Reminder about DLV, BIND 9.6.0 and BIND 9.6.0-P1

2010-03-11 Thread Mark Andrews
DLV records for TLD's signed using RASSHA256 (and RSASHA512) will be added DLV.ISC.ORG in the next few days. BIND 9.6.0 and BIND 9.6.0-P1 do not correctly handle these records and it is recommended that you upgrade to BIND 9.6.1 or later. Thi

Re: Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2010-01-14 Thread Doug Barton
On 1/14/2010 8:11 AM, Evan Hunt wrote: >>> We hear you. Expect a decision in the next few days. >> >> So, has the decision been made? >> >> [I am tentatively planning on going to 9.7 in production round about Easter, >> in good time for the RSASHA256-signed root zone in July, but it would be >> ni

Re: Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2010-01-14 Thread Evan Hunt
> >We hear you. Expect a decision in the next few days. > > So, has the decision been made? > > [I am tentatively planning on going to 9.7 in production round about Easter, > in good time for the RSASHA256-signed root zone in July, but it would be > nice to have a fall-back option.] I'm sorry,

Re: Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2010-01-14 Thread Chris Thompson
On Dec 15 2009, Evan Hunt wrote: (Doug Barton wrote) BIND 9.6.2 is in the "b1" phase atm, which means that there is plenty of time to get SHA2 in there and get the release out before a signed root goes live. I encourage the folks at ISC to do so, and if you agree I encourage you to make your vo

Re: Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2009-12-15 Thread Mark Andrews
In message , Chris Tho mpson writes: > (But it's not too obvious to me that adding support for a new signing > algorithm should necessarily be considered a "major functional change".) If it was *just* adding a new signing algorithm then yes it would be a minor change. A lot more happened under t

Re: Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2009-12-15 Thread Evan Hunt
> BIND 9.6.2 is in the "b1" phase atm, which means that there is plenty > of time to get SHA2 in there and get the release out before a signed > root goes live. I encourage the folks at ISC to do so, and if you > agree I encourage you to make your voice heard. We hear you. Expect a decision in th

Re: Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2009-12-15 Thread Doug Barton
Evan Hunt wrote: >> BIND 9.6.2 is in the "b1" phase atm, which means that there is plenty >> of time to get SHA2 in there and get the release out before a signed >> root goes live. I encourage the folks at ISC to do so, and if you >> agree I encourage you to make your voice heard. > > We hear you.

Re: Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2009-12-15 Thread Doug Barton
Chris Thompson wrote: > (Evan Hunt) >> Adding SHA-2 to 9.6.x would violate our policy of making major >> functional changes only in major releases, so I don't expect we'll >> do that. Given the odd circumstances you mentioned, I won't say for >> certain that we won't--but I doubt it. >> >> 9.7.0 i

Re: Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2009-12-15 Thread Stephane Bortzmeyer
On Mon, Dec 14, 2009 at 08:05:40PM -0800, Doug Barton wrote a message of 44 lines which said: > While this reminder is timely and helpful, more welcome would be the > news that BIND 9.6.2 is going to have actual support for > RSASHA{256|512}. No, it won't. Migrating to >= 9.6.1 is necessary t

Re: Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2009-12-15 Thread Chris Thompson
On Dec 15 2009, Doug Barton wrote: While this reminder is timely and helpful, more welcome would be the news that BIND 9.6.2 is going to have actual support for RSASHA{256|512}. My cursory reading of the 9.6.2b1 code does not seem to indicate that it does, although I would be happy to be proven

Re: Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2009-12-14 Thread Doug Barton
keover!http://SupersetSolutions.com/ Mark Andrews wrote: > With upcoming deployment of RSASHA256 to sign the root zone, ISC > would like to remind BIND 9.6.0 and BIND 9.6.0-P1 users that use > DLV, but have not yet upgraded, that they will need to upgrade to > a more recent version of BIND 9.6.x as B

Handling of RSASHA256 and RSASHA512 in BIND 9.6.0 and BIND 9.6.0-P1

2009-12-14 Thread Mark Andrews
With upcoming deployment of RSASHA256 to sign the root zone, ISC would like to remind BIND 9.6.0 and BIND 9.6.0-P1 users that use DLV, but have not yet upgraded, that they will need to upgrade to a more recent version of BIND 9.6.x as BIND 9.6.0 and BIND 9.6.0-P1 will not correctly handle

rndcstats.pl for bind-9.6.0-P1

2009-05-29 Thread Hossein . Ahmadi
Hello All, Is there a new version of rndcstats.pl available for bind-9.6.0-P1? Regards, Hossein Ahmadi Verizon Wireless The information contained in this message and any attachment may be proprietary, confidential, and privileged or subject to the work product doctrine and thus

"Malformed Transaction" after thawing large zone with lots of DDNS updates / BIND 9.6.0-P1

2009-05-19 Thread ip admin
d transaction'. After this point DDNS updates don't work any more. Is named supposed to process DDNS updates after receiving the thaw command but before completely loading the zone file ? This is with BIND 9.6.0-P1 on Solaris 10. Regards, Tom ___

Re: BIND 9.6.0-P1

2009-03-25 Thread Danny Mayer
Carl Fretwell wrote: > Hi Everyone > > > > I have installed BIND 9.6.0-P1 on a Windows Server 2003 x64 system but > when I come to start the “ISC BIND” service I always get a 1067 error > which I read somewhere was due to permissions so made sure the user > account

BIND 9.6.0-P1

2009-03-20 Thread Carl Fretwell
Hi Everyone I have installed BIND 9.6.0-P1 on a Windows Server 2003 x64 system but when I come to start the "ISC BIND" service I always get a 1067 error which I read somewhere was due to permissions so made sure the user account password etc was correct still didn't fix the is

Re: bind 9.6.0-P1's nsupdate dumps core on NetBSD/i386 4.x

2009-03-05 Thread Mark Andrews
In message , Ray Phillips writes: > > You need to call gdb correctly. > > > > gdb /usr/local/bin/nsupdate nsupdate.core > > Thanks Mark. > > Sorry, I (obviously) don't have much of a clue about using gdb. Looks like you have hit this bug. 2547. [bug] openssl_link.c:

Re: bind 9.6.0-P1's nsupdate dumps core on NetBSD/i386 4.x

2009-03-05 Thread Ray Phillips
at openssl_link.c:251 #11 0x080b9e10 in dst_lib_init (mctx=0x817, ectx=0x8184000, eflags=0) at dst_api.c:183 #12 0x0804c43a in main (argc=Cannot access memory at address 0x2 ) at nsupdate.c:772 (gdb) quit % I just built and installed bind-9.6.0-P1 on NetBSD/i386 4.0 and nsupdate doesn't

Re: bind 9.6.0-P1's nsupdate dumps core on NetBSD/i386 4.x

2009-03-05 Thread Jeremy C. Reed
> I've built bind 9.6.0-P1 on NetBSD/i386 machines (versions 3.1, 4.0, > 4.0.1 and 5.0_RC2) and discovered that nsupdate dumps core on the 4.x > ones. I just built and installed bind-9.6.0-P1 on NetBSD/i386 4.0 and nsupdate doesn't crash for me. (Built with default pthread a

Re: bind 9.6.0-P1's nsupdate dumps core on NetBSD/i386 4.x

2009-03-05 Thread Mark Andrews
In message , Ray Phillips writes: > I've built bind 9.6.0-P1 on NetBSD/i386 machines (versions 3.1, 4.0, > 4.0.1 and 5.0_RC2) and discovered that nsupdate dumps core on the 4.x > ones. > > The build process was just: > > % sh -c './configure --disable-threads

bind 9.6.0-P1's nsupdate dumps core on NetBSD/i386 4.x

2009-03-04 Thread Ray Phillips
I've built bind 9.6.0-P1 on NetBSD/i386 machines (versions 3.1, 4.0, 4.0.1 and 5.0_RC2) and discovered that nsupdate dumps core on the 4.x ones. The build process was just: % sh -c './configure --disable-threads > configure.log 2>&1' % sh -c 'make > make.log 2

Re: BIND 9.6.0-P1 on windows server 2008 32 bit hangs

2009-01-26 Thread Danny Mayer
own. In the meantime, please file a bug report on this with bind9-b...@isc.org. Danny > > -Original Message- > From: Danny Mayer [mailto:ma...@gis.net] > Sent: Monday, January 26, 2009 4:49 AM > To: Kobi Shachar > Cc: bind-users@lists.isc.org > Subject: Re: BIND 9.6

Re: BIND 9.6.0-P1 on windows server 2008 32 bit hangs

2009-01-26 Thread Danny Mayer
Danny Mayer wrote: > Kobi Shachar wrote: >> Recently I upgraded my bind machine to a new windows 2008 server web >> edition 32 bit with 2 E5420 quad core CPU's. >> >> The server is configured with about 7000 master zone files. >> >> >> >> Since the upgrade, BIND hangs every 5-10 hours. >> >> I ch

RE: BIND 9.6.0-P1 on windows server 2008 32 bit hangs

2009-01-25 Thread Kobi Shachar
onday, January 26, 2009 4:49 AM To: Kobi Shachar Cc: bind-users@lists.isc.org Subject: Re: BIND 9.6.0-P1 on windows server 2008 32 bit hangs Kobi Shachar wrote: > Recently I upgraded my bind machine to a new windows 2008 server web > edition 32 bit with 2 E5420 quad core CPU's. > > Th

Re: BIND 9.6.0-P1 on windows server 2008 32 bit hangs

2009-01-25 Thread Danny Mayer
Danny Mayer wrote: > Kobi Shachar wrote: >> Recently I upgraded my bind machine to a new windows 2008 server web >> edition 32 bit with 2 E5420 quad core CPU's. >> >> The server is configured with about 7000 master zone files. >> >> >> >> Since the upgrade, BIND hangs every 5-10 hours. >> >> I ch

Re: BIND 9.6.0-P1 on windows server 2008 32 bit hangs

2009-01-25 Thread Danny Mayer
Kobi Shachar wrote: > Recently I upgraded my bind machine to a new windows 2008 server web > edition 32 bit with 2 E5420 quad core CPU's. > > The server is configured with about 7000 master zone files. > > > > Since the upgrade, BIND hangs every 5-10 hours. > > I checked the logs and I saw th

BIND 9.6.0-P1 on windows server 2008 32 bit hangs

2009-01-25 Thread Kobi Shachar
Recently I upgraded my bind machine to a new windows 2008 server web edition 32 bit with 2 E5420 quad core CPU's. The server is configured with about 7000 master zone files. Since the upgrade, BIND hangs every 5-10 hours. I checked the logs and I saw these lines on the default log: 5-ינו-

Re: BIND 9.6.0-P1 is now available (rob_aust...@isc.org)

2009-01-07 Thread Andy Shellam
...@lists.isc.org] On Behalf Of bsfin...@anl.gov Sent: Thursday, 8 January 2009 9:15 AM To: bind-users@lists.isc.org Subject: Re: BIND 9.6.0-P1 is now available (rob_aust...@isc.org) Echoing a complaint made recently -- I saw the announcements of the -P1 patch for the various supported versions of BIND via

RE: BIND 9.6.0-P1 is now available (rob_aust...@isc.org)

2009-01-07 Thread Jason Mitchell
9.6.0-P1 is now available (rob_aust...@isc.org) Echoing a complaint made recently -- I saw the announcements of the -P1 patch for the various supported versions of BIND via the bind-users digest. I used to get them also via some -announce list at ISC, I do not remember the name, maybe bind-annou

Re: BIND 9.6.0-P1 is now available (rob_aust...@isc.org)

2009-01-07 Thread bsfinkel
Echoing a complaint made recently -- I saw the announcements of the -P1 patch for the various supported versions of BIND via the bind-users digest. I used to get them also via some -announce list at ISC, I do not remember the name, maybe bind-annou...@isc.org . And I noticed that the list archive

BIND 9.6.0-P1 is now available

2009-01-07 Thread Rob_Austein
BIND 9.6.0-P1 is now available. BIND 9.6.0-P1 is a SECURITY patch for BIND 9.6.0. It addresses a bug in which return values from some OpenSSL functions were left unchecked, making it theoretically possible to spoof answers from some signed zones. Bugs should be reported