Release of PowerDNS Authoritative Server 5.0

The release of the authoritative DNS server PowerDNS Authoritative Server 5.0 has been published, designed to manage DNS zone responses. In its prime, PowerDNS Authoritative Server served up to 30% of all domains in Europe and up to 90% of domains with DNSSEC. The project's code is distributed under the GPLv2 license.

PowerDNS Authoritative Server offers the ability to store domain information in various databases, including MySQL, PostgreSQL, SQLite3, LMDB, Oracle, and Microsoft SQL Server, as well as in LDAP and plain text files in BIND format. The response can be further filtered (for example, to filter out spam) or redirected to custom handlers in languages like Lua, Java, Perl, Python, Ruby, C, and C++. Notable features also include tools for remote statistics collection, including via SNMP or through a Web API (an HTTP server is built in for statistics and management), instant restarts, a built-in engine for integrating Lua handlers, and load balancing based on the client's geographic location.

A key innovation in PowerDNS Authoritative Server 5.0 is the support for views styled after BIND DNS server, allowing different DNS zone content to be served based on the an IP addressfrom which the request was received. For example, with views, users with internal addresses (intranet) can be served one version of the DNS zone for the requested domain, while external users receive another. Currently, only the LMDB backend can be used to store different views of DNS zones.

Among other changes:

  • Support for binding to a Unix socket instead of TCP/IP socket has been added.
  • The sdig utility now includes support for EDNS Cookie.
  • The LMDB backend has gained the ability to search records and support for RFC-2136 (DNS UPDATE).
  • A new syntax for launching the pdnsutil utility has been implemented — 'pdnsutil object_type command arguments' (support for the old syntax has been retained).
  • A new command 'pdnsutil backend-lookup' has been added for searching records in the storage backend.
  • Support for RFC-9615 for automatic authenticated bootstrapping of DNSSEC has been added.
  • Support for logging packets that encountered parsing errors has been implemented.
  • A new setting 'dnsupdate-require-tsig' has been added, mandating the use of the TSIG (Transaction Signature) mechanism for DNS record update operations.
  • A setting for "direct-dnskey-signature" has been added, allowing direct extraction of the DNSKEY digital signature from the backend.
  • A setting for "resolve-across-zones" has been added, which, when disabled, prevents the DNS server from resolving CNAME records pointing to other zones.
  • Enhanced capabilities for creating handlers in Lua have been introduced.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster