ืฉืจืช DHCP Kea 1.6, ืฉืคื•ืชื— ืขืœ ื™ื“ื™ ืงื•ื ืกื•ืจืฆื™ื•ื ISC, ืคื•ืจืกื

ืงื•ื ืกื•ืจืฆื™ื•ื ISC ืคื•ืจืกื ืฉื—ืจื•ืจ ืฉืจืช DHCP kea 1.6.0, ื”ืžื—ืœื™ืฃ ืืช ISC DHCP ื”ืงืœืืกื™. ืžืงื•ืจื•ืช ื”ืคืจื•ื™ืงื˜ ื”ืชืคืฉื˜ื•ืช ืชื—ืช ืจื™ืฉื™ื•ืŸ Mozilla Public License (MPL) 2.0, ื‘ืžืงื•ื ืจื™ืฉื™ื•ืŸ ISC ืฉืฉื™ืžืฉ ื‘ืขื‘ืจ ืขื‘ื•ืจ ISC DHCP.

ืฉืจืช DHCP ืฉืœ Kea ืžื‘ื•ืกืก ืขืœ BIND 10 ื• ื‘ื ื•ื™ ื‘ืืžืฆืขื•ืช ืืจื›ื™ื˜ืงื˜ื•ืจื” ืžื•ื“ื•ืœืจื™ืช, ืžื” ืฉืžืจืžื– ืขืœ ื—ืœื•ืงืช ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืœืชื”ืœื™ื›ื™ ืžืขื‘ื“ ืฉื•ื ื™ื. ื”ืžื•ืฆืจ ื›ื•ืœืœ ื™ื™ืฉื•ื ืฉืจืช ืžืœื ืขื ืชืžื™ื›ื” ื‘ืคืจื•ื˜ื•ืงื•ืœื™ DHCPv4 ื•-DHCPv6, ื”ืžืกื•ื’ืœ ืœื”ื—ืœื™ืฃ ืืช ISC DHCP. ืœ- Kea ื›ืœื™ื ืžื•ื‘ื ื™ื ืœืขื“ื›ื•ืŸ ื“ื™ื ืžื™ ืฉืœ ืื–ื•ืจื™ DNS (DNS ื“ื™ื ืžื™), ืชื•ืžืš ื‘ืžื ื’ื ื•ื ื™ื ืœื’ื™ืœื•ื™ ืฉืจืช, ื”ืงืฆืืช ื›ืชื•ื‘ื•ืช, ืขื“ื›ื•ืŸ ื•ื—ื™ื‘ื•ืจ ืžื—ื“ืฉ, ืฉื™ืจื•ืช ื‘ืงืฉื•ืช ืžื™ื“ืข, ืฉืžื™ืจืช ื›ืชื•ื‘ื•ืช ืœืžืืจื—ื™ื, ื•ืืชื—ื•ืœ PXE. ื™ื™ืฉื•ื DHCPv6 ืžืกืคืง ื‘ื ื•ืกืฃ ืืช ื”ื™ื›ื•ืœืช ืœื”ืืฆื™ืœ ืงื™ื“ื•ืžื•ืช. API ืžื™ื•ื—ื“ ืžืกื•ืคืง ืœืื™ื ื˜ืจืืงืฆื™ื” ืขื ื™ื™ืฉื•ืžื™ื ื—ื™ืฆื•ื ื™ื™ื. ืืคืฉืจ ืœืขื“ื›ืŸ ืืช ื”ืชืฆื•ืจื” ืชื•ืš ื›ื“ื™ ืชื ื•ืขื” ืžื‘ืœื™ ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช ื”ืฉืจืช.

ื ื™ืชืŸ ืœืื—ืกืŸ ืžื™ื“ืข ืขืœ ื›ืชื•ื‘ื•ืช ืฉื”ื•ืงืฆื• ื•ืคืจืžื˜ืจื™ ืœืงื•ื— ื‘ืกื•ื’ื™ื ืฉื•ื ื™ื ืฉืœ ืื—ืกื•ืŸ - ื›ื™ื•ื ืžืกื•ืคืงื™ื ืงืฆื” ืื—ื•ืจื™ ืœืื—ืกื•ืŸ ื‘ืงื‘ืฆื™ CSV, MySQL DBMS, Apache Cassandra ื•-PostgreSQL. ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืคืจืžื˜ืจื™ื ืฉืœ ื”ื–ืžื ืช ืžืืจื— ื‘ืงื•ื‘ืฅ ืชืฆื•ืจื” ื‘ืคื•ืจืžื˜ JSON ืื• ื›ื˜ื‘ืœื” ื‘-MySQL ื•-PostgreSQL. ื”ื•ื ื›ื•ืœืœ ืืช ื”ื›ืœื™ perfdhcp ืœืžื“ื™ื“ืช ื‘ื™ืฆื•ืขื™ ืฉืจืช DHCP ื•ืจื›ื™ื‘ื™ื ืœืื™ืกื•ืฃ ื ืชื•ื ื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื. Kea ืžืคื’ื™ืŸ ื‘ื™ืฆื•ืขื™ื ื˜ื•ื‘ื™ื, ืœืžืฉืœ, ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-MySQL backend, ื”ืฉืจืช ื™ื›ื•ืœ ืœื‘ืฆืข 1000 ื”ืงืฆืื•ืช ื›ืชื•ื‘ื•ืช ื‘ืฉื ื™ื™ื” (ื›-4000 ืžื ื•ืช ืœืฉื ื™ื™ื”), ื•ื‘ืฉื™ืžื•ืฉ ื‘-memfile backend, ื”ื‘ื™ืฆื•ืขื™ื ืžื’ื™ืขื™ื ืœ-7500 ื”ืงืฆืื•ืช ื‘ืฉื ื™ื™ื”.

ืฉืจืช DHCP Kea 1.6, ืฉืคื•ืชื— ืขืœ ื™ื“ื™ ืงื•ื ืกื•ืจืฆื™ื•ื ISC, ืคื•ืจืกื

ืžืคืชื— ืฉื™ืคื•ืจื™ื ื‘- Kea 1.6:

  • ืงืฆื” ืื—ื•ืจื™ ืฉืœ ืชืฆื•ืจื” (CB, Configuration Backend) ื™ื•ืฉื, ื”ืžืืคืฉืจ ืœืš ืœื ื”ืœ ื‘ืื•ืคืŸ ืžืจื›ื–ื™ ืืช ื”ื”ื’ื“ืจื•ืช ืฉืœ ืžืกืคืจ ืฉืจืชื™ DHCPv4 ื•-DHCPv6. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-backend ืœืื—ืกื•ืŸ ืจื•ื‘ ื”ื’ื“ืจื•ืช Kea, ื›ื•ืœืœ ื”ื’ื“ืจื•ืช ื’ืœื•ื‘ืœื™ื•ืช, ืจืฉืชื•ืช ืžืฉื•ืชืคื•ืช, ืจืฉืชื•ืช ืžืฉื ื”, ืืคืฉืจื•ื™ื•ืช, ืžืื’ืจื™ื ื•ื”ื’ื“ืจื•ืช ืืคืฉืจื•ื™ื•ืช. ื‘ืžืงื•ื ืœืื—ืกืŸ ืืช ื›ืœ ื”ื”ื’ื“ืจื•ืช ื”ืœืœื• ื‘ืงื•ื‘ืฅ ืชืฆื•ืจื” ืžืงื•ืžื™, ื›ืขืช ื ื™ืชืŸ ืœืžืงื ืื•ืชืŸ ื‘ืžืกื“ ื ืชื•ื ื™ื ื—ื™ืฆื•ื ื™. ื‘ืžืงืจื” ื–ื”, ื ื™ืชืŸ ืœืงื‘ื•ืข ืœื ืืช ื›ื•ืœืŸ, ืืœื ื—ืœืง ืžื”ื”ื’ื“ืจื•ืช ื‘ืืžืฆืขื•ืช CB, ื›ื™ืกื•ื™ ืคืจืžื˜ืจื™ื ืžืžืกื“ ื”ื ืชื•ื ื™ื ื”ื—ื™ืฆื•ื ื™ ื•ืงื‘ืฆื™ ืชืฆื•ืจื” ืžืงื•ืžื™ื™ื (ืœื“ื•ื’ืžื”, ื ื™ืชืŸ ืœื”ืฉืื™ืจ ื”ื’ื“ืจื•ืช ืžืžืฉืง ืจืฉืช ื‘ืงื‘ืฆื™ื ืžืงื•ืžื™ื™ื).

    ืžื‘ื™ืŸ ื”-DBMSs ืœืื—ืกื•ืŸ ืชืฆื•ืจื”, ืจืง MySQL ื ืชืžืš ื›ืจื’ืข (ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-MySQL, PostgreSQL ื•-Cassandra ืœืื—ืกื•ืŸ ืžืกื“ื™ ื ืชื•ื ื™ื ืฉืœ ื”ืงืฆืืช ื›ืชื•ื‘ื•ืช (ื—ื›ื™ืจื”), ื•ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-MySQL ื•-PostgreSQL ืœืฉืžื™ืจืช ืžืืจื—ื™ื). ื ื™ืชืŸ ืœืฉื ื•ืช ืืช ื”ืชืฆื•ืจื” ื‘ืžืกื“ ื”ื ืชื•ื ื™ื ืื• ื‘ืืžืฆืขื•ืช ื’ื™ืฉื” ื™ืฉื™ืจื” ืœ-DBMS ืื• ื‘ืืžืฆืขื•ืช ืกืคืจื™ื•ืช ืฉื›ื‘ื•ืช ืฉื”ื•ื›ื ื• ื‘ืžื™ื•ื—ื“ ื”ืžืกืคืงื•ืช ืกื˜ ืกื˜ื ื“ืจื˜ื™ ืฉืœ ืคืงื•ื“ื•ืช ืœื ื™ื”ื•ืœ ืชืฆื•ืจื”, ื›ื’ื•ืŸ ื”ื•ืกืคื” ื•ืžื—ื™ืงื” ืฉืœ ืคืจืžื˜ืจื™ื, ื›ืจื™ื›ื•ืช, ืืคืฉืจื•ื™ื•ืช DHCP ื•ืจืฉืชื•ืช ืžืฉื ื”;

  • ื ื•ืกืคื” ืžื—ืœืงื” ื—ื“ืฉื” ืฉืœ ืžื˜ืคืœ "DROP" (ื›ืœ ื”ื—ื‘ื™ืœื•ืช ื”ืžืฉื•ื™ื›ื•ืช ืœืžื—ืœืงืช DROP ื ืฉืžื˜ื•ืช ืžื™ื“), ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื” ื›ื“ื™ ืœื”ืคื™ืœ ืชืขื‘ื•ืจื” ืœื ืจืฆื•ื™ื”, ืœืžืฉืœ, ืกื•ื’ื™ื ืžืกื•ื™ืžื™ื ืฉืœ ื”ื•ื“ืขื•ืช DHCP;
  • ื ื•ืกืคื• ืคืจืžื˜ืจื™ื ื—ื“ืฉื™ื max-lease-time ื•-min-lease-time, ื”ืžืืคืฉืจื™ื ืœืš ืœืงื‘ื•ืข ืืช ืžืฉืš ื—ื™ื™ ื”ื›ืชื•ื‘ืช ื”ืžื—ื™ื™ื‘ืช ืืช ื”ืœืงื•ื— (ื—ื›ื™ืจื”) ืœื ื‘ืฆื•ืจื” ืฉืœ ืขืจืš ืžืงื•ื“ื“, ืืœื ื‘ืฆื•ืจื” ืฉืœ ื˜ื•ื•ื— ืžืงื•ื‘ืœ;
  • ืชืื™ืžื•ืช ืžืฉื•ืคืจืช ืœืžื›ืฉื™ืจื™ื ืฉืื™ื ื ืขื•ืžื“ื™ื ื‘ืžืœื•ืื ื‘ืชืงื ื™ DHCP. ื›ื“ื™ ืœืขืงื•ืฃ ืืช ื”ื‘ืขื™ื•ืช, Kea ืฉื•ืœื— ื›ืขืช ืžื™ื“ืข ืขืœ ืกื•ื’ ื”ื•ื“ืขื•ืช DHCPv4 ืžืžืฉ ื‘ืชื—ื™ืœืช ืจืฉื™ืžืช ื”ืืคืฉืจื•ื™ื•ืช, ืžื˜ืคืœ ื‘ื™ื™ืฆื•ื’ื™ื ืฉื•ื ื™ื ืฉืœ ืฉืžื•ืช ืžืืจื—, ืžื–ื”ื” ืฉื™ื“ื•ืจ ืฉืœ ืฉื ืžืืจื— ืจื™ืง ื•ืžืืคืฉืจ ืœื”ื’ื“ื™ืจ ืงื•ื“ื™ ืืคืฉืจื•ื™ื•ืช ืžืฉื ื” 0 ืขื“ 255;
  • ื ื•ืกืฃ ืฉืงืข ื‘ืงืจื” ื ืคืจื“ ืœื“ืžื•ืŸ DDNS, ืฉื“ืจื›ื• ื ื™ืชืŸ ืœืฉืœื•ื— ืคืงื•ื“ื•ืช ื™ืฉื™ืจื•ืช ื•ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘ืชืฆื•ืจื”. ื”ืคืงื•ื“ื•ืช ื”ื‘ืื•ืช ื ืชืžื›ื•ืช: build-report, config-get, config-reload, config-set, config-test, config-write, list-commands, shutdown ื•-version-get;
  • ืžื—ื•ืกืœ ืคื’ื™ืขื•ืช (CVE-2019-6472, CVE-2019-6473, CVE-2019-6474), ืืฉืจ ื™ื›ื•ืœ ืœืฉืžืฉ ื›ื“ื™ ืœื’ืจื•ื ืœืžื ื™ืขืช ืฉื™ืจื•ืช (ื”ื’ื•ืจื ืœืงืจื™ืกื” ืฉืœ ืžื˜ืคืœื™ ืฉืจืชื™ื DHCPv4 ื•-DHCPv6) ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืขื ืืคืฉืจื•ื™ื•ืช ื•ืขืจื›ื™ื ืฉื’ื•ื™ื™ื. ื”ืกื›ื ื” ื”ื’ื“ื•ืœื” ื‘ื™ื•ืชืจ ื”ื™ื ื”ื‘ืขื™ื” CVE-2019-6474, ืืฉืจ, ื›ืืฉืจ ืžืฉืชืžืฉื™ื ื‘ื• ืœืื—ืกื•ืŸ memfile ืขื‘ื•ืจ bindings, ืœื ืžืืคืฉืจ ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช ืชื”ืœื™ืš ื”ืฉืจืช ื‘ื›ื•ื—ื•ืช ืขืฆืžื•, ื•ืœื›ืŸ ื ื“ืจืฉืช ื”ืชืขืจื‘ื•ืช ื™ื“ื ื™ืช ืฉืœ ื”ืžื ื”ืœ (ื ื™ืงื•ื™ ืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ binding) ื›ื“ื™ ืœืฉื—ื–ืจ ืืช ื”ืคืขื•ืœื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”