[RPKI] Krill 0.10.1 'Slash' Released

Tim Bruijnzeels tim at nlnetlabs.nl
Thu Sep 8 12:02:16 UTC 2022


Dear list,

We just released Krill 0.10.1 'Slash'.

This bugfix release ensures that XML files used in the set up of a CA,
which were generated by pre 0.10.0 Krill versions can be used again. For
more background see issue: https://github.com/NLnetLabs/krill/issues/922

Other than that this release introduces no changes. For convenience we
will repeat the release notes here. The Krill 0.10.x series introduces
the following major features:

- BGPSec Router Certificate Signing
- Support the use of Hardware Security Modules (HSMs) for key operations

The following documentation sections have more information:

API changes: https://krill.docs.nlnetlabs.nl/en/stable/upgrade.html#v0-10-0
BGPSec: https://krill.docs.nlnetlabs.nl/en/stable/cli.html#krillc-bgpsec
HSM support: https://krill.docs.nlnetlabs.nl/en/stable/hsm.html

Besides these major features we added a number of small improvements and
bugfixes:
- CRL revocation dates in the future #788
- Prevent that two krill instances modify the same data #829
- Let user force RRDP session reset on restore #828
- Various code improvements aimed at maintainability
- Using a jitter of 0 results in a panic #859
- Security fixes in KMIP dependencies #860 (HSM support)
- Add SSLKEYLOGFILE support #615
- Allow explicit disabling of HTTPS #913

The full list of changes can be found here:
https://github.com/NLnetLabs/krill/projects/19

On behalf of the NLnet Labs RPKI Team,

Tim


More information about the RPKI mailing list