source: server/other/unbound.xml@ 26169e99

gnome
Last change on this file since 26169e99 was d555a31, checked in by Christopher Gregory <cjg@…>, 10 years ago

Converted svnserver mariadb postgresql dovecot exim postfix apache bind proftpd vsftpd openldap unbound and xinetd pages to systemd

git-svn-id: svn://svn.linuxfromscratch.org/BLFS/branches/gnome@13415 af4574ff-66df-0310-9fd7-8a98e5e911e0

  • Property mode set to 100644
File size: 11.0 KB
Line 
1<?xml version="1.0" encoding="ISO-8859-1"?>
2<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3 "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4 <!ENTITY % general-entities SYSTEM "../../general.ent">
5 %general-entities;
6
7 <!ENTITY unbound-download-http "http://www.unbound.net/downloads/unbound-&unbound-version;.tar.gz">
8 <!ENTITY unbound-download-ftp " ">
9 <!ENTITY unbound-md5sum "59728c74fef8783f8bad1d7451eba97f">
10 <!ENTITY unbound-size "4.6 MB">
11 <!ENTITY unbound-buildsize "42 MB (additional 70 MB for docs and 5 MB for tests)">
12 <!ENTITY unbound-time "0.6 SBU (additional less than 0.1 SBU for docs and 0.2 SBU for tests)">
13]>
14
15<sect1 id="unbound" xreflabel="Unbound-&unbound-version;">
16 <?dbhtml filename="unbound.html"?>
17
18 <sect1info>
19 <othername>$LastChangedBy$</othername>
20 <date>$Date$</date>
21 </sect1info>
22
23 <title>Unbound-&unbound-version;</title>
24
25 <indexterm zone="unbound">
26 <primary sortas="a-Unbound">Unbound</primary>
27 </indexterm>
28
29 <sect2 role="package">
30 <title>Introduction to Unbound</title>
31
32 <para>
33 <application>Unbound</application> is a validating, recursive, and caching
34 DNS resolver. It is designed as a set of modular components that
35 incorporate modern features, such as enhanced security (DNSSEC)
36 validation, Internet Protocol Version 6 (IPv6), and a client resolver
37 library API as an integral part of the architecture.
38 </para>
39
40 &lfs75_checked;
41
42 <bridgehead renderas="sect3">Package Information</bridgehead>
43 <itemizedlist spacing="compact">
44 <listitem>
45 <para>
46 Download (HTTP): <ulink url="&unbound-download-http;"/>
47 </para>
48 </listitem>
49 <listitem>
50 <para>
51 Download (FTP): <ulink url="&unbound-download-ftp;"/>
52 </para>
53 </listitem>
54 <listitem>
55 <para>
56 Download MD5 sum: &unbound-md5sum;
57 </para>
58 </listitem>
59 <listitem>
60 <para>
61 Download size: &unbound-size;
62 </para>
63 </listitem>
64 <listitem>
65 <para>
66 Estimated disk space required: &unbound-buildsize;
67 </para>
68 </listitem>
69 <listitem>
70 <para>
71 Estimated build time: &unbound-time;
72 </para>
73 </listitem>
74 </itemizedlist>
75
76 <bridgehead renderas="sect3">Unbound Dependencies</bridgehead>
77
78 <bridgehead renderas="sect4">Required</bridgehead>
79 <para role="required">
80 <xref linkend="ldns"/> and
81 <xref linkend="openssl"/>
82<!-- broken?
83 or <xref linkend="nss"/>
84-->
85 </para>
86
87 <bridgehead renderas="sect4">Optional</bridgehead>
88 <para role="optional">
89 <xref linkend="libevent"/>,
90 <xref linkend="python2"/>,
91 <xref linkend="swig"/> (for Python bindings), and
92 <xref linkend="doxygen"/> (for html documentation)
93 </para>
94
95 <para condition="html" role="usernotes">User Notes:
96 <ulink url="&blfs-wiki;/unbound"/>
97 </para>
98 </sect2>
99
100 <sect2 role="installation">
101 <title>Installation of Unbound</title>
102
103 <para>
104 There should be a dedicated user and group to take control of the
105 <command>unbound</command> daemon after it is started. Issue the following
106 commands as the <systemitem class="username">root</systemitem> user:
107 </para>
108
109<screen role="root"><userinput>groupadd -g 88 unbound &amp;&amp;
110useradd -c "Unbound DNS resolver" -d /var/lib/unbound -u 88 \
111 -g unbound -s /bin/false unbound</userinput></screen>
112
113 <para>
114 Install <application>Unbound</application> by running the following
115 commands:
116 </para>
117
118<screen><userinput>./configure --prefix=/usr \
119 --sysconfdir=/etc \
120 --disable-static \
121 --with-pidfile=/run/unbound.pid &amp;&amp;
122make</userinput></screen>
123
124 <para>
125 If you have <xref linkend="doxygen"/> package installed and want to build
126 html documentation, run the following command:
127 </para>
128
129<screen><userinput>make doc</userinput></screen>
130
131 <para>To test the results, issue <command>make check</command>.</para>
132
133 <para>
134 Now, as the <systemitem class="username">root</systemitem> user:
135 </para>
136
137<screen role="root"><userinput>make install &amp;&amp;
138mv -v /usr/sbin/unbound-host /usr/bin/</userinput></screen>
139
140 <para>
141 If you built html documentation, install it by running the following
142 commands as the <systemitem class="username">root</systemitem> user:
143 </para>
144
145<screen role="root"><userinput>install -v -m755 -d /usr/share/doc/unbound-&unbound-version; &amp;&amp;
146install -v -m644 doc/html/* /usr/share/doc/unbound-&unbound-version;</userinput></screen>
147
148 </sect2>
149
150 <sect2 role="commands">
151 <title>Command Explanations</title>
152
153 <xi:include xmlns:xi="http://www.w3.org/2001/XInclude"
154 href="../../xincludes/static-libraries.xml"/>
155
156 <para>
157 <option>--with-libevent</option>: This option enables libevent support
158 allowing use of large outgoing port ranges.
159 </para>
160
161 <para>
162 <option>--with-pyunbound</option>: This option enables building of the Python
163 bindings.
164 </para>
165
166 </sect2>
167
168 <sect2 role="configuration">
169 <title>Configuring Unbound</title>
170
171 <sect3 id="unbound-config">
172 <title>Config Files</title>
173
174 <para><filename>/etc/unbound/unbound.conf</filename></para>
175
176 <indexterm zone="unbound unbound-config">
177 <primary sortas="e-etc-unbound-unbound.conf">/etc/unbound/unbound.conf</primary>
178 </indexterm>
179
180 </sect3>
181
182 <sect3>
183 <title>Configuration Information</title>
184
185 <para>
186 In the default configuration, <command>unbound</command> will bind to
187 localhost (127.0.0.1 IP address) and allow recursive queries only from
188 localhost clients. If you want to use <command>unbound</command> for
189 local DNS resolution, run the following command as the
190 <systemitem class="username">root</systemitem> user:
191 </para>
192
193<screen role="root"><userinput>echo "nameserver 127.0.0.1" > /etc/resolv.conf</userinput></screen>
194
195 <para>
196 If you are using a DHCP client for connecting to a network,
197 <filename>/etc/resolv.conf</filename> gets overwritten with values
198 provided by DHCP server. You can override this, for example in
199 <xref linkend="dhcp"/>, by running the following command:
200 </para>
201
202<screen role="root"><userinput>sed -i '/request /i\supersede domain-name-servers 127.0.0.1;' \
203 /etc/dhcp/dhclient.conf</userinput></screen>
204
205 <para>
206 For advanced configuration see <filename>/etc/unbound/unbound.conf</filename>
207 file and the documentation.
208 </para>
209
210 </sect3>
211
212 <sect3 id="unbound-init-systemd">
213 <title>Systemd Unit File</title>
214
215 <para>The systemd-units package provides a native systemd unit file.
216 To install and enable the systemd unit file included
217 in the <xref linkend="systemd-units"/> package, run the following
218 command as the <systemitem class="username">root</systemitem>user:
219 </para>
220
221 <indexterm zone="unbound unbound-init-systemd">
222 <primary sortas="f-unbound">unbound</primary>
223 </indexterm>
224
225<screen role="root"><userinput>make install-unbound</userinput></screen>
226
227 </sect3>
228
229 </sect2>
230
231 <sect2 role="content">
232 <title>Contents</title>
233
234 <segmentedlist>
235 <segtitle>Installed Programs</segtitle>
236 <segtitle>Installed Library</segtitle>
237 <segtitle>Installed Directories</segtitle>
238
239 <seglistitem>
240 <seg>
241 unbound, unbound-anchor, unbound-checkconf, unbound-control,
242 unbound-control-setup, and unbound-host
243 </seg>
244 <seg>
245 libunbound.so and
246 /usr/lib/python&python2-majorver;/site-packages/_unbound.so
247 </seg>
248 <seg>
249 /etc/unbound and /usr/share/doc/unbound-&unbound-version;
250 </seg>
251 </seglistitem>
252 </segmentedlist>
253
254 <variablelist>
255 <bridgehead renderas="sect3">Short Descriptions</bridgehead>
256 <?dbfo list-presentation="list"?>
257 <?dbhtml list-presentation="table"?>
258
259 <varlistentry id="unbound-prog">
260 <term><command>unbound</command></term>
261 <listitem>
262 <para>
263 is a DNS resolver daemon.
264 </para>
265 <indexterm zone="unbound unbound-prog">
266 <primary sortas="b-unbound">unbound</primary>
267 </indexterm>
268 </listitem>
269 </varlistentry>
270
271 <varlistentry id="unbound-anchor">
272 <term><command>unbound-anchor</command></term>
273 <listitem>
274 <para>
275 performs setup or update of the root trust anchor for DNSSEC
276 validation.
277 </para>
278 <indexterm zone="unbound unbound-anchor">
279 <primary sortas="b-unbound-anchor">unbound-anchor</primary>
280 </indexterm>
281 </listitem>
282 </varlistentry>
283
284 <varlistentry id="unbound-checkconf">
285 <term><command>unbound-checkconf</command></term>
286 <listitem>
287 <para>
288 checks <command>unbound</command> configuration file for syntax
289 and other errors.
290 </para>
291 <indexterm zone="unbound unbound-checkconf">
292 <primary sortas="b-unbound-checkconf">unbound-checkconf</primary>
293 </indexterm>
294 </listitem>
295 </varlistentry>
296
297 <varlistentry id="unbound-control">
298 <term><command>unbound-control</command></term>
299 <listitem>
300 <para>
301 performs remote administration on the <command>unbound</command> DNS
302 resolver.
303 </para>
304 <indexterm zone="unbound unbound-control">
305 <primary sortas="b-unbound-control">unbound-control</primary>
306 </indexterm>
307 </listitem>
308 </varlistentry>
309
310 <varlistentry id="unbound-control-setup">
311 <term><command>unbound-control-setup</command></term>
312 <listitem>
313 <para>
314 generates self-signed certificate and private keys for the server
315 and client.
316 </para>
317 <indexterm zone="unbound unbound-control-setup">
318 <primary sortas="b-unbound-control-setup">unbound-control-setup</primary>
319 </indexterm>
320 </listitem>
321 </varlistentry>
322
323 <varlistentry id="unbound-host">
324 <term><command>unbound-host</command></term>
325 <listitem>
326 <para>
327 is a DNS lookup utility similar to <command>host</command> from
328 <xref linkend="bind-utils"/>.
329 </para>
330 <indexterm zone="unbound unbound-host">
331 <primary sortas="b-unbound-host">unbound-host</primary>
332 </indexterm>
333 </listitem>
334 </varlistentry>
335
336 <varlistentry id="libunbound">
337 <term><filename class="libraryfile">libunbound.so</filename></term>
338 <listitem>
339 <para>
340 provides the <application>Unbound</application> API functions to
341 programs.
342 </para>
343 <indexterm zone="unbound libunbound">
344 <primary sortas="c-libunbound">libunbound.so</primary>
345 </indexterm>
346 </listitem>
347 </varlistentry>
348
349 </variablelist>
350
351 </sect2>
352
353</sect1>
Note: See TracBrowser for help on using the repository browser.