Release 6.0.6
- Feb 13, 2024
-
-
Vladimír Čunát authored
-
Vladimír Čunát authored
-
Vladimír Čunát authored
-
Vladimír Čunát authored
There were some nontrivial conflicts to resolve, NEWS + the line ctx->vld_limit_crypto = KR_VLD_LIMIT_CRYPTO_DEFAULT; (I had this resolution prepared for a long time.)
-
-
Vladimír Čunát authored
DNSSEC verification complexity could be exploited to exhaust CPU resources and stall DNS resolvers. Solution boils down mainly to limiting crypto-validations per packet.
-
Vladimír Čunát authored
in a separate commit, as it will tend to conflict if patching
-
Vladimír Čunát authored
Improve: don't retry in this case.
-
Vladimír Čunát authored
-
Vladimír Čunát authored
Keep the first error in case priorities are equal. At least with the current KeyTrap topic that should work better, but blaming a single error is alchemy anyway, at least in some cases.
-
Vladimír Čunát authored
-
Vladimír Čunát authored
-
- Feb 12, 2024
-
-
Vladimír Čunát authored
The value is in IANA registry, so it's very constant anyway.
-
Vladimír Čunát authored
-
Vladimír Čunát authored
-
Vladimír Čunát authored
-
Vladimír Čunát authored
That's when searching NSEC3 aggressive cache.
-
Vladimír Čunát authored
Limit combination of iterations and salt length, based on estimated expense of the computation. Note that the result only differs for salt length > 44 which is rather nonsensical and very rare: https://chat.dns-oarc.net/community/pl/h58qx9sjkbgt9dajb7x988p78a
-
Vladimír Čunát authored
Also done by BIND9 >= 9.19.19: https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/8515 The latest real-life measurements show that values above 50 are rare: https://chat.dns-oarc.net/community/pl/aadp9wwrp7g7ux1b8chbzebmze
-