ืฉื—ืจื•ืจ ืฉืœ BIND DNS Server 9.18.0 ืขื ืชืžื™ื›ื” ื‘-DNS-over-TLS ื•-DNS-over-HTTPS

ืœืื—ืจ ืฉื ืชื™ื™ื ืฉืœ ืคื™ืชื•ื—, ืงื•ื ืกื•ืจืฆื™ื•ื ISC ืคืจืกื ืืช ื”ืžื”ื“ื•ืจื” ื”ื™ืฆื™ื‘ื” ื”ืจืืฉื•ื ื” ืฉืœ ืกื ื™ืฃ ื—ื“ืฉ ื•ื’ื“ื•ืœ ืฉืœ ืฉืจืช BIND 9.18 DNS. ืชืžื™ื›ื” ื‘ืกื ื™ืฃ 9.18 ืชื™ื ืชืŸ ืœืžืฉืš ืฉืœื•ืฉ ืฉื ื™ื ืขื“ ื”ืจื‘ืขื•ืŸ ื”ืฉื ื™ ืฉืœ ืฉื ืช 2 ื›ื—ืœืง ืžืžื—ื–ื•ืจ ืชืžื™ื›ื” ืžื•ืจื—ื‘. ื”ืชืžื™ื›ื” ื‘ืกื ื™ืฃ 2025 ืชืกืชื™ื™ื ื‘ืžืจืฅ, ื•ื”ืชืžื™ื›ื” ื‘ืกื ื™ืฃ 9.11 ื‘ืืžืฆืข 9.16. ื›ื“ื™ ืœืคืชื— ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ ื”ื’ืจืกื” ื”ื™ืฆื™ื‘ื” ื”ื‘ืื” ืฉืœ BIND, ื ื•ืฆืจ ืขื ืฃ ื ื™ืกื™ื•ื ื™ BIND 2023.

ื”ืฉื—ืจื•ืจ ืฉืœ BIND 9.18.0 ื‘ื•ืœื˜ ื‘ื”ื˜ืžืขืช ืชืžื™ื›ื” ื‘-DNS ืขืœ HTTPS (DoH, DNS ืขืœ HTTPS) ื•-DNS over TLS (DoT, DNS over TLS), ื›ืžื• ื’ื ื‘ืžื ื’ื ื•ืŸ XoT (XFR-over-TLS) ืœื”ืขื‘ืจื” ืžืื•ื‘ื˜ื—ืช ืฉืœ ืชื•ื›ืŸ DNS.ืื–ื•ืจื™ ื‘ื™ืŸ ืฉืจืชื™ื (ื’ื ืื–ื•ืจื™ ืฉืœื™ื—ื” ื•ื’ื ืื–ื•ืจื™ ืงื‘ืœื” ื‘ืืžืฆืขื•ืช XoT ื ืชืžื›ื™ื). ืขื ื”ื”ื’ื“ืจื•ืช ื”ืžืชืื™ืžื•ืช, ืชื”ืœื™ืš ื‘ืขืœ ืฉื ื™ื—ื™ื“ ื™ื›ื•ืœ ื›ืขืช ืœืฉืจืช ืœื ืจืง ืฉืื™ืœืชื•ืช DNS ืžืกื•ืจืชื™ื•ืช, ืืœื ื’ื ืฉืื™ืœืชื•ืช ืฉื ืฉืœื—ื•ืช ื‘ืืžืฆืขื•ืช DNS-over-HTTPS ื•-DNS-over-TLS. ืชืžื™ื›ืช ืœืงื•ื— ืขื‘ื•ืจ DNS-over-TLS ืžื•ื‘ื ื™ืช ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช ืœื—ืคื™ืจื”, ืืฉืจ ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื” ื›ื“ื™ ืœืฉืœื•ื— ื‘ืงืฉื•ืช ื‘ืืžืฆืขื•ืช TLS ื›ืืฉืจ ื“ื’ืœ "+tls" ืžืฆื•ื™ืŸ.

ื”ื™ื™ืฉื•ื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ HTTP/2 ื”ืžืฉืžืฉ ื‘-DoH ืžื‘ื•ืกืก ืขืœ ื”ืฉื™ืžื•ืฉ ื‘ืกืคืจื™ื™ืช nghttp2, ื”ื ื›ืœืœืช ื›ืชืœื•ืช assembly ืื•ืคืฆื™ื•ื ืœื™ืช. ืื™ืฉื•ืจื™ื ืขื‘ื•ืจ DoH ื•-DoT ื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ืžืกื•ืคืงื™ื ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ ืื• ืœื”ืคื™ืง ืื•ื˜ื•ืžื˜ื™ืช ื‘ื–ืžืŸ ื”ื”ืคืขืœื”.

ืขื™ื‘ื•ื“ ื‘ืงืฉื•ืช ื‘ืืžืฆืขื•ืช DoH ื•-DoT ืžื•ืคืขืœ ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ื”ืืคืฉืจื•ื™ื•ืช "http" ื•- "tls" ืœื”ื ื—ื™ื™ืช ื”ื”ืื–ื ื”. ื›ื“ื™ ืœืชืžื•ืš ื‘-DNS-over-HTTP ืœื ืžื•ืฆืคืŸ, ืขืœื™ืš ืœืฆื™ื™ืŸ "tls none" ื‘ื”ื’ื“ืจื•ืช. ืžืคืชื—ื•ืช ืžื•ื’ื“ืจื™ื ื‘ืกืขื™ืฃ "tls". ื ื™ืชืŸ ืœืขืงื•ืฃ ืืช ื™ืฆื™ืื•ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ื”ืจืฉืช 853 ืขื‘ื•ืจ DoT, 443 ืขื‘ื•ืจ DoH ื•-80 ืขื‘ื•ืจ DNS-over-HTTP ื‘ืืžืฆืขื•ืช ื”ืคืจืžื˜ืจื™ื tls-port, https-port ื•-http-port. ืœื“ื•ื’ืžื”:

tls local-tls { key-file "/path/to/priv_key.pem"; cert-file "/path/to/cert_chain.pem"; }; http local-http-server { endpoints { "/dns-query"; }; }; options { https-port 443; ื™ืฆื™ืืช ื”ืื–ื ื” 443 tls local-tls http myserver {any;}; }

ืื—ืช ื”ืชื›ื•ื ื•ืช ืฉืœ ื”ื˜ืžืขืช DoH ื‘-BIND ื”ื™ื ื”ื™ื›ื•ืœืช ืœื”ืขื‘ื™ืจ ืคืขื•ืœื•ืช ื”ืฆืคื ื” ืขื‘ื•ืจ TLS ืœืฉืจืช ืื—ืจ, ื“ื‘ืจ ืฉืขืฉื•ื™ ืœื”ื™ื•ืช ื ื—ื•ืฅ ื‘ืชื ืื™ื ืฉื‘ื”ื ืชืขื•ื“ื•ืช TLS ืžืื•ื—ืกื ื•ืช ื‘ืžืขืจื›ืช ืื—ืจืช (ืœื“ื•ื’ืžื”, ื‘ืชืฉืชื™ืช ืขื ืฉืจืชื™ ืื™ื ื˜ืจื ื˜) ื•ืžืชื•ื—ื–ืงื•ืช ืขืœ ื™ื“ื™ ื›ื•ื— ืื“ื ืื—ืจ. ืชืžื™ื›ื” ื‘-DNS-over-HTTP ืœื ืžื•ืฆืคืŸ ืžื™ื•ืฉืžืช ื›ื“ื™ ืœืคืฉื˜ ืืช ื ื™ืคื•ื™ ื”ื‘ืื’ื™ื ื•ื›ืฉื›ื‘ื” ืœื”ืขื‘ืจื” ืœืฉืจืช ืื—ืจ ื‘ืจืฉืช ื”ืคื ื™ืžื™ืช (ืœื”ืขื‘ืจืช ื”ืฆืคื ื” ืœืฉืจืช ื ืคืจื“). ื‘ืฉืจืช ืžืจื•ื—ืง, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-nginx ืœื™ืฆื™ืจืช ืชืขื‘ื•ืจืช TLS, ื‘ื“ื•ืžื” ืœืื•ืคืŸ ืฉื‘ื• ืžืื•ืจื’ื ืช ืงืฉื™ืจืช HTTPS ืขื‘ื•ืจ ืืชืจื™ ืื™ื ื˜ืจื ื˜.

ืชื›ื•ื ื” ื ื•ืกืคืช ื”ื™ื ื”ืฉื™ืœื•ื‘ ืฉืœ DoH ื›ืชื—ื‘ื•ืจื” ื›ืœืœื™ืช ืฉื™ื›ื•ืœื” ืœืฉืžืฉ ืœื ืจืง ืœื˜ื™ืคื•ืœ ื‘ื‘ืงืฉื•ืช ืœืงื•ื— ืœืคื•ืชืจ, ืืœื ื’ื ื‘ืขืช ืชืงืฉื•ืจืช ื‘ื™ืŸ ืฉืจืชื™ื, ื‘ืขืช ื”ืขื‘ืจืช ืื–ื•ืจื™ื ืขืœ ื™ื“ื™ ืฉืจืช DNS ืกืžื›ื•ืชื™, ื•ื‘ืขืช ืขื™ื‘ื•ื“ ื›ืœ ืฉืื™ืœืชื” ื”ื ืชืžื›ืช ืขืœ ื™ื“ื™ DNS ืื—ืจ. ื”ื•ื‘ืœื•ืช.

ื‘ื™ืŸ ื”ื—ืกืจื•ื ื•ืช ืฉื ื™ืชืŸ ืœืคืฆื•ืช ืขืœื™ื”ื ืขืœ ื™ื“ื™ ื‘ื™ื˜ื•ืœ ื”ื‘ื ื™ื™ื” ืขื DoH/DoT ืื• ื”ืขื‘ืจืช ื”ื”ืฆืคื ื” ืœืฉืจืช ืื—ืจ, ื‘ื•ืœื˜ืช ื”ืกื™ื‘ื•ืš ื”ื›ืœืœื™ ืฉืœ ื‘ืกื™ืก ื”ืงื•ื“ - ืžืชื•ื•ืกืคื™ื ืฉืจืช HTTP ืžื•ื‘ื ื” ื•ืกืคืจื™ื™ืช TLS, ืฉืขืœื•ืœื™ื ืœื”ื›ื™ืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื•ืœืคืขื•ืœ ื›ื•ื•ืงื˜ื•ืจื™ื ื ื•ืกืคื™ื ืœื”ืชืงืคื•ืช. ื›ืžื• ื›ืŸ, ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-DoH, ื”ืชืขื‘ื•ืจื” ื’ื“ืœื”.

ื ื–ื›ื™ืจ ืฉ-DNS-over-HTTPS ื™ื›ื•ืœ ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ ืœืžื ื™ืขืช ื“ืœื™ืคื•ืช ืžื™ื“ืข ืขืœ ืฉืžื•ืช ื”ืžืืจื—ื™ื ื”ืžื‘ื•ืงืฉื™ื ื“ืจืš ืฉืจืชื™ ื”-DNS ืฉืœ ืกืคืงื™ื, ืžืื‘ืง ื‘ื”ืชืงืคื•ืช MITM ื•ื‘ื–ื™ื•ืฃ ืชืขื‘ื•ืจืช DNS (ืœื“ื•ื’ืžื”, ื‘ืขืช ื—ื™ื‘ื•ืจ ืœ-Wi-Fi ืฆื™ื‘ื•ืจื™), ืžื ื™ืขืช ื—ืกื™ืžื” ืคื•ืขืœืช ื‘ืจืžืช ื”-DNS (DNS-over-HTTPS ืœื ื™ื›ื•ืœ ืœื”ื—ืœื™ืฃ VPN ื‘ืขืงื™ืคืช ื—ืกื™ืžื” ื”ืžื™ื•ืฉืžืช ื‘ืจืžืช DPI) ืื• ืœืืจื’ื•ืŸ ืขื‘ื•ื“ื” ื›ืืฉืจ ืื™ ืืคืฉืจ ืœื’ืฉืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS (ืœื“ื•ื’ืžื”, ื‘ืขื‘ื•ื“ื” ื“ืจืš ืคืจื•ืงืกื™). ืื ื‘ืžืฆื‘ ืจื’ื™ืœ ื‘ืงืฉื•ืช DNS ื ืฉืœื—ื•ืช ื™ืฉื™ืจื•ืช ืœืฉืจืชื™ DNS ื”ืžื•ื’ื“ืจื™ื ื‘ืชืฆื•ืจืช ื”ืžืขืจื›ืช, ืื– ื‘ืžืงืจื” ืฉืœ DNS-over-HTTPS ื”ื‘ืงืฉื” ืœืงื‘ื™ืขืช ื›ืชื•ื‘ืช ื”-IP ื”ืžืืจื— ืžื•ื‘ืœืขืช ื‘ืชืขื‘ื•ืจืช HTTPS ื•ื ืฉืœื—ืช ืœืฉืจืช HTTP, ืฉื ื”ืคื•ืชืจ ืžืขื‘ื“ ื‘ืงืฉื•ืช ื‘ืืžืฆืขื•ืช Web API.

"DNS over TLS" ืฉื•ื ื” ืž-"DNS over HTTPS" ื‘ืฉื™ืžื•ืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ DNS ื”ืกื˜ื ื“ืจื˜ื™ (ื‘ื“ืจืš ื›ืœืœ ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื™ืฆื™ืืช ืจืฉืช 853), ืขื˜ื•ืฃ ื‘ืขืจื•ืฅ ืชืงืฉื•ืจืช ืžื•ืฆืคืŸ ื”ืžืื•ืจื’ืŸ ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ TLS ืขื ื‘ื“ื™ืงืช ืชืงืคื•ืช ื”ืžืืจื— ื‘ืืžืฆืขื•ืช ืชืขื•ื“ื•ืช TLS/SSL ืžืื•ืฉืจื•ืช ืขืœ ื™ื“ื™ ืจืฉื•ืช ืื™ืฉื•ืจื™ื. ืชืงืŸ DNSSEC ื”ืงื™ื™ื ืžืฉืชืžืฉ ื‘ื”ืฆืคื ื” ืจืง ื›ื“ื™ ืœืืžืช ืืช ื”ืœืงื•ื— ื•ื”ืฉืจืช, ืืš ืื™ื ื• ืžื’ืŸ ืขืœ ื”ืชืขื‘ื•ืจื” ืžืคื ื™ ื™ื™ืจื•ื˜ ื•ืื™ื ื• ืžื‘ื˜ื™ื— ืืช ืกื•ื“ื™ื•ืช ื”ื‘ืงืฉื•ืช.

ืขื•ื“ ื›ืžื” ื—ื™ื“ื•ืฉื™ื:

  • ื ื•ืกืคื• ื”ื’ื“ืจื•ืช tcp-receive-buffer, tcp-send-buffer, udp-receive-buffer ื•-udp-send-buffer ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื”ื’ื“ืœื™ื ืฉืœ ืžืื’ืจื™ื ื”ืžืฉืžืฉื™ื ื‘ืขืช ืฉืœื™ื—ื” ื•ืงื‘ืœื” ืฉืœ ื‘ืงืฉื•ืช ื“ืจืš TCP ื•-UDP. ื‘ืฉืจืชื™ื ืขืžื•ืกื™ื, ื”ื’ื“ืœืช ืžืื’ืจื™ื ื ื›ื ืกื™ื ืชืขื–ื•ืจ ืœืžื ื•ืข ื ืคื™ืœืช ืžื ื•ืช ื‘ืžื”ืœืš ืฉื™ื ื”ืชืขื‘ื•ืจื”, ื•ื”ืงื˜ื ืชื ืชืขื–ื•ืจ ืœื”ื™ืคื˜ืจ ืžื—ืกื™ืžืช ื–ื™ื›ืจื•ืŸ ืขื ื‘ืงืฉื•ืช ื™ืฉื ื•ืช.
  • ื ื•ืกืคื” ืงื˜ื’ื•ืจื™ื™ืช ื™ื•ืžืŸ ื—ื“ืฉื” "rpz-passthru", ื”ืžืืคืฉืจืช ืœืš ืœืจืฉื•ื ื‘ื ืคืจื“ ืคืขื•ืœื•ืช ื”ืขื‘ืจืช RPZ (Response Policy Zones).
  • ื‘ืกืขื™ืฃ ืžื“ื™ื ื™ื•ืช ื”ืชื’ื•ื‘ื”, ื ื•ืกืคื” ื”ืืคืฉืจื•ืช "nsdname-wait-recurse", ื›ืืฉืจ ื”ื™ื ืžื•ื’ื“ืจืช ื›"ืœื", ื›ืœืœื™ RPZ NSDNAME ืžื™ื•ืฉืžื™ื ืจืง ืื ื ืžืฆืื• ืฉืจืชื™ ืฉืžื•ืช ืกืžื›ื•ืชื™ื™ื ื”ื ืžืฆืื™ื ื‘ืžื˜ืžื•ืŸ ืขื‘ื•ืจ ื”ื‘ืงืฉื”, ืื—ืจืช ืžืชืขืœืžื™ื ืžื›ืœืœ RPZ NSDNAME, ืืš ื”ืžื™ื“ืข ืžืื•ื—ื–ืจ ื‘ืจืงืข ื•ื—ืœ ืขืœ ื‘ืงืฉื•ืช ืขื•ืงื‘ื•ืช.
  • ืขื‘ื•ืจ ืจืฉื•ืžื•ืช ืขื ืกื•ื’ื™ HTTPS ื•-SVCB, ืขื™ื‘ื•ื“ ืฉืœ ื”ืกืขื™ืฃ "ื ื•ืกืฃ" ื™ื•ืฉื.
  • ื ื•ืกืคื• ืกื•ื’ื™ ื›ืœืœื™ ืžื“ื™ื ื™ื•ืช ืขื“ื›ื•ืŸ ืžื•ืชืืžื™ื ืื™ืฉื™ืช - krb5-subdomain-self-rhs ื•-ms-subdomain-self-rhs, ื”ืžืืคืฉืจื™ื ืœืš ืœื”ื’ื‘ื™ืœ ืืช ื”ืขื“ื›ื•ืŸ ืฉืœ ืจืฉื•ืžื•ืช SRV ื•-PTR. ื‘ืœื•ืงื™ื ืฉืœ ืžื“ื™ื ื™ื•ืช ื”ืขื“ื›ื•ื ื™ื ืžื•ืกื™ืคื™ื ื’ื ืืช ื”ื™ื›ื•ืœืช ืœื”ื’ื“ื™ืจ ืžื’ื‘ืœื•ืช ืขืœ ืžืกืคืจ ื”ืจืฉื•ืžื•ืช, ืื™ื ื“ื™ื‘ื™ื“ื•ืืœื™ื•ืช ืœื›ืœ ืกื•ื’.
  • ื”ื•ืกื™ืฃ ืžื™ื“ืข ืขืœ ืคืจื•ื˜ื•ืงื•ืœ ื”ืชื—ื‘ื•ืจื” (UDP, TCP, TLS, HTTPS) ื•ืงื™ื“ื•ืžื•ืช DNS64 ืœืคืœื˜ ืฉืœ ื›ืœื™ ื”ืฉื™ืจื•ืช dig. ืœืžื˜ืจื•ืช ื ื™ืคื•ื™ ื‘ืื’ื™ื, dig ื”ื•ืกื™ืคื” ืืช ื”ื™ื›ื•ืœืช ืœืฆื™ื™ืŸ ืžื–ื”ื” ื‘ืงืฉื” ืกืคืฆื™ืคื™ (dig +qid= ).
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืกืคืจื™ื™ืช OpenSSL 3.0.
  • ื›ื“ื™ ืœื˜ืคืœ ื‘ื‘ืขื™ื•ืช ืขื ืคื™ืฆื•ืœ IP ื‘ืขืช ืขื™ื‘ื•ื“ ื”ื•ื“ืขื•ืช DNS ื’ื“ื•ืœื•ืช ืฉื–ื•ื”ื• ืขืœ ื™ื“ื™ DNS Flag Day 2020, ื”ื•ืกืจ ืžื”ืคื•ืชืจ ืงื•ื“ ืฉืžืชืื™ื ืืช ื’ื•ื“ืœ ืžืื’ืจ ื”-EDNS ื›ืืฉืจ ืื™ืŸ ืชื’ื•ื‘ื” ืœื‘ืงืฉื”. ื’ื•ื“ืœ ื”ืžืื’ืจ ืฉืœ EDNS ืžื•ื’ื“ืจ ื›ืขืช ืœืงื‘ื•ืข (edns-udp-size) ืขื‘ื•ืจ ื›ืœ ื”ื‘ืงืฉื•ืช ื”ื™ื•ืฆืื•ืช.
  • ืžืขืจื›ืช ื”ื‘ื ื™ื™ื” ื”ื•ืขื‘ืจื” ืœืฉื™ืžื•ืฉ ื‘ืฉื™ืœื•ื‘ ืฉืœ autoconf, automake ื•-libtool.
  • ื”ืชืžื™ื›ื” ื‘ืงื‘ืฆื™ ืื–ื•ืจ ื‘ืคื•ืจืžื˜ "ืžืคื”" (ืžืคื” ื‘ืคื•ืจืžื˜ ืงื•ื‘ืฅ ืžืืกื˜ืจ) ื”ื•ืคืกืงื”. ืœืžืฉืชืžืฉื™ื ื‘ืคื•ืจืžื˜ ื–ื” ืžื•ืžืœืฅ ืœื”ืžื™ืจ ืื–ื•ืจื™ื ืœืคื•ืจืžื˜ ื’ื•ืœืžื™ ื‘ืืžืฆืขื•ืช ื›ืœื™ ื”ืฉื™ืจื•ืช named-compilezone.
  • ื”ื•ืคืกืงื” ื”ืชืžื™ื›ื” ื‘ืžื ื”ืœื™ ื”ืชืงื ื™ื ื™ืฉื ื™ื ื™ื•ืชืจ ืฉืœ DLZ (ืื–ื•ืจื™ื ื ื™ืชื ื™ื ืœื˜ืขื™ื ื” ื“ื™ื ืžื™ืช), ื•ื”ื•ื—ืœืคื• ื‘ืžื•ื“ื•ืœื™ DLZ.
  • ื”ืชืžื™ื›ื” ื‘ื‘ื ื™ื™ื” ื•ื”ืจืฆื” ืฉืœ ืคืœื˜ืคื•ืจืžืช Windows ื”ื•ืคืกืงื”. ื”ืขื ืฃ ื”ืื—ืจื•ืŸ ืฉื ื™ืชืŸ ืœื”ืชืงื™ืŸ ื‘-Windows ื”ื•ื BIND 9.16.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”