man.ddns-confgen.html revision 395c95214142142854509945adf3293c0270e1c5
96fc773162e93e5b85686ab152f11baf4498d868rbb<!--
6f06d481dafc90f1b553f1d2828bcea50a039854fielding - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
71715c646d5231de578431f8961e711764b899d3fanf - Copyright (C) 2000-2003 Internet Software Consortium.
71715c646d5231de578431f8961e711764b899d3fanf -
71715c646d5231de578431f8961e711764b899d3fanf - Permission to use, copy, modify, and/or distribute this software for any
2714d6002fcdf12f5b26cc948c9f2f03ca5e7ee9rbb - purpose with or without fee is hereby granted, provided that the above
2714d6002fcdf12f5b26cc948c9f2f03ca5e7ee9rbb - copyright notice and this permission notice appear in all copies.
2714d6002fcdf12f5b26cc948c9f2f03ca5e7ee9rbb -
2714d6002fcdf12f5b26cc948c9f2f03ca5e7ee9rbb - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
2714d6002fcdf12f5b26cc948c9f2f03ca5e7ee9rbb - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
8695c28e4d0bb9357f606045b37238d4f49ce8b6rbb - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
8695c28e4d0bb9357f606045b37238d4f49ce8b6rbb - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
8695c28e4d0bb9357f606045b37238d4f49ce8b6rbb - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
8695c28e4d0bb9357f606045b37238d4f49ce8b6rbb - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
8695c28e4d0bb9357f606045b37238d4f49ce8b6rbb - PERFORMANCE OF THIS SOFTWARE.
8695c28e4d0bb9357f606045b37238d4f49ce8b6rbb-->
5f69f46ccdf50afd8f0a23f134746e6066185e89rbb<!-- $Id$ -->
5f69f46ccdf50afd8f0a23f134746e6066185e89rbb<html>
5f69f46ccdf50afd8f0a23f134746e6066185e89rbb<head>
5f69f46ccdf50afd8f0a23f134746e6066185e89rbb<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
5f69f46ccdf50afd8f0a23f134746e6066185e89rbb<title>ddns-confgen</title>
e76797ee89ad6fb15ad97b0f3903ae324ac44949wrowe<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
e76797ee89ad6fb15ad97b0f3903ae324ac44949wrowe<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
e76797ee89ad6fb15ad97b0f3903ae324ac44949wrowe<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
e76797ee89ad6fb15ad97b0f3903ae324ac44949wrowe<link rel="prev" href="man.rndc-confgen.html" title="rndc-confgen">
e76797ee89ad6fb15ad97b0f3903ae324ac44949wrowe<link rel="next" href="man.arpaname.html" title="arpaname">
e76797ee89ad6fb15ad97b0f3903ae324ac44949wrowe</head>
e76797ee89ad6fb15ad97b0f3903ae324ac44949wrowe<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
e76797ee89ad6fb15ad97b0f3903ae324ac44949wrowe<div class="navheader">
e76797ee89ad6fb15ad97b0f3903ae324ac44949wrowe<table width="100%" summary="Navigation header">
a1e0709c89175c34a3f72eb4a83d7ee1621a0884rbb<tr><th colspan="3" align="center"><span class="application">ddns-confgen</span></th></tr>
a1e0709c89175c34a3f72eb4a83d7ee1621a0884rbb<tr>
a1e0709c89175c34a3f72eb4a83d7ee1621a0884rbb<td width="20%" align="left">
a1e0709c89175c34a3f72eb4a83d7ee1621a0884rbb<a accesskey="p" href="man.rndc-confgen.html">Prev</a>�</td>
4b13b6bcdcfae61d3c58cc2569757651f28f2bbfrbb<th width="60%" align="center">Manual pages</th>
4b13b6bcdcfae61d3c58cc2569757651f28f2bbfrbb<td width="20%" align="right">�<a accesskey="n" href="man.arpaname.html">Next</a>
4b13b6bcdcfae61d3c58cc2569757651f28f2bbfrbb</td>
34ea1d36f4e1c8d66338e691793017d105cc9c32rbb</tr>
34ea1d36f4e1c8d66338e691793017d105cc9c32rbb</table>
34ea1d36f4e1c8d66338e691793017d105cc9c32rbb<hr>
34ea1d36f4e1c8d66338e691793017d105cc9c32rbb</div>
2c8f06bf370a44a3d0544ed5319355463c417132gregames<div class="refentry" lang="en">
2c8f06bf370a44a3d0544ed5319355463c417132gregames<a name="man.ddns-confgen"></a><div class="titlepage"></div>
2c8f06bf370a44a3d0544ed5319355463c417132gregames<div class="refnamediv">
db06e09891b001667974483058923b88c3258324rbb<h2>Name</h2>
db06e09891b001667974483058923b88c3258324rbb<p><span class="application">ddns-confgen</span> &#8212; ddns key generation tool</p>
db06e09891b001667974483058923b88c3258324rbb</div>
db06e09891b001667974483058923b88c3258324rbb<div class="refsynopsisdiv">
db06e09891b001667974483058923b88c3258324rbb<h2>Synopsis</h2>
8ba9d5e9aaaa79dba0de13f5c1b6e725d98f1dc2fanf<div class="cmdsynopsis"><p><code class="command">tsig-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-h</code>] [<code class="option">-r <em class="replaceable"><code>randomfile</code></em></code>] [name]</p></div>
8ba9d5e9aaaa79dba0de13f5c1b6e725d98f1dc2fanf<div class="cmdsynopsis"><p><code class="command">ddns-confgen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-h</code>] [<code class="option">-k <em class="replaceable"><code>keyname</code></em></code>] [<code class="option">-q</code>] [<code class="option">-r <em class="replaceable"><code>randomfile</code></em></code>] [ -s <em class="replaceable"><code>name</code></em> | -z <em class="replaceable"><code>zone</code></em> ]</p></div>
8ba9d5e9aaaa79dba0de13f5c1b6e725d98f1dc2fanf</div>
8ba9d5e9aaaa79dba0de13f5c1b6e725d98f1dc2fanf<div class="refsect1" lang="en">
26cf4d32b4ff8807a64b0cfa6865a7d6d171c68efanf<a name="id2665307"></a><h2>DESCRIPTION</h2>
26cf4d32b4ff8807a64b0cfa6865a7d6d171c68efanf<p>
26cf4d32b4ff8807a64b0cfa6865a7d6d171c68efanf <span><strong class="command">tsig-keygen</strong></span> and <span><strong class="command">ddns-confgen</strong></span>
06c107289de0a0888386e0bc08ef9fc60aacd8bctrawick are invocation methods for a utility that generates keys for use
06c107289de0a0888386e0bc08ef9fc60aacd8bctrawick in TSIG signing. The resulting keys can be used, for example,
06c107289de0a0888386e0bc08ef9fc60aacd8bctrawick to secure dynamic DNS updates to a zone or for the
06c107289de0a0888386e0bc08ef9fc60aacd8bctrawick <span><strong class="command">rndc</strong></span> command channel.
f4ab6acec7b02518869ca649ce2d3ceeb92d282etrawick </p>
f4ab6acec7b02518869ca649ce2d3ceeb92d282etrawick<p>
f4ab6acec7b02518869ca649ce2d3ceeb92d282etrawick When run as <span><strong class="command">tsig-keygen</strong></span>, a domain name
b0bd38b2226e5cfb86cce6ed1991723f4c9e4f68trawick can be specified on the command line which will be used as
bf9902ea6090f94c9ee0aaddd80b419a184ffe55jim the name of the generated key. If no name is specified,
bf9902ea6090f94c9ee0aaddd80b419a184ffe55jim the default is <code class="constant">tsig-key</code>.
bf9902ea6090f94c9ee0aaddd80b419a184ffe55jim </p>
bf9902ea6090f94c9ee0aaddd80b419a184ffe55jim<p>
bf9902ea6090f94c9ee0aaddd80b419a184ffe55jim When run as <span><strong class="command">ddns-confgen</strong></span>, the generated
bf9902ea6090f94c9ee0aaddd80b419a184ffe55jim key is accompanied by configuration text and instructions
bf9902ea6090f94c9ee0aaddd80b419a184ffe55jim that can be used with <span><strong class="command">nsupdate</strong></span> and
0b34df54ff22d0ca05eb8e9d7c9610138a878c83rbb <span><strong class="command">named</strong></span> when setting up dynamic DNS,
0b34df54ff22d0ca05eb8e9d7c9610138a878c83rbb including an example <span><strong class="command">update-policy</strong></span>
0b34df54ff22d0ca05eb8e9d7c9610138a878c83rbb statement. (This usage similar to the
83047afdc49c183cdca6373dba6a0c6afa638f12gstein <span><strong class="command">rndc-confgen</strong></span> command for setting
0b34df54ff22d0ca05eb8e9d7c9610138a878c83rbb up command channel security.)
c8cc46d12794845f39fa154224075a3bbe57a4c8ben </p>
c8cc46d12794845f39fa154224075a3bbe57a4c8ben<p>
5dea9095cbfab622c65e5f2f806007aaa7d7761arbb Note that <span><strong class="command">named</strong></span> itself can configure a
5dea9095cbfab622c65e5f2f806007aaa7d7761arbb local DDNS key for use with <span><strong class="command">nsupdate -l</strong></span>:
5dea9095cbfab622c65e5f2f806007aaa7d7761arbb it does this when a zone is configured with
5dea9095cbfab622c65e5f2f806007aaa7d7761arbb <span><strong class="command">update-policy local;</strong></span>.
5dea9095cbfab622c65e5f2f806007aaa7d7761arbb <span><strong class="command">ddns-confgen</strong></span> is only needed when a
365c33fd9c0fc3ac27c0bd1d360a5a94980c576atrawick more elaborate configuration is required: for instance,
365c33fd9c0fc3ac27c0bd1d360a5a94980c576atrawick if <span><strong class="command">nsupdate</strong></span> is to be used from a remote
365c33fd9c0fc3ac27c0bd1d360a5a94980c576atrawick system.
0ea568e49752d337d2b513cce07f2a6f4699d6eatrawick </p>
0ea568e49752d337d2b513cce07f2a6f4699d6eatrawick</div>
0ea568e49752d337d2b513cce07f2a6f4699d6eatrawick<div class="refsect1" lang="en">
b7a0ad483b54711addc5f43f679189619a23c749ben<a name="id2665411"></a><h2>OPTIONS</h2>
b7a0ad483b54711addc5f43f679189619a23c749ben<div class="variablelist"><dl>
328d02603f471fad56cc5588fc9e93f589593ad0rbb<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
328d02603f471fad56cc5588fc9e93f589593ad0rbb<dd><p>
1c850e9f96375578e43e5f69ba7499a543b2a7bdtrawick Specifies the algorithm to use for the TSIG key. Available
1c850e9f96375578e43e5f69ba7499a543b2a7bdtrawick choices are: hmac-md5, hmac-sha1, hmac-sha224, hmac-sha256,
1c850e9f96375578e43e5f69ba7499a543b2a7bdtrawick hmac-sha384 and hmac-sha512. The default is hmac-sha256.
48a2f5e2c189669b025d462f44fda5d4b45e8d78trawick Options are case-insensitive, and the "hmac-" prefix
48a2f5e2c189669b025d462f44fda5d4b45e8d78trawick may be omitted.
48a2f5e2c189669b025d462f44fda5d4b45e8d78trawick </p></dd>
48a2f5e2c189669b025d462f44fda5d4b45e8d78trawick<dt><span class="term">-h</span></dt>
48a2f5e2c189669b025d462f44fda5d4b45e8d78trawick<dd><p>
48a2f5e2c189669b025d462f44fda5d4b45e8d78trawick Prints a short summary of options and arguments.
48a2f5e2c189669b025d462f44fda5d4b45e8d78trawick </p></dd>
b22fb75c37b70fbe176afdb8081c3ce2dba86db4rbb<dt><span class="term">-k <em class="replaceable"><code>keyname</code></em></span></dt>
b22fb75c37b70fbe176afdb8081c3ce2dba86db4rbb<dd><p>
b22fb75c37b70fbe176afdb8081c3ce2dba86db4rbb Specifies the key name of the DDNS authentication key.
b22fb75c37b70fbe176afdb8081c3ce2dba86db4rbb The default is <code class="constant">ddns-key</code> when neither
b22fb75c37b70fbe176afdb8081c3ce2dba86db4rbb the <code class="option">-s</code> nor <code class="option">-z</code> option is
8fccb89ed59d5c80c76a818f7ca02bb0d068d4d3rbb specified; otherwise, the default
8fccb89ed59d5c80c76a818f7ca02bb0d068d4d3rbb is <code class="constant">ddns-key</code> as a separate label
8fccb89ed59d5c80c76a818f7ca02bb0d068d4d3rbb followed by the argument of the option, e.g.,
8fccb89ed59d5c80c76a818f7ca02bb0d068d4d3rbb <code class="constant">ddns-key.example.com.</code>
8fccb89ed59d5c80c76a818f7ca02bb0d068d4d3rbb The key name must have the format of a valid domain name,
da07a882b90b44243c9cd88ac09a789999dccc4drbb consisting of letters, digits, hyphens and periods.
da07a882b90b44243c9cd88ac09a789999dccc4drbb </p></dd>
da07a882b90b44243c9cd88ac09a789999dccc4drbb<dt><span class="term">-q</span></dt>
da07a882b90b44243c9cd88ac09a789999dccc4drbb<dd><p>
da07a882b90b44243c9cd88ac09a789999dccc4drbb (<span><strong class="command">ddns-confgen</strong></span> only.) Quiet mode: Print
4a5c8a77f48f0cf10bfe70479d0a2e8e7d6cd917rbb only the key, with no explanatory text or usage examples;
4a5c8a77f48f0cf10bfe70479d0a2e8e7d6cd917rbb This is essentially identical to <span><strong class="command">tsig-keygen</strong></span>.
4a5c8a77f48f0cf10bfe70479d0a2e8e7d6cd917rbb </p></dd>
4a5c8a77f48f0cf10bfe70479d0a2e8e7d6cd917rbb<dt><span class="term">-r <em class="replaceable"><code>randomfile</code></em></span></dt>
4a5c8a77f48f0cf10bfe70479d0a2e8e7d6cd917rbb<dd><p>
4a5c8a77f48f0cf10bfe70479d0a2e8e7d6cd917rbb Specifies a source of random data for generating the
5bf029f8452b6aa105cf3d9d9b19221920725428rbb authorization. If the operating system does not provide a
5bf029f8452b6aa105cf3d9d9b19221920725428rbb <code class="filename">/dev/random</code> or equivalent device, the
5bf029f8452b6aa105cf3d9d9b19221920725428rbb default source of randomness is keyboard input.
60ed053fe71b1e3cfab8c4ed37afde30a6db4841rbb <code class="filename">randomdev</code> specifies the name of a
60ed053fe71b1e3cfab8c4ed37afde30a6db4841rbb character device or file containing random data to be used
60ed053fe71b1e3cfab8c4ed37afde30a6db4841rbb instead of the default. The special value
e03878add0099ba9741efc46d545955a60ea8bdcrbb <code class="filename">keyboard</code> indicates that keyboard input
e03878add0099ba9741efc46d545955a60ea8bdcrbb should be used.
e03878add0099ba9741efc46d545955a60ea8bdcrbb </p></dd>
e03878add0099ba9741efc46d545955a60ea8bdcrbb<dt><span class="term">-s <em class="replaceable"><code>name</code></em></span></dt>
1860b2b5f1de31f8cf9d95f1b394fe98c8dbfab7rbb<dd><p>
1860b2b5f1de31f8cf9d95f1b394fe98c8dbfab7rbb (<span><strong class="command">ddns-confgen</strong></span> only.)
1860b2b5f1de31f8cf9d95f1b394fe98c8dbfab7rbb Generate configuration example to allow dynamic updates
9ec65cbae2f760e485a1c54df5b19853688d5c91wrowe of a single hostname. The example <span><strong class="command">named.conf</strong></span>
9ec65cbae2f760e485a1c54df5b19853688d5c91wrowe text shows how to set an update policy for the specified
9ec65cbae2f760e485a1c54df5b19853688d5c91wrowe <em class="replaceable"><code>name</code></em>
9ec65cbae2f760e485a1c54df5b19853688d5c91wrowe using the "name" nametype. The default key name is
9ec65cbae2f760e485a1c54df5b19853688d5c91wrowe ddns-key.<em class="replaceable"><code>name</code></em>.
9ec65cbae2f760e485a1c54df5b19853688d5c91wrowe Note that the "self" nametype cannot be used, since
9ec65cbae2f760e485a1c54df5b19853688d5c91wrowe the name to be updated may differ from the key name.
9ec65cbae2f760e485a1c54df5b19853688d5c91wrowe This option cannot be used with the <code class="option">-z</code> option.
a8c0c0b8d7dada680bd3f3d70f78ce0656ba5aa6trawick </p></dd>
a8c0c0b8d7dada680bd3f3d70f78ce0656ba5aa6trawick<dt><span class="term">-z <em class="replaceable"><code>zone</code></em></span></dt>
a8c0c0b8d7dada680bd3f3d70f78ce0656ba5aa6trawick<dd><p>
a8c0c0b8d7dada680bd3f3d70f78ce0656ba5aa6trawick (<span><strong class="command">ddns-confgen</strong></span> only.)
a8c0c0b8d7dada680bd3f3d70f78ce0656ba5aa6trawick Generate configuration example to allow dynamic updates
a8c0c0b8d7dada680bd3f3d70f78ce0656ba5aa6trawick of a zone: The example <span><strong class="command">named.conf</strong></span> text
77c656dabf05adcdee0d30b15b4628be738a1913rbb shows how to set an update policy for the specified
77c656dabf05adcdee0d30b15b4628be738a1913rbb <em class="replaceable"><code>zone</code></em>
77c656dabf05adcdee0d30b15b4628be738a1913rbb using the "zonesub" nametype, allowing updates to
77c656dabf05adcdee0d30b15b4628be738a1913rbb all subdomain names within that
77c656dabf05adcdee0d30b15b4628be738a1913rbb <em class="replaceable"><code>zone</code></em>.
7e73041858979fd162c849cc2e7447beb51eedf8rbb This option cannot be used with the <code class="option">-s</code> option.
7e73041858979fd162c849cc2e7447beb51eedf8rbb </p></dd>
886cd69ebf69e990dbc365be87ff8ea7cd681904rbb</dl></div>
886cd69ebf69e990dbc365be87ff8ea7cd681904rbb</div>
886cd69ebf69e990dbc365be87ff8ea7cd681904rbb<div class="refsect1" lang="en">
a8c0c0b8d7dada680bd3f3d70f78ce0656ba5aa6trawick<a name="id2666105"></a><h2>SEE ALSO</h2>
886cd69ebf69e990dbc365be87ff8ea7cd681904rbb<p><span class="citerefentry"><span class="refentrytitle">nsupdate</span>(1)</span>,
886cd69ebf69e990dbc365be87ff8ea7cd681904rbb <span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>,
886cd69ebf69e990dbc365be87ff8ea7cd681904rbb <span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
db9ac238bf63d7df2bebbaff4de1628a32151028trawick <em class="citetitle">BIND 9 Administrator Reference Manual</em>.
ce121a776564df6bb75498209094142d92404b8atrawick </p>
ce121a776564df6bb75498209094142d92404b8atrawick</div>
ce121a776564df6bb75498209094142d92404b8atrawick<div class="refsect1" lang="en">
e1ade9256c87684358786fcf7eef251bd4c1db10rbb<a name="id2666144"></a><h2>AUTHOR</h2>
e1ade9256c87684358786fcf7eef251bd4c1db10rbb<p><span class="corpauthor">Internet Systems Consortium</span>
e1ade9256c87684358786fcf7eef251bd4c1db10rbb </p>
e1ade9256c87684358786fcf7eef251bd4c1db10rbb</div>
e1ade9256c87684358786fcf7eef251bd4c1db10rbb</div>
e1ade9256c87684358786fcf7eef251bd4c1db10rbb<div class="navfooter">
db9ac238bf63d7df2bebbaff4de1628a32151028trawick<hr>
db9ac238bf63d7df2bebbaff4de1628a32151028trawick<table width="100%" summary="Navigation footer">
db9ac238bf63d7df2bebbaff4de1628a32151028trawick<tr>
eae32ab3fb398ca408bc2d45b22adf1b67a75471rbb<td width="40%" align="left">
eae32ab3fb398ca408bc2d45b22adf1b67a75471rbb<a accesskey="p" href="man.rndc-confgen.html">Prev</a>�</td>
d1d25826dbd7d2ba97db90b77122ae2b0f363e89rbb<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
d1d25826dbd7d2ba97db90b77122ae2b0f363e89rbb<td width="40%" align="right">�<a accesskey="n" href="man.arpaname.html">Next</a>
d1d25826dbd7d2ba97db90b77122ae2b0f363e89rbb</td>
42ec91fadb5532438ab4c02993b15c18a517967frbb</tr>
42ec91fadb5532438ab4c02993b15c18a517967frbb<tr>
42ec91fadb5532438ab4c02993b15c18a517967frbb<td width="40%" align="left" valign="top">
42ec91fadb5532438ab4c02993b15c18a517967frbb<span class="application">rndc-confgen</span>�</td>
42ec91fadb5532438ab4c02993b15c18a517967frbb<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
96fc773162e93e5b85686ab152f11baf4498d868rbb<td width="40%" align="right" valign="top">�<span class="application">arpaname</span>
2975523a2901fc601ae9510082a7d4fb11bb9aecake</td>
2975523a2901fc601ae9510082a7d4fb11bb9aecake</tr>
2975523a2901fc601ae9510082a7d4fb11bb9aecake</table>
5827adc4c40ff4b10db9b09cea43f4307c8fc319trawick</div>
5827adc4c40ff4b10db9b09cea43f4307c8fc319trawick<p style="text-align: center;">BIND 9.11.0pre-alpha</p>
5827adc4c40ff4b10db9b09cea43f4307c8fc319trawick</body>
5827adc4c40ff4b10db9b09cea43f4307c8fc319trawick</html>
5827adc4c40ff4b10db9b09cea43f4307c8fc319trawick