Commit graph

7513 commits

Author SHA1 Message Date
Petr Špaček
aa33bcd7dc Tweak and reword release notes 2026-02-04 14:52:33 +01:00
Petr Špaček
2804c4a35e Prepare release notes for BIND 9.20.19 2026-02-04 14:40:59 +01:00
Petr Špaček
0503d77b8f Generate changelog for BIND 9.20.19 2026-02-04 14:40:21 +01:00
Nicki Křížek
bf303c793e Apply black formatting changes
Generated by black 26.1.0 which got updated in CI.
2026-01-21 22:39:09 +01:00
Nicki Křížek
2e625f550a Tweak and reword release notes 2026-01-09 13:23:32 +01:00
Nicki Křížek
1589cc4d74 Remove release note for GL #5671
This was already fixed in the previous release.
2026-01-09 13:22:47 +01:00
Nicki Křížek
64c46390cc Prepare release notes for BIND 9.20.18 2026-01-09 13:22:28 +01:00
Nicki Křížek
2ab0a44336 Generate changelog for BIND 9.20.18 2026-01-08 16:12:53 +01:00
Michal Nowak
0a55f28bc8
Add FreeBSD 15.0
(cherry picked from commit 282f87461b)
2026-01-06 22:47:09 +01:00
Andoni Duarte
59946fce4c Merge tag 'v9.20.17' into bind-9.20 2025-12-17 15:33:14 +00:00
Andoni Duarte Pintado
78089dba2f Tweak and reword release notes 2025-12-11 11:24:55 +01:00
Andoni Duarte Pintado
f8aae78496 Prepare release notes for BIND 9.20.17 2025-12-09 18:33:22 +01:00
Andoni Duarte Pintado
6222bf35fc Generate changelog for BIND 9.20.17 2025-12-09 18:33:21 +01:00
Michal Nowak
2a5863af5a Add Alpine Linux 3.23
(cherry picked from commit 492256643d)
2025-12-09 13:30:54 +01:00
Evan Hunt
2d18b0da46 correct a double negative in the padding doc
`padding` is incompatible with TSIG and SIG(0), not with "no" TSIG
and SIG(0).

(cherry picked from commit d054741d92)
2025-12-05 22:32:07 +00:00
Matthijs Mekking
1d2d23549d Fix sig-signing-* duplicate documentation
(cherry picked from commit c3951cdec0)
2025-12-05 10:53:31 +00:00
Michal Nowak
867fd320a1
Add Fedora 43
(cherry picked from commit 350c3a9a19)
2025-11-27 17:12:24 +01:00
Andoni Duarte Pintado
fc2a620b10 Update wiki.wireshark.org link in doc/arm
Fix the broken link https://wiki.wireshark.org/TLS#tls-decryption.
Since their TOC also has the wrong anchor, we remove it altogether,
i.e. https://wiki.wireshark.org/TLS.

(cherry picked from commit fe98568be6)
2025-11-27 09:42:52 +01:00
Michal Nowak
9240a3eb97
Drop #5525 release note 2025-11-06 19:40:22 +01:00
Michal Nowak
15e365b742
Reorder release notes 2025-11-06 19:39:44 +01:00
Michal Nowak
19aedb42c7
Tweak and reword release notes 2025-11-06 19:36:19 +01:00
Michal Nowak
9f1a1602d7
Prepare release notes for BIND 9.20.16 2025-11-06 19:26:23 +01:00
Michal Nowak
78148b11f1
Generate changelog for BIND 9.20.16 2025-11-06 19:24:45 +01:00
Michał Kępień
064dbdffca
Prepare release notes for BIND 9.20.15 2025-10-18 09:49:32 +02:00
Michał Kępień
5ce20ea209
Prepare changelog for BIND 9.20.15 2025-10-18 09:49:32 +02:00
Michał Kępień
41eb7186c4
Reorder release notes 2025-10-02 18:13:26 +02:00
Michał Kępień
286205501f
Tweak and reword release notes 2025-10-02 18:13:26 +02:00
Michał Kępień
45b4fac602
Prepare release notes for BIND 9.20.14 2025-10-02 18:13:26 +02:00
Michał Kępień
921061aaeb
Generate changelog for BIND 9.20.14 2025-10-02 18:13:26 +02:00
Mark Andrews
a266f329e9
Retry lookups with unsigned DNAME over TCP
To prevent spoofed unsigned DNAME responses being accepted retry
response with unsigned DNAMEs over TCP if the response is not TSIG
signed or there isn't a good DNS CLIENT COOKIE.

(cherry picked from commit 2e40705c06)
2025-10-02 12:58:54 +02:00
Mark Andrews
3ddf4e957b Make it clearer that disable-algorithms applies to zone names
(cherry picked from commit 28848ab578)
2025-09-29 11:16:24 +10:00
Andoni Duarte
4e92403ab6 Merge branch 'bind-9.20' into 'v9.20.13-release'
# Conflicts:
#   configure.ac
2025-09-12 06:52:40 +00:00
Petr Špaček
5ae34607ac Prevent Sphinx from messing up syntax with "smartquotes" feature
Sphinx's smartquotes feature was rewriting -- to en-dash, "" to proper
English quotes etc. This was messing up syntax at unpredictable places.
Disable this feature instead of attempting to escape all the places in
the manual.

(cherry picked from commit 66e58d3315)
2025-09-11 11:18:41 +00:00
Petr Špaček
2f2c312c4f Reorder appendices in ARM
The new order hopefully reflects likelihood of someone reading from start
to the end:

DNSSEC Guide
Manual Pages
General DNS Reference Information
Release Notes
Changelog
A Brief History of the DNS and BIND

(cherry picked from commit ed0db245be)
2025-09-11 11:18:41 +00:00
Petr Špaček
7177e4bc3f Tweak and reword release notes
Two inconsequential bug fixes are not release note worthy.
Use more user-centric terminology about dnssec-policy manual-mode.
Add links, shorten notes.
2025-09-04 18:02:57 +02:00
Petr Špaček
8a542e3a37 Prepare release notes for BIND 9.20.13 2025-09-04 18:01:20 +02:00
Petr Špaček
3a4a40cb9f Generate changelog for BIND 9.20.13 2025-09-04 17:59:40 +02:00
Ondřej Surý
0c28ec295b Clarify rrset-order random distribution
The randomized order of the records in the rrset is not uniform across
all permutations.  Clarify this in the documentation.

(cherry picked from commit 369c8dc388)
2025-09-03 06:53:03 +00:00
Michał Kępień
cae623fa69
Obsolete the "tkey-domain" statement
The "tkey-domain" statement has effectively been a no-op since commit
bd4576b3ce, which removed the only bit of
code using it: the logic implementing TKEY Mode 2 (Diffie-Hellman).

A subsequent cleanup commit, 885c132f4a,
also missed the opportunity to remove the "tkey-domain" statement
altogether.

Mark the "tkey-domain" statement as obsolete and remove all code and
documentation related to it.

(cherry picked from commit 805f1c0f65)
2025-09-01 22:34:08 +02:00
Michał Kępień
5700c77a6f Deprecate the "tkey-gssapi-credential" statement
The "tkey-gssapi-keytab" statement enables GSS-TSIG to be set up in a
simpler and more reliable way than using the "tkey-gssapi-credential"
statement and setting environment variables (e.g. KRB5_KTNAME).

Mark the "tkey-gssapi-credential" statement as deprecated to eventually
only have one method for setting up GSS-TSIG in named.  Do not mention
"tkey-gssapi-credential" in the section of the ARM on dynamic updates.

(cherry picked from commit 6de435c528)
2025-09-01 19:34:14 +00:00
Michal Nowak
a4f910a720
Add Debian "trixie"
(cherry picked from commit 263810e779)
2025-09-01 17:12:43 +02:00
Petr Špaček
0dc4aabaff Clarify forward, stub, and static-stub zone usage
Clarify that forwarding points to a resolver and stub to auths.
Add cross-links. Rewrite stub zone type description.

(cherry picked from commit e84b98a9fc)
2025-08-27 14:17:39 +00:00
Aram Sargsyan
1dd4f95d1e 'servfail-until-ready yes' has no effect with DNSRPS
When a DNS Response Policy Service (DNSRPS) interface is used, the
'servfail-until-ready yes' option is ignored, because RPZ zones are
not processed by BIND.
2025-08-27 10:00:45 +00:00
Aram Sargsyan
ee29e133ac Add a new 'servfail-until-ready' configuration option for RPZ
By default, when named is started it may start answering to
queries before the response policy zones are completely loaded
and processed. This new feature gives an option to the users to
tell named that incoming requests should result in SERVFAIL anwser
until all the response policy zones are procesed and ready.

(cherry picked from commit 41387b8d30)
2025-08-27 10:00:45 +00:00
Matthijs Mekking
40d2f99852 Add manual-mode config option
Add a new option 'manual-mode' to 'dnssec-policy'. The intended
use is that if it is enabled, it will not automatically move to the
next state transition (RUMOURED, UNRETENTIVE), only after manual
confirmation. The intended state transition should be logged.

(cherry picked from commit 63c5b453e0)
2025-08-27 08:16:52 +00:00
Andoni Duarte Pintado
c06e227370 Tweak and reword release notes 2025-08-13 18:02:30 +02:00
Andoni Duarte Pintado
cbb1ff3936 Prepare release notes for BIND 9.20.12 2025-08-13 18:02:30 +02:00
Andoni Duarte Pintado
d2051add01 Generate changelog for BIND 9.20.12 2025-08-13 18:02:30 +02:00
Andoni Duarte Pintado
4255d6d80a Merge tag 'v9.20.11' into bind-9.20 2025-07-16 17:20:09 +02:00
Michal Nowak
42c1aea410
Add AlmaLinux 10
(cherry picked from commit 42367082cc)
2025-07-08 16:04:04 +02:00