This PR brings back the built-in tree of downloaded RISwhois data rather
than using the Roto API. It does so using a memory-optimized tree
implementation and has a much smaller memory footprint than the previous
iteration. At the time of writing, the a full RISwhois dataset requires 55
megabytes of memory.
This PR also reverts the changes to the configuration. It removes the
bgp_api_enabled, bgp_api_uri, and bgp_api_cache_duration fields and adds
bgp_riswhois_enabled, bgp_riswhois_v4_uri, bgp_riswhois_v6_uri, and
bgp_riswhois_refresh_duration fields, all of which are optional.
Because of these config changes, the PR is a breaking change.
This PR fixes an issue where removing children or parents from CAs fails
before a successful communication with the remote CA. It also fixes an error
message when CAs without parent, children, and repository are removed.
This PR resolves an issue with the new BGP API code which returns no
announcement info even though there is announcement info (but it is
available, but there is no information about its relations).
This PR simplifies the structure of the keys used by the key-value store.
It changes the scope portion from being a sequence of identifiers to an
optional single identifier since the sequence is actually never used. As a
consequence, namespace, scope, and key now all use the same type, the newly
introduced Ident.
Breaking Changes
* Refactored command line options processing for all binaries. As a
result, options for both `krillc` and `krillta` have slightly changed.
For `krillc`, the `--server`, `--token`, `--format`, and `--api` options
are now before the first subcommand (since they affect all commands). For
`krillta`, those options are now after `krillta proxy` but before the next
subcommand, while `--format` is now after `krillta signer`. ([#1228])
* Removed support for RTA in `krillc`. Support is currently still
present in the Krill server, though behind a (non-default) feature flag.
([#1228])
* Changed how authorization works with OpenID Connect and configuration
files. Custom profiles have been replaced with a straightforward mapping
from access permission to roles and assigning roles to users. For
configuration file-based authentication, the file format has slightly
changed but the current format is still accepted. If you are using
OpenID Connect, you will have to update your configuration. Please, see
the manual for details. ([#1232])
* Replaced downloading of RISwhois file for ROA analysis with calls to the
[Roto API](https://github.com/NLnetLabs/roto-api). This can be
controlled via new configuration settings `bgp_api_enabled`,
`bgp_api_uri`, and `bgp_api_cache_seconds`. ([#1233], [#1266])
New
* Added a command to re-initialize the trust anchor signer with different
timing values or TAL URLs. ([#1255])
* Disables the protection against early re-issuance for CA certificates that
have the full resource set, typically TA certificates. ([#1281])
Bug Fixes
* Fixed a potential infinite recursion in PKCS11 error handling. ([#1215])
* Open ID connect: Re-initialize the connection after 60s to pick up
configuration changes at the provider. ([#1226])
* Fixed the naming of the trust anchor timing configuration. It was
expected to be `timing_config` for the config used by Krill and
`ta_timing` if used by the Krill TA signer. It is now `ta_timing` in
both cases while `timing_config` is accepted as an alias in both cases.
([#1241])
* Improve performance by using buffered reading and writing in the store.
([#1300], [#1301])
Other changes
* Refactored Prometheus metrics generation which resulted in a slightly
different formatting but should still be syntactically correct.
([#1249])
* Upgraded the bundled Krill UI to
[release 0.9.0](https://github.com/NLnetLabs/krill-ui/releases/tag/v0.9.0).
([#1295])
* Added packaging support for Ubuntu Noble, RHEL 10, Debian Trixie; removed
packaging support for Ubuntu Xenial and Bionic, and Debian Stretch.
([#1239], [#1297], [#1308])
* The minimum supported Rust version is now 1.85. ([#1288])
This RC was only made to properly test upgrading Debian packages. It does
not include any functional changes.
Other changes
* Do not include systemd unit files in krillta and krillup deb packages.
([#1313])
This PR prevents older versions of deb packages from including systemd-unit
files.
Because of the way Krill is set up, this requires both Ubuntu 20.04 and
Debian 11 to have usrmerge (which both have by default, only if upgraded
from an older version it might be missing).
Bug fixes
* Improved the message printed when the TA proxy’s signer request does not
contain any actual requests. ([#1305])
* Fixed various migration issues. ([#1306], [#1307], [#1309])
Other changes
* Add packaging for Debian 13. ([#1308])
* Updated dependencies. ([#1311])
This PR adds a step to the start of the Krill daemon that initializes the
property store with the current version if it hasn’t been initialized
earlier. It also assumes that an uninitialized property store with no
per-store version information indicates that the data is from version 0.14.0
and migrates the stores lock directories accordingly.
This PR changes the function that collects all scopes for a given store to
not include the global scope. This restores the behaviour of kvx.
As a side effect, it changes the store testing code to run on both backends.
This PR skips any scope with .locks as its first segment when upgrading
any stores. This is an artifact of moving the lock directory from the top
level of each store to the top level of the storage space.