Re: named.rfc1912.zones + named.root.key

Greg Choules via bind-users <[email protected]> Thu, 28 May 2026 09:24:41 +0100
Newsgroups gmane.network.dns.bind.user
Message-ID <CANsEUy16+M+F=u31s4DJqdM-x92mAS4ovW8+h18eZBY-zSiQow@mail.gmail.com>
--===============2957112193439279516==
Content-Type: multipart/alternative; boundary="00000000000059a6bc0652dc7698"

--00000000000059a6bc0652dc7698
Content-Type: text/plain; charset="UTF-8"

Package naming is always difficult. Naming things is hard, as they say. It
just so happens that 9.18 has the ESV label at the moment. But, as you
read, 9.18 has nearly had its day, 9.22 is suspended for now and so 9,20
will be maintained for a while. Therefore 9.20 is the best choice right
now. Not only because it is current but also because it is the focus for
vulnerability fixes. Please follow the KB instructions and install the
latest 9.20.

As a side note, people will not stop trying to help - depending on the
issue - however old is your BIND version; if, for instance; you wanted to
know more about a specific statement. But if issues look security-related,
the initial advice will always be to upgrade to the latest release first
and see if the problem still exists.

Cheers, Greg

On Thu, 28 May 2026 at 08:42, Renzo Marengo <[email protected]> wrote:

> >This explains how to obtain ISC official packages
> https://kb.isc.org/docs/isc-packages-for-bind-9#open-source-packages
> >You should consider 9.20 because of this:
> https://www.isc.org/blogs/2026-05-12-bind-security-updates/
>
> So you suggest to migrate from ESV-BIND to BIND (rpm 9.20.23)  ?
> I chose ESV bind because it has life cycle longer than stable bind
> Link, which you indicated, says It will end maintenance for 9.18 and
> 9.18-S at the end of June 2026 and efforts will be fixed efforts on
> vulnerabilities in the 9.20 and 9.21 branches.
> Do you know when 9.20 rpm esv-bind  will be available ?
>
> Il giorno gio 28 mag 2026 alle ore 08:58 Greg Choules
> <[email protected]> ha scritto:
> >
> > As I said, 9.11.4 is so very old, many changes have happened since then
> so please don't get hung up on two files.
> >
> > This explains how to obtain ISC official packages
> https://kb.isc.org/docs/isc-packages-for-bind-9#open-source-packages
> > You should consider 9.20 because of this:
> https://www.isc.org/blogs/2026-05-12-bind-security-updates/
> >
> > I hope that helps.
> >
> > On Thu, 28 May 2026 at 07:43, Renzo Marengo <[email protected]>
> wrote:
> >>
> >> I'm using "ESV" Bind version, the rpm package dedicated for
> >> RHEL-compatible doesn't contains these 2 files and someone says
> >> depends on packaging worker of repository.
> >> Why should I use 9.20.23 version ?
> >>
> >>
> >> Il giorno gio 28 mag 2026 alle ore 08:08 Greg Choules
> >> <[email protected]> ha scritto:
> >> >
> >> > Hello Renzo.
> >> >
> >> > There have been so many changes since 9.11.4 I would suggest that you
> don't get hung up on a couple of files. If you are installing 9.18.49 as a
> package, it will contain everything it needs.
> >> > I would recommend that, if you are planning a jump from 9.11 anyway,
> that you consider 9.20.23 rather than 9.19.49.
> >> >
> >> > Regards, Greg
> >> >
> >> > On Thu, 28 May 2026 at 07:00, Renzo Marengo <[email protected]>
> wrote:
> >> >>
> >> >> in Alma Linux 9 I have decide to migrate to latest ISC-Bind (rpm
> package) which is 9.18.49 version (Copr/Epel 9 repository)
> >> >> Previous bind 9.11.4 contains these 'include' entries:
> >> >>
> >> >> named.rfc1912.zones
> >> >> named.root.key
> >> >>
> >> >> These files don't exist inside isc-bind rpm packages
> >> >> I think the former is about default zones (e.g. localhost) the
> latter is about dnssec keys.
> >> >>
> >> >> I'd like using standard files according to isc-bind documents.
> >> >> How should I proceed ?
> >> >>
> >> >> Thanks
> >> >>
> >> >>
> >> >> --
> >> >> Visit https://lists.isc.org/mailman/listinfo/bind-users to
> unsubscribe from this list.
>

--00000000000059a6bc0652dc7698
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Package naming is always difficult. Naming things is =
hard, as they say. It just so happens that 9.18 has the ESV label at the mo=
ment. But, as you read, 9.18 has nearly had its day, 9.22 is suspended for =
now=C2=A0and so 9,20 will be maintained for a while. Therefore 9.20 is the =
best choice right now. Not only because it is current but also because it i=
s the focus for vulnerability fixes. Please follow the KB instructions and =
install the latest 9.20.</div><div><br></div><div>As a side note, people wi=
ll not stop trying to help - depending on the issue - however old is your B=
IND version; if, for instance; you wanted to know more about a specific sta=
tement. But if issues look security-related, the initial advice will always=
 be to upgrade to the latest release first and see if the problem still exi=
sts.</div><div><br></div><div>Cheers, Greg</div></div><br><div class=3D"gma=
il_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Th=
u, 28 May 2026 at 08:42, Renzo Marengo &lt;<a href=3D"mailto:buckroger2011@=
gmail.com">[email protected]</a>&gt; wrote:<br></div><blockquote clas=
s=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid r=
gb(204,204,204);padding-left:1ex">&gt;This explains how to obtain ISC offic=
ial packages <a href=3D"https://kb.isc.org/docs/isc-packages-for-bind-9#ope=
n-source-packages" rel=3D"noreferrer" target=3D"_blank">https://kb.isc.org/=
docs/isc-packages-for-bind-9#open-source-packages</a><br>
&gt;You should consider 9.20 because of this: <a href=3D"https://www.isc.or=
g/blogs/2026-05-12-bind-security-updates/" rel=3D"noreferrer" target=3D"_bl=
ank">https://www.isc.org/blogs/2026-05-12-bind-security-updates/</a><br>
<br>
So you suggest to migrate from ESV-BIND to BIND (rpm 9.20.23)=C2=A0 ?<br>
I chose ESV bind because it has life cycle longer than stable bind<br>
Link, which you indicated, says It will end maintenance for 9.18 and<br>
9.18-S at the end of June 2026 and efforts will be fixed efforts on<br>
vulnerabilities in the 9.20 and 9.21 branches.<br>
Do you know when 9.20 rpm esv-bind=C2=A0 will be available ?<br>
<br>
Il giorno gio 28 mag 2026 alle ore 08:58 Greg Choules<br>
&lt;<a href=3D"mailto:gregchoules%[email protected]" target=3D"_bl=
ank">[email protected]</a>&gt; ha scritto:<br>
&gt;<br>
&gt; As I said, 9.11.4 is so very old, many changes have happened since the=
n so please don&#39;t get hung up on two files.<br>
&gt;<br>
&gt; This explains how to obtain ISC official packages <a href=3D"https://k=
b.isc.org/docs/isc-packages-for-bind-9#open-source-packages" rel=3D"norefer=
rer" target=3D"_blank">https://kb.isc.org/docs/isc-packages-for-bind-9#open=
-source-packages</a><br>
&gt; You should consider 9.20 because of this: <a href=3D"https://www.isc.o=
rg/blogs/2026-05-12-bind-security-updates/" rel=3D"noreferrer" target=3D"_b=
lank">https://www.isc.org/blogs/2026-05-12-bind-security-updates/</a><br>
&gt;<br>
&gt; I hope that helps.<br>
&gt;<br>
&gt; On Thu, 28 May 2026 at 07:43, Renzo Marengo &lt;<a href=3D"mailto:buck=
[email protected]" target=3D"_blank">[email protected]</a>&gt; wrot=
e:<br>
&gt;&gt;<br>
&gt;&gt; I&#39;m using &quot;ESV&quot; Bind version, the rpm package dedica=
ted for<br>
&gt;&gt; RHEL-compatible doesn&#39;t contains these 2 files and someone say=
s<br>
&gt;&gt; depends on packaging worker of repository.<br>
&gt;&gt; Why should I use 9.20.23 version ?<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt; Il giorno gio 28 mag 2026 alle ore 08:08 Greg Choules<br>
&gt;&gt; &lt;<a href=3D"mailto:gregchoules%[email protected]" targ=
et=3D"_blank">[email protected]</a>&gt; ha scritto:<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; Hello Renzo.<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; There have been so many changes since 9.11.4 I would suggest =
that you don&#39;t get hung up on a couple of files. If you are installing =
9.18.49 as a package, it will contain everything it needs.<br>
&gt;&gt; &gt; I would recommend that, if you are planning a jump from 9.11 =
anyway, that you consider 9.20.23 rather than 9.19.49.<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; Regards, Greg<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; On Thu, 28 May 2026 at 07:00, Renzo Marengo &lt;<a href=3D"ma=
ilto:[email protected]" target=3D"_blank">[email protected]</a>=
&gt; wrote:<br>
&gt;&gt; &gt;&gt;<br>
&gt;&gt; &gt;&gt; in Alma Linux 9 I have decide to migrate to latest ISC-Bi=
nd (rpm package) which is 9.18.49 version (Copr/Epel 9 repository)<br>
&gt;&gt; &gt;&gt; Previous bind 9.11.4 contains these &#39;include&#39; ent=
ries:<br>
&gt;&gt; &gt;&gt;<br>
&gt;&gt; &gt;&gt; named.rfc1912.zones<br>
&gt;&gt; &gt;&gt; named.root.key<br>
&gt;&gt; &gt;&gt;<br>
&gt;&gt; &gt;&gt; These files don&#39;t exist inside isc-bind rpm packages<=
br>
&gt;&gt; &gt;&gt; I think the former is about default zones (e.g. localhost=
) the latter is about dnssec keys.<br>
&gt;&gt; &gt;&gt;<br>
&gt;&gt; &gt;&gt; I&#39;d like using standard files according to isc-bind d=
ocuments.<br>
&gt;&gt; &gt;&gt; How should I proceed ?<br>
&gt;&gt; &gt;&gt;<br>
&gt;&gt; &gt;&gt; Thanks<br>
&gt;&gt; &gt;&gt;<br>
&gt;&gt; &gt;&gt;<br>
&gt;&gt; &gt;&gt; --<br>
&gt;&gt; &gt;&gt; Visit <a href=3D"https://lists.isc.org/mailman/listinfo/b=
ind-users" rel=3D"noreferrer" target=3D"_blank">https://lists.isc.org/mailm=
an/listinfo/bind-users</a> to unsubscribe from this list.<br>
</blockquote></div>

--00000000000059a6bc0652dc7698--

--===============2957112193439279516==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list.

--===============2957112193439279516==--