man.rndc.html revision 12351e0500dff39f56844401fd191a36bcc4a7ad
64c02f1310b7747423957823ee09fb3608430f89nd<!--
64c02f1310b7747423957823ee09fb3608430f89nd - Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC")
64c02f1310b7747423957823ee09fb3608430f89nd - Copyright (C) 2000-2003 Internet Software Consortium.
64c02f1310b7747423957823ee09fb3608430f89nd -
64c02f1310b7747423957823ee09fb3608430f89nd - Permission to use, copy, modify, and distribute this software for any
64c02f1310b7747423957823ee09fb3608430f89nd - purpose with or without fee is hereby granted, provided that the above
64c02f1310b7747423957823ee09fb3608430f89nd - copyright notice and this permission notice appear in all copies.
64c02f1310b7747423957823ee09fb3608430f89nd -
64c02f1310b7747423957823ee09fb3608430f89nd - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
64c02f1310b7747423957823ee09fb3608430f89nd - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
64c02f1310b7747423957823ee09fb3608430f89nd - PERFORMANCE OF THIS SOFTWARE.
64c02f1310b7747423957823ee09fb3608430f89nd-->
64c02f1310b7747423957823ee09fb3608430f89nd<!-- $Id: man.rndc.html,v 1.52 2007/05/30 02:30:15 marka Exp $ -->
d229f940abfb2490dee17979e9a5ff31b7012eb5rbowen<html>
3f08db06526d6901aa08c110b5bc7dde6bc39905nd<head>
64c02f1310b7747423957823ee09fb3608430f89nd<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
64c02f1310b7747423957823ee09fb3608430f89nd<title>rndc</title>
64c02f1310b7747423957823ee09fb3608430f89nd<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
3f08db06526d6901aa08c110b5bc7dde6bc39905nd<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
64c02f1310b7747423957823ee09fb3608430f89nd<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
64c02f1310b7747423957823ee09fb3608430f89nd<link rel="prev" href="man.named.html" title="named">
3b3b7fc78d1f5bfc2769903375050048ff41ff26nd<link rel="next" href="man.rndc.conf.html" title="rndc.conf">
a78048ccbdb6256da15e6b0e7e95355e480c2301nd</head>
0066eddda7203f6345b56f77d146a759298dc635gryzor<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
7f5b59ccc63c0c0e3e678a168f09ee6a2f51f9d0nd<div class="navheader">
f086b4b402fa9a2fefc7dda85de2a3cc1cd0a654rjung<table width="100%" summary="Navigation header">
3b3b7fc78d1f5bfc2769903375050048ff41ff26nd<tr><th colspan="3" align="center"><span class="application">rndc</span></th></tr>
64c02f1310b7747423957823ee09fb3608430f89nd<tr>
64c02f1310b7747423957823ee09fb3608430f89nd<td width="20%" align="left">
64c02f1310b7747423957823ee09fb3608430f89nd<a accesskey="p" href="man.named.html">Prev</a>�</td>
64c02f1310b7747423957823ee09fb3608430f89nd<th width="60%" align="center">Manual pages</th>
64c02f1310b7747423957823ee09fb3608430f89nd<td width="20%" align="right">�<a accesskey="n" href="man.rndc.conf.html">Next</a>
64c02f1310b7747423957823ee09fb3608430f89nd</td>
64c02f1310b7747423957823ee09fb3608430f89nd</tr>
64c02f1310b7747423957823ee09fb3608430f89nd</table>
64c02f1310b7747423957823ee09fb3608430f89nd<hr>
64c02f1310b7747423957823ee09fb3608430f89nd</div>
64c02f1310b7747423957823ee09fb3608430f89nd<div class="refentry" lang="en">
64c02f1310b7747423957823ee09fb3608430f89nd<a name="man.rndc"></a><div class="titlepage"></div>
64c02f1310b7747423957823ee09fb3608430f89nd<div class="refnamediv">
8e0c9984e1432c934dacca53efc92cde30d0fe53rbowen<h2>Name</h2>
64c02f1310b7747423957823ee09fb3608430f89nd<p><span class="application">rndc</span> &#8212; name server control utility</p>
64c02f1310b7747423957823ee09fb3608430f89nd</div>
64c02f1310b7747423957823ee09fb3608430f89nd<div class="refsynopsisdiv">
64c02f1310b7747423957823ee09fb3608430f89nd<h2>Synopsis</h2>
64c02f1310b7747423957823ee09fb3608430f89nd<div class="cmdsynopsis"><p><code class="command">rndc</code> [<code class="option">-b <em class="replaceable"><code>source-address</code></em></code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key-file</code></em></code>] [<code class="option">-s <em class="replaceable"><code>server</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-V</code>] [<code class="option">-y <em class="replaceable"><code>key_id</code></em></code>] {command}</p></div>
64c02f1310b7747423957823ee09fb3608430f89nd</div>
64c02f1310b7747423957823ee09fb3608430f89nd<div class="refsect1" lang="en">
64c02f1310b7747423957823ee09fb3608430f89nd<a name="id2604387"></a><h2>DESCRIPTION</h2>
64c02f1310b7747423957823ee09fb3608430f89nd<p><span><strong class="command">rndc</strong></span>
64c02f1310b7747423957823ee09fb3608430f89nd controls the operation of a name
64c02f1310b7747423957823ee09fb3608430f89nd server. It supersedes the <span><strong class="command">ndc</strong></span> utility
64c02f1310b7747423957823ee09fb3608430f89nd that was provided in old BIND releases. If
64c02f1310b7747423957823ee09fb3608430f89nd <span><strong class="command">rndc</strong></span> is invoked with no command line
64c02f1310b7747423957823ee09fb3608430f89nd options or arguments, it prints a short summary of the
64c02f1310b7747423957823ee09fb3608430f89nd supported commands and the available options and their
64c02f1310b7747423957823ee09fb3608430f89nd arguments.
64c02f1310b7747423957823ee09fb3608430f89nd </p>
64c02f1310b7747423957823ee09fb3608430f89nd<p><span><strong class="command">rndc</strong></span>
64c02f1310b7747423957823ee09fb3608430f89nd communicates with the name server
64c02f1310b7747423957823ee09fb3608430f89nd over a TCP connection, sending commands authenticated with
64c02f1310b7747423957823ee09fb3608430f89nd digital signatures. In the current versions of
64c02f1310b7747423957823ee09fb3608430f89nd <span><strong class="command">rndc</strong></span> and <span><strong class="command">named</strong></span> named
64c02f1310b7747423957823ee09fb3608430f89nd the only supported authentication algorithm is HMAC-MD5,
64c02f1310b7747423957823ee09fb3608430f89nd which uses a shared secret on each end of the connection.
64c02f1310b7747423957823ee09fb3608430f89nd This provides TSIG-style authentication for the command
64c02f1310b7747423957823ee09fb3608430f89nd request and the name server's response. All commands sent
64c02f1310b7747423957823ee09fb3608430f89nd over the channel must be signed by a key_id known to the
64c02f1310b7747423957823ee09fb3608430f89nd server.
64c02f1310b7747423957823ee09fb3608430f89nd </p>
64c02f1310b7747423957823ee09fb3608430f89nd<p><span><strong class="command">rndc</strong></span>
8951c7d73bfa2ae5a2c8fe5bd27f3e677be02564noirin reads a configuration file to
8951c7d73bfa2ae5a2c8fe5bd27f3e677be02564noirin determine how to contact the name server and decide what
64c02f1310b7747423957823ee09fb3608430f89nd algorithm and key it should use.
64c02f1310b7747423957823ee09fb3608430f89nd </p>
64c02f1310b7747423957823ee09fb3608430f89nd</div>
64c02f1310b7747423957823ee09fb3608430f89nd<div class="refsect1" lang="en">
64c02f1310b7747423957823ee09fb3608430f89nd<a name="id2604437"></a><h2>OPTIONS</h2>
9335f6d807d76d60e54af4ededdebebddb3e3d13noodl<div class="variablelist"><dl>
30471a4650391f57975f60bbb6e4a90be7b284bfhumbedooh<dt><span class="term">-b <em class="replaceable"><code>source-address</code></em></span></dt>
64c02f1310b7747423957823ee09fb3608430f89nd<dd><p>
64c02f1310b7747423957823ee09fb3608430f89nd Use <em class="replaceable"><code>source-address</code></em>
64c02f1310b7747423957823ee09fb3608430f89nd as the source address for the connection to the server.
64c02f1310b7747423957823ee09fb3608430f89nd Multiple instances are permitted to allow setting of both
67c026fea89b4faf173772b5944b6aa006ca6eb0nd the IPv4 and IPv6 source addresses.
64c02f1310b7747423957823ee09fb3608430f89nd </p></dd>
64c02f1310b7747423957823ee09fb3608430f89nd<dt><span class="term">-c <em class="replaceable"><code>config-file</code></em></span></dt>
64c02f1310b7747423957823ee09fb3608430f89nd<dd><p>
64c02f1310b7747423957823ee09fb3608430f89nd Use <em class="replaceable"><code>config-file</code></em>
64c02f1310b7747423957823ee09fb3608430f89nd as the configuration file instead of the default,
64c02f1310b7747423957823ee09fb3608430f89nd <code class="filename">/etc/rndc.conf</code>.
64c02f1310b7747423957823ee09fb3608430f89nd </p></dd>
64c02f1310b7747423957823ee09fb3608430f89nd<dt><span class="term">-k <em class="replaceable"><code>key-file</code></em></span></dt>
64c02f1310b7747423957823ee09fb3608430f89nd<dd><p>
64c02f1310b7747423957823ee09fb3608430f89nd Use <em class="replaceable"><code>key-file</code></em>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic as the key file instead of the default,
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic <code class="filename">/etc/rndc.key</code>. The key in
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic <code class="filename">/etc/rndc.key</code> will be used to
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic authenticate
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic commands sent to the server if the <em class="replaceable"><code>config-file</code></em>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic does not exist.
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic </p></dd>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic<dt><span class="term">-s <em class="replaceable"><code>server</code></em></span></dt>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic<dd><p><em class="replaceable"><code>server</code></em> is
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic the name or address of the server which matches a
64c02f1310b7747423957823ee09fb3608430f89nd server statement in the configuration file for
64c02f1310b7747423957823ee09fb3608430f89nd <span><strong class="command">rndc</strong></span>. If no server is supplied on
67c026fea89b4faf173772b5944b6aa006ca6eb0nd the
64c02f1310b7747423957823ee09fb3608430f89nd command line, the host named by the default-server clause
64c02f1310b7747423957823ee09fb3608430f89nd in the option statement of the configuration file will be
64c02f1310b7747423957823ee09fb3608430f89nd used.
64c02f1310b7747423957823ee09fb3608430f89nd </p></dd>
64c02f1310b7747423957823ee09fb3608430f89nd<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
64c02f1310b7747423957823ee09fb3608430f89nd<dd><p>
64c02f1310b7747423957823ee09fb3608430f89nd Send commands to TCP port
64c02f1310b7747423957823ee09fb3608430f89nd <em class="replaceable"><code>port</code></em>
64c02f1310b7747423957823ee09fb3608430f89nd instead
64c02f1310b7747423957823ee09fb3608430f89nd of BIND 9's default control channel port, 953.
64c02f1310b7747423957823ee09fb3608430f89nd </p></dd>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic<dt><span class="term">-V</span></dt>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic<dd><p>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic Enable verbose logging.
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic </p></dd>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic<dt><span class="term">-y <em class="replaceable"><code>keyid</code></em></span></dt>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic<dd><p>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic Use the key <em class="replaceable"><code>keyid</code></em>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic from the configuration file.
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic <em class="replaceable"><code>keyid</code></em>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic must be
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic known by named with the same algorithm and secret string
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic in order for control message validation to succeed.
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic If no <em class="replaceable"><code>keyid</code></em>
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic is specified, <span><strong class="command">rndc</strong></span> will first look
f0fa55ff14fa0bf8fd72d989f6625de6dc3260c8igalic for a key clause in the server statement of the server
64c02f1310b7747423957823ee09fb3608430f89nd being used, or if no server statement is present for that
64c02f1310b7747423957823ee09fb3608430f89nd host, then the default-key clause of the options statement.
64c02f1310b7747423957823ee09fb3608430f89nd Note that the configuration file contains shared secrets
3b3b7fc78d1f5bfc2769903375050048ff41ff26nd which are used to send authenticated control commands
a78048ccbdb6256da15e6b0e7e95355e480c2301nd to name servers. It should therefore not have general read
0066eddda7203f6345b56f77d146a759298dc635gryzor or write access.
7f5b59ccc63c0c0e3e678a168f09ee6a2f51f9d0nd </p></dd>
f086b4b402fa9a2fefc7dda85de2a3cc1cd0a654rjung</dl></div>
727872d18412fc021f03969b8641810d8896820bhumbedooh<p>
0d0ba3a410038e179b695446bb149cce6264e0abnd For the complete set of commands supported by <span><strong class="command">rndc</strong></span>,
727872d18412fc021f03969b8641810d8896820bhumbedooh see the BIND 9 Administrator Reference Manual or run
cc7e1025de9ac63bd4db6fe7f71c158b2cf09fe4humbedooh <span><strong class="command">rndc</strong></span> without arguments to see its help
0d0ba3a410038e179b695446bb149cce6264e0abnd message.
cc7e1025de9ac63bd4db6fe7f71c158b2cf09fe4humbedooh </p>
727872d18412fc021f03969b8641810d8896820bhumbedooh</div>
0d0ba3a410038e179b695446bb149cce6264e0abnd<div class="refsect1" lang="en">
0d0ba3a410038e179b695446bb149cce6264e0abnd<a name="id2604997"></a><h2>LIMITATIONS</h2>
0d0ba3a410038e179b695446bb149cce6264e0abnd<p><span><strong class="command">rndc</strong></span>
ac082aefa89416cbdc9a1836eaf3bed9698201c8humbedooh does not yet support all the commands of
0d0ba3a410038e179b695446bb149cce6264e0abnd the BIND 8 <span><strong class="command">ndc</strong></span> utility.
0d0ba3a410038e179b695446bb149cce6264e0abnd </p>
0d0ba3a410038e179b695446bb149cce6264e0abnd<p>
727872d18412fc021f03969b8641810d8896820bhumbedooh There is currently no way to provide the shared secret for a
0d0ba3a410038e179b695446bb149cce6264e0abnd <code class="option">key_id</code> without using the configuration file.
0d0ba3a410038e179b695446bb149cce6264e0abnd </p>
30471a4650391f57975f60bbb6e4a90be7b284bfhumbedooh<p>
5effc8b39fae5cd169d17f342bfc265705840014rbowen Several error messages could be clearer.
d229f940abfb2490dee17979e9a5ff31b7012eb5rbowen </p>
0d0ba3a410038e179b695446bb149cce6264e0abnd</div>
7fec19672a491661b2fe4b29f685bc7f4efa64d4nd<div class="refsect1" lang="en">
7fec19672a491661b2fe4b29f685bc7f4efa64d4nd<a name="id2605028"></a><h2>SEE ALSO</h2>
7fec19672a491661b2fe4b29f685bc7f4efa64d4nd<p><span class="citerefentry"><span class="refentrytitle">rndc.conf</span>(5)</span>,
64c02f1310b7747423957823ee09fb3608430f89nd <span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>,
<span class="citerefentry"><span class="refentrytitle">ndc</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2605075"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
</div>
<div class="navfooter">
<hr>
<table width="100%" summary="Navigation footer">
<tr>
<td width="40%" align="left">
<a accesskey="p" href="man.named.html">Prev</a>�</td>
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
<td width="40%" align="right">�<a accesskey="n" href="man.rndc.conf.html">Next</a>
</td>
</tr>
<tr>
<td width="40%" align="left" valign="top">
<span class="application">named</span>�</td>
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
<td width="40%" align="right" valign="top">�<code class="filename">rndc.conf</code>
</td>
</tr>
</table>
</div>
</body>
</html>