Skip to content
Back to skills

Bind

ASecurity

Expert coverage of ISC BIND across all versions: named.conf configuration, views (split-horizon), zone files, DNSSEC with KASP, RPZ (Response Policy Zones), TSIG, catalog zones, and rndc management. Use for \"BIND\", \"named.conf\", \"zone file\", \"RPZ\", \"KASP\", \"dnssec-policy\", \"rndc\", \"TSIG\", \"BIND views\", \"split-horizon DNS\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `dns` skill.

  • 4 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 24, 2026
devopsrustgodatabasesecurity

Works with

  • cli

Security analysis

A100/100

Pro scans all 7 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill bind --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Bind?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Bind
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-bind/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-bind)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: bind
description: "Expert coverage of ISC BIND across all versions: named.conf configuration, views (split-horizon), zone files, DNSSEC with KASP, RPZ (Response Policy Zones), TSIG, catalog zones, and rndc management. Use for \"BIND\", \"named.conf\", \"zone file\", \"RPZ\", \"KASP\", \"dnssec-policy\", \"rndc\", \"TSIG\", \"BIND views\", \"split-horizon DNS\". Do NOT use for cross-vendor comparison, platform selection, or category-wide architecture -- use the `dns` skill."
license: MIT
---

# ISC BIND

This skill covers ISC BIND (Berkeley Internet Name Domain) across all supported versions (9.18 ESV, 9.20 stable). Areas of expertise include:

- `named.conf` configuration (options, logging, ACLs, keys, zones, views)
- Zone file format (SOA, NS, A, AAAA, CNAME, MX, TXT, SRV, PTR)
- Views for split-horizon DNS (internal/external)
- DNSSEC with KASP (Key and Signing Policy) for automated signing
- RPZ (Response Policy Zones) for DNS security and threat blocking
- TSIG for zone transfer and dynamic update authentication
- Catalog zones for automated zone provisioning on secondaries
- rndc for runtime management (reload, flush, stats, key management)
- Rate limiting (RRL) for DNS amplification protection

## How to Approach Tasks

1. **Classify** the request:
   - **Configuration** -- named.conf structure, zone setup, views, ACLs
   - **DNSSEC** -- KASP policies, manual signing, key rollover, DS records
   - **Security** -- RPZ setup, TSIG keys, RRL, chroot deployment
   - **Troubleshooting** -- Load `references/diagnostics.md` for rndc, query logging, validation
   - **Architecture** -- Load `references/architecture.md` for named.conf structure, views, zone files

2. **Identify version** -- 9.18 is ESV (Extended Support). 9.20 is current stable with breaking changes (RBTDB removed, auto-dnssec removed). Version matters significantly.

3. **Identify role** -- Authoritative-only, recursive-only, or combined? Best practice is separate instances.

4. **Recommend** -- Provide named.conf configuration blocks. Always validate: `named-checkconf` and `named-checkzone`.

## Core Architecture

### named.conf Structure

```
options { ... };        # Global settings
logging { ... };        # Log channels and categories
acl "internal" { ... }; # Named address match lists
key "transfer-key" { ... }; # TSIG keys
zone "example.com" { ... }; # Zone definitions
view "internal" { ... }; # View definitions (optional)
controls { ... };       # rndc control channel
```

### Key Options

```
options {
    directory "/var/named";
    recursion yes;                      # Enable for recursive; disable for authoritative-only
    allow-recursion { internal; };      # Restrict recursion to trusted clients
    allow-query { any; };
    allow-transfer { none; };           # Default deny zone transfers
    dnssec-validation auto;             # Enable DNSSEC validation
    minimal-responses yes;              # Reduce amplification risk
    version "not disclosed";            # Hide version string
};
```

### Views (Split-Horizon)

```
view "internal" {
    match-clients { internal; };
    recursion yes;
    zone "example.com" { type primary; file "internal/example.com.zone"; };
};
view "external" {
    match-clients { any; };
    recursion no;
    zone "example.com" { type primary; file "external/example.com.zone"; };
};
```

Rules: once any view is defined, ALL zones must be inside a view. First match wins.

### Zone File Format

```
$ORIGIN example.com.
$TTL 3600
@   IN  SOA  ns1.example.com. hostmaster.example.com. (
                2024010101  ; Serial (YYYYMMDDnn)
                3600        ; Refresh
                900         ; Retry
                604800      ; Expire
                300 )       ; Minimum/Negative TTL
@   IN  NS   ns1.example.com.
@   IN  NS   ns2.example.com.
ns1 IN  A    192.0.2.1
www IN  A    192.0.2.10
@   IN  MX   10 mail.example.com.
@   IN  TXT  "v=spf1 ip4:192.0.2.0/24 -all"
```

### DNSSEC with KASP

KASP (`dnssec-policy`) is the recommended automated signing method:

```
dnssec-policy "default";    # Built-in: ECDSAP256SHA256 CSK, 1-year lifetime
inline-signing yes;         # Default in 9.20 when dnssec-policy set

# Custom policy:
dnssec-policy "my-policy" {
    keys {
        ksk lifetime P1Y algorithm ecdsap256sha256;
        zsk lifetime P90D algorithm ecdsap256sha256;
    };
    nsec3param iterations 0 optout no salt-length 0;  # RFC 9276
};
```

### RPZ (Response Policy Zones)

RPZ intercepts DNS responses for threat blocking:

```
response-policy {
    zone "rpz.example.com" policy NXDOMAIN;
};
zone "rpz.example.com" {
    type primary;
    file "rpz.example.com.zone";
};
```

Actions: NXDOMAIN, NODATA, PASSTHRU, DROP, CNAME redirect.
Triggers: qname, client-ip, response-ip, nsdname, nsip.

### TSIG

Cryptographic authentication for zone transfers and dynamic updates:

```
key "transfer-key" {
    algorithm hmac-sha256;
    secret "base64-secret==";
};
zone "example.com" {
    allow-transfer { key "transfer-key"; };
};
```

Generate: `tsig-keygen -a hmac-sha256 transfer-key`

### Catalog Zones

Automated zone provisioning: primary maintains list of zones as DNS records; secondaries auto-create zones.

## Common Pitfalls

1. **Recursion open to internet** -- Never set `recursion yes` without `allow-recursion` restricting to trusted clients. Open recursion enables amplification attacks.
2. **auto-dnssec removed in 9.20** -- `auto-dnssec` is removed in BIND 9.20. Use `dnssec-policy` (KASP) instead. Migration required before upgrading.
3. **Zone file serial not incremented** -- Secondaries check SOA serial to determine if zone changed. Manual zone file edits must increment serial.
4. **Views not covering all zones** -- Once any view is defined, ALL zones must be inside a view, including root hints, localhost, and loopback zones.
5. **RPZ startup race** -- Without `servfail-until-ready yes`, BIND serves unprotected queries before RPZ zones load. Enable in production.
6. **KSK rollover DS update** -- KASP automates timing, but admin must submit DS record to parent/registrar and confirm with `rndc dnssec -checkds`.

## Version-Specific Guidance

| Version | Reference | What's version-specific |
|---|---|---|
| 9.18 | `references/versions/9.18.md` | ESV (Extended Support); DoT server, KASP available, RBTDB default |
| 9.20 | `references/versions/9.20.md` | Current stable; QP-trie database, zone templates, auto-dnssec removed, manual-mode KASP |

## Reference Files

- `references/architecture.md` -- named.conf structure, views, zone files, DNSSEC/KASP, RPZ configuration
- `references/diagnostics.md` -- rndc commands, query logging, statistics, troubleshooting workflows

## Diagnostic Scripts

Ready-made validation/resolution scripts (read-only) in `scripts/`.

- `scripts/01-config-and-zone-check.sh` -- named-checkconf -z full zone parse plus rndc status
- `scripts/02-resolution-battery.sh` -- Serial consistency across NS set, DNSSEC check, timing samples

Files in this skill

  • SKILL.md6.8 KB
  • references/architecture.md2.8 KB
  • references/diagnostics.md3.2 KB
  • references/versions/9.18.md2.6 KB
  • references/versions/9.20.md3.7 KB
  • scripts/01-config-and-zone-check.sh1.2 KB
  • scripts/02-resolution-battery.sh1.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…