From: Petr Špaček Date: Fri, 14 Apr 2023 08:51:23 +0000 (+0200) Subject: Set up release notes for BIND 9.19.13 X-Git-Tag: v9.19.13~34^2~1 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=0fb1e00469071c89d4f60a2d2910620aeaee7c7e;p=thirdparty%2Fbind9.git Set up release notes for BIND 9.19.13 --- diff --git a/doc/notes/notes-current.rst b/doc/notes/notes-current.rst index d2bc6ef6194..5653301c0c0 100644 --- a/doc/notes/notes-current.rst +++ b/doc/notes/notes-current.rst @@ -9,7 +9,7 @@ .. See the COPYRIGHT file distributed with this work for additional .. information regarding copyright ownership. -Notes for BIND 9.19.12 +Notes for BIND 9.19.13 ---------------------- Security Fixes @@ -20,41 +20,12 @@ Security Fixes New Features ~~~~~~~~~~~~ -- BIND now depends on ``liburcu``, Userspace RCU, for lock-free data - structures. :gl:`#3934` - -- The new ``delv +ns`` option activates name server mode, in which ``delv`` - sets up an internal recursive resolver and uses that, rather than an - external server, to look up the requested query name and type. All messages - sent and received during the resolution and validation process are logged. - This can be used in place of ``dig +trace``: it more accurately - reproduces the behavior of ``named`` when resolving a query. - - The log message ``resolver priming query complete`` was moved from the - INFO log level to the DEBUG(1) log level, to prevent ``delv`` from - emitting that message when setting up its internal resolver. :gl:`#3842` - -- A new configuration option :any:`checkds` is introduced that when set to - ``yes`` will detect :any:`parental-agents` automatically by resolving the - parent NS records. These name servers will be used to check the DS RRset - during a KSK rollover initiated by :any:`dnssec-policy`. :gl:`#3901` +- None. Removed Features ~~~~~~~~~~~~~~~~ -- The TKEY Mode 2 (Diffie-Hellman Exchanged Keying Mode) has been removed and - using TKEY Mode 2 is now a fatal error. Users are advised to switch to TKEY - Mode 3 (GSS-API). :gl:`#3905` - -- Zone type ``delegation-only``, and the ``delegation-only`` and - ``root-delegation-only`` options, have been removed. Using them - is a configuration error. - - These options were created to address the SiteFinder controversy, in - which certain top-level domains redirected misspelled queries to other - sites instead of returning NXDOMAIN responses. Since top-level domains are - now DNSSEC signed, and DNSSEC validation is active by default, the - options are no longer needed. :gl:`#3953` +- None. Feature Changes ~~~~~~~~~~~~~~~ @@ -64,8 +35,7 @@ Feature Changes Bug Fixes ~~~~~~~~~ -- Performance of DNSSEC validation in zones with many DNSKEY records - has been improved. :gl:`#3981` +- None. Known Issues ~~~~~~~~~~~~