Commit Graph
2166 Commits
Author SHA1 Message Date
Martin Hoffmann 04e37f5a75 Update changelog. 2026-02-19 16:06:14 +01:00
Martin HoffmannandGitHub 94b5c461eb Release 0.16.0-rc1. (#1360)
Breaking changes

* Reverted the use of Roto API for the ROA analysis to downloading
  RISwhois route origin data and optimized the way this data is stored in
  memory.

  Removed the `bgp_api_enabled`, `bgp_api_uri`, and `bgp_api_cache_duration`
  fields and added `bgp_riswhois_enabled`, `bgp_riswhois_v4_uri`,
  `bgp_riswhois_v6_uri`, and `bgp_riswhois_refresh_duration` fields, all of
  which are optional. ([#1329]
* Krill will now refuse to start if the config file contains unknown
  options. ([#1322])

New

* A local `krillc` can now talk to the server via a Unix socket. In this
  case it will use the name of the local user for authentication purposes.
  By default, only the `root` user is allowed with the `admin` role, but
  both allowed users and what role they are mapped to can be configure.
  ([#1322])
* Added a `krillc parents refresh` command to allow refreshing the parents
  of a single CA rather than having to do a bulk refresh which can take a
  very long time if there are many CAs. ([#1353])

Bug fixes

* Fixed an issue  with the new BGP API code which false returns missing
  announcement info. ([#1326])
* Fixed an issue where deleting children or parents of a CA fails before a
  successful communication with the remote CA. ([#1331])
* Fixed an error message when trying to delete a CA which does not
  have any parents, children, or repositories despite actually removing
  the CA. ([#1331])
* Start sweeping the authenticator cache upon daemon startup. This merely
  reduces memory consumption of the cache. Expired authentication tokens
  were not used either way. ([#1337])
* Fixed a bug introduced in 0.15.0 where CAs do to not clear fulfilled
  certification requests causing them to re-request a certificate every
  time they contact their parent. ([#1345])
* Do not re-try syncing with a parent of a CA when that parent isn’t
  known. ([#1349])
* Fixed un-suspending child CAs: rather then re-publishing the previously
  revoked certificate, a new certificate is now issued. ([#1341])

Other changes

* The default config files don’t serve as config documentation any more.
  Rather, there is now a `krill.conf.5` manual page. This manual page is
  also included in the Krill manual. ([#1322])
* The cryptography library used by the rustls TLS implementation has been
  switched to aws-lc-rs. This has some consequences for packaging:
* Dropped packaging for Ubuntu 20.04 (Focal Fossa). ([#1359])
v0.16.0-rc1
2026-02-19 15:56:39 +01:00
Martin Hoffmann a7eaa34e00 Update changelog. 2026-02-19 15:16:44 +01:00
Martin HoffmannandGitHub faf769f691 Drop packaging for Ubuntu focal. (#1359) 2026-02-19 15:14:55 +01:00
Martin Hoffmann cf91bd65b4 Merge branch 'main' of github.com:NLnetLabs/krill 2026-02-19 11:43:37 +01:00
Martin Hoffmann d0534c03b1 Update changelog. 2026-02-19 11:43:22 +01:00
Alex BandandGitHub 62b0d7e220 Link to community forum 2026-02-17 20:55:08 +01:00
Martin HoffmannandGitHub d5ddaa221c Upgrade MSRV to 1.88 and upgrade dependencies. (#1358) 2026-02-17 15:13:54 +01:00
Martin HoffmannandGitHub 71cda3ad7c Upgrade rpki-rs to 0.19.2. (#1357)
This needs some changes as rpki-rs 0.19.2 mandated the use of signing
time and removed the use of binary signing time from RPKI certificates.
Krill did this already, anyway, so there are no functional changes, just
adjustments to changed APIs.
2026-02-17 11:34:51 +01:00
Martin HoffmannandGitHub 60347788be Upgrade rand to 0.10. (#1356) 2026-02-17 11:11:34 +01:00
Martin HoffmannandGitHub 893d52dab3 Upgrade cryptoki to 0.12. (#1355) 2026-02-16 17:17:12 +01:00
Martin Hoffmann f4d9cc5dbc Update changelog. 2026-02-16 16:06:21 +01:00
Martin Hoffmann 9de8d6cb3d Update changelog. 2026-02-13 14:59:56 +01:00
Koen van HoveandGitHub d8b135207f Add krillc parents refresh command (#1353) 2026-02-13 14:58:24 +01:00
Evann DREUMONTandGitHub 65aeec1e0f Improve TA documentation (#1350)
- minors commands typos
- add hint for space coverage

Signed-off-by: Evann DREUMONT <evann@grifon.fr>
2026-02-06 12:32:55 +01:00
Martin Hoffmann 754f09eb65 Update changelog. 2026-01-30 16:07:24 +01:00
Koen van HoveandGitHub 821c05a48d Reissue child certificate after suspension (#1341)
This PR fixes an issue a CA is unsuspending a child CA. Rather then
re-publishing the previously revoked certificate, a all new certificate is
now issued.
2026-01-30 16:05:41 +01:00
Koen van HoveandGitHub 822ff1f78b Do not reschedule parent sync task if parent is unknown. (#1349) 2026-01-30 15:23:06 +01:00
Martin Hoffmann 07b0fc2955 Update changelog. 2026-01-19 16:10:49 +01:00
Martin HoffmannandGitHub 043655766c Clear cert issuance request when receiving a new cert. (#1344)
This PR fixes a bug introduced in 0.15.0 where CAs do to not clear
fulfilled certification requests causing them to re-request a
certificate every time they contact their parent.
2026-01-19 16:09:41 +01:00
Martin HoffmannandGitHub 1ca1635a91 Remove unused src/server/bgp/rotoapi.rs (#1342) 2026-01-13 10:14:23 +01:00
Koen 4f2a8fcffe Update CONTRIBUTING 2026-01-08 15:04:28 +01:00
Martin Hoffmann b271ca2dd0 Update changelog. 2026-01-06 14:33:38 +01:00
Koen van HoveandGitHub 0ccc5cdff4 Add support for UNIX sockets (#1322)
This PR adds API access via a local Unix socket on Unix systems allowing to
use the username of local user accessing the API as the authentication
username.

Configuration options are provided to map user names to roles similar to the
configfile authentication provider.

This will allow using Krill without authentication tokens if it is only
accessed via krillc on the same machine.

The PR also removes the example configuration files and moves the
documentation included in those files into a krill.conf.5 manual page. By
doing this, it simplifies the creation of the configuation file in the binary
packages. Those are now very minimal and only contain the mandatory config
options.
2026-01-06 14:27:31 +01:00
Alex BandandGitHub a5e19935b2 Add Discourse badge 2026-01-06 08:22:29 +01:00
LaunchPadandGitHub f75c9654b1 Fix TreeIter::more_specific to correctly handle IPv6 subprefixes (#1339) 2026-01-05 17:59:51 +01:00
Martin Hoffmann 5ea098f9d4 Update changelog. 2025-12-02 14:16:55 +01:00
Martin HoffmannandGitHub 8bd1ed3c77 Spawn sweeping of credentials cache. (#1337)
This PR spawns the sweeping of the credentials cache for the authenticator.
Somehow we missed this when rewiring authentication handling.
2025-12-02 14:13:08 +01:00
Koen van HoveandGitHub 206f308b3d Update openidconnect to v4 (#1333) 2025-11-24 12:01:16 +01:00
Martin Hoffmann 40c73f7206 Update changelog. 2025-11-17 17:57:31 +01:00
Martin HoffmannandGitHub dd5c7dcb1d Bring back the built-in RISwhois tree for BGP analysis. (#1329)
This PR brings back the built-in tree of downloaded RISwhois data rather
than using the Roto API. It does so using a memory-optimized tree
implementation and has a much smaller memory footprint than the previous
iteration. At the time of writing, the a full RISwhois dataset requires 55
megabytes of memory.

This PR also reverts the changes to the configuration. It removes the
bgp_api_enabled, bgp_api_uri, and bgp_api_cache_duration fields and adds
bgp_riswhois_enabled, bgp_riswhois_v4_uri, bgp_riswhois_v6_uri, and
bgp_riswhois_refresh_duration fields, all of which are optional.

Because of these config changes, the PR is a breaking change.
2025-11-17 17:54:27 +01:00
Martin Hoffmann 38205078c8 Update changelog. 2025-10-27 16:44:28 +01:00
Koen van HoveandGitHub a776e79abd Fix removing children/parents/CAs with incomplete handshake (#1331)
This PR fixes an issue where removing children or parents from CAs fails
before a successful communication with the remote CA. It also fixes an error
message when CAs without parent, children, and repository are removed.
2025-10-27 16:42:13 +01:00
Koen van HoveandGitHub 836d7fa6c5 Update Ploutos to v9 (#1332) 2025-10-20 18:43:14 +02:00
Martin Hoffmann b32b05c8a1 Update changelog. 2025-10-10 16:18:57 +02:00
Koen van HoveandGitHub ce166d1757 Be more flexible on relations existing in the bgp-api JSON (#1326)
This PR resolves an issue with the new BGP API code which returns no
announcement info even though there is announcement info (but it is
available, but there is no information about its relations).
2025-10-10 16:17:31 +02:00
Martin HoffmannandGitHub 66fe52fedb Simplify storage keys. (#1325)
This PR simplifies the structure of the keys used by the key-value store.
It changes the scope portion from being a sequence of identifiers to an
optional single identifier since the sequence is actually never used. As a
consequence, namespace, scope, and key now all use the same type, the newly
introduced Ident.
2025-10-10 16:14:43 +02:00
Alex BandandGitHub c7eeaae6db Update Mastodon shield 2025-09-25 21:41:14 +02:00
Koen van HoveandGitHub be490b75a2 Fix Clippy not found in CI error (#1323) 2025-09-25 14:01:09 +02:00
Martin HoffmannandGitHub 01bf280229 Code improvements suggested by Clippy 1.90. (#1321) 2025-09-19 12:10:42 +02:00
Koen van HoveandGitHub 986b82e137 Update dependencies (#1317) 2025-08-27 15:37:27 +02:00
Martin Hoffmann 0b5f3d9af7 Bump version. 2025-08-12 13:46:52 +02:00
Martin HoffmannandGitHub c9dedb1610 Release 0.15.0 ‘But I Disgress.’ (#1316)
Breaking Changes

* Refactored command line options processing for all binaries. As a
  result, options for both `krillc` and `krillta` have slightly changed.
  For `krillc`, the `--server`, `--token`, `--format`, and `--api` options
  are now before the first subcommand (since they affect all commands). For
  `krillta`, those options are now after `krillta proxy` but before the next
  subcommand, while `--format` is now after `krillta signer`. ([#1228])
* Removed support for RTA in `krillc`. Support is currently still
  present in the Krill server, though behind a (non-default) feature flag.
  ([#1228])
* Changed how authorization works with OpenID Connect and configuration
  files. Custom profiles have been replaced with a straightforward mapping
  from access permission to roles and assigning roles to users. For
  configuration file-based authentication, the file format has slightly
  changed but the current format is still accepted. If you are using
  OpenID Connect, you will have to update your configuration. Please, see
  the manual for details. ([#1232])
* Replaced downloading of RISwhois file for ROA analysis with calls to the
  [Roto API](https://github.com/NLnetLabs/roto-api). This can be
  controlled via new configuration settings `bgp_api_enabled`,
  `bgp_api_uri`, and `bgp_api_cache_seconds`. ([#1233], [#1266])

New

* Added a command to re-initialize the trust anchor signer with different
  timing values or TAL URLs. ([#1255])
* Disables the protection against early re-issuance for CA certificates that
  have the full resource set, typically TA certificates. ([#1281])

Bug Fixes

* Fixed a potential infinite recursion in PKCS11 error handling. ([#1215])
* Open ID connect: Re-initialize the connection after 60s to pick up
  configuration changes at the provider. ([#1226])
* Fixed the naming of the trust anchor timing configuration. It was
  expected to be `timing_config` for the config used by Krill and
  `ta_timing` if used by the Krill TA signer. It is now `ta_timing` in
  both cases while `timing_config` is accepted as an alias in both cases.
  ([#1241])
* Improve performance by using buffered reading and writing in the store.
  ([#1300], [#1301])

Other changes

* Refactored Prometheus metrics generation which resulted in a slightly
  different formatting but should still be syntactically correct.
  ([#1249])
* Upgraded the bundled Krill UI to
  [release 0.9.0](https://github.com/NLnetLabs/krill-ui/releases/tag/v0.9.0).
  ([#1295])
* Added packaging support for Ubuntu Noble, RHEL 10, Debian Trixie; removed
  packaging support for Ubuntu Xenial and Bionic, and Debian Stretch.
  ([#1239], [#1297], [#1308])
* The minimum supported Rust version is now 1.85. ([#1288])
v0.15.0
2025-08-12 13:40:16 +02:00
Martin Hoffmann 1cd18451d7 Bump version. 2025-08-11 15:05:38 +02:00
Martin HoffmannandGitHub 517f6255b4 Release 0.15.0-rc6. (#1314)
This RC was only made to properly test upgrading Debian packages. It does
not include any functional changes.

Other changes

* Do not include systemd unit files in krillta and krillup deb packages.
  ([#1313])
v0.15.0-rc6
2025-08-11 15:03:21 +02:00
Martin HoffmannandGitHub a87ced05ab Fix hidden lifetime warnings from Rust 1.89. (#1315)
This PR fixes the “hiding a lifetime that's elided elsewhere is confusing”
warning introduced in Rust 1.89.
2025-08-11 14:29:01 +02:00
Koen van HoveandGitHub 321d384a54 Do not include systemd unit files in krillta and krillup (#1313)
This PR prevents older versions of deb packages from including systemd-unit
files.

Because of the way Krill is set up, this requires both Ubuntu 20.04 and
Debian 11 to have usrmerge (which both have by default, only if upgraded
from an older version it might be missing).
2025-08-11 13:55:32 +02:00
Martin Hoffmann 26dabddea5 Bump version. 2025-08-05 10:41:57 +02:00
Martin HoffmannandGitHub 4559e5a478 Release 0.15.0-rc5. (#1312)
Bug fixes

* Improved the message printed when the TA proxy’s signer request does not
  contain any actual requests. ([#1305])
* Fixed various migration issues. ([#1306], [#1307], [#1309])

Other changes

* Add packaging for Debian 13. ([#1308])
* Updated dependencies. ([#1311])
v0.15.0-rc5
2025-08-05 10:36:20 +02:00
Martin HoffmannandGitHub 594b6bb981 Update dependencies. (#1311) 2025-08-05 10:13:39 +02:00