--- /srv/reproducible-results/rbuild-debian/r-b-build.SCy7PSmY/b1/bind9_9.19.24-185-g392e7199df2-1_amd64.changes +++ /srv/reproducible-results/rbuild-debian/r-b-build.SCy7PSmY/b2/bind9_9.19.24-185-g392e7199df2-1_amd64.changes ├── Files │ @@ -1,13 +1,13 @@ │ │ e9b99e865c0b257b63f6020382510016 666556 debug optional bind9-dbgsym_9.19.24-185-g392e7199df2-1_amd64.deb │ 47fb0490cf0d7b41fafc0db970736c00 552252 devel optional bind9-dev_9.19.24-185-g392e7199df2-1_amd64.deb │ 5147e4881302cd930adfc1c8d2444997 430504 debug optional bind9-dnsutils-dbgsym_9.19.24-185-g392e7199df2-1_amd64.deb │ 6114eec7dc851b65bb20634072c8a179 427104 net standard bind9-dnsutils_9.19.24-185-g392e7199df2-1_amd64.deb │ - 9ba5ee94421568ad5895fab77750c266 3496968 doc optional bind9-doc_9.19.24-185-g392e7199df2-1_all.deb │ + 33f063eef619e55af25305aafaad3e28 3496944 doc optional bind9-doc_9.19.24-185-g392e7199df2-1_all.deb │ 3cdaab25c9df5c0aad696b869f834fb9 105476 debug optional bind9-host-dbgsym_9.19.24-185-g392e7199df2-1_amd64.deb │ 4ffbd8ee21011079e48d974c7e2bba10 317840 net standard bind9-host_9.19.24-185-g392e7199df2-1_amd64.deb │ 151c38c362b37b76fe31f6d01aa40a4e 4038924 debug optional bind9-libs-dbgsym_9.19.24-185-g392e7199df2-1_amd64.deb │ b80247560b965c8310d5ba7f5cf456f5 1465068 libs standard bind9-libs_9.19.24-185-g392e7199df2-1_amd64.deb │ 06877671140369e57d9c4745071ad614 481652 debug optional bind9-utils-dbgsym_9.19.24-185-g392e7199df2-1_amd64.deb │ 15a801324134bf246c8be6aa39bd554f 443700 net optional bind9-utils_9.19.24-185-g392e7199df2-1_amd64.deb │ abfd0e4f6d0ff50c4f7a853ca9d0538b 509300 net optional bind9_9.19.24-185-g392e7199df2-1_amd64.deb ├── bind9-doc_9.19.24-185-g392e7199df2-1_all.deb │ ├── file list │ │ @@ -1,3 +1,3 @@ │ │ -rw-r--r-- 0 0 0 4 2024-06-20 13:11:56.000000 debian-binary │ │ -rw-r--r-- 0 0 0 2012 2024-06-20 13:11:56.000000 control.tar.xz │ │ --rw-r--r-- 0 0 0 3494764 2024-06-20 13:11:56.000000 data.tar.xz │ │ +-rw-r--r-- 0 0 0 3494740 2024-06-20 13:11:56.000000 data.tar.xz │ ├── control.tar.xz │ │ ├── control.tar │ │ │ ├── ./md5sums │ │ │ │ ├── ./md5sums │ │ │ │ │┄ Files differ │ ├── data.tar.xz │ │ ├── data.tar │ │ │ ├── ./usr/share/doc/bind9-doc/arm/reference.html │ │ │ │ @@ -762,15 +762,15 @@ │ │ │ │ key-directory.

│ │ │ │

The following options can be specified in a key-store statement:

│ │ │ │
│ │ │ │
│ │ │ │ pkcs11-uri
│ │ │ │

Grammar: pkcs11-uri <quoted_string>;

│ │ │ │

Blocks: key-store

│ │ │ │ -

Tags: pkcs11, dnssec

│ │ │ │ +

Tags: dnssec, pkcs11

│ │ │ │

The uri is a string that specifies a PKCS#11 URI Scheme (defined in │ │ │ │ RFC 7512). When set, named will try to create keys inside the │ │ │ │ corresponding PKCS#11 token. This requires BIND to be built with OpenSSL 3, │ │ │ │ and have a PKCS#11 provider configured.

│ │ │ │
│ │ │ │ │ │ │ │ │ │ │ │ @@ -2752,15 +2752,15 @@ │ │ │ │ │ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ zone-statistics
│ │ │ │

Grammar: zone-statistics ( full | terse | none | <boolean> );

│ │ │ │

Blocks: options, view, zone (mirror, primary, redirect, secondary, static-stub, stub)

│ │ │ │ -

Tags: logging, zone

│ │ │ │ +

Tags: zone, logging

│ │ │ │

Controls the level of statistics gathered for all zones.

│ │ │ │

│ │ │ │

If full, the server collects statistical data on all zones, │ │ │ │ unless specifically turned off on a per-zone basis by specifying │ │ │ │ zone-statistics terse or zone-statistics none in the zone │ │ │ │ statement. The statistical data includes, for example, DNSSEC signing │ │ │ │ operations and the number of authoritative answers per query type. The │ │ │ │ @@ -3637,15 +3637,15 @@ │ │ │ │

│ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ check-dup-records
│ │ │ │

Grammar: check-dup-records ( fail | warn | ignore );

│ │ │ │

Blocks: options, view, zone (primary)

│ │ │ │ -

Tags: query, dnssec

│ │ │ │ +

Tags: dnssec, query

│ │ │ │

Checks primary zones for records that are treated as different by DNSSEC but are semantically equal in plain DNS.

│ │ │ │

│ │ │ │

This checks primary zones for records that are treated as different by │ │ │ │ DNSSEC but are semantically equal in plain DNS. The default is to │ │ │ │ warn. Other possible values are fail and ignore.

│ │ │ │
│ │ │ │ │ │ │ │ @@ -3766,28 +3766,28 @@ │ │ │ │ │ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ zero-no-soa-ttl
│ │ │ │

Grammar: zero-no-soa-ttl <boolean>;

│ │ │ │

Blocks: options, view, zone (mirror, primary, secondary)

│ │ │ │ -

Tags: server, query, zone

│ │ │ │ +

Tags: zone, query, server

│ │ │ │

Specifies whether to set the time to live (TTL) of the SOA record to zero, when returning authoritative negative responses to SOA queries.

│ │ │ │

│ │ │ │

If yes, when returning authoritative negative responses to SOA queries, set │ │ │ │ the TTL of the SOA record returned in the authority section to zero. │ │ │ │ The default is yes.

│ │ │ │
│ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ zero-no-soa-ttl-cache
│ │ │ │

Grammar: zero-no-soa-ttl-cache <boolean>;

│ │ │ │

Blocks: options, view

│ │ │ │ -

Tags: server, query, zone

│ │ │ │ +

Tags: zone, query, server

│ │ │ │

Sets the time to live (TTL) to zero when caching a negative response to an SOA query.

│ │ │ │

│ │ │ │

If yes, when caching a negative response to an SOA query set the TTL to zero. │ │ │ │ The default is no.

│ │ │ │
│ │ │ │ │ │ │ │
│ │ │ │ @@ -4680,30 +4680,30 @@ │ │ │ │
│ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ notify-rate
│ │ │ │

Grammar: notify-rate <integer>;

│ │ │ │

Blocks: options

│ │ │ │ -

Tags: transfer, zone

│ │ │ │ +

Tags: zone, transfer

│ │ │ │

Specifies the rate at which NOTIFY requests are sent during normal zone maintenance operations.

│ │ │ │

│ │ │ │

This specifies the rate at which NOTIFY requests are sent during normal zone │ │ │ │ maintenance operations. (NOTIFY requests due to initial zone loading │ │ │ │ are subject to a separate rate limit; see below.) The default is 20 │ │ │ │ per second. The lowest possible rate is one per second; when set to │ │ │ │ zero, it is silently raised to one.

│ │ │ │
│ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ startup-notify-rate
│ │ │ │

Grammar: startup-notify-rate <integer>;

│ │ │ │

Blocks: options

│ │ │ │ -

Tags: transfer, zone

│ │ │ │ +

Tags: zone, transfer

│ │ │ │

Specifies the rate at which NOTIFY requests are sent when the name server is first starting, or when new zones have been added.

│ │ │ │

│ │ │ │

This is the rate at which NOTIFY requests are sent when the name server │ │ │ │ is first starting up, or when zones have been newly added to the │ │ │ │ name server. The default is 20 per second. The lowest possible rate is │ │ │ │ one per second; when set to zero, it is silently raised to one.

│ │ │ │
│ │ │ │ @@ -4932,15 +4932,15 @@ │ │ │ │ │ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ max-records
│ │ │ │

Grammar: max-records <integer>;

│ │ │ │

Blocks: options, view, zone (mirror, primary, redirect, secondary, static-stub, stub)

│ │ │ │ -

Tags: server, zone

│ │ │ │ +

Tags: zone, server

│ │ │ │

Sets the maximum number of records permitted in a zone.

│ │ │ │

│ │ │ │

This sets the maximum number of records permitted in a zone. The default is │ │ │ │ zero, which means the maximum is unlimited.

│ │ │ │
│ │ │ │ │ │ │ │
│ │ │ │ @@ -5363,15 +5363,15 @@ │ │ │ │ sortlist │ │ │ │
│ │ │ │

Warning

│ │ │ │

This option is deprecated and will be removed in a future version of BIND.

│ │ │ │
│ │ │ │

Grammar: sortlist { <address_match_element>; ... }; // deprecated

│ │ │ │

Blocks: options, view

│ │ │ │ -

Tags: query, deprecated

│ │ │ │ +

Tags: deprecated, query

│ │ │ │

Controls the ordering of RRs returned to the client, based on the client’s IP address.

│ │ │ │

│ │ │ │

This option is deprecated and will be removed in a future release.

│ │ │ │

The sortlist statement (see below) takes an address_match_list and │ │ │ │ interprets it in a special way. Each top-level statement in the sortlist │ │ │ │ must itself be an explicit address_match_list with one or two elements. The │ │ │ │ first element (which may be an IP address, an IP prefix, an ACL name, or a nested │ │ │ │ @@ -5895,15 +5895,15 @@ │ │ │ │

│ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ masterfile-format
│ │ │ │

Grammar: masterfile-format ( raw | text );

│ │ │ │

Blocks: options, view, zone (mirror, primary, redirect, secondary, stub)

│ │ │ │ -

Tags: server, zone

│ │ │ │ +

Tags: zone, server

│ │ │ │

Specifies the file format of zone files.

│ │ │ │

│ │ │ │

This specifies the file format of zone files (see Additional File Formats │ │ │ │ for details). The default value is text, which is the standard │ │ │ │ textual representation, except for secondary zones, in which the default │ │ │ │ value is raw. Files in formats other than text are typically │ │ │ │ expected to be generated by the named-compilezone tool, or dumped by │ │ │ │ @@ -5971,15 +5971,15 @@ │ │ │ │

│ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ notify-delay
│ │ │ │

Grammar: notify-delay <integer>;

│ │ │ │

Blocks: options, view, zone (mirror, primary, secondary)

│ │ │ │ -

Tags: transfer, zone

│ │ │ │ +

Tags: zone, transfer

│ │ │ │

Sets the delay (in seconds) between sending sets of NOTIFY messages for a zone.

│ │ │ │

│ │ │ │

This sets the delay, in seconds, between sending sets of NOTIFY messages │ │ │ │ for a zone. Whenever a NOTIFY message is sent for a zone, a timer will │ │ │ │ be set for this duration. If the zone is updated again before the timer │ │ │ │ expires, the NOTIFY for that update will be postponed. The default is 5 │ │ │ │ seconds.

│ │ │ │ @@ -5988,15 +5988,15 @@ │ │ │ │
│ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ max-rsa-exponent-size
│ │ │ │

Grammar: max-rsa-exponent-size <integer>;

│ │ │ │

Blocks: options

│ │ │ │ -

Tags: query, dnssec

│ │ │ │ +

Tags: dnssec, query

│ │ │ │

Sets the maximum RSA exponent size (in bits) when validating.

│ │ │ │

│ │ │ │

This sets the maximum RSA exponent size, in bits, that is accepted when │ │ │ │ validating. Valid values are 35 to 4096 bits. The default, zero, is │ │ │ │ also accepted and is equivalent to 4096.

│ │ │ │
│ │ │ │ │ │ │ │ @@ -6458,15 +6458,15 @@ │ │ │ │ deny the existence of domains (NXDOMAIN), deny the existence of IP │ │ │ │ addresses for domains (NODATA), or contain other IP addresses or data.

│ │ │ │
│ │ │ │
│ │ │ │ response-policy
│ │ │ │

Grammar: response-policy { zone <string> [ add-soa <boolean> ] [ log <boolean> ] [ max-policy-ttl <duration> ] [ min-update-interval <duration> ] [ policy ( cname | disabled | drop | given | no-op | nodata | nxdomain | passthru | tcp-only <quoted_string> ) ] [ recursive-only <boolean> ] [ nsip-enable <boolean> ] [ nsdname-enable <boolean> ] [ ede <string> ]; ... } [ add-soa <boolean> ] [ break-dnssec <boolean> ] [ max-policy-ttl <duration> ] [ min-update-interval <duration> ] [ min-ns-dots <integer> ] [ nsip-wait-recurse <boolean> ] [ nsdname-wait-recurse <boolean> ] [ qname-wait-recurse <boolean> ] [ recursive-only <boolean> ] [ nsip-enable <boolean> ] [ nsdname-enable <boolean> ] [ dnsrps-enable <boolean> ] [ dnsrps-options { <unspecified-text> } ];

│ │ │ │

Blocks: options, view

│ │ │ │ -

Tags: security, query, zone, server

│ │ │ │ +

Tags: zone, query, security, server

│ │ │ │

Specifies response policy zones for the view or among global options.

│ │ │ │

│ │ │ │

Response policy zones are named in the response-policy option for │ │ │ │ the view, or among the global options if there is no response-policy │ │ │ │ option for the view. Response policy zones are ordinary DNS zones │ │ │ │ containing RRsets that can be queried normally if allowed. It is usually │ │ │ │ best to restrict those queries with something like │ │ │ │ @@ -7126,15 +7126,15 @@ │ │ │ │

│ │ │ │ │ │ │ │
│ │ │ │
│ │ │ │ log-only
│ │ │ │

Grammar: log-only <boolean>;

│ │ │ │

Blocks: options.rate-limit, view.rate-limit

│ │ │ │ -

Tags: query, logging

│ │ │ │ +

Tags: logging, query

│ │ │ │

Tests rate-limiting parameters without actually dropping any requests.

│ │ │ │

│ │ │ │

Use log-only yes to test rate-limiting parameters without actually │ │ │ │ dropping any requests.

│ │ │ │
│ │ │ │ │ │ │ │

Responses dropped by rate limits are included in the RateDropped and │ │ │ │ @@ -9751,15 +9751,15 @@ │ │ │ │ │ │ │ │ │ │ │ │

│ │ │ │
│ │ │ │ server-addresses
│ │ │ │

Grammar: server-addresses { ( <ipv4_address> | <ipv6_address> ); ... };

│ │ │ │

Blocks: zone (static-stub)

│ │ │ │ -

Tags: query, zone

│ │ │ │ +

Tags: zone, query

│ │ │ │

Specifies a list of IP addresses to which queries should be sent in recursive resolution for a static-stub zone.

│ │ │ │

│ │ │ │

This option is only meaningful for static-stub zones. This is a list of IP addresses │ │ │ │ to which queries should be sent in recursive resolution for the zone. │ │ │ │ A non-empty list for this option internally configures the apex │ │ │ │ NS RR with associated glue A or AAAA RRs.

│ │ │ │

For example, if “example.com” is configured as a static-stub zone │ │ │ │ @@ -10318,15 +10318,15 @@ │ │ │ │

Defines a stream of data that can be independently logged.

│ │ │ │

│ │ │ │

logging

│ │ │ │ │ │ │ │ check-dup-records │ │ │ │

Checks primary zones for records that are treated as different by DNSSEC but are semantically equal in plain DNS.

│ │ │ │

│ │ │ │ -

query, dnssec

│ │ │ │ +

dnssec, query

│ │ │ │ │ │ │ │ check-integrity │ │ │ │

Performs post-load zone integrity checks on primary zones.

│ │ │ │

│ │ │ │

zone

│ │ │ │ │ │ │ │ check-mx │ │ │ │ @@ -10834,15 +10834,15 @@ │ │ │ │

Sets a maximum size for the memory map of the new-zone database in LMDB database format.

│ │ │ │

│ │ │ │

server

│ │ │ │ │ │ │ │ log-only │ │ │ │

Tests rate-limiting parameters without actually dropping any requests.

│ │ │ │

│ │ │ │ -

query, logging

│ │ │ │ +

logging, query

│ │ │ │ │ │ │ │ logging │ │ │ │

Configures logging options for the name server.

│ │ │ │

│ │ │ │

logging

│ │ │ │ │ │ │ │ managed-keys │ │ │ │ @@ -10858,15 +10858,15 @@ │ │ │ │

Specifies an access control list (ACL) of IPv4 addresses that are to be mapped to the corresponding A RRset in dns64.

│ │ │ │

│ │ │ │

query

│ │ │ │ │ │ │ │ masterfile-format │ │ │ │

Specifies the file format of zone files.

│ │ │ │

│ │ │ │ -

server, zone

│ │ │ │ +

zone, server

│ │ │ │ │ │ │ │ masterfile-style │ │ │ │

Specifies the format of zone files during a dump, when the masterfile-format is text.

│ │ │ │

│ │ │ │

server

│ │ │ │ │ │ │ │ match-clients │ │ │ │ @@ -10918,15 +10918,15 @@ │ │ │ │

Specifies the maximum retention time (in seconds) for storage of negative answers in the server's cache.

│ │ │ │

│ │ │ │

server

│ │ │ │ │ │ │ │ max-records │ │ │ │

Sets the maximum number of records permitted in a zone.

│ │ │ │

│ │ │ │ -

server, zone

│ │ │ │ +

zone, server

│ │ │ │ │ │ │ │ max-recursion-depth │ │ │ │

Sets the maximum number of levels of recursion permitted at any one time while servicing a recursive query.

│ │ │ │

│ │ │ │

server

│ │ │ │ │ │ │ │ max-recursion-queries │ │ │ │ @@ -10943,15 +10943,15 @@ │ │ │ │

Limits the zone refresh retry interval to no less often than the specified value, in seconds.

│ │ │ │

│ │ │ │

transfer

│ │ │ │ │ │ │ │ max-rsa-exponent-size │ │ │ │

Sets the maximum RSA exponent size (in bits) when validating.

│ │ │ │

│ │ │ │ -

query, dnssec

│ │ │ │ +

dnssec, query

│ │ │ │ │ │ │ │ max-stale-ttl │ │ │ │

Specifies the maximum time that the server retains records past their normal expiry, to return them as stale records.

│ │ │ │

│ │ │ │

server

│ │ │ │ │ │ │ │ max-table-size │ │ │ │ @@ -11078,20 +11078,20 @@ │ │ │ │

Controls whether NOTIFY messages are sent on zone changes.

│ │ │ │

│ │ │ │

transfer

│ │ │ │ │ │ │ │ notify-delay │ │ │ │

Sets the delay (in seconds) between sending sets of NOTIFY messages for a zone.

│ │ │ │

│ │ │ │ -

transfer, zone

│ │ │ │ +

zone, transfer

│ │ │ │ │ │ │ │ notify-rate │ │ │ │

Specifies the rate at which NOTIFY requests are sent during normal zone maintenance operations.

│ │ │ │

│ │ │ │ -

transfer, zone

│ │ │ │ +

zone, transfer

│ │ │ │ │ │ │ │ notify-source │ │ │ │

Defines the IPv4 address (and optional port) to be used for outgoing NOTIFY messages.

│ │ │ │

│ │ │ │

transfer

│ │ │ │ │ │ │ │ notify-source-v6 │ │ │ │ @@ -11172,15 +11172,15 @@ │ │ │ │ pid-file │ │ │ │

Specifies the pathname of the file where the server writes its process ID.

│ │ │ │

│ │ │ │

server

│ │ │ │ │ │ │ │ pkcs11-uri │ │ │ │

│ │ │ │ -

pkcs11, dnssec

│ │ │ │ +

dnssec, pkcs11

│ │ │ │ │ │ │ │ plugin │ │ │ │

Configures plugins in named.conf.

│ │ │ │

│ │ │ │

server

│ │ │ │ │ │ │ │ port │ │ │ │ @@ -11342,15 +11342,15 @@ │ │ │ │

Adds an EDNS Padding option to encrypted messages, to reduce the chance of guessing the contents based on size.

│ │ │ │

│ │ │ │

query

│ │ │ │ │ │ │ │ response-policy │ │ │ │

Specifies response policy zones for the view or among global options.

│ │ │ │

│ │ │ │ -

security, query, zone, server

│ │ │ │ +

zone, query, security, server

│ │ │ │ │ │ │ │ responses-per-second │ │ │ │

Limits the number of non-empty responses for a valid domain name and record type.

│ │ │ │

│ │ │ │

query

│ │ │ │ │ │ │ │ retire-safety │ │ │ │ @@ -11407,15 +11407,15 @@ │ │ │ │

Defines characteristics to be associated with a remote name server.

│ │ │ │

│ │ │ │

server

│ │ │ │ │ │ │ │ server-addresses │ │ │ │

Specifies a list of IP addresses to which queries should be sent in recursive resolution for a static-stub zone.

│ │ │ │

│ │ │ │ -

query, zone

│ │ │ │ +

zone, query

│ │ │ │ │ │ │ │ server-id │ │ │ │

Specifies the ID of the server to return in response to a ID.SERVER query.

│ │ │ │

│ │ │ │

server

│ │ │ │ │ │ │ │ server-names │ │ │ │ @@ -11496,15 +11496,15 @@ │ │ │ │

Sets the number of "slipped" responses to minimize the use of forged source addresses for an attack.

│ │ │ │

│ │ │ │

query

│ │ │ │ │ │ │ │ sortlist │ │ │ │

Controls the ordering of RRs returned to the client, based on the client's IP address.

│ │ │ │

│ │ │ │ -

query, deprecated

│ │ │ │ +

deprecated, query

│ │ │ │ │ │ │ │ stale-answer-client-timeout │ │ │ │

Defines the amount of time (in milliseconds) that named waits before attempting to answer a query with a stale RRset from cache.

│ │ │ │

│ │ │ │

query, server

│ │ │ │ │ │ │ │ stale-answer-enable │ │ │ │ @@ -11526,15 +11526,15 @@ │ │ │ │

Sets the time window for the return of "stale" cached answers before the next attempt to contact, if the name servers for a given zone are not responding.

│ │ │ │

│ │ │ │

query, server

│ │ │ │ │ │ │ │ startup-notify-rate │ │ │ │

Specifies the rate at which NOTIFY requests are sent when the name server is first starting, or when new zones have been added.

│ │ │ │

│ │ │ │ -

transfer, zone

│ │ │ │ +

zone, transfer

│ │ │ │ │ │ │ │ statistics-channels │ │ │ │

Specifies the communication channels to be used by system administrators to access statistics information on the name server.

│ │ │ │

│ │ │ │

logging

│ │ │ │ │ │ │ │ statistics-file │ │ │ │ @@ -11809,35 +11809,35 @@ │ │ │ │

Specifies the length of time during which responses are tracked.

│ │ │ │

│ │ │ │

query

│ │ │ │ │ │ │ │ zero-no-soa-ttl │ │ │ │

Specifies whether to set the time to live (TTL) of the SOA record to zero, when returning authoritative negative responses to SOA queries.

│ │ │ │

│ │ │ │ -

server, query, zone

│ │ │ │ +

zone, query, server

│ │ │ │ │ │ │ │ zero-no-soa-ttl-cache │ │ │ │

Sets the time to live (TTL) to zero when caching a negative response to an SOA query.

│ │ │ │

│ │ │ │ -

server, query, zone

│ │ │ │ +

zone, query, server

│ │ │ │ │ │ │ │ zone │ │ │ │

Specifies the zone in a BIND 9 configuration.

│ │ │ │

│ │ │ │

zone

│ │ │ │ │ │ │ │ zone-propagation-delay │ │ │ │

Sets the propagation delay from the time a zone is first updated to when the new version of the zone is served by all secondary servers.

│ │ │ │

│ │ │ │

dnssec, zone

│ │ │ │ │ │ │ │ zone-statistics │ │ │ │

Controls the level of statistics gathered for all zones.

│ │ │ │

│ │ │ │ -

logging, zone

│ │ │ │ +

zone, logging

│ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │ │
│ │ │ │

8.4. Statements by Tag

│ │ │ │

These tables group the various statements permissible in named.conf by │ │ │ │ ├── html2text {} │ │ │ │ │ @@ -515,15 +515,15 @@ │ │ │ │ │ The key-store statement defines how DNSSEC keys should be stored. │ │ │ │ │ There is one built-in key store named key-directory. Configuring keys to use │ │ │ │ │ key-store "key-directory" is identical to using key-directory. │ │ │ │ │ The following options can be specified in a _k_e_y_-_s_t_o_r_e statement: │ │ │ │ │ pkcs11-uri_ │ │ │ │ │ GGrraammmmaarr:: pkcs11-uri ; │ │ │ │ │ BBlloocckkss:: key-store │ │ │ │ │ - TTaaggss:: pkcs11, dnssec │ │ │ │ │ + TTaaggss:: dnssec, pkcs11 │ │ │ │ │ The uri is a string that specifies a PKCS#11 URI Scheme (defined in _RR_FF_CC │ │ │ │ │ _77_55_11_22). When set, named will try to create keys inside the corresponding │ │ │ │ │ PKCS#11 token. This requires BIND to be built with OpenSSL 3, and have a │ │ │ │ │ PKCS#11 provider configured. │ │ │ │ │ ******** 88..22..99.. _ll_oo_gg_gg_ii_nn_gg BBlloocckk GGrraammmmaarr_? ******** │ │ │ │ │ ******** 88..22..1100.. _ll_oo_gg_gg_ii_nn_gg BBlloocckk DDeeffiinniittiioonn aanndd UUssaaggee_? ******** │ │ │ │ │ The _l_o_g_g_i_n_g statement configures a wide variety of logging options for the name │ │ │ │ │ @@ -2500,15 +2500,15 @@ │ │ │ │ │ certificate for a │ │ │ │ │ connection. │ │ │ │ │ Defines a stream of data │ │ │ │ │ _c_h_a_n_n_e_l that can be independently logging │ │ │ │ │ logged. │ │ │ │ │ Checks primary zones for │ │ │ │ │ records that are treated as │ │ │ │ │ -_c_h_e_c_k_-_d_u_p_-_r_e_c_o_r_d_s different by DNSSEC but are query, dnssec │ │ │ │ │ +_c_h_e_c_k_-_d_u_p_-_r_e_c_o_r_d_s different by DNSSEC but are dnssec, query │ │ │ │ │ semantically equal in plain │ │ │ │ │ DNS. │ │ │ │ │ Performs post-load zone │ │ │ │ │ _c_h_e_c_k_-_i_n_t_e_g_r_i_t_y integrity checks on primary zone │ │ │ │ │ zones. │ │ │ │ │ Checks whether an MX record │ │ │ │ │ _c_h_e_c_k_-_m_x appears to refer to an IP zone │ │ │ │ │ @@ -2824,29 +2824,29 @@ │ │ │ │ │ _l_i_s_t_e_n_e_r_-_c_l_i_e_n_t_s quota for active query, server │ │ │ │ │ connections. │ │ │ │ │ Sets a maximum size for the │ │ │ │ │ _l_m_d_b_-_m_a_p_s_i_z_e memory map of the new-zone server │ │ │ │ │ database in LMDB database │ │ │ │ │ format. │ │ │ │ │ Tests rate-limiting │ │ │ │ │ -_l_o_g_-_o_n_l_y parameters without actually query, logging │ │ │ │ │ +_l_o_g_-_o_n_l_y parameters without actually logging, query │ │ │ │ │ dropping any requests. │ │ │ │ │ _l_o_g_g_i_n_g Configures logging options logging │ │ │ │ │ for the name server. │ │ │ │ │ _m_a_n_a_g_e_d_-_k_e_y_s deprecated │ │ │ │ │ Specifies the directory in │ │ │ │ │ _m_a_n_a_g_e_d_-_k_e_y_s_-_d_i_r_e_c_t_o_r_y which to store the files dnssec │ │ │ │ │ that track managed DNSSEC │ │ │ │ │ keys. │ │ │ │ │ Specifies an access control │ │ │ │ │ list (ACL) of IPv4 addresses │ │ │ │ │ _m_a_p_p_e_d that are to be mapped to the query │ │ │ │ │ corresponding A RRset in │ │ │ │ │ _d_n_s_6_4. │ │ │ │ │ -_m_a_s_t_e_r_f_i_l_e_-_f_o_r_m_a_t Specifies the file format of server, zone │ │ │ │ │ +_m_a_s_t_e_r_f_i_l_e_-_f_o_r_m_a_t Specifies the file format of zone, server │ │ │ │ │ zone files. │ │ │ │ │ Specifies the format of zone │ │ │ │ │ _m_a_s_t_e_r_f_i_l_e_-_s_t_y_l_e files during a dump, when server │ │ │ │ │ the _m_a_s_t_e_r_f_i_l_e_-_f_o_r_m_a_t is │ │ │ │ │ text. │ │ │ │ │ Specifies a view of DNS │ │ │ │ │ _m_a_t_c_h_-_c_l_i_e_n_t_s namespace for a given subset view │ │ │ │ │ @@ -2883,15 +2883,15 @@ │ │ │ │ │ _m_a_x_-_j_o_u_r_n_a_l_-_s_i_z_e Controls the size of journal transfer │ │ │ │ │ files. │ │ │ │ │ Specifies the maximum │ │ │ │ │ retention time (in seconds) │ │ │ │ │ _m_a_x_-_n_c_a_c_h_e_-_t_t_l for storage of negative server │ │ │ │ │ answers in the server's │ │ │ │ │ cache. │ │ │ │ │ -_m_a_x_-_r_e_c_o_r_d_s Sets the maximum number of server, zone │ │ │ │ │ +_m_a_x_-_r_e_c_o_r_d_s Sets the maximum number of zone, server │ │ │ │ │ records permitted in a zone. │ │ │ │ │ Sets the maximum number of │ │ │ │ │ levels of recursion │ │ │ │ │ _m_a_x_-_r_e_c_u_r_s_i_o_n_-_d_e_p_t_h permitted at any one time server │ │ │ │ │ while servicing a recursive │ │ │ │ │ query. │ │ │ │ │ Sets the maximum number of │ │ │ │ │ @@ -2902,15 +2902,15 @@ │ │ │ │ │ than the specified value, in │ │ │ │ │ seconds. │ │ │ │ │ Limits the zone refresh │ │ │ │ │ _m_a_x_-_r_e_t_r_y_-_t_i_m_e retry interval to no less transfer │ │ │ │ │ often than the specified │ │ │ │ │ value, in seconds. │ │ │ │ │ Sets the maximum RSA │ │ │ │ │ -_m_a_x_-_r_s_a_-_e_x_p_o_n_e_n_t_-_s_i_z_e exponent size (in bits) when query, dnssec │ │ │ │ │ +_m_a_x_-_r_s_a_-_e_x_p_o_n_e_n_t_-_s_i_z_e exponent size (in bits) when dnssec, query │ │ │ │ │ validating. │ │ │ │ │ Specifies the maximum time │ │ │ │ │ that the server retains │ │ │ │ │ _m_a_x_-_s_t_a_l_e_-_t_t_l records past their normal server │ │ │ │ │ expiry, to return them as │ │ │ │ │ stale records. │ │ │ │ │ Sets the maximum size of the │ │ │ │ │ @@ -3007,18 +3007,18 @@ │ │ │ │ │ Limits the number of empty │ │ │ │ │ _n_o_d_a_t_a_-_p_e_r_-_s_e_c_o_n_d (NODATA) responses for a query │ │ │ │ │ valid domain name. │ │ │ │ │ Controls whether NOTIFY │ │ │ │ │ _n_o_t_i_f_y messages are sent on zone transfer │ │ │ │ │ changes. │ │ │ │ │ Sets the delay (in seconds) │ │ │ │ │ -_n_o_t_i_f_y_-_d_e_l_a_y between sending sets of transfer, zone │ │ │ │ │ +_n_o_t_i_f_y_-_d_e_l_a_y between sending sets of zone, transfer │ │ │ │ │ NOTIFY messages for a zone. │ │ │ │ │ Specifies the rate at which │ │ │ │ │ -_n_o_t_i_f_y_-_r_a_t_e NOTIFY requests are sent transfer, zone │ │ │ │ │ +_n_o_t_i_f_y_-_r_a_t_e NOTIFY requests are sent zone, transfer │ │ │ │ │ during normal zone │ │ │ │ │ maintenance operations. │ │ │ │ │ Defines the IPv4 address │ │ │ │ │ _n_o_t_i_f_y_-_s_o_u_r_c_e (and optional port) to be transfer │ │ │ │ │ used for outgoing NOTIFY │ │ │ │ │ messages. │ │ │ │ │ Defines the IPv6 address │ │ │ │ │ @@ -3072,15 +3072,15 @@ │ │ │ │ │ send parental DS queries. │ │ │ │ │ Specifies which local IPv6 │ │ │ │ │ _p_a_r_e_n_t_a_l_-_s_o_u_r_c_e_-_v_6 source address is used to dnssec │ │ │ │ │ send parental DS queries. │ │ │ │ │ Specifies the pathname of │ │ │ │ │ _p_i_d_-_f_i_l_e the file where the server server │ │ │ │ │ writes its process ID. │ │ │ │ │ -_p_k_c_s_1_1_-_u_r_i pkcs11, dnssec │ │ │ │ │ +_p_k_c_s_1_1_-_u_r_i dnssec, pkcs11 │ │ │ │ │ _p_l_u_g_i_n Configures plugins in server │ │ │ │ │ _n_a_m_e_d_._c_o_n_f. │ │ │ │ │ Specifies the UDP/TCP port │ │ │ │ │ _p_o_r_t number the server uses to query, server │ │ │ │ │ receive and send DNS │ │ │ │ │ protocol traffic. │ │ │ │ │ Specifies that server │ │ │ │ │ @@ -3191,15 +3191,15 @@ │ │ │ │ │ _r_e_s_o_l_v_e_r_-_u_s_e_-_d_n_s_6_4 DNS64 mappings when sending server │ │ │ │ │ queries. │ │ │ │ │ Adds an EDNS Padding option │ │ │ │ │ to encrypted messages, to │ │ │ │ │ _r_e_s_p_o_n_s_e_-_p_a_d_d_i_n_g reduce the chance of query │ │ │ │ │ guessing the contents based │ │ │ │ │ on size. │ │ │ │ │ - Specifies response policy security, query, zone, │ │ │ │ │ + Specifies response policy zone, query, security, │ │ │ │ │ _r_e_s_p_o_n_s_e_-_p_o_l_i_c_y zones for the view or among server │ │ │ │ │ global options. │ │ │ │ │ Limits the number of non- │ │ │ │ │ _r_e_s_p_o_n_s_e_s_-_p_e_r_-_s_e_c_o_n_d empty responses for a valid query │ │ │ │ │ domain name and record type. │ │ │ │ │ Increases the amount of time │ │ │ │ │ a key remains published │ │ │ │ │ @@ -3238,15 +3238,15 @@ │ │ │ │ │ serial number in the SOA │ │ │ │ │ record. │ │ │ │ │ Defines characteristics to │ │ │ │ │ _s_e_r_v_e_r be associated with a remote server │ │ │ │ │ name server. │ │ │ │ │ Specifies a list of IP │ │ │ │ │ addresses to which queries │ │ │ │ │ -_s_e_r_v_e_r_-_a_d_d_r_e_s_s_e_s should be sent in recursive query, zone │ │ │ │ │ +_s_e_r_v_e_r_-_a_d_d_r_e_s_s_e_s should be sent in recursive zone, query │ │ │ │ │ resolution for a static-stub │ │ │ │ │ zone. │ │ │ │ │ Specifies the ID of the │ │ │ │ │ _s_e_r_v_e_r_-_i_d server to return in response server │ │ │ │ │ to a ID.SERVER query. │ │ │ │ │ Specifies a list of domain │ │ │ │ │ _s_e_r_v_e_r_-_n_a_m_e_s names of name servers that zone │ │ │ │ │ @@ -3292,15 +3292,15 @@ │ │ │ │ │ _s_i_g_n_a_t_u_r_e_s_-_v_a_l_i_d_i_t_y_-_d_n_s_k_e_y Indicates the validity dnssec │ │ │ │ │ period of DNSKEY records. │ │ │ │ │ Sets the number of "slipped" │ │ │ │ │ _s_l_i_p responses to minimize the query │ │ │ │ │ use of forged source │ │ │ │ │ addresses for an attack. │ │ │ │ │ Controls the ordering of RRs │ │ │ │ │ -_s_o_r_t_l_i_s_t returned to the client, query, deprecated │ │ │ │ │ +_s_o_r_t_l_i_s_t returned to the client, deprecated, query │ │ │ │ │ based on the client's IP │ │ │ │ │ address. │ │ │ │ │ Defines the amount of time │ │ │ │ │ (in milliseconds) that _n_a_m_e_d │ │ │ │ │ _s_t_a_l_e_-_a_n_s_w_e_r_-_c_l_i_e_n_t_-_t_i_m_e_o_u_t waits before attempting to query, server │ │ │ │ │ answer a query with a stale │ │ │ │ │ RRset from cache. │ │ │ │ │ @@ -3317,15 +3317,15 @@ │ │ │ │ │ return of "stale" cached │ │ │ │ │ _s_t_a_l_e_-_r_e_f_r_e_s_h_-_t_i_m_e answers before the next query, server │ │ │ │ │ attempt to contact, if the │ │ │ │ │ name servers for a given │ │ │ │ │ zone are not responding. │ │ │ │ │ Specifies the rate at which │ │ │ │ │ NOTIFY requests are sent │ │ │ │ │ -_s_t_a_r_t_u_p_-_n_o_t_i_f_y_-_r_a_t_e when the name server is transfer, zone │ │ │ │ │ +_s_t_a_r_t_u_p_-_n_o_t_i_f_y_-_r_a_t_e when the name server is zone, transfer │ │ │ │ │ first starting, or when new │ │ │ │ │ zones have been added. │ │ │ │ │ Specifies the communication │ │ │ │ │ channels to be used by │ │ │ │ │ _s_t_a_t_i_s_t_i_c_s_-_c_h_a_n_n_e_l_s system administrators to logging │ │ │ │ │ access statistics │ │ │ │ │ information on the name │ │ │ │ │ @@ -3514,32 +3514,32 @@ │ │ │ │ │ differently depending on who │ │ │ │ │ is asking. │ │ │ │ │ Specifies the length of time │ │ │ │ │ _w_i_n_d_o_w during which responses are query │ │ │ │ │ tracked. │ │ │ │ │ Specifies whether to set the │ │ │ │ │ time to live (TTL) of the │ │ │ │ │ -_z_e_r_o_-_n_o_-_s_o_a_-_t_t_l SOA record to zero, when server, query, zone │ │ │ │ │ +_z_e_r_o_-_n_o_-_s_o_a_-_t_t_l SOA record to zero, when zone, query, server │ │ │ │ │ returning authoritative │ │ │ │ │ negative responses to SOA │ │ │ │ │ queries. │ │ │ │ │ Sets the time to live (TTL) │ │ │ │ │ -_z_e_r_o_-_n_o_-_s_o_a_-_t_t_l_-_c_a_c_h_e to zero when caching a server, query, zone │ │ │ │ │ +_z_e_r_o_-_n_o_-_s_o_a_-_t_t_l_-_c_a_c_h_e to zero when caching a zone, query, server │ │ │ │ │ negative response to an SOA │ │ │ │ │ query. │ │ │ │ │ _z_o_n_e Specifies the zone in a BIND zone │ │ │ │ │ 9 configuration. │ │ │ │ │ Sets the propagation delay │ │ │ │ │ from the time a zone is │ │ │ │ │ _z_o_n_e_-_p_r_o_p_a_g_a_t_i_o_n_-_d_e_l_a_y first updated to when the dnssec, zone │ │ │ │ │ new version of the zone is │ │ │ │ │ served by all secondary │ │ │ │ │ servers. │ │ │ │ │ Controls the level of │ │ │ │ │ -_z_o_n_e_-_s_t_a_t_i_s_t_i_c_s statistics gathered for all logging, zone │ │ │ │ │ +_z_o_n_e_-_s_t_a_t_i_s_t_i_c_s statistics gathered for all zone, logging │ │ │ │ │ zones. │ │ │ │ │ ********** 88..44.. SSttaatteemmeennttss bbyy TTaagg_? ********** │ │ │ │ │ These tables group the various statements permissible in named.conf by their │ │ │ │ │ corresponding tag. │ │ │ │ │ ******** 88..44..11.. DDNNSSSSEECC TTaagg SSttaatteemmeennttss_? ******** │ │ │ │ │ SSttaatteemmeenntt DDeessccrriippttiioonn │ │ │ │ │ _b_i_n_d_k_e_y_s_-_f_i_l_e Specifies the pathname of a file to override the