]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
regen security-v9_14
authorTinderbox User <tbox@isc.org>
Wed, 6 Nov 2019 21:15:52 +0000 (21:15 +0000)
committerTinderbox User <tbox@isc.org>
Wed, 6 Nov 2019 21:29:08 +0000 (21:29 +0000)
54 files changed:
doc/arm/Bv9ARM.ch01.html
doc/arm/Bv9ARM.ch02.html
doc/arm/Bv9ARM.ch03.html
doc/arm/Bv9ARM.ch04.html
doc/arm/Bv9ARM.ch05.html
doc/arm/Bv9ARM.ch06.html
doc/arm/Bv9ARM.ch07.html
doc/arm/Bv9ARM.ch08.html
doc/arm/Bv9ARM.ch09.html
doc/arm/Bv9ARM.ch10.html
doc/arm/Bv9ARM.ch11.html
doc/arm/Bv9ARM.ch12.html
doc/arm/Bv9ARM.html
doc/arm/Bv9ARM.pdf
doc/arm/man.arpaname.html
doc/arm/man.ddns-confgen.html
doc/arm/man.delv.html
doc/arm/man.dig.html
doc/arm/man.dnssec-cds.html
doc/arm/man.dnssec-checkds.html
doc/arm/man.dnssec-coverage.html
doc/arm/man.dnssec-dsfromkey.html
doc/arm/man.dnssec-importkey.html
doc/arm/man.dnssec-keyfromlabel.html
doc/arm/man.dnssec-keygen.html
doc/arm/man.dnssec-keymgr.html
doc/arm/man.dnssec-revoke.html
doc/arm/man.dnssec-settime.html
doc/arm/man.dnssec-signzone.html
doc/arm/man.dnssec-verify.html
doc/arm/man.dnstap-read.html
doc/arm/man.filter-aaaa.html
doc/arm/man.host.html
doc/arm/man.mdig.html
doc/arm/man.named-checkconf.html
doc/arm/man.named-checkzone.html
doc/arm/man.named-journalprint.html
doc/arm/man.named-nzd2nzf.html
doc/arm/man.named-rrchecker.html
doc/arm/man.named.conf.html
doc/arm/man.named.html
doc/arm/man.nsec3hash.html
doc/arm/man.nslookup.html
doc/arm/man.nsupdate.html
doc/arm/man.pkcs11-destroy.html
doc/arm/man.pkcs11-keygen.html
doc/arm/man.pkcs11-list.html
doc/arm/man.pkcs11-tokens.html
doc/arm/man.rndc-confgen.html
doc/arm/man.rndc.conf.html
doc/arm/man.rndc.html
doc/arm/notes.html
doc/arm/notes.pdf
doc/arm/notes.txt

index 5d6fa1b8da49851b4d539f5293910abd97989dab..ebad8d93d7761559798256fffa4007216298dc4e 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 1b8f956d43c4818c2cadb428da5175731053fe6e..140c94dd132f936d26eec48f9d84a198138b4329 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index bdcf94d8e5060e4510799918ea088df7c5c7a7f4..73e8b9e8ea3701e1ae8b62f30d4460af06432996 100644 (file)
@@ -856,6 +856,6 @@ controls {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index c2a600aaaaeaca307348eaf84415ba5c7616d758..2789205f1701ee4a6e1262f8aa71299c693ef1a9 100644 (file)
@@ -2863,6 +2863,6 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index bacf9087ab68627464142869cd535bc841703007..1269871cc73d672ae7a19b9ed93565efa232a775 100644 (file)
@@ -3190,7 +3190,7 @@ badresp:1,adberr:0,findfail:0,valfail:0]
                 the first time; if unsuccessful, the server will
                 will terminate, under the assumption that another
                 server is already running.  If not specified, the default is
-                <code class="filename">/var/run/named/named.lock</code>.
+                <code class="filename">none</code>.
               </p>
               <p>
                 Specifying <span class="command"><strong>lock-file none</strong></span> disables the
@@ -3794,15 +3794,21 @@ options {
 <dt><span class="term"><span class="command"><strong>automatic-interface-scan</strong></span></span></dt>
 <dd>
                 <p>
-                  If <strong class="userinput"><code>yes</code></strong> and supported by the OS,
-                  automatically rescan network interfaces when the interface
-                  addresses are added or removed.  The default is
-                  <strong class="userinput"><code>yes</code></strong>.
+                  If <strong class="userinput"><code>yes</code></strong> and supported by the operating
+                  system, automatically rescan network interfaces when the
+                  interface addresses are added or removed.  The default is
+                  <strong class="userinput"><code>yes</code></strong>.  This configuration option does
+                  not affect time based <span class="command"><strong>interface-interval</strong></span>
+                  option, and it is recommended to set the time based
+                  <span class="command"><strong>interface-interval</strong></span> to 0 when the operator
+                  confirms that automatic interface scanning is supported by the
+                  operating system.
                 </p>
                 <p>
-                  Currently the OS needs to support routing sockets for
-                  <span class="command"><strong>automatic-interface-scan</strong></span> to be
-                  supported.
+                  The <span class="command"><strong>automatic-interface-scan</strong></span> implementation
+                  uses routing sockets for the network interface discovery,
+                  and therefore the operating system has to support the routing
+                  sockets for this feature to work.
                 </p>
               </dd>
 <dt><span class="term"><span class="command"><strong>allow-new-zones</strong></span></span></dt>
@@ -4311,6 +4317,17 @@ options {
                   response to a UDP request from a cookie aware client.
                   BADCOOKIE is sent if there is a bad or no existent
                   server cookie.
+                  The default is <strong class="userinput"><code>no</code></strong>.
+                </p>
+                <p>
+                  Set this to <strong class="userinput"><code>yes</code></strong> to test that DNS
+                  COOKIE clients correctly handle BADCOOKIE or if you are
+                  getting a lot of forged DNS requests with DNS COOKIES
+                  present. Setting this to <strong class="userinput"><code>yes</code></strong> will
+                  result in reduced amplification effect in a reflection
+                  attack, as the BADCOOKIE response will be smaller than
+                  a full response, while also requiring a legitimate client
+                  to follow up with a second query with the new, valid, cookie.
                 </p>
               </dd>
 <dt><span class="term"><span class="command"><strong>answer-cookie</strong></span></span></dt>
@@ -4353,6 +4370,7 @@ options {
                   do not send a correct COOKIE option may be limited
                   to receiving smaller responses via the
                   <span class="command"><strong>nocookie-udp-size</strong></span> option.
+                  The default is <strong class="userinput"><code>yes</code></strong>.
                 </p>
               </dd>
 <dt><span class="term"><span class="command"><strong>stale-answer-enable</strong></span></span></dt>
@@ -4978,7 +4996,9 @@ options {
                 <p>
                   Synthesize answers from cached NSEC, NSEC3 and
                   other RRsets that have been proved to be correct
-                  using DNSSEC.  The default is <span class="command"><strong>yes</strong></span>.
+                  using DNSSEC.  The default is <span class="command"><strong>no</strong></span>,
+                  but it will become <span class="command"><strong>yes</strong></span> again
+                  in the future releases.
                 </p>
                 <p>
                   Note:
@@ -6495,10 +6515,11 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
                   minutes. The default
                   is 60 minutes. The maximum value is 28 days (40320 minutes).
                   If set to 0, interface scanning will only occur when
-                  the configuration file is  loaded. After the scan, the
-                  server will
-                  begin listening for queries on any newly discovered
-                  interfaces (provided they are allowed by the
+                  the configuration file is loaded, or when
+                  <span class="command"><strong>automatic-interface-scan</strong></span> is enabled
+                  and supported by the operating system. After the scan, the
+                  server will begin listening for queries on any newly
+                  discovered interfaces (provided they are allowed by the
                   <span class="command"><strong>listen-on</strong></span> configuration), and
                   will stop listening on interfaces that have gone away.
                   For convenience, TTL-style time unit suffixes may be
@@ -6537,7 +6558,8 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
             The first element (which may be an IP address, an IP prefix, an
             ACL name or a nested <span class="command"><strong>address_match_list</strong></span>) of
             each top level list is checked against the source address of
-            the query until a match is found.
+            the query until a match is found. When the addresses in the
+            first element overlap, the first rule to match gets selected.
           </p>
           <p>
             Once the source address of the query has been matched, if the
@@ -6849,6 +6871,20 @@ avoid-v6-udp-ports { 40000; range 50000 60000; };
                   <span class="command"><strong>rndc serve-stale on</strong></span>.
                 </p>
               </dd>
+<dt><span class="term"><span class="command"><strong>resolver-nonbackoff-tries</strong></span></span></dt>
+<dd>
+                <p>
+                  Specifies how many retries occur before exponential
+                  backoff kicks in.  The default is <strong class="userinput"><code>3</code></strong>.
+                </p>
+              </dd>
+<dt><span class="term"><span class="command"><strong>resolver-retry-interval</strong></span></span></dt>
+<dd>
+                <p>
+                  The base retry interval in milliseconds.
+                  The default is <strong class="userinput"><code>800</code></strong>.
+                </p>
+              </dd>
 <dt><span class="term"><span class="command"><strong>sig-validity-interval</strong></span></span></dt>
 <dd>
                 <p>
@@ -14897,6 +14933,6 @@ HOST-127.EXAMPLE. MX 0 .
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index b35d11fb5a51d8e076be286553a498765a3db580..9e803bb133cff65b6306ab92e95fe85736dbb82d 100644 (file)
@@ -362,6 +362,6 @@ allow-query { !{ !10/8; any; }; key example; };
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 48b233c97521864c60890c0948ba17572dadb980..2c236848018170a8d580e5eb1f0840314f016af7 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index b78dbe9a5808d80f8e3fc3d0f141289ff20325dd..426217c2a8c596b0a7ef975f18293049c639e32b 100644 (file)
 <div class="toc">
 <p><b>Table of Contents</b></p>
 <dl class="toc">
-<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.14.7</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.14.8</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_platforms">Supported Platforms</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_download">Download</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_security">Security Fixes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_features">New Features</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_bugs">Bug Fixes</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.8">Notes for BIND 9.14.8</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.7">Notes for BIND 9.14.7</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.6">Notes for BIND 9.14.6</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.5">Notes for BIND 9.14.5</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.4">Notes for BIND 9.14.4</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.3">Notes for BIND 9.14.3</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.2">Notes for BIND 9.14.2</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.1">Notes for BIND 9.14.1</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.0">Notes for BIND 9.14.0</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_license">License</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#end_of_life">End of Life</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_thanks">Thank You</a></span></dt>
@@ -53,7 +59,7 @@
 </div>
       <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.9.2"></a>Release Notes for BIND Version 9.14.7</h2></div></div></div>
+<a name="id-1.9.2"></a>Release Notes for BIND Version 9.14.8</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_download"></a>Download</h3></div></div></div>
   <p>
     The latest versions of BIND 9 software can always be found at
-    <a class="link" href="http://www.isc.org/downloads/" target="_top">http://www.isc.org/downloads/</a>.
+    <a class="link" href="https://www.isc.org/download/" target="_top">https://www.isc.org/download/</a>.
     There you will find additional information about each release,
     source code, and pre-compiled versions for Microsoft Windows
     operating systems.
   </p>
 </div>
+
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_security"></a>Security Fixes</h3></div></div></div>
-  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-      <p>
-        A race condition could trigger an assertion failure when
-        a large number of incoming packets were being rejected.
-        This flaw is disclosed in CVE-2019-6471. [GL #942]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-       <span class="command"><strong>named</strong></span> could crash with an assertion failure
-       if a forwarder returned a referral, rather than resolving the
-       query, when QNAME minimization was enabled.  This flaw is
-       disclosed in CVE-2019-6476. [GL #1051]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-       A flaw in DNSSEC verification when transferring mirror zones
-       could allow data to be incorrectly marked valid. This flaw
-       is disclosed in CVE-2019-6475. [GL #1252]
-      </p>
-    </li>
+<a name="relnotes-9.14.8"></a>Notes for BIND 9.14.8</h3></div></div></div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.8-security"></a>Security Fixes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          Set a limit on the number of concurrently served pipelined TCP
+          queries. This flaw is disclosed in CVE-2019-6477. [GL #1264]
+        </p>
+      </li></ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.8-features"></a>New Features</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          Added a new statistics variable <span class="command"><strong>tcp-highwater</strong></span>
+          that reports the maximum number of simultaneous TCP clients BIND
+          has handled while running. [GL #1206]
+        </p>
+      </li></ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.8-changes"></a>Feature Changes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          NSEC Aggressive Cache (synth-from-dnssec) has been disabled by default
+          because it was found to have a significant performance impact on the
+          recursive service. The NSEC Aggressive Cache will be enable by default
+          in the future releases. [GL #1265]
+        </p>
+      </li></ul></div>
+  </div>
+
+</div>
+  <div class="section">
+<div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes-9.14.7"></a>Notes for BIND 9.14.7</h3></div></div></div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.7-security"></a>Security Fixes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+        <p>
+          <span class="command"><strong>named</strong></span> could crash with an assertion failure
+          if a forwarder returned a referral, rather than resolving the
+          query, when QNAME minimization was enabled.  This flaw is
+          disclosed in CVE-2019-6476. [GL #1051]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          A flaw in DNSSEC verification when transferring mirror zones
+          could allow data to be incorrectly marked valid. This flaw
+          is disclosed in CVE-2019-6475. [GL #1252]
+        </p>
+      </li>
 </ul></div>
+  </div>
+
+</div>
+  <div class="section">
+<div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes-9.14.6"></a>Notes for BIND 9.14.6</h3></div></div></div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.6-bugs"></a>Bug Fixes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          When a <span class="command"><strong>response-policy</strong></span> zone expires, ensure
+          that its policies are removed from the RPZ summary database.
+          [GL #1146]
+        </p>
+      </li></ul></div>
+  </div>
+
 </div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_features"></a>New Features</h3></div></div></div>
-  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-      <p>
-        The new GeoIP2 API from MaxMind is now supported when BIND
-        is compiled using <span class="command"><strong>configure --with-geoip2</strong></span>.
-        The legacy GeoIP API can be used by compiling with
-        <span class="command"><strong>configure --with-geoip</strong></span> instead.  (Note that
-        the databases for the legacy API are no longer maintained by
-        MaxMind.)
-      </p>
-      <p>
-        The default path to the GeoIP2 databases will be set based
-        on the location of the <span class="command"><strong>libmaxminddb</strong></span> library;
-        for example, if it is in <code class="filename">/usr/local/lib</code>,
-        then the default path will be
-        <code class="filename">/usr/local/share/GeoIP</code>.
-        This value can be overridden in <code class="filename">named.conf</code>
-        using the <span class="command"><strong>geoip-directory</strong></span> option.
-      </p>
-      <p>
-        Some <span class="command"><strong>geoip</strong></span> ACL settings that were available with
-        legacy GeoIP, including searches for <span class="command"><strong>netspeed</strong></span>,
-        <span class="command"><strong>org</strong></span>, and three-letter ISO country codes, will
-        no longer work when using GeoIP2. Supported GeoIP2 database
-        types are <span class="command"><strong>country</strong></span>, <span class="command"><strong>city</strong></span>,
-        <span class="command"><strong>domain</strong></span>, <span class="command"><strong>isp</strong></span>, and
-        <span class="command"><strong>as</strong></span>. All of the databases support both IPv4
-        and IPv6 lookups. [GL #182]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        Two new metrics have been added to the
-        <span class="command"><strong>statistics-channel</strong></span> to report DNSSEC
-        signing operations.  For each key in each zone, the
-        <span class="command"><strong>dnssec-sign</strong></span> counter indicates the total
-        number of signatures <span class="command"><strong>named</strong></span> has generated
-        using that key since server startup, and the
-        <span class="command"><strong>dnssec-refresh</strong></span> counter indicates how
-        many of those signatures were refreshed during zone
-        maintenance, as opposed to having been generated
-        as a result of a zone update.  [GL #513]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added.
-        [GL #605]
-      </p>
-      <p>
-        If you are running multiple DNS Servers (different versions of BIND 9
-        or DNS server from multiple vendors) responding from the same IP
-        address (anycast or load-balancing scenarios), you'll have to make
-        sure that all the servers are configured with the same DNS Cookie
-        algorithm and same Server Secret for the best performance.
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        DS records included in DNS referral messages can now be validated
-        and cached immediately, reducing the number of queries needed for
-        a DNSSEC validation. [GL #964]
-      </p>
-    </li>
+<a name="relnotes-9.14.5"></a>Notes for BIND 9.14.5</h3></div></div></div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.5-features"></a>New Features</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+        <p>
+          A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added.
+          [GL #605]
+        </p>
+        <p>
+          If you are running multiple DNS Servers (different versions of BIND 9
+          or DNS server from multiple vendors) responding from the same IP
+          address (anycast or load-balancing scenarios), you'll have to make
+          sure that all the servers are configured with the same DNS Cookie
+          algorithm and same Server Secret for the best performance.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          DS records included in DNS referral messages can now be validated
+          and cached immediately, reducing the number of queries needed for
+          a DNSSEC validation. [GL #964]
+        </p>
+      </li>
 </ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.5-bugs"></a>Bug Fixes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+        <p>
+          Cache database statistics counters could report invalid values
+          when stale answers were enabled, because of a bug in counter
+          maintenance when cache data becomes stale. The statistics counters
+          have been corrected to report the number of RRsets for each
+          RR type that are active, stale but still potentially served,
+          or stale and marked for deletion. [GL #602]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Interaction between DNS64 and RPZ No Data rule (CNAME *.) could
+          cause unexpected results; this has been fixed. [GL #1106]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>named-checkconf</strong></span> now checks DNS64 prefixes
+          to ensure bits 64-71 are zero. [GL #1159]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>named-checkconf</strong></span> could crash during
+          configuration if configured to use "geoip continent" ACLs with
+          legacy GeoIP. [GL #1163]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>named-checkconf</strong></span> now correctly reports a missing
+          <span class="command"><strong>dnstap-output</strong></span> option when
+          <span class="command"><strong>dnstap</strong></span> is set. [GL #1136]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Handle ETIMEDOUT error on connect() with a non-blocking
+          socket. [GL #1133]
+        </p>
+      </li>
+</ul></div>
+  </div>
+
 </div>
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
-<a name="relnotes_bugs"></a>Bug Fixes</h3></div></div></div>
-  <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
-<li class="listitem">
-      <p>
-        When <span class="command"><strong>qname-minimization</strong></span> was set to
-        <span class="command"><strong>relaxed</strong></span>, some improperly configured domains
-        would fail to resolve, but would have succeeded when minimization
-        was disabled. <span class="command"><strong>named</strong></span> will now fall back to normal
-        resolution in such cases, and also uses type A rather than NS for
-        minimal queries in order to reduce the likelihood of encountering
-        the problem. [GL #1055]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        Glue address records were not being returned in responses
-        to root priming queries; this has been corrected. [GL #1092]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        Interaction between DNS64 and RPZ No Data rule (CNAME *.) could
-        cause unexpected results; this has been fixed. [GL #1106]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        <span class="command"><strong>named-checkconf</strong></span> now checks DNS64 prefixes
-        to ensure bits 64-71 are zero. [GL #1159]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        <span class="command"><strong>named-checkconf</strong></span> could crash during
-        configuration if configured to use "geoip continent" ACLs with
-        legacy GeoIP. [GL #1163]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        <span class="command"><strong>named-checkconf</strong></span> now correctly reports a missing
-        <span class="command"><strong>dnstap-output</strong></span> option when
-        <span class="command"><strong>dnstap</strong></span> is set. [GL #1136]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        Handle ETIMEDOUT error on connect() with a non-blocking
-        socket. [GL #1133]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        Cache database statistics counters could report invalid values
-        when stale answers were enabled, because of a bug in counter
-        maintenance when cache data becomes stale. The statistics counters
-        have been corrected to report the number of RRsets for each
-        RR type that are active, stale but still potentially served,
-        or stale and marked for deletion. [GL #602]
-      </p>
-    </li>
-<li class="listitem">
-      <p>
-        When a <span class="command"><strong>response-policy</strong></span> zone expires, ensure
-        that its policies are removed from the RPZ summary database.
-        [GL #1146]
-      </p>
-    </li>
+<a name="relnotes-9.14.4"></a>Notes for BIND 9.14.4</h3></div></div></div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.4-features"></a>New Features</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+        <p>
+          The new GeoIP2 API from MaxMind is now supported when BIND
+          is compiled using <span class="command"><strong>configure --with-geoip2</strong></span>.
+          The legacy GeoIP API can be used by compiling with
+          <span class="command"><strong>configure --with-geoip</strong></span> instead.  (Note that
+          the databases for the legacy API are no longer maintained by
+          MaxMind.)
+        </p>
+        <p>
+          The default path to the GeoIP2 databases will be set based
+          on the location of the <span class="command"><strong>libmaxminddb</strong></span> library;
+          for example, if it is in <code class="filename">/usr/local/lib</code>,
+          then the default path will be
+          <code class="filename">/usr/local/share/GeoIP</code>.
+          This value can be overridden in <code class="filename">named.conf</code>
+          using the <span class="command"><strong>geoip-directory</strong></span> option.
+        </p>
+        <p>
+          Some <span class="command"><strong>geoip</strong></span> ACL settings that were available with
+          legacy GeoIP, including searches for <span class="command"><strong>netspeed</strong></span>,
+          <span class="command"><strong>org</strong></span>, and three-letter ISO country codes, will
+          no longer work when using GeoIP2. Supported GeoIP2 database
+          types are <span class="command"><strong>country</strong></span>, <span class="command"><strong>city</strong></span>,
+          <span class="command"><strong>domain</strong></span>, <span class="command"><strong>isp</strong></span>, and
+          <span class="command"><strong>as</strong></span>. All of the databases support both IPv4
+          and IPv6 lookups. [GL #182]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Two new metrics have been added to the
+          <span class="command"><strong>statistics-channel</strong></span> to report DNSSEC
+          signing operations.  For each key in each zone, the
+          <span class="command"><strong>dnssec-sign</strong></span> counter indicates the total
+          number of signatures <span class="command"><strong>named</strong></span> has generated
+          using that key since server startup, and the
+          <span class="command"><strong>dnssec-refresh</strong></span> counter indicates how
+          many of those signatures were refreshed during zone
+          maintenance, as opposed to having been generated
+          as a result of a zone update.  [GL #513]
+        </p>
+      </li>
+</ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.4-bugs"></a>Bug Fixes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          Glue address records were not being returned in responses
+          to root priming queries; this has been corrected. [GL #1092]
+        </p>
+      </li></ul></div>
+  </div>
+
+</div>
+  <div class="section">
+<div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes-9.14.3"></a>Notes for BIND 9.14.3</h3></div></div></div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.3-security"></a>Security Fixes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          A race condition could trigger an assertion failure when
+          a large number of incoming packets were being rejected.
+          This flaw is disclosed in CVE-2019-6471. [GL #942]
+        </p>
+      </li></ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.3-bugs"></a>Bug Fixes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          When <span class="command"><strong>qname-minimization</strong></span> was set to
+          <span class="command"><strong>relaxed</strong></span>, some improperly configured domains
+          would fail to resolve, but would have succeeded when minimization
+          was disabled. <span class="command"><strong>named</strong></span> will now fall back to normal
+          resolution in such cases, and also uses type A rather than NS for
+          minimal queries in order to reduce the likelihood of encountering
+          the problem. [GL #1055]
+        </p>
+      </li></ul></div>
+  </div>
+
+</div>
+  <div class="section">
+<div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes-9.14.2"></a>Notes for BIND 9.14.2</h3></div></div></div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.2-changes"></a>Feature Changes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          When <span class="command"><strong>trusted-keys</strong></span> and
+          <span class="command"><strong>managed-keys</strong></span> are both configured for the
+          same name, or when <span class="command"><strong>trusted-keys</strong></span> is used to
+          configure a trust anchor for the root zone and
+          <span class="command"><strong>dnssec-validation</strong></span> is set to the default
+          value of <code class="literal">auto</code>, automatic RFC 5011 key
+          rollovers will fail.
+        </p>
+        <p>
+          This combination of settings was never intended to work,
+          but there was no check for it in the parser. This has been
+          corrected; a warning is now logged. (In BIND 9.15 and
+          higher this error will be fatal.) [GL #868]
+        </p>
+      </li></ul></div>
+  </div>
+
+</div>
+  <div class="section">
+<div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes-9.14.1"></a>Notes for BIND 9.14.1</h3></div></div></div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.1-security"></a>Security Fixes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+        <p>
+          In certain configurations, <span class="command"><strong>named</strong></span> could crash
+          with an assertion failure if <span class="command"><strong>nxdomain-redirect</strong></span>
+          was in use and a redirected query resulted in an NXDOMAIN from the
+          cache. This flaw is disclosed in CVE-2019-6467. [GL #880]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The TCP client quota set using the <span class="command"><strong>tcp-clients</strong></span>
+          option could be exceeded in some cases. This could lead to
+          exhaustion of file descriptors. (CVE-2018-5743) [GL #615]
+        </p>
+      </li>
+</ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.1-features"></a>New Features</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          The new <span class="command"><strong>add-soa</strong></span> option specifies whether
+          or not the <span class="command"><strong>response-policy</strong></span> zone's SOA record
+          should be included in the additional section of RPZ responses.
+          [GL #865]
+        </p>
+      </li></ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.1-bugs"></a>Bug Fixes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          The <span class="command"><strong>allow-update</strong></span> and
+          <span class="command"><strong>allow-update-forwarding</strong></span> options were
+          inadvertently treated as configuration errors when used at the
+          <span class="command"><strong>options</strong></span> or <span class="command"><strong>view</strong></span> level.
+          This has now been corrected.
+          [GL #913]
+        </p>
+      </li></ul></div>
+  </div>
+
+</div>
+  <div class="section">
+<div class="titlepage"><div><div><h3 class="title">
+<a name="relnotes-9.14.0"></a>Notes for BIND 9.14.0</h3></div></div></div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.0-features"></a>New Features</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+        <p>
+          Task manager and socket code have been substantially modified.
+          The manager uses per-cpu queues for tasks and network stack runs
+          multiple event loops in CPU-affinitive threads. This greatly
+          improves performance on large systems, especially when using
+          multi-queue NICs.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Support for QNAME minimization was added and enabled by default
+          in <span class="command"><strong>relaxed</strong></span> mode, in which BIND will fall back
+          to normal resolution if the remote server returns something
+          unexpected during the query minimization process. This default
+          setting might change to <span class="command"><strong>strict</strong></span> in the future.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          A new <span class="command"><strong>plugin</strong></span> mechanism has been added to allow
+          extension of query processing functionality through the use of
+          external libraries. The new <code class="filename">filter-aaaa.so</code>
+          plugin replaces the <span class="command"><strong>filter-aaaa</strong></span> feature that
+          was formerly implemented as a native part of BIND.
+        </p>
+        <p>
+          The plugin API is a work in progress and is likely to evolve
+          as further plugins are implemented. [GL #15]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          A new secondary zone option, <span class="command"><strong>mirror</strong></span>,
+          enables <span class="command"><strong>named</strong></span> to serve a transferred copy
+          of a zone's contents without acting as an authority for the
+          zone. A zone must be fully validated against an active trust
+          anchor before it can be used as a mirror zone. DNS responses
+          from mirror zones do not set the AA bit ("authoritative answer"),
+          but do set the AD bit ("authenticated data"). This feature is
+          meant to facilitate deployment of a local copy of the root zone,
+          as described in RFC 7706. [GL #33]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          BIND now can be compiled against the <span class="command"><strong>libidn2</strong></span>
+          library to add IDNA2008 support.  Previously, BIND supported
+          IDNA2003 using the (now obsolete and unsupported)
+          <span class="command"><strong>idnkit-1</strong></span> library.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>named</strong></span> now supports the "root key sentinel"
+          mechanism. This enables validating resolvers to indicate
+          which trust anchors are configured for the root, so that
+          information about root key rollover status can be gathered.
+          To disable this feature, add
+          <span class="command"><strong>root-key-sentinel no;</strong></span> to
+          <code class="filename">named.conf</code>. [GL #37]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The <span class="command"><strong>dnskey-sig-validity</strong></span> option allows the
+          <span class="command"><strong>sig-validity-interval</strong></span> to be overriden for
+          signatures covering DNSKEY RRsets. [GL #145]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          When built on Linux, BIND now requires the <span class="command"><strong>libcap</strong></span>
+          library to set process privileges.  The adds a new compile-time
+          dependency, which can be met on most Linux platforms by installing the
+          <span class="command"><strong>libcap-dev</strong></span> or <span class="command"><strong>libcap-devel</strong></span>
+          package. BIND can also be built without capability support by using
+          <span class="command"><strong>configure --disable-linux-caps</strong></span>, at the cost of some
+          loss of security.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The <span class="command"><strong>validate-except</strong></span> option specifies a list of
+          domains beneath which DNSSEC validation should not be performed,
+          regardless of whether a trust anchor has been configured above
+          them. [GL #237]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Two new update policy rule types have been added
+          <span class="command"><strong>krb5-selfsub</strong></span> and <span class="command"><strong>ms-selfsub</strong></span>
+          which allow machines with Kerberos principals to update
+          the name space at or below the machine names identified
+          in the respective principals.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The new configure option <span class="command"><strong>--enable-fips-mode</strong></span>
+          can be used to make BIND enable and enforce FIPS mode in the
+          OpenSSL library.  When compiled with such option the BIND will
+          refuse to run if FIPS mode can't be enabled, thus this option
+          must be only enabled for the systems where FIPS mode is available.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Two new configuration options <span class="command"><strong>min-cache-ttl</strong></span> and
+          <span class="command"><strong>min-ncache-ttl</strong></span> has been added to allow the BIND 9
+          administrator to override the minimum TTL in the received DNS records
+          (positive caching) and for storing the information about non-existent
+          records (negative caching).  The configured minimum TTL for both
+          configuration options cannot exceed 90 seconds.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>rndc status</strong></span> output now includes a
+          <span class="command"><strong>reconfig/reload in progress</strong></span> status line if named
+          configuration is being reloaded.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The new <span class="command"><strong>answer-cookie</strong></span> option, if set to
+          <code class="literal">no</code>, prevents <span class="command"><strong>named</strong></span> from
+          returning a DNS COOKIE option to a client, even if such an
+          option was present in the request.  This is only intended as
+          a temporary measure, for use when <span class="command"><strong>named</strong></span>
+          shares an IP address with other servers that do not yet
+          support DNS COOKIE.  A mismatch between servers on the same
+          address is not expected to cause operational problems, but the
+          option to disable COOKIE responses so that all servers have the
+          same behavior is provided out of an abundance of caution.
+          DNS COOKIE is an important security mechanism, and this option
+          should not be used to disable it unless absolutely necessary.
+        </p>
+      </li>
+</ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.0-removed"></a>Removed Features</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+        <p>
+          Workarounds for servers that misbehave when queried with EDNS
+          have been removed, because these broken servers and the
+          workarounds for their noncompliance cause unnecessary delays,
+          increase code complexity, and prevent deployment of new DNS
+          features. See <a class="link" href="https://dnsflagday.net" target="_top">https://dnsflagday.net</a>
+          for further details.
+        </p>
+        <p>
+          In particular, resolution will no longer fall back to
+          plain DNS when there was no response from an authoritative
+          server.  This will cause some domains to become non-resolvable
+          without manual intervention.  In these cases, resolution can
+          be restored by adding <span class="command"><strong>server</strong></span> clauses for the
+          offending servers, specifying <span class="command"><strong>edns no</strong></span> or
+          <span class="command"><strong>send-cookie no</strong></span>, depending on the specific
+          noncompliance.
+        </p>
+        <p>
+          To determine which <span class="command"><strong>server</strong></span> clause to use, run
+          the following commands to send queries to the authoritative
+          servers for the broken domain:
+        </p>
+<div class="literallayout"><p><br>
+          dig soa &lt;zone&gt; @&lt;server&gt; +dnssec<br>
+          dig soa &lt;zone&gt; @&lt;server&gt; +dnssec +nocookie<br>
+          dig soa &lt;zone&gt; @&lt;server&gt; +noedns<br>
+</p></div>
+        <p>
+          If the first command fails but the second succeeds, the
+          server most likely needs <span class="command"><strong>send-cookie no</strong></span>.
+          If the first two fail but the third succeeds, then the server
+          needs EDNS to be fully disabled with <span class="command"><strong>edns no</strong></span>.
+        </p>
+        <p>
+          Please contact the administrators of noncompliant domains
+          and encourage them to upgrade their broken DNS servers. [GL #150]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Previously, it was possible to build BIND without thread support
+          for old architectures and systems without threads support.
+          BIND now requires threading support (either POSIX or Windows) from
+          the operating system, and it cannot be built without threads.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The <span class="command"><strong>filter-aaaa</strong></span>,
+          <span class="command"><strong>filter-aaaa-on-v4</strong></span>, and
+          <span class="command"><strong>filter-aaaa-on-v6</strong></span> options have been removed
+          from <span class="command"><strong>named</strong></span>, and can no longer be
+          configured using native <code class="filename">named.conf</code> syntax.
+          However, loading the new <code class="filename">filter-aaaa.so</code>
+          plugin and setting its parameters provides identical
+          functionality.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>named</strong></span> can no longer use the EDNS CLIENT-SUBNET
+          option for view selection.  In its existing form, the authoritative
+          ECS feature was not fully RFC-compliant, and could not realistically
+          have been deployed in production for an authoritative server; its
+          only practical use was for testing and experimentation. In the
+          interest of code simplification, this feature has now been removed.
+        </p>
+        <p>
+          The ECS option is still supported in <span class="command"><strong>dig</strong></span> and
+          <span class="command"><strong>mdig</strong></span> via the +subnet argument, and can be parsed
+          and logged when received by <span class="command"><strong>named</strong></span>, but
+          it is no longer used for ACL processing. The
+          <span class="command"><strong>geoip-use-ecs</strong></span> option is now obsolete;
+          a warning will be logged if it is used in
+          <code class="filename">named.conf</code>.
+          <span class="command"><strong>ecs</strong></span> tags in an ACL definition are
+          also obsolete, and will cause the configuration to fail to
+          load if they are used. [GL #32]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>dnssec-keygen</strong></span> can no longer generate HMAC
+          keys for TSIG authentication. Use <span class="command"><strong>tsig-keygen</strong></span>
+          to generate these keys. [RT #46404]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Support for OpenSSL 0.9.x has been removed.  OpenSSL version
+          1.0.0 or greater, or LibreSSL is now required.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The <span class="command"><strong>configure --enable-seccomp</strong></span> option,
+          which formerly turned on system-call filtering on Linux, has
+          been removed. [GL #93]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          IPv4 addresses in forms other than dotted-quad are no longer
+          accepted in master files. [GL #13] [GL #56]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          IDNA2003 support via (bundled) idnkit-1.0 has been removed.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The "rbtdb64" database implementation (a parallel
+          implementation of "rbt") has been removed. [GL #217]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The <span class="command"><strong>-r randomdev</strong></span> option to explicitly select
+          random device has been removed from the
+          <span class="command"><strong>ddns-confgen</strong></span>,
+          <span class="command"><strong>rndc-confgen</strong></span>,
+          <span class="command"><strong>nsupdate</strong></span>,
+          <span class="command"><strong>dnssec-confgen</strong></span>, and
+          <span class="command"><strong>dnssec-signzone</strong></span> commands.
+        </p>
+        <p>
+          The <span class="command"><strong>-p</strong></span> option to use pseudo-random data
+          has been removed from the <span class="command"><strong>dnssec-signzone</strong></span>
+          command.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Support for the RSAMD5 algorithm has been removed freom BIND as
+          the usage of the RSAMD5 algorithm for DNSSEC has been deprecated
+          in RFC6725, the security of the MD5 algorithm has been compromised,
+          and its usage is considered harmful.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Support for the ECC-GOST (GOST R 34.11-94) algorithm has been
+          removed from BIND, as the algorithm has been superseded by
+          GOST R 34.11-2012 in RFC6986 and it must not be used in new
+          deployments.  BIND will neither create new DNSSEC keys,
+          signatures and digests, nor it will validate them.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Support for DSA and DSA-NSEC3-SHA1 algorithms has been
+          removed from BIND as the DSA key length is limited to 1024
+          bits and this is not considered secure enough.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>named</strong></span> will no longer ignore "no-change" deltas
+          when processing an IXFR stream.  This had previously been
+          permitted for compatibility with BIND 8, but now "no-change"
+          deltas will trigger a fallback to AXFR as the recovery mechanism.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          BIND 9 will no longer build on platforms that don't have
+          proper IPv6 support.  BIND 9 now also requires POSIX-compatible
+          pthread support.  Most of the platforms that lack these featuers
+          are long past their end-of-lifew dates, and they are neither
+          developed nor supported by their respective vendors.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The incomplete support for internationalization message catalogs has
+          been removed from BIND. Since the internationalization was never
+          completed, and no localized message catalogs were ever made available
+          for the portions of BIND in which they could have been used, this
+          change will have no effect except to simplify the source code. BIND's
+          log messages and other output were already only available in English.
+        </p>
+      </li>
+</ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.0-changes"></a>Feature Changes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
+<li class="listitem">
+        <p>
+          BIND will now always use the best CSPRNG (cryptographically-secure
+          pseudo-random number generator) available on the platform where
+          it is compiled.  It will use the <span class="command"><strong>arc4random()</strong></span>
+          family of functions on BSD operating systems,
+          <span class="command"><strong>getrandom()</strong></span> on Linux and Solaris,
+          <span class="command"><strong>CryptGenRandom</strong></span> on Windows, and the selected
+          cryptography provider library (OpenSSL or PKCS#11) as the last
+          resort. [GL #221]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The default setting for <span class="command"><strong>dnssec-validation</strong></span> is
+          now <strong class="userinput"><code>auto</code></strong>, which activates DNSSEC
+          validation using the IANA root key. (The default can be changed
+          back to <strong class="userinput"><code>yes</code></strong>, which activates DNSSEC
+          validation only when keys are explicitly configured in
+          <code class="filename">named.conf</code>, by building BIND with
+          <span class="command"><strong>configure --disable-auto-validation</strong></span>.) [GL #30]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          BIND can no longer be built without DNSSEC support. A cryptography
+          provider (i.e., OpenSSL or a hardware service module with
+          PKCS#11 support) must be available. [GL #244]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Zone types <span class="command"><strong>primary</strong></span> and
+          <span class="command"><strong>secondary</strong></span> are now available as synonyms for
+          <span class="command"><strong>master</strong></span> and <span class="command"><strong>slave</strong></span>,
+          respectively, in <code class="filename">named.conf</code>.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>named</strong></span> will now log a warning if the old
+          root DNSSEC key is explicitly configured and has not been updated.
+          [RT #43670]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>dig +nssearch</strong></span> will now list name servers
+          that have timed out, in addition to those that respond. [GL #64]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Up to 64 <span class="command"><strong>response-policy</strong></span> zones are now
+          supported by default; previously the limit was 32. [GL #123]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Several configuration options for time periods can now use
+          TTL value suffixes (for example, <code class="literal">2h</code> or
+          <code class="literal">1d</code>) in addition to an integer number of
+          seconds. These include
+          <span class="command"><strong>fstrm-set-reopen-interval</strong></span>,
+          <span class="command"><strong>interface-interval</strong></span>,
+          <span class="command"><strong>max-cache-ttl</strong></span>,
+          <span class="command"><strong>max-ncache-ttl</strong></span>,
+          <span class="command"><strong>max-policy-ttl</strong></span>, and
+          <span class="command"><strong>min-update-interval</strong></span>.
+          [GL #203]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          NSID logging (enabled by the <span class="command"><strong>request-nsid</strong></span>
+          option) now has its own <span class="command"><strong>nsid</strong></span> category,
+          instead of using the <span class="command"><strong>resolver</strong></span> category.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The <span class="command"><strong>rndc nta</strong></span> command could not differentiate
+          between views of the same name but different class; this
+          has been corrected with the addition of a <span class="command"><strong>-class</strong></span>
+          option. [GL #105]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          <span class="command"><strong>allow-recursion-on</strong></span> and
+          <span class="command"><strong>allow-query-cache-on</strong></span> each now default to
+          the other if only one of them is set, in order to be consistent
+          with the way <span class="command"><strong>allow-recursion</strong></span> and
+          <span class="command"><strong>allow-query-cache</strong></span> work. [GL #319]
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          When compiled with IDN support, the <span class="command"><strong>dig</strong></span> and
+          <span class="command"><strong>nslookup</strong></span> commands now disable IDN processing
+          when the standard output is not a TTY (i.e., when the output
+          is not being read by a human). When running from a shell
+          script, the command line options <span class="command"><strong>+idnin</strong></span> and
+          <span class="command"><strong>+idnout</strong></span> may be used to enable IDN
+          processing of input and output domain names, respectively.
+          When running on a TTY, the <span class="command"><strong>+noidnin</strong></span> and
+          <span class="command"><strong>+noidnout</strong></span> options may be used to disable
+          IDN processing of input and output domain names.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The configuration option <span class="command"><strong>max-ncache-ttl</strong></span> cannot
+          exceed seven days. Previously, larger values than this were silently
+          lowered; now, they trigger a configuration error.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          The new <span class="command"><strong>dig -r</strong></span> command line option
+          disables reading of the file <code class="filename">$HOME/.digrc</code>.
+        </p>
+      </li>
+<li class="listitem">
+        <p>
+          Zone signing and key maintenance events are now logged to the
+          <span class="command"><strong>dnssec</strong></span> category rather than
+          <span class="command"><strong>zone</strong></span>.
+        </p>
+      </li>
 </ul></div>
+  </div>
+
 </div>
+
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 <a name="relnotes_license"></a>License</h3></div></div></div>
     For those needing long term support, the current Extended Support
     Version (ESV) is BIND 9.11, which will be supported until at
     least December 2021. See
-    <a class="link" href="https://www.isc.org/downloads/software-support-policy/" target="_top">https://www.isc.org/downloads/software-support-policy/</a>
+    <a class="link" href="https://kb.isc.org/docs/aa-00896" target="_top">https://kb.isc.org/docs/aa-00896</a>
     for details of ISC's software support policy.
   </p>
 </div>
     Thank you to everyone who assisted us in making this release possible.
     If you would like to contribute to ISC to assist us in continuing to
     make quality open source software, please visit our donations page at
-    <a class="link" href="http://www.isc.org/donate/" target="_top">http://www.isc.org/donate/</a>.
+    <a class="link" href="https://www.isc.org/donate/" target="_top">https://www.isc.org/donate/</a>.
   </p>
 </div>
 </div>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 1819558b0aedbe219a22aa4243a0662db314b82a..4ee8aeec3b5dd7f6916a60050021717f016dce66 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 8b5fe5f340bc2569aa23856e8847c909be82e69b..81ba80ab46f855c780eb1cd116db04dfb31fe6d6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index fc52d7af621d239a13bc50cb5b8687400a1e4681..bc1ed65e5133893136d2a295af1a4aeffce10b22 100644 (file)
@@ -533,6 +533,6 @@ $ <strong class="userinput"><code>sample-update -a sample-update -k Kxxx.+nnn+mm
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index dad2f78633ca482ad3d789e5640a2beebafc0deb..40f469d6a491c6fd0f7822aa8cfd7cc0e51ae776 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 4b615aabe49cc9bf8210144489c8f35bd77825e8..a7e2ff99391aed784dc1dda5d62c09b086392a73 100644 (file)
@@ -32,7 +32,7 @@
 <div>
 <div><h1 class="title">
 <a name="id-1"></a>BIND 9 Administrator Reference Manual</h1></div>
-<div><p class="releaseinfo">BIND Version 9.14.7</p></div>
+<div><p class="releaseinfo">BIND Version 9.14.8</p></div>
 <div><p class="copyright">Copyright Â© 2000-2019 Internet Systems Consortium, Inc. ("ISC")</p></div>
 </div>
 <hr>
 </dl></dd>
 <dt><span class="appendix"><a href="Bv9ARM.ch08.html">A. Release Notes</a></span></dt>
 <dd><dl>
-<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.14.7</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#id-1.9.2">Release Notes for BIND Version 9.14.8</a></span></dt>
 <dd><dl>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_intro">Introduction</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_versions">Note on Version Numbering</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_platforms">Supported Platforms</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_download">Download</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_security">Security Fixes</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_features">New Features</a></span></dt>
-<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_bugs">Bug Fixes</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.8">Notes for BIND 9.14.8</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.7">Notes for BIND 9.14.7</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.6">Notes for BIND 9.14.6</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.5">Notes for BIND 9.14.5</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.4">Notes for BIND 9.14.4</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.3">Notes for BIND 9.14.3</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.2">Notes for BIND 9.14.2</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.1">Notes for BIND 9.14.1</a></span></dt>
+<dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes-9.14.0">Notes for BIND 9.14.0</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_license">License</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#end_of_life">End of Life</a></span></dt>
 <dt><span class="section"><a href="Bv9ARM.ch08.html#relnotes_thanks">Thank You</a></span></dt>
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 2fe1a892eee262c468436366df429befa6d2cecb..8360e67cecd2e0e2891cba9dbc057752fe27d29a 100644 (file)
Binary files a/doc/arm/Bv9ARM.pdf and b/doc/arm/Bv9ARM.pdf differ
index b01eb01581a01ab5715507dc5314c6f668a724a0..4ad4028f7c7fbc298655001c1cf7312fbaa89050 100644 (file)
@@ -90,6 +90,6 @@
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 3cf3cbef6a0ca18e612e4323cd77e48560bd44ad..09f4265d7f335cd9661254899a90f867f285b67a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index d13a278933faf5a685fe783b73756aaad67402ed..a3c36b9c150b17d06a9b08d4bcb2908ac90caed5 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index c18bce9940e787fab1403b83089880d518fafea5..0d33ff10f6b6fa8dbbb48885b08d3300de7db323 100644 (file)
@@ -1166,6 +1166,6 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 89c2bf2be947496b87f3fcb51efc8fcda751f6d7..8dc91038d258229ae60bd54e6edce550816ba00d 100644 (file)
@@ -376,6 +376,6 @@ nsupdate -l
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 8784ff85bd1ae2ae1e8c7d58dbb62a84190e5daf..04ec160aeb25306f2bc97eae5857a1c8c83bc8d6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 6acce9925338fc48806d2659f3ab8838180ec919..3cf3abcec08a43daebbdb13d65974d793c12309e 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index abc0d66c356b55bc94fb35a3c6f107aa328ab54d..a0d37941382717d76c84890a81ce125ee5fc4e06 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 877edb04689eece8d479a960d2abd3fdf3a48c0e..76ae9adc952ca16f77b06e7cee9bcc2d561c474f 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 3df6dfb33fefae9dd2309a45e9e226a63349788c..873985c9bd3b45d686d471e758ad951945301aaf 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 90dc541dbd52e44a80d867c970892319900920b4..c1a155f08d4aa1fc26218cef62df0a7ad93277eb 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 878ae58f123806107707d0dffe22b4b8d8cf51b1..056e56dcbf97b1a05a03491a347adddf5f67b4fd 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index c8d5357c5c8aa7eeec5a2976ce0fa6a976ecd5b8..e32b5ed178d37920bb77e23e200c9a04f3b22727 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index c67e8730334abe37afc14d8ee4ddbfd3d381ceea..56880e376484ecde7da838bd90e297f10c8361cd 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 8893a29453690584d28c70b5597b631005cc0983..d8da51cbf059d0a08a6d150efbb5a587f2e52956 100644 (file)
@@ -701,6 +701,6 @@ db.example.com.signed
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index db48e9e4a8b09faf4c584ba123778642992e87fb..9ee892e2f35781548e9191d9a886bf62d0f53632 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index f580ed84b76b9ed7d050ad264479f172c14a8dae..043ec311fb35129d346eda4bbcb60367056cbaaa 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 47ff58105d3947446b9f040017323207b670e035..538f2454726d04e76eb5c98dc386e065ac4a3c81 100644 (file)
@@ -168,6 +168,6 @@ plugin query "/usr/local/lib/filter-aaaa.so" {
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index fb8d5187c6975d4aef5b812894030ebd1f9d8899..7d53162732db53951b69fb3a44e78a0d342d2a54 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index cbe9f59c4d58bc504f9345e05e1f8a900d0b7534..ac280a2f525ddf0434393d95044f83f3d4eef3f8 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index f2c19f99324a603c6abd479f37f798bf4a9a5e7a..85945d323caf0e818ecc57a3946adab14ebbcb62 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 0bd0b4872495eaa3986a721ef7489ec3d5fcee4e..24c6a8261fc3066c28ed8e3a21d6cb1ff6481bb6 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 43bd8c945029ead3e38a0e9e8f4ed78f043d84b5..a90ae61aab485d0208de23e9769d92f30e7c41a2 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 3dec266654d544966678a94986f63a7da4dc1daa..d9a26c70911ba687d42f2aa2a8739bf61a8ed892 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 02f71890d5472fcad39daab57999293e2fa767d1..a5f0b250a91061e42f3665e78d18d167bf186a99 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 8bc30c694e27fe87ad52842357155f3747a93d42..f669746b0845f638a26d4d44913596cc78f065f8 100644 (file)
@@ -1075,6 +1075,6 @@ zone
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 225947c95fa6379c9f50e2a0b9d700c5c0a1f40b..7d3e36d85fd1f89bc9dbf4263cc64a89c7ed74bb 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index c7b38bdf4f5479ff0afe456797fde0de1c67f02c..6448e23f4c4570ad1419b4ddae725898aabc888d 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 0c130b23e28b85971bea2b239548f775b1b67d1e..a285ee9605966d31cd652eb9caa7532c2243eb6b 100644 (file)
@@ -437,6 +437,6 @@ nslookup -query=hinfo  -timeout=10
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 3469a520ba33f6c13ea00b8e266385ff33b97e73..d05714edd389b219aaa74941719a63ab515f72af 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index ad74b128fa43c210b4a0ae4a0ee274793bab26c6..5d713a94e8b6823adbf810bf9f90bcd3daec480e 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 0ebf4749f52c3492f7898bb2ea9e216dc5178590..1b877d41f4114f44845f121608878d8cc0a9e275 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 707f8ce902961d1fb0c312c1c712dd162423b269..89801840407042aec5fd6bbfcec91e6fee5ad798 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 06e94bb537f715a342e7082f3056421287546136..f91cad711b081cf1652ec5d574c81d7a67ad6d3a 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 26409634c923470b28170dfc5f2b666d08f87c1a..1b4e102e245b51053283496d7dce70d25ce0014c 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index e6909ad75f4591973df660012299c0e6f6624659..1535365be33ffbc0a9b80603f303a3c0df5f1dcb 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index 980c78b47ec7958be522479cb1f522731e362b42..da003f31f25024156a5ade18415a2205fd6921ab 100644 (file)
 </tr>
 </table>
 </div>
-<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.7 (Stable Release)</p>
+<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.14.8 (Stable Release)</p>
 </body>
 </html>
index fd35c56f93f764b505b183394f0eb79501e5aa17..b7e227c9bf3d18787e4da74471b5c158e6c8fe98 100644 (file)
@@ -15,7 +15,7 @@
 
   <div class="section">
 <div class="titlepage"><div><div><h2 class="title" style="clear: both">
-<a name="id-1.2"></a>Release Notes for BIND Version 9.14.7</h2></div></div></div>
+<a name="id-1.2"></a>Release Notes for BIND Version 9.14.8</h2></div></div></div>
   
   <div class="section">
 <div class="titlepage"><div><div><h3 class="title">
 
   <div class="section">
 <div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.8-security"></a>Security Fixes</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          Set a limit on the number of concurrently served pipelined TCP
+          queries. This flaw is disclosed in CVE-2019-6477. [GL #1264]
+        </p>
+      </li></ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
+<a name="relnotes-9.14.8-features"></a>New Features</h4></div></div></div>
+    <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
+        <p>
+          Added a new statistics variable <span class="command"><strong>tcp-highwater</strong></span>
+          that reports the maximum number of simultaneous TCP clients BIND
+          has handled while running. [GL #1206]
+        </p>
+      </li></ul></div>
+  </div>
+
+  <div class="section">
+<div class="titlepage"><div><div><h4 class="title">
 <a name="relnotes-9.14.8-changes"></a>Feature Changes</h4></div></div></div>
     <div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; "><li class="listitem">
         <p>
index 7eb65e87f275af584077148daef1e34480fd1657..d28cf0eee261ef19c10e6a381efa2d485e1f66b9 100644 (file)
Binary files a/doc/arm/notes.pdf and b/doc/arm/notes.pdf differ
index 87ad3649485030e365360a300016332be8dcac02..0bc32a81ae4839f86399eb15c7041452efc2d0e2 100644 (file)
@@ -1,4 +1,4 @@
-Release Notes for BIND Version 9.14.7
+Release Notes for BIND Version 9.14.8
 
 Introduction
 
@@ -51,6 +51,17 @@ operating systems.
 
 Notes for BIND 9.14.8
 
+Security Fixes
+
+  * Set a limit on the number of concurrently served pipelined TCP
+    queries. This flaw is disclosed in CVE-2019-6477. [GL #1264]
+
+New Features
+
+  * Added a new statistics variable tcp-highwater that reports the maximum
+    number of simultaneous TCP clients BIND has handled while running. [GL
+    #1206]
+
 Feature Changes
 
   * NSEC Aggressive Cache (synth-from-dnssec) has been disabled by default