Deleted Added
full compact
HISTORY (225736) HISTORY (254897)
1Summary of functional enhancements from prior major releases of BIND 9:
2
1Summary of functional enhancements from prior major releases of BIND 9:
2
3BIND 9.8.0
4
5 BIND 9.8.0 includes a number of changes from BIND 9.7 and earlier
6 releases. New features include:
7
8 - Built-in trust anchor for the root zone, which can be
9 switched on via "dnssec-validation auto;"
10 - Support for DNS64.
11 - Support for response policy zones (RPZ).
12 - Support for writable DLZ zones.
13 - Improved ease of configuration of GSS/TSIG for
14 interoperability with Active Directory
15 - Support for GOST signing algorithm for DNSSEC.
16 - Removed RTT Banding from server selection algorithm.
17 - New "static-stub" zone type.
18 - Allow configuration of resolver timeouts via
19 "resolver-query-timeout" option.
20 - The DLZ "dlopen" driver is now built by default.
21 - Added a new include file with function typedefs
22 for the DLZ "dlopen" driver.
23 - Made "--with-gssapi" default.
24 - More verbose error reporting from DLZ LDAP.
25
26BIND 9.7.0
27
28 BIND 9.7.0 includes a number of changes from BIND 9.6 and earlier
29 releases. Most are intended to simplify DNSSEC configuration.
30
31 New features include:
32
33 - Fully automatic signing of zones by "named".
34 - Simplified configuration of DNSSEC Lookaside Validation (DLV).
35 - Simplified configuration of Dynamic DNS, using the "ddns-confgen"
36 command line tool or the "local" update-policy option. (As a side
37 effect, this also makes it easier to configure automatic zone
38 re-signing.)
39 - New named option "attach-cache" that allows multiple views to
40 share a single cache.
41 - DNS rebinding attack prevention.
42 - New default values for dnssec-keygen parameters.
43 - Support for RFC 5011 automated trust anchor maintenance
44 - Smart signing: simplified tools for zone signing and key
45 maintenance.
46 - The "statistics-channels" option is now available on Windows.
47 - A new DNSSEC-aware libdns API for use by non-BIND9 applications
48 - On some platforms, named and other binaries can now print out
49 a stack backtrace on assertion failure, to aid in debugging.
50 - A "tools only" installation mode on Windows, which only installs
51 dig, host, nslookup and nsupdate.
52 - Improved PKCS#11 support, including Keyper support and explicit
53 OpenSSL engine selection.
54
3BIND 9.6.0
4
5 Full NSEC3 support
6
7 Automatic zone re-signing
8
9 New update-policy methods tcp-self and 6to4-self
10

--- 303 unchanged lines hidden ---
55BIND 9.6.0
56
57 Full NSEC3 support
58
59 Automatic zone re-signing
60
61 New update-policy methods tcp-self and 6to4-self
62

--- 303 unchanged lines hidden ---