SYSTEMD
SYSTEMD-RESOLVE
NAMESYNOPSIS
æè¿°
é项
ä¾å
åè§
NOTES
è·
NAME
systemd-resolve - è§£æä¸»æºåãIPå°åãååãDNSèµæºè®°å½ãæå¡
SYNOPSIS
|
systemd-resolve [OPTIONS...] HOSTNAME... |
||
|
systemd-resolve [OPTIONS...] ADDRESS... |
||
|
systemd-resolve [OPTIONS...] --type=TYPE DOMAIN... |
||
|
systemd-resolve [OPTIONS...] --service [[NAME] TYPE] DOMAIN |
||
|
systemd-resolve [OPTIONS...] --openpgp USER@DOMAIN |
||
|
systemd-resolve [OPTIONS...] --tlsa DOMAIN[:PORT] |
||
|
systemd-resolve [OPTIONS...] --statistics |
||
|
systemd-resolve [OPTIONS...] --reset-statistics |
æè¿°
systemd-resolve å©ç¨ systemd-resolved.service(8) ç³»ç»æå¡è§£æä¸»æºåãIPå°åãååãDNSèµæºè®°å½ãæå¡ã é»è®¤æåµä¸ï¼åæ°å表å°è¢«è§ä¸ºåå/主æºåçå表ï¼ç¨åºçè¾åºå°æ¯å®ä»¬æå¯¹åºç IPv4 æ IPv6 å°åã å¦æåæ°ç¬¦å IPv4 æ IPv6 æ ¼å¼ï¼é£ä¹è¡¨ç¤ºåè§£æIPå°åæå¯¹åºç主æºåã
ç¨åºçè¾åºåæ¬æ¥æ¾æä½¿ç¨çåè®®ä¸ç½ç»æ¥å£ï¼ è¿åæ¬æ¥æ¾å°çä¿¡æ¯æ¯å¦æ¯å¯é çã ææéè¿ DNSSEC 认è¯çä¿¡æ¯å°è¢«è§ä¸ºæ¯å¯é çï¼ ææä»æ¬å°å¯ä¿¡æºè·åçä¿¡æ¯ä¹è¢«è§ä¸ºæ¯å¯é çï¼ åæ¬å¯¹æ¬æºä¸»æºåçè§£æãç¹æ®ç "localhost" 主æºåãæææ¥èª /etc/hosts ä¸çç»æã
--type= ç¨äºæå®ä»æ¥è¯¢ç¹å®ç±»åçDNSèµæºè®°å½(A, AAAA, SOA, MX, ...)ï¼ è䏿¯é»è®¤çå°åè§£æ/åè§£æã ç¹æ®å¼ "help" å¯ç¨äºååºææå¯ç¨çè®°å½ç±»åã
--service ç¨äºè§£æ SRV [1] ä¸ DNS-SD [2] æå¡(è§ä¸æ)ã éè¦ä¸è³ä¸ä¸ªåæ°ã妿æå®äºä¸ä¸ªåæ°ï¼é£ä¹ç¬¬ä¸ä¸ªæ¯ DNS-SD æå¡åï¼ ç¬¬äºä¸ªæ¯ SRV æå¡ç±»åï¼ç¬¬ä¸ä¸ªæ¯è¦æ¥æ¾çåãå¨è¿ç§æåµä¸ï¼å°ä¼æ§è¡ä¸æ¬¡å®æ´ç DNS-SD 飿 ¼ç SRV ä¸ TXT æ¥è¯¢ã å¦æåªæå®äºäºä¸ªåæ°ï¼é£ä¹ç¬¬ä¸ä¸ªæ¯ SRV æå¡ç±»åï¼ ç¬¬äºä¸ªæ¯è¦æ¥æ¾çåãå¨è¿ç§æåµä¸ï¼å°çç¥ TXT æ¥è¯¢ãæåï¼å¦æåªæå®äºä¸ä¸ªåæ°ï¼ é£ä¹è¯¥åæ°å°è¢«è§ä¸ºååï¼å¹¶ä¸å·²ç»å ä¸äº SRV ç±»ååç¼ãå¨è¿ç§æåµä¸ï¼å°ä¼æ§è¡ä¸ä¸ª SRV æ¥è¯¢(ä¸å« TXT)
--openpgp ç¨äºæ¥è¯¢åå¨å¨DNSç OPENPGPKEY [3] ç±»åçèµæºè®°å½ä¸ç PGP å¬é¥ã éè¦æå®è³å°ä¸ä¸ªEmailå°åã
--tlsa ç¨äºæ¥è¯¢åå¨å¨DNSç TLSA [4] ç±»åçèµæºè®°å½ä¸ç TLS å¬é¥ã éè¦æå®è³å°ä¸ä¸ªååã
--statistics ç¨äºæ¾ç¤ºè§£æç»è®¡ï¼ 忬 DNSSEC éªè¯æåä¸å¤±è´¥çæ°éã
--reset-statistics ç¨äºéç½®åç§è§£æç»è®¡ç计æ°å¨ï¼ åæ¬ææ --statistics è¾åºçç»è®¡æ°æ®ãæ¤æä½éè¦è¶çº§ç¨æ·æéã
é项
-4, -6
å¨è§£æä¸»æºåæ¶ï¼é»è®¤åæ¶æ¥è¯¢ IPv4 ä¸ IPv6 å°åã ä½¿ç¨ -4 è¡¨ç¤ºä»æ¥è¯¢ IPv4 å°åï¼ ä½¿ç¨ -6 è¡¨ç¤ºä»æ¥è¯¢ IPv6 å°åã
-i INTERFACE, --interface=INTERFACE
æå®ä½¿ç¨åªä¸ªç½ç»æ¥å£ã å¯ä»¥ä½¿ç¨ç½å¡çæ°ååºå·ï¼ä¹å¯ä»¥ä½¿ç¨ä¾å¦ "en0" è¿æ ·çç½å¡åç§°ã æ³¨æï¼å¨ä½¿ç¨å¨å±DNS(ä½äº /etc/resolv.conf ä¸ /etc/systemd/resolve.conf) çæ¶åï¼æ¤éé¡¹æ²¡æææã
-p PROTOCOL, --protocol=PROTOCOL
æå®æ¥è¯¢æç¨çåè®®ãå¯ä»¥è®¾ä¸ºä¸åå个å¼ä¹ä¸ï¼ "dns"(ç»å¸çåæDNS)ã "llmnr"(Link-Local Multicast Name Resolution [5] )ã "llmnr-ipv4" ã "llmnr-ipv6" ã é»è®¤ä½¿ç¨ææéåçåè®®ã å¯ä»¥å¤æ¬¡ä½¿ç¨æ- ¤é项以æå®å¤ä¸ªæ¥è¯¢åè®®ã æ³¨æï¼(1)设置 "llmnr" çä»·äºåæ¶è®¾ç½® "llmnr-ipv4" ä¸ "llmnr-ipv6" ã(2)æ¤é项并ä¸å¼ºå¶ systemd-resolved.service(8) å¿é¡»ä½¿ç¨æå®çæ¥è¯¢åè®®ï¼å 为æä¸ªå¿éçç½ç»æ¥å£ä¸ç¸åºçéç½®å¯è½ä¸åå¨ã (3)ç¹æ®å¼ "help" å¯ç¨äºååºææå¯ç¨çåè®®ã
-t TYPE, --type=TYPE, -c CLASS, --class=CLASS
æå®æ¥æ¾çDNSèµæºè®°å½ç type(A, AAAA, MX, ...) ä¸ class(IN, ANY, ...)ã å¦æä½¿ç¨äºæ¤é项ï¼é£ä¹ä»æ¥è¯¢ä¸æå®ç type/class å¹éçDNSèµæºè®°å½ã 妿仿å®äº type çè¯ï¼é£ä¹ class çé»è®¤å¼æ¯"IN"ã ç¹æ®å¼ "help" å¯ç¨äºååºææå¯ç¨çå¼ã
--service
æ ¹æ®æå®çåæ°å表ï¼å¼å¯ DNS-SD ä¸ ç®å SRV æå¡è§£æã 详è§åæã
--service-address=BOOL
é»è®¤å¼ yes 表示å¨ä½¿ç¨ --service æ¥æ¾æå¡æ¶ï¼åæ¶ä¹è§£æåå«å¨ SRV èµæºè®°å½åç主æºåã
--service-txt=BOOL
é»è®¤å¼ yes 表示å¨ä½¿ç¨ --service æ¥æ¾ DNS-SD æå¡æ¶ï¼åæ¶ä¹è§£æ TXT æå¡åæ°æ®è®°å½ã
--openpgp
æ¥è¯¢åå¨å¨DNSç OPENPGPKEY ç±»åçèµæºè®°å½ä¸ç PGP å¬é¥(åè§åæ)ã æå®çEmailå°åå°è¢«è½¬æ¢ä¸ºå¯¹åºçDNSååï¼å¹¶æå°åºææ OPENPGPKEY å¬é¥ã
--tlsa
为æ¯ä¸ä¸ªå¸¦æ port ä¸ family åç¼çåå ("_port._family.domain") æ¥è¯¢åå¨å¨DNSç TLSA ç±»åçèµæºè®°å½ä¸ç TLS å¬é¥(åè§åæ)ã 端å£å·å¯ä»¥æç¡®çåå¨åå·(:)ä¹åï¼ å¦åå°ä½¿ç¨é»è®¤ç 443 端å£ã family å¯ä»¥ä½ä¸º --tlsa çåæ°æå®ï¼å¦åå°ä½¿ç¨é»è®¤å¼ tcp ã
--cname=BOOL
é»è®¤å¼ yes 表示追踪 DNS ç CNAME æ DNAME éå®åã å¦åï¼å¨æ¥æ¶å° CNAME æ DNAME åºçåï¼ç´æ¥è¿åé误ã
--search=BOOL
é»è®¤å¼ yes 表示ææä¸å«"."ç主æºåé½å°å¨æç´¢åå表(è¥é空)ä¸- è¿è¡æç´¢ã
--raw[=payload|packet]
以åå§çäºè¿å¶æ ¼å¼æ¾ç¤ºåºççæ°æ®ã "payload"(缺çå¼)è¡¨ç¤ºå¯¼åºæ°æ®åçè·è½½ã "packet" 表示导åºåå§çæ°æ®å¸§ï¼å¹¶å¨åé¢å ä¸ä¸ä¸ªå°ç«¯åºå½¢å¼è¡¨ç¤ºç64使´æ°ã æ¤é项ä»ç¨äºè°è¯ç®çã
--legend=BOOL
é»è®¤å¼ yes 表示æ¾ç¤ºåºçåå®¹çæ é¢å¤´ä¸åæ°æ®ã
--statistics
æ¾ç¤ºè§£æç»è®¡ï¼åæ¬ DNSSEC æ¯å¦å¯ç¨ï¼ 以å DNSSEC éªè¯æåä¸å¤±è´¥çæ°éã
--reset-statistics
éç½®åç§è§£æç»è®¡ç计æ°å¨ï¼åæ¬ææ --statistics è¾åºçç»è®¡æ°æ®ãæ- ¤æä½éè¦è¶çº§ç¨æ·æéã
--flush-caches
å·æ°æ¬å°DNSèµæºè®°å½ç¼åã
--status
æ¾ç¤ºå¨å±DNS设置ã以åé对æ¯ä¸ªè¿æ¥çDNS设置ã
-h, --help
æ¾ç¤ºç®çç帮å©ä¿¡æ¯å¹¶éåºã
--version
æ¾ç¤ºç®çççæ¬ä¿¡æ¯å¹¶éåºã
--no-pager
ä¸å°ç¨åºçè¾åºå容管é(pipe)ç»å页ç¨åºã
ä¾å
Example 1. è§£æ "www.0pointer.net" ååæå¯¹åºçå°å
$
systemd-resolve www.0pointer.net
www.0pointer.net: 2a01:238:43ed:c300:10c3:bcf3:3266:da74
85.214.157.71
--
Information acquired via protocol DNS in 611.6ms.
-- Data is authenticated: no
Example 2. åè§£æ "85.214.157.71" å°åæå¯¹åºçåå
$
systemd-resolve 85.214.157.71
85.214.157.71: gardel.0pointer.net
--
Information acquired via protocol DNS in 1.2997s.
-- Data is authenticated: no
Example 3. æ¥æ¾ "0pointer.net" ååç MX è®°å½
$
systemd-resolve -t MX yahoo.com --legend=no
yahoo.com. IN MX 1 mta7.am0.yahoodns.net
yahoo.com. IN MX 1 mta6.am0.yahoodns.net
yahoo.com. IN MX 1 mta5.am0.yahoodns.net
Example 4. æ¥æ¾ä¸ä¸ª SRV æå¡
$
systemd-resolve --service _xmpp-server._tcp gmail.com
_xmpp-server._tcp/gmail.com:
alt1.xmpp-server.l.google.com:5269 [priority=20, weight=0]
173.194.210.125
alt4.xmpp-server.l.google.com:5269 [priority=20, weight=0]
173.194.65.125
...
Example 5. æ¥æ¾ä¸ä¸ª PGP å¬é¥
$
systemd-resolve --openpgp zbyszek@fedoraproject.org
d08ee310438ca124a6149ea5cc21b6313b390dce485576eff96f8722._openpgpkey.fedoraproject.org.
IN OPENPGPKEY
mQINBFBHPMsBEACeInGYJCb+7TurKfb6wGyTottCDtiSJB310i37/6ZYoeIay/5soJjlMyf
MFQ9T2XNT/0LM6gTa0MpC1st9LnzYTMsT6tzRly1D1UbVI6xw0g0vE5y2Cjk3xUwAynCsSs
...
Example 6. æ¥æ¾ä¸ä¸ª TLS å¬é¥ (å¯ä»¥çç¥ "=tcp" ä¸ ":443")
$
systemd-resolve --tlsa=tcp fedoraproject.org:443
_443._tcp.fedoraproject.org IN TLSA 0 0 1
19400be5b7a31fb733917700789d2f0a2471c0c9d506c0e504c06c16d7cb17c0
-- Cert. usage: CA constraint
-- Selector: Full Certificate
-- Matching type: SHA-256
åè§
systemd(1), systemd-resolved.service(8)
NOTES
|
1. |
SRV |
https://tools.ietf.org/html/rfc2782
|
2. |
DNS-SD |
https://tools.ietf.org/html/rfc6763
|
3. |
OPENPGPKEY |
https://tools.ietf.org/html/draft-wouters-dane-openpgp-02
|
4. |
TLSA |
https://tools.ietf.org/html/rfc6698
|
5. |
Link-Local Multicast Name Resolution |
https://tools.ietf.org/html/rfc4795
è·
æ¬é¡µé¢ä¸æçç±ä¸æ man æå页计åæä¾ã
ç¿»è¯äººåï¼éæ¥å½
鿥å½ä½åéï¼http://www.jinbuguo.com
䏿 man
æå页计åï¼https://github.com/man-pages-zh/manpages-zh