]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
doc rebuild
authorTinderbox User <tbox@isc.org>
Sat, 6 Apr 2019 01:47:20 +0000 (01:47 +0000)
committerTinderbox User <tbox@isc.org>
Sat, 6 Apr 2019 01:47:20 +0000 (01:47 +0000)
57 files changed:
README
doc/arm/Bv9ARM.ch01.html
doc/arm/Bv9ARM.ch02.html
doc/arm/Bv9ARM.ch03.html
doc/arm/Bv9ARM.ch04.html
doc/arm/Bv9ARM.ch05.html
doc/arm/Bv9ARM.ch06.html
doc/arm/Bv9ARM.ch07.html
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.ch09.html
doc/arm/Bv9ARM.ch10.html
doc/arm/Bv9ARM.ch11.html
doc/arm/Bv9ARM.ch12.html
doc/arm/Bv9ARM.ch13.html
doc/arm/Bv9ARM.html
doc/arm/Bv9ARM.pdf
doc/arm/man.arpaname.html
doc/arm/man.ddns-confgen.html
doc/arm/man.delv.html
doc/arm/man.dig.html
doc/arm/man.dnssec-checkds.html
doc/arm/man.dnssec-coverage.html
doc/arm/man.dnssec-dsfromkey.html
doc/arm/man.dnssec-importkey.html
doc/arm/man.dnssec-keyfromlabel.html
doc/arm/man.dnssec-keygen.html
doc/arm/man.dnssec-keymgr.html
doc/arm/man.dnssec-revoke.html
doc/arm/man.dnssec-settime.html
doc/arm/man.dnssec-signzone.html
doc/arm/man.dnssec-verify.html
doc/arm/man.dnstap-read.html
doc/arm/man.genrandom.html
doc/arm/man.host.html
doc/arm/man.isc-hmac-fixup.html
doc/arm/man.lwresd.html
doc/arm/man.mdig.html
doc/arm/man.named-checkconf.html
doc/arm/man.named-checkzone.html
doc/arm/man.named-journalprint.html
doc/arm/man.named-nzd2nzf.html
doc/arm/man.named-rrchecker.html
doc/arm/man.named.conf.html
doc/arm/man.named.html
doc/arm/man.nsec3hash.html
doc/arm/man.nslookup.html
doc/arm/man.nsupdate.html
doc/arm/man.pkcs11-destroy.html
doc/arm/man.pkcs11-keygen.html
doc/arm/man.pkcs11-list.html
doc/arm/man.pkcs11-tokens.html
doc/arm/man.rndc-confgen.html
doc/arm/man.rndc.conf.html
doc/arm/man.rndc.html
doc/arm/notes.html
doc/arm/notes.pdf
doc/arm/notes.txt

diff --git a/README b/README
index cf2880557f8c68cf1b21fad55d896d446b73563e..3b28ae32f7d0f87a30994a1c9a8f71927146565d 100644 (file)
--- a/README
+++ b/README
@@ -265,6 +265,11 @@ BIND 9.11.6
 BIND 9.11.6 is a maintenance release, and also addresses the security
 flaws disclosed in CVE-2018-5744, CVE-2018-5745, and CVE-2019-6465.
 
+BIND 9.11.6-P1
+
+BIND 9.11.6-P1 addresses the security vulnerability disclosed in
+CVE-2018-5743.
+
 Building BIND
 
 BIND requires a UNIX or Linux system with an ANSI C compiler, basic POSIX
index e77e4a743bae7f6cf056cc085ba13c841185fbb0..adc7430667398426cefbdb24acff3955a0c2cc5e 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index a38ae89902bedfcc527776b40e428510cdd9c7f5..54f42326c30aabc38f163552e3f8cb8d771fe1d5 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 02805c3665d42df5414d336d1dbec63afdd78e61..777fd4e573984dc1ef9b0dfcd811d2b61b366b50 100644 (file)
@@ -759,6 +759,6 @@ controls {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index f33cfa6e450a4d8f75f7564df5b683a7637b87f6..9ec539676c33731ec45f8e989ef1c6165e9c5259 100644 (file)
@@ -2867,6 +2867,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index fe82e0ec4da7892c90c483e9e9f0cd6b09c90c8e..2d09741b770e8cfe6cc575c18af8786ddc1e782b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index c4adec211f3f5f10db474c5e38bc22f816bf7034..7facb4d5b7fcdc3ea2201ccc74b06432a1651d8f 100644 (file)
@@ -6364,7 +6364,8 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
                 <p>
                   The number of file descriptors reserved for TCP, stdio,
                   etc.  This needs to be big enough to cover the number of
-                  interfaces <span class="command"><strong>named</strong></span> listens on, <span class="command"><strong>tcp-clients</strong></span> as well as
+                  interfaces <span class="command"><strong>named</strong></span> listens on plus
+                  <span class="command"><strong>tcp-clients</strong></span>, as well as
                   to provide room for outgoing TCP queries and incoming zone
                   transfers.  The default is <code class="literal">512</code>.
                   The minimum value is <code class="literal">128</code> and the
@@ -14676,6 +14677,6 @@ HOST-127.EXAMPLE. MX 0 .
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 5a5684faf2256258260ff2191448009172e6e765..d3d729a627593f2fd9f476a71f3a82eca23557db 100644 (file)
@@ -399,6 +399,6 @@ allow-query { !{ !10/8; any; }; key example; };
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 0a8592e3e7028f730379e82181ec557ff8afb9e4..220f0c93bc3bd52b057be037654b8c9ca52c2797 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 7fdb52765a3c7745dc585003b8dd54f965378557..8687123d3c88915843fa0720199e30c1f117a179 100644 (file)
@@ -36,7 +36,7 @@
 <div class="toc">
 <p><b>Table of Contents</b></p>
 <dl class="toc">
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.6</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.6-P1</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
@@ -44,7 +44,6 @@
 <dt><span class="section"><a href="Bv9ARM.ch09.html#win_support">Legacy Windows No Longer Supported</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_removed">Removed Features</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
@@ -54,7 +53,7 @@
 </div>
       <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.6</h2></div></div></div>
+<a name="id-1.10.2"></a>Release Notes for BIND Version 9.11.6-P1</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could crash during recursive processing
-         of DNAME records when <span class="command"><strong>deny-answer-aliases</strong></span> was
-         in use. This flaw is disclosed in CVE-2018-5740. [GL #387]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When recursion is enabled but the <span class="command"><strong>allow-recursion</strong></span>
-         and <span class="command"><strong>allow-query-cache</strong></span> ACLs are not specified, they
-         should be limited to local networks, but they were inadvertently set
-         to match the default <span class="command"><strong>allow-query</strong></span>, thus allowing
-         remote queries. This flaw is disclosed in CVE-2018-5738. [GL #309]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Code change #4964, intended to prevent double signatures
-         when deleting an inactive zone DNSKEY in some situations,
-         introduced a new problem during zone processing in which
-         some delegation glue RRsets are incorrectly identified
-         as needing RRSIGs, which are then created for them using
-         the current active ZSK for the zone. In some, but not all
-         cases, the newly-signed RRsets are added to the zone's
-         NSEC/NSEC3 chain, but incompletely -- this can result in
-         a broken chain, affecting validation of proof of nonexistence
-         for records in the zone. [GL #771]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could crash if it managed a DNSSEC
-         security root with <span class="command"><strong>managed-keys</strong></span> and the
-         authoritative zone rolled the key to an algorithm not supported
-         by BIND 9.  This flaw is disclosed in CVE-2018-5745. [GL #780]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> leaked memory when processing a
-         request with multiple Key Tag EDNS options present. ISC
-         would like to thank Toshifumi Sakaguchi for bringing this
-         to our attention.  This flaw is disclosed in CVE-2018-5744.
-         [GL #772]
-       </p>
-      </li>
-<li class="listitem">
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         Zone transfer controls for writable DLZ zones were not
-         effective as the <span class="command"><strong>allowzonexfr</strong></span> method was
-         not being called for such zones. This flaw is disclosed in
-         CVE-2019-6465. [GL #790]
+         The TCP client quota set using the <span class="command"><strong>tcp-clients</strong></span>
+         option could be exceeded in some cases. This could lead to
+         exhaustion of file descriptors. This flaw is disclosed in
+         CVE-2018-5743. [GL #615]
        </p>
-      </li>
-</ul></div>
+      </li></ul></div>
   </div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_features"></a>New Features</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> now supports the "root key sentinel"
-         mechanism. This enables validating resolvers to indicate
-         which trust anchors are configured for the root, so that
-         information about root key rollover status can be gathered.
-         To disable this feature, add
-         <span class="command"><strong>root-key-sentinel no;</strong></span> to
-         <code class="filename">named.conf</code>.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Added the ability not to return a DNS COOKIE option when one
-         is present in the request.  To prevent a cookie being returned,
-         add <span class="command"><strong>answer-cookie no;</strong></span> to
-         <code class="filename">named.conf</code>. [GL #173]
-       </p>
-       <p>
-         <span class="command"><strong>answer-cookie no</strong></span> is only intended as a
-         temporary measure, for use when <span class="command"><strong>named</strong></span>
-         shares an IP address with other servers that do not yet
-         support DNS COOKIE.  A mismatch between servers on the
-         same address is not expected to cause operational problems,
-         but the option to disable COOKIE responses so that all
-         servers have the same behavior is provided out of an
-         abundance of caution. DNS COOKIE is an important security
-         mechanism, and should not be disabled unless absolutely
-         necessary.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Two new update policy rule types have been added
-         <span class="command"><strong>krb5-selfsub</strong></span> and <span class="command"><strong>ms-selfsub</strong></span>
-         which allow machines with Kerberos principals to update
-         the name space at or below the machine names identified
-         in the respective principals.
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_removed"></a>Removed Features</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         <span class="command"><strong>named</strong></span> will now log a warning if the old
-         BIND now can be compiled against libidn2 library to add
-         IDNA2008 support.  Previously BIND only supported IDNA2003
-         using (now obsolete) idnkit-1 library.
+         None.
        </p>
       </li></ul></div>
   </div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         <span class="command"><strong>dig +noidnin</strong></span> can be used to disable IDN
-         processing on the input domain name, when BIND is compiled
-         with IDN support.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Multiple <span class="command"><strong>cookie-secret</strong></span> clause are now
-         supported.  The first <span class="command"><strong>cookie-secret</strong></span> in
-         <code class="filename">named.conf</code> is used to generate new
-         server cookies.  Any others are used to accept old server
-         cookies or those generated by other servers using the
-         matching <span class="command"><strong>cookie-secret</strong></span>.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The <span class="command"><strong>rndc nta</strong></span> command could not differentiate
-         between views of the same name but different class; this
-         has been corrected with the addition of a <span class="command"><strong>-class</strong></span>
-         option. [GL #105]
-       </p>
-      </li>
-<li class="listitem">
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         When compiled with IDN support, the <span class="command"><strong>dig</strong></span> and the
-         <span class="command"><strong>nslookup</strong></span> commands now disable IDN processing when
-         the standard output is not a tty (e.g. not used by human).  The command
-         line options +idnin and +idnout need to be used to enable IDN
-         processing when <span class="command"><strong>dig</strong></span> or <span class="command"><strong>nslookup</strong></span>
-         is used from the shell scripts.
+         None.
        </p>
-      </li>
-</ul></div>
+      </li></ul></div>
   </div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         When a negative trust anchor was added to multiple views
-         using <span class="command"><strong>rndc nta</strong></span>, the text returned via
-         <span class="command"><strong>rndc</strong></span> was incorrectly truncated after the
-         first line, making it appear that only one NTA had been
-         added. This has been fixed. [GL #105]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> now rejects excessively large
-         incremental (IXFR) zone transfers in order to prevent
-         possible corruption of journal files which could cause
-         <span class="command"><strong>named</strong></span> to abort when loading zones. [GL #339]
-       </p>
-      </li>
-<li class="listitem">
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         <span class="command"><strong>rndc reload</strong></span> could cause <span class="command"><strong>named</strong></span>
-         to leak memory if it was invoked before the zone loading actions
-         from a previous <span class="command"><strong>rndc reload</strong></span> command were
-         completed. [RT #47076]
+         None.
        </p>
-      </li>
-</ul></div>
+      </li></ul></div>
   </div>
 
   <div class="section">
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index a444182a929215e3b0a3a780311a6b801a414dfd..6deb971740b1581e3ce9ee142748d88546e7e63b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index fb73a1c31e26b1b39718219078cd262f986176c8..e258d65d4967d31d5dbe4cacf263cfc0fef1b7c7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 2eacbe72384d91d60de4d968d469e9134b152cfc..490e9114a425a236997398cf268f73b60b864afd 100644 (file)
@@ -533,6 +533,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index d2f404adeafa388458a02700cbe66b4738871782..7ed047ecabdbb791d37f8b2038277359f5a3ba84 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index fa7e4ee512eb5fe13728f83081b742b81efb7b87..9f4a4e6e357891f4cb11c71c631b8783f636c7e5 100644 (file)
@@ -32,7 +32,7 @@
 <div>
 <div><h1 class="title">
 <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
-<div><p class="releaseinfo">BIND Version 9.11.6</p></div>
+<div><p class="releaseinfo">BIND Version 9.11.6-P1</p></div>
 <div><p class="copyright">Copyright Â© 2000-2019 Internet Systems Consortium, Inc. ("ISC")</p></div>
 </div>
 <hr>
 </dl></dd>
 <dt><span class="appendix"><a href="Bv9ARM.ch09.html">A. Release Notes</a></span></dt>
 <dd><dl>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.6</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch09.html#id-1.10.2">Release Notes for BIND Version 9.11.6-P1</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_download">Download</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#win_support">Legacy Windows No Longer Supported</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_security">Security Fixes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_features">New Features</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_removed">Removed Features</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_changes">Feature Changes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#relnotes_bugs">Bug Fixes</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch09.html#end_of_life">End of Life</a></span></dt>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index f4a1d461065310d52d9993dd7b4387610e9ef89d..d50717baebc5ffebdd825114fa487138b5ff2d3c 100644 (file)
Binary files a/doc/arm/Bv9ARM.pdf and b/doc/arm/Bv9ARM.pdf differ
index cde9e807c7944db87015cca035023e9ed42ac135..395bad2b63dd06ed880f767f882fca4309d0da6a 100644 (file)
@@ -91,6 +91,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 2756d41b0241505426046e3d1ee2b9f7cb97d660..205b2effc71fee3083b789adf8007d7eda47efda 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 73a6cd096329589a511f2bd4ef6fd478810cbab9..b71019e75429a80358606ccf01960aba9982bc0a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 63b6e562bce0e2d44657eef4483646d8b014de85..f30a4ade8779196047219ac7019de959fc9c79ee 100644 (file)
@@ -1128,6 +1128,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index dd4c18ba650d102b332942be75e7332ee12ec1e3..3a6e175b6cd85d5d363a6f2d274a2fa193c69f52 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 41253b217f747fc25c36c61066e911c53122c909..be9478b4b6456d9cd17503c818feb93e62ee5f3a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 625a2f99a74f21ee998ac19be694c0a9fb62eb88..c06a3560219f9f4d41788dbfffc71d77ab767d7b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 3b91c4921821f2cdfc838f9c132d055c25c3618c..f350497e5e74cbcc9639ef5be4e0fa08975bcc12 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index d2f7d4caaa77383e128a506a779a85d5c8b1fb1e..a936dd702ae07908fb2562d7f6356344e4afa070 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index a9081e9591e1742afa2a6967f19c56425ba00a47..dfb51c0d05d3f3558e8bb33695b17d6172bf593d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 352f81200e3d07b65eaaff0e7c1f5497080474fc..fc348c2c983b274d5bd0dae31600259be1e3b329 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index b768ab6f9497d06b1891c715003edb127d306de7..e9087374cbf9c4612af119d5b188ca0b2f2eaca4 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 14eded1e40f597df2bb10a11f45efcaac3a969c4..c5dc1af9232ff1af63c90cf2d1dcbaf178144166 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 946caf718cfcd945f6a6d6043127d4be4a666f3c..35948273b261fc861e94785b0e5a6dae2f717e28 100644 (file)
@@ -708,6 +708,6 @@ db.example.com.signed
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 9ca9af2cc3fc2a0b1658c06cc887e177d92eef5a..63b948a9d3450c0bfcc6e30abc37dd6d71f1f684 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 6bb1f24f209ca4d8c300373a33013ea5a6c49509..59f3271ebe77e75acb9b89c59aa54c016f4a99d6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 810dd515e765be697c08b7a702fcaa6252a4d837..f68c808795bbb4e64bd14e9f09a6fe335b72a737 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index cb5d945d73772c6d03ef1f38173c077608777fd0..1c7d82203df6b8dc492d19547def9acb3892da55 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 3365180b15e3d868769fc2142b00701ef51db991..65ebc3f4f38a67feb9a71ac2162700305cae5f83 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 43b97ca45870254c61e73056eef34cde3425aa4a..a5c57babb7d80f25bf3eacb56a79952c7108b0df 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 2decdb358c9b6c3923283979a340ddb27d61a8db..8fcfa030ee1effc7470661b7d53d4df104a5ab75 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 5e2fca546c6cb1146c7e6d3582ef7935475b32e1..3f4e73b4616e79db717c9b1a58fbd6d2245b543b 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index bcf37b869a8c0cb16cdc33881739e055a956c581..443a6c614c512365ea097e2147f957442dc6c4b6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index fc2202c05c3a581c80f08c502a6949f9bfa599a6..889ddceebde2b28a3718601ff3b792964d433992 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index e0df9b030cfae1a5692153f052854557d342f1bb..0927aaa532f726c28cf327e84db0dcc78a187d16 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index a5ba7b4486795a9d3a8039b9feced831079e1ff2..395eca2d5e8894f584d08f4323c5fa06eae22305 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index bf193698f7641145725c4f94fb52bbea3035bc82..fcb3df6eadb67ed47d8dbc86214a00bbd24af8d1 100644 (file)
@@ -1034,6 +1034,6 @@ zone
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 23bcad9aafa68a106899d75c079fd8e63c9bb72d..dbb82c356eb140dce6873be7a7e48001cbe3451a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index c6330a66e4b13416d8d505282c8b45ff2fcb18ae..ac3aaea47e6b84c470ca2e58fd5f5da966adeb01 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 7a388404f64df7c3d7f5e8742be349eb695fd85f..7edcd76db309469e6138d55daaf8f2d73a07b758 100644 (file)
@@ -436,6 +436,6 @@ nslookup -query=hinfo  -timeout=10
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index e152b897394ae86b1936ee4ab0a42d13fa44a297..7a6273954da3f4dc09336d885953f1e35c937dd4 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index fcad97d6645181defba3a43bc90c6759dcfa0f85..7ec83807432c202e5dec7036aa0566d4b8e87ebb 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 990928b24b22abfaa3de80377013aa46e8fc05a1..289fdc562759fe9986f66bc691096705af53c2d7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 9688d57c3b35a5c71e2b3dfc6f7eadd8a1ed34ec..d75d76699b9e7a6321399a56824528f46788db3e 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 8c9ec46a156a110604a678c03349fa4e50458e9b..33cf80705a7f47420424b0322b00a9cf658a8b58 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index b0b86e773439bd066e767294d74f7d5bfd24df95..2d0fd79ddd862115626030879e171e634a717483 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 4aedcd3e8d363559a942a74c2f4d52fab09fe7d8..fd0525103df2e53556bd079e563a42a95084d9c2 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index eb390adc55c4be57a745115f58d68c04e925f820..1dd2e9260c751f0d2f3bfe48229782e922839449 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6 (Extended Support Version)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.6-P1 (Extended Support Version)</p>
 </body>
 </html>
index 3b40f46f70320f6bcbc9a1319e1b2cb611c72ed0..abb0ef6fcaae0287dab394e507dd4d6c329759ad 100644 (file)
@@ -15,7 +15,7 @@
 
   <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.2"></a>Release Notes for BIND Version 9.11.6</h2></div></div></div>
+<a name="id-1.2"></a>Release Notes for BIND Version 9.11.6-P1</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could crash during recursive processing
-         of DNAME records when <span class="command"><strong>deny-answer-aliases</strong></span> was
-         in use. This flaw is disclosed in CVE-2018-5740. [GL #387]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         When recursion is enabled but the <span class="command"><strong>allow-recursion</strong></span>
-         and <span class="command"><strong>allow-query-cache</strong></span> ACLs are not specified, they
-         should be limited to local networks, but they were inadvertently set
-         to match the default <span class="command"><strong>allow-query</strong></span>, thus allowing
-         remote queries. This flaw is disclosed in CVE-2018-5738. [GL #309]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Code change #4964, intended to prevent double signatures
-         when deleting an inactive zone DNSKEY in some situations,
-         introduced a new problem during zone processing in which
-         some delegation glue RRsets are incorrectly identified
-         as needing RRSIGs, which are then created for them using
-         the current active ZSK for the zone. In some, but not all
-         cases, the newly-signed RRsets are added to the zone's
-         NSEC/NSEC3 chain, but incompletely -- this can result in
-         a broken chain, affecting validation of proof of nonexistence
-         for records in the zone. [GL #771]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> could crash if it managed a DNSSEC
-         security root with <span class="command"><strong>managed-keys</strong></span> and the
-         authoritative zone rolled the key to an algorithm not supported
-         by BIND 9.  This flaw is disclosed in CVE-2018-5745. [GL #780]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> leaked memory when processing a
-         request with multiple Key Tag EDNS options present. ISC
-         would like to thank Toshifumi Sakaguchi for bringing this
-         to our attention.  This flaw is disclosed in CVE-2018-5744.
-         [GL #772]
-       </p>
-      </li>
-<li class="listitem">
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         Zone transfer controls for writable DLZ zones were not
-         effective as the <span class="command"><strong>allowzonexfr</strong></span> method was
-         not being called for such zones. This flaw is disclosed in
-         CVE-2019-6465. [GL #790]
+         The TCP client quota set using the <span class="command"><strong>tcp-clients</strong></span>
+         option could be exceeded in some cases. This could lead to
+         exhaustion of file descriptors. This flaw is disclosed in
+         CVE-2018-5743. [GL #615]
        </p>
-      </li>
-</ul></div>
+      </li></ul></div>
   </div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_features"></a>New Features</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> now supports the "root key sentinel"
-         mechanism. This enables validating resolvers to indicate
-         which trust anchors are configured for the root, so that
-         information about root key rollover status can be gathered.
-         To disable this feature, add
-         <span class="command"><strong>root-key-sentinel no;</strong></span> to
-         <code class="filename">named.conf</code>.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Added the ability not to return a DNS COOKIE option when one
-         is present in the request.  To prevent a cookie being returned,
-         add <span class="command"><strong>answer-cookie no;</strong></span> to
-         <code class="filename">named.conf</code>. [GL #173]
-       </p>
-       <p>
-         <span class="command"><strong>answer-cookie no</strong></span> is only intended as a
-         temporary measure, for use when <span class="command"><strong>named</strong></span>
-         shares an IP address with other servers that do not yet
-         support DNS COOKIE.  A mismatch between servers on the
-         same address is not expected to cause operational problems,
-         but the option to disable COOKIE responses so that all
-         servers have the same behavior is provided out of an
-         abundance of caution. DNS COOKIE is an important security
-         mechanism, and should not be disabled unless absolutely
-         necessary.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Two new update policy rule types have been added
-         <span class="command"><strong>krb5-selfsub</strong></span> and <span class="command"><strong>ms-selfsub</strong></span>
-         which allow machines with Kerberos principals to update
-         the name space at or below the machine names identified
-         in the respective principals.
-       </p>
-      </li>
-</ul></div>
-  </div>
-
-  <div class="section">
-<div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_removed"></a>Removed Features</h3></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         <span class="command"><strong>named</strong></span> will now log a warning if the old
-         BIND now can be compiled against libidn2 library to add
-         IDNA2008 support.  Previously BIND only supported IDNA2003
-         using (now obsolete) idnkit-1 library.
+         None.
        </p>
       </li></ul></div>
   </div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_changes"></a>Feature Changes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         <span class="command"><strong>dig +noidnin</strong></span> can be used to disable IDN
-         processing on the input domain name, when BIND is compiled
-         with IDN support.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         Multiple <span class="command"><strong>cookie-secret</strong></span> clause are now
-         supported.  The first <span class="command"><strong>cookie-secret</strong></span> in
-         <code class="filename">named.conf</code> is used to generate new
-         server cookies.  Any others are used to accept old server
-         cookies or those generated by other servers using the
-         matching <span class="command"><strong>cookie-secret</strong></span>.
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         The <span class="command"><strong>rndc nta</strong></span> command could not differentiate
-         between views of the same name but different class; this
-         has been corrected with the addition of a <span class="command"><strong>-class</strong></span>
-         option. [GL #105]
-       </p>
-      </li>
-<li class="listitem">
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         When compiled with IDN support, the <span class="command"><strong>dig</strong></span> and the
-         <span class="command"><strong>nslookup</strong></span> commands now disable IDN processing when
-         the standard output is not a tty (e.g. not used by human).  The command
-         line options +idnin and +idnout need to be used to enable IDN
-         processing when <span class="command"><strong>dig</strong></span> or <span class="command"><strong>nslookup</strong></span>
-         is used from the shell scripts.
+         None.
        </p>
-      </li>
-</ul></div>
+      </li></ul></div>
   </div>
 
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
-    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-       <p>
-         When a negative trust anchor was added to multiple views
-         using <span class="command"><strong>rndc nta</strong></span>, the text returned via
-         <span class="command"><strong>rndc</strong></span> was incorrectly truncated after the
-         first line, making it appear that only one NTA had been
-         added. This has been fixed. [GL #105]
-       </p>
-      </li>
-<li class="listitem">
-       <p>
-         <span class="command"><strong>named</strong></span> now rejects excessively large
-         incremental (IXFR) zone transfers in order to prevent
-         possible corruption of journal files which could cause
-         <span class="command"><strong>named</strong></span> to abort when loading zones. [GL #339]
-       </p>
-      </li>
-<li class="listitem">
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
        <p>
-         <span class="command"><strong>rndc reload</strong></span> could cause <span class="command"><strong>named</strong></span>
-         to leak memory if it was invoked before the zone loading actions
-         from a previous <span class="command"><strong>rndc reload</strong></span> command were
-         completed. [RT #47076]
+         None.
        </p>
-      </li>
-</ul></div>
+      </li></ul></div>
   </div>
 
   <div class="section">
index 840bb6748796ade1ff2a19d58202836d95bed6f4..e7c9babe3b6205474beaa7838bb9a567c44dfac6 100644 (file)
Binary files a/doc/arm/notes.pdf and b/doc/arm/notes.pdf differ
index 5c6bb77b2a28d1f293757adab91d1b9212ef3e5f..6f2ad74bf4188adce164cf0a145823f6c7069f76 100644 (file)
@@ -1,4 +1,4 @@
-Release Notes for BIND Version 9.11.6
+Release Notes for BIND Version 9.11.6-P1
 
 Introduction
 
@@ -41,106 +41,21 @@ from ISC.
 
 Security Fixes
 
-  * named could crash during recursive processing of DNAME records when
-    deny-answer-aliases was in use. This flaw is disclosed in
-    CVE-2018-5740. [GL #387]
-
-  * When recursion is enabled but the allow-recursion and
-    allow-query-cache ACLs are not specified, they should be limited to
-    local networks, but they were inadvertently set to match the default
-    allow-query, thus allowing remote queries. This flaw is disclosed in
-    CVE-2018-5738. [GL #309]
-
-  * Code change #4964, intended to prevent double signatures when deleting
-    an inactive zone DNSKEY in some situations, introduced a new problem
-    during zone processing in which some delegation glue RRsets are
-    incorrectly identified as needing RRSIGs, which are then created for
-    them using the current active ZSK for the zone. In some, but not all
-    cases, the newly-signed RRsets are added to the zone's NSEC/NSEC3
-    chain, but incompletely -- this can result in a broken chain,
-    affecting validation of proof of nonexistence for records in the zone.
-    [GL #771]
-
-  * named could crash if it managed a DNSSEC security root with
-    managed-keys and the authoritative zone rolled the key to an algorithm
-    not supported by BIND 9. This flaw is disclosed in CVE-2018-5745. [GL
-    #780]
-
-  * named leaked memory when processing a request with multiple Key Tag
-    EDNS options present. ISC would like to thank Toshifumi Sakaguchi for
-    bringing this to our attention. This flaw is disclosed in
-    CVE-2018-5744. [GL #772]
-
-  * Zone transfer controls for writable DLZ zones were not effective as
-    the allowzonexfr method was not being called for such zones. This flaw
-    is disclosed in CVE-2019-6465. [GL #790]
+  * The TCP client quota set using the tcp-clients option could be
+    exceeded in some cases. This could lead to exhaustion of file
+    descriptors. This flaw is disclosed in CVE-2018-5743. [GL #615]
 
 New Features
 
-  * named now supports the "root key sentinel" mechanism. This enables
-    validating resolvers to indicate which trust anchors are configured
-    for the root, so that information about root key rollover status can
-    be gathered. To disable this feature, add root-key-sentinel no; to
-    named.conf.
-
-  * Added the ability not to return a DNS COOKIE option when one is
-    present in the request. To prevent a cookie being returned, add
-    answer-cookie no; to named.conf. [GL #173]
-
-    answer-cookie no is only intended as a temporary measure, for use when
-    named shares an IP address with other servers that do not yet support
-    DNS COOKIE. A mismatch between servers on the same address is not
-    expected to cause operational problems, but the option to disable
-    COOKIE responses so that all servers have the same behavior is
-    provided out of an abundance of caution. DNS COOKIE is an important
-    security mechanism, and should not be disabled unless absolutely
-    necessary.
-
-  * Two new update policy rule types have been added krb5-selfsub and
-    ms-selfsub which allow machines with Kerberos principals to update the
-    name space at or below the machine names identified in the respective
-    principals.
-
-Removed Features
-
-  * named will now log a warning if the old BIND now can be compiled
-    against libidn2 library to add IDNA2008 support. Previously BIND only
-    supported IDNA2003 using (now obsolete) idnkit-1 library.
+  * None.
 
 Feature Changes
 
-  * dig +noidnin can be used to disable IDN processing on the input domain
-    name, when BIND is compiled with IDN support.
-
-  * Multiple cookie-secret clause are now supported. The first
-    cookie-secret in named.conf is used to generate new server cookies.
-    Any others are used to accept old server cookies or those generated by
-    other servers using the matching cookie-secret.
-
-  * The rndc nta command could not differentiate between views of the same
-    name but different class; this has been corrected with the addition of
-    a -class option. [GL #105]
-
-  * When compiled with IDN support, the dig and the nslookup commands now
-    disable IDN processing when the standard output is not a tty (e.g. not
-    used by human). The command line options +idnin and +idnout need to be
-    used to enable IDN processing when dig or nslookup is used from the
-    shell scripts.
+  * None.
 
 Bug Fixes
 
-  * When a negative trust anchor was added to multiple views using rndc
-    nta, the text returned via rndc was incorrectly truncated after the
-    first line, making it appear that only one NTA had been added. This
-    has been fixed. [GL #105]
-
-  * named now rejects excessively large incremental (IXFR) zone transfers
-    in order to prevent possible corruption of journal files which could
-    cause named to abort when loading zones. [GL #339]
-
-  * rndc reload could cause named to leak memory if it was invoked before
-    the zone loading actions from a previous rndc reload command were
-    completed. [RT #47076]
+  * None.
 
 End of Life