dnssec-keyfromlabel.docbook revision e939674d53a127ddeeaf4b41fd72933f0b493308
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - Copyright (C) 2008-2012, 2014, 2015 Internet Systems Consortium, Inc. ("ISC")
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - Permission to use, copy, modify, and/or distribute this software for any
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - purpose with or without fee is hereby granted, provided that the above
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - copyright notice and this permission notice appear in all copies.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews - PERFORMANCE OF THIS SOFTWARE.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews<!-- Converted by db4-upgrade version 1.0 -->
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews<refentry xmlns="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dnssec-keyfromlabel">
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <refentryinfo>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <corpauthor>Internet Systems Consortium, Inc.</corpauthor>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews </refentryinfo>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <refentrytitle><application>dnssec-keyfromlabel</application></refentrytitle>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <refnamediv>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <refname><application>dnssec-keyfromlabel</application></refname>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <refpurpose>DNSSEC key generation tool</refpurpose>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews </refnamediv>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews </copyright>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <refsynopsisdiv>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="req" rep="norepeat">-l <replaceable class="parameter">label</replaceable></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-3</option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-a <replaceable class="parameter">algorithm</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-A <replaceable class="parameter">date/offset</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-c <replaceable class="parameter">class</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">date/offset</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-D sync <replaceable class="parameter">date/offset</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">flag</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-G</option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-I <replaceable class="parameter">date/offset</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-k</option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">ttl</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-n <replaceable class="parameter">nametype</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-P sync <replaceable class="parameter">date/offset</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-p <replaceable class="parameter">protocol</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-R <replaceable class="parameter">date/offset</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-S <replaceable class="parameter">key</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-t <replaceable class="parameter">type</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-V</option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <arg choice="opt" rep="norepeat"><option>-y</option></arg>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews </cmdsynopsis>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews </refsynopsisdiv>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <refsection><info><title>DESCRIPTION</title></info>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews generates a key pair of files that referencing a key object stored
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews in a cryptographic hardware service module (HSM). The private key
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews file can be used for DNSSEC signing of zone data as if it were a
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews conventional signing key created by <command>dnssec-keygen</command>,
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews but the key material is stored within the HSM, and the actual signing
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews takes place there.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews The <option>name</option> of the key is specified on the command
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews line. This must match the name of the zone for which the key is
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews being generated.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews </refsection>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <refsection><info><title>OPTIONS</title></info>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <variablelist>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <varlistentry>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <term>-a <replaceable class="parameter">algorithm</replaceable></term>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews Selects the cryptographic algorithm. The value of
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <option>algorithm</option> must be one of RSAMD5, RSASHA1,
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews ECDSAP256SHA256 or ECDSAP384SHA384.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews These values are case insensitive.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews If no algorithm is specified, then RSASHA1 will be used by
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews default, unless the <option>-3</option> option is specified,
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews in which case NSEC3RSASHA1 will be used instead. (If
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <option>-3</option> is used and an algorithm is specified,
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews that algorithm will be checked for compatibility with NSEC3.)
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews algorithm, and DSA is recommended.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews Note 2: DH automatically sets the -k flag.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews </varlistentry>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <varlistentry>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews Use an NSEC3-capable algorithm to generate a DNSSEC key.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews If this option is used and no algorithm is explicitly
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews set on the command line, NSEC3RSASHA1 will be used by
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews </varlistentry>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <varlistentry>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <term>-E <replaceable class="parameter">engine</replaceable></term>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews Specifies the cryptographic hardware to use.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews When BIND is built with OpenSSL PKCS#11 support, this defaults
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews to the string "pkcs11", which identifies an OpenSSL engine
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews that can drive a cryptographic accelerator or hardware service
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews module. When BIND is built with native PKCS#11 cryptography
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews (--enable-native-pkcs11), it defaults to the path of the PKCS#11
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews provider library specified via "--with-pkcs11".
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews </varlistentry>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <varlistentry>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <term>-l <replaceable class="parameter">label</replaceable></term>
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews Specifies the label for a key pair in the crypto hardware.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews When <acronym>BIND</acronym> 9 is built with OpenSSL-based
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews PKCS#11 support, the label is an arbitrary string that
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews identifies a particular key. It may be preceded by an
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews optional OpenSSL engine name, followed by a colon, as in
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews When <acronym>BIND</acronym> 9 is built with native PKCS#11
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews support, the label is a PKCS#11 URI string in the format
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews "pkcs11:<option>keyword</option>=<replaceable>value</replaceable><optional>;<option>keyword</option>=<replaceable>value</replaceable>;...</optional>"
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews Keywords include "token", which identifies the HSM; "object", which
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews identifies the key; and "pin-source", which identifies a file from
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews which the HSM's PIN code can be obtained. The label will be
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews stored in the on-disk "private" file.
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews If the label contains a
0c91911b4d1e872b87eaf6431ed47fe24d18dd43Mark Andrews <option>pin-source</option> field, tools using the generated