Saturday, February 17, 2007

MaraDNS 1.2.12.05 released



I have just released MaraDNS 1.2.12.05, which is a stable release of MaraDNS. This is a bugfix release; a couple of important bugs with MaraDNS 1.2.12.04 have been fixed with this release.

The bugs fixed are important bugs; distributors of MaraDNS are encouraged to update to this version of MaraDNS as soon as possible.

From the changelog:

  • LOC records with a precision that is a multiple of 10 now work.

  • Memory leak found by Rani Assaf plugged.

  • Recursive server now more robust against certain DOS attacks.

  • Documentation updates.


This release has not been uploaded to sourceforge yet; the release can be found here:

http://www.maradns.org/download.html

Friday, February 16, 2007

Cool fonts

Here are some cool freely downloadable fonts:

  • Charis SIL. This is an update to the excellent Bitsream Charter font by Matthew Carter, who later on made Verdana and other WebFonts for Microsoft. The original free Bitstream Charter was never translated in to TTF; this is a TTF translation that includes many more charaters, mainly characters of interest for linguists. The license is a very liberal Open Font license. The font's only problems are that it puts a lot of space between lines (this can be worked around by setting up formatting to force lines to be 12 points apart when using writing with 12 point text), and that it looks unattractive on the screen when writing documents with it (it looks fine on the screen once the document is made a pdf file). I use this font for all of my English lessons.
  • Delicious and three others (look at the toolbar on the left)
  • Smeltery has a few free fonts (Same license as the Delicious font)
  • Lido STF
  • Day roman The BabelFish translation of its license is "The fonts on this site acres freeware and CAN used as they acres in any context without by mission from Apostrophic Laboratories, except ton produce material that is racist, criminal and/or illegaly into nature. It is prohibited tons modify any Apostrophic Laboratories font(s) for repackaging and/or the RH releases without at express written authorization by the designer (s) of OF the font(s) or Apostrophic Laboratories. Under NO circumstance shall any Apostrophic Laboratories Design or font Design pay or purchased."


There are many other fonts listed in other blogs, such as here, here, and here.

New MaraDNS snapshot



I have released a new snapshot of MaraDNS today. In this snapshot, the recursive code has been updated to connect() to the remote DNS server. Rani pointed out to me that you can actually connect with a UDP connection; I looked at the relevant POSIX spec, and, lo and behold, he's right. This is useful because it makes certain DOS attacks more difficult; by connecting() and using send() and recv() instead of sendto() and recvfrom(), the only IP address allowed to connect to an open port is the IP address we are connected() to.

I have also verified that these changes work without problem in OpenBSD, Linux, and Win32. I have also done some basic stress testing of the MaraDNS server.

I have snapshots for both the stable and development versions of MaraDNS available:


Stable
Development


I will release MaraDNS 1.2.12.05 early next week after I do some more testing.

- Sam

Wednesday, February 14, 2007

MaraDNS 1.3.03 released; hash function tarball updated




Rani Assaf found a memory leak in MaraDNS' code that my SQA setup didn't catch. I have revised my SQA process to catch this particular leak, and have plugged the leak.

In addition, since Roy asked me to compile the Win32 port of MaraDNS with the "-pipe" switch to speed things up, I made the appropriate change to the Win32 makefile. Alas, "-pipe" seems to, if anything, slightly slow down the compiling of MaraDNS in win32.

There are a number of other bugfixes and enhancments which are in the post-1.3.02 development branch, such as it now being possible to have "." by itself being a hostname. Read earlier snapshop announcments for details.

MaraDNS 1.3.03 is available here:

MaraDNS 1.3.03




For a few years now, I have had a tarball with various cryptographic hash algorithms available. This tarball hasn't been updated since 2001. Now, with the NIST starting to work on getting a new hash function out there, there have been some new hash primitives developed, including RadioGatun and LASH. In addition, I have found a couple of interesting hash functions which never got mainstream interest: Michael Johnson created a 256-bit hash function called Sapsum a few years ago, and last year a suite of encrpytion primitives, including a hash function, is included with the FastFlex suite.

This in mind, I have finally updated the suite of hash functions, removing some broken algorithms (MD4, MD5, the CRC and UNIX sums, etc.), and adding some new algorithms. The revised suite is available here:

sums-20070214.tar.bz2





Happy Valentine's day everyone!

Tuesday, February 13, 2007

OK, I'm caught up with MaraDNS support email



I have finally answered all of the MaraDNS support email I got in the last few days. Like I said before, it sometimes takes me up to a week to answer email. If you sent a support email before today and it isn't answered, please resend it.

There are a couple of bugs that people reported in support emails:
  • Zone files sometimes act funny if the last character is not a newline. This is something where I will have to go through the RR parsing code for each record type and make sure they can end with either a newline/space or with a EOF.
  • There is a reported memory leak. The reporter was even kind enough to tell me where the memory that causes the leak is allocated. I have already downloaded and installed valgrind. I will look in to this leak in the next day or two.
One support email asked about BIND zone file support. We're very close to getting support; the CSV2 parse code has already been revised to make it easier for me to finish my python script, and to have CSV2 zone files, as much as possible, have the same formatting as the converted BIND zone file. Now I just have to finish up the parsing script. Then the testing will begin.

One thing I am very seriously considering doing is starting to sell commerical level support for MaraDNS. There are some things I want to finish up with MaraDNS first however: The BIND zone support, and the rewrite of the recursive resolver.

Another support email asked for help with making a distribution-specific package for MaraDNS. Quite frankly, this goes beyond the boundaries of support I offer for MaraDNS. I offer both a CentOS/RHEL distribution-specific package of MaraDNS, and a Windows 32 native binary (which is a partial port). Kai makes a Debian/Ubuntu package, Alex makes a FreeBSD port, and Daniel makes a Slackware package. If you run anything else, I can't really help you because I only run Win32, CentOS 3, and Ubuntu 6.06.

That said, I am willing to make a package for your distribution if you're willing to pay me to do it. :-) If MaraDNS doesn't compile on whatever modern *nix you're trying to run MaraDNS on, if you give me a remote account for the *nix in question, I will make the necessary changes so that MaraDNS will compile.

- Sam

Monday, February 12, 2007

New MaraDNS snapshots; Marahash 1.1 released



I have released two new MaraDNS snapshots today; a new snap for both the stable and development branches of MaraDNS. The development snapshot of MaraDNS has the most significant improvments: I have updated the CSV2 parser to allow TXT records with multiple fields to be in the more BIND-compatible 'field 1' 'field 2' format in addition to the 'field 1';'field 2' format MaraDNS 1.2 zone files use. This only works if the ~ is used to separate records, and will make finishing up the bind zone file to csv2 zone file conversion script easier.

In the stable snapshot, I have added the patch file that fixes the bug where a host name can not be a '.' by itself (the root DNS node). I will include this patch with the next stable release of MaraDNS, but will not apply this patch until I am sure this bugfix doesn't introduce any new bugs. I do not want to repeat the mistake I made with the 1.0.33/1.1.50 releases of MaraDNS, where a bug fix resulted in other bugs being created.

The workaround in MaraDNS 1.2 is to use a '%' in a zone file for the root node (csv2["."]) to get a DNS root node.

In both snapshots, the manpage reference PDF file has been updated. I finally got ghostscript 8.54 working on my system. Compiling and installing from the ghostscript 8.54 source was not enough; I also had to copy all of the fonts ghostscript wants from /usr/share/fonts/default/Type1/ and /usr/share/fonts/default/ghostscript/ in to the directory /usr/local/share/ghostscript/8.54/lib.




For a few years now, there has been a program hidden in tools/misc called Marahash. This is a program that uses the MaraDNS random number generator (an AES variant, as it turns out) as a compression function to make a 128-bit cryptographic hash. I recently discovered that the 1.2 security updates to MaraDNS' random number generator made the hash too slow to be usable. Since this hash is something useful to have, I have taken the Marahash code, replaced the MaraRNG with the older pre-1.2 MaraRNG core (the security improvments are not needed when using this core as a hash compression function), and made some usability improvments.

This resulted in Marahash. I then made some usability improvments to Marahash. Instead of being able to hash just a single file, Marahash now takes a list of files and directories as command line arguments. If a given command line argument is a directory, Marahash will recursively find all files in the directory and all sub-directories, and output their hashes. The output format for Marahash is now the hash followed by the filename. One can make a hash of all files in the current directory and all subdirectories with this command:

marahash . > MARASUMS

This is useful for making a file that can be used to verify file integrity on burned CDs and DVDs.

Marahash is not the fastest hash: it is about six times slower than SHA-1 and 10 times slower than MD5. It also has a digest size of only 128 bits. Despite these limitations, it is still a useful hash to have around.

I have both Linux/Unix source code and Windows binaries for Marahash available here:

marahash-1.1.tar.bz2 Sig (Linux/Unix source)
marahash-1-1-win32.zip Sig(Windows 32bit binary)

Monday, February 5, 2007

MaraDNS snapshots released

I am slowly but surely getting closer and closer to having BIND zone file support. In the current 1.3 snapshot, I have made it possible to have freeform line breaks in WKS and LOC records if the ~ is used to separate records.

I have also update the documentation, and have a couple of minor bug fixes.

  • There was a minor problem with LOC processing that affects both the 1.2 and 1.3 releases of MaraDNS. The 1.3 snap fixes this release, and I have also made a 1.2 snap that backports the fix to 1.2. I plan on releasing a new 1.2 release in two weeks (this is a very minor bug)
  • MaraDNS 1.3.02 did not compile with GCC 2.96. Fixed.
Anyway, the 1.3 snapshot can be downloaded here:

http://www.maradns.org/download/1.3/snap/200702

Next: I'm a little behind on support email.

- Sam