rndc.docbook revision 1479200aa05414b2acf33607dbd1682c16f58c51
ac4e70ff8955669341f435bc0a734a17c01af124Mark Andrews<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
885f47576842cf3c569315b9a48bd9f0ca03f203Automatic Updater "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
71bd43eebd9d6e42dbcae62b730f5b6508d5acd8Automatic Updater [<!ENTITY mdash "&#8212;">]>
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater<!--
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater - Copyright (C) 2004, 2005, 2007, 2013-2015 Internet Systems Consortium, Inc. ("ISC")
2bb3422dc683c013db7042f5736240de6b86f182Automatic Updater - Copyright (C) 2000, 2001 Internet Software Consortium.
0bddff542cf2ae1b6595020f2f72ca482c6b438fAutomatic Updater -
75b70a68aefaa17ac4e768d5ed85d2f50d471490Automatic Updater - Permission to use, copy, modify, and/or distribute this software for any
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater - purpose with or without fee is hereby granted, provided that the above
ea854b585041ad19f70f7af15e08144ef2c2bd1bMark Andrews - copyright notice and this permission notice appear in all copies.
78cb74fab4665da2e2641ba909c6f59f74cc4193Automatic Updater -
c89d02f2fb4c06168236d600e86831cff324f763Mark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
90ff38a0d8deaf5f9c2aa5916d99b2e572d28738Automatic Updater - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
ac4e70ff8955669341f435bc0a734a17c01af124Mark Andrews - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater - PERFORMANCE OF THIS SOFTWARE.
bc0a53583d92309bebcf93c408e2f3247ebd3d3cAutomatic Updater-->
56874aef380a64a2c183b7c282c3e7a361d67fa1Automatic Updater
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<refentry id="man.rndc">
96713299d08c0735c18ebe8772dd2cc1ecd4356aAutomatic Updater <refentryinfo>
3cc98b8ecedcbc8465f1cf2740b966b315662430Automatic Updater <date>August 15, 2014</date>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews </refentryinfo>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews
96713299d08c0735c18ebe8772dd2cc1ecd4356aAutomatic Updater <refmeta>
80faf1588895fd26490f82f95a7a1b771df1c324Automatic Updater <refentrytitle><application>rndc</application></refentrytitle>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <manvolnum>8</manvolnum>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater <refmiscinfo>BIND9</refmiscinfo>
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews </refmeta>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson <refnamediv>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater <refname><application>rndc</application></refname>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater <refpurpose>name server control utility</refpurpose>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson </refnamediv>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <docinfo>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <copyright>
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt <year>2004</year>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <year>2005</year>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <year>2007</year>
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt <year>2013</year>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <year>2014</year>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <year>2015</year>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt </copyright>
2d2dc37599979c83495510f8af8d1756753aa2c5Automatic Updater <copyright>
2d2dc37599979c83495510f8af8d1756753aa2c5Automatic Updater <year>2000</year>
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt <year>2001</year>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <holder>Internet Software Consortium.</holder>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater </copyright>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater </docinfo>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <refsynopsisdiv>
cdfc81e048bd34c1d628380247bda6b80a89e20eAutomatic Updater <cmdsynopsis>
cdfc81e048bd34c1d628380247bda6b80a89e20eAutomatic Updater <command>rndc</command>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <arg><option>-b <replaceable class="parameter">source-address</replaceable></option></arg>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <arg><option>-c <replaceable class="parameter">config-file</replaceable></option></arg>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <arg><option>-k <replaceable class="parameter">key-file</replaceable></option></arg>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <arg><option>-s <replaceable class="parameter">server</replaceable></option></arg>
eabc9c3c07cd956d3c436bd7614cb162dabdda76Mark Andrews <arg><option>-p <replaceable class="parameter">port</replaceable></option></arg>
eabc9c3c07cd956d3c436bd7614cb162dabdda76Mark Andrews <arg><option>-q</option></arg>
eabc9c3c07cd956d3c436bd7614cb162dabdda76Mark Andrews <arg><option>-r</option></arg>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <arg><option>-V</option></arg>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater <arg><option>-y <replaceable class="parameter">key_id</replaceable></option></arg>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <arg choice="req">command</arg>
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater </cmdsynopsis>
80faf1588895fd26490f82f95a7a1b771df1c324Automatic Updater </refsynopsisdiv>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater <refsect1>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <title>DESCRIPTION</title>
db5b7e2cdf150c46e8242d3e2e3ad3f5c7300258Automatic Updater <para><command>rndc</command>
80faf1588895fd26490f82f95a7a1b771df1c324Automatic Updater controls the operation of a name
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews server. It supersedes the <command>ndc</command> utility
1a06700908f5a1d9f4a8d51285a0fd971e2f9117Automatic Updater that was provided in old BIND releases. If
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <command>rndc</command> is invoked with no command line
db5b7e2cdf150c46e8242d3e2e3ad3f5c7300258Automatic Updater options or arguments, it prints a short summary of the
4b2cb1422c7c600fbc13b1cb06a8b4693bc11af8Mark Andrews supported commands and the available options and their
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews arguments.
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater </para>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson <para><command>rndc</command>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater communicates with the name server over a TCP connection, sending
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater commands authenticated with digital signatures. In the current
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews versions of
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater <command>rndc</command> and <command>named</command>,
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson the only supported authentication algorithms are HMAC-MD5
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater (for compatibility), HMAC-SHA1, HMAC-SHA224, HMAC-SHA256
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater (default), HMAC-SHA384 and HMAC-SHA512.
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson They use a shared secret on each end of the connection.
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater This provides TSIG-style authentication for the command
dd65eb1efb40b1c47d57963192bfc54873b219beAutomatic Updater request and the name server's response. All commands sent
dd65eb1efb40b1c47d57963192bfc54873b219beAutomatic Updater over the channel must be signed by a key_id known to the
9174e44c14b1cb91a651fa1dc29470438c246ab9Automatic Updater server.
55e03fc54708d97917bf26639b987f759bdc1f44Automatic Updater </para>
9174e44c14b1cb91a651fa1dc29470438c246ab9Automatic Updater <para><command>rndc</command>
9174e44c14b1cb91a651fa1dc29470438c246ab9Automatic Updater reads a configuration file to
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont determine how to contact the name server and decide what
52367885450d8f61d4f2d63292beb15ba8f39ac7Automatic Updater algorithm and key it should use.
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater </para>
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont </refsect1>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews
52367885450d8f61d4f2d63292beb15ba8f39ac7Automatic Updater <refsect1>
9174e44c14b1cb91a651fa1dc29470438c246ab9Automatic Updater <title>OPTIONS</title>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews
dd65eb1efb40b1c47d57963192bfc54873b219beAutomatic Updater <variablelist>
dd65eb1efb40b1c47d57963192bfc54873b219beAutomatic Updater <varlistentry>
dd65eb1efb40b1c47d57963192bfc54873b219beAutomatic Updater <term>-b <replaceable class="parameter">source-address</replaceable></term>
dd65eb1efb40b1c47d57963192bfc54873b219beAutomatic Updater <listitem>
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater <para>
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater Use <replaceable class="parameter">source-address</replaceable>
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater as the source address for the connection to the server.
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater Multiple instances are permitted to allow setting of both
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews the IPv4 and IPv6 source addresses.
885f47576842cf3c569315b9a48bd9f0ca03f203Automatic Updater </para>
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater </listitem>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews </varlistentry>
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater <varlistentry>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater <term>-c <replaceable class="parameter">config-file</replaceable></term>
cdfc81e048bd34c1d628380247bda6b80a89e20eAutomatic Updater <listitem>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater <para>
fe80a4909bf62b602feaf246866e9d29f7654194Automatic Updater Use <replaceable class="parameter">config-file</replaceable>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater as the configuration file instead of the default,
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater <filename>/etc/rndc.conf</filename>.
fe80a4909bf62b602feaf246866e9d29f7654194Automatic Updater </para>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater </listitem>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater </varlistentry>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater <varlistentry>
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews <term>-k <replaceable class="parameter">key-file</replaceable></term>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson <listitem>
dd65eb1efb40b1c47d57963192bfc54873b219beAutomatic Updater <para>
dd65eb1efb40b1c47d57963192bfc54873b219beAutomatic Updater Use <replaceable class="parameter">key-file</replaceable>
dd65eb1efb40b1c47d57963192bfc54873b219beAutomatic Updater as the key file instead of the default,
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater <filename>/etc/rndc.key</filename>. The key in
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater <filename>/etc/rndc.key</filename> will be used to
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater authenticate
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater commands sent to the server if the <replaceable class="parameter">config-file</replaceable>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson does not exist.
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater </para>
d145b64cacc8d9cda51f9924ec70cd4661c3e2cfAutomatic Updater </listitem>
0df8ead472f207020f8da22a185fe4b945248ab8Automatic Updater </varlistentry>
e8c7dc2a5ce48f11c07a67c9923eeb8f419ff19fEvan Hunt
0ce87e5749aabb8eef1e0a37e4bd6e6ffa1d7196Automatic Updater <varlistentry>
0ce87e5749aabb8eef1e0a37e4bd6e6ffa1d7196Automatic Updater <term>-s <replaceable class="parameter">server</replaceable></term>
0df8ead472f207020f8da22a185fe4b945248ab8Automatic Updater <listitem>
2bb3422dc683c013db7042f5736240de6b86f182Automatic Updater <para><replaceable class="parameter">server</replaceable> is
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater the name or address of the server which matches a
0df8ead472f207020f8da22a185fe4b945248ab8Automatic Updater server statement in the configuration file for
3b6e4c84a525b0b3fc9e8affd8bb9fa5c000345fAutomatic Updater <command>rndc</command>. If no server is supplied on the
19b3dc94bce93fa76bd7e066f9298630dbc9dcb4Automatic Updater command line, the host named by the default-server clause
d145b64cacc8d9cda51f9924ec70cd4661c3e2cfAutomatic Updater in the options statement of the <command>rndc</command>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater configuration file will be used.
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater </para>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater </listitem>
c243d779731a410f8dc2d2feeed20c15f299b6e3Automatic Updater </varlistentry>
0df8ead472f207020f8da22a185fe4b945248ab8Automatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term>-p <replaceable class="parameter">port</replaceable></term>
bc0a53583d92309bebcf93c408e2f3247ebd3d3cAutomatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Send commands to TCP port
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater <replaceable class="parameter">port</replaceable>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater instead
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater of BIND 9's default control channel port, 953.
7f79131f9a8e804b93c57f3c679065cce878b726Automatic Updater </para>
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
7f94d9a8162c9a96b56e66176702b66e79d8e1a2Automatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term>-q</term>
19b3dc94bce93fa76bd7e066f9298630dbc9dcb4Automatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater Quiet mode: Message text returned by the server
7f94d9a8162c9a96b56e66176702b66e79d8e1a2Automatic Updater will not be printed except when there is an error.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
71bd43eebd9d6e42dbcae62b730f5b6508d5acd8Automatic Updater <term>-r</term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
7262eb86f2b465822206122921e2f357218f0cfdAutomatic Updater <para>
96ea71632887c58a9d00f47eb318bf76b35903c3Mark Andrews Instructs <command>rndc</command> to print the result code
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater returned by <command>named</command> after executing the
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater requested command (e.g., ISC_R_SUCCESS, ISC_R_FAILURE, etc).
bbb069be941f649228760edcc241122933c066d2Automatic Updater </para>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater </listitem>
4cda4fd158d6ded5586bacea8c388445d99611eaAutomatic Updater </varlistentry>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater <varlistentry>
80faf1588895fd26490f82f95a7a1b771df1c324Automatic Updater <term>-V</term>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater Enable verbose logging.
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews </para>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews </listitem>
70f5a54bf2676b136aa838d1ee9688e00b5dd8b9Automatic Updater </varlistentry>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews
f7c88d61cc1ad2435b0b7cfaedfc9d5248c0be25Automatic Updater <varlistentry>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <term>-y <replaceable class="parameter">key_id</replaceable></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
bc0a53583d92309bebcf93c408e2f3247ebd3d3cAutomatic Updater <para>
7f94d9a8162c9a96b56e66176702b66e79d8e1a2Automatic Updater Use the key <replaceable class="parameter">key_id</replaceable>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater from the configuration file.
7f94d9a8162c9a96b56e66176702b66e79d8e1a2Automatic Updater <replaceable class="parameter">key_id</replaceable>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater must be
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater known by <command>named</command> with the same algorithm and secret string
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington in order for control message validation to succeed.
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater If no <replaceable class="parameter">key_id</replaceable>
cf7e98f59148b559946a7f1ca728471374f1eef3Automatic Updater is specified, <command>rndc</command> will first look
96713299d08c0735c18ebe8772dd2cc1ecd4356aAutomatic Updater for a key clause in the server statement of the server
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater being used, or if no server statement is present for that
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater host, then the default-key clause of the options statement.
cf7e98f59148b559946a7f1ca728471374f1eef3Automatic Updater Note that the configuration file contains shared secrets
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater which are used to send authenticated control commands
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson to name servers. It should therefore not have general read
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater or write access.
361bec4bdec45042897fb479b7071cd05bbd56b9Automatic Updater </para>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater </listitem>
71bd43eebd9d6e42dbcae62b730f5b6508d5acd8Automatic Updater </varlistentry>
0ce87e5749aabb8eef1e0a37e4bd6e6ffa1d7196Automatic Updater
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </variablelist>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater </refsect1>
3857cb6fcabeb79d85de4b3e3e4ab99912b701f8Mark Andrews
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater <refsect1>
80faf1588895fd26490f82f95a7a1b771df1c324Automatic Updater <title>COMMANDS</title>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <para>
9174e44c14b1cb91a651fa1dc29470438c246ab9Automatic Updater A list of commands supported by <command>rndc</command> can
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson be seen by running <command>rndc</command> without arguments.
e2caa7536302de34de6cc04025abcd53dc3a499aAutomatic Updater </para>
56e7dc0c24b04210dcbffb180a9e35644fb820daAutomatic Updater <para>
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater Currently supported commands are:
8292deab031e7599cd7622aa7675fbe139ca6095Mark Andrews </para>
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater <variablelist>
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater
699487d8026a2b931bdce8ce3ae6bc1025d639fbMark Andrews <varlistentry>
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater <term><userinput>addzone <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional> <replaceable>configuration</replaceable> </userinput></term>
3351ccbd5c1961404044f8273d54dad405f53960Mark Andrews <listitem>
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater <para>
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater Add a zone while the server is running. This
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater command requires the
3351ccbd5c1961404044f8273d54dad405f53960Mark Andrews <command>allow-new-zones</command> option to be set
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater to <userinput>yes</userinput>. The
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater <replaceable>configuration</replaceable> string
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater specified on the command line is the zone
3351ccbd5c1961404044f8273d54dad405f53960Mark Andrews configuration text that would ordinarily be
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater placed in <filename>named.conf</filename>.
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater </para>
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater <para>
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater The configuration is saved in a file called
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater <filename><replaceable>name</replaceable>.nzf</filename>,
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater where <replaceable>name</replaceable> is the
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater name of the view, or if it contains characters
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater that are incompatible with use as a file name, a
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater cryptographic hash generated from the name
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater of the view.
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater When <command>named</command> is
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater restarted, the file will be loaded into the view
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater configuration, so that zones that were added
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater can persist after a restart.
e8fc8c884b44371784805e1e0d3100da403dd3f1Automatic Updater </para>
e8fc8c884b44371784805e1e0d3100da403dd3f1Automatic Updater <para>
e8fc8c884b44371784805e1e0d3100da403dd3f1Automatic Updater This sample <command>addzone</command> command
e8fc8c884b44371784805e1e0d3100da403dd3f1Automatic Updater would add the zone <literal>example.com</literal>
e8fc8c884b44371784805e1e0d3100da403dd3f1Automatic Updater to the default view:
e8fc8c884b44371784805e1e0d3100da403dd3f1Automatic Updater </para>
e8fc8c884b44371784805e1e0d3100da403dd3f1Automatic Updater <para>
e8fc8c884b44371784805e1e0d3100da403dd3f1Automatic Updater<prompt>$ </prompt><userinput>rndc addzone example.com '{ type master; file "example.com.db"; };'</userinput>
e8fc8c884b44371784805e1e0d3100da403dd3f1Automatic Updater </para>
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater <para>
807ffe7aba4095b2f25c75ac1459f9efcd017eebMark Andrews (Note the brackets and semi-colon around the zone
7d12a6b412fe47e6d6582923fd6954ab8cd0baebAutomatic Updater configuration text.)
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater <para>
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater See also <command>rndc delzone</command> and <command>rndc modzone</command>.
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews </para>
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews
4b2cb1422c7c600fbc13b1cb06a8b4693bc11af8Mark Andrews <varlistentry>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <term><userinput>delzone <optional>-clean</optional> <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional> </userinput></term>
4b2cb1422c7c600fbc13b1cb06a8b4693bc11af8Mark Andrews <listitem>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Delete a zone while the server is running.
7f79131f9a8e804b93c57f3c679065cce878b726Automatic Updater </para>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater <para>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson If the <option>-clean</option> argument is specified,
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater the zone's master file (and journal file, if any)
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews will be deleted along with the zone. Without the
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews <option>-clean</option> option, zone files must
ac4e70ff8955669341f435bc0a734a17c01af124Mark Andrews be cleaned up by hand. (If the zone is of
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington type "slave" or "stub", the files needing to
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington be cleaned up will be reported in the output
b4cebdb6ccde66a8f3e397a1b90b0cf788519d69Automatic Updater of the <command>rndc delzone</command> command.)
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater If the zone was originally added via
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater <command>rndc addzone</command>, then it will be
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater removed permanently. However, if it was originally
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater configured in <filename>named.conf</filename>, then
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater that original configuration is still in place; when
bc0a4c01beede169df81a3ee5b614ed9e82339dbAutomatic Updater the server is restarted or reconfigured, the zone will
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington come back. To remove it permanently, it must also be
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater removed from <filename>named.conf</filename>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington See also <command>rndc addzone</command> and <command>rndc modzone</command>.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <term><userinput>dumpdb <optional>-all|-cache|-zone|-adb|-bad|-fail</optional> <optional><replaceable>view ...</replaceable></optional></userinput></term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Dump the server's caches (default) and/or zones to
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington the
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington dump file for the specified views. If no view is
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington specified, all
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington views are dumped.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington (See the <command>dump-file</command> option in
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington the BIND 9 Administrator Reference Manual.)
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <term><userinput>flush</userinput></term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Flushes the server's cache.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <term><userinput>flushname</userinput> <replaceable>name</replaceable> <optional><replaceable>view</replaceable></optional> </term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Flushes the given name from the view's DNS cache
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington and, if applicable, from the view's nameserver address
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington database, bad server cache and SERVFAIL cache.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <term><userinput>flushtree</userinput> <replaceable>name</replaceable> <optional><replaceable>view</replaceable></optional> </term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Flushes the given name, and all of its subdomains,
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington from the view's DNS cache, address database,
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington bad server cache, and SERVFAIL cache.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
a26b22914b7bf25f065afb8cdef983766dcd672bAutomatic Updater </listitem>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater </varlistentry>
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater <varlistentry>
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater <term><userinput>freeze <optional><replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></optional></userinput></term>
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater <listitem>
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater <para>
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater Suspend updates to a dynamic zone. If no zone is
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater specified, then all zones are suspended. This allows
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater manual edits to be made to a zone normally updated by
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater dynamic update. It also causes changes in the
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater journal file to be synced into the master file.
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater All dynamic update attempts will be refused while
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater the zone is frozen.
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater </para>
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater <para>
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater See also <command>rndc thaw</command>.
0d3490f93bb980fde704055e74c1b508987a5fe4Mark Andrews </para>
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington </listitem>
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington </varlistentry>
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington <varlistentry>
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews <term><userinput>halt <optional>-p</optional></userinput></term>
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews Stop the server immediately. Recent changes
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington made through dynamic update or IXFR are not saved to
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews the master files, but will be rolled forward from the
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater journal files when the server is restarted.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington If <option>-p</option> is specified <command>named</command>'s process id is returned.
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater This allows an external process to determine when <command>named</command>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater had completed halting.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington See also <command>rndc stop</command>.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
a26b22914b7bf25f065afb8cdef983766dcd672bAutomatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>loadkeys <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Fetch all DNSSEC keys for the given zone
c01dec514a81ecf8c17ca3ef8c3ba95e437295ebAutomatic Updater from the key directory. If they are within
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater their publication period, merge them into the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater zone's DNSKEY RRset. Unlike <command>rndc
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater sign</command>, however, the zone is not
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater immediately re-signed by the new keys, but is
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater allowed to incrementally re-sign over time.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater This command requires that the
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <command>auto-dnssec</command> zone option
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington be set to <literal>maintain</literal>,
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington and also requires the zone to be configured to
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington allow dynamic DNS.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington (See "Dynamic Update Policies" in the Administrator
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Reference Manual for more details.)
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <term><userinput>managed-keys <replaceable>(status | refresh | sync)</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></userinput></term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington When run with the "status" keyword, print the current
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington status of the managed-keys database for the specified
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington view, or for all views if none is specified. When run
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington with the "refresh" keyword, force an immediate refresh
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews of all the managed-keys in the specified view, or all
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews views. When run with the "sync" keyword, force an
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington immediate dump of the managed-keys database to disk (in
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington the file <filename>managed-keys.bind</filename> or
a26b22914b7bf25f065afb8cdef983766dcd672bAutomatic Updater (<filename><replaceable>viewname</replaceable>.mkeys</filename>).
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater </varlistentry>
a26b22914b7bf25f065afb8cdef983766dcd672bAutomatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater <term><userinput>modzone <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional> <replaceable>configuration</replaceable> </userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater Modify the configuration of a zone while the server
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington is running. This command requires the
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews <command>allow-new-zones</command> option to be
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews set to <userinput>yes</userinput>. As with
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <command>addzone</command>, the
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <replaceable>configuration</replaceable> string
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington specified on the command line is the zone
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington configuration text that would ordinarily be
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington placed in <filename>named.conf</filename>.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington If the zone was originally added via
b7aab05edae933e169d5f83c653935b17c7f0a8bMark Andrews <command>rndc addzone</command>, the configuration
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington changes will be recorded permanently and will still be
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington in effect after the server is restarted or reconfigured.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington However, if it was originally configured in
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews <filename>named.conf</filename>, then that original
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews configuration is still in place; when the server is
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington restarted or reconfigured, the zone will revert to
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington its original configuration. To make the changes
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews permanent, it must also be modified in
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <filename>named.conf</filename>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
a26b22914b7bf25f065afb8cdef983766dcd672bAutomatic Updater See also <command>rndc addzone</command> and <command>rndc delzone</command>.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <term><userinput>notify <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></userinput></term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Resend NOTIFY messages for the zone.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </varlistentry>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>notrace</userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Sets the server's debugging level to 0.
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater See also <command>rndc trace</command>.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews <varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <term><userinput>nta
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews <optional>( -d | -f | -r | -l <replaceable>duration</replaceable>)</optional>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <replaceable>domain</replaceable>
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews <optional><replaceable>view</replaceable></optional>
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews </userinput></term>
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews <listitem>
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews <para>
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews Sets a DNSSEC negative trust anchor (NTA)
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington for <option>domain</option>, with a lifetime of
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <option>duration</option>. The default lifetime is
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington configured in <filename>named.conf</filename> via the
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <option>nta-lifetime</option> option, and defaults to
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington one hour. The lifetime cannot exceed one week.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington A negative trust anchor selectively disables
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington DNSSEC validation for zones that are known to be
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington failing because of misconfiguration rather than
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington an attack. When data to be validated is
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington at or below an active NTA (and above any other
a26b22914b7bf25f065afb8cdef983766dcd672bAutomatic Updater configured trust anchors), <command>named</command> will
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater abort the DNSSEC validation process and treat the data as
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington insecure rather than bogus. This continues until the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater NTA's lifetime is elapsed.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater NTAs persist across restarts of the <command>named</command> server.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater The NTAs for a view are saved in a file called
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <filename><replaceable>name</replaceable>.nta</filename>,
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater where <replaceable>name</replaceable> is the
b0d566a2ce0f5a67f537ee7f8233f82f2584cc61Automatic Updater name of the view, or if it contains characters
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington that are incompatible with use as a file name, a
b4cebdb6ccde66a8f3e397a1b90b0cf788519d69Automatic Updater cryptographic hash generated from the name
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater of the view.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater An existing NTA can be removed by using the
068a66979695c77359e7a9181bb3f831c965b21cMark Andrews <option>-remove</option> option.
532d27b39244fadfcf8d8b4593f4c65434c9c664Automatic Updater </para>
532d27b39244fadfcf8d8b4593f4c65434c9c664Automatic Updater <para>
532d27b39244fadfcf8d8b4593f4c65434c9c664Automatic Updater An NTA's lifetime can be specified with the
532d27b39244fadfcf8d8b4593f4c65434c9c664Automatic Updater <option>-lifetime</option> option. TTL-style
532d27b39244fadfcf8d8b4593f4c65434c9c664Automatic Updater suffixes can be used to specify the lifetime in
532d27b39244fadfcf8d8b4593f4c65434c9c664Automatic Updater seconds, minutes, or hours. If the specified NTA
532d27b39244fadfcf8d8b4593f4c65434c9c664Automatic Updater already exists, its lifetime will be updated to the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater new value. Setting <option>lifetime</option> to zero
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington is equivalent to <option>-remove</option>.
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington </para>
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater If <option>-dump</option> is used, any other arguments
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater are ignored, and a list of existing NTAs is printed
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington (note that this may include NTAs that are expired but
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater have not yet been cleaned up).
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Normally, <command>named</command> will periodically
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater test to see whether data below an NTA can now be
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater validated (see the <option>nta-recheck</option> option
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater in the Administrator Reference Manual for details).
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater If data can be validated, then the NTA is regarded as
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater no longer necessary, and will be allowed to expire
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater early. The <option>-force</option> overrides this
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater behavior and forces an NTA to persist for its entire
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater lifetime, regardless of whether data could be
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater validated if the NTA were not present.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater All of these options can be shortened, i.e., to
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater <option>-l</option>, <option>-r</option>, <option>-d</option>,
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater and <option>-f</option>.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>querylog</userinput> <optional>on|off</optional> </term>
47ce374fcf4bac7a56bb69f5dae1d30be5b4376dAutomatic Updater <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Enable or disable query logging. (For backward
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater compatibility, this command can also be used without
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater an argument to toggle query logging on and off.)
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Query logging can also be enabled
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington by explicitly directing the <command>queries</command>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <command>category</command> to a
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <command>channel</command> in the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <command>logging</command> section of
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <filename>named.conf</filename> or by specifying
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <command>querylog yes;</command> in the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <command>options</command> section of
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <filename>named.conf</filename>.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>reconfig</userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Reload the configuration file and load new zones,
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater but do not reload existing zone files even if they
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater have changed.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater This is faster than a full <command>reload</command> when there
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater is a large number of zones because it avoids the need
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater to examine the
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater modification times of the zones files.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
068a66979695c77359e7a9181bb3f831c965b21cMark Andrews
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>recursing</userinput></term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Dump the list of queries <command>named</command> is currently
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater recursing on, and the list of domains to which iterative
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington queries are currently being sent. (The second list includes
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater the number of fetches currently active for the given domain,
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater and how many have been passed or dropped because of the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <option>fetches-per-zone</option> option.)
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
2da2220fe7af2c45724b50b0187523b1fab0cf08Rob Austein <term><userinput>refresh <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></userinput></term>
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Schedule zone maintenance for the given zone.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater </varlistentry>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater <term><userinput>reload</userinput></term>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater <listitem>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater <para>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater Reload configuration file and zones.
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater </para>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater </listitem>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater </varlistentry>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater <varlistentry>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater <term><userinput>reload <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></userinput></term>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater <listitem>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater <para>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater Reload the given zone.
ae7e54b14c946e0984c191554db9abb4893f9349Automatic Updater </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>retransfer <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></userinput></term>
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater <listitem>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater <para>
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater Retransfer the given slave zone from the master server.
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater </para>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater If the zone is configured to use
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <command>inline-signing</command>, the signed
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington version of the zone is discarded; after the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater retransfer of the unsigned version is complete, the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater signed version will be regenerated with all new
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington signatures.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>scan</userinput></term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Scan the list of available network interfaces
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater for changes, without performing a full
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater <command>reconfig</command> or waiting for the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <command>interface-interval</command> timer.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
bbf7c3fd96ae5e02cb84743c581862e35327032aAutomatic Updater <term><userinput>secroots <optional>-</optional> <optional><replaceable>view ...</replaceable></optional></userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Dump the server's security roots and negative trust anchors
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater for the specified views. If no view is specified, all views
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater are dumped.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
7adcb4de92bf4383a4c5624c4ed256736d02bc6dMark Andrews <para>
6d3ca68adcd2e825d7de011d78f14002c8b7e55eAutomatic Updater If the first argument is "-", then the output is
7a6ad11e0185a73984410f3252f3c49c3a301dbdBrian Wellington returned via the <command>rndc</command> response channel
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater and printed to the standard output.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Otherwise, it is written to the secroots dump file, which
7a6ad11e0185a73984410f3252f3c49c3a301dbdBrian Wellington defaults to <filename>named.secroots</filename>, but can be
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater overridden via the <option>secroots-file</option> option in
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <filename>named.conf</filename>.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington See also <command>rndc managed-keys</command>.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>showzone <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional> </userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Print the configuration of a running zone.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater <para>
f65d2e1c04c806a185bf9f3120e80692f5ccd5e6Automatic Updater See also <command>rndc zonestatus</command>.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
bbb069be941f649228760edcc241122933c066d2Automatic Updater
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>sign <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></userinput></term>
e062b72f783cdb436a1a57a630bdff471dbb3038Mark Andrews <listitem>
d145b64cacc8d9cda51f9924ec70cd4661c3e2cfAutomatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Fetch all DNSSEC keys for the given zone
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater from the key directory (see the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <command>key-directory</command> option in
d145b64cacc8d9cda51f9924ec70cd4661c3e2cfAutomatic Updater the BIND 9 Administrator Reference Manual). If they are within
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater their publication period, merge them into the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater zone's DNSKEY RRset. If the DNSKEY RRset
3e79333aa37d3b88959372431a02af8a3eb7cfd9Automatic Updater is changed, then the zone is automatically
e076d0c88be69de7c190ab924d095e69d2e11f7aAndreas Gustafsson re-signed with the new key set.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews <para>
e076d0c88be69de7c190ab924d095e69d2e11f7aAndreas Gustafsson This command requires that the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <command>auto-dnssec</command> zone option be set
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater to <literal>allow</literal> or
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <literal>maintain</literal>,
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater and also requires the zone to be configured to
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater allow dynamic DNS.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater (See "Dynamic Update Policies" in the Administrator
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Reference Manual for more details.)
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater See also <command>rndc loadkeys</command>.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>signing <optional>( -list | -clear <replaceable>keyid/algorithm</replaceable> | -clear <literal>all</literal> | -nsec3param ( <replaceable>parameters</replaceable> | <literal>none</literal> ) | -serial <replaceable>value</replaceable> ) </optional> <replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional> </userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater List, edit, or remove the DNSSEC signing state records
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater for the specified zone. The status of ongoing DNSSEC
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater operations (such as signing or generating
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater NSEC3 chains) is stored in the zone in the form
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater of DNS resource records of type
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <command>sig-signing-type</command>.
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater <command>rndc signing -list</command> converts
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater these records into a human-readable form,
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater indicating which keys are currently signing
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington or have finished signing the zone, and which NSEC3
47ce374fcf4bac7a56bb69f5dae1d30be5b4376dAutomatic Updater chains are being created or removed.
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater </para>
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews <para>
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater <command>rndc signing -clear</command> can remove
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington a single key (specified in the same format that
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater <command>rndc signing -list</command> uses to
47ce374fcf4bac7a56bb69f5dae1d30be5b4376dAutomatic Updater display it), or all keys. In either case, only
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington completed keys are removed; any record indicating
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater that a key has not yet finished signing the zone
47ce374fcf4bac7a56bb69f5dae1d30be5b4376dAutomatic Updater will be retained.
47ce374fcf4bac7a56bb69f5dae1d30be5b4376dAutomatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
068a66979695c77359e7a9181bb3f831c965b21cMark Andrews <command>rndc signing -nsec3param</command> sets
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater the NSEC3 parameters for a zone. This is the
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington only supported mechanism for using NSEC3 with
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <command>inline-signing</command> zones.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Parameters are specified in the same format as
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington an NSEC3PARAM resource record: hash algorithm,
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater flags, iterations, and salt, in that order.
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater </para>
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater <para>
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater Currently, the only defined value for hash algorithm
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater is <literal>1</literal>, representing SHA-1.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington The <option>flags</option> may be set to
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater <literal>0</literal> or <literal>1</literal>,
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington depending on whether you wish to set the opt-out
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater bit in the NSEC3 chain. <option>iterations</option>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater defines the number of additional times to apply
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater the algorithm when generating an NSEC3 hash. The
53aed64e0f8553762fc0c380ee41cb42f514c7d5Brian Wellington <option>salt</option> is a string of data expressed
6de27e27ad6056d7c049feb912df5a6b9a56d1b8Automatic Updater in hexadecimal, a hyphen (`-') if no salt is
53aed64e0f8553762fc0c380ee41cb42f514c7d5Brian Wellington to be used, or the keyword <literal>auto</literal>,
6de27e27ad6056d7c049feb912df5a6b9a56d1b8Automatic Updater which causes <command>named</command> to generate a
6de27e27ad6056d7c049feb912df5a6b9a56d1b8Automatic Updater random 64-bit salt.
53aed64e0f8553762fc0c380ee41cb42f514c7d5Brian Wellington </para>
6de27e27ad6056d7c049feb912df5a6b9a56d1b8Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater So, for example, to create an NSEC3 chain using
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater the SHA-1 hash algorithm, no opt-out flag,
6de27e27ad6056d7c049feb912df5a6b9a56d1b8Automatic Updater 10 iterations, and a salt value of "FFFF", use:
af3e516f771c8ba376a8cd954a7233badfce8cdcAutomatic Updater <command>rndc signing -nsec3param 1 0 10 FFFF <replaceable>zone</replaceable></command>.
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews To set the opt-out flag, 15 iterations, and no
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews salt, use:
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews <command>rndc signing -nsec3param 1 1 15 - <replaceable>zone</replaceable></command>.
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews </para>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews <para>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews <command>rndc signing -nsec3param none</command>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews removes an existing NSEC3 chain and replaces it
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews with NSEC.
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews </para>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews <para>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews <command>rndc signing -serial value</command> sets
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews the serial number of the zone to value. If the value
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews would cause the serial number to go backwards it will
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews be rejected. The primary use is to set the serial on
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews inline signed zones.
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews </para>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews </listitem>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews </varlistentry>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews <varlistentry>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews <term><userinput>stats</userinput></term>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews <listitem>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews <para>
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews Write server statistics to the statistics file.
7e1a8f402e3881388db37152f71c698cb1f1c426Mark Andrews (See the <command>statistics-file</command> option in
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater the BIND 9 Administrator Reference Manual.)
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater </varlistentry>
af3e516f771c8ba376a8cd954a7233badfce8cdcAutomatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>status</userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Display status of the server.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Note that the number of zones includes the internal <command>bind/CH</command> zone
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater and the default <command>/IN</command>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater hint zone if there is not an
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater explicit root zone configured.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
5ae0e2c8b72fa44237edeb37d1945b1c3535ca39Automatic Updater </listitem>
f55369d776907119cd8699a4119d9c80daa7cae4Mark Andrews </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
f55369d776907119cd8699a4119d9c80daa7cae4Mark Andrews <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>stop <optional>-p</optional></userinput></term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Stop the server, making sure any recent changes
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater made through dynamic update or IXFR are first saved to
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington the master files of the updated zones.
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater If <option>-p</option> is specified <command>named</command>'s process id is returned.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington This allows an external process to determine when <command>named</command>
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater had completed stopping.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>See also <command>rndc halt</command>.</para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <term><userinput>sync <optional>-clean</optional> <optional><replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></optional></userinput></term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Sync changes in the journal file for a dynamic zone
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington to the master file. If the "-clean" option is
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater specified, the journal file is also removed. If
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater no zone is specified, then all zones are synced.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
73eb75dc212911e4da58a3ce0a4672d3910193ebBrian Wellington <term><userinput>thaw <optional><replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></optional></userinput></term>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater Enable updates to a frozen dynamic zone. If no
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater zone is specified, then all frozen zones are
73eb75dc212911e4da58a3ce0a4672d3910193ebBrian Wellington enabled. This causes the server to reload the zone
bbf7c3fd96ae5e02cb84743c581862e35327032aAutomatic Updater from disk, and re-enables dynamic updates after the
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater load has completed. After a zone is thawed,
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater dynamic updates will no longer be refused. If
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater the zone has changed and the
133e6d43fa82e80d3798be4de00f4540f485ec6cAutomatic Updater <command>ixfr-from-differences</command> option is
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater in use, then the journal file will be updated to
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater reflect changes in the zone. Otherwise, if the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater zone has changed, any existing journal file will be
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater removed.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>See also <command>rndc freeze</command>.</para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>trace</userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Increment the servers debugging level by one.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <term><userinput>trace <replaceable>level</replaceable></userinput></term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Sets the server's debugging level to an explicit
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater value.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </para>
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington See also <command>rndc notrace</command>.
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
8227257b1c0224a7991e04bb79dc5059d5062dfbAndreas Gustafsson <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>tsig-delete</userinput> <replaceable>keyname</replaceable> <optional><replaceable>view</replaceable></optional></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
8227257b1c0224a7991e04bb79dc5059d5062dfbAndreas Gustafsson <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Delete a given TKEY-negotiated key from the server.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater (This does not apply to statically configured TSIG
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater keys.)
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater </para>
8227257b1c0224a7991e04bb79dc5059d5062dfbAndreas Gustafsson </listitem>
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>tsig-list</userinput></term>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater List the names of all TSIG keys currently configured
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington for use by <command>named</command> in each view. The
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater list both statically configured keys and dynamic
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater TKEY-negotiated keys.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>validation ( on | off | check ) <optional><replaceable>view ...</replaceable></optional> </userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Enable, disable, or check the current status of
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater DNSSEC validation.
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater Note <command>dnssec-enable</command> also needs to be
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater set to <userinput>yes</userinput> or
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <userinput>auto</userinput> to be effective.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater It defaults to enabled.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
fd7c65dce9c2b1a3d12ca4df9074cd38019fdb5fAutomatic Updater <varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <term><userinput>zonestatus <optional><replaceable>zone</replaceable> <optional><replaceable>class</replaceable> <optional><replaceable>view</replaceable></optional></optional></optional></userinput></term>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Displays the current status of the given zone,
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater including the master file name and any include
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater files from which it was loaded, when it was most
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater recently loaded, the current serial number, the
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater number of nodes, whether the zone supports
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington dynamic updates, whether the zone is DNSSEC
601c1908d06375f5dea00ab98671a6c934d8a840Automatic Updater signed, whether it uses automatic DNSSEC key
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater management or inline signing, and the scheduled
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater refresh or expiry times for the zone.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater See also <command>rndc showzone</command>.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </listitem>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </varlistentry>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </variablelist>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </refsect1>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <refsect1>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <title>LIMITATIONS</title>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
b4cebdb6ccde66a8f3e397a1b90b0cf788519d69Automatic Updater There is currently no way to provide the shared secret for a
a26b22914b7bf25f065afb8cdef983766dcd672bAutomatic Updater <option>key_id</option> without using the configuration file.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </para>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para>
b4cebdb6ccde66a8f3e397a1b90b0cf788519d69Automatic Updater Several error messages could be clearer.
a26b22914b7bf25f065afb8cdef983766dcd672bAutomatic Updater </para>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater </refsect1>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <refsect1>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <title>SEE ALSO</title>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <para><citerefentry>
9cd5eb6fe0f26d65724b99216cb31dcdd12e4afdAutomatic Updater <refentrytitle>rndc.conf</refentrytitle><manvolnum>5</manvolnum>
0df8ead472f207020f8da22a185fe4b945248ab8Automatic Updater </citerefentry>,
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater <citerefentry>
0df8ead472f207020f8da22a185fe4b945248ab8Automatic Updater <refentrytitle>rndc-confgen</refentrytitle><manvolnum>8</manvolnum>
0df8ead472f207020f8da22a185fe4b945248ab8Automatic Updater </citerefentry>,
0df8ead472f207020f8da22a185fe4b945248ab8Automatic Updater <citerefentry>
0df8ead472f207020f8da22a185fe4b945248ab8Automatic Updater <refentrytitle>named</refentrytitle><manvolnum>8</manvolnum>
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater </citerefentry>,
cab3e375b77a980a5d4b7e5e4ee90167439e7934Mark Andrews <citerefentry>
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater <refentrytitle>named.conf</refentrytitle><manvolnum>5</manvolnum>
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater </citerefentry>,
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater <citerefentry>
cab3e375b77a980a5d4b7e5e4ee90167439e7934Mark Andrews <refentrytitle>ndc</refentrytitle><manvolnum>8</manvolnum>
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater </citerefentry>,
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater <citetitle>BIND 9 Administrator Reference Manual</citetitle>.
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater </para>
510f19039bcd402dff28c85114551179670f482aAutomatic Updater </refsect1>
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater
6c6a121295b30772cbf3dd75a51fb9d883051a0eAutomatic Updater <refsect1>
7f79131f9a8e804b93c57f3c679065cce878b726Automatic Updater <title>AUTHOR</title>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <para><corpauthor>Internet Systems Consortium</corpauthor>
7f79131f9a8e804b93c57f3c679065cce878b726Automatic Updater </para>
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater </refsect1>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater</refentry><!--
f2770f6b39a9b2a98afb7a11ed105f73f1570c1eAutomatic Updater - Local variables:
3a9593055ead76cbbb417aee2d2e656c2c92cf46Automatic Updater - mode: sgml
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater - End:
3a9593055ead76cbbb417aee2d2e656c2c92cf46Automatic Updater-->
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater