SUSE Support

Here When You Need Us

Changes in BIND with update to version bind-9.9.2P2-0.11.1

This document (7012684) is provided subject to the disclaimer at the end of this document.

Environment

SUSE Linux Enterprise Server 11 Service Pack 2


Situation

To improve DNSSEC handling within bind we have done a version update of bind for Service Pack 2
of SUSE Linux Enterprise Server 11 (SLES11 SP2).

FATE#314615: Improve DNSSEC handling in BIND

The version bind-9.9.2P2-0.11.1 is available as update and will be installed automatically if you apply updates.

Please be aware that the following functionalities might have changed:

Change
Type
Description
3242[func]
Extended the header of raw-format master files to include the serial number of the zone from which they were generated, if different (as in the case of inline-signing zones). This is to be used in inline-signing zones, to track changes between the unsigned and signed versions of the zone, which may have different serial numbers.
(Note: raw zonefiles generated by this version of BIND are no longer compatible with prior versions. To generate a backward-compatible raw zonefile using dnssec-signzone or named-compilezone, specify output format "raw=0" instead of simply "raw".) [RT #26587]
3205
[func]
Upgrade dig's defaults to better reflect modern nameserver behavior.  Enable "dig +adflag" and "dig +edns=0" by default.  Enable "+dnssec" when running "dig +trace". [RT #23497]
2936
[func]
Improved configuration syntax and multiple-view support for addzone/delzone feature (see change #2930). Removed "new-zone-file" option, replaced with "allow-new-zones (yes|no)".  The new-zone-file for each view is now created automatically, with a filename generated from a hash of the view name. It is no longer necessary to "include" the new-zone-file in named.conf; this happens automatically.  Zones that were not added via "rndc addzone" can no longer be removed with "rndc delzone". [RT #19447]
2800
[func]
Reject zones which have NS records which refer to CNAMEs, DNAMEs or don't have address record (class IN only). Reject UPDATEs which would cause the zone to fail the above checks if committed. [RT #20678]

Resolution

null

Disclaimer

This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.

  • Document ID:7012684
  • Creation Date: 24-Jun-2013
  • Modified Date:28-Sep-2022
    • SUSE Linux Enterprise Server

< Back to Support Search

For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com

tick icon

SUSE Support Forums

Get your questions answered by experienced Sys Ops or interact with other SUSE community experts.

tick icon

Support Resources

Learn how to get the most from the technical support you receive with your SUSE Subscription, Premium Support, Academic Program, or Partner Program.

tick icon

Open an Incident

Open an incident with SUSE Technical Support, manage your subscriptions, download patches, or manage user access.