Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
* HanIRCÀÇ #coffeenix ¹æ
[ Àåºñ ¹× ȸ¼± ÈÄ¿ø ]
HOME > ³×Æ®¿öÅ©(network) > ³×ÀÓ¼­¹ö(name server, dns, bind) µµ¿ò¸»
°Ë»ö : »çÀÌÆ® WHOIS À¥¼­¹ö Á¾·ù


  FreeBSD¿¡¼­ DNS ¼³Ä¡(bind9) ÀÛ¼ºÀÏ : 2006/04/13 00:20
 
  • ±Û¾´ÀÌ : ÁÁÀºÁøÈ£ ( http://coffeenix.net/ )
  • Á¶È¸¼ö : 9260
          [ ÀÌÀüÈ­¸é / ¼öÁ¤ ]   ºñ¹Ð¹øÈ£ :     Àμâ¿ë È­¸é
      Á¦  ¸ñ : FreeBSD¿¡¼­ DNS ¼³Ä¡(bind9)
    ÀÛ¼ºÀÚ : ÁÁÀºÁøÈ£(truefeel, http://coffeenix.net/ )
    ÀÛ¼ºÀÏ : 2005.10.27(¸ñ)
    Á¤¸®ÀÏ : 2006.4.12(¼ö)

    FreeBSD¿¡¼­ ±âº»ÀûÀ¸·Î ¼³Ä¡µÇ´Â bind8 ´ë½Å¿¡ ports¸¦ ÅëÇØ bind9·Î ¾÷±×·¹À̵å ÇÏ´Â ¹æ¹ýÀ» ¼³¸íÇÑ´Ù.
    zonefile ¼³Á¤°ú named.confÀÇ ±âº» ¼³Á¤¿¡ ´ëÇØ¼­´Â ¼³¸íÇÏÁö ¾Ê´Â´Ù.
    DNS ±âÃʺÎÅÍ ¾Ë°í ½ÍÀº ºÐÀº
    - ±è½Â¿µ´ÔÀÇ Powered by DNS ( http://www.bsdnet.co.kr/doc/PoweredByDNS/ )
    - ±èÁ¤±Õ´ÔÀÇ How to config BIND 9 for Linux ( http://oops.org/?t=lecture&s=bind9 )
    ¸¦ ¸ÕÀú Àо±â ¹Ù¶õ´Ù.

    1. bind9 ¼³Ä¡

    # cd /usr/ports/dns/bind9

    Makefile¿¡¼­ CONFIGURE_ARGS= ¿¡ ¼³Á¤ÆÄÀÏ °æ·Î¸¦ /etc/namedb ·Î º¯°æÇÑ´Ù. ´Ù¸¥ µð·ºÅ丮¸¦ ÁöÁ¤Çصµ »ó°ü¾ø´Ù.

     
    CONFIGURE_ARGS= --localstatedir=/var --disable-linux-caps --with-openssl \

    ´ë½Å¿¡

    CONFIGURE_ARGS= --localstatedir=/etc/namedb --sysconfdir=/etc/namedb --disable-linux-caps --with-openssl \
     


    # make install clean

    2. /etc/rc.conf ¼³Á¤

    ±âº» ¼³Ä¡µÈ bind ½ÇÇàÀ» À§Çؼ­´Â ´ÙÀ½°ú ºñ½ÁÇÏ°Ô µÇ¾î ÀÖÀ» °ÍÀÌ´Ù. ( named_flags= ´Â Â÷À̳¯ ¼ö ÀÖÀ½)

     
    # for bind 8.x
    named_enable="YES"
    named_program="/usr/sbin/named"
    named_flags="-u bind -g bind"
     


    ´ÙÀ½°ú °°ÀÌ ¼öÁ¤ÇÑ´Ù.

     
    named_enable="YES"
    named_program="/usr/local/sbin/named"
    named_flags="-u bind"
    named_pidfile="/var/run/named/named.pid"
     


    3. named.conf ¿¡¼­ rndc °ü·Ã ºÎºÐ ¼³Á¤

    BIND 8¿¡¼­ ³×ÀÓ¼­¹ö¸¦ Á¦¾îÇÏ´Â ÅøÀÎ ndc´Â BIND 9¿¡¼­´Â rndc¸¦ »ç¿ëÇÑ´Ù. rndc¸¦ »ç¿ëÇϱâ À§Çؼ­´Â
    rndc key¸¦ named.conf¿Í rndc.conf ÆÄÀÏ¿¡ ¼³Á¤À» ÇØÁà¾ß named µ¥¸ó°ú rndc°£¿¡ Åë½ÅÀÌ °¡´ÉÇÏ´Ù.
    rndc.conf ¼³Á¤Àº rndc-confgen ÅøÀ» »ç¿ëÇÏ¸é °£´ÜÇÏ°Ô »ý¼ºÇÒ ¼ö ÀÖ´Ù. ±âº»ÀûÀ¸·Î /dev/randomÀ» ÅëÇØ¼­
    ·¥´øÇÑ µ¥ÀÌÅ͸¦ ÀоîµéÀÌ°Ô µÇ´Âµ¥, FreeBSD¿¡¼­ À̸¦ ÅëÇØ ۸¦ »ý¼ºÇϸé hang°É¸° °Í ó·³ »ó´çÈ÷ ´Ê°Ô
    °á°ú¸¦ ¾òÀ» ¼öµµ ÀÖÀ¸´Ï ´ÙÀ½Ã³·³ /dev/urandomÀ» ÀÌ¿ëÇϰųª keyboardÀ¸·Î ºÎÅÍ randomÇÑ µ¥ÀÌÅ͸¦
    ¹ÞÀ» ¼ö ÀÖµµ·Ï ÇÑ´Ù. keyboardÀ» ÀÌ¿ëÇÒ °æ¿ì 'stop typing'ÀÌ ³ª¿Ã ¶§±îÁö ¾Æ¹«Å°³ª °è¼Ó ÀÔ·ÂÇØ¾ß ÇÑ´Ù.

     
    # /usr/local/sbin/rndc-confgen -r /dev/urandom ¶Ç´Â
    # /usr/local/sbin/rndc-confgen -r keyboard
    start typing:
    ...............................
    ...........................
    ...........................
    ...........................
    ...........................
    ...........................
    ...........................
    ...........................
    stop typing.
    ... »ý¼ºµÈ ۰¡ È­¸é¿¡ Ãâ·ÂµÈ´Ù. ÀÌÇÏ »ý·« ...
     


    Ãâ·ÂµÈ °á°ú¸¦ ¾Æ·¡ ÆÄÀÏ·Î °¢°¢ ÀúÀåÀ» ÇÑ´Ù.

    [ /etc/named/rndc.conf ]
     
    # Start of rndc.conf
    key "rndc-key" {
            algorithm hmac-md5;
            secret "PUIGGLhuCYUmKclP4sayww==";
    };

    options {
            default-key "rndc-key";
            default-server 127.0.0.1;
            default-port 953;
    };
    # End of rndc.conf
     


    [ /etc/named/named.conf ] - ±âÁ¸ named.conf ³» Àû´çÇÑ ºÎºÐ¿¡ ´ÙÀ½À» ³Ö´Â´Ù.
     
    key "rndc-key" {
            algorithm hmac-md5;
            secret "PUIGGLhuCYUmKclP4sayww==";
    };
    #
    controls {
            inet 127.0.0.1 port 953
                    allow { 127.0.0.1; } keys { "rndc-key"; };
    };
     


    named-checkconf named.conf ·Î ¼³Á¤À» Ã¼Å©ÇØ º» ÈÄ ±âÁ¸ named µ¥¸óÀ» kill Çϰí
    /usr/local/sbin/named -u named ·Î ½ÇÇàÇÑ´Ù.
    /var/log/messages ¿¡ ³²Àº ·Î±×¸¦ º¸´Â °ÍÀº Çʼö!!!

    4. Âü°íÀÚ·á

    * BIND 9·Î ¾÷±×·¹À̵åÇϱâ: ¾Ë¾Æ¾ß ÇÒ 9°¡Áö Ư¼º (2001³â)
      http://network.hanbitbook.co.kr/view.php?bi_id=51

    * chrooted ³×ÀÓ¼­¹ö ¼³Ä¡, bind-9.2.0 for FreeBSD 4.5 (±Û H.S. Mok, 2002³â)
      http://coffeenix.net/board_view.php?bd_code=77

    * BINDÀÇ /etc/rndc.conf
      http://radiocom.kunsan.ac.kr/lecture/sol_install/bind_rndc_conf.html

      Ä¿ÇǴнº Ä«Æä ÃÖ±Ù ±Û
    [06/14] ÇØ¿Ü &#
    [06/14] ½Å¼¼&#4
    [06/13] ½ºÅ¸&#4
    [06/13] ÇÏ·ç &#
    [04/22] Re: ¿µÈ­¼Ó¿¡ ÄÄÇ»ÅÍ À̾߱â ~½º¿öµåÇǽ¬(2001)
    [10/20] Cross Compiler ±ò
    [07/14] SSL ¬¡¬°
    [04/26] Re: µµ½ºÈ­¸é ¿ø°ÝÁ¶Á¾ ¿©ºÎ
    [04/25] µµ½ºÈ­¸é ¿ø°ÝÁ¶Á¾ ¿©ºÎ
    [10/30] Cshell¿¡¼­ ³­¼ö ¼³Á¤
    [10/23] °øÇ×öµµÁÖ½Äȸ»ç SE ±¸ÀÎ Ëì
    [01/26] Re: wgetÀ¸·Î ´Ù¸¥¼­¹ö¿¡ÀÖ´Â µð·ºÅ丮¸¦ °¡Á®¿À·Á°íÇÕ´Ï´Ù.
    [01/25] wgetÀ¸·Î ´Ù¸¥¼­¹ö¿¡ÀÖ´Â µð·ºÅ丮¸¦ °¡Á®¿À·Á°íÇÕ´Ï´Ù.
    [01/11] ƯÁ¤ ¾Èµå·ÎÀ̵å WebView ¹öÀü¿¡¼­ SSL ¹®Á¦ (WebView ¹ö±×)
    [08/01] DNS forwarder (Àü´ÞÀÚ) ¼­¹ö¸¦ ÅëÇØ¼­ Äõ¸®ÇÏ¸é ¿ª¹æÇâÀ» ¹Þ¾Æ¿ÀÁú ¸øÇÕ´Ï´Ù.
      New!   ÃÖ±Ù¿¡ µî·ÏÇÑ ÆäÀÌÁö
      KiCad EDA Suite project (Free/Libre/Open-Source EDA Suite) (CAD)
      ¿ÀÇÂij½ºÄÉÀ̵å ijµå (OpenCASCADE CAD)
      QCad for Windows --- GNU GPL (Free Software)
      The Hello World Collection
      IPMI¸¦ Ȱ¿ëÇÑ ¸®´ª½º ¼­¹ö°ü¸®
      DNS ¼³Á¤ °Ë»ç
      nagiosgraph ¼³Ä¡ ¹æ¹ý
      Slony-I ¼³Ä¡ ¹æ¹ý (postgresql replication tool)
      Qmail±â¹ÝÀÇ Anti spam ½Ã½ºÅÛ ±¸ÃàÇϱâ
      clusterssh

    [ ÇÔ²²ÇÏ´Â »çÀÌÆ® ]




    ¿î¿µÁø : ÁÁÀºÁøÈ£(truefeel), ¾ß¼ö(yasu), ¹ü³ÃÀÌ, sCag
    2003³â 8¿ù 4ÀÏ~