2e2c49
//
2e2c49
// named.conf
2e2c49
//
2e2c49
// Provided by Red Hat bind package to configure the ISC BIND named(8) DNS
2e2c49
// server as a caching only nameserver (as a localhost DNS resolver only).
2e2c49
//
2e2c49
// See /usr/share/doc/bind*/sample/ for example named configuration files.
2e2c49
//
2e2c49
2e2c49
options {
2e2c49
	listen-on port 53 { 127.0.0.1; };
2e2c49
	listen-on-v6 port 53 { ::1; };
2e2c49
	directory 	"/var/named";
2e2c49
	dump-file 	"/var/named/data/cache_dump.db";
2e2c49
	statistics-file "/var/named/data/named_stats.txt";
2e2c49
	memstatistics-file "/var/named/data/named_mem_stats.txt";
2e2c49
	secroots-file	"/var/named/data/named.secroots";
2e2c49
	recursing-file	"/var/named/data/named.recursing";
2e2c49
	allow-query     { localhost; };
2e2c49
2e2c49
	/* 
2e2c49
	 - If you are building an AUTHORITATIVE DNS server, do NOT enable recursion.
2e2c49
	 - If you are building a RECURSIVE (caching) DNS server, you need to enable 
2e2c49
	   recursion. 
2e2c49
	 - If your recursive DNS server has a public IP address, you MUST enable access 
2e2c49
	   control to limit queries to your legitimate users. Failing to do so will
2e2c49
	   cause your server to become part of large scale DNS amplification 
2e2c49
	   attacks. Implementing BCP38 within your network would greatly
2e2c49
	   reduce such attack surface 
2e2c49
	*/
2e2c49
	recursion yes;
2e2c49
2e2c49
	dnssec-enable yes;
2e2c49
	dnssec-validation yes;
2e2c49
2e2c49
	managed-keys-directory "/var/named/dynamic";
2e2c49
2e2c49
	pid-file "/run/named/named.pid";
2e2c49
	session-keyfile "/run/named/session.key";
2e2c49
2e2c49
	/* https://fedoraproject.org/wiki/Changes/CryptoPolicy */
2e2c49
	include "/etc/crypto-policies/back-ends/bind.config";
2e2c49
};
2e2c49
2e2c49
logging {
2e2c49
        channel default_debug {
2e2c49
                file "data/named.run";
2e2c49
                severity dynamic;
2e2c49
        };
2e2c49
};
2e2c49
2e2c49
zone "." IN {
2e2c49
	type hint;
2e2c49
	file "named.ca";
2e2c49
};
2e2c49
2e2c49
include "/etc/named.rfc1912.zones";
2e2c49
include "/etc/named.root.key";
2e2c49