nsupdate.html revision d060d8669f5558690e7faf4a1c12fe5c02a7c60d
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - Copyright (C) 2000-2003 Internet Software Consortium.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - Permission to use, copy, modify, and/or distribute this software for any
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - purpose with or without fee is hereby granted, provided that the above
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - copyright notice and this permission notice appear in all copies.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan - PERFORMANCE OF THIS SOFTWARE.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan<!-- $Id: nsupdate.html,v 1.48 2009/10/16 04:20:32 tbox Exp $ -->
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan<a name="man.nsupdate"></a><div class="titlepage"></div>
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan<p><span class="application">nsupdate</span> — Dynamic DNS update utility</p>
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan<div class="cmdsynopsis"><p><code class="command">nsupdate</code> [<code class="option">-d</code>] [<code class="option">-D</code>] [[<code class="option">-g</code>] | [<code class="option">-o</code>] | [<code class="option">-l</code>] | [<code class="option">-y <em class="replaceable"><code>[<span class="optional">hmac:</span>]keyname:secret</code></em></code>] | [<code class="option">-k <em class="replaceable"><code>keyfile</code></em></code>]] [<code class="option">-t <em class="replaceable"><code>timeout</code></em></code>] [<code class="option">-u <em class="replaceable"><code>udptimeout</code></em></code>] [<code class="option">-r <em class="replaceable"><code>udpretries</code></em></code>] [<code class="option">-R <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-v</code>] [filename]</p></div>
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan<p><span><strong class="command">nsupdate</strong></span>
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan is used to submit Dynamic DNS Update requests as defined in RFC 2136
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan to a name server.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan This allows resource records to be added or removed from a zone
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan without manually editing the zone file.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan A single update request can contain requests to add or remove more than
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan resource record.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan Zones that are under dynamic control via
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan <span><strong class="command">nsupdate</strong></span>
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan or a DHCP server should not be edited by hand.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan Manual edits could
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan conflict with dynamic updates and cause data to be lost.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan The resource records that are dynamically added or removed with
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan <span><strong class="command">nsupdate</strong></span>
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan have to be in the same zone.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan Requests are sent to the zone's master server.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan This is identified by the MNAME field of the zone's SOA record.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan option makes
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan <span><strong class="command">nsupdate</strong></span>
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan operate in debug mode.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan This provides tracing information about the update requests that are
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan made and the replies received from the name server.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan The <code class="option">-D</code> option makes <span><strong class="command">nsupdate</strong></span>
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan report additional debugging information to <code class="option">-d</code>.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan The <code class="option">-L</code> option with an integer argument of zero or
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan higher sets the logging debug level. If zero, logging is disabled.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan Transaction signatures can be used to authenticate the Dynamic
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan DNS updates. These use the TSIG resource record type described
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan in RFC 2845 or the SIG(0) record described in RFC 2535 and
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan RFC 2931 or GSS-TSIG as described in RFC 3645. TSIG relies on
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan a shared secret that should only be known to
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan <span><strong class="command">nsupdate</strong></span> and the name server. Currently,
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan the only supported encryption algorithm for TSIG is HMAC-MD5,
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan which is defined in RFC 2104. Once other algorithms are
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan defined for TSIG, applications will need to ensure they select
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan the appropriate algorithm as well as the key when authenticating
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan each other. For instance, suitable <span class="type">key</span> and
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan <span class="type">server</span> statements would be added to
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan <code class="filename">/etc/named.conf</code> so that the name server
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan can associate the appropriate secret key and algorithm with
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan the IP address of the client application that will be using
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan TSIG authentication. SIG(0) uses public key cryptography.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan To use a SIG(0) key, the public key must be stored in a KEY
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan record in a zone served by the name server.
3744900be632496920d4c9aca8f94ba6db4dd882Dirk Hogan <span><strong class="command">nsupdate</strong></span> does not read
[<span class="optional"><em class="parameter"><code>hmac:</code></em></span>]<em class="parameter"><code>keyname:secret.</code></em>
<em class="parameter"><code>keyname</code></em> <em class="parameter"><code>keysecret</code></em> pair.
> update delete oldhost.example.com A
> update add newhost.example.com 86400 A 172.16.1.1
> prereq nxdomain nickname.example.com