diff options
Diffstat (limited to 'doc/arm/Bv9ARM-book.xml')
-rw-r--r-- | doc/arm/Bv9ARM-book.xml | 58 |
1 files changed, 46 insertions, 12 deletions
diff --git a/doc/arm/Bv9ARM-book.xml b/doc/arm/Bv9ARM-book.xml index 66eb7525..510e4cc5 100644 --- a/doc/arm/Bv9ARM-book.xml +++ b/doc/arm/Bv9ARM-book.xml @@ -18,7 +18,7 @@ - PERFORMANCE OF THIS SOFTWARE. --> -<!-- File: $Id: Bv9ARM-book.xml,v 1.445 2009/11/10 19:49:32 each Exp $ --> +<!-- File: $Id: Bv9ARM-book.xml,v 1.450 2009/12/04 21:59:23 marka Exp $ --> <book xmlns:xi="http://www.w3.org/2001/XInclude"> <title>BIND 9 Administrator Reference Manual</title> @@ -4906,6 +4906,7 @@ badresp:1,adberr:0,findfail:0,valfail:0] ... }; </optional> <optional> check-names ( <replaceable>master</replaceable> | <replaceable>slave</replaceable> | <replaceable>response</replaceable> ) ( <replaceable>warn</replaceable> | <replaceable>fail</replaceable> | <replaceable>ignore</replaceable> ); </optional> + <optional> check-dup-records ( <replaceable>warn</replaceable> | <replaceable>fail</replaceable> | <replaceable>ignore</replaceable> ); </optional> <optional> check-mx ( <replaceable>warn</replaceable> | <replaceable>fail</replaceable> | <replaceable>ignore</replaceable> ); </optional> <optional> check-wildcard <replaceable>yes_or_no</replaceable>; </optional> <optional> check-integrity <replaceable>yes_or_no</replaceable>; </optional> @@ -4923,8 +4924,8 @@ badresp:1,adberr:0,findfail:0,valfail:0] <optional> allow-update { <replaceable>address_match_list</replaceable> }; </optional> <optional> allow-update-forwarding { <replaceable>address_match_list</replaceable> }; </optional> <optional> update-check-ksk <replaceable>yes_or_no</replaceable>; </optional> - <optional> dnskey-ksk-only <replaceable>yes_or_no</replaceable>; </optional> - <optional> secure-to-insecure <replaceable>yes_or_no</replaceable> ;</optional> + <optional> dnssec-dnskey-kskonly <replaceable>yes_or_no</replaceable>; </optional> + <optional> dnssec-secure-to-insecure <replaceable>yes_or_no</replaceable> ;</optional> <optional> try-tcp-refresh <replaceable>yes_or_no</replaceable>; </optional> <optional> allow-v6-synthesis { <replaceable>address_match_list</replaceable> }; </optional> <optional> blackhole { <replaceable>address_match_list</replaceable> }; </optional> @@ -6251,6 +6252,10 @@ options { to DNS clients unless they have connections to the IPv6 Internet. This is not recommended unless absolutely necessary. The default is <userinput>no</userinput>. + The <command>filter-aaaa-on-v4</command> option + may also be specified in <command>view</command> statements + to override the global <command>filter-aaaa-on-v4</command> + option. </para> <para> If <userinput>yes</userinput>, @@ -6421,6 +6426,30 @@ options { </varlistentry> <varlistentry> + <term><command>check-dup-records</command></term> + <listitem> + <para> + Check master zones for records that are treated as different + by DNSSEC but are semantically equal in plain DNS. The + default is to <command>warn</command>. Other possible + values are <command>fail</command> and + <command>ignore</command>. + </para> + </listitem> + </varlistentry> + + <varlistentry> + <term><command>check-mx</command></term> + <listitem> + <para> + Check whether the MX record appears to refer to a IP address. + The default is to <command>warn</command>. Other possible + values are <command>fail</command> and + <command>ignore</command>. + </para> + </listitem> + </varlistentry> + <varlistentry> <term><command>check-mx</command></term> <listitem> <para> @@ -6552,7 +6581,7 @@ options { </varlistentry> <varlistentry> - <term><command>dnskey-ksk-only</command></term> + <term><command>dnssec-dnskey-kskonly</command></term> <listitem> <para> When this option and <command>update-check-ksk</command> @@ -6584,7 +6613,7 @@ options { </varlistentry> <varlistentry> - <term><command>secure-to-insecure</command></term> + <term><command>dnssec-secure-to-insecure</command></term> <listitem> <para> Allow a zone to transition from secure to insecure by @@ -9516,8 +9545,8 @@ zone <replaceable>zone_name</replaceable> <optional><replaceable>class</replacea <optional> allow-transfer { <replaceable>address_match_list</replaceable> }; </optional> <optional> allow-update-forwarding { <replaceable>address_match_list</replaceable> }; </optional> <optional> update-check-ksk <replaceable>yes_or_no</replaceable>; </optional> - <optional> dnskey-ksk-only <replaceable>yes_or_no</replaceable>; </optional> - <optional> secure-to-insecure <replaceable>yes_or_no</replaceable> ; </optional> + <optional> dnssec-dnskey-kskonly <replaceable>yes_or_no</replaceable>; </optional> + <optional> dnssec-secure-to-insecure <replaceable>yes_or_no</replaceable> ; </optional> <optional> try-tcp-refresh <replaceable>yes_or_no</replaceable>; </optional> <optional> also-notify { <replaceable>ip_addr</replaceable> <optional>port <replaceable>ip_port</replaceable></optional> ; <optional> <replaceable>ip_addr</replaceable> <optional>port <replaceable>ip_port</replaceable></optional> ; ... </optional> }; </optional> @@ -10030,11 +10059,11 @@ zone <replaceable>zone_name</replaceable> <optional><replaceable>class</replacea </varlistentry> <varlistentry> - <term><command>dnskey-ksk-only</command></term> + <term><command>dnssec-dnskey-kskonly</command></term> <listitem> <para> See the description of - <command>dnskey-ksk-only</command> in <xref linkend="boolean_options"/>. + <command>dnssec-dnskey-kskonly</command> in <xref linkend="boolean_options"/>. </para> </listitem> </varlistentry> @@ -10431,7 +10460,8 @@ zone <replaceable>zone_name</replaceable> <optional><replaceable>class</replacea <para> <command>auto-dnssec allow;</command> permits keys to be updated and the zone re-signed whenever the - user issues the command <command>rndc sign</command>. + user issues the command <command>rndc sign + <replaceable>zonename</replaceable></command>. </para> <para> <command>auto-dnssec maintain;</command> includes the @@ -10474,11 +10504,11 @@ zone <replaceable>zone_name</replaceable> <optional><replaceable>class</replacea </varlistentry> <varlistentry> - <term><command>secure-to-insecure</command></term> + <term><command>dnssec-secure-to-insecure</command></term> <listitem> <para> See the description of - <command>secure-to-insecure</command> in <xref linkend="boolean_options"/>. + <command>dnssec-secure-to-insecure</command> in <xref linkend="boolean_options"/>. </para> </listitem> </varlistentry> @@ -15617,12 +15647,16 @@ zone "example.com" { <xi:include href="../../bin/check/named-checkconf.docbook"/> <xi:include href="../../bin/check/named-checkzone.docbook"/> <xi:include href="../../bin/named/named.docbook"/> + <xi:include href="../../bin/tools/named-journalprint.docbook"/> <!-- named.conf.docbook and others? --> <xi:include href="../../bin/nsupdate/nsupdate.docbook"/> <xi:include href="../../bin/rndc/rndc.docbook"/> <xi:include href="../../bin/rndc/rndc.conf.docbook"/> <xi:include href="../../bin/confgen/rndc-confgen.docbook"/> <xi:include href="../../bin/confgen/ddns-confgen.docbook"/> + <xi:include href="../../bin/tools/arpaname.docbook"/> + <xi:include href="../../bin/tools/genrandom.docbook"/> + <xi:include href="../../bin/tools/nsec3hash.docbook"/> </reference> </book> |