Bv9ARM.ch04.html revision 21163ca842b7969eade26710b4eae72ab0a99c0c
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Advanced Concepts</TITLE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="GENERATOR"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCONTENT="Modular DocBook HTML Stylesheet Version 1.41"><LINK
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinREL="PREVIOUS"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinTITLE="Nameserver Configuration"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinTITLE="The BIND 9 Lightweight Resolver"
ea94d370123a5892f6c47a97f21d1b28d44bb168Tinderbox UserBGCOLOR="#FFFFFF"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinTEXT="#000000"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinLINK="#0000FF"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinVLINK="#840084"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinALINK="#0000FF"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="NAVHEADER"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCELLPADDING="0"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCELLSPACING="0"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinALIGN="center"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinVALIGN="bottom"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinALIGN="center"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinVALIGN="bottom"
2fa992d017c027173a47c834db88bef10df453c0Tinderbox UserVALIGN="bottom"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="chapter"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>Chapter 4. Advanced Concepts</A
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User>Table of Contents</B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinHREF="Bv9ARM.ch04.html#dynamic_update"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Dynamic Update</A
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserHREF="Bv9ARM.ch04.html#incremental_zone_transfers"
2fa992d017c027173a47c834db88bef10df453c0Tinderbox User>Incremental Zone Transfers (IXFR)</A
2fa992d017c027173a47c834db88bef10df453c0Tinderbox User>IPv6 Support in <SPAN
2fa992d017c027173a47c834db88bef10df453c0Tinderbox UserCLASS="acronym"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserNAME="dynamic_update"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>4.1. Dynamic Update</A
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>Dynamic update is the term used for the ability under
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User certain specified conditions to add, modify or delete records or
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User RRsets in the master zone files. Dynamic update is fully described
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User in RFC 2136.</P
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>Dynamic update is enabled on a zone-by-zone basis, by
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User including an <B
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="command"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>allow-update</B
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="command"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>update-policy</B
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User> clause in the
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="command"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User> statement.</P
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>Updating of secure zones (zones using DNSSEC) is modelled
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="emphasis"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>simple-secure-update</I
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User work in progress in the DNS Extensions working group of the IETF.
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserHREF="http://www.ietf.org/html.charters/dnsext-charter.html"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>http://www.ietf.org/html.charters/dnsext-charter.html</A
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User for information about the DNS Extensions working group.) SIG and
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User NXT records affected by updates are automatically regenerated by
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User the server using an online zone key. Update authorization is based
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User on transaction signatures and an explicit server policy.</P
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>The zone files of dynamic zones cannot normally be edited by hand.
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User The zone file on disk at any given time may not contain the latest
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User changes performed by dynamic update. The zone file is only
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User written to disk only occasionally, and when shutting down the server using
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="command"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>. Changes that have occurred since the
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User zone file was last written to disk are stored only in the zone's
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
def82e8de9ff45e29ab21e5aba9a39539138c1f4Tinderbox User>If you have to make changes to a dynamic zone
def82e8de9ff45e29ab21e5aba9a39539138c1f4Tinderbox User manually, the following procedure will work: Shut down
a3ff24aaa545c45b8c581b2127d02d735aff8881Tinderbox User the server using <B
a3ff24aaa545c45b8c581b2127d02d735aff8881Tinderbox UserCLASS="command"
a3ff24aaa545c45b8c581b2127d02d735aff8881Tinderbox User> (sending a signal
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="command"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="emphasis"
def82e8de9ff45e29ab21e5aba9a39539138c1f4Tinderbox User sufficient). Wait for the server to exit,
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="emphasis"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User> file, edit the zone file,
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User and restart the server. Removing the <TT
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User file is necessary because the manual edits will not be
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User present in the journal, rendering it inconsistent with the
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User contents of the zone file.</P
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserNAME="incremental_zone_transfers"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>4.2. Incremental Zone Transfers (IXFR)</A
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>The incremental zone transfer (IXFR) protocol is a way for
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User slave servers to transfer only changed data, instead of having to
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User transfer the entire zone. The IXFR protocol is documented in RFC
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserHREF="Bv9ARM.ch09.html#proposed_standards"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>Proposed Standards</I
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>When acting as a master, <SPAN
a3ff24aaa545c45b8c581b2127d02d735aff8881Tinderbox UserCLASS="acronym"
a3ff24aaa545c45b8c581b2127d02d735aff8881Tinderbox User> 9 supports IXFR for those zones
a3ff24aaa545c45b8c581b2127d02d735aff8881Tinderbox Userwhere the necessary change history information is available. These
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox Userinclude master zones maintained by dynamic update and slave zones
2fa992d017c027173a47c834db88bef10df453c0Tinderbox Userwhose data was obtained by IXFR, but not manually maintained master
2fa992d017c027173a47c834db88bef10df453c0Tinderbox Userzones nor slave zones obtained by performing a full zone transfer
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>When acting as a slave, <SPAN
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="acronym"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User> 9 will attempt to use IXFR unless
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox Userit is explicitly disabled. For more information about disabling
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserIXFR, see the description of the <B
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="command"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>request-ixfr</B
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="command"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User> statement.</P
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>4.3. Split DNS</A
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>Setting up different views, or visibility, of DNS space to
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox Userinternal and external resolvers is usually referred to as a <I
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="emphasis"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User> setup. There are several reasons an organization
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox Userwould want to set up its DNS this way.</P
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>One common reason for setting up a DNS system this way is
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox Userto hide "internal" DNS information from "external" clients on the
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserInternet. There is some debate as to whether or not this is actually useful.
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserInternal DNS information leaks out in many ways (via email headers,
daf4204f82af39a71de8be039c2070aa605145a9Tinderbox Userfor example) and most savvy "attackers" can find the information
daf4204f82af39a71de8be039c2070aa605145a9Tinderbox Userthey need using other means.</P
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>Another common reason for setting up a Split DNS system is
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userto allow internal networks that are behind filters or in RFC 1918
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userspace (reserved IP space, as documented in RFC 1918) to resolve DNS
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Useron the Internet. Split DNS can also be used to allow mail from outside
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userback in to the internal network.</P
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>Here is an example of a split DNS setup:</P
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>Let's say a company named <I
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="emphasis"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>Example, Inc.</I
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userhas several corporate sites that have an internal network with reserved
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserInternet Protocol (IP) space and an external demilitarized zone (DMZ),
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox Useror "outside" section of a network, that is available to the public.</P
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox UserCLASS="emphasis"
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User>Example, Inc.</I
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User> wants its internal clients
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox Userto be able to resolve external hostnames and to exchange mail with
2fa992d017c027173a47c834db88bef10df453c0Tinderbox Userpeople on the outside. The company also wants its internal resolvers
2fa992d017c027173a47c834db88bef10df453c0Tinderbox Userto have access to certain internal-only zones that are not available
2fa992d017c027173a47c834db88bef10df453c0Tinderbox Userat all outside of the internal network.</P
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>In order to accomplish this, the company will set up two sets
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox Userof nameservers. One set will be on the inside network (in the reserved
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserIP space) and the other set will be on bastion hosts, which are "proxy"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox Userhosts that can talk to both sides of its network, in the DMZ.</P
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>The internal servers will be configured to forward all queries,
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox Userexcept queries for <TT
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>, to the servers in the
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserDMZ. These internal servers will have complete sets of information
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="emphasis"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox User>To protect the <TT
eaaf00efc02fdd4965f747afb51f881ac5a389d2Tinderbox UserCLASS="filename"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="filename"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userthe internal nameservers must be configured to disallow all queries
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userto these domains from any external hosts, including the bastion
2fa992d017c027173a47c834db88bef10df453c0Tinderbox User>The external servers, which are on the bastion hosts, will
2fa992d017c027173a47c834db88bef10df453c0Tinderbox Userbe configured to serve the "public" version of the <TT
6469eef791ebc5c7a38850c96db219f9a000c554Tinderbox UserCLASS="filename"
6469eef791ebc5c7a38850c96db219f9a000c554Tinderbox UserCLASS="filename"
6469eef791ebc5c7a38850c96db219f9a000c554Tinderbox UserThis could include things such as the host records for public servers
6469eef791ebc5c7a38850c96db219f9a000c554Tinderbox UserCLASS="filename"
2fa992d017c027173a47c834db88bef10df453c0Tinderbox UserCLASS="filename"
2fa992d017c027173a47c834db88bef10df453c0Tinderbox Userand mail exchange (MX) records (<TT
2fa992d017c027173a47c834db88bef10df453c0Tinderbox UserCLASS="filename"
2fa992d017c027173a47c834db88bef10df453c0Tinderbox UserCLASS="filename"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>In addition, the public <TT
4abdfc917e6635a7c81d1f931a0c79227e72d025Mark AndrewsCLASS="filename"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="filename"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinshould have special MX records that contain wildcard (`*') records
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinpointing to the bastion hosts. This is needed because external mail
b05bdb520d83f7ecaad708fe305268c3420be01dMark Andrewsservers do not have any other way of looking up how to deliver mail
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinto those internal hosts. With the wildcard records, the mail will
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinbe delivered to the bastion host, which can then forward it on to
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeininternal hosts.</P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Here's an example of a wildcard MX record:</P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="programlisting"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="literal"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Now that they accept mail on behalf of anything in the internal
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinnetwork, the bastion hosts will need to know how to deliver mail
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinto internal hosts. In order for this to work properly, the resolvers on
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinthe bastion hosts will need to be configured to point to the internal
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsnameservers for DNS resolution.</P
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>Queries for internal hostnames will be answered by the internal
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinservers, and queries for external hostnames will be forwarded back
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinout to the DNS servers on the bastion hosts.</P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>In order for all this to work properly, internal clients will
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinneed to be configured to query <I
47012ae6dbf18a2503d7b33c1c9583dc38625cb7Mark AndrewsCLASS="emphasis"
47012ae6dbf18a2503d7b33c1c9583dc38625cb7Mark Andrews> the internal
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsnameservers for DNS queries. This could also be enforced via selective
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinfiltering on the network.</P
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>If everything has been set properly, <I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="emphasis"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Example, Inc.</I
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsinternal clients will now be able to:</P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Look up any hostnames in the <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="literal"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="literal"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Look up any hostnames in the <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="literal"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="literal"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> domains.</P
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews>Look up any hostnames on the Internet.</P
a1b05dea35aa30b152a47115e18bbe679d3fcf19Mark Andrews>Exchange mail with internal AND external people.</P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Hosts on the Internet will be able to:</P
a1b05dea35aa30b152a47115e18bbe679d3fcf19Mark Andrews>Look up any hostnames in the <TT
9c6a5d1f22f972232d7a9fd5c5fa64f10bacbdffAutomatic UpdaterCLASS="literal"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="literal"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Exchange mail with anyone in the <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="literal"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="literal"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Here is an example configuration for the setup we just
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein described above. Note that this is only configuration information;
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein for information on how to configure your zone files, see <A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinHREF="Bv9ARM.ch03.html#sample_configuration"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Section 3.1</A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Internal DNS server config:</P
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark AndrewsCLASS="programlisting"
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrewsacl internals { 172.16.72.0/24; 192.168.1.0/24; };
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinacl externals { <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="varname"
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews>bastion-ips-go-here</TT
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews forward only;
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein forwarders { // forward to external servers
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark AndrewsCLASS="varname"
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews>bastion-ips-go-here</TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein allow-transfer { none; }; // sample allow-transfer (no one)
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein allow-query { internals; externals; }; // restrict query access
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews allow-recursion { internals; }; // restrict recursion
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinzone "site1.example.com" { // sample slave zone
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews type master;
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews forwarders { }; // do normal iterative
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews // resolution (do not forward)
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews allow-query { internals; externals; };
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews allow-transfer { internals; };
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein masters { 172.16.72.3; };
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein forwarders { };
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein allow-query { internals; externals; };
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein allow-transfer { internals; };
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein type master;
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein forwarders { };
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein allow-query { internals; };
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein allow-transfer { internals; }
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein masters { 172.16.72.3; };
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews forwarders { };
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews allow-query { internals };
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews allow-transfer { internals; }
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews>External (bastion host) DNS server config:</P
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark AndrewsCLASS="programlisting"
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews> acl internals { 172.16.72.0/24; 192.168.1.0/24; };
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrewsacl externals { bastion-ips-go-here; };
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User allow-transfer { none; }; // sample allow-transfer (no one)
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein allow-query { internals; externals; }; // restrict query access
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein allow-recursion { internals; externals; }; // restrict recursion
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userzone "site1.example.com" { // sample slave zone
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews type master;
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User allow-query { any; };
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews allow-transfer { internals; externals; };
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews masters { another_bastion_host_maybe; };
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User allow-query { any; };
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews allow-transfer { internals; externals; }
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="filename"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User> (or equivalent) on
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsthe bastion host(s):</P
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="programlisting"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews> search ...
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsnameserver 172.16.72.2
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Usernameserver 172.16.72.3
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsnameserver 172.16.72.4
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect1"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect1"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>4.4. TSIG</A
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>This is a short guide to setting up Transaction SIGnatures
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews(TSIG) based transaction security in <SPAN
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="acronym"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>. It describes changes
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userto the configuration file as well as what changes are required for
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsdifferent features, including the process of creating transaction
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewskeys and using transaction signatures with <SPAN
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="acronym"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="acronym"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews> primarily supports TSIG for server to server communication.
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsThis includes zone transfer, notify, and recursive query messages.
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserResolvers based on newer versions of <SPAN
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="acronym"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User> 8 have limited support
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>TSIG might be most useful for dynamic update. A primary
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews server for a dynamic zone should use access control to control
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews updates, but IP-based access control is insufficient. Key-based
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User access control is far superior, see <A
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsHREF="Bv9ARM.ch09.html#proposed_standards"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>Proposed Standards</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="command"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein program supports TSIG via the <TT
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="option"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="option"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews> command line options.</P
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect2"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect2"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>4.4.1. Generate Shared Keys for Each Pair of Hosts</A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>A shared secret is generated to be shared between <I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="emphasis"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="emphasis"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsAn arbitrary key name is chosen: "host1-host2.". The key name must
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsbe the same on both hosts.</P
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect3"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect3"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN758"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>4.4.1.1. Automatic Generation</A
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>The following command will generate a 128 bit (16 byte) HMAC-MD5
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinkey as described above. Longer keys are better, but shorter keys
cefd74ae81cf51692af3a38c1330261a5110fca7Tinderbox Userare easier to read. Note that the maximum key length is 512 bits;
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewskeys longer than that will be digested with MD5 to produce a 128
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="userinput"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>dnssec-keygen -a hmac-md5 -b 128 -n HOST host1-host2.</B
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>The key is in the file <TT
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="filename"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsNothing directly uses this file, but the base-64 encoded string
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsfollowing "<TT
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="literal"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Usercan be extracted from the file and used as a shared secret:</P
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="programlisting"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>The string "<TT
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="literal"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userbe used as the shared secret.</P
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect3"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsNAME="AEN769"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>4.4.1.2. Manual Generation</A
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>The shared secret is simply a random sequence of bits, encoded
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsin base-64. Most ASCII strings are valid base-64 strings (assuming
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userthe length is a multiple of 4 and only valid characters are used),
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsso the shared secret can be manually generated.</P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Also, a known string can be run through <B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="command"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Usera similar program to generate base-64 encoded data.</P
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect2"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>4.4.2. Copying the Shared Secret to Both Machines</A
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>This is beyond the scope of DNS. A secure transport mechanism
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsshould be used. This could be secure FTP, ssh, telephone, etc.</P
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect2"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect2"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN777"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>4.4.3. Informing the Servers of the Key's Existence</A
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="emphasis"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="emphasis"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userboth servers. The following is added to each server's <TT
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="filename"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="programlisting"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews> key host1-host2. {
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User algorithm hmac-md5;
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews>The algorithm, hmac-md5, is the only one supported by <SPAN
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="acronym"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsThe secret is the one generated above. Since this is a secret, it
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsis recommended that either <TT
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="filename"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews> be non-world
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userreadable, or the key directive be added to a non-world readable
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsfile that is included by <TT
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="filename"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>At this point, the key is recognized. This means that if the
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrewsserver receives a message signed by this key, it can verify the
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrewssignature. If the signature succeeds, the response is signed by
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsthe same key.</P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="sect2"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect2"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN789"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>4.4.4. Instructing the Server to Use the Key</A
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>Since keys are shared between two hosts only, the server must
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsbe told when keys are to be used. The following is added to the <TT
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="filename"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="emphasis"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>, if the IP address of <I
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="emphasis"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="programlisting"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews> server 10.1.2.3 {
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User keys { host1-host2. ;};
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>Multiple keys may be present, but only the first is used.
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsThis directive does not contain any secrets, so it may be in a world-readable
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="emphasis"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews> sends a message that is a request
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austeinto that address, the message will be signed with the specified key. <I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="emphasis"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userexpect any responses to signed messages to be signed with the same
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>A similar statement must be present in <I
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="emphasis"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox Userconfiguration file (with <I
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="emphasis"
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews>'s address) for <I
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark AndrewsCLASS="emphasis"
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrewssign request messages to <I
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark AndrewsCLASS="emphasis"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect2"
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="sect2"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>4.4.5. TSIG Key Based Access Control</A
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="acronym"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews> allows IP addresses and ranges to be specified in ACL
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsdefinitions and
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserCLASS="command"
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews>allow-{ query | transfer | update }</B
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews> directives.
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox UserThis has been extended to allow TSIG keys also. The above key would
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrewsbe denoted <B
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="command"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>key host1-host2.</B
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>An example of an allow-update directive would be:</P
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="programlisting"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User> allow-update { key host1-host2. ;};
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>This allows dynamic updates to succeed only if the request
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews was signed by a key named
71c66a876ecca77923638d3f94cc0783152b2f03Mark AndrewsCLASS="command"
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>host1-host2.</B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>You may want to read about the more
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="command"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>update-policy</B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> statement in <A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinHREF="Bv9ARM.ch06.html#dynamic_update_policies"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Section 6.2.22.4</A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="sect2"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="sect2"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN818"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>4.4.6. Errors</A
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>The processing of TSIG signed messages can result in
4abdfc917e6635a7c81d1f931a0c79227e72d025Mark Andrews several errors. If a signed message is sent to a non-TSIG aware
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein server, a FORMERR will be returned, since the server will not
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein understand the record. This is a result of misconfiguration,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein since the server must be explicitly configured to send a TSIG
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User signed message to a specific server.</P
369963ad26cef09c3839d76c74c2d856f91be27aTinderbox User>If a TSIG aware server receives a message signed by an
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater unknown key, the response will be unsigned with the TSIG
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater extended error code set to BADKEY. If a TSIG aware server
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater receives a message with a signature that does not validate, the
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater response will be unsigned with the TSIG extended error code set
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater to BADSIG. If a TSIG aware server receives a message with a time
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater outside of the allowed range, the response will be signed with
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater the TSIG extended error code set to BADTIME, and the time values
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater will be adjusted so that the response can be successfully
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater verified. In any of these cases, the message's rcode is set to
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> is a mechanism for automatically
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater generating a shared secret between two hosts. There are several
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> that specify how the key is
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater generated or assigned. <SPAN
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="acronym"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> implements only one of these modes,
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater the Diffie-Hellman key exchange. Both hosts are required to have
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater a Diffie-Hellman KEY record (although this record is not required
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User to be present in a zone). The <B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater must use signed messages, signed either by TSIG or SIG(0). The
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> is a shared secret that can be
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User used to sign messages with TSIG. <B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater be used to delete shared secrets that it had previously
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> process is initiated by a client
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater or server by sending a signed <B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User (including any appropriate KEYs) to a TKEY-aware server. The
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater server response, if it indicates success, will contain a
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> record and any appropriate keys. After
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater this exchange, both participants have enough information to
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater determine the shared secret; the exact process depends on the
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> mode. When using the Diffie-Hellman
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> mode, Diffie-Hellman keys are exchanged,
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater and the shared secret is derived by both participants.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>4.6. SIG(0)</A
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="acronym"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> 9 partially supports DNSSEC SIG(0) transaction
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater signatures as specified in RFC 2535. SIG(0) uses public/private
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater keys to authenticate messages. Access control is performed in the
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater same manner as TSIG keys; privileges can be granted or denied
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater based on the key name.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>When a SIG(0) signed message is received, it will only be
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater verified if the key is known and trusted by the server; the server
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater will not attempt to locate and/or validate the key.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>SIG(0) signing of multiple-message TCP streams is not
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="acronym"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> 9 does not ship with any tools that generate SIG(0)
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater signed messages.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>4.7. DNSSEC</A
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>Cryptographic authentication of DNS information is possible
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater through the DNS Security (<I
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="emphasis"
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User>) extensions,
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater defined in RFC 2535. This section describes the creation and use
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater of DNSSEC signed zones.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>In order to set up a DNSSEC secure zone, there are a series
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater of steps which must be followed. <SPAN
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="acronym"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater with several tools
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater that are used in this process, which are explained in more detail
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater below. In all cases, the "<TT
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>" option prints a
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater full list of parameters. Note that the DNSSEC tools require the
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater keyset and signedkey files to be in the working directory, and
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater that the tools shipped with BIND 9.0.x are not fully compatible
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User with the current ones.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>There must also be communication with the administrators of
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater the parent and/or child zone to transmit keys and signatures. A
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater zone's security status must be indicated by the parent zone for a
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater DNSSEC capable resolver to trust its data.</P
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User>For other servers to trust data in this zone, they must
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater either be statically configured with this zone's zone key or the
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater zone key of another zone above this one in the DNS tree.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>4.7.1. Generating Keys</A
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>dnssec-keygen</B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> program is used to
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater generate keys.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>A secure zone must contain one or more zone keys. The
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater zone keys will sign all other records in the zone, as well as
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater the zone keys of any secure delegated zones. Zone keys must
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater have the same name as the zone, a name type of
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>, and must be usable for authentication.
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater It is recommended that zone keys be mandatory to implement a
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater cryptographic algorithm; currently the only key mandatory to
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater implement an algorithm is DSA.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>The following command will generate a 768 bit DSA key for
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="userinput"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>dnssec-keygen -a DSA -b 768 -n ZONE child.example.</B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>Two output files will be produced:
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater 12345 is an example of a key tag). The key file names contain
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater the key name (<TT
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>), algorithm (3
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater is DSA, 1 is RSA, etc.), and the key tag (12345 in this case).
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater The private key (in the <TT
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater used to generate signatures, and the public key (in the
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox UserCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> file) is used for signature
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater verification.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>To generate another key with the same properties (but with
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater a different key tag), repeat the above command.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>The public keys should be inserted into the zone file with
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> statements, including the
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>4.7.2. Creating a Keyset</A
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>dnssec-makekeyset</B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> program is used
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater to create a key set from one or more keys.</P
a24330c4805a224191ab687d0291963062fe3355Tinderbox User>Once the zone keys have been generated, a key set must be
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater built for transmission to the administrator of the parent zone,
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater so that the parent zone can sign the keys with its own zone key
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater and correctly indicate the security status of this zone. When
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater building a key set, the list of keys to be included and the TTL
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater of the set must be specified, and the desired signature validity
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater period of the parent's signature may also be specified.</P
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User>The list of keys to be inserted into the key set may also
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater included non-zone keys present at the top of the zone.
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>dnssec-makekeyset</B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> may also be used at other
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater names in the zone.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>The following command generates a key set containing the
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater above key and another key similarly generated, with a TTL of
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater 3600 and a signature validity period of 10 days starting from
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="userinput"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>dnssec-makekeyset -t 3600 -e +864000 Kchild.example.+003+12345 Kchild.example.+003+23456</B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>One output file is produced:
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>. This file should be
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater transmitted to the parent to be signed. It includes the keys,
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater as well as signatures over the key set generated by the zone
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater keys themselves, which are used to prove ownership of the
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater private keys and encode the desired validity period.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>4.7.3. Signing the Child's Keyset</A
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User>dnssec-signkey</B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> program is used to
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater sign one child's keyset.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater delegations which are secure, for example,
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> administrator should receive
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox User keyset files for each secure subzone. These keys must be signed
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater by this zone's zone keys.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>The following command signs the child's key set with the
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="userinput"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>dnssec-signkey keyset-grand.child.example. Kchild.example.+003+12345 Kchild.example.+003+23456</B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>One output file is produced:
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater should be both transmitted back to the child and retained. It
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater includes all keys (the child's keys) from the keyset file and
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater signatures generated by this zone's zone keys.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>4.7.4. Signing the Zone</A
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>dnssec-signzone</B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> program is used to
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater sign a zone.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> files corresponding to
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater secure subzones should be present, as well as a
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> file for this zone generated by
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater the parent (if there is one). The zone signer will generate
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="literal"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="literal"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater the zone, as well as incorporate the zone key signature from the
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater parent and indicate the security status at all delegation
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>The following command signs the zone, assuming it is in a
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater file called <TT
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater default, all zone keys which have an available private key are
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater used to generate signatures.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="userinput"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>dnssec-signzone -o child.example zone.child.example</B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>One output file is produced:
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater should be referenced by <TT
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="filename"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater input file for the zone.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>4.7.5. Configuring Servers</A
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>Unlike in <SPAN
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="acronym"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> 8, data is not verified on load in <SPAN
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="acronym"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater so zone keys for authoritative zones do not need to be specified
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater in the configuration file.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>The public key for any security root must be present in
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater the configuration file's <B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="command"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>trusted-keys</B
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater statement, as described later in this document. </P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>4.8. IPv6 Support in <SPAN
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="acronym"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="acronym"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> 9 fully supports all currently defined forms of IPv6
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater name to address and address to name lookups. It will also use
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater IPv6 addresses to make queries when running on an IPv6 capable
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>For forward lookups, <SPAN
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="acronym"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> 9 supports both A6 and AAAA
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater records. The use of AAAA records is deprecated, but it is still
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater useful for hosts to have both AAAA and A6 records to maintain
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater backward compatibility with installations where AAAA records are
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater still used. In fact, the stub resolvers currently shipped with
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater most operating system support only AAAA lookups, because following
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater A6 chains is much harder than doing A or AAAA lookups.</P
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater>For IPv6 reverse lookups, <SPAN
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="acronym"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater> 9 supports the new
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater "bitstring" format used in the <I
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic UpdaterCLASS="emphasis"
44d0f0256fbdce130a18655023c3b06bacacbd61Automatic Updater domain, as well as the older, deprecated "nibble" format used in
ebca35d493a0f74b0fb3371b7f19ef80f99f156cTinderbox UserCLASS="emphasis"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="acronym"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> 9 includes a new lightweight resolver library and
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein resolver daemon which new applications may choose to use to avoid
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the complexities of A6 chain following and bitstring labels, see <A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Chapter 5</A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="sect2"
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark AndrewsCLASS="sect2"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN936"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>4.8.1. Address Lookups Using AAAA Records</A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>The AAAA record is a parallel to the IPv4 A record. It
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein specifies the entire address in a single record. For
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="programlisting"
> $ORIGIN example.com.
> $ORIGIN example.com.
host 3600 IN A6 64 0:0:0:0:42::1 company.example1.net.
host 3600 IN A6 64 0:0:0:0:42::1 company.example2.net.
> $ORIGIN example1.net.
> $ORIGIN example2.net.
> $ORIGIN example.com.
> $ORIGIN 0.6.8.1.1.0.2.0.0.5.0.8.e.f.f.3.ip6.int.
1.0.0.0.0.0.0.0.0.0.0.0.2.4.0.0 14400 IN PTR host.example.com.
> $ORIGIN example.com.
host A6 64 ::1234:5678:1212:5675 cust1.example.net.
A6 64 ::1234:5678:1212:5675 subnet5.example2.net.
$ORIGIN example.net.
cust1 A6 48 0:0:0:dddd:: ipv6net.example.net.
$ORIGIN example2.net.
subnet5 A6 48 0:0:0:1:: ipv6net2.example2.net.
> $ORIGIN ipv6-rev.example.com.
HREF="Bv9ARM.ch03.html"
HREF="Bv9ARM.html"
HREF="Bv9ARM.ch05.html"