rndc.html revision 71c66a876ecca77923638d3f94cc0783152b2f03
28ec5e4f5c4a71428affc986304e894eda600925takashi<!--
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess - Copyright (C) 2004, 2005 Internet Systems Consortium, Inc. ("ISC")
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess - Copyright (C) 2000, 2001 Internet Software Consortium.
5f5d1b4cc970b7f06ff8ef6526128e9a27303d88nd -
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd - Permission to use, copy, modify, and distribute this software for any
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd - purpose with or without fee is hereby granted, provided that the above
031b91a62d25106ae69d4693475c79618dd5e884fielding - copyright notice and this permission notice appear in all copies.
031b91a62d25106ae69d4693475c79618dd5e884fielding -
031b91a62d25106ae69d4693475c79618dd5e884fielding - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
031b91a62d25106ae69d4693475c79618dd5e884fielding - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
031b91a62d25106ae69d4693475c79618dd5e884fielding - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
031b91a62d25106ae69d4693475c79618dd5e884fielding - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd - PERFORMANCE OF THIS SOFTWARE.
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd-->
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd<!-- $Id: rndc.html,v 1.24 2006/06/29 13:03:32 marka Exp $ -->
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd<html>
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd<head>
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd<title>rndc</title>
6d9c7d0283713aa8ae15fef7e9bfe2c7bfa73872nd<meta name="generator" content="DocBook XSL Stylesheets V1.70.1">
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess</head>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<a name="man.rndc"></a><div class="titlepage"></div>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<div class="refnamediv">
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<h2>Name</h2>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<p><span class="application">rndc</span> &#8212; name server control utility</p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess</div>
1d5dcc190b426185661be06262e446e68f622c64erikabele<div class="refsynopsisdiv">
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<h2>Synopsis</h2>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<div class="cmdsynopsis"><p><code class="command">rndc</code> [<code class="option">-b <em class="replaceable"><code>source-address</code></em></code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key-file</code></em></code>] [<code class="option">-s <em class="replaceable"><code>server</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-V</code>] [<code class="option">-y <em class="replaceable"><code>key_id</code></em></code>] {command}</p></div>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess</div>
9ed703ab1543b3300f4b60c0405fc1a212b601c8slive<div class="refsect1" lang="en">
9ed703ab1543b3300f4b60c0405fc1a212b601c8slive<a name="id2549470"></a><h2>DESCRIPTION</h2>
9ed703ab1543b3300f4b60c0405fc1a212b601c8slive<p><span><strong class="command">rndc</strong></span>
a1db0910d02810490a4a5bb2f3fe13ce96f975e4nilgun controls the operation of a name
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess server. It supersedes the <span><strong class="command">ndc</strong></span> utility
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess that was provided in old BIND releases. If
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <span><strong class="command">rndc</strong></span> is invoked with no command line
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess options or arguments, it prints a short summary of the
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess supported commands and the available options and their
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess arguments.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<p><span><strong class="command">rndc</strong></span>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess communicates with the name server
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess over a TCP connection, sending commands authenticated with
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess digital signatures. In the current versions of
1d5dcc190b426185661be06262e446e68f622c64erikabele <span><strong class="command">rndc</strong></span> and <span><strong class="command">named</strong></span> named
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess the only supported authentication algorithm is HMAC-MD5,
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess which uses a shared secret on each end of the connection.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess This provides TSIG-style authentication for the command
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess request and the name server's response. All commands sent
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess over the channel must be signed by a key_id known to the
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess server.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<p><span><strong class="command">rndc</strong></span>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess reads a configuration file to
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess determine how to contact the name server and decide what
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess algorithm and key it should use.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess</div>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<div class="refsect1" lang="en">
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<a name="id2549574"></a><h2>OPTIONS</h2>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<div class="variablelist"><dl>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dt><span class="term">-b <em class="replaceable"><code>source-address</code></em></span></dt>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dd><p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess Use <em class="replaceable"><code>source-address</code></em>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess as the source address for the connection to the server.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess Multiple instances are permitted to allow setting of both
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess the IPv4 and IPv6 source addresses.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p></dd>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dt><span class="term">-c <em class="replaceable"><code>config-file</code></em></span></dt>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dd><p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess Use <em class="replaceable"><code>config-file</code></em>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess as the configuration file instead of the default,
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <code class="filename">/etc/rndc.conf</code>.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p></dd>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dt><span class="term">-k <em class="replaceable"><code>key-file</code></em></span></dt>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dd><p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess Use <em class="replaceable"><code>key-file</code></em>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess as the key file instead of the default,
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <code class="filename">/etc/rndc.key</code>. The key in
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <code class="filename">/etc/rndc.key</code> will be used to
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess authenticate
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess commands sent to the server if the <em class="replaceable"><code>config-file</code></em>
6d2e44708b8b2c021157997c60d8029f4d4710bderikabele does not exist.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p></dd>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dt><span class="term">-s <em class="replaceable"><code>server</code></em></span></dt>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dd><p><em class="replaceable"><code>server</code></em> is
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess the name or address of the server which matches a
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess server statement in the configuration file for
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <span><strong class="command">rndc</strong></span>. If no server is supplied on
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess the
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess command line, the host named by the default-server clause
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess in the option statement of the configuration file will be
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess used.
d8c44cd75cf575fe51319280c12445109e878523noodl </p></dd>
d8c44cd75cf575fe51319280c12445109e878523noodl<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dd><p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess Send commands to TCP port
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <em class="replaceable"><code>port</code></em>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess instead
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess of BIND 9's default control channel port, 953.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p></dd>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dt><span class="term">-V</span></dt>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dd><p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess Enable verbose logging.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p></dd>
a1db0910d02810490a4a5bb2f3fe13ce96f975e4nilgun<dt><span class="term">-y <em class="replaceable"><code>keyid</code></em></span></dt>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<dd><p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess Use the key <em class="replaceable"><code>keyid</code></em>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess from the configuration file.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <em class="replaceable"><code>keyid</code></em>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess must be
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess known by named with the same algorithm and secret string
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess in order for control message validation to succeed.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess If no <em class="replaceable"><code>keyid</code></em>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess is specified, <span><strong class="command">rndc</strong></span> will first look
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess for a key clause in the server statement of the server
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess being used, or if no server statement is present for that
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess host, then the default-key clause of the options statement.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess Note that the configuration file contains shared secrets
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess which are used to send authenticated control commands
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess to name servers. It should therefore not have general read
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess or write access.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p></dd>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess</dl></div>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess For the complete set of commands supported by <span><strong class="command">rndc</strong></span>,
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess see the BIND 9 Administrator Reference Manual or run
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <span><strong class="command">rndc</strong></span> without arguments to see its help
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess message.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess</div>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<div class="refsect1" lang="en">
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<a name="id2549846"></a><h2>LIMITATIONS</h2>
da9055b2453b398d94e9866fcf80af216a8702d5kess<p><span><strong class="command">rndc</strong></span>
da9055b2453b398d94e9866fcf80af216a8702d5kess does not yet support all the commands of
da9055b2453b398d94e9866fcf80af216a8702d5kess the BIND 8 <span><strong class="command">ndc</strong></span> utility.
da9055b2453b398d94e9866fcf80af216a8702d5kess </p>
da9055b2453b398d94e9866fcf80af216a8702d5kess<p>
da9055b2453b398d94e9866fcf80af216a8702d5kess There is currently no way to provide the shared secret for a
da9055b2453b398d94e9866fcf80af216a8702d5kess <code class="option">key_id</code> without using the configuration file.
da9055b2453b398d94e9866fcf80af216a8702d5kess </p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess Several error messages could be clearer.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess</div>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<div class="refsect1" lang="en">
a1db0910d02810490a4a5bb2f3fe13ce96f975e4nilgun<a name="id2549873"></a><h2>SEE ALSO</h2>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<p><span class="citerefentry"><span class="refentrytitle">rndc.conf</span>(5)</span>,
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
d8c44cd75cf575fe51319280c12445109e878523noodl <span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <span class="citerefentry"><span class="refentrytitle">ndc</span>(8)</span>,
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess <em class="citetitle">BIND 9 Administrator Reference Manual</em>.
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess </p>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess</div>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<div class="refsect1" lang="en">
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<a name="id2549920"></a><h2>AUTHOR</h2>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess<p><span class="corpauthor">Internet Systems Consortium</span>
a1ef40892ffa2b44fc249423c5b6c42a74a84c68nd </p>
a1ef40892ffa2b44fc249423c5b6c42a74a84c68nd</div>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess</div></body>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess</html>
ce6127d4b1f0fb4d7934119ed0e85bca4dd14f9bkess