Dear Knot Resolver users,
Knot Resolver 5.5.0 has been released!
Improvements
- extended_errors: module for extended DNS error support, RFC8914 (!1234)
- policy: log policy actions; useful for RPZ debugging (!1239)
- policy: new action policy.IPTRACE for logging request origin (!1239)
- prefill module: prepare for ZONEMD, improve performance (!1225)
- validator: conditionally ignore SHA1 DS, as SHOULD by RFC4509 (!1251)
- lib/resolve: use EDNS padding for outgoing TLS queries (!1254)
- support for PROXYv2 protocol (!1238)
- lib/resolve, policy: new NO_ANSWER flag for not responding to clients
(!1257)
Incompatible changes
- libknot >= 3.0.2 is required
Bugfixes
- doh2: fix CORS by adding `access-control-allow-origin: *` (!1246)
- net: fix listen by interface - add interface suffix to link-local IPv6
(!1253)
- daemon/tls: fix resumption for outgoing TLS (e.g. TLS_FORWARD) (!1261)
- nameserver selection: fix interaction of timeouts with reboots (#722,
!1269)
Full changelog:
https://gitlab.nic.cz/knot/knot-resolver/raw/v5.5.0/NEWS
Sources:
https://secure.nic.cz/files/knot-resolver/knot-resolver-5.5.0.tar.xz
GPG signature:
https://secure.nic.cz/files/knot-resolver/knot-resolver-5.5.0.tar.xz.asc
Documentation:
https://knot-resolver.readthedocs.io/en/v5.5.0/
Donation:
https://donations.nic.cz/en/donate/?project=knot-resolver
--
Ales Mrazek
PGP: 3057 EE9A 448F 362D 7420 5A77 9AB1 20DA 0A76 F6DE