man.named.html revision 7717ec7a6a898cdd3c35cbfba66010b7304ffd9b
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<!--
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Copyright (C) 2000-2003 Internet Software Consortium.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster -
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Permission to use, copy, modify, and/or distribute this software for any
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - purpose with or without fee is hereby granted, provided that the above
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - copyright notice and this permission notice appear in all copies.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster -
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - PERFORMANCE OF THIS SOFTWARE.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster-->
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<!-- $Id: man.named.html,v 1.191 2011/03/22 01:14:27 tbox Exp $ -->
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<html>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<head>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<title>named</title>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="prev" href="man.named-checkzone.html" title="named-checkzone">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="next" href="man.named-journalprint.html" title="named-journalprint">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</head>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="navheader">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<table width="100%" summary="Navigation header">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr><th colspan="3" align="center"><span class="application">named</span></th></tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford<td width="20%" align="left">
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford<a accesskey="p" href="man.named-checkzone.html">Prev</a>�</td>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford<th width="60%" align="center">Manual pages</th>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="right">�<a accesskey="n" href="man.named-journalprint.html">Next</a>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford</td>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford</tr>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford</table>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford<hr>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refentry" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="man.named"></a><div class="titlepage"></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refnamediv">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<h2>Name</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><span class="application">named</span> &#8212; Internet domain name server</p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsynopsisdiv">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<h2>Synopsis</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="cmdsynopsis"><p><code class="command">named</code> [<code class="option">-4</code>] [<code class="option">-6</code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>debug-level</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine-name</code></em></code>] [<code class="option">-f</code>] [<code class="option">-g</code>] [<code class="option">-m <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-n <em class="replaceable"><code>#cpus</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-s</code>] [<code class="option">-S <em class="replaceable"><code>#max-socks</code></em></code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>] [<code class="option">-v</code>] [<code class="option">-V</code>] [<code class="option">-x <em class="replaceable"><code>cache-file</code></em></code>]</p></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2632794"></a><h2>DESCRIPTION</h2>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford<p><span><strong class="command">named</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster is a Domain Name System (DNS) server,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster part of the BIND 9 distribution from ISC. For more
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster information on the DNS, see RFCs 1033, 1034, and 1035.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster When invoked without arguments, <span><strong class="command">named</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster will
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster read the default configuration file
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="filename">/etc/named.conf</code>, read any initial
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford data, and listen for queries.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2632825"></a><h2>OPTIONS</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="variablelist"><dl>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-4</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford Use IPv4 only even if the host machine is capable of IPv6.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="option">-4</code> and <code class="option">-6</code> are mutually
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster exclusive.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-6</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Use IPv6 only even if the host machine is capable of IPv4.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="option">-4</code> and <code class="option">-6</code> are mutually
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster exclusive.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-c <em class="replaceable"><code>config-file</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Use <em class="replaceable"><code>config-file</code></em> as the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster configuration file instead of the default,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="filename">/etc/named.conf</code>. To
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ensure that reloading the configuration file continues
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to work after the server has changed its working
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster directory due to to a possible
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="option">directory</code> option in the configuration
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster file, <em class="replaceable"><code>config-file</code></em> should be
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster an absolute pathname.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-d <em class="replaceable"><code>debug-level</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford Set the daemon's debug level to <em class="replaceable"><code>debug-level</code></em>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Debugging traces from <span><strong class="command">named</strong></span> become
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster more verbose as the debug level increases.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-E <em class="replaceable"><code>engine-name</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Use a crypto hardware (OpenSSL engine) for the crypto operations
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster it supports, for instance re-signing with private keys from
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster a secure key store. When compiled with PKCS#11 support
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="replaceable"><code>engine-name</code></em>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster defaults to pkcs11, the empty name resets it to no engine.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-f</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Run the server in the foreground (i.e. do not daemonize).
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-g</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Run the server in the foreground and force all logging
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to <code class="filename">stderr</code>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-m <em class="replaceable"><code>flag</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Turn on memory usage debugging flags. Possible flags are
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="replaceable"><code>usage</code></em>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="replaceable"><code>trace</code></em>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="replaceable"><code>record</code></em>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="replaceable"><code>size</code></em>, and
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford <em class="replaceable"><code>mctx</code></em>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster These correspond to the ISC_MEM_DEBUGXXXX flags described in
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="filename">&lt;isc/mem.h&gt;</code>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-n <em class="replaceable"><code>#cpus</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Create <em class="replaceable"><code>#cpus</code></em> worker threads
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to take advantage of multiple CPUs. If not specified,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">named</strong></span> will try to determine the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster number of CPUs present and create one thread per CPU.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster If it is unable to determine the number of CPUs, a
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster single worker thread will be created.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Listen for queries on port <em class="replaceable"><code>port</code></em>. If not
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster specified, the default is port 53.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-s</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Write memory usage statistics to <code class="filename">stdout</code> on exit.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<h3 class="title">Note</h3>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster This option is mainly of interest to BIND 9 developers
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster and may be removed or changed in a future release.
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-S <em class="replaceable"><code>#max-socks</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Allow <span><strong class="command">named</strong></span> to use up to
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="replaceable"><code>#max-socks</code></em> sockets.
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<h3 class="title">Warning</h3>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster This option should be unnecessary for the vast majority
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster of users.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster The use of this option could even be harmful because the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster specified value may exceed the limitation of the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster underlying system API.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster It is therefore set only when the default configuration
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster causes exhaustion of file descriptors and the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster operational environment is known to support the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster specified number of sockets.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Note also that the actual maximum number is normally a little
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford fewer than the specified value because
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">named</strong></span> reserves some file descriptors
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster for its internal use.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-t <em class="replaceable"><code>directory</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>Chroot
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to <em class="replaceable"><code>directory</code></em> after
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster processing the command line arguments, but before
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster reading the configuration file.
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford </p>
45592298219ac1b0f4aea126fab71a247067ce9dRich Riley<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
45592298219ac1b0f4aea126fab71a247067ce9dRich Riley<h3 class="title">Warning</h3>
45592298219ac1b0f4aea126fab71a247067ce9dRich Riley<p>
45592298219ac1b0f4aea126fab71a247067ce9dRich Riley This option should be used in conjunction with the
45592298219ac1b0f4aea126fab71a247067ce9dRich Riley <code class="option">-u</code> option, as chrooting a process
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster running as root doesn't enhance security on most
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster systems; the way <code class="function">chroot(2)</code> is
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster defined allows a process with root privileges to
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster escape a chroot jail.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-u <em class="replaceable"><code>user</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>Setuid
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to <em class="replaceable"><code>user</code></em> after completing
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster privileged operations, such as creating sockets that
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster listen on privileged ports.
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<h3 class="title">Note</h3>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster On Linux, <span><strong class="command">named</strong></span> uses the kernel's
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster capability mechanism to drop all root privileges
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster except the ability to <code class="function">bind(2)</code> to
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster a
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster privileged port and set process resource limits.
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford Unfortunately, this means that the <code class="option">-u</code>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster option only works when <span><strong class="command">named</strong></span> is
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford run
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford on kernel 2.2.18 or later, or kernel 2.3.99-pre3 or
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford later, since previous kernels did not allow privileges
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford to be retained after <code class="function">setuid(2)</code>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-v</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Report the version number and exit.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-V</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Report the version number and build options, and exit.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-x <em class="replaceable"><code>cache-file</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Load data from <em class="replaceable"><code>cache-file</code></em> into the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster cache of the default view.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<h3 class="title">Warning</h3>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster This option must not be used. It is only of interest
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to BIND 9 developers and may be removed or changed in a
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster future release.
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford </p>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dl></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford<a name="id2639386"></a><h2>SIGNALS</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster In routine operation, signals should not be used to control
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster the nameserver; <span><strong class="command">rndc</strong></span> should be used
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster instead.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="variablelist"><dl>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">SIGHUP</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Force a reload of the server.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">SIGINT, SIGTERM</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Shut down the server.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dl></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster The result of sending any other signals to the server is undefined.
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2639436"></a><h2>CONFIGURATION</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster The <span><strong class="command">named</strong></span> configuration file is too complex
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to describe in detail here. A complete description is provided
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster in the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="citetitle">BIND 9 Administrator Reference Manual</em>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">named</strong></span> inherits the <code class="function">umask</code>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster (file creation mode mask) from the parent process. If files
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster created by <span><strong class="command">named</strong></span>, such as journal files,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster need to have custom permissions, the <code class="function">umask</code>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster should be set explicitly in the script used to start the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">named</strong></span> process.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford<a name="id2674984"></a><h2>FILES</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="variablelist"><dl>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term"><code class="filename">/etc/named.conf</code></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster The default configuration file.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term"><code class="filename">/var/run/named/named.pid</code></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster The default process-id file.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dl></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2675028"></a><h2>SEE ALSO</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><em class="citetitle">RFC 1033</em>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="citetitle">RFC 1034</em>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="citetitle">RFC 1035</em>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span class="citerefentry"><span class="refentrytitle">named-checkconf</span>(8)</span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span class="citerefentry"><span class="refentrytitle">named-checkzone</span>(8)</span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span class="citerefentry"><span class="refentrytitle">rndc</span>(8)</span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span class="citerefentry"><span class="refentrytitle">lwresd</span>(8)</span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="citetitle">BIND 9 Administrator Reference Manual</em>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2675098"></a><h2>AUTHOR</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><span class="corpauthor">Internet Systems Consortium</span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="navfooter">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<hr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<table width="100%" summary="Navigation footer">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="left">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a accesskey="p" href="man.named-checkzone.html">Prev</a>�</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="right">�<a accesskey="n" href="man.named-journalprint.html">Next</a>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="left" valign="top">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<span class="application">named-checkzone</span>�</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="right" valign="top">�<span class="application">named-journalprint</span>
cfb80e0cfdc44c2128a14e92ebeb7cda5a09309cTony Bamford</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</table>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</body>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</html>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster