Re: RHEL, Centos, Fedora rpm 9.9.3-P2

2013-07-26 Thread Carl Byington
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 http://www.five-ten-sg.com/mapper/bind contains links to the source rpms, and build instructions. -BEGIN PGP SIGNATURE- Version: GnuPG v2.0.14 (GNU/Linux) iEYEARECAAYFAlHy7/EACgkQL6j7milTFsGtbgCfWaIKqZlzTJp9bMmJV5XW19o5 Ka0AnjBG00Iqu0SfgldEc

Notice: BIND Security Jul2013 CVE2013-4854

2013-07-26 Thread ISC Security Officer
IMPORTANT: The security issue described below has been confirmed by ISC to be 'in the wild' as of 18:00UTC July 26, and exploitation of this vulnerability against production servers has been reported by multiple organizations. Please be advised that immediate action is recommended. A specially cra

Re: "auto-dnssec maintain;" and key "missing or inactive and has no replacement"

2013-07-26 Thread Stephane Bortzmeyer
On Fri, Jul 26, 2013 at 08:52:04AM +0200, Stephane Bortzmeyer wrote a message of 24 lines which said: > Yes. I tested with two keys, a KSK and a ZSK and the warning > disappears. Another solution, even if using only one key, is to add: update-policy local; # Necessary, says the ARM (

Re: "auto-dnssec maintain; " and key "missing or inactive and has no replacement"

2013-07-26 Thread Tony Finch
On 26 Jul 2013, at 07:52, Stephane Bortzmeyer wrote: > On Thu, Jul 25, 2013 at 12:05:35AM +0100, > Tony Finch wrote > a message of 21 lines which said: > >> Does the zone have only one key which is a KSK? > > Yes. I tested with two keys, a KSK and a ZSK and the warning > disappears. Do you me

Re: "auto-dnssec maintain;" and key "missing or inactive and has no replacement"

2013-07-26 Thread Stephane Bortzmeyer
On Fri, Jul 26, 2013 at 08:54:26AM +0200, Stephane Bortzmeyer wrote a message of 23 lines which said: > I just tried, and same warning: But only at startup and not afterwards so it is an improvment. ___ Please visit https://lists.isc.org/mailman/lis