2c0af7
//
2c0af7
// named.conf
2c0af7
//
2c0af7
// Provided by Red Hat bind package to configure the ISC BIND named(8) DNS
2c0af7
// server as a caching only nameserver (as a localhost DNS resolver only).
2c0af7
//
2c0af7
// See /usr/share/doc/bind*/sample/ for example named configuration files.
2c0af7
//
2c0af7
// See the BIND Administrator's Reference Manual (ARM) for details about the
2c0af7
// configuration located in /usr/share/doc/bind-{version}/Bv9ARM.html
2c0af7
2c0af7
options {
2c0af7
	listen-on port 53 { 127.0.0.1; };
2c0af7
	listen-on-v6 port 53 { ::1; };
2c0af7
	directory 	"/var/named";
2c0af7
	dump-file 	"/var/named/data/cache_dump.db";
2c0af7
	statistics-file "/var/named/data/named_stats.txt";
2c0af7
	memstatistics-file "/var/named/data/named_mem_stats.txt";
2c0af7
	recursing-file  "/var/named/data/named.recursing";
2c0af7
	secroots-file   "/var/named/data/named.secroots";
2c0af7
	allow-query     { localhost; };
2c0af7
2c0af7
	/* 
2c0af7
	 - If you are building an AUTHORITATIVE DNS server, do NOT enable recursion.
2c0af7
	 - If you are building a RECURSIVE (caching) DNS server, you need to enable 
2c0af7
	   recursion. 
2c0af7
	 - If your recursive DNS server has a public IP address, you MUST enable access 
2c0af7
	   control to limit queries to your legitimate users. Failing to do so will
2c0af7
	   cause your server to become part of large scale DNS amplification 
2c0af7
	   attacks. Implementing BCP38 within your network would greatly
2c0af7
	   reduce such attack surface 
2c0af7
	*/
2c0af7
	recursion yes;
2c0af7
2c0af7
	dnssec-enable yes;
2c0af7
	dnssec-validation yes;
2c0af7
2c0af7
	/* Path to ISC DLV key */
2c0af7
	bindkeys-file "/etc/named.iscdlv.key";
2c0af7
2c0af7
	managed-keys-directory "/var/named/dynamic";
2c0af7
2c0af7
	pid-file "/run/named/named.pid";
2c0af7
	session-keyfile "/run/named/session.key";
2c0af7
};
2c0af7
2c0af7
logging {
2c0af7
        channel default_debug {
2c0af7
                file "data/named.run";
2c0af7
                severity dynamic;
2c0af7
        };
2c0af7
};
2c0af7
2c0af7
zone "." IN {
2c0af7
	type hint;
2c0af7
	file "named.ca";
2c0af7
};
2c0af7
2c0af7
include "/etc/named.rfc1912.zones";
2c0af7
include "/etc/named.root.key";
2c0af7