Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #573

Re: lightweight "slave" DNS server, +DNSSEC?

Date 2011-09-12 09:11 +0200
From David Brown <david@westcontrol.removethisbit.com>
Newsgroups comp.os.linux.networking
Subject Re: lightweight "slave" DNS server, +DNSSEC?
References <86hb4l3r1t.fsf@gray.siamics.net> <slrnj6otln.gtj.grahn+nntp@frailea.sa.invalid> <8639g330fb.fsf@gray.siamics.net> <1by5xv3syz.fsf@snowball.wb.pfeifferfamily.net>
Message-ID <MsCdnf4XxOLRLPDTnZ2dnUVZ7rGdnZ2d@lyse.net> (permalink)

Show all headers | View raw


On 11/09/2011 19:10, Joe Pfeiffer wrote:
> Ivan Shmakov<ivan@gray.siamics.net>  writes:
>
>>>>>>> Jorgen Grahn<grahn+nntp@snipabacken.se>  writes:
>>>>>>> On Sat, 2011-09-10, Ivan Shmakov wrote:
>>
>>   >>  I wonder, is there a lightweight DNS server to be used as a "slave"?
>>   >>  The zones to be served are DNSSEC-signed, so it should check the
>>   >>  signature on AXFR/IXFR and only accept the new data if it's valid.
>>   >>  (It isn't much an issue to prepare a list of trusted keys for it,
>>   >>  but DLV support will nevertheless be handy.)
>>
>>   >>  Will Maradns or PowerDNS fit?
>>
>>   >>  Or is BIND 9.7 really the best possible solution for this task?
>>
>>   >  Is there any specific reason why you think bind won't do?  Or do you
>>   >  simply think it's overkill because it has lots of features which you
>>   >  don't need?
>>
>> 	Mostly the latter.  However, I'm also somewhat constrained in
>> 	resources (virtual memory, for instance), since this NS is going
>> 	to be run on a so-called "virtual server", and it's a really
>> 	cheap one.  (Not that I had any issues in a similar case, but
>> 	nevertheless.)
>
> dnsmasq is a good, lightweight, easy to configure, caching DNS (and
> DHCP) server.  I don't know whether it supports DNSSEC.

Another vote here for dnsmasq - though I also don't know about DNSSEC. 
dnsmasq is so fast, lightweight, and easy to configure compared to other 
DNS servers that it is definitely the first choice for most uses.  Look 
at dnsmasq first - if it can do the job you need, use it.

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-10 12:27 +0700
  Re: lightweight "slave" DNS server, +DNSSEC? Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-09-11 08:52 +0000
    Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-11 16:15 +0700
      Re: lightweight "slave" DNS server, +DNSSEC? Joe Pfeiffer <pfeiffer@cs.nmsu.edu> - 2011-09-11 11:10 -0600
        Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david@westcontrol.removethisbit.com> - 2011-09-12 09:11 +0200
        Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-12 15:51 +0700
          Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david@westcontrol.removethisbit.com> - 2011-09-12 11:12 +0200
            Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-13 01:18 +0700
              Re: lightweight "slave" DNS server, +DNSSEC? David Brown <david.brown@removethis.hesbynett.no> - 2011-09-12 21:09 +0200
  Re: lightweight "slave" DNS server, +DNSSEC? Hauke Lampe <packbart@blagga.openchaos.org> - 2011-09-11 13:29 +0000
    Re: lightweight "slave" DNS server, +DNSSEC? Ivan Shmakov <ivan@gray.siamics.net> - 2011-09-11 22:29 +0700

csiph-web