dnssec-settime.docbook revision f80b665135127a12ca503c8830aa465aa1ddd17d
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw [<!ENTITY mdash "—">]>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - Copyright (C) 2009 Internet Systems Consortium, Inc. ("ISC")
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - Permission to use, copy, modify, and/or distribute this software for any
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - purpose with or without fee is hereby granted, provided that the above
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - copyright notice and this permission notice appear in all copies.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw - PERFORMANCE OF THIS SOFTWARE.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw<!-- $Id: dnssec-settime.docbook,v 1.7 2009/11/03 21:44:46 each Exp $ -->
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States <refentryinfo>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw </refentryinfo>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <refentrytitle><application>dnssec-settime</application></refentrytitle>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw </refmeta>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <refnamediv>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <refname><application>dnssec-settime</application></refname>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <refpurpose>Set the key timing metadata for a DNSSEC key</refpurpose>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw </refnamediv>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <copyright>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw </copyright>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw </docinfo>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <refsynopsisdiv>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <cmdsynopsis>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <arg><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <arg><option>-P <replaceable class="parameter">date/offset</replaceable></option></arg>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <arg><option>-A <replaceable class="parameter">date/offset</replaceable></option></arg>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <arg><option>-R <replaceable class="parameter">date/offset</replaceable></option></arg>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <arg><option>-I <replaceable class="parameter">date/offset</replaceable></option></arg>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <arg><option>-D <replaceable class="parameter">date/offset</replaceable></option></arg>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <arg><option>-v <replaceable class="parameter">level</replaceable></option></arg>
7b59d02d2a384be9a08087b14defadd214b3c1ddjb <arg><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb </cmdsynopsis>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb </refsynopsisdiv>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb <refsect1>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb reads a DNSSEC private key file and sets the key timing metadata
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb as specified by the <option>-P</option>, <option>-A</option>,
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb <option>-R</option>, <option>-I</option>, and <option>-D</option>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb options. The metadata can then be used by
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb <command>dnssec-signzone</command> or other signing software to
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb determine when a key is to be published, whether it should be
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb used for signing a zone, etc.
7b59d02d2a384be9a08087b14defadd214b3c1ddjb If none of these options is set on the command line,
9fb67ea305c66b6a297583b9b0db6796b0dfe497afshin salek ardakani - Sun Microsystems - Irvine United States then <command>dnssec-settime</command> simply prints the key timing
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw metadata already stored in the key.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw When key metadata fields are changed, both files of a key
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States <filename>Knnnn.+aaa+iiiii.private</filename>) are regenerated.
b89a8333f5e1f75ec0c269b22524bd2eccb972banatalie li - Sun Microsystems - Irvine United States Metadata fields are stored in the private file. A human-readable
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw description of the metadata is also placed in comments in the key
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw </refsect1>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <refsect1>
c8ec8eea9849cac239663c46be8a7f5d2ba7ca00jose borrego <variablelist>
c8ec8eea9849cac239663c46be8a7f5d2ba7ca00jose borrego <varlistentry>
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw <listitem>
faa1795a28a5c712eed6d0a3f84d98c368a316c6jb Force an update of an old-format key with no metadata fields.
da6c28aaf62fa55f0fdb8004aa40f88f23bf53f0amw Without this option, <command>dnssec-settime</command> will