Dear Knot Resolver users,
Knot Resolver 5.7.7 has been released!
Security:
- DNSSEC correctness issues, acting mainly through the aggressive cache:
* dealing with Labels field in RRSIGs being smaller than the signer's
* dealing with NSEC's next-name pointing outside of the zone
Special thanks to Qifan Zhang from Palo Alto Networks.
Improvements:
- support cmocka 2.0.0
- avoid AD=1 in reply if ANSWER+AUTHORITY are empty (#914)
- packaging: rpm: require python3-setuptools (!1831)
- packaging: rpm: provide user/group (!1838)
This should also resolve the issue with user and group
configuration during installation (GH#130).
- make DoH cache-control header respect our cache's TTL limits (!1832)
- support libdnssec merged into libknot, as planned for knot >= 3.6 (!1833)
- update IANA's certificate for root trust anchor bootstrapping (!1862)
Bugfixes:
- respect disablement of QNAME case randomization even after TCP issues
- cache: fix wrong TTL in some cases, typically 32768
- reduce excessive caching of some uncommon failed answers (!1832)
- dns64: fix CNAME problems again (#797, !1862)
Full changelog:
https://gitlab.nic.cz/knot/knot-resolver/raw/v5.7.7/NEWS
Sources:
https://knot-resolver.nic.cz/release/knot-resolver-5.7.7.tar.xz
GPG signature:
https://knot-resolver.nic.cz/release/knot-resolver-5.7.7.tar.xz.asc
Documentation:
https://www.knot-resolver.cz/documentation/v5.7.7/
--
Ales Mrazek
PGP: 3057 EE9A 448F 362D 7420 5A77 9AB1 20DA 0A76 F6DE