bind9-next/sources
Petr Menšík c1c7621d71 Update to 9.19.19 (#2255406)
https://downloads.isc.org/isc/bind9/9.19.19/doc/arm/html/notes.html#notes-for-bind-9-19-19

New Features

- Initial support for the PROXYv2 protocol was added. named can now accept PROXYv2 headers over all currently implemented DNS transports and dig can insert these headers into the queries it sends. Please consult the related documentation (allow-proxy, allow-proxy-on, listen-on, and listen-on-v6 for named, dig +proxy and dig +proxy-plain for dig) for additional details. [GL #4388]

Removed Features

- Support for using AES as the DNS COOKIE algorithm (cookie-algorithm aes;) has been removed. The only supported DNS COOKIE algorithm is now the current default, SipHash-2-4. [GL #4421]

- The resolver-nonbackoff-tries and resolver-retry-interval statements have been removed. Using them is now a fatal error. [GL #4405]

Feature Changes

- The maximum number of NSEC3 iterations allowed for validation purposes has been lowered from 150 to 50. DNSSEC responses containing NSEC3 records with iteration counts greater than 50 are now treated as insecure. [GL #4363]

- Following RFC 9276 recommendations, dnssec-policy now only allows an NSEC3 iteration count of 0 for the DNSSEC-signed zones using NSEC3 that the policy manages. [GL #4363]
2024-01-16 11:08:38 +01:00

2 lines
324 B
Text

SHA512 (bind-9.19.19.tar.xz) = 51ce55bade3a9b239d0ab21d19a0870b91aba1e4c93050f89f1940d322319521631b3b0389eaf5f03e3fc110852e11549365b0efa92536bf5d835510d73c1aa6
SHA512 (bind-9.19.19.tar.xz.asc) = 3217a33be6a885bb42ca972e57c21bfe3000b7cfeaede72aa302750ce9643d4820372f4b147e85ce97409bbc500b40d9b8bc82c12fb13c5c0a2d21fad86712f8