The Trust-DNS server has been renamed to Hickory and will be utilized in the Let's Encrypt infrastructure.

The author of the Trust-DNS server announced the project's name change to Hickory DNS. The reason for the name change is to make the project more appealing to users, developers, and sponsors, to avoid overlaps with the 'Trusted DNS' concept in searches, and to register a trademark to protect the related brand (the name Trust-DNS will be problematic to use as a trademark because it is formed from generic words that cannot be considered unique).

Initially, the project developed as an experiment in creating system components using a programming language that provides features for safe memory handling, but current plans are aimed at turning it into a full-fledged product. The development of the Hickory DNS server will be carried out under the auspices of ISRG (Internet Security Research Group), which is the founder of the Let’s Encrypt project and promotes the development of technologies to enhance internet security (for example, under the auspices of ISRG, implementations of sudo, a TLS module for the Apache web server, an NTP server, and an AV1 decoder, all written in Rust, are being developed).

After the renaming, the project will be moved from the author's personal GitHub repository to a repository under the separate organization Hickory DNS, simplifying participation for developers and community maintainers. The Crate packages trust-dns-resolver and trust-dns-proto will be renamed to hickory-resolver and hickory-proto, while the main server will be provided in the hickory-dns package. Currently, the trust-dns-resolver and trust-dns-proto packages have 19 and 20 million downloads on Crates.io, and it is expected that with investments from ISRG, the usage of the DNS server will expand and become more user-friendly for practical implementations.

Hickory DNS includes components to support an authoritative DNS server, DNS client, local resolver, and recursive DNS server. It also contains libraries with implementations of low-level protocols. The project supports DNSSEC, DoT (DNS over TLS), DoH (DNS over HTTPS), DoQ (DNS over QUIC), mDNS (Multicast DNS), DNS-SD (Service Discovery), ANAME, dynamic record updates, CSYNC (Child-to-Parent Synchronization), DANE (DNS-Based Authentication of Named Entities), DNSKEY, and CAA (Certification Authority Authorization). Support for classless IN-ADDR.ARPA, incremental zone transfers, sending zone update notifications to secondary servers, Trusted DNS, and S/MIME is in progress or pending completion. The project code is written in Rust and is distributed under the MIT and Apache 2.0 licenses.

In the future, Hickory DNS is planned to be used in the Let’s Encrypt infrastructure. Before implementation, a security audit will be conducted, performance optimization will take place, and full recursive query support and validation through DNSSEC will be ensured. Plans also mention support for NSEC3, caching policies for different types of DNS records, and request processing load balancing, as well as whitelists (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community. for incoming connections.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster