Re: DJBDNS vs BIND

Sabahattin Gucukoglu <[email protected]> Wed, 5 May 2010 10:47:09 +0100
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On 5 May 2010, at 07:32, Allen Schultz wrote:
I was wondering what the (dis)advantages in using DJBDNS over BIND?

Yes, very funny, troll.  Go away already.

No, just kidding.  Welcome to the party. :-)

I'll tell you what's funny, I came to djbdns long after BIND, but BIND (of today) came very long after djbdns.  That may tell you how good it is, and it may not.  Basically, if it does what you want and doesn't do what you don't want, it's for you.  I'm now using it full-time precisely because of that: caching-only server on a caching-only machine, authoritative-only servers exposed to the big bad world where they will not get cache corruption.  You will need a tool like DNSProxy if you want to run both roles on one IP address, i.e., one machine connected to a network segment that expects to receive both iterative queries from outside asking for authoritative information and recursive queries asking for cached information or information resolution by stub clients, which is annoying.  And it does a lot of things very well, in a technically superior and standards-conformant fashion.  It's lovely.  Yes, some features are missing, and if we aren't careful it will catch up on us - DNSSec, IPv6 (patches available), TSig, Dynamic DNS, IXFR and notify.  Some people will argue these aren't necessary, or that they can be done better, that the standards are wrong.  And yes, I can stand djbdns as an example of doing things right even though I don't see eye to eye with the author and find many of his decisions to be nothing but inconsiderate and ultimately self-serving.  For example, TCP queries are not something handled by the standard authoritative DNS; you must switch this on deliberately with the axfrdns program if you want to make TCP available even for non-AXFR data sets.

Try this for a turnaround of feelings:
http://forums.channelregister.co.uk/post/265223

Most of this relates to a time before Debian, where had I still been on Gentoo and without the marvelous Debian packages I'd've been following the arguably complicated and very DJB-centric installation process for djbdns and, worse, qmail.  (qmail I simply cannot justify - that is obsolete software with no hope of rescue without the creator's help.)  So, check that you are easily able to get the thing installed on your boxes, and that the requisite tools (daemontools, ucspi-tcp, etc) are ready and working for you to follow the excellent documentation, and make sense of it.  You are expected to be familiar with Unix primitives.

You should also look at other alternatives: MaraDNS is a thread-centric non-BIND alternative.  Unbound is a caching-only name server.  There'll be others.

Cheers,
Sabahattin
smime.p7s (application/pkcs7-signature, 2.6 KB) - not displayed