Bv9ARM.ch04.html revision 575e532437cf7f203707765e21767db92fa1e480
e8ca2abed76b550fd3baddcfb17f2c9a630d6b71Mark Andrews<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
e8ca2abed76b550fd3baddcfb17f2c9a630d6b71Mark Andrews<HTML
e8ca2abed76b550fd3baddcfb17f2c9a630d6b71Mark Andrews><HEAD
81d9d7a10e52b421d7f4784c48ae995b13203c59Mark Andrews><TITLE
81d9d7a10e52b421d7f4784c48ae995b13203c59Mark Andrews>Advanced DNS Features</TITLE
81d9d7a10e52b421d7f4784c48ae995b13203c59Mark Andrews><META
301f6ffbbeabcbf765f8163f4ffb7f6f0146b926Mark AndrewsNAME="GENERATOR"
301f6ffbbeabcbf765f8163f4ffb7f6f0146b926Mark AndrewsCONTENT="Modular DocBook HTML Stylesheet Version 1.7"><LINK
9e4b25fc3eb5777202147634d789345d893b4539Mark AndrewsREL="HOME"
9e4b25fc3eb5777202147634d789345d893b4539Mark AndrewsTITLE="BIND 9 Administrator Reference Manual"
9e4b25fc3eb5777202147634d789345d893b4539Mark AndrewsHREF="Bv9ARM.html"><LINK
7314547af7aa1dd25d690dd3f034d49e5cc8fa9dMark AndrewsREL="PREVIOUS"
7314547af7aa1dd25d690dd3f034d49e5cc8fa9dMark AndrewsTITLE="Name Server Configuration"
541b9722d8031485922ab11221c2e747c0262cf5Mark AndrewsHREF="Bv9ARM.ch03.html"><LINK
541b9722d8031485922ab11221c2e747c0262cf5Mark AndrewsREL="NEXT"
541b9722d8031485922ab11221c2e747c0262cf5Mark AndrewsTITLE="The BIND 9 Lightweight Resolver"
ddaeaddf2b9148ce3e6ec5fecc48f64ea5826faeMark AndrewsHREF="Bv9ARM.ch05.html"></HEAD
ddaeaddf2b9148ce3e6ec5fecc48f64ea5826faeMark Andrews><BODY
ddaeaddf2b9148ce3e6ec5fecc48f64ea5826faeMark AndrewsCLASS="chapter"
a6f7fdcc039de75e9a20da90044caa814f0357a3Michael GraffBGCOLOR="#FFFFFF"
a6f7fdcc039de75e9a20da90044caa814f0357a3Michael GraffTEXT="#000000"
d7e8610d31d83ff863e8b2dc05c238376c35e949Mark AndrewsLINK="#0000FF"
d7e8610d31d83ff863e8b2dc05c238376c35e949Mark AndrewsVLINK="#840084"
d7e8610d31d83ff863e8b2dc05c238376c35e949Mark AndrewsALINK="#0000FF"
7e8214191899dc8043babdfbe9235ba14c825005Mark Andrews><DIV
7e8214191899dc8043babdfbe9235ba14c825005Mark AndrewsCLASS="NAVHEADER"
c4dc5966e0a66f4d75677f1634eff3b45baf988eMark Andrews><TABLE
c4dc5966e0a66f4d75677f1634eff3b45baf988eMark AndrewsSUMMARY="Header navigation table"
c4dc5966e0a66f4d75677f1634eff3b45baf988eMark AndrewsWIDTH="100%"
9429f5a8318bd2142280c949d4af05998ca348a2Evan HuntBORDER="0"
9429f5a8318bd2142280c949d4af05998ca348a2Evan HuntCELLPADDING="0"
0899d16ebd6a70bb027e7899c53e7f542ebc987bEvan HuntCELLSPACING="0"
0899d16ebd6a70bb027e7899c53e7f542ebc987bEvan Hunt><TR
0899d16ebd6a70bb027e7899c53e7f542ebc987bEvan Hunt><TH
0899d16ebd6a70bb027e7899c53e7f542ebc987bEvan HuntCOLSPAN="3"
d2e440ca30f27468443ccc7e21db0b8e10c4faf8Mark AndrewsALIGN="center"
d2e440ca30f27468443ccc7e21db0b8e10c4faf8Mark Andrews>BIND 9 Administrator Reference Manual</TH
d2e440ca30f27468443ccc7e21db0b8e10c4faf8Mark Andrews></TR
404df30f4fcbd318dd1e3cc027d2b5abff3ab6d5Mark Andrews><TR
404df30f4fcbd318dd1e3cc027d2b5abff3ab6d5Mark Andrews><TD
404df30f4fcbd318dd1e3cc027d2b5abff3ab6d5Mark AndrewsWIDTH="10%"
544d0efa38490d67e458aa9c23a7dac2a9d546bfMark AndrewsALIGN="left"
544d0efa38490d67e458aa9c23a7dac2a9d546bfMark AndrewsVALIGN="bottom"
1f2635d3f7b3f0b3bf0d0310fe880d95e84f09fcMark Andrews><A
1f2635d3f7b3f0b3bf0d0310fe880d95e84f09fcMark AndrewsHREF="Bv9ARM.ch03.html"
1f2635d3f7b3f0b3bf0d0310fe880d95e84f09fcMark AndrewsACCESSKEY="P"
802760773ca5224b29a610741a7f2e0a7d6e031bMark Andrews>Prev</A
802760773ca5224b29a610741a7f2e0a7d6e031bMark Andrews></TD
802760773ca5224b29a610741a7f2e0a7d6e031bMark Andrews><TD
b6d496d53851e5ab5ba82e800062a431b05310cbEvan HuntWIDTH="80%"
b6d496d53851e5ab5ba82e800062a431b05310cbEvan HuntALIGN="center"
67213ca3d0594588a6fac32d8188efc68b0ad572Shane KerrVALIGN="bottom"
d55494b8e9887e7ff7cdf1ec96a9dc5e8afe3c94Shane Kerr></TD
d813808a01d5629110b8df483ccc2dff9ec2a84fMark Andrews><TD
67213ca3d0594588a6fac32d8188efc68b0ad572Shane KerrWIDTH="10%"
67213ca3d0594588a6fac32d8188efc68b0ad572Shane KerrALIGN="right"
d813808a01d5629110b8df483ccc2dff9ec2a84fMark AndrewsVALIGN="bottom"
d813808a01d5629110b8df483ccc2dff9ec2a84fMark Andrews><A
33170a4b2b2765583df543efbb13a01e7b664037Mark AndrewsHREF="Bv9ARM.ch05.html"
33170a4b2b2765583df543efbb13a01e7b664037Mark AndrewsACCESSKEY="N"
33170a4b2b2765583df543efbb13a01e7b664037Mark Andrews>Next</A
2cc262c0932a193b261e6e6a172855bd8f898c6dMark Andrews></TD
2cc262c0932a193b261e6e6a172855bd8f898c6dMark Andrews></TR
2cc262c0932a193b261e6e6a172855bd8f898c6dMark Andrews></TABLE
76a378884f628f9b23bff16490e39dcd69b6ef0eMark Andrews><HR
76a378884f628f9b23bff16490e39dcd69b6ef0eMark AndrewsALIGN="LEFT"
76a378884f628f9b23bff16490e39dcd69b6ef0eMark AndrewsWIDTH="100%"></DIV
03745451370778a867e46fdbe315eb958745a391Mark Andrews><DIV
03745451370778a867e46fdbe315eb958745a391Mark AndrewsCLASS="chapter"
f183f4c0cd40354f423bdb129e7a0c9badb5082cMark Andrews><H1
f183f4c0cd40354f423bdb129e7a0c9badb5082cMark Andrews><A
f183f4c0cd40354f423bdb129e7a0c9badb5082cMark AndrewsNAME="ch04"
f183f4c0cd40354f423bdb129e7a0c9badb5082cMark Andrews></A
f183f4c0cd40354f423bdb129e7a0c9badb5082cMark Andrews>Chapter 4. Advanced DNS Features</H1
e9908a145e763591bb407a4cd3d2062c7bc94cd8Mark Andrews><DIV
71f4918fd8a5ec4f0a05aac657b614fdf2467bebMark AndrewsCLASS="TOC"
71f4918fd8a5ec4f0a05aac657b614fdf2467bebMark Andrews><DL
873a2046fb73aee49934d7978efe3da6509faed3Evan Hunt><DT
dabe7f50bb61d75841b535b91edb8f323f82f826Evan Hunt><B
a1e2170ad5c5018fbe8f7b8449d8885d5d298e88Mark Andrews>Table of Contents</B
a1e2170ad5c5018fbe8f7b8449d8885d5d298e88Mark Andrews></DT
a1e2170ad5c5018fbe8f7b8449d8885d5d298e88Mark Andrews><DT
a1e2170ad5c5018fbe8f7b8449d8885d5d298e88Mark Andrews>4.1. <A
a1e2170ad5c5018fbe8f7b8449d8885d5d298e88Mark AndrewsHREF="Bv9ARM.ch04.html#notify"
a1e2170ad5c5018fbe8f7b8449d8885d5d298e88Mark Andrews>Notify</A
a1e2170ad5c5018fbe8f7b8449d8885d5d298e88Mark Andrews></DT
05d2776f6fa8e3628555463b06cb43288c9ee68eEvan Hunt><DT
05d2776f6fa8e3628555463b06cb43288c9ee68eEvan Hunt>4.2. <A
05d2776f6fa8e3628555463b06cb43288c9ee68eEvan HuntHREF="Bv9ARM.ch04.html#dynamic_update"
8327cdb88fdbf306eb4c37fe00a29aac4c2f55c5Evan Hunt>Dynamic Update</A
8327cdb88fdbf306eb4c37fe00a29aac4c2f55c5Evan Hunt></DT
f2d8c4a4c3dfa212ddcf5b86d4c5fced4965e52eMark Andrews><DT
f2d8c4a4c3dfa212ddcf5b86d4c5fced4965e52eMark Andrews>4.3. <A
8c76634f88c5b3169b61505925e10b997ea08e54Mark AndrewsHREF="Bv9ARM.ch04.html#incremental_zone_transfers"
8c76634f88c5b3169b61505925e10b997ea08e54Mark Andrews>Incremental Zone Transfers (IXFR)</A
8c76634f88c5b3169b61505925e10b997ea08e54Mark Andrews></DT
8bedd9647f4d6894e12a8c94d3ccc624dddcee50Mark Andrews><DT
8bedd9647f4d6894e12a8c94d3ccc624dddcee50Mark Andrews>4.4. <A
8bedd9647f4d6894e12a8c94d3ccc624dddcee50Mark AndrewsHREF="Bv9ARM.ch04.html#AEN767"
ca84283333d22c64abfbcb87872dd5e6d9172c5aMark Andrews>Split DNS</A
ca84283333d22c64abfbcb87872dd5e6d9172c5aMark Andrews></DT
ca84283333d22c64abfbcb87872dd5e6d9172c5aMark Andrews><DT
ca84283333d22c64abfbcb87872dd5e6d9172c5aMark Andrews>4.5. <A
e6555b046798b1900e93c3208d26301872f50ca5Shane KerrHREF="Bv9ARM.ch04.html#tsig"
e6555b046798b1900e93c3208d26301872f50ca5Shane Kerr>TSIG</A
e6555b046798b1900e93c3208d26301872f50ca5Shane Kerr></DT
9a41f786b167a2a6df498d5e9c699f9835e1e9dcMark Andrews><DT
9a41f786b167a2a6df498d5e9c699f9835e1e9dcMark Andrews>4.6. <A
9a41f786b167a2a6df498d5e9c699f9835e1e9dcMark AndrewsHREF="Bv9ARM.ch04.html#AEN927"
9a41f786b167a2a6df498d5e9c699f9835e1e9dcMark Andrews>TKEY</A
bf98702c1941f368e54c499dd1ff59ee684cf125Mark Andrews></DT
bf98702c1941f368e54c499dd1ff59ee684cf125Mark Andrews><DT
bf98702c1941f368e54c499dd1ff59ee684cf125Mark Andrews>4.7. <A
bf98702c1941f368e54c499dd1ff59ee684cf125Mark AndrewsHREF="Bv9ARM.ch04.html#AEN942"
bf98702c1941f368e54c499dd1ff59ee684cf125Mark Andrews>SIG(0)</A
bf98702c1941f368e54c499dd1ff59ee684cf125Mark Andrews></DT
bf98702c1941f368e54c499dd1ff59ee684cf125Mark Andrews><DT
bf98702c1941f368e54c499dd1ff59ee684cf125Mark Andrews>4.8. <A
65391557db5d7dc725ed3f2b759248fea31a2445Mark AndrewsHREF="Bv9ARM.ch04.html#DNSSEC"
65391557db5d7dc725ed3f2b759248fea31a2445Mark Andrews>DNSSEC</A
e2c3f8059e77a8e11c4378d22e5d8e78b423a28fMark Andrews></DT
e2c3f8059e77a8e11c4378d22e5d8e78b423a28fMark Andrews><DT
e2c3f8059e77a8e11c4378d22e5d8e78b423a28fMark Andrews>4.9. <A
a7b7a4ebc38ec7460e95da6d3d70ffe7b59573b8Mark AndrewsHREF="Bv9ARM.ch04.html#AEN1011"
a7b7a4ebc38ec7460e95da6d3d70ffe7b59573b8Mark Andrews>IPv6 Support in <ACRONYM
1ca168b58e02fda534cad741a248e549e0f98d4dMark AndrewsCLASS="acronym"
6f1b09965f26ab0d6c38dec4a38f67bb34ebddceMark Andrews>BIND</ACRONYM
23450c23fd19138cfad95b6c7728e2965abfc154Mark Andrews> 9</A
de05f7d061abfe0ce555e0d0f2089f1261b031b6Mark Andrews></DT
de05f7d061abfe0ce555e0d0f2089f1261b031b6Mark Andrews></DL
d468b1b7b2ccfdf132df15f600be48dccf447eb1Evan Hunt></DIV
d468b1b7b2ccfdf132df15f600be48dccf447eb1Evan Hunt><DIV
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan HuntCLASS="sect1"
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt><H1
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan HuntCLASS="sect1"
c7e266b7e5675e12d1ca3cc929f24b3e86d41f8eEvan Hunt><A
85db2b5fb360ccd2aeec1e6e22336b3d654bb39aMark AndrewsNAME="notify"
85db2b5fb360ccd2aeec1e6e22336b3d654bb39aMark Andrews>4.1. Notify</A
85db2b5fb360ccd2aeec1e6e22336b3d654bb39aMark Andrews></H1
a0749e59c0356381fdaea0fefe66256589ec8c99Mark Andrews><P
a0749e59c0356381fdaea0fefe66256589ec8c99Mark Andrews><ACRONYM
a0749e59c0356381fdaea0fefe66256589ec8c99Mark AndrewsCLASS="acronym"
709220567fb820cf7e7625925449dadf86317629Mark Andrews>DNS</ACRONYM
709220567fb820cf7e7625925449dadf86317629Mark Andrews> NOTIFY is a mechanism that allows master
709220567fb820cf7e7625925449dadf86317629Mark Andrewsservers to notify their slave servers of changes to a zone's data. In
fe6b6eebd74f7c5c20088f67081ae690228f9744Mark Andrewsresponse to a <B
adc3f2c0fdcc0a2bee469ffb0e7ae41b83cbf403Mark AndrewsCLASS="command"
adc3f2c0fdcc0a2bee469ffb0e7ae41b83cbf403Mark Andrews>NOTIFY</B
31a2f82193a91e24f31454ff18e0b7723c066a74Mark Andrews> from a master server, the
45deeddf4cf1ea57b8b493dcd2410f2332a36128Mark Andrewsslave will check to see that its version of the zone is the
8731a2bd2f5483f50d82cf28e315090b7ceeed54Mark Andrewscurrent version and, if not, initiate a zone transfer.</P
8731a2bd2f5483f50d82cf28e315090b7ceeed54Mark Andrews><P
2de90cd1e20061bde684a21c3d852056a2e290d0Mark Andrews><ACRONYM
2de90cd1e20061bde684a21c3d852056a2e290d0Mark AndrewsCLASS="acronym"
8a45eeebb8bdd4633bccfd9d77d9b50c1d337d54Mark Andrews>DNS</ACRONYM
8a45eeebb8bdd4633bccfd9d77d9b50c1d337d54Mark Andrews>
8a45eeebb8bdd4633bccfd9d77d9b50c1d337d54Mark AndrewsFor more information about
d4034b48fd112ef43933f1455b194b5249a88ee6Mark Andrews<B
d4034b48fd112ef43933f1455b194b5249a88ee6Mark AndrewsCLASS="command"
d4034b48fd112ef43933f1455b194b5249a88ee6Mark Andrews>NOTIFY</B
d4034b48fd112ef43933f1455b194b5249a88ee6Mark Andrews>, see the description of the
d4034b48fd112ef43933f1455b194b5249a88ee6Mark Andrews<B
ee4bbc8454cc0cb36a25a7d26c5b47370f96d9b2Mark AndrewsCLASS="command"
ee4bbc8454cc0cb36a25a7d26c5b47370f96d9b2Mark Andrews>notify</B
ee4bbc8454cc0cb36a25a7d26c5b47370f96d9b2Mark Andrews> option in <A
f568dad6c7ddaa732e6562a4b89fd2ac922d263bMark AndrewsHREF="Bv9ARM.ch06.html#boolean_options"
03ec481ee88f4ab72af6abb4efe096fe2c661d60Mark Andrews>Section 6.2.16.1</A
03ec481ee88f4ab72af6abb4efe096fe2c661d60Mark Andrews> and
03ec481ee88f4ab72af6abb4efe096fe2c661d60Mark Andrewsthe description of the zone option <B
f568dad6c7ddaa732e6562a4b89fd2ac922d263bMark AndrewsCLASS="command"
8e74bfb6045d78af71b54a2934823b334b3e423aMark Andrews>also-notify</B
8e74bfb6045d78af71b54a2934823b334b3e423aMark Andrews> in
8e74bfb6045d78af71b54a2934823b334b3e423aMark Andrews<A
d91df50b670d92d0ab784b741e2ee9af7f2dc4a1Mark AndrewsHREF="Bv9ARM.ch06.html#zone_transfers"
88a4de3c24caf71426bf06e42ce18f6099d7a439Mark Andrews>Section 6.2.16.7</A
d91df50b670d92d0ab784b741e2ee9af7f2dc4a1Mark Andrews>. The <B
3eab85ca54b681504d772b1d6bb3ccf4f08d4305Mark AndrewsCLASS="command"
3eab85ca54b681504d772b1d6bb3ccf4f08d4305Mark Andrews>NOTIFY</B
3eab85ca54b681504d772b1d6bb3ccf4f08d4305Mark Andrews>
c5adbd722da0908f91be4fb710c082b4b68ec782Mark Andrewsprotocol is specified in RFC 1996.
c5adbd722da0908f91be4fb710c082b4b68ec782Mark Andrews</P
557bcc2092642b2d4668c9b08872c9f2bb88bddbMark Andrews></DIV
557bcc2092642b2d4668c9b08872c9f2bb88bddbMark Andrews><DIV
557bcc2092642b2d4668c9b08872c9f2bb88bddbMark AndrewsCLASS="sect1"
c60eaaf9b3c6bb4d693cdb5f68acdfacf076e1fdMark Andrews><H1
c60eaaf9b3c6bb4d693cdb5f68acdfacf076e1fdMark AndrewsCLASS="sect1"
634a4da58460979fa0fcad5304b810d189f9cf49Mark Andrews><A
634a4da58460979fa0fcad5304b810d189f9cf49Mark AndrewsNAME="dynamic_update"
634a4da58460979fa0fcad5304b810d189f9cf49Mark Andrews>4.2. Dynamic Update</A
634a4da58460979fa0fcad5304b810d189f9cf49Mark Andrews></H1
c0720b90ed6e673264b17eb752d873a89cbd6db5Mark Andrews><P
c0720b90ed6e673264b17eb752d873a89cbd6db5Mark Andrews>Dynamic Update is a method for adding, replacing or deleting
c0720b90ed6e673264b17eb752d873a89cbd6db5Mark Andrews records in a master server by sending it a special form of DNS
576e48e28aae9f28b8e6daa2aabc839bb5c520e3Mark Andrews messages. The format and meaning of these messages is specified
c06cb907737eb7ce128c92dd729c73798733f37aMark Andrews in RFC 2136.</P
c06cb907737eb7ce128c92dd729c73798733f37aMark Andrews><P
6e5e27c38d86f2338688f5123d2ff84558956dd0Mark Andrews>Dynamic update is enabled on a zone-by-zone basis, by
6e5e27c38d86f2338688f5123d2ff84558956dd0Mark Andrews including an <B
6e5e27c38d86f2338688f5123d2ff84558956dd0Mark AndrewsCLASS="command"
5059b393e80cda6beffb74f2f30d7329502c41e6Mark Andrews>allow-update</B
5059b393e80cda6beffb74f2f30d7329502c41e6Mark Andrews> or
5059b393e80cda6beffb74f2f30d7329502c41e6Mark Andrews <B
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark AndrewsCLASS="command"
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews>update-policy</B
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews> clause in the
c16aed9c469a986f1b84e457db4a8c4d2da01ca3Mark Andrews <B
dd19fbaf817f974c24ddfa1d276d7594d5b18750Mark AndrewsCLASS="command"
dd19fbaf817f974c24ddfa1d276d7594d5b18750Mark Andrews>zone</B
dd19fbaf817f974c24ddfa1d276d7594d5b18750Mark Andrews> statement.</P
f408773d47b25594d1302525a4db6efb84b1843cMark Andrews><P
f408773d47b25594d1302525a4db6efb84b1843cMark Andrews>Updating of secure zones (zones using DNSSEC) follows
cd315d4cf631753c94f27fabaa42a37a27d30530Mark Andrews RFC 3007: RRSIG and NSEC records affected by updates are automatically
cd315d4cf631753c94f27fabaa42a37a27d30530Mark Andrews regenerated by the server using an online zone key.
cd315d4cf631753c94f27fabaa42a37a27d30530Mark Andrews Update authorization is based
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews on transaction signatures and an explicit server policy.</P
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews><DIV
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark AndrewsCLASS="sect2"
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews><H2
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark AndrewsCLASS="sect2"
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews><A
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark AndrewsNAME="journal"
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews>4.2.1. The journal file</A
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews></H2
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews><P
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews>All changes made to a zone using dynamic update are stored
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews in the zone's journal file. This file is automatically created
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews by the server when when the first dynamic update takes place.
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews The name of the journal file is formed by appending the extension
69826a6a2f89ecb2b280eeb6d4adb4826bf0db72Mark Andrews <TT
5888f62c204a99da60d7854fe01eda4960fb3b36Mark AndrewsCLASS="filename"
5888f62c204a99da60d7854fe01eda4960fb3b36Mark Andrews>.jnl</TT
57668dc1bb0eb063e9037ff07ddbfd520e0d7186Mark Andrews> to the name of the corresponding zone
fd23bc509d5fddb91247a2a1ca52d432969067e5Mark Andrews file unless specifically overridden. The journal file is in a
7c200913aa7e55bbe28de456bb593c1e05bf6f79Mark Andrews binary format and should not be edited manually.</P
07072c9456f1112705db701bb35f12dbdcb217b0Mark Andrews><P
07072c9456f1112705db701bb35f12dbdcb217b0Mark Andrews>The server will also occasionally write ("dump")
07072c9456f1112705db701bb35f12dbdcb217b0Mark Andrews the complete contents of the updated zone to its zone file.
afd002e89aadf30181155566544480349e70339dMark Andrews This is not done immediately after
afd002e89aadf30181155566544480349e70339dMark Andrews each dynamic update, because that would be too slow when a large
afd002e89aadf30181155566544480349e70339dMark Andrews zone is updated frequently. Instead, the dump is delayed by
7b52c2ad3c9ca65712e962ddc803e34641f2bc07Mark Andrews up to 15 minutes, allowing additional updates to take place.</P
ba5d2a97ee0cd2cc9d4b9e7e344ae8f607cc2994Mark Andrews><P
ba5d2a97ee0cd2cc9d4b9e7e344ae8f607cc2994Mark Andrews>When a server is restarted after a shutdown or crash, it will replay
6133734cecb05630e32edb63031b95d333df8e48Mark Andrews the journal file to incorporate into the zone any updates that took
6133734cecb05630e32edb63031b95d333df8e48Mark Andrews place after the last zone dump.</P
6133734cecb05630e32edb63031b95d333df8e48Mark Andrews><P
47ee25b1f58a5924c51b59194b84621b9b7b6ba5Mark Andrews>Changes that result from incoming incremental zone transfers are also
47ee25b1f58a5924c51b59194b84621b9b7b6ba5Mark Andrews journalled in a similar way.</P
47ee25b1f58a5924c51b59194b84621b9b7b6ba5Mark Andrews><P
32391301db6f532ad17033f188d4540ae3f409f1Mark Andrews>The zone files of dynamic zones cannot normally be edited by
32391301db6f532ad17033f188d4540ae3f409f1Mark Andrews hand because they are not guaranteed to contain the most recent
32391301db6f532ad17033f188d4540ae3f409f1Mark Andrews dynamic changes - those are only in the journal file.
0cedbe4ab56e00d5827941697418476318cbdeb3Mark Andrews The only way to ensure that the zone file of a dynamic zone
0cedbe4ab56e00d5827941697418476318cbdeb3Mark Andrews is up to date is to run <B
0cedbe4ab56e00d5827941697418476318cbdeb3Mark AndrewsCLASS="command"
0cedbe4ab56e00d5827941697418476318cbdeb3Mark Andrews>rndc stop</B
f05a4bf2bfac3aaff0462560b2793cd99a85a297Mark Andrews>.</P
0cedbe4ab56e00d5827941697418476318cbdeb3Mark Andrews><P
f05a4bf2bfac3aaff0462560b2793cd99a85a297Mark Andrews>If you have to make changes to a dynamic zone
bf45f72ed319628eebce60c368177320943d001fMark Andrews manually, the following procedure will work: Disable dynamic updates
bf45f72ed319628eebce60c368177320943d001fMark Andrews to the zone using
bf45f72ed319628eebce60c368177320943d001fMark Andrews <B
e078f002c06b6b26e2d7749a4f9e3907f3e85de3Mark AndrewsCLASS="command"
af1e00675fa573fec779e9a01aac5bedb99f0fd6Mark Andrews>rndc freeze <VAR
af1e00675fa573fec779e9a01aac5bedb99f0fd6Mark AndrewsCLASS="replaceable"
af1e00675fa573fec779e9a01aac5bedb99f0fd6Mark Andrews>zone</VAR
d1199d9c06ba470fa4779981bea2f8f7403e8eabMark Andrews></B
d1199d9c06ba470fa4779981bea2f8f7403e8eabMark Andrews>.
d1199d9c06ba470fa4779981bea2f8f7403e8eabMark Andrews This will also remove the zone's <TT
7c5dfcc60a7ee41ae5ba15a3e1fe337af3bef1a9Mark AndrewsCLASS="filename"
7c5dfcc60a7ee41ae5ba15a3e1fe337af3bef1a9Mark Andrews>.jnl</TT
7c5dfcc60a7ee41ae5ba15a3e1fe337af3bef1a9Mark Andrews> file
7c5dfcc60a7ee41ae5ba15a3e1fe337af3bef1a9Mark Andrews and update the master file. Edit the zone file. Run
0f8c9b5eed7e8714ceb7d6d3675555df9c5f6350Mark Andrews <B
0f8c9b5eed7e8714ceb7d6d3675555df9c5f6350Mark AndrewsCLASS="command"
0f8c9b5eed7e8714ceb7d6d3675555df9c5f6350Mark Andrews>rndc unfreeze <VAR
fc8197c3ce31d81cd5e23703680572fac09a2e8aMark AndrewsCLASS="replaceable"
0f8c9b5eed7e8714ceb7d6d3675555df9c5f6350Mark Andrews>zone</VAR
0f8c9b5eed7e8714ceb7d6d3675555df9c5f6350Mark Andrews></B
0f8c9b5eed7e8714ceb7d6d3675555df9c5f6350Mark Andrews>
bc6af069c80ca33a5619d71d57859724cab1f4c4Mark Andrews to reload the changed zone and re-enable dynamic updates.</P
bc6af069c80ca33a5619d71d57859724cab1f4c4Mark Andrews></DIV
bc6af069c80ca33a5619d71d57859724cab1f4c4Mark Andrews></DIV
bc6af069c80ca33a5619d71d57859724cab1f4c4Mark Andrews><DIV
4bb0f1046f3f3c26539ff91e28b3c8872519df17Mark AndrewsCLASS="sect1"
4bb0f1046f3f3c26539ff91e28b3c8872519df17Mark Andrews><H1
68df4d65c624a9ca06e94fc67ef915adf2ec97beMark AndrewsCLASS="sect1"
ab6e5af4cd644b174709f95c2702ec4c442aa755Mark Andrews><A
ab6e5af4cd644b174709f95c2702ec4c442aa755Mark AndrewsNAME="incremental_zone_transfers"
f3139b9d763cbfd3f8dbf1062191a688ed5195e4Mark Andrews>4.3. Incremental Zone Transfers (IXFR)</A
f3139b9d763cbfd3f8dbf1062191a688ed5195e4Mark Andrews></H1
f3139b9d763cbfd3f8dbf1062191a688ed5195e4Mark Andrews><P
f3139b9d763cbfd3f8dbf1062191a688ed5195e4Mark Andrews>The incremental zone transfer (IXFR) protocol is a way for
79e3817e2c0f1b017643638dc3876ba41da94335Mark Andrewsslave servers to transfer only changed data, instead of having to
79e3817e2c0f1b017643638dc3876ba41da94335Mark Andrewstransfer the entire zone. The IXFR protocol is specified in RFC
79e3817e2c0f1b017643638dc3876ba41da94335Mark Andrews1995. See <A
2d78cc9624dd735ffdc634e6c39dd30bddfb95f7Mark AndrewsHREF="Bv9ARM.ch09.html#proposed_standards"
2d78cc9624dd735ffdc634e6c39dd30bddfb95f7Mark Andrews>Proposed Standards</A
2d78cc9624dd735ffdc634e6c39dd30bddfb95f7Mark Andrews>.</P
eea8cd8d1a9b2762480fab793972d1cefbc7cf90Mark Andrews><P
eea8cd8d1a9b2762480fab793972d1cefbc7cf90Mark Andrews>When acting as a master, <ACRONYM
eea8cd8d1a9b2762480fab793972d1cefbc7cf90Mark AndrewsCLASS="acronym"
9860862cedd41ffaf69e7806e8f8959263552721Mark Andrews>BIND</ACRONYM
9860862cedd41ffaf69e7806e8f8959263552721Mark Andrews> 9
9860862cedd41ffaf69e7806e8f8959263552721Mark Andrewssupports IXFR for those zones
25e2824175eb0c186df3ab0737c83d322410594cMark Andrewswhere the necessary change history information is available. These
25e2824175eb0c186df3ab0737c83d322410594cMark Andrewsinclude master zones maintained by dynamic update and slave zones
25e2824175eb0c186df3ab0737c83d322410594cMark Andrewswhose data was obtained by IXFR. For manually maintained master
25e2824175eb0c186df3ab0737c83d322410594cMark Andrewszones, and for slave zones obtained by performing a full zone
63aaac8137bd1d86aab8c950fb066bb522a26e5bMark Andrewstransfer (AXFR), IXFR is supported only if the option
63aaac8137bd1d86aab8c950fb066bb522a26e5bMark Andrews<B
fe3220466e3c23cd2c22a59a4db46bc97ce0827dMark AndrewsCLASS="command"
fe3220466e3c23cd2c22a59a4db46bc97ce0827dMark Andrews>ixfr-from-differences</B
fe3220466e3c23cd2c22a59a4db46bc97ce0827dMark Andrews> is set
40aadb6a143e0f2d351e743dce43cfc894d4d855Mark Andrewsto <KBD
40aadb6a143e0f2d351e743dce43cfc894d4d855Mark AndrewsCLASS="userinput"
40aadb6a143e0f2d351e743dce43cfc894d4d855Mark Andrews>yes</KBD
65b26a4dc8c6c16d0a5ccb03b67cf968c77d6570Mark Andrews>.
65b26a4dc8c6c16d0a5ccb03b67cf968c77d6570Mark Andrews</P
65b26a4dc8c6c16d0a5ccb03b67cf968c77d6570Mark Andrews><P
c58821f7100821e1d4e4bbace727b988bb3e0623Mark Andrews>When acting as a slave, <ACRONYM
c58821f7100821e1d4e4bbace727b988bb3e0623Mark AndrewsCLASS="acronym"
77397daf05511dc737eeec159badc05f11bfadddMark Andrews>BIND</ACRONYM
337e70ead93aafec305ac0a7a62090339543b8d1Mark Andrews> 9 will
337e70ead93aafec305ac0a7a62090339543b8d1Mark Andrewsattempt to use IXFR unless
337e70ead93aafec305ac0a7a62090339543b8d1Mark Andrewsit is explicitly disabled. For more information about disabling
f0a1b8c85792d4e04716f995a2b2a8ca73f8367dMark AndrewsIXFR, see the description of the <B
a5d7c242b564cbd3cebc0dd27c19d9093d38b3abMark AndrewsCLASS="command"
a5d7c242b564cbd3cebc0dd27c19d9093d38b3abMark Andrews>request-ixfr</B
1de5f8f80930dc322688010740c7dfe56eb035b0Mark Andrews> clause
1de5f8f80930dc322688010740c7dfe56eb035b0Mark Andrewsof the <B
1de5f8f80930dc322688010740c7dfe56eb035b0Mark AndrewsCLASS="command"
7a253b705ccbc30821253e7a124658623f10c499Mark Andrews>server</B
7a253b705ccbc30821253e7a124658623f10c499Mark Andrews> statement.</P
f6476fa52240e3c8278ac4a27fa2cc8a5b7a3e3bMark Andrews></DIV
f6476fa52240e3c8278ac4a27fa2cc8a5b7a3e3bMark Andrews><DIV
f6476fa52240e3c8278ac4a27fa2cc8a5b7a3e3bMark AndrewsCLASS="sect1"
cd1e58c339b2a6709d543a525de0c995bf8b5868Mark Andrews><H1
cd1e58c339b2a6709d543a525de0c995bf8b5868Mark AndrewsCLASS="sect1"
cd1e58c339b2a6709d543a525de0c995bf8b5868Mark Andrews><A
a05f23d07e1b60a1d88119678111a47014480611Mark AndrewsNAME="AEN767"
a05f23d07e1b60a1d88119678111a47014480611Mark Andrews>4.4. Split DNS</A
a05f23d07e1b60a1d88119678111a47014480611Mark Andrews></H1
a05f23d07e1b60a1d88119678111a47014480611Mark Andrews><P
429e23d2f56d28d86439f75c13cda2b4ac5ab67bMark Andrews>Setting up different views, or visibility, of the DNS space to
429e23d2f56d28d86439f75c13cda2b4ac5ab67bMark Andrewsinternal and external resolvers is usually referred to as a <SPAN
c5c825bf07a00a2478afd9400e9f8534457980b0Mark AndrewsCLASS="emphasis"
c5c825bf07a00a2478afd9400e9f8534457980b0Mark Andrews><I
c5c825bf07a00a2478afd9400e9f8534457980b0Mark AndrewsCLASS="emphasis"
aaa42824d2d1f5cc4add01f0191e3784ee0f7396Mark Andrews>Split
43da7565913277c020ded34d6ee2139998b743b6Mark AndrewsDNS</I
43da7565913277c020ded34d6ee2139998b743b6Mark Andrews></SPAN
43da7565913277c020ded34d6ee2139998b743b6Mark Andrews> setup. There are several reasons an organization
c1297b6025bf8ccdc832b7bca705da1d4cf2944eMark Andrewswould want to set up its DNS this way.</P
c1297b6025bf8ccdc832b7bca705da1d4cf2944eMark Andrews><P
25820cf1d110ec22cec5f6be5257aabe6853ca92Evan Hunt>One common reason for setting up a DNS system this way is
25820cf1d110ec22cec5f6be5257aabe6853ca92Evan Huntto hide "internal" DNS information from "external" clients on the
25820cf1d110ec22cec5f6be5257aabe6853ca92Evan HuntInternet. There is some debate as to whether or not this is actually useful.
99cce386a489671727a737b3748937cf3a0676e8Evan HuntInternal DNS information leaks out in many ways (via email headers,
99cce386a489671727a737b3748937cf3a0676e8Evan Huntfor example) and most savvy "attackers" can find the information
99cce386a489671727a737b3748937cf3a0676e8Evan Huntthey need using other means.</P
99cce386a489671727a737b3748937cf3a0676e8Evan Hunt><P
819b98479eff49ed93f57f4d65eb0ffe72136adcMark Andrews>Another common reason for setting up a Split DNS system is
819b98479eff49ed93f57f4d65eb0ffe72136adcMark Andrewsto allow internal networks that are behind filters or in RFC 1918
819b98479eff49ed93f57f4d65eb0ffe72136adcMark Andrewsspace (reserved IP space, as documented in RFC 1918) to resolve DNS
819b98479eff49ed93f57f4d65eb0ffe72136adcMark Andrewson the Internet. Split DNS can also be used to allow mail from outside
819b98479eff49ed93f57f4d65eb0ffe72136adcMark Andrewsback in to the internal network.</P
113e0b7819103f02d5a16bad1b7356587d866ac2Mark Andrews><P
113e0b7819103f02d5a16bad1b7356587d866ac2Mark Andrews>Here is an example of a split DNS setup:</P
113e0b7819103f02d5a16bad1b7356587d866ac2Mark Andrews><P
113e0b7819103f02d5a16bad1b7356587d866ac2Mark Andrews>Let's say a company named <SPAN
6dfc78fab61fafc9bffdc3cbc331cc996bfa2198Mark AndrewsCLASS="emphasis"
6dfc78fab61fafc9bffdc3cbc331cc996bfa2198Mark Andrews><I
6dfc78fab61fafc9bffdc3cbc331cc996bfa2198Mark AndrewsCLASS="emphasis"
6dfc78fab61fafc9bffdc3cbc331cc996bfa2198Mark Andrews>Example, Inc.</I
65085946d4f92481699678e276e3ced04bcfdafbMark Andrews></SPAN
65085946d4f92481699678e276e3ced04bcfdafbMark Andrews>
65085946d4f92481699678e276e3ced04bcfdafbMark Andrews(<VAR
b5f690e1618cffeec15b3bcb9525443206fb7007Mark AndrewsCLASS="literal"
b5f690e1618cffeec15b3bcb9525443206fb7007Mark Andrews>example.com</VAR
b5f690e1618cffeec15b3bcb9525443206fb7007Mark Andrews>)
37d373d88631c7be57a30bf4a49c824a9195781fMark Andrewshas several corporate sites that have an internal network with reserved
37d373d88631c7be57a30bf4a49c824a9195781fMark AndrewsInternet Protocol (IP) space and an external demilitarized zone (DMZ),
37d373d88631c7be57a30bf4a49c824a9195781fMark Andrewsor "outside" section of a network, that is available to the public.</P
b130bf8b4ebdabd5c94eb5c6522a9971997b6ac9Mark Andrews><P
b130bf8b4ebdabd5c94eb5c6522a9971997b6ac9Mark Andrews><SPAN
072eaf055b7fa0d8abe96146fbb9152b14946c84Mark AndrewsCLASS="emphasis"
072eaf055b7fa0d8abe96146fbb9152b14946c84Mark Andrews><I
7a3c2d189e811933c48aace1900a868dffd42f5fMark AndrewsCLASS="emphasis"
7a3c2d189e811933c48aace1900a868dffd42f5fMark Andrews>Example, Inc.</I
7a3c2d189e811933c48aace1900a868dffd42f5fMark Andrews></SPAN
a56f5ada432128085e4a06815328023ee0c9610dMark Andrews> wants its internal clients
a56f5ada432128085e4a06815328023ee0c9610dMark Andrewsto be able to resolve external hostnames and to exchange mail with
a56f5ada432128085e4a06815328023ee0c9610dMark Andrewspeople on the outside. The company also wants its internal resolvers
a56f5ada432128085e4a06815328023ee0c9610dMark Andrewsto have access to certain internal-only zones that are not available
a56f5ada432128085e4a06815328023ee0c9610dMark Andrewsat all outside of the internal network.</P
a56f5ada432128085e4a06815328023ee0c9610dMark Andrews><P
a56f5ada432128085e4a06815328023ee0c9610dMark Andrews>In order to accomplish this, the company will set up two sets
a56f5ada432128085e4a06815328023ee0c9610dMark Andrewsof name servers. One set will be on the inside network (in the reserved
4259095c8058beb9b475f1884dbeda375979e6f6Mark AndrewsIP space) and the other set will be on bastion hosts, which are "proxy"
4259095c8058beb9b475f1884dbeda375979e6f6Mark Andrewshosts that can talk to both sides of its network, in the DMZ.</P
4259095c8058beb9b475f1884dbeda375979e6f6Mark Andrews><P
c53a5699c8242636fd913a4d07b4447efebe3bbfMark Andrews>The internal servers will be configured to forward all queries,
c53a5699c8242636fd913a4d07b4447efebe3bbfMark Andrewsexcept queries for <TT
c53a5699c8242636fd913a4d07b4447efebe3bbfMark AndrewsCLASS="filename"
8c731c1219f1698f15bf5b1fcf6bc301cfd9bc42Mark Andrews>site1.internal</TT
8c731c1219f1698f15bf5b1fcf6bc301cfd9bc42Mark Andrews>, <TT
a630d60b8b628cb2ce46b906dc7b1a5b83b74ed5Mark AndrewsCLASS="filename"
a630d60b8b628cb2ce46b906dc7b1a5b83b74ed5Mark Andrews>site2.internal</TT
a630d60b8b628cb2ce46b906dc7b1a5b83b74ed5Mark Andrews>, <TT
b53871d8592a0bfeacdd06ccba46d75aa96e4fecMark AndrewsCLASS="filename"
b53871d8592a0bfeacdd06ccba46d75aa96e4fecMark Andrews>site1.example.com</TT
b53871d8592a0bfeacdd06ccba46d75aa96e4fecMark Andrews>,
9dabd0455ca923b5b02f74c1e999702ddc9c6fd2Mark Andrewsand <TT
9dabd0455ca923b5b02f74c1e999702ddc9c6fd2Mark AndrewsCLASS="filename"
9dabd0455ca923b5b02f74c1e999702ddc9c6fd2Mark Andrews>site2.example.com</TT
9dabd0455ca923b5b02f74c1e999702ddc9c6fd2Mark Andrews>, to the servers in the
58f32ac26ea330054f7b85579cd93a6376168fe7Mark AndrewsDMZ. These internal servers will have complete sets of information
58f32ac26ea330054f7b85579cd93a6376168fe7Mark Andrewsfor <TT
58f32ac26ea330054f7b85579cd93a6376168fe7Mark AndrewsCLASS="filename"
58f32ac26ea330054f7b85579cd93a6376168fe7Mark Andrews>site1.example.com</TT
bde20a0436dff13e2299cfd4230ddec54d396d02Mark Andrews>, <TT
bde20a0436dff13e2299cfd4230ddec54d396d02Mark AndrewsCLASS="filename"
0deee29113e5919c88f341ec3a181b70f7c905ccMark Andrews>site2.example.com</TT
0deee29113e5919c88f341ec3a181b70f7c905ccMark Andrews>,<SPAN
0deee29113e5919c88f341ec3a181b70f7c905ccMark AndrewsCLASS="emphasis"
340a05967aaad53d90694426c33d81b490b0f915Mark Andrews><I
340a05967aaad53d90694426c33d81b490b0f915Mark AndrewsCLASS="emphasis"
340a05967aaad53d90694426c33d81b490b0f915Mark Andrews> </I
394f4aec2189750d7f861d00f97fe28ffcd9f659Mark Andrews></SPAN
394f4aec2189750d7f861d00f97fe28ffcd9f659Mark Andrews><TT
394f4aec2189750d7f861d00f97fe28ffcd9f659Mark AndrewsCLASS="filename"
2e676167cc8cbb2e6dbb54e9859098dd5b9cd5c8Mark Andrews>site1.internal</TT
2e676167cc8cbb2e6dbb54e9859098dd5b9cd5c8Mark Andrews>,
2e676167cc8cbb2e6dbb54e9859098dd5b9cd5c8Mark Andrewsand <TT
4098271a81b3e965da14f77c893232a0b6be22f3Mark AndrewsCLASS="filename"
4098271a81b3e965da14f77c893232a0b6be22f3Mark Andrews>site2.internal</TT
4098271a81b3e965da14f77c893232a0b6be22f3Mark Andrews>.</P
4098271a81b3e965da14f77c893232a0b6be22f3Mark Andrews><P
57eb7efe13b67455e8c6a08cf080afb3de2ac622Mark Andrews>To protect the <TT
7228a4d9ca1f1b868e257a28de86c6a1f21e9ffeMark AndrewsCLASS="filename"
7228a4d9ca1f1b868e257a28de86c6a1f21e9ffeMark Andrews>site1.internal</TT
5dcc67a0fff89e7ebf051f64b6b987862c331a04Mark Andrews> and <TT
5dcc67a0fff89e7ebf051f64b6b987862c331a04Mark AndrewsCLASS="filename"
5dcc67a0fff89e7ebf051f64b6b987862c331a04Mark Andrews>site2.internal</TT
8363ddb32da86811663d12d0b2c61a8ea2fa0eaeMark Andrews> domains,
8363ddb32da86811663d12d0b2c61a8ea2fa0eaeMark Andrewsthe internal name servers must be configured to disallow all queries
8363ddb32da86811663d12d0b2c61a8ea2fa0eaeMark Andrewsto these domains from any external hosts, including the bastion
cc2720da38bb7bab2bf283de56dd90e9093d7f00Mark Andrewshosts.</P
cc2720da38bb7bab2bf283de56dd90e9093d7f00Mark Andrews><P
cc2720da38bb7bab2bf283de56dd90e9093d7f00Mark Andrews>The external servers, which are on the bastion hosts, will
10fc76d48aa7ecb8a7242970585ba154b368f97eMark Andrewsbe configured to serve the "public" version of the <TT
10fc76d48aa7ecb8a7242970585ba154b368f97eMark AndrewsCLASS="filename"
5cc6a0f7dae472e5c2022b2cbb5343ec9f7f4942Mark Andrews>site1</TT
4490e14feb50cd59a62ce9f348ff53b68a0594ebMark Andrews> and <TT
5cc6a0f7dae472e5c2022b2cbb5343ec9f7f4942Mark AndrewsCLASS="filename"
1e70c9a36639bb1e8d537dcefa3cd12a7bb39db0Mark Andrews>site2.example.com</TT
1e70c9a36639bb1e8d537dcefa3cd12a7bb39db0Mark Andrews> zones.
1e70c9a36639bb1e8d537dcefa3cd12a7bb39db0Mark AndrewsThis could include things such as the host records for public servers
9baec3ca233efe8ffca6fbafea5c75021adff03cMark Andrews(<TT
9baec3ca233efe8ffca6fbafea5c75021adff03cMark AndrewsCLASS="filename"
96ea71632887c58a9d00f47eb318bf76b35903c3Mark Andrews>www.example.com</TT
96ea71632887c58a9d00f47eb318bf76b35903c3Mark Andrews> and <TT
f31446e6b5925395fce4f62adf71f7ad70cea6ceMark AndrewsCLASS="filename"
f31446e6b5925395fce4f62adf71f7ad70cea6ceMark Andrews>ftp.example.com</TT
f31446e6b5925395fce4f62adf71f7ad70cea6ceMark Andrews>),
0961ac0868e7d60e7cb665160f6d3717e1da5228Mark Andrewsand mail exchange (MX) records (<TT
0961ac0868e7d60e7cb665160f6d3717e1da5228Mark AndrewsCLASS="filename"
0961ac0868e7d60e7cb665160f6d3717e1da5228Mark Andrews>a.mx.example.com</TT
3d697a7eddf375586435f8fb6e1440fb3ce9058dMark Andrews> and <TT
3d697a7eddf375586435f8fb6e1440fb3ce9058dMark AndrewsCLASS="filename"
8943ff626fa337419cbffad6a4a910c7d99509f4Mark Andrews>b.mx.example.com</TT
8943ff626fa337419cbffad6a4a910c7d99509f4Mark Andrews>).</P
281bab0f36eaedc56f859721fbdf45568b71cd60Mark Andrews><P
281bab0f36eaedc56f859721fbdf45568b71cd60Mark Andrews>In addition, the public <TT
281bab0f36eaedc56f859721fbdf45568b71cd60Mark AndrewsCLASS="filename"
281bab0f36eaedc56f859721fbdf45568b71cd60Mark Andrews>site1</TT
5cd4555ad444fd391002ae32450572054369fd42Rob Austein> and <TT
5cd4555ad444fd391002ae32450572054369fd42Rob AusteinCLASS="filename"
8eb4eca37538183edb36db88580b5232f15931b0Mark Andrews>site2.example.com</TT
8eb4eca37538183edb36db88580b5232f15931b0Mark Andrews> zones
fa3d0b9991ea0d8344881c5dd4609d9c33314b9bMark Andrewsshould have special MX records that contain wildcard (`*') records
305227476756aecb11cebbc811dba88a2d147b34Mark Andrewspointing to the bastion hosts. This is needed because external mail
e7d32e57a5c8600893f91ec08f74117c983f8b8dMark Andrewsservers do not have any other way of looking up how to deliver mail
e7d32e57a5c8600893f91ec08f74117c983f8b8dMark Andrewsto those internal hosts. With the wildcard records, the mail will
e7d32e57a5c8600893f91ec08f74117c983f8b8dMark Andrewsbe delivered to the bastion host, which can then forward it on to
fa3d0b9991ea0d8344881c5dd4609d9c33314b9bMark Andrewsinternal hosts.</P
e3f66e1617f9fca7313e4005b8c3c611551906d1Mark Andrews><P
ed954ce73b1c712b24eab945190028871433f803Mark Andrews>Here's an example of a wildcard MX record:</P
ed954ce73b1c712b24eab945190028871433f803Mark Andrews><PRE
ed954ce73b1c712b24eab945190028871433f803Mark AndrewsCLASS="programlisting"
29747dfe5e073a299b3681e01f5c55540f8bfed7Mark Andrews><VAR
29747dfe5e073a299b3681e01f5c55540f8bfed7Mark AndrewsCLASS="literal"
29747dfe5e073a299b3681e01f5c55540f8bfed7Mark Andrews>* IN MX 10 external1.example.com.</VAR
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews></PRE
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews><P
186e7f37c9fc985a7a7264cc8170e48a25bed434Mark Andrews>Now that they accept mail on behalf of anything in the internal
1372e172d0e0b08996376b782a9041d1e3542489Mark Andrewsnetwork, the bastion hosts will need to know how to deliver mail
1372e172d0e0b08996376b782a9041d1e3542489Mark Andrewsto internal hosts. In order for this to work properly, the resolvers on
1372e172d0e0b08996376b782a9041d1e3542489Mark Andrewsthe bastion hosts will need to be configured to point to the internal
8d709e3ee443222cd35e44eadc9a4c0a8d92fec2Rob Austeinname servers for DNS resolution.</P
8d709e3ee443222cd35e44eadc9a4c0a8d92fec2Rob Austein><P
23235c00eda9089f38ace0a1371fed9a466ea5ddMark Andrews>Queries for internal hostnames will be answered by the internal
23235c00eda9089f38ace0a1371fed9a466ea5ddMark Andrewsservers, and queries for external hostnames will be forwarded back
23235c00eda9089f38ace0a1371fed9a466ea5ddMark Andrewsout to the DNS servers on the bastion hosts.</P
23235c00eda9089f38ace0a1371fed9a466ea5ddMark Andrews><P
514aeac2acbbe2b77ff3c4e310617523cf5651c5Mark Andrews>In order for all this to work properly, internal clients will
514aeac2acbbe2b77ff3c4e310617523cf5651c5Mark Andrewsneed to be configured to query <SPAN
514aeac2acbbe2b77ff3c4e310617523cf5651c5Mark AndrewsCLASS="emphasis"
514aeac2acbbe2b77ff3c4e310617523cf5651c5Mark Andrews><I
1ea2595e1b33cc63ea73ee1d54b580b717d7d155Mark AndrewsCLASS="emphasis"
1ea2595e1b33cc63ea73ee1d54b580b717d7d155Mark Andrews>only</I
1ea2595e1b33cc63ea73ee1d54b580b717d7d155Mark Andrews></SPAN
1ea2595e1b33cc63ea73ee1d54b580b717d7d155Mark Andrews> the internal
1ea2595e1b33cc63ea73ee1d54b580b717d7d155Mark Andrewsname servers for DNS queries. This could also be enforced via selective
1ea2595e1b33cc63ea73ee1d54b580b717d7d155Mark Andrewsfiltering on the network.</P
1ea2595e1b33cc63ea73ee1d54b580b717d7d155Mark Andrews><P
e60f01cdd29c71e9224273214521b15aef4d4555Mark Andrews>If everything has been set properly, <SPAN
e60f01cdd29c71e9224273214521b15aef4d4555Mark AndrewsCLASS="emphasis"
e60f01cdd29c71e9224273214521b15aef4d4555Mark Andrews><I
13290782cb83ee43c4dc942d186761a46c4a2692Mark AndrewsCLASS="emphasis"
13290782cb83ee43c4dc942d186761a46c4a2692Mark Andrews>Example, Inc.</I
13290782cb83ee43c4dc942d186761a46c4a2692Mark Andrews></SPAN
824cb6567555af556d0963d961798483d252eb5fMark Andrews>'s
895ae38da194143331d667289affd3b43c5bfc14Mark Andrewsinternal clients will now be able to:</P
824cb6567555af556d0963d961798483d252eb5fMark Andrews><P
bca16e31b457598cd1dbbf0cdc7a26a6d2ec3753Mark Andrews></P
bca16e31b457598cd1dbbf0cdc7a26a6d2ec3753Mark Andrews><UL
bca16e31b457598cd1dbbf0cdc7a26a6d2ec3753Mark Andrews><LI
58ea8fb1dfc8c055a7d4ad74d65e345436ede790Mark Andrews><P
58ea8fb1dfc8c055a7d4ad74d65e345436ede790Mark Andrews>Look up any hostnames in the <VAR
cfcb0881d12db2b7cb33475b7d20ac6c9015203bMark AndrewsCLASS="literal"
cfcb0881d12db2b7cb33475b7d20ac6c9015203bMark Andrews>site1</VAR
cfcb0881d12db2b7cb33475b7d20ac6c9015203bMark Andrews> and
1a8efeab76d34327a699894a6a404f97b341c57aMark Andrews<VAR
1a8efeab76d34327a699894a6a404f97b341c57aMark AndrewsCLASS="literal"
1a8efeab76d34327a699894a6a404f97b341c57aMark Andrews>site2.example.com</VAR
f041bef2c60a092ab4dcae475451729a5345830fMark Andrews> zones.</P
f041bef2c60a092ab4dcae475451729a5345830fMark Andrews></LI
a7dd5f21e996b01262a3d564dae9561cb3f8e717Mark Andrews><LI
a7dd5f21e996b01262a3d564dae9561cb3f8e717Mark Andrews><P
92d23165938a5e595f80b2e3fb5d8cb918ac7dacMark Andrews>Look up any hostnames in the <VAR
92d23165938a5e595f80b2e3fb5d8cb918ac7dacMark AndrewsCLASS="literal"
1cbb3a4df30777791ce27a0d2349420808c013d8Mark Andrews>site1.internal</VAR
1cbb3a4df30777791ce27a0d2349420808c013d8Mark Andrews> and
289ae548d52bc8f982d9823af64cafda7bd92232Mark Andrews<VAR
289ae548d52bc8f982d9823af64cafda7bd92232Mark AndrewsCLASS="literal"
4ccea866e64a8ec8525ad4bf7d57606bcd2fc15dMark Andrews>site2.internal</VAR
4ccea866e64a8ec8525ad4bf7d57606bcd2fc15dMark Andrews> domains.</P
4cf228853d658a742a826393f341e2486c629f7bMark Andrews></LI
4cf228853d658a742a826393f341e2486c629f7bMark Andrews><LI
4cf228853d658a742a826393f341e2486c629f7bMark Andrews><P
1672cc63c190e073706a742ebaabc20ac4d2c916Mark Andrews>Look up any hostnames on the Internet.</P
1672cc63c190e073706a742ebaabc20ac4d2c916Mark Andrews></LI
6805e4e2c46ad3c5a4aa941b5e9a29d34579641eMark Andrews><LI
6805e4e2c46ad3c5a4aa941b5e9a29d34579641eMark Andrews><P
6805e4e2c46ad3c5a4aa941b5e9a29d34579641eMark Andrews>Exchange mail with internal AND external people.</P
1afb6c548d9bbfcfb00d0799077faa17ad9a4f59Mark Andrews></LI
1afb6c548d9bbfcfb00d0799077faa17ad9a4f59Mark Andrews></UL
1afb6c548d9bbfcfb00d0799077faa17ad9a4f59Mark Andrews><P
5de1ad63735deb0ea86b2d0a9366eddf5fbeddc1Mark Andrews>Hosts on the Internet will be able to:</P
5de1ad63735deb0ea86b2d0a9366eddf5fbeddc1Mark Andrews><P
92ff69c60001ed270248a6f38bafd2ae12d029beMark Andrews></P
a1210da03636eca13c70502a2b132ead22481b70Mark Andrews><UL
a1210da03636eca13c70502a2b132ead22481b70Mark Andrews><LI
ef54920b4c82a0ea41972d1dc21a0dc96fa791fbTatuya JINMEI 神明達哉><P
a473029e76dfc68db00505f40065607b4ea1e0f5Mark Andrews>Look up any hostnames in the <VAR
a473029e76dfc68db00505f40065607b4ea1e0f5Mark AndrewsCLASS="literal"
a473029e76dfc68db00505f40065607b4ea1e0f5Mark Andrews>site1</VAR
411118a594dbcee68cd6adf5f6bd1b9db0ff9190Mark Andrews> and
411118a594dbcee68cd6adf5f6bd1b9db0ff9190Mark Andrews<VAR
411118a594dbcee68cd6adf5f6bd1b9db0ff9190Mark AndrewsCLASS="literal"
7c0946e74be897d02aaaf980ac146bcb500c2c8cMark Andrews>site2.example.com</VAR
7c0946e74be897d02aaaf980ac146bcb500c2c8cMark Andrews> zones.</P
7c0946e74be897d02aaaf980ac146bcb500c2c8cMark Andrews></LI
09cbf84907de2bd088b4ce8bd1307938bf0e81baMark Andrews><LI
09cbf84907de2bd088b4ce8bd1307938bf0e81baMark Andrews><P
9e2789fd70b954df426b80301b62388497692481Mark Andrews>Exchange mail with anyone in the <VAR
9e2789fd70b954df426b80301b62388497692481Mark AndrewsCLASS="literal"
b1163a6fe91e6e7a14e40cd5d33108c4deb38312Mark Andrews>site1</VAR
b1163a6fe91e6e7a14e40cd5d33108c4deb38312Mark Andrews> and
b1163a6fe91e6e7a14e40cd5d33108c4deb38312Mark Andrews<VAR
b1163a6fe91e6e7a14e40cd5d33108c4deb38312Mark AndrewsCLASS="literal"
8af4bf165e9a6aa111e0b6bfcbcc7f4a741a8ae5Mark Andrews>site2.example.com</VAR
8af4bf165e9a6aa111e0b6bfcbcc7f4a741a8ae5Mark Andrews> zones.</P
5cf0c559489d741ee5c7943ece47e40567bb0ba9Mark Andrews></LI
5cf0c559489d741ee5c7943ece47e40567bb0ba9Mark Andrews></UL
5cf0c559489d741ee5c7943ece47e40567bb0ba9Mark Andrews><P
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews>Here is an example configuration for the setup we just
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews described above. Note that this is only configuration information;
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews for information on how to configure your zone files, see <A
fda0a038810529d6e45b17822ddcc61d82964e83Mark AndrewsHREF="Bv9ARM.ch03.html#sample_configuration"
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews>Section 3.1</A
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews></P
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews><P
fda0a038810529d6e45b17822ddcc61d82964e83Mark Andrews>Internal DNS server config:</P
53d3679913d715cce0dc7e8be04662366eab4842Mark Andrews><PRE
53d3679913d715cce0dc7e8be04662366eab4842Mark AndrewsCLASS="programlisting"
53d3679913d715cce0dc7e8be04662366eab4842Mark Andrews>&#13;
755df9a92a13310eec4b1baeb297c93674a70417Mark Andrewsacl internals { 172.16.72.0/24; 192.168.1.0/24; };
755df9a92a13310eec4b1baeb297c93674a70417Mark Andrews
755df9a92a13310eec4b1baeb297c93674a70417Mark Andrewsacl externals { <VAR
e3582ce43119a95448ccc06ea2586f6547c92967Mark AndrewsCLASS="varname"
e3582ce43119a95448ccc06ea2586f6547c92967Mark Andrews>bastion-ips-go-here</VAR
2952abf7cbbba6c6f821ee18579ca29d87549574Mark Andrews>; };
2952abf7cbbba6c6f821ee18579ca29d87549574Mark Andrews
efb82ed87e916c82b481bee4aa6651f2dbd4cedaMark Andrewsoptions {
efb82ed87e916c82b481bee4aa6651f2dbd4cedaMark Andrews ...
7c693bfdbe488ca8fa4f0831c71f5809972f6cc7Mark Andrews ...
7c693bfdbe488ca8fa4f0831c71f5809972f6cc7Mark Andrews forward only;
7092864f71e0bbb108041ef01ac3d2b41f90c4a9Mark Andrews forwarders { // forward to external servers
7092864f71e0bbb108041ef01ac3d2b41f90c4a9Mark Andrews <VAR
7092864f71e0bbb108041ef01ac3d2b41f90c4a9Mark AndrewsCLASS="varname"
24ee607afa66e5ba5fa8b2f18c34a5c430b8a3feMark Andrews>bastion-ips-go-here</VAR
24ee607afa66e5ba5fa8b2f18c34a5c430b8a3feMark Andrews>;
24ee607afa66e5ba5fa8b2f18c34a5c430b8a3feMark Andrews };
2113dfd6e20a9ca16000ed226517b4660087c1f2Mark Andrews allow-transfer { none; }; // sample allow-transfer (no one)
2113dfd6e20a9ca16000ed226517b4660087c1f2Mark Andrews allow-query { internals; externals; }; // restrict query access
2113dfd6e20a9ca16000ed226517b4660087c1f2Mark Andrews allow-recursion { internals; }; // restrict recursion
2dafa707cc9af9cca66d68c1d2c3af0c768c2900Mark Andrews ...
2dafa707cc9af9cca66d68c1d2c3af0c768c2900Mark Andrews ...
2dafa707cc9af9cca66d68c1d2c3af0c768c2900Mark Andrews};
2dafa707cc9af9cca66d68c1d2c3af0c768c2900Mark Andrews
2dafa707cc9af9cca66d68c1d2c3af0c768c2900Mark Andrewszone "site1.example.com" { // sample master zone
2dafa707cc9af9cca66d68c1d2c3af0c768c2900Mark Andrews type master;
c7817270552b2faab56466b89731b6f290b352a4Mark Andrews file "m/site1.example.com";
c7817270552b2faab56466b89731b6f290b352a4Mark Andrews forwarders { }; // do normal iterative
c7817270552b2faab56466b89731b6f290b352a4Mark Andrews // resolution (do not forward)
22e5a52c3b5bfef7e75d95629e08cab7592fee5cMark Andrews allow-query { internals; externals; };
22e5a52c3b5bfef7e75d95629e08cab7592fee5cMark Andrews allow-transfer { internals; };
22e5a52c3b5bfef7e75d95629e08cab7592fee5cMark Andrews};
6d453e1bb296e88732655f3d736e571eeaaca254Mark Andrews
240e57ab983296e6d52031a594d3345728191b48Mark Andrewszone "site2.example.com" { // sample slave zone
240e57ab983296e6d52031a594d3345728191b48Mark Andrews type slave;
240e57ab983296e6d52031a594d3345728191b48Mark Andrews file "s/site2.example.com";
cdb674387ca19dc8550553d90d8f9731befb6f1fMark Andrews masters { 172.16.72.3; };
cdb674387ca19dc8550553d90d8f9731befb6f1fMark Andrews forwarders { };
cdb674387ca19dc8550553d90d8f9731befb6f1fMark Andrews allow-query { internals; externals; };
02ced31b6aa999099214d2688b1a80ac5d93c57bMark Andrews allow-transfer { internals; };
02ced31b6aa999099214d2688b1a80ac5d93c57bMark Andrews};
02ced31b6aa999099214d2688b1a80ac5d93c57bMark Andrews
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrewszone "site1.internal" {
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews type master;
728156dfbdced7bc18b1f88227cced9d426a70e7Mark Andrews file "m/site1.internal";
d4f5efb4d63e2e17081a49a3457f05fe06fbb5abMark Andrews forwarders { };
d4f5efb4d63e2e17081a49a3457f05fe06fbb5abMark Andrews allow-query { internals; };
d4f5efb4d63e2e17081a49a3457f05fe06fbb5abMark Andrews allow-transfer { internals; }
e560f615b2592deea69c49bfc74acbb56f4fd913Mark Andrews};
e560f615b2592deea69c49bfc74acbb56f4fd913Mark Andrews
cfaf65f53fb0c1779e7b2e07216e5fbfd3a2d52eMark Andrewszone "site2.internal" {
cfaf65f53fb0c1779e7b2e07216e5fbfd3a2d52eMark Andrews type slave;
cfaf65f53fb0c1779e7b2e07216e5fbfd3a2d52eMark Andrews file "s/site2.internal";
f07fe5a1ac9d1345eb7a36a0bc38716a03e25f61Mark Andrews masters { 172.16.72.3; };
f07fe5a1ac9d1345eb7a36a0bc38716a03e25f61Mark Andrews forwarders { };
f07fe5a1ac9d1345eb7a36a0bc38716a03e25f61Mark Andrews allow-query { internals };
f34249bb28093d6589196cd00ca040f503a65e2bMark Andrews allow-transfer { internals; }
dbfc2232ef5b6e5572480070ab87a4d67c18aa39Mark Andrews};
ce8cd4a3efd27ef145847216d513bb341bfe208cMark Andrews</PRE
ce8cd4a3efd27ef145847216d513bb341bfe208cMark Andrews><P
ce8cd4a3efd27ef145847216d513bb341bfe208cMark Andrews>External (bastion host) DNS server config:</P
393e4679cf4dd8bafb031d8a61ece95af61fbedcMark Andrews><PRE
393e4679cf4dd8bafb031d8a61ece95af61fbedcMark AndrewsCLASS="programlisting"
854dac0f186e5b491d65f6d73dd6e440e7a2c227Mark Andrews>&#13;acl internals { 172.16.72.0/24; 192.168.1.0/24; };
854dac0f186e5b491d65f6d73dd6e440e7a2c227Mark Andrews
854dac0f186e5b491d65f6d73dd6e440e7a2c227Mark Andrewsacl externals { bastion-ips-go-here; };
67b1eee9dfde5ad86b54b2b768ff4d6b1354b651Mark Andrews
431fd1b0b5c3c049f9397ed4be8915715ead9cdbMark Andrewsoptions {
431fd1b0b5c3c049f9397ed4be8915715ead9cdbMark Andrews ...
cc7d91bd5c6b9be5a3c67a99112b885602c24873Mark Andrews ...
cc7d91bd5c6b9be5a3c67a99112b885602c24873Mark Andrews allow-transfer { none; }; // sample allow-transfer (no one)
39ef7dddef12152afa3a2fc1c1962cdf6d30b5cbMark Andrews allow-query { any; }; // default query access
39ef7dddef12152afa3a2fc1c1962cdf6d30b5cbMark Andrews allow-query-cache { internals; externals; }; // restrict cache access
39ef7dddef12152afa3a2fc1c1962cdf6d30b5cbMark Andrews allow-recursion { internals; externals; }; // restrict recursion
f22ef4dfb973c4714eedd3818050fde74fb20e48Mark Andrews ...
f22ef4dfb973c4714eedd3818050fde74fb20e48Mark Andrews ...
f22ef4dfb973c4714eedd3818050fde74fb20e48Mark Andrews};
3b572928731d3595990fe360c80977a2d043eb02Tatuya JINMEI 神明達哉
84f5576c149ed0cf18555bcd7cf1ffbe491bb08fMark Andrewszone "site1.example.com" { // sample slave zone
50d3f097d4c2779c8fb2397882d91e0cbca2c260Mark Andrews type master;
84f5576c149ed0cf18555bcd7cf1ffbe491bb08fMark Andrews file "m/site1.foo.com";
84f5576c149ed0cf18555bcd7cf1ffbe491bb08fMark Andrews allow-transfer { internals; externals; };
84f5576c149ed0cf18555bcd7cf1ffbe491bb08fMark Andrews};
6953fd6e20fddcb6389e642aa872cb7425a95f6dMark Andrews
6953fd6e20fddcb6389e642aa872cb7425a95f6dMark Andrewszone "site2.example.com" {
6953fd6e20fddcb6389e642aa872cb7425a95f6dMark Andrews type slave;
2b67af24fa02867fbc703e89277400b10d0c8b92Mark Andrews file "s/site2.foo.com";
2b67af24fa02867fbc703e89277400b10d0c8b92Mark Andrews masters { another_bastion_host_maybe; };
2b67af24fa02867fbc703e89277400b10d0c8b92Mark Andrews allow-transfer { internals; externals; }
f02b985650a6f1277a3a45f18561d519916c1890Mark Andrews};
f02b985650a6f1277a3a45f18561d519916c1890Mark Andrews</PRE
f02b985650a6f1277a3a45f18561d519916c1890Mark Andrews><P
c870001ae1bff0e38f622c4ed56872c7f1d2d336Mark Andrews>In the <TT
c870001ae1bff0e38f622c4ed56872c7f1d2d336Mark AndrewsCLASS="filename"
c870001ae1bff0e38f622c4ed56872c7f1d2d336Mark Andrews>resolv.conf</TT
0b5d8941bb41edbe1296619485c16df536ecc05fMark Andrews> (or equivalent) on
0b5d8941bb41edbe1296619485c16df536ecc05fMark Andrewsthe bastion host(s):</P
bcdf37e0ff7d73310b7bf247d755194a5718ba38Mark Andrews><PRE
bcdf37e0ff7d73310b7bf247d755194a5718ba38Mark AndrewsCLASS="programlisting"
bcdf37e0ff7d73310b7bf247d755194a5718ba38Mark Andrews>&#13;search ...
a34d19803a206febe10866394393ec1c09b28984Mark Andrewsnameserver 172.16.72.2
a34d19803a206febe10866394393ec1c09b28984Mark Andrewsnameserver 172.16.72.3
cbef026164ceabccb2e85403434b722d77f7b5eeMark Andrewsnameserver 172.16.72.4
cbef026164ceabccb2e85403434b722d77f7b5eeMark Andrews</PRE
cbef026164ceabccb2e85403434b722d77f7b5eeMark Andrews></DIV
2db8db63992d081c75d664340866e2a21913705dMark Andrews><DIV
2db8db63992d081c75d664340866e2a21913705dMark AndrewsCLASS="sect1"
2db8db63992d081c75d664340866e2a21913705dMark Andrews><H1
2db8db63992d081c75d664340866e2a21913705dMark AndrewsCLASS="sect1"
2db8db63992d081c75d664340866e2a21913705dMark Andrews><A
7076f000ea3487299a9da9318915d042aaba62c5Mark AndrewsNAME="tsig"
7076f000ea3487299a9da9318915d042aaba62c5Mark Andrews>4.5. TSIG</A
7076f000ea3487299a9da9318915d042aaba62c5Mark Andrews></H1
7076f000ea3487299a9da9318915d042aaba62c5Mark Andrews><P
7076f000ea3487299a9da9318915d042aaba62c5Mark Andrews>This is a short guide to setting up Transaction SIGnatures
8626c376a038da969de1ee6c158957dfe638daacMark Andrews(TSIG) based transaction security in <ACRONYM
8626c376a038da969de1ee6c158957dfe638daacMark AndrewsCLASS="acronym"
8626c376a038da969de1ee6c158957dfe638daacMark Andrews>BIND</ACRONYM
c6ee5082db1e40ab64e08a540620da79996efa9cTatuya JINMEI 神明達哉>. It describes changes
222dcab0a6456c5395545e885f21b5542b7d841dTatuya JINMEI 神明達哉to the configuration file as well as what changes are required for
c6ee5082db1e40ab64e08a540620da79996efa9cTatuya JINMEI 神明達哉different features, including the process of creating transaction
f22ef4dfb973c4714eedd3818050fde74fb20e48Mark Andrewskeys and using transaction signatures with <ACRONYM
9a6522317c97e5487cea816173f63a0e5b4e428aTatuya JINMEI 神明達哉CLASS="acronym"
f5a156fa25e6d341e703782de6368fbe9e256ddeTatuya JINMEI 神明達哉>BIND</ACRONYM
f22ef4dfb973c4714eedd3818050fde74fb20e48Mark Andrews>.</P
78ff0e94eae96f2cf8bf94454d8ff01ba280d30dMark Andrews><P
5a9efbf6bf951267e0844990f5b2cb69f5d5f01fTatuya JINMEI 神明達哉><ACRONYM
08eadd404a59a6befcf51cb13695abee5d03456dMark AndrewsCLASS="acronym"
08eadd404a59a6befcf51cb13695abee5d03456dMark Andrews>BIND</ACRONYM
08eadd404a59a6befcf51cb13695abee5d03456dMark Andrews> primarily supports TSIG for server to server communication.
c55dd77de4ce71b858afb291e44577b51be8b780Mark AndrewsThis includes zone transfer, notify, and recursive query messages.
c55dd77de4ce71b858afb291e44577b51be8b780Mark AndrewsResolvers based on newer versions of <ACRONYM
c55dd77de4ce71b858afb291e44577b51be8b780Mark AndrewsCLASS="acronym"
eca38a9d43391482bfa22e2eb7b86e19be8bf461Mark Andrews>BIND</ACRONYM
eca38a9d43391482bfa22e2eb7b86e19be8bf461Mark Andrews> 8 have limited support
eca38a9d43391482bfa22e2eb7b86e19be8bf461Mark Andrewsfor TSIG.</P
d79296d147cd4c35784dd3efd7ed7f09d976ee61Mark Andrews><P
d79296d147cd4c35784dd3efd7ed7f09d976ee61Mark Andrews>TSIG might be most useful for dynamic update. A primary
4f5a43c5f084290054ddf212add7b4c2abe6edc5Tatuya JINMEI 神明達哉 server for a dynamic zone should use access control to control
9a482d1fcead22ab0d639c463c77672846485f3eMark Andrews updates, but IP-based access control is insufficient.
46390a96dd5f15c9a0b3663bdb7791bdecec3052Mark Andrews The cryptographic access control provided by TSIG
9a482d1fcead22ab0d639c463c77672846485f3eMark Andrews is far superior. The <B
9a482d1fcead22ab0d639c463c77672846485f3eMark AndrewsCLASS="command"
9a482d1fcead22ab0d639c463c77672846485f3eMark Andrews>nsupdate</B
9a482d1fcead22ab0d639c463c77672846485f3eMark Andrews>
9a482d1fcead22ab0d639c463c77672846485f3eMark Andrews program supports TSIG via the <VAR
d48f9877255f41b6074777da0639b6bc2bfad388Mark AndrewsCLASS="option"
d48f9877255f41b6074777da0639b6bc2bfad388Mark Andrews>-k</VAR
d48f9877255f41b6074777da0639b6bc2bfad388Mark Andrews> and
d48f9877255f41b6074777da0639b6bc2bfad388Mark Andrews <VAR
5d51f534831bd648436d22e4faf203fb9abdf3d4Mark AndrewsCLASS="option"
5d51f534831bd648436d22e4faf203fb9abdf3d4Mark Andrews>-y</VAR
5d51f534831bd648436d22e4faf203fb9abdf3d4Mark Andrews> command line options.</P
a45a6ea2b03448751d7c44931e8ac7666e7cc2ceMark Andrews><DIV
a45a6ea2b03448751d7c44931e8ac7666e7cc2ceMark AndrewsCLASS="sect2"
a45a6ea2b03448751d7c44931e8ac7666e7cc2ceMark Andrews><H2
a45a6ea2b03448751d7c44931e8ac7666e7cc2ceMark AndrewsCLASS="sect2"
15bda409010cbf2d3e43baf10f28bae5f7b1abefMark Andrews><A
15bda409010cbf2d3e43baf10f28bae5f7b1abefMark AndrewsNAME="AEN858"
b5205d860b1672c405c57004e6823af873799b42Mark Andrews>4.5.1. Generate Shared Keys for Each Pair of Hosts</A
b5205d860b1672c405c57004e6823af873799b42Mark Andrews></H2
b5205d860b1672c405c57004e6823af873799b42Mark Andrews><P
9a1e8f1baf3e5c53d6b6bfa97d7f60cb3358e404Mark Andrews>A shared secret is generated to be shared between <SPAN
9a1e8f1baf3e5c53d6b6bfa97d7f60cb3358e404Mark AndrewsCLASS="emphasis"
c79e85f7d77317a9b5c34b4bb94eaf1779fc0b6eMark Andrews><I
c79e85f7d77317a9b5c34b4bb94eaf1779fc0b6eMark AndrewsCLASS="emphasis"
c79e85f7d77317a9b5c34b4bb94eaf1779fc0b6eMark Andrews>host1</I
12b1bf8b14ac3b6ec4de9cae6fea10f389b5e5dbMark Andrews></SPAN
12b1bf8b14ac3b6ec4de9cae6fea10f389b5e5dbMark Andrews> and <SPAN
12b1bf8b14ac3b6ec4de9cae6fea10f389b5e5dbMark AndrewsCLASS="emphasis"
e22bd3c4bc0de0b96531fab5c2c944251e02e975Mark Andrews><I
e22bd3c4bc0de0b96531fab5c2c944251e02e975Mark AndrewsCLASS="emphasis"
e22bd3c4bc0de0b96531fab5c2c944251e02e975Mark Andrews>host2</I
9c420baae0dce935d70df3852bc3abdfe5caf093Mark Andrews></SPAN
529035492ea0a427cc8d007cd743934d4494d9d3Mark Andrews>.
529035492ea0a427cc8d007cd743934d4494d9d3Mark AndrewsAn arbitrary key name is chosen: "host1-host2.". The key name must
ff6bd86d5778de50cb1b4e93591e22354062ee17Mark Andrewsbe the same on both hosts.</P
11e43ff752bab2983d9328b6624bbcef613a93e1Mark Andrews><DIV
444bbadb54d4a676aa4b20685d3178d7988534b3Mark AndrewsCLASS="sect3"
444bbadb54d4a676aa4b20685d3178d7988534b3Mark Andrews><H3
444bbadb54d4a676aa4b20685d3178d7988534b3Mark AndrewsCLASS="sect3"
cd6d8d61b076eea02826596334a105b918393627Mark Andrews><A
cd6d8d61b076eea02826596334a105b918393627Mark AndrewsNAME="AEN863"
f04809663f4ba3df0e2ef1247d67bdd6ce0157d6Mark Andrews>4.5.1.1. Automatic Generation</A
f04809663f4ba3df0e2ef1247d67bdd6ce0157d6Mark Andrews></H3
f04809663f4ba3df0e2ef1247d67bdd6ce0157d6Mark Andrews><P
7d7f929274e48808b4771162d6302a99e69865d8Mark Andrews>The following command will generate a 128 bit (16 byte) HMAC-MD5
7d7f929274e48808b4771162d6302a99e69865d8Mark Andrewskey as described above. Longer keys are better, but shorter keys
7d7f929274e48808b4771162d6302a99e69865d8Mark Andrewsare easier to read. Note that the maximum key length is 512 bits;
21b76ee598c937c6736cbc7ab69684bb3332428aMark Andrewskeys longer than that will be digested with MD5 to produce a 128
21b76ee598c937c6736cbc7ab69684bb3332428aMark Andrewsbit key.</P
21b76ee598c937c6736cbc7ab69684bb3332428aMark Andrews><P
21b76ee598c937c6736cbc7ab69684bb3332428aMark Andrews><KBD
21b76ee598c937c6736cbc7ab69684bb3332428aMark AndrewsCLASS="userinput"
5c45d30402af6860e1f66f5aa7d78dff58373b27Mark Andrews>dnssec-keygen -a hmac-md5 -b 128 -n HOST host1-host2.</KBD
5c45d30402af6860e1f66f5aa7d78dff58373b27Mark Andrews></P
b66ca17f2990433a3e277b50cc3c15f19cdd0771Mark Andrews><P
b66ca17f2990433a3e277b50cc3c15f19cdd0771Mark Andrews>The key is in the file <TT
b66ca17f2990433a3e277b50cc3c15f19cdd0771Mark AndrewsCLASS="filename"
dc1f18f211a91735faf2771acc8438f0fbc70d4bMark Andrews>Khost1-host2.+157+00000.private</TT
dc1f18f211a91735faf2771acc8438f0fbc70d4bMark Andrews>.
dc1f18f211a91735faf2771acc8438f0fbc70d4bMark AndrewsNothing directly uses this file, but the base-64 encoded string
dc1f18f211a91735faf2771acc8438f0fbc70d4bMark Andrewsfollowing "<VAR
7b68fa6229f1edadac44c7ec459c9ed77a8368c8Mark AndrewsCLASS="literal"
82ecc9cd96239649dfeb0a16e31c3b978d0d266aMark Andrews>Key:</VAR
82ecc9cd96239649dfeb0a16e31c3b978d0d266aMark Andrews>"
82ecc9cd96239649dfeb0a16e31c3b978d0d266aMark Andrewscan be extracted from the file and used as a shared secret:</P
82ecc9cd96239649dfeb0a16e31c3b978d0d266aMark Andrews><PRE
6412902ffc0d255657f54db768f30b6efa819143Mark AndrewsCLASS="programlisting"
6412902ffc0d255657f54db768f30b6efa819143Mark Andrews>Key: La/E5CjG9O+os1jq0a2jdA==</PRE
6412902ffc0d255657f54db768f30b6efa819143Mark Andrews><P
6412902ffc0d255657f54db768f30b6efa819143Mark Andrews>The string "<VAR
6412902ffc0d255657f54db768f30b6efa819143Mark AndrewsCLASS="literal"
6412902ffc0d255657f54db768f30b6efa819143Mark Andrews>La/E5CjG9O+os1jq0a2jdA==</VAR
0d8971a4b8abed599ec9d9b7d1b51b8de8038ce2Shane Kerr>" can
0d8971a4b8abed599ec9d9b7d1b51b8de8038ce2Shane Kerrbe used as the shared secret.</P
0d8971a4b8abed599ec9d9b7d1b51b8de8038ce2Shane Kerr></DIV
a8f950ff05e2e81d425a3411268cdf21f8f26b16Mark Andrews><DIV
a8f950ff05e2e81d425a3411268cdf21f8f26b16Mark AndrewsCLASS="sect3"
a8f950ff05e2e81d425a3411268cdf21f8f26b16Mark Andrews><H3
bc1467288a25b48446d3229fef0a19fad0cb6f2fMark AndrewsCLASS="sect3"
bc1467288a25b48446d3229fef0a19fad0cb6f2fMark Andrews><A
bc1467288a25b48446d3229fef0a19fad0cb6f2fMark AndrewsNAME="AEN874"
6ed53e5949d9fcd9715b440015b56e5a896d63dfDavid Hankins>4.5.1.2. Manual Generation</A
6ed53e5949d9fcd9715b440015b56e5a896d63dfDavid Hankins></H3
6ed53e5949d9fcd9715b440015b56e5a896d63dfDavid Hankins><P
6ed53e5949d9fcd9715b440015b56e5a896d63dfDavid Hankins>The shared secret is simply a random sequence of bits, encoded
f19353d73186913a6e0f0f766c1f72e5f4c5e9e1Tatuya JINMEI 神明達哉in base-64. Most ASCII strings are valid base-64 strings (assuming
f19353d73186913a6e0f0f766c1f72e5f4c5e9e1Tatuya JINMEI 神明達哉the length is a multiple of 4 and only valid characters are used),
84910d09ee8244027c7031e03999bc60a3d63adbMark Andrewsso the shared secret can be manually generated.</P
84910d09ee8244027c7031e03999bc60a3d63adbMark Andrews><P
d2ef84e07b67e72a4bd9c729c6b8228067d17584Mark Andrews>Also, a known string can be run through <B
d2ef84e07b67e72a4bd9c729c6b8228067d17584Mark AndrewsCLASS="command"
d2ef84e07b67e72a4bd9c729c6b8228067d17584Mark Andrews>mmencode</B
d2ef84e07b67e72a4bd9c729c6b8228067d17584Mark Andrews> or
d2ef84e07b67e72a4bd9c729c6b8228067d17584Mark Andrewsa similar program to generate base-64 encoded data.</P
d2ef84e07b67e72a4bd9c729c6b8228067d17584Mark Andrews></DIV
d2ef84e07b67e72a4bd9c729c6b8228067d17584Mark Andrews></DIV
cfe92110ce4eaf19f7f3255d2961710879bdc9ddMark Andrews><DIV
cfe92110ce4eaf19f7f3255d2961710879bdc9ddMark AndrewsCLASS="sect2"
cfe92110ce4eaf19f7f3255d2961710879bdc9ddMark Andrews><H2
cfe92110ce4eaf19f7f3255d2961710879bdc9ddMark AndrewsCLASS="sect2"
fe6f384b2efde528dabbf822634eedc020be67e0Mark Andrews><A
fe6f384b2efde528dabbf822634eedc020be67e0Mark AndrewsNAME="AEN879"
fe6f384b2efde528dabbf822634eedc020be67e0Mark Andrews>4.5.2. Copying the Shared Secret to Both Machines</A
fe6f384b2efde528dabbf822634eedc020be67e0Mark Andrews></H2
fe6f384b2efde528dabbf822634eedc020be67e0Mark Andrews><P
fe6f384b2efde528dabbf822634eedc020be67e0Mark Andrews>This is beyond the scope of DNS. A secure transport mechanism
fe6f384b2efde528dabbf822634eedc020be67e0Mark Andrewsshould be used. This could be secure FTP, ssh, telephone, etc.</P
fe6f384b2efde528dabbf822634eedc020be67e0Mark Andrews></DIV
fe6f384b2efde528dabbf822634eedc020be67e0Mark Andrews><DIV
fe6f384b2efde528dabbf822634eedc020be67e0Mark AndrewsCLASS="sect2"
fe6f384b2efde528dabbf822634eedc020be67e0Mark Andrews><H2
5929cde251d6d971fda14ac9ea927035421f6480Mark AndrewsCLASS="sect2"
5929cde251d6d971fda14ac9ea927035421f6480Mark Andrews><A
5929cde251d6d971fda14ac9ea927035421f6480Mark AndrewsNAME="AEN882"
5929cde251d6d971fda14ac9ea927035421f6480Mark Andrews>4.5.3. Informing the Servers of the Key's Existence</A
1412643ba5bcc735c3731d8cebf71fd76eedec91Mark Andrews></H2
1412643ba5bcc735c3731d8cebf71fd76eedec91Mark Andrews><P
1412643ba5bcc735c3731d8cebf71fd76eedec91Mark Andrews>Imagine <SPAN
1412643ba5bcc735c3731d8cebf71fd76eedec91Mark AndrewsCLASS="emphasis"
6de9371826bd253eb29aa3965ef03670d9d0a06dMark Andrews><I
6de9371826bd253eb29aa3965ef03670d9d0a06dMark AndrewsCLASS="emphasis"
6de9371826bd253eb29aa3965ef03670d9d0a06dMark Andrews>host1</I
6de9371826bd253eb29aa3965ef03670d9d0a06dMark Andrews></SPAN
6de9371826bd253eb29aa3965ef03670d9d0a06dMark Andrews> and <SPAN
daba3af103617ce4dd49bfdd0d9e07df7f22d08dMark AndrewsCLASS="emphasis"
daba3af103617ce4dd49bfdd0d9e07df7f22d08dMark Andrews><I
59d84d1b077678cb77f6cbcc53d8cfa60ff69cb7Mark AndrewsCLASS="emphasis"
59d84d1b077678cb77f6cbcc53d8cfa60ff69cb7Mark Andrews>host 2</I
59d84d1b077678cb77f6cbcc53d8cfa60ff69cb7Mark Andrews></SPAN
59d84d1b077678cb77f6cbcc53d8cfa60ff69cb7Mark Andrews> are
ac124a78a097a0840992c5726cbbdaf1448b6ab3Mark Andrewsboth servers. The following is added to each server's <TT
d76ed813a51465e5c47d521ab09ea20c06f1428dMark AndrewsCLASS="filename"
d76ed813a51465e5c47d521ab09ea20c06f1428dMark Andrews>named.conf</TT
b6d199bd6a505d84093874339056d9df4d21dfbcMark Andrews> file:</P
b6d199bd6a505d84093874339056d9df4d21dfbcMark Andrews><PRE
b6d199bd6a505d84093874339056d9df4d21dfbcMark AndrewsCLASS="programlisting"
b6d199bd6a505d84093874339056d9df4d21dfbcMark Andrews>&#13;key host1-host2. {
1d7b3b6dac1a0c6c586808c2add2ca2bef80512fMark Andrews algorithm hmac-md5;
1d7b3b6dac1a0c6c586808c2add2ca2bef80512fMark Andrews secret "La/E5CjG9O+os1jq0a2jdA==";
1d7b3b6dac1a0c6c586808c2add2ca2bef80512fMark Andrews};
1d7b3b6dac1a0c6c586808c2add2ca2bef80512fMark Andrews</PRE
f27eae9cfeb5b6c3c38ead6a7a0b1dd36bba691dMark Andrews><P
f27eae9cfeb5b6c3c38ead6a7a0b1dd36bba691dMark Andrews>The algorithm, hmac-md5, is the only one supported by <ACRONYM
f27eae9cfeb5b6c3c38ead6a7a0b1dd36bba691dMark AndrewsCLASS="acronym"
9a8cec4995c1586d27e95f13d421e4de61a97eb5Mark Andrews>BIND</ACRONYM
9a8cec4995c1586d27e95f13d421e4de61a97eb5Mark Andrews>.
9a8cec4995c1586d27e95f13d421e4de61a97eb5Mark AndrewsThe secret is the one generated above. Since this is a secret, it
25c18fded02c5df8391a333e90ea776b52bff079Mark Andrewsis recommended that either <TT
25c18fded02c5df8391a333e90ea776b52bff079Mark AndrewsCLASS="filename"
7042126e8a10315255144989f7723f0510558928Mark Andrews>named.conf</TT
7042126e8a10315255144989f7723f0510558928Mark Andrews> be non-world
7042126e8a10315255144989f7723f0510558928Mark Andrewsreadable, or the key directive be added to a non-world readable
7042126e8a10315255144989f7723f0510558928Mark Andrewsfile that is included by <TT
5581e28ed8c05350ce6119230c223da60dafdbafMark AndrewsCLASS="filename"
2c4ae1d331c98beba03a337a58e9b44aec98d663Mark Andrews>named.conf</TT
2c4ae1d331c98beba03a337a58e9b44aec98d663Mark Andrews>.</P
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews><P
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrews>At this point, the key is recognized. This means that if the
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrewsserver receives a message signed by this key, it can verify the
45e1bd63587102c3bb361eaca42ee7b714fb3542Mark Andrewssignature. If the signature is successfully verified, the
c4008fdd56a8045802ed125e40a06bf1df9b7fbeMark Andrewsresponse is signed by the same key.</P
c4008fdd56a8045802ed125e40a06bf1df9b7fbeMark Andrews></DIV
c4008fdd56a8045802ed125e40a06bf1df9b7fbeMark Andrews><DIV
c4008fdd56a8045802ed125e40a06bf1df9b7fbeMark AndrewsCLASS="sect2"
4f54d095945d6f60f146112d37d31815ad73eb02Mark Andrews><H2
4f54d095945d6f60f146112d37d31815ad73eb02Mark AndrewsCLASS="sect2"
4f54d095945d6f60f146112d37d31815ad73eb02Mark Andrews><A
472ce617b7c19ae38dfaa2fc9e8699e3bf9be4a8Mark AndrewsNAME="AEN894"
472ce617b7c19ae38dfaa2fc9e8699e3bf9be4a8Mark Andrews>4.5.4. Instructing the Server to Use the Key</A
472ce617b7c19ae38dfaa2fc9e8699e3bf9be4a8Mark Andrews></H2
c5387e694299c41361660e54f23e89c7da3ede1dMark Andrews><P
c5387e694299c41361660e54f23e89c7da3ede1dMark Andrews>Since keys are shared between two hosts only, the server must
d00e58d4814b45c13434721b5771782e485dcb73Mark Andrewsbe told when keys are to be used. The following is added to the <TT
d00e58d4814b45c13434721b5771782e485dcb73Mark AndrewsCLASS="filename"
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark Andrews>named.conf</TT
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark Andrews> file
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark Andrewsfor <SPAN
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark AndrewsCLASS="emphasis"
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark Andrews><I
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark AndrewsCLASS="emphasis"
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark Andrews>host1</I
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark Andrews></SPAN
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark Andrews>, if the IP address of <SPAN
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark AndrewsCLASS="emphasis"
f3a8cd3835463b47a8e3dc84cd8e7a02bcd7fee8Mark Andrews><I
3e9ab6efd14ad716e6815718207dac2bdef3fddfMark AndrewsCLASS="emphasis"
3e9ab6efd14ad716e6815718207dac2bdef3fddfMark Andrews>host2</I
3e9ab6efd14ad716e6815718207dac2bdef3fddfMark Andrews></SPAN
6e373c502584f9292e964378411d296c8259026bMark Andrews> is
6e373c502584f9292e964378411d296c8259026bMark Andrews10.1.2.3:</P
6e373c502584f9292e964378411d296c8259026bMark Andrews><PRE
3bf783a6d4627266d76b0ebdc05afdccb3d06ad0Mark AndrewsCLASS="programlisting"
3bf783a6d4627266d76b0ebdc05afdccb3d06ad0Mark Andrews>&#13;server 10.1.2.3 {
3bf783a6d4627266d76b0ebdc05afdccb3d06ad0Mark Andrews keys { host1-host2. ;};
3bf783a6d4627266d76b0ebdc05afdccb3d06ad0Mark Andrews};
a37e44f107f5f60d7e84de77eb33b13139bca03fMark Andrews</PRE
a37e44f107f5f60d7e84de77eb33b13139bca03fMark Andrews><P
a37e44f107f5f60d7e84de77eb33b13139bca03fMark Andrews>Multiple keys may be present, but only the first is used.
2a35dc09d6c14f4041116766c0f7b60f41be0c9eMark AndrewsThis directive does not contain any secrets, so it may be in a world-readable
2a35dc09d6c14f4041116766c0f7b60f41be0c9eMark Andrewsfile.</P
2a35dc09d6c14f4041116766c0f7b60f41be0c9eMark Andrews><P
d53520b78d4a8726396efdbaa71f86f687a6f308Mark Andrews>If <SPAN
d53520b78d4a8726396efdbaa71f86f687a6f308Mark AndrewsCLASS="emphasis"
d53520b78d4a8726396efdbaa71f86f687a6f308Mark Andrews><I
43501e6570e9081d459fb5c1a81b73c2c53c5df0Mark AndrewsCLASS="emphasis"
43501e6570e9081d459fb5c1a81b73c2c53c5df0Mark Andrews>host1</I
43501e6570e9081d459fb5c1a81b73c2c53c5df0Mark Andrews></SPAN
c2b2bd69faabd83143ffb30a132a2f20ebd9abdaMark Andrews> sends a message that is a request
c2b2bd69faabd83143ffb30a132a2f20ebd9abdaMark Andrewsto that address, the message will be signed with the specified key. <SPAN
d140ae28347065500e7efb1ebe884f1606f9ac7bMark AndrewsCLASS="emphasis"
d140ae28347065500e7efb1ebe884f1606f9ac7bMark Andrews><I
d3bcf7adca7fc4a019364b0195818673448072f7Mark AndrewsCLASS="emphasis"
d3bcf7adca7fc4a019364b0195818673448072f7Mark Andrews>host1</I
d3bcf7adca7fc4a019364b0195818673448072f7Mark Andrews></SPAN
cf029c9369548e598379490a039cfbc2b83527eeMark Andrews> will
7b52c2ad3c9ca65712e962ddc803e34641f2bc07Mark Andrewsexpect any responses to signed messages to be signed with the same
cf029c9369548e598379490a039cfbc2b83527eeMark Andrewskey.</P
c6d4f781529d2f28693546b25b2967d44ec89e60Mark Andrews><P
c6d4f781529d2f28693546b25b2967d44ec89e60Mark Andrews>A similar statement must be present in <SPAN
c6d4f781529d2f28693546b25b2967d44ec89e60Mark AndrewsCLASS="emphasis"
c9eaf357a31ea5eaeeed24f2f4e800a6ef9512e0Mark Andrews><I
c9eaf357a31ea5eaeeed24f2f4e800a6ef9512e0Mark AndrewsCLASS="emphasis"
c9eaf357a31ea5eaeeed24f2f4e800a6ef9512e0Mark Andrews>host2</I
3fc7753efdc33559978ce61785961b1305944077Mark Andrews></SPAN
82ecc9cd96239649dfeb0a16e31c3b978d0d266aMark Andrews>'s
3fc7753efdc33559978ce61785961b1305944077Mark Andrewsconfiguration file (with <SPAN
219a8f14a864aca47c340729dfff008a5050dd26Mark AndrewsCLASS="emphasis"
219a8f14a864aca47c340729dfff008a5050dd26Mark Andrews><I
219a8f14a864aca47c340729dfff008a5050dd26Mark AndrewsCLASS="emphasis"
d14e4f3a9916f2159de4c5995006195072e05085Mark Andrews>host1</I
d14e4f3a9916f2159de4c5995006195072e05085Mark Andrews></SPAN
d14e4f3a9916f2159de4c5995006195072e05085Mark Andrews>'s address) for <SPAN
fde1a334ee0d437ccbada347ff09e8ea0eaff221Mark AndrewsCLASS="emphasis"
fde1a334ee0d437ccbada347ff09e8ea0eaff221Mark Andrews><I
8549bc9b78d7664ac99436d36a1ce615f772378aMark AndrewsCLASS="emphasis"
8549bc9b78d7664ac99436d36a1ce615f772378aMark Andrews>host2</I
a957b9ccdccf519018e06213a27e1b70b8dc4640Mark Andrews></SPAN
4ff0e3c8afbbbc30473701c47d75e1d7829bae3eMark Andrews> to
4ff0e3c8afbbbc30473701c47d75e1d7829bae3eMark Andrewssign request messages to <SPAN
9a33e2d135b0de7d2e2d768f2b9c45b2627fe4e6Mark AndrewsCLASS="emphasis"
9a33e2d135b0de7d2e2d768f2b9c45b2627fe4e6Mark Andrews><I
9a33e2d135b0de7d2e2d768f2b9c45b2627fe4e6Mark AndrewsCLASS="emphasis"
7b52c2ad3c9ca65712e962ddc803e34641f2bc07Mark Andrews>host1</I
dc6da18ccbb808d21f123cc6bda399b44ad11445Mark Andrews></SPAN
94b58e01ae98764a045e18581d7aaf05d2889e60Mark Andrews>.</P
94b58e01ae98764a045e18581d7aaf05d2889e60Mark Andrews></DIV
94b58e01ae98764a045e18581d7aaf05d2889e60Mark Andrews><DIV
a687a0592bbe3a582860eb5f03725bf80d7ac1d8Mark AndrewsCLASS="sect2"
a687a0592bbe3a582860eb5f03725bf80d7ac1d8Mark Andrews><H2
a687a0592bbe3a582860eb5f03725bf80d7ac1d8Mark AndrewsCLASS="sect2"
a295fbb55cfed38bcf2853c60410cce52ab6cebbMark Andrews><A
a295fbb55cfed38bcf2853c60410cce52ab6cebbMark AndrewsNAME="AEN910"
a295fbb55cfed38bcf2853c60410cce52ab6cebbMark Andrews>4.5.5. TSIG Key Based Access Control</A
6eb8591f005f3e270d9ffb23769753952d0ec286Mark Andrews></H2
6eb8591f005f3e270d9ffb23769753952d0ec286Mark Andrews><P
6eb8591f005f3e270d9ffb23769753952d0ec286Mark Andrews><ACRONYM
a1bc94109313bf4ebb6e6ff655d71d45582d2e43Mark AndrewsCLASS="acronym"
a1bc94109313bf4ebb6e6ff655d71d45582d2e43Mark Andrews>BIND</ACRONYM
a1bc94109313bf4ebb6e6ff655d71d45582d2e43Mark Andrews> allows IP addresses and ranges to be specified in ACL
a1bc94109313bf4ebb6e6ff655d71d45582d2e43Mark Andrewsdefinitions and
d9c4f954a1ddf7fcd5bf86bb7bbc12f669f81507Mark Andrews<B
d9c4f954a1ddf7fcd5bf86bb7bbc12f669f81507Mark AndrewsCLASS="command"
d9c4f954a1ddf7fcd5bf86bb7bbc12f669f81507Mark Andrews>allow-{ query | transfer | update }</B
6657a9e2d8c039be0bec367cae59a91d77ccaad4Mark Andrews> directives.
6657a9e2d8c039be0bec367cae59a91d77ccaad4Mark AndrewsThis has been extended to allow TSIG keys also. The above key would
6657a9e2d8c039be0bec367cae59a91d77ccaad4Mark Andrewsbe denoted <B
118394ef2ec7cef253c55359a3d70d202ddc2fa0Mark AndrewsCLASS="command"
118394ef2ec7cef253c55359a3d70d202ddc2fa0Mark Andrews>key host1-host2.</B
118394ef2ec7cef253c55359a3d70d202ddc2fa0Mark Andrews></P
118394ef2ec7cef253c55359a3d70d202ddc2fa0Mark Andrews><P
6178552326050b16f5706ee63c931e9388d74318Mark Andrews>An example of an allow-update directive would be:</P
6178552326050b16f5706ee63c931e9388d74318Mark Andrews><PRE
69836f45cff130ab11a1f5a662e8bf8aaf390de2Mark AndrewsCLASS="programlisting"
08c90261660649ca7d92065f6f13a61ec5a9a86dMark Andrews>&#13;allow-update { key host1-host2. ;};
08c90261660649ca7d92065f6f13a61ec5a9a86dMark Andrews</PRE
08c90261660649ca7d92065f6f13a61ec5a9a86dMark Andrews><P
69836f45cff130ab11a1f5a662e8bf8aaf390de2Mark Andrews>This allows dynamic updates to succeed only if the request
08c90261660649ca7d92065f6f13a61ec5a9a86dMark Andrews was signed by a key named
08c90261660649ca7d92065f6f13a61ec5a9a86dMark Andrews "<B
08c90261660649ca7d92065f6f13a61ec5a9a86dMark AndrewsCLASS="command"
08c90261660649ca7d92065f6f13a61ec5a9a86dMark Andrews>host1-host2.</B
f8f65e2de40b1e9874b88f392f3abeb057ce6172Mark Andrews>".</P
f8f65e2de40b1e9874b88f392f3abeb057ce6172Mark Andrews><P
f8f65e2de40b1e9874b88f392f3abeb057ce6172Mark Andrews>You may want to read about the more
05d32f6b0f6590ca22136b753309f070ce769000Mark Andrews powerful <B
05d32f6b0f6590ca22136b753309f070ce769000Mark AndrewsCLASS="command"
05d32f6b0f6590ca22136b753309f070ce769000Mark Andrews>update-policy</B
05d32f6b0f6590ca22136b753309f070ce769000Mark Andrews> statement in <A
2b66a51a7d72e9cc07917fb583ad528b0539d2a3Mark AndrewsHREF="Bv9ARM.ch06.html#dynamic_update_policies"
2b66a51a7d72e9cc07917fb583ad528b0539d2a3Mark Andrews>Section 6.2.24.4</A
2b66a51a7d72e9cc07917fb583ad528b0539d2a3Mark Andrews>.</P
2b66a51a7d72e9cc07917fb583ad528b0539d2a3Mark Andrews></DIV
e9733bc599f30033ffe7af69f5fca254fb59d46eMark Andrews><DIV
e9733bc599f30033ffe7af69f5fca254fb59d46eMark AndrewsCLASS="sect2"
332ed11af0e9837421160ab67619e025520a73f4Mark Andrews><H2
332ed11af0e9837421160ab67619e025520a73f4Mark AndrewsCLASS="sect2"
332ed11af0e9837421160ab67619e025520a73f4Mark Andrews><A
332ed11af0e9837421160ab67619e025520a73f4Mark AndrewsNAME="AEN923"
fabf2ee6b01ee06a0de940b83d53cf57f9f79265Mark Andrews>4.5.6. Errors</A
fabf2ee6b01ee06a0de940b83d53cf57f9f79265Mark Andrews></H2
fabf2ee6b01ee06a0de940b83d53cf57f9f79265Mark Andrews><P
fabf2ee6b01ee06a0de940b83d53cf57f9f79265Mark Andrews>The processing of TSIG signed messages can result in
fabf2ee6b01ee06a0de940b83d53cf57f9f79265Mark Andrews several errors. If a signed message is sent to a non-TSIG aware
1c91b0a6516319d81670da2325e2bd08a7703707Mark Andrews server, a FORMERR will be returned, since the server will not
1c91b0a6516319d81670da2325e2bd08a7703707Mark Andrews understand the record. This is a result of misconfiguration,
1c91b0a6516319d81670da2325e2bd08a7703707Mark Andrews since the server must be explicitly configured to send a TSIG
2a90390deeff6ba07125bfb2c81ab4b582eb2777Mark Andrews signed message to a specific server.</P
95b484c9580d06eb2f9735a22e9841389c2859baMark Andrews><P
2a90390deeff6ba07125bfb2c81ab4b582eb2777Mark Andrews>If a TSIG aware server receives a message signed by an
2a90390deeff6ba07125bfb2c81ab4b582eb2777Mark Andrews unknown key, the response will be unsigned with the TSIG
be2c2c29a88db96bd51f11d671ec207f0b6b0d45Mark Andrews extended error code set to BADKEY. If a TSIG aware server
be2c2c29a88db96bd51f11d671ec207f0b6b0d45Mark Andrews receives a message with a signature that does not validate, the
be2c2c29a88db96bd51f11d671ec207f0b6b0d45Mark Andrews response will be unsigned with the TSIG extended error code set
01db0feafa67200a07ff8f81dde9029f675bbb5cMark Andrews to BADSIG. If a TSIG aware server receives a message with a time
503ab4e136b843ef431f904709698231f1bc39e3Mark Andrews outside of the allowed range, the response will be signed with
503ab4e136b843ef431f904709698231f1bc39e3Mark Andrews the TSIG extended error code set to BADTIME, and the time values
cf224bbf7bab87bc28b12f5b30f5ca3f3e5bf604Mark Andrews will be adjusted so that the response can be successfully
cf224bbf7bab87bc28b12f5b30f5ca3f3e5bf604Mark Andrews verified. In any of these cases, the message's rcode is set to
cf224bbf7bab87bc28b12f5b30f5ca3f3e5bf604Mark Andrews NOTAUTH.</P
cf224bbf7bab87bc28b12f5b30f5ca3f3e5bf604Mark Andrews></DIV
00afe78ab290fec3041731c1fac146a24f556de4Mark Andrews></DIV
00afe78ab290fec3041731c1fac146a24f556de4Mark Andrews><DIV
00afe78ab290fec3041731c1fac146a24f556de4Mark AndrewsCLASS="sect1"
2674e1a455d4f71de09b2b60e7a8304b9a305588Mark Andrews><H1
2674e1a455d4f71de09b2b60e7a8304b9a305588Mark AndrewsCLASS="sect1"
2674e1a455d4f71de09b2b60e7a8304b9a305588Mark Andrews><A
60ab03125c137c48a6b2ed6df1d2c8657757e09dMark AndrewsNAME="AEN927"
60ab03125c137c48a6b2ed6df1d2c8657757e09dMark Andrews>4.6. TKEY</A
60ab03125c137c48a6b2ed6df1d2c8657757e09dMark Andrews></H1
60ab03125c137c48a6b2ed6df1d2c8657757e09dMark Andrews><P
60ab03125c137c48a6b2ed6df1d2c8657757e09dMark Andrews><B
60ab03125c137c48a6b2ed6df1d2c8657757e09dMark AndrewsCLASS="command"
60ab03125c137c48a6b2ed6df1d2c8657757e09dMark Andrews>TKEY</B
405ae948cc01c5fb9fee511ce32de86f8077e01bMark Andrews> is a mechanism for automatically
405ae948cc01c5fb9fee511ce32de86f8077e01bMark Andrews generating a shared secret between two hosts. There are several
57e4191a112bf57a1eab6d37212df2531b6f8a16Mark Andrews "modes" of <B
7d116211ec7b063891130f191e3ed437b45dba70Mark AndrewsCLASS="command"
faa4af28cff84d7ac45c1da98e40c00f65a24aa3Mark Andrews>TKEY</B
faa4af28cff84d7ac45c1da98e40c00f65a24aa3Mark Andrews> that specify how the key is
faa4af28cff84d7ac45c1da98e40c00f65a24aa3Mark Andrews generated or assigned. <ACRONYM
faa4af28cff84d7ac45c1da98e40c00f65a24aa3Mark AndrewsCLASS="acronym"
faa4af28cff84d7ac45c1da98e40c00f65a24aa3Mark Andrews>BIND</ACRONYM
faa4af28cff84d7ac45c1da98e40c00f65a24aa3Mark Andrews> 9
eba8a27e55258ee4470d7c3caa6bb3a335b9731eMark Andrews implements only one of these modes,
203629e729b756601646c639c0dbfb267030a617Mark Andrews the Diffie-Hellman key exchange. Both hosts are required to have
8af4e7aa4e2a6fe84bf4ebe09ca1d4ef1d8ab593Mark Andrews a Diffie-Hellman KEY record (although this record is not required
8af4e7aa4e2a6fe84bf4ebe09ca1d4ef1d8ab593Mark Andrews to be present in a zone). The <B
d08c5dfcd4d1f69004c1382ffc00cc1848dcd1a3Mark AndrewsCLASS="command"
d08c5dfcd4d1f69004c1382ffc00cc1848dcd1a3Mark Andrews>TKEY</B
982a2cfef37a39842ff53dc2e00b947c554fa78eTatuya JINMEI 神明達哉> process
16ee4fe11bad616a76c79e9f626a7e04a88ef4abMark Andrews must use signed messages, signed either by TSIG or SIG(0). The
16ee4fe11bad616a76c79e9f626a7e04a88ef4abMark Andrews result of <B
16ee4fe11bad616a76c79e9f626a7e04a88ef4abMark AndrewsCLASS="command"
16ee4fe11bad616a76c79e9f626a7e04a88ef4abMark Andrews>TKEY</B
a5b66bf342440688739d7207e437bf743e8b7ac0Mark Andrews> is a shared secret that can be
a5b66bf342440688739d7207e437bf743e8b7ac0Mark Andrews used to sign messages with TSIG. <B
982e072a5000bfc072aee8b34f64112cf54369a5Mark AndrewsCLASS="command"
982e072a5000bfc072aee8b34f64112cf54369a5Mark Andrews>TKEY</B
982e072a5000bfc072aee8b34f64112cf54369a5Mark Andrews> can also
e24089c5c33f31a39cea0123765165fa31308343Tatuya JINMEI 神明達哉 be used to delete shared secrets that it had previously
9547d3e03bb082d73aeabb497b60632ebfdc78a6Mark Andrews generated.</P
6f3c2ee187d690f96ffef3ba5a6c2e112bb3798cMark Andrews><P
6f3c2ee187d690f96ffef3ba5a6c2e112bb3798cMark Andrews>The <B
9547d3e03bb082d73aeabb497b60632ebfdc78a6Mark AndrewsCLASS="command"
9de05727e334336ceb0abcca404d770abd23b876Mark Andrews>TKEY</B
9de05727e334336ceb0abcca404d770abd23b876Mark Andrews> process is initiated by a client
9de05727e334336ceb0abcca404d770abd23b876Mark Andrews or server by sending a signed <B
7c61d798f54f7c19f87d46a0df775e0e58fe7d30Mark AndrewsCLASS="command"
7c61d798f54f7c19f87d46a0df775e0e58fe7d30Mark Andrews>TKEY</B
e23932d3c8c154cff3fea0ecff64e26c6ac6f5d8Mark Andrews> query
e23932d3c8c154cff3fea0ecff64e26c6ac6f5d8Mark Andrews (including any appropriate KEYs) to a TKEY-aware server. The
72160d9b51d902a7cf18de84953bc651941f73c2Mark Andrews server response, if it indicates success, will contain a
72160d9b51d902a7cf18de84953bc651941f73c2Mark Andrews <B
72160d9b51d902a7cf18de84953bc651941f73c2Mark AndrewsCLASS="command"
885e60828681cecd17bccbe5ceff8f4e75ef4c5cMark Andrews>TKEY</B
8ec056723666c71a499880ffa415661f37ffd08eMark Andrews> record and any appropriate keys. After
8ec056723666c71a499880ffa415661f37ffd08eMark Andrews this exchange, both participants have enough information to
037b732f88edc943f3141e0342dc993156e3abf3Mark Andrews determine the shared secret; the exact process depends on the
80a609bf44ee09766aeb9ae02cfbf7f9fe86dd83Mark Andrews <B
80a609bf44ee09766aeb9ae02cfbf7f9fe86dd83Mark AndrewsCLASS="command"
80a609bf44ee09766aeb9ae02cfbf7f9fe86dd83Mark Andrews>TKEY</B
b89095ba15e9163f2bacc46239d8f69d1a2b9ad3Tatuya JINMEI 神明達哉> mode. When using the Diffie-Hellman
b89095ba15e9163f2bacc46239d8f69d1a2b9ad3Tatuya JINMEI 神明達哉 <B
b89095ba15e9163f2bacc46239d8f69d1a2b9ad3Tatuya JINMEI 神明達哉CLASS="command"
bd5c8a564b21781fe6b608fe6a75c2e7152200acTatuya JINMEI 神明達哉>TKEY</B
85708f9aabbfe31fc648c90258ae18ce0edc3488Mark Andrews> mode, Diffie-Hellman keys are exchanged,
85708f9aabbfe31fc648c90258ae18ce0edc3488Mark Andrews and the shared secret is derived by both participants.</P
49732e4d6008d7d99dfce596a17e17aa13425502Mark Andrews></DIV
49732e4d6008d7d99dfce596a17e17aa13425502Mark Andrews><DIV
49732e4d6008d7d99dfce596a17e17aa13425502Mark AndrewsCLASS="sect1"
cae2cb086244dfb883739edbe79e34756079f70eMark Andrews><H1
cae2cb086244dfb883739edbe79e34756079f70eMark AndrewsCLASS="sect1"
cf0bcc2c80ca99f1e6e53dcdd0eba03fe70723dfMark Andrews><A
cf0bcc2c80ca99f1e6e53dcdd0eba03fe70723dfMark AndrewsNAME="AEN942"
0da29be670f6fa5b2a6320d9d843bc8b802c153aMark Andrews>4.7. SIG(0)</A
0da29be670f6fa5b2a6320d9d843bc8b802c153aMark Andrews></H1
0da29be670f6fa5b2a6320d9d843bc8b802c153aMark Andrews><P
0da29be670f6fa5b2a6320d9d843bc8b802c153aMark Andrews><ACRONYM
03e200df5dc283f24a6a349f0b31d3eab26da893Mark AndrewsCLASS="acronym"
03e200df5dc283f24a6a349f0b31d3eab26da893Mark Andrews>BIND</ACRONYM
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews> 9 partially supports DNSSEC SIG(0)
6672b3524c2305d8c66d8189c774f549be352ac0Mark Andrews transaction signatures as specified in RFC 2535 and RFC2931. SIG(0)
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews uses public/private keys to authenticate messages. Access control
74f261bd2b7846d8e730ca3a1b28d6503de5c74aMark Andrews is performed in the same manner as TSIG keys; privileges can be
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews granted or denied based on the key name.</P
5be3685b0e57677c0cc03113099cb8f99f9a070bMark Andrews><P
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews>When a SIG(0) signed message is received, it will only be
5be3685b0e57677c0cc03113099cb8f99f9a070bMark Andrews verified if the key is known and trusted by the server; the server
5be3685b0e57677c0cc03113099cb8f99f9a070bMark Andrews will not attempt to locate and/or validate the key.</P
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews><P
715361d0c3800e5ad886e5df971936ce6cd1ca89Mark Andrews>SIG(0) signing of multiple-message TCP streams is not
715361d0c3800e5ad886e5df971936ce6cd1ca89Mark Andrews supported.</P
715361d0c3800e5ad886e5df971936ce6cd1ca89Mark Andrews><P
715361d0c3800e5ad886e5df971936ce6cd1ca89Mark Andrews>The only tool shipped with <ACRONYM
539f477cd03db1ac173bcb5257da136283e57849Mark AndrewsCLASS="acronym"
3d711f2f75cb9a9ddcbf1fca9b2de192e75340e6Mark Andrews>BIND</ACRONYM
3d711f2f75cb9a9ddcbf1fca9b2de192e75340e6Mark Andrews> 9 that
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews generates SIG(0) signed messages is <B
a268fec7f54a89a0772a91da0511c8eae09e6157Mark AndrewsCLASS="command"
a268fec7f54a89a0772a91da0511c8eae09e6157Mark Andrews>nsupdate</B
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews>.</P
4e1d3e67cdc76609bad5f0310ac48de10b442b9fMark Andrews></DIV
4e1d3e67cdc76609bad5f0310ac48de10b442b9fMark Andrews><DIV
4e1d3e67cdc76609bad5f0310ac48de10b442b9fMark AndrewsCLASS="sect1"
4e1d3e67cdc76609bad5f0310ac48de10b442b9fMark Andrews><H1
539f477cd03db1ac173bcb5257da136283e57849Mark AndrewsCLASS="sect1"
6b79e960e6ba2991aeb02a6c39af255ab7f06d99Mark Andrews><A
6b79e960e6ba2991aeb02a6c39af255ab7f06d99Mark AndrewsNAME="DNSSEC"
6b79e960e6ba2991aeb02a6c39af255ab7f06d99Mark Andrews>4.8. DNSSEC</A
6b79e960e6ba2991aeb02a6c39af255ab7f06d99Mark Andrews></H1
6b79e960e6ba2991aeb02a6c39af255ab7f06d99Mark Andrews><P
6b79e960e6ba2991aeb02a6c39af255ab7f06d99Mark Andrews>Cryptographic authentication of DNS information is possible
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews through the DNS Security (<SPAN
74a14c4eb8518a9cc31cb5a918547a93d0c0e838Mark AndrewsCLASS="emphasis"
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews><I
261a6a1f7d95eaf0cd882f3123dcfd775517a54fMark AndrewsCLASS="emphasis"
261a6a1f7d95eaf0cd882f3123dcfd775517a54fMark Andrews>DNSSEC-bis</I
261a6a1f7d95eaf0cd882f3123dcfd775517a54fMark Andrews></SPAN
261a6a1f7d95eaf0cd882f3123dcfd775517a54fMark Andrews>) extensions,
261a6a1f7d95eaf0cd882f3123dcfd775517a54fMark Andrews defined in RFC &#60;TBA&#62;. This section describes the creation and use
261a6a1f7d95eaf0cd882f3123dcfd775517a54fMark Andrews of DNSSEC signed zones.</P
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews><P
7c678cfe0bd477ded2995b9490d72edf7bc76a84Mark Andrews>In order to set up a DNSSEC secure zone, there are a series
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews of steps which must be followed. <ACRONYM
a20e888bde4b307050d76e09266b2fb49f03bc30Mark AndrewsCLASS="acronym"
a20e888bde4b307050d76e09266b2fb49f03bc30Mark Andrews>BIND</ACRONYM
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews> 9 ships
f4f0eedb8916a824124cf56d4c3f18eb6c77b42eMark Andrews with several tools
f4f0eedb8916a824124cf56d4c3f18eb6c77b42eMark Andrews that are used in this process, which are explained in more detail
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews below. In all cases, the <VAR
611ec5dd43d31fd6385f1a94c2f0865375f452b4Mark AndrewsCLASS="option"
611ec5dd43d31fd6385f1a94c2f0865375f452b4Mark Andrews>-h</VAR
7b52c2ad3c9ca65712e962ddc803e34641f2bc07Mark Andrews> option prints a
01b8bc018d83e757b0578723977b0a71e1e626f8Mark Andrews full list of parameters. Note that the DNSSEC tools require the
01b8bc018d83e757b0578723977b0a71e1e626f8Mark Andrews keyset files to be in the working directory or the
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews directory specified by the <VAR
8abe06b25d245ab2955d81525bfe6bd29b80908eMark AndrewsCLASS="option"
8abe06b25d245ab2955d81525bfe6bd29b80908eMark Andrews>-h</VAR
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews> option, and
7755f5932a3e59d0c6a2506cc94519de92b91ca6Mark Andrews that the tools shipped with BIND 9.2.x and earlier are not compatible
7755f5932a3e59d0c6a2506cc94519de92b91ca6Mark Andrews with the current ones.</P
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews><P
b5ad6dfea4cc3e7d1d322ac99f1e5a31096837c4Mark Andrews>There must also be communication with the administrators of
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews the parent and/or child zone to transmit keys. A zone's security
6e9efadbea9febb0494e713e54dfea6f7ef70383Mark Andrews status must be indicated by the parent zone for a DNSSEC capable
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews resolver to trust its data. This is done through the presense
aa0f0779d1ea7150991c3e6eec1cc532086c13fdMark Andrews or absence of a <VAR
539f477cd03db1ac173bcb5257da136283e57849Mark AndrewsCLASS="literal"
18d0b5e54be891a1aa938c165b6d439859121ec8Mark Andrews>DS</VAR
18d0b5e54be891a1aa938c165b6d439859121ec8Mark Andrews> record at the delegation
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews point.</P
0563d476dea35a60a59857cc8bd26ef276d78799Mark Andrews><P
0563d476dea35a60a59857cc8bd26ef276d78799Mark Andrews>For other servers to trust data in this zone, they must
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews either be statically configured with this zone's zone key or the
b2f160f266005ceaed77a3f575109f74cd13d548Mark Andrews zone key of another zone above this one in the DNS tree.</P
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews><DIV
0bb7c66ef8e3e8740cbac4a4de607060dfc4d6c8Mark AndrewsCLASS="sect2"
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews><H2
2b3e34f03675d6c71a654fe2094f3b9c063a70eaMark AndrewsCLASS="sect2"
2b3e34f03675d6c71a654fe2094f3b9c063a70eaMark Andrews><A
539f477cd03db1ac173bcb5257da136283e57849Mark AndrewsNAME="AEN962"
7216566bd596f8fbc98eafd5e9359ec7fa92c8b8Mark Andrews>4.8.1. Generating Keys</A
7216566bd596f8fbc98eafd5e9359ec7fa92c8b8Mark Andrews></H2
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews><P
42b37d29c7709ce5bfe0110d07f1ec163be220d2Mark Andrews>The <B
42b37d29c7709ce5bfe0110d07f1ec163be220d2Mark AndrewsCLASS="command"
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews>dnssec-keygen</B
42b37d29c7709ce5bfe0110d07f1ec163be220d2Mark Andrews> program is used to
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews generate keys.</P
7c386b0c3194aa18089c6fa2e9856b576ec99c81Mark Andrews><P
7c386b0c3194aa18089c6fa2e9856b576ec99c81Mark Andrews>A secure zone must contain one or more zone keys. The
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews zone keys will sign all other records in the zone, as well as
fd780f3d47179d68ba2d4661fb9cac9ce1e74928Mark Andrews the zone keys of any secure delegated zones. Zone keys must
fd780f3d47179d68ba2d4661fb9cac9ce1e74928Mark Andrews have the same name as the zone, a name type of
fd780f3d47179d68ba2d4661fb9cac9ce1e74928Mark Andrews <B
fd780f3d47179d68ba2d4661fb9cac9ce1e74928Mark AndrewsCLASS="command"
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews>ZONE</B
2bef3713093349af52ba61eaab07adf3207da873Mark Andrews>, and must be usable for authentication.
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews It is recommended that zone keys use a cryptographic algorithm
bcf369e513a1cc2209e2a987f5772afa79813540Mark Andrews designated as "mandatory to implement" by the IETF; currently
bcf369e513a1cc2209e2a987f5772afa79813540Mark Andrews the only one is RSASHA1.</P
bcf369e513a1cc2209e2a987f5772afa79813540Mark Andrews><P
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews>The following command will generate a 768 bit RSASHA1 key for
016c0a82f1ce3fe4d362d7c9cf8de4377ffaf5a9Mark Andrews the <TT
016c0a82f1ce3fe4d362d7c9cf8de4377ffaf5a9Mark AndrewsCLASS="filename"
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews>child.example</TT
ad226e3da3207fcb1dbb1054dd339dbbd19f507aMark Andrews> zone:</P
016c0a82f1ce3fe4d362d7c9cf8de4377ffaf5a9Mark Andrews><P
9b80f3a7c739a99b498a37a711a51b6a88df3a78Mark Andrews><KBD
539f477cd03db1ac173bcb5257da136283e57849Mark AndrewsCLASS="userinput"
83a56f1e4f2d11fa895ceff4342fff7157910036Mark Andrews>dnssec-keygen -a RSASHA1 -b 768 -n ZONE child.example.</KBD
83a56f1e4f2d11fa895ceff4342fff7157910036Mark Andrews></P
83a56f1e4f2d11fa895ceff4342fff7157910036Mark Andrews><P
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews>Two output files will be produced:
1425217e5c3a2cbab7f8344e600e0c16047289ffMark Andrews <TT
d4d68515d23668cfe804ab2a174a7e427decedd8Mark AndrewsCLASS="filename"
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews>Kchild.example.+005+12345.key</TT
e8e62bb7829e88fc56360f7edc021dc8493a8704Mark Andrews> and
e8e62bb7829e88fc56360f7edc021dc8493a8704Mark Andrews <TT
539f477cd03db1ac173bcb5257da136283e57849Mark AndrewsCLASS="filename"
e7fb847ed570dd8c1bcdacabb3d69bd81feb79aeMark Andrews>Kchild.example.+005+12345.private</TT
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews> (where
ab9871e71eac6b33ce92a0ad26dc50d0ff241e3bMark Andrews 12345 is an example of a key tag). The key file names contain
ab9871e71eac6b33ce92a0ad26dc50d0ff241e3bMark Andrews the key name (<TT
539f477cd03db1ac173bcb5257da136283e57849Mark AndrewsCLASS="filename"
ab9871e71eac6b33ce92a0ad26dc50d0ff241e3bMark Andrews>child.example.</TT
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews>), algorithm (3
2c6f9101f99cc663074376a5cc1d954d33bdbe36Mark Andrews is DSA, 1 is RSAMD5, 5 is RSASHA1, etc.), and the key tag (12345 in this case).
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews The private key (in the <TT
116e6b4257e3efceca3e82af1e695579129af93dMark AndrewsCLASS="filename"
1fc4793844c9613b17866c33dbeab8aaa94b66ffMark Andrews>.private</TT
539f477cd03db1ac173bcb5257da136283e57849Mark Andrews> file) is
116e6b4257e3efceca3e82af1e695579129af93dMark Andrews used to generate signatures, and the public key (in the
1fc4793844c9613b17866c33dbeab8aaa94b66ffMark Andrews <TT
1c153afce556ff3c687986fb7c4a0b0a7f5e7cd8Mark AndrewsCLASS="filename"
1c153afce556ff3c687986fb7c4a0b0a7f5e7cd8Mark Andrews>.key</TT
81bdad57bd2c0c4b9a0684fe6e222ba95da625ecMark Andrews> file) is used for signature
116e6b4257e3efceca3e82af1e695579129af93dMark Andrews verification.</P
116e6b4257e3efceca3e82af1e695579129af93dMark Andrews><P
a5768d889b4e139e78f2b1d9433f3e9f8d225ff4Mark Andrews>To generate another key with the same properties (but with
3d247992c4a500caa7703edaee68612e545af602Mark Andrews a different key tag), repeat the above command.</P
3d247992c4a500caa7703edaee68612e545af602Mark Andrews><P
5c08d19fb17f0684e6424b94910cef61cec7592fMark Andrews>The public keys should be inserted into the zone file by
3d247992c4a500caa7703edaee68612e545af602Mark Andrews including the <TT
3d247992c4a500caa7703edaee68612e545af602Mark AndrewsCLASS="filename"
5c08d19fb17f0684e6424b94910cef61cec7592fMark Andrews>.key</TT
9eca2b9b95df456545e1bc298c8337400aa24e8eMark Andrews> files using
9eca2b9b95df456545e1bc298c8337400aa24e8eMark Andrews <B
9eca2b9b95df456545e1bc298c8337400aa24e8eMark AndrewsCLASS="command"
cd5f6549b33bf2481538b77934d69313f452ff4bMark Andrews>$INCLUDE</B
05331ce161276d879711342fadbc6144af7f5ba6Mark Andrews> statements.
05331ce161276d879711342fadbc6144af7f5ba6Mark Andrews </P
c5223c9cb7c22620d5ee6611228673e95b48a270Mark Andrews></DIV
c5223c9cb7c22620d5ee6611228673e95b48a270Mark Andrews><DIV
c5223c9cb7c22620d5ee6611228673e95b48a270Mark AndrewsCLASS="sect2"
c5223c9cb7c22620d5ee6611228673e95b48a270Mark Andrews><H2
c5223c9cb7c22620d5ee6611228673e95b48a270Mark AndrewsCLASS="sect2"
c5223c9cb7c22620d5ee6611228673e95b48a270Mark Andrews><A
c5223c9cb7c22620d5ee6611228673e95b48a270Mark AndrewsNAME="AEN982"
2fa0485e9e969dd42dd10339354d7949db46111aMark Andrews>4.8.2. Signing the Zone</A
2fa0485e9e969dd42dd10339354d7949db46111aMark Andrews></H2
092f7679306989293bbe755f31ade0a5f456b370Mark Andrews><P
7d5b32acb1898844afa19123d07483b46edac7cbMark Andrews>The <B
7d5b32acb1898844afa19123d07483b46edac7cbMark AndrewsCLASS="command"
437404e8313481329baa5897eeda8c45bf748553Mark Andrews>dnssec-signzone</B
ef67e6d8fa86d98a2c0defc43b624434324d9ce7Mark Andrews> program is used to
841fc0fd70881499b62f15e35980dd14b905ba45Mark Andrews sign a zone.</P
e5a5c60a5e690ee9858c9e3facba189b8646f0b7Mark Andrews><P
e5a5c60a5e690ee9858c9e3facba189b8646f0b7Mark Andrews>Any <TT
e5a5c60a5e690ee9858c9e3facba189b8646f0b7Mark AndrewsCLASS="filename"
16b9ee24b96a1c1d21d809e88238091c4afa25c9Mark Andrews>keyset</TT
16b9ee24b96a1c1d21d809e88238091c4afa25c9Mark Andrews> files corresponding
afa3f2fab7144761bbf481b9d40d667529c6ec76Mark Andrews to secure subzones should be present. The zone signer will
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein generate <VAR
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="literal"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>NSEC</VAR
da53179d1055c75e64dc2c9623b38cb2b8629eb6Mark Andrews> and <VAR
da53179d1055c75e64dc2c9623b38cb2b8629eb6Mark AndrewsCLASS="literal"
da53179d1055c75e64dc2c9623b38cb2b8629eb6Mark Andrews>RRSIG</VAR
2941824604f9c5aa70f216d1f2941b3c59aa37dcMark Andrews>
b4028939fdffc92cf659764deb9c6e3c805cc948Mark Andrews records for the zone, as well as <VAR
b4028939fdffc92cf659764deb9c6e3c805cc948Mark AndrewsCLASS="literal"
b4028939fdffc92cf659764deb9c6e3c805cc948Mark Andrews>DS</VAR
9840a0767d02f6c6b9d1f73d54e0cab2e8192a93Mark Andrews> for
9840a0767d02f6c6b9d1f73d54e0cab2e8192a93Mark Andrews the child zones if <VAR
9840a0767d02f6c6b9d1f73d54e0cab2e8192a93Mark AndrewsCLASS="literal"
57ed0bab5b92f66af3dc3b86081bd42ab8d4ba09Rob Austein>'-d'</VAR
57ed0bab5b92f66af3dc3b86081bd42ab8d4ba09Rob Austein> is specified.
57ed0bab5b92f66af3dc3b86081bd42ab8d4ba09Rob Austein If <VAR
ab023a65562e62b85a824509d829b6fad87e00b1Rob AusteinCLASS="literal"
ab023a65562e62b85a824509d829b6fad87e00b1Rob Austein>'-d'</VAR
1cb73c69f76c8c2c66b767a8b9ad04f3988cf6a9Mark Andrews> is not specified then DS RRsets for
1cb73c69f76c8c2c66b767a8b9ad04f3988cf6a9Mark Andrews the secure child zones need to be added manually.</P
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews><P
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews>The following command signs the zone, assuming it is in a
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews file called <TT
f754fa97bc698cc251d227173a95e4d39a88ac01Mark AndrewsCLASS="filename"
f754fa97bc698cc251d227173a95e4d39a88ac01Mark Andrews>zone.child.example</TT
a8f1c013b0fdc405ca4b5ec8316d3c9e3ad9d31bMark Andrews>. By
40a547174fb7d14f74bc375f076c8c390498f68eMark Andrews default, all zone keys which have an available private key are
a8f1c013b0fdc405ca4b5ec8316d3c9e3ad9d31bMark Andrews used to generate signatures.</P
a8f1c013b0fdc405ca4b5ec8316d3c9e3ad9d31bMark Andrews><P
959fb01017fa83578e7c8776ed3baba3076a2409Mark Andrews><KBD
959fb01017fa83578e7c8776ed3baba3076a2409Mark AndrewsCLASS="userinput"
959fb01017fa83578e7c8776ed3baba3076a2409Mark Andrews>dnssec-signzone -o child.example zone.child.example</KBD
d73541ea2eebe01cafc5ff1b2ba4b9a8f75237b1Mark Andrews></P
d73541ea2eebe01cafc5ff1b2ba4b9a8f75237b1Mark Andrews><P
d73541ea2eebe01cafc5ff1b2ba4b9a8f75237b1Mark Andrews>One output file is produced:
46cb442c5c53f16ece23bfe7f7f7bf44f78b0e46Mark Andrews <TT
0f222d322b25373c4ef59d7c79f265b082ee98cdMark AndrewsCLASS="filename"
0f222d322b25373c4ef59d7c79f265b082ee98cdMark Andrews>zone.child.example.signed</TT
0f222d322b25373c4ef59d7c79f265b082ee98cdMark Andrews>. This file
0f222d322b25373c4ef59d7c79f265b082ee98cdMark Andrews should be referenced by <TT
0f222d322b25373c4ef59d7c79f265b082ee98cdMark AndrewsCLASS="filename"
0f222d322b25373c4ef59d7c79f265b082ee98cdMark Andrews>named.conf</TT
ae4f85dde3abb7d4afef9e869a83783cbf0aa29cMark Andrews> as the
ae4f85dde3abb7d4afef9e869a83783cbf0aa29cMark Andrews input file for the zone.</P
ae4f85dde3abb7d4afef9e869a83783cbf0aa29cMark Andrews><P
ae4f85dde3abb7d4afef9e869a83783cbf0aa29cMark Andrews><B
ae4f85dde3abb7d4afef9e869a83783cbf0aa29cMark AndrewsCLASS="command"
2132a56b5c6628925838165ae0640e55e3f36188Mark Andrews>dnssec-signzone</B
2132a56b5c6628925838165ae0640e55e3f36188Mark Andrews> will also produce a
b514e0cd0e7959a98dd59665553c8a3635ada10eMark Andrews keyset and dsset files and optionally a dlvset file. These
b514e0cd0e7959a98dd59665553c8a3635ada10eMark Andrews are used to provide the parent zone administators with the
30884083d4149a8ff838b84dac1ad55c86948da8Mark Andrews <VAR
d9ec2891475b8ed894a524a83370cfce30328569Mark AndrewsCLASS="literal"
6e8a8077faf96d8da0b6cf738913f5f1f86e4008Mark Andrews>DNSKEYs</VAR
6e8a8077faf96d8da0b6cf738913f5f1f86e4008Mark Andrews> (or their corresponding <VAR
5cb7e15551f502ab6948689cf3bc7dac6b56571eMark AndrewsCLASS="literal"
5cb7e15551f502ab6948689cf3bc7dac6b56571eMark Andrews>DS</VAR
bb99a72b219ad4f1daa80c636883ab485174c9a6Mark Andrews>
bb99a72b219ad4f1daa80c636883ab485174c9a6Mark Andrews records) that are the secure entry point to the zone.</P
5a6874e4ed544186ccb8519765be8c3a1804e033Mark Andrews></DIV
3b4405aba93729eead9f8f006d426f24fc4c3d78Mark Andrews><DIV
3b4405aba93729eead9f8f006d426f24fc4c3d78Mark AndrewsCLASS="sect2"
2ab6dfca4b7432de4fb7da4cd21ee0e02a695c01Mark Andrews><H2
c553b3308e34edfaddbec57b3308bbbe362ef715Mark AndrewsCLASS="sect2"
c553b3308e34edfaddbec57b3308bbbe362ef715Mark Andrews><A
24efdccd68d157b400bf68926798bc8f3f71c24cMark AndrewsNAME="AEN1004"
24efdccd68d157b400bf68926798bc8f3f71c24cMark Andrews>4.8.3. Configuring Servers</A
a5bb4ad5dbd08f9178e807b1e55cb449b69d8173Mark Andrews></H2
a5bb4ad5dbd08f9178e807b1e55cb449b69d8173Mark Andrews><P
5e5b467e8c8abda496b7896241a46b05256cd22cMark Andrews>Unlike <ACRONYM
5e5b467e8c8abda496b7896241a46b05256cd22cMark AndrewsCLASS="acronym"
713ad87a7f95d06f4bb3e0b92b91172cbebd6c68Mark Andrews>BIND</ACRONYM
713ad87a7f95d06f4bb3e0b92b91172cbebd6c68Mark Andrews> 8,
713ad87a7f95d06f4bb3e0b92b91172cbebd6c68Mark Andrews<ACRONYM
cb2d565b507027f9e5664fa7e167bb24faa7c8fbMark AndrewsCLASS="acronym"
cb2d565b507027f9e5664fa7e167bb24faa7c8fbMark Andrews>BIND</ACRONYM
4f21f7feaff27d5356827e39a4537a60a5e4054cMark Andrews> 9 does not verify signatures on load,
4f21f7feaff27d5356827e39a4537a60a5e4054cMark Andrewsso zone keys for authoritative zones do not need to be specified
1439214380abcc123e27a42d43a23ba441209ebeMark Andrewsin the configuration file.</P
1439214380abcc123e27a42d43a23ba441209ebeMark Andrews><P
7d9b632906c756b215d65a3a08d77fe022807c2dMark Andrews>The public key for any security root must be present in
7d9b632906c756b215d65a3a08d77fe022807c2dMark Andrewsthe configuration file's <B
7d9b632906c756b215d65a3a08d77fe022807c2dMark AndrewsCLASS="command"
5d3083c4b5b11dfb653b15fd0eeb8e0cc9b175e0Mark Andrews>trusted-keys</B
5d3083c4b5b11dfb653b15fd0eeb8e0cc9b175e0Mark Andrews>
52188225731669cd571984c45a1407a55c74ee78Mark Andrewsstatement, as described later in this document. </P
52188225731669cd571984c45a1407a55c74ee78Mark Andrews></DIV
52188225731669cd571984c45a1407a55c74ee78Mark Andrews></DIV
52188225731669cd571984c45a1407a55c74ee78Mark Andrews><DIV
52188225731669cd571984c45a1407a55c74ee78Mark AndrewsCLASS="sect1"
3cbc87c31f76262980d54ddbcdda7875be37b684Mark Andrews><H1
bc29bb9062ab804cd79f4a1f8f366af8a040b636Mark AndrewsCLASS="sect1"
bc29bb9062ab804cd79f4a1f8f366af8a040b636Mark Andrews><A
bc29bb9062ab804cd79f4a1f8f366af8a040b636Mark AndrewsNAME="AEN1011"
5a4854e226ce5eca99bcfb5557b36ea210bb25bcMark Andrews>4.9. IPv6 Support in <ACRONYM
5a4854e226ce5eca99bcfb5557b36ea210bb25bcMark AndrewsCLASS="acronym"
5a4854e226ce5eca99bcfb5557b36ea210bb25bcMark Andrews>BIND</ACRONYM
b101c1e9989d0a010a3146ad823e168d15cb10c7Mark Andrews> 9</A
b101c1e9989d0a010a3146ad823e168d15cb10c7Mark Andrews></H1
989d7b844bdf2d804fda57b9b53a4eff3a6bea91Mark Andrews><P
989d7b844bdf2d804fda57b9b53a4eff3a6bea91Mark Andrews><ACRONYM
d5af5bb38b9b2626b97626569adde258c8f6b808Mark AndrewsCLASS="acronym"
6d7007e807241ae0a32de8db8d3bf434626026eaMark Andrews>BIND</ACRONYM
c941e32d221fbb0cb760e3bc24c7f221c0cf8b97Mark Andrews> 9 fully supports all currently defined forms of IPv6
c941e32d221fbb0cb760e3bc24c7f221c0cf8b97Mark Andrews name to address and address to name lookups. It will also use
c941e32d221fbb0cb760e3bc24c7f221c0cf8b97Mark Andrews IPv6 addresses to make queries when running on an IPv6 capable
c941e32d221fbb0cb760e3bc24c7f221c0cf8b97Mark Andrews system.</P
77b101ced9801cdb226919784bfc1aa0650ace6aMark Andrews><P
77b101ced9801cdb226919784bfc1aa0650ace6aMark Andrews>For forward lookups, <ACRONYM
e174044290953a2499f574e35cc9c22ba126a303Mark AndrewsCLASS="acronym"
a903095bf4512dae561c7f6fc7854a51bebf334aMark Andrews>BIND</ACRONYM
a903095bf4512dae561c7f6fc7854a51bebf334aMark Andrews> 9 supports only AAAA
e174044290953a2499f574e35cc9c22ba126a303Mark Andrews records. The use of A6 records is deprecated by RFC 3363, and the
a903095bf4512dae561c7f6fc7854a51bebf334aMark Andrews support for forward lookups in <ACRONYM
e174044290953a2499f574e35cc9c22ba126a303Mark AndrewsCLASS="acronym"
e174044290953a2499f574e35cc9c22ba126a303Mark Andrews>BIND</ACRONYM
e174044290953a2499f574e35cc9c22ba126a303Mark Andrews> 9 is
25899e7f1ff0db5322362ada01f7aec3006ff0beTatuya JINMEI 神明達哉 removed accordingly.
4f082b58b17ce39087930d5affc2ada90ef386e6Mark Andrews However, authoritative <ACRONYM
4f082b58b17ce39087930d5affc2ada90ef386e6Mark AndrewsCLASS="acronym"
3d79c437d8cc10651b22601b55f4098b4cfe5979Mark Andrews>BIND</ACRONYM
0da70bc50a320a3bb16aa7cecb2727fed2c0683cMark Andrews> 9 name servers still
0da70bc50a320a3bb16aa7cecb2727fed2c0683cMark Andrews load zone files containing A6 records correctly, answer queries
0da70bc50a320a3bb16aa7cecb2727fed2c0683cMark Andrews for A6 records, and accept zone transfer for a zone containing A6
686bcdcb4c63e8dd9bbe9607265061a4d3934bbcMark Andrews records.</P
4423c99613db1399dbb5c51e86ef0d351a1418c2Mark Andrews><P
686bcdcb4c63e8dd9bbe9607265061a4d3934bbcMark Andrews>For IPv6 reverse lookups, <ACRONYM
5597be9bb88de138dfec9fa9176708443813925eTatuya JINMEI 神明達哉CLASS="acronym"
5597be9bb88de138dfec9fa9176708443813925eTatuya JINMEI 神明達哉>BIND</ACRONYM
5597be9bb88de138dfec9fa9176708443813925eTatuya JINMEI 神明達哉> 9 supports
5597be9bb88de138dfec9fa9176708443813925eTatuya JINMEI 神明達哉 the traditional "nibble" format used in the
6be278a81c24c6729aeaae4ba3a7ddd5030d8451Tatuya JINMEI 神明達哉 <SPAN
5597be9bb88de138dfec9fa9176708443813925eTatuya JINMEI 神明達哉CLASS="emphasis"
5cf023372424c1a59fda4a994e3c85c08c26e2f1Tatuya JINMEI 神明達哉><I
fde0a3f89b9c42e9e4ef9aaf8e044e6b18c4978cMark AndrewsCLASS="emphasis"
fde0a3f89b9c42e9e4ef9aaf8e044e6b18c4978cMark Andrews>ip6.arpa</I
fde0a3f89b9c42e9e4ef9aaf8e044e6b18c4978cMark Andrews></SPAN
39c7fc7e00af20144b94ef332943f62c1b3a622fMark Andrews> domain, as well as the older, deprecated
39c7fc7e00af20144b94ef332943f62c1b3a622fMark Andrews <SPAN
073dfc245fd921958b1ccd869ed3471f828cf283Mark AndrewsCLASS="emphasis"
9738408dcbd4c1f7eb2b105c83388608fafd7808Mark Andrews><I
9738408dcbd4c1f7eb2b105c83388608fafd7808Mark AndrewsCLASS="emphasis"
9738408dcbd4c1f7eb2b105c83388608fafd7808Mark Andrews>ip6.int</I
65d64acb51b0655f04b165c8045d1aed556489abMark Andrews></SPAN
e9aca33f362d017fe0d5f7b729bce646038cf1eeMark Andrews> domain.
e9aca33f362d017fe0d5f7b729bce646038cf1eeMark Andrews <ACRONYM
28e36fcc1eea8b5283aa33d3a6d21d42df8fdaf2Mark AndrewsCLASS="acronym"
5cf146c586f69af7c65e4a4f612ae3ef6c9cf8deMark Andrews>BIND</ACRONYM
5cf146c586f69af7c65e4a4f612ae3ef6c9cf8deMark Andrews> 9 formerly
2a2e9c7a1a8cded637be17f32dc1bbdef519ca81Mark Andrews supported the "binary label" (also known as "bitstring") format.
8a713ca49ddddb36e432d4717800f9258a5c2ea9Mark Andrews The support of binary labels, however, is now completely removed
8a713ca49ddddb36e432d4717800f9258a5c2ea9Mark Andrews according to the changes in RFC 3363.
f93d6e86ded924cb23d80a6d45a4c830b57984ddMark Andrews Any applications in <ACRONYM
0ad024cc4272894e877e3a7896f80a2892bc703cMark AndrewsCLASS="acronym"
0ad024cc4272894e877e3a7896f80a2892bc703cMark Andrews>BIND</ACRONYM
0ad024cc4272894e877e3a7896f80a2892bc703cMark Andrews> 9 do not understand
f93d6e86ded924cb23d80a6d45a4c830b57984ddMark Andrews the format any more, and will return an error if given.
0ad024cc4272894e877e3a7896f80a2892bc703cMark Andrews In particular, an authoritative <ACRONYM
0ad024cc4272894e877e3a7896f80a2892bc703cMark AndrewsCLASS="acronym"
f93d6e86ded924cb23d80a6d45a4c830b57984ddMark Andrews>BIND</ACRONYM
e50b75e36ca79f84e2c9b2a12f6e28cbf22aaa83Mark Andrews> 9 name
e50b75e36ca79f84e2c9b2a12f6e28cbf22aaa83Mark Andrews server rejects to load a zone file containing binary labels.</P
e50b75e36ca79f84e2c9b2a12f6e28cbf22aaa83Mark Andrews><P
70ba825728dc64439801981a1abe7f1e28182698Mark Andrews>For an overview of the format and structure of IPv6 addresses,
797944723c8de672430cc59c11bf4eeacd913649Mark Andrews see <A
797944723c8de672430cc59c11bf4eeacd913649Mark AndrewsHREF="Bv9ARM.ch09.html#ipv6addresses"
28b65e6d0a03704f4faee88ebf5105addfa57968Mark Andrews>Section A.2.1</A
8cd830d7c806cac681b057e0c0185f29992fa35fMark Andrews>.</P
11b399514e4af7f370fe3948c3e3779a182ac5acMark Andrews><DIV
4296c5480dde48ea555f5916be8612e173f1edebMark AndrewsCLASS="sect2"
4296c5480dde48ea555f5916be8612e173f1edebMark Andrews><H2
14a97c343bc3adb840b13d515a8298c18f15be52Mark AndrewsCLASS="sect2"
164e2a6f83cc3172bc9ba0c97a326a5eca80bc18Mark Andrews><A
164e2a6f83cc3172bc9ba0c97a326a5eca80bc18Mark AndrewsNAME="AEN1029"
164e2a6f83cc3172bc9ba0c97a326a5eca80bc18Mark Andrews>4.9.1. Address Lookups Using AAAA Records</A
e90994e3f358bdc6fe03005da08567c807a14c1dMark Andrews></H2
e90994e3f358bdc6fe03005da08567c807a14c1dMark Andrews><P
7087b3dc9298e85909df7a10f83bbd0588310f0cMark Andrews>The AAAA record is a parallel to the IPv4 A record. It
4844ed026a9b5a91044e76399cee80a6514cbf0dMark Andrews specifies the entire address in a single record. For
4844ed026a9b5a91044e76399cee80a6514cbf0dMark Andrews example,</P
db2649bad98fc08054feb1a1ed234d8b9b011ea8Mark Andrews><PRE
ad5bc22a819190839bdcc4d102d023782dc23660Mark AndrewsCLASS="programlisting"
ad5bc22a819190839bdcc4d102d023782dc23660Mark Andrews>&#13;$ORIGIN example.com.
ad5bc22a819190839bdcc4d102d023782dc23660Mark Andrewshost 3600 IN AAAA 2001:db8::1
7502c6600645f120434d84d0ce3df7c3585cfe43Mark Andrews</PRE
82572925f8942b599667bf47f22403f5dfd79ab9Mark Andrews><P
cdb15282589682b664dfb70428a3c1750fe05250Mark Andrews>It is recommended that IPv4-in-IPv6 mapped addresses not
b326d7e3a3a50eb65dd06db007d2fddc62606bbfMark Andrews be used. If a host has an IPv4 address, use an A record, not
c0a1ebb1adecc5da1f1ad6f9b06a2b4356d2b135Mark Andrews a AAAA, with <VAR
508f61f8d699c46f962b682f388e54b446a7194dMark AndrewsCLASS="literal"
508f61f8d699c46f962b682f388e54b446a7194dMark Andrews>::ffff:192.168.42.1</VAR
4834c6a7f0054b8f4a8a267d60ef78204521e39eMark Andrews> as the
f450814ab8989820a7bc9a2c484eb9f2c1c7b915Mark Andrews address.</P
4c47c184b98a5ec1b303281959c1f3b0db85d733Mark Andrews></DIV
48f929d315bafeeffe0a37082ab4c9661a928c39Mark Andrews><DIV
48f929d315bafeeffe0a37082ab4c9661a928c39Mark AndrewsCLASS="sect2"
0e93730a02a4cafbc5cdfaa04b2d813a0c11b205Mark Andrews><H2
93f429295a682f44940c8f4e2b05773c50da4e7dMark AndrewsCLASS="sect2"
93f429295a682f44940c8f4e2b05773c50da4e7dMark Andrews><A
c04f4437ff8b2aba326e5099eae0cacb7de6f74bMark AndrewsNAME="AEN1035"
494576ce20cfd98d74955698cf8f7b37dce2f740Mark Andrews>4.9.2. Address to Name Lookups Using Nibble Format</A
494576ce20cfd98d74955698cf8f7b37dce2f740Mark Andrews></H2
494576ce20cfd98d74955698cf8f7b37dce2f740Mark Andrews><P
a36db48f57a59d82af0cf8cfecbdb7620aa3cc47Mark Andrews>When looking up an address in nibble format, the address
a36db48f57a59d82af0cf8cfecbdb7620aa3cc47Mark Andrews components are simply reversed, just as in IPv4, and
a36db48f57a59d82af0cf8cfecbdb7620aa3cc47Mark Andrews <VAR
531f6c355bde4b280d1dea749dd1bcdf6b2f8701Mark AndrewsCLASS="literal"
531f6c355bde4b280d1dea749dd1bcdf6b2f8701Mark Andrews>ip6.arpa.</VAR
531f6c355bde4b280d1dea749dd1bcdf6b2f8701Mark Andrews> is appended to the resulting name.
3ea6d4dc33482a752553c59ed94bcecd23d254b0Mark Andrews For example, the following would provide reverse name lookup for
3ea6d4dc33482a752553c59ed94bcecd23d254b0Mark Andrews a host with address
6e1141e6e83b3907b8b187d97932f30fa82470efMark Andrews <VAR
6e1141e6e83b3907b8b187d97932f30fa82470efMark AndrewsCLASS="literal"
6e1141e6e83b3907b8b187d97932f30fa82470efMark Andrews>2001:db8::1</VAR
6e1141e6e83b3907b8b187d97932f30fa82470efMark Andrews>.</P
e954ec198e535f8a7e17d72241233f825b0df6a6Mark Andrews><PRE
e954ec198e535f8a7e17d72241233f825b0df6a6Mark AndrewsCLASS="programlisting"
e954ec198e535f8a7e17d72241233f825b0df6a6Mark Andrews>&#13;$ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa.
aceae69c7f3e76e8842de178851928619c65b61cMark Andrews1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0 14400 IN PTR host.example.com.
aceae69c7f3e76e8842de178851928619c65b61cMark Andrews</PRE
aceae69c7f3e76e8842de178851928619c65b61cMark Andrews></DIV
aceae69c7f3e76e8842de178851928619c65b61cMark Andrews></DIV
113598f67787f0ed0dcfe23b26d1e5d93256c0acMark Andrews></DIV
113598f67787f0ed0dcfe23b26d1e5d93256c0acMark Andrews><DIV
113598f67787f0ed0dcfe23b26d1e5d93256c0acMark AndrewsCLASS="NAVFOOTER"
dba1bc96f6f4fbbb48ab7b041964d44242731b17Mark Andrews><HR
dba1bc96f6f4fbbb48ab7b041964d44242731b17Mark AndrewsALIGN="LEFT"
b68fe6c0fbfee1dc0659661993de5c6727b66c76Mark AndrewsWIDTH="100%"><TABLE
70e854766f5304f43e94212dc38ebaefe214148cMark AndrewsSUMMARY="Footer navigation table"
136e739d0d7267a8ce72468233fa795359db62faMark AndrewsWIDTH="100%"
7c8662961e2876e22e34c96d41dad0cd70e3ce4cMark AndrewsBORDER="0"
7c8662961e2876e22e34c96d41dad0cd70e3ce4cMark AndrewsCELLPADDING="0"
beb92a43a7451981fad54c98c809d50c1b16c1e9Mark AndrewsCELLSPACING="0"
beb92a43a7451981fad54c98c809d50c1b16c1e9Mark Andrews><TR
82ecc9cd96239649dfeb0a16e31c3b978d0d266aMark Andrews><TD
85bba08193debe026883d2d6bebbb0f7a01d7ba7Mark AndrewsWIDTH="33%"
85bba08193debe026883d2d6bebbb0f7a01d7ba7Mark AndrewsALIGN="left"
82ecc9cd96239649dfeb0a16e31c3b978d0d266aMark AndrewsVALIGN="top"
5173d52b3eb9715259a2890614f869c6baeb18e1Mark Andrews><A
4091f8dfb71b78b53acd1b25f74e26c384750c03Mark AndrewsHREF="Bv9ARM.ch03.html"
82ecc9cd96239649dfeb0a16e31c3b978d0d266aMark AndrewsACCESSKEY="P"
82ecc9cd96239649dfeb0a16e31c3b978d0d266aMark Andrews>Prev</A
74ff5f080abdffa7823ff93da74969cd9fa25308Mark Andrews></TD
a10ae596379471b0dc76ebd8025d91bf2b90bafcMark Andrews><TD
a10ae596379471b0dc76ebd8025d91bf2b90bafcMark AndrewsWIDTH="34%"
09ba9eacebdffc689da9851ce3bd932aedd1deddMark AndrewsALIGN="center"
09ba9eacebdffc689da9851ce3bd932aedd1deddMark AndrewsVALIGN="top"
d5f13fecca944fc7229dac3215581cebec3ac314Mark Andrews><A
c202b9f4dd7438252d77a4dd8936b7a051431a0bMark AndrewsHREF="Bv9ARM.html"
d844741f5516bce45f8897435342731edb2307cbMark AndrewsACCESSKEY="H"
53e8e0e27a3db745548a7989639b91d16f841c1fMark Andrews>Home</A
53e8e0e27a3db745548a7989639b91d16f841c1fMark Andrews></TD
d0c827c9c6a21a0708d97314406ff34d79bed5d8Mark Andrews><TD
d0c827c9c6a21a0708d97314406ff34d79bed5d8Mark AndrewsWIDTH="33%"
6f691d4893bb29cd6658b75860d93797f091da0dMark AndrewsALIGN="right"
6f691d4893bb29cd6658b75860d93797f091da0dMark AndrewsVALIGN="top"
6f691d4893bb29cd6658b75860d93797f091da0dMark Andrews><A
3d75a3aef3c26c1957f393e4626177484f53a9d4Mark AndrewsHREF="Bv9ARM.ch05.html"
3d75a3aef3c26c1957f393e4626177484f53a9d4Mark AndrewsACCESSKEY="N"
3d75a3aef3c26c1957f393e4626177484f53a9d4Mark Andrews>Next</A
4e259c5a2321e994708fb1fe04cd4da30aa3b612Mark Andrews></TD
4e259c5a2321e994708fb1fe04cd4da30aa3b612Mark Andrews></TR
4e259c5a2321e994708fb1fe04cd4da30aa3b612Mark Andrews><TR
fcdef14f4a82138fe835a5c3a20d5667e6f4a26cMark Andrews><TD
fcdef14f4a82138fe835a5c3a20d5667e6f4a26cMark AndrewsWIDTH="33%"
e9a0e12b2b732285e00e0d9436961d0fe3655aa6Mark AndrewsALIGN="left"
e94754428d472bdde2cba0efdd549bac2e87b98bMark AndrewsVALIGN="top"
e94754428d472bdde2cba0efdd549bac2e87b98bMark Andrews>Name Server Configuration</TD
23f2338819fd1a38a828b417eb05be95207e76e2Mark Andrews><TD
a53259c4cc558f86dd008eccc60cc89b6734a03cMark AndrewsWIDTH="34%"
a53259c4cc558f86dd008eccc60cc89b6734a03cMark AndrewsALIGN="center"
a8be540f55786eb9db43ae52bcc891529602c850Mark AndrewsVALIGN="top"
a8be540f55786eb9db43ae52bcc891529602c850Mark Andrews>&nbsp;</TD
a8be540f55786eb9db43ae52bcc891529602c850Mark Andrews><TD
4c8df3b2e8858e97debfe3fb771fe03f22b04d1eMark AndrewsWIDTH="33%"
6c52944ef2281095d1c317a45ea013b8f3cfa135Mark AndrewsALIGN="right"
6c52944ef2281095d1c317a45ea013b8f3cfa135Mark AndrewsVALIGN="top"
72379d863a3bb135e7da36e344b731a59b8c3e33Mark Andrews>The <ACRONYM
77fad835c56b118faf77a69af618d0bca7a16aacMark AndrewsCLASS="acronym"
77fad835c56b118faf77a69af618d0bca7a16aacMark Andrews>BIND</ACRONYM
e021f388dfc2ac024a103def34818af73e7e869fMark Andrews> 9 Lightweight Resolver</TD
dd95acdbce0e2a2775391709cdfca0a9eda7e8f7Mark Andrews></TR
dd95acdbce0e2a2775391709cdfca0a9eda7e8f7Mark Andrews></TABLE
c5eebaf6f1311662f8120a8b560e2dbbfd5c92e8Mark Andrews></DIV
71e7ac828e9f4f2b124455b00c3d11560aa5d4c1Mark Andrews></BODY
71e7ac828e9f4f2b124455b00c3d11560aa5d4c1Mark Andrews></HTML
1e6d80a391137b26e7250e72f6b28eb92c2b9952Mark Andrews>