man.named.html revision 575e15fed997a3ad1cb35c5b9ef34ab24ce47e72
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<!--
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - Copyright (C) 2000-2003 Internet Software Consortium.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte -
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - Permission to use, copy, modify, and/or distribute this software for any
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - purpose with or without fee is hereby granted, provided that the above
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - copyright notice and this permission notice appear in all copies.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte -
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte - PERFORMANCE OF THIS SOFTWARE.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte-->
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<!-- $Id: man.named.html,v 1.148 2009/10/28 01:14:38 tbox Exp $ -->
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<html>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<head>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<title>named</title>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<link rel="prev" href="man.named-checkzone.html" title="named-checkzone">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<link rel="next" href="man.nsupdate.html" title="nsupdate">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</head>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="navheader">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<table width="100%" summary="Navigation header">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<tr><th colspan="3" align="center"><span class="application">named</span></th></tr>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<tr>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<td width="20%" align="left">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<a accesskey="p" href="man.named-checkzone.html">Prev</a>�</td>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<th width="60%" align="center">Manual pages</th>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<td width="20%" align="right">�<a accesskey="n" href="man.nsupdate.html">Next</a>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</td>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</tr>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</table>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<hr>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="refentry" lang="en">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<a name="man.named"></a><div class="titlepage"></div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="refnamediv">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<h2>Name</h2>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p><span class="application">named</span> &#8212; Internet domain name server</p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="refsynopsisdiv">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<h2>Synopsis</h2>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="cmdsynopsis"><p><code class="command">named</code> [<code class="option">-4</code>] [<code class="option">-6</code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>debug-level</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine-name</code></em></code>] [<code class="option">-f</code>] [<code class="option">-g</code>] [<code class="option">-m <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-n <em class="replaceable"><code>#cpus</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-s</code>] [<code class="option">-S <em class="replaceable"><code>#max-socks</code></em></code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>] [<code class="option">-v</code>] [<code class="option">-V</code>] [<code class="option">-x <em class="replaceable"><code>cache-file</code></em></code>]</p></div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="refsect1" lang="en">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<a name="id2614369"></a><h2>DESCRIPTION</h2>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p><span><strong class="command">named</strong></span>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte is a Domain Name System (DNS) server,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte part of the BIND 9 distribution from ISC. For more
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte information on the DNS, see RFCs 1033, 1034, and 1035.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte When invoked without arguments, <span><strong class="command">named</strong></span>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte will
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte read the default configuration file
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <code class="filename">/etc/named.conf</code>, read any initial
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte data, and listen for queries.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="refsect1" lang="en">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<a name="id2614400"></a><h2>OPTIONS</h2>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="variablelist"><dl>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-4</span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Use IPv4 only even if the host machine is capable of IPv6.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <code class="option">-4</code> and <code class="option">-6</code> are mutually
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte exclusive.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-6</span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Use IPv6 only even if the host machine is capable of IPv4.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <code class="option">-4</code> and <code class="option">-6</code> are mutually
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte exclusive.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-c <em class="replaceable"><code>config-file</code></em></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Use <em class="replaceable"><code>config-file</code></em> as the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte configuration file instead of the default,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <code class="filename">/etc/named.conf</code>. To
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte ensure that reloading the configuration file continues
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte to work after the server has changed its working
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte directory due to to a possible
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <code class="option">directory</code> option in the configuration
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte file, <em class="replaceable"><code>config-file</code></em> should be
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte an absolute pathname.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-d <em class="replaceable"><code>debug-level</code></em></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Set the daemon's debug level to <em class="replaceable"><code>debug-level</code></em>.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Debugging traces from <span><strong class="command">named</strong></span> become
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte more verbose as the debug level increases.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-E <em class="replaceable"><code>engine-name</code></em></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Use a crypto hardware (OpenSSL engine) for the crypto operations
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte it supports, for instance re-signing with private keys from
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte a secure key store. When compiled with PKCS#11 support
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="replaceable"><code>engine-name</code></em>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte defaults to pkcs11, the empty name resets it to no engine.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-f</span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Run the server in the foreground (i.e. do not daemonize).
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-g</span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Run the server in the foreground and force all logging
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte to <code class="filename">stderr</code>.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-m <em class="replaceable"><code>flag</code></em></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Turn on memory usage debugging flags. Possible flags are
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="replaceable"><code>usage</code></em>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="replaceable"><code>trace</code></em>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="replaceable"><code>record</code></em>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="replaceable"><code>size</code></em>, and
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="replaceable"><code>mctx</code></em>.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte These correspond to the ISC_MEM_DEBUGXXXX flags described in
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <code class="filename">&lt;isc/mem.h&gt;</code>.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-n <em class="replaceable"><code>#cpus</code></em></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Create <em class="replaceable"><code>#cpus</code></em> worker threads
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte to take advantage of multiple CPUs. If not specified,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <span><strong class="command">named</strong></span> will try to determine the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte number of CPUs present and create one thread per CPU.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte If it is unable to determine the number of CPUs, a
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte single worker thread will be created.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Listen for queries on port <em class="replaceable"><code>port</code></em>. If not
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte specified, the default is port 53.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-s</span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Write memory usage statistics to <code class="filename">stdout</code> on exit.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<h3 class="title">Note</h3>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte This option is mainly of interest to BIND 9 developers
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte and may be removed or changed in a future release.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-S <em class="replaceable"><code>#max-socks</code></em></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Allow <span><strong class="command">named</strong></span> to use up to
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="replaceable"><code>#max-socks</code></em> sockets.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<h3 class="title">Warning</h3>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte This option should be unnecessary for the vast majority
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte of users.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte The use of this option could even be harmful because the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte specified value may exceed the limitation of the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte underlying system API.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte It is therefore set only when the default configuration
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte causes exhaustion of file descriptors and the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte operational environment is known to support the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte specified number of sockets.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Note also that the actual maximum number is normally a little
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte fewer than the specified value because
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <span><strong class="command">named</strong></span> reserves some file descriptors
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte for its internal use.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-t <em class="replaceable"><code>directory</code></em></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>Chroot
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte to <em class="replaceable"><code>directory</code></em> after
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte processing the command line arguments, but before
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte reading the configuration file.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<h3 class="title">Warning</h3>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte This option should be used in conjunction with the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <code class="option">-u</code> option, as chrooting a process
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte running as root doesn't enhance security on most
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte systems; the way <code class="function">chroot(2)</code> is
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte defined allows a process with root privileges to
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte escape a chroot jail.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-u <em class="replaceable"><code>user</code></em></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>Setuid
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte to <em class="replaceable"><code>user</code></em> after completing
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte privileged operations, such as creating sockets that
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte listen on privileged ports.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<h3 class="title">Note</h3>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte On Linux, <span><strong class="command">named</strong></span> uses the kernel's
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte capability mechanism to drop all root privileges
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte except the ability to <code class="function">bind(2)</code> to
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte a
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte privileged port and set process resource limits.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Unfortunately, this means that the <code class="option">-u</code>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte option only works when <span><strong class="command">named</strong></span> is
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte run
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte on kernel 2.2.18 or later, or kernel 2.3.99-pre3 or
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte later, since previous kernels did not allow privileges
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte to be retained after <code class="function">setuid(2)</code>.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-v</span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Report the version number and exit.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-V</span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Report the version number and build options, and exit.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">-x <em class="replaceable"><code>cache-file</code></em></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Load data from <em class="replaceable"><code>cache-file</code></em> into the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte cache of the default view.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<h3 class="title">Warning</h3>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte This option must not be used. It is only of interest
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte to BIND 9 developers and may be removed or changed in a
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte future release.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</dl></div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="refsect1" lang="en">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<a name="id2635024"></a><h2>SIGNALS</h2>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte In routine operation, signals should not be used to control
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte the nameserver; <span><strong class="command">rndc</strong></span> should be used
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte instead.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="variablelist"><dl>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">SIGHUP</span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Force a reload of the server.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term">SIGINT, SIGTERM</span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte Shut down the server.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</dl></div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte The result of sending any other signals to the server is undefined.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="refsect1" lang="en">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<a name="id2635074"></a><h2>CONFIGURATION</h2>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte The <span><strong class="command">named</strong></span> configuration file is too complex
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte to describe in detail here. A complete description is provided
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte in the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="citetitle">BIND 9 Administrator Reference Manual</em>.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <span><strong class="command">named</strong></span> inherits the <code class="function">umask</code>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte (file creation mode mask) from the parent process. If files
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte created by <span><strong class="command">named</strong></span>, such as journal files,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte need to have custom permissions, the <code class="function">umask</code>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte should be set explicitly in the script used to start the
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <span><strong class="command">named</strong></span> process.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="refsect1" lang="en">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<a name="id2635123"></a><h2>FILES</h2>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="variablelist"><dl>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term"><code class="filename">/etc/named.conf</code></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte The default configuration file.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dt><span class="term"><code class="filename">/var/run/named/named.pid</code></span></dt>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<dd><p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte The default process-id file.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p></dd>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</dl></div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="refsect1" lang="en">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<a name="id2669573"></a><h2>SEE ALSO</h2>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p><em class="citetitle">RFC 1033</em>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="citetitle">RFC 1034</em>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="citetitle">RFC 1035</em>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <span class="citerefentry"><span class="refentrytitle">named-checkconf</span>(8)</span>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <span class="citerefentry"><span class="refentrytitle">named-checkzone</span>(8)</span>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <span class="citerefentry"><span class="refentrytitle">rndc</span>(8)</span>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <span class="citerefentry"><span class="refentrytitle">lwresd</span>(8)</span>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>,
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte <em class="citetitle">BIND 9 Administrator Reference Manual</em>.
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="refsect1" lang="en">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<a name="id2669643"></a><h2>AUTHOR</h2>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<p><span class="corpauthor">Internet Systems Consortium</span>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte </p>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<div class="navfooter">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<hr>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<table width="100%" summary="Navigation footer">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<tr>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<td width="40%" align="left">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<a accesskey="p" href="man.named-checkzone.html">Prev</a>�</td>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<td width="40%" align="right">�<a accesskey="n" href="man.nsupdate.html">Next</a>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</td>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</tr>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<tr>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<td width="40%" align="left" valign="top">
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<span class="application">named-checkzone</span>�</td>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte<td width="40%" align="right" valign="top">�<span class="application">nsupdate</span>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</td>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</tr>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</table>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</div>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</body>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte</html>
fcf3ce441efd61da9bb2884968af01cb7c1452ccJohn Forte