// vim: ft=named options { directory "/var/named"; key-directory "keys"; pid-file "/run/named/named.pid"; listen-on-v6 { any; }; tcp-clients 100; allow-query-cache { none; }; allow-query { any; }; allow-transfer { none; }; allow-update { none; }; recursion no; version none; hostname none; server-id none; }; dnssec-policy standard { keys { ksk lifetime 365d algorithm ed25519; zsk lifetime 60d algorithm ed25519; }; }; parental-agents "com" { 192.5.6.30; // a.gtld-servers.net. 192.33.14.30; // b.gtld-servers.net. 192.26.92.30; // c.gtld-servers.net. }; parental-agents "io" { 65.22.160.17; // a0.nic.io. 65.22.161.17; // b0.nic.io. 65.22.162.17; // c0.nic.io. }; zone "kyriasis.com" IN { type master; file "dns/kyriasis.com.zone"; allow-transfer { 178.79.157.58; // lucifer 2a01:7e00::f03c:91ff:fe69:1787; // lucifer }; inline-signing yes; dnssec-policy standard; parental-agents { "com"; }; }; zone "remmy.io" IN { type master; file "dns/remmy.io.zone"; allow-transfer { 178.79.157.58; // lucifer 2a01:7e00::f03c:91ff:fe69:1787; // lucifer }; inline-signing yes; dnssec-policy standard; parental-agents { "io"; }; }; logging { channel dnssec-log { file "/var/named/log/dnssec" versions 3 size 20m; print-time yes; print-category yes; print-severity yes; severity debug 1; }; channel xfer-log { file "/var/named/log/zone_transfers" versions 3 size 20m; print-time yes; print-category yes; print-severity yes; severity info; }; category dnssec { dnssec-log; }; category xfer-in { xfer-log; }; category xfer-out { xfer-log; }; category notify { xfer-log; }; };