From 699095b077b0e4e6138b7546d5bb3f05b0d00bb7 Mon Sep 17 00:00:00 2001
From: Andreas Gustafsson To generate a random secret with dnssec-keygenrndc-confgen:
$ dnssec-keygen -a hmac-md5 -b 128 -n user rndcrndc-confgen
The base-64 string will appear in two files,
- Krndc.+157.+{random}.key and
- Krndc.+157.+{random}.private. After
- extracting the key to be placed in the
- A complete rndc.conf and
- file, including the
+ randomly generated key, will be written to the standard
+ output. Commented out key and
+ controls statements for
+ named.conf key statements, the
- .key and .private files can be removed.
+> are also printed.
To generate a random secret with To generate a base-64 secret with mmencode:
@@ -300,7 +298,7 @@ CLASS="COMMAND"
> $ echo "known plaintext for a secret" | mmencodeecho "known plaintext for a secret" | mmencode
The pathname of the file the server writes
-its process ID in. If not specified, the default is operating system
-dependent, but is usually
-The pathname of the file the server writes its process ID
+in. If not specified, the default is /var/run/named.pid or /etc/named.pid.
The pid-file is used by programs that want to send signals to the running
nameserver. Note: The address specified in the query-source currently applies only
-to UDP queries; TCP queries always use a wildcard IP address and
-a random unprivileged port.6.2.14.2. Forwarding
6.2.14.4. Interfaces
6.2.14.5. Query Address
[RFC974] [RFC1034] [RFC1035] [RFC2181] [RFC2308] [RFC1995] [RFC1996] [RFC2136] [RFC2845] [RFC1886] [RFC2065] [RFC2137] [RFC1535] [RFC1536] [RFC1982] [RFC1183] [RFC1706] [RFC2168] [RFC1876] [RFC2052] [RFC2163] [RFC2230] [RFC1101] [RFC1123] [RFC1591] [RFC2317] [RFC1537] [RFC1912] [RFC1912] [RFC2010] [RFC2219] [RFC1464] [RFC1713] [RFC1794] [RFC2240] [RFC2345] [RFC2352] [RFC1712] Proposed Standards Still Under Development
Other Important RFCs About DNS
Resource Record Types
DNS
DNS
Other DNS
Obsolete and Unimplemented Experimental RRs
A.4.3. Other Documents About BIND
Bibliography