BIND 9.3.2 Release Notes

In BIND 9.3.2, the key file supplied to nsupdate using the -k option must
contain a key of the type KEY and not DNSKEY.
The dnssec-signzone command creates the db.<zone>.signed file, which
contains the NSEC (corresponding to the NXT record in 9.2.0) and RRSIG
(corresponding to the SIG record in 9.2.0) records. Additionally, it creates a
dsset-<zone> file that contains the DS record and the keyset-<zone> file
that contains the DNSKEY record.
The following dig features are modified in BIND 9.3.2:
The -i option in the dig command must be used for IP6.INT IPv6 reverse
lookups. By default, dig performs IP6.ARPA reverse IPv6 lookups.
The output of the dig name command for Not Implemented is changed
from NOTIMPL to NOTIMP.
Table 1-6 lists the changed command-line options for the dnssec-signzone tool
in BIND 9.3.2.
Table 1-6 New Command-Line Options
Changed FunctionalityNew OptionOld OptionBinaries/Tools
Specifies the DNS class of the
zone
-c class-c cycle-timednssec-signzone
No change in the functionality for
this option
-n threads-n ncpusdnssec-signzone
Installing BIND 9.3.2
This section describes how to install BIND 9.3.2. It also lists the prerequisites for
installing BIND 9.3.2.
Prerequisites
Table 1-7 lists the prerequisites for installing BIND 9.3.2 on the HP-UX 11i v1 and v2
operating systems.
Table 1-7 BIND 9.3.2 Prerequisites
PrerequisiteOperating System
For using DNSSEC Public Key Cryptography functionality, the
OpenSSL library must be installed. However, named will
continue to run without the OpenSSL library.
1
HP-UX 11i v1
HP-UX 11i v2
No prerequisitesHP-UX 11i v3
1 For the HP-UX 11i v1 operating system, install the OpenSSL software from http://www.software.hp.com
to obtain the OpenSSL libraries. For the HP-UX 11i v2 operating system, the OpenSSL libraries are
available as part of the core operating system.
16 BIND 9.3.2 Release Notes