man.rndc.html revision 8bbfb495a2c076642fb0b9327ae63e4f5c33d66a
499b34cea04a46823d003d4c0520c8b03e8513cbBrian Wellington<!--
816e576f77e2c46df3e3d97d65822aa8aded7c4bDavid Lawrence - Copyright (C) 2004-2013 Internet Systems Consortium, Inc. ("ISC")
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson - Copyright (C) 2000-2003 Internet Software Consortium.
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson -
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson - Permission to use, copy, modify, and/or distribute this software for any
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson - purpose with or without fee is hereby granted, provided that the above
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson - copyright notice and this permission notice appear in all copies.
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson -
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
181232550d33f7d7846cdc08e1da01f0972c15d6Andreas Gustafsson - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson - PERFORMANCE OF THIS SOFTWARE.
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson-->
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson<!-- $Id$ -->
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson<html>
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson<head>
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson<title>rndc</title>
95b6b97ae0942ceb8244693c3d68d2b396af9960Andreas Gustafsson<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<link rel="prev" href="man.nsupdate.html" title="nsupdate">
b2ca1f1bd04a779f15e12e0b2bee6fa95e512f89Brian Wellington<link rel="next" href="man.rndc.conf.html" title="rndc.conf">
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson</head>
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson<div class="navheader">
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson<table width="100%" summary="Navigation header">
abea3fdc7fafcadf4275a14f261ad6e2332cace4Andreas Gustafsson<tr><th colspan="3" align="center"><span class="application">rndc</span></th></tr>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<tr>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<td width="20%" align="left">
95b6b97ae0942ceb8244693c3d68d2b396af9960Andreas Gustafsson<a accesskey="p" href="man.nsupdate.html">Prev</a>�</td>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<th width="60%" align="center">Manual pages</th>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<td width="20%" align="right">�<a accesskey="n" href="man.rndc.conf.html">Next</a>
ebb48478db5a40916fb9c01c586838d05c47ab06Brian Wellington</td>
ebb48478db5a40916fb9c01c586838d05c47ab06Brian Wellington</tr>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson</table>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<hr>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson</div>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<div class="refentry" lang="en">
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<a name="man.rndc"></a><div class="titlepage"></div>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<div class="refnamediv">
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson<h2>Name</h2>
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson<p><span class="application">rndc</span> &#8212; name server control utility</p>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson</div>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<div class="refsynopsisdiv">
95b6b97ae0942ceb8244693c3d68d2b396af9960Andreas Gustafsson<h2>Synopsis</h2>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<div class="cmdsynopsis"><p><code class="command">rndc</code> [<code class="option">-b <em class="replaceable"><code>source-address</code></em></code>] [<code class="option">-c <em class="replaceable"><code>config-file</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key-file</code></em></code>] [<code class="option">-s <em class="replaceable"><code>server</code></em></code>] [<code class="option">-p <em class="replaceable"><code>port</code></em></code>] [<code class="option">-V</code>] [<code class="option">-y <em class="replaceable"><code>key_id</code></em></code>] {command}</p></div>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson</div>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<div class="refsect1" lang="en">
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<a name="id2643107"></a><h2>DESCRIPTION</h2>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<p><span><strong class="command">rndc</strong></span>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson controls the operation of a name
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson server. It supersedes the <span><strong class="command">ndc</strong></span> utility
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson that was provided in old BIND releases. If
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson <span><strong class="command">rndc</strong></span> is invoked with no command line
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson options or arguments, it prints a short summary of the
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson supported commands and the available options and their
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson arguments.
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson </p>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson<p><span><strong class="command">rndc</strong></span>
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson communicates with the name server
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson over a TCP connection, sending commands authenticated with
5b4397d387b89d696b5eb90c328a385e07d4a380Brian Wellington digital signatures. In the current versions of
5b4397d387b89d696b5eb90c328a385e07d4a380Brian Wellington <span><strong class="command">rndc</strong></span> and <span><strong class="command">named</strong></span>,
5b4397d387b89d696b5eb90c328a385e07d4a380Brian Wellington the only supported authentication algorithm is HMAC-MD5,
5b4397d387b89d696b5eb90c328a385e07d4a380Brian Wellington which uses a shared secret on each end of the connection.
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson This provides TSIG-style authentication for the command
1cb5d53b09cded8298285fdcdcc6a261f2b47afbBrian Wellington request and the name server's response. All commands sent
1cb5d53b09cded8298285fdcdcc6a261f2b47afbBrian Wellington over the channel must be signed by a key_id known to the
1b855974958ebca91882c4b59f66c48dd5784b87Andreas Gustafsson server.
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson </p>
95b6b97ae0942ceb8244693c3d68d2b396af9960Andreas Gustafsson<p><span><strong class="command">rndc</strong></span>
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson reads a configuration file to
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson determine how to contact the name server and decide what
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson algorithm and key it should use.
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson </p>
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson</div>
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson<div class="refsect1" lang="en">
c81bf797a812236e4a6d13a6473bc029d7ce280aAndreas Gustafsson<a name="id2643157"></a><h2>OPTIONS</h2>
e4946c508eb331c28ce1f2b05c7e2adfe73fe701Andreas Gustafsson<div class="variablelist"><dl>
e4946c508eb331c28ce1f2b05c7e2adfe73fe701Andreas Gustafsson<dt><span class="term">-b <em class="replaceable"><code>source-address</code></em></span></dt>
e4946c508eb331c28ce1f2b05c7e2adfe73fe701Andreas Gustafsson<dd><p>
e4946c508eb331c28ce1f2b05c7e2adfe73fe701Andreas Gustafsson Use <em class="replaceable"><code>source-address</code></em>
e4946c508eb331c28ce1f2b05c7e2adfe73fe701Andreas Gustafsson as the source address for the connection to the server.
e4946c508eb331c28ce1f2b05c7e2adfe73fe701Andreas Gustafsson Multiple instances are permitted to allow setting of both
e4946c508eb331c28ce1f2b05c7e2adfe73fe701Andreas Gustafsson the IPv4 and IPv6 source addresses.
e4946c508eb331c28ce1f2b05c7e2adfe73fe701Andreas Gustafsson </p></dd>
e4946c508eb331c28ce1f2b05c7e2adfe73fe701Andreas Gustafsson<dt><span class="term">-c <em class="replaceable"><code>config-file</code></em></span></dt>
<dd><p>
Use <em class="replaceable"><code>config-file</code></em>
as the configuration file instead of the default,
<code class="filename">/etc/rndc.conf</code>.
</p></dd>
<dt><span class="term">-k <em class="replaceable"><code>key-file</code></em></span></dt>
<dd><p>
Use <em class="replaceable"><code>key-file</code></em>
as the key file instead of the default,
<code class="filename">/etc/rndc.key</code>. The key in
<code class="filename">/etc/rndc.key</code> will be used to
authenticate
commands sent to the server if the <em class="replaceable"><code>config-file</code></em>
does not exist.
</p></dd>
<dt><span class="term">-s <em class="replaceable"><code>server</code></em></span></dt>
<dd><p><em class="replaceable"><code>server</code></em> is
the name or address of the server which matches a
server statement in the configuration file for
<span><strong class="command">rndc</strong></span>. If no server is supplied on the
command line, the host named by the default-server clause
in the options statement of the <span><strong class="command">rndc</strong></span>
configuration file will be used.
</p></dd>
<dt><span class="term">-p <em class="replaceable"><code>port</code></em></span></dt>
<dd><p>
Send commands to TCP port
<em class="replaceable"><code>port</code></em>
instead
of BIND 9's default control channel port, 953.
</p></dd>
<dt><span class="term">-V</span></dt>
<dd><p>
Enable verbose logging.
</p></dd>
<dt><span class="term">-y <em class="replaceable"><code>key_id</code></em></span></dt>
<dd><p>
Use the key <em class="replaceable"><code>key_id</code></em>
from the configuration file.
<em class="replaceable"><code>key_id</code></em>
must be
known by named with the same algorithm and secret string
in order for control message validation to succeed.
If no <em class="replaceable"><code>key_id</code></em>
is specified, <span><strong class="command">rndc</strong></span> will first look
for a key clause in the server statement of the server
being used, or if no server statement is present for that
host, then the default-key clause of the options statement.
Note that the configuration file contains shared secrets
which are used to send authenticated control commands
to name servers. It should therefore not have general read
or write access.
</p></dd>
</dl></div>
<p>
For the complete set of commands supported by <span><strong class="command">rndc</strong></span>,
see the BIND 9 Administrator Reference Manual or run
<span><strong class="command">rndc</strong></span> without arguments to see its help
message.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2644269"></a><h2>LIMITATIONS</h2>
<p><span><strong class="command">rndc</strong></span>
does not yet support all the commands of
the BIND 8 <span><strong class="command">ndc</strong></span> utility.
</p>
<p>
There is currently no way to provide the shared secret for a
<code class="option">key_id</code> without using the configuration file.
</p>
<p>
Several error messages could be clearer.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2644300"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">rndc.conf</span>(5)</span>,
<span class="citerefentry"><span class="refentrytitle">rndc-confgen</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">named</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">named.conf</span>(5)</span>,
<span class="citerefentry"><span class="refentrytitle">ndc</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2644356"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
</div>
<div class="navfooter">
<hr>
<table width="100%" summary="Navigation footer">
<tr>
<td width="40%" align="left">
<a accesskey="p" href="man.nsupdate.html">Prev</a>�</td>
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
<td width="40%" align="right">�<a accesskey="n" href="man.rndc.conf.html">Next</a>
</td>
</tr>
<tr>
<td width="40%" align="left" valign="top">
<span class="application">nsupdate</span>�</td>
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
<td width="40%" align="right" valign="top">�<code class="filename">rndc.conf</code>
</td>
</tr>
</table>
</div>
</body>
</html>