BIND DNS Server 9.16.0 ื‘ืืคืจื™ื™ื˜

ื ืึธืš 11 ื—ื“ืฉื™ื ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’, ื“ื™ ื™ืกืง ืงืึธื ืกืึธืจื˜ื™ื•ื ื‘ืึทืงืขื ืขื  ื“ืขืจ ืขืจืฉื˜ืขืจ ืกื˜ืึทื‘ื™ืœ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ืึท ื ื™ื™ึทืข ื‘ืึทื˜ื™ื™ื˜ื™ืง ืฆื•ื•ื™ื™ึทื’ ืคื•ืŸ ื“ื™ BIND 9.16 DNS ืกืขืจื•ื•ืขืจ. ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืฆื•ื•ื™ื™ึทื’ 9.16 ื•ื•ืขื˜ ื–ื™ื™ืŸ ืฆื•ื’ืขืฉื˜ืขืœื˜ ืคึฟืึทืจ ื“ืจื™ื™ ื™ืึธืจ ื‘ื™ื– ื“ื™ 2 ืคืขืจื˜ืœ ืคื•ืŸ 2023 ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ ืึทืŸ ืขืงืกื˜ืขื ื“ืขื“ ืฉื˜ื™ืฆืŸ ืฆื™ืงืœ. ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืคึฟืึทืจ ื“ื™ ืคืจื™ืขืจื“ื™ืงืข LTS ืฆื•ื•ื™ื™ึทื’ 9.11 ื•ื•ืขื˜ ืคืึธืจื–ืขืฆืŸ ืฆื• ื–ื™ื™ืŸ ืคืจื™ื™ ื‘ื™ื– ื“ืขืฆืขืžื‘ืขืจ 2021. ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืฆื•ื•ื™ื™ึทื’ 9.14 ื•ื•ืขื˜ ืกื•ืฃ ืื™ืŸ ื“ืจื™ื™ ื—ื“ืฉื™ื.

ื”ื•ื™ืคึผื˜ ื™ื ืึธื•ื•ื•ื™ื™ืฉืึทื ื–:

  • ืฆื•ื’ืขื’ืขื‘ืŸ KASP (ืฉืœื™ืกืœ ืื•ืŸ ืกื™ื™ื ื™ื ื’ ืคึผืึธืœื™ื˜ื™ืง), ืึท ืกื™ืžืคึผืœืึทืคื™ื™ื“ ื•ื•ืขื’ ืฆื• ืคื™ืจืŸ DNSSEC ืฉืœื™ืกืœืขืŸ ืื•ืŸ ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื–, ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื›ึผืœืœื™ื ื“ื™ืคื™ื™ื ื“ ืžื™ื˜ ื“ื™ "dnssec-policy" ื“ื™ืจืขืงื˜ื™ื•ื•. ื“ื™ ื“ื™ืจืขืงื˜ื™ื•ื• ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ื“ื™ ื“ื•ืจ ืคื•ืŸ ื“ื™ ื ื•ื™ื˜ื™ืง ื ื™ื™ึท ืฉืœื™ืกืœืขืŸ ืคึฟืึทืจ ื“ื ืก ื–ืึธื ืขืก ืื•ืŸ ื“ื™ ืึธื˜ืึทืžืึทื˜ื™ืง ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืคื•ืŸ ZSK ืื•ืŸ KSK ืฉืœื™ืกืœืขืŸ.
  • ื“ื™ ื ืขืฅ ืกืึทื‘ืกื™ืกื˜ืึทื ืื™ื– ื‘ืื˜ื™ื™ื˜ื™ืง ืจื™ื“ื™ื–ื™ื™ื ื“ ืื•ืŸ ืกื•ื•ื™ื˜ืฉื˜ ืฆื• ืึท ื™ื™ืกื™ื ื’ืงืจืึทื ืึทืก ื‘ืขื˜ืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืžืขืงืึทื ื™ื–ืึทื ื™ืžืคึผืœืึทืžืขื ืึทื“ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ืขืจ ื‘ื™ื‘ืœื™ืึธื˜ืขืง libuv.
    ื“ื™ ืจื™ื•ื•ืขืจืง ื”ืื˜ ื ื™ืฉื˜ ื ืึธืš ืจื™ื–ืึทืœื˜ื™ื“ ืื™ืŸ ืงื™ื™ืŸ ืงืขื ื˜ื™ืง ืขื ื“ืขืจื•ื ื’ืขืŸ, ืึธื‘ืขืจ ืื™ืŸ ืฆื•ืงื•ื ืคึฟื˜ ืจื™ืœื™ืกื™ื– ืขืก ื•ื•ืขื˜ ืฆื•ืฉื˜ืขืœืŸ ื“ื™ ื’ืขืœืขื’ื ื”ื™ื™ื˜ ืฆื• ื™ื ืกื˜ืจื•ืžืขื ื˜ ืขื˜ืœืขื›ืข ื‘ืึทื˜ื™ื™ื˜ื™ืง ืคืึธืจืฉื˜ืขืœื•ื ื’ ืึธืคึผื˜ื™ืžื™ื–ืึทื˜ื™ืึธื ืก ืื•ืŸ ืœื™ื™ื’ืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื ื™ื™ึทืข ืคึผืจืึธื˜ืึธืงืึธืœืก ืึทื–ืึท ื•ื•ื™ DNS ืื™ื‘ืขืจ TLS.

  • ื™ืžืคึผืจื•ื•ื•ื“ ืคึผืจืึธืฆืขืก ืคึฟืึทืจ ืึธื ืคื™ืจื•ื ื’ DNSSEC ืฆื•ื˜ืจื•ื™ ืึทื ื’ืงืขืจื– (ื˜ืจืึทืกื˜ ืึทื ืงืขืจ, ืึท ืฆื™ื‘ื•ืจ ืฉืœื™ืกืœ ื˜ื™ื™ื“ ืฆื• ืึท ื–ืึธื ืข ืฆื• ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ืึธื˜ืึทื ื˜ื™ืกื™ื˜ื™ ืคื•ืŸ ื“ืขื ื–ืึธื ืข). ืึทื ืฉื˜ืึธื˜ ื“ื™ ื˜ืจืึทืกื˜ื™ื“ ืงื™ื– ืื•ืŸ ื’ืขืจืื˜ืŸ ืงื™ื– ืกืขื˜ื˜ื™ื ื’ืก, ื•ื•ืึธืก ื–ืขื ืขืŸ ืื™ืฆื˜ ื“ื™ืคึผืจื™ืฉื™ื™ื™ื˜ื™ื“, ืึท ื ื™ื™ึทืข ืฆื•ื˜ืจื•ื™-ืึทื ื’ืงืขืจื– ื“ื™ืจืขืงื˜ื™ื•ื• ืื™ื– ืคืืจื’ืขืœื™ื™ื’ื˜ ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืคื™ืจืŸ ื‘ื™ื™ื“ืข ื˜ื™ื™ืคึผืก ืคื•ืŸ ืฉืœื™ืกืœืขืŸ.

    ื•ื•ืขืŸ ื ื™ืฆืŸ ืฆื•ื˜ืจื•ื™-ืึทื ื’ืงืขืจื– ืžื™ื˜ ื“ื™ ืขืจืฉื˜-ืฉืœื™ืกืœ ืงื™ื•ื•ืขืจื“, ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ ื“ืขื ื“ื™ืจืขืงื˜ื™ื•ื• ืื™ื– ื™ื™ื“ืขื ื™ืงืึทืœ ืฆื• ื’ืขืจืื˜ืŸ ืฉืœื™ืกืœืขืŸ, ื“"ื”. ื“ื™ืคื™ื™ื ื– ื“ื™ ืฆื•ื˜ืจื•ื™ ืึทื ืงืขืจ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ืŸ ืœื•ื™ื˜ ืžื™ื˜ RFC 5011. ื•ื•ืขืŸ ื ื™ืฆืŸ ืฆื•ื˜ืจื•ื™-ืึทื ื’ืงืขืจื– ืžื™ื˜ ื“ื™ ืกื˜ืึทื˜ื™ืง-ืฉืœื™ืกืœ ืงื™ื•ื•ืขืจื“, ื“ื™ ื ืึทื˜ื•ืจ ืงืึธืจืึทืกืคึผืึทื ื“ื– ืฆื• ื“ื™ ื˜ืจืึทืกื˜ื™ื“-ืงื™ื– ื“ื™ืจืขืงื˜ื™ื•ื•, ื“.ื”. ื“ื™ืคื™ื™ื ื– ืึท ืคึผืขืจืกื™ืกื˜ืขื ื˜ ืฉืœื™ืกืœ ื•ื•ืึธืก ืื™ื– ื ื™ืฉื˜ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜. ื˜ืจืึทืกื˜-ืึทื ื’ืงืขืจื– ืื•ื™ืš ืึธืคืคืขืจืก ืฆื•ื•ื™ื™ ืžืขืจ ื˜ืขืจืžื™ื ืขืŸ, ืขืจืฉื˜-ื“ืก ืื•ืŸ ืกื˜ืึทื˜ื™ืง-ื“ืก, ื•ื•ืึธืก ืœืึธื–ืŸ ืื™ืจ ืฆื• ื ื•ืฆืŸ ืฆื•ื˜ืจื•ื™ ืึทื ื’ืงืขืจื– ืื™ืŸ ื“ืขื ืคึฟืึธืจืžืึทื˜. DS (Delegation Signer) ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ DNSKEY, ื•ื•ืึธืก ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ื‘ื™ื™ื ื“ื™ื ื’ื– ืคึฟืึทืจ ืฉืœื™ืกืœืขืŸ ื•ื•ืึธืก ื–ืขื ืขืŸ ื ืึธืš ื ื™ืฉื˜ ืืจื•ื™ืก (ื“ื™ IANA ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ืคึผืœืึทื ื– ืฆื• ื ื•ืฆืŸ ื“ื™ DS ืคึฟืึธืจืžืึทื˜ ืคึฟืึทืจ ื”ืึทืจืฅ ื–ืึธื ืข ืฉืœื™ืกืœืขืŸ ืื™ืŸ ื“ืขืจ ืฆื•ืงื•ื ืคึฟื˜).

  • ื“ื™ "+ ื™ืึทืžืœ" ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื“ื™ dig, mdig ืื•ืŸ delv ื™ื•ื˜ื™ืœืึทื˜ื™ื– ืคึฟืึทืจ ืคึผืจืึธื“ื•ืงืฆื™ืข ืื™ืŸ YAML ืคึฟืึธืจืžืึทื˜.
  • ื“ื™ "+[ื ื™ื˜] ืื•ืžื’ืขืจื™ื›ื˜" ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื“ื™ ื’ืจืึธื‘ืŸ ื ื•ืฆืŸ, ืึทืœืึทื•ื™ื ื’ ื“ื™ ืึธืคึผื˜ืจืึธื’ ืคื•ืŸ ืจืขืกืคึผืึธื ืกืขืก ืคื•ืŸ ืžื—ื ื•ืช ืื ื“ืขืจืข ื•ื•ื™ ื“ื™ ืกืขืจื•ื•ืขืจ ืฆื• ื•ื•ืึธืก ื“ื™ ื‘ืขื˜ืŸ ืื™ื– ื’ืขืฉื™ืงื˜.
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ "+[ืงื™ื™ืŸ] ื™ืงืกืคึผืึทื ื“ืึทืึทืึท" ืึธืคึผืฆื™ืข ืฆื• ื’ืจืึธื‘ืŸ ื ื•ืฆืŸ, ื•ื•ืึธืก ื’ืขืคึฟื™ืจื˜ IPv6 ืึทื“ืจืขืกืขืก ืื™ืŸ ืึทืึทืึทืึท ืจืขืงืึธืจื“ืก ืฆื• ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ืคื•ืœ 128-ื‘ื™ืกืœ ืคืึทืจื˜ืจืขื˜ื•ื ื’, ืืœื ื•ื•ื™ ืื™ืŸ RFC 5952 ืคึฟืึธืจืžืึทื˜.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ื’ืจื•ืคึผืขืก ืคื•ืŸ ืกื˜ืึทื˜ื™ืกื˜ื™ืง ื˜ืฉืึทื ืึทืœื–.
  • DS ืื•ืŸ CDS ืจืขืงืึธืจื“ืก ื–ืขื ืขืŸ ืื™ืฆื˜ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื‘ืœื•ื™ื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ SHA-256 ื”ืึทืฉืขืก (ื“ื•ืจ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ SHA-1 ืื™ื– ื“ื™ืกืงืึทื ื˜ื™ื ื™ื•ื“).
  • ืคึฟืึทืจ ื“ื ืก ืงื™ื›ืœ (RFC 7873), ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืึทืœื’ืขืจื™ื“ืึทื ืื™ื– SipHash 2-4, ืื•ืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ HMAC-SHA ืื™ื– ืึธืคึผื’ืขืฉื˜ืขืœื˜ (AES ืื™ื– ืจื™ื˜ื™ื™ื ื“).
  • ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ื™ ืงืึทืžืึทื ื“ื– dnssec-signzone ืื•ืŸ dnssec-verify ืื™ื– ืื™ืฆื˜ ื’ืขืฉื™ืงื˜ ืฆื• ื ืึธืจืžืึทืœ ืจืขื–ื•ืœื˜ืึทื˜ (STDOUT), ืื•ืŸ ื‘ืœื•ื™ื– ืขืจืจืึธืจืก ืื•ืŸ ื•ื•ืึธืจื ื™ื ื’ื– ื–ืขื ืขืŸ ื’ืขื“ืจื•ืงื˜ ืฆื• STDERR (ื“ื™ -f ืึธืคึผืฆื™ืข ืื•ื™ืš ืคึผืจื™ื ืฅ ื“ื™ ื’ืขื—ืชืžืขื˜ ื–ืึธื ืข). ื“ื™ "-q" ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ืฉื˜ื•ื ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜.
  • ื“ื™ DNSSEC ื•ื•ืึทืœืึทื“ื™ื™ืฉืึทืŸ ืงืึธื“ ืื™ื– ืจื™ื•ื•ืขืจืงื˜ ืฆื• ืขืœื™ืžื™ื ื™ืจืŸ ืงืึธื“ ื“ื•ืคึผืœื™ืงื™ื™ืฉืึทืŸ ืžื™ื˜ ืื ื“ืขืจืข ืกืึทื‘ืกื™ืกื˜ืึทืžื–.
  • ืฆื• ื•ื•ื™ื™ึทื–ืŸ ืกื˜ืึทื˜ื™ืกื˜ื™ืง ืื™ืŸ JSON ืคึฟืึธืจืžืึทื˜, ื‘ืœื•ื™ื– ื“ื™ JSON-C ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜. ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืึธืคึผืฆื™ืข "--with-libjson" ืื™ื– ืจื™ื ื™ื™ืžื“ ืฆื• "--with-json-c".
  • ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจ ืฉืจื™ืคื˜ ื ื™ื˜ ืžืขืจ ื“ื™ืคืึธืœืฅ ืฆื• "--sysconfdir" ืื™ืŸ / ืขื˜ืง ืื•ืŸ "--localstatedir" ืื™ืŸ / var ืกื™ื™ึทื“ืŸ "--ืคึผืจืขืคื™ืงืก" ืื™ื– ืกืคึผืขืกื™ืคื™ืขื“. ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืคึผืึทื˜ืก ื–ืขื ืขืŸ ืื™ืฆื˜ $ ืคึผืจืขืคื™ืงืก / ืขื˜ืง ืื•ืŸ $ ืคึผืจืขืคื™ืงืก / ื•ื•ืึทืจ, ื•ื•ื™ ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ Autoconf.
  • ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ืงืึธื“ ื™ืžืคึผืœืึทืžืขื ื™ื ื’ ื“ื™ DLV (Domain Look-aside Verification, dnssec-lookaside ืึธืคึผืฆื™ืข) ื“ื™ื ืกื˜, ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ื“ื™ืคึผืจื™ืฉื™ื™ื™ื˜ื™ื“ ืื™ืŸ BIND 9.12, ืื•ืŸ ื“ื™ ืคึฟืึทืจื‘ื•ื ื“ืŸ dlv.isc.org ื”ืึทื ื“ืœืขืจ ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜ ืื™ืŸ 2017. ืจื™ืžื•ื•ื•ื™ื ื’ ื“ื™ DLVs ื‘ืืคืจื™ื™ื˜ ื“ื™ BIND ืงืึธื“ ืคื•ืŸ ื•ืžื ื™ื™ื˜ื™ืง ืงืึทืžืคึผืœืึทืงื™ื™ืฉืึทื ื–.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’