rndc-confgen.docbook revision 17cb8353e999e3294e6619613f401af3f7b1540c
f743002678eb67b99bbc29fee116b65d9530fec0wrowe<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook V4.1//EN">
a34684a59b60a4173c25035d0c627ef17e6dc215rpluem - Copyright (C) 2004 Internet Systems Consortium, Inc. ("ISC")
1337c7673efc1f80f634139fbad7cbb98a0dc657ylavic - Copyright (C) 2001, 2003 Internet Software Consortium.
1337c7673efc1f80f634139fbad7cbb98a0dc657ylavic - Permission to use, copy, modify, and distribute this software for any
1337c7673efc1f80f634139fbad7cbb98a0dc657ylavic - purpose with or without fee is hereby granted, provided that the above
4da61833a1cbbca94094f9653fd970582b97a72etrawick - copyright notice and this permission notice appear in all copies.
4da61833a1cbbca94094f9653fd970582b97a72etrawick - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
4da61833a1cbbca94094f9653fd970582b97a72etrawick - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
4da61833a1cbbca94094f9653fd970582b97a72etrawick - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
4789804be088bcd86ae637a29cdb7fda25169521jailletc - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
4789804be088bcd86ae637a29cdb7fda25169521jailletc - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
4789804be088bcd86ae637a29cdb7fda25169521jailletc - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
4789804be088bcd86ae637a29cdb7fda25169521jailletc - PERFORMANCE OF THIS SOFTWARE.
e50c3026198fd496f183cda4c32a202925476778covener<!-- $Id: rndc-confgen.docbook,v 1.7 2004/06/03 02:22:34 marka Exp $ -->
6c3b9cebb551140fbb25d58bae08b539b3802133ylavic <refentryinfo>
6c3b9cebb551140fbb25d58bae08b539b3802133ylavic </refentryinfo>
0a0df13b7f1f4f1a74fe295253d89ca3911b301aylavic <refentrytitle><application>rndc-confgen</application></refentrytitle>
69301145375a889e7e37caf7cc7321ac0f91801erpluem <refnamediv>
69301145375a889e7e37caf7cc7321ac0f91801erpluem <refname><application>rndc-confgen</application></refname>
506bfe33206b2fece40ef25f695af39dd4130facjkaluza </refnamediv>
506bfe33206b2fece40ef25f695af39dd4130facjkaluza <refsynopsisdiv>
d58a848a016d401b965111e50ef829e1641f7834minfrin <cmdsynopsis>
2e6f4d654c96c98b761fb012fd25c5d5b1558c44sf <arg><option>-b <replaceable class="parameter">keysize</replaceable></option></arg>
2e6f4d654c96c98b761fb012fd25c5d5b1558c44sf <arg><option>-c <replaceable class="parameter">keyfile</replaceable></option></arg>
17e6c95f3b22d18acdf8380fb26a8d0e10c80767ylavic <arg><option>-k <replaceable class="parameter">keyname</replaceable></option></arg>
17e6c95f3b22d18acdf8380fb26a8d0e10c80767ylavic <arg><option>-p <replaceable class="parameter">port</replaceable></option></arg>
17e6c95f3b22d18acdf8380fb26a8d0e10c80767ylavic <arg><option>-r <replaceable class="parameter">randomfile</replaceable></option></arg>
17e6c95f3b22d18acdf8380fb26a8d0e10c80767ylavic <arg><option>-s <replaceable class="parameter">address</replaceable></option></arg>
17e6c95f3b22d18acdf8380fb26a8d0e10c80767ylavic <arg><option>-t <replaceable class="parameter">chrootdir</replaceable></option></arg>
e8bd80a4bb88199d2f9a24a50345688e52d9c116ylavic <arg><option>-u <replaceable class="parameter">user</replaceable></option></arg>
e8bd80a4bb88199d2f9a24a50345688e52d9c116ylavic </cmdsynopsis>
e8bd80a4bb88199d2f9a24a50345688e52d9c116ylavic </refsynopsisdiv>
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic <command>rndc-confgen</command> generates configuration files
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic convenient alternative to writing the
d7205b1a86c51c27b71a2c458dc453fd53a261c1covener statements in <filename>named.conf</filename> by hand.
d7205b1a86c51c27b71a2c458dc453fd53a261c1covener Alternatively, it can be run with the <command>-a</command>
44ff304057225e944e220e981d434a046d14cf06covener option to set up a <filename>rndc.key</filename> file and
44ff304057225e944e220e981d434a046d14cf06covener avoid the need for a <filename>rndc.conf</filename> file
44ff304057225e944e220e981d434a046d14cf06covener and a <command>controls</command> statement altogether.
5d1ba75b8794925e67591c209085a49279791de9covener </refsect1>
032982212dbcc7c3cce95bf89c503bb56e185ac7kbrand <variablelist>
caad2986f81ab263f7af41467dd622dc9add17f3ylavic <varlistentry>
45a10d38e6051fd7bdf9d742aaae633d97ff02abjailletc Do automatic <command>rndc</command> configuration.
a34684a59b60a4173c25035d0c627ef17e6dc215rpluem was specified as when <acronym>BIND</acronym> was built)
1e2d421a36999d292042a5539971070d54aa6c63ylavic command channel and authentication key allowing
fa7ed98b9dc94c5845cf845aea0a44ecacd290c9humbedooh with no further configuration.
0b67eb8568cd58bb77082703951679b42cf098actrawick BIND 9 and <command>rndc</command> to be used as drop-in
fb1985a97912b25ec6564c73e610a31e5fc6e25fcovener with no changes to the existing BIND 8
3060ce7f798fbda7999cd4ddf89b525d2b294185covener If a more elaborate configuration than that
c1a63b8fad09c419c1a64f75993feb8a343a6801ylavic is required, for example if rndc is to be used remotely,
c1a63b8fad09c419c1a64f75993feb8a343a6801ylavic you should run <command>rndc-confgen</command> without the
e466c40e1801982602ee0200c9e8b61cc148742djailletc as directed.
457468b82e59d01eba00dd9d0817309c8f5e414ejim </listitem>
457468b82e59d01eba00dd9d0817309c8f5e414ejim </varlistentry>
04983e3bd1754764eec7d6bb772fe3b0bf391771jorton <varlistentry>
15890c9306ba98f6fc243e15a3c4778ddc7d773erpluem <term>-b <replaceable class="parameter">keysize</replaceable></term>
49dacedb6c387b786b7911082ff35121a45f414bcovener Specifies the size of the authentication key in bits.
49dacedb6c387b786b7911082ff35121a45f414bcovener Must be between 1 and 512 bits; the default is 128.
cfd9415521847b2f9394fad04fb701cfb955f503rjung </listitem>
cfd9415521847b2f9394fad04fb701cfb955f503rjung </varlistentry>
28c31fb73c1264bd1d0ff932573677030b024c7dwrowe <varlistentry>
28c31fb73c1264bd1d0ff932573677030b024c7dwrowe <term>-c <replaceable class="parameter">keyfile</replaceable></term>
8491e0600f69b0405e156ea8a419653c065c645bcovener Used with the <command>-a</command> option to specify
63b9f1f5880391261705f696d7d65507bbe9ace3covener an alternate location for <filename>rndc.key</filename>.
63b9f1f5880391261705f696d7d65507bbe9ace3covener </listitem>
49dacedb6c387b786b7911082ff35121a45f414bcovener </varlistentry>
49dacedb6c387b786b7911082ff35121a45f414bcovener <varlistentry>
3c990331fc6702119e4f5b8ba9eae3021aea5265jim <listitem>
3c990331fc6702119e4f5b8ba9eae3021aea5265jim Prints a short summary of the options and arguments to
fc42512879dd0504532f52fe5d0d0383dda96a1eniq </listitem>
fc42512879dd0504532f52fe5d0d0383dda96a1eniq </varlistentry>
0451df5dc50fa5d8b3e07d92ee6a92e36a1181a5niq <varlistentry>
0451df5dc50fa5d8b3e07d92ee6a92e36a1181a5niq <term>-k <replaceable class="parameter">keyname</replaceable></term>
da0442c0440caef34706e2c2f3af05cb65921cc0jailletc Specifies the key name of the rndc authentication key.
da0442c0440caef34706e2c2f3af05cb65921cc0jailletc This must be a valid domain name.
06b8f183140c8e02e0974e938a05078b511d1603covener </listitem>
15890c9306ba98f6fc243e15a3c4778ddc7d773erpluem </varlistentry>
259878293a997ff49f5ddfc53d3739cbdc25444ecovener <varlistentry>
259878293a997ff49f5ddfc53d3739cbdc25444ecovener <term>-p <replaceable class="parameter">port</replaceable></term>
b54b024c06a19926832d77d40ba35ad8c41e4d3dminfrin Specifies the command channel port where <command>named</command>
b54b024c06a19926832d77d40ba35ad8c41e4d3dminfrin listens for connections from <command>rndc</command>.
b54b024c06a19926832d77d40ba35ad8c41e4d3dminfrin The default is 953.
65967d05f839dbf27cf91d91fa79585eeae19660minfrin </listitem>
65967d05f839dbf27cf91d91fa79585eeae19660minfrin </varlistentry>
8152945ae46857b170cb227e79bb799f4fc7710dminfrin <varlistentry>
8152945ae46857b170cb227e79bb799f4fc7710dminfrin <term>-r <replaceable class="parameter">randomfile</replaceable></term>
75f5c2db254c0167a0e396254460de09b775d203trawick Specifies a source of random data for generating the
75f5c2db254c0167a0e396254460de09b775d203trawick authorization. If the operating
75f5c2db254c0167a0e396254460de09b775d203trawick system does not provide a <filename>/dev/random</filename>
4f0358189bfa57b8e75bd6b94db264302a8f336amrumph or equivalent device, the default source of randomness
4f0358189bfa57b8e75bd6b94db264302a8f336amrumph is keyboard input. <filename>randomdev</filename> specifies
4f0358189bfa57b8e75bd6b94db264302a8f336amrumph the name of a character device or file containing random
5716f9c6daa92dde5f2f9d11ed63f7c9549c223atrawick data to be used instead of the default. The special value
5716f9c6daa92dde5f2f9d11ed63f7c9549c223atrawick <filename>keyboard</filename> indicates that keyboard
5716f9c6daa92dde5f2f9d11ed63f7c9549c223atrawick input should be used.
54d750a84a175d8e338880514d440773eb986b50covener </listitem>
54d750a84a175d8e338880514d440773eb986b50covener </varlistentry>
54d750a84a175d8e338880514d440773eb986b50covener <varlistentry>
54d750a84a175d8e338880514d440773eb986b50covener <term>-s <replaceable class="parameter">address</replaceable></term>
54d750a84a175d8e338880514d440773eb986b50covener Specifies the IP address where <command>named</command>
7a3aa12f0eda24793ee26d6a179bd53132e9dae8covener listens for command channel connections from
54d750a84a175d8e338880514d440773eb986b50covener <command>rndc</command>. The default is the loopback
54d750a84a175d8e338880514d440773eb986b50covener address 127.0.0.1.
4e30ef014533a7e93c92d88306291f5e49c9692ftrawick </listitem>
83b50288fa7d306324bba68832011ea08f5c7832covener </varlistentry>
5f066f496cd9f20a2a701255bc67d44e7cb46daetrawick <varlistentry>
5f066f496cd9f20a2a701255bc67d44e7cb46daetrawick <term>-t <replaceable class="parameter">chrootdir</replaceable></term>
2e15620d724fb8e3a5be183b917359a2fd6e9468covener Used with the <command>-a</command> option to specify
1b988c41ee505962781d110a3e4c2c90f1ea0aa4covener chrooted. An additional copy of the <filename>rndc.key</filename>
1b988c41ee505962781d110a3e4c2c90f1ea0aa4covener will be written relative to this directory so that
1b988c41ee505962781d110a3e4c2c90f1ea0aa4covener it will be found by the chrooted <command>named</command>.
b8efdc95bec9cf089aa1be0bfd07d46aa1137a7acovener </listitem>
b8efdc95bec9cf089aa1be0bfd07d46aa1137a7acovener </varlistentry>
f06e7c4b1bce6b6491e5de0b7998d3f5696b293dchrisd <varlistentry>
f06e7c4b1bce6b6491e5de0b7998d3f5696b293dchrisd <term>-u <replaceable class="parameter">user</replaceable></term>
179565be4043d7e5f9161aa75271fa0a001866d9covener Used with the <command>-a</command> option to set the owner
179565be4043d7e5f9161aa75271fa0a001866d9covener of the <filename>rndc.key</filename> file generated. If
111436a32ba1254291e4883292fb116d15fe8f64covener <command>-t</command> is also specified only the file in
fce4949fb0b309a5744afcd503c6ed2d35621ee2covener the chroot area has its owner changed.
fce4949fb0b309a5744afcd503c6ed2d35621ee2covener </listitem>
fce4949fb0b309a5744afcd503c6ed2d35621ee2covener </varlistentry>
7b7430e701e9a31ce809da7c220bb8dfcf68c86etrawick </variablelist>
7b7430e701e9a31ce809da7c220bb8dfcf68c86etrawick </refsect1>
273e512f20f262e5e2aa8e0e83371d1929fb76adjkaluza no manual configuration, run
993d1261a278d7322bccef219101220b7b4fb8c5jkaluza To print a sample <filename>rndc.conf</filename> file and
993d1261a278d7322bccef219101220b7b4fb8c5jkaluza corresponding <command>controls</command> and <command>key</command>
ba050a6f942b9fa0e81ed73437588005c569655ccovener statements to be manually inserted into <filename>named.conf</filename>,
135ddda3a989215d2bedbcf1529bfb269c3eda23niq </refsect1>
793214f67dede32edfd9ee96c664ead04d175cbbjfclere <citerefentry>
9b0076ddd1103e5fa9c1f9bafde4b06ce244fbaecovener </citerefentry>,
9b0076ddd1103e5fa9c1f9bafde4b06ce244fbaecovener <citerefentry>
249d09d51808cb7981af99762c3b3736ca126cd5jkaluza </citerefentry>,
249d09d51808cb7981af99762c3b3736ca126cd5jkaluza <citerefentry>
56589be3d7a3e9343370df240010c6928cc78b39jkaluza </citerefentry>,
77ca16c5676da23155311e13cee61e7eaba9fa3ejailletc <citetitle>BIND 9 Administrator Reference Manual</citetitle>.
77ca16c5676da23155311e13cee61e7eaba9fa3ejailletc </refsect1>
4d12805e6c18253040223ea637acd6b3b3c18f60jorton </refsect1>
a4df2cd1e1391575a327c2a90ba4315f805a0a78covener - Local variables:
a4df2cd1e1391575a327c2a90ba4315f805a0a78covener - mode: sgml