></DT
><DT
>4.9. <A
-HREF="Bv9ARM.ch04.html#AEN1013"
+HREF="Bv9ARM.ch04.html#AEN1015"
>IPv6 Support in <SPAN
CLASS="acronym"
>BIND</SPAN
><SPAN
CLASS="acronym"
>BIND</SPAN
-> 9 partially supports DNSSEC SIG(0) transaction
- signatures as specified in RFC 2535. SIG(0) uses public/private
- keys to authenticate messages. Access control is performed in the
- same manner as TSIG keys; privileges can be granted or denied
- based on the key name.</P
+> 9 partially supports DNSSEC SIG(0)
+ transaction signatures as specified in RFC 2535 and RFC2931. SIG(0)
+ uses public/private keys to authenticate messages. Access control
+ is performed in the same manner as TSIG keys; privileges can be
+ granted or denied based on the key name.</P
><P
>When a SIG(0) signed message is received, it will only be
verified if the key is known and trusted by the server; the server
>SIG(0) signing of multiple-message TCP streams is not
supported.</P
><P
-><SPAN
+>The only tool shipped with <SPAN
CLASS="acronym"
>BIND</SPAN
-> 9 does not ship with any tools that generate SIG(0)
- signed messages.</P
+> 9 that
+ generates SIG(0) signed messages is <B
+CLASS="command"
+>nsupdate</B
+>.</P
></DIV
><DIV
CLASS="sect1"
> 9 ships
with several tools
that are used in this process, which are explained in more detail
- below. In all cases, the "<TT
+ below. In all cases, the <TT
CLASS="option"
>-h</TT
->" option prints a
+> option prints a
full list of parameters. Note that the DNSSEC tools require the
- keyset and signedkey files to be in the working directory, and
+ keyset and signedkey files to be in the working directory or the
+ directory specified by the <TT
+CLASS="option"
+>-h</TT
+> option, and
that the tools shipped with BIND 9.0.x are not fully compatible
with the current ones.</P
><P
><H2
CLASS="sect2"
><A
-NAME="AEN945"
+NAME="AEN947"
>4.8.1. Generating Keys</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN965"
+NAME="AEN967"
>4.8.2. Creating a Keyset</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN977"
+NAME="AEN979"
>4.8.3. Signing the Child's Keyset</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN990"
+NAME="AEN992"
>4.8.4. Signing the Zone</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN1006"
+NAME="AEN1008"
>4.8.5. Configuring Servers</A
></H2
><P
><H1
CLASS="sect1"
><A
-NAME="AEN1013"
+NAME="AEN1015"
>4.9. IPv6 Support in <SPAN
CLASS="acronym"
>BIND</SPAN
><H2
CLASS="sect2"
><A
-NAME="AEN1030"
+NAME="AEN1032"
>4.9.1. Address Lookups Using AAAA Records</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN1035"
+NAME="AEN1037"
>4.9.2. Address Lookups Using A6 Records</A
></H2
><P
><H3
CLASS="sect3"
><A
-NAME="AEN1039"
+NAME="AEN1041"
>4.9.2.1. A6 Chains</A
></H3
><P
><H3
CLASS="sect3"
><A
-NAME="AEN1050"
+NAME="AEN1052"
>4.9.2.2. A6 Records for DNS Servers</A
></H3
><P
><H2
CLASS="sect2"
><A
-NAME="AEN1056"
+NAME="AEN1058"
>4.9.3. Address to Name Lookups Using Nibble Format</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN1063"
+NAME="AEN1065"
>4.9.4. Address to Name Lookups Using Binary Label Format</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN1070"
+NAME="AEN1072"
>4.9.5. Using DNAME for Delegation of IPv6 Reverse Addresses</A
></H2
><P
><DL
><DT
>4.8.1. <A
-HREF="Bv9ARM.ch04.html#AEN945"
+HREF="Bv9ARM.ch04.html#AEN947"
>Generating Keys</A
></DT
><DT
>4.8.2. <A
-HREF="Bv9ARM.ch04.html#AEN965"
+HREF="Bv9ARM.ch04.html#AEN967"
>Creating a Keyset</A
></DT
><DT
>4.8.3. <A
-HREF="Bv9ARM.ch04.html#AEN977"
+HREF="Bv9ARM.ch04.html#AEN979"
>Signing the Child's Keyset</A
></DT
><DT
>4.8.4. <A
-HREF="Bv9ARM.ch04.html#AEN990"
+HREF="Bv9ARM.ch04.html#AEN992"
>Signing the Zone</A
></DT
><DT
>4.8.5. <A
-HREF="Bv9ARM.ch04.html#AEN1006"
+HREF="Bv9ARM.ch04.html#AEN1008"
>Configuring Servers</A
></DT
></DL
></DD
><DT
>4.9. <A
-HREF="Bv9ARM.ch04.html#AEN1013"
+HREF="Bv9ARM.ch04.html#AEN1015"
>IPv6 Support in <SPAN
CLASS="acronym"
>BIND</SPAN
><DL
><DT
>4.9.1. <A
-HREF="Bv9ARM.ch04.html#AEN1030"
+HREF="Bv9ARM.ch04.html#AEN1032"
>Address Lookups Using AAAA Records</A
></DT
><DT
>4.9.2. <A
-HREF="Bv9ARM.ch04.html#AEN1035"
+HREF="Bv9ARM.ch04.html#AEN1037"
>Address Lookups Using A6 Records</A
></DT
><DT
>4.9.3. <A
-HREF="Bv9ARM.ch04.html#AEN1056"
+HREF="Bv9ARM.ch04.html#AEN1058"
>Address to Name Lookups Using Nibble Format</A
></DT
><DT
>4.9.4. <A
-HREF="Bv9ARM.ch04.html#AEN1063"
+HREF="Bv9ARM.ch04.html#AEN1065"
>Address to Name Lookups Using Binary Label Format</A
></DT
><DT
>4.9.5. <A
-HREF="Bv9ARM.ch04.html#AEN1070"
+HREF="Bv9ARM.ch04.html#AEN1072"
>Using DNAME for Delegation of IPv6 Reverse Addresses</A
></DT
></DL
><DL
><DT
>5.1. <A
-HREF="Bv9ARM.ch05.html#AEN1090"
+HREF="Bv9ARM.ch05.html#AEN1092"
>The Lightweight Resolver Library</A
></DT
><DT
></DT
><DT
>6.1.2. <A
-HREF="Bv9ARM.ch06.html#AEN1333"
+HREF="Bv9ARM.ch06.html#AEN1335"
>Comment Syntax</A
></DT
></DL
><DL
><DT
>6.2.1. <A
-HREF="Bv9ARM.ch06.html#AEN1440"
+HREF="Bv9ARM.ch06.html#AEN1442"
><B
CLASS="command"
>acl</B
></DT
><DT
>6.2.3. <A
-HREF="Bv9ARM.ch06.html#AEN1487"
+HREF="Bv9ARM.ch06.html#AEN1489"
><B
CLASS="command"
>controls</B
></DT
><DT
>6.2.5. <A
-HREF="Bv9ARM.ch06.html#AEN1566"
+HREF="Bv9ARM.ch06.html#AEN1568"
><B
CLASS="command"
>include</B
></DT
><DT
>6.2.6. <A
-HREF="Bv9ARM.ch06.html#AEN1571"
+HREF="Bv9ARM.ch06.html#AEN1573"
><B
CLASS="command"
>include</B
></DT
><DT
>6.2.7. <A
-HREF="Bv9ARM.ch06.html#AEN1578"
+HREF="Bv9ARM.ch06.html#AEN1580"
><B
CLASS="command"
>key</B
></DT
><DT
>6.2.8. <A
-HREF="Bv9ARM.ch06.html#AEN1585"
+HREF="Bv9ARM.ch06.html#AEN1587"
><B
CLASS="command"
>key</B
></DT
><DT
>6.2.9. <A
-HREF="Bv9ARM.ch06.html#AEN1605"
+HREF="Bv9ARM.ch06.html#AEN1607"
><B
CLASS="command"
>logging</B
></DT
><DT
>6.2.10. <A
-HREF="Bv9ARM.ch06.html#AEN1645"
+HREF="Bv9ARM.ch06.html#AEN1647"
><B
CLASS="command"
>logging</B
></DT
><DT
>6.2.11. <A
-HREF="Bv9ARM.ch06.html#AEN1876"
+HREF="Bv9ARM.ch06.html#AEN1878"
><B
CLASS="command"
>lwres</B
></DT
><DT
>6.2.12. <A
-HREF="Bv9ARM.ch06.html#AEN1900"
+HREF="Bv9ARM.ch06.html#AEN1902"
><B
CLASS="command"
>lwres</B
></DT
><DT
>6.2.13. <A
-HREF="Bv9ARM.ch06.html#AEN1919"
+HREF="Bv9ARM.ch06.html#AEN1921"
><B
CLASS="command"
>options</B
></DT
><DT
>6.2.17. <A
-HREF="Bv9ARM.ch06.html#AEN3198"
+HREF="Bv9ARM.ch06.html#AEN3200"
><B
CLASS="command"
>trusted-keys</B
></DT
><DT
>6.2.18. <A
-HREF="Bv9ARM.ch06.html#AEN3214"
+HREF="Bv9ARM.ch06.html#AEN3216"
><B
CLASS="command"
>trusted-keys</B
></DT
><DT
>6.2.20. <A
-HREF="Bv9ARM.ch06.html#AEN3236"
+HREF="Bv9ARM.ch06.html#AEN3238"
><B
CLASS="command"
>view</B
></DT
><DT
>6.2.22. <A
-HREF="Bv9ARM.ch06.html#AEN3393"
+HREF="Bv9ARM.ch06.html#AEN3395"
><B
CLASS="command"
>zone</B
></DD
><DT
>6.3. <A
-HREF="Bv9ARM.ch06.html#AEN3753"
+HREF="Bv9ARM.ch06.html#AEN3755"
>Zone File</A
></DT
><DD
></DT
><DT
>6.3.2. <A
-HREF="Bv9ARM.ch06.html#AEN4068"
+HREF="Bv9ARM.ch06.html#AEN4070"
>Discussion of MX Records</A
></DT
><DT
></DT
><DT
>6.3.4. <A
-HREF="Bv9ARM.ch06.html#AEN4189"
+HREF="Bv9ARM.ch06.html#AEN4191"
>Inverse Mapping in IPv4</A
></DT
><DT
>6.3.5. <A
-HREF="Bv9ARM.ch06.html#AEN4216"
+HREF="Bv9ARM.ch06.html#AEN4218"
>Other Zone File Directives</A
></DT
><DT
>6.3.6. <A
-HREF="Bv9ARM.ch06.html#AEN4274"
+HREF="Bv9ARM.ch06.html#AEN4276"
><SPAN
CLASS="acronym"
>BIND</SPAN
></DT
><DT
>7.2. <A
-HREF="Bv9ARM.ch07.html#AEN4366"
+HREF="Bv9ARM.ch07.html#AEN4368"
><B
CLASS="command"
>chroot</B
><DL
><DT
>7.2.1. <A
-HREF="Bv9ARM.ch07.html#AEN4389"
+HREF="Bv9ARM.ch07.html#AEN4391"
>The <B
CLASS="command"
>chroot</B
></DT
><DT
>7.2.2. <A
-HREF="Bv9ARM.ch07.html#AEN4407"
+HREF="Bv9ARM.ch07.html#AEN4409"
>Using the <B
CLASS="command"
>setuid</B
><DL
><DT
>8.1. <A
-HREF="Bv9ARM.ch08.html#AEN4428"
+HREF="Bv9ARM.ch08.html#AEN4430"
>Common Problems</A
></DT
><DD
><DL
><DT
>8.1.1. <A
-HREF="Bv9ARM.ch08.html#AEN4430"
+HREF="Bv9ARM.ch08.html#AEN4432"
>It's not working; how can I figure out what's wrong?</A
></DT
></DL
></DD
><DT
>8.2. <A
-HREF="Bv9ARM.ch08.html#AEN4433"
+HREF="Bv9ARM.ch08.html#AEN4435"
>Incrementing and Changing the Serial Number</A
></DT
><DT
>8.3. <A
-HREF="Bv9ARM.ch08.html#AEN4438"
+HREF="Bv9ARM.ch08.html#AEN4440"
>Where Can I Get Help?</A
></DT
></DL
><DL
><DT
>A.1. <A
-HREF="Bv9ARM.ch09.html#AEN4454"
+HREF="Bv9ARM.ch09.html#AEN4456"
>Acknowledgements</A
></DT
><DD
><DL
><DT
>A.1.1. <A
-HREF="Bv9ARM.ch09.html#AEN4456"
+HREF="Bv9ARM.ch09.html#AEN4458"
>A Brief History of the <SPAN
CLASS="acronym"
>DNS</SPAN
></DT
><DT
>A.3.3. <A
-HREF="Bv9ARM.ch09.html#AEN5090"
+HREF="Bv9ARM.ch09.html#AEN5092"
>Other Documents About <SPAN
CLASS="acronym"
>BIND</SPAN