man.named.html revision 27963ad22062efe8eac2beed51ff70d8f0b35900
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding - Copyright (C) 2004-2014 Internet Systems Consortium, Inc. ("ISC")
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding - Copyright (C) 2000-2003 Internet Software Consortium.
1708435e9c63465fd70c21025bd51cb44170d2dbdougm - Permission to use, copy, modify, and/or distribute this software for any
1708435e9c63465fd70c21025bd51cb44170d2dbdougm - purpose with or without fee is hereby granted, provided that the above
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding - copyright notice and this permission notice appear in all copies.
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding - PERFORMANCE OF THIS SOFTWARE.
ff8c037448da2a14a00420b285ea3b8f2f4738e0fielding<!-- $Id$ -->
ff8c037448da2a14a00420b285ea3b8f2f4738e0fielding<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
75ad9d694b36c11047c0b747cf7fc31a4fdbf6e4dougm<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
75ad9d694b36c11047c0b747cf7fc31a4fdbf6e4dougm<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
75ad9d694b36c11047c0b747cf7fc31a4fdbf6e4dougm<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
75ad9d694b36c11047c0b747cf7fc31a4fdbf6e4dougm<link rel="prev" href="man.named-checkzone.html" title="named-checkzone">
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding<link rel="next" href="man.named-journalprint.html" title="named-journalprint">
1708435e9c63465fd70c21025bd51cb44170d2dbdougm<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding<tr><th colspan="3" align="center"><span class="application">named</span></th></tr>
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding<a accesskey="p" href="man.named-checkzone.html">Prev</a>�</td>
f3220f54126b25e1cf93cc26c17177b7aef850fdfielding<td width="20%" align="right">�<a accesskey="n" href="man.named-journalprint.html">Next</a>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<a name="man.named"></a><div class="titlepage"></div>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<p><span class="application">named</span> — Internet domain name server</p>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<div class="cmdsynopsis"><p><code class="command">named</code> [<code class="option">-4</code>] [<code class="option">-6</code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>debug-level</code></em></code>] [<code class="option">-D <em class="replaceable"><code>string</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine-name</code></em></code>] [<code class="option">-f</code>] [<code class="option">-g</code>] [<code class="option">-m <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-n <em class="replaceable"><code>#cpus</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-s</code>] [<code class="option">-S <em class="replaceable"><code>#max-socks</code></em></code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-U <em class="replaceable"><code>#listeners</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>] [<code class="option">-v</code>] [<code class="option">-V</code>] [<code class="option">-x <em class="replaceable"><code>cache-file</code></em></code>]</p></div>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<p><span><strong class="command">named</strong></span>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley is a Domain Name System (DNS) server,
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley part of the BIND 9 distribution from ISC. For more
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley information on the DNS, see RFCs 1033, 1034, and 1035.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley When invoked without arguments, <span><strong class="command">named</strong></span>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley read the default configuration file
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley <code class="filename">/etc/named.conf</code>, read any initial
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley data, and listen for queries.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Use IPv4 only even if the host machine is capable of IPv6.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley <code class="option">-4</code> and <code class="option">-6</code> are mutually
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Use IPv6 only even if the host machine is capable of IPv4.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley <code class="option">-4</code> and <code class="option">-6</code> are mutually
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<dt><span class="term">-c <em class="replaceable"><code>config-file</code></em></span></dt>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Use <em class="replaceable"><code>config-file</code></em> as the
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley configuration file instead of the default,
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley ensure that reloading the configuration file continues
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley to work after the server has changed its working
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley directory due to to a possible
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley <code class="option">directory</code> option in the configuration
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley file, <em class="replaceable"><code>config-file</code></em> should be
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley an absolute pathname.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<dt><span class="term">-d <em class="replaceable"><code>debug-level</code></em></span></dt>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Set the daemon's debug level to <em class="replaceable"><code>debug-level</code></em>.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Debugging traces from <span><strong class="command">named</strong></span> become
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley more verbose as the debug level increases.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<dt><span class="term">-D <em class="replaceable"><code>string</code></em></span></dt>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Specifies a string that is used to identify a instance of
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley <span><strong class="command">named</strong></span> in a process listing. The contents
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley of <em class="replaceable"><code>string</code></em> are
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley not examined.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<dt><span class="term">-E <em class="replaceable"><code>engine-name</code></em></span></dt>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley When applicable, specifies the hardware to use for
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley cryptographic operations, such as a secure key store used
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley for signing.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley When BIND is built with OpenSSL PKCS#11 support, this defaults
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley to the string "pkcs11", which identifies an OpenSSL engine
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley that can drive a cryptographic accelerator or hardware service
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley module. When BIND is built with native PKCS#11 cryptography
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley (--enable-native-pkcs11), it defaults to the path of the PKCS#11
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley provider library specified via "--with-pkcs11".
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Run the server in the foreground (i.e. do not daemonize).
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Run the server in the foreground and force all logging
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<dt><span class="term">-m <em class="replaceable"><code>flag</code></em></span></dt>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Turn on memory usage debugging flags. Possible flags are
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley <em class="replaceable"><code>size</code></em>, and
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley These correspond to the ISC_MEM_DEBUGXXXX flags described in
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<dt><span class="term">-n <em class="replaceable"><code>#cpus</code></em></span></dt>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Create <em class="replaceable"><code>#cpus</code></em> worker threads
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley to take advantage of multiple CPUs. If not specified,
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley <span><strong class="command">named</strong></span> will try to determine the
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley number of CPUs present and create one thread per CPU.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley If it is unable to determine the number of CPUs, a
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley single worker thread will be created.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Listen for queries on port <em class="replaceable"><code>port</code></em>. If not
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley specified, the default is port 53.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Write memory usage statistics to <code class="filename">stdout</code> on exit.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley This option is mainly of interest to BIND 9 developers
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley and may be removed or changed in a future release.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<dt><span class="term">-S <em class="replaceable"><code>#max-socks</code></em></span></dt>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Allow <span><strong class="command">named</strong></span> to use up to
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley <em class="replaceable"><code>#max-socks</code></em> sockets.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley The default value is 4096 on systems built with default
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley configuration options, and 21000 on systems built with
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley "configure --with-tuning=large".
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley This option should be unnecessary for the vast majority
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley The use of this option could even be harmful because the
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley specified value may exceed the limitation of the
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley underlying system API.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley It is therefore set only when the default configuration
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley causes exhaustion of file descriptors and the
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley operational environment is known to support the
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley specified number of sockets.
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Note also that the actual maximum number is normally a little
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley fewer than the specified value because
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm <span><strong class="command">named</strong></span> reserves some file descriptors
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley for its internal use.
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm<dt><span class="term">-t <em class="replaceable"><code>directory</code></em></span></dt>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley to <em class="replaceable"><code>directory</code></em> after
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley processing the command line arguments, but before
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley reading the configuration file.
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley This option should be used in conjunction with the
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley <code class="option">-u</code> option, as chrooting a process
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley running as root doesn't enhance security on most
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley systems; the way <code class="function">chroot(2)</code> is
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm defined allows a process with root privileges to
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm escape a chroot jail.
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm<dt><span class="term">-U <em class="replaceable"><code>#listeners</code></em></span></dt>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley Use <em class="replaceable"><code>#listeners</code></em>
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley worker threads to listen for incoming UDP packets on each
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm address. If not specified, <span><strong class="command">named</strong></span> will
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm calculate a default value based on the number of detected
a5a57eb904a8e19297b2c84596f24cede337f6edjwoolley CPUs: 1 for 1 CPU, 2 for 2-4 CPUs, and the number of
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm detected CPUs divided by 2 for values higher than 4.
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm If <code class="option">-n</code> has been set to a higher value than
e5d6e4b6e930968edfdc8e94c67988eb34382619dougm the number of detected CPUs, then <code class="option">-U</code> may
75ad9d694b36c11047c0b747cf7fc31a4fdbf6e4dougm be increased as high as that value, but no higher.
960ca33b37540da5d863a4c0a88092d5ec85b3dadougm<dt><span class="term">-u <em class="replaceable"><code>user</code></em></span></dt>
960ca33b37540da5d863a4c0a88092d5ec85b3dadougm to <em class="replaceable"><code>user</code></em> after completing
960ca33b37540da5d863a4c0a88092d5ec85b3dadougm privileged operations, such as creating sockets that
960ca33b37540da5d863a4c0a88092d5ec85b3dadougm listen on privileged ports.
960ca33b37540da5d863a4c0a88092d5ec85b3dadougm<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
960ca33b37540da5d863a4c0a88092d5ec85b3dadougm On Linux, <span><strong class="command">named</strong></span> uses the kernel's
960ca33b37540da5d863a4c0a88092d5ec85b3dadougm capability mechanism to drop all root privileges
4637615de8c93269b8942c581968810ec3c53821dougm except the ability to <code class="function">bind(2)</code> to
4637615de8c93269b8942c581968810ec3c53821dougm privileged port and set process resource limits.
4637615de8c93269b8942c581968810ec3c53821dougm Unfortunately, this means that the <code class="option">-u</code>
4637615de8c93269b8942c581968810ec3c53821dougm option only works when <span><strong class="command">named</strong></span> is
4637615de8c93269b8942c581968810ec3c53821dougm on kernel 2.2.18 or later, or kernel 2.3.99-pre3 or
4637615de8c93269b8942c581968810ec3c53821dougm later, since previous kernels did not allow privileges
4637615de8c93269b8942c581968810ec3c53821dougm to be retained after <code class="function">setuid(2)</code>.
4637615de8c93269b8942c581968810ec3c53821dougm Report the version number and exit.
4637615de8c93269b8942c581968810ec3c53821dougm Report the version number and build options, and exit.
4637615de8c93269b8942c581968810ec3c53821dougm<dt><span class="term">-x <em class="replaceable"><code>cache-file</code></em></span></dt>
4637615de8c93269b8942c581968810ec3c53821dougm Load data from <em class="replaceable"><code>cache-file</code></em> into the
4637615de8c93269b8942c581968810ec3c53821dougm cache of the default view.
4637615de8c93269b8942c581968810ec3c53821dougm<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
4637615de8c93269b8942c581968810ec3c53821dougm This option must not be used. It is only of interest
4637615de8c93269b8942c581968810ec3c53821dougm to BIND 9 developers and may be removed or changed in a
4637615de8c93269b8942c581968810ec3c53821dougm future release.