Welcome to Knot DNS's documentation!¶
- Introduction
- Requirements
- Installation
- Configuration
- Operation
- Configuration database
- Dynamic configuration
- Secondary (slave) mode
- Primary (master) mode
- Reading and editing zones
- Reading and editing the zone file safely
- Zone loading
- Journal behaviour
- Handling zone file, journal, changes, serials
- Zone bootstrapping on secondary
- Zone expiration
- DNSSEC key states
- DNSSEC key rollovers
- DNSSEC shared KSK
- DNSSEC delete algorithm
- DNSSEC Offline KSK
- DNSSEC multi-signer
- DNSSEC keys import to HSM
- Daemon controls
- Logging
- Data and metadata backup
- Statistics
- Mode XDP
- Troubleshooting
- Configuration Reference
- Description
- Comments
- Including configuration
- Clearing configuration sections
modulesectionserversectionxdpsectioncontrolsectionlogsectionstatisticssectiondatabasesectionkeystoresectionkeysectionremotesectionremotessectionaclsectionsubmissionsectiondnskey-syncsectionpolicysectiontemplatesectionzonesection
- Modules
authsignal– Automatic Authenticated DNSSEC Bootstrapping recordscookies— DNS Cookiesdnsproxy– Tiny DNS proxydnstap– Dnstap traffic logginggeoip— Geography-based responsesnoudp— No UDP responseonlinesign— Online DNSSEC signingprobe— DNS traffic probequeryacl— Limit queries by remote address or target interfacerrl— Response rate limitingstats— Query statisticssynthrecord– Automatic forward/reverse recordswhoami— Whoami response
- Utilities
knotd– Knot DNS server daemonknotc– Knot DNS control utilitykeymgr– Key management utilitykjournalprint– Knot DNS journal print utilitykcatalogprint– Knot DNS catalog print utilitykzonecheck– Knot DNS zone file checking toolkzonesign– DNSSEC signing utilitykdig– Advanced DNS lookup utilitykhost– Simple DNS lookup utilityknsec3hash– NSEC hash computation utilityknsupdate– Dynamic DNS update utilitykxdpgun– DNS benchmarking tool
- Migration
- Appendices