Announcement date: July 3, 2024
What's new
Improved UI
BlueCat Edge v24.2 introduces enhancements to the Edge CI, providing a more consistent and unified UI across BlueCat products.
Introduction of Cloud info page
Based on the region that your Edge CI is deployed in and the services that you are using, you might need a subset of the required cloud access requirements. Starting in BlueCat Edge v24.2, you can now view the information about the AWS region that your Edge CI is deployed in, and the cloud access requirements for your environment by clicking the Cloud info button in the top-right corner of the Edge CI. From this page, you can click the copy icon to copy the cloud access endpoints requirements to your clipboard.
Introduction of secrets manager
The BlueCat Edge secrets manager allows you to store sensitive credentials in a secure manner for reuse within Edge services without the need to manually enter in sensitive data in different fields. To use the secrets manager, you must first create a secrets profile that stores the sensitive data. Within the secrets profile, you can add a secret and a name that it will be referred by when managing Edge configurations and settings.
Updates to EDNS Client Subnet (ECS) prefix lengths
Previously, when configuring the EDNS Client Subnet (ECS) prefix length on a namespace, a limitation existed where the IPv4 source prefix could only be between 0 and 24, and the IPv6 source prefix could only be between 0 and 56.
Starting in DNS Resolver v3.11.0, the IPv4 source prefix length limitation has been removed and you can configure a prefix between 0 and 32. Additionally, the IPv6 source prefix length limitation has also been removed and you can configure a prefix between 0 and 128.
What's new
Support for updating NTP configurations
Service Point v4.7.0 introduces the ability to modify the NTP configurations of the service point through the Edge CI without the need to modify configuration files on the service point.
Support for provisioning Service Points on Equinix
Service Point v4.7.0 introduces support for provisioning the service point on Equinix Network Edge.
Enhancements to troubleshooting scripts
Service Point v4.7.0 introduces enhancements to the troubleshooting tools
available on the system, more specifically the reachability
and problems scripts.
Resolved issues
Inconsistent NIC port enumerations when provisioning Service Point on BlueCat hardware appliances
Due to a difference in behavior between Integrity and Edge Service Point NIC port enumerations, ports and port labels might become inconsistent when provisioning Service Point on BlueCat hardware appliances, leading to network connection issues. This issue has now been resolved.
SHA1 algorithm in OpenSSH package on Service Point
Previously, the Service Point installed a version of the OpenSSH package that supported the SHA1 algorithm, which had a serious security vulnerability. This issue has been resolved by upgrading to a newer version of the OpenSSH package which removes support for SHA1.
Security updates
Service Point v4.7.0 includes updates to libraries that addresses multiple CVE vulnerabilities.
What's new
Support for negative cache TTL
DNS Resolver Service v3.11.0 introduces negative cache TTL support, providing the ability to configure a flexible TTL refresh on cached NXDOMAIN records to ensure new records added can be queried and resolved immediately.
Enhancements to custom logging
DNS Resolver Service v3.11.0 introduces enhancements to custom logging to allow the use of any HTTPS destination, including cloud-based SIEMs, when sending DNS queries and responses.
Introduction of BlueCat Threat Protection IP Lists
DNS Resolver Service v3.11.0 introduces support for BlueCat Threat Protection IP Lists.
BlueCat Threat Protection includes data from partner feeds, including additional lists curated by the BlueCat internal research team to protect against IP addresses that employ malware, botnets, exploits, and spam. BlueCat Threat Protection IP lists are denoted by the BlueCat Threat Protection <list type> name and the Threat Intelligence IP list type.
Enhancements to DNS query data
DNS Resolver Service v3.11.0 introduces additional response details for DNS answers, including the original DNS answer and specific matching elements that led to the policy match or action.
When a query is received by DNS resolver service and the service point, the query information logged in the DNS activity table displays the answer that was processed by the DNS resolver service. When viewing the query information, you can now see additional information about the original DNS answer and matching elements that led to a policy match or action.
Updates to EDNS Client Subnet (ECS) prefix lengths
Previously, when configuring the EDNS Client Subnet (ECS) prefix length on a namespace, a limitation existed where the IPv4 source prefix could only be between 0 and 24, and the IPv6 source prefix could only be between 0 and 56.
Starting in DNS Resolver v3.11.0, the IPv4 source prefix length limitation has been removed and you can configure a prefix between 0 and 32. Additionally, the IPv6 source prefix length limitation has also been removed and you can configure a prefix between 0 and 128.
Enhancements to SERVFAIL response handling
DNS Resolver Service v3.11.0 introduces enhancements to the behavior of SERVFAIL responses to DNS queries. Previously, when the Serve Expired Queries from cache option is selected on a namespace, queries were served from the stale cache (expired cache) only if no forwarders were available. Starting in DNS Resolver Service v3.11.0, this functionality has been enhanced to provide reliability and ensure continuous service by serving queries from the stale cache not only when forwarders are unavailable, but also when a SERVFAIL response is received from a forwarder. This ensures that answers are always provided from the cache whenever there is an issue finding answers to the queries, improving the resilience and reliability of the DNS resolution process.
Additional source information when querying NSID EDNS data
DNS Resolver Service v3.11.0 introduces the ability to view whether source
information is coming from the cache, stale cache (expired cache), or if it
is a cache miss and retrieved. You can view this information by querying DNS
Resolver Service with NSID EDNS data, such as using dig +nsid
@<servicepointip> <query question>.
Resolved issues
Warning: Client COOKIE mismatch messages from dig output on Service Point
Previously, the "Warning: Client COOKIE mismatch" warning message would appear when performing a dig command on the service point. This would occur when looking up a DNS record executive due to the service point sending back a response that contained a different EDNS cookie than the original dig request. This issue has now been resolved.
For more information, refer to article 025301 on BlueCat Customer Care.
Source IP lists in multiple namespaces have inconsistent behavior between restarts
Previously, when two namespaces have source IP lists configured and there is a common IP address between the two lists, one of the namespaces is matched instead of both when a query is sent from that source IP. This would result in an inconsistent query response code. This issue has been resolved and when a source IP is common between two IP lists that exist in different namespaces, the query returns a NOERROR.
For more information, refer to article 025584 on BlueCat Customer Care.
Service Points fails to load new namespaces when disk space is low
Previously, Service Points would fail to load new namespaces if the Service Point was running low on disk space. Additionally, this would cause the DNS resolver service to write additional logs, resulting in additional disk space usage. This issue has been resolved and the DNS Resolver Service suppresses extraneous logs.
DNS Resolver Service incorrectly handles corrupted policy updates
Previously, when the Service Point received a policy update that might have been corrupted, the DNS Resolver Service would incorrectly handle the update and crash. This issue has now been resolved.
Security updates
DNS Resolver Service v3.11.0 includes updates to libraries that addresses multiple CVE vulnerabilities.
What's new
Support for additional Windows event logs
Identity Service v2.2.0 introduces support for additional Windows event log sources to capture identity data and IP addresses. Starting in this version, you can now capture identity data and IP addresses for the following Windows security log events:
-
4768: A Kerberos authentication ticket (TGT) was requested
-
4769: A Kerberos service ticket was requested
-
4624: An account was successfully logged on
Large enterprises have distributed, but isolated and complex DNS infrastructures that require access to applications in various clouds or hosted on-premise DNS servers. In many instances, this requires manually creating forwarding rules that are regularly updated by automated mechanisms or manually as DNS zones scale. This can lead to brittle DNS systems that require overhead and upkeep to ensure that the infrastructure is operational. In addition, internal root hints and internal recursive servers must have knowledge of these disparate DNS environments to ensure resolution across the DNS space. This complexity is alleviated with Edge Resolver.
Edge Resolver introduces functionality that discovers and provides DNS resolution across disparate DNS environments. Edge Resolver contains a Discovery Instance (DI) service to perform the discovery of DNS resources.
The DI uses user-supplied configurations for discovering one or more DNS spaces across Address Manager. Each DNS space has its own unique configuration, providing flexibility to users while removing the complexity of manually configuring namespaces. Once the DI has performed the discovery process, it creates a resolution map consisting of DNS zones, the responsible servers, and any DNS view-level recursion or forwarding rules.
Once you have discovered the DNS information, deploy DRS to the service point that provides recursive resolution. DRS evaluates any domains found in the Address Manager list and its internal knowledge of cloud zones to resolve any query needs to follow CNAME chains.