9adfe2dda7f568e3adb7df13ba84 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index c7a3284e45e5c63e63959431ccf49a8e69d1b361..1269c37303cf4bd8933ca89654d17c5735eb01ad 100644 (file)
@@ -1069,6 +1069,6 @@ zone
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 46d8062c401fa87ef536753baa4ae7fe888948db..c2ff92224d0205df8da91ecd868237cee8ae8670 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 32d76b35ed01ad0da9fcb97bb8cde203e3cbbd08..dc35fe16860db35f857b472ad479a1f23bf3cbb7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index ef04d50191079a707cdb53ac024724ac101d76ad..ebe13859dbd53de552b7e41efc7876f50a29c171 100644 (file)
@@ -437,6 +437,6 @@ nslookup -query=hinfo  -timeout=10
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 04f800af8c1621225fe42913ff9ceec37acdec81..6c7ae79b8bdc4cfd4f09cc551ccc9af0428a4861 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 692c032b57843e8327617772e5e182f89ee0c76f..4fa7f31d18fbf9ba0cd6280aa4bb9e8c4c247ab0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index a73d76a0e27d8397e1f1b58d39cc0dea05b89d56..53b984aa314e650a385788abe409435dab30e87a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index d6eacf6d8129bfbba5bfd0f676322e867647fee9..2a93a18b88630baa225e19fd5c2e1b0d1dd224c2 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index dd18c7f26f5423c40f61f598e75d763a9ba659e7..115f7270da753eb4f3e06f0e438e1c1e051b7129 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 2718bc29289e383fd29d95535da2ca3542fa4c6e..448ba701321affca479c73c83f0bded3724edd59 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index fd0135cabe42029d9364468c6fbafe9d0ce9b1c2..563ffc87a0c46f28361cd28749fdddebaa727478 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 740e92a162bd67ef57e2cfb0a9de783005771e95..5f3fc68fe0868af8537070a1012280b87eac3d4c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.4 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.15.5 (Development Release)</p>
 </body>
 </html>
index 657821f602a1ccb02b79f3129596f5ab9dd30ad5..b25e390d1edfaec337190036243028494cfb759f 100644 (file)
 
   <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.2"></a>Release Notes for BIND Version 9.15.4</h2></div></div></div>
+<a name="id-1.2"></a>Release Notes for BIND Version 9.15.5</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
-    <p>
-      BIND 9.15 is an unstable development release of BIND.
-      This document summarizes new features and functional changes that
-      have been introduced on this branch.  With each development release
-      leading up to the stable BIND 9.16 release, this document will be
-      updated with additional features added and bugs fixed.
-    </p>
-  </div>
-
+  <p>
+    BIND 9.15 is an unstable development release of BIND.
+    This document summarizes new features and functional changes that
+    have been introduced on this branch.  With each development release
+    leading up to the stable BIND 9.16 release, this document will be
+    updated with additional features added and bugs fixed.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_versions"></a>Note on Version Numbering</h3></div></div></div>
-    <p>
-      Until BIND 9.12, new feature development releases were tagged
-      as "alpha" and "beta", leading up to the first stable release
-      for a given development branch, which always ended in ".0".
-      More recently, BIND adopted the "odd-unstable/even-stable"
-      release numbering convention. There will be no "alpha" or "beta"
-      releases in the 9.15 branch, only increasing version numbers.
-      So, for example, what would previously have been called 9.15.0a1,
-      9.15.0a2, 9.15.0b1, and so on, will instead be called 9.15.0,
-      9.15.1, 9.15.2, etc.
-    </p>
-    <p>
-      The first stable release from this development branch will be
-      renamed as 9.16.0. Thereafter, maintenance releases will continue
-      on the 9.16 branch, while unstable feature development proceeds in
-      9.17.
-    </p>
-  </div>
-
+  <p>
+    Until BIND 9.12, new feature development releases were tagged
+    as "alpha" and "beta", leading up to the first stable release
+    for a given development branch, which always ended in ".0".
+    More recently, BIND adopted the "odd-unstable/even-stable"
+    release numbering convention. There will be no "alpha" or "beta"
+    releases in the 9.15 branch, only increasing version numbers.
+    So, for example, what would previously have been called 9.15.0a1,
+    9.15.0a2, 9.15.0b1, and so on, will instead be called 9.15.0,
+    9.15.1, 9.15.2, etc.
+  </p>
+  <p>
+    The first stable release from this development branch will be
+    renamed as 9.16.0. Thereafter, maintenance releases will continue
+    on the 9.16 branch, while unstable feature development proceeds in
+    9.17.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_platforms"></a>Supported Platforms</h3></div></div></div>
-    <p>
-      To build on UNIX-like systems, BIND requires support for POSIX.1c
-      threads (IEEE Std 1003.1c-1995), the Advanced Sockets API for
-      IPv6 (RFC 3542), and standard atomic operations provided by the
-      C compiler.
-    </p>
-    <p>
-      The OpenSSL cryptography library must be available for the target
-      platform.  A PKCS#11 provider can be used instead for Public Key
-      cryptography (i.e., DNSSEC signing and validation), but OpenSSL is
-      still required for general cryptography operations such as hashing
-      and random number generation.
-    </p>
-    <p>
-      More information can be found in the <code class="filename">PLATFORMS.md</code>
-      file that is included in the source distribution of BIND 9.  If your
-      compiler and system libraries provide the above features, BIND 9
-      should compile and run. If that isn't the case, the BIND
-      development team will generally accept patches that add support
-      for systems that are still supported by their respective vendors.
-    </p>
-  </div>
-
+  <p>
+    To build on UNIX-like systems, BIND requires support for POSIX.1c
+    threads (IEEE Std 1003.1c-1995), the Advanced Sockets API for
+    IPv6 (RFC 3542), and standard atomic operations provided by the
+    C compiler.
+  </p>
+  <p>
+    The OpenSSL cryptography library must be available for the target
+    platform.  A PKCS#11 provider can be used instead for Public Key
+    cryptography (i.e., DNSSEC signing and validation), but OpenSSL is
+    still required for general cryptography operations such as hashing
+    and random number generation.
+  </p>
+  <p>
+    More information can be found in the <code class="filename">PLATFORMS.md</code>
+    file that is included in the source distribution of BIND 9.  If your
+    compiler and system libraries provide the above features, BIND 9
+    should compile and run. If that isn't the case, the BIND
+    development team will generally accept patches that add support
+    for systems that are still supported by their respective vendors.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_download"></a>Download</h3></div></div></div>
-    <p>
-      The latest versions of BIND 9 software can always be found at
-      <a class="link" href="http://www.isc.org/downloads/" target="_top">http://www.isc.org/downloads/</a>.
-      There you will find additional information about each release,
-      source code, and pre-compiled versions for Microsoft Windows
-      operating systems.
-    </p>
-  </div>
-
+  <p>
+    The latest versions of BIND 9 software can always be found at
+    <a class="link" href="http://www.isc.org/downloads/" target="_top">http://www.isc.org/downloads/</a>.
+    There you will find additional information about each release,
+    source code, and pre-compiled versions for Microsoft Windows
+    operating systems.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-        <p>
-         In certain configurations, <span class="command"><strong>named</strong></span> could crash
-         with an assertion failure if <span class="command"><strong>nxdomain-redirect</strong></span>
-         was in use and a redirected query resulted in an NXDOMAIN from the
-         cache. This flaw is disclosed in CVE-2019-6467. [GL #880]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The TCP client quota set using the <span class="command"><strong>tcp-clients</strong></span>
-         option could be exceeded in some cases. This could lead to
-         exhaustion of file descriptors. This flaw is disclosed in
-         CVE-2018-5743. [GL #615]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         A race condition could trigger an assertion failure when
-         a large number of incoming packets were being rejected.
-         This flaw is disclosed in CVE-2019-6471. [GL #942]
-       </p>
-      </li>
+  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+      <p>
+        The TCP client quota set using the <span class="command"><strong>tcp-clients</strong></span>
+        option could be exceeded in some cases. This could lead to
+        exhaustion of file descriptors. This flaw is disclosed in
+        CVE-2018-5743. [GL #615]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        In certain configurations, <span class="command"><strong>named</strong></span> could crash
+        with an assertion failure if <span class="command"><strong>nxdomain-redirect</strong></span>
+        was in use and a redirected query resulted in an NXDOMAIN from the
+        cache. This flaw is disclosed in CVE-2019-6467. [GL #880]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        A race condition could trigger an assertion failure when
+        a large number of incoming packets were being rejected.
+        This flaw is disclosed in CVE-2019-6471. [GL #942]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+       <span class="command"><strong>named</strong></span> could crash with an assertion failure
+       if a forwarder returned a referral, rather than resolving the
+       query, when QNAME minimization was enabled.  This flaw is
+       disclosed in CVE-2019-6476. [GL #1501]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+       A flaw in DNSSEC verification when transferring mirror zones
+       could allow data to be incorrectly marked valid. This flaw
+       is disclosed in CVE-2019-6475. [GL #16P]
+      </p>
+    </li>
 </ul></div>
-  </div>
-
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_features"></a>New Features</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-          Added a new command line option to <span class="command"><strong>dig</strong></span>:
-         <span style="color: red">&lt;comand&gt;+[no]unexpected&lt;/comand&gt;</span>. By default, <span class="command"><strong>dig</strong></span>
-         won't accept a reply from a source other than the one to which
-         it sent the query.  Add the <span class="command"><strong>+unexpected</strong></span> argument
-         to enable it to process replies from unexpected sources.
-        </p>
-      </li>
-<li class="listitem">
-       <p>
-         The GeoIP2 API from MaxMind is now supported. Geolocation support
-         will be compiled in by default if the <span class="command"><strong>libmaxminddb</strong></span>
-         library is found at compile time, but can be turned off by using
-         <span class="command"><strong>configure --disable-geoip</strong></span>.
-       </p>
-       <p>
-         The default path to the GeoIP2 databases will be set based
-         on the location of the <span class="command"><strong>libmaxminddb</strong></span> library;
-         for example, if it is in <code class="filename">/usr/local/lib</code>,
-         then the default path will be
-         <code class="filename">/usr/local/share/GeoIP</code>.
-         This value can be overridden in <code class="filename">named.conf</code>
-         using the <span class="command"><strong>geoip-directory</strong></span> option.
-       </p>
-       <p>
-         Some <span class="command"><strong>geoip</strong></span> ACL settings that were available with
-         legacy GeoIP, including searches for <span class="command"><strong>netspeed</strong></span>,
-         <span class="command"><strong>org</strong></span>, and three-letter ISO country codes, will
-         no longer work when using GeoIP2. Supported GeoIP2 database
-         types are <span class="command"><strong>country</strong></span>, <span class="command"><strong>city</strong></span>,
-         <span class="command"><strong>domain</strong></span>, <span class="command"><strong>isp</strong></span>, and
-         <span class="command"><strong>as</strong></span>. All of these databases support both IPv4
-         and IPv6 lookups. [GL #182] [GL #1112]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         In order to clarify the configuration of DNSSEC keys,
-         the <span class="command"><strong>trusted-keys</strong></span> and
-         <span class="command"><strong>managed-keys</strong></span> statements have been
-         deprecated, and the new <span class="command"><strong>dnssec-keys</strong></span>
-         statement should now be used for both types of key.
-       </p>
-       <p>
-         When used with the keyword <span class="command"><strong>initial-key</strong></span>,
-         <span class="command"><strong>dnssec-keys</strong></span> has the same behavior as
-         <span class="command"><strong>managed-keys</strong></span>, i.e., it configures
-         a trust anchor that is to be maintained via RFC 5011.
-       </p>
-       <p>
-         When used with the new keyword <span class="command"><strong>static-key</strong></span>, it
-         has the same behavior as <span class="command"><strong>trusted-keys</strong></span>,
-         configuring a permanent trust anchor that will not automatically
-         be updated.  (This usage is not recommended for the root key.)
-         [GL #6]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The new <span class="command"><strong>add-soa</strong></span> option specifies whether
-         or not the <span class="command"><strong>response-policy</strong></span> zone's SOA record
-         should be included in the additional section of RPZ responses.
-         [GL #865]
-        </p>
-      </li>
-<li class="listitem">
-       <p>
-         Two new metrics have been added to the
-         <span class="command"><strong>statistics-channel</strong></span> to report DNSSEC
-         signing operations.  For each key in each zone, the
-         <span class="command"><strong>dnssec-sign</strong></span> counter indicates the total
-         number of signatures <span class="command"><strong>named</strong></span> has generated
-         using that key since server startup, and the
-         <span class="command"><strong>dnssec-refresh</strong></span> counter indicates how
-         many of those signatures were refreshed during zone
-         maintenance, as opposed to having been generated
-         as a result of a zone update.  [GL #513]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Statistics channel groups are now toggleable. [GL #1030]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>dig</strong></span>, <span class="command"><strong>mdig</strong></span> and
-         <span class="command"><strong>delv</strong></span> can all now take a <span class="command"><strong>+yaml</strong></span>
-         option to print output in a a detailed YAML format. [RT #1145]
-        </p>
-      </li>
+  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+      <p>
+        Added a new command line option to <span class="command"><strong>dig</strong></span>:
+        <span class="command"><strong>+[no]unexpected</strong></span>. By default, <span class="command"><strong>dig</strong></span>
+        won't accept a reply from a source other than the one to which
+        it sent the query.  Add the <span class="command"><strong>+unexpected</strong></span> argument
+        to enable it to process replies from unexpected sources.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        The GeoIP2 API from MaxMind is now supported. Geolocation support
+        will be compiled in by default if the <span class="command"><strong>libmaxminddb</strong></span>
+        library is found at compile time, but can be turned off by using
+        <span class="command"><strong>configure --disable-geoip</strong></span>.
+      </p>
+      <p>
+        The default path to the GeoIP2 databases will be set based
+        on the location of the <span class="command"><strong>libmaxminddb</strong></span> library;
+        for example, if it is in <code class="filename">/usr/local/lib</code>,
+        then the default path will be
+        <code class="filename">/usr/local/share/GeoIP</code>.
+        This value can be overridden in <code class="filename">named.conf</code>
+        using the <span class="command"><strong>geoip-directory</strong></span> option.
+      </p>
+      <p>
+        Some <span class="command"><strong>geoip</strong></span> ACL settings that were available with
+        legacy GeoIP, including searches for <span class="command"><strong>netspeed</strong></span>,
+        <span class="command"><strong>org</strong></span>, and three-letter ISO country codes, will
+        no longer work when using GeoIP2. Supported GeoIP2 database
+        types are <span class="command"><strong>country</strong></span>, <span class="command"><strong>city</strong></span>,
+        <span class="command"><strong>domain</strong></span>, <span class="command"><strong>isp</strong></span>, and
+        <span class="command"><strong>as</strong></span>. All of these databases support both IPv4
+        and IPv6 lookups. [GL #182] [GL #1112]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        In order to clarify the configuration of DNSSEC keys,
+        the <span class="command"><strong>trusted-keys</strong></span> and
+        <span class="command"><strong>managed-keys</strong></span> statements have been
+        deprecated, and the new <span class="command"><strong>dnssec-keys</strong></span>
+        statement should now be used for both types of key.
+      </p>
+      <p>
+        When used with the keyword <span class="command"><strong>initial-key</strong></span>,
+        <span class="command"><strong>dnssec-keys</strong></span> has the same behavior as
+        <span class="command"><strong>managed-keys</strong></span>, i.e., it configures
+        a trust anchor that is to be maintained via RFC 5011.
+      </p>
+      <p>
+        When used with the new keyword <span class="command"><strong>static-key</strong></span>, it
+        has the same behavior as <span class="command"><strong>trusted-keys</strong></span>,
+        configuring a permanent trust anchor that will not automatically
+        be updated.  (This usage is not recommended for the root key.)
+        [GL #6]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        The new <span class="command"><strong>add-soa</strong></span> option specifies whether
+        or not the <span class="command"><strong>response-policy</strong></span> zone's SOA record
+        should be included in the additional section of RPZ responses.
+        [GL #865]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Two new metrics have been added to the
+        <span class="command"><strong>statistics-channel</strong></span> to report DNSSEC
+        signing operations.  For each key in each zone, the
+        <span class="command"><strong>dnssec-sign</strong></span> counter indicates the total
+        number of signatures <span class="command"><strong>named</strong></span> has generated
+        using that key since server startup, and the
+        <span class="command"><strong>dnssec-refresh</strong></span> counter indicates how
+        many of those signatures were refreshed during zone
+        maintenance, as opposed to having been generated
+        as a result of a zone update.  [GL #513]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Statistics channel groups are now toggleable. [GL #1030]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        <span class="command"><strong>dig</strong></span>, <span class="command"><strong>mdig</strong></span> and
+        <span class="command"><strong>delv</strong></span> can all now take a <span class="command"><strong>+yaml</strong></span>
+        option to print output in a a detailed YAML format. [RT #1145]
+      </p>
+    </li>
 </ul></div>
-  </div>
-
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_removed"></a>Removed Features</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         The <span class="command"><strong>dnssec-enable</strong></span> option has been obsoleted and
-         no longer has any effect. DNSSEC responses are always enabled
-         if signatures and other DNSSEC data are present. [GL #866]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The <span class="command"><strong>cleaning-interval</strong></span> option has been
-         removed.  [GL !1731]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         DNSSEC Lookaside Validation (DLV) is now obsolete.
-         The <span class="command"><strong>dnssec-lookaside</strong></span> option has been
-         marked as deprecated; when used in <code class="filename">named.conf</code>,
-         it will generate a warning but will otherwise be ignored.
-         All code enabling the use of lookaside validation has been removed
-         from the validator, <span class="command"><strong>delv</strong></span>, and the DNSSEC tools.
-         [GL #7]
-       </p>
-      </li>
+  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+      <p>
+        The <span class="command"><strong>dnssec-enable</strong></span> option has been obsoleted and
+        no longer has any effect. DNSSEC responses are always enabled
+        if signatures and other DNSSEC data are present. [GL #866]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        The <span class="command"><strong>cleaning-interval</strong></span> option has been
+        removed.  [GL !1731]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        DNSSEC Lookaside Validation (DLV) is now obsolete.
+        The <span class="command"><strong>dnssec-lookaside</strong></span> option has been
+        marked as deprecated; when used in <code class="filename">named.conf</code>,
+        it will generate a warning but will otherwise be ignored.
+        All code enabling the use of lookaside validation has been removed
+        from the validator, <span class="command"><strong>delv</strong></span>, and the DNSSEC tools.
+        [GL #7]
+      </p>
+    </li>
 </ul></div>
-  </div>
-
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> will now log a warning if
-         a static key is configured for the root zone. [GL #6]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When static and managed DNSSEC keys were both configured for the
-         same name, or when a static key was used to
-         configure a trust anchor for the root zone and
-         <span class="command"><strong>dnssec-validation</strong></span> was set to the default
-         value of <code class="literal">auto</code>, automatic RFC 5011 key
-         rollovers would be disabled. This combination of settings was
-         never intended to work, but there was no check for it in the
-         parser. This has been corrected, and it is now a fatal
-         configuration error. [GL #868]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         DS and CDS records are now generated with SHA-256 digests
-         only, instead of both SHA-1 and SHA-256. This affects the
-         default output of <span class="command"><strong>dnssec-dsfromkey</strong></span>, the
-         <code class="filename">dsset</code> files generated by
-         <span class="command"><strong>dnssec-signzone</strong></span>, the DS records added to
-         a zone by <span class="command"><strong>dnssec-signzone</strong></span> based on
-         <code class="filename">keyset</code> files, the CDS records added to
-         a zone by <span class="command"><strong>named</strong></span> and
-         <span class="command"><strong>dnssec-signzone</strong></span> based on "sync" timing
-         parameters in key files, and the checks performed by
-         <span class="command"><strong>dnssec-checkds</strong></span>.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         JSON-C is now the only supported library for enabling JSON
-         support for BIND statistics. The <span class="command"><strong>configure</strong></span>
-         option has been renamed from <span class="command"><strong>--with-libjson</strong></span>
-         to <span class="command"><strong>--with-json-c</strong></span>.  Use
-         <span class="command"><strong>PKG_CONFIG_PATH</strong></span> to specify a custom path to
-         the <span class="command"><strong>json-c</strong></span> library as the new
-         <span class="command"><strong>configure</strong></span> option does not take the library
-         installation path as an optional argument.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added and
-         made default.  Old non-default HMAC-SHA based DNS Cookie algorithms
-         have been removed, and only the default AES algorithm is being kept
-         for legacy reasons.  This change doesn't have any operational impact
-         in most common scenarios. [GL #605]
-       </p>
-       <p>
-         If you are running multiple DNS Servers (different versions of BIND 9
-         or DNS server from multiple vendors) responding from the same IP
-         address (anycast or load-balancing scenarios), you'll have to make
-         sure that all the servers are configured with the same DNS Cookie
-         algorithm and same Server Secret for the best performance.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The information from the <span class="command"><strong>dnssec-signzone</strong></span> and
-         <span class="command"><strong>dnssec-verify</strong></span> commands is now printed to standard
-         output.  The standard error output is only used to print warnings and
-         errors, and in case the user requests the signed zone to be printed to
-         standard output with <span class="command"><strong>-f -</strong></span> option.  A new
-         configuration option <span class="command"><strong>-q</strong></span> has been added to silence
-         all output on standard output except for the name of the signed zone.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         DS records included in DNS referral messages can now be validated
-         and cached immediately, reducing the number of queries needed for
-         a DNSSEC validation. [GL #964]
-       </p>
-      </li>
+  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+      <p>
+        <span class="command"><strong>named</strong></span> will now log a warning if
+        a static key is configured for the root zone. [GL #6]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        When static and managed DNSSEC keys were both configured for the
+        same name, or when a static key was used to
+        configure a trust anchor for the root zone and
+        <span class="command"><strong>dnssec-validation</strong></span> was set to the default
+        value of <code class="literal">auto</code>, automatic RFC 5011 key
+        rollovers would be disabled. This combination of settings was
+        never intended to work, but there was no check for it in the
+        parser. This has been corrected, and it is now a fatal
+        configuration error. [GL #868]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        DS and CDS records are now generated with SHA-256 digests
+        only, instead of both SHA-1 and SHA-256. This affects the
+        default output of <span class="command"><strong>dnssec-dsfromkey</strong></span>, the
+        <code class="filename">dsset</code> files generated by
+        <span class="command"><strong>dnssec-signzone</strong></span>, the DS records added to
+        a zone by <span class="command"><strong>dnssec-signzone</strong></span> based on
+        <code class="filename">keyset</code> files, the CDS records added to
+        a zone by <span class="command"><strong>named</strong></span> and
+        <span class="command"><strong>dnssec-signzone</strong></span> based on "sync" timing
+        parameters in key files, and the checks performed by
+        <span class="command"><strong>dnssec-checkds</strong></span>.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        JSON-C is now the only supported library for enabling JSON
+        support for BIND statistics. The <span class="command"><strong>configure</strong></span>
+        option has been renamed from <span class="command"><strong>--with-libjson</strong></span>
+        to <span class="command"><strong>--with-json-c</strong></span>.  Use
+        <span class="command"><strong>PKG_CONFIG_PATH</strong></span> to specify a custom path to
+        the <span class="command"><strong>json-c</strong></span> library as the new
+        <span class="command"><strong>configure</strong></span> option does not take the library
+        installation path as an optional argument.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added and
+        made default.  Old non-default HMAC-SHA based DNS Cookie algorithms
+        have been removed, and only the default AES algorithm is being kept
+        for legacy reasons.  This change doesn't have any operational impact
+        in most common scenarios. [GL #605]
+      </p>
+      <p>
+        If you are running multiple DNS Servers (different versions of BIND 9
+        or DNS server from multiple vendors) responding from the same IP
+        address (anycast or load-balancing scenarios), you'll have to make
+        sure that all the servers are configured with the same DNS Cookie
+        algorithm and same Server Secret for the best performance.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        The information from the <span class="command"><strong>dnssec-signzone</strong></span> and
+        <span class="command"><strong>dnssec-verify</strong></span> commands is now printed to standard
+        output.  The standard error output is only used to print warnings and
+        errors, and in case the user requests the signed zone to be printed to
+        standard output with <span class="command"><strong>-f -</strong></span> option.  A new
+        configuration option <span class="command"><strong>-q</strong></span> has been added to silence
+        all output on standard output except for the name of the signed zone.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        DS records included in DNS referral messages can now be validated
+        and cached immediately, reducing the number of queries needed for
+        a DNSSEC validation. [GL #964]
+      </p>
+    </li>
 </ul></div>
-  </div>
-
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-        <p>
-         The <span class="command"><strong>allow-update</strong></span> and
-         <span class="command"><strong>allow-update-forwarding</strong></span> options were
-         inadvertently treated as configuration errors when used at the
-         <span class="command"><strong>options</strong></span> or <span class="command"><strong>view</strong></span> level.
-         This has now been corrected.
-         [GL #913]
-       </p>
-      </li>
-<li class="listitem">
-        <p>
-         When <span class="command"><strong>qname-minimization</strong></span> was set to
-          <span class="command"><strong>relaxed</strong></span>, some improperly configured domains
-          would fail to resolve, but would have succeeded when minimization
-          was disabled. <span class="command"><strong>named</strong></span> will now fall back to normal
-          resolution in such cases, and also uses type A rather than NS for
-          minimal queries in order to reduce the likelihood of encountering
-          the problem. [GL #1055]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>./configure</strong></span> no longer sets
-         <span class="command"><strong>--sysconfdir</strong></span> to <span class="command"><strong>/etc</strong></span> or
-         <span class="command"><strong>--localstatedir</strong></span> to <span class="command"><strong>/var</strong></span>
-         when <span class="command"><strong>--prefix</strong></span> is not specified and the
-         aforementioned options are not specified explicitly. Instead,
-         Autoconf's defaults of <span class="command"><strong>$prefix/etc</strong></span> and
-         <span class="command"><strong>$prefix/var</strong></span> are respected.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Glue address records were not being returned in responses
-         to root priming queries; this has been corrected. [GL #1092]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Cache database statistics counters could report invalid values
-         when stale answers were enabled, because of a bug in counter
-         maintenance when cache data becomes stale. The statistics counters
-         have been corrected to report the number of RRsets for each
-         RR type that are active, stale but still potentially served,
-         or stale and marked for deletion. [GL #602]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Interaction between DNS64 and RPZ No Data rule (CNAME *.) could
-         cause unexpected results; this has been fixed. [GL #1106]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named-checkconf</strong></span> now checks DNS64 prefixes
-          to ensure bits 64-71 are zero. [GL #1159]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named-checkconf</strong></span> now correctly reports
-         a missing <span class="command"><strong>dnstap-output</strong></span> option when
-         <span class="command"><strong>dnstap</strong></span> is set. [GL #1136]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Handle ETIMEDOUT error on connect() with a non-blocking
-         socket. [GL #1133]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>dig</strong></span> now correctly expands the IPv6 address
-         when run with <span class="command"><strong>+expandaaaa +short</strong></span>. [GL #1152]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When a <span class="command"><strong>response-policy</strong></span> zone expires, ensure
-         that its policies are removed from the RPZ summary database.
-         [GL #1146]
-       </p>
-      </li>
+  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+      <p>
+        The <span class="command"><strong>allow-update</strong></span> and
+        <span class="command"><strong>allow-update-forwarding</strong></span> options were
+        inadvertently treated as configuration errors when used at the
+        <span class="command"><strong>options</strong></span> or <span class="command"><strong>view</strong></span> level.
+        This has now been corrected.
+        [GL #913]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        When <span class="command"><strong>qname-minimization</strong></span> was set to
+        <span class="command"><strong>relaxed</strong></span>, some improperly configured domains
+        would fail to resolve, but would have succeeded when minimization
+        was disabled. <span class="command"><strong>named</strong></span> will now fall back to normal
+        resolution in such cases, and also uses type A rather than NS for
+        minimal queries in order to reduce the likelihood of encountering
+        the problem. [GL #1055]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        <span class="command"><strong>./configure</strong></span> no longer sets
+        <span class="command"><strong>--sysconfdir</strong></span> to <span class="command"><strong>/etc</strong></span> or
+        <span class="command"><strong>--localstatedir</strong></span> to <span class="command"><strong>/var</strong></span>
+        when <span class="command"><strong>--prefix</strong></span> is not specified and the
+        aforementioned options are not specified explicitly. Instead,
+        Autoconf's defaults of <span class="command"><strong>$prefix/etc</strong></span> and
+        <span class="command"><strong>$prefix/var</strong></span> are respected.
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Glue address records were not being returned in responses
+        to root priming queries; this has been corrected. [GL #1092]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Interaction between DNS64 and RPZ No Data rule (CNAME *.) could
+        cause unexpected results; this has been fixed. [GL #1106]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        <span class="command"><strong>named-checkconf</strong></span> now checks DNS64 prefixes
+        to ensure bits 64-71 are zero. [GL #1159]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        <span class="command"><strong>named-checkconf</strong></span> now correctly reports a missing
+        <span class="command"><strong>dnstap-output</strong></span> option when
+        <span class="command"><strong>dnstap</strong></span> is set. [GL #1136]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Handle ETIMEDOUT error on connect() with a non-blocking
+        socket. [GL #1133]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        Cache database statistics counters could report invalid values
+        when stale answers were enabled, because of a bug in counter
+        maintenance when cache data becomes stale. The statistics counters
+        have been corrected to report the number of RRsets for each
+        RR type that are active, stale but still potentially served,
+        or stale and marked for deletion. [GL #602]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        <span class="command"><strong>dig</strong></span> now correctly expands the IPv6 address
+        when run with <span class="command"><strong>+expandaaaa +short</strong></span>. [GL #1152]
+      </p>
+    </li>
+<li class="listitem">
+      <p>
+        When a <span class="command"><strong>response-policy</strong></span> zone expires, ensure
+        that its policies are removed from the RPZ summary database.
+        [GL #1146]
+      </p>
+    </li>
 </ul></div>
-  </div>
-
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_license"></a>License</h3></div></div></div>
-    <p>
-      BIND is open source software licensed under the terms of the Mozilla
-      Public License, version 2.0 (see the <code class="filename">LICENSE</code>
-      file for the full text).
-    </p>
-    <p>
-      The license requires that if you make changes to BIND and distribute
-      them outside your organization, those changes must be published under
-      the same license. It does not require that you publish or disclose
-      anything other than the changes you have made to our software.  This
-      requirement does not affect anyone who is using BIND, with or without
-      modifications, without redistributing it, nor anyone redistributing
-      BIND without changes.
-    </p>
-    <p>
-      Those wishing to discuss license compliance may contact ISC at
-      <a class="link" href="https://www.isc.org/mission/contact/" target="_top">
-       https://www.isc.org/mission/contact/</a>.
-    </p>
-  </div>
-
+  <p>
+    BIND is open source software licensed under the terms of the Mozilla
+    Public License, version 2.0 (see the <code class="filename">LICENSE</code>
+    file for the full text).
+  </p>
+  <p>
+    The license requires that if you make changes to BIND and distribute
+    them outside your organization, those changes must be published under
+    the same license. It does not require that you publish or disclose
+    anything other than the changes you have made to our software.  This
+    requirement does not affect anyone who is using BIND, with or without
+    modifications, without redistributing it, nor anyone redistributing
+    BIND without changes.
+  </p>
+  <p>
+    Those wishing to discuss license compliance may contact ISC at
+    <a class="link" href="https://www.isc.org/mission/contact/" target="_top">
+      https://www.isc.org/mission/contact/</a>.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="end_of_life"></a>End of Life</h3></div></div></div>
-    <p>
-      BIND 9.15 is an unstable development branch. When its development
-      is complete, it will be renamed to BIND 9.16, which will be a
-      stable branch.
-    </p>
-    <p>
-      The end of life date for BIND 9.16 has not yet been determined.
-      For those needing long term support, the current Extended Support
-      Version (ESV) is BIND 9.11, which will be supported until at
-      least December 2021. See
-      <a class="link" href="https://www.isc.org/downloads/software-support-policy/" target="_top">https://www.isc.org/downloads/software-support-policy/</a>
-      for details of ISC's software support policy.
-    </p>
-  </div>
-
+  <p>
+    BIND 9.15 is an unstable development branch. When its development
+    is complete, it will be renamed to BIND 9.16, which will be a
+    stable branch.
+  </p>
+  <p>
+    The end of life date for BIND 9.16 has not yet been determined.
+    For those needing long term support, the current Extended Support
+    Version (ESV) is BIND 9.11, which will be supported until at
+    least December 2021. See
+    <a class="link" href="https://www.isc.org/downloads/software-support-policy/" target="_top">https://www.isc.org/downloads/software-support-policy/</a>
+    for details of ISC's software support policy.
+  </p>
+</div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_thanks"></a>Thank You</h3></div></div></div>
-    <p>
-      Thank you to everyone who assisted us in making this release possible.
-      If you would like to contribute to ISC to assist us in continuing to
-      make quality open source software, please visit our donations page at
-      <a class="link" href="http://www.isc.org/donate/" target="_top">http://www.isc.org/donate/</a>.
-    </p>
-  </div>
+  <p>
+    Thank you to everyone who assisted us in making this release possible.
+    If you would like to contribute to ISC to assist us in continuing to
+    make quality open source software, please visit our donations page at
+    <a class="link" href="http://www.isc.org/donate/" target="_top">http://www.isc.org/donate/</a>.
+  </p>
+</div>
 </div>
 </div></body>
 </html>
index d6d1fc3327d25fce9e59c9b05a7a3acaf35bd9fb..5a6ba162ec5b87f183273426c5c6d68623331664 100644 (file)
Binary files a/doc/arm/notes.pdf and b/doc/arm/notes.pdf differ
index 81fd325693323e6ed3f96a2d31a71598e342c35f..3f1e03a787fdac02df539aa7a816217126a21041 100644 (file)
@@ -1,4 +1,4 @@
-Release Notes for BIND Version 9.15.4
+Release Notes for BIND Version 9.15.5
 
 Introduction
 
@@ -50,25 +50,33 @@ operating systems.
 
 Security Fixes
 
+  * The TCP client quota set using the tcp-clients option could be
+    exceeded in some cases. This could lead to exhaustion of file
+    descriptors. This flaw is disclosed in CVE-2018-5743. [GL #615]
+
   * In certain configurations, named could crash with an assertion failure
     if nxdomain-redirect was in use and a redirected query resulted in an
     NXDOMAIN from the cache. This flaw is disclosed in CVE-2019-6467. [GL
     #880]
 
-  * The TCP client quota set using the tcp-clients option could be
-    exceeded in some cases. This could lead to exhaustion of file
-    descriptors. This flaw is disclosed in CVE-2018-5743. [GL #615]
-
   * A race condition could trigger an assertion failure when a large
     number of incoming packets were being rejected. This flaw is disclosed
     in CVE-2019-6471. [GL #942]
 
+  * named could crash with an assertion failure if a forwarder returned a
+    referral, rather than resolving the query, when QNAME minimization was
+    enabled. This flaw is disclosed in CVE-2019-6476. [GL #1501]
+
+  * A flaw in DNSSEC verification when transferring mirror zones could
+    allow data to be incorrectly marked valid. This flaw is disclosed in
+    CVE-2019-6475. [GL #16P]
+
 New Features
 
-  * Added a new command line option to dig: <comand>+[no]unexpected</
-    comand>. By default, dig won't accept a reply from a source other than
-    the one to which it sent the query. Add the +unexpected argument to
-    enable it to process replies from unexpected sources.
+  * Added a new command line option to dig: +[no]unexpected. By default,
+    dig won't accept a reply from a source other than the one to which it
+    sent the query. Add the +unexpected argument to enable it to process
+    replies from unexpected sources.
 
   * The GeoIP2 API from MaxMind is now supported. Geolocation support will
     be compiled in by default if the libmaxminddb library is found at
@@ -202,13 +210,6 @@ Bug Fixes
   * Glue address records were not being returned in responses to root
     priming queries; this has been corrected. [GL #1092]
 
-  * Cache database statistics counters could report invalid values when
-    stale answers were enabled, because of a bug in counter maintenance
-    when cache data becomes stale. The statistics counters have been
-    corrected to report the number of RRsets for each RR type that are
-    active, stale but still potentially served, or stale and marked for
-    deletion. [GL #602]
-
   * Interaction between DNS64 and RPZ No Data rule (CNAME *.) could cause
     unexpected results; this has been fixed. [GL #1106]
 
@@ -221,6 +222,13 @@ Bug Fixes
   * Handle ETIMEDOUT error on connect() with a non-blocking socket. [GL #
     1133]
 
+  * Cache database statistics counters could report invalid values when
+    stale answers were enabled, because of a bug in counter maintenance
+    when cache data becomes stale. The statistics counters have been
+    corrected to report the number of RRsets for each RR type that are
+    active, stale but still potentially served, or stale and marked for
+    deletion. [GL #602]
+
   * dig now correctly expands the IPv6 address when run with +expandaaaa
     +short. [GL #1152]
 
index ceb49d1675308a490992899579d38c1d31af0223..faf692f58daca42b47288f978a98371ffb73a7c6 100644 (file)
@@ -10,6 +10,6 @@
 # 9.12: 1200-1299
 # 9.13/9.14: 1300-1499
 # 9.15/9.16: 1500-1699
-LIBINTERFACE = 1503
+LIBINTERFACE = 1504
 LIBREVISION = 0
-LIBAGE = 0
+LIBAGE = 1
index c72183594a2fed06c8d8cbb65b98d655d9f7d60d..c65b577dfa4128756047803b607070812ab690a3 100644 (file)
@@ -11,5 +11,5 @@
 # 9.13/9.14: 1300-1499
 # 9.15/9.16: 1500-1699
 LIBINTERFACE = 1501
-LIBREVISION = 0
+LIBREVISION = 1
 LIBAGE = 0
index d1ed585b1a486762f7011433b057e905f63f83d8..ceb49d1675308a490992899579d38c1d31af0223 100644 (file)
@@ -10,6 +10,6 @@
 # 9.12: 1200-1299
 # 9.13/9.14: 1300-1499
 # 9.15/9.16: 1500-1699
-LIBINTERFACE = 1502
-LIBREVISION = 1
+LIBINTERFACE = 1503
+LIBREVISION = 0
 LIBAGE = 0
index c72183594a2fed06c8d8cbb65b98d655d9f7d60d..c65b577dfa4128756047803b607070812ab690a3 100644 (file)
@@ -11,5 +11,5 @@
 # 9.13/9.14: 1300-1499
 # 9.15/9.16: 1500-1699
 LIBINTERFACE = 1501
-LIBREVISION = 0
+LIBREVISION = 1
 LIBAGE = 0
index c72183594a2fed06c8d8cbb65b98d655d9f7d60d..c65b577dfa4128756047803b607070812ab690a3 100644 (file)
@@ -11,5 +11,5 @@
 # 9.13/9.14: 1300-1499
 # 9.15/9.16: 1500-1699
 LIBINTERFACE = 1501
-LIBREVISION = 0
+LIBREVISION = 1
 LIBAGE = 0
diff --git a/version b/version
index 8fc4f4257846921bbcd133417b38b906d9a28523..f125284d8a5e1cd62ae582c6452d09a2367cd6f6 100644 (file)
--- a/version
+++ b/version
@@ -5,7 +5,7 @@ PRODUCT=BIND
 DESCRIPTION="(Development Release)"
 MAJORVER=9
 MINORVER=15
-PATCHVER=4
+PATCHVER=5
 RELEASETYPE=
 RELEASEVER=
 EXTENSIONS=