Knot DNS merge requestshttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests2024-03-20T10:38:18+01:00https://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1653conf: allow catalog role member in a catalog template2024-03-20T10:38:18+01:00Daniel Salzmanconf: allow catalog role member in a catalog template3.3Libor PeltanLibor Peltanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1649dnssec/validation: fix finding invalid redundant RRSIGs within keytag-conflict2024-02-27T13:30:15+01:00Libor Peltandnssec/validation: fix finding invalid redundant RRSIGs within keytag-conflict3.3Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1189dnssec validate: search for invalid redundant RRSIGs2024-02-26T17:33:28+01:00Libor Peltandnssec validate: search for invalid redundant RRSIGs3.0Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1644Various enh2024-02-15T10:31:55+01:00Libor PeltanVarious enhDaniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1638DDNS: perform pre-checks in advance2024-01-24T13:24:48+01:00Libor PeltanDDNS: perform pre-checks in advance3.4Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1635DDNS: unify DNAME semantic errors with CNAME's...2024-01-24T13:24:47+01:00Libor PeltanDDNS: unify DNAME semantic errors with CNAME's......by ignoring first RR that introduces the violation...
...without failing the update or whole bulk of updates...by ignoring first RR that introduces the violation...
...without failing the update or whole bulk of updates3.4Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1637check that the data neeeded for restore are there in the backup2024-01-11T19:50:59+01:00David Vasekcheck that the data neeeded for restore are there in the backupAlso, the internal backup parameters have been converted to a bit-mapped variable.Also, the internal backup parameters have been converted to a bit-mapped variable.Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1631journal: improve log messages when flushing2024-01-04T16:41:19+01:00Libor Peltanjournal: improve log messages when flushingDaniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1629Improve import-bind2024-01-04T11:08:28+01:00Libor PeltanImprove import-bind- import Created timer to make KSK roll-over work afterwards
- clear future timers to fix general automatic key mgmt afterwards
- test- import Created timer to make KSK roll-over work afterwards
- clear future timers to fix general automatic key mgmt afterwards
- test3.4Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1628dnssec/validation: implemented full validation as event...2024-01-02T15:05:13+01:00Libor Peltandnssec/validation: implemented full validation as event......triggered either by knotc or by zone-update/validation+RRSIG expire...triggered either by knotc or by zone-update/validation+RRSIG expire3.4Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1624dnssec/validation: consider end of RRSIG validitiy...2023-12-21T12:12:05+01:00Libor Peltandnssec/validation: consider end of RRSIG validitiy... ...for dnssec-validate that it is longer than rrsig-refresh
...for keymgr offline-ksk, that it's until the next DNSKEY snapshot ...for dnssec-validate that it is longer than rrsig-refresh
...for keymgr offline-ksk, that it's until the next DNSKEY snapshot3.4Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1623backup: add the filter '+keysonly' for backing up/restoring keys without the ...2023-12-12T20:31:00+01:00David Vasekbackup: add the filter '+keysonly' for backing up/restoring keys without the KASP databaseThey are always used with functions from that module anyway.They are always used with functions from that module anyway.Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1619quic-requestor: improve resend and resiliency against timeouts2023-12-08T12:53:21+01:00Libor Peltanquic-requestor: improve resend and resiliency against timeouts3.4Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1602quic: sweep improvements2023-12-04T16:08:50+01:00Libor Peltanquic: sweep improvements3.4Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1614IXFR: dont fallback to AXFR upon network error2023-11-29T19:17:59+01:00Libor PeltanIXFR: dont fallback to AXFR upon network error3.4Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1600tests: use XDP when possible, incl TCP...2023-11-07T17:13:32+01:00Libor Peltantests: use XDP when possible, incl TCP......on loopback interface, so exclusivity must be
ensured with the help of a lock file...on loopback interface, so exclusivity must be
ensured with the help of a lock fileDaniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1601Sign ctx stats2023-10-31T13:30:32+01:00Libor PeltanSign ctx stats3.4Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1594libknot/kdig: enable +nocrypto for all suitable types...2023-10-23T08:08:49+02:00Libor Peltanlibknot/kdig: enable +nocrypto for all suitable types.....except IPSECKEY where it would be too difficult
Fixes #882..except IPSECKEY where it would be too difficult
Fixes #8823.4Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1597test+doc: multi-signer supports DNSKEYs at common primary2023-10-19T11:26:41+02:00Libor Peltantest+doc: multi-signer supports DNSKEYs at common primary3.3Daniel SalzmanDaniel Salzmanhttps://gitlab.nic.cz/knot/knot-dns/-/merge_requests/1593IXFR: benevolent ignorance of add/rem non/existing records2023-10-19T08:37:40+02:00Libor PeltanIXFR: benevolent ignorance of add/rem non/existing records3.3Daniel SalzmanDaniel Salzman