[Opendnssec-develop] OpenDNSSEC 1.4.3rc1 release candidate

Sara Dickinson sara at sinodun.com
Thu Nov 28 13:37:05 UTC 2013


Version 1.4.3rc1 of OpenDNSSEC is now available. This is a release candidate for testing purposes:

OpenDNSSEC 1.4.3rc1 

* SUPPORT-72: Improve logging when failed to increment serial in case of key rollover and serial value "keep" [OPENDNSSEC-461].
* OPENDNSSEC-106: Add 'ods-enforcerd -p <policy>' option. This prompts the enforcer to run once and only process the specified policy and associated zones.
* OPENDNSSEC-330: NSEC3PARAM TTL can now be optionally configured in kasp.xml. Default value remains PT0S.
* OPENDNSSEC-390: ods-ksmutil: Add an option to the 'ods-ksmutil key ds-seen' command so the user can choose not to notify the enforcer.
* OPENDNSSEC-430: ods-ksmutil: Improve 'zone add' - Zone add command could warn if a specified zone file or adapter file does not exits.
* OPENDNSSEC-431: ods-ksmutil: Improve 'zone add' - Support default <input> and <output> values for DNS adapters.
* OPENDNSSEC-454: ods-ksmutil: Add option for 'ods-ksmutil key import' to check if there is a matching key in the repository before import.

* OPENDNSSEC-435: Signer Engine: Fix a serious memory leak in signature cleanup.
* OPENDNSSEC-463: Signer Engine: Duration PT0S is now printed correctly.
* OPENDNSSEC-466: Signer Engine: Created bad TSIG signature when falling back to AXFR.
* OPENDNSSEC-467: Signer Engine: After ods-signer clear, signer should not use inbound serial.

* http://dist.opendnssec.org/source/testing/opendnssec-1.4.3rc1.tar.gz
* http://dist.opendnssec.org/source/testing/opendnssec-1.4.3rc1.tar.gz.sig
* Checksum sha1: ab62a1d224c86635617cfad74c59d2237605b1e4
* Checksum sha256: 42b97694b1fdef7b41929446b3939e4c5b34f4f029014d917d71ce20d40eee8d

A full 1.4.3 release is planned for Wednesday 4th December. 

//OpenDNSSEC team

More information about the Opendnssec-develop mailing list