table of contents
RNDC(8) | BIND9 | RNDC(8) |
NAME¶
rndc - name server control utility
SYNOPSIS¶
rndc [-b source-address] [-c config-file] [-k key-file] [-s server] [-p port] [-V] [-y key_id] {command}
DESCRIPTION¶
rndc controls the operation of a name server. It supersedes the ndc utility that was provided in old BIND releases. If rndc is invoked with no command line options or arguments, it prints a short summary of the supported commands and the available options and their arguments.
rndc communicates with the name server over a TCP connection, sending commands authenticated with digital signatures. In the current versions of rndc and named, the only supported authentication algorithm is HMAC-MD5, which uses a shared secret on each end of the connection. This provides TSIG-style authentication for the command request and the name server's response. All commands sent over the channel must be signed by a key_id known to the server.
rndc reads a configuration file to determine how to contact the name server and decide what algorithm and key it should use.
OPTIONS¶
-b source-address
-c config-file
-k key-file
-s server
-p port
-V
-y key_id
For the complete set of commands supported by rndc, see the BIND 9 Administrator Reference Manual or run rndc without arguments to see its help message.
LIMITATIONS¶
rndc does not yet support all the commands of the BIND 8 ndc utility.
There is currently no way to provide the shared secret for a key_id without using the configuration file.
Several error messages could be clearer.
SEE ALSO¶
rndc.conf(5), rndc-confgen(8), named(8), named.conf(5), ndc(8), BIND 9 Administrator Reference Manual.
AUTHOR¶
Internet Systems Consortium
COPYRIGHT¶
Copyright © 2004, 2005, 2007 Internet Systems Consortium,
Inc. ("ISC")
Copyright © 2000, 2001 Internet Software Consortium.
June 30, 2000 | BIND9 |