[nsd-users] NSD 3.2.11 with TLSA and ECDSA
matthijs at nlnetlabs.nl
Mon Jul 9 09:29:21 UTC 2012
-----BEGIN PGP SIGNED MESSAGE-----
There is a new release for nsd: 3.2.11. It is available here:
This release has some features, and some bug fixes too. This version
of nsd understands new DNSKEY algorithm mnemonics, including GOST and
ECDSA, as well as the TLSA RRtype (for DANE support). You can enable
'per zone statistics', with --enable-zone-stats. For more information,
see the RELNOTES below.
NSD 3.2.11 RELEASE NOTES:
- - Fallback to AXFR if IXFR is unknown at the primary. NSD considers
IXFR unknown at the primary if there is a negative response for the
IXFR RRtype. This does not override the value for
- - Allow for reading in new DNSKEY algorithm mnemonics (RFC5155,
RFC5702, RFC5933, and RFC6605 (ECDSA)).
- - Zone statistics, enable with --enable-zone-stats. This stores the
BIND8 stats per zone in a configurable statistics file. This option
does not scale and should therefore not be enabled when serving
- - Support for TLSA RRtype (DANE).
- - Fix for qtype ANY for a wildcard domain in NSEC signed zone: Don't
add the wildcard domain NSEC into the answer section. Instead,
put the wildcard expanded NSEC into the answer section and keep the
wildcard domain NSEC in the authority section.
- - Fix for accept spinning reported by OpenBSD.
- - Fix restart failed due to bad ixfr packet because of zone removed
- - Bugfix #453: typo in nsdc man page.
- - NSD uses the query name for dname compression again (Fix #235
had as side effect that this didn't happen anymore and is hereby
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
-----END PGP SIGNATURE-----
More information about the nsd-users