]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
Add CHANGES and release notes for [GL #2895]
authorAram Sargsyan <aram@isc.org>
Mon, 31 Oct 2022 13:03:47 +0000 (13:03 +0000)
committerAram Sargsyan <aram@isc.org>
Tue, 1 Nov 2022 10:49:58 +0000 (10:49 +0000)
(cherry picked from commit 3bf4bc7336d9fcb48bc1e3a4834b7a37cd50552f)

CHANGES
doc/notes/notes-current.rst

diff --git a/CHANGES b/CHANGES
index c42f95af1ffeec888d8a521856a7b4701a936a22..170cffb915ae68934a996d5f9d33ce4e49cf4c14 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -1,3 +1,6 @@
+6009.  [bug]           Don't trust a placeholder KEYDATA from the managed-keys
+                       zone by adding it into secroots. [GL #2895]
+
 6008.  [bug]           Fixed a race condition that could cause a crash
                        in dns_zone_synckeyzone(). [GL #3617]
 
index a501bfe4dcde6863ceb20488b6fadc59d0ad2679..0f66431f789d322c5c74103ef76ce1ef0faf1f5f 100644 (file)
@@ -54,3 +54,9 @@ Bug Fixes
 - The port in remote servers such as in :any:`primaries` and
   :any:`parental-agents` could be wrongly configured because of an inheritance
   bug. :gl:`#3627`
+
+- When having Internet connectivity issues during the initial startup of
+  ``named``, BIND resolver with :any:`dnssec-validation` set to ``auto`` could
+  enter into a state where it would not recover without stopping ``named``,
+  manually deleting ``managed-keys.bind`` and ``managed-keys.bind.jnl`` files,
+  and starting ``named`` again. :gl:`#2895`