2
0
mirror of https://gitlab.isc.org/isc-projects/bind9 synced 2025-08-31 14:35:26 +00:00

Set up release notes for BIND 9.19.4

This commit is contained in:
Michał Kępień
2022-07-11 08:49:38 +02:00
parent 26bd3c172c
commit 680d1d29a4

View File

@@ -9,7 +9,7 @@
.. See the COPYRIGHT file distributed with this work for additional .. See the COPYRIGHT file distributed with this work for additional
.. information regarding copyright ownership. .. information regarding copyright ownership.
Notes for BIND 9.19.3 Notes for BIND 9.19.4
--------------------- ---------------------
Security Fixes Security Fixes
@@ -25,38 +25,19 @@ Known Issues
New Features New Features
~~~~~~~~~~~~ ~~~~~~~~~~~~
- The new ``rndc fetchlimit`` command prints a list of name server - None.
addresses that are currently rate-limited due to ``fetches-per-server``
and domain names that are rate limited due to ``fetches-per-zone``.
:gl:`#665`
Removed Features Removed Features
~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~
- The ``glue-cache`` *option* has been removed. The glue cache *feature* - None.
still works and is now permanently *enabled*. :gl:`#2147`
Feature Changes Feature Changes
~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~
- The :option:`dnssec-signzone -H` default value has been changed to 0 additional - None.
NSEC3 iterations. This change aligns the :iscman:`dnssec-signzone` default with
the default used by the :ref:`dnssec-policy <dnssec_policy_grammar>` feature.
At the same time, documentation about NSEC3 has been aligned with
`Best Current Practice
<https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-nsec3-guidance-10>`__.
:gl:`#3395`
Bug Fixes Bug Fixes
~~~~~~~~~ ~~~~~~~~~
- It was possible for a catalog zone consumer to process a catalog zone member - None.
zone when there was a configured pre-existing forward-only forward zone with
the same name. This has been fixed. :gl:`#2506`.
- Fix the assertion failure caused by TCP connection closing between the
connect (or accept) and the read from the socket. :gl:`#3400`
- When grafting on non-delegated namespace, synth-from-dnssec could incorrectly
synthesise non-existance of records within the grafted in namespace using
NSEC records from higher zones. :gl:`#3402`