aboutsummaryrefslogtreecommitdiff
path: root/dns/bind98/Makefile
Commit message (Collapse)AuthorAgeFilesLines
* Use a permanent name for the patch. (same file, the other was a symlink.)Mathieu Arnold2014-02-071-1/+1
| | | | | | | Sponsored by: Absolight Notes: svn path=/head/; revision=343206
* Unbreak in the RPZRRL_PATCH case, patch has been released.Mathieu Arnold2014-02-071-5/+1
| | | | | | | | Many thanks to: Vernon Schryver Sponsored by: Absolight Notes: svn path=/head/; revision=343204
* Note that the RPZRRL patch doesn't work yet with that release.Mathieu Arnold2014-01-311-0/+4
| | | | | | | Sponsored by: Absolight Notes: svn path=/head/; revision=341969
* Update to 9.8.7.Mathieu Arnold2014-01-311-2/+2
| | | | | | | | Changes: https://lists.isc.org/pipermail/bind-announce/2014-January/000895.html Sponsored by: Absolight Notes: svn path=/head/; revision=341951
* Revert r341073, static libs are not supposed to be PICRenato Botelho2014-01-271-1/+0
| | | | Notes: svn path=/head/; revision=341417
* Add -fPIC to CFLAGS for amd64, this fix static librariesRenato Botelho2014-01-251-0/+1
| | | | | | | Approved by: mat@ (maintainer) Notes: svn path=/head/; revision=341073
* Security update to fix CVE-2014-0591 as reported atMathieu Arnold2014-01-131-3/+2
| | | | | | | | | | | | | https://kb.isc.org/article/AA-01078/74/ 9.9.4 -> 9.9.4-P2 9.8.6 -> 9.8.6-P2 9.6-ESV-R10 -> 9.6-ESV-R10-P2 Security: CVE-2014-0591 Remote DOS Notes: svn path=/head/; revision=339612
* Fixup rndc.conf.sample installationMathieu Arnold2014-01-081-3/+3
| | | | | | | Spotted by: antoine Notes: svn path=/head/; revision=339186
* There's always a default value for named_conf now, so no need toErwin Lansing2014-01-071-1/+1
| | | | | | | | | | check for it, and espcially not for a wrong value. Noticed by: Stefan Bethke <stb@lassitu.de> Approved by: mat (maintainer) Notes: svn path=/head/; revision=338989
* Yet another round of fixes.Mathieu Arnold2014-01-061-7/+6
| | | | | | | | This time, it seems all of REPLACE_BASE, not REPLACE_BASE and post Bind removal from base seem to work consistently. Notes: svn path=/head/; revision=338952
* Fix yet another bug, they're creeping like crazy...Mathieu Arnold2014-01-061-1/+1
| | | | Notes: svn path=/head/; revision=338943
* Convert to staging and new options.Mathieu Arnold2014-01-061-147/+62
| | | | Notes: svn path=/head/; revision=338877
* Add the DOCS option to OPTIONS_DEFAULT.Mathieu Arnold2014-01-041-2/+2
| | | | Notes: svn path=/head/; revision=338674
* Hand the BIND ports to a new volunteer.Erwin Lansing2014-01-021-1/+1
| | | | Notes: svn path=/head/; revision=338442
* Fix build with GSSAPI option without KerberosErwin Lansing2013-12-101-0/+4
| | | | | | | | PR: 184560 Submitted by: Dewayne <dewayne@heuristicsystems.com.au> Notes: svn path=/head/; revision=336054
* bind(96,98,99): Couple OSVERSION with OPSYSJohn Marino2013-12-081-4/+4
| | | | | | | | | OSVERSION is platform-specific and must be used with OPSYS. Approved by: maintainer (erwin) Notes: svn path=/head/; revision=335933
* To prevent fallout of lowering __FreeBSD_version in releng/10.0 branch,Glen Barber2013-12-071-4/+4
| | | | | | | | | | adjust OSVERSION evaluation in ports that specifically use '100050N'. Approved by: affected maintainers (implicit) Sponsored by: The FreeBSD Foundation Notes: svn path=/head/; revision=335824
* Install named.conf as named.conf.sample and don't overwrite on upgradeErwin Lansing2013-12-051-3/+6
| | | | | | | | Bullet hole in foot: joeld Pointy hat: erwin Notes: svn path=/head/; revision=335667
* Fix build with GSSAPIErwin Lansing2013-12-041-0/+1
| | | | | | | Submitted by: sunpoet Notes: svn path=/head/; revision=335618
* Fix startup script.Erwin Lansing2013-11-221-0/+1
| | | | | | | | | PR: 184159 [1] Submitted by: Pawel Biernacki <pawel.biernacki@gmail.com> [1], Trond Endrestoel <Trond.Endrestol@ximalas.info> (private email) Notes: svn path=/head/; revision=334593
* Support FreeBSD 10.0.Erwin Lansing2013-11-121-6/+35
| | | | | | | | | | | | | | | | | | On FreeBSD 10.0, all configuration is installed under /usr/local/etc/namedb and installs its own rc script in $PREFIX, which no longer support chroot installations. LINKS and REPLACE_BASE options are not supported on 10.0 for obvious reasons. Note for FreeBSD 9.x and earlier users, LINKS is no longer the default option, though still supported. An UPDATING entry will follow after bind96 and bind99 are fixed as well. Notes: svn path=/head/; revision=333546
* Drop support for REPLACE_BIND option after BIND was removed from base,Erwin Lansing2013-11-041-1/+4
| | | | | | | there's nothing to replace. Notes: svn path=/head/; revision=332693
* Fix PATCH_SITESErwin Lansing2013-11-011-1/+1
| | | | | | | Submitted by: "Felix J. Ogris" <fjo@ogris.de> Notes: svn path=/head/; revision=332348
* Update to 9.8.6Erwin Lansing2013-09-281-4/+4
| | | | Notes: svn path=/head/; revision=328564
* Add an option for filter-aaaaErwin Lansing2013-09-231-1/+6
| | | | | | | Submitted by: Matej Gregr <matej.gregr@gmail.com> Notes: svn path=/head/; revision=327967
* Add NO_STAGE all over the place in preparation for the staging support (cat: ↵Baptiste Daroussin2013-09-201-0/+1
| | | | | | | dns) Notes: svn path=/head/; revision=327719
* Make GSSAPI support optionalErwin Lansing2013-09-171-1/+7
| | | | | | | | PR: 182122 Submitted by: Uwe Doering <gemini@geminix.org> Notes: svn path=/head/; revision=327469
* . introduce ICONV_CONFIGURE_BASE variable at Mk/Uses/iconv.mk. It's value isBoris Samorodov2013-09-051-1/+2
| | | | | | | | | | | "--with-libiconv=${LOCALBASE}" at systems pre OSVERSION 100043 and "" (null) otherwise; . convert all ports which has CONFIGURE_ARGS=--with-libiconv=${LOCALBASE}. Approved by: portmgr (bapt, implicit) Notes: svn path=/head/; revision=326444
* Update the RPZ+RL patches for both versions.Ollivier Robert2013-07-271-1/+1
| | | | | | | Approved by: erwin Notes: svn path=/head/; revision=323808
* Security update to fix CVE-2013-4854 as reported atOllivier Robert2013-07-261-2/+2
| | | | | | | | | | | | | | https://kb.isc.org/article/AA-01015/0 9.9.3-p1 -> 9.9.3-P2 9.8.5-p1 -> 9.8.5-P2 9.6.x is not affected, neither is 10.x. Security: CVE-2013-4854 Remote DOS Notes: svn path=/head/; revision=323757
* Update to 9.8.5-P1Erwin Lansing2013-06-051-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Security Fixes Prevents exploitation of a runtime_check which can crash named when satisfying a recursive query for particular malformed zones. (CVE-2013-3919) [RT #33690] A deliberately constructed combination of records could cause named to hang while populating the additional section of a response. (CVE-2012-5166) [RT #31090] Now supports NAPTR regular expression validation on all platforms, and avoids memory exhaustion compiling pathological regular expressions. (CVE-2013-2266) [RT #32688] Prevents named from aborting with a require assertion failure on servers with DNS64 enabled. These crashes might occur as a result of specific queries that are received. (CVE-2012-5688) [RT #30792 / #30996] Prevents an assertion failure in named when RPZ and DNS64 are used together. (CVE-2012-5689) [RT #32141] See release notes for further features and bug fixes: https://kb.isc.org/article/AA-00969/0/BIND-9.8.5-P1-Release-Notes.html Security: CVE-2013-3919 CVE-2012-5166 CVE-2013-2266 CVE-2012-5688 CVE-2012-5689 Notes: svn path=/head/; revision=319983
* Update to 9.8.5Erwin Lansing2013-05-311-3/+3
| | | | Notes: svn path=/head/; revision=319472
* Update RPZ and RRL patch set:Erwin Lansing2013-05-311-1/+1
| | | | | | | | | | | | | | | | | - address the issue raised by Bob Harold. RRL on recursive servers applies rate limits after waiting for recursion except on sub-domains of domains for which the server is authoritative. - fix the bug reported by Roy Arends in which "slipped" NXDOMAIN responses had rcode values of 0 (NoError) instead of 3 (NXDOMAIN). - move reports of RRL drop and slip actions from the "queries" log category to the "query-errors" category. Because they are not in the "queres" category, enabling or disabling query logging no longer affects them. Notes: svn path=/head/; revision=319468
* Make pkg-message and pkg-install a local file to the bind98 and bind99Erwin Lansing2013-04-231-2/+0
| | | | | | | | ports and not include the one from the deprecated bind97 port, which is to be removed. Notes: svn path=/head/; revision=316321
* Update RPZ+RRL patchset to the latest version.Erwin Lansing2013-04-171-1/+1
| | | | | | | | | | | | | | | | The change makes "slip 1;" send only truncated (TC=1) responses. Without the change, "slip 1;" is the same as the default of "slip 2;". That default, which alternates truncated with dropped responses when the rate limit is exceeded, is better for authoritative DNS servers, because it further reduces the amplification of an attack from about 1X to about 0.5X. DNS RRL is not recommended for recursive servers. Feature safe: yes Notes: svn path=/head/; revision=315942
* Update to 9.8.4-P2Erwin Lansing2013-03-271-2/+2
| | | | | | | | | | | | Removed the check for regex.h in configure in order to disable regex syntax checking, as it exposes BIND to a critical flaw in libregex on some platforms. [RT #32688] Security: CVE-2013-2266 Notes: svn path=/head/; revision=315355
* Update the RPZ+RRL patch files which removeErwin Lansing2013-03-151-1/+1
| | | | | | | | | | | working files that should not have been in the patches[1] Also move to a versioned filename for the patches[2] Submitted by: Robert Sargent <robtsgt@gmail.com> [1], Vernon Schryver <vjs@rhyolite.com> [2] Notes: svn path=/head/; revision=314294
* Reduce lenght of the option description for RPZRRL_PATCH toErwin Lansing2013-01-101-1/+1
| | | | | | | | | avoid problems with the older dialog(1) on FreeBSD 8.x Noticed by: Terry Kennedy <terry@tmk.com> Notes: svn path=/head/; revision=310175
* Update the response rate limiting patch to the latestErwin Lansing2013-01-091-5/+5
| | | | | | | | | | | | | | released version of January 5, 2013. This also includes performance patches to the BIND9 Response Policy Zones (DNS RPZ), Single Zone Response Policy Zone (RPZ) Speed Improvement, in the same patch. More information: http://ss.vix.su/~vjs/rrlrpz.html Notes: svn path=/head/; revision=310131
* Add LICENSE.Erwin Lansing2013-01-041-0/+2
| | | | Notes: svn path=/head/; revision=309925
* Add experimental option for Response Rate Limiting patch.Erwin Lansing2013-01-041-1/+7
| | | | Notes: svn path=/head/; revision=309924
* - Use new OPTIONS_GROUP for DLZ options.[1]Erwin Lansing2012-12-141-3/+3
| | | | | | | | | | | - This also allows more than one DLZ option to be set.[2] Submitted by: bapt [1] (as RADIO) Suggested by: az [2] (thus GROUP instead) Notes: svn path=/head/; revision=308897
* Update to the latest patch level from ISC:Erwin Lansing2012-12-051-2/+2
| | | | | | | | | | | | | | | | BIND 9 nameservers using the DNS64 IPv6 transition mechanism are vulnerable to a software defect that allows a crafted query to crash the server with a REQUIRE assertion failure. Remote exploitation of this defect can be achieved without extensive effort, resulting in a denial-of-service (DoS) vector against affected servers. Security: 2892a8e2-3d68-11e2-8e01-0800273fe665 CVE-2012-5688 Feature safe: yes Notes: svn path=/head/; revision=308317
* Improve the SSL option descriptionErwin Lansing2012-12-031-1/+1
| | | | | | | | Submitted by: Kazunori Fujiwara <fujiwara@jprs.co.jp> Feature safe: yes Notes: svn path=/head/; revision=308136
* Remove gpg signature checking that in itself does notErwin Lansing2012-12-031-5/+0
| | | | | | | | | provide any additional security. Feature safe: yes Notes: svn path=/head/; revision=308135
* - Update CONFLICTSErwin Lansing2012-11-271-6/+21
| | | | | | | | | | | | | - Fix a typo in the OPTIONSNG conversion - Add FIXED_RRSET option - Add RPZ options (9.8 and 9.8 only) PR: 172586 Submitted by: Craig Leres <leres@ee.lbl.gov> Feature safe: yes Notes: svn path=/head/; revision=307830
* Reduce lenght of the option description for DLZ_MYSQL toErwin Lansing2012-10-261-1/+1
| | | | | | | | | | avoid problems with the older dialog(1) on FreeBSD 8.x Noticed by: Terry Kennedy <terry@tmk.com> Feature safe: yes Notes: svn path=/head/; revision=306427
* - Convert to OPTIONSNGErwin Lansing2012-10-251-41/+43
| | | | | | | | | - Turn on IPv6 support by default Feature safe: yes Notes: svn path=/head/; revision=306379
* Update to 9.8.4Erwin Lansing2012-10-191-2/+2
| | | | | | | Feature safe: yes Notes: svn path=/head/; revision=306112
* Upgrade to the latest BIND patch level:Erwin Lansing2012-10-101-2/+2
| | | | | | | | | | A deliberately constructed combination of records could cause named to hang while populating the additional section of a response. Security: http://www.vuxml.org/freebsd/57a700f9-12c0-11e2-9f86-001d923933b6.html Notes: svn path=/head/; revision=305645