Bv9ARM.ch04.html revision 7e4b5437f1e6345bdf56d876b32912bc05c73c60
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
32098293b78922a5fbd10906afa28624820d3756Tinderbox User - Copyright (C) 2000-2003 Internet Software Consortium.
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - Permission to use, copy, modify, and/or distribute this software for any
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - purpose with or without fee is hereby granted, provided that the above
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - copyright notice and this permission notice appear in all copies.
d6fa26d0adaec6c910115be34fe7a5a5f402c14fMark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
cd32f419a8a5432fbb139f56ee73cbf68b9350ccTinderbox User - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - PERFORMANCE OF THIS SOFTWARE.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
cd32f419a8a5432fbb139f56ee73cbf68b9350ccTinderbox User<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<link rel="prev" href="Bv9ARM.ch03.html" title="Chapter�3.�Name Server Configuration">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<link rel="next" href="Bv9ARM.ch05.html" title="Chapter�5.�The BIND 9 Lightweight Resolver">
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<tr><th colspan="3" align="center">Chapter�4.�Advanced DNS Features</th></tr>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<a accesskey="p" href="Bv9ARM.ch03.html">Prev</a>�</td>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<td width="20%" align="right">�<a accesskey="n" href="Bv9ARM.ch05.html">Next</a>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<div class="titlepage"><div><div><h1 class="title">
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<a name="Bv9ARM.ch04"></a>Chapter�4.�Advanced DNS Features</h1></div></div></div>
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#notify">Notify</a></span></dt>
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#dynamic_update">Dynamic Update</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dd><dl><dt><span class="section"><a href="Bv9ARM.ch04.html#journal">The journal file</a></span></dt></dl></dd>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#incremental_zone_transfers">Incremental Zone Transfers (IXFR)</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#split_dns">Split DNS</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dd><dl><dt><span class="section"><a href="Bv9ARM.ch04.html#split_dns_sample">Example split DNS setup</a></span></dt></dl></dd>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#tsig">TSIG</a></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.6.5">Generating a Shared Key</a></span></dt>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.6.6">Loading A New Key</a></span></dt>
f9ce6280cec79deb16ff6d9807aa493ff23e10d9Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.6.7">Instructing the Server to Use a Key</a></span></dt>
0b89eee6167201843c9a46b7e7c63cb1e4e09ba3Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.6.8">TSIG-Based Access Control</a></span></dt>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.6.9">Errors</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#tkey">TKEY</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#sig0">SIG(0)</a></span></dt>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#DNSSEC">DNSSEC</a></span></dt>
0da02c26a6631c25f075a8e4ac6de9e58f49a0c2Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#dnssec_keys">Generating Keys</a></span></dt>
0da02c26a6631c25f075a8e4ac6de9e58f49a0c2Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#dnssec_signing">Signing the Zone</a></span></dt>
0da02c26a6631c25f075a8e4ac6de9e58f49a0c2Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#dnssec_config">Configuring Servers</a></span></dt>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#dnssec.dynamic.zones">DNSSEC, Dynamic Zones, and Automatic Signing</a></span></dt>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.3">Converting from insecure to secure</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.8">Dynamic DNS update method</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.16">Fully automatic zone signing</a></span></dt>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.25">Private-type records</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.32">DNSKEY rollovers</a></span></dt>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.34">Dynamic DNS update method</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.39">Automatic key rollovers</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.41">NSEC3PARAM rollovers via UPDATE</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.43">Converting from NSEC to NSEC3</a></span></dt>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.45">Converting from NSEC3 to NSEC</a></span></dt>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.47">Converting from secure to insecure</a></span></dt>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.51">Periodic re-signing</a></span></dt>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.10.53">NSEC3 and OPTOUT</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#rfc5011.support">Dynamic Trust Anchor Management</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.11.3">Validating Resolver</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.11.4">Authoritative Server</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#pkcs11">PKCS#11 (Cryptoki) support</a></span></dt>
363b21045b718d06d414784c96193dc9a233e8c5Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.12.6">Prerequisites</a></span></dt>
363b21045b718d06d414784c96193dc9a233e8c5Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.12.7">Native PKCS#11</a></span></dt>
363b21045b718d06d414784c96193dc9a233e8c5Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.12.8">OpenSSL-based PKCS#11</a></span></dt>
363b21045b718d06d414784c96193dc9a233e8c5Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.12.9">PKCS#11 Tools</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.12.10">Using the HSM</a></span></dt>
363b21045b718d06d414784c96193dc9a233e8c5Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.12.11">Specifying the engine on the command line</a></span></dt>
363b21045b718d06d414784c96193dc9a233e8c5Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.12.12">Running named with automatic zone re-signing</a></span></dt>
363b21045b718d06d414784c96193dc9a233e8c5Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#dlz-info">DLZ (Dynamically Loadable Zones)</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.13.6">Configuring DLZ</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.13.7">Sample DLZ Driver</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#dyndb-info">DynDB (Dynamic Database)</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.14.5">Configuring DynDB</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.14.6">Sample DynDB Module</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#catz-info">Catalog Zones</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.15.4">Principle of Operation</a></span></dt>
33c9436ef1a43d3c0fc3d9be9b4b0509daa83223Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.15.5">Configuring Catalog Zones</a></span></dt>
a1ff871f78b7d907d6fc3a382beea2a640fe8423Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.15.6">Catalog Zone format</a></span></dt>
0da02c26a6631c25f075a8e4ac6de9e58f49a0c2Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#ipv6">IPv6 Support in <acronym class="acronym">BIND</acronym> 9</a></span></dt>
0da02c26a6631c25f075a8e4ac6de9e58f49a0c2Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.16.6">Address Lookups Using AAAA Records</a></span></dt>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<dt><span class="section"><a href="Bv9ARM.ch04.html#id-1.5.16.7">Address to Name Lookups Using Nibble Format</a></span></dt>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<div class="titlepage"><div><div><h2 class="title" style="clear: both">
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User<a name="notify"></a>Notify</h2></div></div></div>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User <acronym class="acronym">DNS</acronym> NOTIFY is a mechanism that allows master
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User servers to notify their slave servers of changes to a zone's data. In
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User response to a <span class="command"><strong>NOTIFY</strong></span> from a master server, the
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User slave will check to see that its version of the zone is the
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User current version and, if not, initiate a zone transfer.
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User For more information about <acronym class="acronym">DNS</acronym>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User <span class="command"><strong>NOTIFY</strong></span>, see the description of the
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User <span class="command"><strong>notify</strong></span> option in <a class="xref" href="Bv9ARM.ch06.html#boolean_options" title="Boolean Options">the section called “Boolean Options”</a> and
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User the description of the zone option <span class="command"><strong>also-notify</strong></span> in
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User <a class="xref" href="Bv9ARM.ch06.html#zone_transfers" title="Zone Transfers">the section called “Zone Transfers”</a>. The <span class="command"><strong>NOTIFY</strong></span>
8a48b6b9b6fa8486f24b22d1972b2b6ebb36a4a4Tinderbox User protocol is specified in RFC 1996.
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User As a slave zone can also be a master to other slaves, <span class="command"><strong>named</strong></span>,
363b21045b718d06d414784c96193dc9a233e8c5Tinderbox User by default, sends <span class="command"><strong>NOTIFY</strong></span> messages for every zone
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User it loads. Specifying <span class="command"><strong>notify master-only;</strong></span> will
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User cause <span class="command"><strong>named</strong></span> to only send <span class="command"><strong>NOTIFY</strong></span> for master
363b21045b718d06d414784c96193dc9a233e8c5Tinderbox User zones that it loads.
363b21045b718d06d414784c96193dc9a233e8c5Tinderbox User<div class="titlepage"><div><div><h2 class="title" style="clear: both">
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<a name="dynamic_update"></a>Dynamic Update</h2></div></div></div>
550d3276d0490c4918f089ccb1528a3eb0951b0aTinderbox User Dynamic Update is a method for adding, replacing or deleting
550d3276d0490c4918f089ccb1528a3eb0951b0aTinderbox User records in a master server by sending it a special form of DNS
550d3276d0490c4918f089ccb1528a3eb0951b0aTinderbox User messages. The format and meaning of these messages is specified
550d3276d0490c4918f089ccb1528a3eb0951b0aTinderbox User Dynamic update is enabled by including an
51da15c88648a9e47d0cddff4b2b782665e99401Tinderbox User <span class="command"><strong>allow-update</strong></span> or an <span class="command"><strong>update-policy</strong></span>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User clause in the <span class="command"><strong>zone</strong></span> statement.
51da15c88648a9e47d0cddff4b2b782665e99401Tinderbox User If the zone's <span class="command"><strong>update-policy</strong></span> is set to
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User <strong class="userinput"><code>local</code></strong>, updates to the zone
51da15c88648a9e47d0cddff4b2b782665e99401Tinderbox User will be permitted for the key <code class="varname">local-ddns</code>,
51da15c88648a9e47d0cddff4b2b782665e99401Tinderbox User which will be generated by <span class="command"><strong>named</strong></span> at startup.
51da15c88648a9e47d0cddff4b2b782665e99401Tinderbox User See <a class="xref" href="Bv9ARM.ch06.html#dynamic_update_policies" title="Dynamic Update Policies">the section called “Dynamic Update Policies”</a> for more details.
51da15c88648a9e47d0cddff4b2b782665e99401Tinderbox User Dynamic updates using Kerberos signed requests can be made
51da15c88648a9e47d0cddff4b2b782665e99401Tinderbox User using the TKEY/GSS protocol by setting either the
51da15c88648a9e47d0cddff4b2b782665e99401Tinderbox User <span class="command"><strong>tkey-gssapi-keytab</strong></span> option, or alternatively
51da15c88648a9e47d0cddff4b2b782665e99401Tinderbox User by setting both the <span class="command"><strong>tkey-gssapi-credential</strong></span>
51da15c88648a9e47d0cddff4b2b782665e99401Tinderbox User and <span class="command"><strong>tkey-domain</strong></span> options. Once enabled,
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User Kerberos signed requests will be matched against the update
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User policies for the zone, using the Kerberos principal as the
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User signer for the request.
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User Updating of secure zones (zones using DNSSEC) follows RFC
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User 3007: RRSIG, NSEC and NSEC3 records affected by updates are
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User automatically regenerated by the server using an online
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User zone key. Update authorization is based on transaction
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User signatures and an explicit server policy.
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User<div class="titlepage"><div><div><h3 class="title">
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User<a name="journal"></a>The journal file</h3></div></div></div>
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User All changes made to a zone using dynamic update are stored
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User in the zone's journal file. This file is automatically created
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User by the server when the first dynamic update takes place.
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User The name of the journal file is formed by appending the extension
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User <code class="filename">.jnl</code> to the name of the
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User corresponding zone
d253648fe3331622cebea02d60aaecca3082d78dTinderbox User file unless specifically overridden. The journal file is in a
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User binary format and should not be edited manually.
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User The server will also occasionally write ("dump")
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User the complete contents of the updated zone to its zone file.
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User This is not done immediately after
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User each dynamic update, because that would be too slow when a large
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User zone is updated frequently. Instead, the dump is delayed by
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User up to 15 minutes, allowing additional updates to take place.
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User During the dump process, transient files will be created
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User with the extensions <code class="filename">.jnw</code> and
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User <code class="filename">.jbk</code>; under ordinary circumstances, these
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User will be removed when the dump is complete, and can be safely
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User When a server is restarted after a shutdown or crash, it will replay
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User the journal file to incorporate into the zone any updates that
3ca1a32241189d1e02e59f6b56399eb9b40f2aafTinderbox User place after the last zone dump.
dfae459e8c4f794f8a239e74aa9d5e11cce6ea5bTinderbox User Changes that result from incoming incremental zone transfers are
bfb7b680bf88c1fdd9949197b71c512c532280a4Tinderbox User journalled in a similar way.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt The zone files of dynamic zones cannot normally be edited by
abe69df9a7de5cda07a2b8e19e8b7c981bcd7a9dTinderbox User hand because they are not guaranteed to contain the most recent
f14ce68ee54a5a4587fbde4ffacb117946df2d73Tinderbox User dynamic changes — those are only in the journal file.
f14ce68ee54a5a4587fbde4ffacb117946df2d73Tinderbox User The only way to ensure that the zone file of a dynamic zone
f14ce68ee54a5a4587fbde4ffacb117946df2d73Tinderbox User is up to date is to run <span class="command"><strong>rndc stop</strong></span>.
f14ce68ee54a5a4587fbde4ffacb117946df2d73Tinderbox User If you have to make changes to a dynamic zone
f14ce68ee54a5a4587fbde4ffacb117946df2d73Tinderbox User manually, the following procedure will work:
f14ce68ee54a5a4587fbde4ffacb117946df2d73Tinderbox User Disable dynamic updates to the zone using
f14ce68ee54a5a4587fbde4ffacb117946df2d73Tinderbox User <span class="command"><strong>rndc freeze <em class="replaceable"><code>zone</code></em></strong></span>.
f14ce68ee54a5a4587fbde4ffacb117946df2d73Tinderbox User This will update the zone's master file with the changes
f14ce68ee54a5a4587fbde4ffacb117946df2d73Tinderbox User stored in its <code class="filename">.jnl</code> file.
0d6a6642b2be93cffa651c54a9b8810dd2d31392Tinderbox User Edit the zone file. Run
0d6a6642b2be93cffa651c54a9b8810dd2d31392Tinderbox User <span class="command"><strong>rndc thaw <em class="replaceable"><code>zone</code></em></strong></span>
0d6a6642b2be93cffa651c54a9b8810dd2d31392Tinderbox User to reload the changed zone and re-enable dynamic updates.
0d6a6642b2be93cffa651c54a9b8810dd2d31392Tinderbox User <span class="command"><strong>rndc sync <em class="replaceable"><code>zone</code></em></strong></span>
0d6a6642b2be93cffa651c54a9b8810dd2d31392Tinderbox User will update the zone file with changes from the journal file
0d6a6642b2be93cffa651c54a9b8810dd2d31392Tinderbox User without stopping dynamic updates; this may be useful for viewing
0d6a6642b2be93cffa651c54a9b8810dd2d31392Tinderbox User the current zone state. To remove the <code class="filename">.jnl</code>
abe69df9a7de5cda07a2b8e19e8b7c981bcd7a9dTinderbox User file after updating the zone file, use
abe69df9a7de5cda07a2b8e19e8b7c981bcd7a9dTinderbox User <span class="command"><strong>rndc sync -clean</strong></span>.
abe69df9a7de5cda07a2b8e19e8b7c981bcd7a9dTinderbox User<div class="titlepage"><div><div><h2 class="title" style="clear: both">
abe69df9a7de5cda07a2b8e19e8b7c981bcd7a9dTinderbox User<a name="incremental_zone_transfers"></a>Incremental Zone Transfers (IXFR)</h2></div></div></div>
abe69df9a7de5cda07a2b8e19e8b7c981bcd7a9dTinderbox User The incremental zone transfer (IXFR) protocol is a way for
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User slave servers to transfer only changed data, instead of having to
164ade1482251e1da962b42e5bf0d3aa02a11e03Tinderbox User transfer the entire zone. The IXFR protocol is specified in RFC
164ade1482251e1da962b42e5bf0d3aa02a11e03Tinderbox User 1995. See <a class="xref" href="Bv9ARM.ch11.html#proposed_standards" title="Proposed Standards">Proposed Standards</a>.
164ade1482251e1da962b42e5bf0d3aa02a11e03Tinderbox User When acting as a master, <acronym class="acronym">BIND</acronym> 9
164ade1482251e1da962b42e5bf0d3aa02a11e03Tinderbox User supports IXFR for those zones
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User where the necessary change history information is available. These
abe69df9a7de5cda07a2b8e19e8b7c981bcd7a9dTinderbox User include master zones maintained by dynamic update and slave zones
c48fdfda7a8ae8973aadfeb88cbeaab013024a6cTinderbox User whose data was obtained by IXFR. For manually maintained master
c48fdfda7a8ae8973aadfeb88cbeaab013024a6cTinderbox User zones, and for slave zones obtained by performing a full zone
c48fdfda7a8ae8973aadfeb88cbeaab013024a6cTinderbox User transfer (AXFR), IXFR is supported only if the option
c48fdfda7a8ae8973aadfeb88cbeaab013024a6cTinderbox User <span class="command"><strong>ixfr-from-differences</strong></span> is set
c48fdfda7a8ae8973aadfeb88cbeaab013024a6cTinderbox User to <strong class="userinput"><code>yes</code></strong>.
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User When acting as a slave, <acronym class="acronym">BIND</acronym> 9 will
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User attempt to use IXFR unless
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User it is explicitly disabled. For more information about disabling
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt IXFR, see the description of the <span class="command"><strong>request-ixfr</strong></span> clause
164ade1482251e1da962b42e5bf0d3aa02a11e03Tinderbox User of the <span class="command"><strong>server</strong></span> statement.
a0fb6a0980359165a4459723f52d5d7b5725f9c6Tinderbox User<div class="titlepage"><div><div><h2 class="title" style="clear: both">
a0fb6a0980359165a4459723f52d5d7b5725f9c6Tinderbox User<a name="split_dns"></a>Split DNS</h2></div></div></div>
a0fb6a0980359165a4459723f52d5d7b5725f9c6Tinderbox User Setting up different views, or visibility, of the DNS space to
a0fb6a0980359165a4459723f52d5d7b5725f9c6Tinderbox User internal and external resolvers is usually referred to as a
a0fb6a0980359165a4459723f52d5d7b5725f9c6Tinderbox User <span class="emphasis"><em>Split DNS</em></span> setup. There are several
a0fb6a0980359165a4459723f52d5d7b5725f9c6Tinderbox User reasons an organization would want to set up its DNS this way.
8c7245514646663b25d8b186186ebede41903fa3Tinderbox User One common reason for setting up a DNS system this way is
8c7245514646663b25d8b186186ebede41903fa3Tinderbox User to hide "internal" DNS information from "external" clients on the
8c7245514646663b25d8b186186ebede41903fa3Tinderbox User Internet. There is some debate as to whether or not this is actually
8c7245514646663b25d8b186186ebede41903fa3Tinderbox User Internal DNS information leaks out in many ways (via email headers,
8c7245514646663b25d8b186186ebede41903fa3Tinderbox User for example) and most savvy "attackers" can find the information
8c7245514646663b25d8b186186ebede41903fa3Tinderbox User they need using other means.
421ba11f3f07cbcb12c288ef7f4e7bad13fcc28fTinderbox User However, since listing addresses of internal servers that
421ba11f3f07cbcb12c288ef7f4e7bad13fcc28fTinderbox User external clients cannot possibly reach can result in
421ba11f3f07cbcb12c288ef7f4e7bad13fcc28fTinderbox User connection delays and other annoyances, an organization may
421ba11f3f07cbcb12c288ef7f4e7bad13fcc28fTinderbox User choose to use a Split DNS to present a consistent view of itself
421ba11f3f07cbcb12c288ef7f4e7bad13fcc28fTinderbox User to the outside world.
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User Another common reason for setting up a Split DNS system is
3b15473cedf41d48904f5b07bdc5e87afff6b58cTinderbox User to allow internal networks that are behind filters or in RFC 1918
3b15473cedf41d48904f5b07bdc5e87afff6b58cTinderbox User space (reserved IP space, as documented in RFC 1918) to resolve DNS
3b15473cedf41d48904f5b07bdc5e87afff6b58cTinderbox User on the Internet. Split DNS can also be used to allow mail from outside
3b15473cedf41d48904f5b07bdc5e87afff6b58cTinderbox User back in to the internal network.
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User<div class="titlepage"><div><div><h3 class="title">
99b30e26a6beb9092557cc9e5370b517309bff6eTinderbox User<a name="split_dns_sample"></a>Example split DNS setup</h3></div></div></div>
99b30e26a6beb9092557cc9e5370b517309bff6eTinderbox User Let's say a company named <span class="emphasis"><em>Example, Inc.</em></span>
99b30e26a6beb9092557cc9e5370b517309bff6eTinderbox User has several corporate sites that have an internal network with
99b30e26a6beb9092557cc9e5370b517309bff6eTinderbox User Internet Protocol (IP) space and an external demilitarized zone (DMZ),
99b30e26a6beb9092557cc9e5370b517309bff6eTinderbox User or "outside" section of a network, that is available to the public.
c48fdfda7a8ae8973aadfeb88cbeaab013024a6cTinderbox User <span class="emphasis"><em>Example, Inc.</em></span> wants its internal clients
c48fdfda7a8ae8973aadfeb88cbeaab013024a6cTinderbox User to be able to resolve external hostnames and to exchange mail with
c48fdfda7a8ae8973aadfeb88cbeaab013024a6cTinderbox User people on the outside. The company also wants its internal resolvers
c48fdfda7a8ae8973aadfeb88cbeaab013024a6cTinderbox User to have access to certain internal-only zones that are not available
9efd8fc7e811d3c0c160adeb5552c2df7e49df67Tinderbox User at all outside of the internal network.
9efd8fc7e811d3c0c160adeb5552c2df7e49df67Tinderbox User In order to accomplish this, the company will set up two sets
9efd8fc7e811d3c0c160adeb5552c2df7e49df67Tinderbox User of name servers. One set will be on the inside network (in the
9efd8fc7e811d3c0c160adeb5552c2df7e49df67Tinderbox User IP space) and the other set will be on bastion hosts, which are
9efd8fc7e811d3c0c160adeb5552c2df7e49df67Tinderbox User hosts that can talk to both sides of its network, in the DMZ.
666b453b37f9ccfe3c7984fb0b31b70a3ceb918fTinderbox User The internal servers will be configured to forward all queries,
666b453b37f9ccfe3c7984fb0b31b70a3ceb918fTinderbox User except queries for <code class="filename">site1.internal</code>, <code class="filename">site2.internal</code>, <code class="filename">site1.example.com</code>,
666b453b37f9ccfe3c7984fb0b31b70a3ceb918fTinderbox User and <code class="filename">site2.example.com</code>, to the servers
666b453b37f9ccfe3c7984fb0b31b70a3ceb918fTinderbox User DMZ. These internal servers will have complete sets of information
666b453b37f9ccfe3c7984fb0b31b70a3ceb918fTinderbox User for <code class="filename">site1.example.com</code>, <code class="filename">site2.example.com</code>, <code class="filename">site1.internal</code>,
666b453b37f9ccfe3c7984fb0b31b70a3ceb918fTinderbox User and <code class="filename">site2.internal</code>.
bea02a4cc08d57b9f36979906f291ac78a99060aTinderbox User To protect the <code class="filename">site1.internal</code> and <code class="filename">site2.internal</code> domains,
bea02a4cc08d57b9f36979906f291ac78a99060aTinderbox User the internal name servers must be configured to disallow all queries
bea02a4cc08d57b9f36979906f291ac78a99060aTinderbox User to these domains from any external hosts, including the bastion
bea02a4cc08d57b9f36979906f291ac78a99060aTinderbox User The external servers, which are on the bastion hosts, will
9efd8fc7e811d3c0c160adeb5552c2df7e49df67Tinderbox User be configured to serve the "public" version of the <code class="filename">site1</code> and <code class="filename">site2.example.com</code> zones.
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User This could include things such as the host records for public servers
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User (<code class="filename">www.example.com</code> and <code class="filename">ftp.example.com</code>),
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User and mail exchange (MX) records (<code class="filename">a.mx.example.com</code> and <code class="filename">b.mx.example.com</code>).
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User In addition, the public <code class="filename">site1</code> and <code class="filename">site2.example.com</code> zones
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt should have special MX records that contain wildcard (`*') records
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt pointing to the bastion hosts. This is needed because external mail
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User servers do not have any other way of looking up how to deliver mail
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt to those internal hosts. With the wildcard records, the mail will
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User be delivered to the bastion host, which can then forward it on to
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User internal hosts.
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User Here's an example of a wildcard MX record:
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<pre class="programlisting">* IN MX 10 external1.example.com.</pre>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt Now that they accept mail on behalf of anything in the internal
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User network, the bastion hosts will need to know how to deliver mail
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt to internal hosts. In order for this to work properly, the resolvers
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt the bastion hosts will need to be configured to point to the internal
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User name servers for DNS resolution.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Queries for internal hostnames will be answered by the internal
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein servers, and queries for external hostnames will be forwarded back
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein out to the DNS servers on the bastion hosts.
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews In order for all this to work properly, internal clients will
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews need to be configured to query <span class="emphasis"><em>only</em></span> the internal
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein name servers for DNS queries. This could also be enforced via
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein filtering on the network.
cd32f419a8a5432fbb139f56ee73cbf68b9350ccTinderbox User If everything has been set properly, <span class="emphasis"><em>Example, Inc.</em></span>'s
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein internal clients will now be able to:
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Look up any hostnames in the <code class="literal">site1</code>
for information on how to configure your zone files, see <a class="xref" href="Bv9ARM.ch03.html#sample_configuration" title="Sample Configurations">the section called “Sample Configurations”</a>.
zone "site1.example.com" {
zone "site2.example.com" {
zone "site1.internal" {
zone "site2.internal" {
zone "site1.example.com" {
zone "site2.example.com" {
certain server functions (e.g., recursive queries) to authorized
<a class="xref" href="man.nsupdate.html" title="nsupdate"><span class="refentrytitle"><span class="application">nsupdate</span></span>(1)</a> supports TSIG via the
<a class="xref" href="man.dig.html" title="dig"><span class="refentrytitle">dig</span>(1)</a> supports TSIG via the
$ tsig-keygen host1-host2. > host1-host2.key
<span class="command"><strong>named</strong></span>. See <a class="xref" href="man.ddns-confgen.html" title="ddns-confgen"><span class="refentrytitle"><span class="application">ddns-confgen</span></span>(8)</a>
cause <span class="emphasis"><em>all</em></span> requests from <span class="emphasis"><em>host1</em></span>
Requests sent by <span class="emphasis"><em>host2</em></span> to <span class="emphasis"><em>host1</em></span>
<span class="command"><strong>server</strong></span> directive were in <span class="emphasis"><em>host2</em></span>'s
such as <span class="command"><strong>allow-query</strong></span>, <span class="command"><strong>allow-transfer</strong></span>
See <a class="xref" href="Bv9ARM.ch06.html#dynamic_update_policies" title="Dynamic Update Policies">the section called “Dynamic Update Policies”</a> for a discussion of
that the tools shipped with BIND 9.2.x and earlier are not compatible
<strong class="userinput"><code>dnssec-keygen -a RSASHA1 -b 768 -n ZONE child.example.</code></strong>
<strong class="userinput"><code>yes</code></strong> or <strong class="userinput"><code>auto</code></strong>.
example.com. 257 3 5 "AwEAAaxPMcR2x0HbQV4WeZB6oEDX+r0QM6
<a name="dnssec.dynamic.zones"></a>DNSSEC, Dynamic Zones, and Automatic Signing</h2></div></div></div>
zone example.net {
> update add example.net DNSKEY 256 3 7 AwEAAZn17pUF0KpbPA2c7Gz76Vb18v0teKT3EyAGfBfL8eQ8al35zz3Y I1m/SAQBxIqMfLtIwqWPdgthsu36azGQAX8=
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
> update add example.net DNSKEY 256 3 7 AwEAAZn17pUF0KpbPA2c7Gz76Vb18v0teKT3EyAGfBfL8eQ8al35zz3Y I1m/SAQBxIqMfLtIwqWPdgthsu36azGQAX8=
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
> update add example.net NSEC3PARAM 1 1 100 1234567890
(See <a class="xref" href="man.dnssec-keygen.html" title="dnssec-keygen"><span class="refentrytitle"><span class="application">dnssec-keygen</span></span>(8)</a> and
<a class="xref" href="man.dnssec-settime.html" title="dnssec-settime"><span class="refentrytitle"><span class="application">dnssec-settime</span></span>(8)</a> for more information.)
<span class="command"><strong>rndc sign</strong></span> or <span class="command"><strong>rndc loadkeys</strong></span>
<span class="command"><strong>dnssec-keygen</strong></span> or <span class="command"><strong>dnssec-settime</strong></span>),
<p>In any secure zone which supports dynamic updates, <span class="command"><strong>named</strong></span>
<a class="xref" href="Bv9ARM.ch06.html#managed-keys" title="managed-keys Statement Definition and Usage">the section called “<span class="command"><strong>managed-keys</strong></span> Statement Definition
$ <strong class="userinput"><code>dnssec-keygen -K keys -f KSK -P now -A now+2y example.net</code></strong>
and the <span class="command"><strong>dnssec-*</strong></span> and <span class="command"><strong>pkcs11-*</strong></span>
<span class="command"><strong>dnssec-*</strong></span> tools, or the <code class="option">-m</code> in
$ <strong class="userinput"><code> configure --with-crypto-backend=openssl --prefix=/opt/pkcs11/usr --enable-gost </code></strong>
$ <strong class="userinput"><code> /opt/pkcs11/usr/bin/softhsm-util --init-token 0 --slot 0 --label softhsmv2 </code></strong>
$ <strong class="userinput"><code>wget <a class="link" href="" target="_top">http://www.openssl.org/source/openssl-0.9.8zc.tar.gz</a></code></strong>
$ <strong class="userinput"><code>cp pkcs11.GCC4.0.2.so.4.05 /opt/pkcs11/usr/lib/libpkcs11.so</code></strong>
and "<span class="command"><strong>make test</strong></span>". If "<span class="command"><strong>make
$ <strong class="userinput"><code> echo "0:/opt/pkcs11/softhsm.db" > $SOFTHSM_CONF </code></strong>
$ <strong class="userinput"><code> /opt/pkcs11/usr/bin/softhsm --init-token 0 --slot 0 --label softhsm </code></strong>
<span class="quote">“<span class="quote"><code class="literal">[ available ]</code></span>”</span>.
<a name="id-1.5.12.8.18"></a>Configuring BIND 9 for Linux with the AEP Keyper</h4></div></div></div>
<a name="id-1.5.12.8.19"></a>Configuring BIND 9 for Solaris with the SCA 6000</h4></div></div></div>
$ <strong class="userinput"><code>export LD_LIBRARY_PATH=/opt/pkcs11/usr/lib:${LD_LIBRARY_PATH}</code></strong>
$ <strong class="userinput"><code>export KEYPER_LIBRARY_PATH=/opt/Keyper/PKCS11Provider</code></strong>
"sample-ksk" as the key-signing key for "example.net":
$ <strong class="userinput"><code>dnssec-keyfromlabel -l sample-ksk -f KSK example.net</code></strong>
<a class="xref" href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel"><span class="refentrytitle"><span class="application">dnssec-keyfromlabel</span></span>(8)</a> for details.)
then <span class="command"><strong>named</strong></span> must have access to the HSM PIN. In OpenSSL-based PKCS#11,
this is accomplished by placing the PIN into the openssl.cnf file
The location of the openssl.cnf file can be overridden by
Historically, DLZ drivers had to be statically linked with the <span class="command"><strong>named</strong></span>
"dlopen" driver is linked into <span class="command"><strong>named</strong></span> by default, so configure options
When the DLZ module provides data to <span class="command"><strong>named</strong></span>, it does so in text format.
The response is converted to DNS wire format by <span class="command"><strong>named</strong></span>. This
dynamically-linkable DLZ module--i.e., one which can be
"example.nil", which can answer queries and AXFR requests, and
example.nil. 1800 IN A 10.53.0.1
e.g., by providing different address records for a particular name
(see <a class="xref" href="Bv9ARM.ch04.html#dlz-info" title="DLZ (Dynamically Loadable Zones)">the section called “DLZ (Dynamically Loadable Zones)”</a>), allows zone data to be
<a class="link" href="https://fedorahosted.org/bind-dyndb-ldap/" target="_top">https://fedorahosted.org/bind-dyndb-ldap/</a>.
dyndb example "driver.so" {
"example.nil", which can answer queries and AXFR requests, and
example.nil. 86400 IN A 127.0.0.1
whether the updated RR is an address (i.e., type A or AAAA) and if
zone "catalog.example"
means <span class="command"><strong>rndc addzone</strong></span> and <span class="command"><strong>rndc delzone</strong></span>
catalog.example. IN SOA . . 2016022901 900 600 86400 1
catalog.example. IN NS nsexample.
version.catalog.example. IN TXT "1"
masters.catalog.example. IN A 192.0.2.1
masters.catalog.example. IN AAAA 2001:db8::1
masters.5960775ba382e7a4e09263fc06e7c00569b6a05c.zones.catalog.example. IN AAAA 2001:db8::2
see <a class="xref" href="Bv9ARM.ch11.html#ipv6addresses" title="IPv6 addresses (AAAA)">the section called “IPv6 addresses (AAAA)”</a>.
$ORIGIN example.com.