Dear Knot Resolver users,
Knot Resolver 6.4.1 has been released!
Security:
- DNS-over-QUIC (DoQ) had severe issues, allowing even RCE
Many people reported (some of) these issues to us.
- DNSSEC correctness issues, acting mainly through the aggressive cache:
* dealing with Labels field in RRSIGs being smaller than the signer's
* dealing with NSEC's next-name pointing outside of the zone
Special thanks to Qifan Zhang from Palo Alto Networks.
Improvements:
- docker: upgrade to Debian 13 (!1856)
- update IANA's certificate for root trust anchor bootstrapping (!1845)
Bugfixes:
- /local-data/addresses*: make multiple addresses work (#808, #954)
- views: fix protocol-based matching for DoQ
Full changelog:
https://gitlab.nic.cz/knot/knot-resolver/raw/v6.4.1/NEWS
Sources:
https://knot-resolver.nic.cz/release/knot-resolver-6.4.1.tar.xz
GPG signature:
https://knot-resolver.nic.cz/release/knot-resolver-6.4.1.tar.xz.asc
Documentation:
https://www.knot-resolver.cz/documentation/v6.4.1/
--
Ales Mrazek
PGP: 3057 EE9A 448F 362D 7420 5A77 9AB1 20DA 0A76 F6DE
Dear Knot Resolver users,
Knot Resolver 5.7.7 has been released!
Security:
- DNSSEC correctness issues, acting mainly through the aggressive cache:
* dealing with Labels field in RRSIGs being smaller than the signer's
* dealing with NSEC's next-name pointing outside of the zone
Special thanks to Qifan Zhang from Palo Alto Networks.
Improvements:
- support cmocka 2.0.0
- avoid AD=1 in reply if ANSWER+AUTHORITY are empty (#914)
- packaging: rpm: require python3-setuptools (!1831)
- packaging: rpm: provide user/group (!1838)
This should also resolve the issue with user and group
configuration during installation (GH#130).
- make DoH cache-control header respect our cache's TTL limits (!1832)
- support libdnssec merged into libknot, as planned for knot >= 3.6 (!1833)
- update IANA's certificate for root trust anchor bootstrapping (!1862)
Bugfixes:
- respect disablement of QNAME case randomization even after TCP issues
- cache: fix wrong TTL in some cases, typically 32768
- reduce excessive caching of some uncommon failed answers (!1832)
- dns64: fix CNAME problems again (#797, !1862)
Full changelog:
https://gitlab.nic.cz/knot/knot-resolver/raw/v5.7.7/NEWS
Sources:
https://knot-resolver.nic.cz/release/knot-resolver-5.7.7.tar.xz
GPG signature:
https://knot-resolver.nic.cz/release/knot-resolver-5.7.7.tar.xz.asc
Documentation:
https://www.knot-resolver.cz/documentation/v5.7.7/
--
Ales Mrazek
PGP: 3057 EE9A 448F 362D 7420 5A77 9AB1 20DA 0A76 F6DE
Dear Knot Resolver users,
Knot Resolver 6.1.0, the first officially stable version 6, has been
released!
As of this release, version 6 is preferred over version 5.
Improvements:
- logging: improved logging groups (!1768)
- support libdnssec merged into libknot, as planned for knot >= 3.6 (!1769)
- support cmocka 2.0.0 (!1772)
- avoid AD=1 in reply if ANSWER+AUTHORITY are empty (#914, !1780)
- defer: enabled by default in declarative configuration (!1785)
- /defer/enable: false -> true
- datamodel: lua: added Lua scripts for policy-loader (!1771)
Bugfixes:
- reload did not apply changes to /fallback (!1763)
- fix config.cache.clear test on apple silicon (!1766)
- cache: fix wrong TTL in some cases, typically 32768 (!1774)
Full changelog:
https://gitlab.nic.cz/knot/knot-resolver/raw/v6.1.0/NEWS
Sources:
https://secure.nic.cz/files/knot-resolver/knot-resolver-6.1.0.tar.xz
GPG signature:
https://secure.nic.cz/files/knot-resolver/knot-resolver-6.1.0.tar.xz.asc
Documentation:
https://www.knot-resolver.cz/documentation/v6.1.0/
--
Ales Mrazek
PGP: 3057 EE9A 448F 362D 7420 5A77 9AB1 20DA 0A76 F6DE
Dear Knot Resolver users,
Knot Resolver 6.0.16 (early-access) has been released!
Improvements:
- reduce validation strictness for domain names (#934, !1727)
- manager: force a configuration reload via management HTTP API
'api/reload/force' (#939, !1748)
- kresctl: reload: added '--force' flag
- /fallback: add this feature/module (!1733)
- systemd: do not force-fail knot-resolver.service on OOM (!1724)
In basically all cases the OOM killer will kill a kresd process
and supervisord will just restart it, and everything will keep working.
Bugfixes:
- /options/query-case-randomization: respect this even on TCP issues (!1732)
- prometheus metrics: make the latency histogram cumulative (!1731, GH#117)
- fix file permission checks when running as root (!1741)
- /network/address-renumbering: fix conversion to Lua configuration (!1739)
- manager: avoid uncommon bugs when starting/quitting policy-loader (!1742)
Full changelog:
https://gitlab.nic.cz/knot/knot-resolver/raw/v6.0.16/NEWS
Sources:
https://secure.nic.cz/files/knot-resolver/knot-resolver-6.0.16.tar.xz
GPG signature:
https://secure.nic.cz/files/knot-resolver/knot-resolver-6.0.16.tar.xz.asc
Documentation:
https://www.knot-resolver.cz/documentation/v6.0.16/
--
Ales Mrazek
PGP: 3057 EE9A 448F 362D 7420 5A77 9AB1 20DA 0A76 F6DE