summaryrefslogtreecommitdiff
path: root/usr.sbin/bind/doc/misc
diff options
context:
space:
mode:
authorJakob Schlyter <jakob@cvs.openbsd.org>2004-09-28 17:14:10 +0000
committerJakob Schlyter <jakob@cvs.openbsd.org>2004-09-28 17:14:10 +0000
commitff09ecf5e523f7c1678821dfc8753880775b9bc9 (patch)
treecfbc352a0605ad89a62d844079441dca80fca83d /usr.sbin/bind/doc/misc
parentae87190605c9d85eaf9ba7728034f343685da32a (diff)
resolve conflicts
Diffstat (limited to 'usr.sbin/bind/doc/misc')
-rw-r--r--usr.sbin/bind/doc/misc/dnssec22
-rw-r--r--usr.sbin/bind/doc/misc/migration3
2 files changed, 9 insertions, 16 deletions
diff --git a/usr.sbin/bind/doc/misc/dnssec b/usr.sbin/bind/doc/misc/dnssec
index 1800d027ea6..eaed6f32455 100644
--- a/usr.sbin/bind/doc/misc/dnssec
+++ b/usr.sbin/bind/doc/misc/dnssec
@@ -1,4 +1,5 @@
-Copyright (C) 2000-2003 Internet Software Consortium.
+Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC")
+Copyright (C) 2000-2002 Internet Software Consortium.
See COPYRIGHT in the source root or http://isc.org/copyright.html for terms.
DNSSEC Release Notes
@@ -9,11 +10,10 @@ this release of BIND9.
OpenSSL Library Required
-To support DNSSEC, BIND 9 must be linked with version 0.9.6e or 0.9.7beta3
-or newer of the OpenSSL library (patched versions of 0.9.5a - 0.9.6d,
-0.9.7beta1 and 0.9.7beta2 will also be accepted: CERT CA-2002-23).
-As of BIND 9.2, the library is no longer included in the distribution - it
-must be provided by the operating system or installed separately.
+To support DNSSEC, BIND 9 must be linked with version 0.9.6e or newer of
+the OpenSSL library. As of BIND 9.2, the library is no longer
+included in the distribution - it must be provided by the operating
+system or installed separately.
To build BIND 9 with OpenSSL, use "configure --with-openssl". If
the OpenSSL library is installed in a nonstandard location, you can
@@ -38,14 +38,6 @@ When acting as an authoritative name server, BIND9 includes KEY, SIG
and NXT records in responses as specified in RFC2535 when the request
has the DO flag set in the query.
-Response generation for wildcard records in secure zones is not fully
-supported. Responses indicating the nonexistence of a name include a
-NXT record proving the nonexistence of the name itself, but do not
-include any NXT records to prove the nonexistence of a matching
-wildcard record. Positive responses resulting from wildcard expansion
-do not include the NXT records to prove the nonexistence of a
-non-wildcard match or a more specific wildcard match.
-
Secure Resolution
@@ -89,4 +81,4 @@ future as we consider them inferior to the use of TSIG or SIG(0) to
ensure the integrity of zone transfers.
-$ISC: dnssec,v 1.14.2.6 2003/03/06 04:38:20 marka Exp $
+$ISC: dnssec,v 1.14.2.6.4.4 2004/03/08 09:04:25 marka Exp $
diff --git a/usr.sbin/bind/doc/misc/migration b/usr.sbin/bind/doc/misc/migration
index dfe991d599c..5599c4bc85c 100644
--- a/usr.sbin/bind/doc/misc/migration
+++ b/usr.sbin/bind/doc/misc/migration
@@ -1,3 +1,4 @@
+Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC")
Copyright (C) 2000, 2001, 2003 Internet Software Consortium.
See COPYRIGHT in the source root or http://isc.org/copyright.html for terms.
@@ -242,4 +243,4 @@ necessary, the umask should be set explicitly in the script used to
start the named process.
-$ISC: migration,v 1.37.2.4 2003/09/02 02:20:15 marka Exp $
+$ISC: migration,v 1.37.2.3.2.2 2004/03/06 13:16:19 marka Exp $