]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
prep 9.11.7
authorTinderbox User <tbox@isc.org>
Fri, 10 May 2019 04:56:43 +0000 (04:56 +0000)
committerTinderbox User <tbox@isc.org>
Fri, 10 May 2019 05:03:46 +0000 (05:03 +0000)
66 files changed:
CHANGES
README
README.md
bin/dnssec/dnssec-keygen.8
bin/dnssec/dnssec-keygen.html
configure
doc/arm/Bv9ARM.ch01.html
doc/arm/Bv9ARM.ch02.html
doc/arm/Bv9ARM.ch03.html
doc/arm/Bv9ARM.ch04.html
doc/arm/Bv9ARM.ch05.html
doc/arm/Bv9ARM.ch06.html
doc/arm/Bv9ARM.ch07.html
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.ch09.html
doc/arm/Bv9ARM.ch10.html
doc/arm/Bv9ARM.ch11.html
doc/arm/Bv9ARM.ch12.html
doc/arm/Bv9ARM.ch13.html
doc/arm/Bv9ARM.html
doc/arm/Bv9ARM.pdf
doc/arm/man.arpaname.html
doc/arm/man.ddns-confgen.html
doc/arm/man.delv.html
doc/arm/man.dig.html
doc/arm/man.dnssec-checkds.html
doc/arm/man.dnssec-coverage.html
doc/arm/man.dnssec-dsfromkey.html
doc/arm/man.dnssec-importkey.html
doc/arm/man.dnssec-keyfromlabel.html
doc/arm/man.dnssec-keygen.html
doc/arm/man.dnssec-keymgr.html
doc/arm/man.dnssec-revoke.html
doc/arm/man.dnssec-settime.html
doc/arm/man.dnssec-signzone.html
doc/arm/man.dnssec-verify.html
doc/arm/man.dnstap-read.html
doc/arm/man.genrandom.html
doc/arm/man.host.html
doc/arm/man.isc-hmac-fixup.html
doc/arm/man.lwresd.html
doc/arm/man.mdig.html
doc/arm/man.named-checkconf.html
doc/arm/man.named-checkzone.html
doc/arm/man.named-journalprint.html
doc/arm/man.named-nzd2nzf.html
doc/arm/man.named-rrchecker.html
doc/arm/man.named.conf.html
doc/arm/man.named.html
doc/arm/man.nsec3hash.html
doc/arm/man.nslookup.html
doc/arm/man.nsupdate.html
doc/arm/man.pkcs11-destroy.html
doc/arm/man.pkcs11-keygen.html
doc/arm/man.pkcs11-list.html
doc/arm/man.pkcs11-tokens.html
doc/arm/man.rndc-confgen.html
doc/arm/man.rndc.conf.html
doc/arm/man.rndc.html
doc/arm/notes.html
doc/arm/notes.pdf
doc/arm/notes.txt
lib/bind9/api
lib/dns/api
lib/isc/api
version

diff --git a/CHANGES b/CHANGES
index 0e96c2bfa34b555268afd6c4008f3204b98b92e7..d9a0054703a50b2a068e003241adb5baa757de50 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -1,3 +1,5 @@
+       --- 9.11.7 released ---
+
 5233.  [bug]           Negative trust anchors did not work with "forward only;"
                        to validating resolvers. [GL #997]
 
diff --git a/README b/README
index 3b28ae32f7d0f87a30994a1c9a8f71927146565d..45c1f490c8acd7063ea54fb355f3dc0f94d2461a 100644 (file)
--- a/README
+++ b/README
@@ -265,10 +265,10 @@ BIND 9.11.6
 BIND 9.11.6 is a maintenance release, and also addresses the security
 flaws disclosed in CVE-2018-5744, CVE-2018-5745, and CVE-2019-6465.
 
-BIND 9.11.6-P1
+BIND 9.11.7
 
-BIND 9.11.6-P1 addresses the security vulnerability disclosed in
-CVE-2018-5743.
+BIND 9.11.7 is a maintenance release, and also addresses the security flaw
+disclosed in CVE-2018-5743.
 
 Building BIND
 
index 02cc464b3d2e64d8d0ca3a5a2335baa6ebcb4534..ea48104e6863f586954664115dd45ee1b0e9f5a3 100644 (file)
--- a/README.md
+++ b/README.md
@@ -282,10 +282,10 @@ feature:
 BIND 9.11.6 is a maintenance release, and also addresses the security
 flaws disclosed in CVE-2018-5744, CVE-2018-5745, and CVE-2019-6465.
 
-#### BIND 9.11.6-P1
+#### BIND 9.11.7
 
-BIND 9.11.6-P1 addresses the security vulnerability disclosed in
-CVE-2018-5743.
+BIND 9.11.7 is a maintenance release, and also addresses the security
+flaw disclosed in CVE-2018-5743.
 
 ### <a name="build"/> Building BIND
 
index 6f8eedb2f0ba6813710e84250c423e0429a1e141..a169e62d651983b754b0b0dce5bce01f6aaa9a81 100644 (file)
@@ -39,7 +39,7 @@
 dnssec-keygen \- DNSSEC key generation tool
 .SH "SYNOPSIS"
 .HP \w'\fBdnssec\-keygen\fR\ 'u
-\fBdnssec\-keygen\fR [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-z\fR] {name}
+\fBdnssec\-keygen\fR [\fB\-3\fR] [\fB\-A\ \fR\fB\fIdate/offset\fR\fR] [\fB\-a\ \fR\fB\fIalgorithm\fR\fR] [\fB\-b\ \fR\fB\fIkeysize\fR\fR] [\fB\-C\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-D\ \fR\fB\fIdate/offset\fR\fR] [\fB\-D\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-E\ \fR\fB\fIengine\fR\fR] [\fB\-f\ \fR\fB\fIflag\fR\fR] [\fB\-G\fR] [\fB\-g\ \fR\fB\fIgenerator\fR\fR] [\fB\-h\fR] [\fB\-I\ \fR\fB\fIdate/offset\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-K\ \fR\fB\fIdirectory\fR\fR] [\fB\-k\fR] [\fB\-L\ \fR\fB\fIttl\fR\fR] [\fB\-n\ \fR\fB\fInametype\fR\fR] [\fB\-P\ \fR\fB\fIdate/offset\fR\fR] [\fB\-P\ sync\ \fR\fB\fIdate/offset\fR\fR] [\fB\-p\ \fR\fB\fIprotocol\fR\fR] [\fB\-q\fR] [\fB\-R\ \fR\fB\fIdate/offset\fR\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-S\ \fR\fB\fIkey\fR\fR] [\fB\-s\ \fR\fB\fIstrength\fR\fR] [\fB\-t\ \fR\fB\fItype\fR\fR] [\fB\-V\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] {name}
 .SH "DESCRIPTION"
 .PP
 \fBdnssec\-keygen\fR
@@ -50,6 +50,13 @@ The
 of the key is specified on the command line\&. For DNSSEC keys, this must match the name of the zone for which the key is being generated\&.
 .SH "OPTIONS"
 .PP
+\-3
+.RS 4
+Use an NSEC3\-capable algorithm to generate a DNSSEC key\&. If this option is used with an algorithm that has both NSEC and NSEC3 versions, then the NSEC3 version will be used; for example,
+\fBdnssec\-keygen \-3a RSASHA1\fR
+specifies the NSEC3RSASHA1 algorithm\&.
+.RE
+.PP
 \-a \fIalgorithm\fR
 .RS 4
 Selects the cryptographic algorithm\&. For DNSSEC keys, the value of
@@ -78,21 +85,9 @@ The key size does not need to be specified if using a default algorithm\&. The d
 must be used\&.
 .RE
 .PP
-\-n \fInametype\fR
-.RS 4
-Specifies the owner type of the key\&. The value of
-\fBnametype\fR
-must either be ZONE (for a DNSSEC zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with a host (KEY)), USER (for a key associated with a user(KEY)) or OTHER (DNSKEY)\&. These values are case insensitive\&. Defaults to ZONE for DNSKEY generation\&.
-.RE
-.PP
-\-3
-.RS 4
-Use an NSEC3\-capable algorithm to generate a DNSSEC key\&. If this option is used and no algorithm is explicitly set on the command line, NSEC3RSASHA1 will be used by default\&. Note that RSASHA256, RSASHA512, ECCGOST, ECDSAP256SHA256, ECDSAP384SHA384, ED25519 and ED448 algorithms are NSEC3\-capable\&.
-.RE
-.PP
 \-C
 .RS 4
-Compatibility mode: generates an old\-style key, without any metadata\&. By default,
+Compatibility mode: generates an old\-style key, without any timing metadata\&. By default,
 \fBdnssec\-keygen\fR
 will include the key\*(Aqs creation date in the metadata stored with the private key, and other dates may be set there as well (publication date, activation date, etc)\&. Keys that include this data may be incompatible with older versions of BIND; the
 \fB\-C\fR
@@ -151,9 +146,17 @@ none
 is the same as leaving it unset\&.
 .RE
 .PP
+\-n \fInametype\fR
+.RS 4
+Specifies the owner type of the key\&. The value of
+\fBnametype\fR
+must either be ZONE (for a DNSSEC zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with a host (KEY)), USER (for a key associated with a user(KEY)) or OTHER (DNSKEY)\&. These values are case insensitive\&. Defaults to ZONE for DNSKEY generation\&.
+.RE
+.PP
 \-p \fIprotocol\fR
 .RS 4
-Sets the protocol value for the generated key\&. The protocol is a number between 0 and 255\&. The default is 3 (DNSSEC)\&. Other possible values for this argument are listed in RFC 2535 and its successors\&.
+Sets the protocol value for the generated key, for use with
+\fB\-T KEY\fR\&. The protocol is a number between 0 and 255\&. The default is 3 (DNSSEC)\&. Other possible values for this argument are listed in RFC 2535 and its successors\&.
 .RE
 .PP
 \-q
@@ -196,19 +199,20 @@ Using any TSIG algorithm (HMAC\-* or DH) forces this option to KEY\&.
 .PP
 \-t \fItype\fR
 .RS 4
-Indicates the use of the key\&.
+Indicates the use of the key, for use with
+\fB\-T KEY\fR\&.
 \fBtype\fR
 must be one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF\&. The default is AUTHCONF\&. AUTH refers to the ability to authenticate data, and CONF the ability to encrypt data\&.
 .RE
 .PP
-\-v \fIlevel\fR
+\-V
 .RS 4
-Sets the debugging level\&.
+Prints version information\&.
 .RE
 .PP
-\-V
+\-v \fIlevel\fR
 .RS 4
-Prints version information\&.
+Sets the debugging level\&.
 .RE
 .SH "TIMING OPTIONS"
 .PP
@@ -338,6 +342,10 @@ creates the files
 Kexample\&.com\&.+003+26160\&.key
 and
 Kexample\&.com\&.+003+26160\&.private\&.
+.PP
+To generate a matching key\-signing key, issue the command:
+.PP
+\fBdnssec\-keygen \-a DSA \-b 768 \-n ZONE \-f KSK example\&.com\fR
 .SH "SEE ALSO"
 .PP
 \fBdnssec-signzone\fR(8),
index 4cdeca62cc2d0486ff6e0dd0ff7ea5c6f8363a54..70f75b8ff2ad8cdf7c4e1ba6353035ebd7ada536 100644 (file)
 <h2>Synopsis</h2>
     <div class="cmdsynopsis"><p>
       <code class="command">dnssec-keygen</code> 
-       [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>]
-       [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>]
-       [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
        [<code class="option">-3</code>]
        [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>]
+       [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>]
+       [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>]
        [<code class="option">-C</code>]
        [<code class="option">-c <em class="replaceable"><code>class</code></em></code>]
        [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>]
@@ -52,6 +51,7 @@
        [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
        [<code class="option">-k</code>]
        [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>]
+       [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
        [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>]
        [<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>]
        [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>]
@@ -63,7 +63,6 @@
        [<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
        [<code class="option">-V</code>]
        [<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
-       [<code class="option">-z</code>]
        {name}
     </p></div>
   </div>
 
 
     <div class="variablelist"><dl class="variablelist">
+<dt><span class="term">-3</span></dt>
+<dd>
+         <p>
+           Use an NSEC3-capable algorithm to generate a DNSSEC key.
+           If this option is used with an algorithm that has both
+           NSEC and NSEC3 versions, then the NSEC3 version will be
+           used; for example, <span class="command"><strong>dnssec-keygen -3a RSASHA1</strong></span>
+           specifies the NSEC3RSASHA1 algorithm.
+         </p>
+       </dd>
 <dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
 <dd>
          <p>
            must be used.
          </p>
        </dd>
-<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
-<dd>
-         <p>
-           Specifies the owner type of the key.  The value of
-           <code class="option">nametype</code> must either be ZONE (for a DNSSEC
-           zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
-           a host (KEY)),
-           USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
-           These values are case insensitive.  Defaults to ZONE for DNSKEY
-           generation.
-         </p>
-       </dd>
-<dt><span class="term">-3</span></dt>
-<dd>
-         <p>
-           Use an NSEC3-capable algorithm to generate a DNSSEC key.
-           If this option is used and no algorithm is explicitly
-           set on the command line, NSEC3RSASHA1 will be used by
-           default. Note that RSASHA256, RSASHA512, ECCGOST,
-           ECDSAP256SHA256, ECDSAP384SHA384, ED25519 and ED448
-           algorithms are NSEC3-capable.
-         </p>
-       </dd>
 <dt><span class="term">-C</span></dt>
 <dd>
          <p>
-           Compatibility mode:  generates an old-style key, without
-           any metadata.  By default, <span class="command"><strong>dnssec-keygen</strong></span>
-           will include the key's creation date in the metadata stored
-           with the private key, and other dates may be set there as well
-           (publication date, activation date, etc).  Keys that include
-           this data may be incompatible with older versions of BIND; the
+           Compatibility mode: generates an old-style key, without any
+           timing metadata. By default, <span class="command"><strong>dnssec-keygen</strong></span>
+           will include the key's creation date in the metadata stored with
+           the private key, and other dates may be set there as well
+           (publication date, activation date, etc). Keys that include this
+           data may be incompatible with older versions of BIND; the
            <code class="option">-C</code> option suppresses them.
          </p>
        </dd>
            or <code class="literal">none</code> is the same as leaving it unset.
          </p>
        </dd>
+<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
+<dd>
+         <p>
+           Specifies the owner type of the key.  The value of
+           <code class="option">nametype</code> must either be ZONE (for a DNSSEC
+           zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated
+           with a host (KEY)), USER (for a key associated with a
+           user(KEY)) or OTHER (DNSKEY).  These values are case
+           insensitive.  Defaults to ZONE for DNSKEY generation.
+         </p>
+       </dd>
 <dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
 <dd>
          <p>
-           Sets the protocol value for the generated key.  The protocol
-           is a number between 0 and 255.  The default is 3 (DNSSEC).
-           Other possible values for this argument are listed in
-           RFC 2535 and its successors.
+           Sets the protocol value for the generated key, for use
+           with <code class="option">-T KEY</code>. The protocol is a number between 0
+           and 255. The default is 3 (DNSSEC). Other possible values for
+           this argument are listed in RFC 2535 and its successors.
          </p>
        </dd>
 <dt><span class="term">-q</span></dt>
 <dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
 <dd>
          <p>
-           Indicates the use of the key.  <code class="option">type</code> must be
-           one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF.  The default
-           is AUTHCONF.  AUTH refers to the ability to authenticate
-           data, and CONF the ability to encrypt data.
+           Indicates the use of the key, for use with <code class="option">-T
+           KEY</code>. <code class="option">type</code> must be one of AUTHCONF,
+           NOAUTHCONF, NOAUTH, or NOCONF. The default is AUTHCONF. AUTH
+           refers to the ability to authenticate data, and CONF the ability
+           to encrypt data.
          </p>
        </dd>
-<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
+<dt><span class="term">-V</span></dt>
 <dd>
          <p>
-           Sets the debugging level.
+           Prints version information.
          </p>
        </dd>
-<dt><span class="term">-V</span></dt>
+<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
 <dd>
          <p>
-           Prints version information.
+           Sets the debugging level.
          </p>
        </dd>
 </dl></div>
       and
       <code class="filename">Kexample.com.+003+26160.private</code>.
     </p>
+    <p>
+      To generate a matching key-signing key, issue the command:
+    </p>
+    <p>
+      <strong class="userinput"><code>dnssec-keygen -a DSA -b 768 -n ZONE -f KSK example.com</code></strong>
+    </p>
   </div>
 
   <div class="refsection">
index 3ae0f2210cb8ab4c1966e1bce1bcd4c744a28750..b219e160744e018b8eab76fdfdda2f7dafe3349d 100755 (executable)
--- a/configure
+++ b/configure
@@ -971,7 +971,6 @@ infodir
 docdir
 oldincludedir
 includedir
-runstatedir
 localstatedir
 sharedstatedir
 sysconfdir
@@ -1139,7 +1138,6 @@ datadir='${datarootdir}'
 sysconfdir='${prefix}/etc'
 sharedstatedir='${prefix}/com'
 localstatedir='${prefix}/var'
-runstatedir='${localstatedir}/run'
 includedir='${prefix}/include'
 oldincludedir='/usr/include'
 docdir='${datarootdir}/doc/${PACKAGE_TARNAME}'
@@ -1392,15 +1390,6 @@ do
   | -silent | --silent | --silen | --sile | --sil)
     silent=yes ;;
 
-  -runstatedir | --runstatedir | --runstatedi | --runstated \
-  | --runstate | --runstat | --runsta | --runst | --runs \
-  | --run | --ru | --r)
-    ac_prev=runstatedir ;;
-  -runstatedir=* | --runstatedir=* | --runstatedi=* | --runstated=* \
-  | --runstate=* | --runstat=* | --runsta=* | --runst=* | --runs=* \
-  | --run=* | --ru=* | --r=*)
-    runstatedir=$ac_optarg ;;
-
   -sbindir | --sbindir | --sbindi | --sbind | --sbin | --sbi | --sb)
     ac_prev=sbindir ;;
   -sbindir=* | --sbindir=* | --sbindi=* | --sbind=* | --sbin=* \
@@ -1538,7 +1527,7 @@ fi
 for ac_var in  exec_prefix prefix bindir sbindir libexecdir datarootdir \
                datadir sysconfdir sharedstatedir localstatedir includedir \
                oldincludedir docdir infodir htmldir dvidir pdfdir psdir \
-               libdir localedir mandir runstatedir
+               libdir localedir mandir
 do
   eval ac_val=\$$ac_var
   # Remove trailing slashes.
@@ -1691,7 +1680,6 @@ Fine tuning of the installation directories:
   --sysconfdir=DIR        read-only single-machine data [PREFIX/etc]
   --sharedstatedir=DIR    modifiable architecture-independent data [PREFIX/com]
   --localstatedir=DIR     modifiable single-machine data [PREFIX/var]
-  --runstatedir=DIR       modifiable per-process data [LOCALSTATEDIR/run]
   --libdir=DIR            object code libraries [EPREFIX/lib]
   --includedir=DIR        C header files [PREFIX/include]
   --oldincludedir=DIR     C header files for non-gcc [/usr/include]
index adc7430667398426cefbdb24acff3955a0c2cc5e..120ae4f5c417ba0547f59e4089eeecb688d16e5b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 54f42326c30aabc38f163552e3f8cb8d771fe1d5..5e96ea21574791f3d945339c3af4a833693a42de 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 777fd4e573984dc1ef9b0dfcd811d2b61b366b50..4313d1924878c713e3a834436eb1dcda3a0b5ad1 100644 (file)
@@ -759,6 +759,6 @@ controls {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 9ec539676c33731ec45f8e989ef1c6165e9c5259..6401c9ea685c0bf6ee9a3c895d5e6a9a8f158cc3 100644 (file)
@@ -2867,6 +2867,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 2d09741b770e8cfe6cc575c18af8786ddc1e782b..d03d0cbbc5025b50caa37bc91c1f0cb6e230ac0f 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 7facb4d5b7fcdc3ea2201ccc74b06432a1651d8f..f7c381acf13bfb2347698349b2e534377dc3a5fb 100644 (file)
@@ -3401,6 +3401,12 @@ options {
                 by the <span class="command"><strong>disable-algorithms</strong></span> will be treated
                 as insecure.
               </p>
+              <p>
+                Configured trust anchors in <span class="command"><strong>trusted-keys</strong></span>
+                or <span class="command"><strong>managed-keys</strong></span> that match a disabled
+                algorithm will be ignored and treated as if they were not
+                configured at all.
+              </p>
             </dd>
 <dt><span class="term"><span class="command"><strong>disable-ds-digests</strong></span></span></dt>
 <dd>
@@ -7870,7 +7876,7 @@ deny-answer-aliases { "example.net"; };
                     The empty set of resource records is specified by
                     CNAME whose target is the wildcard top-level
                     domain (*.).
-                    It rewrites the response to NODATA or ANCOUNT=1.
+                    It rewrites the response to NODATA or ANCOUNT=0.
                   </p>
                 </dd>
 <dt><span class="term"><span class="command"><strong>Local Data</strong></span></span></dt>
@@ -14677,6 +14683,6 @@ HOST-127.EXAMPLE. MX 0 .
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index d3d729a627593f2fd9f476a71f3a82eca23557db..46a0eca3f481523a295b8048fcc4b82a2b81468a 100644 (file)
@@ -399,6 +399,6 @@ allow-query { !{ !10/8; any; }; key example; };
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 220f0c93bc3bd52b057be037654b8c9ca52c2797..a7d6b718f8e90734648ccbdef9617165fb833e7c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 8687123d3c88915843fa0720199e30c1f117a179..77d27ecba98e2d6c07de92d7ddb196814765bf0d 100644 (file)
 <div class="toc">
 <p><b>Table of Contents</b></p>
 <dl class="toc">
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.6-P1</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.7</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#win_support">Legacy Windows No Longer Supported</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
 </div>
       <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.6-P1</h2></div></div></div>
+<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.7</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
     <p>
-      This document summarizes changes since the last production
-      release on the BIND 9.11 (Extended Support Version) branch.
-      Please see the <code class="filename">CHANGES</code> file for a further
-      list of bug fixes and other changes.
+      BIND 9.11 (Extended Support Version) is a stable branch of BIND.
+      This document summarizes significant changes since the last
+      production release on that branch.
+    </p>
+    <p>
+      Please see the file <code class="filename">CHANGES</code> for a more
+      detailed list of changes and bug fixes.
     </p>
   </div>
 
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="win_support"></a>Legacy Windows No Longer Supported</h3></div></div></div>
-    <p>
-      As of BIND 9.11.2, Windows XP and Windows 2003 are no longer supported
-      platforms for BIND; "XP" binaries are no longer available for download
-      from ISC.
-    </p>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
 <a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         None.
+         When <span class="command"><strong>trusted-keys</strong></span> and
+         <span class="command"><strong>managed-keys</strong></span> are both configured for the
+         same name, or when <span class="command"><strong>trusted-keys</strong></span> is used to
+         configure a trust anchor for the root zone and
+         <span class="command"><strong>dnssec-validation</strong></span> is set to
+         <code class="literal">auto</code>, automatic RFC 5011 key
+         rollovers will fail.
+       </p>
+       <p>
+         This combination of settings was never intended to work,
+         but there was no check for it in the parser. This has been
+         corrected; a warning is now logged. (In BIND 9.15 and
+         higher this error will be fatal.) [GL #868]
        </p>
       </li></ul></div>
   </div>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 6deb971740b1581e3ce9ee142748d88546e7e63b..22182e36925470827368448c3ac2906b80d6bb2b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index e258d65d4967d31d5dbe4cacf263cfc0fef1b7c7..ec683f3f6b4f25c89188ded32d9f47e206b5319f 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 490e9114a425a236997398cf268f73b60b864afd..76b794f372b2217e3edbd6fe462a7c7dbad5a604 100644 (file)
@@ -533,6 +533,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 7ed047ecabdbb791d37f8b2038277359f5a3ba84..cc40a3440abc15c9fd83cc8c047bec0471a18931 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 9f4a4e6e357891f4cb11c71c631b8783f636c7e5..103caa829d54437f2bef1a0efd18856de811b1e8 100644 (file)
@@ -32,7 +32,7 @@
 <div>
 <div><h1 class="title">
 <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
-<div><p class="releaseinfo">BIND Version 9.11.6-P1</p></div>
+<div><p class="releaseinfo">BIND Version 9.11.7</p></div>
 <div><p class="copyright">Copyright Â© 2000-2019 Internet Systems Consortium, Inc. ("ISC")</p></div>
 </div>
 <hr>
 </dl></dd>
 <dt><span class="appendix"><a href="Bv9ARM.ch09.html">A. Release Notes</a></span></dt>
 <dd><dl>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.6-P1</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.7</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_license">License Change</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#win_support">Legacy Windows No Longer Supported</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index d50717baebc5ffebdd825114fa487138b5ff2d3c..99ece4db6cce71f8d42206f618cb116b8e570b6d 100644 (file)
Binary files a/doc/arm/Bv9ARM.pdf and b/doc/arm/Bv9ARM.pdf differ
index 395bad2b63dd06ed880f767f882fca4309d0da6a..3dcc89f11de6c6e5d34e34e112f43855be8aadee 100644 (file)
@@ -91,6 +91,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 205b2effc71fee3083b789adf8007d7eda47efda..542af798b85783d0c2f5fe4f5d186916f83c07a6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index b71019e75429a80358606ccf01960aba9982bc0a..54f43bdcf1aadb9a6a9c3d1924b9099359d73596 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index f30a4ade8779196047219ac7019de959fc9c79ee..b6a0098e1e67d99d234666f1a732171a4ff006b5 100644 (file)
@@ -1128,6 +1128,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 3a6e175b6cd85d5d363a6f2d274a2fa193c69f52..ef03080bd0f3db75534febfb8a24bbf8672550f4 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index be9478b4b6456d9cd17503c818feb93e62ee5f3a..d8a2f17908a16adf29ec31b78c022719ae7c860c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index c06a3560219f9f4d41788dbfffc71d77ab767d7b..8e55ec93250468178a13b7b87bc6487c8d544672 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index f350497e5e74cbcc9639ef5be4e0fa08975bcc12..db9f9e226e3b1f3ee18d38e2fbd8f8849d342530 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index a936dd702ae07908fb2562d7f6356344e4afa070..e0a8676c96185d70f79285b8ee06ffd7b20dec32 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index dfb51c0d05d3f3558e8bb33695b17d6172bf593d..ef6522095d72b2e172e67f8a34f4584364fdc816 100644 (file)
 <h2>Synopsis</h2>
     <div class="cmdsynopsis"><p>
       <code class="command">dnssec-keygen</code> 
-       [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>]
-       [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>]
-       [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
        [<code class="option">-3</code>]
        [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>]
+       [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>]
+       [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>]
        [<code class="option">-C</code>]
        [<code class="option">-c <em class="replaceable"><code>class</code></em></code>]
        [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>]
@@ -70,6 +69,7 @@
        [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
        [<code class="option">-k</code>]
        [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>]
+       [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>]
        [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>]
        [<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>]
        [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>]
@@ -81,7 +81,6 @@
        [<code class="option">-t <em class="replaceable"><code>type</code></em></code>]
        [<code class="option">-V</code>]
        [<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
-       [<code class="option">-z</code>]
        {name}
     </p></div>
   </div>
 
 
     <div class="variablelist"><dl class="variablelist">
+<dt><span class="term">-3</span></dt>
+<dd>
+         <p>
+           Use an NSEC3-capable algorithm to generate a DNSSEC key.
+           If this option is used with an algorithm that has both
+           NSEC and NSEC3 versions, then the NSEC3 version will be
+           used; for example, <span class="command"><strong>dnssec-keygen -3a RSASHA1</strong></span>
+           specifies the NSEC3RSASHA1 algorithm.
+         </p>
+       </dd>
 <dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
 <dd>
          <p>
            must be used.
          </p>
        </dd>
-<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
-<dd>
-         <p>
-           Specifies the owner type of the key.  The value of
-           <code class="option">nametype</code> must either be ZONE (for a DNSSEC
-           zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
-           a host (KEY)),
-           USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
-           These values are case insensitive.  Defaults to ZONE for DNSKEY
-           generation.
-         </p>
-       </dd>
-<dt><span class="term">-3</span></dt>
-<dd>
-         <p>
-           Use an NSEC3-capable algorithm to generate a DNSSEC key.
-           If this option is used and no algorithm is explicitly
-           set on the command line, NSEC3RSASHA1 will be used by
-           default. Note that RSASHA256, RSASHA512, ECCGOST,
-           ECDSAP256SHA256, ECDSAP384SHA384, ED25519 and ED448
-           algorithms are NSEC3-capable.
-         </p>
-       </dd>
 <dt><span class="term">-C</span></dt>
 <dd>
          <p>
-           Compatibility mode:  generates an old-style key, without
-           any metadata.  By default, <span class="command"><strong>dnssec-keygen</strong></span>
-           will include the key's creation date in the metadata stored
-           with the private key, and other dates may be set there as well
-           (publication date, activation date, etc).  Keys that include
-           this data may be incompatible with older versions of BIND; the
+           Compatibility mode: generates an old-style key, without any
+           timing metadata. By default, <span class="command"><strong>dnssec-keygen</strong></span>
+           will include the key's creation date in the metadata stored with
+           the private key, and other dates may be set there as well
+           (publication date, activation date, etc). Keys that include this
+           data may be incompatible with older versions of BIND; the
            <code class="option">-C</code> option suppresses them.
          </p>
        </dd>
            or <code class="literal">none</code> is the same as leaving it unset.
          </p>
        </dd>
+<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
+<dd>
+         <p>
+           Specifies the owner type of the key.  The value of
+           <code class="option">nametype</code> must either be ZONE (for a DNSSEC
+           zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated
+           with a host (KEY)), USER (for a key associated with a
+           user(KEY)) or OTHER (DNSKEY).  These values are case
+           insensitive.  Defaults to ZONE for DNSKEY generation.
+         </p>
+       </dd>
 <dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
 <dd>
          <p>
-           Sets the protocol value for the generated key.  The protocol
-           is a number between 0 and 255.  The default is 3 (DNSSEC).
-           Other possible values for this argument are listed in
-           RFC 2535 and its successors.
+           Sets the protocol value for the generated key, for use
+           with <code class="option">-T KEY</code>. The protocol is a number between 0
+           and 255. The default is 3 (DNSSEC). Other possible values for
+           this argument are listed in RFC 2535 and its successors.
          </p>
        </dd>
 <dt><span class="term">-q</span></dt>
 <dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
 <dd>
          <p>
-           Indicates the use of the key.  <code class="option">type</code> must be
-           one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF.  The default
-           is AUTHCONF.  AUTH refers to the ability to authenticate
-           data, and CONF the ability to encrypt data.
+           Indicates the use of the key, for use with <code class="option">-T
+           KEY</code>. <code class="option">type</code> must be one of AUTHCONF,
+           NOAUTHCONF, NOAUTH, or NOCONF. The default is AUTHCONF. AUTH
+           refers to the ability to authenticate data, and CONF the ability
+           to encrypt data.
          </p>
        </dd>
-<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
+<dt><span class="term">-V</span></dt>
 <dd>
          <p>
-           Sets the debugging level.
+           Prints version information.
          </p>
        </dd>
-<dt><span class="term">-V</span></dt>
+<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
 <dd>
          <p>
-           Prints version information.
+           Sets the debugging level.
          </p>
        </dd>
 </dl></div>
       and
       <code class="filename">Kexample.com.+003+26160.private</code>.
     </p>
+    <p>
+      To generate a matching key-signing key, issue the command:
+    </p>
+    <p>
+      <strong class="userinput"><code>dnssec-keygen -a DSA -b 768 -n ZONE -f KSK example.com</code></strong>
+    </p>
   </div>
 
   <div class="refsection">
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index fc348c2c983b274d5bd0dae31600259be1e3b329..c3ec5067d2f88b0f95893fa634bdcf727aaef6e8 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index e9087374cbf9c4612af119d5b188ca0b2f2eaca4..16cc499d072308435d86e760646e34af75024c41 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index c5dc1af9232ff1af63c90cf2d1dcbaf178144166..7bd55b623c40e61bbe509004214e31231d4cfb10 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 35948273b261fc861e94785b0e5a6dae2f717e28..6d223783e3cf5d30c35fc303d3e44dfe236778c2 100644 (file)
@@ -708,6 +708,6 @@ db.example.com.signed
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 63b948a9d3450c0bfcc6e30abc37dd6d71f1f684..a4cc0d75d890aac8c2d9339c8e3657f9b67b4f63 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 59f3271ebe77e75acb9b89c59aa54c016f4a99d6..d8a75d104b5bbc0f48791b6f24ec39c1d08485ef 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index f68c808795bbb4e64bd14e9f09a6fe335b72a737..6740a12af9183ea1a6ae796d3f595fdc2a4bec06 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 1c7d82203df6b8dc492d19547def9acb3892da55..fa69269bdb5804990ed7dd084889f274fd39d8b0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 65ebc3f4f38a67feb9a71ac2162700305cae5f83..3d4c57d49e9223171317f0e117068fb00dd40673 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index a5c57babb7d80f25bf3eacb56a79952c7108b0df..4737e823ae54bbee296218a5cd47bb9980edf070 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 8fcfa030ee1effc7470661b7d53d4df104a5ab75..ad7aa9b533038f651e5195c3993548b596fd3669 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 3f4e73b4616e79db717c9b1a58fbd6d2245b543b..e36e952680c07d5641c578f95ffe1af0fcd92d1e 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 443a6c614c512365ea097e2147f957442dc6c4b6..bc3f77bac72004c4b47fbc91a3810ff82f46c457 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 889ddceebde2b28a3718601ff3b792964d433992..fc608e4662686c2b9a30c33f41fa37327cf442bb 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 0927aaa532f726c28cf327e84db0dcc78a187d16..7f327aeca974b7258f74316eb30bfa284b7de9f0 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 395eca2d5e8894f584d08f4323c5fa06eae22305..326ec75f4f6a390d574559d5108a649abff41bde 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index fcb3df6eadb67ed47d8dbc86214a00bbd24af8d1..f25dc388af010bf3de6954a140090f1eb0155884 100644 (file)
@@ -1034,6 +1034,6 @@ zone
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index dbb82c356eb140dce6873be7a7e48001cbe3451a..cb28d2b8c343edbe3c485a85fe236af6a1facddf 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index ac3aaea47e6b84c470ca2e58fd5f5da966adeb01..28f1b5e85e1eb2fb2156e2b4da2ed92913c1e2a6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 7edcd76db309469e6138d55daaf8f2d73a07b758..1784785b886c013cb9c8321cbd866f74b664295e 100644 (file)
@@ -436,6 +436,6 @@ nslookup -query=hinfo  -timeout=10
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 7a6273954da3f4dc09336d885953f1e35c937dd4..ebc40ff089641d41ddfa96ed558fb6803d902227 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 7ec83807432c202e5dec7036aa0566d4b8e87ebb..c5ae74486e13c94edc48d394dcce8fdd4320f887 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 289fdc562759fe9986f66bc691096705af53c2d7..ff84c51b5b980fb956ab44e0c960394b21ddd305 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index d75d76699b9e7a6321399a56824528f46788db3e..fe71c60fb14b938969198cf388fee1be396aab51 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 33cf80705a7f47420424b0322b00a9cf658a8b58..981f7fbec8fd2a19ec5cc9ba1d314415030ccd68 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 2d0fd79ddd862115626030879e171e634a717483..8cbc630545e2c93a300e713607ad6fba39acaba1 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index fd0525103df2e53556bd079e563a42a95084d9c2..1eb437e376d5b58d046785d95268fc432d984798 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index 1dd2e9260c751f0d2f3bfe48229782e922839449..f78c8e9b37b01d868878c032bcc2b1d9e2f38d44 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.7 (Extended Support Version)</p>
 </body>
 </html>
index abb0ef6fcaae0287dab394e507dd4d6c329759ad..d63bb3def9299d4f259575b8d7547f690f65bae3 100644 (file)
 
   <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.2"></a>Release Notes for BIND Version 9.11.6-P1</h2></div></div></div>
+<a name="id-1.2"></a>Release Notes for BIND Version 9.11.7</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_intro"></a>Introduction</h3></div></div></div>
     <p>
-      This document summarizes changes since the last production
-      release on the BIND 9.11 (Extended Support Version) branch.
-      Please see the <code class="filename">CHANGES</code> file for a further
-      list of bug fixes and other changes.
+      BIND 9.11 (Extended Support Version) is a stable branch of BIND.
+      This document summarizes significant changes since the last
+      production release on that branch.
+    </p>
+    <p>
+      Please see the file <code class="filename">CHANGES</code> for a more
+      detailed list of changes and bug fixes.
     </p>
   </div>
 
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="win_support"></a>Legacy Windows No Longer Supported</h3></div></div></div>
-    <p>
-      As of BIND 9.11.2, Windows XP and Windows 2003 are no longer supported
-      platforms for BIND; "XP" binaries are no longer available for download
-      from ISC.
-    </p>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
 <a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         None.
+         When <span class="command"><strong>trusted-keys</strong></span> and
+         <span class="command"><strong>managed-keys</strong></span> are both configured for the
+         same name, or when <span class="command"><strong>trusted-keys</strong></span> is used to
+         configure a trust anchor for the root zone and
+         <span class="command"><strong>dnssec-validation</strong></span> is set to
+         <code class="literal">auto</code>, automatic RFC 5011 key
+         rollovers will fail.
+       </p>
+       <p>
+         This combination of settings was never intended to work,
+         but there was no check for it in the parser. This has been
+         corrected; a warning is now logged. (In BIND 9.15 and
+         higher this error will be fatal.) [GL #868]
        </p>
       </li></ul></div>
   </div>
index e7c9babe3b6205474beaa7838bb9a567c44dfac6..bcabafab22b907b2ffc132146ba2475d16860fc1 100644 (file)
Binary files a/doc/arm/notes.pdf and b/doc/arm/notes.pdf differ
index 6f2ad74bf4188adce164cf0a145823f6c7069f76..aecfb96a9656822c8e94a40c75008730f59eb4ed 100644 (file)
@@ -1,10 +1,13 @@
-Release Notes for BIND Version 9.11.6-P1
+Release Notes for BIND Version 9.11.7
 
 Introduction
 
-This document summarizes changes since the last production release on the
-BIND 9.11 (Extended Support Version) branch. Please see the CHANGES file
-for a further list of bug fixes and other changes.
+BIND 9.11 (Extended Support Version) is a stable branch of BIND. This
+document summarizes significant changes since the last production release
+on that branch.
+
+Please see the file CHANGES for a more detailed list of changes and bug
+fixes.
 
 Download
 
@@ -33,12 +36,6 @@ Those unsure whether or not the license change affects their use of BIND,
 or who wish to discuss how to comply with the license may contact ISC at
 https://www.isc.org/mission/contact/.
 
-Legacy Windows No Longer Supported
-
-As of BIND 9.11.2, Windows XP and Windows 2003 are no longer supported
-platforms for BIND; "XP" binaries are no longer available for download
-from ISC.
-
 Security Fixes
 
   * The TCP client quota set using the tcp-clients option could be
@@ -51,7 +48,15 @@ New Features
 
 Feature Changes
 
-  * None.
+  * When trusted-keys and managed-keys are both configured for the same
+    name, or when trusted-keys is used to configure a trust anchor for the
+    root zone and dnssec-validation is set to auto, automatic RFC 5011 key
+    rollovers will fail.
+
+    This combination of settings was never intended to work, but there was
+    no check for it in the parser. This has been corrected; a warning is
+    now logged. (In BIND 9.15 and higher this error will be fatal.) [GL #
+    868]
 
 Bug Fixes
 
index 060936fe15bd042ec1d62ba5bc77028fb7d9f7d8..2fbdc78024e1e084e557914180d1a0555e1b4321 100644 (file)
@@ -9,5 +9,5 @@
 # 9.11: 160-169,1100-1199
 # 9.12: 1200-1299
 LIBINTERFACE = 161
-LIBREVISION = 1
+LIBREVISION = 2
 LIBAGE = 0
index 2edf29de3a87e98378d3b8ea49c9f4820c61ca21..ba00d7368c509584a20feb1a9f6ca5f4d87be828 100644 (file)
@@ -8,6 +8,6 @@
 # 9.10-sub: 180-189
 # 9.11: 160-169,1100-1199
 # 9.12: 1200-1299
-LIBINTERFACE = 1105
+LIBINTERFACE = 1106
 LIBREVISION = 0
 LIBAGE = 0
index 9d5a98d20ccbcbdd92d61a028be8a96abeaa7496..13ceae1114cf2c5f5952b5fb8fcd63c4ac0cf913 100644 (file)
@@ -8,6 +8,6 @@
 # 9.10-sub: 180-189
 # 9.11: 160-169,1100-1199
 # 9.12: 1200-1299
-LIBINTERFACE = 1101
+LIBINTERFACE = 1102
 LIBREVISION = 0
-LIBAGE = 1
+LIBAGE = 2
diff --git a/version b/version
index 1fab3bb50242888d7c903a107b3ea04445b92b90..9584d345fd496b3bcdf453cdbac58d7b12dc0610 100644 (file)
--- a/version
+++ b/version
@@ -5,7 +5,7 @@ PRODUCT=BIND
 DESCRIPTION="(Extended Support Version)"
 MAJORVER=9
 MINORVER=11
-PATCHVER=6
-RELEASETYPE=-P
-RELEASEVER=1
+PATCHVER=7
+RELEASETYPE=
+RELEASEVER=
 EXTENSIONS=