<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OpenDNSSEC</title>
	<atom:link href="http://www.opendnssec.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.opendnssec.org</link>
	<description>OpenDNSSEC News</description>
	<lastBuildDate>Mon, 14 May 2012 11:22:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
		<item>
		<title>OpenDNSSEC 1.3.8</title>
		<link>http://www.opendnssec.org/2012/05/14/opendnssec-1-3-8/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=opendnssec-1-3-8</link>
		<comments>http://www.opendnssec.org/2012/05/14/opendnssec-1-3-8/#comments</comments>
		<pubDate>Mon, 14 May 2012 11:22:29 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=950</guid>
		<description><![CDATA[Version 1.3.8 of OpenDNSSEC has now been released. OPENDNSSEC-228: Signer Engine: Make &#8216;ods-signer update&#8217; reload signconfs even if zonelist has not changed. OPENDNSSEC-231: Signer Engine: Allow for Classless IN-ADDR.ARPA names (RFC 2317). OPENDNSSEC-234: Enforcer: Add indexes for foreign keys in kasp DB. (sqlite only, MySQL already has them.) OPENDNSSEC-246: Signer Engine: Warn if is in [...]]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.8 of OpenDNSSEC has now been released.</p>
<ul>
<li>OPENDNSSEC-228: Signer Engine: Make &#8216;ods-signer update&#8217; reload signconfs even if zonelist has not changed.</li>
<li>OPENDNSSEC-231: Signer Engine: Allow for Classless IN-ADDR.ARPA names (RFC 2317).</li>
<li>OPENDNSSEC-234: Enforcer: Add indexes for foreign keys in kasp DB. (sqlite only, MySQL already has them.)</li>
<li>OPENDNSSEC-246: Signer Engine: Warn if  is in signer configuration, but ods-auditor is not installed.</li>
<li>OPENDNSSEC-249: Enforcer: ods-ksmutil: If key export finds nothing to do then say so rather than display nothing which might be misinterpreted.</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>OPENDNSSEC-247: Signer Engine: TTL on NSEC(3) was not updated on SOA Minimum change.</li>
<li>OPENDNSSEC-253: Enforcer: Fix &#8220;ods-ksmutil zone delete &#8211;all&#8221;</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/opendnssec-1.3.8.tar.gz">opendnssec-1.3.8.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/05/14/opendnssec-1-3-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SoftHSM 1.3.3</title>
		<link>http://www.opendnssec.org/2012/05/14/softhsm-1-3-3/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=softhsm-1-3-3</link>
		<comments>http://www.opendnssec.org/2012/05/14/softhsm-1-3-3/#comments</comments>
		<pubDate>Mon, 14 May 2012 11:22:21 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=947</guid>
		<description><![CDATA[Version 1.3.3 of SoftHSM has now been released. Increased performance by adding more indexes to the database. Describe the usage of SO and user PIN in the README. Bugfixes: Detect if a C++ compiler is missing. Download the tarball from: softhsm-1.3.3.tar.gz]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.3 of SoftHSM has now been released.</p>
<ul>
<li>Increased performance by adding more indexes to the database.</li>
<li>Describe the usage of SO and user PIN in the README.</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>Detect if a C++ compiler is missing.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/softhsm-1.3.3.tar.gz">softhsm-1.3.3.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/05/14/softhsm-1-3-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New partnership between .uk registry Nominet and Swedish company OpenDNSSEC AB (svb)</title>
		<link>http://www.opendnssec.org/2012/03/20/new-partnership-between-uk-registry-nominet-and-swedish-company-opendnssec-ab-svb/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-partnership-between-uk-registry-nominet-and-swedish-company-opendnssec-ab-svb</link>
		<comments>http://www.opendnssec.org/2012/03/20/new-partnership-between-uk-registry-nominet-and-swedish-company-opendnssec-ab-svb/#comments</comments>
		<pubDate>Tue, 20 Mar 2012 14:34:24 +0000</pubDate>
		<dc:creator>pawal</dc:creator>
				<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=938</guid>
		<description><![CDATA[The Swedish company OpenDNSSEC AB (svb), which is operated by .SE (The Internet Infrastructure Foundation), will receive a capital injection of £35,000 from Nominet, which is in charge of the British UK top-level domain .uk. This will provide additional stability to the operation, which develops the OpenDNSSEC software, as well as support and training when [...]]]></description>
			<content:encoded><![CDATA[<p>The Swedish company OpenDNSSEC AB (svb), which is operated by .SE (The Internet Infrastructure Foundation), will receive a capital injection of £35,000 from Nominet, which is in charge of the British UK top-level domain .uk. This will provide additional stability to the operation, which develops the OpenDNSSEC software, as well as support and training when introduced to promote a more reliable Internet.</p>
<p>In collaboration with Nominet among others, .SE jointly developed the free OpenDNSSEC administration tool, which uses open source code, to significantly simplify the implementation of secure DNS, thus making the Internet more reliable. An initial beta version was launched in 2009 and has since been advanced.</p>
<p>The OpenDNSSEC company was formed in 2011 to support other top-level domain administrators in their use of the tool to manage DNSSEC. The company develops the software and offers training and support agreements.</p>
<p>“Nominet’s financial support is valuable to OpenDNSSEC AB in its efforts to develop the software and offer support to other top-level domain administrators who want to implement DNSSEC. OpenDNSSEC significantly simplifies the implementation process and will ultimately entail a more reliable Internet,” says Patrik Wallström, Acting President of OpenDNSSEC.</p>
<p>“It is fitting that as Nominet celebrates reaching 10 million .uk domains, that we are making this investment to protect the continued security and stability of the Internet. We recognise the importance of rolling out DNSSEC as widely as possible and for our own part, we are pleased to have successfully signed .uk at all levels. This investment represents a natural progression of our work as helping other top level domains to follow suit should help to ensure that DNSSEC is implemented more extensively.” says Roy Arends, Head of Research at Nominet.</p>
<h3>More about the software and DNSSEC</h3>
<p>OpenDNSSEC simplifies the management of DNSSEC, an extension of the Internet’s open directory service DNS, which prevents Internet and e-mail addresses from being manipulated and ensures that they lead to the right online destination. Using OpenDNSSEC, which .SE was involved in the development of, the necessary processes are automated to eliminate the need for manual management.</p>
<p>Under DNSSEC, Internet zones are cryptographically signed. When looking up a domain name, the signature is controlled using a key published by the party responsible for this zone.</p>
<p>OpenDNSSEC is available for free download at: <a href="http://www.opendnssec.org/">http://www.opendnssec.org</a></p>
<h3>For more information, please contact:</h3>
<p>Patrik Wallström, Acting President of OpenDNSSEC AB (svb)<br />
Telephone: +46 733 17 39 56<br />
E-mail: <a href="mailto:patrik.wallstrom@iis.se">patrik.wallstrom@iis.se</a></p>
<p>Maria Ekelund, Head of Communications at .SE<br />
Telephone: +46 8-452 35 27, +46 70-777 44 87<br />
E-mail: <a href="mailto:maria.ekelund@iis.se">maria.ekelund@iis.se</a></p>
<p>For Nominet please contact Patrick Yiu at Brands2Life<a href="mailto:nominetuk@brands2life.co.uk"><br />
nominetuk@brands2life.co.uk</a><br />
+44 20 7592 1200</p>
<h3>About .SE</h3>
<p>.SE (The Internet Infrastructure Foundation) is a not-for-profit public-service organization that acts to promote the positive development of the Internet in Sweden. .SE is responsible for the Internet’s Swedish top-level domain, .se, encompassing domain-name registration and administration, as well as the technical operation of the national domain name registry. Proceeds from domain-name registrations are used to support projects that contribute to the Internet development in Sweden, through proprietary operations and the financing of independent projects. Read more at <a href="http://www.iis.se/">http://www.iis.se</a></p>
<h3>About Nominet</h3>
<p>Nominet is the not-for-profit organisation responsible for the smooth and secure running of the .uk infrastructure. A public service ethos drives everything we do – we strive to make the Internet an ever more trusted space for everyone who uses it.</p>
<p>As one of the world’s largest Internet registries, we maintain a ‘directory’ of domain names ending in.uk, and run the technology which locates the computer hosting the website or email address you are looking for.</p>
<p>Our public purpose is manifest in two principal investments – the independently run Nominet Trust and knowthenet.org.uk</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/03/20/new-partnership-between-uk-registry-nominet-and-swedish-company-opendnssec-ab-svb/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenDNSSEC 1.4.0a1</title>
		<link>http://www.opendnssec.org/2012/03/16/opendnssec-1-4-0a1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=opendnssec-1-4-0a1</link>
		<comments>http://www.opendnssec.org/2012/03/16/opendnssec-1-4-0a1/#comments</comments>
		<pubDate>Fri, 16 Mar 2012 07:36:08 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=928</guid>
		<description><![CDATA[Version 1.4.0a1 of OpenDNSSEC has now been released. Auditor: The Auditor has been removed. Enforcer: Key label logging upon deletion (#192 Sebastian Castro) Enforcer: Stop multiple instances of the Enforcer running by checking for the pidfile at startup. If you want to run multiple instances then a different pidfile will need to be specified with [...]]]></description>
			<content:encoded><![CDATA[<p>Version 1.4.0a1 of OpenDNSSEC has now been released.</p>
<ul>
<li>Auditor: The Auditor has been removed.</li>
<li>Enforcer: Key label logging upon deletion (#192 Sebastian Castro)</li>
<li>Enforcer: Stop multiple instances of the Enforcer running by checking for the pidfile at startup. If you want to run multiple instances then a different pidfile will need to be specified with the -P flag.</li>
<li>Enforcer/ods-ksmutil: Use TTLs from KASP when generating DNSKEY and DS records for output.</li>
<li>Enforcer/ods-ksmutil: Give a more descriptive error message if the  tag in conf.xml does not match the database-backend set at compile time.</li>
<li>ods-ksmutil: Add warnings on &#8220;key export &#8211;ds&#8221; if no active or ready keys were seen, or if both were seen (so a key rollover is happening).</li>
<li>ods-ksmutil: Prevent MySQL username or password being interpreted by the shell when running &#8220;ods-ksmutil setup&#8221;</li>
<li>ods-ksmutil: &#8220;zone delete&#8221; renames the signconf file; so that if the zone is put back the signer will not pick up the old file.</li>
<li>ods-ksmutil: &#8220;key delete&#8221; added. It allows keys that are not currently in use to be deleted from the database and HSM.</li>
<li>OPENDNSSEC-1: Enforcer: Check DelegationSignerSubmitCommand exists and can be executed by ods-enforcerd.</li>
<li>OPENDNSSEC-10: ods-ksmutil: Include key size and algorithm in &#8220;key list&#8221; with -v flag.</li>
<li>OPENDNSSEC-28: ods-ksmutil: &#8220;key list&#8221; shows next state with -v flag.</li>
<li>OPENDNSSEC-35: ods-ksmutil: &#8220;rollover list -v&#8221; now includes more information on the KSKs waiting for the ds-seen command.</li>
<li>OPENDNSSEC-83: ods-ksmutil: &#8220;key generate&#8221; now displays how many keys will be generated and presents the user with the opportunity to stop the operation.</li>
<li>OPENDNSSEC-124: ods-ksmutil: Suppress database connection information when no -v flag is given.</li>
<li>Signer Engine: Input and Output DNS Adapters.</li>
<li>Signer Engine: Zonefetcher has been removed.</li>
</ul>
<p>Known issues:</p>
<ul>
<li>Signer Engine: The backup files do not work correctly in this alpha release.</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>Bugfix #246: Less confusing text for XML validation in ods-kaspcheck.</li>
<li>ods-ksmutil: &#8220;update kasp&#8221; now reflects changes in policy descriptions.</li>
<li>ods-ksmutil: Policy descriptions now have special characters quoted.</li>
<li>ods-ksmutil: Fix typo in policy export with NSEC3.</li>
</ul>
<p>The documentation for the new DNS adapters can be found here:<br />
<a href="https://wiki.opendnssec.org/display/DOCSTRUNK/conf.xml">DOCSTRUNK/conf.xml</a><br />
<a href="https://wiki.opendnssec.org/display/DOCSTRUNK/zonelist.xml">DOCSTRUNK/zonelist.xml</a><br />
<a href="https://wiki.opendnssec.org/display/DOCSTRUNK/addns.xml">DOCSTRUNK/addns.xml</a></p>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/testing/opendnssec-1.4.0a1.tar.gz">opendnssec-1.4.0a1.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/03/16/opendnssec-1-4-0a1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenDNSSEC 1.3.7</title>
		<link>http://www.opendnssec.org/2012/03/13/opendnssec-1-3-7/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=opendnssec-1-3-7</link>
		<comments>http://www.opendnssec.org/2012/03/13/opendnssec-1-3-7/#comments</comments>
		<pubDate>Tue, 13 Mar 2012 14:11:54 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=925</guid>
		<description><![CDATA[Version 1.3.7 of OpenDNSSEC has now been released. OPENDNSSEC-215: Signer Engine: Always recover serial from backup, even if it is corrupted, preventing unnecessary serial decrementals. OPENDNSSEC-217: Enforcer: Tries to detect pidfile staleness, so that the daemon will start after a power failure. Bugfixes: ods-hsmutil: Fixed a small memory leak when printing a DNSKEY. OPENDNSSEC-216: Signer [...]]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.7 of OpenDNSSEC has now been released.</p>
<ul>
<li>OPENDNSSEC-215: Signer Engine: Always recover serial from backup, even if it is corrupted, preventing unnecessary serial decrementals.</li>
<li>OPENDNSSEC-217: Enforcer: Tries to detect pidfile staleness, so that the daemon will start after a power failure.</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>ods-hsmutil: Fixed a small memory leak when printing a DNSKEY.</li>
<li>OPENDNSSEC-216: Signer Engine: Fix duplicate NSEC3PARAM bug.</li>
<li>OPENDNSSEC-218: Signer Engine: Prevent endless loop in case the locators in the signer backup files and the HSM are out of sync.</li>
<li>OPENDNSSEC-225: Fix problem with pid found when not existing.</li>
<li>SUPPORT-21: HSM SCA 6000 in combination with OpenCryptoki can return RSA key material with leading zeroes. DNSSEC does not allow leading zeroes in key data. You are affected by this bug if your DNSKEY RDATA e.g. begins with &#8220;BAABA&#8221;. Normal keys begin with e.g. &#8220;AwEAA&#8221;. OpenDNSSEC will now sanitize incoming data before adding it to the DNSKEY. Do not upgrade to this version if you are affected by the bug. You first need to go unsigned, then do the upgrade, and finally sign your zone again. SoftHSM and other HSM:s will not produce data with leading zeroes and the bug will thus not affect you.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/opendnssec-1.3.7.tar.gz">opendnssec-1.3.7.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/03/13/opendnssec-1-3-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SoftHSM 1.3.2</title>
		<link>http://www.opendnssec.org/2012/03/07/softhsm-1-3-2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=softhsm-1-3-2</link>
		<comments>http://www.opendnssec.org/2012/03/07/softhsm-1-3-2/#comments</comments>
		<pubDate>Wed, 07 Mar 2012 10:53:45 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=918</guid>
		<description><![CDATA[Version 1.3.2 of SoftHSM has now been released. Update the README with information on moving the database between different architectures. Bugfixes: Fix the destruction order of the Singleton objects. Download the tarball from: softhsm-1.3.2.tar.gz]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.2 of SoftHSM has now been released.</p>
<ul>
<li>Update the README with information on moving the database between different architectures.</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>Fix the destruction order of the Singleton objects.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/softhsm-1.3.2.tar.gz">softhsm-1.3.2.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/03/07/softhsm-1-3-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenDNSSEC 1.3.6</title>
		<link>http://www.opendnssec.org/2012/02/17/opendnssec-1-3-6/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=opendnssec-1-3-6</link>
		<comments>http://www.opendnssec.org/2012/02/17/opendnssec-1-3-6/#comments</comments>
		<pubDate>Fri, 17 Feb 2012 14:08:34 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=912</guid>
		<description><![CDATA[Version 1.3.6 of OpenDNSSEC has now been released. OPENDNSSEC-33: Signer Engine: Check HSM connection before use, attempt to reconnect if it is not valid. OPENDNSSEC-178: Signer Engine: Instead of waiting an arbitrary amount of time, let worker wait with pushing sign operations until the queue is non-full. Signer Engine: Adjust some log messages. Bugfixes: ods-control: [...]]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.6 of OpenDNSSEC has now been released.</p>
<ul>
<li>OPENDNSSEC-33: Signer Engine: Check HSM connection before use, attempt to reconnect if it is not valid.</li>
<li>OPENDNSSEC-178: Signer Engine: Instead of waiting an arbitrary amount of time, let worker wait with pushing sign operations until the queue is non-full.</li>
<li>Signer Engine: Adjust some log messages.</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>ods-control: Wrong exit status if Enforcer was already running.</li>
<li>OPENDNSSEC-56: ods-ksmutil had the wrong option for config file in the help usage text.</li>
<li>OPENDNSSEC-207: Signer Engine: Fix communication from a process not attached to a shell.</li>
<li>OPENDNSSEC-209: Signer Engine: Make output file adapter atomic by writing signed file to an intermediate file first.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/opendnssec-1.3.6.tar.gz">opendnssec-1.3.6.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/02/17/opendnssec-1-3-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenDNSSEC 1.3.5</title>
		<link>http://www.opendnssec.org/2012/01/23/opendnssec-1-3-5/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=opendnssec-1-3-5</link>
		<comments>http://www.opendnssec.org/2012/01/23/opendnssec-1-3-5/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 10:10:20 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=903</guid>
		<description><![CDATA[Version 1.3.5 of OpenDNSSEC has now been released. Auditor: Include the zone name in the log messages. ldns 1.6.12 is required for bugfixes. ods-ksmutil: Suppress database connection information when no -v flag is given. ods-enforcerd: Stop multiple instances of the enforcer running by checking for the pidfile at startup. If you want to run multiple instances then [...]]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.5 of OpenDNSSEC has now been released.</p>
<ul>
<li>Auditor: Include the zone name in the log messages.</li>
<li>ldns 1.6.12 is required for bugfixes.</li>
<li>ods-ksmutil: Suppress database connection information when no -v flag is given.</li>
<li>ods-enforcerd: Stop multiple instances of the enforcer running by checking for the pidfile at startup. If you want to run multiple instances then a different pidfile will need to be specified with the -P flag.</li>
<li>ods-ksmutil: &#8220;zone delete&#8221; renames the signconf file; so that if the zone is put back the signer will not pick up the old file.</li>
<li>Signer Engine: Verbosity can now be set via conf.xml, default is 3.</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>Bugfix OPENDNSSEC-174: Configure the location for conf.xml with &#8211;config or -c when starting the signer.</li>
<li>Bugfix OPENDNSSEC-192: Signer crashed on deleting NSEC3 for a domain that becomes opt-out.</li>
<li>Bugfix OPENDNSSEC-193: Auditor crashed with certain empty non-terminals.</li>
<li>Signer Engine: A file descriptor for sockets with value zero is allowed.</li>
<li>Signer Engine: Only log messages about a full signing queue in debug mode.</li>
<li>Signer Engine: Fix time issues, make sure that the internal serial does not wander off after a failed audit.</li>
<li>Signer Engine: Upgrade ldns to avoid future problems on 32-bit platforms with extra long signature expiration dates. More information in separate announcement.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/opendnssec-1.3.5.tar.gz">opendnssec-1.3.5.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/01/23/opendnssec-1-3-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SoftHSM 1.3.1</title>
		<link>http://www.opendnssec.org/2012/01/17/softhsm-1-3-1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=softhsm-1-3-1</link>
		<comments>http://www.opendnssec.org/2012/01/17/softhsm-1-3-1/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 21:18:36 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=892</guid>
		<description><![CDATA[Version 1.3.1 of SoftHSM has now been released. The library is now installed in $libdir/softhsm/ Bugfixes: Do not give a warning about the schema version if the token  has not been initialized yet. The tools now return the correct exit code. Download the tarball from: softhsm-1.3.1.tar.gz]]></description>
			<content:encoded><![CDATA[<p>Version 1.3.1 of SoftHSM has now been released.</p>
<ul>
<li>The library is now installed in $libdir/softhsm/</li>
</ul>
<p>Bugfixes:</p>
<ul>
<li>Do not give a warning about the schema version if the token  has not been initialized yet.</li>
<li>The tools now return the correct exit code.</li>
</ul>
<p>Download the tarball from: <a href="http://www.opendnssec.org/files/source/softhsm-1.3.1.tar.gz">softhsm-1.3.1.tar.gz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/01/17/softhsm-1-3-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security bug: Off-by-one error and new year</title>
		<link>http://www.opendnssec.org/2012/01/17/security-bug-off-by-one-error-and-new-year/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=security-bug-off-by-one-error-and-new-year</link>
		<comments>http://www.opendnssec.org/2012/01/17/security-bug-off-by-one-error-and-new-year/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 15:29:48 +0000</pubDate>
		<dc:creator>rb</dc:creator>
				<category><![CDATA[Deployment]]></category>

		<guid isPermaLink="false">http://www.opendnssec.org/?p=894</guid>
		<description><![CDATA[During the end of last year, a bug was uncovered in the library ldns. The bug had an off-by-one error which caused some signatures to have the expiration date set to December 31 2012. 64-bit versions are unaffected. Affected versions: ldns &#60; 1.6.12 (32-bit) Fixed versions: ldns &#62;= 1.6.12 (32-bit) Description: The 32-bit version of [...]]]></description>
			<content:encoded><![CDATA[<p>During the end of last year, a bug was uncovered in the library ldns. The bug had an off-by-one error which caused some signatures to have the expiration date set to December 31 2012. 64-bit versions are unaffected.</p>
<p><strong>Affected versions:</strong> ldns &lt; 1.6.12 (32-bit)<br />
<strong>Fixed versions:</strong> ldns &gt;= 1.6.12 (32-bit)</p>
<p><strong>Description:</strong><br />
The 32-bit version of ldns has code for converting days since epoch to the day of year. That code had a bug which handled the end of the year in the wrong way. The result of the bug was that some signatures got the intended validity period extended by a year. The signature will be reused by the Signer Engine until the key is rolled. However, the Enforcer is not aware that there exist signatures with such a long validity period. Any affected signature will thus have no post-publication of its corresponding DNSKEY, possibly resulting in validation failure. There is also the risk that the affected signature will be used in a replay attack.</p>
<p><strong>Test for affected signatures:</strong><br />
The affected signatures can be spotted by reviewing your signed zone. E.g. by using the following command:<br />
<em>&gt; grep &#8220;20121231[0-9]\{6\} 2011&#8243; signed.zone.file</em></p>
<p><strong>Remove the affected signatures:</strong><br />
If there are signatures in the zone with extra long validity periods, then it is recommended to recreate all of the signatures. This is done by clearing the internal storage of the Signer Engine. You then wait for the next scheduled re-sign, but you can also force an immediate re-sign (the second command below) to speed up the process:<br />
<em>&gt; ods-signer clear &lt;zone&gt;</em><br />
<em> &gt; ods-signer sign &lt;zone&gt;</em></p>
<p><strong>Mitigate replay attacks:</strong><br />
Once the affected signatures are removed from the zone, it may also be advisable to roll your keys. If you have a non-static zone and are changing your zone data, then there is a chance for an attacker to replay old data since the signature is still valid. You need to assess the risk and possible cost of such an attack. If you need to mitigate such an attack, then you need to roll your keys. Rolling keys will invalidate any signatures that an attacker may have stored for later use. If the signature of the DNSKEY RRset was affected, then you also need to roll the KSK:<br />
<em>&gt; ods-ksmutil key rollover &#8211;zone &lt;zone&gt; &#8211;keytype ZSK</em><br />
<em> &gt; ods-ksmutil key rollover &#8211;zone &lt;zone&gt; &#8211;keytype KSK</em></p>
<p><strong>Solution:</strong><br />
The issue has been fixed in ldns 1.6.12. You should upgrade ldns before the end of this year.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.opendnssec.org/2012/01/17/security-bug-off-by-one-error-and-new-year/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

