diff --git a/CHANGES b/CHANGES index a66473d479..78ea4cb640 100644 --- a/CHANGES +++ b/CHANGES @@ -21,6 +21,8 @@ that there is no configured pre-existing forward-only forward zone with that name. [GL #2506] + --- 9.18.4 released --- + 5899. [func] Don't try to process DNSSEC-related and ZONEMD records in catz. [GL #3380] diff --git a/doc/arm/notes.rst b/doc/arm/notes.rst index 9178215ab8..eadf71562f 100644 --- a/doc/arm/notes.rst +++ b/doc/arm/notes.rst @@ -34,6 +34,7 @@ https://www.isc.org/download/. There you will find additional information about each release, and source code. .. include:: ../notes/notes-current.rst +.. include:: ../notes/notes-9.18.4.rst .. include:: ../notes/notes-9.18.3.rst .. include:: ../notes/notes-9.18.2.rst .. include:: ../notes/notes-9.18.1.rst diff --git a/doc/notes/notes-9.18.4.rst b/doc/notes/notes-9.18.4.rst new file mode 100644 index 0000000000..12429c4a78 --- /dev/null +++ b/doc/notes/notes-9.18.4.rst @@ -0,0 +1,37 @@ +.. Copyright (C) Internet Systems Consortium, Inc. ("ISC") +.. +.. SPDX-License-Identifier: MPL-2.0 +.. +.. This Source Code Form is subject to the terms of the Mozilla Public +.. License, v. 2.0. If a copy of the MPL was not distributed with this +.. file, you can obtain one at https://mozilla.org/MPL/2.0/. +.. +.. See the COPYRIGHT file distributed with this work for additional +.. information regarding copyright ownership. + +Notes for BIND 9.18.4 +--------------------- + +Feature Changes +~~~~~~~~~~~~~~~ + +- New ``dnssec-policy`` configuration checks have been added to detect + unusual policies, such as missing KSK and/or ZSK and too-short key + lifetimes and re-sign periods. :gl:`#1611` + +Bug Fixes +~~~~~~~~~ + +- The ``fetches-per-server`` quota is designed to adjust itself downward + automatically when an authoritative server times out too frequently. + Due to a coding error, that adjustment was applied incorrectly, so + that the quota for a congested server was always set to 1. This has + been fixed. :gl:`#3327` + +- DNSSEC-signed catalog zones were not being processed correctly. This + has been fixed. :gl:`#3380` + +- Key files were updated every time the ``dnssec-policy`` key manager + ran, whether the metadata had changed or not. :iscman:`named` now + checks whether changes were applied before writing out the key files. + :gl:`#3302`