From ffc0c321ca13841ea1597021b5d74832967f9424 Mon Sep 17 00:00:00 2001 From: Matthijs Mekking Date: Wed, 10 Aug 2022 16:52:53 +0200 Subject: [PATCH] Add change entry and release note for #3486 News worthy. (cherry picked from commit 2669eb2a34ef65935f8045a6c9d271af486f38d5) --- CHANGES | 3 +++ doc/notes/notes-current.rst | 6 ++++++ 2 files changed, 9 insertions(+) diff --git a/CHANGES b/CHANGES index 1dade4b8ca..d3f64a1ac9 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +5947. [func] Change dnssec-policy to allow graceful transition from + an NSEC only zone to NSEC3. [GL #3486] + 5946. [bug] Fix statistics channel's handling of multiple HTTP requests in a single connection which have non-empty request bodies. [GL #3463] diff --git a/doc/notes/notes-current.rst b/doc/notes/notes-current.rst index 3700e9a3a1..845aa8dba1 100644 --- a/doc/notes/notes-current.rst +++ b/doc/notes/notes-current.rst @@ -37,6 +37,12 @@ Feature Changes - None. +- When reconfiguring ``dnssec-policy`` from using NSEC with an NSEC-only DNSKEY + algorithm (e.g. RSASHA1) to a policy that uses NSEC3, BIND will no longer fail + to sign the zone, but keep using NSEC for a little longer until the offending + DNSKEY records have been removed from the zone, then switch to using NSEC3. + :gl:`#3486` + Bug Fixes ~~~~~~~~~