Release of PowerDNS Authoritative Server 4.7

The release of the authoritative DNS server PowerDNS Authoritative Server 4.7 has been published, designed for DNS zone delivery. According to the project developers, PowerDNS Authoritative Server operates approximately 30% of all domains in Europe (and if only DNSSEC-signed domains are considered, then 90%). The project's code is distributed under the GPLv2 license.

PowerDNS Authoritative Server provides the capability to store domain information in various databases, including MySQL, PostgreSQL, SQLite3, Oracle, and Microsoft SQL Server, as well as in LDAP and plain text files in BIND format. Answer responses can also be further filtered (for example, to block spam) or redirected using custom handlers in languages such as Lua, Java, Perl, Python, Ruby, C, and C++. Notable features also include tools for remote statistics collection, including via SNMP or through a Web API (with an embedded HTTP server for statistics and management), instant restart, an integrated engine for connecting handlers in Lua, and the ability to balance loads based on the client's geographical location.

Key innovations:

  • Support for catalog zones ('Catalog Zones') has been added, simplifying the maintenance of secondary DNS servers by allowing the definition of secondary zones to be managed through the catalog transfer. server Instead of defining separate records for each secondary zone, a catalog of secondary zones is transmitted between the primary and secondary servers. Once the catalog transfer is set up similarly to individual zone transfers, zones created on the primary server marked as belonging to the catalog will automatically be created on the secondary server without the need to edit configuration files. The catalog supports working with storage backends gmysql, gpgsql, gsqlite3, godbc, and lmdb.
  • During the implementation of the catalog of zones, the code was optimized for handling a large number of domains. When storing zones in the DBMS, the number of SQL queries has been significantly reduced — instead of a separate query for each domain, a group selection is now performed. This change positively affected the performance servers, serving a large number of zones, even on systems not using the catalog of zones.
  • The GSS-TSIG key exchange mechanism, which was previously removed due to vulnerabilities and potential security issues, has been redesigned and reintroduced.
  • When querying Lua records using TCP, Lua state reuse has been implemented, which significantly improved performance.
  • In the lmdbbackend database, binding to UUID and the ability to generate random object identifiers has been implemented.
  • Management tools for autoprimary servers have been added to pdnsutil and HTTP API, used for automating the deployment and updating of zones on secondary DNS servers without manual configuration of secondary zones.
  • A new Lua function ifurlextup has been added.
  • An experimental background process for key generation and delivery (key roller) has been introduced.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster