Commit graph

1834 commits

Author SHA1 Message Date
Doug Barton
064004f4ef Update to the release version of BIND 9.7.0, and remove the -devel
suffix as a result.

Feature safe:	yes
2010-02-17 06:13:15 +00:00
Li-Wen Hsu
063255fa5d - Update to 2.1.0
PR:		ports/143957
Submitted by:	Janos Mohacsi <janos.mohacsi AT bsd.hu> (maintainer)
2010-02-15 16:54:31 +00:00
Philip M. Gollucci
6e165bf799 - Fix permission issues
PR:             ports/143550
Submitted by:   Marko Njezic <mrmax063@maxempire.com>
Approved by:    Olafur Osvaldsson <osvaldsson@icelandic.net> (maintainer)
2010-02-11 19:37:10 +00:00
Pav Lucistnik
a639b8cc99 - Update to 1.0.0 release
PR:		ports/143712
Submitted by:	Jaap Akkerhuis <jaap@NLnetLabs.nl> (maintainer)
2010-02-11 10:33:58 +00:00
Philip M. Gollucci
b339872c92 - Reset more ports I don't use anymore 2010-02-10 21:47:48 +00:00
Philip M. Gollucci
178d590d92 - Fix installation permissions
- Submitter is now MAINTAINER

PR:             ports/143450
Submitted by:   Alexey V.Degtyarev <alexey@renatasystems.org>
2010-02-10 02:58:33 +00:00
Martin Wilke
6f2c20c1ab - Update to 1.6.4
PR:		143605
Submitted by:	Cristiano Rolim Pereira <cristianorolim@hotmail.com>
Approved by:	maintainer
2010-02-08 22:03:13 +00:00
Martin Wilke
9285f749d9 - Update to 1.4.03
PR:		143534
Submitted by:	Bernhard Froehlich <decke@bluelife.at> (maintainer)
2010-02-08 15:08:44 +00:00
Li-Wen Hsu
bd472979ca - Update to 9.0.0
PR:		ports/140937
Submitted by:	wen
2010-02-07 09:34:28 +00:00
Dirk Meyer
ca9c60461c - update to jpeg-8 2010-02-05 11:46:55 +00:00
Ion-Mihai Tetcu
fae8374e9f libasyncns is a C library for Linux/Unix for executing name service queries
asynchronously. It is an asynchronous wrapper around getaddrinfo(3),
getnameinfo(3), res_query(3) and res_search(3) from libc and libresolv.

In contrast to GNU's asynchronous name resolving API getaddrinfo_a(),
libasyncns does not make use of UNIX signals for reporting completion of name
queries. Instead, the API exports a standard UNIX file descriptor which may be
integerated cleanly into custom main loops.

In contrast to asynchronous DNS resolving libraries like libdenise, skadns,
adns, libasyncns is just an asynchronous wrapper around the libc's synchronous
getaddrinfo() API, which has the advantage of allowing name resolution using
techniques like Multicast DNS, LDAP or NIS using standard libc NSS (Name
Service Switch) modules. libasyncns is compatible with IPv6 if the underlying
libc is.

libasyncns is very tiny, consisting of just one header and one source file. It
has no dependencies besides libc.

WWW: http://0pointer.de/lennart/projects/libasyncns/
2010-02-04 08:25:54 +00:00
Wen Heping
c14f63bd39 - Update to 1.43 2010-02-04 00:33:47 +00:00
Sergey Matveychuk
28d4421e7e - OpenSSL has no sha256 functions on 6.x
Reported by:	Michael Meelis <m.meelis at easybow.com>
2010-02-02 15:34:31 +00:00
Doug Barton
c595c1f9f0 Upgrade to 9.4-ESV, the first of the "Extended Support Releases"
from ISC. It has numerous bug fixes compared to 9.4.3*, however
in the case of this version "extended" only applies till 2010/12/31
so serious BIND users are still encouraged to upgrade to 9.6.x.
2010-02-02 07:14:33 +00:00
Doug Barton
f89b15d117 Update to 9.7.0rc2 which has numerous bug fixes, especially
for DNSSEC.
2010-02-01 20:57:31 +00:00
Jun Kuriyama
935c866afb - Remove unneeded dependencies which is in perl-5.8.9 dist
(part 13).

Approved by:	portmgr (itetcu)
2010-01-28 04:53:50 +00:00
Jun Kuriyama
3f795ed795 - Remove unneeded dependencies which is in perl-5.8.9 dist
(part 12).

Approved by:	portmgr (itetcu)
2010-01-28 02:32:30 +00:00
Martin Wilke
a602da42eb * Fix for Bug #0000040 http://bugs.mydns-ng.com/view.php?id=40
child processes must not shutdown() their sockets
* Fixes and reports a problem occuring with jumping system time,
  as reported when running inside some virtual machine. Time jumps
  are reported to the log with loglevel NOTICE.
* Delegation now has precedence over wildcard matching
  Thanks to Fab for the fix
  Fixes bugs #0000038, #0000042

PR:		143223
Submitted by:	Hung-Yi Chen <gaod@hychen.org> (maintainer)
2010-01-27 13:03:31 +00:00
Philippe Audeoud
3fa59a7fd4 - Update to 1.16
- Removed useless patches

PR:		ports/143274
Submitted by:	Sofian Brabez <sbrabez gmail.com>
2010-01-27 08:44:43 +00:00
Doug Barton
6769638166 Blah ... forgot to re-add this patch for the slave port again. 2010-01-26 18:18:50 +00:00
Sergey Matveychuk
fd36702b5e - Forgot to set : ${unbound_enable:-"NO"}
- Allow user to set a pid file location with unbound_pidfile="..."

PR:		ports/142793 (based on)
Submitted by:	Keith Gaughan <k at stereochro.me>
2010-01-25 14:30:05 +00:00
Martin Wilke
ab9b313b00 - Update to 1.6.4
PR:		143060
Submitted by:	Konstantin Saurbier <konstantin@saurbier.net> (maintainer)
2010-01-25 08:53:29 +00:00
Doug Barton
9b77b5a942 Upgrade to BIND 9.4.3-P5, 9.5.2-P2, and 9.6.1-P3. These versions address
the following vulnerabilities:

BIND 9 Cache Update from Additional Section
https://www.isc.org/advisories/CVE-2009-4022v6
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022
A nameserver with DNSSEC validation enabled may incorrectly add
unauthenticated records to its cache that are received during the
resolution of a recursive client query

BIND 9 DNSSEC validation code could cause bogus NXDOMAIN responses
https://www.isc.org/advisories/CVE-2010-0097
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097
There was an error in the DNSSEC NSEC/NSEC3 validation code that could
cause bogus NXDOMAIN responses (that is, NXDOMAIN responses for records
proven by NSEC or NSEC3 to exist) to be cached as if they had validated
correctly

These issues only affect systems with DNSSEC validation enabled.
2010-01-25 00:25:08 +00:00
Matthias Andree
e05b66b4de Change MAINTAINER to my FreeBSD address.
Update to new upstream release 2.52. Changelog excerpt below the approval.

Approved by: miwi (mentor)

Upstream changelog excerpt (omitting Linux, Solaris and MacOS X specifics):
[...] Re-read the set of network interfaces when re-loading /etc/resolv.conf
  if --bind-interfaces is not set. This handles the case that loopback
  interfaces do not exist when dnsmasq is first started.

  Tweak the PXE code to support port 4011. This should reduce broadcasts and
  make things more reliable when other servers are around. It also improves
  inter-operability with certain clients.

  Make a pxe-service configuration with no filename or boot service type legal:
  this does a local boot. eg.  pxe-service=x86PC, "Local boot"

  Be more conservative in detecting "A for A" queries. Dnsmasq checks if the
  name in a type=A query looks like a dotted-quad IP address and answers the
  query itself if so, rather than forwarding it. Previously dnsmasq relied in
  the library function inet_addr() to convert addresses, and that will accept
  some things which are confusing in this context, like 1.2.3 or even just
  1234. Now we only do A for A processing for four decimal numbers delimited by
  dots.
[...]
  Increased the default limit on number of leases to 1000 (from 150). This is
  mainly a defence against DoS attacks, and for the average "one for two class
  C networks" installation, IP address exhaustion does that just as well.
  Making the limit greater than the number of IP addresses available in such an
  installation removes a surprise which otherwise can catch people out.

  Removed extraneous trailing space in the value of the DNSMASQ_TIME_REMAINING
  DNSMASQ_LEASE_LENGTH and DNSMASQ_LEASE_EXPIRES environment variables. Thanks
  to Gildas Le Nadan for spotting this.

  Provide the network-id tags for a DHCP transaction to the lease-change script
  in the environment variable DNSMASQ_TAGS. A good suggestion from Gildas Le
  Nadan.

  Add support for RFC3925 "Vendor-Identifying Vendor Options". The syntax looks
  like this:
  --dhcp-option=vi-encap:<enterprise number>, .........

  Add support to --dhcp-match to allow matching against RFC3925
  "Vendor-Identifying Vendor Classes". The syntax looks like this:
  --dhcp-match=tag,vi-encap<enterprise number>, <value>

  Add some application specific code to assist in implementing the Broadband
  forum TR069 CPE-WAN specification. The details are in contrib/CPE-WAN/README

  Increase the default DNS packet size limit to 4096, as recommended by RFC5625
  section 4.4.3. This can be reconfigured using --edns-packet-max if needed.
  Thanks to Francis Dupont for pointing this out.

  Rewrite query-ids even for DNSSEC signed packets, since this is allowed by
  RFC5625 section 4.5.
[...]
  Fix link error when including Dbus but excluding DHCP.
  Thanks to Oschtan for the bug report.

  Updated French translation. Thanks to Gildas Le Nadan.

  Updated Polish translation. Thanks to Jan Psota.

  Updated Spanish translation. Thanks to Chris Chatham.
2010-01-23 11:24:31 +00:00
Sergey A. Osokin
69a365881d Fix build on 6.4-STABLE by add pthread's compiler/linker flags.
Bump PORTREVISION.

Reported by:	pointyhat via erwin@
Approved by:	maintainer aka jaap at NLnetLabs dot nl
2010-01-18 20:02:27 +00:00
Martin Wilke
2104a91372 - Update to 1.4.02
- Pass maintainership to submitter

PR:		142723
Submitted by:	Bernhard Froehlich <decke@bluelife.at>
2010-01-18 07:58:26 +00:00
Sergey A. Osokin
01bb4b3b91 Fix build by change dependences.
Fix COMMENT.
Respect CC/CFLAGS.
Write install target.
Bump PORTREVISION.

Report by:	QAT@
Approved by:	Jaap Akkerhuis aka jaap at NLnetLabs dot nl (maintainer)
Pointy hat to:	nemoliu@
2010-01-13 14:20:09 +00:00
Tong LIU
fec356c200 Add autotrust 0.3.1, a a tool to automatically update DNSSEC trust
anchors.

PR:		ports/142523
Submitted by:	Jaap Akkerhuis <jaap at nlnetlabs.nl>
2010-01-13 06:33:07 +00:00
Sergey Matveychuk
7c55f9279a - A patch from SVN. It fixes a regression in IPv6 caching in
1.4.1 version.
2010-01-12 15:28:11 +00:00
Wen Heping
bc12913b52 - Update to 3.2.4
PR:		ports/142718
Submitted by:	Olafur Osvaldsson <osvaldsson@icelandic.net> (maintainer)
2010-01-12 00:41:23 +00:00
Wen Heping
bbf76ee423 - Update to 1.42
PR:		ports/142607
Submitted by:	"Philip M. Gollucci" <pgollucci@freebsd.org>
2010-01-10 23:38:14 +00:00
Mark Linimon
f61aa69467 With portmgr hat on, reset the maintainership of skv@ for ports that
he has had one or more maintainer-timeouts on in the past 12 months.
2010-01-10 03:54:09 +00:00
Xin LI
cb259a5abd Security update to 3.1.7.2.
Submitted by:	maintainer
Security:	vuln dd8f2394-fd08-11de-b425-00215c6a37bb
2010-01-09 10:59:16 +00:00
Wen Heping
5431cb2cac OpenDNSSEC was created as an open-source turn-key solution for
DNSSEC. It secures zone data just before it is published in an
authoritative name server.

WWW: http://www.opendnssec.org

PR:		ports/142103
Submitted by:	Jaap Akkerhuis <jaap@NLnetLabs.nl>
2010-01-07 06:25:07 +00:00
Philippe Audeoud
69edd3c376 - Update to 3.8.0
PR:		ports/142345
Submitted by:	Rob Farmer <rfarmer predatorlabs.net>
Approved by:	maintainer
2010-01-06 09:00:03 +00:00
Doug Barton
3bf3bb4653 Update to version 0.66, which is a major upgrade. Users are cautioned
to thoroughly test this version before updating production systems.

For the port, introduce a new dependency, security/p5-Digest-SHA

Changes in this version, in addition to numerous minor bug fixes:

Feature: Truncation for Nameserver
    TAKE CARE:
    this feature may cause unexpected behavior for your nameservers

    Net::DNS::Packet::truncate is a new method that is called from
    within Net::DNS::Nameserver that truncates a packet according to
    the rules of RFC2181 section 9.

Feature: Added Net::DNS::Domain
    Net::DNS::Domain is an attemt to consistently approach the various
    ways we interface with what RFC 1035 calls <domain-name>.

Feature: KX RR
    Added support for the KX RR, RFC2230

Feature: HIP RR
    Added support for the HIP RR, RFC5205

Feature: DHCID RR
    Added rudimentary support for the DHCID RR.

Fix improved fuzzy matching of CLASS and TYPE in the Question
    constructor method.

Fix AAAA dynamic update
2010-01-01 00:28:07 +00:00
Martin Wilke
8ca9f0d689 - Convert NOMANCOMPRESS to NO_MANCOMPRESS to sync with src
PR:	ports/136065 ports/127469
Submitted by:	N.J. Mann <njm@njm.me.uk> and Aldis Berjoza <killasmurf86@gmail.com>

- Early identify port CONFLICTS

PR:	137855
Submitted by:		Piotr Smyrak <smyru@heron.pl>

- Add --no-same-permissions to the EXTRACT_AFTER_ARGS command.

Tijl Coosemans has been reported an issue that when root is extracting from the
tarball, and the tarball contains world writable files
(sysutils/policykit as an example), there is a chance that the files
gets changed by malicious third parties right after the extraction,
which makes it possible to inject code into the package thus compromise
the system.

Submitted by:	Tijl Coosemans <tijl@coosemans.org> Xin LI (delphij@)

- Fix some whitespaces

Tested with:	exp-run
2009-12-29 10:25:55 +00:00
Martin Wilke
c5c811f904 - Update to 1.0.51
Changes:
	http://cpansearch.perl.org/src/RCAPUTO/POE-Component-Client-DNS-1.051/CHANGES

PR:		140208
Submitted by:	ehaupt@
Approved by:	maintainer timeout
2009-12-25 23:57:22 +00:00
Martin Wilke
88420dc1eb An experiment in benchmarking DNS name services. This tool
is designed to help you as a user determine what name services
are the best to use for an individual machine.

WWW: http://namebench.googlecode.com/

PR:		ports/141202
Submitted by:	Sahil Tandon <sahil at tandon.net>
2009-12-25 19:24:24 +00:00
Wen Heping
7c80b97183 - Update to 2.0.8 2009-12-24 02:42:09 +00:00
Doug Barton
2fadfa2cfb For ports maintained by ports@FreeBSD.org, remove names and/or
e-mail addresses from the pkg-descr file that could reasonably
be mistaken for maintainer contact information in order to avoid
confusion on the part of users looking for support. As a pleasant
side effect this also avoids confusion and/or frustration for people
who are no longer maintaining those ports.
2009-12-21 02:19:12 +00:00
Wen Heping
a1513a0b78 - Update to 1.41
PR:		ports/141725
Submitted by:	Jaap Akkerhuis <jaap@NLnetLabs.nl>
2009-12-18 01:22:19 +00:00
Philip M. Gollucci
30a675022a - Update to 0.12
PR:             ports/141525
Approved by:    maintainer
Submitted by:   myself (pgollucci@)
2009-12-17 22:28:24 +00:00
Sergey Matveychuk
e2ae93b2ae - Update to 1.4.1
- Use --disable-sha2 on 6.4 because of broken OpenSSL in base.
2009-12-17 12:45:52 +00:00
Philip M. Gollucci
368dad8611 - Update to 0.27
PR:             ports/141557
Approved by:     maintainer
Submitted by:   myself (pgollucci@)
2009-12-15 21:08:45 +00:00
Doug Barton
271ea45669 Disable the (optional, debugging) symtable feature till I can figure
out the depth of the perl dependency.
2009-12-14 07:50:20 +00:00
Doug Barton
cbdc7d619f Update CONFLICTS for bind97 2009-12-14 06:29:30 +00:00
Doug Barton
57152b64e6 Add BIND 9.7.0rc1 with a -devel suffix for now so that people can
start testing it sooner rather than later. When the final version
is released the -devel will be removed.

Some of the new features of BIND 9.7.x are:

	- Fully automatic signing of zones by "named"
	- Simplified configuration of DNSSEC Lookaside Validation (DLV)
	- Simplified configuration of Dynamic DNS, using the "ddns-confgen"
	  command line tool or the "local" update-policy option
	- New named option "attach-cache" that allows multiple views to
	  share a single cache
	- DNS rebinding attack prevention
	- New default values for dnssec-keygen parameters
	- Support for RFC 5011 automated trust anchor maintenance
	  (see README.rfc5011 for additional details)
	- Smart signing: simplified tools for zone signing and key
	  maintenance
	- Improved PKCS#11 support
2009-12-14 06:25:17 +00:00
Martin Wilke
1b1b29c5e6 - Get rip python 2.3+
Note:
Python 2.3 is't longer supported and have a lot of security issues.
Convert 2.3+ to yes/or 2.4/5+

With hat:	portmgr
2009-12-13 17:00:14 +00:00
Martin Wilke
2c75e63b79 - Update to 1.6.3
PR:		141208
Submitted by:	Cristiano Rolim Pereira <cristianorolim@hotmail.com>
Approved by:	maintainer
2009-12-13 00:21:11 +00:00