man.named.html revision 7c6b9b263898daf28d657f65dbd75c330ca4aa13
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd - Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
fd9abdda70912b99b24e3bf1a38f26fde908a74cnd - Copyright (C) 2000-2003 Internet Software Consortium.
fd9abdda70912b99b24e3bf1a38f26fde908a74cnd - Permission to use, copy, modify, and/or distribute this software for any
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd - purpose with or without fee is hereby granted, provided that the above
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd - copyright notice and this permission notice appear in all copies.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
96ad5d81ee4a2cc66a4ae19893efc8aa6d06fae7jailletc - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
2e545ce2450a9953665f701bb05350f0d3f26275nd - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - PERFORMANCE OF THIS SOFTWARE.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<!-- $Id: man.named.html,v 1.170 2010/07/10 01:14:20 tbox Exp $ -->
3f08db06526d6901aa08c110b5bc7dde6bc39905nd<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
3f08db06526d6901aa08c110b5bc7dde6bc39905nd<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<link rel="prev" href="man.named-checkzone.html" title="named-checkzone">
9472e4d3c410be3b3f1addbf3b1db1769f64e765nd<link rel="next" href="man.named-journalprint.html" title="named-journalprint">
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
fac8c35bfb158112226ab43ddf84d59daca5dc30nd<tr><th colspan="3" align="center"><span class="application">named</span></th></tr>
4b575a6b6704b516f22d65a3ad35696d7b9ba372rpluem<a accesskey="p" href="man.named-checkzone.html">Prev</a>�</td>
4b575a6b6704b516f22d65a3ad35696d7b9ba372rpluem<td width="20%" align="right">�<a accesskey="n" href="man.named-journalprint.html">Next</a>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<p><span class="application">named</span> — Internet domain name server</p>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<div class="cmdsynopsis"><p><code class="command">named</code> [<code class="option">-4</code>] [<code class="option">-6</code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>debug-level</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine-name</code></em></code>] [<code class="option">-f</code>] [<code class="option">-g</code>] [<code class="option">-m <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-n <em class="replaceable"><code>#cpus</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-s</code>] [<code class="option">-S <em class="replaceable"><code>#max-socks</code></em></code>] [<code class="option">-t <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-u <em class="replaceable"><code>user</code></em></code>] [<code class="option">-v</code>] [<code class="option">-V</code>] [<code class="option">-x <em class="replaceable"><code>cache-file</code></em></code>]</p></div>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd is a Domain Name System (DNS) server,
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd part of the BIND 9 distribution from ISC. For more
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd information on the DNS, see RFCs 1033, 1034, and 1035.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd When invoked without arguments, <span><strong class="command">named</strong></span>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd read the default configuration file
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd <code class="filename">/etc/named.conf</code>, read any initial
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd data, and listen for queries.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Use IPv4 only even if the host machine is capable of IPv6.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd <code class="option">-4</code> and <code class="option">-6</code> are mutually
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd exclusive.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Use IPv6 only even if the host machine is capable of IPv4.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd <code class="option">-4</code> and <code class="option">-6</code> are mutually
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd exclusive.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<dt><span class="term">-c <em class="replaceable"><code>config-file</code></em></span></dt>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Use <em class="replaceable"><code>config-file</code></em> as the
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd configuration file instead of the default,
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd ensure that reloading the configuration file continues
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd to work after the server has changed its working
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd directory due to to a possible
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd <code class="option">directory</code> option in the configuration
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd file, <em class="replaceable"><code>config-file</code></em> should be
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd an absolute pathname.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<dt><span class="term">-d <em class="replaceable"><code>debug-level</code></em></span></dt>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Set the daemon's debug level to <em class="replaceable"><code>debug-level</code></em>.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Debugging traces from <span><strong class="command">named</strong></span> become
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd more verbose as the debug level increases.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<dt><span class="term">-E <em class="replaceable"><code>engine-name</code></em></span></dt>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Use a crypto hardware (OpenSSL engine) for the crypto operations
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd it supports, for instance re-signing with private keys from
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd a secure key store. When compiled with PKCS#11 support
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd defaults to pkcs11, the empty name resets it to no engine.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Run the server in the foreground (i.e. do not daemonize).
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Run the server in the foreground and force all logging
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<dt><span class="term">-m <em class="replaceable"><code>flag</code></em></span></dt>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Turn on memory usage debugging flags. Possible flags are
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd These correspond to the ISC_MEM_DEBUGXXXX flags described in
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<dt><span class="term">-n <em class="replaceable"><code>#cpus</code></em></span></dt>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Create <em class="replaceable"><code>#cpus</code></em> worker threads
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd to take advantage of multiple CPUs. If not specified,
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd <span><strong class="command">named</strong></span> will try to determine the
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd number of CPUs present and create one thread per CPU.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd If it is unable to determine the number of CPUs, a
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd single worker thread will be created.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Listen for queries on port <em class="replaceable"><code>port</code></em>. If not
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd specified, the default is port 53.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Write memory usage statistics to <code class="filename">stdout</code> on exit.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd This option is mainly of interest to BIND 9 developers
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd and may be removed or changed in a future release.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<dt><span class="term">-S <em class="replaceable"><code>#max-socks</code></em></span></dt>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Allow <span><strong class="command">named</strong></span> to use up to
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd <em class="replaceable"><code>#max-socks</code></em> sockets.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd This option should be unnecessary for the vast majority
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd The use of this option could even be harmful because the
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd specified value may exceed the limitation of the
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd underlying system API.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd It is therefore set only when the default configuration
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd causes exhaustion of file descriptors and the
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd operational environment is known to support the
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd specified number of sockets.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Note also that the actual maximum number is normally a little
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd fewer than the specified value because
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd <span><strong class="command">named</strong></span> reserves some file descriptors
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd for its internal use.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<dt><span class="term">-t <em class="replaceable"><code>directory</code></em></span></dt>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd to <em class="replaceable"><code>directory</code></em> after
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd processing the command line arguments, but before
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd reading the configuration file.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd This option should be used in conjunction with the
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd <code class="option">-u</code> option, as chrooting a process
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd running as root doesn't enhance security on most
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd systems; the way <code class="function">chroot(2)</code> is
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd defined allows a process with root privileges to
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd escape a chroot jail.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<dt><span class="term">-u <em class="replaceable"><code>user</code></em></span></dt>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd to <em class="replaceable"><code>user</code></em> after completing
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd privileged operations, such as creating sockets that
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd listen on privileged ports.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<div class="note" style="margin-left: 0.5in; margin-right: 0.5in;">
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd On Linux, <span><strong class="command">named</strong></span> uses the kernel's
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd capability mechanism to drop all root privileges
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd except the ability to <code class="function">bind(2)</code> to
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd privileged port and set process resource limits.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Unfortunately, this means that the <code class="option">-u</code>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd option only works when <span><strong class="command">named</strong></span> is
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd on kernel 2.2.18 or later, or kernel 2.3.99-pre3 or
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd later, since previous kernels did not allow privileges
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd to be retained after <code class="function">setuid(2)</code>.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Report the version number and exit.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Report the version number and build options, and exit.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<dt><span class="term">-x <em class="replaceable"><code>cache-file</code></em></span></dt>
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Load data from <em class="replaceable"><code>cache-file</code></em> into the
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd cache of the default view.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd<div class="warning" style="margin-left: 0.5in; margin-right: 0.5in;">
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd This option must not be used. It is only of interest
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd to BIND 9 developers and may be removed or changed in a
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd future release.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd In routine operation, signals should not be used to control
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd the nameserver; <span><strong class="command">rndc</strong></span> should be used
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Force a reload of the server.
97a3ecc40b65d5f8e865bbe0b1c9325d8c016e34nd Shut down the server.
9472e4d3c410be3b3f1addbf3b1db1769f64e765nd The result of sending any other signals to the server is undefined.
f086b4b402fa9a2fefc7dda85de2a3cc1cd0a654rjung The <span><strong class="command">named</strong></span> configuration file is too complex
727872d18412fc021f03969b8641810d8896820bhumbedooh to describe in detail here. A complete description is provided
727872d18412fc021f03969b8641810d8896820bhumbedooh <em class="citetitle">BIND 9 Administrator Reference Manual</em>.
cc7e1025de9ac63bd4db6fe7f71c158b2cf09fe4humbedooh <span><strong class="command">named</strong></span> inherits the <code class="function">umask</code>
727872d18412fc021f03969b8641810d8896820bhumbedooh (file creation mode mask) from the parent process. If files
0d0ba3a410038e179b695446bb149cce6264e0abnd created by <span><strong class="command">named</strong></span>, such as journal files,
0d0ba3a410038e179b695446bb149cce6264e0abnd need to have custom permissions, the <code class="function">umask</code>
0d0ba3a410038e179b695446bb149cce6264e0abnd should be set explicitly in the script used to start the
ac082aefa89416cbdc9a1836eaf3bed9698201c8humbedooh <span><strong class="command">named</strong></span> process.
0d0ba3a410038e179b695446bb149cce6264e0abnd<dt><span class="term"><code class="filename">/etc/named.conf</code></span></dt>
205f749042ed530040a4f0080dbcb47ceae8a374rjung The default configuration file.
0d0ba3a410038e179b695446bb149cce6264e0abnd<dt><span class="term"><code class="filename">/var/run/named/named.pid</code></span></dt>
7fec19672a491661b2fe4b29f685bc7f4efa64d4nd The default process-id file.