Provided by:
manpages-ja_0.5.0.0.20060115-1_all 
loggingãå¥ãèãçãèãçãéµã
æåºæ³
logging {
[ channel channel_name {
( file path_name
[ versions ( number | unlimited ) ]
[ size size_spec ]
| syslog ( kern | user | mail | daemon | auth | syslog | lpr |
news | uucp | cron | authpriv | ftp |
local0 | local1 | local2 | local3 |
local4 | local5 | local6 | local7 )
| null );
[ severity ( critical | error | warning | notice |
info | debug [ level ] | dynamic ); ]
[ print-category yes_or_no; ]
[ print-severity yes_or_no; ]
[ print-time yes_or_no; ]
}; ]
[ category category_name {
channel_name; [ channel_name; ... ]
}; ]
...
};
å®èçŸèãéäœèçåæ³
logging
ã¹ããŒãã¡ã³ãã¯ãããŒã ãµãŒãã«å¯Ÿããæ§ã
ãªçš®é¡ã®ãã°çšãªãã·ã§ã³ã
èšå®ããŸãã ãã®äžã® channel
ãã¬ãŒãºã§ã¯ãåºåæ¹æ³ãšãã©ãŒããããªãã·ã§ã³ãšé倧床ã
ååãšçµã³ã€ããŸãã ãã®ååã¯åŸã§ category
ãã¬ãŒãºã§äœ¿çšããæ§ã
ãªã¡ãã»ãŒãžã¯ã©ã¹ãã©ã®ããã«ãã°ã«èœãããéžæããŸãã
ãã 1 ã€ã® logging
ã¹ããŒãã¡ã³ãã䜿çšããŠãæãã ãå€ãã®ãã£ãã«ãšã«ããŽãªã å®çŸ©ã§-
ãŸããèšå®äžã«ãè€æ°ã® logging ã¹ããŒãã¡ã³ãããã£ãå Žåã æå以å€ã®
logging ã¹ããŒãã¡ã³ãã«å¯ŸããŠã¯èŠåãåºãããŸãã logging
ã¹ããŒãã¡ã³ãã 1 åãååšããªãã£ãå Žåããã°çšã®èšå®ã¯
次ã®ããã«ãªãã§ããã :
logging {
category default { default_syslog; default_debug; };
category panic { default_syslog; default_stderr; };
category packet { default_debug; };
category eventlib { default_debug; };
};
ãã°çšã®èšå®ã¯ã logging
ã¹ããŒãã¡ã³ããããŒã¹ããããããã«ç¢ºç«ãããŸãããããèšå®ãã¡ã€ã«
å
šäœã®åŠçç¶æ³ã«ã€ããŠã®ã¡ãã»ãŒãžããªãã€ã¬ã¯ããããã®ã§ããã°ã
logging
ã¹ããŒãã¡ã³ããæåã«åºãŠããããã«ããªããã°ãªããŸãããããšãã
èšå®ãã¡ã€ã«ã®ããŒã¹ç¶æ³ã衚ãã¡ãã»ãŒãžããªãã€ã¬ã¯ãããããªããŠãã
logging
ã¹ããŒãã¡ã³ãã¯ãã¡ã€ã«ã®å
é ã«çœ®ãããšãå§ããŸããããããããšã«ãã£ãŠã
ããŒãµã®åºãã¡ãã»ãŒãžãå床èšå®ããå¿
èŠãçãããšãæ³æèããŠ
ãã®ã«ãŒã«ãæãåºãå¿
èŠããªããªããŸãã
ãèãç€ãåãè¥ãäŸãèãçãº
ãã°ã®åºåã¯ãã¹ãŠã1 ã€ãŸãã¯ãã以äžã®ããã£ãã«ããžãšæž¡ããŸãã
ãã£ãã«ã¯å¥œãèŠäžæµŠé襪海箞ã§ãæ³å
ããããã®ãã£ãã«ã®å®çŸ©ã«ã¯ããã®ãã£ãã«çšã«éžæããã¡ãã»ãŒãžã
ãã¡ã€ã«ã«èœãããã®ããç¹å¥ãª syslog ãã¡ã·ãªãã£ã«æž¡ãããã®ãã
ãŸãã¯ãæšãŠãããã®ããæå®ããç¯ãå«ãŸããŠããªããŠã¯ãªããŸããã
ãã£ãã«ã®å®çŸ©ã§ã¯ããã£ãã«ãåãåãã¡ãã»ãŒãžã®é倧床ãå¶éãã
ããšããªãã·ã§ã³ã§ã§ãæ³ (ããã©ã«ã㯠info ã§ã)ããŸãã named
ãçæããã¿ã€ã ã¹ã¿ã³ããšã
ã«ããŽãªåãšãé倧床ãå«ãããã©ãããå¶éããããšãã§ãæ³å
ããã©ã«ãã§ã¯ããã® 3 ã€ã®ããããå«ããªãããã«ãªã£ãŠããŸãã
ãã£ãã«ã«å¯Ÿãããã°ã®éãå
ã®ãªãã·ã§ã³ã« null
ãšããåèªã䜿çšãããšããã®ãã£ãã«ã«éãããã¡ãã»ãŒãžã¯ãã¹ãŠ
æšãŠãããããã«ãªããŸãããã£ãã«ã«å¯Ÿãããã®ä»ã®ãªãã·ã§ã³ã¯æå³ã
ãããŸããã
file ç¯ã䜿çšãããšããã°ãã¡ã€ã«ãã©ãã ã倧-
ããªã£ãŠãè¯ãããšããããšãšã ãã°ãã¡ã€ã«ããªãŒãã³ãããããšã«
äœåã®ããŒãžã§ã³ãæ®ãã®ããšããããšã«é¢ããå¶éããåã蟌ãããšãã§-
ãŸãã
ãã°ãã¡ã€ã«ã«å¯Ÿãã size ãªãã·ã§ã³ã¯ãåçŽã«ãã°ã倧-
ããªãã®ãå¶éããåºã倩äºã«ãªããã®ã§ãã ãã°ãã¡ã€ã«ã size
ãè¶
ãããšã ãã°ãã¡ã€ã«ãå床ãªãŒãã³ããããŸã§ named
ã¯ãã¡ã€ã«ã«äœãæžãã¿ãŸãããsize ãè¶
ããŠããŠããèªåçã«ã¯ãã¡ã€ã«ã¯
ãªãŒãã³ãããŸãããããã©ã«ãã§ã¯ããã°ãã¡ã€ã«ã®ãµã€ãºå¶éã¯ãããŸããã
ãã°ãã¡ã€ã«ãªãã·ã§ã³ã« version ã䜿çšãããšã named
ã¯ããã°ãã¡ã€ã«ããªãŒãã³ããããšã瞫䟫ïŒã
襪é¢äž±å¥ªã¢ããããŒãžã§ã³ã®
ååã倿ŽããŠãæå®ããæ°ã ãä¿æããŸããäŸãã°ãlamers.log
ãšãããã¡ã€ã«ã® å€ãããŒãžã§ã³ã 3
ã€ä¿æããããã«éžæããå Žåãlamer.log ããªãŒãã³ããã çŽåã«
lamers.log.1 ãšãããã¡ã€ã«ã¯ lamers.log.2 ãšããååã«å€æŽããã
lamers.log.0 ãšãããã¡ã€ã«ã¯ lamers.log.1 ãšããååã«å€æŽããããããŠ
lamers.log ãšãããã¡ã€ã«ã lamers.log.0
ãšããååã«å€æŽãããŸããããŒãžã§ã³å
ãå·¡åãããã®ã¯ããã©ã«ãã§ã¯ä¿æãããŸããã
ãã§ã«ååšããŠãããã°ãã¡ã€ã«ã¯ã ãã åã«è¿œå ããŠæžãããŸãã unlimited
ã¡çœéçœå¹è®çŸåšã® BIND ã®ãªãªãŒã¹ã§ã¯ 99 ãšå矩ã§ããsize ããã³
versions ãªãã·ã§ã³ã®äœ¿çšäŸã¯æ¬¡ã®éãã§ã :
channel an_example_level {
file "lamers.log" versions 3 size 20m;
print-time yes;
print-category yes;
};
syslog ç¯ã®åŒæ°ã¯ã syslog(3) ããã¥ã¢ã«ããŒãžã«æ¬ºåŒæ°èŽèšã syslog
ãã¡ã·ãªãã£ã衚ããŸãã syslogd
ããã®ãã¡ã·ãªãã£ã«éãããã¡ãã»ãŒãžãã©ã®ããã«æ±ããã«ã€ããŠã¯ã
syslog.conf(5) ããã¥ã¢ã«ããŒãžã«æ¬ºåŒãããŸãã openlog()() 颿°ã« 2
ã€ã®åŒæ°ãã䜿çšããªãããšãŠãå€ãããŒãžã§ã³ã® syslog ã
䜿çšããŠããã·ã¹ãã ãã䜿ãã®å Žåã¯ããã®ç¯ã¯é»ã£ãŠç¡èŠãããŸãã
severity ç¯ã¯ãsyslog ã®ãåªå
床ãã®ããã«åãæ³åãã ããsyslog ã
䜿çšãããããã«ãã¡ã€ã«ãçŽæ¥æžããŠã䜿çšã§ã襪箞海è¹éããŸãã
äžããããé倧床ãããäœãã¬ãã«ã®ã¡ãã»ãŒãžã¯ã
ãã®ãã£ãã«ã«å¯ŸããŠã¯éžæãããŸãããäžããããé倧床
ãããé«ãã¬ãã«ã®ã¡ãã»ãŒãžãåãåãããŸãã
syslog ã䜿ã£ãŠããå Žåã syslog.conf
ã§ã®åªå
床ã«ãã£ãŠãæçµçã«äœãéãæããããæ±ºå®ãããŸãã
äŸãã°ããã£ãã«ã®ãã¡ã·ãªãã£ããã³é倧床ã daemon ããã³ debug
ã«å®çŸ©ããŠãããã syslog.conf ã§ã¯ daemon.warning
ãããã°ã«èœãšããªãããã«ããŠããå Žåã info ããã³ notice
ã®é倧床ãæã£ãã¡ãã»ãŒãžã¯æšãŠãããŠããŸããŸãã ç¶æ³ãéã«ãªãã named
ã warning ããã以äžã®é倧床ãæã£ãã¡ãã»ãŒãžããæžãäžæ°èŠãè²Î
ãªã£ãŠããå Žåã syslogd
ã¯ããã®ãã£ãã«ããåãåã£ãã¡ãã»ãŒãžããã¹ãŠæžãäžªå¢æµ·ç®žä»»éŽè
Î
ãããã°ã¢ãŒãã«ãªã£ãŠããå ŽåããµãŒãã¯ãã£ãšå€ãã®ãããã°æ
å ±ã
æäŸã§ãæ³åãµãŒãã®ãããã°ã¬ãã«ã 0 ãã倧ããªã£ãŠããã°ã
ãããã°ã¢ãŒãã¯éã«ãªã£ãŠããŸããå
šäœã§ã®ãããã°ã¬ãã«ã¯ã -d
ãã©ã°ã«æ£ã®æŽæ°å€ãç¶ããŠæå®ã㊠named
ãµãŒããéå§ãããããŸãã¯ãåããŠãããµãŒãã« SIGUSR1 ã·ã°ãã«ãéã
(äŸãã°ã ndc trace ã䜿ã£ãŠ) ããšã«ãã£ãŠèšå®ããŸãã
å
šäœã§ã®ãããã°ã¬ãã«ã¯ 0 ã«ãèšå®ã§ãâ³æµ·é箞ã¯ããããã°ã¢ãŒãã¯
ç¡å¹ã«ãªããŸãããã®ç¶æ
ã«ã¯ããµãŒãã« SIGUSR2 ã·ã°ãã«ãéã ( ndc
notrace ã䜿ã£ãŠ) ããšã«ãã£ãŠãã§ãæ³å
ãµãŒãã§ã®ãããã°ã¡ãã»ãŒãžã«ã¯ãã¹ãŠãããã°ã¬ãã«ããããŸãã
ãããŠããããã°ã¬ãã«ãé«ãã»ã©ãã詳现ãªåºåã«ãªã£ãŠããŸãã
äŸãã°ãç¹å®ã®ãããã°éå€§åºŠãæ¬¡ã®ããã«æå®ãããã£ãã«
ã§ã¯ããµãŒãããããã°ã¢ãŒãã§ããã°ãã€ã§ããã¬ãã« 3 ãŸãã¯
ãã以äžã®ã¬ãã«ã®ãããã°åºåãåŸãããŸãã
channel specific_debug_level {
file "foo";
severity debug 3;
};
ããã¯ãå
šäœã§ã®ãããã°ã¬ãã«ã«ã¯äŸããŸããã dynamic
é倧床ãæå®ãããã£ãã«ã§ã¯ãã©ã®ã¡ãã»ãŒãžãåºåãããã
決ããããã«ãµãŒãå
šäœã®ãããã°ã¬ãã«ã䜿çšããŸãã
print-time ããªã³ã«ãªã£ãŠããã°ãæ¥ä»ããã³æå»ããã°ã«èœãšãããŸãã
print-time ã¯ãsyslog ãã£ãã«ã«å¯ŸããŠãæå®ã§-
ãŸãããéåžžã¯æå³ã®ãªãããšã§ãã ãªããªããsyslog
ãæ¥ä»ããã³æå»ã¯åºåããããã§ãã print-category
ãèŠæ±ãããŠããå Žåãã¡ãã»ãŒãžã®ã«ããŽãªãåæ§ã«ãã°ã«èœãšãããŸãã
æåŸã«ã print-severity
ããªã³ã«ãªã£ãŠããã°ãã¡ãã»ãŒãžã®é倧床ããã°ã«èœãšãããŸãã print-
ãªãã·ã§ã³ã¯ã©ãããçµåãã§ã䜿ãããšãã§ã
åžžã«æ¬¡ã®ãããªé çªã§åºåãããŸã : ãã㯠time, category, severity
ã®é ã§ãã æ¬¡ã«ç€ºãäŸã¯ã3 ã€ãã¹ãŠã® print- ãªãã·ã§ã³ããªã³ã«ããäŸã§ã
:
28-Apr-1997 15:05:32.863 default: notice: Ready to answer queries.
named ã§ã®ããã©ã«ãã®ãã°ååŸçšã«äœ¿çšããããã£ãã«ã«ã¯ã次ã®ãããªã
äºåã«å®çŸ©ããã 4 ã€ããããŸããã©ã®ããã«ãã®ãã£ãã«ã䜿ãã®ãã«
ã€ããŠã¯æ¬¡ç¯ category _categoryãäŸãèãçãº
ã«ããŽãªã¯ãããããããŸãããã®ãããèŠãããšæããã°ãã©ããžã§ãéã
ããšãã§ãèŠãããªããã°ã¯èŠãªãã§ããŸãããšãã§ãæ³åã«ããŽãªã«å¯ŸããŠ
ãã£ãã«ã®ãªã¹ããæå®ããªãã£ãå Žåã¯ã代ããã« default
ã«ããŽãªã«ãã°ãéãããŸãã default
ã«ããŽãªãæå®ããªãã£ãå Žåãæ¬¡ã®ãããªãããã©ã«ãã® default
ã«ããŽãªãã䜿ãããŸã :
category default { default_syslog; default_debug; };
äŸãšããŠãã»ã¥çµ
è¢è¬ã®ã€ãã³ãããã¡ã€ã«ã«ãã°ãšããŠèœãšããããã
ããã©ã«ãã®ãã®ã³ã°ã®æåã¯ç¶æããããšããŸãããããããããšã次ã®ããã«
æå®ããããšã«ãªãã§ããã :
channel my_security_channel {
file "my_security_file";
severity info;
};
category security { my_security_channel;
default_syslog; default_debug; };
ã«ããŽãªå
ã®ãã¹ãŠã®ã¡ãã»ãŒãžãæšãŠãã«ã¯ã null
ãã£ãã«ãæå®ããŠãã ãã :
category lame-servers { null; };
category cname { null; };
次ã®ãããªã«ããŽãªã䜿çšå¯èœã§ã :
default
ãã¹ãŠæãŸããŸããå€ãã®ã¡ãã»ãŒãžããŸã ã«ããŽãªåããããŠãããã
ãã¹ãŠããã§æãŸããŸããããã«ãã«ããŽãªã«å¯ŸããŠäœã®ãã£ãã«ã
æå®ããªãã£ãå Žåã代ããã« default ã«ããŽãªã䜿ãããŸããdefault
ã«ããŽãªãæå®ããªãã£ãå Žåãæ¬¡ã®ãããªå®çŸ©ã䜿ãããŸã :
category default { default_syslog; default_debug; };
config
ãã€ã¬ãã«ã®èšå®ãã¡ã€ã«åŠçã§ãã
parser
ããŒã¬ãã«ã®èšå®ãã¡ã€ã«åŠçã§ãã
queries
ãµãŒããåãåã£ãåãåããããããã«å¯ŸããŠãçããã°ã¡ãã»ãŒãžãçæããŸãã
lame-servers
``Lame server on ...'' ãšãããããªã¡ãã»ãŒãžã§ãã
statistics
çµ±èšã§ãã
panic
ãµãŒãå
éšã®åé¡ã§ãµãŒãèªäœãã·ã£ããããŠã³ããªããŠã¯ãªããªããªããšã
åé¡ã®èµ·ãææ°é¢ããŽãªãšãã®ã«ããŽãªã®äž¡æ¹ã«ã åé¡ããã°ãšããŠæž-
ãã¿ãŸãã panic
ã«ããŽãªãå®çŸ©ããŠããªãå Žåã«ã¯ã次ã®ãããªå®çŸ©ã䜿ãããŸã :
category panic { default_syslog; default_stderr; };
update
åçãªæŽæ°ã§ãã
ncache
ãã¬ãã£ãã¥ç€å¥ªèœ¡éµé¿ä»»å
xfer-in
ãµãŒããåãåã£ãŠãããŸãŒã³è»¢éã§ãã
xfer-out
ãµãŒããéã£ãŠãããŸãŒã³è»¢éã§ãã
db
ãã¹ãŠã®ããŒã¿ããŒã¹ã®æäœã§ãã
eventlib
ã€ãã³ãã·ã¹ãã ããã®ãããã°æ
å ±ã§ãããã®ã«ããŽãªã«ã¯ããã 1 ã€ã®
ãã£ãã«ãæå®ã§ãâ³ä¿®é¢è¹ç€åªè¥ªé¯äŸ«ïŒã
襯è¹ç€åªè¥ªä»»èŠãŠã¯ãªããŸããã
eventlib ã«ããŽãªãæå®ããªãå Žåã¯ã次ã®ãããªå®çŸ©ã䜿ãããŸã :
category eventlib { default_debug; };
packet
åãåã£ããã±ããããã³éã£ããã±ããã®ãã³ãã§ãããã®ã«ããŽãªã«ã¯ã
ãã 1 ã€ã®ãã£ãã«ãæå®ã§ãâ³ä¿®é¢è¹ç€åªè¥ªé¯äŸ«ïŒã
襯è¹ç€åªè¥ªä»»èŠãŠã¯
ãªããŸãããpacket
ã«ããŽãªãæå®ããªãå Žåã¯ã次ã®ãããªå®çŸ©ã䜿ãããŸã :
category packet { default_debug; };
notify
NOTIFY ãããã³ã«ã§ãã
cname
``... points to a CNAME'' ã®ãããªã¡ãã»ãŒãžã§ãã
security
èš±å¯ããã / èš±å¯ãããªãã£ããªã¯ãšã¹ãã§ãã
os
ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®åé¡ã§ãã
insist
å
éšã®æŽåç¬è¹Ð奪ã®å€±æã§ãã
maintenance
宿çã«è¡ãããã¡ã³ããã³ã¹ã®ã€ãã³ãã§ãã
load
ãŸãŒã³ãžã®ããŒãã¡ãã»ãŒãžã§ãã
response-checks
å¿çã®ãã§ãã¯ããçºçããã¡ãã»ãŒãžã§ããäŸãã°ã ``Malformed response
...'', ``wrong ans. name ...'', ``unrelated additional info ...'',
``invalid RR type ...'', ``bad referral ...'' ãšãã£ããã®ã§ãã
optionsãå¥ãèãçãèãçãéµã
æåºæ³
options {
[ version version_string; ]
[ directory path_name; ]
[ named-xfer path_name; ]
[ dump-file path_name; ]
[ memstatistics-file path_name; ]
[ pid-file path_name; ]
[ statistics-file path_name; ]
[ auth-nxdomain yes_or_no; ]
[ deallocate-on-exit yes_or_no; ]
[ dialup yes_or_no; ]
[ fake-iquery yes_or_no; ]
[ fetch-glue yes_or_no; ]
[ has-old-clients yes_or_no; ]
[ host-statistics yes_or_no; ]
[ host-statistics-max number; ]
[ multiple-cnames yes_or_no; ]
[ notify yes_or_no; ]
[ recursion yes_or_no; ]
[ rfc2308-type1 yes_or_no; ]
[ use-id-pool yes_or_no; ]
[ treat-cr-as-space yes_or_no; ]
[ also-notify yes_or_no; ]
[ forward ( only | first ); ]
[ forwarders { [ in_addr ; [ in_addr ; ... ] ] }; ]
[ check-names ( master | slave | response ) ( warn | fail | ignore); ]
[ allow-query { address_match_list }; ]
[ allow-recursion { address_match_list }; ]
[ allow-transfer { address_match_list }; ]
[ blackhole { address_match_list }; ]
[ listen-on [ port ip_port ] { address_match_list }; ]
[ query-source [ address ( ip_addr | * ) ]
[ port ( ip_port | * ) ] ; ]
[ lame-ttl number; ]
[ max-transfer-time-in number; ]
[ max-ncache-ttl number; ]
[ min-roots number; ]
[ serial-queries number; ]
[ transfer-format ( one-answer | many-answers ); ]
[ transfers-in number; ]
[ transfers-out number; ]
[ transfers-per-ns number; ]
[ transfer-source ip_addr; ]
[ maintain-ixfr-base yes_or_no; ]
[ max-ixfr-log-size number; ]
[ coresize size_spec ; ]
[ datasize size_spec ; ]
[ files size_spec ; ]
[ stacksize size_spec ; ]
[ cleaning-interval number; ]
[ heartbeat-interval number; ]
[ interface-interval number; ]
[ statistics-interval number; ]
[ topology { address_match_list }; ]
[ sortlist { address_match_list|fR }; ]
[ rrset-order { order_spec ; [ order_spec ; ... [ [ };
};
å®èçŸèããèãåäœèçåæ³
options ã¹ããŒãã¡ã³ã㯠BIND ã§äœ¿ãããã°ããŒãã«ãªãã·ã§ã³ã
èšå®ããŸãããã®ã¹ããŒãã¡ã³ãã¯ãèšå®ãã¡ã€ã«äžã§ 1 床ã ãåºçŸã§ãæ³å
ããè€æ°ã®ã¹ããŒãã¡ã³ããåºçŸããå Žåã¯ãæåã«åºçŸããã¹ããŒãã¡ã³ãã
å®éã«äœ¿çšããããªãã·ã§ã³ã決å®ããèŠåãè¡ãããŸããoptions
ã¹ããŒãã¡ã³ãã ååšããªãå Žåã¯ãåãªãã·ã§ã³ãããã©ã«ãã«èšå®ããã
options ãããã¯ã 䜿ãããŸãã
ãåãèå
version
ndc ã³ãã³ãã®åãåããã chaos ã¯ã©ã¹ã® version.bind
åã®åãåãããéããŠãµãŒããã¬ããŒãããã¹ã
åŒçœç®è
éµä»»å
ããã©ã«ãã§ã¯ãµãŒãã®æ¬åœã®ããŒãžã§ã³çªå·ã«ãªã£ãŠããŸããã
ãµãŒãã®ãªãã¬ãŒã¿ã®äžã«ã¯ãã®æååã®æ¹ã奜ã¿ãšãã人ãããŸã (
ãçãèãè¹ãé·åèè«æãåæ±èãæ³ãèŸãèšãããæ³ãåã )ã
directory
ãµãŒãã®äœæ¥ãã£ã¬ã¯ããªã§ããèšå®ãã¡ã€ã«äžã®çµ¶å¯Ÿãã¹ã§ãªã
ãã¹åã¯ãã©ããªãã®ã§ããã®ãã£ã¬ã¯ããªããã®çžå¯Ÿãã¹ãšåãåãããŸãã
倧éšåã®ãµãŒãã®åºåãã¡ã€ã« (äŸãã°ã named.run) ã®ããã©ã«ãã®çœ®-
å Žæã¯ããã®ãã£ã¬ã¯ããªã§ããããããã£ã¬ã¯ããªã®æå®ã
ãªããã°ãäœæ¥ãã£ã¬ã¯ããªã¯ããã©ã«ãã§ ~.
ã«ãªããŸãããã®ãã£ã¬ã¯ããªã¯ããµãŒããèµ·åãããã£ã¬ã¯ããªã§ãã
æå®ããããã£ã¬ã¯ããªã¯çµ¶å¯Ÿãã¹ã§ãªããŠã¯ãããŸããã
named-xfer
å
éšãžã®ãŸãŒã³è»¢éçšã«ãµãŒãã䜿çšãã named-xfer
ããã°ã©ã ãžã®ãã¹åã§ãã
æå®ãããŠããªãå Žåã®ããã©ã«ãã¯ãã·ã¹ãã äŸåã§ã (äŸãã°ã
/usr/sbin/named-xfer ã§ã)ã
dump-file
SIGINT ã·ã°ãã«ããµãŒããåãåã£ããš ( ndc dumpdb
ãéã£ãå Žåã®ããã«) ã«ã
ããŒã¿ããŒã¹ã®ãã³ããèœãšããã¡ã€ã«ãžã®ãã¹åã§ãã
æå®ãããŠããªãå Žåã®ããã©ã«ãã¯ã named_dump.db ã§ãã
memstatistics-file
deallocate-on-exit ã yes ã«ãªã£ãŠããå Žåã«ã
ãµãŒããçµäºæã«ã¡ã¢ãªäœ¿çšçµ±èšãæžã䞪奜䟫ïŒã
襪æé¢åèå¬ä»»å
æå®ãããŠããªãå Žåã®ããã©ã«ãã¯ã named.memstats ã§ãã
pid-file
ãµãŒããèªåã®ããã»ã¹ ID ãæžã䞪奜䟫ïŒã
襪æé¢åèå¬ä»»å
æå®ãããŠããªãå Žåã®ããã©ã«ãã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«
äŸåããŸãããéåžžã¯ã /var/run/named.pid ããã㯠/etc/named.pid
ã§ãã pid-file ã¯ã ndc
ã®ãããªãåäœããŠããããŒã ãµãŒãã«ã·ã°ãã«ãéããã
ããã°ã©ã ã䜿çšããŸãã
statistics-file
ãµãŒãã SIGILL ã·ã°ãã«ã ( ndc stats ãã)
åãåã£ãå Žåã«ãçµ±èšãè¿œå æžãã¿ãããã¡ã€ã«ãžã®ãã¹åã§ãã
æå®ãããŠããªãå Žåã®ããã©ã«ãã¯ã named.stats ã§ãã
ãå±ãçãèšåäœãéããå»ãèœãè
ã³
auth-nxdomain
ããã yes ã®å Žåã AA ãããã¯ãåžžã« NXDOMAIN
ã®å¿çã«ã»ãããããŸããããšããµãŒããå®éã«ã¯ä¿¡é Œã§ã襪çŒéä»»
ãªããŠãã§ãã ããã©ã«ãã§ã¯ã yes ã«ãªã£ãŠããŸãã
å€ããããããœãããŠã§ã¢ãå«ãã®ã§ã
èªåã®ããŠããããšã«ç¢ºä¿¡ãæãŠãªãã§ããã®ã§ããã°ã auth-nxdomain
ããªãã«ããŠã¯ãããŸããã
deallocate-on-exit
ããã yes ã®å Žåã«ã¯ããµãŒãã¯ãçµäºæã«èªåã確ä¿ãããªããžã§ã¯ãã
培åºããŠéæŸããŠã memstatistics-file ã«ã¡ã¢ãªäœ¿çšã¬ããŒããæž-
åºããŸãã ããã©ã«ãã§ã¯ã no
ã«ãªã£ãŠããŸãããªããªãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ã¯ãªãŒã³ã¢ããã
ããããã»ããé«éã ããã§ãã deallocate-on-exit
ã¯ãã¡ã¢ãªãªãŒã¯ãæ€åºããããã«äŸ¿å©ã§ãã
dialup
ããã yes ã®å Žåã«ã¯ããµãŒãã¯ããã¹ãŠã®ãŸãŒã³ãã
èŠæ±æãã€ã€ã«ã«ãããã€ã€ã«ã¢ãããªã³ã¯ãéããŠ
ãŸãŒã³è»¢éãè¡ã£ãŠãããã®ããã«æ±ããŸãã
ãã®ãã€ã€ã«ã¢ãããªã³ã¯ã¯ããã®ãµãŒãããéä¿¡ãå§ãŸã£ãå Žåã«
ç«ã¡äžãããããã®ã§ãã
ããã¯ããŸãŒã³ã®çš®é¡ã«ãã£ãŠç°ãªã广ãããããããŸãŒã³ã®ä¿å®ã«
å°å¿µã§ã襪è²Îç ²èŠè
æ³åããã«ãã£ãŠã heartbeat-interval ããšã« 1
床ãé¡ããã¯ã1 åã®åŒã³åºãã®éãšããçãééã§
ãŸãŒã³ã®ä¿å®ãè¡ããããã«ãªããŸãã
ãã®ãªãã·ã§ã³ã¯ãŸããéåžžã®ãŸãŒã³ä¿å®ã«ããããã©ãã£ãã¯ã
ããããæããããšãã§ãæ³å ããã©ã«ãã¯ã no ã§ãã dialup
ãªãã·ã§ã³ã¯ã zone ã¹ããŒãã¡ã³ãäžã§ãæå®ããããšãã§-
ãŸãããã®å Žåã¯ã options dialup ã¹ããŒãã¡ã³ãã¯äžæžãæ°èŽæ³å
ãŸãŒã³ã master ã§ããå Žåã ãµãŒãã¯ããã¹ãŠã®ã¹ã¬ãŒãã«å¯Ÿã㊠NOTIFY
ãªã¯ãšã¹ããéä¿¡ããããã«ãªããŸãã
ããã«ãã£ãŠãã¹ã¬ãŒãããã§ãã¯ããåŒã³åºããçãèšã芺屬
ã¹ã¬ãŒãããŸãŒã³ãæ€èšŒã§ã襪è²Îç ²å¢è¥ªæµ·ç®žåŠ
ãŸãŒã³ãææ°ã®ãã®ã«ãã奿©ãã§ãæ³ (ãµãŒãã NOTIFY
ããµããŒãããå Žåã§ã)ã
ãŸãŒã³ã slave ããã㯠stub ã§ããå Žåã
ãµãŒãã¯ãéåžžã®ãŸãŒã³ã®ã¢ããããŒãåãåãããæå¶ãã
heartbeat-interval ãæéåãã«ãªã£ããšãäžæŽ©ç¬ãè
飿Šè¥ªè²Îç ²éŽæ³å
fake-iquery
ããã yes ã®å Žåã ãµãŒãã¯ã IQUERY
ãšãããããå€ããªã£ãŠäœ¿ãããŠããªã DNS åãåãããã·ãã¥ã¬ãŒã·ã§ã³
ããŸãã ããã©ã«ã㯠no ã§ãã
fetch-glue
ããã yes ã®å Žå
(ããã©ã«ãã§ã¯ããã§ã)ããµãŒãã¯ã远å ã®å¿ççšããŒã¿ã»ã¯ã·ã§ã³ã
äœãéã«ã¯æã£ãŠããªããç³ããšãªããªãœãŒã¹ã¬ã³ãŒããååŸããŸãã
ãµãŒãã®ã¥ç€å¥ªèœ¡çŽå€§ããªã£ãããç Žå£ããããããªãããã«ãããã
(ãããªããšãã¯ã©ã€ã¢ã³ããããã£ãšå€ãã®ä»äºãèŠæ±ããããšãã
代åãæãããšã«ãªããŸã)ã fetch-glue no ã¯ã recursion no
ãšäžç·ã«äœ¿çšã§ãæ³å
has-old-clients
ãã®ãªãã·ã§ã³ã yes ã«èšå®ããããšãšã次㮠3
ã€ã®ãªãã·ã§ã³ãèšå®ããããšãšã¯ç䟡ã§ã : auth-nxdomain yes ;,
maintain-ixfr-base yes ;, rfc2308-type1 no; has-old-clients ã
auth-nxdomain, maintain-ixfr-base, rfc2308-type1
ãšäžç·ã«äœ¿çšããããšã§èµ·ããããšã¯ãæå®ã®é çªã«ãããŸãã
host-statistics
ããã yes ã§ããå Žåã
ããŒã ãµãŒããšçžäºã«äœçšããåãã¹ãã«å¯ŸããŠçµ±èšãä¿æãããŸãã
ããã©ã«ãã§ã¯ no ã§ãã _host-statistics
ããªã³ã«ãããšãèšå€§ãªéã®ã¡ã¢ãªãæ¶è²»ããå¯èœäžãããŸãã
IC host-statistics-max
ä¿æããæå€§ã®ãã¹ãã¬ã³ãŒãæ°ã§ãã
ãã®éçã«éã£ãããšããã¹ãã®çµ±èšæ
å ±ã«æ°èŠãã¹ãã¯è¿œå ãããŸããã 0
ã«èšå®ãããšãéçã¯ãããŸããã ããã©ã«ãå€ã¯ 0 ã§ãã
maintain-ixfr-base
ããã yes ã®å Žåããã¹ãŠã®åçã«æŽæ°ããããŸãŒã³ã«å¯ŸããŠã åäžã® IXFR
ããŒã¿ããŒã¹ãã¡ã€ã«ãä¿æãããŸãã ãããéã«ãããšã
ãŸãŒã³è»¢éãéåžžã«é«éåå¯èœãª IXFR åãåããã«ããµãŒãã¯çããŸãã
ããã©ã«ã㯠no ã§ãã
multiple-cnames
ããã yes ã§ããå Žåã 1 ã€ã®ãã¡ã€ã³åã«ã€ããŠè€æ°ã® CNAME
ãªãœãŒã¹ã¬ã³ãŒããèš±å¯ãããŸãã ããã©ã«ã㯠no ã§ããè€æ°ã® CNAME
ã¬ã³ãŒããèš±å¯ãããšããããšã¯ãæšæºããã¯
å€ããŠãããæšå¥šãããããšã§ã¯ãããŸããã 以åã®ããŒãžã§ã³ã® BIND
ãè€æ°ã® CNAME ã¬ã³ãŒããæã€ããšãèš±ããŠããã
ãã®ã¬ã³ãŒããããã€ãã®ãµã€ãã§ã¯è² è·ã®ãã©ã³ã¹ãåãããã«
䜿çšãããŠããããšãããè€æ°ã® CNAME ã®ãµããŒããå©çšã§-
ããšããããšã§ãã
notify
ããã yes ã§ããå Žå (ãããããã©ã«ãã§ã)ã
倿Žãè¡ãããã«ãŸãŒã³ãµãŒããä¿¡é Œã§ãèšè±ºè
DNS NOTIFY ã¡ãã»ãŒãžã
éãããã«ãªããŸãã NOTIFY
ã䜿çšãããšããã¹ã¿ãµãŒããšãã®ã¹ã¬ãŒããšã®éã®åæã
æ©ãŸããŸããNOTIFY ã¡ãã»ãŒãžãåãåããçè§£ããã¹ã¬ãŒããµãŒãã¯
ãã®ãŸãŒã³çšã«ãã¹ã¿ãµãŒãã«æ¥ç¶ãããŸãŒã³è»¢éãè¡ãå¿
èŠããããã
ç¹æ€ããŸãããããŠãå¿
èŠãããå Žåã¯çŽã¡ã«ãŸãŒã³è»¢éãéå§ããŸãã
notify ãªãã·ã§ã³ã¯ zone ã¹ããŒãã¡ã³ãå
ã§ãæå®ã§ãæ³åãã®å Žåã¯ã
options notify ã¹ããŒãã¡ã³ãã¯äžæžãæ°èŽæ³å
recursion
ããã yes ã§ããã DNS ã®åãåãããååž°åŠçãèŠæ±ããŠããå Žåã
ãµãŒãã¯ãã®åãåããã«çããããã«å¿
èŠãªä»äºããã¹ãŠè¡ãããšããŸãã
recursion ããªã³ã«ãªã£ãŠããªãå ŽåããµãŒããçãã
ç¥ããªãå Žåã¯ããµãŒãã¯ã¯ã©ã€ã¢ã³ãã«ç
§äŒãè¿ããŸããããã©ã«ãã§ã¯ã
yes ã§ããåè¿°ã® fetch-glue ãåç
§ããŠãã ããã
rfc2308-type1
ããã yes ã§ããã°ããµãŒãã¯ãåŠå®å¿ççšã« SOA ã¬ã³ãŒããšäžç·ã« NS
ã¬ã³ãŒãã éããŸãããããå€ã BIND ãµãŒããæã£ãŠããŠã SOA ãš NS
ã®äž¡æ¹ãå«ãã åŠå®å¿çãçè§£ããªããã©ã¯ãŒãçšãµãŒããšããŠäœ¿çšããŠ
ããå Žåããå€ãããŒãžã§ã³ã® sendmail ãæã£ãŠããå Žåã¯ããã®
ãªãã·ã§ã³ã no ã«èšå®ããå¿
èŠããããŸããæ£ãã解決çã¯ã
ããããå£ãããµãŒãã sendmail ã䜿çšããªãããšã§ããããã©ã«ãã§ã¯ã
ãã®ãªãã·ã§ã³ã¯ no ã§ãã
use-id-pool
ããã yes ã§ããã°ããµãŒãã¯èªåèªèº«ã®æªè§£æ±ºã®åãåãã ID
ã远跡ããŠã éè€ãé¿ããã©ã³ãã äžé®çŒç©è¥ªè²Îç ²éŽæ³åããã«ãã£ãŠã
ãµãŒãã 128 KB ãå€ãã¡ã¢ãªãæ¶è²»ããããã«ãªããŸãã ããã©ã«ã㯠no
ã§ãã
treat-cr-as-space
ããã yes ã®å Žåã ãµãŒãã¯ãã¹ããŒã¹ãã¿ããæ±ãã®ãšåãæ¹æ³ã§ CR
æåãæ±ãããã« ãªããŸããNT ããã㯠DOS
ãã·ã³ã§çæãããŸãŒã³ãã¡ã€ã«ã UNIX ã·ã¹ãã äžã«ããŒããããš-
ã«ããã®ãªãã·ã§ã³ã¯å¿
èŠã§ãããã ããã©ã«ãã§ã¯ããã®ãªãã·ã§ã³ã¯ no
ã§ãã
Also-Notify
also-notify
ãŸãŒã³ã®æ°ããã³ããŒãããŒãããããšãåãåŒä»»ç©ä¿¡ããã NOTIFY
ã¡ãã»ãŒãžãåãåã IP ã¢ãã¬ã¹ã®ã°ããŒãã«ãªã¹ããå®çŸ©ããŸãã
ãã®ãªãã·ã§ã³ã¯ããŸãŒã³ã®ã³ããŒãçŽ æ©ããå
å¯ã®ããµãŒãäžã§ç¢ºå®ã«åæ
ããå©ãã«ãªããŸãã also-notify ãªã¹ãã zone
ã¹ããŒãã¡ã³ãã§äžããããå Žåã options also-notify
ã¹ããŒãã¡ã³ãã¯äžæžãæ°èŽæ³å zone notify ã¹ããŒãã¡ã³ãã no
ã«èšå®ãããŠããå Žåã ã°ããŒãã«ã® also-notify ãªã¹ãã® IP
ã¢ãã¬ã¹ã¯ããã®ãŸãŒã³ã«å¯Ÿãã NOTIFY ã¡ãã»ãŒãžã
éä¿¡ãããŸãããããã©ã«ãã§ã¯ããã®ãªã¹ãã¯ç©ºã§ã (ã°ããŒãã«ãª
notification ãªã¹ãã¯ãªããšããããšã§ã)ã
ãäŸããéãçã
ãã©ã¯ãŒãæ©èœã¯ãå°æ°ã®ãµãŒãäžã§å€§ã淵汜ã
æç¢æªé¢ã£ãã·ã¥ãäœæãã
ããã«äœ¿çšããããšãã§ãæ³åããã«ãã£ãŠãå€éšã®ããŒã ãµãŒããžã®
ãªã³ã¯ãè¶ãããã©ãã£ãã¯ã軜æžã§ãæ³åãã©ã¯ãŒãæ©èœã¯ãçŽæ¥
ã€ã³ã¿ãŒãããã«æ¥ç¶ã§ãèŠãããšãããå€éšã®ãã¹ãåãèŠã€ãåºããã
ãšãããµãŒãã®åãåãããèš±å¯ããããã«ã䜿çšã§ãæ³å
ãã©ã¯ãŒããçºçããã®ã¯ãããããåãåããã«å¯ŸããŠãµãŒãã
æš©éãæãããã¥ç€å¥ªèœ¡çŽç ²ä¿®ççãå
¥ã£ãŠããªãå Žåã ãã§ãã
forward
ãã®ãªãã·ã§ã³ã¯ã forwarders
ãªã¹ãã空ã§ãªãå Žåã«ã ãæå³ããããŸãã first
ãšããå€ãããã©ã«ãã§ããããã®ãš-
ãµãŒãã¯ããŸããã©ã¯ãŒããè¡ããµãŒãã«
åãåãããè¡ãããã©ã¯ãŒããè¡ããµãŒããèŠæ±ã«å¯ŸããŠå¿çããªãå Žåã
èªåã§å¿çãæ¢ããŸãã only
ãæå®ãããå ŽåããµãŒãã¯ããã ãã©ã¯ãŒããè¡ããµãŒãã«åãåããã
è¡ãã ãã§ãã
forwarders
ãã©ã¯ãŒããè¡ãããã«äœ¿çšããã IP
ã¢ãã¬ã¹ãæå®ããŸããããã©ã«ãã§ã¯ã ããã¯ç©ºã®ãªã¹ãã§ã
(ãã©ã¯ãŒããè¡ããŸãã)ã
ãã©ã¯ãŒãæ©èœã¯ããŸãŒã³åäœãããšã«ããŠèšå®ããããšãã§ãæ³å ãã®ãš-
ã¯ãã°ããŒãã«ã®ãã©ã¯ãŒãçšãªãã·ã§ã³ããããŸããŸãªæ¹æ³ã§ äžæžãä»»-
ãããã«ãªããŸãã ç¹å®ã®ãŸãŒã³ã«å¯Ÿãã
å¥ã®ãã©ã¯ãŒãçšãµãŒãã䜿çšããããå¥ã® forward only/first
ã®æ¯ããŸãããããããããããã¯ãŸã£ãããã©ã¯ãŒãããªãã£ãã ã§ãæ³å
ãããªãæ
å ±ã«ã€ããŠã¯ã _
ã®ã»ã¯ã·ã§ã³ãåç
§ããŠãã ããã
BIND 8 ã®ç¥¥è²é¢åŒçœç®è
éµä»»è®â³çŒèŸ°é¥åãªãã©ã¯ãŒãçšã·ã¹ãã ã
æäŸããäºå®ã§ããå
ã«è¿°ã¹ãææ³ã¯åŒã¢æµ·ãµããŒããããäºå®ã§ãã
ãè«ãçãçãèãÐãå¥ã¯
ãµãŒãã¯ãæåŸ
ããã¯ã©ã€ã¢ã³ãã®é¢ä¿ã«åºã¥ããŠãã¡ã€ã³åããã§ãã¯ã§-
ãŸãã äŸãã°ããã¹ãåãšããŠäœ¿çšããããã¡ã€ã³åã¯ãæ£åœãªãã¹ãåã
å®çŸ©ããŠãã RFC ã«æºæ ããããšããç¹ã§ãã§ãã¯ãããŸãã
ãã§ãã¯æ¹æ³ã«ã¯ 3 éãã®ããæ¹ãå©çšå¯èœã§ã :
ignore
äœã®ãã§ãã¯ãè¡ãããŸããã
warn
æåŸ
ããã¯ã©ã€ã¢ã³ãã®é¢ä¿ããååããã§ãã¯ããŸããäžæ£ãªååã¯
ãã°ã«æžãããŸãããåŠçã¯æ®éã«ç¶ç¶ããŸãã
fail
æåŸ
ããã¯ã©ã€ã¢ã³ãã®é¢ä¿ããååããã§ãã¯ããŸããäžæ£ãªååã¯
ãã°ã«æžãããã«ãŒã«ã«åããªãããŒã¿ã¯æåŠãããŸãã
ãµãŒãã¯ãååã 3 ã€ã®ãšãªã¢ã§ãã§ãã¯ã§ãæ³ : ãã¹ã¿ãŸãŒã³ãã¡ã€ã«ã
ã¹ã¬ãŒããŸãŒã³ãã¡ã€ã«ããããŠããµãŒããçºè¡ããåãåãããžã®å¿ç ã§ãã
check-names response fail
ãæå®ãããŠãããã¯ã©ã€ã¢ã³ãã®åãåããã«å¯Ÿããå¿çã
ã¯ã©ã€ã¢ã³ãã«äžæ£ãªååãéãå¿
èŠã®ãããã®ã§ãã£ãå Žåã ãµãŒãã¯ã
REFUSED å¿çã³ãŒããã¯ã©ã€ã¢ã³ãã«éããŸãã
ããã©ã«ãã¯ã次ã®éãã§ã :
check-names master fail;
check-names slave warn;
check-names response ignore;
check-names ã¯ã zone ã¹ããŒãã¡ã³ãã§ãæå®ã§ãæ³åãã®å Žåã options
check-names ã¯äžæžãæ°èŽæ³å zone ã¹ããŒãã¡ã³ãã§äœ¿çšããå Žåã
ãšãªã¢ã¯æå®ãããŸãã (ãªããªãããŸãŒã³ã®çš®é¡ãããšãªã¢ã¯æšæž¬ã§ã
ããã§ã)ã
ãâããæãæµå埡
ãµãŒããžã®ã¢ã¯ã»ã¹ã¯ãã¢ã¯ã»ã¹ãèŠæ±ããã·ã¹ãã ã® IP ã¢ãã¬ã¹ ãŸãã¯å
±-
ç§å¯éµã«åºã¥ããŠå¶éããããšãã§ãæ³å
ã¢ã¯ã»ã¹åºæºãã©ã®ããã«æå®ãããã«ã€ããŠã®è©³çްã¯ã _
ãåç
§ããŠãã ããã
allow-query
ã©ã®ãã¹ããéåžžã®åãåããããããšãã§ã襪ãæå®ããŸãã allow-query
ã¯ã zone ã¹ããŒãã¡ã³ãã§ãæå®ã§ãæ³åãã®å Žåã options allow-query
ã¹ããŒãã¡ã³ããäžæžãéŽæ³åãããallow-query ãªãã·ã§ã³ã
æå®ãããŠããªãå Žåã¯ãããã©ã«ãã¯ã
ãã¹ãŠã®ãã¹ãããã®åãåãããèš±å¯ããŸãã
allow-recursion
ã©ã®ãã¹ããååž°çãªåãåãããå¯èœããæå®ããŸãã
æå®ãããŠããªãå Žåã¯ã
ããã©ã«ãã§ã¯å
šãŠã®ãã¹ãããååž°çãªåãåãããã§ãæ³å
allow-transfer
ã©ã®ãã¹ãããŸãŒã³è»¢éããµãŒãããåãåãããšãèš±å¯ããããã
æå®ããŸãã allow-transfer ã¯ã zone ã¹ããŒãã¡ã³ãã§ãæå®ã§-
ãŸãããã®å Žåã options allow-transfer ã¹ããŒãã¡ã³ãã¯äžæž-
ãããŸãããããallow-transfer ãªãã·ã§ã³ã
æå®ãããŠããªãå Žåã¯ãããã©ã«ãã§ã¯ã
ãã¹ãŠã®ãã¹ãããã®è»¢éãèš±å¯ããŸãã
blackhole
ãµãŒããåãåãããåãåããªãããã«ãªã£ãããåãåããã解決ããããã«
䜿çšããªãããã«ãªãã¢ãã¬ã¹ã®ãªã¹ããæå®ããŸãããããã®ã¢ãã¬ã¹ããã®
åãåããã¯ãå¿çãããããšã¯ãããŸããã
ãããéµãç¹ãäŸãÐãçã¹
ãµãŒããåãåããã«çããã€ã³ã¿ãã§ãŒã¹ãªãã³ã«ããŒãã¯ã listen-on
ãªãã·ã§ã³ã䜿ã£ãŠæå®ããããšãã§ãæ³å listen-on
ã¯ããªãã·ã§ã³ã®ããŒãããã³ã¢ãã¬ã¹ããããªã¹ããåããŸãã
ãµãŒãã¯ãã¢ãã¬ã¹ããããªã¹ãã§èš±å¯ãããã€ã³ã¿ãã§ãŒã¹å
šãŠã§åŸ
æ©ããŸãã
ããŒããæå®ããªãå Žåã¯ã53 çªããŒãã䜿ãããŸãã
listen-on ã¹ããŒãã¡ã³ããè€æ°ãã£ãŠãè¯ãã§ããäŸãã°ã
listen-on { 5.6.7.8; };
listen-on port 1234 { !1.2.3.4; 1.2/16; };
ã§ã¯ãIP ã¢ãã¬ã¹ã 5.6.7.8 ã®ãã·ã³çšã«ããŒã ãµãŒãã« 53
çªããŒãã®äœ¿çšã èš±å¯ãã1234 çªããŒãã 1.2
ã®ãããã¯ãŒã¯ã«ããŠãIPã¢ãã¬ã¹ã 1.2.3.4 ã§ã¯ãªã
ãã·ã³ã«äœ¿çšãèš±å¯ããŸãã
listen-on ãæå®ãããŠããªãå Žåã¯ããµãŒãã¯ããã¹ãŠã®ã€ã³ã¿ãã§ãŒã¹äžã§
53 çªããŒãã§ã® åŸ
æ©ãããŸãã
åç¬ããåè
ãéãæãâãçãèã¹
ãµãŒããåãåããã«å¯Ÿããçãç¥ããªãå Žåããã®ãµãŒãã¯ãä»ã®
ããŒã ãµãŒãã«åãåãããè¡ããŸãã query-source
ã¯ãããããåãåããã«äœ¿çšãããã¢ãã¬ã¹ããã³ããŒããæå®ããŸãã
address ã * ã ã£ãããçç¥ãããŠããå Žåãã¯ã€ã«ãã«ãŒã IP ã¢ãã¬ã¹ (
INADDR_ANY ) ã䜿çšãããŸãã port ã *
ã ã£ãããçç¥ãããŠããå Žåãç¹æš©ã®ãããªãããŒããã©ã³ãã ã«
䜿çšãããŸããããã©ã«ãã§ã¯
query-source address * port *;
ã§ãã
泚 : query-source ã¯ãçŸåš UDP åãåããã®ã¿é©çšãããŸãã TCP
åãåããã«ã¯ãåžžã«ã¯ã€ã«ãã«ãŒã IP ã¢ãã¬ã¹ãšã©ã³ãã ã«éžã°ãã
ç¹æš©ã®ãããªãããŒãã䜿çšãããŸãã
ãåãçãé¹è»æšé
max-transfer-time-in
ããã§æå®ãããæéããé·ãåäœããŠããå
éšãžã®ãŸãŒã³è»¢é ( named-xfer
ããã»ã¹) ãçµäºããŸãã ããã©ã«ãã§ã¯ã120 å (2 æé) ã§ãã
transfer-format
ãµãŒã㯠2 çš®é¡ã®ãŸãŒã³è»¢éæ¹æ³ããµããŒãããŠããŸãã one-answer
転éããããªãœãŒã¹ã¬ã³ãŒãããããã«ã€ã㊠1 ã€ã® DNS
ã¡ãã»ãŒãžã䜿çšããŸãã many-answers ã§ã襪äžé€çã®ãªãœãŒã¹ã¬ã³ãŒãã
1 ã€ã®ã¡ãã»ãŒãžã«æŒã蟌ã¿ãŸãã many-answers
ã®æ¹ãå¹ççã§ã¯ãããŸãããBIND 8.1 ããã³ããããã®åœãã£ã BIND
4.9.5 ã§ã®ã¿ çè§£ããããã®ã§ããããã©ã«ãã§ã¯ã one-answer
ã«ãªããŸãã transfer-format ã¯ã server
ã¹ããŒãã¡ã³ãã䜿çšããŠãµãŒãåäœã§äžæžãå¢è¥ªæµ·ç®žã§ãæ³å
transfers-in
åæã«åäœãããããšã®ã§ãè©çç€æé¢åçœé¹œæšµã®æå€§å€ã§ãã
ããã©ã«ã㯠10 ã§ãã transfers-in
ã®æ°ãå¢ãããšãã¹ã¬ãŒãã®ãŸãŒã³ã®åæãæ©ãŸããŸãããããŒã«ã«ã·ã¹ãã ã®è² è·ã
äžãã£ãŠããŸãæãããããŸãã
transfers-out
ãã®ãªãã·ã§ã³ã¯ã祥èµ
åæã«åäœããå€éšãžã®ãŸãŒã³è»¢éæ°ãå¶éããããã«äœ¿çšãã
äºå®ã§ããçŸåšãææ³ã¯ãã§ãã¯ããŠããŸããããã以äžã®ããšã¯ç¡èŠããŠããŸãã
transfers-per-ns
ãããªã¢ãŒãã®ããŒã ãµãŒãããåæã«å®è¡ã§ãè©çç€æé¢åçœé¹œæšµ (
named-xfer ããã»ã¹) ã®æå€§å€ã§ããããã©ã«ã㯠2 ã§ãã
transfers-per-ns
ã®æ°ãå¢ãããšãã¹ã¬ãŒããŸãŒã³ã®åæã¯æ©ãŸããŸããããªã¢ãŒãã®ããŒã ãµãŒãã®
è² è·ãäžãã£ãŠããŸãæãããããŸãã transfers-per-ns ã¯ã server
ã¹ããŒãã¡ã³ãã® transfers ãã¬ãŒãºã䜿çšããŠãµãŒãåäœã§äžæž-
ããããšãã§ãæ³å
transfer-source
transfer-source
ã¯ããµãŒããå
éšã«è»¢éãããŸãŒã³ããã¹ãŠååŸããããã«äœ¿çšããã TCP
ã³ãã¯ã·ã§ã³ãš ã©ã®ããŒã«ã«ã¢ãã¬ã¹ãšãçµã³ã€ããããããæ±ºå®ããŸãã
ãããèšå®ãããŠããªãå Žåã
ã·ã¹ãã ãå¶åŸ¡ããŠããããã©ã«ãå€ã«èšå®ãããŸãã ãã®å€ã¯ãéåžžã
ãªã¢ãŒãåŽã®çµç«¯ã«ãæãè¿ããã€ã³ã¿ãã§ãŒã¹ã®ã¢ãã¬ã¹ã«ãªããŸãã
ãã®ã¢ãã¬ã¹ã¯ãããæå®ãããŠããã®ãªãããªã¢ãŒãåŽã®çµç«¯ã®è»¢éãŸãŒã³çšã®
allow-transfer ãªãã·ã§ã³ã§ç»å ŽããŠããªããŠã¯ãªããŸããã
ãã®ã¹ããŒãã¡ã³ãã¯ããã¹ãŠã®ãŸãŒã³ã® transfer-source
ãèšå®ããŸãããèšå®ãã¡ã€ã«äžã®ãŸãŒã³ãããã¯å
ã« transfer-source
ã¹ããŒãã¡ã³ããå«ããããšã§ãŸãŒã³åäœã§äžæžãå¢è¥ªæµ·ç®žã§ãæ³å
ãèãå®ãçãåãå¯åé
å€çš®ã®ã·ã¹ãã ãªãœãŒã¹ããµãŒããã©ããŸã§äœ¿çšããŠãããå¶éå¯èœã§ãã
ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ãã£ãŠã¯ã
ãã®å¶éãããã€ããµããŒãããŠããªããã®ããããŸãã
ããããã·ã¹ãã ã§ã¯ããµããŒããããŠããªãå¶éã䜿çšãããšèŠåãçºçããŸãã
ãŸãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ãã£ãŠã¯ã
ãªãœãŒã¹å¶éèªäœããµããŒãããŠããªããã®ã
ãããŸããããããã·ã¹ãã ã§ã¯ã
cannot set resource limits on this system
ãšããã¡ãã»ãŒãžããã°ã«æµçæ°èŽæ³å
ãªãœãŒã¹å¶éãæå®ããéã«ã¯ãã¹ã±ãŒã«ãå€ããå€ã䜿çšããããšãã§ãæ³å
äŸãã°ã1 ã®ã¬ãã€ãã®å¶éãæå®ãããå Žåã«ã 1G ã 1073741824
ã®ä»£ããã«äœ¿çšããããšãã§ãæ³å unlimited
ã¯ãç¡å¶éã«ãªãœãŒã¹ã䜿çšããã
ã€ãŸããå©çšå¯èœãªæå€§ã®éã®ãªãœãŒã¹ãèŠæ±ããŸãã default
ã¯ããµãŒããéå§ãããšãåå¹ã ã£ãå¶éå€ã䜿çšããŸãã 詳现ã«ã€ããŠã¯ã
_size_spec ã®é
ãåç
§ããŠãã ããã
coresize
ã³ã¢ãã³ãã®æå€§ãµã€ãºã§ããããã©ã«ãå€ã¯ default ã§ãã
datasize
ãµãŒãã䜿çšã§ã襯åŠçœç¹ç®çè
èè€èçè²ä»»åããã©ã«ãå€ã¯ default
ã§ãã
files
ãµãŒããåæã«ãªãŒãã³ã§ã襯䟫ïŒã
襪èè€èºç€ä»»åããã©ã«ãå€ã¯
unlimited ã§ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«ãã£ãŠã¯ãunlimited
ãšããå€ãèšå®ã§ãæ€ ã«ãŒãã«ããµããŒãã§-
ããªãŒãã³ãããã¡ã€ã«ã®æå€§å€ã 決å®ã§ãèŠãçŒéããããšã«
泚æããŠãã ãããããããã·ã¹ãã ã§ã¯ã unlimited
ãéžæãããšããµãŒãã getrlimit(RLIMIT_NOFILE) ããåŸããã rlim_max
ã®å€ãããå€§ãæ·µäŸ«ïŒã
èšç€ééŽèŸ°èšéŽæ³ã sysconf(_SC_OPEN_MAX)
ãè¿ããŠããŸãããšã«ãªããŸãã å®éã®ã«ãŒãã«ã®å¶éå€ããã®å€ããã倧-
ãå Žåã¯ã limit files ã䜿çšããŠãæç€ºçã«å¶éå€ãæå®ããŠãã ããã
max-ixfr-log-size
max-ixfr-log-size ã¯ã-
æ¥ã®ãµãŒãã®ãªãªãŒã¹ã§ã¯ãã€ã³ã¯ãªã¡ã³ã¿ã«ãŸãŒã³è»¢éçšã«ä¿æããŠãã
ãã©ã³ã¶ã¯ã·ã§ã³ãã°ã®å€§ãæ°æ£éãèšããããã«äœ¿çšããäºå®ã§ãã
stacksize
ãµãŒãã䜿çšã§ã襯奜ç¹å¥ªã¡ã¢ãªã®æå€§éã§ããããã©ã«ãå€ã¯ default
ã§ãã
å®èæçãæ·ãç¹ãå¥ããééå²é
cleaning-interval
ãµãŒãã¯ã cleaning-interval åããšã«æéã®åãããªãœãŒã¹ã¬ã³ãŒãã-
ã£ãã·ã¥ããåé€ããŸãã ããã©ã«ã㯠60 åã§ããããã 0
ã«èšå®ãããŠãããšãè® å®æçã«-
ã£ãã·ã¥ãã¯ãªãŒãã³ã°ãããããšã¯ãããŸããã
heartbeat-interval
ãµãŒãã¯ããã®ééãéããã°ãã€ã§ã dialup yes
ã®å°ã®ã€ãããŸãŒã³ãã¹ãŠã«å¯ŸããŠãŸãŒã³ç®¡çã¿ã¹ã¯ãå®è¡ããŸãã
ããã©ã«ãã§ã¯ 60 åã§ããé©åãªå€ã¯ 1 æ¥ (1440 å) ãŸã§ã§ãã ãã®å€ã
0 ã«èšå®ãããŠããå Žåã
ãããã®ãŸãŒã³ã«å¯ŸãããŸãŒã³ç®¡çã¯å®è¡ãããŸããã
interface-interval
ãµãŒãã¯ã interface-interval
åããšã«ãããã¯ãŒã¯ã€ã³ã¿ãã§ãŒã¹ãªã¹ããã¹ã¥ç€éµéŽæ³å
ããã©ã«ãã§ã¯ 60 åã§ãã ãã®å€ã 0 ã«èšå®ãããŠããå Žåã
ã€ã³ã¿ãã§ãŒã¹ã®ã¹ã¥ç€éµé®åÎéè®âªçè¢äŸ«ïŒã
襪 ããŒãããããš-
ã ãã§ããã¹ã¥ç€éµéŽæçŽåŸ
æ©ã¿ã¹ã¯ (listener) ã¯ãã©ã®
æ°ããã€ã³ã¿ãã§ãŒã¹äžã§ãå§åããŸã (ãã®ã¿ã¹ã¯ã listen-on
ã®èšå®ããããŠããŠèš±å¯ãããŠããå Žåã§ã)ã
åãé€ãããã€ã³ã¿ãã§ãŒã¹äžã§åäœããŠããåŸ
æ©ã¿ã¹ã¯ã¯ãæ¶å»ãããŸãã
statistics-interval
ããŒã ãµãŒãã®çµ±èšã statistics-interval åããšã«ãã°ã«-
é²ãããŸããããã©ã«ã㯠60 ã§ãã ãã®å€ã 0 ã«èšå®ãããŠããå Žåã
äœã®çµ±èšãæµçæ°èŽæ³æŠéµ
ãèãæ«ãè¹ãž
ããŒã ãµãŒãã®ãªã¹ãããåãåããå
ã®ããŒã ãµãŒãããµãŒãã 1 ã€éžã¶ãš-
ã ä»ã®ç¹ã§ã¯ãã¹ãŠå¯Ÿçã§ããå Žåããã®ãµãŒãã¯ã
èªåèªèº«ããããããžçã«æãè¿ããã®ãéžã³ãŸãã topology
ã¹ããŒãã¡ã³ãã¯ãã¢ãã¬ã¹ããããªã¹ãããšãã
ç¹å¥ãªæ¹æ³ã§ãã®ãªã¹ããè§£éããŸãã
ããããã®äžçªäžã®ãªã¹ãèŠçŽ ã¯è·é¢ãå²ãåœãŠãããŠããŸãã
ç¡å¹ã«ãããŠããªãèŠçŽ ã¯ããªã¹ãäžã®äœçœ®ã«åºã¥ããŠè·é¢ãååŸããŸããããã§ã
ãªã¹ãã®å
é ã«ãããããå°ç¹ãè¿ããã°è¿ãã»ã©ããµãŒããšèŠçŽ ãšã®è·é¢ã
è¿ãããšã«ãªããŸãã
ç¡å¹ã«ãããŠãããããã«ã¯ããµãŒãããã®è·é¢ã®æå€§ãå²ãåœãŠãããŸãã
ããããããã®ããªãå Žåã¯ããã®ã¢ãã¬ã¹ã¯ãç¡å¹ã«ãããŠããªããªã¹ãã®èŠçŽ ã®
ã©ããããé ãè·é¢ãååŸããŸããäŸãã°ã
topology {
10/8;
!1.2.3/24;
{ 1.2/16; 3/8; };
};
ã®å Žåã§ã¯ããããã¯ãŒã¯ 10 äžã®ãµãŒããæã奜ãŸãããã®ã«ãªããŸãã
次ãããããã¯ãŒã¯ 1.2.0.0 (ããããã¹ã¯ã 255.255.255.0) äžã®ãã¹ã
ããã³ãããã¯ãŒã¯ 3 äžã®ãã¹ãã§ããã ãããã¯ãŒã¯ 1.2.3
(ããããã¹ã¯ã 255.255.255.0) äžã®ãã¹ãã¯é€å€ãããŸãã
ãã®ãããã¯ãŒã¯äžã®ãã®ã¯ãã©ããããéžã°ãã«ãããã®ã§ãã
ããã©ã«ãã®ããããžã¯
topology { localhost; localnets; };
ã§ãã
ãèãå®ãçãå¥ãèãéãçãåãéãå®ãçã
è€æ°ã® RR (蚳泚: ãªãœãŒã¹ã¬ã³ãŒã) ãè¿ã£ãŠãããšãéåžžããŒã ãµãŒãã¯ã
ãèãÎãéµãçãè¹ãåã ã§ããããè¿ããŸãã ããªãã¡ãåèŠæ±ã®åŸã«ãæåã® RR
ããªã¹ãã®æåŸã«çœ®ãããŸãã RR
ã®é çªã決ãŸã£ãŠããªãã®ã§ãããã§åé¡ãããŸããã
ã¯ã©ã€ã¢ã³ãã®ãªãŸã«ãã®ã³ãŒããããããã® RR ãé©åã«
æ§æããªãããªããŠã¯ãªããŸãããããªãã¡ãä»ã®ã¢ãã¬ã¹ãããã
ããŒã«ã«ãããäžã®ä»»æã®ã¢ãã¬ã¹ãåªå
ããŠäœ¿çšãããšããããšã§ãã
ããããªããããã¹ãŠã®ãªãŸã«ããããããããšãã§ãçè
é©åã«èšå®ãããŠããããã§ã¯ãããŸããã
ã¯ã©ã€ã¢ã³ããããŒã«ã«ãµãŒãã䜿çšããŠãããšãâ²æ©çœäŒ°çŒåŠâ²ã©ã€ã¢ã³ãã®
ã¢ãã¬ã¹ã«åºã¥ãããœãŒããå®è¡ã§ãæ³åãã®ãœãŒãã®ããã«ã¯ã
ãã ããŒã ãµãŒããèšå®ããã ãã§ããããã¹ãŠã®ã¯ã©ã€ã¢ã³ããèšå®ãã
å¿
èŠã¯ãããŸããã
sortlist ã¹ããŒãã¡ã³ãã¯ãã¢ãã¬ã¹ããããªã¹ãããšãã topology
ã¹ããŒãã¡ã³ãããæŽã«å¢ããç¹å¥ãªæ¹æ³ã§ãªã¹ããè§£éããŸãã
ãœãŒããªã¹ãäžã®åå
é ã®ã¹ããŒãã¡ã³ãã¯ã ããèªèº«ã1 ã€ãŸã㯠2
ã€ã®èŠçŽ ãæã£ã
æç€ºçãªã¢ãã¬ã¹ããããªã¹ãã§ãªããŠã¯ãªããŸãããåå
é ã®ãªã¹ãã®æåã®èŠçŽ
(IP ã¢ãã¬ã¹ãIP ã®ãã¬ãã£ãã¯ã¹ãACL åã
ãããã¯ãã¹ããããã¢ãã¬ã¹ããããªã¹ã)
ã«å¯ŸããããããèŠã€ãããŸã§ãåãåããå
ã®ã¢ãã¬ã¹ããã§ãã¯ããŸãã
ã²ãšãã³åãåããå
ã®ã¢ãã¬ã¹ãããããããªãã
å
é ã®ã¹ããŒãã¡ã³ãããã 1 ã€ã®èŠçŽ ã®ã¿ã®å Žåã
åãåããå
ã®ã¢ãã¬ã¹ãšãããããèŠçŽ ãã®ãã®ã
å¿çã®ã¢ãã¬ã¹ãéžæããããã«äœ¿çšããããããå¿çã®å
é ã«ç§»åããŸãã
ã¹ããŒãã¡ã³ãã 2 ã€ã®èŠçŽ ãæã£ããªã¹ãã§ãã£ãå Žåã2 çªç®ã®èŠçŽ ã¯ã
topology ã¹ããŒãã¡ã³ãã®ã¢ãã¬ã¹ããããªã¹ãã®ããã«æ±ãããŸãã
åå
é èŠçŽ ã«ã¯ã
è·é¢ãå²ãåœãŠãããŠãããæãçãè·é¢ãæã£ãå¿çäžã®ã¢ãã¬ã¹ãã
ãã®å¿çã®å
é ã«ç§»åãããŸãã
次ã®äŸã§ã¯ããã¹ãããèªèº«ã®ã¢ãã¬ã¹ããåãåã£ãåãåããã¯ã
ããŒã«ã«ã«æ¥ç¶ããã
ãããã¯ãŒã¯äžã®ã¢ãã¬ã¹ãåªå
ãããããªå¿çãåãåããŸãã
次ã«åªå
ãããã®ãã 192.168.1/24
ãããã¯ãŒã¯äžã®ã¢ãã¬ã¹ã§ããã®åŸã«ã192.168.2/24 ããã㯠192.168.3/24
ãããã¯ãŒã¯ããæ³å æåŸã® 2
ã€ã®ãããã¯ãŒã¯éã«ã¯ã©ã¡ããåªå
ãã¯ç€ºãããŠããŸããã 192.168.1/24
ãããã¯ãŒã¯äžã®ãã¹ãããåãåã£ãåãåããã¯ã
ãã®ãããã¯ãŒã¯äžã®ä»ã®ã¢ãã¬ã¹ã 192.168.2/24 ããã³ 192.168.3/24
ãããã¯ãŒã¯ãããåªå
ããŸãã 192.168.4/24 ããã㯠192.168.5/24
ãããã¯ãŒã¯äžã® ãã¹ãããåãåã£ãåãåããã¯ã
çŽæ¥æ¥ç¶ããããããã¯ãŒã¯äžã®ã¢ãã¬ã¹ãåªå
ãã ã ãã§ãã
sortlist {
{ localhost; // ãã ããŒã«ã«ãã¹ããªã
{ localnets; // 次ã®ãããäžã§
192.168.1/24; // æåã«ãã£ãããããã®ã«ãã
{ 192,168.2/24; 192.168.3/24; }; }; };
{ 192.168.1/24; // ãã ã¯ã©ã¹ C 192.168.1 äžãªã
{ 192.168.1/24; // .1 ãããã¯ã.2 ã .3 ã䜿çšãã
{ 192.168.2/24; 192.168.3/24; }; }; };
{ 192.168.2/24; // ãã ã¯ã©ã¹ C 192.168.2 äžãªã
{ 192.168.2/24; // .2 ãããã¯ã.1 ã .3 ã䜿çšãã
{ 192.168.1/24; 192.168.3/24; }; }; };
{ 192.168.3/24; // ãã ã¯ã©ã¹ C 192.168.3 äžãªã
{ 192.168.3/24; // .3 ãããã¯ã.1 ã .2 ã䜿çšãã
{ 192.168.1/24; 192.168.2/24; }; }; };
{ { 192.168.4/24; 192.168.5/24; }; // .4 ã .5 ãªã
}; // ãã®ããããåªå
ãã
};
次ã®äŸã¯ãããŒã«ã«ãã¹ãããã³çŽæ¥æ¥ç¶ããããããã¯ãŒã¯äžã®ãã¹ãã«å¯Ÿããã
çã«ããªã£ãæ¯ããŸããæäŸãããã®ã§ãã ããã¯ãBIND 4.9.x
ã§ã®ã¢ãã¬ã¹ã®ãœãŒãã®æ¯ããŸããš
䌌ãŠããŸããããŒã«ã«ãã¹ãããã®åãåããã«å¯ŸããŠéãããå¿çã¯ã
çŽæ¥æ¥ç¶ããã ãããã¯ãŒã¯äžã®ãã¹ããåªå
ããŸãã
ä»ã®çŽæ¥æ¥ç¶ããããããã¯ãŒã¯äžã®ãã¹ãããã®
åãåããã«å¯ŸããŠéãããå¿çã¯ã
åããããã¯ãŒã¯äžã®ã¢ãã¬ã¹ãåªå
ããã§ãããã
ãã®ä»ã®åãåããã«å¯Ÿããå¿çã«ã€ããŠã¯ãœãŒããããŸããã
sortlist {
{ localhost; localnets; };
{ localnets; };
};
RRsetãåé èçåµä»äœã
å¿çäžã«è€æ°ã®ã¬ã³ãŒããè¿ãããŠããå Žåã
ãã®å¿çäžã«ã¬ã³ãŒããã©ã®é çªã§çœ®ããããã èšå®ããã®ã-
çãªããšããããŸãã
äŸãã°ããããŸãŒã³ã«å¯Ÿããã¬ã³ãŒãã¯ããŸãŒã³ãã¡ã€ã«ã§
å®çŸ©ãããé çªã§åžžã«è¿ãããããã«èšå®ããããããããŸããã ãããã¯ã
ã¬ã³ãŒããè¿ããããšãçž«èéµç¬ç瞫蜡ç€å¥ªäŸ«è¥ªæ°èŽè¥ªè²Îç ²éŽçã箞ãÎæµ·ç®ž
ããã§ãããã rrset-order ã¹ããŒãã¡ã³ãã䜿çšãããšã
è€æ°ã¬ã³ãŒããå«ãŸããå¿çäžã®ã¬ã³ãŒãã®é çªã èšå®ããããšãã§-
ãŸããé çªãå®çŸ©ãããŠããªãå Žåãããã©ã«ãã§ã¯ãå·¡åé (ã©ãŠã³ãããã³)
ã«ãªããŸã
order_spec ã¯æ¬¡ã®ããã«å®çŸ©ãããŠããŸã :
[ class class_name ][ type type_name ][ name "FQDN" ] order ordering
ã¯ã©ã¹ãæå®ãããŠããªãå Žåãããã©ã«ã㯠ANY ã§ãã Ictype
ãæå®ãããŠããªãå Žåãããã©ã«ã㯠ANY ã§ãã
ååãæå®ãããŠããªãå Žåãããã©ã«ã㯠"*" ã§ãã
ordering ã®æ£åœãªå€ã«ã¯ã次ã®ãããªãã®ããããŸã :
fixed
ã¬ã³ãŒãã¯ããŸãŒã³ãã¡ã€ã«ã§å®çŸ©ãããé çªã§è¿ãããŸãã
random
ã¬ã³ãŒãã¯ãããçš®ã®ã©ã³ãã ãªé çªã§è¿ãããŸãã
cyclic
ã¬ã³ãŒãã¯ãã©ãŠã³ãããã³ã«è¿ãããŸãã
äŸãã°ã
rrset-order {
class IN type A name "rc.vix.com" order random;
order cyclic;
};
ã§ã¯ããµãã£ãã¯ã¹ã« "rc.vix.com" ãæã¡ã ã¯ã©ã¹ IN ã§ã¿ã€ã A
ã®ã¬ã³ãŒãã«å¯Ÿãã å¿çã¯ãåžžã«ã©ã³ãã ãªé çªã§è¿ãããŸãã
ãã®ä»ã®ã¬ã³ãŒãã¯ãã¹ãŠå·¡åé ã«è¿ãããŸãã
rrset-order
ã¹ããŒãã¡ã³ããè€æ°çŸããå Žåãã¹ããŒãã¡ã³ãã¯é£çµãããŸããã
æåŸã®ãã®ãé©çšãããŸãã
rrset-order ã¹ããŒãã¡ã³ããæå®ãããŠããªãå Žåãããã©ã«ãã¯
rrset-order { class ANY type ANY name "*" order cyclic ; };
ã䜿ãããŸãã
ãèãçŽãçãçžãéµã°
lame-ttl
äžå®å
šãªãµãŒãã®æç€ºãã¥ç€å¥ªèœ¡çŽéŽèšãç§æ°ãèšå®ããŸãã 0 ã®å Žåã-
ã£ãã·ã¥ããŸããã ããã©ã«ã㯠600 (10 å) ã§ããæå€§å€ã¯ 1800 (30 å)
ã§ãã
max-ncache-ttl
ãããã¯ãŒã¯ã®è² è·ã軜æžãããã©ãŒãã³ã¹ãäžããããã«ã
ãµãŒããåŠå®å¿çãèããŸãã max-ncache-ttl
ã¯ããµãŒãã§ããã®ãããªå¿çã®æå€§ä¿åæéãèšå®ããããã«äœ¿ããŸãã
ç§åäœã§ãã ããã©ã«ãã® max-ncache-ttl 㯠10800 ç§ (3 æé) ã§ãã
max-ncache-ttl éåžžã® (è¯å®)
å¿çã«å¯ŸããŠã¯ãæå€§ä¿åæéãè¶
ããŠã¯ãããŸãã (7 æ¥)ã
ããããã®å€ã 7 æ¥ä»¥äžã«èšå®ãããŠããå Žåã é»ã£ãŠ 7
æ¥ã«åãè©°ããŠããŸãã§ãããã
min-roots
ã«ãŒããµãŒãã«å¯ŸããèŠæ±ãåãåãããã«å¿
èŠãªã«ãŒããµãŒãã®æå°å€ã§ãã
ããã©ã«ã㯠2 ã§ãã
zoneãå¥ãèãçãèãçãéµã
æåºæ³
zone domain_name [ ( in | hs | hesiod | chaos ) ] {
type master;
file path_name;
[ check-names ( warn | fail | ignore ); ]
[ allow-update { address_match_list }; ]
[ allow-query { address_match_list }; ]
[ allow-transfer { address_match_list }; ]
[ forward ( only | first ); ]
[ forwarders { [ ip_addr ; [ ip_addr ; ... ] ] }; ]
[ dialup yes_or_no; ]
[ notify yes_or_no; ]
[ also-notify { ip_addr; [ ip_addr; ... ] };
[ pubkey number number number string; ]
};
zone domain_name [ ( in | hs | hesiod | chaos ) ] {
type ( slave | stub );
[ file path_name; ]
masters [ port ip_port ] { ip_addr; [ ip_addr; ... ] };
[ check-names ( warn | fail | ignore ); ]
[ allow-update { address_match_list }; ]
[ allow-query { address_match_list }; ]
[ allow-transfer { address_match_list }; ]
[ forward ( only | first ); ]
[ forwarders { [ ip_addr ; [ ip_addr ; ... ] ] }; ]
[ transfer-source ip_addr; ]
[ max-transfer-time-in number; ]
[ notify yes_or_no; ]
[ also-notify { ip_addr; [ ip_addr; ... ] };
[ pubkey number number number string; ]
};
zone domain_name [ ( in | hs | hesiod | chaos ) ] {
type forward;
[ forward ( only | first ); ]
[ forwarders { [ ip_addr ; [ ip_addr ; ... ] ] }; ]
[ check-names ( warn | fail | ignore ); ]
};
zone "." [ ( in | hs | hesiod | chaos ) ] {
type hint;
file path_name;
[ check-names ( warn | fail | ignore ); ]
};
å®èçŸèãéäœèçåæ³
zone ã¹ããŒãã¡ã³ãã¯ã ç¹å®ã® DNS
ãŸãŒã³ããµãŒãã«ã©ã®ããã«ç®¡çãããããæå®ããããã«
䜿ãããŸãããŸãŒã³ã«ã¯ 5 ã€ã®çš®é¡ããããŸãã
master
ãµãŒãã¯ã
ãã®ãŸãŒã³çšããŒã¿ã®ãã¹ã¿ã³ããŒãæã£ãŠããŠããŸãŒã³ã«å¯ŸããŠä¿¡é Œã§ã
å¿çãæäŸã§ãæ³å
slave
slave ãŸãŒã³ã¯ãã¹ã¿ãŸãŒã³ã®è€è£œã§ãã masters
ãªã¹ãã¯ããŸãŒã³ã®è€è£œãæŽæ°ããããã«ã¹ã¬ãŒããµãŒããéä¿¡ãè¡ã 1
ã€ä»¥äžã® IP ã¢ãã¬ã¹ãæå®ããŸãã port
ãæå®ãããŠããå Žåããã®ããŒãã«å¯Ÿãã
ãŸãŒã³ãçŸåšäœ¿çšãããŠãããã®ã§ããããšã®ç¢ºèªãšã
ãŸãŒã³è»¢éãè¡ãããŸãã file ãæå®ãããŠããå Žåã
æå®ããããã¡ã€ã«ãžãŸãŒã³ã®è€è£œãæžã䞪æ°èŽæ³å file
ç¯ã䜿çšããããšã匷ãå§ããŸãã
ãªããªãã倧äœã«ãããŠãµãŒãã®èµ·åãæ©ããŸããã
éä¿¡åç·ãç¡é§ã«äœ¿çšããããšãé²ãã§ãããããã§ãã
stub
stub ãŸãŒã³ã¯ slave
ãŸãŒã³ã®ãããªãã®ã§ããããŸãŒã³å
šäœãè€è£œããã®ã§ã¯ãªãã
ãã¹ã¿ãŸãŒã³ã® NS ã¬ã³ãŒãã®ã¿ãè€è£œãããšããç¹ãéããŸãã
forward
forward
ãŸãŒã³ã¯ãèªåã«åããããåãåãããä»ã®ãµãŒãã«æ¯ãåããããã«äœ¿çšããŸãã
ãã®ããšã¯ã option _
ã®ã»ã¯ã·ã§ã³ã§èª¬æããŠããŸãããããã®ãŸãŒã³ã§ã®ãªãã·ã§ã³ä»æ§ã¯ã
options ã¹ããŒãã¡ã³ãã§å®£èšãããã°ããŒãã«ãªãã·ã§ã³ãäžæžãéŽæ³å
forwarders ç¯ã zone ã¹ããŒãã¡ã³ãäžã«ååšããªããããããã¯ã
forwarders ã«å¯ŸããŠç©ºãªã¹ããäžããããŠããå Žåã¯ã
ãã®ãŸãŒã³ã«å¯ŸããŠãã©ã¯ãŒãã¯è¡ãããã options ã¹ããŒãã¡ã³ãäžã®
forwarders
ã¯ããã¹ãŠå¹åã倱ããŸãããã®ããã䜿çšããããµãŒãã§ã¯ãªããã°ããŒãã«ã®
forward
ãªãã·ã§ã³ã®æåã倿Žããããã ãã«ãã®çš®é¡ã®ãŸãŒã³ã䜿çšãããã®ã§ããã°ã
ã°ããŒãã«ã® forwarders ç¯ãæå®ããªããå¿
èŠããããŸãã
hint
ã«ãŒãããŒã ãµãŒãã®åæéåã¯ã hint
ãŸãŒã³ã䜿çšããŠæå®ãããŸãããµãŒããèµ·åããéã«ãã«ãŒããã³ãã䜿çšããŠ
ã«ãŒãããŒã ãµãŒããèŠã€ããã«ãŒãããŒã ãµãŒãã®ææ°ãªã¹ããååŸããŸãã
泚 : 以åã® BIND ãªãªãŒã¹ã§ã¯ããã¹ã¿ãŸãŒã³ã«å¯ŸããŠã¯ primary
ãšããçšèªã䜿çšããã¹ã¬ãŒããŸãŒã³ã«å¯ŸããŠã¯ã secondary ããhint
ãŸãŒã³ã«å¯ŸããŠã¯ cache ãšããçšèªã䜿çšããŠããŸããã
ããèã¹
ãŸãŒã³åã«ã¯ããªãã·ã§ã³ã§ã¯ã©ã¹ãç¶ããããšãã§ãæ³å
ãããã¯ã©ã¹ãæå®ãããŠããªãå Žåã¯ã in ã¯ã©ã¹ (ãã€ã³ã¿ãŒããããçš)
ã§ãããšä»®å®ãããŸããããã¯ã倧åã®å Žåæ£ããã§ãã
hesiod ã¯ã©ã¹ã¯ãMIT ã® Project Athena ç±æ¥ã®æ
å ±ãµãŒãã¹çšã®ã¯ã©ã¹ã§ãã
ãã®ã¯ã©ã¹ã¯ããŠãŒã¶ãã°ã«ãŒããããªã³ã¿ãªã©ãšãã£ãã
ããŸããŸãªã·ã¹ãã ããŒã¿ããŒã¹ã« é¢ããæ
å ±ãå
±-
ããããã«äœ¿çšãããŸãããããªãæ
å ±ã¯ã ftp://athena-
dist.mit.edu/pub/ATHENA/usenix/athena_changes.PS ããå
¥æã§ãæ³å -
ãŒã¯ãŒã hs 㯠hesiod ãšå矩èªã§ãã
MIT ãéçºãããã 1 ã€ã®ãã®ãã1970 幎代åã°ã«äœããã LAN
ãããã³ã«ã§ãã CHAOSnet ã§ããããã¯ãLISP ã¹ããŒã·ã§ã³ã AI
ã³ãã¥ããã£ã§äœ¿ãããŠãã
ä»ã®ããŒããŠã§ã¢ã§ããŸã ææèŠåããããŸããCHAOSnet çšã®ãŸãŒã³ããŒã¿ã¯ã
chaos ã¯ã©ã¹ã䜿çšããŠæå®ã§ãæ³å
ããå»ãèœãè
ã³
check-names
options __
ã«é¢ãããµãã»ã¯ã·ã§ã³ãåç
§ããŠãã ããã
allow-query
options __allow-query
ã«é¢ãã説æãåç
§ããŠãã ããã
allow-update
ã©ã®ãã¹ããåç㪠DNS
ã®æŽæ°ããµãŒãã«æåºããããæå®ããŸããããã©ã«ãã¯ã
ã©ã®ãã¹ããããæŽæ°ãèš±å¯ããªããšãããã®ã§ãã
allow-transfer
options __allow-transfer ã«é¢ãã説æãåç
§ããŠãã ããã
transfer-source
transfer-source ã©ã®ããŒã«ã«ã¢ãã¬ã¹ãã
ãã®ãŸãŒã³ãååŸããããã«äœ¿çšããã TCP æ¥ç¶ãšçµã³ã€ãããããã
æå®ããŸãã
ãããèšå®ãããŠããªãå Žåã¯ãã·ã¹ãã ãå¶åŸ¡ããå€ãããã©ã«ãã«ãªããŸãã
ãã®å€ã¯ãéåžžã¯ããªã¢ãŒãåŽã®çµç«¯ã«ãæãè¿ããã€ã³ã¿ãã§ãŒã¹ã®ã¢ãã¬ã¹ã§ãã
ãã®ã¢ãã¬ã¹ã¯ã
ããæå®ãããŠããã®ã§ããã°ããã®ãŸãŒã³ã«å¯Ÿãããªã¢ãŒãåŽã®çµç«¯ã®
allow-transfer ãªãã·ã§ã³äžã«åºãŠããªããŠã¯ãªããŸããã
max-transfer-time-in
options __max-transfer-time-in ã®èª¬æãåç
§ããŠãã ããã
dialup
options __dialup
ã®èª¬æãåç
§ããŠãã ããã
notify
options __notify
ã®èª¬æãåç
§ããŠãã ããã
also-notify
notify ããã®ãŸãŒã³ã«å¯ŸããŠã¢ã¯ãã£ãã§ããå Žåã®ã¿ also-notify
ã¯æå³ãæã¡ãŸãã ãã®ãŸãŒã³ã«å¯Ÿãã DNS NOTIFY
ã¡ãã»ãŒãžãåãåããã·ã³çŸ€ã¯ã ãã®ãŸãŒã³çšã«ãªã¹ãããã
ãã¹ãŠã®ããŒã ãµãŒã (ãã©ã€ããªãã¹ã¿ãé€ã) ãšã also-notify
ã§æå®ããã IP ã¢ãã¬ã¹ãããªã£ãŠããŸãã also-notify 㯠stub
ãŸãŒã³ã«å¯ŸããŠã¯æå³ãæã¡ãŸãããããã©ã«ãã§ã¯ãããã¯ç©ºã®ãªã¹ãã§ãã
forward
forward ã¯ããã®ãŸãŒã³ã forwarders
ãªã¹ããæã£ãŠããå Žåã®ã¿æå³ãæã¡ãŸãã only å€ã¯ãå
ã« forwarders
ã詊ããå¿çããªãã£ãå Žåã«æ€çŽ¢ã倱æãããŸãã ããã«å¯Ÿãã first
ã¯ãéåžžã®æ€çŽ¢ãèš±å¯ããŸãã
forwarders
ãŸãŒã³äžã§ forwarders ãªãã·ã§ã³ã䜿çšãããšãã°ããŒãã«ã® forwarders
ãªã¹ããäžæžãæ°èŽæ³å forward
ã¿ã€ãã®ãŸãŒã³äžã§ãããæå®ãããŠããªãã£ãå Žåã¯ã
ãã®ãŸãŒã³ã«å¯ŸããŠã¯ _
ãã©ã¯ãŒããè¡ããŸãããã°ããŒãã«ã®ãªãã·ã§ã³ã¯äœ¿ãããªããšããããšã§ãã
pubkey
DNSSEC ã®ãã©ã°ããããã³ã«ãã¢ã«ãŽãªãºã ãšã base-64
ã§ãšã³ã³ãŒããããéµã衚ãæååãæå®ããŸãã
aclãå¥ãèãçãèãçãéµã
æåºæ³
acl name {
address_match_list
};
å®èçŸèãéäœèçåæ³
acl ã¹ããŒãã¡ã³ãã¯ãååã®ã€ããã¢ãã¬ã¹ããããªã¹ããçæããŸãã
ãã®ã¹ããŒãã¡ã³ãã¯ããã©ã€ããªã§äœ¿çšããŠããã¢ãã¬ã¹ããããªã¹ããã€ãŸãã
ã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ã (ACL) ãããã®ååãååŸããŸãã
ã¢ãã¬ã¹ããããªã¹ãåã¯ãä»ã®ãšããã§äœ¿çšããåã« acl
ã䜿çšããŠå®çŸ©ããªããŠã¯ãªããŸããããã¡ã€ã«ã®åæ¹ãžã®åç
§ã¯èš±ãããŠããŸããã
次ã®ãããªçµã¿èŸŒã¿ã® ACL ããããŸã :
any
ãã¹ãŠã®ãã¹ããèš±å¯ããŸãã
none
ãã¹ãŠã®ãã¹ããæåŠããŸãã
localhost
ã·ã¹ãã äžã®ãã¹ãŠã®ã€ã³ã¿ãã§ãŒã¹ã® IP ã¢ãã¬ã¹ãèš±å¯ããŸãã
localnets
ã·ã¹ãã ãã€ã³ã¿ãã§ãŒã¹ãæã£ããããã¯ãŒã¯äžã®ãã¹ãŠã®ãã¹ããèš±å¯ããŸãã
keyãå¥ãèãçãèãçãéµã
æåºæ³
key key_id {
algorithm algorithm_id;
secret secret_string;
};
å®èçŸèãéäœèçåæ³
key ã¹ããŒãã¡ã³ãã¯ãéµã® ID ãæå®ããŸãããã® ID ã¯ã server
ã¹ããŒãã¡ã³ãã§äœ¿çšãããåçŽãª IP ã¢ãã¬ã¹ã§ã®ãããã³ã°ããã峿 Œãª
ç¹å®ã®ããŒã ãµãŒããšèªèšŒæ¹æ³ãšãé¢é£ã¥ããŸãã éµã® ID ã¯ã server
ã®å®çŸ©ãã¢ãã¬ã¹ããããªã¹ãäžã§äœ¿çšãããåã« key
ã¹ããŒãã¡ã³ãã䜿çšããŠäœæãããŠããªããŠã¯ãªããŸããã
algorithm_id ã¯ãã»ã¥çµ
è¢è¬ / èªèšŒã¢ã«ãŽãªãºã ãæå®ããæååã§ãã
secret_string ã¯ãæå®ãããã¢ã«ãŽãªãºã ã䜿çšããç§å¯ã®éµã§ã base-64
ã§ãšã³ã³ãŒããããæååãšããŠæ±ãããŸãã
èšãããšãåœç¶ã®ããšã§ãããçºå¿µææããŠãããšã named.conf äžã«
secret_string ãå
¥ããŠããå Žåã named.conf
ãã¹ãŒããŠãŒã¶ä»¥å€ã®èª°ã«ãèªã¿èŸŒã¿å¯èœã«ããŠã¯ãããŸããã
trusted-keysãå¥ãèãçãèãçãéµã
æåºæ³
trusted-keys {
[ domain_name flags protocol algorithm key; ]
};
å®èçŸèãéäœèçåæ³
trusted-keys ã¹ããŒãã¡ã³ãã¯ãããšããšãRFC 2065 ã§ä»æ§ã決ããããŠãã
DNSSEC ã¹ã¿ã€ã«ã® ã»ã¥çµ
è¢è¬ãšãšãã«äœ¿çšãããŸããDNSSEC ã¯ã 3
ã€ã®ç°ãªã£ããµãŒãã¹ãæäŸãããã®ã§ã :
ããã¯ãéµã®é
åžãããŒã¿ã®çºçå
ã®èªèšŒã
ãããŠããã©ã³ã¶ã¯ã·ã§ã³ããã³èŠæ±ã®èªèšŒã§ããDNSSEC
ã«ã€ããŠã®å®å
šãªèª¬æãš ãã®ã-
ã¥ã¡ã³ãã®ç¯å²ãè¶
ããäœ¿ãæ¹ãç¥ãããå Žåã ãããŠãèªè
ããããªãæ
å ±ã«
èå³ãããå Žåã¯ããŸããRFC2065 ãèªãããšããå§ããŠãã ããããããŠã
http://www.ietf.org/ids.by.wg/dnssec.html ããå
¥æã§ã襯ã
鵿çœåªå¥ª
ãã©ãããžãšç¶ããŠãã ããã
ä¿¡é Œãããéµã¯ããããããã¡ã€ã³åãšé¢é£ã¥ããããŠããŸãããã®å±äžè®
éè² ã®æŽæ°å€ã§ããã flags, protocol, algorithm ãšã key ã衚ã base-64
ã§ãšã³ã³ãŒããããæååã§ãã
ä¿¡é Œãããéµã®çªå·ã¯ãã¹ãŠæå®å¯èœã§ãã
serverãå¥ãèãçãèãçãéµã
æåºæ³
server ip_addr {
[ bogus yes_or_no; ]
[ transfers number; ]
[ transfer-format ( one-answer | many-answers ); ]
[ keys { key_id [ key_id ... ] }; ]
};
å®èçŸèãéäœèçåæ³
server ã¹ããŒãã¡ã³ãã¯ããªã¢ãŒãã®ããŒã ãµãŒãã«é¢é£ä»ãããã
ç¹åŸŽãå®çŸ©ããŸãã
ãµãŒããééã£ãããŒã¿ãéã£ãŠããããšã«æ°ãã€ããå Žåããã®ãµãŒãã
bogus ã«ããããšã§ããã®ãµãŒããžã®åãåãããææ¢ããããšãã§ãæ³å
bogus ã®ããã©ã«ãå€ã¯ no ã§ãã ãµãŒãã« bogus
ã®å°ãä»ãããšãåœè©²ãµãŒãã®ã¢ãã¬ã¹ãååã§æ€çŽ¢ããŠããããããšãæ³
åœè©²ãµãŒãã«å¯Ÿããä»ã®ã¢ãã¬ã¹ããã¹ãŠ bogus ã®å°ãä»ããŸãã
ãµãŒãã¯ã2 ã€ã®ãŸãŒã³è»¢éæ¹åŒããµããŒãããŠããŸãã1 ã€ç®ã¯ã one-answer
ã§ããã ããã¯ã転éãããåãªãœãŒã¹ã¬ã³ãŒãã« 1 ã€ã® DNS
ã¡ãã»ãŒãžã䜿çšããŸãã many-answers ã¯ãã§-
ãã ãå€ãã®ãªãœãŒã¹ã¬ã³ãŒãã 1 ã€ã®ã¡ãã»ãŒãžã«æŒã蟌ã¿ãŸãã
many-answers ã®æ¹ãå¹ççã§ã¯ãããŸãããBIND 8.1 ããã³ã
ãããã®åœãã£ã BIND 4.9.5 ã§ã®ã¿ çè§£ããããã®ã§ãã
ãµãŒãã«å¯ŸããŠã©ã¡ãã®æ¹æ³ã䜿çšãããã¯ã transfer-format
ãªãã·ã§ã³ã䜿çšããŠæå®ããããšãã§ãæ³å transfer-format
ãæå®ãããŠããªãå Žåã¯ã options ã¹ããŒãã¡ã³ãã§æå®ããã
transfer-format ã䜿çšãããŸãã
transfers ã¯ã祥è²é¢è¢èçœå¢ä»»é¢æ©çœäžªåŠ
æå®ããããµãŒãããåæã«è¡ãããå
éšãžã®ãŸãŒã³è»¢éæ°ã
å¶éããããã«äœ¿çšãããäºå®ã§ãã
çŸåšã¯ãææ³ã¯ãã§ãã¯ããŸããããã®ä»ã®ããšã¯ ç¡èŠãããŸãã
keys ç¯ã¯ã key ã¹ããŒãã¡ã³ãã§å®çŸ©ããã key_id
ãèå¥ããããã«äœ¿çšãããŸããããã¯ããªã¢ãŒããµãŒããšéä¿¡ããéã®
ãã©ã³ã¶ã¯ã·ã§ã³ã®ã»ã¥çµ
è¢è¬ïŒåå¿è©åæ°èŽæ³å key
ã¹ããŒãã¡ã³ãã¯ããããåç
§ãã server
ã¹ããŒãã¡ã³ããããå
ã«çŸããªããŠã¯ãªããŸããã
keys ã¹ããŒãã¡ã³ãã¯ã-
æ¥ããµãŒãã«ãã£ãŠäœ¿çšãããããšãæåŸ
ãããŠããŸãã
çŸåšã¯ãææ³ã¯ãã§ãã¯ãããŸããããã®ä»ã®ããšã¯ç¡èŠãããŸãã
controlsãå¥ãèãçãèãçãéµã
æåºæ³
controls {
[ inet ip_addr
port ip_port
allow { address_match_list; }; ]
[ unix path_name
perm number
owner number
group number; ]
};
å®èçŸèãéäœèçåæ³
controls ã¹ããŒãã¡ã³ãã¯ã
ã·ã¹ãã 管çè
ãããŒã«ã«ã®ããŒã ãµãŒãã®æäœã«åœ±é¿ãäžããããã«
䜿çšããå¶åŸ¡ãã£ãã«ã宣èšããŸããå¶åŸ¡ãã£ãã«ã¯ã ndc
ãŠãŒãã£ãªãã£ããããŒã ãµãŒãã«ã³ãã³ããéãã DNS
以å€ã®çµæãåãåããã㫠䜿çšããŸãã
unix å¶åŸ¡ãã£ãã«ã¯ããã¡ã€ã«ã·ã¹ãã ã§ã® FIFO
ã§ãããã®ãã£ãã«ãžã®ã¢ã¯ã»ã¹ã¯ã
éåžžã®ãã¡ã€ã«ã·ã¹ãã ã®ããŒããã·ã§ã³ã«ãã£ãŠå¶åŸ¡ãããŸãã
ãã®å¶åŸ¡ãã£ãã«ã¯ã æå®ããããã¡ã€ã«ã¢ãŒãã®ããã ( chmod(1) ãåç
§)
ãšãŠãŒã¶ããã³ã°ã«ãŒãã®æå€åéŸéµé®è©åæ named ãäœæããŸãã
泚æããããšã¯ã chmod ãšã¯éãã perm
ã«å¯ŸããŠæå®ãããã¢ãŒãã®ãããã«ã¯ãéåžžå
é ã« 0
ãã€ããŠããããšã§ãããã®ãããæ°å㯠8 鲿°ãšããŠè§£éãããŸãã
ããã«æ³šæããããšã¯ã owner ããã³ group
ãšããŠæå®ããããŠãŒã¶ããã³ã°ã«ãŒãã®æå€åéŸéµè®âåã§äžããªããŠã¯
ãªããªããšããããšã§ããååã§ã¯ãããŸããã
ãã®ããŒããã·ã§ã³ã¯ã管çè
ã®ã¿ã«å¶éããããšãå§ããŸãã
ããããªããšããã®ã·ã¹ãã äžã®ãŠãŒã¶ãªã誰ã§ãããŒã«ã«ããŒã ãµãŒãã
æäœã§ãèšéŽæ³ãæ³å
inet å¶åŸ¡ãã£ãã«ã¯ãã€ã³ã¿ãŒãããæ¥ç¶ã®ã§ã TCP/IP ãœã±ããã§ãã
ããã¯ãæå®ããã ip_addr äžã®æå®ããã ip_port ã«ãããŸãã æè¿ã®
telnet ã¯ã©ã€ã¢ã³ãã¯ããããããœã±ãããšçŽæ¥å¯Ÿè©±ãã§ãæ³å ãã®ãš-
ã®å¶åŸ¡ãããã³ã«ã¯ãARPAnet 圢åŒã®ãã¥å¥œç®žä»»å 127.0.0.1 ã ãã ip_addr
ã«äœ¿çšããããšãå§ããŸããããã¯ãããŒã ãµãŒãã管çããããã«ã
ããŒã«ã«ãã¹ãäžã®ç¹æš©ãæããªããŠãŒã¶ãçä¿¡çšããŠããå Žåã ãã«éããŸãã
includeãå¥ãèãçãèãçãéµã
æåºæ³
include path_name;
å®èçŸèãéäœèçåæ³
include ã¹ããŒãã¡ã³ãã¯ããã®ã¹ããŒãã¡ã³ããçŸããå°ç¹ã«ãæå®ããã
ãã¡ã€ã«ãæ¿å
¥ããŸãããã ããä»ã®ã¹ããŒãã¡ã³ãå
ã§äœ¿çšããããšã¯ ã§-
ãŸãããã§ãã®ã§ã
acl internal_hosts { include internal_hosts.acl; };
ãšããããã«ã¯äœ¿çšã§ãæ³æŠéµ
include ã䜿çšããŠãèšå®ãã¡ã€ã«ãç°¡åã«ç®¡çã§ã襪ããŸãã«åããããã«
ããŠãã ãããäŸãã°ã次ã®ããã«ã§ã :
include "/etc/security/keys.bind";
include "/etc/acls.bind";
ãã®äŸã¯ãä»»æã® ACL ãŸã㯠èªèšŒéµæ
å ±ãåã蟌ãããã«ã BIND
èšå®ãã¡ã€ã«ã®å
é ã§äœ¿ãããšãã§ã襪任éŽè
Î
C èšèªã§ã®ããã°ã©ã ã§ããããã« ``#include'' ãšã¿ã€ãããªãã§ãã ããã
``#'' ã¯ã³ã¡ã³ãã®éå§ãšããŠäœ¿çšãããã®ã ããã§ãã
äœèçåäŸ
å®éã«äœ¿çšããå Žé¢ã§ãå®çšçã§ãæãåçŽãªèšå®ãã¡ã€ã«ã¯ã
ãã åã«ã«ãŒããµãŒããã¡ã€ã«ãžã®ãã«ãã¹ãæã£ããã³ããŸãŒã³ã
å®çŸ©ãããã®ã§ãã
zone "." in {
type hint;
file "/var/named/root.cache";
};
次ã®äŸã¯ããã£ãšå®äžçã«å³ãããã®ã§ãã
/*
* åçŽãª BIND 8 ã®èšå®
*/
logging {
category lame-servers { null; };
category cname { null; };
};
options {
directory "/var/named";
};
controls {
inet * port 52 allow { any; }; // ããã¯è¯ããªã
unix "/var/run/ndc" perm 0600 owner 0 group 0; // ããã©ã«ã
};
zone "isc.org" in {
type master;
file "master/isc.org";
};
zone "vix.com" in {
type slave;
file "slave/vix.com";
masters { 10.0.0.53; };
};
zone "0.0.127.in-addr.arpa" in {
type master;
file "master/127.0.0";
};
zone "." in {
type hint;
file "root.cache";
};
ãäŸãïŒããã«
/etc/namedb/named.conf
BIND 8 named èšå®ãã¡ã€ã«
éæ
éé çç®
named(8), ndc(8)