|
|
|
|
Changelog for bind-libs-9.8.2-0.68.rc1.el6_10.7.x86_64.rpm :
* Mon Jun 01 2020 Petr Menšík - 32:9.8.2-0.68.rc1.7- Correct tests covering CVE-2020-8617 * Fri May 29 2020 Petr Menšík - 32:9.8.2-0.68.rc1.6- Add additional fix to limit recursions * Fri May 22 2020 Petr Menšík - 32:9.8.2-0.68.rc1.5- Add CVE tests to codebase * Tue May 19 2020 Petr Menšík - 32:9.8.2-0.68.rc1.4- Limit number of queries triggered by a request (CVE-2020-8616)- Fix invalid tsig request (CVE-2020-8617) * Fri Jun 07 2019 Petr Menšík - 32:9.8.2-0.68.rc1.3- Use only selected documentation files * Wed May 15 2019 Petr Menšík - 32:9.8.2-0.68.rc1.2- Fix CVE-2018-5743 * Thu Aug 09 2018 Petr Menšík - 32:9.8.2-0.68.rc1.1- Fix CVE-2018-5740 * Tue Jan 16 2018 Petr Menšík - 32:9.8.2-0.68.rc1- Fix CVE-2017-3145 * Mon Dec 04 2017 Petr Menšík - 32:9.8.2-0.67.rc1- Change EDNS flags only after successful query (#1416035)- Fix crash in ldap driver at bind-sdb stop (#1426626) * Thu Jun 29 2017 Petr Menšík - 32:9.8.2-0.66.rc1- Fix CVE-2017-3142 and CVE-2017-3143 * Wed May 31 2017 Petr Menšík - 32:9.8.2-0.65.rc1- Update root servers and trust anchors * Wed May 03 2017 Petr Menšík - 32:9.8.2-0.64.rc1- Fix DNSKEY that encountered a CNAME (#1447872, ISC change 3391) * Tue Apr 18 2017 Petr Menšík - 32:9.8.2-0.63.rc1- Fix CVE-2017-3136 (ISC change 4575)- Fix CVE-2017-3137 (ISC change 4578) * Wed Feb 08 2017 Petr Menšík - 32:9.8.2-0.62.rc1- Fix and test caching CNAME before DNAME (ISC change 4558) * Tue Jan 10 2017 Petr Menšík - 32:9.8.2-0.61.rc1- Fix CVE-2016-9147 (ISC change 4510)- Fix regression introduced by CVE-2016-8864 (ISC change 4530) * Tue Nov 22 2016 Petr Menšík - 32:9.8.2-0.60.rc1- Restore SELinux contexts before named restart * Mon Oct 31 2016 Petr Menšík - 32:9.8.2-0.59.rc1- Use /lib or /lib64 only if directory in chroot already exists- Tighten NSS library pattern, escape chroot mount path * Mon Oct 31 2016 Tomas Hozza - 32:9.8.2-0.58.rc1- Fix CVE-2016-8864 * Thu Oct 20 2016 Petr Menšík - 32:9.8.2-0.57.rc1- Do not change lib permissions in chroot (#1321239)- Support WKS records in chroot (#1297562) * Thu Oct 20 2016 Petr Menšík - 32:9.8.2-0.56.rc1- Do not include patch backup in docs (fixes #1325081 patch) * Wed Oct 19 2016 Petr Menšík - 32:9.8.2-0.55.rc1- Backported relevant parts of [RT #39567] (#1259923) * Wed Oct 19 2016 Petr Menšík - 32:9.8.2-0.54.rc1- Increase ISC_SOCKET_MAXEVENTS to 2048 (#1326283) * Tue Oct 18 2016 Petr Menšík - 32:9.8.2-0.53.rc1- Fix multiple realms in nsupdate script like upstream (#1313286) * Mon Oct 17 2016 Petr Menšík - 32:9.8.2-0.52.rc1- Fix multiple realm in nsupdate script (#1313286) * Mon Oct 17 2016 Petr Menšík - 32:9.8.2-0.51.rc1- Use resolver-query-timeout high enough to recover all forwarders (#1325081) * Mon Oct 17 2016 Tomas Hozza - 32:9.8.2-0.50.rc1- Fix CVE-2016-2848 * Fri Oct 14 2016 Petr Menšík - 32:9.8.2-0.49.rc1- Fix infinite loop in start_lookup (#1306504) * Fri Sep 23 2016 Tomas Hozza - 32:9.8.2-0.48.rc1- Fix CVE-2016-2776 * Wed Mar 09 2016 Tomas Hozza - 32:9.8.2-0.47.rc1- Fix CVE-2016-1285 and CVE-2016-1286 * Mon Jan 18 2016 Tomas Hozza - 32:9.8.2-0.46.rc1- Fix CVE-2015-8704 * Mon Jan 11 2016 Tomas Hozza - 32:9.8.2-0.45.rc1- Updated named.ca hints file to the latest version (#1267991) * Mon Dec 14 2015 Tomas Hozza - 32:9.8.2-0.44.rc1- Fix CVE-2015-8000 * Mon Dec 14 2015 Tomas Hozza - 32:9.8.2-0.43.rc1- Fix excessive queries caused by DS chasing with stub zones when DNSSEC is not used (#1227189)- Added the fixed tarball with configuration to Sources (Related: #1223359) * Fri Nov 20 2015 Tomas Hozza - 32:9.8.2-0.42.rc1- Don\'t use ISC\'s DLV by default (#1223359) * Fri Nov 20 2015 Tomas Hozza - 32:9.8.2-0.41.rc1- Added support for CAA records (#1252611) * Wed Sep 02 2015 Tomas Hozza - 32:9.8.2-0.40.rc1- Fix CVE-2015-5722 * Tue Jul 28 2015 Tomas Hozza - 32:9.8.2-0.39.rc1- Fix CVE-2015-5477 * Thu Jul 09 2015 Tomas Hozza - 32:9.8.2-0.38.rc1- Fix CVE-2015-4620 * Thu May 07 2015 Pavel Šimerda - 32:9.8.2-0.37.rc1- Resolves: 1215687 - DNS resolution failure in high load environment with SERVFAIL and \"out of memory/success\" in the log * Mon Mar 02 2015 Tomas Hozza 32:9.8.2-0.36.rc1- Fix CVE-2015-1349 * Thu Feb 19 2015 Tomas Hozza 32:9.8.2-0.35.rc1- Enable RPZ-NSIP and RPZ-NSDNAME during compilation (#1176476) * Tue Feb 17 2015 Tomas Hozza 32:9.8.2-0.34.rc1- Fix race condition when using isc__begin_beginexclusive (#1175321) * Tue Dec 16 2014 Tomas Hozza 32:9.8.2-0.33.rc1- Sanitize SDB API to better handle database errors (#1146893) * Tue Dec 09 2014 Tomas Hozza 32:9.8.2-0.32.rc1- Fix CVE-2014-8500 (#1171974) * Mon Dec 08 2014 Tomas Hozza 32:9.8.2-0.31.rc1- Fix RRL slip behavior when set to 1 (#1112356)- Fix issue causing bind to hang after reload if using DYNDB (#1142152) * Mon Jun 09 2014 Tomas Hozza 32:9.8.2-0.30.rc1- Use /dev/urandom when generating rndc.key file (#951255) * Mon May 19 2014 Tomas Hozza 32:9.8.2-0.29.rc1- Remove bogus file from /usr/share/doc, introduced by fix for bug #1092035 * Mon May 19 2014 Tomas Hozza 32:9.8.2-0.28.rc1- Add support for TLSA resource records (#956685)- Increase defaults for lwresd workers and make workers and client objects number configurable (#1092035) * Wed Apr 23 2014 Tomas Hozza 32:9.8.2-0.27.rc1- Fix segmentation fault in nsupdate when -r option is used (#1064045)- Fix race condition on send buffer in host tool when sending UDP query (#1008827)- Allow authentication using TSIG in allow-notify configuration statement (#1044545)- Fix SELinux context of /var/named/chroot/etc/localtime (#902431)- Include updated named.ca file with root server addresses (#917356)- Don\'t generate rndc.key if there is rndc.conf on start-up (#997743)- Fix dig man page regarding how to disable IDN (#1023045)- Handle ICMP Destination unreachable (Protocol unreachable) response (#1066876) * Tue Apr 22 2014 Tomas Hozza 32:9.8.2-0.26.rc1- Configure BIND with --with-dlopen=yes to support dynamically loadable DLZ drivers (#846065)- Fix initscript to return correct exit value when calling checkconfig/configtest/check/test (#848033)- Don\'t (un)mount chroot filesystem when running initscript command configtest with running server (#851123)- Fix zone2sqlite tool to accept zones containing \".\" or \"-\" or starting with a digit (#919414)- Fix initscript not to mount chroot filesystem is named is already running (#948743)- Fix initscript to check if the PID in PID-file is really s PID of running named server (#980632)- Correct the installed documentation ownership (#1051283) * Mon Apr 14 2014 Tomas Hozza 32:9.8.2-0.25.rc1- configure with --enable-filter-aaaa to enable use of filter-aaaa-on-v4 option (#1025008)- Fix race condition when destroying a resolver fetch object (#993612)- Fix the RRL functionality to include referrals-per-second and nodata-per-second options (#1036700)- Fix segfault on SERVFAIL to NXDOMAIN failover (#919545) * Mon Jan 13 2014 Tomas Hozza 32:9.8.2-0.24.rc1- Fix CVE-2014-0591 * Wed Aug 14 2013 Tomas Hozza 32:9.8.2-0.23.rc1- Fix gssapictx memory leak (#911167) * Sun Jul 28 2013 Tomas Hozza 32:9.8.2-0.22.rc1- fix CVE-2013-4854 * Wed Mar 27 2013 Adam Tkac 32:9.8.2-0.21.rc1- fix CVE-2013-2266- ship dns/rrl.h in -devel subpkg * Fri Feb 08 2013 Adam Tkac 32:9.8.2-0.20.rc1- remove one bogus file from /usr/share/doc, introduced by RRL patch * Fri Feb 01 2013 Adam Tkac 32:9.8.2-0.19.rc1- fix CVE-2012-5689 * Thu Jan 31 2013 Adam Tkac 32:9.8.2-0.18.rc1- add response rate limit patch (#873624) * Wed Dec 05 2012 Adam Tkac 32:9.8.2-0.17.rc1- fix CVE-2012-5688 * Wed Oct 17 2012 Adam Tkac 32:9.8.2-0.16.rc1- initscript: silence spurious \"named.pid: No such file\" error * Wed Oct 10 2012 Adam Tkac 32:9.8.2-0.15.rc1- fix CVE-2012-5166 * Tue Sep 18 2012 Adam Tkac 32:9.8.2-0.14.rc1- allow forward{,ers} statement in static-stub zones * Thu Sep 13 2012 Adam Tkac 32:9.8.2-0.13.rc1- fix CVE-2012-4244 * Wed Jul 25 2012 Adam Tkac 32:9.8.2-0.12.rc1- fix CVE-2012-3817 * Tue Jul 10 2012 Adam Tkac 32:9.8.2-0.11.rc1- fix rbtnode.deadlink INSIST failures in rbtdb.c (#837165) * Mon Jun 04 2012 Adam Tkac 32:9.8.2-0.10.rc1- fix CVE-2012-1667 * Mon May 07 2012 Adam Tkac 32:9.8.2-0.9.rc1- fix race condition in the resolver module- nslookup: return non-zero exit code when fail to get answer (#816164) * Thu Apr 26 2012 Adam Tkac 32:9.8.2-0.8.rc1- initscript: don\'t umount /var/named when didn\'t mount it * Wed Apr 04 2012 Adam Tkac 32:9.8.2-0.7.rc1- don\'t fail when logfile cannot be opened (#809084) * Tue Mar 06 2012 Adam Tkac 32:9.8.2-0.6.rc1- fix multilib regression in bind-devel (#800053) * Mon Mar 05 2012 Adam Tkac 32:9.8.2-0.5.rc1- fix errors reported by Coverity- be more strict when caching NS RRsets (CVE-2012-1033) * Tue Feb 21 2012 Adam Tkac 32:9.8.2-0.4.rc1- load dynamic-db plugins later (#795414) * Wed Feb 15 2012 Adam Tkac 32:9.8.2-0.3.rc1- decrease severity of various errors related to outside DNS environment (#788870)- fixed various bind-chroot packaging errors (#789886)- use portreserve to reserve rndc control port (#790682) * Wed Feb 15 2012 Adam Tkac 32:9.8.2-0.2.rc1- harden dns_zone_setmasterswithkeys() to avoid INSIST failures- build with \'--enable-fixed-rrset\'- fix potential memory leak in code which processes rndc authentication (#749582)- generate rndc.key during `service named start` (#768798)- nslookup: improve handling of AA responses with recursion off- removed obsolete bind97-rh714049.patch patch * Wed Feb 15 2012 Adam Tkac 32:9.8.2-0.1.rc1- update to 9.8.2rc1- patches merged - bind97-rh754398.patch - bind97-rh700097.patch - bind97-rh734502.patch - bind97-rh746694-1.patch - bind97-rh746694-2.patch - bind97-rh739406-1.patch - bind97-rh739406-2.patch- ship DNSKEY for root zone in default configuration * Tue Dec 20 2011 Adam Tkac 32:9.7.3-10.P3- disable atomic ops on ppc * because they caused named to hang/crash * Tue Nov 29 2011 Adam Tkac 32:9.7.3-9.P3- fix race condition in resolver.c:validated()- improve error handling in zone.c:zone_refreshkeys() to avoid hang during shutdown * Wed Nov 16 2011 Adam Tkac 32:9.7.3-8.P3- fix DOS against recursive servers (#754398) * Fri Sep 09 2011 Adam Tkac 32:9.7.3-7.P3- fix memory leak in nsupdate when using SIG(0) keys * Fri Aug 12 2011 Adam Tkac 32:9.7.3-6.P3- load/unload dyndb plugins on appropriate places to avoid crashes (#725577)- nsupdate could have failed if server has multiple IPs and the first was unreachable (#714049)- nsupdate returned zero when target zone didn\'t exist (#700097)- readd configtest target to initscript- print \"the working directory is not writable\" as debug message- fix some Coverity warnings * Thu Aug 11 2011 Adam Tkac 32:9.7.3-5.P3- fix rare race condition in request.c * Tue Jul 05 2011 Adam Tkac 32:9.7.3-4.P3- update to 9.7.3-P3 (CVE-2011-2464) * Fri May 27 2011 Adam Tkac 32:9.7.3-3.P1- update to 9.7.3-P1 (CVE-2011-1910) * Mon Mar 28 2011 Adam Tkac 32:9.7.3-2- don\'t generate rndc.key during installation * Mon Feb 28 2011 Adam Tkac 32:9.7.3-1- update to 9.7.3 (CVE-2011-0414)- patches merged - bind97-gsstsig.patch - bind97-rh664401.patch - bind97-rh623638.patch * Fri Jan 28 2011 Adam Tkac 32:9.7.2-8.P3- regenerate fixed nsupdate manual page * Fri Jan 28 2011 Adam Tkac 32:9.7.2-7.P3- improve host/dig resolv.conf parser (#rh669163)- improve internal test suite- don\'t mention that HMAC-MD5 is the only one TSIG algorighm in nsupdate manpage- initscript: sybsys name is always named, not named-sdb * Wed Jan 12 2011 Adam Tkac 32:9.7.2-6.P3- named could die on exit after negotiating a GSS-TSIG key (#653486)- fix typo in initscript * Thu Jan 06 2011 Adam Tkac 32:9.7.2-5.P3- include root zone DNSKEY in the bind package (#667375) * Thu Jan 06 2011 Adam Tkac 32:9.7.2-4.P3- solve conflict between i686 and x86_64 bind-devel packages (#658045)- fix \"service named status\" when used with named-sdb- fix \"krb5-self\" update-policy rule processing (#664401)- don\'t check MD5, size and mtime of sysconfig/named * Wed Jan 05 2011 Adam Tkac 32:9.7.2-3.P3- use same atomic operations on both ppc and ppc64 (#623638)- add new option DISABLE_ZONE_CHECKING to sysconfig/named (#623673)- document dig exit codes- add Requires: bind-libs to bind subpkgs- remove statement about system-config-bind from named.8 manpage (#660676) * Wed Jan 05 2011 Adam Tkac 32:9.7.2-2.P3- host utility now honors \"attempts\", \"timeout\" and \"debug\" options in resolv.conf (#622764)- initscript should kill only the \"correct\" named process (#622785)- attempt to reconnect to PostgreSQL during each query if the initial connection failed (#623190) * Tue Dec 21 2010 Adam Tkac 32:9.7.2-1.P3- update to 9.7.2-P3 (#623122)- patch bind97-managed-keyfile.patch replaced by bind97-compat-keysdir.patch- patches merged - bind97-rh554316.patch - bind97-rh576906.patch * Wed May 26 2010 Adam Tkac 32:9.7.0-5.P2- update to 9.7.0-P2 * Tue Mar 30 2010 Adam Tkac 32:9.7.0-4.P1- fix occassional crash on keytable.c:286 (#554316)- active query might be destroyed in resume_dslookup() which triggered REQUIRE failure (#507429) * Fri Mar 19 2010 Adam Tkac 32:9.7.0-3.P1- update to 9.7.0-P1 release * Mon Mar 01 2010 Adam Tkac 32:9.7.0-2- improve automatic DNSSEC reconfiguration trigger- initscript now returns 2 in case that action doesn\'t exist (#523435)- enable/disable chroot when bind-chroot is installed/uninstalled * Wed Feb 17 2010 Adam Tkac 32:9.7.0-1- update to production 9.7.0 release * Mon Feb 15 2010 Adam Tkac 32:9.7.0-0.14.rc2- obsolete dnssec-conf- automatically update configuration from old dnssec-conf based- improve default configuration; enable DLV by default- remove obsolete triggerpostun from bind-libs subpackage * Thu Jan 28 2010 Adam Tkac 32:9.7.0-0.13.rc2- update to 9.7.0rc2 bugfix release (CVE-2010-0097 and CVE-2010-0290) * Wed Jan 27 2010 Adam Tkac 32:9.7.0-0.12.rc1- initscript LSB related fixes (#523435)- revert the \"DEBUG\" feature (#510283), it causes too many problems (#545128) * Thu Jan 07 2010 Adam Tkac 32:9.7.0-0.11.rc1- disable PKCS11 support. PKCS11 support in openssl is not available in RHEL6 * Tue Dec 15 2009 Adam Tkac 32:9.7.0-0.10.rc1- update to 9.7.0rc1- bind97-headers.patch merged- update default configuration * Tue Dec 01 2009 Adam Tkac 32:9.7.0-0.9.b3- update to 9.7.0b3 * Thu Nov 26 2009 Adam Tkac 32:9.7.0-0.8.b2- install isc/namespace.h header * Fri Nov 06 2009 Adam Tkac 32:9.7.0-0.7.b2- update to 9.7.0b2 * Tue Nov 03 2009 Adam Tkac 32:9.7.0-0.6.b1- update to 9.7.0b1- add bind-pkcs11 subpackage to support PKCS11 compatible keystores for DNSSEC keys * Thu Oct 08 2009 Adam Tkac 32:9.7.0-0.5.a3- don\'t package named-bootconf utility, it is very outdated and unneeded * Mon Sep 21 2009 Adam Tkac 32:9.7.0-0.4.a3- determine file size via `stat` instead of `ls` (#523682) * Wed Sep 16 2009 Adam Tkac 32:9.7.0-0.3.a3- update to 9.7.0a3 * Tue Sep 15 2009 Adam Tkac 32:9.7.0-0.2.a2- improve chroot related documentation (#507795)- add NetworkManager dispatcher script to reload named when network interface is activated/deactivated (#490275)- don\'t set/unset named_write_master_zones SELinux boolean every time in initscript, modify it only when it\'s actually needed * Tue Sep 15 2009 Adam Tkac 32:9.7.0-0.1.a2- update to 9.7.0a2- merged patches - bind-96-db_unregister.patch - bind96-rh507469.patch * Tue Sep 01 2009 Adam Tkac 32:9.6.1-9.P1- next attempt to fix the postun trigger (#520385)- remove obsolete bind-9.3.1rc1-fix_libbind_includedir.patch * Fri Aug 21 2009 Tomas Mraz - 32:9.6.1-8.P1- rebuilt with new openssl * Tue Aug 04 2009 Martin Nagy 32:9.6.1-7.P1- update the patch for dynamic loading of database backends * Wed Jul 29 2009 Adam Tkac 32:9.6.1-6.P1- 9.6.1-P1 release (CVE-2009-0696)- fix postun trigger (#513016, hopefully) * Fri Jul 24 2009 Fedora Release Engineering - 32:9.6.1-5- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Mon Jul 20 2009 Adam Tkac 32:9.6.1-4- remove useless bind-9.3.3rc2-rndckey.patch * Mon Jul 13 2009 Adam Tkac 32:9.6.1-3- fix broken symlinks in bind-libs (#509635)- fix typos in /etc/sysconfig/named (#509650)- add DEBUG option to /etc/sysconfig/named (#510283) * Wed Jun 24 2009 Adam Tkac 32:9.6.1-2- improved \"chroot automount\" patches (#504596)- host should fail if specified server doesn\'t respond (#507469) * Wed Jun 17 2009 Adam Tkac 32:9.6.1-1- 9.6.1 release- simplify chroot maintenance. Important files and directories are mounted into chroot (see /etc/sysconfig/named for more info, #504596)- fix doc/named.conf.default perms * Wed May 27 2009 Adam Tkac 32:9.6.1-0.4.rc1- 9.6.1rc1 release * Wed Apr 29 2009 Martin Nagy 32:9.6.1-0.3.b1- update the patch for dynamic loading of database backends- create %{_libdir}/bind directory- copy default named.conf to doc directory, shared with s-c-bind (atkac) * Fri Apr 24 2009 Martin Nagy 32:9.6.1-0.2.b1- update the patch for dynamic loading of database backends- fix dns_db_unregister()- useradd now takes \"-N\" instead of \"-n\" (atkac, #495726)- print nicer error msg when zone file is actually a directory (atkac, #490837) * Mon Mar 30 2009 Adam Tkac 32:9.6.1-0.1.b1- 9.6.1b1 release- patches merged - bind-96-isc_header.patch - bind-95-rh469440.patch - bind-96-realloc.patch - bind9-fedora-0001.diff- use -version-number instead of -version-info libtool param * Mon Mar 23 2009 Adam Tkac 32:9.6.0-11.1.P1- logrotate configuration file now points to /var/named/data/named.run by default (#489986) * Tue Mar 17 2009 Adam Tkac 32:9.6.0-11.P1- fall back to insecure mode when no supported DNSSEC algorithm is found instead of SERVFAIL- don\'t fall back to non-EDNS0 queries when DO bit is set * Tue Mar 10 2009 Adam Tkac 32:9.6.0-10.P1- enable DNSSEC only if it is enabled in sysconfig/dnssec * Mon Mar 09 2009 Adam Tkac 32:9.6.0-9.P1- add DNSSEC support to initscript, enabled it per default- add requires dnssec-conf * Mon Mar 09 2009 Adam Tkac 32:9.6.0-8.P1- fire away libbind, it is now separate package * Wed Mar 04 2009 Adam Tkac 32:9.6.0-7.P1- fixed some read buffer overflows (upstream) * Mon Feb 23 2009 Fedora Release Engineering 32:9.6.0-6.P1- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Thu Feb 12 2009 Martin Nagy 32:9.6.0-5.P1- update the patch for dynamic loading of database backends- include iterated_hash.h * Sat Jan 24 2009 Caolán McNamara 32:9.6.0-4.P1- rebuild for dependencies * Wed Jan 21 2009 Adam Tkac 32:9.6.0-3.P1- rebuild against new openssl * Thu Jan 08 2009 Adam Tkac 32:9.6.0-2.P1- 9.6.0-P1 release (CVE-2009-0025) * Mon Jan 05 2009 Adam Tkac 32:9.6.0-1- Happy new year- 9.6.0 release * Thu Dec 18 2008 Adam Tkac 32:9.6.0-0.7.rc2- 9.6.0rc2 release- bind-96-rh475120.patch merged * Tue Dec 16 2008 Martin Nagy 32:9.6.0-0.6.rc1- add patch for dynamic loading of database backends * Tue Dec 09 2008 Adam Tkac 32:9.6.0-0.5.1.rc1- allow to reuse address for non-random query-source ports (#475120) * Wed Dec 03 2008 Adam Tkac 32:9.6.0-0.5.rc1- 9.6.0rc1 release- patches merged - bind-9.2.0rc3-varrun.patch - bind-95-sdlz-include.patch - bind-96-libxml2.patch- fixed rare use-after-free problem in host utility (#452060)- enabled chase of DNSSEC signature chains in dig * Mon Dec 01 2008 Adam Tkac 32:9.6.0-0.4.1.b1- improved sample config file (#473586) * Wed Nov 26 2008 Adam Tkac 32:9.6.0-0.4.b1- reverted previous change, koji doesn\'t like it * Wed Nov 26 2008 Adam Tkac 32:9.6.0-0.3.b1- build bind-chroot as noarch * Mon Nov 24 2008 Adam Tkac 32:9.6.0-0.2.1.b1- updates due libtool 2.2.6- don\'t pass -DLDAP_DEPRECATED to cpp, handle it directly in sources * Tue Nov 11 2008 Adam Tkac 32:9.6.0-0.2.b1- make statistics http server working, patch backported from 9.6 HEAD * Mon Nov 10 2008 Adam Tkac 32:9.6.0-0.1.b1- 9.6.0b1 release- don\'t build ODBC and Berkeley DB DLZ drivers- end of bind-chroot-admin script, copy config files to chroot manually- /proc doesn\'t have to be mounted to chroot- temporary use libbind from 9.5 series, noone has been released for 9.6 yet * Mon Nov 03 2008 Adam Tkac 32:9.5.1-0.8.4.b2- dig/host: use only IPv4 addresses when -4 option is specified (#469440) * Thu Oct 30 2008 Adam Tkac 32:9.5.1-0.8.2.b2- removed unneeded bind-9.4.1-ldap-api.patch * Thu Oct 30 2008 Adam Tkac 32:9.5.1-0.8.1.b2- ship dns/{s,}dlz.h and isc/radix.h in bind-devel * Tue Oct 07 2008 Adam Tkac 32:9.5.1-0.8.b2- removed bind-9.4.0-dnssec-directory.patch, it is wrong * Wed Sep 24 2008 Adam Tkac 32:9.5.1-0.7.b2- 9.5.1b2 release- patches merged - bind95-rh454783.patch - bind-9.5-edns.patch - bind95-rh450995.patch - bind95-rh457175.patch * Wed Sep 17 2008 Adam Tkac 32:9.5.1-0.6.b1- IDN output strings didn\'t honour locale settings (#461409) * Tue Aug 05 2008 Adam Tkac 32:9.5.1-0.5.b1- disable transfer stats on DLZ zones (#454783) * Mon Aug 04 2008 Adam Tkac 32:9.5.1-0.4.b1- add forgotten patch for #457175- build with -O2 * Thu Jul 31 2008 Adam Tkac 32:9.5.1-0.3.b1- static libraries are no longer supported- IP acls weren\'t merged correctly (#457175)- use fPIE on sparcv9/sparc64 (Dennis Gilmore)- add sparc64 to list of 64bit arches in spec (Dennis Gilmore) * Mon Jul 21 2008 Adam Tkac 32:9.5.1-0.2.b1- updated patches due new rpm (--fuzz=0 patch parameter) * Mon Jul 14 2008 Adam Tkac 32:9.5.1-0.1.1.b1- use %patch0 for Patch0 (#455061)- correct source address (#455118) * Tue Jul 08 2008 Adam Tkac 32:9.5.1-0.1.b1- 9.5.1b1 release (CVE-2008-1447)- dropped bind-9.5-recv-race.patch because upstream doesn\'t want it * Mon Jun 30 2008 Adam Tkac 32:9.5.0-37.1- update default named.conf statements (#452708) * Thu Jun 26 2008 Adam Tkac 32:9.5.0-37- some compat changes to fix building on RHEL4 * Mon Jun 23 2008 Adam Tkac 32:9.5.0-36.3- fixed typo in %posttrans script * Wed Jun 18 2008 Adam Tkac 32:9.5.0-36.2- parse inner acls correctly (#450995) * Mon Jun 02 2008 Adam Tkac 32:9.5.0-36.1- removed dns-keygen utility in favour of rndc-confgen -a (#449287)- some minor sample fixes (#449274) * Thu May 29 2008 Adam Tkac 32:9.5.0-36- updated to 9.5.0 final- use getifaddrs to find available interfaces * Mon May 26 2008 Adam Tkac 32:9.5.0-35.rc1- make /var/run/named writable by named (#448277)- fixed one non-utf8 file * Thu May 22 2008 Adam Tkac 32:9.5.0-34.rc1- fixes needed to pass package review (#225614) * Wed May 21 2008 Adam Tkac 32:9.5.0-33.1.rc1- bind-chroot now depends on bind (#446477) * Wed May 14 2008 Adam Tkac 32:9.5.0-33.rc1- updated to 9.5.0rc1- merged patches - bind-9.5-libcap.patch- make binaries readable by others (#427826) * Tue May 13 2008 Adam Tkac 32:9.5.0-32.b3- reverted \"any\" patch, upstream says not needed- log EDNS failure only when we really switch to plain EDNS (#275091)- detect configuration file better * Tue May 06 2008 Adam Tkac 32:9.5.0-31.1.b3- addresses 0.0.0.0 and ::0 really match any (#275091, comment #28) * Mon May 05 2008 Adam Tkac 32:9.5.0-31.b3- readded bind-9.5-libcap.patch- added bind-9.5-recv-race.patch from F8 branch (#400461) * Wed Apr 23 2008 Adam Tkac 32:9.5.0-30.1.b3- build Berkeley DB DLZ backend * Mon Apr 21 2008 Adam Tkac 32:9.5.0-30.b3- 9.5.0b3 release- dropped patches (upstream) - bind-9.5-transfer-segv.patch - bind-9.5-mudflap.patch - bind-9.5.0-generate-xml.patch - bind-9.5-libcap.patch * Wed Apr 02 2008 Adam Tkac 32:9.5.0-29.3.b2- fixed named.conf.sample file (#437569) * Fri Mar 14 2008 Adam Tkac 32:9.5.0-29.2.b2- fixed URLs * Mon Feb 25 2008 Adam Tkac 32:9.5.0-29.1.b2- BuildRequires cleanup * Sun Feb 24 2008 Adam Tkac 32:9.5.0-29.b2- rebuild without mudflap (#434159) * Wed Feb 20 2008 Adam Tkac 32:9.5.0-28.b2- port named to use libcap library, enable threads (#433102)- removed some unneeded Requires * Tue Feb 19 2008 Adam Tkac 32:9.5.0-27.b2- removed conditional build with libefence (use -fmudflapth instead)- fixed building of DLZ stuff (#432497)- do not build Berkeley DB DLZ backend- temporary build with --disable-linux-caps and without threads (#433102)- update named.ca file to affect IPv6 changes in root zone * Mon Feb 11 2008 Adam Tkac 32:9.5.0-26.b2- build with -D_GNU_SOURCE (#431734)- improved fix for #253537, posttrans script is now used- improved fix for #400461- 9.5.0b2 - bind-9.3.2b1-PIE.patch replaced by bind-9.5-PIE.patch - only named, named-sdb and lwresd are PIE - bind-9.5-sdb.patch has been updated - bind-9.5-libidn.patch has been updated - bind-9.4.0-sdb-sqlite-bld.patch replaced by bind-9.5-sdb-sqlite-bld.patch - removed bind-9.5-gssapi-header.patch (upstream) - removed bind-9.5-CVE-2008-0122.patch (upstream)- removed bind-9.2.2-nsl.patch- improved sdb_tools Makefile.in * Mon Feb 04 2008 Adam Tkac 32:9.5.0-25.b1- fixed segfault during sending notifies (#400461)- rebuild with gcc 4.3 series * Tue Jan 22 2008 Adam Tkac 32:9.5.0-24.b1- removed bind-9.3.2-prctl_set_dumpable.patch (upstream)- allow parallel building of libdns library- CVE-2008-0122 * Thu Dec 27 2007 Adam Tkac 32:9.5.0-23.b1- fixed initscript wait loop (#426382)- removed dependency on policycoreutils and libselinux (#426515) * Thu Dec 20 2007 Adam Tkac 32:9.5.0-22.b1- fixed regression caused by libidn2 patch (#426348) * Wed Dec 19 2007 Adam Tkac 32:9.5.0-21.b1- fixed typo in post section (CVE-2007-6283) * Wed Dec 19 2007 Adam Tkac 32:9.5.0-20.b1- removed obsoleted triggers- CVE-2007-6283 * Wed Dec 12 2007 Adam Tkac 32:9.5.0-19.2.b1- added dst/gssapi.h to -devel subpackage (#419091)- improved fix for (#417431) * Mon Dec 10 2007 Adam Tkac 32:9.5.0-19.1.b1- fixed shutdown with initscript when rndc doesn\'t work (#417431)- fixed IDN patch (#412241) * Thu Dec 06 2007 Adam Tkac 32:9.5.0-19.b1- 9.5.0b1 (#405281, #392491) * Thu Dec 06 2007 Release Engineering 32:9.5.0-18.6.a7- Rebuild for deps * Wed Dec 05 2007 Adam Tkac 32:9.5.0-18.5.a7- build with -O0 * Mon Dec 03 2007 Adam Tkac 32:9.5.0-18.4.a7- bind-9.5-random_ports.patch was removed because upstream doesn\'t like it. query-source{,v6} options are sufficient (#391931)- bind-chroot-admin called restorecon on /proc filesystem (#405281) * Mon Nov 26 2007 Adam Tkac 32:9.5.0-18.3.a7- removed edns patch to keep compatibility with vanilla bind (#275091, comment #20) * Wed Nov 21 2007 Adam Tkac 32:9.5.0-18.2.a7- use system port selector instead ISC\'s (#391931) * Mon Nov 19 2007 Adam Tkac 32:9.5.0-18.a7- removed statement from initscript which passes -D to named * Thu Nov 15 2007 Adam Tkac 32:9.5.0-17.a7- 9.5.0a7- dropped patches (upstream) - bind-9.5-update.patch - bind-9.5-pool_badfree.patch - bind-9.5-_res_errno.patch * Thu Nov 15 2007 Adam Tkac 32:9.5.0-16.5.a6- added bind-sdb again, contains SDB modules and DLZ modules- bind-9.3.1rc1-sdb.patch replaced by bind-9.5-sdb.patch * Mon Nov 12 2007 Adam Tkac 32:9.5.0-16.4.a6- removed Requires: openldap, postgresql, mysql, db4, unixODBC- new L.ROOT-SERVERS.NET address * Mon Oct 29 2007 Adam Tkac 32:9.5.0-16.3.a6- completely disable DBUS * Fri Oct 26 2007 Adam Tkac 32:9.5.0-16.2.a6- minor cleanup in bind-chroot-admin * Thu Oct 25 2007 Adam Tkac 32:9.5.0-16.1.a6- fixed typo in initscript * Tue Oct 23 2007 Adam Tkac 32:9.5.0-16.a6- disabled DBUS (dhcdbd doesn\'t exist & #339191) * Thu Oct 18 2007 Adam Tkac 32:9.5.0-15.1.a6- fixed missing va_end () functions (#336601)- fixed memory leak when dbus initialization fails * Tue Oct 16 2007 Adam Tkac 32:9.5.0-15.a6- corrected named.5 SDB statement (#326051) * Mon Sep 24 2007 Adam Tkac 32:9.5.0-14.a6- added edns patch again (#275091) * Mon Sep 24 2007 Adam Tkac 32:9.5.0-13.a6- removed bind-9.3.3-edns.patch patch (see #275091 for reasons) * Thu Sep 20 2007 Adam Tkac 32:9.5.0-12.4.a6- build with O2- removed \"autotools\" patch- bugfixing in bind-chroot-admin (#279901) * Thu Sep 06 2007 Adam Tkac 32:9.5.0-12.a6- bind-9.5-2119_revert.patch and bind-9.5-fix_h_errno.patch are obsoleted by upstream bind-9.5-_res_errno.patch * Wed Sep 05 2007 Adam Tkac 32:9.5.0-11.9.a6- fixed wrong resolver\'s dispatch pool cleanup (#275011, patch from tmraz redhat com) * Wed Sep 05 2007 Adam Tkac 32:9.5.0-11.3.a6- initscript failure message is now printed correctly (#277981, Quentin Armitage (quentin armitage org uk) ) * Mon Sep 03 2007 Adam Tkac 32:9.5.0-11.2.a6- temporary revert ISC 2119 change and add \"libbind-errno\" patch (#254501) again * Thu Aug 23 2007 Adam Tkac 32:9.5.0-11.1.a6- removed end dots from Summary sections (skasalAATTredhat.com)- fixed wrong file creation by autotools patch (skasalAATTredhat.com) * Thu Aug 23 2007 Adam Tkac 32:9.5.0-11.a6- start using --disable-isc-spnego configure option - remove bind-9.5-spnego-memory_management.patch (source isn\'t compiled) * Wed Aug 22 2007 Adam Tkac 32:9.5.0-10.2.a6- added new initscript option KEYTAB_FILE which specified where is located kerberos .keytab file for named service- obsolete temporary bind-9.5-spnego-memory_management.patch by bind-9.5-gssapictx-free.patch which conforms BIND coding standards (#251853) * Tue Aug 21 2007 Adam Tkac 32:9.5.0-10.a6- dropped direct dependency to /etc/openldap/schema directory- changed hardcoded paths to macros- fired away code which configure LDAP server * Tue Aug 14 2007 Adam Tkac 32:9.5.0-9.1.a6- named could crash with SRV record UPDATE (#251336) * Mon Aug 13 2007 Adam Tkac 32:9.5.0-9.a6- disable 64bit dlz driver patch on alpha and ia64 (#251298)- remove wrong malloc functions from lib/dns/spnego.c (#251853) * Mon Aug 06 2007 Adam Tkac 32:9.5.0-8.2.a6- changed licence from BSD-like to ISC * Tue Jul 31 2007 Adam Tkac 32:9.5.0-8.1.a6- disabled named on all runlevels by default * Mon Jul 30 2007 Adam Tkac 32:9.5.0-8.a6- minor next improvements on autotools patch- dig and host utilities now using libidn instead idnkit for IDN support * Wed Jul 25 2007 Warren Togami 32:9.5.0-7.a6- binutils/gcc bug rebuild (#249435) * Tue Jul 24 2007 Adam Tkac 32:9.5.0-6.a6- updated to 9.5.0a6 which contains fixes for CVE-2007-2925 and CVE-2007-2926- fixed building on 64bits * Mon Jul 23 2007 Adam Tkac 31:9.5.0a5-5- integrated \"autotools\" patch for testing purposes (upstream will accept it in future, for easier building) * Mon Jul 23 2007 Adam Tkac 31:9.5.0a5-4.1- fixed DLZ drivers building on 64bit systems * Fri Jul 20 2007 Adam Tkac 31:9.5.0a5-4- fixed relation between logrotated and chroot-ed named * Wed Jul 18 2007 Adam Tkac 31:9.5.0a5-3.9- removed bind-sdb package (default named has compiled SDB backend now)- integrated DLZ (Dynamically loadable zones) drivers- integrated GSS-TSIG support (RFC 3645)- build with -O0 (many new features, potential core dumps will be more useful) * Tue Jul 17 2007 Adam Tkac 31:9.5.0a5-3.2- initscript should be ready for parallel booting (#246878) * Tue Jul 17 2007 Adam Tkac 31:9.5.0a5-3- handle integer overflow in isc_time_secondsastimet function gracefully (#247856) * Mon Jul 16 2007 Adam Tkac 31:9.5.0a5-2.2- moved chroot configfiles into chroot subpackage (#248306) * Mon Jul 02 2007 Adam Tkac 31:9.5.0a5-2- minor changes in default configuration- fix h_errno assigment during resolver initialization (unbounded recursion, #245857)- removed wrong patch to #150288 * Tue Jun 19 2007 Adam Tkac 31:9.5.0a5-1- updated to latest upstream * Wed Jun 13 2007 Adam Tkac 31:9.4.1-7- marked caching-nameserver as obsolete (#244604)- fixed typo in initscript (causes that named doesn\'t detect NetworkManager correctly)- next cleanup in configuration - moved configfiles into config.tar- removed delay between start & stop in restart function in named.init * Tue Jun 12 2007 Adam Tkac 31:9.4.1-6- major changes in initscript. Could be LSB compatible now- removed caching-nameserver subpackage. Move configs from this package to main bind package as default configuration and major configuration cleanup * Mon Jun 04 2007 Adam Tkac 31:9.4.1-5- very minor compatibility change in bind-chroot-admin (line 215)- enabled IDN support by default and don\'t distribute IDN libraries- specfile cleanup- add dynamic directory to /var/named. This directory will be primarily used for dynamic DNS zones. ENABLE_ZONE_WRITE and SELinux\'s named_write_master_zones no longer exist * Thu May 24 2007 Adam Tkac 31:9.4.1-4- removed ldap-api patch and start using deprecated API- fixed minor problem in bind-chroot-admin script (#241103) * Tue May 22 2007 Adam Tkac 31:9.4.1-3- fixed bind-chroot-admin dynamic DNS handling (#239149)- updated zone-freeze patch to latest upstream- ldap sdb has been rewriten to latest api (#239802) * Mon May 07 2007 Adam Tkac 31:9.4.1-2.fc7- test build on new build system * Wed May 02 2007 Adam Tkac 31:9.4.1-1.fc7- updated to 9.4.1 which contains fix to CVE-2007-2241 * Fri Apr 27 2007 Adam Tkac 31:9.4.0-8.fc7- improved \"zone freeze patch\" - if multiple zone with same name exists no zone is freezed- minor cleanup in caching-nameserver\'s config file- fixed race-condition in dbus code (#235809)- added forgotten restorecon statement in bind-chroot-admin * Tue Apr 17 2007 Adam Tkac 31:9.4.0-7.fc7- removed DEBUGINFO option because with this option (default) was bind builded with -O0 and without this flag no debuginfo package was produced. (I want faster bind => -O2 + debuginfo)- fixed zone finding (#236426) * Mon Apr 16 2007 Adam Tkac 31:9.4.0-6.fc7- added idn support (still under development with upstream, disabled by default) * Wed Apr 11 2007 Adam Tkac 31:9.4.0-5.fc7- dnssec-signzone utility now doesn\'t ignore -d parameter * Tue Apr 10 2007 Adam Tkac 31:9.4.0-4.fc7- removed query-source[-v6] options from caching-nameserver config (#209954, increase security)- throw away idn. It won\'t be ready in fc7 * Tue Mar 13 2007 Adam Tkac 31:9.4.0-3.fc7- prepared bind to merge review- added experimental idn support to bind-utils utils (not enabled by default yet)- change chroot policy in caching-nameserver post section- fixed bug in bind-chroot-admin - rootdir function is called properly now | |