<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Knot Resolver</title><link>https://www.knot-resolver.cz/</link><description>Resolve DNS names like it's 2026</description><atom:link href="https://www.knot-resolver.cz/feeds/knot-resolver.xml" rel="self"/><lastBuildDate>Tue, 16 Jun 2026 14:45:00 +0200</lastBuildDate><item><title>Knot Resolver 6.4.0 released</title><link>https://www.knot-resolver.cz/2026-06-16-knot-resolver-6.4.0.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;packaging: rpm: require python3-setuptools (!1830, #952)&lt;/li&gt;
&lt;li&gt;packaging: rpm: provide user/group (!1837)&lt;/li&gt;
&lt;li&gt;controller: improved error handling when sending commands to workers (!1834)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;dns64: fix CNAME problems again (#797 …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 16 Jun 2026 14:45:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2026-06-16:/2026-06-16-knot-resolver-6.4.0.html</guid></item><item><title>Knot Resolver 6.3.0 released</title><link>https://www.knot-resolver.cz/2026-04-27-knot-resolver-6.3.0.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements:&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;/local-data/rpz: support  *.some.name. CNAME block.page. (!1808)&lt;/li&gt;
&lt;li&gt;/local-data/rpz: print line number in the RPZ on error (!1823)&lt;/li&gt;
&lt;li&gt;/local-data/nodata: also apply to &lt;cite&gt;rpz:&lt;/cite&gt; and &lt;cite&gt;records:&lt;/cite&gt; (!1812 …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Mon, 27 Apr 2026 14:45:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2026-04-27:/2026-04-27-knot-resolver-6.3.0.html</guid></item><item><title>Knot Resolver 6.2.0 released</title><link>https://www.knot-resolver.cz/2026-02-03-knot-resolver-6.2.0.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;DNS-over-QUIC (DoQ) is available for serving (beta, !1747)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix UDP answers without sendmmsg, e.g. on non-Linux (!1795)&lt;/li&gt;
&lt;li&gt;fix /logging/groups in python 3.8 (!1799)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
</description><pubDate>Tue, 03 Feb 2026 14:45:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2026-02-03:/2026-02-03-knot-resolver-6.2.0.html</guid></item><item><title>Knot Resolver 6.1.0 released</title><link>https://www.knot-resolver.cz/2026-01-08-knot-resolver-6.1.0.html</link><description>&lt;p&gt;6.1.0 is the first officially stable release of version 6.
As of this release, version 6 is preferred over version 5.&lt;/p&gt;
&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements:&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;logging: improved logging groups (!1768)&lt;/li&gt;
&lt;li&gt;support …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 08 Jan 2026 14:45:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2026-01-08:/2026-01-08-knot-resolver-6.1.0.html</guid></item><item><title>Knot Resolver 5.7.6 released</title><link>https://www.knot-resolver.cz/2025-07-17-knot-resolver-5.7.6.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;DoS: fix a rare segfault in &lt;cite&gt;resolve&lt;/cite&gt; function (!1720)
Someone controlling the DNS traffic might be able
to trigger this crash intentionally and too often.&lt;/li&gt;
&lt;li&gt;DoS: drop a wrong …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 17 Jul 2025 14:45:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2025-07-17:/2025-07-17-knot-resolver-5.7.6.html</guid></item><item><title>Knot Resolver 5.7.5 released</title><link>https://www.knot-resolver.cz/2025-04-24-knot-resolver-5.7.5.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;DoS: fix unconfirmed crashes with the line below (!1683)
[system] requirement &amp;quot;h &amp;amp;&amp;amp; h-&amp;gt;end &amp;gt; h-&amp;gt;begin&amp;quot; failed in queue_pop_impl&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;tests: disable problematic config.http test (#925, !1678)&lt;/li&gt;
&lt;li&gt;validator …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 24 Apr 2025 14:45:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2025-04-24:/2025-04-24-knot-resolver-5.7.5.html</guid></item><item><title>Knot Resolver 5.7.4 released</title><link>https://www.knot-resolver.cz/2024-07-23-knot-resolver-5.7.4.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;reduce buffering of transmitted data, especially TCP-based in userspace
Also expose some of the new tweaks in lua:&lt;ul&gt;
&lt;li&gt;(require 'ffi').C.the_worker.engine.net.tcp.user_timeout = 1000&lt;/li&gt;
&lt;li&gt;(require 'ffi' …&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 23 Jul 2024 14:45:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2024-07-23:/2024-07-23-knot-resolver-5.7.4.html</guid></item><item><title>Knot Resolver 5.7.3 released</title><link>https://www.knot-resolver.cz/2024-05-30-knot-resolver-5.7.3.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;stats: add separate metrics for IPv6 and IPv4 (!1544)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix NSEC3 records missing in answer for positive wildcard expansion
with the NSEC3 having over-limit iteration count (#910, !1550 …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 30 May 2024 14:45:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2024-05-30:/2024-05-30-knot-resolver-5.7.3.html</guid></item><item><title>Knot Resolver 5.7.2 released</title><link>https://www.knot-resolver.cz/2024-03-27-knot-resolver-5.7.2.html</link><description>&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix on 32-bit systems with 64-bit time_t (!1510)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
</description><pubDate>Wed, 27 Mar 2024 14:30:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2024-03-27:/2024-03-27-knot-resolver-5.7.2.html</guid></item><item><title>Knot Resolver 5.7.1 released</title><link>https://www.knot-resolver.cz/2024-02-13-knot-resolver-5.7.1.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;dl class="first docutils"&gt;
&lt;dt&gt;CVE-2023-50868: NSEC3 closest encloser proof can exhaust CPU&lt;/dt&gt;
&lt;dd&gt;&lt;ul class="first last simple"&gt;
&lt;li&gt;validator: lower the NSEC3 iteration limit (150 -&amp;gt; 50)&lt;/li&gt;
&lt;li&gt;validator: similarly also limit excessive NSEC3 salt length&lt;/li&gt;
&lt;li&gt;cache: limit the amount of …&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;/dl&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 13 Feb 2024 14:30:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2024-02-13:/2024-02-13-knot-resolver-5.7.1.html</guid></item><item><title>Knot Resolver 5.7.0 released</title><link>https://www.knot-resolver.cz/2023-08-22-knot-resolver-5.7.0.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p class="first"&gt;avoid excessive TCP reconnections in a few more cases
Like before, the remote server had to behave nonsensically in order
to inflict this upon itself, but it might be …&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 22 Aug 2023 14:30:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2023-08-22:/2023-08-22-knot-resolver-5.7.0.html</guid></item><item><title>Knot Resolver 5.6.0 released</title><link>https://www.knot-resolver.cz/2023-01-26-knot-resolver-5.6.0.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p class="first"&gt;avoid excessive TCP reconnections in some cases (!1380)
For example, a DNS server that just closes connections without answer
could cause lots of work for the resolver (and itself …&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 26 Jan 2023 18:30:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2023-01-26:/2023-01-26-knot-resolver-5.6.0.html</guid></item><item><title>Knot Resolver 5.5.3 released</title><link>https://www.knot-resolver.cz/2022-09-21-knot-resolver-5.5.3.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix CPU-expensive DoS by malicious domains - CVE-2022-40188&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix config_tests on macOS (both HW variants)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
</description><pubDate>Wed, 21 Sep 2022 14:30:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2022-09-21:/2022-09-21-knot-resolver-5.5.3.html</guid></item><item><title>Knot Resolver 5.5.2 released</title><link>https://www.knot-resolver.cz/2022-08-16-knot-resolver-5.5.2.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;support libknot 3.2 (!1309)&lt;/li&gt;
&lt;li&gt;priming module: hide failures from the default log level (!1310)&lt;/li&gt;
&lt;li&gt;reduce memory usage in some cases (!1328)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;daemon/http: improve URI checks to …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 16 Aug 2022 14:30:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2022-08-16:/2022-08-16-knot-resolver-5.5.2.html</guid></item><item><title>Knot Resolver 5.5.1 released</title><link>https://www.knot-resolver.cz/2022-06-14-knot-resolver-5.5.1.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;daemon/tls: disable TLS resumption via tickets for TLS &amp;lt;= 1.2 (#742, !1295)&lt;/li&gt;
&lt;li&gt;daemon/http: DoH now responds with proper HTTP codes (#728, !1279)&lt;/li&gt;
&lt;li&gt;renumber module: allow rewriting subnet …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 14 Jun 2022 14:30:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2022-06-14:/2022-06-14-knot-resolver-5.5.1.html</guid></item><item><title>Knot Resolver 5.5.0 released</title><link>https://www.knot-resolver.cz/2022-03-15-knot-resolver-5.5.0.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;extended_errors: module for extended DNS error support, RFC8914 (!1234)&lt;/li&gt;
&lt;li&gt;policy: log policy actions; useful for RPZ debugging (!1239)&lt;/li&gt;
&lt;li&gt;policy: new action policy.IPTRACE for logging request origin (!1239)&lt;/li&gt;
&lt;li&gt;prefill …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 15 Mar 2022 14:30:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2022-03-15:/2022-03-15-knot-resolver-5.5.0.html</guid></item><item><title>Knot Resolver 5.4.4 released</title><link>https://www.knot-resolver.cz/2022-01-05-knot-resolver-5.4.4.html</link><description>&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix bad zone cut update in certain cases (e.g. AWS; !1237)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
</description><pubDate>Wed, 05 Jan 2022 14:30:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2022-01-05:/2022-01-05-knot-resolver-5.4.4.html</guid></item><item><title>Knot Resolver 5.4.3 released</title><link>https://www.knot-resolver.cz/2021-12-01-knot-resolver-5.4.3.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;lua: add kres.parse_rdata() to parse RDATA from string to wire format (!1233)&lt;/li&gt;
&lt;li&gt;lua: add policy.domains() for exact domain name matching (!1228)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;policy.rpz: fix origin detection …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 01 Dec 2021 13:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2021-12-01:/2021-12-01-knot-resolver-5.4.3.html</guid></item><item><title>Knot Resolver 5.4.2 released</title><link>https://www.knot-resolver.cz/2021-10-13-knot-resolver-5.4.2.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;dns64 module: also map the reverse (PTR) subtree (#478, !1201)&lt;/li&gt;
&lt;li&gt;dns64 module: allow disabling based on client address (#368, !1201)&lt;/li&gt;
&lt;li&gt;dns64 module: allow configuring AAAA subnets not allowed in …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 13 Oct 2021 14:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2021-10-13:/2021-10-13-knot-resolver-5.4.2.html</guid></item><item><title>Knot Resolver 5.4.1 released</title><link>https://www.knot-resolver.cz/2021-08-19-knot-resolver-5.4.1.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;docker: base image on Debian 11 (!1203)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix build without doh2 support after 5.4.0 (!1197)&lt;/li&gt;
&lt;li&gt;fix policy.DEBUG* logging and -V/--version after 5.4.0 …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 19 Aug 2021 15:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2021-08-19:/2021-08-19-knot-resolver-5.4.1.html</guid></item><item><title>Knot Resolver 5.4.0 released</title><link>https://www.knot-resolver.cz/2021-07-29-knot-resolver-5.4.0.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fine grained logging and syslog support (!1181)&lt;/li&gt;
&lt;li&gt;expose HTTP headers for processing DoH requests (!1165)&lt;/li&gt;
&lt;li&gt;improve assertion mechanism for debugging (!1146)&lt;/li&gt;
&lt;li&gt;support apkg tool for packaging workflow (!1178)&lt;/li&gt;
&lt;li&gt;support …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 29 Jul 2021 16:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2021-07-29:/2021-07-29-knot-resolver-5.4.0.html</guid></item><item><title>Knot Resolver 5.3.2 released</title><link>https://www.knot-resolver.cz/2021-05-05-knot-resolver-5.3.2.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;validator: fix 5.3.1 regression on over-limit NSEC3 edge case (!1169)
Assertion might be triggered by query/answer, potentially DoS.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;cache: improve handling write errors from LMDB …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 05 May 2021 12:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2021-05-05:/2021-05-05-knot-resolver-5.3.2.html</guid></item><item><title>Knot Resolver 5.3.1 released</title><link>https://www.knot-resolver.cz/2021-03-31-knot-resolver-5.3.1.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;policy.STUB: try to avoid TCP (compared to 5.3.0; !1155)&lt;/li&gt;
&lt;li&gt;validator: downgrade NSEC3 records with too many iterations (&amp;gt;150; !1160)&lt;/li&gt;
&lt;li&gt;additional improvements to nameserver selection algorithm (!1154 …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 31 Mar 2021 17:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2021-03-31:/2021-03-31-knot-resolver-5.3.1.html</guid></item><item><title>Knot Resolver 5.3.0 released</title><link>https://www.knot-resolver.cz/2021-02-25-knot-resolver-5.3.0.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;more consistency in using parent-side records for NS addresses (!1097)&lt;/li&gt;
&lt;li&gt;better algorithm for choosing nameservers (!1030, !1126, !1140, !1141, !1143)&lt;/li&gt;
&lt;li&gt;daf module: add daf.clear() (!1114)&lt;/li&gt;
&lt;li&gt;dnstap module: more …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 25 Feb 2021 14:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2021-02-25:/2021-02-25-knot-resolver-5.3.0.html</guid></item><item><title>Knot Resolver 5.2.1 released</title><link>https://www.knot-resolver.cz/2020-12-09-knot-resolver-5.2.1.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;doh2: send Cache-Control header with TTL (#617, !1095)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix map() command on 32-bit platforms; regressed in 5.2.0 (!1093)&lt;/li&gt;
&lt;li&gt;doh2: restrict endpoints to doh and dns-query (#636 …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 09 Dec 2020 11:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2020-12-09:/2020-12-09-knot-resolver-5.2.1.html</guid></item><item><title>Knot Resolver 5.2.0 released</title><link>https://www.knot-resolver.cz/2020-11-11-knot-resolver-5.2.0.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;doh2: add native C module for DNS-over-HTTPS (#600, !997)&lt;/li&gt;
&lt;li&gt;xdp: add server-side XDP support for higher UDP performance (#533, !1083)&lt;/li&gt;
&lt;li&gt;lower default EDNS buffer size to 1232 bytes (#538 …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 11 Nov 2020 14:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2020-11-11:/2020-11-11-knot-resolver-5.2.0.html</guid></item><item><title>Knot Resolver 5.1.3 released</title><link>https://www.knot-resolver.cz/2020-09-08-knot-resolver-5.1.3.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;capabilities are no longer constrained when running as root (!1012)&lt;/li&gt;
&lt;li&gt;cache: add percentage usage to cache.stats() (#580, !1025)&lt;/li&gt;
&lt;li&gt;cache: add number of cache entries to cache.stats() (#510 …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 08 Sep 2020 13:59:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2020-09-08:/2020-09-08-knot-resolver-5.1.3.html</guid></item><item><title>Knot Resolver 5.1.2 released</title><link>https://www.knot-resolver.cz/2020-07-01-knot-resolver-5.1.2.html</link><description>&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;hints module: NODATA answers also for non-address queries (!1005)&lt;/li&gt;
&lt;li&gt;tls: send alert to peer if handshake fails (!1007)&lt;/li&gt;
&lt;li&gt;cache: fix interaction between LMDB locks and preallocation (!1013)&lt;/li&gt;
&lt;li&gt;cache garbage …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 01 Jul 2020 14:30:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2020-07-01:/2020-07-01-knot-resolver-5.1.2.html</guid></item><item><title>Knot Resolver 5.1.1 released</title><link>https://www.knot-resolver.cz/2020-05-19-knot-resolver-5.1.1.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix CVE-2020-12667: mitigation for &lt;a class="reference external" href="https://en.blog.nic.cz/2020/05/19/nxnsattack-upgrade-resolvers-to-stop-new-kind-of-random-subdomain-attack/"&gt;NXNSAttack&lt;/a&gt; DNS protocol vulnerability&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;control sockets: recognize newline as command boundary&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information please see blog post about &lt;a class="reference external" href="https://en.blog.nic.cz/2020/05/19/nxnsattack-upgrade-resolvers-to-stop-new-kind-of-random-subdomain-attack/"&gt;NXNSAttack&lt;/a&gt;.&lt;/p&gt;
&lt;/div&gt;
</description><pubDate>Tue, 19 May 2020 11:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2020-05-19:/2020-05-19-knot-resolver-5.1.1.html</guid></item><item><title>Knot Resolver 5.1.0 released</title><link>https://www.knot-resolver.cz/2020-04-29-knot-resolver-5.1.0.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;cache garbage collector: reduce filesystem operations when idle (!946)&lt;/li&gt;
&lt;li&gt;policy.DEBUG_ALWAYS and policy.DEBUG_IF for limited verbose logging (!957)&lt;/li&gt;
&lt;li&gt;daemon: improve TCP query latency under heavy TCP load (!968 …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 29 Apr 2020 13:30:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2020-04-29:/2020-04-29-knot-resolver-5.1.0.html</guid></item><item><title>Knot Resolver 5.0.1 released</title><link>https://www.knot-resolver.cz/2020-02-05-knot-resolver-5.0.1.html</link><description>&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;systemd: use correct cache location for garbage collector (#543)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;cache: add cache.fssize() lua function to configure entire free disk space on
dedicated cache partition (#524, !932)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
</description><pubDate>Wed, 05 Feb 2020 16:30:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2020-02-05:/2020-02-05-knot-resolver-5.0.1.html</guid></item><item><title>Knot Resolver 5.0.0 released</title><link>https://www.knot-resolver.cz/2020-01-27-knot-resolver-5.0.0.html</link><description>&lt;div class="section" id="incompatible-changes"&gt;
&lt;h2&gt;Incompatible changes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;see upgrading guide: &lt;a class="reference external" href="https://knot-resolver.readthedocs.io/en/stable/upgrading.html"&gt;https://knot-resolver.readthedocs.io/en/stable/upgrading.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;systemd sockets are no longer supported (#485)&lt;/li&gt;
&lt;li&gt;net.listen() throws an error if it fails to bind …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Mon, 27 Jan 2020 14:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2020-01-27:/2020-01-27-knot-resolver-5.0.0.html</guid></item><item><title>Knot Resolver 4.3.0 released</title><link>https://www.knot-resolver.cz/2019-12-04-knot-resolver-4.3.0.html</link><description>&lt;div class="section" id="security-cve-2019-19331"&gt;
&lt;h2&gt;Security - CVE-2019-19331&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix speed of processing large RRsets (DoS, #518)&lt;/li&gt;
&lt;li&gt;improve CNAME chain length accounting (DoS, !899)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;http module: use SO_REUSEPORT (!879)&lt;/li&gt;
&lt;li&gt;systemd: kresd&amp;#64;.service now properly starts after …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 04 Dec 2019 15:30:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2019-12-04:/2019-12-04-knot-resolver-4.3.0.html</guid></item><item><title>Knot Resolver 4.2.2 released</title><link>https://www.knot-resolver.cz/2019-10-07-knot-resolver-4.2.2.html</link><description>&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;lua bindings: fix a 4.2.1 regression on 32-bit systems (#514)
which also fixes libknot 2.9 support on all systems&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
</description><pubDate>Mon, 07 Oct 2019 14:30:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2019-10-07:/2019-10-07-knot-resolver-4.2.2.html</guid></item><item><title>Knot Resolver 4.2.1 released</title><link>https://www.knot-resolver.cz/2019-09-26-knot-resolver-4.2.1.html</link><description>&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;rebinding module: fix handling some requests, respect ALLOW_LOCAL flag&lt;/li&gt;
&lt;li&gt;fix incorrect SERVFAIL on cached bogus answer for +cd request (!860)
(regression since 4.1.0 release, in less common …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 26 Sep 2019 14:30:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2019-09-26:/2019-09-26-knot-resolver-4.2.1.html</guid></item><item><title>Knot Resolver 4.2.0 released</title><link>https://www.knot-resolver.cz/2019-08-05-knot-resolver-4.2.0.html</link><description>&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;queries without RD bit set are REFUSED by default (!838)&lt;/li&gt;
&lt;li&gt;support forwarding to multiple targets (!825)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;tls_client: fix issue with TLS session resumption (#489)&lt;/li&gt;
&lt;li&gt;rebinding module: fix another …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Mon, 05 Aug 2019 17:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2019-08-05:/2019-08-05-knot-resolver-4.2.0.html</guid></item><item><title>Knot Resolver 4.1.0 released</title><link>https://www.knot-resolver.cz/2019-07-10-knot-resolver-4.1.0.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix CVE-2019-10190: do not pass bogus negative answer to client (!827)&lt;/li&gt;
&lt;li&gt;fix CVE-2019-10191: do not cache negative answer with forged QNAME+QTYPE (!839)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;new cache garbage collector is …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 10 Jul 2019 14:40:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2019-07-10:/2019-07-10-knot-resolver-4.1.0.html</guid></item><item><title>Knot Resolver 4.0.0 released</title><link>https://www.knot-resolver.cz/2019-04-18-knot-resolver-4.0.0.html</link><description>&lt;div class="section" id="incompatible-changes"&gt;
&lt;h2&gt;Incompatible changes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;see upgrading guide: &lt;a class="reference external" href="https://knot-resolver.readthedocs.io/en/stable/upgrading.html"&gt;https://knot-resolver.readthedocs.io/en/stable/upgrading.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;configuration: trust_anchors aliases .file, .config() and .negative were removed (!788)&lt;/li&gt;
&lt;li&gt;configuration: trust_anchors.keyfile_default is no longer accessible …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 18 Apr 2019 18:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2019-04-18:/2019-04-18-knot-resolver-4.0.0.html</guid></item><item><title>Knot Resolver 3.2.1 released</title><link>https://www.knot-resolver.cz/2019-01-10-knot-resolver-3.2.1.html</link><description>&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;trust_anchors: respect validity time range during TA bootstrap (!748)&lt;/li&gt;
&lt;li&gt;fix TLS rehandshake handling (!739)&lt;/li&gt;
&lt;li&gt;make TLS_FORWARD compatible with GnuTLS 3.3 (!741)&lt;/li&gt;
&lt;li&gt;special thanks to Grigorii Demidov for his …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 10 Jan 2019 13:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2019-01-10:/2019-01-10-knot-resolver-3.2.1.html</guid></item><item><title>Knot Resolver 3.2.0 released</title><link>https://www.knot-resolver.cz/2018-12-17-knot-resolver-3.2.0.html</link><description>&lt;div class="section" id="new-features"&gt;
&lt;h2&gt;New features&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;module edns_keepalive to implement server side of RFC 7828 (#408)&lt;/li&gt;
&lt;li&gt;module nsid to implement server side of RFC 5001 (#289)&lt;/li&gt;
&lt;li&gt;module bogus_log provides .frequent() table (!629, credit Ulrich …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Mon, 17 Dec 2018 15:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2018-12-17:/2018-12-17-knot-resolver-3.2.0.html</guid></item><item><title>Knot Resolver 3.1.0 released</title><link>https://www.knot-resolver.cz/2018-11-02-knot-resolver-3.1.0.html</link><description>&lt;div class="section" id="incompatible-changes"&gt;
&lt;h2&gt;Incompatible changes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;hints.use_nodata(true) by default; that's what most users want&lt;/li&gt;
&lt;li&gt;libknot &amp;gt;= 2.7.2 is required&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;cache: handle out-of-space SIGBUS slightly better (#197)&lt;/li&gt;
&lt;li&gt;daemon: improve TCP timeout …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Fri, 02 Nov 2018 16:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2018-11-02:/2018-11-02-knot-resolver-3.1.0.html</guid></item><item><title>Knot Resolver 3.0.0 released</title><link>https://www.knot-resolver.cz/2018-08-20-knot-resolver-3.0.0.html</link><description>&lt;div class="section" id="incompatible-changes"&gt;
&lt;h2&gt;Incompatible changes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;cache: fail lua operations if cache isn't open yet (!639)
By default cache is opened &lt;em&gt;after&lt;/em&gt; reading the configuration,
and older versions were silently ignoring cache operations.
Valid …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Mon, 20 Aug 2018 11:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2018-08-20:/2018-08-20-knot-resolver-3.0.0.html</guid></item><item><title>Knot Resolver 2.4.1 released</title><link>https://www.knot-resolver.cz/2018-08-02-knot-resolver-2.4.1.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix CVE-2018-10920: Improper input validation bug in DNS resolver component
(security!7, security!9)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;cache: fix TTL overflow in packet due to min_ttl (#388, security!8)&lt;/li&gt;
&lt;li&gt;TLS session …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 02 Aug 2018 14:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2018-08-02:/2018-08-02-knot-resolver-2.4.1.html</guid></item><item><title>Knot Resolver 2.4.0 released</title><link>https://www.knot-resolver.cz/2018-07-03-knot-resolver-2.4.0.html</link><description>&lt;div class="section" id="incompatible-changes"&gt;
&lt;h2&gt;Incompatible changes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;minimal libknot version is now 2.6.7 to pull in latest fixes (#366)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix a rare case of zones incorrectly downgraded to insecure status (!576)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="new-features"&gt;
&lt;h2&gt;New …&lt;/h2&gt;&lt;/div&gt;</description><pubDate>Tue, 03 Jul 2018 12:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2018-07-03:/2018-07-03-knot-resolver-2.4.0.html</guid></item><item><title>Knot Resolver 2.3.0 released</title><link>https://www.knot-resolver.cz/2018-04-23-knot-resolver-2.3.0.html</link><description>&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix CVE-2018-1110: denial of service triggered by malformed DNS messages
(!550, !558, security!2, security!4)&lt;/li&gt;
&lt;li&gt;increase resilience against slow lorris attack (security!5)&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;validation: fix SERVFAIL in …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Mon, 23 Apr 2018 14:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2018-04-23:/2018-04-23-knot-resolver-2.3.0.html</guid></item><item><title>Knot Resolver 2.2.0 released</title><link>https://www.knot-resolver.cz/2018-03-28-knot-resolver-2.2.0.html</link><description>&lt;div class="section" id="new-features"&gt;
&lt;h2&gt;New features&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;cache server unavailability to prevent flooding unreachable servers
(Please note that caching algorithm needs further optimization
and will change in further versions but we need to gather operational …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 28 Mar 2018 14:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2018-03-28:/2018-03-28-knot-resolver-2.2.0.html</guid></item><item><title>Knot Resolver 2.1.1 released</title><link>https://www.knot-resolver.cz/2018-02-23-knot-resolver-2.1.1.html</link><description>&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;when iterating, avoid unnecessary queries for NS in insecure parent.
This problem worsened in 2.0.0. (#246)&lt;/li&gt;
&lt;li&gt;prevent UDP packet leaks when using TLS forwarding&lt;/li&gt;
&lt;li&gt;fix the hints …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Fri, 23 Feb 2018 14:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2018-02-23:/2018-02-23-knot-resolver-2.1.1.html</guid></item><item><title>Knot Resolver 2.1.0 released</title><link>https://www.knot-resolver.cz/2018-02-16-knot-resolver-2.1.0.html</link><description>&lt;div class="section" id="incompatible-changes"&gt;
&lt;h2&gt;Incompatible changes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;stats: remove tracking of expiring records (predict uses another way)&lt;/li&gt;
&lt;li&gt;systemd: re-use a single kresd.socket and kresd-tls.socket&lt;/li&gt;
&lt;li&gt;ta_sentinel: implement protocol draft-ietf-dnsop-kskroll-sentinel-01
(our draft-ietf-dnsop-kskroll-sentinel-00 implementation had inverted …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Fri, 16 Feb 2018 15:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2018-02-16:/2018-02-16-knot-resolver-2.1.0.html</guid></item><item><title>Knot Resolver 2.0.0 released</title><link>https://www.knot-resolver.cz/2018-01-31-knot-resolver-2.0.0.html</link><description>&lt;div class="section" id="incompatible-changes"&gt;
&lt;h2&gt;Incompatible changes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;systemd: change unit files to allow running multiple instances,
deployments with single instance now must use &lt;cite&gt;kresd&amp;#64;1.service&lt;/cite&gt;
instead of &lt;cite&gt;kresd.service&lt;/cite&gt;; see kresd.systemd(8) for …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 31 Jan 2018 15:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2018-01-31:/2018-01-31-knot-resolver-2.0.0.html</guid></item><item><title>Knot Resolver 1.5.3 released</title><link>https://www.knot-resolver.cz/2018-01-23-knot-resolver-1.5.3.html</link><description>&lt;p&gt;Knot Resolver 1.5.3 is a tiny bugfix release.&lt;/p&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix the hints module on some systems, e.g. Fedora.
Symptom: &lt;cite&gt;undefined symbol: engine_hint_root_file&lt;/cite&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
</description><pubDate>Tue, 23 Jan 2018 15:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2018-01-23:/2018-01-23-knot-resolver-1.5.3.html</guid></item><item><title>Knot Resolver 1.5.2 released</title><link>https://www.knot-resolver.cz/2018-01-22-knot-resolver-1.5.2.html</link><description>&lt;p&gt;Knot Resolver 1.5.2 is a small security release.&lt;/p&gt;
&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix CVE-2018-1000002: insufficient DNSSEC validation, allowing
attackers to deny existence of some data by forging packets.
Some combinations pointed …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Mon, 22 Jan 2018 13:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2018-01-22:/2018-01-22-knot-resolver-1.5.2.html</guid></item><item><title>Knot Resolver 1.5.1 released</title><link>https://www.knot-resolver.cz/2017-12-12-knot-resolver-1.5.1.html</link><description>&lt;div class="section" id="incompatible-changes"&gt;
&lt;h2&gt;Incompatible changes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;script supervisor.py was removed, please migrate to a real process
manager&lt;/li&gt;
&lt;li&gt;module ketcd was renamed to etcd for consistency&lt;/li&gt;
&lt;li&gt;module kmemcached was renamed to memcached for consistency …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 12 Dec 2017 14:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2017-12-12:/2017-12-12-knot-resolver-1.5.1.html</guid></item><item><title>Knot Resolver 1.5.0 released</title><link>https://www.knot-resolver.cz/2017-11-02-knot-resolver-1.5.0.html</link><description>&lt;p&gt;Knot Resolver 1.5.0 has been released.&lt;/p&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix loading modules on Darwin&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;new module ta_signal_query supporting Signaling Trust Anchor
Knowledge using Keytag Query (RFC 8145 section 5 …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 02 Nov 2017 14:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2017-11-02:/2017-11-02-knot-resolver-1.5.0.html</guid></item><item><title>Knot Resolver 1.99.1-alpha released</title><link>https://www.knot-resolver.cz/2017-10-26-knot-resolver-1.99.1-alpha.html</link><description>&lt;p&gt;Knot Resolver 1.99.1-alpha has been released. This is an experimental
release meant for testing aggressive caching.&lt;/p&gt;
&lt;p&gt;It contains some regressions and might (theoretically) be even
vulnerable. The current …&lt;/p&gt;</description><pubDate>Thu, 26 Oct 2017 18:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2017-10-26:/2017-10-26-knot-resolver-1.99.1-alpha.html</guid></item><item><title>Knot Resolver 1.4.0 released</title><link>https://www.knot-resolver.cz/2017-09-22-knot-resolver-1.4.0.html</link><description>&lt;p&gt;Knot Resolver 1.4.0 has been released.&lt;/p&gt;
&lt;div class="section" id="incompatible-changes"&gt;
&lt;h2&gt;Incompatible changes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;lua: query flag-sets are no longer represented as plain integers.
kres.query.* no longer works, and kr_query_t lost trivial methods …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Fri, 22 Sep 2017 12:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2017-09-22:/2017-09-22-knot-resolver-1.4.0.html</guid></item><item><title>Knot Resolver 1.3.3 released</title><link>https://www.knot-resolver.cz/2017-08-09-knot-resolver-1.3.3.html</link><description>&lt;p&gt;Knot Resolver 1.3.3 has been released.&lt;/p&gt;
&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Fix a critical DNSSEC flaw. Signatures might be accepted as valid
even if the signed data was not in bailiwick of …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 09 Aug 2017 12:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2017-08-09:/2017-08-09-knot-resolver-1.3.3.html</guid></item><item><title>Knot Resolver 1.3.2 released</title><link>https://www.knot-resolver.cz/2017-06-28-knot-resolver-1.3.2.html</link><description>&lt;p&gt;Knot Resolver 1.3.2 has been released.&lt;/p&gt;
&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;fix possible opportunities to use insecure data from cache as keys
for validation&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;daemon: check existence of config file even …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 28 Jun 2017 14:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2017-06-28:/2017-06-28-knot-resolver-1.3.2.html</guid></item><item><title>Knot Resolver 1.3.1</title><link>https://www.knot-resolver.cz/2017-06-23-knot-resolver-1.3.1.html</link><description>&lt;p&gt;Knot Resolver 1.3.1 has been released.&lt;/p&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;modules/http: fix finding the static files (bug from 1.3.0)&lt;/li&gt;
&lt;li&gt;policy.FORWARD: fix some cases of CNAMEs obstructing search …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Fri, 23 Jun 2017 14:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2017-06-23:/2017-06-23-knot-resolver-1.3.1.html</guid></item><item><title>Knot Resolver 1.3.0 released</title><link>https://www.knot-resolver.cz/2017-06-13-knot-resolver-1.3.0.html</link><description>&lt;p&gt;Knot Resolver 1.3.0 has been released.&lt;/p&gt;
&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Refactor handling of AD flag and security status of resource records.
In some cases it was possible for secure domains to …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 13 Jun 2017 09:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2017-06-13:/2017-06-13-knot-resolver-1.3.0.html</guid></item><item><title>Knot Resolver 1.2.6 released</title><link>https://www.knot-resolver.cz/2017-04-24-knot-resolver-1.2.6.html</link><description>&lt;p&gt;Knot Resolver 1.2.6 has been released.&lt;/p&gt;
&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;dnssec: don't set AD flag for NODATA answers if wildcard
non-existence is not guaranteed due to opt-out in NSEC3&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="section" id="improvements"&gt;
&lt;h2&gt;Improvements&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;layer …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Mon, 24 Apr 2017 16:20:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2017-04-24:/2017-04-24-knot-resolver-1.2.6.html</guid></item><item><title>Knot Resolver 1.2.5 released</title><link>https://www.knot-resolver.cz/2017-04-05-knot-resolver-1.2.5.html</link><description>&lt;p&gt;Knot Resolver 1.2.5 has been released.&lt;/p&gt;
&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;layer/validate: clear AD if closest encloser proof has opt-outed
NSEC3 (#169)&lt;/li&gt;
&lt;li&gt;layer/validate: check if NSEC3 records in wildcard expansion …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Wed, 05 Apr 2017 15:30:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2017-04-05:/2017-04-05-knot-resolver-1.2.5.html</guid></item><item><title>Knot Resolver 1.2.4 released</title><link>https://www.knot-resolver.cz/2017-03-07-knot-resolver-1.2.4.html</link><description>&lt;p&gt;Knot Resolver 1.2.4 has been released.&lt;/p&gt;
&lt;div class="section" id="security"&gt;
&lt;h2&gt;Security&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Knot Resolver 1.2.0 and higher could return AD flag for insecure
answer if the daemon received answer with invalid …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Tue, 07 Mar 2017 14:30:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2017-03-07:/2017-03-07-knot-resolver-1.2.4.html</guid></item><item><title>Knot Resolver 1.2.3 released</title><link>https://www.knot-resolver.cz/2017-02-23-knot-resolver-1.2.3.html</link><description>&lt;p&gt;Knot Resolver 1.2.3 has been released.&lt;/p&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes:&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Disable storing GLUE records into the cache even in the (non-default)
QUERY_PERMISSIVE mode&lt;/li&gt;
&lt;li&gt;iterate: skip answer RRs that don't match the …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Thu, 23 Feb 2017 16:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2017-02-23:/2017-02-23-knot-resolver-1.2.3.html</guid></item><item><title>Knot Resolver 1.2.2 released</title><link>https://www.knot-resolver.cz/2017-02-10-knot-resolver-1.2.2.html</link><description>&lt;p&gt;Knot Resolver 1.2.2 has been released.&lt;/p&gt;
&lt;div class="section" id="bugfixes"&gt;
&lt;h2&gt;Bugfixes:&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Fix -k argument processing to avoid out-of-bounds memory accesses&lt;/li&gt;
&lt;li&gt;lib/resolve: fix zonecut fetching for explicit DS queries&lt;/li&gt;
&lt;li&gt;hints: more NULL …&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</description><pubDate>Fri, 10 Feb 2017 13:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2017-02-10:/2017-02-10-knot-resolver-1.2.2.html</guid></item><item><title>Knot Resolver 1.2.1 released</title><link>https://www.knot-resolver.cz/2017-02-01-knot-resolver-1.2.1.html</link><description>&lt;p&gt;Knot Resolver 1.2.1 has been released.&lt;/p&gt;
&lt;p&gt;It was discovered during internal testing that under special query
combinations the Knot Resolver can provide Insecure data from the cache
on …&lt;/p&gt;</description><pubDate>Wed, 01 Feb 2017 20:53:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2017-02-01:/2017-02-01-knot-resolver-1.2.1.html</guid></item><item><title>Knot Resolver 1.2.0 released</title><link>https://www.knot-resolver.cz/2017-01-25-knot-resolver-1.2.0.html</link><description>&lt;p&gt;Knot Resolver 1.2.0 has been released.&lt;/p&gt;
&lt;p&gt;CZ.NIC is proud to release a new release of Knot Resolver.&lt;/p&gt;
&lt;p&gt;The Knot Resolver team has worked very hard to bring …&lt;/p&gt;</description><pubDate>Wed, 25 Jan 2017 14:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2017-01-25:/2017-01-25-knot-resolver-1.2.0.html</guid></item><item><title>No DNSSEC when FORWARD policy enabled</title><link>https://www.knot-resolver.cz/2016-12-20-no-dnssec-with-forward-policy.html</link><description>&lt;p&gt;It was discovered that the documentation for &lt;a class="reference external" href="http://knot-resolver.readthedocs.io/en/v1.1.1/modules.html#query-policies"&gt;FORWARD
policy&lt;/a&gt;
missed the information about DNSSEC validation. The query policies are
only applied on inbound queries and therefore the full DNSSEC validation …&lt;/p&gt;</description><pubDate>Tue, 20 Dec 2016 14:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2016-12-20:/2016-12-20-no-dnssec-with-forward-policy.html</guid></item><item><title>Knot Resolver 1.1.1 released</title><link>https://www.knot-resolver.cz/2016-08-24-knot-resolver-1.1.1.html</link><description>&lt;p&gt;Knot Resolver 1.1.1 has been released.&lt;/p&gt;
&lt;p&gt;This Knot Resolver release fixes couple of bugs related to failures when
nameservers were not available and Knot Resolver had to retry …&lt;/p&gt;</description><pubDate>Wed, 24 Aug 2016 14:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2016-08-24:/2016-08-24-knot-resolver-1.1.1.html</guid></item><item><title>Knot Resolver 1.1.0 released</title><link>https://www.knot-resolver.cz/2016-08-12-knot-resolver-1.1.0.html</link><description>&lt;p&gt;Knot Resolver 1.1.0 has been released.&lt;/p&gt;
&lt;p&gt;The second production-ready release of Knot Resolver has been released.&lt;/p&gt;
&lt;p&gt;The list of notable features:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;RFC7873 DNS Cookies&lt;/li&gt;
&lt;li&gt;RFC7858 DNS over TLS …&lt;/li&gt;&lt;/ul&gt;</description><pubDate>Fri, 12 Aug 2016 08:00:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2016-08-12:/2016-08-12-knot-resolver-1.1.0.html</guid></item><item><title>Knot Resolver 1.0.0 released</title><link>https://www.knot-resolver.cz/2016-05-30-knot-resolver-1.0.0.html</link><description>&lt;p&gt;Knot Resolver 1.0.0 has been released.&lt;/p&gt;
&lt;p&gt;The first production-ready release of Knot Resolver has been released.&lt;/p&gt;
&lt;p&gt;The list of notable features:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Full DNSSEC Support&lt;/li&gt;
&lt;li&gt;Automated Root Trust Anchor …&lt;/li&gt;&lt;/ul&gt;</description><pubDate>Mon, 30 May 2016 10:10:00 +0200</pubDate><guid>tag:www.knot-resolver.cz,2016-05-30:/2016-05-30-knot-resolver-1.0.0.html</guid></item><item><title>Knot Resolver Beta 3 released</title><link>https://www.knot-resolver.cz/2016-01-31-knot-resolver-beta3.html</link><description>&lt;p&gt;Knot Resolver 1.0.0-beta3 released.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;Outbound query deduplication&lt;/li&gt;
&lt;li&gt;CLI tools: kresd-host and kresd-query&lt;/li&gt;
&lt;li&gt;Automatic
&lt;a class="reference external" href="http://knot-resolver.readthedocs.org/en/v1.0.0/daemon.html#enabling-dnssec"&gt;bootstrap&lt;/a&gt;
of root TA&lt;/li&gt;
&lt;li&gt;Built-in
&lt;a class="reference external" href="http://knot-resolver.readthedocs.org/en/v1.0.0/build.html#building-with-security-compiler-flags"&gt;hardening&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;More
&lt;a class="reference external" href="http://knot-resolver.readthedocs.org/en/v1.0.0/modules.html#statistics-collector"&gt;metrics&lt;/a&gt;
(dropped, nodata, timeout)&lt;/li&gt;
&lt;li&gt;Ported to libknot 2 …&lt;/li&gt;&lt;/ul&gt;</description><pubDate>Sun, 31 Jan 2016 10:00:00 +0100</pubDate><guid>tag:www.knot-resolver.cz,2016-01-31:/2016-01-31-knot-resolver-beta3.html</guid></item></channel></rss>