Fri Sep 13 21:59:51 2013 UTC ()
OpenDNSSEC 1.4.2 - 2013-09-11

* OPENDNSSEC-428: ods-ksmutil: Add option for 'ods-ksmutil key generate' to
  take number of zones as a parameter

Bugfixes:
* SUPPORT-66: Signer Engine: Fix file descriptor leak in case of TCP write
  error [OPENDNSSEC-427].
* SUPPORT-71: Signer Engine: Fix double free crash in case of HSM connection
  error during signing [OPENDNSSEC-444].
* OPENDNSSEC-401: 'ods-signer sign <zone> --serial <nr>' command produces seg
  fault when run directly on command line (i.e. not via interactive mode)
* OPENDNSSEC-440: 'ods-ksmutil key generate' and the enforcer can create
  too many keys if there are keys already available and the KSK and ZSK use
  same algorithm and length
* OPENDNSSEC-424: Signer Engine: Respond to SOA queries from file instead
  of memory. Makes response non-blocking.
* OPENDNSSEC-425 Change "hsmutil list" output so that the table header goes
  to stdout not stderr
* OPENDNSSEC-438: 'ods-ksmutil key generate' and the enforcer can create
  too many keys for <SharedKeys/> policies when KSK and ZSK use same
  algorithm and length
* OPENDNSSEC-443: ods-ksmutil: Clean up of hsm connection handling
* Signer Engine: Improved Inbound XFR checking.
* Signer Engine: Fix double free corruption in case of adding zone with
  DNS Outbound Adapters and NotifyCommand enabled.


(pettai)
diff -r1.35 -r1.36 pkgsrc/security/opendnssec/Makefile
diff -r1.21 -r1.22 pkgsrc/security/opendnssec/distinfo

cvs diff -r1.35 -r1.36 pkgsrc/security/opendnssec/Makefile (expand / switch to unified diff)

--- pkgsrc/security/opendnssec/Makefile 2013/08/22 11:05:45 1.35
+++ pkgsrc/security/opendnssec/Makefile 2013/09/13 21:59:51 1.36
@@ -1,17 +1,17 @@ @@ -1,17 +1,17 @@
1# $NetBSD: Makefile,v 1.35 2013/08/22 11:05:45 he Exp $ 1# $NetBSD: Makefile,v 1.36 2013/09/13 21:59:51 pettai Exp $
2# 2#
3 3
4DISTNAME= opendnssec-1.4.1 4DISTNAME= opendnssec-1.4.2
5CATEGORIES= security net 5CATEGORIES= security net
6MASTER_SITES= http://www.opendnssec.org/files/source/ 6MASTER_SITES= http://www.opendnssec.org/files/source/
7 7
8MAINTAINER= pettai@NetBSD.org 8MAINTAINER= pettai@NetBSD.org
9HOMEPAGE= http://www.opendnssec.org/ 9HOMEPAGE= http://www.opendnssec.org/
10COMMENT= OSS for a fast and easy DNSSEC deployment 10COMMENT= OSS for a fast and easy DNSSEC deployment
11LICENSE= 2-clause-bsd 11LICENSE= 2-clause-bsd
12 12
13DEPENDS+= ldns>=1.6.13:../../net/ldns 13DEPENDS+= ldns>=1.6.13:../../net/ldns
14BUILD_DEPENDS+= CUnit-[0-9]*:../../devel/cunit 14BUILD_DEPENDS+= CUnit-[0-9]*:../../devel/cunit
15 15
16BUILD_DEFS+= VARBASE 16BUILD_DEFS+= VARBASE
17 17

cvs diff -r1.21 -r1.22 pkgsrc/security/opendnssec/distinfo (expand / switch to unified diff)

--- pkgsrc/security/opendnssec/distinfo 2013/08/22 11:05:45 1.21
+++ pkgsrc/security/opendnssec/distinfo 2013/09/13 21:59:51 1.22
@@ -1,8 +1,8 @@ @@ -1,8 +1,8 @@
1$NetBSD: distinfo,v 1.21 2013/08/22 11:05:45 he Exp $ 1$NetBSD: distinfo,v 1.22 2013/09/13 21:59:51 pettai Exp $
2 2
3SHA1 (opendnssec-1.4.1.tar.gz) = 90020d343456af0846b13c951a6a914109cb5d22 3SHA1 (opendnssec-1.4.2.tar.gz) = 82991f3110820ec0b12608fd3175bb70252a6f2b
4RMD160 (opendnssec-1.4.1.tar.gz) = 54c64bb73295593857ceb0ec89f0c4240d9d841e 4RMD160 (opendnssec-1.4.2.tar.gz) = 8f97b5867d16d9888e1ad3d2a936c3f81e2b1816
5Size (opendnssec-1.4.1.tar.gz) = 988263 bytes 5Size (opendnssec-1.4.2.tar.gz) = 991161 bytes
6SHA1 (patch-aa) = 104e077af6c368cbb5fc3034d58b2f2249fcf991 6SHA1 (patch-aa) = 104e077af6c368cbb5fc3034d58b2f2249fcf991
7SHA1 (patch-enforcer_utils_Makefile.am) = bee7cb4f3cfe5aae96c5726a115eb8b6587288dd 7SHA1 (patch-enforcer_utils_Makefile.am) = bee7cb4f3cfe5aae96c5726a115eb8b6587288dd
8SHA1 (patch-enforcer_utils_Makefile.in) = da9fce97e631bb81607851f9758b206ea975b052 8SHA1 (patch-enforcer_utils_Makefile.in) = da9fce97e631bb81607851f9758b206ea975b052