Summary: | [RFE] named: stale-answer support | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | Reporter: | Petr Menšík <pemensik> | |
Component: | bind | Assignee: | Petr Menšík <pemensik> | |
Status: | CLOSED ERRATA | QA Contact: | Robin Hack <rhack> | |
Severity: | medium | Docs Contact: | Katerina Nemcova <knemcova> | |
Priority: | high | |||
Version: | 8.1 | CC: | fkrska, pemensik, pmendezh, psklenar, redhat-bugzilla, rhack, thozza | |
Target Milestone: | rc | Keywords: | FutureFeature, Reproducer | |
Target Release: | 8.1 | |||
Hardware: | Unspecified | |||
OS: | Unspecified | |||
Whiteboard: | ||||
Fixed In Version: | bind-9.11.12-3.el8 | Doc Type: | Enhancement | |
Doc Text: |
.`stale-answer` now provides old cached records in case of DDoS attack
Previously, the Distributed Denial of Service (DDoS) attack caused the authoritative servers to fail with the SERVFAIL error. With this update, the `stale-answer` functionality provides the expired records until a fresh response is obtained.
To enable or disable the `serve-stale` feature, use either of these:
* Configuration file
* Remote control channel (rndc)
|
Story Points: | --- | |
Clone Of: | ||||
: | 1769869 (view as bug list) | Environment: | ||
Last Closed: | 2020-04-28 16:52:27 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Bug Depends On: | ||||
Bug Blocks: | Engineering1743192, Red Hat1755139, 1769869 |
Description
Petr Menšík
2019-01-09 21:16:54 UTC
Note: Serve-stale feature introduced also some defects fixed in 9.12.2-P1 release. It has to be included right away. https://ftp.isc.org/isc/bind9/9.12.2-P1/RELEASE-NOTES-bind-9.12.2-P1.html Previous refractoring of resolver [1] makes backport hard. Not simple to check it is possible or not, have to decipher which changes would land where in the old code. 1. https://gitlab.isc.org/isc-projects/bind9/commit/96912e44b0b180de56f47d438f91c9e70925bd16 Some working prototype was successful. More changes is required, but it seems possible into 9.11. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2020:1845 |