[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#873481: marked as done (jessie-pu: package bind9/9.9.5.dfsg-9+deb8u13.1)



Your message dated Sat, 09 Dec 2017 10:47:53 +0000
with message-id <1512816473.1994.32.camel@adam-barratt.org.uk>
and subject line Closing bugs for updates included in jessie point release
has caused the Debian Bug report #873481,
regarding jessie-pu: package bind9/9.9.5.dfsg-9+deb8u13.1
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
873481: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=873481
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: release.debian.org
Severity: normal
Tags: jessie
User: release.debian.org@packages.debian.org
Usertags: pu

Dear release team,

this is the jessie counterpart of bind9 update to KSK-2017.

No other change has been done to the package.

Cheers,
Ondrej

-- System Information:
Debian Release: 9.1
  APT prefers stable
  APT policy: (990, 'stable'), (500, 'unstable-debug'), (500, 'stable-debug'), (500, 'unstable'), (1, 'experimental-debug'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 4.4.0-83-generic (SMP w/8 CPU cores)
Locale: LANG=en_DK.UTF-8, LC_CTYPE=en_DK.UTF-8 (charmap=UTF-8), LANGUAGE=en_DK.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.0
Source: bind9
Binary: bind9, bind9utils, bind9-doc, host, bind9-host, libbind-dev, libbind9-90, libdns100, libisc95, liblwres90, libisccc90, libisccfg90, dnsutils, lwresd, libbind-export-dev, libdns-export100, libdns-export100-udeb, libisc-export95, libisc-export95-udeb, libisccfg-export90, libisccfg-export90-udeb, libirs-export91, libirs-export91-udeb
Architecture: any all
Version: 1:9.9.5.dfsg-9+deb8u13.1
Maintainer: LaMont Jones <lamont@debian.org>
Uploaders: Michael Gilbert <mgilbert@debian.org>
Standards-Version: 3.7.3.0
Vcs-Browser: http://git.debian.org/?p=users/lamont/bind9.git
Vcs-Git: git://git.debian.org/~lamont/bind9.git
Build-Depends: libkrb5-dev, debhelper (>= 5), libssl-dev, libtool, bison, libdb-dev (>> 4.6), libldap2-dev, libxml2-dev, libcap2-dev [!kfreebsd-i386 !kfreebsd-amd64 !hurd-i386], hardening-wrapper, libgeoip-dev (>= 1.4.6.dfsg-5), dpkg-dev (>= 1.15.5), python, python-argparse, dh-systemd, autotools-dev, dh-autoreconf
Build-Conflicts: libdb4.2-dev
Package-List:
 bind9 deb net optional arch=any
 bind9-doc deb doc optional arch=all
 bind9-host deb net standard arch=any
 bind9utils deb net optional arch=any
 dnsutils deb net standard arch=any
 host deb net standard arch=all
 libbind-dev deb libdevel optional arch=any
 libbind-export-dev deb libdevel optional arch=any
 libbind9-90 deb libs standard arch=any
 libdns-export100 deb libs optional arch=any
 libdns-export100-udeb udeb debian-installer optional arch=any
 libdns100 deb libs standard arch=any
 libirs-export91 deb libs optional arch=any
 libirs-export91-udeb udeb debian-installer optional arch=any
 libisc-export95 deb libs optional arch=any
 libisc-export95-udeb udeb debian-installer optional arch=any
 libisc95 deb libs standard arch=any
 libisccc90 deb libs optional arch=any
 libisccfg-export90 deb libs optional arch=any
 libisccfg-export90-udeb udeb debian-installer optional arch=any
 libisccfg90 deb libs optional arch=any
 liblwres90 deb libs standard arch=any
 lwresd deb net optional arch=any
Checksums-Sha1:
 ea05323d1d799fae970a7124debe297ef71f2cd0 7877309 bind9_9.9.5.dfsg.orig.tar.gz
 d45a2598b34f4d46a191e6f7782da0ce6e871821 137365 bind9_9.9.5.dfsg-9+deb8u13.1.diff.gz
Checksums-Sha256:
 8108e01d5b501642d986beae7dfff9650b5bf54d87677275a8aaf4f0bcb008e6 7877309 bind9_9.9.5.dfsg.orig.tar.gz
 5d13026388ee8f0fe5727f8a1fc5e30da74ff92715f04540bf9493b13ed3d255 137365 bind9_9.9.5.dfsg-9+deb8u13.1.diff.gz
Files:
 e3b03e1cd273d708cbfbd862297646ce 7877309 bind9_9.9.5.dfsg.orig.tar.gz
 cad09fbae932847b2e10c18d7b6a281f 137365 bind9_9.9.5.dfsg-9+deb8u13.1.diff.gz

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEMLkz2A/OPZgaLTj7DJm3DvT8uwcFAlmj27pfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDMw
QjkzM0Q4MEZDRTNEOTgxQTJEMzhGQjBDOTlCNzBFRjRGQ0JCMDcACgkQDJm3DvT8
uwcEJxAAoNgnTXaMLwFzp23YajYE9l9a2ecNWefjln9lb0b6eaq508xIuTwkWTtT
IzC93IXZYNhA2Me1WxG8+4nem8EGLxCN6+1nnv3ND/NK6chdZsJ9NB9FWju7HSPC
AuqcizCsl7qbh4oNI4sw7bpv0vDvuiLF2O/QFItL31aYnHMaWB07ATjGvHz1y/Bv
el/dnKQcwSTt809ue0QXbCZIhCC2IFkTpz2llF/Bp9fm49BuhhwBFE72yelSD3fo
2660W+wChtBlUVk7H1Vk9ug4X6y04QUc9YrlhW9k+fowsdJc2UMrEMuJMml7XqPN
gCEex1VPMesnnqi1hpxskd0B5vbYdPkC4fZv7xAp1BIKXzsJry9IWLtNHZSFUsiY
ExQjgWgRdtHascvau3enqEMrwogDHvuj+7CUMGwoJZXQ65o/O85sStlTvF/ZY8GE
tNDBXVp/BUJLHycK27NPkpXy9Ge7+7g/dCf11NmCl8gdB0QqVmR8Cp+xaa7YKA/t
02HQRZuYwc5ikJGLvX0olx4+zIyhEiF++i1kDgZJWRRjUxkaUudujH4Gk0A0G68R
zNficFniusmlY1IaP7AK/Zai6q8X/ZhSdnduOh9BycNkqrtUcEehxdDC6TPP8BVL
XuYu1wa3qsuMSCIp/USV1SlHhViDRqVZ76OyEFo8pIalpZ7Qk58=
=es2C
-----END PGP SIGNATURE-----
diff -u bind9-9.9.5.dfsg/debian/changelog bind9-9.9.5.dfsg/debian/changelog
--- bind9-9.9.5.dfsg/debian/changelog
+++ bind9-9.9.5.dfsg/debian/changelog
@@ -1,3 +1,13 @@
+bind9 (1:9.9.5.dfsg-9+deb8u13.1) jessie; urgency=high
+
+  [ Bernhard Schmidt ]
+  * Import upcoming DNSSEC KSK-2017 from 9.10.5
+
+  [ Ondřej Surý ]
+  * Non-maintainer upload.
+
+ -- Ondřej Surý <ondrej@debian.org>  Mon, 28 Aug 2017 10:26:39 +0200
+
 bind9 (1:9.9.5.dfsg-9+deb8u13) jessie-security; urgency=high
 
   * Non-maintainer upload by the Security Team.
only in patch2:
unchanged:
--- bind9-9.9.5.dfsg.orig/bin/named/bind.keys.h
+++ bind9-9.9.5.dfsg/bin/named/bind.keys.h
@@ -1,7 +1,3 @@
-/*
- * Generated by bindkeys.pl 1.7 2011/01/04 23:47:13 tbox Exp  
- * From bind.keys 1.7 2011/01/03 23:45:07 each Exp  
- */
 #define TRUSTED_KEYS "\
 # The bind.keys file is used to override the built-in DNSSEC trust anchors\n\
 # which are included as part of BIND 9.  As of the current release, the only\n\
@@ -19,34 +15,58 @@
 #\n\
 # This file is NOT expected to be user-configured.\n\
 #\n\
-# These keys are current as of January 2011.  If any key fails to\n\
+# These keys are current as of Feburary 2017.  If any key fails to\n\
 # initialize correctly, it may have expired.  In that event you should\n\
 # replace this file with a current version.  The latest version of\n\
 # bind.keys can always be obtained from ISC at https://www.isc.org/bind-keys.\n\
 \n\
 trusted-keys {\n\
-	# ISC DLV: See https://www.isc.org/solutions/dlv for details.\n\
-        # NOTE: This key is activated by setting \"dnssec-lookaside auto;\"\n\
-        # in named.conf.\n\
-	dlv.isc.org. 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2\n\
-		brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+\n\
-		1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5\n\
-		ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk\n\
-		Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM\n\
-		QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt\n\
-		TDN0YUuWrBNh\";\n\
-\n\
-	# ROOT KEY: See https://data.iana.org/root-anchors/root-anchors.xml\n\
-	# for current trust anchor information.\n\
-        # NOTE: This key is activated by setting \"dnssec-validation auto;\"\n\
+        # ISC DLV: See https://www.isc.org/solutions/dlv for details.\n\
+        #\n\
+        # NOTE: The ISC DLV zone is being phased out as of February 2017;\n\
+        # the key will remain in place but the zone will be otherwise empty.\n\
+        # Configuring \"dnssec-lookaside auto;\" to activate this key is\n\
+        # harmless, but is no longer useful and is not recommended.\n\
+        dlv.isc.org. 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2\n\
+                brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+\n\
+                1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5\n\
+                ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk\n\
+                Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM\n\
+                QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt\n\
+                TDN0YUuWrBNh\";\n\
+\n\
+        # ROOT KEYS: See https://data.iana.org/root-anchors/root-anchors.xml\n\
+        # for current trust anchor information.\n\
+        #\n\
+        # These keys are activated by setting \"dnssec-validation auto;\"\n\
         # in named.conf.\n\
-	. 257 3 8 \"AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF\n\
-		FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX\n\
-		bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD\n\
-		X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz\n\
-		W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS\n\
-		Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq\n\
-		QxA+Uk1ihz0=\";\n\
+        #\n\
+        # This key (19036) is to be phased out starting in 2017. It will\n\
+        # remain in the root zone for some time after its successor key\n\
+        # has been added. It will remain this file until it is removed from\n\
+        # the root zone.\n\
+        . 257 3 8 \"AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF\n\
+                FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX\n\
+                bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD\n\
+                X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz\n\
+                W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS\n\
+                Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq\n\
+                QxA+Uk1ihz0=\";\n\
+\n\
+        # This key (20326) is to be published in the root zone in 2017.\n\
+        # Servers which were already using the old key (19036) should\n\
+        # roll seamlessly to this new one via RFC 5011 rollover. Servers\n\
+        # being set up for the first time can use the contents of this\n\
+        # file as initializing keys; thereafter, the keys in the\n\
+        # managed key database will be trusted and maintained\n\
+        # automatically.\n\
+        . 257 3 8 \"AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTOiW1vkIbzxeF3\n\
+                +/4RgWOq7HrxRixHlFlExOLAJr5emLvN7SWXgnLh4+B5xQlNVz8Og8kv\n\
+                ArMtNROxVQuCaSnIDdD5LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF\n\
+                0jLHwVN8efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7pr+e\n\
+                oZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLYA4/ilBmSVIzuDWfd\n\
+                RUfhHdY6+cn8HFRm+2hM8AnXGXws9555KrUB5qihylGa8subX2Nn6UwN\n\
+                R1AkUTV74bU=\";\n\
 };\n\
 "
 
@@ -67,33 +87,57 @@
 #\n\
 # This file is NOT expected to be user-configured.\n\
 #\n\
-# These keys are current as of January 2011.  If any key fails to\n\
+# These keys are current as of Feburary 2017.  If any key fails to\n\
 # initialize correctly, it may have expired.  In that event you should\n\
 # replace this file with a current version.  The latest version of\n\
 # bind.keys can always be obtained from ISC at https://www.isc.org/bind-keys.\n\
 \n\
 managed-keys {\n\
-	# ISC DLV: See https://www.isc.org/solutions/dlv for details.\n\
-        # NOTE: This key is activated by setting \"dnssec-lookaside auto;\"\n\
-        # in named.conf.\n\
-	dlv.isc.org. initial-key 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2\n\
-		brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+\n\
-		1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5\n\
-		ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk\n\
-		Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM\n\
-		QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt\n\
-		TDN0YUuWrBNh\";\n\
-\n\
-	# ROOT KEY: See https://data.iana.org/root-anchors/root-anchors.xml\n\
-	# for current trust anchor information.\n\
-        # NOTE: This key is activated by setting \"dnssec-validation auto;\"\n\
+        # ISC DLV: See https://www.isc.org/solutions/dlv for details.\n\
+        #\n\
+        # NOTE: The ISC DLV zone is being phased out as of February 2017;\n\
+        # the key will remain in place but the zone will be otherwise empty.\n\
+        # Configuring \"dnssec-lookaside auto;\" to activate this key is\n\
+        # harmless, but is no longer useful and is not recommended.\n\
+        dlv.isc.org. initial-key 257 3 5 \"BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2\n\
+                brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+\n\
+                1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5\n\
+                ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk\n\
+                Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM\n\
+                QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt\n\
+                TDN0YUuWrBNh\";\n\
+\n\
+        # ROOT KEYS: See https://data.iana.org/root-anchors/root-anchors.xml\n\
+        # for current trust anchor information.\n\
+        #\n\
+        # These keys are activated by setting \"dnssec-validation auto;\"\n\
         # in named.conf.\n\
-	. initial-key 257 3 8 \"AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF\n\
-		FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX\n\
-		bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD\n\
-		X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz\n\
-		W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS\n\
-		Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq\n\
-		QxA+Uk1ihz0=\";\n\
+        #\n\
+        # This key (19036) is to be phased out starting in 2017. It will\n\
+        # remain in the root zone for some time after its successor key\n\
+        # has been added. It will remain this file until it is removed from\n\
+        # the root zone.\n\
+        . initial-key 257 3 8 \"AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF\n\
+                FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX\n\
+                bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD\n\
+                X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz\n\
+                W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS\n\
+                Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq\n\
+                QxA+Uk1ihz0=\";\n\
+\n\
+        # This key (20326) is to be published in the root zone in 2017.\n\
+        # Servers which were already using the old key (19036) should\n\
+        # roll seamlessly to this new one via RFC 5011 rollover. Servers\n\
+        # being set up for the first time can use the contents of this\n\
+        # file as initializing keys; thereafter, the keys in the\n\
+        # managed key database will be trusted and maintained\n\
+        # automatically.\n\
+        . initial-key 257 3 8 \"AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTOiW1vkIbzxeF3\n\
+                +/4RgWOq7HrxRixHlFlExOLAJr5emLvN7SWXgnLh4+B5xQlNVz8Og8kv\n\
+                ArMtNROxVQuCaSnIDdD5LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF\n\
+                0jLHwVN8efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7pr+e\n\
+                oZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLYA4/ilBmSVIzuDWfd\n\
+                RUfhHdY6+cn8HFRm+2hM8AnXGXws9555KrUB5qihylGa8subX2Nn6UwN\n\
+                R1AkUTV74bU=\";\n\
 };\n\
 "
only in patch2:
unchanged:
--- bind9-9.9.5.dfsg.orig/bind.keys
+++ bind9-9.9.5.dfsg/bind.keys
@@ -1,4 +1,3 @@
-/* $Id: bind.keys,v 1.7 2011/01/03 23:45:07 each Exp $ */
 # The bind.keys file is used to override the built-in DNSSEC trust anchors
 # which are included as part of BIND 9.  As of the current release, the only
 # trust anchors it contains are those for the DNS root zone ("."), and for
@@ -15,32 +14,56 @@
 #
 # This file is NOT expected to be user-configured.
 #
-# These keys are current as of January 2011.  If any key fails to
+# These keys are current as of Feburary 2017.  If any key fails to
 # initialize correctly, it may have expired.  In that event you should
 # replace this file with a current version.  The latest version of
 # bind.keys can always be obtained from ISC at https://www.isc.org/bind-keys.
 
 managed-keys {
-	# ISC DLV: See https://www.isc.org/solutions/dlv for details.
-        # NOTE: This key is activated by setting "dnssec-lookaside auto;"
-        # in named.conf.
-	dlv.isc.org. initial-key 257 3 5 "BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2
-		brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+
-		1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5
-		ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk
-		Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM
-		QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt
-		TDN0YUuWrBNh";
+        # ISC DLV: See https://www.isc.org/solutions/dlv for details.
+        #
+        # NOTE: The ISC DLV zone is being phased out as of February 2017;
+        # the key will remain in place but the zone will be otherwise empty.
+        # Configuring "dnssec-lookaside auto;" to activate this key is
+        # harmless, but is no longer useful and is not recommended.
+        dlv.isc.org. initial-key 257 3 5 "BEAAAAPHMu/5onzrEE7z1egmhg/WPO0+juoZrW3euWEn4MxDCE1+lLy2
+                brhQv5rN32RKtMzX6Mj70jdzeND4XknW58dnJNPCxn8+jAGl2FZLK8t+
+                1uq4W+nnA3qO2+DL+k6BD4mewMLbIYFwe0PG73Te9fZ2kJb56dhgMde5
+                ymX4BI/oQ+cAK50/xvJv00Frf8kw6ucMTwFlgPe+jnGxPPEmHAte/URk
+                Y62ZfkLoBAADLHQ9IrS2tryAe7mbBZVcOwIeU/Rw/mRx/vwwMCTgNboM
+                QKtUdvNXDrYJDSHZws3xiRXF1Rf+al9UmZfSav/4NWLKjHzpT59k/VSt
+                TDN0YUuWrBNh";
 
-	# ROOT KEY: See https://data.iana.org/root-anchors/root-anchors.xml
-	# for current trust anchor information.
-        # NOTE: This key is activated by setting "dnssec-validation auto;"
+        # ROOT KEYS: See https://data.iana.org/root-anchors/root-anchors.xml
+        # for current trust anchor information.
+        #
+        # These keys are activated by setting "dnssec-validation auto;"
         # in named.conf.
-	. initial-key 257 3 8 "AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF
-		FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX
-		bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD
-		X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz
-		W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS
-		Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq
-		QxA+Uk1ihz0=";
+        #
+        # This key (19036) is to be phased out starting in 2017. It will
+        # remain in the root zone for some time after its successor key
+        # has been added. It will remain this file until it is removed from
+        # the root zone.
+        . initial-key 257 3 8 "AwEAAagAIKlVZrpC6Ia7gEzahOR+9W29euxhJhVVLOyQbSEW0O8gcCjF
+                FVQUTf6v58fLjwBd0YI0EzrAcQqBGCzh/RStIoO8g0NfnfL2MTJRkxoX
+                bfDaUeVPQuYEhg37NZWAJQ9VnMVDxP/VHL496M/QZxkjf5/Efucp2gaD
+                X6RS6CXpoY68LsvPVjR0ZSwzz1apAzvN9dlzEheX7ICJBBtuA6G3LQpz
+                W5hOA2hzCTMjJPJ8LbqF6dsV6DoBQzgul0sGIcGOYl7OyQdXfZ57relS
+                Qageu+ipAdTTJ25AsRTAoub8ONGcLmqrAmRLKBP1dfwhYB4N7knNnulq
+                QxA+Uk1ihz0=";
+
+        # This key (20326) is to be published in the root zone in 2017.
+        # Servers which were already using the old key (19036) should
+        # roll seamlessly to this new one via RFC 5011 rollover. Servers
+        # being set up for the first time can use the contents of this
+        # file as initializing keys; thereafter, the keys in the
+        # managed key database will be trusted and maintained
+        # automatically.
+        . initial-key 257 3 8 "AwEAAaz/tAm8yTn4Mfeh5eyI96WSVexTBAvkMgJzkKTOiW1vkIbzxeF3
+                +/4RgWOq7HrxRixHlFlExOLAJr5emLvN7SWXgnLh4+B5xQlNVz8Og8kv
+                ArMtNROxVQuCaSnIDdD5LKyWbRd2n9WGe2R8PzgCmr3EgVLrjyBxWezF
+                0jLHwVN8efS3rCj/EWgvIWgb9tarpVUDK/b58Da+sqqls3eNbuv7pr+e
+                oZG+SrDK6nWeL3c6H5Apxz7LjVc1uTIdsIXxuOLYA4/ilBmSVIzuDWfd
+                RUfhHdY6+cn8HFRm+2hM8AnXGXws9555KrUB5qihylGa8subX2Nn6UwN
+                R1AkUTV74bU=";
 };

Attachment: bind9_9.9.5.dfsg-9+deb8u13.1.diff.gz
Description: application/gzip

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 28 Aug 2017 10:26:39 +0200
Source: bind9
Binary: bind9 bind9utils bind9-doc host bind9-host libbind-dev libbind9-90 libdns100 libisc95 liblwres90 libisccc90 libisccfg90 dnsutils lwresd libbind-export-dev libdns-export100 libdns-export100-udeb libisc-export95 libisc-export95-udeb libisccfg-export90 libisccfg-export90-udeb libirs-export91 libirs-export91-udeb
Architecture: source all amd64
Version: 1:9.9.5.dfsg-9+deb8u13.1
Distribution: jessie
Urgency: high
Maintainer: Ondřej Surý <ondrej@debian.org>
Changed-By: Ondřej Surý <ondrej@debian.org>
Description:
 bind9      - Internet Domain Name Server
 bind9-doc  - Documentation for BIND
 bind9-host - Version of 'host' bundled with BIND 9.X
 bind9utils - Utilities for BIND
 dnsutils   - Clients provided with BIND
 host       - Transitional package
 libbind-dev - Static Libraries and Headers used by BIND
 libbind-export-dev - Development files for the exported BIND libraries
 libbind9-90 - BIND9 Shared Library used by BIND
 libdns-export100 - Exported DNS Shared Library
 libdns-export100-udeb - Exported DNS library for debian-installer (udeb)
 libdns100  - DNS Shared Library used by BIND
 libirs-export91 - Exported IRS Shared Library
 libirs-export91-udeb - Exported IRS library for debian-installer (udeb)
 libisc-export95 - Exported ISC Shared Library
 libisc-export95-udeb - Exported ISC library for debian-installer (udeb)
 libisc95   - ISC Shared Library used by BIND
 libisccc90 - Command Channel Library used by BIND
 libisccfg-export90 - Exported ISC CFG Shared Library
 libisccfg-export90-udeb - Exported ISC CFG library for debian-installer (udeb)
 libisccfg90 - Config File Handling Library used by BIND
 liblwres90 - Lightweight Resolver Library used by BIND
 lwresd     - Lightweight Resolver Daemon
Changes:
 bind9 (1:9.9.5.dfsg-9+deb8u13.1) jessie; urgency=high
 .
   [ Bernhard Schmidt ]
   * Import upcoming DNSSEC KSK-2017 from 9.10.5
 .
   [ Ondřej Surý ]
   * Non-maintainer upload.
Checksums-Sha1:
 ab5c1a95fd1c8dff55a5750d6f8095df196bacbf 3603 bind9_9.9.5.dfsg-9+deb8u13.1.dsc
 d45a2598b34f4d46a191e6f7782da0ce6e871821 137365 bind9_9.9.5.dfsg-9+deb8u13.1.diff.gz
 bf15f9d88738156f1637be988d8742811a4f06fd 340570 bind9-doc_9.9.5.dfsg-9+deb8u13.1_all.deb
 2c9079413922fb4512aeae1d45f8753b5476c3a4 24198 host_9.9.5.dfsg-9+deb8u13.1_all.deb
 27b5c4186de7f19df2fbae19d1bd375b8c16b2ad 316668 bind9_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 e86aa90ea2fa12f41e54766cfad7beaf42a90b64 168652 bind9utils_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 6f271e6e28855c8d2b7a665c475bf41249cb7572 68222 bind9-host_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 2b617cf5450410e557dfcaf3b1dcfb150df93bbc 1232998 libbind-dev_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 b7d7bf481f34f1e6d65c185eea4cf205a8256611 43986 libbind9-90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 ff5c354a56158ae0bff64a242ba69f5f6975a618 680796 libdns100_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 b86f1be4bc1fdbfdf93926932bf2f28adeb5ff38 169246 libisc95_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 b98c02972fd2d6906ae1eebcdc0e4f831e07aec8 53646 liblwres90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 6af7452dd8291616ef9152179ee7e63571e3829b 37204 libisccc90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 92f1bd26f07bf71dce8bcb7211e15bac0da5d52b 58206 libisccfg90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 f227dbb7d503de3b5aad1ccdbda6bc8d0d96d951 119604 dnsutils_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 e3072b6fc9eb12dad57c4484642c45599945255d 233064 lwresd_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 557648933f82f9088475e5f62d50191f64f5e5d1 830396 libbind-export-dev_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 5a1bca1b8930721b53b708660941cd72050b7880 456684 libdns-export100_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 361ed3a99ae6e51bbed9f8c0702edd3e3901831f 433158 libdns-export100-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
 3821c5e7d5cb0e0272eff6d5cfa01a67378dd976 141020 libisc-export95_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 a6296412d6c8e22c97d3f7fe6777909019bbd60e 117424 libisc-export95-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
 e3a2e34423b1463ddde67f760d800974709a751e 41326 libisccfg-export90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 e09baf33adbe2c9818a21d8db5db2d6d75587b66 17576 libisccfg-export90-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
 0f9e8eb0f103e49ac39ce4e29ba72b509f8f6df1 39114 libirs-export91_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 3bb04da0814b254d0fcf1a895e1938432955d9e9 15380 libirs-export91-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
Checksums-Sha256:
 68e63b0be3e8c0217a0b22d84a364bfede86854ae61f86e51c60faf62f2384f6 3603 bind9_9.9.5.dfsg-9+deb8u13.1.dsc
 5d13026388ee8f0fe5727f8a1fc5e30da74ff92715f04540bf9493b13ed3d255 137365 bind9_9.9.5.dfsg-9+deb8u13.1.diff.gz
 a244abab2b4a3c28aa0840195e292ae0137aace73f08e78aa95827dab02a61df 340570 bind9-doc_9.9.5.dfsg-9+deb8u13.1_all.deb
 e675734ad32eca7e00725fd437a409fc52043dc24e11e2dc1cf0e73c04580b35 24198 host_9.9.5.dfsg-9+deb8u13.1_all.deb
 f764e1ea900fbba19e4dd978792ae414463f0a3391e4c6896861a874ad3f7602 316668 bind9_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 ff986870f6471bddc226bf8d92f9cfd25add867af23d861648c10e23fc95b5e6 168652 bind9utils_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 c19e7bb0f708489a39206fd5b368a4e58d4f8d635b0161c1e63e678391cd6ae2 68222 bind9-host_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 da0f2b7987b056d9d6a7c5c0e2a46abec086f819ba3454bab1090957978394bc 1232998 libbind-dev_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 9153d45cdf6e14486003e6dac892a2110a102d871d3cef53a0156377f5162636 43986 libbind9-90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 4e77da5aa86164da0357b2a191a16e44b1aabf27fa87733fd529ee7adb471885 680796 libdns100_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 2ae322d79a2c8c9f68daeb80c519306fd5226a0181d53529354945d810827010 169246 libisc95_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 d0075ba6b38633aca5d3be625675676831c4e658c76463732d6f2116750f4168 53646 liblwres90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 9748869e4f74a46a3a6173fbb921d2dc6f992315d123d1d7c658f43de44e74c3 37204 libisccc90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 517ac639a59cf09943e7b8fc3f0e29569b665e87cc434f2b5b2899d4c6f22098 58206 libisccfg90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 c13f3b9329ff3e3d527bf77fb6f64699a635486280c6cda98da7f30134d0c463 119604 dnsutils_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 39b27cdf59a40957930b692b2a4ce765f85177f81188e2b8f9d2363cd174b933 233064 lwresd_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 a6946233c2187610688980ec80a8e9394091e760008c12d1c5cf72cc1247f5d6 830396 libbind-export-dev_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 5f62ed597f71d0e8097277d0265ac58897caaa929e3ec8c99c08519dfdffc0d7 456684 libdns-export100_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 8f75e0487ca6c22607fc0b66a2d772e55fd18128dc5ebebb7913c2a8fa8b2f91 433158 libdns-export100-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
 4c3eb4d7cfb70d8c7336a0e57512b3e5580f947bffaebb7d4e71e981c6f8f245 141020 libisc-export95_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 44dbb173d6f684d10e9a275a132b3de512e7bae16634227d671338ae8eb65388 117424 libisc-export95-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
 c16b65e40808dcaff7a732c6e91ac7a3c65a3ec018a774c831319dc4314f7218 41326 libisccfg-export90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 27e36cd83fb2a7eba00a0a6f55f95e20cae172d617a8a74297df16866bbed9e8 17576 libisccfg-export90-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
 b0b0747d895083dedd1e728f8c2dbeab291ae3b69e72de9f6684a5fc7356ab59 39114 libirs-export91_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 1d74cf0cf3ec2c7b00ee0cf4469a9b3a63f99c02ddc046e883bdaa43106627ff 15380 libirs-export91-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
Files:
 8d4ec75f6e684d6cbb74ff13130bc170 3603 net optional bind9_9.9.5.dfsg-9+deb8u13.1.dsc
 cad09fbae932847b2e10c18d7b6a281f 137365 net optional bind9_9.9.5.dfsg-9+deb8u13.1.diff.gz
 c4e5b79279959cc3f42cd5a8cafc1b19 340570 doc optional bind9-doc_9.9.5.dfsg-9+deb8u13.1_all.deb
 f9ce63c8ac754645f2a00ef2a6b963c4 24198 net standard host_9.9.5.dfsg-9+deb8u13.1_all.deb
 14c3bddb9f658159d6fd14ca1eef0004 316668 net optional bind9_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 7adbe38507b8aa765a624620d3678aac 168652 net optional bind9utils_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 f3edc4179456166e6e368c328bc9d089 68222 net standard bind9-host_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 ca67d806a8e810204ca6179c9462a15c 1232998 libdevel optional libbind-dev_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 7aacb0cb879a2e68e3f62225fc0bebeb 43986 libs standard libbind9-90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 5a5a52b645c9b8876d21552acbc1e916 680796 libs standard libdns100_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 8d4e1eeeb75be7504a9bb577d9af47b3 169246 libs standard libisc95_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 e3d6cca7da732827321b18e6528d2281 53646 libs standard liblwres90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 ed6446953ca2277aecab147b1a987d40 37204 libs optional libisccc90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 6dc0a60f92c23f62b45739e042c19139 58206 libs optional libisccfg90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 31684b80de6d91205a14eab2a14988cf 119604 net standard dnsutils_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 711ea41e5d04358bbfe31f85c2bdce45 233064 net optional lwresd_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 0f7a2b21534c207283d8ddb5b3d34cb6 830396 libdevel optional libbind-export-dev_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 eb491d0967d59ca717e203411eaf4c83 456684 libs optional libdns-export100_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 1b880a974136076ae4fcae3649a6c9b8 433158 debian-installer optional libdns-export100-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
 3841c3ccecf55dd45195ca3e3e93a205 141020 libs optional libisc-export95_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 a4765511ef884ccb2d400e082631dc11 117424 debian-installer optional libisc-export95-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
 1172447fefb69d97e244e804f3fc9f4a 41326 libs optional libisccfg-export90_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 0d4feeb01492988726ec9fc84985d21a 17576 debian-installer optional libisccfg-export90-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb
 1a0b5c8f39cb2572fde14ed0bc44eb7c 39114 libs optional libirs-export91_9.9.5.dfsg-9+deb8u13.1_amd64.deb
 83ce9d63ef08fd9b2ca4184ecd39e5b8 15380 debian-installer optional libirs-export91-udeb_9.9.5.dfsg-9+deb8u13.1_amd64.udeb

-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEMLkz2A/OPZgaLTj7DJm3DvT8uwcFAlmj27pfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDMw
QjkzM0Q4MEZDRTNEOTgxQTJEMzhGQjBDOTlCNzBFRjRGQ0JCMDcACgkQDJm3DvT8
uwcNbQ/+NElfROUFdRO2fECmEGlQjxurO3mbtWVx4+adRG41LSA1EEUN4CHpI7X6
0gr1UNqS1hb78627oK5SERWBWweD+jjWb1OoiqNygiFqMWhJwvFuyuwbxtA3mjci
Qt4Z8U0n5uvckNNNQhXYJipgEvgNowKaZTeutNgJnv8m5ElwEoe4Zi/W0IYLXhIV
6PHLT+DwVTdDkuN9kbkFcVpXSES2koB9xOaRKyxVNrcmgkdxfzdc79e6okezgdwO
YEjFv3OS42tjXGl74/U587QaWrcr5/Tezh6OEwTRMjlQNiqwCUoFGFtqnlQ7XRux
JqbnzDyHqim1UqN6V3s/31AdBFYsEW0vNn/N7+4uBBfZFlFZIClc0tcpneGvqCvK
WEMC2hXhbXw+xMDtXNtOuCpnlK06zgQjVG/JvvCcMLAjtzmDlzCs1LZ0vixxN+ox
cm0bUCfrhBRKkuQmKa1A08dQNj+WB84r+OvhrHaiSymcqTpnC/DwuC2XTGuVxWqU
PMhOtHos08jl3yToj6OhBZyCDKTgxIaM5hPtA886sj6fFOuV5RPHagH4SbC7p50S
CIgLErKT/LrJZRYhiwggasy9pVigF97IEaDe8+ltD3JBvouvkDn1CRJ5qrNG+8jl
Lt5b/W5Gmq0iHO9rqLQboCtaR6gtXLxCUUfUe2ygBOuOuDNOmtU=
=mUuM
-----END PGP SIGNATURE-----

--- End Message ---
--- Begin Message ---
Version: 8.10

Hi,

Each of the updates referenced in these bugs was included in this
morning's jessie point release. Thanks!

Regards,

Adam

--- End Message ---

Reply to: