{"id":72951,"date":"2020-03-06T02:42:09","date_gmt":"2020-03-05T23:42:09","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/reliz-powerdns-recursor-4-3-i-knotdns-2-9-3"},"modified":"2020-03-06T02:42:09","modified_gmt":"2020-03-05T23:42:09","slug":"reliz-powerdns-recursor-4-3-i-knotdns-2-9-3","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/reliz-powerdns-recursor-4-3-i-knotdns-2-9-3","title":{"rendered":"Release of PowerDNS Recursor 4.3 and KnotDNS 2.9.3","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/blog.powerdns.com\/2020\/03\/03\/powerdns-recursor-4-3-0-released\/\">Took place<\/a><\/noindex> release of the caching DNS server <noindex><a rel=\"nofollow\" href=\"https:\/\/www.powerdns.com\/recursor.html\">PowerDNS Recursor 4.3<\/a><\/noindex>, responsible for recursive name resolution. PowerDNS Recursor is built on the same codebase as PowerDNS Authoritative Server, but the recursive and authoritative DNS servers of PowerDNS evolve within different development cycles and are released as separate products. The project code <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/PowerDNS\/pdns\">is distributed<\/a><\/noindex> is licensed under GPLv2. <\/p>\n<p>The server provides tools for remote statistics gathering, supports instant restart, has a built-in engine for connecting handlers in Lua, fully supports DNSSEC, DNS64, RPZ (Response Policy Zones), and allows connecting blacklists. There is an option to record resolution results as BIND zone files. To ensure high performance, modern connection multiplexing mechanisms in FreeBSD, Linux, and Solaris (kqueue, epoll, \/dev\/poll) are used, as well as a high-performance DNS packet parser capable of handling tens of thousands of parallel requests. <\/p>\n<p>In the new version:<\/p>\n<ul>\n<li class=\"l\"> To prevent information leakage about the requested domain and enhance privacy, the mechanism is enabled by default <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.powerdns.com\/recursor\/settings.html#qname-minimization\">QNAME Minimization<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/datatracker.ietf.org\/doc\/rfc7816\/\">RFC-7816<\/a><\/noindex>), operating in 'relaxed' mode. The essence of the mechanism is that the resolver does not mention the full name of the requested host in its queries to the upstream name server. For example, when resolving the address for the host foo.bar.baz.com, the resolver will query the authoritative server for the '.com' zone with 'QTYPE=NS,QNAME=baz.com', not mentioning 'foo.bar'. The operation in 'relaxed' mode has been implemented in its current form.\n<li class=\"l\"> The possibility of logging outgoing queries to the authoritative server and their responses in dnstap format has been implemented (build with the '--enable-dnstap' option is required for use).\n<li class=\"l\"> Simultaneous processing of multiple incoming requests sent over a TCP connection is ensured, delivering results as they are ready, rather than in the order of the requests in the queue. The limit on simultaneous requests is determined by the setting '<noindex><a rel=\"nofollow\" href=\"https:\/\/docs.powerdns.com\/recursor\/settings.html#max-concurrent-requests-per-tcp-connection\">max-concurrent-requests-per-tcp-connection<\/a><\/noindex>&#171;.\n<li class=\"l\"> The technique for tracking new domains has been implemented <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.powerdns.com\/recursor\/nod_udr.html\">NOD<\/a><\/noindex> (Newly Observed Domain), which can be used to identify suspicious domains or domains associated with malicious activities, such as spreading malware, participation in phishing, and controlling botnets. The method is based on identifying domains that have not been previously accessed and analyzing these new domains. Instead of tracking new domains across a full database of all previously viewed domains, which requires significant resources, NOD uses a probabilistic structure. <noindex><a rel=\"nofollow\" href=\"http:\/\/webdocs.cs.ualberta.ca\/~drafiei\/papers\/DupDet06Sigmod.pdf\">SBF<\/a><\/noindex> (Stable Bloom Filter), which helps minimize memory and CPU consumption. To enable it, 'new-domain-tracking=yes' should be specified in the settings.\n<li class=\"l\"> When running under systemd, the PowerDNS Recursor process now runs as the unprivileged user pdns-recursor instead of root. For systems without systemd and without chroot, the default directory for storing the management socket and pid file is now \/var\/run\/pdns-recursor.\n<\/ul>\n<p>Additionally, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.knot-dns.cz\/2020-03-03-version-293.html\">has been published<\/a><\/noindex> release <noindex><a rel=\"nofollow\" href=\"https:\/\/www.knot-dns.cz\/\">KnotDNS 2.9.3<\/a><\/noindex>, a high-performance authoritative DNS server (the resolver is implemented as a separate application), supporting all modern DNS features. The project is developed by the Czech name registry CZ.NIC, written in C, and <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/CZ-NIC\/knot\">is distributed<\/a><\/noindex> under the GPLv3 license. <\/p>\n<p>KnotDNS is designed for high performance in query processing, employing a multi-threaded, and largely non-blocking implementation, well-scalable on SMP systems. Features include on-the-fly zone addition and removal, zone transfer between servers, DDNS (dynamic updates), NSID (RFC 5001), EDNS0 extensions, and DNSSEC (including NSEC3), along with response rate limiting (RRL). <\/p>\n<p>In the new release:<\/p>\n<ul>\n<li class=\"l\"> A new setting 'remote.block-notify-after-transfer' has been added to disable the sending of NOTIFY messages;\n<li class=\"l\"> Experimental support for the Ed448 algorithm in DNSSE has been implemented (requires GnuTLS 3.6.12+ and yet-to-be-released <noindex><a rel=\"nofollow\" href=\"https:\/\/www.lysator.liu.se\/~nisse\/nettle\/\">Nettle 3.6+<\/a><\/noindex>);\n<li class=\"l\"> A parameter 'local-serial' has been added to keymgr to get or set in the KASP database the serial SOA number for the signed zone;\n<li class=\"l\"> Keymgr has added support for importing Ed25519 and Ed448 keys in BIND DNS server format;\n<li class=\"l\"> The default value of the setting 'server.tcp-io-timeout' has been increased to 500 ms, while 'database.journal-db-max-size' has been reduced to 512 MiB on 32-bit systems.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52488\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0448\u0435\u0433\u043e DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 PowerDNS Recursor 4.3, \u043e\u0442\u0432\u0435\u0447\u0430\u044e\u0449\u0435\u0433\u043e \u0437\u0430 \u0440\u0435\u043a\u0443\u0440\u0441\u0438\u0432\u043d\u043e\u0435 \u043f\u0440\u0435\u043e\u0431\u0440\u0430\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u0438\u043c\u0451\u043d. PowerDNS Recursor \u043f\u043e\u0441\u0442\u0440\u043e\u0435\u043d \u043d\u0430 \u043e\u0434\u043d\u043e\u0439 \u043a\u043e\u0434\u043e\u0432\u043e\u0439 \u0431\u0430\u0437\u0435 \u0441 PowerDNS Authoritative Server, \u043d\u043e \u0440\u0435\u043a\u0443\u0440\u0441\u0438\u0432\u043d\u044b\u0439 \u0438 \u0430\u0432\u0442\u043e\u0440\u0438\u0442\u0435\u0442\u043d\u044b\u0439 DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u044b PowerDNS \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0442\u0441\u044f \u0432 \u0440\u0430\u043c\u043a\u0430\u0445 \u0440\u0430\u0437\u043d\u044b\u0445 \u0446\u0438\u043a\u043b\u043e\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0438 \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u044e\u0442\u0441\u044f \u0432 \u0444\u043e\u0440\u043c\u0435 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u043e\u0432. \u041a\u043e\u0434 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e\u0434 \u043b\u0438\u0446\u0435\u043d\u0437\u0438\u0435\u0439 GPLv2. \u0421\u0435\u0440\u0432\u0435\u0440 \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430 \u0434\u043b\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0433\u043e \u0441\u0431\u043e\u0440\u0430 \u0441\u0442\u0430\u0442\u0438\u0441\u0442\u0438\u043a\u0438, \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u0442 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-72951","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0448\u0435\u0433\u043e DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/reliz-powerdns-recursor-4-3-i-knotdns-2-9-3\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 PowerDNS Recursor 4.3 \u0438 KnotDNS 2.9.3 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0448\u0435\u0433\u043e DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/reliz-powerdns-recursor-4-3-i-knotdns-2-9-3\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-03-05T23:42:09+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-03-05T23:42:09+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Release of PowerDNS Recursor 4.3 and KnotDNS 2.9.3 | ProHoster","description":"The release of a caching DNS server","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/reliz-powerdns-recursor-4-3-i-knotdns-2-9-3","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 PowerDNS Recursor 4.3 \u0438 KnotDNS 2.9.3 | ProHoster","og:description":"\u0421\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u043a\u044d\u0448\u0438\u0440\u0443\u044e\u0448\u0435\u0433\u043e DNS-\u0441\u0435\u0440\u0432\u0435\u0440\u0430","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/reliz-powerdns-recursor-4-3-i-knotdns-2-9-3","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-03-05T23:42:09+00:00","article:modified_time":"2020-03-05T23:42:09+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"72951","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:42:53","updated":"2022-10-04 21:14:34","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/72951","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=72951"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/72951\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=72951"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=72951"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=72951"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}