bind-dyndb-ldap-1.1.0-0.9.b1.0.1.AXS4

エラータID: AXSA:2012-575:02

Release date: 
Tuesday, July 24, 2012 - 14:41
Subject: 
bind-dyndb-ldap-1.1.0-0.9.b1.0.1.AXS4
Affected Channels: 
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity: 
High
Description: 

This package provides an LDAP back-end plug-in for BIND. It features support for dynamic updates and internal caching, to lift the load off of your LDAP server.

Security issues fixed with this release;

CVE-2012-2134
No description available at the time of writing, please use the CVE links below.

Bug Fixes

• If a zone contained an invalid Resource Record (RR) with the same Fully Qualified Domain Name (FQDN) as the zone name, the bind-dyndb-ldap plug-in refused to load the entire zone. This has been fixed: if an invalid RR is encountered, an error message “Failed to parse RR entry” is logged and the zone continues to load.

• The bind-dyndb-ldap plug-in stopped after the first failure to connect to an LDAP server and users had to execute "rndc reload" to make the plug-in work. This has been fixed: the plug-in retries to connect periodically and no user intervention is required.

• Even after the zone_refresh period timed out and a zone was removed from the LDAP server, the plug-in continued to serve the removed zone. This has been fixed.

• When the named daemon received the rndc reload command or a SIGHUP signal and the plug-in failed to connect to an LDAP server, the plug-in caused named to crash when it received a query which belonged to a zone previously handled by the plug-in. This has been fixed.

• If the named daemon lost connection to an LDAP server for some time and then some zones previously present had been removed from LDAP before a successful reconnection, the plug-in crashed. This has been fixed.

• Fixed the length of some strings so that the SOA serial number and the expiry time fot the forward zone are set correctly during ipa-server installation.

• With sub-domains delegated to other DNS servers, the bind-dyndb-ldap plugin managing the top-domain DNS failed to put A or AAAA glue records in the “additional section” of a DNS answer and sub-domains were not accessible by other DNS servers.This has been fixed.

• The plug-in now correctly returns answers for queries with non-ASCII characters.

Enhancements

• Now supports two new attributes, idnsAllowQuery and idnsAllowTransfer, which can be used to set ACLs for queries or transfers.

• Now supports the new zone attributes idnsForwarders and idnsForwardPolicy which can be used to configure forwarding.

• Now supports zone transfers.

• Added a new option called sync_ptr that can be used to keep A and AAAA records and their PTR records synchronized.

• It is now possible to store configuration for the plug-in in LDAP with idnsConfigObject. Options set through this have higher priority than the ones from the named.conf file.

Refer to /usr/share/doc/bind-dyndb-ldap/README for more information about the new options and attributes.

Solution: 

Update packages

Additional Info: 

N/A

Download: 

SRPMS
  1. bind-dyndb-ldap-1.1.0-0.9.b1.0.1.AXS4.src.rpm
    MD5: bb46924206bad476852f68616cb46c87
    SHA-256: 308ff71c896f49769eebedd2e2114b16f4c688c19ef2b667403fb6a833367e3f
    Size: 306.15 kB

Asianux Server 4 for x86
  1. bind-dyndb-ldap-1.1.0-0.9.b1.0.1.AXS4.i686.rpm
    MD5: 5e97396adab95058af97c746f1a6f865
    SHA-256: 963ee6185f6d5d2b029e15eb0b89fb8835ec0889ba398ea826a3ddaee6b6bb92
    Size: 62.13 kB

Asianux Server 4 for x86_64
  1. bind-dyndb-ldap-1.1.0-0.9.b1.0.1.AXS4.x86_64.rpm
    MD5: 1462908eada606dd8c2e327187e74ce1
    SHA-256: a9166e52d4079d98b9243439729ab008636184792f59e4c857c3b14381821439
    Size: 62.29 kB