- Jun 30, 2020
-
-
Vladimír Čunát authored
Also utilize table indexing. This was a "regression" from extending RPZ support in 5.1.0. NS and SOA are even mandatory, as RPZ is supposed to be a valid zone: https://tools.ietf.org/html/draft-ietf-dnsop-dns-rpz-00#section-2
-
- Jun 29, 2020
-
-
Petr Špaček authored
It seems pointless to accumulate "late" connection attempts.
-
Petr Špaček authored
-
Petr Špaček authored
-
-
- May 27, 2020
-
-
Tomas Krizek authored
-
Tomas Krizek authored
-
Tomas Krizek authored
-
Tomas Krizek authored
-
-
-
-
and Ubuntu 18.04, Leap 15.2
-
-
-
- May 25, 2020
-
-
Vladimír Čunát authored
-
Vladimír Čunát authored
Apparently the original implementation in 14de9110 didn't think of this. Noticed by Fantomas: https://forum.turris.cz/t/kresd-returns-nxdomain-for-local-mx-records/12991
-
- May 18, 2020
-
-
- Apr 30, 2020
-
-
Petr Špaček authored
-
- Apr 27, 2020
-
-
- Apr 15, 2020
-
-
Petr Špaček authored
Formerly multiple instances could use the same seed, which prevented the retry logic in Lua modules (e.g. prefill) from retrying at different times. AFAIK security impact is zero aside from potential thundering-herd problem with many kresd instances.
-
-
- Apr 14, 2020
-
-
- Apr 02, 2020
-
-
Vladimír Čunát authored
-
Vladimír Čunát authored
Some rules need it and it was nil until now.
-
Vladimír Čunát authored
DENY, DENY_MSG, DROP, REFUSE and TC will now clear the _selected RRs. I believe that's what people usually expect of these actions anyway.
-
Vladimír Čunát authored
-
Tomas Krizek authored
-
Tomas Krizek authored
-
Tomas Krizek authored
-
Tomas Krizek authored
-
Tomas Krizek authored
Previously, all those actions caused resolver to return SERVFAIL, because the lua code failed to evaluate. Notably, deny action now properly returns NXDOMAIN instead of SERVFAIL. The drop action still returns SERVFAIL.
-
Tomas Krizek authored
-
Old favicon used Knot DNS colors (dark blue) instead of Knot Resolver colors (light blue).
-