Software updates

Unbound 1.4.2 released

Tue, Mar 09 2010

OpenDNSSEC 1.0.0 out now

Tue, Feb 9 2010
The first official OpenDNSSEC release is available right now. For downloads and more information about future release plans, visit the OpenDNSSEC website.
OpenDNSSEC website.

ldns 1.6.4 released

Wed, Jan 20 2010
This new release has the pyldns contribution by Zdenek Vasicek and Karel Slany imported. Plus bug fixes.
Direct Download. Changes.

NSD 3.2.4 released

Wed, Jan 6 2010
This new NSD release comes with some new configure options, DLV record support and some bugfixes.
NSD project page. Direct Download.

Unbound 1.4.1 released

Thu, Dec 17 2009

autotrust 0.3.1 released

Tue, Sep 8 2009
This new autotrust release offers some new features like syslog and resolver reloading, as well as some bug fixes. Also, the configuration file format has changed, to be more in line with Unbound.
Direct Download. Changelog.

ldns 1.6.3 released

Fri, Dec 4 2009
Small bugfix release.
Direct Download. Changes.

Unbound 1.4.0 released

Thu, Nov 26 2009
RFC5011, RFC5702 features and bugfixes.
Unbound website. Direct Download. Changes.

ldns 1.6.2 released

Thu, Nov 12 2009
Enables SHA2 by default. Fixes lots of bugs for OpenDNSSEC and other. ldns-sign-zone will minimally sign the DNSKEY rrset.
Direct Download. Changes.

Unbound 1.3.4 released

Wed, Oct 7 2009
DNSSEC downgrade bug fixed.
Unbound website. Direct Download. Changes.

NSD 3.2.3 released

Mon, Aug 17 2009

ldns 1.6.1 released

Fri, Aug 14 2009

Unbound 1.3.3 released

Tue, Aug 4 2009
Bugfixes, minor features.
Unbound website. Direct Download. Changes.

Unbound 1.3.2 released

Thu, Jul 13 2009
Windows port fixed.
Unbound website. Direct Download. Changes.

Unbound 1.3.1 released

Thu, Jul 9 2009

ldns 1.6.0 released

Thu, Jul 9 2009

Unbound 1.3.0 released

Thu, Jun 11 2009
Windows port. Python contribution. Bugfixes.
Unbound website. Direct Download. Changes.

NSD 3.2.2 release critical

Mon, May 18 2009
Critical bugfix release for NSD.
NSD project page. Direct Download.

ldns 1.5.1 released

Tue, Feb 10 2009
Bugfix release for the zone signer in ldns 1.5
ldns project page. Direct Download. Changelog.

Unbound 1.2.1 released

Tue, Feb 10 2009
Bugfix release, features for smoother operations.
Unbound website. Direct Download. Changes.

ldns 1.5.0 released

Mon, Feb 9 2009

NSD 3.2.1. out now

Mon, Jan 19 2009
Mainly a bugfix release, but also some new features. Fixes AXFR fallback discussion.
NSD project page. Direct Download. Changelog.

Unbound 1.2.0 released

Wed, Jan 14 2009
Minor features and important, security related, bugfixes.
Unbound website. Direct Download. Changes.

ldns 1.4.1 released

Fri, Dec 19 2008
New version of ldns; A couple of NSEC3 related bugs have fixed, as well some gripes in the build scripts.
ldns project page. Direct Download. Changelog.

Unbound 1.1.1 released

Thu, Nov 24 2008

Unbound 1.1.0 released

Thu, Nov 18 2008
DLV support, statistics and lots of other features that have been requested. Also bugfixes.
Unbound website. Direct Download. Changes.

NSD 3.2.0 released

Mon, Nov 10 2008
A "feature rich" release. Contains longstanding requests such as SHA support for TSIG and configuration options for setting the outgoing interface. Also AXFR fallback, and IXFR on TCP by default. VERY IMPORTANT: The format of ixfr.db has changed, so be sure to process the old one before updating to 3.2.0.
NSD project page. Direct Download. Changelog.

ldns 1.4.0 released

Fri, Nov 7 2008
New version of ldns; some small new and fixed features, and a number of bugs fixed
ldns project page. Direct Download. Changelog.

Unbound 1.0.2 released

Thu, Aug 7 2008
This release contains filtering fixes to prevent certain types of exploits. Also bugfixes. More discussion in the announcement.
Unbound website. Direct Download. Announcement.

NSD 3.1.1 released

Mon, Jul 21 2008
This release contains mainly bugfixes. It also allows you to configure the maximum number of allowed interfaces. If you use it, it can have consequences for your memory usage.
NSD project page. Direct Download. Changelog.

NSD 3.1.0 released

Mon, Jun 23 2008
New version of NSD. It supports NSEC3 by default, has a "hide-version" configuration setting, to stop NSD answering from CHAOS class version requests, has bind2nsd 0.5.0, has some bugfixes resolved and reports source and zone for denied AXFR attempts. Some operational notes: the default locations of nsd.db, ixfr.db and xfrd.state are changed to the /var/db/nsd/ directory.
NSD project page. Direct Download. Changelog.

ldns 1.3.0 released

Tue, Jun 2 2008
New version of ldns; If Unbound is to be linked against a separate copy of ldns, this version should be used. There are also some notable features, such as HSM support for DNSSEC signing, and nicer output for signature chasing.
ldns project page. Direct Download. Changelog.

Unbound 1.0.0 released

Tue, May 20 2008
The public release of Unbound, a fast recursive validating caching DNS server.

Unbound logo
Unbound project page. Press release. Direct download.

NSD 3.0.8 Release

Fri, Apr 18 2008
Better logging for nsd-notify, Add chkconfig configuration, nsdc bugfixes, strptime fix, more (bugzilla) fixes and logging features.
NSD project page. Direct Download. Changelog.

ldns 1.2.2 Release

Wed, Nov 28 2007
We released a new version of ldns. There are some bugfixes, an added example tool, and hmac-md5 support for keys.
ldns project page. Direct Download. Changelog.

NSD 3.0.7 Release

Tue, Nov 13 2007
Fixup of error handling for bad data in IXFRs. Manual page syntax improvements.
NSD project page.

NSD 2.3.7 Release

Mon, Apr 16 2007
This is a bug-fix release on our older maintenance branch of NSD. It includes a fixup of type WKS printing from nsd-xfer, a fixup in a call to getservbyport. There are changes in the getaddrinfo error message and a change to make it fall back to IPv4 if it fails for IPv6. A typecast is added to satisfy the compiler. Furthermore a cleanup of the text for NOTAUTH error code.
NSD project page.

ldns 1.2.0 Release

Wed, Apr 11 2007
We released a new version of ldns. There are a lot of bugfixes, some more examples, and drill has had significant updates.
ldns project page. Direct Download.

Publications

Securing DNS: Extending DNS Servers with a DNSSEC Validator

Tue, Oct 27 2009
DNS Security Extensions (DNSSEC) is a proposed standard for securely authenticating information in the Domain Name System. DNSSEC validators check the digital signatures on DNS data. However, designing a validator worth the operational costs is a challenge. Published in IEEE Security & Privacy, Sept/Oct. 2009.
Securing DNS (DOI Bookmark).

DNSSEC HOWTO updated

Thu, Jul 4 2009
The DNSSEC HOWTO received its first public update after 2007. Examples have been updated to use recent versions of the software, Unbound configuration has been added, and some new material has been added.
DNSSEC HOWTO (HTML). DNSSEC HOWTO (PDF preferred).

NLnet Labs Annual Report 2008

Mon, June 8 2009
We are happy to present NLnet Labs Annual report 2008. It is intended to present an overview of Labs' various activities to those who support NLnet Labs financially, through grants or support contracts, and for those who have shown a general interest in our activities.
Annual Report 2008 (PDF).

Implementing OpenLISP with LISP+ALT

Tue, April 14 2009
The LISP protocol has been developed to address the growth of the BGP routing table in the DFZ. OpenLISP is an implementation of this protocol, but does not include a location mapping service. This reports describes how a mapping locations service should interact with OpenLISP, GRE and Quagga to use LISP+ALT as a control plane.
OpenLISP report (PDF).

DNSSEC Key Maintenance Analysis

Thu, Oct 23 2008
This document provides recommendations for the generation, storage and use of keys in the context of DNSSEC. It is a followup of NLnet Labs document 2006-SE-01: DNS Threat Analysis, written for .SE.
pdf.

Enforcing Integrity of Agent Migration Paths by Distribution of Trust

Mon, Sep 25 2008
Agent mobility is the ability of an agent to migrate from one location to another across a network. Though conceptually relatively straightforward, in practice security of mobile agents is a challenge. This paper discusses the security issues involved and proposes protocols for secure agent migration. AgentScape, an agent platform for mobile agents, is used to illustrate the feasibility of the implementation of these protocols.
Download article (pdf).

Master Thesis BGP Modeling and Simulation

Mon, Sep 8 2008
In this thesis we present a new approach to BGP simulation. Instead of focussing on intra-domain communication, network and protocol are highly abstracted in order to allow for large-scale simulation. We describe our model of the BGP protocol along with its implementation. Many tracks of future researc are shown as well as many possible uses of this kind of approach to BGP simulation.
Download master thesis (pdf).

Annual Report 2007 released

Fri, Aug 22 2008
We are happy to present NLnet Labs Annual report 2007. It is intended to present an overview of Labs' various activities to those who support NLnet Labs financially, through grants or support contracts, and for those who have shown a general interest in our activities.
Annual Report 2007(pdf).

HSM Tutorial

Tue, May 13 2008
An introduction to the use of HSM.
Download. HTML version.

Design of a Secure and Decentralized Location Service for Agent Platforms

Wed, Sep 19 2007

Formalization and Verification of the Shim6 Protocol

Mon, Jul 16 2007

Annual Report 2006

Tue, May 21 2007

DNS Threat Analysis

Thu, May 3 2007

Annual Report 2005

Tue, Jun 18 2006

Other related news

Stale keys and unbound behaviour

Fri, Feb 12 2010
Statement regarding concerns about stale keys and Unbound behavior
mail.

SURFnet deploys DNSSEC and uses Unbound

Tue, Sep 8 2009
SURFnet announces that all SURFnet DNS (Domain Name System) resolvers now support DNSSEC. SURFnet uses Unbound as its resolver of choice. SURFnet is one of the first networks in the Netherlands to support DNSSEC.
More information.

Innovation vouchers

Mon, Aug 28 2009
For Dutch companies there is, under a program to promote innovation, the possibility to receive a 2.500 Euro subsidy. The NLnet foundation, our mother, has a program that allows furthering of open source software by any Dutch company that is registered with the Chamber of Commerce. It takes 10 minutes to fill in the paperwork and direct those 2.500 Euro toward a good purpose.
NLnet innovation vouchers.

OpenDNSSEC technology preview

Thu, 30 Jul 2009
The OpenDNSSEC project announces the development of Open Source software that manages the security of domain names on the Internet. The project intends to drive adoption of Domain Name System Security Extensions (DNSSEC) to further enhance Internet security. Visit the OpenDNSSEC website for more information and to download the technology preview.
OpenDNSSEC website.

NLnet Labs is hiring

Sat, Jul 25 2009
We are looking for enthusiastic programmer/developers to complete our 6 persons team. Somebody who will be developing and maintaining open source software and open standards.
More information.

BSD Podcast

Wed, Jul 8 2009
The bsdtalk podcast by Will Backman interviews Wouter Wijngaards about the Unbound resolver.
bsdtalk 176.

NSD Vulnerability Announcement

Mon, May 18 2009
A one-byte buffer overflow has been detected in the NSD software. A fix is ready for download.
More information. Download NSD 3.2.2.

RFI for Unbound Tech Support

Tue, Apr 21 2009
NLnet Labs is seeking information about organizations that would be willing and able to provide first and second line support for Unbound and would like to know more about their ideas on organization and cooperation.
RFI-support.

NLnet Labs joins DNSSEC industry coalition to Increase Adoption of Domain Name Security Extensions (DNSSEC).

Thu, Dec 11 2008
The DNSSEC Industry Coalition is a global group of registries and industry experts whose mission is to work collaboratively to facilitate adoption of Domain Name Security Extensions (DNSSEC) and streamline the implementations across Domain Name Registries. Members work together to establish a consistent set of tools and applications, shared best practices, specifications and shared nomenclature. DNSSEC Industry Coalition members include both generic Top-Level Domain and country code Top-Level Domain registries along with industry and educational experts of the Domain Name System.
Press release. DNSSEC Industry Coalition.

Unbound operation explained in book

Mon, Dec 08 2008
Book "Alternative DNS Servers", also describes Unbound and NSD operation.
More.

Japan Unbound User Group

Thu, Sep 04 2008
The Japan Unbound Users Group has opened its website today, with unbound documentation, support and forum in Japanese.
http://unbound.jp/.

DNS Cache Poisoning Vulnerability

Wed, Jul 19 2008
Statement about US-CERT Vulnerability Note VU#800113 and Unbound
Statement of Unbound Development team. US-CERT Vulnerability Note.

NSD Memory Usage Estimate

Fri, Apr 13 2007
Small web tool added to make a memory size indication given zone specification.
NSD project page. Memory estimate.

NSD Powers Secure64 DNS Solution

Sat, Mar 31 2007
Secure64 is a company specialized in secure and high-performance applications. They have developed SourceT, a micro operating system geared towards secure network systems on Itanium processors. NSD has been ported to SourceT, and is used as the name server software of their Secure64 DNS product, providing RFC-compliant, DNSSEC-enabled, fast DNS services on top of their SourceT operating system. They have performed benchmarks on a Itanium machine with SourceT running NSD, and have been able to handle a query load of over 100,000 queries per second with only 1 CPU. The system was able to sustain DNS service in the face of a variety of common attack profiles until the network link was saturated.
The full test results can be found here. Secure64.

Tue Feb 9 2010

© NLnet Labs

Science Park 140, 1098 XG Amsterdam, The Netherlands

labs@nlnetlabs.nl, subsidised by NLnet