Welcome to Knot DNS's documentation!¶
- Introduction
- Requirements
- Installation
- Configuration
- Operation
- Configuration database
- Dynamic configuration
- Secondary (slave) mode
- Primary (master) mode
- Reading and editing zones
- Reading and editing the zone file safely
- Zone loading
- Journal behaviour
- Handling zone file, journal, changes, serials
- Zone bootstrapping on secondary
- Zone expiration
- DNSSEC key states
- DNSSEC key rollovers
- DNSSEC shared KSK
- DNSSEC delete algorithm
- DNSSEC Offline KSK
- DNSSEC multi-signer
- DNSSEC keys import to HSM
- Daemon controls
- Logging
- Data and metadata backup
- Statistics
- Mode XDP
- Troubleshooting
- Configuration Reference
- Description
- Comments
- Including configuration
- Clearing configuration sections
module
sectionserver
sectionxdp
sectioncontrol
sectionlog
sectionstatistics
sectiondatabase
sectionkeystore
sectionkey
sectionremote
sectionremotes
sectionacl
sectionsubmission
sectiondnskey-sync
sectionpolicy
sectiontemplate
sectionzone
section
- Modules
authsignal
– Automatic Authenticated DNSSEC Bootstrapping recordscookies
— DNS Cookiesdnsproxy
– Tiny DNS proxydnstap
– Dnstap traffic logginggeoip
— Geography-based responsesnoudp
— No UDP responseonlinesign
— Online DNSSEC signingprobe
— DNS traffic probequeryacl
— Limit queries by remote address or target interfacerrl
— Response rate limitingstats
— Query statisticssynthrecord
– Automatic forward/reverse recordswhoami
— Whoami response
- Utilities
knotd
– Knot DNS server daemonknotc
– Knot DNS control utilitykeymgr
– Key management utilitykjournalprint
– Knot DNS journal print utilitykcatalogprint
– Knot DNS catalog print utilitykzonecheck
– Knot DNS zone file checking toolkzonesign
– DNSSEC signing utilitykdig
– Advanced DNS lookup utilitykhost
– Simple DNS lookup utilityknsec3hash
– NSEC hash computation utilityknsupdate
– Dynamic DNS update utilitykxdpgun
– DNS benchmarking tool
- Migration
- Appendices