JVM and OS DNS Caching

2019-03-18 12:26发布

I am facing a problem with JVM and DNS.

Everything I'm reading (including the docs and this) says that I can disable JVM DNS caching using networkaddress.cache.ttl, which can be set using java.security.Security.setProperties, but through the standard approach of using system properties. I have successfully changed this to 0, so no more caching in my JVM.

But now, on each call of InetAddress.getByName("mytest.com"), it seems that my JVM is using the system DNS cache (in my case Windows 8). Indeed, between 2 calls of the method, I have changed the BIND9 properties for "mytest.com", but the IP return is still the same. Here is the workflow:

  1. setCachePolicyInJVM(0) in my Java code.
  2. set mytest.com to 192.168.1.188 in BIND9, restart.
  3. InetAddress.getByName("mytest.com").getHostAddress(); -> 192.168.1.188
  4. set mytest.com -> 192.168.1.160 in BIND9, restart.
  5. InetAddress.getByName("mytest.com").getHostAddress(); -> 192.168.1.188 (should be 160 if there was no caching).
  6. Flush the Windows DNS
  7. InetAddress.getByName("mytest.com").getHostAddress(); -> 192.168.1.160

I have read several times that the JVM does not use the system cache, but that is wrong: it clearly does.

How do we force a new DNS resolution on each call, bypassing the OS DNS cache?

3条回答
孤傲高冷的网名
2楼-- · 2019-03-18 12:37

I think I've run into this problem, or a very similar one. What I did then was to implement my own DNS provider for the JVM, see how to change the java dns service provider for details. You can use the dnsjava mentioned there or roll your own.

查看更多
Ridiculous、
3楼-- · 2019-03-18 12:39

From here it seems you should set sun.net.inetaddr.ttl. This worked for me.

Example from link:

java -Dsun.net.inetaddr.ttl=1 test
Enter the hostname
rrr
Output isrrr/129.145.146.100
Enter the hostname
rrr
Output isrrr/129.147.146.100
查看更多
Explosion°爆炸
4楼-- · 2019-03-18 12:48

You can either edit your $JAVA_HOME/jre/lib/security/java.security for Java 6-8 and $JAVA_HOME/conf/security/java.security property file to add the following property .

networkaddress.cache.ttl=1

It is not available to set it in command line.

Since these 2 properties are part of the security policy, they are not set by either the -D option or the System.setProperty() API, instead they are set as security properties.

To set this property inside the code, you can use the following method.

java.security.Security.setProperty("networkaddress.cache.ttl", "1")

Or add the following property in the java command line.

-Dnetworkaddress.cache.ttl=1

It is also important to note that values are effective only if the corresponding networkaddress.cache.* properties are not set.

See Java 8 Networking Properties, Java 9 Networking Properties and VeriSign DNS Caching in Java Virtual Machines for more details.

This answer also adds some details.

查看更多
登录 后发表回答