Commit graph

1479 commits

Author SHA1 Message Date
David Vašek
92b2653ae9 doc/reference: a basic description of 'policy.trash-delay' 2026-05-20 09:10:38 +02:00
David Vašek
f0cc1706e2 purge: start using keys purge 2026-05-20 09:10:38 +02:00
David Vašek
13b734fd39 doc/reference: fix a typo 2026-05-20 09:10:38 +02:00
David Vašek
48a12528d9 doc/appendices: for Luna HSM's, include their manufacturer name 2026-05-20 09:10:38 +02:00
David Vašek
5570e92935 doc/appendices: fix a letter case in EdDSA 2026-05-20 09:10:38 +02:00
Daniel Salzman
839d88fb1c semchecks: check for DELEG at the zone apex 2026-05-06 12:14:06 +02:00
Libor Peltan
5de6f107c1 DELEG: conf knob to enforce/override DELEG-awareness...
...manually, e.g. even for unsigned zones
2026-05-06 12:14:06 +02:00
Libor Peltan
eb97f3aa31 dnssec/DELEG: conf knob in policy triggers ADT 2026-05-06 12:14:06 +02:00
Libor Peltan
2508e1752f libknot+kdig: support for EDNS DE flag (DELEG-aware signal) 2026-05-06 12:14:06 +02:00
Libor Peltan
26358f91f3 kdig: implemented DNSSEC validation (+validate) 2026-04-16 12:20:09 +02:00
Daniel Salzman
0448549f3f xdp: allow configuring ZERO_COPY by 'xdp.zero-copy'
Disabling ZERO_COPY can help if there is a bug in the kernel/driver.
2026-03-23 10:50:33 +01:00
Daniel Salzman
b8ef28b656 conf: soften catalog zone configuration checks 2026-02-21 20:31:33 +01:00
Libor Peltan
60cd64a885 doc: warn that moving member between generated catalogs is complicated 2026-02-13 16:45:52 +01:00
Daniel Salzman
2e23db82f1 doc: add anchors to knotc commands 2026-02-13 16:45:52 +01:00
Libor Peltan
3dd9ff37fa doc/catalog: clarify that uniq_id must be unique 2026-02-04 09:08:12 +01:00
Daniel Salzman
0c4904c67b doc: add RFC 9103 information to the XoT section 2026-02-04 08:50:25 +01:00
David Vašek
3a7ffd53fd doc/appendices: number the footnotes in the order of appearance 2026-01-16 08:19:53 +01:00
David Vašek
a268ce5dec doc/operation: add a section regarding HSM keystores (note that OS privileges may need to be set) 2026-01-15 14:56:04 +01:00
Daniel Salzman
0cbbc18ca2 doc/appendices: sort HSM devices by measurement date 2026-01-06 08:53:04 +01:00
Daniel Salzman
2291dd9670 doc/appendices: remove some obsolete HSM devices 2026-01-06 08:50:16 +01:00
David Vašek
ec4936c3ee doc/appendices: fix a typo 2026-01-06 08:40:07 +01:00
Jan Doskočil
e09b2853dc doc/appendices: note - HSM FW version affects capabilities 2026-01-06 08:40:07 +01:00
Jan Doskočil
818cf862c3 doc/appendices: add Securosys Primus HSM 2026-01-06 08:40:07 +01:00
Daniel Salzman
1342215081 dbus: emit zone_not_updated signal if zone-updated is enabled 2025-12-18 15:34:15 +01:00
Daniel Salzman
e84658eca9 kdig: remove TCP Fast Open support 2025-12-16 14:36:18 +01:00
Daniel Salzman
a657f110b6 knotd: remove TCP Fast Open support
This technology didn’t prove to be helpful.
2025-12-16 14:36:18 +01:00
Daniel Salzman
314b06225d conf: increase defaults for timer-db-max-size and kasp-db-max-size 2025-12-15 13:45:16 +01:00
madblobfish
f10adc9166 Add reference to journal behaviour paragraph in operation.rst
Adds a reference to the journal-max-usage zone configuration parameter
in a paragraph in the operation.rst file which mentions per-zone limits.
Also reformatted lines of said paragraph due to reaching 80 characters.
2025-12-15 08:14:32 +01:00
Jan Hák
b7a1769bbc libs: support for RESINFO RRtype, RFC 9696
closes #962
2025-12-14 20:04:21 +01:00
Jan Hák
62a64aa104 kdig: replace +noidn with +[no]idnin and +[no]idnout as in dig 2025-12-12 14:12:25 +01:00
Daniel Salzman
3a25b60878 doc: some KSK submission improvements 2025-12-10 15:45:55 +01:00
Libor Peltan
8daa3d91c3 doc/submission: warning about non-application of parent-delay 2025-12-10 14:31:33 +01:00
Libor Peltan
c2d51f704d knotc/zone-ksk-submitted: implemented +ttl for delaying old KSK removal 2025-12-10 14:31:33 +01:00
Jan Doskočil
67bdb1b6a9 doc/appendices: update SoftHSM 2.0 2025-12-06 18:50:06 +01:00
Jan Doskočil
359b9f2c59 doc/appendices: add Luna Network HSM 2025-12-06 18:50:06 +01:00
Daniel Salzman
67b3f17c1f libknot: ED488 is mandatory since GnuTLS 3.6.12 2025-12-05 11:46:14 +01:00
Daniel Salzman
227314cc94 configure: increase minimum required GnuTLS version to 3.6.12 2025-12-05 11:46:14 +01:00
Jan Doskočil
f59721e8fc doc/appendices: add Luna Cloud HSM 2025-11-27 21:03:43 +01:00
Jan Doskočil
0d12eeeda7 doc/appendices: reformat the "supported HSMs" table + add last tested date 2025-11-27 21:03:43 +01:00
Libor Peltan
3f9b634dab timers: implemented configurable periodic dump 2025-11-24 10:53:08 +01:00
Jan Hák
356e9c4987 redis: command knot.zone.info 2025-11-05 15:31:33 +01:00
Daniel Salzman
f760173bb5 doc: extend listen comment in the configuration example 2025-11-03 15:14:32 +01:00
Libor Peltan
a83fab1eec libknot: support for DSYNC RRtype, RFC 9859 2025-11-03 09:13:43 +01:00
Daniel Salzman
721385cd2e process_query: weaken the ACL action for catalog queries to 'query' 2025-10-30 16:08:30 +01:00
Daniel Salzman
9d92c56379 doc: fix typo in operation 2025-10-27 09:10:23 +01:00
Daniel Salzman
f9cf9e6721 Remove libdnssec 2025-10-24 09:17:08 +02:00
Daniel Salzman
357706157a redis: add multi-db and/or sentinel support 2025-10-15 17:57:46 +02:00
Daniel Salzman
a34e5a096d doc: add default TLS and QUIC ports to reference 2025-10-15 13:50:17 +02:00
Daniel Salzman
b7ab32fcae redis: add support for hostname listen specification 2025-10-15 13:50:01 +02:00
Libor Peltan
88b5ed72b3 knotc: implemented zone-serial-set 2025-10-15 12:24:33 +02:00