BIND 9 Administrator Reference Manual
来自DNS-WIKI
- 1. Introduction to DNS and BIND 9
- 2. Resource Requirements
- 3. Configurations and Zone Files
- 4. Name Server Operations
- 5. DNSSEC
- 5.1. Zone Signing
- 5.2. Secure Delegation
- 5.3. DNSSEC Validation
- 5.4. Dynamic Trust Anchor Management
- 5.5. PKCS#11 (Cryptoki) Support
- 6. Advanced Configurations
- 6.1. Dynamic Update
- 6.2. NOTIFY
- 6.3. Incremental Zone Transfers (IXFR)
- 6.4. Split DNS
- 6.5. IPv6 Support in BIND 9
- 6.6. Dynamically Loadable Zones (DLZ)
- 6.7. Dynamic Database (DynDB)
- 6.8. Catalog Zones
- 6.9. DNS Firewalls and Response Policy Zones
- 7. Security Configurations
- 7.1. Security Assumptions
- 7.2. Access Control Lists
- 7.3.
Chroot
andSetuid
- 7.4. Dynamic Update Security
- 7.5. TSIG
- 7.6. TKEY
- 7.7. SIG(0)
- 8. Configuration Reference
- 8.1. Configuration File (named.conf)
- 8.2. Blocks
- 8.3. Statements
- 8.4. Statements by Tag
- 8.5. BIND 9 Statistics
- 9. Troubleshooting
- 9.1. Common Problems
- 9.2. Incrementing and Changing the Serial Number
- 9.3. Where Can I Get Help?
- 10. Building BIND 9
- 10.1. Required Libraries
- 10.2. Optional Features
- 10.3. macOS
Appendices
- Release Notes
- Introduction
- Supported Platforms
- Download
- Known Issues
- Notes for BIND 9.18.26
- Notes for BIND 9.18.25
- Notes for BIND 9.18.24
- Notes for BIND 9.18.23
- Notes for BIND 9.18.22
- Notes for BIND 9.18.21
- Notes for BIND 9.18.20
- Notes for BIND 9.18.19
- Notes for BIND 9.18.18
- Notes for BIND 9.18.17
- Notes for BIND 9.18.16
- Notes for BIND 9.18.15
- Notes for BIND 9.18.14
- Notes for BIND 9.18.13
- Notes for BIND 9.18.12
- Notes for BIND 9.18.11
- Notes for BIND 9.18.10
- Notes for BIND 9.18.9
- Notes for BIND 9.18.8
- Notes for BIND 9.18.7
- Notes for BIND 9.18.6
- Notes for BIND 9.18.5
- Notes for BIND 9.18.4
- Notes for BIND 9.18.3
- Notes for BIND 9.18.2
- Notes for BIND 9.18.1
- Notes for BIND 9.18.0
- License
- End of Life
- Thank You
- DNSSEC Guide
- Preface
- Introduction
- Getting Started
- Validation
- Signing
- Basic DNSSEC Troubleshooting
- Advanced Discussions
- Recipes
- Commonly Asked Questions
- A Brief History of the DNS and BIND
- General DNS Reference Information
- Requests for Comment (RFCs)
- Notes
- Internet Drafts
- Manual Pages
- arpaname - translate IP addresses to the corresponding ARPA names
- ddns-confgen - TSIG key generation tool
- delv - DNS lookup and validation utility
- dig - DNS lookup utility
- dnssec-cds - change DS records for a child zone based on CDS/CDNSKEY
- dnssec-dsfromkey - DNSSEC DS RR generation tool
- dnssec-importkey - import DNSKEY records from external systems so they can be managed
- dnssec-keyfromlabel - DNSSEC key generation tool
- dnssec-keygen: DNSSEC key generation tool
- dnssec-revoke - set the REVOKED bit on a DNSSEC key
- dnssec-settime: set the key timing metadata for a DNSSEC key
- dnssec-signzone - DNSSEC zone signing tool
- dnssec-verify - DNSSEC zone verification tool
- dnstap-read - print dnstap data in human-readable form
- filter-aaaa.so - filter AAAA in DNS responses when A is present
- host - DNS lookup utility
- mdig - DNS pipelined lookup utility
- named-checkconf - named configuration file syntax checking tool
- named-checkzone - zone file validation tool
- named-compilezone - zone file converting tool
- named-journalprint - print zone journal in human-readable form
- named-nzd2nzf - convert an NZD database to NZF text format
- named-rrchecker - syntax checker for individual DNS resource records
- named.conf - configuration file for named
- named - Internet domain name server
- nsec3hash - generate NSEC3 hash
- nslookup - query Internet name servers interactively
- nsupdate - dynamic DNS update utility
- rndc-confgen - rndc key generation tool
- rndc.conf - rndc configuration file
- rndc - name server control utility
- tsig-keygen - TSIG key generation tool