|
Size: 2540
Comment:
|
← Revision 18 as of 2026-09-18 22:10:16 ⇥
Size: 3347
Comment:
|
| Deletions are marked like this. | Additions are marked like this. |
| Line 26: | Line 26: |
=== In bind9 server === |
|
| Line 34: | Line 36: |
| # generates 2 files, one with extension .key and another with extension .private with the same symmetric key # it generates a symmetric key # ensures integrity -anti-tampering and authenticity }}} |
|
| Line 35: | Line 41: |
| # secret contains the Key: value # vim /etc/bind/keys.conf |
=== /etc/bind/keys.conf === secret contains the Key: value in K<...>.private file generated by dnssec-keygen command {{{#!highlight sh |
| Line 41: | Line 48: |
| }}} | |
| Line 42: | Line 50: |
| # vim /etc/bind/named.conf | === /etc/bind/named.conf === {{{#!highlight sh |
| Line 49: | Line 58: |
| }}} | |
| Line 50: | Line 60: |
| #vim /etc/bind/bitarus.mooo.com.hosts | === /etc/bind/bitarus.mooo.com.hosts === Subdomain bitarus.mooo.com {{{#!highlight sh |
| Line 63: | Line 75: |
| TXT "keyx=valuex" | |
| Line 65: | Line 78: |
| }}} | |
| Line 66: | Line 80: |
| {{{#!highlight sh | |
| Line 70: | Line 85: |
| }}} | |
| Line 71: | Line 87: |
| # In raspberry pi | === In raspberry pi === {{{#!highlight sh |
| Line 79: | Line 96: |
| }}} | |
| Line 80: | Line 98: |
| #vim nsupdate-rpi.sh | === nsupdate-rpi.sh === {{{#!highlight sh |
| Line 94: | Line 113: |
| }}} | |
| Line 95: | Line 115: |
| === Steps === {{{#!highlight sh |
|
| Line 107: | Line 129: |
== nslookup == {{{#!highlight sh nslookup > server x.example.org Default server: x.example.org Address: 1.2.3.4#53 > set type=any > x.example.com Server: x.example.org Address: 1.2.3.4#53 Name: x.example.com Address: 1.2.3.4 > exit }}} |
Contents
DNS
Domain name service
Check mail record with dig
1 dig mx bitarus.allowed.org
Check mail record with dig directly in name server
1 dig mx bitarus.allowed.org @ns.bitarus.allowed.org
Check reverse dns
1 dig -x 54.68.9.58
Ask for Reverse DNS for EC2 Elastic IP address
Dynamic DNS Raspberry pi
In bind9 server
1 # change apparmor in ubuntu
2 apt install apparmor-utils
3 sudo aa-complain /usr/sbin/named
4 service bind9 restart
5
6 cd /tmp # bind server
7 dnssec-keygen -a HMAC-SHA512 -b 512 -n USER rpi.dyn.bitarus.allowed.org.
8 # generates 2 files, one with extension .key and another with extension .private with the same symmetric key
9 # it generates a symmetric key
10 # ensures integrity -anti-tampering and authenticity
11
/etc/bind/keys.conf
secret contains the Key: value in K<...>.private file generated by dnssec-keygen command
/etc/bind/named.conf
/etc/bind/bitarus.mooo.com.hosts
Subdomain bitarus.mooo.com
1 $ORIGIN .
2 $TTL 604800 ; 1 week
3 bitarus.mooo.com IN SOA bitarus.mooo.com. root.bitarus.mooo.com. (
4 6 ; serial
5 604800 ; refresh (1 week)
6 86400 ; retry (1 day)
7 2419200 ; expire (4 weeks)
8 604800 ; minimum (1 week)
9 )
10 NS bitarus.mooo.com.
11 A 54.68.9.58
12 MX 5 mail.bitarus.mooo.com.
13 TXT "keyx=valuex"
14 $ORIGIN bitarus.mooo.com.
15 labs A 54.68.9.58
In raspberry pi
nsupdate-rpi.sh
1 logger "Running nsupdate-rpi.sh"
2 EXT_IP=$(wget -qO- http://ifconfig.co/ip)
3 KEY="/home/pi/rpiDdns/Krpi.dyn.bitarus.allowed.org.+165+55648.private"
4 echo "Key: $KEY"
5
6 cat <<EOF | nsupdate -k "$KEY"
7 server bitarus.allowed.org
8 zone bitarus.mooo.com
9 update delete rpi.bitarus.mooo.com. A
10 update add rpi.bitarus.mooo.com. 600 A $EXT_IP
11 show
12 send
13 EOF
Steps
chucknorris host
