dnssec-keygen.docbook revision 5cd4555ad444fd391002ae32450572054369fd42
df8bdeb362277e8d95a74d6c097341fe97409948johnz<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
df8bdeb362277e8d95a74d6c097341fe97409948johnz "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
df8bdeb362277e8d95a74d6c097341fe97409948johnz [<!ENTITY mdash "&#8212;">]>
df8bdeb362277e8d95a74d6c097341fe97409948johnz<!--
df8bdeb362277e8d95a74d6c097341fe97409948johnz - Copyright (C) 2004, 2005 Internet Systems Consortium, Inc. ("ISC")
df8bdeb362277e8d95a74d6c097341fe97409948johnz - Copyright (C) 2000-2003 Internet Software Consortium.
df8bdeb362277e8d95a74d6c097341fe97409948johnz -
df8bdeb362277e8d95a74d6c097341fe97409948johnz - Permission to use, copy, modify, and distribute this software for any
df8bdeb362277e8d95a74d6c097341fe97409948johnz - purpose with or without fee is hereby granted, provided that the above
df8bdeb362277e8d95a74d6c097341fe97409948johnz - copyright notice and this permission notice appear in all copies.
df8bdeb362277e8d95a74d6c097341fe97409948johnz -
df8bdeb362277e8d95a74d6c097341fe97409948johnz - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
df8bdeb362277e8d95a74d6c097341fe97409948johnz - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
df8bdeb362277e8d95a74d6c097341fe97409948johnz - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
df8bdeb362277e8d95a74d6c097341fe97409948johnz - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
df8bdeb362277e8d95a74d6c097341fe97409948johnz - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
df8bdeb362277e8d95a74d6c097341fe97409948johnz - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
df8bdeb362277e8d95a74d6c097341fe97409948johnz - PERFORMANCE OF THIS SOFTWARE.
df8bdeb362277e8d95a74d6c097341fe97409948johnz-->
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz<!-- $Id: dnssec-keygen.docbook,v 1.15 2007/01/29 22:16:02 sra Exp $ -->
df8bdeb362277e8d95a74d6c097341fe97409948johnz<refentry id="man.dnssec-keygen">
9b009fc1b553084f6003dcd46b171890049de0ffValerie Bubb Fenwick <refentryinfo>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <date>June 30, 2000</date>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </refentryinfo>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refmeta>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refentrytitle><application>dnssec-keygen</application></refentrytitle>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <manvolnum>8</manvolnum>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refmiscinfo>BIND9</refmiscinfo>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </refmeta>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refnamediv>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refname><application>dnssec-keygen</application></refname>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refpurpose>DNSSEC key generation tool</refpurpose>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </refnamediv>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <docinfo>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <copyright>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <year>2004</year>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <year>2005</year>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </copyright>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <copyright>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <year>2000</year>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <year>2001</year>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <year>2002</year>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <year>2003</year>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <holder>Internet Software Consortium.</holder>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </copyright>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </docinfo>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refsynopsisdiv>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <cmdsynopsis>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <command>dnssec-keygen</command>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg choice="req">-a <replaceable class="parameter">algorithm</replaceable></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg choice="req">-b <replaceable class="parameter">keysize</replaceable></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg choice="req">-n <replaceable class="parameter">nametype</replaceable></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-c <replaceable class="parameter">class</replaceable></option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-e</option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-f <replaceable class="parameter">flag</replaceable></option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-g <replaceable class="parameter">generator</replaceable></option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-h</option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-k</option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-p <replaceable class="parameter">protocol</replaceable></option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-s <replaceable class="parameter">strength</replaceable></option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-t <replaceable class="parameter">type</replaceable></option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg><option>-v <replaceable class="parameter">level</replaceable></option></arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <arg choice="req">name</arg>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </cmdsynopsis>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </refsynopsisdiv>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <title>DESCRIPTION</title>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para><command>dnssec-keygen</command>
df8bdeb362277e8d95a74d6c097341fe97409948johnz generates keys for DNSSEC (Secure DNS), as defined in RFC 2535
df8bdeb362277e8d95a74d6c097341fe97409948johnz and RFC &lt;TBA\&gt;. It can also generate keys for use with
df8bdeb362277e8d95a74d6c097341fe97409948johnz TSIG (Transaction Signatures), as defined in RFC 2845.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <title>OPTIONS</title>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <variablelist>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-a <replaceable class="parameter">algorithm</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Selects the cryptographic algorithm. The value of
df8bdeb362277e8d95a74d6c097341fe97409948johnz <option>algorithm</option> must be one of RSAMD5 (RSA) or RSASHA1,
df8bdeb362277e8d95a74d6c097341fe97409948johnz DSA, DH (Diffie Hellman), or HMAC-MD5. These values
df8bdeb362277e8d95a74d6c097341fe97409948johnz are case insensitive.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
df8bdeb362277e8d95a74d6c097341fe97409948johnz algorithm,
df8bdeb362277e8d95a74d6c097341fe97409948johnz and DSA is recommended. For TSIG, HMAC-MD5 is mandatory.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Note 2: HMAC-MD5 and DH automatically set the -k flag.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-b <replaceable class="parameter">keysize</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Specifies the number of bits in the key. The choice of key
df8bdeb362277e8d95a74d6c097341fe97409948johnz size depends on the algorithm used. RSAMD5 / RSASHA1 keys must be
df8bdeb362277e8d95a74d6c097341fe97409948johnz between
df8bdeb362277e8d95a74d6c097341fe97409948johnz 512 and 2048 bits. Diffie Hellman keys must be between
df8bdeb362277e8d95a74d6c097341fe97409948johnz 128 and 4096 bits. DSA keys must be between 512 and 1024
df8bdeb362277e8d95a74d6c097341fe97409948johnz bits and an exact multiple of 64. HMAC-MD5 keys must be
df8bdeb362277e8d95a74d6c097341fe97409948johnz between 1 and 512 bits.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-n <replaceable class="parameter">nametype</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Specifies the owner type of the key. The value of
df8bdeb362277e8d95a74d6c097341fe97409948johnz <option>nametype</option> must either be ZONE (for a DNSSEC
df8bdeb362277e8d95a74d6c097341fe97409948johnz zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
df8bdeb362277e8d95a74d6c097341fe97409948johnz a host (KEY)),
df8bdeb362277e8d95a74d6c097341fe97409948johnz USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
df8bdeb362277e8d95a74d6c097341fe97409948johnz These values are
df8bdeb362277e8d95a74d6c097341fe97409948johnz case insensitive.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-c <replaceable class="parameter">class</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Indicates that the DNS record containing the key should have
df8bdeb362277e8d95a74d6c097341fe97409948johnz the specified class. If not specified, class IN is used.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-e</term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz If generating an RSAMD5/RSASHA1 key, use a large exponent.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-f <replaceable class="parameter">flag</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Set the specified flag in the flag field of the KEY/DNSKEY record.
df8bdeb362277e8d95a74d6c097341fe97409948johnz The only recognized flag is KSK (Key Signing Key) DNSKEY.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-g <replaceable class="parameter">generator</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz If generating a Diffie Hellman key, use this generator.
df8bdeb362277e8d95a74d6c097341fe97409948johnz Allowed values are 2 and 5. If no generator
df8bdeb362277e8d95a74d6c097341fe97409948johnz is specified, a known prime from RFC 2539 will be used
df8bdeb362277e8d95a74d6c097341fe97409948johnz if possible; otherwise the default is 2.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-h</term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Prints a short summary of the options and arguments to
df8bdeb362277e8d95a74d6c097341fe97409948johnz <command>dnssec-keygen</command>.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-k</term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Generate KEY records rather than DNSKEY records.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-p <replaceable class="parameter">protocol</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Sets the protocol value for the generated key. The protocol
df8bdeb362277e8d95a74d6c097341fe97409948johnz is a number between 0 and 255. The default is 3 (DNSSEC).
df8bdeb362277e8d95a74d6c097341fe97409948johnz Other possible values for this argument are listed in
df8bdeb362277e8d95a74d6c097341fe97409948johnz RFC 2535 and its successors.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-r <replaceable class="parameter">randomdev</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Specifies the source of randomness. If the operating
df8bdeb362277e8d95a74d6c097341fe97409948johnz system does not provide a <filename>/dev/random</filename>
df8bdeb362277e8d95a74d6c097341fe97409948johnz or equivalent device, the default source of randomness
df8bdeb362277e8d95a74d6c097341fe97409948johnz is keyboard input. <filename>randomdev</filename>
df8bdeb362277e8d95a74d6c097341fe97409948johnz specifies
df8bdeb362277e8d95a74d6c097341fe97409948johnz the name of a character device or file containing random
df8bdeb362277e8d95a74d6c097341fe97409948johnz data to be used instead of the default. The special value
df8bdeb362277e8d95a74d6c097341fe97409948johnz <filename>keyboard</filename> indicates that keyboard
df8bdeb362277e8d95a74d6c097341fe97409948johnz input should be used.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-s <replaceable class="parameter">strength</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Specifies the strength value of the key. The strength is
df8bdeb362277e8d95a74d6c097341fe97409948johnz a number between 0 and 15, and currently has no defined
df8bdeb362277e8d95a74d6c097341fe97409948johnz purpose in DNSSEC.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-t <replaceable class="parameter">type</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Indicates the use of the key. <option>type</option> must be
df8bdeb362277e8d95a74d6c097341fe97409948johnz one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
df8bdeb362277e8d95a74d6c097341fe97409948johnz is AUTHCONF. AUTH refers to the ability to authenticate
df8bdeb362277e8d95a74d6c097341fe97409948johnz data, and CONF the ability to encrypt data.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <term>-v <replaceable class="parameter">level</replaceable></term>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Sets the debugging level.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
735564919188238196dbd0d320770dda59b38369Anthony Scarpino </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </varlistentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz </variablelist>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <title>GENERATED KEYS</title>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz When <command>dnssec-keygen</command> completes
df8bdeb362277e8d95a74d6c097341fe97409948johnz successfully,
df8bdeb362277e8d95a74d6c097341fe97409948johnz it prints a string of the form <filename>Knnnn.+aaa+iiiii</filename>
df8bdeb362277e8d95a74d6c097341fe97409948johnz to the standard output. This is an identification string for
df8bdeb362277e8d95a74d6c097341fe97409948johnz the key it has generated.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <itemizedlist>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para><filename>nnnn</filename> is the key name.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para><filename>aaa</filename> is the numeric representation
df8bdeb362277e8d95a74d6c097341fe97409948johnz of the
df8bdeb362277e8d95a74d6c097341fe97409948johnz algorithm.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para><filename>iiiii</filename> is the key identifier (or
df8bdeb362277e8d95a74d6c097341fe97409948johnz footprint).
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </listitem>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </itemizedlist>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para><command>dnssec-keygen</command>
df8bdeb362277e8d95a74d6c097341fe97409948johnz creates two file, with names based
df8bdeb362277e8d95a74d6c097341fe97409948johnz on the printed string. <filename>Knnnn.+aaa+iiiii.key</filename>
df8bdeb362277e8d95a74d6c097341fe97409948johnz contains the public key, and
df8bdeb362277e8d95a74d6c097341fe97409948johnz <filename>Knnnn.+aaa+iiiii.private</filename> contains the
df8bdeb362277e8d95a74d6c097341fe97409948johnz private
df8bdeb362277e8d95a74d6c097341fe97409948johnz key.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz The <filename>.key</filename> file contains a DNS KEY record
df8bdeb362277e8d95a74d6c097341fe97409948johnz that
df8bdeb362277e8d95a74d6c097341fe97409948johnz can be inserted into a zone file (directly or with a $INCLUDE
df8bdeb362277e8d95a74d6c097341fe97409948johnz statement).
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz The <filename>.private</filename> file contains algorithm
df8bdeb362277e8d95a74d6c097341fe97409948johnz specific
df8bdeb362277e8d95a74d6c097341fe97409948johnz fields. For obvious security reasons, this file does not have
df8bdeb362277e8d95a74d6c097341fe97409948johnz general read permission.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz Both <filename>.key</filename> and <filename>.private</filename>
df8bdeb362277e8d95a74d6c097341fe97409948johnz files are generated for symmetric encryption algorithm such as
df8bdeb362277e8d95a74d6c097341fe97409948johnz HMAC-MD5, even though the public and private key are equivalent.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <title>EXAMPLE</title>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz To generate a 768-bit DSA key for the domain
df8bdeb362277e8d95a74d6c097341fe97409948johnz <userinput>example.com</userinput>, the following command would be
df8bdeb362277e8d95a74d6c097341fe97409948johnz issued:
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para><userinput>dnssec-keygen -a DSA -b 768 -n ZONE example.com</userinput>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz The command would print a string of the form:
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para><userinput>Kexample.com.+003+26160</userinput>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz In this example, <command>dnssec-keygen</command> creates
df8bdeb362277e8d95a74d6c097341fe97409948johnz the files <filename>Kexample.com.+003+26160.key</filename>
df8bdeb362277e8d95a74d6c097341fe97409948johnz and
df8bdeb362277e8d95a74d6c097341fe97409948johnz <filename>Kexample.com.+003+26160.private</filename>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <title>SEE ALSO</title>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para><citerefentry>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refentrytitle>dnssec-signzone</refentrytitle><manvolnum>8</manvolnum>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </citerefentry>,
df8bdeb362277e8d95a74d6c097341fe97409948johnz <citetitle>BIND 9 Administrator Reference Manual</citetitle>,
df8bdeb362277e8d95a74d6c097341fe97409948johnz <citetitle>RFC 2535</citetitle>,
df8bdeb362277e8d95a74d6c097341fe97409948johnz <citetitle>RFC 2845</citetitle>,
df8bdeb362277e8d95a74d6c097341fe97409948johnz <citetitle>RFC 2539</citetitle>.
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
df8bdeb362277e8d95a74d6c097341fe97409948johnz <refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <title>AUTHOR</title>
df8bdeb362277e8d95a74d6c097341fe97409948johnz <para><corpauthor>Internet Systems Consortium</corpauthor>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </para>
df8bdeb362277e8d95a74d6c097341fe97409948johnz </refsect1>
df8bdeb362277e8d95a74d6c097341fe97409948johnz
5c0175258354931b92aa8f3c302005abc001f1f9Ali Bahrami</refentry><!--
df8bdeb362277e8d95a74d6c097341fe97409948johnz - Local variables:
df8bdeb362277e8d95a74d6c097341fe97409948johnz - mode: sgml
df8bdeb362277e8d95a74d6c097341fe97409948johnz - End:
df8bdeb362277e8d95a74d6c097341fe97409948johnz-->
df8bdeb362277e8d95a74d6c097341fe97409948johnz