Changelog for
bind-libs-9.11.4-26.P2.el7_9.5.x86_64.rpm :
* Tue Apr 27 2021 Petr Menšík
- 32:9.11.4-26.P2.5- Possible assertion failure on DNAME processing (CVE-2021-25215)
* Mon Feb 15 2021 Petr Menšík - 32:9.11.4-26.P2.4- Fix off-by-one bug in ISC SPNEGO implementation (CVE-2020-8625)
* Fri Nov 06 2020 Tomas Korbar - 32:9.11.4-26.P2.3- Fix inline re-signing (#rh1889902)
* Fri Oct 02 2020 Tomas Korbar - 32:9.11.4-26.P2.2- Fix unsupported algorithms validation (#rh1769876)
* Wed Aug 26 2020 Petr Menšík - 32:9.11.4-26.P2.1- Fix tsig-request verify (CVE-2020-8622)- Prevent PKCS11 daemon crash on crafted packet (CVE-2020-8623)- Correct update-policy type subdomain to match documentation (CVE-2020-8624)
* Fri May 29 2020 Artem Egorenkov - 32:9.11.4-26.P2- Fix EDNS512 loops on broken servers
* Tue May 26 2020 Artem Egorenkov - 32:9.11.4-25.P2- rebinding protection for forwarding DNS server upstream patch (#1832812)
* Fri May 22 2020 Petr Menšík - 32:9.11.4-24.P2- Add CVE tests to codebase
* Mon May 18 2020 Petr Menšík - 32:9.11.4-23.P2- Limit number of queries triggered by a request (CVE-2020-8616)- Fix invalid tsig request (CVE-2020-8617)
* Wed Mar 18 2020 Petr Menšík - 32:9.11.4-22.P2- Solve often priming queries on some forwarder (#1756201)
* Mon Mar 16 2020 Petr Menšík - 32:9.11.4-21.P2- Disable atomic operations also on ppc (#1779589)
* Fri Mar 13 2020 Petr Menšík - 32:9.11.4-20.P2- Do not crash when nsupdate with GSS terminated early (#1300636)
* Wed Mar 11 2020 Petr Menšík - 32:9.11.4-19.P2- Allow conflicting zone files with a warning (#1744081)
* Wed Mar 04 2020 Miroslav Lichvar - 32:9.11.4-18.P2- Disable atomic operations on ppc64, ppc64le, aarch64 (#1779589)
* Fri Feb 21 2020 Tomas Korbar - 32:9.11.4-17.P2- Prevent deadlock on reload (#1781576)- Disable unit test timer_test on ppc64le because of its instability
* Thu Dec 12 2019 Petr Menšík - 32:9.11.4-16.P2- Finish dig query when name is too long (#1743572)
* Wed Nov 27 2019 Petr Menšík - 32:9.11.4-15.P2- Stop listening on IPv6 by default (#1753259)
* Tue Nov 19 2019 Petr Menšík - 32:9.11.4-14.P2- Limit number of queries per TCP connection (CVE-2019-6477)
* Wed Oct 02 2019 Petr Menšík - 32:9.11.4-13.P2- Revert not searching names with dot (#1743572)
* Thu Sep 05 2019 Petr Menšík - 32:9.11.4-12.P2- Fix mkeys test validating CVE-2018-5745 fix
* Tue Aug 06 2019 Pavel Zhukov - 32:9.11.4-11.P2- Use monotonic time in export library (#1093803)
* Wed Jul 17 2019 Petr Menšík - 32:9.11.4-10.P2- Fix CVE-2018-5745- Fix CVE-2019-6465
* Wed Jun 19 2019 Petr Menšík - 32:9.11.4-9.P2- Fix CVE-2019-6471
* Wed Jun 12 2019 Petr Menšík - 32:9.11.4-8.P2- Fix scriptlet errors when selinux-policy is not installed (#1647659)
* Wed Apr 24 2019 Petr Menšík - 32:9.11.4-7.P2- Fix inefective limit of TCP clients (CVE-2018-5743)
* Wed Mar 27 2019 Petr Menšík - 32:9.11.4-6.P2- Use /sbin/nologin again (#1676661)
* Mon Mar 18 2019 Petr Menšík - 32:9.11.4-5.P2- Make sure selinux-policy is installed soon enough (#1647659)
* Mon Mar 18 2019 Petr Menšík - 32:9.11.4-4.P2- Disable custom random generator for export libs (#1685940)
* Tue Mar 12 2019 Petr Menšík - 32:9.11.4-3.P2- Fix memory handling in zone2ldap tool
* Thu Feb 28 2019 Petr Menšík - 32:9.11.4-2.P2- Move dnssec utilities back to bind package- Remove separate python-bind package
* Tue Jan 29 2019 Petr Menšík - 32:9.11.4-1.P2- Rebase features patches- Disable autodetected eddsa algorithm ED448- Add versioned depends to all library subpackages- Fix multilib conflict of devel packages
* Fri Nov 23 2018 Petr Menšík - 32:9.9.4-73- Fixes debug level comments (#1647539)
* Thu Sep 20 2018 Petr Menšík - 32:9.9.4-72- Fix automatic selinux boolean named_write_master_zones (#1569466)- Allow starting named with readonly home again
* Wed Aug 08 2018 Petr Menšík - 32:9.9.4-71- Fix CVE-2018-5740
* Sun Jun 24 2018 Petr Menšík - 32:9.9.4-70- Fix compiler warnings
* Thu Jun 21 2018 Petr Menšík - 32:9.9.4-69- Refetch always records with TTL 0 (#1549130)
* Thu Jun 21 2018 Petr Menšík - 32:9.9.4-68- Detect and disable MD5 functions in FIPS 140-2 mode (#1519306)
* Thu Jun 14 2018 Petr Menšík - 32:9.9.4-67- Move change of dns_view_t to the end (#1452091)
* Fri Jun 01 2018 Petr Menšík - 32:9.9.4-66- Correct recursing file name (#1435883)- Use python binary again, install all modules (#1510008)
* Thu May 31 2018 Petr Menšík - 32:9.9.4-65- Add rndc secroots and recursing output files into data (#1435883)
* Mon May 28 2018 Petr Menšík - 32:9.9.4-64- Backported negative trust anchors (#1452091)
* Mon May 28 2018 Petr Menšík - 32:9.9.4-63- Make named home writeable (#1569466)- Change named shell to /bin/false
* Tue May 22 2018 Martin Sehnoutka - 32:9.9.4-62- Resolves: #1510008 - add support for dnssec-keymgr
* Tue Jan 16 2018 Petr Menšík - 32:9.9.4-61- Fix CVE-2017-3145
* Tue Dec 05 2017 Petr Menšík - 32:9.9.4-60- Fix regression caused by bug #1470637
* Mon Nov 13 2017 Petr Menšík - 32:9.9.4-59- Support for additional signing algorithms in rndc (#1501531)- New autogenerated rndc keys will use hmac-sha256 algorithm
* Tue Oct 31 2017 Petr Menšík - 32:9.9.4-58- Fix multilib regression in headers
* Mon Oct 30 2017 Petr Menšík - 32:9.9.4-57- Add with-tunning=large support (#rh1464850)
* Thu Oct 19 2017 Petr Menšík - 32:9.9.4-56- Fix named-chroot restart leak (#1503646)
* Thu Oct 12 2017 Petr Menšík - 32:9.9.4-55- Handle dig timeouts the same way as upstream (#1470637)
* Wed Oct 11 2017 Petr Menšík - 32:9.9.4-54- Do not use next search domain on timeout from dig (#1470637)
* Tue Aug 01 2017 Petr Menšík - 32:9.9.4-53- Fixed TSIG validation of AXFR and IXFR (#1476013)
* Fri Jul 07 2017 Petr Menšík - 32:9.9.4-52- Add missing manual for dnssec-importkey (#1472862)
* Thu Jun 29 2017 Petr Menšík - 32:9.9.4-51- Fix CVE-2017-3142 and CVE-2017-3143
* Mon May 22 2017 Petr Menšík - 32:9.9.4-50- Update root servers and trust anchor (#1452635)
* Thu Apr 20 2017 Petr Menšík - 32:9.9.4-49- Address deadlock between view.c and adb.c (#1416304)
* Tue Apr 11 2017 Petr Menšík - 32:9.9.4-48- Fix CVE-2017-3136 (ISC change 4575)- Fix CVE-2017-3137 (ISC change 4578)
* Wed Mar 29 2017 Petr Menšík - 32:9.9.4-47- Simplify change of used config file, point to KB article (#1271315)
* Tue Mar 28 2017 Petr Menšík - 32:9.9.4-46- Make comment how to use different config file (#1271315)
* Thu Mar 16 2017 Petr Menšík - 32:9.9.4-45- Install again dns/dlz.h skipped in rebase- Fixed coverity warnings on reenabled test dlzexternal
* Tue Mar 14 2017 Petr Menšík - 32:9.9.4-44- Backported new upstream dyndb interface, removed dynamic_db (#1393886)
* Mon Feb 27 2017 Petr Menšík - 32:9.9.4-43- Do not warn on WKS patch (#1392362)
* Tue Feb 21 2017 Petr Menšík - 32:9.9.4-42- Support WKS records in chroot
* Wed Feb 08 2017 Petr Menšík - 32:9.9.4-41- Fix CVE-2017-3135 (ISC change 4557)- Fix and test caching CNAME before DNAME (ISC change 4558)
* Fri Jan 20 2017 Petr Menšík - 32:9.9.4-40- Fix possible infinite loop in start_lookup (CVE-2016-2775)- Do not change lib permissions in chroot (#1392531)
* Mon Jan 09 2017 Petr Menšík - 32:9.9.4-39- Fix CVE-2016-9131 (ISC change 4508)- Fix CVE-2016-9147 (ISC change 4510)- Fix regression introduced by CVE-2016-8864 (ISC change 4530)- Fix CVE-2016-9444 (ISC change 4517)
* Mon Oct 31 2016 Tomas Hozza - 32:9.9.4-38- Fix CVE-2016-8864
* Fri Sep 23 2016 Tomas Hozza - 32:9.9.4-37- Fix CVE-2016-2776
* Wed May 11 2016 Tomas Hozza - 32:9.9.4-36- Added automatic interface scan functionality (#1294506)- Removed NetworkManager dispatcher script since it is not needed any more (#1294506)
* Wed Apr 13 2016 Tomas Hozza - 32:9.9.4-35- Added GeoIP support (#1220594)
* Fri Apr 01 2016 Tomas Hozza - 32:9.9.4-34- Added support for CAA records (#1306610)- Use HTTPS URL instead of FTP for upstream sources (#1319280)
* Tue Mar 22 2016 Tomas Hozza - 32:9.9.4-33- Fix excessive queries caused by DS chasing with stub zones when DNSSEC is not used (#1291185)- Fix error in internal test suite (#1259514)- Fix named-checkconf call in
*-chroot.service files (#1278082)- Fix incorrect path in BIND sample configuration and added comment to default configuration (#1247502)
* Tue Mar 08 2016 Tomas Hozza - 32:9.9.4-32- Fix CVE-2016-1285 and CVE-2016-1286
* Mon Jan 18 2016 Tomas Hozza - 32:9.9.4-31- Fix CVE-2015-8704
* Mon Dec 14 2015 Tomas Hozza - 32:9.9.4-30- Fix CVE-2015-8000
* Wed Sep 02 2015 Tomas Hozza - 32:9.9.4-29- Fix CVE-2015-5722
* Wed Aug 05 2015 Tomas Hozza - 32:9.9.4-28- Increase ISC_SOCKET_MAXEVENTS to 2048 (#1235609)
* Tue Jul 28 2015 Tomas Hozza - 32:9.9.4-27- Fix CVE-2015-5477
* Wed Jul 08 2015 Tomas Hozza - 32:9.9.4-26- Fix CVE-2015-4620
* Tue Jul 07 2015 Tomas Hozza - 32:9.9.4-25- Fixed nsupdate realm auto-detection (#1214827)
* Mon Jun 29 2015 Tomas Hozza - 32:9.9.4-24- Reintroduce the DISABLE_ZONE_CHECKING into /etc/sysconfig/named (#1236475)
* Mon Jun 01 2015 Tomas Hozza - 32:9.9.4-23- Don\'t copy /etc/localtime on -chroot package installation (#1186773)- Fix SPF resource records check to comply with RFC7208 (#1215164)- Don\'t use ISC\'s DLV by default (#1223336)
* Fri May 22 2015 Tomas Hozza - 32:9.9.4-22- Add version specific requires on bind for bind-pkcs11 (Related: #1097753)- Resolve issues found by static analysis (Related: #1097753)
* Thu May 21 2015 Tomas Hozza - 32:9.9.4-21- Added native PKCS#11 functionality (#1097753)
* Wed May 20 2015 Tomas Hozza - 32:9.9.4-20- DNS resolution failure in high load environment with SERVFAIL and \"out of memory/success\" in the log (#1221180)
* Thu May 14 2015 Tomas Hozza - 32:9.9.4-19- Install config for tmpfiles under %{_tmpfilesdir} (#1180976)- Fixed systemctl path in logrotate configuration (#1164264)- remove information about system-config-bind from named.8 man page (#1152066)
* Mon Mar 02 2015 Tomas Hozza - 32:9.9.4-18.1- Fix CVE-2015-1349
* Wed Dec 10 2014 Tomas Hozza - 32:9.9.4-18- Fix CVE-2014-8500 (#1171976)
* Thu Sep 18 2014 Tomas Hozza - 32:9.9.4-17- Fix error in dyndb API that can cause named to freeze on shutdown (#1142150)- Fix error in triggerun scriptlet (#1143033)- Remove /var/named/chroot/var/run on bind-chroot update if it is a directory (#1091341)
* Thu Aug 21 2014 Tomas Hozza - 32:9.9.4-16- Add versioned requires on bind-libs to bind-utils and bind-sdb
* Wed Aug 20 2014 Tomas Hozza - 32:9.9.4-15- Use /dev/urandom when generating rndc.key file (#1107568)- Allow authentication using TSIG in allow-notify configuration statement (#1067424)- Fix race condition when destroying a resolver fetch object (#1072379)- Increase defaults for lwresd workers and make workers and client objects number configurable (#1098959)- Configure BIND with --with-dlopen=yes to support dynamically loadable DLZ drivers (#1096688)
* Fri Jan 24 2014 Daniel Mach - 32:9.9.4-14- Mass rebuild 2014-01-24
* Wed Jan 15 2014 Honza Horak - 32:9.9.4-13- Rebuild for mariadb-libs Related: #1045013
* Tue Jan 14 2014 Tomas Hozza 32:9.9.4-12- Fix CVE-2014-0591
* Mon Jan 06 2014 Tomas Hozza 32:9.9.4-11- Build against libdb instead of libdb4 (#1044990)
* Fri Dec 27 2013 Daniel Mach - 32:9.9.4-10- Mass rebuild 2013-12-27
* Wed Dec 18 2013 Tomas Hozza 32:9.9.4-9- Fix crash in rbtdb after two sucessive getoriginnode() calls (#1044026)
* Tue Dec 17 2013 Tomas Hozza 32:9.9.4-8- Split chroot package for named and named-sdb- Extract setting-up/destroying of chroot to a separate systemd service (#1004300)
* Thu Dec 05 2013 Tomas Hozza 32:9.9.4-7- Create symlink /var/named/chroot/var/run -> /var/named/chroot/run (#1024384)- Added session-keyfile statement into default named.conf since we use /run/named (#1024384)
* Thu Nov 28 2013 Tomas Hozza 32:9.9.4-6- Fixed memory leak in nsupdate if \'realm\' was used multiple times (#1034824)
* Tue Nov 12 2013 Tomas Hozza 32:9.9.4-5- Install configuration for rwtab and fix chroot setup script (#1028189)- use --enable-filter-aaaa when building bind to enable filter-aaaa-on-v4 option (#1025245)
* Thu Oct 31 2013 Tomas Hozza 32:9.9.4-4- Correct the patch for #1020683
* Tue Oct 29 2013 Tomas Hozza 32:9.9.4-3- Fix race condition on send buffers in dighost.c (#1020683)
* Tue Oct 08 2013 Tomas Hozza 32:9.9.4-2- install isc/errno2result.h header (#1015165)
* Mon Sep 23 2013 Tomas Hozza 32:9.9.4-1- update to 9.9.4 (#1010200)- drop merged patches- modify patches to fit on new version
* Tue Sep 10 2013 Tomas Hozza 32:9.9.3-8.P2- Fix [ISC-Bugs #34738] dns_journal_open() returns a pointer to stack
* Fri Aug 16 2013 Tomas Hozza 32:9.9.3-7.P2- Don\'t generate rndc.key if there exists rndc.conf
* Fri Aug 16 2013 Tomas Hozza 32:9.9.3-6.P2- don\'t install named-sdb.service if SDB macro is defined to zero
* Sun Jul 28 2013 Tomas Hozza 32:9.9.3-5.P2- update to 9.9.3-P2 (fix for CVE-2013-4854)- update RRL patch to 9.9.3-P2-rl.13207.22- Fix script for setting up chroot so it unmounts everything successfully
* Wed Jul 10 2013 Tomas Hozza 32:9.9.3-4.P1- Fix dates in Changelog
* Wed Jun 05 2013 Tomas Hozza 32:9.9.3-3.P1- update to 9.9.3-P1 (fix for CVE-2013-3919)- update RRL patch to 9.9.3-P1-rl.156.01
* Mon Jun 03 2013 Tomas Hozza 32:9.9.3-2- bump release to prevent update path issues
* Mon Jun 03 2013 Tomas Hozza 32:9.9.3-1- update to 9.9.3- install dns/update.h header- update RRL patch to the latest version 9.9.3-rl.150.20
* Fri May 17 2013 Tomas Hozza 32:9.9.3-0.7.rc2- Fix segfault in host/nslookup (#878139)
* Mon May 13 2013 Tomas Hozza 32:9.9.3-0.6.rc2- update to 9.9.3rc2- part of bind97-exportlib.patch not needed any more- bind-9.9.1-P2-multlib-conflict.patch modified to reflect latest source- rl-9.9.3rc1.patch -> rl-9.9.3rc2.patch- bind99-opts.patch merged
* Fri May 03 2013 Tomas Hozza 32:9.9.3-0.5.rc1- Include recursion Warning in named.conf and named.conf.sample (#740894)- Include managed-keys-directory statement in named.conf.sample (#948026)
* Thu May 02 2013 Tomas Hozza 32:9.9.3-0.4.rc1- Fix zone2sqlite to quote table names when creating/dropping/inserting (#919417)
* Fri Apr 19 2013 Adam Tkac 32:9.9.3-0.3.rc1- fix crash in nsupdate when processing \"-r\" parameter (#949544)
* Tue Apr 16 2013 Adam Tkac 32:9.9.3-0.2.rc1- ship dns/rrl.h in -devel subpkg
* Tue Apr 16 2013 Adam Tkac 32:9.9.3-0.1.rc1- update to 9.9.3rc1- bind-96-libtool2.patch has been merged- fix bind tmpfiles.d for named.pid /run migration (#920713)
* Wed Mar 27 2013 Tomas Hozza 32:9.9.2-12.P2- New upstream patch version fixing CVE-2013-2266 (#928032)
* Tue Mar 19 2013 Adam Tkac 32:9.9.2-11.P1- move pidfile to /run/named/named.pid
* Wed Mar 06 2013 Tomas Hozza 32:9.9.2-10.P1- Fix Makefile.in to include header added by rate limiting patch (#918330)
* Tue Mar 05 2013 Adam Tkac 32:9.9.2-9.P1- drop some developer-only documentation and move ARM to %docdir
* Mon Feb 18 2013 Adam Tkac 32:9.9.2-8.P1- include rate limiting patch
* Tue Jan 29 2013 Tomas Hozza 32:9.9.2-7.P1- Corrected IP addresses in named.ca (#901741)- mount/umount /var/named in setup-named-chroot.sh as the last one (#904666)
* Thu Dec 20 2012 Adam Tkac 32:9.9.2-6.P1- generate /etc/rndc.key during named service startup if doesn\'t exist- increase startup timeout in systemd units to 90sec (default)- fix IDN related statement in dig.1 manpage
* Wed Dec 05 2012 Tomas Hozza 32:9.9.2-5.P1- update to bind-9.9.2-P1
* Mon Nov 12 2012 Adam Tkac 32:9.9.2-4- document dig exit codes in manpage- ignore empty \"search\" options in resolv.conf
* Mon Nov 12 2012 Adam Tkac 32:9.9.2-3- drop PKCS11 support on rhel
* Thu Oct 11 2012 Adam Tkac 32:9.9.2-2- install isc/stat.h
* Thu Oct 11 2012 Adam Tkac 32:9.9.2-1- update to 9.9.2- bind97-rh714049.patch has been dropped- patches merged - bind98-rh816164.patch
* Thu Sep 13 2012 Adam Tkac 32:9.9.1-10.P3- update to bind-9.9.1-P3
* Wed Aug 22 2012 Tomas Hozza 32:9.9.1-9.P2- fixed SPEC file so it comply with new systemd-rpm macros guidelines (#850045)- changed %define macros to %global and fixed several rpmlint warnings
* Wed Aug 08 2012 Tomas Hozza 32:9.9.1-8.P2- Changed PrivateTmp to \"false\" in
*-chroot.service unit files (#825869)
* Wed Aug 01 2012 Tomas Hozza 32:9.9.1-7.P2- Fixed bind-devel multilib conflict (#478718)
* Mon Jul 30 2012 Tomas Hozza 32:9.9.1-6.P2- Fixed bad path to systemctl in /etc/NetworkManager/dispatcher.d/13-named (#844047)- Fixed path to libdb.so in config.dlz.in
* Thu Jul 26 2012 Adam Tkac 32:9.9.1-5.P2- update to 9.9.1-P2
* Wed Jul 18 2012 Fedora Release Engineering - 32:9.9.1-4.P1- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
* Wed Jul 11 2012 Ville Skyttä - 32:9.9.1-3.P1- Avoid shell invocation and dep for -libs-lite %postun.
* Mon Jun 04 2012 Adam Tkac 32:9.9.1-2.P1- update to 9.9.1-P1 (CVE-2012-1667)
* Thu May 24 2012 Adam Tkac 32:9.9.1-1- update to 9.9.1- bind99-coverity.patch merged- bind-9.5-overflow.patch merged
* Mon May 07 2012 Adam Tkac 32:9.9.0-6- nslookup: return non-zero exit code when fail to get answer (#816164)
* Thu Apr 26 2012 Adam Tkac 32:9.9.0-5- initscript: don\'t umount /var/named when didn\'t mount it
* Tue Apr 24 2012 Adam Tkac 32:9.9.0-4- apply all non-SDB patches before SDB ones (#804475)- enable Berkeley DB DLZ backend (#804478)
* Thu Apr 12 2012 Adam Tkac 32:9.9.0-3- bind97-rh699951.patch is no longer needed (different fix is in 9.9.0)
* Mon Mar 26 2012 Adam Tkac 32:9.9.0-2- remove unneeded bind99-v6only.patch
* Mon Mar 05 2012 Adam Tkac 32:9.9.0-1- update to 9.9.0- load dynamic DBs later (and update dyndb patch)- fix memory leak in named during processing of rndc command- don\'t call `rndc-confgen -a` in \"post\" section- fix some packaging bugs in bind-chroot
* Wed Feb 15 2012 Adam Tkac 32:9.9.0-0.8.rc2- build with \"--enable-fixed-rrset\"
* Wed Feb 01 2012 Adam Tkac 32:9.9.0-0.7.rc2- update to 9.9.0rc2- doc/rfc and doc/draft are no longer shipped in tarball
* Mon Jan 30 2012 Adam Tkac 32:9.9.0-0.6.rc1- retire initscript in favour of systemd unit files (#719419)
* Thu Jan 12 2012 Adam Tkac 32:9.9.0-0.5.rc1- update to 9.9.0rc1
* Wed Dec 07 2011 Adam Tkac 32:9.9.0-0.4.b2- ship dns/forward.h in -devel subpkg
* Tue Nov 22 2011 Adam Tkac 32:9.9.0-0.3.b2- update to 9.9.0b2 (CVE-2011-4313)- patches merged - bind97-rh700097.patch - bind99-cinfo.patch
* Mon Nov 14 2011 Adam Tkac 32:9.9.0-0.2.b1- ship dns/clientinfo.h in bind-devel
* Fri Nov 11 2011 Adam Tkac 32:9.9.0-0.1.b1- update to 9.9.0b1- bind98-dlz_buildfix.patch merged
* Fri Oct 28 2011 Adam Tkac 32:9.8.1-4- nslookup failed to resolve name in certain cases
* Mon Sep 26 2011 Adam Tkac 32:9.8.1-3- remove deps filter, it is no longer needed (#739663)
* Fri Sep 09 2011 Adam Tkac 32:9.8.1-2- fix logrotate config file (#725256)
* Wed Sep 07 2011 Adam Tkac 32:9.8.1-1- update to 9.8.1- ship /etc/trusted-key.key (needed by dig)- use select instead of epoll in export libs (#735103)
* Wed Aug 31 2011 Adam Tkac 32:9.8.1-0.3.rc1- fix DLZ related compilation issues- make /etc/named.{root,iscdlv}.key world-readable- add bind-libs versioned requires to bind pkg
* Wed Aug 31 2011 Adam Tkac 32:9.8.1-0.2.rc1- fix rare race condition in request.c- print \"the working directory is not writable\" as debug message- re-add configtest target to initscript- initscript: sybsys name is always named, not named-sdb- nsupdate returned zero when target zone didn\'t exist (#700097)- nsupdate could have failed if server has multiple IPs and the first was unreachable (#714049)
* Wed Aug 31 2011 Adam Tkac 32:9.8.1-0.1.rc1- update to 9.8.1rc1- patches merged - bind97-rh674334.patch - bind97-cleanup.patch - bind98-includes.patch
* Wed Aug 03 2011 Adam Tkac 32:9.8.0-9.P4- improve patch for #725741
* Tue Jul 26 2011 Adam Tkac 32:9.8.0-8.P4- named could have crashed during reload when dyndb module is used (#725741)
* Tue Jul 05 2011 Adam Tkac 32:9.8.0-7.P4- update to 9.8.0-P4 - bind98-libdns-export.patch merged
* Thu Jun 02 2011 Adam Tkac 32:9.8.0-6.P2- update the dyndb patch
* Fri May 27 2011 Adam Tkac 32:9.8.0-5.P2- fix compilation of libdns-export.so
* Fri May 27 2011 Adam Tkac 32:9.8.0-4.P2- update to 9.8.0-P2 (CVE-2011-1910)
* Fri May 06 2011 Adam Tkac 32:9.8.0-3.P1- update to 9.8.0-P1 (CVE-2011-1907)
* Wed Mar 23 2011 Dan Horák - 32:9.8.0-2- rebuilt for mysql 5.5.10 (soname bump in libmysqlclient)
* Thu Mar 03 2011 Adam Tkac 32:9.8.0-1- update to 9.8.0- bind97-rh665971.patch merged
* Thu Mar 03 2011 Adam Tkac 32:9.8.0-0.4.rc1- revert previous change (integration with libnmserver)
* Tue Feb 22 2011 Adam Tkac 32:9.8.0-0.3.rc1- integrate named with libnmserver library
* Tue Feb 22 2011 Adam Tkac 32:9.8.0-0.2.rc1- include dns/rpz.h in -devel subpkg
* Mon Feb 21 2011 Adam Tkac 32:9.8.0-0.1.rc1- update to 9.8.0rc1
* Fri Feb 18 2011 Adam Tkac 32:9.7.3-1- update to 9.7.3- fix dig +trace on dualstack systems (#674334)- fix linkage order when building on system with older BIND (#665971)- reduce number of gcc warnings
* Mon Feb 07 2011 Fedora Release Engineering - 32:9.7.3-0.6.rc1- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Jan 25 2011 Adam Tkac 32:9.7.3-0.5.rc1- update to 9.7.3rc1 - bind97-krb5-self.patch merged
* Wed Jan 12 2011 Adam Tkac 32:9.7.3-0.4.b1- fix typo in initscript
* Thu Jan 06 2011 Adam Tkac 32:9.7.3-0.3.b1- fix \"service named status\" when used with named-sdb- don\'t check MD5, size and mtime of sysconfig/named
* Wed Jan 05 2011 Adam Tkac 32:9.7.3-0.2.b1- add new option DISABLE_ZONE_CHECKING to sysconfig/named
* Wed Jan 05 2011 Adam Tkac 32:9.7.3-0.1.b1- update to 9.7.3b1
* Wed Jan 05 2011 Adam Tkac 32:9.7.2-10.P3- initscript should terminate only the correct \"named\" process (#622785)
* Mon Dec 20 2010 Adam Tkac 32:9.7.2-9.P3- fix \"krb5-self\" update-policy rule processing
* Thu Dec 02 2010 Adam Tkac 32:9.7.2-8.P3- update to 9.7.2-P3
* Mon Nov 29 2010 Jan Görig 32:9.7.2-7.P2- added tmpfiles.d support (#656550)- removed old PID checking in initscript
* Mon Nov 08 2010 Adam Tkac 32:9.7.2-6.P2- don\'t emit various informational messages by default (#645544)
* Wed Oct 20 2010 Adam Tkac 32:9.7.2-5.P2- move BIND9 internal libs back to %{_libdir}- add \"-export\" suffix to public libraries (-lite subpkg)
* Thu Oct 07 2010 Adam Tkac 32:9.7.2-4.P2- ship -devel subpkg for internal libs, dnsperf needs it
* Thu Oct 07 2010 Adam Tkac 32:9.7.2-3.P2- new bind-libs-lite and bind-lite-devel subpkgs which contain public version of BIND 9 libraries- don\'t ship devel files for internal version of BIND 9 libraries
* Wed Sep 29 2010 Adam Tkac 32:9.7.2-2.P2- update to 9.7.2-P2
* Thu Sep 16 2010 Adam Tkac 32:9.7.2-1- update to 9.7.2
* Fri Aug 27 2010 Adam Tkac 32:9.7.2-0.3.rc1- update to 9.7.2rc1
* Tue Aug 10 2010 Adam Tkac 32:9.7.2-0.2.b1- host: handle \"debug\", \"attempts\" and \"timeout\" options in resolv.conf well
* Tue Aug 03 2010 Adam Tkac 32:9.7.2-0.1.b1- update to 9.7.2b1- patches merged - bind97-rh507429.patch
* Mon Jul 19 2010 Adam Tkac 32:9.7.1-5.P2- supply root zone DNSKEY in default configuration
* Mon Jul 19 2010 Adam Tkac 32:9.7.1-4.P2- update to 9.7.1-P2 (CVE-2010-0213)
* Mon Jul 12 2010 Adam Tkac 32:9.7.1-3.P1- remove outdated Copyright.caching-nameserver file- remove rfc1912.txt, it is already located in %doc/rfc directory- move COPYRIGHT to the bind-libs subpkg- add COPYRIGHT to the -pkcs11 subpkg
* Fri Jul 09 2010 Adam Tkac 32:9.7.1-2.P1- update to 9.7.1-P1
* Mon Jun 28 2010 Adam Tkac 32:9.7.1-1- update to 9.7.1- improve the \"dnssec-conf\" trigger
* Wed Jun 09 2010 Adam Tkac 32:9.7.1-0.2.rc1- update to 9.7.1rc1- patches merged - bind97-keysdir.patch
* Mon May 31 2010 Adam Tkac 32:9.7.1-0.1.b1- update to 9.7.1b1- make /var/named/dynamic as a default directory for managed DNSSEC keys- add patch to get \"managed-keys-directory\" option working- patches merged - bind97-managed-keyfile.patch - bind97-rh554316.patch
* Fri May 21 2010 Adam Tkac 32:9.7.0-11.P2- update dnssec-conf Obsoletes/Provides
* Thu May 20 2010 Adam Tkac 32:9.7.0-10.P2- update to 9.7.0-P2
* Fri Mar 26 2010 Adam Tkac 32:9.7.0-9.P1- added lost patch for #554316 (occasional crash in keytable.c)
* Fri Mar 26 2010 Adam Tkac 32:9.7.0-8.P1- active query might be destroyed in resume_dslookup() which triggered REQUIRE failure (#507429)
* Mon Mar 22 2010 Adam Tkac 32:9.7.0-7.P1- install SDB related manpages only when build with SDB
* Fri Mar 19 2010 Adam Tkac 32:9.7.0-6.P1- update to 9.7.0-P1
* Tue Mar 16 2010 Jan Görig 32:9.7.0-5- bind-sdb now requires bind
* Mon Mar 15 2010 Jan Görig 32:9.7.0-4- add man-pages ldap2zone.1 zonetodb.1 zone2sqlite.1 named-sdb.8 (#525655)
* Mon Mar 01 2010 Adam Tkac 32:9.7.0-3- fix multilib issue (#478718) [jgorig]
* Mon Mar 01 2010 Adam Tkac 32:9.7.0-2- improve automatic DNSSEC reconfiguration trigger- initscript now returns 2 in case that action doesn\'t exist (#523435)- enable/disable chroot when bind-chroot is installed/uninstalled
* Wed Feb 17 2010 Adam Tkac 32:9.7.0-1- update to 9.7.0 final
* Mon Feb 15 2010 Adam Tkac 32:9.7.0-0.14.rc2- obsolete dnssec-conf- automatically update configuration from old dnssec-conf based- improve default configuration; enable DLV by default- remove obsolete triggerpostun from bind-libs subpackage
* Thu Jan 28 2010 Adam Tkac 32:9.7.0-0.13.rc2- update to 9.7.0rc2
* Wed Jan 27 2010 Adam Tkac 32:9.7.0-0.12.rc1- initscript LSB related fixes (#523435)
* Wed Jan 27 2010 Adam Tkac 32:9.7.0-0.11.rc1- revert the \"DEBUG\" feature (#510283), it causes too many problems (#545128)
* Tue Dec 15 2009 Adam Tkac 32:9.7.0-0.10.rc1- update to 9.7.0rc1- bind97-headers.patch merged- update default configuration
* Tue Dec 01 2009 Adam Tkac 32:9.7.0-0.9.b3- update to 9.7.0b3
* Thu Nov 26 2009 Adam Tkac 32:9.7.0-0.8.b2- install isc/namespace.h header
* Fri Nov 06 2009 Adam Tkac 32:9.7.0-0.7.b2- update to 9.7.0b2
* Tue Nov 03 2009 Adam Tkac 32:9.7.0-0.6.b1- update to 9.7.0b1- add bind-pkcs11 subpackage to support PKCS11 compatible keystores for DNSSEC keys
* Thu Oct 08 2009 Adam Tkac 32:9.7.0-0.5.a3- don\'t package named-bootconf utility, it is very outdated and unneeded
* Mon Sep 21 2009 Adam Tkac 32:9.7.0-0.4.a3- determine file size via `stat` instead of `ls` (#523682)
* Wed Sep 16 2009 Adam Tkac 32:9.7.0-0.3.a3- update to 9.7.0a3
* Tue Sep 15 2009 Adam Tkac 32:9.7.0-0.2.a2- improve chroot related documentation (#507795)- add NetworkManager dispatcher script to reload named when network interface is activated/deactivated (#490275)- don\'t set/unset named_write_master_zones SELinux boolean every time in initscript, modify it only when it\'s actually needed
* Tue Sep 15 2009 Adam Tkac 32:9.7.0-0.1.a2- update to 9.7.0a2- merged patches - bind-96-db_unregister.patch - bind96-rh507469.patch
* Tue Sep 01 2009 Adam Tkac 32:9.6.1-9.P1- next attempt to fix the postun trigger (#520385)- remove obsolete bind-9.3.1rc1-fix_libbind_includedir.patch
* Fri Aug 21 2009 Tomas Mraz - 32:9.6.1-8.P1- rebuilt with new openssl
* Tue Aug 04 2009 Martin Nagy 32:9.6.1-7.P1- update the patch for dynamic loading of database backends
* Wed Jul 29 2009 Adam Tkac 32:9.6.1-6.P1- 9.6.1-P1 release (CVE-2009-0696)- fix postun trigger (#513016, hopefully)
* Fri Jul 24 2009 Fedora Release Engineering - 32:9.6.1-5- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
* Mon Jul 20 2009 Adam Tkac 32:9.6.1-4- remove useless bind-9.3.3rc2-rndckey.patch
* Mon Jul 13 2009 Adam Tkac 32:9.6.1-3- fix broken symlinks in bind-libs (#509635)- fix typos in /etc/sysconfig/named (#509650)- add DEBUG option to /etc/sysconfig/named (#510283)
* Wed Jun 24 2009 Adam Tkac 32:9.6.1-2- improved \"chroot automount\" patches (#504596)- host should fail if specified server doesn\'t respond (#507469)
* Wed Jun 17 2009 Adam Tkac 32:9.6.1-1- 9.6.1 release- simplify chroot maintenance. Important files and directories are mounted into chroot (see /etc/sysconfig/named for more info, #504596)- fix doc/named.conf.default perms
* Wed May 27 2009 Adam Tkac 32:9.6.1-0.4.rc1- 9.6.1rc1 release
* Wed Apr 29 2009 Martin Nagy 32:9.6.1-0.3.b1- update the patch for dynamic loading of database backends- create %{_libdir}/bind directory- copy default named.conf to doc directory, shared with s-c-bind (atkac)
* Fri Apr 24 2009 Martin Nagy 32:9.6.1-0.2.b1- update the patch for dynamic loading of database backends- fix dns_db_unregister()- useradd now takes \"-N\" instead of \"-n\" (atkac, #495726)- print nicer error msg when zone file is actually a directory (atkac, #490837)
* Mon Mar 30 2009 Adam Tkac 32:9.6.1-0.1.b1- 9.6.1b1 release- patches merged - bind-96-isc_header.patch - bind-95-rh469440.patch - bind-96-realloc.patch - bind9-fedora-0001.diff- use -version-number instead of -version-info libtool param
* Mon Mar 23 2009 Adam Tkac 32:9.6.0-11.1.P1- logrotate configuration file now points to /var/named/data/named.run by default (#489986)
* Tue Mar 17 2009 Adam Tkac 32:9.6.0-11.P1- fall back to insecure mode when no supported DNSSEC algorithm is found instead of SERVFAIL- don\'t fall back to non-EDNS0 queries when DO bit is set
* Tue Mar 10 2009 Adam Tkac 32:9.6.0-10.P1- enable DNSSEC only if it is enabled in sysconfig/dnssec
* Mon Mar 09 2009 Adam Tkac 32:9.6.0-9.P1- add DNSSEC support to initscript, enabled it per default- add requires dnssec-conf