12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

342CHAPTER 16Hostname Resolution with BIND. key: Define a shared secret key to use with TSIG or the control channel. The secretmust be a base-64 encoding of the encryption key, enclosed in double quotationmarks. It can be generated with the rndc-confgen command as described in the“Configuring rndc.conf” section.Replace with a unique name for the key:key {algorithm hmac-md5secret “”};The key statement must be inside a view statement, inside a server statement, or atthe top-level of named.conf. Keys inside view statements can only be used byrequesters matching the view definition. Keys inside server statements are used tosign requests sent to that server. Top-level statements can be referenced inside otherstatements by the . For example, to use a top-level key inside the serverstatement:server {keys { };};. logging: Customize logging. Refer to the “Logging Connections” section for details.. lwres: Configure the name server to act as a lightweight resolver server. Multiplelwres statements can be declared.lwres {listen-on { port ; port };view ;search { ; };ndots ;};The listen-on statement declares a semicolon-separated list of IP addresses and portnumbers for the IPs from which the lightweight resolver accepts requests. If a portnumber is not given, the default port (port 921) is used. If the listen-on statement ismissing, only requests from the local loopback (127.0.0.1) on port 921 are accepted.To bind this lightweight resolver to a view so the response is formatted according tothe view, use the view statement to list the name of the view declared in the toplevelof named.conf. If no view is listed, the default view is used.Use the search statement to list domain names used to convert hostnames toFQDNs when they are sent in requests. This is the same as the search statement in/etc/resolv.conf. Multiple domain names can be listed, separated by semicolons.The ndots statement sets the minimum number of periods in a domain name thatshould match exactly before the domain names declared with the search statements areadded to the end of it. This is the same as the ndots statement in /etc/resolv.conf:

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!