1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
|
.TH "NSD" "8" "Sep 25, 2018" "NLnet Labs" "NSD 4.1.25"
.\" Copyright (c) 2001\-2008, NLnet Labs. All rights reserved.
.\" See LICENSE for the license.
.SH "NAME"
.B nsd
\- Name Server Daemon (NSD) version 4.1.25.
.SH "SYNOPSIS"
.B nsd
.RB [ \-4 ]
.RB [ \-6 ]
.RB [ \-a
.IR ip\-address[@port] ]
.RB [ \-c
.IR configfile ]
.RB [ \-d ]
.RB [ \-f
.IR database ]
.RB [ \-h ]
.RB [ \-i
.IR identity ]
.RB [ \-I
.IR nsid ]
.RB [ \-l
.IR logfile ]
.RB [ \-N
.IR server\-count ]
.RB [ \-n
.IR noncurrent\-tcp\-count ]
.RB [ \-P
.IR pidfile ]
.RB [ \-p
.IR port ]
.RB [ \-s
.IR seconds ]
.RB [ \-t
.IR chrootdir ]
.RB [ \-u
.IR username ]
.RB [ \-V
.IR level ]
.RB [ \-v ]
.SH "DESCRIPTION"
.B NSD
is a complete implementation of an authoritative DNS nameserver.
Upon startup,
.B NSD
will read the database specified with
.B \-f
.I database
argument and put itself into background and answers queries on port
53 or a different port specified with
.B \-p
.I port
option. The
.I database
is created if it does not exist. By default,
.B NSD
will bind to all local interfaces available. Use the
.B \-a
.I ip\-address[@port]
option to specify a single particular interface address to be
bound. If this option is given more than once,
.B NSD
will bind its UDP and TCP sockets to all the specified ip\-addresses
separately. If IPv6 is enabled when
.B NSD
is compiled an IPv6 address can also be specified.
.P
.SH "OPTIONS"
All the options can be specified in the configfile (
.B \-c
argument), except for the
.B \-v
and
.B \-h
options. If options are specified on the commandline, the options
on the commandline take precedence over the options in the
configfile.
.P
Normally
.B NSD
should be started with the `nsd\-control(8) start` command invoked from a
.I /etc/rc.d/nsd.sh
script or similar at the operating system startup.
.TP
.B \-4
Only listen to IPv4 connections.
.TP
.B \-6
Only listen to IPv6 connections.
.TP
.B \-a\fI ip\-address[@port]
Listen to the specified
.IR ip\-address .
The
.I ip\-address
must be specified in numeric format (using the standard IPv4 or IPv6
notation). Optionally, a port number can be given.
This flag can be specified multiple times to listen to
multiple IP addresses. If this flag is not specified,
.B NSD
listens to the wildcard interface.
.TP
.B \-c\fI configfile
Read specified
.I configfile
instead of the default
.IR @nsdconfigfile@ .
For format description see nsd.conf(5).
.TP
.B \-d
Do not fork, stay in the foreground.
.TP
.B \-f\fI database
Use the specified
.I database
instead of the default of
.IR '@dbfile@' .
If a
.B zonesdir:
is specified in the config file this path can be relative to that
directory.
.TP
.B \-h
Print help information and exit.
.TP
.B \-i\fI identity
Return the specified
.I identity
when asked for
.I CH TXT ID.SERVER
(This option is used to determine which server is answering the queries
when they are anycast). The default is the name returned by gethostname(3).
.TP
.B \-I\fI nsid
Add the specified
.I nsid
to the EDNS section of the answer when queried with an NSID EDNS
enabled packet. As a sequence of hex characters or with ascii_ prefix
and then an ascii string.
.TP
.B \-l\fI logfile
Log messages to the specified
.IR logfile .
The default is to log to stderr and syslog. If a
.B zonesdir:
is specified in the config file this path can be relative to that
directory.
.TP
.B \-N\fI count
Start
.I count
.B NSD
servers. The default is 1. Starting more than a single server is
only useful on machines with multiple CPUs and/or network adapters.
.TP
.B \-n\fI number
The maximum
.I number
of concurrent TCP connection that can be handled by each server. The
default is 100.
.TP
.B \-P\fI pidfile
Use the specified
.I pidfile
instead of the platform specific default, which is mostly
.IR @pidfile@ .
If a
.B zonesdir:
is specified in the config file, this path can be relative to that
directory.
.TP
.B \-p\fI port
Answer the queries on the specified
.IR port .
Normally this is port 53.
.TP
.B \-s\fI seconds
Produce statistics dump every
.I seconds
seconds. This is equal to sending
.I SIGUSR1
to the daemon periodically.
.TP
.B \-t\fI chroot
Specifies a directory to
.I chroot
to upon startup. This option requires you to ensure that appropriate
syslogd(8) socket (e.g.
.I chrootdir
/dev/log) is available, otherwise
.B NSD
won't produce any log output.
.TP
.B \-u\fI username
Drop user and group privileges to those of
.I username
after binding the socket.
The
.I username
must be one of: username, id, or id.gid. For example: nsd, 80, or
80.80.
.TP
.B \-V\fI level
This value specifies the verbosity level for (non\-debug) logging.
Default is 0.
.TP
.B \-v
Print the version number of
.B NSD
to standard error and exit.
.LP
.B NSD
reacts to the following signals:
.TP
SIGTERM
Stop answering queries, shutdown, and exit normally.
.TP
SIGHUP
Reload. Scans zone files and if changed (mtime) reads
them in. Also reopens the logfile (assists logrotation).
.TP
SIGUSR1
Dump BIND8\-style statistics into the log. Ignored otherwise.
.SH "FILES"
.TP
"@dbfile@"
default
.B NSD
database
.TP
@pidfile@
the process id of the name server.
.TP
@nsdconfigfile@
default
.B NSD
configuration file
.SH "DIAGNOSTICS"
.B NSD
will log all the problems via the standard syslog(8)
.I daemon
facility, unless the
.B \-d
option is specified.
.SH "SEE ALSO"
\fInsd.conf\fR(5), \fInsd\-checkconf\fR(8), \fInsd\-control\fR(8)
.SH "AUTHORS"
.B NSD
was written by NLnet Labs and RIPE NCC joint team. Please see
CREDITS file in the distribution for further details.
|