Remove GOST support from BIND9 9.11 and 9.12.
It was never (widely|really) used, and support for it has been dropped in OpenSSL starting at 1.1, and BIND9 starting at 9.13. PR: 231980 Reported by: mfechner
This commit is contained in:
parent
9ae23125ac
commit
20b0f0d766
Notes:
svn2git
2021-03-31 03:12:20 +00:00
svn path=/head/; revision=483798
2 changed files with 2 additions and 38 deletions
|
@ -56,9 +56,8 @@ OPTIONS_DEFINE= IDN LARGE_FILE PYTHON JSON \
|
|||
MINCACHE PORTREVISION QUERYTRACE LMDB DNSTAP \
|
||||
START_LATE TUNING_LARGE TCP_FASTOPEN
|
||||
|
||||
OPTIONS_RADIO= CRYPTO GOSTDEF
|
||||
OPTIONS_RADIO= CRYPTO
|
||||
OPTIONS_RADIO_CRYPTO= SSL NATIVE_PKCS11
|
||||
OPTIONS_RADIO_GOSTDEF= GOST GOST_ASN1
|
||||
|
||||
OPTIONS_GROUP= DLZ
|
||||
OPTIONS_GROUP_DLZ= DLZ_POSTGRESQL DLZ_MYSQL DLZ_BDB \
|
||||
|
@ -80,9 +79,6 @@ DNSTAP_DESC= Provides fast passive logging of DNS messages
|
|||
FILTER_AAAA_DESC= Enable filtering of AAAA records
|
||||
FIXED_RRSET_DESC= Enable fixed rrset ordering
|
||||
GEOIP_DESC= Allow geographically based ACL.
|
||||
GOSTDEF_DESC= Enable GOST ciphers, needs SSL
|
||||
GOST_ASN1_DESC= GOST using ASN.1
|
||||
GOST_DESC= GOST raw keys (new default)
|
||||
GSSAPI_BASE_DESC= Using Heimdal in base
|
||||
GSSAPI_HEIMDAL_DESC= Using security/heimdal
|
||||
GSSAPI_MIT_DESC= Using security/krb5
|
||||
|
@ -131,10 +127,6 @@ FIXED_RRSET_CONFIGURE_ENABLE= fixed-rrset
|
|||
GEOIP_CONFIGURE_WITH= geoip
|
||||
GEOIP_LIB_DEPENDS= libGeoIP.so:net/GeoIP
|
||||
|
||||
GOST_ASN1_CONFIGURE_ON= --with-gost=asn1
|
||||
|
||||
GOST_CONFIGURE_ON= --with-gost
|
||||
|
||||
GSSAPI_BASE_CONFIGURE_ON=\
|
||||
--with-gssapi=${GSSAPIBASEDIR} KRB5CONFIG="${KRB5CONFIG}"
|
||||
GSSAPI_BASE_USES= gssapi
|
||||
|
@ -199,16 +191,6 @@ TUNING_LARGE_CONFIGURE_OFF= --with-tuning=default
|
|||
|
||||
.include <bsd.port.pre.mk>
|
||||
|
||||
.if !${PORT_OPTIONS:MGOST} && !${PORT_OPTIONS:MGOST_ASN1}
|
||||
CONFIGURE_ARGS+= --without-gost
|
||||
.endif
|
||||
|
||||
.if ( ${PORT_OPTIONS:MGOST} || ${PORT_OPTIONS:MGOST_ASN1} ) && ${SSL_DEFAULT} == base
|
||||
BROKEN= OpenSSL from the base system does not support GOST, add \
|
||||
DEFAULT_VERSIONS+=ssl=openssl to your /etc/make.conf and rebuild everything \
|
||||
that needs SSL.
|
||||
.endif
|
||||
|
||||
post-patch:
|
||||
.for FILE in check/named-checkconf.8 named/named.8 nsupdate/nsupdate.1 \
|
||||
rndc/rndc.8
|
||||
|
|
|
@ -72,9 +72,8 @@ OPTIONS_DEFAULT= SSL THREADS SIGCHASE IDN GSSAPI_NONE JSON PYTHON
|
|||
OPTIONS_DEFINE= IDN LARGE_FILE PYTHON JSON \
|
||||
FIXED_RRSET SIGCHASE IPV6 THREADS
|
||||
|
||||
OPTIONS_RADIO= CRYPTO GOSTDEF
|
||||
OPTIONS_RADIO= CRYPTO
|
||||
OPTIONS_RADIO_CRYPTO= SSL NATIVE_PKCS11
|
||||
OPTIONS_RADIO_GOSTDEF= GOST GOST_ASN1
|
||||
|
||||
.if !defined(BIND_TOOLS_SLAVE)
|
||||
OPTIONS_DEFAULT+= DLZ_FILESYSTEM LMDB RPZ_NSDNAME RPZ_NSIP TCP_FASTOPEN
|
||||
|
@ -101,9 +100,6 @@ DLZ_STUB_DESC= DLZ stub driver
|
|||
DNSTAP_DESC= Provides fast passive logging of DNS messages
|
||||
FIXED_RRSET_DESC= Enable fixed rrset ordering
|
||||
GEOIP_DESC= Allow geographically based ACL.
|
||||
GOSTDEF_DESC= Enable GOST ciphers, needs SSL
|
||||
GOST_ASN1_DESC= GOST using ASN.1
|
||||
GOST_DESC= GOST raw keys (new default)
|
||||
GSSAPI_BASE_DESC= Using Heimdal in base
|
||||
GSSAPI_HEIMDAL_DESC= Using security/heimdal
|
||||
GSSAPI_MIT_DESC= Using security/krb5
|
||||
|
@ -150,10 +146,6 @@ FIXED_RRSET_CONFIGURE_ENABLE= fixed-rrset
|
|||
GEOIP_CONFIGURE_WITH= geoip
|
||||
GEOIP_LIB_DEPENDS= libGeoIP.so:net/GeoIP
|
||||
|
||||
GOST_ASN1_CONFIGURE_ON= --with-gost=asn1
|
||||
|
||||
GOST_CONFIGURE_ON= --with-gost
|
||||
|
||||
GSSAPI_BASE_CONFIGURE_ON=\
|
||||
--with-gssapi=${GSSAPIBASEDIR} KRB5CONFIG="${KRB5CONFIG}"
|
||||
GSSAPI_BASE_USES= gssapi
|
||||
|
@ -220,16 +212,6 @@ TUNING_LARGE_CONFIGURE_OFF= --with-tuning=default
|
|||
|
||||
.include <bsd.port.pre.mk>
|
||||
|
||||
.if !${PORT_OPTIONS:MGOST} && !${PORT_OPTIONS:MGOST_ASN1}
|
||||
CONFIGURE_ARGS+= --without-gost
|
||||
.endif
|
||||
|
||||
.if ( ${PORT_OPTIONS:MGOST} || ${PORT_OPTIONS:MGOST_ASN1} ) && ${SSL_DEFAULT} == base
|
||||
BROKEN= OpenSSL from the base system does not support GOST, add \
|
||||
DEFAULT_VERSIONS+=ssl=openssl to your /etc/make.conf and rebuild everything \
|
||||
that needs SSL.
|
||||
.endif
|
||||
|
||||
post-patch:
|
||||
.if defined(BIND_TOOLS_SLAVE)
|
||||
@${REINPLACE_CMD} -e 's#^SUBDIRS.*#SUBDIRS = lib bin#' \
|
||||
|
|
Loading…
Reference in a new issue