Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | main/bind: add previous ISC signing key | tcely | 2019-08-23 | 1 | -2/+6 |
| | | | | | | | | | | | | | Without this TOFU unknown entry, a release signed with the older key prompts for a trust decision. Avoiding the prompt is desirable. Also, format GPG details so they are easier to check manually. Used: $ gpg --verify bind-*.asc bind-*.tar.gz $ awk \ '/gpgfingerprints=/,/(^|[^=])["'\'']$/ {print;}' \ APKBUILD | ||||
* | main/bind: downloads.isc.org | tcely | 2019-08-08 | 1 | -1/+1 |
| | | | Closes GH-9961 | ||||
* | main/bind: security upgrade to 9.14.4 (CVE-2019-6471) | Leonardo Arena | 2019-08-08 | 1 | -2/+4 |
| | | | | Fixes #10626 | ||||
* | main/bind: split dnssec-tools and py3-bind | Natanael Copa | 2019-05-02 | 1 | -3/+23 |
| | | | | | | | | move python modules and dnssec-tools to separate subpackages so we avoid install python3 by default. py3-bind may be useful separately for python scripts so lets separate out that as well. | ||||
* | main/bind: become maintainer | tcely | 2019-04-30 | 1 | -1/+2 |
| | |||||
* | main/bind: security upgrade to 9.14.1 | tcely | 2019-04-30 | 1 | -2/+8 |
| | | | | | | | - CVE-2019-6467 - CVE-2018-5743 fixes #10367 | ||||
* | main/bind: upgrade to 9.14.0 | tcely | 2019-04-30 | 2 | -37/+84 |
| | |||||
* | main/bind: clear depends for libs subpackage | Sören Tempel | 2019-04-09 | 1 | -1/+6 |
| | | | | | | | | | | | Otherwise the dev and tools subpackages install dns-root-hints (since both depend on the libs subpackage) even though they shouldn't need it. Discussion: Unfortunately, abuild doesn't have a depends_libs variable thus we need to define a custom libs function to clear the dependency. This approach is also used by other abuilds, e.g. testing/boinc. See also: 4badc1aa803f5dd0f67d2df3004acc3f990ba23f | ||||
* | main/bind: fix slow start | Henrik Riomar | 2019-04-08 | 2 | -3/+3 |
| | | | | | named-checkconf needs entropy to start, or else it will take up to a minute to start at boot. | ||||
* | main/bind: remove unrecognized configure flag | tcely | 2019-04-08 | 1 | -1/+0 |
| | |||||
* | main/bind: security upgrade to 9.12.3-P4 | tcely | 2019-04-08 | 1 | -3/+7 |
| | | | | | | - CVE-2019-6465 - CVE-2018-5745 - CVE-2018-5744 | ||||
* | main/bind: add and use -dnssec-root subpackage | tcely | 2019-04-08 | 1 | -1/+19 |
| | |||||
* | main/bind: use dns-root-hints | tcely | 2019-04-08 | 2 | -98/+4 |
| | |||||
* | main/bind: named.ca cleanup white-space warnings | tcely | 2019-02-06 | 2 | -26/+26 |
| | |||||
* | main/bind: upgrade named.ca to 2018111402 | tcely | 2019-02-06 | 2 | -43/+50 |
| | |||||
* | main/bind: upgrade to 9.12.3-P1 | tcely | 2019-02-06 | 1 | -2/+2 |
| | | | | https://kb.isc.org/docs/dnssec-key-deletion-may-create-broken-nsec-and-nsec3-chains-and-unnecessary-rrsigs | ||||
* | main/bind: Upgrade to 9.12.3 | Taner Tas | 2018-11-29 | 1 | -7/+19 |
| | | | | | | * Add "--disable-isc-spnego" to use gss-spnego instead. fixes #9462 | ||||
* | main/bind: rebuild against openssl 1.1 | Natanael Copa | 2018-11-07 | 1 | -2/+2 |
| | |||||
* | main/bind: add secfixes comment | tcely | 2018-08-28 | 1 | -0/+3 |
| | |||||
* | main/bind: Upgrade to 9.12.2-P1, enable DLZ and kerberos | Taner Tas | 2018-08-16 | 2 | -66/+18 |
| | | | | | | * Enable DLZ (Dynamically Loadable Zones) support with file system, ldap, stub backends * Enable GSSAPI/Kerberos support * Re-arrange configure options | ||||
* | main/bind: security upgrade to 9.12.1_p2 | Jakub Jirutka | 2018-05-22 | 1 | -3/+6 |
| | |||||
* | main/[various]: properly rebuild against json-c-0.13 | Natanael Copa | 2018-04-19 | 1 | -1/+1 |
| | |||||
* | main/bind: rebuild against json-c-0.13 | Natanael Copa | 2018-04-19 | 1 | -1/+1 |
| | |||||
* | main/bind: rebuild against libressl-2.7 | Natanael Copa | 2018-04-06 | 3 | -6/+59 |
| | |||||
* | main/bind: upgrade to 9.12.0 and modernize abuild | tcely | 2018-03-02 | 1 | -32/+25 |
| | |||||
* | main/bind: Split OpenRC scripts, disable check | A. Wilcox | 2018-02-26 | 1 | -2/+6 |
| | |||||
* | main/bind: Upgrade to 9.11.2-P1 | tcely | 2018-02-06 | 1 | -3/+5 |
| | |||||
* | main/bind: enable json statistics | Jared Szechy | 2017-12-15 | 1 | -2/+3 |
| | |||||
* | main/bind: rebuild against libressl-2.6 | Natanael Copa | 2017-11-09 | 1 | -1/+1 |
| | |||||
* | main/bind: upgrade to 9.11.2 | Natanael Copa | 2017-10-31 | 1 | -3/+3 |
| | |||||
* | main/bind: bump pkgrel | Natanael Copa | 2017-08-08 | 1 | -1/+1 |
| | | | | bump pkgrel to avoid mismatch with caches | ||||
* | Revert "main/bind: fix for CVE-2017-3142 and CVE-2017-3143. Fixes #7496" | Francesco Colista | 2017-08-07 | 2 | -291/+2 |
| | | | | This reverts commit 724d3ef9cc4c309dc09e750d37ca4cb86b32df85. | ||||
* | main/bind: fix for CVE-2017-3142 and CVE-2017-3143. Fixes #7496 | Francesco Colista | 2017-08-07 | 2 | -2/+291 |
| | |||||
* | main/bind: upgrade to 9.11.1_p2 | Natanael Copa | 2017-07-06 | 1 | -2/+2 |
| | |||||
* | main/bind: security upgrade to 9.11.1_p1 (CVE-2017-3140) | Natanael Copa | 2017-06-16 | 1 | -2/+2 |
| | | | | fixes #7437 | ||||
* | main/bind: upgrade to 9.11.1 | Natanael Copa | 2017-06-14 | 1 | -3/+3 |
| | |||||
* | main/bind: rebuild against libressl 2.5 | Natanael Copa | 2017-04-18 | 1 | -1/+1 |
| | |||||
* | main/bind: security upgrade to 9.11.0_p5 - fixes #7141 | Sergey Lukin | 2017-04-14 | 1 | -2/+6 |
| | | | | | | CVE-2017-3136: An error handling synthesized records could cause an assertion failure when using DNS64 with "break-dnssec yes;" CVE-2017-3137: A response packet can cause a resolver to terminate when processing an answer containing a CNAME or DNAME CVE-2017-3138: named exits with a REQUIRE assertion failure if it receives a null command string on its control channel | ||||
* | main/bind: security upgrade to 9.11.0_p3 (CVE-2017-3135) | Natanael Copa | 2017-02-09 | 1 | -21/+3 |
| | | | | fixes #6828 | ||||
* | main/bind: dont create homedir for bind user | Natanael Copa | 2017-01-24 | 2 | -2/+2 |
| | | | | | We dont want copy the content of /etc/skel to /etc/bind ref #6725 | ||||
* | main/bind: Upgrade to 9.11.0-P2. | Przemyslaw Pawelczyk | 2017-01-17 | 1 | -4/+4 |
| | | | | | | | | | | | | | | https://www.isc.org/downloads/bind/bind-9-11-new-features/ https://deepthought.isc.org/article/AA-01446/0/BIND-9.11.0-P2-Release-Notes.html https://kb.isc.org/article/AA-00913/74/BIND-9-Security-Vulnerability-Matrix.html Release notes mention addressing issue described in: CVE-2016-9778: An error handling certain queries using the nxdomain-redirect feature could cause a REQUIRE assertion failure in db.c but it's not present in 9.10.x, so it's not a security upgrade. | ||||
* | main/bind: security upgrade to 9.10.4_p5 - fixes #6675 | Sergei Lukin | 2017-01-13 | 1 | -8/+15 |
| | | | | | | CVE-2016-9131: A malformed response to an ANY query can cause an assertion failure during recursion CVE-2016-9147: An error handling a query response containing inconsistent DNSSEC information could cause an assertion failure CVE-2016-9444: An unusually-formed DS record response could cause an assertion failure | ||||
* | main/bind: security upgrade to 9.10.4_p4 (CVE-2016-8864) | Natanael Copa | 2016-11-02 | 1 | -5/+5 |
| | |||||
* | main/bind: rebuild against libressl | Natanael Copa | 2016-10-10 | 1 | -2/+2 |
| | |||||
* | main/bind: security upgrade to 9.10.4_p3 (CVE-2016-2776) | Natanael Copa | 2016-09-28 | 1 | -4/+4 |
| | | | | fixes #6223 | ||||
* | main/bind: security upgrade to 9.10.4_p2 (CVE-2016-2775) | Natanael Copa | 2016-07-25 | 1 | -5/+5 |
| | | | | fixes #5951 | ||||
* | main/bind: rebuild with libxml2. Fixes #5711 | Francesco Colista | 2016-06-27 | 1 | -3/+3 |
| | |||||
* | main/bind: upgrade to 9.10.4_p1 | Natanael Copa | 2016-05-27 | 1 | -5/+5 |
| | |||||
* | main/bind: upgrade to 9.10.4 | Natanael Copa | 2016-05-16 | 1 | -5/+5 |
| | |||||
* | main/[various]: bump pkgrel for pre-install fixes | Przemyslaw Pawelczyk | 2016-04-25 | 1 | -1/+1 |
| |