<feed xmlns='http://www.w3.org/2005/Atom'>
<title>ports/dns/bind94, branch main</title>
<subtitle>FreeBSD ports tree</subtitle>
<id>https://cgit-dev.freebsd.org/ports/atom?h=main</id>
<link rel='self' href='https://cgit-dev.freebsd.org/ports/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/'/>
<updated>2011-06-01T00:22:22Z</updated>
<entry>
<title>BIND 9.4.x is now EOL</title>
<updated>2011-06-01T00:22:22Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2011-06-01T00:22:22Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=d88f9b8236a5e752105a9d1c60a3b5fe77d17b2f'/>
<id>urn:sha1:d88f9b8236a5e752105a9d1c60a3b5fe77d17b2f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Upgrade to 9.4-ESV-R4-P1, which addresses the following issues:</title>
<updated>2011-05-27T23:46:58Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2011-05-27T23:46:58Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=612e91cca50315c1a9286da02c9883380ce3f532'/>
<id>urn:sha1:612e91cca50315c1a9286da02c9883380ce3f532</id>
<content type='text'>
1. Very large RRSIG RRsets included in a negative cache can trigger
an assertion failure that will crash named (BIND 9 DNS) due to an
off-by-one error in a buffer size check.

This bug affects all resolving name servers, whether DNSSEC validation
is enabled or not, on all BIND versions prior to today. There is a
possibility of malicious exploitation of this bug by remote users.

2. Named could fail to validate zones listed in a DLV that validated
insecure without using DLV and had DS records in the parent zone.
</content>
</entry>
<entry>
<title>Miscellaneous cleanups and fixes, some of the windowmaker stuff</title>
<updated>2011-05-16T05:22:09Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2011-05-16T05:22:09Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=31ae302eb665784c7ca35def30a3f47687c59030'/>
<id>urn:sha1:31ae302eb665784c7ca35def30a3f47687c59030</id>
<content type='text'>
gracefully provided by danfe.
</content>
</entry>
<entry>
<title>The actual EOL date is 2011-05-31, as clarified in</title>
<updated>2011-01-08T02:31:09Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2011-01-08T02:31:09Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=ff4a30f27b8c753226fb4222ea852905f1bd8138'/>
<id>urn:sha1:ff4a30f27b8c753226fb4222ea852905f1bd8138</id>
<content type='text'>
https://lists.isc.org/pipermail/bind-users/2011-January/082285.html
</content>
</entry>
<entry>
<title>Give people fair warning:</title>
<updated>2010-12-18T01:29:34Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2010-12-18T01:29:34Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=7cf061ee366ebfe502fe8df094279cd535e61541'/>
<id>urn:sha1:7cf061ee366ebfe502fe8df094279cd535e61541</id>
<content type='text'>
DEPRECATED=		Reaches EOL May 2011
EXPIRATION_DATE=	2011-04-30

While I'm here update CONFLICTS for bind98
</content>
</entry>
<entry>
<title>Update to version 9.4-ESV-R4, the latest from ISC, which addresses</title>
<updated>2010-12-03T23:57:16Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2010-12-03T23:57:16Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=ee030af2cc2b3c28788ff83c7d26fdf909144e22'/>
<id>urn:sha1:ee030af2cc2b3c28788ff83c7d26fdf909144e22</id>
<content type='text'>
the following security vulnerability.

For more information regarding these issues please see:
http://www.isc.org/announcement/guidance-regarding-dec-1st-2010-security-advisories

Key algorithm rollover

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3614

Affects resolver operators who are validating with DNSSEC,
and querying zones which are in a key rollover period.
The bug will cause answers to incorrectly be marked as insecure.

For the port:
1. Add CONFLICT for the ../bind-tools port
2. Remove CONFLICT for the removed ../bind9 port
3. Remove OPTION for threads on &lt; RELENG_7
4. Remove MD5 from distinfo
5. Switch to pkg-install to create the symlinks to /etc/namedb/ as
   requested in [1]

PR:		ports/151635 [1]
Submitted by:	Benjamin Lee &lt;ben@b1c1l1.com&gt; [1]
</content>
</entry>
<entry>
<title>Update to 9.4-ESV-R3, the latest from ISC.</title>
<updated>2010-10-19T00:12:11Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2010-10-19T00:12:11Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=2b4908b3d03dfff525aa78b84e67e5203d24da69'/>
<id>urn:sha1:2b4908b3d03dfff525aa78b84e67e5203d24da69</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Update to the latest patch set from ISC, which addresses the following:</title>
<updated>2010-05-20T06:34:15Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2010-05-20T06:34:15Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=7509c01a81c81cd460d2ea1e6ef3bae0db484d5d'/>
<id>urn:sha1:7509c01a81c81cd460d2ea1e6ef3bae0db484d5d</id>
<content type='text'>
   Named could return SERVFAIL for negative responses
   from unsigned zones.
</content>
</entry>
<entry>
<title>Update to the latest patchfix releases to deal with the problems</title>
<updated>2010-03-17T05:35:03Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2010-03-17T05:35:03Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=e0bc892a0e99733a1869a57540f7ba4a78c55732'/>
<id>urn:sha1:e0bc892a0e99733a1869a57540f7ba4a78c55732</id>
<content type='text'>
related to the handling of broken DNSSEC trust chains.

This fix is only necessary for those who have DNSSEC validation
enabled and configure trust anchors from third parties, either
manually, or through a system like DLV.
</content>
</entry>
<entry>
<title>Upgrade to 9.4-ESV, the first of the "Extended Support Releases"</title>
<updated>2010-02-02T07:14:33Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2010-02-02T07:14:33Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=c595c1f9f0b215930d6f7fa8fb1322e6a26e790b'/>
<id>urn:sha1:c595c1f9f0b215930d6f7fa8fb1322e6a26e790b</id>
<content type='text'>
from ISC. It has numerous bug fixes compared to 9.4.3*, however
in the case of this version "extended" only applies till 2010/12/31
so serious BIND users are still encouraged to upgrade to 9.6.x.
</content>
</entry>
</feed>
