New Features
The new GeoIP2 API from MaxMind is now supported when BIND
is compiled using configure --with-geoip2.
The legacy GeoIP API can be used by compiling with
configure --with-geoip instead. (Note that
the databases for the legacy API are no longer maintained by
MaxMind.)
The default path to the GeoIP2 databases will be set based
on the location of the libmaxminddb library;
for example, if it is in /usr/local/lib,
then the default path will be
/usr/local/share/GeoIP.
This value can be overridden in named.conf
using the geoip-directory option.
Some geoip ACL settings that were available with
legacy GeoIP, including searches for netspeed,
org, and three-letter ISO country codes, will
no longer work when using GeoIP2. Supported GeoIP2 database
types are country, city,
domain, isp, and
as. All of the databases support both IPv4
and IPv6 lookups. [GL #182]
Two new metrics have been added to the
statistics-channel to report DNSSEC
signing operations. For each key in each zone, the
dnssec-sign counter indicates the total
number of signatures named has generated
using that key since server startup, and the
dnssec-refresh counter indicates how
many of those signatures were refreshed during zone
maintenance, as opposed to having been generated
as a result of a zone update. [GL #513]
A SipHash 2-4 based DNS Cookie (RFC 7873) algorithm has been added.
[GL #605]
If you are running multiple DNS Servers (different versions of BIND 9
or DNS server from multiple vendors) responding from the same IP
address (anycast or load-balancing scenarios), you'll have to make
sure that all the servers are configured with the same DNS Cookie
algorithm and same Server Secret for the best performance.
DS records included in DNS referral messages can now be validated
and cached immediately, reducing the number of queries needed for
a DNSSEC validation. [GL #964]