Siideynta KnotDNS 2.9.0 server DNS

la daabacay sii daayo KnotDNS 2.9.0, Adeegga DNS ee awood-sare leh (recursor-ka waxaa loo qaabeeyey codsi gooni ah) kaas oo taageera dhammaan awoodaha DNS casriga ah. Mashruuca waxaa soo saaraya Czech name registry CZ.NIC, oo ku qoran C iyo qaybiyey shatiga ku haysta GPLv3.

KnotDNS waxaa lagu kala soocaa iyada oo diiradda saareysa habaynta weydiinta waxqabadka sare, taas oo ay u isticmaasho hirgelinta taxane badan oo inta badan aan xannibin taas oo si fiican u miisaanaysa nidaamyada SMP. Astaamaha sida ku-darka iyo tirtirida aagagga duulista, wareejinta aagagga u dhexeeya server-yada, DDNS (cusbooneysii firfircoonida), NSID (RFC 5001), EDNS0 iyo kordhinta DNSSEC (oo ay ku jiraan NSEC3), xaddididda heerka jawaabta (RRL) ayaa la bixiyaa.

Siideynta cusub:

  • Taageero buuxda ayaa loo hirgeliyay xisaabaadka kala duwan ee nambarada taxanaha ah (SOA) ee aag ku yaal server-yada sayidka iyo addoonsiga, marka aagga lagu caddeeyo saxiixa dhijitaalka ah ee server-ka addoonta;
  • Taageerada lagu daray diiwaanada leh kaararka duurjoogta ah ee moduleka geoip;
  • Goob cusub oo 'rrsig-pre-fresh' ayaa lagu daray DNSSEC si loo yareeyo inta jeer ee dhacdooyinka xaqiijinta aaga saxeexa dhijitaalka ah;
  • Lagu daray goobta "tcp-reuseport" si loo dejiyo qaabka SO_REUSEPORT(_LB) ee saldhigyada TCP;
  • Lagu daray "tcp-io-timeout" dejinta si loo xaddido wakhtiga soo socda ee hawlgallada I/O ee ka badan TCP;
  • Waxqabadka hawlgallada wax ka beddelka nuxurka aagga ayaa si weyn loo kordhiyey;
  • Taageerada dib-u-habaynta isku-xidhka shabakadaha iyo maamulayaasha waa la joojiyay, maadaama aan la samayn karin ka dib marka habka dib u dejiyo mudnaanta;
  • Dib-u-hawlgalkii hirgelinta Kukiyada DNS si ay si buuxda ugu hoggaansamaan qabyo-qoraalka qoraalka-ietf-dnsop-server-cookies;
  • Sida caadiga ah, xadka isku xirka TCP hadda wuxuu ku xaddidan yahay kala bar xadka qeexida faylka nidaamka, iyo tirada faylasha furan hadda waxay ku kooban tahay 1048576;
  • Markaad dooranayso tirada hawl-wadeennada la bilaabay, tirada CPU-yada hadda waa la isticmaalaa, laakiin aan ka yarayn 10;
  • Ikhtiyaar badan ayaa dib loo magacaabay, tusaale ahaan 'server.tcp-reply-timeout' oo loo bixiyay 'server.tcp-remote-io-timeout', 'server.max-tcp-clients' loona beddelay 'server.tcp-max-clients', 'template. journal-db' ilaa 'database.journal-db', iwm. Taageerada magacyadii hore waa la hayn doonaa ugu yaraan ilaa la sii daayo soo socda weyn.

Source: opennet.ru

Add a comment