dnssec-settime.html revision 77dccf2a5d9327d16b4374a135cdb99bdd48620e
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - Copyright (C) 2009-2011 Internet Systems Consortium, Inc. ("ISC")
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - Permission to use, copy, modify, and/or distribute this software for any
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - purpose with or without fee is hereby granted, provided that the above
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - copyright notice and this permission notice appear in all copies.
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk - PERFORMANCE OF THIS SOFTWARE.
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk<!-- $Id: dnssec-settime.html,v 1.17 2011/11/05 01:14:48 tbox Exp $ -->
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk<a name="man.dnssec-settime"></a><div class="titlepage"></div>
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk<p><span class="application">dnssec-settime</span> — Set the key timing metadata for a DNSSEC key</p>
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk<div class="cmdsynopsis"><p><code class="command">dnssec-settime</code> [<code class="option">-f</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-h</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] {keyfile}</p></div>
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk<p><span><strong class="command">dnssec-settime</strong></span>
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk reads a DNSSEC private key file and sets the key timing metadata
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk as specified by the <code class="option">-P</code>, <code class="option">-A</code>,
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk <code class="option">-R</code>, <code class="option">-I</code>, and <code class="option">-D</code>
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk options. The metadata can then be used by
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk <span><strong class="command">dnssec-signzone</strong></span> or other signing software to
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk determine when a key is to be published, whether it should be
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk used for signing a zone, etc.
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk If none of these options is set on the command line,
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk then <span><strong class="command">dnssec-settime</strong></span> simply prints the key timing
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk metadata already stored in the key.
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk When key metadata fields are changed, both files of a key
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk pair (<code class="filename">Knnnn.+aaa+iiiii.key</code> and
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk <code class="filename">Knnnn.+aaa+iiiii.private</code>) are regenerated.
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk Metadata fields are stored in the private file. A human-readable
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk description of the metadata is also placed in comments in the key
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk file. The private file's permissions are always set to be
4b8d88eb610aa1e0bb6ec632f792744b3d6b5f22jeff.schenk inaccessible to anyone other than the owner (mode 0600).