Commit Graph

200 Commits

Author SHA256 Message Date
Tomáš Chvátal
431b5383b2 Accepting request 714800 from home:mgerstner:branches:network
- removal of SuSEfirewall2 service from Factory, since SuSEfirewall2 has been
  replaced by firewalld, see [1].
  [1]: https://lists.opensuse.org/opensuse-factory/2019-01/msg00490.html

OBS-URL: https://build.opensuse.org/request/show/714800
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=257
2019-07-22 07:51:09 +00:00
Navin Kukreja
3f366a17af Accepting request 694778 from home:nkukreja:branches:network
- Add FIPS patch back into bind (bsc#1128220)
- File: bind-fix-fips.patch

OBS-URL: https://build.opensuse.org/request/show/694778
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=255
2019-04-16 10:45:29 +00:00
Tomáš Chvátal
54e402359e Accepting request 656764 from home:fbui:branches:network
- Don't rely on /etc/insserv.conf anymore for proper dependencies
  against nss-lookup.target in named.service and lwresd.service
  (bsc#1118367 bsc#1118368)

OBS-URL: https://build.opensuse.org/request/show/656764
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=253
2018-12-10 12:05:10 +00:00
Ismail Dönmez
41d567bd7e Accepting request 637877 from home:cgiboudeaux:branches:network
- Update named.root. One of the root servers IP has changed.
- Install the LICENSE file.

OBS-URL: https://build.opensuse.org/request/show/637877
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=251
2018-09-25 08:40:30 +00:00
OBS User mrdocs
f183a6fcba Accepting request 621328 from home:kukuk:branches:network
- Add bind.conf and bind-chrootenv.conf to install the default
  files in /var/lib/named and create chroot environment on systems
  using transactional-updates [bsc#1100369] [FATE#325524].

OBS-URL: https://build.opensuse.org/request/show/621328
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=249
2018-07-19 05:20:17 +00:00
OBS User mrdocs
2b99721cd9 Accepting request 618489 from home:kukuk:branches:network
- Cleanup pre/post install: remove all old code which was needed to
  update to SLES8.

OBS-URL: https://build.opensuse.org/request/show/618489
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=247
2018-06-27 04:27:15 +00:00
530e7d8de1 Accepting request 614550 from home:nkukreja:branches:network
- Fix a patch error in dnszone-schema file (bsc#901577)

OBS-URL: https://build.opensuse.org/request/show/614550
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=245
2018-06-07 06:48:37 +00:00
Navin Kukreja
e30f1eb7cd Accepting request 614223 from home:nkukreja:branches:network
- Add SPF records in dnszone-schema file (bsc#901577)

OBS-URL: https://build.opensuse.org/request/show/614223
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=244
2018-06-05 12:32:41 +00:00
Navin Kukreja
63f4bb281a Accepting request 614210 from home:nkukreja:branches:network
- Patch file - bind-ldapdump-use-valid-host.patch

OBS-URL: https://build.opensuse.org/request/show/614210
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=243
2018-06-05 10:10:15 +00:00
Navin Kukreja
6e77e065be Accepting request 614182 from home:nkukreja:branches:network
- Fix the hostname in ldapdump to be valid (bsc#965748)

OBS-URL: https://build.opensuse.org/request/show/614182
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=242
2018-06-05 09:30:33 +00:00
Navin Kukreja
34d201c2e7 Accepting request 611353 from home:scabrero:branches:network
- Add bug-4697-Restore-workaround-for-Microsoft-Windows-T.patch
  Fixes dynamic DNS updates against samba and Microsoft DNS servers
  (bsc#1094236).

OBS-URL: https://build.opensuse.org/request/show/611353
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=240
2018-05-23 09:09:10 +00:00
Navin Kukreja
ccaf6117d3 Accepting request 610097 from home:nkukreja:branches:network
- Move chroot related files from bind to bind-chrootenv 
  (bsc#1093338)

OBS-URL: https://build.opensuse.org/request/show/610097
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=239
2018-05-17 14:45:41 +00:00
Navin Kukreja
69299c3f09 Accepting request 609105 from home:nkukreja:branches:network
- Remove rndc.key generation from bind.spec file because bind
  should create it on first boot (bsc#1092283)
- Add misisng rndc.key check and generation code is lwresd.init
  script

OBS-URL: https://build.opensuse.org/request/show/609105
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=238
2018-05-16 10:46:10 +00:00
Ismail Dönmez
63b17d629c Accepting request 597553 from home:rudi_m:branches:network
add bug number (bsc#1069633)

OBS-URL: https://build.opensuse.org/request/show/597553
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=236
2018-04-19 08:15:25 +00:00
862ae2408a Accepting request 580513 from home:rudi_m:branches:network
- build with --enable-filter-aaaa to make it possible to use
  config option "filter-aaaa-on-v4 yes". Useful to workaround
  broken websites like netflix which block traffic from certain
  IPv6 tunnel providers.

OBS-URL: https://build.opensuse.org/request/show/580513
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=234
2018-02-27 10:12:33 +00:00
709c0c9ee2 Accepting request 577255 from home:bmwiedemann:branches:network
Add /dev/urandom to chroot env 
note: it is not world writable to make our rpmlint security checker happy - and it is not required anyway

without this, named start shows warnings in journal:
Feb 16 13:28:35 testleap named[1514]: could not open entropy source /dev/urandom: file not found
Feb 16 13:28:35 testleap named[1514]: using pre-chroot entropy source /dev/urandom

OBS-URL: https://build.opensuse.org/request/show/577255
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=232
2018-02-16 14:01:14 +00:00
Navin Kukreja
c27658fca1 Accepting request 574119 from home:nkukreja:branches:network
- Implement systemd init scripts for bind and lwresd (fate#323155)

OBS-URL: https://build.opensuse.org/request/show/574119
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=230
2018-02-08 13:15:18 +00:00
Navin Kukreja
41f90b8125 Accepting request 568769 from home:nkukreja:branches:network
- Apply bind-CVE-2017-3145.patch to fix CVE-2017-3145 (bsc#1076118)

OBS-URL: https://build.opensuse.org/request/show/568769
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=228
2018-01-23 22:28:59 +00:00
Ismail Dönmez
3dc2357a41 Accepting request 554799 from home:vitezslav_cizek:branches:network
- Use getent when adding user/group
- update changelog to mention removed options

  * Remove no longer recognized --enable-rrl

OBS-URL: https://build.opensuse.org/request/show/554799
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=226
2017-12-07 10:37:08 +00:00
e04eec6142 - license changed to MPL-2.0 according to legal.
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=225
2017-11-25 15:31:35 +00:00
b264302d00 Accepting request 545259 from home:scarabeus_iv:branches:network
- Add back init scripts, systemd units aren't ready yet

- Add python3-bind subpackage to allow python bind interactions

- Sync configure options with RH package and remove unused ones
  * Enable python3
  * Enable gssapi
  * Enable dnssec scripts

- Drop idnkit from the build, the bind uses libidn since 2007 to run
  all the resolutions in dig/etc. bsc#1030306
- Add patch to make sure we build against system idn:
  * bind-99-libidn.patch
- Refresh patch:
  * pie_compile.diff
- Remove patches that are unused due to above:
  * idnkit-powerpc-ltconfig.patch
  * runidn.diff

- drop bind-openssl11.patch (merged upstream)

- Remove systemd conditionals as we are not building on sle11 anyway
- Force the systemd to be base for the initscript deployment

- Bump up version of most of the libraries
- Rename the subpackages to match the version updates
- Add macros for easier handling of the library package names
- Drop more unneeded patches
  * dns_dynamic_db.patch (upstream)

OBS-URL: https://build.opensuse.org/request/show/545259
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=224
2017-11-24 16:29:49 +00:00
6c11f8d877 Accepting request 544658 from home:RBrownSUSE:branches:network
Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)

OBS-URL: https://build.opensuse.org/request/show/544658
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=223
2017-11-24 10:22:50 +00:00
fc48f6ba17 Accepting request 543879 from home:pluskalm:branches:network
- Use python3 by default (fate#323526)

OBS-URL: https://build.opensuse.org/request/show/543879
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=221
2017-11-21 09:43:45 +00:00
OBS User mrdocs
efc0e572f3 Accepting request 523293 from home:msmeissn:branches:network
- bind-openssl11.patch: add a patch for enabling
  openssl 1.1 support (builds for 1.0 and 1.1 openssl).
  (bsc#1042635)

OBS-URL: https://build.opensuse.org/request/show/523293
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=219
2017-09-14 01:12:46 +00:00
7e6301a923 Accepting request 520246 from home:j-engel:branches:network
- Enable JSON statistics

OBS-URL: https://build.opensuse.org/request/show/520246
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=216
2017-09-07 12:02:08 +00:00
70734c6ca6 Accepting request 510278 from home:msmeissn:branches:network
- named.root: refreshed from internic to 2017060102 (bsc#1048729)

OBS-URL: https://build.opensuse.org/request/show/510278
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=214
2017-07-14 17:29:38 +00:00
OBS User mrdocs
4215a9d83e Accepting request 507735 from home:dimstar:Factory
- Run systemctl daemon-reload even when this is not build with
  systemd support: if installing bind on a systemd service and not
  reloading systemd daemon, then the service 'named' is not known
  right after package installation, causing confusion.

OBS-URL: https://build.opensuse.org/request/show/507735
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=212
2017-07-03 22:11:50 +00:00
43448a770a Accepting request 507232 from home:simotek:branches:network
- Added bind-CVE-2017-3142-and-3143.patch to fix a security issue
  where an attacker with the ability to send and receive messages
  to an authoritative DNS server was able to circumvent TSIG
  authentication of AXFR requests. A server that relies solely on
  TSIG keys for protection with no other ACL protection could be
  manipulated into (1) providing an AXFR of a zone to an
  unauthorized recipient and (2) accepting bogus Notify packets.
  [bsc#1046554, CVE-2017-3142, bsc#1046555, CVE-2017-3143]

OBS-URL: https://build.opensuse.org/request/show/507232
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=211
2017-06-30 10:58:48 +00:00
7b1425a23f Accepting request 496935 from home:dimstar:Factory
a- Fix named init script to dynamically find the location of the
   openssl engines (boo#1040027).

OBS-URL: https://build.opensuse.org/request/show/496935
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=209
2017-05-20 15:34:20 +00:00
4e8c935dd7 Accepting request 481339 from home:kukuk:branches:network
- Add with_systemd define with default off, since we still use init
  scripts and no systemd units.

OBS-URL: https://build.opensuse.org/request/show/481339
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=207
2017-03-23 16:11:03 +00:00
44c7103fc2 Accepting request 458921 from home:kukuk:branches:network
- Don't require and call insserv if we use systemd

OBS-URL: https://build.opensuse.org/request/show/458921
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=205
2017-02-21 10:39:18 +00:00
Navin Kukreja
9e49836a48 Accepting request 457420 from home:nkukreja:branches:network
- Fix assertion failure or a NULL pointer read for configurations using both DNS64 and RPZ
  * CVE-2017-3135, bsc#1024130
  * bind-CVE-2017-3135.patch

OBS-URL: https://build.opensuse.org/request/show/457420
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=203
2017-02-15 13:26:45 +00:00
c6ec97ecb6 Accepting request 449784 from home:simotek:branches:network
Fix bsc#1018699 by taking latest update in series 9.11 needs a little more work

OBS-URL: https://build.opensuse.org/request/show/449784
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=200
2017-01-12 12:21:22 +00:00
318666062f Accepting request 438189 from home:psimons:branches:network
Apply cve-2016-8864.patch to fix CVE-2016-8864 (bsc#1007829).

OBS-URL: https://build.opensuse.org/request/show/438189
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=198
2016-11-02 13:30:34 +00:00
Ismail Dönmez
7af14e49dd Accepting request 430610 from home:psimons:branches:network
Security update to fix CVE-2016-2776 (bsc#1000362).

OBS-URL: https://build.opensuse.org/request/show/430610
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=196
2016-09-27 18:38:49 +00:00
Reinhard Max
8b99b04f2a - Remove the start/stop dependency of named and lwresd on remote-fs
to break a service dependency cycle (bsc#947483, bsc#963971).
- Make /var/lib/named owned by the named user (bsc#908850,
  bsc#875691).
- Call systemd service macros with the full service name.
- Security update 9.10.3-P4:

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=194
2016-06-16 12:00:45 +00:00
Rusmir Duško
2e4b7daa78 Accepting request 389954 from home:lnussel:branches:network
- remove BuildRequire libcap. That is only a legacy library, not
  actually used for building. libcap-devel pulls in the right one.

OBS-URL: https://build.opensuse.org/request/show/389954
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=192
2016-04-15 07:56:29 +00:00
Reinhard Max
2d8afe69b8 - Security update 9.10.3-P3:
* CVE-2016-1285, bsc#970072: assert failure on input parsing can
    cause premature exit.
  * CVE-2016-1286, bsc#970073: An error when parsing signature
    records for DNAME can lead to named exiting due to an assertion
    failure.
  * CVE-2016-2088, bsc#970074: a deliberately misconstructed packet
    containing multiple cookie options to cause named to terminate
    with an assertion failure.

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=190
2016-03-11 13:59:03 +00:00
Reinhard Max
abbe73be65 - Security update 9.10.3-P3 fixes two assertion failures that can
lead to remote DoS:
  * CVE-2016-1285, bsc#970072
  * CVE-2016-1286, bsc#970073

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=189
2016-03-11 13:55:29 +00:00
0f06af6f9d Accepting request 361463 from home:bmwiedemann:branches:network
- drop a changing timestamp making build reproducible

OBS-URL: https://build.opensuse.org/request/show/361463
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=187
2016-02-26 07:55:47 +00:00
Lars Müller
9508d45935 Accepting request 359100 from home:elvigia:branches:network
- Build with --with-randomdev=/dev/urandom otherwise 
  libisc will use /dev/random to gather entropy and that might
  block, short read etc..

OBS-URL: https://build.opensuse.org/request/show/359100
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=185
2016-02-12 19:11:31 +00:00
Reinhard Max
c7dc2ebf4f - Security update 9.10.3-P3:
* Specific APL data could trigger an INSIST (CVE-2015-8704,
    bsc#962189).
  * Certain errors that could be encountered when printing out or
    logging an OPT record containing a CLIENT-SUBNET option could
    be mishandled, resulting in an assertion failure
    (CVE-2015-8705, bsc#962190).
  * Authoritative servers that were marked as bogus (e.g.
    blackholed in configuration or with invalid addresses) were
    being queried anyway.

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=183
2016-01-20 11:04:34 +00:00
Reinhard Max
5f956be5fc - Update to version 9.10.3-P2 to fix a remote denial of service by
misparsing incoming responses (CVE-2015-8000, bsc#958861).

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=180
2015-12-21 17:12:31 +00:00
Reinhard Max
ee28860376 Accepting request 336332 from home:jengelh:branches:network
- Avoid double %setup, it confuses some versions of quilt.
- Summary/description update

OBS-URL: https://build.opensuse.org/request/show/336332
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=178
2015-10-05 07:46:26 +00:00
Lars Müller
f17cebd7c5 Accepting request 332971 from home:msmeissn:branches:network
- Update to version 9.10.2-P4
  * An incorrect boundary boundary check in the OPENPGPKEY
    rdatatype could trigger an assertion failure.
    (CVE-2015-5986) [RT #40286] (bsc#944107)
  * A buffer accounting error could trigger an
    assertion failure when parsing certain malformed 
    DNSSEC keys. (CVE-2015-5722) [RT #40212] (bsc#944066)

OBS-URL: https://build.opensuse.org/request/show/332971
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=176
2015-09-22 20:15:47 +00:00
Lars Müller
f94eebf621 - Update to version 9.10.2-P3
Security Fixes
  * A specially crafted query could trigger an assertion failure in message.c.
    This flaw was discovered by Jonathan Foote, and is disclosed in
    CVE-2015-5477. [RT #39795]
  * On servers configured to perform DNSSEC validation, an assertion failure
    could be triggered on answers from a specially configured server.
    This flaw was discovered by Breno Silveira Soares, and is disclosed
    in CVE-2015-4620. [RT #39795]
  Bug Fixes
  * Asynchronous zone loads were not handled correctly when the zone load was
    already in progress; this could trigger a crash in zt.c. [RT #37573]
  * Several bugs have been fixed in the RPZ implementation:
    + Policy zones that did not specifically require recursion could be treated
      as if they did; consequently, setting qname-wait-recurse no; was
      sometimes ineffective. This has been corrected. In most configurations,
      behavioral changes due to this fix will not be noticeable. [RT #39229]
    + The server could crash if policy zones were updated (e.g. via
      rndc reload or an incoming zone transfer) while RPZ processing
      was still ongoing for an active query. [RT #39415]
    + On servers with one or more policy zones configured as slaves, if a
      policy zone updated during regular operation (rather than at startup)
      using a full zone reload, such as via AXFR, a bug could allow the RPZ
      summary data to fall out of sync, potentially leading to an assertion
      failure in rpz.c when further incremental updates were made to the zone,
      such as via IXFR. [RT #39567]
    + The server could match a shorter prefix than what was
      available in CLIENT-IP policy triggers, and so, an unexpected
      action could be taken. This has been corrected. [RT #39481]
    + The server could crash if a reload of an RPZ zone was initiated while

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=174
2015-07-29 19:36:46 +00:00
Lars Müller
5693887a0c - Update to version 9.10.2-P2
- An uninitialized value in validator.c could result in an assertion failure.
    (CVE-2015-4620) [RT #39795]
- Update to version 9.10.2-P1
  - Include client-ip rules when logging the number of RPZ rules of each type.
    [RT #39670]
  - Addressed further problems with reloading RPZ zones. [RT #39649]
  - Addressed a regression introduced in change #4121. [RT #39611]
  - The server could match a shorter prefix than what was available in
    CLIENT-IP policy triggers, and so, an unexpected action could be taken.
    This has been corrected. [RT #39481]
  - On servers with one or more policy zones configured as slaves, if a policy
    zone updated during regular operation (rather than at startup) using a full
    zone reload, such as via AXFR, a bug could allow the RPZ summary data to
    fall out of sync, potentially leading to an assertion failure in rpz.c when
    further incremental updates were made to the zone, such as via IXFR.
    [RT #39567]
  - A bug in RPZ could cause the server to crash if policy zones were updated
    while recursion was pending for RPZ processing of an active query.
    [RT #39415]
  - Fix a bug in RPZ that could cause some policy zones that did not
    specifically require recursion to be treated as if they did; consequently,
    setting qname-wait-recurse no; was sometimes ineffective. [RT #39229]
  - Asynchronous zone loads were not handled correctly when the zone load was
    already in progress; this could trigger a crash in zt.c. [RT #37573]
  - Fix an out-of-bounds read in RPZ code. If the read succeeded, it doesn't
    result in a bug during operation. If the read failed, named could segfault.
    [RT #38559]

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=172
2015-07-10 20:54:40 +00:00
Lars Müller
2d26a35729 Change log line wrapping.
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=170
2015-06-18 13:14:58 +00:00
755db9e738 Accepting request 311393 from home:guohouzuo:freeipa
Fix inappropriate use of /var/lib/named for locating dynamic-DB plugins.
Dynamic-DB plugins are now loaded from %{_libexecdir}/bind, consistent with openSUSE packaging guideline.
Install additional header files which are helpful to the development of dynamic-DB plugins.

Please note that - the so-far only implementation of dyanmic-DB plugin does not support running in chroot environment very well, there is great performance impact in doing so.

OBS-URL: https://build.opensuse.org/request/show/311393
OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=169
2015-06-18 12:30:16 +00:00
Lars Müller
1ea9273bb0 This change set makes bind build again for SLE 11 too.
- Depend on systemd macros and sysvinit on post-12.3 only.
- Create empty lwresd.conf at build time.
- Reduce file list pre-13.1.

OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=167
2015-05-08 18:11:21 +00:00