diff --git a/bin/dig/dig.1 b/bin/dig/dig.1 index 3367969ba3..8684aae992 100644 --- a/bin/dig/dig.1 +++ b/bin/dig/dig.1 @@ -328,6 +328,11 @@ Deprecated, treated as a synonym for \fI+[no]search\fR .RE .PP +\fB+[no]dnssec\fR +.RS 4 +Requests DNSSEC records be sent by setting the DNSSEC OK bit (DO) in the OPT record in the additional section of the query. +.RE +.PP \fB+domain=somename\fR .RS 4 Set the search list to contain the single domain @@ -339,11 +344,6 @@ directive in option were given. .RE .PP -\fB+[no]dnssec\fR -.RS 4 -Requests DNSSEC records be sent by setting the DNSSEC OK bit (DO) in the OPT record in the additional section of the query. -.RE -.PP \fB+[no]edns[=#]\fR .RS 4 Specify the EDNS version to query with. Valid values are 0 to 255. Setting the EDNS version will cause a EDNS query to be sent. diff --git a/bin/dig/dig.html b/bin/dig/dig.html index 6c61ff448c..1be764e58a 100644 --- a/bin/dig/dig.html +++ b/bin/dig/dig.html @@ -94,41 +94,41 @@
server
- is the name or IP address of the name server to query. This
- can be an IPv4 address in dotted-decimal notation or an IPv6
- address in colon-delimited notation. When the supplied
- server
argument is a hostname,
- dig resolves that name before querying
- that name server.
-
server
argument is a hostname,
+ dig resolves that name before querying
+ that name server.
+
- If no server
argument is
- provided, dig consults
- /etc/resolv.conf
; if an
- address is found there, it queries the name server at
- that address. If either of the -4
or
- -6
options are in use, then
- only addresses for the corresponding transport
- will be tried. If no usable addresses are found,
- dig will send the query to the
- local host. The reply from the name server that
- responds is displayed.
-
server
argument is
+ provided, dig consults
+ /etc/resolv.conf
; if an
+ address is found there, it queries the name server at
+ that address. If either of the -4
or
+ -6
options are in use, then
+ only addresses for the corresponding transport
+ will be tried. If no usable addresses are found,
+ dig will send the query to the
+ local host. The reply from the name server that
+ responds is displayed.
+
name
- is the name of the resource record that is to be looked up. -
type
- indicates what type of query is required —
- ANY, A, MX, SIG, etc.
- type
can be any valid query
- type. If no
- type
argument is supplied,
- dig will perform a lookup for an
- A record.
-
type
can be any valid query
+ type. If no
+ type
argument is supplied,
+ dig will perform a lookup for an
+ A record.
+
@@ -355,6 +355,12 @@ Deprecated, treated as a synonym for
+[no]search
++[no]dnssec
+ Requests DNSSEC records be sent by setting the DNSSEC + OK bit (DO) in the OPT record in the additional section + of the query. +
+domain=somename
Set the search list to contain the single domain
@@ -364,12 +370,6 @@
search list processing as if the
+search
option were given.
+[no]dnssec
- Requests DNSSEC records be sent by setting the DNSSEC - OK bit (DO) in the OPT record in the additional section - of the query. -
+[no]edns[=#]
Specify the EDNS version to query with. Valid values @@ -553,13 +553,13 @@
+time=T
- Sets the timeout for a query to
- T
seconds. The default
+ Sets the timeout for a query to
+ T
seconds. The default
timeout is 5 seconds.
- An attempt to set T
to less
- than 1 will result
- in a query timeout of 1 second being applied.
-
T
to less
+ than 1 will result
+ in a query timeout of 1 second being applied.
+
+[no]topdown
When chasing DNSSEC signature chains perform a top-down @@ -614,10 +614,10 @@
+[no]ttlunits
- Display [do not display] the TTL in friendly human-readable - time units of "s", "m", "h", "d", and "w", representing - seconds, minutes, hours, days and weeks. Implies +ttlid. -
+[no]vc
Use [do not use] TCP when querying name servers. This @@ -631,7 +631,7 @@
The BIND 9 implementation of dig supports @@ -677,7 +677,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
If dig has been built with IDN (internationalized domain name) support, it can accept and display non-ASCII domain names. @@ -691,14 +691,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
host(1), named(8), dnssec-keygen(8), @@ -706,7 +706,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
There are probably too many query options.
diff --git a/doc/arm/man.arpaname.html b/doc/arm/man.arpaname.html index a367cbe54f..2d51fb3420 100644 --- a/doc/arm/man.arpaname.html +++ b/doc/arm/man.arpaname.html @@ -50,20 +50,20 @@arpaname
{ipaddress
...}
arpaname translates IP addresses (IPv4 and IPv6) to the corresponding IN-ADDR.ARPA or IP6.ARPA names.
ddns-confgen
[-a
] [algorithm
-h
] [-k
] [keyname
-q
] [-r
] [ -s randomfile
name
| -z zone
]
tsig-keygen and ddns-confgen are invokation methods for a utility that generates keys for use @@ -87,7 +87,7 @@
anchor-file
server
- is the name or IP address of the name server to query. This
- can be an IPv4 address in dotted-decimal notation or an IPv6
- address in colon-delimited notation. When the supplied
- server
argument is a hostname,
- dig resolves that name before querying
- that name server.
-
server
argument is a hostname,
+ dig resolves that name before querying
+ that name server.
+
- If no server
argument is
- provided, dig consults
- /etc/resolv.conf
; if an
- address is found there, it queries the name server at
- that address. If either of the -4
or
- -6
options are in use, then
- only addresses for the corresponding transport
- will be tried. If no usable addresses are found,
- dig will send the query to the
- local host. The reply from the name server that
- responds is displayed.
-
server
argument is
+ provided, dig consults
+ /etc/resolv.conf
; if an
+ address is found there, it queries the name server at
+ that address. If either of the -4
or
+ -6
options are in use, then
+ only addresses for the corresponding transport
+ will be tried. If no usable addresses are found,
+ dig will send the query to the
+ local host. The reply from the name server that
+ responds is displayed.
+
name
- is the name of the resource record that is to be looked up. -
type
- indicates what type of query is required —
- ANY, A, MX, SIG, etc.
- type
can be any valid query
- type. If no
- type
argument is supplied,
- dig will perform a lookup for an
- A record.
-
type
can be any valid query
+ type. If no
+ type
argument is supplied,
+ dig will perform a lookup for an
+ A record.
+
@@ -373,6 +373,12 @@ Deprecated, treated as a synonym for
+[no]search
++[no]dnssec
+ Requests DNSSEC records be sent by setting the DNSSEC + OK bit (DO) in the OPT record in the additional section + of the query. +
+domain=somename
Set the search list to contain the single domain
@@ -382,12 +388,6 @@
search list processing as if the
+search
option were given.
+[no]dnssec
- Requests DNSSEC records be sent by setting the DNSSEC - OK bit (DO) in the OPT record in the additional section - of the query. -
+[no]edns[=#]
Specify the EDNS version to query with. Valid values @@ -571,13 +571,13 @@
+time=T
- Sets the timeout for a query to
- T
seconds. The default
+ Sets the timeout for a query to
+ T
seconds. The default
timeout is 5 seconds.
- An attempt to set T
to less
- than 1 will result
- in a query timeout of 1 second being applied.
-
T
to less
+ than 1 will result
+ in a query timeout of 1 second being applied.
+
+[no]topdown
When chasing DNSSEC signature chains perform a top-down @@ -632,10 +632,10 @@
+[no]ttlunits
- Display [do not display] the TTL in friendly human-readable - time units of "s", "m", "h", "d", and "w", representing - seconds, minutes, hours, days and weeks. Implies +ttlid. -
+[no]vc
Use [do not use] TCP when querying name servers. This diff --git a/doc/arm/man.dnssec-checkds.html b/doc/arm/man.dnssec-checkds.html index 40fce94918..a90ea3363c 100644 --- a/doc/arm/man.dnssec-checkds.html +++ b/doc/arm/man.dnssec-checkds.html @@ -51,7 +51,7 @@
dnssec-dsfromkey
[-l
] [domain
-f
] [file
-d
] [dig path
-D
] {zone}dsfromkey path
dnssec-checkds verifies the correctness of Delegation Signer (DS) or DNSSEC Lookaside Validation (DLV) resource records for keys in a specified @@ -59,7 +59,7 @@
dnssec-coverage
[-K
] [directory
-l
] [length
-f
] [file
-d
] [DNSKEY TTL
-m
] [max TTL
-r
] [interval
-c
] [compilezone path
-k
] [-z
] [zone]
dnssec-coverage verifies that the DNSSEC keys for a given zone or a set of zones have timing metadata set properly to ensure no future lapses in DNSSEC @@ -78,7 +78,7 @@
dnssec-dsfromkey
{-s} [-1
] [-2
] [-a
] [alg
-K
] [directory
-l
] [domain
-s
] [-c
] [class
-T
] [TTL
-f
] [file
-A
] [-v
] {dnsname}level
dnssec-dsfromkey outputs the Delegation Signer (DS) resource record (RR), as defined in RFC 3658 and RFC 4509, for the given key(s).
The keyfile can be designed by the key identification
Knnnn.+aaa+iiiii
or the full file name
@@ -164,13 +164,13 @@
dnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, @@ -180,7 +180,7 @@
dnssec-importkey
{-f
} [filename
-K
] [directory
-L
] [ttl
-P
] [date/offset
-D
] [date/offset
-h
] [-v
] [level
dnsname
]
dnssec-importkey reads a public DNSKEY record and generates a pair of .key/.private files. The DNSKEY record may be read from an @@ -71,7 +71,7 @@
Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS. If the argument begins with a '+' or '-', it is interpreted as @@ -138,7 +138,7 @@
A keyfile can be designed by the key identification
Knnnn.+aaa+iiiii
or the full file name
@@ -147,7 +147,7 @@
dnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, @@ -155,7 +155,7 @@
dnssec-keyfromlabel
{-l label
} [-3
] [-a
] [algorithm
-A
] [date/offset
-c
] [class
-D
] [date/offset
-E
] [engine
-f
] [flag
-G
] [-I
] [date/offset
-i
] [interval
-k
] [-K
] [directory
-L
] [ttl
-n
] [nametype
-P
] [date/offset
-p
] [protocol
-R
] [date/offset
-S
] [key
-t
] [type
-v
] [level
-y
] {name}
dnssec-keyfromlabel generates a key pair of files that referencing a key object stored in a cryptographic hardware service module (HSM). The private key @@ -66,7 +66,7 @@
algorithm
dnssec-keygen
[-a
] [algorithm
-b
] [keysize
-n
] [nametype
-3
] [-A
] [date/offset
-C
] [-c
] [class
-D
] [date/offset
-E
] [engine
-f
] [flag
-G
] [-g
] [generator
-h
] [-I
] [date/offset
-i
] [interval
-K
] [directory
-L
] [ttl
-k
] [-P
] [date/offset
-p
] [protocol
-q
] [-R
] [date/offset
-r
] [randomdev
-S
] [key
-s
] [strength
-t
] [type
-v
] [level
-z
] {name}
dnssec-keygen generates keys for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC 4034. It can also generate keys for use with @@ -64,7 +64,7 @@
algorithm
dnssec-revoke
[-hr
] [-v
] [level
-K
] [directory
-E
] [engine
-f
] [-R
] {keyfile}
dnssec-revoke reads a DNSSEC key file, sets the REVOKED bit on the key as defined in RFC 5011, and creates a new pair of key files containing the @@ -58,7 +58,7 @@
dnssec-settime
[-f
] [-K
] [directory
-L
] [ttl
-P
] [date/offset
-A
] [date/offset
-R
] [date/offset
-I
] [date/offset
-D
] [date/offset
-h
] [-v
] [level
-E
] {keyfile}engine
dnssec-settime can also be used to print the timing metadata associated with a key. @@ -232,7 +232,7 @@
dnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, @@ -240,7 +240,7 @@
dnssec-signzone
[-a
] [-c
] [class
-d
] [directory
-D
] [-E
] [engine
-e
] [end-time
-f
] [output-file
-g
] [-h
] [-K
] [directory
-k
] [key
-L
] [serial
-l
] [domain
-M
] [domain
-i
] [interval
-I
] [input-format
-j
] [jitter
-N
] [soa-serial-format
-o
] [origin
-O
] [output-format
-P
] [-p
] [-R
] [-r
] [randomdev
-S
] [-s
] [start-time
-T
] [ttl
-t
] [-u
] [-v
] [level
-X
] [extended end-time
-x
] [-z
] [-3
] [salt
-H
] [iterations
-A
] {zonefile} [key...]
dnssec-signzone signs a zone. It generates NSEC and RRSIG records and produces a signed version of the @@ -61,7 +61,7 @@
diff --git a/doc/arm/man.dnssec-verify.html b/doc/arm/man.dnssec-verify.html index 98caa9b4d8..073d081268 100644 --- a/doc/arm/man.dnssec-verify.html +++ b/doc/arm/man.dnssec-verify.html @@ -50,7 +50,7 @@
dnssec-verify
[-c
] [class
-E
] [engine
-I
] [input-format
-o
] [origin
-v
] [level
-x
] [-z
] {zonefile}
dnssec-verify verifies that a zone is fully signed for each algorithm found in the DNSKEY RRset for the zone, and that the NSEC / NSEC3 @@ -58,7 +58,7 @@
genrandom
[-n
] {number
size
} {filename
}
genrandom generates a file or a set of files containing a specified quantity @@ -59,7 +59,7 @@
dig(1), named(8).
diff --git a/doc/arm/man.isc-hmac-fixup.html b/doc/arm/man.isc-hmac-fixup.html index 2f1c42f815..a593d9a796 100644 --- a/doc/arm/man.isc-hmac-fixup.html +++ b/doc/arm/man.isc-hmac-fixup.html @@ -50,7 +50,7 @@isc-hmac-fixup
{algorithm
} {secret
}
Versions of BIND 9 up to and including BIND 9.6 had a bug causing HMAC-SHA* TSIG keys which were longer than the digest length of the @@ -76,7 +76,7 @@
Secrets that have been converted by isc-hmac-fixup are shortened, but as this is how the HMAC protocol works in @@ -87,14 +87,14 @@
named-checkconf
[-h
] [-v
] [-j
] [-t
] {filename} [directory
-p
] [-x
] [-z
]
named-checkconf checks the syntax, but not the semantics, of a named configuration file. The file is parsed @@ -70,7 +70,7 @@
named-checkconf returns an exit status of 1 if errors were detected and 0 otherwise.
named-compilezone
[-d
] [-j
] [-q
] [-v
] [-c
] [class
-C
] [mode
-f
] [format
-F
] [format
-J
] [filename
-i
] [mode
-k
] [mode
-m
] [mode
-n
] [mode
-l
] [ttl
-L
] [serial
-r
] [mode
-s
] [style
-t
] [directory
-T
] [mode
-w
] [directory
-D
] [-W
] {mode
-o
} {zonename} {filename}filename
named-checkzone checks the syntax and integrity of a zone file. It performs the same checks as named does when loading a @@ -71,7 +71,7 @@
named-checkzone returns an exit status of 1 if errors were detected and 0 otherwise.
named-journalprint
{journal
}
named-journalprint prints the contents of a zone journal file in a human-readable @@ -76,7 +76,7 @@
named-rrchecker
[-h
] [-o
] [origin
-p
] [-u
] [-C
] [-T
] [-P
]
named-rrchecker read a individual DNS resource record from standard input and checks if it is syntactically correct. @@ -78,7 +78,7 @@
RFC 1034, RFC 1035, diff --git a/doc/arm/man.named.html b/doc/arm/man.named.html index 6305b4cdb0..5ab20a3f66 100644 --- a/doc/arm/man.named.html +++ b/doc/arm/man.named.html @@ -50,7 +50,7 @@
named
[-4
] [-6
] [-c
] [config-file
-d
] [debug-level
-D
] [string
-E
] [engine-name
-f
] [-g
] [-L
] [logfile
-m
] [flag
-n
] [#cpus
-p
] [port
-s
] [-S
] [#max-socks
-t
] [directory
-U
] [#listeners
-u
] [user
-v
] [-V
] [-x
]cache-file
named is a Domain Name System (DNS) server, part of the BIND 9 distribution from ISC. For more @@ -65,7 +65,7 @@
In routine operation, signals should not be used to control the nameserver; rndc should be used @@ -302,7 +302,7 @@
The named configuration file is too complex to describe in detail here. A complete description is provided @@ -319,7 +319,7 @@
nsec3hash
{salt
} {algorithm
} {iterations
} {domain
}
nsec3hash generates an NSEC3 hash based on a set of NSEC3 parameters. This can be used to check the validity @@ -56,7 +56,7 @@
nsupdate
[-d
] [-D
] [[-g
] | [-o
] | [-l
] | [-y
] | [[hmac:]keyname:secret
-k
]] [keyfile
-t
] [timeout
-u
] [udptimeout
-r
] [udpretries
-R
] [randomdev
-v
] [-T
] [-P
] [-V
] [filename]
nsupdate is used to submit Dynamic DNS Update requests as defined in RFC 2136 to a name server. diff --git a/doc/arm/man.rndc-confgen.html b/doc/arm/man.rndc-confgen.html index c65db20c29..44c844ca1b 100644 --- a/doc/arm/man.rndc-confgen.html +++ b/doc/arm/man.rndc-confgen.html @@ -50,7 +50,7 @@
rndc-confgen
[-a
] [-A
] [algorithm
-b
] [keysize
-c
] [keyfile
-h
] [-k
] [keyname
-p
] [port
-r
] [randomfile
-s
] [address
-t
] [chrootdir
-u
]user
rndc-confgen generates configuration files for rndc. It can be used as a @@ -66,7 +66,7 @@
rndc.conf
rndc.conf
is the configuration file
for rndc, the BIND 9 name server control
utility. This file has a similar structure and syntax to
@@ -136,7 +136,7 @@
The name server must be configured to accept rndc connections and
to recognize the key specified in the rndc.conf
@@ -220,7 +220,7 @@
rndc
[-b
] [source-address
-c
] [config-file
-k
] [key-file
-s
] [server
-p
] [port
-q
] [-V
] [-y
] {command}key_id