named-checkconf \- named configuration file syntax checking tool
.SH SYNOPSIS
.sp
-\fBnamed-checkconf\fR [ \fB-v\fR ] [ \fB-t \fIdirectory\fB\fR ] \fBfilename\fR [ \fB-z\fR ]
+\fBnamed-checkconf\fR [ \fB-v\fR ] [ \fB-j\fR ] [ \fB-t \fIdirectory\fB\fR ] \fBfilename\fR [ \fB-z\fR ]
.SH "DESCRIPTION"
.PP
\fBnamed-checkconf\fR checks the syntax, but not
Perform a check load the master zonefiles found in
\fInamed.conf\fR.
.TP
+\fB-j\fR
+When loading a zonefile read the journal if it exists.
+.TP
\fBfilename\fR
The name of the configuration file to be checked. If not
specified, it defaults to \fI/etc/named.conf\fR.
>named-checkconf</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"></HEAD
><BODY
CLASS="REFENTRY"
>-v</TT
>] [<TT
CLASS="OPTION"
+>-j</TT
+>] [<TT
+CLASS="OPTION"
>-t <TT
CLASS="REPLACEABLE"
><I
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN24"
+NAME="AEN26"
></A
><H2
>DESCRIPTION</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN28"
+NAME="AEN30"
></A
><H2
>OPTIONS</H2
</P
></DD
><DT
+>-j</DT
+><DD
+><P
+> When loading a zonefile read the journal if it exists.
+ </P
+></DD
+><DT
>filename</DT
><DD
><P
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN52"
+NAME="AEN58"
></A
><H2
>RETURN VALUES</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN56"
+NAME="AEN62"
></A
><H2
>SEE ALSO</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN63"
+NAME="AEN69"
></A
><H2
>AUTHOR</H2
named-checkzone \- zone file validity checking tool
.SH SYNOPSIS
.sp
-\fBnamed-checkzone\fR [ \fB-d\fR ] [ \fB-q\fR ] [ \fB-v\fR ] [ \fB-c \fIclass\fB\fR ] [ \fB-t \fIdirectory\fB\fR ] [ \fB-w \fIdirectory\fB\fR ] \fBzonename\fR \fBfilename\fR
+\fBnamed-checkzone\fR [ \fB-d\fR ] [ \fB-j\fR ] [ \fB-q\fR ] [ \fB-v\fR ] [ \fB-c \fIclass\fB\fR ] [ \fB-n \fImode\fB\fR ] [ \fB-t \fIdirectory\fB\fR ] [ \fB-w \fIdirectory\fB\fR ] \fBzonename\fR \fBfilename\fR
.SH "DESCRIPTION"
.PP
\fBnamed-checkzone\fR checks the syntax and integrity of
Print the version of the \fBnamed-checkzone\fR
program and exit.
.TP
+\fB-j\fR
+When loading the zone file read the journal if it exists.
+.TP
\fB-c \fIclass\fB\fR
Specify the class of the zone. If not specified "IN" is assumed.
.TP
+\fB-n \fImode\fB\fR
+Specify whether NS records should be checked to see if they
+are addresses. Possible modes are \fB"fail"\fR,
+\fB"warn"\fR (default) and
+\fB"ignore"\fR.
+.TP
\fB-t \fIdirectory\fB\fR
chroot to \fIdirectory\fR so that include
directives in the configuration file are processed as if
>named-checkzone</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"></HEAD
><BODY
CLASS="REFENTRY"
>-d</TT
>] [<TT
CLASS="OPTION"
+>-j</TT
+>] [<TT
+CLASS="OPTION"
>-q</TT
>] [<TT
CLASS="OPTION"
></TT
>] [<TT
CLASS="OPTION"
+>-n <TT
+CLASS="REPLACEABLE"
+><I
+>mode</I
+></TT
+></TT
+>] [<TT
+CLASS="OPTION"
>-t <TT
CLASS="REPLACEABLE"
><I
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN33"
+NAME="AEN38"
></A
><H2
>DESCRIPTION</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN39"
+NAME="AEN44"
></A
><H2
>OPTIONS</H2
</P
></DD
><DT
+>-j</DT
+><DD
+><P
+> When loading the zone file read the journal if it exists.
+ </P
+></DD
+><DT
>-c <TT
CLASS="REPLACEABLE"
><I
</P
></DD
><DT
+>-n <TT
+CLASS="REPLACEABLE"
+><I
+>mode</I
+></TT
+></DT
+><DD
+><P
+> Specify whether NS records should be checked to see if they
+ are addresses. Possible modes are <B
+CLASS="COMMAND"
+>"fail"</B
+>,
+ <B
+CLASS="COMMAND"
+>"warn"</B
+> (default) and
+ <B
+CLASS="COMMAND"
+>"ignore"</B
+>.
+ </P
+></DD
+><DT
>-t <TT
CLASS="REPLACEABLE"
><I
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN81"
+NAME="AEN98"
></A
><H2
>RETURN VALUES</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN85"
+NAME="AEN102"
></A
><H2
>SEE ALSO</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN93"
+NAME="AEN110"
></A
><H2
>AUTHOR</H2
.PP
The \fB-b\fR option sets the source IP address of the query
to \fIaddress\fR. This must be a valid address on
-one of the host's network interfaces.
+one of the host's network interfaces or "0.0.0.0" or "::". An optional port
+may be specified by appending "#<port>"
.PP
The default query class (IN for internet) is overridden by the
\fB-c\fR option. \fIclass\fR is any valid
automatically performs a lookup for a name like
11.12.13.10.in-addr.arpa and sets the query type and
class to PTR and IN respectively. By default, IPv6 addresses are
-looked up using the IP6.ARPA domain and binary labels as defined in
-RFC2874. To use the older RFC1886 method using the IP6.INT domain and
-"nibble" labels, specify the \fB-n\fR (nibble) option.
+looked up using nibble format under the IP6.ARPA domain.
+To use the older RFC1886 method using the IP6.INT domain
+specify the \fB-i\fR option. Bit string labels (RFC2874)
+are now experimental and are not attempted.
.PP
To sign the DNS queries sent by \fBdig\fR and their
responses using transaction signatures (TSIG), specify a TSIG key file
Deprecated, treated as a synonym for \fI+[no]search\fR
.TP
\fB+[no]aaonly\fR
-This option does nothing. It is provided for compatibilty with old
+This option does nothing. It is provided for compatibility with old
versions of \fBdig\fR where it set an unimplemented
resolver flag.
.TP
Set [do not set] the CD (checking disabled) bit in the query. This
requests the server to not perform DNSSEC validation of responses.
.TP
-\fB+[no]recursive\fR
+\fB+[no]cl\fR
+Display [do not display] the CLASS when printing the record.
+.TP
+\fB+[no]ttlid\fR
+Display [do not display] the TTL when printing the record.
+.TP
+\fB+[no]recurse\fR
Toggle the setting of the RD (recursion desired) bit in the query.
This bit is set by default, which means \fBdig\fR
normally sends recursive queries. Recursion is automatically disabled
.TP
\fB+[no]dnssec\fR
Requests DNSSEC records be sent by setting the DNSSEC OK bit (DO)
-in the the OPT record in the additional section of the query.
+in the OPT record in the additional section of the query.
.SH "MULTIPLE QUERIES"
.PP
The BIND 9 implementation of \fBdig \fR supports
>dig</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"></HEAD
><BODY
CLASS="REFENTRY"
>address</I
></TT
>. This must be a valid address on
-one of the host's network interfaces.</P
+one of the host's network interfaces or "0.0.0.0" or "::". An optional port
+may be specified by appending "#<port>"</P
><P
>The default query class (IN for internet) is overridden by the
<TT
>11.12.13.10.in-addr.arpa</TT
> and sets the query type and
class to PTR and IN respectively. By default, IPv6 addresses are
-looked up using the IP6.ARPA domain and binary labels as defined in
-RFC2874. To use the older RFC1886 method using the IP6.INT domain and
-"nibble" labels, specify the <TT
+looked up using nibble format under the IP6.ARPA domain.
+To use the older RFC1886 method using the IP6.INT domain
+specify the <TT
CLASS="OPTION"
->-n</TT
-> (nibble) option.</P
+>-i</TT
+> option. Bit string labels (RFC2874)
+are now experimental and are not attempted.</P
><P
>To sign the DNS queries sent by <B
CLASS="COMMAND"
></DT
><DD
><P
->This option does nothing. It is provided for compatibilty with old
+>This option does nothing. It is provided for compatibility with old
versions of <B
CLASS="COMMAND"
>dig</B
><DT
><TT
CLASS="OPTION"
->+[no]recursive</TT
+>+[no]cl</TT
+></DT
+><DD
+><P
+>Display [do not display] the CLASS when printing the record.</P
+></DD
+><DT
+><TT
+CLASS="OPTION"
+>+[no]ttlid</TT
+></DT
+><DD
+><P
+>Display [do not display] the TTL when printing the record.</P
+></DD
+><DT
+><TT
+CLASS="OPTION"
+>+[no]recurse</TT
></DT
><DD
><P
><DD
><P
>Requests DNSSEC records be sent by setting the DNSSEC OK bit (DO)
-in the the OPT record in the additional section of the query.</P
+in the OPT record in the additional section of the query.</P
></DD
></DL
></DIV
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN345"
+NAME="AEN355"
></A
><H2
>MULTIPLE QUERIES</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN363"
+NAME="AEN373"
></A
><H2
>FILES</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN369"
+NAME="AEN379"
></A
><H2
>SEE ALSO</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN382"
+NAME="AEN392"
></A
><H2
>BUGS </H2
dnssec-keygen \- DNSSEC key generation tool
.SH SYNOPSIS
.sp
-\fBdnssec-keygen\fR \fB-a \fIalgorithm\fB\fR \fB-b \fIkeysize\fB\fR \fB-n \fInametype\fB\fR [ \fB-c \fIclass\fB\fR ] [ \fB-e\fR ] [ \fB-g \fIgenerator\fB\fR ] [ \fB-h\fR ] [ \fB-p \fIprotocol\fB\fR ] [ \fB-r \fIrandomdev\fB\fR ] [ \fB-s \fIstrength\fB\fR ] [ \fB-t \fItype\fB\fR ] [ \fB-v \fIlevel\fB\fR ] \fBname\fR
+\fBdnssec-keygen\fR \fB-a \fIalgorithm\fB\fR \fB-b \fIkeysize\fB\fR \fB-n \fInametype\fB\fR [ \fB-c \fIclass\fB\fR ] [ \fB-e\fR ] [ \fB-f \fIflag\fB\fR ] [ \fB-g \fIgenerator\fB\fR ] [ \fB-h\fR ] [ \fB-p \fIprotocol\fB\fR ] [ \fB-r \fIrandomdev\fB\fR ] [ \fB-s \fIstrength\fB\fR ] [ \fB-t \fItype\fB\fR ] [ \fB-v \fIlevel\fB\fR ] \fBname\fR
.SH "DESCRIPTION"
.PP
\fBdnssec-keygen\fR generates keys for DNSSEC
\fB-e\fR
If generating an RSA key, use a large exponent.
.TP
+\fB-f \fIflag\fB\fR
+Set the specified flag in the flag field of the key record.
+The only recognized flag is KSK (Key Signing Key).
+.TP
\fB-g \fIgenerator\fB\fR
If generating a Diffie Hellman key, use this generator.
Allowed values are 2 and 5. If no generator
>dnssec-keygen</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"></HEAD
><BODY
CLASS="REFENTRY"
>-e</TT
>] [<TT
CLASS="OPTION"
+>-f <TT
+CLASS="REPLACEABLE"
+><I
+>flag</I
+></TT
+></TT
+>] [<TT
+CLASS="OPTION"
>-g <TT
CLASS="REPLACEABLE"
><I
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN48"
+NAME="AEN51"
></A
><H2
>DESCRIPTION</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN52"
+NAME="AEN55"
></A
><H2
>OPTIONS</H2
</P
></DD
><DT
+>-f <TT
+CLASS="REPLACEABLE"
+><I
+>flag</I
+></TT
+></DT
+><DD
+><P
+> Set the specified flag in the flag field of the key record.
+ The only recognized flag is KSK (Key Signing Key).
+ </P
+></DD
+><DT
>-g <TT
CLASS="REPLACEABLE"
><I
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN121"
+NAME="AEN129"
></A
><H2
>GENERATED KEYS</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN148"
+NAME="AEN156"
></A
><H2
>EXAMPLE</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN161"
+NAME="AEN169"
></A
><H2
>SEE ALSO</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN177"
+NAME="AEN185"
></A
><H2
>AUTHOR</H2
dnssec-signzone \- DNSSEC zone signing tool
.SH SYNOPSIS
.sp
-\fBdnssec-signzone\fR [ \fB-a\fR ] [ \fB-c \fIclass\fB\fR ] [ \fB-d \fIdirectory\fB\fR ] [ \fB-s \fIstart-time\fB\fR ] [ \fB-e \fIend-time\fB\fR ] [ \fB-f \fIoutput-file\fB\fR ] [ \fB-h\fR ] [ \fB-i \fIinterval\fB\fR ] [ \fB-n \fInthreads\fB\fR ] [ \fB-o \fIorigin\fB\fR ] [ \fB-p\fR ] [ \fB-r \fIrandomdev\fB\fR ] [ \fB-t\fR ] [ \fB-v \fIlevel\fB\fR ] \fBzonefile\fR [ \fBkey\fR\fI...\fR ]
+\fBdnssec-signzone\fR [ \fB-a\fR ] [ \fB-c \fIclass\fB\fR ] [ \fB-d \fIdirectory\fB\fR ] [ \fB-e \fIend-time\fB\fR ] [ \fB-f \fIoutput-file\fB\fR ] [ \fB-g\fR ] [ \fB-h\fR ] [ \fB-k \fIkey\fB\fR ] [ \fB-i \fIinterval\fB\fR ] [ \fB-n \fInthreads\fB\fR ] [ \fB-o \fIorigin\fB\fR ] [ \fB-p\fR ] [ \fB-r \fIrandomdev\fB\fR ] [ \fB-s \fIstart-time\fB\fR ] [ \fB-t\fR ] [ \fB-v \fIlevel\fB\fR ] [ \fB-z\fR ] \fBzonefile\fR [ \fBkey\fR\fI...\fR ]
.SH "DESCRIPTION"
.PP
-\fBdnssec-signzone\fR signs a zone. It generates NXT
-and SIG records and produces a signed version of the zone. If there
+\fBdnssec-signzone\fR signs a zone. It generates NSEC
+and RRSIG records and produces a signed version of the zone. If there
is a \fIsignedkey\fR file from the zone's parent,
the parent's signatures will be incorporated into the generated
signed zone file. The security status of delegations from the the
\fB-c \fIclass\fB\fR
Specifies the DNS class of the zone.
.TP
+\fB-k \fIkey\fB\fR
+Treat specified key as a key signing key ignoring any
+key flags. This option may be specified multiple times.
+.TP
\fB-d \fIdirectory\fB\fR
Look for \fIsignedkey\fR files in
\fBdirectory\fR as the directory
.TP
+\fB-g\fR
+Generate DS records for child zones from keyset files.
+Existing DS records will be removed.
+.TP
\fB-s \fIstart-time\fB\fR
-Specify the date and time when the generated SIG records
+Specify the date and time when the generated RRSIG records
become valid. This can be either an absolute or relative
time. An absolute start time is indicated by a number
in YYYYMMDDHHMMSS notation; 20000530144500 denotes
14:45:00 UTC on May 30th, 2000. A relative start time is
indicated by +N, which is N seconds from the current time.
If no \fBstart-time\fR is specified, the current
-time is used.
+time minus 1 hour (to allow for clock skew) is used.
.TP
\fB-e \fIend-time\fB\fR
-Specify the date and time when the generated SIG records
+Specify the date and time when the generated RRSIG records
expire. As with \fBstart-time\fR, an absolute
time is indicated in YYYYMMDDHHMMSS notation. A time relative
to the start time is indicated with +N, which is N seconds from
-the start time. A time realtive to the current time is
+the start time. A time relative to the current time is
indicated with now+N. If no \fBend-time\fR is
specified, 30 days from the start time is used as a default.
.TP
When a previously signed zone is passed as input, records
may be resigned. The \fBinterval\fR option
specifies the cycle interval as an offset from the current
-time (in seconds). If a SIG record expires after the
+time (in seconds). If a RRSIG record expires after the
cycle interval, it is retained. Otherwise, it is considered
to be expiring soon, and it will be replaced.
\fBend-time\fR or \fBstart-time\fR
are specified, \fBdnssec-signzone\fR generates
signatures that are valid for 30 days, with a cycle
-interval of 7.5 days. Therefore, if any existing SIG records
+interval of 7.5 days. Therefore, if any existing RRSIG records
are due to expire in less than 7.5 days, they would be
replaced.
.TP
\fB-v \fIlevel\fB\fR
Sets the debugging level.
.TP
+\fB-z\fR
+Ignore KSK flag on key when determining what to sign.
+.TP
\fBzonefile\fR
The file containing the zone to be signed.
Sets the debugging level.
>dnssec-signzone</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"></HEAD
><BODY
CLASS="REFENTRY"
></TT
>] [<TT
CLASS="OPTION"
->-s <TT
-CLASS="REPLACEABLE"
-><I
->start-time</I
-></TT
-></TT
->] [<TT
-CLASS="OPTION"
>-e <TT
CLASS="REPLACEABLE"
><I
></TT
>] [<TT
CLASS="OPTION"
+>-g</TT
+>] [<TT
+CLASS="OPTION"
>-h</TT
>] [<TT
CLASS="OPTION"
+>-k <TT
+CLASS="REPLACEABLE"
+><I
+>key</I
+></TT
+></TT
+>] [<TT
+CLASS="OPTION"
>-i <TT
CLASS="REPLACEABLE"
><I
></TT
>] [<TT
CLASS="OPTION"
+>-s <TT
+CLASS="REPLACEABLE"
+><I
+>start-time</I
+></TT
+></TT
+>] [<TT
+CLASS="OPTION"
>-t</TT
>] [<TT
CLASS="OPTION"
>level</I
></TT
></TT
+>] [<TT
+CLASS="OPTION"
+>-z</TT
>] {zonefile} [key...]</P
></DIV
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN56"
+NAME="AEN63"
></A
><H2
>DESCRIPTION</H2
> <B
CLASS="COMMAND"
>dnssec-signzone</B
-> signs a zone. It generates NXT
- and SIG records and produces a signed version of the zone. If there
+> signs a zone. It generates NSEC
+ and RRSIG records and produces a signed version of the zone. If there
is a <TT
CLASS="FILENAME"
>signedkey</TT
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN62"
+NAME="AEN69"
></A
><H2
>OPTIONS</H2
</P
></DD
><DT
+>-k <TT
+CLASS="REPLACEABLE"
+><I
+>key</I
+></TT
+></DT
+><DD
+><P
+> Treat specified key as a key signing key ignoring any
+ key flags. This option may be specified multiple times.
+ </P
+></DD
+><DT
>-d <TT
CLASS="REPLACEABLE"
><I
</P
></DD
><DT
+>-g</DT
+><DD
+><P
+> Generate DS records for child zones from keyset files.
+ Existing DS records will be removed.
+ </P
+></DD
+><DT
>-s <TT
CLASS="REPLACEABLE"
><I
></DT
><DD
><P
-> Specify the date and time when the generated SIG records
+> Specify the date and time when the generated RRSIG records
become valid. This can be either an absolute or relative
time. An absolute start time is indicated by a number
in YYYYMMDDHHMMSS notation; 20000530144500 denotes
CLASS="OPTION"
>start-time</TT
> is specified, the current
- time is used.
+ time minus 1 hour (to allow for clock skew) is used.
</P
></DD
><DT
></DT
><DD
><P
-> Specify the date and time when the generated SIG records
+> Specify the date and time when the generated RRSIG records
expire. As with <TT
CLASS="OPTION"
>start-time</TT
>, an absolute
time is indicated in YYYYMMDDHHMMSS notation. A time relative
to the start time is indicated with +N, which is N seconds from
- the start time. A time realtive to the current time is
+ the start time. A time relative to the current time is
indicated with now+N. If no <TT
CLASS="OPTION"
>end-time</TT
>interval</TT
> option
specifies the cycle interval as an offset from the current
- time (in seconds). If a SIG record expires after the
+ time (in seconds). If a RRSIG record expires after the
cycle interval, it is retained. Otherwise, it is considered
to be expiring soon, and it will be replaced.
</P
>dnssec-signzone</B
> generates
signatures that are valid for 30 days, with a cycle
- interval of 7.5 days. Therefore, if any existing SIG records
+ interval of 7.5 days. Therefore, if any existing RRSIG records
are due to expire in less than 7.5 days, they would be
replaced.
</P
</P
></DD
><DT
+>-z</DT
+><DD
+><P
+> Ignore KSK flag on key when determining what to sign.
+ </P
+></DD
+><DT
>zonefile</DT
><DD
><P
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN154"
+NAME="AEN174"
></A
><H2
>EXAMPLE</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN168"
+NAME="AEN188"
></A
><H2
>SEE ALSO</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN179"
+NAME="AEN199"
></A
><H2
>AUTHOR</H2
named \- Internet domain name server
.SH SYNOPSIS
.sp
-\fBnamed\fR [ \fB-c \fIconfig-file\fB\fR ] [ \fB-d \fIdebug-level\fB\fR ] [ \fB-f\fR ] [ \fB-g\fR ] [ \fB-n \fI#cpus\fB\fR ] [ \fB-p \fIport\fB\fR ] [ \fB-s\fR ] [ \fB-t \fIdirectory\fB\fR ] [ \fB-u \fIuser\fB\fR ] [ \fB-v\fR ] [ \fB-x \fIcache-file\fB\fR ]
+\fBnamed\fR [ \fB-4\fR ] [ \fB-6\fR ] [ \fB-c \fIconfig-file\fB\fR ] [ \fB-d \fIdebug-level\fB\fR ] [ \fB-f\fR ] [ \fB-g\fR ] [ \fB-n \fI#cpus\fB\fR ] [ \fB-p \fIport\fB\fR ] [ \fB-s\fR ] [ \fB-t \fIdirectory\fB\fR ] [ \fB-u \fIuser\fB\fR ] [ \fB-v\fR ] [ \fB-x \fIcache-file\fB\fR ]
.SH "DESCRIPTION"
.PP
\fBnamed\fR is a Domain Name System (DNS) server,
data, and listen for queries.
.SH "OPTIONS"
.TP
+\fB-4\fR
+Use IPv4 only even if the host machine is capable of IPv6.
+\fB-4\fR and \fB-6\fR are mutually
+exclusive.
+.TP
+\fB-6\fR
+Use IPv6 only even if the host machine is capable of IPv4.
+\fB-4\fR and \fB-6\fR are mutually
+exclusive.
+.TP
\fB-c \fIconfig-file\fB\fR
Use \fIconfig-file\fR as the
configuration file instead of the default,
>named</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"></HEAD
><BODY
CLASS="REFENTRY"
>named</B
> [<TT
CLASS="OPTION"
+>-4</TT
+>] [<TT
+CLASS="OPTION"
+>-6</TT
+>] [<TT
+CLASS="OPTION"
>-c <TT
CLASS="REPLACEABLE"
><I
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN45"
+NAME="AEN49"
></A
><H2
>DESCRIPTION</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN52"
+NAME="AEN56"
></A
><H2
>OPTIONS</H2
CLASS="VARIABLELIST"
><DL
><DT
+>-4</DT
+><DD
+><P
+> Use IPv4 only even if the host machine is capable of IPv6.
+ <TT
+CLASS="OPTION"
+>-4</TT
+> and <TT
+CLASS="OPTION"
+>-6</TT
+> are mutually
+ exclusive.
+ </P
+></DD
+><DT
+>-6</DT
+><DD
+><P
+> Use IPv6 only even if the host machine is capable of IPv4.
+ <TT
+CLASS="OPTION"
+>-4</TT
+> and <TT
+CLASS="OPTION"
+>-6</TT
+> are mutually
+ exclusive.
+ </P
+></DD
+><DT
>-c <TT
CLASS="REPLACEABLE"
><I
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN137"
+NAME="AEN153"
></A
><H2
>SIGNALS</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN151"
+NAME="AEN167"
></A
><H2
>CONFIGURATION</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN156"
+NAME="AEN172"
></A
><H2
>FILES</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN169"
+NAME="AEN185"
></A
><H2
>SEE ALSO</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN182"
+NAME="AEN198"
></A
><H2
>AUTHOR</H2
nsupdate \- Dynamic DNS update utility
.SH SYNOPSIS
.sp
-\fBnsupdate\fR [ \fB-d\fR ] [ \fB [ -y \fIkeyname:secret\fB ] [ -k \fIkeyfile\fB ] \fR ] [ \fB-v\fR ] [ \fBfilename\fR ]
+\fBnsupdate\fR [ \fB-d\fR ] [ \fB [ -y \fIkeyname:secret\fB ] [ -k \fIkeyfile\fB ] \fR ] [ \fB-t \fItimeout\fB\fR ] [ \fB-u \fIudptimeout\fB\fR ] [ \fB-r \fIudpretries\fB\fR ] [ \fB-v\fR ] [ \fBfilename\fR ]
.SH "DESCRIPTION"
.PP
\fBnsupdate\fR
.PP
By default
\fBnsupdate\fR
-uses UDP to send update requests to the name server.
+uses UDP to send update requests to the name server unless they are too
+large to fit in a UDP request in which case TCP will be used.
The
\fB-v\fR
option makes
\fBnsupdate\fR
use a TCP connection.
This may be preferable when a batch of update requests is made.
+.PP
+The \fB-t\fR option sets the maximum time a update request can
+take before it is aborted. The default is 300 seconds. Zero can be used
+to disable the timeout.
+.PP
+The \fB-u\fR option sets the UDP retry interval. The default is
+3 seconds. If zero the interval will be computed from the timeout interval
+and number of UDP retries.
+.PP
+The \fB-r\fR option sets the number of UDP retries. The default is
+3. If zero only one update request will be made.
.SH "INPUT FORMAT"
.PP
\fBnsupdate\fR
\fIaddress\fR.
When no local statement is provided,
\fBnsupdate\fR
-will send updates using an address and port choosen by the system.
+will send updates using an address and port chosen by the system.
\fIport\fR
can additionally be used to make requests come from a specific port.
If no port number is specified, the system will assign one.
long-standing rule in RFC1034 that a name must not exist as any other
record type if it exists as a CNAME.
(The rule has been updated for DNSSEC in RFC2535 to allow CNAMEs to have
-SIG, KEY and NXT records.)
+RRSIG, DNSKEY and NSEC records.)
.SH "FILES"
.TP
\fB/etc/resolv.conf\fR
>nsupdate</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"></HEAD
><BODY
CLASS="REFENTRY"
></TT
>] [<TT
CLASS="OPTION"
+>-t <TT
+CLASS="REPLACEABLE"
+><I
+>timeout</I
+></TT
+></TT
+>] [<TT
+CLASS="OPTION"
+>-u <TT
+CLASS="REPLACEABLE"
+><I
+>udptimeout</I
+></TT
+></TT
+>] [<TT
+CLASS="OPTION"
+>-r <TT
+CLASS="REPLACEABLE"
+><I
+>udpretries</I
+></TT
+></TT
+>] [<TT
+CLASS="OPTION"
>-v</TT
>] [filename]</P
></DIV
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN26"
+NAME="AEN35"
></A
><H2
>DESCRIPTION</H2
CLASS="COMMAND"
>nsupdate</B
>
-uses UDP to send update requests to the name server.
+uses UDP to send update requests to the name server unless they are too
+large to fit in a UDP request in which case TCP will be used.
The
<TT
CLASS="OPTION"
>
use a TCP connection.
This may be preferable when a batch of update requests is made.</P
+><P
+>The <TT
+CLASS="OPTION"
+>-t</TT
+> option sets the maximum time a update request can
+take before it is aborted. The default is 300 seconds. Zero can be used
+to disable the timeout.</P
+><P
+>The <TT
+CLASS="OPTION"
+>-u</TT
+> option sets the UDP retry interval. The default is
+3 seconds. If zero the interval will be computed from the timeout interval
+and number of UDP retries.</P
+><P
+>The <TT
+CLASS="OPTION"
+>-r</TT
+> option sets the number of UDP retries. The default is
+3. If zero only one update request will be made.</P
></DIV
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN67"
+NAME="AEN82"
></A
><H2
>INPUT FORMAT</H2
CLASS="COMMAND"
>nsupdate</B
>
-will send updates using an address and port choosen by the system.
+will send updates using an address and port chosen by the system.
<TT
CLASS="PARAMETER"
><I
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN225"
+NAME="AEN240"
></A
><H2
>EXAMPLES</H2
long-standing rule in RFC1034 that a name must not exist as any other
record type if it exists as a CNAME.
(The rule has been updated for DNSSEC in RFC2535 to allow CNAMEs to have
-SIG, KEY and NXT records.)</P
+RRSIG, DNSKEY and NSEC records.)</P
></DIV
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN238"
+NAME="AEN253"
></A
><H2
>FILES</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN262"
+NAME="AEN277"
></A
><H2
>SEE ALSO</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN285"
+NAME="AEN300"
></A
><H2
>BUGS</H2
-.\" Copyright (C) 2001 Internet Software Consortium.
+.\"
+.\" Copyright (C) 2000, 2001 Internet Software Consortium.
.\"
.\" Permission to use, copy, modify, and distribute this software for any
.\" purpose with or without fee is hereby granted, provided that the above
.\" NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION
.\" WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
.\"
-.\" $Id: rndc-confgen.8,v 1.5 2002/02/20 03:33:40 marka Exp $
-
.TH "RNDC-CONFGEN" "8" "Aug 27, 2001" "BIND9" ""
.SH NAME
rndc-confgen \- rndc key generation tool
.TP
\fB-r \fIrandomfile\fB\fR
Specifies a source of random data for generating the
-authoriazation. If the operating
+authorization. If the operating
system does not provide a \fI/dev/random\fR
or equivalent device, the default source of randomness
is keyboard input. \fIrandomdev\fR specifies
<!--
- - Copyright (C) 2001 Internet Software Consortium.
- -
+ - Copyright (C) 2000, 2001 Internet Software Consortium.
+ -
- Permission to use, copy, modify, and distribute this software for any
- purpose with or without fee is hereby granted, provided that the above
- copyright notice and this permission notice appear in all copies.
- -
+ -
- THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM
- DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
- IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
- NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION
- WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
-->
-
-<!-- $Id: rndc-confgen.html,v 1.5 2002/02/20 03:33:42 marka Exp $ -->
-
<HTML
><HEAD
><TITLE
>rndc-confgen</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"></HEAD
><BODY
CLASS="REFENTRY"
><DD
><P
> Specifies a source of random data for generating the
- authoriazation. If the operating
+ authorization. If the operating
system does not provide a <TT
CLASS="FILENAME"
>/dev/random</TT
>Introduction </TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"><LINK
REL="HOME"
TITLE="BIND 9 Administrator Reference Manual"
><DIV
CLASS="NAVHEADER"
><TABLE
+SUMMARY="Header navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="bottom"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="bottom"
><A
HREF="Bv9ARM.ch02.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
>1.2. Organization of This Document</A
></H1
><P
->In this document, <I
+>In this document, <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Section 1</I
+></SPAN
> introduces
the basic <SPAN
CLASS="acronym"
> and <SPAN
CLASS="acronym"
>BIND</SPAN
-> concepts. <I
+> concepts. <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Section 2</I
+></SPAN
>
describes resource requirements for running <SPAN
CLASS="acronym"
>BIND</SPAN
> in various
- environments. Information in <I
+ environments. Information in <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Section 3</I
+></SPAN
> is
- <I
+ <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>task-oriented</I
+></SPAN
> in its presentation and is
organized functionally, to aid in the process of installing the
<SPAN
CLASS="acronym"
>BIND</SPAN
> 9 software. The task-oriented section is followed by
- <I
+ <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Section 4</I
+></SPAN
>, which contains more advanced
concepts that the system administrator may need for implementing
- certain options. <I
+ certain options. <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Section 5</I
+></SPAN
>
describes the <SPAN
CLASS="acronym"
>BIND</SPAN
> 9 lightweight
- resolver. The contents of <I
+ resolver. The contents of <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Section 6</I
+></SPAN
> are
organized as in a reference manual to aid in the ongoing
- maintenance of the software. <I
+ maintenance of the software. <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Section 7
</I
+></SPAN
>addresses security considerations, and
- <I
+ <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Section 8</I
+></SPAN
> contains troubleshooting help. The
main body of the document is followed by several
- <I
+ <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Appendices</I
+></SPAN
> which contain useful reference
- information, such as a <I
+ information, such as a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Bibliography</I
+></SPAN
> and
historic information related to <SPAN
CLASS="acronym"
ALIGN="LEFT"
VALIGN="MIDDLE"
> <P
+><SPAN
+CLASS="emphasis"
><I
CLASS="emphasis"
>To
describe:</I
+></SPAN
></P
></TD
><TD
ALIGN="LEFT"
VALIGN="MIDDLE"
> <P
+><SPAN
+CLASS="emphasis"
><I
CLASS="emphasis"
>We use the style:</I
+></SPAN
></P
></TD
></TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
+><SPAN
+CLASS="emphasis"
><I
CLASS="emphasis"
>To
describe:</I
+></SPAN
></P
></TD
><TD
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
+><SPAN
+CLASS="emphasis"
><I
CLASS="emphasis"
>We use the style:</I
+></SPAN
></P
></TD
></TR
used by Internet applications.</P
><P
>Clients look up information in the DNS by calling a
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>resolver</I
+></SPAN
> library, which sends queries to one or
-more <I
+more <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>name servers</I
+></SPAN
> and interprets the responses.
The <SPAN
CLASS="acronym"
>1.4.2. Domains and Domain Names</A
></H2
><P
->The data stored in the DNS is identified by <I
+>The data stored in the DNS is identified by <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>domain
names</I
+></SPAN
> that are organized as a tree according to
organizational or administrative boundaries. Each node of the tree,
-called a <I
+called a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>domain</I
+></SPAN
>, is given a label. The domain name of the
node is the concatenation of all the labels on the path from the
-node to the <I
+node to the <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>root</I
+></SPAN
> node. This is represented
in written form as a string of labels listed from right to left and
separated by dots. A label need only be unique within its parent
domain.</P
><P
>For example, a domain name for a host at the
-company <I
+company <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Example, Inc.</I
+></SPAN
> could be
<TT
CLASS="literal"
name of the host.</P
><P
>For administrative purposes, the name space is partitioned into
-areas called <I
+areas called <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>zones</I
+></SPAN
>, each starting at a node and
extending down to the leaf nodes or to nodes where other zones start.
-The data for each zone is stored in a <I
+The data for each zone is stored in a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>name
server</I
+></SPAN
>, which answers queries about the zone using the
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>DNS protocol</I
+></SPAN
>.
</P
><P
>The data associated with each domain name is stored in the
-form of <I
+form of <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>resource records</I
+></SPAN
> (<SPAN
CLASS="acronym"
>RR</SPAN
></H2
><P
>To properly operate a name server, it is important to understand
-the difference between a <I
+the difference between a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>zone</I
+></SPAN
>
-and a <I
+and a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>domain</I
+></SPAN
>.</P
><P
>As we stated previously, a zone is a point of delegation in
it has authority. It contains all domain names from a certain point
downward in the domain tree except those which are delegated to
other zones. A delegation point is marked by one or more
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>NS records</I
+></SPAN
> in the
parent zone, which should be matched by equivalent NS records at
the root of the delegated zone.</P
CLASS="acronym"
>DNS</SPAN
> tree is a
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>domain</I
+></SPAN
>, even if it is
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>terminal</I
+></SPAN
>, that is, has no
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>subdomains</I
+></SPAN
>. Every subdomain is a domain and
every domain except the root is also a subdomain. The terminology is
not intuitive and we suggest that you read RFCs 1033, 1034 and 1035 to
>named.conf</TT
> file specify
zones, not domains. When you ask some other site if it is willing to
-be a slave server for your <I
+be a slave server for your <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>domain</I
+></SPAN
>, you are
actually asking for slave service for some collection of zones.</P
></DIV
></H2
><P
>Each zone is served by at least
-one <I
+one <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>authoritative name server</I
+></SPAN
>,
which contains the complete data for the zone.
To make the DNS tolerant of server and network failures,
></H3
><P
> The authoritative server where the master copy of the zone data is maintained is
-called the <I
+called the <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>primary master</I
+></SPAN
> server, or simply the
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>primary</I
+></SPAN
>. It loads the zone contents from some
local file edited by humans or perhaps generated mechanically from
some other local file which is edited by humans. This file is called
-the <I
+the <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>zone file</I
-> or <I
+></SPAN
+> or <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>master file</I
+></SPAN
>.</P
></DIV
><DIV
>1.4.4.2. Slave Servers</A
></H3
><P
->The other authoritative servers, the <I
+>The other authoritative servers, the <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>slave</I
+></SPAN
>
-servers (also known as <I
+servers (also known as <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>secondary</I
+></SPAN
> servers) load
the zone contents from another server using a replication process
-known as a <I
+known as a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>zone transfer</I
+></SPAN
>. Typically the data are
transferred directly from the primary master, but it is also possible
to transfer it from another slave. In other words, a slave server
><P
>Usually all of the zone's authoritative servers are listed in
NS records in the parent zone. These NS records constitute
-a <I
+a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>delegation</I
+></SPAN
> of the zone from the parent.
The authoritative servers are also listed in the zone file itself,
-at the <I
+at the <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>top level</I
-> or <I
+></SPAN
+> or <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>apex</I
+></SPAN
>
of the zone. You can list servers in the zone's top-level NS
records that are not in the parent's NS delegation, but you cannot
list servers in the parent's delegation that are not present at
the zone's top level.</P
><P
->A <I
+>A <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>stealth server</I
+></SPAN
> is a server that is
authoritative for a zone but is not listed in that zone's NS
records. Stealth servers can be used for keeping a local copy of a
></H2
><P
>The resolver libraries provided by most operating systems are
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>stub resolvers</I
+></SPAN
>, meaning that they are not capable of
performing the full DNS resolution process by themselves by talking
directly to the authoritative servers. Instead, they rely on a local
name server to perform the resolution on their behalf. Such a server
-is called a <I
+is called a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>recursive</I
+></SPAN
> name server; it performs
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>recursive lookups</I
+></SPAN
> for local clients.</P
><P
>To improve performance, recursive servers cache the results of
the lookups they perform. Since the processes of recursion and
caching are intimately connected, the terms
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>recursive server</I
+></SPAN
> and
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>caching server</I
+></SPAN
> are often used synonymously.</P
><P
>The length of time for which a record may be retained in
><P
>Even a caching name server does not necessarily perform
the complete recursive lookup itself. Instead, it can
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>forward</I
+></SPAN
> some or all of the queries
that it cannot satisfy from its cache to another caching name server,
-commonly referred to as a <I
+commonly referred to as a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>forwarder</I
+></SPAN
>.
</P
><P
often advantageous to run them on separate server machines.
A server that only provides authoritative name service
-(an <I
+(an <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>authoritative-only</I
+></SPAN
> server) can run with
recursion disabled, improving reliability and security.
A server that is not authoritative for any zones and only provides
recursive service to local
-clients (a <I
+clients (a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>caching-only</I
+></SPAN
> server)
does not need to be reachable from the Internet at large and can
be placed inside a firewall.</P
><HR
ALIGN="LEFT"
WIDTH="100%"><TABLE
+SUMMARY="Footer navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="top"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="H"
>Home</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.ch02.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
>BIND Resource Requirements</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"><LINK
REL="HOME"
TITLE="BIND 9 Administrator Reference Manual"
><DIV
CLASS="NAVHEADER"
><TABLE
+SUMMARY="Header navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="bottom"
><A
HREF="Bv9ARM.ch01.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="bottom"
><A
HREF="Bv9ARM.ch03.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
><HR
ALIGN="LEFT"
WIDTH="100%"><TABLE
+SUMMARY="Footer navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="top"
><A
HREF="Bv9ARM.ch01.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="H"
>Home</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.ch03.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
>Name Server Configuration</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"><LINK
REL="HOME"
TITLE="BIND 9 Administrator Reference Manual"
><DIV
CLASS="NAVHEADER"
><TABLE
+SUMMARY="Header navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="bottom"
><A
HREF="Bv9ARM.ch02.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="bottom"
><A
HREF="Bv9ARM.ch04.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
><DD
><P
>Toggle query logging. Query logging can also be enabled
- by explictly directing the <B
+ by explicitly directing the <B
CLASS="command"
>queries</B
>
></DT
><DD
><P
->Display status of the server.</P
+>Display status of the server.
+Note the number of zones includes the internal <B
+CLASS="command"
+>bind/CH</B
+> zone
+and the default <B
+CLASS="command"
+>./IN</B
+> hint zone if there is not a
+explicit root zone configured.</P
></DD
></DL
></DIV
><H2
CLASS="sect2"
><A
-NAME="AEN675"
+NAME="AEN677"
>3.3.2. Signals</A
></H2
><P
><DIV
CLASS="informaltable"
><A
-NAME="AEN679"
+NAME="AEN681"
></A
><P
></P
><HR
ALIGN="LEFT"
WIDTH="100%"><TABLE
+SUMMARY="Footer navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="top"
><A
HREF="Bv9ARM.ch02.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="H"
>Home</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.ch04.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
>Advanced DNS Features</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"><LINK
REL="HOME"
TITLE="BIND 9 Administrator Reference Manual"
><DIV
CLASS="NAVHEADER"
><TABLE
+SUMMARY="Header navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="bottom"
><A
HREF="Bv9ARM.ch03.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="bottom"
><A
HREF="Bv9ARM.ch05.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
></DT
><DT
>4.4. <A
-HREF="Bv9ARM.ch04.html#AEN753"
+HREF="Bv9ARM.ch04.html#AEN755"
>Split DNS</A
></DT
><DT
></DT
><DT
>4.6. <A
-HREF="Bv9ARM.ch04.html#AEN913"
+HREF="Bv9ARM.ch04.html#AEN915"
>TKEY</A
></DT
><DT
>4.7. <A
-HREF="Bv9ARM.ch04.html#AEN928"
+HREF="Bv9ARM.ch04.html#AEN930"
>SIG(0)</A
></DT
><DT
></DT
><DT
>4.9. <A
-HREF="Bv9ARM.ch04.html#AEN1015"
+HREF="Bv9ARM.ch04.html#AEN1017"
>IPv6 Support in <SPAN
CLASS="acronym"
>BIND</SPAN
>notify</B
> option in <A
HREF="Bv9ARM.ch06.html#boolean_options"
->Section 6.2.14.1</A
+>Section 6.2.16.1</A
> and
the description of the zone option <B
CLASS="command"
> in
<A
HREF="Bv9ARM.ch06.html#zone_transfers"
->Section 6.2.14.6</A
+>Section 6.2.16.7</A
>. The <B
CLASS="command"
>NOTIFY</B
><H1
CLASS="sect1"
><A
-NAME="AEN753"
+NAME="AEN755"
>4.4. Split DNS</A
></H1
><P
>Setting up different views, or visibility, of the DNS space to
-internal and external resolvers is usually referred to as a <I
+internal and external resolvers is usually referred to as a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Split
DNS</I
+></SPAN
> setup. There are several reasons an organization
would want to set up its DNS this way.</P
><P
><P
>Here is an example of a split DNS setup:</P
><P
->Let's say a company named <I
+>Let's say a company named <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Example, Inc.</I
+></SPAN
>
(<TT
CLASS="literal"
Internet Protocol (IP) space and an external demilitarized zone (DMZ),
or "outside" section of a network, that is available to the public.</P
><P
+><SPAN
+CLASS="emphasis"
><I
CLASS="emphasis"
>Example, Inc.</I
+></SPAN
> wants its internal clients
to be able to resolve external hostnames and to exchange mail with
people on the outside. The company also wants its internal resolvers
>, <TT
CLASS="filename"
>site2.example.com</TT
->,<I
+>,<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
> </I
+></SPAN
><TT
CLASS="filename"
>site1.internal</TT
out to the DNS servers on the bastion hosts.</P
><P
>In order for all this to work properly, internal clients will
-need to be configured to query <I
+need to be configured to query <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>only</I
+></SPAN
> the internal
name servers for DNS queries. This could also be enforced via selective
filtering on the network.</P
><P
->If everything has been set properly, <I
+>If everything has been set properly, <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Example, Inc.</I
+></SPAN
>'s
internal clients will now be able to:</P
><P
><H2
CLASS="sect2"
><A
-NAME="AEN844"
+NAME="AEN846"
>4.5.1. Generate Shared Keys for Each Pair of Hosts</A
></H2
><P
->A shared secret is generated to be shared between <I
+>A shared secret is generated to be shared between <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host1</I
-> and <I
+></SPAN
+> and <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host2</I
+></SPAN
>.
An arbitrary key name is chosen: "host1-host2.". The key name must
be the same on both hosts.</P
><H3
CLASS="sect3"
><A
-NAME="AEN849"
+NAME="AEN851"
>4.5.1.1. Automatic Generation</A
></H3
><P
><H3
CLASS="sect3"
><A
-NAME="AEN860"
+NAME="AEN862"
>4.5.1.2. Manual Generation</A
></H3
><P
><H2
CLASS="sect2"
><A
-NAME="AEN865"
+NAME="AEN867"
>4.5.2. Copying the Shared Secret to Both Machines</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN868"
+NAME="AEN870"
>4.5.3. Informing the Servers of the Key's Existence</A
></H2
><P
->Imagine <I
+>Imagine <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host1</I
-> and <I
+></SPAN
+> and <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host 2</I
+></SPAN
> are
both servers. The following is added to each server's <TT
CLASS="filename"
><H2
CLASS="sect2"
><A
-NAME="AEN880"
+NAME="AEN882"
>4.5.4. Instructing the Server to Use the Key</A
></H2
><P
CLASS="filename"
>named.conf</TT
> file
-for <I
+for <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host1</I
->, if the IP address of <I
+></SPAN
+>, if the IP address of <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host2</I
+></SPAN
> is
10.1.2.3:</P
><PRE
This directive does not contain any secrets, so it may be in a world-readable
file.</P
><P
->If <I
+>If <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host1</I
+></SPAN
> sends a message that is a request
-to that address, the message will be signed with the specified key. <I
+to that address, the message will be signed with the specified key. <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host1</I
+></SPAN
> will
expect any responses to signed messages to be signed with the same
key.</P
><P
->A similar statement must be present in <I
+>A similar statement must be present in <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host2</I
+></SPAN
>'s
-configuration file (with <I
+configuration file (with <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host1</I
->'s address) for <I
+></SPAN
+>'s address) for <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host2</I
+></SPAN
> to
-sign request messages to <I
+sign request messages to <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>host1</I
+></SPAN
>.</P
></DIV
><DIV
><H2
CLASS="sect2"
><A
-NAME="AEN896"
+NAME="AEN898"
>4.5.5. TSIG Key Based Access Control</A
></H2
><P
>update-policy</B
> statement in <A
HREF="Bv9ARM.ch06.html#dynamic_update_policies"
->Section 6.2.22.4</A
+>Section 6.2.24.4</A
>.</P
></DIV
><DIV
><H2
CLASS="sect2"
><A
-NAME="AEN909"
+NAME="AEN911"
>4.5.6. Errors</A
></H2
><P
><H1
CLASS="sect1"
><A
-NAME="AEN913"
+NAME="AEN915"
>4.6. TKEY</A
></H1
><P
><H1
CLASS="sect1"
><A
-NAME="AEN928"
+NAME="AEN930"
>4.7. SIG(0)</A
></H1
><P
></H1
><P
>Cryptographic authentication of DNS information is possible
- through the DNS Security (<I
+ through the DNS Security (<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>DNSSEC</I
+></SPAN
>) extensions,
defined in RFC 2535. This section describes the creation and use
of DNSSEC signed zones.</P
><H2
CLASS="sect2"
><A
-NAME="AEN947"
+NAME="AEN949"
>4.8.1. Generating Keys</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN967"
+NAME="AEN969"
>4.8.2. Creating a Keyset</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN979"
+NAME="AEN981"
>4.8.3. Signing the Child's Keyset</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN992"
+NAME="AEN994"
>4.8.4. Signing the Zone</A
></H2
><P
><H2
CLASS="sect2"
><A
-NAME="AEN1008"
+NAME="AEN1010"
>4.8.5. Configuring Servers</A
></H2
><P
><H1
CLASS="sect1"
><A
-NAME="AEN1015"
+NAME="AEN1017"
>4.9. IPv6 Support in <SPAN
CLASS="acronym"
>BIND</SPAN
>For forward lookups, <SPAN
CLASS="acronym"
>BIND</SPAN
-> 9 supports both A6 and AAAA
- records. The use of AAAA records is deprecated, but it is still
- useful for hosts to have both AAAA and A6 records to maintain
- backward compatibility with installations where AAAA records are
- still used. In fact, the stub resolvers currently shipped with
- most operating system support only AAAA lookups, because following
- A6 chains is much harder than doing A or AAAA lookups.</P
+> 9 supports only AAAA
+ records. The use of A6 records is deprecated by RFC 3363, and the
+ support for forward lookups in <SPAN
+CLASS="acronym"
+>BIND</SPAN
+> 9 is
+ removed accordingly.
+ However, authoritative <SPAN
+CLASS="acronym"
+>BIND</SPAN
+> 9 name servers still
+ load zone files containing A6 records correctly, answer queries
+ for A6 records, and accept zone transfer for a zone containing A6
+ records.</P
><P
>For IPv6 reverse lookups, <SPAN
CLASS="acronym"
>BIND</SPAN
-> 9 supports the new
- "binary label" (also known as "bitstring")
- format used in the <I
+> 9 supports
+ the traditional "nibble" format used in the
+ <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>ip6.arpa</I
->
- domain, as well as the older, deprecated "nibble" format used in
- the <I
+></SPAN
+> domain, as well as the older, deprecated
+ <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>ip6.int</I
-> domain.</P
-><P
-><SPAN
+></SPAN
+> domain.
+ <SPAN
CLASS="acronym"
>BIND</SPAN
-> 9 includes a new lightweight resolver library and
- resolver daemon which new applications may choose to use to avoid
- the complexities of A6 chain following and binary labels, see <A
-HREF="Bv9ARM.ch05.html"
->Chapter 5</A
->. Alternatively, applications can link with a stub
- resolver that supports A and AAAA records only and rely on the server to
- synthesize AAAA recorsd from A6 chains (<A
-HREF="Bv9ARM.ch06.html#synthesis"
->Section 6.2.14.13</A
->).
- </P
+> 9 formerly
+ supported the "binary label" (also known as "bitstring") format.
+ The support of binary labels, however, is now completely removed
+ according to the changes in RFC 3363.
+ Any applications in <SPAN
+CLASS="acronym"
+>BIND</SPAN
+> 9 do not understand
+ the format any more, and will return an error if given.
+ In particular, an authoritative <SPAN
+CLASS="acronym"
+>BIND</SPAN
+> 9 name
+ server rejects to load a zone file containing binary labels.</P
><P
>For an overview of the format and structure of IPv6 addresses,
see <A
><H2
CLASS="sect2"
><A
-NAME="AEN1032"
+NAME="AEN1035"
>4.9.1. Address Lookups Using AAAA Records</A
></H2
><P
><PRE
CLASS="programlisting"
> $ORIGIN example.com.
-host 3600 IN AAAA 3ffe:8050:201:1860:42::1
-</PRE
-><P
->While their use is deprecated, they are useful to support
- older IPv6 applications. They should not be added where they
- are not absolutely necessary.</P
-></DIV
-><DIV
-CLASS="sect2"
-><H2
-CLASS="sect2"
-><A
-NAME="AEN1037"
->4.9.2. Address Lookups Using A6 Records</A
-></H2
-><P
->The A6 record is more flexible than the AAAA record, and
- is therefore more complicated. The A6 record can be used to
- form a chain of A6 records, each specifying part of the IPv6
- address. It can also be used to specify the entire record as
- well. For example, this record supplies the same data as the
- AAAA record in the previous example:</P
-><PRE
-CLASS="programlisting"
-> $ORIGIN example.com.
-host 3600 IN A6 0 3ffe:8050:201:1860:42::1
-</PRE
-><DIV
-CLASS="sect3"
-><H3
-CLASS="sect3"
-><A
-NAME="AEN1041"
->4.9.2.1. A6 Chains</A
-></H3
-><P
->A6 records are designed to allow network
- renumbering. This works when an A6 record only specifies the
- part of the address space the domain owner controls. For
- example, a host may be at a company named "company." It has
- two ISPs which provide IPv6 address space for it. These two
- ISPs fully specify the IPv6 prefix they supply.</P
-><P
->In the company's address space:</P
-><PRE
-CLASS="programlisting"
-> $ORIGIN example.com.
-host 3600 IN A6 64 0:0:0:0:42::1 company.example1.net.
-host 3600 IN A6 64 0:0:0:0:42::1 company.example2.net.
-</PRE
-><P
->ISP1 will use:</P
-><PRE
-CLASS="programlisting"
-> $ORIGIN example1.net.
-company 3600 IN A6 0 3ffe:8050:201:1860::
-</PRE
-><P
->ISP2 will use:</P
-><PRE
-CLASS="programlisting"
-> $ORIGIN example2.net.
-company 3600 IN A6 0 1234:5678:90ab:fffa::
-</PRE
-><P
->When <TT
-CLASS="literal"
->host.example.com</TT
-> is looked up,
- the resolver (in the resolver daemon or caching name server)
- will find two partial A6 records, and will use the additional
- name to find the remainder of the data.</P
-></DIV
-><DIV
-CLASS="sect3"
-><H3
-CLASS="sect3"
-><A
-NAME="AEN1052"
->4.9.2.2. A6 Records for DNS Servers</A
-></H3
-><P
->When an A6 record specifies the address of a name
- server, it should use the full address rather than specifying
- a partial address. For example:</P
-><PRE
-CLASS="programlisting"
-> $ORIGIN example.com.
-@ 14400 IN NS ns0
- 14400 IN NS ns1
-ns0 14400 IN A6 0 3ffe:8050:201:1860:42::1
-ns1 14400 IN A 192.168.42.1
+host 3600 IN AAAA 2001:4f8:201:1860:42::1
</PRE
><P
>It is recommended that IPv4-in-IPv6 mapped addresses not
be used. If a host has an IPv4 address, use an A record, not
- an A6, with <TT
+ a AAAA, with <TT
CLASS="literal"
>::ffff:192.168.42.1</TT
> as the
address.</P
></DIV
-></DIV
><DIV
CLASS="sect2"
><H2
CLASS="sect2"
><A
-NAME="AEN1058"
->4.9.3. Address to Name Lookups Using Nibble Format</A
+NAME="AEN1041"
+>4.9.2. Address to Name Lookups Using Nibble Format</A
></H2
><P
->While the use of nibble format to look up names is
- deprecated, it is supported for backwards compatibility with
- existing IPv6 applications.</P
-><P
>When looking up an address in nibble format, the address
components are simply reversed, just as in IPv4, and
<TT
CLASS="literal"
->ip6.int.</TT
+>ip6.arpa.</TT
> is appended to the resulting name.
For example, the following would provide reverse name lookup for
a host with address
<TT
CLASS="literal"
->3ffe:8050:201:1860:42::1</TT
+>2001:4f8:201:1860:42::1</TT
>.</P
><PRE
CLASS="programlisting"
-> $ORIGIN 0.6.8.1.1.0.2.0.0.5.0.8.e.f.f.3.ip6.int.
+> $ORIGIN 0.6.8.1.1.0.2.0.8.f.4.0.1.0.0.2.ip6.arpa.
1.0.0.0.0.0.0.0.0.0.0.0.2.4.0.0 14400 IN PTR host.example.com.
</PRE
></DIV
-><DIV
-CLASS="sect2"
-><H2
-CLASS="sect2"
-><A
-NAME="AEN1065"
->4.9.4. Address to Name Lookups Using Binary Label Format</A
-></H2
-><P
->Binary labels can start and end on any bit boundary,
- rather than on a multiple of 4 bits as in the nibble
- format. They also use <I
-CLASS="emphasis"
->ip6.arpa</I
-> rather than
- <I
-CLASS="emphasis"
->ip6.int</I
->.</P
-><P
->To replicate the previous example using binary labels:</P
-><PRE
-CLASS="programlisting"
-> $ORIGIN \[x3ffe805002011860/64].ip6.arpa.
-\[x0042000000000001/64] 14400 IN PTR host.example.com.
-</PRE
-></DIV
-><DIV
-CLASS="sect2"
-><H2
-CLASS="sect2"
-><A
-NAME="AEN1072"
->4.9.5. Using DNAME for Delegation of IPv6 Reverse Addresses</A
-></H2
-><P
->In IPv6, the same host may have many addresses from many
- network providers. Since the trailing portion of the address
- usually remains constant, <B
-CLASS="command"
->DNAME</B
-> can help
- reduce the number of zone files used for reverse mapping that
- need to be maintained.</P
-><P
->For example, consider a host which has two providers
- (<TT
-CLASS="literal"
->example.net</TT
-> and
- <TT
-CLASS="literal"
->example2.net</TT
->) and
- therefore two IPv6 addresses. Since the host chooses its own 64
- bit host address portion, the provider address is the only part
- that changes:</P
-><PRE
-CLASS="programlisting"
-> $ORIGIN example.com.
-host IN A6 64 ::1234:5678:1212:5675 cust1.example.net.
- IN A6 64 ::1234:5678:1212:5675 subnet5.example2.net.
-$ORIGIN example.net.
-cust1 IN A6 48 0:0:0:dddd:: ipv6net.example.net.
-ipv6net IN A6 0 aa:bb:cccc::
-$ORIGIN example2.net.
-subnet5 IN A6 48 0:0:0:1:: ipv6net2.example2.net.
-ipv6net2 IN A6 0 6666:5555:4::
-</PRE
-><P
->This sets up forward lookups. To handle the reverse lookups,
-the provider <TT
-CLASS="literal"
->example.net</TT
->
-would have:</P
-><PRE
-CLASS="programlisting"
-> $ORIGIN \[x00aa00bbcccc/48].ip6.arpa.
-\[xdddd/16] IN DNAME ipv6-rev.example.com.
-</PRE
-><P
->and <TT
-CLASS="literal"
->example2.net</TT
-> would have:</P
-><PRE
-CLASS="programlisting"
-> $ORIGIN \[x666655550004/48].ip6.arpa.
-\[x0001/16] IN DNAME ipv6-rev.example.com.
-</PRE
-><P
-><TT
-CLASS="literal"
->example.com</TT
->
- needs only one zone file to handle both of these reverse
- mappings:</P
-><PRE
-CLASS="programlisting"
-> $ORIGIN ipv6-rev.example.com.
-\[x1234567812125675/64] IN PTR host.example.com.
-</PRE
-></DIV
></DIV
></DIV
><DIV
><HR
ALIGN="LEFT"
WIDTH="100%"><TABLE
+SUMMARY="Footer navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="top"
><A
HREF="Bv9ARM.ch03.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="H"
>Home</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.ch05.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
>The BIND 9 Lightweight Resolver</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"><LINK
REL="HOME"
TITLE="BIND 9 Administrator Reference Manual"
><DIV
CLASS="NAVHEADER"
><TABLE
+SUMMARY="Header navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="bottom"
><A
HREF="Bv9ARM.ch04.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="bottom"
><A
HREF="Bv9ARM.ch06.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
></DT
><DT
>5.1. <A
-HREF="Bv9ARM.ch05.html#AEN1092"
+HREF="Bv9ARM.ch05.html#AEN1050"
>The Lightweight Resolver Library</A
></DT
><DT
><H1
CLASS="sect1"
><A
-NAME="AEN1092"
+NAME="AEN1050"
>5.1. The Lightweight Resolver Library</A
></H1
><P
library that sends recursive DNS queries to a local caching name
server.</P
><P
->IPv6 introduces new complexity into the resolution process,
+>IPv6 once introduced new complexity into the resolution process,
such as following A6 chains and DNAME records, and simultaneous
-lookup of IPv4 and IPv6 addresses. These are hard or impossible
+lookup of IPv4 and IPv6 addresses. Though most of the complexity was
+then removed, these are hard or impossible
to implement in a traditional stub resolver.</P
><P
>Instead, <SPAN
><HR
ALIGN="LEFT"
WIDTH="100%"><TABLE
+SUMMARY="Footer navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="top"
><A
HREF="Bv9ARM.ch04.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="H"
>Home</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.ch06.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
>BIND 9 Configuration Reference</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"><LINK
REL="HOME"
TITLE="BIND 9 Administrator Reference Manual"
><DIV
CLASS="NAVHEADER"
><TABLE
+SUMMARY="Header navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="bottom"
><A
HREF="Bv9ARM.ch05.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="bottom"
><A
HREF="Bv9ARM.ch07.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
></DT
><DT
>6.3. <A
-HREF="Bv9ARM.ch06.html#AEN3755"
+HREF="Bv9ARM.ch06.html#AEN3956"
>Zone File</A
></DT
></DL
><DIV
CLASS="informaltable"
><A
-NAME="AEN1134"
+NAME="AEN1092"
></A
><P
></P
><P
>An IPv6 address, such as <B
CLASS="command"
->fe80::200:f8ff:fe01:9742</B
->.</P
+>2001:ffff::200:f8ff:fe01:9742</B
+>.
+IPv6 scoped addresses that have ambiguity on their scope zones must be
+disambiguated by an appropriate zone ID with the percent character
+(`%') as delimiter.
+It is strongly recommended to use string zone names rather than
+numeric identifiers, in order to be robust against system
+configuration changes.
+However, since there is no standard mapping for such names and
+identifier values, currently only interface names as link identifiers
+are supported, assuming one-to-one mapping between interfaces and links.
+For example, a link-local address <B
+CLASS="command"
+>fe80::1</B
+> on the
+link attached to the interface <B
+CLASS="command"
+>ne0</B
+>
+can be specified as <B
+CLASS="command"
+>fe80::1%ne0</B
+>.
+Note that on most systems link-local addresses always have the
+ambiguity, and need to be disambiguated.</P
></TD
></TR
><TR
><H3
CLASS="sect3"
><A
-NAME="AEN1296"
+NAME="AEN1257"
>6.1.1.1. Syntax</A
></H3
><PRE
><H3
CLASS="sect3"
><A
-NAME="AEN1304"
+NAME="AEN1265"
>6.1.1.2. Definition and Usage</A
></H3
><P
><H2
CLASS="sect2"
><A
-NAME="AEN1335"
+NAME="AEN1296"
>6.1.2. Comment Syntax</A
></H2
><P
><H3
CLASS="sect3"
><A
-NAME="AEN1340"
+NAME="AEN1301"
>6.1.2.1. Syntax</A
></H3
><P
><H3
CLASS="sect3"
><A
-NAME="AEN1349"
+NAME="AEN1310"
>6.1.2.2. Definition and Usage</A
></H3
><P
><DIV
CLASS="informaltable"
><A
-NAME="AEN1373"
+NAME="AEN1334"
></A
><P
></P
><P
><B
CLASS="command"
+>masters</B
+></P
+></TD
+><TD
+WIDTH="363"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+>defines a named masters list for
+inclusion in stub and slave zone masters clauses.</P
+></TD
+></TR
+><TR
+><TD
+WIDTH="128"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+><B
+CLASS="command"
>options</B
></P
></TD
><H2
CLASS="sect2"
><A
-NAME="AEN1442"
+NAME="AEN1409"
>6.2.1. <B
CLASS="command"
>acl</B
><DIV
CLASS="informaltable"
><A
-NAME="AEN1455"
+NAME="AEN1422"
></A
><P
></P
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->Matches the IPv4 addresses of all network
+>Matches the IPv4 and IPv6 addresses of all network
interfaces on the system.</P
></TD
></TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->Matches any host on an IPv4 network for which
-the system has an interface.</P
+>Matches any host on an IPv4 or IPv6 network
+for which the system has an interface.</P
></TD
></TR
></TBODY
><P
></P
></DIV
-><P
->The <B
-CLASS="command"
->localhost</B
-> and <B
-CLASS="command"
->localnets</B
->
-ACLs do not currently support IPv6 (that is,
-<B
-CLASS="command"
->localhost</B
-> does not match the host's IPv6 addresses,
-and <B
-CLASS="command"
->localnets</B
-> does not match the host's attached
-IPv6 networks) due to the lack of a standard method of determining the
-complete set of local IPv6 addresses for a host.
-</P
></DIV
><DIV
CLASS="sect2"
><H2
CLASS="sect2"
><A
-NAME="AEN1489"
+NAME="AEN1451"
>6.2.3. <B
CLASS="command"
>controls</B
><H2
CLASS="sect2"
><A
-NAME="AEN1568"
+NAME="AEN1530"
>6.2.5. <B
CLASS="command"
>include</B
><H2
CLASS="sect2"
><A
-NAME="AEN1573"
+NAME="AEN1535"
>6.2.6. <B
CLASS="command"
>include</B
><H2
CLASS="sect2"
><A
-NAME="AEN1580"
+NAME="AEN1542"
>6.2.7. <B
CLASS="command"
>key</B
><H2
CLASS="sect2"
><A
-NAME="AEN1587"
+NAME="AEN1549"
>6.2.8. <B
CLASS="command"
>key</B
><H2
CLASS="sect2"
><A
-NAME="AEN1607"
+NAME="AEN1569"
>6.2.9. <B
CLASS="command"
>logging</B
><H2
CLASS="sect2"
><A
-NAME="AEN1647"
+NAME="AEN1609"
>6.2.10. <B
CLASS="command"
>logging</B
><H3
CLASS="sect3"
><A
-NAME="AEN1663"
+NAME="AEN1625"
>6.2.10.1. The <B
CLASS="command"
>channel</B
> Phrase</A
></H3
><P
->All log output goes to one or more <I
+>All log output goes to one or more <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>channels</I
+></SPAN
>;
you can make as many of them as you want.</P
><P
CLASS="command"
>syslog</B
> man
-page. How <B
+page. Known facilities are <B
+CLASS="command"
+>kern</B
+>, <B
+CLASS="command"
+>user</B
+>,
+<B
+CLASS="command"
+>mail</B
+>, <B
+CLASS="command"
+>daemon</B
+>, <B
+CLASS="command"
+>auth</B
+>,
+<B
+CLASS="command"
+>syslog</B
+>, <B
+CLASS="command"
+>lpr</B
+>, <B
+CLASS="command"
+>news</B
+>,
+<B
+CLASS="command"
+>uucp</B
+>, <B
+CLASS="command"
+>cron</B
+>, <B
+CLASS="command"
+>authpriv</B
+>,
+<B
+CLASS="command"
+>ftp</B
+>, <B
+CLASS="command"
+>local0</B
+>, <B
+CLASS="command"
+>local1</B
+>,
+<B
+CLASS="command"
+>local2</B
+>, <B
+CLASS="command"
+>local3</B
+>, <B
+CLASS="command"
+>local4</B
+>,
+<B
+CLASS="command"
+>local5</B
+>, <B
+CLASS="command"
+>local6</B
+> and
+<B
+CLASS="command"
+>local7</B
+>, however not all facilities are supported on
+all operating systems.
+How <B
CLASS="command"
>syslog</B
> will handle messages sent to
><DIV
CLASS="informaltable"
><A
-NAME="AEN1767"
+NAME="AEN1749"
></A
><P
></P
><P
><B
CLASS="command"
+>update-security</B
+></P
+></TD
+><TD
+WIDTH="322"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+>Approval and denial of update requests.</P
+></TD
+></TR
+><TR
+><TD
+WIDTH="110"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+><B
+CLASS="command"
>queries</B
></P
></TD
</P
></TD
></TR
+><TR
+><TD
+WIDTH="110"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+><B
+CLASS="command"
+>delegation-only</B
+></P
+></TD
+><TD
+WIDTH="322"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+>Delegation only. Logs queries that have have
+been forced to NXDOMAIN as the result of a delegation-only zone or
+a <B
+CLASS="command"
+>delegation-only</B
+> in a hint or stub zone declartation.
+</P
+></TD
+></TR
></TBODY
></TABLE
><P
><H2
CLASS="sect2"
><A
-NAME="AEN1878"
+NAME="AEN1873"
>6.2.11. <B
CLASS="command"
>lwres</B
><H2
CLASS="sect2"
><A
-NAME="AEN1902"
+NAME="AEN1897"
>6.2.12. <B
CLASS="command"
>lwres</B
><H2
CLASS="sect2"
><A
-NAME="AEN1921"
+NAME="AEN1916"
>6.2.13. <B
CLASS="command"
+>masters</B
+> Statement Grammar</A
+></H2
+><PRE
+CLASS="programlisting"
+> <B
+CLASS="command"
+>masters</B
+> <TT
+CLASS="replaceable"
+><I
+>name</I
+></TT
+> [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] { ( <TT
+CLASS="replaceable"
+><I
+>masters_list</I
+></TT
+> | <TT
+CLASS="replaceable"
+><I
+>ip_addr</I
+></TT
+> [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] [<SPAN
+CLASS="optional"
+>key <TT
+CLASS="replaceable"
+><I
+>key</I
+></TT
+></SPAN
+>] ) ; [<SPAN
+CLASS="optional"
+>...</SPAN
+>] } ;
+</PRE
+></DIV
+><DIV
+CLASS="sect2"
+><H2
+CLASS="sect2"
+><A
+NAME="AEN1931"
+>6.2.14. <B
+CLASS="command"
+>masters</B
+> Statement Definition and Usage</A
+></H2
+><P
+><B
+CLASS="command"
+>masters</B
+> lists allow for a common set of masters
+to be easily used by multiple stub and slave zones.</P
+></DIV
+><DIV
+CLASS="sect2"
+><H2
+CLASS="sect2"
+><A
+NAME="AEN1936"
+>6.2.15. <B
+CLASS="command"
>options</B
> Statement Grammar</A
></H2
>]
[<SPAN
CLASS="optional"
+> server-id <TT
+CLASS="replaceable"
+><I
+>server_id_string</I
+></TT
+>; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
> directory <TT
CLASS="replaceable"
><I
>]
[<SPAN
CLASS="optional"
+> flush-zones-on-shutdown <TT
+CLASS="replaceable"
+><I
+>yes_or_no</I
+></TT
+>; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
> has-old-clients <TT
CLASS="replaceable"
><I
>]
[<SPAN
CLASS="optional"
+> dual-stack-servers [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] { ( <TT
+CLASS="replaceable"
+><I
+>domain_name</I
+></TT
+> [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] | <TT
+CLASS="replaceable"
+><I
+>ip_addr</I
+></TT
+> [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] ) ; ... }; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
> check-names ( <TT
CLASS="replaceable"
><I
>]
[<SPAN
CLASS="optional"
-> listen-on [<SPAN
+> avoid-v4-udp-ports { <TT
+CLASS="replaceable"
+><I
+>port_list</I
+></TT
+> }; </SPAN
+>]
+ [<SPAN
CLASS="optional"
-> port <TT
+> avoid-v6-udp-ports { <TT
CLASS="replaceable"
><I
->ip_port</I
+>port_list</I
+></TT
+> }; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> listen-on [<SPAN
+CLASS="optional"
+> port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
></TT
> </SPAN
>] { <TT
>]
[<SPAN
CLASS="optional"
+> query-source-v6 [<SPAN
+CLASS="optional"
+> address ( <TT
+CLASS="replaceable"
+><I
+>ip_addr</I
+></TT
+> | <TT
+CLASS="replaceable"
+><I
+>*</I
+></TT
+> ) </SPAN
+>] [<SPAN
+CLASS="optional"
+> port ( <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+> | <TT
+CLASS="replaceable"
+><I
+>*</I
+></TT
+> ) </SPAN
+>]; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
> max-transfer-time-in <TT
CLASS="replaceable"
><I
>]
[<SPAN
CLASS="optional"
+> tcp-listen-queue <TT
+CLASS="replaceable"
+><I
+>number</I
+></TT
+>; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
> transfer-format <TT
CLASS="replaceable"
><I
>]
[<SPAN
CLASS="optional"
+> alt-transfer-source (<TT
+CLASS="replaceable"
+><I
+>ip4_addr</I
+></TT
+> | <TT
+CLASS="constant"
+>*</TT
+>) [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] ; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> alt-transfer-source-v6 (<TT
+CLASS="replaceable"
+><I
+>ip6_addr</I
+></TT
+> | <TT
+CLASS="constant"
+>*</TT
+>) [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] ; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> use-alt-transfer-source <TT
+CLASS="replaceable"
+><I
+>yes_or_no</I
+></TT
+>; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
> notify-source (<TT
CLASS="replaceable"
><I
>yes_or_no</I
></TT
>; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> preferred-glue ( <TT
+CLASS="replaceable"
+><I
+>A</I
+></TT
+> | <TT
+CLASS="replaceable"
+><I
+>AAAA</I
+></TT
+> | <TT
+CLASS="replaceable"
+><I
+>NONE</I
+></TT
+> ); </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> edns-udp-size <TT
+CLASS="replaceable"
+><I
+>number</I
+></TT
+>; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> root-delegation-only [<SPAN
+CLASS="optional"
+> exclude { <TT
+CLASS="replaceable"
+><I
+>namelist</I
+></TT
+> } </SPAN
+>] ; </SPAN
>]
};
</PRE
CLASS="sect2"
><A
NAME="options"
->6.2.14. <B
+>6.2.16. <B
CLASS="command"
>options</B
> Statement Definition and Usage</A
></DT
><DD
><P
+><SPAN
+CLASS="emphasis"
><I
CLASS="emphasis"
>This option is obsolete.</I
+></SPAN
>
It was used in <SPAN
CLASS="acronym"
server's current directory. The format of the file is described
in <A
HREF="Bv9ARM.ch06.html#statsfile"
->Section 6.2.14.16</A
+>Section 6.2.16.17</A
></P
></DD
><DT
the initial configuration load at server startup time and
is ignored on subsequent reloads.</P
></DD
+><DT
+><B
+CLASS="command"
+>preferred-glue</B
+></DT
+><DD
+><P
+> If specified the listed type (A or AAAA) will be emitted before other glue
+in the additional section of a query response.
+The default is not to preference any type (NONE).
+</P
+></DD
+><DT
+><B
+CLASS="command"
+>root-delegation-only</B
+></DT
+><DD
+><P
+> Turn on enforcment of delegation-only in TLDs and root zones with an optional
+exclude list.
+</P
+><P
+> Note some TLDs are NOT delegation only (e.g. "DE", "LV", "US" and "MUSEUM").
+</P
+><PRE
+CLASS="programlisting"
+> options {
+ root-delegation-only exclude { "de"; "lv"; "us"; "museum"; };
+};
+</PRE
+></DD
></DL
></DIV
><DIV
CLASS="sect3"
><A
NAME="boolean_options"
->6.2.14.1. Boolean Options</A
+>6.2.16.1. Boolean Options</A
></H3
><P
></P
>notify</B
> and <B
CLASS="command"
->notify-also</B
+>also-notify</B
>.</P
><P
>If the
><DIV
CLASS="informaltable"
><A
-NAME="AEN2280"
+NAME="AEN2354"
></A
><P
></P
><DT
><B
CLASS="command"
+>flush-zones-on-shutdown</B
+></DT
+><DD
+><P
+>When the nameserver exits due receiving SIGTERM,
+flush / do not flush any pending zone writes. The default is
+<B
+CLASS="command"
+>flush-zones-on-shutdown</B
+> <TT
+CLASS="userinput"
+><B
+>no</B
+></TT
+>.
+</P
+></DD
+><DT
+><B
+CLASS="command"
>has-old-clients</B
></DT
><DD
></DT
><DD
><P
+><SPAN
+CLASS="emphasis"
><I
CLASS="emphasis"
>This option is obsolete</I
+></SPAN
>.
It was used in <SPAN
CLASS="acronym"
></DT
><DD
><P
+><SPAN
+CLASS="emphasis"
><I
CLASS="emphasis"
>This option is obsolete</I
+></SPAN
>.
<SPAN
CLASS="acronym"
>statistics-file</B
>. See also <A
HREF="Bv9ARM.ch06.html#statsfile"
->Section 6.2.14.16</A
+>Section 6.2.16.17</A
>.
</P
></DD
></DT
><DD
><P
+><SPAN
+CLASS="emphasis"
><I
CLASS="emphasis"
>This option is obsolete</I
+></SPAN
>.
If you need to disable IXFR to a particular server or servers see
the information on the <B
> option
in <A
HREF="Bv9ARM.ch06.html#server_statement_definition_and_usage"
->Section 6.2.16</A
+>Section 6.2.18</A
>. See also
<A
HREF="Bv9ARM.ch04.html#incremental_zone_transfers"
> in
<A
HREF="Bv9ARM.ch06.html#server_statement_definition_and_usage"
->Section 6.2.16</A
+>Section 6.2.18</A
>
</P
></DD
> in
<A
HREF="Bv9ARM.ch06.html#server_statement_definition_and_usage"
->Section 6.2.16</A
+>Section 6.2.18</A
>
</P
></DD
CLASS="literal"
>MX 10 mail.example.net</TT
>", normally the address
-records (A, A6, and AAAA) for <TT
+records (A and AAAA) for <TT
CLASS="literal"
>mail.example.net</TT
> will be provided as well,
difference set.
</P
></DD
+><DT
+><B
+CLASS="command"
+>multi-master</B
+></DT
+><DD
+><P
+> This should be set when you have multiple masters for a zone and the
+addresses refer to different machines. If 'yes' named will not log
+when the serial number on the master is less than what named currently
+has. The default is <TT
+CLASS="userinput"
+><B
+>no</B
+></TT
+>.
+</P
+></DD
></DL
></DIV
></DIV
><H3
CLASS="sect3"
><A
-NAME="AEN2532"
->6.2.14.2. Forwarding</A
+NAME="AEN2619"
+>6.2.16.2. Forwarding</A
></H3
><P
>The forwarding facility can be used to create a large site-wide
> behavior,
or not forward at all, see <A
HREF="Bv9ARM.ch06.html#zone_statement_grammar"
->Section 6.2.21</A
+>Section 6.2.23</A
>.</P
></DIV
><DIV
><H3
CLASS="sect3"
><A
+NAME="AEN2638"
+>6.2.16.3. 6 to 4 Servers</A
+></H3
+><P
+>6 to 4 servers are used as servers of last resort to work around
+problems in reachability due the lack of support for either IPv4 or IPv6
+on the host machine.</P
+><P
+></P
+><DIV
+CLASS="variablelist"
+><DL
+><DT
+><B
+CLASS="command"
+>dual-stack-servers</B
+></DT
+><DD
+><P
+>Specifies host names / addresses of machines with access to
+both IPv4 and IPv6 transports. If a hostname is used the server must be able
+to resolve the name using only the transport it has. If the machine is dual
+stacked then the <B
+CLASS="command"
+>dual-stack-servers</B
+> have no effect unless
+access to a transport has been disabled on the command line
+(e.g. <B
+CLASS="command"
+>named -4</B
+>).</P
+></DD
+></DL
+></DIV
+></DIV
+><DIV
+CLASS="sect3"
+><H3
+CLASS="sect3"
+><A
NAME="access_control"
->6.2.14.3. Access Control</A
+>6.2.16.4. Access Control</A
></H3
><P
>Access to the server can be restricted based on the IP address
></DT
><DD
><P
->Specifies which hosts are to receive
-synthetic responses to IPv6 queries as described in
-<A
-HREF="Bv9ARM.ch06.html#synthesis"
->Section 6.2.14.13</A
->.
+>This option was introduced for the smooth transition from AAAA
+to A6 and from "nibble labels" to binary labels.
+However, since both A6 and binary labels were then deprecated,
+this option was also deprecated.
+It is now ignored with some warning messages.
</P
></DD
><DT
CLASS="command"
>options allow-transfer</B
> statement.
-If not specified, the default is to allow transfers from all hosts.</P
+If not specified, the default is to allow transfers to all hosts.</P
></DD
><DT
><B
><H3
CLASS="sect3"
><A
-NAME="AEN2608"
->6.2.14.4. Interfaces</A
+NAME="AEN2705"
+>6.2.16.5. Interfaces</A
></H3
><P
>The interfaces and ports that the server will answer queries
> is specified, the
server will listen on port 53 on all interfaces.</P
><P
->The <B
-CLASS="command"
->listen-on-v6</B
-> option is used to
-specify the ports on which the server will listen for incoming
-queries sent using IPv6.</P
-><P
->The server does not bind a separate socket to each IPv6
-interface address as it does for IPv4. Instead, it always
-listens on the IPv6 wildcard address. Therefore, the only
-values allowed for the <TT
-CLASS="varname"
->address_match_list</TT
->
-argument to the <B
-CLASS="command"
->listen-on-v6</B
-> statement are
-<PRE
-CLASS="programlisting"
->{ any; }</PRE
-> and
-<PRE
-CLASS="programlisting"
->{ none;}</PRE
-></P
+>By default, the server does not bind a separate socket to each
+IPv6 interface address as it does for IPv4. Instead, it listens on the
+IPv6 wildcard address.
+Alternatively, a list of IPv6 addresses can be specified, in which case
+the server listens on a separate socket for each specified address.</P
><P
>Multiple <B
CLASS="command"
>listen-on-v6</B
-> options can be
-used to listen on multiple ports:</P
+> options can be used.
+For example,</P
><PRE
CLASS="programlisting"
->listen-on-v6 port 53 { any; };
-listen-on-v6 port 1234 { any; };
+>listen-on-v6 { any; };
+listen-on-v6 port 1234 { !3ffe::/16; any; };
</PRE
><P
+>will enable the name server on port 53 for any IPv6 addresses
+(with a single wildcard socket),
+and on port 1234 of IPv6 addresses that is not in the prefix
+3ffe::/16 (with separate sockets for each matched address.)</P
+><P
>To make the server not listen on any IPv6 address, use</P
><PRE
CLASS="programlisting"
><H3
CLASS="sect3"
><A
-NAME="AEN2634"
->6.2.14.5. Query Address</A
+NAME="AEN2726"
+>6.2.16.6. Query Address</A
></H3
><P
>If the server doesn't know the answer to a question, it will
CLASS="command"
>*</B
> or is omitted,
-a random unprivileged port will be used. The defaults are</P
+a random unprivileged port will be used, <B
+CLASS="command"
+>avoid-v4-udp-ports</B
+>
+and <B
+CLASS="command"
+>avoid-v6-udp-ports</B
+> can be used to prevent named
+from selecting certian ports. The defaults are</P
><PRE
CLASS="programlisting"
>query-source address * port *;
-query-source-v6 address * port *
+query-source-v6 address * port *;
</PRE
><DIV
CLASS="note"
CLASS="sect3"
><A
NAME="zone_transfers"
->6.2.14.6. Zone Transfers</A
+>6.2.16.7. Zone Transfers</A
></H3
><P
><SPAN
><DT
><B
CLASS="command"
+>alt-transfer-source</B
+></DT
+><DD
+><P
+>An alternate transfer source if the one listed in
+<B
+CLASS="command"
+>transfer-source</B
+> fails and
+<B
+CLASS="command"
+>use-alt-transfer-source</B
+> is set.</P
+></DD
+><DT
+><B
+CLASS="command"
+>alt-transfer-source-v6</B
+></DT
+><DD
+><P
+>An alternate transfer source if the one listed in
+<B
+CLASS="command"
+>transfer-source-v6</B
+> fails and
+<B
+CLASS="command"
+>use-alt-transfer-source</B
+> is set.</P
+></DD
+><DT
+><B
+CLASS="command"
+>use-alt-transfer-source</B
+></DT
+><DD
+><P
+>Use the alternate transfer sources or not. If views are
+specified this defaults to <B
+CLASS="command"
+>no</B
+> otherwise it defaults to
+<B
+CLASS="command"
+>yes</B
+> (for BIND 8 compatibility).</P
+></DD
+><DT
+><B
+CLASS="command"
>notify-source</B
></DT
><DD
><H3
CLASS="sect3"
><A
-NAME="AEN2773"
->6.2.14.7. Operating System Resource Limits</A
+NAME="AEN2888"
+>6.2.16.8. Bad UDP Port Lists</A
+></H3
+><P
+> <B
+CLASS="command"
+>avoid-v4-udp-ports</B
+> and <B
+CLASS="command"
+>avoid-v6-udp-ports</B
+>
+specify a list of IPv4 and IPv6 UDP ports that will not be used as system
+assigned source ports for UDP sockets. These lists are expected to be
+used to prevent named using "well known" ports in the system assigned range
+that have become unusable due to wide spread use of acls containing these
+ports.
+</P
+></DIV
+><DIV
+CLASS="sect3"
+><H3
+CLASS="sect3"
+><A
+NAME="AEN2893"
+>6.2.16.9. Operating System Resource Limits</A
></H3
><P
>The server's usage of many system resources can be limited.
><H3
CLASS="sect3"
><A
-NAME="AEN2810"
->6.2.14.8. Server Resource Limits</A
+NAME="AEN2930"
+>6.2.16.10. Server Resource Limits</A
></H3
><P
>The following options set limits on the server's
records are purged from the cache only when their TTLs expire.
</P
></DD
+><DT
+><B
+CLASS="command"
+>tcp-listen-queue</B
+></DT
+><DD
+><P
+>The listen queue depth. The default and minimum is 3.
+If the kernel supports the accept filter "dataready" this also controls how
+many TCP connections that will be queued in kernel space waiting for
+some data before being passed to accept. Values less than 3 will be
+silently raised.
+</P
+></DD
></DL
></DIV
></DIV
><H3
CLASS="sect3"
><A
-NAME="AEN2846"
->6.2.14.9. Periodic Task Intervals</A
+NAME="AEN2971"
+>6.2.16.11. Periodic Task Intervals</A
></H3
><P
></P
CLASS="sect3"
><A
NAME="topology"
->6.2.14.10. Topology</A
+>6.2.16.12. Topology</A
></H3
><P
>All other things being equal, when the server chooses a name server
CLASS="sect3"
><A
NAME="the_sortlist_statement"
->6.2.14.11. The <B
+>6.2.16.13. The <B
CLASS="command"
>sortlist</B
> Statement</A
>
statement in <A
HREF="Bv9ARM.ch06.html#rrset_ordering"
->Section 6.2.14.12</A
+>Section 6.2.16.14</A
>).
The client resolver code should rearrange the RRs as appropriate,
that is, using any addresses on the local net in preference to other addresses.
> statement
does (<A
HREF="Bv9ARM.ch06.html#topology"
->Section 6.2.14.10</A
+>Section 6.2.16.12</A
>).
Each top level statement in the <B
CLASS="command"
CLASS="sect3"
><A
NAME="rrset_ordering"
->6.2.14.12. RRset Ordering</A
+>6.2.16.14. RRset Ordering</A
></H3
><P
>When multiple records are returned in an answer it may be
> statement,
<A
HREF="Bv9ARM.ch06.html#the_sortlist_statement"
->Section 6.2.14.11</A
+>Section 6.2.16.13</A
>.
</P
><P
><DIV
CLASS="informaltable"
><A
-NAME="AEN2934"
+NAME="AEN3059"
></A
><P
></P
CLASS="command"
>rrset-order</B
> statement
-is not yet implemented in <SPAN
+is not yet fully implemented in <SPAN
CLASS="acronym"
>BIND</SPAN
> 9.
-BIND 9 currently supports only a "random-cyclic" ordering,
-where the server randomly chooses a starting point within
-the RRset and returns the records in order starting at
-that point, wrapping around the end of the RRset if
-necessary.</P
-></BLOCKQUOTE
-></DIV
-></DIV
-><DIV
-CLASS="sect3"
-><H3
-CLASS="sect3"
-><A
-NAME="synthesis"
->6.2.14.13. Synthetic IPv6 responses</A
-></H3
-><P
->Many existing stub resolvers support IPv6 DNS lookups as defined in
-RFC1886, using AAAA records for forward lookups and "nibble labels" in
-the <TT
-CLASS="literal"
->ip6.int</TT
-> domain for reverse lookups, but do not support
-RFC2874-style lookups (using A6 records and binary labels in the
-<TT
-CLASS="literal"
->ip6.arpa</TT
-> domain).</P
-><P
->For those who wish to continue to use such stub resolvers rather than
-switching to the BIND 9 lightweight resolver, BIND 9 provides a way
-to automatically convert RFC1886-style lookups into
-RFC2874-style lookups and return the results as "synthetic" AAAA and
-PTR records.</P
-><P
->This feature is disabled by default and can be enabled on a per-client
-basis by adding a
-<B
-CLASS="command"
->allow-v6-synthesis { <TT
-CLASS="replaceable"
-><I
->address_match_list</I
-></TT
-> }</B
->
-clause to the <B
-CLASS="command"
->options</B
-> or <B
-CLASS="command"
->view</B
-> statement.
- When it is enabled, recursive
-AAAA queries cause the server to first try an A6 lookup and if that
-fails, an AAAA lookups. No matter which one succeeds, the results are
-returned as a set of synthetic AAAA records. Similarly, recursive PTR
-queries in <TT
-CLASS="literal"
->ip6.int</TT
-> will cause a
-lookup in <TT
-CLASS="literal"
->ip6.arpa</TT
-> using binary
-labels, and if that fails, another lookup in <TT
-CLASS="literal"
->ip6.int</TT
->.
-The results are returned as a synthetic PTR record in
-<TT
-CLASS="literal"
->ip6.int</TT
->.</P
-><P
->The synthetic records have a TTL of zero. DNSSEC validation of
-synthetic responses is not currently supported; therefore responses
-containing synthetic RRs will not have the AD flag set.</P
-><DIV
-CLASS="note"
-><BLOCKQUOTE
-CLASS="note"
-><P
-><B
->Note: </B
-><B
-CLASS="command"
->allow-v6-synthesis</B
-> is only performed for
-clients that are supplied recursive service.</P
+BIND 9 currently does not support "fixed" ordering.
+</P
></BLOCKQUOTE
></DIV
></DIV
CLASS="sect3"
><A
NAME="tuning"
->6.2.14.14. Tuning</A
+>6.2.16.15. Tuning</A
></H3
><P
></P
><P
>Sets the number of seconds to cache a
lame server indication. 0 disables caching. (This is
-<I
+<SPAN
+CLASS="bold"
+><B
CLASS="emphasis"
->NOT</I
+>NOT</B
+></SPAN
> recommended.)
Default is <TT
CLASS="literal"
><P
> These options allow the administrator to set a minimum and maximum
refresh and retry time either per-zone, per-view, or globally.
-These options are valid for master, slave and stub zones,
+These options are valid for slave and stub zones,
and clamp the SOA refresh and retry times to the specified values.
</P
></DD
+><DT
+><B
+CLASS="command"
+>edns-udp-size</B
+></DT
+><DD
+><P
+> <B
+CLASS="command"
+>edns-udp-size</B
+> sets the advertised EDNS UDP buffer
+size. Valid values are 512 to 4096 (values outside this range will be
+silently adjusted). The default value is 4096. The usual reason for
+setting edns-udp-size to a non default value it to get UDP answers to
+pass through broken firewalls that block fragmented packets and/or
+block UDP packets that are greater than 512 bytes.
+</P
+></DD
></DL
></DIV
></DIV
CLASS="sect3"
><A
NAME="builtin"
->6.2.14.15. Built-in server information zones</A
+>6.2.16.16. Built-in server information zones</A
></H3
><P
>The server provides some helpful diagnostic information
> class. These zones are part of a
built-in view (see <A
HREF="Bv9ARM.ch06.html#view_statement_grammar"
->Section 6.2.19</A
+>Section 6.2.21</A
>) of class
<B
CLASS="command"
identify which of a group of anycast servers is actually
answering your queries. Specifying <B
CLASS="command"
->hostname none</B
+>hostname none;</B
>
disables processing of the queries.</P
></DD
+><DT
+><B
+CLASS="command"
+>server-id</B
+></DT
+><DD
+><P
+>The ID of the server should report via a query of
+the name <TT
+CLASS="filename"
+>ID.SERVER</TT
+>
+with type <B
+CLASS="command"
+>TXT</B
+>, class <B
+CLASS="command"
+>CHAOS</B
+>.
+The primary purpose of such queries is to
+identify which of a group of anycast servers is actually
+answering your queries. Specifying <B
+CLASS="command"
+>server-id none;</B
+>
+disables processing of the queries.
+Specifying <B
+CLASS="command"
+>server-id hostname;</B
+> will cause named to
+use the hostname as found by gethostname().
+The default <B
+CLASS="command"
+>server-id</B
+> is <B
+CLASS="command"
+>none</B
+>.
+</P
+></DD
></DL
></DIV
></DIV
CLASS="sect3"
><A
NAME="statsfile"
->6.2.14.16. The Statistics File</A
+>6.2.16.17. The Statistics File</A
></H3
><P
>The statistics file generated by <SPAN
><DIV
CLASS="informaltable"
><A
-NAME="AEN3079"
+NAME="AEN3203"
></A
><P
></P
CLASS="sect2"
><A
NAME="server_statement_grammar"
->6.2.15. <B
+>6.2.17. <B
CLASS="command"
>server</B
> Statement Grammar</A
>] }</I
></TT
> ; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> transfer-source (<TT
+CLASS="replaceable"
+><I
+>ip4_addr</I
+></TT
+> | <TT
+CLASS="constant"
+>*</TT
+>) [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] ; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> transfer-source-v6 (<TT
+CLASS="replaceable"
+><I
+>ip6_addr</I
+></TT
+> | <TT
+CLASS="constant"
+>*</TT
+>) [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] ; </SPAN
>]
};
</PRE
CLASS="sect2"
><A
NAME="server_statement_definition_and_usage"
->6.2.16. <B
+>6.2.18. <B
CLASS="command"
>server</B
> Statement Definition and Usage</A
> clause
allows for multiple keys, only a single key per server is currently
supported.</P
+><P
+>The <B
+CLASS="command"
+>transfer-source</B
+> and
+<B
+CLASS="command"
+>transfer-source-v6</B
+> clauses specify the IPv4 and IPv6 source
+address to be used for zone transfer with the remote server, respectively.
+For an IPv4 remote server, only <B
+CLASS="command"
+>transfer-source</B
+> can
+be specified.
+Similarly, for an IPv6 remote server, only
+<B
+CLASS="command"
+>transfer-source-v6</B
+> can be specified.
+Form more details, see the description of
+<B
+CLASS="command"
+>transfer-source</B
+> and
+<B
+CLASS="command"
+>transfer-source-v6</B
+> in
+<A
+HREF="Bv9ARM.ch06.html#zone_transfers"
+>Section 6.2.16.7</A
+>.</P
></DIV
><DIV
CLASS="sect2"
><H2
CLASS="sect2"
><A
-NAME="AEN3200"
->6.2.17. <B
+NAME="AEN3342"
+>6.2.19. <B
CLASS="command"
>trusted-keys</B
> Statement Grammar</A
><H2
CLASS="sect2"
><A
-NAME="AEN3216"
->6.2.18. <B
+NAME="AEN3358"
+>6.2.20. <B
CLASS="command"
>trusted-keys</B
> Statement Definition
CLASS="sect2"
><A
NAME="view_statement_grammar"
->6.2.19. <B
+>6.2.21. <B
CLASS="command"
>view</B
> Statement Grammar</A
>address_match_list</I
></TT
> } ;
- match-recursive-only { <TT
+ match-recursive-only <TT
CLASS="replaceable"
><I
>yes_or_no</I
></TT
-> } ;
+> ;
[<SPAN
CLASS="optional"
> <TT
><H2
CLASS="sect2"
><A
-NAME="AEN3238"
->6.2.20. <B
+NAME="AEN3380"
+>6.2.22. <B
CLASS="command"
>view</B
> Statement Definition and Usage</A
CLASS="sect2"
><A
NAME="zone_statement_grammar"
->6.2.21. <B
+>6.2.23. <B
CLASS="command"
>zone</B
>
>] [<SPAN
CLASS="optional"
>{
- type ( master | slave | hint | stub | forward ) ;
+ type ( master | slave | hint | stub | forward | delegation-only ) ;
[<SPAN
CLASS="optional"
> allow-notify { <TT
>]
[<SPAN
CLASS="optional"
-> dialup <TT
+> dialup <TT
+CLASS="replaceable"
+><I
+>dialup_option</I
+></TT
+> ; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> delegation-only <TT
CLASS="replaceable"
><I
->dialup_option</I
+>yes_or_no</I
></TT
> ; </SPAN
>]
>ip_port</I
></TT
></SPAN
->] { <TT
+>] { ( <TT
+CLASS="replaceable"
+><I
+>masters_list</I
+></TT
+> | <TT
CLASS="replaceable"
><I
>ip_addr</I
>key</I
></TT
></SPAN
->]; [<SPAN
+>] ) ; [<SPAN
CLASS="optional"
>...</SPAN
>] } ; </SPAN
>]
[<SPAN
CLASS="optional"
+> alt-transfer-source (<TT
+CLASS="replaceable"
+><I
+>ip4_addr</I
+></TT
+> | <TT
+CLASS="constant"
+>*</TT
+>) [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] ; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> alt-transfer-source-v6 (<TT
+CLASS="replaceable"
+><I
+>ip6_addr</I
+></TT
+> | <TT
+CLASS="constant"
+>*</TT
+>) [<SPAN
+CLASS="optional"
+>port <TT
+CLASS="replaceable"
+><I
+>ip_port</I
+></TT
+></SPAN
+>] ; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
+> use-alt-transfer-source <TT
+CLASS="replaceable"
+><I
+>yes_or_no</I
+></TT
+>; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
> notify-source (<TT
CLASS="replaceable"
><I
>]
[<SPAN
CLASS="optional"
+> multi-master <TT
+CLASS="replaceable"
+><I
+>yes_or_no</I
+></TT
+> ; </SPAN
+>]
+ [<SPAN
+CLASS="optional"
> key-directory <TT
CLASS="replaceable"
><I
><H2
CLASS="sect2"
><A
-NAME="AEN3395"
->6.2.22. <B
+NAME="AEN3554"
+>6.2.24. <B
CLASS="command"
>zone</B
> Statement Definition and Usage</A
><H3
CLASS="sect3"
><A
-NAME="AEN3398"
->6.2.22.1. Zone Types</A
+NAME="AEN3557"
+>6.2.24.1. Zone Types</A
></H3
><DIV
CLASS="informaltable"
><A
-NAME="AEN3400"
+NAME="AEN3559"
></A
><P
></P
>masters</B
> list specifies one or more IP addresses
of master servers that the slave contacts to update its copy of the zone.
+Masters list elements can also be names of other masters lists.
By default, transfers are made from port 53 on the servers; this can
be changed for all servers by specifying a port number before the
list of IP addresses, or on a per-server basis after the IP address.
Classes other than IN have no built-in defaults hints.</P
></TD
></TR
+><TR
+><TD
+WIDTH="87"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+><TT
+CLASS="varname"
+>delegation-only</TT
+></P
+></TD
+><TD
+WIDTH="405"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+>This is used to enforce the delegation only
+status of infrastructure zones (e.g. COM, NET, ORG). Any answer that
+is received without a explicit or implict delegation in the authority
+section will be treated as NXDOMAIN. This does not apply to the zone
+apex. This SHOULD NOT be applied to leaf zones.</P
+>
+<P
+><TT
+CLASS="varname"
+>delegation-only</TT
+> has no effect on answers received
+from forwarders.</P
+></TD
+></TR
></TBODY
></TABLE
><P
><H3
CLASS="sect3"
><A
-NAME="AEN3455"
->6.2.22.2. Class</A
+NAME="AEN3622"
+>6.2.24.2. Class</A
></H3
><P
>The zone's name may optionally be followed by a class. If
><H3
CLASS="sect3"
><A
-NAME="AEN3465"
->6.2.22.3. Zone Options</A
+NAME="AEN3632"
+>6.2.24.3. Zone Options</A
></H3
><P
></P
>allow-notify</B
> in <A
HREF="Bv9ARM.ch06.html#access_control"
->Section 6.2.14.3</A
+>Section 6.2.16.4</A
></P
></DD
><DT
>allow-query</B
> in <A
HREF="Bv9ARM.ch06.html#access_control"
->Section 6.2.14.3</A
+>Section 6.2.16.4</A
></P
></DD
><DT
>
in <A
HREF="Bv9ARM.ch06.html#access_control"
->Section 6.2.14.3</A
+>Section 6.2.16.4</A
>.</P
></DD
><DT
>Specifies a "Simple Secure Update" policy. See
<A
HREF="Bv9ARM.ch06.html#dynamic_update_policies"
->Section 6.2.22.4</A
+>Section 6.2.24.4</A
>.</P
></DD
><DT
>
in <A
HREF="Bv9ARM.ch06.html#access_control"
->Section 6.2.14.3</A
+>Section 6.2.16.4</A
>.</P
></DD
><DT
>dialup</B
> in <A
HREF="Bv9ARM.ch06.html#boolean_options"
->Section 6.2.14.1</A
+>Section 6.2.16.1</A
>.</P
></DD
><DT
><B
CLASS="command"
+>delegation-only</B
+></DT
+><DD
+><P
+>The flag only applies to hint and stub zones. If set
+to <TT
+CLASS="userinput"
+><B
+>yes</B
+></TT
+> then the zone will also be treated as if it
+is also a delegation-only type zone.
+</P
+></DD
+><DT
+><B
+CLASS="command"
>forward</B
></DT
><DD
>max-transfer-time-in</B
> in <A
HREF="Bv9ARM.ch06.html#zone_transfers"
->Section 6.2.14.6</A
+>Section 6.2.16.7</A
>.</P
></DD
><DT
>max-transfer-idle-in</B
> in <A
HREF="Bv9ARM.ch06.html#zone_transfers"
->Section 6.2.14.6</A
+>Section 6.2.16.7</A
>.</P
></DD
><DT
>max-transfer-time-out</B
> in <A
HREF="Bv9ARM.ch06.html#zone_transfers"
->Section 6.2.14.6</A
+>Section 6.2.16.7</A
>.</P
></DD
><DT
>max-transfer-idle-out</B
> in <A
HREF="Bv9ARM.ch06.html#zone_transfers"
->Section 6.2.14.6</A
+>Section 6.2.16.7</A
>.</P
></DD
><DT
>notify</B
> in <A
HREF="Bv9ARM.ch06.html#boolean_options"
->Section 6.2.14.1</A
+>Section 6.2.16.1</A
>.</P
></DD
><DT
>sig-validity-interval</B
> in <A
HREF="Bv9ARM.ch06.html#tuning"
->Section 6.2.14.14</A
+>Section 6.2.16.15</A
>.</P
></DD
><DT
>transfer-source</B
> in <A
HREF="Bv9ARM.ch06.html#zone_transfers"
->Section 6.2.14.6</A
+>Section 6.2.16.7</A
>
</P
></DD
>transfer-source-v6</B
> in <A
HREF="Bv9ARM.ch06.html#zone_transfers"
->Section 6.2.14.6</A
+>Section 6.2.16.7</A
+>
+</P
+></DD
+><DT
+><B
+CLASS="command"
+>alt-transfer-source</B
+></DT
+><DD
+><P
+>See the description of
+<B
+CLASS="command"
+>alt-transfer-source</B
+> in <A
+HREF="Bv9ARM.ch06.html#zone_transfers"
+>Section 6.2.16.7</A
+>
+</P
+></DD
+><DT
+><B
+CLASS="command"
+>alt-transfer-source-v6</B
+></DT
+><DD
+><P
+>See the description of
+<B
+CLASS="command"
+>alt-transfer-source-v6</B
+> in <A
+HREF="Bv9ARM.ch06.html#zone_transfers"
+>Section 6.2.16.7</A
+>
+</P
+></DD
+><DT
+><B
+CLASS="command"
+>use-alt-transfer-source</B
+></DT
+><DD
+><P
+>See the description of
+<B
+CLASS="command"
+>use-alt-transfer-source</B
+> in <A
+HREF="Bv9ARM.ch06.html#zone_transfers"
+>Section 6.2.16.7</A
>
</P
></DD
>notify-source</B
> in <A
HREF="Bv9ARM.ch06.html#zone_transfers"
->Section 6.2.14.6</A
+>Section 6.2.16.7</A
>
</P
></DD
>notify-source-v6</B
> in <A
HREF="Bv9ARM.ch06.html#zone_transfers"
->Section 6.2.14.6</A
+>Section 6.2.16.7</A
>.
</P
></DD
><P
> See the description in <A
HREF="Bv9ARM.ch06.html#tuning"
->Section 6.2.14.14</A
+>Section 6.2.16.15</A
>.
</P
></DD
>ixfr-from-differences</B
> in <A
HREF="Bv9ARM.ch06.html#boolean_options"
->Section 6.2.14.1</A
+>Section 6.2.16.1</A
>.</P
></DD
><DT
>key-directory</B
> in <A
HREF="Bv9ARM.ch06.html#options"
->Section 6.2.14</A
+>Section 6.2.16</A
></P
></DD
+><DT
+><B
+CLASS="command"
+>multi-master</B
+></DT
+><DD
+><P
+>See the description of
+<B
+CLASS="command"
+>multi-master</B
+> in <A
+HREF="Bv9ARM.ch06.html#boolean_options"
+>Section 6.2.16.1</A
+>.</P
+></DD
></DL
></DIV
></DIV
CLASS="sect3"
><A
NAME="dynamic_update_policies"
->6.2.22.4. Dynamic Update Policies</A
+>6.2.24.4. Dynamic Update Policies</A
></H3
><P
><SPAN
><DIV
CLASS="informaltable"
><A
-NAME="AEN3714"
+NAME="AEN3915"
></A
><P
></P
><H1
CLASS="sect1"
><A
-NAME="AEN3755"
+NAME="AEN3956"
>6.3. Zone File</A
></H1
><DIV
><H3
CLASS="sect3"
><A
-NAME="AEN3760"
+NAME="AEN3961"
>6.3.1.1. Resource Records</A
></H3
><P
permitted for optimization purposes, for example, to specify
that a particular nearby server be tried first. See <A
HREF="Bv9ARM.ch06.html#the_sortlist_statement"
->Section 6.2.14.11</A
+>Section 6.2.16.13</A
> and <A
HREF="Bv9ARM.ch06.html#rrset_ordering"
->Section 6.2.14.12</A
+>Section 6.2.16.14</A
>.</P
><P
>The components of a Resource Record are:</P
><DIV
CLASS="informaltable"
><A
-NAME="AEN3766"
+NAME="AEN3967"
></A
><P
></P
></P
></DIV
><P
->The following are <I
+>The following are <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>types</I
+></SPAN
> of valid RRs:</P
><DIV
CLASS="informaltable"
><A
-NAME="AEN3798"
+NAME="AEN3999"
></A
><P
></P
VALIGN="MIDDLE"
><P
>a host address. In the IN class, this is a
-32-bit IP address.</P
+32-bit IP address. Described in RFC 1035.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->A6</P
+>AAAA</P
></TD
><TD
WIDTH="348"
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->an IPv6 address. This can be a partial
-address (a suffix) and an indirection to the name where the rest of the
-address (the prefix) can be found.</P
+>IPv6 address. Described in RFC 1886.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->AAAA</P
+>A6</P
></TD
><TD
WIDTH="348"
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->obsolete format of IPv6 address</P
+>IPv6 address. This can be a partial
+address (a suffix) and an indirection to the name where the rest of the
+address (the prefix) can be found. Experimental. Described in RFC 2874.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>location of AFS database servers.
-Experimental.</P
+Experimental. Described in RFC 1183.</P
+></TD
+></TR
+><TR
+><TD
+WIDTH="84"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+>APL</P
+></TD
+><TD
+WIDTH="348"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+>address prefix list. Experimental.
+Described in RFC 3123.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->holds a digital certificate.</P
+>holds a digital certificate.
+Described in RFC 2538.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->identifies the canonical name of an alias.</P
+>identifies the canonical name of an alias.
+Described in RFC 1035.</P
></TD
></TR
><TR
>Replaces the domain name specified with
another name to be looked up, effectively aliasing an entire
subtree of the domain name space rather than a single record
-as in the case of the CNAME RR. Used for delegation
-of IPv6 reverse mappings. Described in RFC 2672.</P
+as in the case of the CNAME RR.
+Described in RFC 2672.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->Specifies the global position. Superseded by LOC.</P
+>Specifies the global position. Superseded by LOC.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->identifies the CPU and OS used by a host.</P
+>identifies the CPU and OS used by a host.
+Described in RFC 1035.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>representation of ISDN addresses.
-Experimental.</P
+Experimental. Described in RFC 1183.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>stores a public key associated with a
-DNS name.</P
+DNS name. Described in RFC 2535.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>identifies a key exchanger for this
-DNS name.</P
+DNS name. Described in RFC 2230.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->for storing GPS info. See RFC 1876.
+>for storing GPS info. Described in RFC 1876.
Experimental.</P
></TD
></TR
>identifies a mail exchange for the domain.
a 16 bit preference value (lower is better)
followed by the host name of the mail exchange.
- See RFC 974 for details.</P
+Described in RFC 974, RFC 1035.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->name authority pointer.</P
+>name authority pointer. Described in RFC 2915.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->a network service access point.</P
+>a network service access point.
+Described in RFC 1706.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>the authoritative name server for the
-domain.</P
+domain. Described in RFC 1035.</P
></TD
></TR
><TR
>used in DNSSEC to securely indicate that
RRs with an owner name in a certain name interval do not exist in
a zone and indicate what RR types are present for an existing name.
-See RFC 2535 for details.</P
+Described in RFC 2535.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>a pointer to another part of the domain
-name space.</P
+name space. Described in RFC 1035.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>provides mappings between RFC 822 and X.400
-addresses.</P
+addresses. Described in RFC 2163.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>information on persons responsible
-for the domain. Experimental.</P
+for the domain. Experimental. Described in RFC 1183.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>route-through binding for hosts that
-do not have their own direct wide area network addresses. Experimental.</P
+do not have their own direct wide area network addresses.
+Experimental. Described in RFC 1183.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>("signature") contains data authenticated
-in the secure DNS. See RFC 2535 for details.</P
+in the secure DNS. Described in RFC 2535.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->identifies the start of a zone of authority.</P
+>identifies the start of a zone of authority.
+Described in RFC 1035.</P
></TD
></TR
><TR
VALIGN="MIDDLE"
><P
>information about well known network
-services (replaces WKS).</P
+services (replaces WKS). Described in RFC 2782.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->text records.</P
+>text records. Described in RFC 1035.</P
></TD
></TR
><TR
ALIGN="LEFT"
VALIGN="MIDDLE"
><P
->representation of X.25 network addresses. Experimental.</P
+>representation of X.25 network addresses.
+Experimental. Described in RFC 1183.</P
></TD
></TR
></TBODY
></P
></DIV
><P
->The following <I
+>The following <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>classes</I
+></SPAN
> of resource records
are currently valid in the DNS:</P
><DIV
CLASS="informaltable"
><A
-NAME="AEN3945"
+NAME="AEN4151"
></A
><P
></P
><H3
CLASS="sect3"
><A
-NAME="AEN3969"
+NAME="AEN4175"
>6.3.1.2. Textual expression of RRs</A
></H3
><P
><DIV
CLASS="informaltable"
><A
-NAME="AEN3976"
+NAME="AEN4182"
></A
><P
></P
><DIV
CLASS="informaltable"
><A
-NAME="AEN4042"
+NAME="AEN4248"
></A
><P
></P
><H2
CLASS="sect2"
><A
-NAME="AEN4070"
+NAME="AEN4276"
>6.3.2. Discussion of MX Records</A
></H2
><P
the mail transport agent will fall back to the next largest priority.
Priority numbers do not have any absolute meaning — they are relevant
only respective to other MX records for that domain name. The domain
-name given is the machine to which the mail will be delivered. It <I
+name given is the machine to which the mail will be delivered. It <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>must</I
+></SPAN
> have
an associated A record — CNAME is not sufficient.</P
><P
><DIV
CLASS="informaltable"
><A
-NAME="AEN4076"
+NAME="AEN4282"
></A
><P
></P
><DIV
CLASS="informaltable"
><A
-NAME="AEN4168"
+NAME="AEN4374"
></A
><P
></P
><H2
CLASS="sect2"
><A
-NAME="AEN4191"
+NAME="AEN4397"
>6.3.4. Inverse Mapping in IPv4</A
></H2
><P
>Reverse name resolution (that is, translation from IP address
-to name) is achieved by means of the <I
+to name) is achieved by means of the <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>in-addr.arpa</I
+></SPAN
> domain
and PTR records. Entries in the in-addr.arpa domain are made in
least-to-most significant order, read left to right. This is the
><DIV
CLASS="informaltable"
><A
-NAME="AEN4196"
+NAME="AEN4402"
></A
><P
></P
><H2
CLASS="sect2"
><A
-NAME="AEN4218"
+NAME="AEN4424"
>6.3.5. Other Zone File Directives</A
></H2
><P
><H3
CLASS="sect3"
><A
-NAME="AEN4225"
+NAME="AEN4431"
>6.3.5.1. The <B
CLASS="command"
>$ORIGIN</B
><H3
CLASS="sect3"
><A
-NAME="AEN4245"
+NAME="AEN4451"
>6.3.5.2. The <B
CLASS="command"
>$INCLUDE</B
><H3
CLASS="sect3"
><A
-NAME="AEN4265"
+NAME="AEN4471"
>6.3.5.3. The <B
CLASS="command"
>$TTL</B
><H2
CLASS="sect2"
><A
-NAME="AEN4276"
+NAME="AEN4482"
>6.3.6. <SPAN
CLASS="acronym"
>BIND</SPAN
><I
>lhs</I
></TT
-> <TT
+> [<SPAN
+CLASS="optional"
+><TT
+CLASS="replaceable"
+><I
+>ttl</I
+></TT
+></SPAN
+>] [<SPAN
+CLASS="optional"
+><TT
+CLASS="replaceable"
+><I
+>class</I
+></TT
+></SPAN
+>] <TT
CLASS="replaceable"
><I
>type</I
><TT
CLASS="literal"
>0.0.0.192.IN-ADDR.ARPA NS SERVER1.EXAMPLE.
-0.0.0.192.IN-ADDR.ARPA NS SERVER2.EXAMPLE.
-1.0.0.192.IN-ADDR.ARPA CNAME 1.0.0.0.192.IN-ADDR.ARPA
-2.0.0.192.IN-ADDR.ARPA CNAME 2.0.0.0.192.IN-ADDR.ARPA
+0.0.0.192.IN-ADDR.ARPA. NS SERVER2.EXAMPLE.
+1.0.0.192.IN-ADDR.ARPA. CNAME 1.0.0.0.192.IN-ADDR.ARPA.
+2.0.0.192.IN-ADDR.ARPA. CNAME 2.0.0.0.192.IN-ADDR.ARPA.
...
-127.0.0.192.IN-ADDR.ARPA CNAME 127.0.0.0.192.IN-ADDR.ARPA
-.</TT
+127.0.0.192.IN-ADDR.ARPA. CNAME 127.0.0.0.192.IN-ADDR.ARPA.
+</TT
></PRE
><DIV
CLASS="informaltable"
><A
-NAME="AEN4296"
+NAME="AEN4506"
></A
><P
></P
the name.</P
>
<P
->For compatability with earlier versions <B
+>For compatibility with earlier versions <B
CLASS="command"
>$$</B
> is still
><P
><B
CLASS="command"
+>ttl</B
+></P
+></TD
+><TD
+WIDTH="408"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+><B
+CLASS="command"
+>ttl</B
+> specifies the
+ ttl of the generated records. If not specified this will be
+ inherited using the normal ttl inhertance rules.</P
+>
+ <P
+><B
+CLASS="command"
+>class</B
+> and <B
+CLASS="command"
+>ttl</B
+> can be
+ entered in either order.</P
+></TD
+></TR
+><TR
+><TD
+WIDTH="84"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+><B
+CLASS="command"
+>class</B
+></P
+></TD
+><TD
+WIDTH="408"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+><B
+CLASS="command"
+>class</B
+> specifies the
+ class of the generated records. This must match the zone class if
+ it is specified.</P
+>
+ <P
+><B
+CLASS="command"
+>class</B
+> and <B
+CLASS="command"
+>ttl</B
+> can be
+ entered in either order.</P
+></TD
+></TR
+><TR
+><TD
+WIDTH="84"
+ALIGN="LEFT"
+VALIGN="MIDDLE"
+><P
+><B
+CLASS="command"
>type</B
></P
></TD
>BIND</SPAN
> extension
and not part of the standard zone file format.</P
+><P
+>BIND 8 does not support the optional TTL and CLASS fields.</P
></DIV
></DIV
></DIV
><HR
ALIGN="LEFT"
WIDTH="100%"><TABLE
+SUMMARY="Footer navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="top"
><A
HREF="Bv9ARM.ch05.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="H"
>Home</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.ch07.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
>BIND 9 Security Considerations</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"><LINK
REL="HOME"
TITLE="BIND 9 Administrator Reference Manual"
><DIV
CLASS="NAVHEADER"
><TABLE
+SUMMARY="Header navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="bottom"
><A
HREF="Bv9ARM.ch06.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="bottom"
><A
HREF="Bv9ARM.ch08.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
></DT
><DT
>7.2. <A
-HREF="Bv9ARM.ch07.html#AEN4368"
+HREF="Bv9ARM.ch07.html#AEN4599"
><B
CLASS="command"
>chroot</B
your name server, without cluttering up your config files with huge
lists of IP addresses.</P
><P
->It is a <I
+>It is a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>good idea</I
+></SPAN
> to use ACLs, and to
control access to your server. Limiting access to your server by
outside parties can help prevent spoofing and DoS attacks against
unless recursion has been previously disabled.</P
><P
>For more information on how to use ACLs to protect your server,
-see the <I
+see the <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>AUSCERT</I
+></SPAN
> advisory at
<A
HREF="ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos"
><H1
CLASS="sect1"
><A
-NAME="AEN4368"
+NAME="AEN4599"
>7.2. <B
CLASS="command"
>chroot</B
>On UNIX servers, it is possible to run <SPAN
CLASS="acronym"
>BIND</SPAN
-> in a <I
+> in a <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>chrooted</I
+></SPAN
> environment
(<B
CLASS="command"
><H2
CLASS="sect2"
><A
-NAME="AEN4391"
+NAME="AEN4622"
>7.2.1. The <B
CLASS="command"
>chroot</B
</P
><P
> Unlike with earlier versions of BIND, you will typically
-<I
+<SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>not</I
+></SPAN
> need to compile <B
CLASS="command"
>named</B
><H2
CLASS="sect2"
><A
-NAME="AEN4409"
+NAME="AEN4640"
>7.2.2. Using the <B
CLASS="command"
>setuid</B
><HR
ALIGN="LEFT"
WIDTH="100%"><TABLE
+SUMMARY="Footer navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="top"
><A
HREF="Bv9ARM.ch06.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="H"
>Home</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.ch08.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
>Troubleshooting</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"><LINK
REL="HOME"
TITLE="BIND 9 Administrator Reference Manual"
><DIV
CLASS="NAVHEADER"
><TABLE
+SUMMARY="Header navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="bottom"
><A
HREF="Bv9ARM.ch07.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="bottom"
><A
HREF="Bv9ARM.ch09.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
></DT
><DT
>8.1. <A
-HREF="Bv9ARM.ch08.html#AEN4430"
+HREF="Bv9ARM.ch08.html#AEN4661"
>Common Problems</A
></DT
><DT
>8.2. <A
-HREF="Bv9ARM.ch08.html#AEN4435"
+HREF="Bv9ARM.ch08.html#AEN4666"
>Incrementing and Changing the Serial Number</A
></DT
><DT
>8.3. <A
-HREF="Bv9ARM.ch08.html#AEN4440"
+HREF="Bv9ARM.ch08.html#AEN4671"
>Where Can I Get Help?</A
></DT
></DL
><H1
CLASS="sect1"
><A
-NAME="AEN4430"
+NAME="AEN4661"
>8.1. Common Problems</A
></H1
><DIV
><H2
CLASS="sect2"
><A
-NAME="AEN4432"
+NAME="AEN4663"
>8.1.1. It's not working; how can I figure out what's wrong?</A
></H2
><P
><H1
CLASS="sect1"
><A
-NAME="AEN4435"
+NAME="AEN4666"
>8.2. Incrementing and Changing the Serial Number</A
></H1
><P
><H1
CLASS="sect1"
><A
-NAME="AEN4440"
+NAME="AEN4671"
>8.3. Where Can I Get Help?</A
></H1
><P
><HR
ALIGN="LEFT"
WIDTH="100%"><TABLE
+SUMMARY="Footer navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="top"
><A
HREF="Bv9ARM.ch07.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="H"
>Home</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.ch09.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
>Appendices</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"><LINK
REL="HOME"
TITLE="BIND 9 Administrator Reference Manual"
><DIV
CLASS="NAVHEADER"
><TABLE
+SUMMARY="Header navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="bottom"
><A
HREF="Bv9ARM.ch08.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
></DT
><DT
>A.1. <A
-HREF="Bv9ARM.ch09.html#AEN4456"
+HREF="Bv9ARM.ch09.html#AEN4687"
>Acknowledgements</A
></DT
><DT
><H1
CLASS="sect1"
><A
-NAME="AEN4456"
+NAME="AEN4687"
>A.1. Acknowledgements</A
></H1
><DIV
><H2
CLASS="sect2"
><A
-NAME="AEN4458"
+NAME="AEN4689"
>A.1.1. A Brief History of the <SPAN
CLASS="acronym"
>DNS</SPAN
CLASS="sect2"
><A
NAME="ipv6addresses"
->A.2.1. IPv6 addresses (A6)</A
+>A.2.1. IPv6 addresses (AAAA)</A
></H2
><P
>IPv6 addresses are 128-bit identifiers for interfaces and
CLASS="acronym"
>DNS</SPAN
> to facilitate
-scalable Internet routing. There are three types of addresses: <I
+scalable Internet routing. There are three types of addresses: <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Unicast</I
+></SPAN
>,
-an identifier for a single interface; <I
+an identifier for a single interface; <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Anycast</I
+></SPAN
>,
-an identifier for a set of interfaces; and <I
+an identifier for a set of interfaces; and <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Multicast</I
+></SPAN
>,
an identifier for a set of interfaces. Here we describe the global
Unicast address scheme. For more information, see RFC 2374.</P
><DIV
CLASS="informaltable"
><A
-NAME="AEN4494"
+NAME="AEN4725"
></A
><P
></P
<DIV
CLASS="informaltable"
><A
-NAME="AEN4563"
+NAME="AEN4794"
></A
><P
></P
></DIV
></P
><P
->The <I
+>The <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Public Topology</I
+></SPAN
> is provided by the
-upstream provider or ISP, and (roughly) corresponds to the IPv4 <I
+upstream provider or ISP, and (roughly) corresponds to the IPv4 <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>network</I
+></SPAN
> section
-of the address range. The <I
+of the address range. The <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Site Topology</I
+></SPAN
> is
where you can subnet this space, much the same as subnetting an
-IPv4 /16 network into /24 subnets. The <I
+IPv4 /16 network into /24 subnets. The <SPAN
+CLASS="emphasis"
+><I
CLASS="emphasis"
>Interface Identifier</I
+></SPAN
> is
the address of an individual interface on a given network. (With
IPv6, addresses belong to interfaces rather than machines.)</P
that of IPv4: subnetting can now be carried out on bit boundaries,
in much the same way as Classless InterDomain Routing (CIDR).</P
><P
->The internal structure of the Public Topology for an A6 global
-unicast address consists of:</P
-><DIV
-CLASS="informaltable"
-><A
-NAME="AEN4618"
-></A
-><P
-></P
-><TABLE
-CELLPADDING="3"
-BORDER="1"
-CLASS="CALSTABLE"
-><TBODY
-><TR
-><TD
-WIDTH="49"
-ALIGN="LEFT"
-VALIGN="MIDDLE"
-><P
->3</P
-></TD
-><TD
-WIDTH="64"
-ALIGN="LEFT"
-VALIGN="MIDDLE"
-><P
->13</P
-></TD
-><TD
-WIDTH="53"
-ALIGN="LEFT"
-VALIGN="MIDDLE"
-><P
->8</P
-></TD
-><TD
-WIDTH="79"
-ALIGN="LEFT"
-VALIGN="MIDDLE"
-><P
->24</P
-></TD
-></TR
-><TR
-><TD
-WIDTH="49"
-ALIGN="LEFT"
-VALIGN="MIDDLE"
-><P
->FP</P
-></TD
-><TD
-WIDTH="64"
-ALIGN="LEFT"
-VALIGN="MIDDLE"
-><P
->TLA ID</P
-></TD
-><TD
-WIDTH="53"
-ALIGN="LEFT"
-VALIGN="MIDDLE"
-><P
->RES</P
-></TD
-><TD
-WIDTH="79"
-ALIGN="LEFT"
-VALIGN="MIDDLE"
-><P
->NLA ID</P
-></TD
-></TR
-></TBODY
-></TABLE
-><P
-></P
-></DIV
-><P
->A 3 bit FP (Format Prefix) of 001 indicates this is a global
-Unicast address. FP lengths for other types of addresses may vary.</P
-><P
->13 TLA (Top Level Aggregator) bits give the prefix of your
-top-level IP backbone carrier.</P
-><P
->8 Reserved bits</P
-><P
->24 bits for Next Level Aggregators. This allows organizations
-with a TLA to hand out portions of their IP space to client organizations,
-so that the client can then split up the network further by filling
-in more NLA bits, and hand out IPv6 prefixes to their clients, and
-so forth.</P
-><P
->There is no particular structure for the Site topology section.
-Organizations can allocate these bits in any way they desire.</P
-><P
>The Interface Identifier must be unique on that network. On
ethernet networks, one way to ensure this is to set the address
to the first three bytes of the hardware address, "FFFE", then the
><P
><B
CLASS="command"
->3ffe:8050:201:9:a00:20ff:fe81:2b32</B
+>2001:4f8:201:9:a00:20ff:fe81:2b32</B
></P
><P
>IPv6 address specifications are likely to contain long strings
</P
><H3
><A
-NAME="AEN4662"
+NAME="AEN4862"
>Bibliography</A
></H3
-><H1
+><H2
CLASS="bibliodiv"
><A
-NAME="AEN4663"
+NAME="AEN4863"
>Standards</A
-></H1
+></H2
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4665"
+NAME="AEN4865"
></A
><P
>[RFC974] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4672"
+NAME="AEN4872"
></A
><P
>[RFC1034] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4679"
+NAME="AEN4879"
></A
><P
>[RFC1035] <SPAN
STYLE="margin-left=0.5in"
></DIV
></DIV
-><H1
+><H2
CLASS="bibliodiv"
><A
NAME="proposed_standards"
>Proposed Standards</A
-></H1
+></H2
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4688"
+NAME="AEN4888"
></A
><P
>[RFC2181] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4696"
+NAME="AEN4896"
></A
><P
>[RFC2308] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4704"
+NAME="AEN4904"
></A
><P
>[RFC1995] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4712"
+NAME="AEN4912"
></A
><P
>[RFC1996] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4719"
+NAME="AEN4919"
></A
><P
>[RFC2136] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4736"
+NAME="AEN4936"
></A
><P
>[RFC2845] <SPAN
STYLE="margin-left=0.5in"
></DIV
></DIV
-><H1
+><H2
CLASS="bibliodiv"
><A
-NAME="AEN4755"
+NAME="AEN4955"
>Proposed Standards Still Under Development</A
-></H1
+></H2
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4760"
+NAME="AEN4960"
></A
><P
>[RFC1886] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4772"
+NAME="AEN4972"
></A
><P
>[RFC2065] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4784"
+NAME="AEN4984"
></A
><P
>[RFC2137] <SPAN
STYLE="margin-left=0.5in"
></DIV
></DIV
-><H1
+><H2
CLASS="bibliodiv"
><A
-NAME="AEN4792"
+NAME="AEN4992"
>Other Important RFCs About <SPAN
CLASS="acronym"
>DNS</SPAN
> Implementation</A
-></H1
+></H2
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4795"
+NAME="AEN4995"
></A
><P
>[RFC1535] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4803"
+NAME="AEN5003"
></A
><P
>[RFC1536] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4824"
+NAME="AEN5024"
></A
><P
>[RFC1982] <SPAN
STYLE="margin-left=0.5in"
></DIV
></DIV
-><H1
+><H2
CLASS="bibliodiv"
><A
-NAME="AEN4835"
+NAME="AEN5035"
>Resource Record Types</A
-></H1
+></H2
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4837"
+NAME="AEN5037"
></A
><P
>[RFC1183] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4855"
+NAME="AEN5055"
></A
><P
>[RFC1706] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4867"
+NAME="AEN5067"
></A
><P
>[RFC2168] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4878"
+NAME="AEN5078"
></A
><P
>[RFC1876] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4895"
+NAME="AEN5095"
></A
><P
>[RFC2052] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4907"
+NAME="AEN5107"
></A
><P
>[RFC2163] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4915"
+NAME="AEN5115"
></A
><P
>[RFC2230] <SPAN
STYLE="margin-left=0.5in"
></DIV
></DIV
-><H1
+><H2
CLASS="bibliodiv"
><A
-NAME="AEN4923"
+NAME="AEN5123"
><SPAN
CLASS="acronym"
>DNS</SPAN
> and the Internet</A
-></H1
+></H2
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4926"
+NAME="AEN5126"
></A
><P
>[RFC1101] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4934"
+NAME="AEN5134"
></A
><P
>[RFC1123] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4941"
+NAME="AEN5141"
></A
><P
>[RFC1591] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4948"
+NAME="AEN5148"
></A
><P
>[RFC2317] <SPAN
STYLE="margin-left=0.5in"
></DIV
></DIV
-><H1
+><H2
CLASS="bibliodiv"
><A
-NAME="AEN4962"
+NAME="AEN5162"
><SPAN
CLASS="acronym"
>DNS</SPAN
> Operations</A
-></H1
+></H2
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4965"
+NAME="AEN5165"
></A
><P
>[RFC1537] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4973"
+NAME="AEN5173"
></A
><P
>[RFC1912] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN4981"
-></A
-><P
->[RFC1912] <SPAN
-CLASS="AUTHOR"
->D. Barr</SPAN
->, <I
->Common <SPAN
-CLASS="acronym"
->DNS</SPAN
-> Operational and Configuration Errors</I
->, February 1996.</P
-><DIV
-CLASS="BIBLIOENTRYBLOCK"
-STYLE="margin-left=0.5in"
-></DIV
-></DIV
-><DIV
-CLASS="biblioentry"
-><A
-NAME="AEN4989"
+NAME="AEN5181"
></A
><P
>[RFC2010] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN5000"
+NAME="AEN5192"
></A
><P
>[RFC2219] <SPAN
STYLE="margin-left=0.5in"
></DIV
></DIV
-><H1
+><H2
CLASS="bibliodiv"
><A
-NAME="AEN5012"
+NAME="AEN5204"
>Other <SPAN
CLASS="acronym"
>DNS</SPAN
>-related RFCs</A
-></H1
+></H2
><DIV
CLASS="biblioentry"
><A
-NAME="AEN5018"
+NAME="AEN5210"
></A
><P
>[RFC1464] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN5025"
+NAME="AEN5217"
></A
><P
>[RFC1713] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN5033"
+NAME="AEN5225"
></A
><P
>[RFC1794] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN5041"
+NAME="AEN5233"
></A
><P
>[RFC2240] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN5048"
+NAME="AEN5240"
></A
><P
>[RFC2345] <SPAN
><DIV
CLASS="biblioentry"
><A
-NAME="AEN5062"
+NAME="AEN5254"
></A
><P
>[RFC2352] <SPAN
STYLE="margin-left=0.5in"
></DIV
></DIV
-><H1
+><H2
CLASS="bibliodiv"
><A
-NAME="AEN5069"
+NAME="AEN5261"
>Obsolete and Unimplemented Experimental RRs</A
-></H1
+></H2
><DIV
CLASS="biblioentry"
><A
-NAME="AEN5071"
+NAME="AEN5263"
></A
><P
>[RFC1712] <SPAN
><H2
CLASS="sect2"
><A
-NAME="AEN5092"
+NAME="AEN5284"
>A.3.3. Other Documents About <SPAN
CLASS="acronym"
>BIND</SPAN
></P
><H3
><A
-NAME="AEN5096"
+NAME="AEN5288"
>Bibliography</A
></H3
><DIV
CLASS="biblioentry"
><A
-NAME="AEN5097"
+NAME="AEN5289"
></A
><P
><SPAN
><HR
ALIGN="LEFT"
WIDTH="100%"><TABLE
+SUMMARY="Footer navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="top"
><A
HREF="Bv9ARM.ch08.html"
+ACCESSKEY="P"
>Prev</A
></TD
><TD
VALIGN="top"
><A
HREF="Bv9ARM.html"
+ACCESSKEY="H"
>Home</A
></TD
><TD
>BIND 9 Administrator Reference Manual</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"><LINK
REL="NEXT"
TITLE="Introduction "
></DT
><DT
>3.3.2. <A
-HREF="Bv9ARM.ch03.html#AEN675"
+HREF="Bv9ARM.ch03.html#AEN677"
>Signals</A
></DT
></DL
></DT
><DT
>4.4. <A
-HREF="Bv9ARM.ch04.html#AEN753"
+HREF="Bv9ARM.ch04.html#AEN755"
>Split DNS</A
></DT
><DT
><DL
><DT
>4.5.1. <A
-HREF="Bv9ARM.ch04.html#AEN844"
+HREF="Bv9ARM.ch04.html#AEN846"
>Generate Shared Keys for Each Pair of Hosts</A
></DT
><DT
>4.5.2. <A
-HREF="Bv9ARM.ch04.html#AEN865"
+HREF="Bv9ARM.ch04.html#AEN867"
>Copying the Shared Secret to Both Machines</A
></DT
><DT
>4.5.3. <A
-HREF="Bv9ARM.ch04.html#AEN868"
+HREF="Bv9ARM.ch04.html#AEN870"
>Informing the Servers of the Key's Existence</A
></DT
><DT
>4.5.4. <A
-HREF="Bv9ARM.ch04.html#AEN880"
+HREF="Bv9ARM.ch04.html#AEN882"
>Instructing the Server to Use the Key</A
></DT
><DT
>4.5.5. <A
-HREF="Bv9ARM.ch04.html#AEN896"
+HREF="Bv9ARM.ch04.html#AEN898"
>TSIG Key Based Access Control</A
></DT
><DT
>4.5.6. <A
-HREF="Bv9ARM.ch04.html#AEN909"
+HREF="Bv9ARM.ch04.html#AEN911"
>Errors</A
></DT
></DL
></DD
><DT
>4.6. <A
-HREF="Bv9ARM.ch04.html#AEN913"
+HREF="Bv9ARM.ch04.html#AEN915"
>TKEY</A
></DT
><DT
>4.7. <A
-HREF="Bv9ARM.ch04.html#AEN928"
+HREF="Bv9ARM.ch04.html#AEN930"
>SIG(0)</A
></DT
><DT
><DL
><DT
>4.8.1. <A
-HREF="Bv9ARM.ch04.html#AEN947"
+HREF="Bv9ARM.ch04.html#AEN949"
>Generating Keys</A
></DT
><DT
>4.8.2. <A
-HREF="Bv9ARM.ch04.html#AEN967"
+HREF="Bv9ARM.ch04.html#AEN969"
>Creating a Keyset</A
></DT
><DT
>4.8.3. <A
-HREF="Bv9ARM.ch04.html#AEN979"
+HREF="Bv9ARM.ch04.html#AEN981"
>Signing the Child's Keyset</A
></DT
><DT
>4.8.4. <A
-HREF="Bv9ARM.ch04.html#AEN992"
+HREF="Bv9ARM.ch04.html#AEN994"
>Signing the Zone</A
></DT
><DT
>4.8.5. <A
-HREF="Bv9ARM.ch04.html#AEN1008"
+HREF="Bv9ARM.ch04.html#AEN1010"
>Configuring Servers</A
></DT
></DL
></DD
><DT
>4.9. <A
-HREF="Bv9ARM.ch04.html#AEN1015"
+HREF="Bv9ARM.ch04.html#AEN1017"
>IPv6 Support in <SPAN
CLASS="acronym"
>BIND</SPAN
><DL
><DT
>4.9.1. <A
-HREF="Bv9ARM.ch04.html#AEN1032"
+HREF="Bv9ARM.ch04.html#AEN1035"
>Address Lookups Using AAAA Records</A
></DT
><DT
>4.9.2. <A
-HREF="Bv9ARM.ch04.html#AEN1037"
->Address Lookups Using A6 Records</A
-></DT
-><DT
->4.9.3. <A
-HREF="Bv9ARM.ch04.html#AEN1058"
+HREF="Bv9ARM.ch04.html#AEN1041"
>Address to Name Lookups Using Nibble Format</A
></DT
-><DT
->4.9.4. <A
-HREF="Bv9ARM.ch04.html#AEN1065"
->Address to Name Lookups Using Binary Label Format</A
-></DT
-><DT
->4.9.5. <A
-HREF="Bv9ARM.ch04.html#AEN1072"
->Using DNAME for Delegation of IPv6 Reverse Addresses</A
-></DT
></DL
></DD
></DL
><DL
><DT
>5.1. <A
-HREF="Bv9ARM.ch05.html#AEN1092"
+HREF="Bv9ARM.ch05.html#AEN1050"
>The Lightweight Resolver Library</A
></DT
><DT
></DT
><DT
>6.1.2. <A
-HREF="Bv9ARM.ch06.html#AEN1335"
+HREF="Bv9ARM.ch06.html#AEN1296"
>Comment Syntax</A
></DT
></DL
><DL
><DT
>6.2.1. <A
-HREF="Bv9ARM.ch06.html#AEN1442"
+HREF="Bv9ARM.ch06.html#AEN1409"
><B
CLASS="command"
>acl</B
></DT
><DT
>6.2.3. <A
-HREF="Bv9ARM.ch06.html#AEN1489"
+HREF="Bv9ARM.ch06.html#AEN1451"
><B
CLASS="command"
>controls</B
></DT
><DT
>6.2.5. <A
-HREF="Bv9ARM.ch06.html#AEN1568"
+HREF="Bv9ARM.ch06.html#AEN1530"
><B
CLASS="command"
>include</B
></DT
><DT
>6.2.6. <A
-HREF="Bv9ARM.ch06.html#AEN1573"
+HREF="Bv9ARM.ch06.html#AEN1535"
><B
CLASS="command"
>include</B
></DT
><DT
>6.2.7. <A
-HREF="Bv9ARM.ch06.html#AEN1580"
+HREF="Bv9ARM.ch06.html#AEN1542"
><B
CLASS="command"
>key</B
></DT
><DT
>6.2.8. <A
-HREF="Bv9ARM.ch06.html#AEN1587"
+HREF="Bv9ARM.ch06.html#AEN1549"
><B
CLASS="command"
>key</B
></DT
><DT
>6.2.9. <A
-HREF="Bv9ARM.ch06.html#AEN1607"
+HREF="Bv9ARM.ch06.html#AEN1569"
><B
CLASS="command"
>logging</B
></DT
><DT
>6.2.10. <A
-HREF="Bv9ARM.ch06.html#AEN1647"
+HREF="Bv9ARM.ch06.html#AEN1609"
><B
CLASS="command"
>logging</B
></DT
><DT
>6.2.11. <A
-HREF="Bv9ARM.ch06.html#AEN1878"
+HREF="Bv9ARM.ch06.html#AEN1873"
><B
CLASS="command"
>lwres</B
></DT
><DT
>6.2.12. <A
-HREF="Bv9ARM.ch06.html#AEN1902"
+HREF="Bv9ARM.ch06.html#AEN1897"
><B
CLASS="command"
>lwres</B
></DT
><DT
>6.2.13. <A
-HREF="Bv9ARM.ch06.html#AEN1921"
+HREF="Bv9ARM.ch06.html#AEN1916"
><B
CLASS="command"
->options</B
+>masters</B
> Statement Grammar</A
></DT
><DT
>6.2.14. <A
+HREF="Bv9ARM.ch06.html#AEN1931"
+><B
+CLASS="command"
+>masters</B
+> Statement Definition and Usage</A
+></DT
+><DT
+>6.2.15. <A
+HREF="Bv9ARM.ch06.html#AEN1936"
+><B
+CLASS="command"
+>options</B
+> Statement Grammar</A
+></DT
+><DT
+>6.2.16. <A
HREF="Bv9ARM.ch06.html#options"
><B
CLASS="command"
> Statement Definition and Usage</A
></DT
><DT
->6.2.15. <A
+>6.2.17. <A
HREF="Bv9ARM.ch06.html#server_statement_grammar"
><B
CLASS="command"
> Statement Grammar</A
></DT
><DT
->6.2.16. <A
+>6.2.18. <A
HREF="Bv9ARM.ch06.html#server_statement_definition_and_usage"
><B
CLASS="command"
> Statement Definition and Usage</A
></DT
><DT
->6.2.17. <A
-HREF="Bv9ARM.ch06.html#AEN3200"
+>6.2.19. <A
+HREF="Bv9ARM.ch06.html#AEN3342"
><B
CLASS="command"
>trusted-keys</B
> Statement Grammar</A
></DT
><DT
->6.2.18. <A
-HREF="Bv9ARM.ch06.html#AEN3216"
+>6.2.20. <A
+HREF="Bv9ARM.ch06.html#AEN3358"
><B
CLASS="command"
>trusted-keys</B
and Usage</A
></DT
><DT
->6.2.19. <A
+>6.2.21. <A
HREF="Bv9ARM.ch06.html#view_statement_grammar"
><B
CLASS="command"
> Statement Grammar</A
></DT
><DT
->6.2.20. <A
-HREF="Bv9ARM.ch06.html#AEN3238"
+>6.2.22. <A
+HREF="Bv9ARM.ch06.html#AEN3380"
><B
CLASS="command"
>view</B
> Statement Definition and Usage</A
></DT
><DT
->6.2.21. <A
+>6.2.23. <A
HREF="Bv9ARM.ch06.html#zone_statement_grammar"
><B
CLASS="command"
Statement Grammar</A
></DT
><DT
->6.2.22. <A
-HREF="Bv9ARM.ch06.html#AEN3395"
+>6.2.24. <A
+HREF="Bv9ARM.ch06.html#AEN3554"
><B
CLASS="command"
>zone</B
></DD
><DT
>6.3. <A
-HREF="Bv9ARM.ch06.html#AEN3755"
+HREF="Bv9ARM.ch06.html#AEN3956"
>Zone File</A
></DT
><DD
></DT
><DT
>6.3.2. <A
-HREF="Bv9ARM.ch06.html#AEN4070"
+HREF="Bv9ARM.ch06.html#AEN4276"
>Discussion of MX Records</A
></DT
><DT
></DT
><DT
>6.3.4. <A
-HREF="Bv9ARM.ch06.html#AEN4191"
+HREF="Bv9ARM.ch06.html#AEN4397"
>Inverse Mapping in IPv4</A
></DT
><DT
>6.3.5. <A
-HREF="Bv9ARM.ch06.html#AEN4218"
+HREF="Bv9ARM.ch06.html#AEN4424"
>Other Zone File Directives</A
></DT
><DT
>6.3.6. <A
-HREF="Bv9ARM.ch06.html#AEN4276"
+HREF="Bv9ARM.ch06.html#AEN4482"
><SPAN
CLASS="acronym"
>BIND</SPAN
></DT
><DT
>7.2. <A
-HREF="Bv9ARM.ch07.html#AEN4368"
+HREF="Bv9ARM.ch07.html#AEN4599"
><B
CLASS="command"
>chroot</B
><DL
><DT
>7.2.1. <A
-HREF="Bv9ARM.ch07.html#AEN4391"
+HREF="Bv9ARM.ch07.html#AEN4622"
>The <B
CLASS="command"
>chroot</B
></DT
><DT
>7.2.2. <A
-HREF="Bv9ARM.ch07.html#AEN4409"
+HREF="Bv9ARM.ch07.html#AEN4640"
>Using the <B
CLASS="command"
>setuid</B
><DL
><DT
>8.1. <A
-HREF="Bv9ARM.ch08.html#AEN4430"
+HREF="Bv9ARM.ch08.html#AEN4661"
>Common Problems</A
></DT
><DD
><DL
><DT
>8.1.1. <A
-HREF="Bv9ARM.ch08.html#AEN4432"
+HREF="Bv9ARM.ch08.html#AEN4663"
>It's not working; how can I figure out what's wrong?</A
></DT
></DL
></DD
><DT
>8.2. <A
-HREF="Bv9ARM.ch08.html#AEN4435"
+HREF="Bv9ARM.ch08.html#AEN4666"
>Incrementing and Changing the Serial Number</A
></DT
><DT
>8.3. <A
-HREF="Bv9ARM.ch08.html#AEN4440"
+HREF="Bv9ARM.ch08.html#AEN4671"
>Where Can I Get Help?</A
></DT
></DL
><DL
><DT
>A.1. <A
-HREF="Bv9ARM.ch09.html#AEN4456"
+HREF="Bv9ARM.ch09.html#AEN4687"
>Acknowledgements</A
></DT
><DD
><DL
><DT
>A.1.1. <A
-HREF="Bv9ARM.ch09.html#AEN4458"
+HREF="Bv9ARM.ch09.html#AEN4689"
>A Brief History of the <SPAN
CLASS="acronym"
>DNS</SPAN
><DT
>A.2.1. <A
HREF="Bv9ARM.ch09.html#ipv6addresses"
->IPv6 addresses (A6)</A
+>IPv6 addresses (AAAA)</A
></DT
></DL
></DD
></DT
><DT
>A.3.3. <A
-HREF="Bv9ARM.ch09.html#AEN5092"
+HREF="Bv9ARM.ch09.html#AEN5284"
>Other Documents About <SPAN
CLASS="acronym"
>BIND</SPAN
><HR
ALIGN="LEFT"
WIDTH="100%"><TABLE
+SUMMARY="Footer navigation table"
WIDTH="100%"
BORDER="0"
CELLPADDING="0"
VALIGN="top"
><A
HREF="Bv9ARM.ch01.html"
+ACCESSKEY="N"
>Next</A
></TD
></TR
dual-stack-servers [ port <integer> ] { ( <quoted_string> [port
<integer>] | <ipv4_address> [port <integer>] | <ipv6_address> [port <integer>] ); ... };
edns-udp-size <integer>;
+ root-delegation-only [ exclude { <quoted_string>; ... } ];
allow-query { <address_match_element>; ... };
allow-transfer { <address_match_element>; ... };
allow-update-forwarding { <address_match_element>; ... };
secret <string>;
};
zone <string> <optional_class> {
- type ( master | slave | stub | hint | forward );
+ type ( master | slave | stub | hint | forward |
+ delegation-only );
allow-update { <address_match_element>; ... };
file <quoted_string>;
ixfr-base <quoted_string>; // obsolete
update-policy { ( grant | deny ) <string> ( name |
subdomain | wildcard | self ) <string> <rrtypelist>; ... };
database <string>;
+ delegation-only <boolean>;
check-names <string>; // not implemented
allow-query { <address_match_element>; ... };
allow-transfer { <address_match_element>; ... };
transfer-format ( many-answers | one-answer );
keys <server_key>;
edns <boolean>;
+ transfer-source ( <ipv4_address> | * ) [ port ( <integer> |
+ * ) ];
+ transfer-source-v6 ( <ipv6_address> | * ) [ port (
+ <integer> | * ) ];
};
trusted-keys { <string> <integer> <integer> <integer>
<quoted_string>; ... };
dual-stack-servers [ port <integer> ] { ( <quoted_string> [port
<integer>] | <ipv4_address> [port <integer>] | <ipv6_address> [port <integer>] ); ... };
edns-udp-size <integer>;
+ root-delegation-only [ exclude { <quoted_string>; ... } ];
allow-query { <address_match_element>; ... };
allow-transfer { <address_match_element>; ... };
allow-update-forwarding { <address_match_element>; ... };
};
zone <string> <optional_class> {
- type ( master | slave | stub | hint | forward );
+ type ( master | slave | stub | hint | forward | delegation-only );
allow-update { <address_match_element>; ... };
file <quoted_string>;
ixfr-base <quoted_string>; // obsolete
update-policy { ( grant | deny ) <string> ( name | subdomain |
wildcard | self ) <string> <rrtypelist>; ... };
database <string>;
+ delegation-only <boolean>;
check-names <string>; // not implemented
allow-query { <address_match_element>; ... };
allow-transfer { <address_match_element>; ... };
transfer-format ( many-answers | one-answer );
keys <server_key>;
edns <boolean>;
+ transfer-source ( <ipv4_address> | * ) [ port ( <integer> | * ) ];
+ transfer-source-v6 ( <ipv6_address> | * ) [ port ( <integer> | * ) ];
};
trusted-keys { <string> <integer> <integer> <integer> <quoted_string>; ... };
with a resolver daemon.
The new
\fBlwres_context_t\fR
-is returned throught
+is returned through
\fIcontextp\fR,
a pointer to a
\fBlwres_context_t\fR
>lwres_context</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"></HEAD
><BODY
CLASS="REFENTRY"
CLASS="TYPE"
>lwres_context_t</SPAN
>
-is returned throught
+is returned through
<TT
CLASS="PARAMETER"
><I
\fBlwres_getipnodebyaddr()\fR
set
\fI*error_num\fR
-to an approriate error code and the function returns a
+to an appropriate error code and the function returns a
\fBNULL\fR
pointer.
The error codes and their meanings are defined in
>lwres_getipnode</TITLE
><META
NAME="GENERATOR"
-CONTENT="Modular DocBook HTML Stylesheet Version 1.61
+CONTENT="Modular DocBook HTML Stylesheet Version 1.73
"></HEAD
><BODY
CLASS="REFENTRY"
>*error_num</I
></TT
>
-to an approriate error code and the function returns a
+to an appropriate error code and the function returns a
<SPAN
CLASS="TYPE"
>NULL</SPAN