oss-sec mailing list archives

A recommendation for maintainers of BIND packages (re: DNSSEC validation)


From: ISC Security Officer <security-officer () isc org>
Date: Wed, 30 Aug 2017 08:01:31 -0800

Hello, oss-security list subscribers --

Please pardon the intrusion but ISC are trying to reach packagers who
maintain and redistribute packages of BIND based on our source.

We know that many of you selectively pick and choose changes which are
added to current BIND releases for backporting to older BIND versions
on which your distributed packages are based.  For those of you who do,
we would like to make sure you have selected this change:

4564.   [maint]         Update the built in managed keys to include the
                        upcoming root KSK. [RT #44579]

and distributed it to users prior to the completion of the in-progress
root key rollover in order to ensure that DNSSEC validation continues
to work for operators who are using BIND's managed-keys functionality.

If you have any questions, you may contact us using security-officer () isc org

Thank you,

Michael McNally
ISC Security Officer


Current thread: