named.docbook revision 2eeb74d1cf5355dd98f6d507a10086e16bb08c4b
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder<!--
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - Copyright (C) 2004-2009, 2011, 2013-2015 Internet Systems Consortium, Inc. ("ISC")
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - Copyright (C) 2000, 2001, 2003 Internet Software Consortium.
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder -
98890889ffb2e8f6f722b00e265a211f13b5a861Corneliu-Claudiu Prodescu - Permission to use, copy, modify, and/or distribute this software for any
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - purpose with or without fee is hereby granted, provided that the above
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - copyright notice and this permission notice appear in all copies.
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder -
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder - PERFORMANCE OF THIS SOFTWARE.
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder-->
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder<!-- Converted by db4-upgrade version 1.0 -->
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder<refentry xmlns="http://docbook.org/ns/docbook" version="5.0" xml:id="man.named">
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <info>
3f9fabb8ac5cfd9234431ecf19b51ff3e985595aChristian Maeder <date>2014-02-19</date>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder </info>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder <refentryinfo>
df0e8744a2befcba003ea6d93214601c743bde74Christian Maeder <corpname>ISC</corpname>
df0e8744a2befcba003ea6d93214601c743bde74Christian Maeder <corpauthor>Internet Systems Consortium, Inc.</corpauthor>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder </refentryinfo>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder <refmeta>
df0e8744a2befcba003ea6d93214601c743bde74Christian Maeder <refentrytitle><application>named</application></refentrytitle>
9aec0bc9d57df2669c8095fb1b4bd954d80b5537Christian Maeder <manvolnum>8</manvolnum>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <refmiscinfo>BIND9</refmiscinfo>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder </refmeta>
b8cd2804f426fd97148615fe31c1f47afac7a683Christian Maeder
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder <refnamediv>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder <refname><application>named</application></refname>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder <refpurpose>Internet domain name server</refpurpose>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder </refnamediv>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <docinfo>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder <copyright>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <year>2004</year>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <year>2005</year>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder <year>2006</year>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder <year>2007</year>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder <year>2008</year>
6204e46b2e31a71e6e98c6ecc5efc11e61a76a01Christian Maeder <year>2009</year>
6204e46b2e31a71e6e98c6ecc5efc11e61a76a01Christian Maeder <year>2011</year>
df0e8744a2befcba003ea6d93214601c743bde74Christian Maeder <year>2013</year>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <year>2014</year>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <year>2015</year>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
59bbf8aeab565e86d79c8482a4c7bd7a1841ca7bChristian Maeder </copyright>
d83bd347856e87ba96c0c8e0c5b473db4eb975d0Christian Maeder <copyright>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <year>2000</year>
59bbf8aeab565e86d79c8482a4c7bd7a1841ca7bChristian Maeder <year>2001</year>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <year>2003</year>
59bbf8aeab565e86d79c8482a4c7bd7a1841ca7bChristian Maeder <holder>Internet Software Consortium.</holder>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder </copyright>
59bbf8aeab565e86d79c8482a4c7bd7a1841ca7bChristian Maeder </docinfo>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder
59bbf8aeab565e86d79c8482a4c7bd7a1841ca7bChristian Maeder <refsynopsisdiv>
b8cd2804f426fd97148615fe31c1f47afac7a683Christian Maeder <cmdsynopsis sepchar=" ">
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <command>named</command>
59bbf8aeab565e86d79c8482a4c7bd7a1841ca7bChristian Maeder <arg choice="opt" rep="norepeat"><option>-4</option></arg>
59bbf8aeab565e86d79c8482a4c7bd7a1841ca7bChristian Maeder <arg choice="opt" rep="norepeat"><option>-6</option></arg>
b8cd2804f426fd97148615fe31c1f47afac7a683Christian Maeder <arg choice="opt" rep="norepeat"><option>-c <replaceable class="parameter">config-file</replaceable></option></arg>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">debug-level</replaceable></option></arg>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">string</replaceable></option></arg>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine-name</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-f</option></arg>
59bbf8aeab565e86d79c8482a4c7bd7a1841ca7bChristian Maeder <arg choice="opt" rep="norepeat"><option>-g</option></arg>
46b207daf66b64930a59f3615c8b127aac0b8e43Christian Maeder <arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">logfile</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-M <replaceable class="parameter">option</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-m <replaceable class="parameter">flag</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-n <replaceable class="parameter">#cpus</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-p <replaceable class="parameter">port</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-s</option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-S <replaceable class="parameter">#max-socks</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">directory</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-U <replaceable class="parameter">#listeners</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-u <replaceable class="parameter">user</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-v</option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-V</option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-X <replaceable class="parameter">lock-file</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder <arg choice="opt" rep="norepeat"><option>-x <replaceable class="parameter">cache-file</replaceable></option></arg>
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder </cmdsynopsis>
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder </refsynopsisdiv>
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder <refsection><info><title>DESCRIPTION</title></info>
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder <para><command>named</command>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder is a Domain Name System (DNS) server,
5b68f1141555736e0b7ddbe14218bcabcc44636fChristian Maeder part of the BIND 9 distribution from ISC. For more
5b68f1141555736e0b7ddbe14218bcabcc44636fChristian Maeder information on the DNS, see RFCs 1033, 1034, and 1035.
5b68f1141555736e0b7ddbe14218bcabcc44636fChristian Maeder </para>
5b68f1141555736e0b7ddbe14218bcabcc44636fChristian Maeder <para>
5b68f1141555736e0b7ddbe14218bcabcc44636fChristian Maeder When invoked without arguments, <command>named</command>
987696e96527051add2483eba583b73da930bf39Christian Maeder will
6e513e0de692a0e93f8291038e9f332d66f29f9cChristian Maeder read the default configuration file
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder <filename>/etc/named.conf</filename>, read any initial
987696e96527051add2483eba583b73da930bf39Christian Maeder data, and listen for queries.
4e1239f8b5fa139bd9be8d0431d711c7b88a58c2Christian Maeder </para>
5b68f1141555736e0b7ddbe14218bcabcc44636fChristian Maeder </refsection>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder
e49fd57c63845c7806860a9736ad09f6d44dbaedChristian Maeder <refsection><info><title>OPTIONS</title></info>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder
3f9fabb8ac5cfd9234431ecf19b51ff3e985595aChristian Maeder <variablelist>
3f9fabb8ac5cfd9234431ecf19b51ff3e985595aChristian Maeder <varlistentry>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder <term>-4</term>
3f9fabb8ac5cfd9234431ecf19b51ff3e985595aChristian Maeder <listitem>
83259a366597461d24e6b9236a8a33e201798e4dChristian Maeder <para>
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder Use IPv4 only even if the host machine is capable of IPv6.
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder <option>-4</option> and <option>-6</option> are mutually
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder exclusive.
3f9fabb8ac5cfd9234431ecf19b51ff3e985595aChristian Maeder </para>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder </listitem>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder </varlistentry>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder
3f9fabb8ac5cfd9234431ecf19b51ff3e985595aChristian Maeder <varlistentry>
3f9fabb8ac5cfd9234431ecf19b51ff3e985595aChristian Maeder <term>-6</term>
3f9fabb8ac5cfd9234431ecf19b51ff3e985595aChristian Maeder <listitem>
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <para>
d3c9318c22fcf44d9135a3b2c64f880b9a785babChristian Maeder Use IPv6 only even if the host machine is capable of IPv4.
3f9fabb8ac5cfd9234431ecf19b51ff3e985595aChristian Maeder <option>-4</option> and <option>-6</option> are mutually
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder exclusive.
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder </para>
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder </listitem>
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder </varlistentry>
3f9fabb8ac5cfd9234431ecf19b51ff3e985595aChristian Maeder
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder <varlistentry>
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder <term>-c <replaceable class="parameter">config-file</replaceable></term>
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder <listitem>
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder <para>
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder Use <replaceable class="parameter">config-file</replaceable> as the
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder configuration file instead of the default,
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder <filename>/etc/named.conf</filename>. To
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder ensure that reloading the configuration file continues
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder to work after the server has changed its working
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder directory due to to a possible
081deee1bac477ab8db717646baba47f0fe95479Christian Maeder <option>directory</option> option in the configuration
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder file, <replaceable class="parameter">config-file</replaceable> should be
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder an absolute pathname.
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder </para>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder </listitem>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder </varlistentry>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder
863c98ae89e37c21c0c04b9b130b5136688976eeChristian Maeder <varlistentry>
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder <term>-d <replaceable class="parameter">debug-level</replaceable></term>
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder <listitem>
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder <para>
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder Set the daemon's debug level to <replaceable class="parameter">debug-level</replaceable>.
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder Debugging traces from <command>named</command> become
d83bd347856e87ba96c0c8e0c5b473db4eb975d0Christian Maeder more verbose as the debug level increases.
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder </para>
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder </listitem>
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder </varlistentry>
d83bd347856e87ba96c0c8e0c5b473db4eb975d0Christian Maeder
34db68bf7b0a0cb624373cc364a56442c1b3f0f7Christian Maeder <varlistentry>
d83bd347856e87ba96c0c8e0c5b473db4eb975d0Christian Maeder <term>-D <replaceable class="parameter">string</replaceable></term>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder <listitem>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder <para>
4e1239f8b5fa139bd9be8d0431d711c7b88a58c2Christian Maeder Specifies a string that is used to identify a instance of
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder <command>named</command> in a process listing. The contents
d83bd347856e87ba96c0c8e0c5b473db4eb975d0Christian Maeder of <replaceable class="parameter">string</replaceable> are
f0d823af5e37881b77328bbcff8c96b58b92c89fChristian Maeder not examined.
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder </para>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder </listitem>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder </varlistentry>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder <varlistentry>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder <term>-E <replaceable class="parameter">engine-name</replaceable></term>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder <listitem>
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder <para>
61116f0ae514354dddda28edc7af459e8b23e8b4Christian Maeder When applicable, specifies the hardware to use for
54233d1f5ebf82ebb341a0f481e8ae657fc90e91Christian Maeder cryptographic operations, such as a secure key store used
61116f0ae514354dddda28edc7af459e8b23e8b4Christian Maeder for signing.
61116f0ae514354dddda28edc7af459e8b23e8b4Christian Maeder </para>
<para>
When BIND is built with OpenSSL PKCS#11 support, this defaults
to the string "pkcs11", which identifies an OpenSSL engine
that can drive a cryptographic accelerator or hardware service
module. When BIND is built with native PKCS#11 cryptography
(--enable-native-pkcs11), it defaults to the path of the PKCS#11
provider library specified via "--with-pkcs11".
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-f</term>
<listitem>
<para>
Run the server in the foreground (i.e. do not daemonize).
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-g</term>
<listitem>
<para>
Run the server in the foreground and force all logging
to <filename>stderr</filename>.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-L <replaceable class="parameter">logfile</replaceable></term>
<listitem>
<para>
Log to the file <option>logfile</option> by default
instead of the system log.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-M <replaceable class="parameter">option</replaceable></term>
<listitem>
<para>
Sets the default memory context options. Currently
the only supported option is
<replaceable class="parameter">external</replaceable>,
which causes the internal memory manager to be bypassed
in favor of system-provided memory allocation functions.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-m <replaceable class="parameter">flag</replaceable></term>
<listitem>
<para>
Turn on memory usage debugging flags. Possible flags are
<replaceable class="parameter">usage</replaceable>,
<replaceable class="parameter">trace</replaceable>,
<replaceable class="parameter">record</replaceable>,
<replaceable class="parameter">size</replaceable>, and
<replaceable class="parameter">mctx</replaceable>.
These correspond to the ISC_MEM_DEBUGXXXX flags described in
<filename>&lt;isc/mem.h&gt;</filename>.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-n <replaceable class="parameter">#cpus</replaceable></term>
<listitem>
<para>
Create <replaceable class="parameter">#cpus</replaceable> worker threads
to take advantage of multiple CPUs. If not specified,
<command>named</command> will try to determine the
number of CPUs present and create one thread per CPU.
If it is unable to determine the number of CPUs, a
single worker thread will be created.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-p <replaceable class="parameter">port</replaceable></term>
<listitem>
<para>
Listen for queries on port <replaceable class="parameter">port</replaceable>. If not
specified, the default is port 53.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-s</term>
<listitem>
<para>
Write memory usage statistics to <filename>stdout</filename> on exit.
</para>
<note>
<para>
This option is mainly of interest to BIND 9 developers
and may be removed or changed in a future release.
</para>
</note>
</listitem>
</varlistentry>
<varlistentry>
<term>-S <replaceable class="parameter">#max-socks</replaceable></term>
<listitem>
<para>
Allow <command>named</command> to use up to
<replaceable class="parameter">#max-socks</replaceable> sockets.
The default value is 4096 on systems built with default
configuration options, and 21000 on systems built with
"configure --with-tuning=large".
</para>
<warning>
<para>
This option should be unnecessary for the vast majority
of users.
The use of this option could even be harmful because the
specified value may exceed the limitation of the
underlying system API.
It is therefore set only when the default configuration
causes exhaustion of file descriptors and the
operational environment is known to support the
specified number of sockets.
Note also that the actual maximum number is normally a little
fewer than the specified value because
<command>named</command> reserves some file descriptors
for its internal use.
</para>
</warning>
</listitem>
</varlistentry>
<varlistentry>
<term>-t <replaceable class="parameter">directory</replaceable></term>
<listitem>
<para>Chroot
to <replaceable class="parameter">directory</replaceable> after
processing the command line arguments, but before
reading the configuration file.
</para>
<warning>
<para>
This option should be used in conjunction with the
<option>-u</option> option, as chrooting a process
running as root doesn't enhance security on most
systems; the way <function>chroot(2)</function> is
defined allows a process with root privileges to
escape a chroot jail.
</para>
</warning>
</listitem>
</varlistentry>
<varlistentry>
<term>-U <replaceable class="parameter">#listeners</replaceable></term>
<listitem>
<para>
Use <replaceable class="parameter">#listeners</replaceable>
worker threads to listen for incoming UDP packets on each
address. If not specified, <command>named</command> will
calculate a default value based on the number of detected
CPUs: 1 for 1 CPU, and the number of detected CPUs
minus one for machines with more than 1 CPU. This cannot
be increased to a value higher than the number of CPUs.
If <option>-n</option> has been set to a higher value than
the number of detected CPUs, then <option>-U</option> may
be increased as high as that value, but no higher.
On Windows, the number of UDP listeners is hardwired to 1
and this option has no effect.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-u <replaceable class="parameter">user</replaceable></term>
<listitem>
<para>Setuid
to <replaceable class="parameter">user</replaceable> after completing
privileged operations, such as creating sockets that
listen on privileged ports.
</para>
<note>
<para>
On Linux, <command>named</command> uses the kernel's
capability mechanism to drop all root privileges
except the ability to <function>bind(2)</function> to
a
privileged port and set process resource limits.
Unfortunately, this means that the <option>-u</option>
option only works when <command>named</command> is
run
on kernel 2.2.18 or later, or kernel 2.3.99-pre3 or
later, since previous kernels did not allow privileges
to be retained after <function>setuid(2)</function>.
</para>
</note>
</listitem>
</varlistentry>
<varlistentry>
<term>-v</term>
<listitem>
<para>
Report the version number and exit.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-V</term>
<listitem>
<para>
Report the version number and build options, and exit.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-X <replaceable class="parameter">lock-file</replaceable></term>
<listitem>
<para>
Acquire a lock on the specified file at runtime; this
helps to prevent duplicate <command>named</command> instances
from running simultaneously.
Use of this option overrides the <command>lock-file</command>
option in <filename>named.conf</filename>.
If set to <literal>none</literal>, the lock file check
is disabled.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-x <replaceable class="parameter">cache-file</replaceable></term>
<listitem>
<para>
Load data from <replaceable class="parameter">cache-file</replaceable> into the
cache of the default view.
</para>
<warning>
<para>
This option must not be used. It is only of interest
to BIND 9 developers and may be removed or changed in a
future release.
</para>
</warning>
</listitem>
</varlistentry>
</variablelist>
</refsection>
<refsection><info><title>SIGNALS</title></info>
<para>
In routine operation, signals should not be used to control
the nameserver; <command>rndc</command> should be used
instead.
</para>
<variablelist>
<varlistentry>
<term>SIGHUP</term>
<listitem>
<para>
Force a reload of the server.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>SIGINT, SIGTERM</term>
<listitem>
<para>
Shut down the server.
</para>
</listitem>
</varlistentry>
</variablelist>
<para>
The result of sending any other signals to the server is undefined.
</para>
</refsection>
<refsection><info><title>CONFIGURATION</title></info>
<para>
The <command>named</command> configuration file is too complex
to describe in detail here. A complete description is provided
in the
<citetitle>BIND 9 Administrator Reference Manual</citetitle>.
</para>
<para>
<command>named</command> inherits the <function>umask</function>
(file creation mode mask) from the parent process. If files
created by <command>named</command>, such as journal files,
need to have custom permissions, the <function>umask</function>
should be set explicitly in the script used to start the
<command>named</command> process.
</para>
</refsection>
<refsection><info><title>FILES</title></info>
<variablelist>
<varlistentry>
<term><filename>/etc/named.conf</filename></term>
<listitem>
<para>
The default configuration file.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term><filename>/var/run/named/named.pid</filename></term>
<listitem>
<para>
The default process-id file.
</para>
</listitem>
</varlistentry>
</variablelist>
</refsection>
<refsection><info><title>SEE ALSO</title></info>
<para><citetitle>RFC 1033</citetitle>,
<citetitle>RFC 1034</citetitle>,
<citetitle>RFC 1035</citetitle>,
<citerefentry>
<refentrytitle>named-checkconf</refentrytitle>
<manvolnum>8</manvolnum>
</citerefentry>,
<citerefentry>
<refentrytitle>named-checkzone</refentrytitle>
<manvolnum>8</manvolnum>
</citerefentry>,
<citerefentry>
<refentrytitle>rndc</refentrytitle>
<manvolnum>8</manvolnum>
</citerefentry>,
<citerefentry>
<refentrytitle>lwresd</refentrytitle>
<manvolnum>8</manvolnum>
</citerefentry>,
<citerefentry>
<refentrytitle>named.conf</refentrytitle>
<manvolnum>5</manvolnum>
</citerefentry>,
<citetitle>BIND 9 Administrator Reference Manual</citetitle>.
</para>
</refsection>
</refentry>