Notice: dnssec-conf updates in Fedora 11 and 12
Paul W. Frields
stickster at gmail.com
Tue Feb 9 22:29:27 UTC 2010
-----BEGIN PGP SIGNED MESSAGE-----
The Fedora Project recently issued an update to the dnssec-conf
package, to fix an issue that caused Fedora 11 and 12 systems using
BIND (named) to put an inordinately heavy load on RIPE nameservers.
However, this update has been found to break some BIND configurations
as seen in this bug:
The problem occurs in these packages:
To determine if your system is affected, run the following command:
rpm -q dnssec-conf
If one of the above package descriptors does not appear, your system
is not affected and you may safely ignore this message. If you are
affected, please continue reading.
== Workaround ==
If you have already accepted this update, you can downgrade the
package and start the failed BIND (named) daemon again using these
su -c 'yum downgrade dnssec-conf'
su -c 'service named start'
== Solution ==
System owners running BIND name servers on Fedora 11 or 12 systems are
advised not to accept the specific dnssec-conf pacakge updates listed
above. There are several ways to avoid these specific updates.
* If you use the PackageKit graphical client, or another graphical
client, deselect the dnssec-conf update in the dialog that lists
* If you use the yum command-line client, use this command to exclude
dnssec-conf from the list of packages to be updated:
su -c 'yum --exclude=dnssec-conf update'
== Remediation ==
A new update is being prepared to address this problem for Fedora 11
and 12 users, and will be pushed to our mirrors as soon as possible.
Users who are not running BIND nameservers (named) on their Fedora 11
and 12 can safely disregard this notice. When the new updates are
pushed, a follow-up announcement will be made here. At that time,
affected system owners can safely accept the replacement updates.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
-----END PGP SIGNATURE-----
More information about the announce