Bv9ARM.ch04.html revision ff5760e233f6ab75e33783b6dd48f961ce04d933
6bd8cee98332533a4fa705b82ca9ec1606738ba9Mark Andrews>Advanced Concepts</TITLE
6bd8cee98332533a4fa705b82ca9ec1606738ba9Mark AndrewsNAME="GENERATOR"
0c2509b0b9f9e455fa9d347d08f6ba9abd86d418Mark AndrewsCONTENT="Modular DocBook HTML Stylesheet Version 1.61
8b5de9701428e2b5eb50aba96af23dc1186124ddMark AndrewsTITLE="BIND 9 Administrator Reference Manual"
80b782f356f0692c11b4e52e8dd46ec41704e5a2Mark AndrewsREL="PREVIOUS"
80b782f356f0692c11b4e52e8dd46ec41704e5a2Mark AndrewsTITLE="Nameserver Configuration"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsTITLE="The BIND 9 Lightweight Resolver"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsCLASS="chapter"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsBGCOLOR="#FFFFFF"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsTEXT="#000000"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsLINK="#0000FF"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsVLINK="#840084"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsALINK="#0000FF"
6a2f7bba6f4df137ab3f781fe07b0b88e72e0b19Mark AndrewsCLASS="NAVHEADER"
53cf67186506f9557aaf2149898dd76715803db2Mark AndrewsCELLPADDING="0"
53cf67186506f9557aaf2149898dd76715803db2Mark AndrewsCELLSPACING="0"
888bb8bf68ba1a2b032a64122efd9125a9155ad7Mark AndrewsALIGN="center"
888bb8bf68ba1a2b032a64122efd9125a9155ad7Mark Andrews>BIND 9 Administrator Reference Manual</TH
b312748a11d27fe387984973ba79975a9d6863c4Mark AndrewsVALIGN="bottom"
ee84964a7d29ae88769f67326a65256731769ea7Mark AndrewsALIGN="center"
ee84964a7d29ae88769f67326a65256731769ea7Mark AndrewsVALIGN="bottom"
ee84964a7d29ae88769f67326a65256731769ea7Mark AndrewsALIGN="right"
463fc8f9d61e07613486e64b4b7b3f924ea2b25cMark AndrewsVALIGN="bottom"
c3ea698877cdde327f2bf6a8e97347798fead2d4Mark AndrewsCLASS="chapter"
9368d7df838f58cd32922b526775ca730bc633cfMark Andrews>Chapter 4. Advanced Concepts</A
22a9cd54c072545d13788ceead759911fe8cfe34Mark Andrews>Table of Contents</B
266296414d0ed79980c6d3144a587b42324a50ffMark AndrewsHREF="Bv9ARM.ch04.html#dynamic_update"
c960dffe35970da729219b72f2e41350d3b64c35Mark Andrews>Dynamic Update</A
31b3dc1c6b4fe99a2af2ee63314e842af4a20070Mark AndrewsHREF="Bv9ARM.ch04.html#incremental_zone_transfers"
31b3dc1c6b4fe99a2af2ee63314e842af4a20070Mark Andrews>Incremental Zone Transfers (IXFR)</A
a207a2835e37de52e11d4c143c0425e749409c46Mark Andrews>Split DNS</A
b0c15bd9792112fb47f6d956e580e4369e92f4e7Mark Andrews>IPv6 Support in <SPAN
bf7f253e306d0ced8ae24d7a0598773950da11f4Mark AndrewsCLASS="acronym"
5f89a1ee9e0fe64211d050db5d3e7a5ea282c282Mark AndrewsCLASS="sect1"
c86eed4bdecad9df12f992f9d743dfee3a6c5bdcMark AndrewsCLASS="sect1"
12ff7274fe2ea531ecca6a71fb9f7e1ae92da389Mark AndrewsNAME="dynamic_update"
12ff7274fe2ea531ecca6a71fb9f7e1ae92da389Mark Andrews>4.1. Dynamic Update</A
767fd19da4b699aae46959d834f53af0e1166e80Mark Andrews>Dynamic update is the term used for the ability under
767fd19da4b699aae46959d834f53af0e1166e80Mark Andrews certain specified conditions to add, modify or delete records or
767fd19da4b699aae46959d834f53af0e1166e80Mark Andrews RRsets in the master zone files. Dynamic update is fully described
767fd19da4b699aae46959d834f53af0e1166e80Mark Andrews in RFC 2136.</P
8da0b50e8a8c74602eca97e261ce4ad457df5048Mark Andrews>Dynamic update is enabled on a zone-by-zone basis, by
5b76a09697bfc76f5acefd65d5b37b1214d271a8Mark Andrews including an <B
5b76a09697bfc76f5acefd65d5b37b1214d271a8Mark AndrewsCLASS="command"
6388dcf8e661687c30a5d52f149d193ce86748a8Mark Andrews>allow-update</B
93e353425a81da7793dde3776f4caca658f57c11Mark AndrewsCLASS="command"
93e353425a81da7793dde3776f4caca658f57c11Mark Andrews>update-policy</B
93e353425a81da7793dde3776f4caca658f57c11Mark Andrews> clause in the
49a940dc68b30d9e4f9e1bd3c0503d8b90bb1726Mark AndrewsCLASS="command"
49a940dc68b30d9e4f9e1bd3c0503d8b90bb1726Mark Andrews> statement.</P
d92770e851ebbc1005b3bf121e3c9f13b67a3f42Mark Andrews>Updating of secure zones (zones using DNSSEC) follows
59ab128c972622f5aeafe3229966dcba73b62243Mark Andrews RFC 3007: SIG and NXT records affected by updates are automatically
59ab128c972622f5aeafe3229966dcba73b62243Mark Andrews regenerated by the server using an online zone key.
59ab128c972622f5aeafe3229966dcba73b62243Mark Andrews Update authorization is based
90295f915c883d1aeeda856f518584d4219a704aMark Andrews on transaction signatures and an explicit server policy.</P
90295f915c883d1aeeda856f518584d4219a704aMark AndrewsCLASS="sect2"
1c75ea91cdb49dac65f0f592ddbf66bfdfc4a2d7Mark AndrewsCLASS="sect2"
142d155dd68fd601dc38c6b6f7c35f2798ec24caMark AndrewsNAME="journal"
142d155dd68fd601dc38c6b6f7c35f2798ec24caMark Andrews>4.1.1. The journal file</A
99776003811a413457a2c35a808ad860df877d24Mark Andrews>All changes made to a zone using dynamic update are stored in the
2ffb3eb384ae71ae9f8edbf5fa2219d965ff0552Mark Andrews zone's journal file. This file is automatically created by the
2ffb3eb384ae71ae9f8edbf5fa2219d965ff0552Mark Andrews server when when the first dynamic update takes place. The name of
2ffb3eb384ae71ae9f8edbf5fa2219d965ff0552Mark Andrews the journal file is formed by appending the
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews extension <TT
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark AndrewsCLASS="filename"
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews name of the corresponding zone file. The journal file is in a
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews binary format and should not be edited manually.</P
aa39170da817cae7b4c6c735cc832e05ec3d2351Mark Andrews>The server will also occasionally write ("dump")
52fc1457e44c476a81ec9dee6a664958cb64b8e2Mark Andrews the complete contents of the updated zone to its zone file.
52fc1457e44c476a81ec9dee6a664958cb64b8e2Mark Andrews This is not done immediately after
6526fd032fc418411da3af4201214e95c113d3e2Mark Andrews each dynamic update, because that would be too slow when a large
6526fd032fc418411da3af4201214e95c113d3e2Mark Andrews zone is updated frequently. Instead, the dump is delayed by 15
b8fff4f0d70bb9c5e53023ad0dae0acda67b5cdaMark Andrews minutes, allowing additional updates to take place.</P
757bf8a1e5d85806c648d7a6267da8d49a8ab822Tatuya JINMEI 神明達哉>When a server is restarted after a shutdown or crash, it will replay
757bf8a1e5d85806c648d7a6267da8d49a8ab822Tatuya JINMEI 神明達哉 the journal file to incorporate into the zone any updates that took
be0e075ac2c10ade3e80edef7fa14ac0fda92690Mark Andrews place after the last zone dump.</P
be0e075ac2c10ade3e80edef7fa14ac0fda92690Mark Andrews>Changes that result from incoming incremental zone transfers are also
2a908588fbeacebc5f13b153b73c96e12dacaadcTatuya JINMEI 神明達哉 journalled in a similar way.</P
2a908588fbeacebc5f13b153b73c96e12dacaadcTatuya JINMEI 神明達哉>The zone files of dynamic zones cannot normally be edited by
2a908588fbeacebc5f13b153b73c96e12dacaadcTatuya JINMEI 神明達哉 hand because they are not guaranteed to contain the most recent
af2be1a46813e228cb9d71230d3f41222fdb69baTatuya JINMEI 神明達哉 dynamic changes - those are only in the journal file.
af2be1a46813e228cb9d71230d3f41222fdb69baTatuya JINMEI 神明達哉 The only way to ensure that the zone file of a dynamic zone
af2be1a46813e228cb9d71230d3f41222fdb69baTatuya JINMEI 神明達哉 is up to date is to run <B
2945ac15af547df0268e449252902ead599e2451Mark AndrewsCLASS="command"
2945ac15af547df0268e449252902ead599e2451Mark Andrews>rndc stop</B
285761cf91626976e211f69d9678c138b25f8629Tatuya JINMEI 神明達哉>If you have to make changes to a dynamic zone
285761cf91626976e211f69d9678c138b25f8629Tatuya JINMEI 神明達哉 manually, the following procedure will work: Shut down
ca70688bf60b4f50c4e3ec7d40567341c9962fafMark Andrews the server using <B
ca70688bf60b4f50c4e3ec7d40567341c9962fafMark AndrewsCLASS="command"
ca70688bf60b4f50c4e3ec7d40567341c9962fafMark Andrews>rndc stop</B
ca70688bf60b4f50c4e3ec7d40567341c9962fafMark Andrews> (sending a signal
8b0ee8448bec37bf1e771363dccce7c0e73eb1a7Mark AndrewsCLASS="command"
aec2d57d5b9f5ca97763a1b49b76f0bcb5852e1aMark Andrews>rndc halt</B
aec2d57d5b9f5ca97763a1b49b76f0bcb5852e1aMark AndrewsCLASS="emphasis"
a9ae9d743c7f85bec44e95b1f62c7a2a114a2fd6Mark Andrews sufficient). Wait for the server to exit,
ebbbd34776d668bb2d7cf100b58a6f647c431c03Mark AndrewsCLASS="emphasis"
75ace6601e66840436f52e61353ee0d400577b55Mark AndrewsCLASS="filename"
75ace6601e66840436f52e61353ee0d400577b55Mark Andrews> file, edit the zone file,
75ace6601e66840436f52e61353ee0d400577b55Mark Andrews and restart the server. Removing the <TT
75ace6601e66840436f52e61353ee0d400577b55Mark AndrewsCLASS="filename"
ba4aec8c1853a1deda8eb43ffeaac4d764c8d39eMark Andrews file is necessary because the manual edits will not be
ba4aec8c1853a1deda8eb43ffeaac4d764c8d39eMark Andrews present in the journal, rendering it inconsistent with the
ba4aec8c1853a1deda8eb43ffeaac4d764c8d39eMark Andrews contents of the zone file.</P
f411c2e81cbfcf89ee073a0e31ac902a42fc8f22Mark AndrewsCLASS="sect1"
f411c2e81cbfcf89ee073a0e31ac902a42fc8f22Mark AndrewsCLASS="sect1"
ab2ac96c4e71dc803e47c35592044e116f61aca5Tatuya JINMEI 神明達哉NAME="incremental_zone_transfers"
ab2ac96c4e71dc803e47c35592044e116f61aca5Tatuya JINMEI 神明達哉>4.2. Incremental Zone Transfers (IXFR)</A
3bdf879a5301bce17e0a955585eb3decc541ba79Mark Andrews>The incremental zone transfer (IXFR) protocol is a way for
3bdf879a5301bce17e0a955585eb3decc541ba79Mark Andrews slave servers to transfer only changed data, instead of having to
3bdf879a5301bce17e0a955585eb3decc541ba79Mark Andrews transfer the entire zone. The IXFR protocol is documented in RFC
3bdf879a5301bce17e0a955585eb3decc541ba79Mark Andrews 1995. See <A
3bdf879a5301bce17e0a955585eb3decc541ba79Mark AndrewsHREF="Bv9ARM.ch09.html#proposed_standards"
1b5b46942d149f891bb91e90c6f52944b77c8a68Mark Andrews>Proposed Standards</A
6b25d2f7f7a1125508f8d225a8fef94e1db83555Mark Andrews>When acting as a master, <SPAN
6b25d2f7f7a1125508f8d225a8fef94e1db83555Mark AndrewsCLASS="acronym"
b6309ed962c4988a314d61742c4fbc4935467d68Mark Andrews> 9 supports IXFR for those zones
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrewswhere the necessary change history information is available. These
39fe146f2ab82cb8e49caa319a3345174fa2d69aMark Andrewsinclude master zones maintained by dynamic update and slave zones
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrewswhose data was obtained by IXFR, but not manually maintained master
bd3946db298667e769804b2e978df2d6dcd85e29Mark Andrewszones nor slave zones obtained by performing a full zone transfer
ab5d8edc1bd391a1b306db68114fac303484b30fMark Andrews>When acting as a slave, <SPAN
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark AndrewsCLASS="acronym"
8689f943a4859a8f68344236a1dcb81299a98347Mark Andrews> 9 will attempt to use IXFR unless
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrewsit is explicitly disabled. For more information about disabling
2434ccfde7efa30b6fedf4630e5036eeb5d647d0Mark AndrewsIXFR, see the description of the <B
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark AndrewsCLASS="command"
d8ec783e6dc0bd16a80b30d9888306b1faae6037Mark Andrews>request-ixfr</B
5bd76af084edfdcd1cb4db9453ac781d32dde6f7Mark AndrewsCLASS="command"
311e6d00c584f63665bed5dd9aea292402cad8deMark Andrews> statement.</P
7f32428506d55083fe5ac9aa515294bdef7c6e27Mark AndrewsCLASS="sect1"
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark AndrewsCLASS="sect1"
5c10f54fe38795cbd3d5cf22e3fbd1d22b8226e4Mark AndrewsNAME="AEN714"
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrews>4.3. Split DNS</A
1feb76edcbb8ee97d1757f73115b7c4a71de6e0eMark Andrews>Setting up different views, or visibility, of DNS space to
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark Andrewsinternal and external resolvers is usually referred to as a <I
4c342614f80d867bba23e63795ec6ee79dd6395dMark AndrewsCLASS="emphasis"
0ae34c3f6222ece01e0f710c7c0311f5cf9d9c0fMark Andrews> setup. There are several reasons an organization
0ae34c3f6222ece01e0f710c7c0311f5cf9d9c0fMark Andrewswould want to set up its DNS this way.</P
6c6673405c7e29c1d91d07b326d0fe1d7b52e478Mark Andrews>One common reason for setting up a DNS system this way is
6c6673405c7e29c1d91d07b326d0fe1d7b52e478Mark Andrewsto hide "internal" DNS information from "external" clients on the
bb6936058eb88eadff030462a347c10895c61a9aMark AndrewsInternet. There is some debate as to whether or not this is actually useful.
bb6936058eb88eadff030462a347c10895c61a9aMark AndrewsInternal DNS information leaks out in many ways (via email headers,
bb6936058eb88eadff030462a347c10895c61a9aMark Andrewsfor example) and most savvy "attackers" can find the information
bb6936058eb88eadff030462a347c10895c61a9aMark Andrewsthey need using other means.</P
0ad5cb4782cd419b089bcab28d2fd9e140dbcc59Mark Andrews>Another common reason for setting up a Split DNS system is
0ad5cb4782cd419b089bcab28d2fd9e140dbcc59Mark Andrewsto allow internal networks that are behind filters or in RFC 1918
08d802a9c6ec4c92f18c6cab1250d55c3f649b38Mark Andrewsspace (reserved IP space, as documented in RFC 1918) to resolve DNS
7c5d5a7932b8ac27281eeff64506dff8220bb3eaMark Andrewson the Internet. Split DNS can also be used to allow mail from outside
7c5d5a7932b8ac27281eeff64506dff8220bb3eaMark Andrewsback in to the internal network.</P
1aed0905a50ff8d2bdc4d253b38ae24afe3bab1cDanny Mayer>Here is an example of a split DNS setup:</P
1aed0905a50ff8d2bdc4d253b38ae24afe3bab1cDanny Mayer>Let's say a company named <I
1a9c000f54e6204fb49d785fd0bbb7a8e590dc99Mark AndrewsCLASS="emphasis"
1a9c000f54e6204fb49d785fd0bbb7a8e590dc99Mark Andrews>Example, Inc.</I
3cea35d9159b36eac43d32082a0b98f2cd82fc2eDanny Mayerhas several corporate sites that have an internal network with reserved
53f1312c61fa8618852584bcdf9f35530282eb08Mark AndrewsInternet Protocol (IP) space and an external demilitarized zone (DMZ),
53f1312c61fa8618852584bcdf9f35530282eb08Mark Andrewsor "outside" section of a network, that is available to the public.</P
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark AndrewsCLASS="emphasis"
87f4715d6c0a22f3449eb3291c91aa45ba86c955Mark Andrews>Example, Inc.</I
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark Andrews> wants its internal clients
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark Andrewsto be able to resolve external hostnames and to exchange mail with
87f4715d6c0a22f3449eb3291c91aa45ba86c955Mark Andrewspeople on the outside. The company also wants its internal resolvers
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark Andrewsto have access to certain internal-only zones that are not available
7d011946d27152e6ee1e0f56e380abafddd9cfdbMark Andrewsat all outside of the internal network.</P
e809f3fb3f8567b2777fd100bffe2c0072e03942Mark Andrews>In order to accomplish this, the company will set up two sets
3733c24efa7eaa65455153702c3fb71c9233eafbMark Andrewsof nameservers. One set will be on the inside network (in the reserved
012a2b979e011b13ba0d291c279dc65a167c039eMark AndrewsIP space) and the other set will be on bastion hosts, which are "proxy"
012a2b979e011b13ba0d291c279dc65a167c039eMark Andrewshosts that can talk to both sides of its network, in the DMZ.</P
f6ff00810196d0c0973f62c7917b9975011fa45aMark Andrews>The internal servers will be configured to forward all queries,
ec3984e9df6fd9b7811daa0dacb1b3dd1423ebf3Mark Andrewsexcept queries for <TT
ec3984e9df6fd9b7811daa0dacb1b3dd1423ebf3Mark AndrewsCLASS="filename"
b972ff033b3efd52e747683face674dc4d2e431bMark AndrewsCLASS="filename"
fa4e1438016331502e6d665588021aa7ffef8cc2Mark AndrewsCLASS="filename"
f0471ca4b7bca6e907130ec84e36cf69f2b79a5aMark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>, to the servers in the
638fe804a524ee0c028863c0301b999c79de7651Mark AndrewsDMZ. These internal servers will have complete sets of information
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="emphasis"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
0d993c02babc1e00516272783b310e83bb292d5cMark AndrewsCLASS="filename"
4d9f3f00d93fcb8743b1105e8cf82e862be220d1Mark Andrews>To protect the <TT
4d9f3f00d93fcb8743b1105e8cf82e862be220d1Mark AndrewsCLASS="filename"
86f6b92e35c7bdb5fc1fd1021af75b981863313eMark AndrewsCLASS="filename"
25276bd1ecb372b82c9235648e5defab0655dcd5Mark Andrewsthe internal nameservers must be configured to disallow all queries
25276bd1ecb372b82c9235648e5defab0655dcd5Mark Andrewsto these domains from any external hosts, including the bastion
320d6ee24ea59c0dbcb2c08038586ef03c6a191dMark Andrews>The external servers, which are on the bastion hosts, will
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsbe configured to serve the "public" version of the <TT
475fe52dc33d8d8344e8b1e48fa7bb6643f7ca66Mark AndrewsCLASS="filename"
5af560664daaa984f98cec6925518a3e06c4ab4fMark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsThis could include things such as the host records for public servers
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsand mail exchange (MX) records (<TT
54532c54130de8f374465bb23d5576fc3257ea96Mark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
446ff1959cc3e963778c8770204b72c9e7c7df5aMark Andrews>In addition, the public <TT
446ff1959cc3e963778c8770204b72c9e7c7df5aMark AndrewsCLASS="filename"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="filename"
ac65e45126dda424b5cc9d2865b353dc0ec23e1eMark Andrewsshould have special MX records that contain wildcard (`*') records
ac65e45126dda424b5cc9d2865b353dc0ec23e1eMark Andrewspointing to the bastion hosts. This is needed because external mail
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsservers do not have any other way of looking up how to deliver mail
0423090da198f31ac615cd3a8f7d83aada32d5b3Mark Andrewsto those internal hosts. With the wildcard records, the mail will
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsbe delivered to the bastion host, which can then forward it on to
d9e0458a890c49f977fdcf9d995681f546f7c427Mark Andrewsinternal hosts.</P
de4976142190ae84ed3e4099f3e0fc07781748a3Mark Andrews>Here's an example of a wildcard MX record:</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="programlisting"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="literal"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>Now that they accept mail on behalf of anything in the internal
e0fa16fe191d619d2cd05a039067414409329878Mark Andrewsnetwork, the bastion hosts will need to know how to deliver mail
e0fa16fe191d619d2cd05a039067414409329878Mark Andrewsto internal hosts. In order for this to work properly, the resolvers on
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsthe bastion hosts will need to be configured to point to the internal
93da96c1cfd5f3c47169855867dd18db00c8a386Mark Andrewsnameservers for DNS resolution.</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>Queries for internal hostnames will be answered by the internal
7d389c324cc032475f9d219a12ab84bacbd7fbaaMark Andrewsservers, and queries for external hostnames will be forwarded back
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsout to the DNS servers on the bastion hosts.</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>In order for all this to work properly, internal clients will
dcd371be7d481b242d277d735e4c2d974297c164Mark Andrewsneed to be configured to query <I
dcd371be7d481b242d277d735e4c2d974297c164Mark AndrewsCLASS="emphasis"
cc4928ec7116a064223f60639ca1a80f25ba350fMark Andrews> the internal
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsnameservers for DNS queries. This could also be enforced via selective
e2cf63c5df79eb7c8b86b6278289883fa760cda5Mark Andrewsfiltering on the network.</P
c3184b4e2a1f238f4615d36fee79df82b1711344Mark Andrews>If everything has been set properly, <I
c3184b4e2a1f238f4615d36fee79df82b1711344Mark AndrewsCLASS="emphasis"
c3184b4e2a1f238f4615d36fee79df82b1711344Mark Andrews>Example, Inc.</I
9b7c023fe6dc88ba1e69ace1f7c3ade40c6475f9Mark Andrewsinternal clients will now be able to:</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>Look up any hostnames in the <TT
c61ec97ae0b859914ee26e213fe792f86a157990Mark AndrewsCLASS="literal"
49f7d1585e0e4f1ffa1667391dd7ae1c4d3d4e81Mark AndrewsCLASS="literal"
945cb085b859dbfc6a883813dda03c83e06995d3Mark Andrews>Look up any hostnames in the <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="literal"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="literal"
c549b3a4d5fedba2ae960df667864e824acb1ef9Mark Andrews> domains.</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>Look up any hostnames on the Internet.</P
8f9664521724eefc39728c092d0bc6be527e1496Mark Andrews>Exchange mail with internal AND external people.</P
da091cda77fa951e682119c3df84f60a62bed702Mark Andrews>Hosts on the Internet will be able to:</P
bdb1394788a677d0b6e8499ba1ece17a73f476c7Mark Andrews>Look up any hostnames in the <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="literal"
a1edcd1b8d430650d85ec0962cd32efde76a71fbMark AndrewsCLASS="literal"
7c23b791f4ae8f0c4c2982a91d13c0ecb15ee798Mark Andrews>Exchange mail with anyone in the <TT
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="literal"
acc8b7ac3d16538bf223545bbf71899b9accaebbMark AndrewsCLASS="literal"
b9efcf0a377381b29960137e54ecaf4db85a35c8Mark Andrews>Here is an example configuration for the setup we just
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews described above. Note that this is only configuration information;
8e5893c36cdccc706f9632f51e0c8d390d2a8d06Mark Andrews for information on how to configure your zone files, see <A
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsHREF="Bv9ARM.ch03.html#sample_configuration"
e396939d492e6afa8e31a8dc11d7317c9e62f15fMark Andrews>Section 3.1</A
e70b069e3807d5f499dff31eb31c2b3e0e125457Mark Andrews>Internal DNS server config:</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="programlisting"
88aa68f478c1634f5f10034fb6ea4158efa20ff4Mark Andrewsacl internals { 172.16.72.0/24; 192.168.1.0/24; };
4c83dd7f22b19c75afdd311684f6ba0faa24e8d8Mark Andrewsacl externals { <TT
4c83dd7f22b19c75afdd311684f6ba0faa24e8d8Mark AndrewsCLASS="varname"
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews>bastion-ips-go-here</TT
26cf4737b3e84c3a686a5eacebf22ac39e57d4caMark Andrews forward only;
26cf4737b3e84c3a686a5eacebf22ac39e57d4caMark Andrews forwarders { // forward to external servers
34e5a08809dda3276252269ebddd1616e62081a2Mark AndrewsCLASS="varname"
34e5a08809dda3276252269ebddd1616e62081a2Mark Andrews>bastion-ips-go-here</TT
0cd36f1d15caf6622ec3128544d4238ad180a300Mark Andrews allow-transfer { none; }; // sample allow-transfer (no one)
0cd36f1d15caf6622ec3128544d4238ad180a300Mark Andrews allow-query { internals; externals; }; // restrict query access
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews allow-recursion { internals; }; // restrict recursion
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewszone "site1.example.com" { // sample slave zone
ddc592d128cdde85ada64efbda95981c10c4c03cMark Andrews type master;
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews forwarders { }; // do normal iterative
88c2b83cc548a217cc92a2bf75ca1ef1d4237d4fMark Andrews // resolution (do not forward)
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews allow-query { internals; externals; };
bd6ad47c3dbc52a54f240432878b6832bd6dd6e2Mark Andrews allow-transfer { internals; };
9e205a3c51e68d19a7ed03244d45b14b3e0d69afMark Andrews masters { 172.16.72.3; };
9e205a3c51e68d19a7ed03244d45b14b3e0d69afMark Andrews forwarders { };
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews allow-query { internals; externals; };
e823642ec0c167af8f7db01c96ba0279165a61f3Mark Andrews allow-transfer { internals; };
93e6ebcd0a0f044ba2add424c265b5e0bb4c8afdMark Andrews type master;
8ac1acc30d0f405222ffa7b2b93131d9d4e18599Mark Andrews forwarders { };
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews allow-query { internals; };
c99d9017ba00099bfa89e1ed53e63a5cb07d28d5Mark Andrews allow-transfer { internals; }
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews masters { 172.16.72.3; };
c4a9ce445c48a57eed5aa16582b1964cf8cedf87Mark Andrews forwarders { };
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrews allow-query { internals };
a04a323f9a1ebd4766fc577e11bf3c22bdaf5516Mark Andrews allow-transfer { internals; }
dd0228908543562781a4c0d8773ae87d4c530633Mark Andrews>External (bastion host) DNS server config:</P
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark AndrewsCLASS="programlisting"
810e8d27763c5d8557239ab321eb125163af9236Mark Andrews> acl internals { 172.16.72.0/24; 192.168.1.0/24; };
b907c35b33a5a57e95ac021fb6a0086dbe369840Mark Andrewsacl externals { bastion-ips-go-here; };
984c39beed2fee49dda75c4c8a37b7f32bf434bfMark Andrews allow-transfer { none; }; // sample allow-transfer (no one)
94323de0419d68fe8c48af7ae14a2f1a1cd274a8Mark Andrews allow-query { internals; externals; }; // restrict query access
c08a03a43116c21cf12dea7cbcb5465588f7955cMark Andrews allow-recursion { internals; externals; }; // restrict recursion
79a6a33184abff1999ba13b10922ccb34a2758a5Mark Andrewszone "site1.example.com" { // sample slave zone
79a6a33184abff1999ba13b10922ccb34a2758a5Mark Andrews type master;
5d26560e2b93e1aa0334931ec6ccb6045c3581fcMark Andrews allow-query { any; };
5d26560e2b93e1aa0334931ec6ccb6045c3581fcMark Andrews allow-transfer { internals; externals; };
d6fbfd28ea82e425740de903ddc67f7d9e9f82e7Mark Andrews masters { another_bastion_host_maybe; };
d6fbfd28ea82e425740de903ddc67f7d9e9f82e7Mark Andrews allow-query { any; };
d6fbfd28ea82e425740de903ddc67f7d9e9f82e7Mark Andrews allow-transfer { internals; externals; }
091b098b49a4f84f459abd46451955a18abd6d40Mark AndrewsCLASS="filename"
7d3458a972a902740eb142044655aba6c6ffb9acMark Andrews> (or equivalent) on
7d3458a972a902740eb142044655aba6c6ffb9acMark Andrewsthe bastion host(s):</P
7c441b7f4afdedb6e5a99f113a4f926a005fa950Mark AndrewsCLASS="programlisting"
7c441b7f4afdedb6e5a99f113a4f926a005fa950Mark Andrews> search ...
7c441b7f4afdedb6e5a99f113a4f926a005fa950Mark Andrewsnameserver 172.16.72.2
f0ffc28f61a68b350fef9257f5f50e1ac866e0abMark Andrewsnameserver 172.16.72.3
75e184e4b80c499859574257dd5781d62cfed0b3Mark Andrewsnameserver 172.16.72.4
8695d7b357789bedff63e5b19c5ab25cd58fcd4bMark AndrewsCLASS="sect1"
8695d7b357789bedff63e5b19c5ab25cd58fcd4bMark AndrewsCLASS="sect1"
b597abd9cc44c7b9ecd0ff67df59a21ff45e88d5Mark Andrews>4.4. TSIG</A
b597abd9cc44c7b9ecd0ff67df59a21ff45e88d5Mark Andrews>This is a short guide to setting up Transaction SIGnatures
81e302788a444b81231a7cda721548a020ae5660Brian Wellington(TSIG) based transaction security in <SPAN
81e302788a444b81231a7cda721548a020ae5660Brian WellingtonCLASS="acronym"
c00a1eb423623442aff428336bb55590f79013bbMark Andrews>. It describes changes
c00a1eb423623442aff428336bb55590f79013bbMark Andrewsto the configuration file as well as what changes are required for
1e258716acade52396a8f260b5e19cbf6ca0290aMark Andrewsdifferent features, including the process of creating transaction
1e258716acade52396a8f260b5e19cbf6ca0290aMark Andrewskeys and using transaction signatures with <SPAN
d972fa317829804a692e46a34b6f27a33f861d9dMark AndrewsCLASS="acronym"
cceca51fec3b4af660d28e2d3df7242823312eb6Brian WellingtonCLASS="acronym"
03fae7ef2173cdf32918853b047d95d9046574ccMark Andrews> primarily supports TSIG for server to server communication.
03fae7ef2173cdf32918853b047d95d9046574ccMark AndrewsThis includes zone transfer, notify, and recursive query messages.
03fae7ef2173cdf32918853b047d95d9046574ccMark AndrewsResolvers based on newer versions of <SPAN
03fae7ef2173cdf32918853b047d95d9046574ccMark AndrewsCLASS="acronym"
ad611e746d6fdcbb9e67da361a3a039c226a9236Mark Andrews> 8 have limited support
603d1d1e20fbffc986b3aec93379bb4f6ac37afcMark Andrews>TSIG might be most useful for dynamic update. A primary
94323de0419d68fe8c48af7ae14a2f1a1cd274a8Mark Andrews server for a dynamic zone should use access control to control
2dd99c098ca162f985b7ef3c8142a964ad8281aeMark Andrews updates, but IP-based access control is insufficient. Key-based
2dd99c098ca162f985b7ef3c8142a964ad8281aeMark Andrews access control is far superior, see <A
2dd99c098ca162f985b7ef3c8142a964ad8281aeMark AndrewsHREF="Bv9ARM.ch09.html#proposed_standards"
2dd99c098ca162f985b7ef3c8142a964ad8281aeMark Andrews>Proposed Standards</A
1fb264ed3aa861a67d7bab9aeb5aea5836e03c14Mark AndrewsCLASS="command"
608c703d1231e0b1f291637ca5361b773afcdbf1Mark Andrews program supports TSIG via the <TT
608c703d1231e0b1f291637ca5361b773afcdbf1Mark AndrewsCLASS="option"
27151990b2b48f027f7f01972fe8e0dfa1df52d3Mark AndrewsCLASS="option"
27151990b2b48f027f7f01972fe8e0dfa1df52d3Mark Andrews> command line options.</P
2211bec6a0626b681fdf5a8e4406555ef76ddf70Mark AndrewsCLASS="sect2"
2211bec6a0626b681fdf5a8e4406555ef76ddf70Mark AndrewsNAME="AEN805"
fcb2ecdb52a594a5c0d07c2e98e67c14708c16dfMark Andrews>4.4.1. Generate Shared Keys for Each Pair of Hosts</A
3561e645d77448b20b1676680b08c76d559e5335Mark Andrews>A shared secret is generated to be shared between <I
3561e645d77448b20b1676680b08c76d559e5335Mark AndrewsCLASS="emphasis"
b9c80c8bddbb88384d7baef297a873b5f8715e49Mark AndrewsCLASS="emphasis"
b9c80c8bddbb88384d7baef297a873b5f8715e49Mark AndrewsAn arbitrary key name is chosen: "host1-host2.". The key name must
27269e9dd45b619160f90db1a0f6b2b3f6f4bbb8Mark Andrewsbe the same on both hosts.</P
27269e9dd45b619160f90db1a0f6b2b3f6f4bbb8Mark AndrewsCLASS="sect3"
f38c274c217d0a5b791786877422306a0e477e10Mark AndrewsCLASS="sect3"
84ef147b1fa0aed15cade55478ed647d15f7b094Mark AndrewsNAME="AEN810"
84ef147b1fa0aed15cade55478ed647d15f7b094Mark Andrews>4.4.1.1. Automatic Generation</A
e53a5a116fc531f730df0adb091278ff8a941dffMark Andrews>The following command will generate a 128 bit (16 byte) HMAC-MD5
e53a5a116fc531f730df0adb091278ff8a941dffMark Andrewskey as described above. Longer keys are better, but shorter keys
fc7fbdf6e66fb496442ec4f99f5a84669ea4c6d3Mark Andrewsare easier to read. Note that the maximum key length is 512 bits;
fc7fbdf6e66fb496442ec4f99f5a84669ea4c6d3Mark Andrewskeys longer than that will be digested with MD5 to produce a 128
986be654feec852eb9da0d15599f18d0035e569bMark AndrewsCLASS="userinput"
3703473c4a2672af58b4f141e92067e969fd978eBrian Wellington>dnssec-keygen -a hmac-md5 -b 128 -n HOST host1-host2.</B
43733a83ed92359555c0dcc766e04216ba858309Mark Andrews>The key is in the file <TT
43733a83ed92359555c0dcc766e04216ba858309Mark AndrewsCLASS="filename"
bda64555f62216c3e785338f372a7ad9b79c197cMark AndrewsNothing directly uses this file, but the base-64 encoded string
39c2b741427eedafe5054909773c2e121c078b72Mark Andrewsfollowing "<TT
39c2b741427eedafe5054909773c2e121c078b72Mark AndrewsCLASS="literal"
de36c606c52ad51e5abca6e42faf655937e5ed10Mark Andrewscan be extracted from the file and used as a shared secret:</P
23cb957a81a51a9656917ea98d0ae56b7abdcaccMark AndrewsCLASS="programlisting"
28d8b4118da7abed531ca09136a6d1402837d721Mark Andrews>The string "<TT
28d8b4118da7abed531ca09136a6d1402837d721Mark AndrewsCLASS="literal"
d6c0627d1e4d841eac9576427f2d4a0cf9a47e2cMark Andrewsbe used as the shared secret.</P
5d7b81d2a49d237ff5e73fdc4bd3394a3ee29392Mark AndrewsCLASS="sect3"
8f63de30293716a22054e7db47f27e81bab545c5Mark AndrewsNAME="AEN821"
8f63de30293716a22054e7db47f27e81bab545c5Mark Andrews>4.4.1.2. Manual Generation</A
9ae90732df942a7ffcbaa26ba254b55248ce79a5Mark Andrews>The shared secret is simply a random sequence of bits, encoded
9ae90732df942a7ffcbaa26ba254b55248ce79a5Mark Andrewsin base-64. Most ASCII strings are valid base-64 strings (assuming
9ae90732df942a7ffcbaa26ba254b55248ce79a5Mark Andrewsthe length is a multiple of 4 and only valid characters are used),
f3222d48cc3d81706d198faa00dea9720eb0768dMark Andrewsso the shared secret can be manually generated.</P
f3222d48cc3d81706d198faa00dea9720eb0768dMark Andrews>Also, a known string can be run through <B
c73c1c33ec9569c8f9ffd205b48f044f9b03795bMark AndrewsCLASS="command"
e95cc59f90d35f2d482b6f9c19ba96818275335cMark Andrewsa similar program to generate base-64 encoded data.</P
cde7dfea4c1267a2b526114f4ea80fe9db1fc557Brian Wellington>4.4.2. Copying the Shared Secret to Both Machines</A
fca9cc33ad4299e58e53aa5273d805477267e27aBrian Wellington>This is beyond the scope of DNS. A secure transport mechanism
fca9cc33ad4299e58e53aa5273d805477267e27aBrian Wellingtonshould be used. This could be secure FTP, ssh, telephone, etc.</P
683f10428e292811317df38fa324f242abbf7384Mark Andrews>4.4.3. Informing the Servers of the Key's Existence</A
5da1e589c2288dbe87002f771005a78d80a2e258Mark AndrewsCLASS="emphasis"
5da1e589c2288dbe87002f771005a78d80a2e258Mark AndrewsCLASS="emphasis"
852fa3b2e32719d094f3ad6513238841ae1f078bMark Andrewsboth servers. The following is added to each server's <TT
852fa3b2e32719d094f3ad6513238841ae1f078bMark AndrewsCLASS="filename"
a5c077e40c784cf9e25c95a1ab94db2faab04ae9Brian WellingtonCLASS="programlisting"
a5c077e40c784cf9e25c95a1ab94db2faab04ae9Brian Wellington> key host1-host2. {
a5c077e40c784cf9e25c95a1ab94db2faab04ae9Brian Wellington algorithm hmac-md5;
2ca556300b09a94f0937b303386d29b95ef057ddBrian Wellington>The algorithm, hmac-md5, is the only one supported by <SPAN
97527fc03cdb061759e2c9529c670ac1c190ef84Brian WellingtonCLASS="acronym"
e1c2a8b9c120bcfc2f56e866ca3069b8a90c38dbMark AndrewsThe secret is the one generated above. Since this is a secret, it
e1c2a8b9c120bcfc2f56e866ca3069b8a90c38dbMark Andrewsis recommended that either <TT
b7064914ca566fdd67cf0fe7e82d586cbb596470Mark AndrewsCLASS="filename"
b7064914ca566fdd67cf0fe7e82d586cbb596470Mark Andrews> be non-world
3e67a87fc6be516ec12afa5aa31c2c04d5a6ae17Brian Wellingtonreadable, or the key directive be added to a non-world readable
3e67a87fc6be516ec12afa5aa31c2c04d5a6ae17Brian Wellingtonfile that is included by <TT
3e67a87fc6be516ec12afa5aa31c2c04d5a6ae17Brian WellingtonCLASS="filename"
e9472e9f18f1c4f1279be2b3147be13a2bb731d0Mark Andrews>At this point, the key is recognized. This means that if the
e9472e9f18f1c4f1279be2b3147be13a2bb731d0Mark Andrewsserver receives a message signed by this key, it can verify the
e9472e9f18f1c4f1279be2b3147be13a2bb731d0Mark Andrewssignature. If the signature succeeds, the response is signed by
d073663cb45bef2fff5f9a43b9b6006edfc52483Mark Andrewsthe same key.</P
cad61731f8e960d9d99034a2a6eaafe1069c405cMark AndrewsCLASS="sect2"
54469c2b2262f6a3f09610df69e16e9c75fd1fe5Mark AndrewsNAME="AEN841"
54469c2b2262f6a3f09610df69e16e9c75fd1fe5Mark Andrews>4.4.4. Instructing the Server to Use the Key</A
90e303b114e56db5809fdd19805243457fa43cd9Olafur Gudmundsson>Since keys are shared between two hosts only, the server must
adbb11147cd5d97d140485fa37e85e66e15cf594Mark Andrewsbe told when keys are to be used. The following is added to the <TT
b938d2af619822a8262c86223cad958511e716a9Andreas GustafssonCLASS="filename"
b627356826f7b22e2ef396b80e8394eac76bc109Mark AndrewsCLASS="emphasis"
13ba983cc86bc7d80d5f66ba09002f7d510a6631Mark Andrews>, if the IP address of <I
13ba983cc86bc7d80d5f66ba09002f7d510a6631Mark AndrewsCLASS="emphasis"
66291de2060a1569de3fe9c5f0c1225448868f7aMark AndrewsCLASS="programlisting"
6c06bc591a830023e5e7a41cc4b37978b98c0c51Mark Andrews> server 10.1.2.3 {
84d8c0166ddc63ad5ce64e7d354553de38b9aabdAndreas Gustafsson keys { host1-host2. ;};
9cec4ca6cac428a46c6d64197c64831dcc02f506Andreas Gustafsson>Multiple keys may be present, but only the first is used.
9cec4ca6cac428a46c6d64197c64831dcc02f506Andreas GustafssonThis directive does not contain any secrets, so it may be in a world-readable
23fb770906bf1fd98210f16ad660078274242963Mark AndrewsCLASS="emphasis"
0cb27602e5690baa9ab61c7c1430e507536adca7Brian Wellington> sends a message that is a request
0cb27602e5690baa9ab61c7c1430e507536adca7Brian Wellingtonto that address, the message will be signed with the specified key. <I
ff1b064f5e2bf19c8e25f8927d23df5714e666edMark AndrewsCLASS="emphasis"
8e40433e347bc487cd70f02487fc7ce947a2422aMark Andrewsexpect any responses to signed messages to be signed with the same
880723fb130841459d45695b387651cacd6c9bb8Mark Andrews>A similar statement must be present in <I
880723fb130841459d45695b387651cacd6c9bb8Mark AndrewsCLASS="emphasis"
8f44fd4f8d5cefc227ab0fe59cbcbc3979fbc9caAndreas Gustafssonconfiguration file (with <I
8f44fd4f8d5cefc227ab0fe59cbcbc3979fbc9caAndreas GustafssonCLASS="emphasis"
fefbb64a751f23c9dcf8bb1e62c6ed40a6a04fb2Mark Andrews>'s address) for <I
fefbb64a751f23c9dcf8bb1e62c6ed40a6a04fb2Mark AndrewsCLASS="emphasis"
111e3433d289e8b4ea1260add39baa78c2a46891Mark Andrewssign request messages to <I
cf300e03de3df3ff422db922520bf07c686c86daMark AndrewsCLASS="emphasis"
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas Gustafsson>4.4.5. TSIG Key Based Access Control</A
242bba8991b030b7764f0bdca3922d75c34ea51eAndreas GustafssonCLASS="acronym"
02bdc23f8e3ca0f710e0a40daa15941ab1db6bb2Mark Andrews> allows IP addresses and ranges to be specified in ACL
45fe575607b91147ed753d175a7255198f14f197Andreas Gustafssondefinitions and
ef29912666cc6160f7165558bef017ab3849c5e1Mark AndrewsCLASS="command"
ef29912666cc6160f7165558bef017ab3849c5e1Mark Andrews>allow-{ query | transfer | update }</B
ef29912666cc6160f7165558bef017ab3849c5e1Mark Andrews> directives.
ef29912666cc6160f7165558bef017ab3849c5e1Mark AndrewsThis has been extended to allow TSIG keys also. The above key would
ef29912666cc6160f7165558bef017ab3849c5e1Mark Andrewsbe denoted <B
ef29912666cc6160f7165558bef017ab3849c5e1Mark AndrewsCLASS="command"
0cfa2fb26df42f781eca8c4c856d2d0165055bebMark Andrews>key host1-host2.</B
0cfa2fb26df42f781eca8c4c856d2d0165055bebMark Andrews>An example of an allow-update directive would be:</P
06a949d2ce8d4b4cbfbf4e7a0335316520aafa46Andreas GustafssonCLASS="programlisting"
06a949d2ce8d4b4cbfbf4e7a0335316520aafa46Andreas Gustafsson> allow-update { key host1-host2. ;};
0b81e99ddfb01746e667797dedc291fc550d14d3Brian Wellington>This allows dynamic updates to succeed only if the request
3638017bd3cb8e30874f708a125d1541b680b25eBrian Wellington was signed by a key named
3638017bd3cb8e30874f708a125d1541b680b25eBrian WellingtonCLASS="command"
8771fbe4a2cee7bebd785a486824833d741c7315Brian Wellington>host1-host2.</B
b541c10d0442d9804d94567a97956cec3bd2912dBrian Wellington>You may want to read about the more
f59d47928ed33d1546e8f982370086429f727e85Andreas GustafssonCLASS="command"
f59d47928ed33d1546e8f982370086429f727e85Andreas Gustafsson>update-policy</B
b541c10d0442d9804d94567a97956cec3bd2912dBrian Wellington> statement in <A
c01237c6bc5ec25063b4aae1799fe4de01a7455bAndreas GustafssonHREF="Bv9ARM.ch06.html#dynamic_update_policies"
c01237c6bc5ec25063b4aae1799fe4de01a7455bAndreas Gustafsson>Section 6.2.22.4</A
60213f2815a7e6584a2285546d05633fa7b6f5b4Mark AndrewsCLASS="sect2"
6c8abf481df85a67c3f32f5f107b554d3ff5a3edMark AndrewsNAME="AEN870"
c52806164c335f89e1980af836470b6daffe4f82Andreas Gustafsson>4.4.6. Errors</A
6b31d9c56874d3bd58b420cbe6cd64be502dbe08Andreas Gustafsson>The processing of TSIG signed messages can result in
892476530f3971aff52f25103d488ece9b01f673Andreas Gustafsson several errors. If a signed message is sent to a non-TSIG aware
6b31d9c56874d3bd58b420cbe6cd64be502dbe08Andreas Gustafsson server, a FORMERR will be returned, since the server will not
6b31d9c56874d3bd58b420cbe6cd64be502dbe08Andreas Gustafsson understand the record. This is a result of misconfiguration,
ee80f4506479e189ca1320eb87ac89188c5a7848Mark Andrews since the server must be explicitly configured to send a TSIG
ee80f4506479e189ca1320eb87ac89188c5a7848Mark Andrews signed message to a specific server.</P
d9d6d2f77fe54831dec9cde8ca03ae1f825599f9Andreas Gustafsson>If a TSIG aware server receives a message signed by an
d9d6d2f77fe54831dec9cde8ca03ae1f825599f9Andreas Gustafsson unknown key, the response will be unsigned with the TSIG
d9d6d2f77fe54831dec9cde8ca03ae1f825599f9Andreas Gustafsson extended error code set to BADKEY. If a TSIG aware server
9b2c0d29248ad5f86b47319239a06c783e1b5307Andreas Gustafsson receives a message with a signature that does not validate, the
9b2c0d29248ad5f86b47319239a06c783e1b5307Andreas Gustafsson response will be unsigned with the TSIG extended error code set
eb2c518a3871932e86268e7c6ddae2b2a00d72fdMark Andrews to BADSIG. If a TSIG aware server receives a message with a time
4072dfb9b865c82c24a72e734d54da51a20dfc1eMark Andrews outside of the allowed range, the response will be signed with
4072dfb9b865c82c24a72e734d54da51a20dfc1eMark Andrews the TSIG extended error code set to BADTIME, and the time values
92094d44a2d0cb2b1be58a87299903ba7c436a0cAndreas Gustafsson will be adjusted so that the response can be successfully
92094d44a2d0cb2b1be58a87299903ba7c436a0cAndreas Gustafsson verified. In any of these cases, the message's rcode is set to
d1abb8bb020aacd1ce0da65c2d5d8f7c96ebd52aMark AndrewsCLASS="sect1"
b6b9d8b8434e4eaab74b69cd14fcacf448055ca5Brian WellingtonCLASS="command"
31f6e44dcaad33d66d607e3a919d4aa59cdbaec5Andreas Gustafsson> is a mechanism for automatically
31f6e44dcaad33d66d607e3a919d4aa59cdbaec5Andreas Gustafsson generating a shared secret between two hosts. There are several
31f6e44dcaad33d66d607e3a919d4aa59cdbaec5Andreas GustafssonCLASS="command"
af36ecc41ae6bd73553aacd006ae55474e193b07Andreas Gustafsson> that specify how the key is
6d6529b5e5ab7223fa2560ebe144bcb82517cef3Mark Andrews generated or assigned. <SPAN
0b07b9482c00060d1ddd551a5dcb8cecbe2c1f65Mark AndrewsCLASS="acronym"
0b07b9482c00060d1ddd551a5dcb8cecbe2c1f65Mark Andrews> implements only one of these modes,
c0fe9b0d1b01a9a0883977a362ce4128723a56d6Mark Andrews the Diffie-Hellman key exchange. Both hosts are required to have
c0fe9b0d1b01a9a0883977a362ce4128723a56d6Mark Andrews a Diffie-Hellman KEY record (although this record is not required
2869504d83e84a91dbc822e8a243e837f5c0374dAndreas Gustafsson to be present in a zone). The <B
2869504d83e84a91dbc822e8a243e837f5c0374dAndreas GustafssonCLASS="command"
ce6caa07591b3723968c22f5aa13740f9609135aAndreas Gustafsson must use signed messages, signed either by TSIG or SIG(0). The
138cc7f283889367b11840ff77a9ea08e17a9daeAndreas GustafssonCLASS="command"
ac1a59e95cfd035f38222e739affd43eafa9eeefMark Andrews> is a shared secret that can be
58930ca9802e772afe9f5ccb30f236d201cf60e0Danny Mayer used to sign messages with TSIG. <B
58930ca9802e772afe9f5ccb30f236d201cf60e0Danny MayerCLASS="command"
e3e94dd137c5f9d3d5c5179863f674b27aa0cc02Andreas Gustafsson be used to delete shared secrets that it had previously
7c014c5bf41dc38802e8889c0a9110204eb1a552Andreas GustafssonCLASS="command"
7c014c5bf41dc38802e8889c0a9110204eb1a552Andreas Gustafsson> process is initiated by a client
7c014c5bf41dc38802e8889c0a9110204eb1a552Andreas Gustafsson or server by sending a signed <B
3e42bdfdc901b6b921b02028bd51ca2af8e84adcMark AndrewsCLASS="command"
3e42bdfdc901b6b921b02028bd51ca2af8e84adcMark Andrews (including any appropriate KEYs) to a TKEY-aware server. The
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark Andrews server response, if it indicates success, will contain a
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark AndrewsCLASS="command"
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark Andrews> record and any appropriate keys. After
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark Andrews this exchange, both participants have enough information to
b20eef7ab022dd984e2e9c12f6a7edf35661d3b0Mark Andrews determine the shared secret; the exact process depends on the
ea01b618d981e58f85071a40550bc7f7565d4509Andreas GustafssonCLASS="command"
bad3251d3f7ffccdec39ccfe04d94308985fb36eAndreas Gustafsson> mode. When using the Diffie-Hellman
9eec883bf871ee2235009e889440f986c98908b8Andreas GustafssonCLASS="command"
78bf1ca89505820ed7b03be4bf0c0b53b557f3cdAndreas Gustafsson> mode, Diffie-Hellman keys are exchanged,
78bf1ca89505820ed7b03be4bf0c0b53b557f3cdAndreas Gustafsson and the shared secret is derived by both participants.</P
afeabf9f707ca71192041c1132d9f07d7bd83132Mark AndrewsCLASS="sect1"
3842a051baf34ffc4e428cd6f2d4a641e548e6f6Mark AndrewsNAME="AEN889"
46ba6046bcb3b534346de13a4ff5c1513e72936bAndreas Gustafsson>4.6. SIG(0)</A
04f158ce9a12746eb216892b2bf8259749db254eAndreas GustafssonCLASS="acronym"
04f158ce9a12746eb216892b2bf8259749db254eAndreas Gustafsson> 9 partially supports DNSSEC SIG(0) transaction
04f158ce9a12746eb216892b2bf8259749db254eAndreas Gustafsson signatures as specified in RFC 2535. SIG(0) uses public/private
62c1fe7b450916acdaf4a3fe65a9b691d5d32f3fBrian Wellington keys to authenticate messages. Access control is performed in the
62c1fe7b450916acdaf4a3fe65a9b691d5d32f3fBrian Wellington same manner as TSIG keys; privileges can be granted or denied
62c1fe7b450916acdaf4a3fe65a9b691d5d32f3fBrian Wellington based on the key name.</P
712bf9b0cc4ed34f4bf33b437f8b0e45853b93ceMark Andrews>When a SIG(0) signed message is received, it will only be
7e2f4ceafaae4eac1deddc87f906b29a922fff9dAndreas Gustafsson verified if the key is known and trusted by the server; the server
7e2f4ceafaae4eac1deddc87f906b29a922fff9dAndreas Gustafsson will not attempt to locate and/or validate the key.</P
2053e8c26cd69600132632fbee247601ce8c9e8cAndreas Gustafsson>SIG(0) signing of multiple-message TCP streams is not
72499be79fbb68140bd31e0e4ded18a70a5b523bMark Andrews supported.</P
90c5477ca11a94b0e7d8071181d69544e1ab9be9Mark AndrewsCLASS="acronym"
552a117791c17878c5c1b94b0fc3ac4e8491543eMark Andrews> 9 does not ship with any tools that generate SIG(0)
f3e4c3d6c536973bae92611402ba55277069eba2Mark Andrews signed messages.</P
6fb633bc3fddba07fc9460ffd245b7ee2d459285Mark AndrewsCLASS="sect1"
ca033e166ca9f9dc7bf010065a93af668a09fd44Mark AndrewsCLASS="sect1"
ca033e166ca9f9dc7bf010065a93af668a09fd44Mark AndrewsNAME="DNSSEC"
f9321a16fb8dce8999a43a6d4008c54845305401Mark Andrews>4.7. DNSSEC</A
7a104af70fb3071e7949c4e0e585af18ab362db5Mark Andrews>Cryptographic authentication of DNS information is possible
7a104af70fb3071e7949c4e0e585af18ab362db5Mark Andrews through the DNS Security (<I
e70b069e3807d5f499dff31eb31c2b3e0e125457Mark AndrewsCLASS="emphasis"
923de3bb9cf4d619de206544975986a22b18196fMark Andrews>) extensions,
923de3bb9cf4d619de206544975986a22b18196fMark Andrews defined in RFC 2535. This section describes the creation and use
2359261a252b339f3cef046cefa10ee1e1d4564dMark Andrews of DNSSEC signed zones.</P
769cd7d5dd677434c3dfa27cbfdd8cb76296fcdcMark Andrews>In order to set up a DNSSEC secure zone, there are a series
769cd7d5dd677434c3dfa27cbfdd8cb76296fcdcMark Andrews of steps which must be followed. <SPAN
769cd7d5dd677434c3dfa27cbfdd8cb76296fcdcMark AndrewsCLASS="acronym"
11931cc68d6c8139f507a724e7ca9814eed8b552Mark Andrews with several tools
11931cc68d6c8139f507a724e7ca9814eed8b552Mark Andrews that are used in this process, which are explained in more detail
11931cc68d6c8139f507a724e7ca9814eed8b552Mark Andrews below. In all cases, the "<TT
11931cc68d6c8139f507a724e7ca9814eed8b552Mark Andrews>" option prints a
d91d025deffd075db2507d44fab04b79920b3e91Mark Andrews full list of parameters. Note that the DNSSEC tools require the
d91d025deffd075db2507d44fab04b79920b3e91Mark Andrews keyset and signedkey files to be in the working directory, and
d91d025deffd075db2507d44fab04b79920b3e91Mark Andrews that the tools shipped with BIND 9.0.x are not fully compatible
985b4f1c8653c6dfaa46652c412838850c0ffb1cMark Andrews with the current ones.</P
c8d9ff1fe871a0e9d5834240c5872a26166cc240Andreas Gustafsson>There must also be communication with the administrators of
1d556695ef3c7918ba5061d7d846122d60f5f6c5Mark Andrews the parent and/or child zone to transmit keys and signatures. A
e9ca87459a20f5e6721b9bd0b28c95fc3d6b843cMark Andrews zone's security status must be indicated by the parent zone for a
e9ca87459a20f5e6721b9bd0b28c95fc3d6b843cMark Andrews DNSSEC capable resolver to trust its data.</P
ca690f98020f75758bc26f4b5ef1ccf0472a27c3Mark Andrews>For other servers to trust data in this zone, they must
ca690f98020f75758bc26f4b5ef1ccf0472a27c3Mark Andrews either be statically configured with this zone's zone key or the
137a1f98e3862577ae9ccbb6b735ef63a51c456eMark Andrews zone key of another zone above this one in the DNS tree.</P
cc8e8b59d6780889739657226a95e23ca1ecadb1Andreas Gustafsson>4.7.1. Generating Keys</A
65775fe205e8ac935313c42062c75460e0bc1514Andreas GustafssonCLASS="command"
65775fe205e8ac935313c42062c75460e0bc1514Andreas Gustafsson>dnssec-keygen</B
65775fe205e8ac935313c42062c75460e0bc1514Andreas Gustafsson> program is used to
17b687ef360ba8c07201dc6511a3c975cc1bb2a8Andreas Gustafsson generate keys.</P
17b687ef360ba8c07201dc6511a3c975cc1bb2a8Andreas Gustafsson>A secure zone must contain one or more zone keys. The
17b687ef360ba8c07201dc6511a3c975cc1bb2a8Andreas Gustafsson zone keys will sign all other records in the zone, as well as
998358fa900393378c70ad598c2b2e67385089d4Mark Andrews the zone keys of any secure delegated zones. Zone keys must
998358fa900393378c70ad598c2b2e67385089d4Mark Andrews have the same name as the zone, a name type of
998358fa900393378c70ad598c2b2e67385089d4Mark AndrewsCLASS="command"
bc508906db43dda7eab0988348dd0ae3f3023a9bMark Andrews>, and must be usable for authentication.
bc508906db43dda7eab0988348dd0ae3f3023a9bMark Andrews It is recommended that zone keys be mandatory to implement a
b352902413608d0eb310c4bb45412fa45734afbcAndreas Gustafsson cryptographic algorithm; currently the only key mandatory to
b352902413608d0eb310c4bb45412fa45734afbcAndreas Gustafsson implement an algorithm is DSA.</P
b352902413608d0eb310c4bb45412fa45734afbcAndreas Gustafsson>The following command will generate a 768 bit DSA key for
b352902413608d0eb310c4bb45412fa45734afbcAndreas GustafssonCLASS="filename"
c8ab83c08e5227b5146295a9ef4a96d61b066b67Andreas GustafssonCLASS="userinput"
4e57d3ff7d92abdef4b0b6aebc23a9dfae2ba040Andreas Gustafsson>dnssec-keygen -a DSA -b 768 -n ZONE child.example.</B
be9932698bf35d0f34e65b5ffbb81bedddd76636Mark Andrews>Two output files will be produced:
d352f188cb9e3820054b7451384a3d910619b4a1Andreas GustafssonCLASS="filename"
081cff0c33514a5dc63ab794fc199c07377ab756Mark AndrewsCLASS="filename"
a7cb695600c3c14ac12676f0fb1e179690c5883cMark Andrews 12345 is an example of a key tag). The key file names contain
a7cb695600c3c14ac12676f0fb1e179690c5883cMark Andrews the key name (<TT
479c6fc4584e062088ceee037690cdff85fc349bAndreas GustafssonCLASS="filename"
1500a4fe5da9475d5918b27b566a1278ec6b54ebAndreas Gustafsson>), algorithm (3
1500a4fe5da9475d5918b27b566a1278ec6b54ebAndreas Gustafsson is DSA, 1 is RSA, etc.), and the key tag (12345 in this case).
1255d388f034dc556d235a002527101781dbeb29Mark Andrews The private key (in the <TT
1255d388f034dc556d235a002527101781dbeb29Mark AndrewsCLASS="filename"
c615c2ddce6c08e5a26d9ca61742a20fa8dc1938Mark Andrews>.private</TT
c615c2ddce6c08e5a26d9ca61742a20fa8dc1938Mark Andrews used to generate signatures, and the public key (in the
31d3464c0c0a35236c7924f698c5a8a66a9ed534Mark AndrewsCLASS="filename"
f04c15adc7e62deb2f53cc53f32d890936007903Andreas Gustafsson> file) is used for signature
f04c15adc7e62deb2f53cc53f32d890936007903Andreas Gustafsson verification.</P
53c07ca2164f8a083aa97591345bf4339a8573bdAndreas Gustafsson>To generate another key with the same properties (but with
d1029cbcf03a0a2a6c05c1e17e692d844eb27094Andreas Gustafsson a different key tag), repeat the above command.</P
32d248107a5bc92b4bf9fc77deaa55b3da969ba2Andreas Gustafsson>The public keys should be inserted into the zone file with
32d248107a5bc92b4bf9fc77deaa55b3da969ba2Andreas GustafssonCLASS="command"
4574714ad44ba97f53425fe8d21b7ecb00ac83b9Andreas Gustafsson> statements, including the
4574714ad44ba97f53425fe8d21b7ecb00ac83b9Andreas GustafssonCLASS="filename"
07eaf0b8d0c3c93d8139c413bf9cc8bba7db9432Mark AndrewsCLASS="sect2"
cf70df7d0e24401a358f0b9c1a616ad0e8c783a6Mark AndrewsCLASS="sect2"
9234d92d4e274791eff42cc4ea5766ed7a281b17Mark AndrewsNAME="AEN926"
9234d92d4e274791eff42cc4ea5766ed7a281b17Mark Andrews>4.7.2. Creating a Keyset</A
0cf9ce19cc05a60f85ec610106a983fe806ebb77Andreas GustafssonCLASS="command"
0cf9ce19cc05a60f85ec610106a983fe806ebb77Andreas Gustafsson>dnssec-makekeyset</B
42f61e5c46d4824918385e7279c1b71d8ada8e8dAndreas Gustafsson> program is used
2ba574f329c14376d26d7c0f22c89d7a978a2625Mark Andrews to create a key set from one or more keys.</P
3c3fe072252aecffae43e6349125663c315b092dAndreas Gustafsson>Once the zone keys have been generated, a key set must be
3c3fe072252aecffae43e6349125663c315b092dAndreas Gustafsson built for transmission to the administrator of the parent zone,
3c3fe072252aecffae43e6349125663c315b092dAndreas Gustafsson so that the parent zone can sign the keys with its own zone key
3c3fe072252aecffae43e6349125663c315b092dAndreas Gustafsson and correctly indicate the security status of this zone. When
64ea5fd972c9946a3fe56cbc0bf897266d3f8747Andreas Gustafsson building a key set, the list of keys to be included and the TTL
64ea5fd972c9946a3fe56cbc0bf897266d3f8747Andreas Gustafsson of the set must be specified, and the desired signature validity
05a4a299b599195ca6ede9395b245956a8c3a790Mark Andrews period of the parent's signature may also be specified.</P
3ad07fa335d40330cd1859da42e67f2457443990Andreas Gustafsson>The list of keys to be inserted into the key set may also
3ad07fa335d40330cd1859da42e67f2457443990Andreas Gustafsson included non-zone keys present at the top of the zone.
1094dec52a86e57df53f6167d86de94360a7a382Mark AndrewsCLASS="command"
64ea5fd972c9946a3fe56cbc0bf897266d3f8747Andreas Gustafsson>dnssec-makekeyset</B
1094dec52a86e57df53f6167d86de94360a7a382Mark Andrews> may also be used at other
fa2fb620c7c0a907b220c257007d8fb6d38bb3a4Andreas Gustafsson names in the zone.</P
fa2fb620c7c0a907b220c257007d8fb6d38bb3a4Andreas Gustafsson>The following command generates a key set containing the
fa2fb620c7c0a907b220c257007d8fb6d38bb3a4Andreas Gustafsson above key and another key similarly generated, with a TTL of
fa2fb620c7c0a907b220c257007d8fb6d38bb3a4Andreas Gustafsson 3600 and a signature validity period of 10 days starting from
62a3dbe63e833f2eaf613393399ea4667d8de28dAndreas GustafssonCLASS="userinput"
248732d66fffb557e84264c2bb2fb43ac766163fAndreas Gustafsson>dnssec-makekeyset -t 3600 -e +864000 Kchild.example.+003+12345 Kchild.example.+003+23456</B
e69b9ffb0f8b4d1117a682908c9143ebe3efcd6bAndreas Gustafsson>One output file is produced:
417872b98aec720d587a9ef0197e25e78a2b7ee9Mark AndrewsCLASS="filename"
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas Gustafsson>. This file should be
a77ad145d0109081c5da6ac40a2303369db89735Andreas Gustafsson transmitted to the parent to be signed. It includes the keys,
8ba4e82f5358815fd94f34fde408ffd047ba3430Andreas Gustafsson as well as signatures over the key set generated by the zone
8ba4e82f5358815fd94f34fde408ffd047ba3430Andreas Gustafsson keys themselves, which are used to prove ownership of the
61d5bfc06be978ea962b1c64309894ac80351771Mark Andrews private keys and encode the desired validity period.</P
ada9b8ab20b81716c7ff1f4f3365929b2f7c8ff8Mark AndrewsCLASS="sect2"
bb60abb44549428414cd55a022f2b8cc4488f7adAndreas Gustafsson>4.7.3. Signing the Child's Keyset</A
024face21cdfbfc7a862a3be061e6780533ef755Andreas GustafssonCLASS="command"
024face21cdfbfc7a862a3be061e6780533ef755Andreas Gustafsson>dnssec-signkey</B
024face21cdfbfc7a862a3be061e6780533ef755Andreas Gustafsson> program is used to
1beaa9e45738ad18cb7cae55aea95a1b16a14f94Andreas Gustafsson sign one child's keyset.</P
f953788d75c7df2db43907c68da18ed75c235dd3Andreas GustafssonCLASS="filename"
9df7cf8ea31d8d26f9c1be55f2cdafdc68d63c53Andreas Gustafsson delegations which are secure, for example,
fbdde79262a4ba2bdf4bfae61167026b3220488aAndreas GustafssonCLASS="filename"
fbdde79262a4ba2bdf4bfae61167026b3220488aAndreas GustafssonCLASS="filename"
a7e1dcd84ada7e4e4c78f3f281e8a4d99adaf4d1Andreas Gustafsson> administrator should receive
a7e1dcd84ada7e4e4c78f3f281e8a4d99adaf4d1Andreas Gustafsson keyset files for each secure subzone. These keys must be signed
a7e1dcd84ada7e4e4c78f3f281e8a4d99adaf4d1Andreas Gustafsson by this zone's zone keys.</P
2975d0f819762614526c650b9c2077ef22f81328Andreas Gustafsson>The following command signs the child's key set with the
0bd2ea544e95601e0f0b056acfa079c99d5f6b57Andreas GustafssonCLASS="userinput"
5f7516bee5ace9542701f23fc7723a3e3196802aMark Andrews>dnssec-signkey keyset-grand.child.example. Kchild.example.+003+12345 Kchild.example.+003+23456</B
3c17010ba5a6b8dd8a2bbc550813c7f051f45a08Andreas Gustafsson>One output file is produced:
3c17010ba5a6b8dd8a2bbc550813c7f051f45a08Andreas GustafssonCLASS="filename"
df7596a03eea7f1c2df89bd63d3bd4b73f274565Mark Andrews should be both transmitted back to the child and retained. It
df7596a03eea7f1c2df89bd63d3bd4b73f274565Mark Andrews includes all keys (the child's keys) from the keyset file and
df7596a03eea7f1c2df89bd63d3bd4b73f274565Mark Andrews signatures generated by this zone's zone keys.</P
b923e278535b4e8d264998a85a6ae1eb4b3aa4c6Andreas Gustafsson>4.7.4. Signing the Zone</A
edf97be2b54cbdc4f3f3a46776df3e912892e960Andreas GustafssonCLASS="command"
edf97be2b54cbdc4f3f3a46776df3e912892e960Andreas Gustafsson>dnssec-signzone</B
769ef0b7bdc9520dd62d2f440ea36bc020e88934Andreas Gustafsson> program is used to
9e46f410e716f73abb345be215ccb4c61782b718Andreas Gustafsson sign a zone.</P
769ef0b7bdc9520dd62d2f440ea36bc020e88934Andreas GustafssonCLASS="filename"
b09f4e054cbe67b93a5ff62d511ee25945038943Mark Andrews> files corresponding to
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas Gustafsson secure subzones should be present, as well as a
3d3445447225ab63f49fc24362963ea49ce94901Andreas GustafssonCLASS="filename"
3d3445447225ab63f49fc24362963ea49ce94901Andreas Gustafsson> file for this zone generated by
40dd9cb8cc240c33d820fe79f176ed51e4c06a1aMark Andrews the parent (if there is one). The zone signer will generate
96ea98af241ef00395f4e61de7e2dacfd9941afcMark AndrewsCLASS="literal"
54c4aa0f62aebeb01b6861ee068c1044433fe8feMark AndrewsCLASS="literal"
792de65053d8a48d05746b35a21a9fa1792e71acAndreas Gustafsson the zone, as well as incorporate the zone key signature from the
808b909f27c30d36b27efb5aa5ef2d18f83b6d4bAndreas Gustafsson parent and indicate the security status at all delegation
3e934267660cb13029bcdbddf318fe1cc27b6718Andreas Gustafsson>The following command signs the zone, assuming it is in a
846474d5a6aa21cebb3e94243a11faa5c20200bfAndreas Gustafsson file called <TT
7655e78c366cc0d25e24e2a96ba58e04a96042faAndreas GustafssonCLASS="filename"
6859033d425170380bcfac4809257bc6e9b60383Andreas Gustafsson default, all zone keys which have an available private key are
6859033d425170380bcfac4809257bc6e9b60383Andreas Gustafsson used to generate signatures.</P
5419c0c2d0b77682021084c69f2a5c5e2f9a5525Andreas GustafssonCLASS="userinput"
ff4322d44f8404683b6fb6c86a38a2bc14f6c083Andreas Gustafsson>dnssec-signzone -o child.example zone.child.example</B
8d146b6e1156f5b562af9a4a9aba76b09650412cAndreas Gustafsson>One output file is produced:
8d146b6e1156f5b562af9a4a9aba76b09650412cAndreas GustafssonCLASS="filename"
808b909f27c30d36b27efb5aa5ef2d18f83b6d4bAndreas Gustafsson should be referenced by <TT
595a14576ea14884c35b3726f054f2065365620bMark AndrewsCLASS="filename"
640923da589bc5b8492ac407ef89ea1ee9a1c358Andreas Gustafsson input file for the zone.</P
640923da589bc5b8492ac407ef89ea1ee9a1c358Andreas Gustafsson>4.7.5. Configuring Servers</A
aa30ee42c4b6da9bab4fb84d6cbbda6036a4d426Mark Andrews>Unlike in <SPAN
aa30ee42c4b6da9bab4fb84d6cbbda6036a4d426Mark AndrewsCLASS="acronym"
01446841be2b73f9a2ead74056df2d5342414041Andreas Gustafssondata is not verified on load in <SPAN
01446841be2b73f9a2ead74056df2d5342414041Andreas GustafssonCLASS="acronym"
28cf7340b9c82fc62ca1a1782cb1bd7b0de11aebAndreas Gustafssonso zone keys for authoritative zones do not need to be specified
28cf7340b9c82fc62ca1a1782cb1bd7b0de11aebAndreas Gustafssonin the configuration file.</P
1de63e34f163b7a4708a6ad1779f93ae7636b92eAndreas Gustafsson>The public key for any security root must be present in
1de63e34f163b7a4708a6ad1779f93ae7636b92eAndreas Gustafssonthe configuration file's <B
feb1f6a4ac42988558ecb8dc5dc0c974ec1f0509Brian WellingtonCLASS="command"
feb1f6a4ac42988558ecb8dc5dc0c974ec1f0509Brian Wellington>trusted-keys</B
ea34bcc6376555296a08e4c9e2f9c2cbe58378a9Andreas Gustafssonstatement, as described later in this document. </P
e6f17474cb43a138bf7fc9ad30c6b3a2847cb7a7Mark AndrewsNAME="AEN974"
5fe21da364d4397c9a413fe689ce82dea36a7b29Mark Andrews>4.8. IPv6 Support in <SPAN
5fe21da364d4397c9a413fe689ce82dea36a7b29Mark AndrewsCLASS="acronym"
5c831a1a1b14470037de6d8bc0501aea5dc6cacdAndreas GustafssonCLASS="acronym"
98e231525fda817d393ef0c529b50bfc08cebe47Mark Andrews> 9 fully supports all currently defined forms of IPv6
98e231525fda817d393ef0c529b50bfc08cebe47Mark Andrews name to address and address to name lookups. It will also use
98e231525fda817d393ef0c529b50bfc08cebe47Mark Andrews IPv6 addresses to make queries when running on an IPv6 capable
d4196128b31d511c8513edacc70dea7e8d0c053aMark Andrews>For forward lookups, <SPAN
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas GustafssonCLASS="acronym"
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas Gustafsson> 9 supports both A6 and AAAA
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas Gustafsson records. The use of AAAA records is deprecated, but it is still
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas Gustafsson useful for hosts to have both AAAA and A6 records to maintain
4a20a92f4f96cf2b2fd77898c6afec6c45e481b3Andreas Gustafsson backward compatibility with installations where AAAA records are
56d69016f4fae2eda4d39c92fe13595251aaadd3Mark Andrews still used. In fact, the stub resolvers currently shipped with
e60b3717f0e6f28d6fb2c5124ffb3bd31cc3a746Mark Andrews most operating system support only AAAA lookups, because following
e60b3717f0e6f28d6fb2c5124ffb3bd31cc3a746Mark Andrews A6 chains is much harder than doing A or AAAA lookups.</P
3d8ab44d14f3de797b8454fc2edb7421a6bfc874Andreas Gustafsson>For IPv6 reverse lookups, <SPAN
3d8ab44d14f3de797b8454fc2edb7421a6bfc874Andreas GustafssonCLASS="acronym"
3426f7118c92cab8714a7fddc9e721ff09554447Andreas Gustafsson> 9 supports the new
db235e65884c04058cc6e99ca485170d67cf9538Andreas Gustafsson "bitstring" format used in the <I
db235e65884c04058cc6e99ca485170d67cf9538Andreas GustafssonCLASS="emphasis"
64a5004a66accd190bfd5ddf115667726537be50Andreas Gustafsson domain, as well as the older, deprecated "nibble" format used in
64a5004a66accd190bfd5ddf115667726537be50Andreas GustafssonCLASS="emphasis"
b1ae7a591a4b99a26036e919b87247b65abfcd77Mark AndrewsCLASS="acronym"
6dbc6fae496db1f584c055e63bcd7afd332fe8f6Andreas Gustafsson> 9 includes a new lightweight resolver library and
cab0ee644db604d56b45ec39429d505d635da347Andreas Gustafsson resolver daemon which new applications may choose to use to avoid
cab0ee644db604d56b45ec39429d505d635da347Andreas Gustafsson the complexities of A6 chain following and bitstring labels, see <A
7780a3e5a4659bb8fc44f8915d20a8d3ffa33e00Andreas Gustafsson>For an overview of the format and structure of IPv6 addresses,
6dbc6fae496db1f584c055e63bcd7afd332fe8f6Andreas GustafssonHREF="Bv9ARM.ch09.html#ipv6addresses"
6dbc6fae496db1f584c055e63bcd7afd332fe8f6Andreas Gustafsson>Section A.3.1</A
a24d253a3f4e6f4036800744b348fba858d4959eMark AndrewsCLASS="sect2"
3f543c371fff724d1fb05eb564f732476e946b5bBrian Wellington>4.8.1. Address Lookups Using AAAA Records</A
847169dab2d0496df1d66842b2cce67c66bf9680Andreas Gustafsson>The AAAA record is a parallel to the IPv4 A record. It
9aba20edee4e704433a464ae43b070b0775de506Mark Andrews specifies the entire address in a single record. For
ed03e26c44347ec20aff6608de6082e3594d95fbMark AndrewsCLASS="programlisting"
e8d86192fc424f49e43df9cee439ca5c793e6000Mark Andrewshost 3600 IN AAAA 3ffe:8050:201:1860:42::1
bae5d9fcb4616005fbc861e327b0a48b7bd4d89aMark Andrews>While their use is deprecated, they are useful to support
bae5d9fcb4616005fbc861e327b0a48b7bd4d89aMark Andrews older IPv6 applications. They should not be added where they
e8d86192fc424f49e43df9cee439ca5c793e6000Mark Andrews are not absolutely necessary.</P
98a5dc52bf668b093cda7901c057f7b54e18a2fcAndreas Gustafsson>4.8.2. Address Lookups Using A6 Records</A
452b30ddb32dd9370b2e5ee10427dd3758ef98b4Mark Andrews>The A6 record is more flexible than the AAAA record, and
452b30ddb32dd9370b2e5ee10427dd3758ef98b4Mark Andrews is therefore more complicated. The A6 record can be used to
6668eca26bf3123750afda48b69991bd29d83807Mark Andrews form a chain of A6 records, each specifying part of the IPv6
1299e93989afbe1fee0739811b05fd1641ea14aeAndreas Gustafsson address. It can also be used to specify the entire record as
6668eca26bf3123750afda48b69991bd29d83807Mark Andrews well. For example, this record supplies the same data as the
773e64ec150c33269e748d96dd95726ed7e0d842Mark Andrews AAAA record in the previous example:</P
cb8fd52bbeaf40c9166a0144541c4ff2bafc2dd6Andreas GustafssonCLASS="programlisting"
cad3210bb95057a37aaed20bc8a1542e0534422cAndreas Gustafssonhost 3600 IN A6 0 3ffe:8050:201:1860:42::1
afeded2289de8d193b072da2b44a2d580cc235c1Danny MayerNAME="AEN999"
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer>4.8.2.1. A6 Chains</A
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer>A6 records are designed to allow network
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer renumbering. This works when an A6 record only specifies the
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer part of the address space the domain owner controls. For
afeded2289de8d193b072da2b44a2d580cc235c1Danny Mayer example, a host may be at a company named "company." It has
f462b9aed23b77bda867301f80ead6990df6f4f8Andreas Gustafsson two ISPs which provide IPv6 address space for it. These two
89555ff443c8127a533f6c742316c9b1a713cfd5Mark Andrews ISPs fully specify the IPv6 prefix they supply.</P
aa9a67adeb48069f5c2e5d8936a8ed5aac7d6ad7Andreas Gustafsson>In the company's address space:</P
aa9a67adeb48069f5c2e5d8936a8ed5aac7d6ad7Andreas GustafssonCLASS="programlisting"
aa9a67adeb48069f5c2e5d8936a8ed5aac7d6ad7Andreas Gustafssonhost 3600 IN A6 64 0:0:0:0:42::1 company.example1.net.
73ac1894ea64bc50aff7406872d0e9c5df6d9cf6Mark Andrewshost 3600 IN A6 64 0:0:0:0:42::1 company.example2.net.
e22dca2a9ad30d493a869586abed86f7268204f9Mark Andrews>ISP1 will use:</P
e22dca2a9ad30d493a869586abed86f7268204f9Mark AndrewsCLASS="programlisting"
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas Gustafssoncompany 3600 IN A6 0 3ffe:8050:201:1860::
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas Gustafsson>ISP2 will use:</P
ea72586fc5c360539117119ee35e4c3a04b912bcAndreas GustafssonCLASS="programlisting"
6f7660093e70d3a7c80738b681ac0f5c1b661c00Mark Andrewscompany 3600 IN A6 0 1234:5678:90ab:fffa::
a1898260ad19d02e88ab76c1855d33c67add9defMark AndrewsCLASS="literal"
305b0eda33b16493355db1f1c86313a6f5fbfc3bDanny Mayer> is looked up,
305b0eda33b16493355db1f1c86313a6f5fbfc3bDanny Mayer the resolver (in the resolver daemon or caching name server)
305b0eda33b16493355db1f1c86313a6f5fbfc3bDanny Mayer will find two partial A6 records, and will use the additional
305b0eda33b16493355db1f1c86313a6f5fbfc3bDanny Mayer name to find the remainder of the data.</P
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson>4.8.2.2. A6 Records for DNS Servers</A
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson>When an A6 record specifies the address of a name
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson server, it should use the full address rather than specifying
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson a partial address. For example:</P
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas GustafssonCLASS="programlisting"
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson@ 14400 IN NS ns0
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafsson 14400 IN NS ns1
c0b6c1a5ab50722793cb99b0d8a1e9e910c146a5Andreas Gustafssonns0 14400 IN A6 0 3ffe:8050:201:1860:42::1
ec5a06ccf7b15f07d20fd872c3dc1ab8f82f2ceaMark Andrewsns1 14400 IN A 192.168.42.1
907ec2c618d08d8322b04729779b24bd778d49e7Mark Andrews>It is recommended that IPv4-in-IPv6 mapped addresses not
23a020bc1312fc35e7c4ea36df846c550cb13634Andreas Gustafsson be used. If a host has an IPv4 address, use an A record, not
0a532842050020a1b0577c65f91f38bd022daa78Andreas Gustafsson an A6, with <TT
0a532842050020a1b0577c65f91f38bd022daa78Andreas GustafssonCLASS="literal"
0a532842050020a1b0577c65f91f38bd022daa78Andreas Gustafsson>::ffff:192.168.42.1</TT
7250c1a2616761395bdb9ae7cd1ba43f20d3edc4Andreas Gustafsson>4.8.3. Address to Name Lookups Using Nibble Format</A
c38b92000c0f1a95daaad5468777e165b8047de9Mark Andrews>While the use of nibble format to look up names is
4d77dbcfa052c065a87d2d35b116f17b74bae573Andreas Gustafsson deprecated, it is supported for backwards compatiblity with
c38b92000c0f1a95daaad5468777e165b8047de9Mark Andrews existing IPv6 applications.</P
c38b92000c0f1a95daaad5468777e165b8047de9Mark Andrews>When looking up an address in nibble format, the address
a5b9c2b208b51b039c8f4006cddf3d37dd781561Brian Wellington components are simply reversed, just as in IPv4, and
22f0b13f28a7df3b348b18848d0ccd745ea88c3cAndreas GustafssonCLASS="literal"
22f0b13f28a7df3b348b18848d0ccd745ea88c3cAndreas Gustafsson> is appended to the resulting name.
ee3ab6063dd13b5947d3fbe88b9ce8f38d65df9dBrian Wellington For example, the following would provide reverse name lookup for
9261ca5fc8a564968f34e108eb862157471ca50eAndreas Gustafsson a host with address
d81622b537be1971530cfb459acdbbe7d82d883bBrian WellingtonCLASS="literal"
d81622b537be1971530cfb459acdbbe7d82d883bBrian Wellington>3ffe:8050:201:1860:42::1</TT
aec9f4d0723b0cffcfa9152533fb8f616ec7313bAndreas GustafssonCLASS="programlisting"
a5b9c2b208b51b039c8f4006cddf3d37dd781561Brian Wellington> $ORIGIN 0.6.8.1.1.0.2.0.0.5.0.8.e.f.f.3.ip6.int.
2da0b7dfbd02fab454b8ba60f1fdb7e2a5cbd2dbMark Andrews1.0.0.0.0.0.0.0.0.0.0.0.2.4.0.0 14400 IN PTR host.example.com.
2033e305852d4b76772885ea73ebfb6776c1f820Mark AndrewsCLASS="sect2"
6443201354efa09f16ada26dab99e9b7f8271521Andreas Gustafsson>4.8.4. Address to Name Lookups Using Bitstring Format</A
e980502db40155234b4e8d320b748b34dbaba3a2Brian Wellington>Bitstring labels can start and end on any bit boundary,
e980502db40155234b4e8d320b748b34dbaba3a2Brian Wellington rather than on a multiple of 4 bits as in the nibble
ecd1addb86319bacc6c0bff2c68373619eebbffcMark Andrews format. They also use <I
ecd1addb86319bacc6c0bff2c68373619eebbffcMark AndrewsCLASS="emphasis"
0176adc7c58bb8bd60ec71eeae94dbfbbc4018a8Mark Andrews> rather than
ea20115e347264b9bc1c686d6dfc1b5af3a5516bAndreas GustafssonCLASS="emphasis"
aa0dc8d920a1f79626c3564408db9c5c9a5319a7Andreas Gustafsson>To replicate the previous example using bitstrings:</P
aa0dc8d920a1f79626c3564408db9c5c9a5319a7Andreas GustafssonCLASS="programlisting"
aa0dc8d920a1f79626c3564408db9c5c9a5319a7Andreas Gustafsson> $ORIGIN \[x3ffe805002011860/64].ip6.arpa.
47d48791fc352fcdf9019200070221be41a8d77cMark Andrews\[x0042000000000001/64] 14400 IN PTR host.example.com.
22815444822da17fab82d4ab115da6e055ea1754Brian Wellington>4.8.5. Using DNAME for Delegation of IPv6 Reverse Addresses</A
22815444822da17fab82d4ab115da6e055ea1754Brian Wellington>In IPV6, the same host may have many addresses from many
35db8a8eda6a889675138eb125d366c8851f68a5Andreas Gustafsson network providers. Since the trailing portion of the address
35db8a8eda6a889675138eb125d366c8851f68a5Andreas Gustafsson usually remains constant, <B
35db8a8eda6a889675138eb125d366c8851f68a5Andreas GustafssonCLASS="command"
bd6504aa9aa16a912412fbe010046aaf4bf23621Brian Wellington reduce the number of zone files used for reverse mapping that
5e88852b94830bf71e37dc700d568cb35e2e6f7eAndreas Gustafsson need to be maintained.</P
bd6504aa9aa16a912412fbe010046aaf4bf23621Brian Wellington>For example, consider a host which has two providers
bd6504aa9aa16a912412fbe010046aaf4bf23621Brian WellingtonCLASS="literal"
c54210716ee55b55e22d8dad56fd696a641fc98dBob HalleyCLASS="literal"
c54210716ee55b55e22d8dad56fd696a641fc98dBob Halley therefore two IPv6 addresses. Since the host chooses its own 64
3fcf6b956f47405750724bd84e1b2290b61c9186Brian Wellington bit host address portion, the provider address is the only part
82c65f4f62819340ef8198932d3eab8a308a4874Andreas Gustafsson that changes:</P
1e289d3cca5cdd01dda650fa6e4c1de1aa8b4196Andreas GustafssonCLASS="programlisting"
0a2d5c990559ce2b9f95df752db6e93024d9a250Brian Wellingtonhost IN A6 64 ::1234:5678:1212:5675 cust1.example.net.
96ed62425310854fd6f6f06bfb7651b3e4c17ee7Andreas Gustafsson IN A6 64 ::1234:5678:1212:5675 subnet5.example2.net.
96ed62425310854fd6f6f06bfb7651b3e4c17ee7Andreas Gustafssoncust1 IN A6 48 0:0:0:dddd:: ipv6net.example.net.
96ed62425310854fd6f6f06bfb7651b3e4c17ee7Andreas Gustafssonipv6net IN A6 0 aa:bb:cccc::
96ed62425310854fd6f6f06bfb7651b3e4c17ee7Andreas Gustafssonsubnet5 IN A6 48 0:0:0:1:: ipv6net2.example2.net.
5733d25b06b46067b3751d10436d82aef09cd705Brian Wellingtonipv6net2 IN A6 0 6666:5555:4::
5733d25b06b46067b3751d10436d82aef09cd705Brian Wellington>This sets up forward lookups. To handle the reverse lookups,
82c65f4f62819340ef8198932d3eab8a308a4874Andreas Gustafssonthe provider <TT
5733d25b06b46067b3751d10436d82aef09cd705Brian WellingtonCLASS="literal"
eb6e3b04169a766d2b968bcc978191605c2ef24cAndreas GustafssonCLASS="programlisting"
eb6e3b04169a766d2b968bcc978191605c2ef24cAndreas Gustafsson> $ORIGIN \[x00aa00bbcccc/48].ip6.arpa.
eb6e3b04169a766d2b968bcc978191605c2ef24cAndreas Gustafsson\[xdddd/16] IN DNAME ipv6-rev.example.com.
82c65f4f62819340ef8198932d3eab8a308a4874Andreas GustafssonCLASS="literal"
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson> would have:</P
a26ad011f382d12058478704cb5e90e6f4366d01Andreas GustafssonCLASS="programlisting"
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson> $ORIGIN \[x666655550004/48].ip6.arpa.
57188b5ff2397c0517e55f622879e69ee547918dAndreas Gustafsson\[x0001/16] IN DNAME ipv6-rev.example.com.
9a72459b6040b30d043c5fd9e283441b847e569aAndreas GustafssonCLASS="literal"
07c336a9a85791dff886b1e28514589a25d9b720Andreas Gustafsson needs only one zone file to handle both of these reverse
07c336a9a85791dff886b1e28514589a25d9b720Andreas GustafssonCLASS="programlisting"
07c336a9a85791dff886b1e28514589a25d9b720Andreas Gustafsson\[x1234567812125675/64] IN PTR host.example.com.
5613bf7de9760875da9f5fbc6ffcd93e0af967ffMark AndrewsCLASS="NAVFOOTER"
9bfa90768ab83ea5a8571c98d3774377da4bdcbeDavid LawrenceCELLPADDING="0"
9bfa90768ab83ea5a8571c98d3774377da4bdcbeDavid LawrenceCELLSPACING="0"
41626c0997c89dcdecf67c931f0031aadd507977Andreas Gustafsson>Nameserver Configuration</TD
464c2e4bb960d15bd60d53c3ef3ae7414b129037David LawrenceALIGN="center"
6112718b0dbb01ffbfd3fabc61e30c7e4485b0a7David LawrenceCLASS="acronym"
04260c5c48d234734863f0222e207b6564cd41a8David Lawrence> 9 Lightweight Resolver</TD