Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ
  FreeBSD¿¡¼­ DNS ¼³Ä¡(bind9) ÀÛ¼ºÀÏ : 2006/04/13 00:20
 
  • ±Û¾´ÀÌ : ÁÁÀºÁøÈ£ ( http://coffeenix.net/ )
  • Á¶È¸¼ö : 8884
     
    Á¦  ¸ñ : FreeBSD¿¡¼­ DNS ¼³Ä¡(bind9)
    ÀÛ¼ºÀÚ : ÁÁÀºÁøÈ£(truefeel, http://coffeenix.net/ )
    ÀÛ¼ºÀÏ : 2005.10.27(¸ñ)
    Á¤¸®ÀÏ : 2006.4.12(¼ö)

    FreeBSD¿¡¼­ ±âº»ÀûÀ¸·Î ¼³Ä¡µÇ´Â bind8 ´ë½Å¿¡ ports¸¦ ÅëÇØ bind9·Î ¾÷±×·¹À̵å ÇÏ´Â ¹æ¹ýÀ» ¼³¸íÇÑ´Ù.
    zonefile ¼³Á¤°ú named.confÀÇ ±âº» ¼³Á¤¿¡ ´ëÇؼ­´Â ¼³¸íÇÏÁö ¾Ê´Â´Ù.
    DNS ±âÃʺÎÅÍ ¾Ë°í ½ÍÀº ºÐÀº
    - ±è½Â¿µ´ÔÀÇ Powered by DNS ( http://www.bsdnet.co.kr/doc/PoweredByDNS/ )
    - ±èÁ¤±Õ´ÔÀÇ How to config BIND 9 for Linux ( http://oops.org/?t=lecture&s=bind9 )
    ¸¦ ¸ÕÀú Àо±â ¹Ù¶õ´Ù.

    1. bind9 ¼³Ä¡

    # cd /usr/ports/dns/bind9

    Makefile¿¡¼­ CONFIGURE_ARGS= ¿¡ ¼³Á¤ÆÄÀÏ °æ·Î¸¦ /etc/namedb ·Î º¯°æÇÑ´Ù. ´Ù¸¥ µð·ºÅ丮¸¦ ÁöÁ¤Çصµ »ó°ü¾ø´Ù.

     
    CONFIGURE_ARGS= --localstatedir=/var --disable-linux-caps --with-openssl \

    ´ë½Å¿¡

    CONFIGURE_ARGS= --localstatedir=/etc/namedb --sysconfdir=/etc/namedb --disable-linux-caps --with-openssl \
     


    # make install clean

    2. /etc/rc.conf ¼³Á¤

    ±âº» ¼³Ä¡µÈ bind ½ÇÇàÀ» À§Çؼ­´Â ´ÙÀ½°ú ºñ½ÁÇÏ°Ô µÇ¾î ÀÖÀ» °ÍÀÌ´Ù. ( named_flags= ´Â Â÷À̳¯ ¼ö ÀÖÀ½)

     
    # for bind 8.x
    named_enable="YES"
    named_program="/usr/sbin/named"
    named_flags="-u bind -g bind"
     


    ´ÙÀ½°ú °°ÀÌ ¼öÁ¤ÇÑ´Ù.

     
    named_enable="YES"
    named_program="/usr/local/sbin/named"
    named_flags="-u bind"
    named_pidfile="/var/run/named/named.pid"
     


    3. named.conf ¿¡¼­ rndc °ü·Ã ºÎºÐ ¼³Á¤

    BIND 8¿¡¼­ ³×ÀÓ¼­¹ö¸¦ Á¦¾îÇÏ´Â ÅøÀÎ ndc´Â BIND 9¿¡¼­´Â rndc¸¦ »ç¿ëÇÑ´Ù. rndc¸¦ »ç¿ëÇϱâ À§Çؼ­´Â
    rndc key¸¦ named.conf¿Í rndc.conf ÆÄÀÏ¿¡ ¼³Á¤À» ÇØÁà¾ß named µ¥¸ó°ú rndc°£¿¡ Åë½ÅÀÌ °¡´ÉÇÏ´Ù.
    rndc.conf ¼³Á¤Àº rndc-confgen ÅøÀ» »ç¿ëÇÏ¸é °£´ÜÇÏ°Ô »ý¼ºÇÒ ¼ö ÀÖ´Ù. ±âº»ÀûÀ¸·Î /dev/randomÀ» ÅëÇؼ­
    ·¥´øÇÑ µ¥ÀÌÅ͸¦ ÀоîµéÀÌ°Ô µÇ´Âµ¥, FreeBSD¿¡¼­ À̸¦ ÅëÇØ Å°¸¦ »ý¼ºÇϸé hang°É¸° °Í ó·³ »ó´çÈ÷ ´Ê°Ô
    °á°ú¸¦ ¾òÀ» ¼öµµ ÀÖÀ¸´Ï ´ÙÀ½Ã³·³ /dev/urandomÀ» ÀÌ¿ëÇϰųª keyboardÀ¸·Î ºÎÅÍ randomÇÑ µ¥ÀÌÅ͸¦
    ¹ÞÀ» ¼ö ÀÖµµ·Ï ÇÑ´Ù. keyboardÀ» ÀÌ¿ëÇÒ °æ¿ì 'stop typing'ÀÌ ³ª¿Ã ¶§±îÁö ¾Æ¹«Å°³ª °è¼Ó ÀÔ·ÂÇØ¾ß ÇÑ´Ù.

     
    # /usr/local/sbin/rndc-confgen -r /dev/urandom ¶Ç´Â
    # /usr/local/sbin/rndc-confgen -r keyboard
    start typing:
    ...............................
    ...........................
    ...........................
    ...........................
    ...........................
    ...........................
    ...........................
    ...........................
    stop typing.
    ... »ý¼ºµÈ Å°°¡ È­¸é¿¡ Ãâ·ÂµÈ´Ù. ÀÌÇÏ »ý·« ...
     


    Ãâ·ÂµÈ °á°ú¸¦ ¾Æ·¡ ÆÄÀÏ·Î °¢°¢ ÀúÀåÀ» ÇÑ´Ù.

    [ /etc/named/rndc.conf ]
     
    # Start of rndc.conf
    key "rndc-key" {
            algorithm hmac-md5;
            secret "PUIGGLhuCYUmKclP4sayww==";
    };

    options {
            default-key "rndc-key";
            default-server 127.0.0.1;
            default-port 953;
    };
    # End of rndc.conf
     


    [ /etc/named/named.conf ] - ±âÁ¸ named.conf ³» Àû´çÇÑ ºÎºÐ¿¡ ´ÙÀ½À» ³Ö´Â´Ù.
     
    key "rndc-key" {
            algorithm hmac-md5;
            secret "PUIGGLhuCYUmKclP4sayww==";
    };
    #
    controls {
            inet 127.0.0.1 port 953
                    allow { 127.0.0.1; } keys { "rndc-key"; };
    };
     


    named-checkconf named.conf ·Î ¼³Á¤À» üũÇØ º» ÈÄ ±âÁ¸ named µ¥¸óÀ» kill ÇÏ°í
    /usr/local/sbin/named -u named ·Î ½ÇÇàÇÑ´Ù.
    /var/log/messages ¿¡ ³²Àº ·Î±×¸¦ º¸´Â °ÍÀº Çʼö!!!

    4. Âü°íÀÚ·á

    * BIND 9·Î ¾÷±×·¹À̵åÇϱâ: ¾Ë¾Æ¾ß ÇÒ 9°¡Áö Ư¼º (2001³â)
      http://network.hanbitbook.co.kr/view.php?bi_id=51

    * chrooted ³×ÀÓ¼­¹ö ¼³Ä¡, bind-9.2.0 for FreeBSD 4.5 (±Û H.S. Mok, 2002³â)
      http://coffeenix.net/board_view.php?bd_code=77

    * BINDÀÇ /etc/rndc.conf
      http://radiocom.kunsan.ac.kr/lecture/sol_install/bind_rndc_conf.html



    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ / URL : http://coffeenix.net/board_view.php?bd_code=1375