<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.named.conf">
<info>
- <date>2019-05-10</date>
+ <date>2019-06-28</date>
</info>
<refentryinfo>
<corpname>ISC</corpname>
<refsection><info><title>MANAGED-KEYS</title></info>
<para>Deprecated - see DNSSEC-KEYS.</para>
<literallayout class="normal">
-managed-keys { <replaceable>string</replaceable> ( static-key |
- initial-key ) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
- <replaceable>quoted_string</replaceable>; ... };
+managed-keys { <replaceable>string</replaceable> ( static-key
+ | initial-key ) <replaceable>integer</replaceable>
+ <replaceable>integer</replaceable> <replaceable>integer</replaceable>
+ <replaceable>quoted_string</replaceable>; ... }; deprecated
</literallayout>
</refsection>
check-spf ( warn | ignore );
check-srv-cname ( fail | warn | ignore );
check-wildcard <replaceable>boolean</replaceable>;
- cleaning-interval <replaceable>integer</replaceable>;
clients-per-query <replaceable>integer</replaceable>;
cookie-algorithm ( aes | sha1 | sha256 );
cookie-secret <replaceable>string</replaceable>;
dnssec-accept-expired <replaceable>boolean</replaceable>;
dnssec-dnskey-kskonly <replaceable>boolean</replaceable>;
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
- dnssec-lookaside ( <replaceable>string</replaceable> trust-anchor
- <replaceable>string</replaceable> | auto | no );, deprecated
+ dnssec-lookaside ( <replaceable>string</replaceable>
+ trust-anchor <replaceable>string</replaceable> |
+ auto | no ); deprecated
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
dnssec-update-mode ( maintain | no-resign );
<literallayout class="normal">
trusted-keys { <replaceable>string</replaceable> <replaceable>integer</replaceable>
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
- <replaceable>quoted_string</replaceable>; ... };, deprecated
+ <replaceable>quoted_string</replaceable>; ... }; deprecated
</literallayout>
</refsection>
check-spf ( warn | ignore );
check-srv-cname ( fail | warn | ignore );
check-wildcard <replaceable>boolean</replaceable>;
- cleaning-interval <replaceable>integer</replaceable>;
clients-per-query <replaceable>integer</replaceable>;
deny-answer-addresses { <replaceable>address_match_element</replaceable>; ... } [
except-from { <replaceable>string</replaceable>; ... } ];
initial-key ) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>integer</replaceable> <replaceable>quoted_string</replaceable>; ... };
dnssec-loadkeys-interval <replaceable>integer</replaceable>;
- dnssec-lookaside ( <replaceable>string</replaceable> trust-anchor
- <replaceable>string</replaceable> | auto | no );, deprecated
+ dnssec-lookaside ( <replaceable>string</replaceable>
+ trust-anchor <replaceable>string</replaceable> |
+ auto | no ); deprecated
dnssec-must-be-secure <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
dnssec-secure-to-insecure <replaceable>boolean</replaceable>;
dnssec-update-mode ( maintain | no-resign );
key-directory <replaceable>quoted_string</replaceable>;
lame-ttl <replaceable>ttlval</replaceable>;
lmdb-mapsize <replaceable>sizeval</replaceable>;
- managed-keys { <replaceable>string</replaceable> ( static-key |
- initial-key ) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
- <replaceable>integer</replaceable> <replaceable>quoted_string</replaceable>; ... };, deprecated
+ managed-keys { <replaceable>string</replaceable> (
+ static-key | initial-key
+ ) <replaceable>integer</replaceable> <replaceable>integer</replaceable>
+ <replaceable>integer</replaceable>
+ <replaceable>quoted_string</replaceable>; ... }; deprecated
masterfile-format ( map | raw | text );
masterfile-style ( full | relative );
match-clients { <replaceable>address_match_element</replaceable>; ... };
trusted-keys { <replaceable>string</replaceable>
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
<replaceable>integer</replaceable>
- <replaceable>quoted_string</replaceable>; ... };, deprecated
+ <replaceable>quoted_string</replaceable>; ... }; deprecated
try-tcp-refresh <replaceable>boolean</replaceable>;
update-check-ksk <replaceable>boolean</replaceable>;
use-alt-transfer-source <replaceable>boolean</replaceable>;
<!-- Generated by doc/misc/docbook-options.pl -->
<programlisting>
-<command>managed-keys</command> { <replaceable>string</replaceable> ( static-key |
- <command>initial-key</command> ) <replaceable>integer</replaceable> <replaceable>integer</replaceable> <replaceable>integer</replaceable>
- <replaceable>quoted_string</replaceable>; ... };
+<command>managed-keys</command> { <replaceable>string</replaceable> ( static-key
+ | initial-key ) <replaceable>integer</replaceable>
+ <replaceable>integer</replaceable> <replaceable>integer</replaceable>
+ <replaceable>quoted_string</replaceable>; ... }; deprecated
</programlisting>
<command>check-spf</command> ( warn | ignore );
<command>check-srv-cname</command> ( fail | warn | ignore );
<command>check-wildcard</command> <replaceable>boolean</replaceable>;
- <command>cleaning-interval</command> <replaceable>integer</replaceable>;
<command>clients-per-query</command> <replaceable>integer</replaceable>;
<command>cookie-algorithm</command> ( aes | sha1 | sha256 );
<command>cookie-secret</command> <replaceable>string</replaceable>;
<command>dnssec-accept-expired</command> <replaceable>boolean</replaceable>;
<command>dnssec-dnskey-kskonly</command> <replaceable>boolean</replaceable>;
<command>dnssec-loadkeys-interval</command> <replaceable>integer</replaceable>;
- <command>dnssec-lookaside</command> ( <replaceable>string</replaceable> trust-anchor
- <replaceable>string</replaceable> | auto | no );, deprecated
+ <command>dnssec-lookaside</command> ( <replaceable>string</replaceable>
+ <command>trust-anchor</command> <replaceable>string</replaceable> |
+ <command>auto</command> | no ); deprecated
<command>dnssec-must-be-secure</command> <replaceable>string</replaceable> <replaceable>boolean</replaceable>;
<command>dnssec-secure-to-insecure</command> <replaceable>boolean</replaceable>;
<command>dnssec-update-mode</command> ( maintain | no-resign );
<programlisting>
<command>trusted-keys</command> { <replaceable>string</replaceable> <replaceable>integer</replaceable>
<replaceable>integer</replaceable> <replaceable>integer</replaceable>
- <replaceable>quoted_string</replaceable>; ... };, deprecated
+ <replaceable>quoted_string</replaceable>; ... }; deprecated
</programlisting>
s{ // not configured}{};
s{ // non-operational}{};
- s{ // may occur multiple times}{};
+ s{ // may occur multiple times,*}{};
s{<([a-z0-9_-]+)>}{<replaceable>$1</replaceable>}g;
s{^(\s*)([a-z0-9_-]+)\b}{$1<command>$2</command>};
s{[[]}{[}g;
s{ // not configured}{};
s{ // non-operational}{};
- s{ (// )*may occur multiple times}{};
+ s{ (// )*may occur multiple times,*}{};
s{<([a-z0-9_-]+)>}{<replaceable>$1</replaceable>}g;
s{ // deprecated,*}{// deprecated};
s{[[]}{[}g;
}
s{ // not configured}{};
- s{ // may occur multiple times}{};
+ s{ // may occur multiple times,*}{};
s{<([a-z0-9_-]+)>}{<replaceable>$1</replaceable>}g;
s{^(\s*)([a-z0-9_-]+)\b}{$1<command>$2</command>};
s{[[]}{[}g;
dnssec-dnskey-kskonly <boolean>;
dnssec-enable <boolean>; // obsolete
dnssec-loadkeys-interval <integer>;
- dnssec-lookaside ( <string> trust-anchor
- <string> | auto | no ); // may occur multiple times, deprecated
+ dnssec-lookaside ( <string>
+ trust-anchor <string> |
+ auto | no ); // may occur multiple times, deprecated
dnssec-must-be-secure <string> <boolean>; // may occur multiple times
dnssec-secure-to-insecure <boolean>;
dnssec-update-mode ( maintain | no-resign );
fstrm-set-output-queue-model ( mpsc | spsc ); // not configured
fstrm-set-output-queue-size <integer>; // not configured
fstrm-set-reopen-interval <ttlval>; // not configured
- geoip-directory ( <quoted_string> | none ); // not configured
+ geoip-directory ( <quoted_string> | none );
geoip-use-ecs <boolean>; // obsolete
glue-cache <boolean>;
has-old-clients <boolean>; // ancient
listen-on-v6 [ port <integer> ] [ dscp
<integer> ] {
<address_match_element>; ... }; // may occur multiple times
- lmdb-mapsize <sizeval>; // non-operational
+ lmdb-mapsize <sizeval>;
lock-file ( <quoted_string> | none );
maintain-ixfr-base <boolean>; // ancient
managed-keys-directory <quoted_string>;
initial-key ) <integer> <integer>
<integer> <quoted_string>; ... }; // may occur multiple times
dnssec-loadkeys-interval <integer>;
- dnssec-lookaside ( <string> trust-anchor
- <string> | auto | no ); // may occur multiple times, deprecated
+ dnssec-lookaside ( <string>
+ trust-anchor <string> |
+ auto | no ); // may occur multiple times, deprecated
dnssec-must-be-secure <string> <boolean>; // may occur multiple times
dnssec-secure-to-insecure <boolean>;
dnssec-update-mode ( maintain | no-resign );
}; // may occur multiple times
key-directory <quoted_string>;
lame-ttl <ttlval>;
- lmdb-mapsize <sizeval>; // non-operational
+ lmdb-mapsize <sizeval>;
maintain-ixfr-base <boolean>; // ancient
managed-keys { <string> (
static-key | initial-key