Security Hardening
This guide covers the essentials. Read the full upstream guide on GitHub → For a specific release, select its tag in the repository.
Protect transfers and management
Require TSIG for static zones with transfer.require_tsig = true, restrict NOTIFY sources, and use XoT where transfer encryption is needed. XoT protects outbound transfers only; it does not create an encrypted client-query listener.
Keep management HTTP private. Health probes and metrics are unauthenticated, even when the optional observability API has a bearer token.
Run with limited privileges
Use the installed borondns service account. The systemd service grants CAP_NET_BIND_SERVICE for port 53; a high-port deployment does not need it. Root-launched processes require process.run_as_user and drop privileges before handling network input.
Keep core dumps disabled and no-new-privileges enabled. Give the runtime user read access to credentials and write access to its durable zone cache. Protect secret files from world reads and group/world writes.
DNS and resource policy
Retain response rate limiting for public DNS unless an alternative mitigation has been measured. DNS Cookies default to a lenient policy; anycast or load-balanced nodes need coordinated Cookie secrets and rotation.
Allow both UDP and TCP DNS, and the ICMP messages required for Path MTU Discovery. Size transfer and resident-memory limits with headroom for query serving and publication. See the configuration guide for exact settings.
BoronDNS serves transferred DNSSEC data but does not sign or validate zones. Continue monitoring signing and signature expiry on the primary. XoT does not perform online CRL/OCSP checks; use the upstream guidance on certificate lifetime and trust rotation.
Preserve valid state
A failed refresh retains the previous valid zone generation until expiry. Never-loaded or expired zones return SERVFAIL. Keep durable cache state for restart continuity and retain primary backups.
Follow the upgrade and recovery procedure before changing binaries or manipulating state.
Report a vulnerability
Report suspected vulnerabilities privately to security@integrity.hu. Follow the repository's security policy for current reporting and maintenance information.