From: Tinderbox User Date: Tue, 13 Aug 2019 09:22:34 +0000 (+0000) Subject: prep 9.11.10 X-Git-Tag: v9.11.10^2~1 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=eb55184bda23cdad5947e387947eed7695147c05;p=thirdparty%2Fbind9.git prep 9.11.10 --- diff --git a/CHANGES b/CHANGES index 40fcab190f9..b31c6b578bc 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,5 @@ + --- 9.11.10 released --- + 5275. [bug] Mark DS records included in referral messages with trust level "pending" so that they can be validated and cached immediately, with no need to diff --git a/bin/named/named.conf.docbook b/bin/named/named.conf.docbook index 33a2bf13913..bc129bdb7bc 100644 --- a/bin/named/named.conf.docbook +++ b/bin/named/named.conf.docbook @@ -13,7 +13,7 @@ - 2019-02-20 + 2019-07-22 ISC diff --git a/doc/arm/Bv9ARM.ch01.html b/doc/arm/Bv9ARM.ch01.html index 0c199e41a5b..fd0cb37a678 100644 --- a/doc/arm/Bv9ARM.ch01.html +++ b/doc/arm/Bv9ARM.ch01.html @@ -616,6 +616,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch02.html b/doc/arm/Bv9ARM.ch02.html index 97bbc6148a5..ff13db83f71 100644 --- a/doc/arm/Bv9ARM.ch02.html +++ b/doc/arm/Bv9ARM.ch02.html @@ -151,6 +151,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch03.html b/doc/arm/Bv9ARM.ch03.html index b5d748c9edf..7bebb2a5f83 100644 --- a/doc/arm/Bv9ARM.ch03.html +++ b/doc/arm/Bv9ARM.ch03.html @@ -759,6 +759,6 @@ controls { -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch04.html b/doc/arm/Bv9ARM.ch04.html index d90daf638da..b851fac5637 100644 --- a/doc/arm/Bv9ARM.ch04.html +++ b/doc/arm/Bv9ARM.ch04.html @@ -2867,6 +2867,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa. -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch05.html b/doc/arm/Bv9ARM.ch05.html index 9a156d8de82..25c04fa384b 100644 --- a/doc/arm/Bv9ARM.ch05.html +++ b/doc/arm/Bv9ARM.ch05.html @@ -142,6 +142,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch06.html b/doc/arm/Bv9ARM.ch06.html index 14a209c7ff7..5b0f3001819 100644 --- a/doc/arm/Bv9ARM.ch06.html +++ b/doc/arm/Bv9ARM.ch06.html @@ -2473,7 +2473,7 @@ badresp:1,adberr:0,findfail:0,valfail:0] check-wildcard boolean; cleaning-interval integer; clients-per-query integer; - cookie-algorithm ( aes | sha1 | sha256 ); + cookie-algorithm ( aes | sha1 | sha256 | siphash24 ); cookie-secret string; coresize ( default | unlimited | sizeval ); datasize ( default | unlimited | sizeval ); @@ -3483,7 +3483,9 @@ options {

Compatible IPv6 prefixes have lengths of 32, 40, 48, 56, - 64 and 96 as per RFC 6052. + 64 and 96 as per RFC 6052. Bits 64..71 inclusive must + be zero with the most significate bit of the prefix in + position 0.

Additionally a reverse IP6.ARPA zone will be created for @@ -7683,6 +7685,14 @@ deny-answer-aliases { "example.net"; }; than that is a configuration error.

+

+ Rules encoded in response policy zones are processed after + Access Control Lists + (ACLs). All queries from clients which are not + permitted access to the resolver will be answered with a + status code of REFUSED, regardless of configured RPZ rules. +

+

Five policy triggers can be encoded in RPZ records.

@@ -14672,6 +14682,6 @@ HOST-127.EXAMPLE. MX 0 . -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch07.html b/doc/arm/Bv9ARM.ch07.html index 936fa2885a0..98efd477fa7 100644 --- a/doc/arm/Bv9ARM.ch07.html +++ b/doc/arm/Bv9ARM.ch07.html @@ -400,6 +400,6 @@ allow-query { !{ !10/8; any; }; key example; }; -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch08.html b/doc/arm/Bv9ARM.ch08.html index 74ed7dd0d71..4ab6c33c1f7 100644 --- a/doc/arm/Bv9ARM.ch08.html +++ b/doc/arm/Bv9ARM.ch08.html @@ -136,6 +136,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch09.html b/doc/arm/Bv9ARM.ch09.html index 0f4793c765d..8e5bde693c6 100644 --- a/doc/arm/Bv9ARM.ch09.html +++ b/doc/arm/Bv9ARM.ch09.html @@ -36,7 +36,7 @@

-Release Notes for BIND Version 9.11.9

+Release Notes for BIND Version 9.11.10

@@ -124,7 +124,8 @@

New Features

-
  • +
      +
    • The new GeoIP2 API from MaxMind is now supported when BIND is compiled using configure --with-geoip2. @@ -152,18 +153,79 @@ as. All of the databases support both IPv4 and IPv6 lookups. [GL #182]

      -
    +
  • +
  • +

    + A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added. + [GL #605] +

    +

    + If you are running multiple DNS Servers (different versions of BIND 9 + or DNS server from multiple vendors) responding from the same IP + address (anycast or load-balancing scenarios), you'll have to make + sure that all the servers are configured with the same DNS Cookie + algorithm and same Server Secret for the best performance. +

    +
  • +
  • +

    + DS records included in DNS referral messages can now be validated + and cached immediately, reducing the number of queries needed for + a DNSSEC validation. [GL #964] +

    +
  • +

Bug Fixes

-
  • +
      +
    • Glue address records were not being returned in responses to root priming queries; this has been corrected. [GL #1092]

      -
    +
  • +
  • +

    + Glue address records were not being returned in responses + to root priming queries; this has been corrected. [GL #1092] +

    +
  • +
  • +

    + Interaction between DNS64 and RPZ No Data rule (CNAME *.) could + cause unexpected results; this has been fixed. [GL #1106] +

    +
  • +
  • +

    + named-checkconf now checks DNS64 prefixes + to ensure bits 64-71 are zero. [GL #1159] +

    +
  • +
  • +

    + named-checkconf could crash during + configuration if configured to use "geoip continent" ACLs with + legacy GeoIP. [GL #1163] +

    +
  • +
  • +

    + named-checkconf now correctly reports missing + dnstap-output option when + dnstap is set. [GL #1136] +

    +
  • +
  • +

    + Handle ETIMEDOUT error on connect() with a non-blocking + socket. [GL #1133] +

    +
  • +
@@ -206,6 +268,6 @@
-

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch10.html b/doc/arm/Bv9ARM.ch10.html index 81e55ad3257..23c56e80e0f 100644 --- a/doc/arm/Bv9ARM.ch10.html +++ b/doc/arm/Bv9ARM.ch10.html @@ -148,6 +148,6 @@

-

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch11.html b/doc/arm/Bv9ARM.ch11.html index f9e931617ef..360dc89a95e 100644 --- a/doc/arm/Bv9ARM.ch11.html +++ b/doc/arm/Bv9ARM.ch11.html @@ -914,6 +914,6 @@
-

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch12.html b/doc/arm/Bv9ARM.ch12.html index a7f228c76be..5698f4a423e 100644 --- a/doc/arm/Bv9ARM.ch12.html +++ b/doc/arm/Bv9ARM.ch12.html @@ -533,6 +533,6 @@ $ sample-update -a sample-update -k Kxxx.+nnn+mm
-

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/Bv9ARM.ch13.html b/doc/arm/Bv9ARM.ch13.html index e8ae3910cdd..e91ef06c25e 100644 --- a/doc/arm/Bv9ARM.ch13.html +++ b/doc/arm/Bv9ARM.ch13.html @@ -213,6 +213,6 @@
-

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.arpaname.html b/doc/arm/man.arpaname.html index 982a3548f62..fb099d5533d 100644 --- a/doc/arm/man.arpaname.html +++ b/doc/arm/man.arpaname.html @@ -91,6 +91,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.ddns-confgen.html b/doc/arm/man.ddns-confgen.html index 87705ee4cf3..8afcbfa32ef 100644 --- a/doc/arm/man.ddns-confgen.html +++ b/doc/arm/man.ddns-confgen.html @@ -236,6 +236,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.delv.html b/doc/arm/man.delv.html index 1239aac5d09..e4ba6aa7bcb 100644 --- a/doc/arm/man.delv.html +++ b/doc/arm/man.delv.html @@ -624,6 +624,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dig.html b/doc/arm/man.dig.html index 5d1d96c005a..e72a4299e97 100644 --- a/doc/arm/man.dig.html +++ b/doc/arm/man.dig.html @@ -508,16 +508,28 @@

Toggles the printing of the initial comment in the - output identifying the version of dig - and the query options that have been applied. This - comment is printed by default. + output, identifying the version of dig + and the query options that have been applied. This option + always has global effect; it cannot be set globally + and then overridden on a per-lookup basis. The default + is to print this comment.

+[no]comments

- Toggle the display of comment lines in the output. - The default is to print comments. + Toggles the display of some comment lines in the output, + containing information about the packet header and + OPT pseudosection, and the names of the response + section. The default is to print these comments. +

+

+ Other types of comments in the output are not affected by + this option, but can be controlled using other command + line switches. These include +[no]cmd, + +[no]question, + +[no]stats, and + +[no]rrcomments.

+[no]cookie[=####]
@@ -763,14 +775,14 @@
+[no]qr

- Print [do not print] the query as it is sent. By - default, the query is not printed. + Toggles the display of the query message as it is sent. + By default, the query is not printed.

+[no]question

- Print [do not print] the question section of a query + Toggles the display of the question section of a query when an answer is returned. The default is to print the question section as a comment.

@@ -832,7 +844,9 @@

Provide a terse answer. The default is to print the - answer in a verbose form. + answer in a verbose form. This option always has global + effect; it cannot be set globally and then overridden on + a per-lookup basis.

+[no]showsearch
@@ -866,10 +880,9 @@
+[no]stats

- This query option toggles the printing of statistics: - when the query was made, the size of the reply and - so on. The default behavior is to print the query - statistics. + Toggles the printing of statistics: when the query was made, + the size of the reply and so on. The default behavior is to + print the query statistics as a comment after each lookup.

+[no]subnet=addr[/prefix-length]
@@ -1130,6 +1143,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-checkds.html b/doc/arm/man.dnssec-checkds.html index a70c64dab23..69ad8e24bd8 100644 --- a/doc/arm/man.dnssec-checkds.html +++ b/doc/arm/man.dnssec-checkds.html @@ -148,6 +148,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-coverage.html b/doc/arm/man.dnssec-coverage.html index 9887426d5ad..aee3316f447 100644 --- a/doc/arm/man.dnssec-coverage.html +++ b/doc/arm/man.dnssec-coverage.html @@ -270,6 +270,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-dsfromkey.html b/doc/arm/man.dnssec-dsfromkey.html index 104a7668fc1..2713e31c450 100644 --- a/doc/arm/man.dnssec-dsfromkey.html +++ b/doc/arm/man.dnssec-dsfromkey.html @@ -352,6 +352,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-importkey.html b/doc/arm/man.dnssec-importkey.html index 887e12bfe00..cbe97679233 100644 --- a/doc/arm/man.dnssec-importkey.html +++ b/doc/arm/man.dnssec-importkey.html @@ -250,6 +250,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-keyfromlabel.html b/doc/arm/man.dnssec-keyfromlabel.html index 0202ae7ff13..1819bb2f587 100644 --- a/doc/arm/man.dnssec-keyfromlabel.html +++ b/doc/arm/man.dnssec-keyfromlabel.html @@ -492,6 +492,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-keygen.html b/doc/arm/man.dnssec-keygen.html index f5a26d46360..d6804aee435 100644 --- a/doc/arm/man.dnssec-keygen.html +++ b/doc/arm/man.dnssec-keygen.html @@ -583,6 +583,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-keymgr.html b/doc/arm/man.dnssec-keymgr.html index cd7ea885ef7..da5f4f0afe6 100644 --- a/doc/arm/man.dnssec-keymgr.html +++ b/doc/arm/man.dnssec-keymgr.html @@ -416,6 +416,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-revoke.html b/doc/arm/man.dnssec-revoke.html index 5efe76ffb89..64aafceaeff 100644 --- a/doc/arm/man.dnssec-revoke.html +++ b/doc/arm/man.dnssec-revoke.html @@ -171,6 +171,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-settime.html b/doc/arm/man.dnssec-settime.html index 0f898d252b9..aaf2064dbd7 100644 --- a/doc/arm/man.dnssec-settime.html +++ b/doc/arm/man.dnssec-settime.html @@ -349,6 +349,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-signzone.html b/doc/arm/man.dnssec-signzone.html index 9d3263cf368..407ff1c1b06 100644 --- a/doc/arm/man.dnssec-signzone.html +++ b/doc/arm/man.dnssec-signzone.html @@ -708,6 +708,6 @@ db.example.com.signed -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnssec-verify.html b/doc/arm/man.dnssec-verify.html index e50435a4f93..1e91d58aa02 100644 --- a/doc/arm/man.dnssec-verify.html +++ b/doc/arm/man.dnssec-verify.html @@ -202,6 +202,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.dnstap-read.html b/doc/arm/man.dnstap-read.html index b9bd94a4d5f..f1079f27d5a 100644 --- a/doc/arm/man.dnstap-read.html +++ b/doc/arm/man.dnstap-read.html @@ -134,6 +134,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.genrandom.html b/doc/arm/man.genrandom.html index 85a98c0fcfc..efe9ffccb54 100644 --- a/doc/arm/man.genrandom.html +++ b/doc/arm/man.genrandom.html @@ -127,6 +127,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.host.html b/doc/arm/man.host.html index 29ba82d44ab..d798eb7bd12 100644 --- a/doc/arm/man.host.html +++ b/doc/arm/man.host.html @@ -366,6 +366,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.isc-hmac-fixup.html b/doc/arm/man.isc-hmac-fixup.html index 7c73ccfa000..4d201e1e887 100644 --- a/doc/arm/man.isc-hmac-fixup.html +++ b/doc/arm/man.isc-hmac-fixup.html @@ -126,6 +126,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.lwresd.html b/doc/arm/man.lwresd.html index 3b33d1b28da..1b5103ad9b2 100644 --- a/doc/arm/man.lwresd.html +++ b/doc/arm/man.lwresd.html @@ -329,6 +329,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.mdig.html b/doc/arm/man.mdig.html index d7b11b82aaf..273ea6249de 100644 --- a/doc/arm/man.mdig.html +++ b/doc/arm/man.mdig.html @@ -609,6 +609,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.named-checkconf.html b/doc/arm/man.named-checkconf.html index bad7011d1a6..0944776fd7a 100644 --- a/doc/arm/man.named-checkconf.html +++ b/doc/arm/man.named-checkconf.html @@ -192,6 +192,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.named-checkzone.html b/doc/arm/man.named-checkzone.html index add689e151f..abf3b23ac83 100644 --- a/doc/arm/man.named-checkzone.html +++ b/doc/arm/man.named-checkzone.html @@ -463,6 +463,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.named-journalprint.html b/doc/arm/man.named-journalprint.html index a95539d65cb..520c5cec80f 100644 --- a/doc/arm/man.named-journalprint.html +++ b/doc/arm/man.named-journalprint.html @@ -117,6 +117,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.named-nzd2nzf.html b/doc/arm/man.named-nzd2nzf.html index 8afc1ce31d8..9c675055cac 100644 --- a/doc/arm/man.named-nzd2nzf.html +++ b/doc/arm/man.named-nzd2nzf.html @@ -119,6 +119,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.named-rrchecker.html b/doc/arm/man.named-rrchecker.html index 6de1fe02b16..0f59e9f70d3 100644 --- a/doc/arm/man.named-rrchecker.html +++ b/doc/arm/man.named-rrchecker.html @@ -121,6 +121,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.named.conf.html b/doc/arm/man.named.conf.html index 1fe1ae14266..14f6d31fbd6 100644 --- a/doc/arm/man.named.conf.html +++ b/doc/arm/man.named.conf.html @@ -244,7 +244,7 @@ options check-wildcard boolean;
cleaning-interval integer;
clients-per-query integer;
- cookie-algorithm ( aes | sha1 | sha256 );
+ cookie-algorithm ( aes | sha1 | sha256 | siphash24 );
cookie-secret string;
coresize ( default | unlimited | sizeval );
datasize ( default | unlimited | sizeval );
@@ -1034,6 +1034,6 @@ zone -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.named.html b/doc/arm/man.named.html index 219baa0a69b..f5ef8a53d8e 100644 --- a/doc/arm/man.named.html +++ b/doc/arm/man.named.html @@ -490,6 +490,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.nsec3hash.html b/doc/arm/man.nsec3hash.html index 46e167eab05..b3b4c941e4a 100644 --- a/doc/arm/man.nsec3hash.html +++ b/doc/arm/man.nsec3hash.html @@ -131,6 +131,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.nslookup.html b/doc/arm/man.nslookup.html index 3ff91c7f014..8fdf7c6a7b5 100644 --- a/doc/arm/man.nslookup.html +++ b/doc/arm/man.nslookup.html @@ -436,6 +436,6 @@ nslookup -query=hinfo -timeout=10 -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.nsupdate.html b/doc/arm/man.nsupdate.html index 5f8545d8af6..c16d4039dc1 100644 --- a/doc/arm/man.nsupdate.html +++ b/doc/arm/man.nsupdate.html @@ -817,6 +817,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.pkcs11-destroy.html b/doc/arm/man.pkcs11-destroy.html index 6be35067960..71cf93c5214 100644 --- a/doc/arm/man.pkcs11-destroy.html +++ b/doc/arm/man.pkcs11-destroy.html @@ -162,6 +162,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.pkcs11-keygen.html b/doc/arm/man.pkcs11-keygen.html index d01c5a85735..34372e65a15 100644 --- a/doc/arm/man.pkcs11-keygen.html +++ b/doc/arm/man.pkcs11-keygen.html @@ -200,6 +200,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.pkcs11-list.html b/doc/arm/man.pkcs11-list.html index db859923019..814c825a424 100644 --- a/doc/arm/man.pkcs11-list.html +++ b/doc/arm/man.pkcs11-list.html @@ -158,6 +158,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.pkcs11-tokens.html b/doc/arm/man.pkcs11-tokens.html index 3ade68620bf..17af532d673 100644 --- a/doc/arm/man.pkcs11-tokens.html +++ b/doc/arm/man.pkcs11-tokens.html @@ -119,6 +119,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.rndc-confgen.html b/doc/arm/man.rndc-confgen.html index 738695c5e9a..acaffbcf402 100644 --- a/doc/arm/man.rndc-confgen.html +++ b/doc/arm/man.rndc-confgen.html @@ -277,6 +277,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.rndc.conf.html b/doc/arm/man.rndc.conf.html index 91be67efb5e..7f1637897a3 100644 --- a/doc/arm/man.rndc.conf.html +++ b/doc/arm/man.rndc.conf.html @@ -268,6 +268,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/man.rndc.html b/doc/arm/man.rndc.html index 4f24bd72c89..3c541da1dec 100644 --- a/doc/arm/man.rndc.html +++ b/doc/arm/man.rndc.html @@ -894,6 +894,6 @@ -

BIND 9.11.9 (Extended Support Version)

+

BIND 9.11.10 (Extended Support Version)

diff --git a/doc/arm/notes.xml b/doc/arm/notes.xml index 4297a89e6f3..08a02fa9537 100644 --- a/doc/arm/notes.xml +++ b/doc/arm/notes.xml @@ -115,6 +115,7 @@ A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added. + [GL #605] If you are running multiple DNS Servers (different versions of BIND 9 @@ -142,6 +143,38 @@ to root priming queries; this has been corrected. [GL #1092] + + + Interaction between DNS64 and RPZ No Data rule (CNAME *.) could + cause unexpected results; this has been fixed. [GL #1106] + + + + + named-checkconf now checks DNS64 prefixes + to ensure bits 64-71 are zero. [GL #1159] + + + + + named-checkconf could crash during + configuration if configured to use "geoip continent" ACLs with + legacy GeoIP. [GL #1163] + + + + + named-checkconf now correctly reports missing + dnstap-output option when + dnstap is set. [GL #1136] + + + + + Handle ETIMEDOUT error on connect() with a non-blocking + socket. [GL #1133] + + diff --git a/doc/arm/options.grammar.xml b/doc/arm/options.grammar.xml index 184973f849e..6a8796ae029 100644 --- a/doc/arm/options.grammar.xml +++ b/doc/arm/options.grammar.xml @@ -62,7 +62,7 @@ check-wildcard boolean; cleaning-interval integer; clients-per-query integer; - cookie-algorithm ( aes | sha1 | sha256 ); + cookie-algorithm ( aes | sha1 | sha256 | siphash24 ); cookie-secret string; coresize ( default | unlimited | sizeval ); datasize ( default | unlimited | sizeval ); diff --git a/lib/bind9/api b/lib/bind9/api index 2fbdc78024e..00eb68989dd 100644 --- a/lib/bind9/api +++ b/lib/bind9/api @@ -9,5 +9,5 @@ # 9.11: 160-169,1100-1199 # 9.12: 1200-1299 LIBINTERFACE = 161 -LIBREVISION = 2 +LIBREVISION = 3 LIBAGE = 0 diff --git a/lib/dns/api b/lib/dns/api index 623c05a29cb..b114ab54a1d 100644 --- a/lib/dns/api +++ b/lib/dns/api @@ -8,6 +8,6 @@ # 9.10-sub: 180-189 # 9.11: 160-169,1100-1199 # 9.12: 1200-1299 -LIBINTERFACE = 1106 -LIBREVISION = 2 +LIBINTERFACE = 1107 +LIBREVISION = 0 LIBAGE = 0 diff --git a/lib/isc/api b/lib/isc/api index 13ceae1114c..b4ce33f22b6 100644 --- a/lib/isc/api +++ b/lib/isc/api @@ -8,6 +8,6 @@ # 9.10-sub: 180-189 # 9.11: 160-169,1100-1199 # 9.12: 1200-1299 -LIBINTERFACE = 1102 +LIBINTERFACE = 1103 LIBREVISION = 0 -LIBAGE = 2 +LIBAGE = 3 diff --git a/lib/isccfg/api b/lib/isccfg/api index 0c2a5f693bc..6bfd0867386 100644 --- a/lib/isccfg/api +++ b/lib/isccfg/api @@ -9,5 +9,5 @@ # 9.11: 160-169,1100-1199 # 9.12: 1200-1299 LIBINTERFACE = 163 -LIBREVISION = 1 +LIBREVISION = 2 LIBAGE = 0 diff --git a/version b/version index 5b14fbece44..da1c1dc5547 100644 --- a/version +++ b/version @@ -5,7 +5,7 @@ PRODUCT=BIND DESCRIPTION="(Extended Support Version)" MAJORVER=9 MINORVER=11 -PATCHVER=9 +PATCHVER=10 RELEASETYPE= RELEASEVER= EXTENSIONS=