.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
.\" PERFORMANCE OF THIS SOFTWARE.
.\"
.\" $Id: named-checkzone.8,v 1.29 2005/06/20 03:30:26 marka Exp $
.\" $Id: named-checkzone.8,v 1.30 2005/08/25 03:12:42 marka Exp $
.\"
.hy 0
.ad l
...
...
@@ -67,10 +67,11 @@ When loading the zone file read the journal if it exists\&.
Specify the class of the zone\&. If not specified "IN" is assumed\&.
.TP
\-i \fImode\fR
Perform post load zone integrity checks\&. Possible modes are \fB"full"\fR (default), \fB"local"\fR and \fB"none"\fR\&.
Perform post load zone integrity checks\&. Possible modes are \fB"full"\fR (default), \fB"full\-sibling"\fR, \fB"local"\fR, \fB"local\-sibling"\fR and \fB"none"\fR\&.
Mode \fB"full"\fR checks that MX records refer to A or AAAA record (both in\-zone and out\-of\-zone hostnames)\&. Mode \fB"local"\fR only checks MX records which refer to in\-zone hostnames\&.
Mode \fB"full"\fR checks that SRV records refer to A or AAAA record (both in\-zone and out\-of\-zone hostnames)\&. Mode \fB"local"\fR only checks SRV records which refer to in\-zone hostnames\&.
Mode \fB"full"\fR checks that delegation NS records refer to A or AAAA record (both in\-zone and out\-of\-zone hostnames)\&. It also checks that glue addresses records in the zone match those advertised by the child\&. Mode \fB"local"\fR only checks NS records which refer to in\-zone hostnames or that some required glue exists, that is when the nameserver is in a child zone\&.
Mode \fB"full\-sibling"\fR and \fB"local\-sibling"\fR disable sibling glue checks but are otherwise the same as \fB"full"\fR and \fB"local"\fR respectively\&.
@@ -87,6 +87,8 @@ The \fB\-4\fR option forces \fBdig\fR to only use IPv4 query transport\&. The \f
.PP
The \fB\-t\fR option sets the query type to \fItype\fR\&. It can be any valid query type which is supported in BIND9\&. The default query type "A", unless the \fB\-x\fR option is supplied to indicate a reverse lookup\&. A zone transfer can be requested by specifying a type of AXFR\&. When an incremental zone transfer (IXFR) is required, \fItype\fR is set to ixfr=N\&. The incremental zone transfer will contain the changes made to the zone since the serial number in the zone's SOA record was \fIN\fR\&.
.PP
The \fB\-q\fR option sets the query name to \fIname\fR\&. This useful do distingish the \fIname\fR from other arguements\&.
.PP
Reverse lookups \- mapping addresses to names \- are simplified by the \fB\-x\fR option\&. \fIaddr\fR is an IPv4 address in dotted\-decimal notation, or a colon\-delimited IPv6 address\&. When this option is used, there is no need to provide the \fIname\fR, \fIclass\fR and \fItype\fR arguments\&. \fBdig\fR automatically performs a lookup for a name like 11\&.12\&.13\&.10\&.in\-addr\&.arpa and sets the query type and class to PTR and IN respectively\&. By default, IPv6 addresses are looked up using nibble format under the IP6\&.ARPA domain\&. To use the older RFC1886 method using the IP6\&.INT domain specify the \fB\-i\fR option\&. Bit string labels (RFC2874) are now experimental and are not attempted\&.
.PP
To sign the DNS queries sent by \fBdig\fR and their responses using transaction signatures (TSIG), specify a TSIG key file using the \fB\-k\fR option\&. You can also specify the TSIG key itself on the command line using the \fB\-y\fR option; \fIname\fR is the name of the TSIG key and \fIkey\fR is the actual key\&. The key is a base\-64 encoded string, typically generated by \fBdnssec\-keygen\fR(8)\&. Caution should be taken when using the \fB\-y\fR option on multi\-user systems as the key can be visible in the output from \fBps\fR(1) or in the shell's history file\&. When using TSIG authentication with \fBdig\fR, the name server that is queried needs to know the key and algorithm that is being used\&. In BIND, this is done by providing appropriate \fBkey\fR and \fBserver\fR statements in \fInamed\&.conf\fR\&.
...
...
@@ -111,6 +113,9 @@ Set the search list to contain the single domain \fIsomename\fR, as if specified
\fB+[no]search\fR
Use [do not use] the search list defined by the searchlist or domain directive in \fIresolv\&.conf\fR (if any)\&. The search list is not used by default\&.
.TP
\fB+[no]showsearch\fR
Perform [do not perform] a search showing intermediate results\&.
.TP
\fB+[no]defname\fR
Deprecated, treated as a synonym for \fI+[no]search\fR
\fBhost\fR is a simple utility for performing DNS lookups\&. It is normally used to convert names to IP addresses and vice versa\&. When no arguments or options are given, \fBhost\fR prints a short summary of its command line arguments and options\&.
...
...
@@ -74,6 +74,8 @@ The \fB\-t\fR option is used to select the query type\&. \fItype\fR can be any r
.PP
The time to wait for a reply can be controlled through the \fB\-W\fR and \fB\-w\fR options\&. The \fB\-W\fR option makes \fBhost\fR wait for \fIwait\fR seconds\&. If \fIwait\fR is less than one, the wait interval is set to one second\&. When the \fB\-w\fR option is used, \fBhost\fR will effectively wait forever for a reply\&. The time to wait for a response will be set to the number of seconds given by the hardware's maximum value for an integer quantity\&.
.PP
The \fB\-s\fR option tells \fBhost\fR \fInot\fR to send the query to the next nameserver if any server responds with a SERVFAIL response, which is the reverse of normal stub resolver behaviour\&.
.PP
The \fB\-m\fR can be used to set the memory usage debugging flags \fIrecord\fR, \fIusage\fR and \fItrace\fR\&.
<dt><spanclass="sect1"><ahref="Bv9ARM.ch07.html#Access_Control_Lists">Access Control Lists</a></span></dt>
<dt><spanclass="sect1"><ahref="Bv9ARM.ch07.html#id2561005"><span><strongclass="command">chroot</strong></span> and <span><strongclass="command">setuid</strong></span></a></span></dt>
<dt><spanclass="sect1"><ahref="Bv9ARM.ch07.html#id2561050"><span><strongclass="command">chroot</strong></span> and <span><strongclass="command">setuid</strong></span></a></span></dt>
<aname="id2561005"></a><span><strongclass="command">chroot</strong></span> and <span><strongclass="command">setuid</strong></span></h2></div></div></div>
<aname="id2561050"></a><span><strongclass="command">chroot</strong></span> and <span><strongclass="command">setuid</strong></span></h2></div></div></div>
<p>
On UNIX servers, it is possible to run <spanclass="acronym">BIND</span> in a <spanclass="emphasis"><em>chrooted</em></span> environment
(<span><strongclass="command">chroot()</strong></span>) by specifying the "<codeclass="option">-t</code>"
<dd><dl><dt><spanclass="sect2"><ahref="Bv9ARM.ch09.html#historical_dns_information">A Brief History of the <spanclass="acronym">DNS</span> and <spanclass="acronym">BIND</span></a></span></dt></dl></dd>
<aname="historical_dns_information"></a>A Brief History of the <spanclass="acronym">DNS</span> and <spanclass="acronym">BIND</span></h3></div></div></div>
<dt><spanclass="sect2"><ahref="Bv9ARM.ch06.html#server_statement_definition_and_usage"><span><strongclass="command">server</strong></span> Statement Definition and
<dt><spanclass="sect2"><ahref="Bv9ARM.ch06.html#id2554583"><span><strongclass="command">view</strong></span> Statement Definition and Usage</a></span></dt>
<dt><spanclass="sect2"><ahref="Bv9ARM.ch06.html#id2554538"><span><strongclass="command">view</strong></span> Statement Definition and Usage</a></span></dt>
<dt><spanclass="sect2"><ahref="Bv9ARM.ch06.html#id2555382"><span><strongclass="command">zone</strong></span> Statement Definition and Usage</a></span></dt>
<dt><spanclass="sect2"><ahref="Bv9ARM.ch06.html#id2555337"><span><strongclass="command">zone</strong></span> Statement Definition and Usage</a></span></dt>
<dt><spanclass="sect2"><ahref="Bv9ARM.ch06.html#types_of_resource_records_and_when_to_use_them">Types of Resource Records and When to Use Them</a></span></dt>
<dt><spanclass="sect2"><ahref="Bv9ARM.ch06.html#id2559457">Discussion of MX Records</a></span></dt>
<dt><spanclass="sect2"><ahref="Bv9ARM.ch06.html#id2559433">Discussion of MX Records</a></span></dt>
<dt><spanclass="sect1"><ahref="Bv9ARM.ch07.html#Access_Control_Lists">Access Control Lists</a></span></dt>
<dt><spanclass="sect1"><ahref="Bv9ARM.ch07.html#id2561005"><span><strongclass="command">chroot</strong></span> and <span><strongclass="command">setuid</strong></span></a></span></dt>
<dt><spanclass="sect1"><ahref="Bv9ARM.ch07.html#id2561050"><span><strongclass="command">chroot</strong></span> and <span><strongclass="command">setuid</strong></span></a></span></dt>
<dd><dl><dt><spanclass="sect2"><ahref="Bv9ARM.ch09.html#historical_dns_information">A Brief History of the <spanclass="acronym">DNS</span> and <spanclass="acronym">BIND</span></a></span></dt></dl></dd>