diff --git a/doc/arm/notes.xml b/doc/arm/notes.xml
index b6a4d57645..001e0e0c4d 100644
--- a/doc/arm/notes.xml
+++ b/doc/arm/notes.xml
@@ -279,8 +279,8 @@
named -L filename
- causes named to send log messages to the specified file by
- default instead of to the system log.
+ causes named to send log messages to the
+ specified file by default instead of to the system log.
@@ -432,18 +432,22 @@
- A "read-only" clause is now available for non-destructive
+ A read-only option is now available in the
+ controls statement to grant non-destructive
control channel access. In such cases, a restricted set of
- rndc commands are allowed for querying information from named.
- By default, control channel access is read-write.
+ rndc commands are allowed, which can
+ report information from named, but cannot
+ reconfigure or stop the server. By default, the control channel
+ access is not restricted to these
+ read-only operations. [RT #40498]
- When loading managed signed zones detect if the RRSIG's
- inception time is in the future and regenerate the RRSIG
- immediately. This helps when the system's clock needs to
- be reset backwards.
+ When loading a signed zone, named will
+ now check whether an RRSIG's inception time is in the future,
+ and if so, it will regenerate the RRSIG immediately. This helps
+ when a system's clock needs to be reset backwards.