Commit Graph

24 Commits

Author SHA1 Message Date
François Cami
e09e7a2680 Update to 2.1.10
Issues reported fixed by upstream (same as 2.1.9):
- OPENDNSSEC-955: Prevent concurrency between certain valid
  PKCS#11 HSM operations to avoid some keys to be (transiently)
  unavailable.

- OPENDNSSEC-956: Harden signing procedure to still sign zones
  for which there are unused keys specified in the zone which are
  unavailable.

Issues newly reported fixed:
- OPENDNSSEC-957: Fix exit code signer daemon to not always report
  failure.

- OPENDNSSEC-958: Fix immediate resalting after migration from 1.4.

- OPENDNSSEC-959: Emit warning on ods-kaspcheck for NSEC iteration
  count that is deemed too high.

- SUPPORT-265: Resolve conflict when deleting keys from HSM whilst
  also performing step in key roll process. Typically a message
  “key_data_update failed” is present in logs.
2021-10-18 20:47:18 +02:00
François Cami
a7fe6a09ab Update to 2.1.9
Issues solved:
- OPENDNSSEC-955: Prevent concurrency between certain valid
                  PKCS#11 HSM operations to avoid some keys
                  to be (transiently) unavailable.
- OPENDNSSEC-956: Harden signing procedure to still sign zones
                  for which there are unused keys specified in
                  the zone which are unavailable.

Known issue:
- OPENDNSSEC-957: Signer daemon stops with failure exit code
                  even when no error occured.
2021-07-06 16:55:01 +02:00
Fedora Release Monitoring
33b7514afc Update to 2.1.8 (#1931143) 2021-02-21 18:02:43 +02:00
Alexander Bokovoy
753f88d235 Update to 2.1.7
- OPENDNSSEC-949: Fix for migration bug not keeping proper parameters
   of NSEC3 signed zones. Amongst others the zone become NSEC. Loading
   the policies fixes the situation, migration scripts now corrected. Since
   1.4 does not require a salt, a resalt might be automatic after
   migrating, as this is a required parameter.

 - OPENDNSSEC-948: do not recreate signatures for keys that are moving
   out this fixes unexpected double signatures in the zone.

 - SUPPORT-253: Incorrect keytag used when using Combined Signing keys
   (CSK) (Thanks to Simon Arlott)

 - SUPPORT-257: Export keys by locator (Thansk to Simon Arlott)

 - SUPPORT-222: Support ED25519/ED448 keys. This requires library ldns
   1.7.0 or better, otherwise unavailable. (Thanks again to Simon
   Arlott)

 - Load libsqlite3.so.0 and fall back on libsqlite3.so.0 to allow to run
   migration tool on systems without libsqlite3.so.0 soft link. (Thanks
   to Paul Wouters)

 - Some compilation warnings, o.a. gcc10 related, code quality and
   initialization improvements. (Thanks to Jonas Berlin, and Mathieu
   MirMont, and Paul Wouters)
2020-12-04 17:45:16 +02:00
Paul Wouters
6c8038d198 new sources and patch 2020-02-24 13:36:14 -05:00
Paul Wouters
ffb901ceb2 * Tue Dec 12 2017 Paul Wouters <pwouters@redhat.com> - 1.4.14-1
- Update to 1.4.14 as first steop to migrating to 2.x
- Resolves: rhbz#1413254 Move tmpfiles.d config to %%{_tmpfilesdir}, install LICENSE as %%license
2017-12-12 13:20:29 -05:00
Paul Wouters
c62752cf36 * Mon Feb 01 2016 Paul Wouters <pwouters@redhat.com> - 1.4.9-1
- Updated to 1.4.9
- Removed merged in patch
2016-02-01 13:03:53 +01:00
Paul Wouters
af2cb8cc70 - Updated to 1.4.7 (fix zone update can get stuck, crash on retransfer cmd) 2014-12-08 22:53:46 -05:00
Paul Wouters
83314e9e6a * Mon Jul 28 2014 Paul Wouters <pwouters@redhat.com> - 1.4.6-1
- Updated to 1.4.6
- Removed incorporated patch upstream
- Remove Wants= from ods-signerd.service (rhbz#1098205)
2014-07-28 11:04:29 -04:00
Paul Wouters
70b73e51ed * Fri Apr 18 2014 Paul Wouters <pwouters@redhat.com> - 1.4.5-2
- Updated to 1.4.5
- Added patch for serial 0 bug in XFR adapter
2014-04-18 15:45:50 -04:00
Paul Wouters
0cbe4c95b6 * Thu Mar 27 2014 Paul Wouters <pwouters@redhat.com> - 1.4.4-1
- Updated to 1.4.4 (compatibility with non RFC 5155 errata 3441)
- Change the default ZSK policy from 1024 to 2048 bit RSA keys
- Fix post to be quiet when upgrading opendnssec
2014-03-27 22:37:46 -04:00
Paul Wouters
e0c8af861d * Thu Jan 09 2014 Paul Wouters <pwouters@redhat.com> - 1.4.3-1
- Updated to 1.4.3i (rhel#1048449) - minor bugfixes, minor feature enhancements
- rhel#1025985 OpenDNSSEC signer cannot be started due to a typo in service file
2014-01-09 11:58:22 -05:00
Paul Wouters
7ce960e57c * Wed Sep 11 2013 Paul Wouters <pwouters@redhat.com> - 1.4.2-1
- Updated to 1.4.2, bugfix release
2013-09-11 15:35:11 -04:00
Paul Wouters
62ab72beec * Fri Jun 28 2013 Paul Wouters <pwouters@redhat.com> - 1.4.1-1
- Updated to 1.4.1. NSEC3 handling and serial number handling fixes
2013-06-28 12:45:11 -04:00
Paul Wouters
fac556fae3 * Sat May 11 2013 Paul Wouters <pwouters@redhat.com> - 1.4.0-1
- Updated to 1.4.0
2013-05-11 16:30:13 -04:00
Paul Wouters
53fe96800d * Fri Apr 12 2013 Paul Wouters <pwouters@redhat.com> - 1.4.20-0.8.rc3
- Updated to 1.4.0rc3
- Enabled hardened compile, full relzo/pie
2013-04-12 22:03:51 -04:00
Patrick Uiterwijk
af979b28b3 Updated to 1.4.0rc2 2013-01-25 17:11:08 +01:00
Patrick Uiterwijk
ebc1d51293 Updated to 1.4.0rc1
Applied opendnssec-ksk-premature-retirement.patch (svn r6952)
2013-01-18 19:29:12 +01:00
Paul Wouters
d5585275e8 * upgrade to 1.4.0b2 2012-12-18 16:48:58 -05:00
Paul Wouters
b55d6a76d3 * Tue Oct 30 2012 Paul Wouters <pwouters@redhat.com> - 1.4.0-0.4.b1
- Added BuildRequires: procps-ng for bug OPENDNSSEC-345
- Change RRSIG inception offset to -2h to avoid possible
  daylight saving issues on resolvers
- Patch to prevent removal of occluded data
2012-10-30 15:00:54 -04:00
Paul Wouters
00194be7bd * updated sources 2012-09-12 18:20:35 -04:00
Paul Wouters
9b8ffb6040 * Tue Jun 12 2012 Paul Wouters <pwouters@redhat.com> - 1.4.0-0.a2.1
- Updated to 1.4.0a2
- ksm-utils patch for ods-ksmutil to die sooner when it can't lock
  the HSM.
2012-06-12 17:42:56 -04:00
Paul Wouters
14d52d44e6 * Initial package 2012-03-26 22:29:33 -04:00
Fedora Release Engineering
df2533eb8d Initial setup of the repo 2012-03-26 18:02:55 +00:00