NLnet Labs
Dutch #NonProfit foundation proudly serving the Internet community since 1999 with #OpenSource software for #DNS and #BGP. Applied research, open standards advocates, bridging technology and policy.
#Clang origins, now #rustlang aficionados. The people behind Unbound, NSD, Routinator, Cascade and much more...
Note: We are not @nlnet@social.nlnet.nl, nor are we funded by them or affiliated with them. Lots of 💚 for what they do though!
Back in May 2019, we said goodbye to SVN and Bugzilla and migrated to Git and GitHub [1]. Since then, we accumulated 188 repositories. 🙀
We're now making a list to decide which ones we're moving to @Codeberg@social.anoxinon.de and which are going to be archived and left behind.
While we're doing that, we signed NLnet Labs up as a Codeberg e.V. member!
[1] https://lists.nlnetlabs.nl/pipermail/unbound-users/2019-April/006130.html
To his complete surprise, our colleague Jaap Akkerhuis was awarded Knight of the Order of the Dutch Lion earlier today for Exceptional Contribution to Society. Akkerhuis is a Dutch Internet pioneer, protocol designer and expert on the internet's naming system.
More at https://blog.nlnetlabs.nl/dutch-internet-pioneer-jaap-akkerhuis-knighted-for-exceptional-contribution-to-society/ #internet #dns
In case you’re wondering: while not as extreme as illustrated by ISC (we don’t offer a bug bounty program), NLnet Labs suffers from a similar situation, in particular for Unbound.
Handling vulnerability reports, both valid ones and false positives, has now become a full time job for the entire Unbound team.
You can argue that it ultimately makes our resolver more secure, it also means we cannot work on building and releasing new features, like:
With memory prices skyrocketing we're happy to bring you some good news on the #DNS front.
In version 4.14.0 of our authoritative nameserver NSD we vastly reduced the memory footprint by refactoring the RDATA storage, with gains up to 50%.
Overall, relatively large #DNSSEC-signed zones like .nl and .se benefit the most, but being able to bring the memory requirements to serve .com below 64GB is pretty awesome too.
We're eager to hear the improvements you're seeing!
We released Unbound 1.25.1 just seven days ago and now look at the changelog today. ❤️🩹🔥
https://github.com/NLnetLabs/unbound/blob/master/doc/Changelog
Please pray to the live demo Gods over lunch so @ximon18@fosstodon.org can show you our #DNSSEC signer Cascade in action this afternoon at @dnsoarc@mastodns.net 46.
We’ll cover incremental signing with IXFR in and out with TSIG, all on a YubiHSM we packed. 🤞
For our #Rust projects, we created a bespoke #OpenSource pipeline to build and publish binary packages for the last three major versions of Debian, Ubuntu, RHEL and derivatives.
Ploutos is now almost four years old, and the way #rustlang packaging is done for these OSes has evolved quite a bit. The pipeline is also closely built around GitHub Actions, and now that we're moving to @Codeberg@social.anoxinon.de we need to overhaul it anyway.
Any tips or experiences from the Rust community?
We're thrilled that Cascade is among the first projects supported by the Nominet DNS Fund.
With Nominet's support, our new DNSSEC signing solution receives a massive push forward, allowing our team to focus on implementing speed improvements, a reduced memory footprint and essentials such as incremental signing.
We'll be launching a beta in April, followed by an initial production release in June 2026.
Each of us is a non-profit. Each of us employ EU citizens as #foss maintainers. And each of us do long-term maintenance and development on independent #opensource implementation for DNS, routing and other foundational network protocols. So we thought we’d once again team up for a submission.
Today we joined the discussion with @Nominet@mastodon.social DNS Fund on funding Open Source Software during the #RIPE92 Open Source WG session.
Amy and Dave presented the DNS Fund programme, after which four recipients (including us) shared experiences. We highlighted our very positive experience supporting our Cascade project, a stand-alone DNSSEC signer and key manager.
Slides & recording:
https://ripe92.ripe.net/programme/meeting-plan/sessions/85/GLDW8A/
“If our DNSSEC expert leaves, we’d have no idea how to keep it running.”
When continuity depends on one person, that isn’t resilience — it’s fragility.
We interviewed sixteen TLDs about DNSSEC operations. Stay tuned to learn what keeps them up at night. Full report drops Tuesday, September 9.
Our Winter newsletter is out! It's full of updates on Cascade, news on our community forum, migrating to Codeberg, presentations we've given and more!
#FOSS #FOSDEM #OpenSource #DigitalSovereignty #DNS #DNSSEC #rustlang
Unbound 1.25.0 was released a week ago, and contained fixes for 32 security related reports.
We are diligently working towards the next release, and as of today, the Unbound team is currently triaging 22 reports – and counting – from security researchers employing LLMs.
Will this settle down, or continue to grow as LLMs evolve?
We've released Rotonda 0.5.2, our BMP/BGP route collector, bringing back the web UI in totally revamped fashion. It's still simplistic, by design, but now offers a lot more insight in both the actual routes as well as session information.
As the UI is still evolving, we are gathering feedback. please chime in with anything that comes to mind:
https://community.nlnetlabs.nl/t/web-ui-feedback-ideas/85
https://github.com/NLnetLabs/rotonda/releases/tag/v0.5.2
#BGP #BMP #RustLang
Thanks to the @Nominet@mastodon.social DNS Fund, we have been able to dedicate a team of five developers on building Cascade, our new #OpenSource #DNSSEC signing solution.
Leading up a first production release in June, @ximon18@fosstodon.org will be presenting on our progress at the @dnsoarc@mastodns.net 46 workshop in Edinburgh in May.
Highlights will include new incremental signing and IXFR-out, performance/resource usage improvements, TSIG support, metrics, migration tooling, and more...
We’ve released NSD 4.14.1 with more compact data storage for improved memory efficiency.
Check the release notes: https://www.nlnetlabs.nl/projects/nsd/download/
Willem also wrote a blog post explaining the approach and measurements showing the reduced memory footprint:
https://blog.nlnetlabs.nl/smaller-faster-nsds-refactored-rdata-storage-and-compile-time-memory-reduction-options/
Since launching Cascade early October, we’ve been pumping out alpha releases of our #DNSSEC signer at a fairly high velocity.
We're now at alpha5 and decided to slow down releases for the time being, while we're working on a lot of parallel tasks that a dependent on one another.
We'll resurface in a few weeks with some big steps forward! You can stay up to date with our progress here:
@jasper@mamot.fr and @drk are at the Euro-IX Route Server Workshop today. Jasper presented on our route collector Rotonda, which is nicely shaping up.
We're churning out features and improvements, not in the last place thanks to our collab with Fastnetmon.
We just published 0.16.0-RC1 of our #RPKI Certification Authority Krill, which reverts back to downloading the RISwhois data and processing it locally for analysing ROAs rather than using an external API.
In addition, there are quite a few fixes and improvements. For instance, there now is a man page for the config file, so you can now do man krill.conf for information about the config.
https://community.nlnetlabs.nl/t/krill-0-16-0-rc1-released/73/1
From an operator perspective, how would you like clustering of your #DNSSEC signing solution to work? #OpenSource #Community #DevOps
https://community.nlnetlabs.nl/t/some-thoughts-on-clustering/59
Krill 0.16.0 is now available.
This release of our #RPKI Certification Authority reverts back to downloading the RISwhois data and processing it locally for analysing ROAs rather than using an external API.
The Krill daemon will now also listen on a Unix socket which allows it to use the name of the local user for authentication, making it unnecessary to specify the authentication token when using krillc locally.
https://community.nlnetlabs.nl/t/krill-0-16-0-fruher-war-mehr-lametta-released/73
