ืชืžื™ื›ื” ื ื™ืกื™ื•ื ื™ืช ืขื‘ื•ืจ DNS-over-HTTPS ื ื•ืกืคื” ืœืฉืจืช BIND DNS

ืžืคืชื—ื™ ืฉืจืช BIND DNS ื”ื›ืจื™ื–ื• ืขืœ ื”ื•ืกืคืช ืชืžื™ื›ืช ืฉืจืช ืขื‘ื•ืจ ื˜ื›ื ื•ืœื•ื’ื™ื•ืช DNS over HTTPS (DoH, DNS over HTTPS) ื•-DNS over TLS (DoT, DNS over TLS), ื•ื›ืŸ ืžื ื’ื ื•ืŸ XFR-over-TLS ืœืื‘ื˜ื—ื” ื”ืขื‘ืจืช ื”ืชื•ื›ืŸ ืฉืœ ืื–ื•ืจื™ DNS ื‘ื™ืŸ ืฉืจืชื™ื. DoH ื–ืžื™ืŸ ืœื‘ื“ื™ืงื” ื‘ืžื”ื“ื•ืจื” 9.17, ื•ืชืžื™ื›ื” ื‘-DoT ืงื™ื™ืžืช ืžืื– ื’ืจืกื” 9.17.10. ืœืื—ืจ ื™ื™ืฆื•ื‘, ืชืžื™ื›ืช DoT ื•-DoH ืชื•ืขื‘ืจ ืœืื—ื•ืจ ืœืกื ื™ืฃ ื”ื™ืฆื™ื‘ 9.17.7.

ื™ื™ืฉื•ื ืคืจื•ื˜ื•ืงื•ืœ ื”-HTTP/2 ื”ืžืฉืžืฉ ื‘-DoH ืžื‘ื•ืกืก ืขืœ ื”ืฉื™ืžื•ืฉ ื‘ืกืคืจื™ื™ืช nghttp2, ื”ื ื›ืœืœืช ื‘ื™ืŸ ืชืœื•ื™ื•ืช ื”-assembly (ื‘ืขืชื™ื“, ื”ืกืคืจื™ื™ื” ืžืชื•ื›ื ื ืช ืœืขื‘ื•ืจ ืœืžืกืคืจ ื”ืชืœื•ืช ื”ืื•ืคืฆื™ื•ื ืœื™ืช). ื’ื ื—ื™ื‘ื•ืจื™ HTTP/2 ืžื•ืฆืคื ื™ื (TLS) ื•ื’ื ืœื ืžื•ืฆืคื ื™ื ื ืชืžื›ื™ื. ืขื ื”ื”ื’ื“ืจื•ืช ื”ืžืชืื™ืžื•ืช, ืชื”ืœื™ืš ื‘ืขืœ ืฉื ื™ื—ื™ื“ ื™ื›ื•ืœ ื›ืขืช ืœืฉืจืช ืœื ืจืง ืฉืื™ืœืชื•ืช DNS ืžืกื•ืจืชื™ื•ืช, ืืœื ื’ื ืฉืื™ืœืชื•ืช ืฉื ืฉืœื—ื•ืช ื‘ืืžืฆืขื•ืช DoH (DNS-over-HTTPS) ื•-DoT (DNS-over-TLS). ืชืžื™ื›ืช HTTPS ื‘ืฆื“ ื”ืœืงื•ื— (dig) ืขื“ื™ื™ืŸ ืœื ืžื™ื•ืฉืžืช. ืชืžื™ื›ืช XFR-over-TLS ื–ืžื™ื ื” ืขื‘ื•ืจ ื‘ืงืฉื•ืช ื ื›ื ืกื•ืช ื•ื™ื•ืฆืื•ืช ื›ืื—ื“.

ืขื™ื‘ื•ื“ ื‘ืงืฉื•ืช ื‘ืืžืฆืขื•ืช DoH ื•-DoT ืžื•ืคืขืœ ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ื”ืืคืฉืจื•ื™ื•ืช http ื•-tls ืœื”ื ื—ื™ื™ืช ื”ื”ืื–ื ื”. ื›ื“ื™ ืœืชืžื•ืš ื‘-DNS-over-HTTP ืœื ืžื•ืฆืคืŸ, ืขืœื™ืš ืœืฆื™ื™ืŸ "tls none" ื‘ื”ื’ื“ืจื•ืช. ืžืคืชื—ื•ืช ืžื•ื’ื“ืจื™ื ื‘ืกืขื™ืฃ "tls". ื ื™ืชืŸ ืœืขืงื•ืฃ ืืช ื™ืฆื™ืื•ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ื”ืจืฉืช 853 ืขื‘ื•ืจ DoT, 443 ืขื‘ื•ืจ DoH ื•-80 ืขื‘ื•ืจ DNS-over-HTTP ื‘ืืžืฆืขื•ืช ื”ืคืจืžื˜ืจื™ื tls-port, https-port ื•-http-port. ืœื“ื•ื’ืžื”: tls local-tls { key-file "/path/to/priv_key.pem"; cert-file "/path/to/cert_chain.pem"; }; http local-http-server { endpoints { "/dns-query"; }; }; options { https-port 443; ื™ืฆื™ืืช ื”ืื–ื ื” 443 tls local-tls http myserver {any;}; }

ื‘ื™ืŸ ื”ืžืืคื™ื™ื ื™ื ืฉืœ ื™ื™ืฉื•ื DoH ื‘-BIND, ื”ืื™ื ื˜ื’ืจืฆื™ื” ืžืฆื•ื™ื ืช ื›ืชื—ื‘ื•ืจื” ื›ืœืœื™ืช, ืืฉืจ ื™ื›ื•ืœื” ืœืฉืžืฉ ืœื ืจืง ืœืขื™ื‘ื•ื“ ื‘ืงืฉื•ืช ืœืงื•ื— ืœืคื•ืชืจ, ืืœื ื’ื ื‘ืขืช ื—ื™ืœื•ืคื™ ื ืชื•ื ื™ื ื‘ื™ืŸ ืฉืจืชื™ื, ื‘ืขืช ื”ืขื‘ืจืช ืื–ื•ืจื™ื ืขืœ ื™ื“ื™ ืฉืจืช DNS ืกืžื›ื•ืชื™, ื•ื›ืŸ ื‘ืขืช ืขื™ื‘ื•ื“ ื›ืœ ื‘ืงืฉื•ืช ื”ื ืชืžื›ื•ืช ืขืœ ื™ื“ื™ ื”ืขื‘ืจื•ืช DNS ืื—ืจื•ืช.

ืชื›ื•ื ื” ื ื•ืกืคืช ื”ื™ื ื”ื™ื›ื•ืœืช ืœื”ืขื‘ื™ืจ ืืช ืคืขื•ืœื•ืช ื”ื”ืฆืคื ื” ืขื‘ื•ืจ TLS ืœืฉืจืช ืื—ืจ, ื“ื‘ืจ ืฉืขืฉื•ื™ ืœื”ื™ื•ืช ื ื—ื•ืฅ ื‘ืชื ืื™ื ืฉื‘ื”ื ืชืขื•ื“ื•ืช TLS ืžืื•ื—ืกื ื•ืช ื‘ืžืขืจื›ืช ืื—ืจืช (ืœื“ื•ื’ืžื”, ื‘ืชืฉืชื™ืช ืขื ืฉืจืชื™ ืื™ื ื˜ืจื ื˜) ื•ืžืชื•ื—ื–ืงื•ืช ืขืœ ื™ื“ื™ ื›ื•ื— ืื“ื ืื—ืจ. ืชืžื™ื›ื” ื‘-DNS-over-HTTP ืœื ืžื•ืฆืคืŸ ืžื™ื•ืฉืžืช ื›ื“ื™ ืœืคืฉื˜ ืืช ืื™ืชื•ืจ ื”ื‘ืื’ื™ื ื•ื›ืฉื›ื‘ื” ืœื”ืขื‘ืจื” ื‘ืจืฉืช ื”ืคื ื™ืžื™ืช, ืฉืขืœ ื‘ืกื™ืกื” ื ื™ืชืŸ ืœืืจื’ืŸ ื”ืฆืคื ื” ื‘ืฉืจืช ืื—ืจ. ื‘ืฉืจืช ืžืจื•ื—ืง, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-nginx ืœื™ืฆื™ืจืช ืชืขื‘ื•ืจืช TLS, ื‘ื“ื•ืžื” ืœืื•ืคืŸ ืฉื‘ื• ืžืื•ืจื’ื ืช ืงืฉื™ืจืช HTTPS ืขื‘ื•ืจ ืืชืจื™ ืื™ื ื˜ืจื ื˜.

ื ื–ื›ื™ืจ ืฉ-DNS-over-HTTPS ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ ืœืžื ื™ืขืช ื“ืœื™ืคื•ืช ืžื™ื“ืข ืขืœ ืฉืžื•ืช ื”ืžืืจื—ื™ื ื”ืžื‘ื•ืงืฉื™ื ื“ืจืš ืฉืจืชื™ ื”-DNS ืฉืœ ืกืคืงื™ื, ืžืื‘ืง ื‘ื”ืชืงืคื•ืช MITM ื•ื‘ื–ื™ื•ืฃ ืชืขื‘ื•ืจืช DNS (ืœื“ื•ื’ืžื”, ื‘ืขืช ื—ื™ื‘ื•ืจ ืœ-Wi-Fi ืฆื™ื‘ื•ืจื™), ืžื ื™ืขืช ื—ืกื™ืžื” ืคื•ืขืœืช ื‘ืจืžืช ื”-DNS (DNS-over-HTTPS ืœื ื™ื›ื•ืœ ืœื”ื—ืœื™ืฃ VPN ื‘ืขืงื™ืคืช ื—ืกื™ืžื” ื”ืžื™ื•ืฉืžืช ื‘ืจืžืช DPI) ืื• ืœืืจื’ื•ืŸ ืขื‘ื•ื“ื” ื›ืืฉืจ ืื™ ืืคืฉืจ ืœื’ืฉืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS (ืœื“ื•ื’ืžื”, ื‘ืขื‘ื•ื“ื” ื“ืจืš ืคืจื•ืงืกื™). ืื ื‘ืžืฆื‘ ืจื’ื™ืœ ื‘ืงืฉื•ืช DNS ื ืฉืœื—ื•ืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS ื”ืžื•ื’ื“ืจื™ื ื‘ืชืฆื•ืจืช ื”ืžืขืจื›ืช, ืื– ื‘ืžืงืจื” ืฉืœ DNS-over-HTTPS ื”ื‘ืงืฉื” ืœืงื‘ื™ืขืช ื›ืชื•ื‘ืช ื”-IP ื”ืžืืจื— ืžื•ื‘ืœืขืช ื‘ืชืขื‘ื•ืจืช HTTPS ื•ื ืฉืœื—ืช ืœืฉืจืช HTTP, ืฉื ื”ืคื•ืชืจ ืžืขื‘ื“ ื‘ืงืฉื•ืช ื‘ืืžืฆืขื•ืช Web API.

"DNS over TLS" ืฉื•ื ื” ืž-"DNS over HTTPS" ื‘ืฉื™ืžื•ืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ DNS ื”ืกื˜ื ื“ืจื˜ื™ (ื‘ื“ืจืš ื›ืœืœ ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื™ืฆื™ืืช ืจืฉืช 853), ืขื˜ื•ืฃ ื‘ืขืจื•ืฅ ืชืงืฉื•ืจืช ืžื•ืฆืคืŸ ื”ืžืื•ืจื’ืŸ ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ TLS ืขื ื‘ื“ื™ืงืช ืชืงืคื•ืช ื”ืžืืจื— ื‘ืืžืฆืขื•ืช ืชืขื•ื“ื•ืช TLS/SSL ืžืื•ืฉืจื•ืช ืขืœ ื™ื“ื™ ืจืฉื•ืช ืื™ืฉื•ืจื™ื. ืชืงืŸ DNSSEC ื”ืงื™ื™ื ืžืฉืชืžืฉ ื‘ื”ืฆืคื ื” ืจืง ื›ื“ื™ ืœืืžืช ืืช ื”ืœืงื•ื— ื•ื”ืฉืจืช, ืืš ืื™ื ื• ืžื’ืŸ ืขืœ ื”ืชืขื‘ื•ืจื” ืžืคื ื™ ื™ื™ืจื•ื˜ ื•ืื™ื ื• ืžื‘ื˜ื™ื— ืืช ืกื•ื“ื™ื•ืช ื”ื‘ืงืฉื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”