dnssec-keyfromlabel.html revision 5a24d24c8fba3480d707c0c902379ddb36501e12
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - Copyright (C) 2008, 2009 Internet Systems Consortium, Inc. ("ISC")
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - Permission to use, copy, modify, and/or distribute this software for any
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - purpose with or without fee is hereby granted, provided that the above
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - copyright notice and this permission notice appear in all copies.
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync - PERFORMANCE OF THIS SOFTWARE.
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync<!-- $Id: dnssec-keyfromlabel.html,v 1.13 2009/10/17 01:14:35 tbox Exp $ -->
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync<a name="man.dnssec-keyfromlabel"></a><div class="titlepage"></div>
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync<p><span class="application">dnssec-keyfromlabel</span> — DNSSEC key generation tool</p>
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync<div class="cmdsynopsis"><p><code class="command">dnssec-keyfromlabel</code> {-l <em class="replaceable"><code>label</code></em>} [<code class="option">-3</code>] [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-k</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] {name}</p></div>
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync<p><span><strong class="command">dnssec-keyfromlabel</strong></span>
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync gets keys with the given label from a crypto hardware and builds
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync key files for DNSSEC (Secure DNS), as defined in RFC 2535
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync and RFC 4034.
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync The <code class="option">name</code> of the key is specified on the command
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync line. This must match the name of the zone for which the key is
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync being generated.
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync Selects the cryptographic algorithm. The value of
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync <code class="option">algorithm</code> must be one of RSAMD5 (RSA),
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA or DH (Diffie Hellman).
b1ae8b1c40ec6bb82e7984b72712df5661332e2cvboxsync These values are case insensitive.