CARVIEW |
Select Language
HTTP/2 200
date: Mon, 14 Jul 2025 04:39:55 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"96c88263e7a5dbd5c01d3bb643890620"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: no-referrer-when-downgrade
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=00JeU6Ec2GsLnQg7vVnnC47mUcz7gSuLs3pjeWYD%2Bjy8tK0eou45x6vWO8wK12ogbYz%2FpBnlNFQDqnDtfr0OxX92ZZ%2Fduu2%2BVk1EzzdU42jPwKdDfTzTmQw92oAleqfrxfm2GHWzJMen0KjHCa1VjR2iEF%2Be6KQ7KoG0CqS%2FlMImCgMTY%2Fc2xzpV46KEr8iQc6UTL0F6v9K8nwbhRj4MMwpg7vssM4xZvmyiicjWr1hhK2YeS9ePc5RzwxKmo9jaXlrrWJ1V3wnBHMV0r0z%2FdQ%3D%3D--krmcnAgTpOoj2%2FqP--sw3fbBWK9%2FyQWG8TjEliuQ%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.110569018.1752467994; Path=/; Domain=github.com; Expires=Tue, 14 Jul 2026 04:39:54 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Tue, 14 Jul 2026 04:39:54 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: A772:2731C0:A1193E:D91393:68748A1A
Releases · NLnetLabs/krill · GitHub
26 Jun 12:00
Loading
18 Jun 10:48
Loading
13 Jun 14:33
Loading
13 Jun 12:37
Loading
08 Apr 13:12
Loading
26 Mar 16:34
Loading
27 Jun 14:44
Loading
27 Jun 13:47
Loading
21 Jun 11:39
Loading
Skip to content
Navigation Menu
{{ message }}
-
-
Notifications
You must be signed in to change notification settings - Fork 44
Releases: NLnetLabs/krill
Releases · NLnetLabs/krill
0.15.0-rc4
5a6ea66
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Assets 2
0.15.0-rc3
f18ff6c
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Other changes
- Upgraded the bundled Krill UI to release 0.9.0. (#1295)
- Added packaging support for RHEL 10-alikes. (#1297)
Assets 2
0.15.0-rc2
Compare
Assets 2
0.15.0-rc1
ee7e60a
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Breaking Changes
- Refactored command line options processing for all binaries. As a result, options for both
krillc
andkrillta
have slightly changed. Forkrillc
, the--server
,--token
,--format
, and--api
options are now before the first subcommand (since they affect all commands). Forkrillta
, those options are now afterkrillta proxy
but before the next subcommand, while--format
is now afterkrillta signer
. (#1228) - Removed support for RTA in
krillc
. Support is currently still present in the Krill server, though behind a (non-default) feature flag. (#1228) - Changed how authorization works with OpenID Connect and configuration files. Custom profiles have been replaced with a straightforward mapping from access permission to roles and assigning roles to users. For configuration file-based authentication, the file format has slightly changed but the current format is still accepted. If you are using OpenID Connect, you will have to update your configuration. Please, see the manual for details. (#1232)
- Replaced downloading of RISwhois file for ROA analysis with calls to the Roto API. This can be controlled via new configuration settings
bgp_api_enabled
,bgp_api_uri
, andbgp_api_cache_seconds
. (#1233, #1266)
New
- Added a command to re-initialize the trust anchor signer with different timing values or TAL URLs. (#1255)
- Disables the protection against early re-issuance for CA certificates that have the full resource set, typically TA certificates. (#1281)
Bug Fixes
- Fixed a potential infinite recursion in PKCS11 error handling. (#1215)
- Open ID connect: Re-initialize the connection after 60s to pick up configuration changes at the provider. (#1226)
- Fixed the naming of the trust anchor timing configuration. It was expected to be
timing_config
for the config used by Krill andta_timing
if used by the Krill TA signer. It is nowta_timing
in both cases whiletiming_config
is accepted as an alias in both cases. (#1241)
Other changes
- Refactored Prometheus metrics generation which resulted in a slightly different formatting but should still be syntactically correct. (#1249)
- Added packaging support for Ubuntu Noble; removed packaging support for Ubuntu Xenial and Bionic, and Debian Stretch. (#1239)
- The minimum supported Rust version is now 1.85. (#1288)
Assets 2
0.14.7-rc1
0.14.6 ‘Roll Initiative!’
1b42215
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Bug fixes
- Fixed the naming of the trust anchor timing configuration. It was
expected to betiming_config
for the config used by Krill and
ta_timing
if used by the Krill TA signer. It is nowta_timing
in
both cases whiletiming_config
is accepted as an alias in both cases.
(#1242)
Other changes
- The minimum supported Rust version is now 1.81. (#1260)
Assets 2
0.14.6-rc1
d32d32c
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Bug fixes
- Fixed the naming of the trust anchor timing configuration. It was expected to be
timing_config
for the config used by Krill andta_timing
if used by the Krill TA signer. It is nowta_timing
in both cases whiletiming_config
is accepted as an alias in both cases. (#1242)
Other changes
- The minimum supported Rust version is now 1.81. (#1260)
Assets 2
0.14.5 ‘Who dis? New Phone’
f1340b1
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
New
- Allow overriding the initial manifest number when initializing the TA signer, either by specifying
--initial_manifest_number
in the CLI or by includingta_mft_nr_override: #nr
in theImportTa
JSON. (#1178) - Allow overriding the TA manifest number when signing a TA proxy request by specifying
--ta_mft_number_override
in the CLI. (#1178)
Bug fixes
- Prevent empty RRDP delta lists to be produced. (#1181)
- Correctly encode empty revocation lists in CRLs. (via rpki-rs#295)
- Allow read access to the RIS dump while downloading a new dump. (#1179)
- Don’t apply “child revoke key” command if the resource class does not exist. (#1208)
Other changes
- The minimum supported Rust version is now 1.70.0. (#1198)
Assets 2
0.13.2 ’Be kind, rewind’
523a567
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Bug fixes
- Updated the locked version of the h2 crate to 0.3.26 to fix RUSTSEC-2024-0332. (#1206)
- Don’t apply “child revoke key” command if the resource class does not exist. (#1207)
Assets 2
0.14.5-rc1
c9c8438
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
New
- Allow overriding the initial manifest number when initializing the TA
signer, either by specifying--initial_manifest_number
in the CLI or by
includingta_mft_nr_override: #nr
in theImportTa
JSON. (#1178) - Allow overriding the TA manifest number when signing a TA proxy request by
specifying--ta_mft_number_override
in the CLI. (#1178)
Bug fixes
- Prevent empty RRDP delta lists to be produced. (#1181)
- Correctly encode empty revocation lists in CRLs. (via rpki-rs#295)
- Allow read access to the RIS dump while downloading a new dump.
(#1179) - Don’t apply “child revoke key” command if the resource class does not
exist. (#1208)
Other changes
- The minimum supported Rust version is now 1.70.0. (#1198)
Assets 2
Previous Next
You can’t perform that action at this time.