The keymgr utility serves for manual key management in Knot DNS server.
Functions for DNSSEC keys and KASP (Key And Signature Policy) management are provided.
The DNSSEC and KASP configuration is stored in a so called KASP database. The database is backed by LMDB.
![]()
This utility sends Dynamic DNS update messages to a DNS server. Update content is read from a file (if the parameter filename is given) or from the standard input.
The format of updates is textual and is made up of commands. Every command is placed on the separate line of the input. Lines starting with a semicolon are comments and are not processed.
![]()
This program controls a running knotd process using a socket.
If an action is specified, it is performed and knotc exits, otherwise the program is executed in the interactive mode.
![]()
Knot DNS is a high-performance open-source DNS server. It implements only the authoritative domain name service. Knot DNS can reliably serve TLD domains as well as any other zones.
Knot DNS benefits from its multi-threaded and mostly lock-free implementation which allows it to scale well on SMP systems and operate non-stop even when adding or removing zones.
The server itself is accompanied by several utilities for general DNS operations or for maintaining the server.
For more info and downloads see www.knot-dns.cz.
![]()
This document describes a method for automatic DNS zone provisioning among DNS primary and secondary nameservers by storing and transferring the catalog of zones to be provisioned as one or more regular DNS zones.
Dnspython is a DNS toolkit for Python. It can be used for queries, zone transfers, dynamic updates, nameserver testing, and many other things.
Dnspython provides both high and low level access to the DNS. The high level classes perform queries for data of a given name, type, and class, and return an answer set. The low level classes allow direct manipulation of DNS zones, messages, names, and records. Almost all RR types are supported.
dnspython originated at Nominum where it was developed for testing DNS nameservers.
If you’re into DNSSEC, you’ll probably have to troubleshoot or at least to verify it. While there are some good online tools such as DNSViz, there is also a command-line tool to test DNSSEC signatures onsite: delv.
This is an introductory howto to get DNSSEC running with BIND >=9.9 on Debian >=8 (jessie). We assume an "clean", freshly installed bind9 here.
This document provides introductory information on how DNSSEC works, how to configure BIND 9 to support some commonDNSSEC features, as well as some basic troubleshooting tips. The chapters are organized as such:
Chapter 1 covers the intended audience for this document, assumed background knowledge, and a basic introduction to
the topicof DNSSEC.
Chapter 2 covers various requirements that are needed before implementing DNSSEC, such as software
versions, hardwarecapacity, network requirements, and security changes.
Chapter 3 walks through setting up a validating resolver, more information on the validation process, as well as
examples ofusing tools to verify that the resolver is validating answers.
Chapter 4 walks through setting up a basic signed authoritative zone, explains the relationship with the parent zone,
and on-goingmaintenance tasks.
Chapter 5 provides some tips on how to analyze and diagnose DNSSEC-related problems.
Chapter 6 covers several topics, from key generation, key storage, key management, NSEC and NSEC3, to
disadvantages ofDNSSEC.
Chapter 7 provides several working examples of common solutions, with step-by-step details
DNS servers optionally log queries on demand by formatting a message and storing that in a file, sending it through syslog, etc. This is an I/O-intensive operation which can dramatically slow down busy servers, and the biggest issue is we get the query but not the associated response.
Knot DNS is a high-performance authoritative-only DNS server which supports all key features of the modern domain name system.
This Open Source Guide is about DNS and (mostly) BIND 9.x on Linux (Fedora Core), BSD's (FreeBSD, OpenBSD and NetBSD) and Windows (Windows 7 and 10). It is meant for newbies, Rocket Scientist wannabees and anyone in between.
This Guide was born out of our first attempts a number of years ago at trying to install a much needed DNS service on an early Redhat Linux system. We completed the DNS 'rite of passage' and found it a pretty unedifying and pointless experience.
Health Warning: This is still a work-in-progress. If you find errors don't grumble - tell us. Look at our to do list and if you want to contribute something please do so.
<gratuitous publicity> The newly published book Pro DNS and BIND was largely based on this material but significantly extends it - including DNS security (including DNSSEC.bis), IPv6, DNS APIs and complete reference sections on named.conf and RR types. We are outrageously biased but think it is an essential addition to the DNS admin's library. </gratuitious publicity>