rndc.html revision 2eeb74d1cf5355dd98f6d507a10086e16bb08c4b
4610465ed9408cbe434dbfb8be8ea53f48969c91Bob Halley<!--
11e9368a226272085c337e9e74b79808c16fbdbaTinderbox User - Copyright (C) 2004, 2005, 2007, 2013-2015 Internet Systems Consortium, Inc. ("ISC")
75c0816e8295e180f4bc7f10db3d0d880383bc1cMark Andrews - Copyright (C) 2000, 2001 Internet Software Consortium.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein -
4a14ce5ba00ab7bc55c99ffdcf59c7a4ab902721Automatic Updater - Permission to use, copy, modify, and/or distribute this software for any
4610465ed9408cbe434dbfb8be8ea53f48969c91Bob Halley - purpose with or without fee is hereby granted, provided that the above
4610465ed9408cbe434dbfb8be8ea53f48969c91Bob Halley - copyright notice and this permission notice appear in all copies.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein -
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - PERFORMANCE OF THIS SOFTWARE.
4610465ed9408cbe434dbfb8be8ea53f48969c91Bob Halley-->
ea94d370123a5892f6c47a97f21d1b28d44bb168Tinderbox User<html>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<head>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<title>rndc</title>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<meta name="generator" content="DocBook XSL Stylesheets V1.76.1">
e21a2904f02a03fa06b6db04d348f65fe9c67b2bMark Andrews</head>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" title="rndc">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<a name="man.rndc"></a><div class="titlepage"></div>
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <div class="refnamediv">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<h2>Name</h2>
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User<p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <span class="application">rndc</span>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein &#8212; name server control utility
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein</div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <div class="refsynopsisdiv" title="Synopsis">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<h2>Synopsis</h2>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <div class="cmdsynopsis"><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <code class="command">rndc</code>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein [<code class="option">-b <em class="replaceable"><code>source-address</code></em></code>]
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>]
b2f07642fd712c8fda81a116bcdde229ab291f33Tinderbox User [<code class="option">-k <em class="replaceable"><code>key-file</code></em></code>]
b2f07642fd712c8fda81a116bcdde229ab291f33Tinderbox User [<code class="option">-s <em class="replaceable"><code>server</code></em></code>]
b2f07642fd712c8fda81a116bcdde229ab291f33Tinderbox User [<code class="option">-p <em class="replaceable"><code>port</code></em></code>]
c247e3f281613fabe1af362e9f3157e35ebbe52cMark Andrews [<code class="option">-q</code>]
b2f07642fd712c8fda81a116bcdde229ab291f33Tinderbox User [<code class="option">-r</code>]
b2f07642fd712c8fda81a116bcdde229ab291f33Tinderbox User [<code class="option">-V</code>]
b2f07642fd712c8fda81a116bcdde229ab291f33Tinderbox User [<code class="option">-y <em class="replaceable"><code>key_id</code></em></code>]
b2f07642fd712c8fda81a116bcdde229ab291f33Tinderbox User {command}
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <div class="refsection" title="DESCRIPTION">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<a name="idp61072208"></a><h2>DESCRIPTION</h2>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <p><span class="command"><strong>rndc</strong></span>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein controls the operation of a name
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein server. It supersedes the <span class="command"><strong>ndc</strong></span> utility
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein that was provided in old BIND releases. If
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <span class="command"><strong>rndc</strong></span> is invoked with no command line
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein options or arguments, it prints a short summary of the
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User supported commands and the available options and their
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein arguments.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <p><span class="command"><strong>rndc</strong></span>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User communicates with the name server over a TCP connection, sending
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User commands authenticated with digital signatures. In the current
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User versions of
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>rndc</strong></span> and <span class="command"><strong>named</strong></span>,
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User the only supported authentication algorithms are HMAC-MD5
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein (for compatibility), HMAC-SHA1, HMAC-SHA224, HMAC-SHA256
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein (default), HMAC-SHA384 and HMAC-SHA512.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User They use a shared secret on each end of the connection.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User This provides TSIG-style authentication for the command
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User request and the name server's response. All commands sent
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User over the channel must be signed by a key_id known to the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein server.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p><span class="command"><strong>rndc</strong></span>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User reads a configuration file to
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User determine how to contact the name server and decide what
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User algorithm and key it should use.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </div>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <div class="refsection" title="OPTIONS">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<a name="idp61076688"></a><h2>OPTIONS</h2>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <div class="variablelist"><dl>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term">-b <em class="replaceable"><code>source-address</code></em></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Use <em class="replaceable"><code>source-address</code></em>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User as the source address for the connection to the server.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Multiple instances are permitted to allow setting of both
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the IPv4 and IPv6 source addresses.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term">-c <em class="replaceable"><code>config-file</code></em></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
d3ddafd7469d1f3430ccd1b0fe0d13ccbbaf5debTinderbox User Use <em class="replaceable"><code>config-file</code></em>
d3ddafd7469d1f3430ccd1b0fe0d13ccbbaf5debTinderbox User as the configuration file instead of the default,
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <code class="filename">/etc/rndc.conf</code>.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User<dt><span class="term">-k <em class="replaceable"><code>key-file</code></em></span></dt>
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User<dd>
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User <p>
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User Use <em class="replaceable"><code>key-file</code></em>
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User as the key file instead of the default,
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User <code class="filename">/etc/rndc.key</code>. The key in
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <code class="filename">/etc/rndc.key</code> will be used to
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein authenticate
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User commands sent to the server if the <em class="replaceable"><code>config-file</code></em>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User does not exist.
c247e3f281613fabe1af362e9f3157e35ebbe52cMark Andrews </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term">-s <em class="replaceable"><code>server</code></em></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p><em class="replaceable"><code>server</code></em> is
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User the name or address of the server which matches a
24abfe433efd98bb2099b867fb14d049b2f1f531Tinderbox User server statement in the configuration file for
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>rndc</strong></span>. If no server is supplied on the
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User command line, the host named by the default-server clause
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User in the options statement of the <span class="command"><strong>rndc</strong></span>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User configuration file will be used.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Send commands to TCP port
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <em class="replaceable"><code>port</code></em>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein instead
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User of BIND 9's default control channel port, 953.
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User </p>
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User </dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-q</span></dt>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User<dd>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User <p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Quiet mode: Message text returned by the server
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User will not be printed except when there is an error.
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User </p>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User </dd>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User<dt><span class="term">-r</span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Instructs <span class="command"><strong>rndc</strong></span> to print the result code
395c95214142142854509945adf3293c0270e1c5Tinderbox User returned by <span class="command"><strong>named</strong></span> after executing the
395c95214142142854509945adf3293c0270e1c5Tinderbox User requested command (e.g., ISC_R_SUCCESS, ISC_R_FAILURE, etc).
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term">-V</span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Enable verbose logging.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term">-y <em class="replaceable"><code>key_id</code></em></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Use the key <em class="replaceable"><code>key_id</code></em>
395c95214142142854509945adf3293c0270e1c5Tinderbox User from the configuration file.
395c95214142142854509945adf3293c0270e1c5Tinderbox User <em class="replaceable"><code>key_id</code></em>
395c95214142142854509945adf3293c0270e1c5Tinderbox User must be
395c95214142142854509945adf3293c0270e1c5Tinderbox User known by <span class="command"><strong>named</strong></span> with the same algorithm and secret string
395c95214142142854509945adf3293c0270e1c5Tinderbox User in order for control message validation to succeed.
395c95214142142854509945adf3293c0270e1c5Tinderbox User If no <em class="replaceable"><code>key_id</code></em>
395c95214142142854509945adf3293c0270e1c5Tinderbox User is specified, <span class="command"><strong>rndc</strong></span> will first look
395c95214142142854509945adf3293c0270e1c5Tinderbox User for a key clause in the server statement of the server
395c95214142142854509945adf3293c0270e1c5Tinderbox User being used, or if no server statement is present for that
395c95214142142854509945adf3293c0270e1c5Tinderbox User host, then the default-key clause of the options statement.
395c95214142142854509945adf3293c0270e1c5Tinderbox User Note that the configuration file contains shared secrets
395c95214142142854509945adf3293c0270e1c5Tinderbox User which are used to send authenticated control commands
395c95214142142854509945adf3293c0270e1c5Tinderbox User to name servers. It should therefore not have general read
395c95214142142854509945adf3293c0270e1c5Tinderbox User or write access.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User</dl></div>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </div>
395c95214142142854509945adf3293c0270e1c5Tinderbox User
395c95214142142854509945adf3293c0270e1c5Tinderbox User <div class="refsection" title="COMMANDS">
395c95214142142854509945adf3293c0270e1c5Tinderbox User<a name="idp61102800"></a><h2>COMMANDS</h2>
395c95214142142854509945adf3293c0270e1c5Tinderbox User
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User A list of commands supported by <span class="command"><strong>rndc</strong></span> can
395c95214142142854509945adf3293c0270e1c5Tinderbox User be seen by running <span class="command"><strong>rndc</strong></span> without arguments.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Currently supported commands are:
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User
6d45011a65dfc43f476ca15c3fd9ee5227eb968fTinderbox User <div class="variablelist"><dl>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>addzone <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>] <em class="replaceable"><code>configuration</code></em> </code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Add a zone while the server is running. This
395c95214142142854509945adf3293c0270e1c5Tinderbox User command requires the
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>allow-new-zones</strong></span> option to be set
395c95214142142854509945adf3293c0270e1c5Tinderbox User to <strong class="userinput"><code>yes</code></strong>. The
395c95214142142854509945adf3293c0270e1c5Tinderbox User <em class="replaceable"><code>configuration</code></em> string
395c95214142142854509945adf3293c0270e1c5Tinderbox User specified on the command line is the zone
395c95214142142854509945adf3293c0270e1c5Tinderbox User configuration text that would ordinarily be
395c95214142142854509945adf3293c0270e1c5Tinderbox User placed in <code class="filename">named.conf</code>.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User The configuration is saved in a file called
395c95214142142854509945adf3293c0270e1c5Tinderbox User <code class="filename"><em class="replaceable"><code>name</code></em>.nzf</code>,
395c95214142142854509945adf3293c0270e1c5Tinderbox User where <em class="replaceable"><code>name</code></em> is the
395c95214142142854509945adf3293c0270e1c5Tinderbox User name of the view, or if it contains characters
395c95214142142854509945adf3293c0270e1c5Tinderbox User that are incompatible with use as a file name, a
395c95214142142854509945adf3293c0270e1c5Tinderbox User cryptographic hash generated from the name
395c95214142142854509945adf3293c0270e1c5Tinderbox User of the view.
395c95214142142854509945adf3293c0270e1c5Tinderbox User When <span class="command"><strong>named</strong></span> is
395c95214142142854509945adf3293c0270e1c5Tinderbox User restarted, the file will be loaded into the view
c0cbdeedb5e119c640f098da1851cb1b9adcc739Tinderbox User configuration, so that zones that were added
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User can persist after a restart.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User This sample <span class="command"><strong>addzone</strong></span> command
395c95214142142854509945adf3293c0270e1c5Tinderbox User would add the zone <code class="literal">example.com</code>
395c95214142142854509945adf3293c0270e1c5Tinderbox User to the default view:
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<code class="prompt">$ </code><strong class="userinput"><code>rndc addzone example.com '{ type master; file "example.com.db"; };'</code></strong>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User (Note the brackets and semi-colon around the zone
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User configuration text.)
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User See also <span class="command"><strong>rndc delzone</strong></span> and <span class="command"><strong>rndc modzone</strong></span>.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>delzone [<span class="optional">-clean</span>] <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>] </code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Delete a zone while the server is running.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User If the <code class="option">-clean</code> argument is specified,
395c95214142142854509945adf3293c0270e1c5Tinderbox User the zone's master file (and journal file, if any)
4f9cb7bd58e2c0a7407fee3758ea265aee329ac6Tinderbox User will be deleted along with the zone. Without the
4f9cb7bd58e2c0a7407fee3758ea265aee329ac6Tinderbox User <code class="option">-clean</code> option, zone files must
395c95214142142854509945adf3293c0270e1c5Tinderbox User be cleaned up by hand. (If the zone is of
395c95214142142854509945adf3293c0270e1c5Tinderbox User type "slave" or "stub", the files needing to
395c95214142142854509945adf3293c0270e1c5Tinderbox User be cleaned up will be reported in the output
395c95214142142854509945adf3293c0270e1c5Tinderbox User of the <span class="command"><strong>rndc delzone</strong></span> command.)
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User If the zone was originally added via
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>rndc addzone</strong></span>, then it will be
4f9cb7bd58e2c0a7407fee3758ea265aee329ac6Tinderbox User removed permanently. However, if it was originally
395c95214142142854509945adf3293c0270e1c5Tinderbox User configured in <code class="filename">named.conf</code>, then
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User that original configuration is still in place; when
4f9cb7bd58e2c0a7407fee3758ea265aee329ac6Tinderbox User the server is restarted or reconfigured, the zone will
395c95214142142854509945adf3293c0270e1c5Tinderbox User come back. To remove it permanently, it must also be
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User removed from <code class="filename">named.conf</code>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User See also <span class="command"><strong>rndc addzone</strong></span> and <span class="command"><strong>rndc modzone</strong></span>.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>dumpdb [<span class="optional">-all|-cache|-zone|-adb|-bad|-fail</span>] [<span class="optional"><em class="replaceable"><code>view ...</code></em></span>]</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Dump the server's caches (default) and/or zones to
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User the
395c95214142142854509945adf3293c0270e1c5Tinderbox User dump file for the specified views. If no view is
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User specified, all
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User views are dumped.
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User (See the <span class="command"><strong>dump-file</strong></span> option in
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User the BIND 9 Administrator Reference Manual.)
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>flush</code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Flushes the server's cache.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>flushname</code></strong> <em class="replaceable"><code>name</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>] </span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Flushes the given name from the view's DNS cache
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User and, if applicable, from the view's nameserver address
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User database, bad server cache and SERVFAIL cache.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>flushtree</code></strong> <em class="replaceable"><code>name</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>] </span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Flushes the given name, and all of its subdomains,
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User from the view's DNS cache, address database,
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User bad server cache, and SERVFAIL cache.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>freeze [<span class="optional"><em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</span>]</code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Suspend updates to a dynamic zone. If no zone is
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User specified, then all zones are suspended. This allows
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User manual edits to be made to a zone normally updated by
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User dynamic update. It also causes changes in the
395c95214142142854509945adf3293c0270e1c5Tinderbox User journal file to be synced into the master file.
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User All dynamic update attempts will be refused while
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User the zone is frozen.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User See also <span class="command"><strong>rndc thaw</strong></span>.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>halt [<span class="optional">-p</span>]</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Stop the server immediately. Recent changes
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User made through dynamic update or IXFR are not saved to
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User the master files, but will be rolled forward from the
395c95214142142854509945adf3293c0270e1c5Tinderbox User journal files when the server is restarted.
395c95214142142854509945adf3293c0270e1c5Tinderbox User If <code class="option">-p</code> is specified <span class="command"><strong>named</strong></span>'s process id is returned.
395c95214142142854509945adf3293c0270e1c5Tinderbox User This allows an external process to determine when <span class="command"><strong>named</strong></span>
395c95214142142854509945adf3293c0270e1c5Tinderbox User had completed halting.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User See also <span class="command"><strong>rndc stop</strong></span>.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>loadkeys <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Fetch all DNSSEC keys for the given zone
395c95214142142854509945adf3293c0270e1c5Tinderbox User from the key directory. If they are within
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User their publication period, merge them into the
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User zone's DNSKEY RRset. Unlike <span class="command"><strong>rndc
395c95214142142854509945adf3293c0270e1c5Tinderbox User sign</strong></span>, however, the zone is not
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User immediately re-signed by the new keys, but is
395c95214142142854509945adf3293c0270e1c5Tinderbox User allowed to incrementally re-sign over time.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User This command requires that the
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>auto-dnssec</strong></span> zone option
395c95214142142854509945adf3293c0270e1c5Tinderbox User be set to <code class="literal">maintain</code>,
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User and also requires the zone to be configured to
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User allow dynamic DNS.
395c95214142142854509945adf3293c0270e1c5Tinderbox User (See "Dynamic Update Policies" in the Administrator
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Reference Manual for more details.)
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
61ab11c0ec845606f85452b2c9f2e223772aae00Tinderbox User </dd>
61ab11c0ec845606f85452b2c9f2e223772aae00Tinderbox User<dt><span class="term"><strong class="userinput"><code>managed-keys <em class="replaceable"><code>(status | refresh | sync)</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
61ab11c0ec845606f85452b2c9f2e223772aae00Tinderbox User<dd>
61ab11c0ec845606f85452b2c9f2e223772aae00Tinderbox User <p>
61ab11c0ec845606f85452b2c9f2e223772aae00Tinderbox User When run with the "status" keyword, print the current
f5c27ecceb6dcba6ad8b75172fe5f9823d7a6d42Tinderbox User status of the managed-keys database for the specified
f5c27ecceb6dcba6ad8b75172fe5f9823d7a6d42Tinderbox User view, or for all views if none is specified. When run
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User with the "refresh" keyword, force an immediate refresh
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User of all the managed-keys in the specified view, or all
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User views. When run with the "sync" keyword, force an
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User immediate dump of the managed-keys database to disk (in
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User the file <code class="filename">managed-keys.bind</code> or
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User (<code class="filename"><em class="replaceable"><code>viewname</code></em>.mkeys</code>).
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>modzone <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>] <em class="replaceable"><code>configuration</code></em> </code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Modify the configuration of a zone while the server
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User is running. This command requires the
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>allow-new-zones</strong></span> option to be
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User set to <strong class="userinput"><code>yes</code></strong>. As with
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>addzone</strong></span>, the
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <em class="replaceable"><code>configuration</code></em> string
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User specified on the command line is the zone
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User configuration text that would ordinarily be
24abfe433efd98bb2099b867fb14d049b2f1f531Tinderbox User placed in <code class="filename">named.conf</code>.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User If the zone was originally added via
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>rndc addzone</strong></span>, the configuration
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User changes will be recorded permanently and will still be
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User in effect after the server is restarted or reconfigured.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User However, if it was originally configured in
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <code class="filename">named.conf</code>, then that original
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User configuration is still in place; when the server is
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User restarted or reconfigured, the zone will revert to
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User its original configuration. To make the changes
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User permanent, it must also be modified in
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <code class="filename">named.conf</code>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User See also <span class="command"><strong>rndc addzone</strong></span> and <span class="command"><strong>rndc delzone</strong></span>.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>notify <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Resend NOTIFY messages for the zone.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>notrace</code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Sets the server's debugging level to 0.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User See also <span class="command"><strong>rndc trace</strong></span>.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>nta
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User [<span class="optional">( -d | -f | -r | -l <em class="replaceable"><code>duration</code></em>)</span>]
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <em class="replaceable"><code>domain</code></em>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User [<span class="optional"><em class="replaceable"><code>view</code></em></span>]
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Sets a DNSSEC negative trust anchor (NTA)
395c95214142142854509945adf3293c0270e1c5Tinderbox User for <code class="option">domain</code>, with a lifetime of
395c95214142142854509945adf3293c0270e1c5Tinderbox User <code class="option">duration</code>. The default lifetime is
395c95214142142854509945adf3293c0270e1c5Tinderbox User configured in <code class="filename">named.conf</code> via the
395c95214142142854509945adf3293c0270e1c5Tinderbox User <code class="option">nta-lifetime</code> option, and defaults to
395c95214142142854509945adf3293c0270e1c5Tinderbox User one hour. The lifetime cannot exceed one week.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User A negative trust anchor selectively disables
395c95214142142854509945adf3293c0270e1c5Tinderbox User DNSSEC validation for zones that are known to be
395c95214142142854509945adf3293c0270e1c5Tinderbox User failing because of misconfiguration rather than
395c95214142142854509945adf3293c0270e1c5Tinderbox User an attack. When data to be validated is
395c95214142142854509945adf3293c0270e1c5Tinderbox User at or below an active NTA (and above any other
395c95214142142854509945adf3293c0270e1c5Tinderbox User configured trust anchors), <span class="command"><strong>named</strong></span> will
395c95214142142854509945adf3293c0270e1c5Tinderbox User abort the DNSSEC validation process and treat the data as
395c95214142142854509945adf3293c0270e1c5Tinderbox User insecure rather than bogus. This continues until the
395c95214142142854509945adf3293c0270e1c5Tinderbox User NTA's lifetime is elapsed.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User NTAs persist across restarts of the <span class="command"><strong>named</strong></span> server.
395c95214142142854509945adf3293c0270e1c5Tinderbox User The NTAs for a view are saved in a file called
395c95214142142854509945adf3293c0270e1c5Tinderbox User <code class="filename"><em class="replaceable"><code>name</code></em>.nta</code>,
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User where <em class="replaceable"><code>name</code></em> is the
f5c27ecceb6dcba6ad8b75172fe5f9823d7a6d42Tinderbox User name of the view, or if it contains characters
395c95214142142854509945adf3293c0270e1c5Tinderbox User that are incompatible with use as a file name, a
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User cryptographic hash generated from the name
395c95214142142854509945adf3293c0270e1c5Tinderbox User of the view.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User An existing NTA can be removed by using the
395c95214142142854509945adf3293c0270e1c5Tinderbox User <code class="option">-remove</code> option.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User An NTA's lifetime can be specified with the
395c95214142142854509945adf3293c0270e1c5Tinderbox User <code class="option">-lifetime</code> option. TTL-style
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User suffixes can be used to specify the lifetime in
c0cbdeedb5e119c640f098da1851cb1b9adcc739Tinderbox User seconds, minutes, or hours. If the specified NTA
c0cbdeedb5e119c640f098da1851cb1b9adcc739Tinderbox User already exists, its lifetime will be updated to the
c0cbdeedb5e119c640f098da1851cb1b9adcc739Tinderbox User new value. Setting <code class="option">lifetime</code> to zero
c0cbdeedb5e119c640f098da1851cb1b9adcc739Tinderbox User is equivalent to <code class="option">-remove</code>.
c0cbdeedb5e119c640f098da1851cb1b9adcc739Tinderbox User </p>
c0cbdeedb5e119c640f098da1851cb1b9adcc739Tinderbox User <p>
c0cbdeedb5e119c640f098da1851cb1b9adcc739Tinderbox User If <code class="option">-dump</code> is used, any other arguments
395c95214142142854509945adf3293c0270e1c5Tinderbox User are ignored, and a list of existing NTAs is printed
395c95214142142854509945adf3293c0270e1c5Tinderbox User (note that this may include NTAs that are expired but
395c95214142142854509945adf3293c0270e1c5Tinderbox User have not yet been cleaned up).
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Normally, <span class="command"><strong>named</strong></span> will periodically
395c95214142142854509945adf3293c0270e1c5Tinderbox User test to see whether data below an NTA can now be
395c95214142142854509945adf3293c0270e1c5Tinderbox User validated (see the <code class="option">nta-recheck</code> option
395c95214142142854509945adf3293c0270e1c5Tinderbox User in the Administrator Reference Manual for details).
395c95214142142854509945adf3293c0270e1c5Tinderbox User If data can be validated, then the NTA is regarded as
395c95214142142854509945adf3293c0270e1c5Tinderbox User no longer necessary, and will be allowed to expire
395c95214142142854509945adf3293c0270e1c5Tinderbox User early. The <code class="option">-force</code> overrides this
395c95214142142854509945adf3293c0270e1c5Tinderbox User behavior and forces an NTA to persist for its entire
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User lifetime, regardless of whether data could be
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User validated if the NTA were not present.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User All of these options can be shortened, i.e., to
395c95214142142854509945adf3293c0270e1c5Tinderbox User <code class="option">-l</code>, <code class="option">-r</code>, <code class="option">-d</code>,
395c95214142142854509945adf3293c0270e1c5Tinderbox User and <code class="option">-f</code>.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>querylog</code></strong> [<span class="optional">on|off</span>] </span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Enable or disable query logging. (For backward
395c95214142142854509945adf3293c0270e1c5Tinderbox User compatibility, this command can also be used without
395c95214142142854509945adf3293c0270e1c5Tinderbox User an argument to toggle query logging on and off.)
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Query logging can also be enabled
395c95214142142854509945adf3293c0270e1c5Tinderbox User by explicitly directing the <span class="command"><strong>queries</strong></span>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>category</strong></span> to a
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>channel</strong></span> in the
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>logging</strong></span> section of
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <code class="filename">named.conf</code> or by specifying
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>querylog yes;</strong></span> in the
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>options</strong></span> section of
395c95214142142854509945adf3293c0270e1c5Tinderbox User <code class="filename">named.conf</code>.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>reconfig</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Reload the configuration file and load new zones,
395c95214142142854509945adf3293c0270e1c5Tinderbox User but do not reload existing zone files even if they
395c95214142142854509945adf3293c0270e1c5Tinderbox User have changed.
395c95214142142854509945adf3293c0270e1c5Tinderbox User This is faster than a full <span class="command"><strong>reload</strong></span> when there
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User is a large number of zones because it avoids the need
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User to examine the
395c95214142142854509945adf3293c0270e1c5Tinderbox User modification times of the zones files.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>recursing</code></strong></span></dt>
3e240d6559605696cadf630668683708b18de871Tinderbox User<dd>
3e240d6559605696cadf630668683708b18de871Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Dump the list of queries <span class="command"><strong>named</strong></span> is currently
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User recursing on, and the list of domains to which iterative
3e240d6559605696cadf630668683708b18de871Tinderbox User queries are currently being sent. (The second list includes
395c95214142142854509945adf3293c0270e1c5Tinderbox User the number of fetches currently active for the given domain,
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User and how many have been passed or dropped because of the
3e240d6559605696cadf630668683708b18de871Tinderbox User <code class="option">fetches-per-zone</code> option.)
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User </dd>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User<dt><span class="term"><strong class="userinput"><code>refresh <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Schedule zone maintenance for the given zone.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>reload</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Reload configuration file and zones.
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>reload <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Reload the given zone.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>retransfer <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
11e9368a226272085c337e9e74b79808c16fbdbaTinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Retransfer the given slave zone from the master server.
11e9368a226272085c337e9e74b79808c16fbdbaTinderbox User </p>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User <p>
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User If the zone is configured to use
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User <span class="command"><strong>inline-signing</strong></span>, the signed
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User version of the zone is discarded; after the
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User retransfer of the unsigned version is complete, the
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User signed version will be regenerated with all new
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User signatures.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>scan</code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Scan the list of available network interfaces
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User for changes, without performing a full
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>reconfig</strong></span> or waiting for the
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>interface-interval</strong></span> timer.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>secroots [<span class="optional">-</span>] [<span class="optional"><em class="replaceable"><code>view ...</code></em></span>]</code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Dump the server's security roots and negative trust anchors
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User for the specified views. If no view is specified, all views
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User are dumped.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User If the first argument is "-", then the output is
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User returned via the <span class="command"><strong>rndc</strong></span> response channel
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User and printed to the standard output.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Otherwise, it is written to the secroots dump file, which
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User defaults to <code class="filename">named.secroots</code>, but can be
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User overridden via the <code class="option">secroots-file</code> option in
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <code class="filename">named.conf</code>.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User See also <span class="command"><strong>rndc managed-keys</strong></span>.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>showzone <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>] </code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Print the configuration of a running zone.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User See also <span class="command"><strong>rndc zonestatus</strong></span>.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dt><span class="term"><strong class="userinput"><code>sign <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User<dd>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User Fetch all DNSSEC keys for the given zone
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User from the key directory (see the
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>key-directory</strong></span> option in
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User the BIND 9 Administrator Reference Manual). If they are within
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User their publication period, merge them into the
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User zone's DNSKEY RRset. If the DNSKEY RRset
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User is changed, then the zone is automatically
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User re-signed with the new key set.
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User </p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <p>
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User This command requires that the
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <span class="command"><strong>auto-dnssec</strong></span> zone option be set
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User to <code class="literal">allow</code> or
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User <code class="literal">maintain</code>,
659d063f23a35d77ad5826e6556d3137672bb937Tinderbox User and also requires the zone to be configured to
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User allow dynamic DNS.
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User (See "Dynamic Update Policies" in the Administrator
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User Reference Manual for more details.)
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User </p>
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User <p>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User See also <span class="command"><strong>rndc loadkeys</strong></span>.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>signing [<span class="optional">( -list | -clear <em class="replaceable"><code>keyid/algorithm</code></em> | -clear <code class="literal">all</code> | -nsec3param ( <em class="replaceable"><code>parameters</code></em> | <code class="literal">none</code> ) | -serial <em class="replaceable"><code>value</code></em> ) </span>] <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>] </code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User List, edit, or remove the DNSSEC signing state records
395c95214142142854509945adf3293c0270e1c5Tinderbox User for the specified zone. The status of ongoing DNSSEC
395c95214142142854509945adf3293c0270e1c5Tinderbox User operations (such as signing or generating
395c95214142142854509945adf3293c0270e1c5Tinderbox User NSEC3 chains) is stored in the zone in the form
395c95214142142854509945adf3293c0270e1c5Tinderbox User of DNS resource records of type
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>sig-signing-type</strong></span>.
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>rndc signing -list</strong></span> converts
395c95214142142854509945adf3293c0270e1c5Tinderbox User these records into a human-readable form,
395c95214142142854509945adf3293c0270e1c5Tinderbox User indicating which keys are currently signing
395c95214142142854509945adf3293c0270e1c5Tinderbox User or have finished signing the zone, and which NSEC3
395c95214142142854509945adf3293c0270e1c5Tinderbox User chains are being created or removed.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>rndc signing -clear</strong></span> can remove
395c95214142142854509945adf3293c0270e1c5Tinderbox User a single key (specified in the same format that
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>rndc signing -list</strong></span> uses to
395c95214142142854509945adf3293c0270e1c5Tinderbox User display it), or all keys. In either case, only
395c95214142142854509945adf3293c0270e1c5Tinderbox User completed keys are removed; any record indicating
395c95214142142854509945adf3293c0270e1c5Tinderbox User that a key has not yet finished signing the zone
395c95214142142854509945adf3293c0270e1c5Tinderbox User will be retained.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>rndc signing -nsec3param</strong></span> sets
395c95214142142854509945adf3293c0270e1c5Tinderbox User the NSEC3 parameters for a zone. This is the
395c95214142142854509945adf3293c0270e1c5Tinderbox User only supported mechanism for using NSEC3 with
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>inline-signing</strong></span> zones.
395c95214142142854509945adf3293c0270e1c5Tinderbox User Parameters are specified in the same format as
395c95214142142854509945adf3293c0270e1c5Tinderbox User an NSEC3PARAM resource record: hash algorithm,
395c95214142142854509945adf3293c0270e1c5Tinderbox User flags, iterations, and salt, in that order.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Currently, the only defined value for hash algorithm
395c95214142142854509945adf3293c0270e1c5Tinderbox User is <code class="literal">1</code>, representing SHA-1.
395c95214142142854509945adf3293c0270e1c5Tinderbox User The <code class="option">flags</code> may be set to
395c95214142142854509945adf3293c0270e1c5Tinderbox User <code class="literal">0</code> or <code class="literal">1</code>,
395c95214142142854509945adf3293c0270e1c5Tinderbox User depending on whether you wish to set the opt-out
395c95214142142854509945adf3293c0270e1c5Tinderbox User bit in the NSEC3 chain. <code class="option">iterations</code>
395c95214142142854509945adf3293c0270e1c5Tinderbox User defines the number of additional times to apply
395c95214142142854509945adf3293c0270e1c5Tinderbox User the algorithm when generating an NSEC3 hash. The
395c95214142142854509945adf3293c0270e1c5Tinderbox User <code class="option">salt</code> is a string of data expressed
395c95214142142854509945adf3293c0270e1c5Tinderbox User in hexadecimal, a hyphen (`-') if no salt is
395c95214142142854509945adf3293c0270e1c5Tinderbox User to be used, or the keyword <code class="literal">auto</code>,
395c95214142142854509945adf3293c0270e1c5Tinderbox User which causes <span class="command"><strong>named</strong></span> to generate a
395c95214142142854509945adf3293c0270e1c5Tinderbox User random 64-bit salt.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User So, for example, to create an NSEC3 chain using
395c95214142142854509945adf3293c0270e1c5Tinderbox User the SHA-1 hash algorithm, no opt-out flag,
395c95214142142854509945adf3293c0270e1c5Tinderbox User 10 iterations, and a salt value of "FFFF", use:
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>rndc signing -nsec3param 1 0 10 FFFF <em class="replaceable"><code>zone</code></em></strong></span>.
395c95214142142854509945adf3293c0270e1c5Tinderbox User To set the opt-out flag, 15 iterations, and no
395c95214142142854509945adf3293c0270e1c5Tinderbox User salt, use:
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>rndc signing -nsec3param 1 1 15 - <em class="replaceable"><code>zone</code></em></strong></span>.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>rndc signing -nsec3param none</strong></span>
395c95214142142854509945adf3293c0270e1c5Tinderbox User removes an existing NSEC3 chain and replaces it
395c95214142142854509945adf3293c0270e1c5Tinderbox User with NSEC.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <span class="command"><strong>rndc signing -serial value</strong></span> sets
395c95214142142854509945adf3293c0270e1c5Tinderbox User the serial number of the zone to value. If the value
395c95214142142854509945adf3293c0270e1c5Tinderbox User would cause the serial number to go backwards it will
395c95214142142854509945adf3293c0270e1c5Tinderbox User be rejected. The primary use is to set the serial on
395c95214142142854509945adf3293c0270e1c5Tinderbox User inline signed zones.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>stats</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Write server statistics to the statistics file.
395c95214142142854509945adf3293c0270e1c5Tinderbox User (See the <span class="command"><strong>statistics-file</strong></span> option in
395c95214142142854509945adf3293c0270e1c5Tinderbox User the BIND 9 Administrator Reference Manual.)
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>status</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Display status of the server.
395c95214142142854509945adf3293c0270e1c5Tinderbox User Note that the number of zones includes the internal <span class="command"><strong>bind/CH</strong></span> zone
395c95214142142854509945adf3293c0270e1c5Tinderbox User and the default <span class="command"><strong>/IN</strong></span>
395c95214142142854509945adf3293c0270e1c5Tinderbox User hint zone if there is not an
b3338fc248b647e1a88a824a62e809a5b94c076cTinderbox User explicit root zone configured.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>stop [<span class="optional">-p</span>]</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User Stop the server, making sure any recent changes
395c95214142142854509945adf3293c0270e1c5Tinderbox User made through dynamic update or IXFR are first saved to
395c95214142142854509945adf3293c0270e1c5Tinderbox User the master files of the updated zones.
395c95214142142854509945adf3293c0270e1c5Tinderbox User If <code class="option">-p</code> is specified <span class="command"><strong>named</strong></span>'s process id is returned.
395c95214142142854509945adf3293c0270e1c5Tinderbox User This allows an external process to determine when <span class="command"><strong>named</strong></span>
395c95214142142854509945adf3293c0270e1c5Tinderbox User had completed stopping.
395c95214142142854509945adf3293c0270e1c5Tinderbox User </p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User <p>See also <span class="command"><strong>rndc halt</strong></span>.</p>
395c95214142142854509945adf3293c0270e1c5Tinderbox User </dd>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dt><span class="term"><strong class="userinput"><code>sync [<span class="optional">-clean</span>] [<span class="optional"><em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</span>]</code></strong></span></dt>
395c95214142142854509945adf3293c0270e1c5Tinderbox User<dd>
0ccb0e98c77a9b9636a036f8f64f5679a430aaf4Tinderbox User <p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Sync changes in the journal file for a dynamic zone
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein to the master file. If the "-clean" option is
b3338fc248b647e1a88a824a62e809a5b94c076cTinderbox User specified, the journal file is also removed. If
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein no zone is specified, then all zones are synced.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term"><strong class="userinput"><code>thaw [<span class="optional"><em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</span>]</code></strong></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Enable updates to a frozen dynamic zone. If no
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein zone is specified, then all frozen zones are
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein enabled. This causes the server to reload the zone
b3338fc248b647e1a88a824a62e809a5b94c076cTinderbox User from disk, and re-enables dynamic updates after the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein load has completed. After a zone is thawed,
1d216bfaa764f2b40c57cf61987453c5a6fa9b0aMark Andrews dynamic updates will no longer be refused. If
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the zone has changed and the
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews <span class="command"><strong>ixfr-from-differences</strong></span> option is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein in use, then the journal file will be updated to
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein reflect changes in the zone. Otherwise, if the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein zone has changed, any existing journal file will be
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein removed.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
b3338fc248b647e1a88a824a62e809a5b94c076cTinderbox User <p>See also <span class="command"><strong>rndc freeze</strong></span>.</p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term"><strong class="userinput"><code>trace</code></strong></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Increment the servers debugging level by one.
</p>
</dd>
<dt><span class="term"><strong class="userinput"><code>trace <em class="replaceable"><code>level</code></em></code></strong></span></dt>
<dd>
<p>
Sets the server's debugging level to an explicit
value.
</p>
<p>
See also <span class="command"><strong>rndc notrace</strong></span>.
</p>
</dd>
<dt><span class="term"><strong class="userinput"><code>tsig-delete</code></strong> <em class="replaceable"><code>keyname</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span></dt>
<dd>
<p>
Delete a given TKEY-negotiated key from the server.
(This does not apply to statically configured TSIG
keys.)
</p>
</dd>
<dt><span class="term"><strong class="userinput"><code>tsig-list</code></strong></span></dt>
<dd>
<p>
List the names of all TSIG keys currently configured
for use by <span class="command"><strong>named</strong></span> in each view. The
list both statically configured keys and dynamic
TKEY-negotiated keys.
</p>
</dd>
<dt><span class="term"><strong class="userinput"><code>validation ( on | off | check ) [<span class="optional"><em class="replaceable"><code>view ...</code></em></span>] </code></strong></span></dt>
<dd>
<p>
Enable, disable, or check the current status of
DNSSEC validation.
Note <span class="command"><strong>dnssec-enable</strong></span> also needs to be
set to <strong class="userinput"><code>yes</code></strong> or
<strong class="userinput"><code>auto</code></strong> to be effective.
It defaults to enabled.
</p>
</dd>
<dt><span class="term"><strong class="userinput"><code>zonestatus <em class="replaceable"><code>zone</code></em> [<span class="optional"><em class="replaceable"><code>class</code></em> [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
<dd>
<p>
Displays the current status of the given zone,
including the master file name and any include
files from which it was loaded, when it was most
recently loaded, the current serial number, the
number of nodes, whether the zone supports
dynamic updates, whether the zone is DNSSEC
signed, whether it uses automatic DNSSEC key
management or inline signing, and the scheduled
refresh or expiry times for the zone.
</p>
<p>
See also <span class="command"><strong>rndc showzone</strong></span>.
</p>
</dd>
</dl></div>
</div>
<div class="refsection" title="LIMITATIONS">
<a name="idp61327440"></a><h2>LIMITATIONS</h2>
<p>
There is currently no way to provide the shared secret for a
<code class="option">key_id</code> without using the configuration file.
</p>
<p>
Several error messages could be clearer.
</p>
</div>
<div class="refsection" title="SEE ALSO">
<a name="idp61329616"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry">
<span class="refentrytitle">rndc.conf</span>(5)
</span>,
<span class="citerefentry">
<span class="refentrytitle">rndc-confgen</span>(8)
</span>,
<span class="citerefentry">
<span class="refentrytitle">named</span>(8)
</span>,
<span class="citerefentry">
<span class="refentrytitle">named.conf</span>(5)
</span>,
<span class="citerefentry">
<span class="refentrytitle">ndc</span>(8)
</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>.
</p>
</div>
</div></body>
</html>