dnssec-settime.docbook revision 6f25333e7386515562b30bb8651d066781249351
d5b7ba26785d7494166d48876362ba30ff30b98awrowe<!--
c30ef289fe64ac7fedc44cfcc6b439f0f8458b4cgregames - Copyright (C) 2009-2011, 2014-2017 Internet Systems Consortium, Inc. ("ISC")
c30ef289fe64ac7fedc44cfcc6b439f0f8458b4cgregames -
14763a0db22322626dd8cd59dfbc3a4fcc655d99trawick - This Source Code Form is subject to the terms of the Mozilla Public
263702cf74538e1c6d31b58baae20ac168a45712minfrin - License, v. 2.0. If a copy of the MPL was not distributed with this
263702cf74538e1c6d31b58baae20ac168a45712minfrin - file, You can obtain one at http://mozilla.org/MPL/2.0/.
263702cf74538e1c6d31b58baae20ac168a45712minfrin-->
98e28ee4e3e3972abeb1bfd509c0e79c54c871f6nd
98e28ee4e3e3972abeb1bfd509c0e79c54c871f6nd<!-- Converted by db4-upgrade version 1.0 -->
98e28ee4e3e3972abeb1bfd509c0e79c54c871f6nd<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dnssec-settime">
50e23f7dca0da305e324349792fb7c27d8e04b60minfrin <info>
50e23f7dca0da305e324349792fb7c27d8e04b60minfrin <date>2015-08-21</date>
50e23f7dca0da305e324349792fb7c27d8e04b60minfrin </info>
50e23f7dca0da305e324349792fb7c27d8e04b60minfrin <refentryinfo>
50e23f7dca0da305e324349792fb7c27d8e04b60minfrin <corpname>ISC</corpname>
217f75ac21f879b5d71892790e536cd80184db8dminfrin <corpauthor>Internet Systems Consortium, Inc.</corpauthor>
217f75ac21f879b5d71892790e536cd80184db8dminfrin </refentryinfo>
217f75ac21f879b5d71892790e536cd80184db8dminfrin
217f75ac21f879b5d71892790e536cd80184db8dminfrin <refmeta>
08df8c976ef7d6c1362cba072cadf0e1e6c91975trawick <refentrytitle><application>dnssec-settime</application></refentrytitle>
08df8c976ef7d6c1362cba072cadf0e1e6c91975trawick <manvolnum>8</manvolnum>
c1ba3b0ac00c4fee2f4b950dfdb167b39611b661nd <refmiscinfo>BIND9</refmiscinfo>
c1ba3b0ac00c4fee2f4b950dfdb167b39611b661nd </refmeta>
c1ba3b0ac00c4fee2f4b950dfdb167b39611b661nd
63267f5839a0a485948dd38ba607427d51a169e3madhum <refnamediv>
63267f5839a0a485948dd38ba607427d51a169e3madhum <refname><application>dnssec-settime</application></refname>
63267f5839a0a485948dd38ba607427d51a169e3madhum <refpurpose>set the key timing metadata for a DNSSEC key</refpurpose>
63267f5839a0a485948dd38ba607427d51a169e3madhum </refnamediv>
b95a84193578c904426cef6dda84f7118a400a16jim
b95a84193578c904426cef6dda84f7118a400a16jim <docinfo>
b95a84193578c904426cef6dda84f7118a400a16jim <copyright>
b95a84193578c904426cef6dda84f7118a400a16jim <year>2009</year>
cdd8290ae4505c17de6aff3acd1b9bd48d2c84e0ake <year>2010</year>
cdd8290ae4505c17de6aff3acd1b9bd48d2c84e0ake <year>2011</year>
03a3ed87983471816561562f957390ed935d7b3bnd <year>2014</year>
03a3ed87983471816561562f957390ed935d7b3bnd <year>2015</year>
03a3ed87983471816561562f957390ed935d7b3bnd <year>2016</year>
03a3ed87983471816561562f957390ed935d7b3bnd <year>2017</year>
c533ecac2227dc228070e686fb14dc6860f497f8nd <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
da5472c259c9dad08fd805c3e97a629f9428e7fend </copyright>
da5472c259c9dad08fd805c3e97a629f9428e7fend </docinfo>
da5472c259c9dad08fd805c3e97a629f9428e7fend
33c6c050363f8b571cec0477008390a95b41523and <refsynopsisdiv>
33c6c050363f8b571cec0477008390a95b41523and <cmdsynopsis sepchar=" ">
33c6c050363f8b571cec0477008390a95b41523and <command>dnssec-settime</command>
68ed4d659ab8f6deb93fe6d520b5d3ee65645493nd <arg choice="opt" rep="norepeat"><option>-f</option></arg>
68ed4d659ab8f6deb93fe6d520b5d3ee65645493nd <arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
68ed4d659ab8f6deb93fe6d520b5d3ee65645493nd <arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">ttl</replaceable></option></arg>
68ed4d659ab8f6deb93fe6d520b5d3ee65645493nd <arg choice="opt" rep="norepeat"><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
2bfe4d90e1d374e14fd5db16a799e6f5e0944748nd <arg choice="opt" rep="norepeat"><option>-P sync <replaceable class="parameter">date/offset</replaceable></option></arg>
2bfe4d90e1d374e14fd5db16a799e6f5e0944748nd <arg choice="opt" rep="norepeat"><option>-A <replaceable class="parameter">date/offset</replaceable></option></arg>
2bfe4d90e1d374e14fd5db16a799e6f5e0944748nd <arg choice="opt" rep="norepeat"><option>-R <replaceable class="parameter">date/offset</replaceable></option></arg>
2bfe4d90e1d374e14fd5db16a799e6f5e0944748nd <arg choice="opt" rep="norepeat"><option>-I <replaceable class="parameter">date/offset</replaceable></option></arg>
2bfe4d90e1d374e14fd5db16a799e6f5e0944748nd <arg choice="opt" rep="norepeat"><option>-D <replaceable class="parameter">date/offset</replaceable></option></arg>
2bfe4d90e1d374e14fd5db16a799e6f5e0944748nd <arg choice="opt" rep="norepeat"><option>-D sync <replaceable class="parameter">date/offset</replaceable></option></arg>
97789c9dcc4cc724c9b80fb9b428d128c58e3e0and <arg choice="opt" rep="norepeat"><option>-S <replaceable class="parameter">key</replaceable></option></arg>
97789c9dcc4cc724c9b80fb9b428d128c58e3e0and <arg choice="opt" rep="norepeat"><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
97789c9dcc4cc724c9b80fb9b428d128c58e3e0and <arg choice="opt" rep="norepeat"><option>-h</option></arg>
97789c9dcc4cc724c9b80fb9b428d128c58e3e0and <arg choice="opt" rep="norepeat"><option>-V</option></arg>
97789c9dcc4cc724c9b80fb9b428d128c58e3e0and <arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
56cefde0af6b8db6fda0f1d95d8cdca54f397cd0nd <arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
56cefde0af6b8db6fda0f1d95d8cdca54f397cd0nd <arg choice="req" rep="norepeat">keyfile</arg>
56cefde0af6b8db6fda0f1d95d8cdca54f397cd0nd </cmdsynopsis>
41369ed0bc7f2db6272278c27025f6aabf97fe63nd </refsynopsisdiv>
41369ed0bc7f2db6272278c27025f6aabf97fe63nd
41369ed0bc7f2db6272278c27025f6aabf97fe63nd <refsection><info><title>DESCRIPTION</title></info>
496f8f3966319d43455675630a849bae019d2a32nd
496f8f3966319d43455675630a849bae019d2a32nd <para><command>dnssec-settime</command>
13ed2a88decd6dbe13b11467e7f648f2996b7a70jorton reads a DNSSEC private key file and sets the key timing metadata
13ed2a88decd6dbe13b11467e7f648f2996b7a70jorton as specified by the <option>-P</option>, <option>-A</option>,
13ed2a88decd6dbe13b11467e7f648f2996b7a70jorton <option>-R</option>, <option>-I</option>, and <option>-D</option>
13ed2a88decd6dbe13b11467e7f648f2996b7a70jorton options. The metadata can then be used by
9e8c2603790f490398a0fabf97866b6815748a54ianh <command>dnssec-signzone</command> or other signing software to
9e8c2603790f490398a0fabf97866b6815748a54ianh determine when a key is to be published, whether it should be
9e8c2603790f490398a0fabf97866b6815748a54ianh used for signing a zone, etc.
9e8c2603790f490398a0fabf97866b6815748a54ianh </para>
a21b3b9d8ebb12fd51fa1d17e44d5644a35a9a5fnd <para>
a21b3b9d8ebb12fd51fa1d17e44d5644a35a9a5fnd If none of these options is set on the command line,
a21b3b9d8ebb12fd51fa1d17e44d5644a35a9a5fnd then <command>dnssec-settime</command> simply prints the key timing
5fcef4390e6414ad7754c2f004974982bc33cac2nd metadata already stored in the key.
5fcef4390e6414ad7754c2f004974982bc33cac2nd </para>
5fcef4390e6414ad7754c2f004974982bc33cac2nd <para>
5fcef4390e6414ad7754c2f004974982bc33cac2nd When key metadata fields are changed, both files of a key
46820eca7dc57ae17c235389a0cd39140a5db8b5nd pair (<filename>Knnnn.+aaa+iiiii.key</filename> and
46820eca7dc57ae17c235389a0cd39140a5db8b5nd <filename>Knnnn.+aaa+iiiii.private</filename>) are regenerated.
46820eca7dc57ae17c235389a0cd39140a5db8b5nd Metadata fields are stored in the private file. A human-readable
46820eca7dc57ae17c235389a0cd39140a5db8b5nd description of the metadata is also placed in comments in the key
1fbcf7a8e7b18be1b0e77b7bc38b7b71f8dfb052nd file. The private file's permissions are always set to be
1fbcf7a8e7b18be1b0e77b7bc38b7b71f8dfb052nd inaccessible to anyone other than the owner (mode 0600).
1fbcf7a8e7b18be1b0e77b7bc38b7b71f8dfb052nd </para>
e6c244ee56578707b20a86e0e938498299a93b6cnd </refsection>
e6c244ee56578707b20a86e0e938498299a93b6cnd
e6c244ee56578707b20a86e0e938498299a93b6cnd <refsection><info><title>OPTIONS</title></info>
e6c244ee56578707b20a86e0e938498299a93b6cnd
56d70402724e1872992bcac08b802681cf762d9and
56d70402724e1872992bcac08b802681cf762d9and <variablelist>
56d70402724e1872992bcac08b802681cf762d9and <varlistentry>
bfbca4e24db7fef55c0ab787aca9f89594530b45geoff <term>-f</term>
bfbca4e24db7fef55c0ab787aca9f89594530b45geoff <listitem>
bfbca4e24db7fef55c0ab787aca9f89594530b45geoff <para>
bfbca4e24db7fef55c0ab787aca9f89594530b45geoff Force an update of an old-format key with no metadata fields.
f769c33501f474aed3e0f7c769477c8c4f478783geoff Without this option, <command>dnssec-settime</command> will
f769c33501f474aed3e0f7c769477c8c4f478783geoff fail when attempting to update a legacy key. With this option,
f769c33501f474aed3e0f7c769477c8c4f478783geoff the key will be recreated in the new format, but with the
f769c33501f474aed3e0f7c769477c8c4f478783geoff original key data retained. The key's creation date will be
89ea31761658f422cf21cd3b0224dc5fe95cccd3nd set to the present time. If no other values are specified,
89ea31761658f422cf21cd3b0224dc5fe95cccd3nd then the key's publication and activation dates will also
89ea31761658f422cf21cd3b0224dc5fe95cccd3nd be set to the present time.
67a4d05bab3fc19c1b87fb9042977975bf27cdbdnd </para>
67a4d05bab3fc19c1b87fb9042977975bf27cdbdnd </listitem>
67a4d05bab3fc19c1b87fb9042977975bf27cdbdnd </varlistentry>
210817da3118a900388980e4481e4aec6a58f101nd
210817da3118a900388980e4481e4aec6a58f101nd <varlistentry>
210817da3118a900388980e4481e4aec6a58f101nd <term>-K <replaceable class="parameter">directory</replaceable></term>
46c99ed700a996f84dee6b1fe42d22ce9f27b5a0nd <listitem>
46c99ed700a996f84dee6b1fe42d22ce9f27b5a0nd <para>
46c99ed700a996f84dee6b1fe42d22ce9f27b5a0nd Sets the directory in which the key files are to reside.
d7c7669331357296719d67d1963d40d713ed455atrawick </para>
d7c7669331357296719d67d1963d40d713ed455atrawick </listitem>
d7c7669331357296719d67d1963d40d713ed455atrawick </varlistentry>
d7c7669331357296719d67d1963d40d713ed455atrawick
781888a651637edc0b043a6787cb0c2acf30a187geoff <varlistentry>
781888a651637edc0b043a6787cb0c2acf30a187geoff <term>-L <replaceable class="parameter">ttl</replaceable></term>
781888a651637edc0b043a6787cb0c2acf30a187geoff <listitem>
781888a651637edc0b043a6787cb0c2acf30a187geoff <para>
5d3e5520c34648220ed0cd9dc01c2c203257c86fnd Sets the default TTL to use for this key when it is converted
5d3e5520c34648220ed0cd9dc01c2c203257c86fnd into a DNSKEY RR. If the key is imported into a zone,
5d3e5520c34648220ed0cd9dc01c2c203257c86fnd this is the TTL that will be used for it, unless there was
92d95be777d4365eb79444a7a558355a7a92081ajorton already a DNSKEY RRset in place, in which case the existing TTL
92d95be777d4365eb79444a7a558355a7a92081ajorton would take precedence. If this value is not set and there
92d95be777d4365eb79444a7a558355a7a92081ajorton is no existing DNSKEY RRset, the TTL will default to the
92d95be777d4365eb79444a7a558355a7a92081ajorton SOA TTL. Setting the default TTL to <literal>0</literal>
af8dee354a287249dd9f3f77bbe850108e5afe43trawick or <literal>none</literal> removes it from the key.
af8dee354a287249dd9f3f77bbe850108e5afe43trawick </para>
af8dee354a287249dd9f3f77bbe850108e5afe43trawick </listitem>
af8dee354a287249dd9f3f77bbe850108e5afe43trawick </varlistentry>
af8dee354a287249dd9f3f77bbe850108e5afe43trawick
14763a0db22322626dd8cd59dfbc3a4fcc655d99trawick <varlistentry>
fb82af0f0cd7b58eef19c54b086131b7e1e1e749madhum <term>-h</term>
fb82af0f0cd7b58eef19c54b086131b7e1e1e749madhum <listitem>
fb82af0f0cd7b58eef19c54b086131b7e1e1e749madhum <para>
bcccfc984c481af611fa4ffc3e2732400b041cfend Emit usage message and exit.
bcccfc984c481af611fa4ffc3e2732400b041cfend </para>
bcccfc984c481af611fa4ffc3e2732400b041cfend </listitem>
f78505c7d260473bf11002f5028186f27d0ed8a0geoff </varlistentry>
f78505c7d260473bf11002f5028186f27d0ed8a0geoff
f78505c7d260473bf11002f5028186f27d0ed8a0geoff <varlistentry>
f78505c7d260473bf11002f5028186f27d0ed8a0geoff <term>-V</term>
f78505c7d260473bf11002f5028186f27d0ed8a0geoff <listitem>
f78505c7d260473bf11002f5028186f27d0ed8a0geoff <para>
a8a509c9b67eea07a4a239e7f36c9f3de6022585trawick Prints version information.
a8a509c9b67eea07a4a239e7f36c9f3de6022585trawick </para>
a8a509c9b67eea07a4a239e7f36c9f3de6022585trawick </listitem>
ea981941b1e5ecfb1a27b9e9aff32b9c98640ed9nd </varlistentry>
ea981941b1e5ecfb1a27b9e9aff32b9c98640ed9nd
ea981941b1e5ecfb1a27b9e9aff32b9c98640ed9nd <varlistentry>
ea981941b1e5ecfb1a27b9e9aff32b9c98640ed9nd <term>-v <replaceable class="parameter">level</replaceable></term>
ced699ca391a4fb7d70cfeb995c58d4bf62f00a8trawick <listitem>
ced699ca391a4fb7d70cfeb995c58d4bf62f00a8trawick <para>
ced699ca391a4fb7d70cfeb995c58d4bf62f00a8trawick Sets the debugging level.
d57b793ddd42a997c2cb3bd389bbcf1161226fd8trawick </para>
d57b793ddd42a997c2cb3bd389bbcf1161226fd8trawick </listitem>
d57b793ddd42a997c2cb3bd389bbcf1161226fd8trawick </varlistentry>
f881e72fe4f91fd1445c5d81c95f66d6a4a3ee5btrawick
f881e72fe4f91fd1445c5d81c95f66d6a4a3ee5btrawick <varlistentry>
f881e72fe4f91fd1445c5d81c95f66d6a4a3ee5btrawick <term>-E <replaceable class="parameter">engine</replaceable></term>
d11bf78168abbb07d8ed9f54d7ea0953d46aad83nd <listitem>
d11bf78168abbb07d8ed9f54d7ea0953d46aad83nd <para>
d11bf78168abbb07d8ed9f54d7ea0953d46aad83nd Specifies the cryptographic hardware to use, when applicable.
d11bf78168abbb07d8ed9f54d7ea0953d46aad83nd </para>
bf28a00d8218aa76a56eddabca308e8d0e691626nd <para>
bf28a00d8218aa76a56eddabca308e8d0e691626nd When BIND is built with OpenSSL PKCS#11 support, this defaults
bf28a00d8218aa76a56eddabca308e8d0e691626nd to the string "pkcs11", which identifies an OpenSSL engine
bf28a00d8218aa76a56eddabca308e8d0e691626nd that can drive a cryptographic accelerator or hardware service
bf28a00d8218aa76a56eddabca308e8d0e691626nd module. When BIND is built with native PKCS#11 cryptography
70f665a8945f3bdfe8bbeaa063de2aa722fc9b29nd (--enable-native-pkcs11), it defaults to the path of the PKCS#11
70f665a8945f3bdfe8bbeaa063de2aa722fc9b29nd provider library specified via "--with-pkcs11".
70f665a8945f3bdfe8bbeaa063de2aa722fc9b29nd </para>
c08f5a0cf2b8903255186ba998a4481dfac9c796nd </listitem>
c08f5a0cf2b8903255186ba998a4481dfac9c796nd </varlistentry>
c08f5a0cf2b8903255186ba998a4481dfac9c796nd </variablelist>
c08f5a0cf2b8903255186ba998a4481dfac9c796nd </refsection>
eea521297270de3f9ae70d8822f8665c513de574nd
eea521297270de3f9ae70d8822f8665c513de574nd <refsection><info><title>TIMING OPTIONS</title></info>
eea521297270de3f9ae70d8822f8665c513de574nd
5bcdf2cd27ab0c91a3c7eaffbff4cb8505389dc1nd <para>
5bcdf2cd27ab0c91a3c7eaffbff4cb8505389dc1nd Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
5bcdf2cd27ab0c91a3c7eaffbff4cb8505389dc1nd If the argument begins with a '+' or '-', it is interpreted as
02b0660d7f44ff8106bd5095653e9c19e39ec37dnd an offset from the present time. For convenience, if such an offset
02b0660d7f44ff8106bd5095653e9c19e39ec37dnd is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
02b0660d7f44ff8106bd5095653e9c19e39ec37dnd then the offset is computed in years (defined as 365 24-hour days,
5b8e35ad88268c0210d93288dad57c2f1d3e8811nd ignoring leap years), months (defined as 30 24-hour days), weeks,
5b8e35ad88268c0210d93288dad57c2f1d3e8811nd days, hours, or minutes, respectively. Without a suffix, the offset
5b8e35ad88268c0210d93288dad57c2f1d3e8811nd is computed in seconds. To unset a date, use 'none' or 'never'.
a9ee8e9bd3dffd23ca49be8d0bdf0e33cd0bcce2jorton </para>
a9ee8e9bd3dffd23ca49be8d0bdf0e33cd0bcce2jorton
a9ee8e9bd3dffd23ca49be8d0bdf0e33cd0bcce2jorton <variablelist>
3b86be5b30d5cbacc1f942b05dff8a9365449d30jorton <varlistentry>
8d9494af6ddb7a9c998b1b622e0bcd8d17cac50ejorton <term>-P <replaceable class="parameter">date/offset</replaceable></term>
3b86be5b30d5cbacc1f942b05dff8a9365449d30jorton <listitem>
8aad5258d3ecde3751559bc685a3185e63cbde9aianh <para>
8aad5258d3ecde3751559bc685a3185e63cbde9aianh Sets the date on which a key is to be published to the zone.
8aad5258d3ecde3751559bc685a3185e63cbde9aianh After that date, the key will be included in the zone but will
8aad5258d3ecde3751559bc685a3185e63cbde9aianh not be used to sign it.
71f3601de4983bc2a6aaffcf37dc1d35c8674a34coar </para>
71f3601de4983bc2a6aaffcf37dc1d35c8674a34coar </listitem>
71f3601de4983bc2a6aaffcf37dc1d35c8674a34coar </varlistentry>
71f3601de4983bc2a6aaffcf37dc1d35c8674a34coar
49a82db11388cff9b29ff861b4241bbce69c76fdtrawick <varlistentry>
49a82db11388cff9b29ff861b4241bbce69c76fdtrawick <term>-P sync <replaceable class="parameter">date/offset</replaceable></term>
49a82db11388cff9b29ff861b4241bbce69c76fdtrawick <listitem>
49a82db11388cff9b29ff861b4241bbce69c76fdtrawick <para>
f23c50b3628a8571da2ff3277ae58ef1d675554ftrawick Sets the date on which CDS and CDNSKEY records that match this
f23c50b3628a8571da2ff3277ae58ef1d675554ftrawick key are to be published to the zone.
f23c50b3628a8571da2ff3277ae58ef1d675554ftrawick </para>
f23c50b3628a8571da2ff3277ae58ef1d675554ftrawick </listitem>
8dc154408549195c828b823e9dc7396f107f2512jorton </varlistentry>
8dc154408549195c828b823e9dc7396f107f2512jorton
8dc154408549195c828b823e9dc7396f107f2512jorton <varlistentry>
ca2504b59d48a926af23f6b18af550c1e892d8a6jorton <term>-A <replaceable class="parameter">date/offset</replaceable></term>
ca2504b59d48a926af23f6b18af550c1e892d8a6jorton <listitem>
ca2504b59d48a926af23f6b18af550c1e892d8a6jorton <para>
6126fad8adeca94e9813812c691747afeca164dftrawick Sets the date on which the key is to be activated. After that
6126fad8adeca94e9813812c691747afeca164dftrawick date, the key will be included in the zone and used to sign
6126fad8adeca94e9813812c691747afeca164dftrawick it.
7ed5992392d5babab20be4ce4029ad17ae062b5aianh </para>
7ed5992392d5babab20be4ce4029ad17ae062b5aianh </listitem>
7ed5992392d5babab20be4ce4029ad17ae062b5aianh </varlistentry>
b7973a1e572a3ff7cdedb48ed1f9481ece700bf9trawick
36f2369ee230c310fed3b600e9e99cf5770804a3wrowe <varlistentry>
b7973a1e572a3ff7cdedb48ed1f9481ece700bf9trawick <term>-R <replaceable class="parameter">date/offset</replaceable></term>
5c4e29c5f77fbc967d78886ab378b9500267b0fbtrawick <listitem>
5c4e29c5f77fbc967d78886ab378b9500267b0fbtrawick <para>
5c4e29c5f77fbc967d78886ab378b9500267b0fbtrawick Sets the date on which the key is to be revoked. After that
1fbf6ba0f5207e6637b49f9a9dfcc779bbe952a9trawick date, the key will be flagged as revoked. It will be included
1fbf6ba0f5207e6637b49f9a9dfcc779bbe952a9trawick in the zone and will be used to sign it.
6c4c113ce85934b11c9e78399e1bb8ec7a568af9nd </para>
6c4c113ce85934b11c9e78399e1bb8ec7a568af9nd </listitem>
679cafe33462d8c6bd0a74cc4359e561d19a0aafnd </varlistentry>
679cafe33462d8c6bd0a74cc4359e561d19a0aafnd
6c4c113ce85934b11c9e78399e1bb8ec7a568af9nd <varlistentry>
81ef3d132c8f335006465f297c42319f8734825dnd <term>-I <replaceable class="parameter">date/offset</replaceable></term>
81ef3d132c8f335006465f297c42319f8734825dnd <listitem>
81ef3d132c8f335006465f297c42319f8734825dnd <para>
73291de2e17c97d3549f2f8aa085ca43d27e108and Sets the date on which the key is to be retired. After that
73291de2e17c97d3549f2f8aa085ca43d27e108and date, the key will still be included in the zone, but it
73291de2e17c97d3549f2f8aa085ca43d27e108and will not be used to sign it.
73291de2e17c97d3549f2f8aa085ca43d27e108and </para>
3caed8f01e7d67f3ad5d47cb28bb4e43131652fdjerenkrantz </listitem>
3caed8f01e7d67f3ad5d47cb28bb4e43131652fdjerenkrantz </varlistentry>
3caed8f01e7d67f3ad5d47cb28bb4e43131652fdjerenkrantz
238e707c9022eaa8332a702dd6913dd0d1fb3df8jerenkrantz <varlistentry>
36f2369ee230c310fed3b600e9e99cf5770804a3wrowe <term>-D <replaceable class="parameter">date/offset</replaceable></term>
3caed8f01e7d67f3ad5d47cb28bb4e43131652fdjerenkrantz <listitem>
e127d82e8afc2f885fe2183b68d4a110580d21dfjwoolley <para>
e127d82e8afc2f885fe2183b68d4a110580d21dfjwoolley Sets the date on which the key is to be deleted. After that
e127d82e8afc2f885fe2183b68d4a110580d21dfjwoolley date, the key will no longer be included in the zone. (It
e127d82e8afc2f885fe2183b68d4a110580d21dfjwoolley may remain in the key repository, however.)
fd99717a52886f7d9f9f73be2080d3fdc2ec4bd6nd </para>
fd99717a52886f7d9f9f73be2080d3fdc2ec4bd6nd </listitem>
fd99717a52886f7d9f9f73be2080d3fdc2ec4bd6nd </varlistentry>
5fb2e8564729922524cd011b11e2d4f5d76f5a8dnd
5fb2e8564729922524cd011b11e2d4f5d76f5a8dnd <varlistentry>
5fb2e8564729922524cd011b11e2d4f5d76f5a8dnd <term>-D sync <replaceable class="parameter">date/offset</replaceable></term>
987c2c2ff2f19f306357f79d3280b347d96c470fnd <listitem>
987c2c2ff2f19f306357f79d3280b347d96c470fnd <para>
987c2c2ff2f19f306357f79d3280b347d96c470fnd Sets the date on which the CDS and CDNSKEY records that match this
987c2c2ff2f19f306357f79d3280b347d96c470fnd key are to be deleted.
a4dd3688dd6645faf0c1c1bfb22017c8f03d5b24nd </para>
a4dd3688dd6645faf0c1c1bfb22017c8f03d5b24nd </listitem>
a4dd3688dd6645faf0c1c1bfb22017c8f03d5b24nd </varlistentry>
f2fe083bb9fabd2af7eb39d4f154f27a451bb5a4nd
f2fe083bb9fabd2af7eb39d4f154f27a451bb5a4nd <varlistentry>
f2fe083bb9fabd2af7eb39d4f154f27a451bb5a4nd <term>-S <replaceable class="parameter">predecessor key</replaceable></term>
f2fe083bb9fabd2af7eb39d4f154f27a451bb5a4nd <listitem>
7de6cb79f71a9007ba2b1e786cbad8b84f05d101nd <para>
7de6cb79f71a9007ba2b1e786cbad8b84f05d101nd Select a key for which the key being modified will be an
7de6cb79f71a9007ba2b1e786cbad8b84f05d101nd explicit successor. The name, algorithm, size, and type of the
7de6cb79f71a9007ba2b1e786cbad8b84f05d101nd predecessor key must exactly match those of the key being
aa9b03a5f32732c0caaef03a7ed78ffb290e29e4trawick modified. The activation date of the successor key will be set
36f2369ee230c310fed3b600e9e99cf5770804a3wrowe to the inactivation date of the predecessor. The publication
aa9b03a5f32732c0caaef03a7ed78ffb290e29e4trawick date will be set to the activation date minus the prepublication
ab56518227d474ee08f039e4c5540011c1b8a913trawick interval, which defaults to 30 days.
36f2369ee230c310fed3b600e9e99cf5770804a3wrowe </para>
ab56518227d474ee08f039e4c5540011c1b8a913trawick </listitem>
a18a308d7a942230edcde1bf00d7ae9b4b143c90trawick </varlistentry>
36f2369ee230c310fed3b600e9e99cf5770804a3wrowe
a18a308d7a942230edcde1bf00d7ae9b4b143c90trawick <varlistentry>
3b872593fd5f61981d9dd69a4b0b5d5f5f668929trawick <term>-i <replaceable class="parameter">interval</replaceable></term>
3b872593fd5f61981d9dd69a4b0b5d5f5f668929trawick <listitem>
3b872593fd5f61981d9dd69a4b0b5d5f5f668929trawick <para>
fc25339741311efd7d460f18b6287ef38d76bbe6madhum Sets the prepublication interval for a key. If set, then
fc25339741311efd7d460f18b6287ef38d76bbe6madhum the publication and activation dates must be separated by at least
36f2369ee230c310fed3b600e9e99cf5770804a3wrowe this much time. If the activation date is specified but the
fc25339741311efd7d460f18b6287ef38d76bbe6madhum publication date isn't, then the publication date will default
fcdca175a52fe517f2317ba0e2b6e6d14522b869madhum to this much time before the activation date; conversely, if
19fdbc5566bf67dde644be9e8d38d62db4dd0ba5jerenkrantz the publication date is specified but activation date isn't,
92a2439559cf1161742650ed9c50c6483bd029cemadhum then activation will be set to this much time after publication.
92a2439559cf1161742650ed9c50c6483bd029cemadhum </para>
36f2369ee230c310fed3b600e9e99cf5770804a3wrowe <para>
92a2439559cf1161742650ed9c50c6483bd029cemadhum If the key is being set to be an explicit successor to another
ebecc16986604cce1369d5075eff65032e3dd0deianh key, then the default prepublication interval is 30 days;
0d60370bedd05f9632f54e85c417ce472d463674madhum otherwise it is zero.
ebecc16986604cce1369d5075eff65032e3dd0deianh </para>
764315969cef40e50cdc6a5e9638454e10c1c06end <para>
764315969cef40e50cdc6a5e9638454e10c1c06end As with date offsets, if the argument is followed by one of
764315969cef40e50cdc6a5e9638454e10c1c06end the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
764315969cef40e50cdc6a5e9638454e10c1c06end interval is measured in years, months, weeks, days, hours,
b92cba59a0890be43b14aaf1ce30606140be9593nd or minutes, respectively. Without a suffix, the interval is
b92cba59a0890be43b14aaf1ce30606140be9593nd measured in seconds.
b92cba59a0890be43b14aaf1ce30606140be9593nd </para>
b92cba59a0890be43b14aaf1ce30606140be9593nd </listitem>
402d23baca89e8c4fcb4e52ad8b2d66a6904baaetrawick </varlistentry>
402d23baca89e8c4fcb4e52ad8b2d66a6904baaetrawick </variablelist>
402d23baca89e8c4fcb4e52ad8b2d66a6904baaetrawick </refsection>
4caa28863a3418d26cc20a998dc368c3de3b7e19jerenkrantz
4caa28863a3418d26cc20a998dc368c3de3b7e19jerenkrantz <refsection><info><title>PRINTING OPTIONS</title></info>
4caa28863a3418d26cc20a998dc368c3de3b7e19jerenkrantz
a3f2646ef3d8a3a5234a5601de0f95f10308c2a6jerenkrantz <para>
a3f2646ef3d8a3a5234a5601de0f95f10308c2a6jerenkrantz <command>dnssec-settime</command> can also be used to print the
a3f2646ef3d8a3a5234a5601de0f95f10308c2a6jerenkrantz timing metadata associated with a key.
9e398d701dd430f073ff5418fb720642e064046ajerenkrantz </para>
9e398d701dd430f073ff5418fb720642e064046ajerenkrantz
9e398d701dd430f073ff5418fb720642e064046ajerenkrantz <variablelist>
1a5b9e0071f0c662036250b482d566ad87ff0b4bjerenkrantz <varlistentry>
1a5b9e0071f0c662036250b482d566ad87ff0b4bjerenkrantz <term>-u</term>
1a5b9e0071f0c662036250b482d566ad87ff0b4bjerenkrantz <listitem>
a7ac9b52c3d9f7ce937f078a0d585023db626c55jerenkrantz <para>
a7ac9b52c3d9f7ce937f078a0d585023db626c55jerenkrantz Print times in UNIX epoch format.
a7ac9b52c3d9f7ce937f078a0d585023db626c55jerenkrantz </para>
ba6c07204bd224fa5d4cd0e6b8bf256d6daffb74nd </listitem>
ba6c07204bd224fa5d4cd0e6b8bf256d6daffb74nd </varlistentry>
ba6c07204bd224fa5d4cd0e6b8bf256d6daffb74nd
db5837bbc9bef214303e755fa52122140366cb6fianh <varlistentry>
db5837bbc9bef214303e755fa52122140366cb6fianh <term>-p <replaceable class="parameter">C/P/Psync/A/R/I/D/Dsync/all</replaceable></term>
db5837bbc9bef214303e755fa52122140366cb6fianh <listitem>
aac2b82fe4f1ac117e2a0702438d6615542642dand <para>
aac2b82fe4f1ac117e2a0702438d6615542642dand Print a specific metadata value or set of metadata values.
aac2b82fe4f1ac117e2a0702438d6615542642dand The <option>-p</option> option may be followed by one or more
a793d402c74e50326a2401cfbdc562c5781948fdnd of the following letters or strings to indicate which value
a793d402c74e50326a2401cfbdc562c5781948fdnd or values to print:
0a209fcb17b8c9a42a6149a1758e61cf6527d367nd <option>C</option> for the creation date,
a793d402c74e50326a2401cfbdc562c5781948fdnd <option>P</option> for the publication date,
99d360dcbb5ac2be27694be74cc6124dbadf3315jerenkrantz <option>Psync</option> for the CDS and CDNSKEY publication date,
36f2369ee230c310fed3b600e9e99cf5770804a3wrowe <option>A</option> for the activation date,
99d360dcbb5ac2be27694be74cc6124dbadf3315jerenkrantz <option>R</option> for the revocation date,
3ded62d7f2c9b12616d718b8c97d3044baa9ecdbjerenkrantz <option>I</option> for the inactivation date,
3ded62d7f2c9b12616d718b8c97d3044baa9ecdbjerenkrantz <option>D</option> for the deletion date, and
3ded62d7f2c9b12616d718b8c97d3044baa9ecdbjerenkrantz <option>Dsync</option> for the CDS and CDNSKEY deletion date
ab8c0315521735c73ce16c8072f91e17c406ca5bnd To print all of the metadata, use <option>-p all</option>.
ab8c0315521735c73ce16c8072f91e17c406ca5bnd </para>
ab8c0315521735c73ce16c8072f91e17c406ca5bnd </listitem>
b9e99e0d3154bbebe3e1b8d11d6c15bde79510a5nd </varlistentry>
b9e99e0d3154bbebe3e1b8d11d6c15bde79510a5nd
b9e99e0d3154bbebe3e1b8d11d6c15bde79510a5nd </variablelist>
b9e99e0d3154bbebe3e1b8d11d6c15bde79510a5nd </refsection>
ea5f8cfbb7ef1d19318f6994c26dd73c38ffd8ddjerenkrantz
ea5f8cfbb7ef1d19318f6994c26dd73c38ffd8ddjerenkrantz <refsection><info><title>SEE ALSO</title></info>
ea5f8cfbb7ef1d19318f6994c26dd73c38ffd8ddjerenkrantz
4567cfc6a65328bd3e8dd2b758ca926b389c7058brianp <para><citerefentry>
4567cfc6a65328bd3e8dd2b758ca926b389c7058brianp <refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
4567cfc6a65328bd3e8dd2b758ca926b389c7058brianp </citerefentry>,
4cdc5446050c19b9d519a273a129188586e8d445jerenkrantz <citerefentry>
4cdc5446050c19b9d519a273a129188586e8d445jerenkrantz <refentrytitle>dnssec-signzone</refentrytitle><manvolnum>8</manvolnum>
4cdc5446050c19b9d519a273a129188586e8d445jerenkrantz </citerefentry>,
2f408250e9111c4b85b2b4b9b8836e83987efdefstoddard <citetitle>BIND 9 Administrator Reference Manual</citetitle>,
2f408250e9111c4b85b2b4b9b8836e83987efdefstoddard <citetitle>RFC 5011</citetitle>.
2f408250e9111c4b85b2b4b9b8836e83987efdefstoddard </para>
2f408250e9111c4b85b2b4b9b8836e83987efdefstoddard </refsection>
d5b7ba26785d7494166d48876362ba30ff30b98awrowe
47fe07199bddec6124ab7251c6be5c6c9ac00485jerenkrantz</refentry>
47fe07199bddec6124ab7251c6be5c6c9ac00485jerenkrantz