From 1aa8a9bb8574b3e2a537a225e84504e1bb3ebf1009885a773843443b1f43f073 Mon Sep 17 00:00:00 2001 From: Marcus Meissner Date: Mon, 24 May 2021 12:18:49 +0000 Subject: [PATCH] Accepting request 894731 from home:jmoellers:branches:network OBS-URL: https://build.opensuse.org/request/show/894731 OBS-URL: https://build.opensuse.org/package/show/network/bind?expand=0&rev=320 --- bind-9.16.15.tar.xz | 3 -- bind-9.16.15.tar.xz.sha512.asc | 16 -------- bind-9.16.16.tar.xz | 3 ++ bind-9.16.16.tar.xz.sha512.asc | 16 ++++++++ bind.changes | 67 ++++++++++++++++++++++++++++++++++ bind.spec | 2 +- vendor-files.tar.bz2 | 4 +- 7 files changed, 89 insertions(+), 22 deletions(-) delete mode 100644 bind-9.16.15.tar.xz delete mode 100644 bind-9.16.15.tar.xz.sha512.asc create mode 100644 bind-9.16.16.tar.xz create mode 100644 bind-9.16.16.tar.xz.sha512.asc diff --git a/bind-9.16.15.tar.xz b/bind-9.16.15.tar.xz deleted file mode 100644 index 236e0a0..0000000 --- a/bind-9.16.15.tar.xz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:98b6f432d878a7bf8f57eb7b3c28be27278cf6b9989154bfe6c81104b38e7839 -size 5025688 diff --git a/bind-9.16.15.tar.xz.sha512.asc b/bind-9.16.15.tar.xz.sha512.asc deleted file mode 100644 index c1eb1f1..0000000 --- a/bind-9.16.15.tar.xz.sha512.asc +++ /dev/null @@ -1,16 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQIzBAABCgAdFiEEJFV3TUL9/mucOD64/hACvFlwgR8FAmB+oqoACgkQ/hACvFlw -gR85vRAAvIAItbIcVnNlYRSN5Pmgmcu7XsJF9lTP5m0DM++zF2puStoMfDm4t6tY -k+iV1SwgoNjAOhGpdnhczjNIhct0xImHaqpITcVjRwzNkoAStIkCr+g974EZcYEY -Q0mFowpefARhTUo3IbdkvN87lS+/yYNb7D3rHpluef4fexc29dbLnN8hvkkdiYEV -RAcJaXGjpjoqsxgiVbrhrQk2NA3Y5zKgyJsqMHF9bhSvX8y6cpi1y48W3+S6b31h -9Tx8f9DfoOWPl28rrL93iQTWc+SCK+BPUhP8kaIbEfJjX/CMWKAPjRxk8NPfkqs6 -IgwWsm15sNO2kXc8f2Tg976w1rElaDaWkjPLvQbD8/Yk8sInYSz9sFCoAQ6A7irk -0eVxzFS9Os/cjlf4n+v3b9MsYQ2f40uEP61LZ5hfC5puqfYx4c6pyRFjGvZzX90B -rpx4F94v94M+1lKlBELHhcTOvsiN3RjTti+qnHel02iKPw3AMu22Y9gCQ5d/OxwQ -WJSsvYfFhMt4h9e6Ejx6nQ1lHkC5G/i2ipGJmDFHZwUkXhMvOcAZsc/+EQEUjAyE -oH4gb49xTwrlZFidqmcSh6az/v53UZ396MGNJvQISaCeM3caenn5FCAcEFYngEj1 -Vp96Qmt4qJRI7YpdL2phFgZAmnPOr6h+ej6esdY+nwLUwwqf+DU= -=GxCr ------END PGP SIGNATURE----- diff --git a/bind-9.16.16.tar.xz b/bind-9.16.16.tar.xz new file mode 100644 index 0000000..653d587 --- /dev/null +++ b/bind-9.16.16.tar.xz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:6c913902adf878e7dc5e229cea94faefc9d40f44775a30213edd08860f761d7b +size 5016864 diff --git a/bind-9.16.16.tar.xz.sha512.asc b/bind-9.16.16.tar.xz.sha512.asc new file mode 100644 index 0000000..290cbea --- /dev/null +++ b/bind-9.16.16.tar.xz.sha512.asc @@ -0,0 +1,16 @@ +-----BEGIN PGP SIGNATURE----- + +iQIzBAABCgAdFiEEJFV3TUL9/mucOD64/hACvFlwgR8FAmCdjfgACgkQ/hACvFlw +gR/ndA//a75qqqJnMnLC1HJJ0IaZx9HF0gqevooe9WeRDMox9vJPxxNWFH+MLdAe +TwhJBr65P1XwvUaXeqYZeT2EQKjmrVuJAuJJmM7hxy/TcrzLlU5bTNJNcHdpNhnK +o+GFXHynirTPqaix1FNfIvvkKEqUDJxZzK4Lh7883gD7Xc5NTVPFEjQNHdz2MXp7 +p2eOG8BxrdOSo7jGss2Bpu4nYotFpW1UlovIugwlqpTWFnQzoR8cB68tk7/LQXDQ +INc2n7lm1slFW6tewZDIU2HWSlgRusjaGidzHjQKt7OLM3Uq+P5wCJ4epD5WKHJQ +Bs91u/N80pwTRdkCfSRz0zglIysNay9MmCzDELGsQv5eEDLSA7WGk0eZcxyyiYTp +uayrjosyAWUu4HaJf+nL27DCotxuc8Znhr6whwMiA0G/PoX9mzEdDFhEXz9/yNYy +a1Im7IonEqVMa448//+5HwuZScUV9Ju15zyMFm11H1xCjZn38xJyuHVNCni40Tb3 +ytHcKZReda33yemqYtCjejd5gfoDQfO2G12G3dZwtTlEgO7Y2bdhtQfPPCjEDkh+ +QIYsk3gxpxWtxhWnJO1FCQle8nADj9m8MVlJ6uX3bm6eOJuyr42ynOVoDKtYNEXc +B920yPrEhP8AIa5rc97N0m1b0ZWRfg3EB1xrimQRfThxfS1YCDs= +=UVqV +-----END PGP SIGNATURE----- diff --git a/bind.changes b/bind.changes index df4e2c0..c9e9aca 100644 --- a/bind.changes +++ b/bind.changes @@ -1,3 +1,70 @@ +------------------------------------------------------------------- +Fri May 21 07:23:04 UTC 2021 - Josef Möllers + +- vendor-files/system/named.prep was missing a $ + [bsc#1186278, vendor-files.tar.bz2] + +------------------------------------------------------------------- +Thu May 20 06:21:17 UTC 2021 - Josef Möllers + +- Upgrade to bind 9.16.16 + * Feature Changes + + DNSSEC responses containing NSEC3 records with iteration counts + greater than 150 are now treated as insecure. [GL #2445] + + The maximum supported number of NSEC3 iterations that can be + configured for a zone has been reduced to 150. [GL #2642] + + The default value of the max-ixfr-ratio option was changed to + unlimited, for better backwards compatibility in the stable + release series. [GL #2671] + + Zones that want to transition from secure to insecure mode + without becoming bogus in the process must now have their + dnssec-policy changed first to insecure, rather than none. After + the DNSSEC records have been removed from the zone, the + dnssec-policy can be set to none or removed from the + configuration. Setting the dnssec-policy to insecure causes CDS + and CDNSKEY DELETE records to be published. [GL #2645] + + The implementation of the ZONEMD RR type has been updated to + match RFC 8976. [GL #2658] + + The draft-vandijk-dnsop-nsec-ttl IETF draft was implemented: + NSEC(3) TTL values are now set to the minimum of the SOA MINIMUM + value or the SOA TTL. [GL #2347] + * Bug Fixes + + It was possible for corrupt journal files generated by an earlier + version of named to cause problems after an upgrade. This has been + fixed. [GL #2670] + + TTL values in cache dumps were reported incorrectly when + stale-cache-enable was set to yes. This has been fixed. + [GL #389] [GL #2289] + + A deadlock could occur when multiple rndc addzone, rndc delzone, + and/or rndc modzone commands were invoked simultaneously for + different zones. This has been fixed. [GL #2626] + + named and named-checkconf did not report an error when multiple + zones with the dnssec-policy option set were using the same zone + file. This has been fixed. [GL #2603] + + If dnssec-policy was active and a private key file was temporarily + offline during a rekey event, named could incorrectly introduce + replacement keys and break a signed zone. This has been fixed. + [GL #2596] + + When generating zone signing keys, KASP now also checks for key + ID conflicts among newly created keys, rather than just between + new and existing ones. [GL #2628] + +------------------------------------------------------------------- +Tue May 18 06:57:16 UTC 2021 - Josef Möllers + +- In /usr/libexec/bind/named.prep the order of arguments for + "ln -s" was wrong. + [vendor-files/system/named.prep, bsc#1186057] + +------------------------------------------------------------------- +Mon May 17 14:20:08 UTC 2021 - Josef Möllers + +- "systemctl reload named" does not work: + * the "kill" command is in /usr/bin, not in /sbin, + * the order of the options/arguments was wrong, and + * the "-p" option is wrong (it's not like strace's "-p"). + [bsc#1186046, vendor-files/system/named.service] + ------------------------------------------------------------------- Mon May 10 17:09:43 UTC 2021 - Ferdinand Thiessen diff --git a/bind.spec b/bind.spec index 7db9035..c28ca64 100644 --- a/bind.spec +++ b/bind.spec @@ -45,7 +45,7 @@ %define _fillupdir %{_localstatedir}/adm/fillup-templates %endif Name: bind -Version: 9.16.15 +Version: 9.16.16 Release: 0 Summary: Domain Name System (DNS) Server (named) License: MPL-2.0 diff --git a/vendor-files.tar.bz2 b/vendor-files.tar.bz2 index ded36a3..c73543b 100644 --- a/vendor-files.tar.bz2 +++ b/vendor-files.tar.bz2 @@ -1,3 +1,3 @@ version https://git-lfs.github.com/spec/v1 -oid sha256:4c916821240c2cb1af02b8ed0de7b4c216a756492a7c66094d174cf04376031e -size 19365 +oid sha256:59c7127883d3005e071140dbe76302e2a8ac872af2a569db3a77aebfd03d1184 +size 19234