--- bind-9.3.6-P1-options.txt Mon May 4 17:45:57 2009 +++ bind-9.6.1b1-options.txt Mon May 4 17:46:04 2009 @@ -8,9 +8,14 @@ inet ( | | * ) [ port ( | * ) ] allow { ; ... } [ keys { ; ... } ]; - unix ; // not implemented + unix perm owner group + [ keys { ; ... } ]; }; +dlz { + database ; +}; + key { algorithm ; secret ; @@ -43,12 +48,19 @@ ] | [ port ] ) [ key ]; ... }; options { + acache-cleaning-interval ; + acache-enable ; additional-from-auth ; additional-from-cache ; allow-notify { ; ... }; allow-query { ; ... }; + allow-query-cache { ; ... }; + allow-query-cache-on { ; ... }; + allow-query-on { ; ... }; allow-recursion { ; ... }; + allow-recursion-on { ; ... }; allow-transfer { ; ... }; + allow-update { ; ... }; allow-update-forwarding { ; ... }; allow-v6-synthesis { ; ... }; // obsolete also-notify [ port ] { ( | @@ -61,8 +73,15 @@ avoid-v6-udp-ports { ; ... }; blackhole { ; ... }; cache-file ; + check-integrity ; + check-mx ( fail | warn | ignore ); + check-mx-cname ( fail | warn | ignore ); check-names ( master | slave | response ) ( fail | warn | ignore ); + check-sibling ; + check-srv-cname ( fail | warn | ignore ); + check-wildcard ; cleaning-interval ; + clients-per-query ; coresize ; datasize ; deallocate-on-exit ; // obsolete @@ -69,14 +88,20 @@ dialup ; directory ; disable-algorithms { ; ... }; + disable-empty-zone ; + dnssec-accept-expired ; dnssec-enable ; dnssec-lookaside trust-anchor ; dnssec-must-be-secure ; + dnssec-validation ; dual-stack-servers [ port ] { ( [ port ] | [ port ] | [ port ] ); ... }; dump-file ; edns-udp-size ; + empty-contact ; + empty-server ; + empty-zones-enable ; fake-iquery ; // obsolete fetch-glue ; // obsolete files ; @@ -90,15 +115,18 @@ host-statistics-max ; // not implemented hostname ( | none ); interface-interval ; - ixfr-from-differences ; + ixfr-from-differences ; key-directory ; lame-ttl ; listen-on [ port ] { ; ... }; listen-on-v6 [ port ] { ; ... }; maintain-ixfr-base ; // obsolete + masterfile-format ( text | raw ); match-mapped-addresses ; + max-acache-size ; max-cache-size ; max-cache-ttl ; + max-clients-per-query ; max-ixfr-log-size ; // obsolete max-journal-size ; max-ncache-ttl ; @@ -108,6 +136,8 @@ max-transfer-idle-out ; max-transfer-time-in ; max-transfer-time-out ; + max-udp-size ; + memstatistics ; memstatistics-file ; min-refresh-time ; min-retry-time ; @@ -117,8 +147,11 @@ multiple-cnames ; // obsolete named-xfer ; // obsolete notify ; + notify-delay ; notify-source ( | * ) [ port ( | * ) ]; notify-source-v6 ( | * ) [ port ( | * ) ]; + notify-to-soa ; + nsec3-test-zone ; // test only pid-file ( | none ); port ; preferred-glue ; @@ -126,11 +159,14 @@ query-source ; query-source-v6 ; querylog ; + queryport-pool-ports ; // obsolete + queryport-pool-updateinterval ; // obsolete random-device ; recursing-file ; recursion ; recursive-clients ; request-ixfr ; + request-nsid ; reserved-sockets ; rfc2308-type1 ; // not yet implemented root-delegation-only [ exclude { ; ... } ]; @@ -139,7 +175,10 @@ serial-queries ; // obsolete serial-query-rate ; server-id ( | none |; - sig-validity-interval ; + sig-signing-nodes ; + sig-signing-signatures ; + sig-signing-type ; + sig-validity-interval [ ]; sortlist { ; ... }; stacksize ; statistics-file ; @@ -158,20 +197,31 @@ transfers-out ; transfers-per-ns ; treat-cr-as-space ; // obsolete + try-tcp-refresh ; + update-check-ksk ; use-alt-transfer-source ; use-id-pool ; // obsolete use-ixfr ; + use-queryport-pool ; // obsolete use-v4-udp-ports { ; ... }; use-v6-udp-ports { ; ... }; version ( | none ); + zero-no-soa-ttl ; + zero-no-soa-ttl-cache ; zone-statistics ; }; -server { +server { bogus ; edns ; + edns-udp-size ; keys ; + max-udp-size ; + notify-source ( | * ) [ port ( | * ) ]; + notify-source-v6 ( | * ) [ port ( | * ) ]; provide-ixfr ; + query-source ; + query-source-v6 ; request-ixfr ; support-ixfr ; // obsolete transfer-format ( many-answers | one-answer ); @@ -180,15 +230,27 @@ transfers ; }; +statistics-channels { + inet ( | | * ) [ port ( | * + ) ] [ allow { ; ... } ]; +}; + trusted-keys { ; ... }; view { + acache-cleaning-interval ; + acache-enable ; additional-from-auth ; additional-from-cache ; allow-notify { ; ... }; allow-query { ; ... }; + allow-query-cache { ; ... }; + allow-query-cache-on { ; ... }; + allow-query-on { ; ... }; allow-recursion { ; ... }; + allow-recursion-on { ; ... }; allow-transfer { ; ... }; + allow-update { ; ... }; allow-update-forwarding { ; ... }; allow-v6-synthesis { ; ... }; // obsolete also-notify [ port ] { ( | @@ -198,22 +260,39 @@ * ) ]; auth-nxdomain ; // default changed cache-file ; + check-integrity ; + check-mx ( fail | warn | ignore ); + check-mx-cname ( fail | warn | ignore ); check-names ( master | slave | response ) ( fail | warn | ignore ); + check-sibling ; + check-srv-cname ( fail | warn | ignore ); + check-wildcard ; cleaning-interval ; + clients-per-query ; + database ; dialup ; disable-algorithms { ; ... }; + disable-empty-zone ; + dlz { + database ; + }; + dnssec-accept-expired ; dnssec-enable ; dnssec-lookaside trust-anchor ; dnssec-must-be-secure ; + dnssec-validation ; dual-stack-servers [ port ] { ( [ port ] | [ port ] | [ port ] ); ... }; edns-udp-size ; + empty-contact ; + empty-server ; + empty-zones-enable ; fetch-glue ; // obsolete forward ( first | only ); forwarders [ port ] { ( | ) [ port ]; ... }; - ixfr-from-differences ; + ixfr-from-differences ; key { algorithm ; secret ; @@ -221,11 +300,14 @@ key-directory ; lame-ttl ; maintain-ixfr-base ; // obsolete + masterfile-format ( text | raw ); match-clients { ; ... }; match-destinations { ; ... }; match-recursive-only ; + max-acache-size ; max-cache-size ; max-cache-ttl ; + max-clients-per-query ; max-ixfr-log-size ; // obsolete max-journal-size ; max-ncache-ttl ; @@ -235,6 +317,7 @@ max-transfer-idle-out ; max-transfer-time-in ; max-transfer-time-out ; + max-udp-size ; min-refresh-time ; min-retry-time ; min-roots ; // not implemented @@ -241,23 +324,37 @@ minimal-responses ; multi-master ; notify ; + notify-delay ; notify-source ( | * ) [ port ( | * ) ]; notify-source-v6 ( | * ) [ port ( | * ) ]; + notify-to-soa ; + nsec3-test-zone ; // test only preferred-glue ; provide-ixfr ; query-source ; query-source-v6 ; + queryport-pool-ports ; // obsolete + queryport-pool-updateinterval ; // obsolete recursion ; request-ixfr ; + request-nsid ; rfc2308-type1 ; // not yet implemented root-delegation-only [ exclude { ; ... } ]; rrset-order { [ class ] [ type ] [ name ] ; ... }; - server { + server { bogus ; edns ; + edns-udp-size ; keys ; + max-udp-size ; + notify-source ( | * ) [ port ( | * + ) ]; + notify-source-v6 ( | * ) [ port ( + | * ) ]; provide-ixfr ; + query-source ; + query-source-v6 ; request-ixfr ; support-ixfr ; // obsolete transfer-format ( many-answers | one-answer ); @@ -267,7 +364,10 @@ | * ) ]; transfers ; }; - sig-validity-interval ; + sig-signing-nodes ; + sig-signing-signatures ; + sig-signing-type ; + sig-validity-interval [ ]; sortlist { ; ... }; suppress-initial-notify ; // not yet implemented topology { ; ... }; // not implemented @@ -276,10 +376,16 @@ transfer-source-v6 ( | * ) [ port ( | * ) ]; trusted-keys { ; ... }; + try-tcp-refresh ; + update-check-ksk ; use-alt-transfer-source ; + use-queryport-pool ; // obsolete + zero-no-soa-ttl ; + zero-no-soa-ttl-cache ; zone { allow-notify { ; ... }; allow-query { ; ... }; + allow-query-on { ; ... }; allow-transfer { ; ... }; allow-update { ; ... }; allow-update-forwarding { ; ... }; @@ -289,7 +395,13 @@ | * ) ]; alt-transfer-source-v6 ( | * ) [ port ( | * ) ]; + check-integrity ; + check-mx ( fail | warn | ignore ); + check-mx-cname ( fail | warn | ignore ); check-names ( fail | warn | ignore ); + check-sibling ; + check-srv-cname ( fail | warn | ignore ); + check-wildcard ; database ; delegation-only ; dialup ; @@ -300,8 +412,10 @@ ixfr-base ; // obsolete ixfr-from-differences ; ixfr-tmp-file ; // obsolete + journal ; key-directory ; maintain-ixfr-base ; // obsolete + masterfile-format ( text | raw ); masters [ port ] { ( | [ port ] | [ port ] ) [ key ]; ... }; @@ -317,23 +431,33 @@ min-retry-time ; multi-master ; notify ; + notify-delay ; notify-source ( | * ) [ port ( | * ) ]; notify-source-v6 ( | * ) [ port ( | * ) ]; + notify-to-soa ; + nsec3-test-zone ; // test only pubkey ; // obsolete - sig-validity-interval ; + sig-signing-nodes ; + sig-signing-signatures ; + sig-signing-type ; + sig-validity-interval [ ]; transfer-source ( | * ) [ port ( | * ) ]; transfer-source-v6 ( | * ) [ port ( | * ) ]; + try-tcp-refresh ; type ( master | slave | stub | hint | forward | delegation-only ); + update-check-ksk ; update-policy { ( grant | deny ) ( name | - subdomain | wildcard | self ) ; - ... }; + subdomain | wildcard | self | selfsub | selfwild | + krb5-self | ms-self | krb5-subdomain | ms-subdomain | + tcp-self | 6to4-self ) ; ... }; use-alt-transfer-source ; + zero-no-soa-ttl ; zone-statistics ; }; zone-statistics ; @@ -342,6 +466,7 @@ zone { allow-notify { ; ... }; allow-query { ; ... }; + allow-query-on { ; ... }; allow-transfer { ; ... }; allow-update { ; ... }; allow-update-forwarding { ; ... }; @@ -350,7 +475,13 @@ alt-transfer-source ( | * ) [ port ( | * ) ]; alt-transfer-source-v6 ( | * ) [ port ( | * ) ]; + check-integrity ; + check-mx ( fail | warn | ignore ); + check-mx-cname ( fail | warn | ignore ); check-names ( fail | warn | ignore ); + check-sibling ; + check-srv-cname ( fail | warn | ignore ); + check-wildcard ; database ; delegation-only ; dialup ; @@ -361,8 +492,10 @@ ixfr-base ; // obsolete ixfr-from-differences ; ixfr-tmp-file ; // obsolete + journal ; key-directory ; maintain-ixfr-base ; // obsolete + masterfile-format ( text | raw ); masters [ port ] { ( | [ port ] | [ port ] ) [ key ]; ... }; @@ -378,16 +511,27 @@ min-retry-time ; multi-master ; notify ; + notify-delay ; notify-source ( | * ) [ port ( | * ) ]; notify-source-v6 ( | * ) [ port ( | * ) ]; + notify-to-soa ; + nsec3-test-zone ; // test only pubkey ; // obsolete - sig-validity-interval ; + sig-signing-nodes ; + sig-signing-signatures ; + sig-signing-type ; + sig-validity-interval [ ]; transfer-source ( | * ) [ port ( | * ) ]; transfer-source-v6 ( | * ) [ port ( | * ) ]; + try-tcp-refresh ; type ( master | slave | stub | hint | forward | delegation-only ); + update-check-ksk ; update-policy { ( grant | deny ) ( name | subdomain | - wildcard | self ) ; ... }; + wildcard | self | selfsub | selfwild | krb5-self | ms-self | + krb5-subdomain | ms-subdomain | tcp-self | 6to4-self ) + ; ... }; use-alt-transfer-source ; + zero-no-soa-ttl ; zone-statistics ; };