<feed xmlns='http://www.w3.org/2005/Atom'>
<title>ports/dns/bind9, branch release/8.0.0</title>
<subtitle>FreeBSD ports tree</subtitle>
<id>https://cgit-dev.freebsd.org/ports/atom?h=release%2F8.0.0</id>
<link rel='self' href='https://cgit-dev.freebsd.org/ports/atom?h=release%2F8.0.0'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/'/>
<updated>2009-09-01T01:31:43Z</updated>
<entry>
<title>The new LINKS OPTION is not only useless it's harmful when combined</title>
<updated>2009-09-01T01:31:43Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2009-09-01T01:31:43Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=7d86b05e82a6a45f1e9871f7cc618ea07dba82ca'/>
<id>urn:sha1:7d86b05e82a6a45f1e9871f7cc618ea07dba82ca</id>
<content type='text'>
with the REPLACE_BASE option so if the latter is defined don't try
to make the LINKS.

Problem pointed out by:	Chris Wopat &lt;me@falz.net&gt;
</content>
</entry>
<entry>
<title>For all:</title>
<updated>2009-08-29T23:15:57Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2009-08-29T23:15:57Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=88cce369b3961bde52148670299f64eb914c11c5'/>
<id>urn:sha1:88cce369b3961bde52148670299f64eb914c11c5</id>
<content type='text'>
Add an OPTION (on by default) to install the appropriate symlinks for
named.conf and rndc.key in /usr/local/etc and /var/named/usr/local/etc.

For bind9[456]:
Add OPTIONs (off by default) for the DLZ configure options, and their
corresponding ports knobs. [1] The basic infrastructure for this was
provided in the PR, but this version is slightly different in a few
details so responsibility for bugs is mine.

PR:		ports/122974 [1]
Submitted by:	Michael Schout &lt;mschout@gkg.net&gt; [1]
</content>
</entry>
<entry>
<title>Apply the patch derived from version 9.6.1-P1 which addresses a remote</title>
<updated>2009-07-29T00:22:52Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2009-07-29T00:22:52Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=85e089ac76b997b3dc27a44cd14afcc6d6b29c76'/>
<id>urn:sha1:85e089ac76b997b3dc27a44cd14afcc6d6b29c76</id>
<content type='text'>
DoS vulnerability:

	Receipt of a specially-crafted dynamic update message may
  	cause BIND 9 servers to exit. This vulnerability affects all
  	servers -- it is not limited to those that are configured to
  	allow dynamic updates. Access controls will not provide an
  	effective workaround.

More details can be found here: https://www.isc.org/node/474

All BIND users are encouraged to update to a patched version ASAP.
</content>
</entry>
<entry>
<title>- Flip from MAKE_JOBS_SAFE to MAKE_JOBS_UNSAFE, fails both on pointyhat and on</title>
<updated>2009-04-12T21:33:23Z</updated>
<author>
<name>Pav Lucistnik</name>
<email>pav@FreeBSD.org</email>
</author>
<published>2009-04-12T21:33:23Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=6d3f66735b7a6f1c2af352cdfce4cc4f4c7efb05'/>
<id>urn:sha1:6d3f66735b7a6f1c2af352cdfce4cc4f4c7efb05</id>
<content type='text'>
  my local machine
</content>
</entry>
<entry>
<title>Fix CONFLICTS (again). The previous example didn't work at all for ports</title>
<updated>2009-03-24T20:00:21Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2009-03-24T20:00:21Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=389960986f611e3bb222b4757f6f7558bb52f810'/>
<id>urn:sha1:389960986f611e3bb222b4757f6f7558bb52f810</id>
<content type='text'>
other than plain bind9 since the real PORTNAMEs for the other ports are
bind9[456]. This fix has the added advantage of covering REPLACE_BASE.
</content>
</entry>
<entry>
<title>Where it matters, update regarding MAKE_JOBS_{UN}SAFE for my ports</title>
<updated>2009-03-24T19:51:28Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2009-03-24T19:51:28Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=d31cadffee9652bba4aed758b08c36d8bd083aad'/>
<id>urn:sha1:d31cadffee9652bba4aed758b08c36d8bd083aad</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Update to the -P1 versions of the current BIND ports which contain</title>
<updated>2009-01-08T08:18:45Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2009-01-08T08:18:45Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=0a1b168539318adcfba294ee02ec97bf33e3080d'/>
<id>urn:sha1:0a1b168539318adcfba294ee02ec97bf33e3080d</id>
<content type='text'>
the fix for the following vulnerability: https://www.isc.org/node/373

Description:
Return values from OpenSSL library functions EVP_VerifyFinal()
and DSA_do_verify() were not checked properly.

Impact:
It is theoretically possible to spoof answers returned from
zones using the DNSKEY algorithms DSA (3) and NSEC3DSA (6).

In short, if you're not using DNSSEC to verify signatures you have
nothing to worry about.

While I'm here, address the issues raised in the PR by adding a knob
to disable building with OpenSSL altogether (which eliminates DNSSEC
capability), and fix the configure arguments to better deal with the
situation where the user has ssl bits in both the base and LOCALBASE.

PR:		ports/126297
Submitted by:	Ronald F.Guilmette &lt;rfg@tristatelogic.com&gt;
</content>
</entry>
<entry>
<title>Update CONFLICTS to reflect the addition of the bind96 port,</title>
<updated>2009-01-04T07:26:28Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2009-01-04T07:26:28Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=c288151fe50fef3c00980bcac457819f9efa65f8'/>
<id>urn:sha1:c288151fe50fef3c00980bcac457819f9efa65f8</id>
<content type='text'>
the demise of bind9-dlz, and updates to the bind9-sdb-* ports.
</content>
</entry>
<entry>
<title>Upgrade to version 9.3.6.</title>
<updated>2008-12-19T22:30:01Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2008-12-19T22:30:01Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=ff257d5a2a91ef084be349f21c870f7d8b5e2dff'/>
<id>urn:sha1:ff257d5a2a91ef084be349f21c870f7d8b5e2dff</id>
<content type='text'>
Add a note to pkg-message indicating that ISC declared this version EOL
as of 1 December, but that we will support the port through the RELENG_6
lifetime.
</content>
</entry>
<entry>
<title>Adjust WWWs for new ISC website</title>
<updated>2008-12-19T21:18:27Z</updated>
<author>
<name>Doug Barton</name>
<email>dougb@FreeBSD.org</email>
</author>
<published>2008-12-19T21:18:27Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/ports/commit/?id=338244c44d8ae6a024253e705069077892305c6d'/>
<id>urn:sha1:338244c44d8ae6a024253e705069077892305c6d</id>
<content type='text'>
</content>
</entry>
</feed>
