man.rndc.html revision 44d0f0256fbdce130a18655023c3b06bacacbd61
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
71cef386fae61275b03e203825680b39fedaa8c6Tinderbox User - Copyright (C) 2000-2003 Internet Software Consortium.
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - Permission to use, copy, modify, and/or distribute this software for any
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - purpose with or without fee is hereby granted, provided that the above
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - copyright notice and this permission notice appear in all copies.
d6fa26d0adaec6c910115be34fe7a5a5f402c14fMark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - PERFORMANCE OF THIS SOFTWARE.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<!-- $Id: man.rndc.html,v 1.166 2010/02/04 01:14:16 tbox Exp $ -->
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
71c66a876ecca77923638d3f94cc0783152b2f03Mark Andrews<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<link rel="prev" href="man.nsupdate.html" title="nsupdate">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<link rel="next" href="man.rndc.conf.html" title="rndc.conf">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<tr><th colspan="3" align="center"><span class="application">rndc</span></th></tr>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<a accesskey="p" href="man.nsupdate.html">Prev</a>�</td>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User<th width="60%" align="center">Manual pages</th>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<td width="20%" align="right">�<a accesskey="n" href="man.rndc.conf.html">Next</a>
af40ebed6257e4ac1996144530b3de317cf4da11Tinderbox User<a name="man.rndc"></a><div class="titlepage"></div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p><span class="application">rndc</span> — name server control utility</p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<div class="cmdsynopsis"><p><code class="command">rndc</code> [<code class="option">-b <em class="replaceable"><code>source-address</code></em></code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key-file</code></em></code>] [<code class="option">-s <em class="replaceable"><code>server</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-V</code>] [<code class="option">-y <em class="replaceable"><code>key_id</code></em></code>] {command}</p></div>
9c6a5d1f22f972232d7a9fd5c5fa64f10bacbdffAutomatic Updater<p><span><strong class="command">rndc</strong></span>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User controls the operation of a name
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt server. It supersedes the <span><strong class="command">ndc</strong></span> utility
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt that was provided in old BIND releases. If
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt <span><strong class="command">rndc</strong></span> is invoked with no command line
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt options or arguments, it prints a short summary of the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein supported commands and the available options and their
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p><span><strong class="command">rndc</strong></span>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein communicates with the name server
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein over a TCP connection, sending commands authenticated with
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User digital signatures. In the current versions of
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <span><strong class="command">rndc</strong></span> and <span><strong class="command">named</strong></span>,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the only supported authentication algorithm is HMAC-MD5,
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User which uses a shared secret on each end of the connection.
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User This provides TSIG-style authentication for the command
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein request and the name server's response. All commands sent
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User over the channel must be signed by a key_id known to the
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<p><span><strong class="command">rndc</strong></span>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User reads a configuration file to
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User determine how to contact the name server and decide what
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User algorithm and key it should use.
ac93437301f55ed69bf85883a497a75598c628f9Automatic Updater<dt><span class="term">-b <em class="replaceable"><code>source-address</code></em></span></dt>
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews Use <em class="replaceable"><code>source-address</code></em>
77dccf2a5d9327d16b4374a135cdb99bdd48620eAutomatic Updater as the source address for the connection to the server.
77dccf2a5d9327d16b4374a135cdb99bdd48620eAutomatic Updater Multiple instances are permitted to allow setting of both
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews the IPv4 and IPv6 source addresses.
ac93437301f55ed69bf85883a497a75598c628f9Automatic Updater<dt><span class="term">-c <em class="replaceable"><code>config-file</code></em></span></dt>
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews Use <em class="replaceable"><code>config-file</code></em>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce as the configuration file instead of the default,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="term">-k <em class="replaceable"><code>key-file</code></em></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce Use <em class="replaceable"><code>key-file</code></em>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce as the key file instead of the default,
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="filename">/etc/rndc.key</code>. The key in
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce <code class="filename">/etc/rndc.key</code> will be used to
47012ae6dbf18a2503d7b33c1c9583dc38625cb7Mark Andrews authenticate
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce commands sent to the server if the <em class="replaceable"><code>config-file</code></em>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce does not exist.
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dt><span class="term">-s <em class="replaceable"><code>server</code></em></span></dt>
f293a69bcd1c1dd7bdac8f4102fc2398b9e475c8Eric Luce<dd><p><em class="replaceable"><code>server</code></em> is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the name or address of the server which matches a
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User server statement in the configuration file for
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User <span><strong class="command">rndc</strong></span>. If no server is supplied on the
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User command line, the host named by the default-server clause
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User in the options statement of the <span><strong class="command">rndc</strong></span>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User configuration file will be used.
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User Send commands to TCP port
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User <em class="replaceable"><code>port</code></em>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User of BIND 9's default control channel port, 953.
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User Enable verbose logging.
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<dt><span class="term">-y <em class="replaceable"><code>key_id</code></em></span></dt>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User Use the key <em class="replaceable"><code>key_id</code></em>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User from the configuration file.
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User <em class="replaceable"><code>key_id</code></em>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt known by named with the same algorithm and secret string
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User in order for control message validation to succeed.
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User If no <em class="replaceable"><code>key_id</code></em>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User is specified, <span><strong class="command">rndc</strong></span> will first look
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User for a key clause in the server statement of the server
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User being used, or if no server statement is present for that
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User host, then the default-key clause of the options statement.
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User Note that the configuration file contains shared secrets
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User which are used to send authenticated control commands
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User to name servers. It should therefore not have general read
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User or write access.
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User For the complete set of commands supported by <span><strong class="command">rndc</strong></span>,
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User see the BIND 9 Administrator Reference Manual or run
ffe29868b4bbc64953fc5d0de51f988c20158967Tinderbox User <span><strong class="command">rndc</strong></span> without arguments to see its help
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<p><span><strong class="command">rndc</strong></span>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User does not yet support all the commands of
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt the BIND 8 <span><strong class="command">ndc</strong></span> utility.
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User There is currently no way to provide the shared secret for a
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User <code class="option">key_id</code> without using the configuration file.
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User Several error messages could be clearer.
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<p><span class="citerefentry"><span class="refentrytitle">rndc.conf</span>(5)</span>,
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User <span class="citerefentry"><span class="refentrytitle">rndc-confgen</span>(8)</span>,
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User <span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User <span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>,
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User <span class="citerefentry"><span class="refentrytitle">ndc</span>(8)</span>,
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User <em class="citetitle">BIND 9 Administrator Reference Manual</em>.
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<p><span class="corpauthor">Internet Systems Consortium</span>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<table width="100%" summary="Navigation footer">
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<a accesskey="p" href="man.nsupdate.html">Prev</a>�</td>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<td width="40%" align="right">�<a accesskey="n" href="man.rndc.conf.html">Next</a>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<span class="application">nsupdate</span>�</td>
aa1905addf2f33d90aa020080e4e77a8651e829aTinderbox User<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<td width="40%" align="right" valign="top">�<code class="filename">rndc.conf</code>