Adolf Belka 374b2d8d57 knot: Update to version 3.3.8
- Update from version 3.3.5 to 3.3.8
- Update of rootfile not required
- Changelog
    3.3.8
	Features:
	 - libzscanner,libknot: added support for 'dohpath' and 'ohttp' SVCB parameters
	 - libzscanner,libknot: added support for WALLET rrtype
	 - keymgr: new commands for keystore testing (see 'keystore-test' and 'keystore-bench')
	 - knotd: new configuration option for setting default TTL (see 'zone.default-ttl')
	Improvements:
	 - libknot: added error codes to better describe some failures
	Bugfixes:
	 - knotd: DNSSEC signing doesn't remove NSEC records for non-authoritative nodes
	 - knotd: DNSSEC signing not scheduled on secondary if nothing to be reloaded
	 - libknot: TCP over XDP doesn't ignore SYN+ACK packets on the server side
    3.3.7
	Improvements:
	 - libs: upgraded embedded libngtcp2 to 1.6.0
	Bugfixes:
	 - knotd: insufficient metadata check can cause journal corruption
	 - knotd: missing zone timers initialization upon purge
	 - knotd: missing RCU lock in zone flush and refresh
	 - knotd: defective assert in zone refresh
    3.3.6
	Features:
	 - knotd: configurable control socket backlog size (see 'control.backlog')
	 - knotd: optional configuration of congruency of generated keytags (see 'policy.keytag-modulo')
	 - knotc: support for exporting configuration schema in JSON (see 'conf-export') #912
	 - mod-dnstap: configuration of sink allows TCP address specification
	Improvements:
	 - knotd: last-signed serial is stored to KASP even if not a secondary zone
	 - knotd: allowed catalog role member in a catalog template configuration
	 - knotd: some references in a zone configuration can be set empty to override a template
	 - knotd: allowed zone backup during a zone transaction
	 - knotd: add remote TSIG key name to outgoing event logs
	 - knotc: zone backup with '+keysonly' silently uses all defaults as 'off'
	 - kxdpgun: host name can be used for target specification
	 - libs: upgraded embedded libngtcp2 to 1.5.0
	 - doc: various fixes and updates
	Bugfixes:
	 - knotd: reset TCP connection not removed from a connection pool
	 - knotd: server wrongly tries to remove removed ZONEMD
	 - knotd: failed to parse empty list from a textual configuration
	 - knotd: blocking zone signing in combination with an open transaction causes a deadlock
	 - knotd: missing RCU lock when sending NOTIFY
	 - kdig: QNAME letter case isn't preserved if IDN is enabled
	 - kdig: failed to parse empty QNAME (do not fill question section)
	 - kxdpgun: floating point exception on SIGUSR1 #927
	 - libknot: incorrect handling of regular QUIC tokens in incoming initials
	 - python: failed to set an empty configuration value

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-08-14 09:09:54 +00:00
2024-08-14 09:09:43 +00:00
2024-08-07 14:32:55 +02:00
2024-08-14 09:09:54 +00:00
2021-03-10 14:42:37 +00:00
2024-03-30 12:12:42 +00:00

IPFire 2.x - The Open Source Firewall

What is IPFire?

IPFire is a hardened, versatile, state-of-the-art Open Source firewall based on Linux. Its ease of use, high performance in any scenario and extensibility make it usable for everyone. For a full list of features have a look here.

This repository contains the source code of IPFire 2.x which is used to build the whole distribution from scratch, since IPFire is not based on any other distribution.

Where can I get IPFire?

Just head over to https://www.ipfire.org/download

How do I use this software?

We have a long and detailed documentation located here which should answer most of your questions.

But I have some questions left. Where can I get support?

You can ask your question at our community located here. A complete list of our support channels can be found here.

How can I contribute?

We have another document for this. Please look here.

Description
No description provided
Readme 101 MiB
Languages
Perl 70.4%
Shell 23%
C 4%
Python 0.6%
Makefile 0.5%
Other 1.4%