<section xml:id="relnotes-9.11.32-changes"><info><title>Feature Changes</title></info>
<itemizedlist>
+ <listitem>
+ <para>
+ DNSSEC responses containing NSEC3 records with iteration counts
+ greater than 150 are now treated as insecure. [GL #2445]
+ </para>
+ </listitem>
<listitem>
<para>
The maximum supported number of NSEC3 iterations that can be
</listitem>
<listitem>
<para>
- DNSSEC responses containing NSEC3 records with iteration counts
- greater than 150 are now treated as insecure. [GL #2445]
+ The implementation of the ZONEMD RR type has been updated to match RFC
+ 8976. [GL #2658]
</para>
</listitem>
</itemizedlist>
<itemizedlist>
<listitem>
<para>
- The implementation of the ZONEMD RR type has been updated to match RFC
- 8976. [GL #2658]
+ None.
</para>
</listitem>
</itemizedlist>