Port details |
- bind98 BIND DNS suite with updated DNSSEC and DNS64
- 9.8.8 dns
=11 9.8.8Version of this port present on the latest quarterly branch.
- DEPRECATED: Will be EOL as of September 2014.
This port expired on: 2014-09-30
- Maintainer: mat@FreeBSD.org
- Port Added: 2010-12-17 22:49:08
- Last Update: 2014-10-21 12:06:11
- SVN Revision: 371318
- People watching this port, also watch:: net-snmp, portmaster, rsync, postfix
- Also Listed In: ipv6 net
- License: ISCL
- WWW:
- https://www.isc.org/software/bind
- Description:
- BIND version 9 is a major rewrite of nearly all aspects of the underlying BIND
architecture. Some of the important features of BIND 9 are:
DNS Security: DNSSEC (signed zones), TSIG (signed DNS requests)
IP version 6: Answers DNS queries on IPv6 sockets, IPv6 resource records (AAAA)
Experimental IPv6 Resolver Library
DNS Protocol Enhancements: IXFR, DDNS, Notify, EDNS0
Improved standards conformance
Views: One server process can provide multiple "views" of the DNS namespace,
e.g. an "inside" view to certain clients, and an "outside" view to others.
Multiprocessor Support
BIND 9.8 includes a number of changes from BIND 9.7 and earlier releases,
including:
Preliminary DNS64 support (AAAA synthesis only initially)
See the CHANGES file for more information on features.
WWW: https://www.isc.org/software/bind
-
cgit ¦ GitHub ¦ GitHub ¦ GitLab ¦
- Manual pages:
- FreshPorts has no man page information for this port.
- pkg-plist: as obtained via:
make generate-plist - There is no configure plist information for this port.
- Dependency lines:
-
- No installation instructions:
- This port has been deleted.
- PKGNAME: bind98
- Flavors: there is no flavor information for this port.
- distinfo:
- There is no distinfo for this port.
No package information for this port in our database- Sometimes this happens. Not all ports have packages. Perhaps there is a build error. Check the fallout link:
- Dependencies
- NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
- Build dependencies:
-
- libcrypto.so.8 : security/openssl
- Runtime dependencies:
-
- libcrypto.so.8 : security/openssl
- Library dependencies:
-
- libxml2.so : textproc/libxml2
- There are no ports dependent upon this port
Configuration Options:
- ===> The following configuration options are available for bind98-9.8.8:
DOCS=on: Build and/or install documentation
FILTER_AAAA=off: Enable filtering of AAAA records
FIXED_RRSET=off: Enable fixed rrset ordering
GOST=off: Enable GOST ciphers (DSO incompatible with chroot)
IDN=off: International Domain Names support
IPV6=on: IPv6 protocol support
LARGE_FILE=off: 64-bit file support
LINKS=off: Create conf file symlinks in /usr/local
REPLACE_BASE=off: Replace base BIND (FreeBSD 9.x and earlier)
RPZRRL_PATCH=on: RPZ improvements + RRL patch (experimental)
RPZ_NSDNAME=off: Enable RPZ NSDNAME policy records
RPZ_NSIP=off: Enable RPZ NSIP trigger rules
SIGCHASE=off: dig/host/nslookup will do DNSSEC validation
SSL=on: Build with OpenSSL (Required for DNSSEC)
THREADS=on: Threading support
====> Dynamically Loadable Zones
DLZ_POSTGRESQL=off: DLZ Postgres driver
DLZ_MYSQL=off: DLZ MySQL driver (no threading)
DLZ_BDB=off: DLZ BDB driver
DLZ_LDAP=off: DLZ LDAP driver
DLZ_FILESYSTEM=off: DLZ filesystem driver
DLZ_STUB=off: DLZ stub driver
====> GSSAPI Security API support: you have to select exactly one of them
GSSAPI_BASE=off: GSSAPI Security API support (Heimdal in base)
GSSAPI_HEIMDAL=off: GSSAPI Security API support (security/heimdal)
GSSAPI_MIT=off: GSSAPI Security API support (security/krb5)
GSSAPI_NONE=on: No GSSAPI Security API support
===> Use 'make config' to modify these settings
- Options name:
- N/A
- FreshPorts was unable to extract/find any pkg message
- Master Sites:
|
Number of commits found: 110 (showing only 10 on this page)
Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
9.8.0.4 17 Jul 2011 04:08:59 |
dougb |
Fix the location of the default pid file in named.8
Problem pointed out in the PR
PR: conf/155006
Submitted by: Helmut Schneider <jumper99@gmx.de> |
9.8.0.4 05 Jul 2011 21:19:20 |
dougb |
Update to versions 9.8.0-P4, 9.7.3-P3, and 9.6-ESV-R4-P3.
ALL BIND USERS ENCOURAGED TO UPGRADE IMMEDIATELY
This update addresses the following vulnerabilities:
CVE-2011-2464
=============
Severity: High
Exploitable: Remotely
Description:
A defect in the affected BIND 9 versions allows an attacker to remotely
cause the "named" process to exit using a specially crafted packet. This (Only the first 15 lines of the commit message are shown above ) |
9.8.0.2 27 May 2011 23:47:56 |
dougb |
Upgrade to 9.8.0-P2, which addresses the following issues:
1. Very large RRSIG RRsets included in a negative cache can trigger
an assertion failure that will crash named (BIND 9 DNS) due to an
off-by-one error in a buffer size check.
This bug affects all resolving name servers, whether DNSSEC validation
is enabled or not, on all BIND versions prior to today. There is a
possibility of malicious exploitation of this bug by remote users.
2. Named could fail to validate zones listed in a DLV that validated
insecure without using DLV and had DS records in the parent zone.
Add a patch provided by ru@ and confirmed by ISC to fix a crash at
shutdown time when a SIG(0) key is being used.
Add a patch from ISC that will be in 9.8.1 to handle intermittent
failure of recursive queries involving CNAMEs and previously cached
responses. |
9.8.0.1 06 May 2011 21:13:52 |
dougb |
Upgrade to version 9.8.0-P1:
Certain response policy zone configurations could trigger an INSIST
when receiving a query of type RRSIG.
https://www.isc.org/CVE-2011-1907
This vulnerability is only possible if you have enable the new RPZ feature. |
9.8.0 02 Mar 2011 00:27:33 |
dougb |
This is 9.8.0, the first release version in the 9.8 series.
New features versus previous release candidates include:
* There is a new option in dig, +onesoa, that allows the final SOA
record in an AXFR response to be suppressed. [RT #20929
* There is additional information displayed in the recursing log
(qtype, qclass, qid and whether we are following the original
name). [RT #22043]
* Added option 'resolver-query-timeout' in named.conf (max query
timeout in seconds) to set a different value than the default (30
seconds). A value of 0 means 'use the compiled in default';
anything longer than 30 will be silently set to 30. [RT #22852]
* For Mac OS X, you can now have the test interfaces used during
"make test" stay beyond reboot. See bin/tests/system/README for
details.
There are also numerous bug fixes and enhancements. See
http://ftp.isc.org/isc/bind9/9.8.0/RELEASE-NOTES-BIND-9.8.html
for more information. |
9.8.0.r1 15 Feb 2011 01:50:19 |
dougb |
Update to 9.8.0rc1, the latest from ISC:
* The ADB hash table stores informations about which authoritative
servers to query about particular domains. Previous versions of
BIND had the hash table size as a fixed value. On a busy recursive
server, this could lead to hash table collisions in the ADB cache,
resulting in degraded response time to queries. Bind 9.8 now has a
dynamically scalable ADB hash table, which helps a busy server to
avoid hash table collisions and maintain a consistent query
response time. |
9.8.0.b1 22 Jan 2011 07:43:53 |
dougb |
Update to 9.8.0b1, which in addition to DNS64 support also has
the following new features:
* BIND now supports a new zone type, static-stub. This allows the
administrator of a recursive nameserver to force queries for a
particular zone to go to IP addresses of the administrator's choosing,
on a per zone basis, both globally or per view.
* BIND now supports Response Policy Zones, a way of expressing
"reputation" in real time via specially constructed DNS zones. See the
draft specification here:
http://ftp.isc.org/isc/dnsrpz/isc-tn-2010-1.txt
* Dynamically Loadable Zones (DLZ) now support dynamic updates.
Contributed by Andrew Tridgell of the Samba Project. (Only the first 15 lines of the commit message are shown above ) |
9.8.0.a1 18 Dec 2010 09:50:45 |
dougb |
We need _all_ the fixes from ../bind97 |
9.8.0.a1 18 Dec 2010 08:58:26 |
dougb |
We need the fixes from bind97 for the perl problem here, not bind96 |
9.8.0.a1 17 Dec 2010 22:48:55 |
dougb |
Add a -devel port for 9.8.0a1, which will allow people to experiment
with DNS64. Once 9.8.0 is released officially the -devel tag will be
removed.
BIND version 9 is a major rewrite of nearly all aspects of the underlying BIND
architecture. Some of the important features of BIND 9 are:
DNS Security: DNSSEC (signed zones), TSIG (signed DNS requests)
IP version 6: Answers DNS queries on IPv6 sockets, IPv6 resource records (AAAA)
Experimental IPv6 Resolver Library
DNS Protocol Enhancements: IXFR, DDNS, Notify, EDNS0
Improved standards conformance
Views: One server process can provide multiple "views" of the DNS namespace,
e.g. an "inside" view to certain clients, and an "outside" view to others.
Multiprocessor Support
BIND 9.8 includes a number of changes from BIND 9.7 and earlier releases,
including:
Preliminary DNS64 support (AAAA synthesis only initially)
See the CHANGES file for more information on features.
WWW: https://www.isc.org/software/bind |
Number of commits found: 110 (showing only 10 on this page)
|