mirror of
https://github.com/isc-projects/bind9.git
synced 2026-06-09 12:32:04 -04:00
[master] edit
This commit is contained in:
parent
b5f6271f4d
commit
96a3590505
1 changed files with 13 additions and 9 deletions
22
CHANGES
22
CHANGES
|
|
@ -1,16 +1,20 @@
|
|||
3744. [experimental] SIT: send and process Source Identity Tokens
|
||||
(which are similar to DNS Cookies by Donald Eastlake)
|
||||
and are designed to help clients detect off path
|
||||
spoofed responses and for servers to detect legitimate
|
||||
clients.
|
||||
(similar to DNS Cookies by Donald Eastlake),
|
||||
which are designed to help clients detect off-path
|
||||
spoofed responses and for servers to identify
|
||||
legitimate clients.
|
||||
|
||||
SIT use a experimental EDNS option code (65001).
|
||||
SIT uses an experimental EDNS option code (65001).
|
||||
|
||||
SIT can be enabled via --enable-developer or
|
||||
--enable-sit. It is on by default in Windows.
|
||||
SIT can be enabled via "configure --enable-sit" (or
|
||||
--enable-developer). It is enabled by default in
|
||||
Windows.
|
||||
|
||||
RRL processing as been updated to know about SIT with
|
||||
legitimate clients not being rate limited. [RT #35389]
|
||||
Servers can be configured to send smaller responses
|
||||
to clients that have not identified themselves via
|
||||
SIT. RRL processing has also been updated;
|
||||
legitimate clients are not subject to rate
|
||||
limiting. [RT #35389]
|
||||
|
||||
3743. [bug] delegation-only flag wasn't working in forward zone
|
||||
declarations despite being documented. This is
|
||||
|
|
|
|||
Loading…
Reference in a new issue