c4d8a8858a- Fix that with openssl 1.1 control-use-cert: no uses less cpu, by using no encryption over the unix socket.
wouter
2016-11-25 16:14:14 +0000
ae25494609Check and free data allocated by fname_after_chroot
ralph
2016-11-23 11:21:10 +0000
ff49098e7d- patch from Dag-Erling Smorgrav that removes code that relies on sbrk().
wouter
2016-11-22 15:50:07 +0000
338f46d26f- Added unit test for QNAME minimisation + harden below nxdomain synergy.
ralph
2016-11-22 13:53:51 +0000
b4889ffa4d- QNAME minimisation uses QTYPE=A, therefore always check cache for this type in harden-below-nxdomain functionality.
ralph
2016-11-22 10:50:53 +0000
36b4e3e8d0- Make access-control-tag-data RDATA absolute. This makes the RDATA origin consistent between local-data and access-control-tag-data. - Fix NSEC ENT wildcard check. Matching wildcard does not have to be a subdomain of the NSEC owner.
ralph
2016-11-22 10:10:48 +0000
5795b9d972- Fix unit tests for DS hash processing for fake-dsa test option.
wouter
2016-11-22 08:23:24 +0000
2ab2a2ec28- Fix#1158: reference RFC 8020 "NXDOMAIN: There Really Is Nothing Underneath" for the harden-below-nxdomain option.
wouter
2016-11-21 09:53:43 +0000
51aa35e9e6- Fix#1155: test status code of unbound-control in 04-checkconf, not the status code from the tee command.
ralph
2016-11-10 11:20:27 +0000
95d8709a9a- Note that for harden-below-nxdomain the nxdomain must be secure, this means nsec3 with optout is insufficient.
wouter
2016-11-04 14:49:43 +0000
4097f78b84pass ssl_upstream as int to (lib)worker_send_query
ralph
2016-11-04 14:02:22 +0000
3fb4900c0e- Added stub-ssl-upstream and forward-ssl-upstream options.
ralph
2016-11-04 12:07:52 +0000
ba9a05f5e6- Fix#1154: segfault when reading config with duplicate zones.
wouter
2016-11-04 08:16:55 +0000
7e9e2bfb99- configure detects ssl security level API function in the autoconf manner. Every function on its own, so that other libraries (eg. LibreSSL) can develop their API without hindrance.
wouter
2016-11-04 08:05:42 +0000
22f6a8f7a4Fixup #if at start of line, for portability.
wouter
2016-11-04 07:58:57 +0000
c1f7eb0ce5Set openssl security level to 0 when using aNULL ciphers
ralph
2016-11-03 16:59:00 +0000
ab3589f2d1- Fix failure to build on arm64 with no sbrk.
wouter
2016-10-31 08:05:41 +0000
bbe0c0a707- Patch for server.num.zero_ttl stats for count of expired replies, from Pavel Odintsov.
wouter
2016-10-28 15:08:32 +0000
7073948a03- Fix unit tests for openssl 1.1, with no DSA, by faking DSA, enabled with the undocumented switch 'fake-dsa'. It logs a warning.
wouter
2016-10-26 07:38:00 +0000
cb4533e683- Fix#1134: unbound-control set_option -- val-override-date: -1 works immediately to ignore datetime, or back to 0 to enable it again. The -- is to ignore the '-1' as an option flag.
wouter
2016-10-25 11:49:08 +0000
76d75d9d0d- Fix#1134: unbound-control set_option val-date-override: -1 works immediately to ignore datetime, or back to 0 to enable it again.
wouter
2016-10-25 11:44:03 +0000
78de2ff5aeg.root-servers.net has AAAA address.
wouter
2016-10-24 13:11:39 +0000
fa50e32c4bFixup cachedb for root prime module return.
wouter
2016-10-24 13:01:19 +0000
f1e90237e6Fixup prefetch only when needed
wouter
2016-10-24 12:53:13 +0000
be164dce50- Fix#1125: unbound could reuse an answer packet incorrectly for clients with different EDNS parameters, from Jinmei Tatuya.
wouter
2016-10-18 13:42:08 +0000
593353dc9b- Removed patch comments from acllist.c and msgencode.c
wouter
2016-10-18 13:20:42 +0000
bc78c785ce- Patch that resolves CNAMEs entered in local-data conf statements that point to data on the internet, from Jinmei Tatuya (Infoblox).
wouter
2016-10-18 13:18:20 +0000
948aaf7c4b- Fix#829: doc of sldns_wire2str_rdata_buf() return value has an off-by-one typo, from Jinmei Tatuya (Infoblox).
wouter
2016-09-05 07:14:56 +0000