NSD 4.2.0 released

Wouter Wijngaards <[email protected]>
Newsgroups gmane.network.dns.nsd.general
Message-ID <[email protected]>
Hi,

NSD 4.2.0 is available:
https://www.nlnetlabs.nl/downloads/nsd/nsd-4.2.0.tar.gz
sha256 51df1ca44a00e588c09ff0696e588c13566ce889b50d953896d8b6e507eda74c
pgp https://www.nlnetlabs.nl/downloads/nsd/nsd-4.2.0.tar.gz.asc


This release contains new features, contributed from Sinodun, that
implement TCP fast open support and also support for service on DNS over
TLS.

There is also TLS OCSP stapling support with the tls-service-ocsp option
in nsd.conf.

The new option hide-identity can be used in nsd.conf to stop NSD from
responding with the hostname for probe queries that elicit the chaos
class response, this is conform RFC4892.

There is a bug fix for memory leaks during zone file read, with
duplicate records in the zone file.


4.2.0
================
FEATURES:
- Print IP address when bind socket fails with error.
- Fix #4249: The option hide-identity: yes stops NSD from responding
  with the hostname for chaos class queries.  Implements the RFC4892
  security considerations.
- Patch to add support for TCP Fast Open, from Sara
  Dickinson (Sinodun).
- Patch to add support for tls service on a specified tls port,
  from Sara Dickinson (Sinodun).
- Use travis for build check, initial unit test and clang analysis.
- TLS OCSP stapling support, enabled with tls-service-ocsp: filename,
  patch from Andreas Schulze.

BUG FIXES:
- Fix to delete unused zparser.default_apex member.
- Fix that the TLS handshake routine sets the correct event to
  continue when done.
- Fix that TLS renegotiation calls the read and write routines again
  with the same parameters when the desired event has been satisfied.
- Fix that TCP Fastopen has better error message and supports OSX.
- Fix to avoid buffer alloc with global buffer in tls write handler.
- Fix to initialize event structure when accepting TCP connection.
- Disable TLS1.0, TLS1.1 and weak ciphers, enable
  CIPHER_SERVER_PREFERENCE, patch from Andreas Schulze.
- further setup ssl ctx after the keys are loaded, for ECDH.
- Fix #10: Fix memory leaks caused by duplicate rr and include
  instructions.
- Fix to define _OPENBSD_SOURCE to get reallocarray on NetBSD.


Best regards, Wouter

_______________________________________________
nsd-users mailing list
[email protected]
https://open.nlnetlabs.nl/mailman/listinfo/nsd-users
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE7fqj8spObrBWga+On28cLX4EX40FAlz/oxgACgkQn28cLX4E
X41V2A/+LASnpRkEV3SEjtGVKBGv3FUDk/UM+wh5XwQYdgwgHni4dhepYp/B2bq6
EhcXfh25kMtBH3FdZQYAvMNy06gFBtcFQCYGSPlOYQOV+Dui9J7mgRJr1Os3AXLL
3keyYx4IzqX58SHuptGOzXuwX8ZzCItZ87N2mHCrINyvu0uSIho+0OJS+OVuYF4c
PWBNQoKNoENAVFOahhibEbtMHr5ZrUWeTAb6rk2ccdmbCP5po90w0OyNyysGGSYl
/EdsjVs8zd7Yir2+lZ3/Zc++OYk7//HQ/Q4/deD0NlcSyAJSThEZYzGt22QCLOXS
o7aHasD5ZJioDfELscTe+rIu4HcStM0Cw0+eA665/1bLF+iMIZUJgJl518fVyC3k
z8j1J0QS2n/O16/V70nJDq4J2/I7LhOyMBWSVvyvmGQGlMLIZoriTwTO8vF+CTJY
z6Wh64E/Y5PZytlbhdXryOfTTD+w2ygiT267a65DiTG0gqBij1ZmXMIvTPqL291J
UN5s/7zbsmTH20ZSnYSDh8aNbi2IaWpd5MWFsYETg/DypyoK/Td0ciAFhszKE/3Q
uNKj8zGS/fAFzK9+T0f+CEeWT7aABRLSIAw27Dqiyv+Wub8kTRsEckeUfKBFvNAv
cBAQdxtg6FssA5Yzrw+40Ii7s+pTEir9s+MkDde/R+QA0485LGg=
=q8xY
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.