diff --git a/CHANGES b/CHANGES index 1dade4b8ca..d3f64a1ac9 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +5947. [func] Change dnssec-policy to allow graceful transition from + an NSEC only zone to NSEC3. [GL #3486] + 5946. [bug] Fix statistics channel's handling of multiple HTTP requests in a single connection which have non-empty request bodies. [GL #3463] diff --git a/doc/notes/notes-current.rst b/doc/notes/notes-current.rst index 3700e9a3a1..845aa8dba1 100644 --- a/doc/notes/notes-current.rst +++ b/doc/notes/notes-current.rst @@ -37,6 +37,12 @@ Feature Changes - None. +- When reconfiguring ``dnssec-policy`` from using NSEC with an NSEC-only DNSKEY + algorithm (e.g. RSASHA1) to a policy that uses NSEC3, BIND will no longer fail + to sign the zone, but keep using NSEC for a little longer until the offending + DNSKEY records have been removed from the zone, then switch to using NSEC3. + :gl:`#3486` + Bug Fixes ~~~~~~~~~