52 Commits

Author SHA1 Message Date
Hugo Landau
10f550c471 bind: Modify default config to be more secure
By default BIND will happily serve as both an authoritative nameserver
and recursive resolver, but this is no longer a recommended or desirable
configuration. The previous default configuration did not draw attention
to this fact and the issues involved.

Users are now made to rename one of two sample configuration files,
named.conf.authoritative or named.conf.recursive. Comments inside either
file advise DNS administrators of the most prevalent security issues.

This ensures that users setting up an authoritative nameserver do not
unwittingly also operate a resolver. In the previous default
configuration, BIND would happily perform recursive resolution for
localhost, which means that the local machine may receive
non-authoritative data from what is supposed to be an authoritative
nameserver.

Both default configurations disable zone transfers by default, as BIND
defaults to enabling them for any host (!).
2014-10-16 19:05:10 +00:00
Natanael Copa
49833591ff main/bind: upgrade to 9.10.1 2014-09-23 11:26:14 +00:00
Natanael Copa
6f89add111 main/bind: remove duplicate depend function 2014-06-19 08:30:19 +00:00
Natanael Copa
a628be65ae main/bind: upgrade to 9.10.0_p2 2014-06-12 12:11:02 +00:00
Natanael Copa
6abfda6f33 main/bind: upgrade to 9.10.0_p1 2014-05-22 12:35:00 +00:00
Natanael Copa
89e34a23bf main/bind: upgrade to 9.10.0 2014-05-01 08:40:37 +00:00
Natanael Copa
93a7a06991 main/bind: upgrade to 9.9.5 2014-02-03 10:59:43 +00:00
Natanael Copa
e7ef39f84e main/bind: security upgrade to 9.9.4_p2 (CVE-2014-0591)
ref #2604
2014-01-15 13:12:29 +00:00
Fabian Affolter
bbe4ea51fb main/bind: specify license 2013-12-03 14:39:33 +00:00
Natanael Copa
b825d06115 main/bind: upgrade to 9.9.4_p1 2013-11-07 09:14:14 +00:00
Natanael Copa
f86141b3d6 main/bind: upgrade to 9.9.4 2013-09-24 07:02:51 +00:00
Natanael Copa
518b9b83cc main/bind: use /sbin/nologin as shell 2013-09-04 11:46:33 +00:00
Natanael Copa
794a036321 main/bind: use /sbin/nologin as shell 2013-09-03 07:47:11 +00:00
Timo Teräs
5c90471732 [all autotools packages]: normalize ./configure 2013-07-30 08:54:53 +00:00
Natanael Copa
6f4a5f3bb4 main/bind: security upgrade to 9.9.3_p2 (CVE-2013-4854)
fixes #2174
2013-07-29 06:20:58 +00:00
Natanael Copa
6f22508d6b main/bind: upgrade to 9.9.3_p1 2013-06-05 14:13:49 +00:00
Natanael Copa
87776a43ce main/bind: upgrade to 9.9.3 2013-05-29 07:14:44 +00:00
Natanael Copa
aed44ac288 main/bind: upgrade to 9.9.2_p2 2013-04-01 15:33:35 +00:00
Natanael Copa
91378f2eaa main/bind: upgrade to 9.9.2_p1 2012-12-07 08:23:00 +00:00
Natanael Copa
ecbc84a7f4 main/bind: upgrade to 9.9.2 2012-10-10 18:08:45 +00:00
Natanael Copa
8884830dce main/bind: upgrade to 9.9.1_p3 2012-09-13 09:31:31 +00:00
Natanael Copa
1045ace4f2 main/bind: upgrade to 9.9.1_p2 2012-07-25 09:07:54 +00:00
Natanael Copa
b237d54471 main/bind: upgrade to 9.9.1_p1 2012-06-05 09:43:40 +00:00
Natanael Copa
6b0729497c main/bind: upgrade to 9.9.1 2012-05-22 06:32:50 +00:00
Natanael Copa
0c2a46ee5c main/bind: cleanup and fix named.initd stop 2012-03-14 21:23:57 +00:00
Natanael Copa
6bda80b11f main/bind: upgrade to 9.9.0 2012-03-13 12:08:59 +00:00
Natanael Copa
6a159eecd2 main/bind: upgrade to 9.8.1_p1 2011-11-17 07:52:06 +00:00
Natanael Copa
f61c11fdfa main/bind: security upgrade to 9.8.1 (CVE-2011-1910) 2011-09-01 06:11:27 +00:00
Natanael Copa
2cc0077129 main/bind: upgrade to 9.8.0_p4 2011-07-06 06:59:22 +00:00
Natanael Copa
72222f5fb2 main/bind: remove *.la 2011-07-01 09:20:32 +00:00
Natanael Copa
6fecc2589c main/bind: upgrade to 9.8.0_p2 2011-05-31 07:29:17 +00:00
Natanael Copa
ba1ccb4197 main/bind: upgrade to 9.8.0_p1 2011-05-06 09:42:26 +00:00
Natanael Copa
d3a2598230 main/bind: upgrade to 9.8.0 2011-03-02 20:50:51 +00:00
Natanael Copa
33fc7dabd1 main/bind: upgrade to 9.7.3 2011-02-15 16:03:57 +00:00
William Pitcock
ba2600dc6e Set all packages with arch="x86 x86_64" to arch="all". 2011-01-13 06:06:02 -06:00
Natanael Copa
da49ad32c4 main/*: add arch 2010-12-13 16:00:16 +00:00
Natanael Copa
a0023c2a39 main/bind: upgrade to 9.7.2_p3 2010-12-02 07:13:24 +00:00
Natanael Copa
f846e0fe8f main/bind: upgrade to 9.7.2_p2 2010-10-14 07:39:52 +00:00
Natanael Copa
e7683606a2 main/bind: upgrade to 9.7.1_p2 2010-09-29 10:53:10 +00:00
Natanael Copa
69d1f65dba main/bind: upgrade to 9.7.2_p1 2010-09-17 07:04:07 +00:00
Natanael Copa
69e84b00fd main/bind: upgrade to 9.7.2 2010-09-14 12:53:11 +00:00
Natanael Copa
e0b2dce299 main/bind: upgrade to 9.7.1_p2 2010-07-20 09:09:44 +00:00
Natanael Copa
f2607852eb main/bind: upgrade to 9.7.1 2010-07-05 13:28:14 +00:00
Natanael Copa
9ca82f726f main/[various]: rebuild against openssl-1.0 2010-05-14 17:57:16 +00:00
Natanael Copa
b4eecaf058 main/[various]: bump pkgrel to force rebuild against nptl 2010-05-04 08:26:51 +00:00
Natanael Copa
fea406b997 main/bind: build fix
needs perl to build
2010-03-30 07:35:24 +00:00
Natanael Copa
a17455ed76 main/bind: upgrade to 9.7.0_p1 2010-03-30 06:35:29 +00:00
Natanael Copa
fc24f4a0aa main/bind: upgrade to 9.6.1_p3 2010-01-27 07:47:45 +00:00
Natanael Copa
3cf7d8431b main/bind: upgrade to 9.6.1_p2 2009-12-10 15:36:24 +00:00
Natanael Copa
a64fd3e5c7 main/bind,busybox-initscripts: start net services after firewall 2009-09-15 13:04:51 +00:00