dnssec-importkey.docbook revision e939674d53a127ddeeaf4b41fd72933f0b493308
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder<!--
25cc5fbba63f84b47e389af749f55abbbde71c8cChristian Maeder - Copyright (C) 2013-2015 Internet Systems Consortium, Inc. ("ISC")
25cc5fbba63f84b47e389af749f55abbbde71c8cChristian Maeder -
25cc5fbba63f84b47e389af749f55abbbde71c8cChristian Maeder - Permission to use, copy, modify, and/or distribute this software for any
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder - purpose with or without fee is hereby granted, provided that the above
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder - copyright notice and this permission notice appear in all copies.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder -
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder - PERFORMANCE OF THIS SOFTWARE.
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder-->
b9625461755578f3eed04676d42a63fd2caebd0cChristian Maeder
ce8b15da31cd181b7e90593cbbca98f47eda29d6Till Mossakowski<!-- Converted by db4-upgrade version 1.0 -->
ce8b15da31cd181b7e90593cbbca98f47eda29d6Till Mossakowski<refentry xmlns="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dnssec-importkey">
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder <info>
760ae19a92dde8249679a674f93f58d26a7c5f6bChristian Maeder <date>2014-02-20</date>
760ae19a92dde8249679a674f93f58d26a7c5f6bChristian Maeder </info>
88c800932dd7053322501ea2039d9f234be6866cKlaus Luettich <refentryinfo>
8410667510a76409aca9bb24ff0eda0420088274Christian Maeder <date>August 21, 2015</date>
8410667510a76409aca9bb24ff0eda0420088274Christian Maeder <corpname>ISC</corpname>
8410667510a76409aca9bb24ff0eda0420088274Christian Maeder <corpauthor>Internet Systems Consortium, Inc.</corpauthor>
404166b9366552e9ec5abb87a37c76ec8a815fb7Klaus Luettich </refentryinfo>
404166b9366552e9ec5abb87a37c76ec8a815fb7Klaus Luettich
fdb2d618144159395f7bf8ce3327b3c112a17dd3Till Mossakowski <refmeta>
404166b9366552e9ec5abb87a37c76ec8a815fb7Klaus Luettich <refentrytitle><application>dnssec-importkey</application></refentrytitle>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <manvolnum>8</manvolnum>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <refmiscinfo>BIND9</refmiscinfo>
d67a33b40578beef2e255a274f89bb9c34aaf056Christian Maeder </refmeta>
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder
e593b89bfd4952698dc37feced21cefe869d87a2Christian Maeder <refnamediv>
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder <refname><application>dnssec-importkey</application></refname>
6e049108aa87dc46bcff96fae50a4625df1d9648Klaus Luettich <refpurpose>Import DNSKEY records from external systems so they can be managed.</refpurpose>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </refnamediv>
31c49f2fa23d4ac089f35145d80a224deb6ea7e4Till Mossakowski
760ae19a92dde8249679a674f93f58d26a7c5f6bChristian Maeder <docinfo>
31c49f2fa23d4ac089f35145d80a224deb6ea7e4Till Mossakowski <copyright>
c55a0f77be7e88d3620b419ec8961f4379a586e3Klaus Luettich <year>2013</year>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <year>2014</year>
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder <year>2015</year>
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </copyright>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </docinfo>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <refsynopsisdiv>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <cmdsynopsis sepchar=" ">
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <command>dnssec-importkey</command>
5d4038657f6a63e131f5804af2f7957b69e15a43Klaus Luettich <arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">ttl</replaceable></option></arg>
b0294d73dcefc502ddaa13e18b46103a5916971fTill Mossakowski <arg choice="opt" rep="norepeat"><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <arg choice="opt" rep="norepeat"><option>-P sync <replaceable class="parameter">date/offset</replaceable></option></arg>
77a65251ee036c6aaf09c2775315a4ee24259fbdJorina Freya Gerken <arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">date/offset</replaceable></option></arg>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <arg choice="opt" rep="norepeat"><option>-D sync <replaceable class="parameter">date/offset</replaceable></option></arg>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <arg choice="opt" rep="norepeat"><option>-h</option></arg>
4d7d7f9a423490731c73403c7806bd66967da946Christian Maeder <arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <arg choice="opt" rep="norepeat"><option>-V</option></arg>
97812b7ce9860bf514a8822a63503451795dbc65Klaus Luettich <arg choice="req" rep="norepeat"><option>keyfile</option></arg>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </cmdsynopsis>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <cmdsynopsis sepchar=" ">
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <command>dnssec-importkey</command>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <arg choice="req" rep="norepeat"><option>-f <replaceable class="parameter">filename</replaceable></option></arg>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">ttl</replaceable></option></arg>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <arg choice="opt" rep="norepeat"><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <arg choice="opt" rep="norepeat"><option>-P sync <replaceable class="parameter">date/offset</replaceable></option></arg>
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers <arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">date/offset</replaceable></option></arg>
4e7050bcbcf0f372a5bad32ecd0282bccabf0983Klaus Luettich <arg choice="opt" rep="norepeat"><option>-D sync <replaceable class="parameter">date/offset</replaceable></option></arg>
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder <arg choice="opt" rep="norepeat"><option>-h</option></arg>
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich <arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder <arg choice="opt" rep="norepeat"><option>-V</option></arg>
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder <arg choice="opt" rep="norepeat"><option>dnsname</option></arg>
340706b6c0c6e3dbacdd7003e20e9cab7f9aa765Christian Maeder </cmdsynopsis>
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder </refsynopsisdiv>
ce50fe187cdae64e75e510daafb78156280bdb91Christian Maeder
ebe517300051f765f2ed856a789dd5613d681ab0Klaus Luettich <refsection><info><title>DESCRIPTION</title></info>
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers
c55a0f77be7e88d3620b419ec8961f4379a586e3Klaus Luettich <para><command>dnssec-importkey</command>
6ae5607d2def114f998fd49bac4eef12a2620fafChristian Maeder reads a public DNSKEY record and generates a pair of
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder .key/.private files. The DNSKEY record may be read from an
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder existing .key file, in which case a corresponding .private file
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder will be generated, or it may be read from any other file or
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder from the standard input, in which case both .key and .private
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder files will be generated.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </para>
ebe517300051f765f2ed856a789dd5613d681ab0Klaus Luettich <para>
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers The newly-created .private file does <emphasis>not</emphasis>
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers contain private key data, and cannot be used for signing.
c55a0f77be7e88d3620b419ec8961f4379a586e3Klaus Luettich However, having a .private file makes it possible to set
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder publication (<option>-P</option>) and deletion
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder (<option>-D</option>) times for the key, which means the
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder public key can be added to and removed from the DNSKEY RRset
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder on schedule even if the true private key is stored offline.
ce50fe187cdae64e75e510daafb78156280bdb91Christian Maeder </para>
4e7050bcbcf0f372a5bad32ecd0282bccabf0983Klaus Luettich </refsection>
6ae5607d2def114f998fd49bac4eef12a2620fafChristian Maeder
e593b89bfd4952698dc37feced21cefe869d87a2Christian Maeder <refsection><info><title>OPTIONS</title></info>
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <variablelist>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <varlistentry>
9df11f85fd7f8c4745d64464876e84ec4e263692Christian Maeder <term>-f <replaceable class="parameter">filename</replaceable></term>
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers <listitem>
9df11f85fd7f8c4745d64464876e84ec4e263692Christian Maeder <para>
5b818f10e11fc79def1fdd5c8a080d64a6438d87Christian Maeder Zone file mode: instead of a public keyfile name, the argument
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers is the DNS domain name of a zone master file, which can be read
5d4038657f6a63e131f5804af2f7957b69e15a43Klaus Luettich from <option>file</option>. If the domain name is the same as
5d4038657f6a63e131f5804af2f7957b69e15a43Klaus Luettich <option>file</option>, then it may be omitted.
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder </para>
c432483b64662e8db604a58758cd18ea7fa65659Christian Maeder <para>
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder If <option>file</option> is set to <literal>"-"</literal>, then
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder the zone data is read from the standard input.
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder </para>
e8d782e6e650b71a2b0ee8461fd8d9fa31525591Christian Maeder </listitem>
0310dabcd02da51f78f84e7a73d4c7b2dd3e8507Christian Maeder </varlistentry>
c5e10ba19c9854112e5d29f491759e8e89f83652Christian Maeder
5b818f10e11fc79def1fdd5c8a080d64a6438d87Christian Maeder <varlistentry>
88c66e48620750c42b94db9feb01b42ae23dba97Till Mossakowski <term>-K <replaceable class="parameter">directory</replaceable></term>
ce8b15da31cd181b7e90593cbbca98f47eda29d6Till Mossakowski <listitem>
96ef2e46d048c357927f2795a40e9e66f21b85fbSonja Gröning <para>
8659594bb40eb5f3da5439692f0908300947191eSonja Gröning Sets the directory in which the key files are to reside.
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder </para>
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder </listitem>
96ef2e46d048c357927f2795a40e9e66f21b85fbSonja Gröning </varlistentry>
96ef2e46d048c357927f2795a40e9e66f21b85fbSonja Gröning
96ef2e46d048c357927f2795a40e9e66f21b85fbSonja Gröning <varlistentry>
7d09621f989f5e6dfbf603b36b2fccbacf639a3cTill Mossakowski <term>-L <replaceable class="parameter">ttl</replaceable></term>
eeb419aa20c97b4af973e97ee6ae77a8eed29e15Till Mossakowski <listitem>
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers <para>
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder Sets the default TTL to use for this key when it is converted
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers into a DNSKEY RR. If the key is imported into a zone,
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder this is the TTL that will be used for it, unless there was
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder already a DNSKEY RRset in place, in which case the existing TTL
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder would take precedence. Setting the default TTL to
7d09621f989f5e6dfbf603b36b2fccbacf639a3cTill Mossakowski <literal>0</literal> or <literal>none</literal> removes it.
ce8b15da31cd181b7e90593cbbca98f47eda29d6Till Mossakowski </para>
ce8b15da31cd181b7e90593cbbca98f47eda29d6Till Mossakowski </listitem>
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers </varlistentry>
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <varlistentry>
51e836611726885f6d2719d959ed1b51f8fd06f4Klaus Luettich <term>-h</term>
fdb2d618144159395f7bf8ce3327b3c112a17dd3Till Mossakowski <listitem>
fdb2d618144159395f7bf8ce3327b3c112a17dd3Till Mossakowski <para>
327a9b9bf44b6e33f71fee7526dc1c0035251591Christian Maeder Emit usage message and exit.
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder </para>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </listitem>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </varlistentry>
6e049108aa87dc46bcff96fae50a4625df1d9648Klaus Luettich
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <varlistentry>
6e049108aa87dc46bcff96fae50a4625df1d9648Klaus Luettich <term>-v <replaceable class="parameter">level</replaceable></term>
6e049108aa87dc46bcff96fae50a4625df1d9648Klaus Luettich <listitem>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <para>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder Sets the debugging level.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </para>
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder </listitem>
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder </varlistentry>
857992065be4ed40a72c6296b6c0aec62ab4c5b9Christian Maeder
fdb2d618144159395f7bf8ce3327b3c112a17dd3Till Mossakowski <varlistentry>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <term>-V</term>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <listitem>
8b0f493ae42bad8b94918cc0957f1af57096cda4Felix Reckers <para>
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder Prints version information.
88c800932dd7053322501ea2039d9f234be6866cKlaus Luettich </para>
ed9207cf24e96b0d6f59985822054ae28cb69b2eChristian Maeder </listitem>
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder </varlistentry>
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder </variablelist>
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder </refsection>
b10267ae0a6523b73113fc2dee9ea628266fce60Christian Maeder
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich <refsection><info><title>TIMING OPTIONS</title></info>
fa21fba9ceb1ddf7b3efd54731a12ed8750191d8Christian Maeder
fa21fba9ceb1ddf7b3efd54731a12ed8750191d8Christian Maeder <para>
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich If the argument begins with a '+' or '-', it is interpreted as
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich an offset from the present time. For convenience, if such an offset
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich then the offset is computed in years (defined as 365 24-hour days,
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich ignoring leap years), months (defined as 30 24-hour days), weeks,
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich days, hours, or minutes, respectively. Without a suffix, the offset
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich is computed in seconds. To explicitly prevent a date from being
621799f077b3a1ed0f5a35382cfad0602c255b20Klaus Luettich set, use 'none' or 'never'.
05a8b581f98b928baca6dab60cd20277659ac760Christian Maeder </para>
ed9207cf24e96b0d6f59985822054ae28cb69b2eChristian Maeder
fa21fba9ceb1ddf7b3efd54731a12ed8750191d8Christian Maeder <variablelist>
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder <varlistentry>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <term>-P <replaceable class="parameter">date/offset</replaceable></term>
b49276c9f50038e0bd499ad49f7bd6444566a834Christian Maeder <listitem>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <para>
b905126bab9454b89041f92b3c50bb9efc85e427Klaus Luettich Sets the date on which a key is to be published to the zone.
6e049108aa87dc46bcff96fae50a4625df1d9648Klaus Luettich After that date, the key will be included in the zone but will
b905126bab9454b89041f92b3c50bb9efc85e427Klaus Luettich not be used to sign it.
51e836611726885f6d2719d959ed1b51f8fd06f4Klaus Luettich </para>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </listitem>
f29371d8bd5a232c974e736b06d0d8a655d320fbKlaus Luettich </varlistentry>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <varlistentry>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <term>-P sync <replaceable class="parameter">date/offset</replaceable></term>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <listitem>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <para>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder Sets the date on which CDS and CDNSKEY records that match this
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder key are to be published to the zone.
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </para>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </listitem>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </varlistentry>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder <varlistentry>
b905126bab9454b89041f92b3c50bb9efc85e427Klaus Luettich <term>-D <replaceable class="parameter">date/offset</replaceable></term>
b905126bab9454b89041f92b3c50bb9efc85e427Klaus Luettich <listitem>
b905126bab9454b89041f92b3c50bb9efc85e427Klaus Luettich <para>
b905126bab9454b89041f92b3c50bb9efc85e427Klaus Luettich Sets the date on which the key is to be deleted. After that
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder date, the key will no longer be included in the zone. (It
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder may remain in the key repository, however.)
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </para>
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder </listitem>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder </varlistentry>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder <varlistentry>
ef67402074be14deb95e4ff564737d5593144130Klaus Luettich <term>-D sync <replaceable class="parameter">date/offset</replaceable></term>
ef67402074be14deb95e4ff564737d5593144130Klaus Luettich <listitem>
ef67402074be14deb95e4ff564737d5593144130Klaus Luettich <para>
5958fabb264ec3f5b2125ac5602121bd34814a79Klaus Luettich Sets the date on which the CDS and CDNSKEY records that match
5958fabb264ec3f5b2125ac5602121bd34814a79Klaus Luettich this key are to be deleted.
e7e1ab2ac3f1fded8611bb92ae00e8f3b8c693fbKlaus Luettich </para>
ef67402074be14deb95e4ff564737d5593144130Klaus Luettich </listitem>
1323eba62fc519b068f5aaec4f9d2be05ffabea9Klaus Luettich </varlistentry>
1323eba62fc519b068f5aaec4f9d2be05ffabea9Klaus Luettich
1323eba62fc519b068f5aaec4f9d2be05ffabea9Klaus Luettich </variablelist>
725a68ec81cba9b8aa8647bebfb5baa449803e7eKlaus Luettich </refsection>
d579f5b263e6c73d466c265f2fbfd45b0e69ca64Klaus Luettich
33d042fe6a9eb27a4c48f840b80838f3e7d98e34Christian Maeder <refsection><info><title>FILES</title></info>
5191fa24c532d1f67e7a642e9aece65efb8a0975Christian Maeder
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder <para>
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder A keyfile can be designed by the key identification
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder <filename>Knnnn.+aaa+iiiii</filename> or the full file name
438f9bd974c8e668203e636b0f2bc80c589af043Klaus Luettich <filename>Knnnn.+aaa+iiiii.key</filename> as generated by
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder <refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>.
404166b9366552e9ec5abb87a37c76ec8a815fb7Klaus Luettich </para>
404166b9366552e9ec5abb87a37c76ec8a815fb7Klaus Luettich </refsection>
4e7050bcbcf0f372a5bad32ecd0282bccabf0983Klaus Luettich
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder <refsection><info><title>SEE ALSO</title></info>
404166b9366552e9ec5abb87a37c76ec8a815fb7Klaus Luettich
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder <para><citerefentry>
404166b9366552e9ec5abb87a37c76ec8a815fb7Klaus Luettich <refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
4e7050bcbcf0f372a5bad32ecd0282bccabf0983Klaus Luettich </citerefentry>,
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder <citerefentry>
340706b6c0c6e3dbacdd7003e20e9cab7f9aa765Christian Maeder <refentrytitle>dnssec-signzone</refentrytitle><manvolnum>8</manvolnum>
e593b89bfd4952698dc37feced21cefe869d87a2Christian Maeder </citerefentry>,
340706b6c0c6e3dbacdd7003e20e9cab7f9aa765Christian Maeder <citetitle>BIND 9 Administrator Reference Manual</citetitle>,
340706b6c0c6e3dbacdd7003e20e9cab7f9aa765Christian Maeder <citetitle>RFC 5011</citetitle>.
fdb2d618144159395f7bf8ce3327b3c112a17dd3Till Mossakowski </para>
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder </refsection>
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder</refentry>
ac0bbbcb2774629bb87986e69cf53d3402c5f575Christian Maeder