Bv9ARM.ch04.html revision a87790b9d8e062fac1b2dfb8903e77bfe92a3891
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - Copyright (C) 2004-2014 Internet Systems Consortium, Inc. ("ISC")
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - Copyright (C) 2000-2003 Internet Software Consortium.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - Permission to use, copy, modify, and/or distribute this software for any
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - purpose with or without fee is hereby granted, provided that the above
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - copyright notice and this permission notice appear in all copies.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync - PERFORMANCE OF THIS SOFTWARE.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<!-- $Id$ -->
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<link rel="up" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<link rel="prev" href="Bv9ARM.ch03.html" title="Chapter�3.�Name Server Configuration">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<link rel="next" href="Bv9ARM.ch05.html" title="Chapter�5.�The BIND 9 Lightweight Resolver">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<tr><th colspan="3" align="center">Chapter�4.�Advanced DNS Features</th></tr>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a accesskey="p" href="Bv9ARM.ch03.html">Prev</a>�</td>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<td width="20%" align="right">�<a accesskey="n" href="Bv9ARM.ch05.html">Next</a>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a name="Bv9ARM.ch04"></a>Chapter�4.�Advanced DNS Features</h2></div></div></div>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#notify">Notify</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#dynamic_update">Dynamic Update</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dd><dl><dt><span class="sect2"><a href="Bv9ARM.ch04.html#journal">The journal file</a></span></dt></dl></dd>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#incremental_zone_transfers">Incremental Zone Transfers (IXFR)</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#id2569971">Split DNS</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dd><dl><dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2569989">Example split DNS setup</a></span></dt></dl></dd>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#tsig">TSIG</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2570490">Generate Shared Keys for Each Pair of Hosts</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2570564">Copying the Shared Secret to Both Machines</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2570574">Informing the Servers of the Key's Existence</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2570611">Instructing the Server to Use the Key</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2570668">TSIG Key Based Access Control</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2570717">Errors</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#id2570731">TKEY</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#id2570780">SIG(0)</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#DNSSEC">DNSSEC</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2570985">Generating Keys</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571201">Signing the Zone</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571282">Configuring Servers</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#dnssec.dynamic.zones">DNSSEC, Dynamic Zones, and Automatic Signing</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2611019">Converting from insecure to secure</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2611057">Dynamic DNS update method</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2563511">Fully automatic zone signing</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2563683">Private-type records</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2563857">DNSKEY rollovers</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2563869">Dynamic DNS update method</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2581515">Automatic key rollovers</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2581542">NSEC3PARAM rollovers via UPDATE</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2581552">Converting from NSEC to NSEC3</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2581561">Converting from NSEC3 to NSEC</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2581574">Converting from secure to insecure</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2581611">Periodic re-signing</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2581621">NSEC3 and OPTOUT</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#rfc5011.support">Dynamic Trust Anchor Management</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2610872">Validating Resolver</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2610894">Authoritative Server</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#pkcs11">PKCS#11 (Cryptoki) support</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2665877">Prerequisites</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2610795">Native PKCS#11</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2611081">OpenSSL-based PKCS#11</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2638395">PKCS#11 Tools</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2638432">Using the HSM</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2638854">Specifying the engine on the command line</a></span></dt>
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2638902">Running named with automatic zone re-signing</a></span></dt>
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#dlz-info">DLZ (Dynamically Loadable Zones)</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2612137">Configuring DLZ</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2611596">Sample DLZ Driver</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect1"><a href="Bv9ARM.ch04.html#id2571574">IPv6 Support in <acronym class="acronym">BIND</acronym> 9</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571841">Address Lookups Using AAAA Records</a></span></dt>
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync<dt><span class="sect2"><a href="Bv9ARM.ch04.html#id2571862">Address to Name Lookups Using Nibble Format</a></span></dt>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<div class="titlepage"><div><div><h2 class="title" style="clear: both">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <acronym class="acronym">DNS</acronym> NOTIFY is a mechanism that allows master
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync servers to notify their slave servers of changes to a zone's data. In
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync response to a <span><strong class="command">NOTIFY</strong></span> from a master server, the
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync slave will check to see that its version of the zone is the
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync current version and, if not, initiate a zone transfer.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync For more information about <acronym class="acronym">DNS</acronym>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">NOTIFY</strong></span>, see the description of the
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">notify</strong></span> option in <a href="Bv9ARM.ch06.html#boolean_options" title="Boolean Options">the section called “Boolean Options”</a> and
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync the description of the zone option <span><strong class="command">also-notify</strong></span> in
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <a href="Bv9ARM.ch06.html#zone_transfers" title="Zone Transfers">the section called “Zone Transfers”</a>. The <span><strong class="command">NOTIFY</strong></span>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync protocol is specified in RFC 1996.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync As a slave zone can also be a master to other slaves, <span><strong class="command">named</strong></span>,
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync by default, sends <span><strong class="command">NOTIFY</strong></span> messages for every zone
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync it loads. Specifying <span><strong class="command">notify master-only;</strong></span> will
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync cause <span><strong class="command">named</strong></span> to only send <span><strong class="command">NOTIFY</strong></span> for master
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync zones that it loads.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<div class="titlepage"><div><div><h2 class="title" style="clear: both">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a name="dynamic_update"></a>Dynamic Update</h2></div></div></div>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Dynamic Update is a method for adding, replacing or deleting
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync records in a master server by sending it a special form of DNS
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync messages. The format and meaning of these messages is specified
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync in RFC 2136.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Dynamic update is enabled by including an
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">allow-update</strong></span> or an <span><strong class="command">update-policy</strong></span>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync clause in the <span><strong class="command">zone</strong></span> statement.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync If the zone's <span><strong class="command">update-policy</strong></span> is set to
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <strong class="userinput"><code>local</code></strong>, updates to the zone
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync will be permitted for the key <code class="varname">local-ddns</code>,
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync which will be generated by <span><strong class="command">named</strong></span> at startup.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync See <a href="Bv9ARM.ch06.html#dynamic_update_policies" title="Dynamic Update Policies">the section called “Dynamic Update Policies”</a> for more details.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Dynamic updates using Kerberos signed requests can be made
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">tkey-gssapi-keytab</strong></span> option, or alternatively
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync by setting both the <span><strong class="command">tkey-gssapi-credential</strong></span>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync and <span><strong class="command">tkey-domain</strong></span> options. Once enabled,
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Kerberos signed requests will be matched against the update
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync policies for the zone, using the Kerberos principal as the
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync signer for the request.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Updating of secure zones (zones using DNSSEC) follows RFC
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync 3007: RRSIG, NSEC and NSEC3 records affected by updates are
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync automatically regenerated by the server using an online
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync zone key. Update authorization is based on transaction
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync signatures and an explicit server policy.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a name="journal"></a>The journal file</h3></div></div></div>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync All changes made to a zone using dynamic update are stored
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync in the zone's journal file. This file is automatically created
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync by the server when the first dynamic update takes place.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The name of the journal file is formed by appending the extension
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <code class="filename">.jnl</code> to the name of the
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync corresponding zone
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync file unless specifically overridden. The journal file is in a
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync binary format and should not be edited manually.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The server will also occasionally write ("dump")
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync the complete contents of the updated zone to its zone file.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync This is not done immediately after
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync each dynamic update, because that would be too slow when a large
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync zone is updated frequently. Instead, the dump is delayed by
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync up to 15 minutes, allowing additional updates to take place.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync During the dump process, transient files will be created
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync with the extensions <code class="filename">.jnw</code> and
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <code class="filename">.jbk</code>; under ordinary circumstances, these
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync will be removed when the dump is complete, and can be safely
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync When a server is restarted after a shutdown or crash, it will replay
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync the journal file to incorporate into the zone any updates that
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync place after the last zone dump.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Changes that result from incoming incremental zone transfers are
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync journalled in a similar way.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The zone files of dynamic zones cannot normally be edited by
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync hand because they are not guaranteed to contain the most recent
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync dynamic changes — those are only in the journal file.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The only way to ensure that the zone file of a dynamic zone
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync is up to date is to run <span><strong class="command">rndc stop</strong></span>.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync If you have to make changes to a dynamic zone
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync manually, the following procedure will work:
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Disable dynamic updates to the zone using
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">rndc freeze <em class="replaceable"><code>zone</code></em></strong></span>.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync This will update the zone's master file with the changes
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync stored in its <code class="filename">.jnl</code> file.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Edit the zone file. Run
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">rndc thaw <em class="replaceable"><code>zone</code></em></strong></span>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync to reload the changed zone and re-enable dynamic updates.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">rndc sync <em class="replaceable"><code>zone</code></em></strong></span>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync will update the zone file with changes from the journal file
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync without stopping dynamic updates; this may be useful for viewing
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync the current zone state. To remove the <code class="filename">.jnl</code>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync file after updating the zone file, use
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">rndc sync -clean</strong></span>.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<div class="titlepage"><div><div><h2 class="title" style="clear: both">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a name="incremental_zone_transfers"></a>Incremental Zone Transfers (IXFR)</h2></div></div></div>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The incremental zone transfer (IXFR) protocol is a way for
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync slave servers to transfer only changed data, instead of having to
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync transfer the entire zone. The IXFR protocol is specified in RFC
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync 1995. See <a href="Bv9ARM.ch09.html#proposed_standards">Proposed Standards</a>.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync When acting as a master, <acronym class="acronym">BIND</acronym> 9
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync supports IXFR for those zones
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync where the necessary change history information is available. These
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync include master zones maintained by dynamic update and slave zones
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync whose data was obtained by IXFR. For manually maintained master
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync zones, and for slave zones obtained by performing a full zone
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync transfer (AXFR), IXFR is supported only if the option
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">ixfr-from-differences</strong></span> is set
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync to <strong class="userinput"><code>yes</code></strong>.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync When acting as a slave, <acronym class="acronym">BIND</acronym> 9 will
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync attempt to use IXFR unless
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync it is explicitly disabled. For more information about disabling
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync IXFR, see the description of the <span><strong class="command">request-ixfr</strong></span> clause
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync of the <span><strong class="command">server</strong></span> statement.
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync<div class="titlepage"><div><div><h2 class="title" style="clear: both">
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync<a name="id2569971"></a>Split DNS</h2></div></div></div>
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync Setting up different views, or visibility, of the DNS space to
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync internal and external resolvers is usually referred to as a
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span class="emphasis"><em>Split DNS</em></span> setup. There are several
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync reasons an organization would want to set up its DNS this way.
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync One common reason for setting up a DNS system this way is
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync to hide "internal" DNS information from "external" clients on the
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync Internet. There is some debate as to whether or not this is actually
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync Internal DNS information leaks out in many ways (via email headers,
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync for example) and most savvy "attackers" can find the information
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync they need using other means.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync However, since listing addresses of internal servers that
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync external clients cannot possibly reach can result in
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync connection delays and other annoyances, an organization may
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync choose to use a Split DNS to present a consistent view of itself
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync to the outside world.
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync Another common reason for setting up a Split DNS system is
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync to allow internal networks that are behind filters or in RFC 1918
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync space (reserved IP space, as documented in RFC 1918) to resolve DNS
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync on the Internet. Split DNS can also be used to allow mail from outside
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync back in to the internal network.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a name="id2569989"></a>Example split DNS setup</h3></div></div></div>
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync Let's say a company named <span class="emphasis"><em>Example, Inc.</em></span>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync has several corporate sites that have an internal network with
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync Internet Protocol (IP) space and an external demilitarized zone (DMZ),
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync or "outside" section of a network, that is available to the public.
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync <span class="emphasis"><em>Example, Inc.</em></span> wants its internal clients
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync to be able to resolve external hostnames and to exchange mail with
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync people on the outside. The company also wants its internal resolvers
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync to have access to certain internal-only zones that are not available
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync at all outside of the internal network.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync In order to accomplish this, the company will set up two sets
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync of name servers. One set will be on the inside network (in the
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync IP space) and the other set will be on bastion hosts, which are
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync hosts that can talk to both sides of its network, in the DMZ.
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync The internal servers will be configured to forward all queries,
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync except queries for <code class="filename">site1.internal</code>, <code class="filename">site2.internal</code>, <code class="filename">site1.example.com</code>,
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync and <code class="filename">site2.example.com</code>, to the servers
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync DMZ. These internal servers will have complete sets of information
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync for <code class="filename">site1.example.com</code>, <code class="filename">site2.example.com</code>, <code class="filename">site1.internal</code>,
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync To protect the <code class="filename">site1.internal</code> and <code class="filename">site2.internal</code> domains,
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync the internal name servers must be configured to disallow all queries
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync to these domains from any external hosts, including the bastion
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync The external servers, which are on the bastion hosts, will
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync be configured to serve the "public" version of the <code class="filename">site1</code> and <code class="filename">site2.example.com</code> zones.
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync This could include things such as the host records for public servers
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync (<code class="filename">www.example.com</code> and <code class="filename">ftp.example.com</code>),
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync and mail exchange (MX) records (<code class="filename">a.mx.example.com</code> and <code class="filename">b.mx.example.com</code>).
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync In addition, the public <code class="filename">site1</code> and <code class="filename">site2.example.com</code> zones
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync should have special MX records that contain wildcard (`*') records
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync pointing to the bastion hosts. This is needed because external mail
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync servers do not have any other way of looking up how to deliver mail
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync to those internal hosts. With the wildcard records, the mail will
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync be delivered to the bastion host, which can then forward it on to
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync internal hosts.
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync Here's an example of a wildcard MX record:
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<pre class="programlisting">* IN MX 10 external1.example.com.</pre>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Now that they accept mail on behalf of anything in the internal
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync network, the bastion hosts will need to know how to deliver mail
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync to internal hosts. In order for this to work properly, the resolvers
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync the bastion hosts will need to be configured to point to the internal
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync name servers for DNS resolution.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Queries for internal hostnames will be answered by the internal
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync servers, and queries for external hostnames will be forwarded back
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync out to the DNS servers on the bastion hosts.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync In order for all this to work properly, internal clients will
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync need to be configured to query <span class="emphasis"><em>only</em></span> the internal
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync name servers for DNS queries. This could also be enforced via
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync filtering on the network.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync If everything has been set properly, <span class="emphasis"><em>Example, Inc.</em></span>'s
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync internal clients will now be able to:
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Look up any hostnames in the <code class="literal">site1</code>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <code class="literal">site2.example.com</code> zones.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Look up any hostnames in the <code class="literal">site1.internal</code> and
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <code class="literal">site2.internal</code> domains.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<li>Exchange mail with both internal and external people.</li>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Hosts on the Internet will be able to:
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Look up any hostnames in the <code class="literal">site1</code>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <code class="literal">site2.example.com</code> zones.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Exchange mail with anyone in the <code class="literal">site1</code> and
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <code class="literal">site2.example.com</code> zones.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Here is an example configuration for the setup we just
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync described above. Note that this is only configuration information;
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync for information on how to configure your zone files, see <a href="Bv9ARM.ch03.html#sample_configuration" title="Sample Configurations">the section called “Sample Configurations”</a>.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Internal DNS server config:
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsyncacl externals { <code class="varname">bastion-ips-go-here</code>; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync forward only;
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync // forward to external servers
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync forwarders {
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync // sample allow-transfer (no one)
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-transfer { none; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync // restrict query access
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-query { internals; externals; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync // restrict recursion
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-recursion { internals; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync// sample master zone
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync type master;
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync // do normal iterative resolution (do not forward)
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync forwarders { };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-query { internals; externals; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-transfer { internals; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync// sample slave zone
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync type slave;
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync masters { 172.16.72.3; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync forwarders { };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-query { internals; externals; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-transfer { internals; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync type master;
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync forwarders { };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-query { internals; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-transfer { internals; }
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync type slave;
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync masters { 172.16.72.3; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync forwarders { };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-query { internals };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-transfer { internals; }
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync External (bastion host) DNS server config:
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsyncacl externals { bastion-ips-go-here; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync // sample allow-transfer (no one)
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-transfer { none; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync // default query access
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-query { any; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync // restrict cache access
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-query-cache { internals; externals; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync // restrict recursion
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-recursion { internals; externals; };
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync// sample slave zone
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync type master;
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-transfer { internals; externals; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync type slave;
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync masters { another_bastion_host_maybe; };
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync allow-transfer { internals; externals; }
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync In the <code class="filename">resolv.conf</code> (or equivalent) on
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync the bastion host(s):
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsyncnameserver 172.16.72.2
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsyncnameserver 172.16.72.3
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsyncnameserver 172.16.72.4
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<div class="titlepage"><div><div><h2 class="title" style="clear: both">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync This is a short guide to setting up Transaction SIGnatures
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync (TSIG) based transaction security in <acronym class="acronym">BIND</acronym>. It describes changes
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync to the configuration file as well as what changes are required for
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync different features, including the process of creating transaction
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync keys and using transaction signatures with <acronym class="acronym">BIND</acronym>.
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync <acronym class="acronym">BIND</acronym> primarily supports TSIG for server
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync to server communication.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync This includes zone transfer, notify, and recursive query messages.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Resolvers based on newer versions of <acronym class="acronym">BIND</acronym> 8 have limited support
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync TSIG can also be useful for dynamic update. A primary
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync server for a dynamic zone should control access to the dynamic
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync update service, but IP-based access control is insufficient.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The cryptographic access control provided by TSIG
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync is far superior. The <span><strong class="command">nsupdate</strong></span>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync program supports TSIG via the <code class="option">-k</code> and
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <code class="option">-y</code> command line options or inline by use
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync of the <span><strong class="command">key</strong></span>.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a name="id2570490"></a>Generate Shared Keys for Each Pair of Hosts</h3></div></div></div>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync A shared secret is generated to be shared between <span class="emphasis"><em>host1</em></span> and <span class="emphasis"><em>host2</em></span>.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync An arbitrary key name is chosen: "host1-host2.". The key name must
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync be the same on both hosts.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a name="id2570507"></a>Automatic Generation</h4></div></div></div>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The following command will generate a 128-bit (16 byte) HMAC-SHA256
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync key as described above. Longer keys are better, but shorter keys
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync are easier to read. Note that the maximum key length is the digest
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync length, here 256 bits.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <strong class="userinput"><code>dnssec-keygen -a hmac-sha256 -b 128 -n HOST host1-host2.</code></strong>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The key is in the file <code class="filename">Khost1-host2.+163+00000.private</code>.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Nothing directly uses this file, but the base-64 encoded string
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync can be extracted from the file and used as a shared secret:
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<pre class="programlisting">Key: La/E5CjG9O+os1jq0a2jdA==</pre>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The string "<code class="literal">La/E5CjG9O+os1jq0a2jdA==</code>" can
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync be used as the shared secret.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a name="id2570546"></a>Manual Generation</h4></div></div></div>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The shared secret is simply a random sequence of bits, encoded
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync in base-64. Most ASCII strings are valid base-64 strings (assuming
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync the length is a multiple of 4 and only valid characters are used),
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync so the shared secret can be manually generated.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Also, a known string can be run through <span><strong class="command">mmencode</strong></span> or
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync a similar program to generate base-64 encoded data.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a name="id2570564"></a>Copying the Shared Secret to Both Machines</h3></div></div></div>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync This is beyond the scope of DNS. A secure transport mechanism
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync should be used. This could be secure FTP, ssh, telephone, etc.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<a name="id2570574"></a>Informing the Servers of the Key's Existence</h3></div></div></div>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Imagine <span class="emphasis"><em>host1</em></span> and <span class="emphasis"><em>host 2</em></span>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync both servers. The following is added to each server's <code class="filename">named.conf</code> file:
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsynckey host1-host2. {
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync algorithm hmac-sha256;
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync The secret is the one generated above. Since this is a secret, it
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync is recommended that either <code class="filename">named.conf</code> be
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync non-world readable, or the key directive be added to a non-world
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync readable file that is included by <code class="filename">named.conf</code>.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync At this point, the key is recognized. This means that if the
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync server receives a message signed by this key, it can verify the
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync signature. If the signature is successfully verified, the
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync response is signed by the same key.
de5314ed6e4a1a588f7c8f66a4ec2af3d9039898vboxsync<a name="id2570611"></a>Instructing the Server to Use the Key</h3></div></div></div>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Since keys are shared between two hosts only, the server must
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync be told when keys are to be used. The following is added to the <code class="filename">named.conf</code> file
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync for <span class="emphasis"><em>host1</em></span>, if the IP address of <span class="emphasis"><em>host2</em></span> is
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsyncserver 10.1.2.3 {
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync keys { host1-host2. ;};
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync Multiple keys may be present, but only the first is used.
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync This directive does not contain any secrets, so it may be in a
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync world-readable
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync If <span class="emphasis"><em>host1</em></span> sends a message that is a request
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync to that address, the message will be signed with the specified key. <span class="emphasis"><em>host1</em></span> will
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync expect any responses to signed messages to be signed with the same
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync A similar statement must be present in <span class="emphasis"><em>host2</em></span>'s
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync configuration file (with <span class="emphasis"><em>host1</em></span>'s address) for <span class="emphasis"><em>host2</em></span> to
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync sign request messages to <span class="emphasis"><em>host1</em></span>.
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync<a name="id2570668"></a>TSIG Key Based Access Control</h3></div></div></div>
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync <acronym class="acronym">BIND</acronym> allows IP addresses and ranges
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync to be specified in ACL
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync definitions and
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync <span><strong class="command">allow-{ query | transfer | update }</strong></span>
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync directives.
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync This has been extended to allow TSIG keys also. The above key would
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync be denoted <span><strong class="command">key host1-host2.</strong></span>
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync An example of an <span><strong class="command">allow-update</strong></span> directive would be:
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsyncallow-update { key host1-host2. ;};
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync This allows dynamic updates to succeed only if the request
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync was signed by a key named "<span><strong class="command">host1-host2.</strong></span>".
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync See <a href="Bv9ARM.ch06.html#dynamic_update_policies" title="Dynamic Update Policies">the section called “Dynamic Update Policies”</a> for a discussion of
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync the more flexible <span><strong class="command">update-policy</strong></span> statement.
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync<a name="id2570717"></a>Errors</h3></div></div></div>
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync The processing of TSIG signed messages can result in
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync several errors. If a signed message is sent to a non-TSIG aware
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync server, a FORMERR (format error) will be returned, since the server will not
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync understand the record. This is a result of misconfiguration,
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync since the server must be explicitly configured to send a TSIG
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync signed message to a specific server.
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync If a TSIG aware server receives a message signed by an
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync unknown key, the response will be unsigned with the TSIG
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync extended error code set to BADKEY. If a TSIG aware server
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync receives a message with a signature that does not validate, the
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync response will be unsigned with the TSIG extended error code set
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync to BADSIG. If a TSIG aware server receives a message with a time
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync outside of the allowed range, the response will be signed with
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync the TSIG extended error code set to BADTIME, and the time values
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync will be adjusted so that the response can be successfully
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync verified. In any of these cases, the message's rcode (response code) is set to
e6fae8b2e495e07ed88fcbbd6425dc639dd1f3f1vboxsync NOTAUTH (not authenticated).
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<div class="titlepage"><div><div><h2 class="title" style="clear: both">
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync<p><span><strong class="command">TKEY</strong></span>
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync is a mechanism for automatically generating a shared secret
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync between two hosts. There are several "modes" of
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">TKEY</strong></span> that specify how the key is generated
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync or assigned. <acronym class="acronym">BIND</acronym> 9 implements only one of
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync these modes, the Diffie-Hellman key exchange. Both hosts are
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync required to have a Diffie-Hellman KEY record (although this
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync record is not required to be present in a zone). The
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">TKEY</strong></span> process must use signed messages,
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync signed either by TSIG or SIG(0). The result of
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync <span><strong class="command">TKEY</strong></span> is a shared secret that can be used to
1c2c968fd241148110002d75b2c0fdeddc211e14vboxsync sign messages with TSIG. <span><strong class="command">TKEY</strong></span> can also be
that the tools shipped with BIND 9.2.x and earlier are not compatible
<strong class="userinput"><code>dnssec-keygen -a RSASHA1 -b 768 -n ZONE child.example.</code></strong>
<strong class="userinput"><code>yes</code></strong> or <strong class="userinput"><code>auto</code></strong>.
example.com. 257 3 5 "AwEAAaxPMcR2x0HbQV4WeZB6oEDX+r0QM6
<a name="dnssec.dynamic.zones"></a>DNSSEC, Dynamic Zones, and Automatic Signing</h2></div></div></div>
zone example.net {
> update add example.net DNSKEY 256 3 7 AwEAAZn17pUF0KpbPA2c7Gz76Vb18v0teKT3EyAGfBfL8eQ8al35zz3Y I1m/SAQBxIqMfLtIwqWPdgthsu36azGQAX8=
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
> update add example.net DNSKEY 256 3 7 AwEAAZn17pUF0KpbPA2c7Gz76Vb18v0teKT3EyAGfBfL8eQ8al35zz3Y I1m/SAQBxIqMfLtIwqWPdgthsu36azGQAX8=
> update add example.net DNSKEY 257 3 7 AwEAAd/7odU/64o2LGsifbLtQmtO8dFDtTAZXSX2+X3e/UNlq9IHq3Y0 XtC0Iuawl/qkaKVxXe2lo8Ct+dM6UehyCqk=
> update add example.net NSEC3PARAM 1 1 100 1234567890
(See <a href="man.dnssec-keygen.html" title="dnssec-keygen"><span class="refentrytitle"><span class="application">dnssec-keygen</span></span>(8)</a> and
<a href="man.dnssec-settime.html" title="dnssec-settime"><span class="refentrytitle"><span class="application">dnssec-settime</span></span>(8)</a> for more information.)
<span><strong class="command">rndc sign</strong></span> or <span><strong class="command">rndc loadkeys</strong></span>
<span><strong class="command">dnssec-keygen</strong></span> or <span><strong class="command">dnssec-settime</strong></span>),
and Usage">the section called “<span><strong class="command">managed-keys</strong></span> Statement Definition
$ <strong class="userinput"><code>dnssec-keygen -K keys -f KSK -P now -A now+2y example.net</code></strong>
and the <span><strong class="command">dnssec-*</strong></span> and <span><strong class="command">pkcs11-*</strong></span>
<span><strong class="command">dnssec-*</strong></span> tools, or the <code class="option">-m</code> in
$ <strong class="userinput"><code>wget <a href="" target="_top">http://www.openssl.org/source/openssl-0.9.8y.tar.gz</a></code></strong>
$ <strong class="userinput"><code>cp pkcs11.GCC4.0.2.so.4.05 /opt/pkcs11/usr/lib/libpkcs11.so</code></strong>
and "<span><strong class="command">make test</strong></span>". If "<span><strong class="command">make
project (http://www.opendnssec.org) which provides a PKCS#11
$ <strong class="userinput"><code> echo "0:/opt/pkcs11/softhsm.db" > $SOFTHSM_CONF </code></strong>
$ <strong class="userinput"><code> /opt/pkcs11/usr/bin/softhsm --init-token 0 --slot 0 --label softhsm </code></strong>
$ <strong class="userinput"><code>export LD_LIBRARY_PATH=/opt/pkcs11/usr/lib:${LD_LIBRARY_PATH}</code></strong>
$ <strong class="userinput"><code>export KEYPER_LIBRARY_PATH=/opt/Keyper/PKCS11Provider</code></strong>
"sample-ksk" as the key-signing key for "example.net":
$ <strong class="userinput"><code>dnssec-keyfromlabel -l sample-ksk -f KSK example.net</code></strong>
<a href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel"><span class="refentrytitle"><span class="application">dnssec-keyfromlabel</span></span>(8)</a> for details.)
this is accomplished by placing the PIN into the openssl.cnf file
The location of the openssl.cnf file can be overridden by
dynamically-linkable DLZ module--i.e., one which can be
"example.nil", which can answer queries and AXFR requests, and
example.nil. 1800 IN A 10.53.0.1
e.g., by providing different address records for a particular name
<a name="id2571574"></a>IPv6 Support in <acronym class="acronym">BIND</acronym> 9</h2></div></div></div>
see <a href="Bv9ARM.ch09.html#ipv6addresses" title="IPv6 addresses (AAAA)">the section called “IPv6 addresses (AAAA)”</a>.
$ORIGIN example.com.