Changes between Version 23 and Version 24 of TipAndDoc/network/named


Ignore:
Timestamp:
May 22, 2012 6:56:44 PM (13 years ago)
Author:
mitty
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • TipAndDoc/network/named

    v23 v24  
    2727 > * BIND 9.3 and later: Use TSIG to select the appropriate view. 
    2828 > * Before BIND 9.3: You will need to give the master and slave multiple IP addresses and use those to make sure you reach the correct view on the other machine. 
     29 
     30 * digコマンドを使ったTSIG設定のテスト 
     31 > $ man 1 dig 
     32 >        To sign the DNS queries sent by dig and their responses using 
     33 >        transaction signatures (TSIG), specify a TSIG key file using the -k 
     34 >        option. You can also specify the TSIG key itself on the command line 
     35 >        using the -y option; hmac is the type of the TSIG, default HMAC-MD5, 
     36 >        name is the name of the TSIG key and key is the actual key. The key is 
     37 >        a base-64 encoded string, typically generated by dnssec-keygen(8). 
     38  * $ dig -y key_setting_name:"base64 strings of secret key" axfr target.domain @dns_master.server 
     39  * 「key_setting_name」は、named.confで「key "key_setting_name" { ... };」と設定したものを指定 
     40  * manにも書かれているが、コマンドラインに鍵の中身を直接書くことになるので、シェルのヒストリ等に気をつける 
    2941 
    3042 = disable ipv6 =