Saw a couple of typos in the release notes: DNS Response Policy Service [......] This feature is avaiable if BIND is built with configure --enable-dnsrps, if a DNSRPS provider is installed, and if dnsrps-enable is set to "yes" in named.conf. Standard built-in RPZ is used otherwise. avaiable/available ------- "The additional cache ("acache") was found not to significantly improve performance and has been removed; the acache-enable and acache-cleaning-intervaloptions are now deprecated." acache-cleaning-intervaloptions/interval options ------ "This will reduce query loads on authoritative servers for signed domains: when existing cached records can be used by the resolver to determine that a name does not exist in the authorittive domain, no query needs to be sent. " authorittive/authoritative ------- • dnstap logfiles can now be configured to automatically roll when they reach a specified size. If dnstap-output is configured with mode file, then it can take optionalsize and versions key-value arguments to set the logfile rolling parameters. optionalsize/optional size (?) --------- "Note: This change does not appply to the rndc addzone or rndc modzone commands." appply/apply -------- • rndc managed-keys destroy shuts down all RFC 5011 DNSSEC trust anchor maintenance, and deletes any existing managed keys database. If immediately followed byrndc reconfig, this will reinitialize key maintenance just as if the server was being started for the first time. byrndc/by rndc --------- somewhere, I saw "Addresss", but I can't find it now.