-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On 08/04/15 14:24, Jan Včelák wrote:
Hey Jan,
CZ.NIC Labs just released Knot DNS 1.6.3. This patch
release
contains a few rather serious bug fixes and some minor
improvements. Update is highly recommended.
When performing our internal benchmarking, we discovered a serious
performance drop for large NSEC-signed zones (not NSEC3). In
construction of NSEC proofs for NXDOMAIN responses, the server got
into a loop possibly causing iteration over all domain names in the
zone. The problem was present in Knot DNS since the beginning of
the project. We are sorry for not noticing this earlier.
Thanks for this release. I can confirm that Knot's CPU usage on our
servers has dropped significantly with this update, because it is
spending less time walking NSEC-signed zones.
Regards,
Anand Buddhdev
RIPE NCC
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools -
http://gpgtools.org
iEYEARECAAYFAlUlTsQACgkQi+U8Q0SwlCskzACbBqCYm5ul/VsM3IFJFrEcvuEH
QM0An1TI4W6W7uk5LurZok1pLxEmEhEU
=Em1o
-----END PGP SIGNATURE-----