[Opendnssec-develop] OpenDNSSEC 1.3.16rc1 release candidate

Sara Dickinson sara at sinodun.com
Thu Nov 28 13:37:03 UTC 2013


Version 1.3.16rc1 of OpenDNSSEC is now available. This is a release candidate for testing purposes:

OpenDNSSEC 1.3.16rc1

* SUPPORT-72: Improve logging when failed to increment serial in case of key rollover and serial value "keep" [OPENDNSSEC-441].
* OPENDNSSEC-436: NSEC3PARAM TTL can now be optionally configured in kasp.xml. Default value remains PT0S.
* OPENDNSSEC-458: Add 'ods-enforcerd -p <policy>' option. This prompts the enforcer to run once and only process the specified policy and associated zones. 
* OPENDNSSEC-460: ods-ksmutil: Add an option to the 'ods-ksmutil key ds-seen' command so the user can choose not to notify the enforcer.
* OPENDNSSEC-472: ods-ksmutil: Add option for 'ods-ksmutil key import' to check if there is a matching key in the repository before import.
* OPENDNSSEC-473: ods-ksmutil: Improve 'zone add' - Support default <input> and <output> values for DNS adapters.

* OPENDNSSEC-451: Signer Engine: Prevent CKA_ID and DNSKEY mixup by using a separate HSM context when loading signer configuration.
* OPENDNSSEC-462: Signer Engine: Duration PT0S is not printed correctly.
* ods-ksmutil: Fix typo in policy export with NSEC3 <Iterations>.

* http://dist.opendnssec.org/source/testing/opendnssec-1.3.16rc1.tar.gz
* http://dist.opendnssec.org/source/testing/opendnssec-1.3.16rc1.tar.gz.sig
* Checksum sha1: eea7d0ede9066f5dd65beeba775aafc4db98f592
* Checksum sah256: 5fa05df278932d0125dcb93efc3b08fa7adabea6867bec95ecf59af1e9349612

A full 1.3.16 release is planned for Wednesday 4th December. 

// OpenDNSSEC team

More information about the Opendnssec-develop mailing list