98N/A<!
DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN" 98N/A [<!ENTITY mdash "—">]>
98N/A - Copyright (C) 2004, 2005, 2007, 2009, 2013 Internet Systems Consortium, Inc. ("ISC") 98N/A - Copyright (C) 2001, 2003 Internet Software Consortium. 98N/A - Permission to use, copy, modify, and/or distribute this software for any 98N/A - purpose with or without fee is hereby granted, provided that the above 98N/A - copyright notice and this permission notice appear in all copies. 98N/A - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH 98N/A - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY 98N/A - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT, 98N/A - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM 98N/A - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE 98N/A - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR 98N/A - PERFORMANCE OF THIS SOFTWARE. 98N/A <
date>Aug 27, 2001</
date>
98N/A <
refentrytitle><
application>rndc-confgen</
application></
refentrytitle>
98N/A <
manvolnum>8</
manvolnum>
98N/A <
refmiscinfo>BIND9</
refmiscinfo>
98N/A <
refname><
application>rndc-confgen</
application></
refname>
98N/A <
refpurpose>rndc key generation tool</
refpurpose>
98N/A <
holder>Internet Systems Consortium, Inc. ("ISC")</
holder>
98N/A <
holder>Internet Software Consortium.</
holder>
98N/A <
command>rndc-confgen</
command>
<
arg><
option>-a</
option></
arg>
<
arg><
option>-A <
replaceable class="parameter">algorithm</
replaceable></
option></
arg>
<
arg><
option>-b <
replaceable class="parameter">keysize</
replaceable></
option></
arg>
<
arg><
option>-c <
replaceable class="parameter">keyfile</
replaceable></
option></
arg>
<
arg><
option>-h</
option></
arg>
<
arg><
option>-k <
replaceable class="parameter">keyname</
replaceable></
option></
arg>
<
arg><
option>-p <
replaceable class="parameter">port</
replaceable></
option></
arg>
<
arg><
option>-r <
replaceable class="parameter">randomfile</
replaceable></
option></
arg>
<
arg><
option>-s <
replaceable class="parameter">address</
replaceable></
option></
arg>
<
arg><
option>-t <
replaceable class="parameter">chrootdir</
replaceable></
option></
arg>
<
arg><
option>-u <
replaceable class="parameter">user</
replaceable></
option></
arg>
<
title>DESCRIPTION</
title>
<
para><
command>rndc-confgen</
command>
generates configuration files
for <
command>rndc</
command>. It can be used as a
convenient alternative to writing the
and the corresponding <
command>controls</
command>
and <
command>key</
command>
statements in <
filename>
named.conf</
filename> by hand.
Alternatively, it can be run with the <
command>-a</
command>
option to set up a <
filename>
rndc.key</
filename> file and
avoid the need for a <
filename>
rndc.conf</
filename> file
and a <
command>controls</
command> statement altogether.
Do automatic <
command>rndc</
command> configuration.
This creates a file <
filename>
rndc.key</
filename>
in <
filename>/etc</
filename> (or whatever
<
varname>sysconfdir</
varname>
was specified as when <
acronym>BIND</
acronym> was
that is read by both <
command>rndc</
command>
and <
command>named</
command> on startup. The
<
filename>
rndc.key</
filename> file defines a default
command channel and authentication key allowing
<
command>rndc</
command> to communicate with
<
command>named</
command> on the local host
with no further configuration.
Running <
command>rndc-confgen -a</
command> allows
BIND 9 and <
command>rndc</
command> to be used as
replacements for BIND 8 and <
command>ndc</
command>,
with no changes to the existing BIND 8
If a more elaborate configuration than that
generated by <
command>rndc-confgen -a</
command>
is required, for example if rndc is to be used remotely,
you should run <
command>rndc-confgen</
command> without
<
command>-a</
command> option and set up a
<
term>-A <
replaceable class="parameter">algorithm</
replaceable></
term>
Specifies the algorithm to use for the TSIG key. Available
choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
hmac-sha384 and hmac-sha512. The default is hmac-md5.
<
term>-b <
replaceable class="parameter">keysize</
replaceable></
term>
Specifies the size of the authentication key in bits.
Must be between 1 and 512 bits; the default is the
<
term>-c <
replaceable class="parameter">keyfile</
replaceable></
term>
Used with the <
command>-a</
command> option to specify
an alternate location for <
filename>
rndc.key</
filename>.
Prints a short summary of the options and arguments to
<
command>rndc-confgen</
command>.
<
term>-k <
replaceable class="parameter">keyname</
replaceable></
term>
Specifies the key name of the rndc authentication key.
This must be a valid domain name.
The default is <
constant>rndc-key</
constant>.
<
term>-p <
replaceable class="parameter">port</
replaceable></
term>
Specifies the command channel port where <
command>named</
command>
listens for connections from <
command>rndc</
command>.
<
term>-r <
replaceable class="parameter">randomfile</
replaceable></
term>
Specifies a source of random data for generating the
authorization. If the operating
system does not provide a <
filename>/
dev/
random</
filename>
or equivalent device, the default source of randomness
is keyboard input. <
filename>randomdev</
filename>
the name of a character device or file containing random
data to be used instead of the default. The special value
<
filename>keyboard</
filename> indicates that keyboard
<
term>-s <
replaceable class="parameter">address</
replaceable></
term>
Specifies the IP address where <
command>named</
command>
listens for command channel connections from
<
command>rndc</
command>. The default is the loopback
<
term>-t <
replaceable class="parameter">chrootdir</
replaceable></
term>
Used with the <
command>-a</
command> option to specify
a directory where <
command>named</
command> will run
chrooted. An additional copy of the <
filename>
rndc.key</
filename>
will be written relative to this directory so that
it will be found by the chrooted <
command>named</
command>.
<
term>-u <
replaceable class="parameter">user</
replaceable></
term>
Used with the <
command>-a</
command> option to set the
of the <
filename>
rndc.key</
filename> file generated.
<
command>-t</
command> is also specified only the file
the chroot area has its owner changed.
To allow <
command>rndc</
command> to be used with
no manual configuration, run
<
para><
userinput>rndc-confgen -a</
userinput>
To print a sample <
filename>
rndc.conf</
filename> file and
corresponding <
command>controls</
command> and <
command>key</
command>
statements to be manually inserted into <
filename>
named.conf</
filename>,
<
para><
userinput>rndc-confgen</
userinput>
<
refentrytitle>rndc</
refentrytitle><
manvolnum>8</
manvolnum>
<
refentrytitle>
rndc.conf</
refentrytitle><
manvolnum>5</
manvolnum>
<
refentrytitle>named</
refentrytitle><
manvolnum>8</
manvolnum>
<
citetitle>BIND 9 Administrator Reference Manual</
citetitle>.
<
para><
corpauthor>Internet Systems Consortium</
corpauthor>