sthen 7a32acb9fa Update to BIND 9.10.1-P1, including query limits for recursion (DoS avoidance,
CVE-2014-8500), assertion DoS (recursive only, only with prefetch enabled,
CVE-2014-3214), assertion DoS (EDNS option processing, CVE-2014-3859) and
fixes to GeoIP (CVE-2014-8680 and another unclassified).

https://kb.isc.org/article/AA-01223/81/BIND-9.10.1-P1-Release-Notes.html

Add a local patch to increase the default query limit, during testing it
appears that the standard defaults can be easily falsely triggered during
priming at startup.
2014-12-09 17:21:36 +00:00

464 lines
11 KiB
Plaintext

@comment $OpenBSD: PLIST,v 1.10 2014/12/09 17:21:36 sthen Exp $
@pkgpath net/isc-bind,ratelimit
@newgroup _bind:741
@newuser _bind:741:_bind:daemon:bind user:/nonexistent:/sbin/nologin
@extra ${SYSCONFDIR}/rndc.key
@extra ${LOCALSTATEDIR}/named/etc/rndc.key
bin/bind9-config
@bin bin/delv
@bin bin/dig
@bin bin/host
bin/isc-config.sh
@bin bin/nslookup
@bin bin/nsupdate
include/bind9/
include/bind9/check.h
include/bind9/getaddresses.h
include/bind9/version.h
include/dns/
include/dns/acache.h
include/dns/acl.h
include/dns/adb.h
include/dns/bit.h
include/dns/byaddr.h
include/dns/cache.h
include/dns/callbacks.h
include/dns/cert.h
include/dns/client.h
include/dns/clientinfo.h
include/dns/compress.h
include/dns/db.h
include/dns/dbiterator.h
include/dns/dbtable.h
include/dns/diff.h
include/dns/dispatch.h
include/dns/dlz.h
include/dns/dlz_dlopen.h
include/dns/dns64.h
include/dns/dnssec.h
include/dns/ds.h
include/dns/dsdigest.h
include/dns/ecdb.h
include/dns/enumclass.h
include/dns/enumtype.h
include/dns/events.h
include/dns/fixedname.h
include/dns/forward.h
include/dns/geoip.h
include/dns/iptable.h
include/dns/journal.h
include/dns/keydata.h
include/dns/keyflags.h
include/dns/keytable.h
include/dns/keyvalues.h
include/dns/lib.h
include/dns/log.h
include/dns/lookup.h
include/dns/master.h
include/dns/masterdump.h
include/dns/message.h
include/dns/name.h
include/dns/ncache.h
include/dns/nsec.h
include/dns/nsec3.h
include/dns/opcode.h
include/dns/order.h
include/dns/peer.h
include/dns/portlist.h
include/dns/private.h
include/dns/rbt.h
include/dns/rcode.h
include/dns/rdata.h
include/dns/rdataclass.h
include/dns/rdatalist.h
include/dns/rdataset.h
include/dns/rdatasetiter.h
include/dns/rdataslab.h
include/dns/rdatastruct.h
include/dns/rdatatype.h
include/dns/request.h
include/dns/resolver.h
include/dns/result.h
include/dns/rootns.h
include/dns/rpz.h
include/dns/rriterator.h
include/dns/rrl.h
include/dns/sdb.h
include/dns/sdlz.h
include/dns/secalg.h
include/dns/secproto.h
include/dns/soa.h
include/dns/ssu.h
include/dns/stats.h
include/dns/tcpmsg.h
include/dns/time.h
include/dns/timer.h
include/dns/tkey.h
include/dns/tsec.h
include/dns/tsig.h
include/dns/ttl.h
include/dns/types.h
include/dns/update.h
include/dns/validator.h
include/dns/version.h
include/dns/view.h
include/dns/xfrin.h
include/dns/zone.h
include/dns/zonekey.h
include/dns/zt.h
include/dst/
include/dst/dst.h
include/dst/gssapi.h
include/dst/lib.h
include/dst/result.h
include/irs/
include/irs/context.h
include/irs/dnsconf.h
include/irs/netdb.h
include/irs/platform.h
include/irs/resconf.h
include/irs/types.h
include/irs/version.h
include/isc/
include/isc/aes.h
include/isc/app.h
include/isc/assertions.h
include/isc/atomic.h
include/isc/backtrace.h
include/isc/base32.h
include/isc/base64.h
include/isc/bind9.h
include/isc/boolean.h
include/isc/buffer.h
include/isc/bufferlist.h
include/isc/commandline.h
include/isc/condition.h
include/isc/counter.h
include/isc/crc64.h
include/isc/dir.h
include/isc/entropy.h
include/isc/error.h
include/isc/event.h
include/isc/eventclass.h
include/isc/file.h
include/isc/formatcheck.h
include/isc/fsaccess.h
include/isc/hash.h
include/isc/heap.h
include/isc/hex.h
include/isc/hmacmd5.h
include/isc/hmacsha.h
include/isc/httpd.h
include/isc/int.h
include/isc/interfaceiter.h
include/isc/iterated_hash.h
include/isc/json.h
include/isc/keyboard.h
include/isc/lang.h
include/isc/lex.h
include/isc/lfsr.h
include/isc/lib.h
include/isc/list.h
include/isc/log.h
include/isc/magic.h
include/isc/md5.h
include/isc/mem.h
include/isc/msgcat.h
include/isc/msgs.h
include/isc/mutex.h
include/isc/mutexblock.h
include/isc/net.h
include/isc/netaddr.h
include/isc/netdb.h
include/isc/netscope.h
include/isc/offset.h
include/isc/once.h
include/isc/ondestroy.h
include/isc/os.h
include/isc/parseint.h
include/isc/platform.h
include/isc/pool.h
include/isc/portset.h
include/isc/print.h
include/isc/queue.h
include/isc/quota.h
include/isc/radix.h
include/isc/random.h
include/isc/ratelimiter.h
include/isc/refcount.h
include/isc/regex.h
include/isc/region.h
include/isc/resource.h
include/isc/result.h
include/isc/resultclass.h
include/isc/rwlock.h
include/isc/safe.h
include/isc/serial.h
include/isc/sha1.h
include/isc/sha2.h
include/isc/sockaddr.h
include/isc/socket.h
include/isc/stat.h
include/isc/stats.h
include/isc/stdio.h
include/isc/stdlib.h
include/isc/stdtime.h
include/isc/strerror.h
include/isc/string.h
include/isc/symtab.h
include/isc/syslog.h
include/isc/task.h
include/isc/taskpool.h
include/isc/thread.h
include/isc/time.h
include/isc/timer.h
include/isc/tm.h
include/isc/types.h
include/isc/util.h
include/isc/version.h
include/isc/xml.h
include/isccc/
include/isccc/alist.h
include/isccc/base64.h
include/isccc/cc.h
include/isccc/ccmsg.h
include/isccc/events.h
include/isccc/lib.h
include/isccc/result.h
include/isccc/sexpr.h
include/isccc/symtab.h
include/isccc/symtype.h
include/isccc/types.h
include/isccc/util.h
include/isccc/version.h
include/isccfg/
include/isccfg/aclconf.h
include/isccfg/cfg.h
include/isccfg/dnsconf.h
include/isccfg/grammar.h
include/isccfg/log.h
include/isccfg/namedconf.h
include/isccfg/version.h
include/lwres/
include/lwres/context.h
include/lwres/int.h
include/lwres/ipv6.h
include/lwres/lang.h
include/lwres/list.h
include/lwres/lwbuffer.h
include/lwres/lwpacket.h
include/lwres/lwres.h
include/lwres/net.h
include/lwres/netdb.h
include/lwres/platform.h
include/lwres/result.h
include/lwres/stdlib.h
include/lwres/string.h
include/lwres/version.h
include/pk11/
include/pk11/constants.h
include/pk11/internal.h
include/pk11/pk11.h
include/pk11/result.h
include/pkcs11/
include/pkcs11/cryptoki.h
include/pkcs11/pkcs11.h
include/pkcs11/pkcs11f.h
include/pkcs11/pkcs11t.h
lib/libbind9.a
lib/libbind9.la
@lib lib/libbind9.so.${LIBbind9_VERSION}
lib/libdns.a
lib/libdns.la
@lib lib/libdns.so.${LIBdns_VERSION}
lib/libirs.a
lib/libirs.la
@lib lib/libirs.so.${LIBirs_VERSION}
lib/libisc.a
lib/libisc.la
@lib lib/libisc.so.${LIBisc_VERSION}
lib/libisccc.a
lib/libisccc.la
@lib lib/libisccc.so.${LIBisccc_VERSION}
lib/libisccfg.a
lib/libisccfg.la
@lib lib/libisccfg.so.${LIBisccfg_VERSION}
lib/liblwres.a
lib/liblwres.la
@lib lib/liblwres.so.${LIBlwres_VERSION}
@man man/man1/arpaname.1
@man man/man1/bind9-config.1
@man man/man1/delv.1
@man man/man1/dig.1
@man man/man1/host.1
@man man/man1/isc-config.sh.1
@man man/man1/named-rrchecker.1
@man man/man1/nslookup.1
@man man/man1/nsupdate.1
@man man/man3/lwres.3
@man man/man3/lwres_addr_parse.3
@man man/man3/lwres_buffer.3
@man man/man3/lwres_buffer_add.3
@man man/man3/lwres_buffer_back.3
@man man/man3/lwres_buffer_clear.3
@man man/man3/lwres_buffer_first.3
@man man/man3/lwres_buffer_forward.3
@man man/man3/lwres_buffer_getmem.3
@man man/man3/lwres_buffer_getuint16.3
@man man/man3/lwres_buffer_getuint32.3
@man man/man3/lwres_buffer_getuint8.3
@man man/man3/lwres_buffer_init.3
@man man/man3/lwres_buffer_invalidate.3
@man man/man3/lwres_buffer_putmem.3
@man man/man3/lwres_buffer_putuint16.3
@man man/man3/lwres_buffer_putuint32.3
@man man/man3/lwres_buffer_putuint8.3
@man man/man3/lwres_buffer_subtract.3
@man man/man3/lwres_conf_clear.3
@man man/man3/lwres_conf_get.3
@man man/man3/lwres_conf_init.3
@man man/man3/lwres_conf_parse.3
@man man/man3/lwres_conf_print.3
@man man/man3/lwres_config.3
@man man/man3/lwres_context.3
@man man/man3/lwres_context_allocmem.3
@man man/man3/lwres_context_create.3
@man man/man3/lwres_context_destroy.3
@man man/man3/lwres_context_freemem.3
@man man/man3/lwres_context_initserial.3
@man man/man3/lwres_context_nextserial.3
@man man/man3/lwres_context_sendrecv.3
@man man/man3/lwres_endhostent.3
@man man/man3/lwres_endhostent_r.3
@man man/man3/lwres_freeaddrinfo.3
@man man/man3/lwres_freehostent.3
@man man/man3/lwres_gabn.3
@man man/man3/lwres_gabnrequest_free.3
@man man/man3/lwres_gabnrequest_parse.3
@man man/man3/lwres_gabnrequest_render.3
@man man/man3/lwres_gabnresponse_free.3
@man man/man3/lwres_gabnresponse_parse.3
@man man/man3/lwres_gabnresponse_render.3
@man man/man3/lwres_gai_strerror.3
@man man/man3/lwres_getaddrinfo.3
@man man/man3/lwres_getaddrsbyname.3
@man man/man3/lwres_gethostbyaddr.3
@man man/man3/lwres_gethostbyaddr_r.3
@man man/man3/lwres_gethostbyname.3
@man man/man3/lwres_gethostbyname2.3
@man man/man3/lwres_gethostbyname_r.3
@man man/man3/lwres_gethostent.3
@man man/man3/lwres_gethostent_r.3
@man man/man3/lwres_getipnode.3
@man man/man3/lwres_getipnodebyaddr.3
@man man/man3/lwres_getipnodebyname.3
@man man/man3/lwres_getnamebyaddr.3
@man man/man3/lwres_getnameinfo.3
@man man/man3/lwres_getrrsetbyname.3
@man man/man3/lwres_gnba.3
@man man/man3/lwres_gnbarequest_free.3
@man man/man3/lwres_gnbarequest_parse.3
@man man/man3/lwres_gnbarequest_render.3
@man man/man3/lwres_gnbaresponse_free.3
@man man/man3/lwres_gnbaresponse_parse.3
@man man/man3/lwres_gnbaresponse_render.3
@man man/man3/lwres_herror.3
@man man/man3/lwres_hstrerror.3
@man man/man3/lwres_inetntop.3
@man man/man3/lwres_lwpacket_parseheader.3
@man man/man3/lwres_lwpacket_renderheader.3
@man man/man3/lwres_net_ntop.3
@man man/man3/lwres_noop.3
@man man/man3/lwres_nooprequest_free.3
@man man/man3/lwres_nooprequest_parse.3
@man man/man3/lwres_nooprequest_render.3
@man man/man3/lwres_noopresponse_free.3
@man man/man3/lwres_noopresponse_parse.3
@man man/man3/lwres_noopresponse_render.3
@man man/man3/lwres_packet.3
@man man/man3/lwres_resutil.3
@man man/man3/lwres_sethostent.3
@man man/man3/lwres_sethostent_r.3
@man man/man3/lwres_string_parse.3
@man man/man5/named.conf.5
@man man/man5/rndc.conf.5
@man man/man8/ddns-confgen.8
@man man/man8/dnssec-checkds.8
@man man/man8/dnssec-coverage.8
@man man/man8/dnssec-dsfromkey.8
@man man/man8/dnssec-importkey.8
@man man/man8/dnssec-keyfromlabel.8
@man man/man8/dnssec-keygen.8
@man man/man8/dnssec-revoke.8
@man man/man8/dnssec-settime.8
@man man/man8/dnssec-signzone.8
@man man/man8/dnssec-verify.8
@man man/man8/genrandom.8
@man man/man8/isc-hmac-fixup.8
@man man/man8/lwresd.8
@man man/man8/named-checkconf.8
@man man/man8/named-checkzone.8
@man man/man8/named-compilezone.8
@man man/man8/named-journalprint.8
@man man/man8/named.8
@man man/man8/nsec3hash.8
@man man/man8/rndc-confgen.8
@man man/man8/rndc.8
@man man/man8/tsig-keygen.8
@bin sbin/arpaname
@bin sbin/ddns-confgen
sbin/dnssec-checkds
sbin/dnssec-coverage
@bin sbin/dnssec-dsfromkey
@bin sbin/dnssec-importkey
@bin sbin/dnssec-keyfromlabel
@bin sbin/dnssec-keygen
@bin sbin/dnssec-revoke
@bin sbin/dnssec-settime
@bin sbin/dnssec-signzone
@bin sbin/dnssec-verify
@bin sbin/genrandom
@bin sbin/isc-hmac-fixup
@bin sbin/lwresd
@bin sbin/named
@bin sbin/named-checkconf
@bin sbin/named-checkzone
sbin/named-compilezone
@bin sbin/named-journalprint
@bin sbin/named-rrchecker
@bin sbin/nsec3hash
@bin sbin/rndc
@bin sbin/rndc-confgen
sbin/tsig-keygen
share/examples/bind9/
@sample ${LOCALSTATEDIR}/named/
@sample ${LOCALSTATEDIR}/named/master/
@sample ${LOCALSTATEDIR}/named/standard/
@group _bind
@mode 750
@sample ${LOCALSTATEDIR}/named/etc/
@mode 775
@sample ${LOCALSTATEDIR}/named/slave/
@sample ${LOCALSTATEDIR}/named/tmp/
@mode
@group
share/examples/bind9/bind.keys
@sample ${SYSCONFDIR}/bind.keys
share/examples/bind9/localhost
@sample ${LOCALSTATEDIR}/named/standard/localhost
share/examples/bind9/loopback
@sample ${LOCALSTATEDIR}/named/standard/loopback
share/examples/bind9/loopback6.arpa
@sample ${LOCALSTATEDIR}/named/standard/loopback6.arpa
share/examples/bind9/named.conf
@group _bind
@mode 640
@sample ${LOCALSTATEDIR}/named/etc/named.conf
@mode
@group
share/examples/bind9/root.hint
@group wheel
@sample ${LOCALSTATEDIR}/named/etc/root.hint
@group
@rcscript ${RCDIR}/isc_named