ืฉื—ืจื•ืจ ืฉืœ PowerDNS Recursor 4.3 ื•- KnotDNS 2.9.3

ื”ืชืจื—ืฉ ืฉื—ืจื•ืจ ืฉืจืช DNS ืœืื—ืกื•ืŸ ื‘ืžื˜ืžื•ืŸ ืžืฉืื‘ PowerDNS 4.3, ืื—ืจืื™ ืœื”ืžืจืช ืฉืžื•ืช ืจืงื•ืจืกื™ื‘ื™ืช. PowerDNS Recursor ื‘ื ื•ื™ ืขืœ ืื•ืชื• ื‘ืกื™ืก ืงื•ื“ ื›ืžื• PowerDNS Authoritative Server, ืืš ืฉืจืชื™ DNS ืจืงื•ืจืกื™ื‘ื™ื™ื ื•ืกืžื›ื•ืชื™ื™ื ืฉืœ PowerDNS ืžืคื•ืชื—ื™ื ื‘ืืžืฆืขื•ืช ืžื—ื–ื•ืจื™ ืคื™ืชื•ื— ืฉื•ื ื™ื ื•ืžืฉื•ื—ืจืจื™ื ื›ืžื•ืฆืจื™ื ื ืคืจื“ื™ื. ืงื•ื“ ืคืจื•ื™ืงื˜ ืžื•ืคืฅ ืขืœ ื™ื“ื™ ืžื•ืจืฉื” ืชื—ืช GPLv2.

ื”ืฉืจืช ืžืกืคืง ื›ืœื™ื ืœืื™ืกื•ืฃ ืกื˜ื˜ื™ืกื˜ื™ืงื•ืช ืžืจื—ื•ืง, ืชื•ืžืš ื‘ืืชื—ื•ืœ ืžื™ื™ื“ื™, ื‘ืขืœ ืžื ื•ืข ืžื•ื‘ื ื” ืœื—ื™ื‘ื•ืจ ืžื˜ืคืœื™ื ื‘ืฉืคืช Lua, ืชื•ืžืš ื‘ืื•ืคืŸ ืžืœื ื‘-DNSSEC, DNS64, RPZ (Response Policy Zones), ื•ืžืืคืฉืจ ืœื—ื‘ืจ ืจืฉื™ืžื•ืช ืฉื—ื•ืจื•ืช. ืืคืฉืจ ืœื”ืงืœื™ื˜ ืชื•ืฆืื•ืช ืจื–ื•ืœื•ืฆื™ื” ื›ืงื‘ืฆื™ ืื–ื•ืจ BIND. ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžื ื’ื ื•ื ื™ ืจื™ื‘ื•ื™ ื—ื™ื‘ื•ืจื™ื ืžื•ื“ืจื ื™ื™ื ื‘-FreeBSD, Linux ื•-Solaris (kqueue, epoll, /dev/poll), ื›ืžื• ื’ื ืžื ืชื— ืžื ื•ืช DNS ื‘ืขืœ ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื ื”ืžืกื•ื’ืœ ืœืขื‘ื“ ืขืฉืจื•ืช ืืœืคื™ ื‘ืงืฉื•ืช ืžืงื‘ื™ืœื•ืช.

ื‘ื’ืจืกื” ื”ื—ื“ืฉื”:

  • ืขืœ ืžื ืช ืœืžื ื•ืข ื“ืœื™ืคื•ืช ืžื™ื“ืข ืขืœ ื”ื“ื•ืžื™ื™ืŸ ื”ืžื‘ื•ืงืฉ ื•ืœื”ื’ื‘ื™ืจ ืืช ื”ืคืจื˜ื™ื•ืช, ื”ืžื ื’ื ื•ืŸ ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืžื–ืขื•ืจ QNAME (RFC-7816), ืคื•ืขืœ ื‘ืžืฆื‘ "ืจื’ื•ืข". ืžื”ื•ืช ื”ืžื ื’ื ื•ืŸ ื”ื™ื ืฉื”ืคื•ืจื ืื™ื ื• ืžื–ื›ื™ืจ ืืช ืฉืžื• ื”ืžืœื ืฉืœ ื”ืžืืจื— ื”ืจืฆื•ื™ ื‘ื‘ืงืฉื•ืชื™ื• ืœืฉืจืช ื”ืฉืžื•ืช ื‘ืžืขืœื” ื”ื–ืจื. ืœื“ื•ื’ืžื”, ื‘ืขืช ืงื‘ื™ืขืช ื”ื›ืชื•ื‘ืช ืขื‘ื•ืจ ื”ืžืืจื— foo.bar.baz.com, ื”ืคื•ืชืจ ื™ืฉืœื— ืืช ื”ื‘ืงืฉื” "QTYPE=NS,QNAME=baz.com" ืœืฉืจืช ื”ืกืžื›ื•ืชื™ ืฉืœ ืื–ื•ืจ ".com", ืžื‘ืœื™ ืœืฆื™ื™ืŸ " ืคื• ื‘ืจ". ื‘ืฆื•ืจืชื” ื”ื ื•ื›ื—ื™ืช, ื”ืขื‘ื•ื“ื” ืžื™ื•ืฉืžืช ื‘ืžืฆื‘ "ืจื’ื•ืข".
  • ื”ื•ื˜ืžืขื” ื”ื™ื›ื•ืœืช ืœืจืฉื•ื ื‘ืงืฉื•ืช ื™ื•ืฆืื•ืช ืœืฉืจืช ืกืžื›ื•ืชื™ ื•ืชื’ื•ื‘ื•ืช ืœื”ืŸ ื‘ืคื•ืจืžื˜ dnstap (ืœืฉื™ืžื•ืฉ, ื ื“ืจืฉืช ื‘ื ื™ื™ื” ืขื ืืคืฉืจื•ืช "-enable-dnstap").
  • ื ื™ืชืŸ ืขื™ื‘ื•ื“ ืกื™ืžื•ืœื˜ื ื™ ืฉืœ ืžืกืคืจ ื‘ืงืฉื•ืช ื ื›ื ืกื•ืช ื”ืžื•ืขื‘ืจื•ืช ื“ืจืš ื—ื™ื‘ื•ืจ TCP, ื›ืืฉืจ ื”ืชื•ืฆืื•ืช ืžื•ื—ื–ืจื•ืช ื›ืฉื”ืŸ ืžื•ื›ื ื•ืช, ื•ืœื ืœืคื™ ืกื“ืจ ื”ื‘ืงืฉื•ืช ื‘ืชื•ืจ. ืžื’ื‘ืœืช ื”ื‘ืงืฉื•ืช ื‘ื• ื–ืžื ื™ืช ื ืงื‘ืขืช ืขืœ ื™ื“ื™ "max-concurrent-requests-per-tcp-connection".
  • ื”ื˜ืžื™ืข ื˜ื›ื ื™ืงื” ืœืžืขืงื‘ ืื—ืจ ื“ื•ืžื™ื™ื ื™ื ื—ื“ืฉื™ื Nod (Newly Observed Domain), ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœื–ื”ื•ืช ื“ื•ืžื™ื™ื ื™ื ื—ืฉื•ื“ื™ื ืื• ื“ื•ืžื™ื™ื ื™ื ื”ืงืฉื•ืจื™ื ืœืคืขื™ืœื•ืช ื–ื“ื•ื ื™ืช, ื›ื’ื•ืŸ ื”ืคืฆืช ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช, ื”ืฉืชืชืคื•ืช ื‘ื“ื™ื•ื’ ื•ืฉื™ืžื•ืฉ ืœื”ืคืขืœืช ืจืฉืชื•ืช ื‘ื•ื˜ื™ื. ื”ืฉื™ื˜ื” ืžื‘ื•ืกืกืช ืขืœ ื–ื™ื”ื•ื™ ื“ื•ืžื™ื™ื ื™ื ืฉืœื ื ื™ื’ืฉื• ืืœื™ื”ื ื‘ืขื‘ืจ ื•ื ื™ืชื•ื— ื“ื•ืžื™ื™ื ื™ื ื—ื“ืฉื™ื ืืœื•. ื‘ืžืงื•ื ืœืขืงื•ื‘ ืื—ืจ ื“ื•ืžื™ื™ื ื™ื ื—ื“ืฉื™ื ืžื•ืœ ืžืกื“ ื ืชื•ื ื™ื ืฉืœื ืฉืœ ื›ืœ ื”ื“ื•ืžื™ื™ื ื™ื ืฉื ืฆืคื• ืื™ ืคืขื, ืžื” ืฉื“ื•ืจืฉ ืžืฉืื‘ื™ื ืžืฉืžืขื•ืชื™ื™ื ืœืชื—ื–ื•ืงื”, NOD ืžืฉืชืžืฉืช ื‘ืžืกื’ืจืช ื”ืกืชื‘ืจื•ืชื™ืช Sbf (Stable Bloom Filter), ื”ืžืืคืฉืจ ืœืžื–ืขืจ ืืช ืฆืจื™ื›ืช ื”ื–ื™ื›ืจื•ืŸ ื•ื”ืžืขื‘ื“. ื›ื“ื™ ืœื”ืคืขื™ืœ ืื•ืชื•, ืขืœื™ืš ืœืฆื™ื™ืŸ "new-domain-tracking=yes" ื‘ื”ื’ื“ืจื•ืช.
  • ื›ืืฉืจ ืคื•ืขืœ ืชื—ืช systemd, ืชื”ืœื™ืš PowerDNS Recursor ืคื•ืขืœ ื›ืขืช ืชื—ืช ื”ืžืฉืชืžืฉ ื”ื‘ืœืชื™ ืžื•ื’ืŸ pdns-recursor ื‘ืžืงื•ื ืฉื•ืจืฉ. ืขื‘ื•ืจ ืžืขืจื›ื•ืช ืœืœื systemd ื•ืœืœื chroot, ืกืคืจื™ื™ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืœืื—ืกื•ืŸ ืฉืงืข ื”ื‘ืงืจื” ื•ืงื•ื‘ืฅ ื”-Pid ื”ื™ื ื›ืขืช /var/run/pdns-recursor.

ื‘ื ื•ืกืฃ, ืคื•ืจืกื ืฉื—ืจื•ืจ KnotDNS 2.9.3, ืฉืจืช DNS ืกืžื›ื•ืชื™ ื‘ืขืœ ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื (ื”ืจืงื•ืจืกื•ืจ ืžืชื•ื›ื ืŸ ื›ืืคืœื™ืงืฆื™ื” ื ืคืจื“ืช) ื”ืชื•ืžืš ื‘ื›ืœ ืชื›ื•ื ื•ืช ื”-DNS ื”ืžื•ื“ืจื ื™ื•ืช. ื”ืคืจื•ื™ืงื˜ ืžืคื•ืชื— ืขืœ ื™ื“ื™ ืžืจืฉื ื”ืฉืžื•ืช ื”ืฆ'ื›ื™ CZ.NIC, ื›ืชื•ื‘ ื‘-C ื• ืžื•ืคืฅ ืขืœ ื™ื“ื™ ืžื•ืจืฉื” ืชื—ืช GPLv3.

KnotDNS ื ื‘ื“ืœ ื‘ื”ืชืžืงื“ื•ืช ืฉืœื• ื‘ืขื™ื‘ื•ื“ ืฉืื™ืœืชื•ืช ื‘ืขืœ ื‘ื™ืฆื•ืขื™ื ื’ื‘ื•ื”ื™ื, ืฉืขื‘ื•ืจื• ื”ื•ื ืžืฉืชืžืฉ ื‘ื™ื™ืฉื•ื ืžืจื•ื‘ื” ื”ืœื™ื›ื™ ื•ื‘ืขื™ืงืจ ืœื ื—ื•ืกื ืฉืžืชืจื—ื‘ ื”ื™ื˜ื‘ ื‘ืžืขืจื›ื•ืช SMP. ืชื›ื•ื ื•ืช ื›ื’ื•ืŸ ื”ื•ืกืคื” ื•ืžื—ื™ืงื” ืฉืœ ืื–ื•ืจื™ื ืชื•ืš ื›ื“ื™ ืชื ื•ืขื”, ื”ืขื‘ืจืช ืื–ื•ืจื™ื ื‘ื™ืŸ ืฉืจืชื™ื, DDNS (ืขื“ื›ื•ื ื™ื ื“ื™ื ืžื™ื™ื), NSID (RFC 5001), ื”ืจื—ื‘ื•ืช EDNS0 ื•-DNSSEC (ื›ื•ืœืœ NSEC3), ื”ื’ื‘ืœืช ืฉื™ืขื•ืจ ืชื’ื•ื‘ื” (RRL).

ื‘ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื”:

  • ื ื•ืกืคื” ื”ื’ื“ืจื” 'remote.block-notify-after-transfer' ื›ื“ื™ ืœื‘ื˜ืœ ืืช ืฉืœื™ื—ืช ื”ื•ื“ืขื•ืช NOTIFY;
  • ื”ื˜ืžื™ืขื” ืชืžื™ื›ื” ื ื™ืกื™ื•ื ื™ืช ื‘ืืœื’ื•ืจื™ืชื Ed448 ื‘-DNSSE (ื“ื•ืจืฉ GnuTLS 3.6.12+ ื•ืขื“ื™ื™ืŸ ืœื ืฉื•ื—ืจืจ ืกืจืคื“ 3.6+);
  • ื”ืคืจืžื˜ืจ 'local-serial' ื ื•ืกืฃ ืœ-keymgr ื›ื“ื™ ืœื”ืฉื™ื’ ืื• ืœื”ื’ื“ื™ืจ ืืช ื”ืžืกืคืจ ื”ืกื™ื“ื•ืจื™ ืฉืœ SOA ืขื‘ื•ืจ ื”ืื–ื•ืจ ื”ื—ืชื•ื ื‘ืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ KASP;
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ื™ื™ื‘ื•ื โ€‹โ€‹ืžืคืชื—ื•ืช Ed25519 ื•-Ed448 ื‘ืคื•ืจืžื˜ ืฉืจืช BIND DNS ืœ-keymgr;
  • ื”ื’ื“ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ 'server.tcp-io-timeout' ื”ื•ื’ื“ืœื” ืœ-500 ms ื•-'database.journal-db-max-size' ื”ืฆื˜ืžืฆืžื” ืœ-512 MiB ื‘ืžืขืจื›ื•ืช 32 ืกื™ื‘ื™ื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”