Software updates
Unbound 1.4.2 released
Tue, Mar 09 2010
OpenDNSSEC 1.0.0 out now
Tue, Feb 9 2010
The first official OpenDNSSEC release is available right now.
For downloads and more information about future release plans, visit the OpenDNSSEC website.
OpenDNSSEC website.
ldns 1.6.4 released
Wed, Jan 20 2010
This new release has the pyldns contribution by Zdenek Vasicek and Karel Slany imported. Plus bug fixes.
Direct Download.
Changes.
NSD 3.2.4 released
Wed, Jan 6 2010
Unbound 1.4.1 released
Thu, Dec 17 2009
autotrust 0.3.1 released
Tue, Sep 8 2009
This new autotrust release offers some new features like syslog and resolver reloading,
as well as some bug fixes. Also, the configuration file format has changed, to be more
in line with Unbound.
Direct Download.
Changelog.
ldns 1.6.3 released
Fri, Dec 4 2009
Unbound 1.4.0 released
Thu, Nov 26 2009
ldns 1.6.2 released
Thu, Nov 12 2009
Enables SHA2 by default. Fixes lots of bugs for OpenDNSSEC and other. ldns-sign-zone will minimally sign the DNSKEY rrset. Direct Download.
Changes.
Unbound 1.3.4 released
Wed, Oct 7 2009
NSD 3.2.3 released
Mon, Aug 17 2009
ldns 1.6.1 released
Fri, Aug 14 2009
Unbound 1.3.3 released
Tue, Aug 4 2009
Unbound 1.3.2 released
Thu, Jul 13 2009
Unbound 1.3.1 released
Thu, Jul 9 2009
ldns 1.6.0 released
Thu, Jul 9 2009
Unbound 1.3.0 released
Thu, Jun 11 2009
NSD 3.2.2 release critical
Mon, May 18 2009
ldns 1.5.1 released
Tue, Feb 10 2009
Unbound 1.2.1 released
Tue, Feb 10 2009
ldns 1.5.0 released
Mon, Feb 9 2009
NSD 3.2.1. out now
Mon, Jan 19 2009
Unbound 1.2.0 released
Wed, Jan 14 2009
ldns 1.4.1 released
Fri, Dec 19 2008
Unbound 1.1.1 released
Thu, Nov 24 2008
Unbound 1.1.0 released
Thu, Nov 18 2008
NSD 3.2.0 released
Mon, Nov 10 2008
A "feature rich" release. Contains longstanding requests such as SHA support for TSIG and configuration options for setting the outgoing interface. Also AXFR fallback, and IXFR on TCP by default. VERY IMPORTANT: The format of ixfr.db has changed, so be sure to process the old one before updating to 3.2.0.
NSD project page.
Direct Download.
Changelog.
ldns 1.4.0 released
Fri, Nov 7 2008
Unbound 1.0.2 released
Thu, Aug 7 2008
NSD 3.1.1 released
Mon, Jul 21 2008
This release contains mainly bugfixes. It also allows you to configure the maximum number of allowed interfaces. If you use it, it can have consequences for your memory usage.
NSD project page.
Direct Download.
Changelog.
NSD 3.1.0 released
Mon, Jun 23 2008
New version of NSD. It supports NSEC3 by default, has a "hide-version" configuration setting, to stop NSD answering from CHAOS class version requests, has bind2nsd 0.5.0, has some bugfixes resolved and reports source and zone for denied AXFR attempts. Some operational notes: the default locations of nsd.db, ixfr.db and xfrd.state are changed to the /var/db/nsd/ directory.
NSD project page.
Direct Download.
Changelog.
ldns 1.3.0 released
Tue, Jun 2 2008
New version of ldns; If Unbound is to be linked against a separate copy of ldns, this
version should be used.
There are also some notable features, such as HSM support for DNSSEC signing, and
nicer output for signature chasing.
ldns project page.
Direct Download.
Changelog.
Unbound 1.0.0 released
Tue, May 20 2008
NSD 3.0.8 Release
Fri, Apr 18 2008
ldns 1.2.2 Release
Wed, Nov 28 2007
NSD 3.0.7 Release
Tue, Nov 13 2007
Fixup of error handling for bad data in IXFRs. Manual page syntax improvements.
NSD project page.
NSD 2.3.7 Release
Mon, Apr 16 2007
This is a bug-fix release on our older maintenance branch of NSD. It
includes a fixup of type WKS printing from nsd-xfer, a fixup in a call
to getservbyport. There are changes in the getaddrinfo error message
and a change to make it fall back to IPv4 if it fails for IPv6. A
typecast is added to satisfy the compiler. Furthermore a cleanup of the
text for NOTAUTH error code.
NSD project page.
ldns 1.2.0 Release
Wed, Apr 11 2007
|
Publications
Securing DNS: Extending DNS Servers with a DNSSEC Validator
Tue, Oct 27 2009
DNS Security Extensions (DNSSEC) is a proposed standard for securely authenticating information in the Domain Name System. DNSSEC validators check the digital signatures on DNS data. However, designing a validator worth the operational costs is a challenge. Published in IEEE Security & Privacy, Sept/Oct. 2009.Securing DNS (DOI Bookmark).
DNSSEC HOWTO updated
Thu, Jul 4 2009
The DNSSEC HOWTO received its first public update after 2007. Examples have been updated to use recent versions of the software, Unbound configuration has been added, and some new material has been added. DNSSEC HOWTO (HTML).
DNSSEC HOWTO (PDF preferred).
NLnet Labs Annual Report 2008
Mon, June 8 2009
We are happy to present NLnet Labs Annual report 2008. It is
intended to present an overview of Labs' various activities
to those who support NLnet Labs financially, through grants
or support contracts, and for those who have shown a general
interest in our activities.
Annual Report 2008 (PDF).
Implementing OpenLISP with LISP+ALT
Tue, April 14 2009
The LISP protocol has been developed to address the growth of the BGP routing table in the DFZ. OpenLISP is an implementation of this protocol, but does not include a location mapping service. This reports describes how a mapping locations service should interact with OpenLISP, GRE and Quagga to use LISP+ALT as a control plane. OpenLISP report (PDF).
DNSSEC Key Maintenance Analysis
Thu, Oct 23 2008
This document provides recommendations for the generation, storage
and use of keys in the context of DNSSEC. It is a followup of NLnet
Labs document 2006-SE-01: DNS Threat Analysis, written for .SE.
pdf.
Enforcing Integrity of Agent Migration Paths by Distribution of Trust
Mon, Sep 25 2008
Agent mobility is the ability of an agent to migrate from one
location to another across a network. Though conceptually relatively
straightforward, in practice security of mobile agents is a
challenge. This paper discusses the security
issues involved and proposes protocols for secure agent migration.
AgentScape, an agent platform for mobile agents, is used to
illustrate the feasibility of the implementation of these protocols.
Download article (pdf).
Master Thesis BGP Modeling and Simulation
Mon, Sep 8 2008
In this thesis we present a new approach to BGP simulation. Instead
of focussing on intra-domain communication, network and protocol are
highly abstracted in order to allow for large-scale simulation. We
describe our model of the BGP protocol along with its implementation.
Many tracks of future researc are shown as well as many possible
uses of this kind of approach to BGP simulation.
Download master thesis (pdf).
Annual Report 2007 released
Fri, Aug 22 2008
We are happy to present NLnet Labs Annual report 2007. It is
intended to present an overview of Labs' various activities
to those who support NLnet Labs financially, through grants
or support contracts, and for those who have shown a general
interest in our activities.
Annual Report 2007(pdf).
HSM Tutorial
Tue, May 13 2008
Design of a Secure and Decentralized Location Service for
Agent Platforms
Wed, Sep 19 2007
Formalization and Verification of the Shim6 Protocol
Mon, Jul 16 2007
Annual Report 2006
Tue, May 21 2007
DNS Threat Analysis
Thu, May 3 2007
Annual Report 2005
Tue, Jun 18 2006
|
Other related news
Stale keys and unbound behaviour
Fri, Feb 12 2010
Statement regarding concerns about stale keys and Unbound behavior
mail.
SURFnet deploys DNSSEC and uses Unbound
Tue, Sep 8 2009
SURFnet announces that all SURFnet DNS (Domain Name System) resolvers now support DNSSEC.
SURFnet uses Unbound as its resolver of choice.
SURFnet is one of the first networks in the Netherlands to support DNSSEC.
More information.
Innovation vouchers
Mon, Aug 28 2009
For Dutch companies there is, under a program to promote
innovation, the possibility to receive a 2.500 Euro
subsidy. The NLnet foundation, our mother, has a program that
allows furthering of open source software by any Dutch company
that is registered with the Chamber of Commerce. It takes 10
minutes to fill in the paperwork and direct those 2.500 Euro
toward a good purpose.
NLnet innovation vouchers.
OpenDNSSEC technology preview
Thu, 30 Jul 2009
The OpenDNSSEC project announces the development of Open Source software that manages the security of domain names on the Internet.
The project intends to drive adoption of Domain Name System Security Extensions (DNSSEC) to further enhance Internet security.
Visit the OpenDNSSEC website for more information and to download the technology preview.
OpenDNSSEC website.
NLnet Labs is hiring
Sat, Jul 25 2009
We are looking for enthusiastic programmer/developers to
complete our 6 persons team. Somebody who will be developing and
maintaining open source software and open standards.
More information.
BSD Podcast
Wed, Jul 8 2009
The bsdtalk podcast by Will Backman interviews Wouter
Wijngaards about the Unbound resolver. bsdtalk 176.
NSD Vulnerability Announcement
Mon, May 18 2009
RFI for Unbound Tech Support
Tue, Apr 21 2009
NLnet Labs is seeking information about organizations
that would be willing and able to provide first and second line
support for Unbound and would like to know more about their ideas
on organization and cooperation.
RFI-support.
NLnet Labs joins DNSSEC industry coalition to Increase Adoption of Domain Name Security Extensions (DNSSEC).
Thu, Dec 11 2008
The DNSSEC Industry Coalition is a global group of registries and industry experts whose mission is to work collaboratively to facilitate adoption of Domain Name Security Extensions (DNSSEC) and streamline the implementations across Domain Name Registries. Members work together to establish a consistent set of tools and applications, shared best practices, specifications and shared nomenclature. DNSSEC Industry Coalition members include both generic Top-Level Domain and country code Top-Level Domain registries along with industry and educational experts of the Domain Name System.
Press release.
DNSSEC Industry Coalition.
Unbound operation explained in book
Mon, Dec 08 2008
Book "Alternative DNS Servers", also describes Unbound
and NSD operation. More.
Japan Unbound User Group
Thu, Sep 04 2008
The Japan Unbound Users Group has opened its website today, with
unbound documentation, support and forum in Japanese.
http://unbound.jp/.
DNS Cache Poisoning Vulnerability
Wed, Jul 19 2008
NSD Memory Usage Estimate
Fri, Apr 13 2007
NSD Powers Secure64 DNS Solution
Sat, Mar 31 2007
Secure64 is a company specialized in
secure and high-performance applications. They have developed SourceT,
a micro operating system geared towards secure network systems on
Itanium processors.
NSD has been ported to SourceT, and is used as the name server software
of their Secure64 DNS product, providing RFC-compliant, DNSSEC-enabled,
fast DNS services on top of their SourceT operating system.
They have performed benchmarks on a Itanium machine with SourceT running
NSD, and have been able to handle a query load of over 100,000 queries
per second with only 1 CPU. The system was able to sustain DNS service
in the face of a variety of common attack profiles until the network
link was saturated.
The full test results can be found here.
Secure64.
|