--- - branch: MAIN date: Thu Aug 25 14:11:49 UTC 2016 files: - new: '1.31' old: '1.30' path: pkgsrc/net/knot/Makefile pathrev: pkgsrc/net/knot/Makefile@1.31 type: modified - new: '1.10' old: '1.9' path: pkgsrc/net/knot/PLIST pathrev: pkgsrc/net/knot/PLIST@1.10 type: modified - new: '1.19' old: '1.18' path: pkgsrc/net/knot/distinfo pathrev: pkgsrc/net/knot/distinfo@1.19 type: modified id: 20160825T141149Z.09579f9f8c3f5012a73c802ddde23e11ca8d9c5c log: | Knot DNS 2.3.0 (2016-08-09) =========================== Bugfixes: --------- - No wildcard expansion below empty non-terminal for NSEC signed zone - Avoid multiple loads of the same PKCS #11 module - Fix kdig IXFR response processing if the transfer content is empty - Don't ignore non-existing records to be removed in IXFR Improvements: ------------- - Refactored semantic checks and improved error messages - Set TC flag in delegation only if mandatory glue doesn't fit the response - Separate EDNS(0) payload size configuration for IPv4 and IPv6 Features: --------- - DNSSEC policy can be defined in server configuration - Automatic NSEC3 resalt according to DNSSEC policy - Zone content editing using control interface - Zone size limit restriction for DDNS, AXFR, and IXFR (CVE-2016-6171) - DNS-over-TLS support in kdig (RFC 7858) - EDNS(0) padding and alignment support in kdig (RFC 7830) module: pkgsrc subject: 'CVS commit: pkgsrc/net/knot' unixtime: '1472134309' user: pettai