Bv9ARM.ch03.html revision 7717ec7a6a898cdd3c35cbfba66010b7304ffd9b
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski - Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski - Copyright (C) 2000-2003 Internet Software Consortium.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski - Permission to use, copy, modify, and/or distribute this software for any
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski - purpose with or without fee is hereby granted, provided that the above
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski - copyright notice and this permission notice appear in all copies.
e7eefd526faedd63acb8f91de5793368cfe67655Klaus Luettich - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
e7eefd526faedd63acb8f91de5793368cfe67655Klaus Luettich - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
1d9290e729b7cd9a6f666432934fd890a9766fbdChristoph Lange - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
e7eefd526faedd63acb8f91de5793368cfe67655Klaus Luettich - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
e7eefd526faedd63acb8f91de5793368cfe67655Klaus Luettich - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski - PERFORMANCE OF THIS SOFTWARE.
e7eefd526faedd63acb8f91de5793368cfe67655Klaus Luettich<!-- $Id: Bv9ARM.ch03.html,v 1.84 2011/03/22 01:14:25 tbox Exp $ -->
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<title>Chapter�3.�Name Server Configuration</title>
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<link rel="prev" href="Bv9ARM.ch02.html" title="Chapter�2.�BIND Resource Requirements">
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<link rel="next" href="Bv9ARM.ch04.html" title="Chapter�4.�Advanced DNS Features">
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<table width="100%" summary="Navigation header">
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<tr><th colspan="3" align="center">Chapter�3.�Name Server Configuration</th></tr>
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder<a accesskey="p" href="Bv9ARM.ch02.html">Prev</a>�</td>
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<td width="20%" align="right">�<a accesskey="n" href="Bv9ARM.ch04.html">Next</a>
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<div class="titlepage"><div><div><h2 class="title">
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski<a name="Bv9ARM.ch03"></a>Chapter�3.�Name Server Configuration</h2></div></div></div>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="sect1"><a href="Bv9ARM.ch03.html#sample_configuration">Sample Configurations</a></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="sect2"><a href="Bv9ARM.ch03.html#id2567767">A Caching-only Name Server</a></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="sect2"><a href="Bv9ARM.ch03.html#id2567988">An Authoritative-only Name Server</a></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="sect1"><a href="Bv9ARM.ch03.html#id2568010">Load Balancing</a></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="sect1"><a href="Bv9ARM.ch03.html#id2568364">Name Server Operations</a></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="sect2"><a href="Bv9ARM.ch03.html#id2568370">Tools for Use With the Name Server Daemon</a></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="sect2"><a href="Bv9ARM.ch03.html#id2570345">Signals</a></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski In this chapter we provide some suggested configurations along
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski with guidelines for their use. We suggest reasonable values for
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski certain option settings.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<div class="titlepage"><div><div><h2 class="title" style="clear: both">
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<a name="sample_configuration"></a>Sample Configurations</h2></div></div></div>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<div class="titlepage"><div><div><h3 class="title">
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<a name="id2567767"></a>A Caching-only Name Server</h3></div></div></div>
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski The following sample configuration is appropriate for a caching-only
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski name server for use by clients internal to a corporation. All
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski from outside clients are refused using the <span><strong class="command">allow-query</strong></span>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski option. Alternatively, the same effect could be achieved using
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski firewall rules.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski// Two corporate subnets we wish to allow queries from.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowskiacl corpnets { 192.168.4.0/24; 192.168.7.0/24; };
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski // Working directory
e7eefd526faedd63acb8f91de5793368cfe67655Klaus Luettich allow-query { corpnets; };
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski// Provide a reverse mapping for the loopback
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski// address 127.0.0.1
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<div class="titlepage"><div><div><h3 class="title">
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<a name="id2567988"></a>An Authoritative-only Name Server</h3></div></div></div>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski This sample configuration is for an authoritative-only server
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski that is the master server for "<code class="filename">example.com</code>"
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski and a slave for the subdomain "<code class="filename">eng.example.com</code>".
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski // Working directory
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski // Do not allow access to cache
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski allow-query-cache { none; };
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski // This is the default
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski allow-query { any; };
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski // Do not provide recursive service
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski recursion no;
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski// Provide a reverse mapping for the loopback
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski// address 127.0.0.1
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski// We are the master server for example.com
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski // IP addresses of slave servers allowed to
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski allow-transfer {
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski 192.168.4.14;
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder 192.168.5.53;
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder// We are a slave server for eng.example.com
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski // IP address of eng.example.com master server
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski masters { 192.168.4.12; };
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski<div class="titlepage"><div><div><h2 class="title" style="clear: both">
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski<a name="id2568010"></a>Load Balancing</h2></div></div></div>
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski A primitive form of load balancing can be achieved in
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski the <acronym class="acronym">DNS</acronym> by using multiple records
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski (such as multiple A records) for one name.
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski For example, if you have three WWW servers with network addresses
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski of 10.0.0.1, 10.0.0.2 and 10.0.0.3, a set of records such as the
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski following means that clients will connect to each machine one third
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski<div class="informaltable"><table border="1">
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder Resource Record (RR) Data
0093b49b89d814da4164d43e754509a90a00e9eeChristian Maeder When a resolver queries for these records, <acronym class="acronym">BIND</acronym> will rotate
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder them and respond to the query with the records in a different
3fdf6c17476458d1458d5ae2c085efd2634ba7d9Christian Maeder order. In the example above, clients will randomly receive
4317329b15d986d363c78acf8e4b330f33cccf9dChristian Maeder records in the order 1, 2, 3; 2, 3, 1; and 3, 1, 2. Most clients
2a5598bba75f2fbaa7851a9be2f8f0a1fce19cb6Ewaryst Schulz will use the first record returned and discard the rest.
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski For more detail on ordering responses, check the
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski <span><strong class="command">rrset-order</strong></span> sub-statement in the
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">options</strong></span> statement, see
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski <a href="Bv9ARM.ch06.html#rrset_ordering">RRset Ordering</a>.
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<div class="titlepage"><div><div><h2 class="title" style="clear: both">
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<a name="id2568364"></a>Name Server Operations</h2></div></div></div>
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<div class="titlepage"><div><div><h3 class="title">
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<a name="id2568370"></a>Tools for Use With the Name Server Daemon</h3></div></div></div>
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski This section describes several indispensable diagnostic,
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder administrative and monitoring tools available to the system
30256573a343132354b122097b0ee1215dda1364Till Mossakowski administrator for controlling and debugging the name server
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<div class="titlepage"><div><div><h4 class="title">
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<a name="diagnostic_tools"></a>Diagnostic Tools</h4></div></div></div>
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski The <span><strong class="command">dig</strong></span>, <span><strong class="command">host</strong></span>, and
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski <span><strong class="command">nslookup</strong></span> programs are all command
7a8592051724fa46499bde120f44cdc8db270876Till Mossakowski for manually querying name servers. They differ in style and
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski output format.
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski<dt><span class="term"><a name="dig"></a><span><strong class="command">dig</strong></span></span></dt>
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder The domain information groper (<span><strong class="command">dig</strong></span>)
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski is the most versatile and complete of these lookup tools.
c57bde4abc9029546fa396c4eccacf969e126b96Mihai Codescu It has two modes: simple interactive
c57bde4abc9029546fa396c4eccacf969e126b96Mihai Codescu mode for a single query, and batch mode which executes a
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski each in a list of several query lines. All query options are
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder from the command line.
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski<div class="cmdsynopsis"><p><code class="command">dig</code> [@<em class="replaceable"><code>server</code></em>] <em class="replaceable"><code>domain</code></em> [<em class="replaceable"><code>query-type</code></em>] [<em class="replaceable"><code>query-class</code></em>] [+<em class="replaceable"><code>query-option</code></em>] [-<em class="replaceable"><code>dig-option</code></em>] [%<em class="replaceable"><code>comment</code></em>]</p></div>
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski The usual simple use of <span><strong class="command">dig</strong></span> will take the form
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski <span><strong class="command">dig @server domain query-type query-class</strong></span>
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder For more information and a list of available commands and
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder options, see the <span><strong class="command">dig</strong></span> man
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder<dt><span class="term"><span><strong class="command">host</strong></span></span></dt>
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski The <span><strong class="command">host</strong></span> utility emphasizes
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski and ease of use. By default, it converts
e7eefd526faedd63acb8f91de5793368cfe67655Klaus Luettich between host names and Internet addresses, but its
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski functionality
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder can be extended with the use of options.
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<div class="cmdsynopsis"><p><code class="command">host</code> [-aCdlnrsTwv] [-c <em class="replaceable"><code>class</code></em>] [-N <em class="replaceable"><code>ndots</code></em>] [-t <em class="replaceable"><code>type</code></em>] [-W <em class="replaceable"><code>timeout</code></em>] [-R <em class="replaceable"><code>retries</code></em>] [-m <em class="replaceable"><code>flag</code></em>] [-4] [-6] <em class="replaceable"><code>hostname</code></em> [<em class="replaceable"><code>server</code></em>]</p></div>
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski For more information and a list of available commands and
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder options, see the <span><strong class="command">host</strong></span> man
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<dt><span class="term"><span><strong class="command">nslookup</strong></span></span></dt>
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski<p><span><strong class="command">nslookup</strong></span>
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski has two modes: interactive and
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski non-interactive. Interactive mode allows the user to
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski query name servers for information about various
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski hosts and domains or to print a list of hosts in a
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski domain. Non-interactive mode is used to print just
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski the name and requested information for a host or
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<div class="cmdsynopsis"><p><code class="command">nslookup</code> [-option...] [[<em class="replaceable"><code>host-to-find</code></em>] | [- [server]]]</p></div>
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder Interactive mode is entered when no arguments are given (the
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski default name server will be used) or when the first argument
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder hyphen (`-') and the second argument is the host name or
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder Internet address
c57bde4abc9029546fa396c4eccacf969e126b96Mihai Codescu of a name server.
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski Non-interactive mode is used when the name or Internet
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski of the host to be looked up is given as the first argument.
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski optional second argument specifies the host name or address
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder of a name server.
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski Due to its arcane user interface and frequently inconsistent
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski behavior, we do not recommend the use of <span><strong class="command">nslookup</strong></span>.
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski Use <span><strong class="command">dig</strong></span> instead.
e7eefd526faedd63acb8f91de5793368cfe67655Klaus Luettich<div class="titlepage"><div><div><h4 class="title">
c57bde4abc9029546fa396c4eccacf969e126b96Mihai Codescu<a name="admin_tools"></a>Administrative Tools</h4></div></div></div>
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder Administrative tools play an integral part in the management
749b7d8ea5a481831375f49ae50239dd8e3d2d12Christian Maeder<a name="named-checkconf"></a><span class="term"><span><strong class="command">named-checkconf</strong></span></span>
9db773679fcc0a65c04b99f5699d3db382b6be7aEwaryst Schulz The <span><strong class="command">named-checkconf</strong></span> program
2a5598bba75f2fbaa7851a9be2f8f0a1fce19cb6Ewaryst Schulz checks the syntax of a <code class="filename">named.conf</code> file.
4317329b15d986d363c78acf8e4b330f33cccf9dChristian Maeder<div class="cmdsynopsis"><p><code class="command">named-checkconf</code> [-jvz] [-t <em class="replaceable"><code>directory</code></em>] [<em class="replaceable"><code>filename</code></em>]</p></div>
4317329b15d986d363c78acf8e4b330f33cccf9dChristian Maeder<a name="named-checkzone"></a><span class="term"><span><strong class="command">named-checkzone</strong></span></span>
de55550f7d117195f127481d18ec2d5e8d2317ffMihai Codescu The <span><strong class="command">named-checkzone</strong></span> program
543ded2ae6a6e13f6cd2c22f9f0921e8c452cba0Christian Maeder checks a master file for
de55550f7d117195f127481d18ec2d5e8d2317ffMihai Codescu syntax and consistency.
de55550f7d117195f127481d18ec2d5e8d2317ffMihai Codescu<div class="cmdsynopsis"><p><code class="command">named-checkzone</code> [-djqvD] [-c <em class="replaceable"><code>class</code></em>] [-o <em class="replaceable"><code>output</code></em>] [-t <em class="replaceable"><code>directory</code></em>] [-w <em class="replaceable"><code>directory</code></em>] [-k <em class="replaceable"><code>(ignore|warn|fail)</code></em>] [-n <em class="replaceable"><code>(ignore|warn|fail)</code></em>] [-W <em class="replaceable"><code>(ignore|warn)</code></em>] <em class="replaceable"><code>zone</code></em> [<em class="replaceable"><code>filename</code></em>]</p></div>
c57bde4abc9029546fa396c4eccacf969e126b96Mihai Codescu<a name="named-compilezone"></a><span class="term"><span><strong class="command">named-compilezone</strong></span></span>
3fdf6c17476458d1458d5ae2c085efd2634ba7d9Christian Maeder Similar to <span><strong class="command">named-checkzone,</strong></span> but
3fdf6c17476458d1458d5ae2c085efd2634ba7d9Christian Maeder it always dumps the zone content to a specified file
3fdf6c17476458d1458d5ae2c085efd2634ba7d9Christian Maeder (typically in a different format).
4317329b15d986d363c78acf8e4b330f33cccf9dChristian Maeder<a name="rndc"></a><span class="term"><span><strong class="command">rndc</strong></span></span>
2a5598bba75f2fbaa7851a9be2f8f0a1fce19cb6Ewaryst Schulz The remote name daemon control
2a5598bba75f2fbaa7851a9be2f8f0a1fce19cb6Ewaryst Schulz (<span><strong class="command">rndc</strong></span>) program allows the
2a5598bba75f2fbaa7851a9be2f8f0a1fce19cb6Ewaryst Schulz administrator to control the operation of a name server.
2a5598bba75f2fbaa7851a9be2f8f0a1fce19cb6Ewaryst Schulz Since <acronym class="acronym">BIND</acronym> 9.2, <span><strong class="command">rndc</strong></span>
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski supports all the commands of the BIND 8 <span><strong class="command">ndc</strong></span>
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski utility except <span><strong class="command">ndc start</strong></span> and
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski <span><strong class="command">ndc restart</strong></span>, which were also
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski not supported in <span><strong class="command">ndc</strong></span>'s
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski channel mode.
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski If you run <span><strong class="command">rndc</strong></span> without any
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski it will display a usage message as follows:
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski<div class="cmdsynopsis"><p><code class="command">rndc</code> [-c <em class="replaceable"><code>config</code></em>] [-s <em class="replaceable"><code>server</code></em>] [-p <em class="replaceable"><code>port</code></em>] [-y <em class="replaceable"><code>key</code></em>] <em class="replaceable"><code>command</code></em> [<em class="replaceable"><code>command</code></em>...]</p></div>
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<p>The <span><strong class="command">command</strong></span>
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski is one of the following:
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski<dt><span class="term"><strong class="userinput"><code>reload</code></strong></span></dt>
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski Reload configuration file and zones.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski<dt><span class="term"><strong class="userinput"><code>reload <em class="replaceable"><code>zone</code></em>
30256573a343132354b122097b0ee1215dda1364Till Mossakowski [<span class="optional"><em class="replaceable"><code>class</code></em>
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski Reload the given zone.
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski<dt><span class="term"><strong class="userinput"><code>refresh <em class="replaceable"><code>zone</code></em>
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski [<span class="optional"><em class="replaceable"><code>class</code></em>
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
30256573a343132354b122097b0ee1215dda1364Till Mossakowski Schedule zone maintenance for the given zone.
30256573a343132354b122097b0ee1215dda1364Till Mossakowski<dt><span class="term"><strong class="userinput"><code>retransfer <em class="replaceable"><code>zone</code></em>
30256573a343132354b122097b0ee1215dda1364Till Mossakowski [<span class="optional"><em class="replaceable"><code>class</code></em>
30256573a343132354b122097b0ee1215dda1364Till Mossakowski [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
30256573a343132354b122097b0ee1215dda1364Till Mossakowski Retransfer the given zone from the master.
30256573a343132354b122097b0ee1215dda1364Till Mossakowski<dt><span class="term"><strong class="userinput"><code>sign <em class="replaceable"><code>zone</code></em>
30256573a343132354b122097b0ee1215dda1364Till Mossakowski [<span class="optional"><em class="replaceable"><code>class</code></em>
30256573a343132354b122097b0ee1215dda1364Till Mossakowski [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
30256573a343132354b122097b0ee1215dda1364Till Mossakowski Fetch all DNSSEC keys for the given zone
30256573a343132354b122097b0ee1215dda1364Till Mossakowski from the key directory (see
30256573a343132354b122097b0ee1215dda1364Till Mossakowski <span><strong class="command">key-directory</strong></span> in
30256573a343132354b122097b0ee1215dda1364Till Mossakowski <a href="Bv9ARM.ch06.html#options" title="options Statement Definition and
30256573a343132354b122097b0ee1215dda1364Till Mossakowski Usage">the section called “<span><strong class="command">options</strong></span> Statement Definition and
30256573a343132354b122097b0ee1215dda1364Till Mossakowski Usage”</a>). If they are within
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski their publication period, merge them into the
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder zone's DNSKEY RRset. If the DNSKEY RRset
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder is changed, then the zone is automatically
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder re-signed with the new key set.
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder This command requires that the
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder <span><strong class="command">auto-dnssec</strong></span> zone option to be set
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder <code class="literal">create</code>, and also requires
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski the zone to be configured to allow dynamic DNS.
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder See <a href="Bv9ARM.ch06.html#dynamic_update_policies" title="Dynamic Update Policies">the section called “Dynamic Update Policies”</a> for
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder more details.
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder<dt><span class="term"><strong class="userinput"><code>loadkeys <em class="replaceable"><code>zone</code></em>
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder [<span class="optional"><em class="replaceable"><code>class</code></em>
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder Fetch all DNSSEC keys for the given zone
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder from the key directory (see
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder <span><strong class="command">key-directory</strong></span> in
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski <a href="Bv9ARM.ch06.html#options" title="options Statement Definition and
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski Usage">the section called “<span><strong class="command">options</strong></span> Statement Definition and
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder Usage”</a>). If they are within
5c9181d2fd65687ced28a27cb8e161dee6d97f51Eugen Kuksa their publication period, merge them into the
5c9181d2fd65687ced28a27cb8e161dee6d97f51Eugen Kuksa zone's DNSKEY RRset. Unlike <span><strong class="command">rndc
650631bddf665ec5ef991bf4ce2f569b7709d104Christian Maeder sign</strong></span>, however, the zone is not
5c9181d2fd65687ced28a27cb8e161dee6d97f51Eugen Kuksa immediately re-signed by the new keys, but is
5c9181d2fd65687ced28a27cb8e161dee6d97f51Eugen Kuksa allowed to incrementally re-sign over time.
5c9181d2fd65687ced28a27cb8e161dee6d97f51Eugen Kuksa This command requires that the
650631bddf665ec5ef991bf4ce2f569b7709d104Christian Maeder <span><strong class="command">auto-dnssec</strong></span> zone option to
5c9181d2fd65687ced28a27cb8e161dee6d97f51Eugen Kuksa be set to <code class="literal">maintain</code> or
5c9181d2fd65687ced28a27cb8e161dee6d97f51Eugen Kuksa <code class="literal">create</code>, and also requires
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder the zone to be configured to allow dynamic DNS.
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder See <a href="Bv9ARM.ch06.html#dynamic_update_policies" title="Dynamic Update Policies">the section called “Dynamic Update Policies”</a> for
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder more details.
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder<dt><span class="term"><strong class="userinput"><code>freeze
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder [<span class="optional"><em class="replaceable"><code>zone</code></em>
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder [<span class="optional"><em class="replaceable"><code>class</code></em>
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</span>]</code></strong></span></dt>
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder Suspend updates to a dynamic zone. If no zone is
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski specified, then all zones are suspended. This allows
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder manual edits to be made to a zone normally updated by
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder dynamic update. It also causes changes in the
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder journal file to be synced into the master file.
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder All dynamic update attempts will be refused while
17787092f1a5f5d16445e8293fd4bcde69e3fc81Mihai Codescu the zone is frozen.
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski<dt><span class="term"><strong class="userinput"><code>thaw
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder [<span class="optional"><em class="replaceable"><code>zone</code></em>
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder [<span class="optional"><em class="replaceable"><code>class</code></em>
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</span>]</code></strong></span></dt>
533d6033bec94a46d13b73cafe40953f699757c7Christian Maeder Enable updates to a frozen dynamic zone. If no
7c3c3698b466d4c20e26b7bf4a16f3970303bcf7Christian Maeder zone is specified, then all frozen zones are
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski enabled. This causes the server to reload the zone
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski from disk, and re-enables dynamic updates after the
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski load has completed. After a zone is thawed,
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder dynamic updates will no longer be refused.
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski<dt><span class="term"><strong class="userinput"><code>sync
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder [<span class="optional"><em class="replaceable"><code>zone</code></em>
a8ce558d09f304be325dc89458c9504d3ff7fe80Till Mossakowski [<span class="optional"><em class="replaceable"><code>class</code></em>
a8ce558d09f304be325dc89458c9504d3ff7fe80Till Mossakowski [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</span>]</code></strong></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Sync changes in the journal file for a dynamic zone
e8f447e9e532f38658c7b3bbd0a5407aa42f66fbChristian Maeder to the master file. If the "-clean" option is
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder specified, the journal file is also removed. If
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski no zone is specified, then all zones are synced.
1e1cb538d4c4dc09e86cd8c209f55f9e37ae4970Till Mossakowski<dt><span class="term"><strong class="userinput"><code>notify <em class="replaceable"><code>zone</code></em>
1e1cb538d4c4dc09e86cd8c209f55f9e37ae4970Till Mossakowski [<span class="optional"><em class="replaceable"><code>class</code></em>
543ded2ae6a6e13f6cd2c22f9f0921e8c452cba0Christian Maeder [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]</code></strong></span></dt>
543ded2ae6a6e13f6cd2c22f9f0921e8c452cba0Christian Maeder Resend NOTIFY messages for the zone.
543ded2ae6a6e13f6cd2c22f9f0921e8c452cba0Christian Maeder<dt><span class="term"><strong class="userinput"><code>reconfig</code></strong></span></dt>
543ded2ae6a6e13f6cd2c22f9f0921e8c452cba0Christian Maeder Reload the configuration file and load new zones,
543ded2ae6a6e13f6cd2c22f9f0921e8c452cba0Christian Maeder but do not reload existing zone files even if they
543ded2ae6a6e13f6cd2c22f9f0921e8c452cba0Christian Maeder have changed.
1e1cb538d4c4dc09e86cd8c209f55f9e37ae4970Till Mossakowski This is faster than a full <span><strong class="command">reload</strong></span> when there
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder is a large number of zones because it avoids the need
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski to examine the
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski modification times of the zones files.
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder<dt><span class="term"><strong class="userinput"><code>stats</code></strong></span></dt>
c5e63ec138b908ac9d15e6843120033bf36a1862Till Mossakowski Write server statistics to the statistics file.
e7eefd526faedd63acb8f91de5793368cfe67655Klaus Luettich<dt><span class="term"><strong class="userinput"><code>querylog</code></strong></span></dt>
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski Toggle query logging. Query logging can also be enabled
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski by explicitly directing the <span><strong class="command">queries</strong></span>
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski <span><strong class="command">category</strong></span> to a
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski <span><strong class="command">channel</strong></span> in the
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder <span><strong class="command">logging</strong></span> section of
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder <code class="filename">named.conf</code> or by specifying
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder <span><strong class="command">querylog yes;</strong></span> in the
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder <span><strong class="command">options</strong></span> section of
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder<dt><span class="term"><strong class="userinput"><code>dumpdb
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder [<span class="optional">-all|-cache|-zone</span>]
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder [<span class="optional"><em class="replaceable"><code>view ...</code></em></span>]</code></strong></span></dt>
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder Dump the server's caches (default) and/or zones to
1e1cb538d4c4dc09e86cd8c209f55f9e37ae4970Till Mossakowski dump file for the specified views. If no view is
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder specified, all
a17349d0247036407c22e632ece0e8f2b736253cTill Mossakowski views are dumped.
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski<dt><span class="term"><strong class="userinput"><code>secroots
30256573a343132354b122097b0ee1215dda1364Till Mossakowski [<span class="optional"><em class="replaceable"><code>view ...</code></em></span>]</code></strong></span></dt>
1e1cb538d4c4dc09e86cd8c209f55f9e37ae4970Till Mossakowski Dump the server's security roots to the secroots
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski file for the specified views. If no view is
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder specified, security roots for all
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder views are dumped.
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder<dt><span class="term"><strong class="userinput"><code>stop [<span class="optional">-p</span>]</code></strong></span></dt>
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder Stop the server, making sure any recent changes
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder made through dynamic update or IXFR are first saved to
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder the master files of the updated zones.
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder If <code class="option">-p</code> is specified <span><strong class="command">named</strong></span>'s process id is returned.
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder This allows an external process to determine when <span><strong class="command">named</strong></span>
34d880694ed872dd3e7f922bd9ca3b1aa917c822Christian Maeder had completed stopping.
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder<dt><span class="term"><strong class="userinput"><code>halt [<span class="optional">-p</span>]</code></strong></span></dt>
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder Stop the server immediately. Recent changes
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder made through dynamic update or IXFR are not saved to
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder the master files, but will be rolled forward from the
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder journal files when the server is restarted.
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder If <code class="option">-p</code> is specified <span><strong class="command">named</strong></span>'s process id is returned.
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder This allows an external process to determine when <span><strong class="command">named</strong></span>
e0dcf58cb6eb2ba4cf2e14734d3af3c992cc1885Christian Maeder had completed halting.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski<dt><span class="term"><strong class="userinput"><code>trace</code></strong></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Increment the servers debugging level by one.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="term"><strong class="userinput"><code>trace <em class="replaceable"><code>level</code></em></code></strong></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Sets the server's debugging level to an explicit
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="term"><strong class="userinput"><code>notrace</code></strong></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Sets the server's debugging level to 0.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="term"><strong class="userinput"><code>flush</code></strong></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Flushes the server's cache.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="term"><strong class="userinput"><code>flushname</code></strong> <em class="replaceable"><code>name</code></em></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Flushes the given name from the server's cache.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="term"><strong class="userinput"><code>status</code></strong></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Display status of the server.
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder Note that the number of zones includes the internal <span><strong class="command">bind/CH</strong></span> zone
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski and the default <span><strong class="command">/IN</strong></span>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski hint zone if there is not an
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski explicit root zone configured.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="term"><strong class="userinput"><code>recursing</code></strong></span></dt>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Dump the list of queries <span><strong class="command">named</strong></span> is currently recursing
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="term"><strong class="userinput"><code>validation
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski [<span class="optional"><em class="replaceable"><code>view ...</code></em></span>]
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Enable or disable DNSSEC validation.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Note <span><strong class="command">dnssec-enable</strong></span> also needs to be
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski set to <strong class="userinput"><code>yes</code></strong> to be effective.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski It defaults to enabled.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<dt><span class="term"><strong class="userinput"><code>addzone
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski <em class="replaceable"><code>zone</code></em>
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski [<span class="optional"><em class="replaceable"><code>class</code></em>
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder <em class="replaceable"><code>configuration</code></em>
30256573a343132354b122097b0ee1215dda1364Till Mossakowski Add a zone while the server is running. This
30256573a343132354b122097b0ee1215dda1364Till Mossakowski command requires the
30256573a343132354b122097b0ee1215dda1364Till Mossakowski <span><strong class="command">allow-new-zones</strong></span> option to be set
30256573a343132354b122097b0ee1215dda1364Till Mossakowski to <strong class="userinput"><code>yes</code></strong>. The
30256573a343132354b122097b0ee1215dda1364Till Mossakowski <em class="replaceable"><code>configuration</code></em> string
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski specified on the command line is the zone
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder configuration text that would ordinarily be
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski placed in <code class="filename">named.conf</code>.
91dd24480df03b2cca7c1645bb2866d7000dfdb1Till Mossakowski The configuration is saved in a file called
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder <code class="filename"><em class="replaceable"><code>hash</code></em>.nzf</code>,
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski where <em class="replaceable"><code>hash</code></em> is a
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski cryptographic hash generated from the name of
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski the view. When <span><strong class="command">named</strong></span> is
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski restarted, the file will be loaded into the view
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski configuration, so that zones that were added
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski can persist after a restart.
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski This sample <span><strong class="command">addzone</strong></span> command
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski would add the zone <code class="literal">example.com</code>
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski to the default view:
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski<code class="prompt">$ </code><strong class="userinput"><code>rndc addzone example.com '{ type master; file "example.com.db"; };'</code></strong>
f4dd7b59c284145a320a4b976312de41921d3f9eMaciek Makowski (Note the brackets and semi-colon around the zone
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder configuration text.)
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski<dt><span class="term"><strong class="userinput"><code>delzone
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <em class="replaceable"><code>zone</code></em>
c9d53cd78829e538aee56b84db508d8d944e6551Till Mossakowski [<span class="optional"><em class="replaceable"><code>class</code></em>
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder [<span class="optional"><em class="replaceable"><code>view</code></em></span>]</span>]
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski Delete a zone while the server is running.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski Only zones that were originally added via
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">rndc addzone</strong></span> can be deleted
38914aa544a92aa72e537446cfff297dc6109e04Christian Maeder in this matter.
a748e6c1e72afbfa4f76e06632c05cb535bb54a0Christian Maeder A configuration file is required, since all
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder communication with the server is authenticated with
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski digital signatures that rely on a shared secret, and
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski there is no way to provide that secret other than with a
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski configuration file. The default location for the
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder <span><strong class="command">rndc</strong></span> configuration file is
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder <code class="filename">/etc/rndc.conf</code>, but an
a748e6c1e72afbfa4f76e06632c05cb535bb54a0Christian Maeder location can be specified with the <code class="option">-c</code>
a748e6c1e72afbfa4f76e06632c05cb535bb54a0Christian Maeder option. If the configuration file is not found,
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder <span><strong class="command">rndc</strong></span> will also look in
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <code class="filename">/etc/rndc.key</code> (or whatever
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <code class="varname">sysconfdir</code> was defined when
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski the <acronym class="acronym">BIND</acronym> build was
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder The <code class="filename">rndc.key</code> file is
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski running <span><strong class="command">rndc-confgen -a</strong></span> as
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <a href="Bv9ARM.ch06.html#controls_statement_definition_and_usage" title="controls Statement Definition and
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski Usage">the section called “<span><strong class="command">controls</strong></span> Statement Definition and
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Usage”</a>.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski The format of the configuration file is similar to
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski that of <code class="filename">named.conf</code>, but
89118fd658073a87eddf4ead4bb63c6adb30550dTill Mossakowski only four statements, the <span><strong class="command">options</strong></span>,
30256573a343132354b122097b0ee1215dda1364Till Mossakowski <span><strong class="command">key</strong></span>, <span><strong class="command">server</strong></span> and
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski <span><strong class="command">include</strong></span>
a8ce558d09f304be325dc89458c9504d3ff7fe80Till Mossakowski statements. These statements are what associate the
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski secret keys to the servers with which they are meant to
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski be shared. The order of statements is not
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski The <span><strong class="command">options</strong></span> statement has
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski three clauses:
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski <span><strong class="command">default-server</strong></span>, <span><strong class="command">default-key</strong></span>,
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski and <span><strong class="command">default-port</strong></span>.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">default-server</strong></span> takes a
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski host name or address argument and represents the server
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder be contacted if no <code class="option">-s</code>
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder option is provided on the command line.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">default-key</strong></span> takes
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski the name of a key as its argument, as defined by a <span><strong class="command">key</strong></span> statement.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">default-port</strong></span> specifies the
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski port to which
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">rndc</strong></span> should connect if no
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski port is given on the command line or in a
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">server</strong></span> statement.
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder The <span><strong class="command">key</strong></span> statement defines a
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder key to be used
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder by <span><strong class="command">rndc</strong></span> when authenticating
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">named</strong></span>. Its syntax is
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski identical to the
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">key</strong></span> statement in <code class="filename">named.conf</code>.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski The keyword <strong class="userinput"><code>key</code></strong> is
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski followed by a key name, which must be a valid
a8ce558d09f304be325dc89458c9504d3ff7fe80Till Mossakowski domain name, though it need not actually be hierarchical;
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski a string like "<strong class="userinput"><code>rndc_key</code></strong>" is a valid
9101c1cc72e8daa5e9b56c7c9e841c377f98402eTill Mossakowski The <span><strong class="command">key</strong></span> statement has two
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">algorithm</strong></span> and <span><strong class="command">secret</strong></span>.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski While the configuration parser will accept any string as the
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski to algorithm, currently only the string "<strong class="userinput"><code>hmac-md5</code></strong>"
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski has any meaning. The secret is a base-64 encoded string
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski as specified in RFC 3548.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski The <span><strong class="command">server</strong></span> statement
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder associates a key
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski defined using the <span><strong class="command">key</strong></span>
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski statement with a server.
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder The keyword <strong class="userinput"><code>server</code></strong> is followed by a
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski host name or address. The <span><strong class="command">server</strong></span> statement
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski has two clauses: <span><strong class="command">key</strong></span> and <span><strong class="command">port</strong></span>.
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski The <span><strong class="command">key</strong></span> clause specifies the
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski name of the key
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski to be used when communicating with this server, and the
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <span><strong class="command">port</strong></span> clause can be used to
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski specify the port <span><strong class="command">rndc</strong></span> should
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski to on the server.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski A sample minimal configuration file is as follows:
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowskikey rndc_key {
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski algorithm "hmac-md5";
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski "c3Ryb25nIGVub3VnaCBmb3IgYSBtYW4gYnV0IG1hZGUgZm9yIGEgd29tYW4K";
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski default-server 127.0.0.1;
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski default-key rndc_key;
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski This file, if installed as <code class="filename">/etc/rndc.conf</code>,
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski would allow the command:
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski <code class="prompt">$ </code><strong class="userinput"><code>rndc reload</code></strong>
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski to connect to 127.0.0.1 port 953 and cause the name server
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski to reload, if a name server on the local machine were
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder following controls statements:
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski inet 127.0.0.1
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski allow { localhost; } keys { rndc_key; };
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski and it had an identical key statement for
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski Running the <span><strong class="command">rndc-confgen</strong></span>
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski conveniently create a <code class="filename">rndc.conf</code>
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski file for you, and also display the
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski corresponding <span><strong class="command">controls</strong></span>
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski statement that you need to
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski add to <code class="filename">named.conf</code>.
3532dcfda4dd76997072fcda24e75c305d105233Till Mossakowski Alternatively,
9c3b1fb1952bb78a1942fe612215f940fc8e5f31Till Mossakowski you can run <span><strong class="command">rndc-confgen -a</strong></span>
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski a <code class="filename">rndc.key</code> file and not
38a46398edcd7ad7d1777ae646d4cc484cce49bfTill Mossakowski <code class="filename">named.conf</code> at all.
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder<div class="titlepage"><div><div><h3 class="title">
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder<a name="id2570345"></a>Signals</h3></div></div></div>
d3e4f883d74b0cd6b1708141fddc20e895e82eb1Eugen Kuksa Certain UNIX signals cause the name server to take specific
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder actions, as described in the following table. These signals can
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder be sent using the <span><strong class="command">kill</strong></span> command.
1e276df94eadfeab45099f4482f76a9958bedb9cChristian Maeder<div class="informaltable"><table border="1">
d3f2015ae170a15e5b57d4880ded53073d725ac0Till Mossakowski <p><span><strong class="command">SIGHUP</strong></span></p>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Causes the server to read <code class="filename">named.conf</code> and
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski reload the database.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski <p><span><strong class="command">SIGTERM</strong></span></p>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Causes the server to clean up and exit.
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder <p><span><strong class="command">SIGINT</strong></span></p>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski Causes the server to clean up and exit.
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<table width="100%" summary="Navigation footer">
8d576513b8c89016a3d678378ed75cac0e2e1aefChristian Maeder<a accesskey="p" href="Bv9ARM.ch02.html">Prev</a>�</td>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<td width="40%" align="right">�<a accesskey="n" href="Bv9ARM.ch04.html">Next</a>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<td width="40%" align="left" valign="top">Chapter�2.�<acronym class="acronym">BIND</acronym> Resource Requirements�</td>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
5277e290ad70afdf97f359019afd8fb5816f4102Till Mossakowski<td width="40%" align="right" valign="top">�Chapter�4.�Advanced DNS Features</td>