1819624 Members
2963 Online
109604 Solutions
New Discussion юеВ

Re: BIND 9.2 for 11.0

 
Berlene Herren
Honored Contributor

BIND 9.2 for 11.0

BIND 9.2 for 11.0 is now available as a web download from http://www.software.hp.com


Berlene
http://www.mindspring.com/~bkherren/dobes/index.htm
10 REPLIES 10
Christopher Caldwell
Honored Contributor

Re: BIND 9.2 for 11.0

_Finally_. Send much thanks to the folks who did the port.

Odd thing is, the ISC site says that the 9.2 port for HP-UX 11.0 was easy, and the 11i port wouldn't work due to incompatibilities:

HP-UX 11.x, x < 11


HP-UX 11.11 is not yet supported due to its incompatible SIOCGLIFCONF ioctl

So I was never clear on why they did 11i first ...

Again, give the folks my thanks.
Berlene Herren
Honored Contributor

Re: BIND 9.2 for 11.0

I forwarded your thanks, Christopher!

Berlene
http://www.mindspring.com/~bkherren/dobes/index.htm
U.SivaKumar_2
Honored Contributor

Re: BIND 9.2 for 11.0

Hi ,

Thanks for all who ported the wonderful thing.
Berlene , Thanks for you for letting us know.

Hope this reference will be useful for all.


"BIND 9.2.0 has a number of new features over 9.1, including:

The size of the cache can now be limited using the "max-cache-size" option.
The server can now automatically convert RFC1886-style recursive lookup requests into RFC2874-style lookups, when enabled using the new option "allow-v6-synthesis". This allows stub resolvers that support AAAA records but not A6 record chains or binary labels to perform lookups in domains that make use of these IPv6 DNS features.
Performance has been improved.
The man pages now use the more portable "man" macros rather than the "mandoc" macros, and are installed by "make install".
The named.conf parser has been completely rewritten. It now supports "include" directives in more places such as inside "view" statements, and it no longer has any reserved words.
The "rndc status" command is now implemented.
rndc can now be configured automatically.
A BIND 8 compatible stub resolver library is now included in lib/bind.
OpenSSL has been removed from the distribution. This means that to use DNSSEC, OpenSSL must be installed and the --with-openssl option must be supplied to configure. This does not apply to the use of TSIG, which does not require OpenSSL.
The source distribution now builds on Windows NT/2000. See win32utils/readme1.txt and win32utils/win32-build.txt for details.
This distribution already includes a new lightweight stub resolver library and associated resolver daemon that fully support forward and reverse lookups of both IPv4 and IPv6 addresses. This library is still considered experimental and is not a complete replacement for the BIND 8 resolver library. Applications that use the BIND 8 res_* functions to perform DNS lookups or dynamic updates still need to be linked against the BIND 8 libraries. For DNS lookups, they can also use the new "getrrsetbyname()" API.

BIND 9.2 is capable of acting as an authoritative server for DNSSEC secured zones. This functionality is believed to be stable and complete except for lacking support for wildcard records in secure zones.

When acting as a caching server, BIND 9.2 can be configured to perform DNSSEC secure resolution on behalf of its clients. This part of the DNSSEC implementation is still considered experimental"

regards,
U.SivaKumar

Innovations are made when conventions are broken
Sergey Nikolaev
Occasional Contributor

Re: BIND 9.2 for 11.0

Does HP officially supports
bind 9.* on hpux 11.0?

Thanks,
Sergey
Berlene Herren
Honored Contributor

Re: BIND 9.2 for 11.0

HP supports BIND 9.2 for 11.0 and 11i.

Berlene
http://www.mindspring.com/~bkherren/dobes/index.htm
Kathy McGohan_1
Frequent Advisor

Re: BIND 9.2 for 11.0

Berlene, we have several HP Systems and are running HP-UX 11.0 and 11.i. On our 11.0 systems we have bind 4.9.7 and on 11.i we have bind 8.1.2. We also have bind disabled, but was told from our security team that we still need to keep up with the latest bind patches. It looks like from the IAVA 2003-B-0001 we need bind 9.2.0 for both 11.0 and 11.i. Is this right? This is ISC BIND, right?
Berlene Herren
Honored Contributor

Re: BIND 9.2 for 11.0

Yes, and both are available from http://www.software.hp.com

Berlene
http://www.mindspring.com/~bkherren/dobes/index.htm
harry d brown jr
Honored Contributor

Re: BIND 9.2 for 11.0

Berlene,

I've got 9.2 running on a test server in a "named" "local cache" (cache only) only mode, and it doesn't produce statistics, and I can't seem to get the debugging levels to do much. Is it because I'm running it in a "local cache" mode?

thanks,

live free or die
harry
Live Free or Die
Berlene Herren
Honored Contributor

Re: BIND 9.2 for 11.0

No, you should still be able to get stats on a cache server, according to Paul and Cricket. Are you running
#rndc -s server_name stats

Should put it in /etc/named.data/named.stats"

Berlene
http://www.mindspring.com/~bkherren/dobes/index.htm
harry d brown jr
Honored Contributor

Re: BIND 9.2 for 11.0

Interesting. On my local host I issue:

rndc stats
or
rndc -s localhost stats

and all I get "appended" to the stats file is

+++ Statistics Dump +++ (1046377053)
success 0
referral 0
nxrrset 0
nxdomain 0
recursion 0
failure 0
success 0 0.0.127.IN-ADDR.ARPA
referral 0 0.0.127.IN-ADDR.ARPA
nxrrset 0 0.0.127.IN-ADDR.ARPA
nxdomain 0 0.0.127.IN-ADDR.ARPA
recursion 0 0.0.127.IN-ADDR.ARPA
failure 0 0.0.127.IN-ADDR.ARPA
--- Statistics Dump --- (1046377053)

Is that what I should expect?

also, just as an fyi (plus I have ALL of the lastest patches via custom patch manager):

# what /usr/sbin/named
/usr/sbin/named:
$Revision: 2.0 $ Sat Sep 21 11:37:57 GMT 2002
named 9.2.0 Sat Sep 21 11:37:57 GMT 2002
Copyright (C) 1995-1998 Eric Young.All rights reserved.
#

thanks,

live free or die
harry
Live Free or Die