this changes most visble uses of master/slave terminology in tests.sh and most uses of 'type master' or 'type slave' in named.conf files. files in the checkconf test were not updated in order to confirm that the old syntax still works. rpzrecurse was also left mostly unchanged to avoid interference with DNSRPS.
178 lines
3.2 KiB
Plaintext
178 lines
3.2 KiB
Plaintext
/*
|
|
* Copyright (C) Internet Systems Consortium, Inc. ("ISC")
|
|
*
|
|
* This Source Code Form is subject to the terms of the Mozilla Public
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
*
|
|
* See the COPYRIGHT file distributed with this work for additional
|
|
* information regarding copyright ownership.
|
|
*/
|
|
|
|
// NS3
|
|
|
|
include "../../common/rndc.key";
|
|
|
|
controls {
|
|
inet 10.53.0.3 port @CONTROLPORT@ allow { any; } keys { rndc_key; };
|
|
};
|
|
|
|
options {
|
|
query-source address 10.53.0.3;
|
|
notify-source 10.53.0.3;
|
|
transfer-source 10.53.0.3;
|
|
port @PORT@;
|
|
pid-file "named.pid";
|
|
listen-on { 10.53.0.3; };
|
|
listen-on-v6 { none; };
|
|
recursion no;
|
|
notify yes;
|
|
try-tcp-refresh no;
|
|
notify-delay 0;
|
|
allow-new-zones yes;
|
|
};
|
|
|
|
zone "bits" {
|
|
type secondary;
|
|
primaries { 10.53.0.2; };
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
allow-update-forwarding { any; };
|
|
file "bits.bk";
|
|
sig-signing-signatures 1; // force incremental processing
|
|
};
|
|
|
|
server 10.53.0.4 { request-ixfr no; };
|
|
|
|
zone "noixfr" {
|
|
type secondary;
|
|
primaries { 10.53.0.4; };
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
allow-update-forwarding { any; };
|
|
file "noixfr.bk";
|
|
};
|
|
|
|
zone "master" {
|
|
type primary;
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
file "master.db";
|
|
notify explicit;
|
|
also-notify {
|
|
10.53.0.3;
|
|
};
|
|
};
|
|
|
|
zone "dynamic" {
|
|
type primary;
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
allow-update { any; };
|
|
file "dynamic.db";
|
|
};
|
|
|
|
zone "updated" {
|
|
type primary;
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
allow-update { none; };
|
|
file "updated.db";
|
|
};
|
|
|
|
zone "expired" {
|
|
type primary;
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
allow-update { any; };
|
|
file "expired.db";
|
|
};
|
|
|
|
zone "retransfer" {
|
|
type secondary;
|
|
primaries { 10.53.0.2; };
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
file "retransfer.bk";
|
|
};
|
|
|
|
zone "nsec3" {
|
|
type primary;
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
allow-update { any; };
|
|
file "nsec3.db";
|
|
};
|
|
|
|
zone "externalkey" {
|
|
type primary;
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
allow-update { any; };
|
|
file "externalkey.db";
|
|
};
|
|
|
|
zone "retransfer3" {
|
|
type secondary;
|
|
primaries { 10.53.0.2; };
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
file "retransfer3.bk";
|
|
};
|
|
|
|
zone "inactiveksk" {
|
|
type secondary;
|
|
primaries { 10.53.0.2; };
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
dnssec-dnskey-kskonly yes;
|
|
file "inactiveksk.bk";
|
|
};
|
|
|
|
zone "inactivezsk" {
|
|
type secondary;
|
|
primaries { 10.53.0.2; };
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
file "inactivezsk.bk";
|
|
};
|
|
|
|
zone "nokeys" {
|
|
type secondary;
|
|
primaries { 10.53.0.2; };
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
file "nokeys.bk";
|
|
};
|
|
|
|
zone "delayedkeys" {
|
|
type primary;
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
file "delayedkeys.db";
|
|
};
|
|
|
|
zone "removedkeys-primary" {
|
|
type primary;
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
allow-update { any; };
|
|
also-notify { 10.53.0.2; };
|
|
file "removedkeys-primary.db";
|
|
};
|
|
|
|
zone "removedkeys-secondary" {
|
|
type secondary;
|
|
primaries { 10.53.0.2; };
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
file "removedkeys-secondary.bk";
|
|
};
|
|
|
|
zone "unsupported" {
|
|
type primary;
|
|
file "unsupported.db";
|
|
inline-signing yes;
|
|
auto-dnssec maintain;
|
|
};
|