-
-
Notifications
You must be signed in to change notification settings - Fork 60
Install Nameserver
BIND needs no install instructions as it's very portable and already installed on most Unix-like systems. All nameservers except tinydns and MaraDNS can read from BIND-style zone files. Like tinydns, NSD compiles all the data into a database which it serves from.
- Comparison of DNS server software at Wikipedia
- Alternative DNS Servers at Amazon
TL:DR; BIND aims to support every DNS feature possible. NSD, Knot, and Yadifa aim to be fast and secure. Tinydns is secure and fast.
- NSD4 performance measurements comparing BIND, NSD, Knot, and Yadifa
- Knot DNS Benchmarks with BIND, Knot, NSD, and PowerDNS
- Yadifa benchmarks with Knot, NSD, and BIND 9
TL;DR NSD, Knot, and Yadifa scale really really well. Tinydns was always faster than BIND. PowerDNS is comparable to BIND.
Comparison of managed DNS service providers.
- DNS Security Issues summarized by Sam (author of MaraDNS)
- CVE details
Where it wasn't much work coughnot BINDcough, I excluded vulnerabilities that applied to the recursive portions of a DNS package. Example: djbdns had 3 CVEs for dnscache and 0 for tinydns.
TL;DR In order of fewest vulnerabilities: tinydns (0), Knot (0), NSD (2), MaraDNS (12), PowerDNS (8), BIND (78)
- NicTool Server
- NicTool Client
- on FreeBSD 10.1
- on CentOS 6, 7
- on Ubuntu 14, 16, 18
- Docker