ืžืขืœื“ื•ื ื’ ืคื•ืŸ PowerDNS ืจืขืงื•ืจืกืึธืจ 4.3 ืื•ืŸ KnotDNS 2.9.3

ืคืืจื’ืขืงื•ืžืขืŸ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ืงืึทื˜ืฉื™ื ื’ ื“ื ืก ืกืขืจื•ื•ืขืจ PowerDNS Resource 4.3, ืคืึทืจืึทื ื˜ื•ื•ืึธืจื˜ืœืขืš ืคึฟืึทืจ ืจืขืงื•ืจืกื™ื•ื•ืข ื ืึธืžืขืŸ ืงืึทื ื•ื•ืขืจื–ืฉืึทืŸ. PowerDNS ืจืขืงื•ืจืกืึธืจ ืื™ื– ื’ืขื‘ื•ื™ื˜ ืื•ื™ืฃ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืงืึธื“ ื‘ืึทื–ืข ื•ื•ื™ PowerDNS Authoritative Server, ืึธื‘ืขืจ PowerDNS ืจืขืงื•ืจืกื™ื•ื•ืข ืื•ืŸ ืึทื˜ืึธืจืึทื˜ื™ื™ื˜ื™ื•ื• ื“ื ืก ืกืขืจื•ื•ืขืจืก ื–ืขื ืขืŸ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš ืคืึทืจืฉื™ื“ืขื ืข ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ืกื™ื™ืงืึทืœื– ืื•ืŸ ื–ืขื ืขืŸ ืจืขืœืขืึทืกืขื“ ื•ื•ื™ ื‘ืึทื–ื•ื ื“ืขืจ ืคึผืจืึธื“ื•ืงื˜ืŸ. ืคึผืจืึธื™ืขืงื˜ ืงืึธื“ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ื“ื•ืจืš ืœื™ื™ืกืึทื ืกื˜ ืื•ื ื˜ืขืจ GPLv2.

ื“ืขืจ ืกืขืจื•ื•ืขืจ ื’ื™ื˜ ืžื›ืฉื™ืจื™ื ืคึฟืึทืจ ื–ืึทืžืœื•ื ื’ ืคื•ืŸ ื•ื•ื™ื™ึทื˜ ืกื˜ืึทื˜ื™ืกื˜ื™ืง, ืฉื˜ื™ืฆื˜ ืจืขื’ืข ืจื™ืกื˜ืึทืจื˜, ื”ืื˜ ืึท ื’ืขื‘ื•ื™ื˜-ืื™ืŸ ืžืึธื˜ืึธืจ ืคึฟืึทืจ ืงืึทื ืขืงื˜ื™ื ื’ ื”ืึทื ื“ืœืขืจืก ืื™ืŸ ื“ื™ Lua ืฉืคึผืจืึทืš, ื’ืึธืจ ืฉื˜ื™ืฆื˜ DNSSEC, DNS64, RPZ (ืจืขืกืคึผืึธื ืกืข ืคึผืึธืœื™ื˜ื™ืง ื–ืึธื ืขืก) ืื•ืŸ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ื‘ืœืึทืงืœื™ืกืฅ. ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืจืขืงืึธืจื“ื™ืจืŸ ืจืขื–ื•ืœื˜ืื˜ืŸ ื•ื•ื™ BIND ื–ืึธื ืข ื˜ืขืงืขืก. ืฆื• ืขื ืฉื•ืจ ื”ื•ื™ืš ืคืึธืจืฉื˜ืขืœื•ื ื’, ืžืึธื“ืขืจืŸ ืงืฉืจ ืžื•ืœื˜ื™ืคึผืœืขืงืกื™ื ื’ ืžืขืงืึทื ื™ื–ืึทืžื– ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ ืื™ืŸ FreeBSD, Linux ืื•ืŸ Solaris (kqueue, epoll, /dev/poll), ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืึท ื”ื•ื™ืš-ืคืึธืจืฉื˜ืขืœื•ื ื’ ื“ื ืก ืคึผืึทืงืึทื˜ ืคึผืึทืจืกืขืจ ื•ื•ืึธืก ืื™ื– ื‘ื™ื›ื•ืœืช ืฆื• ืคึผืจืึทืกืขืกื™ื ื’ ื˜ืขื ืก ืคื•ืŸ ื˜ื•ื™ื–ื ื˜ืขืจ ืคื•ืŸ ืคึผืึทืจืึทืœืขืœ ืจื™ืงื•ื•ืขืก.

ืื™ืŸ ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข:

  • ืื™ืŸ ืกื“ืจ ืฆื• ืคืึทืจืžื™ื™ึทื“ืŸ ืœื™ืงืก ืคื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื’ืขื‘ืขื˜ืŸ ืคืขืœื“ ืื•ืŸ ืคืึทืจื’ืจืขืกืขืจืŸ ืคึผืจื™ื•ื•ืึทื˜ืงื™ื™ื˜, ื“ื™ ืžืขืงืึทื ื™ื–ืึทื ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ QNAME ืžื™ื ื™ืžื™ื–ืึทื˜ื™ืึธืŸ (ืจืคืง-7816), ืึทืคึผืขืจื™ื™ื˜ื™ื ื’ ืื™ืŸ "ืจื™ืœืึทืงืกื˜" ืžืึธื“ืข. ื“ื™ ืขืกืึทื ืก ืคื•ืŸ ื“ื™ ืžืขืงืึทื ื™ื–ืึทื ืื™ื– ืึทื– ื“ืขืจ ืจืขืกืึธืœื•ื•ืขืจ ื˜ื•ื˜ ื ื™ืฉื˜ ื“ืขืจืžืึธื ืขืŸ ื“ื™ ืคื•ืœ ื ืึธืžืขืŸ ืคื•ืŸ ื“ื™ ื’ืขื‘ืขื˜ืŸ ื‘ืึทืœืขื‘ืึธืก ืื™ืŸ ื–ื™ื™ืŸ ืจื™ืงื•ื•ืขืก ืฆื• ื“ื™ ืึทืคึผืกื˜ืจื™ื ื ืึธืžืขืŸ ืกืขืจื•ื•ืขืจ. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื•ื•ืขืŸ ื“ื™ื˜ืขืจืžืึทื ื™ื ื’ ื“ื™ ืึทื“ืจืขืก ืคึฟืึทืจ ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก foo.bar.baz.com, ื“ืขืจ ืจืขืกืึธืœื•ื•ืขืจ ื•ื•ืขื˜ ืฉื™ืงืŸ ื“ื™ ื‘ืขื˜ืŸ "QTYPE=NS,QNAME=baz.com" ืฆื• ื“ื™ ืึทื˜ืึธืจืึทื˜ื™ื™ื˜ื™ื•ื• ืกืขืจื•ื•ืขืจ ืคึฟืึทืจ ื“ื™ ".com" ื–ืึธื ืข, ืึธืŸ ื“ืขืจืžืึธื ืขืŸ " foo.bar". ืื™ืŸ ื–ื™ื™ืŸ ืงืจืึทื ื˜ ืคืึธืจืขื, ืึทืจื‘ืขื˜ ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“ ืื™ืŸ ื“ื™ "ืจื™ืœืึทืงืกื˜" ืžืึธื“ืข.
  • ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืงืœืึธืฅ ืึทื•ื˜ื’ืึธื•ื™ื ื’ ืจื™ืงื•ื•ืขืก ืฆื• ืึท ืึทื˜ืึธืจืึทื˜ื™ื™ื˜ื™ื•ื• ืกืขืจื•ื•ืขืจ ืื•ืŸ ืจืขืกืคึผืึธื ืกืขืก ืฆื• ื–ื™ื™ ืื™ืŸ dnstap ืคึฟืึธืจืžืึทื˜ ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“ (ืคึฟืึทืจ ื ื•ืฆืŸ, ืึท ื‘ื•ื™ืขืŸ ืžื™ื˜ ื“ื™ "-enable-dnstap" ืึธืคึผืฆื™ืข ืื™ื– ืคืืจืœืื ื’ื˜).
  • ืกื™ื™ืžืึทืœื˜ื™ื™ื ื™ืึทืก ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ ืขื˜ืœืขื›ืข ื™ื ืงืึทืžื™ื ื’ ืจื™ืงื•ื•ืขืก ื˜ืจืึทื ืกืžื™ื˜ื˜ืขื“ ืื™ื‘ืขืจ ืึท TCP ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืื™ื– ืฆื•ื’ืขืฉื˜ืขืœื˜, ืžื™ื˜ ืจืขื–ื•ืœื˜ืึทื˜ืŸ ื–ืขื ืขืŸ ืื•ืžื’ืขืงืขืจื˜ ื•ื•ื™ ื–ื™ื™ ื–ืขื ืขืŸ ื’ืจื™ื™ื˜, ืื•ืŸ ื ื™ืฉื˜ ืื™ืŸ ื“ืขืจ ืกื“ืจ ืคื•ืŸ ืจื™ืงื•ื•ืขืก ืื™ืŸ ื“ื™ ืจื™ื™. ื“ื™ ืฉื™ืขื•ืจ ืคื•ืŸ ืกื™ื™ืžืึทืœื˜ื™ื™ื ื™ืึทืก ืจื™ืงื•ื•ืขืก ืื™ื– ื‘ืืฉืœืืกืŸ ื“ื•ืจืš ื“ื™ "max-concurrent-requests-per-tcp-connection".
  • ื™ืžืคึผืœืึทืžืขื ืึทื“ ืึท ื˜ืขื›ื ื™ืง ืคึฟืึทืจ ื˜ืจืึทืงื™ื ื’ ื ื™ื™ึท ื“ืึธื•ืžื™ื™ื ื– ื ืึธื“ (ื ื™ื™ ื‘ืืžืขืจืงื˜ ื“ืึธืžืึทื™ืŸ), ื•ื•ืึธืก ืงืขื ืขืŸ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืกืึทืกืคึผื™ืฉืึทืก ื“ืึธื•ืžื™ื™ื ื– ืึธื“ืขืจ ื“ืึธื•ืžื™ื™ื ื– ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ ื‘ื™ื™ื–ืข ืึทืงื˜ื™ื•ื•ื™ื˜ืขื˜ืŸ, ืึทื–ืึท ื•ื•ื™ ื“ื™ืกื˜ืจื™ื‘ื™ื•ื˜ื™ื ื’ ืžืึทืœื•ื•ืึทืจืข, ืึธื ื˜ื™ื™ืœ ื ืขืžืขืŸ ืื™ืŸ ืคื™ืฉื™ื ื’ ืื•ืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ืึทืจื‘ืขื˜ืŸ ื‘ืึธื˜ื ืขืฅ. ื“ืขืจ ืื•ืคึฟืŸ ืื™ื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื“ืึธื•ืžื™ื™ื ื– ื•ื•ืึธืก ื”ืึธื‘ืŸ ื ื™ืฉื˜ ื‘ื™ื– ืึทื”ืขืจ ืึทืงืกืขืกื˜ ืื•ืŸ ืึทื ืึทืœื™ื™ื–ื™ื ื’ ื“ื™ ื ื™ื™ึทืข ื“ืึธื•ืžื™ื™ื ื–. ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื˜ืจืึทืงื™ื ื’ ื ื™ื™ึท ื“ืึธื•ืžื™ื™ื ื– ืงืขื’ืŸ ืึท ื’ืึทื ืฅ ื“ืึทื˜ืึทื‘ื™ื™ืก ืคื•ืŸ ืึทืœืข ื“ืึธื•ืžื™ื™ื ื– ื˜ืึธืžื™ื“ ื•ื•ื™ื•ื“, ื•ื•ืึธืก ืจื™ืงื•ื•ื™ื™ืขืจื– ื‘ืึทื˜ื™ื™ื˜ื™ืง ืจืขืกื•ืจืกืŸ ืฆื• ื˜ื™ื™ึทื ืขืŸ, NOD ื ื™ืฆื˜ ืึท ืคึผืจืึธื‘ืึทื‘ื™ืœื™ืกื˜ื™ืง ืคืจื™ื™ืžื•ื•ืขืจืง SBF (ืกื˜ืึทื‘ืœืข ื‘ืœื•ื ืคื™ืœื˜ืขืจ), ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืžื™ื ืึทืžื™ื™ื– ื–ื›ึผืจื•ืŸ ืื•ืŸ ืงืคึผื• ืงืึทื ืกืึทืžืฉืึทืŸ. ืฆื• ื’ืขื‘ืŸ ืขืก, ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ "new-domain-tracking = ื™ืึธ" ืื™ืŸ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก.
  • ื•ื•ืขืŸ ืคืœื™ืกื ื“ื™ืง ืื•ื ื˜ืขืจ ืกื™ืกื˜ืขืž, ื“ื™ PowerDNS ืจืขืงื•ืจืกืึธืจ ืคึผืจืึธืฆืขืก ืื™ืฆื˜ ืœื•ื™ืคื˜ ืื•ื ื˜ืขืจ ื“ื™ ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉื“ ื‘ืึทื ื™ืฆืขืจ pdns-ืจืขืงื•ืจืกืึธืจ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื•ื•ืึธืจืฆืœ. ืคึฟืึทืจ ืกื™ืกื˜ืขืžืขืŸ ืึธืŸ ืกื™ืกื˜ืขื ืื•ืŸ ืึธืŸ ื˜ืฉืจืึธืึธื˜, ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืคึฟืึทืจ ืกื˜ืึธืจื™ื ื’ ื“ื™ ืงืึธื ื˜ืจืึธืœ ื›ืึธืœืขืœ ืื•ืŸ ืคึผื™ื“ ื˜ืขืงืข ืื™ื– ืื™ืฆื˜ /var/run/pdns-recursor.

ืื™ืŸ ื“ืขืจืฆื•, ืืจื•ื™ืก ืžืขืœื“ื•ื ื’ KnotDNS 2.9.3, ืึท ื”ื•ื™ืš-ืคืึธืจืฉื˜ืขืœื•ื ื’ ืึทื˜ืึธืจืึทื˜ื™ื™ื˜ื™ื•ื• ื“ื ืก ืกืขืจื•ื•ืขืจ (ื“ื™ ืจืขืงื•ืจืกืึธืจ ืื™ื– ื“ื™ื–ื™ื™ื ื“ ื•ื•ื™ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ) ื•ื•ืึธืก ืฉื˜ื™ืฆื˜ ืึทืœืข ืžืึธื“ืขืจืŸ ื“ื ืก ืคึฟืขื™ึดืงื™ื™ื˜ืŸ. ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืื™ื– ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื“ื•ืจืš ื“ื™ ื˜ืฉืขื›ื™ืฉ ื ืึธืžืขืŸ ืจืขื’ื™ืกื˜ืจื™ CZ.NIC, ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ C ืื•ืŸ ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ื“ื•ืจืš ืœื™ื™ืกืึทื ืกื˜ ืื•ื ื˜ืขืจ GPLv3.

KnotDNS ืื™ื– ืื•ื ื˜ืขืจืฉื™ื™ื“ืŸ ื“ื•ืจืš ื–ื™ื™ืŸ ืคืึธืงื•ืก ืื•ื™ืฃ ื”ื•ื™ืš ืคืึธืจืฉื˜ืขืœื•ื ื’ ืึธื ืคึฟืจืขื’ ืคึผืจืึทืกืขืกื™ื ื’, ืคึฟืึทืจ ื•ื•ืึธืก ืขืก ื ื™ืฆื˜ ืึท ืžื•ืœื˜ื™-ื˜ืจืขื“ื™ื“ ืื•ืŸ ืžืขืจืกื˜ื ืก ื ื™ื˜-ื‘ืœืึทืงื™ื ื’ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ื•ื•ืึธืก ื•ื•ืึธื’ ื’ืขื–ื•ื ื˜ ืื•ื™ืฃ SMP ืกื™ืกื˜ืขืžืขืŸ. ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ืึทื–ืึท ื•ื•ื™ ืึทื“ื™ื ื’ ืื•ืŸ ื•ื™ืกืžืขืงืŸ ื–ืึธื ืขืก ืื•ื™ืฃ ื“ื™ ืคืœื™ืขืŸ, ื˜ืจืึทื ืกืคืขืจื™ื ื’ ื–ืึธื ืขืก ืฆื•ื•ื™ืฉืŸ ืกืขืจื•ื•ืขืจืก, DDNS (ื“ื™ื ืึทืžื™ืฉ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ), NSID (RFC 5001), EDNS0 ืื•ืŸ DNSSEC ื™ืงืกื˜ืขื ืฉืึทื ื– (ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ NSEC3), ืขื ื˜ืคืขืจ ืงื•ืจืก ืœื™ืžื™ื˜ื™ื ื’ (ืจืœ) ื–ืขื ืขืŸ ืฆื•ื’ืขืฉื˜ืขืœื˜.

ืื™ืŸ ื“ื™ ื ื™ื™ึทืข ืžืขืœื“ื•ื ื’:

  • ืฆื•ื’ืขืœื™ื™ื’ื˜ 'remote.block-notify-after-transfer' ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืฆื• ื“ื™ืกื™ื™ื‘ืึทืœ ืฉื™ืงื˜ ื ืึธื•ื˜ื™ืคื™ืข ืึทืจื˜ื™ืงืœืขืŸ;
  • ื™ืžืคึผืœืึทืžืขื ื˜ืึทื“ ื™ืงืกืคึผืขืจืžืขื ืึทืœ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ Ed448 ืึทืœื’ืขืจื™ื“ืึทื ืื™ืŸ DNSSE (ืจื™ืงื•ื•ื™ื™ืจื– GnuTLS 3.6.12+ ืื•ืŸ ื ืึธืš ื ื™ืฉื˜ ื‘ืืคืจื™ื™ื˜ ืงืจืึธืคึผืขื•ื•ืข 3.6+);
  • ื“ืขืจ 'ืœืืงืืœืข-ืกื™ืจื™ืึทืœ' ืคึผืึทืจืึทืžืขื˜ืขืจ ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• keymgr ืฆื• ืงืจื™ื’ืŸ ืึธื“ืขืจ ืฉื˜ืขืœืŸ ื“ื™ SOA ืกื™ืจื™ืึทืœ ื ื•ืžืขืจ ืคึฟืึทืจ ื“ื™ ื’ืขื—ืชืžืขื˜ ื–ืึธื ืข ืื™ืŸ ื“ื™ KASP ื“ืึทื˜ืึทื‘ื™ื™ืก;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื™ืžืคึผืึธืจื˜ื™ื ื’ ืขื“25519 ืื•ืŸ ืขื“448 ืฉืœื™ืกืœืขืŸ ืื™ืŸ BIND DNS ืกืขืจื•ื•ืขืจ ืคึฟืึธืจืžืึทื˜ ืฆื• keymgr;
  • ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ 'server.tcp-io-timeout' ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ื’ืขื•ื•ืืงืกืŸ ืฆื• 500 ืžืก ืื•ืŸ 'database.journal-db-max-size' ืื™ื– ืจื™ื“ื•ืกื˜ ืฆื• 512 MiB ืื•ื™ืฃ 32-ื‘ื™ืกืœ ืกื™ืกื˜ืขืžืขืŸ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’