mail us  |  mail this page

products  |  company  |  support  |  training  |  contact us

ZYTRAX OPEN LOGO

Blucat Banner

Appendix C: DNS Resources

Alternate DNS Software

The following links provide additional information about alternative Open Source DNS software.

Constrict

Python binding to BIND 9 APIs. GPLv2.

CustomDNS

A customizable DNS proxy server. License ?

dnsjava

DNS tools/proxy written in Java.

djbdns I

A modified version of djbdns a full DNS bind replacement - but with less features.

djbdns II

Dan Berstein's page (the author of the origibal djbdns). A full DNS bind replacement - but with less features.

Dnsmasq

DN proxy.

dnspython

DNS tools including a reverse mapper written in Python. Contributed by Nominium the BIND developers.

dnslbs

Lightweight DNS server based on Berkeley Database (BDB). GPL.

Domain Name Relay Daemon

Proxy DNS. Optimized for dial-up networks.

GnuDIP

Dynamic IP DNS system written in Perl.

Knot DNS

Authoritative DNS only. Supports DNSSEC. Compiled zone files for load performance. Dynamic add and delete of zones. Targeted at root and TLD operators and designed for continuous operation. *nix support only (packages and ports available). Open Source - license?.

lbdns

Sophisticated DNS Load Balancing server.

lbnamed

Load balancing Name Server written in Perl.

LDAP-DNS v2

LDAP based DNS server based on core djbdns code. License ?

LDAP-DNS v3

LDAP based DNS server based on reworked core and without the use of OpenLDAP libraries. License ?.

ldns

C library for DNS and DNSSEC based on PERL NET::DNS functionality. License GPL.

MaraDNS

A secure DNS for *NIX systems. Limited function DNS.

MyDNS

GNU licensed. Uses MySQL to hold zone file records. No resolve library. Does not support recursive queries.

NSD

Authoritative Only DNS server. Version 2+ supports latest DNSSEC (DNSSEC.bis) standards. Performance is 2 to 3 times BIND. A very serious product and deployed in the RIPE root-server network. Modest documentation.

Oak

Authoritative and recursive DNS server written in Python. LGPL.

pdnsd

No longer actively maintained by author (but there isalternative site. Permanent caching server (Proxy DNS). Optimized for dial-up networks.

Pliant

Proxy DNS

Posadis

Runs on FreeBSD, Linux and Windows. Uses Filemonitor to auto-update zone file changes. Resolver library. SAM is a lite (authoritative only) version for windows only. Various other tools. License

PowerDNS

Authoritative Only DNS server. Flexible back-end supports zone files, MySQL, PostGeSQL, Microsoft SQL, Orable, DB2 and many more. GPL.

Stanford DNS Server

Underlying support for lbnamed written in Perl.

YAKU-NS

Limited function DNS (formerly ENS).

BIND APIs and Drivers

The following links provide information about alternative API for BIND 9 and Open source drivers which use the existing BIND 9 APIs

BIND-DLZ

BIND-DLZ is now provided as a contribution within the normal BIND 9 distribution.

LDAP SDB

A BIND 9 SDB API back-end using LDAP.

DNS Web sites

The following links provide information about DNS or tools for verifying DNS systems:

www.dnssec.net DNS Security Extensions (DNSSEC)

www.bind9.net DNS and BIND Resources

www.ripe.net/disi Great DNSSEC resources, HowTo etc.

www.dnsstuff.com Comprehensive DNS Tools

www.dnsreport.com Quick check of your zone files

Dynamic IP DNS Services

DynDNS.org Name services for dynamic IPs.

Useful Links

The following Links provide some useful background, information on loosely related topics by category:

IPv6

www.ipv6tf.org - major information source for IPv6 deployemnt and products.

www.ipv6forum.com - IPv6 Forum for industry participants.

http://www.fpsn.net/index.cgi?pg=tools&tool=ipv6-inaddr - On-line tool to build IPv6 reverse mapping files.

DNS Operations

www.root-servers.org describes the root-servers and the organizations that administer them.

www.ripe.net/ripe/docs/ripe-203.html RIPE default value recommendations for TTLs.

Security

www.sans.org SANS organization, specialising in system security. Offers an alert newsletter service. Use the Reading Room for good backgrounders.

www.cert.org US Federally funded organisation and center for security expertise.

www.cryptostuff.com Some useful backgrounders

www.rsasecurity.com/rsalabs The research arm of RSA Security, Inc. - excellent overviews and articles.

www.securitydocs.com General security site covering a lot of topics including crytography. Some useful articles and whitepapers many written from a non-mathematicians viewpoint.

csrc.nist.gov US National Institute of Standard and Technology - Computer security division.

www.secwiz.com Lots of security information and articles.

www.gocsi.com The Computer Security Institute - dedicated to training computer and network security professionals.

www.securityfocus.com - security organisation provides BugTrac mailing list for security announcements.

www.infosyssec.com - Data collection site. Headlines and up-to-the-minute status information. Excellent link site to various international security centers.

DNSSEC

idsa.irisa.fr/index.php?page=kro&lang=en Automated tools for key rollovers and building DNSSEC.bis zones.

www.dnssec.org Excellent portal site for collection of DNSSEC information.

ietfreport.isoc.org/ids-wg-dnsext.html Status reports of the dnsext Work Group and current draft RFCs.

www.net-dns.org PERL tools (Net::DNS and Net::DNS::SEC) for secure zone maintenance and key rollovers.

ENUM

www.enumf.org ENUM Forum Primarily US led group looking at North American Country Code (1) implementation of ENUM.

www.enum.org Home page for a Neustart ENUM trial.

www.ripe.net/rs/enum/index.html RIPE is the ITU designated Tier-0 organisation for ENUM.

www.centr.org/kim/enum/index.html Country status of ENUM usage.

Zone Management

Software to help you manage one or more zones. Licenses are GPL unless noted otherwise. List courtesy of David Nolan - many thanks (contact David info-dns at managedandmonitored dot net). Any errors are entirely ours.

NetReg

The Carnegie Mellon NetReg package is a scalable and flexible Web-based multi-user system for managing networks, using perl and MySQL. It consolidates information about DNS zones, subnets, machine registrations, and DHCP configuration, and provides tools for easy management. The system exports ISC BIND configuration and zones, and can update them via either static zone files or TSIG signed dynamic DNS updates. It also exports ISC DHCP configurations, and has a SOAP API for integration with other systems. NetReg is designed for enterprise class network management, if you deal with dozens of hosts NetReg is more then you need. However if you deal with thousands or tens of thousands of hosts, NetReg may be exactly what you need. A live demo site is available off of the link above.

HostDB

A system for generating internal DNS zones, external DNS zones, and DHCP configuration data from the same repository. HostDB is not database driven, doesn't provide a web interface, and isn't designed for managing large networks of hosts, but its great for small networks. You maintain a few small files describing your network and HostDB generates the necessary DNS & DHCP configuration.

DNS Control

DNS Control is a Web-based DNS management tool for BIND 9. It supports maintaining A, MX, and CNAME records, with all information stored in a MySQL database using ADODB. Written in PHP.

maintain

Maintain is a multi-user, highly extensible, Web-based management tool for medium to large size computer networks to maintain host information for building configuration files for DNS and DHCP. Written in PHP.

DNS Dusty

DNSDusty is an uncomplicated Web-based DNS management tool. It does all of its modifications via signed dynamic updates, and gets info on zones via zone transfers. Thus, it does not require any external databases, and plays along well with other tools that do dynamic updates (such as DHCP). DNSDusty is written as a Perl CGI script, so it should work with most Web servers.



Problems, comments, suggestions, corrections (including broken links) or something to add? Please take the time from a busy life to 'mail us' (at top of screen), the webmaster (below) or info-support at zytrax. You will have a warm inner glow for the rest of the day.

Pro DNS and BIND by Ron Aitchison

Contents

tech info
guides home
dns articles
intro
contents
1 objectives
big picture
2 concepts
3 reverse map
4 dns types
quickstart
5 install bind
6 samples
reference
7 named.conf
8 dns records
operations
9 howtos
10 tools
11 trouble
programming
12 bind api's
security
13 dns security
bits & bytes
15 messages
resources
notes & tips
registration FAQ
dns resources
dns rfc's
change log

Creative Commons License
This work is licensed under a Creative Commons License.

If you are happy it's OK - but your browser is giving a less than optimal experience on our site. You could, at no charge, upgrade to a W3C STANDARDS COMPLIANT browser such as Firefox

web zytrax.com

Share Page

share page via facebook tweet this page submit page to stumbleupon submit page to reddit.com

Page Features

Page comment feature Send to a friend feature print this page Decrease font size Increase font size

RSS Feed Icon RSS Feed

Resources

Systems

FreeBSD
NetBSD
OpenBSD
DragonFlyBSD
Linux.org
Debian Linux

Applications

LibreOffice
OpenOffice
Mozilla
SourceForge
GNU-Free SW Foundation

Organisations

Open Source Initiative
Creative Commons

Misc.

Ibiblio - Library
Open Book Project
Open Directory
Wikipedia

SPF Resources

Draft RFC
SPF Web Site
SPF Testing
SPF Testing (member only)

Display full width page Full width page

Print this page Print this page

SPF Record Conformant Domain Logo

Copyright © 1994 - 2014 ZyTrax, Inc.
All rights reserved. Legal and Privacy
site by zytrax
Hosted by super.net.sg
web-master at zytrax
Page modified: September 18 2013.