0N/A - Copyright (C) 2000-2016 Internet Systems Consortium, Inc. ("ISC") 0N/A - This Source Code Form is subject to the terms of the Mozilla Public 0N/A - License, v. 2.0. If a copy of the MPL was not distributed with this 0N/A<
meta http-
equiv="Content-Type" content="text/html; charset=ISO-8859-1">
0N/A<
title>nsupdate</
title>
0N/A<
meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
0N/A<
link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
0N/A<
body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
0N/A<
div class="navheader">
0N/A<
table width="100%" summary="Navigation header">
0N/A<
tr><
th colspan="3" align="center"><
span class="application">nsupdate</
span></
th></
tr>
0N/A<
td width="20%" align="left">
0N/A<
th width="60%" align="center">Manual pages</
th>
0N/A<
div class="refentry">
0N/A <
div class="refnamediv">
0N/A <
span class="application">nsupdate</
span>
0N/A — Dynamic DNS update utility
0N/A <
div class="refsynopsisdiv">
0N/A <
div class="cmdsynopsis"><
p>
0N/A <
code class="command">nsupdate</
code>
0N/A [<
code class="option">-d</
code>]
0N/A [<
code class="option">-D</
code>]
0N/A [<
code class="option">-L <
em class="replaceable"><
code>level</
code></
em></
code>]
0N/A [<
code class="option">-g</
code>]
0N/A | [<
code class="option">-o</
code>]
0N/A | [<
code class="option">-l</
code>]
0N/A | [<
code class="option">-y <
em class="replaceable"><
code>[<
span class="optional">hmac:</
span>]keyname:secret</
code></
em></
code>]
0N/A | [<
code class="option">-k <
em class="replaceable"><
code>keyfile</
code></
em></
code>]
0N/A [<
code class="option">-t <
em class="replaceable"><
code>timeout</
code></
em></
code>]
0N/A [<
code class="option">-u <
em class="replaceable"><
code>udptimeout</
code></
em></
code>]
135N/A [<
code class="option">-r <
em class="replaceable"><
code>udpretries</
code></
em></
code>]
135N/A [<
code class="option">-R <
em class="replaceable"><
code>randomdev</
code></
em></
code>]
135N/A [<
code class="option">-v</
code>]
0N/A [<
code class="option">-T</
code>]
0N/A [<
code class="option">-P</
code>]
0N/A [<
code class="option">-V</
code>]
135N/A <
div class="refsection">
0N/A<
a name="id-1.14.26.7"></
a><
h2>DESCRIPTION</
h2>
0N/A <
p><
span class="command"><
strong>nsupdate</
strong></
span>
0N/A is used to submit Dynamic DNS Update requests as defined in RFC 2136
0N/A This allows resource records to be added or removed from a zone
0N/A without manually editing the zone file.
0N/A A single update request can contain requests to add or remove more than
0N/A Zones that are under dynamic control via
70N/A <
span class="command"><
strong>nsupdate</
strong></
span>
70N/A or a DHCP server should not be edited by hand.
0N/A conflict with dynamic updates and cause data to be lost.
0N/A The resource records that are dynamically added or removed with
0N/A <
span class="command"><
strong>nsupdate</
strong></
span>
0N/A have to be in the same zone.
0N/A Requests are sent to the zone's master server.
135N/A This is identified by the MNAME field of the zone's SOA record.
0N/A Transaction signatures can be used to authenticate the Dynamic
0N/A DNS updates. These use the TSIG resource record type described
0N/A in RFC 2845 or the SIG(0) record described in RFC 2535 and
0N/A RFC 2931 or GSS-TSIG as described in RFC 3645.
0N/A a shared secret that should only be known to
0N/A <
span class="command"><
strong>nsupdate</
strong></
span> and the name server.
0N/A For instance, suitable <
span class="type">key</
span> and
0N/A <
span class="type">server</
span> statements would be added to
0N/A can associate the appropriate secret key and algorithm with
0N/A the IP address of the client application that will be using
0N/A TSIG authentication. You can use <
span class="command"><
strong>ddns-confgen</
strong></
span>
0N/A to generate suitable configuration fragments.
0N/A <
span class="command"><
strong>nsupdate</
strong></
span>
0N/A uses the <
code class="option">-y</
code> or <
code class="option">-k</
code> options
0N/A to provide the TSIG shared secret. These options are mutually exclusive.
0N/A SIG(0) uses public key cryptography.
135N/A To use a SIG(0) key, the public key must be stored in a KEY
135N/A record in a zone served by the name server.
135N/A GSS-TSIG uses Kerberos credentials. Standard GSS-TSIG mode
135N/A is switched on with the <
code class="option">-g</
code> flag. A
135N/A non-standards-compliant variant of GSS-TSIG used by Windows
135N/A 2000 can be switched on with the <
code class="option">-o</
code> flag.
135N/A <
div class="refsection">
135N/A<
a name="id-1.14.26.8"></
a><
h2>OPTIONS</
h2>
0N/A <
div class="variablelist"><
dl class="variablelist">
0N/A<
dt><
span class="term">-d</
span></
dt>
0N/A Debug mode. This provides tracing information about the
0N/A update requests that are made and the replies received
0N/A from the name server.
135N/A<
dt><
span class="term">-D</
span></
dt>
135N/A<
dt><
span class="term">-k <
em class="replaceable"><
code>keyfile</
code></
em></
span></
dt>
135N/A The file containing the TSIG authentication key.
135N/A Keyfiles may be in two formats: a single file containing
135N/A a <
code class="filename">
named.conf</
code>-format <
span class="command"><
strong>key</
strong></
span>
135N/A statement, which may be generated automatically by
135N/A <
span class="command"><
strong>ddns-confgen</
strong></
span>, or a pair of files whose names are
135N/A of the format <
code class="filename">K{name}.+157.+{random}.key</
code> and
135N/A <
code class="filename">K{name}.+157.+{random}.private</
code>, which can be
135N/A generated by <
span class="command"><
strong>dnssec-keygen</
strong></
span>.
135N/A The <
code class="option">-k</
code> may also be used to specify a SIG(0) key used
135N/A to authenticate Dynamic DNS update requests. In this case, the key
135N/A specified is not an HMAC-MD5 key.
135N/A<
dt><
span class="term">-l</
span></
dt>
135N/A Local-host only mode. This sets the server address to
135N/A localhost (disabling the <
span class="command"><
strong>server</
strong></
span> so that the server
135N/A address cannot be overridden). Connections to the local server will
135N/A which is automatically generated by <
span class="command"><
strong>named</
strong></
span> if any
135N/A local master zone has set <
span class="command"><
strong>update-policy</
strong></
span> to
135N/A <
span class="command"><
strong>local</
strong></
span>. The location of this key file can be
135N/A overridden with the <
code class="option">-k</
code> option.
135N/A<
dt><
span class="term">-L <
em class="replaceable"><
code>level</
code></
em></
span></
dt>
135N/A Set the logging debug level. If zero, logging is disabled.
0N/A<
dt><
span class="term">-p <
em class="replaceable"><
code>port</
code></
em></
span></
dt>
0N/A Set the port to use for connections to a name server. The
0N/A<
dt><
span class="term">-P</
span></
dt>
0N/A Print the list of private BIND-specific resource record
0N/A types whose format is understood
0N/A by <
span class="command"><
strong>nsupdate</
strong></
span>. See also
0N/A the <
code class="option">-T</
code> option.
0N/A<
dt><
span class="term">-r <
em class="replaceable"><
code>udpretries</
code></
em></
span></
dt>
0N/A The number of UDP retries. The default is 3. If zero, only
0N/A one update request will be made.
0N/A<
dt><
span class="term">-R <
em class="replaceable"><
code>randomdev</
code></
em></
span></
dt>
0N/A Where to obtain randomness. If the operating system
0N/A does not provide a <
code class="filename">/
dev/
random</
code> or
0N/A equivalent device, the default source of randomness is keyboard
0N/A input. <
code class="filename">randomdev</
code> specifies the name of
0N/A a character device or file containing random data to be used
0N/A instead of the default. The special value
0N/A <
code class="filename">keyboard</
code> indicates that keyboard input
0N/A should be used. This option may be specified multiple times.
0N/A<
dt><
span class="term">-t <
em class="replaceable"><
code>timeout</
code></
em></
span></
dt>
0N/A The maximum time an update request can take before it is
0N/A aborted. The default is 300 seconds. Zero can be used to
0N/A disable the timeout.
0N/A<
dt><
span class="term">-T</
span></
dt>
0N/A Print the list of IANA standard resource record types
0N/A whose format is understood by <
span class="command"><
strong>nsupdate</
strong></
span>.
0N/A <
span class="command"><
strong>nsupdate</
strong></
span> will exit after the lists are
0N/A printed. The <
code class="option">-T</
code> option can be combined
0N/A with the <
code class="option">-P</
code> option.
0N/A Other types can be entered using "TYPEXXXXX" where "XXXXX" is the
0N/A decimal value of the type with no leading zeros. The rdata,
0N/A if present, will be parsed using the UNKNOWN rdata format,
0N/A (<backslash> <hash> <space> <length>
0N/A <space> <hexstring>).
0N/A<
dt><
span class="term">-u <
em class="replaceable"><
code>udptimeout</
code></
em></
span></
dt>
0N/A The UDP retry interval. The default is 3 seconds. If zero,
0N/A the interval will be computed from the timeout interval and
0N/A number of UDP retries.
0N/A<
dt><
span class="term">-v</
span></
dt>
0N/A Use TCP even for small update requests.
0N/A By default, <
span class="command"><
strong>nsupdate</
strong></
span>
0N/A uses UDP to send update requests to the name server unless they are too
0N/A large to fit in a UDP request in which case TCP will be used.
0N/A TCP may be preferable when a batch of update requests is made.
0N/A<
dt><
span class="term">-V</
span></
dt>
0N/A Print the version number and exit.
0N/A<
dt><
span class="term">-y <
em class="replaceable"><
code>[<
span class="optional">hmac:</
span>]keyname:secret</
code></
em></
span></
dt>
0N/A Literal TSIG authentication key.
0N/A <
em class="parameter"><
code>keyname</
code></
em> is the name of the key, and
0N/A <
em class="parameter"><
code>secret</
code></
em> is the base64 encoded shared secret.
0N/A <
em class="parameter"><
code>hmac</
code></
em> is the name of the key algorithm;
0N/A valid choices are <
code class="literal">hmac-md5</
code>,
0N/A <
code class="literal">hmac-sha1</
code>, <
code class="literal">hmac-sha224</
code>,
0N/A <
code class="literal">hmac-sha256</
code>, <
code class="literal">hmac-sha384</
code>, or
0N/A <
code class="literal">hmac-sha512</
code>. If <
em class="parameter"><
code>hmac</
code></
em>
0N/A is not specified, the default is <
code class="literal">hmac-md5</
code>
0N/A or if MD5 was disabled <
code class="literal">hmac-sha256</
code>.
0N/A NOTE: Use of the <
code class="option">-y</
code> option is discouraged because the
0N/A shared secret is supplied as a command line argument in clear text.
0N/A This may be visible in the output from
0N/A <
span class="citerefentry">
0N/A <
span class="refentrytitle">ps</
span>(1)
0N/A or in a history file maintained by the user's shell.
0N/A <
div class="refsection">
0N/A<
a name="id-1.14.26.9"></
a><
h2>INPUT FORMAT</
h2>
0N/A <
p><
span class="command"><
strong>nsupdate</
strong></
span>
0N/A <
em class="parameter"><
code>filename</
code></
em>
0N/A Each command is supplied on exactly one line of input.
0N/A Some commands are for administrative purposes.
0N/A The others are either update instructions or prerequisite checks on the
0N/A contents of the zone.
0N/A These checks set conditions that some name or set of
0N/A resource records (RRset) either exists or is absent from the zone.
0N/A These conditions must be met if the entire update request is to succeed.
0N/A Updates will be rejected if the tests for the prerequisite conditions
0N/A Every update request consists of zero or more prerequisites
0N/A and zero or more updates.
0N/A This allows a suitably authenticated update request to proceed if some
0N/A specified resource records are present or missing from the zone.
0N/A A blank input line (or the <
span class="command"><
strong>send</
strong></
span> command)
0N/A accumulated commands to be sent as one Dynamic DNS update request to the
0N/A The command formats and their meaning are as follows:
0N/A<
div class="variablelist"><
dl class="variablelist">
0N/A<
dt><
span class="term">
0N/A <
span class="command"><
strong>server</
strong></
span>
0N/A Sends all dynamic update requests to the name server
0N/A <
em class="parameter"><
code>servername</
code></
em>.
0N/A When no server statement is provided,
0N/A <
span class="command"><
strong>nsupdate</
strong></
span>
0N/A will send updates to the master server of the correct zone.
0N/A The MNAME field of that zone's SOA record will identify the
0N/A server for that zone.
0N/A <
em class="parameter"><
code>port</
code></
em>
0N/A is the port number on
0N/A <
em class="parameter"><
code>servername</
code></
em>
0N/A where the dynamic update requests get sent.
0N/A If no port number is specified, the default DNS port number of
0N/A<
dt><
span class="term">
0N/A <
span class="command"><
strong>local</
strong></
span>
0N/A Sends all dynamic update requests using the local
0N/A <
em class="parameter"><
code>address</
code></
em>.
0N/A When no local statement is provided,
0N/A <
span class="command"><
strong>nsupdate</
strong></
span>
0N/A will send updates using an address and port chosen by the
0N/A <
em class="parameter"><
code>port</
code></
em>
0N/A can additionally be used to make requests come from a specific
0N/A If no port number is specified, the system will assign one.
0N/A<
dt><
span class="term">
0N/A <
span class="command"><
strong>zone</
strong></
span>
0N/A Specifies that all updates are to be made to the zone
0N/A <
em class="parameter"><
code>zonename</
code></
em>.
0N/A <
em class="parameter"><
code>zone</
code></
em>
0N/A statement is provided,
0N/A <
span class="command"><
strong>nsupdate</
strong></
span>
0N/A will attempt determine the correct zone to update based on the
0N/A<
dt><
span class="term">
0N/A <
span class="command"><
strong>class</
strong></
span>
135N/A Specify the default class.
135N/A If no <
em class="parameter"><
code>class</
code></
em> is specified, the
135N/A <
em class="parameter"><
code>IN</
code></
em>.
135N/A <
span class="command"><
strong>ttl</
strong></
span>
135N/A Specify the default time to live for records to be added.
135N/A The value <
em class="parameter"><
code>none</
code></
em> will clear the default
135N/A <
span class="command"><
strong>key</
strong></
span>
135N/A Specifies that all updates are to be TSIG-signed using the
135N/A <
em class="parameter"><
code>keyname</
code></
em> <
em class="parameter"><
code>secret</
code></
em> pair.
135N/A If <
em class="parameter"><
code>hmac</
code></
em> is specified, then it sets the
135N/A signing algorithm in use; the default is
135N/A <
code class="literal">hmac-md5</
code> or if MD5 was disabled
135N/A <
code class="literal">hmac-sha256</
code>. The <
span class="command"><
strong>key</
strong></
span>
135N/A command overrides any key specified on the command line via
135N/A <
code class="option">-y</
code> or <
code class="option">-k</
code>.
0N/A <
span class="command"><
strong>gsstsig</
strong></
span>
0N/A Use GSS-TSIG to sign the updated. This is equivalent to
61N/A specifying <
code class="option">-g</
code> on the command line.
61N/A<
dt><
span class="term">
61N/A <
span class="command"><
strong>oldgsstsig</
strong></
span>
61N/A Use the Windows 2000 version of GSS-TSIG to sign the updated.
61N/A This is equivalent to specifying <
code class="option">-o</
code> on the
61N/A<
dt><
span class="term">
61N/A <
span class="command"><
strong>realm</
strong></
span>
61N/A {[<
span class="optional">realm_name</
span>]}
61N/A When using GSS-TSIG use <
em class="parameter"><
code>realm_name</
code></
em> rather
61N/A than the default realm in <
code class="filename">
krb5.conf</
code>. If no
61N/A realm is specified the saved realm is cleared.
61N/A<
dt><
span class="term">
0N/A <
span class="command"><
strong>check-names</
strong></
span>
0N/A {[<
span class="optional">yes_or_no</
span>]}
0N/A Turn on or off check-names processing on records to
0N/A be added. Check-names has no effect on prerequisites
0N/A or records to be deleted. By default check-names
0N/A processing is on. If check-names processing fails
0N/A the record will not be added to the UPDATE message.
0N/A<
dt><
span class="term">
0N/A <
span class="command"><
strong>[<
span class="optional">prereq</
span>] nxdomain</
strong></
span>
0N/A Requires that no resource record of any type exists with name
0N/A <
em class="parameter"><
code>domain-name</
code></
em>.
0N/A<
dt><
span class="term">
0N/A <
span class="command"><
strong>[<
span class="optional">prereq</
span>] yxdomain</
strong></
span>
0N/A <
em class="parameter"><
code>domain-name</
code></
em>
0N/A exists (has as at least one resource record, of any type).
61N/A<
dt><
span class="term">
0N/A <
span class="command"><
strong>[<
span class="optional">prereq</
span>] nxrrset</
strong></
span>
61N/A Requires that no resource record exists of the specified
61N/A <
em class="parameter"><
code>type</
code></
em>,
61N/A <
em class="parameter"><
code>class</
code></
em>
61N/A <
em class="parameter"><
code>domain-name</
code></
em>.
61N/A <
em class="parameter"><
code>class</
code></
em>
61N/A is omitted, IN (internet) is assumed.
0N/A<
dt><
span class="term">
61N/A <
span class="command"><
strong>[<
span class="optional">prereq</
span>] yxrrset</
strong></
span>
61N/A This requires that a resource record of the specified
0N/A <
em class="parameter"><
code>type</
code></
em>,
0N/A <
em class="parameter"><
code>class</
code></
em>
0N/A <
em class="parameter"><
code>domain-name</
code></
em>
0N/A <
em class="parameter"><
code>class</
code></
em>
0N/A is omitted, IN (internet) is assumed.
0N/A<
dt><
span class="term">
0N/A <
span class="command"><
strong>[<
span class="optional">prereq</
span>] yxrrset</
strong></
span>
0N/A <
em class="parameter"><
code>data</
code></
em>
0N/A from each set of prerequisites of this form
<
em class="parameter"><
code>type</
code></
em>,
<
em class="parameter"><
code>class</
code></
em>,
<
em class="parameter"><
code>domain-name</
code></
em>
are combined to form a set of RRs. This set of RRs must
exactly match the set of RRs existing in the zone at the
<
em class="parameter"><
code>type</
code></
em>,
<
em class="parameter"><
code>class</
code></
em>,
<
em class="parameter"><
code>domain-name</
code></
em>.
<
em class="parameter"><
code>data</
code></
em>
are written in the standard text representation of the resource
<
span class="command"><
strong>[<
span class="optional">update</
span>] del[<
span class="optional">ete</
span>]</
strong></
span>
Deletes any resource records named
<
em class="parameter"><
code>domain-name</
code></
em>.
<
em class="parameter"><
code>type</
code></
em>
<
em class="parameter"><
code>data</
code></
em>
is provided, only matching resource records will be removed.
The internet class is assumed if
<
em class="parameter"><
code>class</
code></
em>
<
em class="parameter"><
code>ttl</
code></
em>
is ignored, and is only allowed for compatibility.
<
span class="command"><
strong>[<
span class="optional">update</
span>] add</
strong></
span>
Adds a new resource record with the specified
<
em class="parameter"><
code>ttl</
code></
em>,
<
em class="parameter"><
code>class</
code></
em>
<
em class="parameter"><
code>data</
code></
em>.
<
span class="command"><
strong>show</
strong></
span>
Displays the current message, containing all of the
updates specified since the last send.
<
span class="command"><
strong>send</
strong></
span>
Sends the current message. This is equivalent to entering a
<
span class="command"><
strong>answer</
strong></
span>
<
span class="command"><
strong>debug</
strong></
span>
<
span class="command"><
strong>version</
strong></
span>
<
span class="command"><
strong>help</
strong></
span>
Print a list of commands.
Lines beginning with a semicolon are comments and are ignored.
<
a name="id-1.14.26.10"></
a><
h2>EXAMPLES</
h2>
The examples below show how
<
span class="command"><
strong>nsupdate</
strong></
span>
could be used to insert and delete resource records from the
Notice that the input in each example contains a trailing blank line so
a group of commands are sent as one dynamic update request to the
<
pre class="programlisting">
with IP address 172.16.1.1 is added.
The newly-added record has a 1 day TTL (86400 seconds).
<
pre class="programlisting">
The prerequisite condition gets the name server to check that there
are no resource records of any type for
If there are, the update request fails.
If this name does not exist, a CNAME for it is added.
This ensures that when the CNAME is added, it cannot conflict with the
long-standing rule in RFC 1034 that a name must not exist as any other
record type if it exists as a CNAME.
(The rule has been updated for DNSSEC in RFC 2535 to allow CNAMEs to have
RRSIG, DNSKEY and NSEC records.)
<
a name="id-1.14.26.11"></
a><
h2>FILES</
h2>
<
div class="variablelist"><
dl class="variablelist">
<
dt><
span class="term"><
code class="constant">/
etc/
resolv.conf</
code></
span></
dt>
used to identify default name server
sets the default TSIG key for use in local-only mode
<
dt><
span class="term"><
code class="constant">K{name}.+157.+{random}.key</
code></
span></
dt>
base-64 encoding of HMAC-MD5 key created by
<
span class="citerefentry">
<
span class="refentrytitle">dnssec-keygen</
span>(8)
<
dt><
span class="term"><
code class="constant">K{name}.+157.+{random}.private</
code></
span></
dt>
base-64 encoding of HMAC-MD5 key created by
<
span class="citerefentry">
<
span class="refentrytitle">dnssec-keygen</
span>(8)
<
a name="id-1.14.26.12"></
a><
h2>SEE ALSO</
h2>
<
em class="citetitle">RFC 2136</
em>,
<
em class="citetitle">RFC 3007</
em>,
<
em class="citetitle">RFC 2104</
em>,
<
em class="citetitle">RFC 2845</
em>,
<
em class="citetitle">RFC 1034</
em>,
<
em class="citetitle">RFC 2535</
em>,
<
em class="citetitle">RFC 2931</
em>,
<
span class="citerefentry">
<
span class="refentrytitle">named</
span>(8)
<
span class="citerefentry">
<
span class="refentrytitle">ddns-confgen</
span>(8)
<
span class="citerefentry">
<
span class="refentrytitle">dnssec-keygen</
span>(8)
<
a name="id-1.14.26.13"></
a><
h2>BUGS</
h2>
The TSIG key is redundantly stored in two separate files.
This is a consequence of nsupdate using the DST library
for its cryptographic operations, and may change in future
<
table width="100%" summary="Navigation footer">
<
td width="40%" align="left">
<
td width="20%" align="center"><
a accesskey="u" href="Bv9ARM.ch13.html">Up</
a></
td>
<
td width="40%" align="right">�<
a accesskey="n" href="man.rndc.html">Next</
a>
<
td width="40%" align="left" valign="top">
<
span class="application">named-rrchecker</
span>�</
td>
<
td width="20%" align="center"><
a accesskey="h" href="Bv9ARM.html">Home</
a></
td>
<
td width="40%" align="right" valign="top">�<
span class="application">rndc</
span>