Issues reported fixed by upstream (same as 2.1.9):
- OPENDNSSEC-955: Prevent concurrency between certain valid
PKCS#11 HSM operations to avoid some keys to be (transiently)
unavailable.
- OPENDNSSEC-956: Harden signing procedure to still sign zones
for which there are unused keys specified in the zone which are
unavailable.
Issues newly reported fixed:
- OPENDNSSEC-957: Fix exit code signer daemon to not always report
failure.
- OPENDNSSEC-958: Fix immediate resalting after migration from 1.4.
- OPENDNSSEC-959: Emit warning on ods-kaspcheck for NSEC iteration
count that is deemed too high.
- SUPPORT-265: Resolve conflict when deleting keys from HSM whilst
also performing step in key roll process. Typically a message
“key_data_update failed” is present in logs.
Issues solved:
- OPENDNSSEC-955: Prevent concurrency between certain valid
PKCS#11 HSM operations to avoid some keys
to be (transiently) unavailable.
- OPENDNSSEC-956: Harden signing procedure to still sign zones
for which there are unused keys specified in
the zone which are unavailable.
Known issue:
- OPENDNSSEC-957: Signer daemon stops with failure exit code
even when no error occured.
- OPENDNSSEC-949: Fix for migration bug not keeping proper parameters
of NSEC3 signed zones. Amongst others the zone become NSEC. Loading
the policies fixes the situation, migration scripts now corrected. Since
1.4 does not require a salt, a resalt might be automatic after
migrating, as this is a required parameter.
- OPENDNSSEC-948: do not recreate signatures for keys that are moving
out this fixes unexpected double signatures in the zone.
- SUPPORT-253: Incorrect keytag used when using Combined Signing keys
(CSK) (Thanks to Simon Arlott)
- SUPPORT-257: Export keys by locator (Thansk to Simon Arlott)
- SUPPORT-222: Support ED25519/ED448 keys. This requires library ldns
1.7.0 or better, otherwise unavailable. (Thanks again to Simon
Arlott)
- Load libsqlite3.so.0 and fall back on libsqlite3.so.0 to allow to run
migration tool on systems without libsqlite3.so.0 soft link. (Thanks
to Paul Wouters)
- Some compilation warnings, o.a. gcc10 related, code quality and
initialization improvements. (Thanks to Jonas Berlin, and Mathieu
MirMont, and Paul Wouters)
- Update to 1.4.14 as first steop to migrating to 2.x
- Resolves: rhbz#1413254 Move tmpfiles.d config to %%{_tmpfilesdir}, install LICENSE as %%license
See:
https://fedoraproject.org/wiki/Packaging:Perl#Build_Dependencies
No rebuild is required.
The original error was:
...
checking time.h presence... yes
checking for time.h... yes
checking for SSL... found in /usr
checking for HMAC_CTX_init in -lcrypto... yes
checking for EVP_sha1... yes
checking for EVP_sha256... yes
checking for dlopen... no
checking for dlopen in -ldl... yes
checking for perl... no
configure: error: perl not found