Re: Rappel : vérifiez votre version de BIND avant la publication de la signature de .COM le 31 mars
Stephane Bortzmeyer <[email protected]>
| Newsgroups | gmane.network.dns.french |
|---|---|
| Organization | NIC France |
| Message-ID | <[email protected]> |
On Mon, Feb 07, 2011 at 10:10:38AM +0100, Emilio <[email protected]> wrote a message of 15 lines which said: > >https://www.isc.org/announcement/bind-9-dnssec-validation-fails-new-ds-record > > > > malheureusement la page est en accès "privé". Il faut avoir un > login. Oui, c'est une bavure (signalée à l'ISC). Ça marchait avant. > Sinon il faut passer par le cache de google :-( Pour ceux qui ne connaissent pas, voici le texte sauvegardé : BIND 9 DNSSEC Validation Fails on new DS record 04 Feb 2011 Problem Certain versions of BIND have a known bug which will cause DNSSEC validation errors when a new DS record is inserted into a trusted DNSSEC validation tree. This occurred when .NET was inserted into the root. These failures will cause BIND 9 to return SERVFAIL to queries under this newly inserted DS. When a DS record for .COM is inserted into the root on 31 March 2011, non-upgraded BIND 9 resolvers with DNSSEC validation enabled will have a high probability of being unable to successfully resolve .COM names unless they are restarted. DNSSEC is not new technology, but its widespread deployment and use have just begun recently. It is critical that operators using DNSSEC validation keep DNS servers and tools as up to date as possible. This issue was first found when .ARPA was signed, as described in Evan Hunt's blog from the time. Solution If you run a recursive resolver with an affected version of BIND, and are using or plan to use DNSSEC validation, you should upgrade to the most recent version available on the 9.6 branch or 9.7.x branch. * If you run 9.6.x or 9.6-ESV, you should install 9.6.3 or later. 9.6-ESV-R3 and prior will not give complete protection from this problem to DLV users. * If you run 9.7.x, you should install 9.7.2 or later. * If you run an earlier version of BIND, you should not enable DNSSEC validation until you upgrade to one of the above versions, or a newer version. If you are using DNSSEC validation, you should upgrade immediately. * If you do not use DNSSEC validation, and are not planning to use it, you do not need to upgrade. Workaround While there is no workaround to avoid this bug when using DNSSEC validation, restarting BIND once the server is affected will correct the issue. When another DS record is inserted, however, it may re-occur, requiring another restart. Credits ISC would like to thank Duane Wessels and Verisign for their work on diagnosing this issue, and verifying that current versions are unaffected. A detailed description of Verisign's analysis of this issue is available here. For more information on BIND, DNSSEC, and ISC's support, training, and consulting services which can help your organization navigate DNSSEC, please visit http://www.isc.org.