Bv9ARM.ch04.html revision ff5760e233f6ab75e33783b6dd48f961ce04d933
ea6fe0d54f36754c195b3b8dac47c81f7993677eMark Andrews<HTML
ea6fe0d54f36754c195b3b8dac47c81f7993677eMark Andrews><HEAD
ea6fe0d54f36754c195b3b8dac47c81f7993677eMark Andrews><TITLE
6bd8cee98332533a4fa705b82ca9ec1606738ba9Mark Andrews>Advanced Concepts</TITLE
6bd8cee98332533a4fa705b82ca9ec1606738ba9Mark Andrews><META
6bd8cee98332533a4fa705b82ca9ec1606738ba9Mark AndrewsNAME="GENERATOR"
0c2509b0b9f9e455fa9d347d08f6ba9abd86d418Mark AndrewsCONTENT="Modular DocBook HTML Stylesheet Version 1.61
0c2509b0b9f9e455fa9d347d08f6ba9abd86d418Mark Andrews"><LINK
0c2509b0b9f9e455fa9d347d08f6ba9abd86d418Mark AndrewsREL="HOME"
8b5de9701428e2b5eb50aba96af23dc1186124ddMark AndrewsTITLE="BIND 9 Administrator Reference Manual"
8b5de9701428e2b5eb50aba96af23dc1186124ddMark AndrewsHREF="Bv9ARM.html"><LINK
80b782f356f0692c11b4e52e8dd46ec41704e5a2Mark AndrewsREL="PREVIOUS"
80b782f356f0692c11b4e52e8dd46ec41704e5a2Mark AndrewsTITLE="Nameserver Configuration"
80b782f356f0692c11b4e52e8dd46ec41704e5a2Mark AndrewsHREF="Bv9ARM.ch03.html"><LINK
80b782f356f0692c11b4e52e8dd46ec41704e5a2Mark AndrewsREL="NEXT"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsTITLE="The BIND 9 Lightweight Resolver"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsHREF="Bv9ARM.ch05.html"></HEAD
b500de3be9ba5318da157364bf9fbbda5f88f203Mark Andrews><BODY
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsCLASS="chapter"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsBGCOLOR="#FFFFFF"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsTEXT="#000000"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsLINK="#0000FF"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsVLINK="#840084"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsALINK="#0000FF"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark Andrews><DIV
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsCLASS="NAVHEADER"
53cf67186506f9557aaf2149898dd76715803db2Mark Andrews><TABLE
53cf67186506f9557aaf2149898dd76715803db2Mark AndrewsWIDTH="100%"
53cf67186506f9557aaf2149898dd76715803db2Mark AndrewsBORDER="0"
53cf67186506f9557aaf2149898dd76715803db2Mark AndrewsCELLPADDING="0"
53cf67186506f9557aaf2149898dd76715803db2Mark AndrewsCELLSPACING="0"
53cf67186506f9557aaf2149898dd76715803db2Mark Andrews><TR
53cf67186506f9557aaf2149898dd76715803db2Mark Andrews><TH
888bb8bf68ba1a2b032a64122efd9125a9155ad7Mark AndrewsCOLSPAN="3"
888bb8bf68ba1a2b032a64122efd9125a9155ad7Mark AndrewsALIGN="center"
888bb8bf68ba1a2b032a64122efd9125a9155ad7Mark Andrews>BIND 9 Administrator Reference Manual</TH
b312748a11d27fe387984973ba79975a9d6863c4Mark Andrews></TR
b312748a11d27fe387984973ba79975a9d6863c4Mark Andrews><TR
b312748a11d27fe387984973ba79975a9d6863c4Mark Andrews><TD
b312748a11d27fe387984973ba79975a9d6863c4Mark AndrewsWIDTH="10%"
b312748a11d27fe387984973ba79975a9d6863c4Mark AndrewsALIGN="left"
b312748a11d27fe387984973ba79975a9d6863c4Mark AndrewsVALIGN="bottom"
b312748a11d27fe387984973ba79975a9d6863c4Mark Andrews><A
b312748a11d27fe387984973ba79975a9d6863c4Mark AndrewsHREF="Bv9ARM.ch03.html"
b312748a11d27fe387984973ba79975a9d6863c4Mark Andrews>Prev</A
b312748a11d27fe387984973ba79975a9d6863c4Mark Andrews></TD
b312748a11d27fe387984973ba79975a9d6863c4Mark Andrews><TD
b312748a11d27fe387984973ba79975a9d6863c4Mark AndrewsWIDTH="80%"
ee84964a7d29ae88769f67326a65256731769ea7Mark AndrewsALIGN="center"
ee84964a7d29ae88769f67326a65256731769ea7Mark AndrewsVALIGN="bottom"
ee84964a7d29ae88769f67326a65256731769ea7Mark Andrews></TD
ee84964a7d29ae88769f67326a65256731769ea7Mark Andrews><TD
ee84964a7d29ae88769f67326a65256731769ea7Mark AndrewsWIDTH="10%"
ee84964a7d29ae88769f67326a65256731769ea7Mark AndrewsALIGN="right"
463fc8f9d61e07613486e64b4b7b3f924ea2b25cMark AndrewsVALIGN="bottom"
463fc8f9d61e07613486e64b4b7b3f924ea2b25cMark Andrews><A
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark AndrewsHREF="Bv9ARM.ch05.html"
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark Andrews>Next</A
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark Andrews></TD
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark Andrews></TR
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark Andrews></TABLE
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark Andrews><HR
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark AndrewsALIGN="LEFT"
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark AndrewsWIDTH="100%"></DIV
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark Andrews><DIV
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark AndrewsCLASS="chapter"
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark Andrews><H1
9368d7df838f58cd32922b526775ca730bc633cfMark Andrews><A
9368d7df838f58cd32922b526775ca730bc633cfMark AndrewsNAME="ch04"
9368d7df838f58cd32922b526775ca730bc633cfMark Andrews>Chapter 4. Advanced Concepts</A
9368d7df838f58cd32922b526775ca730bc633cfMark Andrews></H1
e2fb08b85de8158fe6b71008311e3d98104b92a6Mark Andrews><DIV
e2fb08b85de8158fe6b71008311e3d98104b92a6Mark AndrewsCLASS="TOC"
e2fb08b85de8158fe6b71008311e3d98104b92a6Mark Andrews><DL
22a9cd54c072545d13788ceead759911fe8cfe34Mark Andrews><DT
22a9cd54c072545d13788ceead759911fe8cfe34Mark Andrews><B
22a9cd54c072545d13788ceead759911fe8cfe34Mark Andrews>Table of Contents</B
21ba6c18e4ccc73933af5cf28701a5cc3b7963ecMark Andrews></DT
21ba6c18e4ccc73933af5cf28701a5cc3b7963ecMark Andrews><DT
266296414d0ed79980c6d3144a587b42324a50ffMark Andrews>4.1. <A
266296414d0ed79980c6d3144a587b42324a50ffMark AndrewsHREF="Bv9ARM.ch04.html#dynamic_update"
c960dffe35970da729219b72f2e41350d3b64c35Mark Andrews>Dynamic Update</A
c960dffe35970da729219b72f2e41350d3b64c35Mark Andrews></DT
5da49e379c79fbd597cf0d47e7697b65991f761fMark Andrews><DT
5da49e379c79fbd597cf0d47e7697b65991f761fMark Andrews>4.2. <A
31b3dc1c6b4fe99a2af2ee63314e842af4a20070Mark AndrewsHREF="Bv9ARM.ch04.html#incremental_zone_transfers"
31b3dc1c6b4fe99a2af2ee63314e842af4a20070Mark Andrews>Incremental Zone Transfers (IXFR)</A
59f51f864c752d2e4bf8d1ad94404ada0c9aa6e9Mark Andrews></DT
59f51f864c752d2e4bf8d1ad94404ada0c9aa6e9Mark Andrews><DT
59f51f864c752d2e4bf8d1ad94404ada0c9aa6e9Mark Andrews>4.3. <A
a207a2835e37de52e11d4c143c0425e749409c46Mark AndrewsHREF="Bv9ARM.ch04.html#AEN714"
a207a2835e37de52e11d4c143c0425e749409c46Mark Andrews>Split DNS</A
03760eeb542cc5e91193eec478cae022df4bcc58Mark Andrews></DT
03760eeb542cc5e91193eec478cae022df4bcc58Mark Andrews><DT
838d608e6f37038f2fb43980a7a9d6b6a490db36Mark Andrews>4.4. <A
838d608e6f37038f2fb43980a7a9d6b6a490db36Mark AndrewsHREF="Bv9ARM.ch04.html#tsig"
64cc9c8818db2552cbdd77f1050e890ffa5a17d8Mark Andrews>TSIG</A
64cc9c8818db2552cbdd77f1050e890ffa5a17d8Mark Andrews></DT
64cc9c8818db2552cbdd77f1050e890ffa5a17d8Mark Andrews><DT
64cc9c8818db2552cbdd77f1050e890ffa5a17d8Mark Andrews>4.5. <A
0f09ef5a50ef09eaed8e6630b4004d5143d6b52cMark AndrewsHREF="Bv9ARM.ch04.html#AEN874"
0f09ef5a50ef09eaed8e6630b4004d5143d6b52cMark Andrews>TKEY</A
0f09ef5a50ef09eaed8e6630b4004d5143d6b52cMark Andrews></DT
0f09ef5a50ef09eaed8e6630b4004d5143d6b52cMark Andrews><DT
c7fc6434fe5949c8e3f76bf69f5655eb3a76dfaeMark Andrews>4.6. <A
c7fc6434fe5949c8e3f76bf69f5655eb3a76dfaeMark AndrewsHREF="Bv9ARM.ch04.html#AEN889"
9bd478a5e6df956a79bbdb5c182d5b44763786ceMark Andrews>SIG(0)</A
9bd478a5e6df956a79bbdb5c182d5b44763786ceMark Andrews></DT
9bd478a5e6df956a79bbdb5c182d5b44763786ceMark Andrews><DT
421e4cf66e4cba0b0751a34a9c027e39fe0474f9Mark Andrews>4.7. <A
421e4cf66e4cba0b0751a34a9c027e39fe0474f9Mark AndrewsHREF="Bv9ARM.ch04.html#DNSSEC"
421e4cf66e4cba0b0751a34a9c027e39fe0474f9Mark Andrews>DNSSEC</A
b0c15bd9792112fb47f6d956e580e4369e92f4e7Mark Andrews></DT
b0c15bd9792112fb47f6d956e580e4369e92f4e7Mark Andrews><DT
b0c15bd9792112fb47f6d956e580e4369e92f4e7Mark Andrews>4.8. <A
b0c15bd9792112fb47f6d956e580e4369e92f4e7Mark AndrewsHREF="Bv9ARM.ch04.html#AEN974"
b0c15bd9792112fb47f6d956e580e4369e92f4e7Mark Andrews>IPv6 Support in <SPAN
bf7f253e306d0ced8ae24d7a0598773950da11f4Mark AndrewsCLASS="acronym"
bf7f253e306d0ced8ae24d7a0598773950da11f4Mark Andrews>BIND</SPAN
bf7f253e306d0ced8ae24d7a0598773950da11f4Mark Andrews> 9</A
0ffaee887ff5674b8c3bb0435ae838f641981706Mark Andrews></DT
0ffaee887ff5674b8c3bb0435ae838f641981706Mark Andrews></DL
0ffaee887ff5674b8c3bb0435ae838f641981706Mark Andrews></DIV
0ffaee887ff5674b8c3bb0435ae838f641981706Mark Andrews><DIV
5f89a1ee9e0fe64211d050db5d3e7a5ea282c282Mark AndrewsCLASS="sect1"
5f89a1ee9e0fe64211d050db5d3e7a5ea282c282Mark Andrews><H1
c86eed4bdecad9df12f992f9d743dfee3a6c5bdcMark AndrewsCLASS="sect1"
c86eed4bdecad9df12f992f9d743dfee3a6c5bdcMark Andrews><A
12ff7274fe2ea531ecca6a71fb9f7e1ae92da389Mark AndrewsNAME="dynamic_update"
12ff7274fe2ea531ecca6a71fb9f7e1ae92da389Mark Andrews>4.1. Dynamic Update</A
9d3ad53203f1ac49f9e876dbbcaca18656eb3e19Mark Andrews></H1
9d3ad53203f1ac49f9e876dbbcaca18656eb3e19Mark Andrews><P
767fd19da4b699aae46959d834f53af0e1166e80Mark Andrews>Dynamic update is the term used for the ability under
767fd19da4b699aae46959d834f53af0e1166e80Mark Andrews certain specified conditions to add, modify or delete records or
767fd19da4b699aae46959d834f53af0e1166e80Mark Andrews RRsets in the master zone files. Dynamic update is fully described
767fd19da4b699aae46959d834f53af0e1166e80Mark Andrews in RFC 2136.</P
8da0b50e8a8c74602eca97e261ce4ad457df5048Mark Andrews><P
8da0b50e8a8c74602eca97e261ce4ad457df5048Mark Andrews>Dynamic update is enabled on a zone-by-zone basis, by
5b76a09697bfc76f5acefd65d5b37b1214d271a8Mark Andrews including an <B
5b76a09697bfc76f5acefd65d5b37b1214d271a8Mark AndrewsCLASS="command"
6388dcf8e661687c30a5d52f149d193ce86748a8Mark Andrews>allow-update</B
6388dcf8e661687c30a5d52f149d193ce86748a8Mark Andrews> or
6388dcf8e661687c30a5d52f149d193ce86748a8Mark Andrews <B
93e353425a81da7793dde3776f4caca658f57c11Mark AndrewsCLASS="command"
93e353425a81da7793dde3776f4caca658f57c11Mark Andrews>update-policy</B
93e353425a81da7793dde3776f4caca658f57c11Mark Andrews> clause in the
93e353425a81da7793dde3776f4caca658f57c11Mark Andrews <B
49a940dc68b30d9e4f9e1bd3c0503d8b90bb1726Mark AndrewsCLASS="command"
49a940dc68b30d9e4f9e1bd3c0503d8b90bb1726Mark Andrews>zone</B
49a940dc68b30d9e4f9e1bd3c0503d8b90bb1726Mark Andrews> statement.</P
d92770e851ebbc1005b3bf121e3c9f13b67a3f42Mark Andrews><P
d92770e851ebbc1005b3bf121e3c9f13b67a3f42Mark Andrews>Updating of secure zones (zones using DNSSEC) follows
59ab128c972622f5aeafe3229966dcba73b62243Mark Andrews RFC 3007: SIG and NXT records affected by updates are automatically
59ab128c972622f5aeafe3229966dcba73b62243Mark Andrews regenerated by the server using an online zone key.
59ab128c972622f5aeafe3229966dcba73b62243Mark Andrews Update authorization is based
90295f915c883d1aeeda856f518584d4219a704aMark Andrews on transaction signatures and an explicit server policy.</P
90295f915c883d1aeeda856f518584d4219a704aMark Andrews><DIV
90295f915c883d1aeeda856f518584d4219a704aMark AndrewsCLASS="sect2"
1c75ea91cdb49dac65f0f592ddbf66bfdfc4a2d7Mark Andrews><H2
1c75ea91cdb49dac65f0f592ddbf66bfdfc4a2d7Mark AndrewsCLASS="sect2"
1c75ea91cdb49dac65f0f592ddbf66bfdfc4a2d7Mark Andrews><A
142d155dd68fd601dc38c6b6f7c35f2798ec24caMark AndrewsNAME="journal"
142d155dd68fd601dc38c6b6f7c35f2798ec24caMark Andrews>4.1.1. The journal file</A
99776003811a413457a2c35a808ad860df877d24Mark Andrews></H2
99776003811a413457a2c35a808ad860df877d24Mark Andrews><P
99776003811a413457a2c35a808ad860df877d24Mark Andrews>All changes made to a zone using dynamic update are stored in the
2ffb3eb384ae71ae9f8edbf5fa2219d965ff0552Mark Andrews zone's journal file. This file is automatically created by the
2ffb3eb384ae71ae9f8edbf5fa2219d965ff0552Mark Andrews server when when the first dynamic update takes place. The name of
2ffb3eb384ae71ae9f8edbf5fa2219d965ff0552Mark Andrews the journal file is formed by appending the
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews extension <TT
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark AndrewsCLASS="filename"
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews>.jnl</TT
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews> to the
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews name of the corresponding zone file. The journal file is in a
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews binary format and should not be edited manually.</P
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews><P
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews>The server will also occasionally write ("dump")
52fc1457e44c476a81ec9dee6a664958cb64b8e2Mark Andrews the complete contents of the updated zone to its zone file.
52fc1457e44c476a81ec9dee6a664958cb64b8e2Mark Andrews This is not done immediately after
6526fd032fc418411da3af4201214e95c113d3e2Mark Andrews each dynamic update, because that would be too slow when a large
6526fd032fc418411da3af4201214e95c113d3e2Mark Andrews zone is updated frequently. Instead, the dump is delayed by 15
b8fff4f0d70bb9c5e53023ad0dae0acda67b5cdaMark Andrews minutes, allowing additional updates to take place.</P
b8fff4f0d70bb9c5e53023ad0dae0acda67b5cdaMark Andrews><P
757bf8a1e5d85806c648d7a6267da8d49a8ab822Tatuya JINMEI 神明達哉>When a server is restarted after a shutdown or crash, it will replay
757bf8a1e5d85806c648d7a6267da8d49a8ab822Tatuya JINMEI 神明達哉 the journal file to incorporate into the zone any updates that took
be0e075ac2c10ade3e80edef7fa14ac0fda92690Mark Andrews place after the last zone dump.</P
be0e075ac2c10ade3e80edef7fa14ac0fda92690Mark Andrews><P
be0e075ac2c10ade3e80edef7fa14ac0fda92690Mark Andrews>Changes that result from incoming incremental zone transfers are also
2a908588fbeacebc5f13b153b73c96e12dacaadcTatuya JINMEI 神明達哉 journalled in a similar way.</P
2a908588fbeacebc5f13b153b73c96e12dacaadcTatuya JINMEI 神明達哉><P
2a908588fbeacebc5f13b153b73c96e12dacaadcTatuya JINMEI 神明達哉>The zone files of dynamic zones cannot normally be edited by
2a908588fbeacebc5f13b153b73c96e12dacaadcTatuya JINMEI 神明達哉 hand because they are not guaranteed to contain the most recent
af2be1a46813e228cb9d71230d3f41222fdb69baTatuya JINMEI 神明達哉 dynamic changes - those are only in the journal file.
af2be1a46813e228cb9d71230d3f41222fdb69baTatuya JINMEI 神明達哉 The only way to ensure that the zone file of a dynamic zone
af2be1a46813e228cb9d71230d3f41222fdb69baTatuya JINMEI 神明達哉 is up to date is to run <B
2945ac15af547df0268e449252902ead599e2451Mark AndrewsCLASS="command"
2945ac15af547df0268e449252902ead599e2451Mark Andrews>rndc stop</B
2945ac15af547df0268e449252902ead599e2451Mark Andrews>.</P
285761cf91626976e211f69d9678c138b25f8629Tatuya JINMEI 神明達哉><P
285761cf91626976e211f69d9678c138b25f8629Tatuya JINMEI 神明達哉>If you have to make changes to a dynamic zone
285761cf91626976e211f69d9678c138b25f8629Tatuya JINMEI 神明達哉 manually, the following procedure will work: Shut down
ca70688bf60b4f50c4e3ec7d40567341c9962fafMark Andrews the server using <B
ca70688bf60b4f50c4e3ec7d40567341c9962fafMark AndrewsCLASS="command"
ca70688bf60b4f50c4e3ec7d40567341c9962fafMark Andrews>rndc stop</B
ca70688bf60b4f50c4e3ec7d40567341c9962fafMark Andrews> (sending a signal
8b0ee8448bec37bf1e771363dccce7c0e73eb1a7Mark Andrews or using <B
8b0ee8448bec37bf1e771363dccce7c0e73eb1a7Mark AndrewsCLASS="command"
aec2d57d5b9f5ca97763a1b49b76f0bcb5852e1aMark Andrews>rndc halt</B
aec2d57d5b9f5ca97763a1b49b76f0bcb5852e1aMark Andrews> is <I
aec2d57d5b9f5ca97763a1b49b76f0bcb5852e1aMark AndrewsCLASS="emphasis"
aec2d57d5b9f5ca97763a1b49b76f0bcb5852e1aMark Andrews>not</I
a9ae9d743c7f85bec44e95b1f62c7a2a114a2fd6Mark Andrews>
a9ae9d743c7f85bec44e95b1f62c7a2a114a2fd6Mark Andrews sufficient). Wait for the server to exit,
a9ae9d743c7f85bec44e95b1f62c7a2a114a2fd6Mark Andrews then <I
ebbbd34776d668bb2d7cf100b58a6f647c431c03Mark AndrewsCLASS="emphasis"
75ace6601e66840436f52e61353ee0d400577b55Mark Andrews>remove</I
75ace6601e66840436f52e61353ee0d400577b55Mark Andrews> the zone's
75ace6601e66840436f52e61353ee0d400577b55Mark Andrews <TT
75ace6601e66840436f52e61353ee0d400577b55Mark AndrewsCLASS="filename"
75ace6601e66840436f52e61353ee0d400577b55Mark Andrews>.jnl</TT
75ace6601e66840436f52e61353ee0d400577b55Mark Andrews> file, edit the zone file,
75ace6601e66840436f52e61353ee0d400577b55Mark Andrews and restart the server. Removing the <TT
75ace6601e66840436f52e61353ee0d400577b55Mark AndrewsCLASS="filename"
75ace6601e66840436f52e61353ee0d400577b55Mark Andrews>.jnl</TT
75ace6601e66840436f52e61353ee0d400577b55Mark Andrews>
ba4aec8c1853a1deda8eb43ffeaac4d764c8d39eMark Andrews file is necessary because the manual edits will not be
ba4aec8c1853a1deda8eb43ffeaac4d764c8d39eMark Andrews present in the journal, rendering it inconsistent with the
ba4aec8c1853a1deda8eb43ffeaac4d764c8d39eMark Andrews contents of the zone file.</P
550085fed1d0af54ba5b2f588898afec158195deMark Andrews></DIV
550085fed1d0af54ba5b2f588898afec158195deMark Andrews></DIV
550085fed1d0af54ba5b2f588898afec158195deMark Andrews><DIV
f411c2e81cbfcf89ee073a0e31ac902a42fc8f22Mark AndrewsCLASS="sect1"
f411c2e81cbfcf89ee073a0e31ac902a42fc8f22Mark Andrews><H1
f411c2e81cbfcf89ee073a0e31ac902a42fc8f22Mark AndrewsCLASS="sect1"
ab2ac96c4e71dc803e47c35592044e116f61aca5Tatuya JINMEI 神明達哉><A
ab2ac96c4e71dc803e47c35592044e116f61aca5Tatuya JINMEI 神明達哉NAME="incremental_zone_transfers"
ab2ac96c4e71dc803e47c35592044e116f61aca5Tatuya JINMEI 神明達哉>4.2. Incremental Zone Transfers (IXFR)</A
ab2ac96c4e71dc803e47c35592044e116f61aca5Tatuya JINMEI 神明達哉></H1
ab2ac96c4e71dc803e47c35592044e116f61aca5Tatuya JINMEI 神明達哉><P
3bdf879a5301bce17e0a955585eb3decc541ba79Mark Andrews>The incremental zone transfer (IXFR) protocol is a way for
3bdf879a5301bce17e0a955585eb3decc541ba79Mark Andrews slave servers to transfer only changed data, instead of having to
3bdf879a5301bce17e0a955585eb3decc541ba79Mark Andrews transfer the entire zone. The IXFR protocol is documented in RFC
3bdf879a5301bce17e0a955585eb3decc541ba79Mark Andrews 1995. See <A
3bdf879a5301bce17e0a955585eb3decc541ba79Mark AndrewsHREF="Bv9ARM.ch09.html#proposed_standards"
1b5b46942d149f891bb91e90c6f52944b77c8a68Mark Andrews>Proposed Standards</A
1b5b46942d149f891bb91e90c6f52944b77c8a68Mark Andrews>.</P
6b25d2f7f7a1125508f8d225a8fef94e1db83555Mark Andrews><P
6b25d2f7f7a1125508f8d225a8fef94e1db83555Mark Andrews>When acting as a master, <SPAN
6b25d2f7f7a1125508f8d225a8fef94e1db83555Mark AndrewsCLASS="acronym"
b6309ed962c4988a314d61742c4fbc4935467d68Mark Andrews>BIND</SPAN
b6309ed962c4988a314d61742c4fbc4935467d68Mark Andrews> 9 supports IXFR for those zones
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrewswhere the necessary change history information is available. These
39fe146f2ab82cb8e49caa319a3345174fa2d69aMark Andrewsinclude master zones maintained by dynamic update and slave zones
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrewswhose data was obtained by IXFR, but not manually maintained master
bd3946db298667e769804b2e978df2d6dcd85e29Mark Andrewszones nor slave zones obtained by performing a full zone transfer
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrews(AXFR).</P
ab5d8edc1bd391a1b306db68114fac303484b30fMark Andrews><P
ab5d8edc1bd391a1b306db68114fac303484b30fMark Andrews>When acting as a slave, <SPAN
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark AndrewsCLASS="acronym"
8689f943a4859a8f68344236a1dcb81299a98347Mark Andrews>BIND</SPAN
8689f943a4859a8f68344236a1dcb81299a98347Mark Andrews> 9 will attempt to use IXFR unless
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrewsit is explicitly disabled. For more information about disabling
2434ccfde7efa30b6fedf4630e5036eeb5d647d0Mark AndrewsIXFR, see the description of the <B
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark AndrewsCLASS="command"
d8ec783e6dc0bd16a80b30d9888306b1faae6037Mark Andrews>request-ixfr</B
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrews> clause
5bd76af084edfdcd1cb4db9453ac781d32dde6f7Mark Andrewsof the <B
5bd76af084edfdcd1cb4db9453ac781d32dde6f7Mark AndrewsCLASS="command"
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrews>server</B
311e6d00c584f63665bed5dd9aea292402cad8deMark Andrews> statement.</P
8bcb0f297b50e80e3c7aab1a41b94d937acf4dc0Mark Andrews></DIV
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrews><DIV
7f32428506d55083fe5ac9aa515294bdef7c6e27Mark AndrewsCLASS="sect1"
7f32428506d55083fe5ac9aa515294bdef7c6e27Mark Andrews><H1
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark AndrewsCLASS="sect1"
5c10f54fe38795cbd3d5cf22e3fbd1d22b8226e4Mark Andrews><A
5c10f54fe38795cbd3d5cf22e3fbd1d22b8226e4Mark AndrewsNAME="AEN714"
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrews>4.3. Split DNS</A
a6211a2f234767a015a6a30b85d5da087fa907f1Mark Andrews></H1
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrews><P
1feb76edcbb8ee97d1757f73115b7c4a71de6e0eMark Andrews>Setting up different views, or visibility, of DNS space to
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrewsinternal and external resolvers is usually referred to as a <I
4c342614f80d867bba23e63795ec6ee79dd6395dMark AndrewsCLASS="emphasis"
e72d4d8929fec51153e4fd0d1cf632cd59335495Mark Andrews>Split
e72d4d8929fec51153e4fd0d1cf632cd59335495Mark AndrewsDNS</I
0ae34c3f6222ece01e0f710c7c0311f5cf9d9c0fMark Andrews> setup. There are several reasons an organization
0ae34c3f6222ece01e0f710c7c0311f5cf9d9c0fMark Andrewswould want to set up its DNS this way.</P
4eaf7590c82871637d1380be59000d8684db649cMark Andrews><P
6c6673405c7e29c1d91d07b326d0fe1d7b52e478Mark Andrews>One common reason for setting up a DNS system this way is
6c6673405c7e29c1d91d07b326d0fe1d7b52e478Mark Andrewsto hide "internal" DNS information from "external" clients on the
bb6936058eb88eadff030462a347c10895c61a9aMark AndrewsInternet. There is some debate as to whether or not this is actually useful.
bb6936058eb88eadff030462a347c10895c61a9aMark AndrewsInternal DNS information leaks out in many ways (via email headers,
bb6936058eb88eadff030462a347c10895c61a9aMark Andrewsfor example) and most savvy "attackers" can find the information
bb6936058eb88eadff030462a347c10895c61a9aMark Andrewsthey need using other means.</P
0ad5cb4782cd419b089bcab28d2fd9e140dbcc59Mark Andrews><P
0ad5cb4782cd419b089bcab28d2fd9e140dbcc59Mark Andrews>Another common reason for setting up a Split DNS system is
0ad5cb4782cd419b089bcab28d2fd9e140dbcc59Mark Andrewsto allow internal networks that are behind filters or in RFC 1918
08d802a9c6ec4c92f18c6cab1250d55c3f649b38Mark Andrewsspace (reserved IP space, as documented in RFC 1918) to resolve DNS
7c5d5a7932b8ac27281eeff64506dff8220bb3eaMark Andrewson the Internet. Split DNS can also be used to allow mail from outside
7c5d5a7932b8ac27281eeff64506dff8220bb3eaMark Andrewsback in to the internal network.</P
1aed0905a50ff8d2bdc4d253b38ae24afe3bab1cDanny Mayer><P
1aed0905a50ff8d2bdc4d253b38ae24afe3bab1cDanny Mayer>Here is an example of a split DNS setup:</P
1aed0905a50ff8d2bdc4d253b38ae24afe3bab1cDanny Mayer><P
1aed0905a50ff8d2bdc4d253b38ae24afe3bab1cDanny Mayer>Let's say a company named <I
1a9c000f54e6204fb49d785fd0bbb7a8e590dc99Mark AndrewsCLASS="emphasis"
1a9c000f54e6204fb49d785fd0bbb7a8e590dc99Mark Andrews>Example, Inc.</I
3cea35d9159b36eac43d32082a0b98f2cd82fc2eDanny Mayer> (example.com)
3cea35d9159b36eac43d32082a0b98f2cd82fc2eDanny Mayerhas several corporate sites that have an internal network with reserved
53f1312c61fa8618852584bcdf9f35530282eb08Mark AndrewsInternet Protocol (IP) space and an external demilitarized zone (DMZ),
53f1312c61fa8618852584bcdf9f35530282eb08Mark Andrewsor "outside" section of a network, that is available to the public.</P
53f1312c61fa8618852584bcdf9f35530282eb08Mark Andrews><P
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark Andrews><I
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark AndrewsCLASS="emphasis"
87f4715d6c0a22f3449eb3291c91aa45ba86c955Mark Andrews>Example, Inc.</I
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark Andrews> wants its internal clients
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark Andrewsto be able to resolve external hostnames and to exchange mail with
87f4715d6c0a22f3449eb3291c91aa45ba86c955Mark Andrewspeople on the outside. The company also wants its internal resolvers
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark Andrewsto have access to certain internal-only zones that are not available
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark Andrewsat all outside of the internal network.</P
1431917c7cddbac7442cb910e83cb058fea59fb5Mark Andrews><P
e809f3fb3f8567b2777fd100bffe2c0072e03942Mark Andrews>In order to accomplish this, the company will set up two sets
3733c24efa7eaa65455153702c3fb71c9233eafbMark Andrewsof nameservers. One set will be on the inside network (in the reserved
012a2b979e011b13ba0d291c279dc65a167c039eMark AndrewsIP space) and the other set will be on bastion hosts, which are "proxy"
012a2b979e011b13ba0d291c279dc65a167c039eMark Andrewshosts that can talk to both sides of its network, in the DMZ.</P
f6ff00810196d0c0973f62c7917b9975011fa45aMark Andrews><P
f6ff00810196d0c0973f62c7917b9975011fa45aMark Andrews>The internal servers will be configured to forward all queries,
ec3984e9df6fd9b7811daa0dacb1b3dd1423ebf3Mark Andrewsexcept queries for <TT
ec3984e9df6fd9b7811daa0dacb1b3dd1423ebf3Mark AndrewsCLASS="filename"
ec3984e9df6fd9b7811daa0dacb1b3dd1423ebf3Mark Andrews>site1.internal</TT
b972ff033b3efd52e747683face674dc4d2e431bMark Andrews>, <TT
b972ff033b3efd52e747683face674dc4d2e431bMark AndrewsCLASS="filename"
b972ff033b3efd52e747683face674dc4d2e431bMark Andrews>site2.internal</TT
fa4e1438016331502e6d665588021aa7ffef8cc2Mark Andrews>, <TT
fa4e1438016331502e6d665588021aa7ffef8cc2Mark AndrewsCLASS="filename"
fa4e1438016331502e6d665588021aa7ffef8cc2Mark Andrews>site1.example.com</TT
f0471ca4b7bca6e907130ec84e36cf69f2b79a5aMark Andrews>,
f0471ca4b7bca6e907130ec84e36cf69f2b79a5aMark Andrewsand <TT
f0471ca4b7bca6e907130ec84e36cf69f2b79a5aMark AndrewsCLASS="filename"
f0471ca4b7bca6e907130ec84e36cf69f2b79a5aMark Andrews>site2.example.com</TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>, to the servers in the
638fe804a524ee0c028863c0301b999c79de7651Mark AndrewsDMZ. These internal servers will have complete sets of information
638fe804a524ee0c028863c0301b999c79de7651Mark Andrewsfor <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
9db3d9d14e2f3641d696dadc59c40c52b6f888bcMark Andrews>site1.example.com</TT
9db3d9d14e2f3641d696dadc59c40c52b6f888bcMark Andrews>, <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
e412f05a4e5ab7727f024c95e2a7515c07107b02Mark Andrews>site2.example.com</TT
e2cf0e8ff9ff37121518af5b34b9e4de7abbb47cMark Andrews>,<I
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="emphasis"
0b75a2dd3bd81a69e2d68fe446cacb46be04c1f1Mark Andrews> </I
0b75a2dd3bd81a69e2d68fe446cacb46be04c1f1Mark Andrews><TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
c54c1eaf26d5a7fc123c4af3712353156a766df1Mark Andrews>site1.internal</TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>,
0d993c02babc1e00516272783b310e83bb292d5cMark Andrewsand <TT
0d993c02babc1e00516272783b310e83bb292d5cMark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>site2.internal</TT
4d9f3f00d93fcb8743b1105e8cf82e862be220d1Mark Andrews>.</P
4d9f3f00d93fcb8743b1105e8cf82e862be220d1Mark Andrews><P
4d9f3f00d93fcb8743b1105e8cf82e862be220d1Mark Andrews>To protect the <TT
4d9f3f00d93fcb8743b1105e8cf82e862be220d1Mark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>site1.internal</TT
86f6b92e35c7bdb5fc1fd1021af75b981863313eMark Andrews> and <TT
86f6b92e35c7bdb5fc1fd1021af75b981863313eMark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>site2.internal</TT
25276bd1ecb372b82c9235648e5defab0655dcd5Mark Andrews> domains,
25276bd1ecb372b82c9235648e5defab0655dcd5Mark Andrewsthe internal nameservers must be configured to disallow all queries
25276bd1ecb372b82c9235648e5defab0655dcd5Mark Andrewsto these domains from any external hosts, including the bastion
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewshosts.</P
320d6ee24ea59c0dbcb2c08038586ef03c6a191dMark Andrews><P
320d6ee24ea59c0dbcb2c08038586ef03c6a191dMark Andrews>The external servers, which are on the bastion hosts, will
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsbe configured to serve the "public" version of the <TT
475fe52dc33d8d8344e8b1e48fa7bb6643f7ca66Mark AndrewsCLASS="filename"
475fe52dc33d8d8344e8b1e48fa7bb6643f7ca66Mark Andrews>site1</TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews> and <TT
5af560664daaa984f98cec6925518a3e06c4ab4fMark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>site2.example.com</TT
0f8f42a09eb102fa88e4d2caacdafbeda931f94cMark Andrews> zones.
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsThis could include things such as the host records for public servers
8d77066ba0feb1353a7c85f929c365c5103f3976Mark Andrews(<TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
8d77066ba0feb1353a7c85f929c365c5103f3976Mark Andrews>www.example.com</TT
8d77066ba0feb1353a7c85f929c365c5103f3976Mark Andrews> and <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
3e7b37e01ba3efc873486140734fd24788092a30Mark Andrews>ftp.example.com</TT
3e7b37e01ba3efc873486140734fd24788092a30Mark Andrews>),
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsand mail exchange (MX) records (<TT
54532c54130de8f374465bb23d5576fc3257ea96Mark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>a.mx.example.com</TT
020f7361a49c5b1cda91927cf8206c1283fc7496Mark Andrews> and <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
1c0927d8a091effcf9b2dc5baa533927c113bd5cMark Andrews>b.mx.example.com</TT
1c0927d8a091effcf9b2dc5baa533927c113bd5cMark Andrews>).</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews><P
446ff1959cc3e963778c8770204b72c9e7c7df5aMark Andrews>In addition, the public <TT
446ff1959cc3e963778c8770204b72c9e7c7df5aMark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>site1</TT
70f8c70cdd3ca68edcf9d448eb508abf3697719aMark Andrews> and <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
33c538015323f4576679e427088372eea614feebMark Andrews>site2.example.com</TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews> zones
ac65e45126dda424b5cc9d2865b353dc0ec23e1eMark Andrewsshould have special MX records that contain wildcard (`*') records
ac65e45126dda424b5cc9d2865b353dc0ec23e1eMark Andrewspointing to the bastion hosts. This is needed because external mail
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsservers do not have any other way of looking up how to deliver mail
0423090da198f31ac615cd3a8f7d83aada32d5b3Mark Andrewsto those internal hosts. With the wildcard records, the mail will
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsbe delivered to the bastion host, which can then forward it on to
d9e0458a890c49f977fdcf9d995681f546f7c427Mark Andrewsinternal hosts.</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews><P
de4976142190ae84ed3e4099f3e0fc07781748a3Mark Andrews>Here's an example of a wildcard MX record:</P
de4976142190ae84ed3e4099f3e0fc07781748a3Mark Andrews><PRE
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="programlisting"
5758e9adfb009286b2b719ff83eb284f1019c589Mark Andrews><TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="literal"
0b09763c354ec91fb352b6b4cea383bd0195b2d8Mark Andrews>* IN MX 10 external1.example.com.</TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews></PRE
6a3c86ff436452d062912bd91ecd289541869d42Mark Andrews><P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>Now that they accept mail on behalf of anything in the internal
e0fa16fe191d619d2cd05a039067414409329878Mark Andrewsnetwork, the bastion hosts will need to know how to deliver mail
e0fa16fe191d619d2cd05a039067414409329878Mark Andrewsto internal hosts. In order for this to work properly, the resolvers on
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsthe bastion hosts will need to be configured to point to the internal
93da96c1cfd5f3c47169855867dd18db00c8a386Mark Andrewsnameservers for DNS resolution.</P
93da96c1cfd5f3c47169855867dd18db00c8a386Mark Andrews><P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>Queries for internal hostnames will be answered by the internal
7d389c324cc032475f9d219a12ab84bacbd7fbaaMark Andrewsservers, and queries for external hostnames will be forwarded back
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsout to the DNS servers on the bastion hosts.</P
cd9bfe5b256a3e84ba090e8fcb5de0d6c50974aeMark Andrews><P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>In order for all this to work properly, internal clients will
dcd371be7d481b242d277d735e4c2d974297c164Mark Andrewsneed to be configured to query <I
dcd371be7d481b242d277d735e4c2d974297c164Mark AndrewsCLASS="emphasis"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>only</I
cc4928ec7116a064223f60639ca1a80f25ba350fMark Andrews> the internal
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsnameservers for DNS queries. This could also be enforced via selective
e2cf63c5df79eb7c8b86b6278289883fa760cda5Mark Andrewsfiltering on the network.</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews><P
c3184b4e2a1f238f4615d36fee79df82b1711344Mark Andrews>If everything has been set properly, <I
c3184b4e2a1f238f4615d36fee79df82b1711344Mark AndrewsCLASS="emphasis"
c3184b4e2a1f238f4615d36fee79df82b1711344Mark Andrews>Example, Inc.</I
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>'s
9b7c023fe6dc88ba1e69ace1f7c3ade40c6475f9Mark Andrewsinternal clients will now be able to:</P
9b7c023fe6dc88ba1e69ace1f7c3ade40c6475f9Mark Andrews><P
9b7c023fe6dc88ba1e69ace1f7c3ade40c6475f9Mark Andrews></P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews><UL
0a1fa37641b59c56d02f5390917a49e4987f0f75Mark Andrews><LI
0a1fa37641b59c56d02f5390917a49e4987f0f75Mark Andrews><P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>Look up any hostnames in the <TT
c61ec97ae0b859914ee26e213fe792f86a157990Mark AndrewsCLASS="literal"
c61ec97ae0b859914ee26e213fe792f86a157990Mark Andrews>site1</TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews> and
49f7d1585e0e4f1ffa1667391dd7ae1c4d3d4e81Mark Andrews<TT
49f7d1585e0e4f1ffa1667391dd7ae1c4d3d4e81Mark AndrewsCLASS="literal"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>site2.example.com</TT
0b1af13f680a865521105a77ee192024b5af33c4Mark Andrews> zones.</P
0b1af13f680a865521105a77ee192024b5af33c4Mark Andrews></LI
0b1af13f680a865521105a77ee192024b5af33c4Mark Andrews><LI
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews><P
945cb085b859dbfc6a883813dda03c83e06995d3Mark Andrews>Look up any hostnames in the <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="literal"
5ed4b0d4452967d9b3aaf7a22a2956a6ee67a614Mark Andrews>site1.internal</TT
5ed4b0d4452967d9b3aaf7a22a2956a6ee67a614Mark Andrews> and
5ed4b0d4452967d9b3aaf7a22a2956a6ee67a614Mark Andrews<TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="literal"
c549b3a4d5fedba2ae960df667864e824acb1ef9Mark Andrews>site2.internal</TT
c549b3a4d5fedba2ae960df667864e824acb1ef9Mark Andrews> domains.</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews></LI
a483e67c4cdcbfc29ddc62b5a2d0d99b1c542fadMark Andrews><LI
a483e67c4cdcbfc29ddc62b5a2d0d99b1c542fadMark Andrews><P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>Look up any hostnames on the Internet.</P
d73de275987d29627dc11d5bd4a22874a29f7874Mark Andrews></LI
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews><LI
8f9664521724eefc39728c092d0bc6be527e1496Mark Andrews><P
8f9664521724eefc39728c092d0bc6be527e1496Mark Andrews>Exchange mail with internal AND external people.</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews></LI
da091cda77fa951e682119c3df84f60a62bed702Mark Andrews></UL
da091cda77fa951e682119c3df84f60a62bed702Mark Andrews><P
da091cda77fa951e682119c3df84f60a62bed702Mark Andrews>Hosts on the Internet will be able to:</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews><P
d8d489cd8efc45b06a232ac07a636b3d36cc7e8fMark Andrews></P
d8d489cd8efc45b06a232ac07a636b3d36cc7e8fMark Andrews><UL
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews><LI
bdb1394788a677d0b6e8499ba1ece17a73f476c7Mark Andrews><P
bdb1394788a677d0b6e8499ba1ece17a73f476c7Mark Andrews>Look up any hostnames in the <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="literal"
c8aa2c83113229a59069cbd05c735896f51b886bMark Andrews>site1</TT
c8aa2c83113229a59069cbd05c735896f51b886bMark Andrews> and
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews<TT
a1edcd1b8d430650d85ec0962cd32efde76a71fbMark AndrewsCLASS="literal"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>site2.example.com</TT
5b1627d469d07c5bfe7f193e3ddd85d0dd6ad4b0Mark Andrews> zones.</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews></LI
7c23b791f4ae8f0c4c2982a91d13c0ecb15ee798Mark Andrews><LI
7c23b791f4ae8f0c4c2982a91d13c0ecb15ee798Mark Andrews><P
7c23b791f4ae8f0c4c2982a91d13c0ecb15ee798Mark Andrews>Exchange mail with anyone in the <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="literal"
8989de1059c6292fc43ce507df4991224af2d789Mark Andrews>site1</TT
8989de1059c6292fc43ce507df4991224af2d789Mark Andrews> and
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews<TT
acc8b7ac3d16538bf223545bbf71899b9accaebbMark AndrewsCLASS="literal"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>site2.example.com</TT
e7bb307667cc89287e810b95bddd342cb5dcb4e7Mark Andrews> zones.</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews></LI
b9efcf0a377381b29960137e54ecaf4db85a35c8Mark Andrews></UL
b9efcf0a377381b29960137e54ecaf4db85a35c8Mark Andrews><P
b9efcf0a377381b29960137e54ecaf4db85a35c8Mark Andrews>Here is an example configuration for the setup we just
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews described above. Note that this is only configuration information;
8e5893c36cdccc706f9632f51e0c8d390d2a8d06Mark Andrews for information on how to configure your zone files, see <A
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsHREF="Bv9ARM.ch03.html#sample_configuration"
e396939d492e6afa8e31a8dc11d7317c9e62f15fMark Andrews>Section 3.1</A
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews></P
9549a96654ead15b264c9159d48eb485e4f9db55Mark Andrews><P
e70b069e3807d5f499dff31eb31c2b3e0e125457Mark Andrews>Internal DNS server config:</P
3d822d111c00e70830dc163a5298196a1e7db29fMark Andrews><PRE
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="programlisting"
88aa68f478c1634f5f10034fb6ea4158efa20ff4Mark Andrews>&#13;
88aa68f478c1634f5f10034fb6ea4158efa20ff4Mark Andrewsacl internals { 172.16.72.0/24; 192.168.1.0/24; };
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews
4c83dd7f22b19c75afdd311684f6ba0faa24e8d8Mark Andrewsacl externals { <TT
4c83dd7f22b19c75afdd311684f6ba0faa24e8d8Mark AndrewsCLASS="varname"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>bastion-ips-go-here</TT
5f4098e478ae913cdc1bb8851599b8f2431050d3Mark Andrews>; };
5f4098e478ae913cdc1bb8851599b8f2431050d3Mark Andrews
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsoptions {
57e0f58b3fd4cb49a57200c8af9cb58d984d871aMark Andrews ...
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews ...
26cf4737b3e84c3a686a5eacebf22ac39e57d4caMark Andrews forward only;
26cf4737b3e84c3a686a5eacebf22ac39e57d4caMark Andrews forwarders { // forward to external servers
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews <TT
34e5a08809dda3276252269ebddd1616e62081a2Mark AndrewsCLASS="varname"
34e5a08809dda3276252269ebddd1616e62081a2Mark Andrews>bastion-ips-go-here</TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>;
0cd36f1d15caf6622ec3128544d4238ad180a300Mark Andrews };
0cd36f1d15caf6622ec3128544d4238ad180a300Mark Andrews allow-transfer { none; }; // sample allow-transfer (no one)
0cd36f1d15caf6622ec3128544d4238ad180a300Mark Andrews allow-query { internals; externals; }; // restrict query access
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews allow-recursion { internals; }; // restrict recursion
93649589d470624e9e1c34403ad076b3a1a4c5c3Mark Andrews ...
93649589d470624e9e1c34403ad076b3a1a4c5c3Mark Andrews ...
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews};
29f5bb81e2d1d72fc6e44c87404bd4598a34df94Mark Andrews
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewszone "site1.example.com" { // sample slave zone
ddc592d128cdde85ada64efbda95981c10c4c03cMark Andrews type master;
ddc592d128cdde85ada64efbda95981c10c4c03cMark Andrews file "m/site1.example.com";
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews forwarders { }; // do normal iterative
88c2b83cc548a217cc92a2bf75ca1ef1d4237d4fMark Andrews // resolution (do not forward)
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews allow-query { internals; externals; };
bd6ad47c3dbc52a54f240432878b6832bd6dd6e2Mark Andrews allow-transfer { internals; };
bd6ad47c3dbc52a54f240432878b6832bd6dd6e2Mark Andrews};
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews
c7c1bf7dc167ff164193bc04f33a22109e4c0829Mark Andrewszone "site2.example.com" {
c7c1bf7dc167ff164193bc04f33a22109e4c0829Mark Andrews type slave;
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews file "s/site2.example.com";
9e205a3c51e68d19a7ed03244d45b14b3e0d69afMark Andrews masters { 172.16.72.3; };
9e205a3c51e68d19a7ed03244d45b14b3e0d69afMark Andrews forwarders { };
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews allow-query { internals; externals; };
e823642ec0c167af8f7db01c96ba0279165a61f3Mark Andrews allow-transfer { internals; };
e823642ec0c167af8f7db01c96ba0279165a61f3Mark Andrews};
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews
93e6ebcd0a0f044ba2add424c265b5e0bb4c8afdMark Andrewszone "site1.internal" {
93e6ebcd0a0f044ba2add424c265b5e0bb4c8afdMark Andrews type master;
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews file "m/site1.internal";
8ac1acc30d0f405222ffa7b2b93131d9d4e18599Mark Andrews forwarders { };
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews allow-query { internals; };
c99d9017ba00099bfa89e1ed53e63a5cb07d28d5Mark Andrews allow-transfer { internals; }
c99d9017ba00099bfa89e1ed53e63a5cb07d28d5Mark Andrews};
c99d9017ba00099bfa89e1ed53e63a5cb07d28d5Mark Andrews
c99d9017ba00099bfa89e1ed53e63a5cb07d28d5Mark Andrewszone "site2.internal" {
c99d9017ba00099bfa89e1ed53e63a5cb07d28d5Mark Andrews type slave;
c99d9017ba00099bfa89e1ed53e63a5cb07d28d5Mark Andrews file "s/site2.internal";
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews masters { 172.16.72.3; };
c4a9ce445c48a57eed5aa16582b1964cf8cedf87Mark Andrews forwarders { };
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews allow-query { internals };
a04a323f9a1ebd4766fc577e11bf3c22bdaf5516Mark Andrews allow-transfer { internals; }
a04a323f9a1ebd4766fc577e11bf3c22bdaf5516Mark Andrews};
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews</PRE
dd0228908543562781a4c0d8773ae87d4c530633Mark Andrews><P
dd0228908543562781a4c0d8773ae87d4c530633Mark Andrews>External (bastion host) DNS server config:</P
dd0228908543562781a4c0d8773ae87d4c530633Mark Andrews><PRE
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="programlisting"
810e8d27763c5d8557239ab321eb125163af9236Mark Andrews>&#13;acl internals { 172.16.72.0/24; 192.168.1.0/24; };
810e8d27763c5d8557239ab321eb125163af9236Mark Andrews
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsacl externals { bastion-ips-go-here; };
15f358ed4ea081793041bbfba70849be472236d3Mark Andrews
15f358ed4ea081793041bbfba70849be472236d3Mark Andrewsoptions {
94323de0419d68fe8c48af7ae14a2f1a1cd274a8Mark Andrews ...
984c39beed2fee49dda75c4c8a37b7f32bf434bfMark Andrews ...
984c39beed2fee49dda75c4c8a37b7f32bf434bfMark Andrews allow-transfer { none; }; // sample allow-transfer (no one)
94323de0419d68fe8c48af7ae14a2f1a1cd274a8Mark Andrews allow-query { internals; externals; }; // restrict query access
c08a03a43116c21cf12dea7cbcb5465588f7955cMark Andrews allow-recursion { internals; externals; }; // restrict recursion
c311ed52d45334e182a093efad827fe4cbe7e686Mark Andrews ...
c311ed52d45334e182a093efad827fe4cbe7e686Mark Andrews ...
c311ed52d45334e182a093efad827fe4cbe7e686Mark Andrews};
79a6a33184abff1999ba13b10922ccb34a2758a5Mark Andrews
79a6a33184abff1999ba13b10922ccb34a2758a5Mark Andrewszone "site1.example.com" { // sample slave zone
79a6a33184abff1999ba13b10922ccb34a2758a5Mark Andrews type master;
79a6a33184abff1999ba13b10922ccb34a2758a5Mark Andrews file "m/site1.foo.com";
5d26560e2b93e1aa0334931ec6ccb6045c3581fcMark Andrews allow-query { any; };
5d26560e2b93e1aa0334931ec6ccb6045c3581fcMark Andrews allow-transfer { internals; externals; };
5d26560e2b93e1aa0334931ec6ccb6045c3581fcMark Andrews};
2b1c71b134eb92f2e297a56f778838e42f41c880Mark Andrews
2b1c71b134eb92f2e297a56f778838e42f41c880Mark Andrewszone "site2.example.com" {
2b1c71b134eb92f2e297a56f778838e42f41c880Mark Andrews type slave;
2b1c71b134eb92f2e297a56f778838e42f41c880Mark Andrews file "s/site2.foo.com";
d6fbfd28ea82e425740de903ddc67f7d9e9f82e7Mark Andrews masters { another_bastion_host_maybe; };
d6fbfd28ea82e425740de903ddc67f7d9e9f82e7Mark Andrews allow-query { any; };
d6fbfd28ea82e425740de903ddc67f7d9e9f82e7Mark Andrews allow-transfer { internals; externals; }
7791dd06ea69d0fb2494788ad4c24d568f40bcdfMark Andrews};
7791dd06ea69d0fb2494788ad4c24d568f40bcdfMark Andrews</PRE
091b098b49a4f84f459abd46451955a18abd6d40Mark Andrews><P
091b098b49a4f84f459abd46451955a18abd6d40Mark Andrews>In the <TT
091b098b49a4f84f459abd46451955a18abd6d40Mark AndrewsCLASS="filename"
7d3458a972a902740eb142044655aba6c6ffb9acMark Andrews>resolv.conf</TT
7d3458a972a902740eb142044655aba6c6ffb9acMark Andrews> (or equivalent) on
7d3458a972a902740eb142044655aba6c6ffb9acMark Andrewsthe bastion host(s):</P
7c441b7f4afdedb6e5a99f113a4f926a005fa950Mark Andrews><PRE
7c441b7f4afdedb6e5a99f113a4f926a005fa950Mark AndrewsCLASS="programlisting"
7c441b7f4afdedb6e5a99f113a4f926a005fa950Mark Andrews>&#13;search ...
7c441b7f4afdedb6e5a99f113a4f926a005fa950Mark Andrewsnameserver 172.16.72.2
f0ffc28f61a68b350fef9257f5f50e1ac866e0abMark Andrewsnameserver 172.16.72.3
75e184e4b80c499859574257dd5781d62cfed0b3Mark Andrewsnameserver 172.16.72.4
f0ffc28f61a68b350fef9257f5f50e1ac866e0abMark Andrews</PRE
7f20fd8ebb0cabc8f935381d958f8371990c9212Mark Andrews></DIV
7f20fd8ebb0cabc8f935381d958f8371990c9212Mark Andrews><DIV
8695d7b357789bedff63e5b19c5ab25cd58fcd4bMark AndrewsCLASS="sect1"
8695d7b357789bedff63e5b19c5ab25cd58fcd4bMark Andrews><H1
8695d7b357789bedff63e5b19c5ab25cd58fcd4bMark AndrewsCLASS="sect1"
f76c4ebaf586a693521f018fbc617c292c1555d7Mark Andrews><A
f76c4ebaf586a693521f018fbc617c292c1555d7Mark AndrewsNAME="tsig"
b597abd9cc44c7b9ecd0ff67df59a21ff45e88d5Mark Andrews>4.4. TSIG</A
b597abd9cc44c7b9ecd0ff67df59a21ff45e88d5Mark Andrews></H1
b597abd9cc44c7b9ecd0ff67df59a21ff45e88d5Mark Andrews><P
b597abd9cc44c7b9ecd0ff67df59a21ff45e88d5Mark Andrews>This is a short guide to setting up Transaction SIGnatures
81e302788a444b81231a7cda721548a020ae5660Brian Wellington(TSIG) based transaction security in <SPAN
81e302788a444b81231a7cda721548a020ae5660Brian WellingtonCLASS="acronym"
81e302788a444b81231a7cda721548a020ae5660Brian Wellington>BIND</SPAN
c00a1eb423623442aff428336bb55590f79013bbMark Andrews>. It describes changes
c00a1eb423623442aff428336bb55590f79013bbMark Andrewsto the configuration file as well as what changes are required for
1e258716acade52396a8f260b5e19cbf6ca0290aMark Andrewsdifferent features, including the process of creating transaction
1e258716acade52396a8f260b5e19cbf6ca0290aMark Andrewskeys and using transaction signatures with <SPAN
d972fa317829804a692e46a34b6f27a33f861d9dMark AndrewsCLASS="acronym"
d972fa317829804a692e46a34b6f27a33f861d9dMark Andrews>BIND</SPAN
4b171ebd702d72200a4d7609f11c5f79d6b6f964Brian Wellington>.</P
4b171ebd702d72200a4d7609f11c5f79d6b6f964Brian Wellington><P
4b171ebd702d72200a4d7609f11c5f79d6b6f964Brian Wellington><SPAN
cceca51fec3b4af660d28e2d3df7242823312eb6Brian WellingtonCLASS="acronym"
cceca51fec3b4af660d28e2d3df7242823312eb6Brian Wellington>BIND</SPAN
03fae7ef2173cdf32918853b047d95d9046574ccMark Andrews> primarily supports TSIG for server to server communication.
03fae7ef2173cdf32918853b047d95d9046574ccMark AndrewsThis includes zone transfer, notify, and recursive query messages.
03fae7ef2173cdf32918853b047d95d9046574ccMark AndrewsResolvers based on newer versions of <SPAN
03fae7ef2173cdf32918853b047d95d9046574ccMark AndrewsCLASS="acronym"
ad611e746d6fdcbb9e67da361a3a039c226a9236Mark Andrews>BIND</SPAN
ad611e746d6fdcbb9e67da361a3a039c226a9236Mark Andrews> 8 have limited support
603d1d1e20fbffc986b3aec93379bb4f6ac37afcMark Andrewsfor TSIG.</P
603d1d1e20fbffc986b3aec93379bb4f6ac37afcMark Andrews><P
603d1d1e20fbffc986b3aec93379bb4f6ac37afcMark Andrews>TSIG might be most useful for dynamic update. A primary
94323de0419d68fe8c48af7ae14a2f1a1cd274a8Mark Andrews server for a dynamic zone should use access control to control
2dd99c098ca162f985b7ef3c8142a964ad8281aeMark Andrews updates, but IP-based access control is insufficient. Key-based
2dd99c098ca162f985b7ef3c8142a964ad8281aeMark Andrews access control is far superior, see <A
2dd99c098ca162f985b7ef3c8142a964ad8281aeMark AndrewsHREF="Bv9ARM.ch09.html#proposed_standards"
2dd99c098ca162f985b7ef3c8142a964ad8281aeMark Andrews>Proposed Standards</A
2dd99c098ca162f985b7ef3c8142a964ad8281aeMark Andrews>. The <B
1fb264ed3aa861a67d7bab9aeb5aea5836e03c14Mark AndrewsCLASS="command"
1fb264ed3aa861a67d7bab9aeb5aea5836e03c14Mark Andrews>nsupdate</B
1fb264ed3aa861a67d7bab9aeb5aea5836e03c14Mark Andrews>
608c703d1231e0b1f291637ca5361b773afcdbf1Mark Andrews program supports TSIG via the <TT
608c703d1231e0b1f291637ca5361b773afcdbf1Mark AndrewsCLASS="option"
608c703d1231e0b1f291637ca5361b773afcdbf1Mark Andrews>-k</TT
feb8ae093115b36ac061e23d0227ea06f51950a3Mark Andrews> and
feb8ae093115b36ac061e23d0227ea06f51950a3Mark Andrews <TT
27151990b2b48f027f7f01972fe8e0dfa1df52d3Mark AndrewsCLASS="option"
27151990b2b48f027f7f01972fe8e0dfa1df52d3Mark Andrews>-y</TT
27151990b2b48f027f7f01972fe8e0dfa1df52d3Mark Andrews> command line options.</P
6b610836bc081fdadf7bc7a16ce27f422c6b5638Brian Wellington><DIV
6b610836bc081fdadf7bc7a16ce27f422c6b5638Brian WellingtonCLASS="sect2"
95b604c5e972a5e9eb713bf45cf0b2d9b98da27eMark Andrews><H2
2211bec6a0626b681fdf5a8e4406555ef76ddf70Mark AndrewsCLASS="sect2"
2211bec6a0626b681fdf5a8e4406555ef76ddf70Mark Andrews><A
2211bec6a0626b681fdf5a8e4406555ef76ddf70Mark AndrewsNAME="AEN805"
fcb2ecdb52a594a5c0d07c2e98e67c14708c16dfMark Andrews>4.4.1. Generate Shared Keys for Each Pair of Hosts</A
fcb2ecdb52a594a5c0d07c2e98e67c14708c16dfMark Andrews></H2
fcb2ecdb52a594a5c0d07c2e98e67c14708c16dfMark Andrews><P
3561e645d77448b20b1676680b08c76d559e5335Mark Andrews>A shared secret is generated to be shared between <I
3561e645d77448b20b1676680b08c76d559e5335Mark AndrewsCLASS="emphasis"
b9c80c8bddbb88384d7baef297a873b5f8715e49Mark Andrews>host1</I
b9c80c8bddbb88384d7baef297a873b5f8715e49Mark Andrews> and <I
b9c80c8bddbb88384d7baef297a873b5f8715e49Mark AndrewsCLASS="emphasis"
b9c80c8bddbb88384d7baef297a873b5f8715e49Mark Andrews>host2</I
b9c80c8bddbb88384d7baef297a873b5f8715e49Mark Andrews>.
b9c80c8bddbb88384d7baef297a873b5f8715e49Mark AndrewsAn arbitrary key name is chosen: "host1-host2.". The key name must
27269e9dd45b619160f90db1a0f6b2b3f6f4bbb8Mark Andrewsbe the same on both hosts.</P
faf23095be9a0b5e2696f2b1f1a260af16e9ebeaMark Andrews><DIV
27269e9dd45b619160f90db1a0f6b2b3f6f4bbb8Mark AndrewsCLASS="sect3"
faf23095be9a0b5e2696f2b1f1a260af16e9ebeaMark Andrews><H3
f38c274c217d0a5b791786877422306a0e477e10Mark AndrewsCLASS="sect3"
f38c274c217d0a5b791786877422306a0e477e10Mark Andrews><A
84ef147b1fa0aed15cade55478ed647d15f7b094Mark AndrewsNAME="AEN810"
84ef147b1fa0aed15cade55478ed647d15f7b094Mark Andrews>4.4.1.1. Automatic Generation</A
84ef147b1fa0aed15cade55478ed647d15f7b094Mark Andrews></H3
e53a5a116fc531f730df0adb091278ff8a941dffMark Andrews><P
e53a5a116fc531f730df0adb091278ff8a941dffMark Andrews>The following command will generate a 128 bit (16 byte) HMAC-MD5
e53a5a116fc531f730df0adb091278ff8a941dffMark Andrewskey as described above. Longer keys are better, but shorter keys
fc7fbdf6e66fb496442ec4f99f5a84669ea4c6d3Mark Andrewsare easier to read. Note that the maximum key length is 512 bits;
fc7fbdf6e66fb496442ec4f99f5a84669ea4c6d3Mark Andrewskeys longer than that will be digested with MD5 to produce a 128
fc7fbdf6e66fb496442ec4f99f5a84669ea4c6d3Mark Andrewsbit key.</P
fc7fbdf6e66fb496442ec4f99f5a84669ea4c6d3Mark Andrews><P
986be654feec852eb9da0d15599f18d0035e569bMark Andrews><TT
986be654feec852eb9da0d15599f18d0035e569bMark AndrewsCLASS="userinput"
986be654feec852eb9da0d15599f18d0035e569bMark Andrews><B
3703473c4a2672af58b4f141e92067e969fd978eBrian Wellington>dnssec-keygen -a hmac-md5 -b 128 -n HOST host1-host2.</B
3703473c4a2672af58b4f141e92067e969fd978eBrian Wellington></TT
c26c65b7a0d036e78bfc73f3e7e0817adb0365c0Mark Andrews></P
43733a83ed92359555c0dcc766e04216ba858309Mark Andrews><P
43733a83ed92359555c0dcc766e04216ba858309Mark Andrews>The key is in the file <TT
43733a83ed92359555c0dcc766e04216ba858309Mark AndrewsCLASS="filename"
bda64555f62216c3e785338f372a7ad9b79c197cMark Andrews>Khost1-host2.+157+00000.private</TT
86e71d7e8626de37559265f0edac8451bef6d001Andreas Gustafsson>.
bda64555f62216c3e785338f372a7ad9b79c197cMark AndrewsNothing directly uses this file, but the base-64 encoded string
39c2b741427eedafe5054909773c2e121c078b72Mark Andrewsfollowing "<TT
39c2b741427eedafe5054909773c2e121c078b72Mark AndrewsCLASS="literal"
39c2b741427eedafe5054909773c2e121c078b72Mark Andrews>Key:</TT
de36c606c52ad51e5abca6e42faf655937e5ed10Mark Andrews>"
de36c606c52ad51e5abca6e42faf655937e5ed10Mark Andrewscan be extracted from the file and used as a shared secret:</P
23cb957a81a51a9656917ea98d0ae56b7abdcaccMark Andrews><PRE
23cb957a81a51a9656917ea98d0ae56b7abdcaccMark AndrewsCLASS="programlisting"
7789eb1345bef03773a2530dce7f2709cc50aa2aAndreas Gustafsson>Key: La/E5CjG9O+os1jq0a2jdA==</PRE
23cb957a81a51a9656917ea98d0ae56b7abdcaccMark Andrews><P
28d8b4118da7abed531ca09136a6d1402837d721Mark Andrews>The string "<TT
28d8b4118da7abed531ca09136a6d1402837d721Mark AndrewsCLASS="literal"
28d8b4118da7abed531ca09136a6d1402837d721Mark Andrews>La/E5CjG9O+os1jq0a2jdA==</TT
d6c0627d1e4d841eac9576427f2d4a0cf9a47e2cMark Andrews>" can
d6c0627d1e4d841eac9576427f2d4a0cf9a47e2cMark Andrewsbe used as the shared secret.</P
d6c0627d1e4d841eac9576427f2d4a0cf9a47e2cMark Andrews></DIV
5d7b81d2a49d237ff5e73fdc4bd3394a3ee29392Mark Andrews><DIV
eeede5be4b3ff940b622799a04951e0dc45ad45fAndreas GustafssonCLASS="sect3"
eeede5be4b3ff940b622799a04951e0dc45ad45fAndreas Gustafsson><H3
5d7b81d2a49d237ff5e73fdc4bd3394a3ee29392Mark AndrewsCLASS="sect3"
8f63de30293716a22054e7db47f27e81bab545c5Mark Andrews><A
8f63de30293716a22054e7db47f27e81bab545c5Mark AndrewsNAME="AEN821"
8f63de30293716a22054e7db47f27e81bab545c5Mark Andrews>4.4.1.2. Manual Generation</A
caa8797a00ccb1a02f1690dda5b4aeda9a1db5a7Mark Andrews></H3
caa8797a00ccb1a02f1690dda5b4aeda9a1db5a7Mark Andrews><P
9ae90732df942a7ffcbaa26ba254b55248ce79a5Mark Andrews>The shared secret is simply a random sequence of bits, encoded
9ae90732df942a7ffcbaa26ba254b55248ce79a5Mark Andrewsin base-64. Most ASCII strings are valid base-64 strings (assuming
9ae90732df942a7ffcbaa26ba254b55248ce79a5Mark Andrewsthe length is a multiple of 4 and only valid characters are used),
f3222d48cc3d81706d198faa00dea9720eb0768dMark Andrewsso the shared secret can be manually generated.</P
c1567cb58cbf2eb816320ff49f000afafea02a85Mark Andrews><P
f3222d48cc3d81706d198faa00dea9720eb0768dMark Andrews>Also, a known string can be run through <B
c73c1c33ec9569c8f9ffd205b48f044f9b03795bMark AndrewsCLASS="command"
c73c1c33ec9569c8f9ffd205b48f044f9b03795bMark Andrews>mmencode</B
c73c1c33ec9569c8f9ffd205b48f044f9b03795bMark Andrews> or
e95cc59f90d35f2d482b6f9c19ba96818275335cMark Andrewsa similar program to generate base-64 encoded data.</P
0062c1ddfe0b2f0a4e206a5d460d8e7d58e29b80Brian Wellington></DIV
0062c1ddfe0b2f0a4e206a5d460d8e7d58e29b80Brian Wellington></DIV
9aa1fb4861dc1d45f5a02fb1b9a9b815cc863747Mark Andrews><DIV
0062c1ddfe0b2f0a4e206a5d460d8e7d58e29b80Brian WellingtonCLASS="sect2"
48b0f5ff87f0a5a138129bcd855fd72908491321Andreas Gustafsson><H2
48b0f5ff87f0a5a138129bcd855fd72908491321Andreas GustafssonCLASS="sect2"
48b0f5ff87f0a5a138129bcd855fd72908491321Andreas Gustafsson><A
0b809e3e23f9f3d9697def5f447aa57d5aeef56bAndreas GustafssonNAME="AEN826"
cde7dfea4c1267a2b526114f4ea80fe9db1fc557Brian Wellington>4.4.2. Copying the Shared Secret to Both Machines</A
cde7dfea4c1267a2b526114f4ea80fe9db1fc557Brian Wellington></H2
fca9cc33ad4299e58e53aa5273d805477267e27aBrian Wellington><P
fca9cc33ad4299e58e53aa5273d805477267e27aBrian Wellington>This is beyond the scope of DNS. A secure transport mechanism
fca9cc33ad4299e58e53aa5273d805477267e27aBrian Wellingtonshould be used. This could be secure FTP, ssh, telephone, etc.</P
fca9cc33ad4299e58e53aa5273d805477267e27aBrian Wellington></DIV
2ca2e1a1ceec59a40f977f01ba8e8f4c0424c484Brian Wellington><DIV
2ca2e1a1ceec59a40f977f01ba8e8f4c0424c484Brian WellingtonCLASS="sect2"
2ca2e1a1ceec59a40f977f01ba8e8f4c0424c484Brian Wellington><H2
84185d19c7a9ef1ac23cc6236c8773697d4efeb1Brian WellingtonCLASS="sect2"
84185d19c7a9ef1ac23cc6236c8773697d4efeb1Brian Wellington><A
84185d19c7a9ef1ac23cc6236c8773697d4efeb1Brian WellingtonNAME="AEN829"
683f10428e292811317df38fa324f242abbf7384Mark Andrews>4.4.3. Informing the Servers of the Key's Existence</A
683f10428e292811317df38fa324f242abbf7384Mark Andrews></H2
683f10428e292811317df38fa324f242abbf7384Mark Andrews><P
5da1e589c2288dbe87002f771005a78d80a2e258Mark Andrews>Imagine <I
5da1e589c2288dbe87002f771005a78d80a2e258Mark AndrewsCLASS="emphasis"
5da1e589c2288dbe87002f771005a78d80a2e258Mark Andrews>host1</I
5da1e589c2288dbe87002f771005a78d80a2e258Mark Andrews> and <I
5da1e589c2288dbe87002f771005a78d80a2e258Mark AndrewsCLASS="emphasis"
5da1e589c2288dbe87002f771005a78d80a2e258Mark Andrews>host 2</I
852fa3b2e32719d094f3ad6513238841ae1f078bMark Andrews> are
852fa3b2e32719d094f3ad6513238841ae1f078bMark Andrewsboth servers. The following is added to each server's <TT
852fa3b2e32719d094f3ad6513238841ae1f078bMark AndrewsCLASS="filename"
8569ab045a4cf6ecd1b5a3354ddb1c93ef34ea57Brian Wellington>named.conf</TT
8569ab045a4cf6ecd1b5a3354ddb1c93ef34ea57Brian Wellington> file:</P
8569ab045a4cf6ecd1b5a3354ddb1c93ef34ea57Brian Wellington><PRE
a5c077e40c784cf9e25c95a1ab94db2faab04ae9Brian WellingtonCLASS="programlisting"
a5c077e40c784cf9e25c95a1ab94db2faab04ae9Brian Wellington>&#13;key host1-host2. {
a5c077e40c784cf9e25c95a1ab94db2faab04ae9Brian Wellington algorithm hmac-md5;
a5c077e40c784cf9e25c95a1ab94db2faab04ae9Brian Wellington secret "La/E5CjG9O+os1jq0a2jdA==";
2ca556300b09a94f0937b303386d29b95ef057ddBrian Wellington};
2ca556300b09a94f0937b303386d29b95ef057ddBrian Wellington</PRE
2ca556300b09a94f0937b303386d29b95ef057ddBrian Wellington><P
2ca556300b09a94f0937b303386d29b95ef057ddBrian Wellington>The algorithm, hmac-md5, is the only one supported by <SPAN
97527fc03cdb061759e2c9529c670ac1c190ef84Brian WellingtonCLASS="acronym"
97527fc03cdb061759e2c9529c670ac1c190ef84Brian Wellington>BIND</SPAN
e1c2a8b9c120bcfc2f56e866ca3069b8a90c38dbMark Andrews>.
e1c2a8b9c120bcfc2f56e866ca3069b8a90c38dbMark AndrewsThe secret is the one generated above. Since this is a secret, it
e1c2a8b9c120bcfc2f56e866ca3069b8a90c38dbMark Andrewsis recommended that either <TT
b7064914ca566fdd67cf0fe7e82d586cbb596470Mark AndrewsCLASS="filename"
b7064914ca566fdd67cf0fe7e82d586cbb596470Mark Andrews>named.conf</TT
b7064914ca566fdd67cf0fe7e82d586cbb596470Mark Andrews> be non-world
3e67a87fc6be516ec12afa5aa31c2c04d5a6ae17Brian Wellingtonreadable, or the key directive be added to a non-world readable
3e67a87fc6be516ec12afa5aa31c2c04d5a6ae17Brian Wellingtonfile that is included by <TT
3e67a87fc6be516ec12afa5aa31c2c04d5a6ae17Brian WellingtonCLASS="filename"
49f62849e5f80add0ee36b0f9b42cdce8de9748aMark Andrews>named.conf</TT
e9472e9f18f1c4f1279be2b3147be13a2bb731d0Mark Andrews>.</P
e9472e9f18f1c4f1279be2b3147be13a2bb731d0Mark Andrews><P
e9472e9f18f1c4f1279be2b3147be13a2bb731d0Mark Andrews>At this point, the key is recognized. This means that if the
e9472e9f18f1c4f1279be2b3147be13a2bb731d0Mark Andrewsserver receives a message signed by this key, it can verify the
e9472e9f18f1c4f1279be2b3147be13a2bb731d0Mark Andrewssignature. If the signature succeeds, the response is signed by
d073663cb45bef2fff5f9a43b9b6006edfc52483Mark Andrewsthe same key.</P
d073663cb45bef2fff5f9a43b9b6006edfc52483Mark Andrews></DIV
d073663cb45bef2fff5f9a43b9b6006edfc52483Mark Andrews><DIV
d83346263dc68358d73de2a8be60846c9c92950eAndreas GustafssonCLASS="sect2"
cad61731f8e960d9d99034a2a6eaafe1069c405cMark Andrews><H2
cad61731f8e960d9d99034a2a6eaafe1069c405cMark AndrewsCLASS="sect2"
54469c2b2262f6a3f09610df69e16e9c75fd1fe5Mark Andrews><A
54469c2b2262f6a3f09610df69e16e9c75fd1fe5Mark AndrewsNAME="AEN841"
54469c2b2262f6a3f09610df69e16e9c75fd1fe5Mark Andrews>4.4.4. Instructing the Server to Use the Key</A
90e303b114e56db5809fdd19805243457fa43cd9Olafur Gudmundsson></H2
90e303b114e56db5809fdd19805243457fa43cd9Olafur Gudmundsson><P
90e303b114e56db5809fdd19805243457fa43cd9Olafur Gudmundsson>Since keys are shared between two hosts only, the server must
adbb11147cd5d97d140485fa37e85e66e15cf594Mark Andrewsbe told when keys are to be used. The following is added to the <TT
b938d2af619822a8262c86223cad958511e716a9Andreas GustafssonCLASS="filename"
adbb11147cd5d97d140485fa37e85e66e15cf594Mark Andrews>named.conf</TT
9ab461a6ffed2ae2fe0380c30b69052db7473405Mark Andrews> file
9ab461a6ffed2ae2fe0380c30b69052db7473405Mark Andrewsfor <I
b627356826f7b22e2ef396b80e8394eac76bc109Mark AndrewsCLASS="emphasis"
77467267d97c781f3f3d050e229a874831e59c3dMark Andrews>host1</I
13ba983cc86bc7d80d5f66ba09002f7d510a6631Mark Andrews>, if the IP address of <I
13ba983cc86bc7d80d5f66ba09002f7d510a6631Mark AndrewsCLASS="emphasis"
3036da01090c0d1e11cddc26af16630d6d9c1f39Mark Andrews>host2</I
84d8c0166ddc63ad5ce64e7d354553de38b9aabdAndreas Gustafsson> is
da5d1cf1b1aa29ae53a0427be49291b04bd60549Mark Andrews10.1.2.3:</P
66291de2060a1569de3fe9c5f0c1225448868f7aMark Andrews><PRE
66291de2060a1569de3fe9c5f0c1225448868f7aMark AndrewsCLASS="programlisting"
6c06bc591a830023e5e7a41cc4b37978b98c0c51Mark Andrews>&#13;server 10.1.2.3 {
84d8c0166ddc63ad5ce64e7d354553de38b9aabdAndreas Gustafsson keys { host1-host2. ;};
6c06bc591a830023e5e7a41cc4b37978b98c0c51Mark Andrews};
58d943711575376b05b3b3b303922a8a9d7ce9c1Mark Andrews</PRE
c36f45e354c0d5b6ab9f821bfe315d0ce9d95a29Mark Andrews><P
9cec4ca6cac428a46c6d64197c64831dcc02f506Andreas Gustafsson>Multiple keys may be present, but only the first is used.
9cec4ca6cac428a46c6d64197c64831dcc02f506Andreas GustafssonThis directive does not contain any secrets, so it may be in a world-readable
9cec4ca6cac428a46c6d64197c64831dcc02f506Andreas Gustafssonfile.</P
23fb770906bf1fd98210f16ad660078274242963Mark Andrews><P
23fb770906bf1fd98210f16ad660078274242963Mark Andrews>If <I
23fb770906bf1fd98210f16ad660078274242963Mark AndrewsCLASS="emphasis"
0cb27602e5690baa9ab61c7c1430e507536adca7Brian Wellington>host1</I
0cb27602e5690baa9ab61c7c1430e507536adca7Brian Wellington> sends a message that is a request
0cb27602e5690baa9ab61c7c1430e507536adca7Brian Wellingtonto that address, the message will be signed with the specified key. <I
ff1b064f5e2bf19c8e25f8927d23df5714e666edMark AndrewsCLASS="emphasis"
ff1b064f5e2bf19c8e25f8927d23df5714e666edMark Andrews>host1</I
8e40433e347bc487cd70f02487fc7ce947a2422aMark Andrews> will
8e40433e347bc487cd70f02487fc7ce947a2422aMark Andrewsexpect any responses to signed messages to be signed with the same
8e40433e347bc487cd70f02487fc7ce947a2422aMark Andrewskey.</P
880723fb130841459d45695b387651cacd6c9bb8Mark Andrews><P
880723fb130841459d45695b387651cacd6c9bb8Mark Andrews>A similar statement must be present in <I
880723fb130841459d45695b387651cacd6c9bb8Mark AndrewsCLASS="emphasis"
8f44fd4f8d5cefc227ab0fe59cbcbc3979fbc9caAndreas Gustafsson>host2</I
8f44fd4f8d5cefc227ab0fe59cbcbc3979fbc9caAndreas Gustafsson>'s
8f44fd4f8d5cefc227ab0fe59cbcbc3979fbc9caAndreas Gustafssonconfiguration file (with <I
8f44fd4f8d5cefc227ab0fe59cbcbc3979fbc9caAndreas GustafssonCLASS="emphasis"
fefbb64a751f23c9dcf8bb1e62c6ed40a6a04fb2Mark Andrews>host1</I
fefbb64a751f23c9dcf8bb1e62c6ed40a6a04fb2Mark Andrews>'s address) for <I
fefbb64a751f23c9dcf8bb1e62c6ed40a6a04fb2Mark AndrewsCLASS="emphasis"
0d6f70f1dbf77cf10e0bae8683c741f5924f6afeMark Andrews>host2</I
b938d2af619822a8262c86223cad958511e716a9Andreas Gustafsson> to
111e3433d289e8b4ea1260add39baa78c2a46891Mark Andrewssign request messages to <I
cf300e03de3df3ff422db922520bf07c686c86daMark AndrewsCLASS="emphasis"
cf300e03de3df3ff422db922520bf07c686c86daMark Andrews>host1</I
cf300e03de3df3ff422db922520bf07c686c86daMark Andrews>.</P
9ac8796f1653d89af589753a3e42c694f35ddd8aMark Andrews></DIV
9ac8796f1653d89af589753a3e42c694f35ddd8aMark Andrews><DIV
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas GustafssonCLASS="sect2"
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas Gustafsson><H2
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas GustafssonCLASS="sect2"
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas Gustafsson><A
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas GustafssonNAME="AEN857"
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas Gustafsson>4.4.5. TSIG Key Based Access Control</A
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas Gustafsson></H2
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas Gustafsson><P
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas Gustafsson><SPAN
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas GustafssonCLASS="acronym"
f2c49862fb348586bb4b95a5388c86e0c0cbfa2cAndreas Gustafsson>BIND</SPAN
02bdc23f8e3ca0f710e0a40daa15941ab1db6bb2Mark Andrews> allows IP addresses and ranges to be specified in ACL
45fe575607b91147ed753d175a7255198f14f197Andreas Gustafssondefinitions and
ef29912666cc6160f7165558bef017ab3849c5e1Mark Andrews<B
ef29912666cc6160f7165558bef017ab3849c5e1Mark AndrewsCLASS="command"
ef29912666cc6160f7165558bef017ab3849c5e1Mark Andrews>allow-{ query | transfer | update }</B
ef29912666cc6160f7165558bef017ab3849c5e1Mark Andrews> directives.
ef29912666cc6160f7165558bef017ab3849c5e1Mark AndrewsThis has been extended to allow TSIG keys also. The above key would
ef29912666cc6160f7165558bef017ab3849c5e1Mark Andrewsbe denoted <B
ef29912666cc6160f7165558bef017ab3849c5e1Mark AndrewsCLASS="command"
0cfa2fb26df42f781eca8c4c856d2d0165055bebMark Andrews>key host1-host2.</B
0cfa2fb26df42f781eca8c4c856d2d0165055bebMark Andrews></P
0cfa2fb26df42f781eca8c4c856d2d0165055bebMark Andrews><P
0cfa2fb26df42f781eca8c4c856d2d0165055bebMark Andrews>An example of an allow-update directive would be:</P
06a949d2ce8d4b4cbfbf4e7a0335316520aafa46Andreas Gustafsson><PRE
06a949d2ce8d4b4cbfbf4e7a0335316520aafa46Andreas GustafssonCLASS="programlisting"
06a949d2ce8d4b4cbfbf4e7a0335316520aafa46Andreas Gustafsson>&#13;allow-update { key host1-host2. ;};
0b81e99ddfb01746e667797dedc291fc550d14d3Brian Wellington</PRE
0b81e99ddfb01746e667797dedc291fc550d14d3Brian Wellington><P
0b81e99ddfb01746e667797dedc291fc550d14d3Brian Wellington>This allows dynamic updates to succeed only if the request
3638017bd3cb8e30874f708a125d1541b680b25eBrian Wellington was signed by a key named
3638017bd3cb8e30874f708a125d1541b680b25eBrian Wellington "<B
3638017bd3cb8e30874f708a125d1541b680b25eBrian WellingtonCLASS="command"
8771fbe4a2cee7bebd785a486824833d741c7315Brian Wellington>host1-host2.</B
8771fbe4a2cee7bebd785a486824833d741c7315Brian Wellington>".</P
8771fbe4a2cee7bebd785a486824833d741c7315Brian Wellington><P
b541c10d0442d9804d94567a97956cec3bd2912dBrian Wellington>You may want to read about the more
8bb79fc9b9952172d10f56f31739730e38d4b013Brian Wellington powerful <B
f59d47928ed33d1546e8f982370086429f727e85Andreas GustafssonCLASS="command"
f59d47928ed33d1546e8f982370086429f727e85Andreas Gustafsson>update-policy</B
b541c10d0442d9804d94567a97956cec3bd2912dBrian Wellington> statement in <A
c01237c6bc5ec25063b4aae1799fe4de01a7455bAndreas GustafssonHREF="Bv9ARM.ch06.html#dynamic_update_policies"
c01237c6bc5ec25063b4aae1799fe4de01a7455bAndreas Gustafsson>Section 6.2.22.4</A
c01237c6bc5ec25063b4aae1799fe4de01a7455bAndreas Gustafsson>.</P
60213f2815a7e6584a2285546d05633fa7b6f5b4Mark Andrews></DIV
c52806164c335f89e1980af836470b6daffe4f82Andreas Gustafsson><DIV
60213f2815a7e6584a2285546d05633fa7b6f5b4Mark AndrewsCLASS="sect2"
c52806164c335f89e1980af836470b6daffe4f82Andreas Gustafsson><H2
c52806164c335f89e1980af836470b6daffe4f82Andreas GustafssonCLASS="sect2"
c52806164c335f89e1980af836470b6daffe4f82Andreas Gustafsson><A
6c8abf481df85a67c3f32f5f107b554d3ff5a3edMark AndrewsNAME="AEN870"
c52806164c335f89e1980af836470b6daffe4f82Andreas Gustafsson>4.4.6. Errors</A
c52806164c335f89e1980af836470b6daffe4f82Andreas Gustafsson></H2
1e4bfff1855795853648f507422b96fc8fecbff1Mark Andrews><P
6b31d9c56874d3bd58b420cbe6cd64be502dbe08Andreas Gustafsson>The processing of TSIG signed messages can result in
892476530f3971aff52f25103d488ece9b01f673Andreas Gustafsson several errors. If a signed message is sent to a non-TSIG aware
6b31d9c56874d3bd58b420cbe6cd64be502dbe08Andreas Gustafsson server, a FORMERR will be returned, since the server will not
6b31d9c56874d3bd58b420cbe6cd64be502dbe08Andreas Gustafsson understand the record. This is a result of misconfiguration,
ee80f4506479e189ca1320eb87ac89188c5a7848Mark Andrews since the server must be explicitly configured to send a TSIG
ee80f4506479e189ca1320eb87ac89188c5a7848Mark Andrews signed message to a specific server.</P
ee80f4506479e189ca1320eb87ac89188c5a7848Mark Andrews><P
d9d6d2f77fe54831dec9cde8ca03ae1f825599f9Andreas Gustafsson>If a TSIG aware server receives a message signed by an
d9d6d2f77fe54831dec9cde8ca03ae1f825599f9Andreas Gustafsson unknown key, the response will be unsigned with the TSIG
d9d6d2f77fe54831dec9cde8ca03ae1f825599f9Andreas Gustafsson extended error code set to BADKEY. If a TSIG aware server
9b2c0d29248ad5f86b47319239a06c783e1b5307Andreas Gustafsson receives a message with a signature that does not validate, the
9b2c0d29248ad5f86b47319239a06c783e1b5307Andreas Gustafsson response will be unsigned with the TSIG extended error code set
eb2c518a3871932e86268e7c6ddae2b2a00d72fdMark Andrews to BADSIG. If a TSIG aware server receives a message with a time
4072dfb9b865c82c24a72e734d54da51a20dfc1eMark Andrews outside of the allowed range, the response will be signed with
4072dfb9b865c82c24a72e734d54da51a20dfc1eMark Andrews the TSIG extended error code set to BADTIME, and the time values
92094d44a2d0cb2b1be58a87299903ba7c436a0cAndreas Gustafsson will be adjusted so that the response can be successfully
92094d44a2d0cb2b1be58a87299903ba7c436a0cAndreas Gustafsson verified. In any of these cases, the message's rcode is set to
92094d44a2d0cb2b1be58a87299903ba7c436a0cAndreas Gustafsson NOTAUTH.</P
11fe3dcfe2a5fbefd0cfe445872dc4c595506204Andreas Gustafsson></DIV
11fe3dcfe2a5fbefd0cfe445872dc4c595506204Andreas Gustafsson></DIV
11fe3dcfe2a5fbefd0cfe445872dc4c595506204Andreas Gustafsson><DIV
d1abb8bb020aacd1ce0da65c2d5d8f7c96ebd52aMark AndrewsCLASS="sect1"
b4aeceec736cd16d4c4e98f519c8df79b15fbe45Andreas Gustafsson><H1
b4aeceec736cd16d4c4e98f519c8df79b15fbe45Andreas GustafssonCLASS="sect1"
b4aeceec736cd16d4c4e98f519c8df79b15fbe45Andreas Gustafsson><A
307ba34fa07db768c3a899844f248a2c1d7dcc7fAndreas GustafssonNAME="AEN874"
307ba34fa07db768c3a899844f248a2c1d7dcc7fAndreas Gustafsson>4.5. TKEY</A
307ba34fa07db768c3a899844f248a2c1d7dcc7fAndreas Gustafsson></H1
307ba34fa07db768c3a899844f248a2c1d7dcc7fAndreas Gustafsson><P
b6b9d8b8434e4eaab74b69cd14fcacf448055ca5Brian Wellington><B
b6b9d8b8434e4eaab74b69cd14fcacf448055ca5Brian WellingtonCLASS="command"
b6b9d8b8434e4eaab74b69cd14fcacf448055ca5Brian Wellington>TKEY</B
31f6e44dcaad33d66d607e3a919d4aa59cdbaec5Andreas Gustafsson> is a mechanism for automatically
31f6e44dcaad33d66d607e3a919d4aa59cdbaec5Andreas Gustafsson generating a shared secret between two hosts. There are several
31f6e44dcaad33d66d607e3a919d4aa59cdbaec5Andreas Gustafsson "modes" of <B
31f6e44dcaad33d66d607e3a919d4aa59cdbaec5Andreas GustafssonCLASS="command"
af36ecc41ae6bd73553aacd006ae55474e193b07Andreas Gustafsson>TKEY</B
af36ecc41ae6bd73553aacd006ae55474e193b07Andreas Gustafsson> that specify how the key is
6d6529b5e5ab7223fa2560ebe144bcb82517cef3Mark Andrews generated or assigned. <SPAN
0b07b9482c00060d1ddd551a5dcb8cecbe2c1f65Mark AndrewsCLASS="acronym"
af36ecc41ae6bd73553aacd006ae55474e193b07Andreas Gustafsson>BIND</SPAN
0b07b9482c00060d1ddd551a5dcb8cecbe2c1f65Mark Andrews> implements only one of these modes,
c0fe9b0d1b01a9a0883977a362ce4128723a56d6Mark Andrews the Diffie-Hellman key exchange. Both hosts are required to have
c0fe9b0d1b01a9a0883977a362ce4128723a56d6Mark Andrews a Diffie-Hellman KEY record (although this record is not required
2869504d83e84a91dbc822e8a243e837f5c0374dAndreas Gustafsson to be present in a zone). The <B
2869504d83e84a91dbc822e8a243e837f5c0374dAndreas GustafssonCLASS="command"
2869504d83e84a91dbc822e8a243e837f5c0374dAndreas Gustafsson>TKEY</B
138cc7f283889367b11840ff77a9ea08e17a9daeAndreas Gustafsson> process
ce6caa07591b3723968c22f5aa13740f9609135aAndreas Gustafsson must use signed messages, signed either by TSIG or SIG(0). The
138cc7f283889367b11840ff77a9ea08e17a9daeAndreas Gustafsson result of <B
138cc7f283889367b11840ff77a9ea08e17a9daeAndreas GustafssonCLASS="command"
ac1a59e95cfd035f38222e739affd43eafa9eeefMark Andrews>TKEY</B
ac1a59e95cfd035f38222e739affd43eafa9eeefMark Andrews> is a shared secret that can be
58930ca9802e772afe9f5ccb30f236d201cf60e0Danny Mayer used to sign messages with TSIG. <B
58930ca9802e772afe9f5ccb30f236d201cf60e0Danny MayerCLASS="command"
58930ca9802e772afe9f5ccb30f236d201cf60e0Danny Mayer>TKEY</B
e3e94dd137c5f9d3d5c5179863f674b27aa0cc02Andreas Gustafsson> can also
e3e94dd137c5f9d3d5c5179863f674b27aa0cc02Andreas Gustafsson be used to delete shared secrets that it had previously
e3e94dd137c5f9d3d5c5179863f674b27aa0cc02Andreas Gustafsson generated.</P
e3e94dd137c5f9d3d5c5179863f674b27aa0cc02Andreas Gustafsson><P
7c014c5bf41dc38802e8889c0a9110204eb1a552Andreas Gustafsson>The <B
7c014c5bf41dc38802e8889c0a9110204eb1a552Andreas GustafssonCLASS="command"
7c014c5bf41dc38802e8889c0a9110204eb1a552Andreas Gustafsson>TKEY</B
7c014c5bf41dc38802e8889c0a9110204eb1a552Andreas Gustafsson> process is initiated by a client
7c014c5bf41dc38802e8889c0a9110204eb1a552Andreas Gustafsson or server by sending a signed <B
3e42bdfdc901b6b921b02028bd51ca2af8e84adcMark AndrewsCLASS="command"
3e42bdfdc901b6b921b02028bd51ca2af8e84adcMark Andrews>TKEY</B
2053e8c26cd69600132632fbee247601ce8c9e8cAndreas Gustafsson> query
3e42bdfdc901b6b921b02028bd51ca2af8e84adcMark Andrews (including any appropriate KEYs) to a TKEY-aware server. The
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark Andrews server response, if it indicates success, will contain a
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark Andrews <B
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark AndrewsCLASS="command"
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark Andrews>TKEY</B
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark Andrews> record and any appropriate keys. After
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark Andrews this exchange, both participants have enough information to
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark Andrews determine the shared secret; the exact process depends on the
ea01b618d981e58f85071a40550bc7f7565d4509Andreas Gustafsson <B
ea01b618d981e58f85071a40550bc7f7565d4509Andreas GustafssonCLASS="command"
bad3251d3f7ffccdec39ccfe04d94308985fb36eAndreas Gustafsson>TKEY</B
bad3251d3f7ffccdec39ccfe04d94308985fb36eAndreas Gustafsson> mode. When using the Diffie-Hellman
80dd46d7aab16c42a8c1acf6156c95406a9f20a4Mark Andrews <B
9eec883bf871ee2235009e889440f986c98908b8Andreas GustafssonCLASS="command"
993572b2495561c57b556621dd9fe493e8c6dd1bDanny Mayer>TKEY</B
78bf1ca89505820ed7b03be4bf0c0b53b557f3cdAndreas Gustafsson> mode, Diffie-Hellman keys are exchanged,
78bf1ca89505820ed7b03be4bf0c0b53b557f3cdAndreas Gustafsson and the shared secret is derived by both participants.</P
78bf1ca89505820ed7b03be4bf0c0b53b557f3cdAndreas Gustafsson></DIV
78bf1ca89505820ed7b03be4bf0c0b53b557f3cdAndreas Gustafsson><DIV
088eaf3878580eebbbd2b020411532af278aae5aAndreas GustafssonCLASS="sect1"
6b13908f7030e09fb4573f3c2f8d7a5edc70e0b5Mark Andrews><H1
afeabf9f707ca71192041c1132d9f07d7bd83132Mark AndrewsCLASS="sect1"
3842a051baf34ffc4e428cd6f2d4a641e548e6f6Mark Andrews><A
3842a051baf34ffc4e428cd6f2d4a641e548e6f6Mark AndrewsNAME="AEN889"
46ba6046bcb3b534346de13a4ff5c1513e72936bAndreas Gustafsson>4.6. SIG(0)</A
46ba6046bcb3b534346de13a4ff5c1513e72936bAndreas Gustafsson></H1
46ba6046bcb3b534346de13a4ff5c1513e72936bAndreas Gustafsson><P
a89d1aea0cce6a28a3751cd508db67e38d307a5eDanny Mayer><SPAN
04f158ce9a12746eb216892b2bf8259749db254eAndreas GustafssonCLASS="acronym"
04f158ce9a12746eb216892b2bf8259749db254eAndreas Gustafsson>BIND</SPAN
04f158ce9a12746eb216892b2bf8259749db254eAndreas Gustafsson> 9 partially supports DNSSEC SIG(0) transaction
04f158ce9a12746eb216892b2bf8259749db254eAndreas Gustafsson signatures as specified in RFC 2535. SIG(0) uses public/private
62c1fe7b450916acdaf4a3fe65a9b691d5d32f3fBrian Wellington keys to authenticate messages. Access control is performed in the
62c1fe7b450916acdaf4a3fe65a9b691d5d32f3fBrian Wellington same manner as TSIG keys; privileges can be granted or denied
62c1fe7b450916acdaf4a3fe65a9b691d5d32f3fBrian Wellington based on the key name.</P
712bf9b0cc4ed34f4bf33b437f8b0e45853b93ceMark Andrews><P
712bf9b0cc4ed34f4bf33b437f8b0e45853b93ceMark Andrews>When a SIG(0) signed message is received, it will only be
7e2f4ceafaae4eac1deddc87f906b29a922fff9dAndreas Gustafsson verified if the key is known and trusted by the server; the server
7e2f4ceafaae4eac1deddc87f906b29a922fff9dAndreas Gustafsson will not attempt to locate and/or validate the key.</P
7e2f4ceafaae4eac1deddc87f906b29a922fff9dAndreas Gustafsson><P
2053e8c26cd69600132632fbee247601ce8c9e8cAndreas Gustafsson>SIG(0) signing of multiple-message TCP streams is not
72499be79fbb68140bd31e0e4ded18a70a5b523bMark Andrews supported.</P
90c5477ca11a94b0e7d8071181d69544e1ab9be9Mark Andrews><P
90c5477ca11a94b0e7d8071181d69544e1ab9be9Mark Andrews><SPAN
90c5477ca11a94b0e7d8071181d69544e1ab9be9Mark AndrewsCLASS="acronym"
552a117791c17878c5c1b94b0fc3ac4e8491543eMark Andrews>BIND</SPAN
552a117791c17878c5c1b94b0fc3ac4e8491543eMark Andrews> 9 does not ship with any tools that generate SIG(0)
f3e4c3d6c536973bae92611402ba55277069eba2Mark Andrews signed messages.</P
f3e4c3d6c536973bae92611402ba55277069eba2Mark Andrews></DIV
6fb633bc3fddba07fc9460ffd245b7ee2d459285Mark Andrews><DIV
6fb633bc3fddba07fc9460ffd245b7ee2d459285Mark AndrewsCLASS="sect1"
6fb633bc3fddba07fc9460ffd245b7ee2d459285Mark Andrews><H1
ca033e166ca9f9dc7bf010065a93af668a09fd44Mark AndrewsCLASS="sect1"
ca033e166ca9f9dc7bf010065a93af668a09fd44Mark Andrews><A
ca033e166ca9f9dc7bf010065a93af668a09fd44Mark AndrewsNAME="DNSSEC"
f9321a16fb8dce8999a43a6d4008c54845305401Mark Andrews>4.7. DNSSEC</A
c8bedec446212b07511ded85ba04a9a3d5965ba8Mark Andrews></H1
c8bedec446212b07511ded85ba04a9a3d5965ba8Mark Andrews><P
7a104af70fb3071e7949c4e0e585af18ab362db5Mark Andrews>Cryptographic authentication of DNS information is possible
7a104af70fb3071e7949c4e0e585af18ab362db5Mark Andrews through the DNS Security (<I
e70b069e3807d5f499dff31eb31c2b3e0e125457Mark AndrewsCLASS="emphasis"
7a104af70fb3071e7949c4e0e585af18ab362db5Mark Andrews>DNSSEC</I
923de3bb9cf4d619de206544975986a22b18196fMark Andrews>) extensions,
923de3bb9cf4d619de206544975986a22b18196fMark Andrews defined in RFC 2535. This section describes the creation and use
2359261a252b339f3cef046cefa10ee1e1d4564dMark Andrews of DNSSEC signed zones.</P
2359261a252b339f3cef046cefa10ee1e1d4564dMark Andrews><P
769cd7d5dd677434c3dfa27cbfdd8cb76296fcdcMark Andrews>In order to set up a DNSSEC secure zone, there are a series
769cd7d5dd677434c3dfa27cbfdd8cb76296fcdcMark Andrews of steps which must be followed. <SPAN
769cd7d5dd677434c3dfa27cbfdd8cb76296fcdcMark AndrewsCLASS="acronym"
6bad645917a026dfa4662dd0a3a78b9efc3f4c36Mark Andrews>BIND</SPAN
6bad645917a026dfa4662dd0a3a78b9efc3f4c36Mark Andrews> 9 ships
11931cc68d6c8139f507a724e7ca9814eed8b552Mark Andrews with several tools
11931cc68d6c8139f507a724e7ca9814eed8b552Mark Andrews that are used in this process, which are explained in more detail
11931cc68d6c8139f507a724e7ca9814eed8b552Mark Andrews below. In all cases, the "<TT
64e9b7eafb798c75e9a40948cf05d8847da59d9dAndreas GustafssonCLASS="option"
11931cc68d6c8139f507a724e7ca9814eed8b552Mark Andrews>-h</TT
11931cc68d6c8139f507a724e7ca9814eed8b552Mark Andrews>" option prints a
d91d025deffd075db2507d44fab04b79920b3e91Mark Andrews full list of parameters. Note that the DNSSEC tools require the
d91d025deffd075db2507d44fab04b79920b3e91Mark Andrews keyset and signedkey files to be in the working directory, and
d91d025deffd075db2507d44fab04b79920b3e91Mark Andrews that the tools shipped with BIND 9.0.x are not fully compatible
985b4f1c8653c6dfaa46652c412838850c0ffb1cMark Andrews with the current ones.</P
985b4f1c8653c6dfaa46652c412838850c0ffb1cMark Andrews><P
c8d9ff1fe871a0e9d5834240c5872a26166cc240Andreas Gustafsson>There must also be communication with the administrators of
1d556695ef3c7918ba5061d7d846122d60f5f6c5Mark Andrews the parent and/or child zone to transmit keys and signatures. A
e9ca87459a20f5e6721b9bd0b28c95fc3d6b843cMark Andrews zone's security status must be indicated by the parent zone for a
e9ca87459a20f5e6721b9bd0b28c95fc3d6b843cMark Andrews DNSSEC capable resolver to trust its data.</P
ca690f98020f75758bc26f4b5ef1ccf0472a27c3Mark Andrews><P
ca690f98020f75758bc26f4b5ef1ccf0472a27c3Mark Andrews>For other servers to trust data in this zone, they must
ca690f98020f75758bc26f4b5ef1ccf0472a27c3Mark Andrews either be statically configured with this zone's zone key or the
137a1f98e3862577ae9ccbb6b735ef63a51c456eMark Andrews zone key of another zone above this one in the DNS tree.</P
137a1f98e3862577ae9ccbb6b735ef63a51c456eMark Andrews><DIV
5cd7e9d4db393c314dd1a761c52d2cb3a4da9b72Andreas GustafssonCLASS="sect2"
5cd7e9d4db393c314dd1a761c52d2cb3a4da9b72Andreas Gustafsson><H2
5f4804c7e47e3cfe7237d27a354d268b0b7ea73bAndreas GustafssonCLASS="sect2"
5cd7e9d4db393c314dd1a761c52d2cb3a4da9b72Andreas Gustafsson><A
cc8e8b59d6780889739657226a95e23ca1ecadb1Andreas GustafssonNAME="AEN906"
cc8e8b59d6780889739657226a95e23ca1ecadb1Andreas Gustafsson>4.7.1. Generating Keys</A
1418d7292da7ebaba1ba389d60192023c0170245Andreas Gustafsson></H2
cc8e8b59d6780889739657226a95e23ca1ecadb1Andreas Gustafsson><P
65775fe205e8ac935313c42062c75460e0bc1514Andreas Gustafsson>The <B
65775fe205e8ac935313c42062c75460e0bc1514Andreas GustafssonCLASS="command"
65775fe205e8ac935313c42062c75460e0bc1514Andreas Gustafsson>dnssec-keygen</B
65775fe205e8ac935313c42062c75460e0bc1514Andreas Gustafsson> program is used to
17b687ef360ba8c07201dc6511a3c975cc1bb2a8Andreas Gustafsson generate keys.</P
17b687ef360ba8c07201dc6511a3c975cc1bb2a8Andreas Gustafsson><P
17b687ef360ba8c07201dc6511a3c975cc1bb2a8Andreas Gustafsson>A secure zone must contain one or more zone keys. The
17b687ef360ba8c07201dc6511a3c975cc1bb2a8Andreas Gustafsson zone keys will sign all other records in the zone, as well as
998358fa900393378c70ad598c2b2e67385089d4Mark Andrews the zone keys of any secure delegated zones. Zone keys must
998358fa900393378c70ad598c2b2e67385089d4Mark Andrews have the same name as the zone, a name type of
2053e8c26cd69600132632fbee247601ce8c9e8cAndreas Gustafsson <B
998358fa900393378c70ad598c2b2e67385089d4Mark AndrewsCLASS="command"
bc508906db43dda7eab0988348dd0ae3f3023a9bMark Andrews>ZONE</B
bc508906db43dda7eab0988348dd0ae3f3023a9bMark Andrews>, and must be usable for authentication.
bc508906db43dda7eab0988348dd0ae3f3023a9bMark Andrews It is recommended that zone keys be mandatory to implement a
b352902413608d0eb310c4bb45412fa45734afbcAndreas Gustafsson cryptographic algorithm; currently the only key mandatory to
b352902413608d0eb310c4bb45412fa45734afbcAndreas Gustafsson implement an algorithm is DSA.</P
b352902413608d0eb310c4bb45412fa45734afbcAndreas Gustafsson><P
b352902413608d0eb310c4bb45412fa45734afbcAndreas Gustafsson>The following command will generate a 768 bit DSA key for
b352902413608d0eb310c4bb45412fa45734afbcAndreas Gustafsson the <TT
b352902413608d0eb310c4bb45412fa45734afbcAndreas GustafssonCLASS="filename"
72e8c079c4c6dc66d565cf89ebf6feb5fa2dea33Mark Andrews>child.example</TT
72e8c079c4c6dc66d565cf89ebf6feb5fa2dea33Mark Andrews> zone:</P
72e8c079c4c6dc66d565cf89ebf6feb5fa2dea33Mark Andrews><P
c8ab83c08e5227b5146295a9ef4a96d61b066b67Andreas Gustafsson><TT
c8ab83c08e5227b5146295a9ef4a96d61b066b67Andreas GustafssonCLASS="userinput"
c8ab83c08e5227b5146295a9ef4a96d61b066b67Andreas Gustafsson><B
4e57d3ff7d92abdef4b0b6aebc23a9dfae2ba040Andreas Gustafsson>dnssec-keygen -a DSA -b 768 -n ZONE child.example.</B
4e57d3ff7d92abdef4b0b6aebc23a9dfae2ba040Andreas Gustafsson></TT
4e57d3ff7d92abdef4b0b6aebc23a9dfae2ba040Andreas Gustafsson></P
1c398fd83c444d61904d23431d3994139919b68eAndreas Gustafsson><P
be9932698bf35d0f34e65b5ffbb81bedddd76636Mark Andrews>Two output files will be produced:
081cff0c33514a5dc63ab794fc199c07377ab756Mark Andrews <TT
d352f188cb9e3820054b7451384a3d910619b4a1Andreas GustafssonCLASS="filename"
d352f188cb9e3820054b7451384a3d910619b4a1Andreas Gustafsson>Kchild.example.+003+12345.key</TT
d352f188cb9e3820054b7451384a3d910619b4a1Andreas Gustafsson> and
3d38596530c389610494e6a6ba70d9f5dc9717c5Andreas Gustafsson <TT
081cff0c33514a5dc63ab794fc199c07377ab756Mark AndrewsCLASS="filename"
3d38596530c389610494e6a6ba70d9f5dc9717c5Andreas Gustafsson>Kchild.example.+003+12345.private</TT
a7cb695600c3c14ac12676f0fb1e179690c5883cMark Andrews> (where
a7cb695600c3c14ac12676f0fb1e179690c5883cMark Andrews 12345 is an example of a key tag). The key file names contain
a7cb695600c3c14ac12676f0fb1e179690c5883cMark Andrews the key name (<TT
479c6fc4584e062088ceee037690cdff85fc349bAndreas GustafssonCLASS="filename"
b19619260fbd447b0fe3e709b2cc8ae38f27ec3fMark Andrews>child.example.</TT
1500a4fe5da9475d5918b27b566a1278ec6b54ebAndreas Gustafsson>), algorithm (3
1500a4fe5da9475d5918b27b566a1278ec6b54ebAndreas Gustafsson is DSA, 1 is RSA, etc.), and the key tag (12345 in this case).
1255d388f034dc556d235a002527101781dbeb29Mark Andrews The private key (in the <TT
1255d388f034dc556d235a002527101781dbeb29Mark AndrewsCLASS="filename"
c615c2ddce6c08e5a26d9ca61742a20fa8dc1938Mark Andrews>.private</TT
c615c2ddce6c08e5a26d9ca61742a20fa8dc1938Mark Andrews> file) is
c615c2ddce6c08e5a26d9ca61742a20fa8dc1938Mark Andrews used to generate signatures, and the public key (in the
31d3464c0c0a35236c7924f698c5a8a66a9ed534Mark Andrews <TT
31d3464c0c0a35236c7924f698c5a8a66a9ed534Mark AndrewsCLASS="filename"
31d3464c0c0a35236c7924f698c5a8a66a9ed534Mark Andrews>.key</TT
f04c15adc7e62deb2f53cc53f32d890936007903Andreas Gustafsson> file) is used for signature
f04c15adc7e62deb2f53cc53f32d890936007903Andreas Gustafsson verification.</P
2f6d1483f665d86501049199b9698554da0eacb0Mark Andrews><P
53c07ca2164f8a083aa97591345bf4339a8573bdAndreas Gustafsson>To generate another key with the same properties (but with
d1029cbcf03a0a2a6c05c1e17e692d844eb27094Andreas Gustafsson a different key tag), repeat the above command.</P
ea7b38cd1e5c6c9e099f1b3a702ba531bc4aba0aMark Andrews><P
32d248107a5bc92b4bf9fc77deaa55b3da969ba2Andreas Gustafsson>The public keys should be inserted into the zone file with
32d248107a5bc92b4bf9fc77deaa55b3da969ba2Andreas Gustafsson <B
32d248107a5bc92b4bf9fc77deaa55b3da969ba2Andreas GustafssonCLASS="command"
32d248107a5bc92b4bf9fc77deaa55b3da969ba2Andreas Gustafsson>$INCLUDE</B
4574714ad44ba97f53425fe8d21b7ecb00ac83b9Andreas Gustafsson> statements, including the
4574714ad44ba97f53425fe8d21b7ecb00ac83b9Andreas Gustafsson <TT
4574714ad44ba97f53425fe8d21b7ecb00ac83b9Andreas GustafssonCLASS="filename"
4574714ad44ba97f53425fe8d21b7ecb00ac83b9Andreas Gustafsson>.key</TT
4574714ad44ba97f53425fe8d21b7ecb00ac83b9Andreas Gustafsson> files.</P
8d8c145175370d2fd8dbdf425b5ac2a9dc19da96Mark Andrews></DIV
8d8c145175370d2fd8dbdf425b5ac2a9dc19da96Mark Andrews><DIV
07eaf0b8d0c3c93d8139c413bf9cc8bba7db9432Mark AndrewsCLASS="sect2"
cf70df7d0e24401a358f0b9c1a616ad0e8c783a6Mark Andrews><H2
cf70df7d0e24401a358f0b9c1a616ad0e8c783a6Mark AndrewsCLASS="sect2"
cf70df7d0e24401a358f0b9c1a616ad0e8c783a6Mark Andrews><A
9234d92d4e274791eff42cc4ea5766ed7a281b17Mark AndrewsNAME="AEN926"
9234d92d4e274791eff42cc4ea5766ed7a281b17Mark Andrews>4.7.2. Creating a Keyset</A
9234d92d4e274791eff42cc4ea5766ed7a281b17Mark Andrews></H2
0cf9ce19cc05a60f85ec610106a983fe806ebb77Andreas Gustafsson><P
0cf9ce19cc05a60f85ec610106a983fe806ebb77Andreas Gustafsson>The <B
0cf9ce19cc05a60f85ec610106a983fe806ebb77Andreas GustafssonCLASS="command"
0cf9ce19cc05a60f85ec610106a983fe806ebb77Andreas Gustafsson>dnssec-makekeyset</B
42f61e5c46d4824918385e7279c1b71d8ada8e8dAndreas Gustafsson> program is used
2ba574f329c14376d26d7c0f22c89d7a978a2625Mark Andrews to create a key set from one or more keys.</P
2ba574f329c14376d26d7c0f22c89d7a978a2625Mark Andrews><P
3c3fe072252aecffae43e6349125663c315b092dAndreas Gustafsson>Once the zone keys have been generated, a key set must be
3c3fe072252aecffae43e6349125663c315b092dAndreas Gustafsson built for transmission to the administrator of the parent zone,
3c3fe072252aecffae43e6349125663c315b092dAndreas Gustafsson so that the parent zone can sign the keys with its own zone key
3c3fe072252aecffae43e6349125663c315b092dAndreas Gustafsson and correctly indicate the security status of this zone. When
64ea5fd972c9946a3fe56cbc0bf897266d3f8747Andreas Gustafsson building a key set, the list of keys to be included and the TTL
64ea5fd972c9946a3fe56cbc0bf897266d3f8747Andreas Gustafsson of the set must be specified, and the desired signature validity
05a4a299b599195ca6ede9395b245956a8c3a790Mark Andrews period of the parent's signature may also be specified.</P
3ad07fa335d40330cd1859da42e67f2457443990Andreas Gustafsson><P
3ad07fa335d40330cd1859da42e67f2457443990Andreas Gustafsson>The list of keys to be inserted into the key set may also
3ad07fa335d40330cd1859da42e67f2457443990Andreas Gustafsson included non-zone keys present at the top of the zone.
1094dec52a86e57df53f6167d86de94360a7a382Mark Andrews <B
1094dec52a86e57df53f6167d86de94360a7a382Mark AndrewsCLASS="command"
64ea5fd972c9946a3fe56cbc0bf897266d3f8747Andreas Gustafsson>dnssec-makekeyset</B
1094dec52a86e57df53f6167d86de94360a7a382Mark Andrews> may also be used at other
fa2fb620c7c0a907b220c257007d8fb6d38bb3a4Andreas Gustafsson names in the zone.</P
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas Gustafsson><P
fa2fb620c7c0a907b220c257007d8fb6d38bb3a4Andreas Gustafsson>The following command generates a key set containing the
fa2fb620c7c0a907b220c257007d8fb6d38bb3a4Andreas Gustafsson above key and another key similarly generated, with a TTL of
fa2fb620c7c0a907b220c257007d8fb6d38bb3a4Andreas Gustafsson 3600 and a signature validity period of 10 days starting from
62a3dbe63e833f2eaf613393399ea4667d8de28dAndreas Gustafsson now.</P
62a3dbe63e833f2eaf613393399ea4667d8de28dAndreas Gustafsson><P
62a3dbe63e833f2eaf613393399ea4667d8de28dAndreas Gustafsson><TT
62a3dbe63e833f2eaf613393399ea4667d8de28dAndreas GustafssonCLASS="userinput"
62a3dbe63e833f2eaf613393399ea4667d8de28dAndreas Gustafsson><B
248732d66fffb557e84264c2bb2fb43ac766163fAndreas Gustafsson>dnssec-makekeyset -t 3600 -e +864000 Kchild.example.+003+12345 Kchild.example.+003+23456</B
9bdb01e6c382e897572791b12190472955994d87Mark Andrews></TT
9bdb01e6c382e897572791b12190472955994d87Mark Andrews></P
e69b9ffb0f8b4d1117a682908c9143ebe3efcd6bAndreas Gustafsson><P
e69b9ffb0f8b4d1117a682908c9143ebe3efcd6bAndreas Gustafsson>One output file is produced:
e69b9ffb0f8b4d1117a682908c9143ebe3efcd6bAndreas Gustafsson <TT
417872b98aec720d587a9ef0197e25e78a2b7ee9Mark AndrewsCLASS="filename"
417872b98aec720d587a9ef0197e25e78a2b7ee9Mark Andrews>keyset-child.example.</TT
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas Gustafsson>. This file should be
a77ad145d0109081c5da6ac40a2303369db89735Andreas Gustafsson transmitted to the parent to be signed. It includes the keys,
8ba4e82f5358815fd94f34fde408ffd047ba3430Andreas Gustafsson as well as signatures over the key set generated by the zone
8ba4e82f5358815fd94f34fde408ffd047ba3430Andreas Gustafsson keys themselves, which are used to prove ownership of the
61d5bfc06be978ea962b1c64309894ac80351771Mark Andrews private keys and encode the desired validity period.</P
ada9b8ab20b81716c7ff1f4f3365929b2f7c8ff8Mark Andrews></DIV
ada9b8ab20b81716c7ff1f4f3365929b2f7c8ff8Mark Andrews><DIV
ada9b8ab20b81716c7ff1f4f3365929b2f7c8ff8Mark AndrewsCLASS="sect2"
3c9b2e62502460c34c2e0ceba1a5d138b3a13cc1Andreas Gustafsson><H2
3c9b2e62502460c34c2e0ceba1a5d138b3a13cc1Andreas GustafssonCLASS="sect2"
3c9b2e62502460c34c2e0ceba1a5d138b3a13cc1Andreas Gustafsson><A
1beaa9e45738ad18cb7cae55aea95a1b16a14f94Andreas GustafssonNAME="AEN938"
bb60abb44549428414cd55a022f2b8cc4488f7adAndreas Gustafsson>4.7.3. Signing the Child's Keyset</A
bb60abb44549428414cd55a022f2b8cc4488f7adAndreas Gustafsson></H2
bb60abb44549428414cd55a022f2b8cc4488f7adAndreas Gustafsson><P
bb60abb44549428414cd55a022f2b8cc4488f7adAndreas Gustafsson>The <B
024face21cdfbfc7a862a3be061e6780533ef755Andreas GustafssonCLASS="command"
024face21cdfbfc7a862a3be061e6780533ef755Andreas Gustafsson>dnssec-signkey</B
024face21cdfbfc7a862a3be061e6780533ef755Andreas Gustafsson> program is used to
1beaa9e45738ad18cb7cae55aea95a1b16a14f94Andreas Gustafsson sign one child's keyset.</P
1beaa9e45738ad18cb7cae55aea95a1b16a14f94Andreas Gustafsson><P
1beaa9e45738ad18cb7cae55aea95a1b16a14f94Andreas Gustafsson>If the <TT
f953788d75c7df2db43907c68da18ed75c235dd3Andreas GustafssonCLASS="filename"
f953788d75c7df2db43907c68da18ed75c235dd3Andreas Gustafsson>child.example</TT
f953788d75c7df2db43907c68da18ed75c235dd3Andreas Gustafsson> zone has any
9df7cf8ea31d8d26f9c1be55f2cdafdc68d63c53Andreas Gustafsson delegations which are secure, for example,
cf638fc378d74dd4afa59fe11d04da7b0cddca88Andreas Gustafsson <TT
fbdde79262a4ba2bdf4bfae61167026b3220488aAndreas GustafssonCLASS="filename"
4fa5d53e750b4e34e19b9648900d489315b185eaAndreas Gustafsson>grand.child.example</TT
4fa5d53e750b4e34e19b9648900d489315b185eaAndreas Gustafsson>, the
fbdde79262a4ba2bdf4bfae61167026b3220488aAndreas Gustafsson <TT
fbdde79262a4ba2bdf4bfae61167026b3220488aAndreas GustafssonCLASS="filename"
a7e1dcd84ada7e4e4c78f3f281e8a4d99adaf4d1Andreas Gustafsson>child.example</TT
a7e1dcd84ada7e4e4c78f3f281e8a4d99adaf4d1Andreas Gustafsson> administrator should receive
a7e1dcd84ada7e4e4c78f3f281e8a4d99adaf4d1Andreas Gustafsson keyset files for each secure subzone. These keys must be signed
a7e1dcd84ada7e4e4c78f3f281e8a4d99adaf4d1Andreas Gustafsson by this zone's zone keys.</P
3fc4c1434d7ac377c720640e2e925a3af567cccbMark Andrews><P
2975d0f819762614526c650b9c2077ef22f81328Andreas Gustafsson>The following command signs the child's key set with the
2975d0f819762614526c650b9c2077ef22f81328Andreas Gustafsson zone keys:</P
0aba41458d345ea901cf945d47162e5f23647de9Mark Andrews><P
0bd2ea544e95601e0f0b056acfa079c99d5f6b57Andreas Gustafsson><TT
0bd2ea544e95601e0f0b056acfa079c99d5f6b57Andreas GustafssonCLASS="userinput"
0bd2ea544e95601e0f0b056acfa079c99d5f6b57Andreas Gustafsson><B
5f7516bee5ace9542701f23fc7723a3e3196802aMark Andrews>dnssec-signkey keyset-grand.child.example. Kchild.example.+003+12345 Kchild.example.+003+23456</B
79432444e84d2d104119fe6a3d5cbc04b1375bd4Andreas Gustafsson></TT
79432444e84d2d104119fe6a3d5cbc04b1375bd4Andreas Gustafsson></P
2e24e82fc3551e3228bcacaa7c45cb61daa49195Mark Andrews><P
3c17010ba5a6b8dd8a2bbc550813c7f051f45a08Andreas Gustafsson>One output file is produced:
3c17010ba5a6b8dd8a2bbc550813c7f051f45a08Andreas Gustafsson <TT
3c17010ba5a6b8dd8a2bbc550813c7f051f45a08Andreas GustafssonCLASS="filename"
d5169236b7260d447e672db8256fdd7c70f5ee1dMark Andrews>signedkey-grand.child.example.</TT
df7596a03eea7f1c2df89bd63d3bd4b73f274565Mark Andrews>. This file
df7596a03eea7f1c2df89bd63d3bd4b73f274565Mark Andrews should be both transmitted back to the child and retained. It
df7596a03eea7f1c2df89bd63d3bd4b73f274565Mark Andrews includes all keys (the child's keys) from the keyset file and
df7596a03eea7f1c2df89bd63d3bd4b73f274565Mark Andrews signatures generated by this zone's zone keys.</P
f08782f0923d11227983a352c26301cf703383cfMark Andrews></DIV
f08782f0923d11227983a352c26301cf703383cfMark Andrews><DIV
b923e278535b4e8d264998a85a6ae1eb4b3aa4c6Andreas GustafssonCLASS="sect2"
ed2cefaf0ea367ee408cb7f6a54a413814240fa7Andreas Gustafsson><H2
ed2cefaf0ea367ee408cb7f6a54a413814240fa7Andreas GustafssonCLASS="sect2"
ed2cefaf0ea367ee408cb7f6a54a413814240fa7Andreas Gustafsson><A
ed2cefaf0ea367ee408cb7f6a54a413814240fa7Andreas GustafssonNAME="AEN951"
b923e278535b4e8d264998a85a6ae1eb4b3aa4c6Andreas Gustafsson>4.7.4. Signing the Zone</A
b923e278535b4e8d264998a85a6ae1eb4b3aa4c6Andreas Gustafsson></H2
b923e278535b4e8d264998a85a6ae1eb4b3aa4c6Andreas Gustafsson><P
b923e278535b4e8d264998a85a6ae1eb4b3aa4c6Andreas Gustafsson>The <B
edf97be2b54cbdc4f3f3a46776df3e912892e960Andreas GustafssonCLASS="command"
edf97be2b54cbdc4f3f3a46776df3e912892e960Andreas Gustafsson>dnssec-signzone</B
769ef0b7bdc9520dd62d2f440ea36bc020e88934Andreas Gustafsson> program is used to
9e46f410e716f73abb345be215ccb4c61782b718Andreas Gustafsson sign a zone.</P
9e46f410e716f73abb345be215ccb4c61782b718Andreas Gustafsson><P
9e46f410e716f73abb345be215ccb4c61782b718Andreas Gustafsson>Any <TT
769ef0b7bdc9520dd62d2f440ea36bc020e88934Andreas GustafssonCLASS="filename"
769ef0b7bdc9520dd62d2f440ea36bc020e88934Andreas Gustafsson>signedkey</TT
b09f4e054cbe67b93a5ff62d511ee25945038943Mark Andrews> files corresponding to
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas Gustafsson secure subzones should be present, as well as a
b09f4e054cbe67b93a5ff62d511ee25945038943Mark Andrews <TT
3d3445447225ab63f49fc24362963ea49ce94901Andreas GustafssonCLASS="filename"
3d3445447225ab63f49fc24362963ea49ce94901Andreas Gustafsson>signedkey</TT
3d3445447225ab63f49fc24362963ea49ce94901Andreas Gustafsson> file for this zone generated by
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews the parent (if there is one). The zone signer will generate
96ea98af241ef00395f4e61de7e2dacfd9941afcMark Andrews <TT
96ea98af241ef00395f4e61de7e2dacfd9941afcMark AndrewsCLASS="literal"
3dff229f5dd223568476acec4df1f513acb00b1dAndreas Gustafsson>NXT</TT
3dff229f5dd223568476acec4df1f513acb00b1dAndreas Gustafsson> and <TT
54c4aa0f62aebeb01b6861ee068c1044433fe8feMark AndrewsCLASS="literal"
792de65053d8a48d05746b35a21a9fa1792e71acAndreas Gustafsson>SIG</TT
792de65053d8a48d05746b35a21a9fa1792e71acAndreas Gustafsson> records for
792de65053d8a48d05746b35a21a9fa1792e71acAndreas Gustafsson the zone, as well as incorporate the zone key signature from the
808b909f27c30d36b27efb5aa5ef2d18f83b6d4bAndreas Gustafsson parent and indicate the security status at all delegation
846474d5a6aa21cebb3e94243a11faa5c20200bfAndreas Gustafsson points.</P
3e934267660cb13029bcdbddf318fe1cc27b6718Andreas Gustafsson><P
3e934267660cb13029bcdbddf318fe1cc27b6718Andreas Gustafsson>The following command signs the zone, assuming it is in a
846474d5a6aa21cebb3e94243a11faa5c20200bfAndreas Gustafsson file called <TT
7655e78c366cc0d25e24e2a96ba58e04a96042faAndreas GustafssonCLASS="filename"
7655e78c366cc0d25e24e2a96ba58e04a96042faAndreas Gustafsson>zone.child.example</TT
7655e78c366cc0d25e24e2a96ba58e04a96042faAndreas Gustafsson>. By
6859033d425170380bcfac4809257bc6e9b60383Andreas Gustafsson default, all zone keys which have an available private key are
6859033d425170380bcfac4809257bc6e9b60383Andreas Gustafsson used to generate signatures.</P
6859033d425170380bcfac4809257bc6e9b60383Andreas Gustafsson><P
f558da602e8b74ed181d9189f20bf32dfa6d8723Brian Wellington><TT
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas GustafssonCLASS="userinput"
f558da602e8b74ed181d9189f20bf32dfa6d8723Brian Wellington><B
ff4322d44f8404683b6fb6c86a38a2bc14f6c083Andreas Gustafsson>dnssec-signzone -o child.example zone.child.example</B
ff4322d44f8404683b6fb6c86a38a2bc14f6c083Andreas Gustafsson></TT
ff4322d44f8404683b6fb6c86a38a2bc14f6c083Andreas Gustafsson></P
8d146b6e1156f5b562af9a4a9aba76b09650412cAndreas Gustafsson><P
8d146b6e1156f5b562af9a4a9aba76b09650412cAndreas Gustafsson>One output file is produced:
8d146b6e1156f5b562af9a4a9aba76b09650412cAndreas Gustafsson <TT
8d146b6e1156f5b562af9a4a9aba76b09650412cAndreas GustafssonCLASS="filename"
808b909f27c30d36b27efb5aa5ef2d18f83b6d4bAndreas Gustafsson>zone.child.example.signed</TT
808b909f27c30d36b27efb5aa5ef2d18f83b6d4bAndreas Gustafsson>. This file
808b909f27c30d36b27efb5aa5ef2d18f83b6d4bAndreas Gustafsson should be referenced by <TT
595a14576ea14884c35b3726f054f2065365620bMark AndrewsCLASS="filename"
595a14576ea14884c35b3726f054f2065365620bMark Andrews>named.conf</TT
595a14576ea14884c35b3726f054f2065365620bMark Andrews> as the
640923da589bc5b8492ac407ef89ea1ee9a1c358Andreas Gustafsson input file for the zone.</P
d9e690eb71bde3c748208733ba40a34e9d0ba29dAndreas Gustafsson></DIV
d9e690eb71bde3c748208733ba40a34e9d0ba29dAndreas Gustafsson><DIV
1299e93989afbe1fee0739811b05fd1641ea14aeAndreas GustafssonCLASS="sect2"
1299e93989afbe1fee0739811b05fd1641ea14aeAndreas Gustafsson><H2
640923da589bc5b8492ac407ef89ea1ee9a1c358Andreas GustafssonCLASS="sect2"
640923da589bc5b8492ac407ef89ea1ee9a1c358Andreas Gustafsson><A
640923da589bc5b8492ac407ef89ea1ee9a1c358Andreas GustafssonNAME="AEN967"
640923da589bc5b8492ac407ef89ea1ee9a1c358Andreas Gustafsson>4.7.5. Configuring Servers</A
1299e93989afbe1fee0739811b05fd1641ea14aeAndreas Gustafsson></H2
0bd1b2fbfed4aa489e9d5fcbc7f48acb96ba7248Mark Andrews><P
aa30ee42c4b6da9bab4fb84d6cbbda6036a4d426Mark Andrews>Unlike in <SPAN
aa30ee42c4b6da9bab4fb84d6cbbda6036a4d426Mark AndrewsCLASS="acronym"
aa30ee42c4b6da9bab4fb84d6cbbda6036a4d426Mark Andrews>BIND</SPAN
1de63e34f163b7a4708a6ad1779f93ae7636b92eAndreas Gustafsson> 8,
01446841be2b73f9a2ead74056df2d5342414041Andreas Gustafssondata is not verified on load in <SPAN
01446841be2b73f9a2ead74056df2d5342414041Andreas GustafssonCLASS="acronym"
01446841be2b73f9a2ead74056df2d5342414041Andreas Gustafsson>BIND</SPAN
01446841be2b73f9a2ead74056df2d5342414041Andreas Gustafsson> 9,
28cf7340b9c82fc62ca1a1782cb1bd7b0de11aebAndreas Gustafssonso zone keys for authoritative zones do not need to be specified
28cf7340b9c82fc62ca1a1782cb1bd7b0de11aebAndreas Gustafssonin the configuration file.</P
28cf7340b9c82fc62ca1a1782cb1bd7b0de11aebAndreas Gustafsson><P
1de63e34f163b7a4708a6ad1779f93ae7636b92eAndreas Gustafsson>The public key for any security root must be present in
1de63e34f163b7a4708a6ad1779f93ae7636b92eAndreas Gustafssonthe configuration file's <B
feb1f6a4ac42988558ecb8dc5dc0c974ec1f0509Brian WellingtonCLASS="command"
feb1f6a4ac42988558ecb8dc5dc0c974ec1f0509Brian Wellington>trusted-keys</B
ea34bcc6376555296a08e4c9e2f9c2cbe58378a9Andreas Gustafsson>
ea34bcc6376555296a08e4c9e2f9c2cbe58378a9Andreas Gustafssonstatement, as described later in this document. </P
d1a6976967d6cfd93f5a8d80878215691ac8fe74Mark Andrews></DIV
5e4c83cfec3f267ea8f22fbb535c61434c94d43cDanny Mayer></DIV
06f12c290c7904f0723094b5cbd11e2a1d49e95eAndreas Gustafsson><DIV
06f12c290c7904f0723094b5cbd11e2a1d49e95eAndreas GustafssonCLASS="sect1"
5e4c83cfec3f267ea8f22fbb535c61434c94d43cDanny Mayer><H1
6e1b2ebcd65c6d0cc90d7789f884aea11184eb5dAndreas GustafssonCLASS="sect1"
1299e93989afbe1fee0739811b05fd1641ea14aeAndreas Gustafsson><A
e6f17474cb43a138bf7fc9ad30c6b3a2847cb7a7Mark AndrewsNAME="AEN974"
5fe21da364d4397c9a413fe689ce82dea36a7b29Mark Andrews>4.8. IPv6 Support in <SPAN
5fe21da364d4397c9a413fe689ce82dea36a7b29Mark AndrewsCLASS="acronym"
5fe21da364d4397c9a413fe689ce82dea36a7b29Mark Andrews>BIND</SPAN
a5aca6df165c601d755b8c5f5727048078bf0db5Andreas Gustafsson> 9</A
43efd9fa56b03e3e285fb58859efc9348c7f4a9fMark Andrews></H1
43efd9fa56b03e3e285fb58859efc9348c7f4a9fMark Andrews><P
43efd9fa56b03e3e285fb58859efc9348c7f4a9fMark Andrews><SPAN
5c831a1a1b14470037de6d8bc0501aea5dc6cacdAndreas GustafssonCLASS="acronym"
36e37042c6c9252cdf6eb99bd71ccb6e6c43ba6dBrian Wellington>BIND</SPAN
98e231525fda817d393ef0c529b50bfc08cebe47Mark Andrews> 9 fully supports all currently defined forms of IPv6
98e231525fda817d393ef0c529b50bfc08cebe47Mark Andrews name to address and address to name lookups. It will also use
98e231525fda817d393ef0c529b50bfc08cebe47Mark Andrews IPv6 addresses to make queries when running on an IPv6 capable
d4196128b31d511c8513edacc70dea7e8d0c053aMark Andrews system.</P
d4196128b31d511c8513edacc70dea7e8d0c053aMark Andrews><P
d4196128b31d511c8513edacc70dea7e8d0c053aMark Andrews>For forward lookups, <SPAN
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas GustafssonCLASS="acronym"
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas Gustafsson>BIND</SPAN
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas Gustafsson> 9 supports both A6 and AAAA
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas Gustafsson records. The use of AAAA records is deprecated, but it is still
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas Gustafsson useful for hosts to have both AAAA and A6 records to maintain
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas Gustafsson backward compatibility with installations where AAAA records are
56d69016f4fae2eda4d39c92fe13595251aaadd3Mark Andrews still used. In fact, the stub resolvers currently shipped with
e60b3717f0e6f28d6fb2c5124ffb3bd31cc3a746Mark Andrews most operating system support only AAAA lookups, because following
e60b3717f0e6f28d6fb2c5124ffb3bd31cc3a746Mark Andrews A6 chains is much harder than doing A or AAAA lookups.</P
0262406cea5802a717539247cbaa596ac808efa9Mark Andrews><P
3d8ab44d14f3de797b8454fc2edb7421a6bfc874Andreas Gustafsson>For IPv6 reverse lookups, <SPAN
3d8ab44d14f3de797b8454fc2edb7421a6bfc874Andreas GustafssonCLASS="acronym"
3d8ab44d14f3de797b8454fc2edb7421a6bfc874Andreas Gustafsson>BIND</SPAN
3426f7118c92cab8714a7fddc9e721ff09554447Andreas Gustafsson> 9 supports the new
db235e65884c04058cc6e99ca485170d67cf9538Andreas Gustafsson "bitstring" format used in the <I
db235e65884c04058cc6e99ca485170d67cf9538Andreas GustafssonCLASS="emphasis"
3426f7118c92cab8714a7fddc9e721ff09554447Andreas Gustafsson>ip6.arpa</I
3426f7118c92cab8714a7fddc9e721ff09554447Andreas Gustafsson>
64a5004a66accd190bfd5ddf115667726537be50Andreas Gustafsson domain, as well as the older, deprecated "nibble" format used in
64a5004a66accd190bfd5ddf115667726537be50Andreas Gustafsson the <I
64a5004a66accd190bfd5ddf115667726537be50Andreas GustafssonCLASS="emphasis"
64a5004a66accd190bfd5ddf115667726537be50Andreas Gustafsson>ip6.int</I
64a5004a66accd190bfd5ddf115667726537be50Andreas Gustafsson> domain.</P
b1ae7a591a4b99a26036e919b87247b65abfcd77Mark Andrews><P
b1ae7a591a4b99a26036e919b87247b65abfcd77Mark Andrews><SPAN
b1ae7a591a4b99a26036e919b87247b65abfcd77Mark AndrewsCLASS="acronym"
b1ae7a591a4b99a26036e919b87247b65abfcd77Mark Andrews>BIND</SPAN
6dbc6fae496db1f584c055e63bcd7afd332fe8f6Andreas Gustafsson> 9 includes a new lightweight resolver library and
cab0ee644db604d56b45ec39429d505d635da347Andreas Gustafsson resolver daemon which new applications may choose to use to avoid
cab0ee644db604d56b45ec39429d505d635da347Andreas Gustafsson the complexities of A6 chain following and bitstring labels, see <A
cab0ee644db604d56b45ec39429d505d635da347Andreas GustafssonHREF="Bv9ARM.ch05.html"
cab0ee644db604d56b45ec39429d505d635da347Andreas Gustafsson>Chapter 5</A
7780a3e5a4659bb8fc44f8915d20a8d3ffa33e00Andreas Gustafsson>.</P
7780a3e5a4659bb8fc44f8915d20a8d3ffa33e00Andreas Gustafsson><P
7780a3e5a4659bb8fc44f8915d20a8d3ffa33e00Andreas Gustafsson>For an overview of the format and structure of IPv6 addresses,
6dbc6fae496db1f584c055e63bcd7afd332fe8f6Andreas Gustafsson see <A
6dbc6fae496db1f584c055e63bcd7afd332fe8f6Andreas GustafssonHREF="Bv9ARM.ch09.html#ipv6addresses"
6dbc6fae496db1f584c055e63bcd7afd332fe8f6Andreas Gustafsson>Section A.3.1</A
6dbc6fae496db1f584c055e63bcd7afd332fe8f6Andreas Gustafsson>.</P
6dbc6fae496db1f584c055e63bcd7afd332fe8f6Andreas Gustafsson><DIV
a24d253a3f4e6f4036800744b348fba858d4959eMark AndrewsCLASS="sect2"
a24d253a3f4e6f4036800744b348fba858d4959eMark Andrews><H2
847169dab2d0496df1d66842b2cce67c66bf9680Andreas GustafssonCLASS="sect2"
3f543c371fff724d1fb05eb564f732476e946b5bBrian Wellington><A
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas GustafssonNAME="AEN990"
3f543c371fff724d1fb05eb564f732476e946b5bBrian Wellington>4.8.1. Address Lookups Using AAAA Records</A
847169dab2d0496df1d66842b2cce67c66bf9680Andreas Gustafsson></H2
847169dab2d0496df1d66842b2cce67c66bf9680Andreas Gustafsson><P
847169dab2d0496df1d66842b2cce67c66bf9680Andreas Gustafsson>The AAAA record is a parallel to the IPv4 A record. It
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews specifies the entire address in a single record. For
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews example,</P
ed03e26c44347ec20aff6608de6082e3594d95fbMark Andrews><PRE
ed03e26c44347ec20aff6608de6082e3594d95fbMark AndrewsCLASS="programlisting"
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews>&#13;$ORIGIN example.com.
e8d86192fc424f49e43df9cee439ca5c793e6000Mark Andrewshost 3600 IN AAAA 3ffe:8050:201:1860:42::1
e8d86192fc424f49e43df9cee439ca5c793e6000Mark Andrews</PRE
e8d86192fc424f49e43df9cee439ca5c793e6000Mark Andrews><P
bae5d9fcb4616005fbc861e327b0a48b7bd4d89aMark Andrews>While their use is deprecated, they are useful to support
bae5d9fcb4616005fbc861e327b0a48b7bd4d89aMark Andrews older IPv6 applications. They should not be added where they
e8d86192fc424f49e43df9cee439ca5c793e6000Mark Andrews are not absolutely necessary.</P
1299e93989afbe1fee0739811b05fd1641ea14aeAndreas Gustafsson></DIV
98a5dc52bf668b093cda7901c057f7b54e18a2fcAndreas Gustafsson><DIV
98a5dc52bf668b093cda7901c057f7b54e18a2fcAndreas GustafssonCLASS="sect2"
98a5dc52bf668b093cda7901c057f7b54e18a2fcAndreas Gustafsson><H2
98a5dc52bf668b093cda7901c057f7b54e18a2fcAndreas GustafssonCLASS="sect2"
5af0708e7fd78976a33de70f9380785f4086a1f0Andreas Gustafsson><A
98a5dc52bf668b093cda7901c057f7b54e18a2fcAndreas GustafssonNAME="AEN995"
98a5dc52bf668b093cda7901c057f7b54e18a2fcAndreas Gustafsson>4.8.2. Address Lookups Using A6 Records</A
452b30ddb32dd9370b2e5ee10427dd3758ef98b4Mark Andrews></H2
452b30ddb32dd9370b2e5ee10427dd3758ef98b4Mark Andrews><P
452b30ddb32dd9370b2e5ee10427dd3758ef98b4Mark Andrews>The A6 record is more flexible than the AAAA record, and
452b30ddb32dd9370b2e5ee10427dd3758ef98b4Mark Andrews is therefore more complicated. The A6 record can be used to
6668eca26bf3123750afda48b69991bd29d83807Mark Andrews form a chain of A6 records, each specifying part of the IPv6
1299e93989afbe1fee0739811b05fd1641ea14aeAndreas Gustafsson address. It can also be used to specify the entire record as
6668eca26bf3123750afda48b69991bd29d83807Mark Andrews well. For example, this record supplies the same data as the
773e64ec150c33269e748d96dd95726ed7e0d842Mark Andrews AAAA record in the previous example:</P
06a960c681566a163af5b9a655cf36023075ddcbMark Andrews><PRE
cb8fd52bbeaf40c9166a0144541c4ff2bafc2dd6Andreas GustafssonCLASS="programlisting"
1eaad22e111709254c70953a4dc768b6d4d31646Mark Andrews>&#13;$ORIGIN example.com.
cad3210bb95057a37aaed20bc8a1542e0534422cAndreas Gustafssonhost 3600 IN A6 0 3ffe:8050:201:1860:42::1
cad3210bb95057a37aaed20bc8a1542e0534422cAndreas Gustafsson</PRE
cad3210bb95057a37aaed20bc8a1542e0534422cAndreas Gustafsson><DIV
cad3210bb95057a37aaed20bc8a1542e0534422cAndreas GustafssonCLASS="sect3"
cad3210bb95057a37aaed20bc8a1542e0534422cAndreas Gustafsson><H3
cad3210bb95057a37aaed20bc8a1542e0534422cAndreas GustafssonCLASS="sect3"
cad3210bb95057a37aaed20bc8a1542e0534422cAndreas Gustafsson><A
afeded2289de8d193b072da2b44a2d580cc235c1Danny MayerNAME="AEN999"
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer>4.8.2.1. A6 Chains</A
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer></H3
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer><P
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer>A6 records are designed to allow network
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer renumbering. This works when an A6 record only specifies the
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer part of the address space the domain owner controls. For
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer example, a host may be at a company named "company." It has
f462b9aed23b77bda867301f80ead6990df6f4f8Andreas Gustafsson two ISPs which provide IPv6 address space for it. These two
89555ff443c8127a533f6c742316c9b1a713cfd5Mark Andrews ISPs fully specify the IPv6 prefix they supply.</P
aa9a67adeb48069f5c2e5d8936a8ed5aac7d6ad7Andreas Gustafsson><P
aa9a67adeb48069f5c2e5d8936a8ed5aac7d6ad7Andreas Gustafsson>In the company's address space:</P
aa9a67adeb48069f5c2e5d8936a8ed5aac7d6ad7Andreas Gustafsson><PRE
aa9a67adeb48069f5c2e5d8936a8ed5aac7d6ad7Andreas GustafssonCLASS="programlisting"
aa9a67adeb48069f5c2e5d8936a8ed5aac7d6ad7Andreas Gustafsson>&#13;$ORIGIN example.com.
aa9a67adeb48069f5c2e5d8936a8ed5aac7d6ad7Andreas Gustafssonhost 3600 IN A6 64 0:0:0:0:42::1 company.example1.net.
73ac1894ea64bc50aff7406872d0e9c5df6d9cf6Mark Andrewshost 3600 IN A6 64 0:0:0:0:42::1 company.example2.net.
539cad8f49b38540b7c20c64d1ef456cb2fa7914Andreas Gustafsson</PRE
330b421487d7c3a5e699472fe889aa633772057fMark Andrews><P
e22dca2a9ad30d493a869586abed86f7268204f9Mark Andrews>ISP1 will use:</P
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas Gustafsson><PRE
e22dca2a9ad30d493a869586abed86f7268204f9Mark AndrewsCLASS="programlisting"
2c0b26955ee32fcee1757ec1be5a8caf8fe695a6Mark Andrews>&#13;$ORIGIN example1.net.
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas Gustafssoncompany 3600 IN A6 0 3ffe:8050:201:1860::
2c0b26955ee32fcee1757ec1be5a8caf8fe695a6Mark Andrews</PRE
2449f41e75d3b3f1c0ec3f05b1603fd8f80d8ae0Mark Andrews><P
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas Gustafsson>ISP2 will use:</P
2449f41e75d3b3f1c0ec3f05b1603fd8f80d8ae0Mark Andrews><PRE
ea72586fc5c360539117119ee35e4c3a04b912bcAndreas GustafssonCLASS="programlisting"
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas Gustafsson>&#13;$ORIGIN example2.net.
6f7660093e70d3a7c80738b681ac0f5c1b661c00Mark Andrewscompany 3600 IN A6 0 1234:5678:90ab:fffa::
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas Gustafsson</PRE
1fdbadc594a49b423052ea342dac74ff1a36089dMark Andrews><P
a1898260ad19d02e88ab76c1855d33c67add9defMark Andrews>When <TT
a1898260ad19d02e88ab76c1855d33c67add9defMark AndrewsCLASS="literal"
a1898260ad19d02e88ab76c1855d33c67add9defMark Andrews>host.example.com</TT
305b0eda33b16493355db1f1c86313a6f5fbfc3bDanny Mayer> is looked up,
305b0eda33b16493355db1f1c86313a6f5fbfc3bDanny Mayer the resolver (in the resolver daemon or caching name server)
305b0eda33b16493355db1f1c86313a6f5fbfc3bDanny Mayer will find two partial A6 records, and will use the additional
305b0eda33b16493355db1f1c86313a6f5fbfc3bDanny Mayer name to find the remainder of the data.</P
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson></DIV
d16b4e8ba885a45933dc6a46f340b76811d60c74Andreas Gustafsson><DIV
d16b4e8ba885a45933dc6a46f340b76811d60c74Andreas GustafssonCLASS="sect3"
de9833be77ef92c17b35c02d138a0ad8df34dd91Mark Andrews><H3
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas GustafssonCLASS="sect3"
de9833be77ef92c17b35c02d138a0ad8df34dd91Mark Andrews><A
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas GustafssonNAME="AEN1010"
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson>4.8.2.2. A6 Records for DNS Servers</A
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas Gustafsson></H3
4e400cb7a2edd25af98ebc25fcbb5b36ca08f9a0Mark Andrews><P
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson>When an A6 record specifies the address of a name
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson server, it should use the full address rather than specifying
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson a partial address. For example:</P
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson><PRE
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas GustafssonCLASS="programlisting"
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas Gustafsson>&#13;$ORIGIN example.com.
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson@ 14400 IN NS ns0
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson 14400 IN NS ns1
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafssonns0 14400 IN A6 0 3ffe:8050:201:1860:42::1
ec5a06ccf7b15f07d20fd872c3dc1ab8f82f2ceaMark Andrewsns1 14400 IN A 192.168.42.1
907ec2c618d08d8322b04729779b24bd778d49e7Mark Andrews</PRE
907ec2c618d08d8322b04729779b24bd778d49e7Mark Andrews><P
907ec2c618d08d8322b04729779b24bd778d49e7Mark Andrews>It is recommended that IPv4-in-IPv6 mapped addresses not
23a020bc1312fc35e7c4ea36df846c550cb13634Andreas Gustafsson be used. If a host has an IPv4 address, use an A record, not
0a532842050020a1b0577c65f91f38bd022daa78Andreas Gustafsson an A6, with <TT
0a532842050020a1b0577c65f91f38bd022daa78Andreas GustafssonCLASS="literal"
0a532842050020a1b0577c65f91f38bd022daa78Andreas Gustafsson>::ffff:192.168.42.1</TT
0a532842050020a1b0577c65f91f38bd022daa78Andreas Gustafsson> as the
23a020bc1312fc35e7c4ea36df846c550cb13634Andreas Gustafsson address.</P
23a020bc1312fc35e7c4ea36df846c550cb13634Andreas Gustafsson></DIV
23a020bc1312fc35e7c4ea36df846c550cb13634Andreas Gustafsson></DIV
44c141f9471a6bb1fac0cba7880ba768ede2f0c8Brian Wellington><DIV
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas GustafssonCLASS="sect2"
ab3eaa20e9a7e56208408563c79b4f8ac01d5e84Andreas Gustafsson><H2
e1a153c3f095e217eea29958950fea36e54862ceAndreas GustafssonCLASS="sect2"
e1a153c3f095e217eea29958950fea36e54862ceAndreas Gustafsson><A
7250c1a2616761395bdb9ae7cd1ba43f20d3edc4Andreas GustafssonNAME="AEN1016"
7250c1a2616761395bdb9ae7cd1ba43f20d3edc4Andreas Gustafsson>4.8.3. Address to Name Lookups Using Nibble Format</A
7250c1a2616761395bdb9ae7cd1ba43f20d3edc4Andreas Gustafsson></H2
ab3eaa20e9a7e56208408563c79b4f8ac01d5e84Andreas Gustafsson><P
c38b92000c0f1a95daaad5468777e165b8047de9Mark Andrews>While the use of nibble format to look up names is
4d77dbcfa052c065a87d2d35b116f17b74bae573Andreas Gustafsson deprecated, it is supported for backwards compatiblity with
c38b92000c0f1a95daaad5468777e165b8047de9Mark Andrews existing IPv6 applications.</P
c38b92000c0f1a95daaad5468777e165b8047de9Mark Andrews><P
c38b92000c0f1a95daaad5468777e165b8047de9Mark Andrews>When looking up an address in nibble format, the address
a5b9c2b208b51b039c8f4006cddf3d37dd781561Brian Wellington components are simply reversed, just as in IPv4, and
22f0b13f28a7df3b348b18848d0ccd745ea88c3cAndreas Gustafsson <TT
22f0b13f28a7df3b348b18848d0ccd745ea88c3cAndreas GustafssonCLASS="literal"
22f0b13f28a7df3b348b18848d0ccd745ea88c3cAndreas Gustafsson>ip6.int.</TT
22f0b13f28a7df3b348b18848d0ccd745ea88c3cAndreas Gustafsson> is appended to the resulting name.
ee3ab6063dd13b5947d3fbe88b9ce8f38d65df9dBrian Wellington For example, the following would provide reverse name lookup for
9261ca5fc8a564968f34e108eb862157471ca50eAndreas Gustafsson a host with address
ee3ab6063dd13b5947d3fbe88b9ce8f38d65df9dBrian Wellington <TT
d81622b537be1971530cfb459acdbbe7d82d883bBrian WellingtonCLASS="literal"
d81622b537be1971530cfb459acdbbe7d82d883bBrian Wellington>3ffe:8050:201:1860:42::1</TT
a5b9c2b208b51b039c8f4006cddf3d37dd781561Brian Wellington>.</P
9261ca5fc8a564968f34e108eb862157471ca50eAndreas Gustafsson><PRE
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas GustafssonCLASS="programlisting"
a5b9c2b208b51b039c8f4006cddf3d37dd781561Brian Wellington>&#13;$ORIGIN 0.6.8.1.1.0.2.0.0.5.0.8.e.f.f.3.ip6.int.
2da0b7dfbd02fab454b8ba60f1fdb7e2a5cbd2dbMark Andrews1.0.0.0.0.0.0.0.0.0.0.0.2.4.0.0 14400 IN PTR host.example.com.
2da0b7dfbd02fab454b8ba60f1fdb7e2a5cbd2dbMark Andrews</PRE
2da0b7dfbd02fab454b8ba60f1fdb7e2a5cbd2dbMark Andrews></DIV
1cb6e8cbe41afade950837319e04da4ccf8649e0Brian Wellington><DIV
9261ca5fc8a564968f34e108eb862157471ca50eAndreas GustafssonCLASS="sect2"
1cb6e8cbe41afade950837319e04da4ccf8649e0Brian Wellington><H2
2033e305852d4b76772885ea73ebfb6776c1f820Mark AndrewsCLASS="sect2"
6443201354efa09f16ada26dab99e9b7f8271521Andreas Gustafsson><A
6443201354efa09f16ada26dab99e9b7f8271521Andreas GustafssonNAME="AEN1023"
6443201354efa09f16ada26dab99e9b7f8271521Andreas Gustafsson>4.8.4. Address to Name Lookups Using Bitstring Format</A
e980502db40155234b4e8d320b748b34dbaba3a2Brian Wellington></H2
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas Gustafsson><P
e980502db40155234b4e8d320b748b34dbaba3a2Brian Wellington>Bitstring labels can start and end on any bit boundary,
e980502db40155234b4e8d320b748b34dbaba3a2Brian Wellington rather than on a multiple of 4 bits as in the nibble
ecd1addb86319bacc6c0bff2c68373619eebbffcMark Andrews format. They also use <I
ecd1addb86319bacc6c0bff2c68373619eebbffcMark AndrewsCLASS="emphasis"
0176adc7c58bb8bd60ec71eeae94dbfbbc4018a8Mark Andrews>ip6.arpa</I
0176adc7c58bb8bd60ec71eeae94dbfbbc4018a8Mark Andrews> rather than
ea20115e347264b9bc1c686d6dfc1b5af3a5516bAndreas Gustafsson <I
ea20115e347264b9bc1c686d6dfc1b5af3a5516bAndreas GustafssonCLASS="emphasis"
ea20115e347264b9bc1c686d6dfc1b5af3a5516bAndreas Gustafsson>ip6.int</I
bddfe77128b0f16af263ff149db40f0d885f43d0Mark Andrews>.</P
bddfe77128b0f16af263ff149db40f0d885f43d0Mark Andrews><P
aa0dc8d920a1f79626c3564408db9c5c9a5319a7Andreas Gustafsson>To replicate the previous example using bitstrings:</P
aa0dc8d920a1f79626c3564408db9c5c9a5319a7Andreas Gustafsson><PRE
aa0dc8d920a1f79626c3564408db9c5c9a5319a7Andreas GustafssonCLASS="programlisting"
aa0dc8d920a1f79626c3564408db9c5c9a5319a7Andreas Gustafsson>&#13;$ORIGIN \[x3ffe805002011860/64].ip6.arpa.
47d48791fc352fcdf9019200070221be41a8d77cMark Andrews\[x0042000000000001/64] 14400 IN PTR host.example.com.
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas Gustafsson</PRE
35db8a8eda6a889675138eb125d366c8851f68a5Andreas Gustafsson></DIV
0d5e7cd0afaee07302f8364aa454f09b4c63ea79Andreas Gustafsson><DIV
0d5e7cd0afaee07302f8364aa454f09b4c63ea79Andreas GustafssonCLASS="sect2"
5e88852b94830bf71e37dc700d568cb35e2e6f7eAndreas Gustafsson><H2
5e88852b94830bf71e37dc700d568cb35e2e6f7eAndreas GustafssonCLASS="sect2"
5e88852b94830bf71e37dc700d568cb35e2e6f7eAndreas Gustafsson><A
5e88852b94830bf71e37dc700d568cb35e2e6f7eAndreas GustafssonNAME="AEN1030"
22815444822da17fab82d4ab115da6e055ea1754Brian Wellington>4.8.5. Using DNAME for Delegation of IPv6 Reverse Addresses</A
5e88852b94830bf71e37dc700d568cb35e2e6f7eAndreas Gustafsson></H2
22815444822da17fab82d4ab115da6e055ea1754Brian Wellington><P
22815444822da17fab82d4ab115da6e055ea1754Brian Wellington>In IPV6, the same host may have many addresses from many
35db8a8eda6a889675138eb125d366c8851f68a5Andreas Gustafsson network providers. Since the trailing portion of the address
35db8a8eda6a889675138eb125d366c8851f68a5Andreas Gustafsson usually remains constant, <B
35db8a8eda6a889675138eb125d366c8851f68a5Andreas GustafssonCLASS="command"
c6de6524d777c90ae8011af8b10f5cac044081e5Mark Andrews>DNAME</B
bd6504aa9aa16a912412fbe010046aaf4bf23621Brian Wellington> can help
bd6504aa9aa16a912412fbe010046aaf4bf23621Brian Wellington reduce the number of zone files used for reverse mapping that
5e88852b94830bf71e37dc700d568cb35e2e6f7eAndreas Gustafsson need to be maintained.</P
bd6504aa9aa16a912412fbe010046aaf4bf23621Brian Wellington><P
bd6504aa9aa16a912412fbe010046aaf4bf23621Brian Wellington>For example, consider a host which has two providers
bd6504aa9aa16a912412fbe010046aaf4bf23621Brian Wellington (<TT
bd6504aa9aa16a912412fbe010046aaf4bf23621Brian WellingtonCLASS="literal"
e9596e1fb3dfa560216776acdbfac3cf5ef97157Mark Andrews>example.net</TT
e9596e1fb3dfa560216776acdbfac3cf5ef97157Mark Andrews> and
1e289d3cca5cdd01dda650fa6e4c1de1aa8b4196Andreas Gustafsson <TT
c54210716ee55b55e22d8dad56fd696a641fc98dBob HalleyCLASS="literal"
c54210716ee55b55e22d8dad56fd696a641fc98dBob Halley>example2.net</TT
c54210716ee55b55e22d8dad56fd696a641fc98dBob Halley>) and
c54210716ee55b55e22d8dad56fd696a641fc98dBob Halley therefore two IPv6 addresses. Since the host chooses its own 64
3fcf6b956f47405750724bd84e1b2290b61c9186Brian Wellington bit host address portion, the provider address is the only part
82c65f4f62819340ef8198932d3eab8a308a4874Andreas Gustafsson that changes:</P
3fcf6b956f47405750724bd84e1b2290b61c9186Brian Wellington><PRE
1e289d3cca5cdd01dda650fa6e4c1de1aa8b4196Andreas GustafssonCLASS="programlisting"
1e289d3cca5cdd01dda650fa6e4c1de1aa8b4196Andreas Gustafsson>&#13;$ORIGIN example.com.
0a2d5c990559ce2b9f95df752db6e93024d9a250Brian Wellingtonhost IN A6 64 ::1234:5678:1212:5675 cust1.example.net.
96ed62425310854fd6f6f06bfb7651b3e4c17ee7Andreas Gustafsson IN A6 64 ::1234:5678:1212:5675 subnet5.example2.net.
96ed62425310854fd6f6f06bfb7651b3e4c17ee7Andreas Gustafsson$ORIGIN example.net.
96ed62425310854fd6f6f06bfb7651b3e4c17ee7Andreas Gustafssoncust1 IN A6 48 0:0:0:dddd:: ipv6net.example.net.
96ed62425310854fd6f6f06bfb7651b3e4c17ee7Andreas Gustafssonipv6net IN A6 0 aa:bb:cccc::
96ed62425310854fd6f6f06bfb7651b3e4c17ee7Andreas Gustafsson$ORIGIN example2.net.
96ed62425310854fd6f6f06bfb7651b3e4c17ee7Andreas Gustafssonsubnet5 IN A6 48 0:0:0:1:: ipv6net2.example2.net.
5733d25b06b46067b3751d10436d82aef09cd705Brian Wellingtonipv6net2 IN A6 0 6666:5555:4::
82c65f4f62819340ef8198932d3eab8a308a4874Andreas Gustafsson</PRE
5733d25b06b46067b3751d10436d82aef09cd705Brian Wellington><P
5733d25b06b46067b3751d10436d82aef09cd705Brian Wellington>This sets up forward lookups. To handle the reverse lookups,
82c65f4f62819340ef8198932d3eab8a308a4874Andreas Gustafssonthe provider <TT
5733d25b06b46067b3751d10436d82aef09cd705Brian WellingtonCLASS="literal"
debff476ad3512687a354499c25d2793e2009acdBrian Wellington>example.net</TT
debff476ad3512687a354499c25d2793e2009acdBrian Wellington>
eb6e3b04169a766d2b968bcc978191605c2ef24cAndreas Gustafssonwould have:</P
eb6e3b04169a766d2b968bcc978191605c2ef24cAndreas Gustafsson><PRE
eb6e3b04169a766d2b968bcc978191605c2ef24cAndreas GustafssonCLASS="programlisting"
eb6e3b04169a766d2b968bcc978191605c2ef24cAndreas Gustafsson>&#13;$ORIGIN \[x00aa00bbcccc/48].ip6.arpa.
eb6e3b04169a766d2b968bcc978191605c2ef24cAndreas Gustafsson\[xdddd/16] IN DNAME ipv6-rev.example.com.
eb6e3b04169a766d2b968bcc978191605c2ef24cAndreas Gustafsson</PRE
7d8c3693d0426b56750b14d80c47df5e42fc75e4Andreas Gustafsson><P
fed846067d265db1037483d81d01f3651c8a3f28Brian Wellington>and <TT
82c65f4f62819340ef8198932d3eab8a308a4874Andreas GustafssonCLASS="literal"
fed846067d265db1037483d81d01f3651c8a3f28Brian Wellington>example2.net</TT
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson> would have:</P
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson><PRE
a26ad011f382d12058478704cb5e90e6f4366d01Andreas GustafssonCLASS="programlisting"
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson>&#13;$ORIGIN \[x666655550004/48].ip6.arpa.
57188b5ff2397c0517e55f622879e69ee547918dAndreas Gustafsson\[x0001/16] IN DNAME ipv6-rev.example.com.
7d8c3693d0426b56750b14d80c47df5e42fc75e4Andreas Gustafsson</PRE
7d8c3693d0426b56750b14d80c47df5e42fc75e4Andreas Gustafsson><P
7d8c3693d0426b56750b14d80c47df5e42fc75e4Andreas Gustafsson><TT
9a72459b6040b30d043c5fd9e283441b847e569aAndreas GustafssonCLASS="literal"
9a72459b6040b30d043c5fd9e283441b847e569aAndreas Gustafsson>example.com</TT
07c336a9a85791dff886b1e28514589a25d9b720Andreas Gustafsson>
07c336a9a85791dff886b1e28514589a25d9b720Andreas Gustafsson needs only one zone file to handle both of these reverse
07c336a9a85791dff886b1e28514589a25d9b720Andreas Gustafsson mappings:</P
07c336a9a85791dff886b1e28514589a25d9b720Andreas Gustafsson><PRE
07c336a9a85791dff886b1e28514589a25d9b720Andreas GustafssonCLASS="programlisting"
07c336a9a85791dff886b1e28514589a25d9b720Andreas Gustafsson>&#13;$ORIGIN ipv6-rev.example.com.
07c336a9a85791dff886b1e28514589a25d9b720Andreas Gustafsson\[x1234567812125675/64] IN PTR host.example.com.
712fa28946312882a60b0c6a913914d3e8c69867Mark Andrews</PRE
712fa28946312882a60b0c6a913914d3e8c69867Mark Andrews></DIV
f2a16ec2e8970615d39f8fe339b215ad0a893b85Mark Andrews></DIV
8bcf7a157900c3a05168aaec708b8c664b96d797Andreas Gustafsson></DIV
63fd201fde27ce408cde1c73a054e401fcfb9e3bDavid Lawrence><DIV
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark AndrewsCLASS="NAVFOOTER"
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrews><HR
f8644da8d948dbc973f6dd4c94a79774e16ec07bDavid LawrenceALIGN="LEFT"
f8644da8d948dbc973f6dd4c94a79774e16ec07bDavid LawrenceWIDTH="100%"><TABLE
9bfa90768ab83ea5a8571c98d3774377da4bdcbeDavid LawrenceWIDTH="100%"
9bfa90768ab83ea5a8571c98d3774377da4bdcbeDavid LawrenceBORDER="0"
9bfa90768ab83ea5a8571c98d3774377da4bdcbeDavid LawrenceCELLPADDING="0"
9bfa90768ab83ea5a8571c98d3774377da4bdcbeDavid LawrenceCELLSPACING="0"
9bfa90768ab83ea5a8571c98d3774377da4bdcbeDavid Lawrence><TR
2d67c2474475acf52c8251dc48bfb7565ee5f2ffDavid Lawrence><TD
2d67c2474475acf52c8251dc48bfb7565ee5f2ffDavid LawrenceWIDTH="33%"
2d67c2474475acf52c8251dc48bfb7565ee5f2ffDavid LawrenceALIGN="left"
2d67c2474475acf52c8251dc48bfb7565ee5f2ffDavid LawrenceVALIGN="top"
6a7a69e9f764812872ec2db775be2ac8bb073102Andreas Gustafsson><A
6a7a69e9f764812872ec2db775be2ac8bb073102Andreas GustafssonHREF="Bv9ARM.ch03.html"
6a7a69e9f764812872ec2db775be2ac8bb073102Andreas Gustafsson>Prev</A
0a9a3d8c6daf9ffcfb62dbe366e26f521cbb9736Brian Wellington></TD
8bcf7a157900c3a05168aaec708b8c664b96d797Andreas Gustafsson><TD
0a9a3d8c6daf9ffcfb62dbe366e26f521cbb9736Brian WellingtonWIDTH="34%"
f5ebf2f0c9e9d2068ace1dbcc2ef2ed3ebdbfde5Andreas GustafssonALIGN="center"
8bcf7a157900c3a05168aaec708b8c664b96d797Andreas GustafssonVALIGN="top"
34d5676aac483e00e16056a6834a27b52bed42f0Brian Wellington><A
1d9ab721315555ac75e7d4f57585323909283688Andreas GustafssonHREF="Bv9ARM.html"
1d9ab721315555ac75e7d4f57585323909283688Andreas Gustafsson>Home</A
1d9ab721315555ac75e7d4f57585323909283688Andreas Gustafsson></TD
63fd201fde27ce408cde1c73a054e401fcfb9e3bDavid Lawrence><TD
ef8d97818f0d30a4e09db97af695f504b311372cMark AndrewsWIDTH="33%"
112d9875bf33e2382f9a986d3e58fce08f1935fcOlafur GudmundssonALIGN="right"
63fd201fde27ce408cde1c73a054e401fcfb9e3bDavid LawrenceVALIGN="top"
63fd201fde27ce408cde1c73a054e401fcfb9e3bDavid Lawrence><A
63fd201fde27ce408cde1c73a054e401fcfb9e3bDavid LawrenceHREF="Bv9ARM.ch05.html"
6af5c66df334c4e275e07b03c9b35e40dbaa4f31Andreas Gustafsson>Next</A
519f8475ff8218e3981ae2b249eb1403da7c52f6Andreas Gustafsson></TD
519f8475ff8218e3981ae2b249eb1403da7c52f6Andreas Gustafsson></TR
edc1c60621b44fbc8131ad1542f657dd129f9a30Andreas Gustafsson><TR
edc1c60621b44fbc8131ad1542f657dd129f9a30Andreas Gustafsson><TD
edc1c60621b44fbc8131ad1542f657dd129f9a30Andreas GustafssonWIDTH="33%"
edc1c60621b44fbc8131ad1542f657dd129f9a30Andreas GustafssonALIGN="left"
41626c0997c89dcdecf67c931f0031aadd507977Andreas GustafssonVALIGN="top"
41626c0997c89dcdecf67c931f0031aadd507977Andreas Gustafsson>Nameserver Configuration</TD
41626c0997c89dcdecf67c931f0031aadd507977Andreas Gustafsson><TD
4f4e44c98f315bfadc6dded1b86b465222a83967David LawrenceWIDTH="34%"
464c2e4bb960d15bd60d53c3ef3ae7414b129037David LawrenceALIGN="center"
464c2e4bb960d15bd60d53c3ef3ae7414b129037David LawrenceVALIGN="top"
464c2e4bb960d15bd60d53c3ef3ae7414b129037David Lawrence>&nbsp;</TD
6112718b0dbb01ffbfd3fabc61e30c7e4485b0a7David Lawrence><TD
6112718b0dbb01ffbfd3fabc61e30c7e4485b0a7David LawrenceWIDTH="33%"
6112718b0dbb01ffbfd3fabc61e30c7e4485b0a7David LawrenceALIGN="right"
6112718b0dbb01ffbfd3fabc61e30c7e4485b0a7David LawrenceVALIGN="top"
6112718b0dbb01ffbfd3fabc61e30c7e4485b0a7David Lawrence>The <SPAN
6112718b0dbb01ffbfd3fabc61e30c7e4485b0a7David LawrenceCLASS="acronym"
04260c5c48d234734863f0222e207b6564cd41a8David Lawrence>BIND</SPAN
04260c5c48d234734863f0222e207b6564cd41a8David Lawrence> 9 Lightweight Resolver</TD
04260c5c48d234734863f0222e207b6564cd41a8David Lawrence></TR
f479c9ff5576b3d138c7e52cfc2319b185b7ebcfDavid Lawrence></TABLE
f479c9ff5576b3d138c7e52cfc2319b185b7ebcfDavid Lawrence></DIV
f479c9ff5576b3d138c7e52cfc2319b185b7ebcfDavid Lawrence></BODY
6c35e4dd17e6562a6b4d106cbf1d824b9f529356David Lawrence></HTML
504f7802d4c9b43db4820f496c4d00e078effa18David Lawrence>