<itemizedlist>
<listitem>
<para>
- Adjust the <command>max-recursion-queries</command> default
- from 75 to 100. Since the queries sent towards root and
- TLD servers are now included in the count (as a result
- of the fix for CVE-2020-8616),
- <command>max-recursion-queries</command> has a higher
- chance of being exceeded by non-attack queries, which is
- the main reason for increasing its default value. [GL
- #2305]
+ The default value of <command>max-recursion-queries</command> was
+ increased from 75 to 100. Since the queries sent towards root and TLD
+ servers are now included in the count (as a result of the fix for
+ CVE-2020-8616), <command>max-recursion-queries</command> has a higher
+ chance of being exceeded by non-attack queries, which is the main
+ reason for increasing its default value. [GL #2305]
</para>
</listitem>
<listitem>
<para>
- Restore the <command>nocookie-udp-size</command> default from 1232 to
- 4096. Normally the EDNS buffer size is configured by
- <command>max-udp-size</command>, but this configuration option
- overrides the value, but most people don't and won't realize there's
- an extra configuration option that needs to be tweaked. By changing
- the default here, we allow the the <command>max-udp-size</command> to
- be the sole option that needs to be changed when operator wants to
- change the default EDNS buffer size. [GL #2250]
+ The default value of <command>nocookie-udp-size</command> was restored
+ back to 4096 bytes. Since <command>max-udp-size</command> is the upper
+ bound for <command>nocookie-udp-size</command>, this change relieves
+ the operator from having to change
+ <command>nocookie-udp-size</command> together with
+ <command>max-udp-size</command> in order to increase the default EDNS
+ buffer size limit. <command>nocookie-udp-size</command> can still be
+ set to a value lower than <command>max-udp-size</command>, if desired.
+ [GL #2250]
</para>
</listitem>
</itemizedlist>
<itemizedlist>
<listitem>
<para>
- Tighten handling of missing DNS COOKIE responses over UDP by
+ Handling of missing DNS COOKIE responses over UDP was tightened by
falling back to TCP. [GL #2275]
</para>
</listitem>
<listitem>
<para>
- Building with native PKCS#11 support for AEP Keyper has
- been broken since BIND 9.11.22. This has been fixed. [GL
+ Building with native PKCS#11 support for AEP Keyper has been broken
+ since BIND 9.11.22. This has been fixed. [GL #2315]
#2315]
</para>
</listitem>
<listitem>
<para>
- The synthesised CNAME from a DNAME was incorrectly followed
- when the QTYPE was CNAME or ANY. [GL #2280]
+ The CNAME synthesized from a DNAME was incorrectly followed when the
+ QTYPE was CNAME or ANY. [GL #2280]
</para>
</listitem>
</itemizedlist>