diff --git a/doc/arm/notes.xml b/doc/arm/notes.xml
index 9d0a2a180a..45d6c4cd7f 100644
--- a/doc/arm/notes.xml
+++ b/doc/arm/notes.xml
@@ -45,16 +45,15 @@
trust anchors, with somewhat different behaviors. If the root
key is configured using the managed-keys
statement, or if the pre-configured root key is enabled by using
- dnssec-validation auto, then BIND can keep
- keys up to date automatically. Servers configured in this way
- will roll seamlessly to the new key when it is published in
- the root zone. However, keys configured using the
+ dnssec-validation auto, then BIND can keep keys up
+ to date automatically. Servers configured in this way should have
+ begun the process of rolling to the new key when it was published in
+ the root zone in July 2017. However, keys configured using the
trusted-keys statement are not automatically
- maintained. If your server is performing DNSSEC validation
- and is configured using trusted-keys, you are
- advised to change your configuration before the root zone begins
- signing with the new KSK. This is currently scheduled for
- October 11, 2017.
+ maintained. If your server is performing DNSSEC validation and is
+ configured using trusted-keys, you are advised to
+ change your configuration before the root zone begins signing with
+ the new KSK. This is currently scheduled for October 11, 2017.
This release includes an updated version of the
@@ -67,6 +66,14 @@
+ Windows XP No Longer Supported
+
+ As of BIND 9.10.6, Windows XP is no longer a supported platform for
+ BIND, and Windows XP binaries are no longer available for download
+ from ISC.
+
+
+