Package Release Info


Update Info: Base Release
Available in Package Hub : 15 SP4





Change Logs

Version: 3.1.4-bp153.2.6.1
* Thu Nov 04 2021 Michal Hrusecky <>
- update to version 3.1.4, see:
* Tue Oct 19 2021 Michal Hrusecky <>
- update to version 3.1.3, see:
Version: 3.1.2-bp153.2.3.2
* Fri Sep 17 2021 Michal Hrusecky <>
- migrate to user creation via sysuser-tools
- run spec-cleaner on spec file
- update to version 3.1.2, see:
* Thu Aug 12 2021 Michal Hrusecky <>
- update to version 3.1.1, see:
* Wed Aug 04 2021 Michal Hrusecky <>
- update to version 3.1.0, see:
* Thu Jul 01 2021 Michal Hrusecky <>
- update to version 3.0.7, see:
* Fri May 14 2021 Michal Hrusecky <>
- make sure we have getent and groupadd/useradd in pre
  * added dependency on shadow and glibc
  * might be related to bnc#1186023
* Wed May 12 2021 Michal Hrusecky <>
- update to version 3.0.6, see:
* Tue May 11 2021 Michal Hrusecky <>
- Make /etc/knot directory owned by knot - fix reload action
* Sat Mar 27 2021 Jan Engelhardt <>
- Update descriptions, remove unsubstantiated claims.
* Thu Mar 25 2021 Michal Hrusecky <>
- update to version 3.0.5, see:
- Update description based on homepage
* Mon Feb 01 2021 Jan Engelhardt <>
- Trim marketing wording from description.
- Drop old rpm constructs.
Version: 3.0.4-bp153.1.48
* Mon Jan 25 2021 Michal Hrusecky <>
- version update to 3.0.4, see:
* Mon Jan 04 2021 Michal Hrusecky <>
- add incompatibility warning about 1.6.X version when updateing
- rename back to knot
* Mon Dec 28 2020
- version update to 3.0.3
* Mon Nov 30 2020 Michal Hrusecky <>
- version update to 2.9.7, see:
- obsolete only pre-2.0 version
* Tue Jul 21 2020 Marcus Rueckert <>
- remove rosedb conditional as lmdb is required in general now
* Tue Jul 21 2020 Marcus Rueckert <>
- replace conflicts with Provides/Obsoletes
* Wed Jun 24 2020 Michal Hrusecky <>
- fix dependency: python-Sphinx -> python3-Sphinx
* Wed Jun 24 2020 Michal Hrusecky <>
- fix dependency: python-Sphinx -> python3-Sphinx
* Wed Jun 24 2020 Michal Hrusecky <>
- use upstream example config file with correct syntax
* Tue May 19 2020 Michal Hrusecky <>
- version update to 2.9.4
  see NEWS
* Fri Dec 20 2019
- version update to 2.9.2
  see NEWS
* Wed Jan 23 2019 Marcus Rueckert <>
- update to 2.7.6
  - Improvements
  - Zone status also shows when the zone load is scheduled
  - Server workers status also shows background workers
  - Default control timeout for knotc was increased to 10 seconds
  - Pkg-config files contain auxiliary variable with library
  - Bugfixes
  - Configuration commit or server reload can drop some pending
    zone events
  - Nonempty zone journal is created even though it's disabled
  - Zone is completely re-signed during empty dynamic update
  - Server can crash when storing a big zone difference to the
  - Failed to link on FreeBSD 12 with Clang
* Mon Jan 07 2019 Marcus Rueckert <>
- update to 2.7.5
  - Features:
  - Keymgr supports NSEC3 salt handling
  - Improvements:
  - Zone history in journal is dropped apon AXFR-like zone update
  - Libdnssec is no longer linked against libm #628
  - Libdnssec is explicitly linked against libpthread if PKCS #11
    enabled #629
  - Better support for libknot packaging in Python
  - Manually generated KSK is 'ready' by default
  - Kdig supports '+timeout' as an alias for '+time'
  - Kdig supports '+nocomments' option
  - Kdig no longer prints empty lines between retries
  - Kdig returns failure if operations not successfully resolved
  - Fixed repeating of the 'KSK submission, waiting for
    confirmation' log
  - Various improvements in documentation, Dockerfile, and tests
  - Bugfixes:
  - Knotc fails to unset huge configuration section
  - Kjournalprint sometimes fails to display zone journal content
  - Improper timing of ZSK removal during ZSK rollover
  - Missing UTC time zone indication in the 'iso' keymgr list
  - A race condition in the online signing module
* Mon Dec 31 2018 Petr Gajdos <>
- update to 2.7.4
  - --------
  - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz)
  - ------------
  - Added warning log when DNSSEC events not successfully scheduled
  - New semantic check on timer values in keymgr
  - DS query no longer asks other addresses if got a negative answer
  - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication
  - Extended logging for zone loading
  - Various documentation improvements
  - --------
  - Failed to import module configuration #613
  - Improper Cflags value in libknot.pc if built with embedded LMDB #615
  - IXFR doesn't fall back to AXFR if malformed reply
  - DNSSEC events not correctly scheduled for empty zone updates
  - During algorithm rollover old keys get removed before DS TTL expires #617
  - Maximum zone's RRSIG TTL not considered during algorithm rollover #620
* Sun Nov 04 2018 Marcus Rueckert <>
- seems we no longer need jansson
* Sun Nov 04 2018 Marcus Rueckert <>
- limit geoip support to opensuse
* Sat Nov 03 2018 Marcus Rueckert <>
- update to 2.7.3
  - Features:
  - New queryacl module for query access control
  - Configurable answer rrset rotation #612
  - Configurable NSEC bitmap in online signing
  - Improvements:
  - Better error logging for KASP DB operations #601
  - Some documentation improvements
  - Bugfixes:
  - Keymgr "list" output doesn't show key size for ECDSA algorithms #602
  - Failed to link statically with embedded LMDB
  - Configuration commit causes zone reload for all zones
  - The statistics module overlooks TSIG record in a request
  - Improper processing of an AXFR-style-IXFR response consisting of one-record messages
  - Race condition in online signing during key rollover #600
  - Server can crash if geoip module is enabled in the geo mode
- changes from 2.7.2
  - Improvements:
  - Keymgr list command displays also key size
  - Kjournalprint displays total occupied size in the debug mode
  - Server doesn't stop if failed to load a shared module from the module directory
  - Libraries libcap-ng, pthread, and dl are linked selectively if needed
  - Bugfixes:
  - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec)
  - Server can crash when loading zone file difference and zone-in-journal is set
  - Incorrect treatment of specific queries in the module RRL
  - Failed to link module Cookies as a shared library
- changes from 2.7.1
  - Improvements:
  - Added zone wire size information to zone loading log message
  - Added debug log message for each unsuccessful remote address operation
  - Various improvements for packaging
  - Bugfixes:
  - Incompatible handling of RRSIG TTL value when creating a DNS message
  - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs
  - Default configure prefix is ignored
- changes from 2.7.0
  - Features:
  - New DNS Cookies module and related '+cookie' kdig option
  - New module for response tailoring according to client's subnet or geographic location
  - General EDNS Client Subnet support in the server
  - OSS-Fuzz integration (Thanks to Jonathan Foote)
  - New '+ednsopt' kdig option (Thanks to Jan V?elák)
  - Online Signing support for automatic key rollover
  - Non-normal file (e.g. pipe) loading support in zscanner #542
  - Automatic SOA serial incrementation if non-empty zone difference
  - New zone file load option for ignoring zone file's SOA serial
  - New build-time option for alternative malloc specification
  - Structured logging for DNSSEC key submission event
  - Empty QNAME support in kdig
  - Improvements:
  - Various library and server optimizations
  - Reduced memory consumption of outgoing IXFR processing
  - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds)
  - Online Signing properly signs delegations and CNAME records
  - CDS/CDNSKEY rrset is signed with KSK instead of ZSK
  - DNSSEC-related records are ignored when loading zone difference with signing enabled
  - Minimum allowed RSA key length was increased to 1024
  - Bugfixes:
  - Possible uninitialized address buffer use in zscanner
  - Possible index overflow during multiline record parsing in zscanner
  - kdig +tls sometimes consumes 100 % CPU #561
  - Single-Type Signing doesn't work with single ZSK key #566
  - Zone not flushed after re-signing during zone load #594
  - Server crashes when committing empty zone transaction
  - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595
  - Compatibility:
  - Removed obsolete RRL configuration
  - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record'
  - Removed obsolete 'ixfr-from-differences' configuration option
  - Removed old journal migration
  - Removed module rosedb
- changes from 2.6.9
  - Improvements:
  - Added zone wire size to zone loading log message
  - Added debug log message for each unsuccessful remote address operation
  - Bugfixes:
  - Zone not flushed after re-signing during zone load #594
  - Server crashes when committing empty zone transaction
  - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595
- packaging changes:
  - enabled geoip module: new BR: pkgconfig(libmaxminddb)
  - enabled cookies module
  - enabled queryacl module
* Sat Jul 14 2018
- update to 2.6.8
  - Features:
  - New 'import-pkcs11' command in keymgr
  - Improvements:
  - Unixtime serial policy mimics Bind ? increment if lower #593
  - Bugfixes:
  - Creeping memory consuption upon server reload #584
  - Kdig incorrectly detects QNAME if 'notify' is a prefix
  - Server crashes when zone sign fails #587
  - CSK->KZSK rollover retires CSK early #588
  - Server crashes when zone expires during outgoing
    multi-message transfer
  - Kjournalprint doesn't convert zone name argument to
  - Cannot switch to a previously used ksk-shared dnssec policy
- update to 2.6.7
  - Features:
  - Added 'dateserial' (YYYYMMDDnn) serial policy configuration
    (Thanks to Wolfgang Jung)
  - Improvements:
  - Trailing data indication from the packet parser (libknot)
  - Better configuration check for a problematical option
  - Bugfixes:
  - Incomplete configuration option item name check
  - Possible buffer overflow in 'knot_dname_to_str' (libknot)
  - Module dnsproxy doesn't preserve letter case of QNAME
  - Module dnsproxy duplicates OPT and TSIG in the non-fallback
* Wed May 02 2018
- Update to 2.6.6
  - Features:
  - New EDNS option counters in the statistics module
  - New '+orphan' filter for the 'zone-purge' operation
  - Improvements:
  - Reduced memory consuption of disabled statistics metrics
  - Some spelling fixes (Thanks to Daniel Kahn Gillmor)
  - Server no longer fails to start if MODULE_DIR doesn't exist
  - Configuration include doesn't fail if empty wildcard match
  - Added a configuration check for a problematical option combination
  - Bugfixes:
  - NSEC3 chain not re-created when SOA minimum TTL changed
  - Failed to start server if no template is configured
  - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing
  - Inaccurate outgoing zone transfer size in the log message
  - Invalid dname compression if empty question section
  - Missing EDNS in EMALF responses
* Mon Apr 02 2018
- update to 2.6.5
  - Features:
  - New 'zone-notify' command in knotc
  - Kdig uses '@server' as a hostname for TLS authenticaion if
    '+tls-ca' is set
  - Improvements:
  - Better heap memory trimming for zone operations
  - Added proper polling for TLS operations in kdig
  - Configuration export uses stdout as a default output
  - Simplified detection of atomic operations
  - Added '--disable-modules' configure option
  - Small documentation updates
  - Bugfixes:
  - Zone retransfer doesn't work well if more masters configured
  - Kdig can leak or double free memory in corner cases
  - Inconsistent error outputs from dynamic configuration
Version: 1.6.8-bp151.4.3.1
* Thu Jul 23 2020 Alexandros Toptsoglou <>
- CVE-2017-11104: Fixed an improper implementation of TSIG protocol
  which could have allowed an attacker with a valid key name and
  algorithm to bypass TSIG authentication (bsc#1047841).
  Added knot-CVE-2017-11104.patch
Version: 1.6.8-bp150.1.3
* Mon Jan 08 2018
- add knot-openssl-1.1+.patch
  * fix build with openssl 1.1+
* Mon Jun 05 2017
- refreshed
  to fix build
* Mon Feb 13 2017
- update to 1.6.8
  - Zone size limit restriction for DDNS, AXFR, and IXFR
* Tue May 10 2016
- fix the sphinx buildrequires so we can build on sle12
* Thu Feb 11 2016
- update to 1.6.7
  - Improvements:
  - IXFR: Log change of the zone serial number after the
  - RRL: Document operational impact of various settings.
  - RRL: Add support for zero slip (dropping of all limited
* Tue Nov 24 2015
- update to 1.6.6
  - Fix daemon startup systemd notification
  - Out-of-bound read in packet parser for malformed NAPTR records
  - Add rosedb module
- enable rosedb
- refresh patches to apply cleanly again
* Thu Sep 03 2015
- skip silent rule in to fix the SLE 11 build
* Thu Sep 03 2015
- update to 1.6.5
  - Bugfixes:
  - Do not reload expired zones on 'knotc reload' and server
  - Fix rare race-condition in event scheduling causing delayed
    event execution
  - Fix skipping of non-authoritative nodes in NSEC proofs
  - Fix TC flag setting in RRL slipped answers
  - Disable domain name compression for root label for better
  - Log via journald only when running under systemd
  - Improve lookup of libsystemd build dependencies
  - Fix compilation warnings in endian conversion functions on
  - Features:
  - Update persistent timers only on shutdown for better
  - Add 'request-edns-option' config option to add custom EDNS0
    option into server initiated queries
  - Allow specification of time units in 'max-conn-idle',
    'max-conn-handshake', 'max-conn-reply', and 'notify-timeout'
    config options
- changes in 1.6.4
  - Bugfixes:
  - Fix lost NOTIFY message if received during zone transfer
  - Fix compilation error with LibreSSL
  - Disable fast zone parser when compiled in Clang (workaround
    for Clang bug)
  - kdig: Record correct dnstap SocketProtocol when retrying
    over TCP
  - kdig: Hide TSIG section with +noall
  - Do not set AA flag for AXFR/IXFR queries
  - Features:
  - Zone parser: Split long TXT/SPF strings into multiple
  - kdig: Add generic dump style option (+generic)
  - Try all master servers in multi-master environment
  - Improvements:
  - Zone dump: Do not write class for SOA record (unified with
    other RR types)
  - Zone dump: Do not write master server address into the zone
- refresh patches to apply cleanly again
- sync spec file with knot2 spec file
  - use bcond_with for the systemd conditional
  - replace all occurences of %{name} with %{pkg_name}
  - removed duplicated libexecdir
  - also pass disable static and includedir
* Wed Apr 29 2015
- local state dir should be just /var
* Thu Apr 09 2015
- enable dnstap support for factory and newer:
  - new BR: protobuf-c and libfstrm-devel
- prepared lto support but not enabled yet, still need to find out
  which distros support it
* Thu Apr 09 2015
- update to 1.6.3
  - Performance drop for NSEC-signed zones
  - Proper handling of TCP short-writes
  - Out-of-bound read in zone parser for long domain names in
    origin (AFL fuzzer)
  - Out-of-bound read in packet parser for TSIG RR without RDATA
    (AFL fuzzer)
  - Out-of-bound read in packet parser for malformed NAPTR RR (AFL
  - CDS and CDNSKEY support in zone parser
  - Add defaults for TCP config options into documentation
  - Detailed error message if zone reload fails
- refreshed patches to apply cleanly again:
* Tue Mar 10 2015
- update to 1.6.2
  - Limiting number of parallel TCP clients (max-tcp-clients config
  - Ignore refresh and transfer events on non-slave zones
  - Compilation with Dnstap support on FreeBSD
  - Possible file descriptor leak when terminating inactive TCP
- refreshed patches to apply cleanly again:
- moved autoreconf -fi to %build so it wont be tried in quilt setup
  or similar tools
- move up the %if case for systemd in for the preun scriptlet to
  avoid warning about empty scripts on non systemd distributions.
- used xz tarball: new buildrequires xz
* Thu Jan 08 2015
- Add deps on the docu packages to regen documentation
- Enable systemd integration fully
- Add dep on libidn
- Cleanup with spec-cleaner
* Wed Dec 31 2014
- Only require lmdb-devel on (Open)SUSE 13.2 and higher
* Wed Dec 31 2014
- Updated to 1.6.1
  - Journal file would sometimes outgrow its set limit
  - Fixed incompatibility with OpenSSL 0.9.8
  - Proper handling when machine hostname cannot be retreived
  - Support for DNSSEC Single Type Signing Scheme
- Compile with lmdb-devel to add support for persistent timers
* Tue Nov 18 2014
- Updated to 1.6.0
  - Fix zone expiration when AXFR/IXFR is being refused by master
  - Fix forced zone refresh on slave (knotc refresh -f)
  - Persistent timers database opening after privileges has been dropped
  - DNSSEC: RFC compliant processing of letter case in RDATA domain names
  - EDNS: Return minimal error response for queries with unsupported version
  - EDNS: Fix interpretation of Extended RCODE
  - Maximal size of persistent timers database increased from 10 MB to 100 MB
  - Added logging of persistent timers database errors
  - Persistent timers for slave zones (expire, refresh, and flush)
* Mon Sep 15 2014
- Updated to 1.5.3
  - Some specific incoming IXFRs were causing server to crash
  - Rare sychronization error during reload caused read-after-free
  - Response synthetization module did not work properly with DNSSEC-enabled zones
  - When Knot sent AXFR when IXFR was requested, message ID and opcode were wrong
  - Knot failed to send large messages to remote control (present since 1.5.1)
  - Some RR parsing corner cases were not handled properly
  - AXFR-style IXFR was refused and had to be retransfered
  - Hash character (#) was not properly escaped when storing text zone file
  - DNSSEC: DNAMEs in RDATA were not lowercased before signing
  - EDNS: OPT RR were not put into responsing for some errors
  - TSIG: DDNS responses were not signed with TSIG
  - DDNS: Prerequisite checks failed for some inputs
  - knsupdate: Zone origin was not used for deletions
  - Basic support for logging using systemd journal
  - DDNS: Ability to process updates in bulk
  - Unified logging messages structure
  - DNSSEC: More strict controls for signing keys
- Refreshed patches on top of 1.5.3 release:
  * 0001-loosen-openssl-dependency.patch
* Fri Jul 11 2014
- Squash 0002-remove-AM_SILENT_RULES.patch and 0003-no-dist-xz.patch
  into that
  removes options incompatible with SLES_11_SP[23].
- added patches:
- removed patches:
  * 0002-remove-AM_SILENT_RULES.patch
  * 0003-no-dist-xz.patch
* Thu Jul 10 2014
- Updated to 1.5.0
  * DDNS forwarding reimplemented
  * edns-client-subnet support in kdig
  * Optional asynchronous startup (config "asynchronous-start")
  * Pluggable query processing modules
  * Synthetic IPv4/IPv6 reverse/forward records (optional module)
  * dnstap support in both utilities & server (optional module)
  * NOTIFY message support and new TSIG section in kdig
  * Multi-master support
  * Transfer sizes logged in bytes if needed
  * Logging outgoing NOTIFY messages
  * Logging unauthorized incoming NOTIFYs
  * Preempt task queue for faster reload
  * Lazy zone file write after zone transfer (governed by "zonefile-sync")
  * Query processing and core functionality overhaul
  * Performance and reduced memory footprint
  * Faster zone events scheduling
  * RFC compliant queries/responses in some corner cases
  * Log messages
  * New documentation (Sphinx)
  * Zone flush planning after bootstrap
  * Incorrect incoming AXFR message sizes
  * DDNS signing changes were freed too soon, posibility of stale data
  * knotc remote control key handling
  * Close zone transfer after SERVFAIL response
  * Incremental to full zone transfer fallback, wrong log message
  * Zone events corner cases, reload replanning
* Tue Jun 24 2014
- updated to 1.4.7:
  * Fixed DDNS corner cases
  * Fixed zone EXPIRE timer
  * Fixed semantic checks false positives
  * Fixed sending malformed IXFR with automatic DNSSEC
  * Fixed NAPTR record serialization