NLnet Labs
nlnetlabs@social.nlnetlabs.nl
<p>Dutch <a href="https://social.nlnetlabs.nl/tags/NonProfit" class="mention hashtag" rel="tag">#<span>NonProfit</span></a> foundation proudly serving the Internet community since 1999 with <a href="https://social.nlnetlabs.nl/tags/OpenSource" class="mention hashtag" rel="tag">#<span>OpenSource</span></a> software for <a href="https://social.nlnetlabs.nl/tags/DNS" class="mention hashtag" rel="tag">#<span>DNS</span></a> and <a href="https://social.nlnetlabs.nl/tags/BGP" class="mention hashtag" rel="tag">#<span>BGP</span></a>. Applied research, open standards advocates, bridging technology and policy. </p><p><a href="https://social.nlnetlabs.nl/tags/Clang" class="mention hashtag" rel="tag">#<span>Clang</span></a> origins, now <a href="https://social.nlnetlabs.nl/tags/rustlang" class="mention
Posts
-
Post #3488936
We have been working incredibly hard on patching all of the LLM-assisted security reports for our authoritative #DNS server NSD. Today, we're happy to launch the NSD 4.15.0rc1 pre-release so you can test the 20+ fixes that are included. This release also improves the Prometheus metrics, as a nice bonus. https://community.nlnetlabs.nl/t/nsd-4-15-0rc1-pre-release/3421
-
Post #3422888
What we do ship this Friday, is a published policy on LLM use in the open source projects we maintain. We hope it’ll help potential contributors assess how to spend their time and ours in the most productive way. https://nlnetlabs.nl/llm-policy/
-
Post #2957510
Unbound 1.25.0 was released a week ago, and contained fixes for 32 security related reports. We are diligently working towards the next release, and as of today, the Unbound team is currently triaging 22 reports – and counting – from security researchers employing LLMs. Will this settle down, or continue to grow as LLMs evolve? #DNS #DNSSEC #LLM #Security
-
Post #2957509
Please pray to the live demo Gods over lunch so @ximon18 can show you our #DNSSEC signer Cascade in action this afternoon at @dnsoarc 46. We’ll cover incremental signing with IXFR in and out with TSIG, all on a YubiHSM we packed. 🤞 #LoveDNS
-
Post #2957508
After showing the progress of our #DNSSEC signing solution Cascade at DNS-OARC last weekend, this week we are at #RustWeek, supporting the developer community that makes our new software possible. #DNS #OpenSource #rustlang
-
Post #2957507
Today we joined the discussion with @Nominet DNS Fund on funding Open Source Software during the #RIPE92 Open Source WG session. Amy and Dave presented the DNS Fund programme, after which four recipients (including us) shared experiences. We highlighted our very positive experience supporting our Cascade project, a stand-alone DNSSEC signer and key manager. Slides &amp; recording: https://ripe92.ripe.net/programme/meeting-plan/sessions/85/GLDW8A/
-
Post #2957506
🚨 SECURITY RELEASE 🚨 Today we released Unbound 1.25.1, which consolidates security fixes for issues reported over a period of time. There are fixes for CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390 and CVE-2026-44608. Please read the release notes carefully and plan to upgrade. #DNS #DNSSEC #Mythos #LLM #OpenSource https://community.nlnetlabs.nl/t/unbound-1-25-1-released/3392
-
Post #2957505
We released Unbound 1.25.1 just seven days ago and now look at the changelog today. ❤️🩹🔥 https://github.com/NLnetLabs/unbound/blob/master/doc/Changelog #DNS #LLM #Mythos #OpenSource
-
Post #1897332
“If our DNSSEC expert leaves, we’d have no idea how to keep it running.” When continuity depends on one person, that isn’t resilience — it’s fragility. We interviewed sixteen TLDs about DNSSEC operations. Stay tuned to learn what keeps them up at night. Full report drops Tuesday, September 9. #DNSSEC #Resilience #Cascade #OpenSource
-
Post #1642157
To his complete surprise, our colleague Jaap Akkerhuis was awarded Knight of the Order of the Dutch Lion earlier today for Exceptional Contribution to Society. Akkerhuis is a Dutch Internet pioneer, protocol designer and expert on the internet&#39;s naming system. More at https://blog.nlnetlabs.nl/dutch-internet-pioneer-jaap-akkerhuis-knighted-for-exceptional-contribution-to-society/ #internet #dns
-
Post #1304381
After more than 20 years of service, we&#39;ve shut down our last Mailman mailing lists and fully transitioned to Discourse. This allows our community to continue using email to discuss our products, but also offer a web-based forum. Many thanks to Communiteq for their excellent hosting services, and cleanly importing the years of email archives into our new forum. This makes a wealth of collective knowledge available in searchable form. We welcome you to https://community.nlnetlabs.nl
-
Post #1304380
@holsta Like that time we literally flipped the script on unbound.net 😅 https://punoqun.net/ #DNS
-
Post #1298314
RE: https://fosstodon.org/@iscdotorg/116416426577631380 In case you’re wondering: while not as extreme as illustrated by ISC (we don’t offer a bug bounty program), NLnet Labs suffers from a similar situation, in particular for Unbound. Handling vulnerability reports, both valid ones and false positives, has now become a full time job for the entire Unbound team. You can argue that it ultimately makes our resolver more secure, it also means we cannot work on building and releasing new featur...
-
Post #1093724
Since launching Cascade early October, we’ve been pumping out alpha releases of our #DNSSEC signer at a fairly high velocity. We&#39;re now at alpha5 and decided to slow down releases for the time being, while we&#39;re working on a lot of parallel tasks that a dependent on one another. We&#39;ll resurface in a few weeks with some big steps forward! You can stay up to date with our progress here: https://github.com/NLnetLabs/cascade/pulls #DNS #OpenSource
-
Post #1093715
Thanks to the @Nominet DNS Fund, we have been able to dedicate a team of five developers on building Cascade, our new #OpenSource #DNSSEC signing solution. Leading up a first production release in June, @ximon18 will be presenting on our progress at the @dnsoarc 46 workshop in Edinburgh in May. Highlights will include new incremental signing and IXFR-out, performance/resource usage improvements, TSIG support, metrics, migration tooling, and more... https://indico.dns-oarc.net/event/56/contr...
-
Post #881223
RE: https://fosstodon.org/@iscdotorg/116007490068547600 Each of us is a non-profit. Each of us employ EU citizens as #foss maintainers. And each of us do long-term maintenance and development on independent #opensource implementation for DNS, routing and other foundational network protocols. So we thought we’d once again team up for a submission.
-
Post #796347
We just published 0.16.0-RC1 of our #RPKI Certification Authority Krill, which reverts back to downloading the RISwhois data and processing it locally for analysing ROAs rather than using an external API. In addition, there are quite a few fixes and improvements. For instance, there now is a man page for the config file, so you can now do man krill.conf for information about the config. https://community.nlnetlabs.nl/t/krill-0-16-0-rc1-released/73/1
-
Post #796346
We’ve released NSD 4.14.1 with more compact data storage for improved memory efficiency. Check the release notes: https://www.nlnetlabs.nl/projects/nsd/download/ Willem also wrote a blog post explaining the approach and measurements showing the reduced memory footprint: https://blog.nlnetlabs.nl/smaller-faster-nsds-refactored-rdata-storage-and-compile-time-memory-reduction-options/
-
Post #796345
With memory prices skyrocketing we&#39;re happy to bring you some good news on the #DNS front. In version 4.14.0 of our authoritative nameserver NSD we vastly reduced the memory footprint by refactoring the RDATA storage, with gains up to 50%. Overall, relatively large #DNSSEC-signed zones like .nl and .se benefit the most, but being able to bring the memory requirements to serve .com below 64GB is pretty awesome too. We&#39;re eager to hear the improvements you&#39;re seeing!...
-
Post #796342
Krill 0.16.0 is now available. This release of our #RPKI Certification Authority reverts back to downloading the RISwhois data and processing it locally for analysing ROAs rather than using an external API. The Krill daemon will now also listen on a Unix socket which allows it to use the name of the local user for authentication, making it unnecessary to specify the authentication token when using krillc locally. https://community.nlnetlabs.nl/t/krill-0-16-0-fruher-war-mehr-lametta-released...
-
Post #796341
Our Winter newsletter is out! It&#39;s full of updates on Cascade, news on our community forum, migrating to Codeberg, presentations we&#39;ve given and more! #FOSS #FOSDEM #OpenSource #DigitalSovereignty #DNS #DNSSEC #rustlang https://blog.nlnetlabs.nl/the-winter-2026-newsletter/
-
Post #796338
For our #Rust projects, we created a bespoke #OpenSource pipeline to build and publish binary packages for the last three major versions of Debian, Ubuntu, RHEL and derivatives. Ploutos is now almost four years old, and the way #rustlang packaging is done for these OSes has evolved quite a bit. The pipeline is also closely built around GitHub Actions, and now that we&#39;re moving to @Codeberg we need to overhaul it anyway. Any tips or experiences from the Rust community? https://github.c...
-
Post #796337
@jasper and @drk are at the Euro-IX Route Server Workshop today. Jasper presented on our route collector Rotonda, which is nicely shaping up. We&#39;re churning out features and improvements, not in the last place thanks to our collab with Fastnetmon. #BGP #OpenSource #rustlang
-
Post #796336
We&#39;ve released Rotonda 0.5.2, our BMP/BGP route collector, bringing back the web UI in totally revamped fashion. It&#39;s still simplistic, by design, but now offers a lot more insight in both the actual routes as well as session information. As the UI is still evolving, we are gathering feedback. please chime in with anything that comes to mind: https://community.nlnetlabs.nl/t/web-ui-feedback-ideas/85 https://github.com/NLnetLabs/rotonda/releases/tag/v0.5.2 #BGP #BMP #RustLang
-
Post #796335
We&#39;re thrilled that Cascade is among the first projects supported by the Nominet DNS Fund. With Nominet&#39;s support, our new DNSSEC signing solution receives a massive push forward, allowing our team to focus on implementing speed improvements, a reduced memory footprint and essentials such as incremental signing. We&#39;ll be launching a beta in April, followed by an initial production release in June 2026. Read more: https://nominet.uk/news/nominet-supports-foundations-o...
-
Post #626460
Back in May 2019, we said goodbye to SVN and Bugzilla and migrated to Git and GitHub [1]. Since then, we accumulated 188 repositories. 🙀 We&#39;re now making a list to decide which ones we&#39;re moving to @Codeberg and which are going to be archived and left behind. While we&#39;re doing that, we signed NLnet Labs up as a Codeberg e.V. member! [1] https://lists.nlnetlabs.nl/pipermail/unbound-users/2019-April/006130.html #OpenSource #FOSS #DigitalSovereignty #DNS #BGP
-
Post #597858
From an operator perspective, how would you like clustering of your #DNSSEC signing solution to work? #OpenSource #Community #DevOps https://community.nlnetlabs.nl/t/some-thoughts-on-clustering/59