From: Michał Kępień Date: Mon, 7 Dec 2020 07:21:06 +0000 (+0100) Subject: Reorder release notes X-Git-Tag: v9.16.11~17^2~43 X-Git-Url: http://git.ipfire.org/gitweb/?a=commitdiff_plain;h=2ef1784b854055b3235a0c502a732c8ff5285e36;p=thirdparty%2Fbind9.git Reorder release notes --- diff --git a/doc/notes/notes-current.rst b/doc/notes/notes-current.rst index c7e9f1f6b47..a29f42390e2 100644 --- a/doc/notes/notes-current.rst +++ b/doc/notes/notes-current.rst @@ -26,6 +26,11 @@ New Features - None. +- NSEC3 support was added to KASP. A new option for ``dnssec-policy``, + ``nsec3param``, can be used to set the desired NSEC3 parameters. + NSEC3 salt collisions are automatically prevented during resalting. + [GL #1620] + Removed Features ~~~~~~~~~~~~~~~~ @@ -36,11 +41,6 @@ Feature Changes - None. -- NSEC3 support was added to KASP. A new option for ``dnssec-policy``, - ``nsec3param``, can be used to set the desired NSEC3 parameters. - NSEC3 salt collisions are automatically prevented during resalting. - [GL #1620] - - The default value of ``max-recursion-queries`` was increased from 75 to 100. Since the queries sent towards root and TLD servers are now included in the count (as a result of the fix for CVE-2020-8616), @@ -59,11 +59,11 @@ Feature Changes Bug Fixes ~~~~~~~~~ -- The CNAME synthesized from a DNAME was incorrectly followed when the - QTYPE was CNAME or ANY. [GL #2280] - - Handling of missing DNS COOKIE responses over UDP was tightened by falling back to TCP. [GL #2275] +- The CNAME synthesized from a DNAME was incorrectly followed when the + QTYPE was CNAME or ANY. [GL #2280] + - Building with native PKCS#11 support for AEP Keyper has been broken since BIND 9.16.6. This has been fixed. [GL #2315]