Bv9ARM.ch04.html revision a1ad6695ed6f988406cf155aa26376f84f73bcb9
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - Copyright (C) 2000-2003 Internet Software Consortium.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - Permission to use, copy, modify, and distribute this software for any
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - purpose with or without fee is hereby granted, provided that the above
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - copyright notice and this permission notice appear in all copies.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce - PERFORMANCE OF THIS SOFTWARE.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<!-- $Id: Bv9ARM.ch04.html,v 1.90 2009/02/24 01:12:23 tbox Exp $ -->
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<link rel="prev" href="Bv9ARM.ch03.html" title="Chapter�3.�Name Server Configuration">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<link rel="next" href="Bv9ARM.ch05.html" title="Chapter�5.�The BIND 9 Lightweight Resolver">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<tr><th colspan="3" align="center">Chapter�4.�Advanced DNS Features</th></tr>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a accesskey="p" href="Bv9ARM.ch03.html">Prev</a>�</td>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<td width="20%" align="right">�<a accesskey="n" href="Bv9ARM.ch05.html">Next</a>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h2 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="Bv9ARM.ch04"></a>Chapter�4.�Advanced DNS Features</h2></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect1"><a href="Bv9ARM.ch04.html#notify">Notify</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect1"><a href="Bv9ARM.ch04.html#dynamic_update">Dynamic Update</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dd><dl><dt><span class="sect2"><a href="Bv9ARM.ch04.html#journal">The journal file</a></span></dt></dl></dd>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect1"><a href="Bv9ARM.ch04.html#incremental_zone_transfers">Incremental Zone Transfers (IXFR)</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect1"><a href="Bv9ARM.ch04.html#id2570513">Split DNS</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dd><dl><dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2570531">Example split DNS setup</a></span></dt></dl></dd>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect1"><a href="Bv9ARM.ch04.html#tsig">TSIG</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571169">Generate Shared Keys for Each Pair of Hosts</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571242">Copying the Shared Secret to Both Machines</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571253">Informing the Servers of the Key's Existence</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571292">Instructing the Server to Use the Key</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571486">TSIG Key Based Access Control</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571531">Errors</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect1"><a href="Bv9ARM.ch04.html#id2571613">TKEY</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect1"><a href="Bv9ARM.ch04.html#id2571662">SIG(0)</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect1"><a href="Bv9ARM.ch04.html#DNSSEC">DNSSEC</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571799">Generating Keys</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571878">Signing the Zone</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571959">Configuring Servers</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect1"><a href="Bv9ARM.ch04.html#id2572102">IPv6 Support in <acronym class="acronym">BIND</acronym> 9</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2572164">Address Lookups Using AAAA Records</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2572185">Address to Name Lookups Using Nibble Format</a></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h2 class="title" style="clear: both">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <acronym class="acronym">DNS</acronym> NOTIFY is a mechanism that allows master
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce servers to notify their slave servers of changes to a zone's data. In
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce response to a <span><strong class="command">NOTIFY</strong></span> from a master server, the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce slave will check to see that its version of the zone is the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce current version and, if not, initiate a zone transfer.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce For more information about <acronym class="acronym">DNS</acronym>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">NOTIFY</strong></span>, see the description of the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">notify</strong></span> option in <a href="Bv9ARM.ch06.html#boolean_options" title="Boolean Options">the section called “Boolean Options”</a> and
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the description of the zone option <span><strong class="command">also-notify</strong></span> in
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <a href="Bv9ARM.ch06.html#zone_transfers" title="Zone Transfers">the section called “Zone Transfers”</a>. The <span><strong class="command">NOTIFY</strong></span>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce protocol is specified in RFC 1996.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce As a slave zone can also be a master to other slaves, named,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce by default, sends <span><strong class="command">NOTIFY</strong></span> messages for every zone
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce it loads. Specifying <span><strong class="command">notify master-only;</strong></span> will
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce cause named to only send <span><strong class="command">NOTIFY</strong></span> for master
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce zones that it loads.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h2 class="title" style="clear: both">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="dynamic_update"></a>Dynamic Update</h2></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Dynamic Update is a method for adding, replacing or deleting
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce records in a master server by sending it a special form of DNS
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce messages. The format and meaning of these messages is specified
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce in RFC 2136.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Dynamic update is enabled by including an
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">allow-update</strong></span> or <span><strong class="command">update-policy</strong></span>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce clause in the <span><strong class="command">zone</strong></span> statement. The
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">tkey-gssapi-credential</strong></span> and
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">tkey-domain</strong></span> clauses in the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">options</strong></span> statement enable the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce server to negotiate keys that can be matched against those
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce in <span><strong class="command">update-policy</strong></span> or
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">allow-update</strong></span>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Updating of secure zones (zones using DNSSEC) follows RFC
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce 3007: RRSIG, NSEC and NSEC3 records affected by updates are
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce automatically regenerated by the server using an online
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce zone key. Update authorization is based on transaction
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce signatures and an explicit server policy.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="journal"></a>The journal file</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce All changes made to a zone using dynamic update are stored
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce in the zone's journal file. This file is automatically created
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce by the server when the first dynamic update takes place.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The name of the journal file is formed by appending the extension
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="filename">.jnl</code> to the name of the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce corresponding zone
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce file unless specifically overridden. The journal file is in a
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce binary format and should not be edited manually.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The server will also occasionally write ("dump")
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the complete contents of the updated zone to its zone file.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce This is not done immediately after
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce each dynamic update, because that would be too slow when a large
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce zone is updated frequently. Instead, the dump is delayed by
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce up to 15 minutes, allowing additional updates to take place.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce When a server is restarted after a shutdown or crash, it will replay
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the journal file to incorporate into the zone any updates that
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce place after the last zone dump.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Changes that result from incoming incremental zone transfers are
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce journalled in a similar way.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The zone files of dynamic zones cannot normally be edited by
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce hand because they are not guaranteed to contain the most recent
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce dynamic changes — those are only in the journal file.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The only way to ensure that the zone file of a dynamic zone
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce is up to date is to run <span><strong class="command">rndc stop</strong></span>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce If you have to make changes to a dynamic zone
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce manually, the following procedure will work: Disable dynamic updates
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to the zone using
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">rndc freeze <em class="replaceable"><code>zone</code></em></strong></span>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce This will also remove the zone's <code class="filename">.jnl</code> file
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce and update the master file. Edit the zone file. Run
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">rndc thaw <em class="replaceable"><code>zone</code></em></strong></span>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to reload the changed zone and re-enable dynamic updates.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h2 class="title" style="clear: both">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="incremental_zone_transfers"></a>Incremental Zone Transfers (IXFR)</h2></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The incremental zone transfer (IXFR) protocol is a way for
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce slave servers to transfer only changed data, instead of having to
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce transfer the entire zone. The IXFR protocol is specified in RFC
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce 1995. See <a href="Bv9ARM.ch09.html#proposed_standards">Proposed Standards</a>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce When acting as a master, <acronym class="acronym">BIND</acronym> 9
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce supports IXFR for those zones
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce where the necessary change history information is available. These
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce include master zones maintained by dynamic update and slave zones
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce whose data was obtained by IXFR. For manually maintained master
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce zones, and for slave zones obtained by performing a full zone
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce transfer (AXFR), IXFR is supported only if the option
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">ixfr-from-differences</strong></span> is set
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to <strong class="userinput"><code>yes</code></strong>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce When acting as a slave, <acronym class="acronym">BIND</acronym> 9 will
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce attempt to use IXFR unless
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce it is explicitly disabled. For more information about disabling
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce IXFR, see the description of the <span><strong class="command">request-ixfr</strong></span> clause
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce of the <span><strong class="command">server</strong></span> statement.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h2 class="title" style="clear: both">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2570513"></a>Split DNS</h2></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Setting up different views, or visibility, of the DNS space to
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce internal and external resolvers is usually referred to as a
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span class="emphasis"><em>Split DNS</em></span> setup. There are several
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce reasons an organization would want to set up its DNS this way.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce One common reason for setting up a DNS system this way is
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to hide "internal" DNS information from "external" clients on the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Internet. There is some debate as to whether or not this is actually
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Internal DNS information leaks out in many ways (via email headers,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce for example) and most savvy "attackers" can find the information
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce they need using other means.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce However, since listing addresses of internal servers that
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce external clients cannot possibly reach can result in
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce connection delays and other annoyances, an organization may
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce choose to use a Split DNS to present a consistent view of itself
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to the outside world.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Another common reason for setting up a Split DNS system is
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to allow internal networks that are behind filters or in RFC 1918
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce space (reserved IP space, as documented in RFC 1918) to resolve DNS
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce on the Internet. Split DNS can also be used to allow mail from outside
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce back in to the internal network.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2570531"></a>Example split DNS setup</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Let's say a company named <span class="emphasis"><em>Example, Inc.</em></span>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce has several corporate sites that have an internal network with
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Internet Protocol (IP) space and an external demilitarized zone (DMZ),
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce or "outside" section of a network, that is available to the public.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span class="emphasis"><em>Example, Inc.</em></span> wants its internal clients
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to be able to resolve external hostnames and to exchange mail with
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce people on the outside. The company also wants its internal resolvers
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to have access to certain internal-only zones that are not available
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce at all outside of the internal network.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce In order to accomplish this, the company will set up two sets
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce of name servers. One set will be on the inside network (in the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce IP space) and the other set will be on bastion hosts, which are
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce hosts that can talk to both sides of its network, in the DMZ.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The internal servers will be configured to forward all queries,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce except queries for <code class="filename">site1.internal</code>, <code class="filename">site2.internal</code>, <code class="filename">site1.example.com</code>,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce and <code class="filename">site2.example.com</code>, to the servers
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce DMZ. These internal servers will have complete sets of information
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce for <code class="filename">site1.example.com</code>, <code class="filename">site2.example.com</code>, <code class="filename">site1.internal</code>,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce To protect the <code class="filename">site1.internal</code> and <code class="filename">site2.internal</code> domains,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the internal name servers must be configured to disallow all queries
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to these domains from any external hosts, including the bastion
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The external servers, which are on the bastion hosts, will
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce be configured to serve the "public" version of the <code class="filename">site1</code> and <code class="filename">site2.example.com</code> zones.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce This could include things such as the host records for public servers
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce (<code class="filename">www.example.com</code> and <code class="filename">ftp.example.com</code>),
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce and mail exchange (MX) records (<code class="filename">a.mx.example.com</code> and <code class="filename">b.mx.example.com</code>).
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce In addition, the public <code class="filename">site1</code> and <code class="filename">site2.example.com</code> zones
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce should have special MX records that contain wildcard (`*') records
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce pointing to the bastion hosts. This is needed because external mail
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce servers do not have any other way of looking up how to deliver mail
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to those internal hosts. With the wildcard records, the mail will
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce be delivered to the bastion host, which can then forward it on to
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce internal hosts.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Here's an example of a wildcard MX record:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<pre class="programlisting">* IN MX 10 external1.example.com.</pre>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Now that they accept mail on behalf of anything in the internal
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce network, the bastion hosts will need to know how to deliver mail
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to internal hosts. In order for this to work properly, the resolvers
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the bastion hosts will need to be configured to point to the internal
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce name servers for DNS resolution.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Queries for internal hostnames will be answered by the internal
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce servers, and queries for external hostnames will be forwarded back
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce out to the DNS servers on the bastion hosts.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce In order for all this to work properly, internal clients will
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce need to be configured to query <span class="emphasis"><em>only</em></span> the internal
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce name servers for DNS queries. This could also be enforced via
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce filtering on the network.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce If everything has been set properly, <span class="emphasis"><em>Example, Inc.</em></span>'s
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce internal clients will now be able to:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Look up any hostnames in the <code class="literal">site1</code>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="literal">site2.example.com</code> zones.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Look up any hostnames in the <code class="literal">site1.internal</code> and
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="literal">site2.internal</code> domains.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<li>Exchange mail with both internal and external people.</li>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Hosts on the Internet will be able to:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Look up any hostnames in the <code class="literal">site1</code>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="literal">site2.example.com</code> zones.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Exchange mail with anyone in the <code class="literal">site1</code> and
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="literal">site2.example.com</code> zones.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Here is an example configuration for the setup we just
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce described above. Note that this is only configuration information;
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce for information on how to configure your zone files, see <a href="Bv9ARM.ch03.html#sample_configuration" title="Sample Configurations">the section called “Sample Configurations”</a>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Internal DNS server config:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luceacl externals { <code class="varname">bastion-ips-go-here</code>; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce forward only;
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce forwarders { // forward to external servers
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-transfer { none; }; // sample allow-transfer (no one)
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-query { internals; externals; }; // restrict query access
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-recursion { internals; }; // restrict recursion
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Lucezone "site1.example.com" { // sample master zone
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce type master;
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce forwarders { }; // do normal iterative
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce // resolution (do not forward)
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-query { internals; externals; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-transfer { internals; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Lucezone "site2.example.com" { // sample slave zone
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce masters { 172.16.72.3; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce forwarders { };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-query { internals; externals; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-transfer { internals; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce type master;
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce forwarders { };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-query { internals; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-transfer { internals; }
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce masters { 172.16.72.3; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce forwarders { };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-query { internals };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-transfer { internals; }
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce External (bastion host) DNS server config:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luceacl externals { bastion-ips-go-here; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-transfer { none; }; // sample allow-transfer (no one)
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-query { any; }; // default query access
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-query-cache { internals; externals; }; // restrict cache access
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-recursion { internals; externals; }; // restrict recursion
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Lucezone "site1.example.com" { // sample slave zone
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce type master;
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-transfer { internals; externals; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce masters { another_bastion_host_maybe; };
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce allow-transfer { internals; externals; }
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce In the <code class="filename">resolv.conf</code> (or equivalent) on
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the bastion host(s):
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Lucenameserver 172.16.72.2
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Lucenameserver 172.16.72.3
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Lucenameserver 172.16.72.4
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h2 class="title" style="clear: both">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce This is a short guide to setting up Transaction SIGnatures
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce (TSIG) based transaction security in <acronym class="acronym">BIND</acronym>. It describes changes
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to the configuration file as well as what changes are required for
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce different features, including the process of creating transaction
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce keys and using transaction signatures with <acronym class="acronym">BIND</acronym>.
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce <acronym class="acronym">BIND</acronym> primarily supports TSIG for server
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce to server communication.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce This includes zone transfer, notify, and recursive query messages.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Resolvers based on newer versions of <acronym class="acronym">BIND</acronym> 8 have limited support
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce TSIG can also be useful for dynamic update. A primary
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce server for a dynamic zone should control access to the dynamic
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce update service, but IP-based access control is insufficient.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The cryptographic access control provided by TSIG
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce is far superior. The <span><strong class="command">nsupdate</strong></span>
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce program supports TSIG via the <code class="option">-k</code> and
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="option">-y</code> command line options or inline by use
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce of the <span><strong class="command">key</strong></span>.
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce<div class="titlepage"><div><div><h3 class="title">
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce<a name="id2571169"></a>Generate Shared Keys for Each Pair of Hosts</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce A shared secret is generated to be shared between <span class="emphasis"><em>host1</em></span> and <span class="emphasis"><em>host2</em></span>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce An arbitrary key name is chosen: "host1-host2.". The key name must
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce be the same on both hosts.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h4 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571186"></a>Automatic Generation</h4></div></div></div>
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce The following command will generate a 128-bit (16 byte) HMAC-MD5
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce key as described above. Longer keys are better, but shorter keys
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce are easier to read. Note that the maximum key length is 512 bits;
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce keys longer than that will be digested with MD5 to produce a
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce 128-bit key.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <strong class="userinput"><code>dnssec-keygen -a hmac-md5 -b 128 -n HOST host1-host2.</code></strong>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The key is in the file <code class="filename">Khost1-host2.+157+00000.private</code>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Nothing directly uses this file, but the base-64 encoded string
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce can be extracted from the file and used as a shared secret:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<pre class="programlisting">Key: La/E5CjG9O+os1jq0a2jdA==</pre>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The string "<code class="literal">La/E5CjG9O+os1jq0a2jdA==</code>" can
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce be used as the shared secret.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h4 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571224"></a>Manual Generation</h4></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The shared secret is simply a random sequence of bits, encoded
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce in base-64. Most ASCII strings are valid base-64 strings (assuming
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the length is a multiple of 4 and only valid characters are used),
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce so the shared secret can be manually generated.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Also, a known string can be run through <span><strong class="command">mmencode</strong></span> or
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce a similar program to generate base-64 encoded data.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce<a name="id2571242"></a>Copying the Shared Secret to Both Machines</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce This is beyond the scope of DNS. A secure transport mechanism
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce should be used. This could be secure FTP, ssh, telephone, etc.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571253"></a>Informing the Servers of the Key's Existence</h3></div></div></div>
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce Imagine <span class="emphasis"><em>host1</em></span> and <span class="emphasis"><em>host 2</em></span>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce both servers. The following is added to each server's <code class="filename">named.conf</code> file:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Lucekey host1-host2. {
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce algorithm hmac-md5;
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The algorithm, hmac-md5, is the only one supported by <acronym class="acronym">BIND</acronym>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The secret is the one generated above. Since this is a secret, it
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce is recommended that either <code class="filename">named.conf</code> be non-world
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce readable, or the key directive be added to a non-world readable
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce file that is included by
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce At this point, the key is recognized. This means that if the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce server receives a message signed by this key, it can verify the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce signature. If the signature is successfully verified, the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce response is signed by the same key.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571292"></a>Instructing the Server to Use the Key</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Since keys are shared between two hosts only, the server must
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce be told when keys are to be used. The following is added to the <code class="filename">named.conf</code> file
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce for <span class="emphasis"><em>host1</em></span>, if the IP address of <span class="emphasis"><em>host2</em></span> is
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luceserver 10.1.2.3 {
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce keys { host1-host2. ;};
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Multiple keys may be present, but only the first is used.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce This directive does not contain any secrets, so it may be in a
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce world-readable
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce If <span class="emphasis"><em>host1</em></span> sends a message that is a request
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to that address, the message will be signed with the specified key. <span class="emphasis"><em>host1</em></span> will
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce expect any responses to signed messages to be signed with the same
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce A similar statement must be present in <span class="emphasis"><em>host2</em></span>'s
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce configuration file (with <span class="emphasis"><em>host1</em></span>'s address) for <span class="emphasis"><em>host2</em></span> to
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce sign request messages to <span class="emphasis"><em>host1</em></span>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571486"></a>TSIG Key Based Access Control</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <acronym class="acronym">BIND</acronym> allows IP addresses and ranges
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to be specified in ACL
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce definitions and
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">allow-{ query | transfer | update }</strong></span>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce This has been extended to allow TSIG keys also. The above key would
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce be denoted <span><strong class="command">key host1-host2.</strong></span>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce An example of an allow-update directive would be:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luceallow-update { key host1-host2. ;};
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce This allows dynamic updates to succeed only if the request
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce was signed by a key named "<span><strong class="command">host1-host2.</strong></span>".
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce You may want to read about the more powerful
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">update-policy</strong></span> statement in
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <a href="Bv9ARM.ch06.html#dynamic_update_policies" title="Dynamic Update Policies">the section called “Dynamic Update Policies”</a>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571531"></a>Errors</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The processing of TSIG signed messages can result in
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce several errors. If a signed message is sent to a non-TSIG aware
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce server, a FORMERR (format error) will be returned, since the server will not
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce understand the record. This is a result of misconfiguration,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce since the server must be explicitly configured to send a TSIG
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce signed message to a specific server.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce If a TSIG aware server receives a message signed by an
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce unknown key, the response will be unsigned with the TSIG
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce extended error code set to BADKEY. If a TSIG aware server
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce receives a message with a signature that does not validate, the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce response will be unsigned with the TSIG extended error code set
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to BADSIG. If a TSIG aware server receives a message with a time
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce outside of the allowed range, the response will be signed with
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the TSIG extended error code set to BADTIME, and the time values
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce will be adjusted so that the response can be successfully
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce verified. In any of these cases, the message's rcode (response code) is set to
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce NOTAUTH (not authenticated).
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h2 class="title" style="clear: both">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571613"></a>TKEY</h2></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<p><span><strong class="command">TKEY</strong></span>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce is a mechanism for automatically generating a shared secret
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce between two hosts. There are several "modes" of
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">TKEY</strong></span> that specify how the key is generated
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce or assigned. <acronym class="acronym">BIND</acronym> 9 implements only one of
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce these modes, the Diffie-Hellman key exchange. Both hosts are
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce required to have a Diffie-Hellman KEY record (although this
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce record is not required to be present in a zone). The
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">TKEY</strong></span> process must use signed messages,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce signed either by TSIG or SIG(0). The result of
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">TKEY</strong></span> is a shared secret that can be used to
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce sign messages with TSIG. <span><strong class="command">TKEY</strong></span> can also be
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce used to delete shared secrets that it had previously
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The <span><strong class="command">TKEY</strong></span> process is initiated by a
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce or server by sending a signed <span><strong class="command">TKEY</strong></span>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce (including any appropriate KEYs) to a TKEY-aware server. The
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce server response, if it indicates success, will contain a
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">TKEY</strong></span> record and any appropriate keys.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce this exchange, both participants have enough information to
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce determine the shared secret; the exact process depends on the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">TKEY</strong></span> mode. When using the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Diffie-Hellman
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">TKEY</strong></span> mode, Diffie-Hellman keys are
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce and the shared secret is derived by both participants.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h2 class="title" style="clear: both">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571662"></a>SIG(0)</h2></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <acronym class="acronym">BIND</acronym> 9 partially supports DNSSEC SIG(0)
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce transaction signatures as specified in RFC 2535 and RFC 2931.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce uses public/private keys to authenticate messages. Access control
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce is performed in the same manner as TSIG keys; privileges can be
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce granted or denied based on the key name.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce When a SIG(0) signed message is received, it will only be
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce verified if the key is known and trusted by the server; the server
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce will not attempt to locate and/or validate the key.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce SIG(0) signing of multiple-message TCP streams is not
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The only tool shipped with <acronym class="acronym">BIND</acronym> 9 that
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce generates SIG(0) signed messages is <span><strong class="command">nsupdate</strong></span>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h2 class="title" style="clear: both">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Cryptographic authentication of DNS information is possible
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce through the DNS Security (<span class="emphasis"><em>DNSSEC-bis</em></span>) extensions,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce defined in RFC 4033, RFC 4034, and RFC 4035.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce This section describes the creation and use of DNSSEC signed zones.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce In order to set up a DNSSEC secure zone, there are a series
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce of steps which must be followed. <acronym class="acronym">BIND</acronym>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce with several tools
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce that are used in this process, which are explained in more detail
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce below. In all cases, the <code class="option">-h</code> option prints a
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce full list of parameters. Note that the DNSSEC tools require the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce keyset files to be in the working directory or the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce directory specified by the <code class="option">-d</code> option, and
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce that the tools shipped with BIND 9.2.x and earlier are not compatible
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce with the current ones.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce There must also be communication with the administrators of
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the parent and/or child zone to transmit keys. A zone's security
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce status must be indicated by the parent zone for a DNSSEC capable
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce resolver to trust its data. This is done through the presence
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce or absence of a <code class="literal">DS</code> record at the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce For other servers to trust data in this zone, they must
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce either be statically configured with this zone's zone key or the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce zone key of another zone above this one in the DNS tree.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571799"></a>Generating Keys</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The <span><strong class="command">dnssec-keygen</strong></span> program is used to
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce generate keys.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce A secure zone must contain one or more zone keys. The
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce zone keys will sign all other records in the zone, as well as
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the zone keys of any secure delegated zones. Zone keys must
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce have the same name as the zone, a name type of
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">ZONE</strong></span>, and must be usable for
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce authentication.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce It is recommended that zone keys use a cryptographic algorithm
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce designated as "mandatory to implement" by the IETF; currently
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the only one is RSASHA1.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The following command will generate a 768-bit RSASHA1 key for
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the <code class="filename">child.example</code> zone:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <strong class="userinput"><code>dnssec-keygen -a RSASHA1 -b 768 -n ZONE child.example.</code></strong>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Two output files will be produced:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="filename">Kchild.example.+005+12345.key</code> and
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="filename">Kchild.example.+005+12345.private</code>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce 12345 is an example of a key tag). The key filenames contain
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the key name (<code class="filename">child.example.</code>),
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce algorithm (3
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce is DSA, 1 is RSAMD5, 5 is RSASHA1, etc.), and the key tag (12345 in
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The private key (in the <code class="filename">.private</code>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce used to generate signatures, and the public key (in the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="filename">.key</code> file) is used for signature
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce verification.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce To generate another key with the same properties (but with
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce a different key tag), repeat the above command.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The <span><strong class="command">dnssec-keyfromlabel</strong></span> program is used
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to get a key pair from a crypto hardware and build the key
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce files. Its usage is similar to <span><strong class="command">dnssec-keygen</strong></span>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The public keys should be inserted into the zone file by
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce including the <code class="filename">.key</code> files using
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">$INCLUDE</strong></span> statements.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571878"></a>Signing the Zone</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The <span><strong class="command">dnssec-signzone</strong></span> program is used
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to sign a zone.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Any <code class="filename">keyset</code> files corresponding to
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce secure subzones should be present. The zone signer will
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce generate <code class="literal">NSEC</code>, <code class="literal">NSEC3</code>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce and <code class="literal">RRSIG</code> records for the zone, as
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce well as <code class="literal">DS</code> for the child zones if
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="literal">'-g'</code> is specified. If <code class="literal">'-g'</code>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce is not specified, then DS RRsets for the secure child
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce zones need to be added manually.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The following command signs the zone, assuming it is in a
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce file called <code class="filename">zone.child.example</code>. By
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce default, all zone keys which have an available private key are
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce used to generate signatures.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <strong class="userinput"><code>dnssec-signzone -o child.example zone.child.example</code></strong>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce One output file is produced:
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="filename">zone.child.example.signed</code>. This
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce should be referenced by <code class="filename">named.conf</code>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce input file for the zone.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<p><span><strong class="command">dnssec-signzone</strong></span>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce will also produce a keyset and dsset files and optionally a
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce dlvset file. These are used to provide the parent zone
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce administrators with the <code class="literal">DNSKEYs</code> (or their
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce corresponding <code class="literal">DS</code> records) that are the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce secure entry point to the zone.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2571959"></a>Configuring Servers</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce To enable <span><strong class="command">named</strong></span> to respond appropriately
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to DNS requests from DNSSEC aware clients,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">dnssec-enable</strong></span> must be set to yes.
c71787bd6356c92e9c7d0a174cd63ab17fcf34c6Eric Luce To enable <span><strong class="command">named</strong></span> to validate answers from
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce other servers both <span><strong class="command">dnssec-enable</strong></span> and
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">dnssec-validation</strong></span> must be set and some
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">trusted-keys</strong></span> must be configured
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">trusted-keys</strong></span> are copies of DNSKEY RRs
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce for zones that are used to form the first link in the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce cryptographic chain of trust. All keys listed in
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">trusted-keys</strong></span> (and corresponding zones)
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce are deemed to exist and only the listed keys will be used
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to validated the DNSKEY RRset that they are from.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span><strong class="command">trusted-keys</strong></span> are described in more detail
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce later in this document.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Unlike <acronym class="acronym">BIND</acronym> 8, <acronym class="acronym">BIND</acronym>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce 9 does not verify signatures on load, so zone keys for
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce authoritative zones do not need to be specified in the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce configuration file.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce After DNSSEC gets established, a typical DNSSEC configuration
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce will look something like the following. It has a one or
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce more public keys for the root. This allows answers from
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce outside the organization to be validated. It will also
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce have several keys for parts of the namespace the organization
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce controls. These are here to ensure that named is immune
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce to compromises in the DNSSEC components of the security
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce of parent zones.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Lucetrusted-keys {
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce /* Root Key */
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce"." 257 3 3 "BNY4wrWM1nCfJ+CXd0rVXyYmobt7sEEfK3clRbGaTwSJxrGkxJWoZu6I7PzJu/
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce E9gx4UC1zGAHlXKdE4zYIpRhaBKnvcC2U9mZhkdUpd1Vso/HAdjNe8LmMlnzY3
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce zy2Xy4klWOADTPzSv9eamj8V18PHGjBLaVtYvk/ln5ZApjYghf+6fElrmLkdaz
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce MQ2OCnACR817DF4BBa7UR/beDHyp5iWTXWSi6XmoJLbG9Scqc7l70KDqlvXR3M
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce /lUUVRbkeg1IPJSidmK3ZyCllh4XSKbje/45SKucHgnwU5jefMtq66gKodQj+M
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce iA21AfUVe7u99WzTLzY3qlxDhxYQQ20FQ97S+LKUTpQcq27R7AT3/V5hRQxScI
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Nqwcz4jYqZD2fQdgxbcDTClU0CRBdiieyLMNzXG3";
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce/* Key for our organization's forward zone */
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luceexample.com. 257 3 5 "AwEAAaxPMcR2x0HbQV4WeZB6oEDX+r0QM65KbhTjrW1ZaARmPhEZZe
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce 3Y9ifgEuq7vZ/zGZUdEGNWy+JZzus0lUptwgjGwhUS1558Hb4JKUbb
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce OTcM8pwXlj0EiX3oDFVmjHO444gLkBO UKUf/mC7HvfwYH/Be22GnC
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce lrinKJp1Og4ywzO9WglMk7jbfW33gUKvirTHr25GL7STQUzBb5Usxt
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce 8lgnyTUHs1t3JwCY5hKZ6CqFxmAVZP20igTixin/1LcrgX/KMEGd/b
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce iuvF4qJCyduieHukuY3H4XMAcR+xia2 nIUPvm/oyWR8BW/hWdzOvn
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce/* Key for our reverse zone. */
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce2.0.192.IN-ADDRPA.NET. 257 3 5 "AQOnS4xn/IgOUpBPJ3bogzwcxOdNax071L18QqZnQQQA
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce VVr+iLhGTnNGp3HoWQLUIzKrJVZ3zggy3WwNT6kZo6c0
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce yOI6BgPsw+YZdzlYMaIJGf4M4dyoKIhzdZyQ2bYQrjyQ
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce 4LB0lC7aOnsMyYKHHYeRv PxjIQXmdqgOJGq+vsevG06
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce 7HJYHJhAZD5L59VvjSPsZJHeDCUyWYrvPZesZDIRvhDD
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce dnssec-enable yes;
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce dnssec-validation yes;
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce None of the keys listed in this example are valid. In particular,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the root key is not valid.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h2 class="title" style="clear: both">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2572102"></a>IPv6 Support in <acronym class="acronym">BIND</acronym> 9</h2></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <acronym class="acronym">BIND</acronym> 9 fully supports all currently
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce defined forms of IPv6
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce name to address and address to name lookups. It will also use
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce IPv6 addresses to make queries when running on an IPv6 capable
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce For forward lookups, <acronym class="acronym">BIND</acronym> 9 supports
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce only AAAA records. RFC 3363 deprecated the use of A6 records,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce and client-side support for A6 records was accordingly removed
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce However, authoritative <acronym class="acronym">BIND</acronym> 9 name servers still
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce load zone files containing A6 records correctly, answer queries
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce for A6 records, and accept zone transfer for a zone containing A6
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce For IPv6 reverse lookups, <acronym class="acronym">BIND</acronym> 9 supports
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the traditional "nibble" format used in the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span class="emphasis"><em>ip6.arpa</em></span> domain, as well as the older, deprecated
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <span class="emphasis"><em>ip6.int</em></span> domain.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Older versions of <acronym class="acronym">BIND</acronym> 9
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce supported the "binary label" (also known as "bitstring") format,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce but support of binary labels has been completely removed per
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Many applications in <acronym class="acronym">BIND</acronym> 9 do not understand
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the binary label format at all any more, and will return an
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce error if given.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce In particular, an authoritative <acronym class="acronym">BIND</acronym> 9
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce name server will not load a zone file containing binary labels.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce For an overview of the format and structure of IPv6 addresses,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce see <a href="Bv9ARM.ch09.html#ipv6addresses" title="IPv6 addresses (AAAA)">the section called “IPv6 addresses (AAAA)”</a>.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2572164"></a>Address Lookups Using AAAA Records</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce The IPv6 AAAA record is a parallel to the IPv4 A record,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce and, unlike the deprecated A6 record, specifies the entire
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce IPv6 address in a single record. For example,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Lucehost 3600 IN AAAA 2001:db8::1
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Use of IPv4-in-IPv6 mapped addresses is not recommended.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce If a host has an IPv4 address, use an A record, not
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce a AAAA, with <code class="literal">::ffff:192.168.42.1</code> as
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce the address.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<div class="titlepage"><div><div><h3 class="title">
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a name="id2572185"></a>Address to Name Lookups Using Nibble Format</h3></div></div></div>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce When looking up an address in nibble format, the address
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce components are simply reversed, just as in IPv4, and
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="literal">ip6.arpa.</code> is appended to the
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce resulting name.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce For example, the following would provide reverse name lookup for
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce a host with address
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0 14400 IN PTR host.example.com.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<a accesskey="p" href="Bv9ARM.ch03.html">Prev</a>�</td>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<td width="40%" align="right">�<a accesskey="n" href="Bv9ARM.ch05.html">Next</a>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<td width="40%" align="left" valign="top">Chapter�3.�Name Server Configuration�</td>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<td width="40%" align="right" valign="top">�Chapter�5.�The <acronym class="acronym">BIND</acronym> 9 Lightweight Resolver</td>