]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
prepare 9.13.1 v9.13.1
authorEvan Hunt <each@isc.org>
Fri, 8 Jun 2018 19:50:21 +0000 (12:50 -0700)
committerEvan Hunt <each@isc.org>
Sun, 10 Jun 2018 05:39:03 +0000 (22:39 -0700)
72 files changed:
CHANGES
README
README.md
bin/dnssec/dnssec-cds.8
bin/dnssec/dnssec-cds.html
bin/dnssec/dnssec-dsfromkey.8
bin/dnssec/dnssec-keyfromlabel.8
bin/dnssec/dnssec-keyfromlabel.html
bin/dnssec/dnssec-keygen.8
bin/dnssec/dnssec-keygen.html
bin/rndc/rndc.8
bin/rndc/rndc.html
doc/arm/Bv9ARM.ch01.html
doc/arm/Bv9ARM.ch02.html
doc/arm/Bv9ARM.ch03.html
doc/arm/Bv9ARM.ch04.html
doc/arm/Bv9ARM.ch05.html
doc/arm/Bv9ARM.ch06.html
doc/arm/Bv9ARM.ch07.html
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.ch09.html
doc/arm/Bv9ARM.ch10.html
doc/arm/Bv9ARM.ch11.html
doc/arm/Bv9ARM.ch12.html
doc/arm/Bv9ARM.html
doc/arm/Bv9ARM.pdf
doc/arm/man.arpaname.html
doc/arm/man.ddns-confgen.html
doc/arm/man.delv.html
doc/arm/man.dig.html
doc/arm/man.dnssec-cds.html
doc/arm/man.dnssec-checkds.html
doc/arm/man.dnssec-coverage.html
doc/arm/man.dnssec-dsfromkey.html
doc/arm/man.dnssec-importkey.html
doc/arm/man.dnssec-keyfromlabel.html
doc/arm/man.dnssec-keygen.html
doc/arm/man.dnssec-keymgr.html
doc/arm/man.dnssec-revoke.html
doc/arm/man.dnssec-settime.html
doc/arm/man.dnssec-signzone.html
doc/arm/man.dnssec-verify.html
doc/arm/man.dnstap-read.html
doc/arm/man.host.html
doc/arm/man.mdig.html
doc/arm/man.named-checkconf.html
doc/arm/man.named-checkzone.html
doc/arm/man.named-journalprint.html
doc/arm/man.named-nzd2nzf.html
doc/arm/man.named-rrchecker.html
doc/arm/man.named.conf.html
doc/arm/man.named.html
doc/arm/man.nsec3hash.html
doc/arm/man.nslookup.html
doc/arm/man.nsupdate.html
doc/arm/man.pkcs11-destroy.html
doc/arm/man.pkcs11-keygen.html
doc/arm/man.pkcs11-list.html
doc/arm/man.pkcs11-tokens.html
doc/arm/man.rndc-confgen.html
doc/arm/man.rndc.conf.html
doc/arm/man.rndc.html
doc/arm/notes.html
doc/arm/notes.pdf
doc/arm/notes.txt
doc/misc/options
lib/bind9/api
lib/dns/api
lib/isc/api
lib/isccfg/api
lib/ns/api
version

diff --git a/CHANGES b/CHANGES
index 5019454462d52ab7c1223a485709d4ff3f945193..24f2a920508af6f711987cd9bf53ad12cef5a4e4 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -1,3 +1,5 @@
+       --- 9.13.1 released ---
+
 4968.  [bug]           If glue records are signed, attempt to validate them.
                        [GL #209]
 
diff --git a/README b/README
index 702af86c0b39abf70c0bbf3a2cd59ba66c908699..8f4315eb588a4b1004d07592e8e359bfeb1ffd73 100644 (file)
--- a/README
+++ b/README
@@ -104,6 +104,7 @@ BIND 9.13 features
 BIND 9.13 is the newest development branch of BIND 9. It includes a number
 of changes from BIND 9.12 and earlier releases. New features include:
 
+  * The default value of "dnssec-validation" is now "auto".
   * Support for IDNA2008 when linking with libidn2.
   * "Root key sentinel" support, enabling validating resolvers to indicate
     via a special query which trust anchors are configured for the root
index 58bd522a0a331aafdd54f1655394109bf2504073..17a4ce6368f2b06e0cb9bb141c0c3f69b0e69454 100644 (file)
--- a/README.md
+++ b/README.md
@@ -122,6 +122,7 @@ BIND 9.13 is the newest development branch of BIND 9. It includes a
 number of changes from BIND 9.12 and earlier releases.  New features
 include:
 
+* The default value of "dnssec-validation" is now "auto".
 * Support for IDNA2008 when linking with `libidn2`.
 * "Root key sentinel" support, enabling validating resolvers to indicate
   via a special query which trust anchors are configured for the root zone.
index 2eaa5318e849cc5588996447926a077fc14ccc45..2048dcec582dbfcb2bc0caeceff12bab304f2728 100644 (file)
@@ -102,7 +102,7 @@ Specify a digest algorithm to use when converting CDNSKEY records to DS records\
 .sp
 The
 \fIalgorithm\fR
-must be one of SHA\-1 (SHA1), SHA\-256 (SHA256), GOST, or SHA\-384 (SHA384)\&. These values are case insensitive\&. If no algorithm is specified, the default is SHA\-256\&.
+must be one of SHA\-1 (SHA1), SHA\-256 (SHA256), or SHA\-384 (SHA384)\&. These values are case insensitive\&. If no algorithm is specified, the default is SHA\-256\&.
 .RE
 .PP
 \-c \fIclass\fR
index c4639d1bcb9a5e9433b141a3a6f6150dfd9b3736..cadb69607f4c7865dc40ad43bc41aad0c5ec85f5 100644 (file)
           </p>
           <p>
            The <em class="replaceable"><code>algorithm</code></em> must be one of SHA-1
-           (SHA1), SHA-256 (SHA256), GOST, or SHA-384 (SHA384). These
+           (SHA1), SHA-256 (SHA256), or SHA-384 (SHA384). These
            values are case insensitive. If no algorithm is specified,
            the default is SHA-256.
           </p>
index 942c657b7a2fd51b162e28ecad3d9b7f8e76de2a..173ac49d938045bd11f4c7f421f947e7569304e6 100644 (file)
@@ -64,7 +64,7 @@ Use SHA\-256 as the digest algorithm\&.
 .RS 4
 Select the digest algorithm\&. The value of
 \fBalgorithm\fR
-must be one of SHA\-1 (SHA1), SHA\-256 (SHA256), GOST or SHA\-384 (SHA384)\&. These values are case insensitive\&.
+must be one of SHA\-1 (SHA1), SHA\-256 (SHA256) or SHA\-384 (SHA384)\&. These values are case insensitive\&.
 .RE
 .PP
 \-C
index d444567da734fc40373067b316ccb1a0ec299b89..ebc20c17f99e67cdc46ada24b7c2bfe38e500f04 100644 (file)
@@ -55,7 +55,7 @@ of the key is specified on the command line\&. This must match the name of the z
 .RS 4
 Selects the cryptographic algorithm\&. The value of
 \fBalgorithm\fR
-must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&.
+must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&.
 .sp
 If no algorithm is specified, then RSASHA1 will be used by default, unless the
 \fB\-3\fR
index 05e32c9fce46d81c26b61d43c5a138bcdb157fcc..d25dcebd62f31bad370adefb4ce7538571a96474 100644 (file)
@@ -90,7 +90,7 @@
          <p>
            Selects the cryptographic algorithm.  The value of
            <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
-           DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
+           DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512,
            ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448.
          </p>
          <p>
index 0aef038c8ec777853b61fe519af0db0ba0d2cb40..5300ed81a1430aa0aafa8ac6cd111583b2fba36c 100644 (file)
@@ -62,7 +62,7 @@ may be preferable to direct use of
 .RS 4
 Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
 \fBalgorithm\fR
-must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TKEY, the value must be DH (Diffie Hellman); specifying his value will automatically set the
+must be one of RSAMD5, RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448\&. For TKEY, the value must be DH (Diffie Hellman); specifying his value will automatically set the
 \fB\-T KEY\fR
 option as well\&.
 .sp
index 19e3e83b4beaccbf7f55ab28009c7d57f997561b..fe28bb439eab7ab0e8d3e56c67bb1d2abbfd7c69 100644 (file)
          <p>
            Selects the cryptographic algorithm.  For DNSSEC keys, the value
            of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
-           DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
+           DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512,
            ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448.  For
            TKEY, the value must be DH (Diffie Hellman); specifying
            his value will automatically set the <code class="option">-T KEY</code>
index c8b4be5aa4d688c3fd59afb79789fc554e9bea02..ca2daec1b17d0aac9edf90e1f6587a10c9c6577d 100644 (file)
@@ -524,13 +524,25 @@ See also
 \fBrndc managed\-keys\fR\&.
 .RE
 .PP
-\fBserve\-stale ( on | off | status | reset ) \fR\fB[\fIclass\fR [\fIview\fR]]\fR
+\fBserve\-stale ( on | off | reset | status ) \fR\fB[\fIclass\fR [\fIview\fR]]\fR
 .RS 4
-Enable, disable, or reset the serving of stale answers as configured in named\&.conf\&. Serving of stale answers will remain disabled across
-named\&.conf
-reloads if disabled via rndc until it is reset via rndc\&.
+Enable, disable, reset, or report the current status of the serving of stale answers as configured in
+named\&.conf\&.
+.sp
+If serving of stale answers is disabled by
+\fBrndc\-serve\-stale off\fR, then it will remain disabled even if
+\fBnamed\fR
+is reloaded or reconfigured\&.
+\fBrndc serve\-stale reset\fR
+restores the setting as configured in
+named\&.conf\&.
 .sp
-Status will report whether serving of stale answers is currently enabled, disabled or not configured for a view\&. If serving of stale records is configured then the values of stale\-answer\-ttl and max\-stale\-ttl are reported\&.
+\fBrndc serve\-stale status\fR
+will report whether serving of stale answers is currently enabled, disabled by the configuration, or disabled by
+\fBrndc\fR\&. It will also report the values of
+\fBstale\-answer\-ttl\fR
+and
+\fBmax\-stale\-ttl\fR\&.
 .RE
 .PP
 \fBshowzone \fR\fB\fIzone\fR\fR\fB \fR\fB[\fIclass\fR [\fIview\fR]]\fR\fB \fR
index adc67481b593b7533a86e2862ab31d0dd3c4def3..97b77cb8dc5e75075e8d1e1fda4e1820eb6611ff 100644 (file)
            See also <span class="command"><strong>rndc managed-keys</strong></span>.
          </p>
        </dd>
-<dt><span class="term"><strong class="userinput"><code>serve-stale ( on | off | status | reset ) [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
+<dt><span class="term"><strong class="userinput"><code>serve-stale ( on | off | reset | status ) [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
 <dd>
          <p>
-           Enable, disable, or reset the serving of stale answers
-           as configured in named.conf. Serving of stale answers
-           will remain disabled across <code class="filename">named.conf</code>
-           reloads if disabled via rndc until it is reset via rndc.
+           Enable, disable, reset, or report the current status
+            of the serving of stale answers as configured in
+            <code class="filename">named.conf</code>.
          </p>
          <p>
-           Status will report whether serving of stale answers is
-           currently enabled, disabled or not configured for a
-           view.  If serving of stale records is configured then
-           the values of stale-answer-ttl and max-stale-ttl are
-           reported.
+            If serving of stale answers is disabled by
+            <span class="command"><strong>rndc-serve-stale off</strong></span>, then it
+           will remain disabled even if <span class="command"><strong>named</strong></span>
+            is reloaded or reconfigured.
+            <span class="command"><strong>rndc serve-stale reset</strong></span> restores
+            the setting as configured in <code class="filename">named.conf</code>.
+         </p>
+         <p>
+           <span class="command"><strong>rndc serve-stale status</strong></span> will report
+            whether serving of stale answers is currently enabled,
+            disabled by the configuration, or disabled by
+            <span class="command"><strong>rndc</strong></span>.  It will also report the
+           values of <span class="command"><strong>stale-answer-ttl</strong></span> and
+           <span class="command"><strong>max-stale-ttl</strong></span>.
          </p>
        </dd>
 <dt><span class="term"><strong class="userinput"><code>showzone <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>] </code></strong></span></dt>
index dd9928894eb14a787698ac49474d7ad37a1e4202..d3bcf3cd744d9cb25975673caf856636b742ccdc 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index f7e2bb7beb8c2e575b638458d8bc025647c2c12b..883fc13377992ffce9e4e92f0ecbb37d4b7b12b3 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 4e3b5bb584079dc2d4c3af1bfcec3ff854fb8457..c361dfc54377f608160ea688feffd0bff45437ac 100644 (file)
@@ -759,6 +759,6 @@ controls {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 48ef8a2337b977d998d8898916dbb72d924232e5..0b1f380f34b0e7a913b13f202dffe6e6bd248610 100644 (file)
@@ -1034,28 +1034,36 @@ allow-update { !{ !localnets; any; }; key host1-host2. ;};
           To enable <span class="command"><strong>named</strong></span> to respond appropriately
           to DNS requests from DNSSEC aware clients,
           <span class="command"><strong>dnssec-enable</strong></span> must be set to yes.
-          (This is the default setting.)
+          This is the default setting.
         </p>
 
         <p>
           To enable <span class="command"><strong>named</strong></span> to validate answers from
           other servers, the <span class="command"><strong>dnssec-enable</strong></span> option
           must be set to <strong class="userinput"><code>yes</code></strong>, and the
-          <span class="command"><strong>dnssec-validation</strong></span> options must be set to
-          <strong class="userinput"><code>yes</code></strong> or <strong class="userinput"><code>auto</code></strong>.
+          <span class="command"><strong>dnssec-validation</strong></span> option must be set to
+          either <strong class="userinput"><code>yes</code></strong> or <strong class="userinput"><code>auto</code></strong>.
         </p>
 
         <p>
+          When <span class="command"><strong>dnssec-validation</strong></span> is set to
+          <strong class="userinput"><code>auto</code></strong>, a trust anchor for the DNS
+          root zone will automatically be used. This trust anchor is
+          provided as part of BIND and is kept up to date using RFC 5011
+          key management.
           If <span class="command"><strong>dnssec-validation</strong></span> is set to
-          <strong class="userinput"><code>auto</code></strong>, then a default
-          trust anchor for the DNS root zone will be used.
-          If it is set to <strong class="userinput"><code>yes</code></strong>, however,
-          then at least one trust anchor must be configured
-          with a <span class="command"><strong>trusted-keys</strong></span> or
-          <span class="command"><strong>managed-keys</strong></span> statement in
-          <code class="filename">named.conf</code>, or DNSSEC validation
-          will not occur.  The default setting is
-          <strong class="userinput"><code>yes</code></strong>.
+          <strong class="userinput"><code>yes</code></strong>, then
+          DNSSEC validation only occurs if
+          at least one trust anchor has been explicitly configured
+          in <code class="filename">named.conf</code>,
+          using a <span class="command"><strong>trusted-keys</strong></span> or
+          <span class="command"><strong>managed-keys</strong></span> statement.
+          If <span class="command"><strong>dnssec-validation</strong></span> is set to
+          <strong class="userinput"><code>no</code></strong>, then DNSSEC validation will
+          not occur.
+          The default is <strong class="userinput"><code>auto</code></strong> unless BIND is
+          built with <span class="command"><strong>configure --disable-auto-validation</strong></span>,
+          in which case the default is <strong class="userinput"><code>yes</code></strong>.
         </p>
 
         <p>
@@ -1702,7 +1710,7 @@ $ <strong class="userinput"><code>./configure --enable-native-pkcs11 \
       </p>
       <pre class="screen">
 $ <strong class="userinput"><code> cd SoftHSMv2 </code></strong>
-$ <strong class="userinput"><code> configure --with-crypto-backend=openssl --prefix=/opt/pkcs11/usr --enable-gost </code></strong>
+$ <strong class="userinput"><code> configure --with-crypto-backend=openssl --prefix=/opt/pkcs11/usr </code></strong>
 $ <strong class="userinput"><code> make </code></strong>
 $ <strong class="userinput"><code> make install </code></strong>
 $ <strong class="userinput"><code> /opt/pkcs11/usr/bin/softhsm-util --init-token 0 --slot 0 --label softhsmv2 </code></strong>
@@ -2867,6 +2875,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 3609e50faf4dd41953c6d55d5248f73a6d710faa..2cb056a86831cc92c57a110a331b1edf74a59b80 100644 (file)
@@ -1564,6 +1564,7 @@ notrace</strong></span>. All debugging messages in the server have a debug
     syslog daemon;
     // only send priority info and higher
     severity info;
+};
 
 channel default_debug {
     // write to named.run in the working directory
@@ -1865,6 +1866,16 @@ category notify { null; };
        </td>
 </tr>
 <tr>
+<td>
+         <p><span class="command"><strong>nsid</strong></span></p>
+       </td>
+<td>
+         <p>
+           NSID options received from upstream servers.
+         </p>
+       </td>
+</tr>
+<tr>
 <td>
          <p><span class="command"><strong>queries</strong></span></p>
        </td>
@@ -1987,6 +1998,17 @@ category notify { null; };
        </td>
 </tr>
 <tr>
+<td>
+         <p><span class="command"><strong>serve-stale</strong></span></p>
+       </td>
+<td>
+         <p>
+           Whether or not a stale answer is used
+           following a resolver failure.
+         </p>
+       </td>
+</tr>
+<tr>
 <td>
          <p><span class="command"><strong>spill</strong></span></p>
        </td>
@@ -3663,12 +3685,13 @@ options {
                 Specifies the TTL to be returned on stale answers.
                 The default is 1 second. The minimum allowed is
                 also 1 second; a value of 0 will be updated silently
-                to 1 second.  For stale answers to be returned,
-                they must be enabled (either in the configuration file
-                using <span class="command"><strong>stale-answer-enable</strong></span> or via
-                <span class="command"><strong>rndc</strong></span>), and
-                <code class="option">max-stale-ttl</code> must be set to a
-                nonzero value.
+                to 1 second.
+              </p>
+              <p>
+                For stale answers to be returned, they must be enabled,
+                either in the configuration file using
+                <span class="command"><strong>stale-answer-enable</strong></span> or via
+                <span class="command"><strong>rndc serve-stale on</strong></span>.
               </p>
             </dd>
 <dt><span class="term"><span class="command"><strong>serial-update-method</strong></span></span></dt>
@@ -4055,7 +4078,7 @@ options {
 <dt><span class="term"><span class="command"><strong>fetch-glue</strong></span></span></dt>
 <dd>
                 <p>
-                  This option is obsolete.
+                  <span class="emphasis"><em>This option is obsolete</em></span>.
                   In BIND 8, <strong class="userinput"><code>fetch-glue yes</code></strong>
                   caused the server to attempt to fetch glue resource records
                   it
@@ -4077,12 +4100,9 @@ options {
 <dt><span class="term"><span class="command"><strong>geoip-use-ecs</strong></span></span></dt>
 <dd>
                 <p>
-                  When BIND is compiled with GeoIP support and configured
-                  with "geoip" ACL elements, this option indicates whether
-                  the EDNS Client Subnet option, if present in a request,
-                  should be used for matching against the GeoIP database.
-                  The default is
-                  <span class="command"><strong>geoip-use-ecs</strong></span> <strong class="userinput"><code>yes</code></strong>.
+                  This option was part of an experimental implementation
+                  of the EDNS CLIENT-SUBNET for authoritative servers,
+                  but is now obsolete.
                 </p>
               </dd>
 <dt><span class="term"><span class="command"><strong>has-old-clients</strong></span></span></dt>
@@ -4290,7 +4310,7 @@ options {
                   queries to authoritative name servers during iterative
                   resolution. If the authoritative server returns an NSID
                   option in its response, then its contents are logged in
-                  the <span class="command"><strong>resolver</strong></span> category at level
+                  the <span class="command"><strong>nsid</strong></span> category at level
                   <span class="command"><strong>info</strong></span>.
                   The default is <strong class="userinput"><code>no</code></strong>.
                 </p>
@@ -4310,6 +4330,15 @@ options {
                   server cookie.
                 </p>
               </dd>
+<dt><span class="term"><span class="command"><strong>answer-cookie</strong></span></span></dt>
+<dd>
+                <p>
+                  <span class="emphasis"><em>This option is obsolete</em></span>.
+                  This option was used to prevent the sending of
+                  a DNS COOKIE option in response to a request with
+                  one present in BIND 9.11 and BIND 9.12.
+                </p>
+              </dd>
 <dt><span class="term"><span class="command"><strong>send-cookie</strong></span></span></dt>
 <dd>
                 <p>
@@ -4333,18 +4362,28 @@ options {
 <dt><span class="term"><span class="command"><strong>stale-answer-enable</strong></span></span></dt>
 <dd>
                 <p>
-                  Enable the returning of stale answers when the
-                  nameservers for the zone are not answering.  This
-                  is off by default, but can be enabled/disabled via
-                  <span class="command"><strong>rndc serve-stale on</strong></span> and
-                  <span class="command"><strong>rndc serve-stale off</strong></span>, which
-                  override the <code class="filename">named.conf</code>
-                  setting.  <span class="command"><strong>rndc serve-stale reset</strong></span>
+                  Enable the returning of "stale" cached answers when
+                  the nameservers for a zone are not answering.  The
+                  default is not to return stale answers.
+                </p>
+                <p>
+                  Stale answers can also be enabled or disabled at
+                  runtime via <span class="command"><strong>rndc serve-stale on</strong></span> or
+                  <span class="command"><strong>rndc serve-stale off</strong></span>; these
+                  override the configured setting.
+                  <span class="command"><strong>rndc serve-stale reset</strong></span>
                   restores the setting to the one specified in
-                  <code class="filename">named.conf</code>.  Note that
-                  reloading or reconfiguring <span class="command"><strong>named</strong></span>
-                  will not re-enable serving of stale records if they
-                  have been disabled via <span class="command"><strong>rndc</strong></span>.
+                  <code class="filename">named.conf</code>.  Note that if
+                  stale answers have been disabled by <span class="command"><strong>rndc</strong></span>,
+                  then they cannot be re-enabled by reloading or
+                  reconfiguring <span class="command"><strong>named</strong></span>;
+                  they must be re-enabled with
+                  <span class="command"><strong>rndc serve-stale on</strong></span>,
+                  or the server must be restarted.
+                </p>
+                <p>
+                  Information about stale answers is logged under
+                  the <span class="command"><strong>serve-stale</strong></span> log category.
                 </p>
               </dd>
 <dt><span class="term"><span class="command"><strong>nocookie-udp-size</strong></span></span></dt>
@@ -6851,19 +6890,21 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
 <dt><span class="term"><span class="command"><strong>max-stale-ttl</strong></span></span></dt>
 <dd>
                 <p>
-                  Sets the maximum time for which the server will
+                  If stale answers are enabled,
+                  <span class="command"><strong>max-stale-ttl</strong></span>
+                  sets the maximum time for which the server will
                   retain records past their normal expiry to
                   return them as stale records when the servers
-                  for those records are not reachable.  The default
-                  is to not retain the record.
+                  for those records are not reachable.
+                  The default is 1 week. The minimum allowed is
+                  1 second; a value of 0 will be updated silently
+                  to 1 second.
                 </p>
                 <p>
-                  <span class="command"><strong>rndc serve-stale</strong></span> can be used
-                  to disable and re-enable the serving of stale
-                  records at runtime.  Reloading or reconfiguring
-                  <span class="command"><strong>named</strong></span> will not re-enable serving
-                  of stale records if they have been disabled via
-                  <span class="command"><strong>rndc</strong></span>.
+                  For stale answers to be returned, they must be enabled,
+                  either in the configuration file using
+                  <span class="command"><strong>stale-answer-enable</strong></span> or via
+                  <span class="command"><strong>rndc serve-stale on</strong></span>.
                 </p>
               </dd>
 <dt><span class="term"><span class="command"><strong>min-roots</strong></span></span></dt>
@@ -7435,6 +7476,8 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
 <li class="listitem">9.E.F.IP6.ARPA</li>
 <li class="listitem">A.E.F.IP6.ARPA</li>
 <li class="listitem">B.E.F.IP6.ARPA</li>
+<li class="listitem">EMPTY.AS112.ARPA</li>
+<li class="listitem">HOME.ARPA</li>
 </ul></div>
 <p>
           </p>
@@ -14672,6 +14715,6 @@ HOST-127.EXAMPLE. MX 0 .
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 3bed6c52154be3bf48b05410cc4fe4c4c720fdc2..8a2d3c293aba1dafa1fd655eae8d9d90a1f6af61 100644 (file)
@@ -118,38 +118,8 @@ zone "example.com" {
           In addition to network addresses and prefixes, which are
           matched against the source address of the DNS request, ACLs
           may include <code class="option">key</code> elements, which specify the
-          name of a TSIG or SIG(0) key, or <code class="option">ecs</code>
-          elements, which specify a network prefix but are only matched
-          if that prefix matches an EDNS client subnet option included
-          in the request.
+          name of a TSIG or SIG(0) key.
         </p>
-        <p>
-          The EDNS Client Subnet (ECS) option is used by a recursive
-          resolver to inform an authoritative name server of the network
-          address block from which the original query was received, enabling
-          authoritative servers to give different answers to the same
-          resolver for different resolver clients.  An ACL containing
-          an element of the form
-          <span class="command"><strong>ecs <em class="replaceable"><code>prefix</code></em></strong></span>
-          will match if a request arrives in containing an ECS option
-          encoding an address within that prefix.  If the request has no
-          ECS option, then "ecs" elements are simply ignored.  Addresses
-          in ACLs that are not prefixed with "ecs" are matched only
-          against the source address.
-        </p>
-        <div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
-<h3 class="title">Note</h3>
-          <p>
-            (Note: The authoritative ECS implementation in
-            <span class="command"><strong>named</strong></span> is based on an early version of the
-            specification, and is known to have incompatibilities with
-            other implementations.  It is also inefficient, requiring
-            a separate view for each client subnet to be sent different
-            answers, and it is unable to correct for overlapping subnets in
-            the configuration.  It can be used for testing purposes, but is
-            not recommended for production use.)
-          </p>
-        </div>
         <p>
           When <acronym class="acronym">BIND</acronym> 9 is built with GeoIP support,
           ACLs can also be used for geographic access restrictions.
@@ -194,14 +164,6 @@ zone "example.com" {
           database if it is installed, or the "region" database if it is
           installed, or the "country" database, in that order.
         </p>
-        <p>
-          By default, if a DNS query includes an EDNS Client Subnet (ECS)
-          option which encodes a non-zero address prefix, then GeoIP ACLs
-          will be matched against that address prefix.  Otherwise, they
-          are matched against the source address of the query.  To
-          prevent GeoIP ACLs from matching against ECS options, set
-          the <span class="command"><strong>geoip-use-ecs</strong></span> to <code class="literal">no</code>.
-        </p>
         <p>
           Some example GeoIP ACLs:
         </p>
@@ -399,6 +361,6 @@ allow-query { !{ !10/8; any; }; key example; };
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index d6ab258963c320b045495ad026494fbfc7dc4cd7..11eedc07e361d4592a7b82c64fa75302b25a9ee4 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index f3461dacb80b7143aa0e10a989c43111961095d6..8e465ba54f1d2573a3d1a32307f3ce3e099449ee 100644 (file)
@@ -36,7 +36,7 @@
 <div class="toc">
 <p><b>Table of Contents</b></p>
 <dl class="toc">
-<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.13.0</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.13.1</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
@@ -54,7 +54,7 @@
 </div>
       <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.9.2"></a>Release Notes for BIND Version 9.13.0</h2></div></div></div>
+<a name="id-1.9.2"></a>Release Notes for BIND Version 9.13.1</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         None.
+         When recursion is enabled but the <span class="command"><strong>allow-recursion</strong></span>
+         and <span class="command"><strong>allow-query-cache</strong></span> ACLs are not specified, they
+         should be limited to local networks, but they were inadvertently set
+         to match the default <span class="command"><strong>allow-query</strong></span>, thus allowing
+         remote queries. This flaw is disclosed in CVE-2018-5738. [GL #309]
        </p>
       </li></ul></div>
   </div>
 <li class="listitem">
        <p>
          <span class="command"><strong>named</strong></span> now supports the "root key sentinel"
-         mechanism. This enables validating resolvers to indicate to
+         mechanism. This enables validating resolvers to indicate
          which trust anchors are configured for the root, so that
          information about root key rollover status can be gathered.
          To disable this feature, add
          <span class="command"><strong>root-key-sentinel no;</strong></span> to
-         <code class="filename">named.conf</code>.
+         <code class="filename">named.conf</code>. [GL #37]
        </p>
       </li>
 <li class="listitem">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_removed"></a>Removed Features</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+       <p>
+         <span class="command"><strong>named</strong></span> can no longer use the EDNS CLIENT-SUBNET
+         option for view selection.  In its existing form, the authoritative
+         ECS feature was not fully RFC-compliant, and could not realistically
+         have been deployed in production for an authoritative server; its
+         only practical use was for testing and experimentation. In the
+         interest of code simplification, this feature has now been removed.
+       </p>
+       <p>
+         The ECS option is still supported in <span class="command"><strong>dig</strong></span> and
+         <span class="command"><strong>mdig</strong></span> via the +subnet argument, and can be parsed
+         and logged when received by <span class="command"><strong>named</strong></span>, but
+         it is no longer used for ACL processing. The
+         <span class="command"><strong>geoip-use-ecs</strong></span> option is now obsolete;
+         a warning will be logged if it is used in
+         <code class="filename">named.conf</code>.
+         <span class="command"><strong>ecs</strong></span> tags in an ACL definition are
+         also obsolete, and will cause the configuration to fail to
+         load if they are used. [GL #32]
+       </p>
+      </li>
 <li class="listitem">
        <p>
          <span class="command"><strong>dnssec-keygen</strong></span> can no longer generate HMAC
          command.
        </p>
       </li>
+<li class="listitem">
+       <p>
+         Support for ECC-GOST (GOST R 34.11-94) algorithm has been
+         removed from BIND as the algorithm has been superseded by
+         GOST R 34.11-2012 in RFC6986 and it must not be used in new
+         deployments.  BIND will neither create new DNSSEC keys,
+         signatures and digest, nor it will validate them.
+       </p>
+      </li>
 </ul></div>
   </div>
 
          resort. [GL #221]
        </p>
       </li>
+<li class="listitem">
+       <p>
+         The default setting for <span class="command"><strong>dnssec-validation</strong></span> is
+         now <strong class="userinput"><code>auto</code></strong>, which activates DNSSEC
+         validation using the IANA root key. (The default can be changed
+         back to <strong class="userinput"><code>yes</code></strong>, which activates DNSSEC
+         validation only when keys are explicitly configured in
+         <code class="filename">named.conf</code>, by building BIND with
+         <span class="command"><strong>configure --disable-auto-validation</strong></span>.) [GL #30]
+       </p>
+      </li>
 <li class="listitem">
        <p>
          BIND can no longer be built without DNSSEC support. A cryptography
          [GL #203]
        </p>
       </li>
+<li class="listitem">
+       <p>
+         NSID logging (enabled by the <span class="command"><strong>request-nsid</strong></span>
+         option) now has its own <span class="command"><strong>nsid</strong></span> category,
+         instead of using the <span class="command"><strong>resolver</strong></span> category.
+       </p>
+      </li>
 </ul></div>
   </div>
 
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 4de17c421e580980af465e66f193d9dc9334a1ff..f98094686212d0719f3772d6da4e69120c96f6a6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 212d08cd17f474eec826c7b11e68e79b3c2429d6..a632958a7ad56337132441b7dd5572f2450f5fe4 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 674ca2d20bb52431124e29bf610a82664113ddd6..8da69d14b4bde07648c1c52432116e66b84b1ec1 100644 (file)
@@ -533,6 +533,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 78fe495d3ccb85d07a57d1cd8b2c0d9900d16c85..4f527a66aaaed0a976aad19c47c439906b7dc87a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index fea007da75d70381989d9de3cc238ff646f3fef0..a54219b28f41c5fdb39e63c3db2d60219c3b5084 100644 (file)
@@ -32,7 +32,7 @@
 <div>
 <div><h1 class="title">
 <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
-<div><p class="releaseinfo">BIND Version 9.13.0</p></div>
+<div><p class="releaseinfo">BIND Version 9.13.1</p></div>
 <div><p class="copyright">Copyright Â© 2000-2018 Internet Systems Consortium, Inc. ("ISC")</p></div>
 </div>
 <hr>
 </dl></dd>
 <dt><span class="appendix"><a href="Bv9ARM.ch08.html">A. Release Notes</a></span></dt>
 <dd><dl>
-<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.13.0</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.13.1</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 1062bc59cd4bc4d93f93669bae4b7e85868bfc4d..3402436b95e98656a63e3268589375ce074f563c 100644 (file)
Binary files a/doc/arm/Bv9ARM.pdf and b/doc/arm/Bv9ARM.pdf differ
index 826110699543f580632094cc595bcc48c05d5e43..539a0c34030a6f8274354e2c82c202152f0f5094 100644 (file)
@@ -90,6 +90,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 1f944e854de591b932d980bf11dc9ddb1161f2e7..4355f6d6e3235593c1413bbe8fa854bb08310545 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 190ec6861fd6691647f15dedf70a18f8e60b87c2..be0255c7fc4313fc53c7aa2852bf3d0c40687bb3 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 56d6661f267e3c749d24ee0923b6d2e5942faec8..b3b7c5edc231253627a286beaf8e0a598d1a8e27 100644 (file)
@@ -1138,6 +1138,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index d9a65d88d83ec623a7a92853c35bbc2c6a24fcac..43263f415a3bf0751354c64f959e2165691fd106 100644 (file)
           </p>
           <p>
            The <em class="replaceable"><code>algorithm</code></em> must be one of SHA-1
-           (SHA1), SHA-256 (SHA256), GOST, or SHA-384 (SHA384). These
+           (SHA1), SHA-256 (SHA256), or SHA-384 (SHA384). These
            values are case insensitive. If no algorithm is specified,
            the default is SHA-256.
           </p>
@@ -376,6 +376,6 @@ nsupdate -l
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 860e1ce79200472790ae89873f942f7c93396a38..7cbc8b3e5a4fdd6b706a43d46197796511f41752 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 85dedf19481635063e2b2ea995f141d9f9ad100d..0fb20c818d66f08d8b48ab622d5169c725654251 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 2103f507c30d2eef4d7e6b7e7ad6823888e96c76..1fa88b17dd71ce0dd48042956a9d59a44f065efa 100644 (file)
          <p>
            Select the digest algorithm. The value of
            <code class="option">algorithm</code> must be one of SHA-1 (SHA1),
-           SHA-256 (SHA256), GOST or SHA-384 (SHA384).
+           SHA-256 (SHA256) or SHA-384 (SHA384).
            These values are case insensitive.
          </p>
        </dd>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index eaeb9e31f36e33bec08876e6c658b32e07ada665..ca8a348eef5e264d2bd8c6164740011c71d295a7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index c5e0ed689cddf4e1a2d1512b3324437e88f10125..eaa3e3725aec14d109838b6e08cedcd7a98e53d5 100644 (file)
          <p>
            Selects the cryptographic algorithm.  The value of
            <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
-           DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
+           DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512,
            ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448.
          </p>
          <p>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index f4c8fe3c0e37246588f1dd1757449a769cafc01a..e5ea4d49cb011793536deeac23e5bdde3eeabdd9 100644 (file)
          <p>
            Selects the cryptographic algorithm.  For DNSSEC keys, the value
            of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
-           DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
+           DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512,
            ECDSAP256SHA256, ECDSAP384SHA384, ED25519 or ED448.  For
            TKEY, the value must be DH (Diffie Hellman); specifying
            his value will automatically set the <code class="option">-T KEY</code>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index c76a537e496cdd64ca24fa2b75cc47c2ae38ea3a..46eec521a58e60cf32882c9d290891f8e9b5ced7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 2452616892cb062fd68feed5eb44586a1f1e3d34..f64712afe71686afd10aab61d682a15c488397e8 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index ee667fcc698962ac6ce33d86268d1da9d844ef54..114c69497f7bf3be16092a9f77aa165547ee23ae 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 67cc2a05850454ea4757c00d90a3867742cc6d36..b3f15e90f600081f1f256dc89c6deb23535199ca 100644 (file)
@@ -700,6 +700,6 @@ db.example.com.signed
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index c9a49025671aa9cac734267e0a38de74007e41cb..5e67319921955a4bc05e9341c3fd5ec3d43bb052 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 1a7c556349394a4f93621ca8b0638e1258b8a165..d6f78df0ff69bde81bca792298af6270f34db557 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 8f22a1efe4188768814f35262d8a579e7ba85a1d..51d1feb7d260476b07f7b487cbd3a822de5bff6b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 5b92154e61794a186e2bdc610fcc980df9696760..a5ea3b4a8c3970ccf489d6ac08a00bcf62cc4c93 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 4f613a52f601a2fc7fd7ae373450dfbc8926520b..a0937c71b9b608b049ca1b3718ebde049d643734 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 2033a1f639c032cf502af9d361d3c75e317a4e82..ae757b8a0c40b4379085d7cad7f31d895f07ab90 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 154f4d99d87ccf5488ae24666077305b44e08301..7fe80bb2e9de5e5f229cf3e92d2749bd6e7f761f 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index feb9097f3f2f268a50f0af638c8333bad7e267c1..d96477993a8f1d4a978efd0ac0ebdd6346fafdc5 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 3fc4a8a7f2d8d2ef8d43a072ffda1660888b0a69..f4500ea9497bc651ced2de409f85931d81360262 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 800c8c263fd6cbab42304db6c0b0e650683a5c6d..148490eca4aea424de9f4ea50fa891f906bb40db 100644 (file)
@@ -1057,6 +1057,6 @@ zone
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index afdc91cbdd2d9297aa8b1c266453ccfb38fe1618..ef1ca972d5338e9aec73ec00947429226d7a749a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 760ea3a248fb998be1d5465e68e50a942eb12da6..e606b9ca202e85e6d5642b62a0ee0d59d0cbe1c0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 9e419a49ba550f4814bb459c5c5a0b4d7d384fa4..1b81135c3f093ec57c23963117e54d390bb24ddf 100644 (file)
@@ -420,6 +420,6 @@ nslookup -query=hinfo  -timeout=10
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index e9eb2dc0a4dd9f12325410bc2dfd8fa11a02de0f..7bb6ecdb0e672e67c8dfbe22df3935bf270fae94 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index d11b1b05625958558d3b8662a25a22b3bdc4e5dd..73972fad856f3763ad2f8fa2cfcee7df5d875daa 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 9417f6626b589582813ca1ed6809931a633e5e3f..7f314c46cc8a8fa907a8de3b0d388fdea05616e0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 64638eb7e52aacfef76053e11f9c1a60f72ce6b3..d8e110a2008b669dcbdcc6e39835c6e9ab44b21b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 58673d376f12136d11a80e700ebf2c3062525e3f..5fff2b1c24ca50ab83500f07a0f4041f09152aa2 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 0b6a4d3536ab2499f00e7de3a7041472f3a488ba..773fce6f08e1cd38d8358b22f6cb62f791aa8c57 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index 1d137bcafc6a4bd0831974f21876a1d49e74b4dd..d5fd1a25ef1376077e15bec69469adce4d588c92 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index fc2077fcec65780e273a7f3d0f25ac9d23ea6f4e..4f6c5f5c26eb4690c06c11a303a705ec21bf6b45 100644 (file)
            See also <span class="command"><strong>rndc managed-keys</strong></span>.
          </p>
        </dd>
-<dt><span class="term"><strong class="userinput"><code>serve-stale ( on | off | status | reset ) [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
+<dt><span class="term"><strong class="userinput"><code>serve-stale ( on | off | reset | status ) [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
 <dd>
          <p>
-           Enable, disable, or reset the serving of stale answers
-           as configured in named.conf. Serving of stale answers
-           will remain disabled across <code class="filename">named.conf</code>
-           reloads if disabled via rndc until it is reset via rndc.
+           Enable, disable, reset, or report the current status
+            of the serving of stale answers as configured in
+            <code class="filename">named.conf</code>.
          </p>
          <p>
-           Status will report whether serving of stale answers is
-           currently enabled, disabled or not configured for a
-           view.  If serving of stale records is configured then
-           the values of stale-answer-ttl and max-stale-ttl are
-           reported.
+            If serving of stale answers is disabled by
+            <span class="command"><strong>rndc-serve-stale off</strong></span>, then it
+           will remain disabled even if <span class="command"><strong>named</strong></span>
+            is reloaded or reconfigured.
+            <span class="command"><strong>rndc serve-stale reset</strong></span> restores
+            the setting as configured in <code class="filename">named.conf</code>.
+         </p>
+         <p>
+           <span class="command"><strong>rndc serve-stale status</strong></span> will report
+            whether serving of stale answers is currently enabled,
+            disabled by the configuration, or disabled by
+            <span class="command"><strong>rndc</strong></span>.  It will also report the
+           values of <span class="command"><strong>stale-answer-ttl</strong></span> and
+           <span class="command"><strong>max-stale-ttl</strong></span>.
          </p>
        </dd>
 <dt><span class="term"><strong class="userinput"><code>showzone <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>] </code></strong></span></dt>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.0 (Development Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.13.1 (Development Release)</p>
 </body>
 </html>
index db17c9a95318c51f5ee356d68099bafc74877f96..96024a4fb7377f0c079f94cb07a6fb16d7ad2092 100644 (file)
@@ -15,7 +15,7 @@
 
   <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.2"></a>Release Notes for BIND Version 9.13.0</h2></div></div></div>
+<a name="id-1.2"></a>Release Notes for BIND Version 9.13.1</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         None.
+         When recursion is enabled but the <span class="command"><strong>allow-recursion</strong></span>
+         and <span class="command"><strong>allow-query-cache</strong></span> ACLs are not specified, they
+         should be limited to local networks, but they were inadvertently set
+         to match the default <span class="command"><strong>allow-query</strong></span>, thus allowing
+         remote queries. This flaw is disclosed in CVE-2018-5738. [GL #309]
        </p>
       </li></ul></div>
   </div>
 <li class="listitem">
        <p>
          <span class="command"><strong>named</strong></span> now supports the "root key sentinel"
-         mechanism. This enables validating resolvers to indicate to
+         mechanism. This enables validating resolvers to indicate
          which trust anchors are configured for the root, so that
          information about root key rollover status can be gathered.
          To disable this feature, add
          <span class="command"><strong>root-key-sentinel no;</strong></span> to
-         <code class="filename">named.conf</code>.
+         <code class="filename">named.conf</code>. [GL #37]
        </p>
       </li>
 <li class="listitem">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_removed"></a>Removed Features</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+       <p>
+         <span class="command"><strong>named</strong></span> can no longer use the EDNS CLIENT-SUBNET
+         option for view selection.  In its existing form, the authoritative
+         ECS feature was not fully RFC-compliant, and could not realistically
+         have been deployed in production for an authoritative server; its
+         only practical use was for testing and experimentation. In the
+         interest of code simplification, this feature has now been removed.
+       </p>
+       <p>
+         The ECS option is still supported in <span class="command"><strong>dig</strong></span> and
+         <span class="command"><strong>mdig</strong></span> via the +subnet argument, and can be parsed
+         and logged when received by <span class="command"><strong>named</strong></span>, but
+         it is no longer used for ACL processing. The
+         <span class="command"><strong>geoip-use-ecs</strong></span> option is now obsolete;
+         a warning will be logged if it is used in
+         <code class="filename">named.conf</code>.
+         <span class="command"><strong>ecs</strong></span> tags in an ACL definition are
+         also obsolete, and will cause the configuration to fail to
+         load if they are used. [GL #32]
+       </p>
+      </li>
 <li class="listitem">
        <p>
          <span class="command"><strong>dnssec-keygen</strong></span> can no longer generate HMAC
          command.
        </p>
       </li>
+<li class="listitem">
+       <p>
+         Support for ECC-GOST (GOST R 34.11-94) algorithm has been
+         removed from BIND as the algorithm has been superseded by
+         GOST R 34.11-2012 in RFC6986 and it must not be used in new
+         deployments.  BIND will neither create new DNSSEC keys,
+         signatures and digest, nor it will validate them.
+       </p>
+      </li>
 </ul></div>
   </div>
 
          resort. [GL #221]
        </p>
       </li>
+<li class="listitem">
+       <p>
+         The default setting for <span class="command"><strong>dnssec-validation</strong></span> is
+         now <strong class="userinput"><code>auto</code></strong>, which activates DNSSEC
+         validation using the IANA root key. (The default can be changed
+         back to <strong class="userinput"><code>yes</code></strong>, which activates DNSSEC
+         validation only when keys are explicitly configured in
+         <code class="filename">named.conf</code>, by building BIND with
+         <span class="command"><strong>configure --disable-auto-validation</strong></span>.) [GL #30]
+       </p>
+      </li>
 <li class="listitem">
        <p>
          BIND can no longer be built without DNSSEC support. A cryptography
          [GL #203]
        </p>
       </li>
+<li class="listitem">
+       <p>
+         NSID logging (enabled by the <span class="command"><strong>request-nsid</strong></span>
+         option) now has its own <span class="command"><strong>nsid</strong></span> category,
+         instead of using the <span class="command"><strong>resolver</strong></span> category.
+       </p>
+      </li>
 </ul></div>
   </div>
 
index 2ffa114b9ce5dca4f8e903d42c6cb69ce2f178b9..987ce27735709b8f450c511124e4821682ab1b0f 100644 (file)
Binary files a/doc/arm/notes.pdf and b/doc/arm/notes.pdf differ
index be47b989765d68d6fa28ff773723758d74954177..7df71bd749989b2297058094e62f243625ac6d4a 100644 (file)
@@ -1,4 +1,4 @@
-Release Notes for BIND Version 9.13.0
+Release Notes for BIND Version 9.13.1
 
 Introduction
 
@@ -33,7 +33,11 @@ operating systems.
 
 Security Fixes
 
-  * None.
+  * When recursion is enabled but the allow-recursion and
+    allow-query-cache ACLs are not specified, they should be limited to
+    local networks, but they were inadvertently set to match the default
+    allow-query, thus allowing remote queries. This flaw is disclosed in
+    CVE-2018-5738. [GL #309]
 
 New Features
 
@@ -42,16 +46,30 @@ New Features
     and unsupported) idnkit-1 library.
 
   * named now supports the "root key sentinel" mechanism. This enables
-    validating resolvers to indicate to which trust anchors are configured
+    validating resolvers to indicate which trust anchors are configured
     for the root, so that information about root key rollover status can
     be gathered. To disable this feature, add root-key-sentinel no; to
-    named.conf.
+    named.conf. [GL #37]
 
   * The dnskey-sig-validity option allows the sig-validity-interval to be
     overriden for signatures covering DNSKEY RRsets. [GL #145]
 
 Removed Features
 
+  * named can no longer use the EDNS CLIENT-SUBNET option for view
+    selection. In its existing form, the authoritative ECS feature was not
+    fully RFC-compliant, and could not realistically have been deployed in
+    production for an authoritative server; its only practical use was for
+    testing and experimentation. In the interest of code simplification,
+    this feature has now been removed.
+
+    The ECS option is still supported in dig and mdig via the +subnet
+    argument, and can be parsed and logged when received by named, but it
+    is no longer used for ACL processing. The geoip-use-ecs option is now
+    obsolete; a warning will be logged if it is used in named.conf. ecs
+    tags in an ACL definition are also obsolete, and will cause the
+    configuration to fail to load if they are used. [GL #32]
+
   * dnssec-keygen can no longer generate HMAC keys for TSIG
     authentication. Use tsig-keygen to generate these keys. [RT #46404]
 
@@ -76,6 +94,12 @@ Removed Features
     The -p option to use pseudo-random data has been removed from the
     dnssec-signzone command.
 
+  * Support for ECC-GOST (GOST R 34.11-94) algorithm has been removed from
+    BIND as the algorithm has been superseded by GOST R 34.11-2012 in
+    RFC6986 and it must not be used in new deployments. BIND will neither
+    create new DNSSEC keys, signatures and digest, nor it will validate
+    them.
+
 Feature Changes
 
   * BIND will now always use the best CSPRNG (cryptographically-secure
@@ -85,6 +109,12 @@ Feature Changes
     Windows, and the selected cryptography provider library (OpenSSL or
     PKCS#11) as the last resort. [GL #221]
 
+  * The default setting for dnssec-validation is now auto, which activates
+    DNSSEC validation using the IANA root key. (The default can be changed
+    back to yes, which activates DNSSEC validation only when keys are
+    explicitly configured in named.conf, by building BIND with configure
+    --disable-auto-validation.) [GL #30]
+
   * BIND can no longer be built without DNSSEC support. A cryptography
     provder (i.e., OpenSSL or a hardware service module with PKCS#11
     support) must be available. [GL #244]
@@ -110,6 +140,9 @@ Feature Changes
     max-cache-ttl, max-ncache-ttl, max-policy-ttl, and min-update-interval
     . [GL #203]
 
+  * NSID logging (enabled by the request-nsid option) now has its own nsid
+    category, instead of using the resolver category.
+
 Bug Fixes
 
   * None.
index e2bcd1eb9e0e7f5ce937c7c5efc6470a6d63a2ff..d05291cea125a60870749eeea593c9abf21eef57 100644 (file)
@@ -79,6 +79,7 @@ options {
             ] [ dscp <integer> ];
         alt-transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> |
             * ) ] [ dscp <integer> ];
+        answer-cookie <boolean>; // obsolete
         attach-cache <string>;
         auth-nxdomain <boolean>; // default changed
         auto-dnssec ( allow | maintain | off );
@@ -185,7 +186,7 @@ options {
         fstrm-set-output-queue-size <integer>; // not configured
         fstrm-set-reopen-interval <ttlval>; // not configured
         geoip-directory ( <quoted_string> | none ); // not configured
-        geoip-use-ecs <boolean>; // not configured
+        geoip-use-ecs <boolean>; // obsolete
         glue-cache <boolean>;
         has-old-clients <boolean>; // obsolete
         heartbeat-interval <integer>;
index dff640d76cde0fc0386905ff774f502850e659d5..f6a05db88fe6add6c6e8b96c73c7206349821e9e 100644 (file)
@@ -10,5 +10,5 @@
 # 9.12: 1200-1299
 # 9.13: 1300-1399
 LIBINTERFACE = 1300
-LIBREVISION = 0
+LIBREVISION = 1
 LIBAGE = 0
index dff640d76cde0fc0386905ff774f502850e659d5..2e3dc0c30eb070e2a5bd43407a1187372ccb1f5a 100644 (file)
@@ -9,6 +9,6 @@
 # 9.11: 160-169,1100-1199
 # 9.12: 1200-1299
 # 9.13: 1300-1399
-LIBINTERFACE = 1300
+LIBINTERFACE = 1301
 LIBREVISION = 0
 LIBAGE = 0
index dff640d76cde0fc0386905ff774f502850e659d5..2e3dc0c30eb070e2a5bd43407a1187372ccb1f5a 100644 (file)
@@ -9,6 +9,6 @@
 # 9.11: 160-169,1100-1199
 # 9.12: 1200-1299
 # 9.13: 1300-1399
-LIBINTERFACE = 1300
+LIBINTERFACE = 1301
 LIBREVISION = 0
 LIBAGE = 0
index dff640d76cde0fc0386905ff774f502850e659d5..298b164cd6f3f85cb0e02c894dbc466b0e37fab9 100644 (file)
@@ -9,6 +9,6 @@
 # 9.11: 160-169,1100-1199
 # 9.12: 1200-1299
 # 9.13: 1300-1399
-LIBINTERFACE = 1300
+LIBINTERFACE = 1301
 LIBREVISION = 0
-LIBAGE = 0
+LIBAGE = 1
index bc92fdbfb677e76e37d94953e717d669ee0594f9..a159a1e446ecb6080a59b9221593f535cbf424a4 100644 (file)
@@ -9,6 +9,6 @@
 # 9.11: 160-169
 # 9.12: 1200-1299
 # 9.13: 1300-1399
-LIBINTERFACE = 1300
+LIBINTERFACE = 1301
 LIBREVISION = 0
-LIBAGE = 0
+LIBAGE = 1
diff --git a/version b/version
index 7018474341c63e5af8b051d33b07606c02cfd397..38fd269f3fd105c7a14a1b9a6e721b4f61320b68 100644 (file)
--- a/version
+++ b/version
@@ -5,7 +5,7 @@ PRODUCT=BIND
 DESCRIPTION="(Development Release)"
 MAJORVER=9
 MINORVER=13
-PATCHVER=0
+PATCHVER=1
 RELEASETYPE=
 RELEASEVER=
 EXTENSIONS=