From: Mark Andrews Date: Thu, 23 Jul 2015 07:56:03 +0000 (+1000) Subject: whitespace X-Git-Tag: v9.11.0a1~636 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=98869e60fafc73aace8f54a36b881adfeb3baa4f;p=thirdparty%2Fbind9.git whitespace --- diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml index 770dbc88d3c..bb253ce2638 100644 --- a/doc/arm/Bv9ARM-book.xml +++ b/doc/arm/Bv9ARM-book.xml @@ -646,7 +646,7 @@ ISC BIND 9 compiles and runs on a large number - of Unix-like operating systems and on + of Unix-like operating systems and on Microsoft Windows Server 2003 and 2008, and Windows XP and Vista. For an up-to-date list of supported systems, see the README file in the top level @@ -1396,7 +1396,7 @@ controls { allow-update or an update-policy clause in the zone statement. - + If the zone's update-policy is set to local, updates to the zone @@ -2240,10 +2240,10 @@ allow-update { key host1-host2. ;}; To enable named to validate answers from other servers, the dnssec-enable option must be set to yes, and the - dnssec-validation options must be set to + dnssec-validation options must be set to yes or auto. - + If dnssec-validation is set to auto, then a default @@ -2256,7 +2256,7 @@ allow-update { key host1-host2. ;}; will not occur. The default setting is yes. - + trusted-keys are copies of DNSKEY RRs for zones that are used to form the first link in the @@ -2365,7 +2365,7 @@ options { including missing, expired, or invalid signatures, a key which does not match the DS RRset in the parent zone, or an insecure response from a zone which, according to its parent, should have - been secure. + been secure. @@ -2427,7 +2427,7 @@ options { the traditional "nibble" format used in the ip6.arpa domain, as well as the older, deprecated ip6.int domain. - Older versions of BIND 9 + Older versions of BIND 9 supported the "binary label" (also known as "bitstring") format, but support of binary labels has been completely removed per RFC 3363. @@ -2565,7 +2565,7 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa. The number of client queries that the lwresd daemon is able to serve can be set using the - and + and statements in the configuration. @@ -2906,7 +2906,7 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa. "as big as possible", depending on the context. See the explanations of particular parameters that use size_spec - for details on how they interpret its use. + for details on how they interpret its use. Numeric values can optionally be followed by a @@ -2925,7 +2925,7 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa. way to safely set a very large number. - default + default uses the limit that was in force when the server was started. @@ -3264,7 +3264,7 @@ $ORIGIN 0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa. defines a named masters list for inclusion in stub and slave zones' - masters or + masters or also-notify lists. @@ -4716,7 +4716,7 @@ badresp:1,adberr:0,findfail:0,valfail:0] of worker threads the lightweight resolver will dedicate to serving clients. By default the number is the same as the number of CPUs on the system; this can be overridden using the - command line option when starting the server. + command line option when starting the server. The specifies @@ -4741,7 +4741,7 @@ badresp:1,adberr:0,findfail:0,valfail:0] <command>masters</command> Statement Grammar -masters name port ip_port dscp ip_dscp { ( masters_list | +masters name port ip_port dscp ip_dscp { ( masters_list | ip_addr port ip_port key key ) ; ... }; @@ -4825,7 +4825,7 @@ badresp:1,adberr:0,findfail:0,valfail:0] forwarders { ip_addr port ip_port dscp ip_dscp ; ... }; dual-stack-servers port ip_port dscp ip_dscp { ( domain_name port ip_port dscp ip_dscp | - ip_addr port ip_port dscp ip_dscp) ; + ip_addr port ip_port dscp ip_dscp) ; ... }; check-names ( master | slave | response ) ( warn | fail | ignore ); @@ -4876,7 +4876,7 @@ badresp:1,adberr:0,findfail:0,valfail:0] query-source-v6 ( ( ip6_addr | * ) port ( ip_port | * ) dscp ip_dscp | - address ( ip6_addr | * ) + address ( ip6_addr | * ) port ( ip_port | * ) ) dscp ip_dscp ; use-queryport-pool yes_or_no; @@ -5420,7 +5420,7 @@ badresp:1,adberr:0,findfail:0,valfail:0] The pathname of a file to override the built-in trusted keys provided by named. See the discussion of dnssec-lookaside - and dnssec-validation for details. + and dnssec-validation for details. If not specified, the default is /etc/bind.keys. @@ -5735,7 +5735,7 @@ options { Each dns64 supports an optional mapped ACL that selects which - IPv4 addresses are to be mapped in the corresponding + IPv4 addresses are to be mapped in the corresponding A RRset. If not defined it defaults to any;. @@ -5826,7 +5826,7 @@ options { Species the default lifetime, in seconds, that will be used for negative trust anchors added - via rndc nta. + via rndc nta. A negative trust anchor selectively disables @@ -5862,7 +5862,7 @@ options { domain has stopped validating due to operator error; it temporarily disables DNSSEC validation for that domain. In the interest of ensuring that DNSSEC - validation is turned back on as soon as possible, + validation is turned back on as soon as possible, named will periodically send a query to the domain, ignoring negative trust anchors, to find out whether it can now be validated. If so, @@ -5942,7 +5942,7 @@ options { option can also accept yes or no; yes has the same meaning as full. - As of BIND 9.10, + As of BIND 9.10, no has the same meaning as none; previously, it was the same as terse. @@ -6297,7 +6297,7 @@ options { with "geoip" ACL elements, this option indicates whether the EDNS Client Subnet option, if present in a request, should be used for matching against the GeoIP database. - The default is + The default is geoip-use-ecs yes. @@ -6452,7 +6452,7 @@ options { If yes, then an empty EDNS(0) - NSID (Name Server Identifier) option is sent with all + NSID (Name Server Identifier) option is sent with all queries to authoritative name servers during iterative resolution. If the authoritative server returns an NSID option in its response, then its contents are logged in @@ -6752,7 +6752,7 @@ options { If yes, the DNS client is at an IPv4 address, in filter-aaaa, - and if the response does not include DNSSEC signatures, + and if the response does not include DNSSEC signatures, then all AAAA records are deleted from the response. This filtering applies to all responses and not only authoritative responses. @@ -6764,8 +6764,8 @@ options { because the DNSSEC protocol is designed detect deletions. - This mechanism can erroneously cause other servers to - not give AAAA records to their clients. + This mechanism can erroneously cause other servers to + not give AAAA records to their clients. A recursing server with both IPv6 and IPv4 network connections that queries an authoritative server using this mechanism via IPv4 will be denied AAAA records even if its client is @@ -7776,7 +7776,7 @@ avoid-v6-udp-ports {}; Note: BIND 9.5.0 introduced - the use-queryport-pool + the use-queryport-pool option to support a pool of such random ports, but this option is now obsolete because reusing the same ports in the pool may not be sufficiently secure. @@ -7814,7 +7814,7 @@ avoid-v6-udp-ports {}; - + @@ -8405,7 +8405,7 @@ avoid-v6-udp-ports { 40000; range 50000 60000; }; A "soft quota" is also set. When this lower quota is exceeded, incoming requests are accepted, but - for each one, a pending request will be dropped. + for each one, a pending request will be dropped. If is greater than 1000, the soft quota is set to minus 100; @@ -8628,7 +8628,7 @@ avoid-v6-udp-ports { 40000; range 50000 60000; }; or the value 0, will place no limit on cache size; records will be purged from the cache only when their TTLs expire. - Any positive values less than 2MB will be ignored + Any positive values less than 2MB will be ignored and reset to 2MB. In a server with multiple views, the limit applies separately to the cache of each view. @@ -8648,7 +8648,7 @@ avoid-v6-udp-ports { 40000; range 50000 60000; }; waiting for some data before being passed to accept. Nonzero values less than 10 will be silently raised. A value of 0 may also - be used; on most platforms this sets the listen queue + be used; on most platforms this sets the listen queue length to a system-defined default value. @@ -9714,7 +9714,7 @@ avoid-v6-udp-ports { 40000; range 50000 60000; }; - + empty-contact @@ -9725,7 +9725,7 @@ avoid-v6-udp-ports { 40000; range 50000 60000; }; - + empty-zones-enable @@ -9735,7 +9735,7 @@ avoid-v6-udp-ports { 40000; range 50000 60000; }; - + disable-empty-zone @@ -10058,7 +10058,7 @@ deny-answer-aliases { "example.net"; }; to the standard IPv6 text representation, prefixlength.W8.W7.W6.W5.W4.W3.W2.W1.rpz-client-ip. Each of W8,...,W1 is a one to four digit hexadecimal number - representing 16 bits of the IPv6 address as in the standard + representing 16 bits of the IPv6 address as in the standard text representation of IPv6 addresses, but reversed as in IP6.ARPA. (Note that this representation of IPv6 address is different from IP6.ARPA where each hex @@ -10876,7 +10876,7 @@ example.com CNAME rpz-tcp-only. when a secondary server transfers a zone from another secondary server; when transferring from the primary, the expiration timer is set from the EXPIRE field of the SOA - record instead. + record instead. The default is yes. @@ -11031,7 +11031,7 @@ example.com CNAME rpz-tcp-only. whether the local server will add a NSID EDNS option to requests sent to the server. This overrides request-nsid set at the view or - option level. + option level. @@ -11123,18 +11123,18 @@ example.com CNAME rpz-tcp-only. >http://127.0.0.1:8888/ or http://127.0.0.1:8888/xml. A CSS file is - included which can format the XML statistics into tables - when viewed with a stylesheet-capable browser, and into + included which can format the XML statistics into tables + when viewed with a stylesheet-capable browser, and into charts and graphs using the Google Charts API when using a javascript-capable browser. Applications that depend on a particular XML schema - can request + can request http://127.0.0.1:8888/xml/v2 for version 2 - of the statistics XML schema or + of the statistics XML schema or http://127.0.0.1:8888/xml/v3 for version 3. If the requested schema is supported by the server, then @@ -11265,7 +11265,7 @@ example.com CNAME rpz-tcp-only. <command>managed-keys</command> Statement Definition and Usage - The managed-keys statement, like + The managed-keys statement, like trusted-keys, defines DNSSEC security roots. The difference is that managed-keys can be kept up to date @@ -11311,7 +11311,7 @@ example.com CNAME rpz-tcp-only. initial-key. The difference is, whereas the keys listed in a trusted-keys continue to be trusted until they are removed from - named.conf, an initializing key listed + named.conf, an initializing key listed in a managed-keys statement is only trusted once: for as long as it takes to load the managed key database and start the RFC 5011 key maintenance @@ -11692,7 +11692,7 @@ zone zone_name class allow-query { address_match_list }; server-addresses { ip_addr ; ... }; - server-names { namelist }; + server-names { namelist }; zone-statistics yes_or_no ; }; @@ -11897,7 +11897,7 @@ zone zone_name class Each static-stub zone is configured with internally generated NS and (if necessary) - glue A or AAAA RRs + glue A or AAAA RRs @@ -11981,7 +11981,7 @@ zone zone_name class"*. IN A 100.100.100.2" and "*. IN AAAA 2001:ffff:ffff::100.100.100.2". @@ -11989,7 +11989,7 @@ zone zone_name class To redirect all Spanish names (under .ES) one would use similar entries but with the names - "*.ES." instead of "*.". To redirect all + "*.ES." instead of "*.". To redirect all commercial Spanish names (under COM.ES) one would use wildcard entries called "*.COM.ES.". @@ -12758,7 +12758,7 @@ example.com. NS ns2.example.net. zonename causes named to load keys from the key repository and sign the zone with all keys that are - active. + active. rndc loadkeys zonename causes named to load keys from the key @@ -12792,7 +12792,7 @@ example.com. NS ns2.example.net. the zone is updated. - When set to + When set to serial-update-method unixtime;, the SOA serial number will be set to the number of seconds since the UNIX epoch, unless the serial number is @@ -12800,7 +12800,7 @@ example.com. NS ns2.example.net. case it is simply incremented by one. - When set to + When set to serial-update-method date;, the new SOA serial number will be the current date in the form "YYYYMMDD", followed by two zeroes, @@ -12834,7 +12834,7 @@ example.com. NS ns2.example.net. - + masterfile-format @@ -13120,7 +13120,7 @@ example.com. NS ns2.example.net. This rule takes a Windows machine principal (machine$@REALM) for machine in REALM and - and converts it machine.realm allowing the machine + and converts it machine.realm allowing the machine to update machine.realm. The REALM to be matched is specified in the identity field. @@ -13134,7 +13134,7 @@ example.com. NS ns2.example.net. - This rule takes a Windows machine principal + This rule takes a Windows machine principal (machine$@REALM) for machine in REALM and converts it to machine.realm allowing the machine to update subdomains of machine.realm. The REALM @@ -13152,7 +13152,7 @@ example.com. NS ns2.example.net. This rule takes a Kerberos machine principal (host/machine@REALM) for machine in REALM and - and converts it machine.realm allowing the machine + and converts it machine.realm allowing the machine to update machine.realm. The REALM to be matched is specified in the identity field. @@ -13166,7 +13166,7 @@ example.com. NS ns2.example.net. - This rule takes a Kerberos machine principal + This rule takes a Kerberos machine principal (host/machine@REALM) for machine in REALM and converts it to machine.realm allowing the machine to update subdomains of machine.realm. The REALM @@ -14623,7 +14623,7 @@ view external { When used in the label (or name) field, the asperand or at-sign (@) symbol represents the current origin. - At the start of the zone file, it is the + At the start of the zone file, it is the <zone_name> (followed by trailing dot). @@ -14918,7 +14918,7 @@ HOST-127.EXAMPLE. MX 0 . In addition to the standard textual format, BIND 9 supports the ability to read or dump to zone files in - other formats. + other formats. The raw format is @@ -14938,7 +14938,7 @@ HOST-127.EXAMPLE. MX 0 . For a primary server, a zone file in raw or map format is expected to be generated from a textual zone - file by the named-compilezone command. + file by the named-compilezone command. For a secondary server or for a dynamic zone, it is automatically generated (if this format is specified by the masterfile-format option) when @@ -14960,7 +14960,7 @@ HOST-127.EXAMPLE. MX 0 . with different pointer size, endianness or data alignment than the system on which it was generated, and should in general be used only inside a single system. - While raw format uses + While raw format uses network byte order and avoids architecture-dependent data alignment so that it is as portable as possible, it is also primarily expected to be used