ืžื”ื“ื•ืจืช BIND DNS Server 9.16.0

ืœืื—ืจ 11 ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื—, ืงื•ื ืกื•ืจืฆื™ื•ื ISC ื”ื’ื™ืฉื• ื”ืžื”ื“ื•ืจื” ื”ื™ืฆื™ื‘ื” ื”ืจืืฉื•ื ื” ืฉืœ ืกื ื™ืฃ ืžืฉืžืขื•ืชื™ ื—ื“ืฉ ืฉืœ ืฉืจืช BIND 9.16 DNS. ืกื ื™ืฃ 9.16 ื™ื™ืชืžืš ื‘ืžืฉืš ืฉืœื•ืฉ ืฉื ื™ื ืขื“ ืœืจื‘ืขื•ืŸ ื”ืฉื ื™ ืฉืœ 2 ื›ื—ืœืง ืžืžื—ื–ื•ืจ ืชื—ื–ื•ืงื” ืžื•ืจื—ื‘. ืขื“ื›ื•ื ื™ื ืขื‘ื•ืจ ืกื ื™ืฃ LTS ื”ืงื•ื“ื 2023 ื™ืžืฉื™ื›ื• ืœื”ืชืคืจืกื ืขื“ ื“ืฆืžื‘ืจ 9.11. ื”ืชืžื™ื›ื” ื‘ืกื ื™ืฃ 2021 ืชืกืชื™ื™ื ื‘ืขื•ื“ ืฉืœื•ืฉื” ื—ื•ื“ืฉื™ื.

ื”ืขื™ืงืจื™ ื—ื™ื“ื•ืฉื™ื:

  • ื ื•ืกืคื” KASP (ืžื“ื™ื ื™ื•ืช ืžืคืชื— ื•ื—ืชื™ืžื”), ื“ืจืš ืคืฉื•ื˜ื” ืœื ื”ืœ ืžืคืชื—ื•ืช DNSSEC ื•ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืขืœ ืกืžืš ื”ื’ื“ืจืช ื›ืœืœื™ื ืฉื”ื•ื’ื“ืจื• ื‘ืืžืฆืขื•ืช ื”ื ื—ื™ื™ืช "dnssec-policy". ื”ื ื—ื™ื” ื–ื• ืžืืคืฉืจืช ืœืš ืœื”ื’ื“ื™ืจ ืืช ื™ืฆื™ืจืช ื”ืžืคืชื—ื•ืช ื”ื—ื“ืฉื™ื ื”ื“ืจื•ืฉื™ื ืขื‘ื•ืจ ืื–ื•ืจื™ DNS ื•ืืช ื”ืฉื™ืžื•ืฉ ื”ืื•ื˜ื•ืžื˜ื™ ื‘ืžืคืชื—ื•ืช ZSK ื•-KSK.
  • ืชืช-ืžืขืจื›ืช ื”ืจืฉืช ืขื•ืฆื‘ื” ืžื—ื“ืฉ ื‘ืื•ืคืŸ ืžืฉืžืขื•ืชื™, ืืฉืจ ื”ื•ืขื‘ืจื” ืœืžื ื’ื ื•ืŸ ืขื™ื‘ื•ื“ ื”ื‘ืงืฉื•ืช ื”ืืกื™ื ื›ืจื•ื ื™ ื”ืžื™ื•ืฉื ืขืœ ื‘ืกื™ืก ื”ืกืคืจื™ื™ื” ืœื™ื‘ื•ื‘.
    ื”ืขื™ื‘ื•ื“ ื”ืžื—ื•ื“ืฉ ืขื“ื™ื™ืŸ ืœื ื‘ื™ืฆืข ืฉื™ื ื•ื™ื™ื ื’ืœื•ื™ื™ื, ืืš ื‘ืžื”ื“ื•ืจื•ืช ืขืชื™ื“ื™ื•ืช ื”ื•ื ื™ืกืคืง ื›ืžื” ืื•ืคื˜ื™ืžื™ื–ืฆื™ื•ืช ืžืฉืžืขื•ืชื™ื•ืช ืฉืœ ื‘ื™ืฆื•ืขื™ื ื•ื™ื•ืกื™ืฃ ืชืžื™ื›ื” ืœืคืจื•ื˜ื•ืงื•ืœื™ื ื—ื“ืฉื™ื ื›ื’ื•ืŸ DNS over TLS.

  • ื ื™ื”ื•ืœ ืžืฉื•ืคืจ ืฉืœ DNSSEC (ืขื•ื’ืŸ ืืžื•ืŸ) ืฉืœ ืžืคืชื— ืฆื™ื‘ื•ืจื™ ืฉืœ ืื–ื•ืจ ืœืื™ืžื•ืช ืื–ื•ืจ. ื‘ืžืงื•ื ื”ื’ื“ืจื•ืช ื”ืžืคืชื—ื•ืช ื”ืžื”ื™ืžื ื•ืช ื•ื”ืžืคืชื—ื•ืช ื”ืžื ื•ื”ืœื™ื ืฉื”ื•ืฆืื• ืžืฉื™ืžื•ืฉ, ื”ื•ืฆืขื” ื”ื ื—ื™ื” ื—ื“ืฉื” ืฉืœ ืขื•ื’ื ื™ ืืžื•ืŸ ืฉืชืืคืฉืจ ื ื™ื”ื•ืœ ืฉืœ ืฉื ื™ ืกื•ื’ื™ ื”ืžืคืชื—ื•ืช.

    ื›ืืฉืจ ืžืฉืชืžืฉื™ื ื‘ืขื•ื’ื ื™ ืืžื•ืŸ ืขื ืžื™ืœืช ื”ืžืคืชื— ื”ืจืืฉื•ื ื™ืช, ื”ื”ืชื ื”ื’ื•ืช ืฉืœ ื”ื ื—ื™ื” ื–ื• ื–ื”ื” ืœื”ืชื ื”ื’ื•ืช ืฉืœ ืžืคืชื—ื•ืช ืžื ื•ื”ืœื™ื, ื›ืœื•ืžืจ. ืžื’ื“ื™ืจ ื”ื’ื“ืจืช ืขื•ื’ืŸ ืืžื•ืŸ ืœืคื™ RFC 5011. ืžื’ื“ื™ืจ ืžืคืชื— ืงื‘ื•ืข ืฉืื™ื ื• ืžืชืขื“ื›ืŸ ืื•ื˜ื•ืžื˜ื™ืช. Trust-anchors ืžืกืคืง ื’ื ืฉืชื™ ืžื™ืœื•ืช ืžืคืชื— ื ื•ืกืคื•ืช, initial-ds ื•-static-ds , ื”ืžืืคืฉืจื•ืช ืœืš ืœื”ืฉืชืžืฉ ื‘ืขื•ื’ื ื™ ืืžื•ืŸ ื‘ืคื•ืจืžื˜ DS (Delegation Signer) ื‘ืžืงื•ื DNSKEY, ื”ืžืืคืฉืจ ืœื”ื’ื“ื™ืจ bindings ืœืžืคืชื—ื•ืช ืฉื˜ืจื ืคื•ืจืกืžื• (ื‘ืขืชื™ื“, ืืจื’ื•ืŸ IANA ืžืชื›ื ืŸ ืœื”ืฉืชืžืฉ ื‘ืคื•ืจืžื˜ DS ืœืžืคืชื—ื•ืช ืื–ื•ืจ ืœื™ื‘ื”).

  • ื ื•ืกืคื” ืืคืฉืจื•ืช "+yaml" ืœื—ืคื™ืจื”, mdig ื•-delv ืœืคืœื˜ ื‘ืคื•ืจืžื˜ YAML.
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "+[ืœื] ื‘ืœืชื™ ืฆืคื•ื™" ืœื—ืคื™ืจืช ื›ืœื™ ื›ื“ื™ ืœืืคืฉืจ ืชืฉื•ื‘ื•ืช ืžืžืืจื—ื™ื ืื—ืจื™ื ืžืœื‘ื“ ื”ืฉืจืช ืฉืืœื™ื• ื ืฉืœื—ื” ื”ื‘ืงืฉื”.
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "+[no]expandaaaa" ืœื—ืคื•ืจ ื›ื“ื™ ืœื”ืฆื™ื’ ื›ืชื•ื‘ื•ืช IPv6 ื‘ืจืฉื•ืžื•ืช AAAA ื‘ืกื™ืžื•ืŸ ืžืœื ืฉืœ 128 ืกื™ื‘ื™ื•ืช ื‘ืžืงื•ื ื‘ืคื•ืจืžื˜ RFC 5952.
  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ื—ืœื™ืฃ ืงื‘ื•ืฆื•ืช ืฉืœ ืขืจื•ืฆื™ ืกื˜ื˜ื™ืกื˜ื™ืงื”.
  • ืจืฉื•ืžื•ืช DS ื•-CDS ื ื•ืฆืจื•ืช ื›ืขืช ืจืง ื‘ื”ืชื‘ืกืก ืขืœ Hash SHA-256 (ื”ื“ื•ืจ ื”ืžื‘ื•ืกืก ืขืœ SHA-1 ื”ื•ืคืกืง).
  • ืขื‘ื•ืจ ืขื•ื’ื™ื•ืช DNS (RFC 7873), ืืœื’ื•ืจื™ืชื SipHash 2-4 ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื•ื”ืชืžื™ื›ื” ื‘-HMAC-SHA ื‘ื•ื˜ืœื” (AES ื ืฉืžืจ).
  • ื”ืคืœื˜ ืฉืœ ื”ืคืงื•ื“ื•ืช dnssec-signzone ื•-dnssec-verify ื ืฉืœื— ื›ืขืช ืœืคืœื˜ ืกื˜ื ื“ืจื˜ื™ (STDOUT), ื•ืจืง ืฉื’ื™ืื•ืช ื•ืื–ื”ืจื•ืช ืžื•ื“ืคืกื•ืช ืœ-STDERR (ื”ืื–ื•ืจ ื”ื—ืชื•ื ืžื•ื“ืคืก ื’ื ืื ืžืฆื•ื™ื ืช ืืคืฉืจื•ืช -f). ื ื•ืกืคื” ืืคืฉืจื•ืช "-q" ืœื”ืฉืชืงืช ื”ืคืœื˜.
  • ืงื•ื“ ื”ืื™ืžื•ืช ืฉืœ DNSSEC ืขื•ืฆื‘ ืžื—ื“ืฉ, ืฉื”ื•ื ืœืœื ืฉื›ืคื•ืœ ืงื•ื“ ืขื ืชืช-ืžืขืจื›ื•ืช ืื—ืจื•ืช.
  • ื›ื“ื™ ืœื”ืฆื™ื’ ื ืชื•ื ื™ื ืกื˜ื˜ื™ืกื˜ื™ื™ื ื‘ืคื•ืจืžื˜ JSON, ื›ืขืช ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ืจืง ื‘ืกืคืจื™ื™ืช JSON-C. ืฉืžื• ืฉืœ ืืคืฉืจื•ืช ื”ืชืฆื•ืจื” "--with-libjson" ืฉื•ื ื” ืœ-"--with-json-c".
  • ืกืงืจื™ืคื˜ ื”ืชืฆื•ืจื” ื›ื‘ืจ ืื™ื ื• ืžื•ื’ื“ืจ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืœ-"--sysconfdir" ื‘-/etc ื•-"--localstatedir" ืœ-/var, ืืœื ืื ืฆื•ื™ืŸ "--prefix". ื ืชื™ื‘ื™ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื ื›ืขืช $prefix/etc ื•-$prefix/var ื‘ืฉื™ืžื•ืฉ ืขืœ ื™ื“ื™ Autoconf.
  • ื”ื•ืกืจ ืงื•ื“ ื”ื˜ืžืขืช ืฉื™ืจื•ืช DLV (ืื™ืžื•ืช ืžื‘ื˜-ืฆื“ ืฉืœ ื“ื•ืžื™ื™ืŸ, ืืคืฉืจื•ืช dnssec-lookaside), ืฉื”ื•ืฆื ืžืฉื™ืžื•ืฉ ื‘-BIND 9.12 ื•ื”ืžื˜ืคืœ ื”ืžืฉื•ื™ืš ืœื• dlv.isc.org ื”ื•ืฉื‘ืช ื‘-2017. ื”ืกืจืช ื”-DLV ืฉื—ืจืจื” ืืช ืงื•ื“ BIND ืžืžื•ืจื›ื‘ื•ืช ืžื™ื•ืชืจืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”