[ANNOUNCE] ktls-utils 1.5.0
Chuck Lever
cel at kernel.org
Wed Sep 23 07:10:32 PDT 2026
[ Although the email displayed in Thunderbird as a plaintext, it
was sent in HTML format from chuck.lever at oracle.com. Resending
as 100% plaintext with my apologies. ]
This email announces the official release of ktls-utils 1.5.0.
ktls-utils 1.5.0 adds DANE authentication of server certificates: tlshd can now
validate a server's certificate against TLSA records published in DNS, with the
new behavior governed by DANE configuration options documented in the tlshd.conf
man page. A new nfstlskey tool manages the NFS client's mTLS identities, and
tlshd now links the NFS keyrings per handshake rather than once at startup, so
identities added after the daemon starts are picked up. Private keys may now be
named by GnuTLS URL, which enables keys held in PKCS#11 tokens and TPMs. The
post-quantum ECDHE + ML-KEM hybrid key exchange groups are enabled. Kernel
capability detection now reads the handshake netlink policy, so new kernel
features are recognized without a tlshd update.
Official source code repo:
https://github.com/oracle/ktls-utils/
Release tag:
ktls-utils-1.5.0
Release artifacts:
A source tarball created automatically by GitHub:
https://github.com/oracle/ktls-utils/archive/refs/tags/ktls-utils-1.5.0.tar.gz
A source tarball created with "make dist":
https://github.com/oracle/ktls-utils/releases/download/ktls-utils-1.5.0/ktls-utils-1.5.0.tar.gz
Issues and requests for enhancement:
https://github.com/oracle/ktls-utils/issues
--
Chuck Lever (Come to NFS bake-a-thon! https://nfsv4bat.org)
More information about the Linux-nvme
mailing list