5dfd2bf8f9
This patch adds dnf support for CentOS. Implements: blueprint centos-and-dnf Change-Id: Ice2477c5c44ef1e4cd87763032dda931a87ab195
93 lines
2.4 KiB
Django/Jinja
93 lines
2.4 KiB
Django/Jinja
#
|
|
# {{ ansible_managed }}
|
|
#
|
|
options {
|
|
{% if ansible_pkg_mgr == 'apt' %}
|
|
directory "/var/cache/bind";
|
|
{% elif ansible_pkg_mgr in ['yum', 'dnf'] %}
|
|
directory "/var/named";
|
|
{% elif ansible_pkg_mgr == 'zypper' %}
|
|
directory "/var/lib/named";
|
|
managed-keys-directory "/var/lib/named/dyn/";
|
|
dump-file "/var/log/named_dump.db";
|
|
statistics-file "/var/log/named.stats";
|
|
notify no;
|
|
disable-empty-zone "1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA";
|
|
{% endif %}
|
|
|
|
// If there is a firewall between you and nameservers you want
|
|
// to talk to, you may need to fix the firewall to allow multiple
|
|
// ports to talk. See http://www.kb.cert.org/vuls/id/800113
|
|
|
|
// If your ISP provided one or more IP addresses for stable
|
|
// nameservers, you probably want to use them as forwarders.
|
|
// Uncomment the following block, and insert the addresses replacing
|
|
// the all-0's placeholder.
|
|
|
|
// forwarders {
|
|
// 0.0.0.0;
|
|
// };
|
|
|
|
//========================================================================
|
|
// If BIND logs error messages about the root key being expired,
|
|
// you will need to update your keys. See https://www.isc.org/bind-keys
|
|
//========================================================================
|
|
dnssec-validation auto;
|
|
|
|
auth-nxdomain no; # conform to RFC1035
|
|
listen-on-v6 { any; };
|
|
allow-new-zones yes;
|
|
request-ixfr no;
|
|
recursion no;
|
|
};
|
|
|
|
{% if ansible_pkg_mgr in ['yum', 'dnf'] %}
|
|
logging {
|
|
channel default_debug {
|
|
file "data/named.run";
|
|
severity dynamic;
|
|
};
|
|
};
|
|
|
|
zone "." IN {
|
|
type hint;
|
|
file "named.ca";
|
|
};
|
|
|
|
include "/etc/rndc.key";
|
|
|
|
controls {
|
|
inet 127.0.0.1 allow { localhost; } keys { "rndc-key"; };
|
|
};
|
|
|
|
include "/etc/named.rfc1912.zones";
|
|
include "/etc/named.root.key";
|
|
|
|
{% elif ansible_pkg_mgr == 'zypper' %}
|
|
|
|
zone "." in {
|
|
type hint;
|
|
file "root.hint";
|
|
};
|
|
|
|
zone "localhost" in {
|
|
type master;
|
|
file "localhost.zone";
|
|
};
|
|
|
|
zone "0.0.127.in-addr.arpa" in {
|
|
type master;
|
|
file "127.0.0.zone";
|
|
};
|
|
|
|
zone "0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.ip6.arpa" IN {
|
|
type master;
|
|
file "127.0.0.zone";
|
|
};
|
|
|
|
|
|
include "/etc/named.conf.include";
|
|
|
|
{% endif %}
|
|
|